NSA Data Stolen via Russian Anti-Virus Software

photo

The Department of Homeland Security recently barred federal agencies from using Kaspersky Lab products due to security concerns but has been tight-lipped about what intelligence linked the popular, Moscow-based computer security firm to specific intelligence operations.

Kaspersky Lab denied any knowledge of any role in the attack, but decried “news coverage of unproven claims continu[ing] to perpetuate accusations about the company” in a written statement.

“As a private company, Kaspersky Lab does not have inappropriate ties to any government, including Russia, and the only conclusion seems to be that Kaspersky Lab is caught in the middle of a geopolitical fight,” the company said. More here.

photo with more detail at this link

Russian hackers stole classified data from NSA contractor

Russian government hackers stole data about how the US penetrates foreign computer networks and defends against cyberattacks after a National Security Agency contractor removed highly classified material and stashed it on his home computer, a new report said Thursday.

The hackers apparently targeted the contractor after identifying the files through the contractor’s use of an anti-virus software made by the Russia-based Kaspersky Lab, The Wall Street Journal reported, citing sources familiar with the hacking.

Experts told the paper the hack was one of the most serious security breaches in years, and that it provided insight into how Russian intelligence exploits commercial software products to spy on the US.

The incident occurred in 2015 but wasn’t discovered until spring of last year, the sources told the WSJ.

The stolen material included details about how the NSA penetrates foreign computer networks, the computer code it uses for that kind of spying and how it defends American networks, the sources said.

The information could help the Russians guard their own networks, making it more difficult for American spooks to surveil Russia.

The breach was believed to be the first time that Kaspersky software, which is sold in the US, was exploited by Russian hackers as they spied on the US.

The revelation comes as special counsel Robert Mueller is investigating Russian meddling in the US election and possible collusion with the Trump campaign.

The president has called Russian hacking a “hoax” and “fake news” and slammed Mueller’s probe as a “witch hunt.”

A spokesman for the NSA would not comment on the security breach.

“Whether the information is credible or not, NSA’s policy is never to comment on affiliate or personnel matters,” the spokseman told the paper.

In a statement, Kaspersky said it “has not been provided any information or evidence substantiating this alleged incident, and as a result, we must assume that this is another example of a false accusation.”

The NSA contractor in the Kaspersky incident was not known, and the company he worked for was not identified.

Sources told The Journal he is believed to have taken home numerous documents and other materials from NSA headquarters, possibly to continue working beyond his normal office hours.

The man apparently did not knowingly work for a foreign government, but knew that removing classified information without authorization was a violation of NSA policies and potentially a criminal act, the sources said.

 

Refugee Proposal to Congress for 2018

Click here to see the report and numbers filed for previous years including locations.

 

 

(Reuters) – The United States will admit a maximum of 45,000 refugees during the 2018 fiscal year, President Donald Trump said in a memorandum to Secretary of State Rex Tillerson and released by the White House on Friday.

The cap, the lowest in decades, was proposed by the administration in a report to Congress on Wednesday.

Refugee advocates say the lower limit ignores growing humanitarian crises around the world that are causing people to flee their native countries in greater numbers, and represents a departure from U.S. global leadership.

The Trump administration says the lower cap is necessary so that U.S. officials can address a growing backlog of people applying for asylum inside the United States, and to do better vetting of refugees.

In its report to Congress, which was reviewed by Reuters, the administration said it may assess refugees on their “likelihood of successful assimilation and contribution to the United States.”

***

Then there is DACA:

A major deadline for recipients of the Deferred Action for Childhood Arrivals policy, or DACA, has arrived as the Trump administration continues to press forward in rolling back the Obama-era program for young undocumented immigrants.

Under the program, these immigrants, who entered the U.S. as children have been able to receive renewable two-year deferred action from deportation so that they can work or go to school.

As part of the wind-down process announced by Attorney General Jeff Sessions last month and under the leadership of the Department of Homeland Security, those eligible for DACA had until Thursday to properly file for a renewal request and other associated applications for employment authorization to the U.S. Citizenship and Immigration Services (USCIS).

