<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CyberScoop</title>
	<atom:link href="https://cyberscoop.com/feed/" rel="self" type="application/rss+xml" />
	<link>https://cyberscoop.com/</link>
	<description></description>
	<lastBuildDate>Wed, 16 Sep 2026 21:38:27 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1</generator>

<image>
	<url>https://cyberscoop.com/wp-content/uploads/sites/3/2023/01/cropped-cs_favicon-2.png?w=32</url>
	<title>CyberScoop</title>
	<link>https://cyberscoop.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>America&#8217;s cyber strategy overlooks the infrastructure that actually keeps the military moving</title>
		<link>https://cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/</link>
		
		<dc:creator><![CDATA[Greg Otto]]></dc:creator>
		<pubDate>Thu, 17 Sep 2026 10:00:00 +0000</pubDate>
				<category><![CDATA[Commentary]]></category>
		<category><![CDATA[CMMC]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[defense industrial base]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[op-ed]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90702</guid>

					<description><![CDATA[<p>Ports, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks.</p>
<p>The post <a href="https://cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/">America&#8217;s cyber strategy overlooks the infrastructure that actually keeps the military moving</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">There is little reason to believe the war with Iran will end anytime soon. Even as efforts to resolve the conflict continue, Iran remains unpredictable, with an enduring ability to disrupt shipping and energy markets via actions in the Strait of Hormuz.</p>



<p class="wp-block-paragraph">So what does a prolonged conflict mean for cybersecurity here at home? U.S. agencies need to prepare for sustained Iranian cyber operations and conduct defensive wargames now.</p>



<p class="wp-block-paragraph">I spent part of my career in Navy intelligence supporting expeditionary and special warfare operations. This experience taught me to look beyond individual attacks to the larger objectives they serve. Iran’s likely objectives are relatively straightforward: impose enough pain on <a href="https://cyberscoop.com/tag/critical-infrastructure/">critical infrastructure</a>, businesses, and public services to increase pressure on Washington, while disrupting the industrial and civilian systems that allow the U.S. to sustain military operations.</p>



<p class="wp-block-paragraph">Iran may not be a top-tier cyber power like China or Russia, but it doesn’t have to be. We recently mapped <a href="https://www.realcleardefense.com/articles/2026/03/24/how_prepared_is_the_defense_industrial_base_for_iranian_cyber_attacks_1172226.html" target="_blank" rel="noopener">130 documented attack techniques</a> used by five <a href="https://cyberscoop.com/tag/iran/">Iranian</a> threat groups. Much of their playbook relies on well-known, repeatable techniques rather than advanced capabilities. Success does not require extraordinary capabilities, only the ability to create enough disruption, uncertainty, and delay is enough.</p>



<p class="wp-block-paragraph">America’s greatest vulnerability may not be any single network or piece of critical infrastructure, but the links in between.&nbsp;</p>



<h4 id="h-critical-infrastructure-prepare-for-volume-not-just-catastrophe" class="wp-block-heading">Critical infrastructure: Prepare for volume, not just catastrophe</h4>



<p class="wp-block-paragraph">When Americans imagine a cyberattack on critical infrastructure, we tend to think of catastrophic events, such as a large-scale blackout, a poisoned <a href="https://cyberscoop.com/water-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed/">water supply</a>, or some other <a href="https://cyberscoop.com/cyber-pearl-harbor-911-cyberwar-hacking-leon-panetta-ciaran-martin/">digital Pearl Harbor</a>.</p>



<p class="wp-block-paragraph">But in an extended conflict, the more realistic possibility is persistent attacks across many targets. Small water systems, manufacturers, transportation providers, energy infrastructure, and local governments all serve as disruptive targets. The recent <a href="https://www.csis.org/analysis/mapping-iranian-cyberattacks-us-water-systems" target="_blank" rel="noopener">string of attacks</a> on mostly smaller water utilities across 12 states is a prime example; so too is the <a href="https://www.theguardian.com/world/2026/aug/23/iran-linked-hackers-blamed-cyber-attack-british-power-plant" target="_blank" rel="noopener">four-day outage</a> of a small-scale power plant in the UK.</p>



<p class="wp-block-paragraph">Attackers do not need to destroy these systems. Any intrusion that manipulates industrial systems, interrupts operations, or forces operators to determine whether equipment can still be trusted consumes valuable time and resources. Multiply that across dozens of organizations, and federal, state, local, and private-sector response capacity will be stretched thin.</p>



<p class="wp-block-paragraph">The cumulative strain on the country’s ability to respond may be more important than any single attack. Iran does not need the world’s most sophisticated cyber force if its affiliated hacking groups can generate problems faster than cyber defenders can investigate and remediate them.</p>



<h4 id="h-defense-contractors-must-prepare-for-destructive-attacks" class="wp-block-heading">Defense contractors must prepare for destructive attacks</h4>



<p class="wp-block-paragraph">Defense contractors have long faced espionage threats targeting military secrets.  While that threat <a href="https://cyberscoop.com/mabna-institute-iranian-hackers-indictment/" target="_blank" rel="noreferrer noopener">remains</a>, the war has significantly changed Iran’s motives and risk calculus.</p>



<p class="wp-block-paragraph">The same access used to steal information from the <a href="https://cyberscoop.com/tag/defense-industrial-base/">defense industrial base</a> (DIB) can also be used to destroy data and disrupt operations. Destructive malware such as wipers and <a href="https://cyberscoop.com/tag/ransomware/">ransomware</a> could destroy engineering files, disable production systems or force manufacturers offline, directly affecting the military’s ability to replenish equipment and supplies.</p>



<p class="wp-block-paragraph">An attacker does not have to shut down production to disrupt it. Consider a compromised calibration setting, altered test result, or unauthorized change to engineering data. Discovering that an adversary had persistent access to a manufacturing environment raises difficult questions: Which files were touched? Which designs can still be trusted? Which components were manufactured from them?</p>



<p class="wp-block-paragraph">The incident quickly becomes a production problem as parts must be quarantined, engineering data re-validated, and products retested.</p>



<p class="wp-block-paragraph">NIST SP 800-171 and <a href="https://defensescoop.com/tag/cmmc/">CMMC</a> provide an essential security baseline, which makes the current pause in CMMC implementation particularly concerning. However, contractors must also be prepared to operate through destructive attacks and establish that their systems, data, and products can still be trusted. This preparedness must extend down the supply chain, where a smaller manufacturer, software provider, or managed service provider may present a greater vulnerability than a well-defended prime.</p>



<h4 id="h-the-military-attack-surface-extends-far-beyond-dod-networks" class="wp-block-heading">The military attack surface extends far beyond DoD networks</h4>



<p class="wp-block-paragraph">The U.S. military is extraordinarily capable at defending its own networks, but its operations depend on infrastructure it doesn’t own or control. Troops and equipment move on commercial railroads, materiel flows through commercial ports, and military airlift can depend on commercial carriers. Military installations and defense contractors also depend on commercial power, telecommunications, and other infrastructure.</p>



<p class="wp-block-paragraph">In an ongoing conflict, those dependencies become part of the attack surface. An adversary like Iran does not have to penetrate military command-and-control to interfere with these operations. At a time when speed matters most, cyberattacks that disrupt port scheduling, corrupt logistics information, or degrade power and communications can introduce critical delays and uncertainty that hamper operations.</p>



<p class="wp-block-paragraph">This is why the line between civilian and military infrastructure becomes blurred during a conflict. A commercial railroad carrying military equipment to a strategic port may be civilian infrastructure administratively, but operationally it is part of the nation’s ability to operate its military power. The same is true of the utilities, communications providers, and other civilian infrastructure supporting military installations and defense production. Their resilience can quickly become a matter of military readiness.</p>



<h4 id="h-cyber-defense-must-cross-organizational-boundaries" class="wp-block-heading">Cyber defense must cross organizational boundaries</h4>



<p class="wp-block-paragraph">American cybersecurity is organized around sectors, organizations, and authorities that make administrative sense, but aren’t necessarily designed for wartime. The boundaries between them can become a serious liability.</p>



<p class="wp-block-paragraph">Our adversaries in Tehran do not care about administrative boundaries. They care about weak spots. A vulnerability anywhere in the chain connecting civilian infrastructure, industrial production, transportation, communications, and military operations can affect everything downstream.</p>



<p class="wp-block-paragraph">We need to ask: Who is responsible for the cyber resilience of a commercial railroad essential to a military deployment? Who ensures the utility serving a critical defense manufacturer can withstand a sustained nation-state campaign? Who identifies the supplier whose failure could disrupt multiple defense programs? And who coordinates the response when several are attacked simultaneously?</p>



<p class="wp-block-paragraph">Those questions should shape how we prepare. Critical infrastructure exercises should assume simultaneous incidents across multiple sectors and regions. We should also be extremely cautious about weakening the incentives driving cybersecurity improvements across the DIB, such as the current pause on CMMC. Additionally, defense manufacturers should also test their ability to operate through destructive attacks and determine whether their engineering data, production systems, and finished products can still be trusted.</p>



<p class="wp-block-paragraph">DoD exercises should treat civilian infrastructure, including rail, ports, energy, and communications, as a routine part of the operating environment and an attractive target for adversaries. Catastrophic scenarios deserve attention, but exercises should also account for lower-level attacks that are less spectacular but still highly consequential.</p>



<p class="wp-block-paragraph">Iran does not need overwhelming cyber capability to impose significant costs. Persistent disruption at home can increase political and economic pressure surrounding the war, while disruption of defense production and military logistics can make it harder for the U.S. to sustain operations abroad.</p>



<p class="wp-block-paragraph">We have spent years strengthening the individual pieces of America’s cyber defenses. A prolonged war with Iran may test the links between them.</p>
<p>The post <a href="https://cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/">America&#8217;s cyber strategy overlooks the infrastructure that actually keeps the military moving</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90702</post-id>	</item>
		<item>
		<title>CISA promotes a fresh way to deter cyberattackers: Lie to them</title>
		<link>https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/</link>
		
		<dc:creator><![CDATA[Tim Starks]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 20:22:03 +0000</pubDate>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[assume compromise]]></category>
		<category><![CDATA[Chris Butera]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[Cybersecurity and Infrastructure Security Agency (CISA)]]></category>
		<category><![CDATA[decoys]]></category>
		<category><![CDATA[honeypots]]></category>
		<category><![CDATA[zero trust]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90695</guid>

					<description><![CDATA[<p>It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries.</p>
<p>The post <a href="https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/">CISA promotes a fresh way to deter cyberattackers: Lie to them</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems, accounts and data to deceive would-be hackers into being distracted and discovered.</p>



<p class="wp-block-paragraph">The Wednesday guidance, “Using Cyber Decoys to Strengthen Detection and Response,” arose from internal discussions with CISA’s threat hunters and penetration testers about how decoys can be a cheap, effective way to disrupt attackers, said Chris Butera, acting executive director of the cybersecurity division.</p>



<p class="wp-block-paragraph">‘We&#8217;ve been looking at it for a while, and we believe that decoys can be both a very low-cost but actually high-fidelity way to detect an adversary who&#8217;s already gained access to networks,” Butera told CyberScoop at Google Cloud’s Cyber Defense Summit 26.</p>



<p class="wp-block-paragraph">It’s especially complementary for zero-trust (maintaining that no user or device is trustworthy by default) and assume-compromise (assuming that hackers have already gotten into a network) approaches, Butera said.</p>



<p class="wp-block-paragraph">While the guidance is “really relevant for everyone,” it’s something that can be especially useful in critical infrastructure sectors that don’t have the most personnel or money, he said.</p>



<p class="wp-block-paragraph">“This could be something to prioritize as a lower cost solution,” Butera said. “You can create your own honey tokens yourself.”</p>



<p class="wp-block-paragraph">The 22-page guidance includes decoy principles and goals, definitions of the different kinds of decoys and how to use them and scenarios for deployment.</p>



<p class="wp-block-paragraph">Honeytokens, for instance, are “Data elements or logical objects with no legitimate business use (e.g., fake records, credentials, or files) planted to detect unauthorized access or exfiltration. Any interaction strongly suggests malicious or otherwise unauthorized activity.”</p>



