NetSPI and Synack have entered into a definitive agreement to merge, creating a combined offensive cybersecurity company with more than $200 million in revenue and a platform that pairs expert security testing with agentic AI. The transaction will bring together NetSPI’s penetration testing capabilities with Synack’s continuous security validation platform and network of vetted security researchers. The combined company will serve a customer base that includes major cloud providers, leading U.S. banks, MAMAA companies, Fortune 100 enterprises and U.S. federal agencies. NetSPI and Synack bring nearly 40 years of combined operating history and more than 13 million hours of real-world offensive security testing experience. The companies are positioning the combination around a hybrid model that uses AI to accelerate security testing while continuing to rely on human expertise for areas requiring judgment, context and an understanding of attacker behavior. The combined platform will offer continuous security testing and validation across enterprise attack surfaces, with AI supporting areas such as vulnerability discovery, analysis and validation. Customers are also expected to gain access to a broader bench of offensive security professionals, expanded service offerings, greater operational scale and additional delivery models. KKR will support the combined company’s growth strategy, including investments in technology and product development, expansion of its offensive security talent base and further international growth. The companies said existing customer relationships and service models will continue through the integration, with broader capabilities becoming available over time. The merger is expected to close in October 2026, subject to regulatory approvals and customary closing conditions. Piper Sandler is serving as financial advisor to Synack, with Latham & Watkins serving as legal counsel. Gibson Dunn & Crutcher is serving as legal advisor to KKR and NetSPI. KEY QUOTES: “AI is transforming security testing, but it’s still experts who find the vulnerabilities that lead
Sep 3, 2026 · via pulse2.com
Consumer Alert: Data breach compromises 153M drivers’ licenses. Here’s what you should do ROCHESTER, N.Y. — A massive data breach at an identity verification company may have exposed the driver’s licenses and personal information of more than 153 million Americans and Canadians. A journalist who covers cybersecurity, Brian Krebs, discovered his driver’s license was being sold on the dark web. Thieves also claimed to have the driver’s license of Secretary of War Pete Hegseth, high-ranking officials and tens of millions of regular people. The stolen information is believed to have come from hacking ID Scan.net, also known as Veriscan. According to its website, the company is used for ID fraud prevention by more than 7,500 businesses worldwide. The company did not verify the hacking, only confirming to Krebs that it was investigating. “The type of data that’s been exposed here is really serious. More than 153 million drivers’ licenses, more than 10 million ID cards, 3 million travel documents and 500,000 medical cards including dispensary cards,” said Jared Connors, an attorney with the firm Meyer Wilson Werning that specializes in representing cybersecurity victims. Some of the businesses that use Veriscan include car rental companies, hotels, retailers, dispensaries and banks. The company’s website says it has verified more than 40,000 scans from banks from December 2024 to the present. Much or all of that information could now be in the hands of thieves who sell it on the dark web to the highest bidder. With a copy of your license, thieves now have your name, address, birth date, driver’s license number, picture and the document number on the back of the card used by state agencies to verify if your license is real. “The most immediate concern is that you’re at risk of identity theft,” Connors said. Thieves can use that
Sep 3, 2026 · via whec.com
International Women in Cyber Day highlights the systemic underrepresentation of women in cybersecurity, a critical issue as AI-driven threats become more sophisticated and originate from unexpected sources, according to a recent report by Arn Net.In Australia, women constitute only 17% of the cybersecurity workforce, with many leaving the industry within four years due to cultural, societal, and organizational barriers. Experts emphasize that diversity in cybersecurity is not merely a metric but a necessity for developing robust approaches to risk and threat mitigation. The evolving landscape, amplified by AI, necessitates a broader range of perspectives to identify blind spots and counter increasingly complex attacks.While flexible work arrangements have improved job satisfaction and retention for women, structural inclusion remains a challenge. The increasing use of AI by attackers requires more brainpower and diverse viewpoints to defend networks effectively. Mentorship and visible female role models are vital for encouraging women to enter and remain in the field, ensuring their essential voices shape the industry's future and enhance its innovation, strength, and resilience.Source: Arn Net
