ZeroHour

Search: “us-northcom”

25 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

10th August – Threat Intelligence Report

North Carolina Ports suffered a cyberattack forcing Wilmington and Morehead City operations onto manual processes; the authority says it is contained.

Check Point's weekly threat intelligence bulletin reports that North Carolina Ports, the US authority operating the ports of Wilmington and Morehead City among others, suffered a cyberattack. The incident forced some operations onto manual processes. The authority claims it has contained the attack.

Check Point Research · Aug 10, 2026Data breach

Help shape the future of resilient private 5G

The UK NCSC invites organizations to collaborate on developing secure, resilient and deployable private 5G network technologies.

The UK National Cyber Security Centre is seeking collaboration with organizations developing technologies and approaches for secure, resilient and deployable private 5G networks. The blog post is an open call to help shape future private 5G resilience.

NCSC UK · Aug 12, 2026Advisory

U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks

The U.S. State Department offered up to $10 million for information on Amir Yaryab, an IRGC cyber chief linked to critical infrastructure attacks.

The U.S. State Department's Rewards for Justice program offers up to $10 million for information identifying or locating Amir Yaryab, who allegedly oversees the Cyber Operations Command of Iran's IRGC Cyber-Electronic Command (IRGC-CEC). Officials tie him to units called Shahid Hemmat and Shahid Shushtari conducting cyber and information campaigns against defense, telecommunications, energy, and finance sectors across the US, Europe, and the Middle East, and to groups including CyberAv3ngers and Dadeh Afzar Arman. CyberAv3ngers compromised at least 75 Unitronics Vision Series PLCs, including 34 in US water and wastewater facilities, between November 2023 and January 2024.

Cyber Security News · 8d agoPolicy & legal

North Korean IT Workers Scheme: Detection IOCs and Tactics for Government and Corporate SOCs

ANY.RUN details the expanding North Korean IT worker infiltration scheme using forged identities and AI-assisted workflows, sharing detection IOCs for SOCs.

ANY.RUN describes how North Korean IT workers infiltrate American and European organizations using forged identities and AI-assisted workflows to become trusted insiders. The operation bypasses traditional security perimeters and has expanded beyond the private sector to government targets. The post provides detection IOCs and tactics for government and corporate SOCs.

ANY.RUN · 27d agoThreat actor

The AI data center boom is colliding with cities scarred by big industry

Philadelphia activists rally against AI data center construction amid energy and pollution concerns, joining a wave of U.S. city moratoriums.

Residents of Philadelphia's Grays Ferry, home to a former oil refinery, launched the 'No Data Centers in Philly' campaign over pollution, noise, and resource concerns. BloombergNEF projects U.S. data centers will consume more natural gas than Germany and Japan combined by 2035. New York Governor Kathy Hochul signed an executive order pausing permits for large data center projects, and moratoriums have passed in Denver, Indianapolis, Asheville, Charlotte, and Reno.

TechCrunch · AI · 1d agoAI industry

SK Hynix reportedly in talks with Intel to build memory chips in US

SK Hynix is reportedly negotiating with Intel to manufacture memory chips in the US, possibly leasing space at Intel's Ohio fab.

Reuters reports SK Hynix and Intel have discussed SK Hynix producing RAM in the US for the first time, including leasing space at Intel's planned Ohio factory or forming a joint venture that could include cloud-service providers; SK Hynix says nothing is finalized. The company is already building a $3.8 billion AI chip packaging and research facility in West Lafayette, Indiana, with mass production expected to begin in 2029, amid surging HBM demand from AI data centers. The potential deal could face a South Korean government review over transfers of strategically important chip technology, and follows Intel's 2020 sale of its NAND flash business to SK Hynix for $9 billion.

TechCrunch · AI · 17h agoAI industry

Ncsc Raises Alarms Prompt

The UK NCSC raised alarms about prompt injection risks in LLM-integrated systems, urging organizations deploying AI to review exposure.

The UK National Cyber Security Centre (NCSC) has raised alarms about prompt injection attacks against systems using large language models. The warning highlights how attackers can manipulate model instructions to bypass safeguards, exfiltrate data, or trigger unintended agent actions. Organizations deploying LLM-based features are advised to assess and mitigate their exposure to this technique.

Infosecurity Magazine · 29d agoAI safety & security

NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

Unit 42 links NOKKI malware to North Korea's Reaper group, uncovering the Final1stspy dropper that deploys the DOGCALL RAT in politically motivated attacks.

Unit 42 analyzed the NOKKI malware family used in politically themed attacks against Russian and Cambodian speakers since July 2018. The researchers linked NOKKI to the Reaper group, publicly attributed to North Korea, whose custom DOGCALL RAT uses third-party hosting services to upload data and receive commands. A previously unreported family, Final1stspy, was found deploying DOGCALL, sharing a unique base64-to-hex deobfuscation routine with NOKKI droppers. Attacks used malicious Microsoft Word macros that download and execute payloads while opening decoy documents.

