Rep. Cisneros and Rep. Carter proposed reauthorizing an EPA grant program to help small water systems improve cybersecurity and resilience. Quiver AI Summary Bill introduced: Reps. Gil Cisneros and Troy A. Carter, Sr. introduced the "Water Technology and Resilience Reauthorization Act," which would extend an EPA technology grant program for small and disadvantaged water systems, currently set to expire in FY26. Stated aim: The proposal says the funding would support technologies intended to address cybersecurity vulnerabilities in drinking water systems. The release cites recent reports of cyberattacks affecting water infrastructure in several states and says the Metropolitan Water District of Southern California is supporting the measure. Disclaimer: This is an AI-generated summary of a press release. The model used to summarize this release may make mistakes. See the full release here. Check out the Quiver Quantitative API to build on top of data on congressional stock trading, insider transactions, hedge fund moves, and more. Gilbert Ray Cisneros, Jr. Fundraising Gilbert Ray Cisneros, Jr. recently disclosed $98.6K of fundraising in a Q4 FEC disclosure filed on January 30th, 2026. This was the 768th most from all Q4 reports we have seen this year. 21.0% came from individual donors. Cisneros disclosed $82.2K of spending. This was the 808th most from all Q4 reports we have seen from politicians so far this year. Cisneros disclosed $111.7K of cash on hand at the end of the filing period. This was the 1019th most from all Q4 reports we have seen this year. You can see the disclosure here, or track Gilbert Ray Cisneros, Jr.'s fundraising on Quiver Quantitative. Gilbert Ray Cisneros, Jr. Net Worth Quiver Quantitative estimates that Gilbert Ray Cisneros, Jr. is worth $81.3M, as of August 13th, 2026. This is the 19th highest net worth in Congress, per our live estimates. Cisneros
Aug 13, 2026 · via quiverquant.com
Siemens Siveillance Video Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affected: - Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014) - Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014) - Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014) | CVSS | Vendor | Equipment | Vulnerabilities | |---|---|---|---| | v3 9.1 | Siemens | Siemens Siveillance Video | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | Background - Critical Infrastructure Sectors: Critical Manufacturing, Communications, Commercial Facilities - Countries/Areas Deployed: Worldwide - Company Headquarters Location: Germany Vulnerabilities CVE-2026-3014 Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. Affected Products Siemens Siveillance Video Siemens Siveillance Video V2023 R3 < V23.3.27, Siveillance Video V2024 R1 < V24.1.16, Siveillance Video V2025 < V25.1.15 known_affected Remediations Vendor fix Update to V23.3 HotfixRev27 or later version https://support.industry.siemens.com/cs/ww/en/view/109827783/ Vendor fix Update to V24.1 HotfixRev16 or later version https://support.industry.siemens.com/cs/ww/en/view/109976123/ Vendor fix Update to V25.1 HotfixRev15 or later version https://support.industry.siemens.com/cs/ww/en/view/109988670/ Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics | CVSS Version | Base Score | Base Severity | Vector String | |---|---|---|---| | 3.1 | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H | Acknowledgments - Milestone PSIRT reported this vulnerability to Siemens General Recommendations As a general security measure Siemens strongly recommends to protect network access to affected products with appropriate mechanisms. It is advised to follow recommended security practices in order
Aug 13, 2026 · via cisa.gov
Updated: 3 hours ago
New Marshall University students gathered Thursday at the Joan C. Edwards stadium to watch “We are Marshall.’
Updated: 3 hours ago
Valley Vital Care of Charleston celebrated its grand opening with a ribbon-cutting ceremony on Thursday.
Updated: 3 hours ago
The Greenbrier is potentially shutting down its casino on Friday.
Updated: 3 hours ago
New details have emerged in a deadly chemical incident that happened earlier this year in Kanawha County, West Virginia.
