The Trump administration is banning the acquisition of foreign-made components used to manage electricity and power, alleging that “certain foreign actors are increasingly creating and exploiting vulnerabilities” in the technology.

The White House has issued an executive order prohibiting the acquisition of foreign-made technology used in bulk-power systems, citing concerns over potential cyber backdoors and supply-chain vulnerabilities. The order, signed by President Donald Trump, declares that certain foreign actors are increasingly exploiting weaknesses in these systems, which manage electricity and power generation.
The executive order specifically targets technology for energy transmission lines rated at 69,000 volts or higher, as well as substations, control rooms, power generating stations, and reactors. It also encompasses associated software and firmware that could be remotely accessed or updated by foreign governments. The administration characterized foreign-made bulk-power system electric equipment as an "unusual and extraordinary threat" to the United States.
President Trump stated that during his first term, he identified the bulk-power system as a potential target for malicious acts, including cyber activities, due to the significant risks a successful attack would pose to the economy, public health and safety, and national defense.
The directive mandates that the Departments of Defense, Commerce, and Energy scrutinize transactions involving bulk-power system electric equipment. Federal agencies are also empowered to impose conditions on previously purchased equipment, provided that suitable replacements are available. A list of pre-qualified equipment and vendors is slated for publication.
Senior officials have 120 days to establish rules and regulations, and to identify countries that warrant particular scrutiny under the order's provisions. Agencies are also required to identify existing at-risk bulk-power system electric equipment and submit plans to the White House for its identification, inventory, isolation, monitoring, or replacement as soon as feasible.
While the White House did not specify the immediate catalyst for the executive order, it follows a series of reported cyberattacks on critical infrastructure. Last month, water utilities in at least 12 states experienced cyberattacks, and the federal cyber defense agency observed malicious activity targeting over 100 internet-exposed systems in the water and wastewater sector. Additionally, a small British power plant was reportedly shut down for four days by hackers.
The National Security Agency and FBI recently issued an advisory concerning an artificial intelligence-powered "active threat" to a specific brand of operational technology used across the energy, water, and agricultural sectors. Although no specific countries were officially blamed for these incidents, some experts have pointed to Iranian hackers. U.S. officials have previously attributed critical infrastructure attacks to Russian and Chinese hackers, with the FBI recently disrupting a Chinese botnet reportedly used to breach the Federal Reserve, NASA, and other federal agencies managing critical infrastructure.
Cybersecurity experts and government agencies have consistently warned about the deployment of artificial intelligence by state-backed hackers in attacks on critical infrastructure, which could simplify potentially devastating assaults. Following the executive order, major tech and finance companies, including OpenAI and Google, issued a joint warning that there is a "limited window to strengthen cyber defenses" before AI-enabled cyberattacks become "far more widespread and sophisticated." They emphasized that critical public services, from hospitals to water treatment plants, are at risk and that security teams for critical infrastructure have historically been under-resourced. These companies urged governments to coordinate cyber defense efforts at local, national, and international levels, and to enhance the sharing of actionable threat intelligence.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.