Cybercriminals, APT Exploited Telerik Vulnerability in Attacks on US Government Agency

Advanced persistent threat (APT) actors and financially motivated cybercriminals have been spotted exploiting an old Telerik vulnerability as part of an attack that impacted a US government agency, according to a joint alert released on Wednesday by CISA, the FBI, and MS-ISAC.

An investigation revealed that a Microsoft Internet Information Services (IIS) web server belonging to a federal civilian executive branch (FCEB) agency hosted a vulnerable instance of the Telerik UI for ASP.NET AJAX application development library.

Progress Software’s Telerik application development solutions are used by major companies around the world, making vulnerabilities in these products highly valuable to threat actors.

According to CISA, an investigation conducted between November 2022 and January 2023 showed that threat actors exploited the Telerik vulnerability tracked as CVE-2019-18935 for remote code execution. 

The impacted agency had been using a vulnerability scanner that should have detected the presence of a component vulnerable to CVE-2019-18935, but it failed to do so due to the software being installed in a path not checked by the scanner. 

It’s believed that CVE-2019-18935 was chained with one of two even older Telerik vulnerabilities tracked as CVE-2017-11357 and CVE-2017-11317. Exploitation of CVE-2017-11357 or CVE-2017-11317 can be used to obtain encryption keys that are needed to exploit CVE-2019-18935.

CISA has not named the APT actor whose presence was detected on the government agency’s IIS server, but it did reveal that exploitation by a cybercrime gang known as XE Group was also observed on the same machine. In both cases, the flaw was leveraged to deliver DLL files that allowed the attackers to perform various activities. 

In the case of the APT, the group apparently exploited the security hole starting in August 2022. The malware they delivered was capable of collecting system information, writing files, and helping the attackers cover their tracks. 

As for XE Group, the earliest activity on the server was traced to August 2021. The hackers delivered DLL files that enabled them to collect system information and deploy additional components on the compromised system.

XE Group is a cybercrime gang that is believed to be operating out of Vietnam. The group has been around since at least 2013 and it has been known to target websites hosted on IIS servers in payment card skimming attacks. 

The hackers have been known to exploit the Telerik UI vulnerability tracked as CVE-2017-9248.

CVE-2019-18935 has been in CISA’s known exploited vulnerabilities catalog since November 2021, when the catalog was launched. One of the 2017 CVEs was added to the catalog in April 2022 and the other in January 2023. 

In 2020, the NSA listed CVE-2019-18935 as one of the most commonly exploited vulnerabilities by Chinese state-sponsored hackers.

In April 2022, cybersecurity agencies in the US, Canada, UK, Australia and New Zealand included CVE-2019-18935 in a list of commonly exploited security holes. Ransomware groups have also been known to target the flaw in their operations. 

The government alert published on Wednesday includes technical details, indicators of compromise (IoCs) and recommendations on how companies can prevent hackers from exploiting these vulnerabilities. 

Related: Dozens of Exploited Vulnerabilities Missing From CISA ‘Must Patch’ List

Related: CISA Warns of Two Mitel Vulnerabilities Exploited in Wild

Cybercriminals, APT Exploited Telerik Vulnerability in Attacks on US Government Agency




CISA Warns of Plex Vulnerability Linked to LastPass Hack

The US Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities impacting Plex and VMware products to its Known Exploited Vulnerabilities (KEV) catalog.

Tracked as CVE-2020-5741, the first is a high-severity flaw in Plex Media Server that is described as a deserialization issue that can be exploited to execute arbitrary Python code, remotely.

“This issue allowed an attacker with access to the server administrator’s Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it,” Plex noted in a May 2020 advisory.

Addressed with the release of Plex Media Server 1.19.3, the vulnerability requires for the attacker to have admin access to a Plex Media Server for successful exploitation, which made it unlikely to be targeted in attacks.

However, Plex in August 2022 disclosed a data breach that likely impacted over 15 million customers, and which resulted in usernames, emails, and password data being stolen.

This essentially opened the door for the exploitation of unpatched Plex Media Server instances still impacted by CVE-2020-5741.

