Reading view

There are new articles available, click to refresh the page.

Supply chain challenges loom large in quantum race, White House official says

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday.

“Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined by a single hardware platform,” said Brad Blakestad, director of the National Quantum Coordination Office within the White House Office of Science and Technology Policy.

“If you look at the quantum computing technologies, the quantum sensing technologies, the networking — those are all different,” he said in a webinar hosted by Inside Cybersecurity and USTelecom. “And even within computing, there’s seven different modalities that use completely different components. So we have this not just one monolithic supply chain, but just a bunch of different supply chains that are kind of intertwined in various ways.”

Blakestad made his remarks a little more than a month after President Donald Trump signed two executive orders on quantum computing. He referenced proposed ways to address the supply chain challenge in one of the orders.

“The other major issue or challenge that we face right now is that we’re on the cusp of quantum exploding from a commercialization perspective, but we’re not quite there yet,” he said. “So there’s not the funding, the revenue coming from large-scale quantum companies at this point to really make the supply chain as robust as you would want. So thinking about it from the government perspective, it’s just [that] there are too many places that I would want to bolster and not enough funding to do it.”

Blakestad touted steps to help that along such as the government buying widgets from a company that makes them to certain specifications, or prize challenges.

The quantum supply chain isn’t just diffuse in the United States, an International Institute for Strategic Studies policy paper noted Wednesday. It’s “inherently international: no single country dominates the supply chain, whether specialised materials, cryogenic equipment, hardware, software, fabrication or algorithms,” the authors, Dongyoun Cho and Maria Shagina, wrote.

And a March report from the Center for a New American Security identified strengthening the quantum supply chain as pivotal to the United States seizing the benefits of the technology, citing gaps in the U.S. supply chain and reliance on foreign suppliers such as China and Russia. 

Supply chain wasn’t the only obstacle Blakestad mentioned as looming large.

“The encryption challenge is a real challenge, and we want to make sure that we are aware of when quantum computers will ultimately get to a scale that they start having these sorts of implications and move as quickly as we can,” he said. “So, just by owning the technologies, by owning the workforce, by making the United States the place that people want to come to be on the cutting edge of this technology, I think that kind of addresses both of those issues, and that’s what makes it so critical.”

Another difficulty is measuring progress, Blakestad said: “It’s also very, very hard to benchmark, and to know that you’re actually doing what you’re supposed to, what you are intending to do.”

The post Supply chain challenges loom large in quantum race, White House official says appeared first on CyberScoop.

White House charts new course for federal agencies and cybersecurity logging

The White House has updated rules for federal agencies to keep logs of significant cyber activities in their networks, touting it as a measure to cut back on red tape and focus on how cybersecurity risks have evolved.

The Office of Management and Budget memorandum, released Friday, replaces a 2021 memo signed by then-President Joe Biden. It continues revisions that President Donald Trump has made to federal cybersecurity guidance under his predecessor.

The new memo, M-26-14, nods at the intentions of the earlier memo, M-21-31, saying that “Implementation of that memorandum improved foundational capabilities across agencies” to establish standards for logging and improve agencies’ record-keeping for the purposes of detecting and responding to cyberattacks.

“However, some requirements, such as the retention of vast quantities of logging data without clear utility, proved neither operationally feasible nor cost-effective for most agencies,” last week’s updated memo states. “To address these inefficiencies and the evolving cyber threat environment, this memorandum directs agencies to employ a risk-based, prioritized logging approach.”

There have been calls for the idea of updating the 2021 memo, and one observer praised the new version to CyberScoop. Another analyst, however, questioned how much harm the Trump administration might do by rescinding the earlier memo before having all of the new memo’s directives in place.

One directive is for the Cybersecurity and Infrastructure Security Agency to develop a “logging reference architecture” within 90 days that prioritizes the objectives of conducting continuous event monitoring and enabling investigations of forensic analysis after a known or suspected compromise.

Agencies would have another 90 days to submit a logging plan that adheres to those principles. The memo also establishes a new model for measuring agency progress in implementation. Multiple government watchdogs have concluded that agencies weren’t meeting the prior memo’s benchmarks.

