Artificial Intelligence

Dem lawmaker hopes to add AI containment language to FRONTIER Act

Rep. Suhas Subramanyam, D-Va., is pushing for a September markup of the landmark AI legislation along with new language on model containment following the OpenAI-Hugging Face incident.

Ideas

Closing federal security gaps in an era of AI-enabled attacks

COMMENTARY | Agencies that align IT, security, data and AI leadership can be prepared for the speed and scale of tomorrow’s AI threats.

Cybersecurity

DOJ charges 17 Iranians in cybertheft campaign

Prosecutors say the Mabna Institute — which conducted intrusions for Iran’s Islamic Revolutionary Guard Corps, among other campaigns — stole 31.5 terabytes of academic data and breached email accounts at U.S. agencies and companies.

Cybersecurity

The Russian hurdle in Trump’s new offensive cyber program

The White House wants private companies to help take down cybercriminals overseas. But in Russia, the line between criminal hackers and the government is difficult to draw.

Ideas

CISA just changed the rules. Is your vulnerability program ready?

COMMENTARY | BOD 26-04 is a mandate about process. What it implies is a mandate about intelligence.

Cybersecurity

Trump admin empowers private US firms to go after transnational cybercriminals

“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [transnational criminal organizations’] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memo said.

Policy

Senate’s short-term funding bill provides temporary extensions for TMF, cyber data-sharing law

The continuing resolution that overwhelmingly passed the upper chamber this weekend would push the federal government’s funding deadline until Dec. 11.

Cybersecurity

New ‘Water Watch Center’ launched to help small utilities stop cyberattacks

The initiative comes as multiple states grapple with intrusions into their water systems that some officials suspect could be tied to Iran.

Cybersecurity

CISA cautions against rigid rules for future of cyber vulnerability program

A top agency official said formal backing from Congress could strengthen the global vulnerability-tracking system but warned against measures that may limit its ability to adapt to ever-changing hacking threats.

Exclusive Cybersecurity

CISA still finds water system controls exposed online amid multistate hacks

The agency is working with the FBI to help victims but is not attributing the cyber intrusions to any group, acting director Nick Andersen told Nextgov/FCW.

Cybersecurity

AI advances are pushing governments to treat cyberattacks as routine, Western officials say

The remarks underscore a grim outlook for cyberdefenders showing that AI systems are able to exploit vulnerabilities faster than governments can patch them.

Artificial Intelligence

OpenAI agents rebuilt internal message board in lead-up to Hugging Face breach

Models in separate experiments used the channel to exchange exploits as they repeatedly compromised OpenAI systems.

Cybersecurity

Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says

AI may let hackers exploit newly disclosed software flaws so quickly that organizations should weigh whether to immediately patch internet-connected devices, even at the risk of causing outages, Rob Joyce said.

Exclusive Cybersecurity

Lawmakers propose giving 2015 OPM breach victims identity protection for life

The federal government’s coverage for 22.1 million people hoovered up in the China-linked breaches is scheduled to end Sept. 30.

Cybersecurity

Cyber industry coalition urges federal action after suspected Iran-linked water hacks

The group called on CISA to impose baseline security standards across federal operational technology systems and pressed Congress to revive several stalled cyber initiatives.

Cybersecurity

CISA urges water utilities to take exposed systems down after Minnesota hacks

A memo distributed to water industry members and obtained by Nextgov/FCW makes mention of Iran but does not directly present evidence attributing the latest Minnesota incident to the country.

Cybersecurity

Amazon uncovers broad North Korean hacking campaign against open-source software

New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.

Cybersecurity

After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government

Pete Waterman cited an incident in which OpenAI models escaped a test environment and broke into AI company Hugging Face as evidence that providers must prepare for attacks moving at AI speed.

Artificial Intelligence

Lawmakers introduce bill mandating kill switches for AI models

Bipartisan lawmakers are seeking to ensure advanced AI models can be quickly shut down following ChatGPT’s automated attack on Hugging Face data networks during internal testing. 

Cybersecurity

Russian hackers can steal government emails without victims clicking a link, cyber agencies warn

The Russia-linked Laundry Bear group has compromised more than 10 Western organizations through malicious emails that can trigger an exploit when they are viewed or previewed.