CISA joins forces with Women in CyberSecurity to break up the boy's club
- Reference: 1678710731
- News link: https://www.theregister.co.uk/2023/03/13/cisa_joins_forces_with_women/
- Source link:
The US department of Homeland Security agency and WiCyS signed a memorandum of understanding on Wednesday to help raise awareness of job opportunities for women in cybersecurity and build "a pipeline for the next generation of women" able to fill those roles, the agency [1]said .
Easterly, who was chosen by President Biden to head CISA in 2021, said that inspiring women and girls to join the cybersecurity field is one of her top priorities. Easterly [2]was a keynote speaker at WiCyS' 2022 annual conference, where she called for half of cybersecurity professionals to be women and underrepresented minorities by 2030. By most recent count, the number is just half that - around [3]a quarter of cybersecurity roles are occupied by women.
[4]
WiCyS was founded in 2014 through a National Science Foundation grant to Dr Ambareen Siraj from Tennessee Tech University to start WiCyS as a conference. By 2018 the group had grown enough to spin up its own nonprofit organization, and began offering other services to women in the security community, like a job board, professional affiliate opportunities, training assistant programs, apprenticeship placement services and more.
[5]
[6]
CISA said in its announcement of the partnership that one of its first joint initiatives will be CISA's participation in WiCyS' [7]mentorship program. Open to all WiCyS members, the nine-month program groups mentees into cohorts for virtual meetings with cybersecurity industry mentors, of whom CISA employees will presumably now be part. Last year, the program included 746 learners from entry to senior levels.
Interested students or potential mentors can enroll now, but the window closes on March 22.
[8]
Of the partnership, WiCyS executive director Lynn Dohm said CISAs goal of developing a stronger, more inclusive cybersecurity workforce aligns perfectly with her group's mission. "Our collaboration will ensure that more women and other under-represented groups will have the tools and resources to jumpstart their career in cyber and be supported throughout their journey," Dohm said.
This week's actionable items
As we noted a few weeks ago, we added this section to the weekly security roundup as a way to ensure The Register readers were aware of the critical vulnerabilities in a timely manner. We've expanded the section to also include some of the other smaller, but nonetheless actionable, security items of the week that didn't make it to print.
CISA caught five more known vulnerabilities being exploited in the wild this week, but only three of them were rated critical:
CVSS 8.5 - [9]CVE-2021-39144 : the XStream library is vulnerable to a RCE that could allow a remote attacker to manipulate the processed input stream to execute commands as the host.
CVSS 8.8 - [10]CVE-2022-33891 : When ACLs are enabled in Apache Spark, a code path is opened in HttpSecurityFilter that allows for impersonation whenever a user provides an arbitrary username.
CVSS 9.8 - [11]CVE-2022-35914 : Open source service management platform GLPI contains a PHP test file in its htmlawed module that allows for PHP code injection.
CISA also released a pair of critical industrial control system vulnerabilities, too:
CVSS 8.8 - [12]CVE-2023-0228 : ABB Ability Symphony Plus software contains an improper authentication bug that could allow an unauthorized client to connect to an operations server and act as a legitimate client.
CVSS 9.8 - [13]Multiple CVEs : All versions of the Akuvox E11, a doorbell camera phone, are affected by vulnerabilities including the use of hardcoded encryption keys, an no-authentication web server, no file extension checks, and a bunch of other reasons to update, or just dump the thing, ASAP.
Here's a quick summary of the other items we've been following this week:
The FBI is [14]warning that, while the world may have moved on from crypto in favor of the AI craze, cybercriminals are still creating fake blockchain games to steal crypto.
Oh, look: It's not just [15]BetterHelp selling customer data to advertisers: Telehealth firm Cerebral [16]said this week it's been doing the same thing - but by accident, it claims.
The IceFire ransomware has [17]mutated , and now infects Linux systems, too.
Wanna see ChatGPT generate polymorphic malware? Sure you do, which is why the folks at Hyas [18]released a PoC of just that. Now go learn what it's capable of so you can be proactive against it.
Cybersecurity ratings company Bitsight said [19]one in 12 companies it tracks have an unsecured internet-facing webcam or similar device - maybe now's the time to check yours?
GitHub Actions was coded with a bit of a security oversight: It turns out bad actors can use commits from forked repositories to bypass allowed workflow settings and hide malicious code. The lesson? Sign all your commits.
The FBI paid for location data to circumvent warrant rules
While speaking before the US Senate, FBI director Christopher Wray made an unsurprising, but still somewhat startling, admission: G-men hampered from getting geolocation data warrants have simply resorted to buying the data they need from brokers.
Wray made a very carefully worded statement to the effect that the FBI no longer buys location data, but that it used to.
"To my knowledge, we do not currently purchase commercial database information that includes location data derived from internet advertising. I understand that we previously — as in the past—purchased some such information for a specific national security pilot project. But that's not been active for some time," Wray said in the hearing.
