No-frills tech news

AI: <b>Cybersecurity</b> experts warn of threats

Extreme Heat Warning until SUN 8:00 PM MST, Northwest Plateau, Lake Havasu and Fort Mohave, West Pinal County, East Valley, Gila River Valley, Yuma County, Deer Valley, Scottsdale/Paradise Valley, Northwest Pinal County, Cave Creek/New River, Apache Junction/Gold Canyon, Gila Bend, Buckeye/Avondale, Central La Paz, Northwest Valley, Sonoran Desert Natl Monument, Fountain Hills/East Mesa, Southeast Valley/Queen Creek, Aguila Valley, South Mountain/Ahwatukee, Kofa, North Phoenix/Glendale, Southeast Yuma County, Tonopah Desert, Central Phoenix, Parker Valley

Cynomi, Spectra give partners a direct path to <b>cybersecurity</b> insurance | Channel Dive

Dive Brief: - Cynomi partnered with Spectra to give partners a direct path to certifications needed for cybersecurity insurance verification, the two companies said in a Tuesday announcement. The combined service will help managed service providers demonstrate security capabilities while providing validation for potential enterprise clients. - Cynomi’s existing platform will map Spectra’s certification criteria against its partners’ cybersecurity assessment data to accelerate the often-lengthy policy verification process. Once certified, partners can offer their clients Spectra’s performance warranty program, with up to $1 million in coverage per customer. - “Good MSPs will benefit from this partnership in three ways,” Edouard von Herberstein, CEO and founder of Spectra, told Channel Dive. “Number one, we help them save money, because if they’re a good MSP, they get better coverage and they pay less for insurance. Number two, because they’re certified and their security solutions are warrantied, they close more business. Last, the largest insurance partners and brokers can refer their customers who need IT to our certified MSPs.” Dive Insight: Cynomi offers a channel-focused interface that manages cybersecurity services by automating risk assessments, compliance and client reporting. Adding Spectra’s certification services to the platform was a natural next step, according to David Primor, CEO and co-founder of Cynomi. Primor said the integration aims to get cybersecurity tools to enterprises and small and medium-sized businesses. “The fact that Cynomi can provide insurance without having to reassess again is a great benefit,” Primor said. “Like democratizing cybersecurity for MSPs, this could democratize insurance and warranty capability in a much easier way.” Von Herberstein added that Cynomi’s platform makes it easier to verify MSPs’ security measures and bridge the gap between cybersecurity services and insurance coverage. “If you run a business, all the stakeholders, investors, customers, providers, and certainly insurers need to know that security

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux 6.14 with every default Spectre v2 mitigation on, their exploit leaked arbitrary kernel memory at 5.47 bytes per second with 91.97% accuracy, enough to locate and read /etc/shadow, which stores the system's password hashes, in five of ten attempts. It needs no privileges, only local code execution, so the risk sits on shared systems running an affected processor. The pair disclosed to AMD and Intel on February 5. AMD told them it plans a kernel patch; MIT says one has since shipped and arrives in a normal operating system update. A fix is in the Linux kernel. The commit, "x86/bugs: Make Safe-RET robust against interrupt injection", is dated June 2 and was written by Borislav Petkov and co-developed with David Kaplan, both AMD engineers. It describes the attack in the same terms the researchers do: injecting interrupts while Safe-RET runs "can neutralize the safe return sequence, potentially leading to data leakage through speculative execution." The patch fixes up register state as though the Safe-RET sequence had completed, and avoids executing a RET instruction after the interrupt returns. That is one of the two routes the paper proposed. AMD published a bulletin on August 6, AMD-SB-7061, titled "Safe RET Interrupt Vulnerability," naming Zen 1 through Zen 4 processors as affected. Its summary says an attacker running code on an affected system "could inject an interrupt at a precise moment to disrupt Safe RET," which "could potentially weaken that protection and may result in information disclosure." AMD

LIVE | Election <b>cybersecurity</b>

About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC

Meta says AI model hacked into another company's systems during <b>cybersecurity</b> testing

