Reading view

There are new articles available, click to refresh the page.

Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams

Senators from both parties Thursday probed Trump administration officials about whether federal agencies and foreign governments are coordinated enough in the battle against scammers, something witnesses told the Foreign Relations Committee they were working to remedy.

At least 13 federal agencies have authorities to counter scams, raising questions about whether someone needs to be in charge of all those efforts. And while there was some bipartisan sentiment at Thursday’s hearing that the Trump administration has taken good actions to battle scammers, both lawmakers and administration officials said that scam operations have demonstrated that cracking down on them in one place often just leads to them going elsewhere.

Sen. Pete Ricketts, R-Neb., compared the situation to an international initiative that gained prominence in the 1990s to counter drug trafficking, Joint Interagency Task Force South.

“Given that today’s scam centers are similarly transnational, combining cybercrime, human trafficking, money laundering and cryptocurrency, has the threat reached the point that we should establish a comparable multinational coordination mechanism?” he asked.

Sen. Jeanne Shaheen, D-N.H., focused on federal coordination: She paraphrased a former federal official who said, “there is nobody that is heading that effort up across agencies. We need to treat this like combat, and so we need somebody in charge.”

Shaheen, the top Democrat on the panel, is a co-sponsor of the bipartisan Scam Compound Accountability and Mobilization (SCAM) Act, which seeks to unify federal efforts on the subject.

A State Department official told Shaeen scammers were a national security priority for President Donald Trump, and that his executive order on the topic sought to tackle coordination.

“I do understand that this is a whole-of-government approach, and many agencies are focused on this,” said David Bedard, deputy assistant secretary at State’s Bureau of International Narcotics and Law Enforcement Affairs “The Action plan that was directed by the president is currently in the interagency review process to deconflict some of the concerns that you have raised. We certainly think the task force that will be implanted through the executive order will solve the problems you might be referencing.”

There’s also an international plan under the task force, he said. Currently, the administration shares intelligence on scammers with foreign allies, and Interpol has “productive” channels to work through there and is setting up its own task force, Bedard said, but there are concerns about other countries taking similar, duplicative action.

There have been signs of progress on the international front, Bedard and another State Department witness told the panel.

Michael DeSombre, assistant secretary at the Bureau of East Asian and Pacific Affairs, said Trump has raised the subject with Chinese President Xi Jinping, and that China has used its influence in Asia as its own citizens have become scam victims. Still, there’s been more progress in countries where the United States has stronger relations, such as Cambodia, than in those where ties aren’t as close, like Burma and Laos.

In Cambodia, one key has been pursuing scam center bosses first and foremost, Bedard said.

The post Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams appeared first on CyberScoop.

Dem senators criticize Trump administration decisionmaking on AI security risks

The Trump administration’s haphazard and opaque interventions into artificial intelligence security matters could catapult Chinese alternatives into broader acceptance, posing new security risks altogether, a group of Democratic senators wrote to top administration officials Monday.

The five senators said that the administration’s handling has alternated between too passive, such as when OpenAI models escaped testing in the Hugging Face hack last month, and overstepping, such as when the Commerce Department suspended access for any foreign national to Anthropic’s Fable 5 and Mythos 5 in June.

“The Administration’s ad hoc and unpredictable approach undermines U.S. competitiveness, heightening market incentives to adopt open weight models from vendors based in the People’s Republic of China (PRC),” wrote Sens. Kristen Gillibrand of New York, Adam Schiff of California, Mark Warner of Virginia, Chris Coons of Delaware and Mark Kelly of Arizona.

In the Hugging Face hack, the senators wrote that “the Federal Government cannot be passive as these capabilities emerge.”

In the case of the Fable 5 and Mythos 5 suspensions, the senators said that the administration “utilized an infrequently used authority to direct Anthropic to suspend all access to its Fable 5 and Mythos 5 models for foreign nationals (including foreign national employees inside the United States) citing an undisclosed national security concern later described as a narrow jailbreak finding.”

Because Anthropic couldn’t immediately assess users’ nationality, the firm had to disable both models for everyone. The administration and Anthropic negotiated for 18 days behind closed doors before reaching an agreement, the lawmakers complained.

“While the Administration may have been responding to real security concerns to protect the United States, even justifiable interventions can create broader harm if the standards and decision-making processes are opaque, ad hoc, or unpredictable,” they said in their letter to leaders in the White House, Office of the National Cyber Director and departments of State, Treasury and Commerce. “Moreover, when the Executive Branch exercises authority delegated from Congress, such as in the conduct of export control administration, it is essential that it keep Congress fully apprised of its actions and procedures.”

During the time Anthropic was under export controls, the stock price of “an entity-listed Chinese lab” nearly doubled, the senators said. And while Hugging Face was breached, the company “had to” rely on a Chinese open-weight model due to guardrails on U.S. frontier models.

“If American models are perceived as subject to sudden access disruptions based on a black-box U.S. Government process, or as unreliable because U.S. AI labs are overcorrecting in the face of this black-box process, companies and governments in the United States and abroad may hedge by adopting Chinese or other foreign models instead,” the senators contended. “That outcome would undermine U.S. technological leadership while increasing exposure to systems that may carry risks of PRC or otherwise directed censorship, espionage, IP theft, and other supply chain security risks.”

