<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:nb="https://www.newsbreak.com/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>Nextgov/FCW - Cybersecurity</title><link>https://www.nextgov.com/cybersecurity/</link><description></description><atom:link href="https://www.nextgov.com/rss/cybersecurity/" rel="self"></atom:link><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 15:58:00 -0400</lastBuildDate><item><title>Treasury launches task force to prepare financial sector for quantum cyber threats</title><link>https://www.nextgov.com/cybersecurity/2026/08/treasury-launches-task-force-prepare-financial-sector-quantum-cyber-threats/415601/</link><description>The public-private task force will focus on moving financial institutions to quantum-resistant technology and addressing risks created by vendors and digital assets.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 24 Aug 2026 15:58:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/treasury-launches-task-force-prepare-financial-sector-quantum-cyber-threats/415601/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Treasury Department announced a new effort Monday to help the financial sector replace widely used cryptographic tools that could eventually be broken by quantum computers.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://home.treasury.gov/news/press-releases/sb0615/"&gt; Quantum-Readiness Task Force&lt;/a&gt; will bring together government officials, financial institutions, market infrastructure operators and technology providers to coordinate the shift to post-quantum cryptography. Those protections are designed to withstand attacks from both conventional computers and future, more powerful quantum systems.&lt;/p&gt;

&lt;p&gt;Financial institutions are widely considered high-value targets for hackers because they hold vast amounts of money and sensitive data and operate payment systems whose disruption can ripple across the economy.&lt;/p&gt;

&lt;p&gt;A sufficiently advanced quantum computer could break many of the cryptographic tools that protect financial records, payment systems and market transactions. The technology does not yet exist, though cyber adversaries can collect encrypted information today and retain it in hopes of decrypting it once quantum capabilities improve, in a practice commonly dubbed&amp;nbsp;&amp;ldquo;harvest now, decrypt later.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The Treasury task force will divide its work among coordinating the financial sector&amp;rsquo;s broader post-quantum transition, assessing the readiness of technology vendors and other third parties and examining risks involving digital assets and emerging technologies.&lt;/p&gt;

&lt;p&gt;Treasury said the group will also work to identify critical dependencies, improve interoperability and promote &amp;ldquo;cryptographic agility,&amp;rdquo; or the ability to replace encryption methods as security standards and threats change.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Post-quantum cryptography readiness is no longer a future-proofing exercise &amp;mdash; it is a present-day risk control,&amp;rdquo; said Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group. Guild said organizations will need to prioritize their most important systems while managing dependencies throughout the financial ecosystem.&lt;/p&gt;

&lt;p&gt;The task force builds on a&lt;a href="https://home.treasury.gov/news/press-releases/sb0355"&gt; roadmap released in January&lt;/a&gt; by the G7 Cyber Expert Group, which is co-chaired by Treasury and the Bank of England. The roadmap calls on financial institutions to inventory where cryptography is used, assess their most sensitive systems and data, develop migration plans and test quantum-resistant technology.&lt;/p&gt;

&lt;p&gt;The G7 document points to 2035 as a general target for completing the financial sector&amp;rsquo;s transition, though it describes that timeline as nonbinding and &lt;a href="https://globalriskinstitute.org/publication/quantum-threat-timeline-report-2025b/"&gt;subject to change&lt;/a&gt; as quantum technology develops.&lt;/p&gt;

&lt;p&gt;Treasury&amp;rsquo;s announcement also follows President Donald Trump&amp;rsquo;s&lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/"&gt; June executive order&lt;/a&gt; directing the federal government and critical infrastructure sectors to &lt;a href="https://www.nextgov.com/emerging-tech/2026/06/white-house-expected-direct-intelligence-agencies-protect-quantum-research-foreign-threats/414308/"&gt;accelerate preparations&lt;/a&gt; for quantum-backed cyber threats.&lt;/p&gt;

&lt;p&gt;The Office of Management and Budget subsequently told agencies to inventory their cryptographic systems and account for software vendors and other third parties in their migration plans,&lt;a href="https://www.nextgov.com/emerging-tech/2026/06/omb-issues-instructions-agency-migration-quantum-proof-encryption/414429/"&gt; as &lt;em&gt;Nextgov/FCW&lt;/em&gt; previously reported&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Federal agencies have also begun applying those instructions to individual systems. The General Services Administration &lt;a href="https://www.nextgov.com/emerging-tech/2026/08/gsa-begins-quantum-security-efforts-digital-and-physical-systems/415583/"&gt;said Monday&lt;/a&gt; that it is updating the government&amp;rsquo;s identity and access-management framework and expanding security testing for federal building credentials to accommodate quantum-resistant technology.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/24/082426TreasuryNG/large.jpg" width="618" height="284"><media:credit>Mehmet Eser/Anadolu via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/24/082426TreasuryNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>DOJ charges 17 Iranians in cybertheft campaign</title><link>https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/</link><description>Prosecutors say the Mabna Institute — which conducted intrusions for Iran’s Islamic Revolutionary Guard Corps, among other campaigns — stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 19 Aug 2026 12:13:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/doj-charges-17-iranians-cybertheft-campaign/415511/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal prosecutors have charged 17 Iranians affiliated with the Tehran-based Mabna Institute over an alleged hacking-for-hire operation that stole research and intellectual property from hundreds of universities and compromised email accounts belonging to U.S. government agencies and companies.&lt;/p&gt;

&lt;p&gt;The&amp;nbsp;&lt;a href="https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary"&gt;14-count superseding indictment&lt;/a&gt;, unsealed Tuesday, adds eight defendants to a case brought against nine other members of the firm in 2018. Prosecutors said the expanded charges expose a broader network that conducted cyber intrusions for Iran&amp;rsquo;s Islamic Revolutionary Guard Corps and other Iranian government and university clients.&lt;/p&gt;

&lt;p&gt;The Mabna Institute targeted systems belonging to 144 U.S. universities, 178 universities abroad, at least 42 U.S. companies, 11 foreign companies and at least five federal and state government agencies since around 2013, according to the Justice Department.&lt;/p&gt;

&lt;p&gt;The victims included the Labor Department, Federal Energy Regulatory Commission, the states of Hawaii and Indiana, the United Nations and UNICEF. The hackers also allegedly targeted HBO and unnamed technology firms and defense contractors.&lt;/p&gt;

&lt;p&gt;Prosecutors said the university campaign targeted more than 100,000 professors&amp;rsquo; accounts worldwide and successfully compromised approximately 8,000. The hackers used stolen credentials to access journals, dissertations, electronic books and other research spanning fields ranging from medicine and engineering to the social sciences.&lt;/p&gt;

&lt;p&gt;All told, the group allegedly stole at least 31.5 terabytes of academic data and intellectual property. U.S. universities had spent more than $3.4 billion to procure or obtain access to the targeted materials, although prosecutors did not characterize that entire amount as a financial loss from the theft.&lt;/p&gt;

&lt;p&gt;Some of the stolen material was later sold to customers in Iran through two websites. One offered academic resources taken from universities, while the other allowed customers to use compromised professors&amp;rsquo; accounts to enter university library systems directly, according to the indictment.&lt;/p&gt;

&lt;p&gt;Prosecutors said Mabna&amp;rsquo;s founders established the firm to help Iranian universities and research organizations obtain scientific resources from abroad. It employed or contracted with hackers who carried out phishing attacks, searched for vulnerable systems and traded credentials for compromised accounts.&lt;/p&gt;

&lt;p&gt;The defendants face charges that include conspiracy to commit computer intrusions, wire fraud and aggravated identity theft. Some of the offenses carry maximum prison sentences of 20 years. The State Department is separately offering a reward of up to $10 million for information leading to the location of five of the defendants.&lt;/p&gt;

&lt;p&gt;The charges come amid concerns about Iran&amp;rsquo;s use of cyber operations during the ongoing war.&lt;/p&gt;

&lt;p&gt;Since U.S. and Israeli strikes began in February, suspected Iran-aligned groups have been linked to a&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt; &lt;/a&gt;disruptive attack against &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt;medical technology company Stryker&lt;/a&gt;, the&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412440/"&gt;compromise&lt;/a&gt; of FBI Director Kash Patel&amp;rsquo;s personal email and attacks against&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;industrial-control systems across several U.S. sectors&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;More than 30 Minnesota water systems and water infrastructure in several other states have been &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/"&gt;targeted in the last month&lt;/a&gt; in activity some officials suspect may be tied to Iran. U.S. officials previously&amp;nbsp;&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/us-officials-see-iran-cyber-threat-persisting-despite-preliminary-deal/414243/"&gt;told &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; that they expected Iranian and Iran-aligned cyber operations to continue regardless of whether fighting subsided.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926IranNG/large.jpg" width="618" height="284"><media:credit>Mojito_mak/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/19/081926IranNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>The Russian hurdle in Trump’s new offensive cyber program</title><link>https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/</link><description>The White House wants private companies to help take down cybercriminals overseas. But in Russia, the line between criminal hackers and the government is difficult to draw.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 18 Aug 2026 15:26:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/russian-hurdle-trumps-new-offensive-cyber-program/415493/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;President Donald Trump&amp;rsquo;s new plan to enlist private companies to help disrupt cybercriminals abroad may face a fundamental problem when it comes to Russia: distinguishing criminal hackers and state-backed operatives.&lt;/p&gt;

&lt;p&gt;Russian intelligence services have long tolerated, protected or intermittently recruited financially-motivated hackers without exercising full control over them. That dynamic gives Moscow easier access to hacking talent, and it complicates a major carveout in Trump&amp;rsquo;s new directive that excludes groups part of or directed by a foreign government, experts and former U.S. officials say.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The line between government control, government-affiliated and government-acknowledged is certainly blurry in Russia,&amp;rdquo; said Michael Daniel, president and CEO of the Cyber Threat Alliance and a former White House cybersecurity coordinator under President Barack Obama. &amp;ldquo;Determining the exact relationship between malicious actors and the Russian government has long been a challenge and is often impossible.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;A White House &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/"&gt;memorandum&lt;/a&gt; signed last week paves the way for vetted U.S. companies to conduct cyber surveillance and operations that manipulate, disrupt and destroy systems used by foreign criminal groups. Companies would work under contracts with the Justice Department and Department of Homeland Security, and every operation would require written approval.&lt;/p&gt;

&lt;p&gt;The memo says eligible targets cannot be &amp;ldquo;an institutional part of a foreign government&amp;rdquo; or &amp;ldquo;wholly operated under a foreign government&amp;rsquo;s direction.&amp;rdquo; It then instructs officials to assume a group is not part of, or wholly controlled by, a foreign government unless &amp;ldquo;clear intelligence&amp;rdquo; establishes that connection.&lt;/p&gt;

&lt;p&gt;Such intelligence collection from spy agencies like the National Security Agency and CIA can help firms determine targeting criteria, though it may not be enough for Russia&amp;rsquo;s ever-evolving cyber landscape.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Russia&amp;rsquo;s cyber web is opaque and always shifting, blurring lines between government and cybercriminal, with no single rule for understanding each and every relationship,&amp;rdquo; said Justin Sherman, CEO of Global Cyber Strategies, a Washington, D.C.-based research and advisory firm.&lt;/p&gt;

&lt;p&gt;Some of that ambiguity is intentional and allows the Kremlin to expand the pool of hackers it can covertly draw upon, Sherman said. It also reflects broader and pervasive corruption conditions inside Russia.&lt;/p&gt;

&lt;p&gt;U.S. companies may have insights about those groups but lack the broader intelligence available to the government. Federal agencies, meanwhile, can only share or declassify so much, he said. &amp;ldquo;Private companies have critical insights in some ways and limited in others,&amp;rdquo; Sherman said. With an incomplete picture, &amp;ldquo;you&amp;rsquo;re bound to get it wrong some of the time.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Simple indicators don&amp;rsquo;t necessarily settle attribution questions, he added. Ties with the FSB &amp;mdash; Russia&amp;rsquo;s Federal Security Service that succeeded the Soviet Union&amp;rsquo;s KGB &amp;mdash; do not by themselves prove that a criminal group is state-directed, nor does a Russian intelligence service&amp;rsquo;s use of tools developed by criminals establish continuous government control.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Simple, bumper sticker ideas for deciding if a Russian cybercriminal is a state actor or not will often collapse in practice,&amp;rdquo; said Sherman.&lt;/p&gt;

&lt;p&gt;Past cases illustrate how those relationships can work. In 2017, the &lt;a href="https://www.justice.gov/archives/opa/pr/us-charges-russian-fsb-officers-and-their-criminal-conspirators-hacking-yahoo-and-millions"&gt;DOJ charged&lt;/a&gt; two FSB officers with directing and protecting criminal hackers involved in the breach of Yahoo. Prosecutors said one of the hackers also conducted separate intrusions for personal profit. The Treasury Department has similarly said Maksim Yakubets, the alleged leader of the Evil Corp cybercrime organization, &lt;a href="https://home.treasury.gov/news/press-releases/sm845"&gt;worked for the FSB&lt;/a&gt; and was tasked with projects on behalf of the Russian state while his organization carried out financially motivated attacks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Russians haven&amp;rsquo;t been strangers to using private sector proxies to get what they want, as long as they&amp;rsquo;re not attacking them,&amp;rdquo; said Chris Painter, a former State Department cyber coordinator and White House cyber official. He questioned how a company could determine where a particular group falls along that continuum when the answer is often not immediately apparent, even for well-resourced governments.&lt;/p&gt;

&lt;p&gt;The new policy is the latest step in an offensive cyber posture the administration has been building for the last year. Trump&amp;rsquo;s &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt;national cybersecurity strategy&lt;/a&gt;, released in March, called for &amp;ldquo;unprecedented coordination&amp;rdquo; between government and industry on offensive and defensive missions. It pledged to &amp;ldquo;unleash the private sector&amp;rdquo; by creating incentives for companies to identify and disrupt adversary networks.&lt;/p&gt;

&lt;p&gt;But that set-up remained unclear for months. National Cyber Director Sean Cairncross&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/national-cyber-director-doesnt-envision-industry-doing-offensive-hacking/412176/"&gt; said shortly after&lt;/a&gt; the strategy&amp;rsquo;s release that he was &amp;ldquo;not talking about private sector, industry or companies engaged in a cyber offensive campaign.&amp;rdquo; Instead, he described companies sharing information and capabilities that would enable the government to respond.&lt;/p&gt;

&lt;p&gt;Some industry executives interviewed by &lt;em&gt;Nextgov/FCW&lt;/em&gt; in April nevertheless &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/us-push-counter-hackers-draws-industry-deeper-offensive-cyber-debate/412770/"&gt;predicted that the government would eventually contract with companies&lt;/a&gt; to support cyber operations. They also raised unresolved questions about legal authorities and how experts would define the fine line between creating obstacles for adversaries and hacking them offensively.&lt;/p&gt;

&lt;p&gt;The administration moved further in May when its &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/us-lists-offensive-cyberattacks-counterterrorism-strategy/413374/"&gt;counterterrorism strategy&lt;/a&gt; explicitly identified offensive cyber operations as one of the tools Washington could use against threatening groups and the states that support them. That document offered scant details about how such operations would work.&lt;/p&gt;

&lt;p&gt;Sherman argued that the U.S. shouldn&amp;rsquo;t let uncertainty about Russia&amp;rsquo;s cyber links stop it from taking action. The United States is overdue to reconsider assumptions about restraint and do more to counter Russia&amp;rsquo;s offensive cyber activity, he said, but a more aggressive posture does not make the underlying attribution decisions any easier.&lt;/p&gt;

&lt;p&gt;Daniel said that ambiguity could give Washington leverage. Moscow could either let an operation against known criminals go unanswered or object and risk exposing its ties to them.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The U.S. could use this formulation to call the Russians&amp;rsquo; bluff &amp;mdash; either acknowledge a relationship or let the group take the damage,&amp;rdquo; he said. But maintaining that bind would require the United States to choose its targets carefully. If a company inadvertently struck clandestine personnel from Moscow&amp;rsquo;s intelligence and security agencies, he added, the operation could create substantially greater consequences.&lt;/p&gt;

&lt;p&gt;Cybercriminals routinely operate through hijacked servers and systems belonging to &lt;a href="https://www.nextgov.com/cybersecurity/2026/06/hidden-market-turning-home-internet-connections-cover-hackers/414413/"&gt;unwitting third parties&lt;/a&gt;, meaning companies carrying out hacks may have to distinguish targeted criminals from the infrastructure they have compromised.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;A lot is left to be determined on how the oversight is going to work, how the targeting is going to work,&amp;rdquo; Painter said. &amp;ldquo;That&amp;rsquo;s all supposed to be decided in 60 days,&amp;rdquo; he said,&amp;nbsp;referring to the timeline the new policy must be developed by.&lt;/p&gt;

&lt;p&gt;Painter said the best version of the program would be a tightly controlled process in which the government uses intelligence provided by companies and its own agencies to select legitimate targets. Companies would likely want written assurances that the government had approved a target and that their actions were covered by the program, he said.&lt;/p&gt;

&lt;p&gt;The public directive does not explain how responsibility would be divided if a contractor followed an approved plan and the underlying intelligence proved wrong. Much of the operational process will also be governed by a classified annex.&lt;/p&gt;

&lt;p&gt;Coordinating government decisions and private-sector activity in something approaching real time will itself be difficult, Daniel said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;rsquo;t know of any analogous precedent,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;A DHS spokesperson did not respond to questions about how the administration would distinguish Russian cybercrime groups from state-linked actors or who would bear responsibility if a target were misidentified.&lt;/p&gt;

&lt;p&gt;The department &amp;ldquo;looks forward to implementing President Trump&amp;rsquo;s directive to combat cyber-enabled transnational crime threatening Americans and our businesses,&amp;rdquo; the spokesperson said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Last year alone, cyber-enabled Transnational Criminal Organizations stole more than $20 billion directly from Americans through rampant fraud, ransomware, and extortion schemes,&amp;rdquo; White House spokesperson Lauren Bis said when asked the same line of questions. &amp;ldquo;The Trump administration is mounting an aggressive campaign to disrupt these illicit syndicates and dismantle them at the source.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Justice and State departments did not provide comments. Russia&amp;rsquo;s embassy in Washington was also contacted.&lt;/p&gt;

&lt;p&gt;The prospect of operations against pro-Russia cybercriminals carries a possible diplomatic dimension. Trump has continued direct engagement with Russian President Vladimir Putin and has sought to broker an end to the war in Ukraine. The two leaders agreed in July to &lt;a href="https://www.reuters.com/world/europe/kremlin-says-putin-trump-agreed-during-weekend-call-talk-again-near-future-2026-07-06/"&gt;maintain contact and speak again&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The administration has previously adjusted its cyber posture during negotiations with Moscow. Rep. Don Bacon, R-Neb., who chairs the House Armed Services Committee&amp;rsquo;s cyber panel, &lt;a href="https://bacon.house.gov/news/documentsingle.aspx?DocumentID=2694"&gt;confirmed&lt;/a&gt; last year that Defense Secretary Pete Hegseth&lt;a href="https://www.nextgov.com/cybersecurity/2025/03/hegseth-orders-suspension-cyber-information-operations-planning-against-russia/403415/"&gt; ordered&lt;/a&gt; a brief pause in U.S. Cyber Command operations against Russia as the administration pursued Ukraine talks.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The memorandum requires coordination with the State Department, suggesting diplomatic consequences will be considered before an operation is approved. It does not say publicly how officials would weigh disrupting a Russian cybercrime group against other negotiations with the Kremlin.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If there&amp;rsquo;s a decision made that says we&amp;rsquo;re being careful with Russia now because we&amp;rsquo;re in some sensitive talks, that will play into it,&amp;rdquo; Painter said. Companies could also &amp;ldquo;paint the target on themselves&amp;rdquo; and face Russian retaliation if their involvement became public, he added. Even if a company is required to keep its role secret, it wouldn&amp;rsquo;t prevent an adversary or another party from exposing it.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I understand what they&amp;rsquo;re trying to do, and if it has really robust oversight, and including targeting and review and oversight of what they&amp;rsquo;re doing, it might work fine,&amp;rdquo; Painter said. &amp;ldquo;But there&amp;rsquo;s so much of a chance of that going wrong.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826TrumpPutinNG/large.jpg" width="618" height="284"><media:description>U.S. President Donald Trump (R) and Russian President Vladimir Putin arrive for a press conference at Joint Base Elmendorf-Richardson on August 15, 2025 in Anchorage, Alaska. </media:description><media:credit>Andrew Harnik/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/081826TrumpPutinNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA contemplates whether to hire security software buying help</title><link>https://www.nextgov.com/cybersecurity/2026/08/cisa-contemplates-whether-hire-security-software-buying-help/415486/</link><description>The Cybersecurity and Infrastructure Security Agency issued a sources sought notice that describes its desire to bring in a company that can help manage enterprise license and materials purchases.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Ross Wilkers</dc:creator><pubDate>Tue, 18 Aug 2026 12:56:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/cisa-contemplates-whether-hire-security-software-buying-help/415486/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The Cybersecurity and Infrastructure&amp;nbsp;Security Agency is contemplating whether to hire a contractor to help manage its purchases of cybersecurity software and related tools via a single mechanism.&lt;/p&gt;

