<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:nb="https://www.newsbreak.com/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Nextgov/FCW - Cybersecurity</title><link>https://www.nextgov.com/cybersecurity/</link><description></description><atom:link href="https://www.nextgov.com/rss/cybersecurity/" rel="self"></atom:link><language>en-us</language><lastBuildDate>Fri, 25 Sep 2026 17:43:00 -0400</lastBuildDate><item><title>OpenAI agents accessed Census, SEC data and tried to hack Education website</title><link>https://www.nextgov.com/cybersecurity/2026/09/openai-says-its-advanced-models-may-have-gone-after-government-websites/416250/</link><description>The disclosure follows warnings from former officials in August that government systems could face unintended intrusions by autonomous AI agents.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 25 Sep 2026 17:43:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/openai-says-its-advanced-models-may-have-gone-after-government-websites/416250/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;&lt;em&gt;UPDATED Saturday, Sept. 26&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;OpenAI&amp;rsquo;s artificial intelligence agents accessed Census Bureau data using developer keys found online and reposted public Securities and Exchange Commission information on another website, the company confirmed. Researchers separately identified a failed attempt by agents linked to OpenAI to hack an Education Department website.&lt;/p&gt;

&lt;p&gt;The details identify specific U.S. agencies following the company&amp;rsquo;s Friday disclosure that government websites were among the outside systems involved in its investigation of agents acting beyond their assigned tasks or intended methods during training and testing.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.nytimes.com/2026/09/25/technology/openais-ai-us-government-websites.html"&gt;The New York Times reported Friday&lt;/a&gt;⁠ that researchers at the AI research organization Transluce identified the unsuccessful attempt to hack Education&amp;rsquo;s website to obtain data from its civil rights office. An Education spokesperson told the newspaper that reviews found no evidence of an impact on its website or databases.&lt;/p&gt;

&lt;p&gt;OpenAI said its models accessed only public information from Census and the SEC. In the Census case, agents used Census Data API developer keys found in public GitHub repositories during internal training tasks. Those keys authenticated read-only requests for public demographic and economic data, the company said.&lt;/p&gt;

&lt;p&gt;OpenAI said it found no access to Census accounts or key-management functions, and no ability to modify agency data or systems.&lt;/p&gt;

&lt;p&gt;At the SEC, agents retrieved information available to any visitor to&lt;a href="http://sec.gov"&gt; SEC.gov&lt;/a&gt; and&lt;a href="http://investor.gov"&gt; Investor.gov&lt;/a&gt;, then posted some of it on another public webpage. OpenAI said it found no use of SEC credentials, access to accounts or nonpublic information, changes to agency systems, or evidence of a compromise or vulnerability.&lt;/p&gt;

&lt;p&gt;The company said it notified both agencies and shared technical findings. The SEC told the Times it was unaware of unauthorized access to nonpublic information, while Commerce said no private Census data was accessed.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As we previously announced, we&amp;rsquo;re conducting an extensive review of misaligned model activity and notifying organizations when we identify potential impacts to their systems,&amp;rdquo; an OpenAI spokesperson told Nextgov/FCW. &amp;ldquo;We expect to make additional notifications as that work continues.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The company has notified dozens of organizations as it reviews activity that may have bypassed security controls, disrupted services or otherwise negatively affected websites. Sites involved include those operated by governments, universities and public agencies.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/"&gt;Nextgov/FCW reported in August&lt;/a&gt;⁠ that former officials and cybersecurity experts saw an increasing risk of unintended AI intrusions into federal systems. They cited aging technology, insufficient separation between networks and contractor connections as potential routes into systems the agents were never authorized to enter.&lt;/p&gt;

&lt;p&gt;The newly detailed U.S. activity does not establish that federal networks were breached. It offers a broader picture of how government websites can become caught up in AI experiments conducted outside their control, raising questions about developers&amp;rsquo; ability to contain agents pursuing routine tasks.&lt;/p&gt;

&lt;p&gt;The disclosures could also intensify debate over whether safeguards can keep pace with increasingly capable systems, amid concerns that similar failures could have more serious consequences for sensitive government networks or critical infrastructure.&lt;/p&gt;

&lt;p&gt;In Australia, officials revealed this week that an OpenAI agent &amp;mdash; autonomous software that uses an AI model to plan and complete tasks &amp;mdash; gained unauthorized access to a government health statistics portal in June.&lt;/p&gt;

&lt;p&gt;The agent was researching public medicine spending when it accessed infrastructure behind the Medicare Statistics Reporting Service portal,&lt;a href="https://www.minister.defence.gov.au/transcripts/2026-09-24/press-conference-sydney"&gt; government officials said Thursday&lt;/a&gt;⁠. After a request for information was denied, it circumvented the portal&amp;rsquo;s restrictions.&lt;/p&gt;

&lt;p&gt;Officials said the information involved aggregated statistics and that no individual medical records were accessed. The portal was separate from systems handling Medicare claims, payments and personal information.&lt;/p&gt;

&lt;p&gt;OpenAI discovered the June activity in August and notified Services Australia on Sept. 10. Prime Minister Anthony Albanese raised concerns directly with OpenAI CEO Sam Altman, and Australian officials announced a task force to examine the incident, government network security and whether existing laws adequately address such activity.&lt;/p&gt;

&lt;p&gt;OpenAI cautioned that its notifications should not automatically be interpreted as evidence of significant security incidents. Most cases identified so far were of low severity, with limited or no evidence of meaningful impact, it said.&lt;/p&gt;

&lt;p&gt;The company said some organizations may conclude the information accessed was intentionally public or the interaction was not concerning, while others may identify a weakness to address.&lt;/p&gt;

&lt;p&gt;The review follows OpenAI models&amp;rsquo; July breach of AI platform Hugging Face during an internal cybersecurity evaluation. The company has since broadened its investigation to examine agents&amp;rsquo; interactions with outside websites.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Most of the activity we&amp;rsquo;ve reviewed so far involved routine research tasks, such as accessing public web content to answer questions,&amp;rdquo; the OpenAI spokesperson said. &amp;ldquo;Some involved government websites because our models often turn to them as authoritative sources of public information.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;OpenAI said the review will take months to complete. It is sharing technical findings with affected organizations and generally leaving decisions about public disclosure to them.&lt;/p&gt;

&lt;p&gt;The company separately&lt;a href="https://openai.com/hugging-face-incident-and-misalignment/"&gt; disclosed Friday&lt;/a&gt;⁠ that research agents had transmitted training and evaluation data to outside services. It identified 53 instances in which user-provided images were posted to image-hosting sites through links that were not publicly listed. Most of that content has been removed, OpenAI said, and it is working with hosting providers to remove the rest.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/25/092526OpenAING/large.jpg" width="618" height="284"><media:credit>ANDREJ IVANOV / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/25/092526OpenAING/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senators propose voluntary telecom security framework after Salt Typhoon hacks</title><link>https://www.nextgov.com/cybersecurity/2026/09/senators-propose-voluntary-telecom-security-framework-after-salt-typhoon-hacks/416201/</link><description>The bipartisan bill would establish cybersecurity best practices and independent certification, following the FCC’s rollback of safeguards adopted in response to the Chinese hacking campaign.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 24 Sep 2026 14:46:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/senators-propose-voluntary-telecom-security-framework-after-salt-typhoon-hacks/416201/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Two Senate committee leaders introduced legislation Thursday to develop voluntary cybersecurity practices for telecommunications operators, renewing efforts to protect U.S. communications networks nearly two years after the Salt Typhoon espionage campaign became public.&lt;/p&gt;

&lt;p&gt;The &lt;a href="https://www.warner.senate.gov/newsroom/press-releases/in-response-to-extensive-salt-typhoon-hacks-warner-cruz-introduce-bipartisan-bill-to-strengthen-telecommunications-cybersecurity/?utm_source=chatgpt.com"&gt;Telecommunications Cybersecurity and Resilience Act&lt;/a&gt;, from Sens. Mark Warner, D-Va., and Ted Cruz, R-Texas, would bring government officials and industry representatives together to develop security guidance and establish a voluntary process for independently assessing companies&amp;rsquo; adoption of those practices. Warner is vice chairman of the Senate Intelligence Committee, while Cruz chairs the Senate Commerce Committee.&lt;/p&gt;

&lt;p&gt;The Chinese hackers compromised systems handling lawful surveillance requests as part of a broader campaign targeting communications providers and prominent political figures. The campaign has also &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/"&gt;spread worldwide&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Under the legislation, a working group within the Commerce Department&amp;rsquo;s National Telecommunications and Information Administration would develop telecom-specific best practices within 18 months of enactment. Its members would include providers, suppliers, cybersecurity experts and government agencies.&lt;a href="https://cyberscoop.com/senate-telecom-cybersecurity-resilience-act-salt-typhoon/"&gt; CyberScoop first reported&lt;/a&gt; the legislation.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Salt Typhoon intrusion was the worst telecom hack in our nation&amp;rsquo;s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,&amp;rdquo; Warner said in a statement.&lt;/p&gt;

&lt;p&gt;Cruz described the bill as a way to develop voluntary protections &amp;ldquo;rather than adopting rigid federal mandates that quickly become outdated.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The proposal comes after the Federal Communications Commission&lt;a href="https://www.nextgov.com/cybersecurity/2025/11/fcc-votes-reverse-telecom-security-rulemaking-issued-under-biden/409656/"&gt; reversed a Biden-era security measure&lt;/a&gt; last November that sought to protect telecom networks against unauthorized access to systems handling lawful surveillance requests.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In reversing the measure, FCC Chairman Brendan Carr argued that the commission had misinterpreted its legal authority and pointed to carriers&amp;rsquo; voluntary work to patch equipment, improve access controls and share threat information.&lt;/p&gt;

&lt;p&gt;Warner criticized that decision at the time, saying Carr had provided little detail about how voluntary efforts would prevent another compromise. The new legislation would establish a more defined process for developing and assessing those practices, while leaving participation voluntary.&lt;/p&gt;

&lt;p&gt;Congress has also struggled to obtain information about carriers&amp;rsquo; security weaknesses following the intrusions.&lt;/p&gt;

&lt;p&gt;Sen. Maria Cantwell, D-Wash., the Commerce Committee&amp;rsquo;s top Democrat,&lt;a href="https://www.nextgov.com/cybersecurity/2026/02/senator-says-t-and-verizon-blocked-release-salt-typhoon-security-reports/411172/"&gt; said in February&lt;/a&gt; that AT&amp;amp;T and Verizon had prevented cybersecurity firm Mandiant from providing network security assessments she requested. She had also called for the companies&amp;rsquo; chief executives to testify.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Nextgov/FCW&lt;/em&gt; &lt;a href="https://www.nextgov.com/cybersecurity/2026/02/senator-says-t-and-verizon-blocked-release-salt-typhoon-security-reports/411172/?utm_source=chatgpt.com"&gt;previously reported&lt;/a&gt; that incident response personnel at two major U.S. telecom operators were instructed by outside counsel not to look for evidence of Salt Typhoon, according to a person familiar with the matter. The person did not identify the companies.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The intelligence consequences may persist long after carriers secure their networks. FBI cyber intelligence official Michael Machtinger&lt;a href="https://www.nextgov.com/cybersecurity/2026/02/chinese-telecom-hackers-likely-holding-stolen-data-perpetuity-later-attempts-fbi-official-says/411528/"&gt; warned in February&lt;/a&gt; that Beijing could retain the stolen information indefinitely and combine it with other collected data for surveillance and future exploitation.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/24/092426CapitolNG/large.jpg" width="618" height="284"><media:credit>Li Xiang/Xinhua via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/24/092426CapitolNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA pledges election security support after cuts weakened ties with states</title><link>https://www.nextgov.com/cybersecurity/2026/09/cisa-pledges-election-security-support-after-cuts-weakened-ties-states/416194/</link><description>A new plan emphasizes threat sharing and coordination ahead of the midterms, but does not explain how those commitments fit with proposed cuts to dedicated election security funding.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 24 Sep 2026 14:14:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/cisa-pledges-election-security-support-after-cuts-weakened-ties-states/416194/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Cybersecurity and Infrastructure Security Agency is pledging to strengthen threat sharing and coordination with election officials ahead of the midterms, following administration cuts that state officials say weakened those relationships and their access to federal cybersecurity expertise.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://www.cisa.gov/sites/default/files/2026-09/2026-CISA-Election-Security-Plan-FINAL-508c.pdf"&gt; 2026 Election Infrastructure Security Plan&lt;/a&gt;, released Thursday, identifies CISA&amp;rsquo;s 10 regional directors as election security advisers and describes a free information-sharing platform connecting election officials, state intelligence hubs and federal partners.&lt;/p&gt;

&lt;p&gt;The document offers one of the clearest public accounts to date of how the second Trump administration intends to support election security. But its emphasis on sustained cooperation comes after staffing and program reductions disrupted the federal support network, and as the administration has proposed eliminating dedicated election security funding and adviser positions.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Election security is national security,&amp;rdquo; Homeland Security Secretary Markwayne Mullin said in a statement announcing the plan, adding that it &amp;ldquo;will be implemented in full.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The document does not specify how many employees will carry out the work, announce the restoration of dedicated election adviser positions or identify funding for the effort. It also doesn&amp;rsquo;t explain how its commitments fit with the administration&amp;rsquo;s&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/trump-proposes-cutting-cisa-election-security-program-fy27-budget/412672/"&gt; fiscal 2027 budget proposal&lt;/a&gt;, which would eliminate CISA&amp;rsquo;s election security program, including information-sharing support for states. Those proposed funding changes require congressional approval.&lt;/p&gt;

&lt;p&gt;State officials have described the consequences of earlier reductions. Michigan Deputy Secretary of State Aghogho Edevbie&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/federal-drawdown-election-support-destroyed-ongoing-relationships-experts-say/413181/"&gt; told lawmakers in April&lt;/a&gt; that local election officials had lost contact with CISA personnel they previously relied on.&lt;/p&gt;

&lt;p&gt;Under the arrangement described in the plan, regional directors will oversee election support while cybersecurity advisers and protective security advisers provide technical guidance and assess risks to facilities. Election officials can request assistance through CISA&amp;rsquo;s regional offices. State and regional fusion centers &amp;mdash; which bring together law enforcement and other government partners to share threat information &amp;mdash; are identified as a key channel for election intelligence.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Threats to elections can range from cyberattacks that disrupt voter registration systems to threats against poll workers to foreign influence campaigns that spread false information to mislead voters or undermine trust in the results.&lt;/p&gt;

&lt;p&gt;CISA also says it is supporting a platform through which election officials can receive threat indicators, ask questions and coordinate with federal partners in near real time. All fusion centers and state and local election officials will have access at no cost, according to the plan.&lt;/p&gt;

&lt;p&gt;The agency says the model was used during the 2026 World Cup, though it does not identify the platform, specify when officials can enroll or describe its staffing and operating hours.&lt;/p&gt;

&lt;p&gt;The document also does not name the Elections Infrastructure Information Sharing and Analysis Center, which has historically been a key hub for election threat information that previously received CISA support.&lt;/p&gt;

&lt;p&gt;Acting CISA Director Nick Andersen previewed the &lt;a href="https://subscriber.politicopro.com/article/2026/09/cisa-to-relaunch-election-security-efforts-ahead-of-midterms-01080059"&gt;broader approach&lt;/a&gt; in remarks to reporters earlier this month, saying the agency would build on coordination with state and local officials during America 250 events and the World Cup as it prepared for the midterms.&lt;/p&gt;

&lt;p&gt;The plan also describes how federal intelligence will reach election officials. CISA says it works with the FBI and DHS&amp;rsquo;s Office of Intelligence and Analysis to provide threat reporting through fusion centers and with the Office of the Director of National Intelligence on monthly classified briefings for critical infrastructure stakeholders.&lt;/p&gt;

&lt;p&gt;Those briefings reach more than 70 secure locations nationwide and are accompanied by unclassified notes and mitigation recommendations. The plan does not specify how frequently election-specific briefings will occur.&lt;/p&gt;

&lt;p&gt;The commitments come as recent reporting points to a narrower role for public warnings about foreign election threats.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://therecord.media/trump-harris-election-meddling-russia"&gt;The Record reported Wednesday&lt;/a&gt; that the administration recently delivered an overdue assessment of foreign threats to the midterms and briefed lawmakers and congressional staff. Officials indicated they would produce two more classified reports before the election but would not issue additional declassified information or public warnings,&amp;nbsp;a departure from the frequent public updates federal agencies provided in 2024, according to the outlet.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.nytimes.com/2026/09/18/us/politics/russia-election-disinformation-us-intelligence.html"&gt;The New York Times reported last week&lt;/a&gt; that classified intelligence assessments found Russia was conducting covert online operations to undermine confidence in the midterms and deepen political divisions. Officials told the newspaper the assessments did not find evidence of attempts to compromise voting machinery in ways that would affect the voting process.&lt;/p&gt;

&lt;p&gt;ODNI in May&lt;a href="https://www.nextgov.com/defense/2026/05/odni-assigns-two-officials-lead-intelligence-coordination-election-threats/413567/"&gt; assigned two officials&lt;/a&gt; to coordinate election-threat intelligence after shifting many of its Foreign Malign Influence Center&amp;rsquo;s responsibilities to other offices.&lt;/p&gt;

&lt;p&gt;The new plan also unfolds against years of conflict between President Donald Trump and CISA, dating to the agency&amp;rsquo;s affirmation of the security of the 2020 election and its rejection of his false claims that the race was stolen from him.&lt;/p&gt;

&lt;p&gt;The administration&amp;rsquo;s handling of election intelligence has added to those tensions. In July, Trump used newly declassified records about China&amp;rsquo;s possession and analysis of U.S. voter data to revive claims about the 2020 election. But&lt;a href="https://www.nextgov.com/cybersecurity/2026/07/trump-stretches-declassified-china-intelligence-broader-2020-election-claims/414837/"&gt; a review&lt;/a&gt; found the documents did not establish that Beijing altered ballots, manipulated voting systems or changed the election&amp;rsquo;s outcome.&lt;/p&gt;

