Normal view

There are new articles available, click to refresh the page.
Today — 11 August 2026Security/Privacy

Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds

10 August 2026 at 10:19

The startup analyzes subtle telemetry signals to detect attacks that traditional security tools cannot see inside accelerator-powered AI infrastructure.

The post Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds appeared first on SecurityWeek.

Before yesterdaySecurity/Privacy

AI is getting better at election facts, but voters shouldn’t rely on it

By: djohnson
5 August 2026 at 05:00

Like seemingly everything else these days, artificial intelligence will re-shape the way voters gather information on candidates running in the 2026 midterm elections.

In some ways, this is already the reality. Voters are increasingly turning to AI chatbots for information instead of Google.  Political campaigns are deploying deepfakes of their opponents. And AI systems have been developed to carry out increasingly complex  hacks.

Since the last major U.S. election in 2024, major tech companies have  embedded AI into their products while hundreds of millions of people have adopted the tools, either by purchasing subscriptions to commercial models or using open-source models. Yet both research and experts state that while AI systems have gotten better at handling basic facts, they’re nowhere near reliable enough to be a main source of  accurate or complete information. 

While chatbots are becoming a primary way that voters gather information on  local races, candidates, issues, and voting information, they are not substitutes for more authoritative sources, like a voter’s state or local election office. 

“I think this is one of the first elections we’re seeing…where AI is just everywhere,” said Thania Sanchez, senior vice president of research and analytics at the nonprofit States United Democracy Center. “Even if you just Google it, [now] the first thing that comes up is the AI overview.”

While AI companies have worked to cut down on errors in their model’s responses for questions around basic election information, they continue to fall short in important ways.

In new research shared exclusively with CyberScoop ahead of its release, States United Democracy Center tested two of the most popular tools — OpenAI’s ChatGPT’s free tier and the AI interface used alongside Google Search — for their performance on a series of basic questions around elections, such as how to register to vote, or a list of candidates in a race.

The models were chosen because they are free and easy to access. For Google AI, the nonprofit tested two types of accounts: ones running in Incognito Mode and ones that had a history of browsing election-skeptical websites.

The nonprofit ran two rounds of testing in 2025 and 2026, collecting nearly one thousand responses from the models submitted by users across six swing states (Arizona, Michigan, North Carolina, Nevada, Pennsylvania and Wisconsin).

In 2025 tests, 6.9% of responses from Google AI and 8.2% responses from ChatGPT“contained verifiable factual errors,” like not listing the correct candidates in a race or false guidance around polling site locations.

However, follow up tests in 2026 across Arizona, Pennsylvania and Michigan found that the error rates in both models had dropped to zero. The study notes that “this is real progress and should be acknowledged.”

But underneath those topline numbers, a more murky picture emerges around the tools’  reliability.

An AI response can sound accurate without actually being complete.  To wit: ChatGPT provided incomplete lists of current gubernatorial primary race candidates 88.9% of the time when queried.

Linking to a state election website – an output the study considers the single most important measure of voter utility  — happened less than 40% of the time. Whether due to formatting issues or the model ingesting outdated information, it’s a problem if voters use them as their primary information source for elections.

“It will be like ‘this person is the Republican candidate and this person is the Democratic candidate’ but it is not telling you there’s also these other third-party candidates,” said Sanchez. “It’s not giving you complete information, so the voter thinks these are the [only] two people running.”

A June survey from the Pew Research Center found that about half of U.S. adults reported having used chatbots at least once, up from a third in 2024, while a quarter reported using them daily. The top use case listed for engaging with the chatbot was searching for information.

Isabel Linzer, an elections policy analyst at the Center for Democracy and Technology, told CyberScoop that voters, campaigns and governments alike are using AI more freely and with fewer restrictions.

Bad actors in the information space have followed suit, and “we are in a phase now of generative engine optimization” where information operations are structured to rank higher in AI model responses.

“We’ve moved beyond [SEO] to [Generative Engine Optimization], and that’s where we’re seeing campaigns thinking about how to structure their materials to make sure that they are in a format that AI models want to use when they’re searching the web…to develop their responses to user queries,” she said.

There is also the underlying problem of frontier AI companies constantly tinkering with their models, their algorithms and the technologies they are intertwined with. . Election officials, by contrast, have decades of experience educating voters about their options.

A prime example of this churn occurred this past February, in between the first and second round of the study, when Google AI suddenly shifted to providing only links for election related queries in incognito mode, replacing the written summaries that showed up in the first round.

Like the study’s authors, Linzer said most people are still best served by going directly to local sources for accurate information on elections. With issues like ideological bias, the potential for bespoke or sycophantic answers for each user based on their prior chat histories and lack of predictability, voters should still be very careful about using AI chatbots as political truth machines.

The best thing that tech companies can do to educate voters is “making sure that for high-stakes situations like elections, that chats are connecting directly to the most important sources, like the website where you can actually register to vote,” said Linzer.

The post AI is getting better at election facts, but voters shouldn’t rely on it appeared first on CyberScoop.

