Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Hackers Issue Voting Machine Security Warning Ahead Of US Midterm Elections
News & Analysis

Hackers Issue Voting Machine Security Warning Ahead Of US Midterm Elections

ISBuzz TeamBy ISBuzz TeamOctober 1, 20184 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It has been reported that just weeks ahead of the US midterm elections, security experts are warning that America’s voting systems are still vulnerable to being hacked. Attackers could manipulate the outcome of November’s votes which will establish the support that President Trump has in Congress for the rest of his term, according to those warnings.

Tim Mackey, Senior Technical Evangelist at Synopsys:

“The 2018 DEFCON Voting Village report highlights a clear disconnect between the security of the devices delivered by vendors and security expectations we as citizens have on our voting systems. Basic best practice training we deliver to employees about setting strong passwords for accounts and IT department processes for updating software flaws in a timely manner are clearly not being followed by those designing and administering voting machines. Part of the problem lays within the process of certifying voting apparatus. In the case of the M650 identified as actively in use within the state of California, it would’ve been certified to the California Voting Systems Standards (October 2014). While the cyber-threat landscape has evolved significantly since CVSS was approved, it is clear given the age of the components used within M650 that it was designed to meet the minimum bar within the standard. Given the costs associated with certification, it’s also very likely that once any device is certified it may have a longer than expected lifespan without update – and an increasingly insecure lifespan.

It is of course easy to identify issues within critical systems like our voting infrastructure, but far harder to address them. Within industry various standards exist for the certification of security surrounding everything from credit card data to health care records. These standards have requirements for periodic reassessments and foster a climate of continuous improvement. Breaches of security within companies are routinely reported in the media and, following a breach, responsible organisations take steps to mitigate any risks or changes in threats which were identified. This process of continuous improvement needs to apply to electronic election systems used in all democratic nations. In the US, were an agency like the Department of Homeland Security or National Security Agency to be tasked with performing an annual penetration test of all voting systems, and publish the results of those assessments; the voting public would retain confidence in the process while technology providers could improve their systems armed with expert security guidance. An annual assessment would have the added benefit of depoliticizing the effort.”

Ross Rustici, Senior Director of Threat Intelligence at Cybereason:

  1. Make route communication between local, state and federal agencies. This will insure that when a crisis happens, all sides are coordinating effectively and conveying the same message across all levels of government.
  2. The ability to get ahead of the consequences is the key to stopping this type of attack. Joint task forces between state and federal resources are the only way to achieve this. But to be successful, a traditional police approach of assess, collect evidence, arrest cannot be taken. Disruptive operations is really important.
  3. When disinformation is being spread, the narrative needs to be controlled early. Not countering the fake social media posts as soon as they appear is a big disadvantage for the defenders. Local and state governments need staff monitoring social media and sending out messages to counter any false information that’s posted.
  4. There is a fundamental difference in capability between a human saboteur and a cyber one. The speed at which cyber actors can layer real world effects easily overwhelm local responders if they aren’t prepared for it.
  5. Election meddling is greater than the direct effects and it is often the indirect means that have the ability to do the most harm. The second and third order effects leave greater room for doubt.
ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}