❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Why federal cyber defense demands an offense-driven mindset

8 September 2026 at 14:30

Federal agencies are drowning in cybersecurity data. Every day, security operations centers absorb millions of logs, scanner alerts and inventory feeds. But raw, static data isn’t actionable intelligence. Ask a room of federal CISOs to name the three critical weaknesses an adversary could exploit today to compromise their missions, and you’ll likely be met with a mountain of compliance reports.

That disconnect reveals a critical velocity problem in government risk management.      Traditional vulnerability management treats every Common Vulnerabilities and Exposures (CVE) entry and high Common Vulnerability Scoring System (CVSS) score as an equal emergency, regardless of whether it’s actually exploitable. Security teams spend weeks chasing theoretical findings, while adversaries exploit overlooked attack paths in hours. CVSS scores are static abstractions: they cannot reveal whether a flaw is reachable today, chainable with other weaknesses or capable of causing immediate mission damage.

As AI collapses the window between vulnerability disclosure and exploit execution, CISA’s issuance of BOD 26-04 marks a long-overdue pivot. The directive codifies what frontline defenders already know: agencies cannot win 90-day patch races against adversaries moving at machine speed. Federal cyber defense must shift from reactive spreadsheet patching to real-time prioritization based on exploitability, active threats and mission risk.

Vulnerable does not mean exploitable

During 30 years in IT operations and military cyber environments, I lost count of how many times I had to tell an auditor: “That high-severity CVE is a false positive, the vulnerable module isn’t running, or we’ve mitigated it six different ways.”

That gap between vulnerable and exploitable is where federal security teams lose the clock. Vulnerability scanners produce thousand-page laundry lists. Teams work from the top down, spending finite engineering hours patching high-severity “purples.” They often exhaust their time and budget before reaching the medium- and low-severity findings.

Adversaries do not follow a 90-day patch cycle. Attackers rarely burn a valuable zero-day exploit when a misconfiguration, weak trust relationship or stolen credential provides a direct path to their objective. As my colleague Todd Beebe from Freeport LNG has noted, “Credentials are the everyday zero-day.” Attackers don’t hack in when they can simply log in.

Defenders spend months building fortresses around static “crown jewel” systems while adversaries maneuver around those controls by chaining low-severity weaknesses with compromised identities. CVEs are only part of the story: misconfigurations and the tactics, techniques and procedures that live between CVEs matter just as much. We’ve validated thousands of attack paths across thousands of organizations that led to critical impact without leveraging a single CVE, and the only way to understand those paths is through offense-driven defense. Closing a vulnerability ticket on schedule doesn’t mean you have stopped an attacker. Untested assumptions are what get organizations in the news.

The cyber version of the McNamara Fallacy

Federal leaders risk falling victim to a modern cyber version of the McNamara Fallacy. Named for Defense Secretary Robert McNamara’s reliance on quantifiable metrics during the Vietnam War, it describes managing by what is easiest to count (e.g., patches applied, tickets closed and average CVSS scores) while overlooking operational reality.

I learned this lesson firsthand while leading IT and cybersecurity operations for a specialized defense unit. Our team was compliant. We checked every DISA STIG box, passed every audit and maintained immaculate documentation. Then a red team assessed our environment. Across people, process and technology, our organization performed well, but the assessment still found things a threat actor could immediately take advantage of.

When I asked whether they could return in three months to verify our fixes, they laughed. “No way,” they said. “You don’t have the budget, and we don’t have the resources.”

That experience fundamentally shifted my mindset: it is much easier to be compliant than secure.

Human-led penetration testing remains valuable, but small-scoped, point-in-time assessments cannot match today’s threat velocity. A manual test conducted annually gives you 24 hours of confidence and 364 days of guesswork. In an AI-accelerated environment, the report may be stale before the ink dries.

Proving defenses work in real time

Across modern framework developments, from NIST SP 800-53 Rev. 5 and NIST CSF 2.0 to federal zero trust mandates, FedRAMP, and Continuous Threat Exposure Management (CTEM), the market is shifting from static attestation toward validation and verification:

  • Compliance asks if a control is present and documented.
  • Validation asks if that control stops realistic attacker behavior now.
  • Verification asks if remediation eliminated the attack path in production.

