TikTok announced the creation of TikTok USDS Joint Venture LLC to keep operating in the U.S. under a September 2025 executive order. Under the arrangement, ByteDance would reduce its ownership to 19.9%, with majority ownership shifting to majority-American investors; TikTok said the new entity will implement national-security safeguards including U.S.-based data protections and controls around the recommendation algorithm. The company stated that U.S. user data and algorithm security will be supported via Oracle’s U.S. cloud environment, and that the joint venture will run a cybersecurity and privacy program aligned to frameworks such as NIST CSF, NIST 800-53, and ISO 27001, with third-party auditing/certification; TikTok said similar safeguards would extend to other U.S.-available apps such as CapCut and Lemon8.
Separately, a policy commentary argued that the TikTok controversy highlights the lack of consistent U.S. standards governing foreign-owned apps—particularly around data ownership/access and algorithmic oversight—and called for clearer, enforceable requirements (e.g., upfront disclosure of who owns collected data and how users can opt out). While it does not add new incident details about TikTok’s joint venture, it frames the broader national-security and consumer-protection rationale for establishing uniform rules for foreign-based software providers operating in the U.S., citing TikTok and other China-linked apps as examples.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
TikTok said the new U.S. joint venture would be overseen by a seven-member board and named Adam Presser as CEO and Will Farrell as chief security officer, while assigning the entity responsibility for U.S. data protection, algorithmic compliance, and content moderation for TikTok, CapCut, and Lemon8.
Alongside the joint venture announcement, TikTok said U.S. user data and recommendation systems would be protected in Oracle's U.S. cloud under a privacy and cybersecurity program aligned with NIST CSF, NIST SP 800-53, ISO 27001, and CISA restricted-transaction requirements, with third-party audits and certifications.
TikTok announced it completed a divestiture of its U.S. business by creating TikTok USDS Joint Venture LLC, with ByteDance reduced to a 19.9% stake and majority ownership transferred to non-Chinese investors. The new structure was designed to satisfy U.S. national security requirements while allowing TikTok to continue U.S. operations.
By January 22, 2026, TikTok said a deal for U.S. ownership had closed, valuing the transaction at about $14 billion and allowing the company to avoid a U.S. ban.
A Nextgov analysis argued that the TikTok controversy and similar concerns around other foreign-linked apps showed the U.S. lacks clear, enforceable rules on data ownership, access, and algorithmic safety, and urged creation of consistent standards for foreign-owned software providers.
In September 2025, President Donald Trump signed an executive order establishing terms under which TikTok could continue operating in the United States while addressing national security concerns tied to ByteDance's ownership.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcearstechnica.com
Open sourcethehackernews.com
Open sourcepolitico.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.