#cisa-leadership-change

[ follow ]
fromComputerworld
1 day ago

A core infrastructure engineer pleads guilty to federal charges in insider attack

Rhyne's attack involved unauthorized remote desktop sessions, deletion of network administrator accounts, and changing of passwords, showcasing significant security vulnerabilities.
Information security
#cisa
US politics
fromTheregister
1 day ago

Trump wants to slash $707M from CISA's budget

CISA faces a proposed $707 million budget cut, risking national cybersecurity and critical infrastructure management.
Intellectual property law
fromNextgov.com
1 day ago

Tech bills of the week: Limiting adversaries' access to US tech; and boosting cyber apprenticeships

New legislation aims to strengthen U.S. export controls on sensitive technologies to prevent adversaries from exploiting them for economic gain.
France news
fromThe Local France
2 days ago

Citigroup orders home-working as US banks in Paris and Frankfurt tighten security

Citigroup has instructed employees in Paris and Frankfurt to work from home due to heightened security concerns following a thwarted attack on a US bank.
fromNextgov.com
4 days ago

HHS reverses Biden-era restructuring of its IT and tech operations

HHS Chief Information Officer Clark Minor stated that consolidating the CTO, CDO, and CAIO roles within his office allows the department to move faster on shared platforms and protect systems more effectively.
Healthcare
fromNextgov.com
3 days ago

Agency CIOs must supply top-down IT contract information, OMB memo states

What we want to do is make sure that CIOs are fully empowered to be there at the beginning of conversations, that they are part of the formulation of budget and policy from liftoff.
Privacy professionals
#dhs
fromNextgov.com
1 day ago
US politics

President's budget proposes folding beleaguered DHS intelligence office into headquarters

US politics
fromIntelligencer
5 days ago

DHS Is Still Shut Down Because Extremists Own Mike Johnson

The Department of Homeland Security faces the longest partial government shutdown in U.S. history due to congressional disagreements over funding and immigration enforcement.
fromThe Atlantic
1 week ago
US politics

How to Fix DHS

The core issue with DHS is not leadership changes but systemic problems within the agency itself.
SF politics
fromNextgov.com
5 days ago

DHS drops investigation into former acting CISA chief's failed polygraph exam

DHS closed an investigation into CISA staff who arranged a polygraph for the former acting director, clearing them of wrongdoing.
US politics
fromNextgov.com
1 day ago

President's budget proposes folding beleaguered DHS intelligence office into headquarters

The Department of Homeland Security's intelligence office faces consolidation and potential workforce reductions under Trump's proposed budget for 2027.
US politics
fromIntelligencer
5 days ago

DHS Is Still Shut Down Because Extremists Own Mike Johnson

The Department of Homeland Security faces the longest partial government shutdown in U.S. history due to congressional disagreements over funding and immigration enforcement.
Remote teams
fromTheregister
5 days ago

Security contractor blew the whistle on shabby support crew

Brad, a security contractor, faced challenges with antivirus alerts while working in a labor hire company's office without proper IT support.
#data-breach
EU data protection
fromTheregister
5 days ago

European Commission admits breach of public web systems

The European Commission confirmed a data breach affecting its public web infrastructure, with details on the extent and nature of the data taken remaining unclear.
Information security
fromTheregister
2 days ago

The company's biggest security hole lived in the breakroom

An internet-connected coffee machine caused a major data breach by exploiting security vulnerabilities in a corporate network.
EU data protection
fromTheregister
5 days ago

European Commission admits breach of public web systems

The European Commission confirmed a data breach affecting its public web infrastructure, with details on the extent and nature of the data taken remaining unclear.
Information security
fromTheregister
2 days ago

The company's biggest security hole lived in the breakroom

An internet-connected coffee machine caused a major data breach by exploiting security vulnerabilities in a corporate network.
Careers
fromFuturism
6 days ago

Top ICE Official Falling Apart Medically Due to Stress of Getting Yelled At

Managing ICE has caused Todd Lyons significant stress, leading to hospital visits and impacting his decision-making ability.
Podcast
fromSecuritymagazine
1 week ago

What Does It Take to Be an Outstanding CSO or CISO?

