❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

16 September 2026 at 10:48

The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint statement from the agencies Wednesday.

The “joint offshore security boardings” of the two commercial ships in the Gulf of Mexico on Aug. 21 and Aug. 24 “were designed to ensure integrity of the vessel’s operational and information technology systems following indications that the networks of both vessels were compromised,” according to the joint statement.

“Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts,” the statement reads. “The Coast Guard is actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption.”

The vessels were reportedly tankers carrying oil and natural gas, and the first got hacked in the Strait of Gibraltar and lost communication for over 30 hours. Authorities were said to be  investigating whether Iran, or perhaps another group seeking to exploit the conflict between Iran and the United States, was behind the attacks.

Coast Guard cyber teams have been investigating “dark fleets” carrying sanctioned oil from Iran and Russia, which rely on digital masking to hide their operations and carry enhanced cyber risks, The Wall Street Journal reported in June.

Then-President Joe Biden signed an executive order in 2024 giving the Coast Guard additional authorities to respond to cybersecurity incidents, citing the risks that a maritime cyber incident could cause “cascading” harm to the global supply chain.

The Aug. 21 boarding party included Coast Guard law enforcement personnel, Coast Guard Cyber Protection Team members, a vessel inspector and FBI Cyber Action Team operators, who boarded “to conduct a comprehensive cyber security boarding and investigation,” according to the agencies’ joint statement. A similar team made up the Aug. 24 boarding party.

“The captain, crew, and shore-side corporate staff were critical partners in helping to ensure the threats were mitigated,” the statement reads.

Top Trump administration cyber officials have refused to answer questions from reporters recently about Iranian cyberattacks during the Middle East conflict. Trump himself has rejected the idea that Iran was behind a recent spate of attacks on U.S. water facilities.

The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop.

Supreme Court denies Trump request to allow USPS mail ballot changes

By: djohnson
14 September 2026 at 22:15

The Supreme Court has rejected a petition by the Trump administration to implement changes to the way the U.S. Postal Service handles mail-in ballots for the upcoming 2026 midterm elections, calling it “arbitrary and capricious.”

The 7-2 decision was handed down Monday with little explanation by the court. Writing for the majority, Justice Kentaji Brown Jackson said the administration “is unlikely to succeed on the merits of its challenge to the District Court’s preliminary injunction” and had failed to articulate a valid reason for seeking emergency relief from the court.

However, in a concurring statement, Justice Brett Kavanaugh said he believed there was “a fair prospect” that the final USPS final regulation would be within their legal authority and appeared to cite unreasonably short timelines imposed on states and his primary reason for denying the stay.

“But applying the rule in the 2026 elections would be arbitrary and capricious and in violation of the Administrative Procedures Act because state and local election officials do not have sufficient time to reasonably implement the rule before the elections,” wrote Kavanaugh.

The executive order would have tasked the USPS with verifying  voter citizenship and the validating ballot materials. The order would have created a barcode tracking system for mail ballot envelopes and “State Citizenship Lists” compiled by the Department of Homeland Security.

The order was quickly challenged by states and voting rights organizations, who argued the executive branch had no constitutional authority to dictate how they maintained their voter rolls.

The White House has justified the order by claiming the federal government has “an unavoidable duty” under Article II of the Constitution to maintain confidence in election outcomes by preventing violations of criminal law, including noncitizen voting.

Lower courts disagreed, blocking the executive order from being put in place before November. The petition to the Supreme Court represented the administration’s best and final hope for judicial relief.

As the administration fought the matter in courts, it moved ahead finalizing the USPS rule. A whistleblower complaint alleged that a “rushed” effort by the White House and U.S. Postal Service to install three new restrictive IT systems meant to verify citizenship that could potentially deny thousands of mail-in ballots if the federal government disagrees with states on a voter or ballot’s eligibility.

While Jackson and Kavanaugh’s rationale took up less than half a page, a dissenting opinion written by Justice Samuel Alito and signed by Justice Clarence Thomas was more than 7 pages long.

Alito wrote that he would have granted the Trump administration their request for a stay, allowing the order to be implemented in time for the 2026 elections. He said states and organizations suing the government lacked standing, and dismissed their concerns that implementing the USPS order ahead of the 2026 elections would thwart their ability to educate voters about mail-in voting, calling them “abstract social interests.”

Ahead of the decision, David Becker, executive director of the nonprofit Center for Election Integrity and Research, told reporters that he doubted members of the Supreme Court majority “want to own the chaos that would ensure” as the USPS, states and voters attempt to navigate changes put in place just months before elections and after many states have begun sending out ballots that do not comply with the proposed rules.

He also said that it would be in line with previous Supreme Court decisions that have recognized state supremacy when it comes to specific election administration authorities, like where and how their citizens vote.

“When they consider issues related to the administration of elections, the casting and counting of ballots, they have sided with the states every time,” said Becker.

The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop.

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

11 September 2026 at 17:26

Beginning next month, if a flight is canceled or delayed because of a cyberattack, feds will give airlines clearance not to hand out meal vouchers or hotels.

The change is the result of a broader rule the Transportation Department published last week that establishes a new “cause of delay” category for tracking information, but that also reduces air carrier responsibilities to customers for 10 kinds of events. Among them: “cybersecurity attacks (provided that the air carrier is in compliance with applicable cybersecurity regulations).”

The 10 events, including those cyberattacks, are deemed “not controllable,” meaning that “carriers are no longer obligated under [customer service] plans to provide amenities or compensation when disruptions arise from these specific causes,” as Sophie Hayashi, counsel at Crowell & Moring in the transportation group, wrote in a client alert.

Those airline-authored customer service plans aren’t legally binding, although DOT has maintained it will hold airlines “accountable” for their pledges.

One airline consumer advocacy organization, FlyersRights, was skeptical of the change, saying it came without giving the public a chance to comment and that it would be monitoring the impact on airline customers and tracking any reduction in amenities. 

Specifically, “cybersecurity is an airline responsibility, so if a flight is delayed or cancelled it should be clear that the delay was not due to carrier neglect, as cyberattacks are constant,” Paul Hudson, president of the group, told CyberScoop. “We have previously urged stress tests for airline computer systems that are going down often.”

Another group, the National Consumers League, had a more mixed view about the rule’s effects on flyers. On one hand, it could be good for them, said John Breyault, vice president of public policy for the group.

‘What we appreciated about this being put into a rule was that it gave consumers certainty that regardless of which airline they were flying, they would know that they have certain rights, and they weren’t beholden to the whims of the airlines who may or may not decide to provide them with a hotel if there’s a delay or cancelation,” he said.

On the other, though, “it’s clear to us that the DOT seems inclined to try and make the rules a little less onerous for the for the airline industry,” Breyault said, and in particular was worried about how airlines could potentially abuse the ambiguity related to one of the 10 events, “unscheduled maintenance,” to find a way to avoid compensating consumers.

The provision might still protect consumers because of its condition on compliance with applicable cybersecurity regulations, Breyault said. Carriers who can’t demonstrate compliance will be subject to customer and other requirements, Hayashi said.

“The final rule’s language regarding applicable cybersecurity regulations is notably broad,” said Kate Growley, partner at Crowell & Moring. “This may have been deliberate to account for the unpredictable nature of cybersecurity attacks. Different regulations may apply depending on the exact circumstances of the attack, such as what information or operational capabilities were affected.”

There’s no formal accounting of how often cyberattacks have caused delays or cancellations that then prompted airlines to provide meal vouchers or hotels. Hackers have targeted airlines and flights before, such as Scattered Spider’s attacks last summer.

