ZeroHour

Search: “Trump administration”

40 stories in the last 30d

Supreme Court denies Trump request to allow USPS mail ballot changes

Supreme Court denied the Trump administration's emergency request to implement USPS mail ballot changes before the 2026 midterms, calling it arbitrary and capricious.

The U.S. Supreme Court rejected 7-2 the Trump administration's petition to change how the U.S. Postal Service handles mail-in ballots for the 2026 midterm elections. Justice Ketanji Brown Jackson wrote the administration was unlikely to succeed, while Justice Brett Kavanaugh cited unreasonably short timelines for state election officials. The blocked executive order would have required USPS citizenship verification, barcode tracking of ballot envelopes, and DHS-compiled "State Citizenship Lists"; a whistleblower alleged a rushed effort to install three restrictive IT verification systems. Justices Alito and Thomas dissented, arguing states and organizations lacked standing.

CyberScoop · 2d agoPolicy & legal

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

FBI officials said AI is accelerating adversary capabilities while its new cyber strategy emphasizes continuous patching, cyber hygiene, and AI-enabled defense.

At the Billington CyberSecurity Summit and ahead of a new FBI cyber strategy, deputy assistant director Jason Bilnoski said AI is boosting the speed and capability of both criminal and nation-state attackers, while stressing that basic controls like MFA would still prevent most attacks. Colleen Ferranti urged a shift from quarterly Patch Tuesday cycles to continuous, risk-based patching as AI accelerates vulnerability discovery. The strategy pledges AI-enabled triage, malware analysis, attribution support, agentic AI adoption, expanded Computer Network Operations, ICS Coordinators in every field office, and a pledge on victim relief and privacy.

CyberScoop · 8d agoPolicy & legal

Lawmakers call for investigation into impact of CISA staffing cuts

Democratic lawmakers asked the GAO to investigate how CISA's roughly one-third workforce reduction affects its mission and critical-infrastructure protection.

Democratic lawmakers led by House Homeland Security ranking member Bennie Thompson asked the Government Accountability Office to examine how recent staffing cuts at CISA affect its ability to protect critical infrastructure and respond to cyber and physical threats. Nearly 1,000 CISA employees have been fired or quit since the Trump administration began, and acting director Nick Andersen plans to hire 300. The letter also flags the FY2027 budget proposal to eliminate nearly 900 additional positions and cut more than $700 million from the agency. CISA has had no confirmed director since Jen Easterly departed, and GAO confirmed it received the request.

The Record · 26d agoPolicy & legal

ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years

DHS subpoenaed REI for all Minneapolis-area customers who bought a specific green beanie since 2024, part of an investigation into 39 ICE protest defendants.

Court filings allege Homeland Security Investigations agents subpoenaed REI in March for transaction records of all persons in the greater Minneapolis–St. Paul area who purchased a specific dark green beanie since 2024. The subpoena was one of 92 sent in a federal case against 39 people, including journalists, who attended an ICE protest at a church. Companies responded differently: T-Mobile handed over six months of a defendant's call and text logs, Google refused a request for YouTube viewers, Reddit withdrew after a First Amendment objection, and Meta pushed back on at least one summons. The 1509 customs summonses require no judicial oversight, and the total number issued under the Trump administration is unknown.

WIRED · Security · 13d agoPolicy & legal

25 Years of Mass Surveillance Is Enough

Bruce Schneier and Cindy Cohn argue post-9/11 mass surveillance expanded far beyond its counterterrorism justification and should be reevaluated for costs to rights.

An essay by Bruce Schneier and Cindy Cohn (originally in Lawfare) traces the post-9/11 shift from targeted surveillance to mass collection of telephone and internet metadata. It cites the Section 215 bulk phone records program, struck down in interpretation by the Second Circuit in 2015 and curtailed by the USA Freedom Act, and the NSA's Upstream program under Section 702 of the 2008 FISA Amendments Act, which ended content searches in 2017. The authors note mass surveillance now serves routine law enforcement and immigration actions, with FBI Director Kash Patel confirming purchases of Americans' data from brokers, and private systems like Flock license plate readers and venue facial recognition feeding government access.

