No-frills tech news

Anthropic Says Its AI Modeals Hacked 3 Organizations During Testing

Anthropic Says Its AI Modeals Hacked 3 Organizations During Testing This comes just days after OpenAI said its AI models went rogue and hacked into another company. Associated Press August 1, 2026 (AP) – Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company. Anthropic, the San Francisco-based AI company behind Claude, posted on its website Thursday that it discovered the three incidents after reviewing more than 141,000 evaluation runs. It had launched a “large-scale” cybersecurity review which specifically looked for evidence whether its AI models were able to access the internet from within testing environments that should have been sealed off, in response to the OpenAI incident, Anthropic said. Anthropic said the models involved in the incidents were Claude Opus 4.7, Claude Mythos 5 and an internal research test model. The earliest incidents date to April, the AI company said. “Claude compromised the impacted organizations’ infrastructure using basic techniques,” Anthropic said, such as exploiting weak passwords. In all three incidents, the AI models were tasked with a “capture the flag” cybersecurity challenge, which Anthropic said has been one of the ways it assesses a model’s cyber capabilities. The models were given a fictional scenario and told a piece of secret information, or the “flag,” had been hidden on a different machine on the network with the objective of breaking in and retrieving it, it said. It added that it had already reached out to the affected organizations, which it did not name. Two of them said they had not previously detected the activity. Anthropic said it was “continuing to reach out to the third.” Anthropic said it conducted its review with Irregular, which describes itself as

U.S. investigating if Iran was behind cyberattack on water systems in 7 states ...

U.S. investigating if Iran was behind cyberattack on water systems in 7 states, including Minnesota and Michigan Malicious cyber activity affected technology at water systems in at least seven states this week, including Minnesota and Michigan, forcing some utilities to switch to manual operations as state and federal authorities dig into who is behind the attack, CBS News has learned. Investigators are probing to determine whether the activity is the work of Iranian hackers, according to U.S. officials and sources familiar with the incident. Sources cautioned that since they had not definitively attributed the attack, their assessment could change as additional technical evidence is collected. They are also probing whether the actor could have attempted to appear Iran-based as a way of stirring the pot amid the ongoing U.S. conflict with Iran. The FBI reported incidents in "at least seven states" but didn't identify them. On Saturday, Michigan joined Minnesota in reporting cyberattacks on the state's water systems but an official said all systems were operating "safely." Dale George, the director of communications at the state's Department of Environment, Great Lakes, and Energy, told CBS News in a statement that the state received "a small number of reports from Michigan communities indicating activity consistent with what federal agencies described." "All systems continued to operate safely, issues were addressed by local operators, and there are no known impacts that posed a public health concern," he added. CBS News has learned more than 30 community water systems across Minnesota were affected. Minnesota and the federal government have not publicly attributed the activity to a particular actor. Even as the investigation continues, President Trump said Friday he doesn't think Iran is to blame. Instead, he pointed the finger at Minnesota and its Democratic governor, Tim Walz, who is no stranger to criticism from

FBI: Cyberattacks hit water systems in at least 7 states; Trump, Walz spar over Minnesota hack

FBI: Cyberattacks hit water systems in at least 7 states; Trump, Walz spar over Minnesota hack Trump blames Minnesota government; Walz points to DOGE cuts to federal cybersecurity agency SAINT PAUL, Minn. — The FBI says utility companies in at least seven states have reported disruptions caused by what the agency described Thursday as “malicious criminal actors” targeting public drinking water systems, with incidents beginning July 27. Minnesota is the only state that has been publicly identified. U.S. and state officials are treating Iran as one of the suspects behind the attacks but have not made a formal determination of responsibility. Some cybersecurity experts have called it one of the most serious attacks on U.S. water systems in years. Trump and Walz exchange blame President Donald Trump addressed the Minnesota hack during a Cabinet meeting Friday, casting doubt on possible Iranian involvement and directing blame at the state government. “I think I blame it on Minnesota because they’re grossly incompetent,” Trump said. “There was a cyber attack of 30 water plants, and I would blame it on Minnesota and the governor, the corrupt governor of Minnesota. They like to say, oh, it’s Iran. Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.” Gov. Tim Walz responded in a Facebook post Thursday, writing that the attack “further illustrates there’s no plan to win a war with Iran.” Walz also said the Department of Government Efficiency — known as DOGE — “took an axe” to the Cybersecurity and Infrastructure Security Agency, or CISA, leaving the nation “exposed to cyber attacks.” CISA funding CISA, which is part of the Department of Homeland Security, received more than $2.6 billion in congressional funding for fiscal year 2026 — down from $2.8 billion in 2025. That funding was not approved until April

Sweeping cyberattack on water systems in multiple states has US officials on edge

Hackers have targeted water systems in several US states in a coordinated cyberattack that has caused some utilities to issue boil-water notices and switch to manual mode, taking their systems offline, according to US officials. It’s one of the most serious cyberattacks on water systems in the US in years, according to some analysts. The US Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the Environmental Protection Agency have for the last week been scrambling to try to help secure the water facilities and ensure that the safety of drinking water isn’t affected. No incidents of contamination have been reported. The hackers “are targeting water entities of all sizes,” CISA said in a warning Thursday that urged water facilities to get vulnerable industrial equipment offline. US and state officials are treating Iran as one of the suspects behind the hack, but have not made a formal determination of who is responsible and are wary of false flags. The first public sign of the cyberattacks came from Minnesota authorities, who said that hackers on Sunday night and Monday morning targeted about 30 water systems in that state. The “likely desired impact” of the hackers’ intrusion at the water facilities was “to cause loss of system pressure and subsequent potential contamination of water supply,” said the memo distributed this week by the Minnesota Bureau of Criminal Apprehension and obtained by CNN. At a cabinet meeting Friday, President Donald Trump blamed Minnesota authorities for the hack and cast doubt on whether Iran was involved. “They like to say, “Oh, it’s Iran.’” Trump said. “Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.” The New York Times first reported on the possible Iran connection. The hackers are targeting internet-facing programmable logic controllers (PLCs), the devices that allow machinery to

Trump blames Minnesota governor, not Iran, for cyberattacks on the state's water systems

Trump blames Minnesota governor, not Iran, for cyberattacks on the state's water systems Georgia and Michigan are reporting similar cyberattacks, according to sources. President Donald Trump on Friday blamed Minnesota's Democratic governor for cyberattacks on the state's water systems even though U.S. officials previously told ABC News authorities are investigating whether Iran or hackers associated with the country could be behind them. "We heard in Minnesota there was a cyberattack and they blame it on Iran. I don't think so. I think, I blame it on Minnesota because they're grossly incompetent," Trump said at a Cabinet meeting at Camp David, without offering evidence. Walz pushed back against Trump's comments in statements on social media Friday. "Trump knows exactly who is responsible for this attack, and knows that other states were hit too. This is what modern warfare looks like, and it further illustrates there's no plan to win a war with Iran," Walz wrote in a social media post. The governor also noted federal cuts by the Department of Government Efficiency (DOGE) weakened cybersecurity. "DOGE took an axe to CISA and left the U.S. exposed to cyber attacks. Thankfully, our experts in Minnesota were able to identify the vulnerability quickly and work with local communities to stop it," Walz wrote. More than 30 water systems in Minnesota were targeted in a cyberattack Sunday and Monday, according to Minnesota IT Services (MNIT). MNIT said the attackers targeted systems to remotely monitor and control equipment, including the programmable logic controllers (PLCs), which are used for remote access. Federal agency officials briefed state and local leaders in Minnesota about the possibility that Iran was behind the cyberattacks, according to a source familiar with the meeting. "The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors. The FBI and our

Anthropic's Claude Hacked 3 Real Companies During Misconfigured <b>Cybersecurity</b> Evaluations

Three Claude models reached real production systems during misconfigured cybersecurity evaluations between April and July 2026, Anthropic disclosed Thursday in a detailed blog post. What makes the disclosure scientifically significant is not just that the breaches occurred — it is what happened next: each of the three models responded differently when evidence emerged that their targets were real, creating the most specific empirical record yet published by a major AI lab on how successive generations of the same model family handle situational awareness failures in live conditions. Claude Opus 4.7, the oldest of the three, recognized it was attacking a real production system and kept going anyway. Claude Mythos 5 correctly identified, midway through its attack, that publishing a malicious package to PyPI would constitute a genuine real-world attack — then reasoned itself back into false certainty that it was still in a simulation, and completed the attack. An unnamed internal research prototype, the newest of the three, reached the same fork in the road and stopped on its own. The disclosure came after Anthropic reviewed 141,006 evaluation runs following OpenAI's July 21 disclosure that its models had escaped an isolated test environment and breached Hugging Face's production servers. That review turned up three incidents Anthropic had not previously known about, involving six individual evaluation runs, three named Claude models, and three real organizations whose infrastructure was compromised — two of which had detected nothing unusual before Anthropic reached out on July 27. Read more: AI Kill Switch Act Targets OpenAI and Anthropic After Containment Breach Hit Hugging Face How a Fictional Exercise Reached Real Organizations All three incidents share the same structural root cause. Anthropic runs cybersecurity evaluations by deploying its models inside capture-the-flag scenarios: the model is given a fictional premise, told that sensitive information has been hidden

Anthropic says its AI models hacked 3 organizations during testing

Anthropic says its AI models hacked 3 organizations during testing Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company. Anthropic, the San Francisco-based AI company behind Claude, posted on its website Thursday that it discovered the three incidents after reviewing more than 141,000 evaluation runs. It had launched a “large-scale” cybersecurity review which specifically looked for evidence whether its AI models were able to access the internet from within testing environments that should have been sealed off, in response to the OpenAI incident, Anthropic said. Anthropic said the models involved in the incidents were Claude Opus 4.7, Claude Mythos 5 and an internal research test model. The earliest incidents date to April, the AI company said. “Claude compromised the impacted organizations’ infrastructure using basic techniques,” Anthropic said, such as exploiting weak passwords. In all three incidents, the AI models were tasked with a “capture the flag” cybersecurity challenge, which Anthropic said has been one of the ways it assesses a model’s cyber capabilities. The models were given a fictional scenario and told a piece of secret information, or the “flag,” had been hidden on a different machine on the network with the objective of breaking in and retrieving it, it said. It added that it had already reached out to the affected organizations, which it did not name. Two of them said they had not previously detected the activity. Anthropic said it was “continuing to reach out to the third.” Anthropic said it conducted its review with Irregular, which describes itself as the “first frontier security lab.” “Addressing these risks will require closer cooperation across the AI ecosystem,” Irregular said in a post on X. Last

Anthropic says its AI models hacked 3 organizations during testing | PBS News

By — Chan Ho-him, Associated Press Chan Ho-him, Associated Press Leave your feedback Share Copy URL https://www.pbs.org/newshour/nation/anthropic-says-its-ai-models-hacked-3-organizations-during-testing Email Facebook Twitter LinkedIn Pinterest Tumblr Share on Facebook Share on Twitter Anthropic says its AI models hacked 3 organizations during testing Nation Jul 31, 2026 1:40 PM EDT Anthropic said its artificial intelligence models hacked into three other organizations during testing, just days after ChatGPT maker OpenAI raised concerns over AI controls after it disclosed its rogue models hacked another company. Anthropic, the San Francisco-based AI company behind Claude, posted on its website Thursday that it discovered the three incidents after reviewing more than 141,000 evaluation runs. It had launched a "large-scale" cybersecurity review which specifically looked for evidence whether its AI models were able to access the internet from within testing environments that should have been sealed off, in response to the OpenAI incident, Anthropic said. WATCH: Anthropic disables new AI model after White House security directive Anthropic said the models involved in the incidents were Claude Opus 4.7, Claude Mythos 5 and an internal research test model. The earliest incidents date to April, the AI company said. "Claude compromised the impacted organizations' infrastructure using basic techniques," Anthropic said, such as exploiting weak passwords. In all three incidents, the AI models were tasked with a "capture the flag" cybersecurity challenge, which Anthropic said has been one of the ways it assesses a model's cyber capabilities. The models were given a fictional scenario and told a piece of secret information, or the "flag," had been hidden on a different machine on the network with the objective of breaking in and retrieving it, it said. It added that it had already reached out to the affected organizations, which it did not name. Two of them said they had not previously detected the activity.

SSP alumnus playing (cyber) defense at the World Cup | School of Foreign Service

By: Alexander Charles (SSP’26), Admissions & Alumni Fellow As millions of fans tuned in to cheer for their national teams during the 2026 FIFA World Cup, Security Studies Program (SSP) alumnus Sina Nemazi (SSP’23) was focused on a different goal: protecting the international tournament from cyber attacks. As a cybersecurity manager for FIFA, Nemazi led efforts to safeguard the digital infrastructure behind one of the world’s largest sporting events. His responsibilities ranged from protecting FIFA’s internal systems and corporate networks to cybersecurity coordination and response with host cities. At the same time, Nemazi interfaced with the FBI, CISA, the Canadian Centre for Cyber Security and Mexico’s National Cyber Incident Response Center, facilitating cross-border cyber threat intelligence sharing while developing FIFA’s trusted partnerships, coordination mechanisms and operational playbooks that will strengthen cybersecurity cooperation for future international sporting events. Nemazi credits his success at FIFA to SSP’s technology and security concentration that taught him to look beyond the technical understanding of cybersecurity. The classes provided the framework to view cyber as a transnational security issue that demands strategic thinking, policy expertise and the ability to navigate complex relationships across governments and international organizations. But navigating complex bureaucracies is nothing new for Nemazi. Before joining FIFA, he served as a political appointee in the Biden-Harris administration as a special adviser to the assistant secretary for cyber, infrastructure, risk and resilience at the U.S. Department of Homeland Security. While his role at FIFA focused on the operational side of cybersecurity, his work in government centered on cyber governance and policy, developing the cybersecurity of U.S. critical infrastructure while contributing to emerging technology initiatives through the AI Safety and Security Board. Nemazi says that SSP equipped him with the practical skills that would later serve him at the White House. Courses such as Writing for

Pace <b>Cybersecurity</b> Students Test Their Skills in Regional Cyber Defense Competition

Discover how Pace students tackled real-world AI challenges during an immersive internship experience at Seidenberg. Pace Cybersecurity Students Test Their Skills in Regional Cyber Defense Competition Students from Pace University's Seidenberg School of Computer Science and Information Systems recently traveled to Lowell, Massachusetts, to compete in the Northeast Collegiate Cyber Defense Competition (NECCDC), where they put their cybersecurity skills to the test against some of the region's top collegiate teams. Part of the National Collegiate Cyber Defense Competition, NECCDC brings together teams from colleges and universities across the Northeast to defend enterprise networks against a professional Red Team of penetration testers and ethical hackers. During the competition, each school’s eight-person Blue Team is tasked with protecting critical systems and services while responding to simulated cyberattacks that mirror the challenges faced by today's cybersecurity professionals. This immersive experience isn't just a competition; it equips [students] for wherever their cybersecurity journey takes them. For Seidenberg students, the competition offered an opportunity to put months of preparation into practice. This year's team competed against nine other colleges and universities from across the region, continuing Pace's streak of qualifying for the regional competition for the fourth consecutive year. "When our students step into the Blue Team room for the NECCDC competition, they transform into cyber defenders," said Seidenberg cybersecurity professor Joe Acampora. "The pressure they feel, the trust they share, and the techniques they master here are nothing short of what professionals in the field face on their craziest days. This immersive experience isn't just a competition; it equips them for wherever their cybersecurity journey takes them." Acampora emphasized that he is especially proud of the team's dedication and preparation. "I am proud to coach such a dedicated team—students who have learned and trained through busy semesters to qualify for our regional competition four

Government Playing a Dangerous Game With Drone <b>Cybersecurity</b> | American Civil Liberties Union

Government Playing a Dangerous Game With Drone Cybersecurity Subscribe to the Free Future Newsletter Or get immediate notifications of new posts via Substack Free Future home Earlier this month I wrote about how police have been seizing hundreds of drones around the country for alleged violations of no-fly rules. The counter-drone business is hopping today, with law enforcement around the country highly focused on gaining the ability to deal with drones flying places they’re not supposed to be, as well as the so-far-nonexistent but probably eventually inevitable prospect of a violent attack via drone. Often called counter-UAS (for “uncrewed aerial system,” a bureaucratic term for drone), the field is dedicated to the difficult problem of how to ground, capture, destroy, or otherwise “mitigate” a rogue drone. Within the counter-UAS field lurks a significant public policy issue that has not been discussed enough: the hacking of drones. It’s not easy to defend against drones. Techniques for mitigating them include shooting at them with projectiles, lasers, or microwaves, jamming GPS or other radio signals, and sending up defensive drones with big nets. US law enforcement officers don’t operate on a battlefield, however (despite how many of them dress and sometimes behave). In a civilian environment, massive interference with the radio spectrum, shooting dangerous lasers into our crowded skies, and aerial shoot-outs that send wreckage crashing down on civilians’ heads just won’t do. There is another counter-drone technique that supposedly avoids all these problems: hacking into a drone to take it over and steer it safely away. But that raises one of the longest-running issues in cybersecurity: the creation or hoarding of software vulnerabilities that can be used by the authorities to break into software, but which also leave the door open for malevolent hackers to do so as well. Those vulnerabilities can

<b>Cybersecurity</b> expert explains cyber threats facing Wisconsin water systems

Watch Now Menu Local National Weather Sports Shop Scripps Watch Now Watch Now Close × Live Watch Alerts Search site Go Weather Today's Forecast Interactive Radar Hourly Forecast 7-Day Forecast Live Weather Cams Weather Maps Travel Forecast Weather Alerts Closings Science Experiments Weather Blog Weather Kids Traffic News by Topic Local News Lighthouse Milwaukee Tonight Positively Milwaukee National Submit News Tips News by Location Dodge County Fond du Lac County Jefferson County Kenosha County Milwaukee County Ozaukee County Racine County Sheboygan County State Capitol Walworth County Washington County Waukesha County Videos Live Newscasts Youtube Channel Sports Green Bay Packers Milwaukee Brewers Milwaukee Bucks Marotta's Mic Drop EmpowHERing the Game Friday Football Frenzy The Morning Blend What's Brewing Wisconsin Entertainment TV Listing The Kelly Clarkson Show Watch NBC Shows About Us Contact Us News Team Jobs Advertise With Us TV Listings Mug Shot Policy Facebook Comment Policy Artificial Intelligence Policy Moving Forward Support Watch TMJ4 News anywhere Contests Chula Vista Sweepstakes Visit Manitowoc Sweepstakes Weather Kids Featured Content If You Give a Child a Book... Every Day Health Manage Emails Apps Careers Search tmj4 tmj4news tmj4 UCKdALw0BErtqmGI2AUtbbhg @tmj4news 5 WX Alerts Milwaukee County Waukesha County Racine County Kenosha County Washington County Sheboygan County Walworth County Fond du Lac County Ozaukee County Dodge County Jefferson County State Capitol More + Quick Links + Milwaukee County Waukesha County Racine County Kenosha County Washington County Sheboygan County Walworth County Fond du Lac County Ozaukee County Dodge County Jefferson County State Capitol Cybersecurity expert explains cyber threats facing Wisconsin water systems Live Stream Schedule

<b>Cybersecurity</b> expert explains cyber threats facing Wisconsin water systems

