Reading view

There are new articles available, click to refresh the page.

The FTC wants to regulate AI for ideological bias 

The Federal Trade Commission wants to start regulating ideological bias in AI systems and assert federal control over state laws. They’re getting an earful from opponents on all sides of the political spectrum.

In a proposed policy statement released last month, the FTC said it was considering treating ideological bias in AI systems as an “unfair and deceptive practice” under Section 5 of the FTC Act.

The commission argued that consumers have an expectation that AI systems will provide them with information free from bias or ideological manipulation. Defining such bias as an unfair or deceptive practice would potentially allow the commission to regulate training or inputs that power AI algorithms. How precisely the FTC would determine when ideological bias exists in these systems is not fully explained in the document. 

Additionally, the statement suggests that the FTC believes this regulatory authority supersedes state AI laws. It specifically mentions the Colorado AI Act, which calls for models to be subject to risk assessments, transparency disclosures and “bias audits” before release. State lawmakers are now seeking to delay or eliminate the audits before the law takes effect in 2027.

CyberScoop reviewed dozens of public comments criticizing  the FTC’s proposal. Even ideological allies raised two main concerns: first, that the proposal distracts from real questions about the federal government’s role in regulating AI deception; and second, that it opens a Pandora’s Box by enabling political censorship of AI model outputs.

Leah Siskind, a former White House digital official and deputy director of the AI Corps at the Department of Homeland Security, told CyberScoop that AI companies face legitimate questions about their obligations to consumers, particularly whether they must ensure their models provide accurate information and protect against deliberate manipulation. 

Siskind’s past research has focused on how authoritarian propaganda tends to be overrepresented in answers provided by large language models, in part due to governments’ intentional efforts to poison data ingested by AI systems.

“There is a really interesting debate here about bias and about accuracy in models and whether that’s deceptive or not… about how we counter disinformation that has been absorbed and is now being reflected by LLMs…but this is not addressing that at all,” said Siskind, now a senior AI fellow at the Foundation for Defense of Democracies.

Instead, Siskind said the FTC statement appears primarily concerned about a power struggle with states over AI regulation and “petty squabbles about which AI model is more woke than the other.” She’s skeptical that the policy statement’s cited legal authorities are on sound footing.

“The way I see it is that the FTC’s role is to police consumer protection violations, not regulating AI systems, and it seems like they’re trying to solve a lack of congressional AI regulation by stretching section 5 [of the FTC Act] well beyond its traditional role,” she said.

Additionally, the policy statement’s language and sourcing suggests that the FTC is concerned with certain kinds of ideological bias more than others.

Anthropic, which has clashed with the Trump administration over AI guardrails and military applications of their technology, shows up more than half a dozen times in footnotes, many which are framed as examples of ideological bias the FTC is seeking to stamp out.

By contrast, the statement ignores a direct example of an American AI company owner influencing their model’s ideology: Elon Musk and his xAI-owned Grok model. Musk has publicly admitted, often on his own website, to intervening when Grok’s responses upset him. These interventions have shaped Grok’s outputs on specific topics, including South African race relations and the term “MechaHitler,” where the model now reflects Musk’s personal views.

But neither Musk and xAI are mentioned in the document, while Grok appears in a footnote which cites an advertisement for Grok as “your truth-seeking AI companion for unfiltered answers with advanced capabilities in reasoning, coding, and visual processing.”

Criticism across the spectrum

The FTC received more than 300 comments on its proposal from trade associations, think tanks, individual experts and members of Congress. Most criticized it as ill-defined and vulnerable to politically-motivated censorship, while some supported stronger rules against bias in AI systems. 

The International Center for Law and Economics noted the statement “offers little practical guidance about how the Commission will apply its deception authority to AI” and also does little to address hard questions, like where AI providers may be exercising their own First Amendment-protected activities.

The statement’s “focus on ‘ideologically motivated distortions’ suggests that the Commission’s concerns extend beyond factual misrepresentations in marketing to speech that may receive the highest degree of First Amendment protection,” the ICLE wrote.

The America First Legal Foundation, a conservative non-profit founded by top White House adviser Stephen Miller, pressed the FTC to adopt the policy “in full,” claiming that frontier models from OpenAI and Anthropic “have been programmed to prioritize ideologically liberal and progressive values as though they are objective, neutral positions rooted in truth.”

The group also argues that regulating these models’ ideological output falls under the FTC’s legal authority, because a “reasonable consumer” would expect that a model advertised for its usefulness and reliability would not prioritize liberal, ideological views.

“A reasonable consumer, based on AI companies’ advertising choices, would not expect that an AI system will adopt overwhelmingly liberal positions, thereby skewing results, or adopt a moral framework that would prefer to annihilate the earth rather than utter a slur,” wrote Emily Percival, senior counsel for America First Legal.

However, comments from other conservative groups questioned that rationale. The R Street Foundation’s Spence Purnell and Adam Thierer wrote that “the consumer expectations rationale is typically used in cases where there is an omission of information that should have existed.”

“Given that most LLMs already have disclosure statements [for their outputs], it seems unlikely that the FTC could explicitly prove that consumers were deceived about a product,” Purnell and Thierer wrote.

Reps. Josh Gottheimer, D-N.J., and Michael Lawler, R-N.Y., urged the FTC to carve out civil rights-related work from their scrutiny, such as preventing models from discriminating against users based on race, religion, gender, age and other federally protected characteristics.

“AI companies must not falsify facts in the name of fairness, but they also must prevent discrimination, stereotypes, and unequal treatment,” Gottheimer and Lawler wrote. “We would appreciate understanding how the FTC intends to ensure that these efforts remain permissible under the final policy framework.”

But the most common concern shared across the political spectrum was that the FTC could establish a precedent allowing the Trump White House and future administrations to reshape AI systems to reflect their political views.

David Inserra, Jennifer Huddleston and Juan Londoño of the Cato Institute point out that the FTC statement is conflating two different issues: ideological bias in AI systems and factual deception in marketing. 

“In other words, the FTC is trying to judge AI models’ accuracy and performance—two largely subjective variables—in the same way it evaluates dietary supplements’ medical-benefit claims or users being charged fees without proper notice or consent,” they write. “This is an absurd comparison.”

The post The FTC wants to regulate AI for ideological bias  appeared first on CyberScoop.

OpenAI says Daybreak will expand to offer specialized cyber services 

OpenAI announced Monday  it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers.

In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program  – which provides unreleased frontier models to private organizations and governments for defensive cybersecurity work – and introducing a new model variant.

Daybreak Blue, powered by OpenAI’s ChatGPT-5.6-Sol, would operate with lower cybersecurity safeguards compared to other commercially available models and is described as “a recommended starting point for most defenders” that supports tasks like vulnerability discovery, secure code review, malware analysis, incident response and patch validation. 

Daybreak Red, meant for more advanced red-teaming, would provide access to a new model, dubbed GPT-5.6-Cyber, that the company said is more purpose-trained for finding vulnerabilities and testing (or exploiting) them. The model is also less likely to refuse requests around “dual-use cyber tasks.”

