❌

Reading view

There are new articles available, click to refresh the page.

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public.

First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and Technology panel, are introducing the Telecommunications Cybersecurity and Resilience Act.

“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”

Federal officials have repeatedly warned that Salt Typhoon — the Chinese group blamed for the massive and “indiscriminate” espionage campaign that hit major telecom carriers and siphoned data from presidential campaigns and candidates — remains a threat to this day.

Yet some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules. In one case the Trump administration has rolled them back.

The Warner-Cruz legislation takes the approach of trying to improve telecom security with voluntary measures jointly developed by government and industry.

“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.”

Their bill would create a telecom cybersecurity working group within the National Telecommunications and Information Administration to bring together carriers, suppliers, experts and relevant government agencies. 

The working group would develop voluntary industry-wide best practices within 18 months of passage of the bill, which would be reviewed for updates every two years or after major incidents.

The best practices would “focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities,” according to the legislation, and would be in line with existing federal cybersecurity risk management frameworks.

The working group would also create a voluntary certification process through independent third-party assessors that companies could choose to use.

“What is missing” now, according to a summary of the bill, “is a common, telecom sector-specific set of best practices that brings that expertise together and can evolve as threats and technology change. Building on industry’s familiarity with security development and threat information sharing, this bill would bring stakeholders — government and private sector — together to develop and maintain effective techniques and practices to secure networks.”

The post Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks appeared first on CyberScoop.

Dem senators criticize Trump administration decisionmaking on AI security risks

The Trump administration’s haphazard and opaque interventions into artificial intelligence security matters could catapult Chinese alternatives into broader acceptance, posing new security risks altogether, a group of Democratic senators wrote to top administration officials Monday.

The five senators said that the administration’s handling has alternated between too passive, such as when OpenAI models escaped testing in the Hugging Face hack last month, and overstepping, such as when the Commerce Department suspended access for any foreign national to Anthropic’s Fable 5 and Mythos 5 in June.

“The Administration’s ad hoc and unpredictable approach undermines U.S. competitiveness, heightening market incentives to adopt open weight models from vendors based in the People’s Republic of China (PRC),” wrote Sens. Kristen Gillibrand of New York, Adam Schiff of California, Mark Warner of Virginia, Chris Coons of Delaware and Mark Kelly of Arizona.

In the Hugging Face hack, the senators wrote that “the Federal Government cannot be passive as these capabilities emerge.”

In the case of the Fable 5 and Mythos 5 suspensions, the senators said that the administration “utilized an infrequently used authority to direct Anthropic to suspend all access to its Fable 5 and Mythos 5 models for foreign nationals (including foreign national employees inside the United States) citing an undisclosed national security concern later described as a narrow jailbreak finding.”

Because Anthropic couldn’t immediately assess users’ nationality, the firm had to disable both models for everyone. The administration and Anthropic negotiated for 18 days behind closed doors before reaching an agreement, the lawmakers complained.

“While the Administration may have been responding to real security concerns to protect the United States, even justifiable interventions can create broader harm if the standards and decision-making processes are opaque, ad hoc, or unpredictable,” they said in their letter to leaders in the White House, Office of the National Cyber Director and departments of State, Treasury and Commerce. “Moreover, when the Executive Branch exercises authority delegated from Congress, such as in the conduct of export control administration, it is essential that it keep Congress fully apprised of its actions and procedures.”

During the time Anthropic was under export controls, the stock price of “an entity-listed Chinese lab” nearly doubled, the senators said. And while Hugging Face was breached, the company “had to” rely on a Chinese open-weight model due to guardrails on U.S. frontier models.

“If American models are perceived as subject to sudden access disruptions based on a black-box U.S. Government process, or as unreliable because U.S. AI labs are overcorrecting in the face of this black-box process, companies and governments in the United States and abroad may hedge by adopting Chinese or other foreign models instead,” the senators contended. “That outcome would undermine U.S. technological leadership while increasing exposure to systems that may carry risks of PRC or otherwise directed censorship, espionage, IP theft, and other supply chain security risks.”

