A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: traditional URL checks may miss the attack while Microsoft 365 access, sensitive data, and response time are already at stake. The Email Looks Safe. The Browser Tells a Different Story A recent EvilTokens attack shows how a phishing link can appear harmless during initial inspection while still leading to Microsoft 365 account takeover. The kit uses Microsoft Device Code Phishing to convince victims to complete a legitimate Microsoft login flow and unknowingly authorize access to their accounts. It does not need to steal the password directly. The real attack remains hidden until the page opens in the browser. Its HTML is encrypted with AES-GCM and becomes visible only after the browser decrypts it and renders the phishing content in the DOM. As a result, static URL checks and network-level controls may capture the initial response without seeing what the employee actually sees. This visibility gap can lead to: - Longer exposure to the Microsoft 365 account takeover - Delayed containment and response decisions - Unauthorized access to corporate email, files, and cloud services - More uncertain alerts escalated to senior analysts - Higher investigation workload and operational costs - Incomplete evidence for blocking related infrastructure The complete attack flow, however, was uncovered inside ANY.RUN’s Interactive Sandbox. Explore the analysis session to see what the browser revealed and how teams can use this evidence to respond faster. Check recent EvilTokens attack and get relevant IOCs | Complicated ghost phishing revealed inside ANY.RUN’s sandbox | Where Ghost Phishing Is Hitting Hardest ANY.RUN’s Threat Intelligence shows recent
Jul 9, 2026 · via thehackernews.com
Georgia Eye Institute investigating network “unusual activity”; cybersecurity expert weighs in SAVANNAH, Ga. (WTOC) - Georgia Eye Institute confirms it is investigating what it describes as “unusual activity” detected within its network last month. In a statement to WTOC, Georgia Eye Institute said it discovered the activity on June 11 and immediately took steps to protect its systems. “On June 11, 2026, we detected unusual activity within our network. Immediately upon discovery, we took steps to ensure the security of our environment and isolate impacted systems. We are working with our IT professionals and outside experts to restore our systems as quickly as possible and investigate this incident. The investigation remains ongoing and will take some time to complete.” The institute has not said what caused the unusual activity or whether any patient information has been accessed. WTOC followed up with additional questions but has not yet received a response. Robert Sexton, department chair of Cybersecurity and Computer Information Systems at Savannah Technical College, says “unusual activity” is a broad term commonly used during the early stages of a cybersecurity investigation. He says the company appears to be taking appropriate initial steps by isolating affected systems and bringing in cybersecurity experts while investigators determine exactly what happened. “The first step in a cyber investigation is to contain the attack,” Sexton said. “At the same time, you’re preserving evidence. Then investigators determine what systems were affected and what user accounts may have been compromised.” Sexton says if investigators determine patient information was accessed or stolen, the company could have legal obligations to notify those affected within a certain timeframe. Until then, he recommends patients monitor their credit, insurance accounts and watch for any unexpected insurance claims. Georgia Eye Institute says patient care has continued despite the technology issues. “Our primary focus
Jul 8, 2026 · via wtoc.com
Cybersecurity stocks are soaring in 2026. Missed Nvidia in 2009? This Rare Signal Is Flashing Again.In 2009, a "Double Down" signal flashed for a little-known chipmaker called Nvidia. For the first time in years, that same "Total Conviction" signal is flashing for a company 1/100th the size of Nvidia. Continue » *Stock prices used were the afternoon prices of July 6, 2026. The video was published on July 8, 2026. Should you buy stock in CrowdStrike right now? Before you buy stock in CrowdStrike, consider this: The Motley Fool Stock Advisor analyst team just identified what they believe are the 10 best stocks for investors to buy now… and CrowdStrike wasn’t one of them. The 10 stocks that made the cut could produce monster returns in the coming years. Consider when Netflix made this list on December 17, 2004... if you invested $1,000 at the time of our recommendation, you’d have $410,833!* Or when Nvidia made this list on April 15, 2005... if you invested $1,000 at the time of our recommendation, you’d have $1,208,693!* Now, it’s worth noting Stock Advisor’s total average return is 917% — a market-crushing outperformance compared to 209% for the S&P 500. Don't miss the latest top 10 list, available with Stock Advisor, and join an investing community built by individual investors for individual investors. *Stock Advisor returns as of July 8, 2026. Parkev Tatevosian, CFA has no position in any of the stocks mentioned. The Motley Fool has positions in and recommends CrowdStrike, Fortinet, and Rubrik. The Motley Fool recommends Palo Alto Networks. The Motley Fool has a disclosure policy. Parkev Tatevosian is an affiliate of The Motley Fool and may be compensated for promoting its services. If you choose to subscribe through his link, he will earn some extra money that supports his
