The White House has a new memo on involving private cybersecurity companies in US defense against AI-driven hacks, vishing, and other attacks:
Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom. Through Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I directed the Federal Government to take various actions to combat cyber‑enabled crime harming American citizens. This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector.
Chris Nyhuis, CEO of Vigilant, released the following comments that all organizations should follow:
It’s the right move. But it quietly changes the role of private cybersecurity companies in American national security. The biggest question isn’t whether America has the technical capability to fight back. It’s whether we establish the doctrine necessary to do it without making a cyber incident worse.
I support this. America has extraordinary cyber capability sitting in the private sector, and we should be putting some of that capability into the fight. But offensive capability without disciplined rules creates its own risk. Before America acts, we need to prove who we’re dealing with, contain the original intrusion, understand the escalation risk, and then decide what action actually accomplishes the mission.
The forthcoming federal operating rules need to establish a simple doctrine:
PROVE > CONTAIN > DECONFLICT > ACT > PROTECT
1. PROVE: “EVERYBODY WANTS TO KICK THE DOOR DOWN. SOMEBODY STILL HAS TO PROVE IT’S THE RIGHT DOOR.”
Cyber attribution has always been difficult. But the consequences of getting attribution wrong are about to become significantly greater.
“Cybersecurity companies use terms like ‘high confidence’ all the time. That’s one thing when the result is a threat-intelligence report. It’s something entirely different when that assessment becomes the basis for an operation against somebody else’s infrastructure.”
Attackers also understand how attribution works and can attempt to manipulate the evidence defenders rely upon. Infrastructure can be shared or compromised. Tools can be copied. Malware can be planted. Indicators can be manufactured. That creates a potentially dangerous scenario:
“Imagine you’re a foreign adversary and you can make America believe your enemy attacked us. If our attribution process isn’t strong enough, you don’t have to attack your enemy yourself. You try to manipulate us into doing it for you.”
Nyhuis believes the program should therefore establish one forensic attribution standard for every participating company.
“One company’s telemetry cannot become America’s definition of truth.”
Attribution should be independently corroborated and then subjected to an adversarial review in which another team actively attempts to prove the attribution wrong.
“Before you ask, ‘Why do we believe it’s them?’ put somebody in the room whose job is to prove that it isn’t.”
2. CONTAIN: “NEVER OPEN A SECOND FRONT WHILE THE ATTACKER IS STILL INSIDE YOUR PERIMETER.”
Correct attribution isn’t enough. Before an offensive operation begins, Nyhuis believes there is another question that has to be answered: Have we actually contained the original intrusion?
Removing malware, restoring a compromised server or blocking the attacker’s known access does not necessarily mean the attacker is gone. The adversary may still possess valid credentials, persistence mechanisms, undiscovered access paths or other footholds inside the victim’s environment.
“Before you start talking about going after somebody, you’d better know whether you’ve actually contained the original intrusion.”
Launching an offensive operation before containment has been established could turn one cyber incident into a two-front fight.
“Never open a second front while the attacker is still inside your perimeter.”
If the attacker retains access when their infrastructure is disrupted, they may already possess everything necessary to retaliate from inside the victim’s environment.
“Think about the position you’ve just created. You’re attacking outward while the adversary may still be operating inward. They don’t have to break back into your network to retaliate — they may already be there.”
The attacker could destroy evidence, steal additional information, establish new persistence, disrupt operations, or deploy destructive malware using access they already possess. That is why containment status and retaliation risk should be part of the government’s operational approval process.
“Offensive cyber doesn’t make incident response less important. It makes disciplined incident response more important.”
Containment also does not necessarily mean immediate eradication. There may be legitimate investigative or intelligence reasons to knowingly maintain visibility into an adversary. The critical distinction is whether continued adversary access is known and intentional or simply undiscovered.
“You can make a deliberate decision to observe an attacker who’s still inside. That’s very different from launching an offensive operation because everybody incorrectly assumed the attacker was gone.”
3. DECONFLICT: “THE TECHNICALLY CORRECT ACTION CAN STILL BE THE OPERATIONALLY WRONG ACTION.”
A cyber target rarely exists in isolation. The same infrastructure could be part of a corporate incident response, federal criminal investigation, intelligence operation, foreign-partner investigation or an active case involving victims.
Before private operators act, they need to know who else may already be operating in that environment, and what could be damaged by taking action.
“Cyberspace doesn’t put up a sign telling you that somebody else is already working the case.”
Nyhuis believes government deconfliction should therefore be a mandatory gate before offensive action. That becomes particularly important when an investigation involves live victims.
“If taking down a server destroys an evidence chain, alerts an offender or puts a victim at greater risk, you’ve won the technical battle and potentially lost the actual mission.”
The question cannot simply be whether an operator can disrupt the target. It has to be whether disrupting the target at that moment advances the larger mission.
“The technically correct action can still be the operationally wrong action.”
4. ACT: “OFFENSE NEEDS AN OBJECTIVE, NOT JUST A TARGET.”
Once attribution, containment, and deconfliction have been established, there is still one more question before action: What exactly are we trying to accomplish? Surveillance, intelligence collection, disruption, denial, degradation and destruction can produce very different consequences.
“The objective can’t simply be, ‘We found the bad guy, now hit him.’ What outcome are we trying to create? What happens when they respond? And what does success actually look like?”
An operation designed to collect intelligence should be evaluated differently from one intended to disrupt infrastructure. An operation intended to temporarily deny capability is different from one intended to permanently destroy it. And every action creates the possibility of a reaction.
Nyhuis believes escalation therefore needs to be evaluated as part of the operational decision—not after the operation has already begun.
“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act.”
Offensive cyber capability is ultimately a tool. The mission should determine how—and whether—that tool is used.
5. PROTECT: “IF AMERICA AUTHORIZES PRIVATE CITIZENS TO ENTER THE FIGHT, WHAT HAPPENS WHEN THE FIGHT FOLLOWS THEM HOME?”
There is another side of this program that Nyhuis believes cannot be an afterthought: Who protects the private-sector people conducting these operations? The individuals carrying out authorized operations may be private-sector cybersecurity professionals—not military personnel, federal law-enforcement officers, or diplomats.
That distinction matters.
“If the United States authorizes a private cybersecurity professional to disrupt a foreign criminal organization on America’s behalf, we need to think seriously about what happens to that person afterward.”
The United States may view the individual as an authorized participant in a lawful government-directed operation. The organization being targeted may see something much simpler: The person who attacked them. And the risk may not end when the operation does.
“Cyber operations don’t necessarily end when somebody closes the laptop.”
An operator who helps disrupt a sophisticated foreign criminal organization could potentially become a target for retaliation, identification, doxxing, intimidation, or other threats.
International travel raises another set of questions. What happens when that private-sector operator travels overseas months or years later? Could a foreign jurisdiction investigate or seek to detain the operator based on its own laws? What assistance would the United States provide? What happens if the criminal organization identifies the operator or their family?
These are questions the program should answer before the first operation is authorized, not after something goes wrong.
“We shouldn’t discover the government’s responsibility to these people when the first American cyber operator gets detained at a foreign airport or targeted because of an operation our government asked them to conduct.”
Nyhuis believes the framework should explicitly address operator identity protection, operational security, physical-security risk, foreign legal exposure, international travel, threat monitoring, and government assistance if an authorized operator is threatened or detained.
This isn’t an argument against using private-sector operators. It’s an argument for recognizing what America is asking them to do.
“If America asks private citizens to accept personal risk while conducting a U.S.-authorized cyber operation, then America needs to define what protection follows that authorization.”
Because bringing private cybersecurity professionals into national-security operations creates responsibilities in both directions.
“We need rules protecting America from a bad operation. But we also need rules protecting the Americans we’re asking to conduct a good one.”
THE DOCTRINE
The framework Nyhuis believes should govern private-sector offensive cyber operations can be reduced to five principles:
- PROVE
Do we have forensic evidence that identifies the right adversary?
