No-frills tech news

Media Tip Sheet: AI Set to Bypass <b>Cybersecurity</b> Systems in Months

WASHINGTON (June 30, 2026) – According to Five Eyes spy agency, advanced AI models are improving quickly enough to outperform cybersecurity systems within months. This has increased the likelihood of a hack on these systems. Security agencies like Britain, the United States, Australia, Canada, and New Zealand are encouraging businesses to prepare themselves as AI evolves. This concern also overlaps with national security. Earlier this month, Anthropic suspended access to their Mythos 5 model to comply with a U.S. national security order, proving that AI is becoming a security risk. For more analysis on these developments, please consider Scott J. White, Associate Professor and Director of the Cybersecurity Program and Cyber Academy at the College of Professional Studies. White is an expert in cybersecurity, cybercrime, counter-terrorism and infrastructure protection. He has worked for a variety of law enforcement agencies in the US, the UK and Canada, holds a Queen’s Commission, and was an officer with the Canadian Security Intelligence Service. To schedule an interview, please contact Nadia Payne at nadia [dot] paynegwu [dot] edu (nadia[dot]payne[at]gwu[dot]edu) or GW Media Relations at gwmediagwu [dot] edu (gwmedia[at]gwu[dot]edu). -GW-

Illumio is Redefining <b>Cybersecurity</b>

About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC

<b>Cybersecurity</b> jobs available right now: June 30, 2026

Cybersecurity jobs available right now: June 30, 2026 AI Offensive Security Engineer AGAPI | UAE | On-site – View job details As an AI Offensive Security Engineer, you will leverage AI and LLMs to accelerate offensive security research, exploit development, vulnerability discovery, and security automation. You will validate AI-generated findings through manual testing, conduct authorized security assessments, and produce high-quality technical reports and remediation guidance. AVP, Enterprise Authentication & Directory Services Synchrony | USA | Hybrid – View job details As an AVP, Enterprise Authentication & Directory Services, you will lead the modernization of enterprise identity by driving the transition from Active Directory to Microsoft Entra ID, architecting secure hybrid identity solutions, managing large-scale IAM transformation programs, and governing Entra ID security, lifecycle management, application integration, and advanced access controls. CISO Lumafield | USA | On-site – View job details As a CISO, you will define and execute the organization’s cybersecurity strategy, oversee secure cloud architecture and product security, embed security across the SDLC, lead compliance and risk management programs, strengthen incident response, support customer security engagements, and foster a security-first culture. Get weekly updates on new cybersecurity job openings. Subscribe here! Cloud Security Engineer Spotify | USA | On-site – View job details As a Cloud Security Engineer, you will design and implement cloud security best practices, integrate security across the software lifecycle, conduct threat modeling and risk assessments, enhance cloud security tooling, support incident response, and drive security improvements across engineering teams. Cloud Security Network SME vSecureLabs | USA | On-site – No longer accepting applications As a Cloud Security Network SME, you will design and implement secure multi-cloud solutions across Azure, AWS, and GCP, architect hybrid connectivity and cloud networking, implement Zero Trust and cloud security best practices, and automate infrastructure deployment using Infrastructure as Code. Cybersecurity

Hottest <b>cybersecurity</b> open-source tools of the month: June 2026

Hottest cybersecurity open-source tools of the month: June 2026 Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. OWASP Agent Memory Guard: Stop AI agents from being weaponized through their own memory AI agents keep memory across sessions. Conversation history, vector stores, scratchpads, and RAG indexes persist between runs, and anything written into that store becomes a privileged input the agent reads back later. An attacker who plants text in the wrong field can override an agent’s instructions, pull out user data, or steer future tool calls, and the effect survives across sessions because the memory does. Agent Memory Guard is an open-source runtime defense layer that sits between an agent and its memory store, screening every read and write through a pipeline of detectors and a YAML policy. Agent Threat Rules: Open detection rule format for AI agent security threats AI agents run inside coding assistants, MCP servers, and multi-agent frameworks, and the access that makes them useful also opens paths to prompt injection, tool poisoning, and credential theft. Public CVE feeds carry agent-execution flaws that reach production faster than the tooling built to catch them. Agent Threat Rules, or ATR, is an open detection format aimed at this category of attack. AgentGG: Open-source agentic SAST scanner Static analysis tools have spent years matching source code against known-bad patterns and handing engineers long lists of candidate issues to triage by hand. AgentGG approaches the same job with AI agents that read the code, follow imports, walk the call graph, and confirm a finding before they report it. The project is an open-source agentic SAST scanner released under the Apache 2.0 license. DockSec: Open-source AI-powered Docker security scanner DockSec is an OWASP Incubator Project

These Recent Insider Threat Allegations

Over the last week, there's been a lot of swirl from a former employee alleging an insider threat within Huntress: passionate posts, public thoughts, and even some conspiracy theory. As the CEO of a company I also co-founded, I've had a front row seat to a volatile situation mixing emotional connections, nuances of ethics, partial truths, US and UK employment law, and active investigations, all while maintaining empathy for all folks involved. Needless to say, this isn't simple and the court of public opinion hasn't made it easy. I think folks understand that I can't share every detail of what occurred (as much as I'd personally love to). Although the full picture supports the actions Huntress has taken, I am not willing to sacrifice teammate privacy, law enforcement efficacy, or our integrity for the sake of reckless transparency. With that said, I'm looking to thread a needle to give as much clarity as I can through the lens of what actually happened—and just as importantly, what did not. What Did Not Happen We've conducted multiple investigations and we have found no evidence of illegal conduct or an insider threat, and consulted law enforcement who reached the same conclusion. When concerns were raised, we audited our systems thoroughly and found no evidence that: unauthorized access occurred, partner or customer data was disclosed, nor that source code or operational data was exposed. There was no "insider caught by the FBI". Based on the totality of the information we have gathered, we concluded that our partners and customers were not at risk then, and we have no reason to believe they are now. What Happened (and can be shared) Huntress permits threat researchers to occasionally engage with threat actors when it's beneficial for proactive R&D and/or to support active investigations. We are aware

New security operations center helps combat <b>cybersecurity</b> issues

The Arizona Department of Homeland Security and the Maricopa County Community College District recently opened the new Central Regional Security Operations Center (RSOC) located at the Glendale Community College. The Central RSOC is the newest location in the state to help combat cybersecurity issues that come up in schools, towns, cities, tribal communities and more. While providing online security for different partners and agencies, it’s also giving real-world experience to students who want to pursue a career in the cybersecurity industry that’s in need of more workers. In the video player above, hear from interns and industry officials about how this new center will help with the workforce as well as the work they’re doing to help protect different communities.

OMB tells agencies to begin executing PQC transition by 2027

Getty Images/WANAN YOSSINGKUM Who will shape the future of AI in the United States? Commentary Read more Anthropic’s Mythos model found vulnerabilities in classified US government systems, official says Artificial Intelligence Read more

<b>Cybersecurity</b> Compliance and Risk Assessment (CCRA)

Cybersecurity Compliance and Risk Assessment (CCRA) Updated Supplier Cybersecurity Requirements in Exostar Following our recent notice, “Document Your CMMC Status in Exostar,” all active Lockheed Martin suppliers are required to submit their Cybersecurity Maturity Model Certification (CMMC) and cyber risk status. The Cybersecurity Compliance and Risk Assessment (CCRA) has been reinstated to include the risk assessment and must be completed in Exostar. - What is the CCRA: Lockheed Martin’s single process to assess suppliers’ compliance with cyber regulations and measure cyber risk, established in March 2024, is being reinstated as the primary cybersecurity form for all Lockheed Martin suppliers. It will include two parts: CCRA – Compliance and CCRA – Risk. - What is going to happen to the CCA: The Cybersecurity Compliance Attestation (CCA) was an interim form used to capture CMMC and DFARS compliance information given the Department of War’s aggressive CMMC implementation timeline. The CCA will be renamed to CCRA - Compliance on Jun. 30, 2026. CCRA – Compliance Survey Requirements The CCRA – Compliance survey is required for all Lockheed Martin suppliers and is part of their Exostar vendor profile Self-Certification. - Suppliers who have completed the interim CCA will have their responses automatically transferred to the CCRA – Compliance survey as part of this update. No action is required to complete this survey. - Suppliers who haven’t completed the CCA will be required to complete the CCRA – Compliance survey. CCRA – Risk Survey Requirements Upon completion of the CCRA – Compliance survey, the system will determine whether the CCRA – Risk is required. See LM Cybersecurity Requirements FAQ (questions 5 and 6) for details. - Suppliers that attested to having a CMMC Level 2 (Self or C3PAO) or higher assessment in SPRS, under question 4.0 of the CCRA – Compliance survey, will not need