According to OpenAI, the organizations in Daybreak Red will have their use closely monitored and supervised, as GPT-5.6-Cyber is significantly more capable in carrying out malicious cyber tasks than Sol. A security evaluation the company devised tested both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. Sol succeeded in 1.5% of the requests, while Cyber completed 95%.

OpenAI said it plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.

“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment,” the company said in a blog. “Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense.”

Additionally, OpenAI announced a partnership program with 16 major cybersecurity providers, saying organizations could access their models through their existing security services. The partners include IBM, CrowdStrike, Accenture, Ernst & Young, KPMG, Palo Alto Networks, Cisco, Cloudflare, Sophos and others. 

“These partners bring deep security expertise and established relationships with organizations around the world,” OpenAI said in its blog. “By bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them faster.”

Companies like OpenAI, Anthropic and others are trying to rebalance their priorities after a string of AI-agent sandbox escapes have rattled policymakers and caused some cybersecurity experts to question if AI companies are doing enough to properly isolate the models from the internet during testing. Last week, OpenAI said it was intentionally slowing down development of its newer “Astra” model in order to develop better guardrails to restrain its behavior.

Cybersecurity and AI experts have told CyberScoop that while AI systems have greatly improved at finding and exploiting vulnerabilities in software code, they still require substantial human guidance and supporting infrastructure to operate as intended.

Additionally, some research has shown that without such guidance, even near-frontier models can struggle to fully patch a discovered vulnerability or avoid introducing new bugs with their fixes.

The post OpenAI says Daybreak will expand to offer specialized cyber services  appeared first on CyberScoop.

NATO and an AI startup can now name and track software vulnerabilities

NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week

The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company with offices in San Francisco and Prague, joined as CVE numbering authorities under the ENISA Root. The CVE program assigns a unique record to each publicly disclosed security flaw so that governments, vendors and researchers have a common marker when referring to particular vulnerabilities. 

Twenty numbering authorities now sit under the ENISA Root, with 12 brought in by ENISA itself and eight moving over from the MITRE Root, run by the U.S. nonprofit that has handled the program’s daily work for more than 20 years.

Hans de Vries, ENISA’s chief cybersecurity and operations officer, linked the growth to changes in how people find flaws. 

“Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities,” he said in a statement. He said ENISA’s role helps build a “more globally representative, resilient, and scalable vulnerability identification ecosystem.”

The two new members show how bespoke each member is within its authority. The NATO Cyber Security Centre can now assign CVE IDs to eligible flaws across the NATO enterprise. The agency said that will make tracking more consistent and let the alliance share information with trusted partners sooner. The center guards NATO’s networks, watches for threats and coordinates the response when incidents hit.

Meanwhile, AISLE’s authorization is narrower. The company said in a July press release that the designation covers vulnerabilities discovered in its own products, allowing it to publish identifiers without waiting for a third-party authority to process a request. 

Jaya Baloo, the company’s co-founder, described the step as “foundational” and said coordinated disclosure “starts with holding your own products to the same standard you expect of everyone else.” Separately from the designation, the company said its researchers have disclosed hundreds of vulnerabilities in widely used open-source software, including OpenSSL, Linux, Apache and OpenEMR, each coordinated through the relevant authority for that project.

The changes come as the CVE process continues to involve amid program upheaval and the torrent of vulnerabilities discovered by AI systems. 

The CVE program, run by CISA, narrowly escaped a sudden demise when a last-minute, 11-month contract extension averted a shutdown in April 2025. Since then, several competing databases from European nonprofits and other private entities have been stood up in order to better coordinate how vulnerabilities are tracked, disclosed, and ultimately patched.

Earlier this year, The Computer Incident Response Center Luxembourg (CIRCL) launched the Global CVE Allocation System, or GCVE, as an alternative to the CVE program.

The post NATO and an AI startup can now name and track software vulnerabilities appeared first on CyberScoop.

U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang

U.S. and South Korean cyber agencies warned Monday about a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers’ tools to target government and critical infrastructure organizations.

Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and construction, media, retail, transportation and utilities. Its global scope is far-ranging, according to Monday’s alert: Africa, the Americas, the Asia-Pacific, Europe and the Middle East.

“Gunra is another variant in the ongoing trend of ransomware attacks causing disruption and harm to U.S. and international organizations,” said Chris Butera, acting assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, which produced the advisory with the Department of Defense’s Cyber Crime Center, FBI, National Security Agency, Secret Service and Republic of Korea’s National Police Agency.

The alert is part of the #StopRansomware series, a joint FBI-CISA project aimed at network defenders.

The FBI first took notice of Gunra in April of last year. The double-extortion group established a data leak site on Tor to list victims and publish purloined data. By January of this year, Gunra had launched a formal ransomware-as-a-service affiliate and was growing in its ambition, Monday’s alert states.

“The FBI observed the group adopting new branding aliases (notably operating under the name Golden Community) to support this expansion,” it reads. “Gunra has further commercialized its platform by actively recruiting penetration testers and ethical hackers to serve as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access.”

Gunra seeks initial access with known vulnerabilities in internet-facing devices like firewalls or virtual private networks, and is based on or influenced by the Conti ransomware code leaked in 2022, according to the agencies.

Research published in July by a South Korean cybersecurity firm took note of Gunra overlap with Lazarus Group, although it doesn’t explicitly mention the latter group’s name.

“These commonalities suggest that although the state-sponsored threat group and the Gunra ransomware group appear to be separate threat actors with different ultimate objectives, they may have shared certain techniques, tools, and infrastructure or collaborated to a limited extent during the attacks,” AhnLab wrote in its report.

That kind of North Korean government-ransomware gang collaboration dates back to at least 2024. Nor is Gunra alone among ransomware-as-a-service outfits recruiting penetration testers.

The post U.S., South Korean government agencies caution to be on lookout for Gunra ransomware gang appeared first on CyberScoop.

UK man tied to The Com sentenced for abusing 117 victims

A 20-year-old man in the United Kingdom was sentenced to two years in prison Monday after admitting to running an online abuse campaign that affected 117 victims across multiple countries during his time in the loosely organized online criminal network known as The Com.

Justin Swaddle, who was a minor when committed the crimes, pleaded guilty last month to a series of child sexual abuse offenses and blackmail. He was sentenced Monday at the same court and will be required to register as a sex offender.

The National Crime Agency, the U.K.’s lead law enforcement agency, had been investigating Swaddle since January 2024 after local police arrested him in October 2023 on charges of possessing, making and distributing indecent images. Investigators eventually found a broad online presence on Snapchat, Telegram and Discord, where he operated under usernames including “Epstein,” “Rugen” and “Moscow.”

A search of his phone and computer also turned up hundreds of sexually explicit conversations with young females, according to the NCA. Investigators determined Swaddle was part of The Com, a sprawling cybercriminal network of minors and young adults who engage in violence, extortion, sextortion and various forms of cybercrime. 

The NCA identified 117 female victims worldwide between the ages of 13 and 17, eight of them in the United Kingdom. One victim, 17, told investigators she met Swaddle on Discord in November 2022 before their conversations moved to Snapchat. She said Swaddle obtained her name, address and school details, then used that information to pressure her into various acts, threatening to expose her personal information unless she provided further images and videos.

