網頁

2018年4月4日 星期三

Overnight Cybersecurity: Facebook says Cambridge Analytica had data on 87M users | Zuckerberg to face lawmakers next week | Trump mulling 'offensive' cyber strategy | White House email domains lack security tool

 
 
View in your browser
 
The Hill Cybersecurity
Facebook   Twitter   LinkedIn   Email
 
 

Welcome to OVERNIGHT CYBERSECURITY, your daily rundown of the biggest news in the world of hacking and data privacy. We're here to connect the dots as leaders in government, policy and industry try to counter the rise in cyber threats. What lies ahead for Congress, the administration and the latest company under siege? Whether you're a consumer, a techie or a D.C. lifer, we're here to give you ...

 

THE BIG STORIES: 

--FACEBOOK SAYS UP TO 87M IMPACTED BY CAMBRIDGE ANALYTICA BREACH: Facebook said on Wednesday that as many as 87 million people have been affected in the Cambridge Analytica data breach. The company previously estimated that the British research firm hired by the Trump campaign had improperly harvested data from around 50 million Facebook users. Facebook's new estimate came in a post outlining new steps it is taking to restrict third-parties' access to user data on its platform. As a part of the data policy changes, Facebook said that it will now delete Android users' call and text logs that are older than a year following outcry over the practice. The social media platform has been scrambling to temper criticism it has received following its disclosure that Cambridge Analytica improperly took user data and then did not delete the information after telling Facebook that it would.

To read more from our piece, click here.

 

--ZUCKERBERG TO TESTIFY ON APRIL 11: Facebook chief executive Mark Zuckerberg will testify before the House Energy and Commerce Committee later this month, lawmakers said on Wednesday. The Facebook CEO's testimony will address how the British research firm used by the Trump campaign, Cambridge Analytica, improperly harvested data from 50 million Facebook users. "This hearing will be an important opportunity to shed light on critical consumer data privacy issues and help all Americans better understand what happens to their personal information online," said Energy and Commerce Chairman Greg Walden (R-Ore.) and the committee's top Democrat, Rep. Frank Pallone Jr. (N.J.) in a statement. "We appreciate Mr. Zuckerberg's willingness to testify before the committee, and we look forward to him answering our questions on April 11th," they added. Facebook officials had previously briefed the Energy and Commerce Committee, as well as other congressional committees on the Cambridge Analytica breach, but Walden said that "many questions were unanswered."

To read more from our piece, click here.

 

--MORE FACEBOOK... NEW TERMS OF SERVICE: Facebook is rewriting its terms of service and data policy in an effort to make them more clear to users as the company faces scrutiny in the U.S. over its privacy practices and prepares for a new European Union law that will require more transparency with users. "These updates are about making things clearer," Facebook said Wednesday in a blog post. "We're not asking for new rights to collect, use or share your data on Facebook. We're also not changing any of the privacy choices you've made in the past." The revisions detail what information the company uses, what users consent to and how Facebook's advertising practices work. The updated policies also make clear how Facebook shares information across the brands it controls, like Instagram, WhatsApp and Messenger. "For example, we can suggest that you join a group on Facebook that includes people you follow on Instagram or communicate with using Messenger," reads the new data policy. Facebook and other internet companies are preparing themselves for a sweeping new data law in the EU that requires them to give users better control over their personal information. Under the new regulations, users will have the ability to easily adjust the permissions they grant to digital services.

To read more from our piece, click here.

 

A POLICY UPDATE: 

TRUMP MULLS OFFENSIVE CYBER STRATEGY: Director of National Intelligence Dan Coats on Wednesday indicated that the U.S. government is seriously considering adopting an offensive cyber warfare strategy.

When asked during a media breakfast in Washington, D.C., whether U.S. intelligence agencies should go on the offensive in terms of information warfare, Coats said such an idea is under "serious consideration" because the U.S. cannot constantly be playing defensive in the cyber space.

"I'm publicly onboard with the idea that you can't just play defense, you have to play offense. How we play offense, what kind of offense is under serious consideration," the cyber chief told reporters.

"Cyber falls under that grey zone of is this warfare or not warfare?" he continued in part. "In that grey zone -- I use the word 'attack.' I wanted people's attention that we have a cyber problem, a cyber issue that we need to deal with. It is affecting a lot of elements of our society and our economy."

