Cyberstability Update – September 2019

Cyberstability Update – September 2019

October 17, 2019, Monthly update

Download Publication Download Document

Cyberstability Update – September 2019

GLOBAL COMMISSION MEETING IN ADDIS ABABA, ETHIOPIA

Published on the Global Commission on the Stability of Cyberspace Website on September 9, 2019.

The Global Commission on the Stability of Cyberspace held its fourth meeting of 2019 in Addis Ababa, Ethiopia, on 11-12 October. The Commission meeting took place just after the Global Forum on Cyber Expertise (GFCE) Annual Meeting, hosted by the African Union Commission.

On Friday 11 October the GCSC held public Cyberstability Hearings, in partnership with the GFCE and hosted by the African Union Commission. The Hearings were dedicated to “Norm Implementation & Capacity Building: Two Sides of the Same Coin?”. The Hearings were conducted in an expanded roundtable format and featured discussions between GCSC Commissioners and representatives from government, the private sector and civil society on matters pertaining to international peace and security in cyberspace.

Read More


National Policy


U.S. counter-spies launch campaign against ‘insider’ threats, Reuters.

Tags: GCSC Norm to Reduce and Mitigate Significant Vulnerabilities.


U.S. Unleashes Military to Fight Fake News, Disinformation, Bloomberg.

Tags: Global Commission on the Stability of Cyberspace.


Moving the Encryption Policy Conversation Forward, Carnegie.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Statement for the Record by the Honorable Michael Chertoff Co-founder and Executive Chairman of the Chertoff Group and Former Secretary of the U.S. DHS, The US Senate Committee on Homeland Security and Government Affairs.

Tags: GCSC Co-Chair Michael Chertoff.


France’s Major Statement on International Law and Cyber: An Assessment, Just Security.

Tags: Global Commission on the Stability of Cyberspace.


International security and cyberspace at the UN, Australian Department of Foreign Affairs and Trade.

Tags: Global Commission on the Stability of Cyberspace.


Trump admin weighing retaliatory action against Iran after Saudi oil attack, NBC News.

Tags: Global Commission on the Stability of Cyberspace.


The American way of cyber warfare and the case of ISIS, Atlantic Council.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


India and Russia share an evergreen relationship of trust and confidence, ORF.

Tags: GCSC Commissioner Samir Saran.


The Urgent Search for a Silver Bullet Against Iran, The New York Times.

Tags: Global Commission on the Stability of Cyberspace.


Iran denies successful cyber attack on oil sector, The Times of Israel.

Tags: Global Commission on the Stability of Cyberspace.


Secret F.B.I. Subpoenas Scoop Up Personal Data From Scores of Companies, The New York Times.

Tags: Global Commission on the Stability of Cyberspace.


Air Force unveils 10-year cyber warfare plan, FCW.

Tags: Global Commission on the Stability of Cyberspace.


Global Governance


Biarritz Strategy for an Open, Free and Secure Digital Transformation, G7.

Tags: Global Commission on the Stability of Cyberspace.


NATO will defend itself, NATO.

Tags: Global Commission on the Stability of Cyberspace.


Joint Statement on Advancing Responsible State Behavior in Cyberspace, US Department of State.

Tags: Global Commission on the Stability of Cyberspace.


Can Tech be Governed?, Berkman Klein Center.

Tags: GCSC Commissioner Jonathan Zittrain.


CEPOL presented to the LIBE MEPs of the new parliament’s mandate, CEPOL.

Tags: GCSC Commissioner Marina Kaljurand.


EU Statement – United Nations Open-ended Working Group on Cyberspace: First Session, EEAS.

Tags: Global Commission on the Stability of Cyberspace.


APC statement to the First Substantive Session of the Open-ended Working Group on developments in the field of information and telecommunications in the context of international security, APC.

Tags: Global Commission on the Stability of Cyberspace.


Statement by the Association for Progressive Communications, APC.

Tags: Global Commission on the Stability of Cyberspace.


The Operationalization of Norms and Principles on Cybersecurity, CircleID.

Tags: Global Commission on the Stability of Cyberspace.


An Innovation Agenda for Europe, Project Syndicate.

Tags: GCSC Commissioner Marietje Schaake.


Global Cooperation in Cyberspace Progress Roundtable – Palo Alto 2019, EWI.

