No-frills tech news

IIT-M, IIT-Kanpur jointly introduce nation's first degree course in <b>cybersecurity</b>

CHENNAI: The Indian Institute of Technology-Madras (IIT-M) and IIT-Kanpur have jointly launched what is touted as the country’s first practice-oriented, four-year Bachelor of Cybersecurity (B Cyber) programme. Admissions to the inaugural batch will be conducted jointly this month, while students will pursue the programme at their institute of choice. The undergraduate programme has been introduced to address the country’s growing demand for skilled cybersecurity professionals amid rapid digital transformation across sectors such as governance, finance, healthcare, telecommunications, manufacturing and defence. There is an estimated shortage of 1.5 million cybersecurity professionals nationally, a release by IIT-M stated. Designed with an emphasis on hands-on learning, the course combines academic instructions with extensive laboratory training and real-world professional experience. A key feature is a two-year field deployment professional project, under which students will spend their final four semesters working on live cybersecurity projects under the mentorship of experts from strategic and critical organisations. The competency-based curriculum covers areas including security operations, vulnerability assessment and penetration testing, secure systems, malware analysis, firmware reverse engineering, hardware security, cloud security and critical infrastructure security. Students can also choose advanced electives such as digital forensics, embedded systems security, secure processor microarchitecture and applied cryptography. During the first two years, students will receive intensive laboratory-oriented training in computer systems, programming, Linux system administration, cryptography, operating systems, computer networks, ethical hacking and web security. Graduates will be equipped for careers in cyber defence, security operations centres, cloud security and critical infrastructure protection, among others, the release added.

Fortinet: A Strong Investment in a Competitive <b>Cybersecurity</b> Market

Explore the exciting world of Fortinet(NASDAQ: FTNT) with our contributing expert analysts in this Motley Fool Scoreboard episode. Check out the video below to gain valuable insights into market trends and potential investment opportunities! *Stock prices used were the prices of May 13, 2026. The video was published on Jul. 3, 2026. Should you buy stock in Fortinet right now? Before you buy stock in Fortinet, consider this: Where to invest $1,000 right now? Our analyst team just revealed what they believe are the 10 best stocks to buy right now, when you join Stock Advisor. See the stocks » The Motley Fool Stock Advisor analyst team just identified what they believe are the 10 best stocks for investors to buy now… and Fortinet wasn’t one of them. The 10 stocks that made the cut could produce monster returns in the coming years. Consider when Netflix made this list on December 17, 2004... if you invested $1,000 at the time of our recommendation, you’d have $418,761!* Or when Nvidia made this list on April 15, 2005... if you invested $1,000 at the time of our recommendation, you’d have $1,195,804!* Now, it’s worth noting Stock Advisor’s total average return is 918% — a market-crushing outperformance compared to 208% for the S&P 500. Don't miss the latest top 10 list, available with Stock Advisor, and join an investing community built by individual investors for individual investors. *Stock Advisor returns as of July 3, 2026. Anand Chokkavelu has no position in any of the stocks mentioned. Jason Hall has positions in Fortinet. Toby Bordelon has no position in any of the stocks mentioned. The Motley Fool has positions in and recommends Fortinet. The Motley Fool has a disclosure policy.

Fortinet: A Strong Investment in a Competitive <b>Cybersecurity</b> Market | The Motley Fool

Explore the exciting world of Fortinet (FTNT 1.72%) with our contributing expert analysts in this Motley Fool Scoreboard episode. Check out the video below to gain valuable insights into market trends and potential investment opportunities! *Stock prices used were the prices of May 13, 2026. The video was published on Jul. 3, 2026. Stocks Mentioned *Average returns of all recommendations since inception. Cost basis and return based on previous market day close.

VIDEO: Fluence's Lars Stephan on what data centres and <b>cybersecurity</b> developments mean ...

We sat down with Lars Stephan, EMEA director of marketing, policy and public affairs for system integrator Fluence, to discuss energy storage, data centres and cybersecurity at Intersolar last month. The interview took place at the Smarter E Europe trade show in Munich, Germany, last month, colloquially known as Intersolar, which is actually the solar PV portion of the expo. The battery and battery energy storage systems (BESS) industry meanwhile convened in the ees Europe section of the show, where Energy-Storage.news had a video interview booth: the full video interview and write-up of our discussion with Stephan is below. BESS technology development While Stephan focuses on market design, policy and regulation, we touched on battery energy storage system (BESS) technology developments too. Fluence unveiled a more energy-dense, 10MWh iteration of its Smartstack AC block solution at the event. Try Premium for just $1 - Full premium access for the first month at only $1 - Converts to an annual rate after 30 days unless cancelled - Cancel anytime during the trial period Premium Benefits - Expert industry analysis and interviews - Digital access to PV Tech Power journal - Exclusive event discounts Or get the full Premium subscription right away Or continue reading this article for free New hardware, particularly around grid-forming and sodium-ion solutions, were a key theme over the three days. Sodium-ion especially was talk of the town, following big industry news in the space. Stephan said new technologies are always exciting, but that analytics and software are also hugely significant and less talked about. “The cells are innovating, more energy density is driving cost declines and better performance, and that’s very exciting,” Stephan said. “And we can’t not talk about sodium-ion. We’re not quite there in terms of large-scale deployments in Europe or the US, but it’s

The rise of autonomous AI in <b>cybersecurity</b>

We help you solve the problems that matter most so you can act faster and move further. What would you like to explore?A new chapter in cybersecurity is unfolding. One where machines follow human-led commands but chart their own course. This shift is being driven by agentic AI: autonomous systems that can reason, plan and act independently to achieve complex goals. AI agents enable companies to rethink and reimagine the way they work. In the context of cyber defence, these agents are not only more efficient tools but they’re also emerging collaborators. Imagine intelligent systems that detect threats in real time, coordinate responses across networks, probe for vulnerabilities and adjust their tactics as conditions change. They don’t wait for instructions. They act. This is more than an upgrade in capability. It’s a shift in how cybersecurity is designed and led. And it raises big questions: This series from PwC’s Cyber & Risk Innovation Institute explores the new frontier of agentic AI in cybersecurity: the opportunities, threats and leadership needed to shape what comes next. Here’s a glimpse of what’s ahead: How attackers might wield agentic AI in future operations, from intelligent recon to dynamic payload delivery. Agentic AI isn’t just changing the tools we use; it’s rewriting the rules of engagement in cybersecurity. We’re stepping into a world where autonomous systems can defend, attack, adapt and evolve faster than humans ever could. For defenders, this is about more than keeping up. It’s about reimagining what’s possible. The organisations that thrive in this new era won’t just adopt AI. They’ll build strategies, cultures and digital teams that think and act alongside us as teammates. This series is your map to that future. The age of agents has already begun. Let’s lead it. PwC helps organisations build Responsible AI programmes that unlock

Unpatched Flaws Disclosed in Filesystem Bundled Into Millions of Embedded Devices

Security firm runZero has disclosed seven vulnerabilities in FatFs, a small filesystem library that lets a device read and write the FAT and exFAT formats used on USB drives and SD cards. The flaws matter because FatFs is nearly everywhere. It ships inside the firmware that runs security cameras, drones, industrial controllers, hardware crypto wallets, and other devices built on real-time operating systems. On the worst-affected systems, an attacker who gets a booby-trapped USB drive, SD card, or update file onto a device can corrupt its memory and run their own code. Many embedded devices lack the memory protections found on phones and desktops, which is why runZero says "any physical access leads to a jailbreak." A public kiosk, a camera with an SD slot, an ATM, or a voting machine with a USB port should not hand over full control after a moment of physical access, but here it can. All seven bugs work the same basic way. The device tries to read a storage volume or firmware image that has been deliberately malformed, and FatFs mishandles the bad data. runZero rated the set CVSS Medium to High, with no Criticals. The headline bug is CVE-2026-6682 (CVSS 7.6), an integer overflow in the code that mounts a FAT32 volume. Bad math can produce a false file size, which later code treats as a real read length. On real hardware, that can become memory corruption and code execution. Here are all seven, worst first by runZero's ranking: - CVE-2026-6682 (7.6, High): FAT32 mount integer overflow leading to memory corruption and possible code execution. Reachable through some firmware updates, not just physical media. - CVE-2026-6687 (7.6, High): an exFAT volume-label field overflows a small buffer, giving an attacker a clean memory-corruption foothold. - CVE-2026-6688 (7.6, High): long filenames overflow the wrapper

New &quot;Bad Epoll&quot; Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android

A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code where Anthropic's most powerful AI model, Mythos, recently found a different bug. The AI caught one flaw and missed this one. A researcher, Jaeyoung Chung, found it and built a working attack. How the Bug Works Epoll is a standard Linux feature that lets a program watch many files or network connections at once. Servers, network services, and web browsers all lean on it. You cannot simply switch it off. Bad Epoll is a "use-after-free" bug. Two parts of the kernel try to clean up the same internal object at the same time. One frees the memory while the other is still writing into it. That brief collision lets an attacker corrupt kernel memory, then climb from a normal account up to root. The catch is timing. The window where the two paths collide is only about six machine instructions wide, so a random attempt almost never lands in it. Chung's exploit widens that window and retries without crashing, reaching root about 99% of the time on tested systems. Two things make it more dangerous: by his account, it can be triggered from inside Chrome's renderer sandbox, which blocks almost every other kernel bug, and it can reach Android, which most Linux privilege bugs cannot. Chung submitted the flaw as a zero-day to Google's kernelCTF program, and full technical details are in his public writeup. There is no sign it has been used in real attacks: as of this writing, it is not on CISA's Known Exploited Vulnerabilities list, and the

New Avalon Malware Framework Packs CrownX Ransomware Capabilities

Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one umbrella. The ransomware component has been internally named CrownX. "The attack began with a spoofed legal document email directing recipients to a password protected archive on Proton Drive," Blackpoint Cyber researchers Nevan Beal and Sam Decker said. "Malicious content was embedded inside an ISO image rather than attached directly, reducing the likelihood of detection at the email layer." Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that culminates in the deployment of Avalon. Specifically, the shortcut runs a command to launch an MSBuild project located in the ISO image. The MSBuild project, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon. The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. "These capabilities give the framework a multitude of ways to reduce telemetry, bypass user mode monitoring, and adjust its execution depending on the defensive controls present on the host," the researchers said. The complete set of features built into Avalon is as follows - - Harvest credentials, cookies, history, and bookmarks from Chromium-based browsers and Mozilla Firefox. - Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic

North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets

Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" mimic the legitimate "rollup-plugin-polyfill-node" project, down to the description, repository metadata, and package shape. "The lookalike packages place themselves in the same rollup, polyfill, core, and node naming space, which can look plausible during a quick dependency review," JFrog said in a technical write-up of the campaign. The campaign also involves four other packages, all of which have since been removed from the npm registry - - quirky-token - react-icon-svgs - rollup-plugin-polyfill-connect - swift-parse-stream What's noteworthy here is that "rollup-packages-polyfill-core" installs and loads "swift-parse-stream," while "rollup-runtime-polyfill-core" installs and "quirky-token." In a similar fashion, "react-icon-svgs" has been found to install "rollup-plugin-polyfill-connect" as a second stage. "The second-stage packages are near-identical SVG utilities that fetch a JSON object from JSONKeeper and eval the model field," the cybersecurity company said. "This layered structure, together with the lookalike names, legitimate-looking metadata, hidden install-time execution, environment checks, and credential-theft/remote-access payloads, is similar to previous North Korean Lazarus-linked npm campaigns." It's worth emphasizing here that this is not the first time North Korean threat actors have uploaded npm packages impersonating Rollup polyfill tools. In April 2026, Panther detailed a sustained npm campaign that involved publishing 108 malicious npm packages spanning 261 versions to deliver BeaverTail and OtterCookie, two known malware families linked to Contagious Interview. Among those packages was "rollup-plugin-polyfill-route," which was published on March 20, 2026. The starting point of the attack is a Base64-encoded npm install command for "swift-parse-stream" (or "quirky-token") that's concealed within "rollup-packages-polyfill-core" (or "rollup-runtime-polyfill-core"). The two second-stage packages are dressed up as SVG sanitization utilities, while reaching out to a JSON Keeper

Medtech's 2026 <b>Cybersecurity</b> Breaches Spared The Devices — And Hammered Everything Else

Home Pink Sheet Scrip Medtech Insight HBW Insight Generics Bulletin In Vivo Spotlight FDA EU Medical Device Regulation Robotics AI Interviews Business Deals Financing Earnings Startups R&D Policy & Regulation Approvals Recalls Legislation Compliance IP & Litigation Commercial Trackers M&A Deals Financing Deals Executive Moves Company Rankings Regulatory Trackers US Original PMAs US PMA Supplements US 510(k) Clearances US De Novo Classifications Non-US Approvals US FDA Warning Letters US Breakthrough Devices Global Guidance Tracker Podcasts Conference Coverage Partner Insights Opens in new window Advertise Opens in new window Medtech Insight Perspectives Uncovering medtech commercial, market access and development trends. View Pink Sheet Scrip Medtech Insight HBW Insight Generics Bulletin In Vivo Medtech’s 2026 Cybersecurity Breaches Spared The Devices — And Hammered Everything Else Jul 03 2026 • By Shubham Singh Hospitals run on a mix of decades-old Java middleware and brand-new patient portals, life-support devices that can never be switched off for a routine update, and corporate IT systems that — however carefully segmented from clinical operations — still hold the data and infrastructure that keep supply chains and billing moving. Picture Credit: Shutterstock More from Cybersecurity More from Digital Technologies

Strengthen Your Business With Lifetime <b>Cybersecurity</b> Training for $53

Strengthen Your Business With Lifetime Cybersecurity Training for $53 Get self-paced courses on CISSP, ethical hacking, and GRC through one lifetime membership. Disclosure: Our goal is to feature products and services that we think you'll find interesting and useful. If you purchase them, Entrepreneur may get a small share of the revenue from the sale from our commerce partners. For a small-business owner or solo entrepreneur, a single security breach can mean lost data, lost customers, and lost revenue. Most of us are too busy running the day-to-day to think about firewalls and phishing scams until something goes wrong. Whether you want to protect your own company or add an in-demand skill to your professional toolkit, understanding cybersecurity is no longer optional. That is where the InfoSec4TC Platinum Membership comes in. This lifetime subscription gives you self-paced access to more than 90 cybersecurity courses for a one-time $52.99 (reg. $280). It is built for working professionals who want practical, certification-focused training without committing to a recurring monthly bill. This cybersecurity training catalog covers the credentials hiring managers actually look for, including CISSP, CISA, CISM, and ISO 27001, alongside hands-on training in ethical hacking and using Python for security work. You also get the latest exam practice questions, frequently updated study materials, and access to private discussion groups, plus one free career consulting session to help map out your next move. Because it is a lifetime membership, every new course InfoSec4TC adds to your account at no extra cost. For a business owner, that knowledge translates directly into safer systems and smarter conversations with any IT vendor or contractor you bring on. For anyone eyeing a career pivot, IT and security roles remain some of the most resilient and well-paid positions on the market, and a recognized certification is often the

<b>Cybersecurity</b> Spending Just Crossed $300 Billion and These 3 ETFs Are the Cleanest ...

Global cybersecurity spending is forecast to exceed $300 billion in 2026, and the catalyst is no longer abstract. AI agents now outnumber human identities within enterprises by roughly 109 to 1; Fortinet’s threat report logged a 389% year-over-year jump in ransomware victims; and Check Point measured a 51-point gap between corporate AI adoption and security readiness. Every prompt-injection vector, deepfake voice clone, and automated phishing campaign expands the attack surface defenders must cover. Three ETFs offer different angles on the same trend: First Trust NASDAQ Cybersecurity ETF (NASDAQ:CIBR), Amplify Cybersecurity ETF (NYSEARCA:HACK), and Global X Cybersecurity ETF (NASDAQ:BUG). Each one screens the universe differently, and the differences matter more than the overlapping top holdings suggest. CIBR: The Default Allocation Holding $13.01 billion in assets as of late June, CIBR stands as the category leader while maintaining an expense ratio of 0.58% across 46 distinct holdings. Its strategy mirrors the NASDAQ CTA Cybersecurity Index by blending specialized vendors with established networking giants and IT service firms. This approach delivers a smart investment logic, as it lets you ride the broader wave of industry spending rather than gambling on a single platform to dominate the market. The portfolio leans heavily on the platform consolidators. Palo Alto Networks sits at 9%, CrowdStrike at 8%, and Fortinet at 7%, with Cisco and Broadcom close behind at 8% and 8%. That weighting matters because the news flow keeps validating the platform thesis: Palo Alto formed a NATO partnership and launched its Idira identity layer for AI agents, while Fortinet’s Q1 2026 billings grew 31%, driven by demand for AI and operational technology. Cisco and Broadcom give CIBR exposure to the networking layer where AI traffic actually moves, which a pure software fund misses. The infrastructure tail goes further than most realize. Cloudflare carries a 5%

Dental <b>Cybersecurity</b> Report Reveals the Most Common Threats Among Practices

The top threat was not a virus. It was attackers hijacking the remote-IT tools dental practices already trust, according to Medix’s Dental’s first-party data. ” DAVENPORT, IA, UNITED STATES, July 3, 2026 /EINPresswire.com/ — Medix Dental IT has released its June 2026 Dental Cybersecurity Data Report, an unusual move in an industry where most IT providers keep what they see to themselves. Most articles about dental cybersecurity are written from the outside looking in. This one is different. The report is built entirely from first-party telemetry across the dental practices and dental service organizations (DSOs) Medix protects, and it shows how practices are actually being attacked. Most dental IT support companies never publish this kind of data. Medix analyzed 2.58 billion security events in a single month and is putting the findings on the record so practice owners and DSO operators can plan against what the data shows, not against headlines. The clearest finding is where the real attacks came from. Analysts confirmed 12 foothold incidents, most of them tied to the abuse of remote monitoring and management (RMM) tools, the same remote-IT software dental practices trust their vendors to use. Attackers increasingly hijack those tools to blend in with legitimate activity, which is why layered monitoring, not antivirus alone, is what surfaced them. Antivirus still did its job, blocking 1,651 malware files during the month. But none of the 13 real incidents came from the files antivirus catches. Antivirus is not a cybersecurity program. It is one layer. For most dental groups, the real target has moved off the server in the back office and onto the identity layer. Medix analyzed 2.2 million Microsoft 365 events and ingested nearly 162 million security logs to catch account takeovers early. Microsoft research shows multi-factor authentication reduces the risk of account compromise

Data of 70000 people compromised in <b>cybersecurity</b> incident involving SLA's vendor IBM

Data of 70,000 people compromised in cybersecurity incident involving SLA’s vendor IBM Names, NRIC numbers and past property addresses were exposed after unauthorised access to a data set created for vendor development and testing. SINGAPORE: Personal data of about 70,000 people was compromised following a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by its vendor IBM. In a media release on Friday (Jul 3), SLA said the incident involved unauthorised access to a data set created for vendor development and testing. IBM manages the development and systems-integration testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS). The web-based system allows lawyers, government agencies and authorised individuals to submit documents relating to property transfers and caveats. Preliminary investigations showed that the compromised dataset, created in 1998 for testing purposes and updated periodically over the years, was meant to contain only mock and anonymised data based on property ownership and lodgment records. However, it was later found to include real information such as names, NRIC numbers and past property addresses of about 70,000 people. "This information should have been anonymised but was not," SLA said. "Investigations are ongoing to determine how this occurred." The affected environment managed by IBM is separate from SLA’s operational systems. “There is no connection or compromise to the live systems used for operations of STARS, ELS or any other SLA systems," the agency said. "Property ownership and lodgment records in STARS and ELS remain secure and unaffected." IBM has since revoked access to the affected system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on steps they can take for assistance. “SLA is working closely with IBM, the Government Technology Agency of Singapore and the Cyber Security

Data of 70000 people compromised after <b>cybersecurity</b> incident involving SLA vendor and its cloud

Personal info of 70,000 people compromised in data breach involving SLA’s vendor IBM SINGAPORE – The personal details of around 70,000 people in Singapore, including NRIC numbers and addresses, have been compromised following a data breach involving the Singapore Land Authority’s (SLA) vendor, IBM. In a statement on July 3, SLA said it was informed about the data security incident by IBM, which it had appointed to support and maintain the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS). IBM also managed the development and systems-integration testing environment for STARS and ELS. Preliminary investigations found that there was unauthorised access to a data set created for vendor development and testing, SLA said. The data set, which was created in 1998 and updated periodically over the years, was intended to contain only mock and anonymised testing data based on property ownership and lodgment records, SLA said. However, the authority said it has since uncovered that the data set also contained the names, NRIC numbers, and then property addresses of about 70,000 individuals. “This information should have been anonymised but was not. Investigations are ongoing to determine how this occurred,” it added. As a precautionary measure, SLA has identified the individuals whose information was contained in the affected data set. It has also started notifying them and advising them on how they can seek further information and assistance. SLA said the affected environment managed by IBM is distinct and separate from its operational systems. The live systems used to operate STARS, ELS or any other SLA systems have not been compromised, it added. Property ownership and lodgment records in STARS and ELS also remain secure and unaffected. IBM has revoked access associated with the affected development and testing environment to prevent any other unauthorised access. “SLA is working closely with

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral movement," Arctic Wolf said in a report published this week. "Anubis affiliates repeatedly abused legitimate remote access and administration tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to blend in with normal IT activity while maintaining control of victim systems." Anubis is a ransomware-as-a-service (RaaS) group that first emerged in late 2024 as a rebrand of Sphinx ransomware. The ransomware operation was formally announced on the Ransomware and Advanced Malware Protection (RAMP) underground forum in February 2025. According to data from Ransomware.Live, the cybercrime crew has claimed 91 victims on its data leak site, with 11 victims reported in June 2026 alone. Some of the prominent sectors targeted include healthcare, business services, manufacturing, technology, and financial services. More than 50% of the victims are located in the U.S., followed by the U.K., Australia, France, and Canada. In a report published in July 2025, Rubrik Zero Labs said Anubis advertises attractive profit splits, offering affiliates 80% of the ransom amounts paid, and pairs it with an irreversible data-wiping feature that ups the pressure on victims to pay up. "When Anubis's /WIPEMODE module is activated, files remain in directories but are reduced to a 0 KB size regardless of ransom payment," Rubrik noted at the time. "Knowing threat actors can revert victims' environments to this scorched-earth state with a single command significantly increases pressure on victims to pay before the wiper is fully activated." The ransomware intrusions, observed this year, involve both valid VPN credential use and the

VIA hosts <b>cybersecurity</b> event at Child &amp; Family Center

The Valley Industry Association’s monthly luncheon focused on cybersecurity at the Child & Family Center’s Education Center on Tuesday. Attendees got to enjoy lunch and mingle before the presentation, “The Cyber Threat You Don’t See Coming: Emerging Risks, Hidden Vulnerabilities, and What Leaders Must Do Now.” The presentation featured guest speaker Detective Sgt. Peter Hish from the Los Angeles County Sheriff’s Department’s Cybercrime Investigations. Hish began his talk by saying that the real problem is leadership, not an information technology problem. “It comes to their security, their company, their infrastructure, from cyberpaths … I see it over and over and over again,” Hish said. He recalled businesses constantly falling victim to different tricks or people hacking into their databases. Hish added that people who are in these businesses want to make money but are not thinking of the bigger picture. “Even a nonprofit is focused on making money for the nonprofit. They’re looking at marketing; they’re looking at innovation,” Hish said. “Staffing, payroll, all those things, but they’re not thinking of security or infrastructure, which does not make them money. It can cost them money later, but it doesn’t make them money.” Hish said that culture is another big part of cybersecurity and said the boss reflects the employees. “A good culture is important. If the boss has their password taped under the keyboard or they’re leaving their computer on the desk, but not doing those basic things, employees see that and do the same thing. And now you’re setting (up) a bad culture within your environment,” Hish said. He added that businesses should do regular training for cybersecurity, suggesting attendees complete a five-minute weekly exercise to help understand the importance of privacy and cybersecurity. At the end of the presentation, attendees participated in a question-and-answer session with Hish about

The Demand for Integrating <b>Cybersecurity</b> into Aerospace Quality

Aerospace The Demand for Integrating Cybersecurity into Aerospace Quality One of the most important conceptual shifts for aerospace quality managers is recognizing that AS9100/IA9100 and CMMC are not competing frameworks requiring duplicate effort. Aerospace quality management is undergoing its most significant transformation in decades. Quality management is rapidly evolving into a multidimensional assurance ecosystem that must simultaneously address physical product integrity, digital information security, supplier trustworthiness, and enterprise resilience. Two frameworks sit at the center of this transformation. The first is AS9100, soon to be rebranded as IA9100, the internationally recognized Quality Management System (QMS) standard governing aviation, space, and defense organizations. Developed and maintained by the International Aerospace Quality Group (IAQG), and built upon the foundation of ISO 9001, AS9100/IA9100 defines the operational expectations for quality across the global aerospace supply chain. The second is the Cybersecurity Maturity Model Certification (CMMC), a U.S. Department of Defense (DoD) mandate requiring defense contractors and their subcontractors to demonstrate verified cybersecurity controls as a condition of contract award. Quality and cybersecurity departments have operated as largely independent disciplines: Quality teams managed audits, corrective actions, supplier evaluations, and process controls. Cybersecurity teams managed IT infrastructure, threat monitoring, access controls, and incident response. That separation is no longer sustainable. Today, the systems used to design, manufacture, inspect, and deliver aerospace products are deeply digital, and therefore deeply vulnerable. (But these systems increasingly are more accessible and potentially less prone to duplication and overlap.) Engineering drawings, manufacturing routines, inspection records, supplier communications, and operational data all flow through networks and platforms that can be compromised, corrupted, or stolen. What Is AS9100 and Why Is It Evolving into IA9100? While AS9100 builds directly on ISO 9001, the internationally recognized baseline for quality management, it adds additional requirements specific to the unique demands of aviation, space, and