No-frills tech news

ISC2: AI raises accountability demands for <b>cybersecurity</b> teams | Network World

AI is reshaping cybersecurity roles, with IT professionals spending more time validating outputs, managing risk, and overseeing AI decisions. Artificial intelligence is changing how cybersecurity teams work, with security professionals spending more time validating AI-generated recommendations and deciding when to trust AI outputs, according to new research from ISC2. The ISC2 survey of 856 cybersecurity professionals found that 65% spent more time deciding when to trust or act on AI-generated recommendations during the past year, while 63% reported spending more time reviewing or validating AI outputs. The study also found that AI-related mistakes remain common. Nearly nine in 10 respondents (89%) said they have experienced AI recommendations that led to incorrect outcomes, and 50% said human decision-makers are ultimately held accountable when those mistakes occur. “AI is not replacing cybersecurity professionals; it is changing what the profession requires of them,” ISC2 CEO Scott Beale said in a statement. “As AI takes on more repetitive tasks, cybersecurity roles are shifting toward higher-value work, from asking the right questions to validating findings, interpreting outputs, and applying human judgment.” The ISC2 survey also revealed that: - 48% said AI has reduced workplace stress. - 32% said it has increased stress. - 62% cited overreliance on AI recommendations as a top concern. - 61% cited undetected errors that could scale rapidly across systems as a top concern. Many cybersecurity professionals are expected to act on AI-generated outputs without fully understanding how those outputs were produced, ISC2 found. Nearly a quarter of respondents (24%) said they are often or very often expected to act on AI-generated outputs without fully understanding how those outputs were produced. Still, respondents emphasized the importance of governance and oversight. About 80% said governance frameworks, understanding when to trust AI outputs, and knowing when to override recommendations are critical for effective

We're Raising Our Price Target on This <b>Cybersecurity</b> ETF | TheStreet Pro

We’re Raising Our Price Target on This Cybersecurity ETF Plus a quick word on ETFs, their strategies and purity levels. You've reached your free article limit You've read 0 of 1 free Pro articles. After lifting our Apple (AAPL) price target yesterday, we are making further progress revisiting a few other Pro Portfolio holdings, including the First Trust Nasdaq Cybersecurity ETF (CIBR). Our underlying thesis for the ETF is that cyberattacks are on a growth vector that is being amplified by the rising adoption and expanding usage of AI by bad actors. We’ve shared numerous examples of that, and odds are that volume of signals isn’t going to slow down much, if at all. That growing cybersecurity pain point, as companies and other entities look to protect their assets, IP, and other crown jewels, is expected to drive cybersecurity spending to more than $520 billion by 2031. The math behind that equates to a 7.6% compound annual growth rate over the ensuing years. Backing that forecast from the Futurum Group is a survey of more than 900 enterprise cybersecurity buyers globally. The survey’s findings flagged cloud security, security operations and governance, risk and compliance, data security and application security as the fastest-growing segments inside that spending. Reviewing that list, we continue to favor the diversified exposure CIBR brings to the Portfolio, and we are raising our price target to $105 from $85. As we make this move, we are also adjusting our CIBR checkpoint to $75 from $70. As holdings in CIBR’s basket report their quarterly results, we’ll look to revisit those figures as needed. Before we move on, let’s take a moment to discuss CIBR’s holdings and share a thought or two on purity levels. For those unfamiliar with the term “purity levels,” we’re referring to the degree to

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer is implemented in native C++, according to Jamf Threat Labs. "It validates the victim's login password locally before harvesting, collects broadly across browsers, cryptocurrency wallets, password managers, and the keychain, encrypts what it collects with AES-GCM before exfiltrating over libcurl, and persists by copying and re-signing itself," security researcher Thijs Xhaflaire said in a report shared with The Hacker News. CrashStealer is said to be distributed by means of a signed and Apple-notarized dropper that's distributed as a disk image file named "Werkbit.app." Because both the disk image and binary are notarized and carry a valid developer ID ("Emil Grigorov (WWB7JA7AQV)"), it passes Gatekeeper checks. The disk image itself originates from the domain "werkbit[.]io," which was registered in June 2026. In an interesting twist, the download is gated behind a meeting PIN, meaning the installer is served only to those site visitors who arrive with the right code rather than everyone. The discovery of additional domains and shared backend infrastructure tied to the same operation points to CrashStealer being part of a larger, multi-platform campaign. Once mounted, the disk image presents the user with an installation setup screen that instructs them to right-click the app and choose "Open" to get them to run it. Once launched, the "veltod" executable contacts a GitHub repository ("github.com/mgothiclove") to retrieve a file named "sys.cache." The file is then used to extract a curl command and pull a shell script, which acts as a downloader to fetch and stage the next payload ("CrashReporter.dmg") and saves it to the "/tmp" directory. The malware, upon execution, establishes persistence as a LaunchAgent, resists analysis,

AI in <b>Cybersecurity</b> Is Not What Vendors Are Selling You | HackerNoon

Every major cybersecurity vendor now claims their product is “AI-powered.” The term has become so overused that it has lost almost all meaning. When everything from a firewall to a password manager is described as artificial intelligence, the word stops being informative and starts being noise. But behind the marketing, there is a real question worth answering: where does AI actually work in cybersecurity, and where is it still failing? Having worked in cybersecurity across regulated industries — aviation, port operations, healthcare, and manufacturing — I have seen both sides of this problem. I have seen AI-labelled tools that were nothing more than regex under a dashboard. I have also seen machine learning solve problems that no human team could handle at scale. And in my own work, I work with a credential exposure dataset of over 8.2 billion records — large enough that the question of what AI can and cannot do stopped being theoretical a long time ago. The difference comes down to one idea: AI is useful in cybersecurity when the problem is scale. It is dangerous when the problem is judgement. Everything below follows that line. Where AI Actually Works These are scale problems — problems where the volume of data exceeds what any human team can process manually, and where pattern recognition provides genuine, measurable value. 1. Dark Web Content Classification The dark web produces an enormous volume of unstructured content across multiple languages, formats, and platforms — forums, paste sites, Telegram channels, marketplaces, and onion services. Manually triaging this content is not scalable. NLP works well here because many threat actor communities use recurring language patterns, listing formats, and commercial vocabulary. Ransomware groups announce victims using consistent phrasing. Credential sellers describe their data in formulaic ways. Multilingual NLP models can classify posts by threat

Election <b>cybersecurity</b>: what's new for 2026

Photo courtesy of: Felicia Pratt Election cybersecurity: what's new for 2026 Tuesday, August 18, 2026 11 a.m. – Noon PT USC Capital Campus, Room 202 and Online The USC Annenberg Center on Communication Leadership and Policy is pleased to host a forum titled "Election Cybersecurity: What's New for 2026" at the USC Capital Campus. Government and campaign officials will address new challenges created by AI-enabled cyber attacks - and how to defend against them. The event will be held in a hybrid format (in person and online) on Tuesday, August 18, at 2:00 p.m. ET / 11:00 a.m. PT. This program is open to all eligible individuals. USC Annenberg operates all of its programs and activities consistent with the University’s Notice of Non-Discrimination. Eligibility is not determined based on race, sex, ethnicity, sexual orientation, or any other prohibited factor.

'Yellow Teams' Are Defining the Future of AI Security

Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. 'Yellow Teams' Are Defining the Future of AI Security In some companies, engineers are building defense and attack tools to test the potential of artificial intelligence for cybersecurity — and its threat. A small number of engineering teams are developing the defenses that organizations will need against future advanced AI attacks. They're also building the frameworks attackers will utilize to carry out those attacks. In April, Anthropic invited more than 50 organizations to participate in its Project Glasswing initiative to preview Claude Mythos, which the company claimed at the time was the most advanced cybersecurity AI. OpenAI followed suit shortly after, inviting organizations to play with its own GPT 5.5 under the Daybreak program. Since then, red teams — penetration testers — have been using the AI models to exploit their own companies' systems, and rival blue teams tried to detect and defend against those exploits. In the middle of it all are engineers, building both mitigations against the models' greatest threats and frameworks for mobilizing their greatest powers. In modern cybersecurity parlance, these are "yellow" teams, a term first introduced at Black Hat 2017 to bring developers into the security testing process. They're out defining what cybersecurity will look like for years to come. "Yellow team is a build team," explains Sam Curry, chief information security officer (CISO) at Zscaler, a Glasswing partner. "They'll say: 'Hey, Red, what tools could you use to do better attacks?' As if they were the engineering department behind a major attacker. They'll also turn to Blue and go: 'What would you like on defense that isn't supplied to you by your vendor community?'" Step Into the Room With Yellow Teams Yellow teams don't often build for red teams. Yet that's

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.

