CISA Releases Apache Log4j Vulnerability Guidance
Through the Joint Cyber Defense Collaborative, CISA and its partners are responding to active, widespread exploitation of a critical remote code execution vulnerability (CVE-2021-44228) in Apache’s Log4j software library. Consumer and enterprise services and applications, as well as operational technology products, use Log4j. The specific versions affected are versions 2.0-beta9 to 2.14.1, known as "Log4Shell" and "Logjam." While Apache has released a security update, managers must actively implement the update.
CISA urges vendors and users to take the following actions:
- Identify internet-facing endpoints that use Log4j
- Ensure security operations center is actioning alerts on these devices
- Install a web application firewall with rules that automatically update
CISA Webinar: DHS Blue Campaign
Every year, millions of men, women, and children are trafficked worldwide, including right here in the United States. Traffickers might use violence, manipulation, or false promises of well-paying jobs or romantic relationships to lure victims into trafficking situations. Hear the Blue Campaign team discuss tools and resources to combat trafficking in a webinar on Thursday, December 16, 2021, 1:00 – 2:30 p.m. ET. Registration is required. The event will be recorded and posted to HSIN for future viewing. For more information, contact CISA Region 8: CISARegion8@hq.dhs.gov.
CISA Releases Updated CISA Services Catalog
CISA's Services Catalog "Catalog 2.0" is a centralized resource of information on services from all CISA mission areas. Catalog 2.0 provides information for federal, state, local, tribal and territorial governments; private industry; academia; non-governmental and non-profit organizations; as well as the public.
Catalog 2.0's interactive features enable users to request, share, and tag favorite capabilities, allowing them to quickly and seamlessly access information on services tailored to their needs. Catalog 2.0 is also mobile-friendly, allowing users to access the library while "on the go."
CISA Launches New ChemLock Program
CISA has launched a new, voluntary chemical security initiative: ChemLock.
ChemLock offers facilities a series of scalable, tailored options for enhancing their chemical security posture. Facilities can apply the most effective combination of services and tools that meet their unique circumstances and business models.
CISA services and tools include:
- On-site assessments and assistance;
- Fact sheets, best practices, and guidance documents;
- Exercises and drills;
- Training courses;
- Cyber Security Evaluation Tool; and
- Active shooter resources.
To sign up for any of these ChemLock services and tools, visit the ChemLock webpage.
2021 President's Cup Cybersecurity Competition Winners
CISA extends its congratulations to the winners of the just-concluded 2021 President's Cup Cybersecurity Competition. Established in 2019, the competition is a national cyber event that identifies, challenges, and rewards the best cybersecurity talent in the federal workforce. Take a look at the final round livestream on CISA's YouTube Channel, featuring commentary on the competitors’ progress, remarks from government officials, a look at making the competition, and interviews from across the federal workforce.
More information about the 2022 President's Cup Cybersecurity Competition will be released in Spring 2022.
2021 Chemical Security Seminars
CISA has concluded the 2021 Chemical Security Seminars, the signature industry event for chemical sector representatives. Hosted on December 1, 8, and 15, this year's seminars featured three days of events covering chemical and cybersecurity threats and countermeasures, and chemical security planning and preparedness.
Select presentations from the 2021 Chemical Security Seminars will be posted in the coming weeks on the Chemical Security Summit webpage. CISA thanks those who have contributed to and participated in the ongoing, collaborative efforts to enhance our Nation’s chemical security.
CISA Releases Request for Information (RFI) on Federal Network Protection
CISA and its partners released this RFI to help protect federal networks and the “.gov” domain enterprise from threats while strengthening cyber defenses. CISA requests information on email security capabilities and tools, including input from entities that have delivered similar solutions to the government or private sector. This information will assist in refining solution design, use cases, and functional requirements. Responses are due December 15, 2021.
CISA Hosts Strategic Assessment Interviews
CISA’s Emergency Communications Preparedness Center (ECPC) will host interviews and events in preparation for its annual strategic assessment. The assessment, submitted to Congress, relates emergency responders' capability and coordination efforts to advance interoperable emergency communications. The ECPC will conduct department and agency interviews from now through January. The center will host a workshop to prepare its findings in March. ECPC encourages all public safety communications management experts to get involved.
CISA Hosts Webinar on the Ransomware Threat to Emergency Communications
On October 26, CISA held a webinar entitled, “Addressing the Ransomware Threat to Emergency Communications” as part of its effort to implement the National Emergency Communications Plan (NECP). The NECP focuses on helping public safety organizations establish proactive measures to manage cybersecurity risks, including against the increasing threat of ransomware. The webinar offered case studies, resources, and guidance. For a copy of the slides, email necp@cisa.dhs.gov.
|