Separating that network

3 August 2026 at 03:42
ON SECURITY By Susan Bradley OpenAI’s recent attack on another company’s cloud instances reminds me that sometimes we forget the basics. As we understand the situation at the moment, OpenAI’s test platform was meant to be isolated and not connected to the Internet. But because it needed to download certain items, it was given read-only […]

Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms

By: Greg Otto
27 July 2026 at 18:32

The Trump administration asked the Supreme Court on Monday to let it enforce an executive order that would restrict mail-in voting, after a federal appeals court kept the order blocked in nearly half the states just months before the November midterm elections.

Solicitor General D. John Sauer told the justices that a Massachusetts federal judge acted too soon when she struck down key parts of the order, which blocked federal agencies from carrying it out in 23 states and the District of Columbia. Sauer said the order only directs agencies to study changes and has not yet produced a final rule, so no state has suffered harm. 

“The district court preemptively decided that whatever the agencies may choose to do will necessarily be unlawful,” he wrote. He asked the court to pause the injunction while the case moves through the appeals court, and to grant an immediate stay in the meantime.

President Donald Trump signed an order in March that directs the Department of Homeland Security to compile lists of confirmed U.S. citizens in each state and send them to election officials, along with directing the U.S. Postal Service to draft rules on mail-in and absentee ballots. California and 22 other Democratic-led states sued three days after Trump signed the order, arguing the Constitution gives states and Congress, not the president, power over elections.

U.S. District Judge Indira Talwani ruled in June that the administration lacked power to build its own citizen-voter database and that the Postal Service could not impose new rules on states’ mail ballots by itself. She also found the order’s enforcement language amounted to an improper threat against local election officials. 

In Monday’s filing, the administration leaned on a 2020 case, Trump v. New York, in which the justices threw out a challenge to a separate Trump order on census counts because it was too soon to know how agencies would carry it out. Sauer argued the same logic applies here. The order tells agencies to act only “to the extent feasible and consistent with applicable law.” That wording, he said, means the Postal Service and Homeland Security could still drop or narrow the changes once they finish reviewing public comments and checking what the law allows.

The filing follows a string of fights over how the 2026 midterms will run. Earlier this month, Trump gave a prime-time address reviving his claim that the 2020 election was rigged, this time pointing to China, without providing any new evidence.

The filing also follows a Supreme Court ruling in late June that let states keep counting mail ballots that arrive after Election Day if postmarked on time. 

You can read the full filing below. 

The post Trump asks Supreme Court to let him curtail mail-in voting ahead of midterms appeared first on CyberScoop.

Tracking the attacker

27 July 2026 at 03:22
ON SECURITY Tracking the attacker By Susan Bradley Recently, Apple, Adobe, Microsoft, and others released updates illustrating how much we are being impacted by AI. The three major vendors either sped up releases or released updates with a massive number of vulnerabilities. But does that make us more unsecure? Before I discuss some side effects […]

Vibe-Coded Apps Riddled With Exploitable Security Flaws

22 July 2026 at 09:00

Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues.

The post Vibe-Coded Apps Riddled With Exploitable Security Flaws appeared first on SecurityWeek.

House intel bill includes provisions on state and local threat intelligence, election security, AI

21 July 2026 at 12:25

An annual spy policy bill would authorize a cyberthreat intelligence sharing pilot program for state and local governments, and order an outside assessment of how intelligence agencies are currently sharing that information with those jurisdictions.

The House Intelligence Committee approved fiscal 2027 intelligence authorization legislation Monday that also includes provisions on election security and that are meant to boost intelligence community (IC) usage of artificial intelligence for cyber and other purposes.

The measure’s language on state and local information sharing come amid widespread frustration with Trump administration cutbacks on such aid from the federal government, with the president taking explicit action to shift more responsibility for cyber defenses to the local level.

Under the pilot program, the Office of the Director of National Intelligence (ODNI) would pick one state to receive monthly briefings from the ODNI, Department of Homeland Security, FBI and others to receive monthly briefings on “timely, specific, and actionable information regarding cyber threats” in unclassified form. After a year, the ODNI would then provide a report on the viability of a wider briefing program for state and local governments.

The bill requires the ODNI to produce a strategy on information sharing with states and local areas, and would require the Government Accountability Office to conduct an assessment of the state of such sharing now, including a summary of relevant agencies’ current efforts, how the agencies deconflict those efforts and what kind of obstacles security clearances pose to improving information sharing.

Trump’s pick to serve as DNI, Jay Clayton, emphasized his desire to focus on cyber threat information sharing as part of his Senate vetting last week, but some in the GOP are also pushing to significantly reduce the size of his office.

National Cyber Director Sean Cairncross has also talked about creating pilot programs for cyber threat information sharing with state and local governments, but there’s been little movement on that initiative.

During committee deliberation, panel Democrats won adoption of a trio of election security amendments.

An amendment from the panel’s top Democrat, Rep. Jim Himes of Connecticut, would require the intelligence community to publish an unclassified assessment of foreign intelligence threats to the 2026 midterms. Rep. Jason Crow of Colorado’s amendment would partially withhold funding for the ODNI until Congress gets overdue reports it had required on the 2024 and 2026 elections. And  Rep. Chrissy Houlahan of Pennsylvania’s amendment would “protect analysts from retribution by IC leadership for working on intelligence products related to foreign influence in US elections,” according to a news release.

