❌

Reading view

There are new articles available, click to refresh the page.

Lawmakers call on Commerce to sanction hackers-for-hire

A bipartisan trio of lawmakers is asking the Commerce Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies.

Democratic Sens. Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island and Rep. Pat Harrigan, R-N.C., sought in a letter to Secretary Howard Lutnick Wednesday to have the mercenary firms added to the Treasury Department’s Entity List, which would limit their access to American software, cybersecurity tools and cloud infrastructure.

“Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote. “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”

The three firms are Sunkissed Organic Farms, BellTroX and CyberRoot. The first of those three was formerly known as Appin and has been the subject of investigative reports and criminal probes. The Citizen Lab at the University of Toronto has delved into the work of BellTroX, and journalists also have reported on the activity of CyberRoot.

“The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence,” the lawmakers wrote. “While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.”

Reuters reported in 2023 that the family member was Kristi Rogers, wife of former House Intelligence Chairman Mike Rogers, now running for Senate as the GOP candidate against one of the midterms’ most important and contested races against Democrat Abdul El-Sayed.

Some of the hacking groups also have sought to censor reporting on their hacking activities, the lawmakers noted.

CyberScoop couldn’t reach the companies for comment. The Commerce Department also didn’t immediately respond to a request for comment, and the government of Qatar didn’t immediately respond to an email seeking comment on the letter. TechCrunch first reported on the letter.

Corrected 9/10/2026: to reflect department to which the lawmakers addressed the letter.

The post Lawmakers call on Commerce to sanction hackers-for-hire appeared first on CyberScoop.

The GTA VI leaks are breaking the internet. Security researchers have seen this before.

Grand Theft Auto VI, widely heralded as the game event of the decade, took a significant hit last week after a cybercriminal sent much of the internet into pandemonium after publishing gameplay footage a week before the game’s publisher planned to reveal core portions of the game to the public.  

The files posted by the online persona “CyberLeek” indicate either a hacker had direct access to Rockstar Games’ most sensitive systems or was given proprietary data by an insider, eventually becoming one of the highest-profile data extortion attacks of the year — a vexing, almost-daily occurrence hitting industries of all types.

While most data extortion attacks rattle companies due to regulatory or privacy concerns, this particular incident has caused an outsized response from Rockstar’s parent company, Take-Two Interactive Software, because it has an audience. While no lives are at risk, as they would be in an attack on critical infrastructure, the financial and reputational stakes are magnified precisely because people are watching every drip of stolen footage become a news story or a trending topic. 

“IP theft — whether it’s conducted by a cybercriminal, an insider, or even potentially [an artificial intelligence] model — rips away the hard work, passion, and livelihood among employees and companies that created the product in the first place,” Cynthia Kaiser, senior vice president of Halycon’s ransomware research center, told CyberScoop.

The game’s prior release, GTA V, along with its online component, has sold over 230 million copies and earned Take-Two over $11 billion since its release in 2013. Industry analysts say GTA VI is on pace to make between $3.3 billion to $5.2 billion in cumulative global sales by the end of its launch week in November. 

“The crown jewels of a company are whatever makes it differentiated and special,” said Kaiser, the former deputy assistant director of the FBI’s cyber division. “For some, that means customer data or source. For a studio in the final stretch before launch, the crown jewel is the surprise.”

While Take-Two hasn’t said anything publicly about the leaks, it has responded feverishly via its legal team. The company petitioned a federal court for subpoenas under the Digital Millennium Copyright Act against Discord, Google, Microsoft and X, seeking the identity of CyberLeeks and other user accounts it accuses of copyright infringement.

Federal judges granted the subpoenas against Discord, Microsoft and X, but the petition against Google remained unapproved as of Monday. Take-Two’s legal representatives also sent copyright notices to the four companies, informing them of the copyrighted material published on their platforms, but it’s unclear if any of the tech companies have been formally served with the signed subpoenas. 

Take-Two and Rockstar did not respond to a request for comment.

The subpoenas may have been enough to spook those responsible for the leaked footage. As of Monday, the websites where those behind CyberLeek were posting leaked information and links to a memecoin were offline.

