GKRootWire
Security ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm ForecastsSecurity ICE Signs $2M Deal for Zero-Click Phone Hacking ToolSecurity Attackers Exploit Critical Elementor Pro Bug to Hijack WordPress SitesAI ChatGPT Goes Down, Serves 404 Errors to UsersAI ChatGPT and Codex Suffer Widespread OutageAI Google DeepMind's WeatherNext 3 Sharpens AI Weather ForecastingAI Google's New AI Weather Model Sharpens Storm Forecasts
Security

White House Clears Private Security Firms to Hack Overseas Cybercriminals

A new administration memo marks the first time the U.S. government has authorized private companies to conduct offensive cyberattacks against foreign threat actors.

The Trump administration has issued a memo permitting private cybersecurity firms to actively hack back against cybercriminals operating outside the United States, according to Ars Technica. This is reportedly the first time the federal government has formally sanctioned offensive cyber operations by private-sector companies rather than reserving that authority for government agencies like the NSA or FBI.

Details on oversight, targeting rules, and liability protections remain limited, but the shift signals a major departure from decades of policy treating 'hacking back' as legally risky or outright prohibited for private entities. Security firms have long argued they're outgunned by ransomware gangs and state-linked hackers who operate with impunity from friendly jurisdictions.

The move raises immediate questions about escalation, attribution errors, and accountability when private actors strike systems abroad.

Why it matters: Letting private firms conduct offensive operations blurs the line between defense and vigilantism, and mistakes in attribution could hit innocent networks or trigger diplomatic incidents. It also creates a new commercial incentive structure around offensive hacking that regulators haven't caught up to yet.

Sources: Ars Technica