No-frills tech news

Govt to promote AI application in <b>cybersecurity</b> defense: Sun Dong

Secretary for Innovation, Technology and Industry Sun Dong stated that the government will continue to strengthen artificial intelligence policies and promote the application of AI to build a solid cybersecurity defense system against the risks brought by the technology. Speaking at the finals of the AI x Cybersecurity Challenge, Sun noted that while the technology introduces new threats to society, it also enhances defense capabilities. He added that the government is continuously reinforcing AI-related policies, guidelines and ethical frameworks, including conducting regular cyber defense drills to guide the responsible use of AI and strengthen Hong Kong's resilience against cyber attacks. Meanwhile, Sun said that the competition, whose finals featured 40 local and overseas teams, serves as a cross-regional platform for professional exchange, adding that cyber threats require global cooperation. Wang Jiang, director-general of the Chinese Academy of Cyberspace Studies and a joint organizer of the event, said he hopes the contest will discover cybersecurity talent and showcase innovative tech achievements. Wang pointed out that frontier AI models are now able to execute cyber attacks autonomously, demonstrating a double-edged sword effect. While AI lowers the threshold for attacks and increases their scale, Wang noted it also offers new defense solutions through proactive perception, dynamic protection and intelligent tracing.

Specialized <b>cybersecurity</b> personnel to receive up to 300% salary allowance

The Government has recently issued Decree No. 329/2026/NĐ-CP, providing detailed regulations on cybersecurity protection forces. A highlight of the decree is the introduction of preferential policies and talent attraction schemes aimed at specialized personnel in the field. Under the decree, the specialized cybersecurity force is defined as the "core force," stationed within the Ministry of Public Security and the Ministry of National Defense in accordance with the Law on Cybersecurity and other relevant legal frameworks. Their primary responsibilities include advising on policies and legislation regarding cybersecurity, data security, personal data protection, and strategic technology projects. They are also tasked with the state management of cybersecurity, data security, and personal data protection as prescribed by law. Personnel on the permanent payroll of these specialized units, or those recruited under talent attraction programs, will receive additional monthly support in addition to their standard salary, allowances, and other statutory benefits. The support is categorized into three levels: Level 1, an additional allowance of up to 100% of the current base salary for those performing professional and technical duties within the specialized cybersecurity force. Level 2, an allowance of up to 200% of the current base salary for individuals directly involved in strategic consulting for cybersecurity or strategic technology projects. This level also applies to those performing tasks requiring highly specialized expertise or those organizing training and coaching for cybersecurity protection. Level 3, an allowance of up to 300% of the current base salary for personnel directly researching, developing, or mastering strategic technologies and products, or new technologies that directly impact national security. This highest tier also covers individuals developing breakthrough technological solutions, models, or strategic projects; those performing tasks with exceptional secrecy requirements or extreme intensity; and those managing 24/7 emergency responses or duties with a significant impact on national security and social

OpenAI Just Unveiled a Powerful New Cyber AI, But You Probably Can't Use It

OpenAI Just Unveiled a Powerful New Cyber AI, But You Probably Can’t Use It OpenAI has introduced a new AI system called GPT-5.6 Cyber, designed specifically for cybersecurity work such as vulnerability research, penetration testing, incident response, and remediation. Most people will not get direct access to it. Instead, OpenAI is limiting GPT-5.6 Cyber to a carefully selected group of cybersecurity companies, consultancies, and managed security providers. The model will be used inside existing security products and professional services rather than being released as another tool that anyone can open and start using. OpenAI Is Keeping GPT-5.6 Cyber Away From Regular Users GPT-5.6 Cyber is designed to help security teams find vulnerabilities, determine whether those vulnerabilities can actually be exploited, identify affected systems, and help develop fixes. That makes the technology useful for defenders, but it also creates an obvious problem. The same capabilities that help a security team investigate weaknesses could potentially be misused if powerful cyber models were made freely available without restrictions. OpenAI appears to be taking a different approach with this release. Instead of handing the underlying models directly to customers, it is working through approved partners that can apply their own expertise, controls, and oversight. Companies including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps are among the organizations with access. The rollout also includes major cybersecurity vendors such as Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare. Customers using these services will not receive the underlying model directly. The approved security provider remains responsible for operating the technology within the boundaries of the engagement. Daybreak Blue and Daybreak Red Target Different Security Work OpenAI is offering two versions of its cyber capabilities through a program called Daybreak Access. Daybreak Blue is intended for a broader range of defensive cybersecurity

Speech by SITI at Opening Ceremony of AI x <b>Cybersecurity</b> Challenge Final Round (English ...