<p class="wp-block-paragraph">“Cyber decoys used in a proactive cyber defense strategy help make critical infrastructure networks unfriendly places for adversaries and enhance resilience to compromise, even against living-off-the-land techniques,” Butera said in a news release. “With this guide, CISA is raising awareness of cyber decoy techniques and enabling any defensive team regardless of skill level to understand the value and steps to implementing decoy operations. CISA encourages critical infrastructure organizations to review this guide and implement a cyber decoy strategy.”&nbsp;</p>
<p>The post <a href="https://cyberscoop.com/cisa-guidance-cyber-decoys-critical-infrastructure/">CISA promotes a fresh way to deter cyberattackers: Lie to them</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90695</post-id>	</item>
		<item>
		<title>Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks</title>
		<link>https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks/</link>
		
		<dc:creator><![CDATA[Tim Starks]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 14:48:07 +0000</pubDate>
				<category><![CDATA[Geopolitics]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Biden administration]]></category>
		<category><![CDATA[energy]]></category>
		<category><![CDATA[Federal Bureau of Investigation (FBI)]]></category>
		<category><![CDATA[gas]]></category>
		<category><![CDATA[Iran]]></category>
		<category><![CDATA[Maritime]]></category>
		<category><![CDATA[maritime cybersecurity]]></category>
		<category><![CDATA[oil]]></category>
		<category><![CDATA[U.S. Coast Guard]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90689</guid>

					<description><![CDATA[<p>The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.”</p>
<p>The post <a href="https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks/">Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint statement from the agencies Wednesday.</p>



<p class="wp-block-paragraph">The “joint offshore security boardings” of the two commercial ships in the Gulf of Mexico on Aug. 21 and Aug. 24 “were designed to ensure integrity of the vessel’s operational and information technology systems following indications that the networks of both vessels were compromised,” according to the joint statement.</p>



<p class="wp-block-paragraph">“Currently, there are no reports of operational disruptions, vessel instability, physical danger to crews, or environmental impacts,” the statement reads. “The Coast Guard is actively managing communications with port operators, vessel owners, and local maritime stakeholders to ensure port operations continue safely and without interruption.”</p>



<p class="wp-block-paragraph"><a href="https://www.wsj.com/politics/national-security/u-s-probes-cyberattacks-on-energy-tankers-bound-for-american-coast-33d92f3a">The vessels</a> were reportedly tankers <a href="https://www.bloomberg.com/news/articles/2026-09-15/us-coast-guard-boards-oil-tanker-in-cyber-attack-investigation">carrying oil and natural gas</a>, and the first <a href="https://abcnews.com/Politics/coast-guard-fbi-investigating-after-2-oil-tankers/story?id=136482324">got hacked</a> in the Strait of Gibraltar and lost communication for over 30 hours. Authorities were said to be&nbsp; investigating whether Iran, or perhaps another group seeking to exploit the conflict between Iran and the United States, was behind the attacks.</p>



<p class="wp-block-paragraph">Coast Guard cyber teams have been investigating “dark fleets” carrying sanctioned oil from Iran and Russia, which rely on digital masking to hide their operations and carry enhanced cyber risks, The Wall Street Journal <a href="https://www.wsj.com/articles/the-dangerous-tech-found-aboard-dark-fleet-tankers-captured-by-the-u-s-34762a3a?mod=article_inline">reported in June</a>.</p>



<p class="wp-block-paragraph">Then-President Joe Biden signed <a href="https://cyberscoop.com/biden-executive-order-coast-guard-cyber/">an executive order</a> in 2024 giving the Coast Guard additional authorities to respond to cybersecurity incidents, citing the risks that a maritime cyber incident could cause “cascading” harm to the global supply chain.</p>



<p class="wp-block-paragraph">The Aug. 21 boarding party included Coast Guard law enforcement personnel, Coast Guard Cyber Protection Team members, a vessel inspector and FBI Cyber Action Team operators, who boarded “to conduct a comprehensive cyber security boarding and investigation,” according to the agencies’ joint statement. A similar team made up the Aug. 24 boarding party.</p>



<p class="wp-block-paragraph">“The captain, crew, and shore-side corporate staff were critical partners in helping to ensure the threats were mitigated,” the statement reads.</p>



<p class="wp-block-paragraph">Top Trump administration cyber officials have refused to answer questions from reporters recently about Iranian cyberattacks during the Middle East conflict. <a href="https://cyberscoop.com/trump-blames-minnesota-water-cyberattacks-iran/">Trump himself has rejected</a> the idea that Iran was behind a recent spate of attacks on U.S. water facilities.</p>
<p>The post <a href="https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks/">Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90689</post-id>	</item>
		<item>
		<title>Treasury’s Scott Bessent says no liability exemptions for AI labs</title>
		<link>https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions/</link>
		
		<dc:creator><![CDATA[Greg Otto]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 14:10:19 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90684</guid>

					<description><![CDATA[<p>The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.”</p>
<p>The post <a href="https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions/">Treasury’s Scott Bessent says no liability exemptions for AI labs</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The post <a href="https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions/">Treasury’s Scott Bessent says no liability exemptions for AI labs</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90684</post-id>	</item>
		<item>
		<title>What’s next for CISA&#8217;s CDM program that gives cybersecurity tools to federal agencies</title>
		<link>https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/</link>
		
		<dc:creator><![CDATA[Tim Starks]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 19:45:35 +0000</pubDate>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[continuous diagnostics and mitigation]]></category>
		<category><![CDATA[Cybersecurity and Infrastructure Security Agency (CISA)]]></category>
		<category><![CDATA[Federal CISO]]></category>
		<category><![CDATA[Federal IT]]></category>
		<category><![CDATA[Mike Duffy]]></category>
		<category><![CDATA[security information and event management (SIEM)]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90680</guid>

					<description><![CDATA[<p>Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned.</p>
<p>The post <a href="https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/">What’s next for CISA&#8217;s CDM program that gives cybersecurity tools to federal agencies</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">A Cybersecurity and Infrastructure Security Agency program that provides tools and capabilities to other agencies has to get speedier so it can push them toward being able to move more quickly themselves, an agency official said Tuesday.</p>



