National Security Agency (NSA) ethical hackers backed by the U.S. Department of Defense (DoD) are scheduled to infiltrate the networks of the top tech companies Amazon, Google, Microsoft and Oracle. The attack aims to better understand zero-trust cybersecurity in commercial cloud environments.
A red team is usually composed of cybersecurity professionals that act as hackers to test cybersecurity controls and identify the target company’s vulnerabilities so that they may improve further.
Red teams from the NSA, and possibly from the armed services, are scheduled to conduct a long-term series of attacks to determine the strength of zero-trust security systems on cloud services offered by Amazon, Google, Microsoft and Oracle.
According to Randy Resnick, chief of the Zero Trust Portfolio Management Office, the planned test “would be a realistic adversary attack to determine whether or not the red teams could get in and exploit data. That will give us a good feel on whether or not these zero trust overlays are implemented correctly.”
The four companies chosen to be part of the testing were the winners of the Joint Warfighting Cloud Capability (JWCC) contract following the failed Joint Enterprise Defense Infrastructure (JEDI) program. The $9 billion contract is sponsored by DoD.
The operation will provide DoD with vital information which could help them proceed with zero trust and will also offer the opportunity for cloud providers to better build the foundation of zero trust.
According to Colin Demarest, a reporter at C4ISRNET, “Unlike older cybersecurity models, zero trust assumes networks are always at risk or are already compromised. The new paradigm, as a result, is inherently distrustful and requires constant validation of users, devices and general access.”
Resnick added that the four companies stated that they can instate basic levels of zero trust and that the operation will be testing if these companies are already capable of resisting attacks with just the primary level. “To our satisfaction, at least on paper, they said that all of them could meet target-level zero trust and that many of them could approach almost the entirety, if not the entirety, of full zero trust, which we’re calling advanced,” he added.
More Stories
Killnet and AnonymousSudan Collaborate to Launch Cyber Attacks on Western Organisations
In recent news, it has been reported that two Russia-sympathetic hacktivist groups, Killnet and AnonymousSudan, have allegedly launched a series...
$4000 Gone In An Instant: Mother Defrauded in Facebook Marketplace Car Deal
A mother of four is warning others to be cautious after believing she had purchased a safe and dependable car...
Shocking Scam: Sydney Family Loses $200K Life-Savings in Suncorp Spoofing Fraud
A family from Sydney has lost their life savings worth $200,000 due to a fraudulent scam. Peter and Madison, who...
Mysterious Money Transfer Leaves Couple Speechless: How They Got an Unsolicited $4000
A young couple in Melbourne claims their bank is making up a personal loan they do not understand. Ashley and...
Phishing + AI + Voice Cloning= Big Trouble: The New Way Criminals are Stealing Your Money
New Alert: Criminals use AI and voice cloning to trick you out of your money. Earlier this year, Microsoft unveiled...
‘Impossible to Spot’ Delivery Scam Email Targets Australia Post Customers – Don’t Fall Victim!
Unsuspecting shoppers should be cautious as a parcel delivery scam that is hard to distinguish targets Australia Post customers. Email...