Poor cybersecurity practices by Secret Service agents put US officials at risk, inspector general says Bad cybersecurity practices from Secret Service agents have left their phones vulnerable to hacking and risked the lives of senior U.S. officials they are charged with protecting, according to a new inspector general report. Foreign “adversaries” — a term that can encompass spies and terrorists — “could have intercepted and exploited Secret Service information, placing at risk our Nation’s leaders, other protectees, and employees,” said the report released Thursday by the Department of Homeland Security inspector general (IG). The findings revive longstanding concerns about security practices at the Secret Service two years after the near-assassination of President Donald Trump in Butler, Pennsylvania, when insecure and faulty communications led to one of the biggest debacles in the agency’s recent history. A big part of the problem is that Secret Service employes have frequently used their less-secure personal phones rather than their government phones while on protective missions, the new IG report found. Someone who hacks an agent’s personal phone could steal “mission-related data, including contacts, user history, geolocation, and photos” and then use that sensitive information to “plan attacks against protectees or Secret Service employees,” the inspector general concluded. The probe also found that the Secret Service was failing to wipe employees’ phones after returning from international travel, and that the agency didn’t have a policy for testing software before it was deployed on employees’ phones. For years, Secret Service agents have complained that their government phones didn’t allow them to use certain apps to communicate with their foreign counterparts or to send certain types of text messages between themselves. Shortly before the July 13, 2024, assassination attempt in Butler, a Secret Service employee “used their personal device to receive a picture message from local law
Jun 25, 2026 · via kcra.com
Middle school students explore cybersecurity at Lexington summer camp
LEXINGTON, Ky. (WKYT) - About 40 middle school students are participating in the KC-7 Cybersecurity Summer Camp at The Hill this week, investigating realistic cyber incidents and analyzing digital evidence to identify potential threats.
The STEM camp is designed for underserved and at-risk youth populations in Title One schools. It introduces students to one of the fastest-growing career fields.
“By introducing activities like this early on, we’re hoping to really spark their interest and bring them back to The Hill, so they can continue to explore those opportunities and send them right out of high school and into jobs,” said Bryan Quillen, a cybersecurity instructor at The Hill.
The camp wraps up Friday.
Copyright 2026 WKYT. All rights reserved.
Jun 25, 2026 · via wkyt.com
What follows is part of the Globe’s weekly Camberville & beyond newsletter, which explores the latest from Cambridge and Somerville. You can read the full June 25 edition here. Sign up for the free newsletter here. It’s Thursday, the latest artificial intelligence model says So I thought maybe I could ask AI who to talk to locally to better understand the latest news about AI. What are we to make of the unusual warning from cyber experts this week that AI-powered threats could overwhelm defenses in months? Talk to Bruce Schneier, Claude suggested. He’s “the most quotable security commentator alive.” Quite the distinction. I put it to the test and emailed Schneier, a security technologist who has long been connected with Harvard’s Berkman Klein Center for Internet & Society, and whose newest book is about democracy and AI. The Cambridge resident, who The Atlantic called “a frenetic and acerbic security expert,” was clearly in a hurry when we spoke on the phone on Tuesday. Our conversation, edited for concision, clarity, and profanity — and offering one among many takes on this AI moment — was illuminating. I don’t pay much attention to AI or cybersecurity or where the two overlap. What is happening in that space? The models are getting better, they’re getting better at all things. Cybersecurity is one of the things. This is good for attack and defense. They’re good at fixing things. Firefox used [the Anthropic model] Mythos to find 270-something vulnerabilities, which have now been fixed, from now until the end of time. That’s great news! But these models separate skill from knowledge. What do you mean? It used to be that you could ask any doctor how to poison someone and they can tell you, right? You ask anybody who’s an engineer how to blow
Jun 25, 2026 · via bostonglobe.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jun 25, 2026 · via youtube.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jun 25, 2026 · via youtube.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jun 25, 2026 · via youtube.com
