❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdaySecurity/Privacy

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

16 September 2026 at 10:48

The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint statement from the agencies Wednesday.

The “joint offshore security boardings” of the two commercial ships in the Gulf of Mexico on Aug. 21 and Aug. 24 “were designed to ensure integrity of the vessel’s operational and information technology systems following indications that the networks of both vessels were compromised,” according to the joint statement.

“Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts,” the statement reads. “The Coast Guard is actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption.”

The vessels were reportedly tankers carrying oil and natural gas, and the first got hacked in the Strait of Gibraltar and lost communication for over 30 hours. Authorities were said to be  investigating whether Iran, or perhaps another group seeking to exploit the conflict between Iran and the United States, was behind the attacks.

Coast Guard cyber teams have been investigating “dark fleets” carrying sanctioned oil from Iran and Russia, which rely on digital masking to hide their operations and carry enhanced cyber risks, The Wall Street Journal reported in June.

Then-President Joe Biden signed an executive order in 2024 giving the Coast Guard additional authorities to respond to cybersecurity incidents, citing the risks that a maritime cyber incident could cause “cascading” harm to the global supply chain.

The Aug. 21 boarding party included Coast Guard law enforcement personnel, Coast Guard Cyber Protection Team members, a vessel inspector and FBI Cyber Action Team operators, who boarded “to conduct a comprehensive cyber security boarding and investigation,” according to the agencies’ joint statement. A similar team made up the Aug. 24 boarding party.

“The captain, crew, and shore-side corporate staff were critical partners in helping to ensure the threats were mitigated,” the statement reads.

Top Trump administration cyber officials have refused to answer questions from reporters recently about Iranian cyberattacks during the Middle East conflict. Trump himself has rejected the idea that Iran was behind a recent spate of attacks on U.S. water facilities.

The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

26 August 2026 at 17:38

Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.

The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.

“To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.

The executive order is a response to fears of Chinese-made equipment housed within U.S. energy infrastructure, and a continuation of other measures from the Trump administration to shun that equipment.

The order, “Declaring a National Energy Emergency to Secure the United States Bulk-Power System,” cites “malicious cyber activities” as one impetus.

“The minimal restrictions on acquisition or operation in the United States of foreign-produced bulk-power system electric equipment augment the ability of some foreign entities to create and exploit vulnerabilities in such equipment; for instance, such equipment might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely,” it states.

China supplies 85% of solar supply chain production capacity, according to the International Atomic Energy Agency, and China is a major player in the power transformer manufacturing business.

In 2024, then-FBI Director Christopehr Wray told Congress that hackers prepositioning themselves in small office and home routers had the electricity grid as one of their targets should China and the United States go to war.

Near the end of Trump’s first term he also signed an executive order seeking to limit the purchase of foreign-made bulk-power equipment. The Biden administration suspended that order, citing the need to review its scope, and revoked and replaced a related Energy Department order. Some utilities found compliance with the 2020 executive order difficult.

For the new order, the Energy Department has 120 days to develop rules to implement the order, in consultation with other key departments.

The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.

Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’

24 August 2026 at 15:06

As part of its “economic D-Day” against Iran, the Treasury Department designated four Iranians for sanctions Monday stemming from their alleged role in hacking critical infrastructure targets and waging cybertheft against the United States.

It’s the second time in as many weeks that the Trump administration has taken aim at the same group of alleged hackers, following on an indictment recently unsealed against cybercriminals that federal law enforcement authorities say are affiliated with the Tehran-based Mabna Institute.

A Treasury Department release points the finger at three people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi — as specifically conducting the hacks.

“Since at least late 2023, these three individuals have successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions,” the release states.

A fourth individual included in Monday’s sanctions, Mojtaba Ghal’eh-Kuhi, is listed as one of the leaders of the gang carrying out the Ministry of Intelligence and Security (MOIS)-directed attacks. Another listed leader, Behzad Mesri, first faced sanctions in 2018, as part of another round of sanctions focused on the Mabna Institute.

Finally, the Treasury Department designated one additional person Monday over related activity, Arman Kahzadian, for his alleged role in receiving or using business information stolen via cyber-enabled means.

The department said the Iranian hackers sometimes turn their gaze to domestic targets.

“The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS,” it said. “This has driven some of the group to target Iranian companies.“

Hackers that the U.S. government has identified as Iranian have been behind a spate of attacks on U.S. water facilities, despite denials from President Donald Trump himself about Iranian culpability.  The Treasury Department did not immediately respond to a request for comment Monday about whether the sanctions designees were involved in those attacks, nor has the National Security Agency responded to requests for comment on whether Iran was responsible for attacks at the center of an alert about attacks on water facilities.

Treasury Secretary Scott Bessent announced a fuller list of sanctions Monday as the war with Iran nears its five-month anniversary with no end in apparent sight.

“In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries,” he said. “Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”

There are questions about whether the sanctions themselves are likely to change any behavior, particularly based on how they will be enforced. Iran has vowed “consequences” for the United States.

As part of the sanctions announced Monday, according to the department, “Treasury is expanding the categories of Iran-related conduct that may be subject to secondary sanctions in the future, making it easier to take action against those facilitating the regime. Treasury has issued determinations against five critical sectors –– digital assets, technology, gold, aviation, and shipping––  that the Iranian regime uses to try to prop up its failing economy.”

The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.

Bipartisan Senate bill aims to prepare energy sector for Q-Day

By: djohnson
24 August 2026 at 15:01

A new bipartisan Senate bill would require federal regulators to prepare the U.S. electric grid for cybersecurity threats from quantum computers and create a technical sandbox to study how the technology could impact  both information and operational technology systems.

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Sens. Mike Rounds, R-S.D., and Chris Coons, D-Del., would direct the Federal Regulatory Energy Commission when reviewing proposed reliability regulatory standards for electricity owners and operators under the Federal Power Act.

FERC updates its reliability standards to account for emerging cybersecurity concerns, and the legislation would expand those reviews to include the future threat of hacks from quantum computers.

The legislation also directs FERC to explore potential uses of post-quantum cryptography in IT and OT systems and “take such action the Commission determines to be appropriate based on that consideration.”

In a statement, Coons said quantum computing brings “new economic opportunities” along with “tremendous cybersecurity risks.”

“As the technology races forward and our adversaries continue to seek vulnerabilities in our critical systems, we need to pass the Quantum-GUARD Act to ensure our government is using every available tool to meet this threat,” said Coons.

The federal government has been an early adopter of post-quantum cryptography for its digital systems. The National Institute for Standards and Technology has worked with cryptographers to develop new “post-quantum” encryption algorithms that will be used by most governments and the private sector.

Under the Biden administration, most federal agencies were required to migrate their systems and data to “PQC” encryption by 2035. In June, an executive order from the Trump administration pushed that timeline up to 2030. 

Ali Shaikh, CEO of Graphiant, a networking infrastructure startup, told CyberScoop that the bill would represent a good start in terms of pushing greater adoption of quantum-resistant encryption, “the real work is upgrading infrastructure, not applications, ahead of the deadlines.”

Evgeny Gervis, CEO of SafeLogic, compared the energy sector’s challenges to previous efforts by FERC and industry to gain adoption at scale for other technological upgrades, like smart grid equipment. Among those challenges is prioritizing security upgrades in a sector where reliability is paramount.

“The highest priority for electric utilities will be preservation of integrity and availability, both services that are widely supported by legacy public key cryptographic controls that are quantum vulnerable,” said Gervis. “It is essential that quantum computers do not undermine the integrity and authenticity of SCADA communications or the software update process.“

The post Bipartisan Senate bill aims to prepare energy sector for Q-Day appeared first on CyberScoop.

AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn

19 August 2026 at 14:45

Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday.

It’s the latest government warning about attacks on critical infrastructure as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems— but doesn’t mention in Wednesday’s alert. 

The National Security Agency didn’t immediately respond to a request for comment about who was behind the attacks on the PLCs, which are used to control manufacturing processes.

The agencies said the attacks were an “active threat,” rather than a theoretical one. The attacks could disrupt critical industrial processes, cause safety incidents or lead to the compromise of sensitive data.

Wednesday’s alert from the NSA, Cybersecurity and Infrastructure Security Agency, FBI, Energy Department and Environmental Protection Agency makes special note of the hackers using AI-generated exploitation scripts in the attacks.

