❌

Reading view

There are new articles available, click to refresh the page.

Supreme Court permits states to use SAVE database for citizenship checks

The U.S. Supreme Court ruled Friday that states may use the federal SAVE database to verify voter citizenship, reversing lower court decisions that found the database was inaccurate and would likely disenfranchise eligible voters.

In its opinion, the majority wrote that “the Federal Government has an obligation to respond to requests from state and local election officials seeking to verify the citizenship of voters.”

“The District Court’s order thus inhibits the Federal Government’s efforts to assist state and local agencies in the proper administration of the midterm elections, the ruling reads. “Under these circumstances, the equities weigh in favor of a stay.”

The Department of Homeland Security initially designed the SAVE database to determine benefit eligibility for immigrants and to track applicants pursuing U.S. citizenship. Under the Trump administration, it had been repurposed to screen voters for citizenship. Critics say the tool is outdated, often inaccurate and poses a significant risk of wrongly removing eligible voters from rolls.

Voting rights groups, including the League of Women Voters and the Electronic Privacy Information Center, filed suit last year. They argued that combining SAVE data with Social Security records violated confidentiality provisions in the Social Security Act, the Privacy Act and the Administrative Procedures Act.

While the ruling permits states to use the database, adoption remains uncertain. Some conservative states have used SAVE previously, saying it has been helpful in maintaining voter rolls. However, most states have resisted the federal government’s efforts to use citizenship verification systems or wrest control of voter registration efforts away from states. The Trump administration has lost 23 federal court cases in attempts to compel states to share additional data.  

Election experts said that the ruling’s impact on 2026 is likely to be limited because of federal laws that bar states from making changes to voter registration within 90 days of an election.

“Given that the SAVE system is used purely as a voluntary system to assist states in keeping their voter lists accurate, states may find this to be a helpful tool to use alongside other mechanisms to keep their lists up to date, even as the Department of Homeland Security itself admits the data is not perfect and evidence suggests the SAVE system has significant flaws,” said David Becker, executive director of the nonprofit Center for Election Innovation and Research.

Three justices – Ketanji Brown Jackson, Sonia Sotomayor and Elena Kagan – dissented, noting that “without full briefing or oral argument, this Court now grants [a stay]—rendering questionable interim rulings about two statutory provisions it has never before interpreted.”

There are laws and procedures that govern how and when federal systems are changed or modified. In this case, DHS did not create a legally mandated system of records notice (SORN) for the SAVE database outlining the broader impacts of the changes on data privacy. Nor did they engage in or offer a public comment period. Instead, they simply announced in May 2025 that the database was ready for use.

In court, the administration cited the Illegal Immigration Reform and Immigrant Responsibility Act to justify merging DHS and Social Security data. That argument was rejected by lower courts, and dissenters argued that the Supreme Court majority overturned those rulings without deliberation about whether the administration’s legal reasoning was sound.

“The majority thus treats [the Illegal Immigration Reform and Immigrant Responsibility Act] as essentially overriding the limits that privacy laws impose on the sharing of citizenship information with DHS. But that ‘back-of-the-napkin assessment,’ is implausible,” wrote Jackson.

The post Supreme Court permits states to use SAVE database for citizenship checks appeared first on CyberScoop.

House and Senate members propose legislation for CISA to step up cyber defenses for biotech

Biotechnology doesn’t fall neatly into any one of the 16 government-designated critical infrastructure sectors that receive specialized and focused attention from feds, leading some lawmakers to worry that it’s not getting the protection from cyberattacks and other risks that it needs.

That’s why a bipartisan group of senators and representatives announced legislation Thursday that would place an emphasis at the Cybersecurity and Infrastructure Security Agency on defending biotechnology, biomanufacturing and biological data.

The Protecting Biotechnology and Biomanufacturing as Critical Infrastructure Act and the Protecting Biological Data Act are two separate bills with the same group of cosponsors. Both bills would weave biotech into the law that established the Department of Homeland Security.

The former would direct DHS to come up with plans to make sure biotech and biomanufacturing are protected as critical infrastructure, but not as a whole new sector. The plans would identify key biotech players, conduct outreach to them and develop steps to update the National Infrastructure Protection Plan this year to incorporate biotech sector input.

The latter would make sure that systems handling genomic sequences and sensitive biometric data are covered as critical infrastructure and integrated into the national cyber strategy, that CISA would work with biotech players on security steps like joint exercises and that the agency would get new personnel to handle biometric data security.

In the last two months, biotech giants Boston Scientific and Amgen have revealed that they suffered recent cyberattacks.

Sponsors of the measures include leaders and members of the National Security Commission on Emerging Biotechnology, a legislative advisory group.

“Biotechnology infrastructure and data are becoming vital to America’s economic and national security,” said Commission Chair Senator Todd Young, R-Ind. “Just as we are serious about where the sensitive data of Americans is stored and who can access it, we should be equally serious about protecting our biological data and infrastructure. Designating biotech as critical infrastructure is about recognizing its strategic importance and making sure the capabilities America will depend on tomorrow remain resilient and protected from foreign threats.”

Notably, however, the bills do not seek a separate critical infrastructure category for biotech to add to the 16. Currently, biotech cuts across a number of existing sectors, including the health, agricultural and industrial sectors.

Some industry groups and experts have lobbied for the inclusion of new critical infrastructure sectors, such as space or artificial intelligence.

“Protecting biomanufacturing infrastructure and the most sensitive biological data of Americans is essential for our national security,” said commissioner Rep. Ro Khanna, D-Calif. “These bipartisan bills will help ensure we are protecting this sector from physical and cyber threats while keeping America as the world leader in biotechnology.”

The bill’s sponsors in the House are Khanna, Stephanie Bice, R-Okla. and Scott Peters, D-Calif., and in the Senate the sponsors are Young and Maggie Hassan, D-N.H.

You can read the text of the bills below.

The post House and Senate members propose legislation for CISA to step up cyber defenses for biotech appeared first on CyberScoop.

New bill would create federal investigative body for AI-driven hacks 

A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others.

The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a federal mechanism to investigate incidents where AI models escape sandbox environments and access live internet systems.

Currently, frontier AI companies like OpenAI and Anthropic largely control the investigation and public reporting of such incidents. Markey and other critics argue that these companies have too much control over investigations and reporting due to their financial and legal interests. 

“Despite the unprecedented depth and scale of recent AI-enabled cyberattacks, the public is learning critical details piecemeal,” Markey said in a statement. “Building stronger defenses requires a full accounting of what goes wrong, and we cannot depend on companies with little incentive to disclose their failures to give us one. We need the Cybersecurity and AI Board of Investigations to get to the bottom of major incidents and give companies and the government the critical information necessary to build resilience and better secure our economy and our country.”

Although frontier AI companies maintain external red-teaming programs and allow limited access to organizations like METR and Redwood Research, they control the scope, terms and time frames of those engagements.

The board, which would coordinate with the secretary of commerce, could subpoena witnesses and conduct “independent and impartial reviews and assessments” of AI agent-led hacks that impact federal information systems or critical infrastructure. 

It would be led by five members, appointed by the president and confirmed by the Senate for five-year terms, with no more than three members from one political party.

The board would also investigate systemic vulnerabilities in the AI supply chain, so-called “near misses” where unauthorized agent-led hacks were “narrowly averted,” and gaps in federal regulatory oversight. It would have technical staff including engineers, malware analysts, and digital forensic experts.

The board would “operate independently from regulatory review and enforcement actions without assigning legal fault or liability for any review and assessment” it conducts, according to the bill.

OpenAI confirmed Wednesday its AI agents breached a statistics portal used by the Australian government’s social services agency, Services Australia. Though the breach happened in June, OpenAI learned of the incident in August. Australian Prime Minister Anthony Albanese said the company did not notify him until Sept. 10, when it sent findings to a general government email inbox, according to the BBC.

The post New bill would create federal investigative body for AI-driven hacks  appeared first on CyberScoop.

Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks

Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public.

First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and Technology panel, are introducing the Telecommunications Cybersecurity and Resilience Act.

“The Salt Typhoon intrusion was the worst telecom hack in our nation’s history and showed us just how vulnerable our critical infrastructure is, but it does not have to be that way,” Warner said. “If telecommunications companies adopt cybersecurity best practices, our networks can be more resilient. This bipartisan legislation is a good start in protecting our nation and strengthening the communications networks Americans rely on every day.”

Federal officials have repeatedly warned that Salt Typhoon — the Chinese group blamed for the massive and “indiscriminate” espionage campaign that hit major telecom carriers and siphoned data from presidential campaigns and candidates — remains a threat to this day.

Yet some cyber officials have worried that public apathy over the attacks has stifled momentum for telecom security rules. In one case the Trump administration has rolled them back.

The Warner-Cruz legislation takes the approach of trying to improve telecom security with voluntary measures jointly developed by government and industry.

“Foreign adversaries are increasingly targeting America’s communications networks. Securing them requires an approach that keeps pace with evolving threats,” Cruz said. “This sensible bill brings government and industry together to develop voluntary, telecom-specific cybersecurity best practices rather than adopting rigid federal mandates that quickly become outdated.”

Their bill would create a telecom cybersecurity working group within the National Telecommunications and Information Administration to bring together carriers, suppliers, experts and relevant government agencies. 

The working group would develop voluntary industry-wide best practices within 18 months of passage of the bill, which would be reviewed for updates every two years or after major incidents.

The best practices would “focus solely on identifying, responding to, mitigating, preventing, and remediating cybersecurity incidents and vulnerabilities,” according to the legislation, and would be in line with existing federal cybersecurity risk management frameworks.

The working group would also create a voluntary certification process through independent third-party assessors that companies could choose to use.

“What is missing” now, according to a summary of the bill, “is a common, telecom sector-specific set of best practices that brings that expertise together and can evolve as threats and technology change. Building on industry’s familiarity with security development and threat information sharing, this bill would bring stakeholders — government and private sector — together to develop and maintain effective techniques and practices to secure networks.”

The post Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks appeared first on CyberScoop.

CISA outlines improvement plan for CVE program

The Cybersecurity and Infrastructure Security Agency published a paper Wednesday that lays out its plan for improving the Common Vulnerabilities and Exposures (CVE) program, a contract for which nearly ended last year before a last-minute reprieve.

The white paper outlines the components of a “Quality Era” for the program, widely used as the definitive clearinghouse for data on vulnerabilities in software and other products, even as the number of CVEs surges. 

“CISA remains committed to leading, growing and sustaining the CVE Program into the foreseeable future, just as we’ve done for more than 25 years without fail,” said Chris Butera, acting executive assistant director for cybersecurity. “Informed by CVE community feedback, this whitepaper communicates CISA’s effort to support and enable stronger participation and governance, a program-wide maturation effort.”

The CVE program has been in a “Growth Era,” according to CISA. Over 67,000 new CVEs have been published in 2026 as of last week, and the National Institute of Standards and Technology National Vulnerability Database program has seen a 263% increase in CVE submissions between 2020 and 2025. Artificial intelligence has furthered the rise.

“These pressures intensify quality challenges across the CVE ecosystem,” the white paper states. “While faster discovery and reporting can improve the value of vulnerability information when records are complete, consistent, timely, and actionable, the same acceleration can expose gaps in processes, tooling, coordination, and accountability — especially when the quality of the submissions is uneven.” 

The plan calls for advancing data quality across four key dimensions: transparent and effective program governance, broad and active participation across the global software community, data infrastructure that supports CVE operational functions and reliable CVE record content.

Some vulnerability experts have questioned whether other organizations should take over CISA’s stewardship, given budget cuts at the agency.

Butera invited further feedback from the CVE community on the white paper, which stems from an earlier strategy document on the future of the program.

Some CVE experts that CyberScoop spoke to were supportive of what CISA wants to achieve, but skeptical about elements of the white paper.

“We’ve been working around long-standing quality issues in CVE reports for decades. Incomplete or inconsistent records create real downstream work for the security tools, developers, and organizations trying to determine whether they’re actually affected and what to do next,” said Sonatype’s co-founder and chief technology officer Brian Fox. “So it’s good to see CISA acknowledge that quality has to extend beyond the record itself to governance, infrastructure, and participation across the ecosystem.”

But, he added, “I’ll believe we’ve entered a ‘Quality Era’ when we can see the improvement in the actual data and in the decisions that data enables.”

Tom Alrich, who leads the OWASP PURL Expansion Working Group that’s focused on establishing a protocol for creating Product URLs for commercial software, said CISA’s white paper ignores a particularly important and growing issue.

“I support everything mentioned. I also support the flag, motherhood and apple pie,” he said. “However, nothing in there is going to affect the CVE program’s most important problem: that a huge and growing percentage of new CVE records don’t contain a machine-readable software identifier.”

Caitlin Condon, VulnCheck’s vice president of security research, said that “CISA and the CVE program are well-positioned to both observe challenges in this space and to create (and enforce) standards that explicitly state what ‘quality’ means in CVE records.”

But she said the white paper was more the basis for a future framework than a full-fledged framework in itself.

“Many of the potential success metrics suggested in the document can be measured today, but simply aren’t shared publicly,” Condon said. “In future iterations on the framework, I’d hope to see more transparency on CVE metrics as they stand today, along with reasoning on why those metrics are the right ones (versus simply the things that are easiest to measure qualitatively or quantitatively).”

The post CISA outlines improvement plan for CVE program appeared first on CyberScoop.

Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack

Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found.

The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs.

The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses. 

The IG took a look at the Secure Cloud Business Applications (SCuBA) project, created in response to the 2022 SolarWinds attack. It provides secure configuration baselines, settings and assessment tools to help agencies reduce the risk of breaches.

A December 2024 directive gave agencies a list of requirements to align with SCuBA, with a deadline of June 2025.

The IG found that 88 of 102 agencies, or 86%, didn’t implement all the mandatory SCuBA policies from BOD 25-01. As of February of this year, “compliance with BOD 25-01 had not improved. A total of 78 out of 102 (76%) [Federal Civilian Executive Branch] agencies were still not in compliance with implementing all mandatory SCuBA policies.”

“Some examples of baselines that FCEB agencies did not implement included blocking outdated authentication procedures, enforcing multifactor authentication, and implementing a policy to protect sensitive and personally identifiable information,” the IG report states. “Implementation of these baselines could mitigate vulnerabilities and threats from affecting the cloud business applications.”

That’s the result of CISA’s lack of power to enforce its BODs, which translates into greater risk, the IG concluded.

“Without defined enforcement oversight of SCuBA policy compliance, the Federal cloud security posture across the Federal enterprise is weakened,” the report states. “When agencies do not adopt required configurations or meet implementation deadlines, their cloud environments remain exposed to preventable threats.”

CISA didn’t respond to the report, according to the IG. 

The agency didn’t immediately respond to a request for comment from CyberScoop.

The post Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack appeared first on CyberScoop.

OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems 

OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks.

The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s Daybreak program. OpenAI said it is also pledging over $1 billion in subsidized tokens to support the initiative.

During a panel discussion Dmytro Kushneruk, consul general of Ukraine in San Francisco, outlined how the tools would be used for cybersecurity automation, including functions such as incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities.

In nearly all cases, Kushneruk said the primary benefit was carrying out those functions at machine speed. But this speed is meant to complement, not replace, Ukrainians’ human expertise.

In regard to incident response Kushneruk said humans must view “thousands and thousands of these logs and they have to find what’s really important, that’s why AI can give capable defenders really much greater advantage and leverage.” 

“This is why the object is not to replace the cyber defender with AI, but to make sure the cyber defender acts faster,” he added.

Kushneruk said that for Ukraine, the partnership “is really not about protecting computers, it is about actually keeping our country running.”