“Justin Swaddle targeted young and vulnerable victims all over the world to abuse and scare them into carrying out shocking self-harm and sexual activity, purely to gain popularity with his peers online,” Danielle Pownall, an operations manager from the NCA, said in a release. “While the number of people involved in Com groups are relatively small, the impact it has on victims is high and long-lasting, as Swaddle’s offending shows.”

Law enforcement in both the U.K. and United States has been extremely active over the past few months in bringing Com-affiliated members to justice. Last week, a Canadian man who was linked with the group pleaded guilty for the widespread compromise of more than 165 Snowflake customer environments. Last month, a pair of young men tied to the Com were sentenced in the U.K. to 66 months in jail for committing a cyberattack on the Transport for London in 2024. 

The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.

Why transparent AI agents matter more than you think

As security operations teams now use large language models (LLMs) and autonomous AI agents into their daily work, a new frontier is emerging: attackers deliberately manipulating AI agents. Prompt injection attacks—where an attacker hides malicious instructions that cause an AI agent to ignore its safety rules—pose a serious risk to enterprises. These attacks continue to grow in size and scale.  

Snyk’s security audit of the Agent Skills ecosystem, which includes Anthropic’s Claude, Vercel, and others, that 36% of all skills contained at least one critical-level security issue, including malware distribution, prompt injection attacks, and exposed secrets.

In June, researchers at Mozilla tested a prompt injection attack on Claude using indirect prompt injection—a technique that embeds malicious instructions in external content the AI agent processes. In this proof-of-concept, attackers took over developers’ systems by hiding indirect prompts in normal-looking repositories. When Claude Code executed them, the agent spawned a reverse shell.

AI agents often connect to more sensitive data than human employees do., A successful prompt injection can lead to catastrophic data loss or unauthorized system actions. Defending against prompt injection attacks requires multiple layers of protection. Security teams must monitor agent behavior for anomalies and prepare for agent containment, forensic preservation, and system remediation. Because AI agents execute tasks at machine speed, human responses must be able to match that pace.

The architecture of trust: Protocols and no “black box”

AI-native workflows need governed access rather than “black-box” autonomy. Modern governance frameworks use standardized protocols like the Model Context Protocol (MCP) to provide secure communication between AI clients and data sources. Visibility and transparency in agentic AI workflows matter, especially in cybersecurity. Autonomous agents perform complex tool executions and use independent logic, so they must show how they reached their decisions to meet regulatory requirements. Agents without transparency post serious risks: obscured reasoning can trigger unpredictable tool interactions, bypass governance controls, and create uncontrolled defensive gaps.

Implementing these protocols matters:

  • Bounded Tenant Awareness: In a stable agentic AI architecture, multi-tenancy scales well. But if an AI tenant misbehaves, the entire system can fail. Bounded tenant awareness isolates any misbehaving AI agent to prevent cross-tenant contamination or data leakage.
  • Strict Access Controls: By controlling connections to the platform, organizations can stop “ignore previous instructions” style bypasses. Maintain tight control over what the AI can see and do within a workflow.
  • Standardized Telemetry: All telemetry must remain consistent and audit-ready. Even if an AI interaction is attempts to break rules, the underlying data movement gets tracked against established frameworks like MITRE ATT&CK and NIST.

Detecting the aftermath: UEBA and NDR as safeguards

A robust, unified SecOps platform can detect anomalous behavior even after prompt injection tricks an AI agent. Prompt injections often serve to steal credentials theft or extract data. When detected it’s important to act quickly. In agentic AI systems, misbehavior can escalate privileges, manipulate memory layers, create unauthorized identities, or alter shared reasoning components. Containment must be automatic and enforced at identity, authentication, and authorization layers.

These safeguards include:

  • User and Entity Behavioral Analytics (UEBA): Identity-focused correlation and behavioral baselines to identify anomalous user activity or privilege escalation. If a compromised AI agent acts outside of its normal operational parameters, UEBA flags it in real-time and alerts a human security analyst.
  • Network Detection and Response (NDR): Combining network traffic analytics with endpoint and cloud telemetry, NDR can identify data exfiltration or policy violations from a successful prompt injection.
  • Multi-Layer AI Filtering: AI filters reduce raw alerts into high-fidelity incidents, cutting noise by up to 90%. This keeps the signals of an AI-driven attack from disappearing in a busy SOC.

Humans remain the strongest defense against AI agent social engineering. The human security analyst is still the one who makes the final decision. While AI handles triage and correlation, humans retain final control over response actions.

Moving beyond reactive guardrails

The traditional SOC model was never designed to handle machine-speed, AI-driven attacks. A human-augmented autonomous SOC approach moves from reactive alert handling to a proactive, verdict-first model. By combining a transparent, governed AI access with robust UEBA and NDR, organizations keep the SOC secure, transparent, and resilient as social engineering methods target machines.

The post Why transparent AI agents matter more than you think appeared first on CyberScoop.

More than half of AI-generated patches are broken

As AI-generated code continues to be injected into all corners of the internet, concerns have risen about an expanding attack surface for malicious hackers to exploit.

Some have argued that the enhanced cybersecurity capabilities of large language models could serve as a check, finding and fixing vulnerabilities nearly as fast as they’re created.

But new research that tested the patching capabilities of two popular commercial models, OpenAI’s ChatGPT 5.5 and Anthropic’s Claude Opus 4.8, found that generative AI is more likely to create an exploitable patch or introduce entirely new bugs than close off a vulnerability.

Researchers at 1Password tested the models ability to patch six “high-impact, high-complexity” CVEs, including the “Copy Fail” vulnerability, a kernel flaw that can give an attacker root access to Linux cloud environments. The overall success rate (or fully patching the vulnerability without introducing new problems), was less than a coin flip at 47%.

“Our research findings show that, in aggregate across a variety of scenarios, both Claude and ChatGPT had a low rate of successful patch generation, which we define as full remediation of all known exploit paths with no erroneous changes to application behavior,” wrote Keith Hoodlet, Axel Mierczuk and Spencer Michaels.

“The models often addressed only a subset of vulnerable code paths, added fragile guard code that satisfied tests while failing to address the vulnerability’s root cause, and sometimes introduced subtle changes in the application’s behavior while patching the immediate vulnerability,” the authors continued.

The research suggests that largely autonomous vulnerability-discovery and patching may not yet be effective in fixing the explosion of vulnerable code that is being created in the AI era.

Other private sector research has pointed to a similar problem. A report this year from Veracode found that while LLMs have made “enormous strides” in crafting workable code, “security is a different story.” Testing across a range of frontier models found the average security “pass rate” for AI generated code is around 56%. Newer models like GPT 5.5 push closer to 70%, while more than half sit between 50-53%.

Veracode tested 100 different models and while there was variability, in general a small number of models were showing progress on security patching while the rest have experienced “stagnation.” Similar to the 1Password research, in 44% of Veracode tests the models introduced a detectable OWASP Top 10 vulnerability into the codebase.

An important caveat: neither report tested newer models, like Anthropic’s Mythos or OpenAI’s GPT-5.6-Sol, that frontier companies tout as having significantly higher cybersecurity capabilities.

