Friday December 3rd, 2021 5:25AM

Massive breach fuels calls for US action on cybersecurity

By The Associated Press
Related Articles
  Contact Editor

WASHINGTON (AP) — Jolted by a sweeping hack that may have revealed government and corporate secrets to Russia, U.S. officials are scrambling to reinforce the nation’s cyber defenses and recognizing that an agency created two years ago to protect America’s networks and infrastructure lacks the money, tools and authority to counter such sophisticated threats.

The breach, which hijacked widely used software from Texas-based SolarWinds Inc., has exposed the profound vulnerability of civilian government networks and the limitations of efforts to detect threats.

It's also likely to unleash a wave of spending on technology modernization and cybersecurity.

“It’s really highlighted the investments we need to make in cybersecurity to have the visibility to block these attacks in the future,” Anne Neuberger, the newly appointed deputy national security adviser for cyber and emergency technology said Wednesday at a White House briefing.

The reaction reflects the severity of a hack that was disclosed only in December. The hackers, as yet unidentified but described by officials as “likely Russian,” had unfettered access to the data and email of at least nine U.S. government agencies and about 100 private companies, with the full extent of the compromise still unknown. And while this incident appeared to be aimed at stealing information, it heightened fears that future hackers could damage critical infrastructure, like electrical grids or water systems.

President Joe Biden plans to release an executive order soon that Neuberger said will include about eight measures intended to address security gaps exposed by the hack. The administration has also proposed expanding by 30% the budget of the U.S. Cybersecurity and Infrastructure Agency, or CISA, a little-known entity now under intense scrutiny because of the SolarWinds breach.

Republicans and Democrats in Congress have called for expanding the size and role of the agency, a component of the Department of Homeland Security. It was created in November 2018 amid a sense that U.S. adversaries were increasingly targeting civilian government and corporate networks as well as the “critical” infrastructure, such as the energy grid that is increasingly vulnerable in a wired world.

Speaking at a recent hearing on cybersecurity, Rep. John Katko, a Republican from New York, urged his colleagues to quickly "find a legislative vehicle to give CISA the resources it needs to fully respond and protect us.”

Biden’s COVID-19 relief package called for $690 million more for CISA, as well as providing the agency with $9 billion to modernize IT across the government in partnership with the General Services Administration.

That has been pulled from the latest version of the bill because some members didn’t see a connection to the pandemic. But Rep. Jim Langevin, co-chair of the Congressional Cybersecurity Caucus, said additional funding for CISA is likely to reemerge with bipartisan support in upcoming legislation, perhaps an infrastructure bill.

“Our cyber infrastructure is every bit as important as our roads and bridges,” Langevin, a Rhode Island Democrat, said in an interview. “It’s important to our economy. It’s important to protecting human life, and we need to make sure we have a modern and resilient cyber infrastructure.”

CISA operates a threat-detection system known as “Einstein" that was unable to detect the SolarWinds breach. Brandon Wales, CISA's acting director, said that was because the breach was hidden in a legitimate software update from SolarWinds to its customers. After it was able to identify the malicious activity, the system was able to scan federal networks and identify some government victims. “It was designed to work in concert with other security programs inside the agencies,” he said.

The former head of CISA, Christopher Krebs, told the House Homeland Security Committee this month that the U.S. should increase support to the agency, in part so it can issue grants to state and local governments to improve their cybersecurity and accelerate IT modernization across the federal government, which is part of the Biden proposal.

“Are we going to stop every attack? No. But we can take care of the most common risks and make the bad guys work that much harder and limit their success,” said Krebs, who was ousted by then-President Donald Trump after the election and now co-owns a consulting company whose clients include SolarWinds.

The breach was discovered in early December by the private security firm FireEye, a cause of concern for some officials.

“It was pretty alarming that we found out about it through a private company as opposed to our being able to detect it ourselves to begin with,” Avril Haines, the director of national intelligence, said at her January confirmation hearing.

Right after the hack was announced, the Treasury Department bypassed its normal competitive contracting process to hire the private security firm CrowdStrike, U.S. contract records show. The department declined to comment. Sen. Ron Wyden, D-Ore., has said that dozens of email accounts of top officials at the agency were hacked.

The Social Security Administration hired FireEye to do an independent forensic analysis of its network logs. The agency had a “backdoor code” installed like other SolarWinds customers, but “there were no indicators suggesting we were targeted or that a future attack occurred beyond the initial software installation,” spokesperson Mark Hinkle said.

Sen. Mark Warner, a Virginia Democrat who chairs the Senate Intelligence Committee, said the hack has highlighted several failures at the federal level but not necessarily a lack of expertise by public sector employees. Still, “I doubt we will ever have all the capacity we’d need in-house,” he said.

There have been some new cybersecurity measures taken in recent months. In the defense policy bill that passed in January, lawmakers created a national director of cybersecurity, replacing a position at the White House that had been cut under Trump, and granted CISA the power to issue administrative subpoenas as part of its efforts to identify vulnerable systems and notify operators.

The legislation also granted CISA increased authority to hunt for threats across the networks of civilian government agencies, something Langevin said they were only previously able to do when invited.

“In practical terms, what that meant is they weren’t invited in because no department or agency wants to look bad,” he said. “So you know what was happening? Everyone was sticking their heads in the sand and hoping that cyberthreats were going to go away.”


Suderman reported from Richmond, Va.


This story has been corrected to show the relief package called for $690 million, not $690 billion, more for CISA.

