{"id":66,"date":"2019-04-24T16:03:42","date_gmt":"2019-04-24T16:03:42","guid":{"rendered":"https:\/\/firwl.qantumthemes.xyz\/installer\/?p=66"},"modified":"2020-06-29T13:37:10","modified_gmt":"2020-06-29T13:37:10","slug":"news-article-12","status":"publish","type":"post","link":"https:\/\/tourabs.com\/index.php\/2019\/04\/24\/news-article-12\/","title":{"rendered":"DHS issues emergency Directive to prevent DNS hijacking attacks"},"content":{"rendered":"\n<p class=\"has-drop-cap\">DHS has issued a notice of a CISA emergency directive urging federal agencies of improving the security of government-managed domains (i.e. .gov) to prevent DNS hijacking attacks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">All the details<\/h3>\n\n\n\n<p>Using the following techniques, attackers have redirected and intercepted web and mail traffic, and could do so for other networked services.<\/p>\n\n\n\n<p>The emergency directive requests federal agencies to check public DNS records for all .gov and other domains they manage to ensure that they have not been tampered with. The check must be completed in 10 days and includes Address (A), Mail Exchanger (MX), and Name Server (NS) records.<\/p>\n\n\n\n<p>Within 10 business days, agencies will have to change the passwords for their DNS account and enable multifactor authentication where available, but CISA warns risks for SMS-based MFA.<\/p>\n\n\n\n<p>DHS also instructed federal agencies to monitor Certificate Transparency logs for any abuse related to fraudulently issued certificates.<\/p>\n\n\n\n<p>The overall process and signs of progress will be monitored by the DHS, the agencies must submit a status report by January 25 and a final report for all the actions done in compliance with the directive by February 5.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">The gallery<\/h3>\n\n\n\n<figure class=\"wp-block-gallery columns-4 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\"><ul class=\"blocks-gallery-grid\"><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-2504-1170x781.jpg\"><img decoding=\"async\" src=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-2504-1170x781.jpg\" alt=\"\" data-id=\"914\" data-link=\"https:\/\/firwl.qantumthemes.xyz\/installer\/post-2504\/\" class=\"wp-image-914\"\/><\/a><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-2157-1170x811.jpg\"><img decoding=\"async\" src=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-2157-1170x811.jpg\" alt=\"\" data-id=\"913\" data-link=\"https:\/\/firwl.qantumthemes.xyz\/installer\/post-2157\/\" class=\"wp-image-913\"\/><\/a><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-775-1170x949.jpg\"><img decoding=\"async\" src=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-775-1170x949.jpg\" alt=\"\" data-id=\"912\" data-link=\"https:\/\/firwl.qantumthemes.xyz\/installer\/post-775\/\" class=\"wp-image-912\"\/><\/a><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-388-1170x658.jpg\"><img decoding=\"async\" src=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-388-1170x658.jpg\" alt=\"\" data-id=\"911\" data-link=\"https:\/\/firwl.qantumthemes.xyz\/installer\/post-388\/\" class=\"wp-image-911\"\/><\/a><\/figure><\/li><li class=\"blocks-gallery-item\"><figure><a href=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-384-1170x781.jpg\"><img decoding=\"async\" src=\"https:\/\/firwl.qantumthemes.xyz\/installer\/wp-content\/uploads\/2019\/05\/post-384-1170x781.jpg\" alt=\"\" data-id=\"910\" data-link=\"https:\/\/firwl.qantumthemes.xyz\/installer\/post-384\/\" class=\"wp-image-910\"\/><\/a><\/figure><\/li><\/ul><\/figure>\n\n\n\n<p><em>In coordination with government and industry partners, the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) is tracking a series of incidents<\/em><sup><a href=\"https:\/\/cyber.dhs.gov\/ed\/19-01\/#fn:1\"><em>1<\/em><\/a><\/sup><em>involving Domain Name System (DNS) infrastructure tampering. CISA is aware of multiple executive branch agency domains that were impacted by the tampering campaign and has notified the agencies that maintain them.\u201d <\/em><\/p>\n\n\n\n<p><em>\u201cTo address the significant and imminent risks to agency information and information systems presented <\/em><em>by<\/em><em> this activity, this emergency directive requires the following near-term actions to mitigate risks from undiscovered tampering, enable agencies to prevent illegitimate DNS activity for their domains, and detect unauthorized certificates.\u201d<\/em><\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Scanning for vulnerabilities<\/h3>\n\n\n\n<p>\u00a0All businesses need a way to detect vulnerabilities on their networks. This is especially true for larger businesses and those with sensitive data\u2014banking, government, finance, law, health care, and education are all industries in which safeguarding network data and infrastructure is paramount. But smaller businesses must also ensure their information is secure, without pouring all their IT time and resources into the task.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DHS has issued a notice of a CISA emergency directive urging federal agencies of improving the security of government-managed domains (i.e. .gov) to prevent DNS hijacking attacks. All the details Using the following techniques, attackers have redirected and intercepted web and mail traffic, and could do so for other networked ...<\/p>\n","protected":false},"author":1,"featured_media":913,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3,5],"tags":[8,9,10,11,12,13],"class_list":["post-66","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","category-globalnews","tag-cyber-security-alert","tag-internet","tag-ransomware","tag-security","tag-trojan","tag-virus"],"_links":{"self":[{"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/posts\/66","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/comments?post=66"}],"version-history":[{"count":2,"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/posts\/66\/revisions"}],"predecessor-version":[{"id":1484,"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/posts\/66\/revisions\/1484"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/media\/913"}],"wp:attachment":[{"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/media?parent=66"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/categories?post=66"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tourabs.com\/index.php\/wp-json\/wp\/v2\/tags?post=66"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}