Policy & Regulation

Government lacks ability to verify AI labs’ claims, experts say
A new survey released by the Institute for Security and Technology (IST) reveals that the U.S. government is inadequately equipped to verify claims made by frontier AI labs about their products, and its reliance on industry expertise may pose risks of regulatory capture. The 111 national security respondents generally believe that speed and legal frameworks are the main barriers to addressing AI threats, while AI has recently helped attackers more than defenders.

CISA scraps 6 free cybersecurity assessments for critical infrastructure operators

Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
The US Federal Bureau of Investigation and the Department of Justice announced the seizure of multiple domains linked to the China-backed hacking group QTFY, which used the QScan and QTRouter platforms to attack US critical infrastructure and government agencies, including the Department of Justice, NASA, and the Federal Reserve. Court documents show that the group also targeted entities such as telecommunications, hospitals, and defense contractors. Nanjing Xinju Wei Network Technology Company employed hackers and provided services to the People's Liberation Army and the Ministry of State Security.

Treasury to help financial firms transition to quantum-resistant encryption
The U.S. Treasury announced on Monday the formation of a Quantum Readiness Working Group aimed at helping the financial industry address the risk that quantum computers could break traditional encryption. The working group will coordinate financial institutions, technology providers, and relevant agencies to promote the adoption of quantum-resistant cryptographic algorithms, focusing on identifying critical dependencies, enhancing cryptographic agility, fostering interoperability, and strengthening operational resilience.

Defense contractors still struggling with basic CMMC requirements
A report released by CyberSheath on Thursday indicates that defense contractors still face difficulties in meeting the requirements of the U.S. military's CMMC program, despite the Pentagon's efforts to ease their compliance burden. In 2026, only two-thirds of contractors submitting self-assessments were highly confident in the accuracy of their scores, and the median contractor believed they were only 70% ready for a CMMC certification review. The report also found that contractors want more types of businesses to be included in cybersecurity requirements, reflecting concerns about supply chain risks.

What we know so far about the hacking campaign against US water systems
美国多地水务系统自7月下旬起遭遇疑似伊朗背景的协同网络攻击,波及至少12个州。攻击者利用可编程逻辑控制器(PLC)的已知漏洞,导致部分设施运营中断。联邦机构已发布警告,行业正推动立法强化监管,运营商则被敦促立即加固系统。

DOJ charges 17 people in Iran-backed hacking campaign against US
The U.S. Department of Justice announced indictments against 17 members of Iran's Mabna Institute, accused of conducting a coordinated cyberattack campaign on behalf of the Islamic Revolutionary Guard Corps, targeting 144 U.S. universities, 42 private companies, and at least five federal and state agencies since 2013.

White House walks tightrope on securing AI without stifling tech innovation
U.S. National Cyber Director Sean Cairncross stated at the Black Hat USA 2026 conference that the Trump administration is striving to balance responsible security development practices with promoting private sector innovation, emphasizing the need for a flexible and adaptable regulatory framework.