❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Lawmakers call on Commerce to sanction hackers-for-hire

9 September 2026 at 14:43

A bipartisan trio of lawmakers is asking the Commerce Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies.

Democratic Sens. Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island and Rep. Pat Harrigan, R-N.C., sought in a letter to Secretary Howard Lutnick Wednesday to have the mercenary firms added to the Treasury Department’s Entity List, which would limit their access to American software, cybersecurity tools and cloud infrastructure.

“Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote. “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”

The three firms are Sunkissed Organic Farms, BellTroX and CyberRoot. The first of those three was formerly known as Appin and has been the subject of investigative reports and criminal probes. The Citizen Lab at the University of Toronto has delved into the work of BellTroX, and journalists also have reported on the activity of CyberRoot.

“The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence,” the lawmakers wrote. “While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.”

Reuters reported in 2023 that the family member was Kristi Rogers, wife of former House Intelligence Chairman Mike Rogers, now running for Senate as the GOP candidate against one of the midterms’ most important and contested races against Democrat Abdul El-Sayed.

Some of the hacking groups also have sought to censor reporting on their hacking activities, the lawmakers noted.

CyberScoop couldn’t reach the companies for comment. The Commerce Department also didn’t immediately respond to a request for comment, and the government of Qatar didn’t immediately respond to an email seeking comment on the letter. TechCrunch first reported on the letter.

Corrected 9/10/2026: to reflect department to which the lawmakers addressed the letter.

The post Lawmakers call on Commerce to sanction hackers-for-hire appeared first on CyberScoop.

Wyden seeks upgraded NSA security guidance on commercial VPN use

2 September 2026 at 11:00

Sen. Ron Wyden, D-Ore., is asking the National Security Agency to update public guidance on the security risks associated with commercial virtual private networks, and to answer questions about foreign surveillance threats against standard VPNs.

In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn about standard, commercial VPNs, following letters to federal agency leaders in March and July.

“While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries,” Wyden wrote in the letter, first reported by CyberScoop. “Other, more secure alternatives are widely available.”

Wyden took aim at “single-hop” VPNs that routes data through one server before arriving at the destination.

He cited a Congressional Research Service paper from last month that said “a single-hop VPN, however strongly encrypted, offers essentially no protection against an adversary who can compel… or infiltrate that one provider,” compared to “multi-hop and mixnet architectures [that] directly target and mitigate this weakness” since a second server only knows the IP address of the first server.

He also cited a letter responding to an earlier missive that Wyden signed with other lawmakers in an exchange with the Office of the Director of National Intelligence. The office offered a note of caution about scrutinizing VPN providers’ privacy and security policies, but Wyden said “it overlooked the importance of the VPN service’s architecture against sophisticated foreign threats.”

Wyden referenced an advisory from the NSA and allied foreign governments last September about a China-sponsored campaign to target telecommunications, government and military networks.

He said that the NSA should update its public guidance on VPN configuration.

“Americans facing advanced foreign threats — including government personnel, defense contractors, journalists, and human rights defenders — deserve clear, honest advice about how best to protect their communications from surveillance by foreign adversaries. 

He also asked Rudd to answer a series of questions in an unclassified reply. Some view single-hop commercial VPNs as sufficient for average internet users, and Wyden asked whether they were strong enough to protect “Americans’ sensitive digital footprints against foreign adversaries capable of monitoring internet backbones.”

And Wyden wants Rudd to weigh in on the importance and effectiveness of multi-hop anti-surveillance systems, like Apple Private Relay, Tor and Nym, as well as how multi-hop proxy systems fare against mixnet architectures.

You can read the full letter below.

The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.

Lawmakers seek watchdog review of federal hacking of Americans

21 August 2026 at 11:05

A pair of lawmakers wants a watchdog agency to probe how the federal government hacks Americans, including with the use of spyware, and deliver a report to the public.

Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas, wrote to the Government Accountability Office on Friday to request the review.

“While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards,” they wrote. “Unlike traditional surveillance authorities, such as wiretaps or pen registers, the government does not publish annual reports for hacking operations.”

