Organizations have become exceptionally good at discovering vulnerabilities but far less effective at determining which ones actually matter. The result is an operational paradox: security teams are processing more findings than ever. Development teams spend increasing amounts of time investigating issues that ultimately pose little or no business risk. More visibility has not necessarily produced better security outcomes. Large organizations may identify tens of thousands of vulnerabilities each quarter, but the majority are likely to be false positives, theoretical risks or findings that are not practically exploitable. According to the SANS 2025 Detection and Response Survey, false positives remained the leading challenge, cited by 73% of respondents. The operational cost can reach thousands of hours per quarter spent validating alerts instead of reducing meaningful risk. The industry’s greatest cybersecurity bottleneck is no longer finding vulnerabilities; it’s separating signal from noise. And there is still a lot of noise. Consequently, leaders must transition from “point-in-time” scanning to a continuous, validated model that focuses scarce human resources on the few critical risks that truly matter. Why traditional vulnerability management creates alert fatigue The volume of security alerts has reached a flashpoint, creating a “firehose of white noise” that frequently paralyzes development and security teams. The average large organization may be processing tens of thousands of issues quarterly, yet as some research has found, a majority of these detections are false positives or theoretical risks that do not pose a direct threat to the business. This lack of accuracy carries a staggering operational cost: enterprise-scale organizations can lose thousands of hours per quarter to manual triage and validation. This is based on our Enterprise CISO reports we deliver quarterly to clients. According to the Forrester State of Privacy and Cybersecurity, Q1 2026, 21% of organizations see false positives as a key challenge. Not
Jul 29, 2026 · via cybersecurity-insiders.com
On June 23, 2026, Analog Devices, Inc. (the “Company”) identified unauthorized access to certain Company systems. Following detection of the unauthorized access, the Company immediately activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities. The Company has also notified and is coordinating with law enforcement authorities. The Company’s operations were not interrupted throughout the duration of the incident. The Company’s investigation has found that certain files were exfiltrated from the affected systems. The Company’s investigation into the nature and scope of the exfiltrated information remains ongoing. To the Company’s knowledge, the data has not been publicly released or used for fraudulent purposes. The Company will continue to monitor for any indication of misuse and will take appropriate action if warranted. The Company will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. While the Company’s investigation continues, based on information currently known, and the containment and mitigation measures taken, the Company does not believe the June 23, 2026 incident is reasonably likely to materially impact its business, operations, or financial condition. Separately and unrelated, on July 26, 2026, the Company was made aware of public reports regarding a disparate cybersecurity matter and is currently assessing its validity, scope, and any potential impact. Forward-Looking Statements This Current Report on Form 8-K contains forward-looking statements regarding future events that are subject to the safe harbor created under the Private Securities Litigation Reform Act of 1995 and other safe harbors under the Securities Act of 1933 and the Securities Exchange Act of 1934. All statements other than statements of historical fact are statements that could be deemed forward-looking statements. These statements are based on current information, beliefs, assumptions and expectations about the matters reported herein. Words such as
Jul 29, 2026 · via stocktitan.net
A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham's water plant went offline, and the city asked residents to minimize water use until treatment resumed. Plymouth reported cellular communications problems at two water towers and multiple wastewater lift stations but continued operating manually. South St. Paul and Maple Plain maintained services after automated utility controls were affected, with Maple Plain declaring a local state of emergency to support its response. Minnesota IT Services (MNIT) said on July 28 that it was not aware of any active requests for residents to change their drinking-water use. Officials have not publicly identified the attacker, affected products, exploited vulnerability, or whether data was stolen. "At this point, we can confirm that more than 30 water systems throughout the state were impacted," MNIT told The Hacker News. "The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions." MNIT said the incidents shared common characteristics, including their timing, methods of access and the type of infrastructure targeted. Those similarities supported the state's description of the activity as coordinated. The agency said the similarities were consistent with activity observed by federal partners in other states and industries, but investigators could not yet determine whether a single actor was responsible for all the incidents. Investigators have also identified similarities in how the systems were accessed, MNIT said, but the agency is not sharing specific technical details while the investigation continues. Attribution has not been finalized. MNIT said it is coordinating containment, investigation, recovery and threat-intelligence sharing with state agencies, the Cybersecurity
Jul 29, 2026 · via thehackernews.com
Government contractors should not mistake the Department of Defense's (DOD) recent suspension of Cybersecurity Maturity Model Certification (CMMC) Phase II certification requirements as any sort of reprieve from their cybersecurity requirements or the government's intent to enforce CMMC. The recently announced LOGZONE False Claims Act (FCA) settlement serves as a stark reminder of the Department of Justice's (DOJ) focus on and pursuit of contractors whose cybersecurity representations fail to match reality. This builds on FCA cybersecurity fraud recoveries more than tripling in each of the past two years, exceeding $52 million across nine settlements in fiscal year 2025 alone.1 Bottom Line The suspension of CMMC Phase II is a welcome development that has dominated most government contracting headlines over the past weeks. Yet the DOJ does not need CMMC third-party assessments to bring claims under the FCA. Existing Defense Federal Acquisition Regulation Supplement (DFARS) contractual obligations – including compliance with NIST Special Publication 800-171 and reporting accurate Supplier Performance Risk System (SPRS) scores – remain fully enforceable, and the DOJ has demonstrated a consistent practice of using FCA liability to punish inaccurate self-assessments and unimplemented cybersecurity controls.2 The LOGZONE Settlement On June 18, 2026, the DOJ announced that LOGZONE INC., a Huntsville, Alabama, defense contractor, agreed to pay $507,144 to resolve FCA liability relating to cybersecurity violations in Department of the Navy contracts. The settlement is modest in dollar terms but provides important takeaways for the defense industrial base. LOGZONE provided logistics, inventory, and facilities support services under two Navy contracts at Stennis Space Center. Those contracts incorporated DFARS 252.204-7012 (requiring adequate security for covered defense information and implementation of NIST SP 800-171 controls), DFARS 252.204-7019, and DFARS 252.204-7020 (requiring contractors to post summary-level NIST SP 800-171 self-assessment SPRS scores). In October 2021, LOGZONE posted a perfect SPRS self-assessment score
Jul 29, 2026 · via bakerdonelson.com
Secure.com today announced that Nicholette Brown Hill has been named Founding General Manager, Americas and Head of Sales for Global Strategic Markets. The newly created executive role reflects the company’s push to accelerate growth and customer acquisition across North and South America as it expands its AI-native cybersecurity platform globally. In her new role, Nicholette will oversee Secure.com’s growth strategy across the Americas while leading sales efforts for global strategic markets. She will focus on expanding customer acquisition, developing channel and alliance partnerships, and strengthening Secure.com’s position as a leader in cybersecurity risk visibility and continuous security validation. Nicholette joins Secure.com with more than 20 years of experience leading sales organizations, strategic partnerships, corporate development, and go-to-market strategy across the cybersecurity, cloud, and enterprise technology sectors. Most recently, she served as Chief Strategy Officer at GUARDDOG.AI, where she led market expansion and built partnerships advancing AI-driven cybersecurity adoption. Prior to GUARDDOG.AI, Nicholette held several executive leadership roles at Meriplex, including Vice President of Corporate Development and Strategic Alliances and Vice President of Sales and Channel. During her tenure, she drove brand development, built strategic partnerships, and executed growth strategies. She also supported the company’s successful recapitalization by Vitruvian Partners. Her experience also includes executive sales roles at VMware and Rackspace, where she consistently delivered growth across enterprise, cloud, networking, and security markets. "Nicholette brings a rare combination of deep experience working at some of the industry's biggest brands paired with a proven ability to scale startups," said Uzair Gadit, Founding Partner of Disrupt.com and CEO of Secure.com. "That range makes her one of the most accomplished growth leaders in cybersecurity and enterprise technology today. Her ability to build high-performing organizations, forge transformative partnerships, and execute winning go-to-market strategies makes her the ideal leader for this next phase of Secure.com's growth.
Jul 29, 2026 · via wboc.com
A shortage of cybersecurity experts has left Australian organisations vulnerable as state-backed hackers and criminal gangs harness artificial intelligence to accelerate their attacks, warns the head of one of the country’s most prominent cybersecurity firms.
CyberCX founder and chief executive John Paitaridis believes there is a simple solution: “We’ve got to prepare the next generation of cybersecurity professionals to be more AI literate. That’s the strategic imperative; we need to tackle this head-on.”
Loading...
