No-frills tech news

Index Ventures raises $3.5 billion to expand AI and Israeli startup investments | Ctech

Index Ventures raises $3.5 billion to expand AI and Israeli startup investments The global venture firm behind Wiz launches new seed, venture and growth funds as it increases its focus on cybersecurity, infrastructure and artificial intelligence. Index Ventures has raised $3.5 billion in new funds that will be used to invest across all stages of company building, including a significant focus on artificial intelligence, cybersecurity and infrastructure startups. The new capital includes a $400 million seed fund, a $900 million venture fund, and a $2.2 billion growth fund, expanded from the firm’s previous $1.5 billion growth vehicle. The firm said its strategy remains focused on identifying founders early and supporting them throughout their growth journey. "From day one, we built Index around a single conviction: that great founders can come from anywhere," the firm said. "Our job is to find the best people early and stay with them for as long as it takes." For Israel, the announcement strengthens Index’s position as one of the most active international investors in the local technology ecosystem. Index has invested in Israeli companies for two decades and has built a portfolio that includes some of the country’s most successful technology companies, including Wiz, Gong, Fireblocks, Capitolis and Empathy. The firm was one of the earliest institutional investors in Wiz, the cloud security company founded by former Adallom executives Assaf Rappaport, Ami Luttwak, Roy Reznik and Yinon Costica. Wiz was acquired for $32 billion by Google, a deal that generated an estimated $4.3 billion return for Index based on its reported ownership stake. Index has increased its activity in Israel in recent years, particularly around artificial intelligence, cybersecurity and infrastructure. Juriaan Duizendstraal, the Index partner leading the firm’s Israeli activity, said late last year that the fund had completed 16 Israeli investments over three

<b>Cybersecurity</b> in healthcare and insurance: building trust in a high-risk digital ecosystem

Cybersecurity in healthcare and insurance: building trust in a high-risk digital ecosystem Chloe Fox speaks to experts about how healthcare’s growing digital connectivity is transforming cybersecurity through zero trust, legacy risks, AI, and telemedicine As healthcare providers, insurers, and assistance companies rely more heavily on digital infrastructure, cybersecurity is no longer just an IT concern. Large volumes of sensitive data – from medical records and payment details to travel itineraries and personal identifiers – are constantly exchanged between insurers, hospitals, third-party administrators (TPAs), telemedicine providers, and travellers. This interconnectedness improves efficiency and claims handling, but it also expands the attack surface for cybercriminals, with ransomware attacks on hospitals and pressure on insurers to demonstrate resilience and secure data handling. Elena Glukhman, Business Development Manager at AP Companies Global Solutions, also emphasised the importance of structurally embedded cybersecurity: “At AP Companies, cybersecurity has evolved from being primarily an IT function into a core operational and governance priority,” she said. “As a global TPA and medical assistance provider handling sensitive medical and insurance data across multiple jurisdictions, we recognise that traditional perimeter-based security models are no longer sufficient. “Our approach today is increasingly aligned with zero trust principles – meaning that no user, device, or connection is automatically trusted, even within internal environments,” she explained. “Access to systems and medical information is granted based on strict identity verification, role-based permissions, and the principle of least privilege.” She added that segmentation helps limit the impact of potential breaches: “Operational environments, claims systems, financial systems, and medical data repositories are separated and controlled to minimise lateral movement in the event of a security incident.” According to Dominic Steptoe, Global Chief Product Officer at BOXX Insurance, a layered approach to security is becoming essential: “Zero trust and data segmentation within an organisation’s network is a

