No-frills tech news

National Cybersecurity Awareness Month is starting!

Each October, IT Services observes National Cybersecurity Awareness Month with a full schedule of events, lectures, content, and more. Main theme for NCSAM 2026: AI and Data Privacy This year, National Cybersecurity Awareness Month (NCSAM) focuses on AI, cybersecurity, and data privacy. By practicing good cybersecurity habits and understanding how our data is being used, we can stay safer and more secure. Helen has a master’s degree in public policy, blogs about cybersecurity stuff and is the author of “Navigating the Cybersecurity Career Path”. Location: Boyd Hall parking lot Please read carefully: Every document shredded still needs to be compliant with university retention policies.

Epic shifts focus to cybersecurity while AI, interoperability agenda still on track, company says

During Modern Healthcare's Leadership Summit on Tuesday, CEO Judy Faulkner said the company was pausing most technology development to focus on system security. "We’re participating in Project Glasswing and using AI tools to stay ahead of cybersecurity threats that are growing across all industries," Epic's spokesperson said. Anthropic's Project Glasswing is an AI cybersecurity initiative that brings together major technology companies along with organizations responsible for maintaining critical digital infrastructure. During Epic's UGM in August, Stirling Martin, Epic's chief security officer, confirmed that Epic was participating in the initiative. Epic's heightened focus on cybersecurity comes as healthcare organizations rapidly adopt AI tools, even as the industry grapples with the risks of accelerating innovation and mounting calls from some leaders to slow AI development.

FBI probes cyberattack tied to third-party jobs portal

The FBI is investigating a cyberattack on its jobs portal after the cybercrime group ShinyHunters said it hacked the system and stole a vast trove of sensitive data from the bureau. ShinyHunters told 404 Media that it hacked into the jobs portal using a zero-day vulnerability in Oracle’s PeopleSoft human-resources platform, a tactic it has used before. Foreign governments could also use FBI employees’ personal data to monitor them and undermine their investigations and operations. The FBI’s jobs portal is currently offline and displays a banner explaining that the site is unavailable. Kaiser pointed to a 2016 breach that led to the theft of personal information belonging to tens of thousands of FBI employees.

AI in cybersecurity: Balancing automation and talent development

September 23, 2026 Managed service providers (MSPs) are increasingly looking to artificial intelligence to address the cybersecurity talent gap. The integration of AI into cybersecurity operations presents a complex challenge for MSPs. While AI can absorb routine Security Operations Center (SOC) and help desk tasks, improving efficiency and lowering costs, this automation risks removing the foundational experience that junior analysts traditionally gain from reviewing numerous alerts. To counter this, experts suggest redesigning entry-level roles to focus on reviewing AI decisions, investigating exceptions, and developing critical thinking skills. Ultimately, the industry must focus on cultivating expertise through mentorship and structured career progression rather than solely relying on automation or traditional recruitment methods.

GAO flags FAA cybersecurity weaknesses across aviation communications, spectrum threats and real-time monitoring

The U.S. Government Accountability Office (GAO) reported that the Federal Aviation Administration (FAA) has not sufficiently addressed cybersecurity threats to aircraft communications. The report examines, among other objectives, extent to which FAA has identified and mitigated spectrum-related cybersecurity threats; extent to which FAA collaborated with federal partners to defend against cybersecurity threats; and what specific cybersecurity vulnerabilities exist in key communication applications. GAO reported that FAA identified emerging spectrum-related cybersecurity threats to the NAS and international flight routes. As a result, FAA may not have sufficient information to identify, assess, and address cybersecurity risks affecting critical aviation communications systems. In conclusion, GAO reported that the NAS relies on increasingly interconnected aviation systems vulnerable to evolving cybersecurity threats, including spectrum interference, spoofing, and jamming.

Itron, Crytica Partner on Grid-Edge Cybersecurity

Itron and Crytica Security have announced a technology collaboration focused on detecting cyber threats and improving operational visibility across utility grid-edge infrastructure. The collaboration is designed to integrate Crytica’s Rapid Detection, Alert and Isolation technology, RDAi, into Itron’s Grid Edge Intelligence portfolio. Itron’s Grid Edge Intelligence portfolio includes layered device, network, communications and data protection. Our collaboration with Crytica builds on that foundation by adding rapid, embedded threat detection designed for the next generation of grid-edge applications.” The collaboration comes as Itron works to support utilities transitioning from traditional advanced metering infrastructure to Grid Edge Intelligence, combining distributed intelligence, connectivity, analytics and security.

What are the risks of not having a cybersecurity plan?

Here, iuvo breaks down the risks every business should know and why a cybersecurity plan is a foundational strategy. Legal, Regulatory and Contractual Obligations Without a cybersecurity plan, businesses may face legal, regulatory and contractual issues at the same time. A strong cybersecurity plan starts with a clear view of how attackers gain access to business systems, data and networks. The Role of Strategic IT Planning in Cybersecurity A cybersecurity plan is strongest when it connects security decisions to business priorities. Building a Cybersecurity Plan for Your Business A strong cybersecurity plan gives businesses a practical way to reduce risk, respond faster and make better security decisions over time.

