No-frills tech news

Dicker Data adds Sophos to boost <b>cybersecurity</b> offering

Demand for cyber security continues to grow. Dicker Data is set to expand is its cyber security portfolio and providing partners across Australia and New Zealand with Sophos solutions. The agreement will see Dicker Data distribute the vendor’s cyber security portfolio across endpoint, network, email and security operation products. The distributor will also support the continued growth of Sophos’ MSP business and services portfolio. This includes managed detection and response (MDR), advisory services and incident response. Through the partnership, Dicker Data will provide local sales, technical, enablement and go-to-market support to help partners build their Sophos capability, as well as help them to develop cyber security opportunities and grow sustainable security practices. Dicker Data general manager — software A/NZ Pennie Stevens said the addition of Sophos reflects the distributor’s continued investment in cyber security as a strategic growth area for partners. “Cyber security continues to be one of the most important priorities for our partners and their customers, and Sophos brings a comprehensive and highly relevant portfolio to help address that need,” she said. “For our partners, this creates new opportunities to grow their security practice, expand managed services offerings and support customers.” The appointment of Dicker Data brings additional reach support Sophos’ next phase of growth across A/NZ, said Sophos director channel and commercial sales A/NZ Marina Brook. “As our business continues to evolve, so does the opportunity for our partners,” she said. “Together with Dicker Data, we want to expand the Sophos partner ecosystem, create new opportunities across the market and help our partners.”

Briefcase: Business snippets from <b>cybersecurity</b> training for pollies to a new mental health centre

In this week’s Briefcase, Detmold Group opens a new manufacturing facility while an Adelaide hotel unveils its new events space. The National Industry Innovation Network (NIIN) has launched a new cybersecurity program aimed at South Australia’s parliamentarians. Securing Our Future: Cyber Essentials for Parliamentarians in South Australia is designed to help participants better understand cyber risks, strengthen cyber hygiene and adopt safer everyday security practices to support parliamentary offices. The program is being delivered in partnership with Cisco, Flinders University, Adelaide University and ArchiTech, bringing together cybersecurity experts, industry leaders and academic partners to examine the evolving cybersecurity threat. “Cyber security is increasingly important across every part of society and government and initiatives such as Cyber Essentials provide practical tools to help strengthen cyber awareness and resilience,” Artificial Intelligence Minister Chris Picton said. A $22 million Crisis Stabilisation Centre has officially opened, providing Northern suburbs residents access to additional mental health support services. The 16-bed crisis support centre has opened next to the Lyell McEwin Hospital and will start providing services from this week as part of a staged opening. It follows a 12 per cent increase in mental health presentations to emergency departments in the Northern Adelaide Local Health Network facilities, with the new centre allowing patients to stay up to three nights. “This new service will provide more options for people to get the help they need closer to home, while ensuring emergency departments can focus on those requiring acute medical care,” Health Minister Blair Boyer said. Crystalbrook Collection Hotels and Resorts has unveiled its events space ahead of the opening of its first Adelaide CBD-based hotel Crystalbrook Sam in December. Crystalbrook Sam will be a 196-room luxury hotel on Halifax Street with dining experiences and a rooftop bar. The three new event spaces will cater for corporate

Inspira Enterprise Expands into Australia to Accelerate AI-Driven <b>Cybersecurity</b> and Digital ...

SYDNEY, Aug. 24, 2026 /PRNewswire/ -- Inspira Enterprise, a global leader in cybersecurity, AI and digital transformation services, today announced its strategic expansion into Australia, reinforcing its commitment to helping organizations strengthen cyber resilience, secure AI adoption, and modernize enterprise security operations across the Asia-Pacific region. With a growing demand for cyber resilience, identity security, AI governance, cloud security, and managed detection and response (MDR), Australia represents a significant milestone in Inspira's global growth journey. The expansion will enable Australian enterprises and government organizations to leverage Inspira's deep expertise in delivering outcome-driven cybersecurity services backed by AI-powered innovation. "Australia is one of the world's most digitally advanced economies, with organizations accelerating AI adoption while navigating an increasingly sophisticated cyber threat landscape," said Josef Figueroa, President – ASEAN, Inspira Enterprise. "Our expansion reflects our long-term commitment to the region. We are bringing together global expertise, local talent, strategic technology partnerships, and AI-powered security capabilities to help Australian organizations build resilient, secure, and future-ready digital enterprises." "Our vision has always been to help organizations stay ahead of evolving cyber risks through innovation, intelligence, and trusted partnerships," said Chetan Jain, Co-founder & Managing Director, Inspira Enterprise. "Australia is a strategic market for us, and this expansion strengthens our ability to serve customers with local expertise backed by our global delivery capabilities and 24x7 Cyber Fusion Centers." The Australian expansion further strengthens Inspira's presence across North America, Middle East & Africa, ASEAN and India, enabling customers to access globally consistent cybersecurity services while benefiting from local engagement and regional expertise. Inspira will be formally launching their operations via a hosted client event at the University of Technology in Sydney on the 26th of August, 2026. If you would like an invite, please email : [email protected] About Inspira Enterprise Inspira Enterprise is a global

South Dakota's <b>Cybersecurity</b> Program Is Running Out Of Time, Money As Local ...

Pennington County residents haven’t been able to access some services since a cyberattack knocked out county computer systems in July. The water system in Rapid City, which is part of Pennington County, was among the first of dozens of utilities targeted in a nationwide wave of cyberattacks this summer. The attackers did not access its network in Rapid City, city officials said. Mitchell, meanwhile, is recovering from its own breach, which left city staff without computer access. The three incidents — all hitting South Dakota local governments within weeks of each other — underscore a vulnerability that state officials have spent years and millions of dollars trying to address. Local governments hold sensitive taxpayer data, but often lack the staff, budget or expertise to protect it from cyberattacks. A 2025 report by the Multi-State Information Sharing and Analysis Center found that 68% of state, local, tribal and territorial governments lack the budget to address major cybersecurity priorities, and that small and rural communities are especially vulnerable. A state-funded program in South Dakota is working to close that gap — but time and money are running short. STATE FUNDING IN PLACE OF DECLINED FEDERAL FUNDING SecureSD is a $7 million program run by the South Dakota Attorney General’s Office and Dakota State University that delivers cybersecurity tools, training and technical support to local governments. Lawmakers launched the program with funds in 2024 in response to Gov. Kristi Noem rejecting a piece of $1 billion in cybersecurity grants to states. Noem spokesman Ian Fury told South Dakota Searchlight at the time that the grants were “wasteful spending,” adding the administrative burden of the grant “would have far exceeded the allowable administrative cost.” That 2022 four-year federal grant program, part of the 2021 Infrastructure Investment and Jobs Act, faces an uncertain future. Congress

Military sweep finds no banned Chinese apps

Inspections of all 2,936 government-issued cellphones used by the military have been completed, with no high-risk Chinese-made apps found installed, the Ministry of National Defense (MND) said, as the ministry works to implement five cybersecurity measures across the armed forces. When China’s navigation app Amap (高德地圖) was deemed to pose a high cybersecurity risk several months ago, lawmakers asked the ministry to ban servicemembers from downloading the app, to prevent tactical planning and defensive strategies from leaking. In a report, the defense ministry said yesterday that the Ministry of Digital Affairs on May 27 announced its cybersecurity assessment results on four apps made in China, including Amap. The MND had already on April 24 and May 29 notified servicemembers that installing Chinese-made apps including Amap is strictly prohibited, and on June 4, ordered all units to inspect all government cellphones, it said. None of the 2,936 phones were found to have the app installed, it said. The ministry said that in accordance with the Regulations Governing the Subsidies for Mobile Phone Numbers and Call Expenses of the Armed Forces (國軍行動通訊門號及通話費補助作業規定) and the Operational Requirements for Civilian Smartphone Control (民用智慧型手機管控作業要求), it protects military information and communication security through five main measures. The measures include setting clear requirements, promoting policy awareness, auditing and inspection, annual checks and clearly defined penalties, it said. The MND said Chinese-made apps such as Amap, TikTok, WeChat, Sina Weibo, Tencent QQ, bilibili, Xiaohongshu (小紅書, known as RedNote in English) and Baidu Netdisk were prohibited to prevent information leaks. The ministry said it raises awareness reminding servicemembers not to install the banned apps. Servicemembers are strictly prohibited from using the phones to record or transmit military information to prevent data leaks or malicious access, it said. The ministry said unit commanders and supervisors and cyberwarfare specialists would conduct

