惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Forbes - Security
Forbes - Security
T
Troy Hunt's Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
H
Hacker News: Front Page
TaoSecurity Blog
TaoSecurity Blog
PCI Perspectives
PCI Perspectives
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
V
Vulnerabilities – Threatpost
博客园 - 【当耐特】
V
Visual Studio Blog
N
News and Events Feed by Topic
Security Archives - TechRepublic
Security Archives - TechRepublic
V
V2EX
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
WordPress大学
WordPress大学
T
Tor Project blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
美团技术团队
P
Proofpoint News Feed
A
Arctic Wolf
C
CERT Recently Published Vulnerability Notes
Last Week in AI
Last Week in AI
T
Tenable Blog
K
Kaspersky official blog
爱范儿
爱范儿
S
Security @ Cisco Blogs
Spread Privacy
Spread Privacy
大猫的无限游戏
大猫的无限游戏
Jina AI
Jina AI
博客园 - 三生石上(FineUI控件)
T
Tailwind CSS Blog
S
SegmentFault 最新的问题
Security Latest
Security Latest
T
The Exploit Database - CXSecurity.com
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Project Zero
Project Zero
W
WeLiveSecurity
L
LINUX DO - 最新话题
Hacker News: Ask HN
Hacker News: Ask HN
阮一峰的网络日志
阮一峰的网络日志
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Cyber Attacks, Cyber Crime and Cyber Security
小众软件
小众软件
Webroot Blog
Webroot Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
Attack and Defense Labs
Attack and Defense Labs

CyberScoop

Security researchers find stalkers abusing Chrome's sync feature SonicWall customers under threat as attackers exploit 2 zero-days Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed Forget the model. When it comes to cybersecurity, it’s all about the harness White House details ‘Gold Eagle’ clearinghouse for AI cyber threats Microsoft discloses ‘the mother of all’ vulnerability loads, tripling June’s previous record Treasury sanctions First VPN Service, others for abetting ransomware gangs Europe strikes out against Russia’s Turla over espionage, ‘destructive attacks’ Officials once again warn defenders that Russian hackers are targeting network devices AI-generated code has made security debt a governance problem Armenian national pleads guilty to Ryuk ransomware attacks CISA looks to remedy ailments from big May credential leak Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail Interpol cybercrime crackdown nets 5,800 arrests across 97 countries 764 splinter group leader sentenced to 40 years in jail French nonprofit starts global intelligence and research hub for AI cyber threats Found fast, fixed slow: The gap the AI clearinghouse must close Spain arrests suspected hacker linked to Russian hacktivist campaign Deepfake CSAM lawsuit against xAI, Grok expands Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities US Army websites defaced with pro-Kurdish sentiments, insults to Trump Sysdig clocks first documented case of agentic ransomware Finding vulnerabilities was never the hard part Someone infected a spyware probe overseer with spyware Alleged longstanding member of Scattered Spider extradited to US Researchers spot exploitation of another critical Oracle defect U.S. lifting export control restrictions on Anthropic’s Mythos, Fable This phishing kit looks more like BEC-as-a-service Citrix patches a new NetScaler flaw with echoes of CitrixBleed Trump budget boss Russell Vought open to re-staffing CISA DHS to unveil replacement council for critical infrastructure cybersecurity How ransomware syndicates weaponize corporate-style organization Warner bill would create federally vetted list for secure, trustworthy AI agents Supreme Court approves mail-in ballots that arrive after Election Day Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling What the post-quantum executive order really demands of CISOs ATF cancels controversial commercial geolocation contract FCC passes new cybersecurity rules for emergency systems, undersea cables Federal court rules Trump election-focused executive order illegal Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack Why patch directives only go so far Malicious hackers exploit Cisco zero-day for highest access level at communications service provider In a first, a court takedown goes after two cybercrime tools at once Open-source security is posing challenges governments can't easily solve Justice Department seizes infrastructure used by cyber scam and criminal marketplace Algerian man charged with running two cybercrime marketplaces Court rules SAVE database illegal, orders it dismantled Trump executive orders speed up post-quantum migration, boost industry Intel agencies: Frontier AI models will reshape cybersecurity faster than expected Authorities disrupt Evil Corp’s SocGholish botnet Congress tees up No FAKES Act, aiming at AI-generated deepfakes How software development's speed obsession enabled TeamPCP’s chaos crusade Accenture shells out $4.18B on three companies in big industrial cybersecurity push Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April Lawmakers leary about Trump administration’s Anthropic order AI’s constant patching treadmill can be a security problem A case for how to shape ‘ingredient lists’ for AI models Google exposes China espionage group that’s been lurking in networks undetected since 2023 Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat Anthropic disables new models after government calls them a national security concern FBI takes down massive China-based cybercrime network that caused $1.9B in losses US, France, and Italian authorities shut down massive deepfake porn site Conti ransomware group member pleads guilty, faces up to 20 years in prison ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw CyberCorps is adapting to AI. The budget isn’t keeping up. Russian national charged in connection with Void Blizzard espionage campaign OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers CISA directive orders agencies to prioritize vulnerability patching in a new way Microsoft breaks Patch Tuesday record with 206 vulnerabilities Anthropic’s new model is Mythos on a leash CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector Cisco customers encounter another SD-WAN zero-day under attack Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint The AI security race needs accountability, not overregulation Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away Hill Dems hammer GOP for $250M CISA budget cut Your AI agent could become your biggest insider threat Inside the race to adapt to an AI-powered security world European authorities crack down on illegal streaming networks DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels DOD wants to integrate cyber in all operations, and integrate security into AI Trump administration releases scaled-back AI executive order Anthropic expanding access to Project Glasswing Attackers are exploiting Palo Alto Networks defect that initially flew under the radar Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order Election threats are focused on campaign systems, not voting machines Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 Federal audit reveals NIST’s NVD is plagued by poor planning and duplication House panel poised to hold hearing centered on AI impact on cyber Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket Zapier fixes bug chain that researchers say risked widespread account takeover OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain Apple open-sources quantum-resistant encryption code White House charts new course for federal agencies and cybersecurity logging Anthropic: Mythos finds more than 10,000 software flaws in first month
States are building their own election defense networks as federal support evaporates
djohnson · 2026-07-14 · via CyberScoop

The Trump administration’s abrupt firing of Election Assistance Commission commissioners last week and a Department of Justice warning threatening states with criminal prosecution have created new legal peril for officials who run, administer and secure elections.

The EAC is an obscure but important agency that oversees testing and standards for voting machines, including around security. While federal certification is voluntary, states have until now relied upon their stamp of approval when purchasing voting machines. 

On July 10, Democratic Commissioners Ben Hovland and Thomas Hicks were fired by the White House, while reports indicate that a third Commissioner, Republican Christy McCormick, resigned. While Congress mandated the commission be bipartisan, the Supreme Court has recently given the President broad authority to fire executive branch officials at will.

In an interview with NPR, Hovland said he worried the firings would further erode trust that the commission was working in a bipartisan manner.

“And as you eliminate things – or if you get rid of commissioners, for example – or as you eliminate some of these other sort of safeguards or norms, it certainly strains the system,” said Hovland. “And it certainly also likely causes people to lose faith in our democracy and in the process and their confidence in our elections. And that’s very concerning.”

A letter also sent last week to all 50 states by the DOJ said the department will investigate and prosecute any election official “who knowingly retains non-citizens on the state’s voter registration list or facilitates noncitizens in receiving and casting ballots.”

CyberScoop spoke with several Secretaries of State who said that the number one threat facing elections in their state is not from a foreign country or AI but their own federal government. 

Tobias Read, the Democratic Secretary of State for Oregon, told CyberScoop that his office is focused on providing the state’s 36 county clerks with the resources and support they need to carry out a smooth election. But he acknowledged that his office is “playing defense in a lot of ways [from] the intrusion from the federal government” that continues to assert its authority over local elections.

“If the president were actually serious about election security, he would be sending more resources to local election officials and bolstering the system rather than cutting it,” said Read.