Outstanding security leaders often come from non-traditional backgrounds, with 40% of recent CSO-CISO Hall of Fame honorees starting in the private sector.
#cybersecurity
Privacy professionals
fromTechRepublic
5 days ago

Iran-Linked Hackers Breach FBI Director Kash Patel's Email, Leak Messages Online

An Iran-linked hacking group breached FBI Director Kash Patel's personal email, releasing non-sensitive information as a retaliatory cyber attack.
Information security
fromTheregister
1 week ago

Jen Easterly, cybersecurity's 'relentless optimist'

Cybersecurity and AI are now inseparable, reshaping the digital ecosystem and emphasizing community collaboration for a secure digital world.
Information security
fromSecuritymagazine
1 day ago

Stakeholder Confidence in the Age of Digital Threats: PR as a Security Asset

Cybersecurity involves both technical measures and effective communication to maintain stakeholder trust during incidents.
Privacy professionals
fromTechRepublic
5 days ago

Iran-Linked Hackers Breach FBI Director Kash Patel's Email, Leak Messages Online

An Iran-linked hacking group breached FBI Director Kash Patel's personal email, releasing non-sensitive information as a retaliatory cyber attack.
Information security
fromTheregister
1 week ago

Jen Easterly, cybersecurity's 'relentless optimist'

Cybersecurity and AI are now inseparable, reshaping the digital ecosystem and emphasizing community collaboration for a secure digital world.
SF politics
fromNextgov.com
5 days ago

New contract for background investigations raises concerns about scale and risk

DCSA is modernizing its Case Processing Operations Center to enhance background investigations and incorporate Continuous Vetting for national security.
US politics
fromwww.npr.org
1 day ago

As DOJ prepares to share state voter data with DHS, a key privacy officer resigns

The DOJ is acquiring sensitive voter registration data, raising privacy concerns, as a key privacy officer resigns amid ongoing legal challenges.
#cyberattack
Privacy professionals
fromTechCrunch
3 days ago

Hasbro says it was hacked, and may take 'several weeks' to recover | TechCrunch

Hasbro confirmed a cyberattack, prompting system shutdowns and ongoing investigations, with potential operational disruptions lasting several weeks.
Information security
fromNextgov.com
2 weeks ago

CISA, FBI have engaged with Stryker staff after cyberattack, official says

CISA and FBI are assisting Stryker in responding to a major cyberattack claimed by an Iran-aligned hacking group that disrupted employee access and systems worldwide.
Privacy professionals
fromTechCrunch
3 days ago

Hasbro says it was hacked, and may take 'several weeks' to recover | TechCrunch

Hasbro confirmed a cyberattack, prompting system shutdowns and ongoing investigations, with potential operational disruptions lasting several weeks.
Information security
fromNextgov.com
2 weeks ago

CISA, FBI have engaged with Stryker staff after cyberattack, official says

CISA and FBI are assisting Stryker in responding to a major cyberattack claimed by an Iran-aligned hacking group that disrupted employee access and systems worldwide.
#ai-security
fromInfoWorld
1 day ago
Information security

Claude Code leak puts enterprise trust at risk as security, governance concerns mount

Software development
fromThe Hacker News
2 weeks ago

How Ceros Gives Security Teams Visibility and Control in Claude Code

AI coding agents like Claude Code operate outside existing enterprise security controls, requiring new machine-level security infrastructure to provide visibility, policy enforcement, and audit trails.
Information security
fromInfoWorld
1 day ago

Claude Code leak puts enterprise trust at risk as security, governance concerns mount

Leaks threaten Anthropic's market position and raise security concerns about its AI coding tools.
Information security
fromThe Hacker News
2 weeks ago

AI is Everywhere, But CISOs are Still Securing It with Yesterday's Skills and Tools, Study Finds

Security leaders lack adequate tools and skills to defend AI systems, with visibility gaps and skills shortages creating critical vulnerabilities in AI infrastructure security.
Privacy professionals
fromFEDweek
6 days ago

Agencies Need More Complete Guidance on Privacy Considerations of AI Use, Says GAO

GAO identifies gaps in AI guidance, highlighting risks and the need for comprehensive privacy protections in agency implementations.
Washington DC
fromNextgov.com
4 weeks ago

DOD names James "Aaron" Bishop to serve as CISO

James Bishop, former Air Force CISO, appointed as Department of Defense's department-wide CISO and deputy chief information officer for cybersecurity, replacing retiring David McKeown.
Information security
fromSecurityWeek
4 days ago

The Next Cybersecurity Crisis Isn't Breaches-It's Data You Can't Trust

Data integrity now encompasses data trust, emphasizing the importance of reliable data in AI-driven decision-making.
SF politics
fromNextgov.com
4 weeks ago

Mullin's appointment to lead DHS raises questions about future of CISA

Trump appointed Oklahoma Senator Markwayne Mullin as DHS Secretary after firing Kristi Noem, amid CISA's significant workforce reductions and leadership instability.
fromNextgov.com
3 weeks ago

Lawmakers seek watchdog probe into former acting CISA chief's polygraph failures

We write with deep concern regarding the Department of Homeland Security's investigation into whether cybersecurity staff provided false information to the former Acting Director of the Cybersecurity and Infrastructure Security Agency. The lawmakers said the development raises questions about whether officials adhered to established intelligence security rules and whether career CISA staff were improperly targeted after administering the exams.
US politics
Privacy professionals
fromNextgov.com
2 weeks ago

