A newly disclosed Linux kernel flaw called Bad Epoll (CVE-2026-46242) lets an ordinary user with no special access take full control of a machine as root. It affects Linux desktops, servers, and Android, and a fix is out. Bad Epoll sits in the same small stretch of kernel code where Anthropic's most powerful AI model, Mythos, recently found a different bug. The AI caught one flaw and missed this one. A researcher, Jaeyoung Chung, found it and built a working attack. How the Bug Works Epoll is a standard Linux feature that lets a program watch many files or network connections at once. Servers, network services, and web browsers all lean on it. You cannot simply switch it off. Bad Epoll is a "use-after-free" bug. Two parts of the kernel try to clean up the same internal object at the same time. One frees the memory while the other is still writing into it. That brief collision lets an attacker corrupt kernel memory, then climb from a normal account up to root. The catch is timing. The window where the two paths collide is only about six machine instructions wide, so a random attempt almost never lands in it. Chung's exploit widens that window and retries without crashing, reaching root about 99% of the time on tested systems. Two things make it more dangerous: by his account, it can be triggered from inside Chrome's renderer sandbox, which blocks almost every other kernel bug, and it can reach Android, which most Linux privilege bugs cannot. Chung submitted the flaw as a zero-day to Google's kernelCTF program, and full technical details are in his public writeup. There is no sign it has been used in real attacks: as of this writing, it is not on CISA's Known Exploited Vulnerabilities list, and the
Jul 3, 2026 · via thehackernews.com
Cybersecurity researchers have discovered a previously undocumented modular malware framework codenamed Avalon that's distributed by means of a multi-stage phishing chain capable of bypassing traditional security controls. Avalon combines credential collection, lateral movement, remote access, recovery disruption, and ransomware execution, bringing together diverse functions under one umbrella. The ransomware component has been internally named CrownX. "The attack began with a spoofed legal document email directing recipients to a password protected archive on Proton Drive," Blackpoint Cyber researchers Nevan Beal and Sam Decker said. "Malicious content was embedded inside an ISO image rather than attached directly, reducing the likelihood of detection at the email layer." Should the email recipient interact with a document-themed Windows Shortcut ("Secure Document CA-283505.pdf.lnk") inside the mounted image, it triggers a staged malware sequence that culminates in the deployment of Avalon. Specifically, the shortcut runs a command to launch an MSBuild project located in the ISO image. The MSBuild project, for its part, loads an embedded .NET assembly, which then interferes with the regular functioning of Event Tracing for Windows (ETW) to reduce forensic visibility and download a next-stage payload over HTTPS responsible for launching Avalon. The malware framework boasts of an extensive defense evasion subsystem that aims to evade detection, while incorporating specific methods to conceal execution from security tools associated with Microsoft Defender, SentinelOne, CrowdStrike, Sophos, Elastic Endpoint, FortiEDR, ESET, McAfee, and Bitdefender. "These capabilities give the framework a multitude of ways to reduce telemetry, bypass user mode monitoring, and adjust its execution depending on the defensive controls present on the host," the researchers said. The complete set of features built into Avalon is as follows - - Harvest credentials, cookies, history, and bookmarks from Chromium-based browsers and Mozilla Firefox. - Gather data from cryptocurrency wallet apps like MetaMask, Phantom, Coinbase Wallet, Exodus, Electrum, Atomic
Jul 3, 2026 · via thehackernews.com
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft. According to JFrog, the packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" mimic the legitimate "rollup-plugin-polyfill-node" project, down to the description, repository metadata, and package shape. "The lookalike packages place themselves in the same rollup, polyfill, core, and node naming space, which can look plausible during a quick dependency review," JFrog said in a technical write-up of the campaign. The campaign also involves four other packages, all of which have since been removed from the npm registry - - quirky-token - react-icon-svgs - rollup-plugin-polyfill-connect - swift-parse-stream What's noteworthy here is that "rollup-packages-polyfill-core" installs and loads "swift-parse-stream," while "rollup-runtime-polyfill-core" installs and "quirky-token." In a similar fashion, "react-icon-svgs" has been found to install "rollup-plugin-polyfill-connect" as a second stage. "The second-stage packages are near-identical SVG utilities that fetch a JSON object from JSONKeeper and eval the model field," the cybersecurity company said. "This layered structure, together with the lookalike names, legitimate-looking metadata, hidden install-time execution, environment checks, and credential-theft/remote-access payloads, is similar to previous North Korean Lazarus-linked npm campaigns." It's worth emphasizing here that this is not the first time North Korean threat actors have uploaded npm packages impersonating Rollup polyfill tools. In April 2026, Panther detailed a sustained npm campaign that involved publishing 108 malicious npm packages spanning 261 versions to deliver BeaverTail and OtterCookie, two known malware families linked to Contagious Interview. Among those packages was "rollup-plugin-polyfill-route," which was published on March 20, 2026. The starting point of the attack is a Base64-encoded npm install command for "swift-parse-stream" (or "quirky-token") that's concealed within "rollup-packages-polyfill-core" (or "rollup-runtime-polyfill-core"). The two second-stage packages are dressed up as SVG sanitization utilities, while reaching out to a JSON Keeper
Jul 3, 2026 · via thehackernews.com
Home
Pink Sheet
Scrip
Medtech Insight
HBW Insight
Generics Bulletin
In Vivo
Spotlight
FDA
EU Medical Device Regulation
Robotics
AI
Interviews
Business
Deals
Financing
Earnings
Startups
R&D
Policy & Regulation
Approvals
Recalls
Legislation
Compliance
IP & Litigation
Commercial Trackers
M&A Deals
Financing Deals
Executive Moves
Company Rankings
Regulatory Trackers
US Original PMAs
US PMA Supplements
US 510(k) Clearances
US De Novo Classifications
Non-US Approvals
US FDA Warning Letters
US Breakthrough Devices
Global Guidance Tracker
Podcasts
Conference Coverage
Partner Insights
Opens in new window
Advertise
Opens in new window
Medtech Insight Perspectives
Uncovering medtech commercial, market access and development trends.
View
Pink Sheet
Scrip
Medtech Insight
HBW Insight
Generics Bulletin
In Vivo
Medtech’s 2026 Cybersecurity Breaches Spared The Devices — And Hammered Everything Else
Jul 03 2026
•
By
Shubham Singh
Hospitals run on a mix of decades-old Java middleware and brand-new patient portals, life-support devices that can never be switched off for a routine update, and corporate IT systems that — however carefully segmented from clinical operations — still hold the data and infrastructure that keep supply chains and billing moving. Picture Credit: Shutterstock
More from Cybersecurity
More from Digital Technologies
Jul 3, 2026 · via insights.citeline.com
Strengthen Your Business With Lifetime Cybersecurity Training for $53 Get self-paced courses on CISSP, ethical hacking, and GRC through one lifetime membership. Disclosure: Our goal is to feature products and services that we think you'll find interesting and useful. If you purchase them, Entrepreneur may get a small share of the revenue from the sale from our commerce partners. For a small-business owner or solo entrepreneur, a single security breach can mean lost data, lost customers, and lost revenue. Most of us are too busy running the day-to-day to think about firewalls and phishing scams until something goes wrong. Whether you want to protect your own company or add an in-demand skill to your professional toolkit, understanding cybersecurity is no longer optional. That is where the InfoSec4TC Platinum Membership comes in. This lifetime subscription gives you self-paced access to more than 90 cybersecurity courses for a one-time $52.99 (reg. $280). It is built for working professionals who want practical, certification-focused training without committing to a recurring monthly bill. This cybersecurity training catalog covers the credentials hiring managers actually look for, including CISSP, CISA, CISM, and ISO 27001, alongside hands-on training in ethical hacking and using Python for security work. You also get the latest exam practice questions, frequently updated study materials, and access to private discussion groups, plus one free career consulting session to help map out your next move. Because it is a lifetime membership, every new course InfoSec4TC adds to your account at no extra cost. For a business owner, that knowledge translates directly into safer systems and smarter conversations with any IT vendor or contractor you bring on. For anyone eyeing a career pivot, IT and security roles remain some of the most resilient and well-paid positions on the market, and a recognized certification is often the
Jul 3, 2026 · via entrepreneur.com