Add Meta to the list of companies with AI agents going rogue. An AI model from the parent company of Facebook and Instagram hacked into another company's systems during cybersecurity testing, a spokesperson confirmed on Wednesday. Meta says the breach occurred because of an inadvertent error during testing of the model, similar to previously disclosed incidents with OpenAI and Anthropic. "A misconfiguration by Irregular, an independent testing company Meta uses, inadvertently allowed one of our models access to the internet during evaluation," the Meta spokesperson said. Meta's Muse Spark model "exploited a security vulnerability" in another company "in a manner similar to previously-reported instances with other companies." MORE: Anthropic says its AI models hacked 3 organizations during testing In a statement, Irregular said the incident "is the exact same evaluation-environment issue" that Anthropic disclosed last week that allowed their models access to the open internet before they went on to hack three different organizations' systems. "This did not involve a sandbox escape or a sophisticated cyber action. There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evals," the spokesperson added. According to The Information, which first reported on the incident, Meta's AI model breached an unnamed company's systems and made changes to its internal system. The-CNN-Wire & 2026 Cable News Network, Inc., a Warner Bros. Discovery Company. All rights reserved.

Hackers grow more willing to destroy, not just disrupt OT systems | <b>Cybersecurity</b> Dive

LAS VEGAS — Cyberattacks on operational technology have shifted in recent years from extortion and espionage to destruction, a trend that should alarm those tasked with defending outdated industrial equipment, experts said on Thursday. The panel discussion at the Black Hat USA cybersecurity conference here highlighted the plethora of risks facing U.S. critical infrastructure operators — many of them poorly staffed and funded — at a time of heightened geopolitical conflict. “OT attacks are increasingly moving from targeting not just data but physical operations,” said Cheri Benedict, a cybersecurity and supply chain adviser at the White House’s Office of the Federal Chief Information Officer. “There is a real desire and willingness to cause this impact at scale,” said Matthew Rogers, the operational technology cybersecurity lead at the Cybersecurity and Infrastructure Security Agency (CISA). Security experts have watched with growing concern over the past few weeks as states have reported Iran-linked intrusions into their water systems. But those attacks failed to compromise the safety and quality of Americans’ drinking water. Meanwhile, Iran has also mounted a campaign to disable safety monitoring systems in water and other sectors. Those attacks are “what should actually scare you,” Rogers said. Rogers pointed to an advisory about the Iranian activity that CISA updated on July 22. In it, the agency said that at one organization, Iran-linked threat actors planted malware on a programmable logic controller (PLC) that “overrode specific instruction sets responsible for maintaining safe operating parameters in the victim’s environment.” One of the first known examples of malware disabling safety systems occurred in 2017, when a tool known as Triton switched off safety equipment at a Saudi Arabian power plant. Since then, hackers have developed new ways to stealthily cripple safety monitoring technology. Because infrastructure operators rarely examine PLCs unless they noticeably malfunction, safety-compromising

Expanding AI Benchmarks in <b>Cybersecurity</b> Beyond Vulnerability Discovery

The conversation about AI in cybersecurity has recently centered on capabilities like vulnerability discovery, exploit generation, and automated proof-of-concept development. It’s easy to see why: These tasks produce binary outcomes; a vulnerability either exists or it doesn't. That makes them useful for measuring model progress and demonstrating increasingly sophisticated cybersecurity capabilities. Vulnerability discovery matters to defenders. According to the Verizon 2026 Data Breach Investigations Report, vulnerability exploitation is now the most common initial access vector, accounting for 31% of breaches in the reporting dataset. This is a meaningful and growing share of the problem and a strong reason to continue advancing AI capabilities in this area. But it also means 69% of breaches begin through other paths. Credential abuse, phishing, social engineering, trusted relationships, and other forms of access remain central to the adversary playbook. A comprehensive evaluation framework should therefore measure not only whether AI can discover and exploit vulnerabilities, but also whether it can help defenders detect identity abuse, investigate suspicious activity, engineer effective detections, hunt for adversaries, and respond across the broader attack lifecycle. We believe effective AI for defense must be evaluated against the operational reality of security teams: the range of techniques adversaries use to gain initial access, the work required across the kill chain, and defenders’ most time-consuming tasks. Here, we explore some of these use cases. Detecting Adversary Behavior After Initial Access Once an adversary is inside, the defender’s work becomes more complex. Security teams must detect and triage suspicious activity across massive alert volumes, balancing signal and noise. Speed here determines whether the adversary is contained in minutes or operates on a network for a longer period of time. When suspicious activity is found, the focus shifts to investigation, which requires significant effort and expertise. Analysts must reconstruct events across endpoints, identities,

Mississippi Senate to form select committee on <b>cybersecurity</b>

As concerns about cybercrime continue to grow in Mississippi, the state’s lieutenant governor has announced a new select committee focused on protecting government systems, providing more resources to law enforcement, and reviewing penalties for cybercriminals. Lt. Gov. Delbert Hosemann, a Republican who oversees the Senate, announced Thursday plans for the Senate Select Committee on Cybersecurity. “Too many Mississippians find themselves the victims of cybercrime,” Hosemann said. “Criminals are using technology to steal identities, target state assets, and exploit vulnerable individuals. We have a responsibility to ensure our laws keep pace with these evolving threats and provide law enforcement with the tools needed to protect Mississippians.” The select committee will be co-chaired by Sens. Bart Williams, R-Starkville, and Tyler McCaughn, R-Newton. Other members include Sens. Bradford Blackmon, D-Canton; Scott DeLano, R-Biloxi; Jeremy England, R-Vancleave; and Rod Hickman, D-Macon. The committee will begin holding hearings this fall before developing recommendations to be considered by the full Senate during the 2027 legislative session. The announcement comes as FBI data shows a sharp national increase in cybercrime losses in recent years. Americans reported more than $16 billion in losses from internet crime in 2024, a 33% increase from the previous year, according to the FBI. While Mississippi has one of the nation’s lowest rates of reported cybercrime, according to a recent data privacy survey, State Auditor Shad White released a report in October 2025 showing nearly one-third of state agencies were vulnerable to hacking after failing to meet cybersecurity assessment requirements.

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed controllers, not water utilities or confirmed victims. Forescout said the publicly described effects could be achieved without a vulnerability exploit: attackers changed IP addresses and set passwords on controllers that were already reachable, causing operators to lose visibility and, in some cases, control of connected equipment. Neither the government alerts nor Forescout's analysis explains how the attackers found, selected, or initially accessed their targets. Water and wastewater utilities in at least seven states have reported incidents since July 27, the FBI and EPA said in a July 30 public service announcement. The Hacker News found on August 6 that Forescout's post says the announcement confirmed at least 12 states, while the FBI page says seven. No agency has attributed the campaign. Whatever the final count, defenders can act now by taking the controllers off the public internet. Exposing EtherNet/IP on port 44818 creates an unauthenticated path that, depending on device configuration, lets an attacker identify a controller or write settings to it, Forescout said. Forescout found more than 70% of the US-based exposed controllers on large mobile carrier networks. The FBI and EPA recommend strong authentication, updates and logging for cellular modems, with remote access isolated through a private APN, VPN or similar architecture. A July 30 Censys snapshot found 4,148 exposed Rockwell/Allen-Bradley EtherNet/IP hosts, with Verizon Business, AT&T Mobility and T-Mobile USA accounting for 59%. The Censys and Forescout snapshots both exceed 4,100 hosts, but different platforms, queries and dates make the figures not

Meta Joins OpenAI and Anthropic in AI <b>Cybersecurity</b> Scare After Model Hacks Third Party

Meta AI Model Exploits Security Flaw During Testing On Wednesday, Meta said that a configuration error by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its AI models access to the open internet during a test. The model then exploited a vulnerability in a third-party service, Meta said, like previously disclosed incidents involving other AI developers. “Meta learned of this when Irregular notified us, and we are currently investigating and will issue a full retrospective once we have all the facts,” a Meta spokesperson said in an emailed statement to Benzinga. The model was Meta’s Muse Spark 1.1, which the company has positioned as a highly capable system for coding and agentic tasks, Reuters reported (via The Information). The report said the model accessed an unidentified company’s systems and modified part of its internal environment. Irregular Says It Was Not a ‘Sandbox Escape’ Irregular said the incident resulted from the same type of evaluation-environment problem that Anthropic disclosed last week. "[It was the] exact same evaluation-environment issue," an Irregular spokesperson told Reuters, adding that the event did not involve a "sandbox escape or a sophisticated cyber action." The company said there were no unresolved issues and that it was preparing a white paper outlining best practices for securely conducting AI cybersecurity evaluations. Meta Incident Adds to AI Safety Concerns The event follows similar incidents involving Anthropic and OpenAI. Anthropic’s incident was also linked to a configuration issue that exposed its models to the open internet. OpenAI’s case differed: The company said an AI agent independently exploited a previously unknown vulnerability to gain internet access during a cybersecurity evaluation. White House Pushes AI Cybersecurity Testing Price Action: Meta closed Wednesday’s session at $588.77, up 0.14% and gained another 0.45% in after-hours trading to $591.42, according

