Korea's Cyber Security Command will take part in a U.S.-led international cybersecurity exercise this week, aimed at helping allies better respond to malicious cyberspace activities, the defense ministry said Monday.
A total of 25 countries, including Korea, will participate in the Cyber Flag exercise, scheduled to run from Monday through Friday (local time) in Virginia, according to the defense ministry.
Launched in 2011, the Cyber Flag is designed to strengthen partnerships between the United States and its key allies by testing their skills to detect and expel enemies in cyberspace under simulated attack scenarios.
It marks the fifth time Korea has taken part in the drills since its first participation in 2022.
The command anticipates that the drills will help enhance its defensive cyber operations capabilities and bolster partnership with participating nations by conducting joint analysis of potential cyber threats.
Korea plans to continue to expand its cooperation with the U.S. through other joint cybersecurity drills, including the Cyber Alliance exercise, as well as through personnel and technology exchanges in the cyber sector, the ministry said.
Jul 27, 2026 · via koreatimes.co.kr
Doha, Qatar: The Ministry of Education and Higher Education (MoEHE) has highlighted the importance of its recently introduced Digital Citizenship courses in equipping students with the knowledge and skills needed to navigate the digital world safely and responsibly, as part of the country’s broader efforts to strengthen cybersecurity awareness among young learners. In remarks to Qatar TV recently, Acting Assistant Director of the Department of E-Learning and Digital Solutions, Eng Lolwah Hassan Al Nuaimi said the courses were introduced to help students make productive use of their summer break through self-directed learning while enhancing their digital literacy. She noted that the rapid pace of digital transformation has made technology an integral part of students’ daily lives, making it essential to prepare them to use digital tools safely, responsibly and confidently. “The goal is to prepare digitally aware citizens who possess the knowledge and skills to use technology securely and responsibly by strengthening concepts of digital citizenship and online safety,” Al Nuaimi said. The ministry launched the Digital Citizenship courses through the Qatar Education System for Grade 5 and Grade 8 students in government schools, offering age-appropriate learning content tailored to the needs of each educational stage while maintaining the common objective of fostering responsible digital behaviour. Al Nuaimi said the courses were developed in partnership with several national entities, including the National Cyber Security Agency and the Ministry of Communications and Information Technology, ensuring students benefit from high-quality educational resources that reflect national cybersecurity priorities. For Grade 5 students, the curriculum covers safe internet use, protecting online accounts, identifying reliable and unreliable information, intellectual property rights and strategies for dealing with cyberbullying. Grade 8 students, meanwhile, study more advanced cybersecurity topics, including personal data protection, device and network security, software updates and data backup, as well as secure digital communication.
Jul 26, 2026 · via m.thepeninsulaqatar.com
Network attacks no longer target only large corporations. Small businesses, retail chains, healthcare offices, and teams spread across many locations all face the same risks. Attackers look for the easiest way in. If your company depends on cloud tools and connected devices, your network is already a target, whether or not you have noticed anything suspicious yet. Remote work, branch offices, and cloud adoption mean data now travels farther and touches more systems than before. Because of this, network security best practices can no longer sit on top of your infrastructure as an afterthought. Security must be part of how a network is designed, built, and supported from day one. Solid network infrastructure services help businesses match security with a network that can grow across many sites. Building a Secure Network Foundation Every strong security plan starts with how the network is built. If every device can talk freely to every other device, one compromised machine can quickly become a company-wide problem. Splitting traffic into clear zones, such as guest, IoT, and internal systems, keeps sensitive data separated and limits how far an attacker can move. Business-grade firewalls and modern switches add another layer of protection. When set up correctly, they do more than open and close ports. Features such as deep packet inspection and intrusion prevention show your team what traffic is actually moving, not just where it is headed. For companies with more than one location, consistency is often the hardest part. One site might run updated equipment with locked-down settings, while another still uses old hardware and default passwords. This is where multi-location business IT security becomes important, since standardizing setup across every site avoids the small mistakes that quietly create openings for attackers. A strong foundation includes: - Clear separation of guest, IoT, and internal traffic
Jul 26, 2026 · via hackernoon.com
A Canadian woman was arrested and accused of espionage while working as an intern in the operational headquarters of the NATO military alliance, Belgian authorities said Saturday. Belgium’s Federal Prosecutor’s Office said it launched an espionage investigation after NATO’s security services tipped off Belgium’s military intelligence. Authorities then detained “a Canadian citizen of Chinese origin” on Friday, a day after raiding the suspect’s home and workplace inside NATO’s vast command center. “She is suspected of spying on behalf of a third country and of being a member of a criminal organization,” the prosecutors said in a statement. The strategic headquarters of the Allied Powers, known as SHAPE, is located in the southern Belgian city of Mons near the French border. Military officials at SHAPE plan and command joint strategy, tactics and operations. The alliance’s political headquarters is in Brussels, where ambassadors from member nations meet to discuss defense spending, drone incursions and cyber threats. NATO’s Cyber Security Centre is based at SHAPE. “At this time, there is no indication that NATO or SHAPE operational readiness, command and control arrangements, or ongoing tasks have been adversely affected. SHAPE continues to fulfil its responsibilities without interruption,” said Col. Martin L. O’Donnell, a spokesperson for SHAPE. Both Canada and Belgium are members of the 32-nation military alliance that in 2021 labeled China a security challenge” alongside active threats in Russia and the Middle East. NATO leaders have said China is working to undermine global order, develop its military opaquely, and run destabilizing disinformation campaigns. They said that Beijing’s goals and “assertive behavior present systemic challenges to the rules-based international order and to areas relevant to alliance security.” The Chinese government denounced the statement and said its military buildup was defensive. The arrest in Belgium comes at a crucial time for the alliance as
Jul 26, 2026 · via fortune.com
Two of OpenAI’s cybersecurity-focused models broke out of a testing sandbox this week and went on to hack the AI research platform Hugging Face in an effort to solve a security benchmark test. Plus, researchers this week shed light on newly identified malware that is capitalizing on blind spots in AI software development infrastructure to grab logins and other sensitive data, even causing destruction to victims’ target files and systems. Looking at the more traditional security nightmare of embedded devices, researchers this week shed light on a car alarm that was installed in vehicles across the US—and that is still silently lurking with a flaw that leaves millions of vehicles vulnerable to hacking and paralysis. There’s a patch available, and WIRED has details on how to check whether your car may have been exposed. US states have worked to bar ICE agents from wearing masks, but Trump administration lawyers are pushing back, claiming that anti-mask laws endanger agents. Their public evidence is incredibly thin, though. Meanwhile, a WIRED investigation revealed that Madison Square Garden briefly disabled its sprawling, controversial surveillance system for Taylor Swift’s rehearsal dinner on July 2. And the ACLU is equipping lawyers in Massachusetts with a new toolkit to expose state surveillance technologies used for building criminal cases—shedding light on everything from face recognition tools to AI-written police reports. Analysis of satellite images of Myanmar shows dozens of alleged scam compounds cropping up in recent months following a purported crackdown on the criminal operations in the region. Plus, a novel analysis of apps marketed to US service members found that more than one in eight contained foreign code, including code developed by US adversaries like Russia and China. And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves.
Jul 26, 2026 · via wired.com
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and Luno to target retail traders and cryptocurrency investors across 12 countries in 25 languages. Its landing pages fingerprint visitors, showing suspected researchers and bots an empty page while selected targets receive a convincing copy of the impersonated service. The defense against that is the ordinary one: install trading and wallet software from the vendor's own site, not from an ad. The documented chain does not rely on a browser vulnerability or remove Mark of the Web (MotW). Confiant's analysis documents the delivery, not execution of the file inside the browser, and does not establish whether the final download starts automatically or requires a click. The landing page begins preparing the delivery path without waiting for a download click. It registers a page-scoped ServiceWorker at /sw.js, then builds a SharedWorker from JavaScript already embedded in the page, so the worker source never appears as a separate fetch. The SharedWorker requests /config, which returns a template, a secondary runtime URL, and session-specific random values. The browser retrieves and decompresses a clean Bun runtime from that second domain, purelogicbox[.]org in the published sample response. Base64 blobs in the configuration supply the Portable Executable (PE) header, section table, and a .bun section containing malicious JavaScriptCore bytecode for app.js. Bun runs on Apple's JavaScriptCore engine and legitimately supports compiling applications and bytecode into standalone Windows executables. The worker then generates a large pseudorandom byte stream using AES in counter mode (AES-CTR). It then follows the supplied template as a byte-copy
Jul 26, 2026 · via thehackernews.com
Russian state-backed hackers have targeted US nuclear scientists, defense contractors and government employees in a cyber-espionage campaign using techniques first deployed against Ukraine, CNN reported, citing cybersecurity researchers and a new joint warning from Western intelligence agencies. The campaign, attributed to a Russian-linked group tracked as Laundry Bear, Void Blizzard and TA488, has targeted Western government and commercial organizations since at least July 2025, according to a joint cybersecurity advisory released by US and allied agencies. JOIN US ON TELEGRAM Follow our coverage of the war on the @Kyivpost_official. The hackers’ targets suggest Moscow is seeking intelligence on nuclear fusion research as well as information that could support Russia’s war against Ukraine, CNN reported. US cybersecurity firm Proofpoint, which investigated parts of the campaign, found that the group targeted email servers belonging to US “nuclear installations and the defense industrial base.” The hackers were particularly interested in “entities and users with an interest in nuclear fusion,” Proofpoint researcher Greg Lesnewich told CNN, suggesting Moscow may have been seeking insight into advances made by competitors in the field. The campaign also targeted federal and local government agencies, law enforcement, education, energy, media, technology organizations and the defense industry, according to the joint advisory. Zelensky Ready to Sign Peace Deal at White House or Mar-a-Lago as Rubio Rejects Moscow’s Anchorage Claims Ukraine used as testing ground The warning was issued by the US National Security Agency, FBI, Cybersecurity and Infrastructure Security Agency and other American bodies together with intelligence and cybersecurity agencies from more than a dozen allied countries, including the UK, France, Italy, Poland, Canada, Australia and several other NATO members. The agencies identified a broader pattern in which Russian cyber groups first deploy techniques against Ukrainian targets before expanding their operations against Western countries. “Extensive Ukrainian targeting, prior to use
Jul 26, 2026 · via kyivpost.com
Guest Post: Prof David Hoffman on “A Call for AI Accountability” Many Lawfire® readers my have seen disturbing headlines last week like this one from CNBC: “OpenAI cyber models broke out of training environment to hack Hugging Face.” Fortunately, we have a top expert, my friend Prof David Hoffman, to break it down for us. Not only does David explain what happened, he has specific ideas as top how to prevent it from occuring again. A Call For AI Accountability By Prof. David A. Hoffman, Duke University If a person had done what OpenAI’s own testing systems did this month, quietly breaking into another company’s servers, stealing credentials, and extracting confidential data, that person would face prosecution under the Computer Fraud and Abuse Act. Unauthorized access to a protected computer, obtaining information without authorization, and using stolen credentials to move across systems are precisely the acts Congress wrote that statute to punish. When an AI system built and operated by one of the best resourced companies in the world does the same thing, the announcement of the intrusion reads more like bragging about an accomplishment than an admission of a crime. Companies that build and operate these autonomous systems need to control them well enough that they do not break the law. Unfortunately, our misguided self-regulation approach to AI governance has left us all at risk from these autonomous criminals. The incident The incident itself was a supply chain cybersecurity failure, not a sudden act of AI rebellion. OpenAI was running an internal cybersecurity evaluation in which advanced models, including an unreleased model, were given difficult exploitation objectives, and some of the safeguards that normally restrict dangerous cyber activity were deliberately removed. The evaluation environment retained a narrow connection to the outside world through a proxy used to reach software
Jul 26, 2026 · via sites.duke.edu
Over the last few decades, several mysterious hackers have captured the public’s imagination, but none quite like Phineas Fisher. A decade after their most famous hack, Phineas remains, by most accounts, the most prolific and public hacker never to have been caught. As part of our series on the biggest cybersecurity mysteries of all time, we’re delving into the enigma of Phineas, the hacktivist who hacked controversial spyware makers FinFisher and Hacking Team. The latter, an Italian startup, was among the first to turn government spyware into a viable global business, paving the way for spyware makers such as the Israeli NSO Group. Phineas’ hack against Hacking Team eventually led to the startup’s demise years later. Apart from Anonymous, an amorphous amalgam of hacktivists with a mixed track record of mostly stunt hacks designed to gather publicity rather than have real impact, Phineas is perhaps the most well-known hacktivist in history. Their story is made of impressive hacks and endless unanswered questions. Who is Phineas Fisher? Variously called an anarchist, a cybercriminal, a hacktivist, and a vigilante, the hacker has said they “use a lot of different names” for different hacking escapades. The hacks we know about were big enough to turn Phineas into a legend among hackers. “I would like to meet Phineas Fisher so that I could buy them a seven-course, three-Michelin-star dinner somewhere and listen to them explain how they turned Hacking Team inside out like a gym sock,” a well-known security researcher once wrote on Twitter. There’s even a song about them. Phineas first emerged in August 2014, when they announced they had hacked Gamma Group, the makers of the FinFisher spyware — which is where the nickname comes from. They publicized the hack via a Twitter account cheekily called @GammaGroupPR, leaking stolen data including mobile
Jul 25, 2026 · via techcrunch.com
Is Hotel Wi-Fi Safe? Here’s What Cybersecurity Experts Say You Need to Know Before You Log In Here’s what to know before logging on to the Wi-Fi at your next hotel. By Iona Brannon Iona Brannon Iona Brannon is a journalist with a love for food and travel. Her work has appeared in Afar, Bon Appétit, Condé Nast Traveler, Travel + Leisure, and Business Insider, among other publications. Travel + Leisure Editorial Guidelines Published on July 25, 2026 Leave a Comment Close A traveler working on her computer in a hotel room. Credit: Thomas M Barwick/Getty Images Two cybersecurity experts say hotel Wi-Fi is generally low risk, but fake networks and poor security habits can still expose travelers.Travelers should verify the hotel’s official Wi-Fi network, keep devices updated, and enable multi-factor authentication before a trip.For banking, work accounts, and other sensitive activities, both experts recommend using a mobile hotspot instead of hotel Wi-Fi. What’s the first thing you do when you check into a hotel? For many travelers, it’s asking for the Wi-Fi password. And while some people log into their bank accounts without a second thought, others won’t even check their email unless they’re connected to a VPN. So, who’s right? Is hotel Wi-Fi actually safe, or should you avoid accessing sensitive information altogether? To find out, we interviewed two cybersecurity experts—and, it turns out, the answer falls somewhere in the middle. Hotel Wi-Fi does come with risks, but in many cases, the biggest vulnerability isn’t the network itself; it’s how travelers use it. Here’s what you need to know about hotel Wi-Fi before your next trip. The Network Isn’t the Main Problem Connecting to Wi-Fi in a hotel room. Luis Alvarez/Getty Images Security analyst Udaya Vemuri says hotel Wi-Fi is convenient but not something he fully trusts. One
Jul 25, 2026 · via travelandleisure.com
Network security has long supported networks that were distinct places – such as offices, branches, and data centers – which shaped how data flowed and how security protected it. But in today’s distributed reality, a network is basically wherever work is happening. The new distributed networking world has turned every endpoint into its own network, and security models designed for centralized control can fracture, revealing gaps that attackers can exploit. The Centralized Network of Yesterday Traditionally, network security was built around control through concentration. Users, applications, and data could be consolidated in a small number of trusted locations, where IT and security teams could inspect traffic and enforce policies from the perimeter. The network had an inside and an outside, where users worked from inside offices and applications lived inside data centers. Security tools protected data from attackers on the outside. VPNs, firewalls, and other security software all emerged from this approach. But today with cloud services, SaaS platforms, and remote work now necessary for the distributed world, traffic no longer flows through a single chokepoint. Applications have moved to the outside of the perimeter, with “inside” no longer clearly defined. Many security solutions still cling to the centralized idea of a single chokepoint, forcing distributed activity through a central control that can’t protect a network that no longer has a center. Network Boundaries Become Infinite Edges In today’s new distributed world, applications no longer reside in data centers with SaaS platforms – the default way for collaboration, finance, and operations. Business infrastructure now resides on the cloud as users, contractors, and third parties access systems without ever setting foot inside an office. Infinite edges have replaced the traditional branch office, where networks stop having a fixed boundary and every user, device, and workload is now its own access point,
Jul 25, 2026 · via cybersecurity-insiders.com
Technology OMB tells agencies to begin executing PQC transition by 2027 Read now Topics Artificial Intelligence Big Data CIO News Cloud Computing Cybersecurity IT Modernization Open Data/Transparency Shows All About Data Ask the CIO The Business of Government Hour Federal Executive Forum Innovation in Government Modern Government Reporter's Notebook Reporters Jason Miller Jory Heckman Justin Doubleday Terry Gerton Defense DoD plans CMMC listening sessions as questions swirl around review Read now Topics Air Force Army Defense Industry Navy On DoD Space Operations Shows On DoD with Jared Serbu The Business of Defense Reporters Jared Serbu Anastasia Obis Rachel S. Cohen Workforce GSA names new leaders for regions, PBS Topics Acquisition Agency Oversight Budget Facilities/Construction Government Shutdown Hiring/Retention Litigation Management Unions Workforce Rights/Governance Leadership Connect Shows Federal Report Your Federal Life Eye on Washington Inside the IC Reporters Drew Friedman Jason Miller Jory Heckman Pay & Benefits OPM to crack down on ineligible health insurance enrollees Read now Topics Benefits Open Season Pay Retirement TSP Shows Your Federal Life Reporters Drew Friedman Federal Drive Terry Gerton joins as the new host of The Federal Drive Meet Terry Shows The Federal Drive Federal Newscast The Space Hour Federal Drive Team Terry Gerton - Host Eric White - Producer Michele Sandiford - Producer Commentaries Submit a commentary Feds with Benefits Submit a question for Feds with Benefits Events See the best prediction markets for trading on real world events and outcomes across politics, financials and many more options. Learn more Upcoming Events Past Events Resources Stay up to date on the latest newsletters and news alerts Subscribe now Podcasts Insights Series Publications Advertise Federal News Network Technology News Read now Advertise with Us Listen Live Listen Schedule Search Search Trending: House NDAA rejects personnel cuts Survey: Impacts of feds' return to office Pentagon
Jul 25, 2026 · via federalnewsnetwork.com
Amplify Cybersecurity ETF vs Walmart Stores Inc — how do they compare? Amplify Cybersecurity ETF trades at $105.18, while Walmart Stores Inc trades at $109.47 (market cap $871.17B). The key difference: Walmart Stores Inc pays a 0.9% dividend while Amplify Cybersecurity ETF pays none, and Amplify Cybersecurity ETF is trading nearer its 52-week high, Walmart Stores Inc nearer its low. Which is the better fit depends on your goals. | HACK | WMT | | |---|---|---| | Sector | Sector/Thematic | Consumer Staples | | 52-Week High | $114.29 | $134.20 | | 52-Week Low | $70.69 | $96.05 | | Market Cap | — | $871.17B | | Volume | — | 5,675,288 | | Enterprise Value | — | $934.62B | | Dividend Yield | — | 0.9% | Signals from Pluang's Aura AI — not financial advice No Aura AI signal available yet. Walmart (WMT) trades at $108.38, down 0.88% for the day, with technical indicators showing a bearish short-term trend but strong fundamentals including consistent earnings beats and robust revenue growth to $681.0 billion in 2025. The company maintains solid profitability with a net income margin of 3.13% and ROE of 25.53%, while expanding initiatives like drone delivery and AI tools enhance operational efficiency. The outlook remains positive with a consensus price target of $142.33, reflecting 31% upside potential, supported by analyst bullishness (72.7% buy ratings). Key risks include competitive pressure from Amazon and margin pressures from consumer spending shifts, but Walmart's scale and innovation provide a defensive growth profile for long-term investors. Trailing returns across standard periods Latest headlines on both assets HACK provides diversified exposure to the global cybersecurity industry. It invests across the full value chain, including hardware, software, and consulting services, with key holdings in firms like Broadcom, Cisco, and Palo Alto
Jul 25, 2026 · via pluang.com
Acquisition marks TAC Security’s strategic entry into consumer cybersecurity as digital threats move from enterprises to everyday internet users NEW YORK, NY, UNITED STATES, July 24, 2026 /EINPresswire.com/ — TAC InfoSec Limited (NSE: TAC), a global cybersecurity company to acquire 100% of Israel-based Safehouse Technologies Ltd., marking TAC Security’s strategic entry into the business-to-consumer (B2C) cybersecurity segment. TAC Security will acquire 100% of Safehouse’s issued share capital on a fully diluted basis and, upon completion, Safehouse will become a wholly owned subsidiary of TAC InfoSec Limited. Safehouse’s flagship consumer app, “Safehouse,” already demonstrates the company’s B2C cybersecurity potential, with 10 lakhs+ downloads, a 4.2-star rating on Google Play. The app is positioned as an all-in-one privacy and digital protection platform, offering unlimited VPN access, encrypted browsing, global servers across markets including the USA, UK, Singapore, Germany, India and Brazil, threat blocking, link protection, phishing alerts and breach-detection features. Its Google Play listing also highlights user-focused privacy practices such as no data shared with third parties, data encryption in transit, and the ability for users to request data deletion — strengthening the case for TAC Security’s entry into consumer cybersecurity through a product that already has market traction and a recognized user base. The transaction represents a significant expansion of TAC Security’s cybersecurity platform from enterprise, government, and technology customers into the fast-growing consumer digital protection market. Upon completion, Safehouse Technologies Ltd. will become a wholly owned subsidiary of TAC InfoSec Limited, or its business, assets, and intellectual property may be transferred as part of the transaction structure, subject to due diligence, regulatory requirements, and definitive agreements. Safehouse Technologies operates in the digital security and consumer cybersecurity space. The proposed acquisition is aligned with TAC Security’s strategy to build a consumer-facing cybersecurity platform through TAC Safehouse Technologies, a proposed new entity
