Trump taps cyber firms to go on offensive against criminals
Presidential memorandum allows vetted private companies to conduct offensive cyber operations against transnational cybercrime with advance DOJ and DHS approval.
A presidential memorandum released Wednesday lets vetted US companies partner with the Justice and Homeland Security departments on offensive operations and surveillance targeting transnational cybercrime, fraud and predatory schemes, with written pre-approval required for every operation. Operations may not cause loss of life or rise to the level of use of force or armed attack under international law. Participating firms face penalties of at least $1 million for contract violations, must disclose all contractual relationships, and face annual evaluation, while agencies have two months to develop participation standards. The move builds on a March executive order; the White House says Americans reported $20.8 billion in cyber-related losses last year.
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
Microsoft warns of Teams IT-impersonation intrusions deploying Node.js implants; Spring Ring vishing hit 150+ employees across 10 companies; The Gentlemen ransomware claims 683 victims.
Microsoft warned of a human-operated campaign abusing Teams external collaboration to impersonate IT help desk staff, deploy malicious MSI packages staging Node.js runtimes and obfuscated JavaScript implants, then pivot to domain controllers over WinRM. Unit 42 documented the Spring Ring vishing operation targeting over 150 employees across at least 10 companies using 26 attacker identities, including an NTLM relay variant against domain controllers. Sophos reported The Gentlemen ransomware (Gold Sherwood) reached 683 total victims by end of July 2026, adding 169 in July, with a playbook using BYOVD-based EDR killers and backup tampering. Group-IB found the Outsider phishing-as-a-service platform created 700+ new phishing pages within a month despite law enforcement takedowns.