Schneier on Security · 2d agoPolicy & legal

Risky Bulletin: Two TeamPCP members arrested in Australia

Australian Federal Police arrested two alleged TeamPCP members behind supply-chain worm attacks that stole over 500,000 credentials from compromised open-source libraries.

The AFP arrested alleged TeamPCP leader Ruben Thomson, 21, and Louis Gaebler, 23, near Perth; both were charged and remain in custody. The group inserted a self-spreading credential-stealing worm into open-source projects including Trivy, KICS, LiteLLM, and Telnyx, harvesting more than 500,000 credentials used for network access, ransomware, extortion, and sales. About 78,000 tokens and secrets from nearly 2,200 organizations leaked online last month, and the FBI supported the investigation that began in April.

Risky Business News · 20d agoPolicy & legal in the wild1

Exclusive: NSA to host a hacker reunion in bid to rebuild secretive unit

NSA will host a reunion of former Tailored Access Operations hackers as it moves to rebuild and rebrand the elite unit.

The invitation-only event at Fort Meade, spearheaded by Deputy Director Tim Kosiba, a former TAO technical director, will tour the new TAO building and pitch alumni to return. TAO, credited with contributions to Stuxnet and once grown to over 2,000 personnel, was renamed Computer Network Operations about a decade ago, and the recent reshuffle undid some of those changes after NSA lost roughly 2,100 staff (8% of its workforce) last year.

The Record · 21d agoIndustry

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

US Coast Guard and FBI boarded two foreign tankers bound for the US after indications their vessel networks were compromised, investigating possible Iranian involvement.

The Coast Guard and FBI conducted joint offshore security boardings of two commercial ships in the Gulf of Mexico on August 21 and 24 to examine their operational and IT systems following indications both networks were compromised. The vessels reportedly carried oil and natural gas, and one was hacked in the Strait of Gibraltar and lost communications for over 30 hours. No operational disruptions, vessel instability, or environmental impacts have been reported, and authorities are investigating whether Iran or another group exploiting US-Iran tensions was behind the attacks.

CyberScoopupdated · 18h agofirst · 22h agoData breach in the wild 2 sources

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

Trump signed an executive order declaring an emergency to bar foreign bulk-power equipment deemed a national security cyber risk.

The executive order, 'Declaring a National Energy Emergency to Secure the United States Bulk-Power System,' prohibits acquiring, importing, transferring, or installing foreign-produced bulk-power equipment and software deemed risky, citing fears of digital backdoors in Chinese-made grid gear. China supplies roughly 85% of solar supply chain capacity and is a major transformer manufacturer. The Energy Department has 120 days to develop implementing rules; the order revives a 2020 Trump-era measure the Biden administration had suspended after utilities found compliance difficult.

CyberScoop · 21d agoPolicy & legal1

Bipartisan Senate bill aims to prepare energy sector for Q

Bipartisan Senate bill would direct FERC to factor quantum computing threats and post-quantum cryptography into US electric grid cybersecurity reliability standards.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Senators Mike Rounds and Chris Coons, would require FERC to consider quantum computing threats when reviewing electric reliability standards and to explore post-quantum cryptography use in both IT and OT systems, plus a technical sandbox to study quantum impacts. It aligns with NIST's post-quantum algorithm work, and a June executive order moved the federal PQC migration deadline from 2035 to 2030. Industry experts noted the hard part is upgrading infrastructure such as SCADA communications and software update integrity ahead of those deadlines.

CyberScoop · 23d agoPolicy & legal

White House bans foreign-made equipment for power generation over cyber backdoor concerns

Trump executive order bans acquisition of foreign-made bulk-power system equipment over cyber backdoor and supply-chain concerns for US electricity infrastructure.

