29 août 2024 | International, C4ISR, Sécurité

Russian Hackers Exploit Safari and Chrome Flaws in High-Profile Cyberattack

Russian hackers exploit patched Safari and Chrome flaws in attacks on Mongolian government websites, targeting mobile users.

https://thehackernews.com/2024/08/russian-hackers-exploit-safari-and.html

Sur le même sujet

  • Air Force wants to expand training for cyber teams

    17 juillet 2020 | International, Aérospatial, C4ISR, Sécurité

    Air Force wants to expand training for cyber teams

    Mark Pomerleau The Air Force has selected the Air National Guard's training and education center at McGhee Tyson Air National Guard Base in Tennessee to be the focal point for training a cadre of defensive focused cyber teams, according to a news release. These teams, called mission defense teams (MDTs), will protect critical Air Force missions and installations such as critical infrastructure or computers associated with aircraft and remotely piloted systems. The teams are an outgrowth of the service's communications squadrons, which have performed much of the IT and cyber defense at the base or wing level. Now, with the Air Force outsourcing much of its IT management, the service was able to free up personnel and resources to focus on protecting these critical assets. The new crews differ from the cyber protection teams that the Air Force, and other services, provide to U.S. Cyber Command as part of the cyber mission force. At first, 20 students will participate in the mission defense team pilot class in mid-August. If that is successful, it will expand to six 20 student classes in 2021. The ultimate goal is to graduate 1,000 students each year across the service beginning in fiscal year 2023, the Air Force said. These teams will be stationed at 84 locations around the world. “This is an exciting moment for TEC and its future as an agile, innovative, and resilient center of learning for the total Air Force and the National Guard Bureau,” Col. Kenneth Lozano, the commander of the traning and education center, said. The Air Force has taken a “total Air Force approach” to cyber, to include its cyber mission force teams and mission defense teams, meaning, these forces are made up of combined active duty, guard and reserve forces. Prior training efforts for mission defense teams began at the 223rd Cyberspace Operations Squadron at Little Rock Air Force Base with a Cyber-Protect and -Defend course. The first classes were held in August 2019. The Air Force said to date, the schoolhouse has trained 160 airmen. The goal is for the training and education center at McGhee Tyson to assume 1,000 graduates a year, with the majority of training to transition there in 2022. One of the biggest hurdles thus far, is procuring a range for trainees to operate on. The Air Force is working through the Defense Cybercrimes Center to procure a cyber range and certify instructors. The price tag associated with this for the initial 20 students is $1.5 million. https://www.c4isrnet.com/cyber/2020/07/16/air-force-wants-to-expand-training-for-cyber-teams/

  • The Pentagon is handling cyber vulnerabilities inconsistently

    18 mars 2020 | International, C4ISR, Sécurité

    The Pentagon is handling cyber vulnerabilities inconsistently

    Mark Pomerleau The Department of Defense has not consistently mitigated cyber vulnerabilities identified in a 2012 report, according to the department's inspector general. The DoD IG issued a follow-on report to its 2012 report, issued March 13 and made public March 17, that determined cyber red teams didn't report the results of assessments to organizations and components didn't effectively correct or mitigate the identified vulnerabilities. The new report discovered that components didn't consistently mitigate or include unmitigated vulnerabilities identified in the prior audit and during this audit by red teams during combatant command exercises, operational testing assessments and agency-specific assessments in plans of action and milestones. “Ensuring DoD Components mitigate vulnerabilities is essential to achieve a better return on investment,” the report stated. “In addition, we determined that the DoD did not establish a unified approach to support and prioritize DoD Cyber Red Team missions. Instead, the DoD Components implemented Component-specific approaches to staff, train and develop tools for DoD Cyber Red Teams, and prioritize DoD Cyber Red Team missions.” The report found that DoD didn't establish a unified approach because it didn't assign an organization with responsibility to oversee and synchronize red team activity based on priorities, it didn't assess the resources needed for each red team and identify requirements to train them to meet priorities and it didn't develop baseline tools to perform assessments. “Without an enterprisewide solution to staff, train and develop tools for DoD Cyber Red Teams and prioritize their missions, DoD Cyber Red Teams have not met current mission requests and will not meet future requests because of the increased demands for DoD Cyber Red Team services,” the report said. “Until the DoD assigns an organization to assess DoD Cyber Red Team resources, it will be unable to determine the number of DoD Cyber Red Teams and staffing of each team to support mission needs, which will impact the Do D's ability to identify vulnerabilities and take corrective actions that limit malicious actors from compromising DoD operations.” The DoD IG issued seven recommendations the secretary of defense assign an organization responsibility for. They include: Review and assess red team reports for systemic vulnerabilities and coordinate the development and implementation of enterprise solutions to mitigate them; Ensure components develop and implement a risk-based process to assess the impact of identified vulnerabilities and prioritize funding for corrective actions for high-risk vulnerabilities; Ensure components develop and implement processes for providing reports with red team findings and recommendations to organizations with responsibility for corrective actions; Develop processes and procedures to oversee red team activities, including synchronizing and prioritizing red team missions, to ensure activities align with priorities; Perform a joint DoD-wide mission-impact analysis to determine the number of red teams, minimum staffing levels of each team, the composition of the staffing levels needed to meet current and future mission requests; Assess and identify a baseline of core and specialized training standards, based on the three red team roles that team staff must meet for the team to be certified and accredited; and Identify and develop baseline tools needed by red teams to perform missions. https://www.fifthdomain.com/dod/2020/03/17/the-pentagon-is-handling-cyber-vulnerabilities-inconsistently/