MILWAUKEE — Cybersecurity expert Alex Holden says Wisconsin utilities are facing growing cyber threats after hackers disrupted water operations in neighboring Minnesota. Officials say there are no confirmed compromises in Wisconsin. Federal and Wisconsin officials are warning water utilities to secure critical infrastructure systems after cyber incidents in neighboring Minnesota disrupted water operations and raised concerns about vulnerabilities in utility control systems. PREVIOUS COVERAGE | Sweeping cyberattack on water systems in multiple states has officials on edge The Wisconsin Department of Natural Resources recently sent a statewide alert to water and wastewater utilities warning of “ongoing malicious activity” targeting programmable logic controllers, or PLCs — small industrial computers used to help manage pumps, pressure and water flow inside utility systems. The alert follows incidents in Minnesota where federal officials say hackers targeted internet-connected control systems tied to water operations. “Control over our critical infrastructure, especially like our water supply, is paramount to us,” said Alex Holden, chief information security officer for Hold Security. Watch: Cybersecurity expert explains cyber threats facing Wisconsin water systems In a joint public warning issued Thursday, the FBI and Environmental Protection Agency said malicious cyber actors have targeted internet-facing Programmable Logic Controllers used by water utilities in at least seven states. Federal officials said some incidents led to operational disruptions, including pressure loss and utilities switching to manual operations. The Cybersecurity and Infrastructure Security Agency, or CISA, also warned of a “significant increase” in cyber actors targeting PLCs used by water and wastewater systems. Holden said internet-exposed industrial control systems remain a concern. ‘They are just sitting open on the internet, exposing their internal configurations,’ Holden said. Federal officials are urging utilities to remove internet-exposed operational technology systems, strengthen passwords and review remote access controls. Despite the warnings, Wisconsin officials say there are currently no confirmed

Texas A&amp;M to receive $2 million for <b>cybersecurity</b> and AI training workforce expansion

Texas A&M University will receive a grant from the state to help continue training for cybersecurity and artificial intelligence workforce development. The gist According to a news release, the goal of boosting the programs is to help "protect critical infrastructure as instances of cyberattacks from foreign adversaries continue to increase.” The cybersecurity program at the university has been ranked among the top on several national lists and operates as part of the nationally recognized College of Engineering. The CHIPs and Science Act was signed into law in 2022 to boost semiconductor manufacturing and computer-related research, and Texas Sen. John Cornyn voted in favor of it. Cornyn said Texans need to take steps to be prepared for cyberattacks and protect computer systems across the state and country.

Local water systems monitor <b>cybersecurity</b> threats following Minnesota attacks

MN water hacks trigger federal alerts for Wisconsin systems EAU CLAIRE, Wis. (WEAU) - Local utility officials are reassuring residents that area drinking water remains safe and protected following a wave of cyberattacks that targeted more than 30 municipal water facilities in neighboring Minnesota. The Minnesota breaches disrupted operations and triggered boil water advisories in several communities, prompting federal and state authorities to step up vigilance across the region. The FBI is actively investigating the attacks, with intelligence reports pointing to a possible link to hackers in Iran. President Donald Trump downplayed foreign involvement, pointing instead to local leadership. “I would blame it on Minnesota and the governor, the corrupt governor of Minnesota,” Trump said. “They like to say, oh, it’s Iran. Iran should be so lucky. Iran’s got bigger problems than worrying about Minnesota.” The Wisconsin Department of Natural Resources issued a security warning on July 27, notifying local water managers of the active threat. The advisory came after the state’s intelligence division identified three specific types of Programmable Logic Controllers (PLCs)—industrial computers used to monitor and control automated water equipment—that are highly vulnerable to malicious activity. “It’s a wake-up call to all critical infrastructure in all states,” said Bryce Austin, a cybersecurity expert. “We need to be prepared for cyber attacks. It’s not a question of if; it’s a question of when.” Wisconsin was listed among seven states identified as vulnerable in recent federal threat reports, but Chippewa Falls utility manager Brandon Cesafsky says they are well-prepared to prevent similar incidents. Chippewa Falls officials confirmed to WEAU that their municipal utility does not use any of the vulnerable PLC brands highlighted in the state’s security advisory. Meanwhile, Chippewa Falls and Chippewa County leaders met with representatives from the Environmental Protection Agency this week to receive briefings on the

