US and EU infosec bodies sign intel-sharing pact The Register

The US Cybersecurity and Infrastructure Security Agency has signed a working arrangement with its EU counterparts to increase cross-border information sharing and more to tackle criminals.
The European Union Agency for Cybersecurity said today the arrangement cements the existing tie-up and opens doors for possible new types of cooperations.
The exchange of best practices will also apply to legislation as both the US and EU continue to embed contemporary cybersecurity principles in law, such as the EU's efforts with the NIS2 Directive and Cyber Resilience Act.
Approaches to tech legislation and regulation have not always aligned between the US and EU, with data protection and more recently AI providing two of the more obvious examples.
A more joined-up approach to cybersecurity is shared among all corners of the industry and one both the US and EU have made strides in developing over the years.
That unified approach was again on display in today's announcement, which promises a more systematic process for sharing threat intelligence between the two agencies - a practice that's long been championed in the industry as threats continue to affect organizations across the world.
Efforts to build frameworks for alliances across the industry include agreements both between national security agencies like CISA and ENISA, and with private sector organizations too.
CISA has its Joint Cyber Defense Collaborative, for example.
The public-private group aims to develop high degrees of threat awareness and preparedness by using insights from different types of organizations.
It also has established cybersecurity deals with ENISA, and the equivalent agencies from the Five Eyes and Quad diplomatic alliances.
The understanding is that an increased awareness of the threat landscape, grown through sharing information from as many reliable sources as possible, will hasten detection and mitigation efforts.
The working agreement will also see the US participate more as a third country in EU-wide cybersecurity training exercises, as well as the promotion of awareness tools and programs.
Also announced on Thursday was the adoption of the draft report for the EU's Cyber Solidarity Act, another legislative proposal making its way through European Parliament that aims to strengthen the bloc's defensive capabilities.
It too is rooted in the idea that alliances equate to better cyber defenses and among its key objectives is the establishment of a European Cyber Shield - a network of all national security operation centers and cross-border SOCs to improve the detection and analysis of threats.
The threat intelligence analyzed and shared between all nations carries the ambition of improving the response times to cyberattacks.
If an attack is observed in one nation, the others will be alerted and work together to develop mitigations that will limit the attack's effectiveness.
With the report adopted by the committee, a decision will be made in mid-December during a plenary session in Strasbourg as to when trilogue discussions begin.


This Cyber News was published on www.theregister.com. Publication date: Fri, 08 Dec 2023 00:44:05 +0000


Cyber News related to US and EU infosec bodies sign intel-sharing pact The Register

