home.social

#governmentsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #governmentsecurity, aggregated by home.social.

  1. CNN: Exclusive: DHS admits its website showcasing the ‘worst of the worst’ immigrants was rife with errors. “The Department of Homeland Security admitted that its website featuring what it calls the ‘worst of the worst’ arrested immigrants was rife with errors and changed the site this week after receiving questions from CNN about it.”

    https://rbfirehose.com/2026/02/24/exclusive-dhs-admits-its-website-showcasing-the-worst-of-the-worst-immigrants-was-rife-with-errors-cnn/
  2. The Conversation: Federal shutdown deals blow to already hobbled cybersecurity agency. “CISA is among the entities that will see the deepest staffing reductions during the shutdown that began Oct. 1, 2025, according to Department of Homeland Security documentation. Only about one-third of its employees remain on the job after federal employees were furloughed. As if cybersecurity wasn’t […]

    https://rbfirehose.com/2025/10/08/the-conversation-federal-shutdown-deals-blow-to-already-hobbled-cybersecurity-agency/

  3. The Register: Three US agencies get failing grades for not following IT best practices . “The GAO flagged failures at the General Services Administration (GSA), Environmental Protection Agency (EPA), and Department of Homeland Security (DHS) in the three reports, with each guilty of not implementing more recommendations than the last. The DHS’ CIO, in particular, has 43 unresolved […]

    https://rbfirehose.com/2025/08/07/the-register-three-us-agencies-get-failing-grades-for-not-following-it-best-practices/

  4. The U.S. House of Representatives made a bold move, banning WhatsApp on all government devices due to cybersecurity risks. What does this mean for data privacy, national security, and the future of digital communication? Dive into our comprehensive analysis.

    #SecurityLand #GeoSphere #WhatsAppBan #Cybersecurity #GovernmentSecurity #DataPrivacy #Government

    Read More: security.land/from-personal-ch

  5. ⚠️ App security alert: TM SGNL — a custom Signal fork used by high-level U.S. officials — was reportedly hacked 📱🔓

    Key findings via researchers:
    🛠️ Hardcoded credentials found in the app’s source code
    📥 Hacker claims to have breached TeleMessage (creator of TM SGNL) in minutes
    📁 Archive server may store unencrypted copies of sensitive messages
    📇 Leaked data includes government contacts, messages, and backend access

    🚨 Why it matters:
    🔐 TM SGNL modifies Signal to support message archiving — possibly before encryption
    ⚠️ That’s a potential plaintext vulnerability — even if E2EE is in place
    💬 Raises urgent questions about how U.S. officials handle sensitive digital comms

    🛡️ Security leaders should:
    📱 Vet third-party forks of secure messaging apps rigorously
    🚫 Avoid using unofficial tools for sensitive communication
    🧾 Align secure messaging practices with compliance and cybersecurity

    This incident isn’t just a breach — it’s a wake-up call about assuming encryption = security.

    #CyberSecurity #MessagingApps #Signal #DataBreach #GovernmentSecurity #ThreatIntel #security #privacy #cloud #infosec

    csoonline.com/article/3977385/

  6. The Register: Forget Signal. National Security Adviser Waltz now accused of using Gmail for work. “Senior members of the US National Security Council, including the White House national security adviser Michael Waltz, have been accused of using their personal Gmail accounts to exchange sensitive information.”

    https://rbfirehose.com/2025/04/02/the-register-forget-signal-national-security-adviser-waltz-now-accused-of-using-gmail-for-work/

  7. In 2024, a group known as DarkCasino emerged as a cyber threat entity. This group has been linked to exploiting a vulnerability in WinRAR, specifically identified as CVE 2023 38831. DarkCasino has been using this security loophole to carry out phishing attacks targeting users in industries such as casinos, financial services, and government sectors across countries. Their strategy involves sending emails containing manipulated archives to distribute malicious software and gather sensitive information.

    DarkCasino, while sharing similarities with other cyber threat groups, stands out for its sophisticated techniques and primarily financial motivation. Their use of Visual Basic-based Trojan horse programs is a testament to their advanced capabilities. Their activities underscore the ever-evolving landscape of risks and the critical need for robust cybersecurity measures. Ongoing surveillance and analysis by cybersecurity firms like NSFOCUS and Group IB have provided insights into DarkCasino's operations, but many specifics regarding their targets and the complete extent of their actions remain undisclosed, adding to the complexity of the challenge.

    #DarkCasino #APT #CyberSecurity #WinRAR #ZeroDay #PhishingAttacks #CyberThreats #DataExfiltration #Malware #AdvancedThreats #VisualBasic #TrojanHorse #FinancialServices #GovernmentSecurity #NSFOCUS #GroupIB #CyberEspionage #ThreatDetection #InformationSecurity #EconomicMotivation

  8. "LockBit's Bold Return: A Threat Renewed 🚨 #CyberAlert"

    Despite recent crackdowns, the notorious LockBit ransomware gang has defiantly announced a comeback, threatening new cyber onslaughts on government sectors in the UK and USA. Leveraging a previously exploited PHP vulnerability, they've bounced back, boasting updated security measures and a new dark web haunt for victim listings. This follows a brief hiatus post-Operation Cronos, highlighting the resilient and adaptive nature of cyber threats today. LockBit's strategy now includes manual decryptor releases and rewards for vulnerability reports, underlining an intensified focus on operational security to thwart future law enforcement infiltrations. Stay vigilant, stay informed. #LockBit #CyberSecurity #RansomwareResurgence #ThreatIntelligence #DigitalDefense

    Source: HackRead

    Tags: #APT #CyberCrime #InfoSec #SecurityAwareness #CyberThreats #GovernmentSecurity #OperationalSecurity #PHPVulnerability 🌐🔒💡