No-frills tech news

How Bitsight Helps Financial Institutions Align With Bank Negara Malaysia's RMiT Policy Document

Financial institutions are not short on cybersecurity policies, frameworks, or regulatory requirements. Turning those requirements into a living risk management program can be challenging. Organizations need a program that can keep pace as technology environments expand, cloud adoption grows, third parties are added, and external exposures change. Especially as the threat landscape continues to evolve. Bank Negara Malaysia’s current Risk Management in Technology, or RMiT, Policy Document reflects that reality. Issued and effective on 28 November 2025, it establishes minimum requirements for managing technology and cyber risk across governance, technology operations, cybersecurity, digital services, third-party service providers, cloud services, audit, assurance, and gap analysis. It also makes clear that larger, more complex, highly digitalized, or highly interconnected institutions are expected to adopt more robust controls proportionate to their exposure. Bitsight can help financial institutions operationalize several of these expectations by providing continuous, outside-in visibility into their cybersecurity posture and the broader digital and third-party ecosystem around them. Institutions still need to enforce controls, policies, security operations, internal testing, and regulatory responsibilities. Bitsight provides an intelligence and measurement layer that can help teams identify risk, prioritize action, monitor change, and communicate progress. RMiT raises the bar for continuous monitoring Traditional technology risk programs often rely heavily on periodic reviews. An organization completes an assessment, collects documentation, records the results, and repeats the process later. Those activities remain important, but they cannot show what happens between assessments. Threats don't wait for assessment intervals. By the time the next formal assessment takes place, the organization’s actual exposure may look very different. As vendors and technology continue to evolve, it is vital to ensure your security posture evolves with those changes. RMiT requires financial institutions to include continuous monitoring within their Technology Risk Management Framework so material risks can be detected and addressed in

A Meta AI Model Hacked Another Company During <b>Cybersecurity</b> Testing

Search, find and engage with others who are serious about tech and business. Follow and be a part of discussions about tech, finance and media. Premium advertising opportunities for brands Team access to our exclusive tech news Journalists who break and shape the news, in your inbox Catch up on conversations with global leaders in tech, media and finance Explore our recent partner collaborations Premium advertising opportunities for brands Team access to our exclusive tech news Explore our recent partner collaborations

OpenAI warns autonomous hacks are 'watershed moment for computer security'

LAS VEGAS — OpenAI models’ autonomous attacks on other companies represent an urgent warning to the AI industry about the need for stronger model development safeguards, employees from the frontier label said on Wednesday. “This is a pivotal moment both for our company as well as the AI industry as a whole,” Michael Dalton, a member of OpenAI’s technical staff, said during a presentation at the Black Hat 2026 cybersecurity conference here. OpenAI stunned the world in late July when it announced that two of its models broke out of their testing environments and used zero-day vulnerabilities to hack into the networks of other companies, including the AI tool library Hugging Face. The disclosure, followed shortly thereafter by a similar announcement from Anthropic, reignited fears about the dangers of powerful and largely unregulated AI models. Speaking at Black Hat, Dalton said that “numerous teams are dropping everything” to improve OpenAI’s ability to detect and prevent similar incidents in the future. The company has slowed down its research and “dramatically scal[ed] up the monitoring of our AI agents.” While the autonomous hacks were effectively innocent mistakes, OpenAI employees described them as harbingers of a grim future, one in which companies face constant, sophisticated attacks by malicious actors using powerful open-source models that no frontier lab can contain. “We believe this is a watershed moment for computer security as an industry,” Dalton said. “AI orchestrated, fully automated offensive attacks are real now.” The Hugging Face incident, he added, represents “a glimpse into the near future of what attacks will look like for our industry.” Defenders need to accelerate their work to keep up with the anticipated surge in attack sophistication, Dalton argued. That could involve experimenting with defense-focused AI models, as well as doubling down on basic security measures that are newly

