Theresa Sostmann Theresa.Sostmann@cor.europa.eu ECON members also stressed the need of a place-based approach to the EU defence industry and to industrial acceleration policies. Strengthening Europe’s competitiveness and resilience through advances in digital transformation, cybersecurity, and industrial policy while ensuring that local and regional authorities are adequately supported and actively involved was the main focus of the meeting of the Commission for Economic Policy (ECON) on 23 April. Local and regional leaders adopted a draft opinion, calling for the simplification of digital public services through user-friendly European Business Wallets. They also addressed growing cybersecurity challenges, and how to align industrial and defence initiatives with territorial needs. Simplifying digital public services Digital transformation is a key driver of European competitiveness and a cornerstone for economic productivity. However, complex procedures and regulatory and administrative burdens remain that continue to hinder the full potential of the Single Market. In this context, ECON members adopted a draft opinion on European Business Wallets (EBWs), stressing that they must be designed as simple, user-friendly and cost-effective solutions, particularly tailored to the needs of SMEs, micro-enterprises and start-ups, to support business growth across borders. They highlighted that EBWs should enable a ‘once-only’ principle, allowing businesses to submit data a single time and reuse it across different administrative procedures. They also called for targeted awareness-raising and clear guidance to ensure broad uptake, as well as adequate financial support, technical assistance and training to help local administrations meet new obligations. Rapporteur Branislav Zacharides (SK/ECR), Mayor of Vrútky, said: "The deployment of the Business Wallets will entail new administrative obligations for public authorities, which can be especially burden some for smaller municipalities. We therefore call on the European Commission and Member States to provide adequate technical capacity-building and financial support so that the Wallets can deliver real added value.” The opinion
Apr 23, 2026 · via cor.europa.eu
CISA Warns of FIRESTARTER Malware Targeting Cisco ASA including Firepower and Secure Firewall Products WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) published a malware analysis report today on FIRESTARTER, malware that allows remote access and control by malicious threat actors targeting Cisco Firepower and Secure Firewall products running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. In conjunction with this report, CISA issued new required actions for Federal Civilian Executive Branch (FCEB) agencies in Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices. Threat actors continue to target these devices and products, posing significant risks to all organizations. This malware analysis report, co-sealed with United Kingdom National Cyber Security Centre (NCSC-UK), provides organizations with the knowledge to help them detect and respond to FIRESTARTER. This report provides technical details on threat actor activity, FIRESTARTER’s secret to achieving persistence, as well as recommended detection methods, mitigations and actions for incident response. In this report, CISA and NCSC-UK assess that an advanced persistent threat (APT) actor exploited CVE-2025-20333 and CVE-2025-20362 in Cisco ASA firmware to gain initial access and deploy FIRESTARTER on Firepower and Secure Firewall devices. “FIRESTARTER can persist as an active threat on Cisco ASA devices or FTD software. CISA encourages organizations using these devices or software to review the FIRESTARTER report, assess devices for compromise, implement mitigations, and report any findings to CISA,” said CISA Acting Director Nick Andersen. “Every day, CISA works with federal government and industry partners to assess cyber threats and publish actionable information for organizations to better protect themselves and ensure the integrity of their digital infrastructure.” During proactive monitoring of Cisco ASA devices used by FCEB agencies, CISA detected FIRESTARTER malware that enabled post-patching persistence. CISA analysis determined that firmware patching actions on compromised devices did not necessarily
Apr 23, 2026 · via cisa.gov
Robert Cohen named among Cybersecurity Docket’s “Incident Response Elite for 2026”
Davis Polk partner Robert Cohen was named among Cybersecurity Docket’s “Incident Response Elite for 2026.” The list recognizes the best incident response lawyers in the business based on considerable research, nominations, and input from senior lawyers and other professionals in the field.
The “Incident Response Elite for 2026” list was announced on April 23, 2026.
