Researchers warn that a critical vulnerability in SAP Commerce Cloud is facing exploitation just days after the company issued a patch.
Defused, a firm that specializes in threat intelligence, said Friday that it detected initial exploitation activity against the flaw, which is tracked as CVE-2026-58231, according to a post on X. Exploitation began hitting the security firm’s honeypots just three days after the patch was issued, according to Defused.
“There has been only one actor to date that has attempted exploitation of CVE-2026-58231 so does not seem to be widespread,” Simo Kohonen, founder and CEO of Defused, told Cybersecurity Dive via email.
Defused said that no proof of concept had been issued previously, nor had the vulnerability previously been exploited.
The vulnerability allows attackers to abuse a default authentication client. Successful exploitation could potentially lead to arbitrary code execution, and internal components could be compromised.
The vulnerability has a severity score of 10, which is the highest level of potential impact.
SAP Commerce Cloud is an enterprise-level platform that helps businesses run e-commerce stores.
SAP in 2024 rolled out cloud-based payments capabilities to beef up services on its e-commerce platform.
Aug 17, 2026 · via cybersecuritydive.com
The National Institute of Standards and Technology (NIST) is seeking public input by Sept. 30 on plans to develop human-centered cybersecurity guidance that puts people’s needs, abilities, and limitations at the forefront. In an Aug. 17 blog post, NIST said it released a concept paper outlining plans for practical guidelines and resources that would complement its existing cybersecurity publications. The effort is intended to address what NIST sees as a gap in authoritative guidance on putting human-centered cybersecurity into practice. “Above all, we see people not just as vulnerabilities to be contained; they’re also defenders, reporters, and problem-solvers to be empowered,” NIST computer scientists Julie Haney and Jody Jacobs wrote. According to NIST, human-centered cybersecurity (HCC) focuses on improving cybersecurity outcomes by considering the needs, abilities, and limitations of people who affect or are affected by cybersecurity when organizations design and implement security technologies and processes or make cybersecurity decisions. NIST said the approach could help address challenges including security professional burnout, employee frustration and mistakes, noncompliance, and losses in productivity, money, and reputation. The agency said existing cybersecurity frameworks and publications do not always incorporate human-centered considerations beyond employee security awareness training. However, the agency warned that awareness training alone is not enough. “Overreliance on training creates unrealistic expectations that employees will commit the knowledge to memory, understand the concepts, and always make the ‘right’ decisions, without addressing the root causes of many cybersecurity issues, like hard-to-use and disruptive security processes or an uninformed organizational security culture,” Haney and Jacobs wrote. The concept paper identifies several barriers to broader adoption of human-centered cybersecurity, including overreliance on annual awareness training. Other barriers include a cybersecurity field that often emphasizes technology over people, a lack of HCC expertise in the cybersecurity workforce, and uncertainty about how organizations should measure HCC outcomes.
Aug 17, 2026 · via meritalk.com
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a lot of small openings turning into bigger problems. Here’s what stood out. ⚡ Threat of the Week Suspected China APT Behind Exploitation of New VMware Flaw — A suspected China-nexus APT is assessed to be behind the exploitation of a newly patched security flaw in VMware vCenter. The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code. In at least one compromised instance, the attacks led to the deployment of a backdoor and. a reverse SSH binary, with the attack ultimately leading to the deployment of Babuk-derived ransomware. "Based on the case we investigated, however, we do not believe ransomware was necessarily the primary objective," QUIRSO said. "To us, its deployment looks more like a smoke screen intended to distract from the underlying intrusion and, importantly, hinder subsequent forensic analysis by encrypting evidence. We therefore see the ransomware activity in this case as potentially serving the broader intrusion rather than being its ultimate objective." AI Adoption Is Outpacing Governance, New SANS Survey Finds Seventy-eight percent of practitioners now say AI is part of their cybersecurity strategy, up from 50% last year. Governance hasn't kept pace: just 36% have a formal AI risk program. See where 536 security professionals say programs are falling short, and what to do about it. Read the Findings ➝ 🔔
Aug 17, 2026 · via thehackernews.com
Just days before the first day of school at the University of Texas at San Antonio, students, faculty and staff have little to no access to university accounts and systems after a potential cybersecurity breach was caught over the weekend. University officials alerted students, faculty and staff of “unauthorized activity”over the weekend that targeted the university’s technology systems. This prompted university officials to cut access to some online services as an ongoing investigation identifies any ongoing threats. “The activity was detected at the edge of our network, before it reached core systems and University Technology Solutions (UTS), working with expert partners, took immediate action to contain it and protect the campus’ entire technology environment,” states a notice issued on Monday by Andrea Marks, senior executive vice president of enterprise operations and strategy and Michael Schnabel, chief technology officer. In their statement, Marks and Schnabel said the actions taken were deemed effective and their ongoing investigation has not found evidence of a data breach. The first day of the fall 2026 academic year at UT San Antonio is on Wednesday, Aug. 19, which is also the last day to pay balances or enroll in payment plans. The proximity to these deadlines prompted concerns from students and their families who tried to access their accounts over the weekend to make payments, change classes or simply access their class syllabus. On Monday afternoon, officials stated payment deadlines were extended until Friday, Aug. 21, at 5 p.m., waitlists were being restored, and registration would remain open for the fall 2026 semester. “We understand how important access to these services is as you prepare for the fall semester,” an update posted at 12:30 p.m. on Monday said. “These adjustments are intended to give you additional time and flexibility while university technology services are restored.” Phone
Aug 17, 2026 · via sanantonioreport.org
Fortinet Fortinet FTNT $ 155.85 $4.16 2.6% 35% IBD Stock Analysis Stock pulled back in a test of 10-week support FTNT at 3-weeks tight, with 172.09 entry IBD Composite Rating 98/99 Industry Group Ranking 7/197 Emerging Pattern Cup Cup A cup-shaped pattern with no handle. Must be at least six weeks long or as long as a year. Buy point…
Fortinet, IBD Stock Of The Day, Steps Up AI Acquisitions To Build Cloud Platform
Copyright ©2026 Investor's Business Daily, LLC. All rights reserved. 87990cbe856818d5eddac44c7b1cdeb8
Aug 17, 2026 · via investors.com
Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the toolkit's communication capabilities. "The main finding is a complex C2 module that uses DNS A-record responses to choose between direct HTTPS and a Google Apps Script relay for each transaction," Kaspersky said in an analysis. "The same DNS infrastructure can validate and replace the relay deployment ID, allowing the operator to rotate the Google channel." Cavern, first publicly documented by Check Point Research in early July 2026, consists of multiple moving parts, including an Agent and an assortment of modules, that work in tandem to enable mission-specific post-exploitation functionality, while minimizing forensic visibility and ensuring persistent access. The modules facilitate file operations, SQL database enumeration, Active Directory reconnaissance, LDAP brute-force attacks, network reconnaissance, and SOCKS5 proxy and WebSocket tunneling. The use of Cavern C2 has been linked to Cavern Manticore, a hacking group affiliated with Iran's Ministry of Intelligence and Security (MOIS) that shares overlaps with MuddyWater and an OilRig sub-group known as Lyceum. Two back-to-back follow-up reports from Group-IB and Kaspersky detailed another module dubbed HOLLOWGRAPH that turns Microsoft 365 calendars into covert C2 channels. The malware, in particular, abuses the Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication. "Using the Microsoft Graph API, it treats the compromised mailbox's calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached," Group-IB
