White House expands its cyber reach with expanded AI policy, new cybercrime memo
The Trump administration, long associated with deregulation, is asserting new control over cyber operations via a reported expansion of its testing framework for frontier AI models and a stunning program that allows vetted private firms to run offensive cyber operations against foreign criminals.

The Trump administration is taking significant steps that could expand the federal government's role in overseeing and deploying some of the most powerful technologies in cybersecurity, even as the White House continues to resist characterizing its approach as regulation.
In one development, the administration is preparing to broaden a still-secret framework for government testing of advanced artificial intelligence models before their release, according to WIRED. In the other, Donald Trump signed a National Security Presidential Memorandum establishing a program under which vetted private companies could conduct surveillance and disruptive cyber operations against foreign criminal organizations under federal direction.
Both moves illustrate an increasingly muscular approach to cybersecurity built around partnerships between government and technology companies. Rather than imposing broad regulatory requirements, the administration is drawing selected companies directly into national-security operations while seeking greater visibility into technologies it believes could themselves pose national-security risks.
The government wants access to more frontier AI models
The AI development builds on Trump's June executive order on advanced AI innovation and security.
That order directed the government to develop a classified benchmarking process for determining when an AI system possesses sufficiently advanced cyber capabilities to qualify as a "covered frontier model." It also called for a voluntary arrangement through which developers could give the government access to such models for as long as 30 days before releasing them to other trusted partners.
The order explicitly said the arrangement should not constitute mandatory licensing, preclearance, or permitting of AI models.
WIRED reported that the resulting framework currently encompasses closed models produced by companies such as OpenAI and Anthropic, but White House officials expect to expand it to open models once they reach comparable frontier capabilities.
The fundamental twist is that AI policy is increasingly becoming capability-based rather than dependent on how a model is distributed.
It also demonstrates the difficulty the administration faces in reconciling two objectives: avoiding an AI regulatory regime it believes could slow American innovation while responding to increasingly capable models whose cybersecurity implications the government considers serious enough to warrant prerelease examination.
According to WIRED, the framework remains voluntary, but officials are considering a more formal relationship with leading AI laboratories. Expanding the program to open models could create additional complications because imposing a testing period on models intended for broad distribution could slow their development and potentially undermine one of the advantages of open development.
The cybercrime memo goes considerably further
The second White House action moves beyond information sharing or voluntary security testing and creates a mechanism for private companies to participate directly in government-controlled cyber operations.
Trump's memorandum orders the Homeland Security Task Force's National Coordination Center to establish a program allowing approved US companies to conduct both "Cyber Surveillance Operations" and "Cyber Effects Operations" against foreign cyber-enabled transnational criminal organizations.
A cyber surveillance operation can involve accessing a target's systems without the owner's authorization while attempting to remain undetected. The definition explicitly encompasses collecting intelligence that could later be used to conduct a cyber effects operation.
Cyber effects operations go considerably further. They can involve the "manipulation, disruption, denial, degradation, or destruction" of information systems, networks, data, or even physical or virtual infrastructure controlled by information systems.
In other words, the memorandum isn't merely asking security companies to provide indicators of compromise, malware analysis, or intelligence to law enforcement. It creates a framework under which private companies could actually enter foreign systems and, with government approval, interfere with or destroy them.
That potentially represents a major expansion of the operational role private cybersecurity companies play in US law enforcement.
Not a private-sector license to hack back
There is an important distinction, however, between the new program and the "hack back" proposals periodically floated in Washington.
The memorandum repeatedly places participating companies under federal control. Companies must contract with either the Department of Justice or the Department of Homeland Security, and operations require government authorization. DOJ and DHS officials serving as the program's co-executive directors must coordinate before approving operations, and participating companies must receive written approval and direction before taking action.
The White House is therefore not giving companies a general right to retaliate against attackers who target their customers. Instead, it is effectively creating a pool of private offensive cyber contractors operating pursuant to government authority.
That distinction is important legally as well as operationally. The memorandum specifically requires the program to comply with the Computer Fraud and Abuse Act, the Constitution, and US international obligations and emphasizes that companies will operate under federal control.
Companies could also generate operations
One of the more interesting provisions is that participating companies won't necessarily execute operations handed to them by Washington.
