Cyber Threats

Moving beyond checklists to living digital identity risk management

COMMENTARY | The era of static checklists is over. The future belongs to living, adaptive digital identity programs.

White House announces ‘Gold Eagle’ AI clearinghouse for cyber vulnerabilities

The initiative stems from a June 2 executive order that urged advanced AI developers to grant the government early access to their capabilities to address potential vulnerabilities.

AI, once relegated to helping hackers with certain tasks, can now power every stage of a cyberattack

Researchers determined that AI was used in steps across entire cyber operations to identify security flaws, generate commands and carry out parts of intrusions, sometimes with little human oversight. Both U.S. and Chinese AI models have been involved.

Russian hackers exploit weak router security to breach critical infrastructure, Western allies warn

The guidance comes as the United Kingdom and European Union blamed a major Russian intelligence unit for an attempted attack on Poland’s power grid last year.

Exclusive

DHS network intrusion was twice ruled a false positive before breach confirmed

Suspicious activity on the Homeland Security Information Network, which is being used to support World Cup games around the U.S., was first detected around mid-to-late May.

Exclusive

Hackers breached DHS information-sharing network, people familiar say

The Homeland Security Information Network is used by government, international and private sector partners to share sensitive but unclassified information.

The hidden market turning home internet connections into cover for hackers

Researchers traced millions of household IP addresses through residential proxy networks, calling the illicit use of those connections the “blood diamonds of the digital age.”

Planned NDAA amendment would codify CISA’s role in cyber vulnerability program

The measure, expected as a proposed add-on to the government’s 2027 defense package, targets a bedrock cybersecurity vulnerability-tracking system after a contracting fiasco last year.

US officials see Iran cyber threat persisting despite preliminary deal

Officials’ views reflect a recurring concern that cyber operations would continue regardless of conflict status, even as the Trump administration pursues a diplomatic off-ramp with Tehran.

Warner presses CISA on whether staff cuts weakened regional cyber support

The Senate Intelligence Committee’s top Democrat is asking the cyber agency for workforce charts, vacancy details and service data as state and local support comes under strain.

NSPM-12: The NSS cyber memo agencies cannot ignore

COMMENTARY | NSPM-12 dropped last week. Anyone who has spent serious time in federal cybersecurity should read it carefully.

Exclusive

Warner proposes overhaul of critical infrastructure cyber plans as AI threats rise

The measure would require CISA to refresh long-outdated sector cybersecurity plans as lawmakers warn that advanced AI tools could accelerate the discovery and exploitation of software flaws.

New coalition will enter legal debate over industry’s role in government cyber missions

Its formation occurs amid a broader discussion over whether existing laws are suited for cyber activities that increasingly depend on cooperation between the government and private sector.

Hackers are already laying groundwork to disrupt the 2026 midterms, research says

The report from cybersecurity firm Check Point lands as the Trump administration pushes new voting rules and intelligence officials face questions about how they are handling foreign election threats.

Commercial location data is being used to target US servicemembers, lawmakers warn

U.S. Central Command said it “has received multiple threat reports concerning adversary exploitation of commercial location data to target or surveil U.S. personnel in theater.”

Exclusive

Iran’s hackers are coordinating more closely, Israel’s top cyberdefense official says

Yossi Karadi also said he is pressing major AI labs for access to advanced models like Anthropic’s Mythos to help defend Israeli government networks.

Why compliance alone doesn’t make federal networks secure

COMMENTARY | Zero Trust is an ongoing operational discipline, not a project with a completion date.