Maya: Customer trust reshapes <b>cybersecurity</b> in digital finance

AS FILIPINOS increasingly rely on apps to move, save, borrow, and manage money, cybersecurity is becoming a more visible part of the financial experience — from the controls customers can use themselves to the systems and policies that keep services running when threats emerge. At the recent BusinessWorld Cybersecurity Summit, Maya executives said this shift is changing how financial institutions approach security, what customers should expect and how regulators need to respond. Maya has put more security controls directly in customers’ hands. Through its in-app features, users can immediately freeze or unfreeze their cards and manage how they are used. Biometric authentication, fraud monitoring, and other safeguards work in the background. Maya credit cards also use dynamic CVVs, adding another layer of protection for online transactions. Maya also works with regulators and law enforcement agencies, including the Bangko Sentral ng Pilipinas (BSP), the Department of Information and Communications Technology (DICT)’s Cybercrime Investigation and Coordinating Center (CICC), the Department of Justice (DOJ), and the Philippine National Police (PNP). For Kristoffer Rada, Maya’s head of corporate affairs, these measures reflect a broader shift in the relationship between cybersecurity and consumer trust. “For us in Maya, cybersecurity is not some back-office product, it’s really part of the product,” Rada said. “As more people depend on digital financial services every day, maintaining trust becomes a responsibility shared by financial institutions, regulators, government and the broader ecosystem. Rada said cybersecurity policy must balance strong safeguards and institutional accountability with the need to respond to rapidly changing technologies and risks. The focus, he said, should go beyond compliance with individual rules. It should also protect customers, keep services running, strengthen accountability and ensure institutions can respond to and recover from cyber incidents. “Technology evolves so fast. The rules that apply this year may no longer be

When a cyberattack becomes a public safety incident

By Angelis Pseftis A cyberattack does not have to knock out 911 to put officers and the public at risk. Phones and radios may still work while computer-aided dispatch (CAD), records, warrant checks, jail systems or digital evidence disappear. At that point, the question for command staff is no longer, “Is this really a cyber incident?” It is, “What must keep working right now, and who has the authority to make that happen?” That is why a serious network disruption belongs in the incident command conversation from the first hour. The chief or sheriff may have to activate manual procedures, move personnel, isolate systems, preserve evidence, request help and brief the public before anyone can say whether the cause is ransomware, equipment failure or a vendor outage. The central mistake is treating the event only as an information technology (IT) recovery job. For a police agency, it is also a problem of keeping essential services running, preserving evidence, supporting a criminal investigation and maintaining public trust. The radio can work while the rest of policing goes dark The FBI received more than 3,600 ransomware complaints in 2025 and identified government facilities among the sectors most affected by the 10 most frequently reported types of ransomware. Those figures are reports, not a census. The FBI also cautions that its loss total generally excludes downtime, lost files and equipment, recovery work by outside vendors and incidents reported only to field offices. For police leaders, those uncounted operational costs are often the part that matters most. Curry County, Oregon, shows the difference. An official account from the Cybersecurity and Infrastructure Security Agency (CISA) says that during the county’s 2023 ransomware attack, the 911 center could still take calls and communicate by radio, but CAD, warrant and license-plate queries, jail records, juvenile records and

South Dakota's <b>cybersecurity</b> program is running out of time, money as local governments ...