The White House issued an executive order declaring foreign-made bulk-power system electric equipment an "unusual and extraordinary threat," banning its acquisition or installation in the US. The order covers technology managing transmission lines rated at 69,000 volts or higher, substations, control rooms, power generating stations, reactors, and associated remotely accessible software and firmware. It follows recent cyberattacks on water utilities in at least 12 states, malicious activity targeting over 100 internet-exposed water and wastewater systems, and an NSA/FBI advisory on an AI-powered threat to operational technology. The Defense, Commerce, and Energy Departments have 120 days to create rules, identify countries warranting scrutiny, and inventory at-risk equipment.

The Record · 20d agoPolicy & legal

Governments ‘buying time’ in race between innovation, security, national cyber director says

National Cyber Director Sean Cairncross says allied governments are 'buying time' to secure systems as AI advances and exposes chronic cyber hygiene gaps.

Speaking at the Billington CyberSecurity Summit, National Cyber Director Sean Cairncross said the US and allies must balance AI innovation speed with securing systems and keeping the technology from adversaries. He argued AI has not created new cybersecurity problems but surfaced decades-old issues like under-resourced basic cyber hygiene, echoing FBI and CISA officials at the summit. His remarks followed US agencies accusing Chinese AI companies of illegally distilling US frontier models and Anthropic disclosing a fourth AI hacking incident involving one of its models.

CyberScoop · 6d agoPolicy & legal

Treasury sanctions alleged Iranian hackers as part of ‘economic D

US Treasury sanctioned four Iranians linked to MOIS-directed hacks that compromised and exfiltrated data from US critical infrastructure, energy, defense, and financial targets.

The Treasury Department designated four Iranian individuals over alleged hacking and cybertheft against US companies in energy, defense, healthcare, IT, and financial sectors since at least late 2023, as part of an 'economic D-Day' sanctions package. It is the second action in weeks against the group, following an indictment of cybercriminals affiliated with Tehran's Mabna Institute; leadership includes Behzad Mesri, first sanctioned in 2018, and the attacks are described as directed by the Ministry of Intelligence and Security (MOIS). Treasury also expanded secondary-sanction categories across digital assets, technology, gold, aviation, and shipping, and noted some group members pursued personal enrichment, including targeting Iranian companies.

CyberScoop · 22d agoPolicy & legal

A California county wants to hire Tina Peters to help run its elections

Shasta County, California plans to hire Tina Peters, convicted of stealing voting system software, as assistant registrar of voters.

Shasta County registrar of voters Clint Curtis said he plans to hire former Mesa County clerk Tina Peters as assistant registrar after Colorado Governor Jared Polis commuted her nine-year sentence for seven felonies, including identity theft, breaking into an election office, and stealing voting system software. Senators Alex Padilla and Adam Schiff asked California Secretary of State Shirley Weber to provide maximum oversight to prevent Peters from improperly accessing ballots, voting systems, or data of over 100,000 registered voters. The county board of supervisors recently censured Curtis after investigations found he was verbally abusive or physically threatening toward staff.

CyberScoop · 28d agoPolicy & legal

The G7 tells industry to hurry up and prep for post-quantum encryption

A G7 working group report urges governments and industry to accelerate post-quantum cryptography migration, framing quantum risk as a near-term economic threat.

A cybersecurity working group formed at the June 2026 G7 Summit in France called on organizations to stop postponing migration of critical systems to post-quantum cryptography, warning that harvest-now-decrypt-later attacks against currently encrypted data exist today. The report was signed by CISA, the UK NCSC, France's ANSSI, Germany's BSI, Canada's CSE, Japan's NCO, and Italy's ACN. It also cautions that some NIST-selected PQC algorithms have already been broken on classical computers, reinforcing support for crypto-agility. The push aligns with a recent US executive order moving federal PQC migration timelines from 2035 to 2030, while Google and others target 2029.

CyberScoop · 13d agoPolicy & legal

‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help

White House launches Watershed 250, a six-month Texas pilot using volunteer vendor cyber and AI tools to harden water utility defenses.

The Office of the National Cyber Director and Texas Cyber Command will oversee the six-month Project Watershed 250 pilot to improve water sector cybersecurity through industry-donated red teaming, system hardening and AI tooling. Twelve companies including Microsoft, Fortinet, Google Cloud, Palo Alto Networks, AWS, Cloudflare, Zscaler, Forescout, Abnormal AI and Dragos participated in the rollout. Officials cited recent attacks including an Iranian-backed campaign against 30 water systems in 12 states and a 2024 incident in Muleshoe, Texas. Some water-security professionals criticized the program as lacking dedicated funding.

CyberScoop · 16d agoPolicy & legal1

Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail

A whistleblower alleges USPS is rushing untested IT systems that could reject thousands of mail-in ballots ahead of the 2026 midterm elections.

A whistleblower complaint released by Sen. Richard Blumenthal says USPS is deploying three new, largely untested IT systems — including the Federal Ballot Mail Portal — that could reject entire ballot batches over single scan errors. The systems were developed in weeks without standard testing or interoperability checks, and USPS allegedly continued work despite court injunctions against its rule changes. House Oversight Democrats demanded USPS halt implementation, and election experts warn the design could lead to new lawsuits and mass ballot denials.

CyberScoop · 15d agoPolicy & legal

Risky Bulletin: Russia tells data centers to deploy drone defenses

Russia ordered data center operators to deploy drone strike defenses under a Putin decree allowing temporary state takeover of unprotected critical infrastructure.

The Russian government instructed data center operators to deploy protections against drone strikes under a presidential decree signed by Putin that allows temporary state administration of critical infrastructure operators failing to defend against Ukrainian hacks and drone strikes. Although data centers are not formally critical infrastructure in Russia, the decree applies to them because other sectors depend heavily on cloud services; Russia has more than 180 data centers, over 80% in the European region within range of Ukrainian strikes. The digest also reports a Dropbox breach affecting nearly 5,000 accounts via the Lenovo ID integration, spyware attacks on at least 14 Serbians using NoviSpy or Pegasus, and a password recovery attack targeting hundreds of thousands of X accounts tied to the new X Money service. Other items include a 14-hour compromise of Coder's Cloudflare infrastructure delivering malicious Terraform modules, donor data breaches at Davayte and You Are Not Alone via the Stripe/WooCommerce integration, a $2.5M Aquifer crypto heist, and a TVING breach exposing data of almost 40 million accounts.

Risky Business News · 13d agoPolicy & legal

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Academics linked Chinese vendor Geedge Networks' Tiangou Secure Gateway source code to one of the Great Firewall's three traffic filtering capabilities.

US researchers presenting at USENIX Security reconstructed Geedge Networks' Tiangou Secure Gateway firmware from over 100,000 leaked files, including Git repositories with commit history, and matched its filtering behavior to sections of China's Great Firewall. They found only 1 of 3 characterized DNS injectors matched Geedge code, noted the system relies on memory-unsafe C components and copied third-party code, and said its bugs could aid future circumvention tools. Geedge also exports censorship tools to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The newsletter additionally rounds up multiple breaches.

Risky Business News · 27d agoResearch2

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

NSA is reorganizing into five mission centers covering China, cybersecurity, AI, combat support and global intelligence, with full capability targeted by January.

NSA Director Gen. Joshua Rudd announced a sweeping reorganization replacing existing directorates with five mission centers focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence. A 30-day implementation clock has started, and the centers are expected to reach full operational capability by January. Officials acknowledge the rapid realignment will 'break things' in the agency's bureaucracy; this is the largest restructuring since the NSA21 effort roughly a decade ago, which was widely viewed as a failure.

The Record · 3d agoPolicy & legal

OFAC Sanctions Chinese Scam Platform Xinbi Guarantee

US Treasury's OFAC sanctioned Chinese scam-platform Xinbi Guarantee, which processed $24bn+, and froze $52.8m in linked cryptoassets.