Their letter asked for answers to questions about the standards the administration uses to determine the national security risks a frontier model presents, what legal authorities it will use to invoke restrictions, which agencies are responsible for which decisions and more.

None of the offices or departments the letter was addressed to immediately responded to a request for comment.

The letter follows inquiries at the state level, where 15 attorneys general asked OpenAI for more information regarding the security incident at Hugging Face.

The post Dem senators criticize Trump administration decisionmaking on AI security risks appeared first on CyberScoop.

Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming

With identity protection services for millions of victims of the 2015 Office of Personnel Management breach set to expire, a group of lawmakers is making a push to extend them forever.

Sen. Mark Warner, D-Va., and Del. Eleanor Holmes Norton, D-D.C., introduced legislation to give lifetime identity protection coverage to around 4.2 million federal employees exposed in the historic breach by alleged Chinese hackers, which affected 22.1 million people. Warner said “the threat remains,” necessitating lifetime coverage.

That coverage is due to end at the end of September, as set by a 10-year authorization from Congress. That prompted the pair of lawmakers to introduce Reducing the Effects of the Cyberattack on OPM Victims Enduring Response and Protecting Identifiable Information Act, or  RECOVER PII Act.

“The data stolen included workers’ most sensitive and personal information – from Social Security numbers to security clearance records – and once that information is in the hands of a bad actor, you don’t get it back,” Warner said in a news release Monday. “We have a responsibility to stand by the federal workers who were put at risk through no fault of their own. This legislation will ensure those affected continue to receive the identity protection they need, while helping better safeguard personal information from future exploitation.”

But the bill could have an uphill climb, given the makeup of Congress and stance of the Trump administration.

The Democratic co-sponsors in the Senate are Tim Kaine of Virginia, with Angela Alsobrooks of Chris Van Hollen, both of Maryland. The Democratic House cosponsors are Reps. Don Beyer and James Walkinshaw of Virginia, with Steny Hoyer of Maryland.

Warner and Norton listed no co-sponsors from the GOP, which controls both chambers of Congress and the White House.  And OPM has declared the program too expensive based on the cost relative to the number of claims.

Similar legislation to extend the coverage, including from Norton, has fallen short in recent years.

“Lifetime identity protection is the only solution that will give the workers whose data was compromised the peace of mind they deserve,” Norton said Monday. “Because there is no limit on how long personal information can be exploited, Congress must protect these federal employees and contractors in perpetuity.”

Some watchdog scrutiny of the OPM program has been critical, and while consumer advocates say identity theft protections are helpful, they nonetheless say they aren’t adequate.

The Warner-Norton legislation also would offer reimbursements to federal employees and contractors for privacy services.

The post Lawmakers spring to save ID theft services for OPM breach victims, with expiration looming appeared first on CyberScoop.

Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed

Democratic senators pressed President Donald Trump’s pick for director of national intelligence on questions of election security and integrity Wednesday, but they didn’t leave his nomination hearing satisfied with the answers.

As is typical for Trump administration nominees, Jay Clayton wouldn’t answer definitively at his Senate Intelligence Committee confirmation hearing whether Joe Biden won the 2020 presidential election, saying only that he was “certified,” while maintaining that he wasn’t an “election denier.”

He said that the Office of the Director of National Intelligence’s responsibilities were “principally” outside the United States. But he claimed varying degrees of ignorance about his predecessor, Tulsi Gabbard, being physically present at an FBI raid of a Georgia election office in January, and wouldn’t comment on its appropriateness.

Democratic senators were also frustrated while trying to pin down Clayton, the U.S. attorney for the Southern District of New York who served as head of the Securities and Exchange Commission in Trump’s first term, on remarks about mail-in ballots and the California primary election results last month.

