Weâre sorry, this site is currently experiencing technical difficulties.
Please try again in a few moments.
Exception: forbidden
Weâre sorry, this site is currently experiencing technical difficulties.
Please try again in a few moments.
Exception: forbidden
Apr 16, 2026 · via ar.usembassy.gov
ATDT, Microsoft Team Up to Boost Mexico Cybersecurity The ATDT and Microsoft signed a memorandum to advance along with Mexico’s National Cybersecurity Plan 2025–2030, addressing rising ransomware and identity-based threats. The initiative targets public sector resilience, impacting government entities, cloud providers, and cybersecurity firms. Mexico’s Digital Transformation and Telecommunications Agency (ATDT) and Microsoft signed a memorandum of understanding to strengthen national cybersecurity infrastructure. This agreement integrates into the National Cybersecurity Plan 2025–2030 to mitigate digital risks and elevate protection standards within the public sector. "The digital transformation of the state requires solid foundations of security,” says Heidy Rocha, Director General of Cybersecurity, ATDT. The implementation of this agreement addresses critical operational safeguards in government digital services, considering the interdependency between state functionality and information security, she adds. The memorandum of understanding focuses on supporting institutional capacities, promoting continuous training, and fostering a cybersecurity culture across agencies, decentralized bodies, and public entities to protect digital services and citizen information. Mexico is a Frequent Victim The significance of this alliance is framed by a rising threat landscape affecting the digital infrastructure of Mexico. According to data from IQSEC, Mexico moved from 16th place in 2024 to 11th place globally in ransomware attack attempts during 2025. This progression establishes the nation as the second most targeted market in Latin America, following Brazil. The rise of Mexico in global threat rankings is linked to structural deficiencies in identity management and multi-cloud security. Research conducted by Permiso Security indicates that 76% of cybersecurity professionals report that more than 54% of security incidents in previous months involved issues relating to identity management, establishing the compromise of human and non-human identities as the primary entry vector. The global cybersecurity environment revealed a high concentration of incidents in North America in 2025. The United States alone accounted for
Apr 16, 2026 · via mexicobusiness.news
Zscaler Blog Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang Zscaler and OpenAI Join Forces to Advance the Next Era of Cybersecurity Zscaler is proud to partner with OpenAI as part of their Trusted Access for Cyber (TAC) program, which expands trusted, verified access to advanced AI capabilities for defenders. As part of this program, we plan to use GPT 5.4-Cyber, a TAC-enabled variant of GPT‑5.4, to further improve cybersecurity for our Zero Trust Exchange platform and for our customers. GPT 5.4-Cyber will be integrated into our secure Software Development Lifecycle (SDLC) workflows, empowering our teams to instantly detect, triage, and mitigate vulnerabilities earlier and patch security vulnerabilities faster. In addition to safeguarding software, Zscaler has a long history of harnessing OpenAI technology to fight AI-based attacks, including within our AI Red Teaming and Agentic SecOps solutions. Safeguarding the Zscaler Platform Secure software development is a business imperative at Zscaler. Participating in Open AI’s TAC program enables us to integrate GPT 5.4-Cyber and Codex Security into Zscaler’s internal multi‑agent security architecture for cyber defenses and product hardening. GPT 5.4-Cyber is a key enabler to offer Security-as-a-Service to our developers throughout the SDLC process, from validating threat models in designs, to assisting with secure code reviews, finding vulnerabilities, and executing black-box testing on built artifacts. We are approaching TAC with both a defensive and offensive mindset. In addition to improving security through the SDLC, we are leveraging the model to improve cyber readiness by turning large volumes of security signals into actionable intelligence, prioritizing true risk, and accelerating remediations. Moreover, we are relying on the model for offensive-informed posture hardening by modeling adversarial attack paths and highlighting weak controls, which enables us to neutralize exposures at unprecedented speeds. Combining the frontier OpenAI models with Zscaler’s industry‑leading Zero Trust architecture leads
Apr 16, 2026 · via zscaler.com
Earlier this month, Anthropic dropped its most advanced artificial intelligence (AI) model, Claude Mythos. However, because the company said it can easily identify and exploit software vulnerabilities, Anthropic said it will not release it to the public. Instead, it will give access to the large language model (LLM) to a select group of about 50 leading tech companies. Called Project Glasswing, the goal is for these companies to improve their cybersecurity defenses. Anthropic said Mythos has already found thousands of vulnerabilities across every major web browser and operating system. It noted it won't be long before bad actors look to use AI to exploit these vulnerabilities. Anthropic will provide participants with a total of $100 million in usage credits. Afterwards, the Claude Mythos will be available at a cost of $25 per million input tokens and $125 per million output tokens. Widening CrowdStrike and Palo Alto's lead Two of the 12 leading members of the project will be cybersecurity companies CrowdStrike (CRWD +3.18%) and Palo Alto Networks (PANW +1.56%). This is important, because it shows that Anthropic is looking to cybersecurity providers to play a big role in AI protection going forward and is not developing its own solution. Wedbush analysts called the announcement big for CrowdStrike and Palo Alto, noting this will help them become an AI enforcement layer, not an AI casualty. NASDAQ: CRWD Key Data Points The capabilities of Claude Mythos, meanwhile, suggest cybersecurity will become all the more important in the age of AI. AI cyber solutions will be needed to fight against AI cybersecurity attacks, which is why CrowdStrike and Palo Alto becoming two of the leading members of Project Glasswing is so important. Gaining access to Claude Mythos will help give them an edge moving forward, allowing them to remain at the forefront of
Apr 16, 2026 · via fool.com
Financial and monetary authorities in the US and other major economies are increasingly focused on Anthropic PBC's new artificial intelligence model, Mythos, amid concerns that its advanced cybersecurity capabilities could reshape both offensive and...
The article requires paid subscription. Subscribe Now
Apr 16, 2026 · via digitimes.com
Is Anthropic's Claude Mythos a big stunt, or a real security threat? What the experts say. Anthropic put the entire tech world on notice last week with an unprecedented announcement: it made an AI model so advanced that it was too dangerous to release to the public. Anthropic said the new frontier language model, Claude Mythos Preview, would "reshape cybersecurity." Anthropic also announced the formation of Project Glasswing, an invite-only group of organizations — including some of Anthropic's biggest competitors — to test Claude Mythos Preview and secure their infrastructure. Anthropic said that Claude Mythos Preview "found thousands of high-severity vulnerabilities, including some in every major operating system and web browser." (Emphasis in original.) The company said Project Glasswing was necessary "to help secure the world’s most critical software." You May Also Like By Friday, CNBC reported that Federal Reserve Chairman Jerome Powell and Treasury Secretary Scott Bessent had summoned the high priests of finance (aka banking CEOs) for an emergency meeting about the new model. New York Times writer Thomas Friedman fretted over a "terrifying" future in which any teenager armed with Claude could hack the local power grid. The reaction to Claude Mythos Preview quickly split along predictable lines. AI boosters hailed the new model as proof that artificial general intelligence (AGI) was nigh, praising Anthropic for rolling it out so responsibly. Critics and AI skeptics called Project Glasswing a big publicity stunt. So, which is it? To find out, Mashable has been reviewing Anthropic's claims and talking to AI and cybersecurity experts. What is Claude Mythos Preview? Claude Mythos is a new large-language model that Anthropic says performs significantly better than Claude Opus 4.6 — widely considered one of the best AI models in the world — especially in cybersecurity. "In our testing, Claude Mythos Preview demonstrated
Apr 16, 2026 · via mashable.com
Secure by Design is a software development philosophy that treats security as a foundational requirement rather than an afterthought. Instead of building a product first and bolting on security fixes later, Secure by Design demands that security considerations are embedded into every stage of the development lifecycle — from architecture and design through coding, testing, deployment, and maintenance. The core idea is straightforward: If you build something securely from the ground up, your users are protected by default rather than only when they know how to flip the right settings or when security gaps are fixed after the fact. In practical terms, this means adopting several core security principles: - Least privilege ensures that processes, agents — AI or otherwise — containers, and system services receive only the minimum access they need. - Secure defaults make sure products ship with the safest configuration enabled out of the box. - Defense in depth layers multiple security controls so no single failure becomes catastrophic. And organizations can further strengthen resilience by eliminating entire classes of vulnerabilities through safer languages, frameworks, and design patterns. Why was the Secure by Design approach introduced? For decades, many players in the technology industry operated under a “ship fast, patch later” model. One consequence of that legacy is that cybersecurity can be seen as just a cost center — something that slows releases and frustrates developers. The impacts are playing out in real time: constant vulnerability disclosures, rushed emergency patches, and breaches that drain billions from organizations while exposing the personal data of hundreds of millions of people. The Ivanti Connect Secure vulnerabilities, the Log4Shell exploit in a ubiquitous open-source library, and the MOVEit Transfer vulnerabilities all demonstrated that reactive security simply cannot keep pace with determined adversaries. Recognizing this imbalance, the U.S. Cybersecurity and Infrastructure Security
Apr 16, 2026 · via sophos.com
New risk-based model will allow NIST to manage current CVE volume while modernizing the NVD for long-term sustainability. NIST is changing the way it handles cybersecurity vulnerabilities and exposures, or CVEs, listed in its National Vulnerability Database (NVD). In the past, NIST’s NVD program aimed to analyze all CVEs to add details — such as severity scores and product lists — that help cybersecurity professionals prioritize and mitigate vulnerabilities. Going forward, NIST will add details, or “enrich,” those CVEs that meet certain criteria, which are explained below. CVEs that do not meet those criteria will still be listed in the NVD but will not automatically be enriched by NIST. This change is driven by a surge in CVE submissions, which increased 263% between 2020 and 2025. We don’t expect this trend to let up anytime soon. Submissions during the first three months of 2026 are nearly one-third higher than the same period last year. We are working faster than ever. We enriched nearly 42,000 CVEs in 2025 — 45% more than any prior year. But this increased productivity is not enough to keep up with growing submissions. Therefore, we are instituting a new approach. The changes described below will allow us to focus on the most critical CVEs while being transparent about how we are managing our current workload. They will also allow us to stabilize the program while we develop the automated systems and workflow enhancements required for long-term sustainability. New Prioritization Criteria Starting on April 15, 2026, we will prioritize the following CVEs for enrichment: All submitted CVEs will still be added to the NVD. However, those that do not meet the criteria above will be categorized as “Not Scheduled.” This will allow us to focus on CVEs with the greatest potential for widespread impact. While CVEs that
Apr 16, 2026 · via nist.gov
Cyber startup Artemis raises $70 million just six months after launch The Israeli-founded company targets AI-driven attacks with new defense platform. U.S.-based cybersecurity startup Artemis, founded by Israeli entrepreneurs, has raised $70 million in Seed and Series A funding just six months after its launch. Of that total, $15 million was raised in the Seed round. The Series A was led by Felicis with First Round Capital and Brightmind returning to increase their stakes. The round was also joined by Theory VC, Two Sigma, Lockstep and prominent cybersecurity industry leaders, including the founders of Demisto and Abnormal AI, the former CEO and CTO of Splunk, and senior executives from CrowdStrike, Palo Alto Networks, Microsoft, and Okta. Artemis was founded roughly six months ago by Shachar Hirshberg and Dan Shiebler. Hirshberg previously served in the Intelligence Corps and later worked as a development manager at Demisto, which was acquired by Palo Alto Networks for approximately $600 million. He subsequently joined Amazon Web Services, where he led GuardDuty, a cloud threat detection product. Shiebler most recently led the AI and machine learning team at Abnormal AI and holds a PhD in machine learning from University of Oxford. Artemis is positioning itself as part of a new generation of tools designed for what it describes as an “AI versus AI” security landscape. Its platform builds a dynamic data model based on each customer’s internal activity, combining behavioral logs across users, machines, cloud workloads, and applications with business context. The goal is to determine not just whether an action is anomalous, but whether it makes sense within a specific organization. From that foundation, the system generates tailored detections, investigates signals autonomously, and presents what the company describes as coherent “attack stories” rather than isolated alerts. In practice, that means correlating seemingly unrelated events, such
Apr 16, 2026 · via calcalistech.com
The Federal Communications Commission on Tuesday said U.S. businesses and consumers could continue to buy some Netgear routers, exempting the company’s products from a new foreign router ban meant to protect national security. After the Department of Defense determined that Netgear’s Nighthawk and Orbi routers and cable modems do not “pose unacceptable risks” to national security, the FCC said it was excluding them from its March 23 ban on routers manufactured outside the U.S. Neither the FCC nor the Pentagon explained the military’s determination that Netgear products were safe enough for U.S. use. They did not respond to requests for comment about the basis for that conclusion. Netgear was the first company to win an exemption. In its initial announcement of the ban, the FCC cited an interagency group’s conclusion that foreign-made routers represent “a supply chain vulnerability that could disrupt the U.S. economy, critical infrastructure, and national defense” and pose “a severe cybersecurity risk that could be leveraged to immediately and severely disrupt U.S. critical infrastructure and directly harm U.S. persons.” Foreign-made routers have powered botnets, helped overseas hackers masquerade as legitimate U.S. network users and enabled serious cyberattacks against critical infrastructure, including the Volt, Flax and Salt Typhoon campaigns that the U.S. government has attributed to China. Netgear manufactures its routers in Taiwan, Vietnam and Indonesia. The company’s reliance on Taiwan could pose a significant supply-chain problem, because Beijing has threatened to invade the island nation and has already tried to steal intellectual property from its domestic industries. Netgear CEO Charles Prober praised the FCC’s decision in an online statement and said the company’s technology “meets rigorous standards.”
Apr 15, 2026 · via cybersecuritydive.com
Cybersecurity researchers have discovered a new campaign where a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited. These extensions are published under five distinct publisher identities – Yana Project, GameGen, SideGames, Rodeo Games, and InterAlt — according to Socket, the cybersecurity firm behind the findings. They have collectively amassed about 20,000 installs in the Chrome Web Store. “All 108 route stolen credentials, user identities, and browsing data to servers controlled by the same operator,” Security Researcher Kush Pandya said in an analysis. READ: Google parent Alphabet hits $3 trillion following DOJ win ( 54 of the add-ons steal Google account identity via OAuth2. 45 extensions contain a universal backdoor that opens arbitrary URLs as soon as the browser is started, and the remaining ones engage in a variety of malicious behaviors. The identified extensions masquerade as Telegram sidebar clients, slot machine and Keno games, YouTube and TikTok enhancers, text translation tools, and page utilities, in order to appear legitimate. While they seem to showcase diverse functionality, malicious code runs in the background capturing session information, injecting arbitrary scripts, and opening URLs chosen by the attacker. “Five extensions use Chrome’s declarativeNetRequest API to strip security headers from target sites before the page loads,” Socket noted. “All 108 malicious extensions share the same backend, hosted at 144.126.135[.]238.” It is not known who is responsible for these malicious extensions. An analysis of the source code has reportedly uncovered Russian language comments across several add-ons. READ: Google Gemini’s ‘Nano-Banana’ trend surpasses OpenAI; tops Apple App Store ( It has been recommended that Chrome users should check whether they have extensions running in
Apr 15, 2026 · via americanbazaaronline.com
CU In Class | Intro to Adversarial Thinking for Cybersecurity Adversarial thinking is central to cybersecurity, and this lecture explains why it matters. 🔗 Learn more about Cedarville Cybersecurity: https://www.cedarville.edu/academics/centers/center-for-the-advancement-of-cybersecurity/cyber-at-cedarville In this lecture, Dr. Seth Hamman introduces a homemade module on adversarial thinking that was developed with support from an NSA grant and shared publicly for cybersecurity educators. Using the familiar framework of computers and bad guys, the lecture shows why cybersecurity is distinct from other fields and why it requires more than technical best practices alone. Students are challenged to think beyond barriers like passwords, firewalls, and multi-factor authentication and consider the mindset, capabilities, and strategies of attackers. The lecture also explores how cyberspace differs from physical space through the ideas of distance-less, digital, and dynamic environments, and how those realities shape threats to confidentiality, integrity, and availability. From there, the lecture defines adversarial thinking as the ability to embody the technological capabilities, unconventional perspectives, and strategic reasoning of hackers. Through examples like the CIA triad, the Cuckoo’s Egg, cross-site scripting, malware, rootkits, social engineering, and game theory, the lecture builds a practical framework for anticipating attacks and strengthening cybersecurity education. Timestamps: 0:00 Introduction to the adversarial thinking module 2:04 What cybersecurity really means 4:00 The three B’s: bad guys, barriers, and bounties 11:22 Why cyberspace is harder to secure 14:02 CIA triad and hacker goals 20:19 Why cyber adversaries define the discipline 23:42 What does it mean to think? 24:37 Sternberg’s triarchic theory of intelligence 31:17 Applying the theory to hackers 37:19 Definition of adversarial thinking 39:15 The Cuckoo’s Egg and real-world hacking 45:05 The Princess Bride analogy 48:15 Strategic reasoning and game theory 51:02 Final takeaways 🎓 Admissions: https://cedar.to/Admissions 💰 Financial Aid: https://cedar.to/FinAid 🏫 Visit Campus: https://cedar.to/Visit 📚 Academic Programs: https://cedar.to/Programs #Cybersecurity #AdversarialThinking #GameTheory #InformationSecurity #Cedarville #HigherEducation
Apr 15, 2026 · via cedarville.edu
Tri‑National Online Exchange: A Cyber Security Research Experience Across the Americas When many people hear the phrase global learning, they imagine passports, flights, and study‑abroad travel. At St. John’s University, however, global learning can also take place through sustained digital collaboration—connecting students across borders, languages, and institutions without leaving campus. Through a tri‑national Global Online Learning Exchange – Research Experience (GOLE‑RE), graduate students in the M.S. in Cyber and Information Security program. The M.S. graduate cohort was led by Dr. Schmeelk, a Fulbright Cyber Security Specialist, who partnered with peers and faculty from Pontifícia Universidade Católica de Campinas (PUC‑Campinas), São Paulo, Brazil (South America), led by Dr. Carlos Moreira, Guilherme Oliveira, and PUC Cybersecurity Faculty) and Universidad Nacional Autónoma de Honduras (Tegucigalpa, Honduras, Central America), led by Dr. Elías Leonardo García Urquía and UNAH Engineering Faculty. Together, they engaged in applied cybersecurity research addressing real‑world challenges affecting financial systems and critical infrastructure across the Americas. This blog highlights how the tri‑national exchange model brings global learning to life by combining virtual collaboration, research, and workforce‑aligned cybersecurity education. What is GOLE-RE? The Global Online Learning Exchange – Research Experience (GOLE‑RE) connects St. John’s students with international partner universities to engage in collaborative, research‑focused coursework. In this tri‑national exchange, students worked in multinational teams to analyze applied cybersecurity case studies, share regional perspectives, and produce collective research deliverables—mirroring how global cyber teams operate in professional environments. This initiative builds on Dr. Schmeelk Fulbright‑supported international collaboration and St. John’s long‑standing commitment to global online learning, strengthening cybersecurity research capacity across North, Central, and South America. Learn more What Cyber and Information Security Graduate Students Gain Over the course of several weeks, graduate students in the St. John’s University M.S. in Cyber and Information Security dual modality graduate program—accredited/validated by Middle States, ABET (graduate
Apr 15, 2026 · via stjohns.edu
An official website of the United States government
Here’s how you know
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
Apr 15, 2026 · via nist.gov
Sponsored by the University of Idaho The University of Idaho continues to lead the way in cybersecurity education, building on more than 30 years of experience preparing students to address evolving digital threats. As cybersecurity becomes increasingly critical, from protecting personal data to securing national infrastructure, the university has expanded its programs to meet growing workforce demands. Designated as a National Center of Academic Excellence in Cyber Defense Education since 1999, U of I has also participated in the federal Scholarship for Service program, providing more than $20 million in student support. The university now offers a full pipeline of cybersecurity education, including a rapidly growing bachelor’s program launched in 2020, as well as master’s and doctoral degrees, making it home to Idaho’s only Ph.D. in cybersecurity. As the field continues to evolve alongside advancements in artificial intelligence and robotics, U of I is focused on preparing students to meet emerging challenges. The program emphasizes hands-on learning, research, and collaboration with industry and government partners to address real-world cybersecurity threats. From protecting connected systems like manufacturing robots and power grid infrastructure to strengthening awareness across industries and communities, graduates are equipped to make an impact across Idaho and beyond. To learn more about available programs, research opportunities, or how to apply, visit the University of Idaho’s Department of Computer Science online.
Apr 15, 2026 · via ktvb.com
BSides South Jersey, a community driven cybersecurity conference hosted by Women in Cybersecurity Chapter (WiCyS) and Cybersecurity Club students, with support from Rowan alumni and the Rowan Computer Science Department. The free, one day event will run from 9:00 AM to 5:00 PM, with doors opening at 8:15 AM, and will be held in the Eynon Ballroom on the third floor of the Chamberlin Student Center. Stream Philadelphia News for free, 24/7, wherever you are with NBC10. Organizers expect 350 to 450 attendees from across South Jersey and the greater Philadelphia region, including students, professionals, and members of the technology community. BSides South Jersey is part of a global series of grassroots cybersecurity conferences designed to make education and knowledge sharing more accessible. The event brings together hackers, security professionals, students, and curious minds to explore real world cybersecurity challenges and emerging threats. Attendees will have access to expert led talks, panel discussions, and a live Capture the Flag (CTF) competition, covering areas such as web security, forensics, cryptography, and networking. Beverages and light food will be provided for attendees throughout the day. NBC10 Weekend Morning Anchor Brenna Weick is confirmed to moderate the BSides South Jersey panel on Saturday, April 18th. Organizers say the goal is to bridge the gap between academic learning and real world application while building a stronger cybersecurity community in South Jersey. Community The event is open to the public, though space is limited. Attendees are encouraged to register in advance and bring their Eventbrite barcode for check in. For more information or to register: https://bsidessouthjersey.org
Apr 15, 2026 · via nbcphiladelphia.com
The IAPP writes: Last year, the California Privacy Protection Agency adopted a major new rule requiring certain businesses to conduct an annual cybersecurity audit. The rule went into effect 1 Jan. 2026. This pioneering requirement, the first of its kind among state data privacy laws of general applicability, may entail substantial compliance efforts for affected companies to identify and correct cybersecurity shortcomings. While compliance concerns may generate new anxiety, the audit requirement’s impact on data breach litigation could have equally significant long-term implications for businesses operating in California. The compliance requirements are considerable and complex, covering eighteen different technical and organizational components of an entity’s cybersecurity practice. Under the rule, covered entities are required to submit to the agency, each calendar year, a written certification that the business has completed a cybersecurity audit report that meets the rule’s standards. Although the report itself does not need to be filed, the need to create and certify one highlights an item of high interest to a plaintiff’s counsel. As a result, the audit will likely become a focal point of plaintiffs’ discovery requests in data breach class actions as they seek to prove negligence or violations of state data privacy laws. Read more at IAPP.