Aug 17, 2026 · via thehackernews.com
Chattanooga-based startup accelerator The Company Lab (CO.LAB) has launched CO.LAB Q, a 12-month quantum commercialization studio designed to translate early-stage quantum research into market-ready companies. Set to begin its inaugural cohort in November 2026, the program offers individualized commercialization pathways, pilot access, and technical infrastructure across quantum computing, networking, cybersecurity, sensing, and control hardware. [ CO.LAB Q Commercialization Studio Architecture ] │ ┌────────────────────────────────────────┼────────────────────────────────────────┐ ▼ ▼ ▼ Founding Technology & Utility Partners Academic & Defense Partners Quantum Infrastructure Access • Quantinuum (Founding Compute Partner). • UTC (Founding Academic Partner). • EPB Quantum Network. • Middle Tennessee Electric (Utility). • Davidson Technologies (Defense). • Oak Ridge National Laboratory (ORNL). • EPB Quantum (Network Partner). • Defense Pilot & SBIR/STTR Pathways. • UTC Quantum Center Facilities. The studio provides customized, milestone-driven support structured around foundational ecosystem partnerships: - Quantum Computing & Cloud Access: As Founding Compute Partner, Quantinuum provides participating startups with direct access to its trapped-ion quantum processors, the Nexus cloud platform, the Guppy programming language, and technical simulation tools. - Defense & National Security Track: Founding Defense Track Sponsor Davidson Technologies mentors startups on Department of Defense (DoD) mission needs, offering access to its quantum laboratory, cybersecurity frameworks, and pilot pathways through DIU and SBIR/STTR programs. - Academic & Facility Integration: Founding Academic Partner University of Tennessee at Chattanooga (UTC) connects startups with quantum faculty, student researchers, and specialized laboratory facilities. - Grid & Utility Testing: Founding Utility Partner Middle Tennessee Electric assists startups in validating quantum algorithms for power grid reliability, load forecasting, and infrastructure resilience. - Quantum Network Infrastructure: EPB Quantum provides optical quantum networking infrastructure via the EPB Quantum Network in Chattanooga, enabling field trials for quantum key distribution (QKD) and quantum communications. Supported by regional collaborators including the Tennessee Valley Authority (TVA), Oak Ridge National Laboratory (ORNL),
Aug 17, 2026 · via quantumcomputingreport.com
In this episode of Motley Fool Hidden Gems Investing, Motley Fool CEO Tom Gardner sits down with Mastercard CEO Michael Miebach to discuss: - Why machine-to-machine payments could transform B2B commerce. - Why Mastercard just acquired the world's largest stablecoin platform. - What the AI revolution really means for employment. - Why proprietary transaction data is Mastercard's deepest competitive moat. - How he stays sharp running a $500 billion company. To catch full episodes of all The Motley Fool's free podcasts, check out our podcast center. When you're ready to invest, check out this top 10 list of stocks to buy. A full transcript is below. This podcast was recorded on Aug. 9, 2026. Michael Miebach: Looking forward a few years, by 2030, the amount of fraud and cyber risk-driven damage is going to amount to $15.6 trillion. If cyber risk were a country, that would be the third-largest economy in the world. Bart Shannon: That was Michael Miebach, CEO of Mastercard, on the scale of the cybersecurity threat facing the global economy right now. I'm Motley Fool producer Bart Shannon. Mastercard is one of the most admired companies we follow, a business that has quietly become as much a cybersecurity and data company as a payments network. Motley Fool CEO Tom Gardner sat down with Michael on the day of Mastercard’s second quarter earnings to talk through how the payment network actually works, why cybersecurity has become one of its most important growth businesses, and what stablecoins really mean for the future of money. We hope you enjoy Part 1. Tom Gardner: Well, we're really excited here at Motley Fool to have Michael Miebach, the CEO of Mastercard, joining us. On the day of your second quarter earnings, we should probably start there, because I don't think there's much
Aug 17, 2026 · via fool.com
AI Intelligence Briefing — August 16, 2026 • Introducing Gemini 3.7 Flash — Google DeepMind's latest Flash model delivers substantial improvements in software engineering, coding, and agentic workflows, shipping just three weeks after Gemini 3.6 Flash. 🔗 Graph: gemini, agentic-ai, google 📅 Published: 2026-08-13 📰 https://deepmind.google/blog/introducing-gemini-3-7-flash/ 📌 Key takeaways: • Gemini 3.7 Flash is positioned as DeepMind's "most intelligent workhorse model yet for coding and agents," with substantial improvements across software engineering, knowledge work, and web development workflows • The release comes just three weeks after Gemini 3.6 Flash, reflecting an aggressive iteration cadence driven by developer feedback and algorithmic innovations • The Flash series targets the high-volume, cost-sensitive tier where most enterprise API calls land — directly competitive with OpenAI's GPT-5.6 Sol and Anthropic's Claude mid-tier models • For UCSD's TritonAI platform, which uses a LiteLLM gateway with model-agnostic routing, Gemini 3.7 Flash is a natural candidate for agentic workloads where coding and tool-use quality matter but frontier-level reasoning is overkill • What We Learned by Reproducing 2,200 papers from ICML — Hugging Face ran a 19-day hackathon where 1,200+ community members used coding agents to reproduce ICML 2026 papers claim-by-claim, finding that 23% of examined papers had at least one falsified or contested claim. 🔗 Graph: agentic-ai, claude-code, codex 📅 Published: 2026-08-13 📰 https://huggingface.co/blog/icml-2026-open-reproductions 📌 Key takeaways: • 1,221 community members used coding agents (Claude Code, Codex, Cursor, and others) to reproduce 2,226 of ICML 2026's 6,352 accepted papers — about a third of the conference — producing 6,816 public reproduction logbooks • 51% of examined papers had at least one claim independently verified, while 23% had at least one claim falsified or contested, including 49 papers where all claims were falsified and nothing could be verified • The automated Logbook Judge running open-weights model GLM-5.2 evaluated 35,908
Aug 16, 2026 · via buttondown.com
Datavault AI has agreed to acquire CyberCatch Holdings for approximately $94.5 million in cash, adding continuous cybersecurity compliance, AI-powered penetration testing, and quantum-resistant encryption technology to its data and edge computing platform. Under the definitive agreement, Datavault AI will acquire all approximately 26.8 million outstanding CyberCatch common shares for $3.53 per share. Outstanding dilutive securities will be exchanged on a cashless-exercise basis. The acquisition is structured as a court-approved plan of arrangement under the Business Corporations Act of British Columbia. Following completion, CyberCatch is expected to become a wholly owned subsidiary of Datavault AI and continue operating from San Diego. CyberCatch founder, Chairman and CEO Sai Huda is expected to become President of the subsidiary and report to Datavault AI CEO Nathaniel T. Bradley. CyberCatch provides a patented AI-enabled software platform designed around continuous compliance and cyber risk mitigation. The system uses generative AI to evaluate whether required cybersecurity controls are in place and calculate a Cyber Hygiene Score. It also uses agentic AI to continuously simulate threat-actor behavior, perform penetration testing, and calculate a Cyber Breach Score. CyberCatch’s approach is designed to replace or supplement periodic manual security assessments with continuous automated testing. The platform evaluates cybersecurity controls from three directions: outside-in, inside-out, and through social engineering. Its reporting can map findings against security and regulatory frameworks including NIST CSF 2.0, NIST 800-171, CMMC 2.0, ISO 27001, HIPAA and PCI DSS. Specialized AI agents perform tasks including reconnaissance, vulnerability detection, selection of attack techniques, exploitation, evidence gathering, reporting and development of mitigation recommendations. Datavault AI plans to integrate those capabilities throughout its broader technology stack. The company expects CyberCatch to become a cybersecurity and continuous-compliance layer supporting DataValue, DataScore and Information Data Exchange, along with workloads operating through Available Infrastructure’s SanQtum quantum-resistant zero-trust edge environment. The integration is also
Aug 16, 2026 · via pulse2.com
Corma has raised $60 million in seed funding to build a foundation model specifically for defensive cybersecurity, targeting a widening gap between rapidly advancing AI-powered attacks and the ability of existing security systems to detect and stop them. Sequoia Capital led the financing, with participation from Khosla Ventures and Coatue. Founded in 2025, Corma describes itself as a frontier AI lab focused exclusively on defensive cybersecurity. The company operates from Tel Aviv and San Francisco and is already working with Fortune 100 and Fortune 500 organizations. Corma’s central thesis is that advances in general-purpose AI have disproportionately benefited attackers. Frontier models have become increasingly capable at coding, software reasoning, vulnerability research and multi-step tool use, capabilities that can also be applied to identifying vulnerabilities and carrying out cyberattacks. But Corma argues that defending large enterprise environments presents a fundamentally