Author Archive

David DiMolfetta

David DiMolfetta
David DiMolfetta covers cybersecurity for Nextgov/FCW. Previously, he researched The Cybersecurity 202 and The Technology 202 newsletters at The Washington Post and covered AI, cybersecurity and technology policy for S&P Global Market Intelligence. He holds a BBA from The George Washington University and an MS from Georgetown University. Get in touch with him on X/Twitter: @ddimolfetta . If you have a tip you'd like to share, David can be securely contacted at djd.99 on Signal.
Cybersecurity

Nearly 20 Democratic states inadvertently share driver data with ICE, lawmakers say

Nlets, a nonprofit law enforcement info-sharing network, can share state residents’ information with immigration agencies, federal lawmakers said Wednesday.

Workforce

CyberCorps talent pipeline buckles under Trump hiring freezes

The cornerstone program for training and placing student talent into government cybersecurity positions has been hobbled by recent federal employment logjams, jeopardizing workforce pipelines and leaving many recruits burdened by debt.

Digital Government

Senators call for election security briefing as major races draw closer

“We are concerned that you may have directed the Intelligence Community (IC) to cease its intelligence reporting on this vital topic,” the senators wrote to the director of national intelligence in a Monday letter.

Cybersecurity

Wyden calls for review of US court systems’ cyber posture after case system hack

Since the incident, several district courts have instructed filers not to submit sealed documents, amid risks that the systems protecting them may not be secure.

Cybersecurity

Foreign adversaries are trying to weaponize open-source software, report finds

Hacking units affiliated with nation-state adversaries are subtly contributing to open-source software tools and working to insert backdoors into publicly available code used by millions worldwide, new research says.

Cybersecurity

Operational tech is ‘underprioritized’ in cyberdefense, experts tell Congress

Witnesses' calls for better investment in securing such systems come just two months before a key cybersecurity information-sharing law is set to expire.

Cybersecurity

Threat intel firms on alert for government systems impacted by Microsoft SharePoint vulnerability

Governments, schools, healthcare providers and large enterprise firms are at risk, one cyber threat intelligence chief said.

Cybersecurity

Feds expect Iran’s cyber forces will target US networks after strikes on nuclear sites

Iran has often targeted U.S. digital systems. Last year, Iranian hackers pilfered and distributed sensitive documents from inside President Donald Trump’s 2024 campaign.

Cybersecurity

US agencies assessed Chinese telecom hackers likely hit data center and residential internet providers

Data center giant Digital Realty and mass media titan Comcast were documented as likely victims of the Salt Typhoon cyberespionage group, people familiar say, marking a potentially major expansion of the group’s initial telecom hacking campaign discovered last year.

Cybersecurity

‘I do not have confidence’ that US infrastructure is cyber-secure, former NSC official says

At the AI Expo for National Competitiveness, Anne Neuberger told audiences that artificial intelligence tools are an enhancement opportunity for U.S. cyber defenses and intelligence collection.

Cybersecurity

US should rethink current views of Russia’s cyber might, new report says

A think tank paper argues that Moscow’s network of hackers is more fragmented than U.S. officials once believed — a dynamic that may have led to exaggerated expectations of Russia’s cyber capabilities during its 2022 Ukraine invasion.

Cybersecurity

South Dakota CIO to become deputy director at CISA

Madhu Gottumukkala will take over a position that has remained vacant since Nitin Natarajan departed the agency in January.

Digital Government

FCC to investigate potential US operations of restricted Chinese firms 

The commission’s new chairman, Brendan Carr, believes that some or all of the companies on the FCC’s Covered List are still operating in the nation.

Cybersecurity

FedRAMP to announce major overhaul next week

The initiative would seek to automate much of the cloud security program’s approval workflow and shift more control to the private sector.

Cybersecurity

Salt Typhoon hackers exploited stolen credentials and a 7-year-old software flaw in Cisco systems

The Chinese hacking collective has used vulnerabilities in communications infrastructure to breach dozens of telecom providers in the U.S. and overseas.

Cybersecurity

China-linked fraud network exploits stolen Massachusetts identities to target U.S. banks

It’s not clear who exactly the Chinese operatives are, but the scheme has been ongoing and persistent, said Socure executive Jordan Burris.

Exclusive Infrastructure

GAO mulls cost evaluation of nationwide telecom hardware replacement

One major vulnerability exploited by China’s Salt Typhoon hacking unit is a Cisco hardware flaw that can’t be patched and requires physical replacement, according to a person with knowledge of the intrusions.

Cybersecurity

Russian email domains sent uncredible bomb threats to polling places, FBI says

Kremlin-backed actors have a long record of sowing fear and disinformation into the U.S. election process.

Breaking News Digital Government

FBI raids government IT and cyber contractor Carahsoft

Company president says the agents were there "as part of an investigation into a company with which Carahsoft has done business in the past."

Cybersecurity

Cyberattacks still ravage schools, defying White House efforts launched last year

Thousands of school districts have tapped into resources committed by the private sector to shore up their cyberdefenses.