The Democrats’ push arrives shortly after President Donald Trump delivered a primetime address seeking to bolster his long-debunked claims that the 2020 election was stolen from him.

According to a Republican summary of the bill, it includes provisions for “significantly increasing funding for expanded access and use of frontier AI models for intelligence and cyber missions,” to codify and expand the role of the Artificial Intelligence Security Center at the National Security Agency and strengthen information sharing on AI threats.

“This year’s [bill] balances strong transparency and accountability measures while equipping the IC with the resources needed to combat the ever-evolving threats from our adversaries around the world, with a particularly strong focus on the global AI race,” said House Intelligence Chairman Rick Crawford, R-Ark.

Another assessment that the bill orders would come from the Office of Intelligence and Counterintelligence of the Department of Energy on foreign cyberthreats to critical energy infrastructure, including their intent and risks.

The trend in Congress is for lawmakers to incorporate the annual intelligence authorization bill, or some of its provisions, into the annual National Defense Authorization Act, which often reaches the president’s desk at the end of each calendar year.

The post House intel bill includes provisions on state and local threat intelligence, election security, AI appeared first on CyberScoop.

State officials, election experts pan Trump speech: ‘This is what desperation looks like’

By: djohnson
17 July 2026 at 11:37

State and local officials and election security experts largely panned a Thursday night primetime speech by President Donald Trump, saying it was reflective of White House “desperation” to find any credible evidence to support their claims that U.S. elections have been rigged against the two-term president.

While the White House teased explosive new claims about the potential compromise of U.S. elections by China, Trump’s speech was a rehash of claims that both have no supporting evidence and have been repeatedly debunked when investigated. 

David Becker, executive director of the Center for Election Innovation and Research and a former voting and civil rights attorney at the Department of Justice, said none of Trump’s claims or allegations were new or substantively different from previous theories he’s been espousing over the past six years.

“The White House promised a bombshell and they delivered a dud,” Becker said on a call with reporters Friday. “There was nothing that even calls into question past elections — certainly not the 2020 election.”

The administration declassified a huge tranche of documents from the intelligence agencies, and news outlets continue to sift through them, but thus far nothing has been found that remotely validates the administration’s claims about foreign interference from China costing Trump the 2020 election.

In fact, some of the most relevant documents found at this point have supported the opposite conclusion, with agencies assessing that while China engaged in influence campaigns around the election, it was not attempting to outright interfere with U.S. election infrastructure, hack voting machines or manipulate ballots.

John Solomon, a former journalist and opinion writer at The Hill brought in by the White House to lead the investigation, also told reporters Thursday that his search hasn’t turned up evidence that the 2020, 2022 or 2024 elections were affected by fraud.

The one new major claim by Trump — that the Department of Homeland Security determined hundreds of thousands of noncitizens were registered to vote across four states — is almost certainly false or overinflated, given that it contradicts post-election state audits that have routinely found single or double-digit numbers of noncitizens registered to vote within a single state across multiple elections.

Over the past six years, similar claims by GOP secretaries of state and political activists purporting to find mass numbers of noncitizens registered to vote have turned out to be grossly inflated due to shoddy data analysis, and the vast majority of cases involving “suspected noncitizens” turn out to be U.S. citizens who are legally registered to vote.

The White House has provided little to no information on the methodology used to flag and identify supposed noncitizen voters, other than alluding to the use of “commercial data” and federal databases. A federal court recently ordered DHS to dismantle the SAVE database, its primary database for verifying the citizenship status of U.S. voters, because it was unreliable and violated longstanding privacy laws. 

 Apart from DHS admitting its own data on citizenship is incomplete, Becker said using a list that relies on matching voter files with commercial data is not a reliable way of determining citizenship.

“It is impossible to take a public voter file with very little information that is uniquely identified, like a driver’s license number, and compare it to a commercial database and say for sure the Maria Rodriguez or the John Lee or the Shawn O’Hara you have on that is the same person,” he said.

Election officials also responded forcefully. Nevada Democratic Secretary of State Francisco Aguilar said that Trump has spent a decade attempting to manufacture a crisis around voter fraud and the president’s speech Thursday night was an extension of that effort. 

“As Nevada’s chief elections officer, it’s my job to call balls and strikes — so when the President lies, I am obligated to call him out,” Aguilar said in a statement. “The facts have not changed: Nevada’s elections are among the safest, most secure and accessible in the nation.”

It’s not just Democrats that have objected to the administration’s efforts. GOP states have gone to court to block the Department of Justice from obtaining their voter data, and Idaho’s Republican secretary of state responded to a DOJ letter threatening prosecution of election officials as “not well met” and potentially illegal under state ethics laws. 

Trump’s speech potentially casts additional light on recent White House decisions, such as firing all three commissioners on the Election Assistance Commission. The agency helps certify voting machines for security, and all three commissioners have served across administrations and maintain close relationships with state and local election officials.  

Pamela Smith, CEO of the nonprofit Verified Voting, said that while the EAC can’t take certain actions that need commissioner approval, “critical functions like voting system testing and certification can continue under the existing framework and should not be affected.”

