Cyber Threats
Exclusive

CISA still finds water system controls exposed online amid multistate hacks

The agency is working with the FBI to help victims but is not attributing the cyber intrusions to any group, acting director Nick Andersen told Nextgov/FCW.

AI advances are pushing governments to treat cyberattacks as routine, Western officials say

The remarks underscore a grim outlook for cyberdefenders showing that AI systems are able to exploit vulnerabilities faster than governments can patch them.

OpenAI agents rebuilt internal message board in lead-up to Hugging Face breach

Models in separate experiments used the channel to exchange exploits as they repeatedly compromised OpenAI systems.

Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says

AI may let hackers exploit newly disclosed software flaws so quickly that organizations should weigh whether to immediately patch internet-connected devices, even at the risk of causing outages, Rob Joyce said.

Exclusive

Lawmakers propose giving 2015 OPM breach victims identity protection for life

The federal government’s coverage for 22.1 million people hoovered up in the China-linked breaches is scheduled to end Sept. 30.

Cyber industry coalition urges federal action after suspected Iran-linked water hacks

The group called on CISA to impose baseline security standards across federal operational technology systems and pressed Congress to revive several stalled cyber initiatives.

CISA urges water utilities to take exposed systems down after Minnesota hacks

A memo distributed to water industry members and obtained by Nextgov/FCW makes mention of Iran but does not directly present evidence attributing the latest Minnesota incident to the country.

Amazon uncovers broad North Korean hacking campaign against open-source software

New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.

After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government

Pete Waterman cited an incident in which OpenAI models escaped a test environment and broke into AI company Hugging Face as evidence that providers must prepare for attacks moving at AI speed.

Lawmakers introduce bill mandating kill switches for AI models

Bipartisan lawmakers are seeking to ensure advanced AI models can be quickly shut down following ChatGPT’s automated attack on Hugging Face data networks during internal testing. 

Russian hackers can steal government emails without victims clicking a link, cyber agencies warn

The Russia-linked Laundry Bear group has compromised more than 10 Western organizations through malicious emails that can trigger an exploit when they are viewed or previewed.

Lawmakers get taste of AI-enabled cyberattacks in China-Taiwan war game

Representatives weighed responses to simulated Chinese cyberattacks on U.S. infrastructure during a tabletop exercise centered on a Taiwan crisis.

Moving beyond checklists to living digital identity risk management

COMMENTARY | The era of static checklists is over. The future belongs to living, adaptive digital identity programs.

White House announces ‘Gold Eagle’ AI clearinghouse for cyber vulnerabilities

The initiative stems from a June 2 executive order that urged advanced AI developers to grant the government early access to their capabilities to address potential vulnerabilities.

AI, once relegated to helping hackers with certain tasks, can now power every stage of a cyberattack

Researchers determined that AI was used in steps across entire cyber operations to identify security flaws, generate commands and carry out parts of intrusions, sometimes with little human oversight. Both U.S. and Chinese AI models have been involved.

Russian hackers exploit weak router security to breach critical infrastructure, Western allies warn

The guidance comes as the United Kingdom and European Union blamed a major Russian intelligence unit for an attempted attack on Poland’s power grid last year.

Exclusive

DHS network intrusion was twice ruled a false positive before breach confirmed

Suspicious activity on the Homeland Security Information Network, which is being used to support World Cup games around the U.S., was first detected around mid-to-late May.