Skip to main content

The problem with Starlink in Gaza

Delivered every Monday by 10 a.m., Weekly Cybersecurity examines the latest news in cybersecurity policy and politics.
Oct 30, 2023 View in browser
 
POLITICO's Weekly Cybersecurity newsletter logo

By Joseph Gedeon

— With help from John Sakellariadis

Driving the day

— Internet service in Gaza is partially restored after a blackout, but unlike in Ukraine, Starlink may not be a viable solution for improved connectivity — or for Israeli officials.

HAPPY MONDAY, and welcome to MORNING CYBERSECURITY! I spent this weekend a little way out of town, and some of it was spent trapped in a moonlit corn maze for some sort of Halloweekend activity. It was a way, way better time than I expected. Me and my city-slicking ways have a lot to learn about how the rest of America does Halloween.

Have any tips or secrets to share with MC? Or thoughts on what we should be covering? Email me at jgedeon@politico.com. You can also follow @POLITICOPro and @MorningCybersec on X. Full team contact info is below. Let’s dive in.

Want to receive this newsletter every weekday? Subscribe to POLITICO Pro. You’ll also receive daily policy news and other intelligence you need to act on the day’s biggest stories.

Today's Agenda

Department of Homeland Security Science and Technology undersecretary Dimitri Kusnezov, DHS management undersecretary Randolph “Tex” Alles, CISA’s associate chief of strategic technology Garfield Jones and others are joining the DHS’ Strategic Industry Conversation IX on innovation, research and development. Starts at 9:30 a.m.

CISA’s executive assistant director for cybersecurity Eric Goldstein is joining the Federal Communications Commission for a joint-agency roundtable on America’s public alert and warning systems. 9:30 a.m.

The International Scene

WISH UPON A STAR(LINK) — Internet connectivity for more than two million people in Gaza has been partially restored after being blacked out by Israeli airstrikes on Friday, but is still far below pre-conflict levels.

While the lack of internet connectivity causes heavy disruption to Hamas’ communication technologies, the limited network also severely limits the messages civilians can send out — with experts remarking that network connectivity is not at all sustainable, especially if Israeli bombardments continue.

“What we've observed on Friday is the new normal,” Alp Toker, the founder of London-based global internet monitoring group Netblocks, tells Morning Cyber. “This connectivity — which hovers around the 20 percent level — is actually the baseline of infrastructure that is still undamaged and that is now becoming a new kind of flat framework for what is the availability of connectivity.”

One potential lifeline for Gaza is Elon Musk's offer of the battle-tested Starlink’s high-speed satellite internet service — but this may not be the fix Gazans are hoping for.

— Not up and running: Starlink is not yet fully operational in Gaza, and it’s unclear when it will be. It could be a matter of days, much like for Ukraine in the immediate aftermath of Russia’s invasion, but it’s also not that simple.

On Feb. 26, 2022, Ukrainian Minister of Digital Transformation Mykhailo Fedorov tweeted at Musk asking for Starlink terminals, with Musk replying within hours. The first shipment would reach Ukraine before the end of that month and played a vital role in Ukraine’s war effort — providing essential comms infrastructure to both military and civilians.

However, the quick work by SpaceX was thanks to prior planning — the company had already been working to launch Starlink services in Ukraine and other places in Europe before the formal request, and had already secured landing rights for the satellites.

— Not for everyone: Musk has said that he will only provide the satellite internet service to “internationally recognized” humanitarian aid groups, which means that many other people and groups in Gaza may not be able to access it anyways. That’s likely to include hospitals (that are run by Hamas as the de facto government of Gaza), news media and other organizations.

There’s a risk that the connectivity could fall into the hands of Hamas militants, Toker explained, which Israel’s government fears could be used to sow disinformation and propaganda campaigns. While Hamas isn’t known to act through sophisticated cyber operations, Starlink could stamp out that possibility anyway by using precise geolocation tools that filter out connections to make sure only allowed groups are using it.

Still, the offer doesn’t sit right with Israeli officials like minister of communications Shlomo Karhi, who posted on X that “Israel will use all means at its disposal to fight this,” and threatened to cut ties with Starlink.

— Uncertain future: It’s unlikely the Gaza Strip will achieve full connectivity any time soon, and it's more and more likely that the network will again face total shutdown at some point. An anonymous senior U.S. official told the Washington Post on Sunday that Israel had intentionally shut off communications in Gaza and turned it back on after U.S. pressure.