Bad cybersecurity practices from Secret Service agents have left their phones vulnerable to hacking and risked the lives of senior US officials they are charged with protecting, according to a new inspector general report. Foreign “adversaries” — a term that can encompass spies and terrorists — “could have intercepted and exploited Secret Service information, placing at risk our Nation’s leaders, other protectees, and employees,” said the report released Thursday by the Department of Homeland Security inspector general (IG). The findings revive longstanding concerns about security practices at the Secret Service two years after the near-assassination of President Donald Trump in Butler, Pennsylvania, when insecure and faulty communications led to one of the biggest debacles in the agency’s recent history. A big part of the problem is that Secret Service employes have frequently used their less-secure personal phones rather than their government phones while on protective missions, the new IG report found. Someone who hacks an agent’s personal phone could steal “mission-related data, including contacts, user history, geolocation, and photos” and then use that sensitive information to “plan attacks against protectees or Secret Service employees,” the inspector general concluded. The probe also found that the Secret Service was failing to wipe employees’ phones after returning from international travel, and that the agency didn’t have a policy for testing software before it was deployed on employees’ phones. For years, Secret Service agents have complained that their government phones didn’t allow them to use certain apps to communicate with their foreign counterparts or to send certain types of text messages between themselves. Shortly before the July 13, 2024, assassination attempt in Butler, a Secret Service employee “used their personal device to receive a picture message from local law enforcement of the would-be assassin due to reliability concerns” with their government phone, the new
Jun 25, 2026 · via cnn.com
FCC passes new cybersecurity rules for emergency systems, undersea cables The Federal Communications Commission approved new rules Thursday that boost cybersecurity regulations for the nation’s emergency alert systems and update security rules for the nation’s undersea cables. The new rule would overhaul two national emergency systems, the Emergency Alert System and Wireless Emergency Alerts, to better protect against hijacking attacks from malicious actors. The EAS is a national public warning system that state and local authorities use to disseminate information related to weather events, AMBER alerts and other emergencies via radio and television broadcasting stations. The WEA handles much of the same messaging via text. A compromise of either system by a foreign government, cybercriminal group or other rogue actor could be used to sow chaos and disinformation in calmer times, or impede coordination efforts in the face of a genuine emergency. Any vulnerability in systems like the Emergency Alert System “can have serious consequences,” said FCC Commissioner Olivia Trusty in a statement after the vote. “That is why it has been appropriate for the Commission to conduct a comprehensive review of the EAS framework by focusing on the security of the system itself,” Trusty continued. “As cybersecurity threats continue to evolve, EAS participants must take appropriate steps to safeguard the infrastructure that supports the delivery of life-saving alerts.” The new rules amount to basic – but still critical – cyber hygiene practices for users accessing and updating the EAS and WEA systems. They must use strong passwords, quickly install security patches from vendors and use firewalls to limit access to their equipment. The rule also creates a new authentication ID system to verify alerts before they’re submitted and avoid duplicate or unauthorized alerts from spreading. Another rule passed by the Commission Thursday provided the first comprehensive update to the
Jun 25, 2026 · via cyberscoop.com
The J.P. Morgan Innovation Economy group hosted its second annual cybersecurity summit in April 2026, bringing together founders, investors and industry experts to discuss the state of cybersecurity. From this event and conversations with stakeholders across the industry, one thing is clear: cybersecurity is at an inflection point. Artificial intelligence (AI) is simultaneously a potent threat and a powerful defense. The builders who stand out will integrate AI to deliver improved outcomes a buyer can measure. “The modern ‘software as a service’ (SaaS) delivery model is quietly enabling cyber attackers and—as its adoption grows—is creating a substantial vulnerability that is weakening the global economic system.” Pat Opet Chief information security officer, JPMorganChase Enterprise AI adoption is pushing identity to the center of the threat landscape. For many organizations, non-human identities (NHIs)—digital credentials for AI agents, service accounts, machines and automated workflows—outnumbered humans 144-to-1 by mid-2025, a ratio that had grown 44% year over year, according to Entro Security’s H1 2025 research report. AI-driven automation has continued to accelerate the trend since. BeyondTrust’s Phantom Labs research, published in March, found a 466.7% year-over-year increase in AI agents operating inside enterprise environments. As these machine identities accumulate, broad permissions, unused credentials and limited visibility can create risks that are harder to track than human access. In enterprise conversations, governance is expanding to cover automated system-to-system access, authorized or not. For builders, this shift is reshaping where durable product categories are forming. NHI governance is emerging as a control layer for access decisions in an AI-driven enterprise. Products that help enterprises manage NHIs, rotate secrets and keys and provide a clear rationale for access decisions in agent-to-agent workflows are becoming foundational to safe AI adoption. As the machine population grows, buyer urgency is rising alongside it. Identity is one dimension of the expanding
Jun 25, 2026 · via jpmorgan.com
Akron Public Schools‘ buildings closed Wednesday for a “network outage” caused by a cybersecurity breach.
As of Wednesday afternoon, the district was still offline but planned to reopen with most regular programming, athletics and offices available on Thursday. Office staff would work remotely to access WiFi, Superintendent Mary Outley said in a text message, and other summer programs — outside of credit recovery — would return to their regular, in-person schedules.
Credit recovery allows students to make up failed or incomplete classes through online coursework. The program was canceled for the rest of the week, according to district social media, and make-up days would be scheduled.
Board of Education President Barbara Sykes said she was not aware of the district receiving any ransom demand as part of the cybersecurity incident. Ohio law requires school districts and municipalities to take public action in response to a ransomware attack.
As of Wednesday evening, it was unclear if any student or staff data had been compromised, or how the breach occurred.
Jun 25, 2026 · via signalakron.org
A Wellington entrepreneur collaborating on cybersecurity projects in the United States and Europe says mathematics can stymie the advancing powers of AI. Boyd Multerer, the CEO of Kiwi start-up Kry10, is an advocate of a maths-based cybersecurity approach called 'formal methods', which is now being piloted by the US Air Force. Just this week, the hacking threat posed by frontier AI models sparked a national security alert by the Five Eyes intelligence group, which includes New Zealand. One defence against that threat is to use other AI to patch software against at ever faster rates - AI versus AI. But Multerer says new research - including projects with the US Department of Energy (DOE) National Labs and intelligence agencies - shows another way. "If you're building a new system and writing a significant amount of code, you are going to be spending a lot of money on the AI versus the AI thing," he said. "It doesn't go away just because you've run it once. You have to keep running it as the techniques from the attackers change. "You haven't actually proven the vulnerabilities are gone. You've only gotten out the ones that you know about now." But if you can prove with maths that the vulnerabilities aren't there in the first place, when the code is developed, you can contain that and corral the costs early, Multerer said. Cyber security expert discusses Five Eyes statement on AI 'Urgent' questions The promise of formal methods has been confined by their complexity. That is now changing as agentic AI systems take on increasingly autonomous roles, said a recent Software Engineering Daily podcast with the founder of the formal methods approach, Professor Byron Cook, of Amazon. "The question of how to define, enforce, and verify what those agents are allowed to do
Jun 25, 2026 · via rnz.co.nz
New CISA Guide Assists Federal Agencies with Transitioning to Modernized Zero Trust Architectures WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA) published a guide that helps federal civilian agencies advance their zero trust capabilities and adopt modern architectures supported under the Trusted Internet Connections (TIC) 3.0 Initiative. Part of CISA’s Journey to Zero Trust series, this guide helps agencies transition away from the limitations of using TIC 2.0 and capitalize on TIC 3.0 flexibilities to employ Secure Access Service Edge (SASE) solutions. Federal agencies will better understand, plan and mature to zero trust architecture to improve user experience, increase visibility and control, and enable telemetry sharing with CISA services. Many legacy architectures rely on perimeter-based security models such as TIC 2.0 that routes all traffic through centralized controls. Today’s rapidly evolving threat landscape and organizations’ shift to more distributed business models with cloud capabilities and remote workforces reveal shortcomings in legacy perimeter-based paradigms. Based on CISA’s work with federal agencies, this guide helps technical leaders and enterprise architects implement a SASE solution to replace their existing managed trusted internet protocol services (MTIPS) connectivity. The transformation to SASE solution improves network performance, reduces latency, and increases visibility and control. “CISA continues to support federal agencies and the broader cybersecurity ecosystem with their continued adoption of zero trust network capabilities to meet mission needs and the evolving cyber threat landscape,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “With this guide, CISA helps agencies realize the benefits of zero trust architectures and the flexibilities of TIC 3.0.” Launched last year with microsegmentation guide, this ongoing series provides resources on cybersecurity capabilities and architecture topics related to the adoption of modern zero trust principles. While directed to federal civilian agencies, organizations such as state and local governments and critical infrastructure
Jun 24, 2026 · via cisa.gov
Every security leader I speak with is wrestling with the same question: we've invested in AI, so where's the return? If they’re being honest, the answer is that they likely can’t tell. Research indicates that an estimated 70 to 80% of AI initiatives either don’t scale out of the pilot stage or fail altogether, but the reason is rarely that the technology doesn't work. It's that organizations haven't defined what "working" means for them. In cybersecurity, this problem is even more acute as security success is, by nature, invisible. When AI stops an attack, nothing happens, and this doesn't make it onto a dashboard or into a board report. Outcomes are probabilistic and value is routinely misunderstood, so without a clear definition of value, scaling AI becomes an exercise in hope. The Adoption Curve Nobody Talks About There's a familiar trajectory to AI adoption in cybersecurity, whereby the tools are purchased and deployed, but the expectations aren’t well defined, and nobody has clearly outlined the goals or metrics of success for what the AI is improving. As a result, while they may see an occasional win, for example a false positives reduction, the project is doomed to be seen as a costly experiment. The result is AI layered on top of existing workflows, so the analysts are still drowning in alerts and spending time on tactical tasks that don't make use of their expertise. The AI is running in the background, but the fundamentals of the work hasn't changed. This is where most organizations stop or change course because they don’t see the promised transformation, despite not articulating the desired ROI from the start. Defining Value at the Level That Matters The issue isn't that AI can't deliver meaningful outcomes. At Abnormal AI, we've seen it reduce missed detections, automate
Jun 24, 2026 · via infosecurity-magazine.com
Cybersecurity Warnings for Smart TVs
- Updated
Most Popular
- Great River Shakespeare Festival opens 2026 season in Winona with two productions
- Less humid with morning cloud cover on Thursday
- Baldwin woman among 455 defendants in DOJ 'health care fraud takedown'
- Shed total loss after fire in Black River Falls
- 1 in 3 Wisconsin households struggle to afford basic needs, United Way report finds
Jun 24, 2026 · via news8000.com
VA’s top health official pushes IT overhaul to cut bureaucracy, boost veteran care Federal Insights Read more
Security at major events now depends on how well government and contractors operate together Contracting Read more
Amelia Brust/Federal News Network First Look Policymakers struggle to factor cybersecurity into federal funding programs Cybersecurity Read more
Jun 24, 2026 · via federalnewsnetwork.com
Calgary, Alberta, Canada, June 24, 2026 (GLOBE NEWSWIRE) -- The Southern Alberta Institute of Technology (SAIT) and Mastercard are collaborating to expand access to cybersecurity learning and help organizations in Western Canada strengthen their digital resilience. SAIT Cybersecurity Learning Collective, powered by Mastercard, is a 10-week, 80-hour course designed for small businesses, non-profits and social enterprises, with the first cohort starting in September. Tuition is fully covered for eligible participants through funding from Mastercard, subject to program criteria and availability. “Cyber threats don’t discriminate by size, yet many small businesses and non-profits are left navigating complex risks without the tools or support they need,” says Vis Naidoo, Associate Vice President, Continuing Education and Professional Studies, SAIT. “This course will help equip leaders with the knowledge and framework to make informed decisions and strengthen their organization’s resilience.” Naidoo adds, “Together with Mastercard, we’re helping businesses build the digital and financial resilience needed to support their long-term growth and integrate resiliency into their foundation and organizational culture.” Participants will gain practical tools to assess cyber risk, implement protective measures and prepare for cybersecurity incidents through immersive simulation exercises. By the end of the course, each participant will work towards developing an implementation-ready plan that aligns cybersecurity practices with their organization’s mission, governance responsibilities and operational capacity. “Small businesses, non-profits and social enterprises are the backbone of the Canadian economy and our communities, and they are operating in an environment of increasingly complex cyber risks,” said Jennifer M. Sloan, Senior Vice President, Government Affairs and Stakeholder Engagement, Mastercard, Canada. “Our collaboration with SAIT is about helping these organizations build the skills and confidence they need to manage digital risk, protect what they’ve built and thrive in today’s digital economy.” SAIT Cybersecurity Learning Collective, powered by Mastercard, aims to empower the next generation of
Jun 24, 2026 · via globenewswire.com
Dive Brief: - The number of ransomware attacks that hackers claimed on dark-web leak sites rose by nearly one-fifth in 2025, to 6,883, while the total number of leak sites increased by roughly one-third, to 115, the security firm Bitsight said in its annual “State of the Underground” report. - Ten groups — five of them associated with Russia — were responsible for roughly 58% of attacks, according to the report, suggesting a remarkable concentration of activity. - Roughly 60% of ransomware victims were in the U.S., with the manufacturing sector topping the list. Dive Insight: While ransomware attacks surged, traditional data breaches fell by 41% in 2025 compared with the previous year. Bitsight cautioned, however, that the decline was likely the result of reporting gaps and evolving threat-actor behavior rather than a reduction in risk. “Attacker focus shifted toward domino-effect targets, including critical infrastructure and defense, government, and utilities,” researchers wrote. Educational institutions experienced the most data breaches in 2025, with 505, followed by government (475) and IT (469). That represented a significant shift from 2024, when IT topped the list, with 1,210 breaches. The data-breach landscape in 2025 was “less dominated by a single sector and more distributed across industries with personally identifiable information (PII) and operational and supply chain importance,” Bitsight said in its report. As AI tools have become a more useful tool for defenders, they have also become increasingly valuable to hackers. On the cybercrime forums and Telegram channels that Bitsight monitors, the company tracked 5.1 million mentions of Google’s Gemini platform, 1.4 million mentions of OpenAI’s ChatGPT service, 656,000 mentions of Anthropic’s Claude tool and 697,000 mentions of xAI’s Grok chatbot. Misconfigured and poorly secured AI platforms also represent weak spots in businesses’ networks. The number of publicly exposed AI tools increased by 360%
Jun 24, 2026 · via cybersecuritydive.com
The Small Business Cybersecurity Assistance Evaluation Act of 2026 aims to ensure small businesses are protected from cybersecurity risks by studying the effects of these attacks on them. The legislation was first passed out of the House Committee on Small Business on May 20, by a bipartisan vote of 23-0. "In the United States, small businesses are 210% more likely to experience cyber incidents compared to larger companies," said Bresnahan. "Despite this, many of our small businesses lack the resources and expertise necessary to defend against these threats. This legislation will help ensure that as cyber threats continue to evolve, our support systems for small businesses evolve as well." Specifically, the legislation directs the U.S. General Accountability Office (GAO) to evaluate federal cybersecurity assistance to small businesses. The bill would require a study to analyze cyber risks, vulnerabilities, and current initiatives, and to identify shortcomings in current preventive and mitigation measures. "Small businesses are the foundation of main streets across the country, and we cannot leave them behind as digital infrastructure becomes more unpredictable," said Bresnahan. "By finding the gaps in current programs, this bill will give our small businesses better access to the tools, training, and resources they need to strengthen their defense against cyber attacks." ©2026 The Times Leader, Distributed by Tribune Content Agency, LLC.
Jun 24, 2026 · via govtech.com
AI Will Elevate Near-Term Cybersecurity Risks but — with Investment and Coordination — Can Strengthen Cybersecurity in the Long Run News Release By Molly Galvin Last update June 24, 2026 WASHINGTON — To counteract emerging cyberthreats posed by artificial intelligence, the baseline level of cybersecurity across society must rise — including stronger security practices, improved software quality, faster response to threats, and more effective sharing of cyberthreat intelligence, says a new rapid expert consultation from the National Academies of Sciences, Engineering, and Medicine. Frontier AI systems are rapidly expanding what is possible for both attackers and defenders, the publication says. In the near term, these advances are likely to favor attackers by reducing the time, expertise, and operational effort required for cyberattacks. “With investment and collaboration, AI could facilitate a stronger approach to cybersecurity that may shift the advantage to the defenders,” said Giovanni Vigna, director of the AI Institute for Agent-based Cyber Threat Intelligence and Operation (ACTION) at the University of California, Santa Barbara, and co-author of the publication. “Cybersecurity will need to improve rapidly to meet this challenge.” Because AI-enabled cyber capabilities are evolving faster than the ability to evaluate and measure them, risk assessment is further complicated for policymakers and practitioners, the publication says. It provides an overview of how advances in AI are reshaping cybersecurity risks and defenses, including examples and policy considerations for decision-makers in the public and private sectors. Long-term advantage could shift to defenders Over longer time horizons, AI may enable fundamentally different and more favorable defensive approaches, allowing for a transition from static, episodic defense to continuous ‘defense-in-depth’ — in which vulnerability discovery and patching, threat detection, intelligence generation, incident response, and other functions operate as ongoing, interconnected processes. “The short-term outlook is concerning, but the longer-term outlook is cautiously optimistic,” said
Jun 24, 2026 · via nationalacademies.org
Cyber Patriot camp gives students hands-on cybersecurity training
AUGUSTA, Ga. (WRDW/WAGT) - Local students are getting hands-on cybersecurity experience through the nation’s largest CyberPatriot summer camp, hosted by the Alliance for Fort Gordon.
The camp gives students immersive training in cybersecurity at no cost.
Dave Besel, the lead instructor at the CyberPatriot camp, said his career in cybersecurity motivates him to invest in students.
“The Navy sent me to the NSA to work on their red team — that’s where we hack other government agencies, mostly the military,” Besel said. “This is a great opportunity for me to kind of help students understand what this career field looks like, can be like, and give them a little hands-on experience.”
The camp is at full capacity and ends Friday.
Copyright 2026 WRDW/WAGT. All rights reserved.
Jun 24, 2026 · via wrdw.com