Their letter asked for answers to questions about the standards the administration uses to determine the national security risks a frontier model presents, what legal authorities it will use to invoke restrictions, which agencies are responsible for which decisions and more.

None of the offices or departments the letter was addressed to immediately responded to a request for comment.

The letter follows inquiries at the state level, where 15 attorneys general asked OpenAI for more information regarding the security incident at Hugging Face.

The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.

Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming

With identity protection services for millions of victims of the 2015 Office of Personnel Management breach set to expire, a group of lawmakers is making a push to extend them forever.

Sen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., introduced legislation to give lifetime identity protection coverage to around 4.2 million federal employees exposed in the historic breach by alleged Chinese hackers, which affected 22.1 million people. Warner said “the threat remains,” necessitating lifetime coverage.

That coverage is due to end at the end of September, as set by a 10-year authorization from Congress. That prompted the pair of lawmakers to introduce Reducing the Effects of the Cyberattack on OPM Victims Enduring Response and Protecting Identifiable Information Act, or  RECOVER PII Act.

“The data stolen included workers’ most sensitive and personal information – from Social Security numbers to security clearance records – and once that information is in the hands of a bad actor, you don’t get it back,” Warner said in a news release Monday. “We have a responsibility to stand by the federal workers who were put at risk through no fault of their own. This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.”

But the bill could have an uphill climb, given the makeup of Congress and stance of the Trump administration.

The Democratic co-sponsors in the Senate are Tim Kaine of Virginia, with Angela Alsobrooks of Chris Van Hollen, both of Maryland. The Democratic House cosponsors are Reps. Don Beyer and James Walkinshaw of Virginia, with Steny Hoyer of Maryland.

Warner and Norton listed no co-sponsors from the GOP, which controls both chambers of Congress and the White House.  And OPM has declared the program too expensive based on the cost relative to the number of claims.

Similar legislation to extend the coverage, including from Norton, has fallen short in recent years.

“Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” Norton said Monday. “Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity.”

Some watchdog scrutiny of the OPM program has been critical, and while consumer advocates say identity theft protections are helpful, they nonetheless say they aren’t adequate.

The Warner-Norton legislation also would offer reimbursements to federal employees and contractors for privacy services.

The post Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming appeared first on CyberScoop.

Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world

President Donald Trump blamed Minnesota Friday for the cyberattacks its water systems have suffered in recent days, saying the state was “behind it.”

Trump said the state being “incompetent” was the issue, but it wasn’t clear whom he thought actually conducted cyberattacks that U.S. investigators have attributed to Iran — if, perhaps, somehow Minnesota incompetently cyberattacked itself. The White House referred a request for clarification back to Trump’s remarks.

“I think that Minnesota is behind it,” Trump told reporters Friday. “Because they’re grossly incompetent. I don’t think there was an Iranian cyberattack. I think Minnesota ought to get its act together.”

The White House also didn’t clarify whom the president believed was behind similar attacks in other states, when asked for comment. Trump has repeatedly used federal power aggressively in Minnesota, a state led by Gov. Tim Walz, a Democrat who was on the ticket that ran against him in 2024 as the vice presidential nominee. Trump also has downplayed Iranian attacks amid the war he launched against the nation with Israel in February.

A number of cyber experts quickly pushed back on Trump’s comments after he made them.

“Victim blaming in cyber is so 2000 and late,” cybersecurity pioneer Chris Wysopal, Veracode co-founder and chief security evangelist, said on the Bluesky social media platform. Said Jake Williams, a member of the IANS faculty: “His own intelligence services are attributing this to Iran.”

Andy Jabbour — founder and CEO of Gate 15, a cybersecurity firm which provides support to the water sector — told CyberScoop that, “speaking candidly, I’m not even sure what he was actually saying or suggesting Minnesota’s government did or didn’t do.”

“Attribution is tricky business,” he continued, referencing recent alerts from the Cybersecurity and Infrastructure Security Agency and others. “But logically, given an ongoing war with Iran, recent statements made by Iran-aligned threat groups, with assessments that the recent activity is aligned with recent CISA warnings, given yesterday’s statements from CISA and the FBI, random unsubstantiated allegations aimed at political opponents seem reckless and are a disservice to the American people.”

Walz struck back at Trump in a Facebook post, noting steps from his Department of Government Efficiency to slash federal funding. CISA has shrunken considerably under Trump, and his administration has pushed states to defend against cyberattacks that feds once countered.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz said. “This is what modern warfare looks like, and it further illustrates there’s no plan to win a war with Iran.”

“DOGE took an axe to CISA and left the U.S. exposed to cyber attacks,” he continued. “Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it.”

A spokesperson for Minnesota IT Services, a state agency that has been responding to the water cyberattacks, declined to address Trump’s remarks.