To outpace adversaries, agencies must augment human expertise with autonomous penetration testing capabilities. We know this works in high-assurance public-sector environments. Under the NSA’s Continuous Autonomous Penetration Testing (CAPT) program, autonomous testing has logged 223,833 hours of operations across 28,282 completed pentests, spanning more than 3.7 million endpoints across 822 Defense Industrial Base organizations.

More importantly, the program accelerated remediation, saving more than 340,000 labor hours and enabling lean security teams to verify and close 71% of critical findings within 30 days. That is the difference between an annual-audit mindset and real-time operational defense.

Three action steps for federal leaders

Federal leaders should take three steps to operate at the speed of the threat:

  1.   Define risk through exploitability and impact. Risk is the product of likelihood and impact. But legacy vulnerability management accepts theoretical guessing of likelihood and fails to account for the consequences of the exploitation. Remediation should prioritize validated attack paths posing immediate mission risk.
  1. Move to continuous verification. In the military, we said, “Trust but verify.” In modern cyber defense, it is simply “verify.” Agencies must safely and continuously test controls, architectures, and identity permissions in production from multiple perspectives, including outside-in, assumed-breach, identity-based, and cloud-native.
  2. Verify the fix, not the activity. A ticket should not close merely because someone deployed a patch or changed a configuration. It should close only after a targeted retest confirms the exploitable attack path is gone.

As Corey Brunkow, Horizon3’s Director of Federal Operations, puts it: “Compliance is the baseline, not the finish line. In the new era of AI-enabled attacks, government and supply chain partners cannot afford to mistake a documented security control for an effective one.” The only way to know whether defenses can withstand an adversary is to send an attacker at them. Federal leaders must turn the map around, view their networks through the eyes of the adversary and continuously validate their security posture before an opponent does.

Learn how Horizon3 can help organizations move from point-in-time compliance to continuous, autonomous penetration testing.

The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop.

The G7 tells industry to hurry up and prep for post-quantum encryption

By: djohnson
3 September 2026 at 15:29

A cybersecurity working group at the G7 is urging governments to accelerate defenses against quantum computers that could break some existing forms of public key encryption.

The working group’s report, prepared in June at the G7 Summit in France, said organizations “can no longer afford to postpone” work transitioning critical systems and data to “post-quantum” forms of encryption.

“The quantum threat remains off the radar for many organizations and not properly resourced, with other security concerns taking precedence,” the working group report said. “Yet, a successful and collective transition to PQC can only be achieved if organizations understand that the quantum threat is an economic and business risk, and not merely a cryptographic risk.”

Instead, leaders in government and industry “must reframe the quantum threat from a distant future problem to a near-term threat that demands action across all sectors, not just critical infrastructure.”

The report acknowledged uncertain timelines for quantum computers, but identified that threats like harvesting current sensitive, encrypted data to decrypt it in the future do exist today.

The report also warned that quantum computers could compromise authentication and assurance mechanisms—by forging trusted data or stealing confirmation— jeopardizing secure communications and legal contracts.

The working group’s conclusions are largely in line with what governments have been recommending for years, urging industry to inventory and prioritize their critical systems and shift over to newer, “post-quantum cryptography” encryption algorithms.

These encryption algorithms, originally designed by independent cryptographers and vetted by the National Institute for Standards and Technology and National Security Agency, will be used to protect the government’s own systems and data from cybercriminals and foreign governments.

The Trump administration recently issued an executive order directing agencies to boost the domestic quantum industry and move up internal timelines for migrating to PQC encryption from 2035 to 2030. Google, a potential industry bellwether, and other companies have opted to move their own migration timelines to 2029.

But while that work has proceeded on schedule in some areas, like the federal government and the highly regulated financial sector, it has lagged in other industries where owners and operators feel they have more immediate concerns than quantum computers.

“We acknowledge that transitioning to PQC is not a problem for individual organizations to solve in isolation, but rather a collective transition that can only be achieved with early engagement, coordinated planning and informed decision making across the public and private sectors,” the working group wrote.

While often referred to as “Post-Quantum” encryption, the reality is more complex. Cryptographers believe the algorithms selected by NIST and NSA will stand up to attacks from a quantum computer, but since one doesn’t exist today, designing cryptographic protections against it requires some guesswork and mathematical estimation.

Estimates can be wrong, or overlook the entire cryptographic attack surface. Some NIST-selected algorithms have already been broken with traditional computers or AI. That’s why the agency backs multiple algorithms and concepts like “crypto-agility,” allowing organizations to quickly switch between them.

The G7 report was signed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the UK’s National Cyber Security Centre (NCSC), The French Cybersecurity Agency (ANSSI), Germany’s Federal Office of Information Security (BSI), Canada’s Communications Security Establishment (CSE), Japan’s National Cybersecurity Office (NCO) and Italy’s National Cybersecurity Agency (ACN).

The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop.

NIST wants to overhaul its vulnerability database for the AI age

By: djohnson
11 August 2026 at 11:36

The National Institute for Standards and Technology is looking for input on how to overhaul its vulnerability reporting process to better meet the challenges of an “evolving cybersecurity landscape increasingly shaped by artificial intelligence and machine-consumable security data.”

In a request for information set to publish Wednesday in the Federal Register, NIST said its National Vulnerability Database, one of the primary ways the federal government coordinates with security researchers to identify and fix software vulnerabilities, must be updated for the AI age.

NIST is concerned that as large language models become more capable of finding and exploiting vulnerabilities at scale, the NVD’s process must be updated.

“The inadequacies of traditional vulnerability management approaches, which center on periodic scanning, static prioritization, and manual remediation, are increasingly apparent,” the RFI states.

NIST believes AI hacking tools are contributing to recent trends in vulnerability reporting. The NVD has seen increased volume and complexity of disclosed vulnerabilities, inconsistent data quality, increased reliance on automation and machine-readable security data, and “demand for near real-time vulnerability enrichment” from defenders facing faster threats.But NIST believes these challenges also present an “opportunity to transform the vulnerability management ecosystem” through proactive reforms and NVD innovation.

That’s where the public comes in. NIST is posing a series of questions that must be answered before a larger strategy can be developed. Many of their questions focus on better integrating automation – AI or otherwise – into the process.

The agency asked for insight on how defenders could better leverage automation in the vulnerability reporting process; which capabilities, products and processes would help more quickly disseminate information to stakeholders, how to build transparency and auditability into AI-driven decisionmaking, and what role AI should play in automated vulnerability remediation.

“NIST intends to support a future-ready vulnerability management ecosystem that is continuous, contextual, and automated, while enabling cybersecurity practices to respond appropriately to real-world threats and business priorities,” the RFI states.

The NIST effort to revamp its vulnerability database comes a month after the Trump administration rolled out a new federal clearinghouse, overseen by the Department of Treasury, for sharing AI threat information between government and the private sector called “Gold Eagle.”

It’s not clear how Treasury’s process will interact with NIST’s database. The White House also partnered with Carnegie Mellon’s Software Engineering Institute to create the Vulnerability Information and Coordination Environment, (VINCE) which will collect and distribute reports on AI-discovered vulnerabilities.

The post NIST wants to overhaul its vulnerability database for the AI age appeared first on CyberScoop.

Here’s what Anthropic found when it turned Mythos loose on encryption algorithms

By: Greg Otto
28 July 2026 at 16:54

Anthropic researchers used Claude Mythos Preview to find new weaknesses in two cryptographic methods, the company said Tuesday, including one that is being considered by the National Institute of Standards and Technology for both traditional and quantum computing.  

In a blog post detailing the work, the frontier AI company called it a “substantial” research advancement, but also emphasized that neither flaw affects software now in use.

“The attacks described in these two papers are the strongest attacks we have found to date,” the company wrote in the post. 

One of the weaknesses found was in HAWK, a digital signature scheme under review by the NIST as part of a search for encryption methods that could survive attacks from quantum computers. Working with a human researcher, the AI system found a mathematical shortcut, known as a nontrivial automorphism, in the lattice structure (a complex mathematical grid underpinning its security) HAWK relies on.

The discovered weakness cuts HAWK’s effective key strength in half, meaning key sizes would need to double to keep the same level of security. Anthropic said that change would erase much of what made HAWK an appealing candidate in the first place.

Ellen Boehm, senior vice president of strategy and AI innovation at Keyfactor, a digital identity and cryptography management provider, told CyberScoop that research like Anthropic’s proves that the NIST PQC evaluation process is working. 

She also said the research “elevates the importance for organizations to have visibility of where cryptography sits inside their enterprise, what business systems and processes it’s connected to, and the need for PQC readiness, if they haven’t already built a plan.” 