<p class="wp-block-paragraph">“We have to get faster,” said Richard Grabowski, acting branch chief of service delivery and deputy program manager for the <a href="https://cyberscoop.com/tag/continuous-diagnostics-and-mitigation/">Continuous Diagnostics and Mitigation</a> program at CISA. “The way that we collaborated today wasn&#8217;t fast enough for the threats of yesterday, and they certainly aren&#8217;t going to be fast enough for the threats of tomorrow.”</p>



<p class="wp-block-paragraph">That means pushing responsible automation of tasks that also can do so at scale, he said, so that experts “can focus more [on] dealing with the novel threats and adoption and tuning of advanced technology, and not hitting alerts every other day.”</p>



<p class="wp-block-paragraph">Velocity is one of the three core goals for the CDM program, along with unification and data-driven risk management, Grabowski said at the Elastic Federal Cyber Defense Breakfast, produced by FedScoop.</p>



<p class="wp-block-paragraph">Unification means keeping data out of silos so “we are connecting those deployments in a meaningful way to really stimulate reusable, actionable lessons learned,” Grabowski said. And data-driven risk management means that in the event of a crisis-level event, agencies are able to “see what is happening with timely, accurate, and trustworthy data, so that we are the tool of first response when the things hit the fan.”</p>



<p class="wp-block-paragraph">One of CDM’s offerings is Security Information and Event Management (SIEM) as a Service, a cloud-based platform for threat analytics, incident response and more. Grabowski said there’s a three-year roadmap for expanding and enhancing it, including by ramping up staff and conducting training.</p>



<p class="wp-block-paragraph">Mike Duffy, the acting federal chief information security officer, said at the same event that three principles should guide what comes next for CDM. One is aggregating demand across agencies that share common problems: &#8220;When agencies need the same capabilities, we should use federal scale to improve security, interoperability and value.&#8221;</p>



<p class="wp-block-paragraph">Second, he said, &#8220;is buying outcomes, not product&#8221; by making it clear what outcomes the federal government is seeking and then allowing commercial markets room to innovate.&nbsp;</p>



<p class="wp-block-paragraph">Duffy said the third was to &#8220;design acquisition for continuous improvement,&#8221; meaning making sure that acquisition models promote competition and opportunities for new capabilities to enter.</p>



<p class="wp-block-paragraph">“Now is not the time to set capabilities and move on for the next 10 years,” he said. “Mow that agile mindset of how we can continue to deliver and deploy capabilities based on the threats we&#8217;re seeing to reduce risk at scale across the federal government — that is absolutely key.”</p>



<p class="wp-block-paragraph">CDM has been evolving since the <a href="https://cyberscoop.com/tag/solarwinds/">SolarWinds breach</a> that compromised at least nine federal agencies, said Matt House, CISA’s acting associate director and program manager for CDM.</p>



<p class="wp-block-paragraph">“Post-SolarWinds, one of the things that that the government took away was, we lack what I would say is a common operating picture with respect to the operational visibility we need to be able to assess and coordinate response government wide,” House said at the event.</p>
<p>The post <a href="https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/">What’s next for CISA&#8217;s CDM program that gives cybersecurity tools to federal agencies</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90680</post-id>	</item>
		<item>
		<title>Cisco warns customers of actively exploited zero-day in email gateways</title>
		<link>https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/</link>
		
		<dc:creator><![CDATA[Matt Kapko]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 15:44:41 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Threats]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cybersecurity and Infrastructure Security Agency (CISA)]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[vulnerability disclosure]]></category>
		<category><![CDATA[zero-day]]></category>
		<category><![CDATA[zero-day exploit]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90678</guid>

					<description><![CDATA[<p>The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base. </p>
<p>The post <a href="https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/">Cisco warns customers of actively exploited zero-day in email gateways</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Attackers of unknown origins and motivations are exploiting a critical zero-day vulnerability in Cisco Secure Email Gateway, authorities and researchers said Monday.</p>



<p class="wp-block-paragraph">The vulnerability — <a href="https://nvd.nist.gov/vuln/detail/cve-2026-76461">CVE-2026-76461</a> —&nbsp; was exploited before <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX">Cisco disclosed and patched the defect</a> Monday and allows unauthenticated, remote attackers to execute commands with root privileges on vulnerable systems. “In practical terms, that gives the attacker control of the gateway itself,” Douglas McKee, director of vulnerability intelligence at Rapid7, told CyberScoop.</p>



<p class="wp-block-paragraph">Cisco said its product security incident response team became aware of active exploitation of the defect affecting Cisco AsyncOS Software for Cisco Secure Email Gateway in September. When asked for further details, a company spokesperson pointed to the advisory and reiterated that the company is aware of active exploitation of the vulnerability.</p>



<p class="wp-block-paragraph">The company did not say how many organizations are impacted for active exploitation thus far, but it indicated multiple customers were likely compromised prior to disclosure.&nbsp;</p>



<p class="wp-block-paragraph">“Cisco has conducted a thorough threat intelligence investigation on devices that belong to Cisco Secure Email Cloud. Cisco has directly contacted customers who own Cisco Secure Email Cloud devices where indicators of possible compromise were identified,” the company wrote in its security advisory. “Cisco is engaged in remediation and recovery operations. Cisco has already deployed mitigations that are within Cisco&#8217;s management.”</p>



<p class="wp-block-paragraph">The Cybersecurity and Infrastructure Security Agency added the zero-day, which affects cloud-based and on-premises instances of Cisco Secure Email Gateway, to its known exploited vulnerabilities catalog shortly after Cisco’s disclosure.&nbsp;</p>



<p class="wp-block-paragraph">The tight timeline between Cisco’s public advisory and patch guidance, and CISA’s quick addition to the KEV catalog indicates the vulnerability deserves immediate attention, McKee said.&nbsp;</p>



<p class="wp-block-paragraph">“The combination here is pretty ugly. No authentication is required, an attacker can reach the vulnerable code by sending an email through the appliance, successful exploitation can result in root-level command execution, and Cisco has observed exploitation in the wild,” he added.</p>



<p class="wp-block-paragraph">Researchers at Rapid7 and VulnCheck said they don’t yet know how many organizations are impacted by active exploits, but they encouraged Cisco customers to patch and hunt for potential signs of compromise as soon as possible.&nbsp;</p>



<p class="wp-block-paragraph">Spencer McIntyre, director of exploit development at VulnCheck, told CyberScoop the exploit could allow an attacker to maintain access to the email gateway and monitor communications. “Stealing or silently snooping on email comms is a common tactic for state-sponsored and other threat actors conducting espionage operations,” he said.&nbsp;</p>



<p class="wp-block-paragraph">“It&#8217;s going to be worse for organizations that have the appliance deployed on-premises. In this case, the attacker could pivot internally,” McIntyre added. “If, however, organizations use a cloud instance, the compromised gateway is less likely to have significant access to internal organizational resources.”</p>



<p class="wp-block-paragraph">Cisco released indicators of compromise to help customers hunt for attempted exploitation in their environments, but the company added that attackers could remove or hide those traces with the level of access granted via exploitation.</p>
<p>The post <a href="https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/">Cisco warns customers of actively exploited zero-day in email gateways</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90678</post-id>	</item>
		<item>
		<title>Supreme Court denies Trump request to allow USPS mail ballot changes</title>
		<link>https://cyberscoop.com/supreme-court-denies-trump-usps-mail-ballot-changes/</link>
		
		<dc:creator><![CDATA[djohnson]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 02:15:47 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Election Security]]></category>
		<category><![CDATA[Government]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[election]]></category>
		<category><![CDATA[election security]]></category>
		<category><![CDATA[Executive order]]></category>
		<category><![CDATA[lawsuit]]></category>
		<category><![CDATA[mail-in voting]]></category>
		<category><![CDATA[Supreme Court]]></category>
		<category><![CDATA[Trump administration]]></category>
		<category><![CDATA[U.S. Postal Service]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90673</guid>

					<description><![CDATA[<p>One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act.</p>
<p>The post <a href="https://cyberscoop.com/supreme-court-denies-trump-usps-mail-ballot-changes/">Supreme Court denies Trump request to allow USPS mail ballot changes</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The Supreme Court has rejected a petition by the Trump administration to implement changes to the way the U.S. Postal Service handles mail-in ballots for the upcoming 2026 midterm elections, calling it “arbitrary and capricious.”</p>



<p class="wp-block-paragraph">The 7-2 <a href="https://www.supremecourt.gov/DocketPDF/26/26A305/423226/20260906094442523_USPS%20v.%20State%20of%20California%20PI%20No.%2026A%20-%20Stay%20App.pdf">decision</a> was handed down Monday with little explanation by the court. Writing for the majority, Justice Kentaji Brown Jackson said the administration “is unlikely to succeed on the merits of its challenge to the District Court’s preliminary injunction” and had failed to articulate a valid reason for seeking emergency relief from the court.</p>



<p class="wp-block-paragraph">However, in a concurring statement, Justice Brett Kavanaugh said he believed there was “a fair prospect” that the final USPS final regulation would be within their legal authority and appeared to cite unreasonably short timelines imposed on states and his primary reason for denying the stay.</p>



<p class="wp-block-paragraph">“But applying the rule in the 2026 elections would be arbitrary and capricious and in violation of the Administrative Procedures Act because state and local election officials do not have sufficient time to reasonably implement the rule before the elections,” wrote Kavanaugh.</p>



<p class="wp-block-paragraph">The executive order <a href="https://cyberscoop.com/white-house-elections-executive-order-limits-mail-voting-creates-federal-voter-lists/">would have</a> tasked the USPS with verifying  voter citizenship and the validating ballot materials. The order would have created a barcode tracking system for mail ballot envelopes and “State Citizenship Lists” compiled by the Department of Homeland Security.</p>



<p class="wp-block-paragraph">The order was quickly challenged by states and voting rights organizations, who argued the executive branch had no constitutional authority to dictate how they maintained their voter rolls.</p>



<p class="wp-block-paragraph">The White House has justified the order by claiming the federal government has “an unavoidable duty” under Article II of the Constitution to maintain confidence in election outcomes by preventing violations of criminal law, including noncitizen voting.</p>



<p class="wp-block-paragraph">Lower courts disagreed, <a href="https://cyberscoop.com/federal-judge-blocks-trump-mail-in-voting-executive-order/">blocking the executive order</a> from being put in place before November. The petition to the Supreme Court represented the administration’s best and final hope for judicial relief.</p>



<p class="wp-block-paragraph">As the administration fought the matter in courts, it <a href="https://cyberscoop.com/postal-service-finalizes-mail-in-ballot-rules-before-scotus-ruling/">moved ahead</a> finalizing the USPS rule. A whistleblower complaint <a href="https://cyberscoop.com/usps-whistleblower-ballot-system-2026-midterms/">alleged</a> that a “rushed” effort by the White House and U.S. Postal Service to install three new restrictive IT systems meant to verify citizenship that could potentially deny thousands of mail-in ballots if the federal government disagrees with states on a voter or ballot’s eligibility.</p>



<p class="wp-block-paragraph">While Jackson and Kavanaugh’s rationale took up less than half a page, a dissenting opinion written by Justice Samuel Alito and signed by Justice Clarence Thomas was more than 7 pages long.</p>



<p class="wp-block-paragraph">Alito wrote that he would have granted the Trump administration their request for a stay, allowing the order to be implemented in time for the 2026 elections. He said states and organizations suing the government lacked standing, and dismissed their concerns that implementing the USPS order ahead of the 2026 elections would thwart their ability to educate voters about mail-in voting, calling them “abstract social interests.”</p>



<p class="wp-block-paragraph">Ahead of the decision, David Becker, executive director of the nonprofit Center for Election Integrity and Research, told reporters that he doubted members of the Supreme Court majority “want to own the chaos that would ensure” as the USPS, states and voters attempt to navigate changes put in place just months before elections and after many states have begun sending out ballots that do not comply with the proposed rules.</p>



<p class="wp-block-paragraph">He also said that it would be in line with previous Supreme Court decisions that have recognized state supremacy when it comes to specific election administration authorities, like where and how their citizens vote.</p>



