Sign in

Tim Starks

@timstarks.bsky.social
7.6K followers 863 following 491 posts

Senior reporter, CyberScoop, covering spyware, cyber policy and more. Russia-sanctioned. Former Washington Post, POLITICO, CQ Roll Call. @timstarks.02 on Signal. tim.starks@cyberscoop.com. Mastodon timstarks@infosec.exchange, X timstarks, Threads tstarks2.

PostsRepliesMedia
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 22/09/2026
Nearly two of every 10 U.S. water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday. Read more by @timstarks.bsky.social: cyberscoop.com/spycloud-stu...
077
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 24/09/2026
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot program. Read more by @timstarks.bsky.social: cyberscoop.com/gottheimer-a...
033
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 24/09/2026
Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from CISA, a watchdog report published Wednesday found. Read more by @timstarks.bsky.social: cyberscoop.com/dhs-ig-repor...
032
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 24/09/2026
The white paper outlines the components of a “Quality Era” for the program, widely used as the definitive clearinghouse for data on vulnerabilities in software and other products, even as the number of CVEs surges. Read more by @timstarks.bsky.social: cyberscoop.com/cisa-cve-dat...
012
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 25/09/2026
Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of lawmakers wants to make sure it’s protected like it. Read more by @timstarks.bsky.social: cyberscoop.com/biotech-crit...
051
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 25/09/2026
The Justice Department said two leaders of the company have been arrested and face conspiracy to commit wire fraud. Read more by @timstarks.bsky.social: cyberscoop.com/oxygen-foren...
022
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 25/09/2026
The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chairman Ted Cruz, R-Tex., would create a government-industry group to write voluntary best practices. Read more by @timstarks.bsky.social: cyberscoop.com/senate-telec...
032
Tim Starks @timstarks.bsky.social · 24/09/2026
First in CyberScoop: Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks cyberscoop.com/senate-telec...
cyberscoop.com
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Sens. Mark Warner and Ted Cruz introduced bipartisan legislation to establish voluntary telecom cybersecurity standards nearly two years after the Salt Typhoon hack.
020
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 22/09/2026
After the exit of around 1,000 CISA workers, legislation from three top House Democrats orders a force structure assessment like that more common to military branches. Read more by @timstarks.bsky.social: cyberscoop.com/house-democr...
032
Tim Starks @timstarks.bsky.social · 21/09/2026
Nice one from @ksophiewill.bsky.social fedscoop.com/veterans-aff... @fedscoop.bsky.social
fedscoop.com
013
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 18/09/2026
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. Read more by @derekbjohnson.bsky.social: cyberscoop.com/ai-agent-hac...
122
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 18/09/2026
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. Read more by @timstarks.bsky.social: cyberscoop.com/cisa-guidanc...
022
Reposted by Tim Starks
Nicholas Grossman @nicholasgrossman.bsky.social · 17/09/2026
We built some new cyber weapons Ones that, like many cyber weapons, we can’t really control once deployed, though even more so Then we deployed them The cyber weapons did some things we didn’t totally intend This means you’re all going to die and we’re prophets, give us all the money and power
411816
Reposted by Tim Starks
Alberto Fittarelli @fittarelli.com · 17/09/2026
🚨 NEW REPORT: We @citizenlab.ca analyze the covert influence ops run by the Israeli firm BlackCore on behalf of the Angolan government. We obtained access to their training documentation. Their claims are shocking - or are they? citizenlab.ca/research/bla... 🧵
Feature image of the Citizen Lab's Research Note on BlackCore's Influence Operations for Hire.
2169
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 16/09/2026
The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint statement from the agencies Wednesday. www.youtube.com/watch?v=BW0n... More by @timstarks.bsky.social: cyberscoop.com/coast-guard-...
022
Reposted by Tim Starks
Liza Goitein @lizagoitein.bsky.social · 16/09/2026
On Sunday, the Trump administration missed a statutory deadline to declassify a FISA Court opinion from March that reportedly finds more Section 702 compliance issues affecting Americans’ rights. The administration is now in violation of the law. 1/18
34731
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 16/09/2026
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. Read more by @timstarks.bsky.social: cyberscoop.com/whats-next-f...
022
Tim Starks @timstarks.bsky.social · 16/09/2026
Asked on stage "Star Wars or Star Trek," CISA acting director Nick Andersen answers "Star Wars" to applause, but gives a little shoutout to "Next Generation."
120
Reposted by Tim Starks
Ryan Goodman @rgoodlaw.bsky.social · 12/09/2026
“The Court has found that … defendants (through Karen Evans [then-Senior Official Performing the Duties of FEMA Administrator]) acted with the intent to deprive plaintiffs of the use of the Signal chat messages in this litigation.”
5433131
Tim Starks @timstarks.bsky.social · 11/09/2026
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal cyberscoop.com/dot-rule-air...
cyberscoop.com
Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal
A new Department of Transportation rule removes requirements for airlines to provide meal and hotel vouchers if flight disruptions are caused by cyberattacks.
043
Reposted by Tim Starks
Brandy Zadrozny @brandyzadrozny.bsky.social · 11/09/2026
Get in, folks: a new Russian disinfo campaign is targeting the midterms, specifically Democrats, in what seems to be the first attempt by the Kremlin-backed op to meddle in this year’s U.S. elections. They're faking celebrity videos attacking Dems and are...very stupid. www.ms.now/news/russia-...
ms.now
A Russian disinformation campaign is doctoring celebrity videos to meddle in the midterms
The Kremlin-backed operation, known as Matryoshka, has Hollywood actors telling voters to disavow the Democratic Party and vote Republican.
8824551547
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 10/09/2026
Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones. Read more by @timstarks.bsky.social: cyberscoop.com/national-cyb...
021
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 09/09/2026
Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike. Read more by @timstarks.bsky.social: cyberscoop.com/fbi-cyber-di...
123
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 09/09/2026
A bipartisan trio of lawmakers is asking the Treasury Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies. Read more by @timstarks.bsky.social: cyberscoop.com/us-lawmakers...
034
Reposted by Tim Starks
Greg Otto @gregotto.bsky.social · 09/09/2026
In other FBI cyber news @timstarks.bsky.social has an exclusive look at the FBI's cyber strategy which was released today, and more comments from FBI cyber leaders who say AI isn’t doing anything that attention to cybersecurity basics wouldn’t prevent cyberscoop.com/fbi-cyber-st...
cyberscoop.com
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The FBI is unveiling a new cyber strategy addressing AI-powered hacker threats while urging organizations to abandon quarterly updates for continuous, risk-based patching.
042
Tim Starks @timstarks.bsky.social · 09/09/2026
FBI cyber-time the last couple days. New strategy, talking about AI, talking about information sharing. cyberscoop.com/fbi-cyber-st...
cyberscoop.com
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The FBI is unveiling a new cyber strategy addressing AI-powered hacker threats while urging organizations to abandon quarterly updates for continuous, risk-based patching.
111
Reposted by Tim Starks
Erik Hane @erikhane.bsky.social · 02/09/2026
I hear you—and I apologize. That mushroom was one of the poisonous ones, you’re right. That’s not just useful feedback—it’s you setting a boundary.
459531105
Reposted by Tim Starks
Eric Geller @ericjgeller.com · 02/09/2026
Scoop: CISA is ending six free cybersecurity assessments for critical infrastructure operators, significantly reducing the hands-on guidance it offers to those organizations even as it tries to rebuild and reassert its value: www.cybersecuritydive.com/news/cisa-cy...
816876
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 02/09/2026
In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn about standard, commercial VPNs, following letters to federal agency leaders in March and July. Read more by @timstarks.bsky.social: cyberscoop.com/wyden-nsa-co...
033
Tim Starks @timstarks.bsky.social · 02/09/2026
Pegasus, NoviSpy variant spyware found on devices of Serbian activists cyberscoop.com/pegasus-novi...
cyberscoop.com
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
022
Tim Starks @timstarks.bsky.social · 02/09/2026
Read it here first cyberscoop.com/wyden-nsa-co...
cyberscoop.com
Wyden seeks upgraded NSA security guidance on commercial VPN use
Sen. Ron Wyden urges the NSA to update its public security guidance, warning that standard commercial VPNs fail to defend against advanced foreign surveillance.
185
Tim Starks @timstarks.bsky.social · 31/08/2026
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help cyberscoop.com/watershed-25...
cyberscoop.com
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Federal officials and Texas launch Watershed 250, a six-month pilot program partnering with top tech firms to protect water infrastructure against foreign cyber threats.
120
Tim Starks @timstarks.bsky.social · 26/08/2026
Yet more intra- @fedscoop.bsky.social / @cyberscoop.bsky.social namesakery, from @derekbjohnson.bsky.social @ksophiewill.bsky.social @madialder.bsky.social fedscoop.com/login-gov-om...
fedscoop.com
Draft OMB memo mandates agency use of Login-dot-gov on government websites
Federal IT leaders across administrations have wanted a single sign-on service. The memo requires the use of Login but does not bar other forms of authentication.
056
Tim Starks @timstarks.bsky.social · 26/08/2026
First in @fedscoop.bsky.social by @lindseywilkinson.bsky.social with an assist from me: a top DHS official is heading for the exits. fedscoop.com/dhs-cio-depa...
fedscoop.com
DHS CIO Antoine McCord to exit agency
The Anduril alum and Marine Corps veteran joined DHS as its top technology leader in March 2025. He is the latest CIO planning to leave the role amid a slew of other resignations.
025
Reposted by Tim Starks
Zack Whittaker @zackwhittaker.com · 26/08/2026
New, by me: U.S. cyber agency CISA says it observed malicious activity targeting over 100 U.S. water and wastewater systems during July, giving some scale of the ongoing hacks targeting water systems across the United States. (Ad-block bypass: web.archive.org/web/20260826...)
techcrunch.com
CISA confirms hackers targeted over 100 US water systems during July | TechCrunch
The federal cyber agency's warning comes amid a wave of suspected Iran-backed cyberattacks targeting critical water systems across the United States.
0139
Reposted by Tim Starks
Maggie Miller @maggiemiller.bsky.social · 26/08/2026
NEW: The White House is planning to launch a program, likely early next week, to provide free cybersecurity services to water utilities. While this has been in the works for months, it’s being launched following attacks on utilities in at least 12 states. www.politico.com/news/2026/08...
politico.com
White House to unveil program to protect water systems against hackers
The new program follows a cascade of cyberattacks across at least a dozen states that many experts suspect are linked to Iran.
165
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 26/08/2026
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. Read more by @timstarks.bsky.social: cyberscoop.com/cisa-red-tea...
011
Reposted by Tim Starks
Greg Otto @gregotto.bsky.social · 25/08/2026
Joshua Culver, aka “Maverick Young,” allegedly impersonated an NSA elite hacking unit and the Supreme Court chief justice in an attempt to get info out of Indiana officials, including the location of his biological daughter. cyberscoop.com/arrested-man...
cyberscoop.com
Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice
Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that.
052
Reposted by Tim Starks
Greg Otto @gregotto.bsky.social · 25/08/2026
The GTA VI leaks are breaking the internet. Security researchers have seen this before. cyberscoop.com/grand-theft-...
cyberscoop.com
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience.
122
Tim Starks @timstarks.bsky.social · 25/08/2026
A couple stories from me lately: cyberscoop.com/us-treasury-... and cyberscoop.com/watchdog-rev...
cyberscoop.com
Treasury sanctions alleged Iranian hackers as part of ‘economic D-Day’
The U.S. Treasury Department has sanctioned key Iranian cybercriminals targeting critical infrastructure as part of a massive "economic D-Day" campaign against Tehran.
022
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 25/08/2026
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector. Read more by @derekbjohnson.bsky.social: cyberscoop.com/quantum-guar...
011
Reposted by Tim Starks
Alexander Martin @alexmartin.bsky.social · 25/08/2026
New: The British government is seeking new powers that would allow it to ban technology vendors on national security grounds from supplying companies working in the country’s critical sectors — potentially doing so in secret.
therecord.media
UK government seeks powers to secretly block risky tech suppliers
The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.
074
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 22/08/2026
The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. Read more by @timstarks.bsky.social: cyberscoop.com/corca-retail...
011
Reposted by Tim Starks
Greg Otto @gregotto.bsky.social · 20/08/2026
@derekbjohnson.bsky.social with an exclusive to @cyberscoop.bsky.social on dc groups coming together to push for the designation of AI as the next critical infrastructure sector cyberscoop.com/ai-critical-...
cyberscoop.com
The push to designate AI as the next critical infrastructure sector
A new report calls on the U.S. to designate the AI sector as critical infrastructure, naming CISA as the lead agency to protect models and data centers against cascading cyberthreats.
258
Reposted by Tim Starks
Eric Geller @ericjgeller.com · 18/08/2026
A new U.S. government clearinghouse is supposed to rescue vulnerability management from an AI-fueled crisis. But experts say its impact will be limited, and they worry about capacity and redundancy. My new story about Trump's "Gold Eagle" program: www.cybersecuritydive.com/news/ai-vuln...
2169
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 19/08/2026
The superseding indictment adds defendants and allegations against the Iranian firm accused of a massive cybertheft campaign against foreign universities and others. Read more by @timstarks.bsky.social: cyberscoop.com/mabna-instit...
012
Reposted by Tim Starks
CyberScoop @cyberscoop.bsky.social · 19/08/2026
The ransomware-as-a-service group Medusa has adopted fresh tactics to gain access and added hundreds of victims in a little more than a year, according to an updated U.S. government advisory published Tuesday. Read more by @timstarks.bsky.social: cyberscoop.com/medusa-ranso...
012
Reposted by Tim Starks
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 17/08/2026
NEW: An "unprecedented" number of people have received Apple's latest notifications alerting them they were targeted with mercenary spyware, according to security researchers. A soldier fighting in Ukraine told us he knows of other soldiers getting them. Lots of posts on social media too.
techcrunch.com
‘Unprecedented’ number of Apple users received recent spyware alert, say investigators | TechCrunch
Cybersecurity experts who investigate spyware attacks say the number of people who received a recent threat notification from Apple is unusually high.
13831
Reposted by Tim Starks
Derek B. Johnson @derekbjohnson.bsky.social · 17/08/2026
Good insight here into a recent meeting between CISA and election officials that did not go well. Fontes and other Secretaries of State expressed similar sentiments to me in a piece back in June: cyberscoop.com/trump-admini...
cyberscoop.com
States are building their own election defense networks as federal support evaporates
Following recent EAC firings and a DOJ warning regarding voter rolls, state election officials are taking new legal and operational precautions.
033
Reposted by Tim Starks
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 14/08/2026
NEW: U.S. courts will start publishing data on how many times the feds do wiretaps using spyware and hacking tools, starting in 2029. As of now, we knew the FBI and others used spyware, but we had no idea how many times that was happening. Change comes after several requests from Sen. Ron Wyden.
techcrunch.com
US courts will start publishing how often the government uses spyware | TechCrunch
The Administrative Office of the U.S. Courts told TechCrunch that it will start disclosing how many times judges authorized the use of spyware to wiretap suspected criminals.
615561