Kaspersky Lab was blocked from joining this U.S.-based cyberthreat information sharing group
Full article1,187 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Cyber Threat Alliance denied Kaspersky entry into the group due to the group's president, former cybersecurity coordinator Michael Daniel, weighing on information he was privy to during his time in the Obama administration.
A former senior U.S. official blocked Moscow-based cybersecurity firm Kaspersky Lab from joining a prominent trade group made up of U.S.-based cybersecurity companies earlier this year, multiple people with knowledge of the proposed deal tell CyberScoop.
When Kaspersky representatives approached the Cyber Threat Alliance (CTA) — a U.S.-based not-for-profit membership organization largely made up of American technology firms who voluntarily share threat intelligence with one another — the group’s leader, Michael Daniel, quietly turned the company away, the sources said. Daniel is a former White House cybersecurity coordinator.
“It didn’t really go anywhere because they got Heisman-ed from the get go,” one source described, referencing the college football trophy that represents a player forcefully pushing someone out of the way.
Daniel spoke with CyberScoop and acknowledged that Kaspersky had shown interest in joining the CTA. Kaspersky is not currently a member.
The choice to exclude Kaspersky alludes to knowledge of the U.S. government’s dealings with the Russian company that have since come to public light.
Daniel, who played a key role in coordinating the U.S. intelligence community’s cyber-operations during the Obama administration, declined Kaspersky’s advances because he knew that a looming battle between the U.S. government and the Russian cybersecurity firm had been stirring behind closed doors for some time and that it could escalate at any minute, the sources said.
Daniel became the CTA’s first president in Feb. 2017 shortly after the inauguration of President Donald Trump. Over the last eight months, the nonprofit has grown substantially under Daniel’s leadership, said Jeff Greene, senior director of global government affairs and policy with Symantec, a founding member of CTA.
This previously unreported, private conversation between the CTA and Kaspersky occurred prior to public revelations and media reports alleging that Kaspersky acts as a digital espionage tool for Russian intelligence agencies — a charge the company repeatedly denied. Kaspersky CEO Eugene Kaspersky recently said it’s possible that his company had been exploited by spies without his knowledge or blessing.
The individuals who spoke with CyberScoop for this story did so on condition of anonymity in order to discuss a confidential decision.
Daniel, in an interview with CyberScoop, declined to discuss how or why he specifically rejected Kaspersky’s interest. He did say, however, that the experiences and knowledge he took from government are today helping him make educated decisions when it comes to accepting and declining potential members. During his time at the White House, Daniel would have had access to classified information concerning foreign digital espionage.
“Trust is extremely important to us,” said Daniel about the CTA. “We’re highly aware of what could happen if we just allowed anybody into this process … we expect our members to contribute as much as they receive.”
He continued, “and that extends to data integrity as well … We are cognizant of what could happen if someone were to, you know, poison the well or do something else malicious to affect our data.”
The CTA, which has grown to 14 members, is one of the largest nonprofit organizations actively facilitating the exchange of threat intelligence between the private sector and, on occasion, the U.S. government. It includes representation from some of the industry’s most prominent brands, including Symantec, Palo Alto Networks, Check Point Technologies, Cisco, Fortinet and RSA — nearly all of which have invested in recent years in recruiting talent from the NSA, CIA and Department of Defense.
Kaspersky spokespeople say the company’s relationship with the Russian government is focused on combating cybercrime.
Executives from CTA member companies said Wednesday during a conference in Washington, D.C. that admission to the group can provide a valuable market advantage that could one day help edge out other competitors. Because the group is structured like a private club, where only members provide and can access each others active reports containing technical indicators about active cyberattacks, the CTA’s growth has the ability to significantly impact the overall market in the future.
While most CTA members and affiliates are American companies, some are headquartered in allied countries, like Israel.
Daniel told CyberScoop that nationality does not affect a company’s application to join the CTA — unless it were based in a sanctioned country — but rather each potential participant is judged on a case-by-case basis which includes a review of that firm’s business and management connections.
CTA members are judged and admitted to the program based on their ability to provide a continuous stream of valuable data regarding unique malware samples, active threats and specific hacking groups. It’s because members consistently contribute such information that the CTA is seen as useful to the industry and attractive to potential members.
Although Kaspersky’s public image at the moment makes it seem like Daniel had a simple choice concerning the Russian firm, the decision carried considerable weight in early 2017.
Experts agree that beyond the current controversy, Kaspersky remains one of the best firms in the business when it comes to capturing cyberthreat intelligence.
More Scoops
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
The president went against his intelligence agencies’ conclusions about Iran being the likely suspect in the campaign.
Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack
Information sharing law’s expiration could squander government vulnerability hunting efforts, senator says
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/kaspersky-cyber-threat-alliance-michael-daniel/