Jul 8, 2026 · via theglobeandmail.com
Upcoming Webinar Community Fireside Chat | The CMMC Retrospective: An MSP’s Journey to Getting Certified Last year, we asked if you were ready for compliance-driven clients. Now that CMMC is officially here, the conversation has shifted from how to prepare to how to actually cross the finish line. But achieving compliance is rarely a straight line, and the most valuable insights come from looking back. Join us for our August Community Fireside Chat for an unfiltered retrospective on the reality of achieving CMMC clearance. We’re bringing together a panel of MSP peers and compliance experts who have survived the process to pull back the curtain on the mistakes made, the surprises uncovered, and the things they wish they’d known ahead of time. Come hear an honest, open conversation about the unexpected roadblocks and real-world realities of the certification journey so you don't have to learn the hard way. * HUNTRESS WEBINAR GIVEAWAY TERMS. Live webinar participants may be eligible to receive one (1) Nintendo Switch 2™ + Mario Kart™ World Bundle (“Gift”), worth approximately USD $500.00. This gift giveaway (“Giveaway”) is sponsored by Huntress Labs Incorporated (“Huntress”). By registering for the above Huntress webinar (“Webinar”), you accept the following Huntress Webinar Giveaway Terms and all decisions of Huntress, which are final and binding in all respects. NO PURCHASE NECESSARY. PURCHASE OF HUNTRESS PRODUCTS OR SERVICES DOES NOT ENHANCE CHANCES OF RECEIVING THE GIFT. Eligibility: The Giveaway is applicable to individuals who are 18 years of age or older who register for and participate in the Webinar. All applicable laws and regulations apply. Void where prohibited or restricted by law, including, but not limited to, international sanctions. Subject to applicable law, the Gift is offered “as is” without any express or implied warranty of any kind or nature, including without limitation,
Jul 8, 2026 · via huntress.com
Indiana quietly scraps transparency tool, cites cybersecurity concerns
Marissa Meador
Indianapolis Star
July 8, 2026, 4:14 p.m. ET
Gov. Mike Braun's administration has scrapped a transparency tool that allowed the public to search for state employees' roles and contact information after determining the application posed a cybersecurity risk.
The tool allowed the public to find basic information about state employees, including the agency they work for, their work email, their office phone number and their job title. It has been available since at least March 2018, according to the Internet Archive, but appeared to go offline at some point July 8.
Jul 8, 2026 · via indystar.com
When Jeff Bezos said that one breakthrough technology would shape Amazon’s destiny, even Wall Street’s biggest analysts were caught off guard. Fast forward a year and Amazon’s new CEO Andy Jassy described generative AI as a “once-in-a-lifetime” technology that is already being used across Amazon to reinvent customer experiences. At the 8th Future Investment Initiative conference, Elon Musk predicted that by 2040 there would be at least 10 billion humanoid robots, with each priced between $20,000 and $25,000. Do the math. According to Musk, this technology could be worth $250 trillion by 2040. Put another way, that’s roughly equal to: - 175 Teslas - 107 Amazons - 140 Metas - 84 Googles - 65 Microsofts - And 55 Nvidias And here’s the wild part — this $250 trillion wave isn’t tied to one company, but to an entire ecosystem of AI innovators set to reshape the global economy. It’s a leap so massive, it could reshape how businesses, governments, and consumers operate worldwide. Even if that $250 trillion figure sounds ambitious, major firms like PwC and McKinsey still see AI unlocking multi-trillion-dollar potential. How could anything be worth that much? The answer lies in a breakthrough so powerful it’s redefining how humanity works, learns, and creates. And this breakthrough has already set off a frenzy among hedge funds and Wall Street’s top investors. What most investors don’t realize is that one under-owned company holds the key to this $250 trillion revolution. In fact, Verge argues this company’s supercheap AI technology should concern rivals. Before I reveal the details, let’s talk about how some of the richest people on the planet are positioning themselves. - Bill Gates sees artificial intelligence as the “biggest technological advance in my lifetime,” more transformative than the internet or personal computer, capable of improving healthcare, education,
Jul 8, 2026 · via insidermonkey.com
When Jeff Bezos said that one breakthrough technology would shape Amazon’s destiny, even Wall Street’s biggest analysts were caught off guard. Fast forward a year and Amazon’s new CEO Andy Jassy described generative AI as a “once-in-a-lifetime” technology that is already being used across Amazon to reinvent customer experiences. At the 8th Future Investment Initiative conference, Elon Musk predicted that by 2040 there would be at least 10 billion humanoid robots, with each priced between $20,000 and $25,000. Do the math. According to Musk, this technology could be worth $250 trillion by 2040. Put another way, that’s roughly equal to: - 175 Teslas - 107 Amazons - 140 Metas - 84 Googles - 65 Microsofts - And 55 Nvidias And here’s the wild part — this $250 trillion wave isn’t tied to one company, but to an entire ecosystem of AI innovators set to reshape the global economy. It’s a leap so massive, it could reshape how businesses, governments, and consumers operate worldwide. Even if that $250 trillion figure sounds ambitious, major firms like PwC and McKinsey still see AI unlocking multi-trillion-dollar potential. How could anything be worth that much? The answer lies in a breakthrough so powerful it’s redefining how humanity works, learns, and creates. And this breakthrough has already set off a frenzy among hedge funds and Wall Street’s top investors. What most investors don’t realize is that one under-owned company holds the key to this $250 trillion revolution. In fact, Verge argues this company’s supercheap AI technology should concern rivals. Before I reveal the details, let’s talk about how some of the richest people on the planet are positioning themselves. - Bill Gates sees artificial intelligence as the “biggest technological advance in my lifetime,” more transformative than the internet or personal computer, capable of improving healthcare, education,
Jul 8, 2026 · via insidermonkey.com
Costa Mesa-based CerraCap, a venture capital firm, announced yesterday its investment in AI-powered cybersecurity platform MazeBolt, based in Israel.
MazeBolt says it focuses on Distributed Denial of Service (DDoS) attack resilience and continuous security validation.
“MazeBolt represents the kind of cybersecurity platform CERRACAP believes will define the next phase of enterprise resilience,” said Vikas Datt, a general partner at CerraCap. “In an environment where adversaries are increasingly automated, adaptive, and AI-enabled, organizations can no longer rely on periodic testing or static assumptions. MazeBolt provides a continuous, independent validation layer that gives enterprises greater visibility, confidence, and control over their DDoS posture.”
More tech stories:
Jul 8, 2026 · via ocbj.com
Getty Images/iStockphoto CISO's guide to hiring for the right cybersecurity skills The cybersecurity talent gap won't be solved by head count alone. CISOs need to fundamentally rethink how they recruit, how they retain talent and what skills they really need. The cybersecurity talent crisis has moved from a simple numbers problem to a fundamental mismatch between what organizations need and what the workforce can deliver. While 87% of organizations plan to expand their security teams this year, according to Fortinet Training Institute's "2026 Cybersecurity Skills Gap" report, the CyberSeek online data tool found that there are only enough available cybersecurity workers in the U.S. to meet 74% of employer demand. As problematic as that data is, it doesn't encapsulate the full extent of the workforce challenge. Cybersecurity leaders are finding not only a shortfall in the number of cybersecurity professionals, but also a significant misalignment between the available skills in the market and those needed in enterprise cybersecurity departments. Researchers from SANS Institute and GIAC called it "a widening skills gap that organizations struggle to close, even as they increasingly recognize that having the right abilities matters more than simply adding head count," in the "2026 Cybersecurity Workforce Research Report." "The problem isn't a shortage in head count. We're never going to get the numbers we want to get. It's really more about getting the needed skills," said Brian Correia, director of global cyber workforce strategy and engagement at SANS. CISOs must modernize their approach to recruiting workers. This involves moving away from a conventional search strategy and adopting one that creates multiple talent pipelines and emphasizes workforce development to ensure hires continuously learn the latest skills. The impact of the security talent, skills gaps Staffing challenges affect an organization's cybersecurity posture. Recent research from ISC2 found that 88% of
Jul 8, 2026 · via techtarget.com
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like an attack. Decrypting browser credentials, listing what sits in Windows' credential store, pulling files down with built-in system tools, writing to the startup folder: these have long been high-signal to defenders. What has changed is who is generating it. On the machines Sophos watched, it was often a developer's AI assistant going about ordinary work. What set the alarms off The analysis draws on seven days of telemetry from June 2026, taken from Sophos's behavioral engine on Windows and counted by unique machines, not raw event volume. It is a narrow window on one vendor's fleet, not an industry census. Sophos's charts put credential access at 56.2 percent of the blocked activity and execution at 28.8 percent: agents reaching for stored secrets, or running code the way attackers do. The biggest credential-access rule, at 42.6 percent of that group, fires when a process uses Windows' built-in Data Protection API, or DPAPI, to decrypt the browser's stored credential data. Sophos calls GStack a widely adopted skill pack for coding agents. Its /browse skill does exactly that, running PowerShell that calls DPAPI to unlock saved browser data. Sophos caught it running under Claude Code. In context, it is almost certainly browser automation on the user's behalf. To the detection engine, it is credential theft, and the rule is right to fire. Some Python examples looked worse on paper. In one instance, Claude Code shut down the running browser and ran a script that pulled data from its credential
Jul 8, 2026 · via thehackernews.com
Oregon Tech recently hosted two free cybersecurity camps for middle and high school students, giving participants the opportunity to learn about online safety, cybersecurity tools, and technology career pathways. The camps were held at the Klamath Falls campus in June through Oregon Tech's Educational Partnerships and Outreach (EPO) program and welcomed 30 students for free instruction, hands-on learning experiences, and lunch each day. Both camps were designed and led by Praveen Guraja, Ph.D., Assistant Professor of Cybersecurity and Information Technology, and Manish Nalluri, Visiting Instructor in Applied Computing and Geomatics. In Cyber Explorers: Defend, Discover, Design, middle school students were introduced to cybersecurity concepts through activities focused on digital citizenship, online safety, passwords, phishing detection, cryptography, and basic cybersecurity investigations. High school students in Cyber Ops: Hack, Defend, Secure, explored more advanced topics, including ethical hacking, digital forensics, network analysis, cryptography, and cyber defense tools. Students participated in group projects, hands-on labs, cyber detective activities, Capture the Flag competitions, and challenge-based games that required teamwork and problem-solving. Among the most popular activities were Capture the Flag challenges, phishing detective exercises, cryptography labs, Kahoot review games, and an escape-room-style lock box challenge. "The students were engaged and quickly connected what they learned to real-world situations," said Guraja. "They were not just listening to cybersecurity concepts. They were practicing them, solving puzzles, working in teams, presenting their findings, and building confidence." Students learned practical skills for recognizing phishing attempts, creating stronger passphrases, understanding how computer networks operate, analyzing digital information, and identifying cyber threats. Participants also earned an industry-recognized cybersecurity credential. "It is important for students to learn cybersecurity at this age because they are already active online and constantly interacting with digital systems, games, apps, school platforms, and social media," said Guraja. "Helping them understand cyber threats early gives them the
Jul 8, 2026 · via oit.edu
Dive Brief: - More than half (52%) of retailers are pouring $50 million or more into digital technology annually, according to KPMG’s recent survey of 250 retail executives across sectors. That includes 28% who are allocating between $100 million and $250 million. - Nearly half (48%) of respondents said the cost of technical debt, defined by IBM as the future costs stemming from shortcuts and flawed decisions during software development, prevents them from investing in other technologies. This is lower than the 63% average across industries. - The majority (86%) of respondents said their tech enhancements are “frequently improving business value.” Furthermore, most have realized between 31% and 40% of their total financial value from AI and other intelligence tech tools, per the report. Dive Insight: As AI tools proliferate throughout the retail industry, a narrative shift is underway, KPMG noted in its report. While retailers focused on digital transformation a few years ago, AI has become a ubiquitous tool to help companies gain a competitive edge and drive future growth, the report said. Currently, 42% of the surveyed executives said their company is innovating and deploying AI use cases at scale, but 74% expect that to be the case in 12 months’ time. AI and automation, including generative AI and agentic AI, is also one of the top areas where retailers expect to increase their investment. Forty-two percent said they would do so, compared to 52% who will increase spending on cybersecurity and 49% who plan to boost investments in data and analytics. While some retailers are diving headfirst into their AI integrations, others are balancing AI tools with human connection. During the Shoptalk Spring 2026 event earlier this year, Denise Paulonis, CEO of Sally Beauty Holdings, noted that the beauty business remains reliant on a personal touch. “AI
Jul 8, 2026 · via retaildive.com
Dive Brief - U.S. companies are merging cyber risk issues into their overall enterprise risk strategy, at a time when AI adoption and business resilience are leading to significant shifts in business priorities, according to a report released Tuesday by Information Services Group, a technology research and advisory firm. - Cybersecurity is increasingly seen as a business-critical concern, as companies accelerate their adoption of agentic AI and transform much of their technology and data infrastructure to hybrid or multicloud environments. - Enterprise leaders are closely integrating cyber spending decisions with overall IT strategy. In addition, C-suite and board members are taking greater accountability for business continuity, financial exposure and regulatory compliance. Dive Insight The report reflects significant changes among large enterprises in terms of how expanded use of AI cloud adoption has changed the conversation around overall business risk. AI adoption is forcing companies to rethink their corporate governance, internal controls and overall preparedness for a major cyberattack or IT outage. “Cybersecurity has become a core business consideration rather than a