Tags: Global Commission on the Stability of Cyberspace.


World powers are pushing to build their own brand of cyber norms, CyberScoop.

Tags: Global Commission on the Stability of Cyberspace.


New global cybersecurity process begins: APC presents statement at UN Open Ended Working GroupAPC.

Tags: Global Commission on the Stability of Cyberspace.


AfriSIG: Capacity-building role-play exercise results in concrete input to UN Secretary-General on digital cooperation, APC.

Tags: GCSC Commission er Anriette Esterhuysen.


SESSION 7: ASSURING CYBER-SECURITY IN THE WESTERN BALKANS AND THE REST OF EUROPE, Belgrade Security Forum.

Tags: Director of the GCSC Secretariat Alexander Klimburg.


‘Right to Be Forgotten’ Privacy Rule Is Limited by Europe’s Top Court, The New York Times.

Tags: GCSC Commissioner Jonathan Zittrain.


Threats and Risk Mitigation


Police hijack a botnet and remotely kill 850,000 malware infections, TechCrunch.

Tags: GCSC Norm Against Commandeering of ICT Devices into BotnetsGCSC Norm Against Offensive Cyber Operations by Non-State Actors.


Microsoft, Hewlett Foundation preparing to launch nonprofit that calls out cyberattacks, CyberScoop.

Tags: Global Commission on the Stability of Cyberspace.


Symantec finds that a ‘new’ Chinese hacking group has actually been around for a decade, CyberScoop.

Tags: Global Commission on the Stability of Cyberspace.


Report reveals play-by-play of first U.S. grid cyberattack, E&ENews.

Tags: GCSC Norm Against Offensive Cyber Operations by Non-State Actors.


ESET discovered an undocumented backdoor used by the infamous Stealth Falcon group, welivesecurity.

Tags: GCSC Norm Against Offensive Cyber Operations by Non-State Actors.


Pervasive Social Engineering Characterizes the Threat Landscape: Proofpoint Releases the Human Factor 2019 Report, ProofPoint.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Well-known ethical hacker describes recent cybersecurity and ransomware attack scenario, International Business Times.

Tags: GCSC Commissioner Ilya Sachkov.


New Clues Show How Russia’s Grid Hackers Aimed for Physical Destruction, WIRED.

Tags: Global Commission on the Stability of Cyberspace.


CISA Chief: Ransomware Attacks ‘Pretty Close’ to Large-Scale Cyber Event, Meritalk.

Tags: Global Commission on the Stability of Cyberspace.


Hybrid and cybersecurity threats and the European Union’s financial system, Breugel.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Notorious GandCrab hacker group ‘returns from retirement’, BBC.

Tags: GCSC Norm Against Offensive Cyber Operations by Non-State Actors.


High-severity vulnerability in vBulletin is being actively exploited, ARS.

Tags: GCSC Commissioner Jeff Moss.


Singapore payment card data compromised by JavaScript sniffers, ComputerWeekly.

Tags: GCSC Commissioner Ilya Sachkov.


 Conflict in Cyberspace


Revealed: How a secret Dutch mole aided the U.S.-Israeli Stuxnet cyberattack on Iran, Yahoo

Tags: Global Commission on the Stability of Cyberspace.


‘Nederland hielp bij hackaanval op Iraans atoomprogramma’, NOS.

Tags: Global Commission on the Stability of Cyberspace.


North Korea denies it amassed $2 billion through cyberattacks on banks, Reuters.

Tags: Global Commission on the Stability of Cyberspace.


Cyber Command’s biggest VirusTotal upload looks to expose North Korean-linked malware, CyberScoop.

Tags: Global Commission on the Stability of Cyberspace.


U.S. Files Criminal Charges Against Chinese Professor Linked to Huawei, The Wall Street Journal.

Tags: Global Commission on the Stability of Cyberspace.


Information warfare should be treated like call-for-fire missions, Army Cyber says, Army Times.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


The Saudi oil attacks could be a precursor to widespread cyberwarfare — with collateral damage for companies in the region, CNBC.

Tags: Global Commission on the Stability of Cyberspace.


Senator Mark R. Warner on U.S.-China Competition, USIP.

Tags: Global Commission on the Stability of Cyberspace.


