No-frills tech news

Kabogo: President's website taken offline after <b>cybersecurity</b> incident as probe gets underway

The government has temporarily restricted access to the official website of the President following a cybersecurity incident, as investigations and restoration efforts continue. In a statement issued on Saturday, July 18, 2026, Information, Communications and the Digital Economy Cabinet Secretary William Kabogo said the government detected the incident and moved quickly to contain it. Kabogo said the ICT Authority immediately activated its established cybersecurity incident response protocols after identifying the breach. "As a precautionary measure, access to the Presidential website was temporarily restricted to facilitate containment, forensic analysis and restoration efforts," he said. He said appropriate mitigation measures had since been put in place and work to restore the website was ongoing. Kabogo assured the public that preliminary findings had not revealed any compromise of sensitive government information. "At this time, there is no evidence of unauthorised access to sensitive data, data exfiltration, or loss of information," he said. He added that government systems and digital services remained secure and operational despite the incident. According to the Cabinet Secretary, the ICT Authority is working closely with relevant government agencies and technical partners to determine what happened. He said the ongoing investigation is expected to establish the full circumstances surrounding the cybersecurity incident through a comprehensive forensic analysis. "ICT Authority is working closely with the relevant Government agencies and technical partners to conduct a comprehensive forensic investigation and establish the full circumstances surrounding the incident," Kabogo said. The ministry did not disclose when the incident occurred or provide details on the nature of the cyberattack. It also did not indicate how long the Presidential website would remain inaccessible. The statement, however, maintained that response measures had already been implemented to contain the incident while restoration efforts continue. By the time of publication, visitors to the website were greeted with the message:

The <b>Cyber Security</b> Hub™ posted on LinkedIn

Your wrong. Thats how developpers life looks like after infosec has established a framework or a strategy in a company. 😀 The Mario representation has one observation: not every shining "?" needs a hit. Choose your hits wisely to conserve energy and vision for a secure, longer run. Applicable to every tech person these days. The speed at which new stuffs are releasing 😅 Forget the post, I want to hire that player. probably a monday All the fire and obstacles represent emails and tickets…😂 This explains so much how I ended up doing what I do. I need that level of lock-in in my life Un opéra numérique où les acteurs sont invisibles, où les décisions se prennent dans des coulisses que personne ne voit, où même les nouveaux gardiens de la sécurité avancent dans une pénombre algorithmique. Dans ce théâtre silencieux, la moindre erreur devient un acte tragique, comme dans un jeu vidéo où les vies se gagnent ou se perdent comme des bonus tombés du ciel. Et pendant que la console d’hier continue de tourner sans broncher, nos systèmes d’aujourd’hui exigent des interprètes capables de déchiffrer des hiéroglyphes que le commun des mortels ne soupçonne même pas. La génération précédente, celle qui savait lire dans les tripes de la machine comme dans celles de la patronne, s’est presque évanouie, laissant derrière elle un héritage de runes et de rites que peu savent encore invoquer.

Healthcare data is now more valuable to cybercriminals than credit card details

Medical records, diagnoses, biometric data… Over a lifetime, we generate a vast amount of healthcare information about ourselves—data that, by its very nature, remains linked to us permanently. It is precisely this permanence that has increased its value on illegal marketplaces used by ransomware groups, access brokers and networks specialising in digital fraud. The growing digitalisation of hospitals, clinics and insurers has also significantly expanded the attack surface. Criminals have refined their methods for profiting from the theft, sale and extortion of highly sensitive information. Ransomware accounts for more than a third of criminal activity The latest analysis by TrendAI shows that ransomware now accounts for 36.3% of all activity detected on underground marketplaces linked to the healthcare sector. The attacks are no longer limited to encrypting servers and demanding a ransom. Threat actors now also extract large volumes of data before locking systems and use the stolen information as leverage. They threaten to publish or sell the stolen files if the affected organisation refuses to pay. This double-extortion strategy considerably increases the financial, reputational and legal impact on hospitals, laboratories and healthcare providers. "Unlike a credit card, a patient’s diagnoses, treatment history or biometric data cannot be cancelled and reissued. This makes healthcare organisations particularly attractive to ransomware groups and data brokers," explains José de la Cruz, Technical Director at TrendAI Iberia. A Highly Organised Underground Economy The study describes a criminal ecosystem that operates like a full-fledged supply chain. At the first stage are initial access brokers, who specialise in finding vulnerabilities and selling entry points into corporate networks. Ransomware groups then use that access to infiltrate networks, extract documents and encrypt the affected systems. Finally, specialised marketplaces sell medical records, login credentials, insurance data and complete identity packages, known in criminal circles as “fullz”. This division of

Coca-Cola Unit Becomes 17th US Cyber Incident This Year

Seventeen companies in the United States have reported or been affected by cyber incidents this year amid a worldwide surge in artificial intelligence-driven cyberattacks, Reuters reported Friday (July 17). The latest company to report a cyberattack is Fairlife, a dairy company owned by The Coca-Cola Co. Coca-Cola said in a Thursday press release that Fairlife identified unauthorized access by a third party to its production-related systems and some other systems, in connection with a ransomware event, temporarily suspended its U.S. production operations, and is working to complete an investigation and restore the systems. “After detecting the issue, the company promptly activated its incident response and business continuity protocols,” Coca-Cola said in the release. “The company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisers and cybersecurity experts. The company has also notified law enforcement.” The FBI’s Internet Crime Complaint Center (IC3) said in April that it received 22,364 internet crime complaints that contained references to AI in 2025. These AI-related complaints reported losses of $893 million. “AI-enabled synthetic content is becoming increasingly difficult to detect and easier to make, which allows criminal actors to potentially conduct successful fraud schemes against individuals, businesses and financial institutions,” the FBI said in its 2025 Internet Crime Report. Overall, across all categories of internet crime, IC3 received 1,008,597 complaints that reported $20.9 billion in losses in 2025. Those figures were up from 859,532 and $16.6 billion, respectively, in 2024. The PYMNTS Intelligence report “Is That Content Generated by AI or Humans? Hard to Tell” found that content produced by AI can deceive humans and AI systems alike and that this has led to businesses and regulators racing to implement strategies to address the growing threat. The White House launched an AI security initiative called Gold Eagle

Ecopetrol Reports <b>Cybersecurity</b> Incident

BOGOTA, Colombia, July 17, 2026 /PRNewswire/ -- Ecopetrol S.A. (BVC: ECOPETROL; NYSE: EC) (the "Company") announced that it has identified an unauthorized access to certain digital resources owned by the Company and its subsidiaries by an external actor who has not been identified, as well as an attempted ransomware attack that was blocked by the cybersecurity controls implemented across the Company and its subsidiaries. The unauthorized access affected cloud-based file storage environments of approximately 15 subsidiaries (including the Company), resulting in the unauthorized download of data associated with approximately 3,300 user accounts. The external actor communicated extortion demands, threatening to publicly disclose the information that had been unlawfully extracted. In response to this incident, the Company initiated an investigation and activated its incident response and management protocols. In addition, the Company deployed the following measures aimed at preventing the public disclosure of the unlawfully extracted information, addressing supervisory actions and/or potential financial costs associated with investigation, remediation, and regulatory compliance, as follows: a. Immediate revocation of unauthorized access to the compromised digital assets. b. Blocking of mechanisms associated with the mass download of information. c. Identification, analysis, and containment of the tactics, techniques, and procedures (TTPs) used by the malicious actor. d. Filing of a criminal complaint before the Office of the Attorney General of Colombia and deployment of cooperation activities with specialized national authorities. e. Identification of external infrastructures used for the storage or download of information to pursue restriction or blocking actions. f. Activation of support mechanisms with insurers and specialized capital markets teams to ensure the proper management of the event. g. Detailed assessment of the downloaded information and determination of its criticality. h. Enhanced monitoring of the technology infrastructure under critical alert protocols and continuous validation of preventive and detective controls. As of the date of

CrowdStrike vs. NVIDIA: Which Growth Tech Stock Is a Better Buy in 2026, the <b>Cybersecurity</b> ...

