No-frills tech news

Cybersecurity for small to medium-sized businesses

The Defense Industrial Base (DIB) faces constant cyber threats, and small to medium-sized businesses (SMBs) are especially vulnerable due to limited resources. This Wednesday, September 30 at 12PM ET, join us for the free webinar Cybersecurity: Bridging the Gap Between Prime Contractors & SMBs. Samantha Anim of the National Security Agency Cybersecurity Collaboration Center will walk you through the free services the organization offers Department of Defense (DOD) contractors, including passive DNS monitoring, Continuous Autonomous Penetration Testing, attack surface management, and real-time threat intelligence. Speaker Samantha Anim Campaign Manager National Security Agency, Cybersecurity Collaboration Center Samantha Anim is currently the Campaign Manager at the National Security Agency, Cybersecurity Collaboration Center. In this role, she is responsible for increasing partnership participation and enrollment into NSA provided no-cost cybersecurity services for Defense Industrial Base (DIB) companies to help them defend against Nation-state and other cyber actors.

Australia summons OpenAI and Anthropic CEOs to appear at AI inquiry

Australia has called for the CEOs of OpenAI and Anthropic to appear before a Senate inquiry into artificial intelligence, just days after revelations that a rogue OpenAI bot had ⁠hacked the country’s health-system database. “There are serious questions for Sam Altman to answer about the OpenAI hack of Australian government websites,” Hanson-Young’s spokesperson said in a statement on Sunday. OpenAI and Anthropic did not immediately respond to requests for comment outside business hours. The Medicare incursion, condemned by Australian Prime Minister Anthony Albanese, is one of the highest-profile incidents of AI agents accessing external systems outside the United States. Addressing reporters in New York on Wednesday, Albanese said the agent, developed by OpenAI, accessed public and nonpublic data on the government’s Medicare portal in June.

Think You'd Never Fall for a Scam Text? Think Again

The hooks have also been called “pig butchering scams” or “romance baiting scams” or “relationship investment scams” and other names. How the Scam Works The Hook: The scammer sends a text that sounds urgent, polite or highly specific (e.g., "Can you move your car?" This will likely lead to you receiving significantly more spam and scam texts in the future. Here are some of the other scam texts I've seen: "Hello, I found this contact saved under my assistant's old notes, but the name tag was blank. Here are a few that I recommend with short excerpts: PC Magazine — Stop Replying 'Stop': The Danger of Responding to Spam Texts (And How to Block Them for Good): “Tired of spam texts?

This Week's Top Five Stories in Cyber

Cognizant: How the CISO Role Evolves in the Age of AI Agents It is no secret that indeterminate systems like autonomous agents have changed the cybersecurity landscape as we knew it. Able to interpret information, make decisions and take action across connected systems, agents introduce new risks when their context, permissions or behaviour are compromised. His industry experience is long standing, and as Vishal puts it: "Three decades in cybersecurity gives you a particular kind of perspective." How a Rogue OpenAI Agent Hacked Australia's Medicare System In yet another addition to the recurring news cycle of rogue AI incidents, OpenAI agents hacked into Medicare – Australia’s universal healthcare system. Users visiting the site on 19 September 2026 would have seen the message: “Domain Seized By ShinyHunters.”

Cyber security stocks are pumped up on P(doom)

"Expert, reliable, considered, actionable opinion" "Brief with no waffle, to the point and has real insight into the corporate world" "Entertaining and often insightful in a way that’s different to most newsletters"

Mayor’s Message | Watsonville’s cybersecurity best practices

October not only marks the change of seasons but the start of Cybersecurity Awareness Month as well. We continued work on a multi-year cybersecurity grant project, now approaching its final phase. The city participated in a regional tabletop exercise that allowed us to work with neighboring agencies during a mock incident. This strengthens our response strategies both locally and regionally and helps build communication channels for sharing information on emerging threats. Our IT department is passionately invested in best practices surrounding cybersecurity.

UTulsa cybersecurity researcher named national RSAC Security Scholar

For University of Tulsa graduate student Jalen Brown, cybersecurity is more than a field of study. Brown, who earned his bachelor’s degree in cybersecurity from UTulsa in just two and a half years and is now pursuing a master’s degree while conducting digital forensics research, was recently selected as a 2026 RSAC Security Scholar. Within that larger gathering, Security Scholars participate in exclusive networking and professional development opportunities designed specifically for the nation’s most promising cybersecurity students. UTulsa is one of only 38 universities nationwide, and the only university in Oklahoma, invited to participate in the RSAC Security Scholar program. The invitation reflects the national reputation of UTulsa’s School of Cyber Studies and its longstanding leadership in cybersecurity education, research, digital forensics and industry engagement.

Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings

The data breach originated with security failings at American Medical Collection Agency (AMCA), a debt collector that Labcorp worked with. The attorneys general contended that Labcorp should have don’t more to police AMCA, after the incident there impacted a total of 27.5 million people nationwide. Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices. In 2021, a court sided with the coalition of attorneys general suing AMCA and ordered the debt collector pay a $21 million fine that was suspended because the company went bankrupt. “As a result of our investigation, Labcorp will make critical changes to protect patients and prevent this kind of data breach from happening again.”

Businesses expand AI’s cybersecurity uses as comfort with technology grows

Dive Brief: Businesses are getting better at securing their AI systems as they spend more time using the technology, the advisory firm KPMG found in its latest quarterly AI survey. Dive Insight: One of the KPMG report’s key insights is that organizations’ AI maturity levels strongly influence how they use AI in the context of cybersecurity. Among experimenters, 26% use AI only to monitor systems; among established users, the figure is 4%, reflecting organizations’ growing comfort with plugging AI into more security tasks over time. Established AI users were also more likely than experimenters to report spending some of their AI budgets on cybersecurity (71% versus 36%). As businesses see the threat landscape grow more complex, they are racing to update their cybersecurity strategies to account for faster-moving attacks.

Information Networking Institute

Her session, “The Future of AI and Cyber: Landscape, Threats and Opportunities,” will examine current trends in how cybersecurity interacts with AI. We interviewed Dr. Wang to understand her thoughts on the field and what participants can expect from her session. Dr. Wang: AI as a field has progressed very quickly, with innovations coming fast and furious. In the Future of Secure AI executive certificate program this November, you’re going to be leading a session on the future of AI and cyber. When you look at how AI innovation and cybersecurity intertwine, what fascinates you the most and what worries you?

NSF Awards $4.8 Million to URI Cybersecurity Center Under Victor Fay-Wolfe

The University of Rhode Island’s Digital Forensics and Cybersecurity Center, part of the Department of Computer Science and Statistics, has been awarded two NSF grants totaling $4.8 million. The funding will support scholarships for students in the Professional Science Master’s in Cybersecurity program and the new Securing Artificial Intelligence track. The first award, a three-year, $2,891,678 CyberAICorps Scholarship for Service grant, will provide full scholarships, stipends, and government summer internships to two cohorts of graduate students who commit to protecting AI and cybersecurity systems in public service. The award builds on URI’s CyberCorps SFS program, which has placed 93% of its graduates in government cybersecurity jobs since 2021. The second award, a $1,993,716 S-STEM grant called Pathways To A Cybersecurity/AI Career, will offer last-dollar scholarships and mentoring to 30 academically talented, low-income students pursuing the Master of Science in Cybersecurity over five years.

USDA Awards 25 Spots on $1B CPOC Cybersecurity Support BPA

Federal spending data shows ordering periods for most of the awards began Monday, Sept. 21, and run through Sept. 20, 2031. Who Are the USDA Cybersecurity BPA Awardees? The company said ordering contracting officers will determine order types at the call-order level under the General Services Administration’s Multiple Award Schedule special item number for highly adaptive cybersecurity services. Functional Area 3 supports CPOC’s departmentwide operations, covering enterprise cybersecurity engineering and operations, privacy operations, security management, identity, credential and access management, and cyber supply chain risk management. The latest USDA award adds to the department’s earlier investments in cybersecurity support services. In June 2023, Alpha Omega and teaming partner Dynamo Technologies received a five-year, $70 million contract to provide cybersecurity operations support to the Information Security Center, which later became the CPOC.

Mastercard Tackles SME Security Gap with Built In Protection

According to the research, small businesses are evaluating growth through a lens of stability and control rather than speed. The need to embed protection within services The Dreamonomics research identified a gap between cyber risk recognition and deployment of security tools among SMEs. "Small business owners are managing cash flow, serving customers and running day-to-day operations," Mark says. How Mastercard Collection for Business integrates security Mastercard launched the Mastercard Collection for Business to address the adoption gap. Business security features include My Cyber Risk, which provides an assessment of an SME's online exposure and highlights vulnerabilities through a dashboard.

