No-frills tech news

Depthfirst: $80 Million Raised For AI-Native <b>Cybersecurity</b> Platform Expansion

depthfirst, an applied AI lab focused on securing software systems, announced it has raised $80 million in a Series B funding round, bringing its total capital raised to $120 million. The round was led by Meritech Capital, with participation from Forerunner Ventures and The House Fund, alongside existing investors including Accel, Box Group, Liquid 2 Ventures, Alt Capital, and Mantis VC. The funding comes less than 90 days after the company emerged from stealth with a $40 million Series A round, signaling strong investor confidence in its approach to AI-driven cybersecurity. As part of the announcement, depthfirst introduced its first in-house security model, dfs-mini1, designed initially to secure cryptocurrency smart contracts. The model was built on an open-source foundation and further trained using reinforcement learning in security-specific environments. It was evaluated on OpenAI’s EVMBench, a benchmark for identifying vulnerabilities in smart contracts. According to the company, dfs-mini1 outperformed frontier models while operating at 10x to 30x lower cost. Early internal testing also suggests the model can generalize beyond smart contracts to broader security tasks, indicating potential scalability across multiple domains. depthfirst’s broader strategy centers on developing domain-specific AI models tailored to high-stakes applications like cybersecurity. Its AI-native platform analyzes entire software systems, identifies vulnerabilities, and provides developers with ready-to-merge fixes directly within their workflows. The company says its platform is already being used by a mix of Fortune 500 companies and high-growth technology firms, including ClickUp, Supabase, incident.io, Moveworks, and Lovable. It reports that approximately 80 percent of its recommended fixes are accepted and merged by developers, reflecting strong real-world utility. The newly raised capital will be used to expand the company’s AI research team, develop additional specialized security models, and accelerate enterprise adoption of its platform. KEY QUOTES: “When you own the training process, you can optimize for what

Why I'm done calling humans the weakest link

Why I’m done calling humans the weakest link Cybersecurity has long suffered from a people problem, but not in the way we often hear about. As industry that is based on enabling communication across the globe via the internet and many types of devices, many of us practitioners are very bad at communicating to people. A primary example is the phrase “humans are the weakest link” which is well known phrase in our industry. This phrase implies that if it were not for human our systems would be fully secure, but most worryingly projects the message to non-cybersecurity people that there are inferior to us. So not only does this phrase alienate our fellow workers it is a phrase that I firmly believe is unfair and completely misleading. The real issue around cybersecurity is not human error, it is the failure of the technology and the system designs and architecture to support real human behavior. Despite years of awareness campaigns, data breaches linked to phishing and credential misuse continue to dominate incident reports and news headlines. And after each of these breaches the vendors and experts commenting on the breach will reuse the phrase “humans are the weakest link” laying the blame not on any failures in the technology meant to protect us but, instead placing the blame on the person using the computer. Even if a person did get phished or fell victim to a malicious email this should not prompt another round of finger-pointing. Instead, it should raise urgent questions about why so many of our systems still leave people so vulnerable. Take phishing, for example. If a malicious email lands in an inbox and a staff member clicks it, the typical response is to blame the individual for not spotting the signs. But why did the email

The Great Repricing Crushed This <b>Cybersecurity</b> Growth Stock. That's a Buying Opportunity.

Zscaler (ZS +2.34%) was one of the market's hottest cybersecurity stocks, reaching an all-time high of $368.78 per share on Nov. 19, 2021. But today, it trades at about $139. Zscaler's stock initially lost its luster as its growth cooled, but macro headwinds -- including rising interest rates and geopolitical conflicts -- further compressed its valuation. Yet after that steep sell-off, Zscaler's stock might be a good contrarian play for patient investors. How fast is Zscaler growing? Zscaler develops "zero trust" tools that treat everyone, including a company's CEO, as a potential threat. Those tools can shield organizations from both internal and external threats while being integrated into larger, more diversified cybersecurity platforms. Before Zscaler was founded in 2007, many organizations installed their zero-trust services on physical appliances -- which took up space, required on-site maintenance, and were difficult to scale. Zscaler addressed those issues by launching its tools as a cloud-native service that locked its users into sticky subscriptions and didn't require any on-site appliances. It subsequently expanded its ecosystem with additional cloud-based cybersecurity tools and now serves more than 9,400 customers, including 40% of the Forbes Global 2000 companies. NASDAQ: ZS Key Data Points From fiscal 2020 to fiscal 2025 (which ended in July 2025), Zscaler's revenue and adjusted net income grew at CAGRs of 44% and 75%, respectively. However, it still isn't profitable by generally accepted accounting principles (GAAP), mainly due to its stock-based compensation expenses and long streak of ecosystem-expanding acquisitions. From fiscal 2025 to fiscal 2028, analysts expect Zscaler's revenue to grow at a 21% CAGR. They also expect it to turn profitable on a GAAP basis in the final year. Its growth is slowing down as its business matures. However, it's still expanding its AI-powered ZDX Copilot platform, deepening its integrations with other cloud-based

VendRespect Introduces Advanced <b>Cybersecurity</b> Scoring System to Help Businesses ...

Los Angeles, California – March 31, 2026 – PRESSADVANTAGE – VendRespect, a Valley Village-based cybersecurity and vendor management company, has introduced a comprehensive scoring system designed to help businesses quantify and manage their digital security risks across their entire vendor ecosystem. The new system addresses a critical challenge facing modern businesses: understanding and managing cybersecurity vulnerabilities not just within their own operations, but throughout their supply chain. With cyber threats becoming increasingly sophisticated and supply chain attacks rising dramatically, organizations need clear metrics to assess their security posture and that of their vendors. VendRespect cybersecurity scoring provides businesses with a dynamic, real-time assessment that changes as vendor security profiles evolve. The system integrates multiple assessment methods, including automated risk evaluations, third-party verifications, and continuous monitoring of vendor security practices. “Businesses today face an unprecedented challenge in managing cybersecurity across their entire vendor network,” said Maksim Avrukin, founder of VendRespect. “Our scoring system transforms complex security data into actionable intelligence that business owners and IT professionals can use to make informed decisions about their digital infrastructure and vendor relationships.” The scoring methodology evaluates multiple security factors including current security practices, vendor security profiles, and third-party verification results. Unlike static assessments that quickly become outdated, the system updates continuously to reflect changes in the threat landscape and vendor security status. For managed service providers and IT consultants, the platform offers integration with existing documentation systems such as IT Glue, enabling seamless incorporation of security scoring into current workflows. This integration allows service providers to leverage existing client data while providing visual documentation that supports security recommendations and compliance requirements. The system also addresses supply chain risk management by identifying critical vendors within an organization’s ecosystem and assessing how their security practices impact overall organizational risk. This comprehensive approach helps businesses understand vulnerabilities

Supply-Chain Compromise of axios npm Package

Note: This Rapid Response article has been written with AI assistance. Acknowledgments: Special thanks to Jevon Ang, Michael Elford, Jordan Sexton, Armelle French, Stephanie Fairless, Juzzy Allen, Ryan Dowd, Chad Hudson, Lindon Wass, James Maclachlan, James Northey, Josh Kiriakoff, Jai Minton, and Max Rogers for their contributions to this investigation and response. TL;DR: Huntress has observed active exploitation of a supply chain compromise targeting the axios npm package -- one of the most widely used JavaScript libraries, with over 100 million weekly downloads. The attack delivered a cross-platform Remote Access Trojan (RAT) to macOS, Windows, and Linux systems via a malicious dependency injected into backdoored axios releases. Organizations should immediately audit their dependencies for axios@1.14.1 or axios@0.30.4, treat any system that installed either version as compromised, and follow the remediation guidance below. Background On March 31, 2026, a coordinated supply chain attack was executed against the axios npm package. An attacker compromised the npm credentials of the lead maintainer account (jasonsaayman) and manually published two backdoored releases: axios@1.14.1 (tagged latest) and axios@0.30.4 (tagged legacy). These versions introduced a phantom dependency -- plain-crypto-js@4.2.1 ... a package that had not existed before that day and is never actually imported by axios code. Its sole purpose was to execute a postinstall script that drops and runs a cross-platform RAT targeting macOS, Windows, and Linux. axios is a promise-based HTTP client used extensively across the JavaScript and Node.js ecosystem. It is a transitive dependency for countless packages, CI/CD pipelines, developer workstations, and production applications worldwide. The scope of this compromise is significant: any environment that ran npm install and resolved to axios@1.14.1 or axios@0.30.4 during the approximately three-hour exposure window may have executed the malicious payload automatically with no user interaction required. The malicious versions were published during overnight hours (just after midnight UTC,

