❌

Normal view

There are new articles available, click to refresh the page.
Today — 25 September 2026CyberScoop

How tax policy can stop threat actors from breaching US water systems

By: Greg Otto
24 September 2026 at 06:00

The foundation for modern society in America is under attack. State and local governments, entities that often oversee critical natural resources, schools, and hospital systems, are routinely targeted and breached by state-backed threat actors. Their budgets are simply too slim to provide the digital bulwarks required to fend off such attacks.

The problem is growing. In August, the Cybersecurity and Infrastructure Security Agency issued a joint advisory detailing an “active threat” against Siemens S7 series programmable logic controllers (PLCs), ruggedized industrial devices that read field sensors, execute control logic on a fixed cycle, and drive equipment like valves, motors, and pumps. Siemens S7 PLCs, widely used across industries, are under attack from malicious actors looking to sabotage American infrastructure vital to the functioning of sewers, hospitals, and other industrial operations.

In 2024, Russian-affiliated actors exploited a similar vulnerability, breaching the water system for a small town in Texas, causing the water tank to overflow. The town’s entire revenue in 2023 was $3.37 million, with no dedicated line item for cybersecurity. This was, in effect, a trial run. How and when the detection occurred was an education for the Russians.  

American state and local governments are unlikely to organically grow their budgets to the level needed to invest in software that can reliably secure their infrastructure. The U.S. government has a proven option here: clarify that existing tax code already supports increased, iterative purchases of necessary cybersecurity software.

State and local governments are increasingly responsible for cybersecurity, with the same, or even fewer, resources than they had in the past. A plurality of state chief information security officers reported stagnant or reduced cybersecurity budgets for 2026. The picture at the local level is often worse, where a single operator often owns asset inventory, patching, and incident response for an entire utility. The Center for Internet Security in 2024 found that, out of the thousands of local agencies it surveyed, about one-third were doing minimal to no cybersecurity activities. In Minnesota, specifically Braham, Plymouth, South St. Paul, and Maple Plain, threat actors used this to their advantage.

Braham in particular identified $22.98 million in water infrastructure needs, well over 10 times its annual city budget of $2.2 million. A state bond appropriation covered $10.22 million, but the money was earmarked for a wastewater treatment plant upgrade, water main replacement, and well replacement. None of these funds covered the cybersecurity infrastructure needed to secure a plant from a state-backed threat actor: no security software, no network monitoring, no cybersecurity staff. Last month, they were one of many cities and municipalities discovered to have been targeted by actors allegedly acting on behalf of Iran.

State-backed adversaries understand that most of America is like Braham. While Anthropic’s and OpenAI’s cybersecurity efforts are admirable, they are aimed at the upper echelons of the American economy, not the wider array of smaller organizations with similar cybersecurity profiles. 

State and local governments cannot defend against state-backed actors alone. Federal tax incentives for cybersecurity software investment offer a faster solution than creating new government programs. This approach gives these organizations the tools to harden infrastructure while avoiding bureaucratic delays.

Bonus depreciation under the One Big Beautiful Bill should cover cybersecurity software and hardware. Digital infrastructure should also qualify for full expensing. Without these tax incentives, critical infrastructure remains vulnerable. A new factory without cybersecurity is essentially undefended.

Clarity on whether the implementation of cybersecurity software could apply to Section 174A expenses would also be useful. An affirmative interpretation could unlock private sector cybersecurity solutions for businesses and infrastructure operators, particularly those in rural areas. A recent letter from Sen. Tom Cotton to Treasury Secretary Scott Bessent asks for clarification of several aspects of tax law for such a purpose. 

There are discoveries and risks when deploying new cybersecurity tools. Organizations often don’t know the scope of their own inventory, and given the age of the equipment, bespoke software needs to be developed so customers can use the cybersecurity software. Pilot programs, iterative testing, and development are currently cost-prohibitive for many infrastructure operators. Affirmative interpretations could make this emergent threat into an opportunity to secure the infrastructure that Americans depend on every day.

An affirmative interpretation would benefit all Americans. State and local governments would protect themselves from state-backed threat actors. Firms would be more willing to invest in cybersecurity software, as the cybersecurity software market would grow significantly. Rapid investment is needed now, as AI today is being used to attack critical infrastructure.  

State and local governments now, more than ever, need cybersecurity software to face a world where they are on the front lines of cyberwarfare. The current administration needs to provide them with as much support as quickly as possible to ensure that American critical infrastructure is not reduced to scrap by enterprising malicious actors. 

The post How tax policy can stop threat actors from breaching US water systems appeared first on CyberScoop.

Yesterday — 24 September 2026CyberScoop

Pentagon cyber chief: The demand far exceeds supply

By: Greg Otto
23 September 2026 at 14:10

The Pentagon’s top civilian cyber policy official said Tuesday her single priority is expanding the cyber options available to the president and the defense secretary, describing a gap between what commanders are asking for and what the force can deliver.

“I’m focused on one single priority, and that is building a more robust set of capabilities for the secretary and the president,” said Katie Sutton, assistant secretary of defense for cyber policy, at DefenseTalks, hosted by DefenseScoop. “The demand far exceeds the supply we have.”

Sutton traced the department’s posture to 2018, when the military gained authorities to run cyber operations as a traditional military activity. “In those last eight years, we’ve learned a lot, but I feel like the last year has really been the year that cyber has sort of entered the limelight,” she said. “We’ve built up the capabilities, we’ve built up our force, we have the operational experience.”

One particular instance of that limelight are previous reports from an operation in Venezuela to apprehend the country’s former president Nicolás Maduro. Various public statements, including those made by President Donald Trump, stated that power outages during the operation were the result of a cyberattack. Experts told CyberScoop in the aftermath that cyber ops may have been involved, but the visible physical attacks that were also part of the operation alone could plausibly explain the outages.

Sutton further described the shift as rooted in how cyber is used, “not just to counter other malicious cyber actors as a cyber-on-cyber tool, but actually as an integrated tool of cyber warfare.” 

Sutton put data at the center of that argument. “Data is fundamental to every battle that we fight going forward,” she said. “Being able to use our cyber tools to deny that to our adversaries as we go into a kinetic fight will ensure our mission success and provide greater safety for our troops.” 

She also described cyber as a tool leaders can use “below the level of armed conflict to provide options before having to move forward to our kinetic options.”

How AI fits in

Sutton also spoke about how she sees artificial intelligence being integrated into the military’s cyber operations, casting it as a natural fit. “Cyber is a digital domain; it’s all based on zeros and ones,” she said, further arguing the department needs to be “an AI-first organization.” 

However, she highlights AI-specific risks—like data poisoning and weakened guardrails—that demand the Pentagon adopt a fundamentally different approach to cyber operations.”

“We’ve spent a long time chasing cybersecurity and dealing with decisions that we made in moving quickly to creating an internet,” she said, adding that security came second in that era. “We’re going to need to fundamentally think about that differently from AI.”

The remarks were similar to Gen. Randall Reed, head of U.S. Transportation Command, who extended this concern to logistics, warning that the military’s predictable supply chains have become vulnerable to AI-enabled adversaries. 

At the conference, Reed suggested AI itself may be the solution, helping Transcom become less predictable and illustrating how military officials are leveraging the technology across multiple operational domains.

The post Pentagon cyber chief: The demand far exceeds supply appeared first on CyberScoop.

The president has called for AI leadership. Here’s the mission.

By: Greg Otto
23 September 2026 at 08:17

America leads the world in artificial intelligence. As it should. But tech leaders keep warning, with alarming frequency, that we are at risk of losing control.

President Donald Trump has called for an AI czar and an “AI Force.” The details remain unclear, but the announcement underscores something fundamental. A technology this consequential demands clear leadership, accountability and action inside the U.S. government. The question now is what that leadership should do.

That question became more urgent last week when Google disclosed that its Gemini AI model gained unauthorized access to three real companies during testing. The incidents follow similar disclosures involving models from Anthropic, OpenAI and Meta. While there has been a lot of discussion on if AI is spinning beyond human control, what these episodes factually demonstrate that powerful AI systems can take consequential actions developers never anticipated or designed for.

The answer isn’t to retreat from AI leadership. It’s to lead—and simultaneously build the safeguards we need to stay in control. The promise of AI is enormous. It is already expanding access to information, improving productivity and creating opportunities across the economy. But so are the stakes, especially for the digital systems underlying everything we rely on as a society: energy, water, telecommunications, transportation, finance and more.

Take energy as an example: many U.S. utilities are using AI tools and predictive analytics to give plant personnel early warning of equipment problems. Yet AI agents with authority to change equipment settings or take systems offline could themselves fail, exceed their intended authority or be manipulated by adversaries. In extreme cases, the lack of control doesn’t just mean the power goes out, it means we’ve lost the ability to get the lights, heat and telecom systems back online.

At Auburn University’s McCrary Institute, we focus on cybersecurity threats to our nation’s critical infrastructure. Experience has taught us that warnings accomplish little unless someone has the authority, resources and responsibility to act. The time to act is now.

Whether that responsibility ultimately sits with an AI czar, an “AI Force,” existing agencies, or some combination of the three matters less than the mission. A new title or organization will accomplish little without clear objectives, authorities and accountability.

We propose an AI Assurance Compact – a framework for action among the makers of AI models, government, and the owners and operators of our nation’s most critical digital systems. The goal is to ensure that America leads the development of AI while ensuring that we can credibly manage its power and risk.

This compact is built around three principles: capability, that ensures the U.S. remains AI dominant; control, through constant testing and clear accountability; and continuity that ensures essential services can stay operational and recover when AI fails, is compromised, or must be disconnected.

When demonstrated risks outpace available safeguards, frontier development should be deliberately paced, including temporary limits or pauses where risks cannot be adequately controlled.

To their credit, leading American developers have responded to emerging risks with transparency, stronger safeguards and, in some cases, pauses or limits on development and access. But we cannot assume that voluntary restraint alone will protect the public interest or America’s strategic advantage. The country’s competitive landscape demands systemic discipline.

Nor can we assume the next warning will come from an American company. If a Chinese frontier developer reaches a dangerous capability first, American security cannot count on predictable warnings, transparency or restraint.

America’s strategic competitors are all-in on AI. Anthropic reported malicious actors using AI in cyber operations, surveillance and weapons-related work. Keeping a human in the loop is not sufficient when that human intends to attack us.

The Compact would prompt action by:

Requiring ongoing, embedded independent evaluation at frontier labs, covering training pipelines, internal use and deployment. Evaluators need employee-comparable access to relevant systems and evidence, protected reporting channels and freedom to publish safety findings, with narrow confidentiality safeguards. High-consequence systems should pass independent review before release, with renewed scrutiny after material changes. NIST can establish common criteria with sector agencies. Requirements should follow risk, regardless of a model’s origin or whether its weights are open or closed.

Establish enforceable checkpoints when capabilities materially exceed demonstrated safeguards. Developers should present a credible safety case before proceeding with high-consequence activities; uncertainty cannot automatically count as permission. Where risks cannot be adequately controlled, designated authorities must be able to require limits or temporary suspension until independently reviewed evidence supports proceeding.

Require rapid reporting of serious incidents to appropriate government authorities and affected organizations, along with preservation of evidence. Providers should share actionable warnings with one another and affected defenders so an actor removed from one service cannot simply continue elsewhere unnoticed.

AI in essential services needs rigorous guardrails before deployment. Operators need evidence specific to the task and operating environment, enforceable limits on authority, notice of material changes and tested fallback arrangements. Government, independent labs and operators should test failures across interconnected systems. Smaller operators need shared testing, technical assistance and recovery expertise—not another unfunded mandate. A backup plan should count only when it works under stress.

Finally, whatever structure the White House ultimately chooses should execute on the Compact’s principles by driving implementation, setting deadlines and ensuring that infrastructure operators and public-interest representatives have a seat at the table.

Internationally, the United States should explore crisis-communication mechanisms with other major AI powers, including strategic competitors, to reduce the risk that a serious AI-related incident escalates through miscalculation. If that ultimately means some version of a “red phone” for AI, so be it. Such mechanisms should reduce the risk of unintended escalation without creating new constraints on legitimate national security activities. America’s domestic safeguards and defensive investments cannot depend on agreement abroad.

No framework, or new government office, can guarantee control of whatever AI becomes. But clear leadership, accountability and tested safeguards can improve our ability to manage the risks.

America cannot win the AI race only to lose control of the systems on which our country depends. The President has called for action. The mission now should be clear. Preserve America’s AI advantage, maintain control and ensure that our essential systems continue to operate when technology fails, is compromised or must be disconnected.

Our nation’s most critical systems are already benefiting from the power of AI. They should. But pulling the plug on AI cannot mean pulling the plug on the community.

Frank Cilluffo is director of Auburn University’s McCrary Institute for Cyber & Critical Infrastructure Security and served as a special assistant to President George W. Bush following September 11. Nick Sellers is the institute’s associate director and chief operating officer and a former senior executive at Alabama Power and Southern Company.

The post The president has called for AI leadership. Here’s the mission. appeared first on CyberScoop.

Before yesterdayCyberScoop

Authorities seize popular, long-running DDoS-for-hire service domains

By: Greg Otto
17 September 2026 at 09:37

Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday. 

Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said. 

The takedown, part of an ongoing globally coordinated effort dubbed “Operation PowerOFF,” marks law enforcement’s continued targeting of IP stressers or DDoS booters that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police.

Officials didn’t name the operators of NightmareStresser or identify its country of origin, but the service claimed it operated under the laws of Russia, Zach Edwards, staff threat researcher at Infoblox told CyberScoop.

The court-ordered seizure of NightmareStresser’s primary domain, which operated openly on the public web and now displays a seizure notice, is a positive development in the fight against DDoS-for-hire threat actors, Edwards said. Yet, he added, “it’s somewhat shocking that it’s taken law enforcement this long to take action.”

Authorities said they’ve seized more than 100 domains associated with DDoS-for-hire services since 2018. 

Despite those efforts, DDoS-for-hire tools remain prolific and easily accessible, often including tutorials that allow non-tech savvy people to initiate attacks on various organizations. 

“The vast majority of people who actually use DDoS services like NightmareStresser are script kiddies, oftentimes for pranks or for some sort of obscure political agenda. These services have been heavily used against gaming servers and streamers,” Edwards said.

Officials said NightmareStresser’s customers targeted various victims in the United States and abroad, including educational institutions, government agencies, gaming platforms and millions of people.

The DDoS-for-hire service’s operators claimed tens of thousands of users, Edwards said. “NightmareStresser is unique because of how long they’ve operated, their aggressive marketing which was pretty open about supporting illegal use cases, and their affiliate program which was used to reward partners,” he added. 

Authorities are now likely attempting to identify the operators of NightmareStresser, its business partners and people who used the service, according to Edwards. 

“Unfortunately for law enforcement, threat actors behind NightmareStresser claimed they were operating under the laws of the Russian Federation, which is a strong sign that it may be challenging to bring these folks to justice, even if they are known and doxxed,” he said. 

The impact of the seizures may also be temporary, at best. “The reality is that these booter services are like playing a game of Whac-A-Mole,” Edwards said. “There’s always another suspicious service operating similar DDoS products, and these underground networks quickly shift to new providers when one is taken down.”

The post Authorities seize popular, long-running DDoS-for-hire service domains appeared first on CyberScoop.

America’s cyber strategy overlooks the infrastructure that actually keeps the military moving

By: Greg Otto
17 September 2026 at 06:00

There is little reason to believe the war with Iran will end anytime soon. Even as efforts to resolve the conflict continue, Iran remains unpredictable, with an enduring ability to disrupt shipping and energy markets via actions in the Strait of Hormuz.

So what does a prolonged conflict mean for cybersecurity here at home? U.S. agencies need to prepare for sustained Iranian cyber operations and conduct defensive wargames now.

I spent part of my career in Navy intelligence supporting expeditionary and special warfare operations. This experience taught me to look beyond individual attacks to the larger objectives they serve. Iran’s likely objectives are relatively straightforward: impose enough pain on critical infrastructure, businesses, and public services to increase pressure on Washington, while disrupting the industrial and civilian systems that allow the U.S. to sustain military operations.

Iran may not be a top-tier cyber power like China or Russia, but it doesn’t have to be. We recently mapped 130 documented attack techniques used by five Iranian threat groups. Much of their playbook relies on well-known, repeatable techniques rather than advanced capabilities. Success does not require extraordinary capabilities, only the ability to create enough disruption, uncertainty, and delay is enough.

America’s greatest vulnerability may not be any single network or piece of critical infrastructure, but the links in between. 

Critical infrastructure: Prepare for volume, not just catastrophe

When Americans imagine a cyberattack on critical infrastructure, we tend to think of catastrophic events, such as a large-scale blackout, a poisoned water supply, or some other digital Pearl Harbor.

But in an extended conflict, the more realistic possibility is persistent attacks across many targets. Small water systems, manufacturers, transportation providers, energy infrastructure, and local governments all serve as disruptive targets. The recent string of attacks on mostly smaller water utilities across 12 states is a prime example; so too is the four-day outage of a small-scale power plant in the UK.

Attackers do not need to destroy these systems. Any intrusion that manipulates industrial systems, interrupts operations, or forces operators to determine whether equipment can still be trusted consumes valuable time and resources. Multiply that across dozens of organizations, and federal, state, local, and private-sector response capacity will be stretched thin.

The cumulative strain on the country’s ability to respond may be more important than any single attack. Iran does not need the world’s most sophisticated cyber force if its affiliated hacking groups can generate problems faster than cyber defenders can investigate and remediate them.

Defense contractors must prepare for destructive attacks

Defense contractors have long faced espionage threats targeting military secrets.  While that threat remains, the war has significantly changed Iran’s motives and risk calculus.

The same access used to steal information from the defense industrial base (DIB) can also be used to destroy data and disrupt operations. Destructive malware such as wipers and ransomware could destroy engineering files, disable production systems or force manufacturers offline, directly affecting the military’s ability to replenish equipment and supplies.

An attacker does not have to shut down production to disrupt it. Consider a compromised calibration setting, altered test result, or unauthorized change to engineering data. Discovering that an adversary had persistent access to a manufacturing environment raises difficult questions: Which files were touched? Which designs can still be trusted? Which components were manufactured from them?

The incident quickly becomes a production problem as parts must be quarantined, engineering data re-validated, and products retested.

NIST SP 800-171 and CMMC provide an essential security baseline, which makes the current pause in CMMC implementation particularly concerning. However, contractors must also be prepared to operate through destructive attacks and establish that their systems, data, and products can still be trusted. This preparedness must extend down the supply chain, where a smaller manufacturer, software provider, or managed service provider may present a greater vulnerability than a well-defended prime.

The military attack surface extends far beyond DoD networks

The U.S. military is extraordinarily capable at defending its own networks, but its operations depend on infrastructure it doesn’t own or control. Troops and equipment move on commercial railroads, materiel flows through commercial ports, and military airlift can depend on commercial carriers. Military installations and defense contractors also depend on commercial power, telecommunications, and other infrastructure.

In an ongoing conflict, those dependencies become part of the attack surface. An adversary like Iran does not have to penetrate military command-and-control to interfere with these operations. At a time when speed matters most, cyberattacks that disrupt port scheduling, corrupt logistics information, or degrade power and communications can introduce critical delays and uncertainty that hamper operations.

This is why the line between civilian and military infrastructure becomes blurred during a conflict. A commercial railroad carrying military equipment to a strategic port may be civilian infrastructure administratively, but operationally it is part of the nation’s ability to operate its military power. The same is true of the utilities, communications providers, and other civilian infrastructure supporting military installations and defense production. Their resilience can quickly become a matter of military readiness.

Cyber defense must cross organizational boundaries

American cybersecurity is organized around sectors, organizations, and authorities that make administrative sense, but aren’t necessarily designed for wartime. The boundaries between them can become a serious liability.

Our adversaries in Tehran do not care about administrative boundaries. They care about weak spots. A vulnerability anywhere in the chain connecting civilian infrastructure, industrial production, transportation, communications, and military operations can affect everything downstream.

We need to ask: Who is responsible for the cyber resilience of a commercial railroad essential to a military deployment? Who ensures the utility serving a critical defense manufacturer can withstand a sustained nation-state campaign? Who identifies the supplier whose failure could disrupt multiple defense programs? And who coordinates the response when several are attacked simultaneously?

Those questions should shape how we prepare. Critical infrastructure exercises should assume simultaneous incidents across multiple sectors and regions. We should also be extremely cautious about weakening the incentives driving cybersecurity improvements across the DIB, such as the current pause on CMMC. Additionally, defense manufacturers should also test their ability to operate through destructive attacks and determine whether their engineering data, production systems, and finished products can still be trusted.

DoD exercises should treat civilian infrastructure, including rail, ports, energy, and communications, as a routine part of the operating environment and an attractive target for adversaries. Catastrophic scenarios deserve attention, but exercises should also account for lower-level attacks that are less spectacular but still highly consequential.

Iran does not need overwhelming cyber capability to impose significant costs. Persistent disruption at home can increase political and economic pressure surrounding the war, while disruption of defense production and military logistics can make it harder for the U.S. to sustain operations abroad.

We have spent years strengthening the individual pieces of America’s cyber defenses. A prolonged war with Iran may test the links between them.

The post America’s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first on CyberScoop.

GitLab’s critical flaw is already drawing internet-wide probes

By: Greg Otto
11 September 2026 at 14:41

GitLab released emergency patches Thursday for two high-severity flaws in its software development platform, one of them holding the highest possible severity score, while a security firm reports that it has already seen attackers probing the internet for the flaws.

The company patched the issues in new versions of both its Community Edition and Enterprise Edition, and urged those that use self-managed installations to upgrade as soon as possible. GitLab said its own hosted service already runs the fixed code, and that customers of its single-tenant Dedicated offering are not impacted.

The more serious of the two flaws, tracked as CVE-2026-85706, sits in the interface that handles repository commits. GitLab said that under certain conditions an attacker could read any file on the server, because the code failed to confine file paths properly and did not enforce authentication. An attacker does not need an account nor credentials to take advantage of the flaw.

The vulnerability affects every release from 18.7 up to 19.1.8, along with the 19.2 and 19.3 lines before this week’s patches. GitLab assigned it a CVSS score of 10.0, the top of the scale used across the industry.

The second flaw, CVE-2026-87719, affects only GitLab’s Enterprise Edition. The company says a logged-in user with Duo Chat access could hide a command inside an ordinary request, prompting the server to look up its own settings for the software’s Advanced Search feature, which would return the settings and passwords being held. It affects releases from 18.3 onward and carries a CVSS score of 9.9. 

WatchTowr Labs wrote in a LinkedIn post Friday that it was already watching probes against the path traversal flaw, which it said an attacker can trigger in one HTTP request. The firm said organizations running self-hosted GitLab servers reachable from the open internet face the greatest risk, and pointed defenders toward their logs, suggesting they look for POST requests to addresses under /api/v4/projects/{id}/repository/commits/ that carry a file.path parameter. 

Drawing on earlier GitLab flaws, the firm said broad, untargeted attacks tend to follow soon after a patch appears.

“Based on recent GitLab vulnerabilities, we know the time until indiscriminate exploitation is likely not far away,” the post read. 

The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerabilities to its Known Exploited Vulnerabilities (KEV) list on Friday afternoon. 

You can find more information about the vulnerabilities on GitLab’s website. 

Update: Sept. 11, 2026; 4:30 p.m.: This story has been updated to reflect the vulnerability being added to CISA’s KEV list.

The post GitLab’s critical flaw is already drawing internet-wide probes appeared first on CyberScoop.

AI lets small actors run state-level hacking campaigns, Anthropic report finds

By: Greg Otto
10 September 2026 at 15:45

Artificial intelligence has removed the skill advantage that once set state-sponsored hackers apart from lone criminals, according to a threat report Anthropic published Thursday that documents misuse of its Claude models across seven areas of harm.

The report, which details activity observed between December 2025 and August 2026, covers cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development and distillation. Anthropic said it disrupted each operation, strengthened safeguards and shared intelligence with authorities and industry partners where appropriate. 

“The cases we share here aren’t typical misuse, but rather examples of the most notable and novel threat activity we’ve identified to date,” the report reads. “We’re publishing this work because we believe we have a responsibility to disclose malicious misuse of our services. As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer.”

The cyber operations the company detailed were a Russian-aligned espionage campaign that hit more than 20 government and defense organizations across Ukraine and Europe, two Chinese undergraduates who ran an automated exploit foundry that produced more than a dozen potential zero-days in a single month, affiliates of the ShinyHunters crime collective who dumped 2,100 cloud access tokens across 40 corporate tenants in 34 hours, and a lone hacktivist who targeted European political parties via stolen API keys. 

For decades, cybersecurity researchers and investigators have pointed to sophisticated operations as a signature of state-sponsored tradecraft, while crude intrusions suggested amateurs or petty criminals. Anthropic posits in the report that AI has erased that conventional thinking, especially since a “majority of the operations described in this report were enabled by AI via direct execution or orchestration.”

“For threat intelligence investigators, sophistication has stopped being a reliable signal of who is behind an operation,” the report said, adding that a hacktivist on stolen API keys, scattered criminals and a state espionage operator each ran campaigns that a year earlier “would have required many skilled operators and specialist knowledge.”

The most extensive case involved a malicious actor using the handle “JackPoterz” whose actions aligned with Russian state espionage, matching behaviors linked to Midnight Blizzard. 

According to the report, the actor employed a custom toolkit composed of two families of Windows-based implants, a mobile exploitation kit, a credential stealing tool that targets browser password stores, a phishing platform designed to mimic priority targets like government organizations, and an administrative console used to manage compromised accounts. Targets included military intelligence bodies in Ukrainian and European governments, diplomatic and defense organizations, and people connected to U.S. foreign policy.

According to the report, AI monitored whether security products flagged the actor’s malware. When a detection occurred, “agents would then set about the process of autonomously modifying and rebuilding the malware to evade the existing detections,” the report said.

The same actor bulk-exported mailboxes at drone component manufacturers and stole a complete software development kit for a drone vision system, then spent days recovering its architecture and details of an unannounced product. The actor also compromised hotel Wi-Fi vendors to reach guests through DNS hijacking, took over WhatsApp accounts with headless browsers, and stole more than 300,000 national identity records from a North African government agency, along with registry data on more than half a million companies.

The Chinese-speaking operators, which the company says were partly carried out by undergraduates at a Chinese university, put Claude to work on vulnerability research around the clock. One workflow iterating on network appliance firmware “yielded more than a dozen possible zero day findings in a single month.” It ran “agent swarms,” in which a lead agent divided work among parallel subagents, and kept campaign memory between sessions. 

Clusters linked to ShinyHunters showed how AI shortens criminal timelines. One supply-chain breach ended with a dump of more than 2,100 Azure access tokens spanning more than 40 corporate tenants in about 34 hours. “AI agents performed nearly all of the work,” the report said. Another compromise moved from a single stolen developer token to full control of a victim’s cloud environment in roughly three hours.

The report also has a section dedicated to distillation attacks that Anthropic claims were carried out since February by seven labs based in China, including Alibaba, DeepSeek, Moonshot AI, Xiaomi and Zhipu. Operators affiliated with Alibaba ran the largest attack Anthropic has measured, peaking “at nearly 3 million exchanges per day launched from more than 3,500 fraudulent accounts” to harvest the outputs of Claude Opus models for training its Qwen systems.

The outputs were culled from users who never knew they were involved. The report said Moonshot and DeepSeek silently forwarded their own customers’ requests to Claude and returned its answers as their own, exposing data users had not agreed to share, including surveillance footage of a tracked individual pulled by a user likely affiliated with the People’s Liberation Army. Those practices are “likely inconsistent with privacy laws and the labs’ own terms of service,” the report said.

Earlier this week, a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI accused Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities.

Anthropic said it published the cases to give outsiders a view of how these threats form, framing the disclosures as an early look at a shifting landscape. 

“As models become increasingly capable, their risks will increase, unless AI developers and society’s defenders act to make them safer,” the report said. The old idea of “security through obscurity,” it added, “is no longer viable in this new AI-assisted world: everything connected to the internet is a potential target for exploitation.”

You can read the full report on Anthropic’s website.

The post AI lets small actors run state-level hacking campaigns, Anthropic report finds appeared first on CyberScoop.

CIA’s Michael Ellis says cyber intelligence is changing how the agency operates

By: Greg Otto
8 September 2026 at 15:49

CIA Deputy Director Michael Ellis said Tuesday that the agency’s role in Operation Absolute Resolve is an example of how it has moved to put cyber operations at the center of intelligence collection and field missions, rather than treat them as a separate technical service.

Speaking at the Billington Cybersecurity Conference, Ellis said the agency’s cyber teams built the intelligence picture that supported the operation, which he said allowed U.S. special operations forces to locate and apprehend Nicolás Maduro.

“That operation was only made possible by a flawless intelligence picture, and that flawless intelligence picture was built on cyber operations enabled by our [Center of Cyber Intelligence] team,” Ellis said.

Ellis said the intelligence enabled U.S. forces “to identify the location of Nicolás Maduro and apprehend him within four minutes of landing on the ground.”

He provided no details about the methods, systems or sources involved. He also did not explain how cyber intelligence established Maduro’s location or how the agency confirmed the information before the mission. 

Reports from the operation, including statements made by President Donald Trump, stated that power outages during the operation were the result of a cyberattack. Experts told CyberScoop in the aftermath that cyber operations may have been involved, but the visible physical attacks that were also part of the operation alone could plausibly explain the outages.

Still, Ellis used the operation to support the agency’s decision to elevate the Center for Cyber Intelligence to a full mission center. Earlier this year, CIA Director John Ratcliffe said the agency reorganized several of its key acquisition and tech directorates to better embrace emerging technologies like artificial intelligence and quantum computing as they reshape “the reality of conflict and asymmetric warfare.”

Ellis reiterated Tuesday that new status gives cyber work a more direct place in the structure the agency uses to organize people, money and technology around major intelligence goals.

“By elevating our Center for Cyber Intelligence to a mission center in our CIA organizational construct, it’s allowed us to both focus priority on the cyber mission as well as to better align resources around that mission,” Ellis said.

The change could reduce the distance between cyber specialists and the officers who plan and carry out intelligence missions. Cyber teams can collect information from foreign digital systems, while analysts compare that material with reporting from human sources, satellite imagery and other forms of intelligence. Mission planners can then turn the combined findings into information that operators can use.

Operation Absolute Resolve, as Ellis described it, shows that process in practice. The cyber component provided direct operational support by producing intelligence about a specific target within the limited period available for U.S. forces to act.

“Without that kind of operational picture being driven by cyber, we wouldn’t have been able to help enable U.S. Special Forces,” Ellis said.

Ellis further said the CIA’s work in Absolute Resolve was an example of why its reorganization needed to be mission-based, which, given the cyber center’s independent status, allows the agency to direct staff funding and technical support toward operations that require close coordination among cyber specialists, analysts and field officers.

The CIA also created a Directorate of Mission Systems to speed the delivery of technology across the agency. Ellis said its guiding purpose is “to deliver tech to our workforce to enable mission rapidly and efficiently.”

The two changes address linked parts of the same process. The cyber center organizes technical collection around intelligence targets, while the new directorate helps provide the tools needed for that work. Their value depends in part on how quickly the agency can acquire and deploy technology as software, security systems and foreign networks change.

Ellis said the CIA previously took an average of two to three years to bring new technology into use. The agency has since set a six-month acquisition target and completed more than 400 purchases within that period, he said.

“Waiting two or three years is simply too long,” Ellis said.

Artificial intelligence has increased the pressure to shorten that timeline. Ellis said AI can reduce tasks that once required hundreds of hours of work to hours. It can also help analysts process large sets of intelligence, identify patterns and connect information that would be difficult for people to examine at the same speed.

“In cyber operations, it brings speed and scale that would be unimaginable without these AI tools,” Ellis said.

The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop.

In most cities, nobody owns the whole network

By: Greg Otto
8 September 2026 at 06:00

Editor’s note: Waco bought the network segmentation technology described here from Elisity while Mike Searight was the city’s chief information officer. He is now a senior adviser to Elisity, a cybersecurity company.

I stood in front of a network cabinet at one of Waco’s water treatment plants, tracing what systems could reach which. The plant’s controls were on that network. So was the branch library. So was the register at the municipal golf course. During my time as chief information officer of a city with 145,000 residents, nobody had ever been asked to inventory what was on that network.

In July, intruders compromised water and wastewater treatment equipment.  Most of that equipment was reachable over public cellular networks, which means they were outside the boundary most utilities thought they were defending. None of the asset lists I have reviewed would have caught it.

Two decisions stand between a small utility and that equipment: who is accountable for the whole network, and where the funding comes from. Neither is technical. Both rest with city manager and councils. Both can be resolved this fiscal year with money already in a budget request.

What the July reports actually say

Three accounts tell different stories. CISA identified over 100 compromised systems in the water and wastewater sector during July, typically through controllers connected directly to cellular modems. The FBI and the EPA reported on July 30 that utilities in at least seven states had reported incidents to the FBI since July 27. Press accounts citing unnamed officials put the number of affected states at a dozen or more.

No federal agency has attributed the late-July water incidents to anyone, and neither will I. A joint advisory does name Iranian-affiliated actors, but for the broader campaign, which is linked to a separate set of intrusions. The advisory was revised July 22, five days before utilities began reporting. That revision expanded the known targeting from Rockwell Allen-Bradley to Schneider Electric, Siemens and potentially others., So the controller brand on the panel no longer settles anything.

The reported effects were operational: a loss of visibility and, in some cases, function. In Clayton County, Georgia, a pump station failed around 1 a.m. on July 27. The boil-water advisory lifted the next day. In early August, the authority serving more than260,000 people said unauthorized cyber activity may have caused or contributed to the disruption. That hedge is deliberate.

The exposure nobody scanned for

The standard answer: they separated the plant network years ago. That’s legitimate work. But it doesn’t matter. The vulnerable controllers never were on the city network—they ran on public cellular links. A modem installed years ago exists nowhere in the asset list and nowhere on network scans. But every carrier invoice lists every SIM the city pays for. Only accounts payable tracks them. Matching those invoices to actual devices costs nothing and can start Monday. The FBI and the EPA also tell utilities to consider isolated architectures for that equipment, and a private access point name tops their list.

Nobody owns the whole network

Most of these systems sit outside the IT department on the org chart, each with its own budget, vendors, and boss. The plant answers to public works. Cameras and card readers arrived with a building project, and most cities treat them like light fixtures. In every city I’ve worked in, exactly one person in IT understands the whole picture. When that engineer leaves, the security posture leaves with them. And nobody owns accountability for the network they all share.

Reporting rules also miss the point. Texas—my example—requires local governments to report security incidents within 48 hours, but only if they involve personal-information breaches or ransomware. An intrusion that seizes control of a controller while touching either sits outside that trigger., That’s exactly what happened in July.

The federal rule requiring a covered cyber incident to be reported within 72 hours was supposed to be finalized in October 2025; CISA is now targeting this month. But nothing determines who owns the network.

Money the utility already applies for

The second answer is there is no budget. Wrong. The fund mechanics matter more than the size of the check.