South Dakota’s cybersecurity program is running out of time, money as local governments face attacks (Getty Images) Pennington County residents haven’t been able to access some services since a cyberattack knocked out county computer systems in July. The water system in Rapid City, which is part of Pennington County, was among the first of dozens of utilities targeted in a nationwide wave of cyberattacks this summer. The attackers did not access its network in Rapid City, city officials said. Mitchell, meanwhile, is recovering from its own breach, which left city staff without computer access. The three incidents — all hitting South Dakota local governments within weeks of each other — underscore a vulnerability that state officials have spent years and millions of dollars trying to address. Local governments hold sensitive taxpayer data, but often lack the staff, budget or expertise to protect it from cyberattacks. A 2025 report by the Multi-State Information Sharing and Analysis Center found that 68% of state, local, tribal and territorial governments lack the budget to address major cybersecurity priorities, and that small and rural communities are especially vulnerable. A state-funded program in South Dakota is working to close that gap — but time and money are running short. State funding in place of declined federal funding SecureSD is a $7 million program run by the South Dakota Attorney General’s Office and Dakota State University that delivers cybersecurity tools, training and technical support to local governments. Lawmakers launched the program with funds in 2024 in response to Gov. Kristi Noem rejecting a piece of $1 billion in cybersecurity grants to states. Noem spokesman Ian Fury told South Dakota Searchlight at the time that the grants were “wasteful spending,” adding the administrative burden of the grant “would have far exceeded the allowable administrative cost.” That 2022 four-year

Govt to promote AI application in <b>cybersecurity</b> defense: Sun Dong

Secretary for Innovation, Technology and Industry Sun Dong stated that the government will continue to strengthen artificial intelligence policies and promote the application of AI to build a solid cybersecurity defense system against the risks brought by the technology. Speaking at the finals of the AI x Cybersecurity Challenge, Sun noted that while the technology introduces new threats to society, it also enhances defense capabilities. He added that the government is continuously reinforcing AI-related policies, guidelines and ethical frameworks, including conducting regular cyber defense drills to guide the responsible use of AI and strengthen Hong Kong's resilience against cyber attacks. Meanwhile, Sun said that the competition, whose finals featured 40 local and overseas teams, serves as a cross-regional platform for professional exchange, adding that cyber threats require global cooperation. Wang Jiang, director-general of the Chinese Academy of Cyberspace Studies and a joint organizer of the event, said he hopes the contest will discover cybersecurity talent and showcase innovative tech achievements. Wang pointed out that frontier AI models are now able to execute cyber attacks autonomously, demonstrating a double-edged sword effect. While AI lowers the threshold for attacks and increases their scale, Wang noted it also offers new defense solutions through proactive perception, dynamic protection and intelligent tracing.

Specialized <b>cybersecurity</b> personnel to receive up to 300% salary allowance

The Government has recently issued Decree No. 329/2026/NĐ-CP, providing detailed regulations on cybersecurity protection forces. A highlight of the decree is the introduction of preferential policies and talent attraction schemes aimed at specialized personnel in the field. Under the decree, the specialized cybersecurity force is defined as the "core force," stationed within the Ministry of Public Security and the Ministry of National Defense in accordance with the Law on Cybersecurity and other relevant legal frameworks. Their primary responsibilities include advising on policies and legislation regarding cybersecurity, data security, personal data protection, and strategic technology projects. They are also tasked with the state management of cybersecurity, data security, and personal data protection as prescribed by law. Personnel on the permanent payroll of these specialized units, or those recruited under talent attraction programs, will receive additional monthly support in addition to their standard salary, allowances, and other statutory benefits. The support is categorized into three levels: Level 1, an additional allowance of up to 100% of the current base salary for those performing professional and technical duties within the specialized cybersecurity force. Level 2, an allowance of up to 200% of the current base salary for individuals directly involved in strategic consulting for cybersecurity or strategic technology projects. This level also applies to those performing tasks requiring highly specialized expertise or those organizing training and coaching for cybersecurity protection. Level 3, an allowance of up to 300% of the current base salary for personnel directly researching, developing, or mastering strategic technologies and products, or new technologies that directly impact national security. This highest tier also covers individuals developing breakthrough technological solutions, models, or strategic projects; those performing tasks with exceptional secrecy requirements or extreme intensity; and those managing 24/7 emergency responses or duties with a significant impact on national security and social

OpenAI Just Unveiled a Powerful New Cyber AI, But You Probably Can't Use It

OpenAI Just Unveiled a Powerful New Cyber AI, But You Probably Can’t Use It OpenAI has introduced a new AI system called GPT-5.6 Cyber, designed specifically for cybersecurity work such as vulnerability research, penetration testing, incident response, and remediation. Most people will not get direct access to it. Instead, OpenAI is limiting GPT-5.6 Cyber to a carefully selected group of cybersecurity companies, consultancies, and managed security providers. The model will be used inside existing security products and professional services rather than being released as another tool that anyone can open and start using. OpenAI Is Keeping GPT-5.6 Cyber Away From Regular Users GPT-5.6 Cyber is designed to help security teams find vulnerabilities, determine whether those vulnerabilities can actually be exploited, identify affected systems, and help develop fixes. That makes the technology useful for defenders, but it also creates an obvious problem. The same capabilities that help a security team investigate weaknesses could potentially be misused if powerful cyber models were made freely available without restrictions. OpenAI appears to be taking a different approach with this release. Instead of handing the underlying models directly to customers, it is working through approved partners that can apply their own expertise, controls, and oversight. Companies including Accenture, IBM, Capgemini, Cognizant, EY, KPMG, PwC, NCC Group, and SpecterOps are among the organizations with access. The rollout also includes major cybersecurity vendors such as Palo Alto Networks, CrowdStrike, Cisco, Sophos, Akamai, Fortinet, and Cloudflare. Customers using these services will not receive the underlying model directly. The approved security provider remains responsible for operating the technology within the boundaries of the engagement. Daybreak Blue and Daybreak Red Target Different Security Work OpenAI is offering two versions of its cyber capabilities through a program called Daybreak Access. Daybreak Blue is intended for a broader range of defensive cybersecurity

Speech by SITI at Opening Ceremony of AI x <b>Cybersecurity</b> Challenge Final Round (English ...

Speech by SITI at Opening Ceremony of AI x Cybersecurity Challenge Final Round (English only) (with photo) ****************************************************************************************** å°æ¬çææå 主任 (Director-general of the general office of the Liaison Office of the Central People's Government in the Hong Kong Special Administrative Region (SAR), Mr Li Shuguang), çæ±é¢é· (Director-General of Chinese Academy of Cyberspace Studies, Mr Wang Jiang), çæåå¯ä¸»ä»» (Deputy Director of the Cyberspace Administration of Guangdong Province, Mr Wang Minwei), Daniel (Acting Commissioner for Digital Policy, Mr Daniel Cheung), Rocky (President of Hong Kong Cybersecurity Professional Association, Dr Rocky Cheng), æè (Director and Chief Executive Officer of China Mobile Hong Kong, Ms Shi Xiaoping), Duncan (member of the Legislative Council (Technology and Innovation Constituency) Mr Duncan Chiu), Francis (Commissioner of Critical Infrastructure (Computer-system Security), Mr Francis Chan), distinguished guests, ladies and gentlemen, Good morning everyone. I am delighted to join you all today for the final round of the inaugural "AI x Cybersecurity Challenge". This competition received 290 entries spanning the Chinese Mainland, Hong Kong and overseas. All of them have demonstrated technical excellence and dedication to safeguarding our digital future. May I extend my warmest congratulations to the 40 finalist teams here today, and my gratitude to the Chinese Academy of Cyberspace Studies, the Hong Kong Cybersecurity Professional Association, China Mobile Hong Kong Company Limited, and all co-organisers for joining hands with our Digital Policy Office to build this platform. This has brought together academia, industry professionals and young talents to advance cybersecurity in this AI-driven era. In today's interconnected world, AI is reshaping every aspect of our life at a breathtaking speed. Although innovation may at times bring new threats, these same technologies can also spur our defensive capabilities. This is why we champion an "AI versus AI" strategy, leveraging AI to forge our strongest shields to effectively manage