Why AI automation needs human judgement in <b>cybersecurity</b>

AI adoption highlights need for human oversight skills Artificial intelligence is not only replacing routine work but also creating a major new demand for verifying its outputs, a trend largely overlooked in industry debate, according to a recent piece of analysis by Shilpi Handa, associate research director at market intelligence firm IDC. Every discussion about AI has focused on the risk that it will compress services revenue and force changes to headcount-driven models, yet this narrative captures only half the picture, Handa argued. “Every industry conversation about AI right now seems to circle the same warning: it will do most of the routine work, services revenue will compress, and headcount-based business models must change to stay competitive,” Handa said. That warning is accurate but incomplete, she noted, as it ignores the growing need for humans capable of checking whether AI systems have performed tasks correctly. Handa pointed to a 1983 study by cognitive psychologist Lisanne Bainbridge, which found that greater automation increases the complexity of human roles rather than reducing it. “The more comprehensively you automate a system, the more demanding, not less, the remaining human role becomes,” Bainbridge wrote. The research showed that as automation takes over routine tasks, humans are left with rare, complex situations and the responsibility of supervising systems whose failures they rarely encounter, leading to skill deterioration over time. “The automation is usually right, until the day it isn’t,” Bainbridge warned. Handa linked this phenomenon to real-world consequences, citing a 1987 Northwest Airlines crash in Detroit that killed 154 people after pilots relied on an automated system that failed without their knowledge. The crew, accustomed to automation, did not manually verify the aircraft’s configuration, illustrating how skills can erode when systems appear consistently reliable. Similar patterns are now emerging across industries adopting AI tools at

SkillSpector: NVIDIA's open-source security scanner for AI agent skills

SkillSpector: NVIDIA’s open-source security scanner for AI agent skills SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of findings, a risk score, and recommendations. The folder it reads runs with everything you have. A skill is Markdown instructing the agent, sometimes with a Python script beside it that reaches the shell, the environment variables, and the SSH directory. The script is where risk concentrates. The study behind the tool found skills that ship one are 2.12x more likely to be vulnerable. Agents load them on trust. How it reads a skill The first pass is static and takes seconds. An AST walk flags exec, eval, subprocess, and dynamic imports. A taint tracker follows environment variables and file contents to network sinks. YARA rules match known malware, webshells, and cryptominers. Regex analyzers handle the rest of the 64 detection patterns, covering prompt injection, credential access, memory poisoning, typosquatted dependencies, and cron-job persistence. Some patterns exist only because a skill is a prompt. One flags a trigger that shadows a built-in command, so the agent reaches for the skill when the user typed something ordinary. Another flags homoglyphs and right-to-left overrides in tool metadata. A third flags zero-width characters and HTML comments carrying directives a human reviewer scrolls right past. Dependency checking goes out to the network. SkillSpector batches a skill’s package list into one query to OSV.dev, gets back known CVEs, and caches the answer for an hour. An air-gapped run falls back to a small built-in list. A second pass is optional, slower, and off until you configure it: it needs an OpenAI-compatible endpoint and a key, set through

Monash partners with <b>cyber security</b> firm to launch AI-focused <b>cybersecurity</b> degree

Monash University has partnered with Australian company CyberCX to launch a new undergraduate degree designed to address Australia’s growing demand for cyber security professionals with expertise in artificial intelligence. The three-year bachelor of CyberAI (Industry Co-Lab), available to domestic students from the first semester of 2027, was unveiled by Monash vice-chancellor Professor Sharon Pickering and CyberCX chief executive John Paitaridis last week. The program has been co-designed with the cyber security provider and aims to prepare graduates to secure AI systems and respond to sophisticated cyber threats. A central feature of the degree is an industry immersion model, in which students undertake supervised, curriculum-aligned placements with CyberCX during the second and third years of the course. The company will also offer eligible graduates a pathway into its CyberCX Academy, with up to 15 places available each year, subject to suitability and workforce demand. Pickering said the degree combines academic research with practical industry experience to help address Australia’s cyber security workforce shortage. “As a top 40 world-ranked and Australia’s most industry-connected university, Monash is uniquely positioned to lead the development of the highly specialised cyber security workforce Australia urgently needs to thrive in an AI-enabled economy and society,” Pickering said. Paitaridis said demand for professionals with both AI and cyber security expertise was increasing rapidly as organisations adopted advanced AI technologies. “Developing skilled talent has never been more important in cyber security with the rapid adoption of frontier AI models accelerating the cyber challenges facing our industry and economy,” Paitaridis said. The course will cover secure systems, cyber security operations, and AI technologies before progressing to the design and management of secure AI systems in real-world environments. Students will also have access to a Secure AI Lab developed jointly by Monash and CyberCX, with a focus on AI ethics, privacy,

PHP Multiple Vulnerabilities

PHP Multiple Vulnerabilities Release Date: 3 Aug 2026 498 Views RISK: Medium Risk TYPE: Servers - Internet App Servers Multiple vulnerabilities were identified in PHP. A remote attacker could exploit some of these vulnerabilities to trigger remote code execution, security restriction bypass, denial of service condition, sensitive information disclosure and data manipulation on the targeted system. Impact - Remote Code Execution - Security Restriction Bypass - Data Manipulation - Denial of Service - Information Disclosure System / Technologies affected - PHP version prior to 8.5.9 - PHP version prior to 8.4.24 - PHP version prior to 8.3.33 - PHP version prior to 8.2.33 Solutions Before installation of the software, please visit the software manufacturer web-site for more details. The vendor has issued a fix: - PHP 8.5.9 - PHP 8.4.24 - PHP 8.3.33 - PHP 8.2.33 Vulnerability Identifier Source Related Link Related Tags Share with

The Federal Cyber Certification Series

The Federal Cyber Certification Series The Federal Cyber Certification Series Virginia, USA November 2 – 3, 2026 The Federal Cyber Certification Series is designed to help product developers, cybersecurity leaders, federal suppliers, cloud providers, software vendors, testing laboratories, systems integrators, standards organizations, and government agencies better understand the rapidly evolving compliance landscape that is reshaping the future of technology procurement and market access. This unique event brings together experts from government, industry, standards bodies, testing laboratories, and the cybersecurity research community to provide practical guidance on the policies, frameworks, technical standards, and operational realities driving the next generation of cybersecurity assurance requirements. The event is organized into four focused conference modules, each addressing one of the most urgent areas affecting ICT product development and federal market readiness today: .IoT Cyber Compliance Day explores the collision of emerging U.S and international cybersecurity regulations impacting connected devices, embedded systems, software transparency, secure-by-design initiatives, and vulnerability disclosure obligations. Software Supply Chain Day examines the rapidly expanding world of SBOM requirements, secure software development, vulnerability management, provenance, and software assurance expectations transforming both government and commercial procurement. FedRAMP Day provides critical insight into the modernization of federal cloud authorization, continuous monitoring, OSCAL automation, cloud-native security architectures, and evolving operational compliance expectations under FedRAMP 20X. Post-Quantum Action Plan Day delivers practical, implementation-focused guidance for organizations preparing for the transition to post-quantum cryptography, including crypto inventories, migration planning, certification impacts, supplier readiness, and long-term product strategy. Unlike traditional policy conferences, the Federal Cyber Certification Series is built around practical execution. Attendees will gain actionable insight into how emerging cybersecurity mandates affect product design, software development, procurement eligibility, certification pathways, cloud operations, cryptographic modernization, and long-term competitive positioning in regulated markets. As federal cybersecurity policy increasingly drives global technology requirements, organizations that understand these changes early will

Map Shows States Hit By Cyberattacks on Water Systems

A wave of cyber incidents targeting water and wastewater infrastructure has put utilities across multiple states on high alert, as federal authorities investigate attacks that have disrupted operations and exposed vulnerabilities in critical public services. The FBI and Environmental Protection Agency (EPA) warned on July 30 that malicious cyber actors had targeted water and wastewater systems in at least seven states since July 27, 2026, causing operational disruptions and, in some cases, degrading water operations. Since then, incidents in fours states appear to match the federal warning. What the FBI Said According to the FBI alert, attackers targeted internet-facing Programmable Logic Controllers (PLCs), which are devices used to monitor and control industrial equipment at water and wastewater facilities. The agency said hackers altered IP addresses and passwords, causing utilities to lose monitoring and control capabilities. Reported consequences included flooding and pressure loss in affected systems. Federal officials said water utilities reported incidents in at least seven states—at the time of reporting, the agencies haven’t identified the affected states—and urged operators to remove exposed control systems from the public internet and strengthen cybersecurity protections. Newsweek has reached out to the FBI for clarification on which states have been affected, and also the Cybersecurity and Infrastructure Security Agency (CISA) for further details about the attacks. Minnesota Reports More Than 30 Attacks The largest publicly disclosed cluster of incidents has emerged in Minnesota. Earlier this week, state officials said cyberattacks had targeted more than 30 water systems across the state. The attacks drew national attention after President Donald Trump referenced the incidents while discussing cybersecurity threats to critical infrastructure, calling Minnesota officials "grossly incompetent." Officials haven’t publicly identified who was responsible, and investigators are continuing to examine the origin of the attacks. Michigan Water System Targeted Michigan also reported a cyber incident affecting

Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation

Acknowledgments: Special thanks to Aaron Deal, Chris Bisnett, Aaron Bennett, Sharon Martin, Dave Kleinatland, James Northey, Josh Kiriakoff, and Kamal Bennoune for their contributions to this investigation and writeup. Update: 8/3/26 @ 12:45 AM ET As Huntress continues our investigation and analysis of activity targeting vulnerable N-able N-central environments, we discovered that the four IPs N-able initially flagged as malicious are actually Mullvad or NordVPN VPN exit nodes. Notably, among the original IPs, we have seen substantial traffic with 87.249.138[.]34 directly attributed to NordVPN, as well as substantial traffic with 37.19.210[.]32 directly attributed to Mullvad VPN. 37.19.210[.]32 has been previously abused for bruteforcing, spam, and other nefarious activity prior to this incident. In parallel, Huntress technology and teammates are rapidly identifying unpatched N-able server instances and contacting at-risk partners and customers about the imminent threat. Beyond this specific vulnerability, we are seeing many environments where the N-central Server has yet to be updated to the 2026.3.1.7 hotfix needed to prevent exploitation of the vulnerability. At the time of posting this update, more than half (55.6%) of our partners' and customers' reachable cloud servers were still unpatched. That is especially concerning because the N-able server runs a custom distribution of AlmaLinux 9, and does not often have EDR software deployed on it due to running as an appliance. N-able has since published an additional security update with two more malicious IPs, 37.153.90[.]88 and 92.118.112[.]181, which we have incorporated into our hunting and guidance below. We will continue to investigate this activity and update this post as we learn more. Background and Vulnerability Overview On August 1–2, 2026, N-able disclosed a critical vulnerability in N-central, its flagship remote monitoring and management (RMM) platform used by MSPs to centrally monitor, patch, and remotely access servers and endpoints across all of their customers. N-able

Ethiack Helps Remediate Critical Vulnerability That Exposed More Than 500,000 Websites

European cybersecurity firm Ethiack has disclosed a critical security vulnerability in Ruby on Rails, one of the most widely used open-source web application frameworks powering hundreds of thousands of websites and digital services worldwide. Known as KindaRails2Shell, the remote code execution (RCE) vulnerability enables attackers to read sensitive files, execute malicious code, and potentially gain full control of affected servers. First released more than two decades ago, Ruby on Rails serves as the foundation for an estimated 500,000 web applications, including many high-profile online platforms and enterprise services. The vulnerability was identified by Ethiack researchers André Baptista, Bruno Mendes, and Rafael Castilho in the framework’s default image processing component. Impacting Ruby on Rails versions 7.x and 8.x, the flaw can be triggered whenever users upload images, including profile photos, avatars, and thumbnails. Instead of immediately disclosing the technical details, Ethiack followed a responsible disclosure process by privately reporting the issue to the Ruby on Rails maintainers. The company subsequently collaborated with GMO Flatt Security, a Tokyo-based security firm that independently discovered the same vulnerability several days later. Together, they supported a coordinated global remediation effort, helping affected organizations validate and deploy the required security updates. The official security advisory for CVE-2026-66066 is now available, assigning the vulnerability a CVSS severity score of 9.5. Ethiack has also released comprehensive technical details and a step-by-step remediation guide on its blog. André Baptista, CTO at Ethiack, commented: “This is a critical remote code execution vulnerability that leaves web applications exposed any time a user uploads an image. The risk is severe and demands immediate action. “Ethiack combines a team of world-class human hackers and AI pentesting agents, who work together to help cyber defenders. When dealing with an emergency like this, we prioritise speed, agility and responsibility. We worked closely with the Ruby

