Normal view
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
Comcast adds motion sensing to millions of its newer routers, with a privacy catch
Bluesky says its recent outage was caused by another DDoS attack
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators
-
TechCrunch
- Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
Crypto hardware wallet owners face fresh security risks after recent spate of personal data thefts
How to tell if your AI platforms’ accounts have been hacked
What we know about the alleged Iranian hacks on US water utilities
-
TechCrunch
- If Apple sends you a push notification alerting you to a spyware attack, take it seriously
If Apple sends you a push notification alerting you to a spyware attack, take it seriously
The government is recruiting tech companies to help fight its cyber battles
President Donald Trump is paving a legal pathway for U.S. companies to launch cyberattacks on foreign cybercriminal gangs — a significant and potentially controversial measure that would put approved tech and cybersecurity firms on the front lines of digital combat.
The presidential memorandum, released late Wednesday, comes as the Trump administration has repeatedly pushed for more aggressive action to counter foreign scams and cyberattacks, which the White House said cost Americans nearly $21 billion last year.
The memo represents one of the biggest shifts in U.S. cyber policy undertaken in recent years. It would empower tech and security companies — whose data and control over internet infrastructure often offer unique insight into foreign hacking operations — to mount state-sanctioned digital strikes.
While many such companies already work closely with U.S. intelligence and law enforcement agencies, a web of legal and political constraints has long prevented them from taking direct action inside foreign networks.
Companies that want to participate would be required to sign contracts with both the Department of Justice and the Department of Homeland Security and to undergo what the memo describes as “rigorous vetting” while working with the government. The overall effort would be overseen by a National Coordination Center, established in an earlier Trump administration executive order, with co-executive directors from DOJ and DHS.
However, the memo states that no operations by the companies would be approved until the executive directors at DOJ and DHS establish “consensus procedures” with the White House Homeland Security Council guaranteeing “complete oversight and control of Participating Companies’ performance.”
Those procedures, it notes, should be drafted within 60 days. They are likely to be extensive.
They will outline steps for participating companies to obtain approval for proposed offensive hacking operations, so the government can confirm that the targets are criminal gangs and ensure that operations are consistent with U.S. law and don’t undermine ongoing U.S. intelligence efforts. Companies could propose surveillance operations to help identify criminals or “effects” operations to degrade the systems they use to stage their attacks.
Participating companies would have to pass minimum standards for technical expertise and personnel vetting, and would be required to notify the federal government if they believe approved operations may result in the loss of life or rise to the level of use of force under international law.
Some see the memo as a critical step to help the U.S. government counter foreign cybercriminal gangs that operate outside the reach of U.S. law enforcement.
“For years we’ve called the American technology industry a strategic asset but left it on the cyber sidelines,” Joe Lin, the CEO and co-founder of Twenty, a start-up that builds offensive cyber tools for the U.S. government, said in a statement. “This administration is changing the paradigm.”
The memo notes that companies will only be authorized to target criminals that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”
Even with the help of the U.S. intelligence community, making that distinction could be difficult.
Adversaries such as Russia, China and Iran have persistently targeted U.S. critical infrastructure, including water systems, ports, and telecommunications infrastructure, while multinational crime syndicates have defrauded billions of dollars annually from Americans via complex online schemes.
But many cyber gangs in Eastern Europe are thought to operate with the tacit consent of the Russian government, while state hackers in Iran and China sometimes moonlight as cybercriminals to earn extra money or deflect blame for their governments’ attacks.
More broadly, it is not always easy for digital investigators to determine who is responsible for a given cyberattack, or who different computer networks belong to — another risk the memo contemplates.
Companies that accidentally carry out operations targeting a U.S. citizen or network will be required to immediately pause the operation and notify the U.S. government, the memo states. It does not appear to preclude activities that are deliberately “directed” at a U.S. person, so long as they receive “any necessary authorization, judicial or otherwise, prior to approval of the operation.” Under U.S. law, a “U.S. person” can refer to an American business or organization.
Many lawmakers and security experts have broadly supported calls for the private sector to play a larger role in responding to cybercrime, though not all approve of granting them the ability to launch active hacking efforts.