Speech by SITI at Opening Ceremony of AI x Cybersecurity Challenge Final Round (English only) (with photo) ****************************************************************************************** å°æ¬çææå 主任 (Director-general of the general office of the Liaison Office of the Central People's Government in the Hong Kong Special Administrative Region (SAR), Mr Li Shuguang), çæ±é¢é· (Director-General of Chinese Academy of Cyberspace Studies, Mr Wang Jiang), çæåå¯ä¸»ä»» (Deputy Director of the Cyberspace Administration of Guangdong Province, Mr Wang Minwei), Daniel (Acting Commissioner for Digital Policy, Mr Daniel Cheung), Rocky (President of Hong Kong Cybersecurity Professional Association, Dr Rocky Cheng), æè (Director and Chief Executive Officer of China Mobile Hong Kong, Ms Shi Xiaoping), Duncan (member of the Legislative Council (Technology and Innovation Constituency) Mr Duncan Chiu), Francis (Commissioner of Critical Infrastructure (Computer-system Security), Mr Francis Chan), distinguished guests, ladies and gentlemen, Good morning everyone. I am delighted to join you all today for the final round of the inaugural "AI x Cybersecurity Challenge". This competition received 290 entries spanning the Chinese Mainland, Hong Kong and overseas. All of them have demonstrated technical excellence and dedication to safeguarding our digital future. May I extend my warmest congratulations to the 40 finalist teams here today, and my gratitude to the Chinese Academy of Cyberspace Studies, the Hong Kong Cybersecurity Professional Association, China Mobile Hong Kong Company Limited, and all co-organisers for joining hands with our Digital Policy Office to build this platform. This has brought together academia, industry professionals and young talents to advance cybersecurity in this AI-driven era. In today's interconnected world, AI is reshaping every aspect of our life at a breathtaking speed. Although innovation may at times bring new threats, these same technologies can also spur our defensive capabilities. This is why we champion an "AI versus AI" strategy, leveraging AI to forge our strongest shields to effectively manage

Managed IT and <b>Cybersecurity</b> Services Expand Across Houston

Texas MSP Brings Enterprise-Grade Managed IT and SMB Cybersecurity to Houston Area Spring, United States – August 22, 2026 / Precise Business Solutions / Precise Business Solutions has expanded its portfolio of fully managed IT, cybersecurity, and cloud migration services to small and mid-sized businesses across Houston and Spring, Texas, bringing locally delivered, enterprise-grade technology support to a market where many organizations have historically relied on remote or overseas providers. The Spring, Texas-based firm now offers a comprehensive suite of services under a single-point-of-contact model, meaning businesses work with one dedicated local partner rather than navigating multiple vendors or offshore support desks. The expansion targets the specific operational and security challenges facing small and mid-sized businesses in the Houston metropolitan area. Addressing a Measurable Gap in Local IT Support Small and mid-sized businesses in Houston have long faced a structural disadvantage when sourcing enterprise-grade IT infrastructure and security tools, as many managed service providers serving this segment route support through overseas call centers or subcontract work to third parties. Precise Business Solutions structured its service delivery to keep all support local, with no overseas outsourcing involved in its operations. The company’s Managed IT Services Houston offering includes proactive network monitoring, help desk support, patch management, and system maintenance. Rather than responding to problems after they surface, the model is designed to identify and resolve technical issues before they interrupt business operations. For small and mid-sized businesses operating with limited internal IT staff, this proactive approach reduces unplanned downtime and helps maintain operational continuity. SMB Cybersecurity Built to Enterprise Standards A central component of the expansion is the company’s SMB Cybersecurity framework, which applies the same protective controls typically associated with larger enterprise environments to smaller business infrastructure. This includes threat detection, endpoint protection, vulnerability assessments, and ongoing security monitoring calibrated

OpenAI urges California to strengthen AI safety...