The new memo “sharpens focus on real-time threat detection and the ability to investigate and recover after a cyber attack,” John Harmon, regional vice president of cyber solutions at Elastic, told CyberScoop. “It gives agencies the flexibility to build logging architectures that fit their specific mission.”

Harmon also praised the memo’s recognition of artificial intelligence risks to cybersecurity, and the revised maturity model.

But Nick Leiserson, senior vice president for policy at the Institute for Security and Technology think tank, said the timing of the replacement memo and the rescinding of the previous memo will give agencies a reason not to budget and prioritize logging for a period of time that adds up to six months or more.

“Moving from that to nothing is not ideal, and that’s essentially what this is doing,” Leiserson, who served in the Biden administration’s Office of the National Cyber Director, told CyberScoop. “This is saying ‘We’re rescinding 21-31 right now’ You won’t have any new guidance for at least 90 days, when CISA publishes this logging reference architecture, and it’s not clear to me why you would disaggregate that and not have the two of those things come out at the same time.”

The post White House charts new course for federal agencies and cybersecurity logging appeared first on CyberScoop.

White House cyber official: identity security matters more than ever in the age of AI

As AI becomes more integrated into federal IT (and attacker toolsets) government agencies will need to focus their resources on regulating and monitoring the identities that access their network, a top White House cybersecurity official said Thursday.

Nick Polk, branch director for federal cybersecurity in the Executive Office of the President, said that while AI models will present unique threats to federal networks, they will still generally require trusted access first, something defenders can use to their advantage.

“I think the important thing is that in many cases in order to use and exploit the vulnerabilities that [AI] might find, or use them in a manner…that could be malicious or adversarial, the first thing you have to do is get into the network,” Polk said at the Rubrik Public Sector Summit presented by FedScoop. “There are some cases where your software is facing the internet, there’s a little bit of an easier solution there, but most times you have to get into the network.”

That often means exploiting the access an employee, contractor or third-party vendor has to your systems and data. Even in an AI-powered future, the network security boundary still matters, providing organizations with meaningful control over who gets access to their systems and data and how.

“That’s really where strong identity is still really critical in order to [first] repel an attempted exploitation before it can happen or, [second,] identify very quickly that this person or this machine really shouldn’t be on the network” or is behaving anomalously,” Polk said.

However, even before large language models emerged, cybercriminals and foreign adversaries were increasingly compromising organizations not with malware or sophisticated exploits,  but by gaining network access through stolen accounts, credentials, and other trusted assets.

Federal identity security, already a concern, is now set to become more critical in the age of AI.

Justin Ubert, director of cyber protection at the Department of Transportation, said beyond speed and scale, AI tools have given malicious hackers other advantages, like obviating the need for stealth.

“Now, you can have a smash-and-grab of your network that’s faster than you can respond to because…there’s no need to be quiet: just go in, grab and go [home],” said Ubert. “By the time your fences are working as they’re supposed to be, as we designed them to be, they’re already gone.”

AI tools can also easily become insider threats. Even when users restrict their ability to perform sensitive actions like downloading or exfiltrating data without human input, models have bypassed those guardrails by exploiting obscure technical loopholes.

Research released last month by the University of California-Riverside found that automated AI agents “can become dangerously fixated on completing assignments without recognizing when their actions are harmful, contradictory or simply irrational.”

The study, which examined Anthropic’s Claude Sonnet and Opus 4, as well as OpenAI’s ChatGPT-5, found that model agents struggled with contextual reasoning, had biases towards taking action (i.e. figuring out how to do something instead of whether to do it) and would frequently get tripped up by contradictory or infeasible goals.

Anna Libkhen, acting CISO for the Bureau of Economic Analysis at the Department of Commerce, said that AI has become “much more clever in hiding how it managed to penetrate and attack and come through as a trustworthy source.” 

When asked how the federal government was working to address current gaps in identity security that are increasingly being exploited by AI systems, Libkhen said federal leaders are “peeing in their pants” before adding “at least I am.”

“It is scary, yes, we are very vulnerable,” Libkhen said.

She compared the use of AI agents to teaching a child to ice skate: the first thing you teach them is how to handle a fall and recover. Likewise, organizations will need to plan for when their agents fail and quickly recover lost assets.