The issue of U.S. government spyware usage has grown in prominence in President Donald Trump’s second term, as Immigration and Customs Enforcement has acknowledged working with spyware firm Paragon. Lawmakers have been asking whether that’s the full extent of U.S. government reliance on spyware after the Biden administration largely shunned it.

But the Wyden and Casar letter is broader than just spyware. It also touches on the federal government’s acquisition of hacking tools, like those in the case of a former senior official at defense contractor L3Harris who was sentenced this year for stealing and selling capabilities developed for the federal government, and Rule 41 hacking powers.

The congressional duo asked GAO to review documented cases of federal law enforcement misusing hacking capabilities for personal or otherwise unauthorized reasons, and what kind of safeguards agencies have against hacking abuses.

“Spyware and other hacking tools grant expansive access to personal devices, including webcams, location data, stored files, and encrypted communications,” they wrote. “Unrestricted access to such invasive surveillance capabilities invites abuse by rogue agency personnel. Indeed, there are countless documented examples of government employees abusing other sensitive surveillance databases and tools for unauthorized personal purposes.”

They also asked GAO to review how agencies buy and protect sophisticated hacking tools, and how agencies make Rule 41 hacking requests to courts.

TechCrunch first reported on the letter from Wyden and Casar.

Casar is the top Democrat on the House Oversight Subcommittee on Federal Law Enforcement, and Wyden has a long career of scrutinizing federal intelligence and surveillance efforts.

The post Lawmakers seek watchdog review of federal hacking of Americans appeared first on CyberScoop.

Sen. Wyden urges feds to discard older, insecure, public-facing VPNs

27 July 2026 at 09:00

Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprehensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies.

“For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden, D-Ore., wrote in his missive to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology. They should coordinate “require the adoption of modern, secure remote-access technology across the federal government,” he said.

Such VPNs serve as a digital “front door” accessible via the public internet that allows mobile devices and remote employees to log in, Wyden said in a letter first reported by CyberScoop.

Wyden referenced several attacks that have affected federal agencies, including the ArcaneDoor attacks on Cisco firewalls, the FortiBleed credential exposures across Fortinet gateways and vulnerabilities that hackers exploited across Ivanti and Check Point VPN appliances.

“Modern remote-access solutions eliminate this vulnerability entirely. Instead of leaving an open door accessible from the public internet, modern solutions provide remote access without broadcasting their presence,” he said. “This effectively makes these servers invisible, ensuring that hackers cannot attack an entry point they cannot see.”

Agencies should move away from what a Congressional Research Service report to Wyden called a “castle-and-moat” approach of assuming anyone inside the network is authorized to access an organization’s resources that VPNs rely upon by extending virtual bridges to a more remote workforce, he said. They should instead focus on zero-trust architecture that uses a never-trust, always-verify approach, he said.

Furthermore, CISA, the OMB and NIST need to fundamentally change how the federal government approaches agency vulnerabilities, Wyden wrote. 

“The federal government has become trapped in an endless game of ‘whack-a-mole’ in responding to widespread compromises of legacy remote access technologies,” he said. “To keep federal networks online, CISA has been forced to repeatedly issue extraordinary Emergency Directives and hyper-accelerated patch mandates. These reactive emergency mandates are unsustainable for federal cybersecurity teams, and fail to address the fundamental issue that these flaws are inherent in the use of legacy remote-access appliances.”

CISA needs to issue a binding operational directive that gives agencies two years to fully expunge legacy, public-facing remote access systems, he said. NIST needs to issue implementation standards for transitioning to zero-trust architectures.

OMB needs to issue a memo directing agencies to prioritize zero-trust architecture spending. And OMB needs to team with CISA and the Defense Department to update procurement rules to block agencies and defense contractors from buying network edge, VPN or other remote access solutions unless a vendor supplies an attestation that it complies with NIST zero-trust standards, Wyden wrote.

The post Sen. Wyden urges feds to discard older, insecure, public-facing VPNs appeared first on CyberScoop.

❌
❌