OFAC sanctioned Xinbi Guarantee, a Chinese-language marketplace connecting Southeast Asian scam centers and transnational crime syndicates to merchants offering financial services, technology and crypto exchange. Treasury estimates over $24bn processed since 2022, while TRM Labs estimates over $36bn, with daily inflows nearly doubling between May and December 2025. Two supporting entities were also sanctioned: SafeW Technology (Singapore) and Anwen Technology (Cambodia, maker of XinbiPay). The US Secret Service and Elliptic froze $52.8m in linked cryptoassets, and the marketplace now appears offline with its Telegram channels deleted.

Infosecurity Magazine · 7d agoPolicy & legal1

CISA head says agency must change quickly to prevent the 'worst that could happen'

Acting CISA Director Nick Andersen warned of US cyber vulnerabilities and said the agency is refilling staff cut to about half strength.

Speaking at the Billington CyberSecurity Summit, acting CISA Director Nick Andersen warned that decades of bad decisions, overwhelming technical debt, outdated technology and AI-driven threats could lead to devastating cyber incidents without rapid, significant changes. He said the agency has about 250 screened hires awaiting security clearances after losing roughly a third of its staff to DOGE-related cuts and attrition, and referenced a June pledge by DHS Secretary Markwayne Mullin to refill about 600 CISA jobs. Andersen called AI a gamechanger, citing daily headlines about rogue AI agents and an Anthropic researcher leaving over model safety concerns.

The Record · 7d agoPolicy & legal

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

US DOJ and Treasury disrupt Xinbi Guarantee Telegram scam marketplace, sanctioning it and freezing $52.8M in USDT across 52 wallets.

The DOJ seized Xinbi Guarantee's Telegram channels and cryptocurrency wallets while OFAC sanctioned the marketplace, freezing $52.8 million in USDT from 52 wallets and bringing the Scam Center Strike Force's total restrained funds to roughly $938 million. Elliptic, which worked with the Secret Service, estimates Xinbi has processed $30 billion in transactions since around 2022, serving pig-butchering scam operators and links to North Korean hackers, Jin Bei Group, and Prince Group TCO. The strike force dismantled 13 scam compounds in Madagascar, seizing over 3,200 devices and interviewing roughly 400 arrestees, with about 30 Chinese compound leaders repatriated to China. After Tether froze funds, Xinbi began converting remaining USDT into the USDD stablecoin.

The Hacker News · 7d agoPolicy & legal

FBI puts its cyber strategy on paper

FBI publishes its first public cybersecurity strategy, a 17-page document with four pillars prioritizing disruption of cybercrime and nation-state hackers.

The FBI released its first-ever public cybersecurity strategy, a 17-page unclassified document outlining four pillars: imposing costs on adversaries, victim support, industry collaboration, and strengthening the bureau's digital capabilities. Cyber Division assistant director Brett Leatherman said the plan builds on the Trump administration's cybersecurity strategy, a recent executive order on countering digital criminals, and a memo enabling private-industry participation in disruptive operations, and promises a faster tempo of sequenced operations after 50 such actions since the start of 2025, including the Lumma malware takedown with Microsoft. No implementation plan or timeline exists yet; threat teams targeting China, Russia, and criminal gangs will develop classified sub-strategies.

The Record · 7d agoPolicy & legal

CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro

CIA deputy director credits the Cyber Mission Center's cyber operations for the intelligence picture behind Nicolás Maduro's capture.

CIA Deputy Director Michael Ellis said at the Billington Cybersecurity Summit that cyber operations built the 'flawless intelligence picture' enabling US special forces to locate Nicolás Maduro in his Caracas bunker and apprehend him within four minutes of landing during January's Operation Absolute Resolve. Director John Ratcliffe elevated the Center for Cyber Intelligence to a standalone mission center, which Ellis said smooths reporting chains and aligns resources. Ellis also said AI will 'permeate' every aspect of intelligence work, with human-in-the-loop safeguards and multi-vendor approaches to avoid model lock-in. The US has unsealed narcoterrorism charges against Maduro and his wife, who are seeking dismissal under immunity claims.