In recent years, some House members have debated the idea of issuing “letters of marque” to private companies to carry out cyberattacks on behalf of the U.S. government, similar to the U.S. Navy authorizing private ships to disrupt British shipping during the War of 1812.
As part of a more assertive cyber posture, Trump has turned to U.S. Cyber Command to mount digital attacks in tandem with U.S. military operations, including in Iranand Venezuela. He signed an executive order this March to clamp down on countries that fail to take action against scam centers operating within their borders.
That same month, the White House called on the private sector to broadly help it “disrupt” foreign adversaries in its new national cyber strategy, though it stopped short of telling private companies to take riskier and more consequential steps, such as directly launching attacks against foreign criminals.
Some of the most prolific online fraud operations are believed to emanate from scam compounds in Southeast Asia. But hackers from North Korea — who for years have stolen hundreds of millions in cryptocurrency from victims around the world — would likely be exempt from targeting by U.S. companies since they work at the direction of the North Korean government.
Anthropic set AI agents loose on the same task. They started a turf war.
In a first, US will allow some private firms to carry out cyberattacks
Uber Freight reportedly investigating after hacking group claims data breach
-
TechCrunch
- After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
After Microsoft threatened legal action, a security researcher publishes a new Windows zero-day bug
-
TechCrunch
- FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures
FBI says cybercriminals are hacking into victims’ online accounts to steal their intimate pictures
Delta investigating after someone set up fake Wi-Fi network mid-flight
North Korean remote IT staffer worked for US government agency, says FBI
Zuckerberg warns against centralizing AI power
Meta CEO Mark Zuckerberg on Monday passionately defended the use of artificial intelligence, as the rapid advancement of the technology faces increased scrutiny — and calls for regulation — in the U.S. and globally.
In a 6,500 word post timed to the announcement of his company’s new open source version of its own model, Muse Spark, Zuckerberg detailed his vision for AI, arguing the technology is not to be feared and pushing back on concerns that superintelligence could strip people of jobs.
“The notion that AI is so dangerous that the only safe path is an extreme concentration of power seems inherently problematic,” Zuckerberg wrote. “Historically, hoping that an absolute power will benevolently provide for humanity if sufficiently enlightened has not led to safe or positive outcomes.”
Zuckerberg’s vision is a direct contrast to Anthropic CEO Dario Amodei’s, who has previously warned how AI could cause job disruption. Meta lags behind Anthropic and OpenAI, which have the most advanced AI models.
While Zuckerberg’s essay did not name Amodei or OpenAI directly, he called to broadly distribute superintelligent AI for economic opportunity. Doing so, Zuckerberg said, would provide a safety net to prevent just a handful of governments, businesses and other institutions holding too much power.
Still, Zuckerberg emphasized that the U.S. must address restrictions on AI companies in order to create the best models in the world.
“It is also important that the US and its allies lead the open source AI ecosystem that will make up a large percent of global AI use,” Zuckerberg wrote. “Foreign labs currently hold several advantages here since American labs have to comply with many additional restrictions on training data.”
Zuckerberg’s essay comes amid growing concerns around AI safety. Last month, Anthropic revealed that several of its advanced models gained access to three organizations in three separate incidents dating back to April. That hack came shortly after OpenAI said that two of its most powerful models escaped a testing environment and breached multiple companies.
Lawmakers last month introduced a bill that would give the government power to restrict the use of models that could lead to catastrophic risks. While it is the latest bipartisan effort to address concerns around AI models, Congress has ultimately failed to advance broad legislation.
Zuckerberg urged the federal government to work with companies to test new models as he laid out his strategies for protecting against cybersecurity and bioterrorism.
“First, we should focus on limiting the physical production and distribution of harmful materials,” he wrote. “I expect it will be easier to regulate and control physical components than the spread of knowledge, so this is an important area of policy focus. Second, we should accelerate society’s ability to develop new cures and inoculate against new issues as they arise. This includes streamlining how the FDA and other regulators test and approve new treatments.”
Zuckerberg also defended the spread of data centers, arguing that the centers represent investment into communities as he touted his company’s goal of being “water-positive, meaning that we’ll restore more water than we use in the watersheds where we operate by 2030.”