The NSA says it recently discovered "a series of critical vulnerabilities" in Microsoft Exchange and disclosed them to Microsoft, which today released a patch.
"NSA values partnership in the cybersecurity community," an NSA spokesperson said. "We are continuing the partnership by urging application of the patches immediately."
New @NSACyber Director @RGB_Lights: "Cybersecurity is national security. Network defenders now have the knowledge needed to act, but so do adversaries and malicious cyber actors. Don't give them the opportunity to exploit this vulnerability on your system."
.@Microsoft said it had "not seen the vulnerabilities used in attacks" against its customers but urged prompt patching "given recent adversary focus on Exchange"

msrc-blog.microsoft.com/2021/04/13/apr…
Statement from Deputy National Security Advisor for Cyber & Emerging Tech Anne Neuberger says U.S. federal agencies required to “immediately” patch Exchange servers Image
Disclosing software flaws is a relatively new practice for the NSA, which in the past would collect and keep secret vulnerabilities for its own use in intelligence gathering -- cbsnews.com/news/nsa-micro…

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Olivia Gazis

Olivia Gazis Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @Olivia_Gazis

14 Apr
Happening now: Leaders of ODNI, CIA, NSA, DIA and FBI offer public testimony at
the Worldwide Threats Hearing before the Senate Select Committee on Intelligence -

Livestream: intelligence.senate.gov/hearings/open-…
Chairman @MarkWarner registers 'dismay' that this hearing did not happen last year - for the first time since 1994 - after then-DNI Ratcliffe refused to engage in public Q&A.
On the docket, Warner says, is how agencies have contended with COVID-19 - including vaccinating its personnel - plus cybersecurity, election security, domestic violent extremism and the Chinese Communist Party
Read 24 tweets
13 Apr
A senior administration official said this is not a conditions-based approach, telling @margbrennan POTUS has deemed that to be "a recipe for staying in Afghanistan forever." United States will remove its forces from Afghanistan "before September 11," SAO said.
The official said the decision is also reflective of the need to address a "global threat picture as it exists today, not as it was two decades ago."
SAO: "This is not 2001; it is 2021. And in 2021, the terrorist threat that we face is real and it emanates from a number of countries, indeed a number of continents....And we have to focus on those aspects of a dispersed and distributed terrorist threat"
Read 4 tweets
13 Apr
New: The U.S. intelligence community is warning in its Annual Threat Assessment of a “diverse array” of global threats that could further destabilize a world shaken by the effects of the COVID-19 pandemic, technological change and interstate competition:

dni.gov/files/ODNI/doc…
The 27pg document contains the collective view of the country’s 18 intel agencies; it said “the potential for cascading events in an increasingly interconnected & mobile world” would create new challenges, as adversaries jockey for influence & climate change heightens instability
It said China, Russia, Iran and North Korea would seek to challenge U.S. interests in different arenas and on multiple levels, and that transnational crime, cyber attacks and terrorist plots posed continued threats. Domestic violent extremists will pose an “elevated threat.”
Read 8 tweets
7 Apr
Deputy National Security Advisor for Cyber & Emerging Tech Anne Neuberger said at @CFR_org that the Biden administration will launch an effort to secure control systems across the country "because of the significant consequences if they fail, or if they're degraded"
Neuberger: "We picked control systems because those are the systems that control water systems, power systems, chemical systems across the US, and we're seeking to have visibility on those networks to detect anomalous cyber behavior and block anomalous cyber behavior." (cont'd)
Neuberger: "Today we cannot trust those systems, because we don't have visibility into those systems, and we need the visibility of those systems because of the significant consequences if they fail, or if they're degraded."
Read 5 tweets
5 Apr
.@SecBlinken said the Biden-Harris administration was "exploring options" to share more resources - including vaccines - to combat COVID-19 in other countries, and that he was appointing a new official to oversee the global effort.
Blinken said the administration has had as its "main focus" getting vaccines to Americans, but "soon the US will need to step up our work and rise to the occasion worldwide."
"This pandemic won’t end at home until it ends worldwide," he said.

Blinken said the U.S. had received requests from other countries -- some with "growing desperation" -- for help. "We hear you, and I promise we're moving as fast as possible," he said.
Read 5 tweets
17 Mar
Declassified US intel assessment of 2020 election shows Russia's foreign influence playbook a) was only marginally changed; b) was adopted selectively by other adversaries & challengers; c) will continue being used unless the cost/benefit calculus changes

dni.gov/files/ODNI/doc…
A few things:

The classified version of this assessment was completed and given to USG stakeholders on January 7, 2021; it draws from information made available to the IC during the Trump administration
It includes guidance on election "influence" versus "interference," two terms that had been used interchangeably and to at times confusing effect:
Read 15 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!

Follow Us on Twitter!