His remarks come as longstanding frustrations continue to simmer among a bipartisan group of senators who say the federal government lacks a clear policy on how to respond if the U.S. faces a cyberattack -- a concern legislators raised during both the Obama and Trump administrations.

Over a dozen lawmakers across the aisle wrote to the Trump administration last month expressing a sense of urgency and urging officials to develop a comprehensive strategy to deter as well as adequately respond to malicious cyber behavior.

Coats, who has previously acknowledged a lack of a comprehensive U.S. cyber strategy, said new laws, policies and presidential directives may all be possible if the federal government does decide to adopt such a strategy.

"It could be all of the above, depending on what we feel we need in order to protect our self -- not only defensively, but we are not going to tolerate somebody using this method to attack our systems," he said.

While Coats did not provide a specific timeline for such a decision, he emphasized that the entire government is engaged on this matter.

"There is more going relative to this issue than I think has been reported," he said, calling it "one of our major challenges."

To read more from our piece, click here.

 

A REPORT IN FOCUS: 

WHITE HOUSE EMAIL DOMAINS LACK SECURITY TOOL: More than half of the email domains managed by the White House's Executive Office of the President (EOP) have not yet implemented an email security tool designed to protect users from phishing attacks, according to new research.

The Department of Homeland Security (DHS) has required that federal agencies and departments operating .gov domains implement the tool, known as the Domain-based Message Authentication, Reporting, and Conformance (DMARC).

DMARC enables organizations to flag potentially fraudulent emails that fail authentication tests or, when stronger settings are turned on, send the messages directly to a recipient's spam folder or block them entirely.

According to the Global Cyber Alliance, only one of the 26 email domains managed by the EOP -- Max.gov -- has implemented the highest DMARC setting.

Seven EOP domains, including WhiteHouse.gov and EOP.gov, have implemented the tool on its lowest security setting, while the remaining 18 have yet to deploy DMARC at all.

Homeland Security announced last year that it would require federal agencies to implement DMARC, setting a mid-January deadline for agencies to comply with the directive.

The binding operational directive issued in October applies to all federal and executive branch .gov domains, with the exception of those used for national security, military or intelligence purposes.

To read more from our piece, click here.

 

A LIGHTER, COMPLETELY NON-CYBER, CLICK: 
"Even monkeys need a spa day." (AFP)

 

WHAT'S IN THE SPOTLIGHT: 

CHINESE CYBER CAMPAIGNS: Chinese espionage activity is posing a challenge for the Trump administration as it seeks to crack down on China for allegedly unfair trade practices, including persistent cyber intrusions targeting U.S. businesses.

While China has largely stopped hacking into U.S. companies to steal intellectual property in accordance with a 2015 Obama-era pact, security experts say Beijing's spies have continued to break into U.S. networks to advance China's economic and national security ambitions--testing the limits of the deal.

Chinese hackers continue to steal information from U.S. defense contractors, likely to gain a strategic edge over the U.S. military. There has also been a surge of new activity of Chinese hackers targeting Western think tanks, U.S. law firms and the U.S. maritime industry.

Meanwhile, the security community is warning that some of President Trump's recent decisions regarding China, including moves to slap tariffs on Beijing and block Chinese acquisitions of U.S. firms, could trigger potential blowback in cyberspace.

"We're warning some of our high tech customers that this 'honeymoon' period they've had for the last couple years could be over if the trade conflict between Beijing and Washington intensifies and Chinese companies are no longer able to acquire their U.S. counterparts," said Christopher Porter, chief intelligence strategist at FireEye.

Chinese cyber activity has long posed a challenge for the U.S. government, which has sought to crack down on Chinese efforts to break into U.S. corporate networks for commercial gain. China is also widely suspected in the massive Office of Personnel Management (OPM) breach that exposed personal data on over 20 million federal workers, though Beijing's government has denied any involvement.

In September 2015, then-President Obama and Chinese President Xi Jinping reached a watershed agreement to stop supporting cyber-enabled intellectual property theft against businesses in their respective borders.

Since the agreement, security experts have observed a significant decline in Chinese cyber-enabled intellectual property theft from U.S. companies, and the pact has been largely cheered as a diplomatic accomplishment. Indeed, the Trump administration reaffirmed the cyber pact with Beijing in October.