Ukraine faces approximately 6,000 cyberattacks per year, or about 15 per day, according to Kushneruk. Over the past twelve years, the country’s critical infrastructure, including electricity and water systems, has endured sustained attacks from Russia in the form of cyberattacks and physical strikes.

Since Russia’s 2022 invasion, Ukraine’s critical infrastructure has been under constant threat. While missiles remain the primary concern, Kushneruk said Ukraine has been preparing to protect vital services since Russian GRU hackers shut down the country’s power grid in 2015. 

He added that while the country was “maybe not so much prepared” to deal with the fallout in 2015, it improved over time, including the resilience displayed in 2025 when trains kept running after Russian hackers attacked Ukraine’s railway system.

Some national security experts and congressional committees have explicitly cited the resilience of Ukrainian critical infrastructure as a model for U.S. industry.

Naz Durakoğlu, minority staff director of the U.S. Senate Foreign Relations Committee, said there is “pretty much across the board” agreement between the parties in favor of similar adoption of defensive AI tools by U.S. critical infrastructure operators, though issues like regulation remain sticking points.

“This is something that’s already happening, and frankly, it’s just kind of a basic duty of government to make sure that when you turn the tap on, water comes out, the electricity doesn’t go out, and hospitals keep running and treating patients,” said Durakoğlu. “So there is a broad understanding that this is a major issue, and I will say seeing what Ukraine has to go through day-to-day is also a huge wake-up call to our members on a bipartisan basis.”

OpenAI has publicly pushed for its product, and AI at-large, to be used to solve these types of problems. Company president and co-founder Greg Brockman signed an open letter released earlier this year calling for “collective action” and widespread use of AI models to find and fix vulnerabilities before the rest of the world,  including foreign governments and cybercriminals, got access to the same capabilities.

According to Politico, OpenAI CEO Sam Altman met with U.S. power companies in July to discuss using AI to protect the nation’s electrical grids.

On Wednesday, OpenAI’s national security policy head, Sasha Baker, said the company felt “urgency” to try to strike similar agreements with other governments and industries.

“There’s this period of time where we’re really rushing to get [these tools] in the hands of critical infrastructure operators, of governments around the world, of people who want to patch systems, defend their networks, remediate vulnerabilities because we know as these tools proliferate out there in the ecosystems, there are going to be bad guys out there that also try to use them,” said Baker. “So, we have this window of time to take action and we’re really motivated by the idea that we need to act with some urgency.”

The post OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems  appeared first on CyberScoop.

The president has called for AI leadership. Here’s the mission.

America leads the world in artificial intelligence. As it should. But tech leaders keep warning, with alarming frequency, that we are at risk of losing control.

President Donald Trump has called for an AI czar and an “AI Force.” The details remain unclear, but the announcement underscores something fundamental. A technology this consequential demands clear leadership, accountability and action inside the U.S. government. The question now is what that leadership should do.

That question became more urgent last week when Google disclosed that its Gemini AI model gained unauthorized access to three real companies during testing. The incidents follow similar disclosures involving models from Anthropic, OpenAI and Meta. While there has been a lot of discussion on if AI is spinning beyond human control, what these episodes factually demonstrate that powerful AI systems can take consequential actions developers never anticipated or designed for.

The answer isn’t to retreat from AI leadership. It’s to lead—and simultaneously build the safeguards we need to stay in control. The promise of AI is enormous. It is already expanding access to information, improving productivity and creating opportunities across the economy. But so are the stakes, especially for the digital systems underlying everything we rely on as a society: energy, water, telecommunications, transportation, finance and more.

Take energy as an example: many U.S. utilities are using AI tools and predictive analytics to give plant personnel early warning of equipment problems. Yet AI agents with authority to change equipment settings or take systems offline could themselves fail, exceed their intended authority or be manipulated by adversaries. In extreme cases, the lack of control doesn’t just mean the power goes out, it means we’ve lost the ability to get the lights, heat and telecom systems back online.

At Auburn University’s McCrary Institute, we focus on cybersecurity threats to our nation’s critical infrastructure. Experience has taught us that warnings accomplish little unless someone has the authority, resources and responsibility to act. The time to act is now.

Whether that responsibility ultimately sits with an AI czar, an “AI Force,” existing agencies, or some combination of the three matters less than the mission. A new title or organization will accomplish little without clear objectives, authorities and accountability.

We propose an AI Assurance Compact – a framework for action among the makers of AI models, government, and the owners and operators of our nation’s most critical digital systems. The goal is to ensure that America leads the development of AI while ensuring that we can credibly manage its power and risk.

This compact is built around three principles: capability, that ensures the U.S. remains AI dominant; control, through constant testing and clear accountability; and continuity that ensures essential services can stay operational and recover when AI fails, is compromised, or must be disconnected.

When demonstrated risks outpace available safeguards, frontier development should be deliberately paced, including temporary limits or pauses where risks cannot be adequately controlled.

To their credit, leading American developers have responded to emerging risks with transparency, stronger safeguards and, in some cases, pauses or limits on development and access. But we cannot assume that voluntary restraint alone will protect the public interest or America’s strategic advantage. The country’s competitive landscape demands systemic discipline.

Nor can we assume the next warning will come from an American company. If a Chinese frontier developer reaches a dangerous capability first, American security cannot count on predictable warnings, transparency or restraint.

America’s strategic competitors are all-in on AI. Anthropic reported malicious actors using AI in cyber operations, surveillance and weapons-related work. Keeping a human in the loop is not sufficient when that human intends to attack us.

The Compact would prompt action by:

Requiring ongoing, embedded independent evaluation at frontier labs, covering training pipelines, internal use and deployment. Evaluators need employee-comparable access to relevant systems and evidence, protected reporting channels and freedom to publish safety findings, with narrow confidentiality safeguards. High-consequence systems should pass independent review before release, with renewed scrutiny after material changes. NIST can establish common criteria with sector agencies. Requirements should follow risk, regardless of a model’s origin or whether its weights are open or closed.

Establish enforceable checkpoints when capabilities materially exceed demonstrated safeguards. Developers should present a credible safety case before proceeding with high-consequence activities; uncertainty cannot automatically count as permission. Where risks cannot be adequately controlled, designated authorities must be able to require limits or temporary suspension until independently reviewed evidence supports proceeding.

Require rapid reporting of serious incidents to appropriate government authorities and affected organizations, along with preservation of evidence. Providers should share actionable warnings with one another and affected defenders so an actor removed from one service cannot simply continue elsewhere unnoticed.

AI in essential services needs rigorous guardrails before deployment. Operators need evidence specific to the task and operating environment, enforceable limits on authority, notice of material changes and tested fallback arrangements. Government, independent labs and operators should test failures across interconnected systems. Smaller operators need shared testing, technical assistance and recovery expertise—not another unfunded mandate. A backup plan should count only when it works under stress.

Finally, whatever structure the White House ultimately chooses should execute on the Compact’s principles by driving implementation, setting deadlines and ensuring that infrastructure operators and public-interest representatives have a seat at the table.

Internationally, the United States should explore crisis-communication mechanisms with other major AI powers, including strategic competitors, to reduce the risk that a serious AI-related incident escalates through miscalculation. If that ultimately means some version of a “red phone” for AI, so be it. Such mechanisms should reduce the risk of unintended escalation without creating new constraints on legitimate national security activities. America’s domestic safeguards and defensive investments cannot depend on agreement abroad.

No framework, or new government office, can guarantee control of whatever AI becomes. But clear leadership, accountability and tested safeguards can improve our ability to manage the risks.

America cannot win the AI race only to lose control of the systems on which our country depends. The President has called for action. The mission now should be clear. Preserve America’s AI advantage, maintain control and ensure that our essential systems continue to operate when technology fails, is compromised or must be disconnected.

Our nation’s most critical systems are already benefiting from the power of AI. They should. But pulling the plug on AI cannot mean pulling the plug on the community.

