No-frills tech news

American Homes 4 Rent Class A (AMH) vs First Trust NASDAQ <b>Cybersecurity</b> ETF (CIBR)

Price movement over the last 24 hours American Homes 4 Rent Class A vs First Trust NASDAQ Cybersecurity ETF — how do they compare? American Homes 4 Rent Class A trades at $33.27 (market cap $11.97B), while First Trust NASDAQ Cybersecurity ETF trades at $91.88. The key difference: American Homes 4 Rent Class A pays a 3.97% dividend while First Trust NASDAQ Cybersecurity ETF pays none, and First Trust NASDAQ Cybersecurity ETF is trading nearer its 52-week high, American Homes 4 Rent Class A nearer its low. Which is the better fit depends on your goals. | AMH | CIBR | | |---|---|---| | Market Cap | $11.97B | — | | Sector | Real Estate | — | | 52-Week High | $36.74 | $94.32 | | 52-Week Low | $27.38 | $60.74 | | Enterprise Value | $17.05B | — | | Dividend Yield | 3.97% | — | Trailing returns across standard periods Latest headlines on both assets American Homes 4 Rent is a real estate investment trust primarily focused on acquiring, operating, and leasing single-family homes as rental properties throughout the United States. The company's real estate portfolio is largely comprised of single-family properties in urban markets in the Southern and Midwestern regions of the U.S. American Homes 4 Rent's land holdings also represent a sizable percentage of its total assets in terms of value. The company derives the vast majority of its income in the form of rental revenue from single-family properties through short-term or annual leases. The firm's largest geographical markets include Dallas, Texas Read more on AMH →The fund will normally invest at least 90% of its net assets (including investment borrowings) in the common stocks and depositary receipts that comprise the index. The index includes securities of companies classified as cyber security

Amphastar Pharmaceuticals Inc (AMPH) vs First Trust NASDAQ <b>Cybersecurity</b> ETF (CIBR)

Price movement over the last 24 hours Amphastar Pharmaceuticals Inc vs First Trust NASDAQ Cybersecurity ETF — how do they compare? Amphastar Pharmaceuticals Inc trades at $18.72 (market cap $826.08M), while First Trust NASDAQ Cybersecurity ETF trades at $91.88. The key difference: First Trust NASDAQ Cybersecurity ETF is trading nearer its 52-week high, Amphastar Pharmaceuticals Inc nearer its low. Which is the better fit depends on your goals. | AMPH | CIBR | | |---|---|---| | Market Cap | $826.08M | — | | Sector | Health | — | | 52-Week High | $30.81 | $94.32 | | 52-Week Low | $16.87 | $60.74 | | Enterprise Value | $1.22B | — | Trailing returns across standard periods Amphastar is a specialty pharmaceutical company that develops and markets injectable, intranasal, and inhalation products. Its portfolio includes both complex generic drugs and proprietary delivery systems. Read more on AMPH →The fund will normally invest at least 90% of its net assets (including investment borrowings) in the common stocks and depositary receipts that comprise the index. The index includes securities of companies classified as cyber security companies. The fund is non-diversified. Read more on CIBR →

CrowdStrike Just Completed a Stock Split. Is the Stock a Buy Now? | The Motley Fool

CrowdStrike Holdings (CRWD 5.85%) has been a winner for investors in recent years -- over the past three, it's soared more than 400%. This is as the cybersecurity giant has increased revenue and benefited from renewed interest in keeping systems, networks, and data safe. In a world where artificial intelligence (AI) is more regularly used, threats are multiplying, and customers are turning to CrowdStrike for protection. The company also demonstrated its strength and the fidelity of its customers by facing an enormous challenge two years ago -- the world's biggest information technology outage -- and going on to grow. CrowdStrike recently announced record new annual recurring revenue and record free cash flow. So it's no surprise that CrowdStrike stock continued its gains into this year and now is up 69% for 2026. With a stock price trading at more than $700 just a few months ago, the company announced a stock split -- a move to bring down the per-share price -- and completed the operation at the start of this month. At the new, lower price, is CrowdStrike a buy? Let's find out. What's a stock split? First, a quick note about stock splits. While they do bring the per-share price down, they don't alter the total value of the company or anything fundamental. The purpose is to make a particular stock more accessible to a wider range of investors -- those who may not have several hundred dollars or a thousand dollars to invest. Fractional shares exist, but they aren't available at every brokerage, so they may not be an option for some investors. A stock split involves offering more shares of a particular stock to current shareholders. This brings down the value of each share, but the value of the shareholder's entire holding remains the same. The

VIEWPOINT | South Dakota's next great economic opportunity is national defense

VIEWPOINT | South Dakota’s next great economic opportunity is national defense Guest column by Glen Herrick South Dakota has always answered the nation’s call to serve. From generations of servicemembers who have worn our nation’s uniform to the strategic importance of Ellsworth Air Force Base, our state has earned a reputation as a trusted partner in America’s national defense. That legacy is something every South Dakotan can take pride in. Today, South Dakota has an opportunity to build on that legacy in a new way, not only by supporting America’s military but by becoming one of the nation’s leading centers for defense innovation and advanced manufacturing. That opportunity is too important to ignore. The nature of national defense is changing rapidly. America’s military advantage will increasingly depend not only on aircraft, ships and armored vehicles but also on artificial intelligence, cybersecurity, autonomous systems, advanced manufacturing, resilient supply chains and commercial innovation. The defense industrial base that supports our warfighters is evolving, and states that prepare today will help shape its future.

Compare Allstate Corp (ALL) vs First Trust NASDAQ <b>Cybersecurity</b> ETF (CIBR) Price &amp; Performance

Price movement over the last 24 hours Allstate Corp vs First Trust NASDAQ Cybersecurity ETF — how do they compare? Allstate Corp trades at $251.61 (market cap $64.77B), while First Trust NASDAQ Cybersecurity ETF trades at $91.88. The key difference: Allstate Corp pays a 1.72% dividend while First Trust NASDAQ Cybersecurity ETF pays none. Which is the better fit depends on your goals. | ALL | CIBR | | |---|---|---| | Market Cap | $64.77B | — | | Sector | Financials | — | | 52-Week High | $251.61 | $94.32 | | 52-Week Low | $190.00 | $60.74 | | Enterprise Value | $73.56B | — | | Dividend Yield | 1.72% | — | Trailing returns across standard periods Latest headlines on both assets On the basis of premium sales, Allstate is one of the largest U.S. property and casualty insurers. Personal auto represents the largest percentage of revenue, but the company offers homeowners insurance and other insurance products. Allstate products are sold in North America primarily by about 10,000 agencies. Read more on ALL →The fund will normally invest at least 90% of its net assets (including investment borrowings) in the common stocks and depositary receipts that comprise the index. The index includes securities of companies classified as cyber security companies. The fund is non-diversified. Read more on CIBR →

Compare Agilysys Inc (AGYS) vs Global X <b>Cybersecurity</b> (BUG) Price &amp; Performance

Price movement over the last 24 hours Agilysys Inc vs Global X Cybersecurity — how do they compare? Agilysys Inc trades at $108.98 (market cap $3.07B), while Global X Cybersecurity trades at $39.37. The key difference: Global X Cybersecurity is trading nearer its 52-week high, Agilysys Inc nearer its low. Which is the better fit depends on your goals. | AGYS | BUG | | |---|---|---| | Market Cap | $3.07B | — | | Sector | Technology | Sector/Thematic | | 52-Week High | $141.12 | $40.85 | | 52-Week Low | $62.19 | $23.30 | | Enterprise Value | $2.97B | — | Trailing returns across standard periods Agilysys provides enterprise software and SaaS solutions for the hospitality industry. Its products specialize in point-of-sale, property management, and inventory systems for hotels, resorts, and cruise lines. Read more on AGYS →BUG is a thematic ETF that invests in companies at the forefront of the global cybersecurity industry. It provides concentrated exposure to leaders in network security, endpoint protection, and cloud security, such as Fortinet, Akamai, and CrowdStrike. Read more on BUG →

Ally Financial Inc (ALLY) vs First Trust NASDAQ <b>Cybersecurity</b> ETF (CIBR)

Price movement over the last 24 hours Ally Financial Inc vs First Trust NASDAQ Cybersecurity ETF — how do they compare? Ally Financial Inc trades at $45.59 (market cap $13.97B), while First Trust NASDAQ Cybersecurity ETF trades at $91.88. The key difference: Ally Financial Inc pays a 2.63% dividend while First Trust NASDAQ Cybersecurity ETF pays none. Which is the better fit depends on your goals. | ALLY | CIBR | | |---|---|---| | Market Cap | $13.97B | — | | Sector | Financials | — | | 52-Week High | $47.25 | $94.32 | | 52-Week Low | $35.96 | $60.74 | | Dividend Yield | 2.63% | — | Trailing returns across standard periods Ally Financial Inc is a diversified financial services firm that services automotive dealers and their retail customers. The company operates as a financial holding company and a bank holding company. Its banking subsidiary, Ally Bank, caters to the direct banking market through Internet, mobile, and mail. The company reports four business segments including Automotive Finance operations, Insurance operations, Mortgage Finance operations and Corporate Finance operations. Read more on ALLY →The fund will normally invest at least 90% of its net assets (including investment borrowings) in the common stocks and depositary receipts that comprise the index. The index includes securities of companies classified as cyber security companies. The fund is non-diversified. Read more on CIBR →

Compare C3.ai Inc (AI) vs Amplify <b>Cybersecurity</b> ETF (HACK) Price &amp; Performance

Price movement over the last 24 hours C3.ai Inc vs Amplify Cybersecurity ETF — how do they compare? C3.ai Inc trades at $8.95 (market cap $1.39B), while Amplify Cybersecurity ETF trades at $108.98. The key difference: Amplify Cybersecurity ETF is trading nearer its 52-week high, C3.ai Inc nearer its low. Which is the better fit depends on your goals. | AI | HACK | | |---|---|---| | Market Cap | $1.39B | — | | Sector | Technology | Sector/Thematic | | 52-Week High | $29.16 | $111.88 | | 52-Week Low | $7.76 | $70.69 | | Enterprise Value | $821.40M | — | Trailing returns across standard periods Latest headlines on both assets C3.ai Inc is an enterprise artificial intelligence company. The company provides software-as-a-service applications that enable customers to rapidly develop, deploy, and operate large-scale Enterprise AI applications across any infrastructure. It provides solutions under three divisions namely, The C3 AI Suite, is a comprehensive application development and runtime environment that is designed to allow customers to rapidly design, develop, and deploy Enterprise AI applications of any type Read more on AI →HACK provides diversified exposure to the global cybersecurity industry. It invests across the full value chain, including hardware, software, and consulting services, with key holdings in firms like Broadcom, Cisco, and Palo Alto Networks. Read more on HACK →

Hardware-Aware Security: The Next <b>Cybersecurity</b> Imperative

Cybersecurity strategy must evolve beyond CPU-centric models to counter GPU-accelerated attacks. Traditional tools like EDR and SIEM miss activity inside GPU memory entirely, creating dangerous blind spots that sophisticated attackers are actively exploiting. Closing this gap requires deploying Data Processing Units (DPUs) — such as NVIDIA BlueField — to run security analytics out-of-band, independent of the host system. Hardware-enforced confidential computing further isolates AI workloads, blocking side-channel attacks and memory manipulation techniques. Human response times are no match for autonomous, GPU-powered threats. Agentic SOAR platforms must autonomously quarantine compromised assets within milliseconds, while behavioural detection monitors API patterns and math-cluster loads rather than relying on static file signatures that GPU malware easily mutates around. Authentication infrastructure needs urgent hardening. Post-quantum hashing algorithms like Argon2id deliberately resist massive parallelism, while FIDO2 passkeys and continuous liveness verification defeat GPU-generated deepfakes targeting biometric systems. Finally, Zero-Trust Network Architecture must isolate all high-performance computing clusters behind application-aware firewalls, while UEFI Secure Boot ensures only cryptographically signed drivers execute — eliminating hardware supply-chain entry points before attacks begin. See What’s Next in Tech With the Fast Forward Newsletter Tweets From @varindiamag Nothing to see here - yet When they Tweet, their Tweets will show up here.

Czech-Jordan ties expand across <b>cybersecurity</b>, energy, development — ambassador

AMMAN — Diplomatic relations between Jordan and the Czech Republic have entered a period of significant growth, with cooperation expanding across cybersecurity, renewable energy, trade, development assistance and regional security, Czech Ambassador to Jordan Andrea Kucerova said. Reflecting on her first year in Amman, Kucerova described her experience in Jordan as both professionally rewarding and personally enriching. "I have been received with exceptional warmth and hospitality by the Jordanian people," she said, adding that she and her family have spent weekends travelling across the Kingdom to explore its natural beauty, cultural traditions and historical heritage. Kucerova said the Czech embassy has made substantial progress in strengthening bilateral cooperation. "Our bilateral cooperation has experienced a dynamic surge across defence, cybersecurity, energy, development cooperation, bilateral political ties and other fields," she said. One of the year's major milestones was the inaugural Czech-Jordanian Cybersecurity Forum on Cybercrime Mitigation and Governance, held in November 2025 at the Royal Scientific Society under the patronage of HRH Princess Sumaya Bint El Hassan. According to the ambassador, the forum significantly enhanced cooperation on cyber threat intelligence sharing and digital security while opening the door for Czech technology firms, including Cogniware, Aura and Wultra, to explore partnerships with Jordanian institutions. Kucerova also highlighted growing cooperation with the Public Security Directorate (PSD) describing the relationship as one of the embassy's most promising initiatives. She noted that the director of the PSD's Special Branch visited Prague in February 2026 as part of efforts to deepen security cooperation. Economic diplomacy has also become a central focus of the embassy's work. “Through partnerships with the Amman Chamber of Commerce and EuroCham Jordan, the embassy has facilitated direct engagement between Czech and Jordanian companies to encourage trade and investment.” In June 2026, Czech companies Solarity, ElkoEP and RSE presented advanced technologies in renewable

dti Publishing Corporation Announces NetEmulator® 2.0, the <b>Cybersecurity</b> Edition

NetEmulator 2.0 allows students to understand cybersecurity as a sequence of observable decisions and outcomes rather than as a disconnected set of terms. SALT LAKE CITY, UT, UNITED STATES, July 11, 2026 /EINPresswire.com/ — dti Publishing Corporation today announced NetEmulator® 3.0, a major new release of its browser-based network simulation and skills-development platform. Release 3.0 is called the Cybersecurity Edition because it adds an impressive array of cybersecurity capabilities designed to help students practice the real tasks involved in securing, testing, monitoring, and troubleshooting modern networks. The announcement follows recent recognition from Education Technology Insights, which awarded NetEmulator® the 2026 Innovation in Education Award. In connection with the recognition, Tina Rosen, Managing Editor of Education Technology Insights, said, “By making technical education more accessible, intuitive, and effective, the company is setting a new benchmark for how students develop real-world skills in the digital age.” NetEmulator 3.0 builds on the platform’s core purpose: helping learners develop practical networking skills through hands-on configuration, observation, testing, and validation. With the Cybersecurity Edition, dti Publishing extends that model into firewall configuration, secure access control, attack-surface reduction, vulnerability testing, intrusion detection, logging, and exploit awareness. “Cybersecurity education cannot be limited to definitions, diagrams, and multiple-choice questions,” said Pierre Askmo, founder and CEO of dti Publishing Corporation. “Students need to see what happens when a service is exposed, when a firewall rule is misconfigured, when traffic is denied, when a scan detects open ports, and when a security policy successfully protects a network. NetEmulator 3.0 was created to make those experiences visible, measurable, and teachable.” The Cybersecurity Edition introduces a robust firewall model supporting both stateless and stateful traffic filtering. Learners can create zone-based rules, control traffic between internal networks, DMZ segments, and external networks, and observe how traffic is permitted or denied based on source,

Keysight launches new <b>cybersecurity</b> test platform for AI traffic | brief | SC Media

As reported by SDx Central, Keysight Technologies has introduced a new modular network cybersecurity test platform designed to handle the increasing demands of large data transfers, particularly those associated with artificial intelligence (AI).The APS-ONE-400, part of Keysight's APS-100/400-gigabit Ethernet (GE) hardware line, offers 400 Gb/s Layer 4-7 throughput and 95 Gb/s of elephant flow throughput, addressing the substantial data transfers common in AI applications. The system supports testing for post-quantum cryptography-encrypted traffic and zero trust network access (ZTNA), along with various network speeds including 100/25/10GE. The one rack unit (RU) system can function independently or be integrated with other Keysight APS-100/400GE devices to create large-scale testbeds capable of generating up to 16 Tb/s of Layer 4-7 traffic.Keysight stated the platform is intended for network equipment manufacturers, service providers, and data center operators who need to validate demanding network scenarios without acquiring multiple specialized tools. This release follows Keysight's recent expansion of its 1.6 Tb/s solutions portfolio aimed at validating interconnects for AI-centric data centers.Source: SDx Central Network Security Keysight launches new cybersecurity test platform for AI traffic (Adobe Stock) An In-Depth Guide to Network Security Get essential knowledge and practical strategies to fortify your network security. Related Events Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds

US <b>cybersecurity</b> agency CISA had to build its incident playbook during the incident, agency reveals

U.S. federal cybersecurity agency CISA said it did not have a prepared response plan for how it should handle a cybersecurity incident in May, after an investigative reporter notified the agency that a contractor had publicly exposed sensitive keys and credentials for accessing U.S. government systems. CISA, the Homeland Security unit tasked with defending federal networks and helping to safeguard critical infrastructure, revealed Friday in a postmortem report that its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency said it is important to prepare playbooks for “all anticipated needs” to ensure that organizations are ready to respond in the event of a security incident rather than scrambling to improvise one in real time. The agency did not say how long the missing playbook delayed CISA’s response, and a spokesperson did not immediately respond to TechCrunch’s request for comment. Independent cybersecurity journalist Brian Krebs reported in May that a security researcher with cyber firm GitGuardian alerted him to reams of exposed passwords stored in a publicly accessible GitHub repository, which an employee of a CISA contractor had uploaded. According to Krebs, the researcher tried to alert the contractor but didn’t hear back. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all of the exposed credentials to prevent any potential future abuse. CISA said that no customer or mission data was exposed in the incident and thanked the researcher and reporter for their help. The agency said that its channels for allowing security researchers to notify CISA of potential incidents “were not well defined,” and that it has made changes to make it easier and faster for researchers to contact the agency. CISA has been without a permanent director since the start of President Donald

Securing our future: July 2026 progress report on Microsoft's Secure Future Initiative

Security is never finished. That conviction is where the Secure Future Initiative (SFI) started two years ago and continues to guide us today. AI is reshaping cybersecurity. Cyberattackers can discover vulnerabilities, chain attack paths, and scale exploitation faster than manual approaches allow. Defenders can use the same advances to identify risk, strengthen protections, and accelerate response. As the threat landscape evolves, security must evolve with it. This latest SFI progress report shows how Microsoft is adapting to that reality: strengthening security foundations for an AI-accelerated cyberthreat landscape, applying AI to improve security outcomes at scale, and preparing for future challenges such as scalable quantum computing. This report organizes our progress into three outcome-driven themes—secure foundations, proactive defense, and future-ready security—and shares lessons learned, practical guidance, and deeper insights across the culture, governance, principles, and engineering pillars that underpin security at Microsoft. Secure foundations The most consequential security failures rarely come from a single missing control. They come from environments where identity gaps, unmanaged assets, and inconsistent configurations sit side by side, creating composite attack paths that determined threat actors can chain together. SFI addresses this systemically, strengthening security across our environment. The results show the progress: - Phishing-resistant multifactor authentication now protects 99.97% of user/device pairs at Microsoft. - More than 732,000 resources have had public access revoked, with network isolation scaling across 1 million resources. - 1.4 million unused apps were decommissioned and cross-boundary credential isolation reached 98.7%. - Engineering defaults now prevent 83% of pipelines from accessing unapproved package endpoints. These controls form reinforcing layers: identity feeds access governance, access governance feeds segmentation, segmentation contains blast radius, and engineering defaults reduce what enters production in the first place. One of the lessons we have learned is that foundations are durable only when they’re continuously validated, not periodically audited.

<b>Cybersecurity</b> Negotiator Gets 70 Months for Helping BlackCat Extort Victims

Press play to start listening A former ransomware negotiator who supplied BlackCat ransomware with confidential information from companies seeking help has been sentenced to 70 months in federal prison. Angelo Martino, 41, of Land O’Lakes, Florida, received the sentence on July 9 for conspiring with operators of the ALPHV, also known as the BlackCat ransomware group. US prosecutors said he used his position at a cyber incident response company to help ransomware operators pressure victims into paying higher demands. Court documents show that Martino began working with BlackCat members in April 2023 while employed as a ransomware negotiator. His job gave him access to private discussions about how affected companies planned to respond, including their negotiating positions and payment strategies. Prosecutors said Martino passed that information to the BlackCat group in exchange for payment. The information allowed the ransomware operators to assess how much victims might pay and adjust their demands during negotiations. According to the DOJ’s press release, the scheme impacted five ransomware victims whose cases Martino was supposed to help manage. His access placed him inside confidential negotiations while he was also assisting the criminals demanding payment from those clients. Martino later worked with former cybersecurity professionals Kevin Martin of Texas and Ryan Goldberg of Georgia to deploy BlackCat ransomware against other organisations in the United States between April and November 2023. Martin joined Martino’s workplace after the conspiracy had begun, while Goldberg worked for a separate incident response company. Prosecutors said the three men operated as BlackCat affiliates and carried out ransomware attacks using the group’s malware and extortion platform. One victim paid approximately $1.2 million in Bitcoin following a successful attack. Martino, Martin, and Goldberg divided their share of the payment into three parts and used several methods to launder the proceeds. Hackread.com previously reported that

<b>Cybersecurity</b> in Retail: Threats, Risks, and Defenses | CloudSEK

🚀 CloudSEK becomes first Indian origin cybersecurity company to receive investment from US state fund Read more Cybersecurity in retail is the practice of protecting payment systems, customer data, and the online and in-store channels that retailers depend on from cyberattacks. Few sectors concentrate as much cashable data, from payment cards to customer accounts, across as many systems as retail does. The stakes are rising. Even as global breach costs fell in 2025, retail was among the sectors where they climbed, reaching $3.54 million per breach, according to IBM's 2025 Cost of a Data Breach Report. The threat has shifted too, from quiet card theft toward ransomware that shuts down trading entirely, as the 2025 attacks on Marks & Spencer and other major retailers showed. That’s why it’s essential to know why retailers are targeted, where the omnichannel attack surface is exposed, the threats and breaches that define the risk, the standards that govern retail data, and how retailers can defend. Retailers are targeted because they sit on exactly what criminals want: payment-card data and mass customer records, tied to money that moves every second. Verizon found that 100 percent of retail breaches in 2025 were financially motivated, a clarity of motive few sectors match. High transaction volumes turn each compromised system into a steady source of cards and credentials. Stolen cards and logins move quickly through dark web markets, where buyers turn them into fraud within hours. The retail attack surface keeps expanding as commerce moves online. Stores, e-commerce sites, mobile apps, loyalty programs, and hundreds of third-party scripts each add exposure, and seasonal peaks like Black Friday concentrate both sales and attacks. Because retailers cannot afford downtime during peak buying periods, they face heavy pressure to pay ransoms quickly. The same urgency makes peak periods the favorite window

Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of the bootloader run their own code, before the device has confirmed that the software is genuine. That last part is the point. A bootloader runs before the operating system, so a flaw here can undermine everything that loads after it. All six bugs are reached while U-Boot is still reading an untrusted image, before it has checked the signature. What Binarly found U-Boot can bundle a kernel, device tree, ramdisk, and other boot components into one package, a FIT (Flattened Image Tree), and it checks that package's digital signature before handing over control. Binarly went looking for weak spots in that check and found six. Most of the vulnerable code has been in U-Boot since v2013.07, Binarly says, across more than 50 stable releases, and it also lives in the many vendor firmwares built on top of U-Boot. The bugs are tracked as Binarly advisories BRLY-2026-037 through BRLY-2026-042. No CVE identifiers have been assigned yet. They fall into two groups: two that could run code, and four that only crash. The two are BRLY-2026-037 and BRLY-2026-038, and both trace to one unchecked value. U-Boot calls fdt_get_name, a lookup in the device-tree parsing library it borrows, and on a malformed image, that lookup returns a null pointer and a negative length. U-Boot uses both without checking either. One bug follows the null pointer into a memory copy that, on devices where address zero is mapped, becomes a stack buffer overflow. The other feeds the

False Claims Act Settlement for a Defense Contractor Triggered by

The U.S. Department of Justice (DOJ) has once again reinforced a critical message for the federal contracting community: Cybersecurity compliance is no longer simply a contractual obligation. It is increasingly becoming a False Claims Act enforcement priority that can expose government contractors to significant financial liability. In a recently announced settlement, a defense contractor agreed to pay more than $500,000 to resolve allegations that it knowingly failed to comply with cybersecurity requirements incorporated into contracts with the Department of the Navy while continuing to submit claims for payment. The case serves as yet another reminder that federal agencies and enforcement authorities are actively scrutinizing contractor compliance with cybersecurity obligations, particularly those tied to safeguarding sensitive government information. This latest enforcement action underscores a growing reality for companies operating in the defense industrial base. Cybersecurity failures can now create not only operational and contractual risk, but also substantial exposure under the False Claims Act. The Government’s Cybersecurity Enforcement Focus Continues to Intensify According to the DOJ, the contractor allegedly failed to fully implement required security controls under NIST Special Publication 800-171, the cybersecurity framework that governs how contractors must protect Controlled Unclassified Information (CUI) across nonfederal systems. The alleged compliance failures occurred over a period spanning nearly four years, during which the contractor continued performing under Navy contracts and submitted invoices for payment despite purportedly failing to implement required cybersecurity safeguards. The contractor’s alleged deficiencies were identified during an assessment conducted by the Defense Contract Management Agency, which reportedly issued the contractor an assessment score of negative 170 under the Department of Defense’s cybersecurity scoring methodology. For context, scoring under the assessment framework ranges from negative 203 to positive 110, making a score this low particularly significant from an enforcement perspective. The government alleged that unimplemented security controls created material vulnerabilities

UB trains future AI, <b>cybersecurity</b> and manufacturing workforce

BUFFALO, N.Y. – The University at Buffalo is leading two National Science Foundation (NSF) awards — together totaling $950,000 — to prepare the next generation of the U.S. workforce in artificial intelligence, cybersecurity and advanced manufacturing. Led by Wenyao Xu, PhD, the Carl V. Granger Endowed Chair Professor in UB’s Department of Computer Science and Engineering, the three-year awards build on UB’s strengths in AI and security and unite partners including the University of Georgia (UGA), placing UB at the center of a growing national training enterprise. Hands-on cybersecurity and AI research for undergraduates The first award, a $450,000 Research Experiences for Undergraduates (REU) site grant approved by NSF in May, will deliver intensive summer research training in cybersecurity and AI to 30 undergraduate students — 10 per year over three years — recruited from across the country. People are also reading… Xu serves as principal investigator, with Jun Xia, PhD, professor in the Department of Biomedical Engineering, a joint program of the School of Engineering and Applied Sciences and the Jacobs School of Medicine and Biomedical Sciences, as co-principal investigator. Hosted under the theme “Frontier Technologies in Authentication and Biometrics,” the program applies AI to real-world security challenges, with student projects spanning micro-expression recognition, 3D finger-vein imaging, electrocardiogram-based continuous authentication, and cancelable biometric systems built from brainwave signals. The grant marks the second renewal of UB’s REU site — a testament to sustained NSF confidence and to the university’s historic strengths in AI and biometrics. The program emphasizes broad participation, reaching first-generation college students, students from economically disadvantaged backgrounds, and those at institutions with limited research infrastructure. Securing agentic AI for advanced manufacturing The second award, a $500,000 NSF CyberTraining grant approved by NSF in October 2025, launches a new program on “Secure Agentic AI for Advanced Manufacturing,” jointly

Local Engagement Helps Shape State <b>Cybersecurity</b> Efforts

Building engagement across local governments was a recurring theme during a whole-of-state panel discussion at last month's ISAC Annual Summit.* As the concept has evolved over the past decade, state cybersecurity leaders said they have learned that engaging local governments early, working through trusted partners and respecting local autonomy are essential to successful statewide cybersecurity programs. Moderator Karen Sorady said one definition of whole-of-state cybersecurity is a unified effort to coordinate collaboration and address shared cyber risks across state and local government, education, and sometimes industry and nonprofit partners. Sorady is the vice president of strategy and plans for the Multi-State Information Sharing and Analysis Center (MS-ISAC), which hosted the summit. “We don’t have an official definition, but we’ve been living it for years,” Tennessee Deputy CISO Aimé Nsengiyumva said. “We’ve been trying to figure out how we can work closely with local government organizations, how to support them, how to help them, but also how to work together.” Nsengiyumva also said his state includes local leaders in developing cybersecurity initiatives through its cybersecurity advisory council and other committees, where officials help shape programs and evaluation criteria. State leaders also speak at conferences hosted by organizations such as the Tennessee Municipal League. This type of association can be key for finding trusted messengers and connectors. In New York, Meghan Cook is director of the Division of Homeland Security and Emergency Services' Cyber Incident Response Team, and she has researched technology and cybersecurity for many years. During her tenure with the University at Albany, she said developing a cybersecurity primer with various professional public-sector organizations gave additional credibility to recommendations that had been made elsewhere. The Cybersecurity Primer for Local Government Leaders, published in 2022 by the University at Albany's Center for Technology in Government, was created in partnership with the