While CISA added the vulnerability to the KEV list without sharing details on in-the-wild exploitation, media reports suggested recently that last year’s LastPass data breach that led to the theft of user vault data might be related to a Plex bug exploited to hack a DevOps engineer’s computer.

Plex provided the following statement to SecurityWeek:

“We take security issues very seriously, and frequently work with external parties who report issues big or small using our guidelines and bug bounty program. When vulnerabilities are reported following responsible disclosure we address them swiftly and thoroughly, and we’ve never had a critical vulnerability published for which there wasn’t already a patched version released. And when we’ve had incidents of our own, we’ve always chosen to communicate them quickly. We are not aware of any unpatched vulnerabilities, and as always, we invite people to disclose issues to us following the guidelines linked above.

We learned from LastPass that the vulnerability that was exploited is detailed here: https://forums.plex.tv/t/security-regarding-cve-2020-5741/586819, which was disclosed by Plex publicly back in May, 2020 (a good 2.5 years prior to the LastPass event). At the time, as noted in that post, an updated version of the Plex Media Server was made available to all (7-MAY-2020). Unfortunately, the LastPass employee never upgraded their software to activate the patch. For reference, the version that addressed this exploit was roughly 75 versions ago. Plex will provide notifications via the admin UI about updates that are available, and will also do automatic updates in many cases.”

The second vulnerability that CISA added to its KEV list last week is CVE-2021-39144, a remote code execution issue in XStream, which was recently seen being exploited in malicious attacks targeting VMware products. VMware Cloud Foundation and NSX Data Center for vSphere (NSX-V) are impacted.

“This vulnerability can affect multiple products including but not limited to VMware Cloud Foundation,” CISA notes. 

As per the Binding Operational Directive (BOD) 22-01, federal agencies are required to address these vulnerabilities until March 31. However, all organizations are encouraged to review the catalog and apply patches where necessary.

Related:Dozens of Exploited Vulnerabilities Missing From CISA ‘Must Patch’ List

Related:557 CVEs Added to CISA’s Known Exploited Vulnerabilities Catalog in 2022

Related: Exploited Control Web Panel Flaw Added to CISA ‘Must-Patch’ List

https://www.securityweek.com/cisa-warns-of-plex-vulnerability-linked-to-lastpass-hack/




Unpatched Akuvox Smart Intercom Vulnerabilities Can Be Exploited for Spying

A smart intercom product made by Chinese company Akuvox is affected by more than a dozen vulnerabilities, including potentially serious flaws that can be exploited for spying. 

The vulnerabilities were discovered by researchers at industrial and IoT cybersecurity firm Claroty. The company — along with CISA and CERT/CC — has attempted to report the findings to the vendor over the past year, but without success, and the security holes remain unpatched. 

Claroty this week disclosed technical details of its findings and CISA has also published an advisory. 

The security firm started analyzing Akuvox’s E11 product after finding it in a new office space it moved into last year. The E11 is advertised as a video doorphone designed for homes, villas, offices, and warehouses. It includes live video streaming, motion detection, and access control capabilities. According to CISA, the affected product has been used worldwide.

Claroty’s analysis revealed the existence of 13 vulnerabilities related to weak encryption, the use of hardcoded cryptographic keys, sensitive information exposure, insecure password recovery mechanisms, command injection flaws, improper access control and authentication, missing authorization, and hidden functionality that can be abused for malicious purposes.

A majority of these vulnerabilities have been assigned ‘critical’ and ‘high’ severity ratings. An attacker could exploit the flaws for remote code execution, remotely activating a device’s microphone and camera and transmitting data to a remote server, and obtaining stored images and data captured by the device.

An attacker could exploit the vulnerabilities to take complete control of the targeted Akuvox device, allowing them to spy on users, open doors, and gain a foothold into the targeted organization’s network, according to Claroty.

“In privacy-sensitive organizations, such as healthcare centers, this can put organizations in violation of numerous regulations designed to ensure patient privacy,” the company warned. 

Many of the vulnerabilities can be exploited without authentication and attacks can even be launched directly from the internet if the targeted device is accessible from the web. 

SecurityWeek has reached out to the vendor for comment and will update this article if the company responds.

While there do not appear to be any patches, Claroty said the risk can be mitigated by ensuring the device is not exposed to the internet, isolating it from the rest of the enterprise network to prevent lateral movement, and changing the default password for the web interface.

Related: Aiphone Intercom System Vulnerability Allows Hackers to Open Doors

Related: Vulnerability in IDEMIA Biometric Readers Allows Hackers to Unlock Doors

Related: Vulnerability Allows Hackers to Unlock Smart Home Door Locks

https://www.securityweek.com/unpatched-akuvox-smart-intercom-vulnerabilities-can-be-exploited-for-spying/




Serious Vulnerability Patched in Veeam Data Backup Solution

Veeam this week announced patches for a severe vulnerability in its Backup & Replication solution that could lead to the exposure of credentials.

A backup solution for virtual environments, Veeam Backup & Replication supports virtual machines running on Hyper-V, Nutanix AHV, and vSphere, as well as servers, workstations, and cloud-based workloads.

Tracked as CVE-2023-27532 (CVSS score of 7.5), the vulnerability allows an attacker to obtain the encrypted credentials that are stored in the configuration database.

“The vulnerable process, Veeam.Backup.Service.exe (TCP 9401 by default), allows an unauthenticated user to request encrypted credentials,” Veeam explains in an advisory.

According to the company, successful exploitation of the security defect could provide attackers with access to the backup infrastructure hosts.

All Veeam Backup & Replication versions are impacted by this issue. Patches were included in application versions 12 (build 12.0.0.1420 P20230223) and 11a (build 11.0.1.1261 P20230227).

Users need to install the patches on the Veeam Backup & Replication server. New deployments installed using the ISO images dated February 23 (version 12) and February 27 (version 11) or later are not vulnerable.

Users of older Veeam Backup & Replication versions are advised to update to a supported iteration as soon as possible.

“If you use an all-in-one Veeam appliance with no remote backup infrastructure components, you can alternatively block external connections to port TCP 9401 in the backup server firewall as a temporary remediation until the patch is installed,” Veeam explains.

The company makes no mention of the vulnerability being exploited in the wild, but hackers have been known to exploit Backup & Replication flaws in their attacks. 

Furthermore, penetration testing firm Code White warns that creating an exploit for this vulnerability is relatively easy.

“CVE-2023-27532 in Veeam Backup & Replication is serious, expect exploitation attempts soon. Our teammate @mwulftange was able to develop an exploit just by using the exposed API,” Code White tweeted.

Related: CISA Warns Veeam Backup & Replication Vulnerabilities Exploited in Attacks

Related:Critical Vulnerabilities Patched in Veeam Data Backup Solution

Related: Exploitation of Critical Vulnerability in End-of-Life VMware Product Ongoing

https://www.securityweek.com/serious-vulnerability-patched-in-veeam-data-backup-solution/




Custom Chinese Malware Found on SonicWall Appliance

Google-owned cybersecurity firm Mandiant reported on Wednesday that it has identified sophisticated malware believed to be of Chinese origin on a SonicWall appliance. 

The malware, apparently deployed as part of a Chinese campaign, was analyzed by Mandiant and SonicWall’s Product Security and Incident Response Team (PSIRT). The researchers found that the attacker had created a series of bash scripts and a TinyShell variant in the form of an ELF binary.

The custom-built malware allows the attackers to steal credentials — this appears to be its main purpose — and provides shell access. The hackers apparently targeted hashed credentials for all logged-in users. 

According to Mandiant, the malware “is well tailored to the system to provide stability and persistence”, being able to persist even across firmware upgrades.

The malware was spotted on an unpatched SonicWall Secure Mobile Access (SMA) appliance, but it’s unclear how the attackers gained initial access. Mandiant suggested that the hackers may have exploited a known vulnerability that the targeted SonicWall customer neglected to patch. 

It’s not uncommon for threat actors to target known and even zero-day vulnerabilities in SonicWall appliances in their attacks. 

Mandiant believes the malware was likely deployed on the device in 2021, but the attacker managed to maintain access by modifying firmware updates in a way that ensured the malware’s persistence. 

