No-frills tech news

Making Cybersecurity Everyone's Business: Moving Cyber Preparedness Beyond the IT Department

Cybersecurity isn’t just about finding vulnerabilities. It’s about what district leaders do with what they learn. Cyber insurance and trusted incident response partners are essential to district cybersecurity. But when an incident occurs, district leaders still must make the operational decisions that keep schools running. The best time to practice those decisions is before a crisis—and to reinforce cybersecurity as a shared organizational responsibility.

Schneider Electric, SECLAB expand OT cybersecurity collaboration for industrial infrastructure

Schneider Electric, a global energy technology leader, and SECLAB, a French provider of OT cybersecurity solutions, announced an expanded collaboration to give industrial infrastructure a level of protection that goes beyond software-only defenses. To strengthen defense in depth for industrial systems, Schneider Electric has chosen to deepen its collaboration with SECLAB. This collaboration has produced a dedicated configuration for securing Schneider Electric OT protocols. Tests conducted on Schneider Electric platforms confirmed application-level filtering, proper operation in redundant configurations, and no perceptible latency for the process. Several industrial companies whose operations depend on continuous OT service availability are already engaged in deployments supported by Schneider Electric.

GPT-6 cyberattacks, ShinyHunters arrest, Nvidia AI guardrails

Even after instructions explicitly said anything not listed was out of scope, Astra still launched full attacks in 4 of 49 runs. (UK AI Security Institute) Dutch police arrest “reformed” hacker in ShinyHunters probe Dutch authorities arrested 23-year-old Pepijn van der Stap, according to sources who spoke with KrebsOnSecurity. ShinyHunters escalated with attacks against the FBI’s jobs site and the Clop ransomware gang. (KrebsOnSecurity) Nvidia builds a browser for AI agents Nvidia released a new Open Agent Safety Platform meant to keep AI agents inside their guardrails. UpGuard says the exposures span the globe and have grown alongside rapid app development, including projects built with AI coding tools.

Marlink, NORMA Cyber Team Up On Fleet Cybersecurity

Marlink and the Nordic Maritime Cyber Resilience Centre (NORMA Cyber) have launched a combined service linking fleet-wide cyber threat monitoring with incident response, with Höegh Autoliners among the first operators to deploy it across its entire fleet. The service combines NORMA Cyber's independent security monitoring and initial threat analysis with Marlink's maritime cybersecurity and incident response capabilities. NORMA Cyber analyses and triages potential threats before escalating incidents requiring action onboard to Marlink's cyber specialists for investigation, containment and remediation. Höegh Autoliners is using NORMA Cyber's monitoring alongside connectivity, IT and cybersecurity services provided through the Marlink Possibility Platform. NORMA Cyber has more than 180 members representing over 3,000 vessels and offshore units.

Cybersecurity vendors turn to multi-model, open AI to bypass guardrails

The Agentic SOC Alliance, for example, is a coalition of 15 cybersecurity vendors founded in July. A recent lab exercise at ExtraHop illustrates the real-world need for multi-model flexibility, according to Paul Giorgi, vice president of global engineering. Bypassing third-party guardrails with open-weight models While multi-model routing offers operational flexibility, other vendors are taking model control a step further by building directly on open-weight foundations. CrowdStrike -- a member of the Agentic SOC Alliance, along with ExtraHop -- recently debuted SafeMind, an agentic harness-model system with complementary red-team and blue-team capabilities. As vendors balance multi-model frameworks with specialized open-weight deployments, resilience is likely to hinge on keeping AI execution layers fluid and adaptable.

Large Companies Slow AI Adoption as Cybersecurity Risk, Regulation and Trust Concerns Grow

The findings suggest businesses are not abandoning AI, but are entering a more cautious phase in which AI risk management, responsible AI governance and internal confidence will determine the pace of adoption. “Companies still see enormous opportunity, but enterprise AI adoption is now being shaped by cybersecurity risk, regulatory uncertainty and a growing trust gap inside organisations.” AI governance is still immature: Only 17% of companies have governance frameworks that are more than two years old. In Spain, 48% prioritise greater investment in AI safety and skills, while mandatory AI risk disclosure leads in Ireland at 42% and Belgium at 45%. About FTI Consulting FTI Consulting, Inc. is a leading global expert firm for organisations facing crisis and transformation, with more than 8,100 employees located in 32 countries and territories as of June 30, 2026.