The Continuous KYC

In each case the identity file is still clean, still evidenced, still perfectly compliant. For an institution operating across several of them, KYC stops being a risk discipline and becomes an administrative one. Continuous KYC changes what’s being maintained. Continuous KYC doesn’t mean continuously asking customers for things. The customer experience of continuous monitoring should be frictionless and based on mutual trust.

How strong is your cybersecurity program?

In today’s evolving landscape of cyber threats, malicious actors can attack from many angles, including exploiting passive DNS (PDNS) data or discovering unknown vulnerabilities. While prime contractors and other large companies in the Defense Industrial Base (DIB) have various tools to protect themselves, small to medium-sized businesses (SMBs) are more vulnerable. On September 30 at 12PM ET, join our free webinar Cybersecurity: Bridging the Gap Between Prime Contractors & SMBs to find out how the National Security Agency Cybersecurity Collaboration Center can help you stay safe through the free enhanced services it offers to Department of Defense (DOD) contractors. Speaker Samantha Anim Campaign Manager National Security Agency, Cybersecurity Collaboration Center Samantha Anim is currently the Campaign Manager at the National Security Agency, Cybersecurity Collaboration Center. In this role, she is responsible for increasing partnership participation and enrollment into NSA provided no-cost cybersecurity services for Defense Industrial Base (DIB) companies to help them defend against Nation-state and other cyber actors.

EWF Adds Cybersecurity Sales Executive to Advisory Board

Haley leads Seemplicity’s global sales organization and go-to-market operations as the company develops AI-based exposure management and response technology for cybersecurity teams. Her appointment adds commercial and operational cybersecurity experience to an advisory group that includes executives from Abnormal AI, Accenture, EY, Security Risk Advisors and Target. Haley previously held senior positions at Exabeam, Veracode, APIsec and Qualys, working across enterprise sales, global field operations, technical alliances, cloud marketplaces and go-to-market strategy. Before moving into technology leadership roles, Haley worked as a vulnerability management practitioner at CVS Caremark, giving her experience on the customer side of enterprise cybersecurity operations. Her appointment also gives EWF an adviser currently responsible for commercializing cybersecurity technology as AI becomes a larger component of exposure-management platforms and enterprise security operations.

11 Cybersecurity CEOs Getting the Industry’s Attention in 2026

Cybersecurity’s center of gravity is shifting. Cloud infrastructure, software supply chains, AI agents, data security, and autonomous defense are creating new categories and giving a new generation of security CEOs plenty to talk about. These 11 executives stand out not necessarily because they run the largest cybersecurity companies, but because their companies and ideas are increasingly part of the industry conversation. 1. Amiram Shachar, Upwind Amiram Shachar is having a particularly consequential year. The Upwind co-founder and CEO previously founded Spot.io, which was acquired by NetApp, and now leads one of the fastest-growing names in cloud security. In September 2026, Upwind raised $300 million at a $3.8 billion valuation, more than doubling its valuation from the roughly $1.5 billion level reported earlier in the year. The latest financing underscores the growing investor interest in securing increasingly AI-driven cloud environments, while putting Shachar among the more closely watched CEOs in cybersecurity. 2. Rob Gurzeev, CyCognito Rob Gurzeev is CEO and co-founder of CyCognito, a leading attack surface management (ASM) platform. Rob has spent his early career on the attacker's side of the problem, previously leading offensive security development for private-sector organizations and intelligence agencies. Today he and his team help enterprises reduce external risk using proprietary AI-powered technologies that simulate adversary activity, from reconnaissance through the full attack chains. This puts Gurzeev at the center of the debate over how enterprises should answer advances in offensive AI, and the new classes of risk AI adoption creates. 3. Tina D’Agostin, Alcatraz AI Tina D’Agostin leads Alcatraz AI, which applies AI-powered facial authentication to physical access control. Her background spans more than 25 years in security technology and solutions, including leadership at Johnson Controls. In 2026, Alcatraz raised a $50 million Series B, while the company reported significant growth in data-center and enterprise

Terra Industries leads strategic investment in Nigerian cybersecurity startup Aeon

Terra Industries has led a $1 million pre-seed round in Aeon, a Nigerian cybersecurity company building sovereign cyber defense for Africa and the Global South. said Samuel Ogbonyomi, co-founder and chief executive officer of Aeon, who founded the company with Ben Eluan and Alex Idowu. Terra is excited to partner with Aeon and its investment follows a successful pilot earlier this year. The two companies have now formed a commercial joint venture to deploy Aeon’s cyber defense technology across military and commercial operations. Together, both companies will co-execute contracts for government and corporate organizations across the Global South, with Terra protecting physical assets and Aeon protecting digital assets.

Turn your military experience into a paid, federal, cybersecurity career

Apply for and join VA’s Cybersecurity Apprenticeship Program for Veterans. The inaugural class of the Cybersecurity Apprenticeship Program for Veterans (CAPV) completed its program in August 2026. VA’s apprenticeship program turns your military discipline and mission focus into real cybersecurity skills. You train hands-on at the VA Cybersecurity Operations Center in Martinsburg, West Virginia, working alongside experienced professionals. Cybersecurity leaders say mentoring apprentices has re-energized even their most experienced staff and sharpened the whole team’s performance.

