Business.Scoop.Co.Nz Government Data Vulnerabilities Linked to Unvetted Third Parties
Article Content
- •Government data is managed by unvetted third parties, increasing cybersecurity risks.
- •GCSB's delayed response to inquiries about vulnerabilities took six times longer than required.
- •High reliance on a few vendors poses a risk to service delivery across public sector agencies.
A Treasury report revealed that government data in New Zealand is being managed by unvetted third parties, raising significant cybersecurity concerns. The Government Communications Security Bureau (GCSB) took 120 working days to respond to inquiries about these vulnerabilities, far exceeding the statutory 20 days. Director-general Andrew Clark cited the need for confidentiality regarding incidents and vulnerabilities to maintain trust in reporting. The report highlighted issues such as poor security controls and unpatched software among third-party vendors, with some services being offshored without prior approval. This situation has led to a high reliance on a few vendors, increasing the risk of service disruption across government agencies. The GCSB refused to disclose the identities of the problematic vendors or the agencies that raised alarms, citing commercial implications and confidentiality. The ongoing reliance on cloud services from major US tech companies further complicates the security landscape. As of now, the GCSB is working on digital investment and procurement strategies to address these issues.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…