Cybersecurity Stocks Soar Amid Mounting Concern Over AI Hacks

As policymakers debate the case for sweeping new AI guardrails, the world isn’t waiting. It’s making a beeline for the cybersecurity industry’s services. In a note to clients last week, Bank of America analysts called cybersecurity a “mega-theme and enabler of the AI era.” This week, the company unveiled a new “Continuous Frontier AI Defense” that employs a handful of models including Mythos 5 and GPT-5.6-Cyber. Meanwhile, both OpenAI’s Sam Altman and Anthropic’s Dario Amodei urged the United Nations Security Council this week to adopt new AI safety standards.

Expert Urges Water Utilities to Focus on Cybersecurity Basics

Meanwhile, other states have already spent several years strengthening cybersecurity for water and wastewater systems. New Hampshire, for example, worked with the Overwatch Foundation to help secure drinking water systems, while Kansas launched a related cybersecurity assessment program in early 2024. New York, New Jersey and Massachusetts are actively providing grants aimed at improving cybersecurity for community water systems. Kellerman said that public utilities can better defend themselves by elevating cybersecurity leadership and focusing on basic cybersecurity hygiene. The advice closely tracks with ongoing advice from agencies such as the Cybersecurity Infrastructure and Security Agency.

Cybersecurity Certification Programs that cover Cloud Security and Incident Response

As organizations increasingly migrate workloads, applications and data to cloud environments, cybersecurity professionals are expected to understand both cloud security and incident response. ISC2 Certified Cloud Security Professional (CCSP) The Certified Cloud Security Professional (CCSP) is designed specifically around cloud security. For professionals working in cloud security, cloud architecture, information security and governance, CCSP can provide a broad understanding of securing cloud environments. GIAC Cloud Security Essentials (GCLD) The GIAC Cloud Security Essentials (GCLD) focuses on practical cloud defense. GIAC Cloud Forensics Responder (GCFR) Another specialized certification is the GIAC Cloud Forensics Responder (GCFR).

Airties Expands AI-Driven Connectivity Platform with Integrated Cybersecurity

The cybersecurity threat landscape is evolving quickly, driven in part by the growing sophistication of AI-driven attacks. About Airties Airties empowers operators to provide smooth, smart, secure connectivity. Airties turns smart connectivity into a competitive advantage for operators and enhances how subscribers experience connectivity in the real world: making every connection more intelligent, reliable and secure. Airties' AI-driven insights enable operators to lower churn, reduce expenses, boost satisfaction, and attract new customers. Sources: ¹NETGEAR and Bitdefender, 2025 IoT Security Landscape Report; ²F-Secure, Global Consumer Market Survey 2026; ³Hitron, SMB Research, 2026 SOURCE Airties

Protecting Michigan Residents: Mitigating, responding to, and recovering from new threats

As part of National Preparedness Month, MI Environment is putting a spotlight on its work on cyber security and threats to Michigan’s critical infrastructure systems. In our connected world, cyber security and threats to critical infrastructure systems have become leading threats for emergency management and utility operators across the globe. In Michigan, threats and cyber bad-actors have targeted hospitals, distribution systems, and water utilities. EGLE, in collaboration with the Michigan State Police, the Environmental Protection Agency (EPA), Michigan Department of Technology, Management, and Budget (DTMB), and the Critical Infrastructure Security Administration (CISA) offers free cyber security risk assessments for drinking water and wastewater treatment facilities in Michigan. For a more detailed summary of what resources are available to water utilities, visit the Cybersecurity Assessments webpage.

America’s Water Systems Face a Growing Cybersecurity Threat

America’s water systems are increasingly in hackers’ crosshairs. But states also are confronting another common challenge—how to help local water systems that already face limited technical and financial capacity and competing infrastructure needs manage growing cyber risks. Fiscal Risks to Water Systems Cyberattacks on water systems can include ransomware incidents, breaches of customer data, and intrusions into operational technology that can disrupt service, damage infrastructure, or compromise technologies used to operate and monitor water systems. As of 2024, more than 85% of Maryland residents were served by water systems that had completed cybersecurity assessments. Final Thoughts As cyber risks grow and regulatory requirements increase, local water utilities will face growing pressure to invest in cybersecurity measures despite ongoing funding and capacity constraints.