Normal view
Tracking the attacker
The patch apocalypse is here
Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
Democratic senators pressed President Donald Trumpβs pick for director of national intelligence on questions of election security and integrity Wednesday, but they didnβt leave his nomination hearing satisfied with the answers.
As is typical for Trump administration nominees, Jay Clayton wouldnβt answer definitively at his Senate Intelligence Committee confirmation hearing whether Joe Biden won the 2020 presidential election, saying only that he was βcertified,β while maintaining that he wasnβt an βelection denier.β
He said that the Office of the Director of National Intelligenceβs responsibilities were βprincipallyβ outside the United States. But he claimed varying degrees of ignorance about his predecessor, Tulsi Gabbard, being physically present at an FBI raid of a Georgia election office in January, and wouldnβt comment on its appropriateness.
Democratic senators were also frustrated while trying to pin down Clayton, the U.S. attorney for the Southern District of New York who served as head of the Securities and Exchange Commission in Trumpβs first term, on remarks about mail-in ballots and the California primary election results last month.
Multiple senators, including Mark Warner, D-Va., Angus King, I-Maine and Mark Kelly, D-Ariz., tried to get Clayton to say whether Biden won the 2020 election. The final exchange came with Jon Ossoff, D-Ga.
Clayton protested that he had already answered. βI think Iβve answered the question,β he said. βWe can keep doing this.β
Ossoff didnβt agree, telling him, βWell weβre going to keep doing it because youβre not being honest or forthright with the committee.β
βIsnβt it humiliating to be unable to answer this question?β he asked. βTo have to indulge the presidentβs delusions? We know, you know, everybody in this room knows the truthful answer to that question. Why can you not give it?β
Earlier Clayton had said, βIβm not an election denier,β but repeatedly wouldnβt answer βyesβ or βnoβ on whether Biden won in 2020.
That matters because of the DNIβs role, Kelly said, and it was worrying that Clayton was seeking to avoid upsetting Trump, who has maintained despite all evidence that he lost the 2020 election.
βItβs not about softening the edges when the truth is unpleasant,β Kelly said. βItβs about delivering information.β
Clayton discussed the DNIβs role on election security at greater length in pre-hearing written answers.
βI understand that the DNI, as head of the Intelligence Community, has substantial statutory authority to address national intelligence threats to U.S. elections,β he said. βIn particular, the Director is responsible for the integration of national intelligence, which may include foreign intelligence threats to U.S. election activity. I also understand that Intelligence Community elements are authorized to cooperate with and provide appropriate intelligence and technical support to law enforcement agencies and that as head of the Intelligence Community, the DNI has oversight of those activities.β
A CNBC interview last month inspired some of the Democratsβ questions. Clayton said in response to questions about the California primaries that βOn the integrity side, weβre doing an absolutely terrible job. And the American people are right to question it.βΒ
He said mail-in ballots present an βopportunity for fraud,β despite studies showing exceptionally low rates of fraud using that method, and said βmail-in ballots being used by one group and not anotherβ¦ honestly and dishonestlyβ was a βquestion that everyone is now asking.β
Sen. Ron Wyden, D-Ore., asked him about what group Clayton was referring to.
ββI would like to see where youβre pulling those quotes from. Iβve been very careful about my remarks on this,β Clayton answered. βIβd like to see the whole passage.β
In his questionnaire, when asked if βit would be inappropriate for a DNI to comment publicly about unsubstantiated claims regarding mail-in-ballots and election fraud,β Clayton answered that βIf confirmed as DNI, any representations I make to the public, including about elections, will be informed by timely, objective national intelligence.β
Ossoff also had a tense exchange with Clayton when asking him about Gabbardβs appearance at the Fulton County office raid. Gabbard has said she was there because Trump asked her to be, in what subsequently became a highly publicized appearance because of questions about what the DNI would be doing at a law enforcement raid.
βI was made aware of it by you yesterday,β Clayton said.
Ossoff responded skeptically: βThe first time you learned that Director Gabbard was present at that raid was in my office yesterday?β
Said Clayton: βIt was the first time that in my recollection Iβve thought about it recently.β
βWhat?β Ossoff replied.
Warner, the top Democrat on the committee, told Clayton βI trust youβ but it βstrains credulityβ that he wasnβt aware of Gabbard being at the raid.
βTo be clear, the ODNIβs role is principally outside of the United States,β Clayton said.
On other topics, in his opening remarks, Clayton touted his SEC work on cybersecurity. In his questionnaire he said he would work to facilitate cyberthreat information sharing from his office.