Meta says AI model accessed the internet and hacked another firm

Meta says AI model accessed the internet and hacked another firm Facebook owner Meta says an issue during an evaluation by an independent testing company allowed one of its artificial intelligence (AI) models to connect to the internet and hack another organisation's system. The announcement follows recent incidents across the AI industry, including breaches by OpenAI and Anthropic models, that have raised cyber-security concerns. A Meta spokesperson told the BBC that it was investigating the hack that was caused by a "misconfiguration", which it described as similar to previously reported incidents at other firms. The incidents have prompted researchers and governments to call for tougher safeguards and more rigorous testing. Meta said the security trials were conducted by Irregular, the same AI security vendor that carried out tests for Anthropic's AI model that had gained access to three other companies' systems. An Irregular spokesperson said the Meta incident "is the exact same evaluation-environment issue that was already disclosed by Anthropic last week." Irregular is working on a report on how to securely run cyber-security tests involving AI agents, the firm's spokesperson told the BBC. Meta also said it will publish more information on the incident "once we have all the facts." In the past two weeks, AI leaders OpenAI and Anthropic have also reported incidents in which their models hacked into other organisation's systems during testing. ChatGPT-maker OpenAI said in a series of announcements that its agents attacked several publicly available services, including AI tools hub Hugging Face. OpenAI's disclosure prompted rival Anthropic to conduct its own checks, leading to the discovery that its Claude AI model had carried out similar attacks on several firms after a "misconfiguration" gave it access to the internet. Daniel Hulme, global chief AI officer of advertising firm WPP, told the BBC that such AI

Boston-based $2.9b <b>cybersecurity</b> player Point Wild bankers up for ASX debut

Point Wild, a $US2 billion ($2.84 billion) cybersecurity business backed by private capital giant Warburg Pincus, has mandated two more brokers to boot up its blockbuster ASX debut. Loading... Sarah Thompson has co-edited Street Talk since 2009, specialising in private equity, investment banking, M&A and equity capital markets stories. Prior to that, she spent 10 years in London as a markets and M&A reporter at Bloomberg and Dow Jones. Email Sarah at sarah.thompson@afr.com Angira Bharadwaj is a co-editor of Street Talk. She covers IPOs, capital raises, mergers and acquisitions and other breaking news in Australia’s capital markets. Previously, she covered financial services, state, and federal politics. Send tips to @angirab.60 on encrypted messaging platform Signal. Email Angira at angira.bharadwaj@nine.com.au

Meta AI model breached another company during <b>cybersecurity</b> test

Meta said Wednesday that one of its artificial intelligence models breached another company during cybersecurity testing, intensifying concerns over developers’ ability to contain increasingly capable AI systems following similar incidents involving Anthropic and OpenAI. The incidents at Meta and Anthropic resulted from configuration errors that inadvertently gave Anthropic’s models access to the open internet. In OpenAI’s case, an AI agent independently exploited a previously unknown vulnerability to reach the internet during cybersecurity testing. The breaches have highlighted growing concerns that advanced AI systems could pose new cybersecurity risks and are likely to intensify U.S. government efforts to improve AI safety as companies race to build more capable models. Some prominent AI leaders have argued that development should slow until stronger safeguards are in place. Meta said it was investigating an incident in which a configuration error by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its models internet access during testing. The model “exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies,” Meta said in a statement. The Information, citing sources, reported that the model involved was Meta’s Muse Spark 1.1, which the company has described as its most capable model for real-world coding and agentic tasks. According to the report, the model breached an unidentified company’s systems and altered its internal environment. An Irregular spokesperson told Reuters that the incident was the “exact same evaluation-environment issue that was already disclosed by Anthropic last week” and did not involve a “sandbox escape or a sophisticated cyber action.” “There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations,” the company said.

