LIVE · cybersecurity feed
Live wire
Critical Avada WordPress theme flaw enables zero-click RCECVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacksEmployee benefits platform Paylogix says hackers stole financial and health dataU.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesCVE-2026-61979 · Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as VulnerableCVE-2024-28224 · A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClawAustralia Warns of Active Exploitation of Critical TeamCity Server FlawCVE-2026-21962 · Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data
nation-state

Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure

The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed. The post Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure appeared first on CyberScoop.

zeroday.news ·

President Donald Trump has signed an executive order declaring a national emergency to safeguard the U.S. bulk-power system, citing cybersecurity and other security threats. The order, titled "Declaring a National Energy Emergency to Secure the United States Bulk-Power System," aims to prohibit the acquisition, importation, transfer, or installation of certain foreign-produced equipment, software, and systems if they are determined to pose a significant national security risk.

The White House issued a fact sheet explaining that the order generally forbids specific foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities, that could present cybersecurity or operational risks. Alternatively, it conditions such purchases and installations to mitigate identified risks.

This executive order is seen as a response to concerns about Chinese-made equipment within U.S. energy infrastructure, continuing a trend from the Trump administration to restrict such technology. The order specifically mentions that minimal restrictions on foreign-produced bulk-power system electric equipment allow some foreign entities to create and exploit vulnerabilities, such as digital backdoors that could enable remote access.

China is a significant player in the power transformer manufacturing sector and accounts for 85% of the global solar supply chain production capacity, according to the International Atomic Energy Agency. In 2024, then-FBI Director Christopher Wray informed Congress that hackers were pre-positioning themselves in small office and home routers, with the electricity grid identified as a target in a potential conflict between China and the United States.

This is not the first time the Trump administration has addressed this issue; near the end of his first term, a similar executive order was signed to limit the purchase of foreign-made bulk-power equipment. However, the Biden administration later suspended that order to review its scope and subsequently revoked and replaced a related Department of Energy order, as some utilities had found compliance with the 2020 executive order challenging.

Under the new order, the Department of Energy has 120 days to develop and implement rules, in consultation with other key departments.

nation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Critical Avada WordPress theme flaw enables zero-click RCE

A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]

malware

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims.

security

More than 100 water systems were hit in July cyberattacks

'These are test runs for a larger-scale attack'

breach

OpenAI: Agent behavior that led to Hugging Face intrusion formed in May

The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks. The post OpenAI: Agent behavior that led to Hugging Face intrusion formed in May appeared first on CyberScoop.

security

New GPUThor attack defeats NVIDIA ECC protection for root access

A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]

security

Meta agrees to $18 billion settlement over teen social media harms

Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]