No-frills tech news

Virginia's governor promotes <b>cybersecurity</b> chief Mike Watson to state CIO role

Virginia’s governor promotes cybersecurity chief Mike Watson to state CIO role Virginia Gov. Abigail Spanberger, who assumed office in January, on Wednesday named Michael Watson, Virginia’s chief information security officer, as the commonwealth’s new CIO. Watson fills a slot recently occupied by Bob Osmond, who was last week named as Delaware’s new CIO. After more than 18 years with the Virginia Information Technologies Agency, Watson is tasked with leading the state’s enterprise IT, cloud, artificial intelligence and “digital modernization” efforts, according to a bio posted to the agency’s website. It also notes his reputation “for bridging technical depth with strategic execution.” The agency says it manages 65,000 users, 2,500 applications and $1.3 billion in annual technology procurement. According to his LinkedIn profile, Watson started his career by working a variety of technical roles over seven years with the Ajax Electric Company, a Pennsylvania manufacturer of heat treatment furnaces. He spent four years as a senior systems programmer at the University of Pennsylvania and nearly one-and-a-half years doing IT at the Virginia Auditor of Public Accounts. He joined Virginia’s technology agency in 2007, as a director of security incident management, before working his way up to the deputy CISO role in 2011. Watson is credited with heading numerous cybersecurity initiatives in Virginia, including shifting the commonwealth toward a “whole of state” cyber program, providing greater support for educational institutions and other non-state-government offices. In 2024, the National Association of State Chief Information Officers presented Watson with its Thomas M. Jarrett State Cybersecurity Leadership Award, a recognition of his work advancing cybersecurity policy in Virginia. He’s credited with implementing a zero-trust strategy and advancing cybersecurity training for state workers, but Watson has also distinguished himself by the length of his tenure. Serving more than a decade in a CISO role puts him

Anthropic releases Claude Opus 4.7 with automated <b>cybersecurity</b> safeguards

Anthropic releases Claude Opus 4.7 with automated cybersecurity safeguards Software teams building agentic AI workflows have been pushing frontier models toward longer, unsupervised task runs. Claude Opus 4.7, now generally available from Anthropic, is aimed squarely at that demand, with particular gains in software engineering, multimodal processing, and the kind of instruction fidelity that matters when a model is running tasks autonomously over multiple steps. Opus 4.7 is available across all Claude products and the API, Amazon Bedrock, Google Cloud’s Vertex AI, and Microsoft Foundry. Pricing remains the same as Opus 4.6: $5 per million input tokens and $25 per million output tokens. What changed from Opus 4.6 Opus 4.7 is a notable improvement on Opus 4.6 in advanced software engineering, with particular gains on the most difficult tasks. The model handles complex, long-running tasks with rigor and consistency, pays precise attention to instructions, and devises ways to verify its own outputs before reporting back. On the vision side, the upgrade is significant. Opus 4.7 can accept images up to 2,576 pixels on the long edge, approximately 3.75 megapixels, more than three times as many as prior Claude models. That increase supports use cases including computer-use agents reading dense screenshots, data extractions from complex diagrams, and work that needs pixel-perfect references The higher resolution is a model-level change, meaning images sent to the API are automatically processed at greater fidelity; users who do not need the extra detail can downsample images before sending to control token costs. Instruction-following behavior has also shifted in ways that require attention from teams migrating existing deployments. Where previous models interpreted instructions loosely or skipped parts entirely, Opus 4.7 takes the instructions literally. Users should re-tune their prompts and harnesses accordingly. Opus 4.7 is also better at using file system-based memory. It remembers important notes