National cyber director doesn't envision industry doing offensive hacking

The U.S. National Cyber Director clarifies that private sector companies will not conduct offensive cyber operations on behalf of the government, but will instead provide intelligence and defensive support.
US politics
fromTruthout
3 weeks ago

DHS Official Responsible for Election Security Previously Called to Ban Voting Machines

A DHS official overseeing election infrastructure security co-founded a company with someone who promoted debunked 2020 election conspiracy theories and has publicly called for banning voting machines.
SF politics
fromNextgov.com
1 month ago

Trump's CISA nominee said he left Coast Guard to address GOP hold

Sean Plankey left the Coast Guard to address concerns about shipbuilding ties that prompted Senator Rick Scott to place a hold on his CISA nomination.
Information security
fromComputerWeekly.com
1 week ago

Cyber pros must grasp the vibe coding nettle, says NCSC chief | Computer Weekly

Cyber security professionals must develop safeguards for AI-enhanced software generation to prevent vulnerabilities and cyber attacks.
fromSecurityWeek
3 weeks ago

Senate Confirms Joshua Rudd to Lead NSA and US Cyber Command

The U.S. Senate on Tuesday confirmed Army Lt. Gen. Joshua Rudd in a 71-29 Senate vote to lead the National Security Agency (NSA) and U.S. Cyber Command (CYBERCOM), filling a critical national security role that had remained vacant for nearly a year after the firing of the previous director, General Timothy Haugh, in April 2025.
US politics
Information security
fromReadWrite
1 week ago

The CISO Struggle: How AI is Changing the Data Security Landscape

Generative AI adoption is rapid, but security governance is lagging, creating significant risks for organizations.
Information security
fromComputerworld
2 weeks ago

CISA urges IT to harden endpoint management systems after cyberattack by pro-Iranian group

CISA urges organizations to harden endpoint management system configurations, particularly Microsoft Intune, following a pro-Iranian threat actor's compromise of Stryker's systems.
#cisa-leadership
Information security
fromSecurityWeek
2 weeks ago

CISA Flags Year-Old Wing FTP Vulnerability as Exploited

CISA warns that a year-old Wing FTP vulnerability (CVE-2025-47813) is being exploited in the wild, disclosing server installation paths that attackers can use to exploit critical remote code execution flaws.
US politics
fromNextgov.com
1 month ago

DOJ elevates deputy CIO to top IT role

Nikki Collier became the Department of Justice's permanent Chief Information Officer in February 2025, replacing Melinda Rogers who departed in May 2024.
#cybersecurity-leadership
Information security
fromSecuritymagazine
1 month ago

Shawn Fallah - Top Cybersecurity Leaders 2026

Shawn Fallah leads HSI's Cyber and Operational Technology directorate, overseeing technical law enforcement systems and a $1.1 billion budget while advancing modern security infrastructure to counter emerging threats.
Information security
fromSecuritymagazine
1 month ago

Shawn Fallah - Top Cybersecurity Leaders 2026

Shawn Fallah leads HSI's Cyber and Operational Technology directorate, overseeing technical law enforcement systems and a $1.1 billion budget while advancing modern security infrastructure to counter emerging threats.
#cisa-leadership-changes
fromDataBreaches.Net
1 month ago

CISA Releases New Guidance on Assembling Multi-Disciplinary Insider Threat Management Teams - DataBreaches.Net

CISA's guidance is intended to assist critical infrastructure stakeholders, which includes private sector entities across various sectors, with implementing an insider threat mitigation program that combines physical security, cybersecurity, personnel awareness, and community partnerships. Although framed for critical infrastructure, CISA's guidance is relevant to a broader range of organizations, including those outside of critical infrastructure sectors.
Information security
US politics
fromNextgov.com
1 month ago

Federal CIO tapped for dual-hatted role at GSA

Greg Barbaccia appointed acting director of GSA's Technology Transformation Services and senior advisor, adding to his federal CIO and chief AI officer responsibilities.
Information security
fromThe Verge
1 month ago

CISA is getting a new acting director after less than a year

CISA's acting director Madhu Gottumukkala is replaced by Nick Andersen following reports of uploading sensitive documents to ChatGPT, amid agency budget cuts and politicization under the Trump administration.
US politics
fromTheregister
2 months ago

CISA insider-threat warning comes with an ironic twist

Insider threats are among the most serious security risks and require multidisciplinary teams and decisive action to detect, mitigate, and prevent damage.
Information security
fromTechCrunch
1 month ago