- CONTAIN
Is the original attacker still inside — and what could they do if we escalate?
- DECONFLICT
Who else is operating, investigating or potentially at risk if we act?
- ACT
What outcome are we trying to achieve, what response should we anticipate, and is offensive action the right tool?
- PROTECT
What responsibility does the United States assume for the private citizens it authorizes to conduct these operations?
“America absolutely needs the capability to go after foreign cybercriminals. But capability needs doctrine. Prove who did it. Contain the original intrusion. Understand the escalation risk. Then decide whether and how to act — and protect the Americans we authorize to do it.”
UPDATE: John Strand, Owner, Black Hills Information Security, Inc. had this comment:
“This article is both exciting and concerning at the exact same time. It genuinely feels like the cyber equivalent of letters of marque, where private industry is authorized to conduct specific, targeted operations on behalf of the United States government.
There are a number of questions that immediately come to mind. How will oversight work? What are the limits of these authorities? Who is responsible for ensuring those limits aren’t exceeded? How does this fit within international law? Those are all critical issues that need to be answered before a program like this reaches full maturity.
“That said, it’s also important to acknowledge the strategic reality. Our adversaries are already operating this way. We’ve seen multiple reports of China leveraging private cybersecurity companies to conduct offensive cyber operations. Russia has long relied on so-called private hackers who carry out activities that align with government objectives. When our adversaries embrace a model that we refuse to consider, it can leave the United States at a strategic disadvantage.
“For that reason, I think this is a positive step, particularly for strengthening U.S. offensive cyber capabilities. At the same time, it has to be implemented carefully. Strong oversight and clearly defined legal boundaries are essential if this model is going to be successful.
“There’s another issue that deserves attention as well. If private security companies are going to participate in these operations, what level of legal protection and indemnification will they receive? Before any company signs a contract to perform offensive cyber activities on behalf of the U.S. government, those questions need clear answers.
“There’s a lot to unpack here, and I expect the next 60 to 90 days will determine not only how this proposal evolves, but also how the relationship between government and private industry develops in the offensive cyber space.”
Jeremiah Fowler, Researcher for Black Hills Information Security, Inc.:
“I personally see this as a positive step in combating cybercrime because it recognizes that some of the best technical expertise is outside of the government.
“The private sector cybersecurity community brings a wide range of skill sets and many have dealt with the aftermath and active defense from these threats on a daily basis. Cybercriminals and state sponsored groups have been attacking US companies and assets for years causing billions of dollars in damages and it’s good to see the gloves come off. Cybercriminals have benefited for years from jurisdictional boundaries and the difficulty of pursuing threat actors operating overseas and this program could be a game changer.
“Speed important in terms of cybersecurity and the perception is that government processes can be slowed down by bureaucracy. Criminal infrastructure can appear, move, and disappear in hours so a public-private model could help bridge that gap of speed and efficiency. Another benefit is information sharing. Private companies often see pieces of an attack that government agencies may not see, while law enforcement and intelligence agencies possess information unavailable to the private sector.”
Donald McFarlane, Advisory Board Member, Xcape, Inc.:
“This is not cyber vigilantism. It connects private-sector visibility and capability to lawful federal authority and oversight.
“This is a significant evolution of the public-private cyber partnership. We’re moving beyond simply sharing threat intelligence to creating a pathway by which threat information acquired through normal business activities, along with threats identified by state and local government, can feed proposed operations for federal approval.
“Capability is not going to be the scarce resource. Target validation, competing intelligence equities and deconfliction will be. The NCC is going to be busy. The secret’s in the deconfliction.”
Corey Ham, Director of Continuous Pentesting, Black Hills Information Security, Inc.:
“My primary concern is the security of these contractors. Giving more entities access to sensitive information increases the likelihood that it can be compromised. Most of the information we have on Chinese state-sponsored hacking similar to this is from data leaks and breaches affecting contractors like I-Soon, for example. I worry that both nation states and crime groups will compromise the contractors who are targeting them, and access information they should not be able to access, like forensic data from other targets or classified data.”
