US and EU infosec bodies sign intel-sharing pact The Register

The US Cybersecurity and Infrastructure Security Agency has signed a working arrangement with its EU counterparts to increase cross-border information sharing and more to tackle criminals.
The European Union Agency for Cybersecurity said today the arrangement cements the existing tie-up and opens doors for possible new types of cooperations.
The exchange of best practices will also apply to legislation as both the US and EU continue to embed contemporary cybersecurity principles in law, such as the EU's efforts with the NIS2 Directive and Cyber Resilience Act.
Approaches to tech legislation and regulation have not always aligned between the US and EU, with data protection and more recently AI providing two of the more obvious examples.
A more joined-up approach to cybersecurity is shared among all corners of the industry and one both the US and EU have made strides in developing over the years.
That unified approach was again on display in today's announcement, which promises a more systematic process for sharing threat intelligence between the two agencies - a practice that's long been championed in the industry as threats continue to affect organizations across the world.
Efforts to build frameworks for alliances across the industry include agreements both between national security agencies like CISA and ENISA, and with private sector organizations too.
CISA has its Joint Cyber Defense Collaborative, for example.
The public-private group aims to develop high degrees of threat awareness and preparedness by using insights from different types of organizations.
It also has established cybersecurity deals with ENISA, and the equivalent agencies from the Five Eyes and Quad diplomatic alliances.
The understanding is that an increased awareness of the threat landscape, grown through sharing information from as many reliable sources as possible, will hasten detection and mitigation efforts.
The working agreement will also see the US participate more as a third country in EU-wide cybersecurity training exercises, as well as the promotion of awareness tools and programs.
Also announced on Thursday was the adoption of the draft report for the EU's Cyber Solidarity Act, another legislative proposal making its way through European Parliament that aims to strengthen the bloc's defensive capabilities.
It too is rooted in the idea that alliances equate to better cyber defenses and among its key objectives is the establishment of a European Cyber Shield - a network of all national security operation centers and cross-border SOCs to improve the detection and analysis of threats.
The threat intelligence analyzed and shared between all nations carries the ambition of improving the response times to cyberattacks.
If an attack is observed in one nation, the others will be alerted and work together to develop mitigations that will limit the attack's effectiveness.
With the report adopted by the committee, a decision will be made in mid-December during a plenary session in Strasbourg as to when trilogue discussions begin.


This Cyber News was published on www.theregister.com. Publication date: Fri, 08 Dec 2023 00:44:05 +0000


Cyber News related to US and EU infosec bodies sign intel-sharing pact The Register

