David DiMolfetta

@ddimolfetta.bsky.social

Nextgov/FCW cybersecurity + intelligence reporter. Tips: ddimolfetta@govexec.com Signal: @ djd.99 X/Twitter: @ddimolfetta

White House will soon unveil a program designed to help protect water providers from cyberattacks, which comes as multiple states face hacking attempts on their water systems that some officials suspect may be tied to Iran. Confirming Politico: www.nextgov.com/cybersecurit...

White House to soon launch water provider cyber protection program

The plans come as several states face water system intrusions from what some official suspect could be linked to Iran.

nextgov.com

NEW -> Trump’s new plan to enlist private companies to disrupt cybercriminals abroad may face a fundamental problem when it comes to Russia: distinguishing criminal hackers and state-backed operatives, former officials + experts tell me. www.nextgov.com/cybersecurit...

The Russian hurdle in Trump’s new offensive cyber program

The White House wants private companies to help take down cybercriminals overseas. But in Russia, the line between criminal hackers and the government is difficult to draw.

nextgov.com

NEW —> Federal systems increasingly likely to face accidental AI breach after Hugging Face, experts say “If the same chain of events began again … there is little reason to assume a federal agency would be spared.” www.nextgov.com/cybersecurit...

Federal systems increasingly likely to face accidental AI breach after Hugging Face, experts say

Former officials and security experts say aged systems, contractors and agency AI adoption could open similar paths into government networks.

nextgov.com

NEW: Amid state water hacks, CISA is still finding water system controls exposed to the internet with no password or only default credentials, acting director Nick Andersen told me on sidelines of Black Hat conference today. www.nextgov.com/cybersecurit...

CISA still finds water system controls exposed online amid multistate hacks

The agency is working with the FBI to help victims but is not attributing the cyber intrusions to any group, acting director Nick Andersen told Nextgov/FCW.

nextgov.com

LAS VEGAS — The rise of autonomous AI systems capable of finding and exploiting software flaws is putting serious pressure on governments to treat cyberattacks as inevitable events rather than rare emergencies, Western officials said Wednesday. www.nextgov.com/cybersecurit...

AI advances are pushing governments to treat cyberattacks as routine, Western officials say

The remarks underscore a grim outlook for cyberdefenders showing that AI systems are able to exploit vulnerabilities faster than governments can patch them.

nextgov.com

NEW: Over the last few months, Meta has run dozens of paid ads that included AI-generated CSAM. The ads, some of which were linking out to “nudify” apps, targeted men in the US, UK, and a dozen European countries. Some were running in the last few days

Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery

More than 50 offending image and video ads were published across Facebook, Instagram, Messenger, or Threads, according to Meta’s ad library data. Some ran as recently as this week.

wired.com

Internal documents show ICE's DNA collection has skyrocketed in the second Trump administration. Now, the genetic information of hundreds of thousands of people never convicted of a crime–including children–are held in an FBI criminal database forever.

ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children

Internal documents show ICE's DNA collection has skyrocketed in the second Trump administration. Now hundreds of thousands of people never convicted of a crime are in an FBI criminal database forever.

wired.com

First in Nextgov/FCW -> Federal employees and contractors whose sensitive data was stolen in the massive OPM breach a decade ago would receive identity protection for the rest of their lives under new bicameral legislation being introduced today: www.nextgov.com/cybersecurit...

Lawmakers propose giving 2015 OPM breach victims identity protection for life

The federal government’s coverage for 22.1 million people hoovered up in the China-linked breaches is scheduled to end Sept. 30.

nextgov.com

North Korea-linked hackers has been tied to four open-source software compromises dating back to March 2025, Amazon researchers said Wednesday, significantly expanding the known scope of DPRK’s efforts to access trusted code environments www.nextgov.com/cybersecurit...

Amazon uncovers broad North Korean hacking campaign against open-source software

New findings connect the same Pyongyang-backed group to four compromises dating to 2025, revealing a larger operation than previously known.

nextgov.com

House Intel Ranking Member Himes tells me providers are still complying with FISA Section 702 requests despite statutory lapse in June: “I’m not sure I’m up to the minute, but last I heard last week was they are continuing to comply with requests, which is good.”

NEW: The US Secret Service is examining an apparent Iranian video that claims to have mapped President Trump's motorcade routes in Florida and New York and identifies potential opportunities to target him. Agency is "aware of it and we're looking into it." www.nextgov.com/cybersecurit...

Secret Service is examining apparent Iranian video outlining Trump motorcade routes, assassination opportunities

The agency said it is looking into the Persian-language video, which uses polished, apparently AI-generated graphics to depict supposed motorcade routes in Florida and New York.

nextgov.com