New York boosts funding for water <b>cybersecurity</b> grants

New York boosts funding for water cybersecurity grants Reminding everyone that not all of the nation’s water infrastructure will be so readily disrupted by cyberattack, New York Gov. Kathy Hochul this week announced more than $9 million in grants to improve the cybersecurity of dozens of water systems across the state. One hundred and fifty-three local government projects are set to receive funding through Strengthening Essential Cybersecurity for Utilities and Resiliency Enhancements, or SECURE, a grant program created to support new cybersecurity standards governing the state’s water and wastewater utilities. The program includes grants of $50,000 for cybersecurity assessments and $100,000 for implementing cybersecurity upgrades. The regulations hold that facilities must implement common cybersecurity controls, such as limiting users’ access to only systems they need, prohibiting the use of default credentials and requiring complex passwords and multifactor authentication. Larger treatment plants, those processing at least 10 million gallons of water per day, are required to begin monitoring and logging network activity. And treatment plant operators will be required to complete cybersecurity training, every five years, to renew their certifications (though the regulations offer assurance that their total training hours will not increase). When officials unveiled the new cybersecurity regulations for New York water utilities in March, Colin Ahern, the state’s former cyber director, who recently became New York’s first director of security and intelligence, said the new rules would move the state “beyond reactive defense.” In at least two press releases, New York officials have said the SECURE program would offer just $2.5 million in grants, an amount that fell short of funding all of the water utilities that had expressed interest. The governor’s office did not immediately respond to an email asking why funding had been increased to $9 million, but in a press release Monday, Hochul said the

Hugging Face AI breach is 'most consequential hack' since Morris Worm, former NSA cyber ...

Hugging Face AI breach is ‘most consequential hack’ since Morris Worm, former NSA cyber chief says AI may let hackers exploit newly disclosed software flaws so quickly that organizations should weigh whether to immediately patch internet-connected devices, even at the risk of causing outages, Rob Joyce said. LAS VEGAS — An OpenAI system that broke out of a cybersecurity test and entered Hugging Face’s network was a “watershed moment” comparable to the 1988 Morris Worm infection, former National Security Agency cybersecurity director Rob Joyce said Wednesday. “We’re living in the last several weeks through with what I think is the most consequential hack,” Joyce said. He spoke alongside fellow former NSA cybersecurity director Dave Luber during a World Wide Technology panel held at the Black Hat cyber conference. “I have to go back all the way to the Morris Worm in the ’80s to say something that’s equivalent to how it’s going to change the way we think about our infrastructure,” he said. The Morris Worm spread automatically across the early internet, disrupting thousands of computers and helping spur major changes in how the government and technology industry handled cyber incidents. The episode led to the first felony conviction under the 1986 Computer Fraud and Abuse Act. Joyce said he once believed large language models would mainly help hackers write convincing phishing emails and create fake images, audio and video, but he didn’t expect them to become broadly useful for carrying out the more technical stages of an attack. “And boy, was I wrong,” he said, adding that the systems can now understand computer programs and networks well enough to find vulnerabilities that can be turned into working intrusions. Hugging Face disclosed in July that an autonomous agent powered by OpenAI models had gained unauthorized access to parts of its

Western government leaders call for a focus on infrastructure resilience, not AI hype

LAS VEGAS — Policymakers and business executives need to focus on basic cybersecurity resilience instead of getting distracted by flashy claims about AI-fueled hacking nightmares, a group of senior U.S. and allied government officials said on Wednesday. “The immediate challenge is not runaway AI,” Jonathon Ellison, director for national resilience at the UK’s National Cyber Security Centre, said during a panel at the Black Hat 2026 cybersecurity conference here. “The immediate challenge is being resilient enough for the faster-paced environment that we are entering into, given the legacy issues that we are carrying.” Michael Duffy, the acting U.S. federal chief information security officer, said organizations needed to shift from a prevention-focused mindset to one that prioritizes continuity of services. “Things will go down,” he said, and organizations need to prioritize their most important systems so they can continue delivering on their mission. The cybersecurity community, he added, needs “a new risk calculus for what it means to operate in a contested environment.” Artificial intelligence is making hacking easier and could make it more destructive in the near future, the government leaders acknowledged. Even so, hackers don’t need AI to exploit the serious technical and process vulnerabilities that exist inside many businesses and government agencies. That danger became clear last week after Iran-linked hackers launched cyberattacks against water utilities in at least 12 states. Water systems are some of the most vulnerable infrastructure operators in the U.S. because of their overworked staffs, small budgets, low tolerance for downtime and heavy reliance on aging operational technology. In recognition of the increasing likelihood that hackers will disrupt critical infrastructure, the U.S. government has recently begun emphasizing resilience as part of its cybersecurity messaging. The Cybersecurity and Infrastructure Security Agency recently launched a program, dubbed CI Fortify, designed to get critical infrastructure operators to

