ZeroHour

Search: “U.S. Senate”

40 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail

A whistleblower alleges USPS is rushing untested IT systems that could reject thousands of mail-in ballots ahead of the 2026 midterm elections.

A whistleblower complaint released by Sen. Richard Blumenthal says USPS is deploying three new, largely untested IT systems — including the Federal Ballot Mail Portal — that could reject entire ballot batches over single scan errors. The systems were developed in weeks without standard testing or interoperability checks, and USPS allegedly continued work despite court injunctions against its rule changes. House Oversight Democrats demanded USPS halt implementation, and election experts warn the design could lead to new lawsuits and mass ballot denials.

CyberScoop · 14d agoPolicy & legal

US military disabled ad tracking on troops’ devices following reports of targeted attacks

US DoD disabled ad tracking on troops' devices after foreign adversaries targeted service members using commercially bought location data.

Per letters shared with Senator Ron Wyden, the Army, Air Force, Navy, Marine Corps, and Special Operations Command disabled advertising IDs on iPhones, Android devices, and Windows computers across the federal military enterprise. The protections rolled out earlier in 2026, with the Air Force implementing changes in July, to prevent adversaries from exploiting app-derived location data sold through data brokers. Wyden warned that personal devices brought onto military bases could still expose troops and facilities, and noted the intelligence community and FBI buy such data without warrants.

TechCrunch · Security · 12d agoPolicy & legal

Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms

Bipartisan US lawmakers urged the Commerce Department to add hack-for-hire firms BellTroX, CyberRoot, and Appin/Sunkissed Organic Farms to the entity list.

Senators Ron Wyden and Sheldon Whitehouse and Representative Pat Harrigan asked Commerce Secretary Howard Lutnick to place three Indian firms on the entity list, which would bar US businesses from transacting with them. The letter says BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly Appin) have conducted cyberattacks and targeted espionage against Americans for over a decade, allegedly at the behest of the Qatari government, and used foreign courts to censor reporting on their activities. Appin previously secured a global takedown order against Reuters that was later lifted, and has been linked to hacks of FIFA officials tied to Qatar's 2022 World Cup plans.

TechCrunch · Security · 7d agoPolicy & legal1

Lawmakers call on Treasury to sanction hackers-for-hire

Bipartisan US lawmakers asked Treasury to sanction three India-based hack-for-hire firms accused of long-running espionage against Americans.

Sens. Ron Wyden and Sheldon Whitehouse and Rep. Pat Harrigan urged Treasury to add Sunkissed Organic Farms (formerly Appin), BellTroX, and CyberRoot to the Entity List. The letter says the mercenary groups conducted targeted espionage against US citizens, businesses, and lawyers for over fifteen years, allegedly including work for Qatar's government such as targeting opponents of Qatar's World Cup bid and Kristi Rogers, wife of Senate candidate Mike Rogers. Adding the firms to the Entity List would restrict their access to American software, cybersecurity tools, and cloud infrastructure. The lawmakers also accuse the groups of lawfare campaigns to censor investigative reporting on their hacking activities.

CyberScoop · 7d agoThreat actor in the wild

FBI takes down China-linked hacking network behind attacks on NASA, DOJ and U.S. Senate

FBI seized domains disabling QScan and QTRouter malware run by China-linked QTFY group behind intrusions at NASA, DOJ, Senate and other agencies.

The Justice Department and FBI seized domains hard-coded into two malware tools, QScan and QTRouter, operated by a Chinese state-sponsored group called QTFY, tied to a Nanjing-based company that sold hacking services to China's Ministry of State Security and the PLA. QScan infected IoT devices worldwide while QTRouter combined them with commercial proxies and rented servers to build an obfuscation network that masked attack origins. Victims include NASA, the Federal Reserve, the Departments of Energy and Justice, HHS, NIH, and the U.S. Senate. The FBI and NSA published a joint advisory with indicators of compromise, the latest in operations against Mustang Panda, Flax Typhoon, and Volt Typhoon infrastructure.

Help Net Security · 20d agoThreat actor in the wild

Senators press TikTok over withholding of safety features for some users

Sens. Blackburn and Blumenthal demand TikTok explain why safety features were withheld from about 10% of users, following a teenager's suicide.

Sens. Marsha Blackburn and Richard Blumenthal sent a letter demanding answers from TikTok after a Bloomberg report showed the company withheld algorithmic safety changes from a control group of about 10% of users, including 16-year-old Chase Nasca, who died by suicide in February 2022. An internal review found the teen viewed more than 7,500 videos in his final two weeks, 73% with themes of sadness or personal struggles. The senators tied the case to the Kids Online Safety Act, which advanced out of the Senate Commerce Committee on August 5, and set a September 1 deadline for responses.

The Record · 27d agoPolicy & legal

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Help Net Security's weekly digest highlights 274 compromised Zimbra servers, Gitea and Citrix NetScaler KEV additions, a PaperCut zero-day, and a suspected Iran-linked power plant attack.

The roundup reports at least 274 internet-facing Zimbra instances compromised via CVE-2026-73570, critical Gitea CVE-2026-60004 added to CISA's KEV catalog after exploitation began, and previously patched Citrix NetScaler flaw CVE-2026-8452 exploited in the wild. It also covers PaperCut NG/MF zero-day attacks, a suspected Iran-linked shutdown of a UK power plant, an FBI seizure of domains tied to a China-linked group that hit NASA, DOJ and the Senate, a cyberattack disrupting Boston Scientific, and the Manchester Airports Group breach. Additional items include Chameleon SEO poisoning phishing, Android car head unit proxy botnet malware, ReliaQuest social engineering by ShinyHunters, fake OpenAI Codex macOS malware, and AI-related workforce and supply chain interviews.

FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure

FBI disrupted Chinese state-linked proxy infrastructure used in hacking campaigns against NASA, the Federal Reserve, the US Senate, and other US targets.

The FBI disrupted Chinese proxy tools used in a mass hacking campaign against US agencies and critical infrastructure, according to the DOJ. Targets included NASA, the Federal Reserve, the US Senate, and the Justice Department. The operation dismantled infrastructure that Chinese state-sponsored hackers relied on to obfuscate their access.

WIRED · Security · 21d agoThreat actor in the wild

DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims

DoJ corrected its statement to say US federal agencies were targets, not confirmed victims, of China-linked group QTFY's intrusions.

The US Department of Justice revised its press release to list NASA, the Federal Reserve, Department of Energy, DoJ, HHS, NIH and the US Senate as 'among the targets' of QTFY (aka QT AND QTCYBER), rather than victims. QTFY, active since 2018 and linked to Nanjing Xinjiuwei Network Technology Co with payments suggesting MSS sponsorship, operates the QScan vulnerability scanning platform and QTRouter obfuscation network, which underpin the Fast Labyrinth encrypted ORB relay network built from infected IoT devices and leased VPSs. The FBI seized qtproxy[.]xyz, qt-proxy[.]org and qt-team[.]com, disrupting QScan and QTRouter, while Lumen Black Lotus Labs reported the actor industrialized ORB networks for China-linked espionage. A 2019 NASA intrusion attempt exploited CVE-2019-11510, a critical Pulse Secure VPN flaw.

The Hacker News · 16d agoThreat actor in the wildCVE-2019-115101

House passes bill to equip local law enforcement with scam-fighting tools

The U.S. House passed the GUARD Act, letting local law enforcement use federal grants to investigate financial scams and trace stolen cryptocurrency.

The bipartisan GUARD Act (Reps. Zachary Nunn, Scott Fitzgerald, Josh Gottheimer) passed the House, allowing existing DOJ grant funds to be used for fraud analysts, victim-support training, blockchain tracing software, and financial-information sharing with law enforcement. It addresses scams like pig butchering, often run by transnational criminal groups overseas; Americans lost a record $11.4 billion to crypto-related fraud in 2025, including $8.6 billion in investment fraud. Senators Katie Britt and Kirsten Gillibrand introduced a Senate companion in July 2025, and the House also passed a bill retroactively eliminating the 'scam tax' on stolen funds for 2021-2025 victims.

The Record · 2h agoPolicy & legal

FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure

FBI seizes China-linked QScan and QTRouter hacking platforms used by QTFY to obfuscate intrusions against US federal agencies.

The DOJ and FBI seized domains hard-coded into QScan and QTRouter, two platforms operated by China-based Nanjing Xinjiuwei Network Technology Company on behalf of state-sponsored group QTFY. QScan automatically infected thousands of IoT devices which were added to QTRouter, an obfuscation network routing malicious traffic through compromised and proxy devices outside China. Targets included NASA, the Federal Reserve, Departments of Energy, Justice, and HHS, NIH, and the US Senate, exploiting flaws in Fortinet SSL-VPN, Citrix ADC, Microsoft Exchange, F5 BIG-IP, Log4j, and others.