“Our agents will go wrong, they will do things we don’t expect them to. How do we get up?” said Libkhen. “Do we have that third set of data because that agent erased the database and the backup? Is it safe elsewhere? What kind of holes can you anticipate and what will it take for us to recover from those holes?”

The post White House cyber official: identity security matters more than ever in the age of AI appeared first on CyberScoop.

DOJ releases legal rationale for nationwide voter data collection


The Trump administration released a legal opinion outlining the legal rationale behind its nationwide voter data collection efforts, justifying an aggressive federal role in vetting voter eligibility, a position courts have repeatedly rejected in related litigation.

The memo, released Tuesday by the Department of Justice Office of Legal Counsel, concedes that while election administration is “primarily the purview of the states,” the administration’s efforts are a lawful exercise of federal oversight. 

The Justice Department grounds that rationale in a provision of the 1960 Civil Rights Act, requiring election officials to keep voter records for 22 months after an election so it can investigate potential civil rights violations. Under the memo’s reading, that retention rule also gives the Attorney General authority to obtain copies of those records “upon demand in writing.” 

The memo also cites several other federal election laws – like the Help America Vote Act, the National Voter Registration Act and the Voting Rights Act – as support for the executive branch’s efforts. It argues that those statutes have long required states to modernize and secure voting systems (including accessibility upgrades) and maintain accurate voter rolls by removing ineligible voters.

The memo further argues that the potential presence of one or more non-citizens on state voter rolls is enough to trigger the federal government’s nationwide data collection and sharing efforts with immigration authorities.

“Because illegal aliens are ineligible to vote, these generally applicable laws are also implicated by an illegal alien’s presence on a state’s voter rolls,” the memo states.

Multiple federal courts have come to the opposite conclusion, dismissing half a dozen lawsuits from DOJ and the Department of Homeland Security that would force states to comply. Further, states have repeatedly confirmed through recounts, audits, investigations and lawsuits that the number of non-citizens registered to vote (and who end up actually casting ballots) in U.S. elections is infinitesimal.

David Becker, executive director of the Center of Election Innovation and Research, noted in a post on BlueSky that “6 courts, including 2 judges appointed by the current president, think this ‘opinion’ isn’t worth the paper it’s written on.” Becker, a former DOJ senior trial attorney in the voting section of the Civil Rights Division, has consistently argued that the executive branch and White House have no legal or constitutional role to play in vetting state voter registration. 

Sarah Copeland Hanzas, Secretary of State for Vermont, gave a similar reaction when CyberScoop reached out for comment.

“It’s not worth the paper it’s printed on,” Hanzas said in a statement. “Or the electrons it takes to store and transmit 41 pages of fantasy.”

Election officials have largely resisted the federal government’s demands. Earlier this year, West Virginia Secretary of State Kris Warner told CyberScoop he had no intentions of handing over more information than is already publicly available.

“If they want it, they can have it: $500 dollars for [anyone to buy] the statewide list, but they’re not getting personal information,” Warner said in a January interview. “State law says we’re not sharing that and my job is to carry out the law laid out by the West Virginia legislature.”

The inability of the federal government to point to serious evidence of mass voter fraud or non-citizen voting has led states to rebuff attempts to collect sensitive data on every voter in their state, including names, social security numbers, home addresses, voter history and other details.

The administration says it intends to cross-check state data against immigration records, share that data with DHS and immigration enforcement agencies and ultimately create its own list of eligible voters. An executive order issued by the White House earlier this year sought to deny federal funding to states that did not accept voter lists from the federal government and directed the Attorney General to investigate state election officials for voter roll discrepancies. Voting groups have challenged the order’s legality, and a previous election-related executive order was largely ruled unconstitutional by the courts.

The administration has sued dozens of states who have refused to hand such data over, though it has yet to convince courts of the merit. One judge called the administration’s efforts “unprecedented and illegal” and accused the administration of twisting the Civil Rights Act and other federal laws that were passed “to protect hard won civil rights victories allowing access to the ballot box” in order to obtain unfettered access to state voter data.

The post DOJ releases legal rationale for nationwide voter data collection appeared first on CyberScoop.

❌