Zach Edwards, staff threat researcher at Infoblox and a self-proclaimed fan of the series, initially thought the leaks were part of a Rockstar guerrilla marketing campaign. But the company’s response “confirms that this is a real investigation, and the content being shared is likely real to some degree,” he said. 

Take-Two’s actions thus far indicate the company is approaching the breach and leaks like an insider threat investigation, Edwards said. Whoever leaked the footage may have had access to an actual build of the game, he added. That could point to an insider, someone who could have saved a copy to a cloud service, uploaded it to a file-hosting site, or walked out with it on an external drive.

CyberLeek’s conflicting motivations

The hacker or group behind CyberLeek claim they are releasing the gameplay videos to protest Rockstar’s decision to not release physical copies of the game. Yet, watermarks on the leaked videos include addresses to crypto wallets, which indicate CyberLeek is also, and perhaps primarily, seeking a payout. 

“The persona behind the leaks, CyberLeek, published an anti-corporate manifesto targeting digital pre-orders and disc-less releases to frame the breach as hacktivism,” Ben Bernstein, manager of Huntress’ cybersecurity advisors team, told CyberScoop. “Yet behind the political posturing, there’s clear financial monetization and clout-chasing.”

Kaiser draws the same conclusion. “Let’s separate stated motive from observed behavior,” she said. “Threat actors who talk about principle while running a monetization channel are usually only telling you what they think will land with an audience, not actually what is driving them.”

Katie Moussouris said “this is what the alternative vulnerability economy looks like.” The founder and CEO at Luta Security has spent decades building legitimate channels for people who find security problems to get paid without turning to crime.

“The leaker launched a cryptocurrency token, watermarked stolen footage with a buy link, and offered to sell ad space on future leaks. Each of those pays out in proportion to how many people are watching. The manifesto is what keeps them watching,” Moussouris said. 

“That is a genuinely new monetization model for stolen pre-release content, and it means the usual playbook of negotiating a ransom payment quietly or paying to make it stop won’t work,” she added.

Different flavor, same crime

Despite its unique characteristics, the rhythm of the attack and its fallout is familiar territory for cybersecurity experts. 

“Steal, publish a sample, promise more, deliver, repeat. Just like ransomware attacks, in cases like these criminals use every lever of pressure they can against a company — including the fear of what is coming next — to profit from their actions,” Kaiser said. 

“The attackers are crowdsourcing their pressure tactics. A meaningful share of the player base is treating the leaks as free content and amplifying them,” she added.

Kaiser also sees some clear parallels with previous attacks targeting major entertainment companies, including the 2014 attack on Sony Pictures and the HBO hack in 2017. 

“The Sony comparison is useful for how these things escalate, but this incident reminds me more of the Iranian hackers’ leak of ‘Game of Thrones’ episodes a few years back,” she said. “North Korea attacked Sony for political purposes, destroying its data along the way; Iranian threat actors compromised HBO, along with hundreds of universities and over forty other companies, in a hacking-for-hire scheme stealing American intellectual property.”

Federal authorities earlier this month unsealed a second wave of indictments against 17 Iranians affiliated with the tech firm Mabna Institute who allegedly stole troves of data from government agencies and dozens of companies, including HBO.

This isn’t the first time Rockstar has been hit with a security incident. In 2022, an 18-year old British man who was a member of the Lapsus$ cybercriminal gang was sentenced to an indefinite hospital order after leaking gameplay footage. According to the BBC, the incident cost Rockstar, along with ridehauling company Uber and chipmaker Nvidia, over $10 million. 

The subpoena that worries security experts

Security professionals expect the situation to escalate on all sides. Leaks have hit the internet daily for the past eight days, including a series of leaks Tuesday morning. Meanwhile, Take-Two has not relented on its subpoenas. Its broadest move was a subpoena against Discord, seeking identifying data on CyberLeek, two other users and every member of three Discord servers where the copyrighted material was posted.  

Moussouris said the scope of that inquiry should worry people well beyond this case. 

“Take-Two asked for Windows device identifiers, login records, and cloud storage contents for every person who spoke in three Discord servers going back to June,” she said. “The people with the best chance of uncovering the culprits are those doing the unglamorous investigation forensics work of figuring out how the build may have leaked.”

Discord would not say whether it had been formally served or what it has done in response. A company spokesperson said it reviews and complies with valid subpoenas when they are received. 