Jul 29, 2026 · via afr.com
Microsoft has launched MAI-Cyber-1-Flash, its first cybersecurity-specific AI model, alongside a new agentic security platform called Perception. MAI-Cyber-1-Flash has been designed to identify vulnerabilities in complex codebases. The model powers MDASH, Microsoft's existing harness for software vulnerability identification and remediation. According to Microsoft, the model performs competitively on Cyber Gym, an established benchmark used to evaluate AI cybersecurity models, and does so at a lower computational cost than comparable models from competitors. Moreover, the company said it is deploying the model into production immediately, combining it with GPT 5.4 within the MDASH harness. Perception automates security workflows Perception, the platform launched alongside the new model, is built to deploy groups of AI agents across security workflows, including bug identification and remediation. It integrates with MDASH and organises its agents into three categories: red teams, which simulate potential attacks and assess likely vulnerabilities based on threat actor behaviour; blue teams, which detect and triage existing vulnerabilities; and green teams, which carry out corrective actions once issues have been identified. Mustafa Suleyman, the co-founder of DeepMind and current CEO of Microsoft AI, described the platform as a way for enterprise defenders to respond to AI-enabled attacks using AI-based tools at comparable scale and speed. Dave Weston, the lead engineer for Perception, said the platform consolidates tasks previously requiring multiple specialised security roles, covering detection, prioritisation, posture correction, and code remediation, into a single automated workflow. Microsoft's announcement comes as several major AI providers have introduced cybersecurity-focused products over recent months. Anthropic released a security platform named Mythos in April 2026 through Glasswing, a programme limited to a small number of partner organisations. Microsoft said MAI-Cyber-1-Flash and Perception will be available in preview from 3 November 2026. Industry implications The launch reflects a broader shift among large AI developers toward specialised, security-focused models,
Jul 29, 2026 · via thepaypers.com
The energy sector’s OT cybersecurity talent is retiring faster than it can be replaced A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years. Marco Ayala has spent more than two decades inside industrial control system security. He is technical director for global energy at ABS Consulting, and he puts the risk with the discipline he thinks owns it. “Reliability, uptime and safety are paramount. Cybersecurity affects all these outcomes, making it an engineering problem.” The bill for getting it wrong has grown. Cyberattacks on U.S. utility companies climbed nearly 70 percent over a single year. Dragos and Marsh McLennan put worst-case global OT cyber losses at $329.5 billion across all sectors. Waterfall Security counted a 146 percent year-over-year rise in OT sites hit by attacks with physical consequences. Operators spend the cybersecurity money elsewhere. OT security draws roughly 20 percent of it, and laptops and enterprise tools take the rest. Recovery is where the plans break Shankar Somasundaram runs Asimily, which inventories connected devices across industrial sites. He watches the restart expose what the recovery plan assumed. “I’ve seen plants with a backup of a controller, but the engineer who knew why it was configured the way it was is long gone. So the backup is restoring a state no one can confirm is actually still correct. Plants end up reverse-engineering their own process under immense pressure (mid-outage!), which is the worst possible time to
Jul 29, 2026 · via helpnetsecurity.com
Last week, U.K. based healthcare billing software provider Craneware announced that it had been impacted by a serious cybersecurity event, indicating that a significant amount of customer and employee data has been compromised. As healthcare billing often entails sensitive patient and medical data, this is a critical event that indicates a broader and ongoing trend across the industry. In fact, healthcare is undergoing one of the most severe cybersecurity crisis periods in the history of the industry. Medical billing software companies and developers seem to be especially targeted in recent years, as hackers are realizing that these companies are often the gateways to numerous hospitals across the globe. Additionally, these targets often contain the most amount of high yield, concentrated datasets, making the threats even more serious and therefore, worthy of higher ransom collection threats. By no means is Craneware alone in this tragedy; other billing companies, such as TriZetto, CareCloud and Episource, have undergone similar breaches over the last year, indicative of a broader industry calamity. According to Becker’s and per the Identify Theft Resource Center, healthcare data breaches climbed to 281 in just the first half of 2026; the number is second only to the financial services industry, which had 387 encounters in the same time period. Per the report, "the healthcare figures come inside a record-setting national picture. The U.S. recorded 1,803 total data compromises across all sectors in the first half of 2026, affecting an estimated 471.2 million individuals — a total that already exceeds all of 2025’s 297.5 million victim notices in just six months.” Per the HIPAA Journal, there has been a significant uptick in the number of data breaches in healthcare since 2009. The report also highlights the largest confirmed healthcare data breaches of all time, with some events impacting more than 190
