← Archive

Actor

CISA

12 sourced claims · 2 documents touched


  • CISA notified the owner/operator in every case it identified a vulnerability in a product or network and encouraged mitigation (p.1).

    p.1
  • From ~2019 to 2024, CISA conducted technical and operational activities to evaluate certain US election systems, all upon request of system owners/operators, including software examination, penetration testing of SLTT (state, local, tribal, and territorial) networks, and incident response for election-system intrusions (p.1).

    p.1
  • From 2019-2024 CISA partnered with Idaho National Laboratory (INL) on the Critical Product Evaluation program for direct technical assessments of election software, often before public release, upon vendor request (p.2).

    p.2
  • Vulnerabilities found included input-validation bugs, insecure deserialization, insufficient logging, race conditions, insecure crypto primitives, and privilege-escalation paths; CISA did not independently validate whether production builds in SLTT environments incorporated all fixes (p.3).

    p.3
  • In multiple cases CISA assessors gained full network control within hours or days, showing many SLTT partners remain "soft targets" (p.4).

    p.4
  • CISA recommends national policymakers encourage harmonization of patch-management and certification rules (p.4).

    p.4
  • Across penetration tests and red-team engagements, CISA observed flat/minimally segmented networks, weak identity and access management (poor MFA, shared credentials, weak service-account hygiene), lack of endpoint hardening, legacy remote-access/file-transfer pathways, and insufficient traffic monitoring (p.4).

    p.4
  • ODNI commissioned a forensic examination of Dominion Voting Systems devices used in Puerto Rico's 2024 election; CISA reviewed the report but did not have access to the devices and could not perform its own examination (p.4).

    p.4
  • CISA recommended mitigations: harmonize patch/certification rules; adhere to CISA Best Practices for Securing Election Systems; use human-readable paper ballots; conduct post-election manual audits of paper ballots before certification (p.5-6).

    p.5
  • CISA and the FBI reported members of the Iranian Republican Guard Corps attempted to exploit websites to obtain voter registration data; they confirmed the actor successfully obtained voter registration data in at least one state and could not determine success in the other 11 states targeted (September 2020) (p.4). [OCR: "Iranian Republic Guard Corp"]

    p.4
  • Ransomware defenses: follow CISA Binding Operational Directives as best practice; patch management remediating critical vulnerabilities within 15 calendar days of detection; network segmentation (including not transferring election results on the business network); endpoint detection and response; use .gov domains; implement Malicious Domain Blocking and Reporting (MDBR); maintain and test incident response plans; maintain backups recoverable to at least 30 days prior, encrypted, offline, with credentials not stored in the targeted environment (p.8).

    p.8
  • Directs readers to CISA's "Cybersecurity Toolkit and Resources to Protect Elections" page: https://www.cisa.gov/cybersecurity-toolkit-and-resources-protect-elections (p.10).

    p.10