Aug 13, 2026 · via wsaz.com
AI Systems Create New Security Challenges Unlike traditional software, AI systems rely on data, models and ongoing learning processes. As a result, they can fail in ways that conventional cybersecurity programs were not designed to address. An AI application may remain online and appear to function normally while producing inaccurate recommendations, biased results or unreliable outputs. Problems with data quality, compromised models or unexpected changes in operating conditions can all affect AI performance without causing a traditional system outage. That distinction makes resilience especially important. Organizations must not only protect AI systems from cyberattacks but also ensure they continue delivering trustworthy results throughout their lifecycle. For government agencies making decisions based on AI-generated insights, maintaining confidence in those results becomes just as important as maintaining system availability. READ MORE: Here is a guide to AI governance for state and local governments. Cyber Resilience Must Evolve Alongside AI For years, cyber resilience has centered on preparing organizations to prevent, withstand and recover from cyber incidents. Backup strategies, disaster recovery plans and business continuity efforts all contribute to that objective. AI expands the definition of resilience. Instead of asking only whether an application remains operational, organizations must also consider whether AI-generated outputs remain accurate, explainable and aligned with organizational objectives. This broader perspective recognizes that an AI system can continue operating even when its results should no longer be trusted. Recovering from that type of failure may require organizations to validate models, verify data integrity or restore previous versions of AI systems rather than simply restarting an application. As AI assumes a greater role in operational decision-making, these capabilities become increasingly important.
Aug 13, 2026 · via statetechmagazine.com
Updated: 3 hours ago
New Marshall University students gathered Thursday at the Joan C. Edwards stadium to watch “We are Marshall.’
Updated: 3 hours ago
Valley Vital Care of Charleston celebrated its grand opening with a ribbon-cutting ceremony on Thursday.
Updated: 4 hours ago
The Greenbrier is potentially shutting down its casino on Friday.
Updated: 4 hours ago
New details have emerged in a deadly chemical incident that happened earlier this year in Kanawha County, West Virginia.
Aug 13, 2026 · via wsaz.com
JPS network offline for 10 days after suspected cybersecurity breach
JPS Health Network remains offline 10 days after detecting suspicious activity. Fort Worth ambulances continue to divert patients to other hospitals as JPS works to secure its systems.
Aug 13, 2026 · via cbsnews.com
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and social engineering campaign orchestrated by Pyongyang-backed hackers to target professionals worldwide with fake-but-compelling job offers at firms like Lockheed Martin and Enveil to steal sensitive data and install malware by approaching them on platforms like LinkedIn, pretending to be recruiters in an attempt to build trust. The attacks have been found to exploit CVE-2026-68820 (CVSS score: 7.0), a privilege escalation flaw affecting Windows Ancillary Function Driver for WinSock ("AFD.sys") that was patched by Microsoft as part of its Patch Tuesday updates for August 2026. As observed in prior campaign waves, victims are lured through bogus recruiter messages and tricked into opening a malicious PDF or installing a trojanized PDF viewer, which is then used to install a new backdoor called Troy that grants remote access to the compromised machine. The end goal of these intrusions is to seize complete control of infected computers and bypass security controls. The use of a trojanized PDF viewer is a tried-and-tested tactic adopted by the Lazarus Group in conjunction with Dream Job, with the threat actors abusing this method as far back as 2022. Two different parallel infection sequences have been detected as part of the latest attacks - - DLL side-loading, in which victims are instructed to download an encrypted archive that's used to trigger a DLL side-loading chain. The malicious DLL ("libmupdf.dll") is used to display a bogus job description lure, while it stealthily downloads and executes in memory a lightweight downloader dubbed MISTPEN.
Aug 13, 2026 · via thehackernews.com
Lawmakers have been pushing forward various bills over the last several weeks, all aiming to reshape different aspects of federal employment and benefits. Most recently, proposals on Capitol Hill have sought to address issues such as workplace health and safety, employee benefits, cybersecurity protections and hiring practices. Heading into the fall, here are just a handful of the current efforts in Congress that may bring changes for federal employees. Identity protection for feds Democrats, for one, are seeking to boost protections for federal employees. Sen. Mark Warner (D-Va.) and Del. Eleanor Holmes Norton (D-D.C.) introduced a bill earlier this month, called the RECOVER PII Act. It would offer lifetime identity protection coverage to federal employees and contractors who were impacted by the 2015 data breach at the Office of Personnel Management. A major cybersecurity incident in 2015 at OPM compromised personal information of about 22 million individuals who were associated with the federal government. Although victims of the data breach, at the time, were afforded 10 years of identity protection coverage from Congress, that benefit is set to expire on Sept. 30 this year. The new legislation seeks to extend coverage to qualifying individuals for life. “More than 10 years after the OPM data breach exposed the personal information of millions of federal employees, the threat remains,” Warner said. “We have a responsibility to stand by the federal workers who were put at risk through no fault of their own.” Currently, eligible federal employees get 12 weeks of unpaid leave under the Family and Medical Leave Act (FMLA) — a benefit that is also available to private sector employees. Although federal employees have access to paid parental leave due to a 2019 law, family and medical leave remains unpaid time off. The new legislation, led by Sen. Brian Schatz (D-Hawaii),
