SecurityCentric is your source for Blog Aggregation in the Security industry

Clearance Applicants and Security Freezes on Credit Reports

 Mark As Read    

In 2018, theEconomic Growth, Regulatory Relief, and Consumer Protection Actwas signed into law, enabling those undergoing background investigations to keep a credit report security freeze in place without any impact to completion of the investigation. At the time, the Office of Personnel Management (OPM) provided guidance to all Federal agencies

MiraclePtr: protecting users from use-after-free vulnerabilities on more platforms

 Mark As Read    

Posted by Keishi Hattori, Sergei Glazunov, Bartek Nowierski on behalf of the MiraclePtr team Welcome back to our latest update on MiraclePtr, our project to protect against use-after-free vulnerabilities in Google Chrome. If you need a refresher, you can read our previous blog post detailing MiraclePtr and its objectives. More platforms We are ...

Contractor Overcomes QAnon and Three-Percenter Concerns to Get Clearance

 Mark As Read    

There were only two Defense Office of Hearing and Appeals (DOHA) cases involving the Allegiance guideline this year. This one involved a DoD contractor who had shown a more than passing interest into the anti-establishment conspiracy theorist group called QAnon, and militia extremists who call themselves Three-Percenters (III%). He was

Registered Sex Offender Denied Clearance

 Mark As Read    

Every once in a while, I run across an appeals case that makes me shake my head and wonder why on earth they tried applying for a job that required a security clearance. This particular one takes the cake. The applicant was initially denied clearance eligibility by the DoD based

Hardening cellular basebands in Android

 Mark As Read    

Posted by Ivan Lozano and Roger Piqueras Jover Androids defense-in-depth strategy applies not only to the Android OS running on the Application Processor (AP) but also the firmware that runs on devices. We particularly prioritize hardening the cellular baseband given its unique combination of running in an elevated privilege and parsing untrusted...

Mozilla VPN Security Audit 2023

 Mark As Read    

To provide transparency into our ongoing efforts to protect your privacy and security on the Internet, we are releasing a security audit of Mozilla VPN that Cure53 conducted earlier this … Read more The post Mozilla VPN Security Audit 2023 appeared first on Mozilla Security Blog.

Mozilla Security Blog 140 days ago

Improving Text Classification Resilience and Efficiency with RETVec

 Mark As Read    

Elie Bursztein, Cybersecurity & AI Research Director, and Marina Zhang, Software EngineerSystems such as Gmail, YouTube and Google Play rely on text classification models to identify harmful content including phishing attacks, inappropriate comments, and scams. These types of texts are harder for machine learning models to classify because bad ...

Two years later: a baseline that drives up security for the industry

 Mark As Read    

Royal Hansen, Vice President of Privacy, Safety and Security Engineering, GoogleNearly half of third-parties fail to meet two or more of the Minimum Viable Secure Product controls. Why is this a problem? Because "98% of organizations have a relationship with at least one third-party that has experienced a breach in the last 2 years."In this post, w...

House Rejects Rule for HR 5393 FY 2024 CJS Spending

 Mark As Read    

Yesterday, the House took up H Res 869, the proposed rule for the consideration of HR 5893 [removed from paywall], the Commerce, Justice, Science, and Related Agencies Appropriations Act, 2024. After 55 minutes of debate (starting at 09:25 EST), the resolution failed by a vote of 198 to 225, with 19 Republicans voting with Democrats to defeat the r...

OMB Approves PSA/CSA ICR Reinstatement

 Mark As Read    

Yesterday, the OMBs Office of Information and Regulatory Affairs (OIRA) announced that it had approved the reinstatement of an information collection request (ICR) from CISA on CISA Vulnerability Assessments. The 60-day ICR notice was published on July 10th, 2019. The 30-day ICR notice was published on November 14th, 2019. CISA allowed this ICR to ...

CSAT ICR Renewal Approved by OMB

 Mark As Read    

Yesterday, the OMBs Office of Information and Regulatory Affairs (OIRA) announced that it had approved an information collection request (ICR) renewal from CISA for Chemical Security Assessment Tool (CSAT). The 60-day ICR notice was published on December 12th, 2022 and the 30-day ICR notice was published on April 20th, 2023. Nothing of specific int...

HR 6363 Passed in House Ladder CR

 Mark As Read    

Yesterday, the House took up HR 6363, the Further Continuing Appropriations and Other Extensions Act, 2024. After about 36 minutes of debate (starting at about 4:02 EST), the bill was passed by a bipartisan vote of 336 to 95 with 93 Republicans voting Nay. The bill now goes to the Senate where it is expected (after potential procedural delays) to p...