Frank Cilluffo is director of Auburn University’s McCrary Institute for Cyber & Critical Infrastructure Security and served as a special assistant to President George W. Bush following September 11. Nick Sellers is the institute’s associate director and chief operating officer and a former senior executive at Alabama Power and Southern Company.

The post The president has called for AI leadership. Here’s the mission. appeared first on CyberScoop.

After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program

A House Democrat tapped to lead his party’s efforts on artificial intelligence has introduced legislation that would establish a test program within the Cybersecurity and Infrastructure Security Agency to give critical infrastructure operators free access to frontier AI models to protect their systems.

Rep. Josh Gottheimer, D-N.J., introduced the AI Cyber Defense Act Monday, inspired by the series of cyberattacks on water facilities in recent months. “If we don’t get ahead of it, it can mean a disaster for our families,” he said at a news conference when he first announced the measure and others tackling water cybersecurity.

Gottheimer holds a couple of posts relevant to the legislation: He’s one of three co-chairs of the House Democratic Commission on Artificial Intelligence, and the top Democrat on the House Intelligence Committee’s cyber subcommittee. He also has bipartisan support for the bill, with co-sponsors Reps. Don Bacon, R-Neb., Zach Nunn, R-Iowa, Hillary Scholten, D-Mich., and Greg Landsman, D-Ohio.

The bill directs the Department of Homeland Security, through CISA, to create a program “through which owners and operators of critical infrastructure that participate in the Program are able to securely utilize artificial intelligence procured through the Secretary and technical assistance provided by the Secretary to protect against, detect, test for, and remediate vulnerabilities in the cybersecurity of such critical infrastructure.”

AI-tinged, water-focused cybersecurity pilot programs are all the rage lately. The introduction of Gottheimer’s legislation is adjacent to, but different from, a test program that the Office of the National Cyber Director recently announced in Texas.

One criticism of that program is that private sector companies offered their cyber and AI services through it on a purely voluntary basis, with no significant budget to bolster the pilot. Gottheimer’s bill would authorize $100 million for the pilot program from 2027 to 2031 before it ends, although appropriators would have to follow through on providing the actual dollars. The Trump administration has significantly cut CISA funding in its second term.

“Right now federal funding for critical infrastructure has an uncertain future and many of our local communities just don’t have the resources they need to pay for AI tokens to do the patching they need,” Gottheimer said when he introduced the bill. “It’s expensive to bring the AI in to analyze your system and find those vulnerabilities.”

Critical infrastructure owners and operators could apply for the pilot program, which the bill directs to give priority to nonprofit, publicly owned, rural and small-sized organizations.

“The same technology that can help a small town’s IT guy find and patch a gap in cybersecurity can also help a hostile government find a hundred more it hasn’t even discovered yet,” Gottheimer said when he announced the bill. “AI didn’t create this threat, but it’s accelerated it, and our defenses have to keep up.”

The post After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program appeared first on CyberScoop.

Citing China, President Trump doubles down on hands-off approach to AI regulation

President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry veterans and spurred calls for more regulatory oversight.

In a Truth Social post Monday, Trump dismissed worries from critics that “AI is going to kill us,” comparing them to complaints from environmentalists about climate change, which he also alleged was a false narrative. He also posited that nothing may matter more than future U.S. dominance of the technology over geopolitical rivals like China.

“Whoever wins AI, WINS!” Trump posted. “We are leading now over China, and everyone else, and I’m going to keep it that way! I’m not going to stifle Growth, of something that will be bigger than the Industrial Revolution, or the internet, itself.”

Trump has previously suggested that good leadership is the only regulation the U.S. needs for artificial intelligence. He later claimed the Department of Justice was ready to “rein things in” if companies overstepped, but offered no specifics on enforcement, legal authority, or where he would draw that line.

“We will be careful, and that’s why we have the Department of Justice, and other Law Enforcement bodies, that will rein things in if we have to, but I will only encourage AI or, SI (SUPER INTELLIGENCE)!” Trump concluded.

Secretary of the Treasury Scott Bessent recently told Congress that private lawsuits could force AI companies to institute better security, saying it’s clear what the government “shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for.”

“The best way to guarantee safety is that the creators are liable for what they build and generate,” Bessent said.

Beyond existential fears, critics also argue that inadequate regulation or cybersecurity controls in current AI systems make them impossible to fully control or monitor.

Recently, former President Barack Obama criticized the argument from Trump administration officials that the free market will naturally push industry toward self-regulation and that “these companies will solve the safety issues because they have every incentive to do so.”

“If it turns out to be dangerous, people will just sue them and they’ll be worried about financial liability,” Obama said last week in remarks at Colgate University in New York. “That’s not how we treat airlines or drug companies or food companies.”

The Trump administration issued an executive order earlier this year that set up a voluntary testing regime for some commercial frontier models, largely at private industry’s discretion. That order was significantly delayed and altered by AI industry boosters to ensure that governmental review did not cause companies to postpone their release timelines for new models.

That agreement did not last long before fast-moving events caused the administration to strike another, non-public agreement with frontier AI companies like OpenAI, Anthropic and others governing pre-release testing for models.

But the Trump administration has consistently argued that regulation will harm, not help, U.S. innovation and global competitiveness, and the threat of China frequently looms large in those discussions.

Experts believe China’s AI models are behind U.S. models at the top of the market, where OpenAI and Anthropic have consistently pushed the frontier limits of model capabilities. But Chinese lower and “middle class” models are often cheaper, more efficient and can even outperform more powerful models because users can dedicate exponentially more tokens for their tasks.

The U.S. government has accused Chinese AI companies of conducting widespread, “systematic” distillation of U.S. frontier models, with the implicit encouragement of Beijing.

In defending the administration’s approach, David Sacks, co-chair of the President’s Council of Advisors on Science & Technology and a top adviser on AI issues, specifically cited the threat from China and other countries that he claimed would not be subject to similar restrictions.

“We’re not the only country that has advanced AI labs, and as the president declared…we have to win this AI race,” Sacks told Politico in May, later adding “I think that’s the first thing to recognize is that if somehow we slow down or stop AI development, it doesn’t mean that AI progress is going to stop. It just means it’s going to happen in other countries and specifically China.”

Some observers have alleged that despite their larger differences, top leaders in the U.S. and China may view AI similarly at the strategic level, specfically that increased adoption – and risks – of AI are inevitable.

Ronan Murphy, director of the tech policy program at the Center for European Policy Analysis, posited that while there may not be a formal agreement between the two countries, “they share views both in Beijing and in Washington, particularly in the White House, of: you have to allow this to happen.”

“Clearly there’s a call for regulation from many quarters of AI in the U.S. and elsewhere, but in the White House – and we heard David Sacks talking about it [recently] – It’s ‘let them cook,’ and the Chinese approach seems to be the same,” said Murphy in a press briefing. “So there might be consensus at that level, if nothing else.”

The post Citing China, President Trump doubles down on hands-off approach to AI regulation appeared first on CyberScoop.

Dems seek top-to-bottom assessment of CISA workforce

A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after the exit of around 1,000 employees during President Donald Trump’s second term.

The concept of a force structure assessment is more common in military branches, including one that Congress previously ordered for Cyber Command. The CISA Force Structure Assessment Act would order the agency to carry out a review of whether the agency still has the necessary personnel, training and certifications after budget cuts and other Trump-era departures.

“America’s cyber defenses are only as strong as the people behind them,” Rep. James Walkinshaw, the Virginia Democrat serving as lead sponsor of the bill, said in a news release. “As cyber threats grow more sophisticated and technologies like artificial intelligence and quantum computing reshape the threat landscape, Congress needs a clear accounting of whether CISA has the workforce, skills, and resources required to keep Americans safe and enable mission delivery. This legislation will identify critical gaps and give Congress concrete information to address them.”

Also sponsoring the bill are the top Democrat on the House Homeland Security Committee, Bennie Thompson of Mississippi, and the top Democrat on its cybersecurity subcommittee, Delia Ramirez, D-Ill.