US AI leaders turn to Chinese open-weight models, challenging closed-source safety claims

US AI leaders turn to Chinese open-weight models, challenging closed-source safety claims Andrew Ng and others argue accessible systems outperform overly restricted platforms on cybersecurity and transparency More American titans of artificial intelligence are describing Chinese open-weight models as better for AI safety and security than closed-source models, challenging the long-standing claim by US closed-source AI model developers such as Anthropic that open-source models present a threat to society. “From what I’m seeing, I think open-weight models seem safer to me than closed-weight models,” AI pioneer Andrew Ng, the former head of Google Brain and former chief scientist at Baidu, said at the Agentic AI Summit in Berkeley, California, on Saturday. Ng said that he and a colleague turned to use two Chinese models – Moonshot AI’s Kimi K3 and Zhipu AI’s GLM-5.2 – to conduct a security review of their new open-source AI agent tool called OpenWorker, released last month, after leading models from OpenAI and Anthropic refused to help with the task. The reason for the reliance on Chinese models is that the latest US models, such as OpenAI’s GPT-5.6 and Anthropic’s Fable 5, have enhanced “safeguards” to refuse assisting with harmful activities. However, users have complained that these safeguards also block legitimate requests, including those to help with shoring up cybersecurity systems.

Can holistic <b>cybersecurity</b> deliver the needed protection?

'Holistic' security can create a defense posture full of holes Modern organizations face a seemingly endless number of cyberthreats to what can seem like an overwhelming number of entry points. It's no wonder that a holistic cybersecurity strategy, where physical and virtual security processes are integrated under one umbrella, has become so enticing to cybersecurity leaders. Under a holistic cybersecurity strategy, all the elements that require protection in an organization -- people, computers, networks, buildings and property -- are considered to be part of one interconnected system. The ultimate goal is continuous protection across all attack surfaces. This integration of different levels and types of security is designed to develop a comprehensive understanding of vulnerabilities in order to create well-balanced protection against a variety of threats. In their efforts to capitalize on this, network management vendors are offering tools that promise this holistic approach to network security that monitors and evaluates companywide networks and data in one program. But while holistic monitoring seems like a streamlined, cost-effective solution, the elimination of several levels of security when turning to a stand-alone management system can leave networks exposed. This guide aims to help security leaders decide whether the holistic cybersecurity approach will actually provide continuous monitoring of their organization's physical and virtual infrastructure. As companies are quickly learning, a holistic approach to cybersecurity can save resources and provide continuous security monitoring that is invaluable to modern business. But if not implemented carefully, "holistic" security can leave holes that create more organizational risk.

Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access

Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat Research. "The campaign relies on a toolkit of VBScript droppers, batch file loaders, compiled .NET executables and an HTML phishing page, all ultimately pointing to a live WsgiDAV-based staging server at 207.174.0[.]143:8080," researchers Shikha Sangwan, Akshay Gaikwad, and Aaron Beardslee said in a report shared with The Hacker News. Successful attacks culminate with a ScreenConnect agent installed and beaconing to one of three attacker-controlled relay servers, providing the attackers with persistent remote access to compromised systems. The activity has not been attributed to any known threat actor or group. The findings add to the growing abuse of legitimate RMM tools by threat actors, as it allows them to bypass security controls and take advantage of their prevalence in enterprise environments to blend in with authorized IT tooling without the need for deploying a purpose-built remote access trojan. Securonix said its investigation commenced following the discovery of a live WsgiDAV server that served two purposes: stage malicious payloads and maintain command-and-control (C2) over existing infected machines through a ScreenConnect relay on port 8041. An analysis of the ScreenConnect relay configuration strings embedded in the MSI and EXE payloads has uncovered three distinct C2 clusters, each associated with software update, document review, and document viewer decoy binaries. The initial access vector is assessed to be spear-phishing, with the emails serving as a conduit for an obfuscated Visual Basic Script (aka VBScript) dropper that first performs a series of environment and anti-analysis checks to ensure safe execution. It also enumerates running processes, and

<b>Cybersecurity</b> expert warns AI is making scams harder to detect, Las Vegas a prime target

Updated: 2 hours ago |Las Vegas Metro Police held a First Tuesday event to provide more information about its Search and Rescue team. Updated: 2 hours ago |Steve Grammas spoke to FOX5 about a deadly shootout that killed a Metro Police officer, who was also a Marine veteran. Updated: 2 hours ago |The Pac-12 and Mountain West conferences have finalized an agreement to settle all pending litigation over realignment exit and poaching fees. Updated: 2 hours ago |As students prepare to return to classrooms across Clark County next week, new data show youth vaping remains a significant public health concern. Updated: 3 hours ago |Trump to speak in Las Vegas on Wednesday Updated: 3 hours ago |Las Vegas police held a press conference to release more details about the shooting that killed one officer on Tuesday

NIST Joins National Genesis Mission to Accelerate AI Innovation

GAITHERSBURG, Md. — The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) and the U.S. Department of Energy (DOE) Office of Science have signed a memorandum of understanding establishing a collaboration to use AI-accelerated innovation to address national science and technology challenges established by the Genesis Mission. The Genesis Mission is a whole-of-government initiative, led by the White House Office of Science and Technology Policy, that aims to double the productivity and impact of American science and engineering within a decade by unlocking AI-enabled scientific discovery and innovation. This MOU formalizes NIST’s commitment to that goal. NIST and DOE have deep expertise and a shared interest in applying AI innovation to address critical national challenges and opportunities. The MOU will enable the two agencies to coordinate their efforts and leverage their complementary resources within the context of the Genesis Mission in areas including biotechnology, quantum science, and materials design and discovery. “Our contribution to the Genesis Mission exemplifies NIST’s ongoing commitment to advancing U.S. leadership in critical technologies that are vital to America’s economic and national security,” said Under Secretary of Commerce for Standards and Technology and NIST Director Arvind Raman. “NIST is using innovative public-private partnerships to apply advanced AI to manufacturing and cybersecurity challenges, with initiatives aimed at rapidly delivering high-impact solutions that can be readily transitioned to the private sector.” NIST will execute two of its efforts in support of the Genesis Mission through its Centers for AI in Manufacturing and Critical Infrastructure, a public-private partnership with the nonprofit MITRE Corporation that aims to advance the delivery of AI-based technology solutions to U.S. industry. These efforts will target the Genesis Mission’s national science and technology challenges. Additional areas of collaboration are also being discussed. First, NIST’s AI Economic Security Center for U.S. Manufacturing Productivity

<b>Cybersecurity</b> expert warns AI is making scams harder to detect, Las Vegas a prime target

Cybersecurity expert warns AI is making scams harder to detect, Las Vegas a prime target Check Point Software’s Tony Sabaj says phishing, deepfakes and credential theft are growing threats LAS VEGAS (FOX5) — A cybersecurity expert speaking at the Black Hat conference in Las Vegas says generative AI is making scams significantly harder to identify, with criminals now using the technology to craft phishing emails that sound natural and match a company’s tone. Tony Sabaj, security evangelist at Check Point Software, said AI-generated phishing messages have replaced the typo-filled, poorly written emails that once made scams easier to spot. MORE ON FOX5: Las Vegas cyber security expert shares insight following statewide cyber attack “A lot of times attacks start with phishing emails, and you’re starting to see a lot of the attackers use generative AI to make the emails seem more realistic,” Sabaj said. “Now with generative AI they can make emails seem more natural language.” Las Vegas casinos and hotels called prime targets Sabaj said deep-fake voice and video technology have also advanced, requiring only a few minutes of audio or video to clone a person’s likeness. He said Las Vegas is a high-value target because casinos and hotels hold bank data, gambling habits and travel history. He also warned about fake Wi-Fi hotspots and attempts to read data from digital room keys or unlocked phones. What to do after a data breach Sabaj said when a casino or local business is hacked, stolen login credentials can quickly become ransom material or be sold online. He said criminals frequently use stolen emails and passwords to attempt access to other accounts — particularly bank accounts — because many people reuse the same credentials across multiple platforms. If you receive a breach notice, Sabaj said to activate any free credit monitoring

US water facilities targeted by 'malicious cyber actors' – who's to blame?

Late last week, federal authorities issued a stern warning saying “malicious cyber actors” were targeting water and wastewater facilities in at least seven states across the US. Minnesota appeared to be the hardest hit with 30 of its water systems hit by cyber-attacks, leading to disruptions in the state’s water supply. The problems ranged from low-pressure water flow in people’s homes to some utilities announcing boil-water notices. But there have been no reports of drinking water contamination. “These threat actors are targeting water entities of all sizes,” the US Cybersecurity and Infrastructure Security Agency (Cisa) said in a statement last Thursday. The agency highlighted the fact that critical infrastructure systems can be especially vulnerable to cyber-attacks in the digital age. Much of the problem stemmed from water facilities’ connection to the internet, which made it possible for hackers to infiltrate, change passwords and lock out operators. To mitigate continued disturbances, the agency advised utilities to take their systems offline and switch to manual mode. The culprit of the coordinated attack is suspected to be Iran, according to officials across the government who have spoken anonymously to various news outlets. Tehran has reportedly stepped up its cyber-attacks on the US since the war began nearly six months ago, but so far has only had nominal success. While the FBI announced that it opened an investigation into the hack, it stopped short of putting the responsibility on Iran. Donald Trump, however, has said the attack is Minnesota’s fault. “I blame it on Minnesota because they’re grossly incompetent,” Trump said at a cabinet meeting last Friday at Camp David in Maryland, without providing evidence to support his claims. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota … Iran’s got bigger problems than worrying about Minnesota.” Tim Walz,

The White House Is Keeping Its AI <b>Cybersecurity</b> Framework Secret

The Trump administration has finalized a plan to address the cybersecurity risks posed by increasingly capable artificial intelligence models, a White House official confirmed to WIRED. But at least for now, it’s deliberately keeping the details under wraps, people familiar with the matter tell WIRED. The Trump administration invited staffers from OpenAI, Anthropic, Google, Meta, Nvidia, and other leading AI companies to the White House on Tuesday to share an overview of its new AI oversight framework, the people said. AI developers will have the ability to voluntarily submit new models to the federal government up to 30 days ahead of their public release. The White House will then vet their cyber capabilities according to a classified benchmarking system and share the AI models with federal agencies and trusted corporate partners. The White House isn’t sharing more information about its testing criteria or which AI models will be covered by the framework, though open models will reportedly be excluded, according to Axios. That has left smaller AI startups, safety advocates, and third-party researchers in the dark about crucial aspects of how the federal government is addressing the cyber risks posed by advanced AI systems. Some argue that the secretive process will give an advantage to larger companies. “They're essentially creating an entrenchment program for the big AI model providers, which are now considered the most frontier,” says a person familiar with the White House’s discussions with AI labs, who requested anonymity to discuss confidential matters. “This creates an economic incentive program for critical infrastructure just to use them and leaves out smaller startups.” The White House did not respond to requests for comment. The Trump administration may be keeping its AI security framework confidential because of national security concerns. A second White House official, who requested anonymity because they were