Intel out-of-band patch addresses privilege escalation flaw The Register - Intel on Tuesday issued an out-of-band security update to address a privilege escalation vulnerability in recent server and personal computer chips. The flaw, designated INTEL-SA-00950 and given a CVSS 3.0 score of 8.8 out of 10, affects Intel ...
7 months ago Theregister.com
Building a Sustainable Data Ecosystem - Finally, I outline future research and policy refinement directions, advocating for a collaborative and responsible approach to building a sustainable data ecosystem in generative AI. In recent years, generative AI has emerged as a transformative ...
3 months ago Feeds.dzone.com
Intel knew AVX chips were insecure and did nothing - Intel has been sued by a handful of PC buyers who claim the x86 goliath failed to act when informed five years ago about faulty chip instructions that allowed the recent Downfall vulnerability, and during that period sold billions of insecure chips. ...
7 months ago Theregister.com
AuditBoard enhances InfoSec Solutions to reduce compliance fatigue across the organization - AuditBoard announced powerful enhancements for its InfoSec Solutions to help organizations meet their IT compliance, cyber risk, and vendor risk management needs in the face of rising risks and increased regulatory requirements. With these new ...
1 month ago Helpnetsecurity.com
US and EU infosec bodies sign intel-sharing pact The Register - The US Cybersecurity and Infrastructure Security Agency has signed a working arrangement with its EU counterparts to increase cross-border information sharing and more to tackle criminals. The European Union Agency for Cybersecurity said today the ...
6 months ago Theregister.com
CVE-2013-0135 - Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) ...
6 years ago
CVE-2022-37327 - Improper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, Intel(R) NUC 11 Compute Element, Intel(R) NUC ...
1 year ago
CVE-2017-17713 - Trape before 2017-11-05 has SQL injection via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp ...
6 years ago
CVE-2017-17714 - Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, ...
6 years ago
Israel $3.2bn Grant For Intel's $25 Billion Chip Factory - Intel to make its largest ever single investment in Israel, with a $25 billion chip-making factory in the south of the country. Intel and the Israeli government have confirmed plans to construct a $25 billion chip-making factory in Southern Israel. ...
6 months ago Silicon.co.uk
CVE-2023-52780 - In the Linux kernel, the following vulnerability has been resolved: net: mvneta: fix calls to page_pool_get_stats Calling page_pool_get_stats in the mvneta driver without checks leads to kernel crashes. First the page pool is only available if the bm ...
1 month ago Tenable.com
Keeper Security Unveils Granular Sharing Enforcements for Easier Compliance - Keeper Security has announced Granular Sharing Enforcements for all products in the Keeper® platform. Granular Sharing enables administrators to enforce detailed creating and sharing permissions at the user level. By implementing these permissions, ...
5 months ago Itsecurityguru.org
Infosec pros sound off on usefulness of higher education The Register - Half of infosec professionals polled by Kaspersky said any cybersecurity knowledge they picked up from their higher education is at best somewhat useful for doing their day jobs. On the other hand, half said the know-how was at least very useful. The ...
5 months ago Go.theregister.com
Infosec pros sound off on usefulness of higher education The Register - Half of infosec professionals polled by Kaspersky said any cybersecurity knowledge they picked up from their higher education is at best somewhat useful for doing their day jobs. On the other hand, half said the know-how was at least very useful. The ...
4 months ago Theregister.com
Intel Discloses Max Severity Bug in Its AI Model Compression Software - Intel has disclosed a maximum severity vulnerability in some versions of its Intel Neural Compressor software for AI model compression. The bug, designated as CVE-2024-22476, provides an unauthenticated attacker with a way to execute arbitrary code ...
1 month ago Darkreading.com
CVE-2017-5682 - Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, ...
4 years ago
What is Certified information Security Manager? Definition from SearchSecurity - Certified Information Security Manager is an advanced certification that indicates that an individual possesses the knowledge and experience required to develop and manage an enterprise information security program. CISM is offered by ISACA, a ...
3 months ago Techtarget.com
Intel Spins Off Enterprise Generative AI Deployment Firm Articul8 - Intel and the global investment firm DigitalBridge Group have formed an independent generative AI software stack company, Articul8 AI, Inc.; Intel announced the new company on Jan. 3. Articul8 will work with Intel and provide solutions for ...
6 months ago Techrepublic.com
CVE-2021-32629 - Cranelift is an open-source code generator maintained by Bytecode Alliance. It translates a target-independent intermediate representation into executable machine code. There is a bug in 0.73 of the Cranelift x64 backend that can create a scenario ...
1 year ago
Intel Spins Out AI Firm Articul8 - AI software developed at Intel is being spun off into independent firm Articul8 AI, with investment firm backing. Intel had been investing heavily into the AI field as it sought to take the fight to AI chip market leader Nvidia, amidst a boom in the ...
6 months ago Silicon.co.uk
Netflix Fails to Crack Down on Password Sharing Restrictions - As much as Netflix account holders were dreading the day the company finally cracked down on password sharing, the streaming giants first taste of what it has in store for users was both confusing and concerning. Folks online were dumbfounded by some ...
1 year ago Packetstormsecurity.com
Chipmaker Patch Tuesday: Intel, AMD Address New Microarchitectural Vulnerabilities - Chipmakers Intel and AMD have published 10 new security advisories this Patch Tuesday to inform customers about vulnerabilities impacting their products. Intel published eight new advisories, including two that describe high-severity vulnerabilities. ...
3 months ago Securityweek.com
Making the Law Accessible in Europe and the USA - Earlier this month, the European Union Court of Justice ruled that harmonized standards are a part of EU law, and thus must be accessible to EU citizens and residents free of charge. While it might seem like common sense that the laws that govern us ...
3 months ago Eff.org
Enabling Threat-Informed Cybersecurity: Evolving CISA's Approach to Cyber Threat Information Sharing - One of CISA's most important and enduring roles is providing timely and actionable cybersecurity information to our partners across the country. Nearly a decade ago, CISA stood up our Automated Indicator Sharing, or AIS, program to widely exchange ...
6 months ago Cisa.gov
New Relic warns customers it's experienced a cyber incident The Register - Web tracking and analytics outfit New Relic has issued a scanty security advisory warning customers it has experienced a scary cyber something. "We value our New Relic community and want to make our customers aware of a recent cyber security incident ...
7 months ago Theregister.com

Latest Cyber News


Cyber Trends (last 7 days)


Trending Cyber News (last 7 days)