No-frills tech news

Sectra awarded framework agreement for operational <b>cybersecurity</b> of critical infrastructure ...

Sectra awarded framework agreement for operational cybersecurity of critical infrastructure in Sweden Linköping, Sweden – July 6, 2026 – International medical imaging IT and cybersecurity company Sectra (STO: SECT B) has been awarded a framework agreement by the Swedish Agency for Civil Defense (MCF) following a public tender process. The framework agreement covers security monitoring in real time for organizations subject to the EU cybersecurity directive NIS 2. More precisely, it encompasses security monitoring services for Operational Technology (OT) environments, IT security monitoring for smaller organizations as well as external network surveillance. The framework agreement enables efficient procurement of security monitoring services through MCF and the arrangement is part of the establishment of Sweden's national Security Operations Center (SOC-SE), aiming to increase operational cybersecurity for critical entities of our society and their operations. "This is a strategically important assignment for Sectra. Being able to contribute to strengthening Sweden's operational cybersecurity and protecting critical infrastructure is both a responsibility and a testament to our expertise," says Gustav Sandberg, President of Critical Infrastructure at Sectra. “We are honored by the trust placed in Sectra and we look forward to supporting those critical entities and thereby strengthening Sweden’s Total Defense capabilities.” Through this framework agreement, valid for up to four years, services are enabled that strengthen the ability of critical societal functions to detect and respond to cyber threats and potential attacks at an early stage. Sectra’s services include real-time security monitoring of IT and OT environments, analysis of security alerts and incidents, proactive threat hunting as well as continuous development of detection capabilities. The services are delivered through Sectra’s 24/7 Security Operations Center (SOC), where large volumes of log data are analyzed to rapidly identify and manage threats in close collaboration with the customer organizations. Similar framework agreements are signed with a

Study finds most Businesses ask Employees to conceal Data Breaches

Cybersecurity experts and law enforcement agencies consistently advise organizations to report data breaches as soon as they are discovered. Timely disclosure allows authorities to investigate incidents, helps affected organizations limit financial and operational damage, and raises awareness among employees and stakeholders about emerging cyber threats. In many regions, data protection laws also require companies to notify regulators and impacted individuals within specified timeframes after a security incident. Despite these recommendations and legal obligations, a recent study suggests that many organizations are still reluctant to be transparent about cybersecurity incidents. According to research conducted by cybersecurity company Bitdefender, a significant number of cybersecurity professionals have been asked by their employers to conceal or avoid reporting data breaches. Such practices can delay incident response, increase the impact of attacks, and expose businesses to greater legal and reputational risks. The study also highlights growing concerns about the role of artificial intelligence (AI) in modern cyberattacks. While AI has become an essential tool for strengthening security defenses, many professionals believe cybercriminals are currently gaining greater advantages from the technology. Attackers are increasingly using AI to automate phishing campaigns, generate convincing social engineering messages, identify system vulnerabilities, and launch more sophisticated attacks at scale. As AI capabilities continue to evolve, security experts expect cyber threats to become even more advanced and difficult to detect. Another key finding from the Bitdefender report is the communication gap developing between business leaders and cybersecurity teams. Around 55% of employees surveyed said they had been discouraged or prevented from openly discussing security breaches within their organizations. This culture of silence can undermine an organization’s ability to respond effectively to cyber incidents, as delayed reporting often gives attackers more time to expand their access and cause additional damage. The survey further revealed that cyberattacks remain a persistent challenge for organizations

These are the Corporate Cyber Threats that need immediate Mitigation

Cyber threats have become one of the biggest operational risks facing organizations of every size. As businesses accelerate digital transformation and rely more heavily on cloud computing, remote work, and connected devices, cybercriminals continue to develop more sophisticated attack techniques. The financial losses, regulatory penalties, and reputational damage resulting from a successful cyberattack can take years to recover from, making proactive cybersecurity an essential business priority. One of the most pressing threats facing enterprises today is ransomware. Modern ransomware attacks no longer focus solely on encrypting files. Attackers increasingly steal sensitive data before locking systems, using the threat of public disclosure to pressure organizations into paying large ransoms. Critical industries such as healthcare, finance, manufacturing, and government remain frequent targets because service disruptions can have severe consequences. Regular data backups, network segmentation, and endpoint detection solutions are essential to reduce the impact of ransomware incidents. Phishing and business email compromise (BEC) attacks also continue to evolve. Cybercriminals now use artificial intelligence to craft highly convincing emails, fake invoices, and executive impersonation messages that are difficult to distinguish from legitimate communications. Employees remain the first line of defense, making regular cybersecurity awareness training and multi-factor authentication (MFA) vital safeguards against credential theft and financial fraud. Cloud security is another growing concern as organizations migrate applications and sensitive data to public and hybrid cloud environments. Misconfigured storage services, weak access controls, and compromised administrator accounts can expose confidential information to attackers. Businesses should implement a zero-trust security model, continuously monitor cloud environments, and enforce strict identity and access management policies to minimize these risks. Supply chain attacks have emerged as one of the most challenging cybersecurity threats in recent years. Instead of attacking a large organization directly, threat actors compromise software vendors, managed service providers, or other trusted third parties to gain

DICT brings <b>cybersecurity</b> awareness to over 1700 learners in Siargao

SURIGAO CITY, Surigao del Norte (PIA) — The Department of Information and Communications Technology (DICT) Caraga, in partnership with the municipal government of Del Carmen, Siargao Island in Surigao del Norte, conducted a series of cybersecurity and cyber-hygiene awareness sessions for 1,733 students from various secondary and elementary schools of the town. The activity, held on June 9-11, formed part of the DICT’s double celebration for its 10th year anniversary and the observance of National ICT Month, strengthening its commitment to build a safer, more secure, and digitally empowered Philippines. On June 9, DICT Caraga held sessions for 1,074 participants from Del Carmen National High School and the elementary schools of Katipunan, Esperanza, Cancohoy, Bagacay, and Jamoyaon at the Del Carmen and Katipunan covered courts. It was followed by a campaign on June 10 that engaged the 390 participants from Oguing National Memorial National High School, Sayak Elementary School, Mahayahay Elementary School, Anitapolo Elementary School, Bitoon Elementary School, and Cabugao Elementary School. Sessions were held at the Oguing NHS Covered Court and the Cabugao Covered Court. On June 11, DICT Caraga directly served 269 more learners from Mariano Matugas Memorial National High School, Tuboran Elementary School, Quezon Elementary School, Numancia Central Elementary School, and Mabuhay Primary School. Sessions took place at the MMMNHS and NCES Covered Courts. DICT Caraga officials said that during awareness sessions, participants learned about the Internet and its consequences. The sessions highlighted both opportunities and risks in today’s digital environment. Students also practiced cyber hygiene, including creating strong passwords, securing accounts, updating devices, and browsing safely. They added that the discussions achieved several key outcomes, namely, promoted responsible online behavior, addressed cyberbullying, and emphasized the protection of personal information. The sessions also increased awareness of digital footprints and guided identifying threats such as scams, phishing, identity

Omnigent: Open-source AI agent framework and meta-harness

Omnigent: Open-source AI agent framework and meta-harness Plenty of developers now keep several coding agents close at hand, reaching for Claude Code on one task and Codex or Cursor on the next. Each tool arrives with its own command line, its own handling of credentials, and its own way of running shell commands against a working directory. That spread leaves teams with a governance gap around where agent actions land and how much they cost. Omnigent, an open-source project, sits one level above those tools as a meta-harness. The common layer drives Claude Code, Codex, Cursor, OpenCode, Hermes, Pi, and agents a team writes in YAML, and a user swaps or combines them with one-line changes. Omnigent draws on a first-party API key, a Claude or ChatGPT subscription, or any compatible gateway such as OpenRouter, with a per-agent default a user can switch mid-session. A single session follows the user from a terminal to a browser to a phone, with messages, sub-agents, terminals, and files in sync. Guardrails set at the harness layer The security design centers on policies. A policy governs what an agent may do across shell commands, file edits, and token spend, and it checks every action to allow it, block it, or pause for a person’s approval. Spend caps and access limits ship as builtins, so a session can carry a hard dollar ceiling with a softer warning along the way. These checks run at the meta-harness layer as stateful, data-centric rules that track agent actions, which keeps enforcement out of the prompt where an agent might drift past it. Policies stack across three levels. An administrator sets server-wide rules, a developer sets per-agent rules, and the person in a session sets per-session rules, with the stricter session rules checked first. A team can write a

DMCC Cyber Hub Launch: Dubai Free Zone Unveils New <b>Cybersecurity</b> Vertical as Tech ...

New DMCC Cyber vertical will support more than 200 cybersecurity companies Dubai: DMCC has launched DMCC Cyber, a dedicated cybersecurity vertical, after its technology sector crossed 4,000 companies and became the largest and fastest-growing segment in the business district. The new vertical will support more than 200 cybersecurity companies operating across cyber resilience, digital trust, data protection, identity, and governance, risk and compliance. Get updated faster and for FREE: Download the Gulf News app now - simply click here. DMCC Cyber has been launched alongside the formal establishment of DMCC Tech, an overarching technology platform that brings together the district’s specialist centres and technology communities. “Technology has become the largest and fastest-growing sector in our business district, reflecting Dubai's position as one of the world's leading destinations for innovation and high-growth businesses," said Ahmed Bin Sulayem, Executive Chairman and CEO, DMCC. "As that community has expanded, so too has the need for more specialised platforms that support different segments of the technology economy. DMCC Tech brings these communities together under a single ecosystem, while DMCC Cyber reflects the growing importance of cybersecurity in an increasingly digital world.” DMCC Cyber joins the DMCC AI Centre, DMCC Crypto Centre and DMCC Gaming Centre under the DMCC Tech platform, with DMCC Quantum set to follow. The platform gives technology companies access to DMCC’s wider business community of more than 26,000 member companies across global trade, finance, commodities and emerging technologies. DMCC said the platform is already home to companies including CrowdStrike, PwC, CYFIRMA and FPT Software, reflecting the scale and international reach of its technology community. DMCC Tech spans artificial intelligence, cybersecurity, blockchain, gaming and emerging technologies, while also extending into the rapidly developing space economy. The district said advances in satellites, earth observation and space-derived data are reshaping sectors such as trade,

Pennington County closes most public-facing offices Monday amid <b>cybersecurity</b> incident

Pennington County closes most public-facing offices Monday amid cybersecurity incident RAPID CITY, S.D. (KOTA) - Most Pennington County public-facing offices will be closed Monday as officials respond to a cybersecurity incident affecting portions of the county’s network. County officials said the closures will allow staff to assess the situation and safely restore affected systems. Several essential services will remain operational, including 911 Dispatch, the Pennington County Jail, the Juvenile Services Center, the Care Campus and other public safety operations. Court operations, the 24/7 Program and early voting at the Pennington County Auditor’s Office will also continue as scheduled from 7 a.m. to 4 p.m. Residents needing vehicle registration services can still use South Dakota’s online registration portal or self-service kiosks. County officials said the full scope of the cybersecurity incident is still being determined. Pennington County is working with the South Dakota National Guard Cyber Incident Response Team, the South Dakota Fusion Center, the Cybersecurity and Infrastructure Security Agency and other partners as the investigation continues. Because the investigation remains active, officials said they have limited verified information available at this time. The county expects to provide its next public update by 11 a.m. Monday. See a spelling or grammatical error in our story? Please click here to report it. Do you have a photo or video of a breaking news story? Send it to us here with a brief description. Copyright 2026 KOTA. All rights reserved.

Most Pennington County offices close due to <b>cybersecurity</b> attack

RAPID CITY, S.D. – Pennington County is responding to a cybersecurity incident affecting portions of the network. A news release from the Pennington County State’s Attorney’s Office says most public-facing County offices will be closed on Monday, July 6, 2026, while the County works to restore systems safely and assess the situation. The following services are still operational: - Critical life safety services, including: 911 dispatch, the Pennington County Jail, Juvenile Services Center, the Care Campus, and other public safety operations. - Court operations - The 24/7 Program - Early voting at the Pennington County Auditor’s Office from 7 a.m. to 4 p.m. - Vehicle registration remains available online at my605drive.sd.gov and at self-service kiosks. The full scope of the incident is still being determined, and Pennington Co. is working closely with the South Dakota National Guard Cyber Incident Response Team, the South Dakota Fusion Center, the Cyber Infrastructure Security Agency, and other partners as the investigation continues.

Pennington County closes most public-facing offices Monday amid <b>cybersecurity</b> incident

Skip to content News Livestream Local Weather Sports We the People Submit Photos and Videos Digital Advertising Home Livestream News KOTA Cares Agriculture Business Community Crime Economy Education Environment Fine Arts Health/Medical Law Enforcement Local Medical Military National Regional Science State Sturgis Rally Technology Video Pets of the Week Weather Download Our Weather App Closings Weather Cams Weather Blog KOTA Territory Mornings Mixology at Home Food & Drink Mr. Food Where In the Hills is Mimi? Live Performances Sports Black Hills Play by Play RC Marshals Games Pigskin Preview Big Ol Fish Friday Night Hike Athlete Of The Week Futbol Frenzy Politics Political Pulse Election Results Community Calendar Contests Contact Us Meet the Team Careers Submit a Tip Submit Photos and Videos Digital Advertising Programming Schedule NextGen TV Newsletter Support Local Business Circle Country Local News Live InvestigateTV Watching Your Wallet PowerNation Gray AI Policy Pennington County closes most public-facing offices Monday amid cybersecurity incident Published: Jul. 5, 2026 at 10:25 PM CDT | Updated: 6 hours ago Share Add Us On Google Add as a preferred source on Google News Rapid City police arrest 10 for DUI ahead of Fourth of July holiday Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News Chamber Music Festival’s “Celebration of Strings” gives area students fast-track performance experience Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News Monthly comics club meetups take off at Goblin Comics in Rapid City Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News CASA raffle fundraiser offers chance to win playhouse built by local partners Updated: 6 hours ago 10 PM KOTA Territory News - Sunday News Rapid City man identified as victim in fatal Highway 40 crash near Hermosa Updated: 6 hours ago

To Catch a Hacker, Think Like One: The Nuance in Modern <b>Cybersecurity</b>

To Catch a Hacker, Think Like One: The Nuance in Modern Cybersecurity The old adage in cybersecurity is straightforward: to catch a hacker, you must think like one. But there's a critical nuance today. It's no longer enough to merely adopt an attacker's mindset within your own four walls. You must see the entire sprawling, interconnected ecosystem the way a hacker does — because that's exactly how they operate. The Fortress Mentality That No Longer Holds Traditional cybersecurity was built on the logic of a medieval castle. A company had clear boundaries: insiders inside, outsiders outside. The mission was simple — fortify the perimeter, monitor the walls, and keep threats at bay. This approach worked reasonably well when operations were centralized in on-premises data centers that physically fit "in one server rack" (an exaggeration, but the point stands). Then everything changed. Outsourcing blurred the lines. Cloud adoption dissolved them entirely. Today, we're entering an agentic economy, where autonomous AI agents roam external services, call APIs, and hold broad permissions — often acting while you sleep. As explored in analyses of prompt injection attacks, these agents can be socially engineered much like the classic "grandma at the ATM" scam, turning helpful tools into unwitting accomplices. Yet the murkiest and most dangerous element isn't the flashy new tech. It's the old-school contractors and third parties. The Hidden Weak Links: Contractors and the Supply Chain Large enterprises work with dozens or hundreds of external partners: accounting outsourcers, CRM vendors, legal firms, ERP integrators, and more. Each is a separate organization with its own infrastructure, security posture, and priorities. You can influence it through contracts, but you can't control it. Hackers figured this out long before the industry fully adapted. Why batter down a heavily fortified corporate firewall when you can slip through a

Apple Products Multiple Vulnerabilities

Apple Products Multiple Vulnerabilities Release Date: 6 Jul 2026 623 Views RISK: Medium Risk TYPE: Operating Systems - Mobile & Apps Multiple vulnerabilities were identified in Apple Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, sensitive information disclosure, data manipulation and security restriction bypass on the targeted system. Impact - Denial of Service - Information Disclosure - Security Restriction Bypass - Data Manipulation System / Technologies affected - Versions prior to iOS 26.5.2 and iPadOS 26.5.2 - Versions prior to macOS Tahoe 26.5.2 - Versions prior to Safari 26.5.2 Solutions Before installation of the software, please visit the vendor web-site for more details. Apply fixes issued by the vendor: - iOS 26.5.2 and iPadOS 26.5.2 - macOS Tahoe 26.5.2 - Safari 26.5.2 Vulnerability Identifier - CVE-2026-28979 - CVE-2026-39868 - CVE-2026-39872 - CVE-2026-43663 - CVE-2026-43676 - CVE-2026-43699 - CVE-2026-43700 - CVE-2026-43701 - CVE-2026-43703 - CVE-2026-43704 - CVE-2026-43705 - CVE-2026-43706 - CVE-2026-43707 - CVE-2026-43708 - CVE-2026-43709 - CVE-2026-43712 - CVE-2026-43713 - CVE-2026-43715 - CVE-2026-43716 - CVE-2026-43717 - CVE-2026-43718 - CVE-2026-43720 - CVE-2026-43721 - CVE-2026-43722 - CVE-2026-43724 - CVE-2026-43725 - CVE-2026-43726 - CVE-2026-43727 - CVE-2026-43731 - CVE-2026-43732 - CVE-2026-43734 - CVE-2026-43735 - CVE-2026-43740 - CVE-2026-43742 - CVE-2026-43743 - CVE-2026-43745 - CVE-2026-43746 Source Related Link Related Tags Share with

Palo Alto Networks and Koi Security sued over alleged AI error in cyber threat report | Ctech

Palo Alto Networks and Koi Security sued over alleged AI error in cyber threat report MeetingTV claims a flawed intelligence classification led to global blocking of its services. A cybersecurity report intended to map Chinese-linked espionage activity has escalated into a legal dispute spanning Silicon Valley and Israel, after a U.S. startup alleged it was wrongly identified as part of a hostile network due to an artificial intelligence error. In March, U.S. media company MeetingTV filed a lawsuit in federal court in Southern California against cyber firm Koi Security, and its four Israeli founders, Amit Assaraf, Idan Dardikman, Tuval Admoni, and Gal Hachamov. Cybersecurity giant Palo Alto Networks, which acquired Koi in April for hundreds of millions of dollars, was added as a defendant in May 2026. At the center of the lawsuit is the claim that a flawed artificial intelligence system at the cybersecurity company caused the complete destruction of legitimate business activity due to what is known as “AI hallucination.” According to the complaint, at the end of December 2025, Koi Security published a threat intelligence report titled “DarkSpectre: Unmasking the Threat Actor Behind 8.8 Million Infected Browsers,” which examined espionage and cyber infrastructure linked to an attack group allegedly operating under Chinese state direction. As part of the report, Koi added the domain of MeetingTV to its IOC (Indicators of Compromise) list, effectively marking the company as part of a Chinese-linked espionage infrastructure. MeetingTV claims the classification was fundamentally incorrect and did not stem from traditional forensic investigation, but rather from an erroneous output generated by Koi’s proprietary AI system, “Wings.” The plaintiff alleges that Koi negligently published the findings without sufficient human oversight or verification. The consequences, according to the lawsuit, were immediate and severe. Once the report circulated in the cybersecurity community, security vendors, enterprise

Harnessing AI in <b>cybersecurity</b>: Ways companies can stay ahead of AI-driven threats

While cybersecurity companies leverage AI to enhance threat detection, cybercriminals are weaponizing the same technology for automated phishing and malware attacks —highlighted by the fact that 43 percent of organizations believe hackers are using AI-driven methods to boost their effectiveness. To stay protected, organizations must adopt AI-powered platforms rather than relying on isolated tools. Artificial intelligence has firmly established its presence in enterprise cybersecurity. According to data from Kaspersky’s 2026 global study, almost 100 percent of organizations in APAC – including firms in markets like Singapore, Indonesia, and Vietnam – intend to incorporate AI into security operations. This is consistent with solution providers embedding AI into their workflows to accelerate detection, reduce analyst workload and counter-attacks that move faster than human responders can manage. On the other hand, cybercriminals are using it to automate reconnaissance, generate convincing phishing content and scale operations that would previously have required significant resources and expertise. This symmetry is the challenge. Every AI-driven capability available to cybersecurity providers is also available, or adaptable, to attackers. According to Kaspersky data, 21 percent of organisations believe cybercriminals are ahead in the technology arms race, with 43 percent saying criminals are able to adopt new technologies like AI to increase the effectiveness of their attacks. Security leaders need to understand how AI is being weaponized, invest in AI-powered protection that is genuinely integrated into daily security workflows and approach the organisational and technical challenges of AI implementation with the same rigour applied to any critical infrastructure decision. AI-based threats: How cybercriminals are using AI The adoption of AI by threat actors is systematic. Attackers are integrating generative AI across the full attack chain: automating the creation of phishing lures, generating functional malicious code, improving the evasiveness of payloads and making social engineering more convincing at scale. What previously

AUTOCRYPT Showcases SDV Platform and <b>Cybersecurity</b> Technologies

AUTOCRYPT, a physical AI security company, showcased its software-defined vehicle (SDV) platform and cybersecurity technologies at Automotive Innovation Day (AID) 2026. The company jointly operated an exhibition booth with global automotive software company Elektrobit, demonstrating core software and vehicle cybersecurity technologies required for SDVs. The event marked the first joint appearance since AUTOCRYPT was appointed Elektrobit's exclusive partner in South Korea on June 25. AUTOCRYPT introduced key SDV security solutions, including its Hardware Security Module (HSM), Intrusion Detection System (IDS), and Automotive Key Management Infrastructure (Automotive KMI). The company also unveiled and demonstrated Mini Rack, a new hardware model for its CSTP Compliance vehicle vulnerability testing and evaluation solution. Mini Rack is approximately 30 times smaller than the previous model, significantly improving portability and ease of installation. AUTOCRYPT said the compact design enables more flexible deployment across a wide range of development and testing environments. During the event, Kim Eui-seok, Global Chief Technology Officer (CTO) of AUTOCRYPT, delivered a keynote presentation titled "Harmonization of Cybersecurity and Safety in the SDV Era." He outlined the future direction of security infrastructure and technology development for SDVs, emphasizing the integration of vehicle cybersecurity and functional safety. Elektrobit demonstrated its Automotive OS and In-Vehicle Network technologies, showcasing core software for SDVs. Arvind Murthy, Chief Commercial Officer (CCO) of Elektrobit, presented the role and future direction of the "Software-Defined Synergy" created through the partnership with AUTOCRYPT.

Nightwing Achieves CMMC Level 2 Certification with Perfect Score

Nightwing announced it has met the requirements for Cybersecurity Maturity Model Certification Level 2 as of April 29, achieving a perfect score in the assessment. The CMMC Level 2 certification validates Nightwing’s compliance with stringent Department of Defense cybersecurity requirements for Federal Contract Information and Controlled Unclassified Information. Nightwing achieved the certification through assessment by a Certified Third-Party Assessor Organization, reinforcing its role protecting national defense and intelligence missions. “As threats evolve and the complexity of safeguarding critical assets increases, this achievement demonstrates Nightwing’s leadership and proactive approach in fortifying its cybersecurity measures,” said John Xereas, CIO at Nightwing. “CMMC Level 2 certification affirms our ability to provide reliable, resilient capabilities to our government partners, ensuring that mission-critical systems remain secure even in the face of highly determined adversaries. And securing a perfect score of 110 points in the assessment showcases the exceptional expertise, diligence, and dedication of our team in delivering cybersecurity excellence.” CMMC Level 2 incorporates 110 security requirements from NIST SP 800-171 R2. It requires a self-assessment or independent C3PAO certification every three years, with annual affirmation. The program enforces cybersecurity standards across the defense industrial base to protect FCI and CUI, holding contractors and subcontractors to those standards throughout contract performance.