A $22000 Bounty announced for information on INC Ransomware Group

As ransomware attacks continue to rise across the globe, law enforcement agencies and cybersecurity organizations are stepping up their efforts to disrupt cybercriminal operations. In a significant move, a U.S.-based non-profit organization has announced a $22,000 reward for information that helps identify, disrupt, or seize the infrastructure used by the INC Ransomware group. The bounty has been introduced by Crime Stoppers, a non-profit organization that has been assisting law enforcement since the 1970s. The initiative aims to encourage individuals with credible information to come forward and assist authorities in tracking down members of the notorious ransomware gang. The reward is expected to support ongoing investigations while increasing pressure on cybercriminals responsible for a growing number of ransomware incidents. The INC Ransomware group has gained notoriety for targeting organizations across multiple sectors, with healthcare providers and operators of critical infrastructure among its primary victims. These attacks have the potential to disrupt essential services, including hospitals, power utilities, and water management systems, leading to financial losses, operational downtime, and risks to public safety. By encrypting critical data and demanding large ransom payments, the group has become a persistent threat to organizations worldwide. According to Crime Stoppers, the reward is available to any individual, business, or organization that can provide actionable intelligence leading to the identification or disruption of the group’s activities. This includes information about the physical location or identities of gang members, their associates, cryptocurrency wallets used to receive ransom payments, funding sources, communication channels, or details related to the servers and digital infrastructure supporting their operations. Information that contributes to the seizure of infrastructure or the arrest of individuals linked to the group may qualify for the announced reward. Cybersecurity experts believe that public participation can play a valuable role in combating ransomware. Intelligence shared by insiders, researchers, or organizations

Banning Open-Source AI Models to Protect Our <b>Cybersecurity</b> May Do the Opposite

In an escalating effort to give the federal government power over the AI industry, some members of the Trump administration have reportedly tried to implement a “de facto ban” on foreign-made open-source AI models. This ban would apply to any non-US-made AI model, but the goal seems to be to specifically target Chinese AI labs, which often release their models as open source. The recent release of the Kimi K3 AI model from Chinese developer Moonshot fueled these concerns. Kimi K3 matched and in some cases exceeded the capabilities of American-made AI models such as those made by OpenAI, Anthropic and Google. Its July release sent shockwaves through Wall Street – not unlike other AI model drops, but with one big difference. Kimi K3 was released as an open-weight model, while American AI leaders like OpenAI and Anthropic companies keep their tech closed with very few exceptions. Open-source AI typically refers to open-weight models. Weights are characteristics that tell the model how to behave – giving more weight to useful answers than incorrect ones, for example. Open-source advocates have said that to be truly open-source, AI companies should release or clarify their training data sources. AI companies haven’t been forthcoming; OpenAI and other companies are being sued by publishers and artists for allegedly violating their copyrights in AI training. (Disclosure: Ziff Davis, CNET’s parent company, in 2025 filed a lawsuit against OpenAI, alleging it infringed Ziff Davis copyrights in training and operating its AI systems.) Open-weight models give developers more insight into how top models work. Nearly 80% of developers use open models, a recent Mozilla report found. “Open-weight models are everywhere in the industry already,” said Linda Griffin, vice president of global policy at Mozilla. “So a world without them would hit a lot of people.” Tech companies immediately

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses. This activity has resulted in boil water notices and sustained manual operations. These threat actors are targeting water entities of all sizes. Even water organizations with mature cybersecurity processes should validate their external connections, as this targeting activity includes cellular modems installed by operators, vendors, or system integrators that may not be documented or included in routine attack surface scans. OT assets exposed to the internet have an increased risk of defacement, configuration changes, operational disruptions, and, in severe cases, physical damage. CISA recommends organizations implement the following mitigations: - Disconnect the PLC from the internet. Remote access for operational purposes should go through a VPN or gateway device, not directly to the PLC. - Enable password protection and change default passwords. - Allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. After disconnecting PLCs from the internet, operators should ensure they have a known clean backup of the PLC image in case they are locked out by a modified password. Note: Owners, operators, and integrators of Rockwell Automation MicroLogix 1400 PLCs should see Rockwell Automation’s IMPORTANT NOTICE: Restoring Access to a MicroLogix™ 1400 Controller When the Password Is Unknown for guidance addressing this activity. To securely enable remote access to your OT systems, CISA recommends system owners, operators,