Aug 13, 2026 · via federalnewsnetwork.com
AI dominated the conversation at Black Hat USA 2026, from wide-ranging explanations of risks faced today through to a vast array of presentations claiming that AI was, in some way, responsible for the cyberthreat plaguing us. The conference opened with keynotes followed by a fireside chat and a panel featuring mainly senior US government officials. First up was Sean Cairncross, the White House National Cyber Director, who set out the case that regulation of AI would both stifle innovation and development and struggle to keep pace with the speed at which AI is currently moving. It was clear from the discussion that there is an AI ownership race, with Mr. Cairncross claiming that “AI is a tremendous story of American innovation” and making various other comments on how America leads the world in this field. I am sure there are many of you who, like me, read this point of view with a shrug of the shoulders. The internet at large is a global resource that no individual, or group of people, can claim is their invention or innovation – and this is certainly true also for the rise of AI. During the opening talks there was even the mention of some companies that have been instrumental to the innovation of ‘AI made in America.’ One of the companies mentioned is based in London, which made the claim even more preposterous. Mr. Cairncross also noted that the US government is looking at ways to build a US open-source infrastructure that the rest of the world can benefit from. The future is one where all of us pull together to create a robust vision and strategy on how the emerging AI functionality can be used safely, efficiently, responsible and without risk. The second part of the opening keynote included Nick Andersen,
Aug 13, 2026 · via welivesecurity.com
PERSPECTIVES FROM THE CAMPUS One of the strengths of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the colleges, universities, and other institutions of higher education throughout our state. Hence the name, “Perspectives from the Campus”, we invite experts – immersed in the pursuit of educating their students – to offer their knowledge for finding solutions in cybersecurity that benefit all Hoosiers. In the latest installment of this series, David Dungan, who serves as the executive director at the Center for Security Services and Cyber Defense at Anderson University, discusses how a Virtual Private Network (VPN) can protect us when we’re online, especially when it comes to connecting to public (and often free) Wi-Fi networks. He also shares his perspective on the cyber risks related to “sharing our story” and why the convenience – even in a place we believe is OK – may not be worth it, without first making sure that you’ve secured your data. By David Dungan Phishing is a common method used by threat actors to steal personal information, install malware, and manipulate the goodwill of users across the world. Despite the rise of Cybersecurity awareness programs and phishing detection tools, Phishing campaigns and similar social engineering attacks are still some of the most common cyber threats out there. In light of these recent trends, combating new campaigns and strategies has never been more important. The Rise of AI (Artificial Intelligence) has given new teeth to age-old cyber threats, bolstering the complexity of phishing attacks and making them harder to detect by automated tools or human analysis. Supplying curated information to AI systems allows it to compile an untold number of personalized emails and custom-built messages made for the sole purpose
Aug 12, 2026 · via in.gov
Five paradoxes shaping the future of cybersecurity The Current issue 15 The 5th edition of the Deloitte Global Future of Cyber Survey unpacks five critical paradoxes facing cyber leaders today, revealing how "Frontrunner" organizations are turning these tensions into a competitive advantage. The confidence paradox: Confidence is outpacing the implementation of recommended cyber actions by a 15 percentage-point gap among survey respondents. The influence paradox: Executive support for cyber is strong, cyber influence remains concentrated in IT and risk management rather than embedded across the broader business. The vendor paradox: Many respondents are showing a growing interest in integrated cyber platforms, yet 74% said the number of cyber partners they work with increased or significantly increased over the past year. The breach paradox: 78% of organizations publicly reported at least one breach in 2025, while only 52% reported significant business impact. The budget paradox: Cyber budgets are stable, predictable, and planned years in advance. The threat landscape is wildly unstable, volatile, and unpredictable. The concept of "digital trust" is a major topic right now—how do you define it in practice, and what does it look like for your organization? Digital trust is huge, and it starts with fundamentally understanding where your data is, who is using it, how it is being used, and whether or not you can protect it effectively regardless of where it sits. For us, digital trust means our customers must be absolutely comfortable that the data we send them is exactly what they are expecting, and that it is actual and factual. At times, security controls are viewed as a hindrance—how have you been able to help reframe that perception for people? A classic example is the restriction of personal webmail. Employees often complain that blocking these services prioritizes administrative inconvenience over actual security, which can
Aug 12, 2026 · via deloitte.com
Artificial intelligence (AI) is no longer just helping cybersecurity teams find suspicious activity. It is starting to find vulnerabilities, test attack paths and, in some cases, act in ways that stretch the limits of the systems built to contain it. A clear directional signal for the landscape came Friday (Aug. 7), when OpenAI said preliminary tests of its upcoming Astra model were strong enough that the company could not rule out its highest cybersecurity warning level, known as the “Critical” threshold. Under OpenAI’s preparedness framework, that level means a model may be able to independently discover and develop working zero-day exploits against real-world systems or carry out cyberattacks from a high-level objective. The International Monetary Fund (IMF) reached a similar conclusion from a financial-stability perspective in a recent report. The organization’s central argument for its note entitled “Artificial Intelligence and Cybersecurity in the Financial Sector” was that AI does not need to invent fundamentally new forms of cyberattack to change the risk equation. By accelerating vulnerability discovery and exploitation across shared technologies, AI can turn weaknesses that once produced isolated incidents into correlated disruptions affecting multiple institutions simultaneously. That is a major development because the question is no longer only whether AI can write better phishing emails or help security teams sort through alerts. The question is what powerful models can do when given tools, credentials, network access or a poorly configured test environment. For banks, FinTechs, merchants and critical infrastructure operators, that changes AI cyber risk from a security-team concern into an enterprise governance problem. The question is no longer simply whether companies should use AI in cybersecurity. It is how much autonomy those systems should receive, what they should be allowed to touch and whether organizations can contain them when something goes wrong. See more: Wall Street’s New
Aug 12, 2026 · via pymnts.com
a NIST blog For over two decades, the NIST National Vulnerability Database (NVD) has served as the U.S. government repository for standards-based vulnerability management data and as a foundational resource for cybersecurity risk analysis, vulnerability management, compliance automation, and software security. New Opportunities for the NVD via Automation Our cybersecurity landscape is changing dramatically and is being reconfigured by artificial intelligence (AI) in unique, exciting, and yes, sometimes challenging ways. This is creating openings to potentially leverage AI systems to discover and exploit vulnerabilities — but AI can also serve as a valuable tool to strengthen cybersecurity and speed up response times. As the volume of reported vulnerabilities surges and emerging technologies reshape the threat picture, it is time for traditional vulnerability management practices centered on periodic patching and manual remediation to be transformed toward continuous, automated, and contextual vulnerability management. With the rapid growth of AI-enabled cyber tools and dramatically accelerated technology delivery cycles, NIST aims to improve the NVD’s scalability, automation, interoperability, transparency, and utility — modernizing it for the future. To guide this transformation, NIST released a Request for Information (RFI) and is seeking feedback, especially from technical experts, industry and government leaders, researchers, cybersecurity professionals, and software vendors. This is an “all hands-on deck” moment for this community. Your voice matters. We want to understand your priorities and challenges and to learn about opportunities you see to improve vulnerability management. We are committed to providing you with the information and tools you need to anticipate and deal with software vulnerabilities. Steps We’ve Already Taken We have already begun work on a tool, called V-etalon, that leverages AI technologies to aid in enriching vulnerability information. We hope that V-etalon will eventually provide a foundation for the evaluation of vulnerability information. We will be looking for feedback and
Aug 12, 2026 · via nist.gov
Peachtree Corners, GA, Aug. 12, 2026 (GLOBE NEWSWIRE) -- Senteon is proud to announce that during Black Hat USA 2026, the company was named a finalist in both the Top InfoSec Innovator Awards and Top 25 Most Innovative Cybersecurity Companies in the World 2026 by Cyber Defense Magazine (CDM), a leading electronic information security magazine. 2026 Top 25 Most Innovative Cybersecurity Companies In The World Judging continues through October 2026, with winners to be announced online, in print, and during CyberDefenseCon 2026, taking place October 20–21, 2026, at The Ritz-Carlton in Orlando, Florida. A select group of winners will have the opportunity to showcase their innovative solutions to top global CISOs during the invitation-only conference. Learn more at https://www.cisoconference.com. “Being named a finalist among some of the most innovative cybersecurity companies in the world is an incredible honor,” said Henry Zhang, CEO of Senteon. “Organizations are managing thousands of security configurations across constantly changing environments, and even a single configuration change can introduce unnecessary risk. At Senteon, we’re focused on making endpoint hardening and configuration integrity continuous, measurable, and manageable at scale. This recognition reinforces our belief that preventing configuration drift and maintaining hardened systems should be a fundamental part of every organization’s cybersecurity strategy.” “Senteon embodies three major features we judges look for with the potential to become winners: understanding tomorrow’s threats, today, providing a cost-effective solution and innovating in unexpected ways that can help mitigate cyber risk and get one step ahead of the next breach,” said Gary S. Miliefsky, Publisher of Cyber Defense Magazine. Senteon is honored to be included among this distinguished group of finalists in the Cyber Defense Awards. About Cyber Defense Awards This is Cyber Defense Magazine’s thirteenth year of honoring InfoSec innovators from around the globe. Submission requirements are open to startups, early-stage,
Aug 12, 2026 · via daily-tribune.com
Cybersecurity company Rapid7 is cutting around 12 per cent of its workforce. The company is restructuring its organisation and redirecting resources towards its core platform and AI-led security capabilities. The restructuring began in the second quarter of 2026 and is aimed at simplifying the company’s organisational structure and aligning teams more closely with its Core Platform Solutions. Around 12 per cent of employees have been informed that their roles will be affected. Rapid7 expects the restructuring to result in charges of approximately $10 million to $11 million. Most of the costs are expected to come from employee severance and related expenses. The workforce reduction comes as Rapid7 accelerates a broader shift towards an AI-first approach to cybersecurity. The company has strengthened its leadership team with the new appointments. Rapid7 is also expanding its use of generative and agentic AI in security operations. Through OpenAI’s Trusted Access for Cyber programme, the company is incorporating models including GPT-5.5 into its Agentic SOC workflows. Rapid7 said the technology has helped speed up the process of analysing security telemetry and cut false-positive queue times by 25 per cent. The company has also joined Anthropic’s Project Glasswing, where it will work on defensive engineering, detailed code reviews and automated vulnerability remediation. The restructuring comes as Rapid7 manages modest declines in key financial metrics. The company reported quarterly revenue of $210.9 million and annual recurring revenue (ARR) of $824 million, both slightly lower than the previous year. Despite the workforce reduction and restructuring costs, Rapid7 generated $31.9 million in free cash flow during the quarter. It ended June with $702.6 million in cash, cash equivalents and government securities. The changes indicate a broader shift in the company’s workforce strategy, with resources being moved away from existing organisational structures and towards AI-driven products and cybersecurity capabilities.
Aug 12, 2026 · via hrkatha.com
OpenAI's (OPENAI) series of cybersecurity-focused models, Daybreak, are now available through the Amazon Web Services (AMZN) Bedrock platform, the company announced today.
This includes Daybreak Blue and Daybreak Red. Daybreak Blue provides access to frontier general-purpose models, including GPTâ5.6 Sol, with safeguards
Aug 12, 2026 · via seekingalpha.com
Darlington Co. investigating cybersecurity incident affecting some services DARLINGTON COUNTY, S.C. (WPDE) — Darlington County officials are investigating a cybersecurity incident affecting some county computer systems and limiting certain services. Darlington County Administrator Marion “Charles” Stewart III said some systems have been proactively taken offline as officials work to address the incident. As a result, some county services are available in a limited capacity. Emergency services remain fully operational, Stewart said. The incident has not affected the county’s 911 communications center or its ability to receive calls and dispatch emergency responders. MORE: Former Florence teacher accused of solicitation of a minor, deputies say Darlington County is working with third-party cybersecurity specialists and law enforcement agencies at multiple levels to investigate the incident and restore full functionality to the county’s network as quickly and securely as possible. “The investigation remains active and ongoing, and we have significant resources dedicated to this process,” Stewart said in a statement. Stewart said the county continues to provide services to residents and the public while working to restore the affected systems. The following statement was released by the Darlington County Government: "We are working with third-party cybersecurity specialists and law enforcement agencies at all levels to restore full functionality to our network as quickly and securely as possible. As part of our response process, certain systems have been proactively taken offline, and some County services are available in a limited capacity. The investigation remains active and ongoing, and we have significant resources dedicated to this process." County officials said additional updates will be provided as more information becomes available.
