No-frills tech news

River Bank &amp; Trust investigating <b>cybersecurity</b> incident

Updated: 2 hours ago |The “Welcome to Fabulous Las Vegas” sign glowed pink and green to welcome Alpha Kappa Alpha’s 72nd International Boule. Updated: 2 hours ago |LVMPD’s Bolden Area Command hosted “Splash with the Badge” at the Bill and Lillie Heinrich YMCA near Meadows Mall. Updated: 2 hours ago |Pitcher J.T Ginn has been a major contributor to the A's 2026 starting pitching staff Updated: 2 hours ago |A Las Vegas Little League team is one step closer to making it to the Little League World Series. Updated: 2 hours ago |HomeAid Southern Nevada is accepting donations and volunteers online after its trivia night fundraiser Updated: 2 hours ago |Las Vegas police are investigating a shooting near W Sahara Ave and Rancho Dr

Even doctors can be fooled by deepfake X-ray images, posing <b>cybersecurity</b> &amp; health risks

Skip to main content Mobile Menu Icon Thumbnails View Thumbnails More Galleries More Galleries 1/7 Close Close Even doctors can be fooled by deepfake X-ray images, posing risk to cybersecurity & health Radiologists look at thousands of images every year (Photo: SBG) Read article Read The Article SHARE Facebook Share Icon X Share Icon Send via Email Share Icon

Beacon Security raises $13 million to build AI-focused <b>cybersecurity</b> platform

Beacon Security, a cybersecurity startup developing tools for AI-driven security operations, has raised $13 million in seed funding as companies look for ways to manage growing risks tied to artificial intelligence. The round was led by Notable Capital, with participation from Holly Ventures, AlphaDrive Ventures, SVCI, Jefferies Family Office and more than 60 cybersecurity founders and chief information security officers. Investors include founders from Talon, Descope, Gem Security, Dig Security and Cider Security. Beacon said it will use the funding to expand its platform, which is designed to give security teams and AI agents a cleaner and more reliable data foundation for detecting, investigating and responding to cyberthreats. The company, founded in 2024, says it has seen rapid early adoption among enterprise customers in sectors including financial services, insurance, technology, health care and hospitality. Beacon said its annual recurring revenue grew more than 300% in the first half of 2026, though it did not disclose revenue figures. Beacon is led by co-founder and CEO Gal Tal-Hochberg, who previously founded HiredScore, an HR technology company acquired by Workday for $520 million. He founded Beacon with Or Mattatia and Iddo Israely, who have backgrounds in cyber defense, offensive security and large-scale data infrastructure. “The acceleration of AI agents in the enterprise is creating a distinct need for a legible context layer for cyber defenders, which is fueling a fundamentally new security architecture,” Tal-Hochberg said. “We built Beacon to solve these challenges by providing the trusted data layer that allows organizations to deploy security agents compliantly and effectively.” Beacon’s platform sits between a company’s security data sources and the tools used by analysts. It is intended to normalize, enrich and organize data from multiple vendors so both human analysts and AI agents can work from a more complete and reliable picture. The company

NexusTek Expands Managed IT and <b>Cybersecurity</b> Services to Financial Services

DENVER, July 16, 2026 (GLOBE NEWSWIRE) -- Today, NexusTek, a leading provider of secure, scalable IT solutions, is expanding its managed IT, cybersecurity, and private cloud services portfolio to the financial services industry with a new suite of industry-focused managed, professional, and advisory services. Designed for mid-market banks, insurers, asset managers, capital markets firms, and payment processors, these services help financial services institutions strengthen their security posture and close cyber resilience gaps, and modernize their technology infrastructure without expanding internal IT teams. Financial institutions face some of the highest cybersecurity risks of any industry and many are challenged to keep pace with evolving threats using limited internal resources. "For too long, financial institutions have treated cybersecurity as something they revisit once a year. That’s no longer enough,” said Hamilton Yu, CEO at NexusTek. "The threats change every day, and organizations need continuous visibility into their security posture. We built this practice so mid-market organizations have access to the expertise they need without having to build a larger team." "Most mid-market organizations face the same challenge,” Yu added. “There’s a gap between what their internal teams can realistically support and what today’s threat environment demands. We built this practice to close that gap by giving financial services leaders a single partner across private cloud, cybersecurity, advisory services, and AI." What’s Included: NexusTek Managed IT and Cybersecurity Services The expanded offering begins with a no-cost cybersecurity and compliance assessment that evaluates an organization’s current security posture, identifies gaps, and delivers a clear prioritized roadmap. From there, clients can access an integrated portfolio of services, including: - Dedicated Private Cloud Infrastructure with built-in SOC 1 and SOC 2 reporting - Managed Detection and Response (MDR) with a 24/7 Security Operations Center - vCIO Advisory for ongoing strategic guidance - Co-Managed IT and Help

District 202 officials: Back to school at ETHS will be impacted by <b>cybersecurity</b> attack

Back-to-school operations at Evanston Township High School will be impacted this fall by the ransomware attack that occurred June 7, District 202 officials said on Thursday. Superintendent Marcus Campbell announced the upcoming impacts in an email to families July 16. “While we are ready and excited to welcome students back, some of the tools, processes, and timelines our families and staff have come to expect will not yet look or function as they have in the past,” Campbell wrote in the email. “Some of these changes reflect our ongoing recovery from the cybersecurity incident, while others represent new systems and processes that will support our district moving forward.” These changes might include new technology platforms, updated back-to-school procedures, and regular services that might be restored in phases, the email states. “Families will not need to re-enroll or complete additional steps outside of typical back-to-school practices,” Reine Hanna, spokesperson for the district, wrote in an email to the RoundTable. “There will be some updated processes and new tools introduced for daily operations and school functions this year, and we will share those details with families as part of our back-to-school information.” According to Hanna, the district continues to work with external cybersecurity experts to investigate if any information may have been accessed by the cyber attackers. “We do not yet have definite findings,” Hanna wrote. “If the investigation determines that an individual’s personal information was affected, the district will provide notification in accordance with applicable law.” The work following the attack has focused on both bringing systems back online and rebuilding technology infrastructure in a way that is secure, reliable and built for the future, Campbell wrote. Details will be shared with families as part of back-to-school information, the district said. ETHS resumes classes on Monday, August 17. ETHS has not

Uganda launches updated <b>cybersecurity</b> framework

Uganda has launched an updated National Information Security Framework (NISF) 2026 to strengthen cybersecurity and provide government institutions with guidelines for protecting digital infrastructure. The framework, launched by the Ministry of ICT and National Guidance, comes as Uganda faces growing cyber risks, with the country reporting a rise in online attacks and financial losses linked to cybercrime. According to industry experts, Uganda has recorded a 60% year-on-year increase in cyberattacks, including a UGX 62 billion ($16.8 million) incident involving the central bank. As governments across Africa increasingly prioritise cybersecurity as part of digital transformation efforts, the ministry said the updated framework demonstrates its commitment to expanding digital services while protecting information systems. Developed under the Uganda Digital Acceleration Project, the updated NISF provides security tools and minimum controls to help institutions strengthen resilience against cyber threats. It aims to protect critical infrastructure and increase confidence in digital public services. Speaking at the launch, Justine Kasule Lumumba, minister at the Ministry of ICT and National Guidance, said information security has become a matter of national security, economic development and public trust. "As government delivers more services digitally, we must ensure those services are safe, reliable and trusted. Information security is no longer just an ICT issue. It is a matter of national security, economic development, public service delivery and public trust. Cyber safety is everyone’s responsibility," said Lumumba. Lumumba urged government entities to collaborate with the National Information Technology Authority – Uganda (NITA-U) to implement the required security measures. Dr Hatwib Mugasa, executive director of NITA-U, said the framework provides a practical roadmap to move from cybersecurity awareness to implementation, supporting Uganda’s goal of creating a secure and resilient digital environment. Share

Five Keys to Cyber Resilience in K–12 Schools | EdTech Magazine

- Foundational Protection. Districts should prioritize next-generation firewalls, endpoint security, email security, and identity and authentication tools. These address the most common entry points for cyberattacks and serve as core components of a modern cybersecurity stack, helping to secure networks, devices, user accounts and communications. - Backup and Recovery. Districts need robust backup, recovery and continuity capabilities that will enable them to resume operations quickly if a breach or outage occurs. They should also have detailed, well-documented incident response plans with clearly defined roles and responsibilities that address incident management, mitigation, analysis, reporting and communication. - Internet of Things Ecosystems. Network-connected devices such as door systems, video cameras and printers are among the most commonly overlooked risks in K–12 environments. Advanced endpoint protection, strong access controls, network segmentation and other tactics can help contain attacks and ensure that every device on the network has proper security. - Cybersecurity Training. Districts need frequent, structured cybersecurity education, which can include alerts to prevalent threats, training campaigns and simulated attacks. Training should be both broad, reaching everyone in the district, and role-based, providing deeper training for staffers whose positions and data access warrant further education. - Risk Assessment. A comprehensive risk assessment service can provide a realistic look at vulnerabilities and recommend effective solutions. These insights can help district leaders achieve buy-in for cybersecurity investments and make informed, strategic decisions.

Top 30+ Penetration Testing tools used by Testers in 2026

The best penetration testing tools for cybersecurity are not limited to enterprise or paid tools alone. Moreover, the tools are limited in scope, often focusing on a single pentesting activity. To help decide which penetration testing tool is best for you, consider the purpose for which you need it. Tools such as Nmap, Unicornscan, or fping are useful for network scanning; Exploit Pack or BeEF are useful for exploitation; and Burp Suite or XSSer for web app testing. Cybersecurity is not just about defending against attacks; it’s about staying one step ahead of potential threats. This is where pentesting (short for penetration testing) plays a critical role. By simulating real-world attacks to uncover weak spots before someone else does, pentesting helps secure small businesses and major enterprises. And having the right tools makes all the difference. In this guide, we list 35 of the most effective pentesting tools, including 27 traditional tools and 8 cutting-edge AI pentesting tools that are streamlining vulnerability assessment and exploitation techniques in 2026. Whether you’re looking for free pen testing tools, fully automated solutions, or open-source penetration testing tools that can be customized and built on, the list below offers a range of options to enhance your toolkit. 27 Penetration Testing Tools Traditional penetration testing tools remain vital. From network analyzers to password crackers, these tools form the backbone of any security professional’s toolkit. Network Scanning and Enumeration - Nmap: A versatile network scanner, Nmap is used for host discovery and service enumeration. It supports various scanning techniques to identify open ports and services. - Masscan: A high-speed, open-source port scanner that can scan the entire IPv4 in minutes using asynchronous TCP SYN scanning, provided sufficient bandwidth is available. It is optimized for large-scale port discovery across vast IP ranges. - Angry IP Scanner: A

Cedar Crest College experiences significant <b>cybersecurity</b> incident affecting colleges technology

ALLENTOWN, Pa. - Cedar Crest College has identified a significant cybersecurity incident that is affecting portions of the College’s technology environment, according to a social media post. Upon becoming aware of the incident, Cedar Crest initiated its emergency response protocols to contain the threat and protect its data, according to the college. The college says it is investigating the incident, working to secure its systems, and taking steps to restore affected services safely. Cedar Crest has shared that they understand this situation may cause concern for members of the community, and they are committed to sharing accurate information as it becomes available. For more information and updates, please check Cedar Crest’s webpage. https://www.cedarcrest.edu/cybersecurityupdate/

What the Section 702 lapse means for <b>cybersecurity</b>

- Safe Mode What the Section 702 lapse means for cybersecurity For the first time in its operational history, FISA Section 702 has lapsed, plunging U.S. intelligence agencies and telecom providers into a highly uncertain “grey zone.” In this episode of Safe Mode, host Greg Otto sits down with Glenn Gerstell, former NSA General Counsel and senior adviser at the Center for Strategic and International Studies (CSIS), to navigate the fog of this unprecedented lapse. While the government is temporarily coasting on grandfathered certifications, the operational reality is getting increasingly dicey. Gerstell explains what this lapse actually means for the future of U.S. cyber defense, how political friction is complicating long-term planning, and why temporary stopgaps are creating unnecessary hurdles for the agencies trying to keep us safe.

CrowdStrike and Schwarz Digits Expand Strategic Partnership to Deliver Sovereign ...

CrowdStrike and Schwarz Digits Expand Strategic Partnership to Deliver Sovereign Cybersecurity Across Europe As part of the expanded partnership, “Organizations globally are increasingly prioritizing sovereignty without wanting to compromise on cybersecurity outcomes,” said Falcon Exposure Management: Built for the Frontier AI Era Falcon® Exposure Management is the foundation for securing organizations in the frontier AI era. Traditional vulnerability management cannot keep pace, leaving teams to chase every finding while attackers target the few that matter. Falcon Exposure Management replaces that model with continuous, real-time visibility across the attack surface and prioritization based on real-world exploitability, so teams eliminate the exposures attackers are most likely to exploit. Built on the Falcon platform, detection, response, and remediation move as one, closing the gap between finding risk and stopping the breach. This is why organizations are standardizing on Falcon: according to IDC, they replace an average of five point tools with the single, real-time view of risk that fragmented tools could never deliver.¹ Extending Sovereign Cybersecurity Across Europe The partnership deepens the strategic relationship between “European organizations should not have to compromise on cybersecurity for sovereignty,” said Expanding Falcon Platform Access Across Europe As part of the partnership, the Falcon platform will be available to European organizations through STACKIT, extending access across the region. Combining A Pathway for XM Cyber Customers to Move to the Falcon Platform XM Cyber, a 2025 Gartner® Magic Quadrant™ Challenger for Exposure Assessment Platforms, built a successful business across European markets. XM Cyber will continue to operate and support its existing customers, who will have the opportunity to adopt the Falcon platform through Falcon Flex and join organizations already standardizing on Falcon to stop breaches in the frontier AI era. Additional Information At closing, About Powered by the CrowdStrike Security Cloud and world-class AI, the CrowdStrike Falcon® platform

Buzzin' Brood Student Spotlight: Emmelyne Diep, Information Science and <b>Cybersecurity</b> ...

BioBuzz’s Buzzin’ Brood Student Spotlight series celebrates the next generation of life sciences talent — and the programs, institutions, and organizations investing in them. Name: Emmelyne Diep Hometown: Clarksburg, MD Institution: University of Maryland, College Park (College Park, MD) Role: Student Ambassador, BioBuzz Networks (Summer 2026) By the time she started high school, Emmelyne Diep was already troubleshooting real infrastructure in a college cybersecurity lab — the kind of experience most students don’t get until their first internship. Through Montgomery College’s dual-enrollment program, she earned her Associate of Applied Science in Cybersecurity while working hands-on as a student assistant in the college’s Cyberlab. Now an Information Science student at the University of Maryland (Class of 2027), Emmelyne is balancing Treasurer roles for Women in Cybersecurity (WiCyS) and InfoSci Fi, as well as serving as Data Archivist for the UMD Coffee Club. This fall she’s joining the UMD Fellows Program, pairing her technical background with public service leadership training. This summer, she’s expanding her curiosity in the life sciences as a Student Ambassador within BioBuzz’s BioCatalyst program, made possible through TEDCO’s Equitech Growth Fund. We sat down with Emmelyne to talk about her path into cybersecurity, what’s exciting her right now, and where she sees herself headed next. How did you get here? My journey into tech and data started early in high school, where I immersed myself in the dual-enrollment program at Montgomery College. Through that program, I earned my Associate of Applied Science in Cybersecurity while working as a student assistant at Montgomery College’s Cyberlab — troubleshooting technical infrastructure hands-on. That experience solidified my passion for computing, data structuring, and ethical security frameworks. I’m motivated to connect technical frameworks with human-centric systems, which is why I chose to pursue my Bachelor’s in Information Science at the University of Maryland,

CSA <b>cybersecurity</b> review finds gaps at registered firms, issues updated guidance

The Canadian Securities Administrators (CSA) has published Staff Notice 33-322, Review of Registered Firms' Cybersecurity Practices and Additional Guidance, following a compliance examination of 73 registered firms' cybersecurity practices. The examinations covered cybersecurity policies and procedures, employee training, risk assessments and controls, oversight of third-party service providers, and incident response planning. The CSA found that a number of firms, particularly larger ones, had robust cybersecurity frameworks in place, but also identified gaps where firms could strengthen their practices. Compliance feedback has been provided to the relevant firms to address the findings, and the notice sets out scalable guidance intended to apply to firms of all sizes, recognizing that cybersecurity risks and resources vary across registrants. Stan Magidson, CSA Chair and Chair and CEO of the Alberta Securities Commission, said the CSA wants to be clear with registrants that strong cybersecurity practices are not optional in today's threat environment. "Our guidance is intended to help firms establish and maintain cybersecurity practices that are appropriate to their size and operations, and are responsive to an evolving threat landscape," he said. Magidson added that cybersecurity risks continue to grow on many fronts as firms rely more heavily on digital tools, hybrid work arrangements, and online platforms to serve clients, and that while the examinations found many firms have frameworks in place, they also identified areas where some firms could strengthen their practices. Staff expect firms to have cybersecurity practices relevant to their business and are encouraging registrants to review the notice and assess whether their own practices can be strengthened. The CSA's findings land alongside a wider push across Canadian financial regulators to tighten cyber expectations, one that increasingly touches the insurance sector directly. The Office of the Superintendent of Financial Institutions, which regulates federally regulated insurers alongside banks, has its own Guideline

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability - CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution

Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH keys and your cloud tokens. Cursor keeps re-running it for as long as the project stays open. No prompt injection, no agent, no model in the loop, and no prior access to the machine: opening the folder is the entire exploit, and the result is arbitrary code execution as the logged-in user. AI security firm Mindgard reported the flaw to Cursor on December 15, 2025 and published full technical details on Tuesday, seven months later. There is still no patch, and Cursor has published no advisory for the issue. The mechanism takes about a sentence. Cursor checks several locations for a Git binary when a project loads, and one of them is the workspace itself. Process Monitor output in the write-up shows Cursor.exe spawning the repo-root binary with the command line git rev-parse --show-toplevel. That is the same repository-root probe Microsoft's VS Code docs describe. Whether Cursor searches those locations itself or hands Windows an unqualified git and lets the search order pick, the write-up does not say. Mindgard's proof of concept was Windows Calculator, renamed git.exe, and committed to the root. Clone, open, done. The screenshot shows Calculator windows stacking up on their own while the project sat open. The precondition sounds like the hard part: an attacker's binary, sitting in your project root. It is not. Cloning a stranger's repository is how binaries land on disk in the first place, and developers and their agents do it all day. The attacker needs no foothold to begin with.

TruStage insurance provider shuts down network after <b>cybersecurity</b> incident

Country United States of America US Virgin Islands United States Minor Outlying Islands Canada Mexico, United Mexican States Bahamas, Commonwealth of the Cuba, Republic of Dominican Republic Haiti, Republic of Jamaica Afghanistan Albania, People's Socialist Republic of Algeria, People's Democratic Republic of American Samoa Andorra, Principality of Angola, Republic of Anguilla Antarctica (the territory South of 60 deg S) Antigua and Barbuda Argentina, Argentine Republic Armenia Aruba Australia, Commonwealth of Austria, Republic of Azerbaijan, Republic of Bahrain, Kingdom of Bangladesh, People's Republic of Barbados Belarus Belgium, Kingdom of Belize Benin, People's Republic of Bermuda Bhutan, Kingdom of Bolivia, Republic of Bosnia and Herzegovina Botswana, Republic of Bouvet Island (Bouvetoya) Brazil, Federative Republic of British Indian Ocean Territory (Chagos Archipelago) British Virgin Islands Brunei Darussalam Bulgaria, People's Republic of Burkina Faso Burundi, Republic of Cambodia, Kingdom of Cameroon, United Republic of Cape Verde, Republic of Cayman Islands Central African Republic Chad, Republic of Chile, Republic of China, People's Republic of Christmas Island Cocos (Keeling) Islands Colombia, Republic of Comoros, Union of the Congo, Democratic Republic of Congo, People's Republic of Cook Islands Costa Rica, Republic of Cote D'Ivoire, Ivory Coast, Republic of the Cyprus, Republic of Czech Republic Denmark, Kingdom of Djibouti, Republic of Dominica, Commonwealth of Ecuador, Republic of Egypt, Arab Republic of El Salvador, Republic of Equatorial Guinea, Republic of Eritrea Estonia Ethiopia Faeroe Islands Falkland Islands (Malvinas) Fiji, Republic of the Fiji Islands Finland, Republic of France, French Republic French Guiana French Polynesia French Southern Territories Gabon, Gabonese Republic Gambia, Republic of the Georgia Germany Ghana, Republic of Gibraltar Greece, Hellenic Republic Greenland Grenada Guadaloupe Guam Guatemala, Republic of Guinea, Revolutionary People's Rep'c of Guinea-Bissau, Republic of Guyana, Republic of Heard and McDonald Islands Holy See (Vatican City State) Honduras, Republic of Hong Kong, Special Administrative Region of

Japan revises AI policy guidelines to bolster <b>cybersecurity</b>

The government has revised its guidelines for artificial intelligence-related policies, calling for constantly strengthening measures against cyberattacks in light of serious risks posed by cutting-edge AI models. The original AI policy guidelines were compiled only last December. The revision comes amid rapid technological innovation, including the launch of U.S. startup Anthropic’s Claude Mythos. The revised guidelines, adopted at a Cabinet meeting on Tuesday, note the growing threat of cyberattacks against the backdrop of advancing AI capabilities, and call for collaborating with foreign government agencies and AI development companies to significantly strengthen the capabilities of Japan’s AI Safety Institute. The guidelines also highlight the need to avoid excessive reliance on specific countries or companies for AI, and express the government’s intention to develop domestic AI that addresses challenges facing Japan. Additionally, the guidelines emphasize the significance of vertical AI, which specializes in specific areas, and physical AI, which controls robots, and include plans to promote efforts to review operations under the assumption of AI. In light of structural changes in society, the guidelines call for continuing to study the division of roles between humans and AI and developing an educational environment that prevents a decline in human capabilities due to reliance on AI. With your current subscription plan you can comment on stories. However, before writing your first comment, please create a display name in the Profile section of your subscriber account page.

How PACTS will upgrade the India–Australia <b>cybersecurity</b> partnership | The Strategist

Australia and India are set to be more prescriptive and streamlined in their joint cyber initiatives through a new partnership launched last week. On 9 July, the two countries unveiled the Partnership on Cyber, Critical Technologies and Supply Chains (PACTS), which will streamline cyber dialogues and working groups to remove duplication. Replacing the 2020 framework, PACTS aims to counter cybercrime, deter malicious cyber activities and ultimately bolster cyber trade and capacity building. It will also establish practical workshops and a cyber skill incubator hub. The partnership is intended to be more prescriptive than its predecessor, with clearer announcements. PACTS is India’s latest security tech partnership, following the TRUST initiative with the United States and the Technology Security Initiative with Britain. It promises top-level synergy with Australia to deliver outcomes. Firstly, PACTS aims to consolidate and rationalise the bilateral mechanism in cybersecurity, removing duplication across working groups and dialogues. Since 2014, there have been five rounds of cyber policy dialogues led by India’s External Affairs Ministry (MEA) and Australia’s Department of Foreign Trade (DFAT), as well as the 2022 India-Australia Foreign Ministers’ Cyber Framework Dialogue. The countries have also held two joint working groups since 2020, one on information and communications technology and the other on cybersecurity cooperation. Under PACTS, cyber dialogues and working groups will still be led by MEA and DFAT but overseen by the deputy national security adviser of the National Security Council Secretariat (NSCS) in India and the deputy secretary of the International and Security Group within the Department of Prime Minister and Cabinet (PM&C) in Australia. They will provide strategic oversight and hold annual review meetings to track progress. India’s NSCS is well positioned to oversee this partnership, following the 2024 Allocation of Business Rules amendment which made it responsible for overall coordination and strategic direction

Securities and Futures Commission (SFC) Circular – Enhanced <b>Cybersecurity</b> Measures to ...

In light of the recent guidance issued by the Securities and Futures Commission (SFC) in June 2026, we would like to share a strategic action plan tailored to help your organisation align with the evolving cybersecurity expectations and address the growing risks posed by AI-enabled threats. The SFC has emphasised the urgent need for licensed firms to reassess and strengthen their cybersecurity controls, particularly in the areas of patching, access management, threat detection, third-party oversight, and incident response. With the rise in sophisticated cyber incidents — including hyper-personalised phishing, deepfake attacks, and AI-driven reconnaissance — traditional security approaches are no longer sufficient. A shift toward continuous, data-centric, and AI-enhanced defences is now essential. KPMG is well-positioned to support your organisation throughout this journey. Our team offers a range of services, including cybersecurity gap assessments, continuous monitoring, incident response planning, and third-party risk governance, all aligned with the latest regulatory expectations and industry best practices. Should you wish to discuss how we can tailor our support to your specific needs, please feel free to contact us directly. We remain committed to helping you navigate this evolving landscape with confidence and clarity.