different AI challenge. Defensive systems must analyze enormous quantities of audit logs, security events, network flows, and other information, correlate weak signals over extended periods, and maintain consistent reasoning across thousands of decisions. Corma conducted hundreds of simulations using realistic enterprise environments modeled after Fortune 500 organizations and incorporating the dozens of security tools commonly deployed by large companies. Leading AI models, including systems from OpenAI and Anthropic, were first instructed to act as attackers and establish persistent threats inside the simulated enterprise environments. The same models were subsequently asked to operate as defenders and identify and remediate the threats they had created. According to Corma’s research, AI attackers succeeded in 88% of the simulations, while AI defenders detected only 12% of the threats. The company said that in nearly every case, the same model capable of executing an end-to-end attack could not successfully defend against that attack when operating from the opposite side. Corma believes that imbalance demonstrates why adapting
Aug 16, 2026 · via pulse2.com
LockBit Took Down UHSP’s Systems. Its Backups Brought Them Back Key Highlights - UHSP's layered backup strategy, including an offsite cloud backup, was crucial in restoring systems without paying the ransom. - The attack originated through a compromised personal device, highlighting the importance of securing end-user endpoints and using out-of-band communication during incidents. - Regular testing and validation of backups, along with features like Object Lock, are essential for effective ransomware recovery. - Healthcare organizations often face pressure to pay ransoms; robust backups and security controls can help avoid this dilemma. - Sharing real-world experiences and best practices fosters a culture of transparency and resilience in cybersecurity for healthcare. When the University of Health Sciences & Pharmacy (UHSP) in St. Louis was hit by LockBit, one of the most aggressive ransomware groups, its internal systems were compromised, and the ransom demand exceeded seven figures. Fortunately, thanks to a layered backup strategy – including a fully isolated tertiary tier in Backblaze B2 Cloud Storage – UHSP’s IT team was able to methodically recover critical systems without being forced into rushed, ransom-driven decisions. Healthcare Innovation interviewed UHSP’s CIO/CISO Zach Lewis, who wrote Locked Up: Cybersecurity Threat Mitigation Lessons from A Real-World LockBit Ransomware Response, along with Kari Wilson, senior product marketing manager at Backblaze, to gain insights into the attack and recovery process. Could you walk me through the ransomware attack? Zach Lewis: The attack started in April of 2023. This was from LockBit, which was at the time one of the most prolific ransomware groups in the world. I got a call early that morning saying some of our servers were down and unavailable. We thought it was just a service outage, an IT problem. We went at it like it was an IT outage, started troubleshooting and trying to bring
Aug 16, 2026 · via hcinnovationgroup.com
AI Winners Shifting? Cybersecurity and Software ETFs Outperform as Chip Funds Falter Only 9 of 154 Tech and AI ETFs Gain Over the Past Three Months Global Cybersecurity, U.S. AI Software and U.S. Medical AI ETFs Rank Among Top Performers Too Early to Call a Shift: “Semiconductor Demand Will Continue to Grow” Amid roller-coaster market volatility, nearly all technology-related exchange-traded funds (ETFs) have declined, while funds focused on cybersecurity and software have held up relatively well. With semiconductor heavyweights Samsung Electronics and SK hynix underperforming, some market watchers say a new group of beneficiaries from the artificial intelligence (AI) boom may be emerging. According to the Korea Exchange on Aug. 13, only nine of the 154 semiconductor, technology and AI-related exchange-traded funds (ETFs) listed in Korea posted positive returns between May 27, when single-stock leveraged ETFs tracking Samsung Electronics and SK hynix were launched, and Aug. 11. The remaining 145 declined. The tally includes ETFs with “semiconductor,” “tech” or “AI” in their names, along with 14 single-stock leveraged ETFs. By product, Mirae Asset Global Investments’ TIGER Global AI Cybersecurity ETF recorded the strongest gain. Its price rose 20.4% from 15,360 won on May 27 to 18,495 won on Aug. 11, significantly outperforming major U.S. stock indexes such as the S&P 500, which gained 3.1%, and the Nasdaq, which fell 0.3%, over the same period. The ETF also rose 3.9% during the sharp Kospi decline from June 22 to July 30, serving as a relative safe haven for Korean investors. The ETF is composed of global companies that generate more than 50% of their revenue from cybersecurity-related businesses. Its top holdings — Palo Alto Networks, Okta, CrowdStrike, Fortinet and Qualys — all posted strong gains between May 27 and Aug. 10 local time, rising 55%, 68.5%, 39.6%, 28.4% and 89%, respectively.
