Currencies28783
Market Cap$ 2.51T-1.07%
24h Spot Volume$ 24.87B-3.48%
BTC Dominance52.02%+0.33%
ETH Gas4 Gwei
Cryptorank
CryptoRankNewsUnearthed Go...

Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox


Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox
May, 06, 2024
3 min read
by Cryptonews
Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox

The United States Securities and Exchange Commission (SEC) received a report from the Office of Inspector General (OIG) alleging that its cybersecurity program was lacking just two weeks before the commission’s X account was hacked on January 9, according to Fox Business reporter Eleanor Terrett.

SEC Received OIG Report Two Weeks Before X Hack


Eleanor Terret tweeted on May 6 about the issue, highlighting a December 2023 OIG report, an independent evaluation by contractor Cotton & Company Assurance and Advisor concluded that the federal regulator fell short of “effectively mitigating security weaknesses.” 

“To improve the SEC’s information security program, we urge management to take action to address areas of potential risk identified in this report,” the report read.

The nearly 30-page document highlighted a list of much-needed improvements to the SEC’s security protocols, including maintaining its vulnerability disclosure policy and logging meeting requirements.

“I am pleased your report identified improvements to SEC’s information security program across several domains, such as risk management, supply chain, security training, and continuous diagnostics and monitoring,” the SEC’s Chief Information Officer David Bottom said in a December 2023 letter to OIG. “The SEC’s Office of Information Technology (OIT) continues to focus on improving maturity throughout the program, even though not all metrics are evaluated and scored each year.”

After receiving OIG’s report on its underperforming security program, the federal agency was ordered to submit an action plan within 45 days. The SEC was hacked shortly after on January 9 when an authorized party gained access to the commission’s X account and posted a fake spot Bitcoin ETF approval announcement.

Cybersecurity Program Questioned Following Report


According to CoinDesk, the hack resulted in $90 million in liquidations, prompting market manipulation concerns.

“Deeply concerned with this alleged hack of the SEC’s Twitter account,” Congresswoman Anne Wagner stated. “This is clear market manipulation that impacted millions of investors. I plan to get more answers from Chair Gensler on this incident.”

The federal agency was later found to have not enabled two-factor authentication, allowing an unknown party to access the commission accounts via a SIM-swapping attack.

“Access to the phone number occurred via the telecom carrier, not via SEC systems,” the SEC said in a statement shortly following the hack. “SEC staff have not identified any evidence that the unauthorized party gained access to SEC systems, data, devices, or other social media accounts.”

Despite its obvious vulnerabilities, it is unclear if or when the federal commission will face reprimand for the incident.

The post Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox appeared first on Cryptonews.

Read the article at Cryptonews

Read More

Polkadot Expands Through Strategic Partnerships and Technological Advancements

Polkadot Expands Through Strategic Partnerships and Technological Advancements

Polkadot grows with frequent improvements and key partnerships. Founder Institute and...
May, 19, 2024
by COINTURK NEWS
Accidental Bitcoin Transfer Pushes Satoshi Nakamoto’s Genesis Wallet Over 100 BTC

Accidental Bitcoin Transfer Pushes Satoshi Nakamoto’s Genesis Wallet Over 100 BTC

Based on the latest data, the well-known Genesis address owned by Satoshi Nakamoto no...
May, 19, 2024
by Bitcoin News
CryptoRankNewsUnearthed Go...

Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox


Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox
May, 06, 2024
3 min read
by Cryptonews
Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox

The United States Securities and Exchange Commission (SEC) received a report from the Office of Inspector General (OIG) alleging that its cybersecurity program was lacking just two weeks before the commission’s X account was hacked on January 9, according to Fox Business reporter Eleanor Terrett.

SEC Received OIG Report Two Weeks Before X Hack


Eleanor Terret tweeted on May 6 about the issue, highlighting a December 2023 OIG report, an independent evaluation by contractor Cotton & Company Assurance and Advisor concluded that the federal regulator fell short of “effectively mitigating security weaknesses.” 

“To improve the SEC’s information security program, we urge management to take action to address areas of potential risk identified in this report,” the report read.

The nearly 30-page document highlighted a list of much-needed improvements to the SEC’s security protocols, including maintaining its vulnerability disclosure policy and logging meeting requirements.

“I am pleased your report identified improvements to SEC’s information security program across several domains, such as risk management, supply chain, security training, and continuous diagnostics and monitoring,” the SEC’s Chief Information Officer David Bottom said in a December 2023 letter to OIG. “The SEC’s Office of Information Technology (OIT) continues to focus on improving maturity throughout the program, even though not all metrics are evaluated and scored each year.”

After receiving OIG’s report on its underperforming security program, the federal agency was ordered to submit an action plan within 45 days. The SEC was hacked shortly after on January 9 when an authorized party gained access to the commission’s X account and posted a fake spot Bitcoin ETF approval announcement.

Cybersecurity Program Questioned Following Report


According to CoinDesk, the hack resulted in $90 million in liquidations, prompting market manipulation concerns.

“Deeply concerned with this alleged hack of the SEC’s Twitter account,” Congresswoman Anne Wagner stated. “This is clear market manipulation that impacted millions of investors. I plan to get more answers from Chair Gensler on this incident.”

The federal agency was later found to have not enabled two-factor authentication, allowing an unknown party to access the commission accounts via a SIM-swapping attack.

“Access to the phone number occurred via the telecom carrier, not via SEC systems,” the SEC said in a statement shortly following the hack. “SEC staff have not identified any evidence that the unauthorized party gained access to SEC systems, data, devices, or other social media accounts.”

Despite its obvious vulnerabilities, it is unclear if or when the federal commission will face reprimand for the incident.

The post Unearthed Government Report Found SEC Lacking “Effective” Cybersecurity Programs Two Weeks Before X Hack: Fox appeared first on Cryptonews.

Read the article at Cryptonews

Read More

Polkadot Expands Through Strategic Partnerships and Technological Advancements

Polkadot Expands Through Strategic Partnerships and Technological Advancements

Polkadot grows with frequent improvements and key partnerships. Founder Institute and...
May, 19, 2024
by COINTURK NEWS
Accidental Bitcoin Transfer Pushes Satoshi Nakamoto’s Genesis Wallet Over 100 BTC

Accidental Bitcoin Transfer Pushes Satoshi Nakamoto’s Genesis Wallet Over 100 BTC

Based on the latest data, the well-known Genesis address owned by Satoshi Nakamoto no...
May, 19, 2024
by Bitcoin News