standalone technology function,” Jason Stading, director, cybersecurity at ISG, told Cybersecurity Dive. “Organizations are embedding cyber risk into AI adoption, digital transformation, and broader technology investment decisions; most enterprises recognize that security enables innovation while managing enterprise risk.” Chief information security officers and chief information officers are playing a more strategic role in these organizations, according to Stading. They are partnering with corporate boards and executive leadership to help shape business decisions and make sure cybersecurity is integrated into overall business strategy A June report by S&P warned that companies lacking strong internal security governance could put their credit ratings at risk. Authorities in the U.K., meanwhile, have pressed corporate leaders to incorporate cyber risk into their overall business strategies and sounded the alarm on the increasing number of
Jul 8, 2026 · via cybersecuritydive.com
Teragonia Appoints Cybersecurity Leader Dhruv Chandra as Executive Vice President of Technology & Operations Industry veteran brings three decades of cybersecurity and enterprise technology experience CHICAGO, July 8, 2026 (Newswire.com) - Teragonia, the AI operating system for private equity, today announced the appointment of Dhruv Chandra as Executive Vice President of AIOS Technology & Operations. In this role, Chandra will be responsible for Teragonia's cybersecurity posture, platform performance, program portfolio management and technology partnerships. As organizations rely on AI to inform business-critical decisions and increasingly complex cybersecurity, governance and data protection have become essential to maintaining customer trust and enabling innovation. Chandra's deep experience deploying strategies that protect complex enterprise environments in highly regulated industries like financial services and healthcare will further strengthen Teragonia's technology, while supporting the company's rapid product innovation and global growth. "Dhruv's background in infrastructure, cybersecurity, digital transformation and enterprise technology makes him a critical addition to the Teragonia leadership team," said Thomas Thayyil Thomas, CEO of Teragonia. "His experience helping some of the world's largest financial institutions modernize their data security strategies will be instrumental as we continue to expand our platform's capabilities for clients across key industry verticals." Chandra joins Teragonia after serving as an advisor to the company's leadership team. Most recently, he served as Managing Director at Intact, where he oversaw automated financial and technology control testing across five continents. Before that, he was Chief Technology & Privacy Officer at CloudMD. He also served as Principal Architect for Security in Financial Services at Google, advising major financial institutions on Zero Trust architecture and cloud modernization, and held technology leadership roles at Royal Bank of Canada, Scotiabank, and CIBC. "I'm excited to officially join Teragonia at a time when cybersecurity has become critical to value creation for private equity-backed businesses," said Chandra. "As
Jul 8, 2026 · via newswire.com
The European Commission has presented a plan to address the risks and harness the opportunities of advanced artificial intelligence (AI) in cybersecurity. While the AI can improve security, it can also be misused to identify vulnerabilities, automate attacks, and significantly increase the scale and speed of cyber incidents. The new plan will bring together EU countries, industry, and EU-level organisations to strengthen the cybersecurity of our digital landscape against the vulnerabilities posed by advanced AI. Key actions - Evaluating AI models: The AI Act requires advanced AI models to be evaluated and their risks to be assessed before they are placed on the EU market. The Commission will help establish an EU evaluation capacity to strengthen third-party assessment of AI capabilities and risks globally, supporting the regulatory function of the AI Office. - Accessing advanced AI models: Europe needs clear and transparent conditions for accessing the most advanced AI systems. The Commission will work with the EU Agency for Cybersecurity to define a European blueprint for structured access to advanced AI capabilities for cybersecurity, supporting public and private organisations in accessing advanced AI models. - Testing AI for cybersecurity: The EU Agency for Cybersecurity and the Commission’s Joint Research Centre will create a secure platform to test AI for cybersecurity, including using simulated environments. This will bring know-how on the safe use of AI to operators in critical sectors. - Reinforcing the EU's cybersecurity and fixing vulnerabilities: The EU must protect its critical infrastructure. In line with the EU's cybersecurity rules, organisations should intensify cyber hygiene practices, risk management measures, and security by design principles. They should also start using available AI capabilities to fix vulnerabilities faster, as well as prevent and respond to cyberattacks. EU Agency for Cybersecurity will assist them in this transition, including guidance, recommendations, and best
Jul 8, 2026 · via commission.europa.eu