Jul 29, 2026 · via forbes.com
Executive Summary On 28 July 2026, Origin Energy publicly confirmed a significant data breach affecting approximately 900,000 current and former customers. The breach resulted in unauthorized access and exfiltration of personally identifiable information (PII), including names, addresses, dates of birth, phone numbers, account details, and partial payment information such as the last four digits of credit cards or the BSB and last three digits of bank accounts. The incident was first identified as a potential threat in early July 2026, but only confirmed as a credible security incident on 22 July 2026, with public disclosure and customer notification following shortly thereafter. The breach is currently under investigation by Australian authorities, including the Australian Cyber Security Centre, the National Office of Cyber Security, the Australian Federal Police, and the Office of the Australian Information Commissioner. No technical indicators of compromise (IOCs) have been published as of the date of this report. All facts in this summary are corroborated by the official Origin Energy disclosure (Origin Energy, 28 July 2026), ABC News (ABC News, 28 July 2026), and Nine.com.au (Nine.com.au, 28 July 2026). Technical Information The Origin Energy data breach represents a major compromise of customer data within the Australian energy sector, a critical infrastructure domain. The breach involved unauthorized access to systems containing sensitive customer information. The types of data confirmed as compromised include names, addresses, dates of birth, phone numbers, account information, and partial payment details (last four digits of credit cards or the BSB and last three digits of bank accounts) (Origin Energy, 28 July 2026; Nine.com.au, 28 July 2026). Attack Vector Analysis The specific technical vector used to gain initial access remains undisclosed. Origin Energy began reviewing a "potential security threat" in early July 2026, which was initially not deemed credible (Origin Energy, 28 July 2026; ABC News,
Jul 29, 2026 · via rescana.com
Stay ahead of rapidly changing global cybersecurity requirements for medical devices. This two-day interactive workshop will provide regulatory, quality, and technical professionals with the tools and knowledge needed to address cybersecurity risks, strengthen regulatory submissions, and meet expectations from health authorities worldwide that you can apply immediately. Cybersecurity remains mission-critical for medical device manufacturers. As regulatory expectations, threats, and technologies continue to evolve, organizations must stay current with the latest approaches to securing devices and supporting regulatory submissions. Securing medical devices and documents for regulatory submissions from cyberattacks is challenging. Many medical device companies struggle to retrofit their security programs to address hardening, vulnerability management, and global incident response. New statutory requirements in the United States are increasing the focus on planned postmarket activities in the submission process. Health authorities spanning the US, European Union, Australia, Canada, and Japan have issued cybersecurity guidance that is essential for regulatory affairs professionals to understand. In addition to premarket concerns, some of the guidance also includes expectations for post-market expectations. This timely interactive virtual workshop will help regulatory and quality professionals develop the knowledge they need to help steer their organizations in the right direction when it comes to global cybersecurity expectations. Technical staff will get a better understanding of how to translate regulatory expectations into concrete design and development. Organizational leaders will gain strategic knowledge that will increase the likelihood of gaining green lights from regulators while also teaching them how to establish trust with customers concerned about risk related to medical devices on their networks. Upon completion of this two-day workshop, attendees will: Basic: Content is introductory in nature and requires no requisite knowledge or experience to grasp concepts and related exercises. Basic educational activities are meant to establish a foundation of knowledge and/or competence that will be expanded upon in
Jul 29, 2026 · via raps.org
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jul 29, 2026 · via youtube.com
Israeli cybersecurity startup Way Security has raised $20 million in a funding round co-led by Insight Partners and Glilot Capital, as the company looks to address one of the enterprise security industry's most persistent challenges: the costly and often unsuccessful implementation of identity and access management (IAM) systems. The company, founded by cybersecurity veterans Yossi Barishev and Yonatan Rosenberg, has developed an AI-powered platform designed to automate much of the operational work required to deploy and maintain IAM systems. Rather than replacing existing identity platforms, Way Security aims to help organizations get more value from the software they already use by reducing their dependence on consultants and lengthy implementation projects. Identity management has become increasingly central to enterprise cybersecurity as organizations move more applications and services to the cloud and traditional network boundaries disappear. At the same time, cyberattacks increasingly target user identities and credentials instead of infrastructure. Despite the strategic importance of IAM, implementation remains a major obstacle. Large enterprise projects often take years to complete, cost millions of dollars and require extensive customization and ongoing professional services. Industry observers note that implementation and operational costs frequently exceed the price of the software itself. Way Security's founders argue that this imbalance has become an accepted part of the market. "IAM is the only space in cyber where overspending and under-delivering is an acceptable reality," said Barishev, the company's CEO. "The more time we spent doing IAM, the more we realized the industry had normalized mediocrity and almost given up trying to solve some of its biggest challenges." The company's platform uses AI agents to automate many of the repetitive tasks traditionally handled by consultants, systems integrators and internal engineering teams. Those tasks include deploying identity controls, enforcing lifecycle management and managing access policies across complex enterprise environments. According to
Jul 28, 2026 · via ynetnews.com
- GAO has flagged three priority areas for DHS action - DHS carries 507 open recommendations, 39 of them priority - The 2026 Homeland Security Summit will examine AI, cyber defense and more The Government Accountability Office has recommended that the Department of Homeland Security improve disaster preparedness and response, enhance IT and cybersecurity, and strengthen immigration and border security policies and data. As DHS works to modernize operations and address evolving security challenges, government and industry leaders will gather at the 2026 Homeland Security Summit on Nov. 12 to examine artificial intelligence, cyber defense and operational capabilities at major DHS agencies. Sign up now to join the discussion. What Are GAO’s Recommendations to DHS? In a letter to DHS Secretary Markwayne Mullin, GAO called on the Federal Emergency Management Agency to address fragmentation across its disaster recovery programs by consolidating or simplifying overlapping requirements. The congressional watchdog pointed to ongoing complaints from state and local officials, who have described difficulty navigating a patchwork of federal recovery programs, each with its own rules, timelines and limited information-sharing between agencies. On the cybersecurity front, GAO flagged the Cybersecurity and Infrastructure Security Agency’s Continuous Diagnostics and Mitigation program, first launched in 2012, as an initiative that several agencies have not fully adopted, citing insufficient guidance from the agency. GAO recommended that CISA issue clearer direction to help agencies roll out network security and data protection tools, along with guidance on how agencies should work together to reduce cyber risks facing operational technology systems. On immigration and border security, GAO said U.S. Immigration and Customs Enforcement’s public detention figures fall short of the actual count by tens of thousands of individuals. The watchdog also reported that U.S. Customs and Border Protection’s rollout plans for non-intrusive inspection equipment at the southwest border leave out
Jul 28, 2026 · via executivegov.com
STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem. Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local privilege escalation, not remote code execution, so an attacker needs a foothold on the machine before any of it applies. The demonstrated exploit also requires unprivileged user namespaces, the CONFIG_NET_ACT_GACT and CONFIG_NET_CLS_FLOWER kernel options, and a kernel-specific return-oriented programming (ROP) chain containing hardcoded offsets. Those conditions narrow the immediate exposure, but full exploit source code is now public. The upstream fix landed on June 1, 2026, and has since been backported to several stable kernel branches. The Linux CNA record lists vulnerable ranges beginning with Linux 4.14. Fixed releases are 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.94, 6.18.36, and 7.0.13, with the mainline fix entering 7.1-rc7. Linux users should install a distribution kernel carrying the fix rather than rely on the upstream version number alone. The Hacker News found no entry for the flaw in CISA's Known Exploited Vulnerabilities catalog and no official report of exploitation in the wild as of July 28, 2026. Lee said in a technical write-up that AI assisted with vulnerability discovery, production of a Kernel Address Sanitizer (KASAN) proof of concept, and optimisation of the race window. STAR Labs also released the CentOS-targeted exploit code. Without the model, prompts, service, or interaction record, the disclosure is difficult to use as a benchmark of AI capability or to separate the system's contribution from Lee's direction and judgement. The Hacker News asked STAR Labs for details on the AI system, test environment, and disclosure timeline and