Managed IT and <b>Cybersecurity</b> Services Expand Across Houston

Texas MSP Brings Enterprise-Grade Managed IT and SMB Cybersecurity to Houston Area Spring, United States – August 22, 2026 / Precise Business Solutions / Precise Business Solutions has expanded its portfolio of fully managed IT, cybersecurity, and cloud migration services to small and mid-sized businesses across Houston and Spring, Texas, bringing locally delivered, enterprise-grade technology support to a market where many organizations have historically relied on remote or overseas providers. The Spring, Texas-based firm now offers a comprehensive suite of services under a single-point-of-contact model, meaning businesses work with one dedicated local partner rather than navigating multiple vendors or offshore support desks. The expansion targets the specific operational and security challenges facing small and mid-sized businesses in the Houston metropolitan area. Addressing a Measurable Gap in Local IT Support Small and mid-sized businesses in Houston have long faced a structural disadvantage when sourcing enterprise-grade IT infrastructure and security tools, as many managed service providers serving this segment route support through overseas call centers or subcontract work to third parties. Precise Business Solutions structured its service delivery to keep all support local, with no overseas outsourcing involved in its operations. The company’s Managed IT Services Houston offering includes proactive network monitoring, help desk support, patch management, and system maintenance. Rather than responding to problems after they surface, the model is designed to identify and resolve technical issues before they interrupt business operations. For small and mid-sized businesses operating with limited internal IT staff, this proactive approach reduces unplanned downtime and helps maintain operational continuity. SMB Cybersecurity Built to Enterprise Standards A central component of the expansion is the company’s SMB Cybersecurity framework, which applies the same protective controls typically associated with larger enterprise environments to smaller business infrastructure. This includes threat detection, endpoint protection, vulnerability assessments, and ongoing security monitoring calibrated

OpenAI urges California to strengthen AI safety...

ABN AMRO beats Q2 expectations, hits ROE target early, and plans high shareholder returns. Dutch bank ABN AMRO reported strong Q2 results, exceeding revenue, cost, and earnings forecasts while achieving its return on equity (ROE) target two years ahead of schedule. The bank expects risk-weighted assets to stay flat through 2028, meaning it...

The <b>Cybersecurity</b> Infrastructure Developing Countries Need

Digital technology is changing how people work, trade, access financial services and interact with governments. Mobile banking, digital payments, cloud platforms and government portals are becoming part of everyday life across developing countries. But as more economic activities move online, cyber risks are also increasing. Criminals target banks, businesses, hospitals, government agencies and individuals. A successful attack can stop services, expose sensitive information and create serious financial losses. For developing countries, the challenge is to expand digital services while ensuring that the systems supporting them remain safe and reliable. Countries need strong cybersecurity infrastructure built into their digital economies from the beginning. The Economic Cost of Weak Cybersecurity Cybersecurity is now an economic issue, not just a technical one. The global average cost of a data breach reached about $4.88 million in 2024, according to IBM research. For a developing country, a major attack against a bank, payment platform or government system can create consequences far beyond repairing computers. If a digital payment system becomes unavailable, businesses may be unable to receive payments, customers may lose access to services and confidence in digital finance may decline. Government systems face similar risks. Tax platforms, national identification systems, healthcare databases and public payment systems contain valuable information. If poorly protected, attackers can exploit them for fraud, disruption or data theft. Cybersecurity should therefore be treated as part of national economic infrastructure, alongside telecommunications and financial systems. Strong protection can help maintain public confidence and reduce the wider economic impact of cyber incidents. Building Security Into Digital Infrastructure Developing countries need to move from reacting to cyberattacks to preparing for them. This means investing in secure digital identities, protected government networks, encryption, multi-factor authentication, continuous monitoring and reliable backup systems. National Computer Emergency Response Teams, commonly known as CERTs or CSIRTs, help countries

