There are some important developments concerning cybersecurity — so let’s push past the anxiety and talk about them. I was at a conference recently where a group of practitioners discussed cybersecurity for retirement plans. The topic admittedly makes me cringe as it dredges up some of the hardest situations I’ve ever helped clients navigate: theft — sometimes of nearly all a plan’s or saver’s assets. Ugh. Not exactly the kind of retirement policy discussion that brightens your day. While this isn’t a new topic — there are some important developments — so let’s push past the anxiety and talk about them. If, like me, you’re a fan of The Hitchhiker’s Guide to the Galaxy, you know the most important words printed on the cover of the Guide are simple: “Don’t Panic.” That’s excellent advice for both interstellar hitchhiking and cybersecurity incidents in retirement plans (which, trust me, feel almost as chaotic). Tempting as panic may feel in the moment — or even when contemplating the possibility of a theft from your plan — cybersecurity requires the opposite response. In today’s world, cybersecurity threats aren’t some sci-fi subplot. They’re part of the routine retirement plan administration that fiduciaries must face. Which brings us to an important lesson from Hitchhiker’s lore: Keep Calm and Carry a Towel (or, in this case, a prudent policy!). Or perhaps a towel and a policy — belt and suspenders never hurt anyone in ERISAland. Prudent Policy: The Cybersecurity Towel Translated into retirement plan terms, the wisdom “Keep Calm and Carry a Towel” holds up remarkably well. Keep calm: don’t let fear or confusion drive bad decisions or inaction. Carry a towel: be prepared with the right governance structures, documentation, and protections in place. Under ERISA, fiduciary prudence and loyalty don’t stop at selecting investments. The Department
Apr 17, 2026 · via asppa-net.org
Artificial intelligence (AI) creates two sets of cybersecurity risks: cyber risks in the AI systems themselves, and cyber risks from AI tools used to exploit non-AI systems. The U.S. government has primarily focused on the former, but it should urgently be preparing for the latter. Securing AI systems has been a priority for the past two administrations. Under President Biden, the National Institute of Standards and Technology (NIST) created the U.S. AI Safety Institute to support the development of safe and secure AI. Later, under President Trump, NIST reformed the organization as the Center for AI Standards and Innovation (CAISI) and refocused its priorities to concentrate on securing commercial systems. Late last year, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) issued a report for securely integrating AI in government operations, which included principles such as secure‑by‑design integration, continuous monitoring, anomaly detection, human‑in‑the‑loop oversight, and rigorous testing and red‑teaming of AI systems. But the federal government has taken relatively few steps to address risks in existing systems that cyber threat actors may discover and exploit using artificial intelligence (AI) tools, despite policymakers being aware of the issue. For example, nearly two years ago, the Bipartisan Senate AI Working Group called on lawmakers “to develop legislation bolstering the use of AI in U.S. cyber capabilities.” Similarly, the Bipartisan House Task Force on AI stated that “security teams must use AI defensively to improve cybersecurity resiliency.” However, the issue has now reached a new level of urgency. Earlier this month, Anthropic announced Claude Mythos Preview, a new frontier AI model—meaning a cutting-edge model that pushes the boundaries of what AI can accomplish —that is “capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser.” For example, the model uncovered
Apr 17, 2026 · via datainnovation.org
An energetic start to a career in cybersecurity KALAMAZOO, Mich.—From Accra, Ghana, Gabriel Gyimah is taking his career to the next level by pursuing a Master of Science in cybersecurity from Western Michigan University’s Haworth College of Business. As a first-year graduate student, Gyimah is not only achieving a robust education, but he is also setting himself up for a fulfilling career. With a Bachelor of Science degree in electrical and electronics engineering from Kwame Nkrumah University of Science and Technology and a Bachelor of Laws degree from the Ghana Institute of Management and Public Administration, Gyimah is bringing his energy for learning to a new facet of his future career. “My professional career began with a foundation in electrical engineering, where I developed strong analytical skills,” he says. “I later expanded my perspective by pursuing legal education, which deepened my understanding of regulation, compliance and ethical decision making in complex organizations.” So why did Gyimah choose cybersecurity at WMU? “The cybersecurity program enables me to combine my technical background with my interests in policy, governance and risk management. The program’s interdisciplinary structure aligns closely with my goal of contributing to secure and compliant systems in real-world environments.” With a high-demand program, support is essential. Gyimah has formed valuable relationships at WMU Haworth to help safeguard his success. “I have found a meaningful mentor in Beth Ernst, the faculty specialist for the Academic and Business Communication Skills course. Her guidance has been instrumental in helping me navigate career development within the American professional context, particularly as an international student learning workplace norms, expectations and communication styles. She has also supported my integration into the Kalamazoo community by encouraging cultural engagement, confidence and effective communication across diverse settings.” During his time at WMU, Gyimah has welcomed the changes in his education