&lt;p&gt;Separately, executives at Mojave Research&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/voting-machine-researchers-say-federal-work-abruptly-ended-after-trump-ally-pushed-back-their-findings/415300/"&gt; said in August&lt;/a&gt; that their federal voting-system research ended after they identified serious security weaknesses in machines used in Puerto Rico in 2024 but found no evidence of exploitation or altered votes. The executives linked resistance to their work to Trump adviser Kurt Olsen and pressure to substantiate claims of election manipulation.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/24/092426votingNG/large.jpg" width="618" height="284"><media:credit>Mehmet Eser/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/24/092426votingNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI scanning tools found security gaps at rail operator and hospitals, Wiz says</title><link>https://www.nextgov.com/cybersecurity/2026/09/ai-scanning-tools-found-security-gaps-rail-operator-and-hospitals-wiz-says/416181/</link><description>Researchers discovered access to rail administration systems, a hospital alert channel and sensitive records in a new effort aimed at organizations with limited cyber resources.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 24 Sep 2026 09:00:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/ai-scanning-tools-found-security-gaps-rail-operator-and-hospitals-wiz-says/416181/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Artificial intelligence-enabled security testing tools developed by Google-owned cybersecurity company Wiz uncovered weaknesses that exposed a public rail operator&amp;rsquo;s administrative systems and gave outsiders a way to control a public hospital&amp;rsquo;s mobile alert channel, the company said Thursday.&lt;/p&gt;

&lt;p&gt;At the rail operator, a leaked database exposed active administrator sessions, enabling access to routes, schedules, service announcements and management accounts. Researchers worked with the operator to secure the system &amp;ldquo;before public transportation could be disrupted,&amp;rdquo; Wiz officials said.&lt;/p&gt;

&lt;p&gt;At the hospital, missing access restrictions exposed staff contact information and allowed anyone online to control a systemwide mobile alert channel. Additionally, a separate private hospital&amp;rsquo;s appointment-booking website contained an unsafe file-upload feature that enabled control of a server and exposed patient identifiers, clinical information and consent signatures.&lt;/p&gt;

&lt;p&gt;The findings are among the early results of the firm&amp;rsquo;s new Scan for Good initiative that pairs AI tools with in-person researchers to identify and help fix security weaknesses affecting public services, critical infrastructure and nonprofits. Wiz says the effort has helped organizations fix hundreds of exposures and that humans were involved in validating their impact and privately notifying affected groups.&lt;/p&gt;

&lt;p&gt;The cases show how digital weaknesses in public-facing websites and applications can open a path to sensitive systems, and how AI tools can help rapidly identify those entry points. Several involved exposed credentials or missing permission checks that allowed researchers to gain broader access without discovering a previously unknown software flaw.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;They also underscore how fast evolving cyber-focused AI tools can benefit defenders and attackers alike. Access to these systems in the wrong hands could have allowed cyber intruders to steal patient records, send false hospital alerts or alter transit service information.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Both of those domains have been real-world cyber victims. A May 2024 &lt;a href="https://www.hipaajournal.com/ascension-cyberattack-2024/"&gt;hack&lt;/a&gt; on the Ascension health system disrupted access to electronic patient records and forced some hospitals to divert ambulances. Last year, a &lt;a href="https://www.kyivpost.com/post/49656"&gt;Russian cyberattack&lt;/a&gt; knocked Ukraine&amp;rsquo;s state railway ticketing system offline.&lt;/p&gt;

&lt;p&gt;Wiz did not identify the affected rail operator, hospitals or other organizations described in its release that outlined Scan for Good&amp;rsquo;s early testing results. The company-described exposures have been addressed and did not say those openings were leveraged by hackers.&lt;/p&gt;

&lt;p&gt;Other discoveries involved sensitive government records, in which a municipal data service exposed personal, health and financial information from about roughly 5,000 elderly residents. In another case, an exposed administrator key also permitted reading, modifying and deleting 8.8 million files in a national archive in an unnamed Middle Eastern country.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The company also uncovered risks at technology providers whose products support other organizations. At one cloud provider, a credential exposed in public website code could have allowed hackers to publish malicious software across more than 500 production container images supporting a flagship AI service, Wiz said without naming the entities involved.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Historically, finding and understanding these paths at scale required significant time, expertise, and manual investigation,&amp;rdquo; said Wiz executives Ami Luttwak and Gal Nagli. &amp;ldquo;AI is changing that, making it dramatically easier to discover exposed systems, understand how they behave, and connect weaknesses into real attack paths.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Scan for Good uses Wiz&amp;rsquo;s &amp;ldquo;Red Agent&amp;rdquo; penetration-testing tool and other internal research capabilities backed by Google DeepMind&amp;rsquo;s Gemini models. Google completed its acquisition of Wiz in March, bringing the company into Google Cloud. DeepMind has separately launched &lt;a href="https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/"&gt;Fairwind&lt;/a&gt;, which provides select groups, including governments and healthcare providers, early access to advanced cyber models.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Fairwind comes after Anthropic earlier this year launched &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/anthropics-glasswing-initiative-raises-questions-us-cyber-operations/412721/"&gt;Project Glasswing&lt;/a&gt;, giving selected companies and developers access to its restricted Mythos model to find and fix software vulnerabilities before similar capabilities became widely available. What followed was a federal push to assess advanced models&amp;rsquo; hacking capabilities and expand their use for cyberdefense.&lt;/p&gt;

&lt;p&gt;Wiz said the Cybersecurity and Infrastructure Security Agency also provided collaboration and guidance on its Scan for Good initiative, without detailing the agency&amp;rsquo;s operational role. &lt;em&gt;Nextgov/FCW&lt;/em&gt; has asked Wiz and CISA for more details on the agency&amp;rsquo;s involvement.&lt;/p&gt;

&lt;p&gt;The launch of Mythos has intensified efforts by global governments and technology companies to assess AI&amp;rsquo;s hacking capabilities and give defenders access to tools that could also help attackers break into sensitive systems.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In recent weeks, concerns about losing control of advanced AI tools have &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/09/hawley-launches-committee-investigation-openais-breach-hugging-face/415910/"&gt;gained urgency&lt;/a&gt; following disclosures that some models took unauthorized actions on real computer systems during testing. Australian Prime Minister Anthony Albanese &lt;a href="https://www.politico.com/news/2026/09/23/openai-australia-government-breach-01091069?utm_source=dlvr.it&amp;amp;utm_medium=twitter"&gt;disclosed Wednesday&lt;/a&gt; that an OpenAI agent gained unauthorized access to a government health statistics portal in June.&lt;/p&gt;

&lt;p&gt;A June &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/06/trump-signs-ai-executive-order-after-postponement-last-month/413912/"&gt;executive order&lt;/a&gt; directed federal agencies to expand access to AI cybersecurity tools for state and local governments and critical infrastructure operators, including rural hospitals and local utilities. It also called for classified assessments of advanced models&amp;rsquo; hacking capabilities and a voluntary process for developers to provide government access before releasing them to other trusted partners.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;U.S. spy agencies are pursuing their &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/04/cia-plans-ai-coworkers-deputy-director-says/412744/"&gt;own uses for AI&lt;/a&gt;, including for offensive cyber operations, network defense scanning, data analysis and intelligence report creation, among other cases.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/23/GettyImages_1221311412/large.jpg" width="618" height="284"><media:credit>bjdlzx/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/23/GettyImages_1221311412/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Stolen FBI data reveals employees’ roles in intelligence and surveillance</title><link>https://www.nextgov.com/cybersecurity/2026/09/stolen-fbi-data-reveals-employees-roles-intelligence-and-surveillance/416182/</link><description>Exposed analysts work on areas including China, Russia and electronic surveillance. ShinyHunters claimed responsibility for the breach this week. The FBI said it’s investigating.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 23 Sep 2026 23:33:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/stolen-fbi-data-reveals-employees-roles-intelligence-and-surveillance/416182/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Data stolen in a major hacking group&amp;rsquo;s alleged intrusion into FBI systems is believed to contain personal information on hundreds of FBI intelligence analysts and other employees involved in clandestine intelligence-gathering and surveillance, according to two people familiar with the matter.&lt;/p&gt;

&lt;p&gt;The analysts focus on myriad subject areas like Russia, China, Hezbollah and cartel-related intelligence, said the people, who spoke on the condition of anonymity because the exposures are sensitive. The employees&amp;rsquo; roles only offer a small picture of their duties, but may still help outsiders identify people working in sensitive parts of the bureau.&lt;/p&gt;

&lt;p&gt;ShinyHunters claimed responsibility for the breach Monday, threatening to release what it described as two to three terabytes of FBI employee data unless the bureau retracted a public warning about its tactics within a week.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;On Tuesday, the group &lt;a href="https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/?oref=ng-author-river"&gt;sent &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt;&lt;em&gt; &lt;/em&gt;and other news outlets an apparent sample of that data containing roughly 5,000 entries listing employees&amp;rsquo; names, home addresses, phone numbers and information about their spouses and siblings.&lt;/p&gt;

&lt;p&gt;Multiple individuals also work on human intelligence-gathering, as well as roles involving electronic surveillance activities that make use of &lt;a href="https://www.fcc.gov/calea"&gt;telecom interception techniques&lt;/a&gt; and other covert access mechanisms. Some employees work in the FBI&amp;rsquo;s Remote Operations Unit, which builds specialized tools to target computers and networks.&lt;/p&gt;

&lt;p&gt;One person works in the bureau&amp;rsquo;s FISA Management Unit, which handles the processing of applications and renewals under the Foreign Intelligence Surveillance Act that governs &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/fbi-queries-americans-data-under-fisa-702-rose-35-2025/412103/"&gt;surveillance and search&lt;/a&gt; standards used to collect foreign intelligence.&lt;/p&gt;

&lt;p&gt;The FBI said it was aware of &amp;ldquo;a cyber-criminal enterprise group claiming a compromise of the FBIJobs.gov portal and alleged impact to FBI employee personally identifiable information&amp;rdquo; and added that it is investigating the matter.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The agency said the cause of the breach was still undetermined. ShinyHunters previously said it exploited vulnerabilities in Amazon and Oracle services to access the bureau data. Neither company has returned a request for comment.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.reuters.com/world/hacked-fbi-data-has-sensitive-information-about-employees-intelligence-roles-2026-09-23/"&gt;Reuters&lt;/a&gt; and &lt;a href="https://www.404media.co/fbi-hack-exposed-fbis-own-hacking-unit-remote-operations-shinyhunters/"&gt;404 Media&lt;/a&gt; previously reported details regarding the intelligence roles and the ROU staff.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The language ShinyHunters wants removed appears in a May 15 &lt;a href="https://www.ic3.gov/PSA/2026/PSA260515"&gt;FBI public service announcement&lt;/a&gt; that describes practices the hacking group contests. The group has built a global reputation for various hacking achievements. In May, it claimed responsibility for &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/canvas-breach-spotlights-cybercriminal-appetite-student-data/413451/"&gt;accessing Canvas&lt;/a&gt;, the popular education tech platform used by thousands of U.S. institutions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The direct claim of an FBI breach is &amp;ldquo;an unusually provocative move&amp;rdquo; and should be taken seriously, said Etay Maor, the vice president of threat intelligence at Cato Networks.&lt;/p&gt;

&lt;p&gt;Exposure of sensitive bureau staffing data could pose profound counterintelligence risks. For employees who do not publicly identify themselves as working for the FBI, the exposure could reveal both their jobs and how to reach them outside secure work environments. Linking that information to home addresses and relatives&amp;rsquo; details could make it easier for nation-state groups and cyber criminals to target employees and their families with harassment, scams or threats.&lt;/p&gt;

&lt;p&gt;The breach would be &amp;ldquo;troubling news&amp;rdquo; for both FBI employees and applicants, said Doc McConnell, a former cyber policy official at the White House and the Cybersecurity and Infrastructure Security Agency.&lt;/p&gt;

&lt;p&gt;McConnell, who now heads policy and compliance at Finite State, compared the incident to the &lt;a href="https://www.govexec.com/management/2026/05/10-years-after-opm-breach-identity-protection-services-affected-feds-expire/413336/"&gt;OPM hack a decade ago&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The breach of OPM&amp;rsquo;s personnel records in 2015 resulted in a decade of credit monitoring for millions of affected individuals, and the full counterintelligence impact will likely never be known. This breach appears to contain similar data, creating potential security concerns for the victims if it is made publicly available,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The bureau will likely work more assertively to crack down on ShinyHunters. When any group directly targets the agency, &amp;ldquo;they should expect that the FBI is going to marshal additional resources to bring them more quickly to justice,&amp;rdquo; said Cynthia Kaiser, the SVP of Halcyon&amp;rsquo;s Ransomware Research Center and former deputy director of the FBI&amp;rsquo;s Cyber Division.&lt;/p&gt;

&lt;p&gt;The incident follows other cyberattacks involving the bureau and its leadership this year. In March, pro-Iran hacking group Handala &lt;a href="https://www.defenseone.com/threats/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412464/"&gt;published material&lt;/a&gt; from FBI Director Kash Patel&amp;rsquo;s personal email account, which the bureau said contained historical information unrelated to government business. Separately, a suspected China-linked &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/suspected-chinese-breach-fbi-system-exposed-surveillance-targets-phone-numbers/412612/"&gt;intrusion&lt;/a&gt; into an FBI system exposed surveillance targets&amp;rsquo; phone numbers.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/23/GettyImages_2288940584/large.jpg" width="618" height="284"><media:credit>Kevin Carter / Contributor / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/23/GettyImages_2288940584/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>ShinyHunters claims FBI data theft, demands bureau retract cyber warning</title><link>https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/</link><description>The hacking group says it obtained sensitive employee and applicant records. The full scope of the claimed breach remains unclear.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 22 Sep 2026 15:09:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/shinyhunters-claims-fbi-data-theft-demands-bureau-retract-cyber-warning/416144/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The ShinyHunters cybercriminal group claims it has stolen sensitive information about FBI employees and job applicants and is demanding that the bureau retract a public warning about its tactics within a week.&lt;/p&gt;

&lt;p&gt;The demand, addressed to FBI Director Kash Patel and Cyber Division Assistant Director Brett Leatherman, seeks to pressure the agency into changing its public account of the group&amp;rsquo;s activities. The group claims the effort was not financially motivated.&lt;/p&gt;

&lt;p&gt;In a statement attributed to the group, the hackers claimed access to several FBI services, including human resources systems and a service identified as Medlink.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,&amp;rdquo; the &lt;a href="https://x.com/DarkWebInformer/status/2102449668449882464"&gt;statement says&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;An FBI jobs page also displayed a &amp;ldquo;Scheduled Maintenance Underway&amp;rdquo; notice Tuesday, saying the site was temporarily unavailable. The notice did not identify a security incident or explain whether the outage was related to the hackers&amp;rsquo; claims. An earlier version of the webpage appears to show a &lt;a href="https://x.com/kevvOH_/status/2102451016956313609/photo/1"&gt;seizure notice&lt;/a&gt; posted by the group.&lt;/p&gt;

&lt;p&gt;The language ShinyHunters wants removed appears in a&lt;a href="https://www.ic3.gov/PSA/2026/PSA260515"&gt; May 15 FBI public service announcement&lt;/a&gt; issued after an attack disrupted an online learning management system used by educational institutions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In the announcement, the FBI warned that ShinyHunters uses harassment to pressure victims, including threatening communications to victims and family members and, in some cases, swatting, the practice of calling in false emergency reports intended to trigger an armed police response at someone&amp;rsquo;s home. The alert also warned that attackers may exaggerate their access to personal information or falsely claim to possess compromising photographs or videos.&lt;/p&gt;

&lt;p&gt;ShinyHunters denied those practices in its statement and gave the bureau one week to correct or remove the warning.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,&amp;rdquo; the bureau said in a statement after this story was published. &lt;em&gt;Nextgov/FCW&lt;/em&gt; has also reached out to the FBI Agents Association, which advocates on behalf of active and retired FBI special agents.&lt;/p&gt;

&lt;p&gt;If the claimed employee records are authentic, their exposure could give criminals or foreign intelligence services information useful for identifying, contacting or intimidating FBI personnel and their families.&lt;/p&gt;

&lt;p&gt;The claims come as the FBI works to pursue a more coordinated campaign focused on dismantling hackers&amp;rsquo; infrastructure and arresting cybercrime operatives. Its &lt;a href="https://www.nextgov.com/cybersecurity/2026/09/new-fbi-cyber-strategy-seeks-faster-action-against-hackers-larger-industry-role/415869/"&gt;new cyber strategy&lt;/a&gt; released this month in part emphasizes disrupting criminal hackers even when those responsible remain beyond the immediate reach of U.S. law enforcement.&lt;/p&gt;

&lt;p&gt;A ShinyHunters representative sent &lt;em&gt;Nextgov/FCW&lt;/em&gt; a text file appearing to contain sensitive personal information on nearly 5,000 FBI employees, including their names, home addresses, phone numbers, and data about their spouses and siblings. &lt;em&gt;Nextgov/FCW&lt;/em&gt; queried some of the listed peoples&amp;rsquo; names online and found that they are employed with the FBI. The job postings in the data included employees designated as intelligence analysts, attorneys, student trainees and special agents, among other roles. The entire data set was not verified.&lt;/p&gt;

&lt;p&gt;A representative told 404 Media, which &lt;a href="https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees/"&gt;earlier reported&lt;/a&gt; the incident Tuesday, that the hackers gained access Monday night through what they described as a previously unknown vulnerability in Oracle&amp;rsquo;s PeopleSoft software, then accessed servers in Amazon Web Services&amp;rsquo; GovCloud environment. The representative claimed the group took between two and three terabytes of data.&lt;/p&gt;

&lt;p&gt;The account of the intrusion has not been independently verified. &lt;em&gt;Nextgov/FCW&lt;/em&gt; has asked Oracle and AWS for comment.&lt;/p&gt;

&lt;p&gt;Cybersecurity specialists should focus on the group&amp;rsquo;s claims regarding an exploit in the PeopleSoft platform because it could be used more broadly to breach other systems, said Dan Calderone, the chief technology officer at cybersecurity and AI firm Suzu Labs.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;They also say this isn&amp;#39;t financially motivated, but I&amp;rsquo;d take that with a grain of salt. I have a hard time believing terabytes of FBI personnel data just sit on a shelf,&amp;rdquo; Calderone said. &amp;ldquo;Foreign intelligence services would love to have it, and having the FBI on their resume makes every future extortion demand more believable, and if the PeopleSoft zero-day is real, the exploit may be worth more than the data.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;On top of that, FBI agents and their spouses &amp;ldquo;could have their home addresses posted publicly within a week if this threat is followed through,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Editor&amp;rsquo;s Note: This story was updated to include a statement from the FBI, remarks from Dan Calderone and additional details about the data &lt;/em&gt;allegedly&lt;em&gt; accessed by ShinyHunters.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/22/GettyImages_2215473392/large.jpg" width="618" height="284"><media:credit>Anna Moneymaker/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/22/GettyImages_2215473392/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI agents are getting better at cybersecurity. That cuts both ways.</title><link>https://www.nextgov.com/cybersecurity/2026/09/ai-agents-are-getting-better-cybersecurity-cuts-both-ways/416025/</link><description>NIST is testing agentic AI to help enrich the National Vulnerability Database, even as increasingly capable models demonstrate why cyber autonomy needs careful containment.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">John Breeden II</dc:creator><pubDate>Wed, 16 Sep 2026 14:41:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/ai-agents-are-getting-better-cybersecurity-cuts-both-ways/416025/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Cybersecurity researchers have spent decades building sandboxes and isolated test environments where they can safely unleash malware, probe vulnerabilities and generally do things that would be extremely dangerous on the open internet. But artificial intelligence is beginning to complicate that arrangement.&lt;/p&gt;

&lt;p&gt;In July, OpenAI disclosed that several of its AI models had circumvented controls designed to isolate them from the internet during cybersecurity evaluations. Operating with reduced safeguards, the models exploited vulnerabilities, established unauthorized communications, reached the internet and &lt;a href="https://www.darkreading.com/cyber-risk/openai-models-autonomously-hack-hugging-face"&gt;ultimately compromised&lt;/a&gt; parts of Hugging Face&amp;rsquo;s systems, meaning they had crossed from OpenAI&amp;rsquo;s controlled research environment into infrastructure operated by a separate AI company.&lt;/p&gt;

&lt;p&gt;There are some important qualifications. These were cybersecurity evaluations specifically designed to test offensive capabilities, and the models were operating under reduced safeguards. They did not simply wake up one morning and decide to go hunting for vulnerable websites. But the fact that increasingly capable agents can find ways beyond their intended boundaries creates an interesting new cybersecurity problem.&lt;/p&gt;

&lt;p&gt;The OpenAI incident also prompted Anthropic to take a much closer look at its own testing. After reviewing 141,006 cybersecurity evaluation runs, the company &lt;a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"&gt;found three incidents&lt;/a&gt; in which Claude models had reached the internet and gained unauthorized access to real systems belonging to three organizations.&lt;/p&gt;

&lt;p&gt;Those incidents were different from the OpenAI case. Anthropic said a misconfiguration in a third-party evaluation environment had unintentionally provided internet access even though the models had been told they were operating inside a simulation. The models then treated real systems as part of their assigned cybersecurity exercises. Anthropic said its most recent research model eventually recognized that it had reached a real system and stopped attacking it on its own.&lt;/p&gt;

&lt;p&gt;Meta subsequently reported &lt;a href="https://www.darkreading.com/cyberattacks-data-breaches/meta-ai-escapes-lab-hacking-joyride"&gt;another incident&lt;/a&gt; involving a pre-release version of its Muse Spark 1.1 model. In that case, a third-party evaluator inadvertently gave the model internet access and identified a real website as the target of what was supposed to be a fictional exercise. The model found and exploited a vulnerability within the real site.&lt;/p&gt;

&lt;p&gt;Meta specifically said the incident was not a sandbox escape or sophisticated offensive cyberattack. It was a testing and configuration failure. But the company also noted that as models become more capable of finding and exploiting vulnerabilities, the environments used to test them will require correspondingly stronger containment.&lt;/p&gt;

&lt;p&gt;Taken together, those incidents demonstrate a cybersecurity challenge that barely existed a few years ago. Increasingly autonomous AI systems can now search for vulnerabilities, exploit them and take actions that extend beyond the environments in which researchers intended them to operate. Even when that behavior results from testing conditions or configuration failures rather than malicious intent, it shows how quickly agentic AI is changing the vulnerability landscape.&lt;/p&gt;

&lt;p&gt;And that is where NIST&amp;rsquo;s latest work becomes especially interesting. Faced with a rapidly growing flood of vulnerabilities, including some that AI systems themselves may help discover or exploit, the agency is turning to agentic AI as part of the defense. NIST is developing an AI agent workflow designed to help enrich vulnerability information, putting some of the same autonomous capabilities that are creating new cybersecurity challenges to work helping defenders keep pace.&lt;/p&gt;

&lt;p&gt;NIST&amp;rsquo;s &lt;a href="https://nvd.nist.gov/"&gt;National Vulnerability Database&lt;/a&gt;, or NVD, acts as the U.S. government repository for standards-based vulnerability management data. The database enriches publicly disclosed vulnerability records with information such as severity scores, affected products and other metadata used by cybersecurity professionals, automated security tools and organizations trying to decide which vulnerabilities pose the greatest risk.&lt;/p&gt;

&lt;p&gt;The NVD is a very important tool, but keeping its information current is getting considerably harder. NIST reported in April that submissions of Common Vulnerabilities and Exposures, or CVEs, &lt;a href="https://www.nist.gov/news-events/news/2026/04/nist-updates-nvd-operations-address-record-cve-growth"&gt;increased 263%&lt;/a&gt; between 2020 and 2025. Submissions during the first three months of 2026 were nearly one-third higher than during the same period a year earlier.&lt;/p&gt;

&lt;p&gt;NIST itself was working faster. It enriched nearly 42,000 CVEs in 2025, 45% more than in any previous year. But the agency acknowledged that even that increased productivity was not enough to keep up with the growing volume. NIST consequently shifted to a &lt;a href="https://www.nist.gov/news-events/events/2026/09/itl-ai-webinar-development-ai-agent-enrichment-workflow-national"&gt;risk-based approach&lt;/a&gt; that gives enrichment priority to vulnerabilities known to be exploited, vulnerabilities affecting software used by the federal government and vulnerabilities involving critical software.&lt;/p&gt;

&lt;p&gt;NIST computer scientist Harold Booth and Jon Boyens of the agency&amp;rsquo;s Computer Security Division addressed that changing environment in an August blog about modernizing the NVD.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This is an &amp;lsquo;all hands-on deck&amp;rsquo; moment for this community,&amp;rdquo; they wrote.&lt;/p&gt;

&lt;p&gt;NIST has already begun developing a tool &lt;a href="https://www.nist.gov/blogs/cybersecurity-insights/shaping-nvd-future-we-need-your-feedback-ai-enabled-vulnerability"&gt;called V-etalon&lt;/a&gt; that uses AI technologies to help enrich vulnerability information. The agency hopes the project can eventually provide a foundation for evaluating vulnerability information and plans to seek outside feedback and collaboration as the work progresses.&lt;/p&gt;

&lt;p&gt;And later this month, NIST plans to provide a closer look at its use of agentic AI for NVD enrichment. On Sept. 17, the agency&amp;#39;s Information Technology Laboratory AI Program will host &lt;a href="https://www.nist.gov/news-events/events/2026/09/itl-ai-webinar-development-ai-agent-enrichment-workflow-national"&gt;a virtual webinar&lt;/a&gt; about the development of an AI agent enrichment workflow for the NVD. NIST says the presentation will cover the approach and architecture behind the system, problems discovered during implementation and early results from using the tool with the NVD. The webinar is scheduled for 11 a.m. to noon Eastern and is &lt;a href="https://events.zoomgov.com/ev/AhBf95scsDeRYu9Pp9mPV-kGWaW8BUAikJKeWAn3Uj6SrWdZQlsJ~Ap-7vHHI0vVxD3BCMEWXeGaxVbnCj3M4C7mPeov81Wb1zZmGzJi5aQc97w"&gt;open for registration&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;There is another way for cybersecurity professionals, researchers, government officials and software vendors to get involved. NIST has issued a &lt;a href="https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of"&gt;request for information&lt;/a&gt; seeking input on the future of the NVD, including vulnerability management, risk prioritization, remediation, vulnerability data and standards and development processes. &amp;ldquo;Your voice matters,&amp;rdquo; Booth and Boyens wrote.&lt;/p&gt;

&lt;p&gt;Comments are due by 11:59 p.m. Eastern on Oct. 13. NIST says the responses may help shape future tools, technical architecture, standards, best practices and data governance.&lt;/p&gt;

&lt;p&gt;There is an interesting symmetry in all of this. More capable AI systems can discover and potentially exploit vulnerabilities faster, adding new pressure to an already rapidly expanding vulnerability-management ecosystem. At the same time, NIST is exploring whether some of that same autonomy can help the NVD enrich vulnerability information more effectively.&lt;/p&gt;

&lt;p&gt;How well that works is still an open question. But over the next several weeks, NIST is giving the cybersecurity community two opportunities to watch the experiment unfold and help shape what comes next.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;John Breeden II is an award-winning journalist and reviewer with over 20 years of experience covering technology. He is the CEO of the &lt;/em&gt;&lt;a href="https://techwritersbureau.com/"&gt;&lt;em&gt;Tech Writers Bureau&lt;/em&gt;&lt;/a&gt;&lt;em&gt;, a group that creates technological thought leadership content for organizations of all sizes. Twitter: @LabGuys&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/16/GettyImages_2229245475/large.jpg" width="618" height="284"><media:credit>Sarayut Thaneerat/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/16/GettyImages_2229245475/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CIA feared terrorists could exploit Y2K glitches, declassified briefs show</title><link>https://www.nextgov.com/cybersecurity/2026/09/cia-feared-terrorists-could-exploit-y2k-glitches-declassified-briefs-show/415945/</link><description>Records released for the 25th anniversary of 9/11 also describe intelligence assessments of extremist websites helping recruit fighters and spread chemical and biological weapons information.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 11 Sep 2026 13:37:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/cia-feared-terrorists-could-exploit-y2k-glitches-declassified-briefs-show/415945/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Newly declassified CIA records detail how analysts viewed emerging technology threats before 9/11, from fears that terrorists could exploit Y2K computer glitches to assessments that extremist websites were helping recruit fighters.&lt;/p&gt;

&lt;p&gt;The CIA&lt;a href="https://www.cia.gov/stories/story/cia-releases-presidents-daily-briefs-in-commemoration-of-the-25th-anniversary-of-9-11/"&gt; released the records&lt;/a&gt; &amp;mdash; President&amp;rsquo;s Daily Brief assessments prepared for the president and senior advisers &amp;mdash; to mark the 25th anniversary of the Sept. 11, 2001 attacks. The collection also includes assessments describing how militants used the internet to circulate chemical and biological weapons information.&lt;/p&gt;

&lt;p&gt;In a&lt;a href="https://www.cia.gov/static/12-30-1999-Terrorism-Near-Term-Threat-Undiminished.pdf"&gt; Dec. 30, 1999, assessment&lt;/a&gt; issued during President Bill Clinton&amp;rsquo;s administration, analysts warned that computer failures accompanying the new year could create opportunities for terrorists.&lt;/p&gt;

&lt;p&gt;The fears around a mass Y2K problem stemmed from computer systems that recorded years using two digits, raising concerns that they &amp;mdash; and the many crucial parts of American life they underpinned &amp;mdash; would misinterpret the transition from 1999 to 2000 and malfunction. The CIA&amp;rsquo;s assessment anticipated that such disruptions could create opportunities for attackers. The agency did not identify a specific hacking operation or establish that one occurred.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Computer degradations due to Y2K glitches are likely to facilitate opportunistic attacks by groups or individuals, including hackers who may be affiliated with terrorist organizations,&amp;rdquo; the assessment said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Bin Ladin affiliates arrested this month in Pakistan, for instance, are linked to the extremist Muslim Hackers Club,&amp;rdquo; it added, using an alternate spelling of the al Qaeda leader&amp;rsquo;s name. Multiple U.S. agencies had &lt;a href="https://www.newsweek.com/islamic-cyberterror-145381"&gt;issued warnings&lt;/a&gt; about the hacking group in the months following the 9/11 attacks.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The assessment&amp;rsquo;s findings came amid heightened concern about attacks surrounding millennium celebrations. Authorities that month arrested Ahmed Ressam while he was bringing explosives into the United States from Canada, disrupting a plot to bomb Los Angeles International Airport, according to the&lt;a href="https://govinfo.library.unt.edu/911/report/911Report_Ch6.htm"&gt; 9/11 Commission Report&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The commission&amp;rsquo;s 2004 findings also noted that officials had feared terrorists would take advantage of Y2K breakdowns. The newly released record provides a specific example of that concern, including the alleged hacker connections. Its unredacted text does not explain the nature of those links or the group&amp;rsquo;s cyber capabilities.&lt;/p&gt;

&lt;p&gt;By August 2000, analysts were describing how extremist websites were helping draw recruits into a network that bin Laden could tap for terrorist operations.&lt;/p&gt;

&lt;p&gt;The releases, while they appear to not contain revolutionary new findings, highlight how U.S. spies were assessing how the then-emerging digital age would augment terrorist groups&amp;rsquo; ability to recruit followers, share information and possibly plan digital attacks.&lt;/p&gt;

&lt;p&gt;The documents also offer a glimpse of how intelligence judgments were presented to the White House at the time. The released passages generally do not assign explicit confidence levels to their conclusions, unlike many intelligence assessments produced today that use them to convey how strongly the available evidence supports analysts&amp;rsquo; judgments. Redactions further limit what the public can determine about the sources behind those findings.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The products trace the story of CIA analysts&amp;rsquo; evolving understanding of al-Qa&amp;#39;ida and efforts to highlight and warn of Usama Bin Ladin&amp;rsquo;s attack plotting despite sparse, vague, and imperfect information,&amp;rdquo; the agency said in a statement.&lt;/p&gt;

&lt;p&gt;The assessments from that time also examine how conflict elsewhere in the world was driving resources to al Qaeda.&lt;/p&gt;

&lt;p&gt;Chechnya, a predominantly Muslim region in southern Russia, fought for independence from Moscow after the Soviet Union collapsed. Russian forces fought separatists there in 1994 to 1996 and&lt;a href="https://time.com/3927017/yuri-kozyrev-chechnya/"&gt; launched another war in 1999&lt;/a&gt;. The conflict also attracted Islamist militants from abroad, and CIA officers were tracking how recruitment for that fighting could benefit bin Laden&amp;rsquo;s network.&lt;/p&gt;

&lt;p&gt;An&lt;a href="https://www.cia.gov/static/10-14-2000-Bin-Ladin-Terrorist-Network-Active-Despite-Disruptions.pdf#page=2"&gt; Aug. 17, 2000, assessment&lt;/a&gt;, also from Clinton&amp;rsquo;s presidency and titled &amp;ldquo;Recruits for Chechnya Swelling Bin Ladin&amp;rsquo;s Ranks,&amp;rdquo; said worldwide recruitment for the fighting in Chechnya had produced a surplus of militants that bin Laden and other extremists were drawing upon to promote terrorism abroad.&lt;/p&gt;

&lt;p&gt;Supporters were recruiting young Muslims in Britain, Pakistan, Turkey, the Arabian Peninsula and elsewhere for training at camps affiliated with bin Laden in Afghanistan, the assessment said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Fueling the recruiting are Islamic extremist Internet sites that glorify the mujahidin in Chechnya, highlight Russian brutality, and stress that fighting in a jihad is every Muslim&amp;rsquo;s religious duty,&amp;rdquo; analysts wrote. The passage does not identify the websites or quantify how many recruits were attracted.&lt;/p&gt;

&lt;p&gt;Another&lt;a href="https://www.cia.gov/static/02-13-2001-Bin-Ladins-unconventional-capabilities.pdf"&gt; assessment, dated Feb. 13, 2001&lt;/a&gt;&amp;nbsp;&amp;mdash;&amp;nbsp;less than a month after President George W. Bush took office &amp;mdash; described militants gaining access to crude chemical and biological production information and training through an international network based in Afghanistan that partly involved the use of the web.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The network uses training camps, electronic media, and the Internet to disseminate CB data,&amp;rdquo; the document says, using an abbreviation for chemical and biological information.&lt;/p&gt;

&lt;p&gt;The records offer a fuller view of the intelligence reaching the White House in the years before 9/11, showing how analysts described bin Laden&amp;rsquo;s ambitions and possible attacks.&lt;/p&gt;

&lt;p&gt;The release also comes as the intelligence community marks a quarter-century of changes in how it gathers information, shares warnings and tracks threats. In interviews with &lt;em&gt;Nextgov/FCW&lt;/em&gt;, former senior intelligence officials &lt;a href="https://www.nextgov.com/cybersecurity/2026/09/25-years-after-911-spy-agencies-face-old-lessons-and-new-threats/415935/"&gt;reflected on the changes&lt;/a&gt; that followed 9/11 and the lessons they believe still matter today.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/11/091126ClintonNG/large.jpg" width="618" height="284"><media:description>President Bill Clinton (C) speaks to an audience gathered at the National Academy of Sciences in Washington, DC July 14, 1998. Clinton announced government initiatives to address the year 2000 problem, that stems from the use in many computer systems of a two-digit dating method that assumes 1 and 9 are the first two digits of the year.</media:description><media:credit>STEPHEN JAFFE/AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/11/091126ClintonNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>25 years after 9/11, spy agencies face old lessons and new threats </title><link>https://www.nextgov.com/cybersecurity/2026/09/25-years-after-911-spy-agencies-face-old-lessons-and-new-threats/415935/</link><description>Former intelligence officials describe a nation better equipped to disrupt terrorist plots, but still wrestling with the costs of its response and how to prevent the next crisis under escalating technology threats.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 11 Sep 2026 10:22:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/25-years-after-911-spy-agencies-face-old-lessons-and-new-threats/415935/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;As Air Force One returned to Washington, D.C. on the night of Sept. 11, 2001, Michael Morell looked out a window and saw an F-16 off the aircraft&amp;rsquo;s wingtip. Beyond it, the Pentagon was still smoldering.&lt;/p&gt;

&lt;p&gt;Morell, then-President George W. Bush&amp;rsquo;s intelligence briefer, had spent the day answering the president&amp;rsquo;s questions and relaying intelligence as the country tried to understand the attacks that had hit the Pentagon and the World Trade Center in New York City. A quarter-century later, that view from the window remains one of his most vivid memories.&lt;/p&gt;

&lt;p&gt;At the National Security Agency, Rick Ledgett recalled colleagues weeping in the hallways as the agency shifted into crisis mode. Within a month, it had transferred 3,000 analysts to counterterrorism work, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Personally, it was shattering,&amp;rdquo; Ledgett, who later served as NSA deputy director, told &lt;em&gt;Nextgov/FCW&lt;/em&gt; in an email, adding that he &amp;ldquo;saw people step up and perform in ways they hadn&amp;rsquo;t before.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The response to the worst terrorist attack in modern history would forever transform the government they served. The efforts involved reorganizing intelligence agencies, expanding surveillance powers and drawing spies deeper into a global campaign to capture or kill suspected terrorists. It also produced longstanding debates over torture policies, targeted killings, mass surveillance, prolonged wars and disputes over presidential power that became inseparable from efforts made to keep Americans safe from another catastrophe.&lt;/p&gt;

&lt;p&gt;Twenty-five years later, former officials describe a country better prepared to disrupt terrorist organizations, but facing a broader mix of threats from foreign governments, hackers and extremists able to reach Americans online.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think we&amp;rsquo;re much safer than we were on September 10, 2001, from the threat of terrorism,&amp;rdquo; Morell, who later served as CIA deputy director and acting director, told &lt;em&gt;Nextgov/FCW &lt;/em&gt;in an interview. But threats from nation-states like China or Russia, he said, are the most significant the country has faced since the Cold War.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://www.9-11commission.gov/report/911Report_Exec.htm"&gt; 9/11 Commission&lt;/a&gt; &amp;mdash; chartered by Congress and the White House in late 2002 to present a full accounting of the attacks and response &amp;mdash; described in its final report failures spanning imagination, policy, capabilities and management. Agencies held pieces of information that did not come together, and domestic defenses were not effectively mobilized despite mounting warnings about al Qaeda.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Just over a month before the attacks, Morell briefed Bush on a landmark intelligence report titled&lt;a href="https://nsarchive2.gwu.edu/NSAEBB/NSAEBB116/?utm_source=chatgpt.com"&gt; &amp;ldquo;Bin Ladin Determined To Strike in US&amp;rdquo;&lt;/a&gt; that flagged &amp;ldquo;patterns of suspicious activity in this country&amp;rdquo; consistent with preparations for hijackings and other attacks. He told &lt;em&gt;Nextgov/FCW&lt;/em&gt; it outlined al Qaeda&amp;rsquo;s intent to attack the country but did not specifically identify when, where or how a specific plot would unfold.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Getting agencies to work together&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The transformation that followed 9/11 sought to make cooperation a standing responsibility. Congress created the Office of the Director of National Intelligence in late 2004, establishing a lead unit responsible for integrating intelligence across agencies that collect data from human informants, satellite imagery, intercepted phone calls and other clandestine sources. The Department of Homeland Security was also &lt;a href="https://www.govexec.com/technology/2003/04/homeland-security-has-not-consolidated-terrorist-watch-lists/13982/?oref=ge-homepage-noscript-river"&gt;stood up&lt;/a&gt; in late 2002 to drive domestic defense efforts.&lt;/p&gt;

&lt;p&gt;The expansion also deepened agencies&amp;rsquo; reliance on contractors. After years of workforce drawdowns following the Cold War, the federal government turned to private companies to meet demands for intelligence collection, analysis and technology support, according to a 2015 report from the &lt;a href="https://www.everycrsreport.com/reports/R44157.html"&gt;Congressional Research Service&lt;/a&gt;. Today, they play a ubiquitous, outsized role in America&amp;rsquo;s national security missions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Lauren Goldman, a former official in ODNI&amp;rsquo;s Cyber Threat Intelligence Integration Center and National Intelligence Council, recalled a major shift in the basic expectations that governed intelligence-sharing across government and the private sector.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The burden became on why you shouldn&amp;rsquo;t share versus why you should share,&amp;rdquo; she said. That culture has permeated many categories of today&amp;rsquo;s national security landscape, especially cybersecurity.&lt;/p&gt;

&lt;p&gt;ODNI sought to help ensure information reached people who needed it, including officials who might otherwise have been left outside an agency&amp;rsquo;s reporting channels, Goldman said. Because the office does not collect intelligence itself, it can assess reporting without the same institutional or cultural attachment to a particular collection method, she added.&lt;/p&gt;

&lt;p&gt;James Clapper, who served as director of national intelligence for more than six years under the Obama administration, said that coordination requires a &amp;ldquo;full-time champion.&amp;rdquo; Under pre-9/11 arrangements, the CIA director also headed the intelligence community, but agency demands often consumed the attention needed for that broader role, he said.&lt;/p&gt;

&lt;p&gt;Clapper said the DNI position was created to coordinate intelligence agencies but was not given full authority over them. Entities like the State Department or the Pentagon, for instance, retained control of their own intelligence shops. Still, the DNI could influence their priorities through oversight of intelligence funding and a direct advisory role to the president, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I do think there&amp;rsquo;s a need for an overall champion of collaboration and integration,&amp;rdquo; Clapper told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. His remarks come as the Trump administration has sought to &lt;a href="https://www.nextgov.com/people/2026/06/odni-deputy-director-pushed-out-amid-pulte-cuts/414412/"&gt;shrink ODNI&amp;rsquo;s workforce&lt;/a&gt; and consolidate its functions, on grounds that the office has become bloated and duplicates work performed elsewhere in the intelligence community.&lt;/p&gt;

&lt;p&gt;Ledgett credited ODNI with promoting cooperation, as well as running the National Counterterrorism Center and other hubs. But he said it had struggled to take power from individual agencies, particularly the CIA, and secure the president&amp;rsquo;s attention.&lt;/p&gt;

&lt;p&gt;Morell said the CIA knew al Qaeda wanted to attack the United States but failed to uncover the 9/11 plot. He blamed that failure largely on a shortage of resources to gather intelligence, rather than agencies failing to share what they knew. That view differs in emphasis from the commission&amp;rsquo;s account, which identified missed opportunities to share or act on information.&lt;/p&gt;

&lt;p&gt;Clapper said mistaken assessments about Iraq&amp;rsquo;s weapons of mass destruction programs also reshaped how spy agencies worked. The Bush administration &lt;a href="https://www.mcclatchydc.com/news/special-reports/iraq-intelligence/article24433474.html"&gt;cited those assessments&lt;/a&gt; in making its case for its 2003 invasion. Clapper, who had&amp;nbsp;involvement in a &lt;a href="https://carnegieendowment.org/posts/2004/03/a-tale-of-two-intelligence-estimates"&gt;key flawed assessment&lt;/a&gt; of Iraq&amp;rsquo;s WMDs, said the failure pushed agencies to scrutinize their sources and challenge assumptions more rigorously. U.S. analysts, in particular, had relied heavily on an &lt;a href="https://www.theguardian.com/world/2011/feb/15/curveball-iraqi-fantasist-cia-saddam"&gt;Iraqi informant&lt;/a&gt; whose claims came through German intelligence, without direct access to question him.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The limits of intelligence powers&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Global surveillance became one of the defining disputes of the post-9/11 era. The NSA&amp;rsquo;s bulk collection of &lt;a href="https://www.theguardian.com/world/2013/jun/06/nsa-phone-records-verizon-court-order"&gt;domestic telephone records&lt;/a&gt;, exposed in Edward Snowden&amp;rsquo;s 2013 disclosures, drew scrutiny over both its intrusions into Americans&amp;rsquo; lives and its value as a counterterrorism tool.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In 2014, the Privacy and Civil Liberties Oversight Board&lt;a href="https://www.govinfo.gov/app/details/GOVPUB-PREX29-PURL-gpo45397"&gt; recommended&lt;/a&gt; ending that collection program, and a federal appeals court &lt;a href="https://law.justia.com/cases/federal/appellate-courts/ca2/14-42/14-42-2015-05-07.html?utm_source=chatgpt.com"&gt;ruled in 2015&lt;/a&gt; that it exceeded what Congress had authorized under Section 215 of the Patriot Act. But other surveillance programs exposed by Snowden &amp;mdash; including those operating under the contentious &lt;a href="https://www.nextgov.com/policy/2026/06/key-spying-power-will-sunset-friday-heres-why/414168/"&gt;Section 702 authority&lt;/a&gt; &amp;mdash; have remained central to U.S. intelligence-gathering.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Ledgett, who led the NSA&amp;rsquo;s assessment of the damage from Snowden&amp;rsquo;s disclosures, defended the post-9/11 surveillance effort as &amp;ldquo;legal and authorized,&amp;rdquo; though he noted the intelligence community could have done better at public relations.&lt;/p&gt;

&lt;p&gt;The incident forever changed how lawmakers and journalists examine spy agencies&amp;rsquo; collection activities and whether Americans&amp;rsquo; privacy is adequately protected. Contemporary mass surveillance debates have taken on new forms, including spy agencies&amp;rsquo;&lt;a href="https://www.nextgov.com/acquisition/2024/05/spy-agencies-must-craft-safeguards-using-sensitive-commercial-data-odni-says/396416/"&gt; purchases of sensitive data&lt;/a&gt; from commercial brokers and police use of&amp;nbsp;&lt;a href="https://www.techradar.com/tech/flocks-ai-search-tool-for-police-officers-has-been-reverse-engineered-heres-what-it-shows"&gt;artificial intelligence-powered tools&lt;/a&gt; to search vast networks of information about people&amp;rsquo;s movements and activities.&lt;/p&gt;

&lt;p&gt;The CIA&amp;rsquo;s &lt;a href="https://www.govexec.com/management/2014/12/psychologists-81m-torture-contract-exposes-cias-remarkably-broad-acquisition-authorities/100995/"&gt;detention, interrogation and torture practices&lt;/a&gt; produced another reckoning. The Senate Intelligence Committee&amp;rsquo;s 2014 investigation &lt;a href="https://www.intelligence.senate.gov/wp-content/uploads/2024/08/sites-default-filesations-crpt-113srpt288.pdf"&gt;concluded&lt;/a&gt; that the agency&amp;rsquo;s coercive interrogation techniques were ineffective in obtaining intelligence or cooperation and that the CIA impeded oversight and misrepresented aspects of the program.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Morell, who has previously disputed the Senate report&amp;rsquo;s conclusions, argued that responsibility also belonged to the president and other authorizing officials, and he rejected the idea that the agencies had acted entirely on their own.&lt;/p&gt;

&lt;p&gt;Asked whether the country went too far in its broader response in the War on Terror, Morell said that &amp;ldquo;as a nation, we overreacted,&amp;rdquo; pointing mainly to the Iraq War and the length of the war in Afghanistan.&lt;/p&gt;

&lt;p&gt;Intelligence agencies also helped identify and track suspected terrorists for controversial targeted killings, including those carried out through U.S. drone strikes. The &lt;a href="https://www.govexec.com/defense/2015/04/humanitarian-groups-say-it-time-obama-acknowledge-more-civilian-deaths-drone-strikes/111277/"&gt;debate&lt;/a&gt; reached American citizenship itself when the government targeted Anwar al-Awlaki, an American and al Qaeda operative, in a lethal strike. Defending the action in 2013, then-President Barack Obama &lt;a href="https://obamawhitehouse.archives.gov/the-press-office/2013/05/23/remarks-president-national-defense-university"&gt;argued&lt;/a&gt; that citizenship could not shield an operative plotting attacks when capture was not feasible.&lt;/p&gt;

&lt;p&gt;Today, drones have become a &lt;a href="https://www.defenseone.com/technology/2026/07/how-ukraine-won-first-great-robot-war/414658/"&gt;battlefield mainstay&lt;/a&gt; in Russia&amp;rsquo;s war against Ukraine, and Western militaries are studying how to build, deploy and counter them. Weapons that drew scrutiny for their role in U.S. counterterrorism operations are now also held up as examples of military innovation, with NATO &lt;a href="https://www.nato.int/en/multimedia/multimedia/videos/2025/10/03/drones-lessons-from-ukraine"&gt;learning directly&lt;/a&gt; from Ukrainian drone operators. But questions about whom they kill and how they are used persist, as the United Nations documents their growing &lt;a href="https://www.reuters.com/world/europe/drones-become-most-common-cause-death-civilians-ukraine-war-un-says-2025-02-11/"&gt;toll on civilians&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The fight over intelligence powers also became increasingly partisan. President Donald Trump&amp;rsquo;s disputes with intelligence officials over Russia&amp;rsquo;s interference in the 2016 election helped fuel his accusations that agencies were being used against him. A bipartisan &lt;a href="https://embed.documentcloud.org/documents/6844148-Report-Volume4/"&gt;Senate investigation&lt;/a&gt; upheld the intelligence community&amp;rsquo;s finding that Moscow sought to help him win. But allegations of political &amp;ldquo;weaponization&amp;rdquo; became a &lt;a href="https://www.whitehouse.gov/presidential-actions/2025/01/ending-the-weaponization-of-the-federal-government/"&gt;recurring theme&lt;/a&gt; in Trump&amp;rsquo;s criticism of intelligence and law enforcement agencies.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A changing threat landscape&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Intelligence agencies now face a wider range of threats, including foreign hackers with access to fast-evolving AI tools.&lt;/p&gt;

&lt;p&gt;Morell said the United States learned how to degrade terrorist organizations by denying them safe havens where they could train, raise money and prepare attacks. But the growing reach of digital networks has created other ways to threaten the U.S. without physically entering it.&lt;/p&gt;

&lt;p&gt;Goldman pointed to critical infrastructure, where connected systems can allow the effects of an intrusion to spread beyond a single building or city, as a target of such threats. Hardening airports and other physical targets has value, she said, but does not eliminate vulnerabilities created by that cyber interconnectedness.&lt;/p&gt;

&lt;p&gt;State-backed hacking illustrates the stakes. About six years ago, Russian cyber operatives&lt;a href="https://www.nextgov.com/cybersecurity/2021/04/hack-roundup-white-house-sanctions-russia-over-solarwinds/173402/?utm_source=chatgpt.com"&gt; compromised SolarWinds software&lt;/a&gt; as part of an espionage campaign that infiltrated multiple federal agencies and some 100 private companies. China-linked&lt;a href="https://www.nextgov.com/cybersecurity/2025/06/us-agencies-assessed-chinese-telecom-hackers-likely-hit-data-center-and-residential-internet-providers/405920/"&gt; Salt Typhoon hackers&lt;/a&gt; later penetrated major telecommunications networks, targeting senior officials&amp;rsquo; communications and accessing systems used for court-authorized wiretaps. And another Chinese campaign,&lt;a href="https://www.nextgov.com/cybersecurity/2024/02/chinese-hackers-embedded-us-networks-years-pre-positioning-future-attacks-ic-warns/394009/"&gt; Volt Typhoon&lt;/a&gt;, embedded hackers in American critical infrastructure, with U.S. officials warning that the access could enable disruption during a future conflict.&lt;/p&gt;

&lt;p&gt;Terrorist groups have also found new ways to spread propaganda and reach potential recruits online. The Digital Citizens Alliance and cybersecurity firm risk3sixty recently examined 25 piracy-based internet television services and &lt;a href="https://hostile-signals.digitalcitizensalliance.org/"&gt;identified&lt;/a&gt; terrorist-linked broadcasters on 17 of them. Hezbollah&amp;rsquo;s Al-Manar satellite television station appeared on all 17, according to their analysis.&lt;/p&gt;

&lt;p&gt;Some terrorism-prevention measures have also lapsed. A Sept. 8 Government Accountability Office &lt;a href="https://www.gao.gov/products/gao-26-108127"&gt;report&lt;/a&gt; found that the 2023 expiration of the Chemical Facility Anti-Terrorism Standards program ended continuous screening of roughly 500,000 people for possible terrorist ties. The program covered about 3,200 high-risk chemical facilities, whose owners cannot independently access federal terrorist watchlist information.&lt;/p&gt;

&lt;p&gt;As officials who lived through 9/11 reflect on their time in government, they want the next generation to remember how warnings were missed and what it took to get agencies working together.&lt;/p&gt;

&lt;p&gt;Goldman said analysts need to keep questioning their conclusions, examining blind spots and sharing information, despite the demands of daily work. Clapper emphasized the difficulty of persuading policymakers to act on a danger the public has not yet experienced.&lt;/p&gt;

&lt;p&gt;Ledgett expressed confidence in those who will take their place.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Everyone eventually retires, and organizations continue,&amp;rdquo; he said. &amp;ldquo;The next generation steps up and delivers when needed.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The U.S. is skilled at responding once a crisis arrives, but has struggled to prepare before it does, Morell said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Becoming a nation, a White House, a Congress, an American people that is proactive in preventing things &amp;mdash; preventing bad things &amp;mdash; is much better than only being reactive to them,&amp;rdquo; he said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/11/091126NG/large.jpg" width="618" height="284"><media:description>The 'Tribute in Light' public art installation commemorating the September 11, 2001 attacks shines up from the skyline of lower Manhattan, as seen from Jersey City, New Jersey, on September 10, 2026.</media:description><media:credit>Leonardo MUNOZ / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/11/091126NG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>White House plans to take water cyber pilot into other sectors</title><link>https://www.nextgov.com/cybersecurity/2026/09/white-house-plans-take-water-cyber-pilot-other-sectors/415903/</link><description>Sean Cairncross also outlined plans for a cyber academy that would combine venture capital and other private sector initiatives with a service component.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 10 Sep 2026 10:51:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/white-house-plans-take-water-cyber-pilot-other-sectors/415903/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The White House plans to apply the approach behind its Texas water cybersecurity pilot to other critical infrastructure sectors in the near future, National Cyber Director Sean Cairncross said Thursday.&lt;/p&gt;

&lt;p&gt;Speaking at the Billington Cybersecurity Summit on stage with OPM Director Scott Kupor, Cairncross said his office would announce the additional sectors soon as it evaluates how to expand Project Watershed 250, which pairs water utilities with government and industry cybersecurity assistance. He did not identify the sectors or give a launch date for the additional efforts.&lt;/p&gt;

&lt;p&gt;The goal is to &amp;ldquo;find a specific, concrete solution, and then scale off of that,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The water pilot,&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/white-house-launches-water-cybersecurity-pilot-texas/415725/"&gt; launched Aug. 31 in San Antonio&lt;/a&gt;, brings together the Office of the National Cyber Director, Texas Cyber Command, the office of Texas Gov. Greg Abbott and private companies to identify vulnerabilities in water systems and help utilities address them.&lt;/p&gt;