Cybersecurity jobs available right now: September 29, 2026

Cybersecurity Analyst Creyos | Canada | On-site – View job details As a Cybersecurity Analyst, you will assess security risks across applications, networks and infrastructure, test controls, and help teams fix vulnerabilities. Cybersecurity Analyst Eastman | India | On-site – View job details As a Cybersecurity Analyst, you will plan and conduct authorized penetration tests and red team exercises across networks, applications, APIs, cloud systems and endpoints. Get weekly updates on new cybersecurity job openings. Cybersecurity Specialist CEF Industries | USA | On-site – View job details As a Cybersecurity Specialist, you will manage daily security operations, investigate alerts, support incident response, and coordinate with security providers until issues are resolved. Senior Cybersecurity Operations Analyst DEFEND | New Zealand | Hybrid – View job details As a Senior Cybersecurity Operations Analyst, you will investigate threats across endpoint, identity, cloud, network, application and AI environments.

Cybersecurity’s New AI Imperative: Attacking the Backlog of Vulnerability Alerts

However, the scale of the vulnerability management challenge is currently all-consuming. Companies must understand and control how vendors deploy AI through the whole life of a contract, including midcycle changes and fourth-party exposure. How leaders are adapting cybersecurity to the AI era Of course, AI is not just a tool for attackers. While AI-enabled vulnerability management is still at an early stage, leading companies are making progress. Other cybersecurity leaders are now pushing their DevOps teams to spend more time finding and mitigating vulnerabilities.

New Rockwell report reveals glaring disconnect between cybersecurity investments and risk protection

A region-by-region scorecard Rockwell’s recently releasedOperational Resilience in the Age of Connectivity report revealed a disconnect between confidence in comprehensive cybersecurity protection and operational risk among organizations, with increased connectivity leading to more cybersecurity risks. According to Rockwell’s research, based on input from 1,500 manufacturing and industrial operations decision-makers across 17 countries, more than one third of organizations see cybersecurity risk as one of the largest external obstacles to growth. Simultaneously, cybersecurity ranks as the second-highest ROI-generating technology investment reported by respondents, and over 60% of organizations have already invested in cybersecurity platforms. See also: IT-OT convergence: When ransomware hits the factory floor These statistics indicate a larger industry shift, according to the Rockwell report. According to Rockwell, the next step is for organizations to bring investments together into a cybersecurity program that improves visibility, reduces risk, and adapts to evolving operational needs.

Engineering velocity is a competitive advantage in modern cybersecurity

In cybersecurity, engineering velocity has become a competitive advantage. In my experience, decision latency is another under-diagnosed constraint in engineering organizations. The engineering work had been ready for months, and decision latency was the bottleneck. That combination makes engineering velocity part of how a cybersecurity organization competes. For CIOs and CTOs looking to increase engineering velocity, my advice is to look first at where work waits.

TekStream to Spotlight Cybersecurity Workforce Development and Digital Resilience at Educause 2026

TekStream will lead two sessions focused on helping colleges and universities evolve their security programs while strengthening long-term digital resilience. They'll discuss another persistent challenge for higher education security teams: turning fragmented security data into a clear picture of institutional cyber risk. Educause attendees are invited to connect with TekStream leaders and higher education peers to continue the conversation around cybersecurity, workforce development and digital resilience. Please RSVP at https://go.tekstream.com/TekStreamEducauseFallHH2026 About TekStream TekStream is a digital resilience company that helps organizations secure, modernize, and operate their technology environments so they can adapt, recover, and grow. The company's Whole-of-State cybersecurity model combines workforce development with cost-deferment strategies, empowering public sector organizations to maintain long-term ownership of their security programs.

Citrix urges immediate upgrades of NetScaler amid widespread exploitation attempts

The Cybersecurity and Infrastructure Security Agency on Sunday warned that critical zero-day vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway are facing exploitation and need to be immediately addressed. The agency later added CVE-2026-88771 and CVE-2026-88772 to its Known Exploited Vulnerabilities catalog. Citrix said the bulletin applies only to customer-managed NetScaler ADC and NetScaler Gateway. The company urged security teams to review the guidance to determine whether certain preconditions were met on NetScaler deployments before applying upgrades. For example, preconditions for CVE-2026-88772 are met only when datagram transport layer security (DTLS) is enabled on NetScaler ADC or NetScaler Gateway.

Meta's Muse AI assistant raises major cybersecurity and privacy concerns

Meta's Muse AI assistant is helping users save money on subscriptions, but it requires access to personal bank accounts and credit cards. Liz Peek warns of potential cybersecurity risks and the threat of rogue agents. With over 3 million downloads for canceling unwanted subscriptions, Meta's Muse AI assistant is raising security alarms. Liz Peek warns that users must grant the AI access to personal bank accounts, credit cards, emails, and texts to make it effective. The anchor agrees that these financial security fears are well-grounded, stressing the need for robust cybersecurity.

Satellite communications growth expands cybersecurity attack surface across IoT, utilities, critical infrastructure

“As a result, the satellite communication market is on an aggressive growth trajectory. Expanding satellite ecosystem is also widening cybersecurity attack surface, with direct-to-device services connecting satellites, ground gateways, network services and endpoints such as smartphones and IoT sensors. The post acknowledges that satellite communications have undergone rapid transformation in recent years, driven by geopolitical pressures, commercial expansion and technological innovation. Satellite connectivity is embedding itself across critical industries, as automotive systems incorporate positioning and emergency SOS, while logistics and utilities deploy IoT monitoring and control. Automotive sector alone is projected to reach $25.8 billion by 2034, while an estimated 2.5 billion to 3 billion IoT devices now have satellite addressability.

Dragos Expands xOT Security Platform With NetRise and runZero Acquisitions

Dragos, Inc., the global leader in extended operational technology (xOT) cybersecurity, has completed its acquisitions of NetRise and runZero. The acquisitions bring the full teams from runZero and NetRise into Dragos, including runZero CEO HD Moore, NetRise CEO Thomas Pace, and NetRise CTO and Chief Scientist Michael Scott. They will oversee the integration of their respective technologies into the Dragos Platform while continuing to support their existing customers. The acquisitions are also expected to strengthen the Dragos Intelligence Fabric, which incorporates a decade of OT-specific telemetry and incident response expertise into the Dragos Platform. _________ About Dragos Dragos is the global leader in extended operational technology (xOT) cybersecurity, delivering on its mission to safeguard civilization.

California Critical Access Hospital Announces Cybersecurity Incident

Modoc Medical Center Modoc Medical Center, a 12-bed critical access hospital and rural healthcare system based in Alturas, California, has identified unauthorized access to its computer network. The review of the data has been completed, and notification letters are now being sent to the affected individuals. Millstone Medical Outsourcing Millstone Medical Outsourcing, a Fall River, Massachusetts-based medical device outsourcing company, has identified a cybersecurity incident that exposed personal and health information. No misuse of the affected information had been identified at the time of issuing notification letters. The number of affected individuals has not been publicly disclosed at the time of publication of this article.

Context matters when it comes to cybersecurity’s agentic operating model

Because context continuously changes, agentic security and governance controls will require access to up-to-date, contextual policy and operating guardrails. Architectural considerations As agent architecture evolves, inter-agent communications models are becoming core to operating models. Model Context Protocol (MCP) servers; Agent2Agent (A2A); Agent Communication Protocol (ACP) and other emerging mechanisms are paramount to providing access to functions and datasets. While what’s needed to support governance and security for agentic solutions is still emerging, human-based governance and security requirements continue to evolve as the machine-human operating model also evolves. Leading model providers increasingly acknowledge that the real breakthrough comes from the context and integration wrapped around the model.

Strengthening NATO Through Military Mobility and Critical Infrastructure Cybersecurity

Yet since the end of the Cold War, Europe’s defense-related infrastructure investment has declined alongside its defense spending, leaving much of the continent’s transportation network ill-suited for today’s heavier forces. Chinese state-linked firms hold stakes in more than 30 European port terminals, including facilities designated to receive U.S. military forces and equipment. NATO identifies the infrastructure and mobility capabilities its forces require and can coordinate national efforts but lacks the authority to impose binding standards on civilian operators. By contrast, the European Union can impose binding standards on civilian operators, but member states retain control over defense priorities and infrastructure investment. As a result, NATO forces cannot move as rapidly as they may need, and investment for upgrades lags behind NATO’s reinforcement requirements.

Honeywell Benchmark Report Finds Critical Gaps in OT Cybersecurity Visibility

Honeywell recently released its inaugural OT Cybersecurity Benchmark Report, delivering an important message for industrial organizations: OT cybersecurity maturity is no longer limited to protecting traditional production environments. As industry analysts, we can sometimes assume that everyone already understands industrial cybersecurity fundamentals and fail to emphasize the basics of a successful OT cybersecurity program. Instead, the focus often shifts to newer technologies, even as many end users are still establishing their OT cybersecurity programs. AI Becomes a Core OT Security Capability The survey reveals broad adoption of artificial intelligence in OT cybersecurity operations. Meanwhile, 99 percent of respondents expect AI to significantly influence OT cybersecurity within the next two to three years.

Disabled? Apply for free IT, cybersecurity training in Pensacola

A new training program aims to give at least 60 disabled Northwest Florida residents a pathway into information technology and cybersecurity careers. Katrina Simpkins, Global Connections to Employment's senior director of community employment services, said the training program will have three cohorts that will each train over a 14-week period. Resume development, interview preparation, networking skills and personalized career support are part of the training program. The abilIT program will pay the CompTIA certification exam fees, which range from over $200 to $500 each. To learn more about abilIT or apply for the program, visit gce.org/abilIT or email Katrina.Simpkins@gce.org or call 850-495-2351.