Apr 17, 2026 · via wmich.edu
GW Law Professor Mary Anne Franks has been selected as a spring 2026 fellow with the University of Chicago’s Forum for Free Inquiry and Expression. Professor Franks, the Eugene L. and Barbara A. Bernard Professor in Intellectual Property, Technology, and Civil Rights Law, is an internationally recognized expert on the intersection of civil rights, free speech, and technology. As a fellow, she will explore the tensions between free expression and harm and connect directly with University of Chicago students through office hours and campus conversations. The Chicago Forum promotes the understanding, practice, and advancement of free and open discourse at the University of Chicago and beyond. Professor Franks, who taught at the University of Chicago Law School as a Bigelow Fellow early in her career, says she is looking forward to returning to the institution that helped shape her scholarly trajectory. “The U of C provided such an intellectually vibrant and challenging community for me when I was starting out as a legal academic,” she said. “I am grateful for the opportunity to return there as a Fellow for the Chicago Forum for Free Inquiry and Expression, especially at a time when authoritarian attacks are gravely endangering academic freedom and freedom of expression in the United States.” Professor Franks’ scholarship has had a global impact. She has written two books, Fearless Speech: Breaking Free from the First Amendment and The Cult of the Constitution: Our Deadly Devotion to Guns and Free Speech. Her scholarship has also been published in numerous law journals, including the Harvard Law Review, the California Law Review, and the UCLA Law Review. Earlier this year, she received the NAACP’s Archwell Digital Civil Rights Award, which was presented in partnership with Archwell Philanthropies, home to the charitable work of Prince Harry and Meghan, the Duke and Duchess
Apr 17, 2026 · via law.gwu.edu
Time for government, business leaders to figure out AI cybersecurity regulation Experts say capabilities of agentic AI rising, along with risk to personal data, economy, national security As new agentic AI models continue to come online, cybersecurity experts laud their ability to sift through vast quantities of data quickly and autonomously — making them great tools to help fight cybercrime. But, they warn, those attributes could also be put to work by bad actors to hack systems and risk our personal data, our economy, and our national security. A group of cybersecurity experts were recently brought together for a Berkman Klein Center for Internet and Security discussion, during which all agreed that it’s high time for business and government leaders to regulate the tech — before it’s too late. Cybercrime, recent data from IBM shows, is rising rapidly. According to a 2026 study, the company found that cyberattacks aimed at public-facing software and systems applications — many of which utilized AI — had a year-over-year increase of 44 percent. High-profile attacks include the November data breach of Anthropic — the AI company behind the Claude Code assistant. Attackers were able to use their own AI models to scan for weak spots in its source code and publish its inner workings. “The unfortunate thing is that the bad people only have to win once in some sense, whereas the defenders have to win all the time,” said James Mickens, Gordon McKay Professor of Computer Science. “To me, at least, that’s a concerning aspect of what it means to think about agentic cyber security, attacks and defenses.” Moreover, cybercriminals have made alarming progress in phishing attacks over recent months, using AI to fine-tune targets and craft messages. “A year ago, we still had email messages in our inbox that had misspellings that
Apr 17, 2026 · via news.harvard.edu
Cybersecurity researchers have warned of an active malicious campaign that's targeting the workforce in the Czech Republic with a previously undocumented botnet dubbed PowMix since at least December 2025. "PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade the network signature detections," Cisco Talos researcher Chetan Raghuprasad said in a report published today. "PowMix embeds the encrypted heartbeat data along with unique identifiers of the victim machine into the C2 URL paths, mimicking legitimate REST API URLs. PowMix has the capability to remotely update the new C2 domain to the botnet configuration file dynamically." The attack chain begins with a malicious ZIP file, likely delivered via a phishing email, to activate a multi-stage infection chain that drops PowMix. Specifically, it involves a Windows Shortcut (LNK) that's used to launch a PowerShell loader, which then extracts the malware embedded within the archive, decrypts it, and runs it in memory. The never-before-seen botnet is designed to facilitate remote access, reconnaissance, and remote code execution, while establishing persistence by means of a scheduled task. At the same time, it verifies the process tree to ensure that another instance of the same malware is not running on the compromised host. PowMix's remote management logic allows it to process two different kinds of commands sent from the C2 server. Any non #-prefixed response causes PowMix to shift to arbitrary execution mode, and decrypt and run the obtained payload. - #KILL, to initiate a self-deletion routine and wipe traces of all malicious artifacts - #HOST, to enable C2 migration to a new server URL. In parallel, it also opens a decoy document with compliance-themed lures as a distraction mechanism. The lure documents reference legitimate brands like Edeka and include compensation data and valid legislative references, potentially in an
Apr 17, 2026 · via thehackernews.com
Alden Trust Grant Powers Creation of Cybersecurity Teaching Lab at St. Lawrence St. Lawrence University has received a $200,000 grant commitment from the George I. Alden Trust to support a new Cybersecurity Teaching Laboratory that will enhance the University’s newest academic major: Cybersecurity. The grant continues the Alden Trust’s longstanding partnership with St. Lawrence, which has strengthened campus learning facilities at pivotal moments—including support for the Bloomberg Finance Lab. The Cybersecurity Teaching Lab builds on that momentum, supporting critical infrastructure upgrades to transform a traditional classroom into a specialized environment designed specifically for one of today’s fastest-growing and most in-demand fields. The lab will provide a dynamic, collaborative learning environment where students develop technical expertise and knowledge through simulations, collaborative projects, and real-world problem solving. Planned for completion this spring and summer, the Cybersecurity Teaching Laboratory is expected to open its doors to students and faculty in fall 2026. The Cybersecurity major is the seventh academic program launched at St. Lawrence since 2020, reflecting the University’s commitment to expanding interdisciplinary offerings aligned with emerging career opportunities. “We are grateful to the George I. Alden Trust for its generous support of this important new facility, which will strengthen experiential learning opportunities for students in our new Cybersecurity major,” says President Kate Morris. “This investment will help prepare students for one of today’s fastest-growing fields through a liberal arts focus that complements interdisciplinary perspectives with content expertise.” Assistant Professor of Computer Science Kevin Angstadt ’14, who helped guide the Cybersecurity major from concept to approval, says the program was intentionally designed to balance technical depth with flexibility. “The new Cybersecurity Lab will serve as the hub for cybersecurity education at St. Lawrence, enabling us to teach a range of courses that bridge the gap between theory and practice and provide our students
Apr 17, 2026 · via stlawu.edu
Katie Bavoso sits down with MK Tong, CEO of SotaTek USA, to break down why infrastructureânot AI modelsâis the real bottleneck for enterprise success SecurityBridge CEO Jesper Zerlang discusses SAP security, AI risks like data poisoning, and why channel partnerships are key to 2026 growth. Spyglass MTG CEO Dori Albert explains how organizations can build secure and data-driven AI platforms that deliver real business value. Leaders from Harbor IT explain why the traditional generalist MSP model is fading and how specialization, cybersecurity expertise, and vertical industry focus are shaping the future of managed services. In this Channel Insider crossover, the hosts of The Neuron break down the AI race, the bubble debate, and what todayâs tools really mean for businesses and everyday users. SurePath AI CEO Casey Bleeker explains how organizations can accelerate generative AI adoption using zero trust principles and AWS guardrails without increasing security and compliance risk. - Channel Business - Security - AI - Infrastructure Related Topics - - Lists & Awards Top ArticlesLink to AI 50 ListAI 50 ListChannel Insider's editorial team spotlights the top AI leaders from MSPs, vendors, and channel businesses delivering measurable outcomes.Link to CML 100 HonoreesCML 100 HonoreesCheck out our CML 100 List to discover the top channel marketing individuals who are transforming channel marketing for their organizations.Link to HSP 250 ListHSP 250 ListView our HSP250 list to see the top Hybrid Solution Providers that have proactively embraced the future of tech.Link to The 2024 Channel Insider VIP ListThe 2024 Channel Insider VIP ListChannel Insider sought nominations from IT vendors, solution providers, and partners to highlight impactful collaborations. Check out our top choices here. - Resources Resource HubsFeatured ResourcesLink to Video: SotaTek US CEO on AI Infrastructure Mistakes MSPs Must FixVideo: SotaTek US CEO on AI Infrastructure Mistakes MSPs Must Fix Katie
Apr 17, 2026 · via channelinsider.com
When Anthropic launched Project Glasswing earlier this month, it did so with the kind of announcement that sounded like public service and read like a market consolidation.