While the breach and leak of ‘GTA VI’ material is a serious matter, Edwards noted that Take-Two is also benefiting from greater interest in the unreleased game on a daily basis. 

“The threat actor leaking these videos has failed by essentially creating a successful underground marketing campaign for the game while also putting themselves at serious risk of being eventually caught,” he said. 

“This incident is playing out like a classic insider threat exploitation scheme. Someone got access to sensitive data, they had a political agenda which clashed with the owner of the sensitive data, and they decided to do something stupid to try and force a change,” Edwards added. “This attack has done nothing but spread ‘GTA VI’ content further than it would have otherwise, and it’s creating ripples across other industries like cybersecurity who would have never covered ‘GTA 6’ issues previously.”

The post The GTA VI leaks are breaking the internet. Security researchers have seen this before. appeared first on CyberScoop.

Most federal cybersecurity reporting rules are duplicative, study finds

Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.

And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.

At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”

The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.

The GAO scrutinized regulations that required the private sector to report cybersecurity incidents, plans and reviews to federal agencies, as part of a study sought by House Homeland Security Chairman Andrew Garbarino, R-N.Y., and the top Democrat on the Senate counterpart to Garbarino’s panel, Gary Peters, D-Mich.

In some cases, a single critical infrastructure sector could have duplication with several agencies. For example, the Cybersecurity and Infrastructure Security Agency has been working on a regulation stemming from the 2022 Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which would require critical infrastructure owners and operators to report when they are the victims of major attacks or make ransomware payments.

Elements of the financial services sector might fall under one of 15 preexisting cybersecurity reporting rules, depending on the agency that has oversight, but they may also be subject to the pending CIRCIA rules, GAO noted.

A 2024 national security memorandum tasked the Office of the National Cyber Director and the Department of Homeland Security to harmonize conflicting regulations, and both agencies made some progress on those goals.

But the executive branch paused some of those efforts after Trump issued an executive order in March of last year while the administration conducted a study of the 2024 memo, a study that was still underway as of last month, according to the GAO.

As such, on harmonization, “many past federal efforts have experienced delays and made limited progress,” the GAO concluded in its report Wednesday, its latest on the topic. 

Congress has also looked at ways to streamline cybersecurity regulations.

GAO’s study was focused only on federal rules. BreachRx, a cyber incident response firm, published its own report Wednesday looking at major cyber incidents and how overlapping regulatory reporting obligations came into play, folding in regulations from states and other sources.

The post Most federal cybersecurity reporting rules are duplicative, study finds appeared first on CyberScoop.

North Korea’s IT worker scheme funds Russia’s war effort

The people orchestrating North Korea’s IT worker scheme are funneling money through a web of front companies and intermediaries, including sanctioned entities, that partly fund Russia’s war effort against Ukraine, DTEX said in a report Tuesday.

The security firm’s research shows that the scheme is moving beyond funding the country’s weapons program and into a bigger pool that supports many of the regime’s objectives. This includes manufacturing weapons and supplying them to Russia’s military, according to DTEX.

“When we think IT workers, we typically think head down, get your money, support the weapons program,” Michael Barnhart, nation state investigator at DTEX and lead author of the report, told CyberScoop.

“It’s a broad cover-all statement when we say it’s supplying the weapons program,” he said. “That’s the predominant place it goes,” but many other domestic programs and entities tasked with other projects are taking cuts from that pool of money as well. 

Barnhart corroborated previously leaked data from an internal North Korean payment server, which included 390 IT worker accounts, chat logs and transaction data.

He mapped the transactions to organizations that received those funds, including multiple sanctioned entities: Sobaeksu, Saenal, and Songkwang. 

The money trail also showed $1.97 million in payments from North Korean IT workers between December 2025 and February 2026 flowing directly through Korea Ryonbong General Corp, a sanctioned defense entity that procures weapons for the regime’s military programs.

Western officials previously reported that North Korea provided ammunition and weapons to Russia in 2023, and in the fall of 2024 sent upwards of 15,000 soldiers to fight alongside Russian troops, according to the Council on Foreign Relations.

“This is a consequence that is often overlooked,” Barnhart wrote in the report. “Revenue from the IT worker stream does not stop at a resume scam or a payroll-abuse story. It can feed a larger DPRK system that supports sanctioned entities, domestic state needs, and a Russia war effort that is actively consuming all facets of North Korean weapons and military support.” 