Note his qualification in that statement: the FBI doesn't currently buy data that includes location data derived from internet advertising . As for location data derived from elsewhere? Well, the FBI relies on court-authorized processes to get that data, Wray [20]said .
[21]
Wray's admission marks the first time a federal agency has copped to what Congress has been [22]worried about for some time, namely that US federal agencies are circumventing the fourth amendment rule against unreasonable searches, which the Supreme Court decided in 2018 [23]included location data, by simply buying it on the commercial market.
Senator Ron Wyden, whose question elicited Wray's confirmation of the judicial side step, wrote letters to the Departments of Homeland Security, Defense and Justice asking them to investigate alleged warrantless collection of location data in their agencies. Now that we know they were doing so, it just remains to be seen if Congress can actually manage to change the law to prevent it from happening - even if it's not going on right now. ®
Get our [24]Tech Resources
[1] https://www.cisa.gov/news-events/news/cisa-and-women-cybersecurity-strengthen-partnership-bridge-gender-gap-cyber-and-tech
[2] https://www.wicys.org/en-easterly-director-of-cisa-to-keynote-at-women-in-cybersecurity-wicys-conference/
[3] https://www.theregister.com/2022/10/15/infosec_boys_club/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZA9WwLP0uVFFIAvZNVaTnAAAAJc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZA9WwLP0uVFFIAvZNVaTnAAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZA9WwLP0uVFFIAvZNVaTnAAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.wicys.org/initiatives/mentorship/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZA9WwLP0uVFFIAvZNVaTnAAAAJc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://nvd.nist.gov/vuln/detail/CVE-2021-39144
[10] https://nvd.nist.gov/vuln/detail/CVE-2022-33891
[11] https://nvd.nist.gov/vuln/detail/CVE-2022-35914
[12] https://www.cisa.gov/news-events/ics-advisories/icsa-23-068-03'
[13] https://www.cisa.gov/news-events/ics-advisories/icsa-23-068-01
[14] https://www.ic3.gov/Media/Y2023/PSA230309
[15] https://www.theregister.com/2023/03/03/ftc_online_counseling_betterhelp/
[16] https://s3.documentcloud.org/documents/23702301/cerebral-breach.pdf
[17] https://www.sentinelone.com/labs/icefire-ransomware-returns-now-targeting-linux-enterprise-networks/
[18] https://www.hyas.com/blog/blackmamba-using-ai-to-generate-polymorphic-malware
[19] https://www.bitsight.com/blog/bitsight-identifies-thousands-organizations-using-internet-facing-and-exposed-webcams
[20] https://www.wired.com/story/fbi-purchase-location-data-wray-senate/
[21] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZA9WwLP0uVFFIAvZNVaTnAAAAJc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[22] https://www.theregister.com/2022/09/22/federal_agencies_american_data/
[23] https://www.theregister.com/2018/06/22/supreme_court_carpenter_location/
[24] https://whitepapers.theregister.com/
Re: Too late!
"since then she now handles all our extended family IT support matters!"
A smart move on your part.
Good luck.
...I work in an Engineering environment and it's pretty much the same. The women get letched at, have had wolf whistles, get patronised and if you go by the rumours,are either lesbians or have slept with at least 10 different guys in the first week.
The amount of times I've had to call people out us just staggering.
Re: Good luck.
That's not the case at my work (or my previous employer for that matter); what on all earth are HR and/or management doing?
"To my knowledge, we do not currently purchase commercial database information" etc
Need to know becomes need not to know?
No it just means that they didn't pay the bill
It would be easier to get the true answer if you just killed him and had his deputy come in next time. Otherwise all you're going to get is bullshit.
side notes
"Open to all WiCyS members, the nine-month program " Seriously...........................
wtf: "women and other under-represented groups" Everyone in IT is weird. Under-represented groups IS what IT is made of. Problem is (also) that these diversity groups only look skin deep/appearances.
As another poster said - If you want more diverse genders - encourage all children with opportunities for careers, (in place of gender manipulation.)
It pisses me off that 2022 woman if the year is a man. There is only one thing men haven't taken from women yet, and I'm sure some idiot is out there trying to make men carrie babies. Then we will all be Moclan (The Orvil)
Re: side notes
And illustrate it with stock photos of people that a 3-letter agency would never hire
Too late!
The first problem you have is that you're already too late! You need to get to the young girls when they start school, ideally before at kindergarten age, teach them as early as possible that tech and STEM in general doesn't care if you're a girl or a boy.
The problem is that even by kindergarten age the "damage" is already done, boys and girls have already been brainwashed into gender roles. Now don't get me wrong, nothing wrong with gender roles but as my wife was told way too many times growing up, "What the hell do you want to learn about computers for?! They're for boys to play with!", so she grew up like most young girls and ended up in a teaching role in a nursery school. I met my wife when she was 16 and I've encouraged her these last 30 years to enjoy tech, use it and do whatever you want to do and I'll support you, since then she now handles all our extended family IT support matters!