Sep 3, 2026 · via msspalert.com
Krishnamoorthi Blasts Trump Cybersecurity Cuts as Experts Warn of “Shockingly Poor” Defenses Intelligence Committee hearing also examined growing threats to U.S. critical infrastructure and Russian aggression against the Baltics WASHINGTON — Congressman Raja Krishnamoorthi (D-IL) today blasted Trump Administration cuts to the Cybersecurity and Infrastructure Security Agency, the federal government’s lead cybersecurity agency, as national security experts warned that defenses protecting critical infrastructure in communities across the country remain dangerously weak. During a House Permanent Select Committee on Intelligence hearing, Dr. Seth Jones confirmed his assessment that some U.S. cyber defenses, particularly among municipalities, are “shockingly poor.” Krishnamoorthi pointed to reports of cyberattacks on water systems across at least 12 states this summer before noting that the Trump Administration cut CISA’s workforce by nearly one-third last year. Krishnamoorthi called for strengthening the agency as threats to critical infrastructure grow, rather than cutting its capacity. “There is no question that with the end of the Cold War and then the terrorism focus of the last quarter century, our counterintelligence architecture deserves a hard look to make sure the government is connecting the dots in our new era of strategic competition. On a bipartisan basis, we have worked with the majority as they focused on this issue, and this open hearing will help advance the goal of an aggressive but measured approach to improving what exists,” Krishnamoorthi said. Krishnamoorthi also pressed witnesses on growing Russian threats to the Baltics as rapidly evolving drone technology creates new challenges for protecting military and civilian infrastructure. He cited witness David Feith’s testimony that direct threats to critical infrastructure, particularly from drones, “have matured with astonishing speed over the last five years,” and pressed witnesses on what more can be done now to deter a Russian attack on the Baltics. Witnesses described the increasing use of
Sep 3, 2026 · via krishnamoorthi.house.gov
State Supreme Court data exposed in cybersecurity breach The New Hampshire Supreme Court says some of its case data was exposed in a cybersecurity breach. The Judicial Branch said names and cases from 2002 to 2015 were accessed by an unauthorized party back in March. The party got access to C-Track, the software used by the state Supreme Court to manage its cases. The breach was discovered a month later. The Judicial Branch says the case information has not been made public. The Branch also says there is no evidence that sensitive information like Social Security numbers was exposed. C-Track issued the following statement: C-Track recently discovered the unauthorized acquisition of certain information by a third party. Immediately after discovering this, C-Track took steps to contain the activity and secure the environment. As part of its cybersecurity incident response protocols, C-Track promptly engaged third-party cybersecurity experts and notified law enforcement. Affected customers have been notified as appropriate. There has been no operational disruption to C-Track as a result of this incident. Our products and services remain fully operational and are safe to continue to use. Independent cybersecurity experts assisted in the investigation and validated the remediation measures implemented. C-Track is actively engaging with the limited number of affected courts and providing support throughout this process. Complementary credit monitoring will be provided to affected individuals. The Judicial Branch said the Superior and Circuit Courts were not affected, as they do not use C-Track.
Sep 3, 2026 · via wmur.com
Rachel Feltman: For Scientific American’s Science Quickly, I’m Rachel Feltman. Last month we talked briefly about how and why cyberattackers are targeting municipal water utilities throughout the United States. Today we’re taking a closer look at that story—why we’re so vulnerable to these attacks but also how volunteer hackers are working to protect our access to clean, safe water. Our guest today is Eric Geller, a senior reporter at Cybersecurity Dive, who focuses on federal cybersecurity policy and critical infrastructure protection. On supporting science journalism If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today. Feltman: Thanks so much for coming on to chat with us today. Eric Geller: Thanks for having me. Feltman: So I wanna start with a very basic question. When we talk about cyberattacks, what is it we’re actually talking about? What’s under that umbrella? Geller: Well, it’s a wide range of things. It can be everything from guessing somebody’s password or tricking them into handing it over and then just logging in like a real authorized user and messing with the computer system. Or it can be essentially fooling the computer system itself, taking advantage of a vulnerability in the software to get access to something that you shouldn’t be able to access. And then you can, sort of, layer on top of that the supply chain aspect, which is: all these companies are interrelated. So if you can get into one company, you might be able to then jump from there into another company’s systems, either by, again, pretending to be an employee of that first company or by taking advantage of actual connections between the computer systems and