The federal government's most underrated <b>cybersecurity</b> tool

- Safe Mode The federal government’s most underrated cybersecurity tool In this episode of Safe Mode, we sit down with Philip George, Executive Technical Strategist at Merlin Group to talk about the real challenges federal agencies face at the intersection of cybersecurity, AI adoption, and post-quantum cryptography. Philip breaks down the disconnect between cyber spending and mission outcomes, why rushing into AI without sound identity management and data integrity is a recipe for disaster, and what evolving federal cryptographic requirements and shortened certificate lifecycles mean for government IT. We dig into why visibility — simply knowing what’s on your network — remains the most powerful defensive posture regardless of the threat, explore the tension between zero trust and agentic AI, and hear Philip’s counterintuitive take that the answer to AI-driven security challenges might just be more AI, purpose-built and narrow in scope. Also, Greg sits down with Chris Townsend, Elastic’s Global VP of Public Sector, at the Elastic Public Sector Summit to unpack how agencies can operationalize data amid rising cyber threats. Townsend explains why open standards and cross-agency data sharing matter—and how agentic AI can help modernize SOC operations by prioritizing alerts and speeding response times. In our reporter chat, Greg Otto and Derek Johnson break down the surge of AI-in-cybersecurity developments—from Anthropic’s Project Glasswing and the “too dangerous to release” Mythos model to OpenAI’s trusted-access approach—focusing on what these tools could mean for vulnerability discovery and the balance between real risk and hype.

AI Use in <b>Cybersecurity</b> Could Show Holes in Short Term, Says Fitch

U.S. cyber insurers in 2025 reversed a couple of years of decline in direct written premiums to post growth of 11% but, according to Fitch Ratings, there are some underwriting concerns brought on by developments with artificial intelligence. Fitch said Anthropic’s Mythos model has raised eyebrows in the financial and cybersecurity worlds. In the short to medium term, vulnerabilities will probably outnumber patches as the artificial intelligence tool works on cyber threat intelligence and incident response. Related: Anthropic Touts AI Cybersecurity Project With Big Tech Partners “AI is particularly disruptive to cyber risk because traditional vulnerability analysis was labor-intensive and offered limited financial upside for researchers, a gap AI now fills at scale and speed,” said Fitch in its brief on the cyber marketplace on Feb. 15. “This lowers barriers for attackers, expands third-party risks, and could materially increase attack volume.” Growth in the cyber market was mostly driven by volume, with policies-in-force up 35% to offset soft aggregate pricing. This, said Fitch, indicates a great awareness among buyers of cyber exposures, as well as a competitive underwriting environment. Larger companies are still more likely to have cyber insurance protection while smaller companies lag behind. Yet, Fitch said, demand overall has “strengthened as boards and management teams recognize that cyber events can disrupt operations, trigger legal liabilities, and impair revenue even when direct financial losses are limited.” Meanwhile, insurers have and will continue to assess and adjust contract language while integrating cybersecurity assessments into underwriting. Policy wordings related to war exclusions, silent cyber, business interruption, and contingent losses “will be critical,” added Fitch. A more detailed look at the cyber market is expected this summer, said the credit-rating agency. Was this article valuable? Here are more articles you may enjoy.

Should the Mythos AI model raise <b>cybersecurity</b> alarms?

On April 7, AI firm Anthropic said its new model, Mythos, is so powerful at finding cybersecurity vulnerabilities that it will not be released publicly. Instead, the company said it will be shared with firms that build critical software used across the economy. The initiative, known as Project Glasswing, has raised cybersecurity concerns among most firms, which must now contend with AI-enabled attackers using so-called “zero-day” exploits, which are unknown even to a given piece of software’s developers, and therefore are not patched through software updates. The Hindu reported last week that the Union government and the Indian IT sector’s main cybersecurity body are both studying the implications of Mythos. Should the Mythos AI model raise cybersecurity alarms? Aseem Jakhar and Sharda Tickoo discuss this in a conversation moderated by Aroon Deep. Aseem Jakhar is the founder of Payatu and co-founder of the Nullcon cybersecurity conference; Sharda Tickoo is the country manager, India at Trend AI, formerly Trend Micro Published - April 17, 2026 01:49 am IST

Hot Picks: <b>Cybersecurity</b> and AI trends highlight software stocks to watch

Software stocks are drawing renewed attention as AI adoption reshapes enterprise technology and heightens cybersecurity risks across industries. BNN Bloomberg spoke with Fatima Boolani, managing director and co-head of software equity research at Citi, about how platform scale, data protection and AI infrastructure are driving long-term opportunities in the sector. Key Takeaways - AI advancements are increasing both the scale and sophistication of cyber threats, reinforcing demand for cybersecurity solutions. - Large, integrated platforms are becoming critical partners as enterprises deploy AI across core operations. - Data growth and sprawl are raising the importance of backup, recovery and resilience capabilities. - Observability and system monitoring are essential as AI infrastructure becomes more complex and mission-critical. - Market weakness in software has created potential opportunities in high-quality cybersecurity names. Read the full transcript below: ANDREW: On Hot Picks today, we are focusing on software. Our guest has Palo Alto, the giant cybersecurity provider, as a top selection. We’re joined by Fatima Boolani, managing director and co-head of software equity research at Citi. Thanks very much indeed for joining us. FATIMA: Thanks for having me. ANDREW: Palo Alto, in some ways, it’s the IBM of cybersecurity. People don’t get fired for hiring them. Why? Where do you — I mean, we know cybersecurity is a growth industry. What, in particular, about Palo Alto do you think investors should focus on? FATIMA: There are two very important reasons why we are very decidedly advocating for investors to build bigger core positions in their portfolios with respect to cybersecurity and increase their cybersecurity exposure. The first one is the last two weeks, and more particularly the last week. We’ve seen some very important, consequential, almost tectonic plate-shifting news out of the frontier labs of the Anthropics and the OpenAIs of the world in terms

<b>Cybersecurity</b> Alert for America's Railroads

Following a newly issued cybersecurity warning from the Federal Railroad Administration (FRA), SMART-TD is alerting all members across both freight and passenger rail operations of what they need to know. The alert highlights a credible threat from Iranian state-affiliated cyber actors targeting railroad systems by attempting to access internet-connected industrial control devices used throughout rail operations. What Risk Does Iran Pose to the U.S. Rail System? According to the FRA, these foreign actors are specifically targeting programmable logic controllers (PLCs). These are the behind-the-scenes computer systems that help control critical railroad infrastructure. If compromised, these systems could be manipulated or disabled, potentially causing service disruptions, or in the worst case, interfering with the safe movement of our trains. Federal officials also warn that attackers are scanning for exposed systems across the internet, looking for any vulnerabilities they can exploit. This means they are not just targeting one railroad or one type of equipment. This table, provided by the FRA, lays out some of their largest concerns. Why This Matters to Railroaders While much of this technology operates in the background, the impact of a cyber incident would be felt directly by the operating crews. Railroaders are the last line of defense when something doesn’t look, feel, or operate the way it should out there. Keeping that in mind, we encourage you to read over the table of potential issues the FRA released today. Please include discussions of what this warning means on your territory as part of your crew’s job briefings. The idea that our signals, crossing gates, drawbridges, ventilation in tunnels, and even our braking systems have been flagged as targets of cybercriminals is not something any of us can afford to blow off. History has taught us that critical infrastructure like railroads often becomes a high-priority target during

Arm CEO Rene Haas on AI <b>cybersecurity</b> risks

About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC

ATDT, Microsoft Team Up to Boost Mexico <b>Cybersecurity</b>

ATDT, Microsoft Team Up to Boost Mexico Cybersecurity The ATDT and Microsoft signed a memorandum to advance along with Mexico’s National Cybersecurity Plan 2025–2030, addressing rising ransomware and identity-based threats. The initiative targets public sector resilience, impacting government entities, cloud providers, and cybersecurity firms. Mexico’s Digital Transformation and Telecommunications Agency (ATDT) and Microsoft signed a memorandum of understanding to strengthen national cybersecurity infrastructure. This agreement integrates into the National Cybersecurity Plan 2025–2030 to mitigate digital risks and elevate protection standards within the public sector. "The digital transformation of the state requires solid foundations of security,” says Heidy Rocha, Director General of Cybersecurity, ATDT. The implementation of this agreement addresses critical operational safeguards in government digital services, considering the interdependency between state functionality and information security, she adds. The memorandum of understanding focuses on supporting institutional capacities, promoting continuous training, and fostering a cybersecurity culture across agencies, decentralized bodies, and public entities to protect digital services and citizen information. Mexico is a Frequent Victim The significance of this alliance is framed by a rising threat landscape affecting the digital infrastructure of Mexico. According to data from IQSEC, Mexico moved from 16th place in 2024 to 11th place globally in ransomware attack attempts during 2025. This progression establishes the nation as the second most targeted market in Latin America, following Brazil. The rise of Mexico in global threat rankings is linked to structural deficiencies in identity management and multi-cloud security. Research conducted by Permiso Security indicates that 76% of cybersecurity professionals report that more than 54% of security incidents in previous months involved issues relating to identity management, establishing the compromise of human and non-human identities as the primary entry vector. The global cybersecurity environment revealed a high concentration of incidents in North America in 2025. The United States alone accounted for

