Connect with us

Infosecurity

Senate confirms Adam Cassady as U.S. cyber ambassador in 51-47 vote

Published

on

cyber ambassador confirmed

Senate backs Cassady for top cyber diplomacy post

The Senate on Friday confirmed Adam Cassady as the next U.S. ambassador for cyber and digital policy, filling a role that has sat empty since the start of the Trump administration.

The vote was 51-47, part of a broader package covering more than 70 nominees. Cassady becomes only the second person to hold the ambassador-at-large position. The first, Nate Fick, stepped down in early 2025.

Cassady arrives from the National Telecommunications and Information Administration, where he served as a senior official. His previous stops include the Federal Communications Commission.

A bureau reshaped by reorganization

The job Cassady is walking into looks different than it did a year ago. The State Department’s Bureau of Cyberspace and Digital Policy — which he will now lead — was split into three separate entities during a major reorganization. A new Bureau of Emerging Threats was carved out, and the cyber bureau’s staffing was cut.

Exactly how much influence Cassady will wield is an open question. The restructuring diluted the bureau’s scope, and the role’s responsibilities have shifted. Still, the confirmation gives the U.S. a permanent face for international cyber diplomacy after more than a year of vacancy.

Quiet hearing, big questions on China chips

Cassady faced little pushback at his April confirmation hearing. He told senators the U.S. should work with “trusted partners who share our commitment to secure, resilient and open digital ecosystems.”

But he was less definitive on one hot-button issue: whether the U.S. should allow advanced semiconductor shipments to China.

“I don’t have a strong point of view on that topic yet. Certainly I will very, very quickly develop one,” Cassady said at the time.

He added that the administration was trying to “balance very important competing considerations as it relates to both economic prosperity and national security.” If confirmed, he said, that issue would be one he’d “dig very deeply into.”

The Nvidia H200 question

The chip question isn’t hypothetical. Last month, Jeffrey Kessler, undersecretary of Commerce for industry and security, told the House Foreign Affairs Committee that “very few” of Nvidia’s H200 artificial intelligence chips have reached China and Hong Kong — an indication that shipments are quietly underway.

That puts Cassady in an awkward spot. His bureau will likely have a voice in how the U.S. frames these export decisions on the world stage, even if Commerce holds the actual levers.

What comes next for the cyber ambassador role

Cassady’s confirmation ends a period of uncertainty for U.S. cyber diplomacy. The ambassador post was created under the Biden administration, and Fick’s departure left a gap that some allies were watching closely.

The new ambassador inherits a bureau with fewer resources and a narrower mandate. Whether he can restore its influence — or even define its new boundaries — remains to be seen.

For now, the Senate has spoken. Cassady is in. The hard part starts now.

For more on how the State Department’s cyber operations are structured, see our explainer on U.S. cyber diplomacy strategy. And if you’re tracking export controls, check out this breakdown of AI chip restrictions on China.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Infosecurity

NIST Wants to Rebuild the NVD for an AI World — Here’s What That Means

Published

on

NVD modernization

A Database Under Pressure

The US National Institute of Standards and Technology (NIST) is asking the cybersecurity community to help it drag the National Vulnerability Database (NVD) into the age of artificial intelligence. On August 12, the agency published a request for information (RFI) in the Federal Register, inviting stakeholders to weigh in on how to modernize the NVD for what it calls “an evolving cybersecurity landscape increasingly shaped by AI and machine-consumable security data.”

The NVD is the backbone of vulnerability management for countless organizations. It automatically ingests Common Vulnerabilities and Exposures (CVE) records within about an hour, then analysts enrich each record with severity scores, affected product versions, and other context. That enriched data flows out through the NVD website and automated tools used by security teams worldwide.

But the system is straining. NIST says traditional methods — periodic scanning, static prioritization, manual remediation — no longer cut it. Vulnerability volumes are exploding, technology cycles are faster, and organizations want near-real-time data and deeper automation. The RFI lays out a vision for a system that is “continuous, contextual, and automated.”

This is not just a routine update. The NVD is a critical piece of national infrastructure, and how it evolves will shape vulnerability management for years to come.

Why AI Changes the Game

The RFI doesn’t treat AI as a passing trend. NIST sees it as both an opportunity and a threat.

On the upside, AI could help automate CVE enrichment, spot patterns in vulnerability data, and even assist in discovering new vulnerabilities. The agency wants to integrate AI tools and automation workflows directly into the NVD’s operations.

On the downside, AI is also enabling attackers. AI-assisted vulnerability discovery and exploitation are real concerns, and NIST acknowledges that the same technology that helps defenders can also help adversaries find and weaponize flaws faster.

The RFI includes 30 questions covering everything from scalability and interoperability to transparency and utility. NIST is looking for “forward-looking perspectives, practical recommendations and innovative models” — not just tweaks, but a fundamental rethinking of how the NVD should work.

What Experts Say About AI in Vulnerability Management

Tyler Reguly, associate director of security R&D at Fortra, sees real promise in using AI for vulnerability discovery. “AI can be beneficial when analyzing source code,” he says. “It can identify all sorts of obscure vulnerabilities that human researchers might overlook.”

But he draws a hard line at remediation. “I would not trust the remediation of vulnerabilities in critical systems to AI just yet,” Reguly warns. “Human-in-the-loop is still so critical.”

His advice: use AI in test environments and labs, but keep humans in charge of production systems. “In production systems… not yet.”

That’s a sentiment worth keeping in mind as NIST builds out its modernization plan. Automation can speed things up, but it shouldn’t replace human judgment where the stakes are highest.

Key Questions in the RFI

The RFI is not a vague call for comments. It’s a structured set of 30 questions designed to extract specific, actionable input. Here’s a snapshot of what NIST wants to know:

  • How should the NVD prioritize vulnerability enrichment to keep pace with the growing CVE backlog?
  • What AI tools and techniques could improve the accuracy and speed of CVE analysis?
  • How can the NVD better support machine-consumable data formats for automated security tools?
  • What transparency and accountability measures should be in place for AI-assisted analysis?
  • How can the NVD balance automation with human oversight to maintain trust?

These aren’t just technical questions. They’re about governance, reliability, and the role of a national database in an era of AI-driven both defense and offense.

What’s at Stake

The NVD is more than a website. It’s the foundation for vulnerability scanners, patch management systems, and security research. If it can’t keep up with the pace of modern threats, the entire ecosystem suffers.

NIST’s move to modernize is overdue, but welcome. The agency is right to seek input early, before making major investments in AI and automation. The question is whether the final design will balance speed with accuracy, and automation with human judgment.

Stakeholders have until October 13 to submit their input. If you work in vulnerability management, this is a rare chance to shape the tools you’ll rely on for the next decade.

For more on how AI is reshaping security, check out our coverage of AI in vulnerability management and the broader shift toward automated threat intelligence. And if you’re still using manual CVE analysis, it might be time to start planning for the NVD’s AI-powered future.

Continue Reading

Infosecurity

Gunra Ransomware Exploits Fortinet Flaws to Target Critical Infrastructure

Published

on

Gunra ransomware exploits Fortinet

New Advisory Warns of Gunra’s Double Extortion Campaign

A joint advisory from US and Republic of Korea authorities has put a spotlight on Gunra, a ransomware-as-a-service (RaaS) operation that’s actively targeting government agencies and critical national infrastructure. The warning, published on August 10, details how the group is exploiting two known Fortinet vulnerabilities to gain a foothold in high-value networks.

The advisory comes from the FBI, the Cybersecurity and Infrastructure Security Agency (CISA), and other US agencies, alongside South Korea’s National Police Agency (KNPA). It paints a picture of a sophisticated operation that doesn’t just lock files—it steals vast amounts of data first, then demands a hefty ransom.

Gunra’s code traces back to leaked Conti ransomware source code from 2022. The group first appeared in April 2025, but by early 2026 it had structured itself into a proper RaaS affiliate program, advertised on dark web forums. It’s also adopted new branding, sometimes operating under the alias “Golden Community.”

Legacy Fortinet Vulnerabilities Still Effective

The FBI has observed Gunra specifically targeting two legacy Fortinet vulnerabilities. Both are authentication bypass flaws affecting specific versions of FortiOS and FortiProxy.

  • CVE-2024-55591: A critical flaw that lets a remote attacker gain super-admin privileges via crafted requests to the Node.js websocket module.
  • CVE-2025-24472: A high-severity vulnerability allowing a remote unauthenticated attacker, who knows upstream and downstream device serial numbers, to gain super-admin privileges on the downstream device when Security Fabric is enabled, via crafted CSF proxy requests.

Patches are available for both. Yet the advisory notes that victims are still getting hit—often even after applying fixes.

Jacob Krell, senior director of secure AI solutions and cybersecurity at Suzu Labs, explains why. “Patching fixes the entry point. It does nothing about an authentication backdoor already embedded in the MFA flow. I’ve seen organizations close the vulnerability and declare themselves clean while the attacker’s persistence mechanism sat untouched in the auth stack.”

How Gunra Operates Once Inside

The advisory details several observed techniques. In one case, Gunra actors accessed an administrator account for an SSL-VPN appliance by exploiting default credentials when account lockout controls weren’t in place. They then downloaded OpenSSH to establish connections between compromised systems and an external attacker-controlled server.

In another example, attackers modified authentication processing files on a corporate VDI authentication portal server, enabling them to continuously bypass multi-factor authentication (MFA). These aren’t flashy exploits—they’re quiet, persistent adjustments that let the group move freely.

Stealthy Exfiltration of Massive Data Volumes

Gunra’s approach is built around stealth. The group primarily conducts malicious activities and internal reconnaissance between 10:00 PM and 6:00 AM in the victim’s time zone, when administrators are typically offline. They also delete system and network access logs, and clear command history to hinder detection.

Roman Sannikov, global research coordinator at iCOUNTER, warns security teams to take note. “If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”

The ransomware binary includes filtering rules to focus only on user data files, avoiding wasted encryption resources on non-critical files. The FBI has observed actors using a malicious executable to exfiltrate data from Microsoft OneDrive and SharePoint. In at least one case, they successfully exfiltrated tens of terabytes of data by creating compressed archives and sending them to the file-sharing service Mega.

Ransom Demands in the Tens of Millions

Gunra’s ransom notes typically start negotiations by demanding tens of millions of dollars—a figure the report describes as “arbitrarily high.” Victims get five to seven days to begin negotiations via a Tor-based portal. In some cases, the group has even emailed management staff directly at victim organizations.

If victims don’t engage or pay, the group threatens to publish leaked data on its data leak site. This is classic double extortion: pay to decrypt your files, and pay again to keep your data private.

Victims span regions worldwide and include healthcare, financial services, government organizations, and critical manufacturing sectors.

Defending Against Gunra

The advisory urges organizations to focus on three key areas to counter Gunra’s tactics:

  • Prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and RDP-exposed infrastructure.
  • Implement and test offline, immutable backups stored in a physically separate, segmented location to ensure recoverability without paying a ransom.
  • Segment networks to restrict lateral movement from an initially compromised device to other systems.

The message is clear: this group is patient, stealthy, and well-organized. They’re exploiting known flaws in legacy systems, and they’re doing it under the cover of night. Organizations in critical sectors need to patch fast, monitor around the clock, and assume that MFA alone won’t save them. For more on protecting your infrastructure, check out our guide on ransomware defense strategies for enterprises and learn how to harden VPN gateways against cyberattacks.

The clock is ticking. If you haven’t patched those Fortinet vulnerabilities yet, consider this your wake-up call.

Continue Reading

Infosecurity

Lazarus Group Used Post-Quantum Key Exchange to Deliver Windows Zero-Day

Published

on

post-quantum key exchange

The Lazarus Group’s Latest Attack Chain

North Korea’s Lazarus Group has been busy. A new campaign targeting defense and aerospace companies in Europe and India shows the hackers adopting cutting-edge cryptography — post-quantum key exchange — to protect their command-and-control traffic.

Check Point Research spotted the activity and reported the vulnerability to Microsoft on July 28. The patch shipped August 11, the same day Check Point went public with its analysis. That’s a fast turnaround for a zero-day.

The flaw, tracked as CVE-2026-68820, is a use-after-free race condition in AFD.sys — the Windows kernel driver that handles network sockets. Microsoft’s August Patch Tuesday release flagged it as the only bug under active exploitation.

This is the latest wave of Operation Dream Job, a long-running Lazarus campaign that lures employees at defense firms with fake job offers. The targets here included organizations working on surveillance sensors, drones, and robotics, with activity or targeting in France, Germany, Brazil, and India.

Post-Quantum Key Exchange in the Wild

Here’s what makes this stand out: the malware negotiated its command channel using Kyber/ML-KEM, the key encapsulation mechanism NIST standardized in 2024 to resist quantum computer attacks. That’s not something you see every day in real-world attacks.

The infection started with MISTPEN, an in-memory downloader that talks to attacker-controlled files on OneDrive via the Microsoft Graph API. After reconnaissance and persistence, it loaded a dedicated module to fetch the privilege escalation exploit.

That module fingerprinted the host, then requested four public keys from the command server. It used them to generate fresh key material with Kyber/ML-KEM, returned the encapsulated result, and only then requested the exploit — which it decrypted and ran in memory. The traffic also carried a second encryption layer using GOST-CBC, on top of MISTPEN’s own AES transport encryption.

What Arrived Through the Handshake

The payload was FudModule, Lazarus’s kernel rootkit, in a build Check Point tracks as v3.1. It disables telemetry callbacks, removes minifilters, kills the NT Kernel Logger, and blinds 94 Event Tracing for Windows (ETW) providers. Newly added is tampering with Smart App Control, resetting its policy state, and forcing a code integrity reload.

Command and Control on Borrowed Servers

Lazarus ran its infrastructure almost entirely on machines it didn’t own. The group used Roundcube webmail servers exploited through CVE-2025-49113, with credentials likely sourced from dark web leaks, plus compromised PrestaShop sites.

Each host ran RelayShell, a previously undocumented PHP webshell that acts as a message relay rather than a conventional command shell. It passes traffic between operator and victim through session files. Check Point found evidence of at least 17 compromised relay servers.

Fake Websites and a New Backdoor

Delivery has shifted too. The group built at least three websites impersonating privacy technology vendor Enveil, some ranking top in search results. Check Point stressed Enveil was neither targeted nor compromised.

Those sites distributed a trojanized PDF viewer that runs a payload hidden inside crafted documents, delivering Troy — a previously undocumented backdoor supporting 17 operator commands.

For defenders, the takeaway is clear: Lazarus keeps evolving. Post-quantum key exchange isn’t just a lab experiment anymore — it’s in the hands of nation-state hackers. If you’re in defense or aerospace, this is a good time to review your patch management and check for signs of Operation Dream Job activity.

Continue Reading

Trending