Box CEO Aaron Levie recently posted on X that AI for cybersecurity "is about to go vertical" as models become increasingly capable of finding and exploiting vulnerabilities.
As threats multiply, companies need systems that can prioritize alerts, investigate risk, recommend fixes, and automate remediation.
AI may ease the talent shortage — and change the job Bourzikas said that the cybersecurity industry has faced a historic "talent shortage" due to a gap in specialized skills.
"The war for engineers with deep AI and security expertise is at an absolute fever pitch," Bourzikas wrote.
Unlike Bourzikas, who expects cybersecurity worker headcount to keep growing, Palmore expects fewer people may ultimately be needed — and that they'll be expected to have a different, more advanced skillset from the get-go.
Sep 18, 2026 · via businessinsider.com
Cybersecurity leaders have surged this year as investors rotate within technology and seek exposure to AI-driven security demand.
Freedom Capital’s chief market strategist, Jay Woods, sees further upside in one laggard: Zscaler.
According to Woods, the sector’s strength has increasingly spread beyond its market leaders, creating opportunities among cybersecurity stocks that have yet to participate fully in the rally.
AI Buildout Supports Cybersecurity Demand Woods argues that the AI buildout is strengthening the long-term case for cybersecurity.
Retail Sentiment For Cybersecurity Stocks On Stocktwits, the retail sentiment was ‘bullish’ for ZS and PANW, and ‘neutral’ for CRWD and OKTA.
Sep 18, 2026 · via stocktwits.com
Troy Hunt of HaveIBeenPwned has reported that the data allegedly stolen from McKesson included 6.4 million unique email addresses from marketing campaigns, patients, staff members, and other individuals.
ShinyHunters added McKesson to its data leak site, and the listing claims that 284 million patient data records were exfiltrated.
McKesson announced the incident on August 28, 2026, explaining that an investigation had been launched following “a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data.”
According to the SEC filing, the cybersecurity incident was first detected on August 25, 2026.
ShinyHunters claims that the stolen data includes names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication/allergy information, diagnoses, appointment information, and other sensitive data.
Sep 18, 2026 · via hipaajournal.com
CHICAGO (WLS) -- Former Homeland Security officials and federal cybersecurity agencies are warning that artificial intelligence is increasingly being exploited by terrorists, criminals and foreign adversaries, raising concerns about potential threats to national security.
Former Homeland Security Acting Undersecretary for Intelligence and ABC News contributor John Cohen told the ABC7 I-Team that terrorist groups and criminal organizations are already using artificial intelligence to enhance their capabilities.
The growing use of AI presents significant national security concerns because it can accelerate the planning and execution of attacks, according to Cohen.
"Artificial intelligence has dramatically shortened the time it takes for a terrorist group to plan an attack, and it increases the likelihood that their attack plan will be successful," he said.
SEE ALSO | OpenAI flags concerning new AI behavior and vows to track it more closely Federal authorities, including the National Security Agency, have warned that adversaries such as China are working to exploit American-made AI technology and extract its capabilities.
Sep 18, 2026 · via abc7chicago.com
With doomsday AI scenarios dominating the news, lawmakers are rightly concerned about reports concerning security breaches at major US AI labs, such as the OpenAI–Hugging Face incident and the many others reported in its aftermath.
As they consider potentially regulating frontier AI, they should focus any new legislation on the immediate, demonstrated risks from those incidents.
Post-incident reports show that the Hugging Face incident could have been mitigated or prevented by following longstanding cybersecurity best practices, like stronger sandboxing and monitoring.
Following these fundamental best practices would have prevented or substantially mitigated all of the incidents at AI labs that we currently know about.
Tying any new mandates to evidence-backed security protocols also protects the public without impeding future AI development.
Sep 18, 2026 · via eff.org
1 min read | | Latin Lawyer Editorial Team Latin Lawyer Editorial Team Madrona Advogados has advised Brazilian aerospace company Embraer on the combination of its cybersecurity subsidiary with Vision Cybersecurity, a subsidiary of investment group SPX, which relied on Mattos Filho.
To read more Subscribe to Latin Lawyer Register for limited access Register to receive regular round-up emails and limited access to selected content.
Register now Subscribe to unlock unlimited access Get news, unique commentary, expert analysis and essential resources from the Latin Lawyer experts.
Subscribe now Already have access?
Login below E-mail or username Password Remember me Latin Lawyer Editorial Team Copyright © 2026 LBR trading as CentellicCompany Number: 03281866 VAT: GB 160 7529 10
Sep 18, 2026 · via latinlawyer.com
Headline The National Institute of Standards and Technology and the Cybersecurity and Infrastructure and Security Agency have released guidelines to protect… Headline The House Energy and Commerce Subcommittee on Health held a hearing Sept. 15 to discuss more than a dozen legislative proposals regarding Medicare provider… Headline The National Security Agency has released a best practices guide on effective cyber hygiene for defending against advanced cyber threats, including those… Headline An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to… Headline In this conversation, John Riggi, AHA national advisor for cybersecurity and risk, and Scott Gee, AHA deputy national advisor for cybersecurity and risk, break…
Sep 18, 2026 · via aha.org
Three cybersecurity researchers used Claude to breach OpenAI Group PBC’s GitHub repository.
OpenAI’s forum is powered by an open-source discussion board platform called Discourse.
Under the hood, the software processes images with the help of an open-source tool called libheif.
The proof-of-concept worked well in their internal Discourse instance, but didn’t carry over to OpenAI’s forum because it uses a safeguard called ASLR.
The libheif vulnerability that exposed OpenAI’s code is one of several exploits in the image processing tool.
Sep 18, 2026 · via siliconangle.com
That center of gravity is George Prepakis, an accomplished security researcher and self-described exploit developer who operates the Twitter/X profile @kernelstub.
Zach Edwards is chief research officer for DecryptAds and a threat researcher at the security company Infoblox.
“It’s really built for a lot of privacy and security use cases that have been dramatically underserved.”
Moucka also threatened and harassed government officials and security researchers who were helping to track him down.
Further investigation into the Fengwo Group revealed it has registered multiple patents that match the inner workings of these apps.
Sep 17, 2026 · via krebsonsecurity.com
Dive Insight: Black Kite paints a grim picture of cybersecurity at the 1,000 largest manufacturers.
Manufacturers aren’t moving quickly enough to fix the problems that will create tomorrow’s cyberattacks, Black Kite said.
Top 1,000 manufacturers’ improvements in patching are important, researchers wrote, but they only address “the doors attackers have always used.”
One of those groups, The Gentlemen, conducted roughly 12% of all the attacks that Black Kite has logged so far in 2026.
Black Kite warned in August that the midmarket was a disproportionate ransomware target because of its unique challenges.
Sep 17, 2026 · via cybersecuritydive.com
The Healthcare and Public Health Sector Coordinating Council’s Cybersecurity Working Group testified to the House Energy and Commerce Subcommittee on Health about sector progress in adopting strong cybersecurity practices.
Greg Garcia, HSCC executive director, endorsed two pending bills—the ‘Healthcare Cybersecurity and Resiliency Act’ and the ‘Rural Hospital Cybersecurity Enhancement Act,’ while offering refinement suggestions.
These bills provide complementary guidance on structured coordination processes and objectives across HHS, CISA, and the healthcare sector, and targeted assistance to rural and resource-constrained health providers.
Garcia referenced HSCC’s 2025 report ‘On the Edge: Cybersecurity Health of America’s Resource-Constrained Health Providers’ as validation of the bill’s findings and provisions.
Finally, the NICE Framework’s Work Roles and Job Descriptions should be mapped to HHS-HSCC Health Industry Cybersecurity Practices to create clarity and uniformity in matching skills with healthcare cybersecurity job requirements.
Sep 17, 2026 · via industrialcyber.co
Frontier AI is rapidly becoming one of the defining cybersecurity and sovereignty issues of our time.
For organizations, this means frontier AI should not be viewed simply as another innovation wave or productivity tool.
This is also why frontier AI has become inseparable from the debate about digital sovereignty.
The answer is not to choose between innovation and sovereignty, or between access to frontier AI and security.
Frontier AI will be a powerful force for defense, but only if it is deployed on foundations that are secure, sovereign and resilient by design.
Sep 17, 2026 · via cybersecurity-insiders.com
Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader.
In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut.
Her advice is to stop trimming every line by the same percentage.
Hotman says waste is common, with companies running three or four GRC tools that each do part of the job.
Security leaders who speak in risk and dollars, back their estimates with due diligence, and tie spending to revenue get a different conversation with finance.
Sep 17, 2026 · via helpnetsecurity.com
Election security concerns have long been at the forefront of the conversation around election equipment.
Here are some of the election security issues state lawmakers will have to consider.
“Election security is a process and not a purchase.”
Foreign interference Federal cuts to election security systems and a recent spike in cyberattacks may also fuel the risk of foreign interference in the midterm elections.
“We have a very, very robust state system that takes care of us that knows when things like that are going on and they alert us very quickly,” she said.
Sep 17, 2026 · via georgiarecorder.com
State Superintendent Jill Underly announced the first part of the department’s 2027-29 biennial budget request on Wednesday.
“This first portion of our budget request addresses critical needs at the Department of Public Instruction while making investments in Deafblind Outreach, public libraries, and other essential programs.”
Last fall, the U.S. Department of Education terminated grant funding for the Wisconsin Deafblind Technical Assistance Project and denied a DPI appeal.
Additional provisions included in the first part of the DPI’s biennium budget request include: $350,200 to fund two additional positions dedicated to educator license investigations.
$6.7 million in cybersecurity investments to prepare for, respond to, and mitigate the impact of incidents potentially affecting Wisconsin K-12 schools and public libraries.
Sep 17, 2026 · via urbanmilwaukee.com
Polk State College announced on Wednesday that it is revitalizing its registered apprenticeship program in cybersecurity in partnership with the Florida Department of Education.
Commissioner of Education Dr. Henry Mack and members of the State Board of Education joined Polk State President Anastasios Kamoutsas for the announcement as the College hosted the Board on the Winter Haven Campus for its monthly meeting.
“Polk State is doing the hard work of rebuilding a registered apprenticeship that employers can trust and that communities need.
“By revitalizing this registered apprenticeship, Polk State is connecting classroom instruction with paid on-the-job training and portable credentials.
“Jeremiah Anhalt, who went through this registered apprenticeship program previously at Polk State, was recently promoted to Director of Technology Management, while Shemar Mais in our Technology Management Department is looking forward to participating in the program now,” said Hall, who added that she is also a proud Polk State alumna.
Sep 16, 2026 · via polk.edu
— Another Massachusetts community is investigating a cybersecurity incident that affected portions of their network and school environment, according to Sutton officials.
Independent cybersecurity and forensic experts have been hired, and law enforcement has been notified, Sutton officials said.
Officials are still trying to determine the nature and scope of the incident, including whether any information was affected.
Town officials said municipal services continue to operate and that additional security measures have been implemented to strengthen the town's systems.
Last week, the Springfield, Massachusetts, school district's data was breached as a result of a cyberattack that closed schools for several days last week.
Sep 16, 2026 · via wcvb.com
In July, OpenAI disclosed that several of its AI models had circumvented controls designed to isolate them from the internet during cybersecurity evaluations.
But the fact that increasingly capable agents can find ways beyond their intended boundaries creates an interesting new cybersecurity problem.
Faced with a rapidly growing flood of vulnerabilities, including some that AI systems themselves may help discover or exploit, the agency is turning to agentic AI as part of the defense.
NIST has already begun developing a tool called V-etalon that uses AI technologies to help enrich vulnerability information.
More capable AI systems can discover and potentially exploit vulnerabilities faster, adding new pressure to an already rapidly expanding vulnerability-management ecosystem.
Sep 16, 2026 · via nextgov.com
UAE boards now face direct accountability for cybersecurity oversight and governance failures.
DUBAI, UNITED ARAB EMIRATES, September 16, 2026 /EINPresswire.com/ -- Cybersecurity oversight in the UAE has moved from a technical reporting line to a board-level governance matter.
That began to change once UAE regulators started framing a breach not solely as a technical failure, but as evidence of inadequate board oversight.
UAE boards are now expected to show more than a signed-off annual report.
Regulators increasingly look for documented engagement: meeting minutes that discuss security risk, specific questions put to the security function, and decisions that can be traced back to that input.
Sep 16, 2026 · via natlawreview.com
In Huntsville, Alabama, home to one of the nation's largest cybersecurity hubs, educators and industry professionals are rethinking what cybersecurity education can look like.
At the Madison County Schools Career Technical Center, cybersecurity instructor Kala Jo Grice-Dobbins is showing what that looks like in practice.
Working alongside industry professionals, she is creating a classroom where students learn not only technical skills, but also how cybersecurity professionals think, collaborate and solve problems.
For Grice-Dobbins, participating in the Accelerator became an opportunity to deepen those partnerships and rethink how students experience cybersecurity in the classroom.
Seeing a Future in Cybersecurity Jaxton first discovered cybersecurity during a freshman visit to the Madison County Career Technical Center.
Sep 16, 2026 · via edsurge.com