Aug 16, 2026 · via it.chosun.com
- United States - / - Software - / - NasdaqGM:RPD Cybersecurity Stocks Investors Are Watching After Ukraine Linked Attacks Hit Payments And Logistics Cyberattacks linked to the war in Ukraine are no longer just headlines about battlefields. They are spilling into warehouses, payment systems and logistics networks, and that pulls cybersecurity stocks into sharper focus for investors watching risk and opportunity. This article walks through three stocks exposed to these rising cyber threats, all flagged in our Cybersecurity Stocks screener, to help you judge where the news flow may be creating openings or adding extra caution signals. The three cybersecurity stocks in focus below are just a starting sample, and the full screen surfaced 46 more companies with equally compelling narratives that are not covered in this article. If you want to go wider and deeper on this theme right now, head straight into the Cybersecurity Stocks screener to identify, filter and analyze the highest conviction plays. Riskified (RSKD) Overview: Riskified runs an e-commerce risk intelligence platform that helps online merchants approve more legitimate transactions while screening out fraud, handling chargeback disputes and policing abuse of refunds, returns and account access across sectors like payments, travel, electronics and fashion. Market Cap: US$942 million Riskified sits in the crosshairs of two big themes you may care about right now. Online fraud is getting more complex, and geopolitical shocks like the Ukraine cyber incidents are putting payment and logistics systems under pressure. Merchants are looking for partners that can keep approval rates high while limiting fraud losses, which is where Riskified’s AI driven products, recent partnerships such as Marqeta, and case studies like Kogan.com’s reported savings come in. At the same time, the company is still reporting losses and faces questions over margins, funding risk and competition from larger payment providers.
Aug 16, 2026 · via simplywall.st
Canadian cybersecurity startup Lastwall raises $16M to protect against quantum computer attacks
● 12 hours ago
New Brunswick cybersecurity firm Lastwall has raised $16 million to protect Canada against quantum computer attacks. The funding round was led by the Business Development Bank of Canada through its StrongNorth Fund, with participation from the New Brunswick Innovation Foundation, which made its largest single investment.
Lastwall's platform uses biometric credentials like face scans and fingerprints to secure critical infrastructure. Chief executive Karl Holmqvist warned that quantum computers capable of breaking current encryption could emerge in the 2030s, enabling attacks on banking, power plants, and hospitals.
The Canadian government has set 2031 as the target date for migrating high-priority systems to post-quantum cryptography. Lastwall, headquartered in Fredericton, plans to hire engineers and sales professionals, with 15 open roles currently.
Source: tj.news
Aug 16, 2026 · via app.dealroom.co
🤔
Fortune favors the bald 👌
They didn't have Elon Musk because that would have ruined their theory. And, of course, me!
The future is rather male, unfortunately.
“The future is bald” certainly gets attention, but this image may be even more iconic for how neatly marketing can segment the human condition. Personally, I think they missed the better headline: The future is toupee-less. 😄
I can only name three of these guys, wonder why Ballmer is among them. Also, the only vision these guys have is how to make more money, nothing that would truly benefit the user.
How far we’ve come, from wig headed men to bald headed men. Where will the pendulum swing next? If implants become more affordable and natural-looking, my bet is it will land there. Although, I am not an opponent of a beautiful chrome dome. Shine on!
Microslop is absolutely not the future of anything remotely innovative....
They should rent out that dome space for datacenters
And apparently male according to what they are pushing. Nice try.
The Future is old-school male only and that is Not really a Future :/
Aug 16, 2026 · via linkedin.com
New Delhi, Delhi, 16th of August, 2026 : The National Institute of Electronics and Information Technology (NIELIT), under the Ministry of Electronics and Information Technology (MeitY), Government of India, launched CYBER KUSHTI 2026 on August 15, a national cybersecurity and Artificial Intelligence (AI) hackathon designed to test and recognise human judgment in cybersecurity assessment. The hackathon was formally launched by Prof. (Dr.) M. M. Tripathi, Director General, NIELIT and Vice Chancellor, NIELIT Deemed to be University, as the official parallel technical track of the 3rd National Conference on Cyber Security, Digital Forensics and Intelligence (NCCDFI 2026). The competition is being conducted in collaboration with the Information Sharing and Analysis Center (ISAC Foundation) under the National Security Database (NSD), with CERT-In as the Knowledge Partner. Registration for CYBER KUSHTI 2026 opened on August 15th, and will remain open until 10 September 2026. Participation is free and open to students and independent researchers in teams of three. A Hackathon Focused on Judgment, Not Just Detection Unlike conventional cybersecurity competitions that primarily focus on vulnerability discovery or Capture The Flag (CTF) challenges, CYBER KUSHTI 2026 is designed to assess the ability of participants to evaluate, prioritise and defend cybersecurity decisions. Each participating team will receive an identical and deliberately imperfect Security Assessment Package, comprising AI-generated findings, static analysis outputs, dependency and secrets scans, architecture documentation, source code and application logs. The package will contain false, duplicated and genuine findings, while some actual vulnerabilities will be deliberately omitted. Teams will be required to produce a corrected and prioritised security assessment and defend the decisions made. The competition will reward participants not only for identifying genuine issues but also for correctly rejecting false findings. Speaking on the occasion, Prof. (Dr.) M. M. Tripathi, Director General, NIELIT, said,“The most difficult part of security work has shifted.
Aug 16, 2026 · via tripurastarnews.com
Citizens Capital Markets & Advisory has added Doug Brockway as a managing director in its Technology Investment Banking group, strengthening the firm’s coverage of cybersecurity and infrastructure software. Brockway will lead Citizens’ Cybersecurity and Infrastructure Software practice and will be based in Boston. He brings more than 35 years of investment banking experience and has advised clients on more than 125 mergers and acquisitions and capital raising transactions throughout his career. Brockway will work alongside Salil Kapoor, a vice president on the Cybersecurity and Infrastructure Software team. He will report to Kevin McClelland, head of technology investment banking at Citizens. The appointment expands Citizens’ investment banking capabilities across two technology sectors that continue to generate significant strategic and financial activity. Cybersecurity companies are navigating rapidly evolving threats, increasing enterprise security spending and growing demand for technologies capable of protecting increasingly complex digital environments. Infrastructure software companies are similarly playing an important role as businesses modernize technology stacks, adopt cloud infrastructure and deploy new applications across increasingly distributed environments. Citizens is positioning Brockway’s experience and industry relationships as a way to deepen its ability to advise companies and investors operating across those markets. His background includes extensive experience advising cybersecurity and software businesses on strategic transactions and capital formation. Brockway joins Citizens from Stephens. While at Stephens, he founded the firm’s Boston investment banking office and led its Cybersecurity Software investment banking practice. He previously held technology investment banking positions at ThinkEquity and Stifel. The hire also reflects Citizens’ broader strategy of expanding sector-specific expertise across its commercial banking and capital markets platform. By adding senior bankers with deep industry experience, the firm is seeking to strengthen relationships with companies throughout their growth and transaction lifecycles. Citizens Capital Markets & Advisory provides investment banking, research, sales and trading capabilities through Citizens