Palo Alto Unit 42 · Aug 17, 2026Malware

UK appoints new commander of National Cyber Force

The UK National Cyber Force has a new commander, its third since 2020, succeeding Air Vice-Marshal Tim Neal-Hopes; identity not yet avowed.

The United Kingdom's National Cyber Force has changed commanders, with the new leader's identity not yet formally avowed pending security considerations. The new commander is the third since the force was established in 2020, following James Babbage (GCHQ) and Air Vice-Marshal Tim Neal-Hopes (armed forces), both of whom have now completed their tenure. The NCF consolidates UK offensive cyber capabilities under a joint defense-intelligence partnership including GCHQ, MI6, and Dstl, with funding committed to 2030 and a permanent headquarters at Samlesbury progressing as scheduled.

The Record · 6d agoPolicy & legal

Is Someone Hacking DoD Refrigerators?

Refrigeration outages hit commissaries at seven US military installations, with hacking suspected but not confirmed by the Pentagon.

Refrigeration disruptions were reported at Defense Commissary Agency commissaries at Fort Irwin, F.E. Warren AFB, Fort Huachuca, Naval Station Newport, Columbus AFB, Travis AFB, and Naval Air Station Lemoore. A defense official acknowledged awareness of a possible refrigeration disruption, but the services and Pentagon declined to provide details. The post is speculative, arguing the coincidence of outages suggests possible hacking, though no evidence or attribution is provided.

Schneier on Security · 16d agoData breach

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

NSA is reorganizing into five mission centers covering China, cybersecurity, AI, combat support and global intelligence, with full capability targeted by January.

NSA Director Gen. Joshua Rudd announced a sweeping reorganization replacing existing directorates with five mission centers focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence. A 30-day implementation clock has started, and the centers are expected to reach full operational capability by January. Officials acknowledge the rapid realignment will 'break things' in the agency's bureaucracy; this is the largest restructuring since the NSA21 effort roughly a decade ago, which was widely viewed as a failure.

The Record · 3d agoPolicy & legal

Cyber Command turns to veteran of intelligence agencies for top AI role

US Cyber Command appoints Rear Adm. Ronzelle Green as chief AI officer as its AI budget grows from $5M to $138M.

US Cyber Command has named Ronzelle Green, previously head of research and development at the National Geospatial-Intelligence Agency, as its new Chief Artificial Intelligence Officer, replacing Brig. Gen. Reid Novotny. The command's 'AI for Cyber Operations' budget request grew from $5 million in fiscal 2026 to $138 million in fiscal 2027, aiming to let cyber operators process data and respond to threats faster than humans alone. Sources say Green's priority will be consolidating fragmented AI pilot programs across the organization, in contrast to the NSA's more established Artificial Intelligence Security Center created in 2023.

The Record · 6d agoAI policy 3 sources1· 1 read

US, Britain to coordinate on scam center takedowns

The US and UK signed an MOU to jointly investigate Southeast Asian scam compounds behind fraud that stole over $12 billion from Americans last year.

The DOJ and UK's National Crime Agency and Crown Prosecutor signed a memorandum of understanding on Thursday for parallel investigations and information sharing on scam centers, largely run by Chinese gangs using human trafficking victims in compounds across Myanmar, Cambodia, and Laos. The Scam Center Strike Force, with more than 150 personnel from the FBI, IRS, and US Postal Inspection Service, leads the effort; the FBI says cyber-enabled fraud accounted for almost 85% of reported losses, with over $12 billion stolen from Americans last year. An in-person disruption event with private industry partners is planned in London in early October. The initiative follows sanctions on Prince Group and a roughly $15 billion bitcoin seizure linked to its CEO Chen Zhi.

The Record · 12d agoPolicy & legal

US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks

Trump signed a national security memorandum letting vetted private US cybersecurity firms run government-approved offensive cyber operations against transnational criminal organizations.

The August 13 memorandum creates a program managed by the National Coordination Center covering Cyber Surveillance Operations and Cyber Effects Operations against Cyber-Enabled Transnational Criminal Organizations, explicitly excluding entities that are parts of foreign governments. DOJ and DHS executive directors must co-approve every operation in writing, with extra authorization for operations raising laws-of-armed-conflict questions. Participating firms must pass vetting, annual evaluations and hold a $1 million bond or escrow. Operating procedures are due within 60 days, and the unresolved CFAA exemption question is addressed by requiring direct government control.

Security Affairs · Aug 14, 2026Policy & legal

Trump Targets Foreign Technology in New U.S. Power Grid Security Order

Trump's Executive Order 14420 declares a national emergency to restrict foreign-made bulk-power grid equipment over cyber, sabotage and supply-chain risks.

