Emergency Directive by the Cybersecurity and Infrastructure Security Agency Puts Pentagon on Alert
Pentagon on Tuesday reportedly ordered the emergency shutdown of a classified internal communications network, three Defense Department sources confirmed. The shutdown comes amid recent revelations that other federal agencies, including the NSA, Department of Homeland Security, were breached. DOD alerted employees that the SIPRNET system was being shut down in the late morning for emergency software updates, the sources told Just the News.
The Pentagon has not officially confirmed the report but DOD was on alert.
Acting Secretary of Defense Chris Miller said “looking at it right now, don’t have anything definitive.” He said the department was continue to assess the damage. “We have standard operating procedures in place that are very refined when an intrusion is noted or a potential intrusion so that we can monitor our networks and counteract anything,” Miller said.
CISA ISSUES EMERGENCY DIRECTIVE TO MITIGATE THE COMPROMISE OF SOLARWINDS ORION NETWORK MANAGEMENT PRODUCTS
Original release date: December 13, 2020 | Last revised: December 14, 2020
WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) tonight issued Emergency Directive 21-01, in response to a known compromise involving SolarWinds Orion products that are currently being exploited by malicious actors. This Emergency Directive calls on all federal civilian agencies to review their networks for indicators of compromise and disconnect or power down SolarWinds Orion products immediately.
“The compromise of SolarWinds’ Orion Network Management Products poses unacceptable risks to the security of federal networks,” said CISA Acting Director Brandon Wales. “Tonight’s directive is intended to mitigate potential compromises within federal civilian networks, and we urge all our partners—in the public and private sectors—to assess their exposure to this compromise and to secure their networks against any exploitation.”
This is the fifth Emergency Directive issued by CISA under the authorities granted by Congress in the Cybersecurity Act of 2015. All agencies operating SolarWinds products should provide a completion report to CISA by 12pm Eastern Standard Time on Monday December 14, 2020.
NSA ALERT:
Dec. 7, 2020 —
The National Security Agency (NSA) released a Cybersecurity Advisory today detailing how Russian state-sponsored actors have been exploiting a vulnerability in VMware® products to access protected data on affected systems. This advisory emphasizes the importance for National Security System (NSS), Department of Defense (DoD), and Defense Industrial Base (DIB) system administrators to apply vendor-provided patches to affected VMware® identity management products and provides further details on how to detect and mitigate compromised networks. Russian State-Sponsored Actors Exploiting Vulnerability in VMware® Workspace Infographic
The products affected by this vulnerability are the VMware® Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector, with specific product versions also identified in the VMware® advisory. The exploitation of this vulnerability first requires that a malicious actor have access to the management interface of the device. This access can allow attackers to forge security assertion markup language (SAML) credentials to send seemingly authentic requests to gain access to protected data.
NSA strongly recommends that NSS, DoD, and DIB system administrators apply the vendor-issued patch as soon as possible. If a compromise is suspected, check server logs and authentication server configurations as well as applying the product update. In the event that an immediate patch is not possible, system administrators should apply mitigations detailed in the advisory to help reduce risk of exploitation/compromise/attack.
For a quick summary on how you can take action, take a look at our infographic.