Follow CSI on Twitter

LATEST FBI CERT VULNERABILITIES

The latest vulnerabilities and updates (the hack and patch) from the FBI’s Computer Emergency Readiness Team:

Microsoft Releases March Security Bulletin

Energizer DUO USB Battery Charger Software Allows Remote System Access

Cisco Releases Multiple Security Advisories

NATIONAL CYBER ALERT SYSTEM BULLETINS

The latest cybersecurity alert bulletins from the FBI:

SB10-067: Vulnerability Summary for the Week of March 1, 2010

SB10-060: Vulnerability Summary for the Week of February 22, 2010

SB10-053: Vulnerability Summary for the Week of February 15, 2010

CYBER SECURITY ALERTS

US-CERT Cyber Security Alerts:

TECHNICAL

TA10-068A: Microsoft Updates for Multiple Vulnerabilities

TA10-055A: Malicious Activity Associated with "Aurora" Internet Explorer Exploit

TA10-040A: Microsoft Updates for Multiple Vulnerabilities

NEW THREATS

US-CERT Recently Published Vulnerability Notes:

VU#744549: Microsoft Internet Explorer iepeers.dll use-after-free vulnerability

VU#154421: Energizer DUO USB battery charger software allows unauthorized remote system access

VU#576029: libpng stalls on highly compressed ancillary chunks

BLOG

Debunking the Growing Use of Misleading Claims and False Truisms in Cybersecurity: Wind River and Google Android Examples (Release)

Cyber Secure Institute Calls Wired Magazine’s “2009 Smart List” Idea “Forget Medical Privacy” Profoundly Stupid (Release)

Cyber Secure Institute Releases Preliminary Analysis of the National Institute of Standards and Technology’s Newly Announced Recommended Security Controls for Federal Information Systems and Organizations

CSI WHITEPAPERS

2/17/10
Cybersecurity: The Challenge of Political and Corporate Will

by Hon. C. Thomas McMillen

2nd in the series, Provoking Cybersecurity Change.


2/1/10
Cyberwar and Cyberterrorism

by Gen. Eugene Habiger

Today, the Cyber Secure Institute published a whitepaper, entitled “Cyberwar and Cyberterrorism: The Need for a New U.S. Strategic Approach,” written by Gen. Eugene Habiger USAF (ret.), who formerly served as Commander in Chief of United States Strategic Command. He also served as the Department of Energy's “Security Czar.”

General Habiger’s whitepaper draws a number of important conclusions, including these five points:

1. America is routinely the victim of nation-state driven cyber intrusions that can be seen as low-grade cyber-border conflicts.

2. Some of these attacks have crossed a critical line: they have compromised critical systems supporting our troops engaged in combat.

3. Our failure to proactively address these threats risks a digital Pearl Harbor or 9-11.

4. Deterrence by retribution and preemption, our nation’s core national security strategies, are of limited value against cyberwar and cyberterror threats—“these rotary-phone-era strategies are not well suited for today’s digital world.”

5. A new approach based upon deterrence by denial is needed, which will require nothing short of a total paradigm shift from both government and the private sector.


ABOUT CSI

The Cyber Security Institute is a newly established analysis and advocacy institute dedicated to serving as the voice for effective cyber security. Our objectives are:

Unlike most cybersecurity-focused groups, we are not an industry or trade association. We are also not a think tank per se. While we will be doing high-level analytical work, our purpose is not to solely study issues; our role is to drive awareness and change.

TEAM

Officers and Directors

Rob Housman, Acting Executive Director and Chairman of the Board
Mr. Housman has more than two decades of experience in public policy, particularly in the national and homeland security areas. During the Clinton Administration he served as Assistant Director for Strategic Planning in the White House Drug Czar's Office. He is a contributing author of the Homeland Security Law Handbook. He teaches Counter-Terrorism and Homeland Security for the University of Maryland, University College, School of Management and Technology. He has taught national security for Syracuse University's Maxwell School and law for the Washington College of Law, American University. He is also a partner with Book Hill Partners.

Rick Moore, Member of the Board
Mr. Moore has almost three decades of experience in public policy and public affairs, in particular in the technology sector. He served in a variety of communications capacities in both the Carter and Clinton administrations. He previously served as Senior Vice President with the Oracle Corporation in Silicon Valley reporting directly to Chairman and CEO Larry Ellison. At Oracle he served on the technology development committee and the executive management committee. He has also worked with a number of other leading tech companies including Hewlett Packard, Compaq Computer and Sprint. He is also a partner with Book Hill Partners.

Ira Sockowitz, Member of the Board
Mr. Sockowitz has over two decades of experience in public policy, in particular commercial and technology policy. During the Clinton administration, he served as Special Counsel to the late-Secretary Ron Brown at the U.S. Department of Commerce. His efforts on behalf of U.S. business interests resulted in over $42 billion of contracts. While at the Department, Mr. Sockowitz worked extensively with senior management and the agency's National Institute of Standards and Technology (NIST) staff on the development of encryption policy. In addition, he represented the Department on the National Security Council¹s inter-agency Task Force on Encryption and on Office of Management and Budget discussion groups. After the death of Secretary Brown, Mr. Sockowitz was appointed the Senior Advisor for the Small Business Administration.

Staff

Courtney Hill, Office Manager
Ms. Hill serves as the Cyber Secure Institute's Office Manager and as an Administrative Assistant with Book Hill Partners. She was previously the Office Coordinator at The Direct Marketing Association, Government Affairs Department. She graduated with a B.A. in Political Science from Marymount University in 2007.

John Benford, Associate
Mr. Benford serves as an Associate with the Cyber Secure Institute. He graduated from Iona College with a B.A. in History in 2006.