Industry Letter Date: August 11, 2026 To: All DFS-Regulated Entities Re: Cybersecurity Threat Alert – N-central Vulnerability The New York State Department of Financial Services (“DFS” or “Department”) is issuing this alert to DFS-regulated entities regarding an active cybersecurity campaign targeting a security vulnerability in the remote monitoring and management system N-central, developed and maintained by N-able (“Alert”). N-central is used by some managed service providers (“MSPs”) to centrally monitor, patch, and remotely access their customers’ services and endpoints (also referred to as Remote Monitoring and Management services or RMM services). Threat actors are targeting a Known Exploited Vulnerability in N-central to compromise MSP environments. Once access is obtained, threat actors may create or register for new services, allowing continued access even after compromised N-central credentials are revoked. Attackers are using a compromised MSP’s environment to move laterally into their customer’s networks and information systems with administrator network privileges. DFS-regulated entities should promptly determine whether N-central is used within their environment or by any MSP or other Third-Party Service Provider that supports their information systems. Where N-central is used, DFS-regulated entities should work with their service providers to assess and mitigate potential exposure, including reviewing N-central activity for evidence of unauthorized or persistent access; verifying that applicable security updates, including software patches and other threat mitigation steps, have been implemented; and evaluating whether any systems or credentials were affected. While the vulnerability addressed in this Alert is likely limited to MSPs, the senior governing bodies and senior officers of DFS-regulated entities must actively engage in cybersecurity risk management, including through monitoring and oversight of third-party service providers. To that end, the Department expects DFS-regulated entities that may be exposed to cybersecurity risk related to the N-central vulnerability to appropriately manage this risk through due diligence and engagement with Third-Party Service
Aug 11, 2026 · via dfs.ny.gov
As concerns about cybersecurity increase, robotics developers are getting tools to test it in simulation. VicOne Inc. yesterday released the free VicOne Radeis Extension for NVIDIA Isaac Sim, which it said enables developers to test how selected attack scenarios could affect the behavior of their own robot models. “Robotics companies are moving from proving individual use cases to deploying robots at scale in real-world environments. As that shift accelerates, the industry must validate not only whether robots function as designed, but [also] whether they remain reliable when the digital systems they depend on are compromised,” stated Max Cheng, CEO of VicOne. “Cyber-safety validation must become a standard part of robotics development,” he added. “By turning DEF CON research into repeatable simulation scenarios, we are helping developers address these risks earlier and build more resilient physical AI at scale.” Founded in 2022, VicOne has built its cybersecurity for physical AI on its automotive expertise. The Trend Micro subsidiary said its software and services can protect the digital systems that shape how vehicles and robots see, decide, and act. Tokyo-based VicOne helps OEMs, Tier 1 suppliers, robot makers, and operators identify cyber risks early, assess their potential safety impact, and protect systems in operation. The company said it has uncovered more than 180 zero-days across automotive and robotics, added over 100 million threat intelligence signals monthly, and filed 30 U.S. patent applications for AI-defined vehicle and physical AI security. VicOne learns from DEF CON findings Robot makers invest heavily in functional testing, safety engineering, and simulation, but cyber-induced conditions can still fall outside conventional test plans, noted VicOne. At DEF CON 34’s Robotic Hacking Community, the company conducted its Physical AI Safety Stress Test CTF (capture the flag) exercise. Security researchers tested how digital compromises could alter robot behavior under controlled conditions.