Those advanced models can identify and fix vulnerable code. Anthropic and OpenAI are distributing them to key industries through Project Glasswing and Daybreak before foreign or open-source alternatives can compete.

Tim Jarret, vice president of product at Veracode, told CyberScoop that AI tools are still subject to a range of limitations that can make them unreliable for cybersecurity patching without knowledgeable humans in the loop.

While some vulnerabilities – like SQL injections – can be easily patched through automation, other bugs like cross-site scripting, can be exploitable in several different ways and require either a human touch, additional context or both to fully close off. Additionally, models can slowly lose context from prior sessions over time, affecting their ability to complete tasks correctly and raising the possibility they’ll hallucinate to fill in the missing gaps.

“I think we would say, at this point, that Iits premature to treat those as anything other than another code change to the code base that needs to be reviewed and accepted by the team, as opposed to letting the agent merge the code freely,” said Jarrett.

However, he acknowledged that may not be possible in a world where AI agents are generating exponentially more code for human defenders to review. Some kind of automated code review will be necessary – preferably not by the same automation tool that produced the code. The ultimate goal is the same as it has always been in security: “trust but verify.”

“Ninety percent of the time, the human check might just be ‘did the cross check look good?’ Do we have a thumbs up?’” Jarrett said. “In those cases where there’s still something wrong, that’s where you focus your attention a little bit more.”

The post More than half of AI-generated patches are broken appeared first on CyberScoop.

Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports

The U.S. Coast Guard said it is monitoring the aftermath of a cyberattack that disrupted gate operations at all three of North Carolina’s port facilities this week, though it offered few details as the investigation into the breach continues.

A Coast Guard spokesperson told CyberScoop that the branch’s IT unit was coordinating with partner agencies while conducting the investigation. A spokesperson for CISA did not respond to CyberScoop’s inquiry by press time. 

The Coast Guard is one of several state and federal partners the North Carolina State Ports Authority brought in after discovering the attack on its systems earlier this week. The breach affected the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port, forcing the agency to delay gate openings and shift to manual processing while it worked to contain the intrusion.

A spokesperson for the ports authority told local media its IT team activated the agency’s cybersecurity contingency plan upon discovering the attack, as well as reaching out to state authorities for further support. 

As of Friday morning, a notice on the ports website said a normal operating schedule was in effect while the IT teams continued their investigation. It has not disclosed the nature of the attack, which systems were affected, or whether vessel operations, cargo-handling equipment or rail services were disrupted.

North Carolina’s ports serve as a trade hub along the southeastern U.S., with Wilmington in particular functioning as a gateway for agricultural exports, retail goods and raw materials.

The North Carolina Ports Authority said it would continue posting updates on its website and pointed users toward its email alert service for further information. It did not provide an estimate of how much truck or cargo traffic has been affected by the disruption.

The incident adds to a recent string of cyberattacks against water and wastewater systems in the U.S., which also fall under the umbrella of “critical infrastructure.” While there has been no official attribution, experts have expressed confidence that Iranian actors are responsible for the attacks on water systems.

As of Friday morning, there has been no public information tying the port cyberattack to a specific actor.  

The post Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports appeared first on CyberScoop.

Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams

Senators from both parties Thursday probed Trump administration officials about whether federal agencies and foreign governments are coordinated enough in the battle against scammers, something witnesses told the Foreign Relations Committee they were working to remedy.

At least 13 federal agencies have authorities to counter scams, raising questions about whether someone needs to be in charge of all those efforts. And while there was some bipartisan sentiment at Thursday’s hearing that the Trump administration has taken good actions to battle scammers, both lawmakers and administration officials said that scam operations have demonstrated that cracking down on them in one place often just leads to them going elsewhere.

Sen. Pete Ricketts, R-Neb., compared the situation to an international initiative that gained prominence in the 1990s to counter drug trafficking, Joint Interagency Task Force South.

“Given that today’s scam centers are similarly transnational, combining cybercrime, human trafficking, money laundering and cryptocurrency, has the threat reached the point that we should establish a comparable multinational coordination mechanism?” he asked.

Sen. Jeanne Shaheen, D-N.H., focused on federal coordination: She paraphrased a former federal official who said, “there is nobody that is heading that effort up across agencies. We need to treat this like combat, and so we need somebody in charge.”

Shaheen, the top Democrat on the panel, is a co-sponsor of the bipartisan Scam Compound Accountability and Mobilization (SCAM) Act, which seeks to unify federal efforts on the subject.

A State Department official told Shaeen scammers were a national security priority for President Donald Trump, and that his executive order on the topic sought to tackle coordination.

“I do understand that this is a whole-of-government approach, and many agencies are focused on this,” said David Bedard, deputy assistant secretary at State’s Bureau of International Narcotics and Law Enforcement Affairs “The Action plan that was directed by the president is currently in the interagency review process to deconflict some of the concerns that you have raised. We certainly think the task force that will be implanted through the executive order will solve the problems you might be referencing.”

There’s also an international plan under the task force, he said. Currently, the administration shares intelligence on scammers with foreign allies, and Interpol has “productive” channels to work through there and is setting up its own task force, Bedard said, but there are concerns about other countries taking similar, duplicative action.

There have been signs of progress on the international front, Bedard and another State Department witness told the panel.

Michael DeSombre, assistant secretary at the Bureau of East Asian and Pacific Affairs, said Trump has raised the subject with Chinese President Xi Jinping, and that China has used its influence in Asia as its own citizens have become scam victims. Still, there’s been more progress in countries where the United States has stronger relations, such as Cambodia, than in those where ties aren’t as close, like Burma and Laos.

In Cambodia, one key has been pursuing scam center bosses first and foremost, Bedard said.

The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop.

Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online

A new scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems.

The findings, published Wednesday by Forescout’s Vedere Labs, show that direct internet access to equipment used in water and wastewater operations remains common despite years of warnings from manufacturers and federal agencies.

The exposed devices use EtherNet/IP, an industrial protocol that allows for communication between control equipment, engineering workstations and other systems. When the port is open to the public internet, outside users may be able to identify devices and, depending on their setup, change settings or write new configurations.

The scan, run through the Shodan search engine Monday, found that 2,844 of the exposed controllers (65%) were in the United States.

The FBI and Environmental Protection Agency issued a joint advisory last week confirming attacks at water and wastewater utilities in at least 12 states since July 27. Officials have since named Michigan, South Dakota and Georgia among the affected states. Nine systems were hit in Michigan, and one wastewater lift station was hit in South Dakota.

Several reports have linked the attacks to Iranian actors, but Sai Molige, senior manager of threat hunting at Forescout, says the company has not attributed this activity to any actor or group.  

“The evidence supports opportunistic, at-scale exploitation of a known class of vulnerabilities affecting internet-exposed devices,” Molige told CyberScoop. “The scale and speed of the activity are more consistent with mass scanning and enumeration than with zero-day exploitation, a months-long intrusion campaign, or custom malware.”