Apr 15, 2026 · via databreaches.net
On most days, Christian Ruff can be found in a chemistry lab, assembling molecules into structures designed to move energy more efficiently or teaching lab skills to other students. Soon, his workspace will look very different. Instead of a lab bench, Ruff will head to New York City as a product manager on Mastercard’s cybersecurity team, helping develop technologies that detect fraud and secure digital transactions. At first glance, the shift from chemistry to cybersecurity seems curious. But for Ruff, a senior in the McCausland College of Arts and Sciences, it goes to show that your major doesn’t define your future. Ruff, who grew up in Columbia, didn’t always see himself in science. “I was scared of science in high school,” he said. “It felt really complex, almost mystical, and you can feel excluded from those spaces.” At USC, he leaned into that challenge. A Chemistry 111 course sparked his interest and reshaped how he approached learning. “I just wanted to learn and grow,” Ruff said. “If you only focus on the outcome, you miss the fun of actually thinking, of getting stuck on a problem and puzzling it out.” That mindset carried into his research, where he spent three years studying battery materials. He also conducted full-time research through a competitive REU program at University of California San Diego, where he worked on metal-organic frameworks and co-authored a published paper. “People may think chemistry is just right or wrong answers,” he said. “But it’s actually really creative. You’re building something completely new.” Outside the lab, Ruff explored widely, taking courses in philosophy, media arts and vocal performance. Those experiences, he said, sharpened his ability to think critically and communicate complex ideas clearly. Over time, his interests expanded. After adding a second major in computer science, he discovered product management,
Apr 15, 2026 · via sc.edu
Anthropic Launches Glasswing to Boost Global Cybersecurity Anthropic launched Project Glasswing, an AI-driven cybersecurity initiative using advanced models to detect critical software vulnerabilities at scale. The program impacts technology, finance, and infrastructure sectors, raising urgency for AI governance. Anthropic launched Project Glasswing, a defensive cybersecurity initiative that integrates major technology and financial organizations to protect global software infrastructure. The program utilizes Claude Mythos Preview, an AI model capable of identifying and mitigating complex vulnerabilities that frequently bypass human detection. "AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back,” says Anthony Grieco, Senior Vice President and Chief Security and Trust Officer, Cisco. “Our foundational work with these models has shown we can identify and fix security vulnerabilities across hardware and software at a pace and scale previously impossible. That is a profound shift, and a clear signal that the old ways of hardening systems are no longer sufficient." Modern global infrastructure — including banking systems, medical records, logistics networks, and power grids — relies on software that contains inherent flaws. While many bugs are minor, high-severity vulnerabilities allow adversaries to disrupt operations, hijack sensitive systems, or extract proprietary data. Reports show that the global financial impact of cybercrime can reach about US$500 billion annually. Threat actors, including state-sponsored groups, have historically targeted critical civilian and military infrastructure. Previously, identifying these flaws required specialized expertise held by a small number of researchers. However, frontier AI models have dramatically reduced the cost and effort required to locate and exploit these vulnerabilities. Claude Mythos Preview, an unreleased frontier model developed by Anthropic, demonstrates a significant advancement in autonomous coding and reasoning. This model has identified thousands of high-severity vulnerabilities, including those that have survived decades of human review
Apr 14, 2026 · via mexicobusiness.news
Veteran-founded firm brings 60+ years of combined security leadership to a platform that eliminates the conflict of interest at the heart of the cybersecurity industry, the partner ecosystem. SCOTTSDALE, Ariz., April 14, 2026 /PRNewswire/ -- Crush Security Group today announced its official launch as a cybersecurity intelligence platform built specifically for CISOs, Risk, and Procurement teams who are tired of getting little tangible value from their current partners and resellers. Crush Security enters the market with a platform model that separates advisory from commission to bring back the trust in trusted advisors. The Problem Crush Solves Security leaders managing $100k–$300M security budgets are routinely steered toward tools and strategies that serve their vendors — not their programs. Value-added resellers earn margin on what they sell. Advisory firms grow through recurring retainers. Independent assessors lack the platform data to make cross-client recommendations. The result: fragmented tool stacks, duplicated spend, and compliance programs built on assumptions rather than evidence. Crush Security was built to close that gap. The Platform Crush Security operates across five interconnected ecosystems: - Readiness & Assessments — Independent gap analysis and compliance readiness using your data with no vendor affiliation. - Auditing Body — Third-party audit capabilities that validate posture without selling the fix. - Unbiased Software Resell — Technology procurement guided by program fit, not margin targets, and the ability for CISOs to use the platform regardless of whether they purchase from Crush Security. - AI Threat Intelligence — Continuous threat intel with automated framework mapping across NIST, PCI, SOC 2, HITRUST, UCF, ISO 27001, CMMC, pand dozens more constantly coming out. - Adaptive Security Intelligence — Every customer's environment is unique. The platform learns from each program — adapting recommendations to the customer's industry, regulatory requirements, and risk profile while benchmarking anonymously against peer organizations to
Apr 14, 2026 · via prnewswire.com