Aug 16, 2026 · via pulse2.com
Three weeks from now, the War Department owes Congress a report that could matter far beyond the Pentagon. Section 1512 of the fiscal 2026 defense authorization law requires a comprehensive review of how the department secures artificial intelligence and machine-learning systems, with findings due by Aug. 31. The law asks for current practices, identified gaps, commercial runtime-security options, alignment with industry frameworks, and recommendations for additional authorities or resources. That deadline arrives at an unusually useful moment. President Donald Trump signed Executive Order 14409 on June 2 to accelerate AI-enabled cyber defense while explicitly rejecting the idea that security requires a new licensing regime for AI development. Then, on July 13, the Pentagon suspended Phase II of the Cybersecurity Maturity Model Certification program, which had been scheduled for Nov. 10, and launched a review aimed at reducing compliance burden while preserving cybersecurity. The administration has therefore set a clear direction: move faster, cut bureaucracy, and keep the security requirement real. Recommended Stories The Aug. 31 report should be judged against that standard. A useful review will identify which AI-security controls actually change operational risk, which can be measured continuously, and which should become enforceable contract terms. The risk is that the review translates the new technology into familiar compliance language and leaves program managers with another checklist that says little about what happens when a model is manipulated at runtime. Congress already gave the department the structure for the next step. Section 1513 requires a risk-based security framework for AI systems acquired by the Pentagon. It directs the department to cover supply chain risks, data poisoning, adversarial tampering, unintended exposure, continuous monitoring, and incident reporting. It also tells the Pentagon to extend or augment existing cybersecurity frameworks, including CMMC, and to amend the Defense Federal Acquisition Regulation Supplement or take
Aug 16, 2026 · via washingtonexaminer.com
AI - ai and ml Anthropic says text watermarking scheme relies on inconsequential words'Shall I compare thee to a summer's afternoon' is the sort of thing this will make, and others look likely to adopt it - AI and ML DeepSeek's innovative harness treats everything as a plug-inChinese AI labs keep moving forward while US labs play defense - SECURITY Autonomous AI attacks pose 'clear and present danger' to critical infrastructureWeaponized agents could turn digital intrusions into kinetic disasters, experts warn - off-prem Rent-a-GPU outfit Nebius promises rapid 1 GW powerup plan isn't nebulousAnd it'll jump through every financial hoop it can to get there - AI and ML Modular's Mojo programming language hits 1.0 milestoneDevelopers await open source compiler release to dispel uncertainty following Qualcomm acquisition Infosec - Security Russians are posing as Signal support to launch phishing attacksPLUS: US takes down Iranian propaganda sites; Marketing company asks 'Why Do We Have Your Information?' And more! - Security Microsoft patches failed to fix on-prem SharePoint, which is now under zero-day attackPLUS: China upgrades smartphone surveillance tools; Ring eases anti-snooping stance; and more - Black Hat and DEF CON DEF CON Franklin project enlists hackers to harden critical infrastructureVoting village reports have been so successful, says Jeff Moss, that the whole of DEF CON will now be included - Security EQT buys majority share in Swiss cybersecurity biz AcronisWent at equivalent of $3.5B+ valuation for entire firm, though portion sold not specified - Malware Month Ten years since the first corp ransomware, Mikko Hyppönen sees no end in sightOn the plus side, infosec's a good bet for a long, stable career FOSS - FOSS smashed one Microsoft monopoly. After 20 years of failure, it's time to smash anotherWord up - GNOME can look like Windows – and Flashback can do
Aug 16, 2026 · via theregister.com