The memorandum allows them to establish commercial relationships with other private companies that can supply threat information gathered through their normal operations. Participating companies can use that information to propose cyber operations to the National Coordination Center.
State, local, tribal, and territorial governments can similarly identify threats that participating companies can turn into operational proposals.
That creates a pipeline that could look something like this:
A cybersecurity provider discovers infrastructure belonging to a ransomware operation while protecting a customer. It provides the intelligence to a participating company. That company develops a proposed surveillance or disruption operation and sends an operational package to the NCC. DOJ and DHS review the proposal, coordinate it against intelligence, diplomatic, military, and other federal equities, and authorize the contractor to execute it on the government's behalf.
The private sector therefore becomes not merely an extra pair of hands but potentially a source of intelligence, targeting proposals and operational capacity.
The safeguards reveal some of the risks
Some of the most revealing portions of the memorandum concern the safeguards the White House believes the program will require.
Within 60 days, DOJ and DHS must establish detailed operating procedures governing the program. Those procedures must include standards for technical competence, personnel vetting, facility security and previous cyber-operational performance.
Companies may also be required to maintain a bond or escrow worth at least $1 million that can be forfeited for violating their contracts.
More consequentially, the procedures must establish mechanisms for deconflicting operations across federal law enforcement, State, Treasury, the Department of War and the intelligence community.
That provision points toward one of the central hazards of offensive cyber operations: a contractor attempting to disrupt infrastructure that another government agency is monitoring, exploiting, or using for intelligence collection.
The government must also establish an adjudication system intended to ensure that targets really qualify as cyber-enabled transnational criminal organizations.
The memo makes a consequential assumption about who counts as a criminal rather than a state actor
One of the most striking provisions is buried in the definitions.
Section 4(c) defines an eligible cyber-enabled transnational criminal organization as a foreign group conducting cyber-enabled crime against the United States, Americans, or US interests that isn't an institutional part of a foreign government or wholly operating at a foreign government's direction.
But the memorandum then establishes a significant presumption for making that determination: A foreign group will be assumed not to be part of a foreign government or wholly operating under its direction unless "clear intelligence" establishes such a connection.
That puts the presumption on the side of treating an organization as a criminal rather than a state actor. Section 4(c) presumes a foreign group is a criminal actor, not a state one, unless the government already has "clear intelligence" proving otherwise — a default that's easy for independent gangs but untested for the harder cases: groups tolerated or informally tasked by Russia, China, Iran or North Korea, where that clear intelligence rarely exists. That's precisely where a disruption operation risks escalating into a state-to-state incident.
The distinction could become particularly consequential when dealing with ransomware gangs and other cybercriminal groups operating from countries such as Russia, China, Iran and North Korea. The relationship between cybercriminals and governments isn't always binary. A criminal group might operate with a government's tolerance or protection, share personnel with state security services, occasionally conduct operations useful to the government, or assist intelligence agencies without being wholly controlled by them.
Russia in particular has long presented precisely that attribution problem. Cybercriminal organizations can operate from Russian territory while the precise nature of their relationship with Russian intelligence or security services remains uncertain.
Under the memorandum, uncertainty alone would not appear to be enough to treat such a group as state-controlled. Unless the government possesses clear intelligence establishing that the organization is part of or wholly directed by the foreign government, the presumption runs in the opposite direction.
That matters because the program authorizes considerably more than intelligence collection. Participating companies could conduct operations that manipulate, disrupt, degrade, or destroy foreign systems and infrastructure.
The presumption therefore isn't merely a definitional technicality. It could affect which foreign targets the United States considers eligible for disruptive operations and how much evidence officials need about a group's relationship with a hostile government before authorizing private contractors to act against it.
It could also carry escalation risks. An operation nominally directed at a criminal organization could affect infrastructure, capabilities, or individuals with connections to a foreign intelligence service, potentially turning what Washington regards as an anti-crime operation into something the foreign government views very differently.
The memorandum attempts to manage some of that risk through an adjudication framework and extensive interagency deconfliction. But Section 4(c) establishes the baseline from which those decisions begin: absent clear intelligence demonstrating government control, the target is presumed to be a non-state criminal organization.
Some operations remain beyond the program's authority
The memorandum establishes another boundary around what it calls "Critical Outcomes."
