The White House has issued a presidential memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” which directs the Department of Justice (DOJ) and Department of Homeland Security (DHS) to establish a program enabling private companies to conduct cyber operations against transnational criminal organizations outside the United States. This initiative goes beyond traditional intelligence sharing or investigative assistance, explicitly envisioning private sector involvement in cyber surveillance and "cyber effects operations" under the direction and delegated authority of the U.S. government.
The memorandum represents a significant shift in U.S. policy, creating a formal mechanism for private companies to participate directly in government-authorized offensive cyber operations abroad. While distinct from "hack back" policies, the framework raises numerous operational questions, including how attribution will be established for authorizing operations, how to handle overlaps between criminal and state infrastructure, the ownership of access discovered during operations, and the management of intelligence collected by private entities. A key concern is the potential international implications if employees of an American cybersecurity company are discovered conducting offensive operations within another country's borders.
The DOJ and DHS have been given 60 days to establish the operating procedures for this program, and no operations can be approved until these procedures are in place. This timeline suggests that more concrete details about the program's implementation will emerge within the next two months. The new framework is expected to significantly alter the threat model for private cybersecurity companies and their employees who choose to participate.
In related cybersecurity news, researchers have identified a Chinese-speaking cybercrime group, UAT-10147, which is leveraging agentic AI to orchestrate sophisticated post-compromise operations on global web servers. This group utilizes AI to generate operational playbooks, automate exploits, and develop custom malware. Among their tools is the newly discovered SPECTRE implant, a cross-platform backdoor that includes a custom Linux kernel rootkit and employs Bring Your Own Vulnerable Driver (BYOVD) techniques to evade endpoint detection and response (EDR) solutions.
UAT-10147's integration of agentic AI allows them to scale complex attacks efficiently, dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize security stacks at the kernel level. This significantly reduces the window for detection as adversaries can automate reconnaissance and blind EDR systems. Defenders are advised to prioritize patching known one-day vulnerabilities in internet-facing applications such as Zimbra, Nacos, and Telerik UI. Additionally, securing ASP.NET MachineKeys to prevent ViewState deserialization attacks, blocking known vulnerable drivers, and tuning network monitoring to detect anomalous HTTP 500 errors used for exploit validation are critical mitigation steps.
Other notable cybersecurity developments include a critical zero-click flaw in GitLab that requires immediate upgrades for self-managed versions, an "unprecedented" wave of Apple spyware alerts sent to users in 110 countries, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding critical vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. A recent survey also indicates that AI adoption in cybersecurity, particularly for red team activities, is outpacing the establishment of formal governance and audit frameworks.