In 2020, Trump’s initial claims of widespread election fraud were undercut by leaders at the Cybersecurity and Infrastructure Security Agency, which said there was no evidence the election was compromised. The removal of EAC commissioners could represent an attempt to preempt any efforts to rebut or criticize White House claims that elections and voting machines have been compromised.

Some have worried that Trump could use the speech as a pretext to declare a national emergency or cancel elections.

Tom Lopach, CEO of the Voter Participation Center, said “you don’t dismantle election security infrastructure if you’re serious about protecting elections.”

“You dismantle it if you’re planning to claim, without evidence, that the system failed you,” he said. 

While Becker takes Trump’s broadsides against state election authority seriously, he also said it’s important not to lose sight of the fact that, in his view, the administration is losing the argument across the board.

More than a dozen federal courts have unanimously rejected the federal government’s attempts to forcibly obtain state voter data, while other courts have rejected core pieces of his election-related executive orders. State officials have publicly — and at times, angrily — pushed back on the administration’s demands as blatant federal overreach. 

Becker predicted that such an act would be quickly shot down by courts as well, noting that the U.S. has never canceled or postponed an election in its 250-year history, including when British troops were marauding on American soil during the War of 1812 or even at the height of the Civil War.

It’s important not to conflate the White House’s bluster and intentions with its actual authorities or capability to seize control of U.S. elections.

“This is what panic and desperation look like,” Becker said. “They’ve had 18 months in total control of the federal government and they have found nothing that would support President Trump’s lies about the 2020 election, and so they’re just trying to grab as much garbage as they can and throw it up against the wall, and it’s not sticking.”

The post State officials, election experts pan Trump speech: ‘This is what desperation looks like’ appeared first on CyberScoop.

Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed

15 July 2026 at 14:29

Democratic senators pressed President Donald Trump’s pick for director of national intelligence on questions of election security and integrity Wednesday, but they didn’t leave his nomination hearing satisfied with the answers.

As is typical for Trump administration nominees, Jay Clayton wouldn’t answer definitively at his Senate Intelligence Committee confirmation hearing whether Joe Biden won the 2020 presidential election, saying only that he was “certified,” while maintaining that he wasn’t an “election denier.”

He said that the Office of the Director of National Intelligence’s responsibilities were “principally” outside the United States. But he claimed varying degrees of ignorance about his predecessor, Tulsi Gabbard, being physically present at an FBI raid of a Georgia election office in January, and wouldn’t comment on its appropriateness.

Democratic senators were also frustrated while trying to pin down Clayton, the U.S. attorney for the Southern District of New York who served as head of the Securities and Exchange Commission in Trump’s first term, on remarks about mail-in ballots and the California primary election results last month.

Multiple senators, including Mark Warner, D-Va., Angus King, I-Maine and Mark Kelly, D-Ariz., tried to get Clayton to say whether Biden won the 2020 election. The final exchange came with Jon Ossoff, D-Ga.

Clayton protested that he had already answered. “I think I’ve answered the question,” he said. “We can keep doing this.”

Ossoff didn’t agree, telling him, “Well we’re going to keep doing it because you’re not being honest or forthright with the committee.”

“Isn’t it humiliating to be unable to answer this question?” he asked. “To have to indulge the president’s delusions? We know, you know, everybody in this room knows the truthful answer to that question. Why can you not give it?”

Earlier Clayton had said, “I’m not an election denier,” but repeatedly wouldn’t answer “yes” or “no” on whether Biden won in 2020.

That matters because of the DNI’s role, Kelly said, and it was worrying that Clayton was seeking to avoid upsetting Trump, who has maintained despite all evidence that he lost the 2020 election.

“It’s not about softening the edges when the truth is unpleasant,” Kelly said. “It’s about delivering information.”

Clayton discussed the DNI’s role on election security at greater length in pre-hearing written answers.

“I understand that the DNI, as head of the Intelligence Community, has substantial statutory authority to address national intelligence threats to U.S. elections,” he said. “In particular, the Director is responsible for the integration of national intelligence, which may include foreign intelligence threats to U.S. election activity. I also understand that Intelligence Community elements are authorized to cooperate with and provide appropriate intelligence and technical support to law enforcement agencies and that as head of the Intelligence Community, the DNI has oversight of those activities.”

A CNBC interview last month inspired some of the Democrats’ questions. Clayton said in response to questions about the California primaries that “On the integrity side, we’re doing an absolutely terrible job. And the American people are right to question it.” 

He said mail-in ballots present an “opportunity for fraud,” despite studies showing exceptionally low rates of fraud using that method, and said “mail-in ballots being used by one group and not another… honestly and dishonestly” was a “question that everyone is now asking.”

Sen. Ron Wyden, D-Ore., asked him about what group Clayton was referring to.

“”I would like to see where you’re pulling those quotes from. I’ve been very careful about my remarks on this,” Clayton answered. “I’d like to see the whole passage.”

In his questionnaire, when asked if “it would be inappropriate for a DNI to comment publicly about unsubstantiated claims regarding mail-in-ballots and election fraud,” Clayton answered that “If confirmed as DNI, any representations I make to the public, including about elections, will be informed by timely, objective national intelligence.”

Ossoff also had a tense exchange with Clayton when asking him about Gabbard’s appearance at the Fulton County office raid. Gabbard has said she was there because Trump asked her to be, in what subsequently became a highly publicized appearance because of questions about what the DNI would be doing at a law enforcement raid.

“I was made aware of it by you yesterday,” Clayton said.

Ossoff responded skeptically: “The first time you learned that Director Gabbard was present at that raid was in my office yesterday?”

Said Clayton: “It was the first time that in my recollection I’ve thought about it recently.”

“What?” Ossoff replied.

Warner, the top Democrat on the committee, told Clayton “I trust you” but it “strains credulity” that he wasn’t aware of Gabbard being at the raid.

“To be clear, the ODNI’s role is principally outside of the United States,” Clayton said.

On other topics, in his opening remarks, Clayton touted his SEC work on cybersecurity. In his questionnaire he said he would work to facilitate cyberthreat information sharing from his office.

He told Sen. Kirsten Gillibrand, D-N.Y., that he would evaluate whether the DNI should devote more resources to cybersecurity with federal government cyber experts being pushed out since Trump came back to office. Many Republicans are pushing to further reduce the size of Clayton’s office, contending it has become bloated beyond Congress’ original intentions as a coordinating body.

He said he supported renewal of Section 702 of the Foreign Intelligence Surveillance Act, which gives the executive branch controversial spying powers that Congress recently allowed to expire.

Trump has threatened to block renewal unless lawmakers advance his priority election bill. He said he will study how to “minimize the detrimental impact to our national security caused by the lapse in 702 authorities.” Some Democrats, meanwhile, have resisted action on the law until Trump’s pick for acting DNI Bill Pulte is gone, citing his prior efforts to investigate officials as head of the Federal Housing Finance Agency and lack of intelligence experience.

Because the GOP controls the Senate, Clayton is likely to get confirmed as DNI as long as no Republicans emerge in opposition. Wednesday’s hearing revealed no significant Republican objections.

Intelligence Chairman Tom Cotton, R-Ark., touted Clayton’s experience prosecuting terrorism cases and more.

“Jay Clayton has worked hand in glove with our intelligence agencies and counterterrorism personnel to lock up criminals who threaten our national security,” Clayton said. “I encourage my colleagues to join me and get Mr. Clayton’s nomination over the finish line.”

The post Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed appeared first on CyberScoop.

Hardening your systems

13 July 2026 at 03:42
ON SECURITY By Susan Bradley If you are a Windows 11 owner, it’s wise to review your security practices on a regular basis. Recently, I’ve come across a new tool that you may want to check out. The advantage? It uses only official Microsoft built-in techniques that are documented and approved. In addition, it comes […]

States are building their own election defense networks as federal support evaporates 

By: djohnson
13 July 2026 at 16:59

The Trump administration’s abrupt firing of Election Assistance Commission commissioners last week and a Department of Justice warning threatening states with criminal prosecution have created new legal peril for officials who run, administer and secure elections.

The EAC is an obscure but important agency that oversees testing and standards for voting machines, including around security. While federal certification is voluntary, states have until now relied upon their stamp of approval when purchasing voting machines. 

On July 10, Democratic Commissioners Ben Hovland and Thomas Hicks were fired by the White House, while reports indicate that a third Commissioner, Republican Christy McCormick, resigned. While Congress mandated the commission be bipartisan, the Supreme Court has recently given the President broad authority to fire executive branch officials at will.

In an interview with NPR, Hovland said he worried the firings would further erode trust that the commission was working in a bipartisan manner.

“And as you eliminate things – or if you get rid of commissioners, for example – or as you eliminate some of these other sort of safeguards or norms, it certainly strains the system,” said Hovland. “And it certainly also likely causes people to lose faith in our democracy and in the process and their confidence in our elections. And that’s very concerning.”

A letter also sent last week to all 50 states by the DOJ said the department will investigate and prosecute any election official “who knowingly retains non-citizens on the state’s voter registration list or facilitates noncitizens in receiving and casting ballots.”

CyberScoop spoke with several Secretaries of State who said that the number one threat facing elections in their state is not from a foreign country or AI but their own federal government. 

Tobias Read, the Democratic Secretary of State for Oregon, told CyberScoop that his office is focused on providing the state’s 36 county clerks with the resources and support they need to carry out a smooth election. But he acknowledged that his office is “playing defense in a lot of ways [from] the intrusion from the federal government” that continues to assert its authority over local elections.

“If the president were actually serious about election security, he would be sending more resources to local election officials and bolstering the system rather than cutting it,” said Read.

This year, several counties in Oregon will offer voters access to a new ballot tracking system that provides text or email updates when a voter’s ballot is moving through mail and has been certified.  Reed estimated at “pennies per voter per election” and called it a good option for cash-strapped counties to assure voters their ballots are secure and properly tracked.

At the same time, Read said federal agencies like the Cybersecurity and Infrastructure Security Agency – which once regularly deployed cybersecurity and technical expertise to help states fix vulnerabilities and share threat intelligence – have largely gone quiet.