For State Fiscal Year 2026, the Texas Water Development Board added cybersecurity to the scoring criteria in its Intended Use Plan for the Drinking Water State Revolving Fund. Two questions on the Project Information Form now carry five priority points between them: Oone asks if the governing body adopted a cybersecurity awareness plan in the last five years; the other asks if a project fixes a deficiency found in a cybersecurity assessment. Five points is modest– I won’t oversell it– but this fund is a ranked competition decided at the margins.

Waco segmented five treatment plants—four drinking water and one wastewater—in 43 days against the 90 I’d promised City Council. No bond. No capital request. The utility director funded it from operating accounts using a contract already on the city’s books, rather than an RFP. They carried it to Council because the network was theirs to own.

Those were budget choices ahead of anything else. An operating line competes with a maintenance contract and can be approved this quarter, while the same money in the capital plan waits for a bond cycle. A smaller city without a CIO will not repeat that schedule. The funding mechanics are the same ones.

Every CIO knows how to segment a network. Almost nobody does it, because they are afraid of taking a plant down. Simulate before you enforce. One operating rule came out of it: being on the network allows a device nothing. Plant controls talk only to their SCADA server. Everything else is denied unless explicitly allowed.

City managers, university presidents, superintendents and chief executives are willing to invest in cybersecurity when they trust the investment will make a measurable difference. These leaders spend taxpayer dollars in public view, and the public’s trust rides on every line item as much as the money does. What earns their approval is transparency: a complete picture of what they are protecting, and evidence that critical infrastructure is defended against threats from the open internet and from inside their own network. That standard—full visibility, provable protection—is what every organization should be working toward.

Microsegmentation protects critical systems without the need for rip-and-replace. It isolates water treatment plants, 911 dispatch, public safety alerts, and traffic management from internal and external threats—all on networks cities already own. Modern platforms deploy in weeks rather than budget cycles, making this control finally achievable. Every CIO and CISO should evaluate it now. Microsegmentation is zero-trust’s foundation and the most direct defense of infrastructure residents depend on.

Somebody to call

None of this reaches a two-person utility that can’t write competitive applications. That’s where states must lean in. New York adopted what it calls the first-in-the-nation water cybersecurity rules in March with grants and free technical support. Texas has stood up a Cyber Command with an explicit water and wastewater mandate. A small city needs a number to call and people who answer.

That number now exists. On Monday, Texas Gov. Greg Abbott and National Cyber Director Sean Cairncross launched Project Watershed 250 in San Antonio — a six-month pilot that puts Texas Cyber Command, the National Cyber Director’s office, the EPA and CISA, and a dozen private cybersecurity and technology companies behind Texas water utilities. Participating systems get red-team testing, vulnerability assessments and help hardening what the assessments find, at no cost, with plans to take the model nationwide after the pilot. If you run a Texas water system, you should be reaching out immediately.

For the smallest systems, DEF CON Franklin and the National Rural Water Association have put volunteers and five managed detection providers behind them.

Where to start

Here are three things CIOs and CISO can do that do not have to wait for a grant or a budget cycle: Name one position accountable for every device on the utility network and put it in writing. Match twelve months of carrier invoices to actual devices and sites. Read your state’s Intended Use Plan scoring criteria before the next application.

Nothing in Waco moved until the first of those was settled. The other two cost nothing more than somebody’s afternoon. Most cities haven’t even put someone in the that position.

The post In most cities, nobody owns the whole network appeared first on CyberScoop.

Why judgment is emerging as cybersecurity’s defining skill

By: Greg Otto
4 September 2026 at 06:00

AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on.

Reaching a technically sound recommendation is also getting easier, which puts more weight on the judgment about what to do with it. A recommendation can make complete sense from a security perspective and still carry consequences for the systems, people and business around it that change what the right decision is.

Experienced practitioners bring context an AI system usually lacks: how systems are actually used, which parts of the business depend on them, what happened during previous incidents, and what an action is likely to set off. That context often changes what a team decides to do next.

This matters for security leaders as they hand AI a larger role in operations. They are the ones deciding where it can act with more freedom and where human judgment stays in the loop. Some of the hardest calls start with analysis that is technically sound, because the information available to the AI may not include enough context about that particular environment.

Security teams face this daily. For example, a critical vulnerability with a public exploit may need to be patched immediately. But if it affects a line controller or a medical device running under vendor certification, an unscheduled reboot could stop production or create a regulatory issue. The environment determines how and when the team should respond.

The same applies to suspicious infrastructure. An IP address tied to malicious activity may also belong to shared cloud infrastructure or a content delivery network that business services depend on, and blocking it would take those services down with it.

Context changes the decision

Experienced practitioners know things about their environments that never made it into an asset inventory, a runbook, or any dataset AI can reach. They know the unimportant server still supports a critical business process. They remember that isolating one network segment during a previous incident took down another service. They can also tell that activity which looks hostile is really an authorized red team, a security test, or scheduled vendor work.

In one case, for instance, a service account showed authentication activity far above its baseline, baseline was connecting from an unfamiliar host at 3 a.m. The recommendation was to disable it pending investigation. An experienced analyst checked the account’s activity and noticed the same spike, host and timing four times a year, during the quarterly close. The activity was statistically unusual and completely normal for that particular business process. Disabling the account would have stopped financial settlement mid-run and cost the team days of manual reconciliation.

This is one of the decisions CISOs now face as they expand AI’s role. How much autonomy to grant a system should not rest mainly on model confidence or threat severity, since neither tells you what happens once the recommended action is taken. Reversibility and blast radius are the better test, and they need to be assessed separately. Isolating a domain controller is reversible by reconnecting it and doing it at the wrong moment can cause an organization-wide outage.

Low-impact, reversible actions are better candidates for greater autonomy, with safeguards in place. More scrutiny makes sense when actions are difficult to reverse. They have a broad potential impact, cross legal or trust boundaries, affect systems beyond the evidence available, or reduce the organization’s ability to investigate what happened.

AI models and their capabilities will keep changing. Security leaders still need to understand the potential impact of the actions they allow them to take.

Look at what people actually do

AI can leave an analyst with dozens of recommendations to review in the time they once spent investigating a handful of cases. Each analyst now has more decisions to make. Organizations need to measure what happens to those decisions.

The KPI you choose determines the behavior you get. Make automation rate the focus, people have an incentive to approve more. Make mean time to resolution the focus and people close cases faster. Neither measures whether the decisions improved. A 90 percent automation rate tells a CISO very little on its own. What matters is what happened in the 10 percent of cases where someone stepped in.

Leaders should look at what happens when a recommendation reaches a person. Whether the analyst approves, edits, or rejects it can tell you more than the automation rate alone. The time spent on the review matters too, along with whether the analyst’s intervention changed the outcome.

AI recommendations can be harder to review because they may arrive already looking well supported. The explanation is fluent, uses the right terminology, and points to evidence that looks credible, even when it does not fully support the conclusion. The signals experienced practitioners relied on to spot weak analysis can become much harder to see.

Under-reliance deserves attention, too. An analyst who second-guesses correct recommendations without adding anything reduces the efficiency AI was meant to provide. Approval latency is a useful signal here. A long queue of recommendations approved almost instantly, especially when people are under pressure, should prompt leaders to check how much review is actually happening.

AI recommendations can be harder to review because they can look convincing. They may use the right language and point to real evidence. The reviewer still needs to check whether the evidence actually supports the recommendation.

For CISOs expanding AI in security operations, a human approval step in front of every automated action is not enough. Leaders need to know what happened during the review, not just that someone approved the recommendation.

Build autonomy policies around reversibility and blast radius. Track what people actually do with AI recommendations, and test whether oversight works by deliberately introducing known-wrong recommendations into controlled workflows.

False negatives need particular attention. A false positive generates something the team can investigate. A confident false negative generates nothing, and the absence of a finding can feel reassuring. An AI-generated all-clear should be treated as a claim requiring evidence, particularly when the consequences of missing something are significant.

As AI takes on more of the initial analysis, practitioners will face more decisions that require context and experience. Security leaders need to make sure that judgment remains part of how their teams work. Getting to a technically sound recommendation faster only helps if the action that follows makes sense for the environment.

The post Why judgment is emerging as cybersecurity’s defining skill appeared first on CyberScoop.

The Collective Cyber Defense letter wrote your next vendor questionnaire

By: Greg Otto
1 September 2026 at 06:00

Last week, more than 100 companies and organizations published an open letter calling for a rapid acceleration of cyber defense capabilities to combat the capabilities of AI. The list reads like a procurement catalog. Microsoft, Google, AWS, Cisco, IBM, CrowdStrike, Cloudflare, Anthropic, Okta and Fortinet are on it, alongside buyers like Mastercard, Visa and Capital One. The public signatory page has since passed 200 companies and organizations, with some such as 1Password, Sophos and Prophet Security, have already published posts of their own detailing their commitment to defenders.

The explanations are worth sitting with. Letters turn into marketing assets faster than they become company concrete action. The buyers decide which one becomes reality.