The security firm is aware of another Chinese threat actor using similar techniques, but it has decided to track the threats separately. The new group is currently tracked by Mandiant as UNC4540.

SonicWall announced this week that it has released an update for SMA 100 series devices (10.2.1.7), which “includes several key security features that protect the operating system from potential attack”.

Related: SonicWall Zero-Day Exploited by Ransomware Group Before It Was Patched

Related: Three Zero-Day Flaws in SonicWall Email Security Product Exploited in Attacks

Related: SonicWall Patches SMA Zero-Day Vulnerability Exploited in Attacks

https://www.securityweek.com/custom-chinese-malware-found-on-sonicwall-appliance/




Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks

Cisco this week announced patches for a high-severity denial-of-service (DoS) vulnerability in the IOS XR software for ASR 9000, ASR 9902, and ASR 9903 series enterprise routers.

Tracked as CVE-2023-20049 (CVSS score of 8.6), the vulnerability impacts the bidirectional forwarding detection (BFD) hardware offload feature for the platform and can be exploited remotely, without authentication.

On vulnerable devices with the BFD hardware offload feature enabled, malformed BFD packets are incorrectly handled, allowing an attacker to send crafted IPv4 BFD packets to the configured IPv4 address and trigger the flaw.

“A successful exploit could allow the attacker to cause line card exceptions or a hard reset, resulting in loss of traffic over that line card while the line card reloads,” Cisco explains in an advisory.

As a workaround, the tech giant recommends disabling the BFD hardware offload feature, which can be done by removing all hw-module bfw-hw-offload enable commands and resetting the line card.

The security defect impacts ASR 9000 series aggregation services routers with a Lightspeed or Lightspeed-Plus-based line card installed and ASR 9902 and ASR 9903 compact high-performance routers.

Patches for this vulnerability were included in IOS XR software versions 7.5.3, 7.6.2, and 7.7.1.

This week, Cisco also announced patches for an information disclosure vulnerability in the GRand Unified Bootloader (GRUB) for IOS XR software. Tracked as CVE-2023-20064, the vulnerability can be exploited by unauthenticated attackers that have physical access to the device.

The tech giant says it is not aware of any of these vulnerabilities being exploited in attacks. Additional details can be found on Cisco’s product security page.

Related: Cisco Patches Critical Vulnerability in IP Phones

Related: Cisco Patches High-Severity Vulnerabilities in ACI Components

Related: Critical Vulnerability Patched in Cisco Security Products

https://www.securityweek.com/vulnerability-exposes-cisco-enterprise-routers-to-disruptive-attacks/




Dozens of Exploited Vulnerabilities Missing From CISA ‘Must Patch’ List

Dozens of security flaws that have likely been exploited in the wild are missing from the Known Exploited Vulnerabilities (KEV) catalog maintained by the US Cybersecurity and Infrastructure Security Agency (CISA), according to vulnerability intelligence company VulnCheck.

VulnCheck recently conducted an analysis of the vulnerabilities added by CISA to its catalog in 2022. While the agency added more than 550 security holes last year, VulnCheck found that 42 vulnerabilities that have likely been exploited in malicious attacks and assigned CVE identifiers in 2022 were not present as of March 3.

CISA’s KEV catalog is often referred to as a ‘must patch’ list because government organizations are required to patch the flaws within specified timeframes and private companies are strongly encouraged to do so.

Of the vulnerabilities that VulnCheck believes have been exploited in attacks but have not been added to CISA’s KEV catalog, 64% are related to botnets, followed by threat actors (12%) and ransomware (10%) — the rest are unattributed. 

One of the missing flaws is CVE-2017-20149, which impacts Mikrotik routers. Information about this issue emerged in 2017, when WikiLeaks published Vault7 documents, which describe hacking tools allegedly developed by the CIA. The vulnerability was only assigned a CVE identifier in 2022, but it was backdated to 2017. 

Another missing CVE was CVE-2022-28810, a ManageEngine ADSelfService Plus vulnerability linked to Chinese APT activity. CISA did add this flaw to its catalog just before the VulnCheck report came out, along with CVE-2022-35914, a GLPI bug, and CVE-2022-33891, an Apache Spark vulnerability whose exploitation was spotted in December 2022 by Microsoft. The GLPI vulnerability was also among the 42 vulnerabilities mentioned in VulnCheck’s report.   