Cyberattacks have caused flying delays and cancellations, although sometimes those attacks have been aimed at third parties, such as in last year’s attack on Collins Aerospace led to delays in Europe. Attackers also have targeted other elements of the aviation sector. The 2024 IT outage related to the cybersecurity company CrowdStrike that grounded flights wasn’t a cyberattack, but did lead to airlines providing some compensation to travelers; the Transportation Department determined that incident was within airlines’ control.

The Biden administration notably imposed cybersecurity regulations on airports, aircraft owners and aircraft operators in 2023 due to “persistent cybersecurity threats” in the sector. 

The newly-published Department of Transportation (DOT) rule stems from a Federal Aviation Administration authorization law that President Joe Biden signed in 2024. 

“Congress explicitly directed DOT in the FAA Reauthorization Act of 2024 to make these changes,” a Department of Transportation spokesperson said. “These 10 specific types of flight disruptions will now … be tracked in a brand-new reporting category to ensure government delay data accurately reflects what airlines can and cannot control.”

The Aviation Information Sharing Analysis Center said it appreciated the elements of the rule related to reporting incidents.

“The Aviation ISAC supports efforts to simplify and harmonize cybersecurity reporting across numerous government agencies,” said Jeff Troy, president and CEO of the organization. “This rule is a move in the right direction.”

Hayashi told CyberScoop the rule change looks to be positive for both airlines — because of the clarity it provides them about disruptions not under their control — and consumers.

“This actually is beneficial for everyone, and particularly consumers, because it makes it clear if you’re looking at airlines delay and cancellation rates, this is going to give you the most accurate picture of carrier delays,” she said.

The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first on CyberScoop.

Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots

By: djohnson
1 September 2026 at 09:58

A newly released whistleblower complaint reveals details about the “rushed” effort by the Trump administration and U.S. Postal Service to install three new restrictive IT systems that would potentially deny thousands of mail-in ballots, if the federal government disagrees on their eligibility.

According to the complaint, written by attorneys at the nonprofit Whistleblower Aid and released by Sen. Richard Blumenthal, D-Conn., the individual is a federal employee with “direct knowledge of potentially catastrophic problems” related to USPS’ handling of mail-in ballots for the upcoming 2026 midterm elections.

The person claims that USPS is deploying entirely “new and untested” IT systems, including a new Federal Ballot Mail Portal that would potentially give USPS more control over whether and when voters receive federal mail ballots.

The disclosure describes the portal and other systems as “new IT systems and corresponding protocols [that] will govern the delivery of ballots to voters as soon as the 2026 mid-term federal elections and beyond.” It calls the development process “secretive, rushed, chaotic and fundamentally flawed,” and part of a larger effort by agency leaders to rush implementation of the system ahead of the 2026 elections.

That rush has forced USPS to forgo much of the pre-release testing of those systems to ensure they work as intended and can safely interoperate with other federal systems. As a result, the whistleblower says the portal is so restrictive it can potentially reject large batches of mail-in ballots based on a single identified ballot error.

According to the letter, there are three primary new IT systems USPS is rolling out this election cycle. The Federal Ballot Mail Portal stores both voter names and newly placed ballot barcodes, while a new verification system will compare ballot batch manifests with information in the portal. A third system is described as a new physical barcode sampling verification standard “with a zero percent failure rate.”

“The Whistleblower paints a dire picture of a slapdash software development process as the USPS attempted to create this complex IT system, with multiple points of ballot review, in a matter of weeks,” the letter said. “The very manner in which the project is being developed deviates dangerously from even the most basic software development best practices.”

In all three cases, the onus is explicitly placed on state election officials to resolve discrepancies between federal and state systems.

For example, when the federal government and election officials have different data on batch manifests, which can include tens of thousands of ballots, “election officials will be responsible for resolving any errors purportedly identified in the scan, and for resubmitting the batch manifest – USPS will refuse to accept the ballot batch until the errors are resolved.”

A similarly restrictive approach is described for verifying ballot bar codes.

“As presently designed, if even one bar code on one single ballot in a bulk-mailing of 10,000 ballots fails to properly scan during the verification process, the entire batch is rejected and sent back to the state – effectively stopping the ballots from being mailed to voters,” the letter stated.

But the whistleblower said those kinds of small errors are likely to happen in any process that relies on scanning barcodes. In this case, the rushed development and specific location of the barcodes on federal mail ballots means the portal “will almost certainly have significant operating problems.”

The letter says the whistleblower is aware of concerns “among those whose job it is to build this software” that the project is not subject to standard testing and debugging work, and that the systems were escalated to other testing environments before they were even finished. It also claims that the systems’ development was siloed across different teams, with no time to test different software components individually or the system as a whole.

The whistleblower also claims that the USPS rule changes,  which have been subject to multiple court injunctions, have continued throughout, in violation of federal court orders. Despite those orders, the agency is believed to have started work on the IT systems in June 2026.

In response, Democrats on the House Committee on Oversight and Reform led by Robert Garcia, D-Calif., wrote to Postmaster General David Steiner saying the disclosures indicate the new IT systems are “faulty” and demanding USPS “immediately cease implementation of this irresponsible and illegal scheme.”

“To be clear, any actions taken by the Postal Service that prevent any registered voter, let alone millions, from voting are unacceptable, a violation of Americans’ voting rights, and likely illegal,” the members wrote.

David Becker, executive director of the Center for Election Innovation and Research, said the disclosures could potentially lead to new lawsuits against USPS and the federal government.

“This seems to confirm that the USPS is totally unprepared and unqualified to take on this vast responsibility interjecting itself into state’s mail voting processes,” said Becker on Bluesky. “And could incur liability if USPS truly plans to reject thousands of ballots if there’s even one error.”

The post Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots appeared first on CyberScoop.

100-plus companies call for ‘global surge’ in AI-powered cyber defense

By: Greg Otto
27 August 2026 at 14:29

More than 100 companies and organizations, including OpenAI, Anthropic, Google, Microsoft and Amazon Web Services, have signed an open letter calling for a global effort to improve cybersecurity defenses as artificial intelligence capabilities advance.

The letter, published Thursday, argues that the timeframe to strengthen defenses before AI-enabled attacks become more widespread and complex is rapidly dwindling. Conversely, the letter says the same advances can give defenders new ways to find and fix vulnerabilities that have accumulated over years, a period the signatories call a “defenders’ window.”

“Each of us can reduce risk now,” the letter reads. “All organizations, cybersecurity companies, technology partners, governments, and AI frontier companies have an important role: accelerate defenders’ priorities with tools, funding, and hands-on support, especially for critical infrastructure organizations with limited budgets.”

Aside from AI-centric companies, financial institutions like Capital One, Mastercard and Visa, and cybersecurity firms like CrowdStrike, Palo Alto Networks, and Proofpoint, also signed the letter. Organizers describe the effort as ongoing, with more organizations expected to join over time.

An image of company logos depicting the signatories of a letter calling for enhanced AI defenses.

The letter states that “status quo security won’t be enough.” It cites longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication and technical debt in legacy systems as sources of exposure. Security teams, particularly those protecting critical infrastructure, have been historically under-resourced, the letter says, and need what it describes as a surge in tools, resources and hands-on support.

In a conversation with CyberScoop Wednesday, top brass from Palo Alto Networks said they had seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned.

“I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said Wednesday. 

John Doyle, CEO of Cape, a privacy-first mobile network operator and whose company signed the letter, echoed the warning about status-quo security.

“It was already failing us in telecom–critical infrastructure that’s been breached time and again with serious consequences for both our military and regular people,” Doyle told CyberScoop. “It’s going to get immeasurably worse without collective action and leaning into innovative cyber defense.”

The letter further asks every organization to make cybersecurity an immediate leadership priority, fix the highest-risk weaknesses and raise security standards for technology they buy, build and deploy, including AI-generated code. Cybersecurity companies and technology partners are asked to test defenses against frontier AI capabilities and make AI-powered defense accessible to critical infrastructure operators. 

