LIVE · cybersecurity feed
Live wire
cybersecurityhigh

Trump Authorizes Private Sector Participation in Offensive Cyber Operations

The Trump administration has authorized federal law enforcement to collaborate with private companies on offensive cyber operations against foreign threat actors. A new National Security Presidential Memorandum facilitates this by establishing a framework for private sector involvement in gathering threat intelligence and proposing disruptive cyber operations, overseen by a Homeland Security Task Force program. While some in the cybersecurity community view this as a significant expansion of public-private collaboration, others express concerns about attribution accuracy and the potential for escalating cyber hostilities.

zeroday.news ·

The White House has issued a National Security Presidential Memorandum (NSPM) on August 12, authorizing federal law enforcement agencies to partner with private companies in conducting offensive cyber operations against foreign threat actors targeting the United States. This directive expands upon an Executive Order from March, which mandated aggressive measures by government agencies to combat cyber-enabled crime affecting Americans.

The NSPM acknowledges the private sector's advanced technological capabilities, which it states have been historically underutilized in efforts to disrupt cybercriminal networks. The new memorandum aims to integrate these capabilities into such operations.

To oversee these activities, the Homeland Security Task Force’s National Coordination Center (NCC) will establish a program led by two Executive Directors from the Department of Justice and the Department of Homeland Security. This framework will allow private sector companies to form agreements with other firms and government bodies at federal, state, and local levels. These agreements will facilitate intelligence gathering on transnational cybercrime groups and the proposal of cyber operations designed to disrupt their activities.

The memorandum specifies that "rigorous procedures" will be implemented for the review and execution of "limited" cyber operations, which will always be conducted under the direct supervision of the U.S. government. It also emphasizes that the program will adhere to the U.S. Constitution, relevant laws, and international agreements.

The White House justifies this expanded approach by citing the significant financial damage inflicted on American businesses and individuals by cyberattacks. In 2025, American consumers reportedly lost over $20.8 billion to cyber-enabled crime, with 73% of U.S. adults experiencing some form of online scam or attack. The administration argues that "every available tool" must be deployed to counter these transnational cyber threats.

The cybersecurity community has offered mixed reactions to the NSPM. Chris Wysopal, co-founder of Veracode, characterized the policy as a "big shift" in U.S. cyber strategy, noting it represents a significant expansion of the private sector's role in offensive cyber operations, even if not explicitly "hack back" actions.

However, concerns have been raised regarding the risks associated with private sector involvement in offensive cyber strikes. These include the potential for misidentification of targets and the possibility of escalating cyber hostilities rather than deterring them. Nick Carr, technical director for the Microsoft Threat Intelligence Center (MSTIC) team and former chief technical analyst at CISA, highlighted the inherent difficulty in accurately attributing cybercrime, even for government agencies. He expressed concern that many organizations frequently make errors in attribution, though he suggested the new program could mitigate this by improving attribution work.

Dr. Lukasz Olejnik, an independent cybersecurity and privacy researcher, cautioned that authorizing the destruction of cyber-controlled infrastructure could inadvertently affect state-linked systems, potentially increasing the risk of interstate escalation and conflict.

The United Kingdom has also moved to facilitate offensive cyber actions to disrupt cybercriminal groups, establishing the National Cyber Force (NCF) in 2020. In 2023, the UK government published principles for the NCF's use of these capabilities, stressing that such measures would be deployed sparingly, only when other responses are less effective.

cybersecurityoffensive cyber operationspublic-private partnershipcybercrimenational security
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.