LIVE · cybersecurity feed
Live wire
security

Is Cyber missing the Marque?

In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber operations.

zeroday.news ·

The White House has issued a presidential memorandum titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” which directs the Department of Justice (DOJ) and Department of Homeland Security (DHS) to establish a program enabling private companies to conduct cyber operations against transnational criminal organizations outside the United States. This initiative goes beyond traditional intelligence sharing or investigative assistance, explicitly envisioning private sector involvement in cyber surveillance and "cyber effects operations" under the direction and delegated authority of the U.S. government.

The memorandum represents a significant shift in U.S. policy, creating a formal mechanism for private companies to participate directly in government-authorized offensive cyber operations abroad. While distinct from "hack back" policies, the framework raises numerous operational questions, including how attribution will be established for authorizing operations, how to handle overlaps between criminal and state infrastructure, the ownership of access discovered during operations, and the management of intelligence collected by private entities. A key concern is the potential international implications if employees of an American cybersecurity company are discovered conducting offensive operations within another country's borders.

The DOJ and DHS have been given 60 days to establish the operating procedures for this program, and no operations can be approved until these procedures are in place. This timeline suggests that more concrete details about the program's implementation will emerge within the next two months. The new framework is expected to significantly alter the threat model for private cybersecurity companies and their employees who choose to participate.

In related cybersecurity news, researchers have identified a Chinese-speaking cybercrime group, UAT-10147, which is leveraging agentic AI to orchestrate sophisticated post-compromise operations on global web servers. This group utilizes AI to generate operational playbooks, automate exploits, and develop custom malware. Among their tools is the newly discovered SPECTRE implant, a cross-platform backdoor that includes a custom Linux kernel rootkit and employs Bring Your Own Vulnerable Driver (BYOVD) techniques to evade endpoint detection and response (EDR) solutions.

UAT-10147's integration of agentic AI allows them to scale complex attacks efficiently, dynamically troubleshoot, validate exploit paths, and generate custom rootkits that neutralize security stacks at the kernel level. This significantly reduces the window for detection as adversaries can automate reconnaissance and blind EDR systems. Defenders are advised to prioritize patching known one-day vulnerabilities in internet-facing applications such as Zimbra, Nacos, and Telerik UI. Additionally, securing ASP.NET MachineKeys to prevent ViewState deserialization attacks, blocking known vulnerable drivers, and tuning network monitoring to detect anomalous HTTP 500 errors used for exploit validation are critical mitigation steps.

Other notable cybersecurity developments include a critical zero-click flaw in GitLab that requires immediate upgrades for self-managed versions, an "unprecedented" wave of Apple spyware alerts sent to users in 110 countries, and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding critical vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. A recent survey also indicates that AI adoption in cybersecurity, particularly for red team activities, is outpacing the establishment of formal governance and audit frameworks.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

security

China Is Strapping ‘Digital Bombs’ to Civilian Infrastructure—Is the US Ready?

This week on “Uncanny Valley,” Andy Greenberg discusses sitting in on a war game simulating a cyberattack from the Chinese hacking group Volt Typhoon

nation-state

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These clusters include UNC6293, UNC7005, and UNC5976. "These clusters engage in persistent, adaptive

malware

China’s ‘SilkParasite’ espionage operation targeting Central Asia with AI-assisted malware

Suspected military-grade hackers based in China used artificial intelligence to develop malware in a campaign to penetrate Central Asian governments.

security

What We Missed: Delta Flight Disrupted With Wi-Fi Hack

In this video, Dark Reading editors discuss some of the news they didn't get a chance to cover, including some scary airplane security risks and the US government's newest "hack back" strategy.

security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.