Axios Codebook

March 31, 2023
😎 TGIF, everyone. Welcome back to Codebook.
- 🌉 Today's newsletter comes to you from Sausalito, California, where I've spent the last couple of days hanging out with some of the top cyber minds in the biz at the Verify Conference — a rare and delightful treat!
- 📬 Have thoughts, feedback or scoops to share? [email protected]
Today's newsletter is 1,423 words, a 5.5-minute read.
1 big thing: DOJ leans into transparency in surveillance fight
Illustration: Eniola Odetunde/Axios
The Justice Department's second-in-command is readying her case for Capitol Hill on why a controversial surveillance tool is key in the fight against cyber threats.
Driving the news: Deputy attorney general Lisa Monaco said during this week's Verify Conference in Sausalito that the DOJ is prepared to share more with lawmakers about how Section 702 of the Foreign Intelligence Surveillance Act assists the department's cyber investigations.
- Congress has until the end of the year to reauthorize Section 702, which allows intelligence agencies to collect warrantless surveillance of non-American citizens abroad.
- Monaco, in some of her first public remarks this congressional session about Section 702, said the program has helped "prevent foreign ransomware attacks" on U.S. critical infrastructure.
What they're saying: "A significant amount of the most vital intelligence that I see every morning when I read the president's daily brief is supported by 702 collection," Monaco said.
- "We used to talk about the importance of 702 on the terrorist front," she added. "But having now returned to government and consuming this information, I am really struck at how important it is when it comes to these issues of what our adversaries are doing in the cyber realm."
The big picture: Intelligence officials and law enforcement are facing mounting pressure to be more transparent about how data collected by the 702 program is used in ongoing investigations.
- Senate Intelligence Chair Mark Warner (D-Va.), who supports reauthorization, pushed intelligence officials during a hearing this month to "lean in" on declassifying information about the program's use cases.
- Monaco noted that DOJ has made improvements to the program in recent years "that addressed very important and legitimate privacy and civil liberties concerns and issues" while also "preserving the efficacy."
- A New York Times report this month indicates some of those changes include FBI agents seeking prior approval from a lawyer to search 702 data, among other changes.
Catch up quick: Monaco, alongside the broader intelligence community, is gearing up for what's expected to be a contentious fight on Capitol Hill.
- A group of House Republicans is already reportedly considering letting the surveillance authority disappear entirely.
- Gen. Paul Nakasone, leader of the Cyber Command and National Security Agency, made a similar argument to Monaco's earlier this year, arguing that the authority gives the U.S. "irreplaceable insights, whether we're reporting on cybersecurity threats, counterterrorism threats, or protecting U.S. and allied forces."
- The White House also released its official statement last month calling reauthorization of Section 702 a "top priority."
Yes, but: The surveillance power has come under fire due to the sheer amount of data inadvertently collected about Americans through the program.
- Data collected under Section 702 is stored in an accessible database for several years, allowing law enforcement officials to conduct unreported searches of the information in ways that aren't publicly known.
The intrigue: As of now, the intelligence community isn't preparing for Section 702's expiration.
- A senior Defense Department official told reporters during a dinner last week that there aren't contingency plans in place in the event the power expires. The official noted that the community does have other powers at its disposal to help fill the gaps.
Meanwhile, the prospect that Section 702 will pass without any reforms is growing more unlikely by the day.
- A member of the Privacy and Civil Liberties Oversight Board called on Congress earlier this month to implement several changes to the program, like requiring a warrant to search the 702 database.
Between the lines: Monaco said the DOJ is open to "improvements upon [the program] that keep the efficacy and address whatever concerns folks have."
2. Thousands vulnerable in supply chain attack
Illustration: Aïda Amer/Axios
Thousands of companies using the same voice- and video-calling application are now at risk, as North Korean hackers carry out an ongoing supply chain attack, several cybersecurity companies warned earlier this week.
Driving the news: CrowdStrike warned Wednesday that North Korea-linked hackers are actively attaching malware to the Windows and MacOS versions of 3CX's video conferencing tool.
- 3CX claims it has more than 12 million daily users and 600,000 enterprise customers, including Ikea, Toyota, BMW, Coca-Cola and McDonald's.
- Researchers at other firms, including SentinelOne, Check Point Research and Huntress, each confirmed the ongoing attack.
- The Cybersecurity and Infrastructure Security Agency said Thursday it's "aware" of the incident and encouraged organizations to hunt for indicators of compromise on their networks.
Why it matters: The malware started infecting users' devices as early as February, according to SentinelOne, and it's still unclear how many of 3CX's customers have been affected.
- The last time the U.S. faced a supply chain attack of this magnitude was in 2020 when Russia-linked hackers compromised SolarWinds, affecting at least nine federal agencies and roughly 100 companies.
The big picture: A successful supply chain attack would mark a huge escalation in North Korea's hacking prowess. Typically researchers see them either carrying out espionage via email phishing campaigns or hacking crypto firms to fund the regime.
- CrowdStrike believes the attack was carried out by "Labyrinth Chollima," which conducts espionage against the U.S. and South Korea for the North Korea regime's intelligence agency.
Between the lines: Supply-chain attacks are some of the hardest cyberattacks to prevent given businesses' limited visibility into their vendors' cybersecurity practices.
Be smart: 3CX CEO Nick Galea said in a blog post Thursday that customers should uninstall the app from their devices and avoid using the app "unless absolutely necessary."
- "In a day or two from now, we will have another Electron App rebuilt from the ground up with a new signed certificate," Galea wrote. "This is expected to be completely secure."
What's next: It's going to take weeks until the public has a better understanding of how long the attack has been going on, who was impacted and what access North Korea was able to get.
3. Kids' privacy at the top of Congress' agenda
Illustration: Sarah Grillo/Axios
Congress is under pressure to reintroduce and pass bills to bolster children’s online safety as states approve increasingly aggressive laws, Axios Pro: Tech Policy co-authors Maria Curi and Ashley Gold report.
Why it matters: Social media’s impact on young Americans’ mental health is one of the rare issues that has bipartisan interest on the Hill to get a law on the books, backing from the White House and buy-in from companies that dread a patchwork of state regulations.
Driving the news: Sens. Richard Blumenthal and Marsha Blackburn are looking to reintroduce their Kids Online Safety Act in mid- or late April, sources familiar with the discussions told Axios.
- They’re eyeing the weeks of April 17 or April 24, which would give the Senate time to hold a markup in the spring and a floor vote by the summer.
- Rep. Kathy Castor, who plans to introduce KOSA in the House, also plans to reintroduce her Kids PRIVCY Act, which would strengthen the Children’s Online Privacy Protection Act and adopt elements of the U.K.’s Age-Appropriate Design Code.
Yes, but: State-level online privacy efforts were supposed to prompt Congress to get it together and pass a federal law. That hasn’t happened, despite many new states moving forward with privacy proposals for kids and Americans of all ages.
What we’re watching: Look out for pushes to include preemption language in a kids’ measure.
To read more stories like this, subscribe to our new Axios Pro Tech Policy newsletter.
4. Catch up quick
@ D.C.
🐦 Elon Musk tried meeting with FTC chair Lina Khan late last year as the agency investigates Twitter's data security practices, but Khan declined. (New York Times)
💸 The U.S. government is giving Costa Rica $25 million to bolster cybersecurity efforts following last year's ransomware attacks. (Axios)
🤖 Italy's privacy regulator ordered a temporary ban on OpenAI's ChatGPT, claiming the company doesn't have a legal basis for "the mass collection and storage of personal data" in training algorithms. (Politico)
@ Industry
👀 More than 5,000 leaked documents shared with a consortium of news organizations provide a rare look at how Moscow-based defense contractors help the Russian government plan cyber assaults. (Washington Post)
🤷🏻♀️ Lumen Technologies disclosed two separate security incidents in a recent filing to the Securities and Exchange Commission. (Cybersecurity Dive)
@ Hackers and hacks
🔍 Google unveiled a set of critical vulnerabilities that spyware vendors used to target people in the United Arab Emirates, Italy, Malaysia and Kazakhstan. (TechCrunch)
🛢️ A massive hacking-for-hire operation targeted opponents of Exxon's climate practices. (Wall Street Journal)
🇷🇺 Researchers at Proofpoint have found pro-Russian hackers are targeting U.S. elected officials and staffers who support Ukraine. (Ars Technica)
☀️ See y'all on Tuesday!
Thanks to Peter Allen Clark for editing and Lisa Hornung for copy editing this newsletter.
If you like Axios Codebook, spread the word.