The initiative, first teased in April, has garnered nationwide interest — DoD said it received more than 70,000 inquiries from prospective candidates. Applications for the Defense Department’s long-anticipated cyber apprenticeship program are now open, providing additional details about the 12-month paid pilot designed to train the department’s next generation of cyber professionals. The department’s chief information officer’s office announced Monday that applications will be accepted through July 17 on USAJobs.gov. The initiative, first teased in April, has garnered nationwide interest — the Defense Department said it received more than 70,000 inquiries from prospective candidates. “This overwhelming surge highlights a massive, untapped demand for alternative, skills-based training pathways into national security roles,” the Defense Department said in a press release. The initial announcement of the program captured the public’s imagination in part due to relatively low barriers to entry. Unlike many government cyber roles, the program does not require prior professional cyber experience. The only qualifications are that applicants must be at least 18 years old, U.S. citizens and able to obtain a security clearance. Join us July 21 – 23 for Federal News Network's Space & Satellite Exchange where government and industry leaders will discuss advancing connectivity, resilience and mission reach. Register today! Plus, the CIO office said these positions would be entry-level — DoD’s recent pay tables show that a recent college graduate just starting out in the Washington, D.C. area as a GG-7 Step 1 would make approximately $57,735 a year. The office also said that while participants would be able to complete technical training modules online from any location approved by the employing agency, on-the-job training would be conducted in person and vary by employing agency. But according to the USAJOBS posting, the salary is only $22,584 a year, and most vacancies are based in the Washington,
Jul 8, 2026 · via federalnewsnetwork.com
Trustifi Appoints New CEO to Lead Cybersecurity and AI Advances Tuesday, 07 July 2026 10:00 AM Company Update Technology industry veteran Jeff Spridgeon to lead the continued transformation of the renowned channel email security organization LAS VEGAS, NV / ACCESS Newswire / July 7, 2026 / Editorial Summary - Trustifi has appointed Jeff Spridgeon as CEO to lead the company's next phase of growth and strengthen its indirect go-to-market strategy. - This hire solidifies Trustifi's commitment to innovation and partner success, emphasizing faster responses to evolving cyber threats-especially for SMB customers-and expanded support for channel partners. - The company's zero-trust email protection platform and AI-driven security awareness training capabilities were designed to help channel partners protect themselves and their clients from modern threat Trustifi, a provider of AI-driven, next-generation email cybersecurity solutions, has appointed experienced channel and technology industry leader Jeff Spridgeon to the role of Chief Executive Officer. An accomplished sales and partnership development leader, Spridgeon has built, grown and successfully directed a number of indirect teams and organizations over his career. That channel experience and expertise will be invaluable as Trustifi continues to transform its cybersecurity and go-to-market strategy. "As cybercriminals adopt new tactics and automation to escalate attacks on businesses, especially the highly vulnerable SMB customers, Trustifi has to innovate and respond even faster to help partners protect their IT ecosystems," says company board member Jason Hable, a co-founder and partner at Camber Partners. "Jeff brings the insight and leadership skills required to carry out that mission, including a strong focus on the technological, support and business needs of our partners and robust growth of our AI-powered cybersecurity portfolio." Trustifi delivers an innovative and powerful email security solution through its network of channel partners and recently launched a new AI-driven SAT module, which directly integrates into the
Jul 8, 2026 · via accessnewswire.com
Member-only story Notes on Cybersecurity’s Machine-Speed Future What a day inside the frontier of AI-driven security taught me about the collapse of the patch window, the rise of the remediation economy, and why your evals are about to matter more than your tools. tl;dr — There is a strategic shift in cybersecurity where AI-accelerated vulnerability discovery is outstripping the human ability to repair systems. Anthropic positions itself as an intelligence hyperscaler and the advent of frontier AI models has fundamentally altered the cybersecurity landscape by collapsing the window between vulnerability discovery and exploitation to near zero, shifting the industry’s primary bottleneck from finding flaws to remediating them at machine speed. This shift requires a move away from rigid, manual playbooks toward autonomous, goal-oriented agentic defense systems that can continuously triage alerts and conduct investigations. However, the rapid proliferation of these non-human actors introduces novel risks such as “poisoned memory” and prompt injection, necessitating that organizations treat AI agents like human employees by enforcing strict cryptographic identities, blast-radius limits, kill switches, and robust verifier networks. Ultimately, to survive this new era of abundant AI-driven threats, defenders must abandon static public benchmarks in favor of custom, operational evaluations and transition to continuous, real-time mitigation strategies.