The Record · 8d agoPolicy & legal 2 sources

Risky Bulletin: BEC campaign steals €35 million from French notaries

Hackers stole over €35 million from 500+ French notary offices in a four-year BEC campaign; ANSSI spent two years helping evict the attackers.

A business email compromise campaign breached more than 500 French notary offices — about 7% of all French notaries per the Conseil Supérieur du Notariat — over four years, stealing more than €35 million by phishing initial access and silently modifying wire transfer details. France's cybersecurity agency ANSSI worked for two years behind the scenes to help notaries remove the persistent attackers, who had deep access; officials also feared hackers could issue fake notarized acts such as marriage certificates or forged real estate deals. No forged documents have been found so far, but notaries have added two-factor authentication and in-person requirements for banking details, and banks added extra checks in 2024. The newsletter also notes other incidents, including a $320 million Bitcoin extraction from Blockstream's Liquid Network and a JetBrains Cadence breach via TeamCity servers.

Risky Business News · 10d agoPhishing & fraud in the wild1

Srsly Risky Biz: China's Private Sector Botnets Are Worth Disrupting

DoJ seized domains of Chinese espionage botnet platforms QScan and QTRouter, run by private firm QTFY for MSS and PLA targeting.

The US Department of Justice disrupted QScan, a distributed vulnerability scanning system with nearly a decade of internet scanning data, and QTRouter, a covert communications platform routing traffic through compromised IoT devices, operated by QTFY under Chinese company Nanjing Xinjiuwei Network Technology. FBI and NSA advisories say QTFY customers include China's Ministry of State Security and the People's Liberation Army, targeting federal agencies, the US Senate, hospitals, telecoms and financial institutions. This is the third Chinese state-backed botnet disrupted since December 2023, following the KV botnet (Volt Typhoon) and Raptor Train (Flax Typhoon), and a sister network, JDY, has more than doubled since the KV disruption. Separately, the Qilin ransomware group claimed a breach of the ATF's CALEA system, briefly publishing 6.3 GB of case folders and forensic data.

Risky Business News · 14d agoThreat actor1

Sality, one of the longest

US and European authorities, with CrowdStrike and Shadowserver, disrupted the 20-year-old Sality peer-to-peer botnet, severing 15,000+ infected machines from operators.

US and European authorities disrupted the Sality botnet, active since at least 2003, in an operation involving the DOJ, CrowdStrike, the Shadowserver Foundation and agencies in Bulgaria, Hungary and Romania. Researchers reverse-engineered the botnet's peer-to-peer architecture and injected false data into infected machines' 'super peer' lists, cutting more than 15,000 systems off from their operators. For the past eight years Sality primarily distributed EggJagger, malware that replaces clipboard cryptocurrency addresses and is estimated to have netted the operator at least $150,000. No arrests were announced, and CrowdStrike assesses the operator works from Russia's Bashkortostan region.

The Record · 15d agoMalware in the wild

Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea

A Trump presidential memo directs DHS to authorize vetted private-sector hackers to conduct cyber operations against foreign cybercriminal groups (CE-TCOs).

A presidential memorandum directs the Department of Homeland Security to establish a program authorizing private companies to conduct cyber surveillance and cyber effects operations against Cyber-Enabled Transnational Crime Organisations (CE-TCOs). Participating companies must pass vetting, obtain government approval before operations, and post a USD $1 million bond. The accompanying fact sheet cites more than USD $20.8 billion in US losses to cyber-enabled crime in 2025. Critics worry about accidental escalation if operations touch foreign government systems.

Risky Business News · 28d agoPolicy & legal1

Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft

Malone Lam's plea hearing approaches in the $240 million bitcoin social engineering theft; the case highlights surging crypto fraud and limited enforcement.

