No-frills tech news

FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER. FIRESTARTER, per CISA and the U.K.'s National Cyber Security Centre (NCSC), is assessed to be a backdoor designed for remote access and control. It's believed to be deployed as part of a "widespread" campaign orchestrated by an advanced persistent threat (APT) actor to obtain access to Cisco Adaptive Security Appliance (ASA) firmware by exploiting now-patched security flaws such as - - CVE-2025-20333 (CVSS score: 9.9) - An improper validation of user-supplied input vulnerability that could allow an authenticated, remote attacker with valid VPN user credentials to execute arbitrary code as root on an affected device by sending crafted HTTP requests. - CVE-2025-20362 (CVSS score: 6.5) - An improper validation of user-supplied input vulnerability that could allow an unauthenticated, remote attacker to access restricted URL endpoints without authentication by sending crafted HTTP requests. "FIRESTARTER can persist as an active threat on Cisco devices running ASA or Firepower Threat Defense (FTD) software, maintaining post-patching persistence and enabling threat actors to re-access compromised devices without re-exploiting vulnerabilities," the agencies said. In the investigated incident, the threat actors have been found to deploy a post-exploitation toolkit called LINE VIPER that can execute CLI commands, perform packet captures, bypass VPN Authentication, Authorization, and Accounting (AAA) for actor devices, suppress syslog messages, harvest user CLI commands, and force a delayed reboot. The elevated access afforded by LINE VIPER served as a conduit for FIRESTARTER, which was deployed on the Firepower device before September 25, 2025, allowing the threat actors to maintain continued access and return to the compromised appliance as recently as last month. A Linux ELF binary, FIRESTARTER can

Governor McKee Announces Finalization of Settlement with Deloitte Related to RIBridges ...

Governor McKee Announces Finalization of Settlement with Deloitte Related to RIBridges Cybersecurity Incident Published on Friday, April 24, 2026 PROVIDENCE, RI — Governor Dan McKee today announced that the State of Rhode Island, through the Department of Administration, has finalized a settlement agreement with Deloitte Consulting LLP related to the December 2024 RIBridges cybersecurity incident and the subsequent system restoration efforts. Under the terms of the agreement, at Governor McKee’s and the State’s request, Deloitte has agreed to pay the State an additional $7 million. Early last year, Governor McKee secured a $5 million payment from Deloitte for unexpected expenses related to the incident, bringing the State’s total direct financial recovery to $12 million. Deloitte has also provided $6 million worth of system enhancements, operational support, and business continuity services in response to the incident that were outside the scope of their contract. The State will not incur additional charges for these services. “This agreement reflects a deliberate effort to protect Rhode Island taxpayers while ensuring the State has the resources needed to move forward,” said Governor McKee. “During the cybersecurity incident, my administration worked diligently to ensure Rhode Islanders maintained access to their benefits. Our focus remains on supporting Rhode Islanders who rely on these critical benefits.” “This was a comprehensive and carefully negotiated agreement,” said Thomas Verdi, Acting Director of the Department of Administration. “It ensures the State receives additional financial support while also capturing significant value in additional technological enhancements and operational support services during system restoration.”

LPL Financial Reveals <b>Cybersecurity</b> Data Breach

LPL Claims Hackers Accessed Client Accounts Through Advisors’ Devices LPL reports that malware from phishing led to unauthorized transactions in client accounts. LPL Financial is the latest firm to reveal a cybersecurity incident. According to a notice submitted to Maine’s Attorney General, the breach led to “unauthorized securities transactions and financial transfers” in some clients’ accounts. According to the data breach notification information on the attorney general’s site, LPL notified affected consumers regarding the breach that occurred on November 10, 2025 and was discovered 10 days later. A sample letter to clients provides details on the breach that affected clients working with “a small number” of the firm’s affiliated financial advisors. (LPL reported that 1,581 total clients were affected, and only two in Maine.) “Our investigation found that malware distributed through phishing messages affected a limited number of individual advisor devices and resulted in unauthorized third-party access to the accounts of those advisors on LPL’s web-based advisor portal,” the sample letter read. LPL stated in the letter that it contacted law enforcement after discovering the breach and conducted an internal investigation. While the firm didn’t identify specific evidence that “sensitive personal information was accessed or acquired by a third party,” it couldn’t rule out the possibility that third parties may have seen some clients’ information during the breach. When LPL found that breach, it stopped the activity, secured the affected accounts, and restored “any impacted accounts to their original financial positions.” The firm also implemented new “technical safeguards” to bolster its existing security and found no evidence that its systems remained compromised. The firm offered affected clients a complimentary two-year Experian credit monitoring membership. According to an LPL spokesperson, the firm "identified unusual activity involving accounts associated with a very small number of affiliated advisors. The activity was promptly contained,

