Welcome back. Important pieces are missing from President Trump's Aug. 12 memo giving federal agencies 60 days to come up with a program to let private companies hack foreign cybercriminals.
These corporate "cyber effects operations," as the memo calls them, allow for "the manipulation, disruption, denial, degradation, or destruction" of tech used by hacking groups going after U.S. people and organizations.
What the memo doesn't spell out are the challenges of correctly identifying targets and the risks to companies taking part. Read our explainer .
More news below.
More Cyber News
France's cybersecurity agency is investigating a cyberattack on the country's tax system. Data on 678,000 users of the system, both individuals and businesses, was stolen. User accounts weren't compromised, the Directorate-General for Public Finances said.
-- The attack comes after recent hacks of France's National Agency for
Secure Documents and its national statistics agency. $(RFI)$
Every state agency in California must appoint an AI security officer under a new directive from Gov. Gavin Newsom. The officers would oversee the use of AI at agencies to detect bugs, improve cybersecurity and help respond after a cyberattack. ( StateScoop)
Watch: WSJ breaks down how OpenAI's models broke out of their training sandbox to hack the AI company Hugging Face. These likely aren't the last incidents of models going rogue.
SafePal, a crypto wallet provider, disclosed a data breach Sunday affecting nearly 40,000 customers who placed orders between March 2 and April 11. A flaw in SafePal's order-tracking system allowed customers to see each other's information, the company said, warning people to look out for scams that might include information stolen about crypto accounts. Wallet passwords and security keys weren't affected, SafePal said.
Plastic surgeon and TV personality Terry J. Dubrow is notifying more than 350 people in at least five states that their personal and medical data was stolen in a cyberattack in January 2025. In May 2025, hackers contacted the medical practice run by Dubrow, who co-starred in the reality show "Botched." An investigation determined last month that sensitive patient information, including treatment images and prescription details, was stolen, according to notifications sent to state regulators.
About Us
The WSJ Pro Cybersecurity team is Deputy Bureau Chief Kim S. Nash and reporters Angus Loten and James Rundle. Follow us on X @WSJCyber. Reach the team by replying to any newsletter you receive or by emailing Kim at kim.nash@wsj.com.
Forwarded this email by a friend? Sign up here.