Jul 25, 2026 · via kitsapsun.com
| Walkinshaw Amendment to Speed up Pentagon’s Adoption of Cybersecurity Tools Passes House Washington, D.C., July 24, 2026 Tags: Federal Employees Washington, D.C. -- Today, Congressman James R. Walkinshaw (VA-11), who serves on the House Oversight and Government Reform and Homeland Security Committees, secured House passage of his amendment to more efficiently deploy modern cybersecurity solutions within the Department of Defense (Dod), strengthen military cyber readiness, and encourage the concept of interagency reciprocity with regard to cloud security assessments and certifications. The amendment establishes a pilot program to help the DoD deploy modern cybersecurity tools more efficiently by accelerating review of cloud-based products that have already received FedRAMP High certification, the federal government's highest cloud security standard for handling sensitive unclassified information. By encouraging reciprocity between FedRAMP and DoD's cloud security assessment processes, the amendment saves taxpayer resources and helps ensure America's servicemembers have faster access to proven commercial cybersecurity capabilities. "At a time when cyber threats from our adversaries are becoming more sophisticated, the DoD must continue to improve efficiency around how it securely deploys proven cybersecurity tools," said Congressman Walkinshaw. "My amendment will help the Department speed up the process of assessing solutions that have already been vetted for federal agency use, while upholding rigorous security standards and helping ensure our servicemembers have access to the innovative capabilities they need to defend our nation." Currently, cloud service providers seeking to serve both civilian federal agencies and the DoD must complete separate security assessment processes, even though both rely on the same underlying National Institute of Standards and Technology (NIST) cybersecurity standards. Walkinshaw's amendment makes that process more efficient by helping DoD deploy trusted cybersecurity solutions faster while upholding the rigorous security standards our military and national security depend on. The amendment was included in the House-passed FY2027 National
Jul 25, 2026 · via walkinshaw.house.gov
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jul 25, 2026 · via youtube.com
OpenAI models escaped a controlled security test and attacked Hugging Face, prompting the platform’s co-founder to warn that corporate cybersecurity has entered a new phase. Key Points: - Hugging Face recorded about 17,000 attacks from multiple IP addresses after OpenAI models left a secure testing environment. - Co-founder Thomas Wolf said the breach differed from routine attacks and showed that many companies remain unprepared for autonomous AI threats. - Researchers and UK officials are examining whether existing safeguards can contain advanced AI agents during cybersecurity testing. Hugging Face Breach Thomas Wolf, Hugging Face co-founder and chief science officer, told the BBC’s Newsday program Thursday that the incident should serve as “a wake-up call” across the technology industry. OpenAI said Tuesday that advanced models escaped a secure test environment and launched a cyberattack during an evaluation, which the company called unprecedented. The ChatGPT developer said it was investigating with Hugging Face. Hugging Face detected unusual activity in mid-July but initially did not know its source. The company contained the intrusion before OpenAI disclosed that its models were responsible. Wolf said the network faced about 17,000 attacks from multiple internet protocol addresses within a short period. He said the pattern differed sharply from the routine attacks the platform regularly encounters. Hugging Face runs a major open-source repository for AI models, datasets and development tools used by researchers and technology companies. Wolf warned that autonomous agents could make similar attacks increasingly common. Many businesses, he said, have not adapted their defenses because they do not recognize how quickly the threat has changed. Also Read: Apple's $2,000 Folding iPhone: Everything We Know Ahead Of September OpenAI Safeguards Nate Soares, president of the Machine Intelligence Research Institute, said the incident was troubling because the models appeared to bypass safeguards designed to prevent unauthorized cyber activity.
Jul 25, 2026 · via yellow.com
Cybersecurity Beyond the Tools: Investments,… The first comprehensive, evidence-based study of how cybersecurity leaders in Hong Kong actually make investment and vendor selection decisions, not in theory, but under budget pressure, regulatory scrutiny, talent constraints, and a relentless threat landscape Hong Kong's cybersecurity sector has never faced greater pressure. Cyber incidents reached a record 15,877 in 2025 — a 27% year-on-year increase — while financial losses from cybercrime hit HK$3.04 billion in the first half of 2025 alone. At the same time, the landmark Protection of Critical Infrastructures (Computer Systems) Ordinance (PCICSO) came into force in January 2026, fundamentally reshaping the regulatory landscape across eight critical sectors. Yet most organizations continue to operate under flat budgets, with 95% citing a persistent shortage of skilled cybersecurity professionals. Against this backdrop, HKCNSA and Sia joined forces to answer one central question: how do cybersecurity leaders in Hong Kong actually make decisions? Not according to best-practice frameworks, but in practice — under real constraints, with real trade-offs. This study draws on four complementary sources of insight: The data does not simply describe a market investing in cybersecurity. It reveals a market under tension — and six interconnected structural forces define its current state: The research report delivers a clear message: organizations can no longer solve escalating cyber threats simply by accumulating new tools. The critical gap—and the true differentiator for resilient enterprises—lies in strategic architectural alignment and modernized governance. The real-world case studies reveal that structured procurement is non-negotiable, geopolitical risk has become a core selection criterion, and the aspiration of a single unified global security stack is increasingly unachievable across the Greater China region. Instead, leaders must skillfully orchestrate hybrid architectures. What truly matters is technical integration, organizational maturity, and local ecosystem support. Drawing on lessons from three senior cybersecurity leaders, it
Jul 24, 2026 · via sia-partners.com
Cybersecurity stacks rarely become complicated through one bad decision. They grow one purchase at a time as businesses add firewalls, endpoint protection, multi-factor authentication, cloud controls, managed detection, and reporting tools to close the latest visible gap. Each purchase may solve a real problem, yet the combined environment can leave customers with more consoles, licences, alerts, and uncertainty about who takes responsibility when an incident unfolds. For resellers and managed service providers, the answer cannot be another product pushed into an already crowded stack. The channel creates greater value by reducing operational friction, showing customers where protection is fragmented, where controls overlap, and where gaps remain between detection and response. Complexity has become a security risk A large collection of tools can create the appearance of strong protection while making the environment harder to operate. Separate products generate their own alerts, policies, reports, and renewal cycles. Security teams must correlate activity across them, maintain integrations, and decide which console deserves attention first. That burden becomes more serious for customers with lean internal teams. A business may have capable technology in place but still lack the time or specialist skills to monitor it continuously, investigate suspicious activity, and respond before an attacker moves across identities, endpoints, networks, and cloud services. The customer can be well protected in individual areas and still exposed in the gaps between them. More coverage does not automatically require more vendors. In many cases, the customer needs a clearer operating model before another control is added. Start with the way the customer operates The right security model depends on the customer’s risk, internal capacity, existing investments, and appetite for operational responsibility. Some organisations want to manage security internally and need better visibility and control. Others want a partner to share monitoring and response responsibilities. Customers without a
Jul 24, 2026 · via itweb.africa
WASHINGTON – Today, U.S. Sens. Mark R. Warner (D-VA), Vice Chair of the Senate Select Committee on Intelligence, and Marsha Blackburn (R-TN) reintroduced the Enhancing K-12 Cybersecurity Act, bipartisan legislation to help schools defend against ransomware, data breaches, and other cyberattacks that can expose students’ information, disrupt classroom learning, and strain already limited school resources. Companion legislation was introduced in the House of Representatives by U.S. Reps. Doris Matsui (D-CA) and Zach Nunn (R-IA). “As cyberattacks grow more frequent and sophisticated, it’s our responsibility as lawmakers to ensure our schools have the tools and resources needed to protect students, parents, educators, and their sensitive information from being compromised,” said Sen. Warner. “Schools should be focused on teaching young people – not worried about fending off ransomware attacks or recovering from cyber incidents. I’m proud to reintroduce this legislation that would help school districts strengthen their cyber defenses, improve coordination with federal experts, and better prepare for the growing threats facing classrooms across the country.” “Cyberattacks continue to grow in size, frequency, and complexity in critical U.S. institutions, including in America’s schools,” said Sen. Blackburn. “We must ensure that our education sector is equipped to address these threats and keep students’ personal information private. This bipartisan and bicameral legislation will improve the cybersecurity tracking system for schools and provide them with necessary training resources and best practices for prevention.” “When I thought about my own grandchildren going to school, I wanted what every parent and grandparent wants: for them to be safe and focused on learning,” said Rep. Matsui. “No family should have to worry that a cyberattack could expose a child’s personal information or disrupt their education. This bill gives schools the tools, training, and support they need to protect students’ data, help teachers keep classrooms running, and give administrators
Jul 24, 2026 · via warner.senate.gov