DOJ and DHS program directors cannot themselves approve an operation likely to cause death or serious injury or one that would rise to the level of a use of force or armed attack under international law.
That limitation underscores just how consequential some of the authorized operations immediately below that threshold could nevertheless be.
The definition of cyber effects explicitly includes destruction and operations affecting infrastructure. The policy therefore isn't confined to removing criminal websites or seizing servers. Depending on the implementation rules developed over the next 60 days, it could permit much more aggressive disruption.
This has been building since March
Wednesday's memorandum did not appear from nowhere.
Trump's March cybercrime executive order directed the government to establish an operational cell within the National Coordination Center to coordinate federal efforts to "detect, disrupt, dismantle, and deter" cybercrime committed by foreign transnational criminal organizations, including through private-sector participation where appropriate.
The new memorandum appears to provide the operational architecture for carrying out that ambition.
It also fits the administration's broader 2026 cybersecurity strategy, which placed considerably greater emphasis on disruption and imposing consequences on adversaries rather than relying primarily on defense.
What is new is the specificity: who can conduct the operations, who approves them, what kinds of effects they can produce, how private intelligence can generate proposed operations, and how government agencies are supposed to prevent those activities from colliding with one another.
A common thread between AI and offensive cyber policy
At first glance, prerelease testing of AI models and contractor-assisted operations against ransomware gangs might seem like separate policies.
But they reflect a similar conception of Washington's relationship with the technology sector.
The administration isn't primarily trying to regulate technology companies from outside. It increasingly wants to bring selected companies inside national-security activities.
AI developers would voluntarily provide the government access to frontier models so federal experts can determine what those models can do. Cybersecurity companies would provide intelligence, develop operational proposals, and potentially conduct surveillance and disruptive operations on government-selected targets.
In both cases, private-sector capabilities are advancing faster than the government's ability to reproduce them internally. The administration's answer appears to be deeper operational integration rather than building those capabilities entirely inside government or subjecting the industries to traditional regulatory regimes.
That may ultimately prove to be one of the defining characteristics of Trump's cyber policy: not less government involvement in advanced technology, but a different kind of government involvement — one that increasingly treats private technological capability as an instrument of national power. (Hugo Lowell / Wired and White House, White House)
Related: Reuters, Bloomberg, r/singularity, r/accelerate
Metacurity is the cybersecurity news and analysis you'd need hours and expert staff to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
During a US Army exercise called Combined Resolve, Ukrainian drone units easily spotted and defeated US troops and armored vehicles on rotation from Fort Hood in Texas, according to people familiar with the events.
The exercise, coupled with US casualties in Iran, shows American vulnerabilities to drones—years after the US made uncrewed systems an essential part of warfare. America pioneered using long-range drones in war. The Pentagon has recently spent billions acquiring new drone and counter-drone technology and formed special units to operate it.
Still, in the Middle East this year, the US has struggled to defend against Iran’s long-range drones, which have killed and injured soldiers and destroyed aircraft.
The drubbing in Germany conveyed lessons from Ukraine focused on short-range battlefield drones. The exercise, held in April and May, tested visiting troops’ ability to operate and defend against the proliferation of smaller, front-line drones that have dominated the conflict between Russia and Ukraine. (Alistair MacDonald, Lara Seligman and Daniel Michaels / Wall Street Journal)
Related: Ukrainska Pravda, Anadolu Ajansı, The New Voice of Ukraine
A day after the Israeli cybersecurity company Dream reported that it had uncovered an AI-driven hacking campaign that stole credentials and other data from an unnamed government in Asia, Taiwan's Ministry of Digital Affairs said that it had detected AI-assisted cyberattacks on government agencies last month coming from overseas, but the affected bodies successfully "handled" the incident.
In a statement, the Ministry of Digital Affairs said its cybersecurity monitoring units detected the "abnormal attack" targeting government agencies in July, and beginning July 20, its National Institute of Cyber Security issued a series of warning alerts while it investigated.
