Thursday , May 15 2025
cyber

GAO: NASA Faces ‘Inconsistent’ Cybersecurity Across Spacecraft

The GAO reviewed NASA’s cybersecurity practices and found that there is a need to update spacecraft acquisition policies and standards. They specifically focused on assessing the cybersecurity requirements in NASA contracts for spacecraft projects.

The GAO report reviewed NASA’s spacecraft cybersecurity policies and standards. They looked at three different spacecraft projects that represent various NASA centers and development stages, including both robotic and human spaceflight projects. GAO analyzed contracts and project documents and interviewed project and cybersecurity officials.

CVSS 10.0 Flaw
Critical flaw in Siemens OZW Web Servers Enable Unauthenticated RCE

Siemens issued a security advisory (SSA-047424) for two serious vulnerabilities—CVE-2025-26389 and CVE-2025-26390—impacting the OZW672 and OZW772 web servers. These servers...
Read More
CVSS 10.0 Flaw  Critical flaw in Siemens OZW Web Servers Enable Unauthenticated RCE

Microsoft Patch Tuesday May 2025: 72 flaws, 5 Actively Exploited Zero-Day

Microsoft has released its Patch Tuesday updates for May 2025, addressing a total of 78 vulnerabilities across its product ecosystem,...
Read More
Microsoft Patch Tuesday May 2025: 72 flaws, 5 Actively Exploited Zero-Day

OTP glitch disrupted NID services across the country

NID services in Bangladesh are temporarily suspended due to issues with delivering One-Time Passwords (OTP) needed to access the NID...
Read More
OTP glitch disrupted NID services across the country

Google to pay Texas $1.4 billion for location tracking practices

Google will pay about $1.4 billion to Texas to settle two lawsuits regarding location tracking and biometric data storage without...
Read More
Google to pay Texas $1.4 billion for location tracking practices

YouTube geo-blocks at least 4 Bangladeshi TV channels in India

YouTube has restricted access to at least four Bangladeshi television channels in India following a takedown request from the Indian...
Read More
YouTube geo-blocks at least 4 Bangladeshi TV channels in India

Microsoft Patches Four Critical Azure and Power Apps Vulns

Microsoft has fixed critical vulnerabilities in its core cloud services, including Azure Automation, Azure Storage, Azure DevOps, and Microsoft Power...
Read More
Microsoft Patches Four Critical Azure and Power Apps Vulns

Qilin Ransomware topped April 2025 with 45+ data leak disclosures

The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
Qilin Ransomware topped April 2025 with 45+ data leak disclosures

SonicWall Patches 3 Flaws in SMA 100 Devices

SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
SonicWall Patches 3 Flaws in SMA 100 Devices

Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

GAO examined cybersecurity requirements in NASA contracts for spacecraft projects. The report assessed cybersecurity in selected spacecraft contracts and determined if updates to acquisition policies and standards are needed. The review focused on spacecraft, not ground systems or contractor information security.

GAO is evaluating if NASA has implemented information security controls according to guidelines, standards, and cybersecurity best practices.

NASA released a cybersecurity requirements document in 2019. They have been thinking about updating their spacecraft acquisition policies and standards since then, but they haven’t done it yet. In 2023, NASA published a guide with best practices for space cybersecurity. This guide includes information about principles, controls, threats, and how to reduce risks. However, following this guide is not mandatory for spacecraft programs.

NASA officials say it takes too long to incorporate guidance into acquisition policies. GAO agrees it takes time but says it’s essential for NASA to do it.

The watchdog found that all the NASA spacecraft contracts included cybersecurity requirements. The contractors were required to demonstrate that they met these requirements according to NASA’s 2019 Space System Protection Standard.

“All three projects in our review—Orion, Gateway PPE, SPHEREx—were in development before NASA issued the Space System Protection Standard. NASA required such programs to coordinate with the Office of the Chief Engineer to determine whether any of the requirements should be incorporated based on threats.” Full report here.

Check Also

Protect AI

Palo Alto Networks to Acquire AI Security Firm “Protect AI”

On Monday, Palo Alto Networks confirmed it is acquiring the US-based AI security company Protect …

Leave a Reply

Your email address will not be published. Required fields are marked *