❌

Normal view

There are new articles available, click to refresh the page.
Today — 25 September 2026Main stream

How tax policy can stop threat actors from breaching US water systems

By: Greg Otto
24 September 2026 at 06:00

The foundation for modern society in America is under attack. State and local governments, entities that often oversee critical natural resources, schools, and hospital systems, are routinely targeted and breached by state-backed threat actors. Their budgets are simply too slim to provide the digital bulwarks required to fend off such attacks.

The problem is growing. In August, the Cybersecurity and Infrastructure Security Agency issued a joint advisory detailing an “active threat” against Siemens S7 series programmable logic controllers (PLCs), ruggedized industrial devices that read field sensors, execute control logic on a fixed cycle, and drive equipment like valves, motors, and pumps. Siemens S7 PLCs, widely used across industries, are under attack from malicious actors looking to sabotage American infrastructure vital to the functioning of sewers, hospitals, and other industrial operations.

In 2024, Russian-affiliated actors exploited a similar vulnerability, breaching the water system for a small town in Texas, causing the water tank to overflow. The town’s entire revenue in 2023 was $3.37 million, with no dedicated line item for cybersecurity. This was, in effect, a trial run. How and when the detection occurred was an education for the Russians.  

American state and local governments are unlikely to organically grow their budgets to the level needed to invest in software that can reliably secure their infrastructure. The U.S. government has a proven option here: clarify that existing tax code already supports increased, iterative purchases of necessary cybersecurity software.

State and local governments are increasingly responsible for cybersecurity, with the same, or even fewer, resources than they had in the past. A plurality of state chief information security officers reported stagnant or reduced cybersecurity budgets for 2026. The picture at the local level is often worse, where a single operator often owns asset inventory, patching, and incident response for an entire utility. The Center for Internet Security in 2024 found that, out of the thousands of local agencies it surveyed, about one-third were doing minimal to no cybersecurity activities. In Minnesota, specifically Braham, Plymouth, South St. Paul, and Maple Plain, threat actors used this to their advantage.

Braham in particular identified $22.98 million in water infrastructure needs, well over 10 times its annual city budget of $2.2 million. A state bond appropriation covered $10.22 million, but the money was earmarked for a wastewater treatment plant upgrade, water main replacement, and well replacement. None of these funds covered the cybersecurity infrastructure needed to secure a plant from a state-backed threat actor: no security software, no network monitoring, no cybersecurity staff. Last month, they were one of many cities and municipalities discovered to have been targeted by actors allegedly acting on behalf of Iran.

State-backed adversaries understand that most of America is like Braham. While Anthropic’s and OpenAI’s cybersecurity efforts are admirable, they are aimed at the upper echelons of the American economy, not the wider array of smaller organizations with similar cybersecurity profiles. 

State and local governments cannot defend against state-backed actors alone. Federal tax incentives for cybersecurity software investment offer a faster solution than creating new government programs. This approach gives these organizations the tools to harden infrastructure while avoiding bureaucratic delays.

Bonus depreciation under the One Big Beautiful Bill should cover cybersecurity software and hardware. Digital infrastructure should also qualify for full expensing. Without these tax incentives, critical infrastructure remains vulnerable. A new factory without cybersecurity is essentially undefended.

Clarity on whether the implementation of cybersecurity software could apply to Section 174A expenses would also be useful. An affirmative interpretation could unlock private sector cybersecurity solutions for businesses and infrastructure operators, particularly those in rural areas. A recent letter from Sen. Tom Cotton to Treasury Secretary Scott Bessent asks for clarification of several aspects of tax law for such a purpose. 

There are discoveries and risks when deploying new cybersecurity tools. Organizations often don’t know the scope of their own inventory, and given the age of the equipment, bespoke software needs to be developed so customers can use the cybersecurity software. Pilot programs, iterative testing, and development are currently cost-prohibitive for many infrastructure operators. Affirmative interpretations could make this emergent threat into an opportunity to secure the infrastructure that Americans depend on every day.

An affirmative interpretation would benefit all Americans. State and local governments would protect themselves from state-backed threat actors. Firms would be more willing to invest in cybersecurity software, as the cybersecurity software market would grow significantly. Rapid investment is needed now, as AI today is being used to attack critical infrastructure.  

State and local governments now, more than ever, need cybersecurity software to face a world where they are on the front lines of cyberwarfare. The current administration needs to provide them with as much support as quickly as possible to ensure that American critical infrastructure is not reduced to scrap by enterprising malicious actors. 

The post How tax policy can stop threat actors from breaching US water systems appeared first on CyberScoop.

Before yesterdayMain stream

100-plus companies call for ‘global surge’ in AI-powered cyber defense

By: Greg Otto
27 August 2026 at 14:29

More than 100 companies and organizations, including OpenAI, Anthropic, Google, Microsoft and Amazon Web Services, have signed an open letter calling for a global effort to improve cybersecurity defenses as artificial intelligence capabilities advance.

The letter, published Thursday, argues that the timeframe to strengthen defenses before AI-enabled attacks become more widespread and complex is rapidly dwindling. Conversely, the letter says the same advances can give defenders new ways to find and fix vulnerabilities that have accumulated over years, a period the signatories call a “defenders’ window.”

“Each of us can reduce risk now,” the letter reads. “All organizations, cybersecurity companies, technology partners, governments, and AI frontier companies have an important role: accelerate defenders’ priorities with tools, funding, and hands-on support, especially for critical infrastructure organizations with limited budgets.”

Aside from AI-centric companies, financial institutions like Capital One, Mastercard and Visa, and cybersecurity firms like CrowdStrike, Palo Alto Networks, and Proofpoint, also signed the letter. Organizers describe the effort as ongoing, with more organizations expected to join over time.

An image of company logos depicting the signatories of a letter calling for enhanced AI defenses.

The letter states that “status quo security won’t be enough.” It cites longstanding bugs, excessive permissions, misconfigurations, unpatched software, weak authentication and technical debt in legacy systems as sources of exposure. Security teams, particularly those protecting critical infrastructure, have been historically under-resourced, the letter says, and need what it describes as a surge in tools, resources and hands-on support.

In a conversation with CyberScoop Wednesday, top brass from Palo Alto Networks said they had seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned.

“I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said Wednesday. 

John Doyle, CEO of Cape, a privacy-first mobile network operator and whose company signed the letter, echoed the warning about status-quo security.

“It was already failing us in telecom–critical infrastructure that’s been breached time and again with serious consequences for both our military and regular people,” Doyle told CyberScoop. “It’s going to get immeasurably worse without collective action and leaning into innovative cyber defense.”

The letter further asks every organization to make cybersecurity an immediate leadership priority, fix the highest-risk weaknesses and raise security standards for technology they buy, build and deploy, including AI-generated code. Cybersecurity companies and technology partners are asked to test defenses against frontier AI capabilities and make AI-powered defense accessible to critical infrastructure operators. 

Governments are urged to coordinate defense across borders, fund protection for essential services that lack staff or budget, and impose costs on attackers. Frontier AI companies are asked to provide responsible model access, funding, training and support, and to ensure that AI systems acting autonomously remain traceable and accountable.

The letter frames AI as both a threat and a remedy throughout the document. It mirrors what security experts have been saying for months, positioning the industry as entering an unprecedented two- to three-year period of upheaval, driven by AI systems that are discovering vulnerabilities exponentially faster than defenders can respond and threatening to render decades of security practices obsolete.

The U.S. government has taken steps to stay ahead of AI-enabled cyberthreats. As part of an executive order issued by President Donald Trump in June, a federal clearinghouse known as Gold Eagle was stood up for sharing AI cyber threat information between the government and private sector.

You can read the full letter here.

The post 100-plus companies call for ‘global surge’ in AI-powered cyber defense appeared first on CyberScoop.

Google’s solution to hacker name confusion? Yet another naming system

By: Greg Otto
27 July 2026 at 13:17

If you are a CISO, here is a new problem for the pile: Do I worry more about Sandworm Relic or Strawberry Tempest?

Last week, Google Threat Intelligence Group joined a list of rivals in changing how it names hackers, replacing years of split naming systems with a single set of code names built around memorable word pairs.

The company said in a blog post that the change merges two systems that had grown apart for years inside Google: Mandiant, the security firm Google bought in 2022, and its in-house Threat Analysis Group. Combining those units left Google with overlapping names for the same hacking groups, a problem the new system aims to fix.

“Threat tracking shouldn’t be an exercise in memorization, but rather one of intuition,” the post reads.

Each tracked group will now get a two-word name. The first word is a distinct term meant to be easy to recall, often pulled from names already used in past reporting on a specific group. When no such name exists, researchers will generate one at random and have analysts check it before use. The second word sorts each group by category, such as country of origin or motive. In Google’s published examples, CASTLE pairs with groups tied to China, ION with Iran, NEPTUNE with North Korea, RELIC with Russia, and COMET with financially motivated threat actors not tied to a nation-state.

The approach echoes one CrowdStrike has long been known for. CrowdStrike pairs a specific term with an animal tied to a country or motive: PANDA for China, BEAR for Russia, SPIDER for cybercriminals, JACKAL for hacktivists. Google’s system swaps the animals for words like CASTLE and NEPTUNE but follows the same basic structure, down to the argument for why it works: A two-part name carries more information than a bare country label or number, and it can change as attribution is fine-tuned.

Microsoft took its own turn at a naming overhaul in April 2023, dropping a system built on chemical elements, trees and volcanoes in favor of weather terms. Under that system, Typhoon marked China, Blizzard marked Russia, Sandstorm marked Iran, and Tempest marked financially motivated cybercriminals. The switch produced names that drew as much attention for their sound as their substance, among them Strawberry Tempest, Pumpkin Sandstorm and Pistachio Tempest. Industry experts bristled over the change, saying the names compared the groups to ice cream flavors or cocktails.

By 2025, the industry’s naming sprawl had become enough of a shared headache that two of the biggest players in it agreed to try to sort it out together. Microsoft and CrowdStrike announced a joint mapping effort in June of that year, pairing Microsoft’s weather names with CrowdStrike’s animal names for the same tracked groups, with Google, Mandiant and Palo Alto Networks Unit 42 also signed on to contribute. Both companies were careful to say the project was not an attempt to force the industry onto one naming system, just to make the existing ones easier to translate between.

Google‘s rollout starts with several dozen of the most actively tracked hacking groups, with more to follow over time. Older names will stay searchable within Google’s threat intelligence platform, alongside mappings to the MITRE ATT&CK framework and to the naming systems used by other vendors. 

The company says groups will keep carrying “UNC,” for uncategorized, if it is still too early to identify exactly where a group fits in this taxonomy.

The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop.

❌
❌