What to Know About the U.S. Water Systems Cyberattacks

Malicious cyber activity has affected technology at water systems in at least seven states last week, forcing some facilities to switch to manual operations and prompting the FBI and Environmental Protection Agency (EPA) to warn facilities nationwide of hackers. Minnesota IT Services said in a statement last week that at least 30 municipal water facilities were targeted July 26-27 and that it had “immediately activated the state's cybersecurity incident response capabilities.” Over the weekend, Michigan also reported cyberattacks on nine of its water systems. Without confirming just how widespread the attacks may have been or which states they affected, the FBI and EPA said in a joint statement that multiple incidents had occurred. It explained that hackers are remotely accessing internet-connected controls, changing administrator passwords, and “causing operational disruption” like flooding and pressure loss, which “could potentially allow untreated ground water to seep into pipes.” The incidents also came days after federal agencies updated a warning about ongoing Iranian cyber threats targeting U.S. critical infrastructure, though investigators have not publicly linked the latest attacks to Tehran. Read More: Why Cybersecurity Threats Are Growing United States water systems are a part of critical infrastructure in the country, which makes them attractive targets for cyberattacks. The EPA has warned in recent years that a significant number of local water systems had critical or high-risk vulnerabilities, including “outdated software, poor network security, weak access controls, and a lack of employee cybersecurity training.” But it has also indicated that it’s up to individual operators to protect their own systems from external threats. An EPA spokesperson pointed TIME to Administrator Lee Zeldin’s comments on FOX on Saturday, where he called on utility operators and local entities to protect themselves. “There is a lot of individual responsibility on the part of companies and local water systems

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG) instead of the STM32 hardware random number generator (RNG). Block says an attacker who can determine or sufficiently constrain the device UID, timer state, and prior RNG-call history can reproduce candidate output streams offline without accessing the device. Candidate seeds can then be checked by deriving their addresses and comparing them with public blockchain data. Coinkite shipped emergency firmware for every affected model and release track on July 31, but installing it does not repair an existing seed. Coinkite tells owners with exposed seeds to generate a new one on patched firmware and move their coins. Restoring the old seed to updated firmware or another wallet carries the weakness forward. No public report has reconstructed a victim's seed and matched it to a drained address. Block traced the fault to Coldcard's production config, which defines MICROPY_HW_ENABLE_RNG as zero because Coinkite supplies its own hardware-RNG wrapper. The libngu library checked whether the macro existed rather than whether it was enabled, binding the build to MicroPython's Yasmarang fallback. The MicroPython fallback was initialized from the chip's unique ID and timer registers and collected no fresh entropy after initialization. Coinkite estimates effective entropy at roughly 40 bits on the Mk3 and about 72 bits on the Mk4, Mk5 and Q, against 128 bits for a 12-word BIP-39 seed. Block does not give one practical figure. It sets conditional ceilings below 240.7 and 273.3 and warns that the latter is not equivalent

OpenAI's Escaped Models Were Allegedly Rampaging More Extensively Than Previously Reported

Last week, OpenAI claimed that a group of its AI models had broken containment, successfully hacking into the systems of open source AI platform Hugging Face to cheat on a benchmark test. In the wake of the announcement, two very distinct narratives have emerged surrounding OpenAI’s claims. Some say it was essentially a publicity stunt, with the company setting parameters for the test that pushed the models toward outrageous behavior. But others, including certain prominent researchers, warn that the hack should serve as a warning shot for an even more severe AI-enabled cybersecurity disaster that’ll inevitably take place as models become more sophisticated. “This is the first time, to my knowledge, that an AI system has autonomously committed a crime,” said New York Times journalist Kevin Roose of the event. “If a human did to Hugging Face what OpenAI’s models did to Hugging Face, they would be charged with computer fraud, and potentially sent to prison or fined or prosecuted.” Debate will surely continue to rage among wonks and skeptics. And new details aren’t exactly tamping out the sense of alarm: on Tuesday, OpenAI issued an update to its ongoing investigation, claiming the incident was worse than initially thought. In addition to hacking Hugging Face, the company now says, its models “used publicly exposed credentials at the account-level on other publicly available services,” totaling “four accounts on four services.” “We’ll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services,” OpenAI wrote, without elaborating on which services were affected. The news further raised alarm bells among some cybersecurity experts, highlighting ongoing concerns over the tech’s ability to evade protective measures. It’s a possibility that researchers have warned about for years, and the incident suggests that the threat