Artificial Intelligence

IT’S AI TIME — In a 100-plus-page draft executive order obtained by POLITICO, the Biden administration lays out serious steps to manage the risks of artificial intelligence in critical infrastructure and cybersecurity.

The EO comes as Washington becomes increasingly concerned about the potential for AI to be used in malicious attacks, such as developing powerful new cyber weapons or to create and deploy deepfakes ahead of the elections. Here’s what sticks out to us.

— Cyber weapons: The order would require companies developing AI models that have the ability to be used for malicious purposes or have access to sensitive data to provide regular reports to the Commerce Department outlining how they are protecting their technology from espionage or digital subversion.

It would also require large cloud services providers to notify the government each time a foreign entity rents server space to train a large AI model.

— Critical infrastructure: The order paves the way for new federal cybersecurity regulation in critical infrastructure sectors like hospitals, gas pipelines and the electric grid.

Agencies with regulatory authority over critical infrastructure will have three months to assess the potential risks related to the use of AI in those sectors. That includes identifying ways in which deploying AI could make critical infrastructure systems more vulnerable to failures or cyberattacks.

The order also requires the Department of Homeland Security to develop guidelines for critical infrastructure owners and operators on how to manage AI-specific cyber risks. Those guidelines will be based on existing security guidance and NIST’s AI Risk Management framework.

— Advisory committee: DHS will be tasked with establishing an AI safety and security advisory committee that’s expected to be up and running in early 2024. The committee will have to provide advice to the critical infrastructure community on how to improve security, resilience and incident response related to AI usage.

The key committee will comprise AI experts from the private sector, academia and the government.

— Pilot projects: The order directs the Department of Defense and DHS to carry out operational pilot projects within six months using AI for defensive efforts to identify, test and fix vulnerabilities in critical United States government software, systems and networks.

Ransomware

WHITE HOUSE TO UNVEIL RANSOM BAN — The U.S. and dozens of foreign governments will soon issue a joint commitment not to pay ransoms to cybercriminal gangs, a senior administration official told MC.

The pledge, John writes in, which represents the latest effort by the White House to tamp down the continued scourge of online extortion, will be unveiled later this week as part of third-ever gathering of the international counter-ransomware initiative in Washington.

However, the payment ban will not necessarily include all 48 national governments that are party to the CRI, said the official, who was granted anonymity as a condition of talking about the planning for the summit. “There's still a few nations that have not yet signed up to that statement, but it'll be the vast majority,” the official said.

— What else to watch: The CRI, which also counts the EU and INTERPOL among its members, will announce new intelligence-sharing, anti-money laundering and capacity-building initiatives, deputy national security adviser for cybersecurity and emergency technology Anne Neuberger said last week.

In addition, there is a push among CRI members to “get as much transparency as possible” around how many ransomware attacks occur within each member country, the official told MC. Many victims do not report attacks due to fear of legal, reputational or regulatory liability, complicating law enforcement’s ability to understand the prevalence of the problem.

In addition, members are talking about creating a fund “to assist nations that are in distress,” the official said, and exploring mechanisms to ensure the CRI endures long after the Biden administration, which spearheaded the partnership. “I don't think that the ransomware problem is going away anytime soon,” the official said.

Vulnerabilities

STEALING FROM AWS — A fast-moving cryptojacking campaign has been targeting exposed Amazon Web Services credentials on GitHub since at least December 2020, according to a new report from Unit 42.

Researchers from Unit 42, the threat intelligence arm of Palo Alto Networks, dubbed the operation “EleKtra-Leak” and note attackers have been able to detect and use exposed credentials within five minutes of their initial exposure on GitHub — a show of force that displays how cyber gangs can leverage cloud automation techniques to achieve their cryptojacking dreams.

— What’s the damage?: Researchers believe there have been 474 unique miners potentially linked to the attackers who mined Monero, a digital asset with strong privacy controls that mean the exact amount stolen can’t be determined.

— How it’s being done: Researchers believe the attackers use automated tools to scan for exposed identity and access management credentials on public GitHub repositories. Once they find a set of exposed credentials, they use them to create EC2 instances (a virtual server that enables you to run applications on AWS infrastructure) that they then use for cryptojacking.

The researchers were able to track the criminal movements by automating the creation of randomized AWS and user accounts with targeted overly permissive credentials.

