CISA boss swatted as bogus emergency calls on the rise The Register

CISA Director Jen Easterly has confirmed she was the subject of a swatting attempt on December 30 after a bogus report of a shooting at her home.
One of the most troubling trends we have seen in recent years has been the harassment of public officials across the political spectrum, including extreme incidents involving swatting and direct personal threats.
These incidents pose a serious risk to the individuals, their families, and in the case of swatting, to the law enforcement officers responding to the situation.
While my own experience was certainly harrowing, it was unfortunately not unique.
In particular, several of our nation's election officials have also been targeted with this type of harassment and other threats of violence.
The men and women of both parties who run our elections work tirelessly to ensure their security and integrity.
We at CISA, along with our partners, will continue to support these election heroes as they work every day to safeguard our most sacred democratic process.
Swatting - calling in a hoax an emergency report for a serious crime to bring heavily armed law enforcement officers onto the scene can sometimes turn deadly, as was the case with a Kansas man who was killed by police in 2017 when a California gamer made a fake emergency call after a dispute over a Call of Duty session.
Over the last few months, criminals have also been using this tactic in extortion attempts and trying to force victim organizations, specifically hospitals and medical clinics, to pay ransom demand by swatting their patients.
The Record first reported that police in Arlington County, Virginia, were investigating a 911 call on the evening of December 30 that falsely claimed a shooting had occurred inside a home on Easterly's block.
The CISA declined to answer questions about who was behind the crime or why Easterly was targeted.
Several politicians and election officials have been targeted by swatting attempts over the last couple months as the US gears up for a contentious 2024 presidential election.
These include Maine Secretary of State Shenna Bellows, following her decision that Donald Trump was ineligible to be on her state's primary ballot.
Other calls and threats have been made against judges overseeing cases against Trump; Democratic and Republican politicians; a prosecutor; the White House; and various state capitol buildings.


This Cyber News was published on www.theregister.com. Publication date: Wed, 24 Jan 2024 01:44:04 +0000


Cyber News related to CISA boss swatted as bogus emergency calls on the rise The Register