Third-party cyber evaluations involving OpenAI models

Third-party cyber evaluations involving OpenAI models Independent testing plays an important role in helping us validate and further understand risks before deployment. Some cyber evaluations intentionally use custom configurations, including lowered safeguards to measure underlying capability—not how models ordinarily behave in publicly available deployments. During recent evaluations, two external testing partners identified incidents in which testing configurations and controls combined with the advancing capabilities of the recent models allowed for model activity to extend beyond their intended testing boundaries. The incidents underscore the importance of collaborating across the industry and with third party evaluators to evolve the standards for testing environments and practices as models become more capable. Editor’s Note: These are separate from the Hugging Face security incident, and we will continue to share updates on the Hugging Face incident here. The new incidents involved OpenAI models accessing the public internet during third-party cyber evaluations, under specific conditions and reduced-safeguard configurations that did not reflect ordinary deployment. The incidents included: - UK AISI, the UK government’s AI Security Institute, was running cyber-range evaluations with internet access intentionally enabled so agents could find their own tools and operate under conditions closer to a real attacker, and with cyber classifiers disabled to measure underlying capability. You can read their blog here.(opens in a new window) - Irregular, one of our external cybersecurity testing partners, was running Capture-the-Flag-style evaluations intended to be isolated from the internet, but a testing-environment misconfiguration allowed models to access the public internet. Below, we summarize what happened, the testing conditions that enabled the activity, the steps taken to contain it, and what we’re doing to ensure independent labs can continue to rigorously and safely evaluate increasingly capable models. These incidents point to the same broader challenge we described in our recent post about the Hugging Face incident:

The quantum imperative: Why federal <b>cybersecurity</b> cannot wait for tomorrow's threat

The quantum imperative: Why federal cybersecurity cannot wait for tomorrow’s threat The harvest-now, decrypt-later threat is active now. The CRQC timeline moved. The quantum imperative is not a warning, it is an accounting of present dangers. Federal systems face a compounding crisis. Artificial intelligence-driven adversarial attacks are arriving faster than defenders can respond — and the agency charged with protecting government infrastructure has been critically weakened at the worst possible moment. In addition to a rise in classical threats –– ransomware, malware, supply chain attacks –– a quantum computing deadline that once seemed distant has moved uncomfortably close. The window to act is closing. A defense under siege The warnings have accumulated for years, but the reality confronting federal cybersecurity professionals today is no longer theoretical. Government systems — spanning defense agencies, civilian departments, and the critical infrastructure that underpins national life — are under constant adversarial pressure. Every day brings fresh intrusion attempts, credential harvesting operations, and targeted campaigns designed to extract sensitive data from the networks that run the country. These threats have been a constant presence for several years. What is changing — and changing rapidly — is the nature and velocity of those attacks. Artificial intelligence tools have crossed a threshold. Where human-operated intrusion campaigns once required skilled teams, careful planning and months of patient reconnaissance, AI-driven attack platforms are compressing that timeline to hours or minutes. These systems do not sleep. They do not make human errors. They can probe thousands of endpoints simultaneously, adapt to defensive responses in real time, and generate novel attack vectors at a scale that no human analyst can match. The attack surface has not merely grown; it has been fundamentally transformed. At the center of the federal government’s response to this threat sits the Cybersecurity and Infrastructure Security Agency.

<b>Cybersecurity</b> incident triggers dayslong AnMed facility closures

Featured Stories Cybersecurity incident triggers dayslong AnMed facility closures A malware-related incident has disrupted phone, internet and computer systems at the South Carolina system. Skip to main content Featured Stories Cybersecurity incident triggers dayslong AnMed facility closures A malware-related incident has disrupted phone, internet and computer systems at the South Carolina system.