Malone Lam, accused of organizing a social engineering attack that stole over $240 million in bitcoin (4,100+ BTC) from a Washington, D.C. resident in August 2024, has a plea agreement hearing set. Callers impersonating Google and Gemini staff tricked the victim into revealing security codes. Lam and 17 co-defendants spent lavishly before FBI arrests; crypto investment fraud complaints to the FBI rose nearly 50% in 2025 while DOJ disbanded its crypto crimes unit.

SecurityWeek · 9d agoPolicy & legal

ICE Wants the Country’s Voter Data

ICE seeks a federal contractor to access national voter registration and history files, citing fraud detection ahead of the midterm elections.

Procurement records reviewed by 404 Media show ICE seeking a federal contractor to provide access to US voter registration and voter history data to help detect fraud. Observers question whether the data will support immigration enforcement actions ahead of the midterms, given the administration's use of fraud as a pretense. The paywalled article provides few further details.

404 Media · 22d agoPolicy & legal

Leaks, data breaches, and ransom notes: The worst hacks of 2026 so far

TechCrunch's 2026 roundup covers SSA data exposure, Iranian water-utility attacks, Klue breach hitting ~200 firms, and Meta AI chatbot account hijacks.

TechCrunch's mid-year roundup highlights a whistleblower claim that DOGE uploaded a live Social Security database copy to an unsecured third-party server, which House Democrats called potentially the largest US breach in history. CISA reported Iranian hackers targeted over 100 US water providers over the summer, while Russian-linked attacks hit Polish, Swedish, and Norwegian energy and water infrastructure. Market research firm Klue was breached via a stale 2022 pilot credential, exposing cloud keys of ~200 customers including Jamf, HackerOne, and LastPass to extortion gang Icarus. Separately, tens of thousands of Instagram accounts were hijacked by abusing Meta's AI chatbot to trigger password resets to attacker-controlled emails.

TechCrunch · Security · 1d agoData breach in the wild

Lawmakers seek watchdog review of federal hacking of Americans

Sen. Wyden and Rep. Casar asked the GAO to review the federal government's use of spyware and hacking tools against Americans.

Sen. Ron Wyden and Rep. Greg Casar sent a letter to the Government Accountability Office requesting a review of federal law enforcement hacking operations, including spyware use, Rule 41 hacking powers, and acquisition of hacking tools. The letter cites ICE's confirmed work with spyware vendor Paragon and concerns about abuse of invasive surveillance capabilities. The lawmakers note the government publishes no annual reports on hacking operations unlike wiretaps.

CyberScoop · 26d agoPolicy & legal

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Trump's Executive Order 14420 declares a national emergency to restrict foreign-made bulk-power grid equipment over cyber, sabotage and supply-chain risks.

Executive Order 14420, signed August 26, declares a national emergency regarding the foreign supply of bulk-power system electric equipment to the United States. It empowers the Energy Secretary to restrict transactions with designated Covered Foreign Entities involving equipment, software, firmware, digital services, maintenance services, and remote-access capabilities. Covered equipment includes transformers, generators, inverters, RTUs, PLCs, intelligent electronic devices, and protective relays, with transmission rated 69 kV or higher in scope while local distribution is excluded. Already-installed foreign equipment may be subject to identification, isolation, monitoring, or replacement requirements, with phased compliance and pre-qualified vendor exemptions permitted.

Security Affairs · 19d agoPolicy & legal

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

The Combating Organized Retail Crime Act advances toward Senate attachment to the defense bill, drawing ACLU warnings of expanded ICE surveillance powers.

The Combating Organized Retail Crime Act (CORCA) passed the House 348-60 in June, and Senate supporters including Chuck Grassley are pushing to attach it to the annual defense policy bill. The bill would create an Organized Retail and Supply Chain Crime Coordination Center within ICE's Homeland Security Investigations, add criminal penalties for laundering stolen-goods proceeds with a $5,000 charging threshold, and broaden data sharing with retailers. The ACLU, NAACP LDF, and allied groups warn the vaguely drafted provisions would effectively grant DHS access to retail surveillance feeds such as cameras and license plate readers, while industry backers say it only enhances existing information sharing and could help fight cyber-enabled crime.