Investors often weigh the hyper-growth of cybersecurity against the explosive power of AI hardware. Deciding between CrowdStrike (CRWD 0.33%) and NVIDIA (NVDA 1.97%) requires looking closely at their recent performance and long-term outlooks. CrowdStrike offers a cloud-native platform for endpoint security, while NVIDIA dominates the data center market with its high-performance chips. Both companies sit at the heart of critical technology trends, making them favorites for growth-oriented investors looking to capitalize on digital transformation. The case for CrowdStrike CrowdStrike provides the Falcon platform, an AI-native solution designed to detect and stop security breaches across cloud and identity environments. The company is a prominent player among tech stocks that focus on cloud-native security and managed protection. It recently formed a strategic alliance with Grant Thornton Advisors and continues to carefully manage the reputational impact of a July 19, 2024 incident where it mistakenly released a bug in its software code. In its 2026 fiscal year (FY), revenue reached $4.8 billion, representing growth of 21.7% compared to the prior year. Despite this growth, the company reported a net loss of $162.5 million. This reflects an increase in losses compared to FY 2025 as the company invests in platform expansion and provides customer incentives to manage relationships after its 2024 service disruption. As of its January 2026 balance sheet, the debt-to-equity ratio is 0.2x, while the current ratio is 1.8x. Free cash flow, which is cash from operations minus capital expenditures, reached $1.3 billion. Note that stock-based compensation (SBC) represented 68% of operating cash flow, which inflates reported cash generation since SBC is a non-cash expense added back in the cash flow statement. The case for NVIDIA NVIDIA designs the chips and software systems that power global artificial intelligence infrastructure. Revenue is highly concentrated, with two direct customers accounting for 22% and 14%

Abbott discloses cyberattack on cancer diagnostics business

Abbott disclosed on Thursday that a cyberattack hit its cancer diagnostics business. The medical device company said in a statement posted to its website that there was unauthorized access to a limited number of internal systems in its cancer diagnostics business. There was no impact on other Abbott businesses, sites or systems. Abbott’s cancer diagnostics business includes Exact Sciences, which the company acquired in a $21 billion deal earlier this year. The legacy Exact Sciences systems are separate from Abbott’s, according to the statement. “This does not impact any business operations, product or product availability, manufacturing or lab operations, or our ability to serve patients,” Abbott said. At this time, the company does not expect a material impact on the business or financial results. Upon discovering the attack, Abbott contacted third-party cybersecurity experts and law enforcement, and an investigation is underway regarding the information accessed. Abbott did not disclose what kind of information was accessed. The company declined to respond further to MedTech Dive’s request for comment regarding when the attack was discovered and what kind of information was accessed. Abbott is one of several medtech companies to disclose a cyberattack in recent months. In March, Stryker experienced an attack that brought down its ordering, shipping and manufacturing for weeks and ate into its first-quarter earnings. Stryker’s incident was followed by disclosures of cyberattacks from Intuitive, Medtronic, iRhythm and AdaptHealth.