ABN AMRO beats Q2 expectations, hits ROE target early, and plans high shareholder returns. Dutch bank ABN AMRO reported strong Q2 results, exceeding revenue, cost, and earnings forecasts while achieving its return on equity (ROE) target two years ahead of schedule. The bank expects risk-weighted assets to stay flat through 2028, meaning it...

The <b>Cybersecurity</b> Infrastructure Developing Countries Need

Digital technology is changing how people work, trade, access financial services and interact with governments. Mobile banking, digital payments, cloud platforms and government portals are becoming part of everyday life across developing countries. But as more economic activities move online, cyber risks are also increasing. Criminals target banks, businesses, hospitals, government agencies and individuals. A successful attack can stop services, expose sensitive information and create serious financial losses. For developing countries, the challenge is to expand digital services while ensuring that the systems supporting them remain safe and reliable. Countries need strong cybersecurity infrastructure built into their digital economies from the beginning. The Economic Cost of Weak Cybersecurity Cybersecurity is now an economic issue, not just a technical one. The global average cost of a data breach reached about $4.88 million in 2024, according to IBM research. For a developing country, a major attack against a bank, payment platform or government system can create consequences far beyond repairing computers. If a digital payment system becomes unavailable, businesses may be unable to receive payments, customers may lose access to services and confidence in digital finance may decline. Government systems face similar risks. Tax platforms, national identification systems, healthcare databases and public payment systems contain valuable information. If poorly protected, attackers can exploit them for fraud, disruption or data theft. Cybersecurity should therefore be treated as part of national economic infrastructure, alongside telecommunications and financial systems. Strong protection can help maintain public confidence and reduce the wider economic impact of cyber incidents. Building Security Into Digital Infrastructure Developing countries need to move from reacting to cyberattacks to preparing for them. This means investing in secure digital identities, protected government networks, encryption, multi-factor authentication, continuous monitoring and reliable backup systems. National Computer Emergency Response Teams, commonly known as CERTs or CSIRTs, help countries

U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs

U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs What you’ll learn: - Multiple U.S. investigative agencies said cyberattackers used AI-generated code to target Siemens S7 Series PLCs, these in U.S. critical infrastructure. - The multi-agency advisory stated that the as-yet-unidentified attackers are using AI to develop Python exploitation scripts that use the 'snap7.dll' and 'python-snap7' libraries. - The reports follow an episode last fall when vulnerabilities were discovered in the Siemens RuggedCom ROXOS II multiservice platform but not exploited by threat actors, thanks to detection and patching. Far be it for us to toot our own horn, but we'll do so anyway: AI-powered cyberattacks on manufacturing and critical infrastructure are a thing, a very big thing. And we and our contributing writers have been telling you so for more than a minute. The latest news provides more proof. Dennis Scimeca grabbed this for our brands last week, based on advisories reflected at tech and cybersecurity news website BleepingComputer: Siemens manufacturing and critical infrastructure hardware has been coming under assault from cyberattackers, who most notably used AI-generated code to do so. See also: AI is superpowering cyberattacks, but manufacturers can cut their exposure The details: The U.S. National Security Agency, the FBI, the U.S. Department of Energy, the U.S. Environmental Protection Agency, and the U.S. Cybersecurity and Infrastructure Agency all jointly announced that cyberattackers had used or are using AI-generated code to target Siemens S7 Series programmable logic controllers, these specific ones embedded into critical infrastructure. Many of you are “boots-on-the-ground” in OT or IT so you know that PLCs are vitally important plant gear—and those from Siemens are some of the most widely used in manufacturing and other sectors. PLCs are the rugged, reliable brains that monitor inputs from sensors, execute custom user logic, and control physical

If you're not using AI to attack your own systems, your adversaries will

AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies. “There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. “As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added. “AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially

AI Stocks With Real Revenue From Enterprise Software and <b>Cybersecurity</b>

Global services activity is holding up even as some manufacturing readings soften, and this keeps demand for computing power and automation firmly in focus. That backdrop keeps attention on artificial intelligence stocks, where companies tied to chips, cloud and large language models are helping power new productivity tools. This article highlights three AI related stocks from the screener that could interest investors building long term exposure to the theme. The three stocks discussed next are just a starting sample, and the full screen surfaced 32 more companies with equally compelling AI related narratives that are not covered here. To see the bigger picture and size up potential opportunities for your own watchlist, head straight into the Artificial Intelligence/ AI Stocks screener to identify, filter and analyze the highest conviction plays across the theme. Docebo (TSX:DCBO) Overview: Docebo is a Toronto based software company that provides a cloud learning management platform, with AI powered Harmony Search and personalization tools that tailor training content for each user. Its AI and analytics sit inside the core learning suite, so investors are looking at a learning software business where machine learning and NLP features support, rather than dominate, the revenue story. Operations: Docebo generates about $258.9 million in revenue from educational software. The United States contributes $174.0 million, the rest of the world $71.4 million and Canada $13.5 million. Market Cap: CA$807.0 million Investors interested in AI may consider Docebo because its Harmony Search and AI driven analytics are already embedded in a full scale learning platform used across enterprises, rather than sitting in a lab. The company reports triple digit million revenue and positive earnings, which gives those AI tools a commercial footing, although monetization of some newer features is still unproven. A sizeable buyback authorization funded through a mix of cash and

US authorities say Siemens controllers used for water and other infrastructure are being ...

US authorities say Siemens controllers used for water and other infrastructure are being targeted by hackers — agencies claim threat actors use AI tools to generate exploitation scripts Attacks on these industrial controllers could lead to sabotage of critical infrastructure. Various U.S. agencies just released a warning claiming that Iranian hackers are targeting Siemens S7-series programmable logic controllers (PLCs). According to the Cybersecurity and Infrastructure Security Agency (CISA) advisory, hackers are using publicly available information on these widely used devices to develop exploits that would enable remote access and control. They’re also using AI tools, allowing them to identify additional attack vectors and possibly adapt to any defensive measures operators may have taken to protect their systems. “The actors leverage Internet scanning services to find Internet-exposed PLCs running outdated software or that are otherwise poorly protected,” the agency said in its warning. “The U.S. critical infrastructure sectors most targeted by this threat activity include Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture, and Commercial Facilities. This is not a theoretical risk — it is an active threat. Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems.” The warning comes from multiple government agencies, not just CISA. The advisory was also co-authored by the National Security Agency (NSA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE), and the Environmental Protection Agency (EPA), underscoring how serious this issue could become. Because of this, operators using Siemens S7 PLCs (and other PLCs operating critical infrastructure) are advised to keep their equipment updated with the latest applicable security patches, isolate it from the internet as much as possible, protect it with strong

This Week's Top Five Stories in Cyber

This Week's Top Five Stories in Cyber China Closes in on Cyber Race as GLM-5.3 Beats US Models Leading Chinese start-up Z.ai has launched GLM-5.3, an open-source model that demonstrates improved coding and cybersecurity performance compared to GLM-5.2. Benchmark data released by Z.ai reveals that the model achieved high scores on a cyber performance test, surpassing several models from US companies Anthropic and OpenAI. The release comes at a time when the US State Department has reportedly been drafting a correspondence to multiple countries regarding the AI competition with China. Reuters reviewed an internal draft, which states that dozens of countries must choose between a US-led AI coalition and Beijing's competing framework, with exclusion from the former if they join the latter. How RingCentral Breach Exposed 1.6 Million Customer Records Cybercriminal group ShinyHunters has released into the open 1.6 million records of customer accounts from cloud-based business communications platform – RingCentral. Data from the company was compromised following what it called “a sophisticated social engineering campaign” back in July. RingCentral disclosed on July 28 2026 that it had been targeted in an incident which “has affected data for a limited portion of RingCentral customers”. “Upon detection, we promptly took steps to stop the unauthorised activity and immediately began an investigation with assistance from a leading third-party forensic firm,” RingCentral highlighted. PLM Zero Day Flaw Exploited by Clop in Massive Data Breach Infamous for exploiting vulnerabilities in software used by a large number of enterprises claiming multiple high-profile victims in a single attempt, the Clop cybercriminal group has struck again. Coming out with claims of a massive data breach affecting nearly 50 companies, the prolific Russian-speaking threat actor adds giants like Shell, Philips, GE and Fiserv among the multinationals affected. Clop alleges to have stolen 89GB data from Shell, 15.5GB from