“We remain focused on supporting affected communities, securing critical infrastructure and coordinating with local partners and federal officials as the investigation continues,” the spokesperson, Emily Zimmer, told CyberScoop. “We will not comment on political statements or speculate about attribution.”

Other cyber professionals declined to comment directly on Trump’s remarks, but offered thoughts on who was behind the attacks and their motives.

Bryson Bort, CEO and founder of Scythe said the evidence supports the attribution with Iran, and that it looks like hackers there found something they could exploit on the internet and seized the chance.

“This was a target of opportunity,” said Bort, co-founder of the ICS Village, a non-profit advancing awareness of industrial control system security; such systems are common in the water sector. “It wasn’t that Minnesota did something as a state to raise Iran’s ire.”

Cynthia Kaiser, a former top FBI cyber official, said that when the bureau conducts attributions, it looks at technical indicators but also who has the capability, who has conducted similar attacks in the past and what the purpose of the attacks is.

“Iran ticks all these kinds of things,” Kaiser, now senior vice president at cybersecurity firm Halcyon, told CyberScoop. “My view is, if it walks like a duck, if it talks like a duck, I strongly suspect it’s a duck. I’d be shocked if we found out it wasn’t Iran.”

Just last week, CISA updated an advisory about how Iranian hackers were targeting programmable logic controllers in the water sector and other sectors, a warning that the water industry’s information sharing and analysis center said it believed.

“WaterISAC is confident in our government partners’ assessment that the confirmed activity is aligned with the joint Cybersecurity Advisory (CSA) AA26-097A ‘Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across U.S. Critical Infrastructure’ published and recently updated by CISA,” Tom Dobbins, executive director, WaterISAC, told CyberScoop. “We have evidence of earlier attacks from Iran even before this current conflict. Cyber attacks are the most viable way that Iran can directly attack our homeland, and it is logical that they would do so, especially given the challenges of absolute attribution.”

The water sector is often viewed as one of the most vulnerable critical infrastructure sectors, and Dobbins called on Congress to provide funding to provide funding for the ISAC.

Sen. Tina Smith, D-Minn., also took issue with Trump’s comments.

“The President provided an unserious response that is beneath the dignity of the office he holds. Iran’s purported cyberattack on Minnesota’s water infrastructure must be taken as a serious threat to our national security.  Smith said in a statement, adding that she’s been in touch with CISA and the FBI and was grateful to Minnesota’s IT experts. “The entire situation serves as a stark reminder of the danger this war puts us in the longer it drags on.”

Fellow Minnesota Democratic Sen. Amy Klobuchar had earlier been in touch with Sean Cairncross, the national cyber director and a Minnesota native, about the incident.

Trump has previously displayed a laissez-faire view toward other cyberattacks on the United States, such as when he’s been asked about Chinese and Russian cyberattacks and Trump shrugs them off as something America does, too.

He also has cast doubt before on his government officials’ assessments of who’s responsible for cyberattacks on the United States, such as when he asserted China rather than Russia was behind the landmark SolarWinds breach.

Updated 8/3/2026: with comments from Minnesota’s senators.

The post Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world appeared first on CyberScoop.

Supply chain challenges loom large in quantum race, White House official says

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.

“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.

“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there’s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”

Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.

“The other major issue or challenge that we face right now is that we’re on the cusp of quantum exploding from a commercialization perspective, but we’re not quite there yet,” he said. “So there’s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it’s just [that] there are too many places that I would want to bolster and not enough funding to do it.”

Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.

The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.

And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia. 

Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.

“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that’s what makes it so critical.”

Another difficulty is measuring progress, Blakestad said: “It’s also very, very hard to benchmark, and to know that you’re actually doing what you’re supposed to, what you are intending to do.”

The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.

White House accuses Chinese company of distilling Anthropic’s Fable

A top White House technology official is accusing a Chinese company of distilling Anthropic’s models to create their own AI product.

Michael Kratsios, who leads the White House Office of Science and Technology Policy, claimed that Moonshot AI, a Beijing, China-based AI company, had distilled Anthropic’s recently-released Fable model to develop its own K3 model.

“To do this they developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection,” Kratsios wrote on X Wednesday.

Kratsios also said the company has used GB300 servers – either newly acquired or through Thailand – to train its AI models.

“The United States strongly supports the free and fair development of AI, including a thriving competitive ecosystem that spans frontier models, specialized systems, open-source frameworks, and open-weight models,” Kratsios continued. “Legitimate AI distillation used to create smaller, more efficient models plays a vital role in this open innovation ecosystem. However, large-scale, covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.”

Kratsios did not provide details on how the U.S. government learned that K3 had been distilled from Anthropic’s model. 

Frontier AI companies in the U.S. have pressed policymakers to make it more difficult for third-parties to copy or duplicate advanced commercial models, calling it a form of intellectual property theft.

On their website, Moonshot AI describes its Kimi K3 model as the first open 2.8 trillion parameter model, and promotes its lower token costs while still delivering near-frontier performance. 

“While its overall performance still trails the most powerful proprietary models, Claude Fable 5 and GPT 5.6 Sol, Kimi K3 demonstrated frontier-level performance across our evaluation suite, consistently outperforming other tested models,” the company said on its website. 

