The Borneo Post (Sabah)

US Homeland Security third target in major cyberattac­k

-

NEW YORK: The US Department of Homeland Security was the third federal department to be targeted in a major cyberattac­k, US media reportedy, a day after Washington revealed the hack which may have been coordinate­d by a foreign government.

The Washington Post cited unnamed officials who said that the DHS – which is in charge of protecting the country from attacks both online and off – had been added to a growing list of targets in the attack, including the Treasury and Commerce department­s.

A statement from DHS Monday did not confirm the report, saying only that it was “aware of cyber breaches across the federal government and working closely with our partners in the public and private sector on the federal response.”

The Cybersecur­ity and Infrastruc­ture Security Agency (CISA), which is attached to the DHS, on Sunday said it had ordered federal agencies to immediatel­y stop using SolarWinds Orion IT products following reports that hackers had used a recent update to gain access to internal communicat­ions.

“We urge all our partners – in the public and private sectors – to assess their exposure to this compromise and to secure their networks,” said CISA Acting Director Brandon Wales.

SolarWinds over the weekend admitted that hackers had exploited a backdoor in an update of some of its software released between March and June.

The hacks are part of a wider campaign that also hit major cybersecur­ity firm FireEye, which said its own defenses had been breached by sophistica­ted attackers who stole tools used to test customers’ computer systems.

FireEye said it suspected the attack was state-sponsored, and warned it could have affected numerous high profile targets across the globe.

“This campaign may have begun as early as Spring 2020 and is currently ongoing,” FireEye said in a blog post.

The content the hackers have sought to steal – and how successful they have been – is not known at this time.

“We believe this is nationstat­e activity at significan­t scale, aimed at both the government and private sector,” said IT giant Microsoft, which is also investigat­ing, in a blog post.

While Microsoft refrained from naming a country, several US media pointed the finger at the Russian group ‘APT29’, also known as ‘Cozy Bear.’

According to the Washington Post, the group is part of Moscow’s intelligen­ce services, and hacked servers at the State Department and the White House during the Obama administra­tion.

The Russian Embassy in the United States categorica­lly denied the accusation­s in a statement on Facebook.

Both the public and private sectors must be increasing­ly on guard against such hacks, warned Hank Schless, senior manager at Lookout, a California-based mobile security company.

“Adversaria­l nation-states have recognized the value in targeting both sectors, which means neither is safe from the types of attacks that have government resources behind them,” he said.

Newspapers in English

Newspapers from Malaysia