AI officials to discuss regulation of <b>cybersecurity</b> capabilities with White House

AI officials to discuss regulation of cybersecurity capabilities with White House Artificial intelligence companies are meeting with Trump administration officials in Washington, D.C. Tuesday to discuss regulation of the cybersecurity capabilities of what are known as "frontier" AI models. Two sources familiar with the situation, but not authorized to talk about it publicly, confirmed the meeting to NPR. They say it may result in a final version of a framework for cyber regulation to deal with cutting-edge AI models. One source told NPR at the heart of the matter is a benchmarking process to determine which AI models are covered. They're also discussing a process through which companies will voluntarily submit their models for testing and assessment of their cyber capabilities. The meeting comes after a string of new models hit the market, including Anthropic's Mythos, that can quickly find — and potentially exploit — cybersecurity vulnerabilities, something experts and policymakers see as a major AI risk. An NPR editor adapted this audio report by NPR's John Ruwitch.

Columbus Water Works hit by <b>cybersecurity</b> attack, no threat to public water supply

Columbus Water Works hit by cybersecurity attack, no threat to public water supply EMA director says manual operations prevented service disruption COLUMBUS, Ga. (WTVM) - Columbus Water Works experienced a cybersecurity attack on Monday, July 27, according to Columbus Emergency Management Agency Director Chance Corbett. Corbett said the hack affected operating systems that transmit data, such as water usage monitoring, which were not functioning properly. CWW immediately switched to manual operations following the attack. Corbett said the incident did not affect water service to Columbus residents. Agencies notified, investigation ongoing Corbett said any cyber threat to a government agency requires a report to the Georgia Emergency Management Agency. GEMA’s IT support and the FBI have been working to determine the source of the attack. Corbett said there has been no loss of water, no threat to the water supply and no threat to the public. Corbett said if residents had needed to be concerned, CWW would have issued public notifications. He said there was no compromise to water volume, flow or quality. Systems being restored CWW is working to secure any portions of the system that were found to be vulnerable, Corbett said. Not all operating systems are fully functional, and staff are continuing to conduct manual checks. Corbett said the systems are expected to be fully restored by this week. The source of the attack has not been determined. Corbett said he could not speculate on whether the attack is connected to reported hacks of water systems in Minnesota that have been attributed to Iran. Copyright 2026 WTVM. All rights reserved.

NuSummit Joins CREST AI Charter Founding Signatories to Advance Trusted AI in <b>Cybersecurity</b>

NuSummit Joins CREST AI Charter Founding Signatories to Advance Trusted AI in Cybersecurity PLANO, Texas, Aug. 4, 2026 /CNW/ -- Artificial intelligence is changing how organizations approach cybersecurity, from threat detection to security operations. As adoption accelerates, trust, transparency, and accountability are becoming the deciding factors in its success. NuSummit Cybersecurity today announced it has become a Founding Signatory of the CREST AI Charter, joining a group of leading cybersecurity organizations committed to promoting the responsible use of AI across the industry. Through this commitment, NuSummit Cybersecurity supports CREST's Nine Principles for AI-Enabled Activities, ensuring its AI-enabled services are built and delivered with strong governance, security, human oversight and accountability. "Clients don't just want AI, they want AI that is accountable. That is why, as we embed AI deeper into our cybersecurity offerings, we treat governance and human oversight as non-negotiable. Becoming a Founding Signatory of the CREST AI Charter reflects the standard we set for ourselves, so that every AI-enabled solution we deliver is one that our clients can trust and depend on," said Anantharaman Sreenivasan (Ganesh), Managing Director and Group CEO, NuSummit. NuSummit Cybersecurity remains focused on applying AI responsibly, strengthening human expertise, and upholding the highest standards of customer trust. "AI is changing cybersecurity, but trust will determine how successfully organizations adopt it. We believe responsible AI must combine innovation with transparency, governance and human expertise. Becoming a Founding Signatory of the CREST AI Charter reflects our commitment to helping shape a trusted future for AI-enabled cybersecurity," said Sameer Shelke, President Americas and Cybersecurity Services Head, NuSummit, and CEO, NuSummit Cybersecurity. The CREST AI Charter gives organizations an important framework for working through the opportunities and challenges that come with AI. By joining as a founding signatory, NuSummit Cybersecurity is contributing to a shared effort to make