Profile avatar
ddimolfetta.bsky.social
Nextgov/FCW cybersecurity + intelligence reporter. Tips: [email protected] Signal: @ djd.99 X/Twitter: @ddimolfetta
333 posts 2,366 followers 238 following
Prolific Poster

I was happy to appear on two podcasts out today to discuss the cyber element of the conflict between Iran and Israel, and how the U.S. could be impacted. First, for an episode of iHeartPodcasts’s TechStuff: podcasts.apple.com/us/podcast/t...

According to a DOJ IG report released this week, the Sinaloa cartel identified an FBI official working at the U.S. Embassy in Mexico, tracked him via phone location data, tapped into Mexico’s surveillance camera network, & killed an unspecified number of informants. www.reuters.com/world/americ...

Mandiant is now aware of multiple incidents in the airline sector that resemble Scattered Spider. The industry should button up its call centers where this actor has had a lot of success with social engineering. www.axios.com/2025/06/27/a...

Hawaiian Airlines discloses cyberattack, flights not affected via @bleepingcomputer.com

Potentially very big cybercrime story developing. Hawaiian Airlines and WestJet have been hacked, with the group of nefarious teens that the industry calls Scattered Spider targeting the industry. American Airlines also has technical issues today though it's unclear if it's related.

Good rundown from Eric of the ins and outs that government and industry have felt in cybersecurity land in recent months.

Hawaiian Airlines assured customers that it is still able to safely operate its full flight schedule after a cyberattack took down some of its IT systems This is the second airline to face a cyberattack in the last two weeks after Canada's WestJet therecord.media/hawaiian-air...

Patrick Ware, a senior executive at the National Security Agency, has been named the new top civilian leader at U.S. Cyber Command. therecord.media/patrick-ware...

“Preliminary intelligence assessments provided to European governments indicate that Iran’s highly enriched uranium stockpile remains largely intact following US strikes on its main nuclear sites, two officials have said.” Andrew England & Henry Foy, @financialtimes.com on.ft.com/4kSoxUW

Former Biden cyber chief defends Cyber Trust Mark in the face of FCC review by @ddimolfetta.bsky.social www.nextgov.com/cybersecurit...

"Before she became a Cabinet official, Gabbard found it easy to lob those kinds of critiques at the 'deep state.' Now she’s the president’s principal intelligence adviser, struggling to reconcile the conclusions of career experts with the aims of the president she serves."

DOGE-driven cuts make it harder for the US government to prepare for potential retaliation from Iran, current and former officials say: www.cnn.com/2025/06/26/p...

Top Biden cyber official Anne Neuberger defends testing lab UL Solutions, which is overseeing a new IoT cyber labeling program, as the FCC investigates its links to China. Neuberger says UL "has consumers’ trust and a network of experienced labs." www.nextgov.com/cybersecurit...

First in Nextgov/FCW: Former Biden cyber official Anne Neuberger is backing the Cyber Trust Mark's device-labeling initiative she helped oversee after the FCC recently launched a national security review of the program’s alleged links to China⬇️

25-yr-old Brit Kai West has been unmasked and arrested by French police for being 'IntelBroker'. “Kai West, an alleged serial hacker, is charged for a nefarious, years-long scheme to steal victim’s data and sell it for millions in illicit funds, causing more than $25 million in damages worldwide.”

Confirming CNN + other reports - Preliminary DIA assessment says Iran’s nuclear program has only been set back by some months, undercutting White House claims that Tehran’s nuclear capabilities were obliterated after the strikes over the weekend. www.nextgov.com/defense/2025...

Trump’s bombing didn’t actually destroy the nuclear sites. But it made Americans targets for years.

Iran has built a pernicious offensive cyber capability since Stuxnet that it could wield in retribution against the U.S. More likely, it will authorize minor attacks and make them seem like a big deal. Gift link w/signup email. wapo.st/3FTWzcl

Cybersecurity and Infrastructure Security Agency tells me there are “currently no specific credible threats against the homeland” following the announced Israel-Iran ceasefire agreement.