Copy link to share post
Apr 23, 2026 · via davispolk.com
EvilTokens: Big Cybercrime’s AI Platform Built to Bypass Your MFA May 5, 2026 | 3pm ET | 12pm PT In February 2026, a phishing operation called EvilTokens popped up on Telegram with its own storefront and pricing. By mid-March, it had compromised identities at hundreds of organizations across five countries, all without using malware. Cybercriminals wasted no time putting AI to work. They were early adopters because AI makes phishing more convincing and makes it easier to stand up infrastructure on demand. In this case, the operation abused legit authentication flows and routed victims through trusted services their own security tools were built to trust, making MFA far less protective. Microsoft and Huntress will break down how attackers are actually using AI. Join two of the best in the business as they examine a watershed moment in cybercrime. Sherrod DeGrippo Sherrod DeGrippo is General Manager of Global Threat Intelligence and host of the Microsoft Threat Intelligence Podcast. She has been recognized as Cybersecurity Woman of the Year (2022) and Cybersecurity PR Spokesperson of the Year (2021). Before her current role, Sherrod served as Director of Threat Intelligence Strategy at Microsoft. Her background also includes serving as Vice President of Threat Research and Detection at Proofpoint, where she led a global team focused on threat research, malware analysis, and intelligence operations. With more than two decades of cybersecurity experience, she has held senior roles at Nexum, Symantec, Secureworks, and the National Nuclear Security Administration. Sherrod is a frequently cited expert across major media outlets and a regular speaker at global security conferences. Casey Smith Casey Smith's cybersecurity journey began in the early 2000s at Cisco Systems, where he contributed to the groundbreaking SAFE (Secure Architecture for Enterprise) initiative — sparking a career-long passion for testing the boundaries of defensive systems. He
Apr 23, 2026 · via huntress.com
UWF breaks ground on new AI, cybersecurity and engineering research building PENSACOLA, Fla. -- The University of West Florida officially broke ground on a "new advanced intelligence, cybersecurity and engineering research building" Thursday. The building is called "The Synapse." It's partly funded by Triumph Gulf Coast's $32.5 million award, with more than $21 million in state dollars. "The 55,000-square-foot building on the Pensacola campus will house specialized labs and state-of-the-art equipment and technology to support advanced computational, AI, cybersecurity and engineering research across the University," UWF said. It'll be Building 129, located just south of the John C. Pace Library. Many in the UWF community came together to celebrate the start of construction. “The Synapse is a transformational facility made possible through the support of Triumph Gulf Coast and the state of Florida,” said UWF President Manny Diaz Jr. “This new modern facility will allow the University to expand research capacity, strengthen industry partnerships and better prepare students for career fields critical to our region’s future.” "The facility will serve as the base for the Center for Computational Intelligence and the Center for Cybersecurity and AI, as well as a hub for collaborative projects in robotics, artificial intelligence, cybersecurity, power systems, material science and civil engineering," according to UWF. "A central multi-story atrium with interconnected corridors create efficient pathways for interaction, resulting in a facility built not only for cutting-edge technology, but for constant intellectual connection." When construction is complete, the UWF Center for Cybersecurity and AI will join CCI in the Synapse.
Apr 23, 2026 · via weartv.com
Be scared. Very scared. Readers captivated by cybersecurity developments have likely seen mention of Mythos, the latest version of the Claude artificial intelligence that has been developed by Anthropic. The company decided to withhold release of the software to the public because it is considered too dangerous. Anthropic isn’t worried about some abstract hypothetical: This isn’t handwringing over a Terminator-style AI that will conquer the world. The decision was based on actual experience. Mythos discovered thousands of vulnerabilities in every major operating system and browser. Anthropic has been largely applauded for its caution and responsible decision-making. Cybersecurity experts warn that it’s too early to reach firm conclusions but there appears to be consensus that Mythos represents a “step change” in capability and is a taste of the new digital world that we now inhabit. When testing the new version, Anthropic’s red team found that it “is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so. The vulnerabilities it finds are often subtle or difficult to detect.” (For the uninitiated, a “red team” is the officially designated group who tests a system’s safety and security. And while I’m providing a lexicon, a “zero-day vulnerability” is a software bug that is unknown to the manufacturer and for which there is no immediate fix. It is considered the holy grail of hacks; companies pay hackers to find them and national cybersecurity authorities have huge budgets to buy them for future use.) Mythos uncovered thousands of vulnerabilities, including one more than 25 years old in what was thought to be one of the most secure software applications in the world. Not only does it find those holes; it also figures out how to exploit them. Mythos turned
Apr 23, 2026 · via japantimes.co.jp
OpenAI has briefed US federal agencies, state governments and Five Eyes member countries on the capabilities of its new cybersecurity product over the past week, Axios reported on Wednesday. Cybersecurity is becoming a key battleground for AI labs such as OpenAI and Anthropic as their advanced AI models can both pose security risks and offer cyber defense capabilities, sparking interest from governments and enterprises. OpenAI did not immediately respond to a request for comment. Reuters could not independently verify the report. The ChatGPT-maker unveiled GPT-5.4-Cyber last week, a variant of its latest flagship model fine-tuned specifically for defensive cybersecurity work, following rival Anthropic’s announcement of advanced AI model Mythos. OpenAI held an event in DC on Tuesday for about 50 cyber defense practitioners across the federal government to demo the capabilities of its new GPT-5.4-Cyber model, according to the report by Axios. OpenAI is starting briefings with Five Eyes members this week to get them vetted and signed up to access the model, the report said. The Five Eyes intelligence sharing network comprises the US, Britain, Canada, Australia and New Zealand. Sam Altman-led OpenAI has said that GPT-5.4-Cyber would initially be rolled out on a limited basis to vetted security vendors, organizations and researchers because of its more permissive design. Earlier this month, rival Anthropic also announced a “Project Glasswing” initiative with major technology companies that lets partners preview the startup’s unreleased model.
Apr 23, 2026 · via indianexpress.com
The AI developer Anthropic has confirmed it is investigating a report that unauthorised users have gained access to its Mythos model, which it has warned poses risks to cybersecurity. The US startup made the statement after Bloomberg reported on Wednesday that a small group of people had accessed the model, which has not been released to the public because of its ability to enable cyber-attacks. “We’re investigating a report claiming unauthorised access to Claude Mythos Preview through one of our third-party vendor environments,” said Anthropic. Bloomberg said a “handful” of users in a private online forum gained access to Mythos on the same day Anthropic said it was being released to a small number of companies including Apple and Goldman Sachs for testing purposes. It reported that the unnamed users got to Mythos through access that one of them had as a worker at a third-party contractor for Anthropic and by deploying methods used by cybersecurity researchers. The group has not run cybersecurity prompts on the model and is more interested in “playing around” with the technology than causing trouble, according to Bloomberg, which corroborated the claims via screenshots and a live demonstration of the model. Nonetheless, news of the potential breach will alarm authorities who have raised concerns about Mythos’s potential to wreak havoc and will raise questions about how potentially damaging technology can be kept out of the wrong hands. Kanishka Narayan, the UK’s AI minister, has said UK businesses “should be worried” about the model’s ability to spot flaws in IT systems – which hackers could then act upon. The model has been vetted by the world’s leading safety authority for the technology, the UK’s AI Security Institute (AISI), which warned last week that Mythos was a “step up” from previous models in terms of the cyber-threat
Apr 23, 2026 · via theguardian.com
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-33825 Microsoft Defender Insufficient Granularity of Access Control Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
This product is provided subject to this Notification and this Privacy & Use policy.
Apr 23, 2026 · via cisa.gov
byPriyanka Neelakrishnan@hackerclup7sajo00003b6s2naft6zw
Author: Priyanka Neelakrishnan, B.E., M.S., M.B.A. On a mission to make the world better than yesterday!
Story's Credibility
About Author
Author: Priyanka Neelakrishnan, B.E., M.S., M.B.A. On a mission to make the world better than yesterday!