The other flaw was found in a weakened version of the Advanced Encryption Standard, or AES, the cipher NIST adopted in 2001 and the most widely used method for scrambling data in transit. Working largely on its own, Mythos invented a mathematical shortcut dubbed the “Möbius Bridge.” While real-world encryption scrambles data through 10 sequential layers, or “rounds,” researchers regularly study a simplified seven-round test version to measure security margins. In previous theoretical attacks, codebreakers had to check 256 separate values against a memory table, but Mythos created a shortcut that eliminated that lookup process entirely.

Combined with other optimizations, this discovery made the strongest known theoretical attack against seven-round AES 200 to 800 times faster. The attack is purely theoretical: It requires an impossible amount of target data — over 400 octillion messages — and cannot touch the full 10-round encryption protecting everyday software. Additionally, Anthropic pointed out that real-world systems remain completely safe.

Anthropic said it followed standard disclosure practices, notifying HAWK’s designers in June and coordinating public release with a NIST mailing list, and briefing government and industry partners beforehand. It also worked with researchers at ETH Zurich, Tel Aviv University and the University of Haifa to build a shared testing tool, called CryptanalysisBench, meant to let other researchers measure how AI systems perform against a range of ciphers.

The findings come as frontier AI models are being deployed by cybersecurity researchers in order to find vulnerabilities in all kinds of software. In June, intelligence agencies in the Five Eyes alliance warned that advanced AI models capable of wreaking havoc in the cyber domain are “months away.” However, a recent report found that despite the avalanche of bugs being unearthed, the threat level across the internet has not materially changed. 

Anthropic said it expects the same AI capabilities eventually to be applied to systems already in wide use, raising a separate question it said it has not yet resolved: how researchers, companies and governments should respond if a language model uncovers a flaw in a cryptographic system that protects critical infrastructure.

“As we develop increasingly powerful cryptanalytic results, it would be prudent to consider how researchers should react if a language model were to discover vulnerabilities in cryptosystems where attacks do have an immediate real-world impact,” the company wrote. “We hope that our work here will help launch these conversations.” 

Boehm said work like Anthropic’s further shows that enterprises should not rest on their laurels with any facet of their security apparatus. 

“AI is becoming a powerful tool for many things, including software quality assurance, code development, and in this case cryptographic analysis,” she told CyberScoop. “As AI tools become more widely and continuously used, it just elevates the need for enterprises to treat their trust infrastructure in an ongoing, operational manner versus thinking of it as a static environment that only changes every few years as new cryptographic algorithms are released.”

The post Here’s what Anthropic found when it turned Mythos loose on encryption algorithms appeared first on CyberScoop.

Director of Commerce AI standards office out after three months

By: djohnson
20 July 2026 at 14:10

The head of a key federal government AI testing lab is leaving his post just months after taking over.

A Department of Commerce spokesperson confirmed to CyberScoop that Chris Fall is stepping down as director of the Center for AI Standards and Innovation, and his position is being backfilled.

“Following Chris’s departure, NIST Director Dr. Arvind Raman will continue to oversee CAISI and will serve as Acting CAISI Director,” the spokesperson said in a statement to CyberScoop.

Further details about the circumstances behind Fall’s departure were not provided. Axios, which first reported the departure, cited sources saying that Fall resigned.

The Center for AI Standards and Innovation has quietly become a key hub for the federal government to assess potential threats and harms that AI systems can pose to cybersecurity and national security. 

Early in the Trump administration, the center began informally working with frontier AI companies like OpenAI and Anthropic to test their models for threats, like their offensive hacking skills, assistance with building biological or nuclear weapons and other dangerous capabilities.

Fall was tapped to lead the center in April, and his departure just three months later comes as the White House has elevated the work of the center as one of the key means for determining which frontier AI models do — and do not — represent a step change in cyber or other capabilities compared to what’s available today.

Fall previously held other government posts, including as director of the Department of Energy’s Office of Science, assistant director for defense programs at the White House Office of Science and Technology Policy, and acting chief scientist at the Office of Naval Research.

The post Director of Commerce AI standards office out after three months appeared first on CyberScoop.

Found fast, fixed slow: The gap the AI clearinghouse must close

By: Greg Otto
8 July 2026 at 05:00

The AI-focused executive order President Donald Trump signed last month gave the Treasury Department, the National Security Agency, and the Cybersecurity and Infrastructure Security Agency (CISA) 30 days to establish a new “AI cybersecurity clearinghouse.” The deadline passed last week.