Additional elements of the force structure assessmewould include a review of the security of federal IT systems and support for state and local governments; the risks posed by AI, quantum computing and other cutting edge technologies; CISA’s threat-hunting and incident response capabilities; support for critical infrastructure and operating technology, including CISA’s role as a sector risk management agency for a number of industry sectors; the operation of the Joint Cyber Defense Collaborative; and international cooperation.

Some lawmakers and other observers have worried those areas have been greatly impacted by staffing cuts, ultimately hurting CISA’s ability to carry out its core functions.

Ramirez dinged GOP lawmakers for “a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy” in going along with the CISA cuts and other developments at the Department of Homeland Security.

Lawmakers on both sides of the aisle have voiced concern about the scope of cuts at CISA, but Republicans have approved some of them while pushing back on others. CISA itself is currently seeking to hire hundreds of new personnel, even as its latest budget blueprint calls for yet more funding reductions.

“With Iran targeting our critical infrastructure and frontier AI models creating new cyber risks, we must ensure we have a cybersecurity workforce to counter these growing threats,” Thompson said. “After Trump has spent the past two years targeting and slashing CISA’s workforce, we need the agency to assess if it has [the] right personnel in place to fulfill its mission.”

National Cyber Director Sean Cairncross has discussed White House plans to develop a cybersecurity academy meant to consolidate and enhance existing federal cyber training and education programs, with the aim of addressing cyber workforce shortages. His office has reportedly drafted an executive order that would establish that academy.

The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop.

The AI hacking apocalypse is not inevitable

The past few weeks have “felt very strange” for Juan Andres Guerrero-Saade.

Like many, he is trying to sort through the spate of frontier-model AI agents from OpenAI, Anthropic, Meta and others hacking their way onto the open internet over the past few months, particularly amid the already-heated national debate around the emerging technology and its impact on society.

Guerrero-Saade, a fellow for AI and security research at SentinelOne and an adjunct professor at Johns Hopkins University, said the hacks are worth taking seriously, but at a time when businesses and open-source maintainers should be focused on further hardening their systems and policymakers should be discussing new solutions,  “what we see is cybersecurity being used essentially as an excuse for these AI doomer arguments.”

The incidents have spawned those “doomer arguments” amid an intense public debate about the technology, the pace of industry development, and whether government and the private sector are doing enough to protect against “doomsday”-type scenarios, where AI systems take over or attack large parts of the internet or society.

Guerrero-Saade is among a growing chorus of cybersecurity professionals who say that while AI systems pose real, unique threats to our systems, the apocalypse is far from inevitable. Most of the public concerns around the incidents, let alone worries about killer AIs attacking critical infrastructure, assuming control of the internet and wiping out humanity, are either technically impossible or can largely be controlled through established cybersecurity principles.

There is this “narrative or magical thinking of ‘Well, AI is going to be able to hack everything, and therefore it can control everything, and therefore it’s going to kill us all,’” he told CyberScoop. “And you [think] these just don’t add up. They’re not very well-reasoned arguments.”

This fatalistic narrative tied to AI’s eventual dominance doesn’t hold up under scrutiny, according to experts CyberScoop spoke with. In recent conversations, cybersecurity and national security professionals raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review.

For example, Jacob Coxon, an Anthropic employee who resigned over AI safety concerns, told CBS News that frontier models could not be “unplugged” by humans once deployed because the model would copy itself to thousands of other computers connected to the internet.

By contrast, Matt Tait, a former information security specialist at UK signals intelligence agency Government Communications Headquarters (GCHQ), pointed out that the models run by Anthropic and other frontier companies require extremely expensive, “ultraspecialist” machines that “are functionally supercomputers.”

“There is a zero chance that Anthropic’s most capable models will be able to extract their own model and run in the wild, because those supercomputers essentially only exist in datacenters,” Tait said.

“Not a credible warning”

Other former cybersecurity government leaders say the agentic hacks represent a failure by regulators and industry to deploy known technical and policy options that make it harder for these types of incidents to occur.

Matt Hartman, former deputy executive assistant director for cybersecurity at the Cybersecurity and Infrastructure Security Agency, said “we should not accept harmful AI behavior as inevitable or unmanageable.”

“There are meaningful steps companies can take to monitor agent activity, constrain permissions, detect anomalous behavior, and build stronger safeguards into how these systems operate,” said Hartman, now a chief strategy officer at Merlin Group. “Those controls will inevitably involve trade-offs in capability and speed, but that’s a familiar cybersecurity challenge. Our goal should be to manage the risk without unnecessarily limiting the enormous benefits AI can provide.”

Ciaran Martin, former head of the UK’s National Cyber Security Centre, took issue with the way the CEOs of frontier AI companies have framed the threat of “rogue” AI behavior as inevitable, while issuing dire warnings about future threats and capabilities with little transparency.

Martin’s comments came after an essay published by Anthropic CEO Dario Amodei that cited the threat of a HuggingFace-style swarm of agents that could create a botnet capable of “taking over the entire internet” within 6-12 months.

This, Martin said, “is not a credible warning,” because it doesn’t explain how the exploitation would function, how such a botnet would persist on the internet, or how it would escape law enforcement. 

 “It assumes no monitoring of systems, no anti-virus, no DDoS protection, no network segmentation, no incident management, no nothing of any kind of the cybersecurity on the global Internet of the type that has developed over the last 30 years,” wrote Martin. “For a claim of this magnitude, there is neither evidence for the contention nor a credible account of a path to this outcome.”

Meanwhile, some federal government cybersecurity leaders have touted the technology’s disruptive potential and called for more widespread adoption of AI tools by defenders.

Joseph Alm, assistant secretary of cyber, infrastructure and risk resilience at the Department of Homeland Security, said classified systems may retain stronger protections. But for most other data, AI models are “just going to know things and be able to infer things about the world, and we’re going to have to adapt to that as almost inevitable.”

Asked by CyberScoop whether the government or frontier AI companies could be doing more to prevent or deter their models from carrying out unauthorized hacks via agents, Alm cited recent efforts by the Trump administration this year to establish pre-release testing of commercial models as a step in the right direction. But he called unauthorized AI agent hacks “a new threat class” that is different from previous threats and can be easily distributed to users through open-source software today.

“I think what we can do is…encourage the building of good sandboxes, so that the best models aren’t used for this and the stuff you see out in the wild is the kind of detritus that you can actually respond to effectively and control your networks,” said Alm.

Other experts have shared similar concerns. Earlier this month, CrowdStrike CEO George Kurtz recently warned of a new threat class emerging alongside nation-states, cybercriminals, and hacktivists: “the agent state.” By pairing AI systems with small human teams, these operators can now match the speed, scale, and sophistication of government-backed hackers.

“It took a nation to fund the talent, the tooling, the infrastructure, the patience,” said Kurtz. “That scarcity is over.” 

To be sure, frontier AI companies tout their commitment to both approaches. OpenAI and Anthropic have rolled out an array of cybersecurity partnerships, external red-teaming programs, vulnerability disclosure programs and cybersecurity technical advisory bodies filled with cybersecurity experts.

Mohammed Husain, strategic delivery lead for government at OpenAI, told CyberScoop that the company deploys both internal safety guardrails for their models and relies on outside cybersecurity vendors for additional expertise.

Internally, OpenAI focuses on vulnerabilities at the training level: filtering data poisoning attacks, blocking harmful datasets, and using network controls to prevent prompt injections. For other security layers like sandboxing, identity management, networking controls, they outsource to external vendors. 

“I don’t think OpenAI has all the answers here but what we do as a research lab is we’re going to focus on levels of protection we have expertise in and we partner to self-complement,” said Husain.

AI safety vs. AI cybersecurity

In response to the HuggingFace hack, OpenAI and Anthropic have allowed third-party organizations, such as nonprofit AI research firms METR and Redwood Research, to investigate. But multiple cybersecurity professionals told CyberScoop that both firms lack incident response experience and focus primarily on AI alignment and safety. Their reporting on the hack also lacked critical details: network monitoring logs, telemetry, and other data standard in cybersecurity threat intelligence reports.  