Aug 11, 2026 · via therobotreport.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Aug 11, 2026 · via youtube.com
OpenAI hits pause on new bot testing over ‘critical’ risk concerns in latest AI cybersecurity incident See more of our coverage in your search results. Add The New York Post on Google OpenAI is tapping the brakes on some “internal activities” involving its new model, Astra, over concerns it might have reached a critical cybersecurity risk level – following a string of AI bots that went rogue during internal testing, carrying out hacks and creating fake online identities. In a recent blog post, the Sam Altman-led company said it cannot rule out that the Astra model has reached the “critical” threshold, meaning it can potentially exploit real-world systems or execute cyberattacks without human guidance. OpenAI said it has paused internal activities involving Astra, implemented universal monitoring for risky actions and pledged to work with government agencies to test the new model’s capabilities. “We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution,” OpenAI said in the Friday blog post. It added that it is sharing its concerns around Astra “because we believe it’s important to be transparent with the public and the safety and security communities about this potential shift in capabilities.” OpenAI, Anthropic and Meta have all recently disclosed events in which their early-stage AI models went rogue during internal testing – stoking fears around the potential risks of out-of-control AI models and pushing lawmakers to call for a so-called “AI Kill Switch.” The first to reveal such an incident was OpenAI, disclosing last month that an experimental bot had escaped its testing environment and hacked into rival AI developer Hugging Face. OpenAI said Friday that Astra was not the model involved in exploiting
Aug 11, 2026 · via nypost.com
The FBI is investigating how an unidentified federal agency was recently swept up in a yearslong campaign involving North Korean remote IT workers fraudulently obtaining jobs at major companies and other organizations. The North Korean campaign has been notorious for using remote IT contract jobs to infiltrate both Fortune 500 companies and smaller private sector firms. But experts contacted for this story said it’s not surprising the public sector has been implicated as well. They said the incident highlights a new kind of insider threat, as well as potential gaps in the government and industry vetting processes, especially for jobs like IT support work. During a panel discussion at a July 28 conference hosted by the Digital Government Institute in Washington, D.C., Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, was asked whether the North Korean remote IT worker issue had impacted government. “Without getting into ongoing investigations, we identified just this past week a [Democratic People’s Republic of Korea] remote IT worker that was working for the federal government,” Hemmen said. “Still kind of unpacking that recent case. It’s actually a little bit baffling to me, not understanding this particular agency’s process. But the short answer is yes, we are seeing remote IT workers not just in the private sector – although a vastly higher proportion in the private sector – but we’re also seeing this impact the government to a degree.” The FBI declined to comment further on the story. It’s unclear what agency was impacted, how long the intrusion lasted, and whether any sensitive data was stolen. It’s highly likely Hemmen was referring to a remote IT employee doing contract work on behalf of an agency, experts confirmed, given extensive background investigation and identity proofing requirements needed to get a federal job. Such a
Aug 11, 2026 · via federalnewsnetwork.com
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s everything else that made the Monday recap. ⚡ Threat of the Week Anthropic's Model Attempts to Poison Open-Source Project — A new evaluation conducted by the U.K. AI Security Institute (AISI) found that AI models with access to the internet reached out into the real world to target individuals and organizations autonomously across 10 of the total of 122 runs. Of 19 such actions recorded, 17 originated from Anthropic's Mythos 5 and the remaining two involved OpenAI's GPT-5.6-Sol with cyber classifiers. In the most serious case, Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real open-source project and engaged in social engineering by creating fake online identities and using them to pressure the project's maintainer to approve the code. Ultimately, a human maintainer caught and refused to approve the malicious code. "These attempts were unsuccessful, and our investigations have not evidenced any resulting real-world harm," AISI said. But this is the first time we have seen risks around autonomy and deception manifest this clearly, without specific prompting, in the real-world." Ransomware Encryption Dropped 38%. Here's What Attackers Do Instead Data Encrypted for Impact fell from 21% to 13% of samples in one year. Meanwhile, Process Injection held #1 for the third straight year and sandbox evasion surged to #4. The Red Report 2026 ranks the top 10 ATT&CK techniques and the behaviors to
Aug 11, 2026 · via thehackernews.com