Executive Order 14420, signed August 26, declares a national emergency regarding the foreign supply of bulk-power system electric equipment to the United States. It empowers the Energy Secretary to restrict transactions with designated Covered Foreign Entities involving equipment, software, firmware, digital services, maintenance services, and remote-access capabilities. Covered equipment includes transformers, generators, inverters, RTUs, PLCs, intelligent electronic devices, and protective relays, with transmission rated 69 kV or higher in scope while local distribution is excluded. Already-installed foreign equipment may be subject to identification, isolation, monitoring, or replacement requirements, with phased compliance and pre-qualified vendor exemptions permitted.

Security Affairs · 19d agoPolicy & legal

Risky Bulletin: White House lets private companies carry out offensive cyber ops

A White House memo directs DHS to create a program letting vetted private companies conduct US-government-directed offensive cyber operations against cybercrime.

A presidential memo tasks the DHS National Coordination Center with building a program, under DOJ and DHS oversight, through which private-sector companies can conduct offensive cyber operations against large-scale cybercrime organizations. Requirements include secure facilities, vetted personnel, a $1 million escrow for damages, and written approvals co-signed by DHS and DOJ executive directors. The program must launch within 60 days, around October 11, expanding a March executive order targeting scam compounds, ransomware, and other large-scale cybercrime.

Risky Business News · Aug 14, 2026Policy & legal

You don’t have to join the hack-back program to inherit its risk

A new US presidential memorandum creates a vetted private hack-back program, leaving participating vendors and their customers with untested legal liability and collateral risks.

The August 12 National Security Presidential Memorandum directs the National Coordination Center, run jointly by DOJ and DHS, to approve covert surveillance and disruptive Cyber Effects Operations by vetted private companies, with a forfeitable bond of at least $1 million required as a contract condition. The analysis argues the criminal shield rests on an untested reading of the CFAA exemption at 18 U.S.C. 1030(f), with no civil safe harbor, no state-law preemption and no foreign-law protection. Non-participating organizations can still inherit risk through shared infrastructure collateral damage, lack of customer disclosure, Lloyd's bulletin Y5381 state-backed attack exclusions, and threat-intelligence pipelines feeding offensive proposals.

CSO Online · 22h agoPolicy & legal

Red Flags That Expose Fake North Korean IT Workers

Researchers outline red flags for spotting North Korean operatives posing as remote IT workers as their tactics improve.

Dark Reading describes indicators that help organizations identify North Korean operatives working undercover as IT workers. Researchers say these operatives are improving their tactics, but detection methods still exist. Catching them early helps employers avoid infiltration, data theft, and damage.

Dark Reading · 21d agoPhishing & fraud

US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate

US Justice Department seized domains of a Chinese botnet used to hack NASA, the Justice Department, and the Senate, disabling its C2.

The US Justice Department seized domains belonging to a Chinese botnet that was used to hack NASA, the Justice Department, and the Senate. The seized domains were hardcoded into the botnet's code, so the seizures rendered the botnet and its command-and-control servers inoperable. The action disrupted the malware's communication channels and essential operations.

TechCrunch · Security · 21d agoThreat actor in the wild

Managing the cyber risk of agentic AI

UK NCSC guidance recommends safeguards, sandboxing, and active oversight to manage cyber risks of autonomous agentic AI systems.

The UK National Cyber Security Centre published guidance on managing the cyber risk of agentic AI systems. It recommends safeguards, sandboxing, and active human oversight to limit unintended autonomous activity while realizing the benefits of these systems. The publication is official national guidance for organizations deploying agentic AI.

NCSC UK · 27d agoAdvisory

AT&T store worker gets 16 months inside for SIM-swap side hustle

Former AT&T store worker Kenneth Carter sentenced to 16 months for SIM-swapping customers for cybercriminals.

Kenneth Carter, 44, a former AT&T retail employee in Portland, Oregon, used his internal system access to perform SIM swaps on customers' phone numbers for cybercriminals. The swaps allowed criminals to intercept authentication codes and raid victims' bank accounts. Carter was sentenced to 16 months in federal prison.

DataBreaches.net · 3d agoPolicy & legal1· 1 read

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Unauthorized access to Thomson Reuters' C-Track court platform may have exposed SSNs and sealed records across 11 US states, USVI, and Ontario.

Thomson Reuters' West Publishing disclosed that an unauthorized party obtained files from the C-Track court case management platform starting in March 2026, with access to one environment running from March 1 through June 29, 2026 per Montana's account. Notices name roughly 24 court bodies across 11 US states, the US Virgin Islands, and Ontario, including appellate courts in Minnesota, Ohio, Montana, and Pennsylvania. Exposed data may include names, Social Security numbers, driver's license numbers, dates of birth, medical and health insurance information, and confidential or sealed court records. The company is offering 12 months of Experian or TransUnion monitoring, and courts disagree over whether the vendor's backup cloud environment or the production platform was accessed.

The Hacker News · 13d agoData breach in the wild