OPM seeks cybersecurity talent to join Tech Force "Through Tech Force, we’re recruiting highly skilled cybersecurity professionals to take on real challenges and strengthen the government’s defenses where it matters most,” OPM director Scott Kupor said in a statement. The Office of Personnel Management is now expressly recruiting cybersecurity employees through the U.S. Tech Force, which the Trump administration launched last year after pushing out over 19,500 tech, data and cyber government workers from across various agencies. Recruits will work across the federal government for two-year terms. OPM set an initial goal of hiring a 1,000-person cohort when it began the program last winter. Many agencies participating in Tech Force are currently in the final stages of hiring, according to an OPM spokesperson, who said that cyber hires will also be part of the initial cohort. The government has long struggled to recruit and retain the cyber talent it needs to protect critical systems, although that workforce hasn’t been spared from cuts under the Trump administration’s aggressive downsizing. The government is looking to hire software engineers, data scientists and product managers to join the Tech Force in addition to cybersecurity talent. Last month, OPM also launched a dedicated NASA Force within the larger program to place fellows at the space agency. Twenty-plus private companies are collaborating with the administration on the program by providing training and mentorship opportunities. Those companies will also nominate their own employees to do government stints as managers for the Tech Force, a setup that’s raised a host of ethics and conflict of interest concerns, as these managers will remain employed by and on leave from their private sector companies while working for the government. Scott Kupor, the head of OPM, has emphasized the importance of making it easier for professionals to move in and out
Apr 13, 2026 · via nextgov.com
Getty Images/Khanchit Khirisutchalual DHS fosters intentional approach to AI for cybersecurity Artificial Intelligence Read more
Getty Images/design master Yeske helped change what complying with zero trust means Ask the CIO Read more
Apr 13, 2026 · via federalnewsnetwork.com
Palm Beach State College secures $1 million for AI, cybersecurity training center Palm Beach State College has received more than $1 million in federal funding to launch a new artificial intelligence and cybersecurity training center at its Lake Worth campus. The center aims to prepare students for the workforce with a hands-on approach in an industry experiencing a surge in demand. In Florida, PBSC reports entry-level cybersecurity and AI-related roles typically offer starting salaries ranging from approximately $60,000 to $100,000. Your neighborhood: Local coverage from WPBF 25 News Currently, 300 students are enrolled in PBSC's AI and cybersecurity programs, reflecting growing demand among the student body, according to school officials. The center will feature labs specializing in AI for IT security and data privacy, helping students learn to combat rising security threats targeting community organizations. It will also be the first cyber range in Palm Beach County, aiding in training for surrounding municipalities. "They provide us a lot of tools and resources to learn cybersecurity, but there is a gap between cybersecurity and AI, and I feel like the center is going to help fill that gap for us," a Palm Beach State student said. U.S. Rep. Lois Frankel, who helped secure the funding for the program, said it will benefit not only students but also the surrounding community. "Here's the thing: AI and cybersecurity are no longer optional," Frankel said. "It's going to help our local community by growing the talent we need right here in Palm Beach County." Graduates of the program are prepared for a wide range of entry-level to mid-level positions within the AI and cybersecurity industry. Get the latest news updates with the WPBF 25 News app. You can download it here. The school is still determining the exact location for the center on campus.