House Passes Energy and Commerce Legislation to Strengthen Grid and <b>Cyber Security</b>

House Passes Energy and Commerce Legislation to Strengthen Grid and Cyber Security WASHINGTON, D.C. - Today, Congressman Brett Guthrie (KY-02), Chairman of the House Committee on Energy and Commerce, celebrated House passage of four bills that will harden the electric grid, clarify federal emergency leadership, and ensure smaller utilities have the resources they need to defend against increasingly sophisticated threats. The House passed H.R. 7257, the Securing Community Upgrades for a Resilient Grid (SECURE Grid) Act; H.R. 7258, the Energy Emergency Leadership Act; H.R. 7266, the Rural and Municipal Utility Cybersecurity Act; and H.R. 7305, the Energy Threat Analysis Center Act of 2026. Together these bills strengthen state energy security planning, establish clear Department of Energy (DOE) leadership during energy emergencies, reauthorize cybersecurity grants and technical assistance for rural and municipal utilities, and ensure there is a dedicated threat analysis center to improve intelligence sharing between the federal government and American energy producers. "As threats to our nation's energy infrastructure grow more frequent and more complex, it's essential that we strengthen our grid's security in order to keep our communities safe," said Chairman Guthrie. "These four bills provide critical solutions to help us meet the challenges we face. By strengthening our security planning, ensuring the Department of Energy has the leadership necessary to confront threats, providing utilities with the tools necessary to protect the grid, and supporting increased collaboration between grid operators and the federal government, we can stay ahead of adversaries and ensure reliable, secure energy for American families and businesses." "America's electric grid must be secure and resilient to ensure families and businesses have reliable access to affordable energy. From extreme weather to physical and cyber threats posed by our adversaries, protecting our nation's energy infrastructure is a matter of national security," said Chairman Latta. "That's why I

House Passes Miller-Meeks Bill to Strengthen <b>Cybersecurity</b> for Rural and Municipal Utilities

House Passes Miller-Meeks Bill to Strengthen Cybersecurity for Rural and Municipal Utilities WASHINGTON, D.C. — Today, the U.S. House of Representatives passed Congresswoman Mariannette Miller-Meeks' (IA-01) bipartisan Rural and Municipal Utility Cybersecurity Act, legislation to strengthen America's energy grid by helping rural electric cooperatives and municipal utilities defend against increasingly sophisticated cyberattacks. The legislation reauthorizes the Rural and Municipal Utility Advanced Cybersecurity Grant and Technical Assistance Program, providing critical resources to help smaller utilities deploy advanced cybersecurity technologies, strengthen information sharing, and protect the infrastructure millions of Americans rely on every day. The bill authorizes $250 million over five years to support these efforts. "America's electric grid is one of our most critical national assets, and cybercriminals and foreign adversaries know that" said Miller-Meeks. "Our rural electric cooperatives and municipal utilities play an indispensable role in powering our communities, yet they often face the same sophisticated cyber threats with far fewer resources. As those threats continue to evolve, Congress must ensure every utility has the tools it needs to defend critical infrastructure, protect American families and businesses, and strengthen our national security. I'm proud the House has passed this bipartisan legislation, and I urge the Senate to swiftly send it to the President's desk." As threats to our nation’s energy infrastructure grow more frequent and more complex, it’s essential that we strengthen our grid’s security in order to keep our communities safe,” said Energy & Commerce Chairman Guthrie. “These four bills provide critical solutions to help us meet the challenges we face. By strengthening our security planning, ensuring the Department of Energy has the leadership necessary to confront threats, providing utilities with the tools necessary to protect the grid, and supporting increased collaboration between grid operators and the federal government, we can stay ahead of adversaries and ensure reliable, secure

