No-frills tech news

Parsons Capture the Flag Competition Brings Global <b>Cybersecurity</b> Teams to Augusta

AUGUSTA, Ga. (WFXG) — Cybersecurity teams from around the world are putting their skills to the test in Augusta this week as Parsons hosts its sixth annual International Collegiate and Military Capture the Flag competition during AFCEA TechNet Augusta 2026. The competition is being held at the Georgia Cyber Center and features 40 teams representing eight countries, including the United States, Japan, India, Peru, France and Italy. Participants are using a customized Parsons platform to work through scenario-based, Jeopardy-style challenges designed to simulate real-world cybersecurity operations. Challenges test skills including network security, coding, digital forensics and identifying vulnerabilities. Tom Barnes, vice president of capture for Parsons' Defense Engineering Services, said the competition gives participants an opportunity to practice cybersecurity tactics in a controlled environment before applying those skills in real-world situations. "That digital cyber front is quickly becoming the battlefield of the future," Barnes said. Barnes said the event also provides an opportunity for military teams from different countries to exchange ideas, improve communication and strengthen their cybersecurity capabilities. The competition includes both military and collegiate participants, with some college teams competing remotely. Teams compete for first-, second- and third-place honors based on their performance. Alyssa Quinones, with Parsons technical operations, said hands-on competitions like the Capture the Flag event allow participants to identify vulnerabilities and practice both defensive and offensive cybersecurity measures. Quinones said developing those skills is increasingly important as technology, artificial intelligence and connected systems become more integrated into everyday life. The event is part of AFCEA TechNet Augusta, which brings military, government, industry and academic leaders to the CSRA to discuss technology and cybersecurity. The Georgia Cyber Center's location in Augusta also provides a natural setting for the competition, with Fort Gordon's Cyber Center of Excellence and Army Cyber located nearby. Parsons is also hosting additional

UTSA delays start of fall classes after attempted <b>cybersecurity</b> hack

UTSA delays start of fall classes after attempted cybersecurity hack SAN ANTONIO — UT San Antonio announced they will be delaying the start of fall classes after an attempted cybersecurity hack. On Tuesday, UTSA said fall classes will begin on Monday, August 24, three days later than originally scheduled. "We are making this decision to ensure the university systems, technology and services our students, faculty and staff rely upon are operating optimally as we begin the semester. Starting classes on Monday gives our teams the necessary time to restore services carefully and position our university community for a strong start." The university said on Monday they responded to attempted unauthorized activity against university technology systems that was identified over the weekend and impacted their academic campus. The breach was detected before before it reached core systems and University Technology Solutions (UTS). For more information on revised schedules and updates, visit UTSA's website.

DOJ charges 17 people in Iran-backed hacking campaign against US | <b>Cybersecurity</b> Dive

The U.S. Department of Justice today announced indictments against 17 members of the Mabna Institute, an Iranian organization alleged to be behind a coordinated cyberattack campaign on behalf of the Islamic Revolutionary Guard Corp. Federal prosecutors said the group allegedly hacked into 144 U.S.-based universities, 42 U.S.-based private sector companies and at least five federal and state agencies, as well as a large number of foreign universities and companies, since 2013. The charges reveal a broader effort behind a “sweeping state-sponsored campaign to steal research and intellectual property from American universities, businesses and government institutions,” Jamie McDonald, U.S. Attorney for the Southern District of New York, said in a statement. Prosecutors allege more than 100,000 accounts of professors were targeted by the alleged hackers, and 8,000 of those accounts were successfully compromised. In all, the attackers stole more than 31TB of academic data and intellectual property from various universities and broke into employee email accounts at universities, private companies and government agencies. The charges are part of a superseding indictment that originated against the Mabna Institute eight years ago. Nine of the 17 defendants were part of a seven-count indictment unsealed in the 2018 case. Iran war rages on The charges come amid an investigation into a coordinated hack of water systems in 12 U.S. states. No charges have been filed in that case, but federal and state investigators linked the incidents to recent cyberattacks targeting industrial devices that monitor water systems. The U.S. has been at war with Iran since launching a bombing campaign with Israel in late February.

UH Maui College receives $660K to enhance AI, <b>cybersecurity</b> education | University of Hawaii News

UH Maui College receives $660K to enhance AI, cybersecurity education Maui College To tackle a critical nationwide shortage of cybersecurity and artificial intelligence (AI) professionals, the University of Hawaiʻi Maui College has secured a three-year, $441,645 National Science Foundation (NSF) award to launch a groundbreaking project: “CyberAI Innovation: AI-Enhanced Cyber Data Analytics Education.” Led by Principal Investigator Debasis Bhattacharya and Co-Investigator Thomas Blamey, the initiative builds on previous NSF-funded efforts and directly addresses a vital local need, as Hawaiʻi currently ranks among the top five states in the nation for unmet cybersecurity workforce demand. "The intersection of AI, data analytics and cybersecurity is a critical frontier for modern digital defense," said Bhattacharya, who also serves as the director of the Center for Cybersecurity Education and Research. "With Hawaiʻi facing such a steep challenge in meeting cybersecurity job demands, this grant enables us to build robust, early-career pipelines. We are excited to empower local educators and students with the advanced skills needed to protect our critical systems.” New curriculum, training The project will introduce an AI-integrated curriculum by embedding six new modules—including adversarial machine learning, AI-powered threat detection, secure AI pipelines and CyberAI ethics—across six core computer science courses at UH Maui College. Additionally, a three-year professional development program will deliver statewide faculty training across all seven UH community colleges and Hawaiʻi Department of Education (HIDOE) secondary schools. To cultivate early interest, the college will leverage the community of practice created by the NSF Project CSP4Hawaii (a collaboration aimed at improving computer science education at the state level) to expand K–14 academic pathways. The project also extends beyond IT, developing customized cyberAI micro-modules for non-IT fields such as healthcare/nursing, automotive technology and accounting/finance. AI, GenCyber cybersecurity camps UH Maui College has also secured a supplement award of $129,190 from the NSF

White House looks to revamp cyber supply chain security data calls

The White House is reviewing how agencies report on their cyber supply chain security programs, with new metrics expected in the “near term” to get a better picture of shared risks, especially those related to foreign adversaries. The White House Office of the Federal Chief Information Officer has been tasked with reviewing how agencies align with National Institute for Standards and Technology guidelines on “Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations.” Those standards provide guidance on evaluating risks associated with products and services “that may potentially contain malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices within the supply chain,” according to NIST. Cheri Benedict, senior cyber supply chain advisor within the federal CIO’s office, said governmentwide compliance mechanisms for those NIST standards are due for an upgrade. They were last updated in the wake of the Strengthening and Enhancing Cyber-capabilities by Utilizing Risk Exposure (SECURE) Technology Act of 2018. “We are now reviewing all practices and procedures as it relates to that to then inform the way forward,” Benedict said during a Tuesday webinar hosted by the Intelligence and National Security Alliance. “And in in the near future, agencies can expect a revamp of that data collection that tries to capture the status and perspective of maturity of their program, and moreover, not just that, but really helps us realize how we can better partner to move forward in common against threats.” Benedict said the ongoing review of governmentwide standards is emphasizing “the sharing perspective and the perspective of shared risk.” “There are many different risks, and we want all of it to be brought to bear if there’s a desire and shared perspective, but we especially focus on adversarial related risk, and that can take different forms and fashions,” she

Rules about funding and <b>cybersecurity</b> can shape the defense market as surely as contracts do

"We are in a messy middle situation, where they don't have funding certainty, but they also don't have regulatory certainty," said Stephanie Kostro. Interview transcript Terry Gerton Two important topics. One is CMMC. The deadline for CMMC reform comments has just passed. PSC submitted comments on that. What were at the top of your list in terms of concerns or feedback on the proposal? Stephanie Kostro So just as a reminder to your listening audience, Terry, PSC represents some 400 member companies that provide services and solutions. And a lot of those are technology companies. And so we were present as the creation here at PSC when CMMC came into being, you know, seven years ago, and this is not the first strategic pause, the first time an executive branch action had been taken to review this program, and we are very, very interested in what happens with CMM see for a couple of reasons. We have long voiced a few overarching concerns with how the federal government as an enterprise tackles cybersecurity internally within the government as well as with its contracting partners. And I’ll let you know what those three overarching concerns that we typically highlight are, one, that any reforms in cybersecurity as it affects contractors and industry that support the government really needs to be consistent. Any rules that they have for cybersecurity if you’re a Department of War or Defense contractor, or if you are a DHS contractor, or a Health and Human Services contractor, doesn’t it make sense to have common cybersecurity standards across the board? From an industry perspective, that makes sense because oftentimes if you a defense contractor, you’re also a Homeland Security contractor. So to have two different standards is problematic and costly, to be honest. The second overarching concern is

Wiley Alert Regarding White House Memorandum on Transnational Cyber Enabled-Crime ...

Wiley Alert Regarding White House Memorandum on Transnational Cyber Enabled-Crime Covered by Inside Cybersecurity Wiley attorneys Megan L. Brown, Jacqueline F. "Lyn" Brown, Tracye Winfrey Howard, Erin M. Joe, Sydney M. White, Teresita R. Kummer, and Alissa Lynwood's August 14 client alert on the White House National Security Presidential Memorandum, which shifts the United States’ approach to cyber operations and disrupting international cyber crime, was extensively covered by Inside Cybersecurity in the article, "Law firm Wiley offers considerations for private sector participation under White House offensive cyber memo." Related Professionals - Partner - Partner - Partner - Special Counsel - Special Counsel - Associate - Associate Contact Sarah Richmond Director of Communications 202.719.4423 srichmond@wiley.law

5 <b>Cybersecurity</b> Stocks with More Upside Ahead

Cybersecurity stocks are in the spotlight as ever-expanding AI demand now includes data safety and agent protection. While the broader AI sector has cooled, cybersecurity stocks have outperformed, fueling a rotation out of hardware and into software. According to research firm Gartner, information security spend will top $215 billion in 2026 despite pesky inflation and weak hiring, and frames this spending more as compliance-driven insurance rather than capex. Today, we’ll look at five cybersecurity stocks leading this sector higher. Each stock has a minimum market cap of $5 billion with a Benzinga Edge Momentum rating of at least 90. Palo Alto Networks Inc. Benzinga Edge Momentum Score: 97.16 Palo Alto Networks (NASDAQ:PANW) has the most momentum of any large-cap cybersecurity firm on the market, and its recent earnings help explain its recent run. The company beat top- and bottom-line estimates in its fiscal Q3 2026 report release in June, with revenue growing more than 30% year-over-year (YoY). Earnings per share (EPS) also grew more than 6% YoY, and full-year guidance was raised to $3.79 per share, with total annual revenue between $11.41 billion and $11.43 billion. The company’s fiscal Q4 2026 report is scheduled for after-hours on September 1. Still, analysts have already started bumping targets, including a new Street-high $475 price target from Wells Fargo on August 17, which represents upside of more than 25% from current levels. The bullish pattern on the PANW daily chart is familiar, and one often repeated in other stocks on this list. The breakout is confirmed by a Golden Cross, which flips the 50-day moving average from resistance level to support level. Support at the 50-day is buoyed by a bullish reversal on the Moving Average Convergence Divergence (MACD) indicator, and the Relative Strength Index (RSI) is in the Goldilocks territory between 50

Camp Welcomes Hampton Roads Youth to Learn About <b>Cybersecurity</b> and AI

What does it take to become a cyber professional in a field increasingly shaped by artificial intelligence (AI)? What skills should the future workforce be building? How can Old Dominion University help give students a leg up when it finally comes time to send out job applications? These are just some of the questions Hampton Roads middle and high school students had for faculty, industry professionals and Old Dominion University cybersecurity students at the 10th annual Summer Cyber Camp. This summer, it was renamed CyberAI Camp to highlight how the program has adapted to give campers more hands-on experience with AI tools alongside key cybersecurity topics like computer forensics, cryptography and network security. These are the skills and tools the campers will need in the future. “AI is a tool, just like the internet,” said Charles Kirkpatrick, camp director and a senior lecturer in the School of Cybersecurity. “It’s a tool these students must learn to use responsibly. It is the biggest change in history without question, and these students are in the middle of it. It’s changing everything we do, and our cybersecurity program has to change with evolving technology.” Every activity was designed to mirror real challenges and scenarios cybersecurity professionals face. Campers intercepted radio signals and visited the David F. Harnage Computer and Data Center to experience firsthand the kinds of technology they can work with in the cyber field. They learned about AI bots and how they can be influenced and heard from industry professionals and current students about education and career pathways. “It’s honestly not what I expected at all,” said Hamza Rezk, a rising junior at Norview High School in Norfolk. “The camp has opened up a new path I can go down.” Hamza came into the camp with the idea that he would

Newsline | ABC Voices Member Concerns on DOD <b>Cybersecurity</b> Requir

Awards Events/Products/Programs Legislation Politics and Policy Regulations Safety State/Local News Workforce Development On Aug. 14, ABC responded to the U.S. Department of Defense’s Request for Information on its Reforming Cybersecurity Maturity Model Certification and Reducing Compliance Burden for the DIB memo, which was issued on July 13. ABC urged the DOD to streamline and clarify requirements under the CMMC program while maintaining strong cybersecurity protections for the defense industrial base. The request follows a suspension of the planned CMMC Phase II requirements, which had been scheduled to take effect on Nov. 10. This suspension is intended to give the department time to conduct a broader review of the program. In the comments, ABC shared feedback from members on the challenges that federal contractors are facing in implementing CMMC and offered practical recommendations to reduce unnecessary compliance burdens. ABC identified concerns related to Controlled Unclassified Information identification and scoping, secure enclaves, subcontractor requirements and duplicative assessment and evidence requirements. ABC continues to support the DOD’s efforts to streamline and improve CMMC to ensure national security remains protected while avoiding unnecessary burdens on federal contractors.

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability - CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability - CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability - CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.

CompTIA SecAI+ earns ANAB accreditation, helping organizations build trusted AI ...

Independent accreditation helps organizations build AI security skills and strengthen workforce readiness DOWNERS GROVE, Ill., Aug. 18, 2026 /PRNewswire/ -- CompTIA, the leading global provider of vendor-neutral technology training and certifications, today announced that CompTIA SecAI+, its certification focused on the intersection of artificial intelligence (AI) and cybersecurity, has earned accreditation from the ANSI National Accreditation Board (ANAB). ANAB accreditation confirms that CompTIA SecAI+ meets the internationally recognized ISO/IEC 17024 standard for certification quality, validity and impartiality. This milestone comes as organizations seek proven workforce capabilities to secure AI systems, manage AI risk and support responsible AI adoption. "Organizations are adopting AI faster than they can develop the skills needed to secure it," said Katie Hoenicke, chief product officer, CompTIA. "ANAB accreditation provides independent validation that CompTIA SecAI+ measures the competencies employers need to manage AI risk, strengthen governance and support responsible AI adoption." SecAI+ joins CompTIA's portfolio of ANSI/ISO 17024-accredited certifications, reflecting internationally recognized standards for certification quality and impartiality.1 "As AI becomes embedded in business and mission-critical operations, organizations need confidence that their cybersecurity teams can address emerging AI security challenges," said Carl Bowman, senior vice president, exam services, CompTIA. "ANAB accreditation reinforces the rigor and credibility of CompTIA SecAI+." Introduced earlier this year, CompTIA SecAI+ validates skills in securing AI systems, identifying AI-enabled threats, managing AI risk, supporting AI governance and using AI-powered cybersecurity tools. Learn more about exam objectives, training resources and other certification information at CompTIA SecAI+. About CompTIA CompTIA, Inc. is the leading global provider of vendor-neutral training and certification products in the information technology (IT) space. Over four million CompTIA certifications have been awarded to current and aspiring technology workers, business professionals, government and military personnel, career changers, students and others. Working in partnership with thousands of academic institutions, governments, training providers and

Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other information available to the victim's Copilot session. The flaws, which the researchers collectively named CoSnitch, turn in part on an undocumented URL parameter that the assistant itself surfaced during testing. The company said it reported the issue to Microsoft in December 2025 and that patches shipped on August 18, 2026. CoSnitch is tracked as CVE-2026-24301 in Microsoft's Security Update Guide. The research names Copilot Personal, the consumer assistant hosted at copilot.microsoft.com, and does not state that the same behavior affected Microsoft 365 Copilot. The researchers said they found no evidence that CoSnitch was exploited in the wild. They reached the parameter by repeatedly asking Copilot why a prompt could not be made to run without user interaction, an approach the firm calls meta-hacking. Each refusal carried a technical justification, and the assistant eventually named a parameter, autorun=1, along with the session conditions under which it worked and the protections that were supposed to have disabled it. When the researchers built the URL exactly as described, the parameter Copilot had said no longer worked executed. Copilot "wasn't breached; it was played," Varonis said in its report. The attack URL pairs autorun=1 with the existing q parameter. In the CoSnitch report, Varonis said q alone only pre-fills the input box and that both parameters must be present for the prompt to fire without a user gesture. Its earlier Reprompt research also used q as the Parameter-to-Prompt entry point in a one-click attack. Varonis said that once CoSnitch execution begins, the prompt runs to completion even if the victim closes the Copilot tab immediately after the page loads. Varonis grouped the

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data. The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of 9.4. Released on August 17, 2026, the critical patch release arrived outside the company's usual schedule of twice-monthly updates on the second and fourth Wednesdays, five days after a routine patch release that carried no critical-rated issues. Only self-managed installations need to act. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.11.11. "GitLab.com and GitLab Dedicated are already running the patched version. GitLab.com and GitLab Dedicated customers do not need to take action," the company said. The following versions are affected - - All versions from 18.2 before 18.11.11 - 19.0 before 19.0.8 - 19.1 before 19.1.6 - 19.2 before 19.2.4 The fixes do not extend to the 18.2 through 18.10 branches, which fall inside the affected range. "GitLab has remediated an issue that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive," GitLab said. The CVSS vector published for the flaw indicates that it can be exploited over a network by an attacker holding no credentials, and without any action on the part of a victim. GitLab has not named the GraphQL directive involved or specified what the conditions necessary for exploitation are. The advisory discloses no exploitation of either flaw, and no public exploit code for them has surfaced on GitHub as of August 18, 2026. The second issue fixed in the release, CVE-2026-19650, has been rated High by GitLab with a CVSS score of 7.1, and

Ice cream makers as 'critical infrastructure'? EU's new <b>cybersecurity</b> law suffers wobbly rollout

A young woman takes a picture of her ice-cream in the Vittorio Emanuele II Gallery during a heatwave in Milan on June 24, 2026. | Stefano Rellandini/AFP via Getty Images Ice cream makers, Christmas lights manufacturers and German landlords may be set to get extra EU protection from cyber attacks. That's right, tech and cybersecurity lawyers are warning POLITICO that these unlikely sectors are on track to be classed as critical infrastructure under an EU cybersecurity law designed to protect cyber targets such as power plants, water facilities and energy grids. It's the latest stumbling block for the European Union's NIS2 Directive, which was originally passed in 2022 but is still being implemented by EU countries. Clarity about how to direct resources to protect infrastructure is more urgent than ever as Europe faces an unprecedented barrage of cyber attacks, super-charged by AI and increasing hybrid forms of aggression. Advertisement Governments were supposed to have their own legislation in place by late 2024, but delays have meant that many companies and their advisers are only now getting into the nitty-gritty of preparing to comply. Operators of the EU's most critical sectors are now being required to register with their national cyber agencies, which means understanding exactly who the law applies to. That has proved difficult, with lawyers and lawmakers citing examples such as chewing gum wholesalers to highlight the confusion and complexity associated with that task. The bizarre cases are emblematic of a real-world puzzle for companies and their legal advisers to solve — and a tricky piece of extra red tape at a time when the EU is trying hard to trim it back. It’s also another example of the difficulties the EU has faced in getting NIS2 up and running. Heavyweights France and Spain have not yet passed corresponding

SEBI Chairman Highlights <b>Cybersecurity</b> As Board-Level Issue

SEBI Chairman Tuhin Kanta Pandey underscores that cybersecurity has evolved into a critical board-level concern, urging careful deployment of artificial intelligence and addressing the future challenges posed by quantum computing in financial markets. Key Points - Cybersecurity is a board-level, business-continuity, market-integrity, and investor-confidence issue, not merely an IT challenge. - Deployment of Artificial Intelligence in critical infrastructure requires proper care, as automation introduces new risks. - AI for cybersecurity must be secure, governed, and accountable to ensure responsible use and mitigate emerging threats. - Quantum computing poses a significant future threat to current cryptographic systems, necessitating 'crypto-agility' and 'quantum readiness' in defence strategies. - SEBI has launched initiatives like the 'Incident Reporting Portal' and 'Cyber Suraksha Portal' to enhance cybersecurity knowledge sharing and incident response in the securities market. Cybersecurity is no longer only an IT-related challenge but also a board-level issue, Sebi Chairman Tuhin Kanta Pandey said on Monday, cautioning that proper care should be taken while deploying artificial intelligence in critical infrastructure. Pandey underlined that automation in cyber defence introduces more risks, and AI for cyber security must "itself be secure, governed and accountable." Cybersecurity: A Board-Level Imperative Speaking at the inauguration of a symposium for cyber defence organized by Sebi at its capacity building body National Institute of Securities Markets near here, Pandey said "we need to look at cybersecurity more from a collective perspective than merely individual lens". "Cybersecurity is no longer only an IT issue. It is a board-level issue. It is a business-continuity issue. It is a market-integrity issue. It is an investor-confidence issue," Pandey said. He urged fellow regulators, as also countries, to share the best practices when he said that any good practice, when developed, should become a reference point for others. "In cyberspace, our collective resilience depends on the strength