Trump's pick to run US cyber agency CISA asks to drop out | TechCrunch

Trump’s twice-chosen pick to run the U.S. federal cybersecurity agency CISA has requested to withdraw from the position, leaving the agency without any clear person to lead it on a permanent basis. In a letter to the White House on Wednesday, Sean Plankey requested that the Trump administration withdraw his nomination, citing a holdup in the Senate, which is required to hold a vote to approve his appointment. Plankey said it has “become clear” that the Senate will not confirm him, more than a year after he was first nominated to lead CISA. The New York Times published a copy of Plankey’s letter on Thursday. Politico first reported Plankey’s decision to withdraw his nomination. Both publications said that Plankey was unlikely to reach a majority vote needed for his appointment as Sen. Rick Scott (R-FL) was blocking his nomination over a Coast Guard contract unrelated to cybersecurity. Plankey previously served as a senior adviser to Coast Guard leadership. Nick Andersen has been the acting director of CISA since the departure of Madhu Gottumukkala in February. Gottumukkala was appointed in May 2025 to oversee the agency on a temporary basis but left less than a year later after a tumultuous tenure in the role. CISA is tasked by Congress with cybersecurity defense and infrastructure protection across the civilian federal government. The agency has faced a challenging year, following at least three government shutdowns, several rounds of furloughs, and budget cuts and staff reductions as directed by the White House, despite a raft of cyberattacks facing the U.S. government and its allies over the past year. Earlier this month, the Trump administration requested to slash CISA’s budget by more than $700 million amid claims that the agency was engaged in “censorship” — referring to CISA’s efforts to counter election misinformation during the

Microsoft and OpenAI tighten <b>cybersecurity</b> pact as AI models reshape defender workflows

Microsoft and OpenAI tighten cybersecurity pact as AI models reshape defender workflows Microsoft and OpenAI have confirmed a deeper cybersecurity collaboration that will see Microsoft's Office of the Chief Information Security Officer (CISO) gain access to OpenAI's most cyber-capable models through the Trusted Access for Cyber program, the two companies announced on LinkedIn. The pact pairs OpenAI's cyber-focused model work with Microsoft's Secure Future Initiative, formalizing a defender stack that stretches across cloud, identity, productivity and frontier AI. It lands at a moment when AI-assisted attacks are climbing and open-source dependencies remain a persistent weak point across enterprise software. The announcement also signals a broader repositioning of AI labs inside the security supply chain. According to reporting around OpenAI's recent cyber defense expansion, Anthropic has also released a frontier model variant positioned for security use, meaning the top AI labs are increasingly being drawn directly into defender workflows rather than sitting behind hyperscaler partnerships. The Microsoft deal makes that shift explicit for joint customers already running on Azure, Microsoft 365 and Microsoft Security. GPT-5.4-Cyber moves into Microsoft's defender stack Trusted Access for Cyber is OpenAI's tiered program for vetted security teams, built on the principle that advanced cyber tools should be broadly available to defenders under identity verification and organizational validation controls. OpenAI confirmed in its own announcement that the program is scaling to thousands of verified individual defenders and hundreds of teams responsible for defending critical software, and that participants include major enterprises and security vendors across financial services, cloud, and cybersecurity. In a joint statement posted on LinkedIn, Microsoft Security wrote, "AI models are becoming much more capable in cybersecurity, and that progress raises the bar for everyone. As capabilities advance, we're focused on deep collaboration with defenders to make software more resilient." The post confirmed that OpenAI

Google Favors General-Purpose Gemini Models Over <b>Cybersecurity</b>‑Specific AI