Dual Enrollment Student Helps Win Cyber Title

by Cara Ramer, Student Public Relations Writer After hours of defending simulated networks against coordinated cyberattacks, a team of Cedarville University students secured first place in one of two Midwest Divisions of the NCAE Cyber Games on Feb. 7, 2026 — and one member of the winning team has yet to graduate from high school. For Kieran Klukas, a high school senior from Westerville, Ohio, taking dual enrollment courses at Cedarville, competing in a collegiate-level cybersecurity competition was an unexpected opportunity. After attending the university’s summer cybersecurity camp, Klukas discovered a passion for cybersecurity and began pursuing the field academically. Klukas sought additional hands-on opportunities within Cedarville’s cybersecurity program, which ultimately led to his selection for the NCAE Cyber Games team. Dual enrollment senior excels in collegiate cybersecurity competition The competition follows a red team-blue team format in which industry professionals and graduate students attempt to breach the systems of competing teams. Participants must defend network infrastructure, maintain system uptime and respond to live attacks in a scenario designed to simulate real-world cybersecurity threats facing businesses, government agencies and critical infrastructure. NCAE Cyber Games: red team–blue team live-fire format Over seven hours, the competition operated as a live-fire exercise, with industry professionals deploying real exploits against each team’s systems. From the opening minutes, services were “catching on fire” as the red team exposed vulnerabilities across the machines. Klukas shifted rapidly between systems, patching weaknesses and shutting down access points as they appeared. By the final stretch, Cedarville was one of the only teams still operational, making it a primary target. Klukas spent the last hours of the competition jumping from service to service, eliminating threats and refusing to let their systems go dark. Cedarville winning team roster and majors Cedarville’s winning team included computer engineering, computer science and cyber operations

Silver Fox Expands Asia Cyber Campaign with AtlasCross RAT and Fake Domains

Chinese-speaking users are the target of an active campaign that uses typosquatted domains impersonating trusted software brands to deliver a previously undocumented remote access trojan named AtlasCross RAT. "The operation covers VPN clients, encrypted messengers, video conferencing tools, cryptocurrency trackers, and e-commerce applications, with eleven confirmed delivery domains impersonating brands including Surfshark VPN, Signal, Telegram, Zoom, Microsoft Teams, and others," Germany-based cybersecurity company Hexastrike said in a report published last week. The activity has been attributed to a Chinese cybercrime group called Silver Fox, which is also tracked as SwimSnake, The Great Thief of Valley (or Valley Thief), UTG-Q-1000, and Void Arachne. The discovery of AtlasCross RAT represents an evolution of the threat actor's arsenal from Gh0st RAT derivatives like ValleyRAT (aka Winos 4.0), Gh0stCringe, and HoldingHands RAT (aka Gh0stBins). The attack chains involve using bogus websites as lures to trick users into downloading ZIP archives containing an installer that drops a trojanized Autodesk binary along with the legitimate decoy application. The trojanized AutoDesk installer, in turn, launches a shellcode loader that decrypts an embedded Gh0st RAT configuration to extract the command-and-control (C2) details and then downloads a second-stage shellcode payload from "bifa668[.]com" over TCP on port 9899, ultimately leading to the execution of AtlasCross RAT in memory. The majority of fake websites were registered in a single day on October 27, 2025, indicating a deliberate approach behind the campaign. The list of confirmed malware delivery domains is listed below - - app-zoom.com (Zoom) - eyy-eyy.com (unknown) - kefubao-pc.com (KeFuBao, a Chinese customer service software for e-commerce) - quickq-quickq.com (QuickQ VPN) - signal-signal.com (Signal) - telegrtam.com.cn (Telegram) - trezor-trezor.com (Trezor) - ultraviewer-cn.com (UltraViewer) - wwtalk-app.com (WangWang) - www-surfshark.com (Surfshark VPN) - www-teams.com (Microsoft Teams) All identified installer packages have been found to carry the same stolen Extended Validation code-signing certificate