But last month, Trump accused China of continuing to conduct and support "unauthorized intrusions into, and theft from" U.S. company networks when announcing new tariffs on China -- raising the specter that Beijing may have run afoul of the agreement. On Wednesday, Trump said intellectual property theft has cost the U.S. economy $300 billion annually.

Experts say that Chinese hackers, widely viewed as among the most sophisticated, have shifted their operations so as not to explicitly violate the agreement while still maintaining a presence in U.S. networks.

Porter said that FireEye, which monitors more than two-dozen groups linked to the Chinese government, has seen espionage activity continue against U.S. firms, including those producing sensitive military technology like satellite navigation systems and semiconductors.

"We do see these same Chinese groups aggressively going after the U.S. private sector," said Porter. "They are collecting confidential business information, it's just the intellectual property theft that has been stopped."

In March, FireEye revealed that Chinese hackers have stepped up attacks on the U.S. maritime and engineering targets. While the espionage group has not been definitively linked to the Chinese government, the hackers appeared to be after information on South China Sea issues, which would be valuable to the Chinese navy.

"In the end of 2016 and beginning of 2017, we saw an uptick in offensive operations against U.S. targets by China," said Adam Meyers, vice president of intelligence at CrowdStrike.

Meyers also told The Hill that the firm has seen a large increase in activity targeting U.S. law firms since June 2017.

To read more of our piece, click here.

 

IN CASE YOU MISSED IT:

Links from our blog, The Hill, and around the Web.

Google employees urge company to drop Pentagon A.I. work. (The Hill)

Tech rivalries spill into Washington. (The Hill)

Several White House domains lack anti-phishing tool: research. (The Hill)

OP-ED: When it comes to online data, the feds appear to believe in privacy for some, but not all. (The Hill)

OP-ED: A ransomware attack brought Atlanta to its knees -- and no one seems to care. (The Hill)

Hackers change display of multiple Israeli sites to read: 'Jerusalem is the capital of Palestine.' (The Times of Israel)

U.S. Air Force shifting towards outsourcing IT operations in effort to boost cybersecurity workforce. (Cyberscoop)

The ACLU has eight questions for Mark Zuckerberg. (ACLU)

Judge says Massachusetts can sue Equifax. (Reuters)

The mysterious hacking group behind major recent breaches. (Wired)

New survey says hiring gamers could fill cybersecurity workforce gap. (McAfee)

New report details latest global cyber trends like workforce skills gap, targeted organizations. (FireEye)

New America offers policymakers some election security advice. (New America)

If you'd like to receive our newsletter in your inbox, please sign up here.

 
 

THE HILL EVENTS

Leadership in Action: The Hill's Newsmaker Series

Join The Hill on April 11 for Leadership in Action: The Hill's Newsmaker Series. Sen. Lamar Alexander (R-Tenn.), Rep. Nanette Barragán (D-Calif.) and Rep. Steny Hoyer (D-Md.) will sit down with Editor-in-Chief Bob Cusack to discuss congressional values, diversity and bipartisanship. RSVP today.

Latinos in College: Closing the Graduation Gap

On April 17, The Hill will gather lawmakers, university presidents and education experts for Latinos in College: Closing the Graduation Gap. Conversations will address ways to boost Hispanic college completion rates nationwide. RSVP today.

 
 
 
 
 
  Facebook   Twitter   LinkedIn   Email  
 
Did a friend forward you this email?
Sign up for Cybersecurity Newsletters  
 
 
 
 
 
THE HILL
 
Privacy Policy  |  Manage Subscriptions  |  Unsubscribe  |  Email to a friend  |  Sign Up for Other Newsletters
 
The Hill 1625 K Street, NW 9th Floor, Washington DC 20006
©2016 Capitol Hill Publishing Corp., a subsidiary of News Communications, Inc.
 
 

SearchCap: Bing Ads extensions, Apple hires Google exec & local image bug

 
 
Featured story
 

In big win, Apple hires Google AI chief John Giannandrea away from Google

 

Apr 4, 2018 by Greg Sterling

Apple must succeed in AI if it is to remain competitive with rivals.

 
From Search Engine Land
 
7 ways to turn a webinar into a stream of link-attracting content
  Apr 4, 2018 by Jordan Kasteler

Contributor Jordan Kasteler explains how to use webinars you've created to develop new content and become a marketing and link-building machine your competitors can't keep up with.

