No-frills tech news

<b>Cybersecurity</b> beyond blocking: A call for collaboration

Cybersecurity beyond blocking: A call for collaboration Residential proxies and AI-detected zero-day vulnerabilities pose major 2026 cybersecurity threats, writes one IT leader. Traditional blocking fails; global collaboration is needed. This is no time for complacency on the cybersecurity front, as two major security threats are shaking the industry in 2026. They are posed by residential proxies, which have global footprints through every major home network provider, and the recent revelation of AI models capable of identifying zero-day vulnerabilities in every major software distribution far faster than the industry is ready or capable of addressing them. While they are not strictly new attack types, they are raising threat levels by orders of magnitude. Traditional approaches to operational security generally fall into some form of blocking or limiting. Those don't work here, by design or by scale. It's not possible to block or limit enough of the potential threat without significantly affecting usability of the internet as a whole. To address the threats, we must look at the basic attack problems they are amplifying, and bring more solutions to bear by working collaboratively. Residential proxies Residential proxies are specifically designed to blend in with and be covered by unpatterned daily network traffic from residential IP addresses, meaning they often go undetected for long periods. Unlike malware infections that rely on gaining access through security lapses, residential proxy software is often willingly brought into home networks through the lure of cheap VPN connections or on consumer devices like TVs. Once established across all major ISPs, these proxy networks can be used to carry out DDoS attacks of untraceable origin, or even more sophisticated attack campaigns such as Salt Typhoon. Even when the attacks are detected, blocking them is difficult, because they are likely to be scattered throughout an ISP's IP address space. Plus,

CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure

CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure WASHINGTON – Today the Cybersecurity and Infrastructure Security Agency (CISA) announced the formation of the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI), a new advisory-body framework that will strengthen information sharing and broaden partnerships across government and industry to secure the nation’s critical infrastructure. ANCHOR-CI incorporates the best practices and lessons learned from the Critical Infrastructure Partnership Advisory Council (CIPAC) and will expand meaningful, impactful engagement to a wider range of public-private critical infrastructure stakeholders to address threats in real time. “The new and innovative ANCHOR-CI framework will be a game changer in how the public and private sectors collaborate and share information,” said Department of Homeland Security (DHS) Secretary Markwayne Mullin. “In a rapidly evolving threat environment, ANCHOR-CI will ensure we have the right people in the room working together to keep the critical infrastructure Americans rely on secure and resilient. This is just another example of the partnership needed to confront the threats of today and tomorrow.” DHS and CISA built the framework, and CISA will manage the governance of the councils established under ANCHOR-CI, which will facilitate open and candid discussion of sensitive information among participants, strengthening collaboration amongst government and industry. “As the national coordinator for critical infrastructure security and resilience, CISA is dedicated to actively engaging partners from the critical infrastructure community in every step of our work,” said Nick Andersen, CISA Acting Director. “This framework was developed to address the unique challenges our partners face, ensuring their voices are heard and their needs are met. By establishing ANCHOR-CI, CISA is not only fulfilling its core statutory mission but also strengthening our collective ability to safeguard the vital services Americans rely on every day.” The ANCHOR-CI framework allows

#explained #whatsapp #meta #<b>cybersecurity</b> #digitalindia | moneycontrol.com

🚨 #EXPLAINED | WhatsApp vs Government: GoI issues notice to Meta in username feature 🇮🇳📱 The Indian government has issued a notice to Meta over WhatsApp's upcoming username feature, raising concerns about traceability, user identification, and compliance with India's IT rules. What is the feature? Why is the government objecting? And what could this mean for your privacy and WhatsApp experience? 🎥 Chandra R. Srikanth breaks it down | #WhatsApp #Meta #CyberSecurity #DigitalIndia moneycontrol.com’s Post More from this author - Data centre to go public, ease of investing and Apple’s India price shock -- Editor’s Picks from Moneycontrol - #MCTech3 | WhatsApp username brouhaha explained; PhysicsWallah wants teachers to do more than just teach; and more - HDFC Bank’s leadership moves, Amazon turns up heat in Q-Comm, and cracks in the influencer economy -- Editor’s Picks from Moneycontrol Explore content categories - Career - Productivity - Finance - Soft Skills & Emotional Intelligence - Project Management - Education - Technology - Leadership - Ecommerce - User Experience - Recruitment & HR - Customer Experience - Real Estate - Marketing - Sales - Retail & Merchandising - Science - Supply Chain Management - Future Of Work - Consulting - Writing - Economics - Artificial Intelligence - Employee Experience - Workplace Trends - Fundraising - Networking - Corporate Social Responsibility - Negotiation - Communication - Engineering - Hospitality & Tourism - Business Strategy - Change Management - Organizational Culture - Design - Innovation - Event Planning - Training & Development

How federal <b>cybersecurity</b> teams can adapt to a post-DOGE environment

How federal cybersecurity teams can adapt to a post-DOGE environment COMMENTARY | The long-lasting impact of DOGE has been to accelerate a broader shift toward more disciplined, efficient and operationally resilient security strategies. The actions of DOGE may have faded from the news cycle, but for government chief information security officers the cuts that were made last year still feel fresh. Most are facing rising cyber threats with leaner teams and smaller budgets, including increased risks tied to the Iran conflict. There is a silver lining, however. Many security teams are using this moment to modernize and operate more efficiently. They’re not necessarily trying to do more with less. Instead, they’re prioritizing, automating and simplifying. What’s more, CISOs are concerned but not panicking. A new Forrester Consulting report found only 38% of public sector cybersecurity decision-makers are confident in their agency’s cybersecurity posture in the wake of headcount reductions. But those same decision-makers are proactively — and successfully — adapting their risk management approach to accommodate the current reality. Here are the operational shifts they’re adopting to meet the demands of a post-DOGE world. A renewed focus on high-priority vulnerabilities and critical infrastructure Agencies simply do not have the resources to try to protect everything equally. According to OPM workforce data published in March, the federal government had experienced a net workforce reduction of more than 278,000 employees since January 2025. As a result, security teams are under pressure to move faster while managing increasingly complex environments with fewer people. That reality is forcing CISOs to become far more disciplined about how risk is prioritized and managed. Instead of spreading limited resources across every possible vulnerability or compliance requirement, agencies are increasingly concentrating on the systems, networks and data sets most critical to mission continuity and public services. According to

Trump administration lifts restrictions on Anthropic's Claude models after <b>cybersecurity</b> alarm

3:02AM Obituaries PGe PG Store Archives Classifieds Classified Events Jobs Public Notices Pets MENU SUBSCRIBE LOGIN REGISTER LOG OUT MY PROFILE Home News Local Sports A&E Life Business Contact Us Public Notices NEWSLETTERS MENU ACCOUNT Subscribe Login Register Log out My Profile Subscriber Services Search SECTIONS HOME Homepage Top Stories Chats Weather Traffic Event Guide PG Store PGe Video Photos The Digs RSS Feeds NEWS News Home Crimes & Courts Politics Education Health & Wellness Transportation State Nation World Weather News Obituaries News Obituaries Science Environment Faith & Religion Social Services LOCAL Local Home City Region East North South West Washington Westmoreland Obituaries Classifieds Public Notices SPORTS Sports Home Steelers Penguins Pirates Sports Columns Pitt Penn State WVU PG Sports Network podcasts Riverhounds NFL NHL MLB NBA NCAA College Sports High School Sports A&E A&E Home Celebrities Movies TV & Radio Music Concert Listings Theatre & Dance Art & Architecture Books Events LIFE Life Home Food Dining Recipes Drinks Buying Here Homes & Gardens goodness Random Acts of Kindness Seen Outdoors Style & Fashion Travel Holidays BUSINESS Business Home Building PGH Your Money Business Health Powersource Workzone Tech News Business / Law Other Business Consumer Alerts Top Workplaces PGH Partners PGH Partners Home UPMC | Ask the Experts OTHER PGe NEWSLETTERS PG STORE ARCHIVES CLASSIFIEDS PUBLIC NOTICES OBITUARIES JOBS CLASSIFIEDS EVENTS PETS CONTACT US / FAQ CONTACT US ADVERTISING CULTURE & CAREERS DONATE TOP Email a Story Your e-mail: Friends e-mail: Submit

Your Perspective Matters: Join the NIS360 survey - ENISA

ENISA launches a survey for both national authorities and high criticality entities under NIS2 in preparation of the next edition of the NIS360 report. Following the publication of the NIS360 2026 report in May 2026, a new assessment cycle has now started with the launch of data collection and surveys for the NIS360 2027 edition. For this assessment, data is collected via an online platform using two structured questionnaires designed to assess cybersecurity maturity by combining insights from the private sector with perspectives from national authorities. The NIS360 surveys are carefully designed to ensure that data collected each year remains comparable and reflects overall trends. All responses are analysed in aggregate form, ensuring confidentiality. What’s new in the survey? The survey for both authorities and entities has been simplified, is quick to complete and features a user-friendly interface. It also introduces new features that allow registered entities to receive a benchmarking report, compare themselves with their peers, and better understand where they stand. Your responses are essential for ENISA’s assessment of sectoral cybersecurity maturity and criticality under NIS360.Share your feedback by taking part to the survey by 30 October 2026 via the following link: https://enisa.enablor.dk/auth/register/survey/eca2ce47cdd14826b095192fbdc15edc?lang=en The survey will be used to prepare the new NIS360 report, which will be published in 2027. For any further information regarding the survey, please contact NIS360@enisa.europa.eu. About the ENISA NIS360 report The ENISA NIS360 aims to work as an annual assessment tool supporting national authorities, policymakers and other stakeholders in assessing the cybersecurity maturity and criticality of high criticality sectors under the NIS2 Directive. Under the NIS360, a sector’s maturity is determined by: legislation and its effectiveness, companies and their preparedness, authorities and their institutional capacity, and sectoral ecosystem structures and their effectiveness. The assessment relies on a structured methodology developed and continuously refined

Cal Water says <b>cybersecurity</b> breach by Iranian-linked hackers was limited

CHICO — An investigation into a June 11 cyberattack claimed by an Iranian-linked hacker group found that hackers accessed one California Water Service customer’s online account using stolen credentials, but did not breach the utility’s internal systems or billing infrastructure, the company announced this week. Cal Water has continued to investigate claims made on June 11 by an Iranian-linked hacker group that it breached Cal Water’s systems throughout the state — including some in Chico. When the claims were made, Cal Water said it activated its cybersecurity response plan and worked “around the clock” to conduct an investigation, being supported by the state and federal government, as well as cybersecurity experts. Based on the investigation, Cal Water said the threat actor activity was limited to “unauthorized access to a small number of specific user accounts within two third-party service provider platforms.” Mandiant, a cybersecurity firm and subsidiary of Google Cloud, supported Cal Water in the investigation, and did not identify any evidence of activity in Cal Water’s internal technology of operational technology environments. However, the investigation did find that one customer’s account was accessed. “The investigation determined that the threat actor accessed one active customer’s online Cal Water account using stolen user credentials. The customer account did not provide access to the billing system, and no payment information was compromised,” Cal Water said. “The threat actor also accessed an external, third-party web site related to a GPS location correction tool; however, the website does not contain any confidential or sensitive information.” The hacker group, known as Handala, claimed responsibility for the breach June 11. In a screenshot of the groups claims, hackers from the group said the breach was a “warning” to the federal government after air strikes damaged water resources in Sirik, Iran two days prior to the breach.

China storage battery makers denied <b>cybersecurity</b> approval in Japan

TOKYO -- None of China's storage battery makers have received cybersecurity clearance from Japan's government despite an upcoming requirement that such equipment needs certification to connect to the power grid. Chinese manufacturer decries 'de facto exclusion' as certification requirement looms Even Chinese manufacturers with market share in Japan lack approved products. (Nikkei montage/Source photos by Nikkei) TOKYO -- None of China's storage battery makers have received cybersecurity clearance from Japan's government despite an upcoming requirement that such equipment needs certification to connect to the power grid.

GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks

The safety check that is supposed to stop an AI coding agent from running a dangerous command can be walked straight past using a shell trick that has been public for decades. New research from Adversa AI, which is named the bypass GuardFall, found it works against ten of the eleven popular open-source coding and computer-use agents the firm tested. Only one, "Continue," was built to defend against it. Why does it matter? These agents run shell commands with your full account access. Point one at a booby-trapped repository or software package, and a hidden instruction can quietly run a command that wipes files or steals the secrets your account can reach, from SSH keys and cloud credentials to anything sitting in your home folder. How does it get past the guard? Most of these agents try to stay safe by checking each command against a blocklist of dangerous patterns before running it. The flaw is that they check the command as plain text, while bash rewrites that text before it actually runs. The shell strips quotes and expands shortcuts, so the filter and the shell end up looking at two different things. The simplest example: a filter watching for rm sees nothing wrong with r''m, because to a text matcher those are different strings. Bash removes the empty quotes and runs rm anyway. The same idea works in other forms: a command hidden in base64 and piped into a shell, or ordinary tools like find and dd turned destructive with the right flag. The researchers call this not a bug but "a dangerous convention and a class of problems," which is why adding more blocklist patterns fixes none of it. There is no single CVE to track or patch. Two things have to line up for an attack to

AI agents seen reshaping <b>cybersecurity</b>

AI agents seen reshaping cybersecurity Experts urge for major paradigm shift to active immunity at forum in Beijing By Ma Si | China Daily | Updated: 2026-07-01 00:00 As artificial intelligence agents evolve from assistive tools into autonomous decisionmakers and executors, the traditional logic of cybersecurity defense is being fundamentally rewritten, experts and officials said. Li Bing, vice-chairman of the All-China Federation of Industry and Commerce, said the AI industry is at a critical juncture, transitioning from isolated technological breakthroughs to full-scale value creation. He called on private enterprises — as key drivers of technological innovation — to actively participate in the "AI plus" initiative, increase research and development investment, and accelerate the large-scale deployment and commercialization of foundation models and agent technologies, while adhering to security guardrails and ensuring that AI benefits humanity. Li made the comments at the 14th Internet Security Conference, also known as ISC. AI 2026, held in Beijing last week. Ren Xianliang, secretary-general of the World Internet Conference, said: "The development of AI agents must embed values of fairness, inclusiveness and security throughout the R&D and application process, while strengthening international rule-making and multilateral coordination to make AI agents a global public good that safeguards security and benefits all." Zhao Zhiguo, vice-chairman of the Internet Society of China and former chief engineer of the Ministry of Industry and Information Technology, called for a holistic approach to national security, urging stronger core technology R&D, improved tiered classification management and assessment mechanisms, and the establishment of security standards covering the entire lifecycle from development and deployment, to operations and maintenance. Wu Hequan, an academician from the Chinese Academy of Engineering, said that AI agent-driven attacks now exhibit autonomous decision-making, swarm coordination and continuous evolution. He argued that the security paradigm must shift from passive defense to active

Why Is <b>Cybersecurity</b> Company Intrusion Stock Soaring Today?

Intrusion Inc (NASDAQ:INTZ) shares are up almost 43% during Tuesday’s premarket session. On Monday, the company announced its acquisition of VigilAigent to enhance its cybersecurity offerings significantly. The company expects the acquisition to add approximately $3.5 million in annual recurring revenue from multi-year contracts. The deal will also add over 80 reseller partners and an installed base of around 1,000 customers to expand the company’s commercial footprint. The acquisition of VigilAigent will integrate its proprietary Agentic AI engine, The Oracle, with Intrusion’s TraceCop database, creating a more robust cybersecurity platform. This strategic move will bolster Intrusion’s capabilities in threat detection and response, positioning the company for future growth. As of March 31, 2026, Intrusion’s cash and cash equivalents stood at $1.4 million. What Intrusion Inc Does: Cybersecurity And Threat Intelligence The recent acquisition of VigilAigent is significant as it not only adds revenue but also enhances Intrusion’s technological capabilities in the rapidly evolving cybersecurity landscape. With the integration of VigilAigent’s AI-driven solutions, Intrusion is well-positioned to expand its market reach and improve its service offerings. INTZ Earnings Date, Estimates And Analyst Price Targets Intrusion is slated to provide its next financial update on August 11, 2026 (estimated). - EPS Estimate: Loss of 10 cents (Up from Loss of 10 cents) - Revenue Estimate: $1.57 million (Down from $1.90 million) Analyst Consensus & Recent Actions: The stock carries a Buy rating with an average price target of $5.25. Recent analyst moves include: - Ascendiant Capital: Buy (Lowers Target to $9.50) (June 8) - Ascendiant Capital: Buy (Lowers Target to $10.50) (April 9) - HC Wainwright & Co.: Neutral (Lowers Target to $1.00) (March 30) INTZ Price Action: Intrusion shares were up 26.86% at $0.86 during premarket trading on Tuesday, according to Benzinga Pro data. Photo via Shutterstock © 2026 Benzinga.com. Benzinga

Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data

New Microsoft research shows how attackers can hijack AI agents that act on a user's behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider. The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire. The work comes from Microsoft Incident Response and its Defender security research team, and it lands as companies start letting AI do more than read and summarize. What changes when an agent can act Until recently, the workplace AI risk was mostly framed around what a model read and wrote. A poisoned document could skew an answer, and that was mostly where it ended. Agents are different. Microsoft 365 Copilot can send email, create files, and change calendars. Custom agents built in Copilot Studio or Azure AI Foundry can reach into business systems and run multi-step jobs on their own. The same injection trick that biases a summary now triggers an action. Against a reader, an attack changes the output. Against an agent, it changes what the software actually does. These agents reach business systems through MCP, the Model Context Protocol, an open protocol that lets an AI call outside tools the way an app calls an API. Microsoft calls it the fastest-growing part of the agentic AI supply chain, which makes it an expanding attack surface. How the attack works Every MCP tool ships with a description: a few lines of plain text that tell the agent what the tool does and when to use it. The agent reads that text to decide how to act. That is the whole weakness. The description is just words, and words can carry instructions. Microsoft walks through it with an invoice example, built

Heart to Heart Hospice Strengthens <b>Cybersecurity</b> Through Partnership with CyberMaxx

Collaboration enhances protection of patient and employee information PLANO, Texas, June 30, 2026 /PRNewswire/ -- Heart to Heart Hospice, one of the country's largest private providers of hospice care, has partnered with CyberMaxx to strengthen the organization's cybersecurity capabilities and further protect sensitive patient and employee information. CyberMaxx provides healthcare-focused cybersecurity expertise, continuous security monitoring, endpoint detection and response capabilities, investigation support, and defined escalation pathways. The partnership complements Heart to Heart's internal information technology and security teams while adding specialized expertise and enhanced response capacity. Heart to Heart Hospice operates across more than 80 clinical and administrative locations in multiple states. The organization supports more than 2,800 employees and clinicians serving more than 4,500 patients. Many members of their care teams work in patients' homes and rely on secure, reliable access to technology throughout the day. "Our information technology and security teams recognize the importance of protecting patient, employee, and company information without interrupting patient care," said David Ewers, Senior Director of Information Technology for Heart to Heart Hospice. "With that responsibility in mind, we partnered with CyberMaxx to strengthen protection across the organization." The partnership is part of Heart to Heart's broader commitment to technology, modernization, operational resilience, and responsible growth. Over the past 18 months, the organization has grown by approximately 25 percent while continuing to expand its services into additional communities. About Heart to Heart Hospice Heart to Heart Hospice, founded in 2003, is one of the largest private providers of hospice care in the United States. Headquartered in the Dallas-Fort Worth Metroplex, Heart to Heart provides a broad range of hospice services to patients with life-limiting illnesses across 80 locations in multiple states. At Heart to Heart, we understand both the physical and emotional challenges for our patients and their loved ones and our compassionate

GAO Urges NTIA to Address Priority Recommendations on RF Spectrum, <b>Cybersecurity</b>

- GAO has identified 10 remaining priority recommendations for NTIA - Recommendations address spectrum management, cybersecurity and broadband programs - The 2026 FedCiv Summit on Oct. 29 will examine AI, cloud and more The Government Accountability Office has called on the National Telecommunications and Information Administration to implement its remaining priority recommendations, saying the actions could improve the agency’s operations across spectrum management, IT modernization, cybersecurity and broadband programs. As federal agencies continue advancing modernization efforts, government and industry leaders will gather at the Potomac Officers Club’s 2026 FedCiv Summit on Oct. 29 to discuss artificial intelligence deployment, cloud, data and compute infrastructure, workforce enablement, and cross-agency and enterprisewide programs. Sign up now and join experts as they discuss technologies and strategies shaping modernization initiatives across the federal civilian sector. In a report publicly released Monday, GAO said NTIA has implemented one of the 11 priority recommendations identified in July 2025, leaving 10 priority recommendations open as of May. What Are GAO’s Recommendations to Manage RF Spectrum & Cybersecurity Risks? GAO recommended that NTIA, in consultation with the Federal Communications Commission and other relevant federal agencies, monitor and update its collaboration guidance for radio frequency spectrum management. It also recommended that NTIA establish shared procedures for designing spectrum studies used during domestic and international spectrum management activities to strengthen interagency collaboration and better position the United States at international spectrum conferences. For spectrum infrastructure cybersecurity, GAO said NTIA relies on multiple custom IT systems that are outdated despite awarding modernization contracts in 2024. GAO recommended that the agency implement key planning and cybersecurity practices as it modernizes those systems to better support the success of its IT modernization efforts. What Is GAO’s Recommendation Regarding Federal Broadband Programs? GAO recommended that NTIA improve how it communicates the financial sustainability of broadband

AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks

Two researchers have found six security flaws in AirDrop and Quick Share, the wireless features that beam files between nearby devices with no cables or shared network. An attacker within wireless range, with just a laptop and no prior connection, can crash the sharing service on a Mac or iPhone set to receive from anyone, with no tap or prompt. The same research found Quick Share flaws that bypass Samsung's session checks and trigger a potentially exploitable crash in Google's Windows app. The two features run inside an ecosystem of more than five billion active Apple and Android devices, though the tested bugs hit specific implementations and versions. The work, laid out in a new research paper by Arash Ale Ebrahim and Nils Ole Tippenhauer of the CISPA Helmholtz Center for Information Security, is the first to pull both stacks apart side by side, above the radio layer, where discovery becomes session handling, parsing, and trust decisions. The fixes have already started. Apple has patched one of the three AirDrop bugs and assigned it a CVE, though the advisory is not yet public; the other two are still in coordinated disclosure. Google paid a bounty for the Windows flaw and has landed a code fix, with its CVE still pending. Samsung's two bugs were handed to Google and remain under investigation. No public reports of these flaws being exploited have surfaced as of this writing. Three ways to knock out Apple's sharing All three AirDrop flaws end in the same crash: they take down sharingd, the background service on macOS and iOS that handles AirDrop. The catch is that this service also runs AirPlay, Handoff, Universal Clipboard, Continuity Camera, and NameDrop, so one crash takes the whole set down together. The simplest of the three needs only a single malformed

New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker. The targets included OpenAI's ChatGPT Atlas, Perplexity's Comet, and Anthropic's Claude browser extension. An AI browser is one that can act for you, not just read pages. Switch it to agent mode, and it can click, type, and reach into the sites you are already signed into. That access is the whole point, and it is also the problem. The trick works because of how these agents read. The web page and your own instructions arrive as a single stream of text. That lets a malicious page slip in commands dressed up as ordinary content or game rules, and the agent cannot reliably tell the difference. Researchers call this indirect prompt injection. How the trick works The attack starts with a web page built as a puzzle. To fit its dystopian theme, the puzzle rewards wrong answers, like insisting that 2 + 2 = 5. Once the agent accepts that "wrong" is the winning move, it follows game logic instead of safety logic. The final step of the puzzle asks it to grab the user's credentials, and not one of the six agents flagged that as something it should refuse. The dangerous part is where the agent looks. In the test, a link was sent to the victim's work GitHub repository, where it pulled SSH login credentials and passed them to the attacker. LayerX used a harmless plaintext file, but the same trick could point the agent at other resources it can reach in that session: open tabs, signed-in accounts, and internal

2026 <b>Cybersecurity</b> Assessment Report

Breaches are being buried. AI is reshaping the risk landscape. Leaders and front-line practitioners are reporting different realities. To uncover what's really happening inside organizations, Bitdefender surveyed 1,200 IT and cybersecurity professionals about the changes, pressures, and priorities defining cybersecurity today. The full report goes deeper - more data, more peer benchmarks, more context for the decisions your team is navigating right now.

Why Identity Security Is Your Cyber Career Entry Point

Cybersecurity In-Depth: Feature articles on security strategy, latest trends, and people to know. Why Identity Security Is Your Cyber Career Entry Point As AI reshapes cybersecurity workflows, John Paul Cunningham, CISO at SIlverfort, says the technology is creating opportunities rather than eliminating jobs — and there are more ways than ever to break into the essential field. At a Glance - Despite AI automation of certain tasks like log analysis, cybersecurity still requires human oversight - Leadership foundations and physical security expertise from military service naturally complement cybersecurity roles - Professionals can leverage their existing strengths and backgrounds to find a path that fits in cybersecurity As organizations grapple with emerging threats and transformative, new technologies, John Paul Cunningham, chief information security officer (CISO) at SIlverfort, says demand for skilled security practitioners shows no signs of slowing — despite concerns that artificial intelligence might diminish career prospects for newcomers. In this latest Heard It From a CISO video series installment, Cunningham brings his perspective to these industry dynamics. With a background spanning military service, financial sector duty, and now his role in protecting Silverfort's corporate infrastructure, Cunningham shares with us the multifaceted nature of modern security leadership. The conversation around AI's impact on cybersecurity jobs has reached a fever pitch, with junior analysts questioning whether automation will render their skills obsolete. Yet industry veterans like Cunningham argue that this technological shift represents evolution rather than elimination. While AI excels at parsing massive log files and identifying patterns, the human element remains irreplaceable in areas requiring strategic thinking, stakeholder engagement, and adaptive problem-solving. Perhaps most striking is the field's accessibility through multiple entry points. Unlike many professions that demand a singular educational path, cybersecurity welcomes talent from technical backgrounds — audit and compliance roles, project management, law enforcement, and more. This

UAE Launches National Accelerator to Build Homegrown <b>Cybersecurity</b> Startups

UAE Launches National Accelerator to Build Homegrown Cybersecurity Startups The program aims to produce a new generation of national cybersecurity companies capable of developing innovative solutions that meet the needs of both local and international markets. News - UAE Launches National Accelerator to Build Homegrown Cybersecurity Startups - Employee Resistance to AI Becomes UAE Firms' Top Workforce Risk: Report - Apple’s AI Hardware Strategy Faces Pressure on Two Fronts - Saudi Arabia Launches AI Tourism Vision, Unveils TourismX Platform to Power Growth - Ford Rehires 350 Engineers After Finding AI Alone Wasn't Enough - $725 Billion Later, 91% Say Organizations Still Aren't Realizing AI's Full Value The UAE is reinforcing its national cybersecurity commitment with the launch of a national accelerator program dedicated to cybersecurity startups. The Khalifa Fund for Enterprise Development (KFED), in partnership with the UAE Government Cybersecurity Council, has launched a specialized program to produce a new generation of national cybersecurity companies capable of developing innovative solutions that meet the needs of both local and international markets. Unveiled during an MZN Hub Al Ain event, in the presence of Dr. Mohamed Al Kuwaiti, Head of Cyber Security for the UAE Government, and KFED CEO Mouza Obaid Al Nasri, the program has been developed in collaboration with CyberE71, the country’s flagship cybersecurity startup incubator. “Cybersecurity is no longer merely a technical sector; it has become a strategic driver of the digital economy and one of the fundamental pillars of the security and sustainability of societies,” said Dr. Al Kuwaiti. Building upon the existing memorandum of understanding (MoU) between KFED and the council, the initiative aims to attract, develop, and support cybersecurity startups through a comprehensive approach. The framework will provide startups with specialized mentorship, partnership-building opportunities, and access to experts, investors, and key industry stakeholders. Meanwhile, CyberE71 will