Security Affairs · 21d agoThreat actor in the wild

I Think the Military Commissary Freezers Were Hacked

Refrigeration failures at six-plus US military commissaries prompt speculation of a cyber attack on DeCA's remote monitoring systems; Pentagon acknowledges possible disruption.

The author documents near-simultaneous freezer and refrigeration failures at confirmed installations including Fort Huachuca, F.E. Warren AFB, Fort Irwin and Travis AFB on August 26-27, with freezers entering defrost mode that heated and spoiled food. DeCA's Remote Monitoring Control System controls defrost across roughly 182 locations, and an unverified comment attributed the Fort Huachuca failure to a network issue. Stars and Stripes and Military Times independently reported the multi-base failures, and the Pentagon acknowledged a 'possible refrigeration disruption,' though no evidence of hacking has been confirmed.

Lobsters · security · 13d agoData breach

Supreme Court denies Trump request to allow USPS mail ballot changes

Supreme Court denied the Trump administration's emergency request to implement USPS mail ballot changes before the 2026 midterms, calling it arbitrary and capricious.

The U.S. Supreme Court rejected 7-2 the Trump administration's petition to change how the U.S. Postal Service handles mail-in ballots for the 2026 midterm elections. Justice Ketanji Brown Jackson wrote the administration was unlikely to succeed, while Justice Brett Kavanaugh cited unreasonably short timelines for state election officials. The blocked executive order would have required USPS citizenship verification, barcode tracking of ballot envelopes, and DHS-compiled "State Citizenship Lists"; a whistleblower alleged a rushed effort to install three restrictive IT verification systems. Justices Alito and Thomas dissented, arguing states and organizations lacked standing.

CyberScoop · 1d agoPolicy & legal

US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate

US Justice Department seized domains of a Chinese botnet used to hack NASA, the Justice Department, and the Senate, disabling its C2.

The US Justice Department seized domains belonging to a Chinese botnet that was used to hack NASA, the Justice Department, and the Senate. The seized domains were hardcoded into the botnet's code, so the seizures rendered the botnet and its command-and-control servers inoperable. The action disrupted the malware's communication channels and essential operations.

TechCrunch · Security · 21d agoThreat actor in the wild

White House Launches Pilot Program in Texas to Protect Water Infrastructure

White House launches Project Watershed 250, giving Texas water providers federal and private-sector cybersecurity resources amid rising nation-state threats to critical infrastructure.

The White House launched Project Watershed 250, a pilot program providing water providers in Texas with federal and private-sector cybersecurity resources. The initiative comes amid rising nation-state threats targeting water utilities and other critical infrastructure in the United States.

Infosecurity Magazine · 15d agoPolicy & legal

A California county wants to hire Tina Peters to help run its elections

Shasta County, California plans to hire Tina Peters, convicted of stealing voting system software, as assistant registrar of voters.

Shasta County registrar of voters Clint Curtis said he plans to hire former Mesa County clerk Tina Peters as assistant registrar after Colorado Governor Jared Polis commuted her nine-year sentence for seven felonies, including identity theft, breaking into an election office, and stealing voting system software. Senators Alex Padilla and Adam Schiff asked California Secretary of State Shirley Weber to provide maximum oversight to prevent Peters from improperly accessing ballots, voting systems, or data of over 100,000 registered voters. The county board of supervisors recently censured Curtis after investigations found he was verbally abusive or physically threatening toward staff.

CyberScoop · 27d agoPolicy & legal

Kids’ online safety bill faces dim prospects of passage this session despite progress

Kids Online Safety Act clears Senate committee but passage looks unlikely this session amid House-Senate deadlock over the duty-of-care provision.

KOSA advanced out of the Senate Commerce Committee, but the chambers remain split on a duty-of-care provision requiring platforms to act with reasonable caution to prevent foreseeable harm, which House leadership opposes over First Amendment and negligence-lawsuit concerns. The Senate passed KOSA 91-3 last Congress before it died in the House, and the House passed its own version without the duty of care in June as part of a larger package, after stripping a state-law preemption provision. Observers say even Senate passage this year is a struggle given the short calendar, with a lame-duck window between November and January the more plausible path, and Majority Leader John Thune controlling whether a roll-call vote happens.

The Record · 23d agoPolicy & legal

GOP issues stark warning to AI companies

Axios reports the US Republican Party issued a stark warning to AI companies, apparently tied to a data-center memo ahead of elections.

An Axios article titled "GOP issues stark warning to AI companies" was published on August 19, 2026; its URL suggests coverage of a Republican memo on data centers and AI in elections. The provided source text contains only the headline and engagement metrics, so no substantive details about the warning's content are available.