Governments are urged to coordinate defense across borders, fund protection for essential services that lack staff or budget, and impose costs on attackers. Frontier AI companies are asked to provide responsible model access, funding, training and support, and to ensure that AI systems acting autonomously remain traceable and accountable.

The letter frames AI as both a threat and a remedy throughout the document. It mirrors what security experts have been saying for months, positioning the industry as entering an unprecedented two- to three-year period of upheaval, driven by AI systems that are discovering vulnerabilities exponentially faster than defenders can respond and threatening to render decades of security practices obsolete.

The U.S. government has taken steps to stay ahead of AI-enabled cyberthreats. As part of an executive order issued by President Donald Trump in June, a federal clearinghouse known as Gold Eagle was stood up for sharing AI cyber threat information between the government and private sector.

You can read the full letter here.

The post 100-plus companies call for ‘global surge’ in AI-powered cyber defense appeared first on CyberScoop.

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

26 August 2026 at 17:38

Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.

The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.

“To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.

The executive order is a response to fears of Chinese-made equipment housed within U.S. energy infrastructure, and a continuation of other measures from the Trump administration to shun that equipment.

The order, “Declaring a National Energy Emergency to Secure the United States Bulk-Power System,” cites “malicious cyber activities” as one impetus.

“The minimal restrictions on acquisition or operation in the United States of foreign-produced bulk-power system electric equipment augment the ability of some foreign entities to create and exploit vulnerabilities in such equipment; for instance, such equipment might have digital backdoors built into their systems that allow a foreign country to access that equipment remotely,” it states.

China supplies 85% of solar supply chain production capacity, according to the International Atomic Energy Agency, and China is a major player in the power transformer manufacturing business.

In 2024, then-FBI Director Christopehr Wray told Congress that hackers prepositioning themselves in small office and home routers had the electricity grid as one of their targets should China and the United States go to war.

Near the end of Trump’s first term he also signed an executive order seeking to limit the purchase of foreign-made bulk-power equipment. The Biden administration suspended that order, citing the need to review its scope, and revoked and replaced a related Energy Department order. Some utilities found compliance with the 2020 executive order difficult.

For the new order, the Energy Department has 120 days to develop rules to implement the order, in consultation with other key departments.

The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.

Election official says Tina Peters would be consultant, won’t have access to election systems

By: djohnson
26 August 2026 at 09:30

The top election official for Shasta County, Calif. said he has offered convicted felon and former Mesa County, Colo. clerk Tina Peters a position as a consultant to help with the 2026 elections, but that she hasn’t accepted the position yet.  

Earlier this month, Shasta County registrar Clint Curtis told local news outlets that he intended to hire Peters as assistant registrar of voters to help with the upcoming 2026 elections, months after she was released from prison in Colorado.

In an interview with CyberScoop this week, Curtis said he was looking to hire Peters as a consultant, citing the length of time involved in hiring her as a full-time employee and the need for immediate help running the upcoming midterm elections.

Curtis said that he initially believed Peters had accepted the position, only to later hear from her that she needed to consult her legal team after her prison sentence was commuted in June.

“She’s got to check it all out, make sure it’s okay, make sure there’s not any roadblocks in there that we don’t know about [or are] illegal, so you got to walk through the whole mess,” said Curtis.

A Colorado Department of Corrections official told CyberScoop that as part of her parole conditions, Peters must be employed and live in Colorado. Peters can request a transfer to another state, but she must first receive permission from both states and go through a formal review process.

According to Curtis, hiring Peters as a consultant means she would not have local access to county email or election systems. Peters’ past conviction “doesn’t matter” because her access to county IT would be limited.

“If she’s on staff she’d have logins to the network, logins in the system, she’d basically have full access,” Curtis said in a phone interview. “But consultants don’t have any of that, nor should they, right?”

Consultants “are basically there to actually watch other people do it and make sure they do it right rather than do it themselves,” he added.

At the same time, when asked what responsibilities Peters would have, Curtis described an expansive role, with Peters helping him oversee the registrar’s office and direct his full-time staff of about 12.

Asked what drew him to Peters, Curtis said “well, she’s out [of prison] and I have this position become available [and] I need somebody that can actually supervise and knows something about elections.”

In 2024, Peters was convicted of seven felony crimes related to the theft of voting machine software from Mesa County election facilities, in a failed attempt to prove that the machines had been involved in election fraud during the 2020 election.

She served less than two years of that sentence, as legal appeals, relentless pressure from the Trump administration and eventually a commutation by Colorado Governor Jared Polis saw her released from prison in June.

Curtis said he did not reach out to any Mesa County officials before offering Peters the job, but did cite conversations with her that impressed him and his confidence that he would remain in control of the county’s elections.

“I talked to her and basically, she’s very even tempered, she’s not wild and crazy which is good,” said Curtis. “And so basically I’d still be in charge so it wouldn’t really be a problem…there’s no way she would get out of bounds on me.”

A request to Mesa County’s press office seeking comment was not returned. At Peters’ sentencing hearing in 2024, multiple Mesa County officials testified about the negative impact her crimes and behavior had on the county’s elections, finances and reputation.

When reached for comment, a representative for Peter Ticktin, Peters’ lawyer, provided CyberScoop with a statement from last week regarding Peters’ intentions.

“Tina Peters is giving consideration to helping in the efforts in Shasta County as there most definitely has been monkey business in the way the election was handled,” Ticktin said. “Tina is one of the key voices leading the effort to get the invasive machines out of our election process.”

Earlier this month, Curtis was censured by the Shasta County Board of Supervisors following investigations into  allegations of verbal abuse and threatening language to staff.

Curtis, who was appointed county registrar in 2025, also made a number of claims about what he called suspicious mail-in ballots used during the 2024 election. He claimed the ballots were different sizes and looked, felt and “smelled” different from normal mail-in ballots.

Curtis told CyberScoop he did not follow up with the county’s ballot manufacturer to ask if there was a credible explanation, saying he lacked investigative authority to do so. He also could not answer how many instances of voter fraud his office had confirmed. 

A day after speaking with CyberScoop, the Shasta County Board of Supervisors said Curtis’ claims were “frivolous” and that they “welcomed” investigations by state and federal authorities.

“Mr. Curtis was hired to enhance transparency, strengthen election integrity and restore trust. While some progress has been achieved, including the promotion of meaningful observation within the Elections Office, Mr. Curtis has failed significantly in other core responsibilities, undermining the very principles he was appointed to uphold.”

The press office for California Secretary of State Shirley Weber’s told CyberScoop that irrespective of whom a county employs or contracts with, they must comply with California law, security and confidentiality requirements, and “maintain the integrity of our state’s elections and election processes.”  

Weber also sharply questioned Peters’ involvement in California elections.

“As Secretary Weber has stated, ‘The mere thought of letting someone near any part of California’s elections when that person was convicted of serious election-related crimes while serving as an election official, is simply outrageous,’” Weber’s office wrote in an email. “Our office is monitoring the situation and, as always, will act within our authority and work closely with law enforcement officials to ensure that all elections in our state remain transparent, safe, and fair for all eligible voters.”

Curtis expressed frustration to CyberScoop at the delays, saying he needed immediate help and expressing concern that Peters’ legal roadblocks may make it harder to hire her at all.

“You know, if they stall sufficiently enough, then she won’t be able to get any help to me,” said Curtis. “So I need her fairly quickly. We start early voting in…30 days, something like that. So we need it quickly, we need to get her in here, tell her what to do, set people up and get it ready to go. Otherwise, I have to do it all, and that’s going to be a pain.”

The post Election official says Tina Peters would be consultant, won’t have access to election systems appeared first on CyberScoop.

SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules

By: djohnson
24 August 2026 at 18:47

The Supreme Court dismissed one of two lawsuits blocking the Trump administration from implementing changes to U.S. Postal Service regulations regarding mail-in ballots, saying that states lacked standing because they could not prove that the regulations would cause “concrete harm.”

 California and 23 other states sued the federal government after a White House executive order directed USPS to begin creating “State Citizenship Lists” for each state, consisting of voters who, according to federal data, are eligible to receive mail-in ballots. 

The order states that the lists will be updated and transmitted to states 60 days before the election, and states that “An individual’s identification on the State Citizenship List does not indicate that the individual has been properly registered to vote in the State” and that “there may be State laws, not reflected in the State Citizenship List, that preclude voter registration, or the individual may choose not to be registered.”

That provision was thrown out by two federal courts, who found them unconstitutional and likely to result in the federal government intruding on the constitutional rights of states to run their elections.

But the Supreme Court’s conservative majority voted 6-3 to dismiss the lawsuit, saying that states have no standing to sue because “The Order is an internal directive from the President to his subordinates mandating that certain agencies pursue certain policies” and the order “neither requires nor forbids anything of anyone outside the executive branch.”

Because the section of the order is prefaced to say that the Secretary of Homeland Security will transmit the lists “to the extent feasible and consistent with applicable law,” the majority said the claims of harm by states are, at this point, entirely speculative.

 “The true ‘source of any injury’ to the States would be the downstream action that the Secretary ‘might take in the future’ to implement” the USPS sections,” the court wrote. “Emphasis on might.” 

At the same time, another section directs the Department of Justice to prioritize investigation and prosecution of state and local election officials who “knowingly” allow instances of non-citizen voting.  

The majority argued the DOJ directive was internal guidance  that neither regulated states’ voter registration nor limited states’ authority to set their own election rules. Since it only prioritized enforcement of existing laws, the court said it did “nothing” to states.

“The States lack standing to challenge for much the same reason: It does nothing to them,” the majority wrote. “This provision directs the Attorney General to ‘prioritize’ the investigation and prosecution of those who violate existing federal laws by issuing ballots to ineligible voters.”

The USPS regulations remain blocked under a separate injunction issued by federal court in Massachusetts, but the ruling demonstrates there are major differences between the Supreme Court majority and lower federal courts on the Trump administration’s years-long effort to assert more federal control over elections. On Friday, USPS moved to finalize the new regulations despite the nationwide injunction.

The three remaining liberal justices – Elena Kagan, Sonia Sotomayor and Kentaji Brown Jackson – laid out their opposition to the ruling across two dissenting opinions. In one, Sotomayor and Kagan wrote that the majority’s decision “merely postpones adjudication” and does not address or rule in favor of the administration on many substantive constitutional questions.

Both would have granted relief to the states, writing that “a commonsense reading of the executive order, corroborated by the government’s own representations, make clear that the respondent states face a sufficiently concrete and imminent injury.”

Sotomayor also expressed incredulity at the majority’s view that the order’s sections on USPS state citizenship lists and directing DOJ to prosecute election officials were unrelated or nonthreatening.

“To pretend that the lists assembled [in one section] bear no relation to the prosecutions directed by [the second section] is to ignore the structure of the Executive Order and the Government’s words alike,” she wrote. “As this Court has long recognized, ‘[p]eople do not lightly disregard public officers’ thinly veiled threats to institute criminal proceedings against them if they do not come around.”

Justice Jackson, in her own dissent, was even blunter.

“The District Court held that the President’s Order is unlawful, the Government does not defend the lawfulness of the Order before this Court, and no judge or Justice has held (or holds today) that the Order comports with the Constitution,” wrote Jackson. “Still, the Court sees fit to grant the Government equitable relief to proceed with implementing the challenged Order on the grounds that, because the Government had not yet issued a final rule at the time the complaint was filed, the Plaintiff States lacked a concrete injury for Article III purposes.”

The post SCOTUS tosses one of two injunctions against Trump USPS mail-in ballot rules appeared first on CyberScoop.

Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’

24 August 2026 at 15:06

As part of its “economic D-Day” against Iran, the Treasury Department designated four Iranians for sanctions Monday stemming from their alleged role in hacking critical infrastructure targets and waging cybertheft against the United States.

It’s the second time in as many weeks that the Trump administration has taken aim at the same group of alleged hackers, following on an indictment recently unsealed against cybercriminals that federal law enforcement authorities say are affiliated with the Tehran-based Mabna Institute.

A Treasury Department release points the finger at three people — Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, Mohammad Reza Kadkhoda’i and Mojtaba Ghal’eh-Kuhi — as specifically conducting the hacks.

“Since at least late 2023, these three individuals have successfully compromised and exfiltrated data from multiple U.S. companies in various critical infrastructure sectors, including energy companies, defense contractors, healthcare institutions, information technology companies, and financial institutions,” the release states.

A fourth individual included in Monday’s sanctions, Mojtaba Ghal’eh-Kuhi, is listed as one of the leaders of the gang carrying out the Ministry of Intelligence and Security (MOIS)-directed attacks. Another listed leader, Behzad Mesri, first faced sanctions in 2018, as part of another round of sanctions focused on the Mabna Institute.

Finally, the Treasury Department designated one additional person Monday over related activity, Arman Kahzadian, for his alleged role in receiving or using business information stolen via cyber-enabled means.

The department said the Iranian hackers sometimes turn their gaze to domestic targets.

“The members of this group are also heavily motivated by personal enrichment and greed, leading some members to prioritize their own profits over operations that benefit the MOIS,” it said. “This has driven some of the group to target Iranian companies.“

Hackers that the U.S. government has identified as Iranian have been behind a spate of attacks on U.S. water facilities, despite denials from President Donald Trump himself about Iranian culpability.  The Treasury Department did not immediately respond to a request for comment Monday about whether the sanctions designees were involved in those attacks, nor has the National Security Agency responded to requests for comment on whether Iran was responsible for attacks at the center of an alert about attacks on water facilities.

Treasury Secretary Scott Bessent announced a fuller list of sanctions Monday as the war with Iran nears its five-month anniversary with no end in apparent sight.

“In the Second World War, D-Day marked the historic beginning of a campaign with our allies to target and drive the enemy from its positions, including those in third countries,” he said. “Today, in that same spirit, we are launching an economic onslaught against Iran’s financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone.”

There are questions about whether the sanctions themselves are likely to change any behavior, particularly based on how they will be enforced. Iran has vowed “consequences” for the United States.

As part of the sanctions announced Monday, according to the department, “Treasury is expanding the categories of Iran-related conduct that may be subject to secondary sanctions in the future, making it easier to take action against those facilitating the regime. Treasury has issued determinations against five critical sectors –– digital assets, technology, gold, aviation, and shipping––  that the Iranian regime uses to try to prop up its failing economy.”

The post Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’ appeared first on CyberScoop.

Postal Service moves to finalize mail ballot regs before SCOTUS ruling

By: djohnson
22 August 2026 at 13:01

In a late Friday night posting to the Federal Register, the U.S. Postal Service said it is finalizing new regulations that would give the federal government potentially vast powers to control mail-in ballots for voters.

The changes are part of an executive order signed by President Donald Trump in March, which directed USPS to develop lists of residents “eligible” for mail-in voting — standards that would be defined by the federal government.

The U.S. Constitution vests states and Congress with the power to regulate elections, and the USPS rules have already been struck down by multiple lower courts. But as the White House appeals to the Supreme Court to reverse those decisions, it is still moving ahead in finalizing the regulations, though USPS says it will not move to implement them until after the Supreme Court rules.

But USPS said it must begin moving forward now in order to ensure the changes are in place by the mid-term elections.

“To ensure the faithful execution of federal law in connection with federal elections, this rule has an immediate effective date,” USPS wrote. “Delaying the effective date would jeopardize implementation of this rule in time for the 2026 general election, which will be held on November 3, 2026.”