US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs | TechCrunch

CISA has lost approximately one-third of its staff, compromising its cybersecurity mission capabilities and leaving the nation vulnerable to cyber threats.
fromSecuritymagazine
1 month ago

Strategies for Security Leaders in the Midst of Skill Shortages

Organizations have reported heightened cybersecurity risks as a result of these skill shortages, but the issues don't end there. Many teams will also experience burnout, which is an issue for security teams even in the best of times, which can only add to the talent gap concern if burnt out employees leave the industry.
Information security
US politics
fromNextgov.com
1 month ago

Inside the federal CIO's culture-first approach

Federal CIO Gregory Barbaccia prioritizes changing government technology culture to drive scalable reforms, build a digital front door, and strengthen agency engagement and compliance.
fromNextgov.com
1 month ago

OMB is hiring for a deputy federal chief information officer

The post has been without a permanent official since former Deputy Federal CIO Drew Myklegard departed OMB last September, though the website for the CIO Council lists Jay Teitelbaum as holding the position in an acting capacity. Myklegard joined the White House office in January 2022 and was named acting deputy federal CIO that March. The agency then elevated him to the permanent role in October 2022.
US politics
fromTheregister
1 month ago

CISA gives feds 3 days to patch actively exploited Dell bug

Uncle Sam's cyber defenders have given federal agencies just three days to patch a maximum-severity Dell bug that's been under active exploitation since at least mid-2024. CISA this week added the flaw, tracked as CVE-2026-22769, to its Known Exploited Vulnerabilities catalog, ordering civilian agencies to secure affected systems by February 21 - giving them just three days to get fixes in place.
Information security
US politics
fromNextgov.com
2 months ago

NSA alum returns to agency to serve as deputy director

Tim Kosiba was appointed NSA deputy director to lead operations, manage civilian leadership, set policy, and oversee execution of the agency's strategy.
Information security
fromThe Hacker News
1 month ago

CISA Flags Four Security Flaws Under Active Exploitation in Latest KEV Update

CISA added four actively exploited high-severity vulnerabilities to its KEV catalog, including Chrome use-after-free, TeamT5 arbitrary upload, Zimbra SSRF, and Windows ActiveX RCE.
fromWIRED
2 months ago

Former CISA Director Jen Easterly Will Lead RSA Conference

The organization puts on the prominent annual gathering of cybersecurity experts, vendors, and researchers that started in 1991 as a small cryptography event hosted by the corporate security giant RSA. RSAC is now a separate company with events and initiatives throughout the year, but its conference in San Francisco is still its flagship offering with tens of thousands of attendees each spring.
Information security
Information security
fromTechzine Global
1 month ago

CISA warns of active exploitation of critical SolarWinds vulnerability

A critical remote-code-execution vulnerability CVE-2025-40551 in SolarWinds Web Help Desk is actively exploited; federal agencies must install the patch within three days.
fromNextgov.com
1 month ago

AI info-sharing center is in development, CISA official says

We just want to make sure we've got the right elements of, how do we pull together people, and how do we take advantage of the leadership position that we have
Information security
fromDataBreaches.Net
2 months ago

Cyber Counterintelligence (CCI): Resecurity releases data on John Erin Binns (IRDev) - DataBreaches.Net

It may be a bit of an understatement to say that Resecurity has been up in the faces of ScatteredLapsus$Hunters and ShinyHunters. Not Only did they recently embarrass the former by deceiving them with a honeypot and providing law enforcement with details about the threat actor attempting to access the synthetic data, but now they have followed up with a new article about Connor Riley Moucka ("Waifu," "Judische," "Ellyel8"), Cameron John Wagenius ("Kiberphant0m"), and John Erin Binns ("IRDev," "IntelSecrets").
Information security
fromSecuritymagazine
2 months ago

CISO Salaries Continue to Rise Despite Economic Uncertainty

CISO compensation rose 6.7% in 2025 with equity growing faster than cash, security budgets slowed to 4%, and executive perks and equity prevalence increased.
fromNextgov.com
2 months ago

Katie Arrington departs DOD to rejoin private sector

"If you go on LinkedIn one more time and tell me how hard CMMC is, I'm going to beat you," she said at an AFCEA DC luncheon in April.
Information security
fromNextgov.com
2 months ago

Kirsten Davies sworn in as Pentagon CIO

Kirsten Davies has been sworn in as the Pentagon's chief information officer, giving the Defense Department its first permanent IT head during Trump 2.0. Davies was confirmed by the Senate on Dec. 18 as part of a group of tech nominations, which included Ethan Klein to be the U.S. chief technology officer and Pedro Allende to lead the Department of Homeland Security's Science and Technology office. The LinkedIn page for the DOD CIO office said Davies was officially sworn in on Dec. 23.
Information security
[ Load more ]