LIVE · cybersecurity feed
Live wire
security

A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo.

The “philosophical shift” that the memo authorizes raises legal, practical and moral questions, experts say. The post A bold new strategy or a dangerous precedent? Experts are divided on Trump’s memo. appeared first on CyberScoop.

zeroday.news ·

A recently signed presidential memorandum aims to enlist private sector companies in federal law enforcement hacking operations against transnational criminal organizations, a move that has sparked debate among cybersecurity experts regarding its legal, practical, and ethical implications. The directive, which sets a 60-day timeframe for establishing the program, represents a significant shift in U.S. cyber policy.

Supporters of the memo, including those within the former Trump administration, view it as an essential step to enhance the nation's capabilities in cyberspace. Amanda Naylor, former director of cyber policy at the National Security Council, stated that the memo is designed to leverage the private sector's speed and innovation in combating transnational cybercrime and fraud. Joshua Steinman, a former Trump White House cybersecurity official, suggested it would help the U.S. achieve parity with adversaries who operate with fewer restrictions in cyberspace, allowing for the pursuit of strategic objectives against criminal organizations.

However, critics express serious concerns, likening the memo to the historical practice of "letters of marque" that authorized privateers. Security consultant Davi Ottenheimer criticized the memo, highlighting that the practice of privateering was abandoned due to the violence and mercenarism it fostered. He also raised concerns about the targeting of individuals or groups designated as "criminals," fearing potential misuse of such broad authority.

The memo mandates the establishment of legal and constitutional procedures for approving the targeting of U.S. citizens and developing methods to prevent unintentional targeting of U.S. persons or systems. Despite these provisions, Ottenheimer argued that limiting operations to "criminals" could create perverse incentives for attackers and complicate defenses, potentially allowing targets to halt operations by claiming state affiliation. He also pointed out the lack of notification for individuals being designated as targets, raising ethical questions about due process.

Michael Garcia, a former CISA official, acknowledged some positive aspects of the memo but expressed significant worries about its execution, particularly regarding attribution. He cautioned that pressure for faster attribution could lead to lower certainty about targets, potentially resulting in private companies accidentally attacking foreign governments. Garcia also questioned the legality of private citizens engaging in such operations, noting that the Constitution grants the federal government the sole authority to wage war. He suggested that court oversight, similar to that required for private sector takedown operations, should be included.

Another point of contention is the willingness of companies to participate. Garcia wondered if the legal risks involved would deter a large pool of companies, especially given uncertainties about government protections. Robert Graham, CEO of Errata Security, noted that while the program involves federal supervision, there's a risk it could evolve into law enforcement delegating more autonomy to private companies.

The memo's classified annex and the fate of any seized assets remain unclear, according to both Graham and Ari Redbord, global head of policy at TRM Labs. Redbord, while generally supportive of the memo as a transformative step to combine private sector data with public sector authorities against rapidly evolving AI-driven scams, also raised questions about the specifics of government direction and control during live operations and how disruption efforts would unfold.

Ultimately, the success and implications of this new policy will largely depend on the details established within the 60-day implementation period, which will define the operational framework, legal safeguards, and oversight mechanisms for private sector involvement in offensive cyber operations.

ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]

ddos

DDoS Attacks Cause Major Threema Outages

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid se

security

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]

malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of […]