After Thursday, young undocumented immigrants will not be able to apply for renewal of their DACA status.

According to DHS, eligible individuals are DACA recipients whose DACA and work authorization expire between Sept. 5, 2017, and March 5, 2018, inclusive. Of the approximately 154,200 individuals whose DACA is set to expire between Sept. 5, 2017, and March 5, 2018, just over 106,000 either have renewal requests currently pending with USCIS, or have already had USCIS adjudicate their renewal request.

Acting Secretary of DHS Elaine Duke released a memo on Wednesday urging all those still eligible to request a renewal of their DACA status as soon as possible if they have not done so already.

“I urge you to make this a priority. The renewal process is quicker than an initial request and requires minimal documentation, so take the time now to fill out and properly file your renewal request.  It is imperative that USCIS physically receives your request by October 5th,” said Duke.

USCIS has also been frequently updating applicants over social media, urging followers to file their requests in order to get their case adjudicated in time.

But in light of the recent devastation in Puerto Rico, which left millions without power, food or shelter, Duke said she has directed USCIS to consider on a “case-by-case basis DACA requests received from U.S. Virgin Islands and Puerto Rico residents.”

“As of today, fewer than 20 current recipients from the U.S. Virgin Islands and Puerto Rico have yet to renew with USCIS,” she added.

Since the announcement, several lawmakers have made moves on drafting legislation to serve as a temporary fix to the DACA program as the roll back allowed for six months of adjudication, time that Congress could use to develop new immigration laws.

President Trump hosted a dinner last month with Democratic leaders Nancy Pelosi and Chuck Schumer which caused an uproar after the two Democrats issued a statement saying they had they had agreed to finalize a law “quickly” that would protect DACA recipients, and that the law would also include border security, “excluding the wall.” More here.

Russian Ad: Black Woman Brandishing a Rifle

Facebook is expected today to provide the US Congress with evidence concerning 2016 election ads purchased by Russia’s Internet Research Agency. Bots have become more visibly active in social media; their tendency has been to exacerbate conflict without much discernible interest in conflict’s outcome. US Senator Warner (D-Virginia), vice chair of the Senate Intelligence Committee, thinks social media have now become decidedly weaponized.

Congressional investigators could combine Facebook’s data with that which Twitter has pledged to provide. This includes data on 201 accounts suspected of having engaged in misinformation campaigns on Twitter, and $274,100 in spend on U.S. ads in 2016 by Russian government-linked news outlet Russia. More here.

photo

***

One of the 2016 election ads that Facebook sold to Russia-linked accounts showed the image of a black woman brandishing a rifle, an apparent attempt to stoke racial tensions in the U.S., according to The Washington Post.

The ad is among those that Facebook is handing over to Congress as part of the Russia investigation.

The Post reported that the ad showed the woman “dry firing” a rifle — meaning that she was pulling the trigger while the gun was unloaded.

None of the ads in the trove that Facebook is handing to Congress have been made public, though leaks have suggested that the ads were aimed at playing up divisive issues. More here from The Hill.

***

“For the ways my work was used to divide people rather than bring us together, I ask forgiveness and I will work to do better” Mark Zuckerberg posted to Facebook tonight on Yom Kippur, the Jewish day of atonement. Yet first Facebook must redeem itself by recognizing how its dewy-eyed trust in the world can be abused.

Zuckerberg has recently faced stern criticism from liberals over Facebook’s failure to block fake news and Russian interference in the 2016 U.S. election, while simultaneously having Facebook called “anti-Trump” by the President himself.

Today’s statement was met with mixed reactions, with some pointing out that Zuckerberg had listed himself as an atheist until late 2016 when he reaffirmed the Jewish faith in which he’d been raised.

“Oh former atheist Mark Zuckerberg, suddenly so religious now that he’s aiming for the world’s presidency. To make it very clear: no problem in being an atheist whatsoever; the problem is to use religion as a political tool” Brazilian ad platform Boo Box co-founder Marco Gomes tweeted.