CISA last year clarified the criteria for adding vulnerabilities to the KEV catalog. There are three main conditions that need to be met: the flaw needs to have a CVE identifier, there has to be reliable evidence of exploitation in the wild, and patches, mitigations or workarounds need to be available. 

It’s unclear why dozens of apparently exploited vulnerabilities have yet to be added to the KEV catalog. SecurityWeek has reached out to CISA for clarifications and will update this article if the agency responds. 

VulnCheck’s analysis, which provides links to reliable sources reporting exploitation of the neglected flaws, shows that three-quarters of the bugs can be exploited for initial access. In addition, 31 of the vulnerabilities have public exploits. 

The list of missing vulnerabilities includes CVE-2022-2003, which Cisco Talos believes has been exploited in attacks involving the Truebot malware, and CVE-2022-2003, which industrial cybersecurity firm Dragos has seen being exploited by a programmable logic controller (PLC) password cracking tool.

“​​The CISA KEV Catalog is undoubtedly helpful and a driving force in our industry. Still, as long as it’s missing actively exploited vulnerabilities, it cannot be treated as the authoritative catalog of exploited vulnerabilities,” VulnCheck said. “Practitioners should augment vulnerability management programs by seeking out additional sources or finding a source with a more complete dataset.”

Related: Exploited Control Web Panel Flaw Added to CISA ‘Must-Patch’ List

https://www.securityweek.com/dozens-of-exploited-vulnerabilities-missing-from-cisa-must-patch-list/




Jenkins Server Vulnerabilities Chained for Remote Code Execution 

Two recently patched vulnerabilities affecting Jenkins servers can be chained to achieve remote code execution, cybersecurity firm Aqua Security warns.

Tracked as CVE-2023-27898 and CVE-2023-27905 and impacting both Jenkins Server and Update Center, the two security defects are described as cross-site scripting (XSS) bugs that can be exploited by providing a malicious plugin.

Rated ‘high severity’, CVE-2023-27898 exists because Jenkins “does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins in the plugin manager”.

An attacker could provide a manipulated plugin to trigger the XSS. The plugin’s installation is not required for successful exploitation.

The flaw impacts Jenkins versions 2.270 through 2.393 and long-term support (LTS) releases 2.277.1 through 2.375.3. Jenkins version 2.394, LTS 2.375.4, and LTS 2.387.1 escape the Jenkins version a plugin depends on.

“Due to how Jenkins community update sites serve plugin metadata based on the reported Jenkins core version, it is unlikely that a reasonably up to date Jenkins instance shows the vulnerable error message in the plugin manager at all,” Jenkins explains.

A medium-severity flaw, CVE-2023-27905 impacts update-center2, a tool that generates Jenkins update sites that are hosted on updates.jenkins.io.

The tool “renders the required Jenkins core version on plugin download index pages” and retrieves this version from plugin metadata without sanitization, which results in an XSS vulnerability. An attacker could trigger the bug by providing a plugin for hosting.

Aqua Security says that a remote attacker could chain these issues to achieve arbitrary code execution on a vulnerable server, without authentication. Named CorePlague, the attack chain could result in full compromise of the Jenkins server, the cybersecurity firm warns.

For that, the attacker would need to upload a malicious plugin to the Jenkins Update Center. Next, when the victim opens the Available Plugin Manager, the vulnerability is triggered, leading to code execution without further user interaction.

“Attackers could exploit these vulnerabilities to compromise Jenkins Servers, even though they are not directly reachable because the public Jenkins Update Center – which is used by default on Jenkins Servers to obtain available plugin lists – could be injected by attackers,” Aqua Security says.

Jenkins released a fix for update-center2 on February 15, when it also patched the public Jenkins Update Center. This week, updates were released for Jenkins core to resolve these two flaws along with five other high- and medium-severity bugs.

Additional details on the addressed vulnerabilities can be found in the Jenkins security advisory.