Zscaler and OpenAI Join Forces to Advance the Next Era of <b>Cybersecurity</b>

Zscaler Blog Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang Zscaler and OpenAI Join Forces to Advance the Next Era of Cybersecurity Zscaler is proud to partner with OpenAI as part of their Trusted Access for Cyber (TAC) program, which expands trusted, verified access to advanced AI capabilities for defenders. As part of this program, we plan to use GPT 5.4-Cyber, a TAC-enabled variant of GPT‑5.4, to further improve cybersecurity for our Zero Trust Exchange platform and for our customers. GPT 5.4-Cyber will be integrated into our secure Software Development Lifecycle (SDLC) workflows, empowering our teams to instantly detect, triage, and mitigate vulnerabilities earlier and patch security vulnerabilities faster. In addition to safeguarding software, Zscaler has a long history of harnessing OpenAI technology to fight AI-based attacks, including within our AI Red Teaming and Agentic SecOps solutions. Safeguarding the Zscaler Platform Secure software development is a business imperative at Zscaler. Participating in Open AI’s TAC program enables us to integrate GPT 5.4-Cyber and Codex Security into Zscaler’s internal multi‑agent security architecture for cyber defenses and product hardening. GPT 5.4-Cyber is a key enabler to offer Security-as-a-Service to our developers throughout the SDLC process, from validating threat models in designs, to assisting with secure code reviews, finding vulnerabilities, and executing black-box testing on built artifacts. We are approaching TAC with both a defensive and offensive mindset. In addition to improving security through the SDLC, we are leveraging the model to improve cyber readiness by turning large volumes of security signals into actionable intelligence, prioritizing true risk, and accelerating remediations. Moreover, we are relying on the model for offensive-informed posture hardening by modeling adversarial attack paths and highlighting weak controls, which enables us to neutralize exposures at unprecedented speeds. Combining the frontier OpenAI models with Zscaler’s industry‑leading Zero Trust architecture leads

Did Anthropic Just Crown CrowdStrike and Palo Alto Networks the AI <b>Cybersecurity</b> Stock Winners?

Earlier this month, Anthropic dropped its most advanced artificial intelligence (AI) model, Claude Mythos. However, because the company said it can easily identify and exploit software vulnerabilities, Anthropic said it will not release it to the public. Instead, it will give access to the large language model (LLM) to a select group of about 50 leading tech companies. Called Project Glasswing, the goal is for these companies to improve their cybersecurity defenses. Anthropic said Mythos has already found thousands of vulnerabilities across every major web browser and operating system. It noted it won't be long before bad actors look to use AI to exploit these vulnerabilities. Anthropic will provide participants with a total of $100 million in usage credits. Afterwards, the Claude Mythos will be available at a cost of $25 per million input tokens and $125 per million output tokens. Widening CrowdStrike and Palo Alto's lead Two of the 12 leading members of the project will be cybersecurity companies CrowdStrike (CRWD +3.18%) and Palo Alto Networks (PANW +1.56%). This is important, because it shows that Anthropic is looking to cybersecurity providers to play a big role in AI protection going forward and is not developing its own solution. Wedbush analysts called the announcement big for CrowdStrike and Palo Alto, noting this will help them become an AI enforcement layer, not an AI casualty. NASDAQ: CRWD Key Data Points The capabilities of Claude Mythos, meanwhile, suggest cybersecurity will become all the more important in the age of AI. AI cyber solutions will be needed to fight against AI cybersecurity attacks, which is why CrowdStrike and Palo Alto becoming two of the leading members of Project Glasswing is so important. Gaining access to Claude Mythos will help give them an edge moving forward, allowing them to remain at the forefront of