Oregon ranks in the top ten states for voter participation and relies heavily on mail-in voting.  However, state officials like Read lack confidence in the US Postal Service. Though a recent Supreme Court decision blocked an executive order giving the service control over mail-in ballot distribution, officials like Read are urging voters to take other measures to use drop boxes instead as a  safer alternative to ensure their vote is counted.

Adrian Fontes, Arizona’s Secretary of State and a Democrat running for reelection, said his office is focused on primary elections and processing the mail ballots that have been arriving “for a while.”

After Iranian hackers defaced Arizona’s candidate bio portal last year, Fontes moved to fill a widening gap: the Trump administration’s withdrawal of federal foreign interference training and support. His office is now directly supporting local jurisdictions on election security while coordinating more closely with state law enforcement, intelligence agencies, and other states.

But it’s being done with a fraction of the resources and coordination that the federal government brought to bear under both the Biden and first Trump administrations. While Fontes said he maintains positive personal relationships within the Department of Homeland Security, his office does not have a formal relationship with CISA.

“We’ve hobbled together a loose and often informal network of information sharing – that doesn’t violate any rules, it doesn’t break any laws – but it is certainly not anywhere near as robust as it would be if we had a responsible federal agency that was interested in the security of American elections,” said Fontes.

He said even if CISA offered such services today, he wouldn’t accept it, citing the lack of trust between states and the Trump administration.

“They have proven through their actions that they don’t want to be effective partners in protecting the American electorate and protecting American voters,” said Fontes. “Because of that, the clear answer, the only sensible answer for someone like me, would be to say ‘No, I don’t want the help of people I cannot trust.’ People who have demonstrably and explicitly threatened me and local election administrators of all political stripes with criminal prosecution.”

After this story’s initial publication, CISA acting director Nick Andersen said the agency remains committed working with “with critical infrastructure owners and operators to assist them in securing both the physical security and cybersecurity of the systems and assets that support the nation’s election process.”

“We provide state and local election officials, upon request, no-cost voluntary services such as the sharing of threat information, technical expertise, vulnerability scanning, and resilience-building support,” said Andersen in a statement sent to CyberScoop. “Our regional teams assist partners across the country by assessing risks, helping entities bolster defenses and improve resilience, and responding promptly to threats. We are committed to supporting state and local elections officials to protect election infrastructure and safeguard our democracy.”

Secretaries of State in Colorado, Nevada, Minnesota, Rhode Island, and others have also called the DOJ letters an attempt at federal intimidation of election officials. 

Others, like West Virginia Republican Secretary of State Kris Warner, have reiterated their refusal to hand over state voter data. On Monday, a federal judge upheld his right to do so. 

Warner wrote to the DOJ in response to say the state was “available to discuss our existing voter registration list maintenance” but “West Virginia law prohibits the disclosure of sensitive personally identifiable information contained in voter registration records.”

It’s leading some states to take new precautions. 

Read said he was working with Oregon county officials to make sure “county clerks have the number of their county counsel on speed dial” and know how to distinguish between a legitimate and illegitimate federal warrant or subpoena.

Additionally, FBI raids of election offices around the country to seize ballots records related to the 2020 and 2024 elections have been a cause for Read’s concern. By state law, Oregon and other states must keep copies of the ballot records and other election data they receive from counties for a certain time according to state law, after which they must eventually archive or destroy them according to ballot retention schedules.

Read emphasized that “it’s important to destroy those ballots at the appropriate time,”  The Trump administration has used the raids to further the impression of electoral fraud, despite the absence of credible evidence. 

“We can see when people are not on top of that, then you expose yourself to other vulnerabilities like the federal government seizing those ballots in Maricopa County [Arizona] and Fulton County [Georgia] as well,” said Read.

A former CISA official estimated that on Election Day in 2024, more than 1,000 representatives from federal, state and local governments, election technology vendors and other election stakeholders sat together in a room to communicate and coordinate.

Less than two years later, Read called his office’s interactions with CISA “minimal.” He recalled that upon taking office as Secretary of State in Jan 2025, one of his first conversations was with one of CISA’s regional advisors. A week later, those advisors were summarily fired by the Trump administration.

UPDATE: 7/14/2026, 11:15 a.m.: Updated with comments from CISA acting director Nick Andersen.

The post States are building their own election defense networks as federal support evaporates  appeared first on CyberScoop.

AI-generated code has made security debt a governance problem

By: Greg Otto
13 July 2026 at 05:00

AI-generated code is part of everyday software development. Developers use it to prototype, refactor, troubleshoot, and move from idea to implementation with less friction than ever before. The productivity gains are undeniable, which means that security leaders now face a hard question: whether their organizations can govern the risk that AI creates at that same speed.

That challenge is rooted in scale. AI changes how quickly software can be created, while many application security programs still depend on controls designed for a slower development model. When code generation accelerates beyond the capacity to review, test, and remediate issues, security debt accumulates faster.

That is the hidden cost of AI-assisted development. Risk now enters the enterprise at machine speed, while many organizations still manage it with human-scale processes. CISOs should govern AI-generated code as a high-risk input: tested automatically, checked for unsafe dependencies, remediated quickly, and blocked from production if it fails policy.