According to the notice, USPS has received an astonishing 200,000 comments from the public in response to the proposed rule. It doesn’t provide a breakdown of how many comments were in support or opposition.

By the agency’s own admission, the vast majority of supportive comments appear to argue that the rules would help with the perception among voters that fraud is a “significant problem.”  Phrases like “strengthens confidence” and “reduce uncertainty” are peppered throughout the descriptions.

But no credible evidence of coordinated mail-in voter fraud is presented, and Trump and his allies have been the primary force in American politics spreading the perception that voter fraud by noncitizens, dead people and Democrats is rampant. Courts, post-election audits and independent experts have repeatedly debunked these arguments.

“Whether or not voter fraud is common or uncommon, the Postal Service has the legal authority to take the measures in this rule to facilitate enforcement of federal law, reduce the risk of fraud, and help protect the integrity of federal elections,” the notice stated.

According to the notice, the comments in opposition pointed out that two courts have already blocked the White House’s USPS rules, finding them unconstitutional. Others expressed concerns that the Postal Service “would refuse to accept certain ballots for federal elections that states tender without satisfying the data-entry obligations that the rule would impose,” echoing concerns that election experts have conveyed to CyberScoop in interviews.

The notice also dismisses comments “influenced by partisan political speculation,” that include “conjecture about the underlying intent” of the order, its impact on voter turnout and elections.

“Such remarks are speculative and exceed the scope of this proceeding,” USPS wrote in its notice. “In any event … this rule does not—nor is it intended to—facilitate any form of voter suppression, affect election outcomes, or target particular demographics, districts, or states.”

Last week the U.S. District Court of Massachusetts, which ruled against the administration’s USPS order in an ongoing lawsuit brought by states and voter groups, took the unusual step of issuing a second, separate injunction against the USPS rules. It’s not clear whether the Supreme Court will address both injunctions in the same ruling or separately ahead of election day in November.

“The court has already answered and will again resolve the question clearly and affirmatively,” Judge Indira Talwani wrote when issuing the second injunction. “The executive branch has no authority to regulate elections.”

Some voting groups quickly moved to condemn the Friday night posting, saying it will confuse voters about a state-led voting process that is, as of today, still the law of the land.

“For the 2026 election, voters can continue to rely on the voting rules established by their state unless and until a court orders otherwise,” said Michael McNulty, senior policy director at the nonprofit Issue One. “Yet, because the Trump administration continues its attempts to undermine trust in an effort to centralize control of elections, we all must remain vigilant and continue to build trust in our election system.”

The post Postal Service moves to finalize mail ballot regs before SCOTUS ruling appeared first on CyberScoop.

A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.

13 August 2026 at 18:19

A newly-signed presidential memorandum enlisting private sector companies in federal law enforcement hacking operations against criminal organizations could present a number of legal, practical and moral pitfalls, cyber experts told CyberScoop a day after the order was released.

While some have celebrated the memo as an overdue maneuver to more aggressively combat cybercriminals, others view it as risky at best and potentially destructive at worst. Supporters, critics and everyone in between also said that how it plays out could be decided in the 60-day timeframe the memo sets to establish the program.

But ultimately, “it’s a massive shift in the cyber policy community,” said Michael Garcia, a former top official at the Cybersecurity and Infrastructure Agency. “This is a philosophical shift.”

The Concerns

On the most critical end of the spectrum is security consultant Davi Ottenheimer, who has been a proponent of concepts like “hack back” or “active defense” that envision a bigger role for the private sector. But he was unsparing in his criticism of the Trump memo. 

“It’s an embarrassment to America,” he told CyberScoop. “It’s like seeing somebody strapped onto a horse backwards, looking at the wrong end of a rifle.”

The Trump memo’s approach has been likened to the “letters of marque” concept used in early U.S. history, when it authorized sea privateers to attack and capture enemy ships and goods on behalf of the country. But Ottenheimer, founder of Ottenheimer GmbH, noted that the practice fell out of favor for good reason in the 1800s because of the violence it unleashed and how it contributed to mercenarism.

Additionally, the memo raises a number of targeting-related issues, he said. Ottenheimer is concerned about Trump’s intentions. The memo specifically pertains to the use of participating companies against transnational criminal organizations.

“Left-wing opposition, liberals, anti-fascists —they’re all criminals to him,” Ottenheimer said. “So to authorize attacking criminals under this means private organizations can go hack people that he designates as criminals.”

Under the memo, the program must establish legal and constitutional procedures for the prior approval of the targeting of U.S. citizens, as well as develop procedures to halt any unintentional targeting of U.S. people or systems. 

However, the limitation on targeting criminals only creates a perverse incentive for attackers and a peculiar defense for anyone who’s attacked, Ottenheimer said.

He envisioned a scenario for a company participating in the program where “you’re hacking [a target], and they go, ‘Hey, we’re the state.’ And then [private companies] are like, ‘Oh, I can’t hack you anymore.’ Boom. They decided when you can and can’t hack.”

Furthermore, “you incentivize people to know as little as possible so [operations] can be authorized,” he said.

The memo raises ethical concerns for him as well: “You can’t attack somebody and then say it’s your fault that you didn’t notify them you didn’t want to be attacked.”

“There’s no notice for you being designated. There’s no prevention of you being designated. There’s no way for you to know you’re being designated,” Ottenheimer said. “That’s like a person sitting down next to you and smoking a cigarette and blowing smoke in your face and saying, ‘Hey, you got to say you don’t like cancer if you don’t want me to do this to you right now.’”

Garcia, now vice president of the cybersecurity practice at Monument Advocacy, said he supports some of the ideas of the memo, but worries about how it will be executed.

“It comes down to attribution, and if you make a risky bet on who we’re attributing [attacks] to, that’s where things can get dicey,” Garcia told CyberScoop.

There could be pressure to attribute faster, which could perhaps lead to lower certainty about who’s being targeted, and that in turn could lead to a private sector company accidentally attacking a foreign government, he said.

That raises legal questions: “It’s in the Constitution —the federal government has the ability to wage war. And there are laws by which private citizens can’t take up arms,” Garcia said.

He wanted the memo to include court oversight of the program, similar to what’s been required for private sector takedown operations. .

Garcia also isn’t sure whether there will be a big enough pool of companies willing to jump into offensive cyber operations.

“From the lawyer perspective, it’s, ‘Are you okay with engaging in this kind of legal risk? And who knows what protections the government will provide?’” he said. “I’d be very curious to see what the foreign governments’ reactions are — ‘We’re going to cut ties with any participating company that engages in this.’”

Errata Security CEO Robert Graham wrote that under the program, companies “are not willy-nilly hacking back,” given the federal supervision elements. “Though, I wonder if it doesn’t eventually morph into law enforcement saying ‘Stop bothering us, just do what you think is best.’’” 

The Case For

The Trump administration and the memo’s supporters  have touted it as a means to put the United States on stronger ground in cyberspace. 

Amanda Naylor, the director of cyber policy at the National Security Council who worked on the memo, said on LinkedIn that it was designed “to bring the capabilities, speed, and innovation of the American private sector into the fight against transnational cybercrime and fraud.”

Former Trump White House cybersecurity official Joshua Steinman said he views the memo as a step toward “parity,” given how U.S. adversaries operate in cyberspace.

“The Chinese and the Russians do this at scale, and I guarantee you they have very few limiting tools when they do it,” said Steinman, now founder of the security firm Gavalnick. “It opens up an entire workforce that allows us to go out and achieve strategic objectives.”

The restrictions in the memo are important, he told CyberScoop.

“The most sensitive things are going to continue to be done by the uniformed and authorized civilian workforces, but there’s a lot of low-hanging fruit,” i.e., criminal organizations, Steinman said. He doesn’t have any fear of the program overstepping as a result.