How viral e-rickshaw hack exposes a national <b>cybersecurity</b> blind-spot

How viral e-rickshaw hack exposes a national cybersecurity blind-spot As India pushes electric mobility, the episode has underscored the urgent need to embed cybersecurity into product design rather than treat it as an afterthought What began as a series of viral prank videos has rapidly evolved into a serious cybersecurity alarm for India’s rapidly expanding electric mobility sector. The ability to remotely switch off moving e-rickshaws using nothing more than a smartphone and a freely available Bluetooth application has exposed a glaring security flaw—one that experts warn could have implications far beyond three-wheelers. The episode has prompted the Union government to ask Apple and Google to remove at least seven mobile apps used to remotely disable e-rickshaws. The controversy centres on a Bluetooth battery management application, BAT-BMS, which researchers say allows users within a range of about 10-15 metres to disconnect power to an e-rickshaw without any authentication or specialised hacking skills. The incident has already prompted police action in Madhya Pradesh and drawn the attention of the Union ministry of electronics and information technology (MeitY), raising concerns over the cyber resilience of connected vehicles. Rather than an isolated software bug, cybersecurity experts describe the episode as evidence of a far deeper problem: critical vehicle systems being designed with wireless maintenance interfaces that lack even basic authentication. “The e-rickshaw incident is not merely about a vulnerable app. It demonstrates how convenience has been prioritised over security in connected mobility,” say experts. The implications extend well beyond e-rickshaws. Researchers warn that the same design philosophy—wireless maintenance access left exposed through poorly secured Bluetooth, telemetry or diagnostic interfaces—exists across a wide range of connected platforms, including civilian drones, autonomous systems and smart mobility solutions. Many commercially available drones, particularly low-cost and prosumer platforms, rely on autopilot stacks, flight controllers and companion applications

Chairman Garbarino on America 250: The Homeland Security Mission is an American Imperative

Chairman Garbarino on America 250: The Homeland Security Mission is an American Imperative July 4, 2026 WASHINGTON, D.C. –– Today, House Committee on Homeland Security Chairman Andrew R. Garbarino (R-NY) released the following statement commemorating the 250th anniversary of our nation’s founding: “For 250 years, Americans have risen to meet the challenges of each generation. The homeland security mission is an American imperative, one we undertake in honor of those who built this great nation and on behalf of the future generations of Americans who will benefit from what we accomplish. Created in the aftermath of the worst terrorist attacks in U.S. history, the Department of Homeland Security was built on the legacy of the dedicated personnel and agencies that came before it, those protecting our borders, waterways, financial systems, communities, and more. As we celebrate America’s birthday, we honor those who have served to protect the homeland at home and abroad, thank those who continue the tradition of service today, and recommit ourselves to ensuring this nation can be safe and prosperous for the next 250 years and beyond.” ###

Every Entrepreneur Needs a VPN — This One Is Just $30 and Comes With Bonus ...

