Nuclear weapons agency breached amid cyber onslaught
politico.com
politico.com
This kind of thing raises the disturbing question of what will/should be done in response.
About 1/4 of the country believes that the last presidential election was rigged, and over 100 members of Congress supported a lawsuit to the same effect.
So it seems plausible that claims by the next administration of culpability will face a stiff resistance from not only the public but Congress itself.
How are these systems secured in other Western countries? How do France and the UK, for example, secure their critical infrastructure networks? The U.S. strategy of just contracting out all these essential service is revealing its pressure points. Seems that the USG insists on just cutting checks to these companies like SolarWinds, which are more interested in gaining clients, generating revenue, and marketing than effectively engineering durable solutions. Another factor is probably NIST's questionable practices about password hygiene (requiring them to be changed every 30-60 days).
There are probably better citations but this is the first I found: https://grahamcluley.com/new-nist-guidelines-do-away-with-pe...