METR president Chris Painter addressed those general concerns in a post on X, saying since 2022 the organization has worked with Google, Anthropic, OpenAI, Meta, Amazon and others on investigations and third-party evaluations. Painter said none of the AI companies fund METR and that his employees are not uniformly “doomer” or “accelerationist” around AI.

Painter also said METR’s work ensures that if AI systems become autonomous or “rogue” within a company, there are ways to share that information with governments and people “outside the company’s walls.”

“We don’t accept money from frontier AI companies,” wrote Painter. “They haven’t paid us for our work, and we don’t accept donations from them or their employees. As we’ve shared previously, multiple frontier AI companies currently provide us with free access to their models in order to perform our evaluations, research, and engineering.”

AI safety and AI cybersecurity advocates take different approaches to securing “rogue” AI behavior. Safety advocates focus on aligning models around ethical training and behavior. Cybersecurity advocates argue that technical and regulatory controls must go further—actively preventing models from accessing what they need to carry out malicious behavior.

Guerrero-Saade said sandboxes in particular can easily be programmed with aggressive cybersecurity monitoring in order to spot when something odd may be happening and react in real time.

“I can’t think of an easier situation in which to set up trip wires, set up configurations like DNS servers, just different parts where you can say ‘Hey, anomalous behavior is happening,’” he said. “We should have been able to tell this immediately, not weeks and months later. So watching [the AI hacking incidents] go down is a little ‘crazy-making’ because we’re seeing things that, frankly, look like neglect, negligence, people just mishandling things, and then being told that these are categorically new incidents that mean that AI systems need to be treated completely different from anything that’s come before.”

While cybersecurity experts say AI systems are, at their core, still software, they do operate differently from more traditional code in ways that can make them harder to predict and control.

John Hultquist, chief analyst at Google’s Threat Intelligence Group, said most software has been deterministic. It may have bugs or vulnerabilities, but an expert could generally understand how it would react to certain stimuli, making it easier to design straightforward controls.

AI models are non-deterministic, with far more variability than traditional software. That can break security controls that rely too much on predicting behavior in advance. Using AI to enforce security controls on other AI models faces the same problem: the systems being deployed to control AI are just as unpredictable. 

But people are also non-deterministic, and people have developed systems in other industries and practices to account for that.

Hultquist drew on his Army experience, noting that “they give incredibly dangerous, expensive things to 18-year-olds” and expect responsible use. The military manages this through two types of controls: deterministic ones like strict weapons and ammunition protocols, and non-deterministic ones like human officers who monitor and correct violations.

Similarly, established cybersecurity controls have been used by incident responders to detect and prevent or mitigate ongoing cybersecurity breaches.

“I don’t think we should throw out all the other tools that we have learned to use as well. I think that would be utterly foolish,” he said, later adding “I will say that if we use only non-deterministic tools to figure out when things are happening, we shouldn’t be surprised when we get the wrong answer.”

The post The AI hacking apocalypse is not inevitable appeared first on CyberScoop.

What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies

A Cybersecurity and Infrastructure Security Agency program that provides tools and capabilities to other agencies has to get speedier so it can push them toward being able to move more quickly themselves, an agency official said Tuesday.

“We have to get faster,” said Richard Grabowski, acting branch chief of service delivery and deputy program manager for the Continuous Diagnostics and Mitigation program at CISA. “The way that we collaborated today wasn’t fast enough for the threats of yesterday, and they certainly aren’t going to be fast enough for the threats of tomorrow.”

That means pushing responsible automation of tasks that also can do so at scale, he said, so that experts “can focus more [on] dealing with the novel threats and adoption and tuning of advanced technology, and not hitting alerts every other day.”

Velocity is one of the three core goals for the CDM program, along with unification and data-driven risk management, Grabowski said at the Elastic Federal Cyber Defense Breakfast, produced by FedScoop.

Unification means keeping data out of silos so “we are connecting those deployments in a meaningful way to really stimulate reusable, actionable lessons learned,” Grabowski said. And data-driven risk management means that in the event of a crisis-level event, agencies are able to “see what is happening with timely, accurate, and trustworthy data, so that we are the tool of first response when the things hit the fan.”

One of CDM’s offerings is Security Information and Event Management (SIEM) as a Service, a cloud-based platform for threat analytics, incident response and more. Grabowski said there’s a three-year roadmap for expanding and enhancing it, including by ramping up staff and conducting training.

Mike Duffy, the acting federal chief information security officer, said at the same event that three principles should guide what comes next for CDM. One is aggregating demand across agencies that share common problems: “When agencies need the same capabilities, we should use federal scale to improve security, interoperability and value.”

Second, he said, “is buying outcomes, not product” by making it clear what outcomes the federal government is seeking and then allowing commercial markets room to innovate. 

Duffy said the third was to “design acquisition for continuous improvement,” meaning making sure that acquisition models promote competition and opportunities for new capabilities to enter.

“Now is not the time to set capabilities and move on for the next 10 years,” he said. “Mow that agile mindset of how we can continue to deliver and deploy capabilities based on the threats we’re seeing to reduce risk at scale across the federal government — that is absolutely key.”

CDM has been evolving since the SolarWinds breach that compromised at least nine federal agencies, said Matt House, CISA’s acting associate director and program manager for CDM.

“Post-SolarWinds, one of the things that that the government took away was, we lack what I would say is a common operating picture with respect to the operational visibility we need to be able to assess and coordinate response government wide,” House said at the event.

The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies appeared first on CyberScoop.

Supreme Court denies Trump request to allow USPS mail ballot changes

The Supreme Court has rejected a petition by the Trump administration to implement changes to the way the U.S. Postal Service handles mail-in ballots for the upcoming 2026 midterm elections, calling it “arbitrary and capricious.”

The 7-2 decision was handed down Monday with little explanation by the court. Writing for the majority, Justice Kentaji Brown Jackson said the administration “is unlikely to succeed on the merits of its challenge to the District Court’s preliminary injunction” and had failed to articulate a valid reason for seeking emergency relief from the court.

However, in a concurring statement, Justice Brett Kavanaugh said he believed there was “a fair prospect” that the final USPS final regulation would be within their legal authority and appeared to cite unreasonably short timelines imposed on states and his primary reason for denying the stay.

“But applying the rule in the 2026 elections would be arbitrary and capricious and in violation of the Administrative Procedures Act because state and local election officials do not have sufficient time to reasonably implement the rule before the elections,” wrote Kavanaugh.

The executive order would have tasked the USPS with verifying  voter citizenship and the validating ballot materials. The order would have created a barcode tracking system for mail ballot envelopes and “State Citizenship Lists” compiled by the Department of Homeland Security.

The order was quickly challenged by states and voting rights organizations, who argued the executive branch had no constitutional authority to dictate how they maintained their voter rolls.

The White House has justified the order by claiming the federal government has “an unavoidable duty” under Article II of the Constitution to maintain confidence in election outcomes by preventing violations of criminal law, including noncitizen voting.

Lower courts disagreed, blocking the executive order from being put in place before November. The petition to the Supreme Court represented the administration’s best and final hope for judicial relief.

As the administration fought the matter in courts, it moved ahead finalizing the USPS rule. A whistleblower complaint alleged that a “rushed” effort by the White House and U.S. Postal Service to install three new restrictive IT systems meant to verify citizenship that could potentially deny thousands of mail-in ballots if the federal government disagrees with states on a voter or ballot’s eligibility.

While Jackson and Kavanaugh’s rationale took up less than half a page, a dissenting opinion written by Justice Samuel Alito and signed by Justice Clarence Thomas was more than 7 pages long.

Alito wrote that he would have granted the Trump administration their request for a stay, allowing the order to be implemented in time for the 2026 elections. He said states and organizations suing the government lacked standing, and dismissed their concerns that implementing the USPS order ahead of the 2026 elections would thwart their ability to educate voters about mail-in voting, calling them “abstract social interests.”