Multiple senators, including Mark Warner, D-Va., Angus King, I-Maine and Mark Kelly, D-Ariz., tried to get Clayton to say whether Biden won the 2020 election. The final exchange came with Jon Ossoff, D-Ga.

Clayton protested that he had already answered. “I think I’ve answered the question,” he said. “We can keep doing this.”

Ossoff didn’t agree, telling him, “Well we’re going to keep doing it because you’re not being honest or forthright with the committee.”

“Isn’t it humiliating to be unable to answer this question?” he asked. “To have to indulge the president’s delusions? We know, you know, everybody in this room knows the truthful answer to that question. Why can you not give it?”

Earlier Clayton had said, “I’m not an election denier,” but repeatedly wouldn’t answer “yes” or “no” on whether Biden won in 2020.

That matters because of the DNI’s role, Kelly said, and it was worrying that Clayton was seeking to avoid upsetting Trump, who has maintained despite all evidence that he lost the 2020 election.

“It’s not about softening the edges when the truth is unpleasant,” Kelly said. “It’s about delivering information.”

Clayton discussed the DNI’s role on election security at greater length in pre-hearing written answers.

“I understand that the DNI, as head of the Intelligence Community, has substantial statutory authority to address national intelligence threats to U.S. elections,” he said. “In particular, the Director is responsible for the integration of national intelligence, which may include foreign intelligence threats to U.S. election activity. I also understand that Intelligence Community elements are authorized to cooperate with and provide appropriate intelligence and technical support to law enforcement agencies and that as head of the Intelligence Community, the DNI has oversight of those activities.”

A CNBC interview last month inspired some of the Democrats’ questions. Clayton said in response to questions about the California primaries that “On the integrity side, we’re doing an absolutely terrible job. And the American people are right to question it.” 

He said mail-in ballots present an “opportunity for fraud,” despite studies showing exceptionally low rates of fraud using that method, and said “mail-in ballots being used by one group and not another… honestly and dishonestly” was a “question that everyone is now asking.”

Sen. Ron Wyden, D-Ore., asked him about what group Clayton was referring to.

“”I would like to see where you’re pulling those quotes from. I’ve been very careful about my remarks on this,” Clayton answered. “I’d like to see the whole passage.”

In his questionnaire, when asked if “it would be inappropriate for a DNI to comment publicly about unsubstantiated claims regarding mail-in-ballots and election fraud,” Clayton answered that “If confirmed as DNI, any representations I make to the public, including about elections, will be informed by timely, objective national intelligence.”

Ossoff also had a tense exchange with Clayton when asking him about Gabbard’s appearance at the Fulton County office raid. Gabbard has said she was there because Trump asked her to be, in what subsequently became a highly publicized appearance because of questions about what the DNI would be doing at a law enforcement raid.

“I was made aware of it by you yesterday,” Clayton said.

Ossoff responded skeptically: “The first time you learned that Director Gabbard was present at that raid was in my office yesterday?”

Said Clayton: “It was the first time that in my recollection I’ve thought about it recently.”

“What?” Ossoff replied.

Warner, the top Democrat on the committee, told Clayton “I trust you” but it “strains credulity” that he wasn’t aware of Gabbard being at the raid.

“To be clear, the ODNI’s role is principally outside of the United States,” Clayton said.

On other topics, in his opening remarks, Clayton touted his SEC work on cybersecurity. In his questionnaire he said he would work to facilitate cyberthreat information sharing from his office.

He told Sen. Kirsten Gillibrand, D-N.Y., that he would evaluate whether the DNI should devote more resources to cybersecurity with federal government cyber experts being pushed out since Trump came back to office. Many Republicans are pushing to further reduce the size of Clayton’s office, contending it has become bloated beyond Congress’ original intentions as a coordinating body.

He said he supported renewal of Section 702 of the Foreign Intelligence Surveillance Act, which gives the executive branch controversial spying powers that Congress recently allowed to expire.