7 States' Water Systems Hit by Cyberattacks Likely Tied to Iran | WIRED

This week, WIRED obtained a memo that tied dozens of cyberattacks against Minnesota water and wastewater utilities to Iran, the first official documentation of Iran’s likely responsibility for the most impactful campaign of cyberattacks to hit the US in the midst of the war that began nearly six months ago. In other news, more details have emerged about OpenAI’s “rogue” AI agent breach of Hugging Face’s platform. OpenAI disclosed that the AI agent hacked multiple third-party accounts and services as it sought to breach Hugging Face’s production database, which contained solutions for the cybersecurity tests OpenAI was evaluating the agent with. Anthropic, too, disclosed that its AI models gained unauthorized access to three organizations’ systems during its own cybersecurity testing. Experts say the incidents underscore the importance of implementing well-known security best practices on the part of AI labs. AI is changing cybersecurity in other ways. Google’s Chrome Browser now receives twice-a-week security updates as more bugs are identified and fixed thanks to the security team’s use of AI tools. And a new research study found that AI chatbots are effective at reeling victims into pig-butchering scams. The US Immigration and Customs Enforcement is attempting to prevent state oversight of four detention facilities, and a Department of Homeland Security official resigned, citing the agency’s “war on immigrants.” Plus, a GPS jamming exercise in New Mexico contributed to the crash of a civilian plane, as drone warfare reshapes how safe the skies are both in the US and abroad. People were surprised to see shared Claude chats popping up as search results on major search engines. An innocent gamer was imprisoned for 18 months after law enforcement made a typo in a subpoena. Researchers found that the top image-editing models on Hugging Face can easily create explicit deepfakes. And attendee badges

As AI hits software sector, defense-tech flourishes | The Jerusalem Post

A new survey by Israeli recruiting firm GotFriends, seen by Globes, reports that while many tech companies continue to reduce employees and slow hiring, as part of streamlining adjustments for AI adoption, defense-tech startups are aggressively expanding their workforce. The number of new jobs in the defense-tech industry increased 20% in 2026 compared with the same period last year, and wages are climbing by about 8%. In recent months, dozens of tech companies in Israel and around the world have announced new rounds of layoffs. Many of them explained that these are part of efficiency measures due to expanded use of AI, automation of work processes, and reconfiguring the workforce structure. However, while large parts of the tech industry are laying off employees, one sector continues to move in the opposite direction. In effect, the GotFriends report indicates a change in the employment map of Israel's tech industry. The survey reports that the number of new jobs opened at defense-tech startups has increased 20% this year compared with the same period last year. At the same time, wages in the industry increased about 8%, a figure that illustrates, among other things, the increasing competition for employees with experience in the fields of software, hardware, cybersecurity and AI. According to GotFriends, among the companies currently hiring the largest number of employees in the field are Kela Technologies, Xtend, Airis Labs, D-Fend Solutions and Axon Vision. Thus, if in the past the main competition for engineers was between software, fintech and cybersecurity companies, today defense-tech startups are also competing for the same candidates, offering similar salaries and conditions. Procurement orders from the Ministry of Defense The increase in the number of jobs in defense-tech in Israel is not happening in a vacuum. It is coming in parallel with broader growth in the

Amid fears of Iranian cyberattacks, Michigan joins Minnesota in reporting hackers hit water systems