The investigation results showed the attacks displayed clear characteristics of an "overseas source," with hackers employing a hybrid approach that combined manual operations with AI agent-assisted attacks, such as Open Claw, it said."The relevant attack sources, methods, and scope of impact have all been fully investigated, and the affected units have successively completed their handling," the ministry added. (Ben Blanchard and Raphael Satter / Reuters)
Related: CNN, AFP, Focus Taiwan, The Guardian, Dream Security, The Guardian, CNN, The Register, Focus Taiwan, Silicon UK, Tom's Hardware, PCMag, Cyber Security News, Security Affairs
More than three dozen bitcoin and crypto companies have asked the largest AI labs to give open-source security researchers early access to their most capable models, arguing that the people defending a trillion dollars of infrastructure are working with weaker tools than those attacking it.
The letter, organized by the Bitcoin Policy Institute and published earlier this week, is signed by Coinbase, Block, BitGo, Blockstream, Anchorage Digital, ARK Invest, Bitwise, Foundry, Casa, Exodus and others, alongside nonprofit developer funds including Brink, Chaincode and Btrust.
Its central complaint is that Bitcoin Core developers, the small group maintaining the software that runs the network, cannot access the programs' labs run for trusted security partners.
When they turn to publicly available models instead, the safety filters designed to stop people from writing malware also block efforts to find flaws before criminals do.
That leaves them on open-weight models, which can be freely downloaded and are generally less capable.
Attackers face none of those constraints. The letter said the labs and a handful of partners can see new offensive capabilities months before anyone else. In contrast, those capabilities spread anyway through public models, stolen access to corporate systems and purpose-built hacking tools. (Shaurya Malwa / CoinDesk)
Related: crypto.news, CryptoSlate, Bitcoin Policy Institute, crypto.news, Cointelegraph, Blockchain.News, The Crypto Times
New studies show that American artificial-intelligence models are unwittingly incorporating Chinese censorship into their chatbot answers, and researchers say AI companies haven’t done much to fix it.
The unexpected censorship comes in part from how AI models are trained. They act as a giant blender, gobbling up mountains of data across the web, including state-controlled media. That leaves the resulting smoothie with a taste of authoritarian propaganda.
“It’s some of the unintended side effects of the training,” said Nicolas Suzor, an Australian law professor and member of Meta Platforms’ independent oversight board. He and other researchers say AI companies can help address the issue with simple tweaks, including greater transparency about where information comes from.
American AI companies say they take steps to ensure neutral responses that protect free speech. Still, the oversight board last month published research that found models from OpenAI, Anthropic, Google and Meta were significantly less likely to criticize repressive governments than governments in freer countries.
In one test, Anthropic’s Claude Sonnet 4 willingly created fliers criticizing President Trump and King Charles III, but refused to do the same for Chinese leader Xi Jinping or Thai King Maha Vajiralongkorn, citing safety concerns.
Google’s Gemini 3 Pro and Meta’s Llama 4 Maverick sometimes declined to create protest fliers targeting those two Asian leaders, while always complying with requests for the American and British ones. (Stu Woo / The Wall Street Journal)
Researchers at Check Point report that malware used by North Korea's Lazarus group negotiated its command channel using a post-quantum key exchange before pulling down a Windows zero-day exploit, in a campaign against defense and aerospace companies across Europe and India.
Check Point Research reported the vulnerability to Microsoft on July 28 and published its analysis on August 11, the day a patch shipped.
CVE-2026-68820 is a use-after-free race condition in AFD.sys, the driver handling network sockets in the Windows kernel, and was the only flaw in this the August Patch Tuesday release Microsoft flagged as under active exploitation.
The activity is the latest wave of Operation Dream Job, which approaches employees at defense firms with fraudulent job offers.
Targets included organizations working on surveillance sensors, drones and robotics, with activity or targeting in France, Germany, Brazil and India. (Alessandro Mascellino / Infosecurity Magazine)
Related: Check Point, The Record, Security Affairs, Help Net Security

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.
The data-theft campaign, dubbed City-Forum by SaaS security firm Reco, has been traced to a single server that has targeted multiple organizations worldwide. These organizations include telecommunications companies, banks and financial services firms, enterprise software vendors, security and data privacy companies, and public-sector portals.
Reco says the attacks are ongoing, with activity continuing to increase. (Lawrence Abrams / Bleeping Computer)
Related: Reco, Security Week, Techzine, Help Net Security, GBHackers, Cyber Security News
The FBI is investigating how an unidentified federal agency was recently swept up in a years-long campaign involving North Korean remote IT workers fraudulently obtaining jobs at major companies and other organizations.