“Forgiveness is denied by both. God and humanity, since you & Sheryl knew what was happening, condoned it, & then lied about both its existence and impact” tweeted Matt Ocko, partner at VC fund Data Collective. Journalists from the New York Times and Wall Street Journal cautiously shared Zuckerberg’s post without comment.

Facebook has shown significant progress in thwarting interference in elections in Germany and France, deleting malicious accounts and working closely with election commissions. But as more information about the extent of Russian meddling in the U.S. presidential race emerges, Zuckerberg has come under additional fire.

Source: Volkan Furuncu/Anadolu Agency + David Ramos/Getty Images

The company has repeatedly been warned of abuse and its inadequate responses, yet dismissed issues as edge-cases or bugs in its system. Back in 2015, Russian trolls attacked Ukrainian protesters with false reports of inappropriate content, causing their accounts to be taken down. Now news continues to unfold about Russians posting fake news and buying ads to stoke anti-immigrant sentiments in the US, discourage democrat voters, and further divide the country.

Matters worsened when Zuckerberg responded to Trump tweet that “Facebook was always anti-Trump” by saying “Trump says Facebook is against him. Liberals say we helped Trump. Both sides are upset about ideas and content they don’t like. That’s what running a platform for all ideas looks like.”

That response derided critics as close-minded and washed over Facebook’s troubles as being inevitable while highlighting Facebook’s positive impacts on the election. It also cowed to Trump’s go-to tactic of bullying his opponents in hopes of receiving softer treatment. Zuckerberg was baited into positioning Facebook as neutral despite Russian election interference coming to the aide of Trump’s campaign.

By saying criticism comes from all-sides with Facebook in the middle instead of directly rebuking the President’s statement, Zuckerberg puts Facebook in a tenuous situation. If its internal investigation into election interference reports the Russians aided Trump, the President can merely dismiss it as the “anti-Trump” sentiment he warned about. More here.

450 Arrested ‘Operation Safe City’

 Related reading: Operation Safe Surrender and Operation Clean Slate

ICE arrests over 450 on federal immigration charges during Operation ‘Safe City’

09282017_Operation_Safe_City_DOJ

WASHINGTON – U.S. Immigration and Customs Enforcement (ICE) Enforcement and Removal Operations (ERO) Fugitive Operations teams arrested 498 individuals from 42 countries for federal immigration violations in multiple cities across the U.S. during a four-day operation that ended Wednesday. Operation ‘Safe City’ focused on cities and regions where ICE deportation officers are denied access to jails and prisons to interview suspected immigration violators or jurisdictions where ICE detainers are not honored.

The operation targeted individuals who have violated U.S. immigration laws, prioritizing aliens with criminal convictions, pending criminal charges, known gang members and affiliates, immigration fugitives and those who re-entered the U.S. after deportation. Individuals with active DACA were not targeted for arrest.

“Sanctuary jurisdictions that do not honor detainers or allow us access to jails and prisons are shielding criminal aliens from immigration enforcement and creating a magnet for illegal immigration,” said ICE Acting Director Tom Homan. “As a result, ICE is forced to dedicate more resources to conduct at-large arrests in these communities.”

“ICE’s goal is to build cooperative, respectful relationships with our law enforcement partners to help prevent dangerous criminal aliens from being released back onto the streets. Non-cooperation policies severely undermine that effort at the expense of public safety,” he said.

Operation Safe City arrests took place in Baltimore (28), Cook County, Illinois (30), Denver (63), Los Angeles (101), New York (45), Philadelphia (107), Portland, Ore. (33), Santa Clara County, Calif (27); and Washington, D.C. (14) and the state of Massachusetts (50).