Cloudflare, CrowdStrike, and Ping Identity end a 2022 project offering free cybersecurity tools to critical infrastructure sectors at risk from Russian attacks (David DiMolfetta/Nextgov/FCW) Main Link | Techmeme Permalink

DUBAI, United Arab Emirates (AP) — Iran says it launched attack on US forces at Qatar's Al Udeid Air Base.

“People working for Israel’s security services who speak Persian, Iran’s primary language, called senior Iranian officials on their cellphones and warned them that they, too, would die unless they ceased supporting the regime of Ayatollah Ali Khamenei…” wapo.st/4ezT8EF

Three cybersecurity firms quietly end their free support for critical infrastructure organizations, saying its use has "subsided" since the height of Russia/Ukraine-related threats. www.nextgov.com/cybersecurit...

New: Over the past decade, Donald Trump has repeatedly claimed that millions of people commit voter fraud to rig elections in favor of his Democratic opponents. Until now these claims have always crashed head on into a brick wall of reality. cyberscoop.com/voter-citize...

Scoop: Cloudflare, CrowdStrike and Ping Identity have ended the Critical Infrastructure Defense Project, launched in 2022 to support critical sectors seen as potential targets of Russia-linked cyberattacks⬇️

I made my first national TV appearance on @newsnation.bsky.social Morning in America to discuss yesterday’s DHS bulletin warning of heightened cyber threats from Iran: youtu.be/qlSNgp9PjGs

DHS terrorism advisory bulletin warns Iran will likely launch cyberattacks against U.S. networks in response to strikes on nuclear facilities → www.nextgov.com/cybersecurit...

WH rejects Hegseth atypical pick for NSA/CYBERCOM chief www.politico.com/news/2025/06...

POTUS, asked today about American IC assessments of Iran’s distance from a nuclear weapon, says “my intelligence community is wrong.” Trump: “Who in the intelligence community says that?” Reporter: “Your Director of National Intelligence, Tulsi Gabbard.” Trump: “She’s wrong.”

US scrambles to bring back VOA’s Persian service amid Iran-Israel conflict politi.co/3HHsTQ4, via @politico.com

Mossad agents sabotaged Iranian defenses as airstrikes began, Israeli official says: www.defenseone.com/threats/2025...

It is already clear that this is not a limited attack on core nuclear sites. The target set is broad and includes top military leadership in a way that Iran will see as regime threatening. The IRGC chief is dead. That is likely to drive more expansive Iranian retaliation.

DNI Gabbard said Tuesday that she wants the federal government to pivot away from developing its own in-house solutions and rely more on the private sector to supply technologies needed for spies and analysts. www.nextgov.com/acquisition/...

"Inside two major U.S. telecom operators, incident response staff have been instructed by outside counsel not to look for signs of Salt Typhoon" bruh... 🤣

Good story here by David on the expanding footprint of Salt Typhoon. If true, this detail in particular confirms what we were told more broadly about the way telcos were publicly messaging their ongoing exposure to the public (i.e. misleadingly) www.nextgov.com/cybersecurit...

US agencies assessed Chinese telecom hackers likely hit data center and residential internet providers – Nextgov/FCW: ‘Inside two major U.S. telecom operators, incident response staff have been instructed by outside counsel not to look for signs of Salt Typhoon, said one of the people’

Most interesting part of this story: "There’s uncertainty among officials about who was impacted by Salt Typhoon. Various agencies ... are in possession of lists of confirmed or potential victims, but it’s not clear if the tallies are consistent..." www.nextgov.com/cybersecurit...

Scoop: U.S. agencies assessed that Salt Typhoon likely hit data center giant Digital Realty and mass media provider Comcast, marking a potentially major expansion of the Chinese hacking group’s initial telecom intrusions discovered last year.⬇️

Better Identity Coalition not pleased with EO removal of digital ID language in prior Biden order

Nextgov/FCW previously reported that Trump White House staff would review parts of Biden's January cyber EO and scrap parts of it they didn't like: www.nextgov.com/cybersecurit... www.whitehouse.gov/fact-sheets/...

New, and sure to be controversial: The firm hired to protect the Harris-Walz campaign's iPhones believes it has seen indication that a handful of high profile Americans' phones — including campaign members'! — were hacked with sophisticated and unidentified spyware.