CyberPeace Institute to Support Victims Harmed by Escalating Conflicts in Cyberspace, CISION.

Tags: GCSC Commissioner Khoo Boon HuiGCSC Commissioner Marietje Schaake.


Humanitarian Implications of Cyber Conflicts, CSIS.

Tags: GCSC Commissioner James Andrew Lewis.


Industry and Civil Society Developments


France says social media platforms will still sign hate speech pledge, Reuters.

Tags: Global Commission on the Stability of Cyberspace.


Better Security And Business Outcomes With Security Performance Management, Forrester.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Seventh African School on Internet Governance to take place in N’Djamena, Chad, on 4-9 September, APC.

Tags: GCSC Commissioner Anriette Esterhuysen.


Regulator Weighs Disclosing Names of Utilities That Violate Grid Security Rules, The Wall Street Journal.

Tags: GCSC Norm to Create a Vulnerability Equities Process.


Submission to Global Commission on Stability of Cyberspace on the definition of Cyber Stability, CIS.

Tags: Global Commission on the Stability of Cyberspace.


Cyber AI Platform, DarkTrace.

Tags: GCSC Co-Chair Michael Chertoff.


The Great Anti-China Tech Alliance, Foreign Policy.

Tags: Global Commission on the Stability of Cyberspace.


Why Companies Are Forming Cybersecurity Alliances, Harvard Business Review.

Tags: Global Commission on the Stability of Cyberspace.


Raising the resilience quotient, PWC.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Cyber Crisis: Foundations of  Multi-Stakeholder Coordination, Council to Secure the Digital Economy (CSDE).

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


The C2 Consensus on IoT Device Security Baseline Capabilities, Council to Secure the Digital Economy (CSDE).

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


My way or the Huawei: how US ultimatum over China’s 5G giant fell flat in Southeast Asia, SCMP.

Tags: GCSC Commissioner James Andrew Lewis.


The NCCoE released a draft of the NIST Cybersecurity Practice Guide, SP 1800-23, Energy Sector Asset Management, on September 23, 2019, and is requesting your feedback, NCCoE.

Tags: GCSC Norm to Reduce and Mitigate Significant Vulnerabilities.


Companies Face Uncertainty Over Challenges to Trans-Atlantic Data Transfers, The Wall Street Journal.

Tags: Global Commission on the Stability of Cyberspace.


The side projects of Mark Zuckerberg, from building a nightlight and a robot to his new podcast, BI India.

Tags: GCSC Commissioner Jonathan Zittrain.


Breach Updates


Recent ransomware surge linked to Russian criminal group, StateScoop.

Tags: GCSC Norm Against Offensive Cyber Operations by Non-State Actors.


Paige Thompson Charged With Hacking 30 Organizations, Bank Info Security.

Tags: GCSC Norm Against Offensive Cyber Operations by Non-State Actors.


Supermicro Bug Could Let “Virtual USBs” Take Over Corporate Servers, Wired.

Tags: GCSC Norm to Protect the Public Core of the InternetGCSC Norm Against Offensive Cyber Operations by Non-State Actors., GCSC Norm to Reduce and Mitigate Significant Vulnerabilities.


iPhone Hackers Caught By Google Also Targeted Android And Microsoft Windows, Say Sources, Forbes.

Tags: Global Commission on the Stability of Cyberspace.


Hong Kong Cyber Attack Briefly Disrupts Key Protester Forum, Bloomberg.

Tags: Global Commission on the Stability of Cyberspace.


IoT security: Now dark web hackers are targeting internet-connected gas pumps, ZDNet.

Tags: GCSC Norm to Reduce and Mitigate Significant Vulnerabilities.


Political targets at risk as Fancy Bear returns with refreshed backdoor malware, ZDNet.

Tags: Global Commission on the Stability of Cyberspace.


‘Carpet-bombing’ DDoS attack takes down South African ISP for an entire day, ZDNet.

Tags: GCSC Norm to Protect the Public Core of the InternetGCSC Norm Against Offensive Cyber Operations by Non-State Actors.


Security Warning For 23 Million YouTube Creators Following ‘Massive’ Hack Attack, Forbes.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Democracy and Electoral Infrastructure


Unlike U.S., Canada plans coordinated attack on foreign election interference, Politico.