&lt;p&gt;Cairncross said water was a starting point because providers often lack the funding and technical capacity to adequately defend their systems. The pilot is intended to test whether industry partnerships can lower costs, deploy new technology and improve operators&amp;rsquo; ability to protect their facilities, he said. The White House had been exploring pilot programs for multiple infrastructure sectors with private companies for some time.&lt;/p&gt;

&lt;p&gt;Separately, Cairncross said his office is developing a cyber academy proposal that would connect venture capital and other private sector initiatives with a service component intended to attract people into cybersecurity work, a topic he has discussed in several other public appearances. He said the office would have more to share soon without providing a timeline.&lt;/p&gt;

&lt;p&gt;The proposal would &amp;ldquo;knit together elements of venture capital and other private sector initiatives&amp;rdquo; and seek to &amp;ldquo;align patriotic and economic incentives,&amp;rdquo; he said. He did not identify participating investors or explain how the financing would work.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/10/IMG_8463/large.jpg" width="618" height="284"><media:description>(L-R) Thomas K. Billington, founder of Billington CyberSecurity, speaks with National Cyber Director Sean Cairncross and OPM Director Scott Kupor Spet. 10 at the Billington Cybersecurity Summit in Washington. D.C.</media:description><media:credit>David DiMolfetta/Staff</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/10/IMG_8463/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Lawmakers ask Commerce to sanction Indian firms involved in mercenary hacking</title><link>https://www.nextgov.com/cybersecurity/2026/09/lawmakers-ask-commerce-sanction-indian-firms-involved-mercenary-hacking/415874/</link><description>The “hack-for-hire” entities have systematically targeted newsrooms covering corporate fraud, legal teams in high-stakes litigation and NGOs.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 09 Sep 2026 14:21:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/lawmakers-ask-commerce-sanction-indian-firms-involved-mercenary-hacking/415874/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;A bipartisan, bicameral group of lawmakers is asking the Commerce Department to sanction a trio of Indian firms involved in mercenary hacking activities against U.S. citizens and companies.&lt;/p&gt;

&lt;p&gt;Sens. Ron Wyden, D-Ore., and Sheldon Whitehouse, D-R.I., alongside Rep. Pat Harrigan, R-N.C., asked Commerce Secretary Howard Lutnik on Wednesday to impose penalties on Sunkissed Organic Farms &amp;mdash; previously branded as Appin &amp;mdash; BellTroX and CyberRoot, according to a &lt;a href="https://www.wyden.senate.gov/news/press-releases/wyden-harrigan-and-whitehouse-call-on-commerce-department-to-sanction-mercenary-foreign-hacking-firms"&gt;letter sent Wednesday&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The three firms were exposed in a 2023 Reuters &lt;a href="https://www.reuters.com/investigates/special-report/usa-hackers-appin/"&gt;investigation&lt;/a&gt; into a global &amp;ldquo;hack-for-hire&amp;rdquo; industry operating out of India. BellTroX was also identified in a &lt;a href="https://citizenlab.ca/research/dark-basin-uncovering-a-massive-hack-for-hire-operation/"&gt;2020 Citizen Lab investigation&lt;/a&gt; into mercenary hacking activities.&lt;/p&gt;

&lt;p&gt;The entities systematically targeted newsrooms covering corporate fraud, legal teams in high-stakes litigation&amp;nbsp;and NGOs. Their reach also extended to senior executives at firms like WeWork and Wirecard, foreign heads of state and U.S. political figures.&lt;/p&gt;

&lt;p&gt;The Reuters reporting gained notable publicity after a New Delhi court ordered its temporary removal, triggering a global censorship controversy. Appin-linked entities backed the suit with legal threats to over a dozen media outlets, while the Indian government &lt;a href="https://www.theguardian.com/world/2025/mar/13/us-journalist-sues-indian-government-after-losing-his-overseas-citizenship"&gt;revoked&lt;/a&gt; Reuters reporter Raphael Satter&amp;rsquo;s residency status in retaliation. Following press freedom backlash, an Indian court ultimately overturned the injunction in late 2024, allowing the news service to fully restore the investigation online.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations,&amp;rdquo; the lawmakers wrote. &amp;ldquo;This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;India&amp;rsquo;s embassy in Washington, D.C., and the Commerce Department did not immediately respond to a request for comment on the letter. &lt;em&gt;Nextgov/FCW&lt;/em&gt; also attempted to reach multiple email addresses affiliated with the three companies. Emails that appear to be tied with BellTrox and CyberRoot kicked back.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The United States cannot allow mercenary hackers to target Americans and undermine our legal system nor stand by as foreign nationals weaponize foreign judicial systems to enforce censorship within our borders,&amp;rdquo; the lawmakers added.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/09/GettyImages_1427993261/large.jpg" width="618" height="284"><media:credit>mirsad sarajlic/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/09/GettyImages_1427993261/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title> New FBI cyber strategy seeks faster action against hackers, larger industry role</title><link>https://www.nextgov.com/cybersecurity/2026/09/new-fbi-cyber-strategy-seeks-faster-action-against-hackers-larger-industry-role/415869/</link><description>The bureau wants more frequent disruption operations and quicker warnings to victims as the Justice Department works through rules for expanded private sector participation in hacking cybercrime groups.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 09 Sep 2026 11:25:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/new-fbi-cyber-strategy-seeks-faster-action-against-hackers-larger-industry-role/415869/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The FBI is seeking more frequent operations against hackers and a larger role for private companies under a new cyber strategy released Wednesday, with the bureau&amp;rsquo;s cyber chief saying teams are aiming to act more quickly to disrupt attacks and warn victims.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://www.fbi.gov/file-repository/fbi-cyber-strategy-2026.pdf/view"&gt; strategy&lt;/a&gt; directs the bureau&amp;rsquo;s 56 field offices and overseas cyber personnel to coordinate investigations, help compromised organizations and expand partnerships with government agencies, foreign authorities and industry. It also calls for wider use of artificial intelligence tools that could cut the time needed to alert organizations about threats.&lt;/p&gt;

&lt;p&gt;FBI cyber chief Brett Leatherman told reporters at the Billington Cybersecurity Summit that the bureau wants to move more regularly against hackers, including by helping partners act when the FBI is not entirely positioned to do so itself.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If we can&amp;rsquo;t take action right now, let&amp;rsquo;s not wait six months till we&amp;rsquo;re positioned to take action,&amp;rdquo; he said, pointing to Cyber Command and authorities in Britain and Japan as potential partners.&lt;/p&gt;

&lt;p&gt;Leatherman described the document as the FBI&amp;rsquo;s first comprehensive public cyber strategy covering both criminal and national security threats. Previous plans, he said, were classified or developed within teams responsible for specific threats.&lt;/p&gt;

&lt;p&gt;The public strategy is unclassified and also has no classified annex, Leatherman said. Individual teams focused on specific foreign adversaries and cybercriminal threats are developing more detailed classified strategies to guide field office operations, he added.&lt;/p&gt;

&lt;p&gt;The strategy comes as the Trump administration develops a&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/"&gt; &lt;/a&gt;program allowing vetted U.S. companies to &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/"&gt;conduct cyber operations&lt;/a&gt; against foreign criminal organizations under federal supervision.&lt;/p&gt;

&lt;p&gt;A presidential memorandum issued last month directed the departments of Justice and Homeland Security to establish operating procedures and standards for participating companies. Implementation guidance for the initiative remains under development.&lt;/p&gt;

&lt;p&gt;Nation-state groups are off the table as part of the new program. Asked about the risk of &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/"&gt;accidentally targeting&lt;/a&gt; entities connected to foreign governments, Leatherman said federal agencies would retain control and apply the same testing and scrutiny used in existing operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think the American public should understand that with DOJ, FBI [and]&amp;nbsp;DHS oversight, that won&amp;rsquo;t change where industry gets involved,&amp;rdquo; he said. &amp;ldquo;This is not a situation where industry is going to pick targets and go after targets themselves.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The strategy also puts greater emphasis on transmitting intelligence to victims more quickly, an approach Leatherman said has required a notable cultural change within the bureau.&lt;/p&gt;

&lt;p&gt;But he also noted some companies have grown more reluctant to involve the FBI after a breach. He suggested that hesitation may stem from uncertainty about what help the bureau can provide and concerns about information reaching regulators.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;AI is another component of the plan. The strategy calls for tools to accelerate malware analysis, map hackers&amp;rsquo; infrastructure, identify relationships in large datasets and prioritize victim notifications. The document says the work will remain subject to human review and legal controls.&lt;/p&gt;

&lt;p&gt;Leatherman said the FBI is coordinating with CISA, NSA, Cyber Command and CIA as those agencies develop their own strategies to carry out the White House&amp;rsquo;s national cyber framework. Some of those plans may never become public, he said. He also pointed to the&lt;a href="https://www.nextgov.com/cybersecurity/2026/09/pentagon-cyber-strategy-expected-soon-next-week-sources-say/415778/"&gt; Pentagon&amp;rsquo;s forthcoming cyber strategy&lt;/a&gt;, which may be released sometime this week.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/09/GettyImages_2288940584/large.jpg" width="618" height="284"><media:credit>Kevin Carter/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/09/GettyImages_2288940584/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CIA cyber intelligence helped US forces capture Maduro, deputy director says</title><link>https://www.nextgov.com/cybersecurity/2026/09/cia-cyber-intelligence-helped-us-forces-capture-maduro-deputy-director-says/415849/</link><description>Michael Ellis credited the agency’s cyber intelligence officers with helping U.S. troops locate and apprehend the Venezuelan leader within minutes of landing.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 08 Sep 2026 17:07:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/cia-cyber-intelligence-helped-us-forces-capture-maduro-deputy-director-says/415849/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;CIA cyber operatives provided intelligence that helped U.S. forces locate and capture deposed Venezuelan leader Nicol&amp;aacute;s Maduro within four minutes of landing on the ground in January this year, agency Deputy Director Michael Ellis said Tuesday.&lt;/p&gt;

&lt;p&gt;Ellis credited the agency&amp;rsquo;s Center for Cyber Intelligence with building what he called a &amp;ldquo;flawless intelligence picture&amp;rdquo; for Operation Absolute Resolve, the U.S. operation that seized Maduro.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If you look at [Absolute Resolve], you know that operation was only made possible by a flawless intelligence picture, and that flawless intelligence picture was built on cyber operations enabled by our CCI team,&amp;rdquo; Ellis said, speaking at the Billington Cybersecurity Conference in Washington, D.C. Without that intelligence, he said, the agency could not have helped U.S. forces locate and apprehend Maduro as quickly as they did.&lt;/p&gt;

&lt;p&gt;The remarks offer a more detailed public picture of how CIA cyber prowess helped U.S. forces locate and capture Maduro, expanding on&lt;a href="https://www.cia.gov/stories/story/director-ratcliffe-delivers-remarks-at-amazon-web-services-summit/"&gt; earlier accounts&lt;/a&gt; from officials that acknowledged support without explaining the agency&amp;rsquo;s entire contribution.&lt;/p&gt;

&lt;p&gt;Joint Chiefs Chairman Gen. Dan Caine&lt;a href="https://www.defenseone.com/threats/2026/01/us-spy-agencies-contributed-operation-captured-maduro/410437/"&gt; previously acknowledged&lt;/a&gt; Cyber Command&amp;rsquo;s participation in the efforts and credited the CIA, National Security Agency and National Geospatial-Intelligence Agency with supporting the Venezuela mission. He described months of intelligence collection on Maduro&amp;rsquo;s movements and daily routines, but did not directly identify the CIA cyber role Ellis outlined.&lt;/p&gt;

&lt;p&gt;During the capture mission, multiple intelligence agencies established crisis action teams to support Special Operations Command and Southern Command. A U.S. official familiar with the operation &lt;a href="https://www.defenseone.com/threats/2026/01/us-spy-agencies-contributed-operation-captured-maduro/410437/"&gt;previously said&lt;/a&gt; the NSA provided geolocation support and monitored communications and signals that could reveal troop movements or plans to activate radar.&lt;/p&gt;

&lt;p&gt;Ellis discussed the operation in explaining the CIA&amp;rsquo;s recent decision to &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/04/cia-plans-ai-coworkers-deputy-director-says/412744/#:~:text=But%20there%20have%20been%20benefits%20to%20technological%20investments.%20The%20agency%20recently%20elevated%20its%20Center%20for%20Cyber%20Intelligence%20into%20an%20entire%20mission%20center%2C%20a%20move%20that%E2%80%99s%20%E2%80%9Cpaying%20dividends%20already%20by%20allowing%20us%20to%20deploy%20new%20tools%20to%20the%20field%20and%20gain%20more%20access%20to%20priority%20targets%2C%E2%80%9D%20Ellis%20said.%C2%A0"&gt;elevate&lt;/a&gt; CCI to a mission center, a change he said gave their cyber operators greater priority and helped align resources around intelligence needs.&lt;/p&gt;

&lt;p&gt;The change has helped the agency &amp;ldquo;bring cyber operations to bear to solve these tough intelligence problems,&amp;rdquo; Ellis said. He did not specifically identify the systems targeted or explain how the cyber operations revealed Maduro&amp;rsquo;s location.&lt;/p&gt;

&lt;p&gt;The CIA primarily executes and coordinates human intelligence gathering overseas, often done undercover. Officers recruit and manage foreign assets to clandestinely gather intelligence on areas like economics and terrorism threats. Much of that work has often involved the use of technology, including computer intrusions.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/08/GettyImages_2254194482/large.jpg" width="618" height="284"><media:description>Nicolas Maduro and his wife, Cilia Flores, are seen in handcuffs after landing at a Manhattan helipad, escorted by heavily armed Federal agents as they make their way into an armored car en route to a Federal courthouse in Manhattan on January 5, 2026 in New York City. </media:description><media:credit>XNY/Star Max/GC Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/08/GettyImages_2254194482/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Senator asks NSA to update Americans about VPN spying risks</title><link>https://www.nextgov.com/cybersecurity/2026/09/senator-asks-nsa-update-americans-about-vpn-spying-risks/415784/</link><description>A congressional analysis found foreign spies could trace users by comparing encrypted traffic entering and leaving a VPN server, according to the lawmaker’s office.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 02 Sep 2026 16:01:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/senator-asks-nsa-update-americans-about-vpn-spying-risks/415784/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Sen. Ron Wyden, D-Ore., is pressing the National Security Agency to revise cybersecurity guidance to warn Americans that a standard commercial virtual private network service may not protect them from sophisticated foreign surveillance threats.&lt;/p&gt;

&lt;p&gt;Foreign intelligence services monitoring large parts of the internet may be able to connect a VPN user to specific websites by matching the timing and amount of encrypted data entering and leaving the VPN server, according to a&lt;a href="https://www.wyden.senate.gov/imo/media/doc/20260902wydenlettertonsavpntrafficanalysisdniletterandcrsmemo.pdf#page=6"&gt; Congressional Research Service analysis&lt;/a&gt; requested by Wyden that his office released Wednesday.&lt;/p&gt;

&lt;p&gt;The method, known as traffic analysis, does not require an adversary to break the service&amp;rsquo;s encryption and could expose a user&amp;rsquo;s online behavior even while the underlying data remains unreadable.&lt;/p&gt;

&lt;p&gt;Major intelligence powers like the United States and China have sought sweeping visibility into global internet traffic through domestic legal authorities and covert access to the infrastructure carrying it, ranging from telecommunications networks to undersea fiber-optic cables.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Encryption strength alone does not protect users from an advanced, persistent threat conducting bulk traffic collection,&amp;rdquo; CRS wrote.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;VPNs are commonly used to protect people on public Wi-Fi, conceal their internet addresses and prevent internet providers from directly viewing their online activity.&lt;/p&gt;

&lt;p&gt;The concern is centered largely on single-hop VPNs, which route a user&amp;rsquo;s traffic through one provider&amp;rsquo;s server before sending it to its destination. Anyone capable of monitoring or compromising that server may be able to connect the traffic entering the VPN with the traffic leaving it, according to CRS. Wyden argues that dynamic should be made clear to government personnel, contractors, journalists and others who may be espionage targets.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Americans facing advanced foreign threats &amp;hellip; deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries,&amp;rdquo; Wyden also wrote in a&lt;a href="https://www.wyden.senate.gov/news/press-releases/wyden-calls-on-nsa-to-update-federal-cybersecurity-guidance-for-vpns"&gt; letter Wednesday&lt;/a&gt; to NSA Director Gen. Joshua Rudd.&lt;/p&gt;

&lt;p&gt;Wyden asked the NSA to provide unclassified answers by Oct. 14.&lt;em&gt; Nextgov/FCW&lt;/em&gt; has also asked the NSA for comment. The agency serves as the primary foreign electronic eavesdropping and hacking titan of the U.S. intelligence community.&lt;/p&gt;

&lt;p&gt;CRS said services such as Tor, Nym and Apple&amp;rsquo;s iCloud Private Relay make traffic analysis harder by splitting information about a user and their destination across multiple servers, although Private Relay service does not cover all device traffic. None guarantee full anonymity.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Current&lt;a href="https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/2791320/nsa-cisa-release-guidance-on-selecting-and-hardening-remote-access-vpns/"&gt; NSA and Cybersecurity and Infrastructure Security Agency guidance&lt;/a&gt; largely focuses on preventing hackers from exploiting vulnerabilities in remote-access VPN products to enter government or corporate networks. It recommends measures such as rapidly installing security updates, requiring multifactor authentication and reducing the number of exposed features.&lt;/p&gt;

&lt;p&gt;The Office of the Director of National Intelligence offered another assessment in a July response that Wyden also released Wednesday. ODNI described VPNs as useful for basic cybersecurity and said consumers should examine a provider&amp;rsquo;s encryption, privacy and data-retention practices.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The top intelligence office also noted that a VPN provider may know a customer&amp;rsquo;s identity and retain records of their activity. It&amp;rsquo;s not clear if ODNI examined whether a conventional VPN could expose users to spying, or if analysts compared single-hop services with other offerings.&lt;/p&gt;

&lt;p&gt;Wyden&amp;rsquo;s request comes amid evidence that Chinese state-owned telecom providers retained U.S. network footholds that could facilitate the hacking and surveillance he wants NSA to address. A bipartisan House China Committee investigation&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/chinese-telecom-firms-kept-footholds-us-networks-despite-federal-crackdowns-house-probe-finds/415190/"&gt; first reported by &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; last month found three Chinese carriers kept equipment, data center space and network ties in the U.S., despite federal crackdowns.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/02/GettyImages_2281570436/large.jpg" width="618" height="284"><media:description>Sen. Ron Wyden, D-Ore., is seen during votes in the U.S. Capitol on Wednesday, June 17, 2026</media:description><media:credit>Tom Williams/CQ-Roll Call, Inc via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/02/GettyImages_2281570436/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Pentagon cyber strategy expected as soon as next week, sources say</title><link>https://www.nextgov.com/cybersecurity/2026/09/pentagon-cyber-strategy-expected-soon-next-week-sources-say/415778/</link><description>Officials have previewed a blueprint emphasizing offensive operations, AI adoption and closer industry ties as the military reorganizes its cyber forces.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 02 Sep 2026 12:56:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/09/pentagon-cyber-strategy-expected-soon-next-week-sources-say/415778/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Defense Department is expected to release its anticipated cyber strategy early next week, according to three people familiar with the plans for the blueprint that officials argue will more tightly integrate digital operations into U.S. military campaigns.&lt;/p&gt;

&lt;p&gt;One of the people predicted the strategy would be released Tuesday. All three spoke on the condition of anonymity to discuss the release timing, with two noting its exact release could still be subject to change.&lt;/p&gt;

&lt;p&gt;The strategy has been under development for months by the office of Katie Sutton, the assistant secretary of defense for cyber policy and principal cyber adviser to the secretary. It will be the department&amp;rsquo;s first overarching cyber framework &lt;a href="https://www.nextgov.com/ideas/2023/08/dods-2023-cyber-strategy-what-we-know-and-what-we-need/389385/"&gt;since 2023&lt;/a&gt; and is expected to be accompanied by an action plan.&lt;/p&gt;

&lt;p&gt;Officials initially said it would be completed during the summer. Sutton told lawmakers in April that the strategy would seek to build &amp;ldquo;the most capable, lethal and agile cyber force in the world,&amp;rdquo; able to defend military networks, gain strategic advantage and give the president more options to deter or defeat adversaries.&lt;/p&gt;

&lt;p&gt;The plan is expected to center on three priorities Sutton outlined before Congress: integrating cyber capabilities across every domain of warfare; gaining an advantage over adversaries; and reorganizing the military&amp;rsquo;s cyber forces to improve their skill and agility.&lt;/p&gt;

&lt;p&gt;A &lt;a href="https://jobs.parsons.com/jobs/project-manager-staunton-r-183931-jobs--project-program-management--"&gt;job posting&lt;/a&gt; on the website of defense and technology provider Parsons seeks support for the Pentagon&amp;rsquo;s cyber policy office&amp;nbsp;and says the strategy&amp;rsquo;s action plan contains approximately nine strategic initiatives and 34 lines of effort. It&amp;rsquo;s not clear when the role was posted, and the specific initiatives&amp;rsquo; contents are not disclosed in the description.&lt;/p&gt;

&lt;p&gt;The approach would aim to further move cyber operations into routine military planning, meaning tools that can disrupt an enemy&amp;rsquo;s communications or computer systems would be planned alongside airstrikes and other conventional operations. Officials have cited recent Trump-era operations in &lt;a href="https://www.nextgov.com/cybersecurity/2026/01/us-developed-non-kinetic-cell-ahead-venezuela-mission-push-cyber-operations/411029/"&gt;Venezuela&lt;/a&gt; and &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/how-cyber-command-contributed-operation-epic-fury-against-iran/411818/"&gt;Iran&lt;/a&gt; as examples of this integration.&lt;/p&gt;

&lt;p&gt;The strategy will also translate the&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt; White House&amp;rsquo;s March cyber strategy&lt;/a&gt; into more specific military priorities and investments. That document pledged to deploy the government&amp;rsquo;s entire toolkit of offensive and defensive cyber capabilities, disrupt threats before they reach U.S. networks and impose greater consequences on foreign hackers.&lt;/p&gt;

&lt;p&gt;The posture is not entirely new. The Pentagon&amp;rsquo;s 2023 strategy embraced &amp;ldquo;defend forward,&amp;rdquo; an approach that calls for confronting malicious cyber threats closer to the source of their operations. The new strategy is expected to emphasize delivering cyber options to combatant commanders and integrating them with conventional military power.&lt;/p&gt;

&lt;p&gt;Artificial intelligence is also expected to feature prominently. Sutton &lt;a href="https://breakingdefense.com/2026/06/dod-cyber-strategy-will-set-a-clear-and-specific-vision-for-ai-to-enable-the-force-official/"&gt;said in June&lt;/a&gt; that the strategy would set a &amp;ldquo;clear and specific vision&amp;rdquo; for enabling AI across the cyber force, supported by coordination among Cyber Command, the Pentagon&amp;rsquo;s chief information office and its Chief Digital and Artificial Intelligence Office.&lt;/p&gt;

&lt;p&gt;The Pentagon and National Security Agency have been expanding access to commercial models that can find vulnerabilities and automate parts of cyber operations. NSA Deputy Director Tim Kosiba&lt;a href="https://www.nextgov.com/artificial-intelligence/2026/08/nsa-wants-access-all-ai-models-top-official-says/415672/"&gt; said last week&lt;/a&gt; that the agency wants access to &amp;ldquo;all the models&amp;rdquo; and is holding discussions with leading developers.&lt;/p&gt;

&lt;p&gt;The efforts, broadly, are closely tied to Cyber Command 2.0, the Pentagon&amp;rsquo;s overhaul of how it recruits, trains and employs cyber personnel. The initiative emphasizes greater specialization and purpose-built teams, along with a Cyber Innovation Warfare Center intended to bring commercial technology directly to operators for testing.&lt;/p&gt;

&lt;p&gt;The strategy arrives as officials continue grappling with myriad cyber threats to U.S. systems, including an apparently extensive &lt;a href="https://www.nbcnews.com/politics/national-security/iran-attempted-cyberattacks-range-us-infrastructure-sources-say-rcna595424"&gt;Iran-linked campaign&lt;/a&gt; to access water systems and other critical infrastructure around the nation. The Defense Department has also begun an&lt;a href="https://www.nextgov.com/defense/2026/06/dod-quantum-strategy-first-step-preparing-future-cio-says/414408/"&gt; accelerated migration&lt;/a&gt; to quantum-resistant encryption, with a goal of protecting its highest-impact systems by 2030.&lt;/p&gt;

&lt;p&gt;The administration separately moved last month to let&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/"&gt; &lt;/a&gt;vetted U.S. companies &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/"&gt;conduct government-approved operations&lt;/a&gt; against foreign cybercriminal groups. The initiative also raises questions about how the departments of Justice, Homeland Security and Defense will divide responsibilities and avoid interfering with one another&amp;rsquo;s cyber operations.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;To securely contact the reporter for this story, he can be reached on Signal via username did.99&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/09/02/090226pentagonNG/large.jpg" width="618" height="284"><media:credit>Artem Onoprienko/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/09/02/090226pentagonNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>White House launches water cybersecurity pilot in Texas</title><link>https://www.nextgov.com/cybersecurity/2026/08/white-house-launches-water-cybersecurity-pilot-texas/415725/</link><description>Project Watershed 250 will stress-test utilities over six months and could serve as a model for protecting water providers nationwide.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 31 Aug 2026 10:52:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/white-house-launches-water-cybersecurity-pilot-texas/415725/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Trump administration is formally launching a new water sector cybersecurity program Monday in San Antonio that will bring together the Office of the National Cyber Director, Texas Cyber Command, the office of Texas Gov. Greg Abbott and private industry partners, according to two people familiar with the efforts.&lt;/p&gt;

&lt;p&gt;The people spoke on the condition of anonymity because they were not authorized to discuss the plans.&lt;/p&gt;

&lt;p&gt;The initiative, dubbed Project Watershed 250, will use Texas as the testing ground for a six-month pilot aimed at finding vulnerabilities in water systems and helping utilities address them with private sector cybersecurity and artificial intelligence tools. The administration ultimately plans to expand the model nationwide.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Fox News &lt;a href="https://www.foxnews.com/politics/first-fox-texas-becomes-testing-ground-new-defense-against-attacks-americas-water-systems"&gt;first disclosed&lt;/a&gt; the program&amp;rsquo;s details Monday after receiving advance materials from the Trump administration and participating companies. The rollout follows &lt;a href="https://www.politico.com/news/2026/08/26/white-house-program-private-companies-water-hacks-01050315"&gt;Politico&lt;/a&gt; and&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/white-house-soon-launch-water-provider-cyber-protection-program/415650/"&gt; &lt;em&gt;Nextgov/FCW&lt;/em&gt; reporting&lt;/a&gt; on the plans last week.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;President Trump has cemented America&amp;rsquo;s leadership in AI security and innovation and is now bringing those exquisite tools to local communities and utilities in Texas and ultimately,&amp;nbsp;across the nation,&amp;rdquo; National Cyber Director Sean Cairncross said in a statement to Fox.&lt;/p&gt;

&lt;p&gt;The EPA and the Cybersecurity and Infrastructure Security Agency will serve as federal partners for the program. Firms including Microsoft, Reflection AI, Palo Alto Networks and industrial cybersecurity company Dragos will participate alongside ONCD and Texas Cyber Command. The utilities will receive the assistance at no cost, according to Abbott&amp;rsquo;s office.&lt;/p&gt;

&lt;p&gt;The program was already under development before recent cyberattacks that officials suspect may be tied to Iran targeted community water systems in Minnesota and several other states. State officials have said affected water systems continued operating safely and experienced no known effects on public health. The FBI and CISA have been assisting with the response.&lt;/p&gt;

&lt;p&gt;Water providers are widely considered among the country&amp;rsquo;s most vulnerable critical infrastructure sectors because many have limited cybersecurity personnel, funding and technical expertise. Current and former officials have also warned that poorly secured remote-access systems can &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/new-water-watch-center-launched-help-small-utilities-stop-cyberattacks/415288/#:~:text=Retired%20Gen.%20Paul,inside%20water%20facilities."&gt;give hackers a pathway&lt;/a&gt; into the equipment used to manage water treatment and distribution.&lt;/p&gt;

&lt;p&gt;Texas Cyber Command, headquartered in San Antonio, was created last year with $135 million in state funding to protect state and local government systems and coordinate responses to cyberattacks. The organization is led by retired Navy Vice Adm. TJ White, a former commander of U.S. Fleet Cyber Command and the Cyber National Mission Force.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/31/083126AbbotNG/large.jpg" width="618" height="284"><media:description>Texas Governor Greg Abbott gives a thumbs up to supporters before ringing the closing bell to celebrate the grand opening of NYSE Texas on August 27, 2026 in Dallas, Texas.</media:description><media:credit>Ron Jenkins/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/31/083126AbbotNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Trump admin moves to block risky foreign technology from US power grid</title><link>https://www.nextgov.com/cybersecurity/2026/08/trump-admin-moves-block-risky-foreign-technology-us-power-grid/415701/</link><description>A new executive order targets hardware, software and remote-access services and could require operators to isolate or replace equipment already in use.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 28 Aug 2026 12:25:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/trump-admin-moves-block-risky-foreign-technology-us-power-grid/415701/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;President Donald Trump declared a national emergency this week over foreign-made technology in the U.S. power grid, giving the Energy Department broader authority to block equipment, software and services that officials determine could allow an adversary to disrupt or remotely access the electricity system.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/declaring-a-national-emergency-to-secure-the-united-states-bulk-power-system/"&gt; executive order&lt;/a&gt; prohibits the purchase, import or installation of certain foreign-produced equipment when the Energy Department determines that it is connected to a covered foreign entity and presents an unacceptable national security risk.&lt;/p&gt;

&lt;p&gt;The department must determine which countries, vendors, products and transactions present enough risk to warrant restrictions within 120 days.&lt;/p&gt;

&lt;p&gt;The order focuses on the bulk-power system &amp;mdash; the high-voltage generation and transmission infrastructure that moves electricity over long distances &amp;mdash; rather than the local lines that deliver power to homes and businesses. It covers transmission infrastructure operating at 69 kilovolts or higher but excludes local distribution facilities.&lt;/p&gt;

&lt;p&gt;Affected technology could include transformers, generators and other industrial control equipment used to operate power plants or substations. Energy may examine associated software, firmware, remote-access capabilities and the mechanisms vendors use to update equipment throughout its lifespan.&lt;/p&gt;

&lt;p&gt;That provision reflects concern that foreign suppliers could build hidden access into grid equipment or retain the ability to reach it remotely after installation. The administration also contends that reliance on overseas manufacturers could leave the United States without critical replacement parts during disruptions in international trade.&lt;/p&gt;

&lt;p&gt;The directive does not name China or any individual company. Covered foreign entities include countries subject to certain U.S. arms embargoes or sanctions, as well as people and companies controlled by or operating under the direction of those governments. Energy can also designate other countries or entities whose conduct it determines is harmful to U.S. national security or foreign policy.&lt;/p&gt;

&lt;p&gt;But the spectre of China appears to loom over the policy. During Trump&amp;rsquo;s first term, the Energy Department used a&lt;a href="https://www.nextgov.com/cybersecurity/2020/05/citing-cyber-threats-trump-orders-ban-buying-energy-sector-equipment-foreign-adversaries/165083/"&gt; similar 2020 executive order&lt;/a&gt; to prohibit certain Chinese equipment from being installed by utilities serving critical defense facilities.&lt;/p&gt;

&lt;p&gt;The move also comes amid broader warnings about Chinese efforts to establish access inside American infrastructure before a potential conflict. U.S. agencies&lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a"&gt; assessed in 2024&lt;/a&gt; that the state-backed hacking group Volt Typhoon had compromised multiple critical infrastructure organizations, including in the energy sector, and was seeking covert access that could be used to disrupt essential services during a crisis involving Taiwan.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Thursday order does not estimate how much replacement or mitigation efforts could cost.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The White House also tied the action to increasing electricity demands. The rapid growth of data centers, which has become a &lt;a href="https://www.brookings.edu/articles/why-data-centers-are-a-top-issue-in-the-2026-midterms/"&gt;political flashpoint&lt;/a&gt; as midterm elections approach, has made electricity access more important and increased the potential consequences of a successful attack or supply disruption, a&lt;a href="https://www.whitehouse.gov/fact-sheets/2026/08/fact-sheet-president-donald-j-trump-declares-a-national-emergency-to-secure-americas-bulk-power-system/"&gt; White House fact sheet&lt;/a&gt; argues.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/28/GettyImages_2290036156/large.jpg" width="618" height="284"><media:credit>Photography by TIL/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/28/GettyImages_2290036156/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>ATF investigating ‘major’ cyber incident after ransomware group claim</title><link>https://www.nextgov.com/cybersecurity/2026/08/atf-investigating-major-cyber-incident-after-ransomware-group-claim/415668/</link><description>The agency says the affected system was isolated from its broader network and eForms platform but has not disclosed whether data was stolen.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 27 Aug 2026 10:17:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/atf-investigating-major-cyber-incident-after-ransomware-group-claim/415668/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Bureau of Alcohol, Tobacco, Firearms and Explosives is &lt;a href="https://www.atf.gov/news/press-releases/atf-responds-to-cybersecurity-incident"&gt;investigating&lt;/a&gt; a cybersecurity event affecting one of its systems, which Justice Department officials have designated a &amp;ldquo;major incident&amp;rdquo; under federal guidelines.&lt;/p&gt;

&lt;p&gt;The disclosure came after the ransomware group Qilin listed ATF on its dark-web leak site and claimed to have compromised the agency. ATF has not attributed the incident to Qilin or said whether ransomware was involved.&lt;/p&gt;

&lt;p&gt;The bureau, housed within the Justice Department, said the affected system operates separately from its main computer network. The agency found no indication that the incident spread to its broader network, its electronic firearms application platform or any other ATF system.&lt;/p&gt;

&lt;p&gt;The eForms platform allows members of the firearms industry and the public to electronically submit applications involving weapons regulated under the National Firearms Act, including silencers, short-barreled rifles and machine guns.&lt;/p&gt;

&lt;p&gt;The Record&amp;nbsp;&lt;a href="https://therecord.media/doj-atf-cyberattack-qilin-ransomware"&gt;reported&lt;/a&gt; the intrusion before ATF&lt;a href="https://www.atf.gov/news/press-releases/atf-responds-to-cybersecurity-incident"&gt; &lt;/a&gt;acknowledged it Wednesday. The agency said it disconnected the affected system and began examining it for evidence about how the intrusion occurred.&lt;/p&gt;

&lt;p&gt;ATF did not identify the affected system, say when the incident was discovered or disclose whether the intruders accessed or stole information. The agency did say the incident has not disrupted its operations or affected its ability to carry out its law enforcement and regulatory missions.&lt;/p&gt;

&lt;p&gt;The &amp;ldquo;major incident&amp;rdquo; designation is likely a formal classification under the Federal Information Security Modernization Act, or FISMA. Federal guidelines generally apply the label to incidents likely to cause significant harm to national security, public confidence, civil liberties, public health or safety, or government operations. The designation also triggers reporting requirements to Congress.&lt;/p&gt;

&lt;p&gt;ATF said the required notifications have been completed but did not explain what prompted Justice Department officials to classify the incident as major.&lt;/p&gt;

&lt;p&gt;The hack could be significant because ATF investigates firearms trafficking, violent criminal organizations, bombings, arson and illegal explosives. It also operates systems used to trace guns recovered by law enforcement and administers licensing and regulatory programs for firearms and explosives businesses.&lt;/p&gt;

&lt;p&gt;Qilin is generally deemed a ransomware-as-a-service operation, meaning its developers provide malware and supporting infrastructure to affiliates who conduct individual attacks, typically in exchange for a portion of any ransom. The group commonly attempts to steal data before threatening to publish it unless a victim pays.&lt;/p&gt;

&lt;p&gt;Cisco researchers last year &lt;a href="https://blog.talosintelligence.com/uncovering-qilin-attack-methods-exposed-through-multiple-cases/"&gt;described the group&lt;/a&gt; as one of the world&amp;rsquo;s most active ransomware operations, with victims spanning companies, hospitals and government organizations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The ATF incident follows several other breaches involving sensitive federal law enforcement systems this year. Hackers&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/hackers-breached-dhs-information-sharing-network-people-familiar-say/414534/"&gt; breached the Homeland Security Information Network&lt;/a&gt;, a Department of Homeland Security platform used to exchange sensitive information with federal, state, local and private-sector partners. Investigators later determined that intruders had remained inside the environment for weeks after suspicious activity was twice dismissed as harmless.&lt;/p&gt;

&lt;p&gt;A suspected China-linked group also &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/suspected-chinese-breach-fbi-system-exposed-surveillance-targets-phone-numbers/412612/"&gt;accessed&lt;/a&gt; an FBI system used to manage information about court-authorized surveillance operations earlier this year.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/27/082726ATFNG/large.jpg" width="618" height="284"><media:credit>Kevin Carter/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/27/082726ATFNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>White House to soon launch water provider cyber protection program</title><link>https://www.nextgov.com/cybersecurity/2026/08/white-house-soon-launch-water-provider-cyber-protection-program/415650/</link><description>The plans come as several states face water system intrusions from what some official suspect could be linked to Iran.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 26 Aug 2026 14:22:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/white-house-soon-launch-water-provider-cyber-protection-program/415650/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The White House will soon unveil a program designed to help protect water infrastructure providers from cyberattacks, which comes as multiple states face hacking attempts on their water systems that some officials suspect may be tied to Iran, according to a person with knowledge of the plans.&lt;/p&gt;

&lt;p&gt;The program, led by the Office of the National Cyber Director, would enlist a slew of private firms to help states with few cyber resources bolster their defenses against digital attacks on platforms that manage areas like water and wastewater transmission, said the person, who spoke on the condition of anonymity to communicate the plans.&lt;/p&gt;

&lt;p&gt;The program could be announced next week and may begin in Texas to serve as a testbed for other states that request services. Politico &lt;a href="https://www.politico.com/news/2026/08/26/white-house-program-private-companies-water-hacks-01050315"&gt;first reported&lt;/a&gt; the White House&amp;rsquo;s plans.&lt;/p&gt;

&lt;p&gt;Since around May, the White House has been discussing a slew of pilot programs for various critical infrastructure domains with the private sector, according to a second person with knowledge of those discussions, who said that it made sense for the water sector to be among those categories that would get assistance.&lt;/p&gt;

&lt;p&gt;An ONCD spokesperson did not immediately return a request for comment. It&amp;rsquo;s not clear how many companies, or which companies specifically, would be involved in the efforts.&lt;/p&gt;

&lt;p&gt;More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity, though state officials said they continued operating safely and experienced no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt;incident response&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Water systems are often the most underresourced forms of critical infrastructure in the cyberdefense landscape. Some industry groups have stepped up to &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/new-water-watch-center-launched-help-small-utilities-stop-cyberattacks/415288/"&gt;provide assistance&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;When policymakers used to ask what systems I was most concerned about, my answer was always water,&amp;rdquo; Cynthia Kaiser, the FBI&amp;rsquo;s former cyber deputy director, told &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;The incidents from this summer have shown how much the water industry needs the assistance,&amp;rdquo; she added.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think this is a great step;&amp;nbsp;however, we need to ensure that systems integrators for rural water utilities are looped in on deployments,&amp;rdquo; she advised, referring to providers that install equipment allowing utilities to manage their systems remotely. Several current and former officials have decried &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/new-water-watch-center-launched-help-small-utilities-stop-cyberattacks/415288/#:~:text=Retired%20Gen.%20Paul,inside%20water%20facilities."&gt;lax management of remote systems&lt;/a&gt; as a pathway that has let hackers get inside water infrastructure over the last several weeks.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/26/082626WHNG/large.jpg" width="618" height="284"><media:credit>Li Rui/Xinhua via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/26/082626WHNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>FBI disables China-linked hacking tools used against US agencies</title><link>https://www.nextgov.com/cybersecurity/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415646/</link><description>A hacking group used the tools to target networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the departments of Energy, Justice and Health and Human Services.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 26 Aug 2026 12:28:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/fbi-disables-china-linked-hacking-tools-used-against-us-agencies/415646/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The FBI seized three internet domains Wednesday that prosecutors say Chinese government-backed hackers used to target U.S. agencies, critical infrastructure and other networks.&lt;/p&gt;

&lt;p&gt;The Justice Department&lt;a href="https://www.justice.gov/opa/pr/justice-department-and-fbi-seize-platforms-operated-and-used-china-state-sponsored-hackers"&gt; attributed&lt;/a&gt; the tools, known as QScan and QTRouter, to a hacking group called QTFY.&lt;a href="https://www.justice.gov/opa/media/1459096/dl?inline"&gt; Court records&lt;/a&gt; say the group operates through Nanjing Xinjiuwei Network Technology Company, a private Chinese firm that sold hacking services to China&amp;rsquo;s main civilian intelligence agency and its military.&lt;/p&gt;

&lt;p&gt;The group targeted networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the Energy, Justice and Health and Human Services departments, according to an FBI affidavit. Hospitals, telecommunications providers, power companies, banks and defense contractors were also targeted.&lt;/p&gt;

&lt;p&gt;The filing does not say that every attempted attack succeeded. A 2019 attempt against NASA, for example, failed because the agency had already fixed the security flaw the hackers tried to exploit.&lt;/p&gt;

&lt;p&gt;China&amp;rsquo;s embassy in Washington, D.C. did not immediately respond to a request for comment. Chinese officials have repeatedly denied Beijing sponsors hacking operations against the United States.&lt;/p&gt;

&lt;p&gt;QScan was used to look for weak spots while QTRouter helped the hackers hide. QScan searched the internet for vulnerable systems and tried to break into them. QTRouter sent the hackers&amp;rsquo; traffic through hijacked routers and other internet-connected devices, commercial proxy services and rented servers. The setup was meant to make the activity appear to come from somewhere other than China.&lt;/p&gt;

&lt;p&gt;QScan carried code for more than 200 different attacks and could work on a massive scale. On one day in 2024, it processed more than 2 million scanning or exploitation tasks, according to the affidavit.&lt;/p&gt;

&lt;p&gt;Lumen Technologies, which tracked the same infrastructure for roughly a year, described the operator as an &amp;ldquo;&lt;a href="https://www.lumen.com/blog/en-us/the-infrastructure-quartermaster-inside-a-china-nexus-state-enablement-model"&gt;infrastructure quartermaster&lt;/a&gt;&amp;rdquo; that provided other China-linked hackers with a ready-made service for finding targets and hiding their tracks. Lumen said networks first examined by QScan were later seen communicating through the group&amp;rsquo;s concealed network, suggesting some operations had moved from scouting targets toward attempts to break in. The system also mixed malicious traffic with that of ordinary internet users, making it harder to spot and block.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These tools were used by PRC cyber actors to hide the origin of their attacks,&amp;rdquo; FBI Director Kash Patel said Wednesday.&lt;/p&gt;

&lt;p&gt;Investigators said QTFY could take advantage of newly discovered security flaws quickly and at a large scale. In May 2024, the group allegedly exploited a flaw in Check Point security equipment shortly after it became public, stealing server settings and user account information from more than 300 U.S. organizations, according to court documents.&lt;/p&gt;

&lt;p&gt;Several months later, the hackers allegedly used a previously unknown flaw in an Ivanti product to access three national laboratories, NIH, another HHS agency and a U.S. security-device manufacturer.&lt;/p&gt;

&lt;p&gt;Investigators also tied the group&amp;rsquo;s infrastructure to attempted attacks against an Ohio medical center during the COVID-19 pandemic, financial organizations in Michigan and South Korea and an insurance organization in Missouri.&lt;/p&gt;

&lt;p&gt;The case highlights how Chinese intelligence and military agencies continue to heavily &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/researchers-detail-new-gray-zone-conflict-ai-driven-chinese-propaganda/407358/"&gt;rely on private companies&lt;/a&gt; for cyber operations and services.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Wednesday&amp;rsquo;s announcement follows years of similar FBI operations against Chinese hacking infrastructure. The bureau last year&lt;a href="https://www.nextgov.com/cybersecurity/2025/01/fbi-deleted-chinese-malware-4200-us-computers/402174/"&gt; removed PlugX surveillance malware&lt;/a&gt; from more than 4,200 U.S. computers infected by another state-backed hacking group.&lt;/p&gt;

&lt;p&gt;Federal authorities have also&lt;a href="https://www.nextgov.com/cybersecurity/2025/01/us-sanctions-chinese-company-helped-facilitate-espionage-hacks/401939/"&gt; dismantled&lt;/a&gt; a network of compromised routers, cameras and other devices associated with Flax Typhoon and&lt;a href="https://www.nextgov.com/cybersecurity/2024/01/us-disrupts-china-linked-cyber-campaign-impacting-critical-infrastructure-justice-officials-say/393794/"&gt; &lt;/a&gt;disrupted a separate network &lt;a href="https://www.nextgov.com/cybersecurity/2024/01/us-disrupts-china-linked-cyber-campaign-impacting-critical-infrastructure-justice-officials-say/393794/"&gt;used by prominent Chinese hacking collective Volt Typhoon&lt;/a&gt; to hide attacks against U.S. critical infrastructure.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/26/082626ChinaNG/large.jpg" width="618" height="284"><media:credit>kritsapong jieantaratip/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/26/082626ChinaNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Treasury sanctions Iranian hackers tied to critical infrastructure breaches</title><link>https://www.nextgov.com/cybersecurity/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415619/</link><description>Four of the five people named in the cyber action were also charged last week in the Justice Department’s expanded Mabna Institute case.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 25 Aug 2026 11:37:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/treasury-sanctions-iranian-hackers-tied-critical-infrastructure-breaches/415619/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Treasury Department sanctioned five Iranian nationals on Monday over alleged cyberattacks and theft targeting U.S. critical infrastructure, government offices and digital assets.&lt;/p&gt;

&lt;p&gt;The designations were part of a&lt;a href="https://home.treasury.gov/news/press-releases/sb0613"&gt; much broader sanctions package&lt;/a&gt; that Treasury Secretary Scott Bessent billed as an &amp;ldquo;economic D-Day&amp;rdquo; aimed at isolating Iran and cutting off its sources of revenue during the ongoing war.&lt;/p&gt;

&lt;p&gt;Treasury accused four of the individuals &amp;mdash; Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda&amp;rsquo;i and Mojtaba Ghal&amp;rsquo;eh-Kuhi &amp;mdash; of participating in a hacking operation directed by Iran&amp;rsquo;s Ministry of Intelligence and Security.&lt;/p&gt;

&lt;p&gt;Blagh, Balujeh and Kadkhoda&amp;rsquo;i allegedly carried out most of the group&amp;rsquo;s intrusions. Since late 2023, they have breached and stolen data from U.S. energy companies, defense contractors, health care institutions, technology firms and financial institutions, according to the department. The three are believed to have also compromised several local, state and federal government offices during the summer of 2024.&lt;/p&gt;

&lt;p&gt;Treasury said Ghal&amp;rsquo;eh-Kuhi and Behzad Mesri, who was previously sanctioned in 2018, have led the group since at least 2023. The hackers regularly conducted operations for the intelligence ministry, though officials said personal profit also played a significant role in their activity.&lt;/p&gt;

&lt;p&gt;The department separately sanctioned Arman Kahzadian, another alleged member of the network who focused on digital asset theft. Treasury said Kahzadian illicitly took control of a cryptocurrency wallet holding more than $30,000 in Bitcoin in 2023.&lt;/p&gt;

&lt;p&gt;Other members sometimes turned their attention to targets inside Iran. Ghal&amp;rsquo;eh-Kuhi and Balujeh allegedly stole data from an Iranian telecommunications company in 2025. Treasury said that activity reflected the hackers&amp;rsquo; willingness to put their own financial interests ahead of work benefiting Tehran.&lt;/p&gt;

&lt;p&gt;Four of the five people sanctioned Monday were also charged last week in the Justice Department&amp;rsquo;s&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/"&gt; expanded case&lt;/a&gt; against 17 Iranian cyber actors affiliated with the Mabna Institute. Prosecutors have accused the Tehran-based firm of conducting a sprawling hacking-for-hire campaign for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian partners. The group allegedly breached universities, government agencies and companies while stealing more than 31 terabytes of academic research and intellectual property.&lt;/p&gt;

&lt;p&gt;The sanctions come amid heightened concern about Iran&amp;rsquo;s ability to reach vulnerable U.S. infrastructure. CISA and the FBI have recently helped water utilities recover from&lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt; cyberattacks affecting at least 12 states&lt;/a&gt;. Some U.S. officials suspect Iran-linked hackers were responsible, although CISA has not publicly attributed those intrusions.&lt;/p&gt;

&lt;p&gt;Federal agencies also warned earlier this year that&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt; &lt;/a&gt;Iran-aligned groups were &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;targeting&lt;/a&gt; industrial control systems used across the energy, water and government sectors.&lt;/p&gt;

&lt;p&gt;The cyber sanctions were part of a broader package targeting nearly 60 people, companies and vessels tied to Iran&amp;rsquo;s nuclear and missile programs, oil trade and hacking operations. The moves block assets under U.S. control and generally prohibit Americans from doing business with those designated. Treasury also expanded sanctions categories to target people and companies operating in Iran&amp;rsquo;s digital assets, technology, gold, aviation and shipping sectors.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/25/082526TreasuryNG/large.jpg" width="618" height="284"><media:description>Treasury Secretary Scott Bessent speaks during a press conference at the Cash Room of the Treasury Department in Washington, D.C., on August 24, 2026, as he announces a new set of sanctions against Iran, describing the measures as âan economic D-Day.</media:description><media:credit>Mehmet Eser/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/25/082526TreasuryNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Treasury launches task force to prepare financial sector for quantum cyber threats</title><link>https://www.nextgov.com/cybersecurity/2026/08/treasury-launches-task-force-prepare-financial-sector-quantum-cyber-threats/415601/</link><description>The public-private task force will focus on moving financial institutions to quantum-resistant technology and addressing risks created by vendors and digital assets.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 24 Aug 2026 15:58:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/treasury-launches-task-force-prepare-financial-sector-quantum-cyber-threats/415601/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Treasury Department announced a new effort Monday to help the financial sector replace widely used cryptographic tools that could eventually be broken by quantum computers.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://home.treasury.gov/news/press-releases/sb0615/"&gt; Quantum-Readiness Task Force&lt;/a&gt; will bring together government officials, financial institutions, market infrastructure operators and technology providers to coordinate the shift to post-quantum cryptography. Those protections are designed to withstand attacks from both conventional computers and future, more powerful quantum systems.&lt;/p&gt;

&lt;p&gt;Financial institutions are widely considered high-value targets for hackers because they hold vast amounts of money and sensitive data and operate payment systems whose disruption can ripple across the economy.&lt;/p&gt;

&lt;p&gt;A sufficiently advanced quantum computer could break many of the cryptographic tools that protect financial records, payment systems and market transactions. The technology does not yet exist, though cyber adversaries can collect encrypted information today and retain it in hopes of decrypting it once quantum capabilities improve, in a practice commonly dubbed&amp;nbsp;&amp;ldquo;harvest now, decrypt later.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Treasury task force will divide its work among coordinating the financial sector&amp;rsquo;s broader post-quantum transition, assessing the readiness of technology vendors and other third parties and examining risks involving digital assets and emerging technologies.&lt;/p&gt;

&lt;p&gt;Treasury said the group will also work to identify critical dependencies, improve interoperability and promote &amp;ldquo;cryptographic agility,&amp;rdquo; or the ability to replace encryption methods as security standards and threats change.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Post-quantum cryptography readiness is no longer a future-proofing exercise &amp;mdash; it is a present-day risk control,&amp;rdquo; said Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group. Guild said organizations will need to prioritize their most important systems while managing dependencies throughout the financial ecosystem.&lt;/p&gt;

&lt;p&gt;The task force builds on a&lt;a href="https://home.treasury.gov/news/press-releases/sb0355"&gt; roadmap released in January&lt;/a&gt; by the G7 Cyber Expert Group, which is co-chaired by Treasury and the Bank of England. The roadmap calls on financial institutions to inventory where cryptography is used, assess their most sensitive systems and data, develop migration plans and test quantum-resistant technology.&lt;/p&gt;

&lt;p&gt;The G7 document points to 2035 as a general target for completing the financial sector&amp;rsquo;s transition, though it describes that timeline as nonbinding and &lt;a href="https://globalriskinstitute.org/publication/quantum-threat-timeline-report-2025b/"&gt;subject to change&lt;/a&gt; as quantum technology develops.&lt;/p&gt;

&lt;p&gt;Treasury&amp;rsquo;s announcement also follows President Donald Trump&amp;rsquo;s&lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/"&gt; June executive order&lt;/a&gt; directing the federal government and critical infrastructure sectors to &lt;a href="https://www.nextgov.com/emerging-tech/2026/06/white-house-expected-direct-intelligence-agencies-protect-quantum-research-foreign-threats/414308/"&gt;accelerate preparations&lt;/a&gt; for quantum-backed cyber threats.&lt;/p&gt;

&lt;p&gt;The Office of Management and Budget subsequently told agencies to inventory their cryptographic systems and account for software vendors and other third parties in their migration plans,&lt;a href="https://www.nextgov.com/emerging-tech/2026/06/omb-issues-instructions-agency-migration-quantum-proof-encryption/414429/"&gt; as &lt;em&gt;Nextgov/FCW&lt;/em&gt; previously reported&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Federal agencies have also begun applying those instructions to individual systems. The General Services Administration &lt;a href="https://www.nextgov.com/emerging-tech/2026/08/gsa-begins-quantum-security-efforts-digital-and-physical-systems/415583/"&gt;said Monday&lt;/a&gt; that it is updating the government&amp;rsquo;s identity and access-management framework and expanding security testing for federal building credentials to accommodate quantum-resistant technology.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/24/082426TreasuryNG/large.jpg" width="618" height="284"><media:credit>Mehmet Eser/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/24/082426TreasuryNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DOJ charges 17 Iranians in cybertheft campaign</title><link>https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/</link><description>Prosecutors say the Mabna Institute — which conducted intrusions for Iran’s Islamic Revolutionary Guard Corps, among other campaigns — stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 19 Aug 2026 12:13:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal prosecutors have charged 17 Iranians affiliated with the Tehran-based Mabna Institute over an alleged hacking-for-hire operation that stole research and intellectual property from hundreds of universities and compromised email accounts belonging to U.S. government agencies and companies.&lt;/p&gt;