CyberScoop · 27d agoPolicy & legal1

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze, an early 764 member, was sentenced to 77 years for producing CSAM, the longest sentence for a nihilistic violent extremist.

Kyle William Spitze, an original member of the 764 nihilistic violent extremist network and administrator of the Harm Nation offshoot, was sentenced to 77 years in federal prison. He pleaded guilty in December 2024 to producing child sexual abuse material, possession of CSAM, and distributing animal crush videos, victimizing dozens of girls through coercion, doxing and swatting threats. Investigators found roughly 25 photo albums of abuse imagery on his phone and evidence of animal torture. The Justice Department framed the sentence as a signal in a broader enforcement push against 764, which has seen multiple members arrested or sentenced since 2025.

CyberScoop · 27d agoPolicy & legal

FTC rescinds policy requiring health apps to notify customers after a breach

The FTC unanimously rescinded its 2021 policy statement that required health and fitness apps to notify users after health-data breaches.

The FTC voted to rescind a September 2021 Biden-era policy statement that extended federal health-data breach notification rules to health apps, fitness trackers, and connected devices, which had exposed violators to fines of $43,792 per violation per day. The 2021 statement, adopted in a divided 3-2 vote under then-chair Lina Khan, cited HIPAA coverage gaps for consumer health applications. The commission said the statement provided minimal benefit, was superseded by rulemaking, and aligns with the White House deregulatory agenda.

CyberScoop · 7d agoPolicy & legal

Attackers exploit zero-days in consistently besieged SonicWall product

Two actively exploited SonicWall SMA 1000 zero-days chain to unauthenticated RCE; patches released and CISA added both to KEV.

SonicWall disclosed and patched two zero-days in SMA 1000 appliances: CVE-2026-83548, a maximum-severity pre-authentication SSRF, and CVE-2026-83549, a high-severity OS command injection. Rapid7 said chaining the flaws yields unauthenticated remote code execution, and CISA added both to its KEV catalog Wednesday. The vendor provided no IOCs or victim counts, urging customers to hunt for compromise, reimage or redeploy appliances, and reset all passwords and tokens. The product has faced repeated exploitation, including ransomware-linked flaws used by INC and Akira.

CyberScoop · 13d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549

America’s cyber strategy overlooks the infrastructure that actually keeps the military moving

Op-ed argues US cyber strategy underweights Iranian threats to ports, rail, utilities and other commercial infrastructure sustaining military operations.

The author, a former Navy intelligence officer, argues that a prolonged Iran conflict means sustained Iranian cyber operations targeting many smaller systems like water utilities, manufacturers and transportation providers. He cites mapping of 130 documented techniques across five Iranian threat groups and warns destructive attacks such as wipers and ransomware could hit the defense industrial base. The piece urges defensive wargames now and flags the pause in CMMC implementation as particularly concerning.

CyberScoop · 3h agoIndustry

FCC proposes public scorecard to rate telecoms on anti-robocall efforts

The FCC proposed a public scorecard rating telecoms' anti-robocall effectiveness and removed 14 providers from US networks for compliance failures.

The Federal Communications Commission issued a public notice proposing a scorecard that would assess how effectively retail voice providers, including wireless, wireline and VoIP, prevent illegal robocalls, drawing on Robocall Mitigation Database filings, consumer complaint and enforcement data. The agency stressed it is not a rulemaking imposing new requirements, and it is seeking comment on scope, such as whether to focus on larger providers. The same day, the FCC removed 14 providers from the Robocall Mitigation Database for non-compliance, effectively requiring other US providers to block their traffic within two days.

CyberScoop · 14d agoPolicy & legal