Sep 3, 2026 · via scientificamerican.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Sep 3, 2026 · via youtube.com
Large organizations are spending millions of dollars on cybersecurity, yet they continue to rank among the most attractive targets for cyber-criminals. A recent study from cybersecurity firm Huntress highlights a troubling paradox: the organizations investing heavily in cybersecurity are also among those most likely to report experiencing cyberattacks. The financial sector stands out. According to Huntress, 51% of respondents working in banking and financial services said their firm had experienced a breach, compared with 39% of respondents in healthcare. The finding underscores why banks remain high-value targets: they hold vast quantities of financial information, personally identifiable information (PII), credentials and other sensitive data that can be monetized by threat actors. The same research reveals a correlation between cybersecurity spending and attack exposure. Fifty-four percent of respondents at organizations with cybersecurity budgets of $10 million or more said they had experienced an attack, compared with 44% among organizations with smaller security budgets. This does not necessarily mean that larger cybersecurity budgets make organizations more vulnerable. Rather, large enterprises tend to possess more valuable data, larger digital footprints and more complex IT environments—making them attractive targets for ransomware groups, cyber criminals and other threat actors. Healthcare faces a different kind of risk Healthcare remains another major target because of the sensitivity and immediacy of the information it stores. Patient records, medical histories, insurance information, payment details and personally identifiable information can all be exploited for financial gain or fraud. Huntress has separately identified healthcare as a major target in its threat research. Its 2025 healthcare threat report found that healthcare accounted for 17% of all cyberattacks tracked by Huntress in 2024, with attackers targeting everything from small clinics to large hospital networks. The consequences of a successful healthcare attack can extend well beyond data theft. Ransomware can disrupt electronic health records, medical
Sep 3, 2026 · via cybersecurity-insiders.com
SUN | Luminis Health facilities dealing with a cyberattack
ANNE ARUNDEL COUNTY, MD (WBFF) — Luminis Health is experiencing a cybersecurity incident affecting certain systems across its organization, according to a Facebook post Tuesday.
“Our priority remains providing safe, high-quality care to our patients,” the health system said in the post that went up around 6:45 p.m. “We understand the concern this may cause for our patients, families and community, and we appreciate your patience and understanding.”
The health system’s online portal was down as of 7:30 p.m. Tuesday.
Luminis Health operates facilities primarily in central Maryland and on the Eastern Shore. Its two main hospitals are Luminis Health Anne Arundel Medical Center in Annapolis and Luminis Health Doctors Community Medical Center in Lanham in Prince George’s County.
Read the full story on the Baltimore Sun.
Sep 3, 2026 · via foxbaltimore.com
'We need a national cybersecurity law,' says TU alumna and CEO focused on virtual risks Sep 2, 2026 Sep 2, 2026 Updated 6 hrs ago 0 Jody Westby, CEO of Washington, D.C.-based Global Cyber Risk LLC, speaks Wednesday at the Rotary Club of Tulsa's regular meeting. Michael Dekker Michael Dekker Tulsa World Business Reporter Author facebook Author twitter Author email Follow Michael Dekker Prefer us on Google Learn More Facebook Twitter Bluesky WhatsApp SMS Email Print Copy article link Save Michael Dekker A cybersecurity expert, Forbes blogger, University of Tulsa alumna and Georgetown University law school graduate said many company leaders don't understand artificial intelligence tools.kAmQ%96C6 2C6 D@ >2?J 4@>A2?:6D FD:?8 px[ 3FE E96J 5@?VE C62==J 92G6 2 DEC2E68J 7@C :E[Q D2:5 k2 9C67lQ9EEADi^^HHH]8=@32=4J36CC:D<]4@>^@FC\E62>^;@5J\H6DE3J^Q E2C86ElQ03=2?<Qmy@5J (6DE3Jk^2m[ rt~ @7 (2D9:?8E@?[ s]r]\32D65 k2 9C67lQ9EEADi^^HHH]8=@32=4J36CC:D<]4@>^Q E2C86ElQ03=2?<Qmv=@32= rJ36C #:D< {{rk^2m]k^AmkAmQp =@E @7 4@>A2?:6D 5@?VE F?56CDE2?5 Vw@H 5@6D px 4C62E6 E9:D H:=5 H6DE 2E>@DA96C6nVQ k^Am kAm$96 DA@<6 (65?6D52J 2E E96 k2 9C67lQ9EEADi^^EF=D2C@E2CJ]4@>^Q E2C86ElQ03=2?<Qm#@E2CJ r=F3 @7 %F=D2k^2m 2?5 2=D@ :? 2? 6I4=FD:G6 :?E6CG:6H H:E9 E96 %F=D2 (@C=5 @? %F6D52J]k^Am People are also reading… Sand Springs business where explosion occurred had been told to cease operations 5 things to know as Cox becomes Spectrum after Charter acquisition Trump Justice Department intervenes in Inola smelter lawsuit Bill Haisten: Jenks’ Cotton Bowl experience – a 27-0 lead and a stunning loss Tulsa man faces murder charges after explosion at Sand Springs business Update: Tulsa towing company owners killed in argument; alleged shooter arrested 'Final encore' event punctuating Peter Mayo's decades-long ownership of Tulsa Theater 4 things to know after Bixby outlasts Owasso in season-opening showdown Donor-funded scholarships help students realize their college dreams OSSAA announces 7 changes on student eligibility rules AG's Office says Stitt can't call for constitutional convention vote Petition on high electricity bills gets attention: 'We've
Sep 3, 2026 · via tulsaworld.com
Utility executives and cybersecurity experts warn Pa. lawmakers of growing threats As grid infrastructure increasingly relies on internet connections to function, bad actors’ tools have become more sophisticated. Power lines cross a field in Snyder County, Pennsylvania. (Photo by Peter Hall/Pennsylvania Capital-Star) In the past year, FirstEnergy Pennsylvania has seen a growing number of attempted malware and cyberattacks around their critical infrastructure. “Our defensive systems block tens of thousands of automated malicious connection attempts against public facing services each month,” said Brian Harrell, the chief security officer at the company that serves 2.1 million electric customers across 56 counties in Pennsylvania. “These statistics underscore why cybersecurity requires constant attention and continual enhancement.” He was speaking to a panel of Pennsylvania House members about the increased cybersecurity threats utilities across the state are facing. In the last few years, criminal and state-sponsored actors have increasingly targeted critical infrastructure across America and Europe. And as utilities and grid infrastructure increasingly rely on internet connections to function, bad actors’ tools have become more sophisticated. “They’re seeking to manipulate, disrupt or disable the very control systems that provide light, heat and clean water for our communities,” said Rep. Pat Gallagher (D-Philadelphia), chair of the House Consumer Protection, Technology and Utilities Committee’s subcommittee on utilities. “Protecting our public utilities requires a unified front, one that bridges private operators, public regulators, state agencies and both political parties.” Utility executives and cybersecurity experts agreed that, at this point, investments in cybersecurity have become nearly as necessary as spending on infrastructures. But they warned lawmakers they come at a cost to ratepayers, and asked for any new regulations or requirements to take that into account. “These investments are necessary, but cybersecurity now competes for the same limited resources needed for pipes, pumps and capital improvements,” said Craig Fahnestock,
Sep 2, 2026 · via penncapital-star.com
Search, find and engage with others who are serious about tech and business.
Follow and be a part of discussions about tech, finance and media.
Premium advertising opportunities for brands
Team access to our exclusive tech news
Journalists who break and shape the news, in your inbox
Catch up on conversations with global leaders in tech, media and finance
Explore our recent partner collaborations
Premium advertising opportunities for brands
Team access to our exclusive tech news
Explore our recent partner collaborations
Read this briefing for free
Sep 2, 2026 · via theinformation.com
olly - stock.adobe.com AI cybersecurity vs. AI cyberattacks: Who's winning? To stay ahead in the AI vs. AI cybersecurity race, businesses must incorporate the technology into detection, investigation, vulnerability management and response. The emergence of AI and its increasing accessibility have changed the nature of cyber conflict. As both defensive and offensive systems become more autonomous, cybersecurity is rapidly shifting toward an AI-versus-AI context, where success depends on who can make decisions faster to overcome the opposing side. In today's complex threat environment, security teams rely on AI to analyze millions of security events, prioritize alerts and accelerate incident response. However, cybercriminals are now using the same technology to automate reconnaissance, create highly customized phishing messages and develop evasive malware that is difficult to detect. For CISOs and other security leaders, this shift represents more than a technology trend. While AI offers numerous ways to enhance security operations, it also expands the attack surface. It makes enterprises vulnerable to various cyberattacks, enabled by attackers' ability to execute them at high speed and scale. This means enterprises must evaluate AI from two different sides: as an important capability that strengthens cyber defenses and as a risk factor that changes how cyberattacks are planned and executed. The AI vs. AI cybersecurity arms race The growing use of AI for both defense and attack introduces an important question: Who holds the strategic advantage? The answer is not straightforward. On the offensive side, AI's force multiplier is evident. Human capabilities no longer constrain attackers; they use AI to automate the collection of vast volumes of data from various public sources, automate reconnaissance, analyze large volumes of scan results and prioritize vulnerable systems at a scale that would be difficult to achieve manually. AI can also create personalized phishing messages and deepfakes to impersonate other
Sep 2, 2026 · via techtarget.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Sep 2, 2026 · via youtube.com
Palo Alto Networks Acquires Console to Agentify Security Transforming how customers benefit from agentic-driven workflows that are purpose-built for the AI era As AI reshapes the threat landscape, organizations need a security platform that can operate with speed, context, and operational discipline. Console will help advance this vision by deepening our agentic capabilities in Cortex®, supporting teams as they investigate signals, prioritize work, and take action across their environment. "Security operations can no longer be about managing dashboards and queuing tickets just to help humans work faster. By bringing Console into "We built Console around a simple idea: people should be able to express an operational goal, and intelligent software should handle the complexity required to achieve it. Our customers have already proven that agents can dramatically slash overhead and transform their business. Joining Follow About Palo Alto Networks Palo Alto Networks (NASDAQ: PANW), the global AI cybersecurity leader, protects our digital way of life with a comprehensive portfolio of cybersecurity solutions and platforms across Network, Cloud, Security Operations, AI and Identity. Trusted by 70,000+ customers and powered by Unit 42 threat intelligence, our AI-driven platforms eliminate complexity, empowering enterprises to modernize with confidence and securing the speed of innovation. Explore the future of security at www.paloaltonetworks.com. Palo Alto Networks and the Palo Alto Networks logo are trademarks of Palo Alto Networks, Inc. in the United States and in jurisdictions throughout the world. All other trademarks, trade names, or service marks used or mentioned herein belong to their respective owners. Any unreleased services or features (and any services or features not generally available to customers) referenced in this or other press releases or public statements are not currently available (or are not yet generally available to customers) and may not be delivered when expected or at all. Customers who purchase
Sep 2, 2026 · via investors.paloaltonetworks.com
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the malware strains under the names NodeRabbit and PollCat. The first sample of NodeRabbit was discovered on a system in Afghanistan, with subsequent sightings on two distinct machines located in Egypt and Ethiopia. "Its operators deliver [NodeRabbit] through spear-phishing messages on LinkedIn and other job search platforms that contain trojanized coding challenge archives," Kaspersky security researcher Omar Amin said. "Like NodeRabbit, PollCat is a cross-platform RAT, but it is written in obfuscated JavaScript also distributed through trojanized coding challenge archives." While Nimbus Manticore has historically employed malware written in C, C++, and Go, and relied on DLL search-order hijacking techniques to deploy them, the latest findings mark the threat actor's foray into cross-platform tools to accomplish its goals. The development also comes amid a rapid expansion of the hacking group's malware arsenal in recent months, including - - A Windows backdoor called NightLedger - Two custom WebSocket tunnelers, BridgeHead and ArcBridge - A reverse SSH tunneling tool - A backdoor that shares overlaps with TWOSTROKE The starting point of the suspicious activity observed in the Afghanistan-based system starts with a ZIP file ("Front-Technical-Challenge.zip") hosted on AWS that's assessed to have been delivered as part of a job opportunity for an engineering role. The threat actor is said to have masqueraded as a talent acquisition specialist at a major technology company to approach a software engineer and invited them to complete a technical assignment. It's worth noting that Nimbus Manticore is also tracked under the moniker Iranian Dream
Sep 2, 2026 · via thehackernews.com
BOSTON, Sept. 1, 2026 /PRNewswire/ -- Apiphani, a premier Managed Intelligence Provider (MIP), offering measurable business outcomes to companies running complex, mission-critical SAP environments, today announced it has achieved Cybersecurity Maturity Model Certification (CMMC) Level 2. Apiphani achieved a perfect assessment outcome, concluding the process with no outstanding remediation. The certification validates apiphani's cybersecurity practices against the rigorous standards established by the U.S. Department of Defense and demonstrates the company's longstanding commitment to protecting sensitive information and supporting customers operating in regulated industries. CMMC Level 2 requires organizations to implement and maintain 110 security controls aligned with the National Institute of Standards and Technology (NIST) SP 800-171 framework. Through an independent assessment of its systems, processes, documentation and security practices, apiphani successfully demonstrated compliance with all 110 controls, reinforcing its ability to support customers across aerospace, defense, law enforcement and other regulated industries while helping them meet increasingly stringent cybersecurity requirements. While CMMC Level 2 often takes organizations one to two years to achieve, apiphani completed the process in just seven months, reflecting both the company's strong security foundation and the extent to which it was already embedded across its people, processes and technology. "Security isn't something we add to our services or treat as a compliance exercise," said Justin Folkers, co-founder and CEO of apiphani. "It's foundational to how we build, operate and support the mission-critical systems our customers rely on every day. CMMC Level 2 is independent confirmation of the standards we've held ourselves to for years and strengthens our ability to help customers navigate an increasingly demanding security landscape." As threats and compliance requirements evolve, apiphani will continue to build on CMMC Level 2 as a baseline for its broader security program, strengthening its ability to protect mission-critical environments. This achievement adds to apiphani's existing compliance portfolio,
Sep 2, 2026 · via prnewswire.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Sep 1, 2026 · via youtube.com
Congress is kicking the can down the road again on a long term debate over reauthorizing the Cybersecurity Information Sharing Act of 2015. The continuing resolution passed by the House on Tuesday would extend CISA 2015 through the stopgap funding period into early December. The Senate has already passed the measure, meaning it now heads to President Donald Trump’s desk. There has been a persistent chorus of voices in industry calling on Congress to find a long-term solution to re-authorizing CISA 2015. Those calls have only grown louder amid advancements in artificial intelligence models and recent cyber attacks on critical infrastructure. The 2015 law provides privacy and liability protections to encourage companies to share data about cyber vulnerabilities and threats with government and each other. The information sharing law briefly lapsed during last fall’s shutdown and again earlier this year before being extended through Sept. 30. Groups continue to call on lawmakers to advance a long-term reauthorization bill. Senate Homeland Security and Governmental Affairs Committee Chairman Rand Paul (R-Ky.) has been a roadblock to otherwise bipartisan efforts, as he seeks to address free speech concerns as part of the reauthorization. In late July, the Operational Technology Cybersecurity Coalition issued a statement highlighting CISA 2015 reauthorization following cyber attacks on water and wastewater systems across multiple states. “This information allows the U.S. government to identify widespread, large scale cyber campaigns and trends across sectors,” OTCC Executive Director Tatyana Bolton said in the July 31 statement. “It also enables [the Cybersecurity and Infrastructure Security Agency] and the FBI to warn other potential victims before they are potentially impacted.” “We can no longer keep doing minor extensions of CISA 2015,” Bolton added. “We must have long-term authority to keep CISA 2015 operational to further enable the foundation of public-private partnership that allows us
Sep 1, 2026 · via federalnewsnetwork.com
“We’re at an inflection point in cybersecurity,” Jensen Huang told a sold-out crowd at CrowdStrike’s Fal.Con 2026 in Las Vegas Tuesday. Attacks are now automated. Defense has to be, too. The NVIDIA founder and CEO joined CrowdStrike CEO and founder George Kurtz to announce CrowdStrike SafeMind, its agentic cybersecurity system developed by the CrowdStrike Cyber Superintelligence Lab. “This is the beginning of a new age of cybersecurity,” Huang told the crowd of 10,000 security professionals. “On the one hand, the adversaries are going to be more armed than ever. On the other hand, all of you are going to be more armed than ever.” SafeMind combines CrowdStrike’s purpose-built, beyond frontier-capable models and customized agentic harnesses, with defensive models built on NVIDIA Nemotron, in a continuous coevolution loop where offense and defense repeatedly challenge and improve each other. CrowdStrike also announced CrowdStrike Falcon IQ to operationalize Project QuiltWorks through agentic workload automation and expanded its CrowdStrike Guardian AI safety solution. “We have asymmetric advantages because we have a large community of cybersecurity experts who want to work with each other and keep the world safe,” Huang told the crowd. CrowdStrike’s annual conference drew security leaders from financial services, healthcare, the public sector and critical infrastructure. “The real gap that I saw was that the attackers had frontier AI, and the defenders didn’t,” Kurtz told them. “And that changes now.” SafeMind CrowdStrike built SafeMind’s defensive model using NVIDIA Nemotron open models, post-trained with CrowdStrike’s cyber experience and threat data. The SafeMind models are paired with proprietary cybersecurity harnesses optimized to work as an agentic stack. The result ships natively in the CrowdStrike Falcon platform as SafeMind, CrowdStrike’s agentic cybersecurity system. SafeMind brings offensive and defensive AI together in a continuous coevolution loop, where each side adapts to and strengthens the other. This
Sep 1, 2026 · via blogs.nvidia.com