No-frills tech news

ASU launches new scholarship pipeline to AI-powered <b>cybersecurity</b> careers

Future cybersecurity threats may not look much like past ones. Artificial intelligence is changing how attackers find vulnerabilities, automate attacks and probe digital systems. At the same time, federal agencies, businesses and communities are expanding their use of AI. Related story These factors create a new, urgent question: Who will secure our vulnerable infrastructure and computer security systems? The United States already faces a persistent shortage of skilled cybersecurity professionals, with experts estimating about 500,000 unfilled roles. Now employers need a new kind of professional — one who understands how to use AI to defend digital systems and how adversaries can harness the same technology to attack them. The School of Computing and Augmented Intelligence, part of the Ira A. Fulton Schools of Engineering at Arizona State University, will help train that workforce. ASU is one of 14 universities selected to receive inaugural awards from the U.S. National Science Foundation's CyberAICorps Scholarship for Service, or CyberAI SFS, program. The Fulton Schools’ AI-Augmented Cybersecurity Scholars Program will provide students with scholarship support, advanced education and research opportunities at the intersection of AI and cybersecurity. But there is another crucial component: a pathway to a job. CyberAI SFS is a scholarship-for-service program. Its goal is to prepare graduates for cybersecurity careers supporting U.S. government agencies and other eligible public-sector organizations. The scholarship is designed as a pipeline stretching from university classrooms and research labs to the places where some of the nation’s most consequential cybersecurity work happens. A pipeline with a proven track record In the School of Computing and Augmented Intelligence, that pipeline isn’t being built from scratch. The new program builds on existing NSF Scholarship for Service efforts, led in the school by the ASU Center for Cybersecurity and Trusted Foundations. Across two previous iterations of the program, ASU has

Wyden, Warren Demand FINRA Strengthen <b>Cybersecurity</b> Standards to Prevent ACATS ...

Wyden, Warren Demand FINRA Strengthen Cybersecurity Standards to Prevent ACATS Brokerage Fraud Millions of Americans’ life savings at risk due to a lack of basic online account holder features by leading brokerages Washington, D.C. – U.S. Senators Ron Wyden and Elizabeth Warren today called for the Financial Industry Regulatory Authority (FINRA) to strengthen consumer protections and prevent Automated Customer Account Transfer Service (ACATS) brokerage fraud. ACATS is an automated system managed by the National Securities Clearing Corporation which allows investors to seamlessly transfer their stocks, bonds, and cash from one brokerage firm to another. Designed to keep brokerages from slowing transfers, ACATS' rapid process also gives fraudsters an opportunity to exploit the system's weak security measures before victims can respond. Under current regulations, brokerages have one business day to validate or object to a transfer request and three business days to complete asset transfers. FINRA recommends, but does not require, that brokerages notify customers before they transfer their assets to another company. Most firms rely on a bare-bones electronic verification process and do not verify the transfer with the outgoing account holder. Some do not even notify customers about the transfer of their assets. As a result, the press has reported that fraudsters can open accounts in victims' names and use the ACATS system to drain their investments before they realize what has happened. “It is unacceptable that major brokerage firms are putting customers’ life savings at risk of being ripped off by criminals because of inadequate account protections,” the senators said in their letter to Robert W. Cook, the President and CEO of FINRA. “FINRA must step in to protect consumers.” An analysis conducted by the senators’ offices revealed an inconsistent security landscape, with only a fraction of brokerages voluntarily providing customers with strong protections. While firms like Fidelity

Will AI Replace Detection Roles in <b>Cybersecurity</b>?

Will AI Replace Detection Roles in Cybersecurity? AI agents are already starting to handle the grunt work of detection engineering, or essentially finding malware. If AI is now doing the job, what's the future of this role? Or will it completely vanish? Check out this post from Caleb Sima of Whiterabbit for the discussion that is the basis of our conversation on this week's episode co-hosted David Spark , the producer of CISO Series, and Yaron Levi , CISO, Dolby Laboratories . Joining is Adrian Ludwig , CSO, Rippling . Thanks to our podcast sponsor, ThreatLocker . The messy middle The challenge facing detection engineering teams goes well beyond writing better rules. "The problem isn't just context and predicting what types of possible threats exist, and it's also not just creating detection rules," said Fred Wilmot of Detecteam . "It means we also have to be able to accurately and completely represent what happens to that contextual value." That scope extends well past detection engineering, he said, into "change management, audit, data provenance, and governance." Meny Har of Spectrum Security described the current model as "entirely unsustainable." The sharpest people on security teams are spending 70% of their time in what he calls the "Messy Middle" — "reconciling threat behaviors with log realities and legacy SIEM logic." Compress that time-to-coverage from weeks to minutes, he said, and the game changes. The 2030 team, in his view, isn't a skeleton crew. "It's a full team of senior practitioners who have transitioned from being mechanics to being conductors. They will direct a fleet of agents to handle the 'Messy Middle' of syntax and tuning, giving them the actual bandwidth to tackle that adversary frontier." The automatable part Cutting detection engineers because AI can handle triage misreads the evidence. Mike McCabe of Cloud

New <b>cybersecurity</b> committee follows years of attacks without preventive requirements

At a time when municipal water systems in seven states have suffered cyberattacks, the need to guard against malicious hacking has taken on greater urgency. Mississippi’s hospitals and other institutions have meanwhile been subjected to their own run of attacks, yet for years the state has not required the facilities to defend against them. Against that backdrop, Lt. Gov. Delbert Hosemann has created a Senate Select Committee on Cybersecurity to study the security of state and local government computer systems and review how Mississippi prosecutes cybercrime. Hosemann points to the most severe recent Mississippi case, in February 2026, when a ransomware group that security researchers link to Russia took the University of Mississippi Medical Center offline for more than a week, which resulted in the closure of its clinics, forced doctors to work with pen and paper, and demanded an $800,000 ransom. The FBI and the Department of Homeland Security joined the recovery in that case. UMMC houses the state’s only children’s hospital, its only Level I trauma center and its only organ transplant program. Hosemann said cybercrime costs the state hundreds of millions of dollars. The medical center was the fourth Mississippi hospital system hit in three years. A 2023 ransomware attack on Singing River Health System in Ocean Springs exposed the health information of nearly a million people. North Mississippi Health Services and OCH Regional Medical Center in Starkville were struck the same year. UMMC had been breached before that. A decade ago, it paid $2.75 million in federal fines after the 2013 theft of a laptop exposed about 10,000 patients’ records, and federal investigators found the center had known of the vulnerability since 2005 and left it unaddressed. Through all of this, Mississippi has had no state law requiring hospitals to guard against cyberattacks. Only the federal

CMMC review: DoD's inconsistent CUI marking continues to plague program

While there are differing opinions about how the Pentagon could improve the Cybersecurity Maturity Model Certification program, most organizations agree the Defense Department’s inconsistent and unclear process for marking controlled unclassified information continues to be a critical problem driving CMMC costs and confusion. In comments filed to the CMMC Reform Task Force, multiple industry groups highlighted CUI identification and marking as one of the main cost drivers of the cyber evaluation program. The Pentagon has paused CMMC third-party assessment requirements to address cost and compliance concerns, especially for small businesses. CUI is sensitive government data that doesn’t meet strict criteria for national security classification, but still requires special protection and handling controls under federal laws or policies. CMMC is intended to verify whether contractors are protecting CUI in line with federal cyber standards. But industry organizations say both DoD and prime contractors often improperly mark CUI or apply blanket CMMC requirements across subcontractors, regardless of whether companies will handle CUI. They say that in turn requires companies, including smaller firms, to unnecessarily comply with costlier CMMC standards. The Office of Advocacy, an independent organization within the Small Business Administration, highlighted CUI uncertainty as the “most frequently cited concern” for small businesses when it comes to CMMC. “This uncertainty has downstream consequences,” Advocacy wrote in reply to the CMMC Reform Task Force’s request for information. “When a contractor cannot confidently determine what information is CUI, they will generally err on the side of including all of it into their compliance boundary. Small businesses expressed numerous times that CUI is being overmarked, inconsistently marked, or improperly flowed down through the supply chain.” The office said DoD in some cases has even treated publicly available information as CUI. Likewise, the National Defense Industrial Association said its members have identified “multiple instances where inconsistencies,

AI-backed campaign targeting vulnerable Siemens S7 devices, CISA and FBI warn

U.S. authorities on Wednesday warned of an AI-fueled campaign that attempts to exploit vulnerable Siemens S7 devices across multiple industries, including energy, water, critical manufacturing, agriculture and, potentially, the defense industry. The FBI, the National Security Agency and the Cybersecurity and Infrastructure Security Agency said in an advisory that hackers are conducting reconnaissance and gathering other information about Internet-exposed S7 programmable logic controllers. Many of the targeted devices run out-of-service software or are otherwise vulnerable to attack. As part of the campaign, attackers are using AI-generated exploitation scripts disguised as legitimate monitoring software. They employ AI to generate code to gain initial access, pilfer credentials, and execute denial-of-service and other nefarious actions. Depending on the specific circumstances, exploitation of these tools could lead to the “disruption of critical industrial processes, safety incidents, downtime or equipment damage,” among other impacts, according to the advisory. The hackers are targeting variants of Siemens S7-200, S7-200, S7-400, S7-1200 and S7-1500 Series PLC models. Recent Iran-linked cyber activity The advisory follows a wave of recent cyber threat activity linked to Iran-nexus actors against drinking and wastewater facilities. Authorities in July warned about exploitation of vulnerable PLCs from Rockwell Automation, Schneider Electric and Siemens S7-1200 devices. U.S. authorities suspect that Iran-nexus threat actors are behind a wave of cyberattacks against water systems across at least 12 states. Operators at those sites were cut off from their monitoring equipment and locked out of their own password-protected systems. It is not immediately clear whether the latest PLC attacks came from the same Iran-backed threat groups or if other hackers have begun targeting PLCs as well. Security teams should ensure their current firmware versions are updated to the latest versions and apply security patches as well as check for known vulnerabilities, enable multifactor authentication and confirm that PLCs are

University of Memphis AI, <b>cybersecurity</b> conference focuses on Mid-South's future in tech

University of Memphis AI, cybersecurity conference focuses on Mid-South’s future in tech Published: Aug. 19, 2026 at 3:28 PM CDT|Updated: 10 hours ago MEMPHIS, Tenn. (WMC) - Artificial intelligence is rapidly changing the way businesses and organizations operate and creating new cybersecurity challenges. The University of Memphis is hosting the AI and Cybersecurity Conference 2026 on August 27, bringing together leaders to discuss innovation, security and the future of AI in the Mid-South. Parker King spoke with Dr. William Duffy, director of Applied AI at the University of Memphis on the Digital Desk, about what this conference means for the region. Click here for more information. Click here to sign up for our newsletter! Click here to report a spelling or grammar error. Please include the headline. Copyright 2026 WMC. All rights reserved.

T-Mobile 'chopped a cable' to expel Chinese hackers from its network | TechCrunch

New reporting from Bloomberg revealed how cybersecurity staff at U.S. phone provider T-Mobile identified and expelled Chinese hackers from its network in 2024 during a spate of industry-wide intrusions by Beijing aimed at stealing customer data. The hacks were carried out by a Chinese government-backed hacking group called Salt Typhoon. The campaign compromised hundreds of phone companies, internet giants, and data center providers with the goal of collecting phone records and information about senior U.S. government officials, including then-presidential candidates. Hacked companies included AT&T, Verizon, satellite phone network Viasat, and network infrastructure giants Charter and Windstream. By and large, T-Mobile escaped a widescale breach of its network by catching the activity early — and resorted to physically cutting the cable to a compromised system, per Bloomberg. The publication said T-Mobile’s cyber staff spent months looking for suspected hackers in its network without success. Eventually, the company found unusual behavior on one of its systems coming from another router belonging to a different telecom company, which T-Mobile did not name. After identifying the breach, T-Mobile’s cybersecurity chief, Jeff Simon, told Bloomberg that he and three others drove to the data center nearby to its Bellevue, Washington headquarters, found the compromised system, pulled out a set of scissors, and snipped the cable connecting the box to the outside world. When reached by TechCrunch, T-Mobile did not provide comment.

CrowdStrike Sinks 7% Despite Truist Price Target Raise to $245, Palo Alto Networks Falls 5%

Although the NASDAQ 100 is trading slightly in the green, CrowdStrike (NASDAQ:CRWD | CRWD Price Prediction) stock is down 7% to $198.99 midday Wednesday. The decline comes even after Truist raised its price target on the stock sharply ahead of next week’s earnings. Palo Alto Networks (NASDAQ:PANW) stock is also down 5% to $355.54 in the same session. The selloff pulls in CrowdStrike and Palo Alto Networks on a day with no company-specific catalyst identified. Broad software and technology selling appears to be driving the move, and cybersecurity software is falling with the broader complex rather than acting as an obvious safe haven from AI-hardware rotation. CrowdStrike stock is up 82% year to date through Tuesday’s close. Palo Alto Networks stock is up 103% over the same window. Both names have run hard into a crowded earnings week, and today’s drawdown is happening from elevated multiples that leave little room for disappointment. The Truist note leans into that setup constructively for CrowdStrike, yet the stock is trading as if positioning matters more than fundamentals ahead of earnings. Traders may want to keep an eye on whether the pre-earnings drift extends into next week or resets before the release. Truist Raises Targets but Prefers Smaller Names Truist analyst Junaid Siddiqui raised CrowdStrike’s price target to $245 from $187.50 while keeping a Buy rating. The firm called cybersecurity spending resilient overall and described the CrowdStrike setup as “constructive” heading into earnings. Siddiqui also raised Rubrik’s price target to $135 from $90, and SailPoint’s price target to $23 from $18, both Buy-rated, as part of an off-cycle software earnings preview. Truist named Rubrik and SailPoint its preferred cybersecurity picks, calling both positioned for “beat-and-raise quarters.” The firm’s core thesis is that enterprise cyber budgets are concentrating on identity security, cyber resilience, AI governance,

StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data

Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software working together – some components encrypt files, others silently steal documents or lock the screen, and another acts as a live chat between the attackers and their victims," Check Point Research's Jaromír Hořejší said. The large-scale campaign is being tracked by the cybersecurity company under the moniker StopAndProtect after discovering a ransomware family of the same name in mid-May 2026. The infection chain begins with a ClickFix social engineering attack, resulting in the execution of a PowerShell command that leads to the deployment of additional .NET downloaders and loaders. This subsequently gives way to the main components, including ransomware, SMB/USB worm, LockScreen, VBS spreader, chat utility and credential stealer. That said, it's worth noting that the operation does not always result in ransomware deployment. In most cases, the threat actors have been observed covertly stealing lists of files and then specific files from the systems. The operation is supported by a cluster of hacked WordPress sites that serve multiple functions - - Host malware stages - Run as command-and-control (C2) servers to send instructions - Store logs exfiltrated from victims Check Point said it was able to glean more insights into the campaign due to the threat actor's operational security blunders that exposed detailed infection logs and screenshots from victim machines, as well as the tools used to mass-manage compromised websites. As many as close to 2,000 WordPress sites are estimated to have been hacked as part of the campaign. Most of the sites

Silicon Meets Asphalt: <b>Cybersecurity</b> Project Uses AI to Protect Highways | Newswise

Newswise — The highways Georgia citizens use each day are built on more than concrete, steel, and asphalt. Getting to and from school, work, or shopping now depends on networked systems using optical fiber, sensors, video cameras, and electronic devices known as programmable logic controllers (PLCs) that help process information. As part of the existing Georgia Traffic Management Center (TMC), those systems notify drivers of changing highway conditions, operate traffic management devices, and help the Georgia Department of Transportation (GDOT) identify and respond to traffic issues requiring immediate attention. In December 2025, Georgia Tech cybersecurity researchers began working with GDOT to ensure the security of those networked systems and devices. As part of this advanced cybersecurity project, they are applying machine learning (ML), a type of artificial intelligence (AI), to safeguard existing systems and set the stage for future automation. Read the full article on the Georgia Tech Research Institute news page Original release: https://news.research.gatech.edu/2026/08/19/silicon-meets-asphalt-cybersecurity-project-uses-ai-protect-highways

Seeking Public Comment! Using Artificial Intelligence for <b>Cybersecurity</b> Framework 2.0 ...

NIST announces the release of Special Publication (SP) 1353 ipd (Initial Public Draft), QuickStart Guide for Using Artificial Intelligence (AI) for Cybersecurity Framework (CSF) Analysis and Reporting. This new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes. The document’s purpose is to: While the focus was not to write about AI best practices or to provide cybersecurity guidelines thereof, there are places where specific precautions are denoted with the /!\ notation. This guide includes three notional use cases, examples of prompts for structuring natural language inputs to produce specified CSF 2.0 outputs from a generative AI model, simulated organizational files for a fictitious company, tips for getting started, and more. Use case examples illustrate a possible approach and are not prescriptive assessment or assurance methodologies. Submit Your Comments: The comment period for NIST SP 1353 ipd is open through October 15, 2026, at 11:59 PM. Email comments to: csf [at] nist.gov (csf[at]nist[dot]gov). Note: NIST is only seeking comments on the quick-start guide and supplied AI prompts. NIST is not seeking comment on the fictional organizational documents. Those are for illustrative purposes only. This publication is the most recent within a portfolio of CSF 2.0 quick-start guides released by the CSF 2.0 project team since February 26, 2024. These resources offer tailored pathways for different audiences to engage with the CSF 2.0, making the Framework easier to implement. View all CSF 2.0 quick-start guides here. NIST Cybersecurity and Privacy Program Questions and comments can be directed to: csf [at] nist.gov (csf[at]nist[dot]gov) CSRC Website questions: csrc-inquiry [at] nist.gov (csrc-inquiry[at]nist[dot]gov)

<b>Cybersecurity</b> ETFs to Buy as Top Holdings Deliver Robust Q2 Results

Cybersecurity ETFs to Buy as Top Holdings Deliver Robust Q2 Results This year’s second-quarter earnings cycle has delivered a clear message to investors: cybersecurity is no longer a defensive bet — it's a growth imperative. As enterprises grapple with an unprecedented surge in AI-driven cyber threats, which have jumped 89% from last year, according to CrowdStrike’s 2026 Threat Hunting Report, securing digital infrastructure has become a non-negotiable operational priority. This reality has created a powerful tailwind for industry leaders like Palo Alto NetworksPANW, which has not only surpassed analyst expectations but also demonstrated accelerating momentum. Notably, the Nasdaq CTA Cybersecurity Index has soared 36.5% year to date, outperforming the broader Nasdaq Index’s 13% return over the same period. For investors looking to capitalize on this secular growth trend, the recent market performance could make cybersecurity stocks and the exchange-traded funds (ETFs) that hold them compelling entry points. The following section breaks down the standout financial performances delivered by top cybersecurity players in the second quarter and illustrates how their underlying strength powers broader ETF growth. Q2 Performance Breakdown: Cybersecurity Leaders The recent second-quarter earnings cycle highlighted strong top and bottom-line growth among leading cybersecurity companies, driven by an increasingly challenging AI-enabled threat environment: CrowdStrikeCRWD reported a 26% year-over-year increase in revenues to $1.19 billion for the first quarter of fiscal 2027, while Annual Recurring Revenue (ARR) reached $5.51 billion as of April 30, 2026. Its adjusted earnings per share improved a solid 50.7% year over year, fueled by rapid customer adoption of its AI-powered Falcon platform. It became the only cybersecurity company selected as a launch partner in both Anthropic’s Project Glasswing and OpenAI’s Trusted Access for Cyber (TAC) programs. The stock gained a solid 94.1% during the April-June quarter. Palo Alto Networks posted third-quarter fiscal 2026 revenue growth of

Agentic SOC helps telecom <b>cybersecurity</b> models evolve | EY

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients. How EY can help - Seamless, strategic cybersecurity operations can give you the confidence to focus on innovation and growth. EY Cybersecurity Managed Services can help. Read more - Find out how EY Technology Managed Services can help organizations improve operational efficiency, fuel innovation and build the confidence to transform. Read more AI-enabled cyber attacks are increasing the urgency for telecom organizations to rethink how they detect, investigate and respond to threats. Attackers are using automation and AI to accelerate reconnaissance, identify vulnerabilities and execute attacks in minutes or seconds. As the time between discovery and exploitation shrinks, security teams have less room for manual investigation, fragmented decision-making or delayed response. For telecoms, the challenge is especially acute. Large distributed environments, legacy systems, high volumes of customer and operational data, third-party ecosystems, ongoing M&A activity and nation-state threat exposure all increase operational risk. These factors make telecom environments difficult to secure at speed and scale. They also create significant operational complexity. A single security incident may span enterprise IT, telecom networks, operational technology (OT), cloud platforms, customer-facing systems and third-party networks, requiring security teams to correlate vast amounts of data and make decisions under significant time pressure. The result is a widening gap between the pace of AI-enabled threats and the capacity of traditional security operations centers (SOCs) to respond. Closing that gap requires more than new cybersecurity tools. It requires a clearer view of where the current SOC model is under strain, where automation can reduce risk and where human judgment

How AI is changing <b>cybersecurity</b> jobs

JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser.

