The US Department of Justice issued an opinion authorizing a federal hiring approach that allows technologists from private companies to work in government roles while remaining employed by their firms and retaining unvested equity (e.g., restricted stock units). The arrangement is tied to the administration’s U.S. Tech Force program, which plans to onboard managers from more than 20 companies; ethics experts raised concerns that such dual-employment and deferred-compensation structures could create conflicts of interest and weaken public-interest safeguards.
Separately, the US Department of Homeland Security reassigned or removed multiple career Customs and Border Protection officials involved in privacy and FOIA compliance after they objected to directives to withhold or relabel records about surveillance technologies. Reporting indicates DHS leadership ordered routine compliance documents—such as Privacy Threshold Analyses (PTAs)—to be treated as legally privileged or labeled as “drafts” to limit disclosure, following the release of a PTA that revealed details about Mobile Fortify, a previously undisclosed face recognition app that could capture faces and fingerprints without consent.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Office of Personnel Management said the U.S. Tech Force is explicitly recruiting cybersecurity personnel as part of its initial cohort, alongside software engineers, data scientists, and product managers. An agency spokesperson said cyber hires would be included in the first group of roughly 1,000 planned hires as participating agencies near the end of hiring.
The Justice Department issued an opinion allowing private-sector technologists to work in the federal government while remaining employed by their companies and keeping unvested restricted stock units. The decision cleared the way for the Trump administration's U.S. Tech Force program to recruit managers from more than 20 firms under recusal-based ethics assumptions.
Multiple career CBP officials were reassigned after they challenged directives to mislabel surveillance-technology privacy compliance records and limit their release under FOIA. Critics described the orders as illegal retaliation, while DHS denied having a policy that made PTAs categorically FOIA-exempt.
On December 3, the DHS Privacy Office announced a "major change" requiring future Privacy Threshold Analyses to carry disclaimers asserting deliberative-process and attorney-client privilege and restricting external sharing. Sources said officials were also directed to label signed privacy assessments as drafts to support FOIA withholding.
A CBP FOIA officer released a redacted Privacy Threshold Analysis that exposed details of the previously undisclosed Mobile Fortify face-recognition app. The document said DHS expected the app to collect faces and fingerprints without consent, include U.S. citizens and lawful permanent residents, and retain images for up to 15 years.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
nextgov.com
Open sourcelawfaremedia.org
Open sourcenextgov.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.