The initiative brought together Amazon Web Services (AWS), Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks — essentially the who’s who of the global technology industry — under a single coordinated effort to secure the world’s most critical software using an unreleased AI model called Claude Mythos Preview.
Published - April 17, 2026 06:12 am IST
Apr 17, 2026 · via thehindu.com
The arrival of artificial intelligence (AI) supercharged technology stocks in recent years, but the situation changed in 2026. Wall Street's "great rotation" away from tech stocks caused a sharp drop in the share prices of cybersecurity companies. Now, investors have an opportunity to scoop up stocks in the sector at attractive valuations. Buying the dip makes sense because cybersecurity is a necessity to safely navigate online. That's why the industry is forecast to grow from $248 billion in 2026 to $699 billion by 2034. In fact, Palo Alto Networks (PANW +1.74%) CEO Nikesh Arora took advantage of the situation to buy company shares worth about $10 million in March. This was his first buy since 2019. Here's a look at this situation and why it makes sense to buy cybersecurity stocks now. Cybersecurity remains a resilient sector In early 2026, Wall Street believed that artificial intelligence (AI) could usurp cybersecurity companies' business. But several factors make that possibility unlikely. The stakes are too high for organizations to entrust IT security to unproven AI substitutes from the likes of Anthropic, despite its release of an AI capable of finding software vulnerabilities. Look no further than CrowdStrike's technical glitch in 2024 for an example of cybersecurity's central role in today's digital world. The company's mistake caused global disruption to airlines, banks, and hospitals. Rather than lose to AI, the more likely scenario is for cybersecurity enterprises to partner with the companies building artificial intelligence. Both Palo Alto Networks and SentinelOne (S +5.17%) are collaborating with Alphabet-owned Google Cloud to ensure AI infrastructure is protected. NASDAQ: PANW Key Data Points Moreover, several IT security providers have already woven artificial intelligence into their platforms. A prime example is SentinelOne, an early adopter of the tech, having built AI into the core of its systems
Apr 17, 2026 · via fool.com
Cybersecurity experts warn of new CAPTCHA scam How to protect yourself online ST. LOUIS, Mo. (First Alert 4) - You’ve probably seen CAPTCHA security prompts on some websites to verify that you’re human. But cybersecurity experts are warning you to watch out for CAPTCHA scams. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. Retail, banking, and other websites often ask users to click on CAPTCHA prompts to verify that they’re not a robot. CAPTCHA prompts are designed to prevent automated bots from rapidly buying up inventory of things like popular concert tickets or products, or opening online accounts. But Dean Gefen, CEO and founder of cybersecurity firm NuKudo, says fake CAPTCHA scams are popping up on both real and fake websites. Some will ask users to press Windows Key +R, then Ctrl +V, then Enter, ask users for passwords to accounts, or to download something on their device. “If the CAPTCHA is asking you to put something on your device, to do a shortcut, it shouldn’t be the case. Also, CAPTCHA doesn’t require you to insert your name or password. And it doesn’t require you to download software on your device,” explained Gefen. Those requests, he said, are red flags for CAPTCHA scams. The Identity Theft Resource Center reports that when victims press the sequence of keys, it can open a hidden command box on the device, paste in and run a script to download a virus. The ITRC says it’s called the “STealC” virus, which can track what you do on the device, as well as collect passwords and cookies from Outlook and other accounts. If you do fall for a CAPTCHA scam, ITRC says immediately take action: - Disconnect your device from the internet, but turning off the WIFI or unplug the
Apr 16, 2026 · via firstalert4.com
