DHS Cybersecurity
Watchdogs Miss Hundreds of Vulnerabilities on Their Own Network The federal agency in charge of protecting other agencies from computer
intruders was found riddled with hundreds of high-risk security holes on its
own systems, according to the results of an audit released Wednesday.
The United States Computer Emergency Readiness Team, or
US-CERT, monitors the Einstein intrusion-detection
sensors on nonmilitary government networks, and helps other civil agencies respond
to hack attacks. It also issues alerts on the latest software security holes,
so that everyone from the White House to the FAA can react quickly to install
workarounds and patches.
But in a case of "physician, heal thyself," the agency - which forms the
operational arm of DHS’s National Cyber Security Division, or NCSD - failed
to keep its own systems up to date with the latest software patches. Auditors
working for the DHS inspector general ran a sweep of US-CERT using the vulnerability
scanner Nessus and turned up
1,085
instances of 202 high-risk security holes (.pdf).
Тот случай, когда объяснить ТАКОЕ глупостью уже невозможно, как не пыжься. Остается
или злонамеренность и саботаж, что вряд ли, или же кибер-терроризм - такая же (в
основном) мистификация как "мировой терроризм", "империя зла", "арабская угроза",
"Аль-Каида", "свинной грипп", и прочие хорошие поводы попилить бабло.