“We operate like a Boy Scout in cyberspace,” he said. “It’s measured and reasoned.” He compared it to the Right to Try Act for medications.

He also said he expects to see a lot of interest in participating in the private sector.

Ari Redbord, global head of policy at TRM Labs, praised the memo too, calling it “a huge step toward empowering the private sector at a critical moment” that “has a real opportunity to be truly transformative.”

“Scammers are using AI to move with unprecedented speed and scale, stealing billions in life savings from average Americans and small businesses,” he said. “The private sector holds the data. The public sector holds the authorities. This [memo] puts them together.”

What’s Next

The coordination center charged with establishing the program under the memo has 60 days to complete its work. That process could determine a lot. Graham noted that the memo has a classified annex, too.

The memo as written is quiet about what becomes of any seized assets, Graham noted. Redbord raised the same topic as one of his questions about execution of the memo. 

“What government direction and control looks like in the middle of a live operation,” he said in listing his questions. “How disruption turns into actual dollars back in victims’ pockets, and whether we can build a true victim compensation fund as part of this program. What happens when an operation touches a third country with its own laws and its own interests. And how success gets measured, in money recovered and networks dismantled.”

Will Barker, cybersecurity adviser at Huntress, said what’s next could be key.

“The 60-day implementing guidance is where the real substance lives,” he said in a written quote. “Minimum standards, operational procedures, the adjudicatory framework for target selection.”

The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop.

Federal judge issues second order blocking Trump mail-in voting directive

By: djohnson
11 August 2026 at 19:26

A federal judge has issued a second injunction preventing the United States Postal Service from carrying out President Donald Trump’s executive order focused on mail-in voting.

Judge Indira Talwani had previously ruled that the White House order, which would have essentially placed the federal government in charge of deciding which voters in each state would receive mail-in ballots, was unconstitutional.

The order was part of an ongoing lawsuit between the federal government and 23 states over the order’s legality. The Trump administration has formally petitioned the U.S. Supreme Court to review the case and reverse the decision.

In a new ruling issued Tuesday, Talwani’s said the court “finds it prudent to review the EO now, where less than 90 days pend before the midterms and the millions of citizens who rely on mail voting require clarity as to how or whether they will vote in November.”

“As to those elections occurring before or on November 3, 2026, the court preserves the current electoral status quo, grants the Plaintiffs’ Renewed Motion…enjoins the USPS’s implementation of Section 3 of the EO,” Talwani wrote.

The opinion concluded that the states “are likely to succeed on the merits” in claiming that Section 3 of the executive order violates constitutional separation of powers, and noted that the federal government’s “sole attempts to grapple with the actual merits of Plaintiff Organizations’ constitutional challenge are their briefly presented unitary executive arguments.”

But Talwani wrote that whether the president has ultimate authority over USPS actions is irrelevant if it results in a “facially unconstitutional” act.

“Instead, the court need only determine whether the EO is facially unconstitutional based on the substance of the text’s directives,” the opinion said. “The court has already answered and will again resolve the question clearly and affirmatively. The executive branch has no authority to regulate elections.”

The post Federal judge issues second order blocking Trump mail-in voting directive appeared first on CyberScoop.

Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas

By: Greg Otto
11 August 2026 at 14:02

Delta Airlines said Tuesday it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.

Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.

Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”

Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.

“We are fully investigating to gather a complete set of facts, which will take time,” Durrant told CyberScoop. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding.”

The Atlanta office of the FBI, along with the Federal Aviation Administration, said it was aware of the incident, but did not provide further comment. The Transportation Security Administration referred CyberScoop to the FBI. Homeland Security Investigations did not respond to a request for comment.

The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.  

The timing of the incident comes as the annual DEF CON cybersecurity conference concluded in Las Vegas on Sunday. The flight, originally scheduled for Sunday, did not leave Las Vegas until 8:30 a.m. Monday.

Monika Hathaway, head of press for DEF CON, told CyberScoop that Delta nor any federal authorities have reached out about the incident. However, she said this year’s conference had trouble with similar attacks.

“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Hathaway told CyberScoop. “If we had caught them doing this at DEF CON we would have removed and banned them from the conference.”

The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.

Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams

6 August 2026 at 16:27

Senators from both parties Thursday probed Trump administration officials about whether federal agencies and foreign governments are coordinated enough in the battle against scammers, something witnesses told the Foreign Relations Committee they were working to remedy.

At least 13 federal agencies have authorities to counter scams, raising questions about whether someone needs to be in charge of all those efforts. And while there was some bipartisan sentiment at Thursday’s hearing that the Trump administration has taken good actions to battle scammers, both lawmakers and administration officials said that scam operations have demonstrated that cracking down on them in one place often just leads to them going elsewhere.

Sen. Pete Ricketts, R-Neb., compared the situation to an international initiative that gained prominence in the 1990s to counter drug trafficking, Joint Interagency Task Force South.

“Given that today’s scam centers are similarly transnational, combining cybercrime, human trafficking, money laundering and cryptocurrency, has the threat reached the point that we should establish a comparable multinational coordination mechanism?” he asked.

Sen. Jeanne Shaheen, D-N.H., focused on federal coordination: She paraphrased a former federal official who said, “there is nobody that is heading that effort up across agencies. We need to treat this like combat, and so we need somebody in charge.”

Shaheen, the top Democrat on the panel, is a co-sponsor of the bipartisan Scam Compound Accountability and Mobilization (SCAM) Act, which seeks to unify federal efforts on the subject.

A State Department official told Shaeen scammers were a national security priority for President Donald Trump, and that his executive order on the topic sought to tackle coordination.

“I do understand that this is a whole-of-government approach, and many agencies are focused on this,” said David Bedard, deputy assistant secretary at State’s Bureau of International Narcotics and Law Enforcement Affairs “The Action plan that was directed by the president is currently in the interagency review process to deconflict some of the concerns that you have raised. We certainly think the task force that will be implanted through the executive order will solve the problems you might be referencing.”

There’s also an international plan under the task force, he said. Currently, the administration shares intelligence on scammers with foreign allies, and Interpol has “productive” channels to work through there and is setting up its own task force, Bedard said, but there are concerns about other countries taking similar, duplicative action.

There have been signs of progress on the international front, Bedard and another State Department witness told the panel.

Michael DeSombre, assistant secretary at the Bureau of East Asian and Pacific Affairs, said Trump has raised the subject with Chinese President Xi Jinping, and that China has used its influence in Asia as its own citizens have become scam victims. Still, there’s been more progress in countries where the United States has stronger relations, such as Cambodia, than in those where ties aren’t as close, like Burma and Laos.

In Cambodia, one key has been pursuing scam center bosses first and foremost, Bedard said.

The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop.

AISI, OpenAI report more ‘unsanctioned’ model hacks

By: djohnson
4 August 2026 at 18:46

The UK’s AI Security Institute said that their AI research system took “unsanctioned” actions over the internet to engage in “sustained, potentially harmful activity directed at real people.”

According to a blog post and technical report released Tuesday, the organization noticed “unusual data transfers” leaving their research systems through the pseudo-anonymous Tor network on July 28. The models, which included Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol models, were being tested for their cybersecurity capabilities.

Like the OpenAI and Anthropic incidents before it, the offending agents were attempting to solve a challenge. On 10 of 122 runs taken by two models, they took a combined 19 malicious actions, including attempting to insert malicious code into a real open-source software project and creating fake online identities to contact human maintainers and press them to approve it.

It also inserted malicious prompt injection instructions in places “where it reasoned that other automated AI systems might pick them up and execute them.” Sometimes multiple agents would collaborate on a task, with one model leaving public messages or notes for the other on GitHub.

However, AISI said their incident differs in one critical way.

