The U.S. government signaled that private industry is not expected to conduct offensive cyber operations on the government's behalf, even as the new national cyber strategy calls for stronger collaboration with commercial partners. National Cyber Director Sean Cairncross said the administration wants to use private-sector capabilities for information sharing, threat intelligence, and defensive support, while offensive action remains the responsibility of agencies that already hold that authority, including the NSA, CIA, FBI, and U.S. Cyber Command.
The same policy direction is reflected in the Energy Department's planned first-ever cyber strategy, which is intended to align with the national strategy and focus on protecting the energy grid through stronger public-private coordination. Energy officials said the plan will prioritize getting timely, actionable information to operators, improving the sector's security resilience, and investing in AI for cyber defense to counter adversaries using AI-enabled offensive capabilities against critical infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Google publicly launched a new threat disruption unit within its threat intelligence organization at the RSAC Conference. The company said the unit will use intelligence, legal processes, infrastructure takedowns, public exposure of threat actors, and product improvements to proactively impede adversaries without engaging in 'hacking back.'
Senior administration cyber officials said the new national cyber strategy does not contemplate cyber 'letters of marque' or authorizing private companies to hack on the government's behalf. At the Prague Cyber Security Conference and McCrary Cyber Summit, they said industry's role is to provide visibility and support for government-led actions against criminal and state-backed actors.
FBI Cyber Division head Brett Leatherman said the bureau's joint sequenced operations to degrade adversaries often begin when victim organizations report incidents to the FBI. He urged organizations to include contacting their local FBI field office in breach-response plans, saying the benefits outweigh liability concerns.
At a McCrary Institute event, National Cyber Director Sean Cairncross said the U.S. government does not envision private companies carrying out offensive cyber actions on its behalf. He said industry should instead contribute threat intelligence, technical visibility, and defensive support while agencies with existing legal authority handle offensive operations.
A senior Department of Energy cybersecurity official said the department is developing its first strategic plan focused on protecting the energy grid. The strategy is intended to complement the recently published national cyber strategy and emphasize resilience, public-private partnership, and AI investment for defense of critical energy infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcenextgov.com
Open sourcetherecord.media
Open sourcecyberscoop.com
Open sourcenextgov.com
Open sourcetherecord.media
Open sourcelawfaremedia.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.