The advisory said attackers targeted programmable logic controllers (PLCs) made by Rockwell Automation under its Allen-Bradley brand, specifically the MicroLogix 1100 and 1400 models. In at least one case, attackers reached controllers remotely and changed their IP addresses and passwords, cutting off the utility’s own view and control of the equipment. The advisory said the attacks caused pressure loss and flooding.

Forescout’s research states that the most common exposed device family was the MicroLogix 1400, which made up half of the devices found. Other versions, such as AllenBradley’s CompactLogix 1769 controllers, made up 22%. MicroLogix 1100 and ControlLogix 5590 devices each accounted for about 8%.

Forescout cross-referenced those machines against the recently targeted cities and municipalities and found 22 devices still exposed to the internet. However, the company did not say those systems had been attacked or that they belonged to the affected utilities.

The research also found that 19 of the 22 hosts in affected cities appeared, based on firmware versions, to be open to CVE-2017-16740, a remote code execution flaw disclosed in 2017 that impacts MicroLogix 1400 devices. An attacker would need Modbus TCP enabled to use that flaw, and the researchers could not confirm whether the affected systems had it enabled.

Rockwell Automation and other industrial equipment makers have warned customers not to place controllers directly on the public internet as far back as 2018.

Beyond the controllers, the researchers also looked at the digital records tied to these utilities. They found expired certificates, remote-access web addresses left unrenewed for months or years, and servers that appear abandoned — in one case, a server that has shown nothing but a default Microsoft webpage since April 2019. 

“These stale services can increase the attack surface; however, we have not yet confirmed how the observed attacks occurred,” Molige told CyberScoop.

The post Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online appeared first on CyberScoop.

Ransom Cartel creator sentenced to 16 years in prison

A longtime cybercriminal was sentenced to 16 years in prison for creating and running Ransom Cartel, a ransomware strain linked to attacks on at least 18 companies between 2021 and 2023, the Justice Department said Wednesday. 

Maksim Silnikau, a Belarusian national, actively participated in Russian-speaking cybercrime forums since at least 2005, and was a member of the cybercrime site Direct Connection from 2011 to 2016, officials said. The 40-year-old created Ransom Cartel and began recruiting participants from cybercrime forums in 2021. 

Silnikau and his co-conspirators attempted to extort at least $5.2 million from victims during the multi-year scheme. 

Victims included a group of law firms, medium-sized businesses, a small medical technology startup, educational institutions and large multinational corporations based in California, New York, Nebraska and elsewhere. Some of the victims’ operations were disrupted for several months, officials said. 

Officials said Silnikau provided his co-conspirators information and tools to attack systems, including stolen credentials and mechanisms to encrypt compromised computers. He also built a site to monitor and control ongoing attacks, communicate with co-conspirators and victims, negotiate payment demands with victims and manage the distribution of funds between co-conspirators. 

Silnikau, also known as “J.P. Morgan,” “xxx,” and “lansky,” fled from Spain while awaiting extradition to the United States and was arrested in Poland in July 2023 as he tried to return to Belarus, according to court records. He was extradited to the United States in August 2023. 

Ransom Cartel’s operations ended when Silnikau was arrested. Authorities applauded his capture at the time, noting that Ransom Cartel didn’t grow large enough to inflict losses comparable to larger ransomware variants. 

Silnikau pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft.

The post Ransom Cartel creator sentenced to 16 years in prison appeared first on CyberScoop.

The water sector just got it’s wake-up call. Again.

Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment. Some of these attacks degraded operations. Utilities reported pressure loss and flooding, several systems reverted to manual control, and one Minnesota community declaring a local state of emergency.

Nothing about these attacks required sophisticated methods. The attackers didn’t use zero-day exploits or novel malware. They found controllers exposed to the public internet, many of them so old that they stopped receiving security patches years ago. They logged in, changed IP addresses and passwords, and locked operators out of their own equipment. In at least one case, they modified the ladder logic controlling industrial equipment. These were not Hollywood-style hacks. The controllers sat exposed and undefended.

If this feels familiar, it should. In late 2023, attackers compromised controllers at water utilities across several states, including the widely reported incident in Aliquippa, Pennsylvania. The federal government issued guidance then, too. One of the crucial differences between then and now is that attackers have grown in ambition. They’ve moved from defacing screens to disrupting operations across dozens of systems at once, exploiting the fact that third-party integrators often deploy the same vulnerable configuration across many small utilities. 

The uncomfortable truth is that this was preventable. The reason it wasn’t stopped is more structural than technical. The United States has roughly 50,000 community water systems. Most are small, publicly funded, and run by operators whose primary job is keeping water safe and flowing. Cybersecurity ranks far below that, if it ranks at all. The devices in question are often a decade or more old and replacing them takes capital these utilities don’t have. Rules governing water cybersecurity remain mostly voluntary. Attackers understand these economics perfectly. We should too, yet these attacks keep happening.

 But inaction is a choice. The defenses that work here cost little and require no exotic technology. The FBI and EPA guidance is sound, and every water and wastewater organization should act on it this week, not later. Here’s how:

  • Get controllers off the public internet. No PLC should be reachable from the outside world. Remote access should go through a secure gateway that mediates, monitors, and logs every connection. That includes cellular modems, which are the overlooked entry point in nearly every audit.
  • Fix passwords. Default and shared credentials are still the most common way in. Strong, unique passwords are the cheapest security control available.
  • Restrict communication between devices. Firewall rules and access control lists should allow only expected communication between known control system devices. Block traffic from hosting providers and other sources that have no business touching a water plant.
  • Lock the logic. Keep physical and software key switches in the run position except during authorized updates. This prevents unauthorized changes to configuration and firmware.
  • Practice running manually. The utilities that survived these attacks best were the those that switched to manual operations quickly. That skill requires constant practice.
  • Verify, don’t assume. Nearly every utility believes its PLCs aren’t internet-exposed, right up until an inventory proves otherwise. You can’t protect what you can’t see. Most operators are surprised by what a complete asset inventory reveals: forgotten modems, integrator-installed remote access, devices nobody knew were still online.

Every attack like this follows the same pattern. Attackers change configurations, reset passwords, and modify project files. Every one of those actions creates a signal on the network before operations degrade. In this most recent case, one victim only noticed ladder logic discrepancies across multiple sites. Catching intrusions shouldn’t depend on a sharp-eyed engineer having a good day. Continuous monitoring of OT environments exists to turn those signals into alerts within minutes instead of days. That difference is the difference between an incident report and a boil-water notice.

Water systems have the least margin for error and, too often, the fewest resources to defend themselves. The FBI and EPA have told us plainly what’s happening and what to do about it. The attackers are betting we won’t follow through. For the third time in three years, they’re testing that bet.

Let’s finally prove them wrong.

The post The water sector just got it’s wake-up call. Again. appeared first on CyberScoop.

Snowflake hacker pleads guilty, faces up to 32 years in prison

A Canadian man pleaded guilty to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion, the Justice Department said Wednesday. 

Connor Moucka earned $495,000 by extorting his victims, offering stolen data for sale online, and in one case re-extorted a victim with stolen data of a government official and members of a then-former government official’s immediate family, authorities said.

Moucka and his alleged co-conspirators John Binns and Cameron Wagenius stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors. Victims of the attack spree included AT&T, Ticketmaster, Advance Auto Parts and Santander.