House Begins Consideration of HR 5894, FY 2024 LHH Spending

 Mark As Read    

Yesterday, the House began consideration of HR 5894, the Departments of Labor, Health and Human Services, and Education, and Related Agencies Appropriations Act, 2024. This is the first time in a number of years that the House has considered an LHH spending bill because of the controversies (both ways) surrounding various abortion provisions typica...

CSB Updates Recommendation Status 11-09-23

 Mark As Read    

Yesterday, the Chemical Safety Board updated the status from Open to Closed for of one of the recommendations from the Optima Belle investigation. The change in status of recommendation 2021-02-I-WV-R14 reflects the fact that the National Center for Biotechnology Information has updated the PubChem database entry for sodium dichloroisocyanurate (Na...

EPA Sends TSCA Fee Adjustment Final Rule to OMB

 Mark As Read    

Yesterday, OMBs Office of Information and Regulatory Affairs announced that it had received a final rule from the EPA on Fees for the Administration of the Toxic Substances Control Act (TSCA). The EPA is required to periodically (every three years) update the fees it charges for the administration of the TSCA program. This would be the first adjust...

Short Takes 11-14-23

 Mark As Read    

Trumps incendiary vermin remarks prompt backlash. TheHill.com article. Pull quote: The Trump campaign rejected comparisons between Trump and old dictators, with spokesperson Steven Cheung saying in a statement that those who try to make that ridiculous assertion are clearly snowflakes grasping for anything because they are suffering from Trump Dera...

November 2023 SecKC Presentation: Mobile SDR

 Mark As Read    

Thanks to all who showed up and asked questions! We are proud members of the Security Bloggers Network. This content originally posted on HiR Information Report. Copyright 1997-2010, HiR

HiR Information Report 162 days ago

OSHA Walk Around Inspection Rule and CFATS

 Mark As Read    

Today I read a press release from the Alliance for Chemical Distribution (formerly the National Association of Chemical Distributors) on the OSHA Worker Walkaround Representative Designation Process notice of proposed rulemaking (NPRM) that was published on August 30th, 2023. The comment period closed on Monday. Not surprisingly, ACD (and probably ...

Review 2 Advisories Published 11-14-23

 Mark As Read    

Today, CISAs NCCIC-ICS published two control system security advisories for products from Rockwell Automation and AVEVA. Advisory Rockwell Advisory - This advisory discusses an improper input validation vulnerability in the Rockwell SIS Workstation and ISaGRAF Workbench. AVEVA Advisory - This advisory describes two vulnerabilities in the AVEVA O...

Review - HR 6363 Introduced Ladder CR

 Mark As Read    

Yesterday, Rep Granger (R,TX) introduced HR 6363, the Further Continuing Appropriations and Other Extensions Act, 2024. Colloquially known as a Ladder CR, the bill continues current funding for some programs (of the Federal Government through January 19th, 2024 and through February 2nd, 2024. It also includes a section that extends the termination ...

Coast Guard Sends Cybersecurity NPRM to OMB

 Mark As Read    

Yesterday, the OMBs Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the Coast Guard on Cybersecurity in the Marine Transportation System. According to the Spring 2023 Unified Agenda entry for this rulemaking: The Coast Guard proposes to update its maritime security regu...

Bills Introduced 11-13-23

 Mark As Read    

Yesterday, with both the House and Senate in Session, there were 42 bills introduced. Two of those bills may receive additional coverage in this blog: HR 6363 Further Continuing Appropriations and Other Extensions Act, 2024 Granger, Kay [Rep.-R-TX-12] HR 6372 To amend the National Quantum Initiative Act to require the Secretary of Energy to cond...

Short Takes 11-13-23

 Mark As Read    

How Ukraine, With No Warships, Is Thwarting Russias Navy. NYTimes.com article (free). Pull quote: Despite having no warships of its own, Ukraine has over the course of the war shifted the balance of power in the naval conflict. Its use of unmanned maritime drones and growing arsenal of long-range anti-ship missiles along with critical surveillance...

Review - HR 5893 Introduced FY 2024 CJS Spending

 Mark As Read    

Last month, Rep Rogers (R,KY) introduced HR 5893, the Commerce, Justice, Science, and Related Agencies Appropriations Act, 2024. The House Appropriations Committee did not publish a report for this bill, nor has it published an explanatory text as it did for HR 5894. There are three cybersecurity mentions in the bill, none of particular interest he...

Intent to Keep Using Illegal Drugs = Public Trust Denial

 Mark As Read    

It would be safe to say that most, if not all, government workers know that using drugs is not copasetic or in line with the Drug-Free Federal Workplace policy. This applies to all tiers of investigations, not just security clearance applicants. When I find Defense Office of Hearing and Appeals

Committee Hearings Week of 11-12-23

 Mark As Read    

This week, with both the House and Senate in session and the latest funding deadline set for Friday midnight, there is a modest hearing schedule in the both houses. For the purposes of this blog, there are three hearings of interest (all in the House); a homeland threat hearing and two rules hearings. Homeland Security Threat On Wednesday, the Ho...

CFSN Production Milestone

 Mark As Read    

This post marks the 1000th blog post here for this year, kind of a magic number for bloggers. That, combined with the 585 blog posts over on my Substack site, CFSN Detailed Analysis, makes this, hands-down, my most prolific year as a writer to date. A lot of that is due to the contentious nature of the House in the 118th Congress, they have provide...

Short Takes 11-11-23

 Mark As Read    

Senate Leaders Plan to Prolong NSA Surveillance Using a Must-Pass Bill. Wired.com article. Pull quote: Extending the program by attaching it to another bill that Congress cant avoid is a risky political maneuver that will cause significant unrest among a majority of House lawmakers and a number of senators who are working to reform the 702 program....

Review Public ICS Disclosures Week of 11-4-23 Part 2

 Mark As Read    

For Part 2 this week we have nine additional vendor advisories from HP, Palo Alto Networks, Pilz, QNAP (2), Supermicro, Weidmller, Zebra, and Zyxel. There are ten updates for products from Broadcom (7), Cisco (2), and HPE. Finally, we have a researcher report of vulnerabilities in products from Weston. Advisories HP Advisory - HP published an adv...

CRS Reports Week of 11-4-23 Armed Drones

 Mark As Read    

This week the Congressional Research Service (CRS) published a report on Armed Drones: Evolution as a Counterterrorism Tool. This is a brief review of the evolution of the policy issues surrounding the use of armed drones as a counter-terrorism weapon. Missing from this is any discussion about how the successes that the US has had with drones as w...

Chemical Incident Reporting Week of 11-4-23

 Mark As Read    

NOTE: See here for series background. Graham, TX 11-2-23 Local New Reports: Here, here, and here. Explosion in sodium hypochlorite (industrial strength bleach) tank at water treatment plant. 1 injured and hospitalized. Details are sketchy, but it sounds like truck unloading incident, where something other than sodium hypochlorite into the tank...

Review Public ICS Disclosures Week of 11-4-23 Part 1

 Mark As Read    

This week we have 23 vendor disclosures from Broadcom (15), Fuji Electric, GE Gas Power, GE Grid Solutions (4), and Hitachi (2). Advisories Broadcom Advisory #1 - Broadcom published an advisory that discusses an unquoted search path or element vulnerability in their Fabric OS. Broadcom Advisory #2 - Broadcom published an advisory that describes ...

Short Takes 11-10-23

 Mark As Read    

Terrorist who tried to attack Jewish school in Indianapolis charged with 3 felonies. Fox59.com article. Pull quote: In reality, however, the building targetted by Almaghtheh was used by the Israelite School of Universal and Practical Knowledge a sect of Black Hebrew Israelites labeled by the Anti-Defamation League as extreme and antisemitic and cl...

Review - TSA Publishes BASE Program 60-day ICR Revision Notice

 Mark As Read    

Today, the Transportation Security Administration (TSA) published a 60-day information collection request (ICR) revision notice in the Federal Register (88 FR 77602-77603) for their Baseline Assessment for Security Enhancement (BASE) Program (1652-0062) for public transportation passenger rail (PTPR) and highway and motor carrier (HWY) industries. ...

House Continues Consideration of HR 4664 FY 2024 FinServices Spending

 Mark As Read    

Yesterday, the House continued consideration of HR 4664, the Financial Services and General Government Appropriations Act, 2024. The last four amendments listed in Part B of H Rept 118-269 were considered and three were adopted. The House recessed for the Veterans Day weekend without taking a vote on the amended bill. TheHill.com is reporting that...

Bills Introduced 11-9-23

 Mark As Read    

Yesterday, with the House and Senate in session (and preparing to observe Veterans Day today), there were 85 bills introduced. Two of those bills will receive additional attention in this blog: HJ Res 100 Providing for congressional disapproval under chapter 8 of title 5, United States Code, of the rule submitted by the Securities and Exchange Com...

Review - HR 5894 Introduced FY 2024 LHH Spending

 Mark As Read    

Last month, Rep Aderholt (R,AL) introduced HR 5894, the Departments of Labor, Health and Human Services, and Education, and Related Agencies Appropriations Act, 2024. There is no report from the House Appropriations Committee on this legislation, instead the Committee staff has published an explanatory materials document, reflecting the fact that t...