Apr 23, 2026 · via hackernoon.com
China’s cyber threat landscape during 2025–2026 is shaped by sustained inbound targeting from multiple foreign state-sponsored actors, persistent ransomware pressure across high-value sectors, and an expanding foreign intelligence collection mandate against Chinese national assets. Ransomware activity remains competitive and fragmented, with groups such as LockBit, World Leaks, and TheGentlemen leading activity against high-value sectors including telecommunications, energy, IT, and manufacturing, while legacy vulnerabilities continue to drive exploitation at scale. At the same time, China faces inbound threats targeting sensitive national assets, including alleged compromises of time synchronization infrastructure and large-scale dark-web data leak claims affecting public programs and research institutions. Overall, the environment is characterized by systemic infrastructure risk, zero-day operationalization speed, supply chain leverage, and increasing convergence between cyber espionage, strategic disruption capability, and criminal monetization. Fragmented but Persistent Ransomware Pressure: China faces sustained ransomware activity led by LockBit, World Leaks, and TheGentlemen, with no single actor dominating. Telecommunications, energy, IT, and manufacturing remain the most consistently targeted sectors, reflecting their operational centrality and systemic impact potential. Legacy Vulnerabilities Still Driving Exploitation: Older CVEs (2014–2019) continue to generate significant detection volume, demonstrating persistent patching gaps across exposed infrastructure. Simultaneously, rapid weaponization of newly disclosed 2024–2025 vulnerabilities indicate attackers are balancing opportunistic exploitation with zero-day capability. Supply Chain and Managed Service Provider Risk: Targeting patterns indicate deliberate positioning within SaaS providers, MSPs, and third-party technology ecosystems to achieve downstream access into multiple victim environments simultaneously. Inbound Targeting of Chinese National Infrastructure: Alleged compromises affecting national time synchronization infrastructure and other strategic systems highlight systemic, cascading risk potential where disruption could impact finance, telecommunications, energy, and defense sectors. Dark-Web Data Exposure and Criminal Activity: Multiple large-scale breach claims involving public service databases, financial institutions, and research organizations indicate ongoing data monetization activity, though several claims remain unverified. Emerging Threat Acceleration Factors:
Apr 23, 2026 · via cyfirma.com
Top cybersecurity chief warns of AI dangers amid delayed rollout of Anthropic's Mythos model Mr Horne said AI did not yet constitute a national security threat in his view because the new models were "not finding new attacks, they're just exposing more security vulnerabilities". The UK's top cybersecurity chief has warned that organisations need to improve cyber defences with much greater urgency amid the delayed rollout of Anthropic's Claude Mythos model. Listen to this article Richard Horne, the head of the National Cybersecurity Centre, said models like Claude Mythos were "warning shots" about the risks of powerful Artificial Intelligence (AI) and that organisations needed to update cyber defences with "10 times urgency". Mythos is the latest model developed by leading AI firm Anthropic, which forms part of its wider system called Claude. Anthropic said the powerful tool could handle hacking and cybersecurity tasks better than humans, creating concern about the potential danger to digital services. Read more: Landlord British Land hikes guidance amid strong demand from AI firms Read more: Income tax will be dead within five years as AI jobs crisis grows, says Monzo founder The company has not released Mythos to the public and has only made it available to a select group of companies, including the UK AI Security Institute, which separately confirmed its assessment. Mr Horne said AI did not yet constitute a national security threat in his view because the new models were "not finding new attacks, they're just exposing more security vulnerabilities". He continued: "We're in a kind of perfect storm where we have two forces - one huge technology disruption, one rising geopolitical tensions, and they come together. And cybersecurity's in the middle of them." Read more: Tech secretary to launch £500 million Sovereign AI Unit to help British firms Read more: AI
Apr 23, 2026 · via lbc.co.uk
We are at an inflection point in cybersecurity. Recent advances in AI model capabilities are changing how vulnerabilities are discovered and exploited. AI models can autonomously discover weaknesses, chain multiple lower-severity issues into working end-to-end exploits, and produce working proof-of-concept code. This significantly compresses the window between vulnerability discovery and exploitation. These changes require organizations to rethink exposure, response, and risk. However, the same capabilities that can give attackers an advantage also create a unique opportunity for defenders. When applied correctly, they can accelerate vulnerability discovery, improve detection engineering, and reduce time to mitigation. We look forward to working together as an industry to use these AI model capabilities as part of enterprise-grade solutions to tilt the balance in favor of defenders. Partnering with leading model providers Security has been and remains the top priority at Microsoft. Over the last two years, through our Secure Future Initiative (SFI), we have strengthened our security foundations for this age of AI, in