A new report from Dartmouth's Institute for Security, Technology and Society calls for the US government to develop a comprehensive strategy to better utilize its private sector in scaling up offensive cyber activities. The report, based on input from 30 experts from government, industry, and academia, highlights a significant capability gap between the US and China in cyberspace. While China conducts both targeted and opportunistic cyber operations, the US approach remains narrowly focused and top-down, limiting its operational tempo and agility. The report suggests that the US private sector, with its agility and technical expertise, could help close this gap and enable more effective cyber operations at scale.
The analysis contrasts the US and Chinese models, noting that China often steals data broadly and determines its value later, whereas the US prioritizes select, high-value targets. The report references leaks from Chinese cyber espionage firm i-SOON to illustrate the opportunistic nature of Chinese operations. It concludes that integrating private sector capabilities could help the US achieve greater cyberspace dominance and respond more flexibly to emerging threats, recommending a shift in strategy to harness both high- and low-end offensive cyber capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
F5 disclosed a significant security breach in which attackers stole source code and vulnerability reports. The company said disclosure had been delayed because of national security concerns.
A prisoner in Romania reportedly compromised the country's prison management system. The incident underscored weaknesses in government IT security and insider-access-related risk.
Security researchers identified a new worm dubbed GlassWorm that can self-propagate via Visual Studio Code extensions. The finding added a new software supply-chain and developer-environment threat to the reporting period.
Authorities imposed fines on several companies across the United States, United Kingdom, and Australia for data-breach-related failures. The penalties were cited as part of broader cyber enforcement and accountability efforts.
Europol took down a major SIM box fraud network operating in Latvia. The operation targeted infrastructure used to facilitate large-scale telecom-enabled scam activity.
SpaceX reportedly disabled more than 2,500 Starlink terminals that were being used by scammers. The action was highlighted as a significant private-sector disruption of criminal infrastructure.
A newly cited report described how an affiliate known as Devman quickly transitioned into running a ransomware-as-a-service operation. The case was presented as evidence that new ransomware strains are easy to create and that smaller splinter groups persist despite disruption of major ransomware actors.
A Dartmouth report argued that the U.S. government should leverage private-sector cyber capabilities to help scale offensive operations and narrow a capability gap with China's broad hacking approach. It recommended starting with lower-risk targets such as ransomware gangs and crypto scammers rather than immediately pursuing large-scale intelligence collection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.