What the latest Lazarus attack says about the limits of EDR
Posted in Commentary with tags Microsoft on August 14, 2026 by itnerdTwo experts get into why Lazarus exploiting a Windows zero-day is particularly concerning despite the vulnerability’s “Important” CVSS rating. And how kernel-level rootkits like FudModule can undermine the security tools defenders rely on, and what organizations can do when patching or traditional mitigations aren’t immediately possible.
John Strand, Owner, Black Hills Information Security (https://www.linkedin.com/in/john-strand-a1b4b62)
“This story highlights an important shift in how organizations need to think about defense. Effective cybersecurity can no longer be reduced to firewall rule changes, patching, and configuration updates. Those remain important, but they’re no longer sufficient on their own.
“Security teams need to start training for the moments when those traditional options aren’t available. What happens when a critical system can’t be patched? What happens when operational requirements prevent you from making firewall changes? Those situations are becoming increasingly common, especially in legacy environments and critical infrastructure.
“That’s where compensating controls become essential. Organizations should be regularly exercising these scenarios and asking, ‘What can we do today to reduce risk while we wait for a patch or a permanent fix?’ Whether it’s increased monitoring, network segmentation, deception technologies, stricter access controls, or enhanced threat hunting, teams need to understand which defensive options are available and when to deploy them.
“The goal of compensating controls isn’t to eliminate the risk. It’s to buy time. As zero-day vulnerabilities continue to emerge at a faster pace, organizations need strategies that slow attackers down and reduce their opportunities while vendors develop patches and defenders work to implement them.
“The organizations that will be most successful over the next several years won’t necessarily be the ones that patch the fastest. They’ll be the ones that have rehearsed how to operate safely when patching isn’t immediately possible.”
Denis Calderone, CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)
“Lazarus has now exploited use-after-free vulnerabilities in Windows built-in drivers three times in two years to deploy the same rootkit. They went from appid.sys to AFD.sys to AFD.sys again. For a while, the standard playbook for getting kernel access was bring-your-own-vulnerable-driver: load a signed but buggy third-party driver, exploit it, get kernel privileges. Defenders adapted with driver allowlisting. Lazarus adapted by finding bugs in drivers that Windows ships by default. AFD.sys handles every socket operation on every Windows machine. You can’t blocklist it.
“Once the use-after-free fires, the attacker gets a kernel read/write primitive, and from there FudModule takes over. This is a rootkit that disables EDR callbacks, zeros out ETW provider registrations, and hides its own processes from the tools security teams rely on. The latest version, v3.1, adds the ability to tamper with Smart App Control, which means the rootkit is evolving faster than the mitigations Microsoft is building around it. And this CVE carries a CVSS 7.0, rated Important. There are 42 Critical patches in the same August Patch Tuesday release. If your vulnerability management program triages by severity score, this one is going to land in the middle of the queue behind remote code execution bugs that nobody has actually exploited yet. That’s exactly backwards.
“CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities catalog on August 11 with a federal remediation deadline of August 25, so needless to say, get this one patched right away, regardless of the CVSS score. Given that Lazarus had at least five weeks of active exploitation before the fix shipped, organizations in defense, aerospace, and adjacent sectors should be particularly diligent and treat anything unpatched since early July as potentially compromised. Check Point’s report includes the full IOC list covering file hashes, C2 domains, and the specific malware components used in the campaigns. Hunt for evidence of the MISTPEN downloader. It beacons out using Microsoft Graph API and OneDrive traffic, so look for anomalous indicators from workstations that don’t typically use those tools. Also look for unsigned DLLs loaded alongside legitimate PDF viewers and any evidence of ETW provider or kernel callback manipulation. Lazarus has shown that it’s possible to render EDR telemetry useless from the kernel level, and too many defenders still treat their EDR as a single source of truth. That dependency is exactly what FudModule is built to exploit.”
Leave a comment »