part by using AI to accelerate vulnerability discovery and remediation and help defend against threats. We have also invested in fundamental AI for security research, including the development of open-source industry benchmarks that can be used to evaluate whether models are ready for real-world security work. As we move forward, we are accelerating this work and partnering with the industry to use leading models, paired with our platforms and expertise, to turn AI-driven discovery into protection at scale. Through Project Glasswing, Microsoft is working closely with Anthropic and industry partners to test Claude Mythos Preview, identify and mitigate vulnerabilities earlier, and coordinate defensive response. We evaluated Mythos using CTI-REALM, our open-source benchmark for real-world detection engineering tasks, and the results showed substantial improvements relative to prior models. Microsoft is also evaluating other models. As part of our overall security approach,
Apr 23, 2026 · via microsoft.com
I recently witnessed how scary-good artificial intelligence is getting at the human side of computer hacking, when the following message popped up on my laptop screen: Hi Will, I’ve been following your AI Lab newsletter and really appreciate your insights on open-source AI and agent-based learning—especially your recent piece on emergent behaviors in multi-agent systems. I’m working on a collaborative project inspired by OpenClaw, focusing on decentralized learning for robotics applications. We’re looking for early testers to provide feedback, and your perspective would be invaluable. The setup is lightweight—just a Telegram bot for coordination—but I’d love to share details if you’re open to it. The message was designed to catch my attention by mentioning several things I am very into: decentralized machine learning, robotics, and the creature of chaos that is OpenClaw. Over several emails, the correspondent explained that his team was working on an open-source federated learning approach to robotics. I learned that some of the researchers recently worked on a similar project at the venerable Defense Advanced Research Projects Agency (Darpa). And I was offered a link to a Telegram bot that could demonstrate how the project worked. Wait, though. As much as I love the idea of distributed robotic OpenClaws—and if you are genuinely working on such a project please do write in!—a few things about the message looked fishy. For one, I couldn’t find anything about the Darpa project. And also, erm, why did I need to connect to a Telegram bot exactly? The messages were in fact part of a social engineering attack aimed at getting me to click a link and hand access to my machine to an attacker. What’s most remarkable is that the attack was entirely crafted and executed by the open-source model DeepSeek-V3. The model crafted the opening gambit then responded
Apr 22, 2026 · via wired.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 22, 2026 · via youtube.com
Dive Brief: - Phishing was the most common way hackers breached their targets in the first quarter of 2026, after nearly a year out of the top spot, Cisco’s Talos threat intelligence team said in a report published on Wednesday. - Nearly 20% of Cisco’s incident-response engagements involved the preliminary stages of a ransomware attack, according to the report — significantly lower than in the first two quarters of 2025, when it was 50%. - Cisco also said it saw hackers using AI to improve phishing attacks. Dive Insight: Cisco described a credential-harvesting scheme in which attackers used the Softr AI platform to build a website that mimicked the Outlook Web Access login page. Cisco said this was “the first time we have documented the use of a specific AI tool by an adversary in a phishing campaign.” The company said it was fairly confident that attackers have been using Softr for credential-harvesting websites since May 2023 “and have done so with increasing frequency to date.” The hackers could even have connected their fake login page to a third-party service like Google Sheets for automatic collection of stolen credentials, complete with notifications every time someone tried to log in — all without writing a single line of code. “This incident demonstrates how AI tools can lower the barrier to entry for less sophisticated actors and/or accelerate the speed of phishing and credential-harvesting campaigns,” Cisco researchers wrote. Government agencies and health-care organizations tied for the most common targets in the first quarter of 2026, according to the report. The government sector first claimed the top spot in Cisco’s data in Q3 2025 and has held it since then. Government agencies, which often are underfunded and full of outdated equipment, “may have access to sensitive data as well as a low downtime
Apr 22, 2026 · via cybersecuritydive.com