Laurel Lee legislation to strengthen power grid <b>cybersecurity</b> passes in House

The U.S. Energy Department could soon take on more cybersecurity and resiliency responsibilities. The House has passed Republican U.S. Rep. Laurel Lee’s Energy Emergency Leadership Act (HR 7258) to strengthen and secure the U.S. power grid. “The Energy Emergency Leadership Act strengthens our nation’s ability to prepare for and respond to threats to our electric grid by establishing clear leadership and accountability within the Department of Energy during energy emergencies,” Lee said. “As cyber threats against our nation’s critical energy infrastructure continue to grow, we need a federal government that is prepared to respond quickly and effectively. That leadership is especially important for Florida, where hurricanes and other severe weather events regularly test the resilience of our energy infrastructure. Reliable electricity is essential for our families, hospitals, military installations, businesses, and economy. This commonsense bipartisan legislation will help strengthen our nation’s energy resilience and ensure the federal government is prepared when emergencies occur.” The legislation was among several bills dealing with energy taken up on the House floor. The bipartisan bill passed on a voice vote, months after Lee carried the bill through the Energy and Commerce Committee. On the floor, U.S. Rep. Kathy Castor, a Tampa Democrat, touted the importance of the legislation as well. She noted the importance of the bill requiring a Senate-confirmed leader to direct the Office of Cyber Security, Energy Security, and Emergency Response. “As the grid becomes increasingly complex and faces a host of new challenges, it is critical that ensuring the security of the grid is managed by top officials,” Castor said. She said the Energy Department already plays a key role in addressing energy emergencies. The structural change means consistent and effective leadership will ensure proper response. The legislation will now head to the Senate for consideration. Should it pass, the bill

Mastercard Launches Africa <b>Cybersecurity</b> Center of Excellence to Help Secure the ...

Mastercard announced the launch of its Africa Cybersecurity Center of Excellence, a pan-African initiative designed to strengthen cyber resilience, enhance collaboration and help safeguard the trust that underpins Africa's expanding digital economy. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260629910205/en/ Michael Miebach, CEO, Mastercard unveiling The Cybersecurity Center of Excellence in Johannesburg, South Africa on Thursday, 25 June 2026. (Photo: AETOSWire) The announcement was made during a visit to South Africa and Nigeria by Mastercard CEO, Michael Miebach, reflecting Mastercard's long-term commitment to supporting Africa's digital transformation by helping organizations anticipate, withstand and recover from increasingly sophisticated cyber threats. The Cybersecurity Center of Excellence extends Mastercard’s expertise and network, bringing global competence and intelligence to one of the world's fastest-growing digital economies. This initiative follows through on commitments made in recent discussions with the Nigerian Government in Abuja, and the South African Government during last year’s G20 meetings in Johannesburg, to strengthen cybersecurity efforts in Africa. His Excellency, Cyril Ramaphosa, President of South Africa, said: “We recognize that for digitization to be inclusive, it must be trusted and secure. Mastercard has long been a trusted partner to South Africa, and its Cybersecurity Centre of Excellence is a welcome step to build on that foundation, drawing on the country’s best and brightest to meet a challenge no government or company can solve alone." His Excellency, Bola Ahmed Tinubu, GCFR, President of Nigeria, said: “As Nigeria deepens its digital transformation, secure and trusted systems will be critical to inclusion and growth. We welcome collaborations that strengthen our digital economy and build resilience for the future.” As digital adoption accelerates across Africa, cybersecurity has become an imperative for economic growth. No single organization can face today’s cyber threats alone. The Africa Cybersecurity Center of Excellence has been established to support

Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks

The China-aligned espionage group Mustang Panda is running two campaigns against the Indian government and hydropower targets, deploying new malware and turning a legitimate cloud service into its command channel. Acronis Threat Research Unit found active compromises inside Indian government networks, including machines used by senior administrative staff, and worked with CERT-In on notification and cleanup. The malware abuses Zoho WorkDrive, a cloud storage platform common in India's government sector, to pass commands and exfiltrate data. That is the whole idea: the traffic looks like ordinary cloud activity, so it hides inside the network it is stealing from. Acronis names three new tools. - SHARDLOADER is a loader that runs by sideloading a malicious DLL through a legitimately signed binary, a Solid PDF Creator executable in one campaign, and a Citrix Receiver binary in the other. It deploys one of two implants. - MINIRECON is a reworked variant of the Toneshell backdoor documented by IBM X-Force, now beaconing over a WebSocket connection on HTTPS. - ZOHOMURK is the novel piece: it carries hardcoded Zoho OAuth credentials and uses them to run an attacker-controlled WorkDrive account as a dead drop, reading commands from an inbox folder and writing stolen output to an outbox. Both campaigns arrive as ZIP archives with the malicious DLL marked hidden. Acronis believes they were delivered by spear-phishing. The lures fit the targets: one themed around a hydropower cooperation proposal, the other around a memorandum of understanding between Indian and Taiwanese institutions. Per Acronis, the goal is intelligence on India's hydropower plans and its defense ties with Taiwan. Acronis attributes the activity to Mustang Panda with high confidence. The report includes the reused Solid PDF Creator sideloading chain, code overlap with Toneshell, command servers sitting in the same network block as infrastructure IBM X-Force tied to the

How Marshall University Is Preparing Students for an Evolving <b>Cybersecurity</b> Workforce

What Is a Security Operations Center? It’s a staple of cinema: a darkened room full of people bent over computers, their faces lit by screens displaying an array of impending dangers. A SOC is similar in energy: Analysts pore over potential threats, flag suspicious activity and escalate concerns to protect the company’s data. “The security operations center and the people within are where the initial steps and triage happen,” explains Alexandria Donathan, executive director of the Institute for Cyber Security. Regardless of industry — whether it’s healthcare, finance, real estate, education, manufacturing or a government agency — everything has systems, data and information to protect. A SOC analyst is the gatekeeper for these systems. “A good SOC analyst is not valuable just because they understand technology. They also have to be curious, patient and able to make good decisions. They need to ask the right questions, follow the evidence, write down what they find and know when something needs to be escalated,” explains Lanham. “When they do that well, they can help an organization catch problems early, respond faster and avoid a much larger incident.” DISCOVER: Quantifying risk can help justify cybersecurity investments. SOC Project Illustrates the Value of Industry Partnerships In 2025, Marshall University announced its partnership with Intuit — something that Donathan believes higher education needs more of. “Industry and academia work together to align education with real, operational workforce demands, and with that, students graduate with applied learning skills they’re ready to use on day one,” she says. This June, Intuit launched a SOC at Marshall University. The partnership covers the cost of two full-time employees who will be working out of a shared space on campus until the new Institute for Cyber Security building is finished in August 2027. Beyond securing the physical space, the institute

How Marshall University Is Preparing Students for an Evolving <b>Cybersecurity</b> Workforce

What Is a Security Operations Center? It’s a staple of cinema: a darkened room full of people bent over computers, their faces lit by screens displaying an array of impending dangers. A SOC is similar in energy: Analysts pore over potential threats, flag suspicious activity and escalate concerns to protect the company’s data. “The security operations center and the people within are where the initial steps and triage happen,” explains Alexandria Donathan, executive director of the Institute for Cyber Security. Regardless of industry — whether it’s healthcare, finance, real estate, education, manufacturing or a government agency — everything has systems, data and information to protect. A SOC analyst is the gatekeeper for these systems. “A good SOC analyst is not valuable just because they understand technology. They also have to be curious, patient and able to make good decisions. They need to ask the right questions, follow the evidence, write down what they find and know when something needs to be escalated,” explains Lanham. “When they do that well, they can help an organization catch problems early, respond faster and avoid a much larger incident.” DISCOVER: Quantifying risk can help justify cybersecurity investments. SOC Project Illustrates the Value of Industry Partnerships In 2025, Marshall University announced its partnership with Intuit — something that Donathan believes higher education needs more of. “Industry and academia work together to align education with real, operational workforce demands, and with that, students graduate with applied learning skills they’re ready to use on day one,” she says. This June, Intuit launched a SOC at Marshall University. The partnership covers the cost of two full-time employees who will be working out of a shared space on campus until the new Institute for Cyber Security building is finished in August 2027. Beyond securing the physical space, the institute

Chairman Guthrie Delivers Remarks on Four Pieces Legislation to Strengthen the Safety ...

Chairman Guthrie Delivers Remarks on Four Pieces Legislation to Strengthen the Safety and Cyber Security Reliability of American Energy WASHINGTON, D.C. - Today, Congressman Brett Guthrie (KY-02), Chairman of the House Committee on Energy and Commerce, delivered remarks on the House floor regarding H.R. 7257, the Securing Community Upgrades for a Resilient Grid (SECURE Grid) Act, H.R.7258, the Energy Emergency Leadership Act, H.R. 7266, the Rural and Municipal Utility Cybersecurity Act, and H.R.7305, the Energy Threat Analysis Center Act of 2026. These bills strengthen the cybersecurity of America's grid to ensure the safe and reliable delivery of energy to communities across the country. Chairman Guthrie's remarks on H.R. 7257, the Securing Community Upgrades for a Resilient Grid (SECURE Grid) Act, as prepared for delivery: "I rise in support of H.R. 7257 the SECURE Grid Act, sponsored by my colleague and Energy Subcommittee Chairman from Ohio's 5th Congressional District. "State Energy Security Plans are an important tool for states to consider vulnerabilities in their energy systems. "The interconnected nature of our energy systems requires constant information sharing and cohesive planning to assess, identify, and address potential threats. "During this historic period of exponential demand growth caused by next generation industries, we need to be even more vigilant against adversaries that seek to undermine U.S. competitiveness. "The SECURE Grid Act is a timely bill that will enhance a state's ability to manage the security of their energy systems. "H.R. 7257 will improve visibility into an evolving threat landscape while ensuring that experts in the energy field can help provide critical insights into complex engineering operations. "As technology improvements have the potential to positively transform our economy, these tools can also be used and exploited by bad actors. "This bill will ensure that states remain on the cutting edge of innovation and security.

China's AI Matches Anthropic in <b>Cybersecurity</b>, Causing Worry Over US Restrictions

China's AI Matches Anthropic in Cybersecurity, Causing Worry Over US Restrictions (msn.com) 32 Chinese AI systems "have matched the performance of Anthropic's powerful model Mythos in some cybersecurity scenarios," reports the Wall Street Journal. They call it "a development poised to reset the global tech race and pressure the White House in its overhaul of U.S. AI policy." Security researchers said that a new AI model, released this month by China's Zhipu AI, also known as Z.ai, can match the latest U.S. models when it comes to finding security bugs, although it still lags behind Anthropic's and OpenAI's products in other tasks. Overall, the capability gap between top U.S. models and those built by Chinese companies has narrowed significantly, and use of Chinese AI systems has surged as businesses seek to rein in runaway costs. A host of companies, including Microsoft, are weighing how they can offer Chinese models on their platforms, a development that is set to alter the balance of power among tech companies... Unlike models from Anthropic or OpenAI, Zhipu's GLM-5.2 is open-weight. That means it can be downloaded and run on hardware operated by anybody and can be modified and used without supervision. Open-weight models are ideal for users who want unfettered access to systems they control, but they are also ideal for hackers, who can run them in the shadows. GLM-5.2 has ranked as one of the 10 most-used AI models, according to data from OpenRouter, a company that provides access to more than 400 AI models. In some benchmarking tests, according to the cybersecurity company Semgrep, GLM-5.2 bested Anthropic's Claude Opus 4.8 model, which was released in May. When given further instructions, Opus 4.8 and GLM-5.2 can match Mythos in bug-finding ability, according to researchers... "Banning Fable while selling chips China needs to develop