Google Cloud’s operations chief said the tech giant does not plan to release a separate, cyber‑focused frontier model like Anthropic’s Clause Mythos. Instead, Google believes high‑quality generalist AI models, like Gemini 3.1 Pro, Google’s latest large language model (LLM), are already strong enough across domains to meet cybersecurity needs. Speaking at Google Cloud Next 26, Francis DeSouza, COO of Google Cloud, said that while early thinking in the deployment of generative AI anticipated many domain‑specific frontier models, the reality has now changed. “What we found over time was that the core model was doing really well and that it started to get good across all domains,” he added. “For example, coding is now done incredibly well by Gemini and you don't need a coding specific Gemini model. We are finding that inside our security too, that models themselves are getting better and better. I believe that Gemini is a terrific model for our security. You shouldn't expect to see a cyber version that's different.” The practical path forward, DeSouza argued, is to apply a high‑quality, generalist frontier model together with the right tooling and governance, rather than fragmenting effort into niche frontier models. Read more: Google Introduces Unique AI Agent Identities Google plans to combine the latest Gemini versions with agent and platform capabilities to meet cyber defense needs. DeSouza said that enterprises should focus on integrating strong general models into security workflows, training them with context, wrapping them with access controls and embedding them in automated detection, triage and response pipelines. Yinon Costica, co-founder and VP of product at Wiz, now part of Google Cloud, said that cyber defenders possess richer, more organization‑specific context than attackers and feeding that context into a strong general model produces better defensive outcomes. AI competitors like Anthropic and OpenAI are pursuing specialized paths,

A group of users leaked Anthropic's AI model Mythos by reportedly guessing where it was located

The AI model that Anthropic billed as too dangerous to release has reportedly been accessed by an unauthorized third party, and the incident raises concerns about the future of cybersecurity. The Mythos model was reportedly accessed by a handful of users in a private Discord chat on the day it was announced publicly, Bloomberg reported. Earlier this month, the group was able to access the program in part because one of the members of the group is a third party contractor for Anthropic, according to Bloomberg. Using this access, the group was able to guess where the model was located based on previously leaked knowledge by another group about Anthropic’s past practices, that hackers obtained from AI training startup Mercor. Although the group that accessed it has not been using the model for cyberattacks, it has been using the program continuously since its release and still has access, the outlet reported. Anthropic did not immediately respond to Fortune’s request for comment. A spokesperson from Anthropic told Bloomberg the company was “investigating a report claiming unauthorized access to Claude Mythos Preview through one of our third-party vendor environments.” The fact that the model was leaked so quickly doesn’t surprise David Lindner, the chief information security officer at Contrast Security and a 25-year industry veteran. Even though Anthropic intentionally limited the model to a small group of 40 companies—including Microsoft, Apple, and Google— to beef up their security ahead of a wider release, thousands of people likely had access to the program across these companies, which makes a leak nearly inevitable, he said. “It was bound to happen,” Lindner said. “The more they add to this elite group, the more likely it was to get released to someone who shouldn’t probably have access to it.” Anthropic claims its Mythos model is more

The <b>Cybersecurity</b> Firm Most Enterprises Have Never Heard Of Just Earned an EY ...

Three consecutive Inc. 5000 appearances and back-to-back #1 MSSP honors — now the founder behind 2.5 million protected users earns EY recognition. TAMPA, FL, UNITED STATES, April 23, 2026 /EINPresswire.com/ — When a wave of SonicWall-related attacks hit earlier this year, Ridge IT Cyber‘s clients saw the intrusion attempts detected and contained automatically — identities locked down user by user before attackers could move laterally. Organizations without that identity-first architecture got breached. That outcome — the difference between a contained event and a business-impacting one — is why Ridge IT Cyber co-founder and CEO Chad Koslow has just been named a 2026 finalist for the EY Entrepreneur of the Year® Florida program, which includes entrepreneurs from both Florida and Puerto Rico. Regional winners will be announced June 12, 2026. The thesis that built the company Most cybersecurity vendors sell products against a checklist. Ridge IT Cyber was founded on the opposite premise: the tools only matter if the architecture survives a real attacker. That conviction — forged supporting some of the most demanding government environments in the world — has grown into a firm that today protects more than 2.5 million users across 160 countries, has delivered more than 1,500 Zero Trust implementations in the last three years, and maintains a 99% client retention rate. It’s also why Ridge IT Cyber has stacked recognition most MSSPs never see: • Inc. Magazine’s #1 MSSP in America — back-to-back, 2023 and 2024 • Inc. 5000 national list — three consecutive years (2023–2025) • Inc. Regionals: Southeast — three consecutive years, including 2026 • CRN MSP 500 — 2025 • Zscaler Partner of the Year • Okta Service Delivery Authorized – Okta Workforce Identity (OWI) and Okta Customer Identity (OCI) Why this matters to the people buying security in 2026 The threat landscape

The <b>Cybersecurity</b> Firm Most Enterprises Have Never Heard Of Just Earned an EY ...