Bipartisan Senate bill aims to prepare energy sector for Q

Bipartisan Senate bill would direct FERC to factor quantum computing threats and post-quantum cryptography into US electric grid cybersecurity reliability standards.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Senators Mike Rounds and Chris Coons, would require FERC to consider quantum computing threats when reviewing electric reliability standards and to explore post-quantum cryptography use in both IT and OT systems, plus a technical sandbox to study quantum impacts. It aligns with NIST's post-quantum algorithm work, and a June executive order moved the federal PQC migration deadline from 2035 to 2030. Industry experts noted the hard part is upgrading infrastructure such as SCADA communications and software update integrity ahead of those deadlines.

CyberScoop · 23d agoPolicy & legal

Confused about which VPN is right, US senator asks the NSA for guidance

Senator Ron Wyden asked the NSA to update public guidance on VPN configurations, questioning single-hop designs and services like Tor.

Sen. Ron Wyden (D-Ore.) sent a letter Wednesday to NSA director Gen. Joshua Rudd requesting updated public guidance on VPN best practices for Americans facing advanced foreign threats, including government personnel, contractors, and journalists. The letter highlights limitations such as decrypted traffic at single-hop termination servers, metadata like timestamps enabling nation-state profiling, and asks the NSA to assess multi-hop architectures, random delays, cryptographic padding, and specific services including Apple Private Relay, Nym, and Tor.

Ars Technica · Security · 13d agoPolicy & legal

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

NSA is reorganizing into five mission centers covering China, cybersecurity, AI, combat support and global intelligence, with full capability targeted by January.

NSA Director Gen. Joshua Rudd announced a sweeping reorganization replacing existing directorates with five mission centers focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence. A 30-day implementation clock has started, and the centers are expected to reach full operational capability by January. Officials acknowledge the rapid realignment will 'break things' in the agency's bureaucracy; this is the largest restructuring since the NSA21 effort roughly a decade ago, which was widely viewed as a failure.

The Record · 2d agoPolicy & legal

'Lake America' makes one thing clear: We can't trust U.S. tech companies

TVO opinion analysis argues the 'Lake America' dynamic shows foreign organizations can no longer trust US tech companies.

An opinion analysis argues that US tech companies can no longer be trusted by foreign customers, coining the framing 'Lake America'. The piece reflects growing concerns around data sovereignty and dependence on US cloud and software providers. No specific incident, breach, or vulnerability is described.

Lawmakers call for investigation into impact of CISA staffing cuts

Democratic lawmakers asked the GAO to investigate how CISA's roughly one-third workforce reduction affects its mission and critical-infrastructure protection.

Democratic lawmakers led by House Homeland Security ranking member Bennie Thompson asked the Government Accountability Office to examine how recent staffing cuts at CISA affect its ability to protect critical infrastructure and respond to cyber and physical threats. Nearly 1,000 CISA employees have been fired or quit since the Trump administration began, and acting director Nick Andersen plans to hire 300. The letter also flags the FY2027 budget proposal to eliminate nearly 900 additional positions and cut more than $700 million from the agency. CISA has had no confirmed director since Jen Easterly departed, and GAO confirmed it received the request.

The Record · 26d agoPolicy & legal

White House authorizes private US companies to hack foreign criminal networks

Trump memorandum authorizes vetted private US companies to conduct government-supervised offensive cyber operations against foreign criminal networks.

The National Security Presidential Memorandum signed August 12 lets vetted private companies run offensive cyber operations against transnational criminal organizations behind ransomware, phishing and sextortion, under US government oversight. The Homeland Security Task Force's National Coordination Center, led by DOJ and DHS executive directors, must give written approval for both Cyber Surveillance Operations and Cyber Effects Operations. Participating companies must post a $1 million bond or escrow, undergo annual review, and notify authorities if they unintentionally target US persons or systems.

Help Net Security · Aug 13, 2026Policy & legal

Russian national extradited to US for alleged involvement in bank-account takeover scheme

US extradited Russian national Sergei Filimonov over a bank-account takeover scheme using spoofed bank domains that defrauded two banks of $6.3 million.

