Compiled by Athena Smith.
Articles
The FBI Data Breach Is a Counterintelligence Disaster
Justin Sherman argued that the FBI data breach is a potential counterintelligence nightmare, exposing thousands of FBI personnel to profiling and foreign intelligence targeting—and, more broadly, to doxing and even violent retribution from threat actors ranging from foreign adversaries to domestic extremists. Sherman explained that the FBI and the U.S. government first need to verify the authenticity of the incident and understand its scope before taking both cyber and physical security measures to mitigate the harm to impacted employees.
The supposedly breached FBI data, exploited years down the line, would be as if a nation-state hacked a U.S. military academy, stole information on all the cadets, and used that data to start building dossiers on every single person in the data, so that someone who later goes into a special forces unit, intelligence role, or senior commanding position could have their names and personal data laid out clearly from the initial breach. Novel artificial intelligence data analytic capabilities make this problem even worse, allowing nation-states that could access this or other breached data to conduct more sophisticated pattern analysis and anomaly detection within datasets. The end goal is all about exploitation against U.S. security interests.
The Full Stack of U.S.-China Cyber Competition
Eugenio Benincasa reviewed Ahana Datta Fasel’s book, “Full Stack Spies: Cyber Espionage in the Age of US-China Competition,” which traces U.S.-China cyber espionage across the three levels of tradecraft, statecraft, and instability. Benincasa explored the book’s useful “upstairs-downstairs” approach, which illustrated both top-level geopolitical decisions and the substructure of hackers operationalizing them, but also noted that the book’s broad scope led to some overreach.
For readers already immersed in cyber threat intelligence or Chinese cyber operations, some of the book’s interpretations will invite debate, particularly where public attribution remains uncertain or where historical examples are used to sustain broader claims about the evolution of China’s cyber ecosystem. These tensions are most visible in the book’s treatment of attribution, where its own emphasis on ambiguity and incomplete information makes some of its broader conclusions harder to sustain.
In the latest edition of the* Seriously Risky Business *cybersecurity newsletter, Tom Uren explored Treasury Secretary Scott Bessent’s argument that frontier artificial intelligence (AI) labs should not be exempt from liability amid hacks by rogue AI, how Chinese and Russian hackers are putting AI to different uses—with China diversifying its malware to complicate attribution and Russia cyberattacks are using AI to automate operations and evading detection—, and more.
Bessent made his comments while testifying at a hearing of the House Financial Services Committee. When asked about AI safety, he replied that “the best way to guarantee safety” is for those creating the technology to be “liable for what they build and generate.” Frontier labs, he added, are instead asking for liability shields or antitrust waivers to coordinate on safety—meaning that they are not liable for what they build. Headlines detailing various frontier lab models escaping cybersecurity training and embarking on hacking sprees have been coming thick and fast. Most recently, the Wall Street Journal reported last week that Google’s Gemini model had hacked three companies during a cybersecurity test in May.
Podcasts
Lawfare Daily: Iran War Update—and How We Got Here: Natalie Orpett sat down with Ariane Tabatabai and Julia Curlee to discuss the ongoing war in Iran. The group explored where the conflict stands today, how the gutting of the national security apparatus in Washington has affected the way the government is waging the war, and more.
Videos and Webinars
Lawfare Live:** The Trials of the Trump Administration, September 25: **On Friday, Sept. 25, at 4 p.m. ET,
*Support *Lawfare
*Follow us on Twitter, Facebook, YouTube, and LinkedIn. Become a material supporter on Patreon. Sign up to receive *Lawfare