Upgrade Your <b>Cybersecurity</b> With This 66% off Antivirus and Security Deal | PCMag

TL;DR: Stay safer online with just a few taps thanks to this one-year subscription to Panda Dome Antivirus and Security Advanced Plan, now on sale for just $19.99 (MSRP $59.99). Protecting yourself online doesn’t need to be complicated. Panda Dome Antivirus and Security makes it simple with an Advanced Plan for your Windows device that includes VPN access, a dark web scanner, anti-ransomware protection, parental controls, and more. Right now, you can secure a one-year subscription for just $19.99—less than $2 a month. Keep Your Windows PC Safer With This Deal Give your online security a boost with this all-in-one Panda Dome Antivirus and Security deal. It packs multiple layers of protection into a single app, giving you a full year of security features at one low price. With Panda Dome, you’ll enjoy real-time antivirus protection that blocks viruses, malware, spyware, and more, plus anti-ransomware security that prevents unauthorized encryption of your personal files. Though you may have never considered securing your Firewall and Wi-Fi, don’t worry. Panda Dome has it covered with this deal. It also offers safe browsing, anti-phishing protection, and a dark web scanner to help ensure your info doesn’t surface in data breaches. Get access to a VPN, parental controls, and even USB scanning, which checks your removable devices for threats. Recommended by Our Editors Lock in your own year of security with this one-year subscription to Panda Dome Antivirus and Security Advanced Plan for just $19.99 today. Prices subject to change. PCMag editors select and review products independently. If you buy through StackSocial affiliate links, we may earn commissions, which help support our testing. About Our Expert Products featured in these stories are selected by our partners at StackCommerce. If you buy something through links on our site, PCMag may earn an affiliate commission. -

Pentagon announces 'immediate suspension' of CMMC Phase II mandates

WASHINGTON — The Pentagon is suspending part of its cybersecurity requirements for industry, specifically related to third party assessments, citing onerous burdens on especially smaller defense firms. “In support of Secretary of War Hegseth’s directive to aggressively scale warfighter readiness, I’m announcing the immediate suspension of the Cybersecurity Maturity Model Certification, or CMMC, Phase II requirements, which were originally scheduled to go into effect November 10, 2026,” Kirsten Davies, chief information officer, told reporters at the Pentagon today, using the secondary name for the secretary of defense. “I want to be clear across the Department of War and our defense industrial base, investing in and dynamically maintaining robust cybersecurity remains a critical non-negotiable priority. This action does not eliminate the legal requirement for our industry partners to protect federal data.” Davies added later, “We are not reducing cybersecurity through this measure. We are reducing the red tape.” A July 10 memo released by the Pentagon today notes that the current iteration of CMMC imposes “significant and often prohibitive burdens on the Defense Industrial Base (DIB), particularly the small and non-traditional businesses that are the engine of American innovation. While cybersecurity is essential, administrative compliance cannot come at the cost of warfighting capability and industrial base growth.” The current administration has made it a top priority to loosen perceived bureaucratic restrictions and hurdles in order to speed up the delivery of systems and capabilities while seeking to simultaneously grow the industrial base. CMMC has been in the works since at least 2019, during the first Trump administration. At the time, there was worry that America’s enemies were able to infiltrate contractors and suppliers to steal information and aggregate it to gain a significant advantage. The program was meant to bolster the security of the entire industrial base so that the weakest

Ohio Cyber Guardian trains teams to defend against cyberattacks

CINCINNATI — As cyberattacks continue to target critical infrastructure across the country, cybersecurity professionals from government, the military and private industry gathered at the University of Cincinnati this week to prepare for the next digital threat. Now in its fifth year, Ohio Cyber Guardian is a four-day cyber defense exercise hosted by the Ohio Cyber Range Institute at UC’s Digital Futures building. The exercise simulates cyberattacks against critical infrastructure, allowing participants to practice detecting threats, coordinating responses and strengthening cybersecurity readiness. “We are cyber insecure; that’s just a starting point,” said Richard Harknett, co-director of the Ohio Cyber Range Institute. The exercise comes as cybercrime continues to rise nationwide. According to the FBI’s Internet Crime Complaint Center, Americans reported more than $20 billion in cybercrime losses last year. Rebekah Michael, executive staff director of the Ohio Cyber Range Institute, said cyber threats extend beyond computers and can affect the services Ohioans depend on every day. “Every Ohioan is vulnerable, but also businesses and our critical infrastructure like our electric grids and our wastewater treatment plants,” Michael said. Organizers said one of the exercise’s greatest strengths is the collaboration between military personnel, government agencies, private industry and cybersecurity professionals. “There will be no future war without cyber, and there will be no winning of wars without cyber readiness and superiority,” said Brig. Gen. Clarence K. Maynus, Ohio’s assistant adjutant general. Michael said cyber threats will continue to evolve, making ongoing training essential. “There’s no way to ensure that we are safe. There’s no 100% solution,” she said. “But with trainings like this and preparing our people for this, we are more secure.” Harknett said participants leave the exercise with more than technical experience. “Hopefully they’re going back trained up, skilled up, but also with a different orientation about what they can

Translating Higher Education <b>Cybersecurity</b> Into Business Value

When platforms like Canvas or the underlying cloud providers experience outages, the impact is immediate and personal: Exams are postponed, schedules are disrupted, grades are delayed and students question whether the institution is as reliable as its marketing suggests. That’s not a “technical hiccup.” It’s a hit to student experience, and ultimately to retention, recruitment and revenue. Cybersecurity leaders who continue to talk in terms of patches, vulnerabilities and scan counts are missing the moment. The institutions that are evolving are those where CISOs are now business enablers, not just technical guardians. The Modern Higher Ed CISO: Business Leader First, Technician Second Thirty years ago, a CISO or security practitioner was often buried inside IT, there to fulfill compliance requirements and keep systems “secure enough.” Reporting lines and expectations reflected that. Today’s reality is different. Modern CISOs must be able to answer questions like: - How does our security posture help us retain current students and attract new ones? - How does it support new research initiatives and the grants tied to them? - How does it protect our intellectual property and institutional reputation? That requires business acumen: understanding funding models, student lifecycle, research pipelines and competitive positioning. It also requires the courage to move away from purely technical metrics and speak in the language of outcomes. WATCH: IT leaders share their CIO playbook best practices when cybersecurity threats surge. Demonstrate Business Value Through Outcomes Fear‑based arguments such as breach headlines, critical vulnerabilities and compliance fines might get attention, but they rarely sustain investment. Boards and CIOs increasingly want to know, what do we get for this spend? That’s where outcome‑based framing comes in: - Instead of “we patched 3,000 systems,” say, “we ensured 100% uptime for the 55 systems that drive tuition revenue and student success.” - Instead of

Tracking The AI Revolution: Innovation And Cyber Risks

Artificial intelligence has emerged as the quintessential innovation platform of the 21st century, transforming economies, governments, businesses, and the everyday lives of billions. Similar to electricity, the Internet, and cloud computing, AI is developing into essential infrastructure—yet at a significantly accelerated rate and with implications that affect every industry. Artificial intelligence continues to evolve at an accelerating pace, transitioning from narrow, data-driven tools to systems capable of reasoning, autonomous action, human augmentation, brain-inspired efficiency, and deeper human-machine integration. We are entering the Acceleration Era, where AI converges with quantum computing, enhanced networking, robotics, biotechnology, space technologies, edge computing, and next-generation computing architectures, integrating biological and chemical paradigms. These technologies are not evolving in isolation. They are enhancing each other to develop whole new capabilities while concurrently broadening our cyber risk landscape. Technological innovation and cybersecurity have become fundamentally intertwined. Each novel breakthrough presents remarkable opportunities, yet also unparalleled vulnerabilities. This trajectory—from machine learning foundations through generative and agentic phases to augmentation-focused decision-making, neuromorphic efficiency, and cyborg symbiosis—will redefine industries, security, and human potential. The potential of AI is vast. Artificial Intelligence Transforms Global Society; AI replicates human capabilities in learning, problem-solving, and natural language processing. It generates multi-trillion-dollar economic effects, transforms healthcare through pharmaceutical innovation and predictive analytics, improves customer experiences through robotic process automation and chatbots, and facilitates human enhancement via neuromorphic computing and brain-computer interfaces that could significantly augment cognitive abilities. However, the challenges are equally substantial. Artificial intelligence, along with 5G, the Internet of Things, and quantum computing, creates hyper-connected systems that improve efficiency but also lead to complex data flows, model opacity, bias vulnerabilities, and larger attack surfaces, which require immediate governance and security frameworks. Please see: This overview aims to examine the evolution of AI from four interrelated angles, weighing its revolutionary advantages against its

Translating Higher Education <b>Cybersecurity</b> Into Business Value

When platforms like Canvas or the underlying cloud providers experience outages, the impact is immediate and personal: Exams are postponed, schedules are disrupted, grades are delayed and students question whether the institution is as reliable as its marketing suggests. That’s not a “technical hiccup.” It’s a hit to student experience, and ultimately to retention, recruitment and revenue. Cybersecurity leaders who continue to talk in terms of patches, vulnerabilities and scan counts are missing the moment. The institutions that are evolving are those where CISOs are now business enablers, not just technical guardians. The Modern Higher Ed CISO: Business Leader First, Technician Second Thirty years ago, a CISO or security practitioner was often buried inside IT, there to fulfill compliance requirements and keep systems “secure enough.” Reporting lines and expectations reflected that. Today’s reality is different. Modern CISOs must be able to answer questions like: - How does our security posture help us retain current students and attract new ones? - How does it support new research initiatives and the grants tied to them? - How does it protect our intellectual property and institutional reputation? That requires business acumen: understanding funding models, student lifecycle, research pipelines and competitive positioning. It also requires the courage to move away from purely technical metrics and speak in the language of outcomes. WATCH: IT leaders share their CIO playbook best practices when cybersecurity threats surge. Demonstrate Business Value Through Outcomes Fear‑based arguments such as breach headlines, critical vulnerabilities and compliance fines might get attention, but they rarely sustain investment. Boards and CIOs increasingly want to know, what do we get for this spend? That’s where outcome‑based framing comes in: - Instead of “we patched 3,000 systems,” say, “we ensured 100% uptime for the 55 systems that drive tuition revenue and student success.” - Instead of

Where do SMEs stand in preparing for the Cyber Resilience Act? | ENISA

The EU Agency for Cybersecurity (ENISA) publishes the Micro, Small and Medium-sized enterprises (SME) Cyber Resilience Maturity Assessment Model, a simple and practical guidance for SMEs to support them assess their current status, identify improvements and strengthen their cyber resilience practices. As SMEs make up a large part of EU´s digital ecosystem, their ability to understand and implement the Cyber Resilience Act (CRA)is significant for the regulation’s success. Particularly, as smaller organisations face practical challenges related to resources, expertise, time and implementation capacity. To help address this, as part of the European Commission’s SME cybersecurity strategy, ENISA is working on practical guidance, tools and support activities tailored to the realities and needs of smaller organisations. The SME Cyber Resilience Maturity Assessment Model provides a structured approach for SMEs to evaluate and strengthen their overall cyber resilience, while taking into account the requirements of the CRA. The model is primarily intended for organisations that manufacture and place products with digital elements on the market, as these are directly subject to CRA requirements. However, it can also be used by other organisations involved in the product life cycle, such as integrators or service providers, to assess and improve their product security practices. It focuses on the following five domains, with each domain divided into five maturity criteria that reflect expected practices under the CRA and product security approaches: - governance and documentation, - risk management and security by design and by default, - vulnerability and patch management, - product life cycle management, - awareness, competence and skills. The model suggests three maturity profiles: basic, intermediate and advanced, intended to show how consistently product-related risks are managed in the organisation. Overall, this model reflects practices supporting the implementation of the CRA and supports organisations in strengthening their product security and cyber resilience over

3D Printing <b>Cybersecurity</b> Market to Grow 22.5% Annually

3D Printing Cybersecurity Market to Grow 22.5% Annually The global cybersecurity market for 3D printing machines is projected to grow from US$120 million in 2026 to US$910 million by 2036, at a 22.5% CAGR, as manufacturers strengthen protection against cyberattacks targeting digital design files, cloud-based additive manufacturing workflows and safety-critical production environments. As additive manufacturing becomes a core production technology for industries such as aerospace, defense and healthcare, cybersecurity is emerging as a business requirement rather than an operational consideration. A new study from Meticulous Research projects the global cybersecurity market for 3D printing machines will expand from an estimated US$120 million in 2026 to US$910 million by 2036, reflecting a compound annual growth rate of 22.5%. The forecast highlights how manufacturers are responding to a growing threat landscape in which digital design files, connected printers and cloud-based production environments have become valuable targets for cybercriminals. As 3D printing shifts from prototyping to manufacturing mission-critical components, securing the digital workflow has become increasingly important for protecting intellectual property, ensuring product integrity and meeting regulatory requirements. Cyberattacks Turn 3D Printing Security Into a Business Priority Unlike conventional manufacturing, additive manufacturing depends on digital files that define every aspect of a component. Those files are transferred across software platforms, cloud environments and production equipment before becoming physical products. Each step creates opportunities for unauthorized access, data theft or manipulation. A compromised design file can result in counterfeit products, intellectual property theft or subtle modifications that weaken a component without altering its appearance. In sectors where printed parts are installed in aircraft, medical devices or industrial equipment, those alterations can introduce operational and safety risks beyond financial losses. As a result, organizations are expanding investments in technologies such as encryption, access controls, secure file transfer and traceability solutions to protect the complete digital

BREAKING: Pentagon Suspends Phase 2 of CMMC Program

CYBERSECURITY BREAKING: Pentagon Suspends Phase 2 of CMMC Program By Josh Luckenbaugh iStock illustration The Defense Department announced July 13 that it was suspending the Phase 2 requirements for its Cybersecurity Maturity Model Certification program and that it would be conducting a comprehensive review of the initiative to ensure it aligns with Secretary of War Pete Hegseth’s Acquisition Transformation Strategy. The program, known as CMMC, is meant to be the department’s mechanism for verifying defense contractors are compliant with its cybersecurity requirements. Phase 1 of the program began Nov. 10 of last year and required companies to self-assess compliance at two security levels. Phase 2, which would have begun on Nov. 10, would have seen the introduction in applicable Pentagon solicitations of CMMC Level 2 requirements for companies to be certified by a third-party assessment organization. But while CMMC was designed to enhance the defense industry’s cybersecurity, “instead it has created prohibitive compliance costs and bureaucratic burdens,” according to a Defense Department release. Small Business Administration reports have shown that “CMMC compliance is forcing innovative companies out of the defense industrial base, which will delay the delivery of critical capabilities to the warfighters,” it said. To support Hegseth’s directive as part of his Acquisition Transformation Strategy to reduce compliance barriers for small and medium-sized businesses, the department is suspending CMMC Phase 2 requirements, Pentagon Chief Information Officer Kirsten Davies said. “Robust cybersecurity and operational resilience remain critical to protecting American innovation and supporting warfighter readiness,” Davies said in the release. “We believe the [defense industrial base] can achieve both, while we reduce unnecessary government red tape.” Additionally, pending and future CMMC implementation milestones in Pentagon solicitations and contracts will be suspended, the release stated. However, Phase 1 self-assessment requirements remain in place. Meanwhile, Davies is establishing a CMMC Reform Task

New Jersey Continues Statewide Investment in <b>Cybersecurity</b>

The first program is aimed at the state’s water and wastewater operators, which have until July 31 to apply for the Safe Drinking Water Cybersecurity Grant Program (SDWCGP). At the same time, New Jersey is also accepting applications through Sept. 11 for its Nonprofit Security Grant Program, which supports eligible security technologies and facility upgrades. The SDWCGP is offered by the New Jersey Office of Homeland Security and Preparedness, and it is focused on four areas: governance and planning, risk management, resilience and workforce development. Taking a whole-of-state approach, the office’s Cybersecurity and Communications Integration Cell (NJCCIC) will directly procure software, services and training to be provided to awardees. Tools include endpoint detection and response, managed detection and response, and multifactor authentication, among others. Workforce development offerings include in-person and remote training on cybersecurity awareness, IT and operational technology security, cyber operations, incident response, and threat and vulnerability management. The program was established with $4 million in early 2024. Organizations that serve New Jersey communities and residents are eligible, but they must join the NJCCIC and complete an online assessment before submitting an application. While the utility program focuses on critical infrastructure cyber readiness, a separate nonprofit grant program supports organizations that may face elevated security risks. The New Jersey Nonprofit Security Grant Program, a permanent state program, is taking applications for funds toward approved physical security improvements as well as IT and cybersecurity equipment for eligible organizations. Eligible parties may apply for both security personnel as well as for equipment grants, but applicants can only receive one award, according to the documentation. For equipment relating to cybersecurity, the list includes credentialing systems, software as a service applications, remote authentication, encryption software, firewalls and anti-virus software. Organizations may apply for up to $100,000 in this area. According to the state,

Can AI narrow <b>cybersecurity's</b> class divide?

AI is giving elite security orgs new ways to automate red teaming, detection engineering, and vulnerability discovery. But experts debate whether the technology will deepen cyber’s long-standing resource divide — or finally help close it. At Amazon Web Services (AWS), artificial intelligence is already compressing security work that once took months into minutes. In the old world, human red teams would find vulnerabilities, write reports, refine those reports, and eventually hand them to defenders, who would then begin building detections or fixes, Steve Schmidt, chief security officer at AWS, tells CSO. That process could take “two, four, six, eight, 10 months,” Schmidt says. “Now with proper application of AI, we can have the detections built for the problems the red team finds in 15 minutes-ish,” he says. “I think the outside is about four hours.” That kind of workflow offers a glimpse of what AI could make possible for the most sophisticated security organizations: AI agents testing systems, other agents generating defenses, and human security engineers validating results and refining the feedback loop. But it also raises a more uncomfortable question for the rest of the cybersecurity industry: What happens to organizations that cannot build anything close to that? The concern has become significant enough that the Trump administration recently directed agencies to expand access to AI-enabled cybersecurity capabilities for resource-constrained organizations, including rural hospitals, community banks, and local utilities. The order reflects a growing fear that AI could deepen a divide that has existed in cybersecurity for years: the divide between organizations with money, expertise, and engineering depth, and those struggling to keep pace with basic security demands. Yet security leaders and practitioners suggest the impact of AI will be more complicated than a simple widening gap. Some experts say AI is merely adding a new layer to a

CyberCUBE, ESA's mission to strengthen the <b>cybersecurity</b> of space systems, successfully ...

CyberCUBE, ESAs mission to strengthen the cybersecurity of space systems, successfully launched from California Led by GMV for the European Space Agency, the mission relies on a 3U CubeSat platform developed by Alén Space and will serve as an in-orbit laboratory to validate cutting-edge space cybersecurity technologies The European Space Agencys (ESA) CyberCUBE mission, designed to strengthen the protection of space assets against growing cyber threats, has been successfully launched from the Vandenberg Space Force Base in California, aboard a Falcon 9 rocket. The mission, led by the multinational technology company GMV through its teams in Romania and Spain, also involves Alén Space, a pioneering New Space company that has been part of GMV since 2023. The successful launch of the satellite into orbit marks the start of a pioneering mission designed to validate cutting-edge cybersecurity technologies and capabilities applied to the space environment under real-world conditions. CyberCUBE is part of the Cyber Evolutions activities of ESAs Cybersecurity Operations Center (CSOC) within the framework of the Cyber Security Resilience programme, a cross-cutting initiative led by the Agencys Security Office to strengthen the protection of both its corporate systems and its space missions. CyberCUBE was designed as an in-orbit experimentation platform capable of providing ESA with a secure, flexible, and reconfigurable environment for demonstrating new cybersecurity technologies before they are incorporated into future European missions. The missions main goal is to validate the CSOCs data monitoring and analysis capabilities using actual space assets. At the same time, it will make it possible to test new onboard cyber capabilities and collect critical information to improve the resilience of space systems against emerging threats. Highlights of the planned experiments include detection and protection against unauthorised access to command-and-control systems, identification and mitigation of jamming and spoofing attacks, monitoring of onboard systems, and the