Jul 7, 2026 · via medium.com
New ClickFix scam tricks users into installing malware, cybersecurity expert warns LITTLE ROCK, Ark. (KATV) — A resurfacing scam known as “ClickFix” is tricking people into installing malware on their own devices by posing as a “prove you’re human” verification step, according to cybersecurity expert Chris Wright of Sullivan Wright Technologies. Wright said the scam has been around for a while but has “reared its head again with a new theme,” using prompts that look like familiar human-verification tests. The key difference, he said, is that ClickFix instructs users to copy and paste code onto their own computer and run it, which can bypass typical security protections. “It’s asking you to actually copy code into your own computer, so it’s kind of bypassing all of your protective mechanisms and saying go ahead and paste this sight unseen code and run it for me,” Wright said. Wright said that once a victim runs the code, it can give an attacker a foothold on the device. That access can be used to steal sensitive information such as “passwords and credentials,” he said, or to install a remote access tool that allows the attacker to return repeatedly. He said cybercriminals are increasingly targeting everyday people rather than only large institutions. “There’s so many of these folks who, they’re, you know, they don’t need a whole lot, so they’re going to come after the little folks like us,” Wright said. “If they can get a little bit of money, if they can hit your small bank account, or you know, get something out of your email, then that’s good enough for them.” To protect against ClickFix-style attacks, Wright said people should be wary of any “prove you’re human” prompt that instructs them to open system tools and paste in commands. “It’s asking you to
Jul 7, 2026 · via katv.com
âWeâre giving local communities in Alabama a fighting chanceâ: McCrary program provides cyber defense for local governments across the state Published: Jul 7, 2026 3:30 PM By Joe McAdory The average cost of a data breach in 2025 for U.S. organizations was $10.22 million, according to IBM. Even more, 34 percent of local agencies — city halls, fire stations, hospitals, schools — were compromised by ransomware. To combat this threat, the average information technology division in Alabama employs 2.2 people. That’s it. 2.2. A successful cyberattack can shut down the systems a community depends on. Water systems go offline. Utility billing stops. Communications are disrupted. Public safety is put at risk. It’s what cybersecurity experts consider “a city’s worst day.” “When a cyberattack strikes Anytown, USA, what does that mayor do?” asked Nick Sellers, McCrary Institute for Cyber and Critical Infrastructure Security chief operating officer. “What do county commissioners do? What does that local hospital administrator do? They’ve got to get services going, and if they don’t have a plan or the resources, they’re in trouble.” Cybersecurity professionals and students at Auburn University’s Samuel Ginn College of Engineering have a solution. The Alabama Cybersecurity Intelligence Center, a joint initiative of the Alabama Office of Information Technology (AOIT) and the McCrary Institute, offers basic cyber hygiene, multi factor authentication, penetration testing, incident response planning and round-the-clock monitoring of every device on a municipal network. The fundamental elements that can be quickly deployed are known as McCrary Secure and are made possible through the State and Local Cybersecurity Grant Program (SLCGP), a $19 million, five‑year federal investment under the Infrastructure Investment and Jobs Act. “We’re giving local communities in Alabama a fighting chance,” Sellers said. “What we’re offering is real, no‑cost protection from experienced cybersecurity professionals and industry partners. It’s a no‑risk
Jul 7, 2026 · via eng.auburn.edu