Showing posts with label CISA. Show all posts
Showing posts with label CISA. Show all posts

Thursday, January 13, 2022

FBI, CISA And NSA Release Cybersecurity Advisory On Russian Cyber Threats To U.S. Critical Infrastructure


CISA, the Federal Bureau of Investigation (FBI), and the National Security Agency (NSA) have released a joint Cybersecurity Advisory (CSA) that provides an overview of Russian state-sponsored cyber operations, including commonly observed tactics, techniques, and procedures. The CSA also provides detection actions, incident response guidance, and mitigations. CISA, the FBI, and NSA are releasing the joint CSA to help the cybersecurity community reduce the risk presented by Russian state-sponsored cyber threats.  

CISA, the FBI, and NSA encourage the cybersecurity community—especially critical infrastructure network defenders—to adopt a heightened state of awareness, conduct proactive threat hunting, and implement the mitigations identified in the joint CSA. CISA recommends network defenders review CISA's Russia Cyber Threat Overview and Advisories page for more information on Russian state-sponsored malicious cyber activity. CISA recommends critical infrastructure leaders review CISA Insights: Preparing For and Mitigating Potential Cyber Threats for steps to proactively strengthen their organization’s operational resiliency against sophisticated threat actors, including nation-states and their proxies. 

Monday, October 5, 2020

FBI/CISA: Spoofed Internet Domains And Email Accounts Pose Cyber And Disinformation Risks To Voters

 The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are issuing this announcement to help the public recognize and avoid spoofed election-related internet domains and email accounts during the 2020 election year.

Spoofed domains and email accounts are leveraged by foreign actors and cybercriminals and can be easily mistaken for legitimate websites or emails. Adversaries can use spoofed domains and email accounts to disseminate false information; gather valid usernames, passwords, and email addresses; collect personally identifiable information; and spread malware, leading to further compromises and potential financial losses.

Cyber actors set up spoofed domains with slightly altered characteristics of legitimate domains. A spoofed domain may feature an alternate spelling of a word ("electon" instead of "election"), or use an alternative top-level domain, such as a "[.]com" version of a legitimate "[.] gov" website. Members of the public could unknowingly visit spoofed domains while seeking information regarding the 2020 election. Additionally, cyber actors may use a seemingly legitimate email account to entice the public into clicking on malicious files or links.

The FBI and CISA urge all members of the American public to critically evaluate the websites they visit and the emails sent to their personal and business email accounts, to seek out reliable and verified information on election information.

RECOMMENDATIONS
  • Verify the spelling of web addresses, websites, and email addresses that look trustworthy but may be close imitations of legitimate election websites.
  • Seek out information from trustworthy sources, verifying who produced the content and considering their intent. The Election Assistance Commission (https://www.eac.gov) provides a vast amount of verified information and resources.
  • Ensure operating systems and applications are updated to the most current versions.
  • Update anti-malware and anti-virus software and conduct regular network scans.
  • Do not enable macros on documents downloaded from an email unless absolutely necessary, and only then, after ensuring the file is not malicious.
  • Disable or remove unneeded software applications.
  • Use strong two-factor authentication if possible, via biometrics, hardware tokens, or authentication apps.
  • Do not open e-mails or attachments from unknown individuals. Do not communicate with unsolicited e-mail senders.
  • Never provide personal information of any sort via e-mail. Be aware that many e-mails requesting your personal information appear to be legitimate.

The FBI is responsible for investigating and prosecuting election crimes, malign foreign influence operations, and malicious cyber activity targeting election infrastructure and other U.S. democratic institutions. CISA helps critical infrastructure owners and operators, including those in the election community, remain resilient against physical and cyber threats. The FBI and CISA provide services and information to uphold the security, integrity, and resiliency of U.S. electoral processes.

VICTIM REPORTING AND ADDITIONAL INFORMATION

The FBI encourages the public to report information concerning suspicious or criminal activity to their local field office (www.fbi.gov/contact-us/field-offices) or to the FBI's Internet Crime Complaint Center (www.ic3.gov). For additional assistance, best practices, and common terms, please visit the following websites:


Friday, May 15, 2020

The FBI Warns That Communist China Is Targeting U.S. COVID-19 Research Organizations


The FBI released the below statement:
The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA) are issuing this announcement to raise awareness of the threat to COVID-19-related research. The FBI is investigating the targeting and compromise of U.S. organizations conducting COVID-19-related research by PRC-affiliated cyber actors and non-traditional collectors. These actors have been observed attempting to identify and illicitly obtain valuable intellectual property (IP) and public health data related to vaccines, treatments, and testing from networks and personnel affiliated with COVID-19-related research. The potential theft of this information jeopardizes the delivery of secure, effective, and efficient treatment options.
The FBI and CISA urge all organizations conducting research in these areas to maintain dedicated cybersecurity and insider threat practices to prevent surreptitious review or theft of COVID-19-related material. FBI is responsible for protecting the U.S. against foreign intelligence, espionage, and cyber operations, among other responsibilities. CISA is responsible for protecting the nation’s critical infrastructure from physical and cyber threats. CISA is providing services and information to support the cybersecurity of federal and state/local/tribal/territorial entities and private sector entities that play a critical role in COVID-19 research and response.