No-frills tech news

This Week's Top Five Stories in Cyber

This Week's Top Five Stories in Cyber How OpenAI Agents Plotted and Breached Hugging Face Weeks after OpenAI’s announcement that its agents breached Hugging Face, two researchers from the company have dissected the incident, revealing significant details of the “unprecedented” attack. Taking the stage at BlackHat USA 2026, were Members of Technical Staff focussed on infrastructure and security, Michael Dalton, and Alignment and Safety Researcher, Eric Wallace, explaining what Michael called a “watershed moment for computer security as an industry.” The duo presented details of an elaborate investigation of over seven billion logs, which took up 3 million GPU hours – which, Fortune estimates, could have cost the company anywhere between US$4m to US$15m in compute. Although the industry learned of the incident in July, the actual trigger dates back months prior. On May 7, OpenAI started a training run for an internal-only model. The models are sandboxed and run in a virtual machine without access to the internet. ServiceNow Unveils Autonomous Cyber Defence Security Vision Building off its Autonomous Security vision, ServiceNow will offer six unified solutions to deliver AI-native cyber defence, expected to be available in December 2026, with a focus on prevention over reaction. The solutions will span cyber-physical security, agentic incident response, cyber risk and compliance, unified exposure management, identity and access security and continuous vulnerability detection. Following 82.8% of organisations reporting AI projects are already underway or planned for release within the next year, governing agents multiplies exposure faster than a human team can handle. But without proper integration of AI tools, insights and automations risk fragmentation, leaving enterprises in no better position than teams without proper agentic AI tools. China-Linked Autonomous Cyberattack on Taiwan Explained In a demonstration of what could happen when autonomous AI attacks meet geopolitical volatility, many government websites in Taiwan

White House authorizes private companies to launch 'hack-back' cyberattacks that destroy ...

White House authorizes private companies to launch 'hack-back' cyberattacks that destroy data and systems, targeting foreign cybercrime organizations — vetted organizations can now conduct offensive cyber operations Vetted U.S. firms can now conduct surveillance and destructive cyber operations under federal supervision. President Donald Trump signed a presidential memorandum on August 12 establishing the first U.S. program that lets vetted private companies conduct offensive cyber operations, including attacks that destroy data and systems, against foreign cybercrime organizations. Participating firms must post at least $1 million in escrow, forfeited if they break the program's rules, and every operation requires written approval from officials of the Department of Justice and the Department of Homeland Security. Just a few months ago, the administration publicly ruled out this very policy. In March, Thomas Lind, then a senior adviser at the Office of the National Cyber Director, told a conference the administration had no plans to authorize private offensive operations. "We're not interested in fighting pirates with pirates," Lind said. National Cyber Director Sean Cairncross said the same week that companies running offensive campaigns weren't what the administration meant when it asked industry for more help. The memorandum authorizes two categories of activity: "Cyber Surveillance Operations," meaning unauthorized access to foreign systems to collect intelligence while staying undetected, and "Cyber Effects Operations," meaning the disruption or destruction of systems and the data on them. A National Coordination Center manages the program, implementation guidance is due within 60 days, and eligibility rules will admit both large firms and smaller companies suited to specialized tasks. Any company that unintentionally hits a U.S. person or a system on U.S. soil must halt operations and notify the government immediately. A foreign group qualifies as a target under the memo unless "clear intelligence exists" establishing it's institutionally part of a foreign

Receive a warning from Facebook about your account? It's likely a scam

That warning that your Facebook account is about to be deleted is most likely a scam. Cybersecurity experts say scammers are sending fake account suspension notices through email and Facebook Messenger in hopes that users will panic and click. They will often claim your account violated rules and urge you to “appeal” or “verify” your account. RELATED STORY | FTC reports social media scams caused more than $90 million in losses in 2025 The links they provide lead to login pages that are designed to steal your password and access your account. Facebook urges users that if they see something on Facebook that they think is a scam, to not respond and to instead report it. They say you should follow three simple rules to protect yourself from being scammed: Slow down: Scammers will often try to make you panic by creating a sense of urgency. Take time to ask questions and think it through. Spot check: Does what they're telling you make sense? Do your research and double-check the details before clicking links or downloading files. Don't Send: No reputable organization will demand payment on the spot. RELATED STORY | New consumer alert warns about scams targeting previously defrauded individuals For additional tips on how to keep your Facebook page safe and secure, click here.

Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner

A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to authenticate to the built-in remote desktop feature service without valid credentials. The updates released by Apple improve state management mechanisms to enforce correct credential validation and prevent unauthorized authentication attempts. The shortcoming was addressed as part of an emergency update in macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, and macOS Sonoma 14.8.9 earlier this month. "An authentication issue was addressed with improved state management," Apple said in an advisory released on August 6, 2026. It credited security researcher Alfredo Pesoli of Bynario for discovering and reporting the issue. In an update to its advisory, the NCSC-NL said it has received a report indicating active abuse of the vulnerability across multiple systems on which port 5900 was accessible from the internet. "In all these cases, root had gained access to the affected system and placed a Monero crypto miner," the agency added. There are currently no details on when these attacks were observed, the scale of such efforts, if the flaw was exploited as a zero-day, and if it goes beyond cryptocurrency mining. Calif, which published additional information about the flaw, said it's part of a series of bugs in the Screen Sharing Server component that were patched by Apple with macOS Tahoe 26.6 shipped late last month - - CVE-2026-43779 (CVSS score: 9.8) - A logic issue that could allow an app to intercept network connections intended for another process - CVE-2026-43777 (CVSS score: 7.5) - An unspecified issue that could a remote

Red Teaming in <b>Cybersecurity</b>: How It Works, Types, and Tools | CloudSEK

🚀 Introducing the CloudSEK MCP Server! Read more Red teaming is a form of ethical hacking in which security professionals emulate the tactics, techniques, and procedures (TTPs) of real attackers to test an organization's defenses. The exercise is authorized, scoped, and nondestructive: red teamers carry written permission and avoid real harm to systems or users. Attack speed makes that test urgent: IBM's X-Force Threat Intelligence Index found the time to execute a ransomware attack fell 94%, from 68 days in 2019 to under four days in 2023. Red teaming measures detection and response across people, processes, and technology, rather than the presence of vulnerabilities alone. This guide explains what red teaming is, how an engagement works, the types and tools involved, how red teams differ from blue and purple teams and from penetration testing, the frameworks behind the work, and the rise of AI red teaming. A red team engagement runs through six phases, from scoping to the final readout. The red team and the organization agree on objectives, targets, and rules of engagement. This phase sets what is in scope, what is off-limits, and the goal the team works toward, such as access to a specific system or dataset. The team gathers open-source intelligence and probes the attack surface to map people, technology, and exposed assets. Reconnaissance shapes the attack plan and identifies the likeliest entry points. The team gains a foothold through a phishing lure, an exposed credential, or an exploitable vulnerability. Initial access turns external reconnaissance into a position inside the environment. From the first foothold, the team moves between systems and escalates privileges toward higher-value targets. This phase mirrors how a real intruder expands access after breaching the perimeter. The team reaches the agreed goal, such as a sensitive dataset, a critical system, or domain-admin control.

Datavault AI will acquire CyberCatch in an all-cash transaction | Portal ERP

Datavault AI Inc., a provider of data monetization, credentialing, digital engagement and real-world asset tokenization technologies, has signed a definitive agreement to acquire 100% of CyberCatch Holdings, a cybersecurity company that provides an AI-enabled platform for continuous compliance and cyber risk mitigation. The transaction is structured as a court-approved plan of arrangement under the Business Corporations Act of British Columbia. Datavault AI will acquire CyberCatch’s approximately 26.8 million issued and outstanding common shares for $94.5 million in cash, or $3.53 per share. Outstanding dilutive securities will be exchanged on a cashless-exercise basis. Subject to board, stock exchange, regulatory and shareholder approvals, CyberCatch will operate as a subsidiary of Datavault AI from San Diego, California. CyberCatch founder, Chairman and CEO Sai Huda will serve as president of the subsidiary and report to Datavault AI CEO Nathaniel T. Bradley. Cybersecurity and compliance platform CyberCatch’s platform uses generative AI to assess whether required cybersecurity controls are in place and calculate a Cyber Hygiene Score. It also uses agentic AI to simulate threat-actor tactics, techniques and procedures, conduct penetration tests and calculate a Cyber Breach Score. The platform assesses cybersecurity controls from outside-in, inside-out and social engineering perspectives, with mappings to frameworks including NIST CSF 2.0, NIST 800-171, CMMC 2.0, ISO 27001, HIPAA and PCI DSS. Its agentic AI system consists of specialized agents assigned to tasks such as reconnaissance, vulnerability detection, selection of attacker tactics, vulnerability exploitation, evidence gathering, reporting and risk mitigation recommendations. The platform also provides dashboard reporting covering cybersecurity control failures and compliance status across frameworks including NIST CSF 2.0, NIST 800-171, CMMC, HIPAA, CAN/DGC 104 and EU NIS. Acquisition expands Datavault AI platform Following the closing of the transaction, Datavault AI expects CyberCatch’s software-as-a-service platform to operate as a cybersecurity and continuous-compliance layer across its existing technology portfolio. The

Kharon at the Financial Crime and <b>Cybersecurity</b> Forum 2026

About this event Kharon is exhibiting in the Innovation Showcase at the Financial Crime and Cybersecurity Forum hosted by Datos Insights. This year's AML track asks how programs keep pace — with geopolitics, with crypto, with real-time rails, and with the expectation that effectiveness be proven rather than assumed. Kharon provides the world's most comprehensive data on sanctioned and trade-restricted entities, and their related parties: expert-verified, entity-resolved, and built for programs moving from rules to risk intelligence. Stop by our table to discuss: - Sanctions at the speed of geopolitics: Designations land faster than screening lists absorb them, and the exposure is rarely the designated party itself. Kharon's proprietary tool visualizes beneficial ownership networks and identifies unlisted blocked entities under the OFAC 50 Percent Rule. - When the entity comes back under a new name: Screening against designations alone will always trail a rebrand. Kharon's subject matter experts track the people, addresses, and corporate filings that carry over when the name doesn't. - Financial crime's hidden victims: Treasury designated the Prince Group transnational criminal organization for operating Southeast Asian scam compounds staffed by trafficked workers, and expanded the action in June 2026 with 35 more targets. Kharon identifies the corporate structures behind scam networks like these — when OFAC unmasked the organization's second-in-command, Kharon already had the alias connected.

Safaricom Wins IT Risk Trailblazer Award for <b>Cybersecurity</b> and Risk Management

Safaricom Wins IT Risk Trailblazer Award for Cybersecurity and Risk Management Safaricom also uses security measures such as Hakikisha and biometric authentication on My OneApp to strengthen protection for customers and digital transactions. Safaricom has been named the winner of the IT Risk Trailblazer Corporate Award by the ISACA Kenya Chapter, recognising its approach to governance, cybersecurity, fraud prevention and enterprise risk management across the M-PESA ecosystem and its wider operations. The recognition highlights Safaricom’s continued investment in digital security, including its 24/7 Security Operations Centre, AI-powered threat detection and KingaSphere, the company’s in-house Cyber Threat Intelligence solution. Safaricom also uses security measures such as Hakikisha and biometric authentication on My OneApp to strengthen protection for customers and digital transactions. The company said its security framework is supported by internationally certified standards and board-level governance, as it works to maintain secure and reliable digital services for more than 50 million customers across its markets.

Mission-Driven Security: Inside a Global Bank's Defense

Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Mission-Driven Security: Inside a Global Bank's Defense In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking. In an era where cyber threats evolve at breakneck speed and financial institutions remain prime targets for sophisticated adversaries, the role of the chief information security officer (CISO) has never been more critical — or more complex. Cezary Piekarski, group CISO at global bank Standard Chartered, is helping shape the modern security executive: part technology expert, part business strategist, and part cultural architect. His journey from early tinkering to leading cybersecurity for a global banking institution offers insight into how technical expertise can evolve into strategic leadership. In this interview for Dark Reading's Heard It From a CISO series, Piekarski shares his unwavering belief that successful cybersecurity isn't built on technology alone, but on mission-driven teams united by a shared purpose. In an industry where sleepless nights come with the territory, he's learned to "worry productively" — channeling the anxiety that comes with the job into action that protects clients, colleagues, and the broader financial ecosystem. Through his approach, Piekarski argues that executives who exist in the space between technology and business must be executives who understand commercial trade-offs, technology visionaries who shape strategic direction, and cultural influencers who embed security consciousness throughout their organizations. This is especially the case as artificial intelligence reshapes both defensive capabilities and threat landscapes, obviously. Piekarski sees its rise not as a job-killing disruption but an evolution that demands new skills; and one that likely will draw in more people to cybersecurity. His vision for the future

Crossbow Enterprise <b>Cybersecurity</b> Secures Third Consecutive PCI SSC GEAR Term (2026 ...

Crossbow Enterprise Cybersecurity Secures Third Consecutive PCI SSC GEAR Term (2026-2028), Bringing Nearly 12 Years of Expertise to Global Payment Security BusinessWire India Bengaluru (Karnataka) [India], August 14: Crossbow Enterprise Cybersecurity has been selected to serve on the PCI Security Standards Council's (PCI SSC) 2026-2028 Global Executive Assessor Roundtable (GEAR), marking its third consecutive term on the global payment security forum. Founded in October 2014, Crossbow brings nearly 12 years of experience across cybersecurity consulting, payment security, security assessment, compliance and advisory services. The company works with organizations across India, APAC, the GCC, the UK, Europe and the USA. The PCI SSC Global Executive Assessor Roundtable serves as a direct channel between senior leadership of payment security assessors and PCI SSC senior leadership. Crossbow is one of 33 organizations selected for the 2026-2028 Roundtable. As strategic partners, Roundtable members bring industry, geographical and technical insight to PCI SSC plans and projects on behalf of the assessor community. Strengthening Payment Security Beyond Compliance The growth of digital payments is changing the way organizations approach payment security. Modern payment environments increasingly connect mobile applications, APIs, cloud infrastructure, payment gateways, third-party platforms and customer-facing systems, making payment data protection part of a broader cybersecurity environment. As digital payment models evolve, security controls must advance in tandem by integrating payment protection directly into broader enterprise risk, cybersecurity, and business resilience strategies. Adapting to this shifting landscape demands sustained, active collaboration between standards bodies, assessors, and the organizations tasked with securing modern payment environments. Crossbow's continued role on GEAR enables it to bridge the gap between rapidly evolving payment technologies and global compliance standards, ensuring security frameworks stay practical, resilient, and effective for global enterprises. Gina Gobeyn, Executive Director, PCI Security Standards Council, said: 'The Global Executive Assessor Roundtable brings together experienced industry leaders whose

Trump's move to 'unleash' private sector hackers raises novel oversight, liability questions

The goal is to let private companies take on foreign cyber criminals, but the unprecedented approach raises plenty of questions about oversight and liability. President Donald Trump’s order to “unleash” the private sector to conduct offensive cyber operations against foreign criminal hackers is raising novel questions about government oversight, as well as legal liability and other risks for private companies that enlist in the program. The national security presidential memorandum signed by Trump this week does not enable private sector companies to “hack back” when they face a cyber intrusion. Instead, it establishes a government-run program that will contract with private sector companies and approve any offensive cyber operations conducted by industry participants. The new directive follows the White House’s national cyber strategy, released in March, which says the Trump administration will “unleash the private sector by creating incentives to identify and disrupt adversary networks and scale our national capabilities.” Trump’s memo directs the National Coordination Center to create and manage a program that authorizes companies to take offensive cyber action against “cyber-enabled transnational criminal organizations.” The Department of Homeland Security and the Justice Department will each designate a program executive director to co-lead the program. “Cyber operations shall only be approved after coordination between the program executive directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the federal government pursuant to the federal government’s lawful authorities,” the memo states. Tonya Ugoretz, former assistant director of intelligence at the FBI’s directorate of intelligence, said the directive is “a novel approach to what’s proved to be an intractable problem of cyber-enabled crime that we know affects every U.S. citizen to the tune of billions of dollars per year.” Ugoretz is currently the leader of PwC’s Cyber & Risk Innovation Institute. “These cybercriminal

Cisco security revenue jumps 14% as agentic AI sharpens cyberattacks | <b>Cybersecurity</b> Dive

Dive Brief: - Cisco's security revenue surged last quarter as the technology giant saw growing demand for products designed to protect businesses against emerging cybersecurity threats, including those enabled by artificial intelligence agents, the company reported Wednesday. - The company posted $17.3 billion in total revenue for its fiscal 2026 fourth quarter ended July 25, a year-over-year increase of 18%. Security revenue rose 14% in the quarter to $2.2 billion from a year earlier. - “The rise of agentic AI is expanding the threat landscape, driving demand for our security and observability solutions to help monitor agent behavior and mitigate evolving threats,” CEO Chuck Robbins said during a Wednesday earnings call. Dive Insight: The revenue surge coincides with increasing reports of AI’s role in cyberattacks. IBM's 2026 Cost of a Data Breach study released last month found that one in four malicious attacks are AI-enabled, up 56% from the prior year. Those breaches cost organizations an average of $6 million, according to the research. “These attacks, compromised of mostly deepfake impersonation and AI-enabled malware, are reshaping breach economics,” IBM said in a press release. “Attacks are getting faster and cheaper to launch, while breaches keep getting more expensive to find and fix.” Meanwhile, identity-verification firm Incode estimates that publicly documented AI-enabled fraud grew more than fivefold between 2023 and 2025. “Reported losses across those catalogued cases approach 900 million dollars, and that figure represents only a fraction of the true total,” Veljko Davidovic, a senior strategy and growth manager for Incode’s North America business, said in a Thursday blog post. Robbins said the evolving threat landscape “presents a unique opportunity” for his company. More than 1,500 customers purchased new Cisco security products including Secure Access and Hypershield, while orders for firewalls grew more than 30%. “When it comes to securing

AI 'Breakout' sparks <b>cybersecurity</b> concerns

About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC

Congressional staff visit highlights DSU's role in rural broadband and <b>cybersecurity</b>

MADISON — Fourteen congressional staff members from across the country visited Dakota State University on Aug. 11 to learn how South Dakota has expanded rural broadband and how DSU helps communities use and protect the technology that connectivity makes possible. Staff members representing U.S. House and Senate offices and congressional committees visited as part of a multistate educational tour focused on broadband’s role in rural communities. At DSU, they heard how connectivity supports education, workforce development, government services, healthcare, agriculture, research, and economic opportunity. ADVERTISEMENT Mike Waldner, DSU’s director of SecureSD and Project Boundary Fence, spoke with the group about South Dakota’s broadband development and the University’s involvement throughout that work. “DSU was intertwined in just about every step along the way,” Waldner said. “We’ve done a lot of things with technology on a statewide basis, and they really wanted to hear the South Dakota story — what we have done dating back to 1999 and 2000, and how that work has grown into all of the technology we’re using now.” Waldner said one of South Dakota’s strengths is its ability to bring organizations together around statewide technology projects. That collaboration allows communities to share resources, reduce costs, and maintain systems that continue to produce value decades later. “I think we do an extremely good job of pulling together,” he said. “If we continue to come together and do these statewide projects, we can create economies of scale and make them less expensive for taxpayers across the entire state.” The visit also gave staff members a look at the next stage of that work: protecting the networks, public services, and sensitive information that increasingly depend on broadband. Waldner said he hopes visitors will take South Dakota’s collaborative approach back to the members of Congress and communities they serve. “I hope

Initiative will pay <b>cybersecurity</b> vendors to protect rural water systems | Facilities Dive

LAS VEGAS — A water industry trade group and a collective of volunteer cybersecurity experts are bringing free security services to small water utilities that desperately need help protecting their systems from hackers. The DEF CON Franklin project on Friday announced that it will pay cybersecurity firms to provide their monitoring and protection products for free to water utilities serving fewer than 10,000 people. Those utilities, which account for more than 90% of the 50,000 community water systems in the U.S., are among the most digitally vulnerable, a danger highlighted by recent Iran-linked attacks on water systems across the country. Five managed detection and response (MDR) providers — Defendify, Legato Security, L1 Secure, Rapid7 and Sentinel Technologies — will initially participate in the program, and they will share the threat intelligence they collect from utilities’ networks through a new Water Watch Center run by the National Rural Water Association (NRWA). When MDR software installed on a utility’s network detects a potential cyberattack or vulnerability, the vendor will alert the utility and provide a report on the problem. The utility can then either fix the problem itself or request help from a volunteer expert on Franklin’s roster. “This is all about scale,” DEF CON Franklin organizer Jake Braun said in a Friday interview here on the sidelines of the DEF CON cybersecurity conference, the birthplace of the volunteer group. “Scaling delivery of cyber is where all the challenges fall.” The MDR offering and watch center represent a significant expansion of Franklin’s work supporting the water sector. In late 2024, the group started dispatching volunteers to help participating water utilities implement basic cybersecurity measures, map their networks and write incident-response plans. But Friday’s announcement marks the beginning of an ambitious new era for the group that will see it directly fund commercial

Data Theft Extortion Is Booming! Hooray!

Data Theft Extortion Is Booming! Hooray! Data Theft Extortion Is Booming! Hooray! The cybercriminal ecosystem is increasingly focusing on data theft and extortion rather than locking up victims' files. That criminals have stumbled across a new lucrative business model is a bittersweet win in the fight against disruptive, encrypting ransomware. Data theft extortion isn't great, but it doesn't leave widespread chaos in its wake like ransomware can. Silent Ransom, aka Luna Moth, is one group currently making big bucks from data theft extortion. Last week The Cyber Risk Insurer reported two law firms had paid substantial ransoms to the group this year: Goodwin Procter and WilmerHale, which paid $10 million and $18 million, respectively. Silent Ransom has been targeting law firms since 2023. It historically used phishing and convinced victims to install legitimate remote access software, which was then used to steal sensitive data. In the past year, however, they've brazenly sent people to compromise systems in person by posing as information technology (IT) support staff. Its data exfiltration process prioritizes speed over completeness. Google's Threat Intelligence Group (GTIG) says the groups' entire attack process, from initial target contact to data theft and extortion, is often completed within a single day. With ransom payments in the millions, that works out to a pretty good hourly rate. Another group that emerged in early 2026 was BlackFile, which now calls itself Redact. The group has also targeted similar organizations, but its data exfiltration is more comprehensive. Redact gains initial access using sophisticated high-volume voice phishing attacks (vishing) to steal credentials from victim organizations. It then uses these credentials to steal data from OneDrive and Sharepoint. It also pivots out to other software-as-a-service applications. GTIG says BlackFile spent April and May this year targeting enterprises in the real estate, health care, and insurance

Monitoring the Midterms: Are midterms safe from <b>cybersecurity</b> threats? | PBS News Hour Classroom

SUMMARY CISA, the federal agency tasked with protecting the cybersecurity of the nation’s critical infrastructure, held a conference call with state election officials to discuss the upcoming midterms. Despite President Trump’s claims about the risk of hackers targeting voting systems, this was one of CISA’s first broad outreach efforts just three months ahead of elections. News Hour's Liz Landers reports. View the transcript of the story. NOTE: If you are short on time, watch the video and complete this See, Think, Wonder activity: What did you notice? What did the story make you think? What do you want to learn more about? You can also make a Google doc copy of these general discussion questions. News alternative: Check our recent segments from the News Hour and choose the story you’re most interested in watching. See the Google doc above for discussion questions. WARM-UP QUESTIONS - What is CISA (Cybersecurity and Infrastructure Security Agency), and what role does it take in national elections? - Who met with CISA to discuss midterms? - Why did some participants think that the call came too late? - How might the security of elections come under threat in 2026, according to this segment? - When did CISA lose a third of its workforce? ESSENTIAL QUESTIONS - What do you think might be the biggest threat to election security in 2026? Did this segment change your opinion at all? - Do you think the federal government should have a role in ensuring secure elections? If so, what should that role be? Media literacy: In this segment, anchor Geoff Bennett speaks with reporter Liz Landers about conversations she had had with election officials regarding their call with CISA. Why do you think this segment focuses on this reporting rather than directly interviewing election officials about the call?

AI <b>Cybersecurity</b> Agents For SMBs: From Deployment To Digital Surface

SMBs from all industries are being hammered in today’s threat landscape. While headlines spotlight high-profile cyberattacks and sophisticated hacks, SMBs are the most impacted sector in cybersecurity. They face the same attacks large companies do, including increasing AI threats, but with far fewer resources. In 2025, the Identity Theft Resource Center found that as threat actors embraced AI, more than 80% of small businesses reported a cybercrime. The trend showed no signs of deceleration in 2026. The 2026 Verizon DBIR noted that a shocking 96% of all ransomware attacks hit SMBs. AI allows cybercriminals to reduce exploitation times from months to hours while scaling attacks to record-high levels. SMBs from all sectors are being targeted, including healthcare, agriculture, commerce, mining, logistics, energy, manufacturing, banking and fintech, software development and other industries. While the cyberattack stats may be discouraging for SMB decision-makers, the advances made in agentic cybersecurity technologies can help them turn the trend around and protect their business. In this report, executives, leaders and experts from HackerOne, 0rcus, Moonlock by Mac Paw and EC-Council guide SMBs on what agentic security tools can do, how they can deploy the tech safely and cost-efficiently and how SMBs can secure their digital surface, from front-end to workers' devices. What Can AI Cybersecurity Agents Do Today? As AI accelerates the speed and volume of threats and attacks, agentic security tools are designed to help companies respond. Until recently, these technologies were only accessible to large, well-funded companies. However, today SMBs can access them through big tech platforms and other vendors at competitive prices. There are a wide range of AI cybersecurity tools in the market for SMBs, including SentinelOne Singularity, Microsoft Defender for Business, Google Agentic SOC, GitHub Copilot Security and others developed by Amazon Web Services (AWS), CISCO, Palo Alto Networks and