No-frills tech news

Embry-Riddle Delivers Inaugural <b>Cybersecurity</b> Course in Bahrain

- Date - August 21, 2026 Embry-Riddle Aeronautical University provided a cybersecurity course to aviation and defense professionals at Gulf Air’s Gulf Air Academy (GAA) Training Center in Bahrain, marking the university's first training at the center in the Kingdom of Bahrain. Justin Pettit, a professor at Embry-Riddle Worldwide, led the course titled “Understanding Cybersecurity.” Conducted under a commercial training agreement between Embry-Riddle and Gulf Air, the course was held in February and included 20 professionals from across Bahrain's aviation and defense sectors, including Gulf Air Academy, Gulf Air, Bahrain Royal Flight, Bahrain Civil Aviation Affairs and the Bahrain Defense Force. All 20 participants successfully completed the course. Luis E. Alcaraz, manager of Business Strategies for the Worldwide Campus, said the professional diversity of participants highlights the Kingdom's commitment to strengthening aviation cybersecurity, an area of growing strategic importance. The course's delivery coincided with Embry-Riddle’s centennial year and with Gulf Air's 75th anniversary, providing a meaningful backdrop for a collaboration that honors both institutions' legacies and invests in the future of aviation in the region. Captain Qasim AlBastaki, Chief Operating Officer of Gulf Air and Accountable Manager of Gulf Air Academy, said, “We are proud to collaborate with Embry-Riddle Aeronautical University to deliver specialized cybersecurity training for aviation and defense professionals in Bahrain. As cyber resilience becomes increasingly critical to the safe and secure operation of the aviation sector, this course provides participants with practical knowledge to identify and respond to evolving risks. Gulf Air Academy remains committed to offering high-quality, targeted training programs that support professional capability and strengthen the wider aviation ecosystem.” Recent meetings among senior leaders at both companies affirmed shared training priorities and supported the expansion of the university’s programs in Bahrain. “The collaboration between Embry-Riddle and its partners in Bahrain reflects a shared commitment to

CISA issues guidance for agencies to improve <b>cybersecurity</b> data logging

CISA issues guidance for agencies to improve cybersecurity data logging CISA said agencies will be able to achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response and more. Agencies are getting some help to improve how they log cybersecurity data. A new logging architecture from the Cybersecurity and Infrastructure Security Agency, the Office of Management and Budget and the Chief Information Security Officer Council aims to assist agencies in taking a practical, risk-based, prioritized logging approach that improves agency network monitoring. The guidance, released yesterday, helps agencies implement the changes OMB outlined in a May memo. CISA said agencies will be able to achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response and forensics. Through this guidance, agencies will be able to update their enterprise logging strategies by applying CISA's operational checklists. CISA said it will continually update the guidance as cybersecurity threats and agency capabilities evolve. Add the employees at the Agriculture Department's Rural Development Agency to the growing list of successful feds who have won grievances before an arbitrator after losing their remote work and telework rights. Arbitrator Margaret Donaghy ruled Wednesday in favor of RDA employees represented by the American Federation of State, County and Municipal Employees. The union filed a grievance when USDA ended teleworking and remote work agreements without bargaining in April 2025. Donaghy ordered USDA to restore the telework and remote work arrangements and make the employees whole by paying any travel expenses, compensation or credit for additional hours worked. Suzanne Summerlin, the attorney representing the employees, said this is the fifth arbitration award won by employees in recent months, with similar awards issued at the Department of Housing and Urban Development, Forest Service, IRS and Social Security Administration. The federal civilian hiring freeze has limited

GTA 6 Leaks, The Odyssey Malware, and Water Grid Attacks: This Week in <b>Cybersecurity</b>

Maybe you've heard about this little video game coming out soon called Grand Theft Auto VI. Well, while most people are waiting to get their hands on it, one enterprising group, CyberLeek, claims to have a copy and has been posting images and videos from it, prompting Rockstar Games to file copyright takedowns to stem the flow. The group is also asking folks to buy their memecoin, supposedly to fight anti-consumerism in games, while critics note they probably hacked a dev build and just want a payout. Depending on how this plays out, we might be watching the birth of another hacking group. Speaking of hacks, the FBI is warning infrastructure companies that hackers targeting water systems across the United States are likely using AI to streamline their operations. So if you’ve been wondering when AI is going to make security nightmares in the real world worse, guess what: It’s already happening. In other news, we covered a report from researchers at Incogni that examines the privacy policies and data retention practices of 13 major AI companies and the chatbots they offer. From names like ChatGPT and Gemini to Meta AI, Perplexity, and even Grok, the report identifies which chatbots are the most privacy-friendly and transparent in their practices and which are the worst offenders. We also checked out a privacy-focused AI tool that reveals where popular chatbots get your data in the first place. It's worth trying out yourself. Finally, if you’ve ever wondered what retailers, both online and brick-and-mortar, do with your personal data once you give it to them to make a purchase, we looked into it. You have to hand over some information to make a purchase, of course, but to some of those companies, the data they get from you is way more valuable than

A surprising source is helping uncover compromised government websites

Federal agencies work hard to secure their online presence, but some website compromises are being uncovered through an unlikely source. We'll dig into what those discoveries reveal about the challenge of keeping track of sprawling government web infrastructure. Interview transcript Eric White So with an emphasis on NSFW, this is a vulnerability pertaining to .edu and .gov domains that you seem to have discovered that there’s a little bit of it was something that wasn’t necessarily they had on their radar, but it seems as if OnlyFans takedowns are helping .gov and .edu domains protect themselves a little more. Why don’t we just start from the beginning on what exactly you were looking for and how you found out about this? Greg Pollock Sure, I was conducting a kind of routine investigation of a website that had other indicators of compromise. And as part of that process, I go to Google, I just search across that site to see what’s going on with this thing. At the bottom of that page, at the bottom the search results, I see a little notice that I had never seen before, which said some results have been omitted because of DMCA notices against the content. So I click through and there I see a DMCA takedown notice from clearly an adult content creator, sent to mostly adult content piracy sites, but also this government domain that I was looking at. I thought, well, that’s pretty weird. What’s going on there? And so pulling on that thread led me to discover how this is happening across lots of domains and how those DMCA copyright notices can be a pretty effective way to look for domains that are somehow advertising search results they don’t mean to. Eric White And when you say they are advertising,

CrowdStrike mobilizes <b>cybersecurity</b> coalition to defend SMBs

CrowdStrike is expanding the reach of its Project QuiltWorks cyberdefense alliance. Just four months after launching the initiative for large enterprises, the cybersecurity vendor wants to reach small and midsized businesses through distributors, managed service providers and other channel firms. Project QuiltWorks’s launch partners included Accenture, EY, IBM, Kroll and OpenAI. The aim was to integrate CrowdStrike’s AI-driven vulnerability discovery capabilities with systems integration expertise and input from LLM labs OpenAI and Anthropic to deploy enterprise-grade protection. In early August, the company corralled Arrow Electronics, Pax8, TD Synnex and several other channel firms to mobilize the midmarket push. The move comes amid a wave of interest in SMB opportunities. Earlier this year, Accenture rolled out a business unit focused on midmarket organizations to compete with smaller MSPs. CrowdStrike and other large security vendors have tailored cyber management platforms for smaller enterprises, leaning on partners to reach customers they can’t efficiently serve on their own. For CrowdStrike, the calculation comes down largely to reaching more organizations and capitalizing on the specialized services its partners provide. “The core of what we’re trying to unlock here is scale,” Dan Danielli, CrowdStrike VP of scale partnerships, told Channel Dive. “We can’t be in every single conversation in every corner of the globe.” Partners have rapport and opportunities with SMBs that CrowdStrike wants to tap as those organizations adopt AI. “What we also understood was that we needed to put the partner at the forefront of the conversation because they were having multiple touchpoints with customers that oftentimes went way beyond security,” Danielli said. Platform support CrowdStrike’s Falcon platform provides the common technology layer underneath QuiltWorks. The cloud-native security platform covers endpoints and cloud workloads, identity and data. Within QuiltWorks, partners use Falcon and their own services to assess customers’ security posture, identify and prioritize

<b>Cybersecurity</b> Data Sharing Faces Liability Deadline

If not renewed, CISA 2015 protections end in the US on September 30. This article appears in the September issue of Global Finance Magazine. Companies that share cybersecurity information with their peers have until Sept. 30, 2026, before the limited liability granted by the Cybersecurity Information Sharing Act of 2015 runs out, exposing them to potential regulatory scrutiny and penalties. Under the Act, non-federal entities may share anonymized cyberattack and response information with other non-federal entities and the federal government via the Automated Indicator Sharing (AIS) program operated by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA). In July, 23 industry associations that represented the financial services, energy, technology, transportation, healthcare, and retail sectors wrote to Speaker of the House Michael Johnson (R-LA) requesting an extension to the Act since it is “a foundational component of the nation’s cybersecurity.” However, some view AIS as a relic of an earlier era of cyberdefense that provides machine-readable cyber threat indicators and defensive measures against malicious IP addresses, file hashes associated with malware distribution, and known malicious web links. “It was a failure from the get-go, and it accomplishes nothing,” Milton Mueller, a professor of cybersecurity policy at Georgia Institute of Technology’s Jimmy and Rosalynn Carter School of Public Policy, told Global Finance. “No one will notice when it’s gone.” A web post by Mueller earlier this year cited a DHS Office of Inspector General (OIG) report stating that non-federal participants using AIS fell to fewer than 90 in 2024 from a high of 304 in late 2022. The report also noted that alert volume on the platform dropped 93% between 2020 and 2022. Though there was a surge in alerts, to 10 million from 1 million, the OIG found that 89% of the data came from a single

Wazuh and AI For Enhanced SOC Workflows

Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cybersecurity has experienced a similar transformation. While attackers employ AI to automate cyberattacks and accelerate vulnerability discovery, defenders are adopting AI to improve threat detection and enhance incident response. Security Operations Centers (SOCs) receive a high volume of alerts from endpoints, cloud workloads, network devices, identity providers, and business applications. Although SIEM and XDR platforms provide visibility into these environments, analysts often spend considerable time correlating alerts, searching documentation, and determining the next investigative steps. AI offers a practical way to augment analysts by providing contextual explanations, summarizing findings, and recommending remediation actions, rather than replacing human expertise. Challenges facing modern SOCs Modern SOCs are expected to detect and respond to sophisticated threats while processing millions of security events every day. High alert volumes contribute to analyst fatigue and increase the likelihood that critical events are overlooked. Investigations frequently require switching between dashboards, documentation, vulnerability databases, and threat intelligence feeds before a complete picture emerges. As infrastructures become increasingly distributed across on-premises and cloud environments, maintaining consistent situational awareness becomes more difficult. AI-assisted workflows help address these challenges by reducing repetitive analysis, adding context, and accelerating investigative decision-making. Wazuh and artificial intelligence for enhanced SOC workflows Wazuh promotes flexible AI adoption through the Wazuh AI Analyst available on the Wazuh Cloud and integrations with third-party AI providers. Organizations can leverage the Wazuh AI Analyst capability on the Wazuh Cloud for guidance on their environment's security posture. Organizations that self-deploy Wazuh can also leverage Wazuh integrations with AI providers. The following sections highlight further details: The Wazuh AI Analyst The Wazuh AI Analyst

Palo Alto Networks, NTT Data ink $1B <b>cybersecurity</b> pact | Channel Dive

Dive Brief: - Palo Alto Networks and NTT Data strengthened an existing partnership with a strategic pact that aims to generate $1 billion in business over the next three years, the two companies said Tuesday. The strategic alliance spans enterprise security operations center modernization, AI governance, cloud resilience, firewall improvements and zero-trust architecture, per the announcement. - NTT Data will bring more than 2,000 Palo Alto Networks certified professionals and a network of more than 20 cyber defense centers to the joint effort. Palo Alto Networks’ Unit 42 threat intelligence team and an unspecified number of the forward deployed engineers will work alongside the global systems integrator to deliver managed security services, according to the announcement. - The alliance is Palo Alto Networks’ largest with a GSI to date, Simone Gammeri, chief partnerships officer at Palo Alto Networks, said in an email. “By aligning joint engineering investments, operational delivery and early product access, the agreement transforms a standard vendor-integrator dynamic into a co-led growth engine designed to secure complex global enterprises.” Dive Insight: Palo Alto Networks remains intent on growing its formidable channel presence. The company refreshed its partner program in February with a focus on simplifying deal processes, boosting development funding and incentivizing outcomes as well as sales. The strategic alliance is in Palo Alto Networks’ enterprise wheelhouse, which is large organizations that retain GSIs to manage big-budget modernization projects. Accenture, Cognizant, Deloitte and HCLTech are among the company’s other major GSI partners. Palo Alto Networks’ broader strategy includes a significant midmarket expansion to deploy its security platform and products to small and midsize businesses. SMBs have been on the company’s agenda for the last year. “Palo Alto Network smells upmarket because, historically, that's where we have been operating,” Gammeri told Channel Dive in March, just seven months after

What every OHIO employee should know about <b>cybersecurity</b>

Image Ben Wirtz Siegel Cybersecurity isn’t just an IT issue; it’s a shared responsibility for everyone at Ohio University. Every day, employees handle sensitive information, use multiple systems, and make quick decisions that can either protect or expose university data. From creating strong passwords to recognizing suspicious emails, small actions make a big difference. The Information Security Office (ISO) is here to help you understand risks, use technology safely and know what to do when something doesn’t feel right. To learn more and get started with Information Security at OHIO, check out these Top 10 Cybersecurity Basics and become informed about how to report an information security incident.

2026 <b>Cybersecurity</b> Awareness Month Speaker Lineup

Living Security Announces 2026 Cybersecurity Awareness Month Speaker Lineup Focused on Trust in an AI World Thursday, 20 August 2026 01:30 PM Company Update Five cybersecurity experts join Living Security's turnkey Cybersecurity Awareness Month program to help employees navigate AI-driven deception, digital trust, and human risk AUSTIN, TX / ACCESS Newswire / August 20, 2026 / Living Security, the global leader in Human Risk Management (HRM), today announced the featured speaker lineup for its 2026 Cybersecurity Awareness Month program, bringing together five experts whose careers span cybercrime prosecution, intelligence operations, online safety advocacy, insider threats, and human behavior risk. The speakers are part of Living Security's turnkey Cybersecurity Awareness Month offering, designed to give security awareness teams the expert-led programming, interactive experiences, ready-to-launch campaign content, employee communications, and planning resources needed to run an engaging October campaign. Built around the theme Navigating Trust in an AI World, this year's Cybersecurity Awareness Month program explores one of the defining security challenges of the AI era: how employees can make informed decisions when deepfakes, voice cloning, synthetic content, misinformation, and increasingly sophisticated social engineering make deception easier to create and harder to detect. Employees are being asked to evaluate information, verify identities, and make security decisions in situations where traditional signals of trust may no longer be reliable. The 2026 speaker lineup brings those challenges to life through firsthand experiences with cybercrime, espionage, manipulation, insider threats, digital safety, and the human behaviors that can either increase or reduce organizational risk. "The security challenge facing organizations today isn't simply awareness; it's trust," said Ashley Rose, CEO and Co-Founder of Living Security. "The experts joining this year's program have spent their careers confronting cybercrime, deception, manipulation, insider threats, and online safety challenges. Their experiences bring this year's theme to life and help employees understand

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and capability development using AI-generated scripts disguised as legitimate monitoring tools. That said, the ongoing PLC targeting activity is assessed to be broader in scope than Siemens PLCs. "The actors leverage internet scanning services like Censys and ZoomEye to identify internet-exposed PLCs running outdated software or that are otherwise poorly protected," according to the advisory published by the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Energy (DOE), and Environmental Protection Agency (EPA). Targets of the activity include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities. The agencies did not attribute the attacks to a known threat actor or group. The exploitation of poorly secured PLCs could result in disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, and compliance violations, not to mention have cascading impacts across interconnected systems. The activity has been found to have singled out the following Siemens PLC models - - S7-200 Series (all CPU variants) - S7-300 Series (all CPU variants including 314, 315, 317 models) - S7-400 Series (all CPU variants) - S7-1200 Series (CPU 1211C, 1212C, 1214C, 1215C, 1217C variants) - S7-1500 Series (all CPU variants, including F-series safety controllers) "Threat actors are using AI assistance to generate exploitation scripts using publicly available information on these Siemens S7 Series PLCs for initial access, credential access, denial of service, and other objectives," the agencies said. "If these PLCs are exposed to the internet or insufficiently segmented, then threat actors can exploit various critical and high severity

CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement ...

CISA Releases Foundational, Flexible Guidance to Help Federal Agencies Implement Effective Logging, Visibility and Operational Standards WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture, an outcome-driven guide for federal civilian executive branch (FCEB) agencies to establish logging, visibility and operational standards in an Agency Logging Plan, as required in Office of Management and Budget (OMB) Memorandum M-26-14. Developed in collaboration with OMB and the Chief Information Security Officers (CISO) Council, this guidance implements a practical, risk-based, prioritized logging approach that improves agency network monitoring. In alignment with the objectives of M-26-14, CISA’s Logging Reference Architecture guidance directly helps agencies achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response, and forensics. Agencies will be able to utilize this guidance to update enterprise logging strategies, which will inform an Agency Logging Plan that agencies are required to submit to OMB and CISA by November 18, 2026. The M-26-14 Agency Logging Plan Template, provided by CISA, offers a structured format to streamline planning. “Cyber defense begins with insight. Robust logs provide the critical visibility needed to counter daily threats targeting federal systems. CISA is enhancing agency logging strategies to ensure security teams can rapidly detect and respond to cyber incidents,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “The Logging Reference Architecture guides agencies away from fragmented practices, establishing a mature enterprise capability that maximizes the operational value of their data.” Within the Logging Reference Architecture, CISA provides operational checklists to help federal agencies inform their logging architecture design and organizational strategies, achieve baseline logging fidelity, and ensure logging plans are operationally ready to support necessary security outcomes. The guidance will also inform agency decisions on integrating artificial intelligence (AI) into logging processes in ways that enhance operational value while

Penn State Beaver alumna turns IT degree into <b>cybersecurity</b> career

MONACA, Pa. — For Penn State Beaver alumna Ava-Li Baker, a small campus, big opportunities and real connections with professors helped transform her choice to stay close to home into a rewarding cybersecurity career. Baker, who graduated in 2022 with a degree in information technology, is a cybersecurity analyst for the Naval Nuclear Propulsion Program. The Hopewell Area High School graduate said she wanted to stay close to home, and when she took a tour of the Beaver campus, she liked the more intimate feel of a small campus and knew that “Penn State had a great IT program.” “My experience there was great,” she said, adding that even through the COVID-19 lockdown, she didn’t feel like the pivot to online learning affected her education. “It was interesting to transition to virtual classes, and when we came back, I was still connected to my classmates and remembered people from Zoom classes.” Baker said she was trying to decide between information technology or studying drafting at a technical school. She said her mom always thought she was good with computers, so she decided to go that route. “I like to work with computers and figure out how to do things with computers. What can I do? What can I make? she said. “The degree in information technology appealed to me because it was broad. The world was my oyster. I could do anything with it.” Baker added a minor in security and risk analysis and applied for an information technology internship with the Bettis Atomic Power Laboratory a year in advance because of the clearance process necessary to work there. “I did my internship during the summer of 2021, and then they offered me a chance to return for the next summer in cybersecurity,” she said. “My manager from the previous

AI data giant Alation confirms cyberattack

Days after reporting an incident affecting a number of its customers, enterprise data giant Alation on Thursday confirmed a cyberattack. Alation makes data software that its enterprise customers use to search for files and data using natural language queries. In recent years, the company has expanded into AI, allowing customers to turn large amounts of messy data into usable content. The company says it services more than 500 global companies, including around half of the Fortune 1000 largest companies in the United States. When reached by TechCrunch about the incident, the company said it was investigating. “Alation recently identified an isolated incident involving unauthorized activity in one of its systems,” the company said in a statement provided to TechCrunch by an external representative, Stephen Russell. “We are conducting a thorough investigation of what occurred and we will provide additional information as appropriate.” Alation did not specify the nature of the cyberattack, mention the root cause of the incident, or say how many customers are affected. The company did not say if it had alerted its customers to the incident or what defensive actions, if any, they should take following the intrusion. On Tuesday, Alation reported an unspecified incident that resulted in “degraded availability” for some of its customers. The company said it had resolved the incident within an hour. Much of the company’s systems are hosted on Amazon Web Services. It’s not immediately clear if any data was stolen or exfiltrated during the incident. This is the latest cybersecurity incident in recent weeks to affect a large-scale technology giant, as hackers increasingly target companies that store large amounts of sensitive or proprietary information for their corporate customers. Earlier this month, several companies reported data thefts following a breach at European shipping giant Ceva Logistics. Hackers are also said to be

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-72529 TrueConf Server Missing Authentication for Critical Function Vulnerability - CVE-2026-72530 TrueConf Server Code Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.

Living Security Announces 2026 <b>Cybersecurity</b> Awareness Month Speaker Lineup Focused ...

Living Security Announces 2026 Cybersecurity Awareness Month Speaker Lineup Focused on Trust in an AI World Five cybersecurity experts join Living Security's turnkey Cybersecurity Awareness Month program to help employees navigate AI-driven deception, digital trust, and human risk AUSTIN, Texas, August 20, 2026 (Newswire.com) - Living Security, the global leader in Human Risk Management (HRM), today announced the featured speaker lineup for its 2026 Cybersecurity Awareness Month program, bringing together five experts whose careers span cybercrime prosecution, intelligence operations, online safety advocacy, insider threats, and human behavior risk. The speakers are part of Living Security's turnkey Cybersecurity Awareness Month offering, designed to give security awareness teams the expert-led programming, interactive experiences, ready-to-launch campaign content, employee communications, and planning resources needed to run an engaging October campaign. Built around the theme Navigating Trust in an AI World, this year's Cybersecurity Awareness Month program explores one of the defining security challenges of the AI era: how employees can make informed decisions when deepfakes, voice cloning, synthetic content, misinformation, and increasingly sophisticated social engineering make deception easier to create and harder to detect. Employees are being asked to evaluate information, verify identities, and make security decisions in situations where traditional signals of trust may no longer be reliable. The 2026 speaker lineup brings those challenges to life through firsthand experiences with cybercrime, espionage, manipulation, insider threats, digital safety, and the human behaviors that can either increase or reduce organizational risk. "The security challenge facing organizations today isn't simply awareness; it's trust," said Ashley Rose, CEO and Co-Founder of Living Security. "The experts joining this year's program have spent their careers confronting cybercrime, deception, manipulation, insider threats, and online safety challenges. Their experiences bring this year's theme to life and help employees understand how to build trust, verify information, and make better security decisions."

AI <b>Cybersecurity</b> Risks: Practical Guidance for Leaders | Forvis Mazars US

Frontier artificial intelligence (AI) models, such as Anthropic’s Mythos model family, have drawn attention for their reported ability to find software vulnerabilities, develop exploits, and complete multistep tasks with limited human direction. While the precise extent of those capabilities may be difficult to determine, the direction is apparent: advanced AI can reduce the time and technical skill required to identify and exploit weaknesses. National and international bodies now describe this openly. The European Commission has noted that advanced AI can be misused to identify vulnerabilities, automate attacks, and increase the scale and speed of cyber incidents.1 The National Institute of Standards and Technology (NIST) makes a similar point, framing AI-enabled cyberthreats as a core concern for enterprise risk management.2 The operating conditions for cybersecurity are changing rapidly, placing more pressure on organizations to apply a defense-in-depth strategy. As businesses integrate AI tools into software development, customer service, financial processes, and internal operations, the stakes are high. Some systems retrieve sensitive information, connect to critical business systems, and act through an employee’s or AI agent’s permissions. Organizations also may become dependent on AI models whose availability is controlled by an outside provider or affected by government action.3 Business leaders now face two corresponding questions regarding external and internal risks: - How will AI change threats directed at the organization? - What new exposure will the organization create by embedding AI inside its own operations? Vulnerability Discovery Is Getting Faster AI technology didn’t invent software vulnerabilities or zero-day attacks. Researchers and threat actors have long looked for weaknesses in operating systems, browsers, applications, and infrastructure. What frontier models can escalate is the speed and scale of that work. The European Commission observes that frontier capabilities, once concentrated in a few systems, are becoming more accessible as open-source models improve, including to criminal

<b>Cybersecurity</b> Threat Delays Start of Classes at UT San Antonio

Creative Commons One day before the University of Texas at San Antonio was scheduled to begin its fall semester Wednesday, officials postponed the start by three days after “attempted unauthorized activity against university technology systems” prompted them to shut down many of the university’s digital systems, including some related to email and phone services. The university also pushed back registration and payment deadlines. “We are making this decision to ensure the university systems, technology and services our students, faculty and staff rely upon are operating optimally as we begin the semester. Starting classes on Monday (Aug. 24) gives our teams the necessary time to restore services carefully and position our university community for a strong start,” UT San Antonio President Taylor Eighmy wrote in a statement to the campus community Tuesday. “Out of an abundance of caution, we proactively took systems and services offline to evaluate our technology environment and reinforce safeguards before bringing services back online.” Over the weekend, UT San Antonio detected a potential threat to its systems “at the edge of our network, before it reached core systems and University Technology Solutions,” officials said in an announcement. “Our response has been effective. At this time, our ongoing investigation has found no evidence that university data was accessed or exfiltrated as a result of this activity.” A university spokesperson wrote in an email to Inside Higher Ed that UT San Antonio has identified the source of the attempted unauthorized activity, but didn’t provide further details; they said only that the “university’s investigation remains ongoing in coordination with expert partners” and has no “definitive timeline for completion.” Aside from starting three days late, the semester is expected to carry on as scheduled, with the university “making the necessary academic adjustments within the existing semester calendar,” they wrote. While UT

ReliaQuest Advances Agentic Cyber Defense for Enterprises with Anthropic's Claude

ReliaQuest, the AI cybersecurity company behind GreyMatter, announced expanded AI initiatives with Anthropic, the AI safety company and creator of the Claude family of models, aimed at accelerating the development and deployment of AI for enterprise cyber defense. The collaboration brings Anthropic’s Claude core family of models into the ReliaQuest GreyMatter platform, which is used by some of the world’s largest organizations to detect, investigate, and respond to cyber threats at machine speed. Through the partnership, GreyMatter customers will gain access to advanced AI capabilities designed to strengthen enterprise cyber defenses. ReliaQuest has also joined Anthropic’s Project Glasswing and is using Mythos within its own systems for defensive cybersecurity applications. Through its participation in Project Glasswing, ReliaQuest will gain shared insights into how emerging AI models may be leveraged by threat actors. “We are at a defining moment for cybersecurity,” said ReliaQuest founder and CEO Brian Murphy. “AI is changing what attackers can do. It has to change what defenders can do too. Our work with Anthropic means our customers will have more access to frontier AI models deeply integrated into GreyMatter — so they can move faster and respond with greater confidence than the adversary.” The expanded integration of Claude builds on an existing relationship between the two companies. GreyMatter already uses Claude’s advanced reasoning capabilities for complex security operations tasks, including alert triage, threat investigation, and analysis of sophisticated multi-stage attacks. ReliaQuest was also among an initial group of security vendors recently selected to integrate with Anthropic’s compliance API — enabling authorized Claude activity data to be brought into GreyMatter. This allows enterprise security teams to monitor, detect, and respond to Claude usage in the same manner as other enterprise applications operating within their environments. Claude models have been incorporated into GreyMatter since the platform’s early development. They

Study: DIB Reports Higher <b>Cybersecurity</b> Scores, but Confidence Falls

Defense contractors are reporting their highest cybersecurity compliance scores since tracking began, but confidence in the accuracy of those scores has fallen sharply, according to an annual study conducted by Merrill Research and commissioned by CyberSheath, a cybersecurity compliance services provider. The study, which surveyed 302 defense contractors, found that average Supplier Performance Risk System (SPRS) scores climbed to plus 51 in 2026, up from plus 33 last year. At the same time, just 65% of contractors that submitted an SPRS score said they were extremely or very confident in its accuracy, down from 89% last year and 94% in 2024. SPRS scores measure contractor compliance with National Institute of Standards and Technology (NIST) Special Publication 800-171 security requirements. Those requirements also form the cybersecurity foundation for the Department of Defense’s (DOD) Cybersecurity Maturity Model Certification (CMMC) program. CMMC provides a framework for DOD to verify that defense industrial base (DIB) contractors meet applicable cybersecurity requirements, including through self-assessments and, for some contractors, third-party assessments. According to the report, the latest SPRS results show substantial improvement on paper. The average score had remained negative for three consecutive years, at minus 12 in 2024, minus 15 in 2023, and minus 25 in 2022. SPRS scores can range from minus 203 to a maximum of plus 110. The scores do not represent all respondents, however. Only 67% said they had submitted an SPRS score. The study characterized the disconnect between higher scores and lower confidence as a “central challenge for the DIB,” saying the issue is increasingly about “independently validating whether claimed compliance reflects operational reality.” The report’s findings come as DOD has paused Phase 2 of CMMC, which had been scheduled to take effect on Nov. 10. The department announced a 60-day review of the program on July 13 while keeping