Related:Jenkins Says Confluence Service Compromised Using Recent Exploit

Related: Jenkins Vulnerability Exploited to Deliver ‘Kerberods’ Malware

Related: Vulnerabilities Found in Over 100 Jenkins Plugins

https://www.securityweek.com/jenkins-server-vulnerabilities-chained-for-remote-code-execution/




Fortinet Patches Critical Unauthenticated RCE Vulnerability in FortiOS

Cybersecurity company Fortinet this week announced patches for multiple severe vulnerabilities across its product portfolio, including a critical flaw in FortiOS and FortiProxy that could lead to remote code execution (RCE).

Tracked as CVE-2023-25610 (CVSS score of 9.3), the issue impacts the administrative interface of the affected products and can be exploited without authentication, either for code execution or to cause a denial-of-service (DoS) condition, via crafted requests.

The bug impacts FortiOS versions 7.2.0 through 7.2.3, 7.0.0 – 7.0.9, 6.4.0 – 6.4.11, 6.2.0 – 6.2.12, and all 6.0 versions. FortiProxy versions 7.2.0 – 7.2.2, 7.0.0 – 7.0.8, 2.0.0 – 2.0.11, all 1.2 versions, and all 1.1 versions are also impacted.

However, Fortinet also notes that on roughly 50 FortiGate and FortiWiFi appliances, the vulnerability can only be exploited to cause a DoS condition.

Users are advised to update to FortiOS version 7.4.0 or above, 7.2.4 or above, 7.0.10 or above, 6.4.12 or above, and 6.2.13 or above, FortiProxy version 7.2.3 or above, 7.0.9 or above, and 2.0.12 or above, and FortiOS-6K7K version 7.0.10 or above, 6.4.12 or above, and 6.2.13 or above.

As a workaround, administrators can disable the HTTP/HTTPS administrative interface or set IP address restrictions for accessing the interface.

Fortinet says it is not aware of this vulnerability being exploited in malicious attacks, but it’s not uncommon for such flaws to be exploited by threat actors shortly after the release of a patch. 

This week, the cybersecurity firm also announced patches for high-severity bugs in FortiOS, FortiProxy, FortiNAC, FortiSOAR, and FortiWeb.

Successful exploitation of these flaws could allow an attacker to escalate privileges, perform a cross-site scripting (XSS) attack, execute arbitrary commands as root, perform unauthorized actions, and execute unauthorized code.

Patches were also released for several medium-severity and low-severity issues impacting products such as FortiAnalyzer, FortiManager, FortiPortal, FortiSwitch, FortiOS, FortiProxy, FortiRecorder, FortiWeb, FortiAuthenticator, FortiDeceptor, and FortiMail.

Additional information on the addressed vulnerabilities can be found on Fortinet’s PSIRT advisories page.

Related:Fortinet Shares Clarifications on Exploitation of FortiNAC Vulnerability

Related: Chinese Hackers Exploited Fortinet VPN Vulnerability as Zero-Day

Related: Fortinet Says Recently Patched Vulnerability Exploited to Hack Governments

https://www.securityweek.com/fortinet-patches-critical-unauthenticated-rce-vulnerability-in-fortios/




White House Cybersecurity Strategy Stresses Software Safety

An ambitious and wide-ranging White House cybersecurity plan released Thursday calls for bolstering protections on critical sectors and making software companies legally liable when their products don’t meet basic standards. The strategy document promises to use “all instruments of national power” to pre-empt cyberattacks.

The Democratic administration also said it would work to “impose robust and clear limits” on private sector data collection, including of geolocation and health information.

“We still have a long way to go before every American feels confident that cyberspace is safe for them,” acting national cyber director Kemba Walden said during an online forum on Thursday. “We expect school districts to go toe-to-toe with transnational criminal organizations largely by themselves. This isn’t just unfair. It’s ineffective.”

The strategy largely codifies work already underway during the last two years following a spate of high-profile ransomware attacks on critical infrastructure. A 2021 attack on a major fuel pipeline caused panic at the pump, resulting in an East Coast fuel shortage, and other damaging attacks made cybersecurity a national priority. Russia’s invasion of Ukraine compounded those concerns.