Is Claude Mythos and Project Glasswing a PR stunt? Experts weigh in. | Mashable

Is Anthropic's Claude Mythos a big stunt, or a real security threat? What the experts say. Anthropic put the entire tech world on notice last week with an unprecedented announcement: it made an AI model so advanced that it was too dangerous to release to the public. Anthropic said the new frontier language model, Claude Mythos Preview, would "reshape cybersecurity." Anthropic also announced the formation of Project Glasswing, an invite-only group of organizations — including some of Anthropic's biggest competitors — to test Claude Mythos Preview and secure their infrastructure. Anthropic said that Claude Mythos Preview "found thousands of high-severity vulnerabilities, including some in every major operating system and web browser." (Emphasis in original.) The company said Project Glasswing was necessary "to help secure the world’s most critical software." You May Also Like By Friday, CNBC reported that Federal Reserve Chairman Jerome Powell and Treasury Secretary Scott Bessent had summoned the high priests of finance (aka banking CEOs) for an emergency meeting about the new model. New York Times writer Thomas Friedman fretted over a "terrifying" future in which any teenager armed with Claude could hack the local power grid. The reaction to Claude Mythos Preview quickly split along predictable lines. AI boosters hailed the new model as proof that artificial general intelligence (AGI) was nigh, praising Anthropic for rolling it out so responsibly. Critics and AI skeptics called Project Glasswing a big publicity stunt. So, which is it? To find out, Mashable has been reviewing Anthropic's claims and talking to AI and cybersecurity experts. What is Claude Mythos Preview? Claude Mythos is a new large-language model that Anthropic says performs significantly better than Claude Opus 4.6 — widely considered one of the best AI models in the world — especially in cybersecurity. "In our testing, Claude Mythos Preview demonstrated

Secure by Design

Secure by Design is a software development philosophy that treats security as a foundational requirement rather than an afterthought. Instead of building a product first and bolting on security fixes later, Secure by Design demands that security considerations are embedded into every stage of the development lifecycle — from architecture and design through coding, testing, deployment, and maintenance. The core idea is straightforward: If you build something securely from the ground up, your users are protected by default rather than only when they know how to flip the right settings or when security gaps are fixed after the fact. In practical terms, this means adopting several core security principles: - Least privilege ensures that processes, agents — AI or otherwise — containers, and system services receive only the minimum access they need. - Secure defaults make sure products ship with the safest configuration enabled out of the box. - Defense in depth layers multiple security controls so no single failure becomes catastrophic. And organizations can further strengthen resilience by eliminating entire classes of vulnerabilities through safer languages, frameworks, and design patterns. Why was the Secure by Design approach introduced? For decades, many players in the technology industry operated under a “ship fast, patch later” model. One consequence of that legacy is that cybersecurity can be seen as just a cost center — something that slows releases and frustrates developers. The impacts are playing out in real time: constant vulnerability disclosures, rushed emergency patches, and breaches that drain billions from organizations while exposing the personal data of hundreds of millions of people. The Ivanti Connect Secure vulnerabilities, the Log4Shell exploit in a ubiquitous open-source library, and the MOVEit Transfer vulnerabilities all demonstrated that reactive security simply cannot keep pace with determined adversaries. Recognizing this imbalance, the U.S. Cybersecurity and Infrastructure Security