 
Maya Angelou Google doodle features Oprah Winfrey, Laverne Cox & others reciting her poem, 'Still I Rise'
  Apr 4, 2018 by Amy Gesenhues

Today would have been Dr. Angelou's 90th birthday.

 
Google local knowledge panel profile images are not loading in search
  Apr 4, 2018 by Barry Schwartz

Broken images in the local Google results seem to be caused by a bug.

 
Bing Ads launches price extensions
  Apr 4, 2018 by Ginny Marvin

Price extensions are available in the US and rolling out to international markets this month.

 
Updated: Google's Ben Gomes expands role to head all of search as John Giannandrea moves to Apple to head AI
  Apr 3, 2018 by Michelle Robbins

Role previously held by John Giannandrea to be split between Jeff Dean and Ben Gomes

From Marketing Land
 
Update these 3 organizational buzzwords to shift perceptions
  Apr 4, 2018 by Matt Umbro

Contributor Matt Umbro believes you can improve the way you think about and attack challenges by changing the way you talk about them.

 
Facebook CEO Mark Zuckerberg will testify before Congress next week
  Apr 4, 2018 by Robin Kurzer

The social media company and its CEO continue to face increased scrutiny in the wake of the Facebook/Cambridge Analytica debacle.

 
Who's storming the stage at MarTech?
  Apr 4, 2018 by Marketing Land

L'Oréal. The New York Times. Verizon. Aetna. Weight Watchers. Netflix. Airbnb. What do they have in common? They'll all be sharing their experiences from the intersection of marketing, technology, and management at MarTech, April 23-25 in San Jose. Join them and thousands of other members of your marketing technology tribe for an inspiring experience.

 
Pinterest's head of ad products exits company less than 6 months after taking over ad business
  Apr 4, 2018 by Amy Gesenhues

After less than a year at Pinterest, Jon Alferness is no longer with the company. He had taken over the site's ad products in December after Tim Kendall left.

 
What mobile marketers really need to know about deep linking
  Apr 4, 2018 by Shani Rosenfelder

Contributor Shani Rosenfelder explains the benefits of deep linking and expresses surprise that the tactic is so infrequently used.

 
Smart marketing still hinges on humanity, not technology
  Apr 4, 2018 by Mike Sands

As exciting as technological developments may be, contributor Mike Sands urges marketers to keep their eyes on their customers.

 
Facebook CEO Mark Zuckerberg says the company does not plan to apply GDPR globally
  Apr 4, 2018 by Robin Kurzer

The news comes despite a January announcement of a global privacy center. The beleagured CEO says the social network "wanted to extend privacy guarantees worldwide in spirit."

 
Adobe rains down announcements for its Experience Cloud
  Apr 4, 2018 by Barry Levine

At the Adobe Summit last week: a new unified customer profile, the general launch of the Device Co-Op, analytics for streaming audio and new AI services

 
Facebook now displaying related stories & share info for articles as part of ongoing News Feed test
  Apr 3, 2018 by Amy Gesenhues

Facebook's News Feed test, launched last October, expands to give users more context around news headlines.

 
#LookUp: The most important view for high-impact B2B marketers (with inspiration from Stephen Hawking)
  Apr 3, 2018 by Scott Vaughan

Contributor Scott Vaughan explores some lessons taught by the influential cosmologist and explains how these ideas can be applied to your work in marketing.


 
 

Only elite marketers attend Search Engine Land's SMX Advanced for expert SEO and SEM tactics: June 11-13, 2018

Attend SMX Advanced for actionable, expert-level SEO and SEM tactics. At SMX Advanced, we do not slow down to cover the basics. Don't miss this once a year opportunity to attend the only truly advanced search marketing conference in the nation. Join us in Seattle for an unrivaled professional experience. View pass options and register today!

 

Connect with us on:

Get the Search Engine Land App:

Like what you see? Check out Search Engine Land's other email newsletters here.
News | SEO | SEM | Local | Retail | Social
 
This email was sent to tweatsho.email004@blogger.com. Click here to unsubscribe or manage your subscriptions.
 
This email was sent by: Search Engine Land - a Third Door Media, Inc. publication with headquarters at 279 Newtown Tpke. Redding, CT 06896 USA