The 35-page document lays the groundwork for better countering rising threats to government agencies, private industry, schools, hospitals and other vital infrastructure that are routinely breached. In the past few weeks, the FBI, U.S. Marshals Service and Dish Network were among the intrusion victims.

“The defense is hardly winning. Every few weeks someone gets hacked terribly,” said Edward Amoroso, CEO of the cybersecurity firm TAG Cyber.

He called the White House strategy largely aspirational. Its boldest initiatives — including stricter rules on breach reporting and software liability — are apt to meet resistance from business and Republicans in Congress.

Brandon Valeriano, former senior adviser to the federal government’s Cyberspace Solarium Commission, agreed.

“There’s a lot to like here. It just lacks a lot of specifics,” said Valeriano, a distinguished senior fellow at the Marine Corp. University. “They produce a document that speaks very much to regulation at a time when the United States is very much against regulation.”

The strategy’s data-collection component is also expected to meet stiff headwinds in Congress, though opinion polls say most Americans favor federal data privacy legislation.

In a new report, the tech data firm Forrester Research said state-sponsored cyberattacks rose nearly 100% between 2019 and 2022 and their nature changed, with a greater percentage now carried out for data destruction and financial theft. The threats are mostly from abroad: Russia-based cybercrooks and state-backed hackers from Russia, China, North Korea and Iran.

President Joe Biden’s administration has already imposed cybersecurity regulations on certain critical industry sectors, such as electric utilities, gas pipelines and nuclear facilities. The strategy calls for expanding them to other vital sectors.

In a statement accompanying the document, Biden says his administration is taking on the “systemic challenge that too much of the responsibility for cybersecurity has fallen on individual users and small organizations.” That will mean shifting legal liability onto software makers, holding companies rather than end users accountable.

As a nation, “we tend to devolve responsibility for cybersecurity downward. We ask individuals, small businesses and local governments to shoulder a significant burden for defending us all,” Walden said.

The White House wants to put greater responsibility on the software companies.

“Too many vendors ignore best practices for secure development, ship products with insecure default configurations or known vulnerabilities, and integrate third-party software of unvetted or unknown provenance,” the document says. That must change, it adds, stating that the White House will work with Congress and the private sector on legislation to establish liability.

The director of the Cybersecurity and Infrastructure Security Agency, Jen Easterly, drew an analogy in a speech Monday at Carnegie Mellon University to the automotive industry before consumer advocates led by Ralph Nader forced safety reforms, including seat belts and air bags: “The burden of safety should never fall solely upon the customer. Technology manufacturers must take ownership of the security outcomes for their customers.”

But Amoroso, the cybersecurity executive, called that comparison misguided because software is a different animal, inherently complex with hackers constantly finding ways to break it. The liability initiative is apt to get tied up in the courts as industry resists, he said. “If you are a cybersecurity lawyer this is manna from heaven.”

Asked if it was fair to make software companies liable in court for cyberattack damage, the trade association BSA — The Software Alliance said in a statement: “Cybersecurity is constantly evolving and providing incentives for companies to use best practices in secure software design and development would benefit the entire ecosystem.”

The group, whose members include Microsoft, Adobe, SAP, Oracle and Zoom, added: “We look forward to working with the administration and Congress on any proposed legislation to promote best practices.” Amoroso said he liked positive aspects of the strategy such as securing clean-energy technologies and bolstering the cybersecurity work force, currently short 700,000 workers nationally.

The document also calls for more aggressive efforts to pre-empt cyberattacks by drawing on military, law enforcement and diplomatic tools as well as help from the private sector. Such offensive operations, it says, must take place with “greater speed, scale, and frequency.”

Disruption of hostile cyberactivity through “defending forward” is already happening.

The FBI and U.S. Cyber Command now routinely engage cybercriminals and state-backed hackers in cyberspace, working with foreign partners to thwart ransomware operations and election interference in 2018 and 2020. The government has already deemed ransomware a national security threat and the document says it will continue to use methods such as “hacking the hackers” to combat it.

Related: A Deeper Dive Into Zero-Trust and Biden’s Cybersecurity Executive Order

https://www.securityweek.com/white-house-cybersecurity-strategy-stresses-software-safety/