&lt;p&gt;CISA currently acquires the tools through the &lt;a href="https://www.washingtontechnology.com/contracts/2024/04/dhs-extends-civilian-network-cyber-contracts/395983/"&gt;Continuous Diagnostics and Mitigation program&lt;/a&gt; for protecting civilian government networks and Capacity Building, an arm of the agency that leads federal enterprise cyber governance efforts.&lt;/p&gt;

&lt;p&gt;By launching &lt;a href="https://sam.gov/workspace/contract/opp/a12bcbd9bfbc4e3ea64a0f8db379df70/view"&gt;this sources sought notice on Aug. 12&lt;/a&gt;, CISA is signaling the start of its evaluation of acquisition approaches that would support roughly $600 million in cyber software purchases per year.&lt;/p&gt;

&lt;p&gt;The agency eventually wants that figure to grow to $6 billion per year over the entire contract&amp;rsquo;s lifecycle, should a contract be created.&lt;/p&gt;

&lt;p&gt;CISA is working with the General Services Administration&amp;rsquo;s Assisted Acquisition Services team to evaluate the market research collected via the request for information. GSA AAS works with other agencies on planning, awarding and managing complex contracts.&lt;/p&gt;

&lt;p&gt;In the new notice, CISA describes its desire to bring in a contractor that can aid the agency in managing its enterprise license and materials purchases. The contractor would also work with CISA&amp;rsquo;s CB team to implement a singular software buying management process and procurement support platforms.&lt;/p&gt;

&lt;p&gt;CISA is undertaking this effort as part of its plans to transition away from the CDM program&amp;rsquo;s current approved product list to a new Cyber Product List and Technical Capability Catalog. The agency describes the latter two initiatives as its baselines for future enterprise cyber software procurements.&lt;/p&gt;

&lt;p&gt;The RFI describes the scope of work as covering strategic buying advisory services, acquisition and procurement support, enterprise license management, software asset management, category management, vendor management and procurement analytics. These services would be provided in addition to the cyber tools themselves.&lt;/p&gt;

&lt;p&gt;Other requirements include market analysis, historical spend analysis, pricing analysis, procurement strategy development, software category management, enterprise licensing recommendations, and development of cost savings metrics.&lt;/p&gt;

&lt;p&gt;Responses to the RFI are due by 5 p.m. ET&amp;nbsp;on Sept. 1.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/18/digital_code/large.jpg" width="618" height="284"><media:credit>Gettyimages.com / Fotograzia</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/18/digital_code/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>As warfare becomes engineering, the era of the digital mercenary dawns</title><link>https://www.nextgov.com/cybersecurity/2026/08/warfare-becomes-engineering-era-digital-mercenary-dawns/415442/</link><description>The White House revives “privateering for the digital age” by authorizing cyber firms to strike foreign targets.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Patrick Tucker</dc:creator><pubDate>Fri, 14 Aug 2026 20:28:52 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/warfare-becomes-engineering-era-digital-mercenary-dawns/415442/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Private cyber firms will be allowed to take action against foreign threats under a new White House policy, another step into a future where tech developers are ever more closely entwined with military operations, which now evolve faster than governments can keep up.&lt;/p&gt;

&lt;p&gt;Under the policy, &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/"&gt;announced&lt;/a&gt; Wednesday, the U.S. government will pay private cybersecurity companies to &amp;ldquo;manipulate,&amp;rdquo; &amp;ldquo;degrade,&amp;rdquo; &amp;ldquo;disrupt,&amp;rdquo; and &amp;ldquo;destroy&amp;rdquo; foreign adversary computer networks. The U.S. government historically reserves the right to take those sorts of actions, although they increasingly do so with help from front-line private workers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The companies will undergo vetting, be supervised by the departments of Justice and Homeland Security, and be forbidden to take actions that could &amp;ldquo;result in the loss of life or serious injury,&amp;rdquo; according to the presidential memo.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The United States just revived privateering for the digital age,&amp;rdquo; &lt;a href="https://controlsystemssecurity.com/posts/cyberteering-return-letter-marque-cyberspace.html"&gt;wrote&lt;/a&gt; Jeff Gray, who led training for DHS&amp;rsquo;s emergency response team and currently leads incident response training with the Cybersecurity and Infrastructure Security Agency.&lt;/p&gt;

&lt;p&gt;The phrase recalls the 17th and 18th centuries, when governments issued letters of marque that allowed swashbuckling sea captains to attack foreign merchant ships. That official authorization is what distinguished men like Captain Kidd and Henry Morgan as &amp;ldquo;privateers,&amp;rdquo; not pirates. But when they lost that marque, many, like Kidd, went on to be pirates anyway.&lt;/p&gt;

&lt;p&gt;Gray acknowledges that the term isn&amp;rsquo;t a perfect fit; for one thing, letters of marque are &lt;a href="https://constitution.congress.gov/browse/essay/artI-S8-C11-3-4/ALDE_00000196/"&gt;granted&lt;/a&gt; by Congress, not the president. Nevertheless, he says, &amp;ldquo;The government is authorizing private actors to conduct offensive cyber operations on its behalf, under its control. That&amp;#39;s privateering.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The memo says hiring private hackers is only logical:&amp;nbsp; &amp;ldquo;American businesses&amp;rsquo; innovative capabilities have historically been underutilized&amp;rdquo; to &amp;ldquo;secure a critical offensive cyber advantage for the United States.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Russia has been &lt;a href="https://www.defenseone.com/technology/2021/10/russian-corruption-makes-it-harder-crack-down-ransomware/186252/"&gt;doing&lt;/a&gt; this sort of thing for years: enlisting, or &lt;a href="https://therecord.media/a-conversation-with-alisa-esage-a-russian-hacker-who-had-her-company-sanctioned-after-the-2016-election"&gt;coercing&lt;/a&gt;, private companies and groups to carry out cyberattacks against Western targets.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;One cybersecurity exec said the policy makes sense, especially as AI gives adversaries more tools.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There will be more cyberattacks for sure, so I do think you want to expand the takedown activity as well,&amp;rdquo; said the executive, a founder of a prominent U.S. cybersecurity firm that works with the U.S. government.&lt;/p&gt;

&lt;p&gt;AI-assisted cyberattacks rose 89 percent in 2025, according to a February&lt;a href="https://go.crowdstrike.com/rs/281-OBQ-266/images/CrowdStrike-2026-Global-Threat-Report.pdf"&gt; report f&lt;/a&gt;rom cybersecurity company CrowdStrike.&lt;/p&gt;

&lt;p&gt;Gray also described the strategy as &amp;ldquo;strategically sound.&amp;rdquo; But he expects it to provoke a short-term increase in attacks, and over a longer timeframe, to cause adversaries to shift tactics, accelerate operations, and gain additional &amp;ldquo;cover&amp;rdquo; to hide their operations.&lt;/p&gt;

&lt;p&gt;Finally, Gray noted that law-enforcement agencies have long &lt;a href="https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks"&gt;hired&lt;/a&gt; private firms for this sort of work, particularly taking down &lt;a href="https://www.justice.gov/archives/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation#:~:text=%E2%80%9CBy%20working%20closely%20with%20WatchGuard%20and%20other,public%2Dprivate%20partnership%20brings%20to%20our%20country's%20cybersecurity."&gt;botnets&lt;/a&gt;. &amp;ldquo;The work is still the same. But the environment just got more complicated,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The cyber exec agreed. &amp;ldquo;Instead of a law-enforcement person pushing the button, it will be a private-sector person,&amp;rdquo; said the company founder. &amp;ldquo;I expect every Israeli cyber startup to jump at the chance.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Cyberops and physical war&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The policy is the latest indication that software weapons are &lt;a href="https://www.defenseone.com/business/2025/06/pentagon-pushes-us-dronemakers-innovate-quickly-ukraine-does/405739/"&gt;evolving&lt;/a&gt; to be as crucial as hardware on the modern battlefield&amp;mdash;and that is putting private coders and weapon designers &lt;a href="https://www.defenseone.com/technology/2024/10/us-made-jam-resistant-drones-are-helping-ukrainians-cut-through-russia-ew/400735/"&gt;closer&lt;/a&gt;&lt;strong&gt; &lt;/strong&gt;to real-world operations. In Ukraine, for example, engineers with drone maker Shield AI and other contractors work closely with soldiers, sometimes under fire, to modify weapons based on digital attacks.&lt;/p&gt;

&lt;p&gt;The job of fighting is, more and more, becoming a job of engineering, said one former senior defense official we spoke to in 2025, just after Donald Trump returned to office. The official said that the Pentagon&amp;rsquo;s new leaders were considering a plan to let drone makers and other tech companies conduct operations under company-owned, company-operated agreements.&lt;/p&gt;

&lt;p&gt;The idea was not without precedent. SpaceX operates the Starlink satellites that connect U.S. troops, rather than allowing U.S. personnel to do so. And under the first Trump administration, the Pentagon &lt;a href="https://www.anduril.com/news/special-operations-command-selects-anduril-industries-as-systems-integration-partner"&gt;paid&lt;/a&gt; Anduril to maintain and update drones in the field, deploying along with special operations forces.&lt;/p&gt;

&lt;p&gt;The official said putting engineers in the field is essential to getting new capabilities to the front lines faster.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;A lot of these technologies,&amp;rdquo; they said, are&amp;nbsp; &amp;ldquo;super exquisite, they&amp;#39;re fragile, they&amp;#39;re very technical. The people that built them are the ones that know how they work.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Having the weapons&amp;rsquo; makers observe and even operate their products in the field reduced red tape in getting new designs approved, changed, or deployed.&lt;/p&gt;

&lt;p&gt;The official last year acknowledged that most defense firms don&amp;rsquo;t operate that way, and federal law outlines boundaries on what defense contractors can and can&amp;rsquo;t do (engaging in combat is in the &amp;quot;can&amp;rsquo;t do&amp;quot; column). But ultimately, they said, &amp;ldquo;If you want capability in 2027 the only way you&amp;#39;re going to get is if this happens.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In April, CENTCOM &lt;a href="https://shield.ai/shield-ai-selected-by-u-s-navy-to-compete-for-800m-in-isr-services-with-v-bat/"&gt;hired&lt;/a&gt; Shield AI to provide intelligence, surveillance, and reconnaissance to U.S. forces with its V-BAT drone, under a contractor-owned, contractor-operated arrangement.&lt;/p&gt;

&lt;p&gt;Brandon Tseng, Shield AI&amp;rsquo;s co-founder, said of the agreement: &amp;ldquo;We aren&amp;rsquo;t just bringing the V-BAT product and service to the Navy; we&amp;rsquo;re bringing a world-class team with a wealth of operational experience and the ability to produce undeniable outcomes for our warfighters.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2197446878_1/large.jpg" width="618" height="284"><media:description>A 10th Mountain Division soldier operates a simulation of the Low Altitude Stalking and Strike Ordnance (LASSO) loitering munition during the Combined Resolve 25-1 exercise at the Hohenfels Training Area near Hohenfels, Germany, on February 3, 2025.</media:description><media:credit>Sean Gallup/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/14/GettyImages_2197446878_1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Trump admin empowers private US firms to go after transnational cybercriminals</title><link>https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/</link><description>“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [transnational criminal organizations’] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memo said.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Christian Robles</dc:creator><pubDate>Thu, 13 Aug 2026 12:40:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/trump-admin-gives-private-us-firms-ability-go-after-transnational-cybercriminals/415398/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The National Coordination Center will create a program allowing authorized U.S. companies to conduct cyber operations against transnational criminal organizations at the direction of the federal government, according to a &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/"&gt;memorandum&lt;/a&gt; signed by President Donald Trump on Wednesday.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Program executive directors from the departments of Homeland Security and Justice will have the authority to greenlight companies&amp;rsquo; cyber operations unless the authorization would result in a loss of life, serious injury or &amp;ldquo;rise to the level of use of forced or armed attack under international law.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The federal government would vet and conduct oversight of authorized companies, which would need to enter into contractual agreements with either DHS or Justice.&lt;/p&gt;

&lt;p&gt;The specific standards the government will use to screen the companies will be drafted by the program executive directors &amp;mdash; in coordination with the Homeland Security Council &amp;mdash; within 60 days of the memo&amp;rsquo;s signing. They will include technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence and reliability, according to the document.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The group will ensure that program participation criteria enable&amp;nbsp;involvement from large and small companies, and that operations target only transnational criminal organizations.&lt;/p&gt;

&lt;p&gt;The memo also allows participating companies to enter into commercial agreements with other private sector entities, federal agencies and state entities. The program executive directors will produce a report on the initiative&amp;rsquo;s status and submit it to the National Cyber Director and Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor.&lt;/p&gt;

&lt;p&gt;The cybersecurity program seeks to build on a &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/03/combating-cybercrime-fraud-and-predatory-schemes-against-american-citizens/"&gt;March executive order&lt;/a&gt; laying out steps to combat cybercrime. That order was released alongside a &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/trumps-new-cyber-strategy-details-more-offensive-response-cyber-threats/411963/"&gt;national security strategy&lt;/a&gt; that called for the government to more directly respond to adversarial threats and secure critical U.S. technologies.&lt;/p&gt;

&lt;p&gt;In a statement, Mike Centrella &amp;mdash; the head of public policy at SecurityScorecard &amp;mdash; said the document &amp;ldquo;represents an important shift in how the United States approaches cyber threats originating overseas.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Strengthening defenses remains critical, but the memorandum recognizes that addressing cybercrime also requires identifying and disrupting the infrastructure and networks that allow criminal organizations to operate,&amp;rdquo; he said, adding that the guidance &amp;ldquo;signals an evolution in public-private cybersecurity collaboration &amp;mdash; from primarily sharing information about threats toward combining government authorities with private-sector intelligence and capabilities to more actively disrupt them.&amp;quot;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2289620789/large.jpg" width="618" height="284"><media:description>US President Donald Trump gives a thumbs up before boarding Air Force One en route back to Washington, DC, at Cleveland Hopkins International Airport in Cleveland, Ohio on August 11, 2026. </media:description><media:credit>Jim WATSON / AFP via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/13/GettyImages_2289620789/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>NIST wants to outfit the National Vulnerability Database with AI</title><link>https://www.nextgov.com/cybersecurity/2026/08/nist-wants-outfit-national-vulnerability-database-ai/415371/</link><description>The National Institute of Standards and Technology is angling to modernize how it reports and responds to cyber vulnerabilities with the help of artificial intelligence.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Wed, 12 Aug 2026 14:22:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/nist-wants-outfit-national-vulnerability-database-ai/415371/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The National Institute of Standards and Technology is looking to augment its central repository of digital vulnerabilities with help from artificial intelligence.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In a new Request for Information &lt;a href="https://www.federalregister.gov/documents/2026/08/12/2026-16371/request-for-information-rfi-on-modernizing-the-national-vulnerability-database-in-the-age-of"&gt;published&lt;/a&gt; in the Federal Register on Wednesday, NIST said it is seeking input surrounding how to best modernize its National Vulnerability Database by leveraging AI to enhance how the agency documents and responds to identified cybersecurity weaknesses.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://nvd.nist.gov/"&gt;The NVD&lt;/a&gt; documents digital vulnerabilities, cataloguing their severity, impacted products and other relevant data. Some of the challenges to modernization the RFI seeks to address include growth in both the number and complexity of newly disclosed vulnerabilities, a diverse range in data quality, a reliance on automation and machine-readable security data and the emergence of AI-assisted vulnerability discovery.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The advancement of AI presents an opportunity to transform the vulnerability management ecosystem,&amp;rdquo; &lt;a href="https://public-inspection.federalregister.gov/2026-16371.pdf"&gt;the document reads&lt;/a&gt;. &amp;ldquo;This requires input from across the community to ensure this ecosystem is effective, scalable, and resilient in the face of emerging threats.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The RFI seeks feedback to better understand how AI tools can improve the broad vulnerability management lifecycle and ecosystem, enhance risk&amp;nbsp;assessment efforts and better remediate vulnerabilities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;NIST is also looking to learn more about what, if any, changes need to be made to existing organizational structures and standards to improve both the data quality and procedural handling of vulnerabilities.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Rapid advancements in AI technology and its impact &amp;ndash;&amp;ndash; both as an asset and adversary &amp;ndash;&amp;ndash; on cybersecurity has been a paramount tech policy issue, reaching a climax after models from both &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/"&gt;OpenAI and Anthropic escaping containment environments&lt;/a&gt;. Prior to these incidents, the White House had turned its attention to addressing the cybersecurity impacts of AI, including multiple cybersecurity action items in &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/06/trump-signs-ai-executive-order-after-postponement-last-month/413912/"&gt;a June executive order&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;As part of the EO, the Trump administration created an AI-supported vulnerability clearinghouse within &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/white-house-announces-gold-eagle-ai-clearinghouse-cyber-vulnerabilities/414768/"&gt;the new Gold Eagle initiative&lt;/a&gt;. Gold Eagle is primarily a coordinated vulnerability sharing effort. A NIST spokesperson told &lt;em&gt;Nextgov/FCW &lt;/em&gt;that its effort to modernize the NVD is not related to any recent executive action.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Our RFI is not in response to any specific executive orders or to the Gold Eagle Initiative,&amp;rdquo; the spokesperson said. &amp;ldquo;However, we expect that tools like the NVD will continue to play an important role in the broader vulnerability management and coordination ecosystem.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/12/860x394-1/large.jpg" width="618" height="284"><media:credit>R. Wilson/NIST</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/12/860x394-1/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Federal systems increasingly likely to face accidental AI breach after Hugging Face, experts say</title><link>https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/</link><description>Former officials and security experts say aged systems, contractors and agency AI adoption could open similar paths into government networks.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 10 Aug 2026 11:19:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/federal-systems-increasingly-likely-face-accidental-ai-breach-after-hugging-face-experts-say/415307/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; An OpenAI agent tasked with finding software flaws escaped its testing environment, hacked into Hugging Face and spent days moving through the company&amp;rsquo;s systems in search of answers to an evaluation. It had not been sent to attack the company, yet it did so anyway &amp;mdash; and a smattering of other accidental AI intrusions in separate environments have &lt;a href="https://www.theguardian.com/technology/2026/aug/05/openai-anthropic-models-went-rogue-cybersecurity-test-ai-security-institute"&gt;since followed&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;If the same chain of events began again, former officials and cybersecurity experts told &lt;em&gt;Nextgov/FCW&lt;/em&gt; there is little reason to assume a federal agency would be spared. In interviews during Black Hat and DEF CON this past week, they said aging networks, systems that are not properly separated and the government&amp;rsquo;s heavy reliance on contractors could present weaknesses that would let an unauthorized AI agent move from one environment into another before defenders realize.&lt;/p&gt;

&lt;p&gt;One former federal chief information officer likened the risk to turning loose a hunting dog: &amp;ldquo;If you&amp;rsquo;re going to put your dog in the yard and instruct it to hunt, probably best to ensure the back gate is closed.&amp;rdquo; The former official spoke on condition of anonymity to discuss their views more candidly.&lt;/p&gt;

&lt;p&gt;The&lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt; July intrusion&lt;/a&gt; began during an internal OpenAI test designed to measure how effectively advanced models could find and exploit vulnerabilities. OpenAI said the agent &amp;mdash; powered by GPT-5.6 Sol and a more capable internal research prototype &amp;mdash; was operating with some security safeguards intentionally reduced.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The agent exploited a previously unknown flaw in an internal package-management service, reached the public internet and commandeered a third-party code sandbox as a staging point. From there, it exploited two flaws in Hugging Face&amp;rsquo;s dataset-processing systems, obtained credentials, executed commands and moved through parts of the company&amp;rsquo;s infrastructure.&lt;/p&gt;

&lt;p&gt;In the leadup to the intrusion, OpenAI models created an internal message board, used it to trade hacking methods and found a way to bring it back even after humans shut it down, company engineers &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/08/openai-agents-rebuilt-internal-message-board-lead-hugging-face-breach/415240/"&gt;said in a presentation&lt;/a&gt; at the cyber conferences this past week.&lt;/p&gt;

&lt;p&gt;The agent deliberately exploited Hugging Face&amp;rsquo;s systems in pursuit of its assigned goal, but OpenAI had not instructed it to attack the company. Bob Costello, who served as chief information officer at the Cybersecurity and Infrastructure Security Agency before becoming chief digital and information officer at Merlin Group, said a similar federal incident could begin with authorized security testing.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;As we start using really advanced AI to operate our systems or penetration-test our systems or blue-red-purple team our systems,&amp;rdquo; he said, &amp;ldquo;maybe one of those kind of goes sideways, [and] takes a lateral system to the side.&amp;rdquo; The color-coding he described refers to red teams that simulate hackers, blue teams that defend systems and purple teams that combine both approaches to find digital weaknesses.&lt;/p&gt;

&lt;p&gt;That possibility is becoming more relevant as agencies begin experimenting with AI agents that can retrieve information and take actions. The General Services Administration is preparing a&lt;a href="https://www.gsa.gov/artificial-intelligence/ai-community-of-practice/events-and-training/2026-ai-hackathon"&gt; governmentwide hackathon&lt;/a&gt; in which federal, state and local employees will build connections between AI systems and agency data and public services, including prototypes that would let AI route data directly to an agency.&amp;nbsp;The work is slated to be conducted exclusively in sandboxed environments and will not involve any access to restricted data or production systems.&lt;/p&gt;

&lt;p&gt;Contractors may keep their federal and commercial systems separate, said Leslie Nielsen, the executive vice president and CISO at Mimecast, but the same employees may still access both: &amp;ldquo;There&amp;rsquo;s lots of people using it from both sides, and getting in through one could eventually lead to the other.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The chances of it happening again, I would say it&amp;rsquo;s going to,&amp;rdquo; he added. &amp;ldquo;Some of these [federal] infrastructures are just so big and, candidly, so old, that there are little nooks and crannies in them, they&amp;rsquo;re going to get teased out.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Asked to assess the likelihood of a comparable federal incident, Ellen Boehm, senior vice president of internet-of-things strategy and operations at Keyfactor, called it &amp;ldquo;pretty likely&amp;rdquo; and placed the odds at &amp;ldquo;seven out of 10.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Michael Leland, vice president and field chief technology officer at enterprise browser provider Island, said some civilian agencies are exposed because &amp;ldquo;they don&amp;rsquo;t have the infrastructure, they don&amp;rsquo;t have the talent, and they haven&amp;rsquo;t spent years building those guardrails or that containment because they didn&amp;rsquo;t have to.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It shouldn&amp;rsquo;t be different for AI because AI doesn&amp;rsquo;t care where it is,&amp;rdquo; Leland said. &amp;ldquo;It is opportunistic.&amp;rdquo; Agencies that don&amp;rsquo;t do national security work that have lower cyberdefense standards are &amp;ldquo;very much at risk,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;Bob Ackerman, co-founder and managing partner at cyber venture capital firm DataTribe, also said many organizations have embraced powerful AI systems before learning how to reliably control them.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We fundamentally are kidding ourselves that we&amp;rsquo;ve got this under control,&amp;rdquo; Ackerman said. &amp;ldquo;We&amp;rsquo;ve got a really, really powerful tool, but we don&amp;rsquo;t know how to control it yet.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;But people interviewed for this story largely rejected the idea that autonomous agents have rendered the government&amp;rsquo;s existing security playbook obsolete. The Hugging Face campaign relied on recognizable techniques like finding exposed systems, stealing credentials, escalating privileges and moving between connected environments, all of which are problems agencies have faced for years.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It&amp;rsquo;s really not gonna play out all that differently than if it was a hands-on keyboard actor &amp;hellip; or someone who&amp;rsquo;s writing a script and letting a programmatic algorithm go and do its thing,&amp;rdquo; said Ben Bernstein, who manages the cybersecurity advisors team at Huntress.&lt;/p&gt;

&lt;p&gt;The difference, ultimately, is tempo and scale. An AI hacker can probe potential routes, link digital weaknesses and iterate its maneuvers without the delays of human intervention. Such tools maintain a relentless fixation on specific targets, persisting with an objective well beyond the point where a human operative might question the value of taking their selected intrusion path. On top of it all, they don&amp;rsquo;t need to eat, sleep or take restroom breaks.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;An agent&amp;rsquo;s just a fast hacker at the end of the day, right?&amp;rdquo; Nielsen said. &amp;ldquo;But the one thing the agent doesn&amp;rsquo;t have is a moral or ethical compass. They&amp;rsquo;re given a task and they have focus, and they&amp;rsquo;re going to go do what you&amp;rsquo;ve told them to do.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;David Weston, Microsoft&amp;rsquo;s corporate vice president of agentic security, similarly cautioned against treating the federal government as a fundamentally different kind of target. The approach demonstrated in the Hugging Face breach &amp;ldquo;is going to be a challenge for most folks,&amp;rdquo; he said, but the response still comes down to basic security practices.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Regardless of the target, everyone needs to follow those fundamentals,&amp;rdquo; Weston added.&lt;/p&gt;

&lt;p&gt;Duncan Greatwood, CEO of Xage Security, also said agencies should not rely on simply telling an agent not to perform certain actions because those instructions can be bypassed. Instead, they should use separate security controls that technically prevent the agent from reaching systems or changing data it&amp;rsquo;s not authorized to touch. He described the approach as &amp;ldquo;bounded autonomy.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;You allow the agent to do stuff, but you&amp;rsquo;re not going to allow it to go crazy. You&amp;rsquo;re going to put hard bounds around it,&amp;rdquo; Greatwood said.&lt;/p&gt;

&lt;p&gt;Retired Gen. Paul Nakasone, the former director of U.S. Cyber Command and the NSA who now leads Vanderbilt University&amp;rsquo;s Institute of National Security and sits on OpenAI&amp;rsquo;s board, called the Hugging Face episode &amp;ldquo;an inflection point in terms of AI-generated autonomous cyber attack.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;My question is, how do we ensure that the defense starts to catch up, right?&amp;rdquo; Nakasone said. &amp;ldquo;How do we make sure that artificial intelligence is able to bring together a capable defense that allows us to do vulnerability detection, to do patching, to do incident response, and to do mitigation?&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Editor&amp;#39;s note: This article has been updated to clarify the participants in GSA&amp;#39;s upcoming hackathon and where the work will&amp;nbsp;occur.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2288181917/large.jpg" width="618" height="284"><media:description> Sam Altman, CEO of OpenAI, leaves a meeting at the U.S. Capitol on July 29, 2026 in Washington, DC. </media:description><media:credit>Kevin Dietsch / Staff  Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/10/GettyImages_2288181917/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Voting machine researchers say federal work abruptly ended after Trump ally pushed back on their findings</title><link>https://www.nextgov.com/cybersecurity/2026/08/voting-machine-researchers-say-federal-work-abruptly-ended-after-trump-ally-pushed-back-their-findings/415300/</link><description>Mojave Research executives said at DEF CON that the government had been preparing to expand the company’s election security work, and linked Trump adviser Kurt Olsen to pressure they faced after finding election system vulnerabilities but no evidence votes were altered.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Sun, 09 Aug 2026 06:00:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/voting-machine-researchers-say-federal-work-abruptly-ended-after-trump-ally-pushed-back-their-findings/415300/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; After spending roughly six weeks analyzing Dominion voting systems used in Puerto Rico&amp;rsquo;s 2024 elections, Mojave Research came back to the Trump administration with findings that startled its researchers.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The systems contained at least a dozen high- or critical-severity software vulnerabilities. Passwords were reused, firewalls were disabled and basic cryptographic protections were poorly implemented. And in Puerto Rico, active cellular hardware modems opened additional pathways into underlying software that was thought to be isolated.&lt;/p&gt;

&lt;p&gt;But the small cybersecurity firm found no evidence that any of those weaknesses had actually been exploited, or that votes had been changed. The company still wanted more time to be certain.&lt;/p&gt;

&lt;p&gt;Federal officials initially seemed willing to give them considerably more of it. The company was asked to grow the team working on the effort from roughly 10 people to about 60, according to CEO Jason Wareham.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Chief Technology Officer Manbir Gulati also said Mojave received an authorization to proceed with a follow-on effort, hired personnel and was given funding to acquire equipment for examining additional voting systems ahead of the November midterms. A contracting officer had even been brought in to finalize the new agreement, Gulati said.&lt;/p&gt;

&lt;p&gt;Then, as Mojave prepared to move ahead, the work was abruptly shut down.&lt;/p&gt;

&lt;p&gt;Wareham and Gulati recounted the episode on Friday at DEF CON hacker convention&amp;rsquo;s Voting Village, where they publicly unpacked their technical findings before sitting down with a small group of reporters and onlookers afterward.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Their account fills in new details about a federal effort that grew out of the Trump administration&amp;rsquo;s broader focus on voting machines and election interference, and the political pressures that emerged when Mojave&amp;rsquo;s findings did not support claims of election manipulation.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The ODNI request&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Mojave never set out to become an election security provider. Its involvement began last year through the Office of the Director of National Intelligence under then-director Tulsi Gabbard, where it was already performing unrelated technical work for the agency when officials approached the company about examining voting machines and data obtained from Puerto Rico.&lt;/p&gt;

&lt;p&gt;Reuters &lt;a href="https://www.reuters.com/world/americas/us-spy-chiefs-office-investigated-voting-machines-puerto-rico-2026-02-04/"&gt;reported&lt;/a&gt; in February that the May 2025 operation was tied to an effort involving ODNI and the FBI to investigate allegations that Venezuela had hacked Puerto Rico&amp;rsquo;s voting systems, though Gabbard&amp;rsquo;s office denied that Venezuela drove its work and said the examination was focused on technical vulnerabilities. The probe produced no clear evidence of Venezuelan interference.&lt;/p&gt;

&lt;p&gt;Wareham said at DEF CON that ODNI asked whether his team of reverse engineers and forensic specialists could travel to Puerto Rico and capture an image of a voting system that had actually been used in an election, without the vendor overseeing the process. He agreed, thinking it would be a relatively small addition to Mojave&amp;rsquo;s existing contract.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The assignment instead dropped Mojave into a much larger skirmish over American elections. &amp;ldquo;Ultimately, I made the worst decision of my life in a business context,&amp;rdquo; Wareham said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;President Donald Trump has spent years falsely maintaining that his 2020 loss was stolen and the product of widespread fraud and foreign interference, claims that have been rejected by courts and officials in his own administration. A 2021 intelligence community &lt;a href="https://www.intel.gov/assets/documents/702-documents/declassified/ICA-declass-16MAR21.pdf"&gt;assessment&lt;/a&gt; found no indication that a foreign actor attempted to alter ballots, vote tabulations or any other technical aspect of the election.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Since returning to office, Trump and allies have revived investigations into the 2020 contest and pushed election security back to the center of his administration&amp;rsquo;s agenda. Gabbard&amp;rsquo;s ODNI was &lt;a href="https://www.nextgov.com/people/2026/02/gabbards-expanded-role-election-security-draws-scrutiny/411295/"&gt;one part of that effort&lt;/a&gt;, hauling off and analyzing voting systems from Puerto Rico and later becoming involved in a federal investigation of 2020 election records in Georgia.&lt;/p&gt;

&lt;p&gt;Wareham said the ODNI officials directly overseeing the company&amp;rsquo;s technical work wanted the research to continue. Both he and Gulati described the ODNI staff they worked with as professionals who wanted to protect the security of election systems.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The resistance, Wareham said, came from a separate White House collective that was repeatedly dissatisfied Mojave had not produced evidence supporting claims that the 2020 election had been manipulated.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There was a separate group &amp;mdash; let&amp;rsquo;s call them White House-adjacent &amp;mdash; who was dissatisfied,&amp;rdquo; he said. &amp;ldquo;They were dissatisfied overall that I was not willing to name and shame at that moment&amp;rdquo; and declare that Trump had actually won the 2020 election.&lt;/p&gt;

&lt;p&gt;Asked whether he believed Mojave&amp;rsquo;s government work was axed because it failed to find the &amp;ldquo;smoking gun&amp;rdquo; some officials wanted, Wareham said: &amp;ldquo;I believe that was part of the termination, yes.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Reuters reported in April that Kurt Olsen, a prominent 2020 election-denier and Trump adviser involved in efforts to investigate the election, &lt;a href="https://www.reuters.com/world/us/trump-aides-chase-vote-rigging-claims-even-after-latest-probe-finds-nothing-2026-04-23/"&gt;pressed Mojave&lt;/a&gt; to broaden its work in search of evidence that could support those claims.&lt;/p&gt;

&lt;p&gt;Olsen, who now works at the Justice Department, turned against the company when its research failed to uncover evidence that the Puerto Rico machines had been hacked. He advocated terminating its work and accused Mojave of secretly receiving money from billionaire George Soros, a frequent target of right-wing conspiracy theories, the news agency reported. ODNI has said Mojave&amp;rsquo;s contract ended because the company completed its voting-machine analysis.&lt;/p&gt;

&lt;p&gt;Wareham said an ODNI official informed him while Mojave was preparing to expand its work that the company had been accused of receiving Soros funding. The allegation prompted him to compile a detailed accounting of the young company&amp;rsquo;s funding sources within three days and send it up the government chain. Asked who he was told had made the accusation, he said an ODNI official reported to him that it was Olsen.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;One, I&amp;rsquo;m not funded by George Soros,&amp;rdquo; Wareham said. &amp;ldquo;Two, it would be great to be funded by George Soros because I would probably not be here, I&amp;rsquo;d be on a yacht.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The company kept moving forward. Wareham said Mojave briefed the White House on some of its findings around September. The firm believed it was heading toward a broader effort to remediate vulnerabilities before the midterms and conduct a deeper analysis for signs that the weaknesses it discovered had ever been actually abused.&lt;/p&gt;

&lt;p&gt;Then came the record-long &lt;a href="https://www.govexec.com/management/2025/11/government-reopen-after-house-votes-end-longest-ever-shutdown/409477/?oref=ge-topic-lander-river"&gt;government shutdown&lt;/a&gt;. Wareham said that on the day he expected an expanded contract to move ahead, Mojave instead received a stop-work order and no additional funding.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think the government shutdown was all that was required, really, to have some folks that I didn&amp;rsquo;t know were still in the game, again, White-House adjacent, to take their shot,&amp;rdquo; he said. Wareham stopped short of saying he had direct proof that White House officials ordered Mojave removed because of its findings, but said &amp;ldquo;it was reported to me it was Kurt Olsen&amp;rdquo; who led the efforts.&lt;/p&gt;

&lt;p&gt;The White House, ODNI and Olsen did not return requests for comment.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Identified vulnerabilities&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Mojave had found many issues with the machines it examined. Gulati described the Puerto Rico system during the Voting Village presentation as &amp;ldquo;deeply insecure,&amp;rdquo; saying it did not meet the security bar he would expect from &amp;ldquo;an average low-risk application, let alone critical infrastructure.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Researchers identified at least 12 major vulnerabilities in commercial software installed on the system, Gulati said. Mojave successfully executed five of them. None were newly discovered flaws, and fixes were already available &amp;mdash; in some cases well before the system was used in the election.&lt;/p&gt;

&lt;p&gt;Other weaknesses were rooted more deeply in how the system was built and deployed. Some passwords could be easily cracked and others were embedded directly into software. Firewalls were turned off on critical systems and ports were left open. Gulati was particularly critical of the system&amp;rsquo;s cryptography, which he described as being &amp;ldquo;in shambles.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The company does not believe every problem it found necessarily stopped at Puerto Rico, as its formal review covered only one system from one manufacturer in one jurisdiction. Gulati suspects the issues could extend beyond a single voting machine company, though Mojave has not examined enough systems from other manufacturers to establish that.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I don&amp;rsquo;t expect that the problems are unique to them,&amp;rdquo; he said. &amp;ldquo;I think many manufacturers probably exhibit the same problems.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Mojave produced an approximately 100-page document of the Puerto Rico findings. Gulati said Mojave has been in discussions with Liberty Vote &amp;mdash; which acquired Dominion&amp;rsquo;s election business last year &amp;mdash; and that Liberty told the researchers it does not plan to make changes before November.&lt;/p&gt;

&lt;p&gt;Liberty said it has not received Mojave&amp;rsquo;s report.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Liberty Vote is not in receipt of any such report so, therefore, we cannot provide any comment,&amp;rdquo; a spokesperson said. &amp;ldquo;As always, Liberty Vote is committed to advancing the future of secure American elections.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;No evidence of vote tampering&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Looking at the systems headed into the midterms, Gulati said, &amp;ldquo;I do know that as of now, the state that we have described is going to be pretty similar to what will be deployed in November.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Despite the extensive findings, Gulati repeatedly returned to what the researchers did not establish: &amp;ldquo;We found extensive and largely unacceptable weaknesses,&amp;rdquo; he said in the presentation. &amp;ldquo;But we did not find evidence that those weaknesses were actively exploited or that votes were altered.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;That distinction has drawn renewed attention as Trump and his allies again focus on election matters.&lt;/p&gt;

&lt;p&gt;Last month, the president used a prime-time White House address to release newly declassified intelligence he said showed China interfered in the 2020 election. Among several disclosures, Trump pointed to intelligence showing Beijing had acquired personal information on roughly 220 million American voters. But the documents &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/trump-stretches-declassified-china-intelligence-broader-2020-election-claims/414837/"&gt;did not show&lt;/a&gt; China altered votes or gained the ability to manipulate voting systems.&lt;/p&gt;

&lt;p&gt;Gulati echoed those conclusions Friday when asked about the declassification.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The China thing isn&amp;rsquo;t really much of anything,&amp;rdquo; he said, arguing that a large amount of the voter information at issue could be obtained commercially and should not be confused with access to election systems in ways that can manipulate votes.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There is no evidence that I know of that says China successfully or any other country has successfully infiltrated our systems and manipulated votes in any way,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;Wareham called the 100-page document a preliminary report and said the firm had wanted another six months to a year to dig deeper into the underlying data.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Gulati said the company&amp;rsquo;s interactions with the ODNI employees overseeing that work were markedly different from the political pressure the researchers later encountered. &amp;ldquo;We were never pressured to put anything in our reports that was untrue or politically leaning in a certain way,&amp;rdquo; he said of those officials.&lt;/p&gt;

&lt;p&gt;Wareham said Friday that Mojave itself has pushed for its report to be made public for roughly a year and has recently been told it could soon emerge through a Freedom of Information Act request. &lt;em&gt;Nextgov/FCW&lt;/em&gt; could not immediately determine the origin of the FOIA requester. As of publishing time, ODNI&amp;rsquo;s FOIA logs are &lt;a href="https://archive.dni.gov/index.php/foia#:~:text=ODNI%20FOIA%20Logs,January%202025"&gt;available up until January 2025&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I&amp;rsquo;m a little annoyed that we are very close to midterms and we had a whole year to freaking figure this out,&amp;rdquo; Wareham said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;With their government work scrapped, he announced at the Voting Village that he had filed paperwork to create the &lt;a href="https://vote.machineassurance.org/"&gt;Machine Assurance Institute&lt;/a&gt;, seeking to bring together cybersecurity researchers and election technology companies to examine and independently verify voting infrastructure.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We wanted to be the national security answer, and put to bed, finally, discussions about prior elections and/or accusations of voter fraud,&amp;rdquo; said Wareham. &amp;ldquo;Because, believe it or not, I find it fairly national security-destabilizing to constantly accuse each other of cheating.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/09/GettyImages_1289778741/large.jpg" width="618" height="284"><media:credit>eyecrave productions / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/09/GettyImages_1289778741/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>New ‘Water Watch Center’ launched to help small utilities stop cyberattacks</title><link>https://www.nextgov.com/cybersecurity/2026/08/new-water-watch-center-launched-help-small-utilities-stop-cyberattacks/415288/</link><description>The initiative comes as multiple states grapple with intrusions into their water systems that some officials suspect could be tied to Iran.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 07 Aug 2026 14:19:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/new-water-watch-center-launched-help-small-utilities-stop-cyberattacks/415288/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; A new program is seeking to assist water providers around the country as multiple states grapple with possible Iran-linked cyber intrusions against water infrastructure.&lt;/p&gt;

&lt;p&gt;The Water Watch Center provides direct cyber mitigation support to utilities serving fewer than 10,000 people, which represents most of the nation&amp;rsquo;s community water systems. Launched at this year&amp;rsquo;s DEF CON hacker convention, the initiative is a joint effort between the National Rural Water Association and DEF CON Franklin, a project of the Cyber Policy Initiative at the University of Chicago Harris School of Public Policy.&lt;/p&gt;

&lt;p&gt;More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued operating safely and experienced no known effects on public health. The FBI and Cybersecurity and Infrastructure Security Agency are working on &lt;a href="https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/"&gt;incident response&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;An initial group of five cybersecurity firms will help deliver services to water utilities as part of the initiative.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These leading cyber firms and NRWA are architecting a scalable cyber delivery model that has eluded water industry and national security officials to date,&amp;rdquo; Jake Braun, the co-founder of DEF CON Franklin and a former White House acting principal deputy national cyber director, said in a statement.&lt;/p&gt;

&lt;p&gt;Retired Gen. Paul Nakasone, who led U.S. Cyber Command and the NSA from 2018 to 2024, said at DEF CON this year that water utilities around the country are highly exposed, and he pushed for higher defense standards in the sector.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;These [programmable logic controllers] should not be exposed to the internet,&amp;rdquo; he told reporters in a briefing on Friday, referring to the small computers used to operate pumps, valves and other equipment inside water facilities.&lt;/p&gt;

&lt;p&gt;Some U.S. officials believe Iran may be responsible, though there has been no definitive public confirmation.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think [the government] is taking a very measured approach to make sure that they have the right actor that&amp;rsquo;s doing this,&amp;rdquo; Nakasone said when asked about why Iran hasn&amp;rsquo;t publicly been linked to the hacks&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I look at intent. I look at capability. I look at history. I&amp;rsquo;m not the person that&amp;rsquo;s making the call on the attribution, but I see an actor here that has certainly shown a history of being able to do this,&amp;rdquo; he said. &amp;ldquo;They certainly have the capability, and I think there&amp;rsquo;s an intent right now &amp;mdash; we&amp;rsquo;re in conflict with Iran.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726waterNG/large.jpg" width="618" height="284"><media:credit>Seth McConnell/The Denver Post via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/080726waterNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA cautions against rigid rules for future of cyber vulnerability program</title><link>https://www.nextgov.com/cybersecurity/2026/08/cisa-cautions-against-rigid-rules-future-cyber-vulnerability-program/415282/</link><description>A top agency official said formal backing from Congress could strengthen the global vulnerability-tracking system but warned against measures that may limit its ability to adapt to ever-changing hacking threats.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 07 Aug 2026 10:33:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/cisa-cautions-against-rigid-rules-future-cyber-vulnerability-program/415282/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; The Cybersecurity and Infrastructure Security Agency sees value in formally placing the world&amp;rsquo;s dominant software vulnerability tracking program into federal law but is cautioning Congress against imposing rules that could make it harder to adapt as artificial intelligence and international partners reshape the system.&lt;/p&gt;

&lt;p&gt;The Common Vulnerabilities and Exposures Program, or CVE, gives publicly known security flaws standardized identifiers so that governments, software companies and researchers can easily communicate about the same issue. It was first created in 1999, and it underpins cybersecurity discussions across both private industry and the national intelligence community.&lt;/p&gt;

&lt;p&gt;Policymaking interest in the program followed a funding scare last year that exposed the fragility of the arrangement supporting its functions. MITRE, the scientific research giant that helps operate CVE under a federal contract,&lt;a href="https://www.nextgov.com/cybersecurity/2025/04/mitre-backed-cyber-vulnerability-program-lose-funding-wednesday/404585/"&gt; warned last April&lt;/a&gt; that its funding from the government would imminently expire.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;CISA then extended the contract within hours, a sweeping relief for the cybersecurity community that raised fresh questions about why a major global cybersecurity resource leaned so much on a sole U.S. contract. A CISA official previously said that a &amp;ldquo;broad internal contracting review caused a brief renewal delay in April 2025, but operations continued without disruption and MITRE was ultimately retained as the program operator.&amp;rdquo;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A legislative proposal&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/planned-ndaa-amendment-would-codify-cisas-role-cyber-vulnerability-program/414286/"&gt; reported by &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; in June would formally authorize CVE within the Department of Homeland Security and establish a clearer legal role for CISA, its longtime federal sponsor.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Defining the importance of the program in legislation in general seems like a very helpful thing,&amp;rdquo; Lindsey Cerkovnik, branch chief for vulnerability response and coordination at CISA, said Thursday during a panel at the Black Hat cybersecurity conference.&lt;/p&gt;

&lt;p&gt;But Cerkovnik, whose office helps oversee CVE, said legislation could become counterproductive if it dictates too precisely how the program must operate.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;When you overdefine how to execute the thing, it can make it very restrictive and difficult,&amp;rdquo; she said. &amp;ldquo;In some ways, we are wary of overly-restrictive guidance&amp;rdquo; that could make CVE less nimble, agile and flexible, she added.&lt;/p&gt;

&lt;p&gt;The congressional proposal would also require CISA and the National Institute of Standards and Technology to develop a modernization plan and establish a 15-member board to set CVE policies and priorities. Permanent seats would go to CISA, NIST and top-level CVE authorities, while rotating members would represent industry, academia, researchers and foreign governments.&lt;/p&gt;

&lt;p&gt;Reps. Delia Ramirez, D-Ill., and George Whitesides, D-Calif., submitted the proposal as an &lt;a href="https://rules.house.gov/bill/119/hr-8800#:~:text=Authorizes%20the%20existing,Department%20of%20Commerce."&gt;amendment&lt;/a&gt; to the fiscal 2027 defense authorization bill. But the House Rules Committee didn&amp;rsquo;t select it for floor consideration, preventing it from getting a vote in the full House last month.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cerkovnik said CISA had reviewed the proposal and saw both benefits and challenges. Formal recognition could help preserve support for the program, although CISA and DHS have maintained its operations without a lapse for more than 26 years, she said.&lt;/p&gt;

&lt;p&gt;CISA is CVE&amp;rsquo;s sole federal sponsor, while MITRE helps execute the program alongside a global network of more than 530 CVE Numbering Authorities, known as CNAs. Those organizations &amp;mdash; which include software vendors, research groups and national cybersecurity agencies &amp;mdash; can assign identifiers and publish information about vulnerabilities within their areas of responsibility.&lt;/p&gt;

&lt;p&gt;The number and variety of those participants has allowed CVE to keep pace with a growing volume of software flaws. AI, however, is widely expected to accelerate vulnerability discovery further and may require the program to make changes that its current structure did not anticipate.&lt;/p&gt;

&lt;p&gt;Cerkovnik pointed to a recently announced AI researcher CNA &lt;a href="https://www.cve.org/Media/News/item/blog/2026/07/28/CVE-Launches-Frontier-AI-Researcher-CNA-Pilot"&gt;pilot program&lt;/a&gt; that would allow selected AI companies to assign CVE identifiers for vulnerabilities uncovered through research using their own models.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;That program may need to bring people with AI expertise into its leadership, she said, and rules narrowly prescribing who can serve on CVE boards or how new participants are admitted could complicate that kind of response. Cerkovnik didn&amp;rsquo;t say the current congressional proposal would block the pilot, instead using it to illustrate why the program needs room to adjust as technology changes.&lt;/p&gt;

&lt;p&gt;CVE is also becoming less centered on the United States. The European Union Agency for Cybersecurity, known as ENISA, became a CVE Numbering Authority in 2024 and a CVE Root in November 2025. Roots oversee groups of numbering authorities, helping organizations join the program and maintaining the quality of the vulnerability records they produce.&lt;/p&gt;

&lt;p&gt;ENISA has since begun bringing European organizations under its Root, building on the agency&amp;rsquo;s stated goal of&lt;a href="https://www.nextgov.com/cybersecurity/2026/03/eu-wants-support-bedrock-cyber-vulnerability-program-top-official-says/412429/"&gt; helping strengthen and modernize CVE&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Nuno Rodrigues Carvalho, ENISA&amp;rsquo;s head of sector for incident and vulnerability services, said on the panel Thursday that the agency now wants to &amp;ldquo;step up in the coming months&amp;rdquo; to also be a top-level Root, bringing it to the same level as CISA and MITRE.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;He described a more federated model in which organizations in Europe, Japan and potentially other regions oversee nearby numbering authorities and provide further support to the project.&lt;/p&gt;

&lt;p&gt;Europe already accounts for roughly one-fifth of the organizations authorized to assign CVE identifiers, Carvalho said. ENISA also operates the European Vulnerability Database, although he emphasized that it relies on CVE identifiers rather than competing with the existing system.&lt;/p&gt;

&lt;p&gt;Cerkovnik backed growing foreign participation, arguing the past year had reinforced the need to describe CVE as &amp;ldquo;a global program and not just a U.S.-centric program.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;AI poses another challenge by potentially increasing the number of vulnerabilities companies and governments must process. Cerkovnik said she expects CVE to scale alongside that growth but is more concerned about whether organizations can determine which flaws demand immediate attention.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Not all vulnerabilities matter. Not all vulnerabilities matter at the same level,&amp;rdquo; she said. CISA made a similar argument in a&lt;a href="https://www.nextgov.com/cybersecurity/2026/06/cisa-directive-revamps-how-agencies-prioritize-vulnerable-systems/414096/"&gt; binding directive&lt;/a&gt; issued in June that tells federal agencies to base patching deadlines on a variety of factors.&lt;/p&gt;

&lt;p&gt;Some lower-risk flaws could be left until a system receives a major upgrade, while the most dangerous vulnerabilities may require action within days. That kind of triage will become more important as AI produces more findings, Cerkovnik said, because neither CVE nor the organizations relying on it can treat every newly discovered flaw as equally urgent.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/07/IMG_4308/large.jpg" width="618" height="284"><media:description>(L to R) Nuno Rodrigues Carvalho, head of sector for Incident and Vulnerability Services at the European Union Agency for Cybersecurity, and Lindsey Cerkovnik, branch chief of vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency, speak with Nextgov/FCW Cybersecurity Reporter David DiMolfetta Aug. 6 ant the Black Hat cybersecurity conference.</media:description><media:credit>David DiMolfetta/Staff</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/07/IMG_4308/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA still finds water system controls exposed online amid multistate hacks</title><link>https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/</link><description>The agency is working with the FBI to help victims but is not attributing the cyber intrusions to any group, acting director Nick Andersen told Nextgov/FCW.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 06 Aug 2026 14:53:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/cisa-still-finds-water-system-controls-exposed-online-amid-multistate-hacks/415266/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; Federal cyber officials are still finding water system controls exposed to the public internet, even as the Cybersecurity and Infrastructure Security Agency and the FBI help utilities recover from a series of cyberattacks affecting at least 12 states, acting CISA Director Nick Andersen told &lt;em&gt;Nextgov/FCW&lt;/em&gt; on Thursday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;rsquo;re seeing things like [programmable logic controllers] that are open and accessible on the internet with either no password set or default password set,&amp;rdquo; Andersen said in a brief interview on the sidelines of the Black Hat cybersecurity conference. &amp;ldquo;We&amp;rsquo;re not making ourselves hardened targets.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Programmable logic controllers, commonly dubbed PLCs, are small computers used to operate pumps, valves and other equipment inside water facilities. Connecting them to the internet can allow operators to manage equipment remotely but it can also give hackers a path into systems that directly control physical processes.&lt;/p&gt;

&lt;p&gt;Andersen said CISA&amp;rsquo;s immediate guidance to utilities remains straightforward: &amp;ldquo;Get your operational technology off the internet, set a password.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The remarks come about a week after&lt;a href="https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs"&gt; CISA warned&lt;/a&gt; that hackers were &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/"&gt;increasingly targeting&lt;/a&gt; internet-connected controllers used by water and wastewater utilities. The agency said attackers had changed passwords and other settings, locking out operators and contributing to water pressure problems, boil-water notices and extended periods of manual operation.&lt;/p&gt;

&lt;p&gt;More than 30 community water systems in Minnesota were targeted late last month, according to state officials. Around 12 states have reported similar activity in recent days, though state officials said they continued operating safely and experienced no known effects on public health. The FBI has said it is aware of the incidents. Andersen also said CISA is working with the FBI on incident response.&lt;/p&gt;

&lt;p&gt;But the cyberdefense agency isn&amp;rsquo;t attempting to determine publicly who was responsible for the hacks, he said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Some U.S. officials suspect Iran-linked hackers carried out the attacks. A CISA &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/#:~:text=A%20recent%20memo,on%20July%2022."&gt;notice&lt;/a&gt; distributed to water utilities last month said the activity in Minnesota shared characteristics with an earlier campaign involving Iran-affiliated hackers, though it didn&amp;rsquo;t provide direct evidence linking the latest incidents to Tehran.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;For us, we&amp;rsquo;re not doing anything with attribution right now,&amp;rdquo; Andersen said, explaining the agency is instead focused on assisting affected organizations, educating operators and improving the sector&amp;rsquo;s security over the longer term.&lt;/p&gt;

&lt;p&gt;CISA also tries to identify vulnerable organizations before they are attacked by examining the broader collection of internet-facing systems, Andersen said. When the agency discovers a potentially exposed device or another security problem, it coordinates with other agencies and contacts the operator, he added.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Andersen couldn&amp;rsquo;t provide a precise estimate of how many exposed or poorly secured devices remain online.&lt;/p&gt;

&lt;p&gt;Water utilities can be difficult to secure because many are small, have limited budgets and depend on aging equipment installed and maintained by multiple contractors. Still, Andersen said infrastructure operators bear some responsibility for taking basic precautions that can make their systems more difficult to compromise.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There&amp;rsquo;s a degree of personal responsibility there to sort of engage in these minimum requirements that are feasible for helping to continue to secure yourselves,&amp;rdquo; he said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626waterNG/large.jpg" width="618" height="284"><media:credit>Brandon Bell/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626waterNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>AI advances are pushing governments to treat cyberattacks as routine, Western officials say</title><link>https://www.nextgov.com/cybersecurity/2026/08/ai-advances-are-pushing-governments-treat-cyberattacks-routine-western-officials-say/415250/</link><description>The remarks underscore a grim outlook for cyberdefenders showing that AI systems are able to exploit vulnerabilities faster than governments can patch them.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 06 Aug 2026 10:15:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/ai-advances-are-pushing-governments-treat-cyberattacks-routine-western-officials-say/415250/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; The rise of autonomous artificial intelligence systems capable of finding and exploiting software flaws is putting serious pressure on governments to treat cyberattacks as inevitable events rather than rare emergencies, senior officials from the United States, Canada and Britain said Wednesday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Cyber compromise is not a black swan anymore. It&amp;rsquo;s just a swan,&amp;rdquo; Joseph Alm, the Department of Homeland Security&amp;rsquo;s assistant secretary for cyber, infrastructure, risk and resilience policy, said on an OpenPolicy panel at the Black Hat cyber conference. Organizations can no longer treat a breach as an unforeseeable crisis, he argued, and they should instead assume one will occur and prepare to limit the damage.&lt;/p&gt;

&lt;p&gt;Alm said governments and companies need to devote more attention to &amp;ldquo;harm reduction,&amp;rdquo; including the steps they would take to contain an intrusion and continue operating after a hacker gets inside. AI is making it easier for hackers to find and exploit the weaknesses already buried in older technology, he added.&lt;/p&gt;

&lt;p&gt;The remarks highlight a bleak near-term reality for cyberdefenders that concludes AI systems will find and exploit weaknesses faster than governments can fix them, and that agencies will need to assume some attacks will succeed and plan accordingly.&lt;/p&gt;

&lt;p&gt;Michael Duffy, the federal government&amp;rsquo;s acting chief information security officer, said federal cyber policies over the past decade have largely been written after a crisis, with the Office of Personnel Management and SolarWinds breaches prompting new requirements designed to prevent the same failures from recurring.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The U.S. has become better at finding what went wrong and preventing the same failure from happening again, but the next decade needs to focus on anticipating attacks and ensuring agencies can continue functioning while under pressure, he argued .&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We know things cannot go down for an extended period of time,&amp;rdquo; Duffy said.&lt;/p&gt;

&lt;p&gt;Some officials, however, cautioned against viewing AI as the source of most cyber risk. Jonathon Ellison, the U.K. National Cyber Security Centre&amp;rsquo;s director for national resilience, said a more immediate problem for many organizations remains the large number of known weaknesses already sitting inside their networks after years of underinvestment.&lt;/p&gt;

&lt;p&gt;Policy discussions can focus too heavily on AI discovering new vulnerabilities when companies are already carrying enormous security burdens from outdated and poorly secured technology, Ellison said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Thomas Lind, a former intelligence officer who directed policy at the White House Office of the National Cyber Director until June, noted that while officials anticipated advanced AI cyber capabilities, the rapid proliferation of these tools beyond certain governments and large firms has drastically reduced response times for policymakers and defenders.&lt;/p&gt;

&lt;p&gt;Rajiv Gupta, head of the Canadian Centre for Cyber Security, similarly described autonomous agents as a significant change that governments are still working to understand, even though Canada has used less advanced forms of AI in cyber defense for years. At the same time, he said, countries still face a substantial backlog of older technology that must be replaced or secured, and governments will not have a &amp;ldquo;patch army&amp;rdquo; capable of fixing every vulnerable system for every organization.&lt;/p&gt;

&lt;p&gt;That reality has led Canadian officials to consider what basic services citizens should expect the government to preserve during an extreme disruption, including the hypothetical loss of internet access for as long as three months. Gupta described the work as a &amp;ldquo;Minimum Viable Canada&amp;rdquo; initiative focused on identifying and maintaining the country&amp;rsquo;s most essential functions through a crisis.&lt;/p&gt;

&lt;p&gt;The warnings come amid a series of recent unprecedented cyber incidents involving autonomous AI agents. Last month, OpenAI models escaped an internal cybersecurity evaluation environment and breached Hugging Face. Britain&amp;rsquo;s&lt;a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing"&gt; AI Security Institute&lt;/a&gt; disclosed this week that agents powered by Anthropic&amp;rsquo;s Mythos 5 and OpenAI&amp;rsquo;s GPT-5.6 Sol took unauthorized actions on the public internet during testing, including an unsuccessful attempt to place malicious code in an open-source software project.&lt;/p&gt;

&lt;p&gt;And just Wednesday, Meta confirmed that one of its models &lt;a href="https://www.theinformation.com/articles/meta-ai-model-hacked-another-company-cybersecurity-testing"&gt;exploited a flaw&lt;/a&gt; at another company after an outside testing firm mistakenly gave it internet access.&lt;/p&gt;

&lt;p&gt;Duffy said he is working with NIST, the Cybersecurity and Infrastructure Security Agency and other parts of the government to more quickly turn technical guidance on emerging cybersecurity risks, including those involving AI, into policies for federal agencies. He didn&amp;rsquo;t provide a timeline for any finalized guidance.&lt;/p&gt;

