On Executive Order 12333

Mark Jaycox has written a long article on the US Executive Order 12333: “No Oversight, No Limits, No Worries: A Primer on Presidential Spying and Executive Order 12,333“:

Abstract: Executive Order 12,333 (“EO 12333”) is a 1980s Executive Order signed by President Ronald Reagan that, among other things, establishes an overarching policy framework for the Executive Branch’s spying powers. Although electronic surveillance programs authorized by EO 12333 generally target foreign intelligence from foreign targets, its permissive targeting standards allow for the substantial collection of Americans’ communications containing little to no foreign intelligence value. This fact alone necessitates closer inspection.

This working draft conducts such an inspection by collecting and coalescing the various declassifications, disclosures, legislative investigations, and news reports concerning EO 12333 electronic surveillance programs in order to provide a better understanding of how the Executive Branch implements the order and the surveillance programs it authorizes. The Article pays particular attention to EO 12333’s designation of the National Security Agency as primarily responsible for conducting signals intelligence, which includes the installation of malware, the analysis of internet traffic traversing the telecommunications backbone, the hacking of U.S.-based companies like Yahoo and Google, and the analysis of Americans’ communications, contact lists, text messages, geolocation data, and other information.

After exploring the electronic surveillance programs authorized by EO 12333, this Article proposes reforms to the existing policy framework, including narrowing the aperture of authorized surveillance, increasing privacy standards for the retention of data, and requiring greater transparency and accountability.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Texas Software Provider Reports Cyber-attack

Texas Software Provider Reports Cyber-attack

A cyber-attack has struck a Texas company that provides software services to schools and state and local governments across the United States.

Tyler Technologies notified customers on September 23 that its phone and computer systems had been compromised by a bad actor. 

Since the incident, the website of the company has carried the message: “Our Tyler Technologies corporate website is temporarily unavailable. We are aware of the issue and are working to bring the site back online.”

Customers are advised to visit Tyler’s Online Support Incidents tool for online support access.

In an email sent out to customers, the Plano-based company said that the cyber-incident was uncovered on Wednesday morning. The help of external IT specialists was subsequently enlisted by the company, and law enforcement was informed of the attack.

“Upon discovery and out of an abundance of caution, we shut down points of access to external systems and immediately began investigating and remediating the problem,” Tyler’s chief information officer, Matt Bieri, told KrebsonSecurity.

“We have since engaged outside IT security and forensics experts to conduct a detailed review and help us securely restore affected equipment. We are implementing enhanced monitoring systems, and we have notified law enforcement.”

Bieri went on to say that the extent of the attack appeared to be limited to the company’s internal network and phone systems. 

“We currently have no reason to believe that any client data, client servers, or hosted systems were affected,” said Bieri.

Yesterday, Tyler confirmed that the attack had involved ransomware. A statement on the company’s website reads: “We have confirmed that the malicious software the intruder used was ransomware. Because this is an active investigation, we will not provide any additional specifics relating to our incident response or our investigation at this time.” 

Tyler Technologies employs around 5,300 people. Last year the company brought in revenues of more than $1bn. 

Products sold by the company include appraisal and tax software, public safety software, integrated software for courts and justice agencies, records/document management software solutions, enterprise financial software systems, and transportation software solutions for schools.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

US Federal Agency Compromised by Cyber-Actor

US Federal Agency Compromised by Cyber-Actor

warning has been issued by America’s Cybersecurity and Infrastructure Security Agency (CISA) after a malicious cyber-actor compromised a United States federal agency. 

The attacker used valid log-in credentials for multiple users’ Microsoft Office 365 accounts and domain administrator accounts to gain access to the agency’s enterprise network. Once inside, the bad actor infected the network with sophisticated malware.

“By leveraging compromised credentials, the cyber threat actor implanted sophisticated malware—including multi-stage malware that evaded the affected agency’s anti-malware protection—and gained persistent access through two reverse Socket Secure (SOCKS) proxies that exploited weaknesses in the agency’s firewall,” said CISA in a statement released yesterday.

CISA was alerted to a potential compromise of a federal agency’s network via EINSTEIN, an intrusion detection system that monitors federal civilian networks.

Malicious activity was confirmed during an investigation launched by CISA in conjunction with the affected agency.

Investigators found the threat actor logged into a user’s Office 365 account remotely, then browsed pages on a SharePoint site and downloaded a file. The threat actor then connected multiple times by Transmission Control Protocol to the victim organization’s virtual private network (VPN) server.

“Immediately afterward, the threat actor used common Microsoft Windows command line processes—conhost, ipconfig, net, query, netstat, ping and whoami, plink.exe—to enumerate the compromised system and network,” stated CISA.

The cyber-criminal copied files and exfiltrated the data via a Microsoft Windows Terminal Services client. Further attacks were planned, as the intruder created a backdoor. 

CISA analysts were not able to determine how the cyber threat actor initially obtained the credentials used in the attack; however, they did come up with a theory involving Pulse Secure.

“It is possible the cyber actor obtained the credentials from an unpatched agency VPN server by exploiting a known vulnerability—CVE-2019-11510—in Pulse Secure,” stated CISA, adding that it “has observed wide exploitation of CVE-2019-11510 across the federal government.”

The error allows the remote, unauthenticated retrieval of files, including passwords. Patches were released by Pulse Secure in April 2019 for several critical vulnerabilities, including CVE-2019-11510.

No details of when the attack took place or which agency was compromised have been released. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk