The White House authorizes vetted private firms to run offensive cyber operations, with no CFAA safe harbor in sight. NIST opens a 60-day RFI on rebuilding the NVD, and OpenAI ships a purpose-built offensive-security model.
Your weekly briefing on cybersecurity policy affecting vulnerability disclosure and security research.
Top Story
The White House authorizes private firms to hack back, and never touches the CFAA
On August 12, President Trump signed a presidential memorandum, "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," that for the first time lets vetted private US companies conduct offensive cyber operations, both "Cyber Surveillance Operations" and "Cyber Effects Operations," against foreign cyber-enabled transnational criminal organizations. Every operation requires sign-off from two co-Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, who must approve "after coordination with each other." Participating companies must maintain a bond or escrow of "not less than $1 million," forfeited on non-compliance. The Executive Directors have 60 days to publish operating procedures (around October 11) and must file a first status report to the White House within 180 days, then annually. (whitehouse.gov)
The memo requires compliance with 18 U.S.C. § 1030, the CFAA itself, but it does not amend the statute, create a safe harbor, or say a word about vulnerability disclosure or good-faith security research. Crowell & Moring's read, published two days later, names the gap precisely: "The NSPM purports to provide federal criminal immunity but does not appear to offer safe harbor against civil liability." A participating company that inadvertently touches an innocent third party's infrastructure, the firm notes, still faces civil CFAA claims, tort, and IP suits. (Crowell & Moring) Security reaction was blunt: Chris Wysopal called it "a pretty big shift in US cyber policy" and Jason Kitka described the program as "a perpetual motion machine for billable threats" (CyberScoop), while Jake Williams of Hunter Strategy warned that "Americans participating in these operations could easily be classified as non-uniformed combatants while traveling overseas" (TechCrunch).
Why it matters for VDP: The government just built a licensed, contract-based authorization pathway for private offensive access, on purpose, while good-faith defensive research still runs on the same 1986 statute and the same DOJ charging-policy discretion it always has. That asymmetry is the argument for statutory safe harbor, made concrete: Congress authorized nothing here, a memorandum did, and a memorandum can be rescinded on day one of the next administration. Watch the October 11 operating-procedures release for any definitional language about "authorized" access; whatever DOJ and DHS write there is likely to get cited the next time a court has to decide what "authorization" means under § 1030.
Throwback: our full breakdown of what the memorandum does and doesn't say is on the blog; this week adds the legal community's first formal read.
Upcoming Deadlines & Events
| Date | Agency | Event/Deadline | Action Required | Link |
|---|---|---|---|---|
| Aug 24, 2026 | ||||
| US Copyright Office | DMCA Section 1201 petitions due (renew or lose the good-faith security research exemption) | File a renewal or new-exemption petition | ||
Aug 24, 2026csrc.nist.gov** Aug 28, 2026**tapportals.mk.gov.lvSept 1, 2026Cybersecurity News** Sept 11, 2026**digital-strategy.ec.europa.eu** Sept 25, 2026**csrc.nist.gov** Sept 28, 2026**copyright.gov** Sept 30, 2026**federalnewsnetwork.comOct 1, 2026pwn2own@trendmicro.comthezdi.com~Oct 11, 2026whitehouse.govOct 13, 2026federalregister.govPrioritized nearest-first. Two federal comment windows opened this week, September 1 (OpenAI hardware-key mandate) and October 13 (NIST NVD RFI); the DMCA petition deadline (Aug 24) remains the item where community inaction directly costs the community a protection it currently has.
This Week in Policy
Federal Strategy & Regulation
CISA, FBI and international partners warn on Gunra ransomware targeting healthcare and utilities. The joint advisory (AA26-222A), issued August 10 with FBI, DC3, NSA, the Secret Service and South Korea's National Police Agency, describes Gunra as a Conti-derived, ransomware-as-a-service operation gaining initial access via two already-patched vulnerabilities: CVE-2024-55591 and CVE-2025-24472. (CISA)
*Why it matters for VDP:*Both entry-point CVEs were public and patchable well before this advisory. The recurring bottleneck is remediation reaching asset owners, not discovery, the same argument for treating disclosure and patch management as one pipeline rather than two. - CISA adds three actively exploited vulnerabilities to the KEV catalog. CVE-2026-20349 (Cisco Secure Firewall ASA/FTD), CVE-2026-68820 (Windows Ancillary Function Driver for WinSock), and CVE-2026-72898 (Metabase SQL injection) were added August 11, triggering BOD 26-04 risk-based remediation deadlines for federal civilian agencies. (CISA)
CVE & Vulnerability Programs
NIST opens a 60-day RFI on rebuilding the NVD, and names vulnerability disclosure as a first-class subject. Published in the Federal Register on August 12 (Docket 260805-0401), the RFI poses 30 questions across seven topic areas on modernizing the National Vulnerability Database "in the age of artificial intelligence." One entire topic area is titled "Vulnerability Information Dissemination," and a separate question asks how the NVD should improve interoperability with "vulnerability disclosure programs, vendor advisories, threat intelligence providers" and other ecosystem components. Comments closeOctober 13, 2026. (Federal Register)
*Why it matters for VDP:*This is a named, dated, on-the-record channel to argue for disclosure standards inside federal vulnerability infrastructure, not just AI-tooling questions.
Throwback:we covered this RFI in depth on the main blogthe day after it published; this week's addition is where it sits next to the volume story below. - CVE Program leadership: automation and globalization, not new law, is the plan for AI-scale volume. At Black Hat and DEF CON, CISA's Lindsey Cerkovnik said of the CVE Program, "CVE is going to continue to flourish and improve, and I feel very positively about it." The same reporting states GitHub alone, one of more than 530 CVE Numbering Authorities, has published over 7,000 CVE identifiers so far in 2026, and CISA's vulnerability response team is handling 360 to 400 concurrent cases at a time. (Cybersecurity Dive)
*Why it matters for VDP:*The GitHub figure is a rough proxy for how much of the CVE namespace now flows through a single large CNA's pipeline. Scale is being absorbed by delegation rather than new intake capacity, worth watching against this same week's NVD RFI question on dissemination bottlenecks.
AI & Emerging Tech Security
OpenAI ships a purpose-built offensive-security model behind a new vetted tier, and used it to find a real Chrome vulnerability.GPT-5.6-Cyber launched August 10 exclusively inside "Daybreak Red," OpenAI's stricter-vetting offensive tier alongside the existing defensive "Daybreak Blue." It completes 95% of advanced cybersecurity requests, against 1.5% for the standard safeguarded model and 2% under Daybreak Blue. OpenAI says it used the model to find two previously unknown Chrome V8 flaws, one patched asCVE-2026-15903(an out-of-bounds read/write from a skipped integer-conversion safety check), fixed in Chrome 150.0.7871.128. Hardware security keys become mandatory for all individual Daybreak accounts startingSeptember 1, 2026. (Cybersecurity News,NVD)
*Why it matters for VDP:*Frontier offensive capability is now gated behind identity verification and legal attestation, not skill, a new axis dividing the research population by institutional form rather than ability, and it lands on a community that already carries CFAA exposure for doing less. - Sanders tells Altman, Amodei and Zuckerberg to "keep your word" and development. In an August 10 letter, Senator Bernie Sanders argued the three companies should "honour their previous safety commitments and stop development if they can no longer safely control increasingly powerful systems," citing each company's own prior pledges (Anthropic 2023, Meta and OpenAI 2025), and warned he and Senate colleagues "will act" if they do not. (IBTimes UK)
*Why it matters for VDP:*With no statute to invoke, Sanders is converting the labs' own voluntary safety commitments into a political enforcement lever, a preview of the argument structure disclosure advocates should expect to see used against voluntary VDP commitments too.
Legal & Researcher Protections
First formal legal read on the offensive-cyber memo: criminal cover, no civil shield. Crowell & Moring's August 14 client alert is the first substantive practitioner analysis of the memorandum covered in this issue's Top Story, and its central finding, that the apparent criminal immunity does not extend to civil CFAA, tort, or IP exposure, is the detail every researcher-adjacent counsel will be citing next. (Crowell & Moring)
*Why it matters for VDP:*The same civil-exposure gap has been the standing objection to relying on prosecutorial discretion instead of statute for good-faith research. Notable to see a corporate law firm make disclose.io's argument, for a different audience, in the same week.
International Developments
ENISA's CVE root reaches 20 numbering authorities as NATO and an AI startup join. The NATO Cyber Security Centre and AISLE, an AI-focused security firm, became CVE Numbering Authorities under the ENISA Root, bringing it to 20 CNAs (12 recruited directly, 8 transferred from the MITRE Root). ENISA's Hans de Vries tied the expansion directly to AI: "Recent developments in the global cybersecurity landscape, coupled with the emergence of Frontier AI models and their impact on vulnerability discovery and exploitation, have underscored the need to build strong vulnerability management infrastructure and capabilities." (CyberScoop)
*Why it matters for VDP:*The identifier namespace stays singular while its governance goes multipolar, resilience today and a coordination tax later, once reports start routing through roots with divergent disclosure norms. - Apple sends mercenary spyware warnings to users in 110 countries. On August 13, Apple issued threat notifications to targeted users across 110 countries, part of a program that has now reached users in more than 150 countries since it began in late 2021. Recipients are typically journalists, activists, politicians and diplomats "individually targeted because of who they are or what they do." (The Hacker News)
*Why it matters for VDP:*Concrete, ongoing demand-side evidence for the premise the Pall Mall Process exists to address, landing while the industry Code of Practice is still being negotiated behind closed doors with no new public comment window announced this week.
Friends of disclose.io: Trend Micro's Zero Day Initiative
Twenty-one years in, the Zero Day Initiative is still the standing proof that coordinated disclosure works at industrial scale. Running since 2005, and lately badged under parent Trend Micro's TrendAI brand, ZDI buys vulnerability research from independent researchers, reports it to vendors under a published deadline policy, and ships public advisories when the clock runs out. Its disclosure policy gives vendors a standard 120-day coordination window, with tighter clocks where circumstances warrant and an escalation path for vendors who go silent. That is disclosure policy with teeth, enforced by publication rather than statute, and it has been running longer than most of the laws this bulletin tracks have been under reform.
Two reasons to look their way this week:
The Pwn2Own-to-patch pipeline closed another loop on Tuesday. ZDI'sAugust security update review(Dustin Childs, August 11) walks Microsoft's 398-CVE release and flags CVE-2026-62911, an Exchange privilege-escalation bug: "This bug was one of the ones demonstrated at Pwn2Own Berlin, so ignore Microsoft's exploitability and Exploit Code Maturity ratings." A contest demo in May, a coordinated report, a shipped fix in August. That is the model working as designed.Pwn2Own Ireland (Cork, October 6-9) goes exactly where this issue's other stories point. The2026 target listadds two AI categories, AI Infrastructure and AI Coding Agents, plus a first Wellness category for healthcare devices. The same week frontier labs are gating offensive AI capability behind vetted tiers, ZDI is putting AI systems in front of its researcher community with prize money and a vendor-coordination pipeline already attached. Registration closes October 1.
Why they're a friend: every argument disclose.io makes for safe harbor and disclosure norms leans on the empirical record that paying researchers and publishing deadlines produces patches, not chaos. ZDI is a large share of that record. When the NVD modernization RFI covered above asks how federal vulnerability infrastructure should interoperate with disclosure programs, ZDI's two decades of coordination data is what a good answer looks like.
Worth Reading
(runZero, Tod Beardsley): The clearest independent walk-through of the failed NDAA amendment that would have codified the CVE Program in statute, including governance-board mechanics the trade press glossed over.The CVE Program's Future in Congress(TechCrunch, Zack Whittaker): The fullest reporting on the memo, including the "half-baked" criticism and the classified-addendum detail that didn't fit in our Top Story."In a first, US will allow some private firms to carry out cyberattacks"(CyberScoop, Greg Otto): Full context on the ENISA CNA expansion and why a European AI-native security firm now sits inside the same identifier infrastructure as MITRE."NATO and an AI startup can now name and track software vulnerabilities"
Policy Pulse is a weekly bulletin from disclose.io. Keeping the security research community informed on policy that affects our work.
Have a tip or want to contribute? Reply to this email, reach out on Twitter/X, or drop a comment here!