3 ms·
The US govt can also do a lot better. The very agency they formed to counter cyber threats and alert against(CISA) itself got hacked because they failed to patc
by ripjaygn 2y ago
The US govt can also do a lot better. The very agency they formed to counter cyber threats and alert against(CISA) itself got hacked because they failed to patch or remediate, and led to a serious leak of sensitive chemical industry information among others. Because they failed to follow their own security advisory. And they won't even put out a report detailing the hack like MS did.
> According to an early report on the breach, an anonymous source said that the compromised systems were the Infrastructure Protection (IP) Gateway, which houses critical information about the interdependency of U.S. infrastructure, and the Chemical Security Assessment Tool (CSAT), which houses private sector chemical security plans.
> CSAT is an online portal that contains highly sensitive information that determines which facilities are considered high-risk under the Chemical Facility Anti-Terrorism Standards (CFATS).
> CISA declined to confirm or deny which of their systems were taken offline.
https://securityintelligence.com/news/cisa-hackers-key-systems-offline/ https://securityintelligence.com/news/cisa-hackers-key-syste...
> In late February, CISA had already issued a warning that cyber threat actors are exploiting previously identified vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure gateways. Ivanti Connect Secure is a widely deployed SSL VPN, while Ivanti Policy Secure (IPS) is a network access control (NAC) solution.
> Now, CISA itself has fallen victim to a cyberattack involving Ivanti products.