NIST Updates NVD Operations to Address Record CVE Growth

New risk-based model will allow NIST to manage current CVE volume while modernizing the NVD for long-term sustainability. NIST is changing the way it handles cybersecurity vulnerabilities and exposures, or CVEs, listed in its National Vulnerability Database (NVD). In the past, NIST’s NVD program aimed to analyze all CVEs to add details — such as severity scores and product lists — that help cybersecurity professionals prioritize and mitigate vulnerabilities. Going forward, NIST will add details, or “enrich,” those CVEs that meet certain criteria, which are explained below. CVEs that do not meet those criteria will still be listed in the NVD but will not automatically be enriched by NIST. This change is driven by a surge in CVE submissions, which increased 263% between 2020 and 2025. We don’t expect this trend to let up anytime soon. Submissions during the first three months of 2026 are nearly one-third higher than the same period last year. We are working faster than ever. We enriched nearly 42,000 CVEs in 2025 — 45% more than any prior year. But this increased productivity is not enough to keep up with growing submissions. Therefore, we are instituting a new approach. The changes described below will allow us to focus on the most critical CVEs while being transparent about how we are managing our current workload. They will also allow us to stabilize the program while we develop the automated systems and workflow enhancements required for long-term sustainability. New Prioritization Criteria Starting on April 15, 2026, we will prioritize the following CVEs for enrichment: All submitted CVEs will still be added to the NVD. However, those that do not meet the criteria above will be categorized as “Not Scheduled.” This will allow us to focus on CVEs with the greatest potential for widespread impact. While CVEs that

Cyber startup Artemis raises $70 million just six months after launch | Ctech

Cyber startup Artemis raises $70 million just six months after launch The Israeli-founded company targets AI-driven attacks with new defense platform. U.S.-based cybersecurity startup Artemis, founded by Israeli entrepreneurs, has raised $70 million in Seed and Series A funding just six months after its launch. Of that total, $15 million was raised in the Seed round. The Series A was led by Felicis with First Round Capital and Brightmind returning to increase their stakes. The round was also joined by Theory VC, Two Sigma, Lockstep and prominent cybersecurity industry leaders, including the founders of Demisto and Abnormal AI, the former CEO and CTO of Splunk, and senior executives from CrowdStrike, Palo Alto Networks, Microsoft, and Okta. Artemis was founded roughly six months ago by Shachar Hirshberg and Dan Shiebler. Hirshberg previously served in the Intelligence Corps and later worked as a development manager at Demisto, which was acquired by Palo Alto Networks for approximately $600 million. He subsequently joined Amazon Web Services, where he led GuardDuty, a cloud threat detection product. Shiebler most recently led the AI and machine learning team at Abnormal AI and holds a PhD in machine learning from University of Oxford. Artemis is positioning itself as part of a new generation of tools designed for what it describes as an “AI versus AI” security landscape. Its platform builds a dynamic data model based on each customer’s internal activity, combining behavioral logs across users, machines, cloud workloads, and applications with business context. The goal is to determine not just whether an action is anomalous, but whether it makes sense within a specific organization. From that foundation, the system generates tailored detections, investigates signals autonomously, and presents what the company describes as coherent “attack stories” rather than isolated alerts. In practice, that means correlating seemingly unrelated events, such

FCC exempts Netgear from foreign router ban

The Federal Communications Commission on Tuesday said U.S. businesses and consumers could continue to buy some Netgear routers, exempting the company’s products from a new foreign router ban meant to protect national security. After the Department of Defense determined that Netgear’s Nighthawk and Orbi routers and cable modems do not “pose unacceptable risks” to national security, the FCC said it was excluding them from its March 23 ban on routers manufactured outside the U.S. Neither the FCC nor the Pentagon explained the military’s determination that Netgear products were safe enough for U.S. use. They did not respond to requests for comment about the basis for that conclusion. Netgear was the first company to win an exemption. In its initial announcement of the ban, the FCC cited an interagency group’s conclusion that foreign-made routers represent “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense” and pose “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.” Foreign-made routers have powered botnets, helped overseas hackers masquerade as legitimate U.S. network users and enabled serious cyberattacks against critical infrastructure, including the Volt, Flax and Salt Typhoon campaigns that the U.S. government has attributed to China. Netgear manufactures its routers in Taiwan, Vietnam and Indonesia. The company’s reliance on Taiwan could pose a significant supply-chain problem, because Beijing has threatened to invade the island nation and has already tried to steal intellectual property from its domestic industries. Netgear CEO Charles Prober praised the FCC’s decision in an online statement and said the company’s technology “meets rigorous standards.”