Jul 28, 2026 · via thehackernews.com
Cyber threats are escalating faster than most enterprise budgets can absorb, and the platform vendors capturing the largest share of that spend are pulling away from the pack. AI-generated phishing, ransomware, and identity attacks are pushing CISOs toward consolidated security stacks. That is showing up cleanly in the numbers for the three names below. Each is US-listed on Nasdaq, each posted a beat-and-raise quarter, and each has a defensible moat that will benefit them in the second half of 2026. CrowdStrike (CRWD) CrowdStrike (NASDAQ:CRWD | CRWD Price Prediction) is the AI-security bellwether, and Q1 FY27 confirmed the recovery from the July 2024 Falcon sensor incident is complete on the operating side. Revenue hit $1.39 billion, up 25.6% year over year, beating the $1.36 billion consensus. Non-GAAP EPS of $1.10 topped the $1.07 estimate, marking eight consecutive EPS beats. Net new ARR came in at a record Q1 $255.8 million, up 32%, pushing total ARR to $5.51 billion, up 24%. Free cash flow reached $468.5 million, a 34% FCF margin. The bull case is platform depth. 51% of customers now run six or more modules, Charlotte AI is monetizing, and the QuiltWorks coalition with OpenAI and Anthropic positions Falcon as connective tissue for enterprise AI deployments. CEO George Kurtz framed the quarter bluntly: “In Q1, the worlds of cybersecurity and frontier AI collided: this was the Mythos moment. CrowdStrike is AI security infrastructure, critical to successful AI adoption.” Management raised FY27 revenue guidance to $5.91 billion to $5.96 billion. The stock split 4-for-1 on July 2, and shares are up 60.45% year to date on a split-adjusted basis. Risk: Legal and remediation costs tied to the 2024 outage still linger, stock-based comp ran $317.6 million in Q1, and forward valuation is rich at roughly 159x forward earnings. That is the price
Jul 28, 2026 · via 247wallst.com
Microsoft yesterday launched Project Perception, a new cybersecurity platform based on autonomous AI agents. The company also unveiled MAI Cyber 1 Flash, its first dedicated AI model for cybersecurity missions. Microsoft says the launch comes amid increasing use of AI by attackers to develop high-speed and large-scale attacks. Thus, instead of adding AI capabilities to existing security products, Microsoft has built a new architecture in which AI agents are a central part of the defense system. The agents operate continuously, collecting data from different sources in the enterprise, locating vulnerabilities, examining their risk level and helping to address them before they can be exploited for an attack. The aim, Microsoft says, is to move defense from a reactive model, in which events are handled after they have occurred, to a model that tries to reduce risk in advance. Next generation of cybersecurity systems Microsoft's R&D center in Israel plays a central role in the process. The MDASH system, developed in Israel and first presented at the Build conference last month, will be the first system to incorporate MAI Cyber 1 Flash. The system is designed to detect and analyze software vulnerabilities using AI, and is one of the first examples of the practical application of Project Perception. According to Microsoft, a significant part of the capabilities on which the new platform is based were developed in Israel. This means that one of the first capabilities to be used within the framework of the new architecture relies on development carried out at the local R&D center. Beyond the technological announcement, this is also a strategic move. The cybersecurity market is currently in a race to develop systems based on AI agents, which can perform an increasing part of the work of security teams autonomously. Through Project Perception, Microsoft seeks to strengthen
Jul 28, 2026 · via en.globes.co.il
You need to enable JavaScript to run this app.
Jul 28, 2026 · via qualcomm.com
Maryland Announces Cybersecurity Funding Opportunities for Local Government
MDEM is opening applications for the Local Cybersecurity Support Fund to help strengthen cyber resilience across Maryland
HANOVER, Md. (July 27, 2026) — The Maryland Department of Emergency Management (MDEM) is announcing a funding opportunity through the Local Cybersecurity Support Fund (LCSF), a fund created by the State and managed by MDEM. The Fund aims to improve cyber security preparedness at the local government level to include local school systems, local school boards, and local health departments. The application period for the LCSF is open now, and applicants have until August 28 to apply.
This funding opportunity can be an important tool that local governments can use to bolster their cybersecurity defenses in an increasingly complex and evolving threat landscape.
For more information on the LCSF Application process, please visit the Cyber Preparedness Unit’s LSCF webpage or email [email protected].
###
Jul 28, 2026 · via news.maryland.gov
CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.
Jul 28, 2026 · via cisa.gov