When it comes to cybersecurity readiness, McKaveney presented five questions that small districts and those with limited staffing and budgets should answer. - Do we know what we have, what data we protect and where our biggest risks are? - Are we using basic protections that prevent the most common attacks? - Would we notice if something went wrong? - What do we do if a cyber incident happens tomorrow? - Could we recover learning and operations quickly after an incident or other disaster? Identify Cyber Inventory and Risks CoSN guidance recommends starting with an asset inventory and risk assessment to ensure cybersecurity efforts are directed properly to maximize investments. This could be as simple as a list on a spreadsheet or identifying assets via helpdesk software, McKaveney said. DISCOVER: K–12 schools need a roadmap for effective cybersecurity. Richard Platts, CTO of Allegheny Intermediate Unit in Pennsylvania, said data inventory is just as important as hardware and software inventory. Governance and ownership are a large piece of that. Data ownership is a three-tier system, he said. “Think about your your IEP [Individualized Education Program] management software,” he said. “I've always insisted that that data owner is the special education director. It's a named person who owns that data. They might not do the daily maintenance of that data or the data entry, but at the end of the day, they're responsible for the overall quality of that data to be able to provide services to students.” The next tier down are the data stewards, the people responsible for the maintenance and fitness the data, typically the IT team. “Then you have a lot of other people down there, as general data users, who might be doing the day-to-day data entry or are relying on that data to do their job,”
Apr 16, 2026 · via edtechmagazine.com
Virginia’s governor promotes cybersecurity chief Mike Watson to state CIO role Virginia Gov. Abigail Spanberger, who assumed office in January, on Wednesday named Michael Watson, Virginia’s chief information security officer, as the commonwealth’s new CIO. Watson fills a slot recently occupied by Bob Osmond, who was last week named as Delaware’s new CIO. After more than 18 years with the Virginia Information Technologies Agency, Watson is tasked with leading the state’s enterprise IT, cloud, artificial intelligence and “digital modernization” efforts, according to a bio posted to the agency’s website. It also notes his reputation “for bridging technical depth with strategic execution.” The agency says it manages 65,000 users, 2,500 applications and $1.3 billion in annual technology procurement. According to his LinkedIn profile, Watson started his career by working a variety of technical roles over seven years with the Ajax Electric Company, a Pennsylvania manufacturer of heat treatment furnaces. He spent four years as a senior systems programmer at the University of Pennsylvania and nearly one-and-a-half years doing IT at the Virginia Auditor of Public Accounts. He joined Virginia’s technology agency in 2007, as a director of security incident management, before working his way up to the deputy CISO role in 2011. Watson is credited with heading numerous cybersecurity initiatives in Virginia, including shifting the commonwealth toward a “whole of state” cyber program, providing greater support for educational institutions and other non-state-government offices. In 2024, the National Association of State Chief Information Officers presented Watson with its Thomas M. Jarrett State Cybersecurity Leadership Award, a recognition of his work advancing cybersecurity policy in Virginia. He’s credited with implementing a zero-trust strategy and advancing cybersecurity training for state workers, but Watson has also distinguished himself by the length of his tenure. Serving more than a decade in a CISO role puts him
Apr 16, 2026 · via statescoop.com
Anthropic releases Claude Opus 4.7 with automated cybersecurity safeguards Software teams building agentic AI workflows have been pushing frontier models toward longer, unsupervised task runs. Claude Opus 4.7, now generally available from Anthropic, is aimed squarely at that demand, with particular gains in software engineering, multimodal processing, and the kind of instruction fidelity that matters when a model is running tasks autonomously over multiple steps. Opus 4.7 is available across all Claude products and the API, Amazon Bedrock, Google Cloud’s Vertex AI, and Microsoft Foundry. Pricing remains the same as Opus 4.6: $5 per million input tokens and $25 per million output tokens. What changed from Opus 4.6 Opus 4.7 is a notable improvement on Opus 4.6 in advanced software engineering, with particular gains on the most difficult tasks. The model handles complex, long-running tasks with rigor and consistency, pays precise attention to instructions, and devises ways to verify its own outputs before reporting back. On the vision side, the upgrade is significant. Opus 4.7 can accept images up to 2,576 pixels on the long edge, approximately 