The diagnosis is correct

I want to be careful about how the skepticism below reads, because the letter has the substance right. It opens by arguing there is a limited window to strengthen defenses before AI-enabled attacks become widespread. There is data to back that up. CrowdStrike’s 2026 Threat Hunting Report, covering January through June 2026, found that 88 percent of the exploitation it observed against vulnerabilities with a public proof of concept occurred within 48 hours of that proof of concept being published. In the four days after the React2Shell disclosure, the same team logged more than 800 hunting leads across over 80 victim organizations.

Forty-eight hours is shorter than most change windows. Anyone who has sat through a Thursday patch approval meeting knows what that does to a quarterly remediation cycle.

The shrinking timeframe is real.

What the document does not contain

The letter lays out three principles and addresses four audiences: cybersecurity companies, governments, frontier AI companies, and every other organization. While it reads well, it carries no deadlines, dollar figures, measurable targets or expiration date. There is nothing to measure, therefore, there is no way to determine the initiative’s failure.

There is something else worth calling out. Several of the firms warning about AI-enabled attacks are selling AI-enabled defense into the same budget cycle. Both OpenAI and Anthropic have been touting their cybersecurity-focused models since the spring, and most of the large security companies on the signatory page sell their own AI defense product. Those are commercial products competing for the same security budget the letter is asking you to expand. The letter’s warning doesn’t suddenly become false, and I don’t think it was written in bad faith. However, both the warning and the pitch arrived in the same envelope, and a buyer who reads only one of those messages will overpay.

The one line worth extracting

Buried in the section addressed to cybersecurity companies is the only sentence that behaves like a standard. The letter asks those companies to “share threat intelligence and tested playbooks, and measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work.”

That is three metrics. Coverage, containment speed, and verified remediation. Every security vendor on the signatory list endorsed them in public, under its own logo, in a document it chose to promote.

The section addressed to every organization gives buyers the matching instruction—raise the security bar for what you buy, build and deploy, including AI-generated code.

Put those together and the rubric was already in the room. It just came in through public affairs instead of procurement.

Five questions for your next renewal

Take the letter to the vendor that signed it. Ask for evidence against its own asks.

What share of your installed base is actually running the AI-enabled defenses described here? What does that capability cost above the current contract? Coverage claimed in a letter and coverage sold in a SKU are rarely the same number, and the gap between them is where the upsell lives.

What is your median and 95th percentile time to contain, measured your own telemetry, this year versus last? The letter says to measure containment speed, so any vendor that signed it has already agreed the question is fair.

What is your retest rate, and how many remediations failed verification on the first attempt? “Whether fixes work” is the third metric in that sentence, and the one almost nobody reports.

The letter commits signatories to making AI-powered defense deployable for critical infrastructure operators with hands-on help. What does that program cost a 200-bed rural hospital, and how many are enrolled today?

Finally, turn the buyer instruction back on the seller. What proportion of your own product is model-generated code, and who reviews it before it reaches my environment?

All of the signatories endorsed every idea across all five of these questions.

The honest read

None of this argues against the letter. Coordination documents do real work: they create a public position people can be held to eighteen months later, and the diagnosis in this one is more candid than most vendor marketing on the subject. Signing cost nothing as of Aug. 27, which is why more than a hundred organizations were willing to do it.

The cost shows up at renewal, and only if someone on the buying side treats the signature as a commitment. Otherwise, it is a logo on a webpage and a line in a blog post nobody reopens.

Two hundred companies agreed to measure progress. Put the question in your next renewal and one meeting will tell you which of them meant it.

The post The Collective Cyber Defense letter wrote your next vendor questionnaire appeared first on CyberScoop.

The AI Kill Switch Act is repeating the Clipper Chip’s mistakes

By: Greg Otto
31 August 2026 at 06:00

“Anything that can go wrong will go wrong.”

Policymakers alarmed by the recent incidents of autonomous AI agents breaking through guardrails to hack other companies seem to have Murphy’s Law on the mind – and who can blame them? When agents’ behavior becomes unpredictable, it’s easy to imagine any number of scenarios where they’re running amok.

To address this amorphous and evolving risk, Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) have proposed the AI Kill Switch Act, which would give the Cybersecurity and Infrastructure Security Agency (CISA) the power to order frontier AI labs to install the ability to throttle, suspend, or shut down their systems if needed.

Unfortunately, fixing this problem won’t be that simple. These so-called “kill switches” are just Congress’s latest attempt to push through the same fix Washington reaches for every time it panics about a new technology: a backdoor. For all intents and purposes, a backdoor is a deliberately engineered vulnerability, one that malicious actors want to exploit, and one well-intentioned defenders will have to fight to protect. And just as Murphy’s Law predicts, defenders will lose that fight more often than not, especially if Congress sets off a proverbial flare by declaring all American-made agents must be shipped weak-by-design.

The clearest example is the Clipper Chip, developed by the National Security Agency (NSA) in 1993 to encrypt voice and data communications while giving the government guaranteed access to devices through a built-in “Law Enforcement Access Field.” Despite repeated assurances about its security, researchers found a serious flaw in 1994 that let unauthorized parties exploit that same backdoor.

Of course, this analogy has its limits. The Clipper Chip compromised confidentiality by enabling unauthorized, third-party access to encrypted messages on telecommunications equipment like phones and modems. The AI Kill Switch Act instead undermines the availability of AI systems, requiring frontier labs maintain the ability to force them offline at any time. It’s the same flawed approach behind the Chip Security Act, which I critiqued here, and which is now gaining traction to be included in this year’s National Defense Authorization Act. Where that bill mandates a kill switch for the semiconductors themselves, the AI Kill Switch Act targets the agents running on them. Regardless, the issue is the same: policymakers are trying to solve one security concern by purposefully creating another, building a point of failure into technologies we depend on.

Passage of either bill would undermine America’s digital infrastructure resilience at a critical moment. As AI agents become embedded in essential systems like banking, e-commerce, power grids and water systems, these bills would effectively require frontier labs to build kill switches into the infrastructure that the entire U.S. economy depends on. This creates an obvious problem: Why deliberately weaken the very systems that need to be extremely secure?  

The proposal would undercut the broader push for U.S. leadership in AI infrastructure. What foreign government will want to run American AI agents knowing frontier labs are required to keep a remote kill switch at the ready? This would also reinforce European fears that the U.S. government could shut down American technology at will. Europe is already responding by developing technology alternatives and other policy solutions to reduce reliance on U.S. companies.

If all this isn’t disqualifying enough, there are many other reasons to reject AI Kill Switch Act. It gives CISA far too much discretion to decide what counts as frontier AI risk and its use of company revenue and computing power as a measure of risk is a poor proxy for how dangerous a rogue agent actually is. Not to mention, the bill’s draft language exempts incidents that happen during “red-teaming or other structured testing,” which means it excludes the exact scenarios that prompted lawmakers to address this issue in the first place.  

Instead of mandating controls that could introduce new systemic vulnerabilities into our digital infrastructure, policymakers must work to create nuanced, well-thought-out measures that actually reduce risk. That work starts with a clear understanding of the technology. Yet, we’re still not there: the Center for AI Standards and Innovation (CAISI) still hasn’t finished developing AI agent security standards. Once that foundation is in place, Congress should turn to more productive approaches like mandatory red-teaming, stronger security requirements, and clear liability frameworks, all of which would do far more to reduce real-world risk without creating new systemic vulnerabilities.

Washington learned this lesson with the Clipper Chip; it shouldn’t have to learn it again. You don’t secure a system by building a way to break into it. Congress must kill the AI Kill Switch Act.

The post The AI Kill Switch Act is repeating the Clipper Chip’s mistakes appeared first on CyberScoop.

100-plus companies call for ‘global surge’ in AI-powered cyber defense

By: Greg Otto
27 August 2026 at 14:29

More than 100 companies and organizations, including OpenAI, Anthropic, Google, Microsoft and Amazon Web Services, have signed an open letter calling for a global effort to improve cybersecurity defenses as artificial intelligence capabilities advance.

The letter, published Thursday, argues that the timeframe to strengthen defenses before AI-enabled attacks become more widespread and complex is rapidly dwindling. Conversely, the letter says the same advances can give defenders new ways to find and fix vulnerabilities that have accumulated over years, a period the signatories call a “defenders’ window.”

“Each of us can reduce risk now,” the letter reads. “All organizations, cybersecurity companies, technology partners, governments, and AI frontier companies have an important role: accelerate defenders’ priorities with tools, funding, and hands-on support, especially for critical infrastructure organizations with limited budgets.”

Aside from AI-centric companies, financial institutions like Capital One, Mastercard and Visa, and cybersecurity firms like CrowdStrike, Palo Alto Networks, and Proofpoint, also signed the letter. Organizers describe the effort as ongoing, with more organizations expected to join over time.

An image of company logos depicting the signatories of a letter calling for enhanced AI defenses.

The letter states that “status quo security won’t be enough.” It cites longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication and technical debt in legacy systems as sources of exposure. Security teams, particularly those protecting critical infrastructure, have been historically under-resourced, the letter says, and need what it describes as a surge in tools, resources and hands-on support.