Data from the internal North Korean payment server, which was first published by ZachXBT in April, is controlled by “PC-1234,” a single administrator that DTEX has been tracking for a while. The wallet and its cluster of activity remains active, Barnhart said. 

The three months of previous activity attributed to the wallet amounted to more than $2.84 million, which then flowed upward into dozens of organizations. 

“It’s not a top-down funded regime. It’s a bottom-up,” Barnhart said. “Everyone makes money at the bottom and then they take a tiny cut, and then the money goes upwards to what we just blanketly say is the weapons program. But really, it can go a lot more places.”

The post North Korea’s IT worker scheme funds Russia’s war effort appeared first on CyberScoop.

Forget the model. When it comes to cybersecurity, it’s all about the harness

As AI-enabled hacking becomes a bigger threat for cybersecurity and national security, public attention has focused on mainly a few leading frontier AI companies developing more powerful large language models.

These models, and the billions of dollars behind them matter, but they’re only part of a larger shift. Enterprises are now building their own technology platforms that take these general-purpose LLMs and turn them into bespoke cybersecurity tools.

Industry professionals refer to these tools as a “harness.” They control the model’s behavior, limit its risks, and connect it to internal IT systems and networks so it can work reliably at scale.

New research from Cato Networks shared exclusively with CyberScoop shows how much power can come from a harness. It paired OpenAI’s ChatGPT 5.5 and GPT 5.5-Cyber models with its own tool and tested the abilities of the agent to hack into a victim network with as little human direction as possible.

Across six different scenarios, the pairing achieved complete end-to-end attack chains, including domain administrator privileges and Active Directory access, sometimes in as little as 40 minutes.

“What was most surprising is that first we saw that it was capable of doing accelerated reasoning and attack, and interacting and doing all this by itself, like doing all of the stages of the attacks,” said Guy Waizel, a tech evangelist at Cato Networks and one of the authors behind the research.

Critically, the most successful scenarios happened when the model was given appropriate operational context from the technical harness developed by Cato Networks.

“It does support that it’s not just about the frontier model,” said Waizel. “We found that [our harness] really helps the reasoning” of the LLM.

An illustration of an agentic AI attack chain and lateral movement within victim networks. (Source: Cato Networks)

The agent was given some – but not abundant – resources to complete its tasks, including an external Kali Linux attack host, the simulated target’s public IP address and a set of low-level domain credentials acquired through phishing.

It was not provided with any other details, and had to probe further for key information, such as further knowledge of the server type (Microsoft Exchange), the target’s operating system, version, build number, internal network topology, access to higher privilege accounts and other critical assets, nor was agent given any predetermined attack paths.

The Cato Networks research uses OpenAI models, but only as an example. Waizel said he believes other models would likely achieve similar results. In any event, if current trends hold, the kind of capabilities provided by LLMs like GPT 5.5 are likely to be open-source within a year.

Cato Networks is far from alone. Most enterprises have their own AI harnesses, and  executives tell CyberScoop they are playing an increasing role in more effectively steering the frontier model workflows.

While AI tools can struggle to duplicate human workflows in other areas, LLMs have long shown potential in cybersecurity and coding, improving greatly over the past few years. The Trump administration has set up a new federal clearinghouse for exchanging information between the public and private sectors on AI-discovered vulnerabilities, while European groups are setting up their own organizations to coordinate globally on AI cyber threats.

Eric Doerr, chief product officer at Tenable, told CyberScoop a harness used in the company called “Hexa”  offers a defensive advantage:  it can work with different commercial LLMs while delivering consistent  results.

“One of the first things we do when we get a [new] model is say ‘Well, let’s run it through Hexa and see what we learn,’” said Doerr. “We have a whole bunch of benchmarks. Is it the same, is it better? Where is it better? Where is it worse?”

Hexa is meant to ensure that whichever model or models become dominant, Tenable will be able to integrate it into their tech stack and protect their most sensitive assets from unintended behaviors. That frees up the LLM to do what it does best: find vulnerable code and establish attacker pathways for exploiting them.