ATTACKS BREAKING THROUGH — Security teams are struggling to get ahead of attacks lobbed at their organizations, with reactive measures meaning more than 40 percent of cyberattacks are being treated after their defenses have been successfully penetrated, according to a new report from Tenable.

Most cyber professionals in the report say they focus almost entirely on fighting successful attacks rather than working to prevent them in the first place — resulting in only being able to fend off about 57 percent of cyberattacks encountered in the last two years. Cyber professionals claim the reactive stance is largely due to their companies' struggle to get an accurate read of their attack surface.

— Greatest exposure point: Seventy-five percent of respondents point to cloud infrastructure as the highest source of risk for most organizations.

— Tack on the SEC rules: There are industry and governmental fears that the new SEC rules on cyber risk management and incident disclosure that take effect in December are likely to put even more strain on organizations looking to improve preventive measures.

Along with public companies having to disclose serious cyberattacks, there’s a stipulation that they outline their processes for assessing and identifying material risks from cyber threats.

Tweet of the Day

Now that’s what I call a derailment of duty.

Source: https://twitter.com/NSA_CSDirector/status/1718239165353967836

Quick Bytes

TIME’S TICKING — Russian-linked ransomware group LockBit claimed to have hacked Boeing and threatened to leak stolen data by Thursday, reports Stefanie Schappert and Vilius Petkauskas for CyberNews.

SCHOOL DISTRICT BREACHED — The Clark County School District in Nevada, the fifth largest in the U.S., is dealing with potential massive data breach after hackers email parents their children's data. Get the details from BleepingComputer’s Lawrence Abrams.

ICYMI — StripedFly malware, disguised as a cryptocurrency miner, evaded detection for five years, infecting more than 1 million devices, writes SecurityWeek’s Ionut Arghire.

Chat soon. 

Stay in touch with the whole team: Joseph Gedeon (jgedeon@politico.com); John Sakellariadis (jsakellariadis@politico.com); Maggie Miller (mmiller@politico.com); and Heidi Vogt (hvogt@politico.com).

 

Follow us on Twitter

Heidi Vogt @HeidiVogt

Maggie Miller @magmill95

John Sakellariadis @johnnysaks130

Joseph Gedeon @JGedeon1

 

Follow us

Follow us on Facebook Follow us on Twitter Follow us on Instagram Listen on Apple Podcast
 

To change your alert settings, please log in at https://www.politico.com/_login?base=https%3A%2F%2Fwww.politico.com/settings

This email was sent to rouf@idiot.cloudns.cc by: POLITICO, LLC 1000 Wilson Blvd. Arlington, VA, 22209, USA

Please click here and follow the steps to unsubscribe.

Comments

Popular Posts

📄 Sazzad Khan shared Ahlebayet media's post

  See the post that he shared.           Facebook                 📄 Sazzad Khan shared Ahlebayet media 's post. 17 June at 00:28   View               This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Support, 1 Facebook Way, Menlo Park, CA 94025         To help keep your account secure, please don't forward this email. Learn more.      

Insider Today: McDonald's got too pricey

Plus: Miss USA drama, and top sports startups. View in browser   July 30, 2024 • 5 min read with Dan DeFrancesco Hello there! When it comes to the future of space, are you picking Elon Musk or Jeff Bezos? We compared whether living on Mars (Musk) or a space station (Bezos) is more realistic for humanity's future .  In today's big story, McDonald's admitted it got too expensive . But it's got a fix, and the market is lovin' it .  What's on deck Markets: Goldman's top tech executive sounds off on generative AI in a Q&A .  Tech: The tech industry doesn't like how the media covers it, so it took matters into its own hands . Business: Inside the Miss USA drama that even has pageant queens questioning the competition . But first, fast-food prices are too damn high.   Was this email forwarded to you? Sign up now McDonald's, Tyler Le/BI The big story Unhappy meals You expect many things from fast food — good and bad — but bei...

📄 Sazzad Khan shared Islamic tv ইসলামিক টিভি's post

  See the post that he shared.           Facebook                 📄 Sazzad Khan shared Islamic tv ইসলামিক টিভি 's post. 16 June at 00:42   View               This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Support, 1 Facebook Way, Menlo Park, CA 94025         To help keep your account secure, please don't forward this email. Learn more.      

📄 Yameen Nutkani shared ‎غضنفر عزیز‎'s post

  See the post that he shared.           Facebook                 ‎📄 Yameen Nutkani shared ‎ غضنفر عزیز ‎'s post‎. 25 June at 16:22   View               This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Support, 1 Facebook Way, Menlo Park, CA 94025         To help keep your account secure, please don't forward this email. Learn more.      

Google Alert - Swift

Swift Daily update ⋅ December 11, 2017 NEWS Taylor Swift holds hands with Joe Alwyn while heading home from Jingle Ball -- see the sweet pic! AOL Taylor Swift and Joe Alwyn took their relationship a little more public on Friday, as they were photographed holding hands while leaving Z100 New York's iHeartRadio Jingle Ball at Madison Square Garden in New York City. The low-key couple turned away from the cameras as they headed home for the ... Flag as irrelevant Watch Katie Holmes and Suri Cruise introduce Taylor Swift at Jingle Ball AOL Cruise then enthusiastically jumped in with, "Taylor Swift !" Watch below. In addition to Swift , this year's Jingle Ball at Madison Square Garden featured performances by Ed Sheeran, Niall Horn, Julia Michaels, Charlie Puth, The Chainsmokers, Demi Lovato, Sam Smith, and more. Read our full recap here. Review: Tay...

Google settles 'Incognito mode' lawsuit / X fails to block California content-moderation law / BuzzFeed president resigns

Plus: The iOS features expected to launch in 2024 Inside Tech For December 29, 2023 Here are today's top tech stories:  Google agrees to settle Chrome "Incognito mode" lawsuit. X fails to block California content-moderation law. Huawei says company "back on track" after U.S. trade restrictions. Beth p/beth-duckett 1 Google has tentatively settled a class-action lawsuit claiming it tracked users in Chrome's "Incognito" mode. While settlement terms weren't made public, the lawsuit sought at least $5B from Google. More: The lawsuit alleged that Google tracked Chrome users' online activity even in Incognito mode or "private" mode in other browsers. The plaintiffs claim that Google deceived customers when its cookies, analytics, and app tools continued tracking browsing activity while they thought they were doing private browsing. Google disputed the claims, saying that Incogn...

CVS closes Signify acquisition / Amazon faces FTC privacy violations / Foot Locker sets $2.5B digital sales target

Plus, Walmart lays off over 600 e-commerce fulfilment workers Inside.com Part of   Network March 31, 2023 Presented by CVS Health closed its $8B acquisition of Signify health this week.  The pharmaceutical retail giant plans to expand its healthcare offering with Signify's at-home care technology, a sector that  brings e-commerce strategies into healthcare. More: The deal saw CVS Health acquire Signify Health's common stock at $30.50 per share, amounting to a total transaction value of $8B. Signify brings its technology and analytics into CVS Health's ecosystem to enhance home care services. CVS also acquired over 10,000 Signify clinicians across the U.S.  CVS's move into clinical practice puts it into competition with e-commerce giant Amazon, which recently closed its acquisition of primary healthcare provider On...

🔔 See Aizik Sandhu's message and other notifications that you've missed

    A lot has happened on Facebook since you last logged in. Here are some notifications you've missed from your friends.       Ludo Maallam             8 messages           7 new notifications               You have new notifications.             A lot has happened on Facebook since you last logged in. Here are some notifications you've missed from your friends.       Ludo Maallam             8 messages           7 new notifications               Go to Facebook     View Notifications             This message was sent to ludomallam@idiot.cloudns.cc . If you don't want to receive these emails from Facebook in the future, please unsubscribe . Facebook, Inc., Attention: Community Sup...

Solar & wind produced 10% of electricity in 2021 / House passes 401(k) bill / Yemen war ceasefire for Ramadan

Plus, researchers observed a rare astronomical phenomenon for only the fifth time in history. Inside.com Part of   Network March 30, 2022 Presented by The House of Representatives passed a bill that would allow older workers to make  larger contributions  to their 401(k).  The bill includes mandatory automatic enrollment in retirement savings and allows companies to offer "small immediate financial incentives" like cash or gifts to people who sign up for a retirement plan. More: The bipartisan measure, which passed 414-5, will build upon changes to retirement policy that were enacted in 2019. The 2019 bill raised the age at which people are mandated to start withdrawing money from their retirement accounts from 70.5 to 72. If approved by the Senate in its current form, the new bill will raise the age to 75 over the next decade. Th...

New December Magic School classes announced.

December is your last chance to take a class before SUMMER 2022. ...