<b>Cybersecurity</b> incident disrupts Kenaitze services

The Kenaitze Indian Tribe is facing its second week of disrupted internet services after a cybersecurity incident. The tribe first reported late last month on Facebook the tribe’s internet and phone service was down. Later that day, the tribe said it was “mitigating a risk” to its network that led to a prolonged computer outage. The day after the disruption was reported, the tribe said it would still be able to offer services through its behavioral health and childcare programs. The tribe announced limited services at its Dena’ina Wellness Center and said it would provide onsite meals only at its Tyotkas Elder Center. Last Friday the tribe announced that a cybersecurity incident was behind the ongoing outages. In a social media update, the tribe wrote that it is “aware that an unknown actor has claimed responsibility for the incident, and these claims are part of our investigation.” The tribe’s communications manager declined an interview request and said no additional information will be provided. The tribe has established temporary phone numbers for services, including: - Dena’ina Wellness Center - Primary care: 907-513-4438 - Dental: 907-513-4434 - Behavioral Health: 907-513-1758 - Education: 907-513-7512 - Kahtnu Area Transit and other transportation: 907-513-4458 - Na’ini Family and Social Services: 907-690-0826 The tribe’s K’beq’ Cultural Heritage Center and Educational Fishery are not impacted by the cybersecurity incident. Updates on the outage are being shared by the tribe on social media and on its website.

Meta's AI model follows rivals in revealing hacks of outside systems

Meta’s AI model follows rivals in revealing hacks of outside systems Meta joins rivals OpenAI and Anthropic in disclosing AI hacking during cybersecurity testing. Meta has said that its AI model hacked another company during cybersecurity testing, following on from recent similar announcements by rival companies Anthropic and OpenAI. Meta said on Wednesday that one of its AI models – reported to have been Muse Spark 1.1 – made changes to the unnamed hacked company’s internal systems after accessing the public internet because of an error in the setup of the “sandbox” testing environment by independent testing company Irregular. Recommended Stories list of 3 items - list 1 of 3SpaceX shares slide on the heels of first quarterly report - list 2 of 3AI models attempted ‘unsanctioned’ cyberattacks in tests, watchdog says - list 3 of 3Elon Musk’s SpaceX reports losses but less than expected A “sandbox” is an isolated internal virtual testing environment, which has no access to the internet. Last week, Anthropic said that its Claude AI model hacked into the systems of three organisations during testing that was supposed to keep it isolated from the internet. Anthropic said a misconfiguration had allowed Claude models to reach the internet. The company said it discovered the incidents after reviewing 141,006 test sessions. The announcement came days after rival OpenAI first revealed that its models improperly accessed the internet and went rogue during security testing. OpenAI and Anthropic have both released their most powerful models this year, known as Sol and Mythos, respectively. The AI Security Institute (AISI), the UK’s AI watchdog, warned in a report released on Tuesday that OpenAI’s GPT-5.6-Sol and Anthropic’s Claude Mythos 5 employed previously unseen levels of deception to carry out “sustained, potentially harmful activity” during a routine safety evaluation.

Meta AI model hacks another company during testing

Aug 5 (Reuters) - Meta (META.O) said on Wednesday one of its AI models hacked another company during cybersecurity testing, fanning concerns about how developers can contain increasingly capable AI systems after similar incidents at rivals Anthropic and OpenAI. The incidents at Meta and Anthropic stemmed from configuration errors that inadvertently gave Anthropic's models access to the open internet. In OpenAI's case, an AI agent independently exploited a previously unknown vulnerability to reach the internet during cybersecurity testing. Sign up here. The breaches highlight growing concerns that advanced AI systems could pose new cybersecurity risks and will likely intensify U.S. government efforts to improve AI safety as companies race to develop more capable models. Some prominent AI leaders have argued that development should slow until stronger safeguards are in place. Meta said it was investigating an incident in which a misconfiguration by Irregular, an independent company that conducts cybersecurity evaluations for Meta, inadvertently gave one of its models internet access during a testing. The model "exploited a security vulnerability in a third-party service, in a manner similar to previously reported instances with other companies," Meta said in a statement. The Information, citing sources, reported that the model involved was Meta's Muse Spark 1.1, which the company has touted as its most capable model for real-world coding and agentic tasks. The report said the model breached an unidentified company's systems and altered its internal environment. A spokesperson for Irregular told Reuters the incident was the "exact same evaluation-environment issue that was already disclosed by Anthropic last week" and did not involve a "sandbox escape or a sophisticated cyber action". "There are no current open issues. Irregular is developing a white paper to share best practices for containment and securely running cyber evaluations," Irregular said. CONCERNS ABOUT CYBER RISKS The recent breaches

Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Cybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer. The new dead drop resolver approach, observed in two trojanized npm packages "bianira-ui" and "fluid-type-ui," has been codenamed NullReceiver by OpenSourceMalware, which has described it as a "deliberate improvement on EtherHiding." The activity has been linked to North Korea. The packages are currently no longer available for download from npm. However, statistics show that they have been downloaded a few hundred times since they were first published on July 28, 2026 - - bianira-ui (109 downloads), uploaded by an npm user named "npmuser1101" - fluid-type-ui (587 downloads), uploaded by an npm user named "npmuser3002" EtherHiding was first publicly documented by Guardio Labs in October 2023 as a covert approach that involves embedding nefarious code within a smart contract on a public blockchain like BNB Smart Chain (BSC) or Ethereum. The technique heralded the "next level of bulletproof hosting" as it improves operational resilience in the face of takedowns. The use of EtherHiding by North Korean hacking groups was detailed by Google Threat Intelligence Group (GTIG) late last year in connection with Contagious Interview, a long-running campaign that aims to deceive potential targets by approaching them on LinkedIn with lucrative job opportunities and asking them to complete an assessment that leads to malware deployment. The latest development indicates that the threat actors are further refining their tactics and making it difficult for defenders to detect. "Instead of hardcoding a C2 address or hiding it in transaction calldata (as in EtherHiding), NullReceiver encodes the C2 IP directly in the bytes of the recipient address of a zero-value, zero-data Ethereum transfer," security researcher Paul McCarty said. "The malware looks up the attacker's

AWWA urges expanded U.S. <b>cybersecurity</b> support, measures

AWWA urges expanded U.S. cybersecurity support, measures WASHINGTON, Aug. 5, 2026 /PRNewswire/ -- The American Water Works Association (AWWA) today sent a letter to U.S. Congressional leaders urging strong federal support for water utilities following cyber attacks on multiple water systems in recent days. "Recent cybersecurity attacks on water utilities across multiple states underscore the need to further support drinking water and wastewater utilities as critical infrastructure," AWWA CEO David LaFrance wrote in a letter to U.S. House and Senate leadership. "Water utilities are often out of sight and out of mind – historically under-resourced compared to other critical infrastructure sectors – despite their central role in daily life, the economy, and public health." The letter encouraged federal funding for critical cybersecurity needs, expansion of eligibility under existing programs to include cybersecurity training for utilities of all sizes, information-sharing among key agencies, and a collaborative process, with input from water sector and cybersecurity experts, in developing sensible regulation that accounts for the variability in size and complexity of all water systems. AWWA expressed support for cybersecurity measures included in the Senate's Water Resources Development Act of 2026 (S. 4949), including: - Reauthorization of the Midsize and Large Drinking Water System Infrastructure Resilience and Sustainability Program. - Cybersecurity training as an eligible use of funds in: - the Drinking Water Infrastructure Resilience and Sustainability Program and, - the Innovative Water Infrastructure Workforce Development Program. - A program to design, construct, or maintain digital infrastructure technology, including through cybersecurity risk mitigation training and technical assistance, for rural water systems and systems in areas experiencing critical water supply needs. - A program to encourage participation in the communications and intelligence sharing organization WaterISAC. AWWA also asked Congress to consider additional measures, including: - Water Risk and Resilience Organization Establishment Act (H.R. 2594), which

New AP courses focus on business, finance and <b>cybersecurity</b> skills

TAMPA, Fla. — High schools across Tampa Bay are adding new Advanced Placement courses in cybersecurity and business this year through the AP Career Kickstart program. The program is an effort designed to connect high school coursework with real-world job skills. At Jesuit High School, more than 100 students are enrolled in the new elective, AP Business with Personal Finance. Senior Bryce Besece said he is looking forward to taking the course. “I feel this is a class that’s going to give me the fundamentals and the background to go succeed as soon as I can get into college,” Besece said. David O’Sullivan, Jesuit’s Math Department chair, is teaching the class. Before becoming an educator, O’Sullivan spent nearly 15 years in accounting. It’s one of the subjects he will be teaching as part of AP Business with Personal Finance. “It’s accounting, it’s finance, it’s marketing, it’s management, entrepreneurship,” O’Sullivan said. “If a student, junior or senior, is considering business, any kind of business, marketing or management, it’s going to let them dip their toe in the water and get a taste of it, a flavor and say, ‘Yes, this is something that I think I may enjoy or I want to get in a different direction.’” According to the College Board, business is the most popular major in college, but only 20% of students take a business course in high school. The AP Business with Personal Finance course was created as part of the AP Career Kickstart program to help address that gap. O’Sullivan said the class is not only for students planning to major in business. He said it will also cover practical financial topics students can use after high school. “We need people to understand how credit works, loans, because students are going to leave college with student