3.75 megapixels, more than three times as many as prior Claude models. That increase supports use cases including computer-use agents reading dense screenshots, data extractions from complex diagrams, and work that needs pixel-perfect references The higher resolution is a model-level change, meaning images sent to the API are automatically processed at greater fidelity; users who do not need the extra detail can downsample images before sending to control token costs. Instruction-following behavior has also shifted in ways that require attention from teams migrating existing deployments. Where previous models interpreted instructions loosely or skipped parts entirely, Opus 4.7 takes the instructions literally. Users should re-tune their prompts and harnesses accordingly. Opus 4.7 is also better at using file system-based memory. It remembers important notes
Apr 16, 2026 · via helpnetsecurity.com
- Safe Mode The federal government’s most underrated cybersecurity tool In this episode of Safe Mode, we sit down with Philip George, Executive Technical Strategist at Merlin Group to talk about the real challenges federal agencies face at the intersection of cybersecurity, AI adoption, and post-quantum cryptography. Philip breaks down the disconnect between cyber spending and mission outcomes, why rushing into AI without sound identity management and data integrity is a recipe for disaster, and what evolving federal cryptographic requirements and shortened certificate lifecycles mean for government IT. We dig into why visibility — simply knowing what’s on your network — remains the most powerful defensive posture regardless of the threat, explore the tension between zero trust and agentic AI, and hear Philip’s counterintuitive take that the answer to AI-driven security challenges might just be more AI, purpose-built and narrow in scope. Also, Greg sits down with Chris Townsend, Elastic’s Global VP of Public Sector, at the Elastic Public Sector Summit to unpack how agencies can operationalize data amid rising cyber threats. Townsend explains why open standards and cross-agency data sharing matter—and how agentic AI can help modernize SOC operations by prioritizing alerts and speeding response times. In our reporter chat, Greg Otto and Derek Johnson break down the surge of AI-in-cybersecurity developments—from Anthropic’s Project Glasswing and the “too dangerous to release” Mythos model to OpenAI’s trusted-access approach—focusing on what these tools could mean for vulnerability discovery and the balance between real risk and hype.
Apr 16, 2026 · via cyberscoop.com
U.S. cyber insurers in 2025 reversed a couple of years of decline in direct written premiums to post growth of 11% but, according to Fitch Ratings, there are some underwriting concerns brought on by developments with artificial intelligence. Fitch said Anthropic’s Mythos model has raised eyebrows in the financial and cybersecurity worlds. In the short to medium term, vulnerabilities will probably outnumber patches as the artificial intelligence tool works on cyber threat intelligence and incident response. Related: Anthropic Touts AI Cybersecurity Project With Big Tech Partners “AI is particularly disruptive to cyber risk because traditional vulnerability analysis was labor-intensive and offered limited financial upside for researchers, a gap AI now fills at scale and speed,” said Fitch in its brief on the cyber marketplace on Feb. 15. “This lowers barriers for attackers, expands third-party risks, and could materially increase attack volume.” Growth in the cyber market was mostly driven by volume, with policies-in-force up 35% to offset soft aggregate pricing. This, said Fitch, indicates a great awareness among buyers of cyber exposures, as well as a competitive underwriting environment. Larger companies are still more likely to have cyber insurance protection while smaller companies lag behind. Yet, Fitch said, demand overall has “strengthened as boards and management teams recognize that cyber events can disrupt operations, trigger legal liabilities, and impair revenue even when direct financial losses are limited.” Meanwhile, insurers have and will continue to assess and adjust contract language while integrating cybersecurity assessments into underwriting. Policy wordings related to war exclusions, silent cyber, business interruption, and contingent losses “will be critical,” added Fitch. A more detailed look at the cyber market is expected this summer, said the credit-rating agency. Was this article valuable? Here are more articles you may enjoy.
