logo

Energy Department patched flaws enabling email impersonation in critical minerals system

ID: 29c4591c-60c0-5811-8bc1-1500dde50051

STIX ID: report--29c4591c-60c0-5811-8bc1-1500dde50051

Feed Name: Nextgov Cybersecurity

Threat Score
55/100

Date Published: 2026-02-23

Date Updated: 2026-04-22

Author: David DiMolfetta

...
...

A security researcher discovered an identity verification flaw in the U.S. Department of Energy Office of Critical Minerals portal that allowed users to register and operate accounts appearing to belong to Energy Department email addresses via subdomain enumeration; the agency has remediated the issue and publicly credited the researcher, and there is no evidence the vulnerability was exploited. The flaw could have enabled adversaries to impersonate officials, request sensitive information, or insert themselves into program communications, posing national-security-relevant risks to critical-minerals initiatives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.