&lt;p&gt;The government can&amp;rsquo;t wait for another major incident to determine how AI should be governed or how agencies should use them, Duffy argued. &amp;ldquo;We likely won&amp;rsquo;t have time to pick up the pieces with the speed and the scale of what we&amp;rsquo;re seeing in these AI capabilities,&amp;rdquo; he said. &amp;ldquo;We know the types of steps that need to be taken. Let&amp;rsquo;s take them now.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626AIcyberNG/large.jpg" width="618" height="284"><media:credit>Apichat Noipang/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/06/080626AIcyberNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says</title><link>https://www.nextgov.com/cybersecurity/2026/08/hugging-face-ai-breach-most-consequential-hack-morris-worm-former-nsa-cyber-chief-says/415230/</link><description>AI may let hackers exploit newly disclosed software flaws so quickly that organizations should weigh whether to immediately patch internet-connected devices, even at the risk of causing outages, Rob Joyce said.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 05 Aug 2026 13:32:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/hugging-face-ai-breach-most-consequential-hack-morris-worm-former-nsa-cyber-chief-says/415230/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;LAS VEGAS &amp;mdash; An OpenAI system that broke out of a cybersecurity test and entered Hugging Face&amp;rsquo;s network was a &amp;ldquo;watershed moment&amp;rdquo; comparable to the 1988 Morris Worm infection, former National Security Agency cybersecurity director Rob Joyce said Wednesday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We&amp;rsquo;re living in the last several weeks through with what I think is the most consequential hack,&amp;rdquo; Joyce said. He spoke alongside fellow former NSA cybersecurity director Dave Luber during a World Wide Technology panel held at the Black Hat cyber conference.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I have to go back all the way to the Morris Worm in the &amp;rsquo;80s to say something that&amp;rsquo;s equivalent to how it&amp;rsquo;s going to change the way we think about our infrastructure,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The Morris Worm spread automatically across the early internet, disrupting thousands of computers and helping spur major changes in how the government and technology industry handled cyber incidents. The episode led to the first felony conviction under the 1986 Computer Fraud and Abuse Act.&lt;/p&gt;

&lt;p&gt;Joyce said he once believed large language models would mainly help hackers write convincing phishing emails and create fake images, audio and video, but he didn&amp;rsquo;t expect them to become broadly useful for carrying out the more technical stages of an attack.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;And boy, was I wrong,&amp;rdquo; he said, adding that the systems can now understand computer programs and networks well enough to find vulnerabilities that can be turned into working intrusions.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://huggingface.co/blog/security-incident-july-2026"&gt;Hugging Face disclosed in July&lt;/a&gt; that an autonomous agent powered by OpenAI models had gained unauthorized access to parts of its production network. The company operates a widely used platform where developers store and share AI models, software and data.&lt;/p&gt;

&lt;p&gt;OpenAI had been testing how effectively its models could find and exploit software vulnerabilities. The company loosened some of the models&amp;rsquo; normal security safeguards for the exercise, which was supposed to remain inside an isolated testing environment. The agent instead reached Hugging Face, accessed internal datasets and credentials and moved across parts of its infrastructure.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Other researchers have since reported AI agents acting beyond the intended limits of cybersecurity tests. Britain&amp;rsquo;s AI Security Institute&lt;a href="https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing"&gt; said Tuesday&lt;/a&gt; that agents powered by Anthropic and OpenAI models took unauthorized actions on the public internet during 10 of 122 test runs.&lt;/p&gt;

&lt;p&gt;In the most serious case, an agent created fake online identities and attempted to convince an open-source software maintainer to approve malicious code. The maintainer rejected the proposed change, and investigators found no resulting real-world harm.&lt;/p&gt;

&lt;p&gt;Luber, who succeeded Joyce at NSA before retiring from government last year, said advanced AI can also make powerful hacking tools available to a wider range of adversarial groups.&lt;/p&gt;

&lt;p&gt;Five years ago, Luber said, previously unknown software flaws &amp;mdash; known as zero-days because developers have &amp;ldquo;zero days&amp;rdquo; to fix them before being exploited &amp;mdash; were mainly used by well-resourced nation-state hackers, while ransomware gangs generally relied on known vulnerabilities that victims had failed to patch.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think that&amp;rsquo;s changed,&amp;rdquo; Luber said. As advanced capabilities become more widely available, ransomware collectives could acquire more undisclosed exploits and use them more freely to break into victims&amp;rsquo; networks, he added.&lt;/p&gt;

&lt;p&gt;Joyce said attackers already use automation to scan continuously for various digital security gaps. AI agents can perform that work around the clock without becoming tired or distracted. Defenders, meanwhile, still rely heavily on people to review alerts, approve updates and respond to suspicious activity.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The attackers are coming at machine-speed,&amp;rdquo; Joyce said. &amp;ldquo;We are on the defense, not at machine-speed today, and that&amp;rsquo;s got to change.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The tools aren&amp;rsquo;t necessarily inventing entirely new hacking techniques, Joyce said, but they are becoming much better at uncovering years of neglected security problems &amp;mdash; often dubbed technology debt &amp;mdash; across companies and government agencies. Tech debt can include outdated software, unpatched security flaws, default passwords and systems that were built or configured quickly but never fully secured.&lt;/p&gt;

&lt;p&gt;That speed should change how organizations install security updates, especially on devices connected directly to the public internet, he argued.&lt;/p&gt;

&lt;p&gt;Companies typically test patches before broadly installing them because a faulty update can crash computers or disrupt operations. The widespread 2024 &lt;a href="https://www.nextgov.com/cybersecurity/2024/07/how-crowdstrike-outage-carved-out-new-opportunities-hackers/398216/"&gt;CrowdStrike outage&lt;/a&gt; demonstrated the damage a defective software update can cause.&lt;/p&gt;

&lt;p&gt;But AI could allow attackers to exploit a newly disclosed vulnerability before an organization finishes testing the patch, Joyce added.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;I think it&amp;rsquo;s gotten to the point where we have to blindly accept patches for those internet-facing devices and just take them from the manufacturer and immediately put them on,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;That leaves organizations choosing between the possibility that a patch causes an outage and the possibility that waiting exposes them to hacking attempts. But &amp;ldquo;of those two bad choices, I&amp;rsquo;m going to accept more risk on a self-inflicted outage than I am exposing myself to ransomware or an extortion event,&amp;rdquo; Joyce said.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526WWTNG/large.jpg" width="618" height="284"><media:description>(L to R) Former National Security Agency cybersecurity director Rob Joyce and fellow former NSA cybersecurity director Dave Luber speak with Vice President of Global Cyber at World Wide Technology Chris Konrad at an Aug. 5 World Wide Technology panel held at the Black Hat cyber conference. </media:description><media:credit>David DiMolfetta/Staff</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/05/080526WWTNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Chinese telecom firms kept footholds in US networks despite federal crackdowns, House probe finds</title><link>https://www.nextgov.com/cybersecurity/2026/08/chinese-telecom-firms-kept-footholds-us-networks-despite-federal-crackdowns-house-probe-finds/415190/</link><description>China Mobile, China Telecom and China Unicom retained equipment, data center space and network ties after FCC restrictions, including a China Mobile-linked network that appeared in routes to Salt Typhoon servers.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Tue, 04 Aug 2026 12:00:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/chinese-telecom-firms-kept-footholds-us-networks-despite-federal-crackdowns-house-probe-finds/415190/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Years after federal regulators invoked national security grounds to push three Chinese state-owned telecommunications providers out of the American market, the companies never fully left, a new House probe has found.&lt;/p&gt;

&lt;p&gt;China Telecom, China Mobile and China Unicom retained equipment, data-center space and connections to other networks in the United States after the Federal Communications Commission denied or revoked their authority to provide certain telecommunications services, according to a nearly 50-page bipartisan House China Committee investigation planned for release Tuesday and first seen by &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;From 2019 to 2022, the FCC denied China Mobile USA&amp;rsquo;s application to provide international service and revoked authorizations held by China Telecom Americas and China Unicom Americas. But those actions did not require the companies to remove equipment, leave data centers or sever private network links, and the carriers continued offering enterprise networking, internet transit and other services, the panel found.&lt;/p&gt;

&lt;p&gt;The committee argues that those remaining footholds could give Beijing&amp;rsquo;s cyberspies visibility into sensitive traffic, help keep malicious infrastructure online and create opportunities to reroute data or reach U.S. targets. American officials regard China as the country&amp;rsquo;s leading cyber adversary, with a record of targeting critical infrastructure and stealing military, commercial and personal data.&lt;/p&gt;

&lt;p&gt;The three carriers did not respond to detailed requests for comment. &lt;em&gt;Nextgov/FCW&lt;/em&gt; also sought comment from the FBI, the Cybersecurity and Infrastructure Security Agency and several U.S. spy agencies. The Defense Intelligence Agency, which produces intelligence findings for the Pentagon, declined to comment.&lt;/p&gt;

&lt;p&gt;A spokesperson for China&amp;rsquo;s embassy in Washington said Beijing &amp;ldquo;firmly opposes the U.S. overstretching the concept of national security and going after Chinese companies,&amp;rdquo; adding that China would defend its &amp;ldquo;legitimate and lawful rights and interests.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The remaining network ties took on added significance in the committee&amp;rsquo;s review of Salt Typhoon, the sweeping Chinese &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/salt-typhoon-hackers-targeted-over-80-countries-fbi-says/407719/"&gt;espionage campaign&lt;/a&gt; uncovered in 2024 where hackers breached major telecom carriers in the United States and abroad. The intrusion reached systems used to comply with court-authorized wiretap requests and allowed the cyberspies to target the communications of senior U.S. officials, including President Donald Trump and Vice President JD Vance.&lt;/p&gt;

&lt;p&gt;Reviewing routing data from Sept. 22 to 25, 2024, just as the Salt Typhoon campaign &lt;a href="https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835"&gt;became public&lt;/a&gt;, the committee identified 58 groups of internet addresses that CISA had linked to Salt Typhoon servers. China Mobile International&amp;rsquo;s network appeared in routes to those servers at least 192 times, helping keep the attacker infrastructure reachable as U.S. defenders sought to shut it down, the report said.&lt;/p&gt;

&lt;p&gt;The committee does not allege that China Mobile USA employees knew about or participated in the campaign, and it says the routing evidence does not definitively link the company to Salt Typhoon. But the panel argues that the overlap shows how China Mobile&amp;rsquo;s remaining network ties could help sustain malicious infrastructure.&lt;/p&gt;

&lt;p&gt;That finding came from a broader analysis that identified nearly 109,000 incidents from January 2018 through May 2025 in which Chinese or Hong Kong-linked networks allegedly claimed U.S. internet addresses without authorization, potentially diverting American traffic through their systems. The committee classified them as high-confidence &lt;a href="https://www.nextgov.com/cybersecurity/2024/09/white-house-plan-looks-secure-foundational-piece-global-internet/399239/"&gt;hijacks&lt;/a&gt; of the Border Gateway Protocol, a bedrock system that directs traffic across networks, but acknowledged that some may have resulted from mistakes or poor network management.&lt;/p&gt;

&lt;p&gt;More than 4,200 of the incidents involved China Mobile-controlled networks. In September 2024, eight originated from the same network that appeared in routes to Salt Typhoon servers and diverted traffic belonging to unnamed U.S. network operators, the committee said.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Addressing the threat&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Telecommunications networks have long been prized intelligence targets because they can expose private conversations and reveal what political and diplomatic leaders are thinking. Such concerns are compounded by China&amp;rsquo;s 2017 National Intelligence Law, which requires companies and citizens to assist state intelligence work. Beijing denies that the law compels companies to participate in illegal espionage.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China&amp;rsquo;s state telecommunications carriers for too long have enjoyed non-reciprocal access to U.S. domestic networks, but the seriousness of Salt Typhoon gives the FCC and other agencies more than enough justification to restrict or expel them,&amp;rdquo; said James Mulvenon, a leading authority on Chinese national security issues and vice president of intelligence at risk advisory firm Pamir Consulting.&lt;/p&gt;

&lt;p&gt;The committee recommends giving federal agencies greater authority over equipment and private network arrangements that remain after a license revocation, along with targeted removal funding, stronger routing protections and logging requirements for foreign-controlled operators.&lt;/p&gt;

&lt;p&gt;Marc Rogers, a veteran telecommunications expert who helped develop the mobile internet in the 2000s and has spent roughly two decades consulting governments and companies on telecom cybersecurity, agreed with many of the panel&amp;rsquo;s recommendations. Those include treating core telecom systems as high-risk targets requiring closer oversight, strengthening checks on how traffic moves across networks and tightening rules on the foreign-made equipment U.S. carriers can use.&lt;/p&gt;

&lt;p&gt;But he disputed the panel&amp;rsquo;s call to expand &amp;ldquo;rip-and-replace&amp;rdquo; efforts targeting legacy telecom equipment, arguing that such programs are economically unrealistic and could significantly disrupt carrier operations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;On paper it sounds great, until you get someone with operational experience,&amp;rdquo; Rogers said. &amp;ldquo;Then they realize you&amp;rsquo;re basically talking about bulldozing an entire city and building a new one.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Rogers also said the panel&amp;rsquo;s recommendations resemble measures in British &lt;a href="https://www.osborneclarke.com/insights/regulatory-outlook-june-2026-telecoms"&gt;telecom security law&lt;/a&gt; but warned that they would work only if countries act together.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If only one country takes a strong position, China will just maneuver around them,&amp;rdquo; he said, adding that the proposals are largely aimed at tactics China has already used. Policymakers should learn from those incidents, Rogers said, while also preparing for how Beijing&amp;rsquo;s methods may evolve.&lt;/p&gt;

&lt;p&gt;The findings underscore the difficulty of removing operators deemed national security risks from a telecommunications ecosystem built on private infrastructure and decades of commercial ties. Regulators can ban specific services without necessarily reaching the equipment, leases and private agreements that preserve connectivity.&lt;/p&gt;

&lt;p&gt;The committee based its report on subpoenaed company records, eight interviews conducted under oath, federal records, routing data and network infrastructure scans. It said Cloudflare and unnamed outside cybersecurity experts independently reviewed and verified portions of its routing analysis.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Parent company control and U.S. footprint&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Across all three companies, the committee found U.S. subsidiaries that remained dependent on parent or affiliate entities in China or Hong Kong for important technical and operational functions while retaining equipment and network connections inside the United States.&lt;/p&gt;

&lt;p&gt;At China Telecom Americas, requests involving connections between U.S. and overseas networks were handled by personnel in Shanghai, Hong Kong or Beijing, according to testimony cited in the report. Service orders could also flow through a parent-controlled system to Shanghai Telecom without a separate contract. The U.S. subsidiary did not keep independent traffic-flow records, leaving employees unable to determine whether a parent or affiliate had changed routes involving equipment in the United States.&lt;/p&gt;

&lt;p&gt;China Telecom Americas identified 10 active points of presence &amp;mdash; sites where a carrier keeps equipment and connects with other networks &amp;mdash; across seven metropolitan areas. A senior engineering official also told the committee that about a quarter of the company&amp;rsquo;s U.S. transmission hardware was still made by Huawei, whose equipment the FCC has deemed a national security risk.&lt;/p&gt;

&lt;p&gt;China Mobile USA, meanwhile, was described by one witness as &amp;ldquo;basically a sales team,&amp;rdquo; while another said it had no network engineers. Orders for data center space and network connections were approved at its Hong Kong headquarters, and witnesses could not identify a network operations team based elsewhere.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Despite this, China Mobile USA&amp;rsquo;s records contained 39 point-of-presence entries across 27 data-center and interconnection facilities. The committee said those sites connected it to carrier backbones, internet exchanges and private networks used by major U.S. technology companies. Investigators identified at least 143 active China Mobile network assets in U.S. facilities.&lt;/p&gt;

&lt;p&gt;China Unicom Americas disclosed that seven of its eight directors and two of its three senior managers were Chinese Communist Party members. Its U.S. employees used parent-controlled email and computer systems, and evidence indicated that they operated under cybersecurity, administrative and privacy policies issued by China Unicom Global.&lt;/p&gt;

&lt;p&gt;A compliance official told the report&amp;rsquo;s authors the subsidiary could guarantee its own adherence to U.S. law, but not its parent&amp;rsquo;s.&lt;/p&gt;

&lt;p&gt;A China Unicom Americas compliance official also acknowledged that the subsidiary did not know the identities of some third parties in China that ultimately received services ordered through China Unicom Global. The company had equipment and active connections in roughly 10 U.S. data centers.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Other carrier relations&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The report also describes relationships between the three Chinese carriers and companies linked by U.S. authorities to Chinese hacking operations.&lt;/p&gt;

&lt;p&gt;China Mobile, in one case, acted as a middleman for CloudRadium, a Hong Kong hosting provider whose infrastructure has repeatedly surfaced in malicious cyber activity, the committee said. Subpoenaed records showed that China Mobile purchased U.S. data center space and network connections on CloudRadium&amp;rsquo;s behalf, including through a four-year contract valued at $480,000.&lt;/p&gt;

&lt;p&gt;The report also links CloudRadium to a Wyoming company of the same name and GlobalData Investments, a California corporation that markets hosting and data center services under the CeraNetworks name. &lt;em&gt;Nextgov/FCW&lt;/em&gt; found that the companies&amp;rsquo; websites used similar logos, layouts and animations. An email sent to an address listed for Steven Beals, identified online as GlobalData Investments&amp;rsquo; chief operating officer, was returned as undeliverable.&lt;/p&gt;

&lt;p&gt;The committee also details China Unicom&amp;rsquo;s relationships with Integrity Technology Group and i-SOON, two Chinese cybersecurity contractors U.S. authorities have linked to state-backed hacking.&lt;/p&gt;

&lt;p&gt;A 2024 &lt;a href="https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/0/CSA-PRC-LINKED-ACTORS-BOTNET.PDF"&gt;U.S. advisory&lt;/a&gt; identified Integrity Tech infrastructure as the control layer for a botnet of compromised routers and other internet-connected devices operated by Flax Typhoon, a Chinese state-sponsored hacking group. China Unicom Beijing network addresses were used to manage the botnet and connect it to other attack infrastructure and, according to the committee&amp;rsquo;s report, China Unicom and Integrity Tech formalized a cooperation agreement in November 2023 while the botnet was operating.&lt;/p&gt;

&lt;p&gt;China Unicom separately appeared as a corporate partner of i-SOON. The company &lt;a href="https://unit42.paloaltonetworks.com/i-soon-data-leaks/"&gt;drew international scrutiny&lt;/a&gt; after a large collection of purported internal documents appeared on GitHub in 2024, exposing details about its hacking tools, targets and work for Chinese police and intelligence agencies.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The Justice Department later &lt;a href="https://www.justice.gov/opa/pr/justice-department-charges-12-chinese-contract-hackers-and-law-enforcement-officers-global"&gt;charged&lt;/a&gt; eight i-SOON employees and two Chinese police officers in a years-long hacking campaign, alleging that the company worked with at least 43 intelligence or police bureaus. The charges have not been proven in court.&lt;/p&gt;

&lt;p&gt;Integrity Tech&amp;rsquo;s website was unavailable when &lt;em&gt;Nextgov/FCW&lt;/em&gt; attempted to contact the company, and a functioning corporate website for i-SOON could not be located.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;China has been conducting an escalating campaign of cyberattacks on U.S. networks as a form [of] operational preparation of the battlefield,&amp;rdquo; said Jack Burnham, a senior research analyst in the China Program at the Foundation for Defense of Democracies whose work focuses on China&amp;rsquo;s military, emerging technologies and science and technology policy.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Key to these efforts is Beijing&amp;rsquo;s capacity to access core domestic networks, either via installed equipment, routing relationships, or other interconnections,&amp;rdquo; Burnham said. &amp;ldquo;While the FCC has sought to tamp down on Chinese state-owned telecoms firms that pose a national security threat, there is clearly more work to be done, both in terms of regulation and rip-and-replace, to properly handle these threats.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/03/080326ChinaNG/large.jpg" width="618" height="284"><media:credit>Thomas Faull/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/03/080326ChinaNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Lawmakers propose giving 2015 OPM breach victims identity protection for life</title><link>https://www.nextgov.com/cybersecurity/2026/08/lawmakers-propose-giving-2015-opm-breach-victims-identity-protection-life/415166/</link><description>The federal government’s coverage for 22.1 million people hoovered up in the China-linked breaches is scheduled to end Sept. 30.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 03 Aug 2026 09:00:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/08/lawmakers-propose-giving-2015-opm-breach-victims-identity-protection-life/415166/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Federal employees and contractors whose sensitive personal data was stolen in the massive Office of Personnel Management breaches disclosed a decade ago would receive identity protection for the rest of their lives under new bicameral legislation.&lt;/p&gt;