<p class="wp-block-paragraph">“When they consider issues related to the administration of elections, the casting and counting of ballots, they have sided with the states every time,” said Becker.</p>
<p>The post <a href="https://cyberscoop.com/supreme-court-denies-trump-usps-mail-ballot-changes/">Supreme Court denies Trump request to allow USPS mail ballot changes</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90673</post-id>	</item>
		<item>
		<title>Five alleged leaders of Black Axe’s operations in South Africa extradited to US</title>
		<link>https://cyberscoop.com/black-axe-south-africa-leaders-extradited/</link>
		
		<dc:creator><![CDATA[Matt Kapko]]></dc:creator>
		<pubDate>Mon, 14 Sep 2026 18:37:44 +0000</pubDate>
				<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Black Axe]]></category>
		<category><![CDATA[cybercrime]]></category>
		<category><![CDATA[Department of Justice (DOJ)]]></category>
		<category><![CDATA[Federal Bureau of Investigation (FBI)]]></category>
		<category><![CDATA[Justice Department]]></category>
		<category><![CDATA[Nigeria]]></category>
		<category><![CDATA[romance scams]]></category>
		<category><![CDATA[Social engineering]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90671</guid>

					<description><![CDATA[<p>Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money.</p>
<p>The post <a href="https://cyberscoop.com/black-axe-south-africa-leaders-extradited/">Five alleged leaders of Black Axe’s operations in South Africa extradited to US</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Five alleged leaders of the South African wing of Black Axe, a global cybercrime group with operations spanning dozens of countries, were <a href="https://www.justice.gov/usao-nj/pr/five-prominent-black-axe-members-extradited-conspiring-engage-internet-scams-and-money">extradited to the United States</a> Friday to face multiple charges, the Justice Department said.</p>



<p class="wp-block-paragraph">Officials accuse the five people, all originally from Nigeria, of running romance scams and advance fee scams from at least 2011 until they were all arrested in South Africa in 2021. The defendants were due Monday for initial court appearances and arraignments in a federal court in Trenton, N.J.</p>



<p class="wp-block-paragraph">&#8220;Black Axe is a notoriously violent transnational criminal organization that also happens to dabble in romance scams to make money,” Stefanie Roddy, special agent in charge of the FBI Newark field office, said in a statement. “The ability of FBI Newark and our partner agencies to reach into South Africa illustrates our resolve to hold accountable any and every type of fraudster who preys on innocent victims here in the United States.”</p>



<p class="wp-block-paragraph">The accused include Perry Osagiede, founder and leader of the Cape Town Zone of Black Axe; Franklyn Edosa Osagiede, the zone’s “chief ihaza” Osariemen Eric Clement, “assistant eye of the zone,” Collins Owhofasa Otughwor, the zone’s “chief eye,” and Musa Mudashiru, one of the group’s “assistant butchers.”</p>



<p class="wp-block-paragraph">Prosecutors said the five defendants and their co-conspirators used fake identities to pose as a love interest, relatives, business partners or friends to trick victims into sending them money.</p>



<p class="wp-block-paragraph">Many of the scams involved claims that the alleged cybercriminals needed money for work travel or to hold them over financially following a series of unfortunate events. This included requests for loans, often involving issues with a construction site, delayed inheritance, or expensive health costs for claimed relatives, according to an unsealed indictment filed in the U.S. District Court of New Jersey in 2021.&nbsp;</p>



<p class="wp-block-paragraph">Prosecutors said the co-conspirators also used business entities and gained access to the financial accounts of some victims to conceal the funds illegally obtained from other victims. In some cases, the alleged Black Axe members threatened to distribute sensitive photos of victims when they hesitated to send money, officials added.</p>



<p class="wp-block-paragraph">The extradition follows a heightened period of law enforcement activity targeting Black Axe in multiple countries.&nbsp;</p>



<p class="wp-block-paragraph">Authorities <a href="https://cyberscoop.com/black-axe-disruption-arrests-spain/">arrested 34 alleged cybercriminals in Spain</a>, including some Black Axe leaders, for adversary-in-the-middle scams such as business email compromise, money laundering and vehicle trafficking in January.&nbsp;</p>



<p class="wp-block-paragraph">Officials seized millions in assets, arrested 58 individuals and identified 263 suspects, including members of Black Axe, in a <a href="https://cyberscoop.com/interpol-operation-jackal-iv-black-axe-arrests/">multi-country sting operation</a> in August.&nbsp;</p>



<p class="wp-block-paragraph">Black Axe is a highly structured, hierarchical group that generates billions of dollars in criminal proceeds annually from many small-scale operations spanning dozens of countries.&nbsp;</p>



<p class="wp-block-paragraph">All five of the extradited individuals are charged with conspiracy to commit wire fraud and money laundering. Perry Osagiede and Franklyn Osagiede are also charged with wire fraud and aggravated identity theft. Officials also charged Clement with wire fraud and Otughwor with aggravated identity theft. The combined charges carry up to 62 years in prison.&nbsp;</p>



<p class="wp-block-paragraph">“This case reflects the result of a years-long effort by the U.S. Secret Service and our law enforcement partners to identify, investigate, and bring to justice those who allegedly preyed on victims through sophisticated online fraud and money laundering schemes,” Craig Marech, special agent in charge of the U.S. Secret Service’s Newark field office, said in a statement.&nbsp;</p>



<p class="wp-block-paragraph">The Justice Department published additional information about the <a href="https://www.justice.gov/usao-nj/blackaxe">Cape Town Zone wing of Black Axe</a>, including multiple aliases and business entities used by the group’s members, and encouraged potential victims to contact the FBI.</p>
<p>The post <a href="https://cyberscoop.com/black-axe-south-africa-leaders-extradited/">Five alleged leaders of Black Axe’s operations in South Africa extradited to US</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90671</post-id>	</item>
		<item>
		<title>Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems</title>
		<link>https://cyberscoop.com/openai-agents-malicious-rubygems-packages/</link>
		
		<dc:creator><![CDATA[djohnson]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 01:50:30 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Agentic AI]]></category>
		<category><![CDATA[AI hacking]]></category>
		<category><![CDATA[Artificial Intelligence (AI)]]></category>
		<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[RubyGems]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90664</guid>

					<description><![CDATA[<p>OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages.</p>
<p>The post <a href="https://cyberscoop.com/openai-agents-malicious-rubygems-packages/">Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Researchers say they have discovered thousands of malicious software packages uploaded to an online public software repository that were left by a “swarm” of OpenAI agents.</p>



<p class="wp-block-paragraph">According to an incident timeline <a href="https://www.rubyhack.ai/">published</a> Friday by researchers Spencer Kitts, Thomas Larsen and Sydney Von Arx, the campaign began May 5 when they observed a handful of suspicious packages being uploaded to RubyGems, a public library for the Ruby programming language. By May 11 and 12, the site saw more than 2,000 malicious uploads from the same actors before RubyGems maintainers halted new user sign-ups for four days to stop the flow.</p>



<p class="wp-block-paragraph">In one instance, the agents attempted to exploit a very recent vulnerability that had only been discovered this past July that would have given them access to RubyGem user API keys. According to Colby Swandale, the technical lead at RubyGems, the flaw involved <a href="https://blog.rubygems.org/2026/07/22/security-advisory-legacy-api-key-leak.html">an improper cache configuration</a>. While initial access logs showed no evidence of malicious key use, Swandale acknowledged the review was limited in scope and inconclusive.&nbsp;</p>



<p class="wp-block-paragraph">According to the report published Friday, the agents also used “disposable” email addresses and exploited another bug in RubyGems platform (since patched) that allowed them to register new accounts and gain API keys without verifying their email address.</p>



<p class="wp-block-paragraph">The researchers said their understanding, based on discussions with “people in the RubyGems community,” is that OpenAI had yet to disclose the involvement of their agents in the May campaign.</p>



<p class="wp-block-paragraph">An OpenAI spokesperson told CyberScoop that the company is aware of the incident and said they were in contact with both the researchers and RubyGems to conduct a broader review. The company characterized the episode as “benign,” describing it as routine training runs where agents attempt to access publicly available data.</p>



<p class="wp-block-paragraph">“Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information,” the spokesperson said. “We’ll continue to investigate as part of our broader review of agent activity during training and evaluation.”</p>



<p class="wp-block-paragraph">In many ways, the agents were not subtle about their identities or goals.</p>



<p class="wp-block-paragraph">Days into the campaign, researchers noticed that some of the packages had “oai” in their filenames, while fifteen of them had “oai” set as their author and another listed the email “openaixyz65947@gmail.com” as their point of contact.</p>



<p class="wp-block-paragraph">They also “clearly regarded what they were doing as hacking,” naming some of their files “hack.rb,” “evil.rb,” “inject.rb” and “exploit.rb.” Other packages were given names like “pwnp999,” “exfiltestwand3,” and “hacksvn,” and comments referring to things like a “malicious probe” or “#hack” are present through the files.</p>



<p class="wp-block-paragraph">They also said the actors’ behavior was extremely similar to another incident revealed earlier this month where OpenAI agents flooded a German wiki&nbsp; with thousands of hacking-related posts. OpenAI has confirmed their agents were involved in that incident.</p>



<p class="wp-block-paragraph">The RubyGems campaign used some of the same retrieval methods as the German Wiki agents, while thousands of malicious packages uploaded included a similar snippet, r.jini.ai, that was contained in the German posts.</p>



<p class="wp-block-paragraph">Cybersecurity company Socket first flagged the campaign in a threat intelligence report posted May 13, but it does not mention or attribute any of the activity to OpenAI or AI agents.</p>



<p class="wp-block-paragraph">However, the researchers said they had only limited visibility over the model’s actions and how successful some of them were, noting only OpenAI had the full details.</p>



<p class="wp-block-paragraph">“This analysis is entirely based on the publicly available RubyGems packages uploaded by these agents,” the researchers wrote. “However, we do not have access to the rest of the AI behavior, in particular the chain-of-thought produced by the model during the incident, which is internal to OpenAI. Therefore, we do not know why the AI agents chose this strategy or whether it was successful.”</p>



<p class="wp-block-paragraph">OpenAI’s spokesperson told CyberScoop that to date, they have not been able to verify the specific claims about malicious packages or exploitation detailed in the report and are continuing to investigate.</p>
<p>The post <a href="https://cyberscoop.com/openai-agents-malicious-rubygems-packages/">Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90664</post-id>	</item>
		<item>
		<title>Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal</title>
		<link>https://cyberscoop.com/dot-rule-airline-cyberattack-flight-delays/</link>
		
		<dc:creator><![CDATA[Tim Starks]]></dc:creator>
		<pubDate>Fri, 11 Sep 2026 21:26:23 +0000</pubDate>
				<category><![CDATA[Government]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Transportation]]></category>
		<category><![CDATA[aviation]]></category>
		<category><![CDATA[Crowell & Moring]]></category>
		<category><![CDATA[Department of Transportation]]></category>
		<category><![CDATA[Federal Aviation Administration]]></category>
		<category><![CDATA[FlyersRights]]></category>
		<category><![CDATA[National Consumers League]]></category>
		<category><![CDATA[regulation]]></category>
		<guid isPermaLink="false">https://cyberscoop.com/?p=90656</guid>

					<description><![CDATA[<p>A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack.</p>
<p>The post <a href="https://cyberscoop.com/dot-rule-airline-cyberattack-flight-delays/">Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Beginning next month, if a flight is canceled or delayed because of a cyberattack, feds will give airlines clearance not to hand out meal vouchers or hotels.</p>



<p class="wp-block-paragraph">The change is the result of a broader rule the Transportation Department <a href="https://www.federalregister.gov/documents/2026/09/03/2026-18040/cause-of-airline-delay-and-cancellation-categories-under-section-511b-of-the-faa-reauthorization-act">published last week</a> that establishes a new “cause of delay” category for tracking information, but that also reduces air carrier responsibilities to customers for 10 kinds of events. Among them: “cybersecurity attacks (provided that the air carrier is in compliance with applicable cybersecurity regulations).”</p>



