CISA tells agencies to consider ad blockers to fend off 'malvertising'
Full article643 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The NSA previously made a similar recommendation.
The U.S. Cybersecurity and Infrastructure Security Agency urged federal agencies on Thursday to deploy ad-blocking software and standardize web browser usage across their workforces in order to fend off advertisements implanted with malware.
“With many agencies greatly expanding telework options, agencies should increase attention on securing federal endpoints, including associated web browsing capabilities,” the Department of Homeland Security’s cyber arm said in a guide for agencies.
With the alert, CISA joins the National Security Agency, which in 2018 likewise urged agencies to adopt ad blockers in response to the threat from “malvertising” that can spread malware.
However, CISA cautioned that ad blockers aren’t a cure-all for the issue of malicious adversiting which in recent months has plagued TikTok and a slew of industries during the coronavirus.
“Some browser extensions are known to accept payment from advertisers to ensure their ads are allowlisted from blocking,” the agency said, citing concerns that Sen. Ron Wyden, D-Ore. raised last year to the Federal Trade Commission.
Wyden nonetheless had urged the White House to use ad blockers, citing at least one media report of Russia using seemingly innocuous advertisements to target a state election agency.
Additionally, CISA said that agencies can safeguard their networks from malvertising by standardizing web browser usage, since multiple web browsers and browser versions give attackers more targets.
Furthermore, CISA said agencies should consider isolating web browsers from operating systems, as the Department of Defense does.
While expensive to implement at the start, “over its lifecycle, browser isolation may have a lower cost, based on reduced costs for maintaining ad blocking software, lower incident response and recovery costs, and bandwidth efficiencies,” the guide said.
Another possible step is using Domain Name System technologies that can protect against malvertising, CISA said.
More Scoops
AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn
The agencies said the hackers are taking aim at Siemens S7 Series programmable logic controllers in what could be a first.
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
States are building their own election defense networks as federal support evaporates
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ad-blockers-security-nsa-dhs-wyden/