BoletimSecAugust 13, 2026🇵🇹Translated from Portuguese

US Presidential Memo Authorizes Selected Private Companies to Join Federal Cyber Operations Against Foreign Criminal Groups

The United States government has launched a new program that permits carefully selected private companies to take part in cyber operations against foreign criminal organizations. The presidential memorandum authorizing the initiative was signed by Donald Trump on 12 August 2026.

The program will be managed by the National Coordination Center and jointly directed by the Department of Justice and the Department of Homeland Security. Private firms may only participate through formal contracts and will remain under continuous federal direction, control, and supervision.

Authorized activities include network surveillance of criminal groups as well as operations designed to manipulate, interrupt, degrade, or disable digital systems used by transnational organizations. Primary targets encompass infrastructure linked to ransomware, phishing campaigns, financial fraud, and other scams directed at US citizens.

Selection and Contractual Requirements

Companies seeking to join the program must undergo rigorous assessments covering technical capability, operational history, physical security, and personnel reliability. Contracts may require a financial guarantee or deposit of at least US$1 million, which can be forfeited in the event of rule violations. Every individual operation requires written authorization before execution.

Safeguards and Prohibited Outcomes

The memorandum mandates procedures to prevent accidental impact on US citizens, businesses, or systems. Any such incident must trigger immediate cessation of the action and prompt notification to authorities. Activities carrying a risk of death, serious injury, or reaching the threshold of use of force under international law are classified as critical outcomes and cannot be approved by the program’s co-directors.

Final operational guidelines are required within 60 days. The decision represents a notable evolution in government policy by formally acknowledging that leading offensive cyber expertise now resides in the private sector and by establishing a structured channel to leverage that expertise under state oversight.

Related articles

HabrPolicy & Regulation

Why Vulnerability Management Specialists Must Master Compliance: Closing All CVEs but Leaving admin:admin

The article explains how compliance has evolved from a paperwork exercise into a mandatory, heavily penalized process in Russian cybersecurity. New regulations such as FSTEC Order 117, turnover fines for personal data leaks, and Presidential Decree 250 impose strict timelines and personal liability for vulnerability management failures. It outlines three approaches to compliance, from doing nothing to building custom standards based on CIS Benchmarks and local requirements. The text stresses moving from reactive scanning to golden images that embed compliance controls before deployment. It highlights tools like MaxPatrol HCC, RedCheck, and ScanOVAL for automated checks and warns that technical patches alone are useless without proper configuration controls such as strong passwords.

安全客Policy & Regulation

China Public Security Ministry Warns IoT Operators: Default Passwords on Devices Like Bus Stop Displays Violate Cybersecurity Law Even Without Major Incidents

A bus electronic display router in Wuhu, Anhui, was compromised in April 2026 because the device retained factory-default credentials and exposed multiple management ports. The Ministry of Public Security highlighted the case in its Hu Wang 2026 report, stressing that failing to change default passwords and leaving ports open constitutes a violation of the Cybersecurity Law regardless of whether serious harm occurred. The RCtea botnet actively targeted similar routers and cameras across China, infecting 9,827 devices in just six days in January 2026 through Telnet brute-force attacks. Experts from the Chinese Academy of Social Sciences clarified that penalties do not require actual damage and that operators must implement technical measures, retain logs for at least six months, and maintain internal security procedures. Additional cases in Qinghai and Nanchong demonstrated repeated enforcement actions against entities that ignored weak-password remediation orders. The report calls on operators, regulators, and manufacturers to enforce password changes at installation, close unnecessary ports, and apply network segmentation to prevent low-hanging IoT devices from becoming botnet recruits.

HabrPolicy & Regulation

Alfa-Bank Balances Cloud Trust and Zero Trust Models During Migration to Yandex Cloud

Alfa-Bank's head of container and cloud security, Sasha Chertok, detailed how the bank migrated regulated workloads to Yandex Cloud while preserving existing Zero Trust controls. The organization mapped on-premises network segmentation, Active Directory authentication, and firewall policies directly onto Yandex Cloud resources using interconnect links secured with GOST encryption. Responsibility for managed services is shared under a Cloud Trust model, yet the bank retains oversight through Terraform-managed Security Groups, custom CSPM checks, and internal CI/CD gates. User access continues to authenticate via on-premises Active Directory and KeyCloak federations, while authorization leverages granular Yandex Cloud IAM roles. Logging and detection rely on a combination of Yandex Cloud Audit Trail, Cloud Logging, and the YCDR service to compensate for incomplete control-plane visibility. The resulting hybrid architecture now supports 1,500 virtual machines, 100 managed services, and 1,000 identities across multiple environments without disrupting established security processes.

HabrPolicy & Regulation

EnvSpec Naming Standard Introduces Strict Six-Environment Hierarchy for Zero Trust Infrastructure

The EnvSpec Naming 1.0.0 standard proposes replacing ad-hoc hostnames with a strict hierarchical naming system based on environment, perimeter, system, slot and node. It defines exactly six environments—dev, test, stage, prod, infrastructure and workplace—and treats any test or pilot system processing real data as prod. The model projects names into SPIFFE IDs, Kubernetes namespaces, cloud projects and mandatory tags for automated policy enforcement. Rules prohibit direct communication between different linear environments and require all access from workplace devices through dedicated gateways. The standard is published under CC BY-SA 4.0 and includes machine-checkable criteria for compliance.