A request for comment sent to Moonshot AI was not returned before this article’s publication. 

Piyush Sharma, CEO of Tuskira, an AI cybersecurity detection and response company, said distillation of AI models allows developers many of a model’s core capabilities. He pointed to another example when Anthropic earlier this year accused Chinese company Alibaba of distilling their Claude AI model.

According to Anthropic, the campaign used 25,000 fraudulent accounts to run 28.8 million interactions on Claude over six weeks. Given that kind of volume “the goal was clearly replication,” he said. 

“When a model has learned to reason through software weaknesses, security gaps, and attack paths, copying its behavior also copies that analytical capability,” said Sharma.

In April, Rep. Andrew Garbarino, R-N.Y., who chairs the House Homeland Security Committee and Rep. John Moolenaar, R-Mich., Chair of the Select Committee on China, announced they were conducting a joint investigation into the integration of Chinese AI models.

The committees said the inquiry will also focus on “examining a pattern of conduct by [Chinese]-based AI laboratories involving the large-scale theft of proprietary capabilities from American frontier AI systems through adversarial distillation” as well as “ the redistribution of those stolen capabilities as open-weight models available for global download, and the incorporation of PRC-origin models into products used daily by hundreds of thousands of American developers and engineers.”

Western governments and industry accuse Chinese companies of routinely stealing their technology, intellectual property and other trade secrets, often with the tacit support of Beijing. The copying of AI models would continue a long and established tradition of Chinese-sponsored intellectual property theft.

However, while distillation attacks by foreign governments or companies on U.S. frontier companies can have real national security implications, it’s still a fraught question of where policymakers should draw the line.

The AI industry, which includes not just frontier companies but large businesses with their own bespoke models, smaller proprietary startups and a vibrant open-source ecosystem, routinely share and use third-party data, including critical code and training sets for AI models.

Further, U.S. frontier AI companies have built and trained their world leading models in large part by crawling the open internet, ingesting content created and produced by others. Critics (and multiple ongoing lawsuits) argue that AI companies like OpenAI and Anthropic built their empires on data and content from others, taken almost entirely without consent or compensation.

The post White House accuses Chinese company of distilling Anthropic’s Fable appeared first on CyberScoop.

State officials, election experts pan Trump speech: ‘This is what desperation looks like’

State and local officials and election security experts largely panned a Thursday night primetime speech by President Donald Trump, saying it was reflective of White House “desperation” to find any credible evidence to support their claims that U.S. elections have been rigged against the two-term president.

While the White House teased explosive new claims about the potential compromise of U.S. elections by China, Trump’s speech was a rehash of claims that both have no supporting evidence and have been repeatedly debunked when investigated. 

David Becker, executive director of the Center for Election Innovation and Research and a former voting and civil rights attorney at the Department of Justice, said none of Trump’s claims or allegations were new or substantively different from previous theories he’s been espousing over the past six years.

“The White House promised a bombshell and they delivered a dud,” Becker said on a call with reporters Friday. “There was nothing that even calls into question past elections — certainly not the 2020 election.”

The administration declassified a huge tranche of documents from the intelligence agencies, and news outlets continue to sift through them, but thus far nothing has been found that remotely validates the administration’s claims about foreign interference from China costing Trump the 2020 election.

In fact, some of the most relevant documents found at this point have supported the opposite conclusion, with agencies assessing that while China engaged in influence campaigns around the election, it was not attempting to outright interfere with U.S. election infrastructure, hack voting machines or manipulate ballots.

John Solomon, a former journalist and opinion writer at The Hill brought in by the White House to lead the investigation, also told reporters Thursday that his search hasn’t turned up evidence that the 2020, 2022 or 2024 elections were affected by fraud.

The one new major claim by Trump — that the Department of Homeland Security determined hundreds of thousands of noncitizens were registered to vote across four states — is almost certainly false or overinflated, given that it contradicts post-election state audits that have routinely found single or double-digit numbers of noncitizens registered to vote within a single state across multiple elections.

Over the past six years, similar claims by GOP secretaries of state and political activists purporting to find mass numbers of noncitizens registered to vote have turned out to be grossly inflated due to shoddy data analysis, and the vast majority of cases involving “suspected noncitizens” turn out to be U.S. citizens who are legally registered to vote.

The White House has provided little to no information on the methodology used to flag and identify supposed noncitizen voters, other than alluding to the use of “commercial data” and federal databases. A federal court recently ordered DHS to dismantle the SAVE database, its primary database for verifying the citizenship status of U.S. voters, because it was unreliable and violated longstanding privacy laws. 

 Apart from DHS admitting its own data on citizenship is incomplete, Becker said using a list that relies on matching voter files with commercial data is not a reliable way of determining citizenship.

“It is impossible to take a public voter file with very little information that is uniquely identified, like a driver’s license number, and compare it to a commercial database and say for sure the Maria Rodriguez or the John Lee or the Shawn O’Hara you have on that is the same person,” he said.

Election officials also responded forcefully. Nevada Democratic Secretary of State Francisco Aguilar said that Trump has spent a decade attempting to manufacture a crisis around voter fraud and the president’s speech Thursday night was an extension of that effort. 

“As Nevada’s chief elections officer, it’s my job to call balls and strikes — so when the President lies, I am obligated to call him out,” Aguilar said in a statement. “The facts have not changed: Nevada’s elections are among the safest, most secure and accessible in the nation.”

It’s not just Democrats that have objected to the administration’s efforts. GOP states have gone to court to block the Department of Justice from obtaining their voter data, and Idaho’s Republican secretary of state responded to a DOJ letter threatening prosecution of election officials as “not well met” and potentially illegal under state ethics laws. 

Trump’s speech potentially casts additional light on recent White House decisions, such as firing all three commissioners on the Election Assistance Commission. The agency helps certify voting machines for security, and all three commissioners have served across administrations and maintain close relationships with state and local election officials.  

Pamela Smith, CEO of the nonprofit Verified Voting, said that while the EAC can’t take certain actions that need commissioner approval, “critical functions like voting system testing and certification can continue under the existing framework and should not be affected.”

In 2020, Trump’s initial claims of widespread election fraud were undercut by leaders at the Cybersecurity and Infrastructure Security Agency, which said there was no evidence the election was compromised. The removal of EAC commissioners could represent an attempt to preempt any efforts to rebut or criticize White House claims that elections and voting machines have been compromised.

Some have worried that Trump could use the speech as a pretext to declare a national emergency or cancel elections.

Tom Lopach, CEO of the Voter Participation Center, said “you don’t dismantle election security infrastructure if you’re serious about protecting elections.”

“You dismantle it if you’re planning to claim, without evidence, that the system failed you,” he said. 

While Becker takes Trump’s broadsides against state election authority seriously, he also said it’s important not to lose sight of the fact that, in his view, the administration is losing the argument across the board.

More than a dozen federal courts have unanimously rejected the federal government’s attempts to forcibly obtain state voter data, while other courts have rejected core pieces of his election-related executive orders. State officials have publicly — and at times, angrily — pushed back on the administration’s demands as blatant federal overreach. 

Becker predicted that such an act would be quickly shot down by courts as well, noting that the U.S. has never canceled or postponed an election in its 250-year history, including when British troops were marauding on American soil during the War of 1812 or even at the height of the Civil War.

It’s important not to conflate the White House’s bluster and intentions with its actual authorities or capability to seize control of U.S. elections.

“This is what panic and desperation look like,” Becker said. “They’ve had 18 months in total control of the federal government and they have found nothing that would support President Trump’s lies about the 2020 election, and so they’re just trying to grab as much garbage as they can and throw it up against the wall, and it’s not sticking.”

The post State officials, election experts pan Trump speech: ‘This is what desperation looks like’ appeared first on CyberScoop.

Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities

China-aligned attackers broke into the networks of U.S. and Canadian universities to steal sensitive data and establish persistent access via webshells and backdoors, Proofpoint threat researchers said Tuesday. 

The espionage-motivated attacks targeted physics and engineering departments, focusing on administrators and professors with national security links or organizations researching astrophysics and particle physics.

Proofpoint identified less than 10 university victims and estimates a few dozen universities may be impacted, Greg Lesnewich, principal threat researcher at Proofpoint, told CyberScoop. The company first observed the campaign in May and believes the campaign is ongoing. 

“There is a high likelihood that many victims have not been made aware of this activity yet,” Lesnewich added.

Researchers traced the attacks to a pair of critical vulnerabilities in Roundcube, an open-source email client, that were exploited and chained together to steal credentials and gain long-term access.

The threat cluster, which Proofpoint tracks as UNK_MassTraction, exploited CVE-2024-42009 to execute JavaScript inside the victim’s browser, then exploited CVE-2025-49113 to gain a foothold in the mailserver. 

The initial exploit in the chain only requires a victim to open an email, and the attackers sent victims a series of generic lures to trigger the initial access.

Proofpoint attributes the campaign to a China-aligned cluster because the attackers used a known covert network used by multiple China-aligned threat groups, an infection chain leading to VShell and left Chinese language artifacts in the phishing emails. 

Researchers haven’t drawn any conclusions about why attackers targeted the universities and what they are seeking. 

“We do not have data to suggest what got stolen, as we only observe the initial inbound email attempt,” Lesnewich said. 

The engineering aspects do align with China’s strategic initiatives, he added. Google threat hunters recently spotted a Chinese state-sponsored espionage group that burrowed into systems for years, stealing data across academia, medicine, military, cybersecurity and foreign policy. 

“China-aligned adversaries have been targeting other types of edge devices such as routers and VPN concentrators for years with various exploits to create a foothold into a target network, not using email for delivery,” Lesnewich said. “This campaign flips that on its head, using email to deliver an exploit chain to compromise a mail server, instead of using email to deliver a credential harvesting URL or malware to target an end user, not a server.”

The post Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities appeared first on CyberScoop.