Losses keep piling up for Trump administration over handling of RTO mandate

The Trump administration’s losses keep piling up in grievance cases over its return to office and telework policies for union employees. The latest loss came earlier this week when an arbitrator ruled that the Agriculture Department violated its collective bargaining agreement and committed unfair labor practices when it ended its telework and mandated Rural Development Agency employees represented by the American Federation of State, County and Municipal Employees (AFSCME) return to the office without negotiating the terms first. Margaret Donaghy, the arbitrator in this case, found USDA “committed unfair labor practices (ULPs) when it engaged in bad faith bargaining and implemented a rule that conflicted with the existing agreement. The nature and scope of the agency’s breaches amounted to a repudiation of the agreement.” The agency changed the remote work and telework agreements for 135 employees, 46 of which required remote work as a condition of employment. “The arbitrator points out in this new decision that nothing the agency argued hasn’t already been argued in other cases and none of it was convincing. The arbitrator is aligning with same opinions from earlier cases,” Summerlin said. “That fact is very illuminating because it seems like a dozen different arbitrators have come to same decision on these cases. Everyone who has a neutral eye and any background in federal labor law could look at this process and say this is wrong and the administration screwed this up from the beginning. It doesn’t matter what agency, the marching orders the agencies received were the same from the administration.” The administration has come out on top in at least three other cases, including one case that became public today, which is related to a grievance filed by the American Federation of Government Employees Local 3313, whose members work for the Transportation Department’s Federal Motor

How Nigeria-UK cyber alliance Is countering AI-driven threats, financial crime

Nigeria and the United Kingdom are deepening their cybersecurity partnership to strengthen Nigeria’s capacity to combat AI-driven cyber threats, financial cybercrime and attacks on critical national infrastructure. Through the UK-funded Africa Cyber Programme and the broader UK-Nigeria Cyber Memorandum of Understanding, both countries have expanded cooperation in intelligence sharing, cyber resilience, digital forensics, policy development and workforce development, positioning Nigeria as one of Africa’s leading cybersecurity hubs. Stakeholders say the partnership has moved beyond isolated training programmes to become a long-term institution-building initiative designed to leave Nigeria with sustainable local capacity. The intervention comes as Nigeria’s cyber threat landscape continues to evolve, with financially motivated cybercrime targeting banks and fintech companies remaining the country’s biggest digital security challenge, while ransomware attacks against critical infrastructure, including energy facilities and cloud-hosted services, continue to increase. In an interview with BusinessDay Newspapers in Abuja, Lawrence Devlin, Head of Counter-Terrorism British High Commission West Africa, noted that the partnership has focused on building the institutional foundations required for Nigeria to independently identify, investigate and respond to cyber threats rather than relying on external support. A major outcome of the collaboration has been the strengthening of Nigeria’s cyber governance architecture through the review of the National Incident Response Plan, development of cyber maturity frameworks for the protection of Critical National Information Infrastructure and foundational work on the country’s National Digital Forensics Policy framework. Devlin said these initiatives have significantly improved Nigeria’s ability to standardise digital forensic investigations, ensuring that electronic evidence gathered during cyber investigations can withstand scrutiny in both domestic and international courts. Another landmark achievement has been the development of highly specialised Nigerian cybersecurity professionals. “Through the programme, four officers of the National Cybersecurity Coordination Centre (NCCC) became among the first SIM3-certified cybersecurity auditors in Africa. SIM3 is an internationally recognised framework for