<p class="wp-block-paragraph">The 10 events, including those cyberattacks, are deemed “not controllable,” meaning that “carriers are no longer obligated under [customer service] plans to provide amenities or compensation when disruptions arise from these specific causes,” as Sophie Hayashi, counsel at Crowell &amp; Moring in the transportation group, wrote in a <a href="https://www.crowell.com/en/insights/client-alerts/DOT-Final-Rule-Narrows-Airline-Delay-and-Cancellation-Reporting-Obligation-Under-FAA-Reauthorization-Act-of-2024">client alert</a>.</p>



<p class="wp-block-paragraph">Those airline-authored customer service plans aren’t legally binding, although DOT has maintained it will <a href="https://www.transportation.gov/airconsumer/airline-customer-service-dashboard">hold airlines “accountable”</a> for their pledges.</p>



<p class="wp-block-paragraph">One airline consumer advocacy organization, FlyersRights, was skeptical of the change, saying it came without giving the public a chance to comment and that it would be monitoring the impact on airline customers and tracking any reduction in amenities.&nbsp;</p>



<p class="wp-block-paragraph">Specifically, “cybersecurity is an airline responsibility, so if a flight is delayed or cancelled it should be clear that the delay was not due to carrier neglect, as cyberattacks are constant,” Paul Hudson, president of the group, told CyberScoop. “We have previously urged stress tests for airline computer systems that are going down often.”</p>



<p class="wp-block-paragraph">Another group, the National Consumers League, had a more mixed view about the rule’s effects on flyers. On one hand, it could be good for them, said John Breyault, vice president of public policy for the group.</p>



<p class="wp-block-paragraph">‘What we appreciated about this being put into a rule was that it gave consumers certainty that regardless of which airline they were flying, they would know that they have certain rights, and they weren&#8217;t beholden to the whims of the airlines who may or may not decide to provide them with a hotel if there&#8217;s a delay or cancelation,” he said.</p>



<p class="wp-block-paragraph">On the other, though, “it&#8217;s clear to us that the DOT seems inclined to try and make the rules a little less onerous for the for the airline industry,” Breyault said, and in particular was worried about how airlines could potentially abuse the ambiguity related to one of the 10 events, “unscheduled maintenance,” to find a way to avoid compensating consumers.</p>



<p class="wp-block-paragraph">The provision might still protect consumers because of its condition on compliance with applicable cybersecurity regulations, Breyault said. Carriers who can’t demonstrate compliance will be subject to customer and other requirements, Hayashi said.</p>



<p class="wp-block-paragraph">“The final rule&#8217;s language regarding applicable cybersecurity regulations is notably broad,” said Kate Growley, partner at Crowell &amp; Moring. “This may have been deliberate to account for the unpredictable nature of cybersecurity attacks. Different regulations may apply depending on the exact circumstances of the attack, such as what information or operational capabilities were affected.”</p>



<p class="wp-block-paragraph">There’s no formal accounting of how often cyberattacks have caused delays or cancellations that then prompted airlines to provide meal vouchers or hotels. Hackers have targeted airlines <a href="https://cyberscoop.com/delta-flight-rogue-wifi-investigation-def-con-las-vegas/">and flights</a> before, such as Scattered Spider’s attacks <a href="https://cyberscoop.com/scattered-spider-aviation-hawaiian-airlines-cyberattack/">last summer</a>.</p>



<p class="wp-block-paragraph">Cyberattacks have caused flying delays and cancellations, although sometimes those attacks have been aimed at third parties, such as in last year’s attack on <a href="https://www.cybersecuritydive.com/news/flights-europe-delayed-cyberattack-third-party/760745/">Collins Aerospace</a> led to delays in Europe. Attackers also have <a href="https://cyberscoop.com/boeing-confirms-attempted-200-million-ransomware-extortion-attempt/">targeted other elements</a> of the aviation sector. The 2024 IT outage related to the cybersecurity company CrowdStrike that grounded flights wasn’t a cyberattack, but did lead to airlines providing <a href="https://www.fastcompany.com/91161578/delta-get-paid-crowdstrike">some compensation</a> to travelers; the Transportation Department determined that incident was <a href="https://www.nytimes.com/2024/09/13/travel/crowdstrike-outage-delta-airlines.html">within airlines’ control</a>.</p>



<p class="wp-block-paragraph">The Biden administration notably <a href="https://cyberscoop.com/tsa-cybersecurity-airlines/">imposed cybersecurity regulations</a> on airports, aircraft owners and aircraft operators in 2023 due to “persistent cybersecurity threats” in the sector.&nbsp;</p>



<p class="wp-block-paragraph">The newly-published Department of Transportation (DOT) rule stems from a Federal Aviation Administration authorization law that President Joe Biden signed in 2024.&nbsp;</p>



<p class="wp-block-paragraph">&#8220;Congress explicitly directed DOT in the FAA Reauthorization Act of 2024 to make these changes,” a Department of Transportation spokesperson said. “These 10 specific types of flight disruptions will now … be tracked in a brand-new reporting category to ensure government delay data accurately reflects what airlines can and cannot control.&#8221;</p>



<p class="wp-block-paragraph">The Aviation Information Sharing Analysis Center said it appreciated the elements of the rule related to reporting incidents.</p>



<p class="wp-block-paragraph">&#8220;The Aviation ISAC supports efforts to simplify and harmonize cybersecurity reporting across numerous government agencies,” said Jeff Troy, president and CEO of the organization. “This rule is a move in the right direction.&#8221;</p>



<p class="wp-block-paragraph">Hayashi told CyberScoop the rule change looks to be positive for both airlines — because of the clarity it provides them about disruptions not under their control — and consumers.</p>



<p class="wp-block-paragraph">“This actually is beneficial for everyone, and particularly consumers, because it makes it clear if you&#8217;re looking at airlines delay and cancellation rates, this is going to give you the most accurate picture of carrier delays,” she said.</p>
<p>The post <a href="https://cyberscoop.com/dot-rule-airline-cyberattack-flight-delays/">Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal</a> appeared first on <a href="https://cyberscoop.com">CyberScoop</a>.</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">90656</post-id>	</item>
	</channel>
</rss>