Michigan on Saturday joined Minnesota in reporting cyberattacks on nine of the state’s water systems but an official said all systems were operating “safely.” Earlier this week, authorities said cyberattacks targeted over 30 water systems in Minnesota. The source of the attacks is being investigated, but they came amid warnings that Iranian hackers have been focused on such systems. The reports in Michigan surfaced after the state received a federal cyber alert Tuesday about attempts to tamper with operational technology at water systems. Soon after, the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described,” said Dale George, the director of communications at the state’s Department of Environment, Great Lakes, and Energy. He later said nine systems were impacted. “All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern,” George said in an statement. The FBI, which is investigating, has not publicly identified a culprit and a spokesperson declined to say Thursday who the bureau thought might be responsible. The FBI, Cybersecurity and Infrastructure Security Agency and other agencies warned in an advisory last week that Iranian hackers have been targeting water and wastewater systems and the operational controls of other critical infrastructure sectors. “The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors,” the agency said in a statement Saturday. “The FBI and our interagency partners are fully engaged to protect critical infrastructure and we remain well-equipped to protect against cyber threats of all varieties.” Digital warfare has become ingrained in military conflict, and local water plants or healthcare facilities often lack the funds and know-how to install the latest software patches or take other security steps. That has made them a

Michigan joins Minnesota in reporting cyberattacks, with FBI investigating

Michigan joins Minnesota in reporting cyberattacks, with FBI investigating No culprit has been identified in any of the attacks, which comes after authorities warned of a possible Iranian plot. Michigan has reported cyberattacks on nine of its water systems, days after Minnesota reported similar breaches across the state. The United States Federal Bureau of Investigation (FBI) said it was investigating both of the attacks on Saturday. In an advisory earlier this week, it said that at least seven states have reported incidents, but so far only Minnesota and Michigan have been identified. Recommended Stories list of 3 items - list 1 of 3The Gulf does not have to choose Iran or Israel - list 2 of 3Anthropic urges AI labs to pause, warns humans risk losing control - list 3 of 3Sam Altman meets lawmakers on back of OpenAI agents hacking companies No culprit has yet been pinpointed. However, the breaches came after the FBI, Cybersecurity and Infrastructure Security Agency (CISA) and other agencies warned in an advisory last week that Iranian hackers have been targeting water and wastewater systems and the operational controls of other critical infrastructure sectors. “The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors,” the agency said in a statement on Saturday. “The FBI and our interagency partners are fully engaged to protect critical infrastructure, and we remain well-equipped to protect against cyber threats of all varieties.” Dale George, the director of communications for Michigan’s Department of Environment, Great Lakes and Energy, meanwhile, said that “all systems continued to operate safely” following the attacks. He said Michigan received a federal cyber alert on Tuesday about attempts to tamper with operational technology in water systems. Soon after, the state received “a small number of reports from Michigan communities indicating activity consistent with

Google helps local <b>cyber security</b> academy get mobile bus in Hampton Roads

RFK SolutionsCHESAPEAKE, Va. — , a Chesapeake-based cyber security company, is expanding its community outreach efforts after Google sponsored equipment to help the organization launch a mobile bus program. The company, which has been in business for 14 years, created RFK Outreach and its Cyber Academy to teach young people about cyber security. The mobile bus will allow the organization to reach more community members in undeserved areas. One of the program's central goals is to offer students an alternative path to a career in cyber security outside of the traditional four-year college route. Dr. Kimberly Frost, co-founder of RFK Solutionz, said the organization's mission spans generations. "One of the things that we're really trying to establish when it comes to what RFK is trying to do in the community, and that is just to educate our children from the cradle to the 60 years of age, we want to make sure that they have a great understanding of what cyber security is, how to protect themselves, how to protect our area and our nation as a whole," Frost said. Upcoming events include a Community Day at the RFK Solutionz location at 3500 Tejo Lane, Chesapeake, Va. on Aug. 22 at 9:00 a.m. As well as a Seniors Learning Seminar on Aug. 26. This story was reported on-air by a journalist and has been converted to this platform with the assistance of AI. Our editorial team verifies all reporting on all platforms for fairness and accuracy. Click