Apr 13, 2026 · via wpbf.com
When it comes to understanding how artificial intelligence (AI) is changing cybersecurity, those discussions tend to focus on the technical skills that cybersecurity professionals have or must acquire to compete. In today’s job market, professionals with proven AI skills are increasingly sought after as enterprises look to better utilize these platforms. As AI interest grows, however, there is also a significant need for cybersecurity professionals and others to help address knowledge gaps when it comes to a wide range of security-related issues beyond the technical aspects. These include governance, risk assessment, data protection, data privacy, government compliance and regulatory issues. This is where the field of governance, risk and compliance – GRC for short – is having its moment. A term coined in 2002, this field encompasses traditional IT and cybersecurity teams as well as other parts of the organization, from legal to finance to HR to the executive boardroom. One definition of GRC is an organization-wide strategy to “manage governance and risks while maintaining compliance with industry and government regulations,” according to IBM. By creating this type of framework – one that encompasses various parts of an enterprise – an organization is then able to establish policies and procedures that address risk. One reason GRC is gaining more attention now is that the growing use of AI is creating fresh risk concerns for organizations, from how internal data is used with these virtual chatbots and platforms to the responsibility of managing large language models. These challenges require enterprise-wide rules and procedures to ensure security. “First, AI itself now requires governance. Organizations must develop policies around model risk, data handling, prompt injection, bias, explainability and regulatory compliance. AI introduces new oversight obligations at both the technical and board level,” said Shane Barney, CISO at Keeper Security. “Second, regulatory expansion tied
Apr 13, 2026 · via dice.com
Asteria Joins “CAMS,” the Cybersecurity Research Consortium at MIT Sloan School of Management Participating in an International Consortium to Strengthen Cybersecurity in the AI Era Press Release April 13, 2026 Asteria Corporation Tokyo – April 13, 2026 – Asteria Corporation (Headquarters: Shibuya-ku, Tokyo; President and CEO: Yoichiro Hirano; Securities Code: 3853; hereinafter “Asteria”) announces that it has joined Cybersecurity at MIT Sloan (hereinafter “CAMS”), a cybersecurity research consortium based at the Massachusetts Institute of Technology (MIT) Sloan School of Management. Cybersecurity: From a “Technical Issue” to a “Management Issue” Driven by digital transformation (DX), data integration between enterprises is accelerating, and environments where diverse devices and control systems—including IoT—connect to networks are expanding. Under these circumstances, security measures that look beyond individual companies to encompass the entire supply chain are now required both domestically and internationally. As a result, cybersecurity is no longer merely an IT implementation task; it is positioned as a critical issue directly linked to corporate governance and management decisions. CAMS is an international research consortium based at MIT Sloan that views cybersecurity precisely as a management issue. Achieving Global Standards in Cyber Governance As a pioneer in data integration with over 10,000 corporate adoptions, Asteria continues to push boundaries in emerging fields such as AI, robotics, and stablecoins. By joining CAMS, Asteria will support research that could inform its executive-level cyber governance and management structure to meet rigorous global standards. CAMS unites leading global enterprises and institutions across diverse sectors—including IT, finance, manufacturing, and public infrastructure—creating a powerful hub for cross-industry knowledge exchange. The consortium focuses on key strategic themes, including: - Cyber Risk and Resilience - Corporate Governance - Artificial Intelligence (AI) and Cybersecurity - Cybersecurity Ecosystems - Security in IoT and Industrial Control Systems Through this membership, Asteria will leverage international best practices to
Apr 13, 2026 · via en.asteria.com
Anthropic, the company behind Claude, has released Claude Mythos Preview, its most capable frontier model to date, with dramatic improvements in reasoning, coding, and cybersecurity. In an unusual move, the company has chosen not to make the model generally available, instead restricting access to a consortium of technology companies through a new initiative called Project Glasswing. Claude Mythos Preview represents what Anthropic describes as a "step change" over its predecessor, Claude Opus 4.6. During internal testing, the model autonomously discovered and exploited zero-day vulnerabilities in every major operating system and web browser. The oldest it found was a now-patched 27-year-old bug in OpenBSD, a system known primarily for its security. It also found a 16-year-old vulnerability in FFmpeg's H.264 codec. Internal benchmarks showed dramatic gains. Where Opus 4.6 developed working JavaScript shell exploits only twice out of several hundred attempts on Firefox vulnerabilities, Mythos Preview succeeded 181 times. On the OSS-Fuzz corpus, it achieved full control flow hijack on ten separate, fully patched targets. Engineers at Anthropic with no formal security training asked the model to find remote code execution vulnerabilities overnight, and woke up to complete, working exploits. Rather than releasing Mythos Preview publicly, Anthropic has launched Project Glasswing. Project Glasswing brings together AWS, Apple, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, NVIDIA, and Palo Alto Networks. Anthropic is committing $100M in usage credits. These organizations will use Mythos Preview to identify and patch vulnerabilities in critical software. Commentary has been swift. On Hacker News someone raised practical concerns around the scale of problem this can uncover: …hundreds of millions of embedded devices that cannot be upgraded easily and will be running vulnerable binaries essentially forever. This was a problem before of course, but the ease of chaining vulnerabilities takes the issue to a new level. A
Apr 13, 2026 · via infoq.com
CCPA Final Regulations: A Comprehensive Guide for Business Compliance - April 13, 2026 - Effective January 1, 2026, amendments to the California Consumer Privacy Act (“CCPA”) establish unprecedented protections for consumer data.1 The reforms emphasize the CCPA’s continued focus on mitigating risks to consumers’ personal information, creating heightened expectations proper protections to be implemented. Understanding these regulatory updates and their business implications is essential for effective compliance. This is the first in a series of articles that will examine key provisions of the CCPA Final Regulations and provide actionable guidance for organizations navigating these requirements. New Obligations The CCPA Final Regulations strengthen privacy protection and data security across several critical dimensions. Beyond refining existing transparency requirements, the regulations introduce substantial new obligations in three primary areas: - Cybersecurity Audits – Mandatory independent assessments to verify security measures and compliance. - Risk Assessments – Systematic evaluation of risks inherent in data processing activities. - Automated Decision-Making Technology (“ADMT”) – Governance requirements for businesses that use ADMT to make significant decisions regarding consumers. Failure to comply can result in significant enforcement actions, including administrative fines, monetary damages per consumer per incident, and civil penalties.2 Organizations should begin compliance preparations immediately to meet implementation timelines outlined below. Annual Cybersecurity Audit Requirements Recognizing the critical importance of cybersecurity, the CCPA now mandates annual independent audits that assess 18 control areas, for businesses meeting specific risk-based criteria.3 These audits verify the security and integrity of personal and sensitive information, with initial submissions required by April 1, 2028, for qualifying organizations. Applicability Criteria The audit requirement applies to businesses that: - Derive 50% or more of revenue from selling or sharing data; and/or - Generate annual revenue exceeding $25 million (inflation-adjusted), while processing substantial volumes of personal or sensitive information. Core Requirements Organizations meeting these thresholds
Apr 13, 2026 · via fticonsulting.com
Latest Search
Quote
| Back Zoom + Zoom - | |
|
UK Financial Regulators Reportedly Hold Urgent Talks with Cybersecurity Authorities Over Risks of Anthropic's Latest Model
Recommend 0 Positive 0 Negative 0 |
|
|
The Financial Times, citing sources, reported that officials from the Bank of England, the Financial Conduct Authority and the Treasury are holding urgent talks with the UK National Cyber Security Centre to assess potential vulnerabilities in critical IT systems highlighted by Anthropic's latest artificial intelligence model. It is expected that over the next two weeks, representatives from major UK banks, insurers and exchanges will meet regulators to receive briefings on the cybersecurity risks posed by the preview version of the Claude Mythos model. Reuters previously cited sources as saying that US Treasury Secretary Bessent has convened a meeting with major Wall Street banks to discuss the model's potential cyber risks. (fc/j) This article was automatically translated by AI, the Chinese version should be considered the authoritative version. AASTOCKS.com Limited does not guarantee its accuracy or completeness and accepts no liability for any damages or losses arising from the use of this translation. Auto-translated by AI AASTOCKS Financial News |
|
Apr 13, 2026 · via aastocks.com
AASTOCKS.COM LIMITED (阿斯達克網絡信息有限公司) All rights reserved. You expressly agree that the use of this app/website is at your sole risk. AASTOCKS.com Limited, HKEx Information Services Limited, China Investment Information Services Limited, Shenzhen Securities Information Co. Ltd, Nasdaq, Inc., their respective holding companies and/or any subsidiaries of such holding companies, their Sources and/or other third party data provider(s) endeavour to ensure the accuracy and reliability of the Information provided but do not guarantee its accuracy or reliability and accept no liability (whether in tort or contract or otherwise) for any loss or damage arising from any inaccuracies or omissions. Neither AASTOCKS.com Limited, HKEx Information Services Limited, China Investment Information Services Limited, Shenzhen Securities Information Co.Ltd., Nasdaq, Inc. nor their respective holding companies and/or any subsidiaries of such holding companies nor their Sources and/or other third party data provider(s) make any express or implied offers, representations or warranties (including, without limitation, any warranty or merchantability or fitness for a particular purpose or use) regarding the Information. Neither AASTOCKS.com Limited, HKEx Information Services Limited, China Investment Information Services Limited, Shenzhen Securities Information Co. Ltd., Nasdaq, Inc. nor their respective holding companies and/or any subsidiaries of such holding companies nor their Sources and/or other third party data provider(s) will be liable to any Subscriber or any other party for any interruption, inaccuracy, error, or omission, regardless of cause, in the Information or for any damages (whether direct or indirect, consequential, punitive, or exemplary) resulting from its use by any party. AASTOCKS.com Limited shall not be liable for any failure or delay in performance of its obligations under this Disclaimer because of circumstances beyond its reasonable control, including but without limitation, acts of God, typhoons, rainstorms, other natural disasters, government restrictions, strikes, wars, virus outbreak, network failures or telecommunications failures. Morningstar Disclaimer: Copyright © 2020
Apr 13, 2026 · via aastocks.com
This website is using a security service to protect itself from online attacks. We are checking your browser to establish a secure connection and keep you safe.
