Cisco will pay $8.6 million to settle claims it sold US flawed surveillance software
Full article545 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Department of Homeland Security and four branches of the U.S. military had purchased the affected software.
Technology giant Cisco has agreed to pay $8.6 million to settle allegations it knowingly sold video surveillance equipment with security vulnerabilities to federal, state and local government agencies, according to court records unsealed Wednesday.
A company whistleblower first informed Cisco in 2008 that a bug in its surveillance software could have enabled hackers to monitor video footage, delete footage and turn on or disable the systems. Government entities including the U.S. Secret Service, the Federal Emergency Management Agency and the New York Police Department had purchased the software, according to the Washington Post, which first reported the news. Cisco’s settlement appears to be the first whistleblower resolution of the False Claims Act, which prohibits defrauding the government, regarding cybersecurity issues.
“The tech industry needs to fulfill its professional responsibility to protect the public from their products and services,” whistleblower James Glenn said in a statement. “There’s this culture that tends to prioritize profit and reputation over doing what’s right. I hope coming forward with my experience causes many others in the tech community to think about their ethical mandate.”
The Department of Homeland Security as well as the Army, Navy, Air Force and Marine Corps also had purchased the affected software, along with a number of prisons. There is no evidence to indicate the bug, which existed for roughly four years, per the Post, had been exploited.
The settlement comes amid mounting concerns in Washington about the security of the technology the government and military rely on. The White House issued an executive order in May prohibiting U.S. companies from using telecommunications equipment manufactured by companies beholden to foreign governments that may engage in economic espionage.
Cisco’s resolution comes after the security vendor Fortinet agreed to pay $545,000 to settle allegations is violated the False Claims Act by intentionally selling the U.S. military equipment that had been produced in China, but made to appear as if it were American-made.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/cisco-settlement-whistleblower-false-claims-act/