this post was submitted on 30 Aug 2025
74 points (100.0% liked)

Cybersecurity

8343 readers
67 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 2 years ago
MODERATORS
 

cross-posted from: https://programming.dev/post/36577114

FEMA Chief Information Officer (CIO) Charles Armstrong, Chief Information Security Officer (CISO) Gregory Edwards, and 22 other FEMA IT employees directly responsible were immediately terminated.

While conducting a routine cybersecurity review, the DHS Office of the Chief Information Officer (OCIO) discovered significant security vulnerabilities that gave a threat actor access to FEMA’s network. The investigation uncovered several severe lapses in security that allowed the threat actor to breach FEMA’s network and threaten the entire Department and the nation as a whole.

The entrenched bureaucrats who led FEMA’s IT team for decades resisted any efforts to fix the problem. Instead, they avoided scheduled inspections and lied to officials about the scope and scale of the cyber vulnerabilities.

Failures included: an agency-wide lack of multi-factor authentication, use of prohibited legacy protocols, failing to fix known and critical vulnerabilities, and inadequate operational visibility.

FEMA spent nearly half a billion dollars on IT and cybersecurity measures in Fiscal Year 2025 alone and delivered virtually nothing for the American people. Despite burning hundreds of millions of taxpayer dollars, FEMA’s IT leadership still neglected its basic duties and exposed the entire Department to cyberattacks.

you are viewing a single comment's thread
view the rest of the comments
[–] xorollo@leminal.space 27 points 3 weeks ago

So these guys wouldn't or couldn't hand over some data or install some malware or something?