Please enable JavaScript to continue.
Apr 13, 2026 · via openpr.com
Foresite Cybersecurity announced a strategic partnership with Tanium to launch a managed, autonomous endpoint operations service to enhance visibility, automation, and security across complex IT environments. The new offering leverages the Tanium Autonomous IT Platform to integrate endpoint security, IT operations, and risk management into a unified solution. It is designed for mid-market and enterprise organizations, including public sector agencies, that operate large, distributed endpoint environments and require real-time operational control and resilience. By extending Foresite’s Catalyst platform to the endpoint layer, the service enables organizations to implement policy-driven actions across their infrastructure in real time. Capabilities include endpoint management, exposure management, and security operations, allowing customers to maintain continuous visibility, enforce compliance, and remediate vulnerabilities at scale. The platform uses real-time intelligence and automation to support tasks such as patch governance, configuration remediation, and security policy enforcement. These capabilities are designed to reduce exposure windows, improve compliance, and enhance operational efficiency by enabling organizations to query and act across millions of endpoints in seconds. The service is delivered through two engagement models: an advisory-led “Essentials” option for organizations maintaining operational control, and a fully managed “Complete” model where Foresite assumes responsibility for endpoint operations, including patching, compliance enforcement, and security execution. Through this launch, Foresite aims to help organizations transition from reactive cybersecurity approaches to proactive, autonomous operations, improving both security posture and operational performance across increasingly complex digital environments. KEY QUOTES “You cannot secure what you cannot see, and in a world where the endpoint is the new battleground, guessing is a liability. Our new managed service offering gives organizations the real-time endpoint intelligence and control they need to stay ahead of threats. By combining Foresite’s managed services expertise with the power of the Tanium Autonomous IT Platform, we are helping organizations of every size move from reactive
Apr 13, 2026 · via pulse2.com
Anthropic’s “Mythos” AI Sparks Cybersecurity Fears as Company Limits Release Anthropic’s “Mythos” AI Sparks Cybersecurity Fears as Company Limits Release ——————————— Artificial intelligence company Anthropic has developed a new system reportedly capable of identifying software vulnerabilities across major operating systems and web browsers, raising concerns among cybersecurity experts and policymakers about potential misuse. According to company disclosures, the tool—referred to as “Mythos”—has already identified thousands of security weaknesses and could be used to strengthen digital infrastructure. However, Anthropic has not released the model publicly, citing risks that it could be exploited by malicious actors. Instead, the company is reportedly sharing access under a restricted program known as “Project Glasswing” with selected major technology and financial firms, including Amazon, Apple, Cisco, JPMorgan Chase, and Nvidia, to help them test and improve their cybersecurity defenses. The development has drawn attention from government and financial leaders. Senior U.S. officials and banking executives have reportedly discussed AI-related cyber risks in closed-door meetings, reflecting growing concern that advanced AI systems could accelerate cyberattacks on critical infrastructure. Security experts warn that AI tools are already being used to enhance phishing campaigns, malware development, and automated cyberattacks, reducing the time needed for hackers to exploit vulnerabilities. Analysts say AI significantly increases both the speed and scale of cyber threats compared to human-led operations. Critics have also questioned whether Anthropic’s controlled rollout is motivated partly by commercial strategy, especially as the company is widely reported to be considering future public listing plans. Others argue the restricted release aligns with its stated focus on AI safety and responsible deployment. Anthropic has emphasized that misuse of such technology could pose serious risks to economies, public safety, and national security, and says its cautious approach is intended to prevent harmful deployment while still enabling defensive cybersecurity improvements.
Apr 13, 2026 · via shiawaves.com
For the uninitiated, cybersecurity extravaganza DEF CON may seem like any other conference heavy on handshakes and deal-making. If that’s what you think the inaugural Singapore edition of the event is going to be like, read this article. Till. The. End. Held annually in Las Vegas, DEF CON typically features thousands of hackers, many of whom are inclined to do what they do best (hack things, of course). And they will do so either via official channels like the popular Capture the Flag competitions or, well, whatever else they can get their hands on – including your laptop or mobile phone. DEF CON SG isn’t expected to be any different. So bear in mind the following DO NOTs before you head on down to the convention. 1. DO NOT trust any network That “Free DEFCON WiFi” network? Don’t even think about connecting to it, or any other seemingly official network that’s available. Connecting to random networks at DEF CON is a surefire way to get your devices compromised. After all, hackers tend to compete among themselves when it comes to intercepting, spoofing and just messing around with network traffic at DEF CON – but in the name of fun, of course. Still, harmless prank or not, it’s best to err on the side of caution. We’d suggest you use a Virtual Private Network (VPN) or a hotspot. Some people would even go to the extent of using burner phones at DEF CON. 2. DO NOT plug random USB drives into your laptop You wouldn’t stuff a random cookie you found lying around in your mouth (or would you?). So don’t stick a random USB stick you find lying around DEF CON into your laptop. At DEF CON, “free USB” is basically a guise for “please install malware on yourself”. Rule
Apr 13, 2026 · via htx.gov.sg
Presentation providing analysis of the leading cybersecurity vendors’ recent financial results compared with their competitors. Email Article All set! This article has been sent to my@email.address. All fields are required. For multiple recipients, separate email addresses with a semicolon. Please Note: Only individuals with an active subscription will be able to access the full article. All other readers will be directed to the abstract and would need to subscribe. The Analyst Team Srikara Upadhyaya Follow AnalystResearch Analyst Srikara Upadhyaya works as a research analyst and is based in the Bangalore office. His research is focused on the cybersecurity and infrastructure markets. Prior to joining Canalys, now part of Omdia, Srikara spent two years working as an associate market analyst for IDC India, with a focus on worldwide software, artificial intelligence, and the public cloud service market. He also worked as an analyst at John Crane India Limited, where he worked closely with the production team to analyze SAP production and material management module data. Srikara holds an MBA from Jain University Bangalore and a bachelor’s degree in mechanical engineering from Vishweshwaraiah Technological University.More Content By Srikara Upadhyaya Become A Client Find out more about our full suite of products and solutions. Become A ClientYou must sign in to use this functionality Authentication.SignIn.HeadSignInHeader These are Omdia driven recommendations based on content that is both similar, and has been frequently visited by other users in combination with the content you are currently viewing. Omdia Recommends These are Omdia driven recommendations based on content that is both similar, and has been frequently visited by other users in combination with the content you are currently viewing. Thank you Our expert analysts will review your question and the Ask an Analyst team will get back to you. We aim to respond within 24 hours, but
Apr 13, 2026 · via omdia.tech.informa.com
Latest News The National Security Agency (NSA) along with a number of other parties, has released a new Cybersecurity Information Sheet (CSI), a report that highlights high-level cybersecurity risks and mitigation strategies for users of LEO satellite communication systems. The report is titled “Securing Space: Cyber Security for Low Earth Orbit Satellite Communications.” The NSA has worked with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) in collaboration with the Australian Space Agency on the report. NSA revealed details of the report, March 24. In the report, the risks and mitigations are detailed through the lens of the space segment comprising the satellites themselves; the ground segment encompassing satellite control centers, ground stations, gateways, and user terminals; the user segment that includes end-user devices, applications, and associated interfaces that connect to LEO satcom services; and the communication links and broader supply chain for LEO satcom systems. The CSI suggests numerous mitigation strategies for the space segment and legacy space equipment, including implementing tailored security measures, and using frequency-hopping signals, redundant communication paths, and anti-jam antennas. For the ground segment, continuous monitoring and anomaly detection are essential. The report says the user segment should focus on strengthening endpoint security and enforcing secure access practices. The report also provides frameworks for maintaining the resilience of critical networks, while offering valuable insights and guidelines for users to understand their roles and responsibilities in securing LEO satcom systems. Other agencies co-sealing this CSI are the Canadian Centre for Cyber Security (Cyber Centre), New Zealand National Cyber Security Centre (NCSC-NZ), and Australian Space Agency. Stay connected and get ahead with the leading source of industry intel! Subscribe Now
