The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security. The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.

A new report advocates for the designation of artificial intelligence (AI) and its supporting infrastructure as the 17th critical infrastructure sector in the United States. This move would unlock federal resources and services for an industry increasingly vital to national and economic security, according to the report.
The report, published by the nonprofit Americans for Responsible Innovation, specifically calls for the Cybersecurity and Infrastructure Security Agency (CISA) to lead cybersecurity efforts for this proposed sector. Authors Terrence Kelly and Jessica Maksimov argue that the AI sector, encompassing organizations, facilities, technologies, and industries involved in the development, training, deployment, and operation of AI systems, already exhibits characteristics of critical infrastructure. This includes frontier model designs, model weights, evaluation and alignment systems, data centers, AI-specific hardware, semiconductor chips, and platforms for deploying AI models at scale.
Maksimov emphasized that CISA is well-suited for this role due to its statutory mission, experience managing eight other critical infrastructure sectors, and its established ability to address cybersecurity issues across various industries. The report highlights the interconnectedness of AI with public and private services, its concentration among a few foundation models, and its growing interdependence with existing critical infrastructure sectors. This interdependence means a single attack on the AI "stack" could trigger cascading failures across multiple sectors.
Experts note that the U.S. is particularly vulnerable to AI supply chain disruptions because most frontier AI companies and their computing resources are based domestically. With the current administration pushing for broader AI adoption across government and the private sector, a major disruption could have significant economic consequences. Recent incidents, such as Iranian drones attacking Amazon-owned data centers and Ukrainian drones striking the Russian e-commerce giant Wildberries, illustrate the potential for critical internet service disruptions.
Matt Hayden, a former assistant secretary of homeland security for cyber infrastructure risk and resilience, explained that a critical infrastructure designation places an industry in a special category, identifying it as a component of a national critical function essential to the U.S. population and economy. Such a designation provides access to a wide array of federal tools and resources, often free of charge. These include operational continuity and incident response services, cybersecurity software, access to federal systems like Continuous Diagnostics and Mitigation (CDM), and bespoke, real-time threat intelligence.
Hayden believes that at a minimum, frontier AI models will eventually be covered as critical infrastructure, either through a new sector or by integrating them into existing ones like IT and telecommunications. However, he cautioned that efforts to formalize a federal lead for AI security would likely lead to bureaucratic disputes, citing similar challenges faced by sectors like space and cloud computing in their pursuit of critical infrastructure designations.
Bob Kolasky, former director of CISA's National Risk Management Center, anticipates that companies such as OpenAI and Anthropic, along with data center operators, will eventually be designated as critical infrastructure. He also noted that while CISA is well-positioned, the AI sector will present unique challenges and coordination issues. Kolasky pointed out that the effectiveness of simply adding AI as another sector, functioning like the existing 16, is an open question, given the varied operational approaches among current critical infrastructure sectors.
The Department of Homeland Security's new ANCHOR-CI program, rolled out in July, allows CISA to convene ad-hoc stakeholder meetings for emerging cyber threats and grants the CISA director authority to add individual companies to existing critical infrastructure sectors. It remains to be seen whether this program will improve upon previous processes.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.