Thu, Nov 30, 2023
Pro-Russian entities attempted to divert attention away from the growing volume of potential intel-gathering equipment on its embassy roof
Wed, Nov 1, 2023
Telegram feeds of hacker groups document alleged attacks targeting Israel
Mon, Oct 30, 2023
Web browsers are the gateway to the internet. As browser developers replicate design features and concentrate around shared underlying technologies, they create cybersecurity risks with the potential to impact many internet users at once.
by Justin Sherman and Jessica Edelson
Thu, Oct 12, 2023
Product recalls require practices that can help software vendors move toward better component selection and tracking and better relationships with customers, all while making software vendors responsible for OSS security instead of maintainers.
by Jeff Wayman, Brian Fox
Wed, Sep 27, 2023
Software supply chain attacks are popular, impactful, and are used to great effect by malicious actors. To dive deeper on this topic, we asked eight experts about these threats and how policymakers can help protect against them.
by Cyber Statecraft Initiative
Wed, Jul 19, 2023
SBOMs are an important step forward for software supply chain security, so despite pushback and opposition, industry and government should take a page out of Taylor Swift’s book and just keep cruisin’, don’t let SBOM haters get in the way.
by John Speed Meyers, Sara Ann Brackett, and Trey Herr
Tue, Jul 18, 2023
On July 13, the White House released the Implementation Plan for the 2023 US National Cybersecurity Strategy. Read along with CSI staff, fellows, and experts for commentary and what the NCSIP means for the Strategy.
Mon, Jul 10, 2023
Critical infrastructure increasingly depends upon cloud computing. Policy must adapt its approach to risk management accordingly.
by Tianjiu Zuo, Justin Sherman, Maia Hamin, and Stewart Scott
Wed, Jun 28, 2023
The United States and its allies can do more to improve their position on spyware. Further policy action should, through greater collaboration with marketplace operators and allies and partners, work on furthering the development of norms and common understanding of what spyware can and cannot be used for.
by Jen Roberts and Emmeline Nettles
Fri, Jun 16, 2023
Press Release: Task Force for a Trustworthy Future Web launches final report Scaling Trust on the Web
Wed, Jun 14, 2023
The SEC wants to require fast, public disclosure of cybersecurity incidents. These rules could benefit investors—and the cyber ecosystem.