“Hiding behind a screen is no shield from justice,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said in a statement. “Moucka learned that when he was arrested just months after he began targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars.”

Authorities arrested Moucka relatively quickly because he caused significant damage, said Allison Nixon, chief research officer at Unit 221B. 

“His gang went on a spree of maximizing harm, which directly correlated to maximizing the resources devoted to stopping it,” she said. 

“His behavior was bizarre throughout. Even while stealing data and extorting victims, he did many unnecessary things like threatening me because he thought I was working on his case. I was not working on his case before he threatened me,” Nixon added.

Moucka, who used several aliases online, including “Waifu,” “Judische,” “Catist” and “Ellyel8,” was arrested Oct. 30, 2024, in Kitchener, a city in the Canadian province of Ontario, at the behest of U.S. authorities. He was extradited to the United States in March 2025.

Moucka and his co-conspirators used stolen credentials to access the data storage platform’s customers’ accounts en masse. Records of more than 100 million people were exposed by the data theft campaign, including call and text history records, banking and other financial information, payroll records, government ID numbers and other personally identifiable data. 

Officials said victim companies bore more than $9.5 million in losses combined, not including losses attributable to their respective customers. 

Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” W. Mike Herrington, special agent in charge of the FBI Seattle field office, said in a statement.

Researchers said Moucka and his co-conspirators are all associated with The Com, a sprawling cybercriminal network of minors and young adults who engage in violence, extortion, sextortion and various forms of cybercrime.

“His legacy is one of failure. He extorted and then scammed his victims by not deleting the data, casting doubt on all future pay-or-leak extortion gangs,” Nixon said. 

“The pay-or-leak business model was popularized by him and his gang,” and his claims of data deletion were a lie, she added. “With copycat gangs, defenders grapple with the uncertainty of whether the threat actors are honest.”

Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy. He is scheduled for sentencing Oct. 27 and faces up to 32 years in prison.

The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.

Open-source software’s archenemy TeamPCP goes back further than anyone thought

TeamPCP, the threat actor behind an unrelenting flurry of attacks on open-source software this year, has been active much longer than previously thought, according to research Oligo Security shared exclusively with CyberScoop. 

The threat actor, which gained notoriety and has captivated threat hunters as it compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year, was also responsible for attacks dating back to 2020, Oligo Security found. 

The security vendor’s research team found multiple attacks that bear the markings of TeamPCP, including a late 2025 campaign involving the exploitation of a ShadowRay vulnerability that resulted in the first self-propogating botnet running on hijacked AI infrastructure.

Evidence uncovered during that investigation into the ShadowRay 2.0 campaign was linked to more historical attacks originating from the same IPs, domains and other infrastructure TeamPCP used in attacks that captured widespread attention earlier this year. 

“The scariest thing in this campaign is the speed at which the payloads evolved and changed and adapted to the environment they run in. We saw changes in the speed that we’re not used to seeing in these kinds of attacks. They’re usually slow, careful,” said Uri Katz, director of research at Oligo Security. “This was clearly with the help of AI — the payloads changed rapidly to adjust and change to the environment that they were trying to attack.”

One of the domains that Oligo Security identified in July 2025 was in the profile of TeamPCP’s official GitHub account, said Avi Lumelsky, AI security researcher at Oligo Security. “It’s public, they’re not even trying to hide their identity,” he said. 

From there, Oligo linked TeamPCP to activity tracked under multiple names, including TA-NATALSTATUS and IronErn, spanning from 2020 to late 2025. Much of that activity was traced to the same IPs, domain names, a file server and command-and-control server, researchers said. 

TeamPCP emerged publicly as a brand in late 2025. Soon after, “TeamPCP started to go really broad and do campaigns, which are much more noisy,” said Gal Elbaz, co-founder and CTO at Oligo Security. 

Widespread adoption of AI and TeamPCP’s use of the technology supported this growth as the threat actor built a brand, got more active on social media and boasted publicly about its activities and claimed victims.

“The ability to control the infrastructure and orchestrate the attack with AI was also super new, and I’m sure it helps them,” Elbaz said. 

“All of the companies in the world are in this race to adopt AI because they are afraid their business will die, and they understand, of course, the opportunity. But it’s also what gives the attacker this power to go into it,” he added. “If you don’t really have visibility in what’s going on there or how it behaves, that’s exactly what attackers are after.”

TeamPCP’s more recent attacks have capitalized on new security gaps created by developers’ increasing reliance on AI and the automated systems companies use to deploy code. The threat actor is also consistently wrecking the open-source frameworks and software packages these systems rely on. 

“Most AI infrastructure is open source by design because nobody has the manpower and money to develop everything from scratch,” Lumelsky said. 

“We love open source. We use many of these products ourselves, but it’s all about reading the documentation, and I think many of these tools place the responsibility of using it right and security on the user, and developers are not used to these new kinds of animals,” he added. “That’s why the trust can be exploited at scale.”

As it uncovered a long operational history spanning multiple campaigns, Oligo Security has gained more confidence in understanding how TeamPCP operates. It also means TeamPCP was likely involved in other attacks that haven’t been attributed to it yet or attacks that haven’t been detected. 

“There’s a lot more out there that we haven’t caught or been able to prove up until now,” Elbaz said.

The post Open-source software’s archenemy TeamPCP goes back further than anyone thought appeared first on CyberScoop.

AI is getting better at election facts, but voters shouldn’t rely on it

Like seemingly everything else these days, artificial intelligence will re-shape the way voters gather information on candidates running in the 2026 midterm elections.

In some ways, this is already the reality. Voters are increasingly turning to AI chatbots for information instead of Google.  Political campaigns are deploying deepfakes of their opponents. And AI systems have been developed to carry out increasingly complex  hacks.

Since the last major U.S. election in 2024, major tech companies have  embedded AI into their products while hundreds of millions of people have adopted the tools, either by purchasing subscriptions to commercial models or using open-source models. Yet both research and experts state that while AI systems have gotten better at handling basic facts, they’re nowhere near reliable enough to be a main source of  accurate or complete information. 

While chatbots are becoming a primary way that voters gather information on  local races, candidates, issues, and voting information, they are not substitutes for more authoritative sources, like a voter’s state or local election office. 

“I think this is one of the first elections we’re seeing…where AI is just everywhere,” said Thania Sanchez, senior vice president of research and analytics at the nonprofit States United Democracy Center. “Even if you just Google it, [now] the first thing that comes up is the AI overview.”

While AI companies have worked to cut down on errors in their model’s responses for questions around basic election information, they continue to fall short in important ways.

In new research shared exclusively with CyberScoop ahead of its release, States United Democracy Center tested two of the most popular tools — OpenAI’s ChatGPT’s free tier and the AI interface used alongside Google Search — for their performance on a series of basic questions around elections, such as how to register to vote, or a list of candidates in a race.

The models were chosen because they are free and easy to access. For Google AI, the nonprofit tested two types of accounts: ones running in Incognito Mode and ones that had a history of browsing election-skeptical websites.

