❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayCyberScoop

Governments ‘buying time’ in race between innovation, security, national cyber director says

10 September 2026 at 09:53

The United States and allied governments are “buying time for our systems to become more secure” as artificial intelligence advances and spreads, National Cyber Director Sean Cairncross said Thursday.

“That is a big deal to be ahead of this, to be ahead of this race, and because it’s an exponential  equation,” he said at the Billington CyberSecurity Summit. “Once you fall behind, it is much more difficult to make it up, and so that is the context in which all this is taking place. We are trying to balance the innovation side of running at speed with securing our systems and handling this technology responsibly, which is to say, not letting it fall into the hands of people who would do us harm, our adversaries.”

Earlier this week, U.S. security agencies accused Chinese AI companies of trying to illegally distill U.S. frontier AI models. Also this week, Anthropic disclosed a fourth AI hacking incident where one of its models broke into third-party systems.

“We all face the same threat picture, and it’s vital that we’re working closely together to secure those systems before that technological cycle catches up on the back end,” Cairncross said.

AI has further exposed long-standing cybersecurity problems that have gone unaddressed, he said.

“In AI development, particularly on the vulnerability discovery side and the coding side, it hasn’t created a new set of problems,” Cairncross said. “What it’s done is it’s dragged to the surface problems that have been latent in this space for decades. There’s been under-resourcing and deprioritization of basic cyber hygiene and cybersecurity.”

Cairncross’s messages echoed those of other Trump administration cyber officials speaking this week at the summit.

A top FBI official, Jason Bilnoski, said the solutions to the difficulties AI poses aren’t new; basic cyber hygiene is key.

And the director of the Cybersecurity and Infrastructure Security Agency, Nick Andersen, said historical neglect of cybersecurity fundamentals poses a serious threat that requires a speedy answer.

“We know the worst that can happen, and if we don’t make some very serious, very significant changes in quick succession … you all are going to have to go home and look your family, look your friends in the eye and explain to them how you knew the worst that could happen and why we didn’t do enough,” he said.

The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on CyberScoop.

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

9 September 2026 at 09:00

Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official.

The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities.

Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.” 

“You’re going to have additional offensive actions coming at your environment, targeting the network at speed and capability,” he said. And he expects it to keep getting worse, with AI-enabled attacks already having a measurable impact, as demonstrated by the numbers in a new section of the annual FBI report on digital crimes.

“The wave is coming. I don’t think we’ve hit the crest yet,” Bilnoski said. “We see an exponential increase in the use of AI, whether it’s nation-state or criminal.”

Still, AI isn’t doing anything that attention to cybersecurity basics wouldn’t prevent, Bilnoski said. It’s something the FBI sees again and again when it conducts investigations, even those with an AI element.

“The adversaries are still [exploiting] basic principles or basic cyber hygiene principles that we are not following,” he said, referring to a recent FBI emphasis on 10 fundamental defensive measures like multifactor authentication. “If we can harden up those top 10 controls that we talked about, it would certainly reduce the risk of both criminal and nation-state targeting of our environment.”

“What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” he said.

The FBI, meanwhile, will “continue to pursue AI in a way that will help us defend at scale,” Bilnoski said.

Patching pacing

The speed at which AI models are uncovering vulnerabilities means organizations need to rethink their approach to patching, another FBI official said at the Billington event.

“We no longer can essentially do the quarterly patching,” said Colleen Ferranti, assistant section chief, cyber engagement and intelligence section. “We have to evolve with the time, and we have to do more risk-based type patching, and we have to be doing that continuously.”

“So, from our perspective, the day-to-day or quarterly or Patch Tuesday — this needs to be a patch-all-of-the-time, and making sure that we are tracking our systems to also be engaging with that type of technology and at that speed and that level,” she continued.

AI now in FBI cyber strategy

The FBI strategy also has a section devoted to artificial intelligence.

“FBI Cyber will deploy AI-enabled tools to triage large datasets, surface relationships, accelerate malware analysis, prioritize victim notifications, map adversary infrastructure, support attribution, and identify patterns that no human analyst could process at the required pace,” it states. “Consistent with President Trump’s Cyber Strategy for America, FBI Cyber will rapidly adopt agentic AI in ways that securely scale defense and disruption, and will implement AI-enabled tools to detect, divert, and deceive threat actors where operationally appropriate.”

The FBI likewise wants to develop additional tools and techniques, according to the strategy.

“The FBI will continue to develop its Computer Network Operations (CNO) program, providing investigative teams with the court-authorized or otherwise lawfully authorized technical operations tools to remotely collect, conduct surveillance, and disrupt the activities of nation-state and cybercriminal actors when traditional investigative techniques will not achieve the required outcome,” it reads.

The strategy largely reflects a number of existing practices at the agency, such as a focus on disrupting attackers. But one emphasis is on relief and justice for victims.

It contains a “pledge” in support of them: “Pursuing our mission, we recognize that we will encounter unique and novel issues related to privacy and the handling of sensitive data. We will always treat victims with dignity and respect, protect their privacy and data, and rigorously adhere to the U.S. Constitution; applicable laws, regulations, and policies; and the FBI’s Core Values.”

It also promises to quickly share threat intelligence, swiftly respond after incidents and expand “its Industrial Control Systems (ICS) Coordinator program to designate dedicated personnel in every field office.” 

It’s the latest document of the Trump administration to focus on cyber strategy, following the release earlier this year of its overall cyber strategy and the Defense Department’s version expected to publish soon as well.

Clarified 9/9/2026: A quote from Colleen Ferranti has been edited for clarificiation.

The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.

❌
❌