Every Entrepreneur Needs a VPN — This One Is Just $30 and Comes With Bonus Cybersecurity Features This cybersecurity deal is the lowest online price for NordVPN. Disclosure: Our goal is to feature products and services that we think you'll find interesting and useful. If you purchase them, Entrepreneur may get a small share of the revenue from the sale from our commerce partners. As an entrepreneur, the last thing you need is another expense. Prioritizing your cybersecurity can help you avoid a laundry list of issues in the future — from data theft to malware infections. Right now, you can secure up to 10 devices with this 1-year NordVPN Standard 2026 VPN and Cybersecurity deal for only $29.99 (MSRP $69.99), the lowest price online, with code SECURE. Upgrade your online security with this limited-time NordVPN deal Whether you’re hopping on the airport Wi-Fi to close a deal or just tackling emails at home, it’s important to safeguard your connection. NordVPN Standard makes it as easy as one click. This NordVPN Standard 2026 deal is a perfect option for a busy entrepreneur. It offers a VPN that provides an encrypted connection that hides your data from hackers and thieves, while also letting you choose from over 7,000 servers in over 100 countries so you can bypass any geographical restrictions. In addition to keeping you safer with a VPN, NordVPN Standard includes built-in cybersecurity features to better protect you from cybercriminals. NordVPN Standard scans your downloads for malware or any other harmful files and blocks dangerous links. You’ll also enjoy an ad and tracker blocker and a dark web monitor that lets you know if your credentials ever appear in a breach. Since you’re likely working from multiple devices, this 1-year NordVPN Standard deal helps by securing 10 devices simultaneously. Use

U.S. Government Entity Paid Kairos $1 Million in Data-Theft Extortion Case

A U.S. government entity paid about $1 million to keep stolen files from being leaked, according to a new case study by Rakesh Krishnan for Ransom-ISAC, built on a leaked negotiation chat and the blockchain trail the payment left. The odd part: the group that took the money calls itself Kairos, but it may not be a ransomware gang at all. Krishnan found no sign that it ever locked a single machine: no encryptor, no locker, no demand for a decryption key. The threat was simpler. Steal the files, then charge the victim not to publish them. Krishnan does not name the victim, but the chat points to Union County, Ohio. The proof-of-theft files carry names like Union.xlsx, 1 union co psi template.doc, and a final archive called union.rar. The victim calls itself a small county with limited resources. The attacker leans on one folder in particular, marked "prosecutors office," warning that leaking it would help criminals dodge charges. The clues fit a real case. In May 2025, Union County, Ohio, said it detected ransomware on its network and later notified 45,487 residents and staff that their data had been taken, affecting most of the county of roughly 70,000. The stolen records ran from Social Security and financial details to fingerprints and passport numbers. Neither the county nor Kairos has confirmed the connection. But if it holds, a county government paid about $1 million it never publicly disclosed. The Hacker News has contacted the Union County Commissioners' Office for comment. This story will be updated with any response. The negotiation ran for about a month. Kairos opened at $3 million and claimed it was holding more than 2 terabytes of data, some 1.6 million files. The county started at $100,000, crept up to $255,000, then $430,000. Kairos dropped to $2

Shaima al Hashmi wins '<b>Cybersecurity</b> Woman for 2026' award

MUSCAT: Shaima bint Juma al Hashmi, Cybersecurity Lecturer at the Muscat Branch of the University of Technology and Applied Sciences (UTAS), has won the "Cybersecurity Woman of the Year 2026" award during a ceremony held in the city of Feldkirch, Principality of Liechtenstein. The award was presented under the auspices of Liechtenstein's Minister of Home Affairs, Economy and Sport as part of the global awards programme organised by the International Cybersecurity Alliance, with the participation of leading cybersecurity experts and specialists from around the world. Al Hashmi received the award following an international competition evaluated by an independent jury, which assessed nominees based on a comprehensive set of professional and scientific criteria, including societal impact, innovation, contributions to the advancement of the cybersecurity sector, academic and research achievements, and initiatives aimed at strengthening digital security and developing human capabilities in this vital field. The achievement reflects the growing international presence of Omani professionals and highlights the remarkable accomplishments of Omani women in specialised technical fields, particularly cybersecurity, which continues to witness rapid regional and global development amid increasing efforts to strengthen digital systems, enhance information security, and address evolving cyber threats. The "Cybersecurity Woman of the Year 2026" award is an international recognition programme that honours outstanding female leaders in cybersecurity, highlights women's impactful contributions to the sector, promotes innovation, and encourages best practices that support the development of a secure and sustainable digital environment. Oman Observer is now on the WhatsApp channel. Click here