The nonprofit ran two rounds of testing in 2025 and 2026, collecting nearly one thousand responses from the models submitted by users across six swing states (Arizona, Michigan, North Carolina, Nevada, Pennsylvania and Wisconsin).

In 2025 tests, 6.9% of responses from Google AI and 8.2% responses from ChatGPT“contained verifiable factual errors,” like not listing the correct candidates in a race or false guidance around polling site locations.

However, follow up tests in 2026 across Arizona, Pennsylvania and Michigan found that the error rates in both models had dropped to zero. The study notes that “this is real progress and should be acknowledged.”

But underneath those topline numbers, a more murky picture emerges around the tools’  reliability.

An AI response can sound accurate without actually being complete.  To wit: ChatGPT provided incomplete lists of current gubernatorial primary race candidates 88.9% of the time when queried.

Linking to a state election website – an output the study considers the single most important measure of voter utility  — happened less than 40% of the time. Whether due to formatting issues or the model ingesting outdated information, it’s a problem if voters use them as their primary information source for elections.

“It will be like ‘this person is the Republican candidate and this person is the Democratic candidate’ but it is not telling you there’s also these other third-party candidates,” said Sanchez. “It’s not giving you complete information, so the voter thinks these are the [only] two people running.”

A June survey from the Pew Research Center found that about half of U.S. adults reported having used chatbots at least once, up from a third in 2024, while a quarter reported using them daily. The top use case listed for engaging with the chatbot was searching for information.

Isabel Linzer, an elections policy analyst at the Center for Democracy and Technology, told CyberScoop that voters, campaigns and governments alike are using AI more freely and with fewer restrictions.

Bad actors in the information space have followed suit, and “we are in a phase now of generative engine optimization” where information operations are structured to rank higher in AI model responses.

“We’ve moved beyond [SEO] to [Generative Engine Optimization], and that’s where we’re seeing campaigns thinking about how to structure their materials to make sure that they are in a format that AI models want to use when they’re searching the web…to develop their responses to user queries,” she said.

There is also the underlying problem of frontier AI companies constantly tinkering with their models, their algorithms and the technologies they are intertwined with. . Election officials, by contrast, have decades of experience educating voters about their options.

A prime example of this churn occurred this past February, in between the first and second round of the study, when Google AI suddenly shifted to providing only links for election related queries in incognito mode, replacing the written summaries that showed up in the first round.

Like the study’s authors, Linzer said most people are still best served by going directly to local sources for accurate information on elections. With issues like ideological bias, the potential for bespoke or sycophantic answers for each user based on their prior chat histories and lack of predictability, voters should still be very careful about using AI chatbots as political truth machines.

The best thing that tech companies can do to educate voters is “making sure that for high-stakes situations like elections, that chats are connecting directly to the most important sources, like the website where you can actually register to vote,” said Linzer.

The post AI is getting better at election facts, but voters shouldn’t rely on it appeared first on CyberScoop.

National cyber director lays out White House plans to secure AI without writing new rules

The Trump administration executive order on artificial intelligence tried to strike the balance between responsible use, security and mutual benefit, all with an eye toward not making it regulatory in nature, National Cyber Director Sean Cairncross said Tuesday.

“Everyone is working towards the same goal in terms of protecting the country and securing our systems, and we are trying to ensure that defenders have this technology as quickly and at scale as possible, but there are obviously specific security concerns, and industry has been very sensitive to this as well,” Cairncross said at the Black Hat 2026 conference in Las Vegas.

The security concerns about AI have moved to the forefront of discussions about the technology after OpenAI models escaped a test environment to hack the company Hugging Face last month.

“The design of this is that when there is something that happens, when there is a breach, when there is an event, that that system, that network of connections can exist, adapt to that, and seek to remedy that as quickly as possible, so that form follows function rather than turning that upside down, and as usual with the government pen just proceeding in a vacuum,” Cairncross said.

The Trump administration has drawn criticism over whether it has struck the right balance on AI rules. Trump’s AI executive order notably got pulled just before its scheduled release, with the final version signed in June missing some aspects that had drawn industry opposition.

“What needs to be built is a flexible, adaptable structure that enables information sharing between industry and government, so we can guarantee that this technology benefits everyone it’s going to benefit, but is used responsibly and securely,” Cairncross said.

He said the administration is working with industry during implementation of the executive order.

“A regulatory regime would not only strangle growth, development, and innovation, and be enormously harmful to the industry, but it would be obsolete 48 hours after it was gone through whatever process it had gone through,” Cairncross said.

Open source will play a “vital” role in the U.S. spreading its vision for AI across the globe, he said.

“We are extremely interested in looking at ways to build U.S. open source, make it competitive, make it the preferential adoption by planet Earth,” Cairncross said. “We understand and appreciate the value to the ecosystem that it has, the innovation, the startups who rely on it, the leap forward it makes possible in ways that otherwise would never happen. And so I think it’s an incredibly thriving ecosystem in AI right now, and we are looking to do what we can to grow, foster, and push that U.S. open source model.” 

Speaking at the same conference, Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency, seconded Cairncross’s comments about AI executive order implementation. He touted the Gold Eagle clearinghouse as one example.

“Those are fantastic opportunities we have to really provide a unifying function around the way that we’re going to do AI-enabled vulnerability reporting and disclosure at scale in a way that we haven’t had to do before with some of our legacy platforms, and just continue to expand out those opportunities,” he said. “That access — to build off the director’s point earlier — to really enable that industry collaboration, that’s so key and critical to us as we move forward.”

Matt Kapko contributed reporting to this story.

Updated 8/5/2026: to include comments from Andersen.

The post National cyber director lays out White House plans to secure AI without writing new rules appeared first on CyberScoop.

AISI, OpenAI report more ‘unsanctioned’ model hacks

The UK’s AI Security Institute said that their AI research system took “unsanctioned” actions over the internet to engage in “sustained, potentially harmful activity directed at real people.”

According to a blog post and technical report released Tuesday, the organization noticed “unusual data transfers” leaving their research systems through the pseudo-anonymous Tor network on July 28. The models, which included Anthropic’s Mythos 5 and OpenAI’s GPT-5.6-Sol models, were being tested for their cybersecurity capabilities.

Like the OpenAI and Anthropic incidents before it, the offending agents were attempting to solve a challenge. On 10 of 122 runs taken by two models, they took a combined 19 malicious actions, including attempting to insert malicious code into a real open-source software project and creating fake online identities to contact human maintainers and press them to approve it.

It also inserted malicious prompt injection instructions in places “where it reasoned that other automated AI systems might pick them up and execute them.” Sometimes multiple agents would collaborate on a task, with one model leaving public messages or notes for the other on GitHub.

However, AISI said their incident differs in one critical way.

“Importantly, this was not a case of a model escaping its secure test environment, or ‘sandbox,’” the institute wrote in an unsigned blog. “As was standard in our cyber testing, we had intentionally permitted internet access, and model-provider cyber classifiers were deliberately disabled – conditions that do not reflect how frontier models are made available to the public.”

The institute said that while their own design and evaluation choices “to some degree” enabled the malicious behavior, the models still displayed “novel, potentially deceptive behaviors” and were executed “to an extent and severity that we did not anticipate.”