US authorities extradited 36-year-old Russian national Sergei Anatolyevich Filimonov from the Republic of Georgia on charges including bank and wire fraud conspiracy and aggravated identity theft. He and unnamed co-conspirators allegedly ran spoofed bank domains, bought sponsored links to lure victims, and harvested over 5,000 victim login credentials starting in November 2023, causing unauthorized transfers of about $5.58 million and $735,000 from two banks in 2024. The FBI previously identified at least 19 US victims linked to the credential-storage domain, with roughly $28 million in attempted losses including $14.6 million confirmed. Filimonov faces up to 175 years in prison, pleaded not guilty on September 4, and remains detained in the Northern District of Georgia.

CyberScoop · 8d agoPolicy & legal

Bernie's AI bill proposes to sentence AI developers to 20 years in prison

Senator Bernie Sanders proposed AI legislation that would impose criminal penalties on AI developers, including sentences of up to 20 years in prison.

A Hacker News discussion (21 points, 4 comments) links to a tweet about Bernie Sanders' AI bill, which would establish criminal liability for AI developers, with potential 20-year prison sentences. The proposal targets individual developers rather than only companies. As a proposed bill, it has not been enacted, and the linked discussion is brief.

Jail time for Maine child in 764 marks turning point in federal law enforcement

A 17-year-old from Maine became the first minor federally adjudicated for 764 extremist crimes, including child exploitation, signaling a policy shift on prosecuting juveniles.

The FBI said a Maine teenager is the first child federally charged and adjudicated for crimes tied to the nihilistic violent extremist collective 764, part of The Com network. Charges include conspiracy to sexually exploit a child, distributing CSAM, interstate threats, cyberstalking, and identity theft. The case marks a turning point in federal policy on prosecuting juveniles and continues heightened enforcement: Kyle Spitze was sentenced to 77 years and Alexis Chavez to 40 years in related cases. The FBI is investigating more than 500 subjects connected to 764 and its offshoots nationwide.

CyberScoop · 13d agoPolicy & legal

FTC rescinds policy requiring health apps to notify customers after a breach

The FTC unanimously rescinded its 2021 policy statement that required health and fitness apps to notify users after health-data breaches.

The FTC voted to rescind a September 2021 Biden-era policy statement that extended federal health-data breach notification rules to health apps, fitness trackers, and connected devices, which had exposed violators to fines of $43,792 per violation per day. The 2021 statement, adopted in a divided 3-2 vote under then-chair Lina Khan, cited HIPAA coverage gaps for consumer health applications. The commission said the statement provided minimal benefit, was superseded by rulemaking, and aligns with the White House deregulatory agenda.

CyberScoop · 7d agoPolicy & legal

Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities

Class action lawsuit accuses xAI of training Grok's deepfake nudify feature on real child abuse images and generating sexualized depictions of victims.

A class action filed in the U.S. District Court for the Northern District of California under Masha's Law claims xAI trained Grok's 'nudify' deepfake capability on real child sexual abuse material and names thousands of victims. An analysis by the Center for Countering Digital Hate found Grok generated over 3 million sexualized images between December 2025 and January 2026, at least 23,000 of which depicted children. The suit says Grok's terms of service treat posts on X as training data and that its text-based guardrails against sexualized deepfakes are weak and easily bypassed. Plaintiffs seek damages and injunctions; xAI did not respond to a request for comment.

CyberScoop · 20d agoAI safety & security

Security Vulnerability in a Voting System

A four-year-old vulnerability letting anyone recover ballot casting order was demonstrated with AI coding agents against Georgia's May 2026 primary data.

A previously disclosed vulnerability in ballot scanners used across 21 US states, including Georgia, allows recovery of the order in which ballots were cast. Nearly four years after the original disclosure, a researcher pointed AI coding agents at the vulnerability paper and used only public data — county early-voting lists and cast-vote record (CVR) files — to analyze voter behavior in Georgia's May 2026 primary. The demonstration required no access to voting machines, networks, source code, or non-public records.

Schneier on Security · 12d agoResearch in the wild

NSA installs DHS lawyer as new general counsel

NSA confirmed Kerianne Tobitsch, formerly a senior DHS lawyer, began as the agency's general counsel on June 15, 2026, after a year-long vacancy.

The NSA appointed Kerianne Tobitsch, previously a senior lawyer at the Department of Homeland Security and a former Jones Day partner, as general counsel effective June 15, 2026, filling a role that had been vacant for roughly a year. The role oversees lawyers who review and approve clandestine operations. The previous general counsel, April Falcon Doss, was fired in 2022 after conservative media criticism amplified on social media, and two other senior NSA lawyers retired around that time. Tobitsch is expected to play a role in upcoming congressional efforts to renew FISA Section 702, which sunset in June 2026.

The Record · Aug 11, 2026Policy & legal