#NSBCS.141 - Trump Administration Allowing Private Companies to Hack Foreign Criminal Organisations

 

The United States government recently published a memorandum titled ‘Expanding Capabilities to Combat Transnational Cyber-Enabled Crime’. This allows private corporations to spy and sabotage foreign criminal organisation’s operations. President Trump has stated that this would assist the US in combating cybercrime schemes that cost the nation significant sums annually. But at what expense?

This poses a large grey area between the government’s foreign policy and commercial activity conducted by the businesses. This new program significantly increases the private sector’s role in offensive cyber operations. Participating companies must meet certain criteria before being permitted to take part, including technical competency and personnel vetting. They must also set aside US$1 million of bonds that they forfeit if they violate the program’s rules. Taken together, these conditions suggest the government is attempting to formalise accountability in a space that has historically operated with minimal oversight.

This initiative also raises several concerns. The memorandum says that the program’s leaders cannot authorise surveillance or disrupt operations that would kill or seriously injure people or constitute the use of force or an armed attack under international law. But what if an attack of this nature were to occur despite these restrictions? Would it be classified as cyber warfare? Would it trigger a counterattack by the foreign criminal organisation, affecting not only the private company but also the US government?

The memorandum requires the Department of Justice and Department of Homeland Security to review and approve every proposed operation, but oversight on paper is not the same as oversight in practice. With the growth of sophisticated adversaries and the threat of AI-powered autonomous threats and automation, what if something goes wrong? Who will be held accountable?

The memorandum says that both smaller and larger companies should participate in the initiative. If something were to go wrong, a smaller company may not have the same resources that a larger corporation has in responding to a threat on them. This increases the potential risk for all participating businesses, the US government and society, since a single under-resourced company could become a weak point exploited to reach the broader initiative.

Within the US cybersecurity field there are mixed reviews of the initiative. Some professionals say the program could be effective if properly designed and overseen. With appropriate protection and accountability in place, it could be a meaningful response to a growing problem. It would let the private sector enter the counter-offensive space within a controlled environment, provided the scheme functions as intended. Paul Rosenzweig, former deputy assistant secretary for policy at the Department of Homeland Security, has stated to Cybersecurity Dive that this memorandum is a bad idea and that there are significantly better ways to carry out what seems to be an essential government function.

Whether this initiative marks a necessary evolution in cyber defence or a dangerous outsourcing of state power may ultimately depend less on the memorandum’s intent than on how rigorously its safeguards are enforced in practice.

Reference: https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/


What we read this week

  • ACSC Warns of Active Exploitation of Critical Adobe Commerce and Magento Vulnerability in Australia - The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has issued a critical alert regarding active exploitation of CVE-2026-75650 (also known as StyleSmuggler) in Adobe Commerce and Magento Open Source. The flaw is an improper neutralisation of special elements used in a template engine that can enable unauthenticated remote code execution when the /graphql endpoint is exposed. ACSC reports a substantial number of potentially vulnerable instances across the Australian economy and urges system owners to apply the vendor patch released on 7 September as a priority. No specific industry or sector has been identified as targeted. Organisations should review exposure of the GraphQL endpoint, apply updates immediately and engage managed service providers where relevant.

  • Mathspace Data Breach Exposes Details of More Than One Million Australians - Online mathematics learning platform Mathspace has disclosed a data breach in which attackers accessed and stole information relating to more than one million students, staff and parents. The incident involved compromise of the company’s Metabase internal reporting system. Affected individuals are being notified. The disclosure emerged around 7 September and highlights ongoing risks associated with third-party analytics and reporting tools used by education providers. Organisations handling student and family data should review access controls, logging and third-party integrations as a priority.

  • Microsoft Delivers Record September Patch Tuesday Including Two Actively Exploited Windows Zero-Days - Microsoft has released its largest Patch Tuesday update to date, addressing approximately 974 vulnerabilities, including more than 110 rated critical. Two Windows elevation-of-privilege zero-days already under active exploitation have been fixed: CVE-2026-85880 (heap-based buffer overflow in Advanced Local Procedure Call allowing escalation to SYSTEM) and CVE-2026-81963 (improper link resolution in the Windows Update Stack, also enabling local privilege escalation to SYSTEM). CISA has added both to its Known Exploited Vulnerabilities catalogue. Organisations should prioritise these updates, particularly on older Windows builds, and check for signs of prior compromise.

  • Multiple Espionage Groups Adopt BlueMoon Exploit Kit Chaining Chrome and Windows Flaws - Proofpoint researchers have identified a new exploit kit, BlueMoon, that chains Chromium V8 vulnerabilities (including the patch-gap zero-day CVE-2026-85046) with a Windows local privilege-escalation flaw (CVE-2026-85880). At least four espionage-motivated clusters, the majority assessed as China-aligned (including TA412/APT31/Violet Typhoon), began using the kit within days of one another from late August, with activity continuing into early September. Attacks typically start with phishing that directs victims to an actor-controlled URL. Defenders should ensure browsers and Windows systems are fully patched and monitor for related indicators.

  • Cisco Confirms Active Exploitation of Critical Secure FMC Authentication-Bypass Flaw - Cisco has confirmed that CVE-2026-20079, a maximum-severity (CVSS 10.0) authentication-bypass vulnerability in the web interface of Secure Firewall Management Center (FMC) Software, is being actively exploited. An unauthenticated remote attacker can send crafted HTTP requests to bypass authentication and execute scripts or commands with root privileges. The issue arises from an improper system process created at boot time. Cisco became aware of exploitation in August and recommends upgrading to a fixed release; no complete workarounds exist. Administrators should review logs for indicators such as references to /var/tmp/license.tmp and contact Cisco TAC if compromise is suspected.


Next
Next

#NSBCS.140 - What Policing Taught Me About Ransomware Investigations