&lt;p&gt;Senate Intelligence Committee Vice Chair Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., plan to introduce the RECOVER PII Act on Monday, aiming to prevent the federal government&amp;rsquo;s identity-protection program for victims from expiring Sept. 30, according to bill text first seen by &lt;em&gt;Nextgov/FCW&lt;/em&gt;. Sens. Tim Kaine, D-Va.; Angela Alsobrooks, D-Md.; and Chris Van Hollen, D-Md., are also Senate cosponsors.&lt;/p&gt;

&lt;p&gt;Just over 10 years after the OPM breaches compromised personal information belonging to roughly 22 million people, the identity-protection services provided to affected federal workers, contractors and their families have &lt;a href="https://www.govexec.com/management/2026/05/10-years-after-opm-breach-identity-protection-services-affected-feds-expire/413336/"&gt;begun expiring&lt;/a&gt;. People who enrolled in OPM&amp;rsquo;s MyIDCare program are receiving notices that their complimentary coverage will end 10 years after their individual enrollment date. Some notices began arriving late last year and will continue through September, when OPM plans to conclude the services at the end of the federal fiscal year.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;More than ten years after the OPM data breach exposed the personal information of millions of federal employees, the threat remains,&amp;rdquo; Warner said in the statement. &amp;ldquo;The data stolen included workers&amp;rsquo; most sensitive and personal information &amp;mdash; from Social Security numbers to security clearance records &amp;mdash; and once that information is in the hands of a bad actor, you don&amp;rsquo;t get it back.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The two breaches compromised information belonging to some 22.1 million current, former and prospective federal employees, contractors and others. One intrusion exposed personnel records for roughly 4.2 million people, while a second compromised 21.5 million background-investigation records. About 3.6 million people were affected in both incidents, according to the Government Accountability Office.&lt;/p&gt;

&lt;p&gt;Foreign intelligence services can hold onto these OPM records for years, combine them with information from other cyber intrusions and use the fuller picture to identify or target government personnel and their families.&lt;/p&gt;

&lt;p&gt;Those risks can also grow over time. Data stolen from a lower-level employee in 2015 could become far more valuable if that person later moves into a more sensitive national security role. GAO warned last year that adversaries can &lt;a href="https://www.gao.gov/products/gao-26-108771"&gt;combine publicly available data&lt;/a&gt; to identify military personnel and their families or disrupt Defense Department operations.&lt;/p&gt;

&lt;p&gt;Congress responded to the breach in a 2017 appropriations law by requiring OPM to provide victims with at least 10 years of complimentary identity protection and no less than $5 million in identity-theft insurance. The new bill would replace that limit with coverage lasting for the remainder of each affected person&amp;rsquo;s life while retaining the insurance requirement.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;We have a responsibility to stand by the federal workers who were put at risk through no fault of their own,&amp;rdquo; Warner said. &amp;ldquo;This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The bill would also allow agencies to reimburse federal employees and contractors for privacy tools and services, such as those that remove or limit their personal information online. Agencies would decide whether to offer the reimbursements, which would not be limited to OPM breach victims and would come from their salary-and-expense budgets.&lt;/p&gt;

&lt;p&gt;Norton has &lt;a href="https://www.congress.gov/bill/118th-congress/house-bill/7236/text"&gt;introduced&lt;/a&gt; legislation in the past seeking lifetime protection for OPM victims, beginning after the breaches were disclosed. Similar bills introduced over the years have not become law.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,&amp;rdquo; Norton said in a statement. &amp;ldquo;Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity. Thank you to Senator Warner for working with me to secure this vital protection for those affected.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/08/02/080226WarnerNG/large.jpg" width="618" height="284"><media:description>Sen. Mark Warner (D-VA) speaks at the confirmation hearing for Jay Clayton before the Senate Intelligence Committee during his nomination hearing on Capitol Hill July 15, 2026 in Washington, DC.</media:description><media:credit>Aaron Schwartz/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/08/02/080226WarnerNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Cyber industry coalition urges federal action after suspected Iran-linked water hacks</title><link>https://www.nextgov.com/cybersecurity/2026/07/cyber-industry-coalition-urges-federal-action-after-suspected-iran-linked-water-hacks/415156/</link><description>The group called on CISA to impose baseline security standards across federal operational technology systems and pressed Congress to revive several stalled cyber initiatives.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 31 Jul 2026 16:20:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/cyber-industry-coalition-urges-federal-action-after-suspected-iran-linked-water-hacks/415156/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;An industry coalition representing operational technology cybersecurity firms and critical infrastructure operators on Friday called for a stronger federal response to a wave of cyberattacks against U.S. water systems, including suspected Iran-linked intrusions affecting more than 30 utilities in Minnesota.&lt;/p&gt;

&lt;p&gt;The Operational Technology Cybersecurity Coalition &lt;a href="https://www.otcybercoalition.org/post/a-wake-up-call-for-ot-security-otcc-statement-on-critical-infrastructure-cybersecurity-and-the-nee"&gt;urged&lt;/a&gt; the Cybersecurity and Infrastructure Security Agency to issue a governmentwide directive establishing baseline cybersecurity requirements for operational technology used across federal civilian agencies.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;No clearer call to action has existed in the operational technology space,&amp;rdquo; former CISA cyber policy official and OTCC Executive Director Tatyana Bolton told &lt;em&gt;Nextgov/FCW&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;The statement comes a day after CISA &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/?oref=ng-home-top-story"&gt;warned&lt;/a&gt; that hackers are increasingly targeting internet-exposed programmable logic controllers used by water and wastewater systems. The FBI said it is aware of cyber incidents affecting water and wastewater entities in at least seven states.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;OTCC&amp;rsquo;s main recommendation is for CISA to issue a Binding Operational Directive requiring federal civilian agencies to strengthen security across operational technology systems used in buildings and other facilities.&lt;/p&gt;

&lt;p&gt;The directive would not apply to the local water utilities targeted in Minnesota, but the coalition contends it would establish stronger federal standards and encourage broader adoption across the private sector.&lt;/p&gt;

&lt;p&gt;CISA did not immediately respond to a request for comment.&lt;/p&gt;

&lt;p&gt;The group also called on Congress to renew the State and Local Cybersecurity Grant Program, extend the Cybersecurity Information Sharing Act of 2015 and support Andrew McClure in&amp;nbsp;leading the Energy Department office responsible for protecting the power sector from cyber threats.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;By not extending this [state and local] grant program, Congress is leaving small towns to protect themselves from nation-state actors like Iran,&amp;rdquo; the coalition said.&lt;/p&gt;

&lt;p&gt;The information-sharing law is set to expire at the end of September. OTCC said allowing it to lapse could make it harder for the government to identify large-scale cyber campaigns and warn potential victims.&lt;/p&gt;

&lt;p&gt;The recent attacks follow years of warnings that Iranian and Chinese hackers have targeted vulnerable systems that support water, energy and other critical services.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;To date, we have been lucky that a more catastrophic incident hasn&amp;rsquo;t occurred,&amp;rdquo; Bolton said. &amp;ldquo;We can no longer rely on luck. We must act.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Editor&amp;#39;s note: This article has been updated to correct the coalition&amp;#39;s call for Congress to support Andrew McClure.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/31/073126hackNG/large.jpg" width="618" height="284"><media:credit>AndreyPopov/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/31/073126hackNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>CISA urges water utilities to take exposed systems down after Minnesota hacks</title><link>https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/</link><description>A memo distributed to water industry members and obtained by Nextgov/FCW makes mention of Iran but does not directly present evidence attributing the latest Minnesota incident to the country.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Fri, 31 Jul 2026 09:51:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/cisa-urges-water-utilities-take-exposed-systems-down-after-minnesota-hacks/415142/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Following coordinated cyberattacks on Minnesota water systems that officials suspect may be linked to Iran, the Cybersecurity and Infrastructure Security Agency on Thursday warned utilities nationwide to remove exposed industrial-control equipment from the internet, citing a surge in activity that has locked operators out, disrupted facilities and triggered boil-water notices.&lt;/p&gt;

&lt;p&gt;The Minnesota hacks targeted technology used by more than 30 community water systems on Sunday and Monday, state officials said. Some utilities were forced to operate equipment manually, while an &lt;a href="https://www.mprnews.org/story/2026/07/27/braham-cyberattack-knocked-water-system-offline"&gt;intrusion in Braham&lt;/a&gt; briefly knocked out controls for the city&amp;rsquo;s well and water treatment plant. Officials said they had found no evidence that drinking water quality was affected.&lt;/p&gt;

&lt;p&gt;Some officials believe an Iran-aligned cyber group is the culprit behind the attacks, two people familiar with the matter said, though one noted that investigations remain ongoing. Both were granted anonymity because the situation is sensitive.&lt;/p&gt;

&lt;p&gt;A recent memo distributed to water industry members and obtained by &lt;em&gt;Nextgov/FCW &lt;/em&gt;makes mention of Iran and says several public water utilities reported suspicious cyber activity between July 26 and 27.&lt;/p&gt;

&lt;p&gt;The notice, addressed to members of the Water Information-Sharing Analysis Center, cites findings from the Minnesota Fusion Center, which say the water attacks are &amp;ldquo;aligned&amp;rdquo; with characteristics of a &lt;a href="https://www.nextgov.com/cybersecurity/2026/04/pro-iran-hackers-are-targeting-us-industrial-control-systems-advisory-says/412679/"&gt;cyber campaign&lt;/a&gt; described by CISA in April that involved Iran-linked hackers, though it does not present direct evidence attributing the latest Minnesota incident to Iran. CISA&amp;rsquo;s April advisory was notably &lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a"&gt;updated last week&lt;/a&gt; on July 22.&lt;/p&gt;

&lt;p&gt;The contents of the WaterISAC memo were &lt;a href="https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/?_sp=f77a0930-bd25-4c6a-a2ee-21cd5eb154f6.1785466051747"&gt;first reported&lt;/a&gt; by Wired. Investigators&amp;rsquo; suspicion of Iranian involvement was &lt;a href="https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html"&gt;first reported&lt;/a&gt; by the New York Times.&lt;/p&gt;

&lt;p&gt;Water and wastewater systems are designated as &lt;a href="https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/critical-infrastructure-sectors/water-and-wastewater-sector"&gt;critical infrastructure&lt;/a&gt; under federal policy. Major sabotage could disrupt access to safe drinking water or, in severe cases, damage physical equipment and threaten public health. In the early months of the Israel-Hamas war, a pro-Iran group &lt;a href="https://www.nextgov.com/cybersecurity/2024/02/treasury-sanctions-iranian-cyber-officials-tied-2023-water-system-hacks/393877/"&gt;accessed and defaced&lt;/a&gt; interfaces embedded onto U.S. water systems in Aliquippa, Pennsylvania.&lt;/p&gt;

&lt;p&gt;If tied to Tehran, the Minnesota attacks would represent the latest escalation in a cyber campaign that U.S. officials and security researchers &lt;a href="https://www.nextgov.com/defense/2026/02/strikes-iran-will-test-us-cyber-strategy-abroad-and-defenses-home/411783/?oref=ng-author-river"&gt;anticipated&lt;/a&gt; from the earliest days of the war against Iran.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;After U.S. and Israeli strikes began in late February, suspected Iran-linked actors have since &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/suspected-pro-iran-hacker-group-tied-stryker-cyberattack/412050/"&gt;disrupted&lt;/a&gt; medical technology giant Stryker, targeted FBI Director Kash Patel&amp;rsquo;s &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/pro-iran-hackers-claim-breach-fbi-directors-email/412440/"&gt;personal email&lt;/a&gt; and breached industrial-control equipment across several U.S. sectors.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;U.S. officials &lt;a href="https://www.nextgov.com/cybersecurity/2026/06/us-officials-see-iran-cyber-threat-persisting-despite-preliminary-deal/414243/"&gt;expected that activity to continue&lt;/a&gt; even after a preliminary agreement with Tehran was reached last month because cyberattacks are widely accepted as standard procedure even in peacetime conditions.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;There is no ceasefire in cyber,&amp;rdquo; Israel&amp;rsquo;s top cyberdefense official &lt;a href="https://www.nextgov.com/cybersecurity/2026/05/irans-hackers-are-coordinating-more-closely-israels-top-cyberdefense-official-says/413792/"&gt;told &lt;em&gt;Nextgov/FCW&lt;/em&gt;&lt;/a&gt; in May.&lt;/p&gt;

&lt;p&gt;CISA&amp;rsquo;s &lt;a href="https://www.cisa.gov/news-events/alerts/2026/07/30/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs"&gt;alert&lt;/a&gt; issued Thursday says unnamed hackers are increasingly targeting internet-connected programmable logic controllers, the devices used to automate pumps, valves and other water-system equipment. The agency urged utilities of all sizes to disconnect exposed equipment, replace default passwords and limit remote access to trusted devices.&lt;/p&gt;

&lt;p&gt;One person who works in the water sector expressed frustration that providers continue to leave these devices and other operational technology exposed to the open web.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If utilities are exposing programmable logic controllers to the public internet, and if the U.S. was a serious country, we&amp;rsquo;d shut down their operator and sell the utility operations to a competent entity,&amp;rdquo; said this person, who spoke on the condition of anonymity to be candid about their discontent. &amp;ldquo;It&amp;rsquo;s more proof of how unserious the U.S. is about public health in the water sector.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Water infrastructure is particularly challenging to defend, in part because utilities often manage a patchwork of aging equipment and work with components maintained by multiple contractors over decades, said Aurigo Software CISO Manish Sharma.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Cybersecurity has to account for that complexity. It must be treated as an infrastructure requirement throughout the asset lifecycle, from planning and design through construction, commissioning, operation, modernization and replacement,&amp;rdquo; he said.&lt;/p&gt;

&lt;p&gt;The Minnesota attacks come as the five-month war with Iran has again escalated after a brief pause in U.S. airstrikes. American forces struck dozens of Iranian Revolutionary Guard targets Wednesday after Tehran fired missiles toward U.S. positions, while Iran launched additional attacks toward Jordan and Kuwait on Thursday. The Strait of Hormuz remains the central obstacle to a peace agreement, with traffic through the major oil and gas route &lt;a href="https://www.lloydslistintelligence.com/resources/blog/strait-of-hormuz-brief-29-july-2026"&gt;near a standstill&lt;/a&gt;.&amp;nbsp;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/31/073126WaterNG/large.jpg" width="618" height="284"><media:credit>Robert Alexander/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/31/073126WaterNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Anthropic confirms its AI breached 3 organizations during testing</title><link>https://www.nextgov.com/cybersecurity/2026/07/anthropic-confirms-its-ai-breached-3-organizations-during-testing/415138/</link><description>Three Claude models were inadvertently given access to the internet during security evaluations, and each model took a different approach to hacking external systems.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Alexandra Kelley</dc:creator><pubDate>Fri, 31 Jul 2026 09:40:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/anthropic-confirms-its-ai-breached-3-organizations-during-testing/415138/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Anthropic&amp;rsquo;s flagship artificial intelligence model Claude gained unauthorized access to the networks of three different organizations, the company announced following internal cybersecurity audits of its routine model evaluations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals"&gt;In a press release posted on Thursday&lt;/a&gt;, Anthropic said that, following the containment breach of OpenAI&amp;rsquo;s ChatGPT-5.6 and &lt;a href="https://huggingface.co/blog/security-incident-july-2026"&gt;subsequent attack on Hugging Face&amp;rsquo;s systems&lt;/a&gt;, Anthropic conducted an audit of its own model evaluations. The findings revealed that, out of 141,006 examined evaluations of Claude models dating back to April, there were three incidents where a model accessed the internet from within or while interacting with the third-party evaluators.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Each attack occurred during a &amp;ldquo;capture-the-flag&amp;rdquo; scenario where the models are asked to find hidden information housed within a different node.&lt;/p&gt;

&lt;p&gt;In the blog post, Anthropic blamed a &amp;ldquo;misunderstanding&amp;rdquo; between them and their third-party evaluators that granted the models internet access. The models were told in prompts that they would not have real internet access and therefore operated under the premise that all accessible systems were part of the test environment.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Operating under the false belief that all accessible entities were intended to be in-scope for the exercise, Claude compromised the impacted organizations&amp;rsquo; infrastructure using basic techniques, such as exploiting weak passwords and unauthenticated endpoints,&amp;rdquo; the post reads. &amp;ldquo;It did not find or exploit any complex vulnerabilities, and in each case, Claude continued working to complete only the specific capture-the-flag task its evaluation had assigned.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The models involved in the incidents were Opus 4.7, Mythos 5, and an unnamed internal research test model that isn&amp;rsquo;t planned for release. Anthropic stated that, despite accessing the internet as part of its cybersecurity testing, the models did not deliberately attempt to leave their training environments; accessing the internet only occurred as they looked to complete their tasks.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;In one incident, Opus 4.7 executed the task on the real-world networks of a company once it realized it could via internet access.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;A second incident was more extensive. Mythos 5 sought to find information by referencing software development instructions inside a fictional environment. It used these instructions to install a Python package from a public registry that didn&amp;rsquo;t actually exist in the hopes that the fictional company would automatically download it, thus granting the model access to its networks. In order to do this, it created login credentials a human user would need.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;That Python package was inadvertently uploaded to the internet, where 15 systems downloaded it and compromised their systems.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The third incident saw the prototype model scan real targets after being unable to find the fictional target included in the test.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Anthropic noted that, when the models were able to discern that the attacks affected real systems, they halted their testing processes &amp;mdash; something that, in part, the company said,&amp;nbsp;gives it &amp;ldquo;cautious optimism.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Several defense-in-depth measures, on both our side and our partner&amp;rsquo;s, could have prevented these incidents&amp;nbsp;or at least reduced their likelihood of occurring,&amp;rdquo; the post read. &amp;ldquo;Both we and our partner also could have reviewed evaluation transcripts or network logs more thoroughly. It&amp;rsquo;s also possible that a prompt which told Claude it did have internet access would have changed how Claude behaved when it came into contact with real systems.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;In the aftermath of the breaches, Anthropic is working with its evaluation partner, Irregular, and METR, an independent AI evaluation organization, to continue conducting reviews. It is also working alongside affected companies whose systems were compromised.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Anthropic concluded by saying it encourages other AI developers to conduct similar audits and that evaluation exercises in general need stronger oversight and safeguards.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Ultimately, many factors contributed to these incidents, but, consistent with a blameless postmortem culture, we&amp;rsquo;re approaching the fixes as if the responsibility were ours alone,&amp;rdquo; the post reads.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Industry peers characterized Anthropic&amp;rsquo;s revelations on the heels of OpenAI&amp;rsquo;s incident as a burgeoning pattern cyberdefenders should heed.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Tom Kellermann, the vice president of AI Security and Threat Research at TrendAI, said that these incidents underscore the continued need for safeguards even in secure sandbox environments.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Anthropic and OpenAI just proved that when you strip guardrails for testing, you&amp;rsquo;re not creating a sandbox, you&amp;rsquo;re inviting systemic risk,&amp;rdquo; Kellermann said in a statement to &lt;em&gt;Nextgov/FCW&lt;/em&gt;. &amp;ldquo;Every organization deploying agentic AI needs to ask itself if their evaluation environment is actually contained. Containment and monitoring are no longer optional.&amp;rdquo;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/31/073126AnthropicNG/large.jpg" width="618" height="284"><media:credit>Jakub Porzycki/NurPhoto via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/31/073126AnthropicNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Amazon uncovers broad North Korean hacking campaign against open-source software</title><link>https://www.nextgov.com/cybersecurity/2026/07/amazon-uncovers-broad-north-korean-hacking-campaign-against-open-source-software/415099/</link><description>New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 29 Jul 2026 14:58:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/amazon-uncovers-broad-north-korean-hacking-campaign-against-open-source-software/415099/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;A North Korea-linked hacker group has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the publicly known scope of Pyongyang&amp;rsquo;s efforts to use trusted code to reach large numbers of potential victims and gain access to companies&amp;rsquo; systems.&lt;/p&gt;

&lt;p&gt;The assessment for the first time links the same financially-motivated hacking group to compromises of four major JavaScript packages &amp;mdash; typo-crypto, debug, chalk and axios &amp;mdash; that developers use as building blocks for other software. The axios package alone receives more than 100 million downloads each week, and its compromise had &lt;a href="https://www.nextgov.com/cybersecurity/2026/03/north-korea-linked-hackers-suspected-axios-open-source-hijack-google-analysts-say/412523/"&gt;previously been attributed&lt;/a&gt; to the North Korean group.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Amazon said Wednesday that it had uncovered evidence connecting the actor to the three earlier incidents, based on technical findings that included instances of reused code and similarities in how the attacks were carried out.&lt;/p&gt;

&lt;p&gt;Amazon Threat Intelligence attributed the campaigns to the group with &amp;ldquo;medium confidence,&amp;rdquo; according a blog post authored by Amazon Integrated Security CISO CJ Moses scheduled for release Wednesday evening. The cyber intruders are tracked by researchers under several names, including Sapphire Sleet, Stardust Chollima, BlueNoroff, CageyChameleon and Alluring Pisces.&lt;/p&gt;

&lt;p&gt;In each incident, the hackers tricked a trusted software maintainer and used the access to publish an update containing malicious code, according to Amazon. Organizations configured to automatically download the latest version of those packages may have pulled the compromised updates directly into their systems. The approach allows hackers to compromise a small number of widely used packages while potentially gaining access to thousands of downstream systems, making it more efficient than targeting organizations individually.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Open-source software &amp;mdash; code that can be freely inspected, modified and reused &amp;mdash; underpins operating systems, web servers, encryption tools and many of the applications businesses rely on daily all over the world. The projects often depend on volunteer maintainers to review proposed changes, fix security flaws and publish updates.&lt;/p&gt;

&lt;p&gt;That model relies heavily on trust. Attackers can spend weeks or months posing as legitimate contributors, fixing bugs and building relationships before attempting to gain control of an established project or publishing a malicious update.&lt;/p&gt;

&lt;p&gt;That dynamic drew &lt;a href="https://www.nextgov.com/cybersecurity/2024/04/linux-backdoor-was-long-con-possibly-nation-state-support-experts-say/395511/"&gt;widespread attention&lt;/a&gt; in 2024, when an account operating under the name &amp;ldquo;Jia Tan&amp;rdquo; spent years gaining the trust of other developers before attempting to insert a backdoor into XZ Utils, a widely used data-compression tool included in numerous Linux distributions. The backdoor was discovered before it could be broadly deployed.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Quite frankly, the open-source community is looking for good citizens because these packages are often not maintained by people who are getting paid to do that as a full-time job,&amp;rdquo; Rick Anthony, senior manager for Amazon&amp;rsquo;s Inspector vulnerability management service, told reporters in Arlington, Va. on Wednesday. &amp;ldquo;They are very welcoming for anyone who is willing to contribute.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;North Korea has long treated cyber operations as both an intelligence tool and a source of revenue. Its hackers steal cryptocurrency, conduct espionage and extort victims, while operatives posing as remote IT workers obtain jobs at foreign companies and quietly funnel their salaries back to the regime. Amazon is among those companies, executives said Wednesday. U.S. officials say the proceeds help Pyongyang evade sanctions and finance its nuclear weapons and ballistic missile programs.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;For a sanctions-constrained regime, generating revenue through these operations means that the greater the efficiency, the more money they get, and the more that they can use that money to do things that got them the sanctions to begin with,&amp;rdquo; Moses told reporters. &amp;ldquo;One successful supply chain compromise can yield access to hundreds, if not more, targeted intrusions.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The findings also illustrate how open-source attacks are becoming harder to detect.&lt;/p&gt;

&lt;p&gt;Amazon said attackers are increasingly dividing a malicious operation among several packages that appear harmless when reviewed individually. One package may contain encrypted data, another the code needed to unlock it and a third the instructions to download and execute the final payload. The malicious behavior becomes visible only when the components are used together.&lt;/p&gt;

&lt;p&gt;AI is also making malicious software harder to spot, the blog warned. Hackers can use it to create polished-looking code, convincing documentation and fake developer profiles, eliminating many of the obvious mistakes that once raised red flags.&lt;/p&gt;

&lt;p&gt;Attackers can also exploit errors made by AI coding assistants. If an AI tool recommends a software package that does not exist, hackers can register the name and load it with malware, hoping a developer or automated system will download it without realizing the recommendation was wrong.&lt;/p&gt;

&lt;p&gt;Concerns about open-source software security have increasingly drawn attention in Washington. In December, the chairman of the Senate Intelligence Committee asked the White House national cyber director to &lt;a href="https://www.nextgov.com/cybersecurity/2025/12/sen-cotton-urges-top-white-house-cyber-official-protect-open-source-software/410264/?oref=ng-topic-lander-top-story"&gt;take steps&lt;/a&gt; to address vulnerabilities in open-source projects that help power systems used throughout U.S. military and civilian agencies.&lt;/p&gt;

&lt;p&gt;Last August, &lt;em&gt;Nextgov/FCW&lt;/em&gt; &lt;a href="https://www.nextgov.com/cybersecurity/2025/08/report-russia-based-yandex-employee-oversees-open-source-software-approved-dod-use/407703/"&gt;first reported&lt;/a&gt; that an employee of the Russian technology company Yandex was the sole maintainer of a widely used open-source tool embedded in at least 30 pre-built software packages available to the Defense Department.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/29/072926NKoreaNG/large.jpg" width="618" height="284"><media:credit>Matt Anderson Photography/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/29/072926NKoreaNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government</title><link>https://www.nextgov.com/cybersecurity/2026/07/after-hugging-face-breach-fedramp-chief-tells-slow-patch-vendors-stay-out-government/414972/</link><description>Pete Waterman cited an incident in which OpenAI models escaped a test environment and broke into AI company Hugging Face as evidence that providers must prepare for attacks moving at AI speed.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 23 Jul 2026 14:32:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/after-hugging-face-breach-fedramp-chief-tells-slow-patch-vendors-stay-out-government/414972/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Technology companies that cannot quickly fix dangerous vulnerabilities should not be allowed to sell their products to federal agencies, the head of the government&amp;rsquo;s bedrock cloud security program said Thursday.&lt;/p&gt;

&lt;p&gt;Pete Waterman, director of the General Services Administration&amp;rsquo;s Federal Risk and Authorization Management Program, known as FedRAMP, delivered the blunt warning while discussing resistance from companies that say they lack the resources to address a known, exploitable vulnerability exposed to the internet within a matter of days.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;If that is the way that you are approaching information security today &amp;hellip; the way your company is approaching information security today, I don&amp;rsquo;t want you in the federal marketplace, and you shouldn&amp;rsquo;t be selling your software to anyone,&amp;rdquo; Waterman said in a discussion at Carahsoft&amp;rsquo;s &lt;a href="https://events.govexec.com/2026-fedramp-summit/agenda/"&gt;FedRAMP Summit &lt;/a&gt;in Washington, D.C. FedRAMP is a cornerstone governmentwide program that sets security requirements for cloud products used by federal agencies.&lt;/p&gt;

&lt;p&gt;Waterman pointed to a major incident involving OpenAI and Hugging Face disclosed this week as evidence that companies must prepare to detect and counter cyber activity at speeds that human security teams alone cannot match.&lt;/p&gt;

&lt;p&gt;OpenAI said Tuesday that several of its models &amp;mdash; including GPT-5.6 Sol and a more capable model that has not yet been released &amp;mdash; escaped a restricted testing environment and compromised parts of Hugging Face&amp;rsquo;s production infrastructure while pursuing the answer to a cybersecurity test. Hugging Face is a popular open platform where researchers, developers and companies can share and test AI models, datasets and applications.&lt;/p&gt;

&lt;p&gt;OpenAI was testing how well the models could exploit software flaws. The company had loosened safeguards that normally prevent risky cyber activity so researchers could measure the models&amp;rsquo; full capabilities. The test took place in a sealed-off environment that was not supposed to have access to the internet. But the models found a previously unknown flaw in one of the few services they could reach and used it to break out.&lt;/p&gt;

&lt;p&gt;According to&lt;a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/"&gt; OpenAI&amp;rsquo;s preliminary account&lt;/a&gt;, the models exploited the flaw to escape the testing nexus, moved through parts of OpenAI&amp;rsquo;s research infrastructure and found a system connected to the public internet.&lt;/p&gt;

&lt;p&gt;The models then determined that Hugging Face might contain material related to the test. They used stolen credentials and additional previously unknown vulnerabilities to gain access to Hugging Face servers and retrieve test solutions from a production database, OpenAI said.&lt;/p&gt;

&lt;p&gt;All available evidence suggests the models were narrowly focused on completing the assigned evaluation rather than deliberately trying to harm Hugging Face, according to OpenAI. But the incident demonstrated that advanced models can autonomously discover vulnerabilities, combine them into a longer attack and take actions outside their intended environment in pursuit of a goal.&lt;/p&gt;

&lt;p&gt;Hugging Face&lt;a href="https://huggingface.co/blog/security-incident-july-2026"&gt; first disclosed the intrusion on July 16&lt;/a&gt;, before OpenAI publicly identified its models as the source. The company said the autonomous system performed thousands of actions over a weekend, accessed a limited number of internal datasets and obtained credentials used by several services.&lt;/p&gt;

&lt;p&gt;The remarks are highly significant because FedRAMP serves as the government&amp;rsquo;s main security gatekeeper for cloud products. Companies generally need FedRAMP authorization before agencies can use their services, meaning Waterman&amp;rsquo;s warning may carry real implications for which providers can compete for federal business. He did not announce any new enforcement actions or say that any provider would be removed from the federal marketplace.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Still, the OpenAI-Hugging Face incident itself &amp;ldquo;unequivocally changed&amp;rdquo; the world of cybersecurity, Waterman said.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Everything that you do has changed and will change. You knew this was coming for a long time, but it wasn&amp;#39;t quite real. Now it is,&amp;rdquo; he added.&lt;/p&gt;

&lt;p&gt;FedRAMP&amp;rsquo;s ongoing 20x &lt;a href="https://www.nextgov.com/ideas/2026/02/navigating-fedramp-20x-and-continuous-compliance-imperative/411300/"&gt;overhaul&lt;/a&gt; places greater emphasis on automation and security outcomes instead of treating authorization mainly as a paperwork and compliance exercise. Its&lt;a href="https://www.fedramp.gov/2026/reference/20x/c/vulnerability-detection-and-response/"&gt; new vulnerability-response framework&lt;/a&gt; directs providers to continuously find, evaluate and address security weaknesses.&lt;/p&gt;

&lt;p&gt;Under the rules, providers are expected to begin reducing the risk from the most serious internet-facing and likely exploitable vulnerabilities within two or four days, depending on the potential impact. FedRAMP 20x providers must also verify the condition of their machine-based systems at least once every three days. The Cybersecurity and Infrastructure Security Agency has also directed &lt;a href="https://www.nextgov.com/cybersecurity/2026/06/cisa-directive-revamps-how-agencies-prioritize-vulnerable-systems/414096/"&gt;similar timelines&lt;/a&gt; for the most risky flaws that need immediate patching.&lt;/p&gt;

&lt;p&gt;Waterman said companies will not meet those expectations by leaving compliance personnel separated from the engineers who build and maintain their products. Security, engineering and product teams must be able to work together and make changes quickly enough to counter AI-backed cyberattacks, he said.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The compliance part of FedRAMP is how you assure us that you&amp;rsquo;re doing that,&amp;rdquo; he said. But if a company is not already motivated to invest in security and integrate those functions, he added, its approach &amp;ldquo;will not succeed.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It is about you being an ambassador to your business to make sure that your business is properly investing in security and making the changes necessary, which is going to include changes to your job in order to make your business successful,&amp;rdquo; Waterman argued. &amp;ldquo;Otherwise, you will fail because you cannot play this game the way that we played it last year.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Nextgov/FCW Managing Editor Edward Graham contributed to this story.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/23/IMG_2442/large.jpg" width="618" height="284"><media:description>FedRAMP Director Pete Waterman speaks at Carahsofts FedRAMP Summit on July 23, 2026.</media:description><media:credit>Frank Konkel / Government Executive</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/23/IMG_2442/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Russian hackers can steal government emails without victims clicking a link, cyber agencies warn</title><link>https://www.nextgov.com/cybersecurity/2026/07/russian-hackers-can-steal-government-emails-without-victims-clicking-link-cyber-agencies-warn/414967/</link><description>The Russia-linked Laundry Bear group has compromised more than 10 Western organizations through malicious emails that can trigger an exploit when they are viewed or previewed.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Thu, 23 Jul 2026 13:13:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/russian-hackers-can-steal-government-emails-without-victims-clicking-link-cyber-agencies-warn/414967/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Russian state-backed hackers have exploited a vulnerability in widely used email software to steal messages, passwords and authentication data from Western government agencies and other organizations, U.S. and allied cyber-intelligence authorities said Thursday.&lt;/p&gt;

&lt;p&gt;The campaign is notable because it does not require victims to click a malicious link or download an attachment. The exploit can instead activate when someone simply opens or previews an email in an unpatched version of the Zimbra Collaboration Suite &amp;mdash; a popular alternative to major collaborative messaging platforms like Microsoft Exchange or Google Workspace &amp;mdash; according to a joint advisory issued by the Cybersecurity and Infrastructure Security Agency, National Security Agency and FBI.&lt;/p&gt;

&lt;p&gt;The Russian hacking group, known primarily as Laundry Bear, has successfully targeted more than 10 organizations since July 2025, the agencies said. The campaign has hit the defense industrial base, federal and local governments, law enforcement, technology companies, educational institutions, media outlets and nongovernmental organizations.&lt;/p&gt;

&lt;p&gt;The hackers sought to steal email addresses, passwords and two-factor authentication tokens, which could allow them to retain access to compromised accounts even after obtaining a victim&amp;rsquo;s password. Their tools also attempted to collect an organization&amp;rsquo;s email directory, as&amp;nbsp;much as 90 days of a victim&amp;rsquo;s communications and other sensitive information.&lt;/p&gt;

&lt;p&gt;The Treasury Department&amp;rsquo;s Financial Crimes Enforcement Network purchased a Zimbra standard support subscription in February 2025, according to federal contracting data listed in GovTribe, a federal market intelligence platform owned by&lt;em&gt; Nextgov/FCW&lt;/em&gt; parent company GovExec. The purchase does not indicate whether FinCEN used the vulnerable version of the software or was targeted in the campaign.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, Laundry Bear&amp;rsquo;s current campaign uses a zero-click exploit that only requires a user to view a malicious email,&amp;rdquo; CISA said in a statement.&lt;/p&gt;

&lt;p&gt;Proofpoint, which also investigated the activity, &lt;a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits"&gt;describes&lt;/a&gt; the technique as a &amp;ldquo;half-click&amp;rdquo; exploit because the victim must still open or preview the email. The company said no additional interaction is required once the message appears in a vulnerable Zimbra webmail client.&lt;/p&gt;

&lt;p&gt;The emails were sent from both attacker-controlled Proton Mail accounts and addresses that had already been compromised, according to Proofpoint.&lt;/p&gt;

&lt;p&gt;In one example released by the company, the sender claimed to represent a Belgian media-verification organization and proposed cooperation among European institutions combating disinformation. The message contained a legitimate-looking link to a European Union events calendar, but the malicious code was embedded directly in the email itself.&lt;/p&gt;

&lt;p&gt;CISA urged organizations to update all Zimbra mail software, monitor their email systems for suspicious activity and review the technical indicators included in the advisory. Organizations that find evidence of a compromise should follow the agencies&amp;rsquo; remediation guidance rather than relying solely on installing the available patch.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;CISA continues to see sophisticated and less sophisticated nation-state cyber groups deploy increasingly novel exploits into a highly successful capability to disrupt critical infrastructure or conduct espionage,&amp;rdquo; said Chris Butera, CISA&amp;rsquo;s acting executive assistant director for cybersecurity.&lt;/p&gt;

&lt;p&gt;The advisory was also backed by defense, cybersecurity and intelligence agencies from Australia, Canada, New Zealand, the United Kingdom and more than a dozen European countries.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/23/072326emailNG/large.jpg" width="618" height="284"><media:credit>da-kuk/Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/23/072326emailNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Lawmakers get taste of AI-enabled cyberattacks in China-Taiwan war game</title><link>https://www.nextgov.com/cybersecurity/2026/07/lawmakers-get-taste-ai-enabled-cyberattacks-china-taiwan-war-game/414938/</link><description>Representatives weighed responses to simulated Chinese cyberattacks on U.S. infrastructure during a tabletop exercise centered on a Taiwan crisis.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Wed, 22 Jul 2026 12:17:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/lawmakers-get-taste-ai-enabled-cyberattacks-china-taiwan-war-game/414938/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;Members and staffers from the House Homeland Security Committee and the House China Select Committee were put through a simulated Taiwan crisis Tuesday that tested how U.S. officials might respond to AI-backed cyberattacks targeting transportation and logistics networks needed to deploy American forces.&lt;/p&gt;

&lt;p&gt;The Center for Strategic and International Studies hosted the event to give lawmakers a window into the trade-offs and uncertainty that would shape the U.S. response to a fast-moving conflict involving China and its implications in American cyberspace.&lt;/p&gt;

&lt;p&gt;Among those participating were Republican Reps. Eli Crane of Arizona, Michael Guest of Mississippi and Michael McCaul of Texas, along with Democratic Rep. Shri Thanedar of Michigan and Puerto Rico Resident Commissioner Pablo Jos&amp;eacute; Hern&amp;aacute;ndez, also a Democrat.&lt;/p&gt;

&lt;p&gt;The scenario begins with China launching a massive military exercise around Taiwan in the summer of 2027, leaving U.S. officials unsure whether Beijing was being coercive, imposing a de facto blockade or preparing for a full invasion of the island, per a readout provided to reporters just before the simulation began. Beijing avoids using the term &amp;ldquo;blockade&amp;rdquo; but the moves effectively quarantine Taiwan, the summary says.&lt;/p&gt;

&lt;p&gt;Lawmakers are then told that U.S. intelligence analysts suspect Chinese hackers had begun targeting ports, freight rail systems, airports and other transportation networks that could be used to move U.S. forces and supplies. Some of the attacks cause immediate disruptions, while others appear designed to preserve access that could be leveraged later.&lt;/p&gt;

&lt;p&gt;Participants also have to decide which networks to defend first, how closely to coordinate with private sector critical infrastructure operators and whether moving U.S. forces would deter China or further escalate the crisis.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cyber &amp;ldquo;is always going to be a leader in any kinetic war,&amp;rdquo; McCaul told participants before reporters were asked to leave the war game room so lawmakers and staff could participate more candidly.&lt;/p&gt;

