← 返回日报
略读 预计 2 分钟

US Government says it got hacked – again

摘要

标题:US Government says it got hacked – again;类型:文章;正文摘录中,DHS 正在调查其 Homeland Security Information Network(HSIN)平台遭网络攻击,该平台供联邦、州和地方政府执法机构共享情报;黑客于 5 月底至 6 月初入侵 HSIN 服务器,可能暴露使用该平台的共享信息;DHS 发言人称已隔离受影响系统、缓解漏洞并启动调查,调查仍在进行;未披露被盗数据数量或细节;此前 2023 年安全漏洞显示 HSIN 包含执法机构共享的美国人个人信息;该事件使政府自身安全能力面临 scrutiny;参议员 Mark Warner 称 HSIN 支持 2026 年美国世界杯赛事,并用于去年美国航空公司客机与黑鹰直升机碰撞事故管理;黑客身份、动机未知;该事件是过去一年联邦政府多起网络漏洞之一,包括 Signal 泄露机密信息、DOGE 数据泄露和 CISA 承包商密码泄露。

荐读理由

HSIN 平台曾用于管理美军直升机坠机伤亡67人等真实紧急响应,泄露风险直接威胁国家安全;多起联邦系统遭黑且政府自保失败,点出AI工程创业中要优先自建安全架构才能避开政府级别的公关式漏洞

原文

The Department of Homeland Security is investigating a breach of its platform, which federal, state, and local governments and law enforcement use to share intelligence, with one senior lawmaker warning that the information spill could risk national security.

News sites Nextgov, which first broke news of the incident, and Bleeping Computer report that DHS officials are probing a cyberattack on its Homeland Security Information Network, or HSIN, which allows government agencies and local officials to plan, coordinate, and share information and intelligence about major events and respond to emergencies.

The hackers reportedly broke into HSIN servers during late May and early June, potentially exposing information shared using the platform, per Nextgov.

When reached by email, an unnamed DHS spokesperson said that the department is “aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment.”

“We immediately took action to isolate the affected systems, mitigate the vulnerability, and launch a comprehensive forensic investigation,” said the statement. The investigation is ongoing and the spokesperson declined to comment further.

It’s unclear what data was stolen or how much was taken, and Homeland Security did not answer TechCrunch’s questions about the incident. A previously reported security lapse during 2023 revealed that HSIN contained personal information shared among law enforcement related to the surveillance of Americans.

The incident involving HSIN puts fresh scrutiny on the government’s ability to defend the cybersecurity of its own systems, following over a year of deep cuts across the federal government, including Homeland Security and its cybersecurity agency CISA, under the Trump administration.

While the intelligence shared over HSIN is unclassified, the information “is highly sensitive, and its exposure risks national security,” said Mark Warner, a Democratic senator representing Virginia who also serves as the ranking member of the Senate Intelligence Committee, in a statement.

Warner said that the HSIN platform is supporting the World Cup games currently underway in the United States, and was also used last year to manage the response to the mid-air collision of an American Airlines jetliner and a U.S. Army Black Hawk helicopter over Washington, D.C., which killed 67 people.

The identity, affiliation, and motives of the hackers who targeted HSIN are not known, but the breach marks the latest security lapse to affect the federal government over the past year.

Since the Trump administration took office in January 2025, the federal government has been beset by several major cybersecurity breaches, including the sharing of classified information and war plans over apps like Signal that haven’t been cleared for government use, the raiding of federal databases of Americans’ personal information by members of Elon Musk’s Department of Government Efficiency, or DOGE, and a reported public spill of reams of passwords and credentials by a CISA contractor that exposed access to government cloud systems.

Earlier this year, the FBI notified lawmakers in Congress that it had to declare a “major cyber incident” after exposing the phone numbers of targets under surveillance by federal agents, potentially giving those adversaries a potential advantage.

Do you know more about the DHS HSIN cyberattack? We would love to hear from you. To contact Zack Whittaker securely, reach out via Signal username zackwhittaker.1337 or by email: zack.whittaker@techcrunch.com.

Updated with comment from Homeland Security.

Hacker News · 4 赞 · 0 评 讨论 → 阅读原文 →

这条对你有帮助吗?