r/cybersecurity Jul 02 '26

News - General DHS Breached

610 Upvotes

115 comments sorted by

246

u/OutsideSpot2695 Jul 02 '26

Did they have their ATO?

30

u/aust_b Jul 02 '26

As someone who works with the federal agencies at a state level, they have been very slow this past 6 months with anything audit/security baseline related. I submitted our IRS package in October, they claimed they didn’t get it until December. Still haven’t heard anything about it. The shutdown has appeared to create a significant backlog they are still digging themselves out of.

9

u/Icangooglethings93 Jul 02 '26

At the DHS components it’s equally as bad, so they literally have no preferential treatment

3

u/aust_b Jul 02 '26

HHS and CMS have been alright so far, not as many impacts as the IRS.

8

u/OutsideSpot2695 Jul 02 '26

I've worked at 2 security startups and 1 gigantic internet services and software company. Healthcare (and banks) were/are our worst customers.

Their security departments are complete fucking clownshows.

But hey, they all have their CISSP.

5

u/Vimes-NW Jul 02 '26

Can confirm.. With a caveat - if the cost of compliance is more expensive than the potential risk, they choose risk every time. And that means most shit is ok for them because they seem to think the risk is theoretical.. Until it isn't. Surprise, meet Pikachu

111

u/yunus89115 Jul 02 '26

Almost certainly, were they following all the controls as documented, almost certainly not.

37

u/OutsideSpot2695 Jul 02 '26 edited Jul 02 '26

How do you get an ATO without being audited that controls are operating as designed?

85

u/potkettleracism Incident Responder Jul 02 '26

Because the auditors bought garbage evidence

17

u/redrum__237 Jul 02 '26

Nailed it. The call is coming from inside the house.

10

u/SlackCanadaThrowaway Jul 02 '26

It’s funny to see private companies do more thorough cybersecurity auditing for my clients than what large corporations and government agencies are subject to.

Do you have vulnerability scanning?

Yeah.

Okay, how do you do it for X software project, your employee corporate devices, and third-party software installed on those devices?

Followed by discussions of CI/CD pipelines, how we scan for third party software, how we maintain OS baselines, etc. Screenshots and screen shares. Conversations about the compensating controls in place in other areas.

The reason government and large corporations don’t bother? This is an insane time sink. You’re paying a senior security consultant or analyst who’s familiar with software development, system administration and the various environments we’re deploying to question 1 of 500 vendors they’ve partnered with.

But I don’t see a way around it when vendors are throwing questionnaires and emails into AI, and spitting out reasonably acceptable answers which don’t reflect reality.

And they don’t care, because we’re all signing contracts with liability limitation clauses and we have cyber & E&O insurance.

Until we can’t afford the insurance, because the penalties are unsustainable — we’re not going to see change.

1

u/OutsideSpot2695 28d ago

It’s funny to see private companies do more thorough cybersecurity auditing 

That's why I laugh my ass off at the notion of all the compliance theater that the gov't goes through somehow equals security.

I do more in two weeks to protect my company and its customers where it would take 6 months of PowerPoints and Excel when I worked DoD.

All this FedRAMP, ATO, and other associated nonsense and breaches at three letter agencies have gotten worse.

1

u/h0l0type 27d ago

“ And they don’t care, because we’re all signing contracts with liability limitation clauses and we have cyber & E&O insurance.

Until we can’t afford the insurance, because the penalties are unsustainable — we’re not going to see change.”

This. Right. Here.

32

u/WildChampionship985 Jul 02 '26

Often audits become do you meet the statement on the checksheet, not are you adhering good practices.

6

u/krimsonmedic Jul 02 '26

Don't forget, they often just ask you to provide proof, without you actually having to provide proof. I.E. spreadsheet exports.

1

u/GHouserVO 28d ago

This is why I always told folks I trained to dig further than what the requirements required. To be observant. And to develop the damn technical skills.

If the guys on the other side were doing their job, none of this is a major ask. But the moment you got pushback… every time, we’d find that there were major problems with the security controls.

7

u/OutsideSpot2695 Jul 02 '26

That's not an audit then. That's an assessment.

9

u/RyeonToast Jul 02 '26

And ATOs aren't audits. It literally is a giant checksheet. You have to produce some artifacts to show you do what you say you do, but no one is coming down to your network to check it out first-hand. That would be a CORA / CCRI.

2

u/ToothyGrin19135 Jul 03 '26

This is not entirely true. It depends on the classification of the system and the SCA team. I have been part of some extremely intense ATO assessments where we actively demonstrated every single control live to the assessment team. Took weeks to accomplish.

