BoletimSecAugust 13, 2026🇵🇹Translated from Portuguese

US Presidential Memo Authorizes Selected Private Companies to Join Federal Cyber Operations Against Foreign Criminal Groups

The United States government has launched a new program that permits carefully selected private companies to take part in cyber operations against foreign criminal organizations. The presidential memorandum authorizing the initiative was signed by Donald Trump on 12 August 2026.

The program will be managed by the National Coordination Center and jointly directed by the Department of Justice and the Department of Homeland Security. Private firms may only participate through formal contracts and will remain under continuous federal direction, control, and supervision.

Authorized activities include network surveillance of criminal groups as well as operations designed to manipulate, interrupt, degrade, or disable digital systems used by transnational organizations. Primary targets encompass infrastructure linked to ransomware, phishing campaigns, financial fraud, and other scams directed at US citizens.

Selection and Contractual Requirements

Companies seeking to join the program must undergo rigorous assessments covering technical capability, operational history, physical security, and personnel reliability. Contracts may require a financial guarantee or deposit of at least US$1 million, which can be forfeited in the event of rule violations. Every individual operation requires written authorization before execution.

Safeguards and Prohibited Outcomes

The memorandum mandates procedures to prevent accidental impact on US citizens, businesses, or systems. Any such incident must trigger immediate cessation of the action and prompt notification to authorities. Activities carrying a risk of death, serious injury, or reaching the threshold of use of force under international law are classified as critical outcomes and cannot be approved by the program’s co-directors.

Final operational guidelines are required within 60 days. The decision represents a notable evolution in government policy by formally acknowledging that leading offensive cyber expertise now resides in the private sector and by establishing a structured channel to leverage that expertise under state oversight.

Related articles

AntiMalwarePolicy & Regulation

Russia to Require Independent Lab Testing of Sovereign AI Models for Legal and Traditional Values Compliance

The Russian Ministry of Digital Development is discussing a certification scheme under which developers can submit large generative AI models to accredited independent laboratories. These labs will verify compliance with Russian legislation and traditional spiritual-moral values defined in presidential decree No. 809. Only models seeking official national or sovereign status, which unlocks state support, data access and priority procurement, will undergo the process. Developers must first conduct self-testing according to a risk-oriented methodology and supply architecture details, filtering mechanisms and other documentation. Accredited laboratories will then run benchmarks, attempt prompt-injection attacks and produce evaluation reports, while the final decision remains with MinTsifry. Separate security assessments for government systems will be performed by the FSB and FSTEC Russia. Experts have called for transparent, reproducible tests and periodic re-certification after model updates.

SecuritylabPolicy & Regulation

Why Separate Corporate and Personal Email Accounts: Risks of Mixing Work and Private Communications

Mixing corporate and personal email accounts creates serious security, compliance, and operational risks for both employees and organizations. When employees forward contracts or client data to personal mailboxes to bypass size limits or convenience, copies proliferate beyond company control in phones, backups, and cloud services. After termination, the employer loses any ability to revoke access or audit the data, while personal accounts often lack multi-factor authentication and strong password practices. Russian legislation including Federal Law No. 152-FZ on personal data, the Labor Code, and Federal Law No. 98-FZ on trade secrets requires proper protection of sensitive information. Using work email for shopping, banking, or password recovery exposes the corporate domain to phishing and leaks, while the reverse creates dependency on private accounts for business continuity. The recommended practice is strict separation with unique passwords, MFA on both accounts, and approved corporate channels for file transfer.

AntiMalwarePolicy & Regulation

Yandex Pay App Permanently Removed from App Store Across All Regions Due to Sanctions

The Yandex Pay application has been fully removed from the App Store in every region worldwide. Existing installations continue to operate normally, and the company has confirmed that all client funds remain secure. However, users can no longer download the app or receive updates, prompting Apple device owners to avoid deleting the application. Yandex recommends disabling automatic app updates through iOS settings to prevent any potential loss of functionality. If the app is accidentally removed, the service remains accessible through the web version at pay.yandex.ru, which can be added to the home screen via Safari. The removal occurs amid broader sanctions and information-related restrictions affecting Russian technology services.

AntiMalwarePolicy & Regulation

NSPK Warns of Potential Online Payment Disruptions for Visa and Mastercard Holders Due to Russian Certificate Transition

The National System of Payment Cards (NSPK) has issued a warning that holders of Russian-issued Visa and Mastercard cards may encounter difficulties when making online purchases. The issues stem from NSPK's ongoing transition to Russian security certificates required for authenticating internet resources and establishing secure connections. NSPK recommends that users proactively replace their existing cards with Mir-branded alternatives to avoid payment failures at critical moments. The move aligns with broader efforts toward import substitution and ensuring stable access to payment services amid international sanctions imposed on Russia since 2022. Mir cards will remain fully functional for both in-store and online transactions without any changes. Foreign browsers may display security warnings when encountering the new Russian certificates, though NSPK stresses that these alerts do not indicate compromised resources or data leaks. The transition is described as standard practice among Russian organizations and will not affect payment security, data protection, or overall service operations.