  • Contract Awards by US Department of Defense - June 02, 2020

    3 juin 2020 | International, Aérospatial, Naval, Terrestre, C4ISR, Sécurité

    Contract Awards by US Department of Defense - June 02, 2020

    AIR FORCE National Aerospace Solutions LLC, Arnold Air Force Base, Tennessee, has been awarded an $181,934,683 cost-plus-award-fee modification (P00106) to contract FA9101-15-C-0500 for test operations and sustainment. This modification adds Option Year Four for test operations, technology development, equipment and facility sustainment, capital improvements and some support services for the Arnold Engineering Development Complex. Work will be performed at Arnold AFB, Tennessee, and is expected to be completed June 30, 2021. No funds are being obligated at the time of award. This modification brings the total cumulative face value of the contract to $1,186,513,728. Air Force Test Center, Arnold AFB, Tennessee, is the contracting activity. Range Generation Next LLC, Sterling, Virginia, has been awarded a $13,941,843 cost-plus-fixed-fee modification (P000297) to contract FA8806-15-C-0001 for cyber hardened infrastructure support. This modification supports an increase in launch and test range requirements. The primary locations of performance are the Eastern Range, Patrick Air Force Base, Florida; and the Western Range, Vandenberg AFB, California. Work is expected to be completed Feb. 14, 2022. Fiscal 2020 operations and maintenance funds in the amount of $13,941,843 are being obligated at the time of award. The total cumulative face value is $1,210,861,882. Space and Missile Systems Center, Peterson AFB, Colorado, is the contracting activity. Oracle America Inc., Reston, Virginia, has been awarded a $10,499,623 firm-fixed-price contract to provide software licenses, Oracle Service Cloud Hosting Services and maintenance in support of the myPers Customer Relationship Management software. The vendor will be required to provide 1,000 full software licenses for business process owners/administrators and 5,000 light software licenses for users requiring access to support customers. Work will be performed in Washington, D.C., and is expected to be completed May 31, 2021. Fiscal 2020 operations and maintenance funds in the amount of $5,249,812 are being obligated at the time of award. Air Force District of Washington, Joint Base Andrews, Maryland, is the contracting activity (FA7014-20-C-0024). (Awarded May 29, 2020) NAVY Northrop Grumman Systems Corp., Woodland Hills, California, is awarded a $79,083,495 modification (P00018) to previously awarded cost-plus-fixed-fee, firm-fixed-price, cost reimbursable, indefinite-delivery/indefinite-quantity contract N68936-15-D-0013. This modification increases the ceiling for the research and development of AH-1Z and UH-1Y system configuration set mission computers in support of the Marine Corps. Work will be performed in Woodland Hills, California (98%); Salt Lake City, Utah (1%); and Baltimore, Maryland (1%). Efforts include researching alternatives, investigating and documenting new capabilities and anomalies related to avionics and weapons, designing, developing, integrating, verifying, validating and testing upgrades to existing mission computer software and ancillary hardware and/or improved functionality and obsolescence management of the mission computer. This modification also includes the logistics requirements to support the system. Work is expected to be complete by April 2021. No funds are being obligated at time of award. Funds will be obligated on individual orders as they are issued. The Naval Air Warfare Center, Weapons Division, China Lake, California, is the contracting activity. Viasat Inc., Carlsbad, California, is awarded $75,373,500 (a modification with a maximum potential value) under previously awarded, indefinite-delivery/indefinite-quantity, multiple award contract N00039-15-D-0043 for the Block Upgrade II retrofit of multifunctional information distribution system (MIDS) low volume terminals. Work will be performed in Carlsbad, California. The terminals provide secure, high-capacity, jam-resistant, digital data and voice communications capability for the Navy, Air Force and Army platforms as well as Foreign Military Sales customers. Work is expected to be complete by May 2024. This modification will increase the current contract value from $599,093,506 to $674,467,006. No funding is being obligated at the time of award. Funds will be obligated as individual delivery orders are issued. This contract modification was not competitively procured because it is a sole-source acquisition pursuant to the authority of 10 U.S. Code 2304(c)(1). Only one responsible source (Federal Acquisition Regulation subpart 6.302-1) was addressed under Justification and Approval No. 18,413 (April 2, 2018) and the contract was awarded on behalf of the Multifunctional Information Distribution System Program Office. The Naval Information Warfare Systems Command, San Diego, California, is the contracting activity. Trandes Corp., Linthicum, Maryland, is awarded a $24,388,698 for an indefinite-delivery/indefinite-quantity, cost-plus-fixed-fee contract (N66001-20-D-0336) to provide engineering services to support electronic tactical air navigation, air traffic and command control, landing systems and joint tactical systems. Work will be performed in San Diego, California (75%); and potential air traffic control sites, ships, and Department of Defense facilities worldwide (25%). The period of performance of the base award is from June 2, 2020, to June 1, 2022. If all options are exercised, the period of performance will extend through June 1, 2025. This two-year contract includes three one-year options, which if exercised will bring the potential value of this contact to an estimated $63,833,003. No funds will be obligated at the time of award. Funds will be obligated as task orders are issued using operations and maintenance (Navy); other procurement (Navy); research, development, test and evaluation (Navy); and potential funding from other government agencies to include the Army, Air Force, Coast Guard and the Department of Homeland Security. This contract was competitively procured as a small business set-aside via request for proposal which was published on the contract opportunities section of the System for Award Management website and the Naval Information Warfare Systems Command e-Commerce Central website. Two proposals were received and one was selected for award. The Naval Information Warfare Center Pacific, San Diego, California, is the contracting activity. Metson Marine Services Inc. (N66604-20-D-M001); Seaward Services Inc. (N66604-20-D-M002); and Oceanetics Inc. (N66604-20-D-M003), are awarded $22,950,296 for a maximum value, indefinite-delivery/indefinite-quantity, multiple-award contract for the procurement of operational and logistic services required to support various at-sea tests for the Naval Undersea Warfare Center Division Newport customers. Work will be performed at the contractors' sites and at government locations based on each individual task orders all over the world and is expected to be complete by June 2025. For these base five-year contracts, funding will not be obligated at time of award; the $1,000 minimum guarantee will be executed on each awardee's initial task order. Fiscal 2020 service cost center funding in the amount of $3,000 will be obligated at time of award, and will not expire at the end of the current fiscal year. This multiple-award contract was competitively procured and three acceptable offers were received via the BETA.SAM.gov website. The Naval Undersea Warfare Center Division Newport, Newport, Rhode Island, is the contracting activity. Northrop Grumman Systems Corp., Aerospace Systems, Melbourne, Florida, is awarded a $17,649,408 modification (P00001) to firm-fixed-price, cost-plus-fixed-fee order N0001920-F-0025 against previously issued basic ordering agreement N00019-15-G-0026. Work will be performed in Norfolk, Virginia (39.2%); Ronkonkoma, New York (23.98%); Bethpage, New York (18.02%); Petaluma, California (6.8%); Irvine, California (6.76%); Melbourne, Florida (3.25%); Minden, Nebraska (1.5%); and various locations within the continental U.S. (.49%). This modification procures fabrication and installation support to retrofit the Link 16 (L16) Crypto-Modernization (CM)/Hybrid-Beyond Line of Sight (HBLOS) capability on 34 E-2D Advanced Hawkeye aircraft. This modification also provides for the retrofit of four sets of support equipment to satisfy operational requirements for the L16 and HBLOS as well as the procurement of five new radio interface units in support of the installation schedule for the CM/HBLOS capability. Work is expected to be complete by June 2021. Fiscal 2020 aircraft procurement (Navy) funds for $17,649,408 will be obligated at time of award, none of which will expire at the end of the current fiscal year. The Naval Air Systems Command, Patuxent River, Maryland, is the contracting activity. AECOM Technical Services Inc., Los Angeles, California, is awarded $9,054,900 for cost-plus-award-fee task order N62742-19-F-4006 modification under an indefinite-delivery/indefinite-quantity, multiple award contract for the Shipyard Infrastructure Optimization Program advanced studies, part three, at the Pearl Harbor Naval Shipyard (PHNSY) and Intermediate Maintenance Facility (IMF). Work will be performed in PHNSY and IMF, Joint Base Pearl Harbor-Hickam, Hawaii, and provides for 17 advanced studies and project management for Site 1, PHNSY and IMF, in accordance with the scope of work as negotiated. Work is expected to be completed by September 2021. Fiscal 2020 Navy contract funds in the amount of $9,054,900 are obligated on this award and will not expire at the end of the current fiscal year. The Naval Facilities Engineering Command, Pacific, Pearl Harbor, Hawaii, is the contracting activity (N62742-16-D-3555). Northrop Grumman Systems Corp., Herndon, Virginia, is awarded a $7,815,609 firm-fixed-price modification to previously awarded contract