Cyber Threats
Updated

ShinyHunters claims FBI data theft, demands bureau retract cyber warning

The hacking group says it obtained sensitive employee and applicant records. The full scope of the claimed breach remains unclear.

AI agents are getting better at cybersecurity. That cuts both ways.

NIST is testing agentic AI to help enrich the National Vulnerability Database, even as increasingly capable models demonstrate why cyber autonomy needs careful containment.

FBI needs access to latest models to police AI-driven cybercrime, director says

Federal Bureau of Investigation Director Kash Patel spoke about how he thinks the bureau can best police new AI-related criminal activity, beginning with model access.

25 years after 9/11, spy agencies face old lessons and new threats 

Former intelligence officials describe a nation better equipped to disrupt terrorist plots, but still wrestling with the costs of its response and how to prevent the next crisis under escalating technology threats.

Hawley launches committee investigation into OpenAI’s breach of Hugging Face

Following reports of two autonomous attacks conducted by OpenAI’s agents, Sen. Josh Hawley sent a letter to OpenAI CEO Sam Altman for answers.

Lawmakers ask Commerce to sanction Indian firms involved in mercenary hacking

The “hack-for-hire” entities have systematically targeted newsrooms covering corporate fraud, legal teams in high-stakes litigation and NGOs.

Intelligence agencies warn of China’s large-scale AI model distillation efforts

Three agencies issued a joint statement warning that Chinese companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI have used the tactics to extract billions of tokens from U.S. models.

Senator asks NSA to update Americans about VPN spying risks

A congressional analysis found foreign spies could trace users by comparing encrypted traffic entering and leaving a VPN server, according to the lawmaker’s office.

ATF investigating ‘major’ cyber incident after ransomware group claim

The agency says the affected system was isolated from its broader network and eForms platform but has not disclosed whether data was stolen.

White House to soon launch water provider cyber protection program

The plans come as several states face water system intrusions from what some official suspect could be linked to Iran.

FBI disables China-linked hacking tools used against US agencies

A hacking group used the tools to target networks belonging to NASA, the Federal Reserve, the National Institutes of Health, the U.S. Senate and the departments of Energy, Justice and Health and Human Services.

Treasury sanctions Iranian hackers tied to critical infrastructure breaches

Four of the five people named in the cyber action were also charged last week in the Justice Department’s expanded Mabna Institute case.

Dem lawmaker hopes to add AI containment language to FRONTIER Act

Rep. Suhas Subramanyam, D-Va., is pushing for a September markup of the landmark AI legislation along with new language on model containment following the OpenAI-Hugging Face incident.

Closing federal security gaps in an era of AI-enabled attacks

COMMENTARY | Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.

DOJ charges 17 Iranians in cybertheft campaign

Prosecutors say the Mabna Institute — which conducted intrusions for Iran’s Islamic Revolutionary Guard Corps, among other campaigns — stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.

The Russian hurdle in Trump’s new offensive cyber program

The White House wants private companies to help take down cybercriminals overseas. But in Russia, the line between criminal hackers and the government is difficult to draw.

CISA just changed the rules. Is your vulnerability program ready?

COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.