The North Korean campaign has been notorious for using remote IT contract jobs to infiltrate both Fortune 500 companies and smaller private sector firms.
But experts contacted for this story said it’s not surprising the public sector has been implicated as well. They said the incident highlights a new kind of insider threat, as well as potential gaps in the government and industry vetting processes, especially for jobs like IT support work. (Justin Doubleday / Federal News Network)
Related: TechCrunch
Some 19 million records have been stolen from over 12,000 healthcare facilities, Poland's digitization Minister Krzysztof Gawkowski said, adding that the company had confirmed the breach.
"The records contain various types of personal information that can be linked to individual patients," he added.
The minister said that security services and law enforcement agencies were working together to identify those responsible. However, he stressed that there was currently no evidence pointing to an attack carried out by a foreign state.
Authorities have also launched procedures to secure the affected data and transfer it to a dedicated database. The database will allow individuals to check whether their personal information was among the data exposed in the breach.
The digitization ministry said in a statement that the attack did not disrupt the day-to-day operations of healthcare providers, including the issuance of medical prescriptions. (Polska Agencja Prasowa)
Related: anews, TVP World, Türkiye Today, Anadolu Ajansı, UNN
Colombia's Ministry of Justice confirmed that a ransomware attack struck part of its technology infrastructure and degraded several public-facing services on Aug. 2, just five days before the nation's presidential handover.
The attack, which disrupted some services around illicit-drug monitoring and legal processes, came a day after Colombia's national CERT (ColCERT) published a threat intelligence warning that ransomware groups had increased their focus on the country. While some media reports suggested that data had leaked during the Ministry of Justice compromise, then acting Minister of Justice Cielo Rusinque denied that any information had been stolen during a Spanish-language news interview.
"Some files were encrypted," she said, according to a translation service. "We are currently working on overcoming that encryption, [but] it has already been verified ... that there was no data capture. That was the first thing I asked." (Robert Lemos / Dark Reading)
Related: SC Media
Researchers at CloudSEK and Hudson Rock report that terabytes' worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open-source tool that streamlines AI-driven software development.
Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it discovered this after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.
The LiteLLM compromise was the result of a previous supply-chain attack that infected the widely used vulnerability scanner Trivy. Other software infected in the campaign includes KICS and the Telnyx Python SDK. TeamPCP, a ramshackle but extremely capable gang largely made up of teenagers, took credit for the attack, and researchers have largely corroborated the claim.
“I’ve confirmed the data is legit by the way, multiple victim orgs,” independent security researcher Kevin Beaumont said. “It contains a significant volume of sensitive content at orgs. It’s a massive supply chain breach due to poor AI security—not because AI is the threat, but because teens can run circles around orgs obsessed with rushing out AI and poor DevOps security.” (Dan Goodin / Ars Technica)
Related: CloudSek, Hudson Rock, Cyber Kendra, Help Net Security

Researchers at Group-IB report that a previously unseen NFC relay malware family has been deployed alongside a remote access trojan in a single 13-minute phone call, letting a fraudster take out a loan in the victim's name and relay their card data to a fake terminal while keeping them on the line.
They track the NFC malware as WindRelay and attribute the remote access trojan (RAT) to a variant of SpyNote.
The fraudster called, posing as a bank employee reporting a problem with the victim's card, then talked them through installing the first app.
The RAT arrived through the device's package installer, the standard route for sideloading outside an app store. Its app label carried the victim's own name, rather than a generic or impersonated brand.
SpyNote ships with a builder toolkit letting an operator set a custom app name, label, and package name, so personalization is built in rather than manual effort.
Group-IB said the label pointed to pre-call reconnaissance harvesting the victim's name and phone number, and meant there was no unfamiliar app name to give the victim pause.
With the RAT active, the fraudster used its remote access to install WindRelay himself, requiring nothing further from the victim. No screen sharing was triggered at any point. (Alessandro Mascellino / Infosecurity Magazine)
Related: Group-IB, Bleeping Computer, The Register, Cybersecurity News, GBHackers, Cyber Press

Adobe rolled out patches for over 50 vulnerabilities across its products, including critical-severity bugs in ColdFusion, Campaign Classic, and Commerce.