“Importantly, this was not a case of a model escaping its secure test environment, or ‘sandbox,’” the institute wrote in an unsigned blog. “As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled – conditions that do not reflect how frontier models are made available to the public.”

The institute said that while their own design and evaluation choices “to some degree” enabled the malicious behavior, the models still displayed “novel, potentially deceptive behaviors” and were executed “to an extent and severity that we did not anticipate.”

The same day, OpenAI acknowledged AISI and another third-party cybersecurity tester,  private firm Irregular, had recently reported incidents where their models exceeded “beyond their intended testing boundaries.”

That included GPT-5.6-Sol reusing GitHub tokens left by another agent to attempt to recover accounts and to access a DNS server that contained malicious payloads meant to exploit a software vulnerability.

The setup did not work, there is no evidence any real resolver queried it, and the infrastructure was removed when the evaluation ended,” the company wrote in an unsigned blog post Tuesday.

OpenAI said it would review its own third-party testing procedures to focus on higher risk evaluations, assess requests by third-parties to enable internet access, stop conditions and other features for their models.

The incident with Irregular occurred on July 29 during a Capture-the-Flag cybersecurity evaluation of OpenAI’s models. Due to a “misconfiguration” the models were allowed to access the public internet, where they encountered and exploited a real domain, mistakenly believing it was still in a test environment.

OpenAI said an investigation by Irregular is ongoing, but also found that the models had found and used credentials for the site at one point. The blog also references other additional potential cybersecurity incidents.

“Irregular has informed us that all of the issues identified pertaining to the incident are no longer active and relevant safeguards were added to the testing environment,” the blog said. “Irregular has also communicated about related incidents involving other labs from the same testing environment.”

CyberScoop has reached out to Irregular for comment.

The incidents were made public the same day that the White House met with Anthropic, Open AI and other frontier AI companies to preview a new framework for evaluating models before they’re released publicly. Some media outlets have reported that after an executive order, export controls and other actions, the administration does not plan to make the new framework public.

The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop.

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

31 July 2026 at 16:16

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.”

Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The White House referred a request for clarification back to Trump’s remarks.

“I think that Minnesota is behind it,” Trump told reporters Friday. “Because they’re grossly incompetent. I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”

The White House also didn’t clarify whom the president believed was behind similar attacks in other states, when asked for comment. Trump has repeatedly used federal power aggressively in Minnesota, a state led by Gov. Tim Walz, a Democrat who was on the ticket that ran against him in 2024 as the vice presidential nominee. Trump also has downplayed Iranian attacks amid the war he launched against the nation with Israel in February.

A number of cyber experts quickly pushed back on Trump’s comments after he made them.

“Victim blaming in cyber is so 2000 and late,” cybersecurity pioneer Chris Wysopal, Veracode co-founder and chief security evangelist, said on the Bluesky social media platform. Said Jake Williams, a member of the IANS faculty: “His own intelligence services are attributing this to Iran.”

Andy Jabbour — founder and CEO of Gate 15, a cybersecurity firm which provides support to the water sector — told CyberScoop that, “speaking candidly, I’m not even sure what he was actually saying or suggesting Minnesota’s government did or didn’t do.”

“Attribution is tricky business,” he continued, referencing recent alerts from the Cybersecurity and Infrastructure Security Agency and others. “But logically, given an ongoing war with Iran, recent statements made by Iran-aligned threat groups, with assessments that the recent activity is aligned with recent CISA warnings, given yesterday’s statements from CISA and the FBI, random unsubstantiated allegations aimed at political opponents seem reckless and are a disservice to the American people.”

Walz struck back at Trump in a Facebook post, noting steps from his Department of Government Efficiency to slash federal funding. CISA has shrunken considerably under Trump, and his administration has pushed states to defend against cyberattacks that feds once countered.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

“DOGE took an axe to CISA and left the U.S. exposed to cyber attacks,” he continued. “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.”

A spokesperson for Minnesota IT Services, a state agency that has been responding to the water cyberattacks, declined to address Trump’s remarks.

“We remain focused on supporting affected communities, securing critical infrastructure and coordinating with local partners and federal officials as the investigation continues,” the spokesperson, Emily Zimmer, told CyberScoop. “We will not comment on political statements or speculate about attribution.”

Other cyber professionals declined to comment directly on Trump’s remarks, but offered thoughts on who was behind the attacks and their motives.

Bryson Bort, CEO and founder of Scythe said the evidence supports the attribution with Iran, and that it looks like hackers there found something they could exploit on the internet and seized the chance.

“This was a target of opportunity,” said Bort, co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security; such systems are common in the water sector. “It wasn’t that Minnesota did something as a state to raise Iran’s ire.”

Cynthia Kaiser, a former top FBI cyber official, said that when the bureau conducts attributions, it looks at technical indicators but also who has the capability, who has conducted similar attacks in the past and what the purpose of the attacks is.

“Iran ticks all these kinds of things,” Kaiser, now senior vice president at cybersecurity firm Halcyon, told CyberScoop. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck. I’d be shocked if we found out it wasn’t Iran.”

Just last week, CISA updated an advisory about how Iranian hackers were targeting programmable logic controllers in the water sector and other sectors, a warning that the water industry’s information sharing and analysis center said it believed.

“WaterISAC is confident in our government partners’ assessment that the confirmed activity is aligned with the joint Cybersecurity Advisory (CSA) AA26-097A ‘Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure’ published and recently updated by CISA,” Tom Dobbins, executive director, WaterISAC, told CyberScoop. “We have evidence of earlier attacks from Iran even before this current conflict. Cyber attacks are the most viable way that Iran can directly attack our homeland, and it is logical that they would do so, especially given the challenges of absolute attribution.”

The water sector is often viewed as one of the most vulnerable critical infrastructure sectors, and Dobbins called on Congress to provide funding to provide funding for the ISAC.

Sen. Tina Smith, D-Minn., also took issue with Trump’s comments.

“The President provided an unserious response that is beneath the dignity of the office he holds. Iran’s purported cyberattack on Minnesota’s water infrastructure must be taken as a serious threat to our national security.  Smith said in a statement, adding that she’s been in touch with CISA and the FBI and was grateful to Minnesota’s IT experts. “The entire situation serves as a stark reminder of the danger this war puts us in the longer it drags on.”

Fellow Minnesota Democratic Sen. Amy Klobuchar had earlier been in touch with Sean Cairncross, the national cyber director and a Minnesota native, about the incident.

Trump has previously displayed a laissez-faire view toward other cyberattacks on the United States, such as when he’s been asked about Chinese and Russian cyberattacks and Trump shrugs them off as something America does, too.

He also has cast doubt before on his government officials’ assessments of who’s responsible for cyberattacks on the United States, such as when he asserted China rather than Russia was behind the landmark SolarWinds breach.

Updated 8/3/2026: with comments from Minnesota’s senators.

The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.

CISA issues recommendations to federal agencies on open-source software security

30 July 2026 at 14:24

The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.

An executive order President Joe Biden signed and that President Donald Trump amended ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given a recent slew of attacks on open-source software (OSS).

“As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Chris Butera, acting executive assistant director for cybersecurity. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.” 

The document, “Open Source Software: Security Principles and Practices,” touts the advantages of open-source software — which anyone can use, modify and share — as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.

“All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,” the guidance reads. “OSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSS’s unique characteristics will position themselves to meet future challenges and leverage new innovations.”

The guidance says that agencies need to take steps to evaluate the trustworthiness of an OSS project before approving an OSS component for use, and track OSS in their asset management repositories. It details how agencies should deal with patching, including when there’s a new OSS vulnerability that doesn’t have one. It offers advice on how agencies might contribute to OSS projects, produce them and secure rights for government reuse of code when contracting for custom software development. And it explains how it should approach open-weight AI models.

