Kerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News.

The National Security Agency has appointed Kerianne Tobitsch as its new general counsel, filling a key legal role that had been vacant for approximately a year. Tobitsch, who previously served as a senior lawyer at the Department of Homeland Security, began her appointment on June 15, 2026.
Before her tenure at DHS, which began in April 2025, Tobitsch worked for over eight years at the New York City office of the law firm Jones Day, where she became a partner. Her professional background also includes contributions to JD Supra, an online legal publication, where she and her colleagues at Jones Day offered insights on privacy and data security matters.
The general counsel position at the NSA is a career civil servant role, intended to be apolitical, and involves overseeing the legal reviews and approvals for clandestine operations. Tobitsch's appointment comes at a critical time, as policymakers are expected to address the renewal of Section 702 of the Foreign Intelligence Surveillance Act (FISA) when they return from summer recess. This statute, which expired in June, permits the NSA to collect electronic communications of targeted foreigners abroad from American companies without a warrant.
The previous general counsel, April Falcon Doss, appointed in 2022 during the Biden administration, was removed from her position after a conservative website published a story about her past work as a Democratic staffer for the Senate Intelligence Committee. This story gained traction on social media, amplified by a far-right conspiracy theorist who had previously claimed responsibility for other high-level departures at U.S. Cyber Command and the NSA.
Around the time of Doss's departure, two other senior NSA lawyers voluntarily retired. These positions were subsequently filled on an acting basis. The NSA has not commented on whether these specific roles have been permanently refilled. The series of high-level departures had caused some internal concern within the agency and command, though officials are reportedly more at ease following the installation of a new commander and recent appointments to other top personnel roles.
The appointment of a general counsel has been a point of contention in recent years. In the final days of the first Trump presidency, Michael Ellis, an administration loyalist, was appointed to the role. This move was criticized by Congressional Democrats as an attempt to "burrow" a political appointee into a career position. Ellis was placed on leave at the beginning of the Biden administration before ultimately resigning. An inspector general probe later found no improper pressure from the Trump administration on the Defense Department regarding Ellis's appointment; Ellis is now the CIA's deputy director.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed