Home
Categories
Front Page
News
News
Community
National
Statewide
Obituaries
Sports
Social
Social
Pets
Tourism
Business
Health
Food
Health
Agriculture
Agriculture
Outdoors
Area Interest
Columns
Education
Featured
Misc
Viewpoints
Weather
Special Pages
Archives
Search
About Us
Printed Paper Online
SUBSCRIBE
SUBSCRIBE
LOGIN
LOGIN
Login with Facebook
Login with Facebook
×
Subscribe
Loading...
RUSK WEATHER
Front Page
News
News
Community
National
Statewide
Obituaries
Sports
Social
Social
Pets
Tourism
Business
Health
Food
Health
Agriculture
Agriculture
Outdoors
Area Interest
Columns
Education
Featured
Misc
Viewpoints
Weather
Special Pages
Archives
Search
Jacksonville Investigating Cybersecurity Incident
by Press release from City of Jacksonville.
This content is for subscribers only. Log in or sign up for a free trial below.
Click here to start your Free Trial
(No credit card required)
Click here to start your Free Trial
(No credit card required)
×
Free Trial
Loading...
Register/Claim
Register/Claim
Loading...
Jul 6, 2026 · via thecherokeean.com
Cybersecurity Lessons from a Floriculture Phishing Attack The floriculture sector is increasingly facing cyber incidents. It is no longer a question of *if* you will be affected, but *when*. That is why it is important for growers and buyers — and, by extension, the entire floriculture sector — to become more resilient to cyber incidents. Floris Kloeg, an IT Specialist at Ter Laak Orchios, remembers it well. It was around a quarter past six in the morning on Wednesday, April 8, 2026, when he received a message via WhatsApp from a colleague. The colleague had received an email from a member of staff at Riza Growers, the growers’ collective of which Ter Laak Orchios is a part. The sender’s name was correct, as was the email address. The layout looked genuine, too. Yet, Floris’s colleague thought: something isn’t quite right. “He’s never been in contact with that Riza employee. And the content of the email was vague as well,” says Floris. “We checked it out and sure enough: it wasn’t genuine.” From a Single Wrong Click to Crop Damage What had happened? The Riza Growers employee had clicked on the wrong link in a phishing email. This gave cybercriminals access to his email account, and they sent emails in his name to around 125 contacts. This is how the phishing email spread within the floriculture sector. Floris acted quickly. “We blocked the employee’s account at around a quarter to seven. We informed the recipients of the email as quickly as possible.” As a result, the ultimate damage was limited. “We reported it promptly to Royal FloraHolland, which was able to link this incident to a number of other cyber incidents,” says Floris. In collaboration with organizations including the National Cyber Security Centre, Royal FloraHolland traced the source of the attack.
Jul 6, 2026 · via greenhousegrower.com
Students in the Oregon Tech Portland-Metro Cybersecurity Club held a hands-on hackathon June 4, focused on applying classroom knowledge in a practical, enterprise-style environment. Participants Scott Reinholtz (Cybersecurity), Joshua Brady (Information Technology), Anibal Lopez-Bonilla (Software Engineering Technology), Trevor Craig (Cybersecurity), and Noah Etchemendy (Software Engineering Technology) tested their classroom learning by building servers and testing them against attacks. The hackathon emphasized the full lifecycle of cybersecurity work. Students built and configured systems, hardened servers and workstations against potential threats, and then used their hacking skills to get into the machines and find flags placed everywhere on the servers and workstations. “This allowed students to apply what they learned in class in a practical way, demonstrating those skills in a real environment,” said Scott Reinholtz, one of the club’s organizers. “It also allows students opportunities to ask questions and keep learning outside the classroom. We want students to be able to continue their education with an on-site practical use case that uses enterprise hardware and software to enhance their skills in cybersecurity, IT, and networking.” All participants received commemorative awards 3D printed by Reinholtz. The Oregon Tech Cybersecurity Club Portland is a 12-member student-run group that meets weekly to explore cybersecurity topics and prepare for competitions. The club introduces students to a range of tools and practices used in the field, including: - Network and web exploitation (nmap, Burp, sqlmap, Metasploit) - Hardware and wireless security (Pwnagotchi, Flipper, Bash Bunny, Alfa cards) - Reverse engineering and binary exploitation (Ghidra, pwntools, ROP) - Defensive ops and SIEM (Splunk, Wazuh, network forensics) - Capture-the-Flag (CTF) preparation — internal practice + external competitions Faculty and staff support for the club includes advisor Malini Nagasundaram, along with Gary Lomprey and Kellyn Beeck. Students interested in getting involved can attend weekly meetings or join the club’s
Jul 6, 2026 · via oit.edu
Home
Pink Sheet
Scrip
Medtech Insight
HBW Insight
Generics Bulletin
In Vivo
Spotlight
FDA
EU Medical Device Regulation
Robotics
AI
Interviews
Business
Deals
Financing
Earnings
Startups
R&D
Policy & Regulation
Approvals
Recalls
Legislation
Compliance
IP & Litigation
Commercial Trackers
M&A Deals
Financing Deals
Executive Moves
Company Rankings
Regulatory Trackers
US Original PMAs
US PMA Supplements
US 510(k) Clearances
US De Novo Classifications
Non-US Approvals
US FDA Warning Letters
US Breakthrough Devices
Global Guidance Tracker
Podcasts
Conference Coverage
Partner Insights
Opens in new window
Advertise
Opens in new window
Medtech Insight Perspectives
Uncovering medtech commercial, market access and development trends.
View
Pink Sheet
Scrip
Medtech Insight
HBW Insight
Generics Bulletin
In Vivo
MDIC Lays Out Five-Step Cybersecurity Penetration Testing Process For Connected Device Makers
Jul 06 2026
•
By
Krishna Chandra Eluri
More from Cybersecurity
More from Digital Technologies
Jul 6, 2026 · via insights.citeline.com
Pursuing a career in cybersecurity can seem intimidating, particularly for those without a traditional IT or mathematics background. It’s a challenging field where responding to threats not only requires an understanding of complex solutions, but also patience and practice. Video games have emerged as a way of making the act of learning these complex solutions accessible for anyone with ambitions to become a cybersecurity professional. TryHackMe is a training platform that gamifies cybersecurity, transforming regular classes into accessible modules taught in rewarding, straightforward ways. Could gaming make cybersecurity careers more accessible? One of the biggest barriers to pursuing a career in cybersecurity is the perception that it’s only for IT professionals or programmers. Today there are a growing number of platforms that gamify cybersecurity, opening up learning opportunities and making it accessible to everyone. By introducing puzzles, virtual environments and simulations, this approach helps learners grasp complex topics in a way that may be far more engaging than sitting through a lecture. If you originally dismissed cybersecurity as a career, a gamified experience could entirely prove you wrong. How are cybersecurity platforms borrowing from video games? TryHackMe is a gamified cybersecurity training platform designed to teach anyone cybersecurity through a more rewarding, accessible approach than a traditional degree course. You’ll follow a ‘learning roadmap’ that guides you through pathways and industry-recognised certifications needed to specialise in one of four areas. These pathways are broken down into modules, all of which encourage hands-on learning from the outset: you’ll learn how to attack and defend corporate networks, secure cloud-based applications and be guided through real-world scenarios like investigating suspicious activity in a security operations centre (SOC). There’s even a King of the Hill mode where 10 players compete to compromise a system first while fending off other skilled hackers who want to
Jul 6, 2026 · via sciencefocus.com
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits. In a proof of concept, they reconstructed a signed-in user's full Gmail address from a single visit, with no click. Opera has patched the flaw and says it found no evidence that it was ever used in the wild. The fix shipped in Opera GX version 130.0.5847.89, so anyone on a current build is already covered; you can confirm yours at opera://about. There is no CVE. Because the attack needed no clicks or approvals, there was no workaround short of the patch. Opera's bug bounty team rated the issue P1, its top severity, and paid the maximum $5,000 award for a critical bug. How the attack works GX Mods let you reskin Opera GX with custom sounds, themes, wallpapers, and CSS that restyles the sites you visit. They ship as .crx files, like browser extensions, but they cannot run JavaScript and hold no permissions. The weakness is in how they install: Opera's mod pipeline downloads and enables a mod automatically, with no approval prompt. So a malicious page can install one silently, for instance by loading a hidden iframe pointed at a .crx file. The only sign is a notification bar below the address bar telling you a mod was added, with a Remove button. This auto-install behavior is not new. The researcher Renwa identified it back in 2023 and, by escalating an installed mod into a full extension, used it to spoof the browser's address bar. Opera patched that specific attack in March 2023 but left the underlying auto-install in place, which is what this new research builds on. A silent look-and-feel
Jul 6, 2026 · via thehackernews.com
The proposed regulations would require cybersecurity and software update management systems for advanced vehicles, with phased implementation beginning in October for new models featuring Level-3 automation. Share Post The proposed regulations would require cybersecurity and software update management systems for advanced vehicles, with phased implementation beginning in October for new models featuring Level-3 automation. The Ministry of Road Transport and Highways (MoRTH) has proposed new regulations that would make cybersecurity and software update management systems mandatory for vehicles equipped with advanced technologies. This comes amid growing concerns over cyber threats as modern vehicles become increasingly connected and software-driven, making them more vulnerable to malware and other forms of cyberattacks. Under the proposed framework, the rules would apply to passenger vehicles, commercial vehicles and tractors fitted with at least one electronic control unit (ECU) capable of supporting Level-3 or higher automated driving functions, The Economic Times reported, New vehicle models equipped with Level-3 automation and above, including models such as the Mercedes-Benz S-Class, Audi A8 and BMW 7 Series, would be required to comply with the cybersecurity and cybersecurity management system requirements from October. Existing models would have to meet the requirements from April next year. The regulations would then be expanded in phases. Vehicles capable of receiving over-the-air (OTA) software updates would be required to comply between April and October 2028, followed by vehicles with software update capability from October 2029. Over-the-air software updates allow vehicles to receive software, firmware and system upgrades through Wi-Fi or cellular networks, similar to software updates on smartphones. The technology enables manufacturers to deliver feature enhancements, bug fixes and system improvements without requiring customers to visit a dealership. Officials said vehicle manufacturers need to strengthen the security of software code used in critical systems, including battery management systems, which monitor and manage the operation
Jul 6, 2026 · via ackodrive.com
News/Reuters/LTM Launches Blueverse Rightlogic Cybersecurity FrameworkLTM Launches Blueverse Rightlogic Cybersecurity FrameworkRefinitivSign up to read this newsJoin for free
Jul 6, 2026 · via tradingview.com
Sectra awarded framework agreement for operational cybersecurity of critical infrastructure in Sweden Linköping, Sweden – July 6, 2026 – International medical imaging IT and cybersecurity company Sectra (STO: SECT B) has been awarded a framework agreement by the Swedish Agency for Civil Defense (MCF) following a public tender process. The framework agreement covers security monitoring in real time for organizations subject to the EU cybersecurity directive NIS 2. More precisely, it encompasses security monitoring services for Operational Technology (OT) environments, IT security monitoring for smaller organizations as well as external network surveillance. The framework agreement enables efficient procurement of security monitoring services through MCF and the arrangement is part of the establishment of Sweden's national Security Operations Center (SOC-SE), aiming to increase operational cybersecurity for critical entities of our society and their operations. "This is a strategically important assignment for Sectra. Being able to contribute to strengthening Sweden's operational cybersecurity and protecting critical infrastructure is both a responsibility and a testament to our expertise," says Gustav Sandberg, President of Critical Infrastructure at Sectra. “We are honored by the trust placed in Sectra and we look forward to supporting those critical entities and thereby strengthening Sweden’s Total Defense capabilities.” Through this framework agreement, valid for up to four years, services are enabled that strengthen the ability of critical societal functions to detect and respond to cyber threats and potential attacks at an early stage. Sectra’s services include real-time security monitoring of IT and OT environments, analysis of security alerts and incidents, proactive threat hunting as well as continuous development of detection capabilities. The services are delivered through Sectra’s 24/7 Security Operations Center (SOC), where large volumes of log data are analyzed to rapidly identify and manage threats in close collaboration with the customer organizations. Similar framework agreements are signed with a
Jul 6, 2026 · via news.cision.com
Cybersecurity experts and law enforcement agencies consistently advise organizations to report data breaches as soon as they are discovered. Timely disclosure allows authorities to investigate incidents, helps affected organizations limit financial and operational damage, and raises awareness among employees and stakeholders about emerging cyber threats. In many regions, data protection laws also require companies to notify regulators and impacted individuals within specified timeframes after a security incident. Despite these recommendations and legal obligations, a recent study suggests that many organizations are still reluctant to be transparent about cybersecurity incidents. According to research conducted by cybersecurity company Bitdefender, a significant number of cybersecurity professionals have been asked by their employers to conceal or avoid reporting data breaches. Such practices can delay incident response, increase the impact of attacks, and expose businesses to greater legal and reputational risks. The study also highlights growing concerns about the role of artificial intelligence (AI) in modern cyberattacks. While AI has become an essential tool for strengthening security defenses, many professionals believe cybercriminals are currently gaining greater advantages from the technology. Attackers are increasingly using AI to automate phishing campaigns, generate convincing social engineering messages, identify system vulnerabilities, and launch more sophisticated attacks at scale. As AI capabilities continue to evolve, security experts expect cyber threats to become even more advanced and difficult to detect. Another key finding from the Bitdefender report is the communication gap developing between business leaders and cybersecurity teams. Around 55% of employees surveyed said they had been discouraged or prevented from openly discussing security breaches within their organizations. This culture of silence can undermine an organization’s ability to respond effectively to cyber incidents, as delayed reporting often gives attackers more time to expand their access and cause additional damage. The survey further revealed that cyberattacks remain a persistent challenge for organizations
Jul 6, 2026 · via cybersecurity-insiders.com
Cyber threats have become one of the biggest operational risks facing organizations of every size. As businesses accelerate digital transformation and rely more heavily on cloud computing, remote work, and connected devices, cybercriminals continue to develop more sophisticated attack techniques. The financial losses, regulatory penalties, and reputational damage resulting from a successful cyberattack can take years to recover from, making proactive cybersecurity an essential business priority. One of the most pressing threats facing enterprises today is ransomware. Modern ransomware attacks no longer focus solely on encrypting files. Attackers increasingly steal sensitive data before locking systems, using the threat of public disclosure to pressure organizations into paying large ransoms. Critical industries such as healthcare, finance, manufacturing, and government remain frequent targets because service disruptions can have severe consequences. Regular data backups, network segmentation, and endpoint detection solutions are essential to reduce the impact of ransomware incidents. Phishing and business email compromise (BEC) attacks also continue to evolve. Cybercriminals now use artificial intelligence to craft highly convincing emails, fake invoices, and executive impersonation messages that are difficult to distinguish from legitimate communications. Employees remain the first line of defense, making regular cybersecurity awareness training and multi-factor authentication (MFA) vital safeguards against credential theft and financial fraud. Cloud security is another growing concern as organizations migrate applications and sensitive data to public and hybrid cloud environments. Misconfigured storage services, weak access controls, and compromised administrator accounts can expose confidential information to attackers. Businesses should implement a zero-trust security model, continuously monitor cloud environments, and enforce strict identity and access management policies to minimize these risks. Supply chain attacks have emerged as one of the most challenging cybersecurity threats in recent years. Instead of attacking a large organization directly, threat actors compromise software vendors, managed service providers, or other trusted third parties to gain
Jul 6, 2026 · via cybersecurity-insiders.com
SURIGAO CITY, Surigao del Norte (PIA) — The Department of Information and Communications Technology (DICT) Caraga, in partnership with the municipal government of Del Carmen, Siargao Island in Surigao del Norte, conducted a series of cybersecurity and cyber-hygiene awareness sessions for 1,733 students from various secondary and elementary schools of the town. The activity, held on June 9-11, formed part of the DICT’s double celebration for its 10th year anniversary and the observance of National ICT Month, strengthening its commitment to build a safer, more secure, and digitally empowered Philippines. On June 9, DICT Caraga held sessions for 1,074 participants from Del Carmen National High School and the elementary schools of Katipunan, Esperanza, Cancohoy, Bagacay, and Jamoyaon at the Del Carmen and Katipunan covered courts. It was followed by a campaign on June 10 that engaged the 390 participants from Oguing National Memorial National High School, Sayak Elementary School, Mahayahay Elementary School, Anitapolo Elementary School, Bitoon Elementary School, and Cabugao Elementary School. Sessions were held at the Oguing NHS Covered Court and the Cabugao Covered Court. On June 11, DICT Caraga directly served 269 more learners from Mariano Matugas Memorial National High School, Tuboran Elementary School, Quezon Elementary School, Numancia Central Elementary School, and Mabuhay Primary School. Sessions took place at the MMMNHS and NCES Covered Courts. DICT Caraga officials said that during awareness sessions, participants learned about the Internet and its consequences. The sessions highlighted both opportunities and risks in today’s digital environment. Students also practiced cyber hygiene, including creating strong passwords, securing accounts, updating devices, and browsing safely. They added that the discussions achieved several key outcomes, namely, promoted responsible online behavior, addressed cyberbullying, and emphasized the protection of personal information. The sessions also increased awareness of digital footprints and guided identifying threats such as scams, phishing, identity
Jul 6, 2026 · via pia.gov.ph
Omnigent: Open-source AI agent framework and meta-harness Plenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way of running shell commands against a working directory. That spread leaves teams with a governance gap around where agent actions land and how much they cost. Omnigent, an open-source project, sits one level above those tools as a meta-harness. The common layer drives Claude Code, Codex, Cursor, OpenCode, Hermes, Pi, and agents a team writes in YAML, and a user swaps or combines them with one-line changes. Omnigent draws on a first-party API key, a Claude or ChatGPT subscription, or any compatible gateway such as OpenRouter, with a per-agent default a user can switch mid-session. A single session follows the user from a terminal to a browser to a phone, with messages, sub-agents, terminals, and files in sync. Guardrails set at the harness layer The security design centers on policies. A policy governs what an agent may do across shell commands, file edits, and token spend, and it checks every action to allow it, block it, or pause for a person’s approval. Spend caps and access limits ship as builtins, so a session can carry a hard dollar ceiling with a softer warning along the way. These checks run at the meta-harness layer as stateful, data-centric rules that track agent actions, which keeps enforcement out of the prompt where an agent might drift past it. Policies stack across three levels. An administrator sets server-wide rules, a developer sets per-agent rules, and the person in a session sets per-session rules, with the stricter session rules checked first. A team can write a
Jul 6, 2026 · via helpnetsecurity.com
New DMCC Cyber vertical will support more than 200 cybersecurity companies Dubai: DMCC has launched DMCC Cyber, a dedicated cybersecurity vertical, after its technology sector crossed 4,000 companies and became the largest and fastest-growing segment in the business district. The new vertical will support more than 200 cybersecurity companies operating across cyber resilience, digital trust, data protection, identity, and governance, risk and compliance. Get updated faster and for FREE: Download the Gulf News app now - simply click here. DMCC Cyber has been launched alongside the formal establishment of DMCC Tech, an overarching technology platform that brings together the district’s specialist centres and technology communities. “Technology has become the largest and fastest-growing sector in our business district, reflecting Dubai's position as one of the world's leading destinations for innovation and high-growth businesses," said Ahmed Bin Sulayem, Executive Chairman and CEO, DMCC. "As that community has expanded, so too has the need for more specialised platforms that support different segments of the technology economy. DMCC Tech brings these communities together under a single ecosystem, while DMCC Cyber reflects the growing importance of cybersecurity in an increasingly digital world.” DMCC Cyber joins the DMCC AI Centre, DMCC Crypto Centre and DMCC Gaming Centre under the DMCC Tech platform, with DMCC Quantum set to follow. The platform gives technology companies access to DMCC’s wider business community of more than 26,000 member companies across global trade, finance, commodities and emerging technologies. DMCC said the platform is already home to companies including CrowdStrike, PwC, CYFIRMA and FPT Software, reflecting the scale and international reach of its technology community. DMCC Tech spans artificial intelligence, cybersecurity, blockchain, gaming and emerging technologies, while also extending into the rapidly developing space economy. The district said advances in satellites, earth observation and space-derived data are reshaping sectors such as trade,
Jul 6, 2026 · via gulfnews.com
Pennington County closes most public-facing offices Monday amid cybersecurity incident RAPID CITY, S.D. (KOTA) - Most Pennington County public-facing offices will be closed Monday as officials respond to a cybersecurity incident affecting portions of the county’s network. County officials said the closures will allow staff to assess the situation and safely restore affected systems. Several essential services will remain operational, including 911 Dispatch, the Pennington County Jail, the Juvenile Services Center, the Care Campus and other public safety operations. Court operations, the 24/7 Program and early voting at the Pennington County Auditor’s Office will also continue as scheduled from 7 a.m. to 4 p.m. Residents needing vehicle registration services can still use South Dakota’s online registration portal or self-service kiosks. County officials said the full scope of the cybersecurity incident is still being determined. Pennington County is working with the South Dakota National Guard Cyber Incident Response Team, the South Dakota Fusion Center, the Cybersecurity and Infrastructure Security Agency and other partners as the investigation continues. Because the investigation remains active, officials said they have limited verified information available at this time. The county expects to provide its next public update by 11 a.m. Monday. See a spelling or grammatical error in our story? Please click here to report it. Do you have a photo or video of a breaking news story? Send it to us here with a brief description. Copyright 2026 KOTA. All rights reserved.
Jul 6, 2026 · via kotatv.com
RAPID CITY, S.D. – Pennington County is responding to a cybersecurity incident affecting portions of the network.
A news release from the Pennington County State’s Attorney’s Office says most public-facing County offices will be closed on Monday, July 6, 2026, while the County works to restore systems safely and assess the situation.
The following services are still operational:
- Critical life safety services, including: 911 dispatch, the Pennington County Jail, Juvenile Services Center, the Care Campus, and other public safety operations.
- Court operations
- The 24/7 Program
- Early voting at the Pennington County Auditor’s Office from 7 a.m. to 4 p.m.
- Vehicle registration remains available online at my605drive.sd.gov and at self-service kiosks.
The full scope of the incident is still being determined, and Pennington Co. is working closely with the South Dakota National Guard Cyber Incident Response Team, the South Dakota Fusion Center, the Cyber Infrastructure Security Agency, and other partners as the investigation continues.
Jul 6, 2026 · via kbhbradio.com
Skip to content News Livestream Local Weather Sports We the People Submit Photos and Videos Digital Advertising Home Livestream News KOTA Cares Agriculture Business Community Crime Economy Education Environment Fine Arts Health/Medical Law Enforcement Local Medical Military National Regional Science State Sturgis Rally Technology Video Pets of the Week Weather Download Our Weather App Closings Weather Cams Weather Blog KOTA Territory Mornings Mixology at Home Food & Drink Mr. Food Where In the Hills is Mimi? Live Performances Sports Black Hills Play by Play RC Marshals Games Pigskin Preview Big Ol Fish Friday Night Hike Athlete Of The Week Futbol Frenzy Politics Political Pulse Election Results Community Calendar Contests Contact Us Meet the Team Careers Submit a Tip Submit Photos and Videos Digital Advertising Programming Schedule NextGen TV Newsletter Support Local Business Circle Country Local News Live InvestigateTV Watching Your Wallet PowerNation Gray AI Policy Pennington County closes most public-facing offices Monday amid cybersecurity incident Published: Jul. 5, 2026 at 10:25 PM CDT | Updated: 6 hours ago Share Add Us On Google Add as a preferred source on Google News Rapid City police arrest 10 for DUI ahead of Fourth of July holiday Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News Chamber Music Festival’s “Celebration of Strings” gives area students fast-track performance experience Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News Monthly comics club meetups take off at Goblin Comics in Rapid City Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News CASA raffle fundraiser offers chance to win playhouse built by local partners Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News Rapid City man identified as victim in fatal Highway 40 crash near Hermosa Updated: 6 hours ago
Jul 6, 2026 · via kotatv.com
To Catch a Hacker, Think Like One: The Nuance in Modern Cybersecurity The old adage in cybersecurity is straightforward: to catch a hacker, you must think like one. But there's a critical nuance today. It's no longer enough to merely adopt an attacker's mindset within your own four walls. You must see the entire sprawling, interconnected ecosystem the way a hacker does — because that's exactly how they operate. The Fortress Mentality That No Longer Holds Traditional cybersecurity was built on the logic of a medieval castle. A company had clear boundaries: insiders inside, outsiders outside. The mission was simple — fortify the perimeter, monitor the walls, and keep threats at bay. This approach worked reasonably well when operations were centralized in on-premises data centers that physically fit "in one server rack" (an exaggeration, but the point stands). Then everything changed. Outsourcing blurred the lines. Cloud adoption dissolved them entirely. Today, we're entering an agentic economy, where autonomous AI agents roam external services, call APIs, and hold broad permissions — often acting while you sleep. As explored in analyses of prompt injection attacks, these agents can be socially engineered much like the classic "grandma at the ATM" scam, turning helpful tools into unwitting accomplices. Yet the murkiest and most dangerous element isn't the flashy new tech. It's the old-school contractors and third parties. The Hidden Weak Links: Contractors and the Supply Chain Large enterprises work with dozens or hundreds of external partners: accounting outsourcers, CRM vendors, legal firms, ERP integrators, and more. Each is a separate organization with its own infrastructure, security posture, and priorities. You can influence it through contracts, but you can't control it. Hackers figured this out long before the industry fully adapted. Why batter down a heavily fortified corporate firewall when you can slip through a
Jul 6, 2026 · via quasa.io
Apple Products Multiple Vulnerabilities Release Date: 6 Jul 2026 623 Views RISK: Medium Risk TYPE: Operating Systems - Mobile & Apps Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system. Impact - Denial of Service - Information Disclosure - Security Restriction Bypass - Data Manipulation System / Technologies affected - Versions prior to iOS 26.5.2 and iPadOS 26.5.2 - Versions prior to macOS Tahoe 26.5.2 - Versions prior to Safari 26.5.2 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: - iOS 26.5.2 and iPadOS 26.5.2 - macOS Tahoe 26.5.2 - Safari 26.5.2 Vulnerability Identifier - CVE-2026-28979 - CVE-2026-39868 - CVE-2026-39872 - CVE-2026-43663 - CVE-2026-43676 - CVE-2026-43699 - CVE-2026-43700 - CVE-2026-43701 - CVE-2026-43703 - CVE-2026-43704 - CVE-2026-43705 - CVE-2026-43706 - CVE-2026-43707 - CVE-2026-43708 - CVE-2026-43709 - CVE-2026-43712 - CVE-2026-43713 - CVE-2026-43715 - CVE-2026-43716 - CVE-2026-43717 - CVE-2026-43718 - CVE-2026-43720 - CVE-2026-43721 - CVE-2026-43722 - CVE-2026-43724 - CVE-2026-43725 - CVE-2026-43726 - CVE-2026-43727 - CVE-2026-43731 - CVE-2026-43732 - CVE-2026-43734 - CVE-2026-43735 - CVE-2026-43740 - CVE-2026-43742 - CVE-2026-43743 - CVE-2026-43745 - CVE-2026-43746 Source Related Link Related Tags Share with
Jul 6, 2026 · via hkcert.org
Palo Alto Networks and Koi Security sued over alleged AI error in cyber threat report MeetingTV claims a flawed intelligence classification led to global blocking of its services. A cybersecurity report intended to map Chinese-linked espionage activity has escalated into a legal dispute spanning Silicon Valley and Israel, after a U.S. startup alleged it was wrongly identified as part of a hostile network due to an artificial intelligence error. In March, U.S. media company MeetingTV filed a lawsuit in federal court in Southern California against cyber firm Koi Security, and its four Israeli founders, Amit Assaraf, Idan Dardikman, Tuval Admoni, and Gal Hachamov. Cybersecurity giant Palo Alto Networks, which acquired Koi in April for hundreds of millions of dollars, was added as a defendant in May 2026. At the center of the lawsuit is the claim that a flawed artificial intelligence system at the cybersecurity company caused the complete destruction of legitimate business activity due to what is known as “AI hallucination.” According to the complaint, at the end of December 2025, Koi Security published a threat intelligence report titled “DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers,” which examined espionage and cyber infrastructure linked to an attack group allegedly operating under Chinese state direction. As part of the report, Koi added the domain of MeetingTV to its IOC (Indicators of Compromise) list, effectively marking the company as part of a Chinese-linked espionage infrastructure. MeetingTV claims the classification was fundamentally incorrect and did not stem from traditional forensic investigation, but rather from an erroneous output generated by Koi’s proprietary AI system, “Wings.” The plaintiff alleges that Koi negligently published the findings without sufficient human oversight or verification. The consequences, according to the lawsuit, were immediate and severe. Once the report circulated in the cybersecurity community, security vendors, enterprise
Jul 6, 2026 · via calcalistech.com