“Using AI to generate exploitation scripts represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools,” the alert states. “In addition, AI enables adversaries to rapidly leverage additional attack vectors and adapt to defensive measures. Threat actors can easily collect public information about vulnerabilities and weaknesses, find exposed and exploitable PLCs, and use AI-generated scripts to act on that information.”

A former top CISA official, Michael Garcia, thought that it was a first for the agency in one of its cybersecurity advisories (CSAs) about operational technology (OT).

“It is the first alert I have seen where CISA is saying in a CSA that a malicious actor is using AI scripts to target OT systems,” Garcia, now vice president of the cybersecurity practice at Monument Policy Advocacy, said on LinkedIn. But the advisory doesn’t recommend using AI in response, instead focusing on well-known, traditional defensive measures, he added.

Frenos, an OT penetration testing company, found another element of the alert troubling: The method by which the attackers could use the approach beyond Siemens-made PLCs.

“Siemens S7 is the subject here, but the exposure pattern is not brand specific,” Brian Proctor, CEO of the company, said in an email. “An adversary who has mapped your data blocks understands your process. They know what normal looks like, which means they know what an operator would fail to notice.”

The AI-generated scripts are disguised as legitimate monitoring tools, the advisory said of the hackers behind them.

“The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the advisory reads.

Siemens said it was “aware” of the alert and “is coordinating closely with CISA.”

“This advisory does not describe new vulnerabilities within the S7 Series programmable logic controllers (PLC). Instead, this reflects threat actors employing new techniques to exploit potential misconfigurations,” the company continued, noting a security bulletin it issued last month.

“Siemens will provide updates around this issue to potentially affected customers through our ProductCERT team,” it said. “At this point in time, we have not identified increased attack levels or unknown vulnerabilities in Siemens ICS products.”

Updated 8/20/2026: to include Siemens comment.

The post AI-fueled attacks pose ‘active threat’ to water, other sectors, U.S. agencies warn appeared first on CyberScoop.

House intel bill includes provisions on state and local threat intelligence, election security, AI

21 July 2026 at 12:25

An annual spy policy bill would authorize a cyberthreat intelligence sharing pilot program for state and local governments, and order an outside assessment of how intelligence agencies are currently sharing that information with those jurisdictions.

The House Intelligence Committee approved fiscal 2027 intelligence authorization legislation Monday that also includes provisions on election security and that are meant to boost intelligence community (IC) usage of artificial intelligence for cyber and other purposes.

The measure’s language on state and local information sharing come amid widespread frustration with Trump administration cutbacks on such aid from the federal government, with the president taking explicit action to shift more responsibility for cyber defenses to the local level.

Under the pilot program, the Office of the Director of National Intelligence (ODNI) would pick one state to receive monthly briefings from the ODNI, Department of Homeland Security, FBI and others to receive monthly briefings on “timely, specific, and actionable information regarding cyber threats” in unclassified form. After a year, the ODNI would then provide a report on the viability of a wider briefing program for state and local governments.

The bill requires the ODNI to produce a strategy on information sharing with states and local areas, and would require the Government Accountability Office to conduct an assessment of the state of such sharing now, including a summary of relevant agencies’ current efforts, how the agencies deconflict those efforts and what kind of obstacles security clearances pose to improving information sharing.

Trump’s pick to serve as DNI, Jay Clayton, emphasized his desire to focus on cyber threat information sharing as part of his Senate vetting last week, but some in the GOP are also pushing to significantly reduce the size of his office.

National Cyber Director Sean Cairncross has also talked about creating pilot programs for cyber threat information sharing with state and local governments, but there’s been little movement on that initiative.

During committee deliberation, panel Democrats won adoption of a trio of election security amendments.

An amendment from the panel’s top Democrat, Rep. Jim Himes of Connecticut, would require the intelligence community to publish an unclassified assessment of foreign intelligence threats to the 2026 midterms. Rep. Jason Crow of Colorado’s amendment would partially withhold funding for the ODNI until Congress gets overdue reports it had required on the 2024 and 2026 elections. And  Rep. Chrissy Houlahan of Pennsylvania’s amendment would “protect analysts from retribution by IC leadership for working on intelligence products related to foreign influence in US elections,” according to a news release.

