Actor
CISA
12 sourced claims · 2 documents touched
CISA notified the owner/operator in every case it identified a vulnerability in a product or network and encouraged mitigation (p.1).
p.1From ~2019 to 2024, CISA conducted technical and operational activities to evaluate certain US election systems, all upon request of system owners/operators, including software examination, penetration testing of SLTT (state, local, tribal, and territorial) networks, and incident response for election-system intrusions (p.1).
p.1From 2019-2024 CISA partnered with Idaho National Laboratory (INL) on the Critical Product Evaluation program for direct technical assessments of election software, often before public release, upon vendor request (p.2).
p.2Vulnerabilities found included input-validation bugs, insecure deserialization, insufficient logging, race conditions, insecure crypto primitives, and privilege-escalation paths; CISA did not independently validate whether production builds in SLTT environments incorporated all fixes (p.3).
p.3In multiple cases CISA assessors gained full network control within hours or days, showing many SLTT partners remain "soft targets" (p.4).
p.4CISA recommends national policymakers encourage harmonization of patch-management and certification rules (p.4).
p.4Across penetration tests and red-team engagements, CISA observed flat/minimally segmented networks, weak identity and access management (poor MFA, shared credentials, weak service-account hygiene), lack of endpoint hardening, legacy remote-access/file-transfer pathways, and insufficient traffic monitoring (p.4).
p.4ODNI commissioned a forensic examination of Dominion Voting Systems devices used in Puerto Rico's 2024 election; CISA reviewed the report but did not have access to the devices and could not perform its own examination (p.4).
p.4CISA recommended mitigations: harmonize patch/certification rules; adhere to CISA Best Practices for Securing Election Systems; use human-readable paper ballots; conduct post-election manual audits of paper ballots before certification (p.5-6).
p.5
CISA and the FBI reported members of the Iranian Republican Guard Corps attempted to exploit websites to obtain voter registration data; they confirmed the actor successfully obtained voter registration data in at least one state and could not determine success in the other 11 states targeted (September 2020) (p.4). [OCR: "Iranian Republic Guard Corp"]
p.4Ransomware defenses: follow CISA Binding Operational Directives as best practice; patch management remediating critical vulnerabilities within 15 calendar days of detection; network segmentation (including not transferring election results on the business network); endpoint detection and response; use .gov domains; implement Malicious Domain Blocking and Reporting (MDBR); maintain and test incident response plans; maintain backups recoverable to at least 30 days prior, encrypted, offline, with credentials not stored in the targeted environment (p.8).
p.8Directs readers to CISA's "Cybersecurity Toolkit and Resources to Protect Elections" page: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections (p.10).
p.10