He told Sen. Kirsten Gillibrand, D-N.Y., that he would evaluate whether the DNI should devote more resources to cybersecurity with federal government cyber experts being pushed out since Trump came back to office. Many Republicans are pushing to further reduce the size of Claytonβs office, contending it has become bloated beyond Congressβ original intentions as a coordinating body.
He said he supported renewal of Section 702 of the Foreign Intelligence Surveillance Act, which gives the executive branch controversial spying powers that Congress recently allowed to expire.
Trump has threatened to block renewal unless lawmakers advance his priority election bill. He said he will study how to βminimize the detrimental impact to our national security caused by the lapse in 702 authorities.β Some Democrats, meanwhile, have resisted action on the law until Trumpβs pick for acting DNI Bill Pulte is gone, citing his prior efforts to investigate officials as head of the Federal Housing Finance Agency and lack of intelligence experience.
Because the GOP controls the Senate, Clayton is likely to get confirmed as DNI as long as no Republicans emerge in opposition. Wednesdayβs hearing revealed no significant Republican objections.
Intelligence Chairman Tom Cotton, R-Ark., touted Claytonβs experience prosecuting terrorism cases and more.
βJay Clayton has worked hand in glove with our intelligence agencies and counterterrorism personnel to lock up criminals who threaten our national security,β Clayton said. βI encourage my colleagues to join me and get Mr. Claytonβs nomination over the finish line.β
The post Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed appeared first on CyberScoop.
Windows K2: Microsoftβs reported plan to fix Windows 11
MS-DEFCON 2: More patches from Apple and Adobe
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
The X/Twitter account IRIS C2 (@C2IRIS) has gained more than 4,000 followers since its creation in January 2025, posting frequently about security vulnerabilities, AI and software exploits. IRIS C2 says it is a company in McLean, Va. that sells offensive cybersecurity capabilities.
The IRIS C2 website dangles the possibility of million-dollar payouts for exploits to attract talent.
βOur business model is this,β reads a pinned post on top of the IRIS C2 account on X. βAttract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We donβt care if they have a college degree/industry experience.β
The website linked in that profile β irisc2[.]com β says the company is hiring for a number of open positions, and a recent post on its LinkedIn page enthuses about an overwhelming number of applications from potential employees. The website claims IRIS C2 is in the business of acquiring βzero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms. Payouts range from $10,000 to $7 million depending on target, reliability, and operational value.β
The government contracting portal g2exchange.com reports that irisc2[.]com is operated by a business based in Virginia called Calvexa Group LLC. The βcontactβ link on the website for Calvexa Group β calvexagroup[.]com β forwards visitors to irisc2[.]com. G2Exchange shows that while Calvexa Group LLC is registered as a federal contractor, it does not appear to be working on any direct government contracts.
A search on the Arlington, Va. address listed in the incorporation records for Calvexa Group LLC finds the property is occupied by Jack Burkman, the 60-year-old founder and managing partner of the lobbying firm Burkman & Associates. When approached with questions about IRIS C2, Burkman referred further inquiries to his longtime associate, 28-year-old Jacob Wohl.
Jack Burkman (left) and Jacob Wohl, at a press conference in August 2020. Image: Wikipedia.
Burkman and Wohl have a storied history of creating fake intelligence companies and using them to spread false claims about and frame public figures, including fabricated sexual assault claims against then FBI director Robert Mueller, and Pete Buttigieg, then mayor of South Bend, Indiana and a Democratic candidate for the presidency. In 2019, Burkman and Wohl held press conferences falsely alleging extramarital affairs by Sen. Elizabeth Warren (D-Mass.) and then-2020 presidential candidate Kamala Harris.
In the wake of the 2020 presidential election, Wohl and Burkman were prosecuted by multiple U.S. states for making thousands of robocalls to residents of battleground states and disseminating false claims about mail-in ballots. They were indicted in Cleveland on 15 felony counts of orchestrating a robocall scheme aimed at suppressing the black vote in Detroit, and were sentenced in late 2025 to probation after their appeals to dismiss the charges were rejected.
In 2022, Wohl and Burkman both pleaded guilty to a single felony charge of telecommunications fraud in Ohio, and sentenced to a fine, probation, and community service. In March 2023, a judge in a New York civil case ruled that Wohl and Burkman had violated federal and state civil rights laws, and the two agreed to pay a $1 million settlement.
In June 2023, the Federal Communications Commission (FCC) imposed a $5.1 million fine against Wohl and Burkman for their robocall campaigns, at the time the largest fine ever sought by the FCC under the Telephone Consumer Protection Act.
Jacob βJayβ Wohlβs GitHub account.
