{"id":4571,"date":"2024-07-22T09:00:00","date_gmt":"2024-07-22T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/kaspersky-is-unacceptable-risk-threatening-nations-cyber-defense"},"modified":"2024-07-22T09:00:00","modified_gmt":"2024-07-22T14:00:00","slug":"kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/22\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense\/","title":{"rendered":"Kaspersky Is an Unacceptable Risk Threatening the Nation&#8217;s Cyber Defense"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blta4dde16a031d6a50\/669e65d9236343d6fbf24570\/Geopolitics%281800%29_rico_ploeg_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The current state of play with <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/cyberattacks-wreaking-physical-disruption-on-the-rise\" rel=\"noopener\">rising cyberattacks<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/geopolitical-conflicts-5-ways-to-cushion-the-blow\" rel=\"noopener\">geopolitical tension<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> is proving to pose significant threats to national security. The recent announcement by the US federal government to&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/kaspersky-us-customers-deadline-govt-ban\" rel=\"noopener\">ban Kaspersky software<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, effective July 20, will prevent Kaspersky from selling its products in the United States, as well as restrict software updates and resales. This ruling comes on the heels of growing tensions with Russia.&nbsp;A Russian national was recently indicted for <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/opa\/pr\/russian-national-charged-conspiring-russia-military-intelligence-destroy-ukrainian\" rel=\"noopener\">conspiring with Russian military intelligence<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;to destroy Ukraine computer systems as part of cyberattacks.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This tension has been mounting, and Kaspersky is in the crossfire, for good reason. Kaspersky has long been a Russia-based company that the United States has deemed a foreign adversary, and Kaspersky is subjected to the&nbsp;jurisdiction, control, or direction of the Russian government, as cited in the&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.federalregister.gov\/documents\/2024\/06\/24\/2024-13532\/final-determination-case-no-icts-2021-002-kaspersky-lab-inc\" rel=\"noopener\">Final Determination order<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Undue and Unacceptable Risk\">Undue and Unacceptable Risk<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The order cites significant cybersecurity threats that pose undue and unacceptable risk to national security centered around strategic exploitation, primarily exposure and access to sensitive information, exploiting known software vulnerabilities to gain unauthorized access, lack of threat coverage and signatures, and access to install malicious software for backdoors. While evidence regarding the plausibility and likelihood of successful strategic exploitation has not been published, experts contend that these threat scenarios are serious enough given the review of documents and information Kaspersky provided regarding its mitigation measures to address cybersecurity risk.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In the end, Kaspersky did not provide any new or substantial information to counter the concerns regarding undue and unacceptable risk. Given the state of play, and the ongoing concerns over Russia&#8217;s cyber operations targeting US critical infrastructure, Ukraine, and other multinational partners, the Final Determination is not surprising. In fact, many believed that this should have happened back in 2017, when Kaspersky was banned for use in government environments.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"The Foreign Software Supply Chain Threat\">The Foreign Software Supply Chain Threat<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Vendors&#8217; software supply chains become an attractive attack vector for nation-state adversaries to exploit and target organizations. Oftentimes, these software supply chain attacks are carried out using zero-day attacks, or by exploiting known&nbsp;CVEs&nbsp;in the wild. For widely used software, vulnerability prevalence becomes a key driver in expanding the blast radius in cyberattacks that allow threat actors to use extortion techniques through ransomware, espionage to access classified or sensitive information, destruction, and other tactics to impose cyber effects that disrupt cyber-defense capabilities. Managing and mitigating software supply chain risk is important for sustaining long-term cyber resiliency.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">According to Verizon&#8217;s &#8220;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/\" rel=\"noopener\">2024 Data Breach Investigations Report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">,&#8221; vulnerabilities in third-party software attributed to a significant increase in data breaches. All software has or will have exploitable vulnerabilities, so banning Kaspersky and other foreign software lowers the attack surface associated with these vulnerabilities. Foreign software presents a considerable supply chain risk given the geopolitical implications that can be used as part of a cyber operation to compromise national security.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Geopolitical Impact on Cybersecurity and Additional Measures\">Geopolitical Impact on Cybersecurity and Additional Measures<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As organizations continue to formalize and evolve their cybersecurity strategies, they must now factor in impacts from geopolitical activities. Security teams and leaders need to have an active finger on the pulse of the latest national security headlines, understand their effects, and use that information to inform cybersecurity strategies.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Adversaries are also not wasting any time in weaponizing cyber for espionage activities and disruption. When cybersecurity and geopolitics are combined, it elevates mission and business risk for this nation. Organizations must also take this shift into account and use it to elevate their cyber defenses. Proactive threat intelligence is an essential tool for staying ahead of nation state and supply chain attacks, while doubling down on public\/private collaborations and partnerships also helps organizations stay informed.&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Defending Forward\">Defending Forward<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The Kaspersky ban should not be taken lightly. It&#8217;s an opportune time for an adversary&#8217;s cyber operations. Geopolitics continues to shape the new cyber battlefield and will require organizations to be more informed \u2014 not just about cyber threats, but also about the impact of geopolitics on cyber activity. Foreign software is the ideal attack vector that allows adversaries to gain a wealth of telemetry about operating environments and valuable intelligence as part of counter-intelligence operations. We must continue to &#8220;defend forward&#8221; and protect the nation from hostile threats.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/kaspersky-is-unacceptable-risk-threatening-nations-cyber-defense\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY The current state of play with rising cyberattacks and<\/p>\n","protected":false},"author":12,"featured_media":4572,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4571","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/kaspersky-is-an-unacceptable-risk-threatening-the-nations-cyber-defense.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4571","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4571"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4571\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4572"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}