&lt;p&gt;The exercise notably included a smattering of AI-related attacks involving stolen credentials and interference with logistics and routing systems. AI is also used in one attack scenario for a misinformation campaign, per the readout. The final scenario involved a prompt injection, in which attackers try to &lt;a href="https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware"&gt;trick an AI system&lt;/a&gt; into following malicious instructions instead of its intended safeguards.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;This committee has been &lt;a href="https://www.nextgov.com/artificial-intelligence/2026/05/house-homeland-panel-gets-briefing-anthropics-mythos/413542/"&gt;briefed extensively&lt;/a&gt; on our latest AI capabilities, Anthropic in particular, the Mythos model, and the amount of destruction that Mythos can do if it&amp;rsquo;s in the wrong hands,&amp;rdquo; McCaul said, referring to the powerful cyber-focused AI model unveiled in early April. &amp;ldquo;And we know China is three to five months behind us. That&amp;rsquo;s not very long, in my judgment.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Current and former officials have long warned that China could disrupt U.S. military deployments by &lt;a href="https://www.thecipherbrief.com/americas-military-plans-depend-on-infrastructure-it-doesnt-secure"&gt;digitally sabotaging&lt;/a&gt; the largely private-sector ports, railways, airports and other infrastructure used to move troops and equipment overseas. Advanced AI tools, broadly, can &lt;a href="https://www.nextgov.com/cybersecurity/2026/07/ai-once-relegated-helping-hackers-certain-tasks-can-now-power-every-stage-cyberattack/414744/"&gt;help hackers&lt;/a&gt; work faster, carry out more parts of an attack automatically and target more systems at once.&lt;/p&gt;

&lt;p&gt;The war game scenario mirrors longstanding concerns surrounding &lt;a href="https://www.nextgov.com/cybersecurity/2024/04/some-volt-typhoon-victims-wont-know-theyre-impacted-mandiant-ceo-says/395659/"&gt;Volt Typhoon&lt;/a&gt;, a Chinese government-backed hacking group that U.S. officials say has spent years quietly burrowing into American critical infrastructure. The hackers are believed to be positioning themselves inside sectors such as communications, energy, transportation and water systems to disrupt them during a future conflict, including one over Taiwan.&lt;/p&gt;

&lt;p&gt;China claims Taiwan as part of its territory and seeks to bring the self-governing island under Beijing&amp;rsquo;s control. Its major role in &lt;a href="https://www.nextgov.com/ideas/2023/01/lessons-taiwans-rise-dominate-computer-chip-industry/381582/"&gt;producing advanced computer chips&lt;/a&gt; makes it strategically important to both China and the United States.&lt;/p&gt;

&lt;p&gt;U.S. spy agencies &lt;a href="https://www.dni.gov/files/ODNI/documents/assessments/ATA-2026-Unclassified-Report.pdf"&gt;assessed&lt;/a&gt; earlier this year that China is not planning to invade Taiwan in 2027. While Beijing has repeatedly refused to rule out using force, the intelligence community said it believes China still prefers to achieve unification without military action.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/22/072226WarGameNG/large.jpg" width="618" height="284"><media:description>Rep. Shri Thanedar, D-Mich. of the House Homeland Security Committee gets an overview of the CSIS war game simulating AI-cyber threats involving China and Taiwan.</media:description><media:credit>David DiMolfetta/Staff</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/22/072226WarGameNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Moving beyond checklists to living digital identity risk management</title><link>https://www.nextgov.com/cybersecurity/2026/07/moving-beyond-checklists-living-digital-identity-risk-management/414892/</link><description>COMMENTARY | The era of static checklists is over. The future belongs to living, adaptive digital identity programs.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Adam McBride</dc:creator><pubDate>Mon, 20 Jul 2026 18:23:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/moving-beyond-checklists-living-digital-identity-risk-management/414892/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The federal government is racing to deliver secure, seamless digital services to millions of Americans, from veterans seeking healthcare to citizens accessing benefits. Yet our digital identity systems too often rely on outdated frameworks that treat security as a one-time checkbox exercise.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The National Institute of Standards and Technology&amp;rsquo;s &lt;a href="https://csrc.nist.gov/pubs/sp/800/63/4/ipd"&gt;Special Publication 800-63-4&lt;/a&gt; changes that. Released this year, it marks a doctrinal shift from static compliance to a dynamic, holistic Digital Identity Risk Management (DIRM) process.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;As someone leading ICAM efforts at the Department of Health and Human Services and co-chairing related working groups, I believe agencies that treat this update as &amp;ldquo;just another revision&amp;rdquo; will fall behind. Those that lean in will build identity systems that are more secure, equitable and user-friendly in an era of sophisticated threats and rising public expectations.&lt;/p&gt;

&lt;p&gt;The previous version, SP 800-63-3, served us well by establishing risk-based assurance levels (IAL, AAL and FAL). But the digital landscape has evolved dramatically. Phishing attacks have grown more targeted, synthetic identity fraud proliferates and users demand frictionless experiences across devices.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;SP 800-63-4 responds with a five-step DIRM lifecycle: Define the online service, conduct impact assessments, select initial assurance levels, tailor controls and &amp;mdash; most importantly &amp;mdash; continuously evaluate and improve. This is not incremental; it embeds privacy, customer experience and threat resistance into every decision.&lt;/p&gt;

&lt;p&gt;A core advancement is the raised bar for Identity Assurance Levels (IAL). IAL1 no longer tolerates purely self-asserted identities. Even at the lowest level, agencies must validate core attributes against authoritative or credible sources to counter bots and synthetic fraud.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;For higher assurance, IAL3 now requires attended sessions with biometric collection. Critically, the standard introduces &amp;ldquo;No IAL&amp;rdquo; for services where proofing adds no value &amp;mdash; preventing unnecessary data collection and aligning with privacy principles. This flexibility, guided by DIRM&amp;rsquo;s tailoring step, lets agencies avoid over-provisioning security that harms usability or under-provisioning that invites risk.&lt;/p&gt;

&lt;p&gt;Authentication Assurance Levels (AAL) see equally pragmatic evolution. Phishing resistance moves from AAL3 specialty to a requirement offered at AAL2 and mandated at AAL3. Modern authenticators like FIDO2 passkeys and non-exportable keys in secure elements become central, while session management relaxes appropriately (e.g., longer timeouts with device-bound credentials) to reduce user fatigue.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;These changes directly support &lt;a href="https://www.govinfo.gov/content/pkg/DCPD-201400778/pdf/DCPD-201400778.pdf"&gt;Executive Order 13681&lt;/a&gt;&amp;rsquo;s MFA push and Zero Trust architectures without sacrificing security. Agencies can now inventory authenticators, conduct gap analyses and phase in phishing-resistant options &amp;mdash; practical steps that deliver measurable risk reduction.&lt;/p&gt;

&lt;p&gt;Federation Assurance Levels (FAL) similarly adapt to modern models, including subscriber-controlled wallets. The emphasis on performance metrics, redress processes and AI/ML governance stands out. Organizations must now document AI use in proofing or fraud detection, assess risks per the NIST AI RMF and ensure human oversight for redress. No longer can automated systems operate as black boxes. Users denied access deserve transparent, trackable paths to resolution &amp;mdash; essential for equity and public trust.&lt;/p&gt;

&lt;p&gt;The new Digital Identity Acceptance Statement (DIAS) serves as the capstone: a living record of impact assessments, tailoring decisions, compensating controls and monitoring plans. Paired with the GSA DIRA Playbook, it turns DIRM from abstract framework into operational reality.&lt;/p&gt;

&lt;p&gt;For federal leaders, the benefits are clear. At HHS, expanding FedHub as a government-wide identity hub demands this risk-based agility. Services supporting veterans, healthcare data exchange via CARIN Alliance, or public benefits require tailored assurance that balances security with accessibility. Rigid checklists lead to either abandoned enrollments (hurting mission delivery) or unaddressed threats (risking breaches).&amp;nbsp;&lt;/p&gt;

&lt;p&gt;DIRM&amp;rsquo;s continuous evaluation &amp;mdash; tracking pass/fail rates, abandonment, fraud indicators and redress requests &amp;mdash; enables data-driven iteration. This is how we achieve &amp;ldquo;inclusive security&amp;rdquo;: strong enough to protect sensitive PII, flexible enough for diverse populations.&lt;/p&gt;

&lt;p&gt;Implementation will require effort. Cross-functional teams (IT, privacy, CX, legal) must reassess services, update DIAS documents, inventory authenticators and build redress mechanisms. Agencies should prioritize high-impact systems first, leveraging existing investments in PIV/CAC, ID.me, Login.gov and emerging tools. The ATARC Identity Management Working Group&amp;rsquo;s &lt;a href="https://atarc.org/project/white-paper-implementation-guide-transitioning-from-nist-sp-800-63-3-to-sp-800-63-4/"&gt;new Implementation Guide&lt;/a&gt; &amp;mdash; developed collaboratively with government and industry experts &amp;mdash; provides practical checklists, roadmaps, gap analyses and templates to accelerate this transition.&lt;/p&gt;

&lt;p&gt;Critics may worry about added bureaucracy. But DIRM reduces it by enabling risk-based tailoring instead of uniform mandates. It aligns identity programs with broader FISMA, RMF and Zero Trust initiatives while preparing for subscriber wallets and advanced biometrics. Ignoring the update risks non-compliance, poor user experiences and vulnerability to evolving threats.&lt;/p&gt;

&lt;p&gt;The federal government has invested billions in digital transformation. NIST SP 800-63-4 ensures those investments deliver trustworthy, resilient identity foundations. I urge CIOs, ICAM leaders and program managers to adopt the DIRM process now. Read the standard, use the implementation resources and produce DIAS documents that demonstrate thoughtful risk management. Our citizens &amp;mdash; veterans, patients and taxpayers &amp;mdash; deserve identity systems as modern and responsive as the services they access.&lt;/p&gt;

&lt;p&gt;The era of static checklists is over. The future belongs to living, adaptive digital identity programs. Let&amp;rsquo;s lead that transition together.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Adam McBride is the ICAM/IdAM Program Manager for the Department of Health and Human Services (HHS) and co-chair of the ATARC Identity Management Working Group. He has over fifteen years of experience in government and a retired Master Sargeant, US Army.&lt;/em&gt;&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/20/GettyImages_2211893962/large.jpg" width="618" height="284"><media:credit>Tatiana Maksimova / Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/20/GettyImages_2211893962/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item><item><title>Secret Service is examining apparent Iranian video outlining Trump motorcade routes, assassination opportunities</title><link>https://www.nextgov.com/cybersecurity/2026/07/secret-service-examining-apparent-iranian-video-outlining-trump-motorcade-routes-assassination-opportunities/414881/</link><description>The agency said it is looking into the Persian-language video, which uses polished, apparently AI-generated graphics to depict supposed motorcade routes in Florida and New York.</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">David DiMolfetta</dc:creator><pubDate>Mon, 20 Jul 2026 14:18:00 -0400</pubDate><guid>https://www.nextgov.com/cybersecurity/2026/07/secret-service-examining-apparent-iranian-video-outlining-trump-motorcade-routes-assassination-opportunities/414881/</guid><category>Cybersecurity</category><content:encoded>&lt;![CDATA[&lt;p&gt;The U.S. Secret Service is examining a video that appears to have been produced by Iranian operatives and aims to identify opportunities to assassinate President Donald Trump, including supposed motorcade routes used by his protective details in Florida and New York.&lt;/p&gt;

&lt;p&gt;The video, which was sent to &lt;em&gt;Nextgov/FCW &lt;/em&gt;by a U.S. government official, is titled &amp;ldquo;Where to Kill Trump?!&amp;rdquo; with the title written in a blood-stained font alongside a bloody silhouette of the president&amp;rsquo;s side profile. In high-quality, likely AI-generated red, black and white graphics of people, buildings, vehicles, roads and other infrastructure, it claims to show how the president and his Secret Service detail commute from Palm Beach International Airport in Florida to his Mar-a-Lago estate, and from LaGuardia Airport to Trump Tower in New York City.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;It has been taken off several sites since reports of it surfaced around the end of last week. The Secret Service is &amp;ldquo;aware of it and we&amp;rsquo;re looking into it,&amp;rdquo; a spokesperson for the agency said in a brief phone interview on Friday.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Protecting the president and those under our protection is a responsibility we take extremely seriously,&amp;rdquo; a spokesperson added in a follow-up email. &amp;ldquo;While we do not comment on the specifics of protective intelligence, our teams work around the clock to assess real-time information and intelligence, ensuring our protective operations remain layered, adaptive, and fully aligned to address the climate.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;The video is narrated in Persian with English captions. &amp;ldquo;This is no ordinary report,&amp;rdquo; the captions say. &amp;ldquo;Based on the most complex security protocols between 2024 and 2026, Donald Trump&amp;rsquo;s routine movements in the US have been gathered and decoded.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Almost three minutes long, the video describes the apparent core arrangement of the president&amp;rsquo;s motorcade, alongside the routes that are supposedly taken in each location. The Florida route also claims to show how Trump is escorted from Mar-a-Lago to the Trump International Golf Club in West Palm Beach during the weekends.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Nextgov/FCW&lt;/em&gt; is withholding details of the routes, road closures and security measures described in the video, on grounds that, if its contents are accurate enough, it may expose protective details that could put officials in danger. About halfway through the video, the captions say a specific location along one of the purported routes &amp;ldquo;seems like a very suitable location for the free people of the world!&amp;rdquo;&lt;/p&gt;

&lt;p&gt;At the end of the video, as it describes supposed street closure arrangements around Trump Tower, the captions tell viewers: &amp;ldquo;Stay tuned &amp;hellip; we are going to get even closer than this.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;It&amp;rsquo;s not immediately clear how widely the video has been circulated or who specifically produced it, nor when it was completed and disseminated, or whether more follow-up videos exist. Some social media posts last week attributed the clip to Iran&amp;rsquo;s state-backed Fars News Agency, though this could not be immediately verified.&lt;/p&gt;

&lt;p&gt;But if the video&amp;#39;s contents are sufficiently precise, it could raise concerns that Iran has expanded its surveillance and targeting efforts against the president, potentially revealing details about the routes and protective measures used by his Secret Service detail.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Tehran has long threatened to assassinate Trump in retaliation for the 2020 U.S. drone strike that killed Qasem Soleimani, the commander of Iran&amp;rsquo;s elite Quds Force. Those calls from Iranian leaders have intensified since Supreme Leader Ayatollah Ali Khamenei was killed in a joint U.S.-Israeli strike earlier this year that began the ongoing Iran war.&lt;/p&gt;

&lt;p&gt;The president makes regular trips to Florida to stay at his Mar-a-Lago estate, where he and his team often land at the Palm Beach airport, now officially named President Donald J. Trump International Airport. A &lt;em&gt;Nextgov/FCW&lt;/em&gt; analysis of White House travel pool reports shows that the president appears to have only made two trips to New York City via LaGuardia last year. Throughout 2026, Trump made visits to New York, but they appear to not have involved LaGuardia as a destination airport.&lt;/p&gt;

&lt;p&gt;Former presidents receive lifelong Secret Service protection. In 2024, while out of office, Trump regularly traveled by Secret Service motorcade from Trump Tower to the Manhattan Criminal Courthouse for his criminal hush-money trial. Trump also used his private Boeing 757, nicknamed &amp;ldquo;Trump Force One,&amp;rdquo; to travel between Florida and New York during the trial, including &lt;a href="https://www.cnbc.com/2023/04/03/trump-to-fly-to-new-york-to-surrender-on-indictment-.html"&gt;flights&lt;/a&gt; into &lt;a href="https://www.newsweek.com/donald-trump-plane-laguardia-airport-new-york-photo-hush-money-trial-1892047"&gt;LaGuardia&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Iran&amp;rsquo;s permanent mission to the United Nations did not return a request for comment.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;What&amp;rsquo;s most telling about this video is what it does not include,&amp;rdquo; said Paul Eckloff, a former Secret Service official who oversaw presidential protection duties for then President Barack Obama and for Trump in his first term. &amp;ldquo;Is this video a coded signal to attack things that are not listed?&amp;rdquo; he said, referring to the fact that presidential routes in Washington, D.C. are not described.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;That would be a concern of mine, that there is another target that they&amp;rsquo;re trying to steer concern away from. Or is D.C. such a hard target that they wouldn&amp;rsquo;t attempt it? I don&amp;rsquo;t know,&amp;rdquo; Eckloff said. He added that fear is a &amp;ldquo;primary export&amp;rdquo; of Iranian groups and opined that even a small attack on the president in D.C. would shake confidence more profoundly than an attack in Florida or New York.&lt;/p&gt;

&lt;p&gt;The Secret Service is likely conducting a forensic review of the video with assistance from the intelligence community, Eckloff said.&lt;/p&gt;

&lt;p&gt;Investigators would look for distinctive words, phrases or technical clues that could help trace the video to its original source, including the AI model or other tools used to make it. Any credible findings could then be shared with the president&amp;rsquo;s protective detail, which may adjust motorcade routes or strengthen security along them, he added.&lt;/p&gt;

&lt;p&gt;The video illustrates how generative AI is &lt;a href="https://bisi.org.uk/reports/ai-driven-information-warfare-disinformation-and-psychological-manipulation"&gt;increasingly being used&lt;/a&gt; in information operations and modern-day warfare. AI tools can give such content a more polished and realistic appearance, but the apparent use of AI doesn&amp;rsquo;t necessarily prove whether the routes or scenarios depicted are based on actual gathered intelligence.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;The Secret Service has all sorts of intelligence sources &amp;hellip; both in this country and outside, so it&amp;rsquo;s understandable that they would already have this and be evaluating it in terms of the procedures followed,&amp;rdquo; said A.T. Smith, a former Secret Service deputy director who served in the agency for nearly 30 years between the Reagan and Obama administrations.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;It&amp;rsquo;s not uncommon for these sorts of things to pop up when you&amp;rsquo;re having these kinds of events in the world,&amp;rdquo; he added. &amp;ldquo;I&amp;rsquo;m sure the service is getting information from not only American intelligence agencies and sources, but probably around the world as well.&amp;rdquo;&lt;/p&gt;

&lt;p&gt;Earlier this month, Trump departed the NATO summit in Turkey aboard the older Air Force One instead of the Qatari-donated Boeing 747-8 after U.S. officials received Israeli intelligence warning of a possible Iranian plot to target him, The Wall Street Journal &lt;a href="https://www.wsj.com/politics/national-security/trump-air-force-one-israel-iran-intelligence-7b51d456"&gt;reported&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The video has emerged as the war between the United States and Iran continues to widen, with American forces striking Iranian targets and Tehran retaliating against U.S. personnel and regional allies. At least two U.S. service members were killed Friday while defending against an Iranian missile and drone attack in Jordan, the U.S. military said over the weekend.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;Given Trump&amp;rsquo;s worsening war in Iran, this video is very concerning, and I hope the Secret Service investigates it properly and adjusts protectee operations as necessary to counter this threat,&amp;rdquo; said Rep. Bennie Thompson, D-Miss., the ranking member on the House Homeland Security Committee.&lt;/p&gt;

&lt;p&gt;&amp;ldquo;However, I have become increasingly concerned the Secret Service does not have the proper resources to do its job after its funding has been diverted to construction of Trump&amp;rsquo;s ballroom and it has frequently been forced to devote vast resources to act as a chauffeur for JD Vance and his family,&amp;rdquo; he said, referring to recent reports that federal funds were &lt;a href="https://www.washingtonpost.com/investigations/2026/06/18/budget-office-redirects-352m-secret-service-funds-white-house-security/"&gt;redirected&lt;/a&gt; toward security work connected to the White House ballroom and that agents have &lt;a href="https://www.ms.now/news/veeps-security-detail-fed-up-with-hastily-arranged-personal-and-family-travel-requests"&gt;grown frustrated&lt;/a&gt; with the Vance family&amp;rsquo;s frequent, last-minute travel requests.&lt;/p&gt;
]]&gt;</content:encoded><media:content url="https://cdn.nextgov.com/media/img/cd/2026/07/20/072026TrumpNG/large.jpg" width="618" height="284"><media:description>U.S. President Donald Trump walks onto the stage before presenting the FIFA World Cup Winner's Trophy to Spain following the FIFA World Cup 2026 Final match between Spain and Argentina at New York New Jersey Stadium on July 19, 2026 in East Rutherford, New Jersey. </media:description><media:credit>Ryan Pierse - FIFA/FIFA via Getty Images</media:credit><media:thumbnail url="https://cdn.nextgov.com/media/img/cd/2026/07/20/072026TrumpNG/thumb.jpg" width="138" height="83"></media:thumbnail></media:content></item></channel></rss>