Cybersecurity and Infrastructure Security Agency — US federal agency
A French disinformation watchdog has linked the Israeli firm BlackCore to online campaigns that targeted elections in Scotland and New York, in addition to France’s local elections. The report ties BlackCore to a network amplifying content through automated accounts; authorities say the operations spanned Angola and Togo, with comments aimed at Scotland’s First Minister and the SNP.
President Trump has delivered a primetime address releasing declassified intelligence he says shows China acquired large volumes of U.S. voter data and that officials hid reports about foreign efforts to target U.S. elections. Journalists, former intelligence officials and state authorities have said the documents do not prove foreign actors altered 2020 vote counts and many of the administration's claims have been disputed.
Security researchers warn AI-enabled cybercrime is accelerating, with autonomous AI agents rewriting code, exfiltrating data, and negotiating ransoms. Patches and defensive tools are racing to keep pace, while experts urge tougher controls and faster updates.
OpenAI has said its unreleased model Astra may have reached a "Critical" capability for autonomous cyberattacks and has paused internal activities that do not meet heightened safeguards. The company has implemented isolated testing, universal monitoring for risky actions, and is working with government agencies and safety organisations to evaluate Astra's abilities.
Federal agencies and state officials have reported coordinated cyberattacks that have targeted internet-connected controllers at water and wastewater utilities in at least a dozen states since late July. Operators have had passwords changed and been locked out, forcing many plants to revert to manual control; officials say drinking water remains broadly safe while investigations continue.
Cyberattacks targeting water systems in multiple states have been linked by security researchers to Iran‑affiliated groups. Officials warn the threat is ongoing and could widen, with misleading claims about responsibility surfacing in political discourse.
The White House has authorised a program that will allow vetted U.S. private companies to carry out government-directed cyber surveillance and disruptive operations against overseas transnational criminal organisations. The memorandum has required Justice and Homeland Security oversight, a $1m escrow for participating firms, and a 60-day deadline for agencies to set participation rules.
The UK government has confirmed that Iranian-linked hackers targeted a small-scale energy generator last month. The incident did not threaten the wider energy system, and authorities have issued guidance to power firms while expanding cyber resilience plans, including an AI-powered shield for critical infrastructure.
Beijing has rejected US security allegations that Chinese AI firms extracted proprietary knowledge from American labs at an industrial scale. The accusation follows a U.S. joint advisory accusing Chinese firms of distillation from US models since late 2024.