Apr 13, 2026 · via satellitetoday.com
FOR IMMEDIATE RELEASE Unbreakable, Grace and Grit: ‘Echoes Through the Network’ Chronicles the Unlikely Rise of a Cybersecurity Leader Who Refused to Shrink Kotka, Finland – March 31, 2026 - She did not inherit a legacy. She built one from the quiet corners of a fractured childhood, from the roar of stockcar racetracks, and from the disciplined silence of gym floors where she trained her body to match her will. Dr. Connie McIntosh’s story arrives not as a corporate success manual but as a raw, intimate memoir titled Echoes Through the Network: The Life of Dr. Connie McIntosh. Already available worldwide, the book steps beyond the firewall of her high‑profile career to reveal the woman behind the title: a mother of two, a former world fitness champion, and a leader who redefined what it means to hold power with grace. For more than two decades, Dr. McIntosh has operated at the highest levels of global security, protecting systems of national interest and serving as Head of Security for Ericsson across forty countries. Yet Echoes Through the Network does not dwell on technical blueprints. Instead it walks readers through the emotional architecture of a life built from scratch. From a home touched by domestic instability to boardrooms where she often stood as the only woman, her journey speaks to anyone who has ever been underestimated, silenced, or told they did not belong. At its heart, the book carries a single, unwavering message: real strength is not measured by what you command but by what you choose to carry with grace, grit, and quiet conviction. Dr. McIntosh invites readers to reject the false choice between competence and compassion, between ambition and motherhood, between technical mastery and emotional depth. She writes for the woman hesitating to raise her voice in a male‑dominated room,
Apr 12, 2026 · via markets.financialcontent.com
- United States - / - Semiconductors - / - NasdaqGS:LSCC Why Lattice Semiconductor (LSCC) Is Up 11.7% After New AI, Cybersecurity, And Culture Milestones – And What's Next - Lattice Semiconductor was recently recognized as a 2026 USA TODAY Top Workplaces award winner and received multiple Globee Cybersecurity Awards for its low-power, quantum-resilient FPGA technologies, while also integrating its solutions into NVIDIA’s Halos AI Systems lab for robotics and industrial automation. - Together with positive institutional commentary on its role in AI servers and robotics, these developments highlight how Lattice’s culture, security credentials, and AI partnerships are shaping its position within the semiconductor ecosystem. - We’ll now examine how Lattice’s NVIDIA collaboration and cybersecurity accolades may influence the existing investment narrative around its AI exposure. AI is about to change healthcare. These 31 stocks are working on everything from early diagnostics to drug discovery. The best part - they are all under $10b in market cap - there's still time to get in early. Lattice Semiconductor Investment Narrative Recap To own Lattice, you need to believe its low power FPGAs can stay central to AI servers, robotics, and secure edge devices despite intense competition and semiconductor cyclicality. Right now, the key near term catalyst is execution on AI related design wins, while the biggest risk is that concentrated exposure to a few end markets magnifies any cyclical slowdown. The recent workplace and cybersecurity awards, plus the NVIDIA lab integration, support the AI narrative but do not materially change those core drivers. The NVIDIA Halos AI Systems lab collaboration is the most relevant update here, because it ties Lattice’s low power FPGAs directly into real world AI inspection, robotics, and industrial automation use cases. This sits squarely on the main catalyst that investors are watching: whether Lattice can translate its
Apr 12, 2026 · via simplywall.st
Claude Mythos has created quite a buzz with its cybersecurity concerns, but a prominent cybersecurity expert has said that those risks might be overblown. George Hotz — the hacker who famously jailbroke the iPhone and PlayStation 3, and now serves as President of autonomous driving startup comma.ai — took to LinkedIn to challenge the safety narrative being pushed by the two biggest names in frontier AI. His provocation was blunt: “What if I release one zero day a day until a big new model is released? Will this finally make OpenAI and Anthropic shut up about ‘cybersecurity risk’?” The Argument: It’s Not Hard, It’s Not Incentivized Hotz’s core claim is that software vulnerabilities are far easier to find than AI labs would have the public believe — and that the scarcity of zero-days in the wild is a function of