With a priority 1 rating, the ColdFusion update fixes 15 security defects, including three flagged as critical that could lead to arbitrary code execution and application denial-of-service (DoS).
These include an OS command injection tracked as CVE-2026-48362 (CVSS score of 10/10), an eval injection tracked as CVE-2026-48273 (CVSS score of 9.9/10), and an incorrect authorization tracked as CVE-2026-71384 (CVSS score of 9.6/10).
The update for Campaign Classic also has a priority 1 rating, as it resolves three critical flaws leading to arbitrary code execution: two incorrect authorization issues, CVE-2026-71398 and CVE-2026-27302 (CVSS score of 10/10), and an SQL injection bug, CVE-2026-48381 (CVSS score of 9.0/10).
Per Adobe’s priority rating system, these security defects have a higher risk of being targeted in the wild, and users should apply the patches for both products immediately.
Adobe resolved seven vulnerabilities in Commerce, including CVE-2026-71362 (CVSS score of 9.1/10), an incorrect authorization issue leading to privilege escalation. High-severity code execution and security feature bypass bugs were also addressed. (Ionut Arghire / Security Week)
Related: Adobe, Bleeping Computer, Cyber Security News
More than 80% of Japanese companies use artificial intelligence in only a limited capacity in their operations or not at all, a Reuters survey showed, a trend that could hinder official efforts to boost productivity.
About 60% of respondents said AI is being used only in some parts of their companies or in other limited ways. Another 18% said they have not decided whether to introduce AI into the workplace, while 6% are not even considering AI adoption.
The remaining 16% have deployed AI company-wide as an integral tool, the survey showed.
"We have started using it company-wide, but its use is limited to tasks such as document creation," a manager at a wholesaler wrote in the survey.
Separately, a real estate firm official said, "We don't know how to put it in use."
A government report this year showed Japan lagged other industrial powers in AI adoption, with 86.4% of local firms using generative AI for at least one task, compared with China's 98.1%, Germany's 91.6% and the United States' 90.9%. (Kiyoshi Takenaka / Reuters)
US Rep. Josh Gottheimer (D-NJ) announced a package of bipartisan federal measures aimed at shielding water and electric utilities from hackers, weeks after cyberattacks disrupted municipal water systems in Cape May County and more than a dozen other states.
“Every morning, folks in this town wake up, turn on the faucet, and clean water comes out. You flip a switch and your lights come on. Nobody thinks twice about it. Nobody should have to,” said Gottheimer. “I’m standing here because in towns just like this one, all over the country, that deal we have with our utility companies has been put in real jeopardy, and if we don’t get out ahead of it, it could mean a disaster.”
Hackers targeted the City of Cape May’s water and sewer department and the Borough of Woodbine’s water department in the early morning hours of July 27, cutting off staff’s ability to remotely monitor and manage the systems. (Lia Opperman / NJ.com)
Related: Josh Gottheimer, CBS News, The Press Group, WRNJ, Pix11
Mindgard, a Boston, MA, and London, UK-based provider of an AI security platform, announced it had raised $30 million in a Series A funding round.
Album VC led the round with additional support from Karma Ventures and previous investors, .406 Ventures, Atlantic Bridge, IQ Capital, and Lakestar. (Ionut Arghire / Security Week)
Related: Cyber Security News, FinTech Global, Pulse 2.0, FinSMEs
Best Thing of the Day: Seeing Is Believing
In this half-hour documentary, leaked data, interviews and never-before-seen videos obtained by The Wall Street Journal reveal how a single team of these workers infiltrated at least eight companies in just a few months.
Bonus Best Thing of the Day: The IC Needs AI Talent Too
The intelligence community’s lead IT shop has launched a shared classified jobs portal, as the IC looks to boost its artificial intelligence talent and other expertise.
Worst Thing of the Day: Better Be Nice to That CBP Officer
Internal records obtained by WIRED reveal how, for years, United States Customs and Border Protection employees and contractors were accused of abusing sensitive government databases for reasons that had nothing to do with their jobs.
Bonus Worst Thing of the Day: Little Mittens Now Hates You
A Petlibro outage is preventing its smart pet feeders and other devices from performing scheduled tasks, like dispensing food.
Closing Thought