Z.ai Matches Mythos on <b>Cybersecurity</b> Bug-Finding | Let's Data Science

Practitioner takeaway When an open-weight model reaches frontier-adjacent performance on vulnerability discovery with no access controls or gating, the practical threat model for security teams changes immediately. Unlike Anthropic's Mythos - which sits behind subscription gates, geographic restrictions, and US export controls enacted June 12, 2026 - GLM-5.2 runs locally under an MIT license with safety controls that can be removed, fine-tuned away, or replaced. This compresses the operational timeline for both defensive tooling and offensive exploitation, and it forces an update to any threat model that relied on access friction to constrain capability. What the benchmarks show Two independent security evaluations provide the primary evidence for the parity claim. Semgrep, a security tooling company, published benchmark results on June 22, 2026, comparing models on IDOR (Insecure Direct Object Reference) detection. GLM-5.2 scored 39% F1, ahead of Claude Code (32%), though still below Semgrep's own multimodal pipeline (53-61% F1). Graphistry ran a separate evaluation on the CyBT-CTF benchmark - a capture-the-flag evaluation set used by security researchers - and found GLM-5.2 matched Opus 4.8 on solve rate, making it the first open-weight model Graphistry said it would recommend for a "frontier-like" cybersecurity experience. The Wall Street Journal first brought these evaluations to a broad audience, describing the results as a meaningful narrowing of the US-China gap in security-relevant model capabilities. Distillation concern Graphistry researchers flagged a statistical anomaly that may help explain the rapid capability gain: GLM-5.2's outputs correlated unusually highly with both GPT-5.5 and Opus 4.8 responses on identical prompts, with Cohen's Kappa values of 0.80 and 0.76 respectively, against a baseline of 0.63 between the two US models. Graphistry described this pattern as consistent with knowledge distillation - a technique where a model is trained on the outputs of a larger proprietary one, violating the terms of service

Fortifying your future: Key drivers for embracing managed <b>cybersecurity</b> services

In Malaysia’s evolving digital landscape, many organizations proudly display certificates like ISO 27001, SOC 2 or PCI DSS compliance. These framed accolades and passed audit reports reassure customers, regulators and even leadership that cybersecurity is under control. Yet, despite these certifications, cyber breaches continue to occur. When incidents happen, a common and painful question arises from senior leadership: “How could this happen if we were compliant?” The uncomfortable truth is that compliance is not the same as cybersecurity. Treating compliance as the ultimate goal rather than a byproduct of genuine security efforts creates a dangerous illusion of safety, one that cyber attackers are adept at exploiting. This misunderstanding represents one of the most significant hidden risks facing Malaysian boards and executives today. Compliance and security address fundamentally different challenges. The audit gap: Evidence vs. effectiveness Compliance is about proving that controls are documented and in place. It’s a process of ticking boxes to demonstrate adherence to standards and regulations. Cybersecurity, on the other hand, is about having those controls work to protect the organization. It’s entirely possible — and increasingly common for organizations to pass audits and still have critical vulnerabilities. For example, a company might have successfully passed its SOC 2 or ISO 27001 audit, with auditors signing off on their controls, yet still have unpatched critical systems, privileged accounts without multi-factor authentication or incident response plans that exist only on paper or unresolved findings from failed penetration tests. This gap exists because audits focus on evidence rather than effectiveness. To put it simply, an audit might ask, “Do you have a password policy?” and be satisfied with a written document. Meanwhile, a security team asks, “Are people actually using strong passwords, and can attackers bypass them?” A policy on paper satisfies compliance, but only phishing-resistant controls stop attackers.