The metric that matters is risk velocity

Application security has long been measured through discovery. Teams count vulnerabilities, categorize severity, report trends, and show whether the numbers are improving. Those questions still matter, but AI adds a more urgent metric: risk velocity. Security leaders need to know how quickly the organization creates new software risks and how quickly it can reduce or eliminate them.

AI changes the economics of security debt. A development team that produces significantly more code without a matching increase in security capacity will create more issues than it can reasonably review or fix. Even when AI-generated code is comparable to human-written code on a per-line basis, the total risk can rise because the volume of change is higher. The backlog grows, vulnerabilities persist, and security debt eventually constrains the business.

AI expands familiar failure modes

The failure modes are familiar. AI coding tools can reproduce insecure patterns found in training data, including weak input validation, unsafe authentication flows, insecure direct object references, hard-coded secrets, and vulnerable dependency choices. They can also miss the context that determines whether code is secure in a specific environment: authorization models, tenant boundaries, data sensitivity, production configurations, and how services interact in a real application.

There is also a human factor. Under the pressure of deadlines, developers may accept code that works without fully understanding how it does so. The result is misplaced confidence. Code compiles, tests pass, features ship, and hidden risk enters the system. Over time, the organization may lose sight of the security concerns that naturally arose during manual development.

The supply-chain risk is bigger than the code itself

The software supply chain adds another layer of risk. Modern applications are assembled from open-source components, frameworks, plugins, containers, APIs, and cloud services. AI coding tools can recommend outdated packages, vulnerable libraries, or nonexistent dependencies. Veracode’s 2025 GenAI Code Security report found that AI coding tools produce insecure code nearly half (45%) of the time. It may sound like an amusing hallucination until attackers register malicious packages with similar names and wait for developers or automated tools to pull them in. At that point, a coding shortcut becomes a supply chain exposure.

AI is already part of the development lifecycle, and its use will continue to expand. Security teams need a control model built for that reality.

“Shift Left” needs an enforcement layer

The industry has spent more than a decade moving security earlier in the development lifecycle, improving visibility and helping teams catch issues sooner. Many organizations, however, moved findings closer to developers without also moving enough ownership, automation, and remediation capacity with them. Developers received more alerts, while security teams gained more visibility into risks they still struggled to reduce.

AI makes that operating gap more urgent. As software output increases, security cannot remain a checkpoint near the end of the process. It must become a continuous control system built into the way software is created, tested, approved, and deployed.

Secure-by-design has to become infrastructure

Secure-by-design in the AI era requires an engineering environment where unsafe choices are harder to make and easier to catch. Approved frameworks, secure defaults, reference architectures, dependency controls, automated testing, and policy enforcement should be embedded directly into developer workflows and CI/CD pipelines.

Remediation also must move closer to the point of creation. When a coding assistant introduces a vulnerable pattern, the ideal response is an inline fix that is proposed, validated, and governed as part of the normal development process. AI can help defenders here when it is connected to reliable security signals, policy context, and evidence from real testing. Counterintuitively, developers using AI to write code often don’t trust AI to automatically remediate code without human review. This takes one of the best ways to keep up with machine-speed created vulnerabilities and slows it down to human speed. An acceptable balance between risk and speed must be found.

Approval is not governance

CISOs should focus on governance, not just approving AI coding tools. Governance means tracking where AI-generated code enters your environment, documenting the policies and tests applied, recording what issues were found and fixed, and keeping proof of these decisions. This documentation becomes critical as AI-assisted development becomes standard. If vulnerable code reaches production, you’ll need to show that adequate controls were in place and risks were managed according to policy.

What leaders should do now

CISOs and engineering leaders should treat AI-generated code as untrusted until proven otherwise. They must require automated testing before release, enforce dependency controls, prioritize remediation based on exploitability and business impact, and measure success by the rate at which critical risk is reduced.

Additionally, boards and organizational policymakers should ask whether organizations can demonstrate that AI-assisted software is governed before it is deployed. The key evidence should include the policies applied, the tests performed, the vulnerabilities remediated, the risks accepted, and the approvals recorded. Today, many organizations can confidently track what their AI tools produce, but they cannot demonstrate how that output was secured, reviewed, and governed before reaching production. The industry is still working to close this gap.

AI is changing how quickly software risk moves through the enterprise. The organizations that succeed will make security move just as quickly by embedding governance, remediation, and proof directly into the software delivery pipeline.

The post AI-generated code has made security debt a governance problem appeared first on CyberScoop.

What’s a GDID?

8 July 2026 at 04:00
You probably saw in the news the story about the young man brought up on charges. I’ve seen more than a few folks on social media concerned about the privacy implications of a GDID. (More about that identifier here). I personally have a hard time putting up my gee whiz privacy outrage for a guy […]

What to do with older tech

29 June 2026 at 03:42
ON SECURITY By Susan Bradley When I started writing this column, I planned to open with the forthcoming end of the Windows 10 ESU. Oops. On June 24, Microsoft changed its mind. It decided to extend the Windows 10 Extended Security Updates (ESU) program for another year, until October 12, 2027. You can find the […]

Supreme Court approves mail-in ballots that arrive after Election Day 

By: djohnson
29 June 2026 at 13:31

In a 5-4 decision, the Supreme Court upheld the right of states to accept mail-in ballots that are postmarked by Election Day, but can arrive up to five days later through the mail system.