Aug 12, 2026 · via wpde.com
COMMENTARY: For more than a decade, the cybersecurity industry has told itself the same story: there aren't enough skilled people to do the work, and to fix it we need more hiring, more training programs, more pipeline investment.Every year the workforce gap gets cited again, slightly larger than the year before, as proof the strategy isn't working fast enough. Maybe it's time to consider a less comfortable explanation: the strategy was never going to work, because hiring was never the actual constraint.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]Security operations centers (SOCs) don't have a people problem. They have a throughput problem, and the two look identical on a staffing report while being completely different in cause.Alert volume scales with attack surface — more cloud services, more endpoints, more third-party integrations, more identities to track — and attack surface has been growing exponentially for years. Headcount, even in a generous hiring environment, grows linearly at best. We cannot out-hire an exponential curve. No SOC has ever closed this gap by adding analysts faster than the alert volume grew, and none ever will, because the two are growing on different curves entirely.What that means in practice: the "shortage" isn't a shortage of qualified people. It's a mismatch between a triage workload that scales with infrastructure and a workforce that scales with budget cycles. Framing it as a hiring problem set the entire industry chasing a fix that was structurally incapable of closing the gap, no matter how much was spent on it.Where the actual bottleneck livesMost SOC analyst time doesn't go to the high-judgment work — the actual threat hunting, the incident response that requires real expertise. It goes to triage: Is this alert real? Does it matter?
Aug 12, 2026 · via scworld.com
Managing Cybersecurity Risk is a Non-Negotiable for Organizations – But Can Be Expensive Cybersecurity is no longer a "nice to have" for organizations; it is a must. And the resources required to build, maintain, and monitor a layered cybersecurity architecture around the clock are costly. Now more than ever, organizations are outsourcing their cybersecurity needs to third-party vendors to the tune of more than $200 billion globally in 2025. Not only is outsourcing cybersecurity needs often a more cost-efficient strategy, but it is also a means for organizations to transfer some of their cybersecurity risk. Organizations often rely on the belief, and provide assurances of the same to customers and regulators, that their networks, systems, and data are safe with their cybersecurity vendors on guard to detect and respond to suspected threats. However, it is only when something goes wrong that the effectiveness of the risk transfer is fully understood. When cybersecurity service agreements fail to capture and transfer the intended risks, the resulting legal consequences can be costly, leaving organizations managing regulatory scrutiny and litigation on multiple fronts, including with their own cybersecurity vendors. To avoid these costly battles, organizations should scrutinize the cybersecurity vendor agreements from both a legal and technical point of view. How these agreements define the scope of the services and obligations of the parties or otherwise limit liability can be the difference of millions of dollars when something goes wrong. Scope of Services The starting point for any cybersecurity services agreement is a clear understanding of exactly what the vendor is responsible for doing – and just as importantly, what it is not responsible for doing. The broad umbrella of "managed security services" can sound all-encompassing, but agreements often differ in terms of the functions and duties the vendor is obligated to perform. While
Aug 12, 2026 · via bakerdonelson.com
The Cybersecurity and Infrastructure Security Agency (CISA) on Aug. 12 released a new package of cybersecurity resources to help K-12 schools and districts prevent, mitigate, and respond to cyber threats. The K-12 Cybersecurity Foundations Resource Package includes guides, a six-part video series, and quick-reference materials tailored to school leaders, non-technical staff, and cybersecurity and IT professionals, according to a press release from the agency. “Cyberattacks on K-12 schools and districts jeopardize not only the integrity of our educational mission, but the safety and security of our students and teachers as well,” said Nick Andersen, CISA’s acting director. “These impacts are often felt well beyond the classroom.” “The K-12 Cybersecurity Foundations Resource Package empowers school communities with practical strategies and supports our school safety mission,” Andersen added. “CISA is helping the K-12 community proactively defend against cyber threats, minimize disruption and better protect the systems our nation’s children, parents and educators depend on every day.” CISA said schools and districts face increasing cybersecurity threats because they maintain sensitive student and staff data, depend on a range of technologies and systems, and have users with varying access privileges. The agency also pointed to limited resources for cybersecurity programs as a risk for K-12 institutions. Cyber incidents can disrupt school operations and learning, compromise student privacy and safety, and consume limited resources, CISA said. The package features a Getting Started Guide and a more detailed Implementation Guide. The guides organize cybersecurity practices around eight objectives: - Protecting login credentials - Safeguarding devices and assets - Testing backups - Strengthening incident response capabilities - Improving cybersecurity training - Appropriately managing sensitive data - Aligning investments with recognized cybersecurity frameworks - Developing customized long-term plans “K-12 cybersecurity has evolved beyond an IT department concern and must now be recognized as a fundamental pillar of school
Aug 12, 2026 · via meritalk.com