UC <b>cybersecurity</b> student battles ransomware at Kroger and U.S. Bank | University of Cincinnati

UC student keeps ransomware raiders at bay Cybersecurity major thrives at Kroger, U.S. Bank co-ops Ethan Bernhardt is a cyber-sleuth at heart. It started in high school with him taking classes in a criminal justice and forensics academy at Colerain High School in Cincinnati. He was interested in digital forensics and had a chance meeting with a ransomware negotiator. These professionals use their technical IT knowledge along with good insight to protect organizations from cybercriminals by minimizing damage, reducing ransom demands, safely recovering encrypted data and stopping the release of stolen information. “I learned more about the cybersecurity side of forensics, which I think is very cool and very important,” says Bernhardt, a fourth-year cybersecurity student in the School of Information Technology at the University of Cincinnati. “It sounds cheesy to say, ‘I want to better the world and make people feel more secure,’ but there are a lot of bad actors out there and it is only gonna get exponentially worse.” Securing private information for individuals and companies is a necessity. And Bernhardt is continuing to sharpen his digital detecting skills with co-op experiences at Kroger Co. and U.S. Bank. He is one of more than 9,600 UC co-op students who gain valuable real-world work experience with partners across industry, government, nonprofit organizations and the university while continuing to make progress toward their degrees. At Kroger, Bernhardt was an information systems auditor intern during three co-op experiences with the company. He gathered data for financial audits, corrected security flaws to protect sensitive files and ensured that network firewalls worked properly. His work involved using automated code to find, format and document user permissions and system logs for mandated audits and also documenting how apps and automated scripts are used in a financial/sox and HIPAA compliant databases to improve security

<b>Cybersecurity</b> Excellence Awards 2026 Announces Dual Recognition for Principal AI ...

San Francisco-Oakland-San Jose, California--(Newsfile Corp. - August 18, 2026) - Harsh Verma, Principal Software Engineer for Artificial Intelligence at Palo Alto Networks, has received two recognitions at the 2026 Cybersecurity Excellence Awards, including AI Security Innovator of the Year, selected by an independent jury of cybersecurity practitioners, analysts, and CISOs and Community Choice Winner in AI cybersecurity based on community influence. The 2026 Cybersecurity Excellence Awards team recently announced Harsh Verma, Principal Software Engineer for AI, at Palo Alto Networks wins dual recognition at the Cybersecurity Excellence Awards, one of the most established global recognition programmes in the cybersecurity industry. Verma was recognised in the AI Security Innovator of the Year category, selected by an independent jury of cybersecurity practitioners, analysts, and CISOs, and was additionally named a 2026 Community Choice Winner in the same category, determined by community voting across a programme that received 79,455 eligible votes during the 2026 awards season. The Cybersecurity Excellence Awards are presented by Cybersecurity Insiders, the trusted platform for CISO insight and strategic research, and are backed by a community of over 600,000 security professionals. The programme has recognised achievement across the cybersecurity community for more than a decade. "We congratulate Harsh Verma for outstanding achievements in the AI Security Innovator of the Year category of the 2026 Cybersecurity Excellence Awards," said Holger Schulze, founder of Cybersecurity Insiders and organiser of the Cybersecurity Excellence Awards. "Selected by an independent jury of cybersecurity practitioners, analysts, and CISOs, this recognition highlights meaningful contributions that strengthen cybersecurity across organisations worldwide." The Work Behind the Recognition Verma's recognition reflects his work at Palo Alto Networks at the intersection of artificial intelligence, cybersecurity, and autonomous agent architectures. His contributions focus on how modern enterprises can evolve toward real-time, self-directed security systems through agentic AI, accelerating the industry's shift