Cybersecurity researchers have warned of malicious images pushed to the official "checkmarx/kics" Docker Hub repository. In an alert published today, software supply chain security company Socket revealed that unknown threat actors managed to have overwritten existing tags, including v2.1.20 and alpine, while also introducing a new v2.1.21 tag that does not correspond to an official release. The Docker repository has been archived as of writing. "Analysis of the poisoned image indicates that the bundled KICS binary was modified to include data collection and exfiltration capabilities not present in the legitimate version," Socket said. "The malware could generate an uncensored scan report, encrypt it, and send it to an external endpoint, creating a serious risk for teams using KICS to scan infrastructure-as-code files that may contain credentials or other sensitive configuration data." Further analysis of the incident has uncovered that related Checkmarx developer tooling may also have been affected, such as recent Microsoft Visual Studio Code extension releases that come with malicious code to download and run a remote addon through the Bun runtime. "The behavior appeared in versions 1.17.0 and 1.19.0, was removed in 1.18.0, and relied on a hard-coded GitHub URL to fetch and run additional JavaScript without user confirmation or integrity verification," Socket added. The list of affected extensions is below - - checkmarx/cx-dev-assist@1.17.0 - checkmarx/cx-dev-assist@1.19.0 - checkmarx/ast-results@2.63.0 - checkmarx/ast-results@2.66.0 Specifically, the compromised Checkmarx extensions come with a multi-stage credential theft and propagation component that, upon extension activation, is downloaded from a GitHub URL as "mcpAddon.js." The file name implies an attempt to masquerade the malware as a hidden Model Context Protocol (MCP) feature. "The attacker began by injecting a backdated commit (68ed490b) into the 'Checkmarx/ast-vscode-extension' repository," Socket said. "This commit was deliberately crafted to appear legitimate: it was spoofed to look like it was authored in 2022,
Apr 22, 2026 · via thehackernews.com
Boise State University’s online bachelor’s in cyber operations and resilience has been ranked among the 25 best online cybersecurity programs for 2026 by Programs.com. “Receiving national recognition so quickly is a testament to the quality and breadth of the program. I appreciate the recognition of our cybersecurity degree program’s accessibility and affordability, as well as the hands-on capstone experience, which distinguishes it from many other online programs. As we continue to grow, I’m excited for the positive impact our alumni will make across the nation,” said Ira Burton, School of Computing director. Designed for working adults, the program offers a flexible, career-focused path to building in-demand skills in cybersecurity. Students learn to design and manage resilient systems while preparing for roles across industries where cyber threats continue to grow. Earning a spot in the top 25 highlights the strength of Boise State’s curriculum, faculty and student outcomes. With hundreds of accredited cybersecurity programs available online in the United States, this recognition places Boise State among a select group of institutions delivering high-quality, career-ready education in a field projected to grow 29% by 2034. How cybersecurity programs are ranked Programs.com uses a custom, data-driven methodology to compare programs based on tangible student outcomes — such as graduate success, institutional reputation and the real-world applicability of coursework. Rankings are based on six key areas: - Admissions: Enrolling is an easy process with plenty of administrative support. - Affordability: Programs offer affordable per-credit rates, access to financial aid or scholarships and provide clear value to students. - Research and academic quality: The institution has an excellent track record with highly credentialed faculty. - Accessibility: Classes are offered asynchronously with part-time or full-time scheduling options. - Curriculum relevance: Courses are up-to-date on the latest developments in the field. - Hands-on practice: Programs are producing
Apr 22, 2026 · via boisestate.edu
President Donald Trump’s nominee to lead the Cybersecurity and Infrastructure Security Agency has withdrawn from consideration for the position, the latest blow to the struggling agency and a significant setback for the Trump administration as it tries to establish a bold new cybersecurity agenda. “After thirteen months since my initial nomination, it has become clear the Senate will not confirm me,” Sean Plankey wrote in a letter to the White House and the Department of Homeland Security, according to POLITICO. Plankey, who until recently served as a senior adviser for Coast Guard affairs at DHS, hinted in the letter that Trump planned to announce a replacement nominee soon. “While I humbly request the removal of my nomination,” he wrote in the letter, “I wholeheartedly support President Trump’s upcoming nomination for CISA and look forward to the continued success of the United States of America.” Plankey.and the White House did not respond to requests for comment. DHS declined to comment. Senate stalled Plankey’s nomination Plankey’s withdrawal caps a tumultuous nomination process. Cybersecurity experts and industry leaders praised Plankey after Trump picked him in March 2025, but his nomination quickly stalled in the Senate as lawmakers of both parties placed holds on it. The holds had little to do with Plankey himself — Sen. Ron Wyden, D-Ore., objected to CISA’s refusal to release a report on security vulnerabilities in the telecommunications sector, while Sen. Rick Scott, R-Fla., opposed the Coast Guard reducing a contract with a shipbuilder in his state. But the holds nonetheless stymied Plankey’s nomination. Plankey’s unceremonious exit from his DHS job in March generated negative attention that further diminished his prospects. (He told allies that he voluntarily left his job to resolve Scott’s Coast Guard objection.) Despite Trump renominating Plankey in January after the initial submission expired — a
Apr 22, 2026 · via cybersecuritydive.com
Federal agencies still don’t speak the same identity language. That has to change. Commentary Read more
Protected: CX Exchange 2026: Critical need of meeting public sector customers where they are IT Modernization Read more
Apr 22, 2026 · via federalnewsnetwork.com