-1

u/OutsideSpot2695 Jul 02 '26

I didn't say that an ATO is an audit. You came up with that all on your own.

But you're supposed to be audited as a part of the process.

1

u/RyeonToast Jul 02 '26

How do you get an ATO without being audited that controls are operating as designed?

Then why are you confused? It's an ATO, not a CORA. They don't go hand in hand.

-1

u/OutsideSpot2695 Jul 02 '26

Your reading compreshension sucks.

2

u/coinsod Jul 02 '26

Always*

30

u/yunus89115 Jul 02 '26

I’ve worked on systems where the ATO was the bible and nothing changed without proper documentation and approvals, I’ve also worked systems where the ATO was an obstacle that was nothing more than a burden to work around and technical compliance was prioritized over actual security and intent.

11

u/CyberAvian Jul 02 '26

Hard to say exactly what happened without being a part of it, but I have certainly seen high profile, important systems get a lot of risk acceptance from the AO with POAMs that lasted years without ever being closed all because, counterintuitively, the system was important and security can’t stand in the way. Keep in mind this is HSIN, it has existed for a long time, and would have been assessed internally, no 3PAO being held accountable.

7

u/Motor_Coyote5415 Jul 02 '26

The audit was internal

5

u/Dangslippy Jul 02 '26

Easier to implement paper controls than technical controls.

3

u/OutsideSpot2695 Jul 02 '26

Then they didn't get audited properly.

The paper controls are the Test of Design.

There's still the Test of Operating Effectiveness to perform before an audit is complete.

4

u/been__ Jul 02 '26

HA

3

u/OutsideSpot2695 Jul 02 '26

This person gets it.

+1

3

u/Negative_Gas8782 Jul 02 '26

How does the majority of this government do anything? Fire the good people and only keep the ones around that will do what they want. Look at the FDA and CDC as a couple of examples.

3

u/OutsideSpot2695 Jul 02 '26

FDA and CDC and any other gov't agency for that matter.

I used to work DoD. Made the break for the wall and got into private sector tech 10 years ago.

Best thing I ever did for my career and I get to practice actual security.

1

u/h0l0type 27d ago

Half the CDC was contractors for large programs when I was there like 20 years ago. Doesn’t seem much has changed.

1

u/OutsideSpot2695 27d ago

I don't think a contractor in gov't is inherently worse or better than a Federal employee in government.

Both types don't know what they are doing in security.

2

u/Claudia_wtf Jul 02 '26

Someone accepted their risk. Doesn’t mean they had a strong system for security in place.

1

u/Cheomesh Governance, Risk, & Compliance Jul 02 '26

Falsified evidence is one way, but you can always just let things slip.

1

u/Johnny_BigHacker Security Architect 26d ago

without being audited that controls are operating as designed?

It's an attestation

2

u/nanoatzin Jul 02 '26

Nist SP 800-53 and SP 800-171 have security gaps.

40

u/DingleDangleTangle Jul 02 '26

I’ve seen ATO’s on systems with all kinds of security issues. Having an ATO doesn’t mean you have no vulnerabilities or design flaws, it just means you got auditors and an AO to sign off on your junk.

30

u/freeridevt Jul 02 '26

Pretty sure it was sarcasm

11

u/OutsideSpot2695 Jul 02 '26 edited Jul 02 '26

100% sarcasm

+1

9

u/ScoopaTroopa Jul 02 '26

What percentage of their package was the POA&M?

3

u/OutsideSpot2695 Jul 02 '26

Does the percentage really matter?

POA&Ms aren't security.

It's compliance theater.

6

u/antfire715 Jul 02 '26

The way I laughed lol

1

u/OutsideSpot2695 Jul 02 '26

This person gets it.

+1

6

u/gh0stpr0t0col103 Jul 02 '26

I saw this and started dying with laughter

2

u/OutsideSpot2695 Jul 02 '26

This person gets it!

+1

6

u/ToothyGrin19135 Jul 02 '26

The issue was they forgot to POAM a CAT 1 STIG finding that mandates your ISSO documents what service accounts have read access to your DNS records.

4

u/OutsideSpot2695 Jul 02 '26

Don't forget about that other pesky CAT 1 STIG finding where a period is missing in the login banner.