CISA boss swatted as bogus emergency calls on the rise The Register - CISA Director Jen Easterly has confirmed she was the subject of a swatting attempt on December 30 after a bogus report of a shooting at her home. One of the most troubling trends we have seen in recent years has been the harassment of public ...
2 years ago Theregister.com
CISA adds Check Point Quantum Security Gateways and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog - CISA adds Apache Flink flaw to its Known Exploited Vulnerabilities catalog. CISA adds D-Link DIR router flaws to its Known Exploited Vulnerabilities catalog. CISA adds Google Chrome zero-days to its Known Exploited Vulnerabilities catalog. CISA adds ...
1 year ago Securityaffairs.com
Securing Tomorrow: A Recap of CISA's Cyber Resilient 911 Symposium - CISA's Emergency Communications Division spearheaded the Cyber Resilient 911 Program's fourth regional symposium, which included CISA Regions 5 and 7. Among the attendees were state 911 administrators, representatives from 911 centers, IT/cyber ...
1 year ago Cisa.gov
CISA pledges to resolve issues with threat sharing system after watchdog report - On Friday, the Department of Homeland Security’s Office of the Inspector General published a report on Automated Indicator Sharing (AIS) — which was used to spread cyber threat intelligence and was mandated as part of a 2015 law. The nation’s ...
1 year ago Therecord.media
CVE-2013-0135 - Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) ...
8 years ago
CVE-2021-47465 - In the Linux kernel, the following vulnerability has been resolved: KVM: PPC: Book3S HV: Fix stack handling in idle_kvm_start_guest() In commit 10d91611f426 ("powerpc/64s: Reimplement book3s idle code in C") kvm_start_guest() became ...
1 year ago Tenable.com
Enabling Threat-Informed Cybersecurity: Evolving CISA's Approach to Cyber Threat Information Sharing - One of CISA's most important and enduring roles is providing timely and actionable cybersecurity information to our partners across the country. Nearly a decade ago, CISA stood up our Automated Indicator Sharing, or AIS, program to widely exchange ...
2 years ago Cisa.gov
CISA's OT Attack Response Team Understaffed: GAO - The US Government Accountability Office has conducted a study focusing on the operational technology cybersecurity products and services offered by CISA and found that some of the security agency's teams are understaffed. OT environments continue to ...
1 year ago Securityweek.com
CISA Hosts Second Cyber Resilient 911 Symposium - CISA's Emergency Communications Division led the Cyber Resilient 911 Program's second regional symposium in the Southeast, which included CISA regions 4 and 6 as well as Delaware, Puerto Rico, West Virginia, and the U.S. Virgin Islands. Attendees ...
2 years ago Cisa.gov
CEO arranged his own cybersecurity, with predictable results The Register - On Call It's the last Friday of 2023, but because the need for tech support never goes away neither does On Call, The Register's Friday column in which readers share their tales of being asked to fix the unfeasible, in circumstances that are often ...
2 years ago Go.theregister.com
CVE-2017-17713 - Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp ...
8 years ago
CVE-2017-17714 - Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, ...
8 years ago
Cybersecurity Performance Goals: Assessing How CPGs Help Organizations Reduce Cyber Risk - In October 2022, CISA released the Cybersecurity Performance Goals to help organizations of all sizes and at all levels of cyber maturity become confident in their cybersecurity posture and reduce business risk. Earlier this summer, CISA outlined ...
2 years ago Cisa.gov
CVE-2023-52780 - In the Linux kernel, the following vulnerability has been resolved: net: mvneta: fix calls to page_pool_get_stats Calling page_pool_get_stats in the mvneta driver without checks leads to kernel crashes. First the page pool is only available if the bm ...
1 year ago Tenable.com
CVE-2024-47716 - In the Linux kernel, the following vulnerability has been resolved: ARM: 9410/1: vfp: Use asm volatile in fmrx/fmxr macros Floating point instructions in userspace can crash some arm kernels built with clang/LLD 17.0.6: BUG: unsupported FP ...
1 year ago Tenable.com
CISA Announces the FY 2024 Rural Emergency Medical Communications Demonstration Project (REMCDP) Cooperative Agreement Recipient | CISA - Earlier this year, the Cybersecurity and Infrastructure Security Agency (CISA) reestablished the Rural Emergency Medical Communications Demonstration Project (REMCDP) to work with a community to examine communications barriers and identify solutions ...
1 year ago Cisa.gov
CVE-2023-52911 - In the Linux kernel, the following vulnerability has been resolved: ...
1 year ago
CISA Issues Emergency Directive Requiring Federal Agencies to Mitigate Ivanti Connect Secure and Policy Secure Vulnerabilities - WASHINGTON - Today, the Cybersecurity and Infrastructure Security Agency issued Emergency Directive 24-01 in response to observed widespread and active exploitation of vulnerabilities in Ivanti Connect Secure and Ivanti Policy Secure appliances by ...
2 years ago Cisa.gov CVE-2023-46805 CVE-2024-21887
CISA reveals how fed agency succumbed to ColdFusion attacks The Register - CISA has released details about a federal agency that recently had at least two public-facing servers compromised by attackers exploiting a critical Adobe ColdFusion vulnerability. The vulnerability, tracked as CVE-2023-26360, was disclosed in March ...
2 years ago Go.theregister.com CVE-2023-26360
APT36 Attacking BOSS Linux Systems With Weaponized ZIP Files to Steal Sensitive Data - Data collection capabilities include the “github.com/kbinani/screenshot” library for desktop capture and main.sendResponse function for exfiltrating various data types, including files, command outputs, and system information. The ...
8 months ago Cybersecuritynews.com
EuroTel ETL3100 Radio Transmitter - RISK EVALUATION. Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to gain full access to the system, disclose sensitive information, or access hidden resources. EuroTel ETL3100 versions v01c01 and v01x37 does ...
2 years ago Cisa.gov CVE-2023-6928 CVE-2023-6929 CVE-2023-6930
CISA confirms compromise of its Ivanti systems - CISA confirmed two of its internal systems were breached by a threat actor that exploited flaws in Ivanti products used by the U.S. cybersecurity agency. Ivanti on Jan. 10 disclosed two zero-day vulnerabilities that were under exploitation by a ...
2 years ago Techtarget.com CVE-2023-46805 CVE-2024-21887
Optigo Networks ONS-S8 Spectra Aggregation Switch | CISA - CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial ...
1 year ago Cisa.gov CVE-2024-41925 CVE-2024-45367
Biden's budget proposal boosts CISA's funding to $3b The Register - US President Joe Biden has asked Congress to approve an extra $103 million in funding for the Cybersecurity and Infrastructure Security Agency, bringing CISA's total budget to $3 billion. Biden proposed his $7.3 trillion spending plan for fiscal year ...
1 year ago Go.theregister.com
CISA Issues Emergency Directive on Ivanti Zero-Days - The US government's cybersecurity agency CISA is ramping up the pressure on organizations to urgently mitigate a pair of critical vulnerabilities in Ivanti Connect Secure VPN devices. The CISA missive sets strict deadlines for Federal Civilian ...
2 years ago Securityweek.com CVE-2023-46805 CVE-2024-21887