Cybersecurity, Privacy, & AI

Trending Now
Anthropic’s Reported $30B Funding Talks Spotlight AI’s Growing Role in Cybersecurity, Defense • DC3 Seeks New Contractors for DCISE Voluntary Cyber Information-Sharing Program • Pentagon Cyber Official Calls Advanced AI ‘Revolutionary Warfare’ • NIST Aims for Summer Release of AI Cyber Guidelines • President Trump’s Cyber Strategy: Cross-Sector Implications for U.S. and UK Businesses

Nation-State Hackers Attempted to Use Equifax Vulnerability Against DoD

An NSA official has revealed that a government-backed hacking group tried to breach the Department of Defense via the same software vulnerability that was used against Equifax, less than 24 hours after the exploit became public knowledge.

David Hogue, a senior technical director for the NSA’s Cybersecurity Threat Operations Center, says that this shows how most attackers, regardless of skill or available resources, will first rely on simplistic and easily accessible methods to compromise their victims. In this case, the exploit took advantage of a known vulnerability in the Apache Struts software framework, which Equifax went months without fixing.

Hogue says that “zero-day” vulnerabilities are uncommon problem for the NSA. “The majority of incidents we see are a result of hardware and software updates that are not applying.” Most data breach incidents that are analyzed by his team are caused by phishing emails or unpatched vulnerable systems.

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.