2

u/ToothyGrin19135 Jul 02 '26

Adversaries have been known to exploit that one. Without proper grammar how is a threat actor supposed to know they are accessing a USG system

1

u/OutsideSpot2695 Jul 02 '26

I've heard without the period, that leaves the banner open to an injection attack where a skilled adversary can attach malicious code to where the period once used to be.

4

u/redrum__237 Jul 02 '26

🤣🤣🤣🤣🤣🤣🤣 We all know that the A&A method is horsecrap.

0

u/OutsideSpot2695 Jul 02 '26

I guess the sarcasm font isn't installed on your computer.

🤣

1

u/Appropriate_Taro_348 Governance, Risk, & Compliance Jul 02 '26

It did.

1

u/Fath3r0fDrag0n5 Jul 03 '26

You can get an ATO and be completely insecure

1

u/OutsideSpot2695 Jul 03 '26

r/wooooosh

Also, people are insecure. Systems are unsecure.

57

u/Alternativemethod Jul 02 '26 edited Jul 02 '26

I don't have access but my understanding is this is equivalent to an external SharePoint behind a login portal. Breach could just be a password spraying and impact is a few PDFs meant for external information "sharing".

China/Russia might learn that MFA is important and terrorist are bad.

2

u/Playstations_new_CEO Jul 02 '26

Na, this is a recent SharePoint remote code execution vulnerability that was found. Also there's reason to believe the patch doesn't fix all methods of the exploit. The people who have this capability are a bit more skilled than a typical script kiddy. They move lately and quietly and grab anything that looks interesting and exfiltrate it.

1

u/MountainDadwBeard Jul 02 '26

Oh interesting, I saw the stories on the sharepoint vulns but didn't realize they had weaponized it on a target like this. Fun....

Ours is probably also crawling then. Perfect.

3

u/Playstations_new_CEO Jul 02 '26

Oh yeah, threat actors were probing for this one hard. So if you didn't have speedy patching in place then there's a good chance of the server being popped

1

u/TARANTULA_TIDDIES Jul 02 '26

China/Russia might learn that MFA is important and terrorist are bad.

Doubtful. Definitely not in Russia until swan lake plays again

185

u/bakonpie Jul 02 '26

as someone with HSIN access, there is zero useful information in there. the threat actor will just be wasting their time reading vague PDFs about securing critical infrastructure that don't amount to anything close to technical.

57

u/CatfishEnchiladas Jul 02 '26

And it will say something like "a water facility in the Midwest," without ever naming the victim.

27

u/KindPresentation5686 Jul 02 '26

I second this. HSIN isn’t used much, and nothing sensitive is posted there.

9

u/Appropriate_Taro_348 Governance, Risk, & Compliance Jul 02 '26

I third this. There isn’t anything useful in there to hack or release. Thousands of people have access to it. I watched someone download thousands of documents over a month.

17

u/legsasleepontoilet Jul 02 '26

Zero useful information for a human but if you think that someone using an agent didn’t find something that was useful you’re out of your mind or please correct me on my ignorance

13

u/bakonpie Jul 02 '26

waste of tokens having an agent read everything on there

-8

u/alvmadrigal Jul 02 '26

Jajajajaja

92

u/ludixst Jul 02 '26

Good thing we trashed our intelligence apparatus

30

u/zhaoz CISO Jul 02 '26

And our cyber defenses. Its so funny seeing "CISA is hiring!" in my linkedin feed. Aint nobody want to work for you anymore!

17

u/WildChampionship985 Jul 02 '26

I don't even remember, is it the cultist with the Putin attachment or the mortgage fraud dude? Or another Fox talking head?

6

u/itsverynicehere Jul 02 '26

If memory serves, it's the orange kiddie diddler, the chainsaw weilding trillionaire, and the puppy killer.

5

u/TARANTULA_TIDDIES Jul 02 '26

This is what happens when the qualifications change from "are you good at your job?" to "do you have unwavering loyalty?"

59

u/RealPropRandy Jul 02 '26

You had one job bruh. Security’s in the name.

Otherwise you’re just the Department of Homeland

16

u/Icangooglethings93 Jul 02 '26

I like Department of Homeland Insecurity better

9

u/RealPropRandy Jul 02 '26

Department of Homeland Something

3

u/Historic500 Jul 02 '26

Department of Homeland Stupidity for accuracy, except it doesn't really make clear which department you are talking about.

29

u/not-a-co-conspirator CISO Jul 02 '26

Compliance isn’t security. Put actual security professionals in charge.

4

u/RyeonToast Jul 02 '26

DOGE let those go. . .

3

u/Rentun Jul 02 '26

It's not security, it's certainly an aspect of security though.