Three consecutive Inc. 5000 appearances and back-to-back #1 MSSP honors — now the founder behind 2.5 million protected users earns EY recognition. TAMPA, FL, UNITED STATES, April 23, 2026 /EINPresswire.com/ — When a wave of SonicWall-related attacks hit earlier this year, Ridge IT Cyber‘s clients saw the intrusion attempts detected and contained automatically — identities locked down user by user before attackers could move laterally. Organizations without that identity-first architecture got breached. That outcome — the difference between a contained event and a business-impacting one — is why Ridge IT Cyber co-founder and CEO Chad Koslow has just been named a 2026 finalist for the EY Entrepreneur of the Year® Florida program, which includes entrepreneurs from both Florida and Puerto Rico. Regional winners will be announced June 12, 2026. The thesis that built the company Most cybersecurity vendors sell products against a checklist. Ridge IT Cyber was founded on the opposite premise: the tools only matter if the architecture survives a real attacker. That conviction — forged supporting some of the most demanding government environments in the world — has grown into a firm that today protects more than 2.5 million users across 160 countries, has delivered more than 1,500 Zero Trust implementations in the last three years, and maintains a 99% client retention rate. It’s also why Ridge IT Cyber has stacked recognition most MSSPs never see: • Inc. Magazine’s #1 MSSP in America — back-to-back, 2023 and 2024 • Inc. 5000 national list — three consecutive years (2023–2025) • Inc. Regionals: Southeast — three consecutive years, including 2026 • CRN MSP 500 — 2025 • Zscaler Partner of the Year • Okta Service Delivery Authorized – Okta Workforce Identity (OWI) and Okta Customer Identity (OCI) Why this matters to the people buying security in 2026 The threat landscape

CISO Diaries: Stefano Pasotti on <b>Cybersecurity</b> as Strategy, Not Cost

CISO Diaries: Stefano Pasotti on Cybersecurity as Strategy, Not Cost Cybersecurity is often viewed through the lens of controls, compliance, and incident response, but its real value is much broader. In CISO Diaries, we speak with security leaders around the world to understand how they approach the role beyond the technical domain, particularly on how they make decisions, manage uncertainty, and align security with business resilience. The series explores the routines, habits, and perspectives that shape modern security leadership, revealing the human judgment behind the frameworks. As the role of the CISO continues to expand, the job is increasingly about more than protecting systems. It is about enabling continuity, supporting operational efficiency, and helping organizations make better decisions in the face of complexity. Through these conversations, CISO Diaries highlights how security leaders are not just defending against risk, but helping shape strategy, culture, and long-term competitive advantage. About Stefano Pasotti Stefano Pasotti is CISO and ICT Manager at DN Automotive Italy, where he leads cybersecurity, IT infrastructure, and digitalization initiatives across European operations. His career spans software development, strategic IT leadership, and cybersecurity, with deep experience connecting technology decisions to business outcomes across manufacturing and logistics environments, including WMS, production planning, EDI, and IoT integration. Known for his pragmatic and strategic approach, Stefano views cybersecurity not as a cost center, but as a driver of resilience, efficiency, and competitive advantage. His perspective is shaped by operating in multinational environments where security requires not only technical expertise, but cultural alignment, regulatory awareness, and careful communication. Through that lens, he brings a leadership approach grounded in discipline, continuous learning, and the belief that effective security is inseparable from sound business strategy. How do you usually explain what you do to someone outside of cybersecurity? I say I’m the person who makes sure

Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?

Last week, Anthropic announced Project Glasswing, an AI model so effective at discovering software vulnerabilities that they took the extraordinary step of postponing its public release. Instead, the company has given access to Apple, Microsoft, Google, Amazon, and a coalition of others to find and patch bugs before adversaries can. Mythos Preview, the model that led to Project Glasswing, found vulnerabilities across every major operating system and browser. Some of these bugs had survived decades of human audits, aggressive fuzzing, and open-source scrutiny. One had been sitting for 27 years in OpenBSD, generally considered to be one of the world’s most secure operating systems. It's tempting to file this under "AI lab says their AI is too dangerous," the same playbook OpenAI ran with GPT-2. Not so fast; there's a material difference this time. Mythos didn't just find individual CVEs. - It chained four independent bugs into an exploit sequence that bypassed both the browser renderer and the OS sandboxing - It performed local privilege escalation in Linux through race conditions - It built a 20-gadget ROP chain targeting FreeBSD's NFS server, distributed across packets. Claude Opus 4.6, Anthropic's previous frontier model, failed at autonomous exploit development almost entirely.Mythos hit a 72.4% success rate in the Firefox JS shell. This isn't theoretical, nor some new three-to-five-year prediction. This is about to be a real-world engineering reality. Why Project Glasswing Exposes the Real Cybersecurity Gap Here's the number that should keep security leaders awake at night: fewer than 1% of the vulnerabilities found by Mythos were patched. Let that sink in for a moment. The most powerful vulnerability discovery engine ever built ran against the world's most critical software, and the ecosystem couldn't absorb the output. Glasswing solved the finding problem. Nobody solved the problem of fixing. Why Defenders Can't Keep

Regions and cities push for simpler digital tools and advanced <b>cybersecurity</b> capacities

Theresa Sostmann Theresa.Sostmann@cor.europa.eu ECON members also stressed the need of a place-based approach to the EU defence industry and to industrial acceleration policies. Strengthening Europe’s competitiveness and resilience through advances in digital transformation, cybersecurity, and industrial policy while ensuring that local and regional authorities are adequately supported and actively involved was the main focus of the meeting of the Commission for Economic Policy (ECON) on 23 April. Local and regional leaders adopted a draft opinion, calling for the simplification of digital public services through user-friendly European Business Wallets. They also addressed growing cybersecurity challenges, and how to align industrial and defence initiatives with territorial needs. Simplifying digital public services Digital transformation is a key driver of European competitiveness and a cornerstone for economic productivity. However, complex procedures and regulatory and administrative burdens remain that continue to hinder the full potential of the Single Market. In this context, ECON members adopted a draft opinion on European Business Wallets (EBWs), stressing that they must be designed as simple, user-friendly and cost-effective solutions, particularly tailored to the needs of SMEs, micro-enterprises and start-ups, to support business growth across borders. They highlighted that EBWs should enable a ‘once-only’ principle, allowing businesses to submit data a single time and reuse it across different administrative procedures. They also called for targeted awareness-raising and clear guidance to ensure broad uptake, as well as adequate financial support, technical assistance and training to help local administrations meet new obligations. Rapporteur Branislav Zacharides (SK/ECR), Mayor of Vrútky, said: "The deployment of the Business Wallets will entail new administrative obligations for public authorities, which can be especially burden some for smaller municipalities. We therefore call on the European Commission and Member States to provide adequate technical capacity-building and financial support so that the Wallets can deliver real added value.” The opinion

CISA Warns of FIRESTARTER Malware Targeting Cisco ASA including Firepower and ...

CISA Warns of FIRESTARTER Malware Targeting Cisco ASA including Firepower and Secure Firewall Products WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) published a malware analysis report today on FIRESTARTER, malware that allows remote access and control by malicious threat actors targeting Cisco Firepower and Secure Firewall products running Adaptive Security Appliance (ASA) or Firepower Threat Defense (FTD) software. In conjunction with this report, CISA issued new required actions for Federal Civilian Executive Branch (FCEB) agencies in Emergency Directive 25-03: Identify and Mitigate Potential Compromise of Cisco Devices. Threat actors continue to target these devices and products, posing significant risks to all organizations. This malware analysis report, co-sealed with United Kingdom National Cyber Security Centre (NCSC-UK), provides organizations with the knowledge to help them detect and respond to FIRESTARTER. This report provides technical details on threat actor activity, FIRESTARTER’s secret to achieving persistence, as well as recommended detection methods, mitigations and actions for incident response. In this report, CISA and NCSC-UK assess that an advanced persistent threat (APT) actor exploited CVE-2025-20333 and CVE-2025-20362 in Cisco ASA firmware to gain initial access and deploy FIRESTARTER on Firepower and Secure Firewall devices. “FIRESTARTER can persist as an active threat on Cisco ASA devices or FTD software. CISA encourages organizations using these devices or software to review the FIRESTARTER report, assess devices for compromise, implement mitigations, and report any findings to CISA,” said CISA Acting Director Nick Andersen. “Every day, CISA works with federal government and industry partners to assess cyber threats and publish actionable information for organizations to better protect themselves and ensure the integrity of their digital infrastructure.” During proactive monitoring of Cisco ASA devices used by FCEB agencies, CISA detected FIRESTARTER malware that enabled post-patching persistence. CISA analysis determined that firmware patching actions on compromised devices did not necessarily

Robert Cohen named among <b>Cybersecurity</b> Docket's “Incident Response Elite for 2026”

Robert Cohen named among Cybersecurity Docket’s “Incident Response Elite for 2026” Davis Polk partner Robert Cohen was named among Cybersecurity Docket’s “Incident Response Elite for 2026.” The list recognizes the best incident response lawyers in the business based on considerable research, nominations, and input from senior lawyers and other professionals in the field. The “Incident Response Elite for 2026” list was announced on April 23, 2026. Copy link to share post

EvilTokens: Big Cybercrime's AI Platform Built to Bypass Your MFA | Huntress

EvilTokens: Big Cybercrime’s AI Platform Built to Bypass Your MFA May 5, 2026 | 3pm ET | 12pm PT In February 2026, a phishing operation called EvilTokens popped up on Telegram with its own storefront and pricing. By mid-March, it had compromised identities at hundreds of organizations across five countries, all without using malware. Cybercriminals wasted no time putting AI to work. They were early adopters because AI makes phishing more convincing and makes it easier to stand up infrastructure on demand. In this case, the operation abused legit authentication flows and routed victims through trusted services their own security tools were built to trust, making MFA far less protective. Microsoft and Huntress will break down how attackers are actually using AI. Join two of the best in the business as they examine a watershed moment in cybercrime. Sherrod DeGrippo Sherrod DeGrippo is General Manager of Global Threat Intelligence and host of the Microsoft Threat Intelligence Podcast. She has been recognized as Cybersecurity Woman of the Year (2022) and Cybersecurity PR Spokesperson of the Year (2021). Before her current role, Sherrod served as Director of Threat Intelligence Strategy at Microsoft. Her background also includes serving as Vice President of Threat Research and Detection at Proofpoint, where she led a global team focused on threat research, malware analysis, and intelligence operations. With more than two decades of cybersecurity experience, she has held senior roles at Nexum, Symantec, Secureworks, and the National Nuclear Security Administration. Sherrod is a frequently cited expert across major media outlets and a regular speaker at global security conferences. Casey Smith Casey Smith's cybersecurity journey began in the early 2000s at Cisco Systems, where he contributed to the groundbreaking SAFE (Secure Architecture for Enterprise) initiative — sparking a career-long passion for testing the boundaries of defensive systems. He

UWF breaks ground on new AI, <b>cybersecurity</b> and engineering research building

UWF breaks ground on new AI, cybersecurity and engineering research building PENSACOLA, Fla. -- The University of West Florida officially broke ground on a "new advanced intelligence, cybersecurity and engineering research building" Thursday. The building is called "The Synapse." It's partly funded by Triumph Gulf Coast's $32.5 million award, with more than $21 million in state dollars. "The 55,000-square-foot building on the Pensacola campus will house specialized labs and state-of-the-art equipment and technology to support advanced computational, AI, cybersecurity and engineering research across the University," UWF said. It'll be Building 129, located just south of the John C. Pace Library. Many in the UWF community came together to celebrate the start of construction. “The Synapse is a transformational facility made possible through the support of Triumph Gulf Coast and the state of Florida,” said UWF President Manny Diaz Jr. “This new modern facility will allow the University to expand research capacity, strengthen industry partnerships and better prepare students for career fields critical to our region’s future.” "The facility will serve as the base for the Center for Computational Intelligence and the Center for Cybersecurity and AI, as well as a hub for collaborative projects in robotics, artificial intelligence, cybersecurity, power systems, material science and civil engineering," according to UWF. "A central multi-story atrium with interconnected corridors create efficient pathways for interaction, resulting in a facility built not only for cutting-edge technology, but for constant intellectual connection." When construction is complete, the UWF Center for Cybersecurity and AI will join CCI in the Synapse.