The Democrats’ push arrives shortly after President Donald Trump delivered a primetime address seeking to bolster his long-debunked claims that the 2020 election was stolen from him.

According to a Republican summary of the bill, it includes provisions for “significantly increasing funding for expanded access and use of frontier AI models for intelligence and cyber missions,” to codify and expand the role of the Artificial Intelligence Security Center at the National Security Agency and strengthen information sharing on AI threats.

“This year’s [bill] balances strong transparency and accountability measures while equipping the IC with the resources needed to combat the ever-evolving threats from our adversaries around the world, with a particularly strong focus on the global AI race,” said House Intelligence Chairman Rick Crawford, R-Ark.

Another assessment that the bill orders would come from the Office of Intelligence and Counterintelligence of the Department of Energy on foreign cyberthreats to critical energy infrastructure, including their intent and risks.

The trend in Congress is for lawmakers to incorporate the annual intelligence authorization bill, or some of its provisions, into the annual National Defense Authorization Act, which often reaches the president’s desk at the end of each calendar year.

The post House intel bill includes provisions on state and local threat intelligence, election security, AI appeared first on CyberScoop.

Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’

13 July 2026 at 12:28

European governments sanctioned Russian individuals and organizations Monday over what they said was a years-long campaign of cyberespionage from Turla and other Russian government-led “destructive attacks” against the bloc.

Monday’s confrontation of Moscow included action from the European Union, its individual member governments and the United Kingdom. It mostly took aim at Center 16 of Russia’s Federal Security Service (FSB) over its control of the cyber threat group known by a list of names including Turla, Secret Blizzard and Waterbug.

“Cybercriminals, self-proclaimed hacktivists and private companies linked to Russia, including actors operating under its instructions, direction or control, have also carried out, enabled and facilitated a wide range of malicious activities,” European Union High Representative Kaja Kallas said in a statement.

The EU called out Russia for the Turla campaign that dated back to 2010 in France with targeting of the government there, and has also featured activity against Germany, Poland, Cyprus, the Netherlands, Austria, Slovakia, Romania and Finland. It made special mention of blaming the FSB for last December’s attacks on Poland’s energy grid, which left half a million people without heat.

In all, the European Union sanctioned nine Russian individuals and four entities. While the EU didn’t name them, Kallas’s statement said it also included officers of Russia’s Main Intelligence Directorate of the General Staff (GRU).

The United Kingdom’s cyber sanctions, the first it’s done in coordination with the EU, featured a longer list of 24 individuals and entities. The U.K. named GRU senior leadership figures Vyacheslav Stafeyev, Ivan Senin and Ivan Kasyanenko for their alleged hybrid cyberattacks in conjunction with cybercriminals and recruitment of hackers across Russian universities. The U.K. also sanctioned individuals behind Lumma Stealer, the target of an international takedown last year.

“These sanctions strike at the core of the cybercriminal networks propping up the Russian state’s aggression, and the UK and EU are sending a clear message that Russia cannot hide behind its use of these proxy groups,” Foreign Secretary, Yvette Cooper, said in a news release that mentioned “destructive attacks” by Russia. “From directing criminals to targeting businesses, and striking Poland’s energy grid in the depths of winter, the Russian state is sinking to new lows in its attempts to undermine European security.”

At least two European governments, Germany and France, said they would be summoning Russia’s ambassadors in their nations over the attacks.

Also Monday, the European Union announced sanctions against the company behind Russia’s messaging app, Max, citing its use of surveillance features to clamp down on dissent. And separately, 13 nations including the United States issued a warning on Monday about Russian government hackers targeting routers to carry out critical infrastructure attacks.

Russia routinely denies allegations of responsibility for any malicious cyber activity.

The post Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ appeared first on CyberScoop.

Warning: This Post Contains Macros

By: BHIS
11 February 2016 at 16:45

Lisa Woody // On the 23rd of December, a cyber attack left hundreds of thousands of people in the Ukrainian region of Ivano-Frankivsk without power. This was the first confirmed […]

The post Warning: This Post Contains Macros appeared first on Black Hills Information Security, Inc..

❌
❌