This year, several counties in Oregon will offer voters access to a new ballot tracking system that provides text or email updates when a voter’s ballot is moving through mail and has been certified.  Reed estimated at “pennies per voter per election” and called it a good option for cash-strapped counties to assure voters their ballots are secure and properly tracked.

At the same time, Read said federal agencies like the Cybersecurity and Infrastructure Security Agency – which once regularly deployed cybersecurity and technical expertise to help states fix vulnerabilities and share threat intelligence – have largely gone quiet.

Oregon ranks in the top ten states for voter participation and relies heavily on mail-in voting.  However, state officials like Read lack confidence in the US Postal Service. Though a recent Supreme Court decision blocked an executive order giving the service control over mail-in ballot distribution, officials like Read are urging voters to take other measures to use drop boxes instead as a  safer alternative to ensure their vote is counted.

Adrian Fontes, Arizona’s Secretary of State and a Democrat running for reelection, said his office is focused on primary elections and processing the mail ballots that have been arriving “for a while.”

After Iranian hackers defaced Arizona’s candidate bio portal last year, Fontes moved to fill a widening gap: the Trump administration’s withdrawal of federal foreign interference training and support. His office is now directly supporting local jurisdictions on election security while coordinating more closely with state law enforcement, intelligence agencies, and other states.

But it’s being done with a fraction of the resources and coordination that the federal government brought to bear under both the Biden and first Trump administrations. While Fontes said he maintains positive personal relationships within the Department of Homeland Security, his office does not have a formal relationship with CISA.

“We’ve hobbled together a loose and often informal network of information sharing – that doesn’t violate any rules, it doesn’t break any laws – but it is certainly not anywhere near as robust as it would be if we had a responsible federal agency that was interested in the security of American elections,” said Fontes.

He said even if CISA offered such services today, he wouldn’t accept it, citing the lack of trust between states and the Trump administration.

“They have proven through their actions that they don’t want to be effective partners in protecting the American electorate and protecting American voters,” said Fontes. “Because of that, the clear answer, the only sensible answer for someone like me, would be to say ‘No, I don’t want the help of people I cannot trust.’ People who have demonstrably and explicitly threatened me and local election administrators of all political stripes with criminal prosecution.”

Secretaries of State in Colorado, Nevada, Minnesota, Rhode Island, and others have also called the DOJ letters an attempt at federal intimidation of election officials. 

Others, like West Virginia Republican Secretary of State Kris Warner, have reiterated their refusal to hand over state voter data. On Monday, a federal judge upheld his right to do so. 

Warner wrote to the DOJ in response to say the state was “available to discuss our existing voter registration list maintenance” but “West Virginia law prohibits the disclosure of sensitive personally identifiable information contained in voter registration records.”

It’s leading some states to take new precautions. 

Read said he was working with Oregon county officials to make sure “county clerks have the number of their county counsel on speed dial” and know how to distinguish between a legitimate and illegitimate federal warrant or subpoena.

Additionally, FBI raids of election offices around the country to seize ballots records related to the 2020 and 2024 elections have been a cause for Read’s concern. By state law, Oregon and other states must keep copies of the ballot records and other election data they receive from counties for a certain time according to state law, after which they must eventually archive or destroy them according to ballot retention schedules.

Read emphasized that “it’s important to destroy those ballots at the appropriate time,”  The Trump administration has used the raids to further the impression of electoral fraud, despite the absence of credible evidence. 

“We can see when people are not on top of that, then you expose yourself to other vulnerabilities like the federal government seizing those ballots in Maricopa County [Arizona] and Fulton County [Georgia] as well,” said Read.

A former CISA official estimated that on Election Day in 2024, more than 1,000 representatives from federal, state and local governments, election technology vendors and other election stakeholders sat together in a room to communicate and coordinate.

Less than two years later, Read called his office’s interactions with CISA “minimal.” He recalled that upon taking office as Secretary of State in Jan 2025, one of his first conversations was with one of CISA’s regional advisors. A week later, those advisors were summarily fired by the Trump administration.