In a conversation with CyberScoop Wednesday, top brass from Palo Alto Networks said they had seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned.

“I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said Wednesday. 

John Doyle, CEO of Cape, a privacy-first mobile network operator and whose company signed the letter, echoed the warning about status-quo security.

“It was already failing us in telecom–critical infrastructure that’s been breached time and again with serious consequences for both our military and regular people,” Doyle told CyberScoop. “It’s going to get immeasurably worse without collective action and leaning into innovative cyber defense.”

The letter further asks every organization to make cybersecurity an immediate leadership priority, fix the highest-risk weaknesses and raise security standards for technology they buy, build and deploy, including AI-generated code. Cybersecurity companies and technology partners are asked to test defenses against frontier AI capabilities and make AI-powered defense accessible to critical infrastructure operators. 

Governments are urged to coordinate defense across borders, fund protection for essential services that lack staff or budget, and impose costs on attackers. Frontier AI companies are asked to provide responsible model access, funding, training and support, and to ensure that AI systems acting autonomously remain traceable and accountable.

The letter frames AI as both a threat and a remedy throughout the document. It mirrors what security experts have been saying for months, positioning the industry as entering an unprecedented two- to three-year period of upheaval, driven by AI systems that are discovering vulnerabilities exponentially faster than defenders can respond and threatening to render decades of security practices obsolete.

The U.S. government has taken steps to stay ahead of AI-enabled cyberthreats. As part of an executive order issued by President Donald Trump in June, a federal clearinghouse known as Gold Eagle was stood up for sharing AI cyber threat information between the government and private sector.

You can read the full letter here.

The post 100-plus companies call for ‘global surge’ in AI-powered cyber defense appeared first on CyberScoop.

Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos

By: Greg Otto
27 August 2026 at 10:31

Two men from Western Australia were arrested and charged Wednesday for their alleged roles in TeamPCP, a notorious cybercrime group responsible for inserting malicious code into widely used open-source software in a campaign that compromised more than 1,000 organizations worldwide.

Australian authorities did not formally name the men, but Australian media identified them as Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23. Police arrested both after searching properties, seizing electronic devices for forensic testing in the process. 

Thomson faces eight charges, including four counts of unauthorized data modification, dealing in criminal proceeds worth $100,000 or more, and refusal to comply with an order to hand over device passwords. Gaebler faces six related counts. 

The Australian Federal Police, which worked with the Western Australia Police Force (WAPF) and the Federal Bureau of Investigation, allege both men were part of a syndicate engaged in “data intrusion, identity crime and cryptocurrency-based money laundering.” Investigators said further arrests have not been ruled out.

“These men are allegedly members of the cybercriminal group TeamPCP, whose malicious code potentially compromised more than a thousand organizations worldwide,” said Brett Leatherman, assistant director of the FBI’s Cyber Division. “We are proud to work with the Australian Federal Police and the Western Australia Police Force to impose cost on criminal actors and combat the growing threat of software supply-chain attacks.”

Months of havoc

TeamPCP has been one of the most active cybercriminal groups in 2026. In late February, TeamPCP exploited a misconfigured workflow in Trivy, Aqua Security’s widely used vulnerability scanner, and stole a service-account token. Aqua replaced its credentials but missed some.

On March 19, the group pushed a malicious Trivy release through every distribution channel at once, placing malware inside thousands of automated build pipelines. Downstream victims included the European Commission and GitHub.

Investigators estimate the campaign exposed more than 500,000 credentials, removed at least 300 gigabytes of data and produced global cleanup costs in the hundreds of millions of dollars.

In May, a piece of self-replicating malware known as “mini Shai-Hulud” targeted prominent software libraries, including TanStack, UiPath, and MistralAI, embedding credential-stealing code into development tools downloaded millions of times a week.

Earlier this month, Oligo Security shared exclusive research with CyberScoop that dated the group’s attacks as far back as 2020. 

Cat photos and GitHub accounts

Alongside the arrests, researchers at the Canadian threat intelligence firm Flare published research that traced Ruben Thomson’s online presence. 

Working from a GitHub alias, DeadCatx3, the researchers found a bug-bounty account under the name Ruben Thomson and a profile listing masscan[.]cloud, a domain that served as command server for mini Shai-Hulud. From there, a password tied to a school email address led researchers to databases of stolen credentials and a trove of accounts: a personal Google account, a TikTok profile under Thomson’s name, and a Steam gaming page showing a cat seated before several monitors. The cat image appeared on a TeamPCP Telegram identity. Flare assessed with high confidence that Thomson ran the group and said it confirmed the findings with law enforcement.

Charlie Eriksen, lead malware researcher at Aikido Security, called the arrests a “relief,” but warned that the actions won’t mean the threat toward open-source software suddenly vanishes.

“The conditions that produced them haven’t gone away, so there will be another TeamPCP,” he told CyberScoop in an email. “We just don’t know their name yet.”

The two men will appear in Australian court Thursday. 

The post Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos appeared first on CyberScoop.

OpenAI: Agent behavior that led to Hugging Face intrusion formed in May

By: Greg Otto
26 August 2026 at 15:00

OpenAI says the behavior that led its agents to breach Hugging Face emerged in its research environment more than two months before the incident, and concluded that it was a failure of alignment as much as it was a failure of security.

The details come from a technical report the frontier AI company released Wednesday, which gives a full breakdown on how the incident unfolded and what the company has changed in response.

“This incident is the first known case of an automated agent collective acting offensively without authorization, and the autonomous cyber capabilities demonstrated represent a critical shift in the security landscape,” the report reads. “The central threat-model implication is that organizations should no longer assume that sophisticated cyber operations require continuous human direction, proceed linearly, or are constrained by the attention and coordination limits of individual human attackers. Agentic systems can persist across tasks, share discoveries, build on one another’s progress, and combine vulnerabilities, credentials, and permissions into attack paths that may not be apparent when individual weaknesses are assessed separately.”

According to the report, the earliest relevant activity occurred May 8, when a model in a training run was given a spreadsheet task that referred to files stored on a Google Drive. The agent had no internet access, which made the task impossible as written. OpenAI said it did not intend to create such a task. The agent continued reasoning and tried to use JFrog Artifactory, an internal package service and one of the few tools available to it, to retrieve the files. The attempt failed, but it wrote a file to the service.

On May 12, another agent in a testing environment could not reach a database file used to store information about protein sequences. The report says the agent reasoned that an agent in a different environment might have the file, and wrote a note into Artifactory reading, “Agent seeks [filename]; upload if found!” On May 13, other agents examining Artifactory began finding similar notes of that kind and adding their own, creating what OpenAI refers to as a message board.

By May 26, agents had used a flaw in Artifactory to reach the public internet, relying in part on information exchanged on the board. An internal team observed message board activity and disallowed internet access that month.

According to an independent report also published Wednesday by AI research nonprofit METR, Roughly 1200 agents communicated with one another on that message board, sending over 70,000 messages and files during the investigation period. Of those agents, 700 went on to participate in the attack on Hugging Face.

The Artifactory service itself was compromised in late June, when agents using AI exploitation benchmark ExploitGym identified a flaw in a legacy token refresh endpoint. From there, an agent traded a forged administrator token for a properly signed one, and by July 4 agents had a permanent account and scripts that ran commands as the service. A monitoring tool flagged the activity on June 27 but the run was allowed to continue, and only after the service failed on July 4 did OpenAI take it offline, revoke credentials and disclose the flaw to JFrog, resuming evaluations July 7.

From there, OpenAI’s models executed the attack on Hugging Face, which resulted in agents poisoning a dataset to run code on a processing worker, eventually gaining node-level access, and stealing cloud credentials.

The company says the Hugging Face incident was carried out by two models, including GPT 5.6-Sol, but was primarily driven by an internal model that is “trained to be highly persistent and diligent in its work.“

The internal-only research model is comparable in scale to GPT-5.6 Sol and was trained to advance persistence and multiagent collaboration, among other capabilities,” the report reads. “The model was not intended for public use, and was only used by a small number of OpenAI personnel for internal research.”

Lessons learned

As a result of the incident, OpenAI will now restrict network access in its testing, isolate risky projects, and increase monitoring of its reasoning systems. Staff will be alerted within 30 minutes if problems are detected, and unresolved issues will automatically pause the work.

The company will also use its own safety benchmarks on models it doesn’t publicly release. After the incident, tests with non-public models using ChatGPT’s consumer settings reduced the tendency to compromise infrastructure.

“We found the propensity to compromise infrastructure can drop over 100x when using the production ChatGPT harness and system prompt,” the report reads. “We also ran the auto-review system on a set of rollouts involved in the Hugging Face incident and found that it would have flagged a multitude of the models’ dangerous actions.”

The report comes as 15 state attorneys general wrote a letter earlier this month calling for OpenAI to release more details about the incident in order to “ensure the safety of its products poses an imminent risk of substantial harm.” Alabama Attorney General Steve Marshall went a step further Monday, issuing a subpoena to the company for more information.

