President Biden’s Cyber Dilemma

The Biden administration is grappling with two major cyber incidents in its first 50 days in office, underscoring the challenge the new White House faces from foreign actors. Russia and China are suspected in the two incidents, which may have compromised thousands of federal, state and private groups for long periods of time before discovery. The effect has been to move cyber security up the list of the administration’s priorities.

Russia has expressed its alarm after it was reported the United States was planning a series of covert counter-attacks on Russian networks, saying such strikes would amount to cyber crimes.

The US security level is being raised probably because of the recent attacks on the US government systems and these US attacks may also be focused on the Chinese and Russian hackers because of the amount of hacks on Microsoft Exchange is now thought to be tens of thousands of organisations that have probably been cyber attacked and compromised. The hackers have used previously unknown flaws in the email software to steal information and data.  Microsoft has said the attackers are "state-sponsored and operating out of China". And now it looks like other hackers are also attacking these systems.   

The hacking group known as Hafnium breached as many victims they could find across the global Internet, leaving behind backdoors to return to later. This follows the recent SolarWinds cyber hacks, linked to Russia, that affected multiple US government departments and other organisations.

US national security adviser Jake Sullivan wrote on Twitter,“We are closely tracking Microsoft’s emergency patch for previously unknown vulnerabilities in Exchange Server software and reports of potential compromises of US think tanks and defense industrial base entities. We encourage network owners to patch ASAP.” 

One US senator has described the SolarWinds attack as an "act of war", but what options President Biden has is not obvious..

That these cyber attacks by potentially hackers backed by governments is a real problem for the Biden administration and will likley result in US Cybercommand being directed to step up hacking into adversary systems to find out what they are doing and stopping operations against the US before they are unleashed.

The US has often considered espionage as then stealing of information as acceptable, because it practised it extensively, as whistleblower Edward Snowden revealed in 2013 and these attacks and the response may fit into the same category. President Biden is launching an emergency taskforce to address an aggressive cyber-attack that has affected hundreds of thousands of Microsoft customers around the world, the second major hacking campaign to hit the US since the election.

The first major move is expected over the next three weeks, officials said, with a series of clandestine actions across Russian and Chinese networks.  

White House press secretary Jen Psaki warned anyone running the affected Exchange servers to implement Microsoft's patch for the vulnerabilities immediately. "We are concerned that there are a large number of victims and are working with our partners to understand the scope of this... Network owners also need to consider whether they have already been compromised and should immediately take appropriate steps."

The task of cleaning up the hackers' tens of thousands of infections may be, that early detection may give victims a chance to both patch their systems and remove the hackers before they can take advantage of their foothold inside organisations.

The Hill:      New York Times:   Wired:      Guardian:       Yahoo:     Jake Sullivan:       BBC

You Might Also Read: 

Solving Mr. Biden’s Wicked Cyber Problem:

 

« Cyber Security For The Internet of Medical Things
British Schools & Universities Suffer Attacks »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

44CON

44CON

44CON is an Information Security Conference & Training event taking place in London. Designed to provide something for the business and technical Information Security professional.

Sucuri

Sucuri

Sucuri have offered holistic website security solutions since 2008 including malware removal, malware monitoring and website protection services.

Cyber Security Recruiters

Cyber Security Recruiters

Cyber Security Recruiters is a niche recruiting firm who finds impact players for our clients in the Information Security Space.

Cyber Affairs

Cyber Affairs

Cyber Affairs is the first Italian press agency entirely dedicated to cyber security.

Picus Security

Picus Security

Huge gaps often exists between the "perceived"​ and "actual"​ IT security level of an organization. Picus Security continuously assesses security controls and reveals deficient ones before hackers do.

CSL Group

CSL Group

CSL solutions provide complete end-to-end connectivity services for Security, Fire, Telecare and other mission critical M2M/IoT applications.

Riverside Research

Riverside Research

Riverside Research is a not-for-profit organization chartered to advance scientific research in areas including Trusted & Resilient Systems.

Steganos

Steganos

Steganos offers highly secure and easy to use software tools that protect and secure on and offline data.

Finnish Accreditation Service (FINAS)

Finnish Accreditation Service (FINAS)

FINAS is the national accreditation body for Finland. The directory of members provides details of organisations offering certification services for ISO 27001.

Blockchains LLC

Blockchains LLC

Blockchains is committed to changing the world for the better. Using blockchain and other innovative technologies, we’ll build new systems, new security, and new interactions.

DAtAnchor

DAtAnchor

Anchor is simply a better way to protect and control sensitive data. Zero-trust, data-centric security. Simplified.

Techmentum

Techmentum

At Techmentum, our mission is to utilize technology to help companies succeed. Our expertise includes fully managed IT services, cybersecurity, cloud, and custom technology solutions.

Closed Door Security

Closed Door Security

Closed Door Security is the only cybersecurity team in the north of Scotland offering everything from IASME Certification to CREST-Accredited penetration testing.

Uptime Institute

Uptime Institute

Uptime Institute is an unbiased advisory organization focused on improving the performance, efficiency, and reliability of business critical infrastructure.

CyXcel

CyXcel

CyXcel is a cyber security consulting business grounded in the law which natively fuses crises, legal, technical, and consulting expertise digital networks, information and operational technology.

Loccus AI

Loccus AI

Loccus are developers of AI solutions in the voice safety space. We build identity verification solutions, deepfake detection systems and fraud protection products for companies and end-users.