<b>Cybersecurity</b> - Blogs: Got Tickets? How to Make It to Kick-Off Without the Rip-Off

PERSPECTIVES FROM THE CAMPUS One of the strengths of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the colleges, universities, and other institutions of higher education throughout our state. Hence the name, “Perspectives from the Campus”, we invite experts – immersed in the pursuit of educating their students – to offer their knowledge for finding solutions in cybersecurity that benefit all Hoosiers. In the latest installment of this series, David Dungan, who serves as the executive director at the Center for Security Services and Cyber Defense at Anderson University, discusses some important tips sports fans will want to follow when it comes to making sure that the tickets we’re buying for the game are genuine and purchased using a secure and trusted source. With the start of the professional (and college) football season just around the corner, the information is intended to help ensure that your game day experience is a memorable one. By David Dungan Football season is here, and Indianapolis Colts fans across Indiana are getting ready for another season of game-day excitement. Whether you are a longtime football fan or attending your first Colts game, buying tickets brings the same excitement every time. That is, until you arrive at Lucas Oil Stadium and discover that your tickets have already been redeemed, or never existed in the first place. As Colts fans begin purchasing tickets for this season, scammers are also looking for opportunities to take advantage of your excitement as a fan. Fake tickets, social media listings, phishing links, and fraudulent ticket transfers are just some of the online scams that buyers should watch out for before making a purchase. To ensure your tickets are authentic, there are a few tips you’ll

Eighth Annual UNCW <b>Cybersecurity</b> Conference

- About Get to Know UNCWA Top Doctoral & Research InstitutionFrom humble beginnings in 1947 as Wilmington College, UNCW has evolved into a top doctoral and research institution with nearly 19,000 students and about 2,500 employees. - Academics Academic ExcellencePursue Your Path to ExcellenceHere at the stateâs coastal university, youâll enjoy a powerful academic experience that stimulates creative inquiry, critical thinking and thoughtful expression in a beautiful setting. - Admissions Find Your ProgramExplore Our Program Finder!Find an outstanding program to fit your strengths and prepare you to excel in our changing world. - Seahawk Life Experience Seahawk LifeOn Campus and in Our CommunityDiscover entertainment, involvement and engagement opportunities as a current Seahawk, alumnus, or community member. Plus, we offer a range of support and services. Explore all UNCW has to offer! - Research Knowledge, Innovation, DiscoveryTeaching & Research Are Entwined at UNCWDelve deep into your interests through applied learning, where undergraduate and graduate students partner with faculty on high-quality research projects.

The <b>Cybersecurity</b> Imperative in Smart Factories

Newswise — As manufacturing systems become more connected, the cyberthreat grows with them. Saman Zonouz has spent years documenting how vulnerable smart manufacturing environments are. He’s an associate professor in the School of Cybersecurity and Privacy and the School of Electrical and Computer Engineering, where he co-leads the Cyber-Physical Security Lab with Raheem Beyah, Georgia Tech’s provost and executive vice president for Academic Affairs. "Disrupting the manufacturing sector doesn't just shut down individual shops. It can directly impact national security and public safety," Zonouz said. Because manufacturing is one of 16 federally designated critical infrastructure sectors, it is deeply intertwined with energy, water, and defense, meaning disruptions can cascade far beyond the factory floor. The threats Zonouz documents go beyond ransomware. His research has demonstrated how adversaries can insert logic bombs into design files, compromising Computer Numerical Control machines or 3D printers. "We've shown how logic bombs can be inserted remotely into design files so that everything looks normal when the part is printed, but once it's in operation, the attacker can decide when it fails," Zonouz said, citing drone propellers, aircraft wings, and power grid transformer components as examples where invisible sabotage could have catastrophic consequences. Internet-wide scans conducted by his team found that many shop-floor controllers are directly exposed to the internet, with no meaningful barrier between an adversary and the machines running a production line. Imported equipment compounds the risk, because controllers and firmware from unknown developers may carry unintentional vulnerabilities or deliberately planted backdoors. "In manufacturing, many controllers and machines can still be accessed easily from outside," Zonouz said, echoing the kind of supply chain exposure seen in high-profile attacks on widely used software platforms. His prescription is straightforward but still largely unimplemented across the sector: Build security into the system design rather than adding it