  • Associated Categories: U.S. News, Associated Press (AP), AP National News, AP Online National News, Top U.S. News short headlines, Top General short headlines, AP Online Headlines - Washington, AP Online Congress News, AP Business, AP Business - Corporate News
© Copyright 2021
All rights reserved. This material may not be published, broadcast, rewritten, or redistributed without permission.
Massive breach fuels calls for US action on cybersecurity
U.S. officials are scrambling to reinforce the nation’s cyber defenses following a sweeping hack that may have exposed government and corporate secrets to Russia
1:16AM ( 11 minutes ago )
DA son seeks release of father imprisoned in fatal '81 heist
Advocates are seeking clemency for one of the last robbers in a fatal 1981 Brink's armored truck robbery still in prison
1:08AM ( 19 minutes ago )
Woman shot last week at Myanmar protest dies
A young woman who was shot in the head by police during a protest last week against the military’s takeover of power in Myanmar died Friday morning, her brother said
1:08AM ( 20 minutes ago )
Associated Press (AP)
Biden repudiates Trump on Iran, ready for talks on nuke deal
The Biden administration says it's ready to join talks with Iran and world powers to discuss a return to the 2015 nuclear deal
12:03AM ( 1 hour ago )
Lights come back on in Texas as water woes rise in the South
Many Texans finally have electricity back after a deadly blast of winter this week overwhelmed the electrical grid and left millions shivering in the cold for days
11:50PM ( 1 hour ago )
'Obviously a mistake': Cruz returns from Cancun after uproar
Texas Sen. Ted Cruz says his family vacation to Mexico was “obviously a mistake” as he returned stateside following an uproar over his disappearance during a deadly winter storm
10:02PM ( 3 hours ago )
AP National News
Texas crisis has governor facing big backer: energy industry
Texas Gov. Greg Abbott wants mandates that would require power plants to withstand extreme winter weather
9:49PM ( 3 hours ago )
Democrats consider piecemeal approach to immigration reform
Congressional Democrats and the Biden administration have unveiled a broad immigration bill that would provide an eight-year pathway to citizenship for 11 million people living in the country without legal status
9:37PM ( 3 hours ago )
Some electricity restored in Texas, but water woes grow
Power was restored to more homes and businesses in Texas after a deadly blast of winter this week overwhelmed the electrical grid and left millions shivering in the cold
9:33PM ( 3 hours ago )
Top General short headlines
Asia stocks follow Wall St. down after weaker US jobs data
Asian stock markets have followed Wall Street lower after disappointing U.S. jobs and economic data
10:48PM ( 2 hours ago )
Australian leader urges Facebook to lift its news blockade
Australia’s prime minister has urged Facebook to lift its blockade of Australian users and return to the negotiating table with news publishing businesses
8:56PM ( 4 hours ago )
Ex-Illinois House Speaker Michael Madigan to resign seat
Illinois state Rep. Michael Madigan has announced that he has resigned his seat in the Legislature
6:55PM ( 6 hours ago )
AP Online Headlines - Washington
Path to citizenship in new Democratic immigration bill
President Joe Biden's administration has joined Democrats on Capitol Hill in unveiling a major immigration overhaul
3:10PM ( 10 hours ago )
Pelosi says bipartisan panel should investigate Capitol riot
House Speaker Nancy Pelosi says a commission to study the deadly attack at the Capitol must be “strongly bipartisan.”
2:36PM ( 10 hours ago )
AP source: Police suggest keeping Capitol fence for months
U.S. Capitol Police officials told congressional leaders the razor-wire topped fencing around the Capitol should remain in place for several more months as law enforcement continues to track threats against lawmakers
2:28PM ( 11 hours ago )
AP Online Congress News
The Latest: Most of a Mississippi city is without water
Mayor Chokwe Antar Lumumba says almost all of Jackson, a city of around 150,000 people, is now without water
8:26PM ( 5 hours ago )
The Latest: Nevada has 1st confirmed case of SAfrica variant
Nevada health officials have confirmed the state’s first known case of a coronavirus variant that was originally identified in South Africa
8:14PM ( 5 hours ago )
Ford loses track of dangerous air bags, forcing 2 recalls
Ford has lost track of some older Takata air bags that can explode and hurl shrapnel, so it’s recalling more than 154,000 vehicles in North America
7:11PM ( 6 hours ago )
AP Business
The Latest: Algeria to start producing Russian vaccine
Algerian President Abdelmadjid Tebboune says his country will start producing Russia’s Sputnik-V coronavirus vaccine in six or seven months
5:04PM ( 8 hours ago )
The Latest: Deal to get 1.1B vaccines to over 190 nations
Vaccine developer Novavax has agreed to provide 1.1 billion doses of its experimental COVID-19 vaccine for use in more than 190 low- and middle-income countries
4:38PM ( 8 hours ago )
The Latest: Drug companies start pregnancy vaccine study
Drugmaker Pfizer and German parterner BioNTech have started a nine-country study of their COVID-19 vaccine in pregnant women
3:02PM ( 10 hours ago )
AP Business - Corporate News
DA son seeks release of father imprisoned in fatal '81 heist
Advocates are seeking clemency for one of the last robbers in a fatal 1981 Brink's armored truck robbery still in prison
1:08AM ( 20 minutes ago )
Woman shot last week at Myanmar protest dies
A young woman who was shot in the head by police during a protest last week against the military’s takeover of power in Myanmar died Friday morning, her brother said
1:08AM ( 20 minutes ago )
US lets in asylum-seekers stuck in Mexico, ends Trump policy
After waiting months and sometimes years in Mexico, people seeking asylum in the United States are starting to be allowed into the country as they wait for courts to decide on their cases
1:05AM ( 22 minutes ago )
Biden to lay out his foreign policy at G-7, Munich summit
Joe Biden will make his first big appearance on the global stage as president on Friday,
12:51AM ( 37 minutes ago )
World leaders applaud US formal return to Paris climate pact
The United States is once again part of the Paris climate accord
12:46AM ( 41 minutes ago )