❌

Reading view

There are new articles available, click to refresh the page.

House and Senate members propose legislation for CISA to step up cyber defenses for biotech

Biotechnology doesn’t fall neatly into any one of the 16 government-designated critical infrastructure sectors that receive specialized and focused attention from feds, leading some lawmakers to worry that it’s not getting the protection from cyberattacks and other risks that it needs.

That’s why a bipartisan group of senators and representatives announced legislation Thursday that would place an emphasis at the Cybersecurity and Infrastructure Security Agency on defending biotechnology, biomanufacturing and biological data.

The Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act and the Protecting Biological Data Act are two separate bills with the same group of cosponsors. Both bills would weave biotech into the law that established the Department of Homeland Security.

The former would direct DHS to come up with plans to make sure biotech and biomanufacturing are protected as critical infrastructure, but not as a whole new sector. The plans would identify key biotech players, conduct outreach to them and develop steps to update the National Infrastructure Protection Plan this year to incorporate biotech sector input.

The latter would make sure that systems handling genomic sequences and sensitive biometric data are covered as critical infrastructure and integrated into the national cyber strategy, that CISA would work with biotech players on security steps like joint exercises and that the agency would get new personnel to handle biometric data security.

In the last two months, biotech giants Boston Scientific and Amgen have revealed that they suffered recent cyberattacks.

Sponsors of the measures include leaders and members of the National Security Commission on Emerging Biotechnology, a legislative advisory group.

“Biotechnology infrastructure and data are becoming vital to America’s economic and national security,” said Commission Chair Senator Todd Young, R-Ind. “Just as we are serious about where the sensitive data of Americans is stored and who can access it, we should be equally serious about protecting our biological data and infrastructure. Designating biotech as critical infrastructure is about recognizing its strategic importance and making sure the capabilities America will depend on tomorrow remain resilient and protected from foreign threats.”

Notably, however, the bills do not seek a separate critical infrastructure category for biotech to add to the 16. Currently, biotech cuts across a number of existing sectors, including the health, agricultural and industrial sectors.

Some industry groups and experts have lobbied for the inclusion of new critical infrastructure sectors, such as space or artificial intelligence.

“Protecting biomanufacturing infrastructure and the most sensitive biological data of Americans is essential for our national security,” said commissioner Rep. Ro Khanna, D-Calif. “These bipartisan bills will help ensure we are protecting this sector from physical and cyber threats while keeping America as the world leader in biotechnology.”

The bill’s sponsors in the House are Khanna, Stephanie Bice, R-Okla. and Scott Peters, D-Calif., and in the Senate the sponsors are Young and Maggie Hassan, D-N.H.

You can read the text of the bills below.

The post House and Senate members propose legislation for CISA to step up cyber defenses for biotech appeared first on CyberScoop.

FBI cyber chief worries private sector not sharing enough cyber threat information

The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.

Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”

“From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.

“It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,” he said. “That should worry all of us when that happens, because who is positioned to eradicate the PRC from their environments as quickly as when they might have law enforcement or the intelligence teams at FBI come in and actually help with that effort?”

In response, the bureau has held events like outside counsel summits to walk attorneys through what the FBI offers victims during a major breach, Leatherman said. The FBI also has adjusted its standards for when to share information about threats when weighing how much it might help victims versus whether it might jeopardize a law enforcement operation in the future.

“Our posture is, ‘Share until it hurts,’” he said. “What I always ask my team is, if the victim were sitting in this room right now … would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation 90 days from now?”

“We have to in every situation where we have intelligence, we have to take that victim perspective because they can’t voice it in that moment,” he said. “Where we can share in a way that will protect our equities in conducting those operations, we’ll do it. But [where] we can have an impact to hundreds of pieces of critical infrastructure, we should share that, and we should share it quickly.”

The FBI published a new cyber strategy Wednesday that places an emphasis on aiding victims of cyberattacks. Helping victims also helps investigations, Leatherman said.

“We used to look at remediation and incident response as mutually exclusive to investigation and threat pursuit,” he said. “And what we’ve shown over the last few years is that they are not mutually exclusive. … If we can work with victims in a way that preserves investigative information, that allows us to move upstream against the actors.”

The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared first on CyberScoop.

FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

Artificial intelligence is souping up the speed and capabilities of malicious hackers, a top FBI official said Tuesday. And the speed of vulnerability discoveries is forcing organizations to patch more frequently, said another top FBI official.

The officials made their remarks one day before the release of a new FBI cyber strategy Wednesday, which touches on AI, relief and justice for victims and other bureau priorities.

Speaking to both CyberScoop and at the Billington CyberSecurity Summit, Jason Bilnoski, deputy assistant director of the FBI’s cyber division, said AI is “taking actors to the next level.” 

“You’re going to have additional offensive actions coming at your environment, targeting the network at speed and capability,” he said. And he expects it to keep getting worse, with AI-enabled attacks already having a measurable impact, as demonstrated by the numbers in a new section of the annual FBI report on digital crimes.

“The wave is coming. I don’t think we’ve hit the crest yet,” Bilnoski said. “We see an exponential increase in the use of AI, whether it’s nation-state or criminal.”

Still, AI isn’t doing anything that attention to cybersecurity basics wouldn’t prevent, Bilnoski said. It’s something the FBI sees again and again when it conducts investigations, even those with an AI element.

“The adversaries are still [exploiting] basic principles or basic cyber hygiene principles that we are not following,” he said, referring to a recent FBI emphasis on 10 fundamental defensive measures like multifactor authentication. “If we can harden up those top 10 controls that we talked about, it would certainly reduce the risk of both criminal and nation-state targeting of our environment.”

“What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” he said.

The FBI, meanwhile, will “continue to pursue AI in a way that will help us defend at scale,” Bilnoski said.

Patching pacing

The speed at which AI models are uncovering vulnerabilities means organizations need to rethink their approach to patching, another FBI official said at the Billington event.

“We no longer can essentially do the quarterly patching,” said Colleen Ferranti, assistant section chief, cyber engagement and intelligence section. “We have to evolve with the time, and we have to do more risk-based type patching, and we have to be doing that continuously.”

“So, from our perspective, the day-to-day or quarterly or Patch Tuesday — this needs to be a patch-all-of-the-time, and making sure that we are tracking our systems to also be engaging with that type of technology and at that speed and that level,” she continued.

AI now in FBI cyber strategy

The FBI strategy also has a section devoted to artificial intelligence.

“FBI Cyber will deploy AI-enabled tools to triage large datasets, surface relationships, accelerate malware analysis, prioritize victim notifications, map adversary infrastructure, support attribution, and identify patterns that no human analyst could process at the required pace,” it states. “Consistent with President Trump’s Cyber Strategy for America, FBI Cyber will rapidly adopt agentic AI in ways that securely scale defense and disruption, and will implement AI-enabled tools to detect, divert, and deceive threat actors where operationally appropriate.”

The FBI likewise wants to develop additional tools and techniques, according to the strategy.

“The FBI will continue to develop its Computer Network Operations (CNO) program, providing investigative teams with the court-authorized or otherwise lawfully authorized technical operations tools to remotely collect, conduct surveillance, and disrupt the activities of nation-state and cybercriminal actors when traditional investigative techniques will not achieve the required outcome,” it reads.

The strategy largely reflects a number of existing practices at the agency, such as a focus on disrupting attackers. But one emphasis is on relief and justice for victims.

It contains a “pledge” in support of them: “Pursuing our mission, we recognize that we will encounter unique and novel issues related to privacy and the handling of sensitive data. We will always treat victims with dignity and respect, protect their privacy and data, and rigorously adhere to the U.S. Constitution; applicable laws, regulations, and policies; and the FBI’s Core Values.”

It also promises to quickly share threat intelligence, swiftly respond after incidents and expand “its Industrial Control Systems (ICS) Coordinator program to designate dedicated personnel in every field office.” 

It’s the latest document of the Trump administration to focus on cyber strategy, following the release earlier this year of its overall cyber strategy and the Defense Department’s version expected to publish soon as well.

Clarified 9/9/2026: A quote from Colleen Ferranti has been edited for clarificiation.

The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop.

❌