Intel out-of-band patch addresses privilege escalation flaw The Register - Intel on Tuesday issued an out-of-band security update to address a privilege escalation vulnerability in recent server and personal computer chips. The flaw, designated INTEL-SA-00950 and given a CVSS 3.0 score of 8.8 out of 10, affects Intel ...
1 year ago Theregister.com
UN cybercrime pact to be signed in Hanoi, raising hopes and concerns - The United Nations is set to sign a landmark cybercrime pact in Hanoi, aiming to enhance international cooperation against cyber threats. This agreement represents a significant step forward in global efforts to combat cybercrime, providing a ...
2 weeks ago Reuters.com
Intel knew AVX chips were insecure and did nothing - Intel has been sued by a handful of PC buyers who claim the x86 goliath failed to act when informed five years ago about faulty chip instructions that allowed the recent Downfall vulnerability, and during that period sold billions of insecure chips. ...
1 year ago Theregister.com
Building a Sustainable Data Ecosystem - Finally, I outline future research and policy refinement directions, advocating for a collaborative and responsible approach to building a sustainable data ecosystem in generative AI. In recent years, generative AI has emerged as a transformative ...
1 year ago Feeds.dzone.com
CVE-2013-0135 - Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) ...
8 years ago
US and EU infosec bodies sign intel-sharing pact The Register - The US Cybersecurity and Infrastructure Security Agency has signed a working arrangement with its EU counterparts to increase cross-border information sharing and more to tackle criminals. The European Union Agency for Cybersecurity said today the ...
1 year ago Theregister.com
CVE-2022-37327 - Improper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, Intel(R) NUC 11 Compute Element, Intel(R) NUC ...
2 years ago
CVE-2017-17713 - Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp ...
7 years ago
CVE-2017-17714 - Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, ...
7 years ago
AuditBoard enhances InfoSec Solutions to reduce compliance fatigue across the organization - AuditBoard announced powerful enhancements for its InfoSec Solutions to help organizations meet their IT compliance, cyber risk, and vendor risk management needs in the face of rising risks and increased regulatory requirements. With these new ...
1 year ago Helpnetsecurity.com
Israel $3.2bn Grant For Intel's $25 Billion Chip Factory - Intel to make its largest ever single investment in Israel, with a $25 billion chip-making factory in the south of the country. Intel and the Israeli government have confirmed plans to construct a $25 billion chip-making factory in Southern Israel. ...
1 year ago Silicon.co.uk
CVE-2024-47716 - In the Linux kernel, the following vulnerability has been resolved: ARM: 9410/1: vfp: Use asm volatile in fmrx/fmxr macros Floating point instructions in userspace can crash some arm kernels built with clang/LLD 17.0.6: BUG: unsupported FP ...
1 year ago Tenable.com
CVE-2023-52780 - In the Linux kernel, the following vulnerability has been resolved: net: mvneta: fix calls to page_pool_get_stats Calling page_pool_get_stats in the mvneta driver without checks leads to kernel crashes. First the page pool is only available if the bm ...
1 year ago Tenable.com
CVE-2023-52911 - In the Linux kernel, the following vulnerability has been resolved: ...
10 months ago
Intel Discloses Max Severity Bug in Its AI Model Compression Software - Intel has disclosed a maximum severity vulnerability in some versions of its Intel Neural Compressor software for AI model compression. The bug, designated as CVE-2024-22476, provides an unauthenticated attacker with a way to execute arbitrary code ...
1 year ago Darkreading.com CVE-2024-22476
CVE-2017-5682 - Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, ...
6 years ago
Keeper Security Unveils Granular Sharing Enforcements for Easier Compliance - Keeper Security has announced Granular Sharing Enforcements for all products in the Keeper® platform. Granular Sharing enables administrators to enforce detailed creating and sharing permissions at the user level. By implementing these permissions, ...
1 year ago Itsecurityguru.org
Intel Spins Off Enterprise Generative AI Deployment Firm Articul8 - Intel and the global investment firm DigitalBridge Group have formed an independent generative AI software stack company, Articul8 AI, Inc.; Intel announced the new company on Jan. 3. Articul8 will work with Intel and provide solutions for ...
1 year ago Techrepublic.com Cuba
Infosec pros sound off on usefulness of higher education The Register - Half of infosec professionals polled by Kaspersky said any cybersecurity knowledge they picked up from their higher education is at best somewhat useful for doing their day jobs. On the other hand, half said the know-how was at least very useful. The ...
1 year ago Go.theregister.com
Infosec pros sound off on usefulness of higher education The Register - Half of infosec professionals polled by Kaspersky said any cybersecurity knowledge they picked up from their higher education is at best somewhat useful for doing their day jobs. On the other hand, half said the know-how was at least very useful. The ...
1 year ago Theregister.com
CVE-2021-32629 - Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a scenario ...
2 years ago
Intel Spins Out AI Firm Articul8 - AI software developed at Intel is being spun off into independent firm Articul8 AI, with investment firm backing. Intel had been investing heavily into the AI field as it sought to take the fight to AI chip market leader Nvidia, amidst a boom in the ...
1 year ago Silicon.co.uk
CVE-2025-26603 - Vim is a greatly improved version of the good old UNIX editor Vi. Vim allows to redirect screen messages using the `:redir` ex command to register, variables and files. It also allows to show the contents of registers using the `:registers` or ...
8 months ago Tenable.com
CVE-2024-42253 - In the Linux kernel, the following vulnerability has been resolved: ...
10 months ago
CVE-2024-44937 - In the Linux kernel, the following vulnerability has been resolved: ...
10 months ago

Cyber Trends (last 7 days)