 Supply Chain Exploitation Complex and interconnected supply chains for software and other information technology and services, combined with growing reliance on common third-party service providers, create opportunities for sophisticated adversaries to access victims at scale and complicate the efforts of defenders to identify and manage cybersecurity risks. Adversaries are increasingly taking advantage of complex and interconnected relationships between organizations and their suppliers, customers, vendors, and service providers, compromising single nodes that grant surreptitious access to victims in the United States and around the world. In 2023, several high-profile compromises of technology providers impacted thousands of connected victims, including critical infrastructure owners and operators. In December, Russia’s Foreign Intelligence Service (SVR) targeted servers used by computer programmers to compile and test software, presumably intending to maliciously modify developers’ source code. Earlier in the year, a compromise of a widely used identity and access management firm enabled malicious actors to steal credentials and session tokens that could provide surreptitious access to thousands of customers. And, at the beginning of the year, a popular enterprise communications suite was compromised in an entirely separate supply chain attack, demonstrating how a single initial compromise can quickly spread through interlinked technology supply chains and thirdparty relationships. Commercial Spyware There is a growing market for sophisticated and invasive end-to-end cyber-surveillance tools sold by private vendors to access electronic devices remotely, monitor and extract their content, and manipulate their components without the knowledge or consent of the devices’ users. Commercial spyware providers now offer world-class capabilities to the highest bidder, who often employ these capabilities in cyber operations that are not subject to oversight or regulatory constraints. While the commercial spyware industry has a long history, the recent proliferation and misuse of these tools allows malicious cyber actors to target journalists, activists, human rights defenders, and government officials with greater frequency. A growing number of authoritarian regimes and democratic governments have misused commercial spyware to surveil targets; intimidate perceived opponents; suppress dissent; limit freedoms of expression, peaceful assembly, or association; and otherwise abuse human rights. Some foreign governments and persons have deployed commercial spyware against U.S. government personnel, information, and computer systems, presenting significant counterintelligence and security risks to the United States. The misuse of these tools also threatens the security and privacy of individuals in the United States and around the world. Artificial Intelligence Artificial intelligence (AI) is one of the most powerful technologies of our time, and it continues to receive substantial public attention and media coverage. Advances in large-language models (LLMs) and other foundational algorithms, combined with more affordable computing power and access to data, have given rise to a new generation of AI tools. These tools captured 2024 REPORT 6 ON THE CYBERSECURITY OF THE UNITED STATES POSTURE

Select target paragraph3