Tags: GCSC Norm to Create a Vulnerability Equities Process.


Trump extends national emergency on foreign election interference, The Hill.

Tags: GCSC Norm to Protect the Electoral Infrastructure.


Former DHS chiefs: We should anticipate efforts to interfere in the upcoming election, CBSNews.

Tags: GCSC Co-Chair Michael Chertoff.


What would a vulnerability disclosure program look like for voting equipment? Expect an RFI soon, CyberScoop.

Tags: GCSC Commissioner Jeff Moss.


The Cybersecurity 202: How counties are war-gaming Election Day cyberattacks, Washington Post.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Senator Warner and Michael Chertoff at Digital Disinformation Symposium, C-SPAN.

Tags: GCSC Co-Chair Michael Chertoff.


Democracy, Disinformation, and the 2020 Threat: Recapping a PEN America Symposium, PEN.

Tags: GCSC Co-Chair Michael Chertoff.


Microsoft will offer free Windows 7 support for election officials through 2020, CyberScoop.

Tags: GCSC Norm to Protect the Electoral InfrastructureGCSC Norm to Reduce and Mitigate Significant Vulnerabilities.


“Technology should not disrupt democracy and the rule of law”, ERSTE Foundation.

Tags: GCSC Commissioner Marietje Schaake.


 Others


Avoiding Unintended Harm to Internet Infrastructure, IAB.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Marietje Schaake to Join Stanford Cyber Policy Center and Institute for Human-Centered Artificial Intelligence in Dual Policy Roles, Stanford.

Tags: GCSC Commissioner Maarietje Schaake.


Emerging Technologies and Managing the Risk of Tech Transfer to China, CSIS.

Tags: GCSC Commissioner James Andrew Lewis.


Hacking, Privacy, and Democratic Freedoms in the Information Age, New America.

Tags: GCSC Co-Chair Michael Chertoff.


Christopher Painter on Cyber Politics, UCD Clinton Institute.

Tags: GCSC Commissioner Christopher Painter.


The Law & Politics of Cyberattack Attribution, UCLA Law Review.

Tags: GCSC Norm Against Offensive Cyber Operations by Non-State Actors.


Exclusive: Edward Snowden’s First Adventures in Cyberspace, The Nation.

Tags: Global Commission on the Stability of Cyberspace.


Foreign intelligence in the digital age. Navigating a state of ‘unpeace’, The Hague Program for Cyber Norms.

Tags: Global Commission on the Stability of Cyberspace.


JPMorgan Hacker Will Plead Guilty Over Role in Vast Cyber-Attack, Bloomberg.

Tags: GCSC Norm on Basic Cyber Hygiene as Foundational Defense.


Decoding the GRU indictment, Medium.

Tags: Global Commission on the Stability of Cyberspace.


Dear network operators, please use the existing tools to fix security, ZDNet.
Tags: GCSC Norm to Protect the Electoral InfrastructureGCSC Norm to Reduce and Mitigate Significant Vulnerabilities.


The Art of Cyber Journalism, CSIS.

Tags: GCSC Commissioner James Andrew Lewis.


 Events


11 September 2019: Japan’s Response to Cyber Threats: Mega Events and Beyond, Reischauer Center for East Asian Studies.


21-22 September 2019: The Dark and the Digital, Institute of Art and Ideas.


26 September 2019: Securing Elections – Global Lessons Learned, Center for Cyber and Homeland Security.


1-3 October 2019: Singapore International Cyber Week, SICW.


2-3 October 2019: CyberCrimeCon/19, Group-IB.


4 October 2019: The state of OT cybersecurity in the utilities industry, Atlantic Council.


8-10 October 2019: GFCE Annual Meeting 2019, GFCE.


11-12 October 2019: GCSC Meeting in Addis Ababa, Ethiopia, GCSC.


14-16 October 2019: CyFy, ORF.


20-22 2019: 6th World Internet Conference Wuzhen Summit, Wuhzen Summit.


21-25 October 2019: Cyberweek, CyberScoop.


28-29 October 2019: AI Ethics, Policy, and Governance, Stanford University.


12-13 November 2019: Paris Peace Forum, PPF.


25-29 November 2019: Internet Governance Forum, IGF.


28-29 November 2019: CyberCrimeCon 2019 – Singapore, Qwoted.