Google exposes China espionage group that’s been lurking in networks undetected since 2023

Google threat hunters spotted yet another Chinese state-sponsored espionage group that for years had burrowed into systems belonging to government and private organizations to steal data across academia, medicine, military, cybersecurity and foreign policy. 

Google Threat Intelligence Group discovered the previously unknown threat group UNC6508, which targeted organizations in the United States and Canada, in late 2025 but traced its earliest known compromise back to September 2023. 

The revelation mirrors an alarming pattern of Chinese espionage groups dropping backdoors into critical infrastructure to pre-position for potential sabotage, intercept research and steal data with national security implications. These groups working at the behest of China’s government, including UNC6508, operated in stealth for years before authorities or researchers discovered their activity.

“We don’t know the full extent or impact of the campaign,” Patrick Whitsell, senior security engineer at GTIG, told CyberScoop. Researchers said the threat group intruded a medical research university in September 2023, stole credentials and communications, and remained active on the institution’s systems through November 2025 when it was discovered.

Google said it confirmed multiple victims compromised with INFINITERED, a custom backdoor the threat group deployed on targeted networks to steal administrative credentials after it exploited externally facing REDCap (Research Electronic Data Capture) servers.

Researchers still don’t know how UNC6508 gained initial access to the REDCap servers. Google said the survey and database software, which was created at Vanderbilt University and issued multiple patches for critical remote-code execution vulnerabilities throughout 2023, is widely used across the medical research community. 

“Given the breadth of the threat actor’s intelligence collection criteria and their ability to remain undetected within compromised networks for more than a year, we assess the known victims likely represent only a fraction of a larger campaign,” Whitsell said. “We also assess that this highly capable threat actor will remain active and continue to be a threat to the defense, technology and medical industries for the foreseeable future.”

Google said the campaign targeted clinical providers, academic medical centers and U.S. military health institutions, demonstrating advanced capabilities from a threat group that doesn’t currently overlap with any other publicly known groups.

The threat group abused domain compliance rules to steal data, a technique that doesn’t rely on malware or living-off-the-land tools, and routed traffic through U.S.-based IPs to blend in with legitimate traffic, researchers said.

“We have some evidence to suggest this is a large threat group with multiple sub-teams, but this is not confirmed,” Whitsell said.

Like other previously identified China state-sponsored espionage groups, UNC6508 remains active.

Google said it disrupted some of UNC6508’s known infrastructure by disabling an Gmail account it used to exfiltrate data, notified the affected organizations and helped remediate compromises before it published research on UNC6508’s activities.

Whitsell said several unconfirmed instances of compromise remain under investigation.

The post Google exposes China espionage group that’s been lurking in networks undetected since 2023 appeared first on CyberScoop.

FBI takes down massive China-based cybercrime network that caused $1.9B in losses

The FBI, along with Google and Lumen Technologies, took down a major cybercrime network based in China that was responsible for an estimated $1.9 billion in losses, officials said Friday. 

Outsider, which provided phishing kits and hosted infrastructure for cybercriminals since July 2023, facilitated a wave of phishing attacks against people and businesses in 55 countries, including the United States, the FBI said in a LinkedIn post.

The jointly coordinated effort dubbed “Operation Ghost Hook” netted the seizure of several domains of the group’s core admin servers, a Shopify storefront, roughly $100,000 from Outsider payment wallets and thousands of domains registered through U.S.-based providers, officials said.

The FBI said it also used an Outsider Telegram bot to access information on the cybercrime network’s customers.

“The criminals behind Outsider Enterprise built a business out of impersonating trusted brands to defraud hundreds of thousands of victims,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a statement.

Authorities traced Outsider’s phishing domains to nearly 3.9 million stolen credit cards.

Google, one of the vendors impersonated by the phishing kits, described Outsider as a massive AI-powered operation. 

Outsider provided its phishing kit, which allowed cybercriminals to create fake sites and phishing campaigns to steal credit cards, bank account credentials and personal data, for a weekly subscription as low as $88 per week, the company said in a civil lawsuit it filed to dismantle the cybercrime network’s infrastructure. 

The China-based group behind the operation encouraged and provided step-by-step instructions for customers to use Gemini and other AI platforms to generate custom code for phishing lures and corresponding sites for illegitimate missed packages, overdue highway tolls, parking violations, issues with a brokerage account or wireless carrier rewards.

“The Outsider software allows scammers to request multiple types of verification from victims, including SMS, PIN, email and app verification,” Google wrote in the lawsuit filed in the U.S. District for the Southern District of New York. “This flexibility enables the enterprise to defeat various forms of authentication security.”

Google said it’s working with AT&T, T-Mobile and Verizon to intercept the spam messages before they reach customers, but these types of phishing attacks are prevalent and have been spreading for years. 

Google is also pushing for legislative action, including a series of bills, to combat these scams, General Counsel Halimah DeLaine Prado wrote in a blog post.

“Litigation alone won’t end this,” she wrote. “As threats evolve, our laws must, too.”

Google said it doesn’t know the real names of the people or entities involved in Outsider, but said the operation is supported by multiple cybercrime groups providing different roles with overlapping infrastructure.

The FBI said the takedown was part of Operation Riptide, an ongoing campaign targeting cybercriminals and the infrastructure and financial networks they use to commit fraud.

The post FBI takes down massive China-based cybercrime network that caused $1.9B in losses appeared first on CyberScoop.

OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers 

OpenAI’s threat intelligence team tracked what it believes are two distinct clusters of activity online from groups with ties to China and posting content seemingly designed to stoke anger around divisive topics like AI and data centers.

The first, dubbed “Data Center Bandwagon,” used ChatGPT to create imagery and social media comments claiming data center buildouts were raising electricity prices for Americans.

Another used the tool to develop images and online posts characterizing tariffs as a covert means for the countries to exert control over the global technological landscape. According to OpenAI, the originating prompts directed ChatGPT to only include U.S. President Donald Trump in this content, while leaving out Chinese President Xi Jinping, who has also made use of tariffs.  

In both cases, OpenAI said the operators “likely originated” in China. The anti-data center content was traced to an unnamed Chinese technology company that holds multiple contracts with regional Chinese governments, and both clusters used VPNs to evade restrictions, prompted ChatGPT in simplified Chinese and asked for both English and Chinese-language outputs, all while posing as Americans on social media platforms like X and YouTube.

“This looks like a classic example of a foreign influence operation jumping onto the bandwagon of a genuine and pre-existing domestic debate and trying to manipulate it by using fake accounts posing as Americans,” online, said Ben Nimmo, principal investigator at OpenAI and author of the report. 

While OpenAI – which has sought to raise hundreds of millions of dollars in funding to build datacenters in the U.S. – is not a neutral party, the report does not claim that anti-data center sentiment in the country is being driven or bolstered by foreign propaganda online.

There’s little evidence that the campaigns got much attention outside their own amplification networks. Such engagement from third parties is an imperfect but important indicator of an influence operation’s impact. OpenAI rated the campaigns a 1 and 2 on the Bookings breakout scale, scores that indicate activity on one or more platforms but no evidence of meaningful engagement by targeted audiences.

Additionally, researchers who study state-sponsored influence campaigns say these groups are happy to latch onto and amplify genuine domestic movements or messaging so long as it serves their larger destabilization goals.

Others have suggested that piggybacking off established narratives with organic momentum – like public anger at AI and data centers – can make an influence operation appear more effective.

While AI tools can be leveraged to create such internet content at scale, they often fail to gain traction. Some images used by Chinese actors appear clunky or use overly direct messaging that display a lack of familiarity with both the English language and internet virality.

“I do want to be really clear here: this was not a case of an influence operation creating a debate,” said Nimmo. “The debate existed already. This was an influence operation from China trying to interfere in it. We didn’t see any signs that it succeeded.”

He added that while such views are “reasonable” and “sincerely held” by many participants on both sides, “what we don’t want to see is a covert foreign influence operation posing as Americans to try to shape it, still less a foreign influence operation using the very AI that it attacks.”

According to the OpenAI report, the actors used ChatGPT to edit work reports which contained operational security details about their social media campaigns. In them, they described their goals as “establishing persistent and credible accounts, producing visually appealing content to expand audience reach in different regions and maintaining long term account viability by anticipating platform enforcement.”

Another report fed into ChatGPT discussed how best to leverage Facebook’s content ecosystem, groups, pages, hashtags, advertising tools, recommendation systems and reporting mechanisms, as well as strategies for evading Meta’s detection of coordinated inauthentic accounts.

The campaign around tariffs also used ChatGPT to create short comments, comics in English but also Italian, Japanese and traditional Chinese accusing the US of putting profits over loyalty to its allies. OpenAI said they were targeted by the same network on X with an influence campaign alleging a widespread user data breach that Nimmo said “never happened.”

While OpenAI said the campaigns likely originated in China, they do not directly attribute the operations to the Chinese government or actors working on their behalf, but do note that many parts of the campaign and its tactics overlap with pre-established Chinese government propaganda campaigns online.

The post OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers  appeared first on CyberScoop.

Hill Dems hammer GOP for $250M CISA budget cut

House Democrats criticized a draft Republican Department of Homeland Security spending bill Thursday that they said would cut funding for the Cybersecurity and Infrastructure Security Agency by $250 million.

Republicans said the bill provides $2.4 billion for CISA, and that among its focuses are “improving cybersecurity resilience,” in the words of House Appropriations Chairman Tom Cole, R-Okla.

But Democrats decried it as a funding reduction. The panel’s subcommittee on homeland security is set to vote on the bill Friday.

The fiscal 2027 funding measure “dramatically cuts funding for cybersecurity and infrastructure protection despite an increasing number of sophisticated attacks from foreign adversaries against U.S. businesses, health care systems, utilities, schools, and state and local governments,” Democrats said in a fact sheet.

They also said it limits DHS’s ability to counter foreign propaganda seeking to undermine U.S. democracy, and to protect states against foreign groups during the elections.

The second Trump administration has sought deep cuts in CISA’s personnel numbers and budget in both fiscal 2026 and 2027, drawing concerns from both sides of the aisle.