Review 2 Advisories and 2 Updates Published 11-9-23

 Mark As Read    

Today, CISAs NCCIC-ICS published two control system security advisories for products from Hitachi Energy and Johnson Controls. They also updated two control systems security advisories for products from Hitachi Energy and Mitsubishi Electric. Advisories Hitachi Energy Advisory - This advisory describes three vulnerabilities in the Hitachi Energy ...

House Begins Consideration of HR 4664 FY 2024 FinServices Spending

 Mark As Read    

Yesterday, the House began consideration of HR 4664, the Financial Services and General Government Appropriations Act, 2024. There were 65 amendments considered yesterday, with one of those being an en bloc amendment for the consideration 22 non-controversial amendments listed in Part B of H Rept 118-269. Fifty-one of the offered amendments were ag...

Short Takes 11-8-23

 Mark As Read    

Lucy continues to surprise astronomers with its first flyby. ArsTechnica.com article. Pull quote: A few days ago, the Daily Telescope reported that the Lucy spacecraft had found not one but two asteroids during its flyby of the small main-belt asteroid Dinkinesh. It turns out that was not the whole story. Subsequent data downlinked from the spacecr...

HR 6022 Introduced CFATS Propane Exception

 Mark As Read    

Last month, Rep Burlison (R,MO) introduced HR 6022, the Propane Accessibility and Regulatory Relief Act. The bill would exempt from any CFATS regulation any propane tank with a capacity of up to 126,000 pounds of propane. No funding is authorized by this legislation. Moving Forward Neither Burlison, nor his sole cosponsor {Rep Latta (R,OH)} are m...

Evolving the App Defense Alliance

 Mark As Read    

Posted by Nataliya Stanetsky, Android Security and Privacy Team The App Defense Alliance (ADA), an industry-leading collaboration launched by Google in 2019 dedicated to ensuring the safety of the app ecosystem, is taking a major step forward. We are proud to announce that the App Defense Alliance is moving under the umbrella of the Linux Foundat...

CSB Updates 1 Safety Recommendation Status 10-31-23

 Mark As Read    

Yesterday, the Chemical Safety Board (CSB) updated their Recommendations page to show 146 open recommendations, down one from the previous day. The also updated their Recent Recommendation Status Updates page to show a change in the status of the National Fire Protection Association (NFPA) recommendation from their Oil Tank Safety Study. The Octob...

House Continued Consideration of HR 4820 FY 2024 THUD Spending 11-7-23

 Mark As Read    

Yesterday, the House continued consideration of HR 4820, the Transportation, Housing and Urban Development, and Related Agencies (THUD) Appropriations Act, 2024. Thirty-three amendments were considered and 21 of those were adopted. None of the amendments were of specific interest here. Of the five amendments initially considered on Monday, but held...

Short Takes 11-7-23

 Mark As Read    

Senate eyes huge maxi-bus to address year-end spending crunch. TheHill.com article. Pull quote: At least if there is a decision made by the leaders to put all nine of the remaining bills together, at least theyre bills that have gone through committee, [have] been vetted, will be subject to amendment, are not drafted by just a few people behind clo...

PHMSA Portal IE7 Requirement

 Mark As Read    

Today, while looking for some information on DOTs Pipeline and Hazardous Materials Safety Administration (PHMSA) web site to answer a reader question, I ran across an interesting piece of information in a text window on the PHMSA Portal page: Microsoft deprecated IE7 on October 10th, 2023. PHMSA should not have been caught by surprise as Microsoft...

Review 1 Advisory Published 11-7-23

 Mark As Read    

Today, CISAs NCCIC-ICS published a control system security advisory or product from GE Grid Solutions. Advisories GE Advisory - This advisory describes an uncontrolled search path vulnerability in the GE MiCOM S1 Agile engineering tool suite. For more information about this advisory and its related GE disclosures, see my article at CFSN Detai...

House Begins Consideration of HR 4820 FY 2024 THUD Spending

 Mark As Read    

Yesterday, the House began consideration of HR 4820, the Transportation, Housing and Urban Development, and Related Agencies (THUD) Appropriations Act, 2024. Eleven amendments were considered and four were adopted. One of the adopted amendments was an en bloc amendment that included 24 non-controversial amendments. Five of the amendments considered...

Security
Welcome!
SecurityCentric aggregates blogs for the Security industry.
Custom Feeds
Add any RSS feed to the information you read daily.
Blocked Feeds
Block feeds to remove blogs you’re not interested in.
Account Settings
Customize the site by adding or removing feeds.

About Us

SecurityCentric is your source for all your Security news.

Have a Suggestion for Us?
Know of a Security blog that we're missing? Let us know!

Share SecurityCentric.com