Among those arrested during this week’s operation were:

  • In Baltimore, a citizen of El Salvador who entered the U.S. illegally on a fraudulent passport, and was previously charged with attempted murder/conspiracy to commit murder and convicted of first degree assault. She was previously released from local custody before ICE could assume custody.
  • In Boston, a citizen of India who entered the U.S. illegally and who was convicted of indecent assault/battery on a person over 14 and was required to register as a sex offender.
  • In Denver, a citizen of Guatemala with lawful permanent legal status who was previously convicted of felony menacing, 6 DUIs, child abuse, assault and domestic violence harassment.
  • In Los Angeles, a citizen of Mexico and documented Colonia Chiques gang member who entered the United States illegally. At the time of his arrest, the subject rammed multiple law enforcement vehicles in an effort to evade arrest. After he was placed under arrest, a search of his person revealed a loaded handgun in his pocket. The subject was turned over to local authorities and charged with assault with a deadly weapon, probation in possession of firearm, carrying a concealed weapon and carrying a loaded firearm in public.
  • In New York, a citizen of Ecuador with lawful permanent resident status who was previously charged with sexual abuse of a minor and convicted of endangering the welfare of a child, and convicted of sexual abuse of a minor under 14. He was previously released from local custody before ICE could assume custody.
  • In Philadelphia, a citizen of the Dominican Republic, who entered the country illegally and who has previous convictions for possession of firearms. He was previously released from local custody before ICE could assume custody.
  • In San Francisco, a citizen of El Salvador who entered the country illegally and who has previous convictions for sex with a minor under 16. He was previously released from local custody before ICE could assume custody.
  • In San Jose, a citizen of Mexico who entered the U.S. on a visa and overstayed that visa for more than 10 years. He was previously convicted of felony possession and purchase of narcotics, possession of a controlled substance for sale, and felony child cruelty with the possibility of injury or death. He was previously released from local custody before ICE could assume custody.
  • In Seattle, a citizen of Mexico who entered the country illegally and who has previous convictions for DUI, reckless endangerment and negligent driving.
  • In Washington, D.C., a citizen of El Salvador who entered the country illegally and who has previous convictions for possession of an unregistered firearm and unlawful possession of ammunition.

Of the 498 individuals taken into custody during this operation for immigration violations:

  • 317 had criminal convictions, as noted in the chart below;
  • 68 are immigration fugitives;
  • 104 are previously deported criminal aliens; and
  • 18 are gang members or affiliates.

***

Seems we still cant get things right and comply with all the recommendations made in 2004 by the 9/11 Commission.

The Global Entry Program provides expedited clearance for pre-approved, low-risk international travelers and members of these programs can expect expedited processing when entering the United States using automated kiosks at airports. As an added benefit, Global Entry members are also eligible to participate in the TSA Pre✓™, the Transportation Security Administration’s expedited security program.

Travelers interested in enrolling in Global Entry can learn more about that and other CBP Trusted Traveler Programs or apply online through the CBP website. Read more here as a second center just re-opened again in Boston.

Mueller Obtains Search Warrant on Facebook

Facebook sold ads for up to $100,000 each incident. Facebook is expected to send a representative to participate in a panel in a Senate hearing.

It is also important to note Russia Today, now known as RT is to formally register as a foreign agent. Sputnik News may be asked to do the same.

Related reading: FBI investigates Russian government media organizations accused of spreading propaganda in U.S.

  Photo

In part from Newsweek:

The recent news that Robert Mueller obtained a search warrant for the contents of Facebook accounts associated with Russian operatives trying to undermine the 2016 presidential election was a key turning point in our knowledge of his investigation that could transform the scope of the inquiry and the legal strategy of the people in the special counsel’s sights.

Before news of the Facebook search warrant broke, it appeared that Mueller was focused on several discrete areas of inquiry, such as potentially false disclosures by former Trump campaign chair Paul Manafort, potential tax charges and alleged obstruction of justice related to President Donald Trump’s firing of former FBI Director James Comey. Mueller’s warrant tells us that the special counsel is closing in on specific foreigners who tried to undermine our democracy, that he’s serious about going after Russian interference and he is far enough along to convince a federal judge that he has good evidence of such a crime. Read the full article here.

Deeper Dive

The Hill: The American public should be furious about the recent revelations regarding Russian manipulation of social media. What the public should not be is surprised. Although exploitation of cyber venues may be a new twist, it is just another chapter in an old story.