U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs

U.S. agencies report cybercriminals used AI-generated code to crack Siemens PLCs What you’ll learn: - Multiple U.S. investigative agencies said cyberattackers used AI-generated code to target Siemens S7 Series PLCs, these in U.S. critical infrastructure. - The multi-agency advisory stated that the as-yet-unidentified attackers are using AI to develop Python exploitation scripts that use the 'snap7.dll' and 'python-snap7' libraries. - The reports follow an episode last fall when vulnerabilities were discovered in the Siemens RuggedCom ROXOS II multiservice platform but not exploited by threat actors, thanks to detection and patching. Far be it for us to toot our own horn, but we'll do so anyway: AI-powered cyberattacks on manufacturing and critical infrastructure are a thing, a very big thing. And we and our contributing writers have been telling you so for more than a minute. The latest news provides more proof. Dennis Scimeca grabbed this for our brands last week, based on advisories reflected at tech and cybersecurity news website BleepingComputer: Siemens manufacturing and critical infrastructure hardware has been coming under assault from cyberattackers, who most notably used AI-generated code to do so. See also: AI is superpowering cyberattacks, but manufacturers can cut their exposure The details: The U.S. National Security Agency, the FBI, the U.S. Department of Energy, the U.S. Environmental Protection Agency, and the U.S. Cybersecurity and Infrastructure Agency all jointly announced that cyberattackers had used or are using AI-generated code to target Siemens S7 Series programmable logic controllers, these specific ones embedded into critical infrastructure. Many of you are “boots-on-the-ground” in OT or IT so you know that PLCs are vitally important plant gear—and those from Siemens are some of the most widely used in manufacturing and other sectors. PLCs are the rugged, reliable brains that monitor inputs from sensors, execute custom user logic, and control physical

If you're not using AI to attack your own systems, your adversaries will

AI agents excel at hacking organizations, as they’ve demonstrated in real-life attacks multiple times over the past few weeks. They also expose a whole new attack surface for organizations trying to protect against both human and AI intrusions. As if defenders needed more worries to keep them up at night, agents introduce new data-integration channels that attackers can abuse. They also introduce a new type – and ever growing number – of non-human identities that are difficult to manage and can bypass traditional, static security policies. “There is tremendous risk associated with agentic AI and machine identities,” Matt Hartman, former acting head of cyber of the US Cybersecurity and Infrastructure Security Agency (CISA), told The Register. “As AI moves from generating content – yesterday's use case – to taking actions, it is inevitable that agents are going to receive access to sensitive systems and sensitive data,” Hartman said. “One area where organizations are struggling today is that they're going to need to treat every agent as a privileged identity.” Enterprises also face agentic threats from outside their organization, he added. “AI-enabled or AI-amplified identity and social engineering attacks are increasing significantly by the minute,” Hartman said. “We're seeing very highly personalized phishing, very good impersonation, automated reconnaissance. That really makes traditional indicators of trust increasingly unreliable.” For defenders, this means a “continued focus on strong identity, on phishing-resistant authentication, on behavioral signals, and on zero-trust principles therein,” he added. “Nothing deeply new here - but it is a whole new attack surface.” Meanwhile, on the attackers’ side, agents don’t take time off, and they remain singularly focused on completing a task, whether that’s finding vulnerabilities and exploit chains or mapping networks and identifying sensitive files. All of this makes these near-autonomous attack bots a gift from the heavens for financially