The US lets private firms go on the cyber-offensive, defenders weaponise prompt injection, Trezor's breach wasn't Trezor's, Belgium's top-trust eID was Swiss cheese, and a tool to map ad-tech.
In this edition
- 01The US just cleared private companies to launch cyberattacks.
- 02Defenders are now weaponising prompt injection too.
- 03Trezor got breached. Except it wasn't Trezor.
- 04Belgium's national eID carried the top EU trust badge. It was Swiss cheese.
- 05A new tool exposes the ad-tech supply chain hiding in your sites.
Get the next GRC Brief in your inbox.
Subscribe to The GRC BriefThe US just cleared private companies to launch cyberattacks.
On August 13, the White House published a presidential memorandum that, for the first time, lets vetted private companies conduct offensive cyber operations against foreign criminal gangs and hackers. It sweeps away decades of US policy, and the computer-crime laws prohibiting private hacking, under which the private sector could defend but never attack. Participating firms could run surveillance, including deploying spyware, and launch disruptive attacks that destroy criminals' systems and data. The guardrails: a 1 million dollar escrow forfeited for breaking the rules, sign-offs from the Justice Department and Homeland Security before any operation, federal supervision throughout, and a ban on targeting Americans or US systems. Guidance on who qualifies is due within two months. Critics call it half-baked, warning of legal challenges, diplomatic blowback if a foreign government says a US company attacked it, and the risk that Americans running these operations could be treated as combatants abroad. It lands amid a US-Iran conflict, attacks on US water utilities, and the wave of autonomous AI-driven attacks.
Source: TechCrunch · White House memorandum, 13 Aug 2026
My take
This is bigger than the headline, and it deserves the reaction. For decades the line was clear: the state attacks, the private sector defends. That line is now gone in the US. Vetted companies can deploy spyware and destroy systems, on the government's behalf but with commercial hands on the trigger. A legitimate market for private offensive cyber just opened, and markets do not stay small or stay put. Other governments will follow, or feel they have to.
The problems are not subtle. Attribution gets murkier, was that a criminal, a nation, or a contractor? Escalation gets easier, and a mistake by a private operator can become a diplomatic incident. And the people doing this work are exposed: a security veteran quoted in the reporting warns that Americans running these ops could be branded combatants abroad and detained, and that the accusation need not even be true to be useful to a foreign government. Escrow and sign-offs are real, but they do not answer what happens when this goes wrong at speed.
For those of us outside the US, this is a geopolitical risk to log now, not later. Retaliation for a private US operation does not politely stay in the US, it hits the interconnected infrastructure everyone shares. If you run a European business, your threat model just gained a new actor: hostile responses to attacks you had nothing to do with. And it rhymes with the sovereignty point I keep making, the rules of the digital world are being rewritten unilaterally, and you are downstream of decisions you get no vote on.
Defenders are now weaponising prompt injection too.
For two years, prompt injection, feeding hidden instructions to an AI to hijack it, has been the attacker's tool. Now defenders are turning it around. As autonomous AI agents increasingly crawl, probe and attack systems on their own, security teams are planting prompt injections as traps: honeypots seeded with instructions a malicious AI agent will read and act on, unmasking and fingerprinting itself in the process, while a human attacker would ignore them. It is deception technology built for the age of machine attackers, the same technique the Gaslight malware used against AI defenders a few months back, now pointed the other way. It sits alongside the harder architectural work, treating every input an agent touches as untrusted and keeping trusted instruction channels separate from untrusted data, that the Five Eyes agencies flagged this year as essential.
Source: Ars Technica · AI deception via prompt injection, Jul 2026
My take
This is the first genuinely encouraging AI-security story I have run in a while, so take the good with the caution. The insight is elegant: an autonomous attacker that reads and obeys natural language can be trapped by planting language for it to read. A human ignores the honeypot's hidden note. A malicious AI agent takes the bait and unmasks itself. For the first time, defenders have a detection technique built specifically for machine attackers.
But do not mistake a clever trap for a strategy. Think of this exactly as you would any deception layer in defense in depth: it catches some attackers, it buys signal, and it fails the moment you rely on it alone. The real work underneath has not changed, treat every input your agents touch as untrusted, keep trusted instructions and untrusted data on separate rails, and monitor what the agent actually does. Prompt injection as a trap is a fine new tool for the box. It is not the box.
Trezor got breached. Except it wasn't Trezor.