Google Confirms AI Model Hacked Companies In Cybersecurity Tests 09/21/2026

by Laurie Sullivan , 5 hours ago Google confirmed Friday that a Gemini AI model accessed the internet and hacked other companies' systems during a test of its cybersecurity capabilities. In one case the Gemini model guessed passwords until it gained access to a protected system, The Wall Street Journal writes. These events highlight the importance of training powerful AI models to act responsibly." When an AI model is deployed to detect or stop sophisticated threats, it is often granted powerful tools and network access. It is unclear whether these companies -- from Google to OpenAI and Anthropic -- gave their AI model less privilege to enforce "principle of least privilege" access across its runtime, network and data, treating the AI model as an non-trusted user executing non-trusted code.

Gemini AI hacked 3 real companies after escaping cybersecurity test

Google's Gemini artificial intelligence model hacked into the computer systems of three real companies during a cybersecurity test in May, marking the first known case of Google's AI autonomously carrying out such intrusions. The incidents occurred during a "capture the flag" cybersecurity exercise conducted by Irregular, an independent company that evaluates AI systems. "These events highlight the importance of training powerful AI models to act responsibly," she added. Irregular said Google's incident stemmed from the same underlying testing problem involved in similar cases affecting other major AI companies. Google is now the fourth major AI developer linked to an incident in which an AI model being evaluated gained unauthorized access to a real company's systems.

This Week's Top Five Stories in Cyber

Experts React to New EU Cyber Resilience Act Reporting Rules The EU Cyber Resilience Act (CRA) is entering a critical new phase, as mandatory reporting obligations are now in effect for manufacturers across the bloc. The rules mark a significant shift in how organisations must approach product security, putting greater pressure on manufacturers to identify, manage and report cyber risks throughout the product lifecycle. What Do Experts Have to Say About the Revolut Data Breach? CHOSEN BRICK: What We Know about Iranian Spyware Cyber intrusions have long been wielded to meet geopolitical ends and spyware is Iran’s new weapon of choice. Iran-linked cyber actors are “trying to trick targets” into downloading malware that can be used to track their movements, NCSC warns.

Quantum X Labs Announces Quantum-Native Cybersecurity Architecture Under QuantumQ Division

Israeli deeptech developer Quantum X Labs Inc. (NASDAQ: QXL) has unveiled a multi-dimensional cybersecurity initiative under its QuantumQ Security operational division. The announcement follows the appointment of former Mossad Chief Yossi Cohen as President of Quantum X Labs’ Scientific Advisory Board to guide commercialization across defense, aerospace, and critical infrastructure sectors. Rather than focusing solely on post-quantum algorithms or hardware security modules, the three-part framework investigates quantum-state properties for threat detection (including the LayerQake protocol), data confidentiality (Qatacomb), and distributed verification of digital assets and key ownership. Formerly operating as Viewbix Inc. before a corporate rebranding and business pivot in April 2026, Tel Aviv-based Quantum X Labs maintains legacy ad-tech and enterprise software subsidiaries (Gix Media and Metagramm) alongside its expanding quantum portfolio. Review the press release on GlobeNewswire here and examine our previous analysis of Quantum X Labs Launches “Qatacomb” Quantum-Native Security Research Initiative here.

First-generation MSU Denver student turns cybersecurity training into internship at Sierra Space

Victor Torres-Corona spent three years after high school figuring out his next step. Torres-Corona, a first-generation college student, said the center's hands-on training program, Centurion Secured, has made a major difference in his education. "The amount of resources that are available to me as a first-gen student, and as a cybersecurity student, are really important," he said. Student analysts monitor real data for Colorado communities, according to Richard MacNamee, director of the MSU Denver Cybersecurity Center. That training helped Torres-Corona land an internship in cybersecurity at Sierra Space, the Colorado-based space technology company.

Lawmakers mull cybersecurity concerns as they prepare for overhaul of Georgia’s voting system

Election security concerns have long been at the forefront of the conversation around election equipment. State lawmakers have passed legislation to phase out the use of QR codes on ballots, but are still developing the guidelines that state lawmakers will use when selecting their next statewide voting system. Here are some of the election security issues state lawmakers will have to consider. Whichever system the state turns to next, state leaders say, will likely be in use for at least the next decade. "We have a very, very robust state system that takes care of us that knows when things like that are going on and they alert us very quickly," she said.

Google confirms Gemini hacked into three companies during cybersecurity test months ago

Following a Wall Street Journal investigation, Google has confirmed that Gemini went rogue in May 2026, accessing the internet and breaching the security of three different companies. Google’s Heather Adkins, VP of security engineering, said: This event highlights the importance of training powerful AI models to act responsibly. These events highlight the importance of training powerful AI models to act responsibly. The exact Gemini model used in the test has not been confirmed, but the May 2026 timing alone rules out the latest Gemini models. More on Gemini: Gemini app for macOS adding send and read iMessage integration Gemini 3.8 Live Extended Thinking powers Gemini Live, Gmail, & Keep Google brings Gemini for desktop app to Windows