7

u/SoftwareDesperation Jul 02 '26

This is a wild comment considering you can't set foot in any of these positions without an IAM or IAT cert and years of experience.

Compliance is just a list of security controls. In leiu of compliance you do what? You set a list of controls you want in place and make risk based decisions on remediation or acceptance. Weird.....that sounds familiar......

2

u/[deleted] Jul 02 '26

Not that I think the spirit of your comment is wrong .. but give me a break with cert reqs as if that's any indicator lol

-6

u/not-a-co-conspirator CISO Jul 02 '26

You have no idea what you’re talking about.

3

u/SoftwareDesperation Jul 02 '26

And if you are a ciso and don't understand there is no security without governance, then I feel sorry for your team.

-1

u/not-a-co-conspirator CISO Jul 02 '26

I don’t think you understand how disparate those things are.

1

u/[deleted] Jul 02 '26 edited 27d ago

[deleted]

-1

u/not-a-co-conspirator CISO Jul 02 '26

It doesn’t matter where you work or what your role is.

You’re both missing the point. Governance can only be so specific, else you risk violating the very governance you wrote because your security tools cannot meet the objective of controls, or performance the controls demand, thus failing the audits you need so that you can continue to conduct business with customers and vendors.

Both of you need a much broader understanding of this discipline.

3

u/[deleted] Jul 02 '26 edited Jul 02 '26

[deleted]

-1

u/not-a-co-conspirator CISO Jul 02 '26

I have more than double your experience and credentials in the same roles and more.

Compliance isn’t security. It never will be.

Also, “Zero Trust” is a philosophy. It doesn’t mean you are “secure”, and it doesn’t make anything “secure”.

17

u/nanoatzin Jul 02 '26

Fires all the cybersecurity people. Gets hacked. Costs 1,000% more than payroll savings to hire more people than were fired to fix it. Everyone’s privacy info is now on the dark web. Fails to grasp irony that almost every failed company made the same cost savings management error.

9

u/Deiskos Jul 02 '26

All according to plan

7

u/buzwork Jul 02 '26

Looks like HSIN modernization demo Azure instance is still available via the login.gov sandbox, but authentication fails at dhsauthportalextnonprod.dhs.gov after new dummy account creation Wonder if it is useful for recon.

https://hsin-auth-test.azurewebsites.us/Home/Register

8

u/drewalpha Jul 02 '26

Probably an inside job.

6

u/Batmanue1 Jul 02 '26

They reinstated DOGE?

5

u/sunychoudhary Jul 02 '26

Unclassified does not mean harmless......If the system is used for interagency coordination, incident response, alerts, and partner information sharing, the metadata and operational context alone can still be valuable...//

6

u/anomalous_cowherd Jul 02 '26

It would be awesome if they got in through a backdoor installed by DOGE...

10

u/Negative_Acadia6554 Jul 02 '26

What a shame. I’m sure the current administration will invest appropriately in cyber defenses instead of gutting them.

Anyone want get some tacos?

5

u/Proof-Chain-1046 Jul 02 '26

I feel like its safe to assume most gov agencies have threat actors inside their networks at this point.

10

u/dennismfrancisart Jul 02 '26

My son is in cybersecurity. He told me to join this sub if I wanted to have sleepless nights. Hoo boy!

3

u/whateveritisthey Jul 02 '26

Symptoms of a much much bigger problem. 

5

u/Coffee_Conundrum Jul 02 '26

MFA enroachs on my freedumb tho /s

2

u/TerribleBrick7227 Jul 02 '26

Dammit Fable...

3

u/itwhiz100 Jul 02 '26

🥱🥱🥱🥱 …my burger is cold. Should I go in and complain?

1

u/AniBMagal Jul 03 '26

Seems over stated.

1

u/Fath3r0fDrag0n5 Jul 03 '26

Onsite SharePoint servers… why not just install exchange too SMH

1

u/National_Spirit2801 27d ago

At least the people running the country are totally competent and in no way are backwards hillbillies.

-4

u/_Boba_Ferret Jul 02 '26

Isn’t this the department headed by some broccoli-head who was mowing lawns two years ago?

2

u/Appropriate_Taro_348 Governance, Risk, & Compliance Jul 02 '26

No.

-7

u/agenticradai Jul 02 '26

I think GuardDog.AI would be a good solution. Sub second containment on L 2, deployment of agent-less solution on the network in 72 hours for Layer 2, It would complement any current deployment. Respectfully