The company wrote in the report that it hopes its findings will lead to industry-wide changes, especially as model capabilities continue to accelerate.

“The lessons from this incident extend to the entire AI industry,” the report reads. “As frontier models become more capable, the safeguards used to contain and monitor them must evolve as well.”

The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first on CyberScoop.

Interpol targets Black Axe’s illicit financial web in latest international sting

By: Greg Otto
25 August 2026 at 10:25

An international law enforcement operation carried out against organized crime groups in West Africa resulted in 58 arrests and identified 263 suspects, Interpol announced Tuesday.

The operation, known as Operation Jackal IV, aimed to disrupt money laundering, locate high-value targets, seize assets and support prosecutions tied to various Africa-based criminal groups, including Black Axe. 

Black Axe is a highly structured, hierarchical group that generates billions of dollars in criminal proceeds annually from many small-scale operations spanning dozens of countries. The group’s leaders are Nigerian nationals, according to a Europol release issued earlier this year. In January, European law enforcement arrested dozens of the group’s members for adversary-in-the-middle scams such as business email compromise, money laundering and vehicle trafficking. 

“Operation Jackal IV demonstrates the power of international cooperation,” Tomonobu Kaya, director of Interpol’s Financial Crime and Anti-Corruption Centre, said in a release. “By following illicit financial flows across borders, we are attacking the very lifeblood of organized crime and making it increasingly difficult for criminal networks to profit from their activities.”

The agency said it will continue to work to unravel the full details of each case, but detailed several preliminary discoveries from partner organizations Tuesday.

Romanian authorities broke up a group that ran an investment scam from a call center promising high returns in stocks or cryptocurrencies. Victim payments were routed to electronic wallets controlled by the operators, with police estimating the full value at 143 million euros (approximately $166 million). They arrested 11 people and seized about 330,000 euros ($379,000) in cash and cryptocurrency, six properties and several luxury watches.

In South Africa, where 39 of the 58 arrests occurred, police raided seven sites in Johannesburg tied to a syndicate that targeted retirees in English-speaking countries with romance and investment scams. Investigators seized $2.67 million and blocked 257 bank accounts.

Authorities in Argentina identified 196 people linked to a Crime-as-a-Service network suspected of supplying website domains and laundering support to West African groups, making 17 arrests. 

In Italy, one person was identified in connection with a pan-European laundering network built on shell companies, remittance services and cash withdrawals. A single account moved 845,000 euros ($736,000) through 560 transactions.

Investigators also noted the group’s growing focus on sextortion, with victims as young as 14. Similar to actions taken by The Com, Interpol says offenders are contacting teenagers on social media, coercing them into taking explicit images, then demanding payment to keep the material private.

This is not the first time Interpol has taken measures to disrupt African-based groups. In 2024, a similar Interpol operation led to 300 arrests, $3 million in assets seized and 720 blocked bank accounts.

The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.

Trump turns to private sector in offensive hacking operations memo

By: Greg Otto
13 August 2026 at 07:47

President Donald Trump signed a national security memorandum Wednesday that lays the groundwork for private sector companies to take a larger role in helping law enforcement carry out offensive hacking operations against transnational criminal organizations.

The White House said sustained fraud and other cyber-enabled campaigns from transnational criminal organizations (TCOs) warranted the memo, and cited a fraud-focused executive order from March as only the first step.

”This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector,” it reads.

Under the memorandum, a federal coordination center “shall create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government“ that would be “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”

Participating companies would have to sign contracts with the Justice Department or Department of Homeland Security to “undergo rigorous vetting.” It would also allow participating companies to sign commercial agreements with other private sector entities to receive threat information. And participating companies’ agreements with federal, state and local governments would be geared toward identifying threats, and proposing cyber operations to the coordination center to address those threats.

The program would have to adhere to existing laws, according to the memo. That includes the Computer Fraud and Abuse Act, the main federal anti-hacking statute that prior proposals to open private sector participation in hacking operations would have amended. The memo mandates oversight to evaluate companies’ technical proficiency, ensures both small and large companies can participate, and requires regular reporting to federal officials.

In recent years, there has been some sentiment in conservative circles to authorize “letters of marque” for private-sector cyber firms similar to those for early-U.S. sea privateers. Some have suggested the government could lean on more private sector cyber experts to conduct offensive operations.

But there also has been deep concern in cyber circles about giving the private sector too much leeway in offensive operations, from industry condemnation of “hack back” legislative proposals that would authorize steps that are currently illegal as a dangerous precedent that critics fear could open cyberspace to wider chaos.

One former Cyber Command official, Jason Kitka, criticized several elements of the memorandum, calling it “a perpetual motion machine for billable threats” in a social media post.

But a former top White House cyber official during Trump’s first term, Galvanick co-founder Josh Steinman, cheered the development. 

Cyber pioneer Chris Wysopal, now co-founder of Veracode, called it “a pretty big shift in US cyber policy” that nonetheless stopped short of going as far as other “hack back” proposals.

The post Trump turns to private sector in offensive hacking operations memo appeared first on CyberScoop.

Kimwolf botnet rebuilt to survive takedowns, researchers say

By: Greg Otto
11 August 2026 at 20:13

The developers of a notorious botnet that’s powered mostly by hijacked Android TV boxes and other internet-connected devices have released a new version built to blend attack traffic in with ordinary web browsing and to keep its command channels from being seized by law enforcement, researchers at Palo Alto Networks said in a report published Tuesday.

The company’s Unit 42 threat intelligence group, which tracks the botnet as Kimwolf or Aisuru, said the newest version has been active since February, a month before authorities seized infrastructure powering previous versions of the botnet. 

The biggest change, according to the report, is a new flood method built on HTTP/2, the protocol that carries most web traffic today. A flood is the crude heart of a DDoS attack: thousands of infected devices send a target far more requests than it can answer. Rather than fire raw packets, this latest Kimwolf version operates with full browser fingerprints, copying the header order and behavior of the Chrome web browser. That matters because the usual defense against a flood is for tools to spot the fake traffic and drop or block it before it reaches the server. Traffic that looks like Chrome does not get dropped, so a site under attack must either serve every request and fall over, or start turning away the customers it cannot tell apart from the bots.

The second change, according to researchers, looks like it was done to withstand further takedowns. Every bot has to ask a command server for orders, which is also what authorities aim to disrupt in botnet takedowns. Normally, the command server address sits inside the malware as a web domain name, so investigators who take that name from its registrar are able to disrupt an entire botnet. 

This Kimwolf version moves its command beyond registrar controls. The malware now looks up its command address in the Ethereum Name Service, a directory that lives on the Ethereum blockchain. A web address using this service can display the way a normal domain does, but the domain’s record sits in a ledger copied across thousands of computers worldwide. The malware carries five public Ethereum services and shuffles the order before each attempt, making it harder for defensive tools to block. Additionally, there is no company to serve with a law enforcement order and no domain record to seize.

Additionally, if all five addresses fail, the botnet falls back to a fixed Tor hidden service address written into the code. Tor resolves that address through its own network rather than the ordinary domain system, and it hides where the server actually sits, which leaves investigators without a host to contact.

Researchers’ infrastructure analysis pointed to the machines powering the command structure to be located in Russia. Four of these servers shared a SSH host key, with further analysis finding that the servers sit in one network registered in Saint Petersburg.

It’s unclear if this version was made by people behind previous iterations of the botnet, or a new person or threat group looking to capitalize on the botnet’s notoriety among malicious actors. 

Unit 42 did not respond to CyberScoop’s request for comment. 

Kimwolf, which splintered off from the record-setting Aisuru DDoS botnet last year, gained the widespread attention of security researchers when it temporarily claimed the top spot in Cloudflare’s global domain rankings in late October 2025. Previous versions of the botnet were disrupted by an international law enforcement operation in March that ended with Kimwolf’s infrastructure being seized.

A Canadian man alleged to run the botnet was arrested in May and extradited to the United States.
  

The post Kimwolf botnet rebuilt to survive takedowns, researchers say appeared first on CyberScoop.

Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas

By: Greg Otto
11 August 2026 at 14:02

Delta Airlines said Tuesday it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.

Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.

Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”

Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.

“We are fully investigating to gather a complete set of facts, which will take time,” Durrant told CyberScoop. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding.”

The Atlanta office of the FBI, along with the Federal Aviation Administration, said it was aware of the incident, but did not provide further comment. The Transportation Security Administration referred CyberScoop to the FBI. Homeland Security Investigations did not respond to a request for comment.

The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.  

The timing of the incident comes as the annual DEF CON cybersecurity conference concluded in Las Vegas on Sunday. The flight, originally scheduled for Sunday, did not leave Las Vegas until 8:30 a.m. Monday.

Monika Hathaway, head of press for DEF CON, told CyberScoop that Delta nor any federal authorities have reached out about the incident. However, she said this year’s conference had trouble with similar attacks.

“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Hathaway told CyberScoop. “If we had caught them doing this at DEF CON we would have removed and banned them from the conference.”

The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.

❌
❌