Trump has threatened to block renewal unless lawmakers advance his priority election bill. He said he will study how to “minimize the detrimental impact to our national security caused by the lapse in 702 authorities.” Some Democrats, meanwhile, have resisted action on the law until Trump’s pick for acting DNI Bill Pulte is gone, citing his prior efforts to investigate officials as head of the Federal Housing Finance Agency and lack of intelligence experience.

Because the GOP controls the Senate, Clayton is likely to get confirmed as DNI as long as no Republicans emerge in opposition. Wednesday’s hearing revealed no significant Republican objections.

Intelligence Chairman Tom Cotton, R-Ark., touted Clayton’s experience prosecuting terrorism cases and more.

“Jay Clayton has worked hand in glove with our intelligence agencies and counterterrorism personnel to lock up criminals who threaten our national security,” Clayton said. “I encourage my colleagues to join me and get Mr. Clayton’s nomination over the finish line.”

The post Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed appeared first on CyberScoop.

Warner bill would create federally vetted list for secure, trustworthy AI agents

A new Senate draft bill would establish a list of AI agent software providers that people can use to establish human ownership and securely run agents on social media and other online platforms.

The Artificial Intelligence Access, Gatekeeper Exchange, and Nondiscriminatory Transfer (AI AGENT) Act, led by Sen. Mark Warner, D-Va., would allow end users of large online platforms with more than 50 million customers or subscribers per month the right to choose at least one AI agent provider who complies with security and identity standards developed by the Federal Trade Commission.

Such agents are increasingly making decisions on behalf of users, like shopping, posting content on social media, or changing account settings, sometimes without the user’s consent or knowledge.

Under the bill, the FTC would certify independent bodies to vet AI agent vendors. These certification bodies would ensure products meet baseline protections for privacy, data security and acting in the user’s interest. The bill would also require providers to link each AI agent to its human operator’s identity and to include built-in controls that let users clearly grant or revoke permission for the agent to act on their behalf.

While the commission cannot bar platforms from using AI agent providers that fail to meet those standards, it can deregister violators from the FTC list.

The bill is a discussion draft, and Warner said he was releasing it now to receive feedback before introducing a formal version for consideration in the Senate.

“As agentic AI transforms how Americans interact with technology, consumers deserve a real choice in the marketplace – and AI agents must be accountable to the people they serve,” Warner said in a statement. “This discussion draft is a major step toward building a clear federal framework that promotes innovation, protects consumers, and ensures the United States continues to lead the world in emerging technology.”

Last year, Morgan Stanley estimated that nearly one-in-four (23%) Americans made purchases using AI over a 30-day period, and that agentic shoppers could account for potentially hundreds of billions of dollars in online commerce by 2030.

But AI agents can still be unreliable or erratic. They can make absurd purchases that a user would never knowingly approve, leak sensitive data or act contrary to a user’s interest.

As more agents flood the internet, it increases the likelihood of AI bots interacting with and buying from other AI bots – underscoring the need for safe or regulated user solutions that can verify accountable human identities behind AI activity and provide baseline security and privacy protections.

The Trump administration is trying to find its own baseline for regulating frontier models. Earlier this month the Department of Commerce placed export controls on Anthropic’s Mythos 5 and Fable 5 models, and the two parties are attempting to negotiate a framework to provide government oversight of newer releases.

An AI executive order released by the Trump administration set up a voluntary 30-day testing program for AI companies to submit certain frontier models for testing and evaluation, but the administration imposed the export controls days after Anthropic released Fable 5 publicly, reportedly citing concerns that the model could be jailbroken.

Anthropic claims that extensive internal testing has identified no universal jailbreaks for Fable 5 and that third-party research released thus far hasn’t shown that their guardrails preventing access to the model’s enhanced cybersecurity or biological capabilities have been circumvented. Those are the capabilities that Anthropic cited when it held back its newest model, Mythos, from public release.

The post Warner bill would create federally vetted list for secure, trustworthy AI agents appeared first on CyberScoop.

❌