N00024-15-C-6327 to provide equitable adjustments for engineering change proposals for Increment One Block One (I1B1) Systems low rate initial production in support of the Expeditionary Warfare Program Office. Work will be performed in San Diego, California. This modification is to provide for an equitable adjustment for already completed engineering work for Counter Radio-Controlled Improvised Explosive Devises Electronic Warfare (CREW) systems that provide combat troops protection against Radio-Controlled Improvised Explosive Devices (RCIEDs). CREW systems are designed to provide protection for foot soldiers, vehicles and permanent structures. The Joint CREW (JCREW) I1B1 system is the first generation system that develops a common open architecture across all three capabilities and provides protection for worldwide military operations. This modification is issued to ensure JCREW systems are viable for future production and maintain operational readiness for the field. Work is expected to be complete by May 2020. Fiscal 2020 operations and maintenance (Air Force) funds; 2019 other procurement (Navy) funds; and 2018 other procurement (Navy) funding in the amount of $7,815,609 will be obligated at time of award; $5,011,497 will expire at the end of the current fiscal year. The Naval Sea Systems Command, Washington, D.C., is the contracting activity. (Awarded May 28, 2020) DEFENSE ADVANCED RESEARCH PROJECTS AGENCY Agile Defense Inc.,* Reston, Virginia, has been awarded a $31,225,244 modification (P00052) to previously awarded task order HR0011-15-F-0002 for unclassified information technology services. The modification brings the total cumulative face value of the task order from $176,513,865 to $207,739,109. Work will be performed in Arlington, Virginia, with an expected completion date of February 2021. Fiscal 2019 and 2020 research and development funds in the amount of $12,224,558 are being obligated at time of award. The Defense Advanced Research Projects Agency, Arlington, Virginia, is the contracting activity. ARMY Chi-Chack LLC,* Tacoma, Washington, was awarded a $29,082,048 firm-fixed-price contract for language and culture services to include creativity and flexibility to meet the unique instruction needs of commanders requiring language and/or culture related capabilities. Bids were solicited via the internet with four received. Work locations and funding will be determined with each order, with an estimated completion date of May 31, 2025. U.S. Army 419th Contracting Support Brigade, Fort Bragg, North Carolina, is the contracting activity (W9124720D9001). Technica LLC,* Charleston, South Carolina, was awarded an $11,316,045 modification (0004 C4) to contract W52P1J-12-G-0018 for Fort Bliss, Texas, Logistics Readiness Center support services to include maintenance, transportation and supply. Work will be performed in El Paso, Texas, with an estimated completion date of Sept. 1, 2020. Fiscal 2020 operations and maintenance (Army) funds in the amount of $11,316,045 were obligated at the time of the award. U.S. Army Contracting Command, Rock Island Arsenal, Illinois, is the contracting activity. Maloof Weathertight Solutions LLC, Warner Robins, Georgia, was awarded an $8,847,818 firm-fixed-price contract to provide all work for repair and replacement of roof projects at Fort Stewart and Hunter Army Airfield, Georgia. Bids were solicited via the internet with 11 received. Work locations and funding will be determined with each order, with an estimated completion date of June 1, 2023. U.S. Army 419th Contracting Support Brigade, Fort Stewart, Georgia, is the contracting activity (W9124M-20-D-0006). DEFENSE LOGISTICS AGENCY Telephonics Corp., Farmingdale, New York, has been awarded a maximum $15,236,585 firm-fixed-price, indefinite-delivery/indefinite-quantity contract for aviation control interface. This was a competitive acquisition with one offer received. This is a five-year contract with no option periods. Location of performance is New York, with a June 1, 2025, ordering period end date. Using military service is Army. Type of appropriation is fiscal 2020 through 2025 Army working capital funds. The contracting activity is the Defense Logistics Agency Aviation, Redstone Arsenal, Alabama (SPRRA1-20-D-0044). Northrop Grumman Systems Corp., Rolling Meadows, Illinois, has been awarded a $12,494,230 firm-fixed-price delivery order (SPRPA1-20-F-KF0C) against a five-year basic ordering agreement (SPE4A1-16-G-0005) for AAQ-24 ATW sensors. This was a sole-source acquisition using justification 10 U.S. Code 2304 (c)(1), as stated in Federal Acquisition Regulation 6.302-1. Location of performance is Illinois, with a May 31, 2022, performance completion date. Using military service is Navy. Type of appropriation is fiscal 2020 through 2022 Navy working capital funds. The contracting activity is the Defense Logistics Agency Aviation, Philadelphia, Pennsylvania. *Small business https://www.defense.gov/Newsroom/Contracts/Contract/Article/2205772/source/GovDelivery/

Toutes les nouvelles