Congress last year sought to implement some, but not all, of Trump’s proposed cuts for the agency, advancing legislation to set its budget at $2.6 billion.

In their fact sheet, Republicans said they were reallocating $100 million from past appropriations to fund CISA’s core missions.

They acknowledged some cutbacks, saying that the bill “Includes strategic reductions to redundant, unauthorized, or duplicative contracts, positions, and programs.”

Despite the cutbacks at CISA over the last year and a half, officials have talked about wanting to hire additional personnel. The fiscal 2027 bill includes “$31 million to hire mission critical positions to counter threats from foreign adversaries, such as China,” according to the GOP.

The GOP also highlighted other cyber funds in the DHS bill. DHS’s management director would get $11.3 million for “enhanced cybersecurity protections,” while the Homeland Security Investigations division of Immigration and Customs Enforcement would get $5 million for the Cyber Crime Center.

Neither panel Republicans nor Democrats responded to requests for comment seeking more detailed numbers for the fiscal 2027 bill.

The post Hill Dems hammer GOP for $250M CISA budget cut appeared first on CyberScoop.

House panel poised to hold hearing centered on AI impact on cyber

A House subcommittee will hold an open hearing next week on how frontier artificial intelligence models are shaping the cybersecurity landscape, for good and for ill.

The June 4 hearing will be the second the Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection has held that was focused at least in part on the subject, following a similar hearing held in December. But unlike at that joint subcommittee hearing, where members also examined other emerging technologies, AI takes center stage next week.

It caps a series of closed-door meetings of the Homeland panel where members and staff have been evaluating the intersection of AI and cyber. CyberScoop is first to report details on the hearing.

The witnesses will be Sandra Joyce, vice president of Google Threat Intelligence; Chris Meserole, executive director of the Frontier Model Forum; Jack Cable, a former top official at the Cybersecurity and Infrastructure Security Agency and now chief executive officer and co-founder of Corridor Security; and Matthew Guariglia, senior policy analyst at the Electronic Frontier Foundation.

“Communist China is moving aggressively to control the technologies that will define the future of economic and military power, and few technologies are more consequential than artificial intelligence,” subcommittee chairman Andy Ogles, R-Tenn., said in a written statement. “Adversaries are already working to steal American AI capabilities, weaponize AI-enabled tools, infiltrate critical systems and undermine our national security.”

“AI is the America First mission of the future, and it is becoming our number one offensive and defensive weapon against cyber terrorists,” he continued. “I look forward to hearing from our witnesses on how we can stay ahead of AI-enabled cyber threats, protect the services Americans rely on and win this AI arms race.”

The hearing is the latest response from Capitol Hill to the spate of news about the capabilities of advanced AI models to uncover cyber vulnerabilities. Earlier this month, for instance, lawmakers wrote to National Cyber Director Sean Cairncross asking for a plan to deal with the potential surge in vulnerability discovery stemming from such models.

Last week, the Trump administration postponed a draft AI executive order. It’s something lawmakers are likely to ask about at next week’s hearing.

The post House panel poised to hold hearing centered on AI impact on cyber appeared first on CyberScoop.

UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace

Artificial intelligence is an “unstoppable force” that allows tech to be “weaponized just below the threshold of traditional warfare,” including in cyberspace, the head of a U.K. intelligence, security and cybersecurity agency said Wednesday.

We live in a world “where the latest frontier AI is rapidly unearthing fault lines in technologies our society relies on every single day,” said Anne Keast-Butler, director of the Government Communications Headquarters (GCHQ) spy agency. “The ground beneath our feet is shifting, and shifting fast. Which means cybersecurity has never been more important.”

She added; “we need to reimagine cybersecurity in the AI world.”

Keast-Butler said her agency has spent the last few months developing defensive capabilities that are integrated with agentic AI, and embedding it into its operations “responsibly and ethically.”

Her speech offered the view of one of the world’s cyber superpowers about how AI is evolving both cyber offense and defense. The GCHQ is the largest of the U.K.’s spy agencies and home to the National Cyber Security Centre.

The U.K.’s AI Security Institute recently reported on how advanced AI models have surpassed prior benchmarks for autonomously uncovering vulnerabilities. At the same time, government officials in Europe, the United States and elsewhere have warned about how AI will exacerbate cyber risks.

Keast-Butler said Wednesday that “warfare is being reconfigured; increasingly data-driven, AI-enabled, and automated in conflicts from Ukraine to Iran.”

Overall, “AI is an unstoppable force with great opportunity. But it’s also a force with risks,” she said. “As AI gains increased autonomy, we all have an intergenerational duty to harness and secure it for good; to protect our national security, our economy and our way of life.”

She warned about China’s arrival as a tech superpower, which includes its sophisticated cyber capabilities. She said China recognizes the value of AI combined with the availability of massive amounts of data.

And Russia is upping its use of hybrid warfare against both Ukraine and the U.K., Keast-Butler said, with both cyber and physical forces.

The post UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace appeared first on CyberScoop.

❌