Z.ai delays GLM 5.3 release over <b>cybersecurity</b> risks

Z.ai announced GLM 5.3 on Friday, Aug. 14, 2026, introducing an open-weight artificial intelligence model built for advanced coding and cybersecurity work. The company said the model runs on the same base architecture as its predecessor, GLM 5.2, with every capability gain coming from expanded post-training instead of a larger base model. Z.ai launched OpenVuln alongside the release, a scanning service, branded internally as "VulnHunter," that uses GLM 5.3 to check public code repositories for security flaws. Maintainers submit projects for review, and Z.ai publishes an aggregate security score while keeping detailed findings private until a fix is ready. On CyberGym, a benchmark that scores how well a model finds known vulnerabilities in source code, GLM 5.3 reached 84.5 percent, up from 77.2 percent for GLM 5.2. On ExploitBench, a separate benchmark measuring exploit reasoning, the new model scored 54.4 percent, more than double GLM 5.2's 24.4 percent. Both figures come from Z.ai's own testing and have not been independently verified. Z.ai's public disclosure ledger credits GLM 5.3 with 2,436 vulnerability findings across 269 open-source projects, including 1,097 rated critical or high severity. The company said several of those flaws turned up in the Linux kernel and in widely used VMware and Apache projects. A Z.ai developer advocate also wrote on X that GLM 5.3 flagged a possible vulnerability in Cursor, the AI coding tool SpaceX acquired earlier this year. Z.ai said it will hold back GLM 5.3's public model weights for about two weeks after the Aug. 14 launch, restricting access during that window to a group of vetted security partners through its GLM Coding Plan and ZCode agent. In its announcement, Z.ai wrote that the model's gains "can help defenders identify weaknesses earlier, validate risks, and accelerate remediation." The company also acknowledged that those same gains carry risk

Dr. Christina Asare Advances <b>Cybersecurity</b> Strategy and AI

Dr. Christina Asare Advances Cybersecurity Strategy and AI Governance Leadership Through Growing Consulting Portfolio Chief Program Strategy Officer and Fractional vCISO Brings More Than 14 Years of Enterprise Program Leadership to Government and Institutional Clients. Suffolk, Virginia, United States - August 22, 2026 - Dr. Christina Asare, PhD, MBA, PMP, Chief Program Strategy Officer and Fractional vCISO, continues to expand her footprint across cybersecurity strategy, AI governance, and organizational consulting, serving government agencies, healthcare systems, and institutional clients nationwide. Dr. Asare brings more than 14 years of enterprise program management experience spanning healthcare, federal defense, utilities, and SaaS environments, with a track record of leading large-scale technology and program initiatives for major national organizations. As Chief Program Strategy Officer and leader of Titanium CyberForce, Dr. Asare serves as a fractional vCISO for client organizations, providing executive leadership for cybersecurity strategy, governance, risk management, and enterprise security decision-making across engagements. Founded in November 2014, Global 1 Consulting, LLC holds WBENC Women's Business Enterprise and NMSDC Minority Business Enterprise certifications. The firm's model centers on securing government and institutional contracts while managing subcontractor teams across concurrent engagements. Dr. Asare holds a PhD in Technology Innovation, an MBA in Information Technology, and a Master of Science in Management, along with graduate certificates from Harvard Business School Online and UMass Lowell. Her professional certifications include Project Management Professional (PMP), SAFe Agilist, SAFe Scrum Master, Certified ScrumMaster (CSM), Certified Scrum Product Owner (CSPO), CompTIA Security+, Certified in Cybersecurity through IS2C, the Google AI Professional Certificate, and the Google Cybersecurity Professional Certificate. Beyond her consulting practice, Dr. Asare is a Minister of the Gospel and a prolific author whose published works span cybersecurity, faith, leadership, and children's literature. She publishes The Tech Strategy Brief and The HealthPro Leadership Letter through the Asare Tech and Business Academy,