Ahead of the decision, David Becker, executive director of the nonprofit Center for Election Integrity and Research, told reporters that he doubted members of the Supreme Court majority “want to own the chaos that would ensure” as the USPS, states and voters attempt to navigate changes put in place just months before elections and after many states have begun sending out ballots that do not comply with the proposed rules.

He also said that it would be in line with previous Supreme Court decisions that have recognized state supremacy when it comes to specific election administration authorities, like where and how their citizens vote.

“When they consider issues related to the administration of elections, the casting and counting of ballots, they have sided with the states every time,” said Becker.

The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop.

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

Beginning next month, if a flight is canceled or delayed because of a cyberattack, feds will give airlines clearance not to hand out meal vouchers or hotels.

The change is the result of a broader rule the Transportation Department published last week that establishes a new “cause of delay” category for tracking information, but that also reduces air carrier responsibilities to customers for 10 kinds of events. Among them: “cybersecurity attacks (provided that the air carrier is in compliance with applicable cybersecurity regulations).”

The 10 events, including those cyberattacks, are deemed “not controllable,” meaning that “carriers are no longer obligated under [customer service] plans to provide amenities or compensation when disruptions arise from these specific causes,” as Sophie Hayashi, counsel at Crowell & Moring in the transportation group, wrote in a client alert.

Those airline-authored customer service plans aren’t legally binding, although DOT has maintained it will hold airlines “accountable” for their pledges.

One airline consumer advocacy organization, FlyersRights, was skeptical of the change, saying it came without giving the public a chance to comment and that it would be monitoring the impact on airline customers and tracking any reduction in amenities. 

Specifically, “cybersecurity is an airline responsibility, so if a flight is delayed or cancelled it should be clear that the delay was not due to carrier neglect, as cyberattacks are constant,” Paul Hudson, president of the group, told CyberScoop. “We have previously urged stress tests for airline computer systems that are going down often.”

Another group, the National Consumers League, had a more mixed view about the rule’s effects on flyers. On one hand, it could be good for them, said John Breyault, vice president of public policy for the group.

‘What we appreciated about this being put into a rule was that it gave consumers certainty that regardless of which airline they were flying, they would know that they have certain rights, and they weren’t beholden to the whims of the airlines who may or may not decide to provide them with a hotel if there’s a delay or cancelation,” he said.

On the other, though, “it’s clear to us that the DOT seems inclined to try and make the rules a little less onerous for the for the airline industry,” Breyault said, and in particular was worried about how airlines could potentially abuse the ambiguity related to one of the 10 events, “unscheduled maintenance,” to find a way to avoid compensating consumers.

The provision might still protect consumers because of its condition on compliance with applicable cybersecurity regulations, Breyault said. Carriers who can’t demonstrate compliance will be subject to customer and other requirements, Hayashi said.

“The final rule’s language regarding applicable cybersecurity regulations is notably broad,” said Kate Growley, partner at Crowell & Moring. “This may have been deliberate to account for the unpredictable nature of cybersecurity attacks. Different regulations may apply depending on the exact circumstances of the attack, such as what information or operational capabilities were affected.”

There’s no formal accounting of how often cyberattacks have caused delays or cancellations that then prompted airlines to provide meal vouchers or hotels. Hackers have targeted airlines and flights before, such as Scattered Spider’s attacks last summer.

Cyberattacks have caused flying delays and cancellations, although sometimes those attacks have been aimed at third parties, such as in last year’s attack on Collins Aerospace led to delays in Europe. Attackers also have targeted other elements of the aviation sector. The 2024 IT outage related to the cybersecurity company CrowdStrike that grounded flights wasn’t a cyberattack, but did lead to airlines providing some compensation to travelers; the Transportation Department determined that incident was within airlines’ control.

The Biden administration notably imposed cybersecurity regulations on airports, aircraft owners and aircraft operators in 2023 due to “persistent cybersecurity threats” in the sector. 

The newly-published Department of Transportation (DOT) rule stems from a Federal Aviation Administration authorization law that President Joe Biden signed in 2024. 

“Congress explicitly directed DOT in the FAA Reauthorization Act of 2024 to make these changes,” a Department of Transportation spokesperson said. “These 10 specific types of flight disruptions will now … be tracked in a brand-new reporting category to ensure government delay data accurately reflects what airlines can and cannot control.”

The Aviation Information Sharing Analysis Center said it appreciated the elements of the rule related to reporting incidents.

“The Aviation ISAC supports efforts to simplify and harmonize cybersecurity reporting across numerous government agencies,” said Jeff Troy, president and CEO of the organization. “This rule is a move in the right direction.”

Hayashi told CyberScoop the rule change looks to be positive for both airlines — because of the clarity it provides them about disruptions not under their control — and consumers.

“This actually is beneficial for everyone, and particularly consumers, because it makes it clear if you’re looking at airlines delay and cancellation rates, this is going to give you the most accurate picture of carrier delays,” she said.

The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first on CyberScoop.

Hawley probes OpenAI over Hugging Face breach

OpenAI is facing mounting pressure from Capitol Hill due to the attack its agents carried out on Hugging Face, while lawmakers voice widening concerns about AI’s potentially existential risks.

Sen. Josh Hawley, R-Mo., criticized OpenAI leadership for what he described as “reckless” activities leading up to the Hugging Face breach, and accused the company of withholding important details from a technical report it released in late August.

The Chair of the Subcommittee on Disaster Management kicked off an investigation into the incident “in light of new, disturbing evidence,” he wrote in a letter Tuesday to OpenAI CEO Sam Altman.

“My investigation will probe this AI hacking incident, along with growing allegations of the existential risk of new AI products,” Hawley added. 

“The Hugging Face incident was an important moment for AI safety and a warning about the risks that can come with increasingly capable AI across the industry,” a spokesperson for OpenAI told CyberScoop. “We conducted an extensive investigation and published a detailed report on what happened, what we learned, and how we’re strengthening our security and alignment practices.”

The lawmaker is seeking detailed internal communications, exhaustive technical information and reasoning behind OpenAI leaders’ decisionmaking and activities surrounding the hack by Oct. 1.

“The American people deserve to know the details of what went on in the Hugging Face incident and other incidents of AI models going rogue,” Hawley wrote. 

He accused the company for not providing more details and resources to the third-party auditors who published an independent report on the breach, adding “they had limited visibility into the circumstances leading to the attack and its aftermath.”

Hawley sent his letter to Altman amid a seeming internal chasm within the ranks of AI’s top proprietors over the ways they are allowing the technology to advance mostly unrestrained. He referenced some of these latest warnings in his letter.

Jacob Coxon publicly quit his job as a researcher at Anthropic earlier this week, claiming the company and his previous employer OpenAI are acting irresponsibly and “gambling with our lives.” His social media missive went viral for insisting “the people building AI earnestly believe that it could kill us all by the end of the decade.”

Evan Hubinger, alignment science lead at Anthropic, responded to Coxon’s post in the affirmative, adding that guardrails for superintelligence are lacking and he believes there’s a greater than 10% chance AI could kill all humans within the next decade.

Using those posts as fuel for his inquiry, Hawley questioned what might happen if AI agents hack into critical infrastructure, banks or utilities. Ultimately, he asked Altman: “Who is held liable when AI goes rogue?”

You can read Hawley’s full letter and requested details below.

The post Hawley probes OpenAI over Hugging Face breach appeared first on CyberScoop.

Governments ‘buying time’ in race between innovation, security, national cyber director says

The United States and allied governments are “buying time for our systems to become more secure” as artificial intelligence advances and spreads, National Cyber Director Sean Cairncross said Thursday.

“That is a big deal to be ahead of this, to be ahead of this race, and because it’s an exponential  equation,” he said at the Billington CyberSecurity Summit. “Once you fall behind, it is much more difficult to make it up, and so that is the context in which all this is taking place. We are trying to balance the innovation side of running at speed with securing our systems and handling this technology responsibly, which is to say, not letting it fall into the hands of people who would do us harm, our adversaries.”