Apr 16, 2026 · via insurancejournal.com
On April 7, AI firm Anthropic said its new model, Mythos, is so powerful at finding cybersecurity vulnerabilities that it will not be released publicly. Instead, the company said it will be shared with firms that build critical software used across the economy. The initiative, known as Project Glasswing, has raised cybersecurity concerns among most firms, which must now contend with AI-enabled attackers using so-called “zero-day” exploits, which are unknown even to a given piece of software’s developers, and therefore are not patched through software updates. The Hindu reported last week that the Union government and the Indian IT sector’s main cybersecurity body are both studying the implications of Mythos. Should the Mythos AI model raise cybersecurity alarms? Aseem Jakhar and Sharda Tickoo discuss this in a conversation moderated by Aroon Deep.
Aseem Jakhar is the founder of Payatu and co-founder of the Nullcon cybersecurity conference; Sharda Tickoo is the country manager, India at Trend AI, formerly Trend Micro
Published - April 17, 2026 01:49 am IST
Apr 16, 2026 · via thehindu.com
Software stocks are drawing renewed attention as AI adoption reshapes enterprise technology and heightens cybersecurity risks across industries. BNN Bloomberg spoke with Fatima Boolani, managing director and co-head of software equity research at Citi, about how platform scale, data protection and AI infrastructure are driving long-term opportunities in the sector. Key Takeaways - AI advancements are increasing both the scale and sophistication of cyber threats, reinforcing demand for cybersecurity solutions. - Large, integrated platforms are becoming critical partners as enterprises deploy AI across core operations. - Data growth and sprawl are raising the importance of backup, recovery and resilience capabilities. - Observability and system monitoring are essential as AI infrastructure becomes more complex and mission-critical. - Market weakness in software has created potential opportunities in high-quality cybersecurity names. Read the full transcript below: ANDREW: On Hot Picks today, we are focusing on software. Our guest has Palo Alto, the giant cybersecurity provider, as a top selection. We’re joined by Fatima Boolani, managing director and co-head of software equity research at Citi. Thanks very much indeed for joining us. FATIMA: Thanks for having me. ANDREW: Palo Alto, in some ways, it’s the IBM of cybersecurity. People don’t get fired for hiring them. Why? Where do you — I mean, we know cybersecurity is a growth industry. What, in particular, about Palo Alto do you think investors should focus on? FATIMA: There are two very important reasons why we are very decidedly advocating for investors to build bigger core positions in their portfolios with respect to cybersecurity and increase their cybersecurity exposure. The first one is the last two weeks, and more particularly the last week. We’ve seen some very important, consequential, almost tectonic plate-shifting news out of the frontier labs of the Anthropics and the OpenAIs of the world in terms
Apr 16, 2026 · via bnnbloomberg.ca
Following a newly issued cybersecurity warning from the Federal Railroad Administration (FRA), SMART-TD is alerting all members across both freight and passenger rail operations of what they need to know. The alert highlights a credible threat from Iranian state-affiliated cyber actors targeting railroad systems by attempting to access internet-connected industrial control devices used throughout rail operations. What Risk Does Iran Pose to the U.S. Rail System? According to the FRA, these foreign actors are specifically targeting programmable logic controllers (PLCs). These are the behind-the-scenes computer systems that help control critical railroad infrastructure. If compromised, these systems could be manipulated or disabled, potentially causing service disruptions, or in the worst case, interfering with the safe movement of our trains. Federal officials also warn that attackers are scanning for exposed systems across the internet, looking for any vulnerabilities they can exploit. This means they are not just targeting one railroad or one type of equipment. This table, provided by the FRA, lays out some of their largest concerns. Why This Matters to Railroaders While much of this technology operates in the background, the impact of a cyber incident would be felt directly by the operating crews. Railroaders are the last line of defense when something doesn’t look, feel, or operate the way it should out there. Keeping that in mind, we encourage you to read over the table of potential issues the FRA released today. Please include discussions of what this warning means on your territory as part of your crew’s job briefings. The idea that our signals, crossing gates, drawbridges, ventilation in tunnels, and even our braking systems have been flagged as targets of cybercriminals is not something any of us can afford to blow off. History has taught us that critical infrastructure like railroads often becomes a high-priority target during
Apr 16, 2026 · via smart-union.org
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 16, 2026 · via youtube.com