CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Is Cyber missing the Marque?

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4809

As cited

Copy frozen at (site build).

threat intel

Is Cyber missing the Marque?

A White House presidential memorandum authorizes private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside the United States under government direction and oversight. The policy raises operational questions about attribution, infrastructure overlap, access ownership, and international implications. Additionally, researchers identified UAT-10147, a Chinese-speaking cybercrime group leveraging agentic AI to automate post-compromise operations including a new SPECTRE implant with kernel-level rootkit and EDR-evasion capabilities.

Why it matters: Security leaders and offensive practitioners must understand the new legal and operational framework for government-authorized private sector cyber operations, as employees conducting these operations now face significantly altered threat models and potential international incidents. Defenders urgently need to patch internet-facing vulnerabilities (Zimbra, Nacos, Telerik UI), secure ASP.NET MachineKeys, block vulnerable drivers, and enhance network monitoring to detect UAT-10147 and similar AI-augmented threats that scale post-compromise attacks and bypass endpoint detection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Is Cyber missing the Marque?

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Is Cyber missing the Marque?

A White House presidential memorandum issued August 14, 2026, directs the Department of Justice and Department of Homeland Security to establish a program authorizing private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside U.S. borders under government delegation. The framework creates significant operational questions around attribution, jurisdiction, intelligence handling, and the implications when private sector employees conduct state-authorized attacks. The memorandum provides 60 days for DOJ and DHS to develop operating procedures before any operations can be approved.

Why it matters: Security leaders and employees at firms engaged in government cyber programs face substantially altered threat models, legal exposure, and geopolitical risk if their offensive operations are discovered by foreign governments or used as pretexts for counterattacks; practitioners should review the memorandum details and prepare for clarification in 60 days on which companies, operations, and safeguards will be permitted.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

Is Cyber missing the Marque?

A White House presidential memorandum issued August 14, 2026, directs the Department of Justice and Department of Homeland Security to establish a program authorizing private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside U.S. borders under government delegation. The framework creates significant operational questions around attribution, jurisdiction, intelligence handling, and the implications when private sector employees conduct state-authorized attacks. The memorandum provides 60 days for DOJ and DHS to develop operating procedures before any operations can be approved.

Why it matters: Security leaders and employees at firms engaged in government cyber programs face substantially altered threat models, legal exposure, and geopolitical risk if their offensive operations are discovered by foreign governments or used as pretexts for counterattacks; practitioners should review the memorandum details and prepare for clarification in 60 days on which companies, operations, and safeguards will be permitted.

VendorsMicrosoftAppleVMwareGitLabProgress SoftwareLinux
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary