Cybersecurity, Privacy, & AI

Trending Now
Top House Cyber Lawmaker Plans to Introduce DHS Overhaul Bill by Next Year • Executive Orders Seek to Hasten Quantum Computing—and Guard Against Its Use • In a First, a Court Takedown Goes After Two Cybercrime Tools at Once • NIST Opens Updated IoT Security Guidance to Public Review • Five Eyes Agencies Urge Leaders to Strengthen Cyber Resilience in AI Era

Nation-State Hackers Attempted to Use Equifax Vulnerability Against DoD

An NSA official has revealed that a government-backed hacking group tried to breach the Department of Defense via the same software vulnerability that was used against Equifax, less than 24 hours after the exploit became public knowledge.

David Hogue, a senior technical director for the NSA’s Cybersecurity Threat Operations Center, says that this shows how most attackers, regardless of skill or available resources, will first rely on simplistic and easily accessible methods to compromise their victims. In this case, the exploit took advantage of a known vulnerability in the Apache Struts software framework, which Equifax went months without fixing.

Hogue says that “zero-day” vulnerabilities are uncommon problem for the NSA. “The majority of incidents we see are a result of hardware and software updates that are not applying.” Most data breach incidents that are analyzed by his team are caused by phishing emails or unpatched vulnerable systems.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.