<b>Cybersecurity</b> firm identifies 108 malicious Chrome extensions affecting 20,000 users

Cybersecurity researchers have discovered a new campaign where a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited. These extensions are published under five distinct publisher identities – Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt — according to Socket, the cybersecurity firm behind the findings. They have collectively amassed about 20,000 installs in the Chrome Web Store. “All 108 route stolen credentials, user identities, and browsing data to servers controlled by the same operator,” Security Researcher Kush Pandya said in an analysis. READ: Google parent Alphabet hits $3 trillion following DOJ win ( 54 of the add-ons steal Google account identity via OAuth2. 45 extensions contain a universal backdoor that opens arbitrary URLs as soon as the browser is started, and the remaining ones engage in a variety of malicious behaviors. The identified extensions masquerade as Telegram sidebar clients, slot machine and Keno games, YouTube and TikTok enhancers, text translation tools, and page utilities, in order to appear legitimate. While they seem to showcase diverse functionality, malicious code runs in the background capturing session information, injecting arbitrary scripts, and opening URLs chosen by the attacker. “Five extensions use Chrome’s declarativeNetRequest API to strip security headers from target sites before the page loads,” Socket noted. “All 108 malicious extensions share the same backend, hosted at 144.126.135[.]238.” It is not known who is responsible for these malicious extensions. An analysis of the source code has reportedly uncovered Russian language comments across several add-ons. READ: Google Gemini’s ‘Nano-Banana’ trend surpasses OpenAI; tops Apple App Store ( It has been recommended that Chrome users should check whether they have extensions running in

CU In Class | Intro to Adversarial Thinking for <b>Cybersecurity</b>

CU In Class | Intro to Adversarial Thinking for Cybersecurity Adversarial thinking is central to cybersecurity, and this lecture explains why it matters. 🔗 Learn more about Cedarville Cybersecurity: https://www.cedarville.edu/academics/centers/center-for-the-advancement-of-cybersecurity/cyber-at-cedarville In this lecture, Dr. Seth Hamman introduces a homemade module on adversarial thinking that was developed with support from an NSA grant and shared publicly for cybersecurity educators. Using the familiar framework of computers and bad guys, the lecture shows why cybersecurity is distinct from other fields and why it requires more than technical best practices alone. Students are challenged to think beyond barriers like passwords, firewalls, and multi-factor authentication and consider the mindset, capabilities, and strategies of attackers. The lecture also explores how cyberspace differs from physical space through the ideas of distance-less, digital, and dynamic environments, and how those realities shape threats to confidentiality, integrity, and availability. From there, the lecture defines adversarial thinking as the ability to embody the technological capabilities, unconventional perspectives, and strategic reasoning of hackers. Through examples like the CIA triad, the Cuckoo’s Egg, cross-site scripting, malware, rootkits, social engineering, and game theory, the lecture builds a practical framework for anticipating attacks and strengthening cybersecurity education. Timestamps: 0:00 Introduction to the adversarial thinking module 2:04 What cybersecurity really means 4:00 The three B’s: bad guys, barriers, and bounties 11:22 Why cyberspace is harder to secure 14:02 CIA triad and hacker goals 20:19 Why cyber adversaries define the discipline 23:42 What does it mean to think? 24:37 Sternberg’s triarchic theory of intelligence 31:17 Applying the theory to hackers 37:19 Definition of adversarial thinking 39:15 The Cuckoo’s Egg and real-world hacking 45:05 The Princess Bride analogy 48:15 Strategic reasoning and game theory 51:02 Final takeaways 🎓 Admissions: https://cedar.to/Admissions 💰 Financial Aid: https://cedar.to/FinAid 🏫 Visit Campus: https://cedar.to/Visit 📚 Academic Programs: https://cedar.to/Programs #Cybersecurity #AdversarialThinking #GameTheory #InformationSecurity #Cedarville #HigherEducation