By the age of 17, Wohl had started multiple investment firms, and cultivated the nickname βWohl of Wall Streetβ after appearing on Fox News in 2015 to discuss his new hedge funds. In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud, and ordered him to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts of selling unregistered securities and was sentenced to two years of probation.
The market for previously unknown security vulnerabilities has always been populated by a colorful mix of researchers, academics, charlatans, clout-chasers and people actively involved in cybercrime communities. But the market for selling offensive security services to the U.S. government tends to be far more circumspect. Plenty of government contractors recruit vulnerability researchers and pay for the exclusive rights to novel software exploits, yet none of them do so quite as brazenly and openly as IRIS C2.
Recent posts from the Twitter/X account IRISC2 (@c2iris).
Indeed, KrebsOnSecurity was unaware of IRIS C2 until last month, when an attendee at a regional cybersecurity conference shared that Wohl and Calvexa Group were pestering people at the conference about selling their vulnerability research.
In an interview with KrebsOnSecurity, Wohl said Mr. Burkman was not involved in the day-to-day operations of IRIS C2. Wohl shared that IRIS C2 originally began as a penetration testing company, but shifted its focus recently to selling phone-hacking services to the government. Several times throughout the interview, Mr. Wohl mentioned working on federal government contracts, but when pressed for specifics said he was not at liberty to speak publicly about them.
Mr. Wohl said he does not have any formal education or training in computer science or information security, and that most of his knowledge on the matter is self-taught.
βI know more about tech than anyone,β Wohl bragged. βMy background has always been extremely technical, and Iβve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin.β
Wohl said security researchers bring the company unique vulnerability findings βon a regular basis,β but that in many cases those findings are preliminary and not fully fleshed-out.
βLetβs say someone finds a flaw in a media decoder on a phone,β Wohl said. βA lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and thatβs what we do.β
Wohl claims IRIS C2 has approximately 40 employees, although he said none of them are allowed to list their employment on LinkedIn for operational security reasons. In May, the author of the IRIS C2 account on X said that his girlfriend had no idea what he did for a living. But if IRIS C2 has any other employees, they may be similarly unaware of Mr. Wohlβs history of outright fabrications β or even his real name.
In September 2024, Politico reported that Burkman and Wohl were bragging about big companies supposedly buying services from their now-defunct company LobbyMatic, which claimed to use artificial intelligence to assist in political lobbying efforts. However, Politico found the pair were running the company using pseudonyms, with Wohl reportedly adopting the name βJay Kleinβ and Burkman using the moniker βBill Sanders.β Politico reported that two of the former LobbyMatic employees resigned after learning of their true identities, while other employees only learned after they had left the company.
Update, July 9, 9:44 a.m. ET: Several readers pointed our attention to a March 31 publication from journalist Molly White, which reported that Burkman and Wohl were paid a $300,000 retainer by a Canadian cryptocurrency fraudster wanted by the United States and several other countries for allegedly stealing $65 million from the crypto platforms KyberSwap and Indexed Finance. According to that report, the two were hired to pursue a βpresidential pardon to avert a miscarriage of justiceβ on behalf of the accused hacker, who has not yet been convicted.
Critical Adobe ColdFusion Vulnerability Exploited in Attacks
Hackers are exploiting a recently patched critical vulnerability (CVE-2026-48282) in Adobe ColdFusion that carries a CVSS score of 10/10.
The post Critical Adobe ColdFusion Vulnerability Exploited in Attacks appeared first on SecurityWeek.
-
SecurityWeek RSS Feed
- Proof-of-Concept Exploit Released for Linux βBad Epollβ Root Access Vulnerability
Proof-of-Concept Exploit Released for Linux βBad Epollβ Root Access Vulnerability
Organizations are urged to patch after proof-of-concept code makes the Linux root escalation flaw easier to exploit.
The post Proof-of-Concept Exploit Released for Linux βBad Epollβ Root Access Vulnerability appeared first on SecurityWeek.
June 29, 2026 Apple Updates
-
SecurityWeek RSS Feed
- US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve
UNC5792 and UNC4221 have been targeting US government officials, military leaders, and allied personnel.
The post US Offers $10 Million Bounty for Russian State Hackers as Messaging App Attacks Evolve appeared first on SecurityWeek.
What to do with older tech
-
Black Hills Information Security
- Insufficient Egress Filtering: How Weak Outbound Controls Enable Attacks
Insufficient Egress Filtering: How Weak Outbound Controls Enable Attacks
![]()
Insufficient egress filtering is a commonly identified vulnerability found during BHIS penetration tests. The insufficient egress filtering finding indicates that network traffic leaving the organizationβs environment is not properly restricted.