Why Btech. (Information Technology) at LPU stands out

Overview of the B.Tech. (Information Technology) Program at LPU The digital world is evolving rapidly. From cloud platforms and artificial intelligence to cybersecurity, data-driven applications, connected devices, and software automation, technology is influencing almost every industry. This transformation has increased the demand for professionals who can understand, develop, and manage modern IT solutions. For students looking to build a career in this technology-driven environment, B.Tech. Information Technology at LPU offers an opportunity to study core computing concepts while exploring emerging technologies and practical applications. The information technology program at LPU combines technical learning with projects, laboratory work, industry exposure, innovation activities, and interdisciplinary opportunities. Whether a student is interested in software development, cloud computing, cybersecurity, data science, AI, or emerging digital technologies, an IT engineering course can provide a foundation for exploring multiple career directions. Program Snapshot | Feature | Details | | Program | B.Tech. (Information Technology) | | Core Focus | Information Technology, Programming, Software & Computing | | Learning Approach | Practical, Project-Based & Industry-Oriented | | Emerging Areas | AI, Data Science, Cybersecurity, Cloud Computing & IoT | | Potential Career Areas | Software Development, Cloud, Cybersecurity, Data, IT Services & Technology | Why Is LPU’s Information Technology Curriculum Industry-Oriented and Future-Ready? Technology changes quickly, so an information technology syllabus needs to provide students with both fundamental knowledge and opportunities to understand emerging technologies. The industry-oriented IT curriculum at LPU is designed around computing and technology concepts that can help students develop a broad understanding of the IT ecosystem. Along with foundational subjects, students can explore areas connected with software engineering, databases, networks, cloud technologies, artificial intelligence, data, cybersecurity, and other digital technologies. A future-ready IT education can help students develop the ability to learn new technologies rather than depending only on one programming language or

TikTok settles children's privacy suit with DOJ for $400 million | Fortune

TikTok has reached a $400 million settlement with the U.S. Department of Justice, ending a 2024 lawsuit alleging the company violated federal children’s privacy laws. The DOJ said Friday that TikTok will pay $300 million immediately and another $100 million after an order vacates an earlier consent decree against its predecessor company, Musical.ly. “This settlement is a major victory for American children and parents,” said U.S. Associate Attorney General Stanley E. Woodward Jr. in a statement. “The Department’s priority is ensuring that children are protected online and that companies entrusted with their personal information meet their legal obligations. This resolution secures a substantial recovery while reinforcing the protections that families expect and deserve.” Since the DOJ’s lawsuit in 2024, TikTok has undergone major changes, most notably in the ownership structure of its U.S. arm. In January, the social video platform company signed agreements with major investors including Oracle, Silver Lake and the Emirati investment firm MGX to form the new TikTok U.S. joint venture. Representatives for TikTok did not immediately respond to a message for comment Friday. The latest lawsuit focused on allegations that TikTok and its China-based parent company ByteDance violated a federal law that requires kid-oriented apps and websites to get parental consent before collecting personal information of children under 13. It also says the companies failed to honor requests from parents who wanted their children’s accounts deleted, and chose not to delete accounts even when the firms knew they belonged to kids under 13. The settlement comes as social media companies face an avalanche of lawsuits over children’s safety and privacy and a growing number of countries are banning young kids and teens from social media apps. Instagram’s parent company, Meta Platforms, is currently on trial in federal court in Oakland, California, over allegations it violated the

First malware targeting vehicle infotainment systems discovered

A novel malicious software campaign targeting Android specifically for vehicle smart screens has been detected by the research team at cybersecurity company Kaspersky. These systems, which sometimes combine multimedia entertainment and key car controls, have become the new target for cybercriminals. The cybercriminals use a stealthy multi-stage download program, marking the first documented case of this type of harmful computer code infecting a vehicle's multimedia screen through an infection chain exclusively adapted to these automotive systems. With cyber fraud as the goal The main objective of the cybercriminals is to deploy malicious code to commit massive advertising fraud and other harmful activities. According to experts, this activity may be linked to MoYu Group, a cyber threat actor closely related to the well-known infected device network BadBox. Car multimedia screens, whether factory-installed or added later, commonly use the Android operating system to customize the interface and add key functions. This allows most Android applications and malware to run on them. Although these devices rarely store sensitive personal data, they have SIM card slots and continuous internet connection for map navigation and updates, making them an attractive entry point for cybercriminals. Compromised updates The malicious software was distributed by exploiting the update mechanisms integrated into the software of several models of Android screens from provider DoFun, which claims to have already fixed the vulnerability following Kaspersky's notification. The infection chain was caused in the legitimate system application TWCore, responsible for collecting analytics and managing device updates. The cybercriminals manipulated this channel to directly deliver a hidden installation program called JarService, which operated in the background without a user interface and without the driver noticing anything unusual. Once inside, the cybercriminals had nine different commands capable of displaying unwanted ads, executing advertising fraud, and downloading additional harmful modules. Additionally, the malicious software collected