For the better part of a century, Russia (including its Soviet predecessor), Soviet proxies, as well as other countries have attempted to exploit wedge issues and social unrest to interfere with U.S. internal politics. These countries’ objectives are likely twofold: driving policies toward a desired outcome and forcing the United States to focus inward, distracting it from international developments.

From the 1930s onward, the Soviet Union and its Russian successor have consistently exploited divisions in American society to Moscow’s advantage. Moscow, starting with its Popular Front strategy in the mid-1930s, has insinuated its proxies into grievance-driven domestic coalitions.

 

These ranged from the Great Depression’s disenfranchised, to the anti-nuclear and pro-peace crowds. More recently, according to the Office of the Director of National Intelligence, Russia attempted to co-opt populists on both ends of the ideological spectrum by facilitating both the Occupy movement, via the Russian television network RT, and the far right, members of which have looked to Vladimir Putin as an exemplar of traditional values.

In addition to efforts at co-optation of mass movements, the Soviet Union attempted to inflame tensions within American society. In the 1960s, Soviet officials skulked around Capitol Hill, querying offices on a variety of issues including the dynamics of the civil rights movement.

For instance, one official specifically wanted to know about which civil rights leaders had been excluded from a White House meeting. This collection activity probably indicated Moscow’s desire to get smarter on a hot-button topic, which it could then exploit through an “active measures” campaign.

The civil rights issue came full circle when, in 1980, the Soviets surfaced a forgery which purported to show the U.S. government as using the CIA against African-Americans.

Cuba, a Soviet satellite, pursued similar disruptions against the United States. The Cuban government viewed American minorities as a constituency that Havana could incite to create mayhem on U.S. soil. Fidel Castro, himself, suggested that he could prompt a race riot at a time of his choosing.

Furthermore, Cuba arguably attempted to weaponize criminality against the United States when, in 1980, it seeded 8,000 criminals into the Mariel boatlift’s refugee population.

Given Venezuela’s status as a protégé of Cuba, it is hardly surprising that Caracas, under Hugo Chavez, sought to exploit socioeconomic tensions by distributing subsidized heating oil for low-income Americans as a propaganda ploy.

The Soviet/Russian-perpetrated and inspired attempts to exploit divisive U.S. political issues is notable but hardly unique to Moscow and its minions. China, during the 1960s, courted U.S. Maoist-inspired groups, including the Revolutionary Union, that embraced militancy.

More recently, the Chinese government, known for keeping a tight rein on social media, nevertheless seemed to let its WeChat platform off the leash to stir up rallies against the New York Police Department in 2016.

This history of foreign-sponsored disruption suggests that U.S. adversaries and competitors are sufficiently knowledgeable about the tensions within American society to effectively exploit them. The jury is out on whether Washington is paying similar attention.

Both the Church and Pike investigations of American intelligence in the mid-1970s produced skittishness about looking too closely at domestic actors, as indicated by the guidelines issued by Attorney General Levi, in 1976, regarding domestic security investigations.

Such trepidation about identifying dangerous domestic dynamics appears to persist, if the outraged reaction to the Department of Homeland Security’s 2009 report on right-wing extremism is any indication. Is it possible that risk-aversion has become willful blindness?

Social media may be a new front in foreign exploitation of tensions in the United States, but the underlying concept of exacerbating divisions and inciting conflict on American soil is a timeworn strategy.

Although Russia is the perpetrator of current interest, it is not alone in its effort to disrupt American politics through the sowing of dissent and division.

For Washington to anticipate (and, hopefully, deter) future, foreign-sponsored attacks on the public’s perceptions, it must ensure that it is aware of the vulnerabilities inherent to the domestic setting that U.S. adversaries and competitors may manipulate to their advantage.

Darren E. Tromblay served as an intelligence analyst with the U.S. intelligence community for more than a decade and is the author of the forthcoming book, “Foreign Influence on U.S. Policymaking: How Adversaries and Allies Manipulate and Marginalize the American Electorate,”