Author Archive

David DiMolfetta

Cybersecurity Reporter, Nextgov/FCW

David DiMolfetta
David DiMolfetta covers cybersecurity for Nextgov/FCW. Previously, he researched The Cybersecurity 202 and The Technology 202 newsletters at The Washington Post and covered AI, cybersecurity and technology policy for S&P Global Market Intelligence. He holds a BBA from The George Washington University and an MS from Georgetown University. Get in touch with him on X/Twitter: @ddimolfetta
People

Top CISA official Eric Goldstein to depart agency next month

Goldstein was part of several Biden-era CISA initiatives. It’s unclear what his plans are next.

Cybersecurity

CISA issues guidance to help federal agencies better encrypt DNS traffic

The guidance is part of a broader effort to help the federal ecosystem meet a zero trust deadline this fall.

Cybersecurity

North Korean IT workers tried getting jobs in government agencies — the US is offering $5M for details

DPRK operatives have long worked to position themselves in remote IT jobs and pilfer money for Pyongyang's weapons programs.

Cybersecurity

Cyber workforce efforts need to address diversity ‘head on,’ ex-White House official says

Camille Stewart Gloster just departed the White House, but stressed that not achieving a diverse cyber workforce is a national security concern that creates “gaps in our threat picture.”

Defense

DOD ordered to evaluate mobile device cybersecurity in 2025 defense bill

The evaluations would include basic tools like virtual private networks that encrypt connections when browsing the web.

Cybersecurity

NIST issues new guidelines on protecting unclassified data in government systems

The framework considers the private sector’s increased role in helping the federal government in day-to-day operations and aims to reduce the risk of supply chain cyberattacks.

Cybersecurity

Space assets are in foreign adversaries' cyber crosshairs, DOD official says

The easiest targets are ground assets like operation centers and launch facilities, said Mieke Eoyang.

Cybersecurity

Tech firms pledge to release products with built-in security features

The Cybersecurity and Infrastructure Security Agency has been trying to get companies to agree to its "secure by design" paradigm for months.

Acquisition

Spy agencies must craft safeguards for using sensitive commercial data, ODNI says

The new framework follows a report last year that showed the intelligence community frequently relies on purchased sensitive information.

Cybersecurity

Thwarted cyberattack targeted Library of Congress in tandem with October British Library breach

Multifactor authentication prevented hackers from accessing the U.S. institution’s systems in the October campaign, documents show.

Cybersecurity

US advances on cyber goals amid rapidly changing threat environment, White House says

Cyber challenges in U.S. crosshairs include ransomware, AI, supply chain attacks and commercial spyware. A new version of an implementation plan might help address them.

Cybersecurity

CISA, FBI resuming talks with social media firms over disinformation removal, Senate Intel chair says

The Senate Intelligence Committee will hold an election security hearing in two weeks, according to Sen. Mark Warner, D-Va.

Cybersecurity

White House in talks with industry to build legal framework for software liability

As part of a broad cybersecurity strategy, the U.S. wants to create incentives for the tech industry to manufacture products and software that don’t contain major security flaws.

Cybersecurity

US sets sights on partnerships to counter cyberthreats, secure AI in new global cyber strategy

An update to US international cyberspace policy will leverage partnerships to defend against cyberattacks on critical infrastructure and help prevent surveillance misuses.

Digital Government

US to unveil new international cyber framework

The last international cyber blueprint came out more than a decade ago from the Obama administration.

Cybersecurity

US warns of North Korean hackers using email security flaws for phishing attacks

The readout urges organizations to change email configurations to prevent the malign messages from reaching their inboxes.

Cybersecurity

House cyber chairman tries again to undo SEC cyber disclosure rules

Rep. Andrew Garbarino, a New York Republican, said he plans to get the measure into a House Financial Services markup.

Cybersecurity

US warns of Russian hackers targeting operational technology in water systems

The advisory represents official U.S. confirmation that Russian operatives have breached water systems.