&lt;p&gt;The&amp;nbsp;&lt;a href="https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary"&gt;14-count superseding indictment&lt;/a&gt;, unsealed Tuesday, adds eight defendants to a case brought against nine other members of the firm in 2018. Prosecutors said the expanded charges expose a broader network that conducted cyber intrusions for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian government and university clients.&lt;/p&gt;

&lt;p&gt;The Mabna Institute targeted systems belonging to 144 U.S. universities, 178 universities abroad, at least 42 U.S. companies, 11 foreign companies and at least five federal and state government agencies since around 2013, according to the Justice Department.&lt;/p&gt;

&lt;p&gt;The victims included the Labor Department, Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. The hackers also allegedly targeted HBO and unnamed technology firms and defense contractors.&lt;/p&gt;

&lt;p&gt;Prosecutors said the university campaign targeted more than 100,000 professors&amp;rsquo; accounts worldwide and successfully compromised approximately 8,000. The hackers used stolen credentials to access journals, dissertations, electronic books and other research spanning fields ranging from medicine and engineering to the social sciences.&lt;/p&gt;

&lt;p&gt;All told, the group allegedly stole at least 31.5 terabytes of academic data and intellectual property. U.S. universities had spent more than $3.4 billion to procure or obtain access to the targeted materials, although prosecutors did not characterize that entire amount as a financial loss from the theft.&lt;/p&gt;

&lt;p&gt;Some of the stolen material was later sold to customers in Iran through two websites. One offered academic resources taken from universities, while the other allowed customers to use compromised professors&amp;rsquo; accounts to enter university library systems directly, according to the indictment.&lt;/p&gt;

&lt;p&gt;Prosecutors said Mabna&amp;rsquo;s founders established the firm to help Iranian universities and research organizations obtain scientific resources from abroad. It employed or contracted with hackers who carried out phishing attacks, searched for vulnerable systems and traded credentials for compromised accounts.&lt;/p&gt;

&lt;p&gt;The defendants face charges that include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Some of the offenses carry maximum prison sentences of 20 years. The State Department is separately offering a reward of up to $10 million for information leading to the location of five of the defendants.&lt;/p&gt;

&lt;p&gt;The charges come amid concerns about Iran&amp;rsquo;s use of cyber operations during the ongoing war.&lt;/p&gt;

&lt;p&gt;Since U.S. and Israeli strikes began in February, suspected Iran-aligned groups have been linked to a&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt; &lt;/a&gt;disruptive attack against &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt;medical technology company Stryker&lt;/a&gt;, the&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412440/"&gt;compromise&lt;/a&gt; of FBI Director Kash Patel&amp;rsquo;s personal email and attacks against&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;industrial-control systems across several U.S. sectors&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;More than 30 Minnesota water systems and water infrastructure in several other states have been &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/"&gt;targeted in the last month&lt;/a&gt; in activity some officials suspect may be tied to Iran. U.S. officials previously&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/us-officials-see-iran-cyber-threat-persisting-despite-preliminary-deal/414243/"&gt;told &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; that they expected Iranian and Iran-aligned cyber operations to continue regardless of whether fighting subsided.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926IranNG/large.jpg" width="618" height="284"><media:credit>Mojito_mak/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926IranNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The Russian hurdle in Trump’s new offensive cyber program</title><link>https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/</link><description>The White House wants private companies to help take down cybercriminals overseas. But in Russia, the line between criminal hackers and the government is difficult to draw.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 18 Aug 2026 15:26:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;President Donald Trump&amp;rsquo;s new plan to enlist private companies to help disrupt cybercriminals abroad may face a fundamental problem when it comes to Russia: distinguishing criminal hackers and state-backed operatives.&lt;/p&gt;

&lt;p&gt;Russian intelligence services have long tolerated, protected or intermittently recruited financially-motivated hackers without exercising full control over them. That dynamic gives Moscow easier access to hacking talent, and it complicates a major carveout in Trump&amp;rsquo;s new directive that excludes groups part of or directed by a foreign government, experts and former U.S. officials say.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The line between government control, government-affiliated and government-acknowledged is certainly blurry in Russia,&amp;rdquo; said Michael Daniel, president and CEO of the Cyber Threat Alliance and a former White House cybersecurity coordinator under President Barack Obama. &amp;ldquo;Determining the exact relationship between malicious actors and the Russian government has long been a challenge and is often impossible.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;A White House &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/"&gt;memorandum&lt;/a&gt; signed last week paves the way for vetted U.S. companies to conduct cyber surveillance and operations that manipulate, disrupt and destroy systems used by foreign criminal groups. Companies would work under contracts with the Justice Department and Department of Homeland Security, and every operation would require written approval.&lt;/p&gt;

&lt;p&gt;The memo says eligible targets cannot be &amp;ldquo;an institutional part of a foreign government&amp;rdquo; or &amp;ldquo;wholly operated under a foreign government&amp;rsquo;s direction.&amp;rdquo; It then instructs officials to assume a group is not part of, or wholly controlled by, a foreign government unless &amp;ldquo;clear intelligence&amp;rdquo; establishes that connection.&lt;/p&gt;

&lt;p&gt;Such intelligence collection from spy agencies like the National Security Agency and CIA can help firms determine targeting criteria, though it may not be enough for Russia&amp;rsquo;s ever-evolving cyber landscape.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Russia&amp;rsquo;s cyber web is opaque and always shifting, blurring lines between government and cybercriminal, with no single rule for understanding each and every relationship,&amp;rdquo; said Justin Sherman, CEO of Global Cyber Strategies, a Washington, D.C.-based research and advisory firm.&lt;/p&gt;

&lt;p&gt;Some of that ambiguity is intentional and allows the Kremlin to expand the pool of hackers it can covertly draw upon, Sherman said. It also reflects broader and pervasive corruption conditions inside Russia.&lt;/p&gt;

&lt;p&gt;U.S. companies may have insights about those groups but lack the broader intelligence available to the government. Federal agencies, meanwhile, can only share or declassify so much, he said. &amp;ldquo;Private companies have critical insights in some ways and limited in others,&amp;rdquo; Sherman said. With an incomplete picture, &amp;ldquo;you&amp;rsquo;re bound to get it wrong some of the time.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Simple indicators don&amp;rsquo;t necessarily settle attribution questions, he added. Ties with the FSB &amp;mdash; Russia&amp;rsquo;s Federal Security Service that succeeded the Soviet Union&amp;rsquo;s KGB &amp;mdash; do not by themselves prove that a criminal group is state-directed, nor does a Russian intelligence service&amp;rsquo;s use of tools developed by criminals establish continuous government control.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Simple, bumper sticker ideas for deciding if a Russian cybercriminal is a state actor or not will often collapse in practice,&amp;rdquo; said Sherman.&lt;/p&gt;

&lt;p&gt;Past cases illustrate how those relationships can work. In 2017, the &lt;a href="https://www.justice.gov/archives/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-millions"&gt;DOJ charged&lt;/a&gt; two FSB officers with directing and protecting criminal hackers involved in the breach of Yahoo. Prosecutors said one of the hackers also conducted separate intrusions for personal profit. The Treasury Department has similarly said Maksim Yakubets, the alleged leader of the Evil Corp cybercrime organization, &lt;a href="https://home.treasury.gov/news/press-releases/sm845"&gt;worked for the FSB&lt;/a&gt; and was tasked with projects on behalf of the Russian state while his organization carried out financially motivated attacks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Russians haven&amp;rsquo;t been strangers to using private sector proxies to get what they want, as long as they&amp;rsquo;re not attacking them,&amp;rdquo; said Chris Painter, a former State Department cyber coordinator and White House cyber official. He questioned how a company could determine where a particular group falls along that continuum when the answer is often not immediately apparent, even for well-resourced governments.&lt;/p&gt;

&lt;p&gt;The new policy is the latest step in an offensive cyber posture the administration has been building for the last year. Trump&amp;rsquo;s &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt;national cybersecurity strategy&lt;/a&gt;, released in March, called for &amp;ldquo;unprecedented coordination&amp;rdquo; between government and industry on offensive and defensive missions. It pledged to &amp;ldquo;unleash the private sector&amp;rdquo; by creating incentives for companies to identify and disrupt adversary networks.&lt;/p&gt;

&lt;p&gt;But that set-up remained unclear for months. National Cyber Director Sean Cairncross&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/national-cyber-director-doesnt-envision-industry-doing-offensive-hacking/412176/"&gt; said shortly after&lt;/a&gt; the strategy&amp;rsquo;s release that he was &amp;ldquo;not talking about private sector, industry or companies engaged in a cyber offensive campaign.&amp;rdquo; Instead, he described companies sharing information and capabilities that would enable the government to respond.&lt;/p&gt;

&lt;p&gt;Some industry executives interviewed by &lt;em&gt;Nextgov/FCW&lt;/em&gt; in April nevertheless &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/us-push-counter-hackers-draws-industry-deeper-offensive-cyber-debate/412770/"&gt;predicted that the government would eventually contract with companies&lt;/a&gt; to support cyber operations. They also raised unresolved questions about legal authorities and how experts would define the fine line between creating obstacles for adversaries and hacking them offensively.&lt;/p&gt;

&lt;p&gt;The administration moved further in May when its &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/us-lists-offensive-cyberattacks-counterterrorism-strategy/413374/"&gt;counterterrorism strategy&lt;/a&gt; explicitly identified offensive cyber operations as one of the tools Washington could use against threatening groups and the states that support them. That document offered scant details about how such operations would work.&lt;/p&gt;

&lt;p&gt;Sherman argued that the U.S. shouldn&amp;rsquo;t let uncertainty about Russia&amp;rsquo;s cyber links stop it from taking action. The United States is overdue to reconsider assumptions about restraint and do more to counter Russia&amp;rsquo;s offensive cyber activity, he said, but a more aggressive posture does not make the underlying attribution decisions any easier.&lt;/p&gt;

&lt;p&gt;Daniel said that ambiguity could give Washington leverage. Moscow could either let an operation against known criminals go unanswered or object and risk exposing its ties to them.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The U.S. could use this formulation to call the Russians&amp;rsquo; bluff &amp;mdash; either acknowledge a relationship or let the group take the damage,&amp;rdquo; he said. But maintaining that bind would require the United States to choose its targets carefully. If a company inadvertently struck clandestine personnel from Moscow&amp;rsquo;s intelligence and security agencies, he added, the operation could create substantially greater consequences.&lt;/p&gt;

&lt;p&gt;Cybercriminals routinely operate through hijacked servers and systems belonging to &lt;a href="https://www.nextgov.com/cybersecurity/2026/06/hidden-market-turning-home-internet-connections-cover-hackers/414413/"&gt;unwitting third parties&lt;/a&gt;, meaning companies carrying out hacks may have to distinguish targeted criminals from the infrastructure they have compromised.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;A lot is left to be determined on how the oversight is going to work, how the targeting is going to work,&amp;rdquo; Painter said. &amp;ldquo;That&amp;rsquo;s all supposed to be decided in 60 days,&amp;rdquo; he said,&amp;nbsp;referring to the timeline the new policy must be developed by.&lt;/p&gt;

&lt;p&gt;Painter said the best version of the program would be a tightly controlled process in which the government uses intelligence provided by companies and its own agencies to select legitimate targets. Companies would likely want written assurances that the government had approved a target and that their actions were covered by the program, he said.&lt;/p&gt;

&lt;p&gt;The public directive does not explain how responsibility would be divided if a contractor followed an approved plan and the underlying intelligence proved wrong. Much of the operational process will also be governed by a classified annex.&lt;/p&gt;

&lt;p&gt;Coordinating government decisions and private-sector activity in something approaching real time will itself be difficult, Daniel said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;rsquo;t know of any analogous precedent,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;A DHS spokesperson did not respond to questions about how the administration would distinguish Russian cybercrime groups from state-linked actors or who would bear responsibility if a target were misidentified.&lt;/p&gt;

&lt;p&gt;The department &amp;ldquo;looks forward to implementing President Trump&amp;rsquo;s directive to combat cyber-enabled transnational crime threatening Americans and our businesses,&amp;rdquo; the spokesperson said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Last year alone, cyber-enabled Transnational Criminal Organizations stole more than $20 billion directly from Americans through rampant fraud, ransomware, and extortion schemes,&amp;rdquo; White House spokesperson Lauren Bis said when asked the same line of questions. &amp;ldquo;The Trump administration is mounting an aggressive campaign to disrupt these illicit syndicates and dismantle them at the source.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Justice and State departments did not provide comments. Russia&amp;rsquo;s embassy in Washington was also contacted.&lt;/p&gt;

&lt;p&gt;The prospect of operations against pro-Russia cybercriminals carries a possible diplomatic dimension. Trump has continued direct engagement with Russian President Vladimir Putin and has sought to broker an end to the war in Ukraine. The two leaders agreed in July to &lt;a href="https://www.reuters.com/world/europe/kremlin-says-putin-trump-agreed-during-weekend-call-talk-again-near-future-2026-07-06/"&gt;maintain contact and speak again&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The administration has previously adjusted its cyber posture during negotiations with Moscow. Rep. Don Bacon, R-Neb., who chairs the House Armed Services Committee&amp;rsquo;s cyber panel, &lt;a href="https://bacon.house.gov/news/documentsingle.aspx?DocumentID=2694"&gt;confirmed&lt;/a&gt; last year that Defense Secretary Pete Hegseth&lt;a href="https://www.nextgov.com/cybersecurity/2025/03/hegseth-orders-suspension-cyber-information-operations-planning-against-russia/403415/"&gt; ordered&lt;/a&gt; a brief pause in U.S. Cyber Command operations against Russia as the administration pursued Ukraine talks.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The memorandum requires coordination with the State Department, suggesting diplomatic consequences will be considered before an operation is approved. It does not say publicly how officials would weigh disrupting a Russian cybercrime group against other negotiations with the Kremlin.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If there&amp;rsquo;s a decision made that says we&amp;rsquo;re being careful with Russia now because we&amp;rsquo;re in some sensitive talks, that will play into it,&amp;rdquo; Painter said. Companies could also &amp;ldquo;paint the target on themselves&amp;rdquo; and face Russian retaliation if their involvement became public, he added. Even if a company is required to keep its role secret, it wouldn&amp;rsquo;t prevent an adversary or another party from exposing it.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I understand what they&amp;rsquo;re trying to do, and if it has really robust oversight, and including targeting and review and oversight of what they&amp;rsquo;re doing, it might work fine,&amp;rdquo; Painter said. &amp;ldquo;But there&amp;rsquo;s so much of a chance of that going wrong.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826TrumpPutinNG/large.jpg" width="618" height="284"><media:description>U.S. President Donald Trump (R) and Russian President Vladimir Putin arrive for a press conference at Joint Base Elmendorf-Richardson on August 15, 2025 in Anchorage, Alaska. </media:description><media:credit>Andrew Harnik/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826TrumpPutinNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA contemplates whether to hire security software buying help</title><link>https://www.nextgov.com/cybersecurity/2026/08/cisa-contemplates-whether-hire-security-software-buying-help/415486/</link><description>The Cybersecurity and Infrastructure Security Agency issued a sources sought notice that describes its desire to bring in a company that can help manage enterprise license and materials purchases.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Tue, 18 Aug 2026 12:56:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/cisa-contemplates-whether-hire-security-software-buying-help/415486/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Cybersecurity and Infrastructure&amp;nbsp;Security Agency is contemplating whether to hire a contractor to help manage its purchases of cybersecurity software and related tools via a single mechanism.&lt;/p&gt;

&lt;p&gt;CISA currently acquires the tools through the &lt;a href="https://www.washingtontechnology.com/contracts/2024/04/dhs-extends-civilian-network-cyber-contracts/395983/"&gt;Continuous Diagnostics and Mitigation program&lt;/a&gt; for protecting civilian government networks and Capacity Building, an arm of the agency that leads federal enterprise cyber governance efforts.&lt;/p&gt;

&lt;p&gt;By launching &lt;a href="https://sam.gov/workspace/contract/opp/a12bcbd9bfbc4e3ea64a0f8db379df70/view"&gt;this sources sought notice on Aug. 12&lt;/a&gt;, CISA is signaling the start of its evaluation of acquisition approaches that would support roughly $600 million in cyber software purchases per year.&lt;/p&gt;

&lt;p&gt;The agency eventually wants that figure to grow to $6 billion per year over the entire contract&amp;rsquo;s lifecycle, should a contract be created.&lt;/p&gt;

&lt;p&gt;CISA is working with the General Services Administration&amp;rsquo;s Assisted Acquisition Services team to evaluate the market research collected via the request for information. GSA AAS works with other agencies on planning, awarding and managing complex contracts.&lt;/p&gt;

&lt;p&gt;In the new notice, CISA describes its desire to bring in a contractor that can aid the agency in managing its enterprise license and materials purchases. The contractor would also work with CISA&amp;rsquo;s CB team to implement a singular software buying management process and procurement support platforms.&lt;/p&gt;

&lt;p&gt;CISA is undertaking this effort as part of its plans to transition away from the CDM program&amp;rsquo;s current approved product list to a new Cyber Product List and Technical Capability Catalog. The agency describes the latter two initiatives as its baselines for future enterprise cyber software procurements.&lt;/p&gt;

&lt;p&gt;The RFI describes the scope of work as covering strategic buying advisory services, acquisition and procurement support, enterprise license management, software asset management, category management, vendor management and procurement analytics. These services would be provided in addition to the cyber tools themselves.&lt;/p&gt;

&lt;p&gt;Other requirements include market analysis, historical spend analysis, pricing analysis, procurement strategy development, software category management, enterprise licensing recommendations, and development of cost savings metrics.&lt;/p&gt;

&lt;p&gt;Responses to the RFI are due by 5 p.m. ET&amp;nbsp;on Sept. 1.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/digital_code/large.jpg" width="618" height="284"><media:credit>Gettyimages.com / Fotograzia</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/digital_code/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item></channel></rss>