Earlier this week, U.S. security agencies accused Chinese AI companies of trying to illegally distill U.S. frontier AI models. Also this week, Anthropic disclosed a fourth AI hacking incident where one of its models broke into third-party systems.

“We all face the same threat picture, and it’s vital that we’re working closely together to secure those systems before that technological cycle catches up on the back end,” Cairncross said.

AI has further exposed long-standing cybersecurity problems that have gone unaddressed, he said.

“In AI development, particularly on the vulnerability discovery side and the coding side, it hasn’t created a new set of problems,” Cairncross said. “What it’s done is it’s dragged to the surface problems that have been latent in this space for decades. There’s been under-resourcing and deprioritization of basic cyber hygiene and cybersecurity.”

Cairncross’s messages echoed those of other Trump administration cyber officials speaking this week at the summit.

A top FBI official, Jason Bilnoski, said the solutions to the difficulties AI poses aren’t new; basic cyber hygiene is key.

And the director of the Cybersecurity and Infrastructure Security Agency, Nick Andersen, said historical neglect of cybersecurity fundamentals poses a serious threat that requires a speedy answer.

“We know the worst that can happen, and if we don’t make some very serious, very significant changes in quick succession … you all are going to have to go home and look your family, look your friends in the eye and explain to them how you knew the worst that could happen and why we didn’t do enough,” he said.

The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on CyberScoop.

FTC rescinds policy statement requiring health apps to notify customers after a breach 

The Federal Trade Commission has rescinded a Biden administration-era policy statement that asserted coverage over health and fitness apps under federal data breach notification regulations.

In a half-page statement posted Wednesday, the FTC said it “has determined that the statement – contentious at the time of issuance – provided minimal benefit and has been superseded by rulemaking.” The commission said the statement’s withdrawal also aligns with guidance from the White House to pursue a deregulatory agenda and avoid “unnecessary use of subregulatory guidance.”

Unlike a formal regulation, which carries the legally binding force of law created through a public rulemaking process, an agency policy statement is non-binding guidance that merely outlines how officials intend to interpret and enforce existing statutes. An FTC spokesperson told CyberScoop that the underlying policy including health apps remains codified through a regulatory update in 2024.

“Each of these reasons is independently sufficient to support the Commission’s decision to rescind this policy statement,” the FTC continued. “Parties understand that guidance generally creates neither substantive rights nor binding obligations.”

The initial policy statement, passed in a divided 3-2 vote during the Biden administration under then-FTC chair Lina Khan, asserted that health apps, fitness trackers and other connected devices were covered under an existing regulation requiring companies to disclose health-related data breaches to customers.

The interpretation targeted any “vendor of personal health records that contain individually identifiable health information created or received by health care providers.” Many health and fitness apps ask users to upload medical records and other health-related data in order to function effectively.

More recently, health and cybersecurity experts have pointed to similar regulatory gaps that exist for AI companies that make healthcare specific models that can answer questions, examine patient records and dispense medical advice to users.

The underlying Health Breach Notification Rule also triggers automatic notification when a covered entity suffers a breach of security, which can include both standard breaches and data losses as well as the disclosure of sensitive health information to third parties without users’ authorization. That would potentially put health apps on the hook for selling customer data to third-party data brokers and other entities-a standard formally codified in a binding 2024 FTC rule update.

A Sept. 2021 statement by the FTC justifies its interpretation by citing digital security and privacy provisions in the 2009 American Recovery and Reinvestment Act as well as gaps in major health privacy laws like the Health Insurance Portability and Accountability Act that allow such apps to handle and store sensitive personal health records or data without being subject to the same breach notification requirements as other health care organizations.

The FTC said it intended to enforce health apps under the law and subject violators to daily fines of $43,792 per violation.

“As many Americans turn to apps and other technologies to track diseases, diagnoses, treatment, medications, fitness, fertility, sleep, mental health, diet, and other vital areas, this Rule is more important than ever,” the FTC said in 2021. “Firms offering these services should take appropriate care to secure and protect consumer data.”

This week, the FTC voted unanimously to rescind the policy statement. But that unity is in part because President Trump fired Democratic FTC commissioners who voted in favor of the original rules, while advancing party allies as their replacements.

The two dissenting votes against the policy statement in 2021 were from Republican-appointed commissioners casting their dissents under a Democratic executive. Andrew Ferguson, a Republican commissioner nominated by former Democratic President Joe Biden, is now chair of an FTC filled entirely with Republican appointees, and has defended President Trump’s authority to fire and hire new commissioners at-will.

Update, 9/11/26, 4:15 p.m.: This story has been updated to clarify the impact of the FTC’s policy statement revision.

The post FTC rescinds policy statement requiring health apps to notify customers after a breach  appeared first on CyberScoop.

Lawmakers call on Commerce to sanction hackers-for-hire

A bipartisan trio of lawmakers is asking the Commerce Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies.

Democratic Sens. Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island and Rep. Pat Harrigan, R-N.C., sought in a letter to Secretary Howard Lutnick Wednesday to have the mercenary firms added to the Treasury Department’s Entity List, which would limit their access to American software, cybersecurity tools and cloud infrastructure.

“Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote. “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”

The three firms are Sunkissed Organic Farms, BellTroX and CyberRoot. The first of those three was formerly known as Appin and has been the subject of investigative reports and criminal probes. The Citizen Lab at the University of Toronto has delved into the work of BellTroX, and journalists also have reported on the activity of CyberRoot.

“The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence,” the lawmakers wrote. “While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.”

Reuters reported in 2023 that the family member was Kristi Rogers, wife of former House Intelligence Chairman Mike Rogers, now running for Senate as the GOP candidate against one of the midterms’ most important and contested races against Democrat Abdul El-Sayed.

Some of the hacking groups also have sought to censor reporting on their hacking activities, the lawmakers noted.

CyberScoop couldn’t reach the companies for comment. The Commerce Department also didn’t immediately respond to a request for comment, and the government of Qatar didn’t immediately respond to an email seeking comment on the letter. TechCrunch first reported on the letter.

Corrected 9/10/2026: to reflect department to which the lawmakers addressed the letter.

The post Lawmakers call on Commerce to sanction hackers-for-hire appeared first on CyberScoop.

FBI cyber chief worries private sector not sharing enough cyber threat information

The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.

Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”

“From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.

“It worries me when an organization is breached by a nation-state actor and believes that bringing law enforcement in might be more risky than handling it on their own,” he said. “That should worry all of us when that happens, because who is positioned to eradicate the PRC from their environments as quickly as when they might have law enforcement or the intelligence teams at FBI come in and actually help with that effort?”

In response, the bureau has held events like outside counsel summits to walk attorneys through what the FBI offers victims during a major breach, Leatherman said. The FBI also has adjusted its standards for when to share information about threats when weighing how much it might help victims versus whether it might jeopardize a law enforcement operation in the future.

“Our posture is, ‘Share until it hurts,’” he said. “What I always ask my team is, if the victim were sitting in this room right now … would they want this information, and what is the compelling justification we have to not share this now to stop the impact versus taking an operation 90 days from now?”

“We have to in every situation where we have intelligence, we have to take that victim perspective because they can’t voice it in that moment,” he said. “Where we can share in a way that will protect our equities in conducting those operations, we’ll do it. But [where] we can have an impact to hundreds of pieces of critical infrastructure, we should share that, and we should share it quickly.”

The FBI published a new cyber strategy Wednesday that places an emphasis on aiding victims of cyberattacks. Helping victims also helps investigations, Leatherman said.

“We used to look at remediation and incident response as mutually exclusive to investigation and threat pursuit,” he said. “And what we’ve shown over the last few years is that they are not mutually exclusive. … If we can work with victims in a way that preserves investigative information, that allows us to move upstream against the actors.”

The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared first on CyberScoop.

❌