“For years, it has been true that there are way more potential issues that a company has to deal with: code vulnerabilities, things that are unpatched, misconfigurations,” said Doerr. “There’s way more than you can actually remediate, and you really need to understand the difference between what’s a theoretical problem and a real problem.”

Dan Rapp, chief AI and data officer at Proofpoint, said their harness, “Satori,” has become a critical tool for keeping their agentic AI on track while giving humans the ability to step in when things go awry.

“I think what you’re seeing in the foundation of frontier models is you have raw intelligence, raw reasoning power, but to get these systems to perform the way you want to, both context engineering – the content provided ensuring that its accurate and relevant – and the harness engineering are essential to actually get the systems to perform well,” Rapp told CyberScoop.

That was a common theme in interviews with companies. While frontier models come and go, or are overtaken by international competitors, there will always be the need for the model to operate with data and context that often only the organization can provide.  

It suggests that while policymakers and cybersecurity experts have focused on the spread of newer and more powerful frontier models, industry – and likely soon the cybercriminal underground — has quickly developed the kind of technical infrastructure that is becoming far more important to AI cyber defensive and offensive tasks.

“We’ve had to bootstrap quite a few of these systems from first principles, and what it always boils down to is how effective you are with the tool calling… bringing in data, enriching the context,” said John Hopper, vice president of product engineering at SpecterOps.

The post Forget the model. When it comes to cybersecurity, it’s all about the harness appeared first on CyberScoop.

Citrix patches a new NetScaler flaw with echoes of CitrixBleed

Citrix published a security bulletin Tuesday disclosing six vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, including a high-severity memory disclosure flaw that researchers say belongs to a vulnerability class first identified in the 2023 incident known as CitrixBleed.

The company rated the overall bulletin severity as high and assigned CVSS scores ranging from 6.9 to 8.8 across the six CVEs. Citrix said customers should install the updated builds and, in one case, manually adjust a configuration parameter even after patching.

The most closely scrutinized of the vulnerabilities, CVE-2026-8451, was discovered by researchers at watchTowr, a cybersecurity firm that has published several prior analyses of issues in NetScaler products. According to a technical writeup the firm released alongside Tuesday’s disclosure, the vulnerability stems from how NetScaler parses SAML authentication requests when an appliance is configured as a SAML identity provider, a deployment mode commonly used for single sign-on.

WatchTowr researcher Aliz Hammond wrote that the firm found the flaw in late March while reproducing a separate vulnerability, CVE-2026-3055, that Citrix disclosed earlier this year. That March flaw was added to CISA’s Known Exploited Vulnerabilities catalog after researchers and the agency confirmed active exploitation within days of disclosure. The new flaw shares a root cause with the March bug: both involve out-of-bounds memory reads triggered by malformed SAML requests sent to NetScaler’s authentication endpoints.

“Referencing what we wrote previously, because it is demonstrably evergreen: ‘However, what should be of concern is the bigger picture – the trend, which is very clearly suggesting that memory management continues to appear fragile within Citrix NetScaler appliances, to the extent that even accidentally misconfiguring an appliance can lead to the disclosure of leaked memory,’” Hammond wrote in the report. 

The bulletin also discloses five additional vulnerabilities affecting different NetScaler subsystems. Two involve memory overflow conditions that could cause denial-of-service outcomes. A separate flaw could allow unauthenticated arbitrary file reads on appliances where management access is exposed on certain network interfaces. Another concerns memory overread triggered through TCP timestamp handling. The sixth involves a denial-of-service condition tied to malformed HTTP/2 requests, which requires an additional manual configuration change to fully fix, since the relevant timeout parameter defaults to a value that leaves the underlying condition unaddressed unless administrators set it explicitly.

Along with Hammond, the bulletin credits Michael Tucker of the XOR team at JPMorgan Chase and Maxim Suhanov for finding the vulnerabilities. 

The NetScaler product line has accumulated more than 20 entries in CISA’s KEV catalog over the past three years, including multiple flaws that have been weaponized in ransomware campaigns. As of Tuesday, the latest vulnerability had not joined that list — neither the vendor bulletin nor watchTowr’s writeup cited confirmed exploitation at the time of disclosure.

The post Citrix patches a new NetScaler flaw with echoes of CitrixBleed appeared first on CyberScoop.

❌