Hardware-wallet maker Trezor disclosed a breach exposing the names, addresses, emails and phone numbers of nearly 14,000 customers. Except the breach was not at Trezor. Its systems were untouched and its devices are secure. The data was taken from ShipMonk, its shipping and logistics provider, which was itself breached through a zero-day in Metabase, a third-party analytics tool it uses. So the chain runs Trezor, to ShipMonk, to Metabase, and the same Metabase flaw also hit the laptop maker Framework and the form builder Tally. Trezor is warning customers to expect targeted phishing, since the leaked data is ideal for impersonating banks, exchanges, or Trezor itself. It is the company's second supplier-driven breach, and it came the same week Valve notified Steam customers of data stolen from its shipping partner.
Source: BleepingComputer · Trezor via ShipMonk via Metabase, 13 Aug 2026
My take
Read the headline again: Trezor breached. Read the facts: Trezor was not breached, ShipMonk was, via Metabase. And yet it is Trezor sending the emails, Trezor taking the reputational hit, Trezor's customers getting phished. This is the point I will keep hammering until it lands: your supplier's breach is your breach. Your customers do not know or care who ShipMonk is. They know they trusted Trezor with their address, and now a scammer has it.
And notice the chain has three links, not two, Trezor, ShipMonk, Metabase, which is the part most vendor-risk programmes miss. You assessed your supplier. Did you assess your supplier's supplier? Under NIS2 and DORA, supply-chain risk management is not a box to tick, it is a map you are supposed to actually draw, all the way down to the analytics tool three companies removed from you that is holding your customers' data. If you cannot name your fourth parties, you cannot claim to manage this risk.
Belgium's national eID carried the top EU trust badge. It was Swiss cheese.
At DEF CON last week, researchers from Bay Area Labs revealed that Connective, the browser extension underpinning Belgium's national eID, used by 8 of the country's 10 largest banks, 60-plus government agencies and over 2 million people, was riddled with critical flaws. Any website could silently read a victim's eID and payment-card data, recover their PIN, which the software returned to the page bundled with its own decryption key, and even trigger a drive-by remote code execution: visit a page, it downloads a file, and you are compromised. With a stolen eID signature, an attacker could take over a victim's itsme identity, the layer that logs Belgians into banking, tax and government services. Here is the part that stings: the vendor, Nitro, is a Qualified Trust Service Provider, the highest trust tier the EU's eIDAS regulation defines, and it advertised yearly penetration tests and ISO 27001. The researchers found the flaws using an AI model as a test harness, and were offered a 200 dollar bounty for compromising the entire national eID ecosystem.
Source: Dark Reading · Connective eID flaws, DEF CON, 13 Aug 2026
My take
Sit with the trust badges here. Nitro is a Qualified Trust Service Provider, the single highest tier the EU's eIDAS regulation offers. It advertised yearly penetration tests. It held ISO 27001. And its software let any web page read your national ID, lift your PIN, and run code on your machine. The researchers' own verdict was blunt: it looks like security theater. This is my whole argument in one case study, the certificate is not the control. A QTSP stamp, an ISO badge and a pen-test line on a trust page told Belgian citizens they were safe. The code told a different story, and nobody with the badges had actually looked.
Now the part that should make every practitioner angry. For finding flaws that broke the entire Belgian eID ecosystem, national ID, banking logins, qualified legal signatures, the researchers were offered a 200 dollar bounty. Two hundred dollars. We wonder why critical infrastructure stays broken while defenders burn out, and then we pay the person who quietly saved a nation's identity system less than the cost of the audit that missed the holes. The economics of defense are upside down, and this is exactly what it looks like.
A new tool exposes the ad-tech supply chain hiding in your sites.
A tool worth a look. DecryptAds, launched this week, maps the programmatic advertising supply chain, the sprawl of ad-tech companies that quietly touch every impression on your sites and apps, using the industry's own disclosure files plus data-broker registries and geo-risk data. Its first finding sets the tone: nearly 300 ad-tech companies in its corpus are registered in sanctioned, adversarial or financial-secrecy jurisdictions, Russia, China and offshore havens among them, and they sit in the declared supply of everyday sites and apps, almost certainly without those publishers knowing. There is a free tier, and it exposes an MCP server so you can query the data with your own AI tools.
Source: DecryptAds · Ad-tech transparency launch, 12 Aug 2026
My take
A rare "here is something useful" to close on. If you have ever tried to answer "whose code actually runs on our marketing site," you know the ad-tech supply chain is a black box, and DecryptAds is the first tool I have seen that cracks it open with the industry's own files. The finding that around 300 ad-tech firms sit in sanctioned or secrecy jurisdictions, inside the declared supply of ordinary sites, should reframe how you see it: your ad stack is a third-party supply chain you never vetted, with geopolitical risk baked in, and now it is a bill of materials you can actually pull. Worth an afternoon, especially on the free tier.