legality, not difficulty. “The reason there aren’t zero days everywhere is cause nobody seriously looks,” he wrote. “Because hacking other people’s shit with them is illegal and criminals are usually not very skilled, or they would choose a different line of work.” His prescription is direct: “Want more zero days to be found? Make hacking legal. Until then, don’t try to claim it’s hard, it’s just not incentivized.” He also took a swipe at the economics of AI-assisted vulnerability research. Reports had surfaced that finding exploits via AI was costing around $20,000 in token usage — a figure Hotz dismissed outright, saying he’d do it for less if not for bug bounty restrictions. Context: The Claude Mythos Rollout Hotz’s post lands in the middle of a charged moment for Anthropic. The company recently unveiled Claude Mythos, its most capable model to date — one it declined to release to the general public, citing its unprecedented ability to identify and exploit
Apr 11, 2026 · via officechai.com
The Rise of the Guardian: Securing the Era of Agentic Autonomy In 2025, AI agents officially became “a thing.” A mid-year CISO survey found that two thirds of enterprises already run AI agents in production and a further 23% planned to do so this year. This warp-speed adoption is already outpacing established security controls, with Gartner reporting in their Market Guide for Guardian Agents that “enterprises are rapidly adopting AI agents, but governance and control mechanisms are not keeping pace.” Embodying the unprecedented combination of the boundless improvisation of humans with the endless stamina of software, the benefits have immediately become clear. (What enterprise wouldn’t want its most creative employees working 24/7/365, without complaint, illness or personal time off?) However, more recently, so too have the risks- unplanned, if unintentional, business interruption; an exploitable target for threat actors seeking access; a source of identity dark matter, the unseen layer of unmanaged identity. To add insult to injury, AI agents not only expand identity dark matter, they also exploit it. Despite the endless stamina highlighted earlier, AI Agents are, by design, lazy- always looking for the most efficient path to return a satisfactory outcome to each prompt. However in doing so, identity dark matter- like orphan, dormant accounts or loose tokens, usually with local clear-text credentials and excessive privileges- often provides the shortcuts necessary to reach the “end of job,” regardless of whether they should have been allowed to do so. So, how does an enterprise unlock the value of AI Agents while managing the risk of this new- neither human nor machine- element of the workforce? 1. Use Agents to Supervise Agents Expand your identity governance program to cover this new class of workers, with a new extension to identity and access management (IAM)- the Guardian Agent. Gartner defines Guardian
Apr 11, 2026 · via linkedin.com
Nassau, The Bahamas - 27 February 2026. PwC Bahamas participated in the second annual ALIV Business Cyber Security Summit, joining a diverse cross-section of stakeholders — including government leaders and regulators, global cybersecurity officials, industry executives, and technology and digital risk specialists — to examine the rapidly evolving cyber threat landscape. In the face of unprecedented digital risks and escalating attack sophistication, 78% of organisations plan to increase their cybersecurity budgets. Yet only 6% of organisations consider themselves “very capable” of withstanding sophisticated cyber-attacks, underscoring the widening resilience gap (PwC’s 2026 Global Digital Trust Insights Survey). Nestle Maullon, Director, Risk Assurance at PwC Bahamas, outlined what national cyber readiness means for The Bahamas during her commentary as a panelist at the Summit. From an enterprise risk standpoint, she highlighted the misalignment between regulatory expectations and real‑world cyber risk management includes cyber risk remaining siloed within IT; boards receiving technical updates instead of business‑risk insights tied to financial exposure and operational continuity; low incident‑response maturity; and limited adoption of threat‑led testing. She noted that the updated Data Protection Act 2025 and The Bahamas National Cybersecurity Strategy (NCS), create an opportunity for stronger, more coordinated national cyber defense strategies. With more than 15 years' experience shaping cybersecurity strategies across the region, she highlighted the critical crossroads facing the nation as it accelerates its digital transformation. “Let us operationalise The Bahamas National Cybersecurity Strategy (NCS) through aligning governance structures with the NCS principles and engage proactively with National Computer Incident Response Team of The Bahamas (CIRT-BS) for reporting and intelligence sharing. " At the summit, PwC underscored several priorities essential to national and organisational readiness: “Cyber resilience must be a top priority for leaders. The organisations that will flourish are those that invest in secure, compliant, and trusted digital ecosystems. PwC remains deeply
Apr 11, 2026 · via pwc.com