New AI tool reshapes the <b>cybersecurity</b> landscape

Be scared. Very scared. Readers captivated by cybersecurity developments have likely seen mention of Mythos, the latest version of the Claude artificial intelligence that has been developed by Anthropic. The company decided to withhold release of the software to the public because it is considered too dangerous. Anthropic isn’t worried about some abstract hypothetical: This isn’t handwringing over a Terminator-style AI that will conquer the world. The decision was based on actual experience. Mythos discovered thousands of vulnerabilities in every major operating system and browser. Anthropic has been largely applauded for its caution and responsible decision-making. Cybersecurity experts warn that it’s too early to reach firm conclusions but there appears to be consensus that Mythos represents a “step change” in capability and is a taste of the new digital world that we now inhabit. When testing the new version, Anthropic’s red team found that it “is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so. The vulnerabilities it finds are often subtle or difficult to detect.” (For the uninitiated, a “red team” is the officially designated group who tests a system’s safety and security. And while I’m providing a lexicon, a “zero-day vulnerability” is a software bug that is unknown to the manufacturer and for which there is no immediate fix. It is considered the holy grail of hacks; companies pay hackers to find them and national cybersecurity authorities have huge budgets to buy them for future use.) Mythos uncovered thousands of vulnerabilities, including one more than 25 years old in what was thought to be one of the most secure software applications in the world. Not only does it find those holes; it also figures out how to exploit them. Mythos turned

OpenAI briefs US agencies, Five Eyes on new <b>cybersecurity</b> product: Report

OpenAI has briefed US federal agencies, state governments and Five Eyes member countries on the capabilities of its new cybersecurity product over the past week, Axios reported on Wednesday. Cybersecurity is becoming a key battleground for AI labs such as OpenAI and Anthropic as their advanced AI models can both pose security risks and offer cyber defense capabilities, sparking interest from governments and enterprises. OpenAI did not immediately respond to a request for comment. Reuters could not independently verify the report. The ChatGPT-maker unveiled GPT-5.4-Cyber last week, a variant of its latest flagship model fine-tuned specifically for defensive cybersecurity work, following rival Anthropic’s announcement of advanced AI model Mythos. OpenAI held an event in DC on Tuesday for about 50 cyber defense practitioners across the federal government to demo the capabilities of its new GPT-5.4-Cyber model, according to the report by Axios. OpenAI is starting briefings with Five Eyes members this week to get them vetted and signed up to access the model, the report said. The Five Eyes intelligence sharing network comprises the US, Britain, Canada, Australia and New Zealand. Sam Altman-led OpenAI has said that GPT-5.4-Cyber would initially be rolled out on a limited basis to vetted security vendors, organizations and researchers because of its more permissive design. Earlier this month, rival Anthropic also announced a “Project Glasswing” initiative with major technology companies that lets partners preview the startup’s unreleased model.

Anthropic investigates report of rogue access to hack-enabling Mythos AI

The AI developer Anthropic has confirmed it is investigating a report that unauthorised users have gained access to its Mythos model, which it has warned poses risks to cybersecurity. The US startup made the statement after Bloomberg reported on Wednesday that a small group of people had accessed the model, which has not been released to the public because of its ability to enable cyber-attacks. “We’re investigating a report claiming unauthorised access to Claude Mythos Preview through one of our third-party vendor environments,” said Anthropic. Bloomberg said a “handful” of users in a private online forum gained access to Mythos on the same day Anthropic said it was being released to a small number of companies including Apple and Goldman Sachs for testing purposes. It reported that the unnamed users got to Mythos through access that one of them had as a worker at a third-party contractor for Anthropic and by deploying methods used by cybersecurity researchers. The group has not run cybersecurity prompts on the model and is more interested in “playing around” with the technology than causing trouble, according to Bloomberg, which corroborated the claims via screenshots and a live demonstration of the model. Nonetheless, news of the potential breach will alarm authorities who have raised concerns about Mythos’s potential to wreak havoc and will raise questions about how potentially damaging technology can be kept out of the wrong hands. Kanishka Narayan, the UK’s AI minister, has said UK businesses “should be worried” about the model’s ability to spot flaws in IT systems – which hackers could then act upon. The model has been vetted by the world’s leading safety authority for the technology, the UK’s AI Security Institute (AISI), which warned last week that Mythos was a “step up” from previous models in terms of the cyber-threat