The Trump administration has authorized federal law enforcement to collaborate with private companies on offensive cyber operations against foreign threat actors. A new National Security Presidential Memorandum facilitates this by establishing a framework for private sector involvement in gathering threat intelligence and proposing disruptive cyber operations, overseen by a Homeland Security Task Force program. While some in the cybersecurity community view this as a significant expansion of public-private collaboration, others express concerns about attribution accuracy and the potential for escalating cyber hostilities.

The White House has issued a National Security Presidential Memorandum (NSPM) on August 12, authorizing federal law enforcement agencies to partner with private companies in conducting offensive cyber operations against foreign threat actors targeting the United States. This directive expands upon an Executive Order from March, which mandated aggressive measures by government agencies to combat cyber-enabled crime affecting Americans.
The NSPM acknowledges the private sector's advanced technological capabilities, which it states have been historically underutilized in efforts to disrupt cybercriminal networks. The new memorandum aims to integrate these capabilities into such operations.
To oversee these activities, the Homeland Security Task Force’s National Coordination Center (NCC) will establish a program led by two Executive Directors from the Department of Justice and the Department of Homeland Security. This framework will allow private sector companies to form agreements with other firms and government bodies at federal, state, and local levels. These agreements will facilitate intelligence gathering on transnational cybercrime groups and the proposal of cyber operations designed to disrupt their activities.
The memorandum specifies that "rigorous procedures" will be implemented for the review and execution of "limited" cyber operations, which will always be conducted under the direct supervision of the U.S. government. It also emphasizes that the program will adhere to the U.S. Constitution, relevant laws, and international agreements.
The White House justifies this expanded approach by citing the significant financial damage inflicted on American businesses and individuals by cyberattacks. In 2025, American consumers reportedly lost over $20.8 billion to cyber-enabled crime, with 73% of U.S. adults experiencing some form of online scam or attack. The administration argues that "every available tool" must be deployed to counter these transnational cyber threats.
The cybersecurity community has offered mixed reactions to the NSPM. Chris Wysopal, co-founder of Veracode, characterized the policy as a "big shift" in U.S. cyber strategy, noting it represents a significant expansion of the private sector's role in offensive cyber operations, even if not explicitly "hack back" actions.
However, concerns have been raised regarding the risks associated with private sector involvement in offensive cyber strikes. These include the potential for misidentification of targets and the possibility of escalating cyber hostilities rather than deterring them. Nick Carr, technical director for the Microsoft Threat Intelligence Center (MSTIC) team and former chief technical analyst at CISA, highlighted the inherent difficulty in accurately attributing cybercrime, even for government agencies. He expressed concern that many organizations frequently make errors in attribution, though he suggested the new program could mitigate this by improving attribution work.
Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher, cautioned that authorizing the destruction of cyber-controlled infrastructure could inadvertently affect state-linked systems, potentially increasing the risk of interstate escalation and conflict.
The United Kingdom has also moved to facilitate offensive cyber actions to disrupt cybercriminal groups, establishing the National Cyber Force (NCF) in 2020. In 2023, the UK government published principles for the NCF's use of these capabilities, stressing that such measures would be deployed sparingly, only when other responses are less effective.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed