No-frills tech news

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a command injection vulnerability in the SNMP monitoring component when SNMP notifications are enabled. Also patched are four cross-site scripting (XSS) flaws in the Classic Web Client - - A stored cross-site scripting (XSS) vulnerability that could allow malicious attachment filenames to execute script under specific conditions. - An XSS vulnerability where crafted fields could execute a malicious script under specific conditions. - An XSS vulnerability where a crafted field could execute a malicious script when rendered. - An XSS vulnerability where crafted attachments could execute a malicious script when rendered. Separately, fixes have been released for a mail forwarding restriction bypass (CVE-2026-50055) that could allow authenticated users to exfiltrate email despite mail forwarding restrictions being enabled. Rapid7 security researcher Jonah Burgess has been credited with discovering and reporting the flaw. The company did not share any additional specifics, stating "in line with industry best practices, information disclosure is limited for security vulnerability fixes." The release comes a little over a week after Zimbra patched a critical stored XSS flaw in the Classic Web Client that could result in arbitrary code execution. Although none of the identified vulnerabilities have been flagged as actively exploited, XSS bugs in the email software have been repeatedly exploited by bad actors in the past, making it crucial that customers apply the updates to keep the environment secure.

<b>Cybersecurity</b> student in Indianapolis tackles certifications, builds YouTube community

Noah Heroldt, a junior in cybersecurity in Indianapolis, grew up with an interest in computers: "I was basically a 'user' for a really long time, and that was it." Before he decided on college, he already knew he wanted to go into a field that would expand his knowledge base. His father discovered that Purdue is a participant in the federal CyberCorps Scholarship for Service program. Heroldt toured Indianapolis during his junior year of high school and met Feng Li, now head of the School of Applied and Creative Computing. Li asked Heroldt if he knew about Kali Linux, an operating system used for penetration testing. "I went home that day [and] searched for it," Heroldt said. "I didn't know hacking could be used as a career. From there I was kind of dead-set, locked in on, 'this is what I want to do.'" Heroldt spent the next 10 months teaching himself the fundamentals of networking and ethical hacking. Through no small amount of self-training, he was able to arrive at college with a meaningful head start. "That raw curiosity that sparked after my conversation with Doctor Li fueled a fire that has done me so much good throughout my college career," Heroldt said. "I learned a lot of what I know now outside of class, just on my own time, being curious about how things worked." "I truly believe that anyone can learn anything these days as long as you have a connection to the internet. It's one of the reasons why I started my YouTube channel. I learned so much from the cyber community online and I wanted to do my part and give back, laying my knowledge down for future learners who might just pick this up on a whim, which is basically what I did." While

AI Is Rewriting <b>Cybersecurity's</b> Rules

AI Is Rewriting Cybersecurity's Rules Top 3 Takeaways - AI is accelerating cyberattacks. - The same technology can strengthen defenses. - The biggest risk is falling behind. Artificial intelligence is changing cybersecurity on both sides of the battlefield. The technology helping organizations improve efficiency also enables cybercriminals to identify vulnerabilities, develop exploits, and launch attacks at unprecedented speed. Researchers in the School of Cybersecurity and Privacy (SCP) say the greatest concern is not that AI is creating entirely new forms of cyberattacks. Instead, it is accelerating activities that attackers already perform, making existing threats quicker, cheaper, and harder to stop. "AI is dramatically speeding up cyberattacks," said Brendan Saltaformaggio, associate professor in the SCP and the School of Electrical and Computer Engineering (ECE). "AI can identify vulnerabilities far faster than humans and often in places humans wouldn't think to look." Hackers Are Moving Faster Most cyberattacks include several stages: finding vulnerabilities, developing ways to exploit them, gaining access to systems, and pursuing a goal such as stealing information or disrupting operations. According to Frank Li, associate professor in the SCP and ECE, AI is having its biggest impact on the early phases of that process. "AI can help attackers explore potential decisions and implement attacks faster than in the past, whether it's identifying software bugs or constructing social engineering hooks," Li said. The pace of attacks has already changed dramatically. Peter Swire, J.Z. Liang Chair in the SCP and professor of law and ethics in the Scheller College of Business, says attackers are moving from vulnerability discovery to exploitation much faster than in the past. "The average time until an exploit is detected even a couple of years ago was measured in months," Swire said. "Now it is measured in hours." That compressed timeline is forcing organizations to rethink how

FAA-TSA <b>Cybersecurity</b> Gaps Threaten Aviation | Legis1

Why it Matters The federal government's two primary aviation agencies are struggling to coordinate on a critical vulnerability: protecting aircraft from cyberattacks. A new Government Accountability Office (GAO) report reveals that while the Federal Aviation Administration (FAA) and Transportation Security Administration (TSA) collaborate on aviation cybersecurity, they have failed to clearly delineate who is responsible for what, leaving potential gaps in the nation's defenses against digital threats to commercial aviation. The stakes are significant. Modern aircraft depend on interconnected systems both onboard and on the ground to operate safely. That same interconnection makes them more vulnerable to cyberattacks. If adversaries compromise these systems, the consequences could range from disrupted operations to safety hazards affecting millions of passengers annually. The GAO report, released on July 16, identifies key shortfalls in how the two agencies are managing this shared responsibility. The findings underscore a fundamental problem in how the federal government approaches aviation security in an era when cyber threats are as real as physical ones. The Big Picture Aircraft systems today communicate with ground-based infrastructure, maintenance networks, and air traffic control systems. This interconnectedness is essential for modern aviation operations, but it creates multiple entry points for potential cyberattacks. The FAA, housed within the Department of Transportation, serves as the primary aviation safety regulator. The TSA, part of the Department of Homeland Security, functions as the aviation security agency. Both agencies have important roles in protecting air travel and travelers from threats. But their missions, structures, and authorities differ significantly. The FAA has clearly defined roles and responsibilities for aviation cybersecurity within its regulatory framework; TSA does not. This asymmetry creates confusion about accountability and potentially leaves blind spots in security coverage. While the two agencies do work together on aviation cybersecurity matters, and the GAO acknowledges this collaboration exists, the

The Einstein of <b>cybersecurity</b> still needs developer trust

This post is based on Mackenzie's conversation with Arun Singh on The Secure Disclosure podcast. Listen to the full episode or watch below. In leading security for major Australian fintechs, Arun Singh has learned that "You could be the Einstein of cybersecurity, but if you cannot influence the business, you're no good." Implementing a new security control developers hate influences the business, but not in a good way. Singh learned this lesson early in his career, when he made the decision to remove local administrator rights across every workstation in the company. For 90% of users, it went fine. But the small cohort of software engineers who needed system-level access beyond just installing applications had their productivity completely destroyed. His team found the right compromise in days, but the trust took a year to rebuild. "Any time I'd go and talk to them about a new control, it was a hard-fought battle." The problem compounds at scale. Mike Wilkes, Aikido Security's Enterprise CISO, argues most enterprise security rollouts fail because they're run like software deployments when they're actually cultural changes. At 5,000 engineers, trust isn't something you rebuild one conversation at a time. The supply chain twist Singh's recent board conversations at Tyro have centered on supply chain attacks, and the conventional security wisdom that has been drilled into developers can, counterintuitively, make the problem worse. "We've been advocating for developers and other security folk to keep their packages and dependences up to date. It is something that we have ingrained in them for years. And threat actors have used that teaching to start compromising these companies." Singh's team now advocates a 7-day cooldown period for any new package version. That means telling developers to do the opposite of what security has told them for years. You want to patch

Introducing Fugu-Cyber: our new orchestration model that achieves state-of-the-art ...

Today, we are releasing an update to our Fugu orchestration model: Fugu Cyber. Available as a new API endpoint, Fugu-Cyber is purpose-built for the complexities of modern cyber defense. Fugu-Cyber achieves state-of-the-art performance on the industry’s most challenging security benchmarks, reaching a success rate of 86.9% on CyberGym and 72.1% on CTI-REALM, comparable to leading cybersecurity-focused frontier models such as GPT-5.5-Cyber and Mythos-Preview. Fugu-Cyber achieves state-of-the-art performance on real-world security benchmarks, matching cyber-focused frontier models like GPT-5.5-Cyber and Mythos Preview. Together, these benchmarks test the core pillars of enterprise defense: CyberGym evaluates an agent’s ability to analyze complex codebases to verify real-world vulnerabilities, while CTI-REALM measures its capacity to translate raw threat intelligence reports into working detection rules. Like our original Fugu orchestration model, Fugu-Cyber is a multi-agent system that behaves like a single model. You send a request to one endpoint, and the system dynamically orchestrates a pool of specialized agents to tackle complex, multi-step tasks without the risk of single-vendor dependency. It is now available as a new API endpoint in sakana.ai/fugu The Reality Check on Frontier Cyber Capabilities Achieving high scores on an evaluation is only the beginning of the story. Recently, there has been a lot of fearmongering about the cyber capabilities of frontier models. Much of the industry narrative suggests that simply granting an organization access to a frontier model with cyber capabilities will instantly solve their security challenges. We believe it is time to ground this conversation in reality. As highlighted in a recent Nikkei Digital Governance report (in Japanese), simply having access to a frontier model like Anthropic’s Mythos does not magically solve enterprise security. In reality, large organizations, including major financial institutions, often struggle to operationalize these tools. Without specialized internal talent and deep integration into proprietary source code, a frontier model,

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action

Hugging Face, a platform that hosts AI models and datasets, said its internal datasets and service credentials were compromised in a hack last week. The company disclosed the breach on Friday, but said it was still investigating whether any customer or partner data was stolen during the incident. In a blog post, the company said a dataset uploaded to its platform abused a security vulnerability to run malicious code on its servers, allowing the attackers to escalate their permissions and gain broader access to Hugging Face’s internal systems. The company said it has revoked and rotated the stolen credentials that were accessed. It urged users to do the same with any keys stored on the platform, and review any suspicious activity on their accounts. Hugging Face said it has fixed the vulnerability that was abused during the cyberattack. While it’s common for hackers to try to break into a company’s network using stolen employee credentials, keys, or a weak point in their security perimeter, this incident underscores the challenges that companies like Hugging Face face when hackers try to abuse platforms and tools to access and steal sensitive data from within. Hugging Face blamed the breach on an external AI agent, which executed “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.” The company did not immediately provide evidence for this claim when asked by TechCrunch. Hugging Face said its own anomaly detection spotted the attack, and used an AI model to analyze server logs that kept record of the cyberattack. The company said it initially used a frontier AI model from a commercial provider, though it didn’t name a company, but found that the analysis effort was blocked by the provider’s guardrails. Instead, the company used its own local large

NOT SO FAST: Use Caution When You Find a Thumb Drive or Charging Cables in

PERSPECTIVES FROM THE CAMPUS One of the strengths of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the colleges, universities, and other institutions of higher education throughout our state. Hence the name, “Perspectives from the Campus”, we invite experts – immersed in the pursuit of educating their students – to offer their knowledge for finding solutions in cybersecurity that benefit all Hoosiers. In the latest installment of this series, David Dungan, who serves as the executive director at the Center for Security Services and Cyber Defense at Anderson University, discusses the very real-world cyber risks involved when using (some) USB thumb drives and charging cables. It’s something we might not think about, but the threat is something that certainly deserves our attention. By David Dungan In our connected world, charging cables and USB thumb drives are essential tools that help us stay powered up and share data on the go. Whether you’re charging your phone in an airport or borrowing a flash drive to transfer files, it can be tempting to use whatever is available at the time. However, before you plug in that seemingly harmless device, think again. What looks like a helpful convenience could be a digital trap. Hidden Threats in Cables and Drives Most people might not realize that charging cables can do more than power your phone, they can also transfer data. Malicious charging cables, like the O.MG cable, are modified to install malware or steal information the moment you plug it into a charging port. Known as “juice jacking”, it involves a situation in which common charging stations -- found in public buildings – are adversely impacted by potentially holding one of these cables, allowing a hacker to silently compromise

Ecopetrol Continues to Implement Monitoring and Protection Measures in Response to ...

BOGOTÁ, Colombia, July 20, 2026 /PRNewswire/ -- Ecopetrol S.A. (BVC: ECOPETROL; NYSE: EC) reports that the latest analyses conducted regarding the cybersecurity incident and its effects, previously disclosed on July 17, indicate that the impact was limited exclusively to the downloading of files. Accordingly, no compromise to the integrity of the information has been identified, despite the external threat actor's attempts to destroy, delete, and/or encrypt data. The identities of users associated with the 3,300 accounts that were unlawfully infiltrated were not compromised, nor were any user access credentials captured. Ecopetrol S.A. also confirms that no compromise has been identified in the transactional technology solutions within its digital ecosystem, those of its subsidiaries, or those of its network of commercial and financial partners, suppliers, and customers. The Company and its subsidiaries continue to carry out containment efforts, now in an advanced phase, prioritizing the following actions: - Classification of the information downloaded as a result of the incident. - Assessment and management of extortion demands and threats based on information unlawfully obtained by the external threat actor, which have been reported to the relevant authorities. - Ongoing collaboration with Colombia's Cyber Emergency Response Team (ColCERT), given Ecopetrol's designation as critical national infrastructure; the Specialized Directorate for Cybercrime of the Office of the Attorney General; the Joint Cyber Command of the Colombian Armed Forces (CCOCI); and the Cybercrime Center of the National Police's Criminal Investigation Directorate (DIJIN). The operational activities of the Company and its Business Group continue without interruption, while efforts to monitor and address the cybersecurity incident remain ongoing. Ecopetrol is the largest company in Colombia and one of the main integrated energy companies in the American continent, with more than 19,000 employees. In Colombia, it is responsible for more than 60% of the hydrocarbon production of most transportation,

AI in <b>cybersecurity</b>: Adoption rises, but governance gaps remain | Barracuda Networks Blog

Cybersecurity AI use jumps, but maturity and governance lag Security teams are embracing AI to keep pace with attackers, but gaps in maturity, detection, and governance remain. Key takeaways - Cybersecurity teams are adopting AI faster as attackers use it to scale and speed up attacks. - AI maturity remains low, with only 27% of survey respondents describing their implementation as mature. - Governance, detection, and training gaps are limiting how effectively organizations can use AI in cybersecurity. - Security teams need practical controls, faster vulnerability remediation, and human oversight to reduce AI-related risk. A global survey of 536 cybersecurity and IT practitioners finds cybersecurity teams are now more aggressively adopting artificial intelligence (AI) tools and platforms in the hopes of leveling a playing field that has generally been lopsided for as long as anyone can remember. Conducted by the SANS Institute, the survey finds, for example, 61% of respondents now use AI to augment the capabilities of red teams that are trying to discover and remediate vulnerabilities before adversaries can exploit them. Why AI maturity remains a cybersecurity challenge However, only slightly more than a quarter (27%) describe their implementation of AI as mature, which suggests that in terms of AI capabilities many cybersecurity teams may be still far behind adversaries that are clearly using AI to launch more sophisticated attacks faster than ever. In fact, the survey finds more than three-quarters (78%) of respondents reported confirmed or suspected AI-enabled attacks in the past year, with nearly all (95%) believing threat actors are using AI. How AI-enabled attacks are changing vulnerability risk More troubling still, as more advanced AI models become available, cybercriminals will increasingly be able to discover and exploit vulnerabilities in a matter of hours. While access to the latest AI models from Anthropic and OpenAI is

DOD CMMC Task Force Seeks Industry Input on <b>Cybersecurity</b> Reforms

The Defense Department’s (DOD) newly established Cybersecurity Maturity Model Certification (CMMC) Reform Task Force is seeking feedback from the defense industrial base companies as it reviews the department’s cybersecurity compliance program following the recent suspension of CMMC Phase 2 requirements. The July 13 request for information (RFI) seeks industry recommendations on practical strategies to protect federal data, improve operational resilience against cyberattacks, reduce compliance costs, and lessen administrative burdens. The solicitation follows the DOD chief information officer’s (CIO) decision to immediately suspend CMMC Phase 2 requirements, which had been scheduled to take effect Nov. 10, 2026. All Phase 1 self-assessment requirements will remain in effect while the DOD conducts a comprehensive 60-day review of the program. The suspension also applies to pending and future CMMC implementation milestones in DOD solicitations and contracts. The department originally planned to implement the program in four phases over three years. Under this suspension, the CMMC Reform Task Force will conduct the 60-day review of the program. The department argued that CMMC, while intended to improve cybersecurity, had instead created prohibitive compliance costs and administrative burdens. “The combination of prohibitive compliance costs, severe shortages in third-party assessment capacity, and complex regulatory timelines is actively forcing innovative new entrants and small businesses to opt out of [DOD] contracts and freezing critical suppliers out of the market,” DOD CIO Kirsten Davies said. Feedback from the RFI is intended to support the task force as it reviews CMMC. According to the solicitation, industry responses will help inform policy reforms aligned with the Acquisition Transformation System that are designed to make partnering with the DOD more accessible, cost-effective, and secure while accelerating the delivery of cybersecure capabilities to the warfighter. The task force is seeking feedback on the use of existing commercial cybersecurity capabilities, self-attestation, and other approaches to

8 Reasons You Need to Attend Convene: Boston

Online Safety and Privacy | Min Read 8 Reasons You Need to Attend Convene: Boston There are a ton of reasons to join us in August 2026 for Convene: Boston and get to participate in the future of cybersecurity! If your career sits at the intersection of people and security, you've got to join us this August for Convene: Boston. Hosted by the National Cybersecurity Alliance on August 13-14, Convene brings together security awareness leaders, behavioral scientists, cybersecurity professionals, communicators, and culture builders for two days of practical learning, meaningful networking, and fresh ideas. This isn't a conference where you sit quietly in the back of the room and don't meet anyone. We named it Convene, for crying out loud! You'll exchange ideas, challenge assumptions, and leave with strategies you can put to work immediately. Need more reasons, or need to make a case to your boss? Look no further! 1. Learn from experts who are redefining human risk Cybersecurity is constantly evolving, and so is the science behind human behavior. Convene features experts tackling everything from phishing and social engineering to behavioral science, insider threats, and security culture. Every session is designed to move beyond theory and provide practical ideas you can apply in your own organization. 2. Hear groundbreaking research from leading academics Some of the brightest minds studying cybersecurity and human behavior will be sharing their latest research â check out the full agenda here! Dr. Lorrie Cranor, Director of Carnegie Mellon University's CyLab Security and Privacy Institute, will present new findings on why people fall for scams. Dr. Calvin Noble of the University of Maryland will examine how artificial intelligence is reshaping decision-making, education, and security. Meanwhile, Dr. Marc Dupuis of the University of Washington will present research that challenges attendees to rethink security culture by

These are the most urgent AI risks, according to 272 experts | MIT Sloan

These are the most urgent AI risks, according to 272 experts What you’ll learn: - Researchers asked 272 experts to evaluate 24 AI risks based on their likelihood and severity of harm between 2025 and 2030. - Experts said the five risks with highest expected severity are AI possessing dangerous capabilities, competitive dynamics, weapons and cyberattacks, power centralization, and AI spreading false or misleading information. - Information, national security, and finance sectors are considered the most vulnerable. AI developers and governance actors hold primary responsibility for addressing risks, while system users and other stakeholders are most vulnerable to them. Artificial intelligence presents business leaders with a difficult management problem: The risks are numerous and fast-moving and fall unevenly across organizations, sectors, and stakeholders. Some challenges are well known, like the potential for discrimination and the spread of misinformation, while others are emergent, like AI systems that could accelerate cyberattacks, make weapons development easier, or behave in ways that were never intended. A new study from MIT FutureTech and the University of Queensland offers a way to sort through that landscape. For “Prioritization of Risks From Artificial Intelligence,” a research team that included MIT Sloan School of Management principal research scientist asked 272 international AI experts to evaluate 24 AI risks based on their likelihood and severity of harm, and to note which sectors and actors are most vulnerable and who should bear responsibility for addressing the risks. The experts identified five risks — dangerous capabilities, competitive pressures, weapons and cyberattacks, concentrated power, and false information — as the most likely to produce the most severe harms over the next five years. The information and finance sectors are especially vulnerable, the experts said, and the people and organizations most vulnerable to risks are often not best positioned to address them. “There

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

Hackers are breaking into websites that run vulnerable versions of the popular blogging software WordPress, according to several cybersecurity firms. One estimate puts the number of vulnerable WordPress websites at tens of millions as of Monday. Last week, WordPress patched two critical security flaws, urging people who run its software on their websites to update it “immediately.” The vulnerabilities are so severe that WordPress enabled forced updates where possible. Since then, cybersecurity companies Patchstack, Hexastrike, and WatchTowr have all warned that hackers are exploiting the vulnerabilities in the wild, meaning they are taking over websites that are still running susceptible versions of WordPress. It’s unclear how many WordPress-powered websites on the internet are at risk, but it’s possible to make some educated guesses. The vulnerable versions of WordPress are 6.9.0 through 6.9.4, and 7.0.0 to 7.0.1. According to WordPress’ official stats, there are more than 400 million websites that run those flawed versions, although these statistics likely don’t reflect websites that have recently been patched. Cybersecurity consultant Daniel Card, who told TechCrunch that he looked at a sample of around 3,500 WordPress websites, estimates that less than 15% are vulnerable. Applying Card’s projection across the total population of WordPress websites on the internet, the total figure would still be around 90 million. The researcher credited WordPress with pushing automatic updates, Cloudflare with blocking attacks against vulnerable websites, and websites using cybersecurity protections such as web firewalls for the limited number of sites that could currently be hacked. WordPress.org, the project that develops WordPress’ open source code, did not immediately respond to a request for comment. Megan Fox, a spokesperson for Automattic, the company that runs WordPress.com and contributes to the open source project, told TechCrunch that “all sites hosted by Automattic, including WordPress.com, Pressable, WPVIP, and WP.cloud partners, were protected

Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence services, which describe the operation as ongoing. In Ukraine, the surveillance has not stayed passive. Camera access there has been "used in attempts to neutralise Ukrainian military personnel" and destroy their equipment, the services say, turning an exposed roadside or business camera into a targeting aid. Across EU and NATO states, the services add, the same camera access is also collecting military intelligence that has nothing to do with the war. Getting in is rarely the hard part. The operators scan the internet for exposed devices, fingerprint IP cameras by brand, and walk into the ones still running default passwords, obsolete firmware, and factory settings nobody changed. From there, image-recognition software does the watching, running automated searches through the video for military vehicles and the cargo they carry. None of the access the advisory describes needs a zero-day. Just how exposed are these cameras? Being reachable from the internet is not the same as being hacked. "Having a camera publicly accessible doesn't make it hackable," writes Martijn Grooten, a principal security researcher at Censys, the internet-scanning firm, in the company's own analysis of the exposed surface. The surface, though, is enormous. Across the EU, NATO members, and Ukraine, Censys counted more than 87,000 internet-connected cameras running a service whose version matches a known-exploited vulnerability, a total it calls a lower bound. More than 4,000 of them sit in Ukraine. That total counts hosts running any vulnerable service, not cameras whose own software is

Why Security companies can't create an invincible Vaccine against Ransomware

Every time a major ransomware attack makes headlines, the same question resurfaces: Why can’t cybersecurity companies create a foolproof solution that prevents all malware, just as vaccines protect people from diseases? While the comparison is appealing, it overlooks a fundamental difference between biological viruses and digital threats. In cybersecurity, there is no such thing as an “invincible vaccine.” Traditional antivirus software relied heavily on signature-based detection. Security vendors analyzed malware samples, identified unique characteristics, and distributed updates that enabled computers to recognize and block those specific threats. This approach was effective when malware evolved relatively slowly. Today, however, cybercriminals employ automated malware-generation tools, artificial intelligence, and polymorphic techniques that allow malicious code to alter its appearance each time it is deployed. A ransomware sample can produce thousands of unique variants, making static signatures insufficient. The challenge extends beyond the malware itself. Modern ransomware attacks rarely begin with a malicious file alone. Attackers exploit software vulnerabilities, steal credentials through phishing, abuse legitimate administrative tools, compromise cloud environments, and even leverage trusted third-party software. In many cases, ransomware is merely the final stage of a carefully orchestrated intrusion. Blocking the ransomware executable does little if the attacker has already gained privileged access to the victim’s network. Unlike biological viruses, malware is intentionally designed by intelligent adversaries who constantly adapt to defensive measures. Every improvement in security technology prompts attackers to develop new techniques to bypass it. This ongoing cycle resembles an arms race more than a medical vaccination program. Security companies cannot predict every future attack because adversaries continually invent new methods that have never been observed before. Another limitation is the need to balance security with usability. A security product could theoretically block every unknown application, script, or network connection. While this might stop many attacks, it would also prevent legitimate

DoW Requests Information for CMMC Reform Task Force

What: The U.S. Department of War (DoW) issued a request for information (RFI) seeking feedback from companies in the defense industrial base. The information will be used to inform the DoW’s new Cybersecurity Maturity Model Certification (CMMC) Reform Task Force. Why: CMMC is a tiered program used to assess the cybersecurity compliance of anyone doing business with DoW. On July 13, 2026, the DoW suspended Phase II CMMC requirements, which were supposed to take effect on November 10, 2026. The DoW also established a CMMC Reform Task Force “to comprehensively review the program and deliver actionable recommendations for reform.” The DoW is seeking “industry perspectives on utilizing existing commercial cybersecurity capabilities, leveraging and optimizing self-attestation capabilities, and streamlining cybersecurity compliance requirements.” In the RFI, DoW poses the following questions: - Identify the top five most prohibitive cost drivers, administrative burdens, or operational challenges your organization has experienced, or anticipates to experience, when attempting to comply with the CMMC framework and NIST SP 800-171 Rev 2. - Which specific security controls has your organization found to deliver the most tangible uplift of cybersecurity and actual risk reduction? - Conversely, which specific regulatory requirements or security controls create the highest administrative overhead and financial burden with the least measurable improvement to your actual cybersecurity posture? - Describe how your organization utilizes existing commercial cybersecurity capabilities, platforms, managed services, or any other additional strategies or initiatives to safeguard data, improve operational resiliency, and reduce cybersecurity risk, and how the DoW might better recognize or accept these commercial solutions within a compliance or risk framework. - Regarding Phase I self-assessments, what specific administrative or technical challenges does your organization face in maintaining, verifying, and reporting compliance, and how could this process be fundamentally streamlined? Have your self-assessments led to a more dynamic cyber posture

Wall Street Just Supersized Its Price Targets on Okta and Fortinet. Are <b>Cybersecurity</b> Stocks ...

Wells Fargo (NYSE:WFC | WFC Price Prediction) just delivered a striking pair of price target hikes on cybersecurity leaders Okta (NASDAQ:OKTA) and Fortinet (NASDAQ:FTNT). The firm raised its Okta stock price target to $150 from $100 while keeping an Equal Weight rating, and lifted its Fortinet stock price target to $120 from $70 while keeping an Underweight rating. For investors, the size of these hikes matters more than the unchanged ratings: they mark a sector-wide re-rating rather than a green light to pile in. The move lands as cybersecurity demand accelerates on the back of AI-driven threat proliferation and enterprise platform consolidation. Both Okta and Fortinet have posted five consecutive quarterly EPS beats, and management teams at each are pitching their platforms as essential infrastructure for securing AI agents and hybrid workloads. Still, Wells Fargo kept Okta stock at Equal Weight and Fortinet stock at Underweight, signaling that valuation, not fundamentals, is the constraint. That gap between raised targets and cautious ratings is what investors need to weigh before adding exposure here. | Ticker | Company | Firm | Action | Old Rating | New Rating | Old Target | New Target | |---|---|---|---|---|---|---|---| | OKTA | Okta | Wells Fargo | Price Target Raise | Equal Weight | Equal Weight | $100 | $150 | | FTNT | Fortinet | Wells Fargo | Price Target Raise | Underweight | Underweight | $70 | $120 | The Analyst’s Case Wells Fargo’s rationale is identical for both names. Supplementing 14 field checks over the past month, the firm’s Q2 on-cycle reseller survey pointed to improving overall cyber demand driven by AI-related urgency. That’s a demand-side signal, and it’s why targets moved sharply higher on Okta stock and Fortinet stock. Yet, the ratings didn’t budge. Equal Weight on Okta and Underweight on

cyan AG expands its successful <b>cybersecurity</b> solution to MásOrange subsidiaries in Spain

cyan AG expands its successful cybersecurity solution to MásOrange subsidiaries in Spain cyan AG/ Key word(s): Alliance/Contract cyan AG expands its successful cybersecurity solution to MásOrange subsidiaries in Spain 20.07.2026 / 08:46 CET/CEST The issuer is solely responsible for the content of this announcement. cyan AG expands its successful cybersecurity solution to MásOrange subsidiaries in Spain Munich, July 20, 2026 – cyan AG, a provider of intelligent cybersecurity solutions, announces the expansion of its successful cybersecurity solution “Ciber Protección”, currently deployed by Orange Spain, to three additional MásOrange subsidiaries: Euskaltel, R and Telecable. The rollout targets B2B and SMB customers with a focus on the northern Spain region. The initiative builds on the strong market traction of “Ciber Protección” at Orange Spain and aims to replicate this success across MásOrange subsidiaries. The comprehensive cybersecurity solution is designed to protect business customers’ internet connections and devices against digital threats, such as phishing, which continues to represent the most significant cyber threat for companies in Spain. With this expansion, MásOrange strengthens its cybersecurity portfolio for business customers by offering an integrated, easy-to-use solution that enhances digital resilience without adding complexity for its customers. Markus Cserna, CEO of cyan AG: "The rollout of Ciber Protección to additional MásOrange subsidiaries is a strong validation of the solution’s performance and scalability. Building on the successful deployment at Orange Spain, we are extending proven cybersecurity capabilities to further regional brands and providing MásOrange customers with effective protection against the most prevalent cyber threats, particularly phishing. This expansion underlines the strength of our long-term cooperation with the Orange Group and our ability to support complex, multi-brand rollouts." About cyan cyan AG (XETR: CYR) is a provider of intelligent cybersecurity solutions with almost 20 years of experience in the IT industry. The company offers IT security products for

Tech IPO alert! Boston-based $2.9b <b>cybersecurity</b> biz Point Wild eyes ASX

Boston-headquartered Point Wild, a $US2 billion ($2.86 billion) cybersecurity business backed by private capital giants Warburg Pincus, Accel and General Catalyst, is mulling life on the ASX. Loading... Sarah Thompson has co-edited Street Talk since 2009, specialising in private equity, investment banking, M&A and equity capital markets stories. Prior to that, she spent 10 years in London as a markets and M&A reporter at Bloomberg and Dow Jones. Email Sarah at sarah.thompson@afr.com Kanika Sood is a journalist based in Sydney who writes for the Street Talk column. Email Kanika at kanika.sood@afr.com.au Emma Rapaport is a co-editor of the Street Talk column. Prior to that, she was a markets reporter at The Australian Financial Review. Connect with Emma on Twitter. Email Emma at emma.rapaport@afr.com Angira Bharadwaj is a co-editor of Street Talk. She covers IPOs, capital raises, mergers and acquisitions and other breaking news in Australia’s capital markets. Previously, she covered financial services, state, and federal politics. Send tips to @angirab.60 on encrypted messaging platform Signal. Email Angira at angira.bharadwaj@nine.com.au  or Subscribe to save article Subscribe to gift this article Gift 5 articles to anyone you choose each month when you subscribe. Subscribe nowAlready a subscriber?