{"database": "press", "table": "releases", "rows": [["https://www.cotton.senate.gov/news/press-releases/cotton-to-cairncross-address-national-cyber-security-risk", "Cotton to Cairncross: Address National Cyber Security Risk", "2025-12-18", "2025", "2025-12", "Republican", "Senate", "AR", "Tom Cotton", "C001095", "www.cotton.senate.gov", "cotton", "https://www.cotton.senate.gov/news/press-releases", "scraper", "FOR IMMEDIATE RELEASE\n\nContact: Patrick McCann (202) 224-2353\n\nDecember 18, 2025\n\nCotton to Cairncross: Address National Cyber Security Risk\n\nWashington, D.C. \u2014 Senator Tom Cotton (R-Arkansas) yesterday sent a letter to National Cyber Director Sean Cairncross concerned about China and Russia contributing to the open source software ecosystem that underpins important American software systems, including the Department of War software. This reliance on open source software could create a critical national security risk and needs to be addressed.\n\nIn part, Senator Cotton wrote:\n\n\u201cAs the Office of the National Cyber Director holds responsibility for coordinating implementation of national cyber policy and government-wide cybersecurity, you are well-positioned to lead the U.S. government in addressing this cross-cutting vulnerability. I respectfully request that you take steps to build up the federal government\u2019s capability to maintain awareness of provenance and foreign influence on OSS and track contributions from developers in adversary nations.\u201d\n\nFull text of the letter may be found here and below.\n\nDecember 17, 2025\n\nThe Honorable Sean Cairncross\n\nDirector\n\nOffice of the National Cyber Director\n\n1600 Pennsylvania Ave NW\n\nWashington, DC 20500\n\nDear Mr. Cairncross,\n\nI write concerning a critical national security risk of foreign adversaries, particularly China and Russia, contributing to the open source software (OSS) ecosystem that underpins American software systems, including Department of War software. OSS relies on a trust-based, global community of contributors to ensure that software stays accessible, secure, and updated. Historically, such a framework has pulled in talent from around the world to build projects that have become ubiquitous, foundational technology. Unfortunately, there are reports that state-sponsored software developers and cyber espionage groups have started to exploit this communal environment, which assumes that contributors are benevolent, to insert malicious code into widely used open source codebases.\n\nFor example, last year, an intentionally planted backdoor was discovered in XZ Utils, a critical open source tool. The actor behind this malicious code, known as \u201cJia Tan\u201d, spent years building credibility and lying in wait until the right moment. A Russia-based developer is the sole maintainer of fast-glob, another piece of OSS embedded in numerous software packages in the Department of War, raising alarms about potential compromises. Chinese giants like Alibaba and Huawei are ranked in the top 20 contributors worldwide in the most recent Open Source Contributor Index. As you know, the Chinese Communist Party\u2019s (CCP) national security laws impose broad obligations on China-based entities, including compelling companies to provide technical assistance to further CCP goals.\n\nOSS is the backbone of U.S. government systems, including mission-critical defense systems, where we reap the numerous benefits of OSS to innovate, develop, and deploy technology quickly. However, leaving our reliance on OSS unmonitored is exposing America to increasingly dangerous risks. Secretary Hegseth has already sounded the alarm, releasing a memorandum declaring that the Department of War \u201cwill not procure any\u2026software susceptible to adversarial foreign influence\u2026and must prevent such adversaries from introducing malicious capabilities into the products and services utilized by the Department.\u201d He also directed the Department to purge its software of Chinese involvement.\n\nAs the Office of the National Cyber Director holds responsibility for coordinating implementation of national cyber policy and government-wide cybersecurity, you are well-positioned to lead the U.S. government in addressing this cross-cutting vulnerability. I respectfully request that you take steps to build up the federal government\u2019s capability to maintain awareness of provenance and foreign influence on OSS and track contributions from developers in adversary nations.\n\nThank you for your attention to this matter.\n\nSincerely,\n\nTom Cotton\n\nUnited States Senator\n\n###", 1, "2026-03-30T01:40:41Z", "2026-04-06T20:09:11Z"]], "columns": ["url", "title", "date", "year", "month", "party", "chamber", "state", "member_name", "bioguide_id", "domain", "scraper", "source", "date_source", "text", "has_text", "collected_at", "updated_at"], "primary_keys": ["url"], "primary_key_values": ["https://www.cotton.senate.gov/news/press-releases/cotton-to-cairncross-address-national-cyber-security-risk"], "units": {}, "query_ms": 0.8276309818029404, "source": "dwillis/congress-press", "source_url": "https://github.com/dwillis/congress-press", "license": "MIT", "license_url": "https://github.com/dwillis/congress-press/blob/main/LICENSE"}