Struggling Boston cybersecurity company Rapid7 said on Monday it cut 12 percent of its workforce, or about 300 jobs, in the second quarter. The cuts, announced alongside the company’s second-quarter earnings report, came as the company’s revenue and profits have been shrinking, and less than a month after the company told the Globe it was laying off only 21 people. The company did not immediately respond to a request for comment Monday. Shares of Rapid7, which were down 35 percent over the past year before Monday’s news, jumped 6 percent in aftermarket trading. Larger rivals, meanwhile, have been thriving, with fears of AI-powered cybercrooks driving up sales. Shares of CrowdStrike have gained 112 percent over the past year, and Palo Alto Networks’ stock price is up 130 percent. Rapid7 brought in revenue of $860 million last year, but on Monday the company forecast 2026 sales would shrink to as little as $837 million, as some customers held off on switching to Rapid7’s newer cybersecurity offerings. Chief executive Wael Mohamed, who replaced longtime leader Corey Thomas in June, has been overhauling Rapid7’s executive ranks and trying to add more AI to its software. “Rapid7 is a good company ready to be great, but getting there requires clear choices, strong execution, and the discipline to focus on what matters most,” Mohamed said in a statement on Monday. The job cuts will cost $11 million to $12 million, largely to cover severance, Rapid7 said. The growth of cyber apps powered by artificial intelligence is roiling the software security industry. Older firms like Rapid7 and Snyk have been trying to adapt their apps, while new local firms starting out using using AI, such as 7AI and Realm.Security, have raised hundreds of millions of dollars to fund hiring sprees. Even before the emergence of AI,
Aug 11, 2026 · via bostonglobe.com
Legislation recently introduced in the U.S. Senate would reauthorize the Rural and Municipal Utility Advanced Cybersecurity (RMUC) Grant and Technical Assistance Program at the Department of Energy through 2031 and authorize $250 in appropriations.
S. 5360, the Rural and Municipal Cybersecurity Act, was introduced late last week by Senators Dave McCormick (R-PA), John Hickenlooper (D-CO), John Hoeven (R-ND), John Curtis (R-UT), and Catherine Cortez-Masto (D-NV).
Originally authorized in 2021, APPA and numerous public power utilities have received funding to develop and promote cybersecurity resources and training through RMUC.
S. 5360 is the Senate companion bill to H.R 7266, which is sponsored by Representatives Mariannette Millers Meeks (R-IA) and Jennifer McClellan (D-VA) and passed the House in late June.
APPA strongly supports S. 5360/H.R. 7266.
Aug 10, 2026 · via publicpower.org
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted in a series of posts on Bluesky. "It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned directory." Although the exact vulnerability exploited by the threat actor as part of this campaign is unclear, the tech giant said it likely involves the exploitation of CVE-2026-18577, a newly disclosed security flaw in N-able N‑central, to obtain initial access. The vulnerability is assessed to be a patch bypass for CVE-2026-18556, both of which allow authentication bypass and account takeover in susceptible versions. The vulnerabilities have since been flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited in the wild. Storm-1175 is the name assigned to a China-based threat actor with a history of deploying Medusa ransomware after exploiting security flaws in Mirth Connect (CVE-2023-37679, CVE-2023-43208), ConnectWise ScreenConnect (CVE-2024-1709, CVE-2024-1708), JetBrains TeamCity (CVE-2024-27198, CVE-2024-27199), and Fortinet FortiClient EMS (CVE-2023-48788). In an analysis published in October 2025, Microsoft also attributed the threat actor to the exploitation of a critical security vulnerability impacting Fortra GoAnywhere (CVE-2025-10035) to facilitate the deployment of Medusa ransomware. The group, per the Windows maker, weaponizes a combination of zero-days and N-day vulnerabilities to carry out high-velocity attacks and break into susceptible internet-facing systems by taking advantage of the window between vulnerability disclosure and patch adoption. "In this new activity, Storm-1175's post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz," it
Aug 10, 2026 · via thehackernews.com
Finance and payments are gearing up for a new future. And they’re spending big to do so. During the first half of the year, the cybersecurity industry recorded over 215 mergers and acquisitions (M&A) collectively worth over a hundred billion dollars. But the more consequential signal was buried beneath the transaction count. Artificial intelligence (AI) security, machine identity, industrial infrastructure, browser protection, behavioral fraud detection and automated remediation are increasingly appearing on buyers’ shopping lists. The enterprise attack surface is expanding to new targets: AI agents, industrial equipment, cloud applications, browsers, application programming interfaces (APIs) and automated software. At the same time, attackers are exploiting something more fundamental than technical vulnerabilities: how people and machines behave within interconnected digital systems. That shift is turning cybersecurity M&A into a useful leading indicator. See more: Wall Street’s New Cybersecurity Threat Starts With a Phone Call Fraud and Cybersecurity Are Becoming the Same Problem Cybersecurity buyers are assembling platforms capable of connecting signals that historically lived in separate tools. Identity data alone may not reveal an attack. Neither may behavioral data, network telemetry, browser activity or application logs. But correlated together, those signals can show that an authenticated employee is behaving unusually, an AI agent is accessing unexpected information or an industrial device is communicating with a system it normally does not. Visa’s planned $2.4 billion acquisition of BioCatch, announced last week (Aug. 3), makes this emerging trend difficult to ignore. BioCatch already serves more than 350 banks across 21 countries, protecting users with its AI) and machine learning-based solutions that analyze thousands of application, behavioral, device, and network signals like keystrokes and device handling to separate legitimate users from fraudsters. PYMNTS Intelligence collaborated with Visa DPS on “The Issuer Risk Playbook,” which found that 42% of bank and non-bank issuers rank fraud
Aug 10, 2026 · via pymnts.com
CrowdStrike and Palo Alto Networks hit record highs on Monday. Each rose more than 5%, after a week in which the Black Hat conference in Las Vegas turned into an argument about AI agents. CNBC’s Samantha Subin reported the move. CrowdStrike gained 11.32 points, or 5.28%. Palo Alto added 17.84 points, or 4.90%, and traded at $381.70 in the afternoon. The rest of the sector followed. Tenable and Rubrik rose more than 7%. Netskope and Zscaler each gained about 5%. A price target overtaken the same day BTIG lifted its price target on Palo Alto to $380 on Monday. The firm called that about 4% upside from Friday’s close. The stock passed it within hours. Palo Alto changed hands at $381.70 that afternoon, above a target raised the same morning. Buyers are repricing this sector faster than the analysts who cover it. CrowdStrike’s target went to $237, which BTIG put at 11% upside from Friday. Rubrik went to $109. None of the three revisions followed an earnings release. What changed at Black Hat BTIG’s analysts spent the conference talking to partners, vendors and customers. The consistent theme, they wrote, was that AI agents “have fundamentally changed the threat landscape.” They called the environment meaningfully worse than before. They also said the deployment of AI security tools sits “only in the early innings”. Cantor’s analysts reached a similar view. AI has moved “from being a cybersecurity feature to a key pillar” of both the attack surface and the infrastructure on either side of it, they wrote. The trade has a name on television too. Jefferies analyst Joseph Gallo argued last week that cyber spending will benefit from AI anxiety over the next couple of quarters. The week supplied its own evidence Black Hat did not lack for demonstrations. Researchers used the
Aug 10, 2026 · via thenextweb.com
Pleasants Set to Bring Cybersecurity Perspective to Trevecca Students | Faculty For Scott Pleasants, cybersecurity is not just a technical field. It’s also about people: what they share online and who they can trust. “Cyber threats are exploiting the human element,” Pleasants said. “It creates unrest.” Pleasants is joining Trevecca as director of strategic initiatives for cyber security, AI and information sciences to educate and equip students about the growing need and urgency for cybersecurity. Pleasants brings experience in Christian higher education, military service, cybersecurity, artificial intelligence and Christ-centered leadership. He previously served at Liberty University, where he was one of the founding members of the school’s engineering program. His professional background includes a long career of strategic innovation, cybersecurity, artificial intelligence, technology commercialization, strategic partnerships, organizational transformation, higher education strategy, entrepreneurship, civil-military collaboration, leadership development and faith and vocation integration. Pleasants’ work at Trevecca comes at a time when Nashville and Middle Tennessee continue to grow in fields where cybersecurity and information systems are increasingly important. “Nashville is exploding,” Pleasants said, pointing to growth in healthcare, technology, music, film and business. “We’re going to create core partnerships in the Nashville area.” Pleasants said he is helping Trevecca think about artificial intelligence, cybersecurity and information systems, including how those fields will affect students as they prepare for future careers. Regarding his new role, he points to the importance of cybersecurity in healthcare and opportunities to serve military-connected students. Healthcare in particular is what Pleasants sees as a clear need; as more systems rely on artificial intelligence and digital information, the amount of sensitive data creates new risks. “There’s so much information that can be exploited,” Pleasants said. That concern extends beyond organizations. Pleasants said students in every field need to understand how cyber threats work because the risks are increasingly
Aug 10, 2026 · via blog.trevecca.edu
Please wait while your request is being verified...
Aug 10, 2026 · via citybiz.co
Just days after an OpenAI model went rogue and hacked into Hugging Face, the company has announced it is pausing work on a separate upcoming model due to concerns that it may have gained “critical cyber capabilities.” The company says its internal evaluations found that the model, dubbed Astra, made “significant advancements in agentic coding and cybersecurity” and crossed the Critical cybersecurity threshold set by its Preparedness Framework. Under the framework, introduced for internal assessment by the AI startup in 2023, “a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal.” In simple terms, if Astra is given an extremely complex task, it can hack into systems autonomously. The explanation mirrors the disclosure OpenAI released about its rogue AI last month: the model had escaped its sandboxed test environment and exploited a zero-day vulnerability in third-party software. After OpenAI made its first disclosure, Anthropic released a statement saying its Claude AI had gained unauthorized access to three organizations as well. Meta followed up soon after with a similar disclosure about one of its AI models. OpenAI’s latest statement comes after over 1,300 employees from Meta, Google, Anthropic, and OpenAI wrote to the US government seeking its intervention to slow AI development. For now, OpenAI will pause all internal activities involving Astra until it meets the company’s security requirements. “We will work with relevant government agencies and select AI safety organizations to test the capabilities for this model,” the company added. Disclosure: Ziff Davis, PCMag's parent company, filed a lawsuit against OpenAI in April 2025, alleging it infringed Ziff Davis copyrights in
Aug 10, 2026 · via uk.pcmag.com
Analysts at BTIG said AI agents have fundamentally changed the threat landscape, lifting price targets on both cybersecurity companies BTIG analysts, writing to clients after the conference, said AI agents had emerged as the foremost attack vector and that the overall security environment was "meaningfully worse," while noting that the rollout of AI-driven security tools remains nascent. "The single most consistent theme across our conversations — partners, vendors, and customers alike — was that AI agents have fundamentally changed the threat landscape," the analysts wrote, according to CNBC. BTIG raised its price target on CrowdStrike to $237 per share, implying roughly 11% gains from where the stock closed on Friday. The firm said AI is catalyzing a fresh wave of modernization across endpoint security, with CrowdStrike standing to gain most directly given the nature of its core offerings. BTIG also raised its price target on Palo Alto Networks to $380 per share, about 4% higher than Friday's close, arguing that the company's identity platform and offerings such as XSIAM and Chronosphere are well placed to capitalize as AI agents proliferate across enterprise environments. Analysts at Cantor described a broader shift in how the industry views AI. "AI has moved from being a cybersecurity feature to a key pillar of both the attack surface and the attacker/defender infrastructure," the firm's analysts wrote. Other cybersecurity stocks also posted gains on Monday. Tenable and Rubrik were both up more than 7%, and Netskope and Zscaler added roughly 5% apiece. The rally follows a period of sustained attention to the cost and complexity of AI adoption at the enterprise level. Palo Alto Networks CEO Nikesh Arora argued earlier this year that AI token prices need to fall by as much as 90% before large-scale enterprise AI deployment becomes practical, describing current pricing as a
Aug 10, 2026 · via qz.com
Putting frontier cyber models in more trusted hands Expanding the Daybreak Cyber Partner Program to close the growing defense gap. We’re bringing OpenAI’s frontier cyber models to the security partners protecting organizations around the world. Together, we’re putting frontier intelligence directly into the products, services, and security operations defenders already depend on. More organizations can now find serious vulnerabilities, fix them faster, and stay ahead of threats moving at machine speed. AI is changing cybersecurity faster than most organizations can respond. Attackers can identify vulnerabilities, develop exploits, and move through complex systems with increasing speed and scale. At the same time, security teams are confronting a growing volume of weaknesses across the software and infrastructure they protect. Finding those vulnerabilities is only the beginning. The harder challenge is determining which ones pose a real threat and fixing them before they can be exploited. Too many defenders still lack access to the frontier models that can help them do that. Our Daybreak Cyber Partner program includes leading security & services partners such as Accenture(opens in a new window), IBM(opens in a new window), Capgemini(opens in a new window), Cognizant(opens in a new window), EY(opens in a new window), KPMG(opens in a new window), PwC(opens in a new window), NCC Group(opens in a new window), and SpecterOps(opens in a new window) along with technology partners Palo Alto Networks(opens in a new window) , CrowdStrike(opens in a new window), Cisco(opens in a new window), Sophos(opens in a new window), Akamai(opens in a new window), Fortinet(opens in a new window) and Cloudflare(opens in a new window). These partners bring deep security expertise and established relationships with organizations around the world. By bringing our frontier cyber models into their services, we can help more defenders find serious vulnerabilities, validate which ones matter, and fix them
Aug 10, 2026 · via openai.com
Suisun City Declares State of Emergency After Cyberattack Suisun City has shut down its computer network and declared a state of emergency after a cybersecurity attack impacted services like police and fire dispatch in the community. The city said “malicious software” infected information technology systems around 5:45 a.m. on Friday. The attack “hit critical public safety operations, including 911 routing, police and fire dispatch, records and City services,” according to a statement on the city’s website. Suisun City Police dispatchers began taking calls through the Solano County dispatch center and officials activated its emergency operations center. “From a public safety standpoint, there’s no threat to the public at this time,” said Michael Elm with the Suisun City Public Information Office. “For a resident experiencing daily life in Suisun City, there really isn’t anything going to be any impact to them other than maybe not being able to pay their water bill or process permits at the moment.” The city said it shut down its entire IT network to save evidence for a federal investigation. Suisun City’s IT system is set up to automatically shut down when it detects an intruder, according to Elm. Elm said that there was no interruption to emergency services or to dispatchers being able to answer 911 calls; however, some software became unusable because of the network shutdown. On Saturday morning, City Council members held a special meeting to declare a state of emergency, which the city said allows it to “quickly access emergency support services and to recoup costs.” Elm said “a lot of the investigation” will be starting tomorrow when private and government cybersecurity experts come to the city. The entire system will remain shut down while the city clears each function to bring operations back online. They’re only the latest local government in
Aug 9, 2026 · via kqed.org
🚀 Introducing the CloudSEK MCP Server! Read more Cybersecurity in manufacturing is the practice of protecting factories, production lines, and the industrial systems that run them from cyberattacks. It differs from cybersecurity in most other sectors in one decisive way: an attack on a manufacturer does not just expose data, it can stop production, damage equipment, and endanger people. That impact is why manufacturing has become the world's most-attacked industry. According to the IBM X-Force Threat Intelligence Index, manufacturing accounted for 27.7 percent of all cyberattacks in 2025, the most of any sector and the fifth consecutive year in the top spot. What makes manufacturing cybersecurity distinct is the mix of two worlds: the information technology (IT) systems that run the business and the operational technology (OT) that runs the plant floor. Securing both at once, across legacy machines never built for the internet, is the central challenge. This guide explains why manufacturers are targeted, why cybersecurity for manufacturing matters, how IT and OT differ, the top threats and real incidents that define the field, the frameworks that govern it, and how to secure production. Attackers choose targets by leverage, and manufacturing offers more of it than any other sector. Production cannot pause without immediate financial damage, with unplanned downtime costing manufacturers roughly $260,000 an hour on average, so attackers know a ransomware victim is likely to pay quickly to restore operations. That pressure shows in the numbers: Dragos attributes about 68 percent of all industrial ransomware to manufacturing, and the average manufacturing ransomware incident costs around $8.7 million, most of it from downtime rather than the ransom itself, which makes paying look cheaper than waiting even when it is not. Three structural factors compound the pressure. Manufacturers hold valuable intellectual property, from product designs to proprietary processes, and IBM
Aug 9, 2026 · via cloudsek.com
Central Texas College is investing in hands-on cybersecurity education with a new $20,000 cyber range that will allow students to attack, defend and analyze computer systems in an environment designed to mirror situations they could encounter in the workforce. The cyber range was purchased with federal funding through the Carl D. Perkins Career and Technical Education grant. The funding covered the components needed for the system, while CTC students provided the labor to build the servers that will power the training environment. Shane Curington, professor of computer science at CTC, said the range is intended to move cybersecurity education beyond classroom theory by allowing students to apply their skills against other students. “What we’re doing is we’re installing servers for our cybersecurity cyber range,” Curington said. “We’ll have attackers and defenders, and they’ll be able to try to attack the systems. We’ll have students try to attack the systems, and we’ll have students trying to defend the systems.” The student-built aspect of the project adds another layer of practical experience. Before using the cyber range for simulated attacks and defenses, students gained experience assembling the physical infrastructure behind the system. Once operational, the range will function as a controlled environment where students can practice cybersecurity techniques without targeting outside computer systems. The exercises will follow what the cybersecurity industry commonly calls red-team and blue-team operations. Red teams act as attackers and attempt to identify and exploit vulnerabilities, while blue teams defend the systems, monitor activity and respond to attempted intrusions. Curington compared the concept to the more familiar distinction between black-hat and white-hat hackers but said students will use the red-team and blue-team terminology. Students will not remain on one side. “We’ll switch from attackers to defenders,” Curington said. “Everyone will have a chance to attack. Everyone will have a
Aug 9, 2026 · via kdhnews.com
Cases of AI escaping the lab, infiltrating other companies and trying to deceive people have all made headlines in recent weeks. And in one case, AI models even worked together to break free from their test environments. Does this mean the machines are taking over? Not quite. AI isn’t the mastermind behind today’s most widespread cyber threats; it’s people who can use AI nefariously – and for nefarious purposes. AI has given bad actors massive power, allowing them to create malicious software, research targets, create convincing schemes and automate attacks at an unprecedented pace. One in four data breaches were driven by AI from February 2025 to March 2026, according to an IBM report. And Americans lost more than $893 million to AI-related scams last year, the FBI says. But experts say real-world threat actors – that is, people – are still the ones pulling the strings. AI agents have only perpetuated existing attack methods, like phishing and malware scams, rather than creating wholly new ones. “It’s the humans that we need to watch out for,” said Oren Etzioni, professor emeritus at the University of Washington and former CEO of the Allen Institute for Artificial Intelligence. “AI is just the tool.” AI going rogue Some recent incidents have shown what AI is capable of in the real world, not just in theory, igniting fears about whether the technology is advancing too quickly. Those breaches also show how unpredictable AI can be when interpreting instructions. OpenAI’s models, for example, were trying to pass a cybersecurity test when they broke out of their test environment and breached another company, even though they weren’t told to do so. Patrick Fussell, global head of adversary simulation at IBM, compared AI to a genie. “You want to ask it a wish, but you have to
Aug 9, 2026 · via ctvnews.ca