The White House issued a presidential memorandum creating a federally supervised program that allows vetted U.S. private companies to support cyber operations against foreign cyber-enabled transnational criminal organizations. The framework will be managed by the National Coordination Center and jointly overseen by officials designated by the Department of Justice and Department of Homeland Security, with participating firms required to contract with DOJ or DHS, disclose relevant commercial ties, and potentially post a $1 million bond or escrow.
The memorandum authorizes both cyber surveillance for covert intelligence collection and cyber effects operations to disrupt, degrade, or destroy criminal infrastructure, but limits activity to non-state criminal groups and requires written government approval, legal review, and multi-agency deconfliction before missions proceed. It also bars operations likely to cause death, serious injury, use of force, or an armed attack under international law, and requires immediate halt-and-report procedures if a U.S. person or domestic system is accidentally affected; agencies were directed to establish operating procedures within 60 days and provide follow-on reporting within 180 days and annually thereafter.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On August 13, 2026, President Trump signed a national security memorandum establishing a formal program for vetted U.S. cybersecurity firms to conduct government-approved cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations. The memorandum set oversight, approval, vetting, and bonding requirements for participating companies.
On August 12, 2026, the White House issued a presidential memorandum creating a federally supervised program that allows vetted US private companies to conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations. The program is to be managed by the National Coordination Center under DOJ and DHS oversight, with written approval, vetting, contracting, and safeguards required for each operation.
In March 2026, the administration first signaled its intent to use private-sector capacity for offensive cyber operations against foreign cybercrime groups through an executive order. The later August memorandum converted that direction into a formal contractor program with explicit authorization for private companies to conduct approved operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
41 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecysecurity.news
Open sourcetomshardware.com
Open sourcemalware.news
Open sourcewhitehouse.gov
Open sourcewhitehouse.gov
Open sourcewhitehouse.gov
Open sourceohchr.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.