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no changelog entry pointing at it. Okta's Red Team, which reported the denial-of-service bug and named it, published the details on Thursday. The fixed releases are OpenSSL 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21, all dated June 9. Every release on those branches before the fixed ones has it. Nothing in a normal patch pipeline will point you at them: there is no identifier for a scanner to match and no advisory to read. The flaw is that OpenSSL took the attacker's word for it. Every TLS handshake message carries a 4-byte header, three bytes of which declare how long the body will be. Older versions grew the receive buffer to that declared size the moment the header landed, before a single byte of the body showed up, and before the handshake's own checks ran. For an inbound ClientHello the ceiling is 131 KB. Then the worker thread blocks, waiting on a body that never comes. No authentication, no session, no key exchange. The memory does not come back On its own, that is a connection-exhaustion attack, and those are as old as Slowloris. What makes HollowByte stick is glibc. When the attacker drops the connection, OpenSSL frees the buffer, but glibc holds small and medium chunks for reuse rather than returning them to the kernel. The attack varies the claimed size on every connection, and in Okta's tests, that was enough to stop the allocator from reusing what it freed. The heap fragments, resident set size climbs, and it stays climbed

The Intelligent Security Stack: AI Across Cloud, Web, and Network Defense

Topic: The Intelligent Security Stack: AI Across Cloud, Web, and Network Defense Abstract: Modern enterprises operate across increasingly distributed environments where cloud platforms, web applications, APIs, SaaS services, remote users, and traditional networks must be secured as a unified ecosystem. Artificial Intelligence is transforming this security stack by enabling intelligent detection, automated response, predictive analytics, and adaptive protection across every layer of enterprise infrastructure. The current webinar examines how AI enhances cloud security, network defense, web application protection, API security, identity security, and endpoint visibility through intelligent automation and advanced analytics. The session will also discuss integrating AI into Security Operations Centers, Zero Trust architectures, Extended Detection and Response (XDR), and Security Orchestration, Automation and Response (SOAR) platforms to create a cohesive and adaptive security ecosystem. Participants will gain practical guidance for implementing AI across their security stack while addressing governance, data quality, model security, and operational challenges to maximize both security effectiveness and business resilience. Join us to explore AI-powered capabilities such as anomaly detection, behavioral analytics, cloud posture management, network traffic analysis, automated vulnerability prioritization, and threat correlation across diverse security tools. Key Takeaways: - Understanding how AI strengthens cloud, network, web, and identity security through intelligent automation. - AI to improve threat detection, correlation, and response across integrated security platforms. - Role of AI in Zero Trust, XDR, SIEM, SOAR, and cloud security architectures. - Best practices for building an AI-enabled security stack that scales with enterprise growth. - Governance, privacy, and operational considerations associated with AI-powered security solutions. - Practical approaches to improving cyber resilience through unified, AI-driven security operations. Speaker: Ali Chinwala, Cloud Security Architect and Cybersecurity Educator Bio: A seasoned cybersecurity professional with nearly three decades of experience in information security, cloud security, and security architecture. Expertise includes Identity and Access Management, data protection,

The researchers racing against routers and hackers - ASU News

The researchers racing against routers and hackers Award-winning ASU research reveals more than 1 million vulnerable routers and cameras still online If your router still works, why replace it? That logic has kept countless aging internet-connected devices alive long past their intended lifespan: Old Wi-Fi routers keep humming in closets. Outdated security cameras continue watching front porches. These forgotten network devices solider on for years after manufacturers stop supporting them. New research from Arizona State University suggests that many of those devices may still be vulnerable to publicly known cyberattacks, and their owners likely have no idea. Hui Jun Tay, a computer science doctoral student focused on cybersecurity in the School of Computing and Augmented Intelligence, part of the Ira A. Fulton Schools of Engineering at ASU, led the study and presented its findings at the 2026 Institute of Electrical and Electronics Engineers Symposium on Security and Privacy, earning a Distinguished Paper Award at the conference. The research challenges one of cybersecurity’s most trusted assumptions — that responsible disclosure reliably protects users once a vulnerability becomes public. For many years, the process has been considered a cornerstone of cybersecurity. Researchers who discover a flaw typically report it privately to a vendor, giving the company time to investigate, identify affected products and develop a fix before details are released publicly. The idea is to patch the hole before attackers can exploit it. Working under the supervision of Yan Shoshitaishvili and Fish Wang, both Fulton Schools associate professors of computer science and engineering, Tay and collaborators found that millions of devices may be slipping through the gaps in that process. “We kept finding these overlaps where the same vulnerability affected multiple devices, but only some of the devices were reported,” Tay says. “That made us wonder how many more are out there.