The same day, OpenAI acknowledged AISI and another third-party cybersecurity tester,  private firm Irregular, had recently reported incidents where their models exceeded “beyond their intended testing boundaries.”

That included GPT-5.6-Sol reusing GitHub tokens left by another agent to attempt to recover accounts and to access a DNS server that contained malicious payloads meant to exploit a software vulnerability.

The setup did not work, there is no evidence any real resolver queried it, and the infrastructure was removed when the evaluation ended,” the company wrote in an unsigned blog post Tuesday.

OpenAI said it would review its own third-party testing procedures to focus on higher risk evaluations, assess requests by third-parties to enable internet access, stop conditions and other features for their models.

The incident with Irregular occurred on July 29 during a Capture-the-Flag cybersecurity evaluation of OpenAI’s models. Due to a “misconfiguration” the models were allowed to access the public internet, where they encountered and exploited a real domain, mistakenly believing it was still in a test environment.

OpenAI said an investigation by Irregular is ongoing, but also found that the models had found and used credentials for the site at one point. The blog also references other additional potential cybersecurity incidents.

“Irregular has informed us that all of the issues identified pertaining to the incident are no longer active and relevant safeguards were added to the testing environment,” the blog said. “Irregular has also communicated about related incidents involving other labs from the same testing environment.”

CyberScoop has reached out to Irregular for comment.

The incidents were made public the same day that the White House met with Anthropic, Open AI and other frontier AI companies to preview a new framework for evaluating models before they’re released publicly. Some media outlets have reported that after an executive order, export controls and other actions, the administration does not plan to make the new framework public.

The post AISI, OpenAI report more ‘unsanctioned’ model hacks appeared first on CyberScoop.

Massive supply-chain attack compromises 440 packages under four hours

In less than four hours early Tuesday, an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms. 

The worm, built on the open-source Mini Shai-Hulud repository that TeamPCP published in May, was initially let loose in keyv, a data management interface software package with more than 600 million monthly downloads. The attacker spent the next 30 minutes compromising additional packages controlled by the same maintainer, including cacheable, flat-cache, file-entry-cache.

The attack spread to other maintainers, eventually compromising more than 860 packages with a “combined total of over 2 billion monthly installs,” Ilyas Makari, malware researcher at Aikido Security, wrote in a blog post

Wiz researchers told CyberScoop it hasn’t observed any new malicious packages since the initial wave moved through a massive footpoint of cloud and code environments in those first four hours. 

“This is the most critical initial compromise, with over 155 million weekly downloads on the root packages,” Wiz Research said in an email. 

Some of the compromised packages, including keyv, flat-cache and file-entry-cache, are present in more than 46% of all cloud environments, according to Wiz. “By comparison, back in the Shai-Hulud 2.0 campaign the most prevalent packages were only in about 28% of environments,” the company said. 

“Time will tell whether the eventual cost and impact outpaces past attacks, or whether adoption of hardening mechanisms such as package aging, and the usage of the relatively less aggressive Mini Shai-Hulud code as basis, will defray the final toll here,” Wiz Research added. 

Researchers from multiple firms sprung into action to monitor the widening attack spree and published indicators of compromise to help potential victims hunt for malicious activity in their systems. 

The Mini Shai-Hulud variant used in these attacks scoops up a trove of sensitive data, including npm, GitHub, AWS and continuous integration credentials. It also steals AI-related configuration files and cryptocurrency wallets, researchers said. 

Microsoft, Aikido, Socket and Wiz all said the same payload and pattern was observed across all affected packages, indicating a single attacker or threat cluster was behind the supply-chain attack and using multiple stolen tokens. 

The malware showcased a few pieces of new functionality, but retained the same core mechanisms that are hallmarks of Mini Shai-Hulud. 

“The evolution is consistent with what we’ve seen from them in past waves, however we don’t yet have the hard links” to confidently attribute the attacks to TeamPCP, Wiz Research said.

The notorious threat actor, which Google previously told CyberScoop it attributes to one core operator that was located in South Africa during at least some of the attacks, compromised and injected malicious code into more than 1,000 software packages in less than four months earlier this year.

The post Massive supply-chain attack compromises 440 packages under four hours appeared first on CyberScoop.

Dem senators criticize Trump administration decisionmaking on AI security risks

The Trump administration’s haphazard and opaque interventions into artificial intelligence security matters could catapult Chinese alternatives into broader acceptance, posing new security risks altogether, a group of Democratic senators wrote to top administration officials Monday.

The five senators said that the administration’s handling has alternated between too passive, such as when OpenAI models escaped testing in the Hugging Face hack last month, and overstepping, such as when the Commerce Department suspended access for any foreign national to Anthropic’s Fable 5 and Mythos 5 in June.

“The Administration’s ad hoc and unpredictable approach undermines U.S. competitiveness, heightening market incentives to adopt open weight models from vendors based in the People’s Republic of China (PRC),” wrote Sens. Kristen Gillibrand of New York, Adam Schiff of California, Mark Warner of Virginia, Chris Coons of Delaware and Mark Kelly of Arizona.

In the Hugging Face hack, the senators wrote that “the Federal Government cannot be passive as these capabilities emerge.”

In the case of the Fable 5 and Mythos 5 suspensions, the senators said that the administration “utilized an infrequently used authority to direct Anthropic to suspend all access to its Fable 5 and Mythos 5 models for foreign nationals (including foreign national employees inside the United States) citing an undisclosed national security concern later described as a narrow jailbreak finding.”

Because Anthropic couldn’t immediately assess users’ nationality, the firm had to disable both models for everyone. The administration and Anthropic negotiated for 18 days behind closed doors before reaching an agreement, the lawmakers complained.

“While the Administration may have been responding to real security concerns to protect the United States, even justifiable interventions can create broader harm if the standards and decision-making processes are opaque, ad hoc, or unpredictable,” they said in their letter to leaders in the White House, Office of the National Cyber Director and departments of State, Treasury and Commerce. “Moreover, when the Executive Branch exercises authority delegated from Congress, such as in the conduct of export control administration, it is essential that it keep Congress fully apprised of its actions and procedures.”

During the time Anthropic was under export controls, the stock price of “an entity-listed Chinese lab” nearly doubled, the senators said. And while Hugging Face was breached, the company “had to” rely on a Chinese open-weight model due to guardrails on U.S. frontier models.

“If American models are perceived as subject to sudden access disruptions based on a black-box U.S. Government process, or as unreliable because U.S. AI labs are overcorrecting in the face of this black-box process, companies and governments in the United States and abroad may hedge by adopting Chinese or other foreign models instead,” the senators contended. “That outcome would undermine U.S. technological leadership while increasing exposure to systems that may carry risks of PRC or otherwise directed censorship, espionage, IP theft, and other supply chain security risks.”

Their letter asked for answers to questions about the standards the administration uses to determine the national security risks a frontier model presents, what legal authorities it will use to invoke restrictions, which agencies are responsible for which decisions and more.

None of the offices or departments the letter was addressed to immediately responded to a request for comment.

The letter follows inquiries at the state level, where 15 attorneys general asked OpenAI for more information regarding the security incident at Hugging Face.

The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.

❌