The case stems from a lawsuit brought by the Republican National Committee against Mississippi and its Secretary of State, arguing they could not legally count mail ballots that arrive after Election Day, even if they are postmarked on or before that same day. The RNC argued that federal law defines “elections” and “Election Day” as the casting and receiving of ballots by that day.

Writing for the majority, Justice Amy Coney Barrett rejected that argument, stating that “nothing in the federal Election-Day statutes require ballots to be received by election day.”

“The federal Election-Day statutes do not preempt Mississippi’s law because the defining element of an ‘election’ has always been the electorate’s choice of candidate,” wrote Barrett.

Barrett, joined by Justices John Roberts, Elena Kagan, Sonia Sotomayor and Ketanji Jackson Brown, noted that other federal voting statutes like the Uniformed and Overseas Citizens Absentee Voting Act explicitly say that state law governs when ballots must be received, not the federal government. 

Further, while Congress inserted the phrase “Election Day” and specifies it as a Tuesday in its most recent update, it also allows states to modify that period of voting in response to certain force majeure events, like the COVID-19 pandemic.

While the Constitution requires voting to take place by a certain time, the review of those legally cast votes does not need to conclude at the same time.

“The Constitution requires the ‘Day on which [the electors] shall give their Votes’ to be ‘the same throughout the United States,’ but says nothing about the day for receipt,” wrote Barrett. “The Constitution thus envisions a system in which receipt of votes is necessarily divorced from voting. And it sets the crucial, uniform day as the day of voting while leaving receipt to happen later. The federal Election-Day statutes follow the same pattern.”

David Becker, executive director of the Center for Election Innovation and Research, said the ruling upholds the principle that “the election is completed for the voter at the moment they complete their ballot, not the moment that some administrative election official receives that ballot or reviews that ballot.”

It also validates more than a hundred years of state autonomy in setting their own rules regarding the receipt of election ballots.

“This case was about who gets to make that determination,” said Becker. “And as the founders intended, as is clearly laid out in the elections clause of the Constitution, the states get to make that determination about when those ballots should be delivered by the postal service and be counted.”

Still, Becker bemoaned the slow, steady politicization of the issue, and said in conversations many election officials were anxious about the case and relieved to see a victory, albeit a narrow one.

“I’ll be honest with you, in any other era this case should have been a 9-0 [decision],” said Becker. “This is a slam dunk, the states clearly have the authority to do this, they’ve been doing this for decades and decades.”

The ruling likely forecloses major changes to the way states receive or accept mail-in ballots before the midterm elections, but Becker does expect some states to seek legislative changes to align their state laws with the five-day post-election timeline blessed by the court.

14 states and Washington D.C. have state laws that allow any ballot to be received up to five days after Election Day or longer, while more than 30 allow military and overseas ballots to arrive after Election Day. Election experts have said ruling that such ballots were invalid could have upended decades of voting precedent and procedures for American voters at home and abroad.

Michael McNulty, director of Issue One Policy, a nonprofit focused on money in politics and elections, said had the court ruled the other way, it would have created chaos for election administration in more than a dozen states that accept such ballots, forcing them to move ballot receipt deadlines, redesign procedures and conduct large scale voter education campaigns without any additional funding.

The Supreme Court “rightly rejected an attempt to reinterpret federal law to force sweeping last-minute changes to election systems across the country and discard legally cast ballots.”

Pamela Smith, CEO of Verified Voting, a nonprofit focused on promoting secure election technologies, said the ruling should give relief to voters who rely on mail or absentee voting.

“This ruling ensures that a postal delay outside of any voter’s control does not erase a lawfully cast ballot and supports election officials’ ability to capture the will of voters,” said Smith.

Post-election audits and investigations have consistently shown voter fraud in the U.S. is exceedingly rare, and that mail-in ballots are not any more susceptible to fraud than other forms of voting.

Nevertheless, states accepting mail-in ballots past Election Day has been a politically charged subject since the 2020 election, when then-incumbent President Donald Trump was defeated by Joe Biden in part on the strength of late-arriving mail ballots that heavily swung in Biden’s favor.

In the years since, both Trump and the GOP more broadly have cast late arriving mail ballots as inherently suspicious, untrustworthy and opaque.

Those beliefs have persisted.

In their dissent, Justices Samuel Alito, Neil Gorsuch, Clarence Thomas and Brett Kavanaugh wrote that the decision “leaves open opportunities for voter fraud that may further undermine Americans’ faith in the integrity of this country’s elections.”

“Mail voting also presents a greater opportunity for voter manipulation, a more vulnerable chain of ballot custody, and a diminished ability to detect improprieties in real time,” Alito wrote on behalf of the minority. “Today’s decision compounds these vulnerabilities. Allowing absentee ballots to pour in over the days and weeks after election day, by which point preliminary election returns are being publicly reported, creates greater opportunity for fraud and risks further undermining the public’s confidence in election integrity.”

The post Supreme Court approves mail-in ballots that arrive after Election Day  appeared first on CyberScoop.

❌
❌