The post Insufficient Egress Filtering: How Weak Outbound Controls Enable Attacks appeared first on Black Hills Information Security, Inc..
Controversial FISA spying law expired this week. The spying will continue.
MS-DEFCON 2: Fixes for Windows 11
European authorities crack down on illegal streaming networks
Authorities in Europe arrested 29 alleged cybercriminals and took down more than 27,000 illegal streaming URLs that pirated major sporting events, films and TV programming, Europol said Wednesday.
The continent-wide collaboration, led by Bulgaria and the European Unionβs police agency, allowed authorities to dismantle nine organized crime groups supporting the illicit streaming networks, officials said. βOperation Kratos 2β focused on disrupting the networksβ underlying infrastructure and stretched for seven months before coming to a close in April.Β
Officials did not name the suspects, groups or services targeted during the crackdown, but noted that investigators identified key players responsible for managing and operating the piracy platforms.
Europol said the streaming sites infringed on nearly 850,000 media across 169 domains.Β
βWhat appears to consumers as cheap access to premium content is powered by complex criminal enterprises,β the agency said in a news release. Illegal streaming site operators host separate servers for customer-facing websites and illegal content, and distribute their services across multiple countries.
During the course of the operation, officials conducted 148 house searches, identified 86 suspects and referred 59 cases to courts for criminal proceedings.Β
Investigators also worked with private-sector partners to identify nearly 4,400 new domains and more than 18,000 IP addresses linked to piracy and other illegal activity. Those efforts allowed authorities to report almost 400,000 additional URLs for suspension or removal.Β
Live sports piracy networks are widespread and consistently tracked by antipiracy coalitions and authorities globally. Authorities in Egypt last year shut down Streameast, the most popular and largest illegal live sports streaming network at the time, with an operation that spanned 80 domains and logged more than 1.6 billion visits during the year prior.
Operation Kratos 2 was supported by anti-piracy associations, UEFA Europa League, La Liga, beIN Media Group and officials from Belgium, Bulgaria, Croatia, France, Greece, Ireland, Italy, the Netherlands, Poland, Romania, Spain, the United Kingdom and the United States.
The post European authorities crack down on illegal streaming networks appeared first on CyberScoop.
Snapdragon X2 is fast, but Windows on Arm holds it back
MS-DEFCON 2: Sometimes thereβs no fix
Congress kicks the can down the road on surveillance law (again)
Congress extended a controversial surveillance law for 45 days on Thursday, hours before its latest expiration following an earlier extension.
The Senate passed β then the House cleared β a 45-day extension of Section 702 of the Foreign Intelligence Surveillance Act, which authorizes warrantless surveillance of foreign targets. But those targets are sometimes communicating electronically with Americans, and intelligence officials can search the database using their identifying information, which has long given privacy groups and privacy-minded lawmakers heartburn.
The 45-day reprieve gives lawmakers more time to hammer out a lasting deal, and comes after the leaders of the Senate Intelligence Committee agreed to send a letter to the Director of National Intelligence and attorney general, seeking swift declassification of a letter on a classified ruling from the Foreign Intelligence Surveillance Court.
Sen. Ron Wyden, D-Ore., had sought release of that opinion, and had resisted giving unanimous consent for the latest short-term extension to move forward until Senate Intelligence Chairman Tom Cotton, R-Ark., and top panel Democrat Mark Warner of Virginia agreed to send the letter.
A declassification review was already underway, but the Cotton-Warner letter states that βWe expect that this declassification review will be completed and the FISC opinion released publicly within 15 days,β according to Wyden, speaking on the Senate floor.
The March 17 opinion reportedly came with annual recertification of the warrantless surveillance program. The Justice Department is appealing that ruling because it blocked them from using certain tools to analyze communications.
βA few weeks ago, the Foreign Intelligence Surveillance Court found major compliance problems related to the surveillance law known as section 702,β Wyden said earlier this month. βThese compliance problems are directly related to Americansβ Constitutional rights.β
Senate Majority Leader John Thune, R-S.D., said the extension will give lawmakers additional room to hold βdiscussion on reforms.β
The House this week had passed a 3-year reauthorization with some changes to the surveillance program, but key to doing so was leadershipβs agreement to attach legislative language on a separate matter that would ban a central bank digital currency. Thune had said that language was going nowhere in the Senate.
On Thursday, the House voted 261-111 to extend the law for 45 days. President Donald Trump has sought a βcleanβ 18-month reauthorization of the surveillance powers.
The extension continues a perennial ritual for the Hill when it comes to Section 702: A deadline looms, and Congress kicks the can down the road repeatedly.
The post Congress kicks the can down the road on surveillance law (again) appeared first on CyberScoop.