Digital Growth, Expansion and <b>Cybersecurity</b> Challenges

Digital Growth, Expansion and Cybersecurity Challenges Mexico’s retail sector is evolving through digital and physical expansion, with social media and digital payments reshaping consumer purchasing habits while e-commerce platforms improve access to online transactions. Meanwhile, Grupo Comercial Chedraui is strengthening its retail footprint in the State of Mexico through a MX$7.8 billion investment focused on new stores, job creation and regional economic growth. This is the Week in Retail & E-Commerce! Social Media Drives 65% of Mexico Consumer Purchases: Kueski Mexico’s e-commerce sector is increasingly shaped by social media, with platforms becoming key channels for product discovery and purchases as consumers move toward mobile-first shopping experiences. Kueski data highlights the growing role of digital payments and flexible financing options in enabling online transactions, particularly among consumers seeking more accessible purchasing methods. Chedraui to Invest MX$7.8 Billion in State of Mexico Expansion Grupo Comercial Chedraui will invest MX$7.8 billion to expand its presence in the State of Mexico with 245 new stores over four years, creating approximately 15,000 direct and indirect jobs in one of the country’s largest consumer markets. The expansion will focus on Supercito Chedraui convenience-format stores and larger locations to strengthen supply chains, improve access to consumer goods and stimulate regional economic activity. Farmacias del Ahorro Modernizes Digital Operations to Scale AI Farmacias del Ahorro is accelerating its digital transformation by modernizing its IT infrastructure and integrating artificial intelligence to improve operational efficiency, customer experience and digital service delivery. The company adopted Red Hat OpenShift to support cloud-native applications and launched the PotencIA initiative with Google Cloud to automate processes, optimize decision-making and free up operational capacity. Mercado Libre Expands E-Commerce Training for SMEs Mercado Libre launched the second edition of CLIC: El Impulso de lo Nuestro, a free e-commerce training platform aimed at helping Mexican producers, cooperatives

Jim Cramer Says There Will Always Be Another DeepSeek

Jim Cramer just told his followers that “there will always be another DeepSeek,” and he named CrowdStrike and Palo Alto Networks as the cybersecurity plays for a world where every enterprise is scrambling to wall off frontier AI models and compromised agents. The money is already moving: Palo Alto Networks trades up 92.18% year-to-date, and the AI-security capex cycle is only beginning. Here are the five names to know before the next shock hits. 1. Zscaler (ZS): The Zero-Trust Sleeper Zscaler (NASDAQ:ZS | ZS Price Prediction) is the name most investors are underweighting into the AI security wave, and that is exactly the setup. CEO Jay Chaudhry has been explicit: “Zscaler is ideally positioned as the cybersecurity platform for the AI era. Our differentiated Zero Trust SASE architecture, which hides applications from attackers and eliminates lateral movement, has never been more essential in securing against threats exposed by frontier models and compromised AI agents.” Zscaler is a launch partner on Anthropic’s Project Glasswing and OpenAI’s DayBreak, and it announced intent to acquire Symmetry Systems to govern AI agent communication at scale. The Q3 FY26 numbers, reported May 26, 2026, show a business firing on all cylinders even as the stock lags. Revenue landed at $850.48 million, up 25.4% year over year. ARR hit $3.52 billion, and non-GAAP EPS of $1.08 extended the beat streak to nine straight quarters. Here is the setup nobody is talking about: shares are down 34.9% year-to-date while fundamentals accelerate, and the analyst target sits at $192.58 against a current price near $147.67. The obvious heavyweight is next. 2. Palo Alto Networks (PANW): The Platform Giant Cramer Named Palo Alto Networks (NASDAQ:PANW) is the platform consolidator every CISO calls first when frontier AI models start leaking. CEO Nikesh Arora told investors on the Q3 FY26 call

DoD plans CMMC listening sessions as questions swirl around review

The CMMC review could lead to "everything from an overhaul, to small tweaks here and there,” DoD CIO Kirsten Davies said after the review team's first meeting. The Pentagon wants to move quickly with its review of the Cybersecurity Maturity Model Certification program, but plenty of questions swirl around what defense officials can do differently this time to balance compliance concerns for small businesses with the need to enforce cybersecurity requirements. The CMMC review team met for the first time on Thursday, July 16, Defense Department Chief Information Officer Kirsten Davies told reporters that same day following a tour of the factory floor at Kform, a small defense manufacturer based in Sterling, Va. Davies was joined on the tour by Small Business Administrator Kelly Loeffler and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey. Davies said small business considerations were central in the decision to suspend CMMC third-party assessment requirements and launch a “top-to-bottom” review of the program. The goal is to address cost and compliance concerns that Davies, Loeffler and Duffey said are creating barriers for smaller companies to compete for defense contracts. Join us July 21 – 23 for Federal News Network's Space & Satellite Exchange where government and industry leaders will discuss advancing connectivity, resilience and mission reach. Register today! “We took this action because data, including the reports from the Small Business Administration, makes one thing very clear: our planned compliance requirements progression was creating prohibitive costs and unacceptable burdens to the defense industrial base,” Davies said. DoD has published a request for information on the CMMC review. And officials will also hold listening sessions across the country to get feedback from defense contractors, “especially the small businesses, and from the cybersecurity operators and executives who serve your companies,” Davies said. “We want to

Frontier Airlines sued twice for weak <b>cybersecurity</b> after data breaches

Audio By Carbonatix Frontier Airlines got hacked, and now it’s getting smacked with two separate lawsuits. Both an employee and a customer filed lawsuits against the Denver-based airline on July 15, alleging that the company failed to meet the Federal Trade Commission’s data security guidelines by failing to protect information and to alert potentially affected people when a data breach occurred. Both lawsuits were filed in the United States District Court for the District of Colorado and currently seek class certification. Frontier declined to speak directly about the lawsuit, but the airline immediately “initiated our incident response protocols, notified law enforcement and engaged a third-party cybersecurity firm to conduct a comprehensive investigation,” according to spokesperson Rob Harris. “We are in the process of notifying affected individuals and are otherwise complying with all applicable requirements,” he tells Westword. The incident began in May, when Frontier was attacked by hacker group Scattered Lapsus$ Hunters (yes, that’s the real name). Frontier was then attacked again in June, according to one of the lawsuits, leading to the collection of both employee and customer Personally Identifiable Information (PII). Held for ransom Scattered Lapsus$ Hunters is considered a “supergroup” of multiple hacking collectives, including Scattered Spider, LAPSUS$ and ShinyHunters. In addition to its ability to create fantastic names, the group has extorted hundreds of millions of dollars since its founding in 2025, according to Dataminr. Both lawsuits against Frontier say the company hasn’t publicly announced whether a ransom was presented or paid. They point at a faulty security system and argue that the airline was negligent in protecting both client and employee info. “[Frontier’s] cyber and data security systems were so completely inadequate in that it allowed cybercriminals, including at least Scattered Lapsus$ Hunters, to obtain files containing a treasure trove of thousands of its employees’

Federal <b>Cybersecurity</b> Mandate Suspended: What the CMMC Pause Teaches Firms About ...

In July 2026, the Department of War suspended Phase II of its Cybersecurity Maturity Model Certification (CMMC) program, a requirement that would have forced more than 100,000 defense contractors into costly third-party cybersecurity assessments starting this November. The program stalled under its own weight: compliance costs approaching $600,000 per organization and a severe shortage of qualified assessors to conduct the certifications. Accounting and tax firms don’t fall under CMMC. But the pattern deserves attention from anyone advising clients on compliance and risk. A federal deadline was delayed, and it’s tempting to read that as license to delay related work elsewhere. For firms managing client financial and tax records, that instinct is worth resisting. Obligations under the FTC Safeguards Rule and GLBA don’t move just because a different program’s timeline did, and client financial data remains a high-value target for cybercriminals regardless of what happens in the defense sector. The Real Lesson Behind the Suspension Government compliance programs get delayed, revised, or scrapped with some regularity. The underlying risk they were designed to address rarely follows suit. For firms serving clients who depend on the confidentiality of tax records, banking details, and payroll information, a documented, consistently enforced security policy isn’t a box to check when a regulator demands it. It’s a baseline expectation clients increasingly assume is already in place. Firms that treat cybersecurity policy as an ongoing practice, rather than a reaction to the next compliance deadline, tend to identify gaps before they become incidents. That distinction matters most during filing season, when client data volume peaks and downtime carries the highest cost. Practical Steps Firms Can Take Now - Formalize a written information security policy (WISP). This is already an expectation under the FTC Safeguards Rule, and having it documented protects both the firm and its clients. -

3 ways to close <b>cybersecurity's</b> remediation gap | perspective

COMMENTARY: In just 18 months, AI systems have moved from barely performing entry-level security tasks to autonomously discovering and exploiting vulnerabilities across open-source and production environments.As open-weight models close the gap with frontier systems, AI-driven vulnerability discovery has rapidly expanded. It’s become accessible, affordable, and routine, ushering in a new era of AI for security.[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]However, a growing remediation deficit has emerged. While discovery accelerates, the ability to fix what’s found has not kept pace, creating a widening gap between exposure and resolution.We’ve already seen this deficit play out. At DEF CON 32 Semifinals, AI systems advanced in just one year, moving from partial effectiveness to near-systemic capability, by identifying the majority of planted vulnerabilities while also surfacing previously unknown real-world issues at low cost.These capabilities are no longer isolated or experimental. The math has fundamentally changed, and the remediation deficit has become a defining constraint on security itself, in an era of AI-driven security operations.It’s clear we’re doing business in a dense vulnerability landscape. Vulnerabilities appear throughout complex systems and require approaches that account for that density. Today, we have to keep pace with the speed and scale of discovery across organizational, technical, and economic systems, while continuously reducing exposure.Our industry will shape the next phase of cybersecurity by how effectively we evolve remediation to match a world where continuous discovery continues to expand.Nidhi Aggarwal, chief product officer, HackerOneSC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial. The illusion of scarcity Security teams have traditionally assumed that

Quanta Tech Systems Reaches Profitability After Advising More Than 500 Private Clients on ...

Quanta Tech Systems LLC reaches profitability after helping 500+ private clients improve their cybersecurity and digital safety. NEW YORK, NY, UNITED STATES, July 17, 2026 /EINPresswire.com/ — Quanta Tech Systems LLC has turned profitable after a year spent advising more than 500 private clients in the United States and abroad on cybersecurity. The New York company is now hiring to enter its next phase of growth. Most of those 500 clients aren’t corporations with a security department. They’re parents locking down their kids’ accounts, families securing home devices and personal messages, people trying to figure out whether a call or email is a scam. A year ago, cybersecurity consulting for individuals wasn’t really Quanta Tech Systems’ core business. Now it’s 500 clients deep and the thing the company measures itself by. “When we started, cybersecurity was still largely viewed as something companies invested in. But the reality has changed. Today everyone has a digital identity, personal data, and people they want to protect. Parents think about their children’s accounts, families face online fraud, older people are targeted by increasingly sophisticated scams. Our job as a technology company is to make security easier to understand and easier to get,” says Vasyl Zahorodniuk, founder and CEO of Quanta Tech Systems. The consultations are built around the same idea: give people something they can actually use, not a lecture on threat models. Clients leave with specific steps for their situation, not a generic checklist. “Technology creates real value when it gives people more confidence and less to worry about. Security lets us communicate, work, manage money, and look after our families with less uncertainty. That’s the impact we’re after,” Zahorodniuk says. Profitable, and hiring Profitability gives Quanta Tech Systems a stronger base to build on. The company is hiring across cybersecurity, software development,

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which was observed using an "unprecedented" four-tier blockchain-based command-and-control (C2) infrastructure spanning Tron, Aptos, and Binance Smart Chain to deliver a remote access trojan (RAT) capable reverse shell, credential harvesting, file exfiltration, and persistent backdoor injection. "This tactic makes disabling or destroying the C2 infrastructure extremely difficult," Checkmarx researcher Pavan Gudimalla said in an analysis published last month. The activity has been attributed to a threat actor named SuccessKey, with evidence of malicious activity detected as far back as February 27, 2026, when cryptocurrency wallets linked to ViteVenom were activated. While the typosquats published to npm in connection with ChainVeil masqueraded as libraries for Tailwind, Sass, ORM, and rate-limiting tools, the latest iteration specifically focuses on developers building applications using the Vite JavaScript and frontend build tool. The list of identified packages, published between June 29 and July 3, 2026, is below - - @uw010010/vite-tree (1070 Downloads) - @vite-tab/tab (289 Downloads) - @vite-ln/build-ts (252 Downloads) - @vite-mcp/vite-type (239 Downloads) - @vite-pro/vite-ui (200 Downloads) - @vitets/vite-ts (194 Downloads) - @vite-ts/vite-ui (176 Downloads) Another crucial difference between the two clusters is that, unlike ChainVeil's unscoped typosquats (e.g., "rate-limit-flexible"), ViteVenom makes use of scoped package names in an attempt to impersonate the "@vitejs/*" namespace and lend it a veneer of legitimacy. The main aspect that unites the two campaigns is the use of shared tier-2 infrastructure, which is used to deliver the RAT. Specifically, this involves the same Tron wallet and Aptos account addresses, which point to the same Binance Smart Chain (BSC) transaction leading to the malware. Like in the case of ChainVeil, the

AI broke <b>cybersecurity's</b> math. Now what?

Illumio Founder and CEO Andrew Rubin explains why Mythos and other frontier AI models are shattering cybersecurity’s operating model – and why resilience is the only way forward Cyber-security has long rested on a single, uncomfortable assumption: attackers only have to be right once, while defenders have to be right every time. The odds were bad, but the fight was at least fair. Both sides operated at human speed. Humans found vulnerabilities. Humans built exploits. And humans on the other side drove the defense. That equilibrium is gone. In April 2026, Anthropic announced Mythos Preview, an AI model that autonomously discovered thousands of previously unknown vulnerabilities across every major operating system and browser, including flaws that had survived decades of human review. The implications were severe enough that Anthropic withheld public release, fearing that the model could dramatically accelerate cyberattacks if it were widely accessible. CEO Dario Amodei warned of a six- to 12-month window to patch tens of thousands of flaws before rival models caught up. Andrew Rubin, founder and CEO of Illumio, calls it a breaking point for cybersecurity’s old assumptions. “AI didn’t just raise the stakes,” he says. “It changed the rules.” In a recent episode of The Segment podcast, Rubin lays out what this means for the industry. He’s spent 13 years building Illumio around the premise that breaches must be contained because they can’t be prevented. That’s always been true, he says, but Mythos finally proves it. “We’re investing more and more money to get worse and worse outcomes, but we literally keep doing the exact same thing over and over again,” he said. AI just made the math asymmetric Some observers suggest AI can also generate patches at machine speed, neatly cancelling the threat. But Rubin compares that logic to the Covid-19 vaccine rollout.