National Security Agency’s cover photo
National Security Agency

National Security Agency

Defense and Space Manufacturing

Ft. Meade, MD 543,690 followers

Where Intelligence Goes to Work. https://www.nsa.gov

About us

NSA is at the forefront of U.S. government cryptology, integrating signals intelligence (SIGINT) and cybersecurity to enhance national and allied advantages. Our mission encompasses computer network operations aimed at securing critical insights and services, ensuring decisive advantages for the nation and our allies. NSA's cybersecurity initiatives are pivotal in safeguarding U.S. national security systems, particularly within the Defense Industrial Base and enhancing the security of U.S. weaponry. We are committed to advancing cybersecurity through education, research, and career development. Through foreign signals intelligence (SIGINT), NSA delivers crucial intelligence to U.S. policymakers and military forces. This intelligence, derived from electronic signals and systems used by foreign entities, provides essential insights into the capabilities, actions, and intentions of adversaries worldwide. It supports our efforts to defend the nation, save lives, and advance U.S. objectives and alliances globally.

Website
https://www.nsa.gov
Industry
Defense and Space Manufacturing
Company size
10,001+ employees
Headquarters
Ft. Meade, MD
Type
Government Agency
Founded
1952
Specialties
Computer/Electrical Engineering, Computer Science, Cybersecurity, Mathematics, Data Science, Foreign Language Analysis, Business, Accounting and Budget, Intelligence Analysis, Information Assurance, Cryptanalysis, Signals Analysis, Security & Counterintelligence, STEM, Intelligence Collection, Infrastructure & Logistics, Human Resources, Inspection, Investigation & Compliance, Communication & Public Affairs, Education & Training, and Paid Internships, Scholarships and Co-op

Locations

Employees at National Security Agency

Updates

  • NSA, in collaboration with its partners, has released a new Cybersecurity Advisory regarding a phishing campaign conducted by Russian state-supported cyber actors targeting the Zimbra Collaboration Suite (ZCS). The threat group, known as LAUNDRY BEAR, is utilizing a view-based exploit to exfiltrate sensitive communications and email directories from U.S. and allied government and commercial networks. All organizations using ZCS are urged to: ·        Review the joint CSA for detailed indicators of compromise ·        Update vulnerable software immediately ·        Implement other recommended mitigations to minimize risk posed by this campaign and other similar activities. Collaboration is key to defending shared infrastructure. #NSA #Cybersecurity #Zimbra #NationalSecurity #Collaboration #RussianCyberActors #ZCS Read the full advisory here: https://lnkd.in/egGcf2Aj

  • We joined Cybersecurity and Infrastructure Security Agency, JPCERT/CC, and Nationaal Cyber Security Centrum (NCSC-NL) in releasing the guidance on implementing a coordinated vulnerability disclosure (CVD) program to provide best practices for software manufacturers and online service providers to engage with external security researchers.   An effective CVD program includes well-defined processes for: 1. Triage and Assessment: Review vulnerability reports to assess whether they pose a risk to the product and its end users. Use risk assessment systems to help prioritize reports. 2. Developing Fixes: If a reported vulnerability requires a fix, remediate accordingly and share mitigations, fixes, or patch details with the researcher for validation. 3. Assigning Common Vulnerabilities and Exposure (CVE) IDs: Assign CVE IDs for discovered vulnerabilities, whether identified internally or externally. Suppliers are encouraged to become CVE numbering authorities (CNAs). 4. Ensuring Accuracy: Include sufficient and accurate details in CVE records to give customers and the public insight into the true nature of vulnerability and its associated risks. 5. Developing Communications: Publicly release information on vulnerabilities, severity scores, and mitigation steps to customers in an unrestricted location on the supplier's website. 6. Release Vulnerability Details: Determine a timeline for public disclosure in conjunction with the researcher or intermediary, including issuance of the CVE record and other public statements. To learn more about CVD programs and how they can help your suppliers, read the full report: https://lnkd.in/epkaFHXw

    • No alternative text description for this image
  • NSA and partners released a new joint Cybersecurity Advisory “Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting.” The advisory warns that Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit vulnerable, poorly configured networks worldwide, specifically targeting critical infrastructure sectors, including: - Defense Industrial Base - Energy - Financial Services - Healthcare - Government Facilities - Communications Basic router hygiene is one of the most effective ways to deter Russian state-sponsored actors. To protect your organization, we urge network defenders to prioritize these mitigations: - Implement Simple Network Management Protocol v3 (SNMPv3) - Use strong, unique passwords - Disable Cisco Smart Install - Block the Trivial File Transfer Protocol (TFTP), Smart Install (SMI), and SNMP protocols at the firewall - Upgrade software and firmware images to patch vulnerabilities Building on a previous Federal Bureau of Investigation (FBI) alert, this guidance addresses a decade-long pattern of Russian FSB Center 16 cyber activity and provides tactics, techniques, and procedures to counter this ongoing threat. #cybersecurityadvisory #cybersecurity #NSA #criticalinfrastructure #networksecurity

    • No alternative text description for this image
  • For 250 years, the United States has relied on the courage and willpower of its people to overcome adversity. Today, NSA provides critical insights and strategic advantages through foreign signals intelligence and cybersecurity to safeguard the nation from emerging threats. We are proud to provide the information advantage necessary to protect this country’s allies and democratic way of life. #America250 #HappyIndependenceDay

    • No alternative text description for this image
  • The Laboratory for Physical Sciences at the National Security Agency, in partnership with the U.S. Army DEVCOM Army Research Laboratory, is postured to support the President’s Executive Order on Quantum Computing. To advance this vision, we are officially launching the Quantum Ecosystem Advancement, Growth & Leadership (QuantumEAGLe) initiative. "Our new QuantumEAGLe initiative represents an expansion of our quantum computing efforts, focusing on engaging with industry, enabling commercial roadmaps, advancing U.S. supply chain needs, developing algorithmic applications, and overcoming fundamental research challenges. Together, we are committed to bolstering the U.S. quantum industry and ensuring our nation leads in this critical technology." Read the full press release: https://lnkd.in/dYnC32uF

    • No alternative text description for this image
  • A strong close to #TechNetCyber. Daniel McCormack, Chief Operations Officer of NSA’s Cybersecurity Directorate, discussed the evolving cyber landscape, the technologies shaping the future, and the importance of partnerships in strengthening our collective defense. Thank you to everyone who joined the conversation and engaged with us throughout the week. #CyberDefense #Cybersecurity #NationalSecurity

    • No alternative text description for this image
    • No alternative text description for this image

Affiliated pages

Similar pages

Browse jobs