“Agencies should approach ‘open source’ AI systems differently from other OSS because open source licenses for AI software do not require the level of transparency needed to evaluate the trustworthiness of the software,” the guidance states.

Æva Black, an open-source security expert and former OSS lead at CISA, said she applauded her former agency for the guidance, telling CyberScoop that it “demonstrates a grounded understanding of the global, diverse, and participatory nature of open source software development, and provides essential guidance for federal agencies to safely use open soure during a crucial moment.” 

She singled out its recommendations on the risks of deploying unverifiable open-weight AI models on sensitive networks.

“Due to recent advances in AI, particularly in large language models capable of finding and exploiting software vulnerabilities, vulnerability management is facing a global crisis,” she said. “Many proprietary software vendors are using this as an opportunity to spread ‘fear, uncertainty, and doubt’ about open source in order to capture public attention, and, I presume, public money — but when used responsibly and maintained collaboratively, I believe open source software is, and will remain, the safest and most cost-effective means for building large scale public infrastructure.” 

CISA has produced a bevy of security guidance and updated advisory materials this week: on the creation of software bills of materials written in conjunction with other agencies and allied governments that won praise from experts; on the isolation of vital operational technology during a crisis, also written with other agencies and allied governments; and the release of updated secure cloud configuration baselines for Google Workspace.

The post CISA issues recommendations to federal agencies on open-source software security appeared first on CyberScoop.

Supply chain challenges loom large in quantum race, White House official says

29 July 2026 at 16:22

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.

“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.

“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there’s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”

Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.

“The other major issue or challenge that we face right now is that we’re on the cusp of quantum exploding from a commercialization perspective, but we’re not quite there yet,” he said. “So there’s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it’s just [that] there are too many places that I would want to bolster and not enough funding to do it.”

Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.

The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.

And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia. 

Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.

“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that’s what makes it so critical.”

Another difficulty is measuring progress, Blakestad said: “It’s also very, very hard to benchmark, and to know that you’re actually doing what you’re supposed to, what you are intending to do.”

The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.

Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks

24 July 2026 at 16:58

Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency about a pending cyber incident notification regulation had a few consistent messages:

We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do. 

CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.

The law was designed to let the feds share information about significant incidents more widely to prepare other would-be victims. CISA published a proposed rule on the law in 2024 to define terms like “covered cyber incident” and more, and industry groups have persistently registered their objections since then.

CISA missed the October 2025 deadline for finalizing the rule, then missed a May reset target date, and now the administration says the rule will be completed in September.

Some industry sources told CyberScoop they consider that unlikely. Most also haven’t received any indications from CISA about how much of the town hall feedback it intends to embrace, they said.

Companies, incidents, information 

Those town hall comments over the course of four June dates were often very direct.

“The rule includes too many companies,” said Grant MacIntyre, director of regulatory affairs and senior attorney at the Auto Care Association. CISA estimated that more than 300,000 entities will be subject to its requirements.

Some industries advocated for their removal entirely, such as two different groups representing elements of the insurance sector. Some sought to reduce the number affected within their sector, such as the Nuclear Energy Institute wanting the list cut down to those already subject to Nuclear Regulatory Commission cybersecurity reporting requirements.

While CISA wrote the regulation with the intention to avoid overburdening small businesses, some feared it wouldn’t work that way in practice.

“The current approach where an entity qualifies either by size or by sector effectively negates the intended limitation on small businesses,” said Douglas Leigh, vice president of legislative affairs for the Alliance for Chemical Distribution. “In chemical distribution, even small entities could be swept in under multiple cyber categories.”

Where the rule specifies what kind of data organizations should report in a major incident, CISA should “seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed,” said Samantha Burch, vice president of technology public policy at government affairs at AHIP, a health insurance industry trade association.

Many, for instance, argued the report should not include information on the affected entities’ security measures.

Others worried about what kind of incidents would trigger reporting requirements.

“My big concern is that you’re going to be asking us to report incidents on every time some foreign entity tickles our firewall, whether they do anything or not, if they just do a ping or a search,” said Tim Pospisil, chief security officer for Nebraska Public Power District. “And that could be extremely burdensome.”

Industry Expectations

One industry representative told CyberScoop that CISA’s willingness to hold town halls, combined with the Trump administration strategy emphasizing “common sense regulation,” was a good sign about where the rule might be heading.

‘They are not picking up on the Biden administration’s approach and tweaking it. They’re thinking, ‘What are the specific pieces of information we need during a cyber incident to help critical infrastructure companies respond?’” said Henry Young, senior director of policy for the Business Software Alliance. “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”

But multiple industry sources said they haven’t gotten many indications about CISA’s intentions. Nor are they optimistic CISA can meet the September target date in the Unified Agenda of Regulatory and Deregulatory Actions.

“It could slip,” one said. “But I think they’re going to try.”

That industry source said they’d like to see a proposal from CISA before it cements anything forever.

Another industry source said it’s hard to trust the September date given past CISA delays, some of which aren’t CISA’s fault, such as dealing with multiple government shutdowns. Some of the delays trace to the Trump administration, given the massive cuts to CISA’s personnel.

Congress is also getting impatient.

The House Appropriations Committee “is concerned about delays in publishing the final CIRCIA rule and urges CISA to finalize it promptly following stakeholder review and feedback,” the panel wrote in the committee report for its fiscal 2027 Department of Homeland Security spending bill.

It’s a much different world than when CISA began writing the rule, something the agency also has to take into account now.

“AI has fundamentally changed the playing field,” the source said. “When this was set up, we didn’t even have the first generation of ChatGPT. We’re now in a mythos class environment.” That’s changed “how quickly we can identify threats, mitigate them, the level of human intervention, potential machine engagement.”

While CISA might have good intentions, past interactions give cause for skepticism about how capable it is of working collaboratively with industry, the source said.

Another industry source said conversations with CISA suggest the agency will look to simplify the regulation to keep it smaller and narrower, then potentially build upon it later.

From CISA’s mouth

Nick Andersen, the acting director of CISA, talked about his overarching intentions with CIRCIA at the town halls.

“CISA does not view CIRCIA as simply a check-the-box compliance exercise,” Andersen said at one. “CIRCIA will enhance visibility into the cyberthreat landscape to enable a robust national early warning capability for critical infrastructure. By quickly reporting covered cyber incidents and ransom payments to CISA, we will be able to provide timely and actionable defensive and eviction measures to your network defenders.”

Asked by CyberScoop about next steps for CIRCIA, and how it might incorporate the industry feedback, a spokesperson provided a statement.

“CISA recognizes the importance of CIRCIA, however, multiple funding lapses impacted CISA’s ability to conduct rulemaking activity for CIRCIA. CISA continues to work on the final rule,” the spokesperson said, adding that 1,200 critical infrastructure stakeholders attended the town halls.  “CISA will continue to communicate updates on the CIRCIA rulemaking process and timeline through CISA.gov/CIRCIA and the Office of Information and Regulatory Affairs’ Unified Agenda of Regulatory and Deregulatory Actions.”

The post Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks appeared first on CyberScoop.

Most federal cybersecurity reporting rules are duplicative, study finds

22 July 2026 at 17:04

Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.

And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.

At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”

The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.

The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D-Mich.

In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.

Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted.

A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals.

But the executive branch paused some of those efforts after Trump issued an executive order in March of last year while the administration conducted a study of the 2024 memo, a study that was still underway as of last month, according to the GAO.

As such, on harmonization, “many past federal efforts have experienced delays and made limited progress,” the GAO concluded in its report Wednesday, its latest on the topic. 

Congress has also looked at ways to streamline cybersecurity regulations.

GAO’s study was focused only on federal rules. BreachRx, a cyber incident response firm, published its own report Wednesday looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.

The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

❌
❌