The clearinghouse is meant to coordinate the scanning, discovery, and validation of software vulnerabilities in critical infrastructure, and then prioritize how those vulnerabilities get patched and distributed.

It’s the right problem to solve. The question now is whether what is created will actually solve it.

The risk is that urgency produces something that looks like a clearinghouse, but functions like a committee: collecting information, convening meetings, and then stalling when it gets to the hard part.

Going beyond bug discovery is mission critical

It’s counterintuitive at a moment when AI-assisted vulnerability discovery is advancing rapidly, but the hard part is no longer just finding bugs. Those of us working at the intersection of AI and cybersecurity know where the real bottleneck is. HackerOne has seen it firsthand as a launch partner in Patch the Planet, OpenAI‘s initiative to use AI to find and fix vulnerabilities in critical open-source software at internet scale. The lesson underpinning that work, and informed by more than a decade of running vulnerability disclosure programs, is consistent: AI tools can surface vulnerabilities faster than anyone can act on them. What lags behind is everything that comes after discovery: deciding which findings are real, assessing severity in context, writing and testing a fix, and getting a patch accepted and deployed by the people responsible for maintaining the affected code.

Experienced human reviewers frequently disagree with AI-assigned severity ratings, because a model cannot see a project’s threat model or operational context. Software providers, especially the many volunteer open-source maintainers that so much of today’s digital infrastructure rely upon, face a relentless queue: verify the claim, assess the importance, write the patch, coordinate disclosure. AI has accelerated the incoming volume without yet equally accelerating our people and processes’ capacity to manage it. Better bug-finding tools mean you find more bugs. The improvements that really matter are the ones that help defenders push patches out and get them deployed faster.

That lesson should sit at the center of how the clearinghouse is designed.

If the clearinghouse focuses primarily on scanning coordination, which the executive order’s text emphasizes, it risks widening that gap rather than closing it. A body that finds more vulnerabilities but cannot move them to resolution is not a security win. At national scale, it is a backlog generator.

Laying a foundation for success

The administration can get this right, but it requires building the correct infrastructure now, not layering it on later.

The clearinghouse needs to do more than coordinate scanning. It needs to actually triage the results. Its core job should be filtering reports to identify which findings are truly credible, exploitable, and consequential for critical infrastructure. Using shared validation standards and risk-based prioritization, it can determine what warrants a national response. Otherwise, it’s just automating bigger backlogs.

Second, the clearinghouse also needs to tackle something more fundamental. Defenders don’t have the resources to respond to what gets reported. Vulnerabilities in critical infrastructure often live in open-source code maintained by small teams or individuals with no formal obligation to respond to disclosures and limited capacity to act quickly. The clearinghouse should work with the National Institute of Standards and Technology (NIST) to develop guidelines for open-source maintainers on structuring repositories and workflows to speed up patch review and deployment.

These guidelines should include how to use AI-assisted patching and clarify what downstream consumers of open-source code should do to help maintainers address vulnerabilities.  Federal policy should create incentives for downstream users to share responsibility for remediation through funding, engineering support, AI-assisted patch development, and procurement requirements that reward participation in coordinated vulnerability response.

Third, the clearinghouse should treat software bills of materials (SBOMs), the structured inventories of the components that make up a software product, as foundational infrastructure. SBOMs are what make it possible to trace where a vulnerable component lives across the supply chain. Without them, validated findings won’t be fixed fast enough at scale.

Finally, the clearinghouse should measure success based on what is fixed, not based on what is discovered.  Agencies need to publish data on validation rates, time-to-patch, adoption of fixes, and recurring classes of vulnerabilities. These metrics help AI systems, software vendors, and policymakers to continuously improve how vulnerabilities are addressed.

Most importantly: the agencies standing up this clearinghouse should resist the temptation to build its operational model from scratch. The private sector and the open-source security community have years of experience running exactly the kind of vulnerability intake, triage, and coordinated disclosure workflows the clearinghouse needs. The executive order wisely calls for voluntary collaboration with industry. That collaboration should be structural, not advisory, embedded in how the clearinghouse operates from the start, not bolted on after the architecture is already set.

The clearinghouse can work. But the challenge is no longer finding vulnerabilities. It is building a system that can turn discoveries into action. That is how its success should be measured.

The post Found fast, fixed slow: The gap the AI clearinghouse must close appeared first on CyberScoop.

❌
❌