Global cybersecurity spending is forecast to exceed $300 billion in 2026, and the catalyst is no longer abstract. AI agents now outnumber human identities within enterprises by roughly 109 to 1; Fortinet’s threat report logged a 389% year-over-year jump in ransomware victims; and Check Point measured a 51-point gap between corporate AI adoption and security readiness. Every prompt-injection vector, deepfake voice clone, and automated phishing campaign expands the attack surface defenders must cover. Three ETFs offer different angles on the same trend: First Trust NASDAQ Cybersecurity ETF (NASDAQ:CIBR), Amplify Cybersecurity ETF (NYSEARCA:HACK), and Global X Cybersecurity ETF (NASDAQ:BUG). Each one screens the universe differently, and the differences matter more than the overlapping top holdings suggest. CIBR: The Default Allocation Holding $13.01 billion in assets as of late June, CIBR stands as the category leader while maintaining an expense ratio of 0.58% across 46 distinct holdings. Its strategy mirrors the NASDAQ CTA Cybersecurity Index by blending specialized vendors with established networking giants and IT service firms. This approach delivers a smart investment logic, as it lets you ride the broader wave of industry spending rather than gambling on a single platform to dominate the market. The portfolio leans heavily on the platform consolidators. Palo Alto Networks sits at 9%, CrowdStrike at 8%, and Fortinet at 7%, with Cisco and Broadcom close behind at 8% and 8%. That weighting matters because the news flow keeps validating the platform thesis: Palo Alto formed a NATO partnership and launched its Idira identity layer for AI agents, while Fortinet’s Q1 2026 billings grew 31%, driven by demand for AI and operational technology. Cisco and Broadcom give CIBR exposure to the networking layer where AI traffic actually moves, which a pure software fund misses. The infrastructure tail goes further than most realize. Cloudflare carries a 5%
Jul 3, 2026 · via 247wallst.com
The top threat was not a virus. It was attackers hijacking the remote-IT tools dental practices already trust, according to Medix’s Dental’s first-party data. ” DAVENPORT, IA, UNITED STATES, July 3, 2026 /EINPresswire.com/ — Medix Dental IT has released its June 2026 Dental Cybersecurity Data Report, an unusual move in an industry where most IT providers keep what they see to themselves. Most articles about dental cybersecurity are written from the outside looking in. This one is different. The report is built entirely from first-party telemetry across the dental practices and dental service organizations (DSOs) Medix protects, and it shows how practices are actually being attacked. Most dental IT support companies never publish this kind of data. Medix analyzed 2.58 billion security events in a single month and is putting the findings on the record so practice owners and DSO operators can plan against what the data shows, not against headlines. The clearest finding is where the real attacks came from. Analysts confirmed 12 foothold incidents, most of them tied to the abuse of remote monitoring and management (RMM) tools, the same remote-IT software dental practices trust their vendors to use. Attackers increasingly hijack those tools to blend in with legitimate activity, which is why layered monitoring, not antivirus alone, is what surfaced them. Antivirus still did its job, blocking 1,651 malware files during the month. But none of the 13 real incidents came from the files antivirus catches. Antivirus is not a cybersecurity program. It is one layer. For most dental groups, the real target has moved off the server in the back office and onto the identity layer. Medix analyzed 2.2 million Microsoft 365 events and ingested nearly 162 million security logs to catch account takeovers early. Microsoft research shows multi-factor authentication reduces the risk of account compromise
Jul 3, 2026 · via dispatch.com
Data of 70,000 people compromised in cybersecurity incident involving SLA’s vendor IBM Names, NRIC numbers and past property addresses were exposed after unauthorised access to a data set created for vendor development and testing. SINGAPORE: Personal data of about 70,000 people was compromised following a cybersecurity incident involving the Singapore Land Authority (SLA) and a cloud environment managed by its vendor IBM. In a media release on Friday (Jul 3), SLA said the incident involved unauthorised access to a data set created for vendor development and testing. IBM manages the development and systems-integration testing environment for the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS). The web-based system allows lawyers, government agencies and authorised individuals to submit documents relating to property transfers and caveats. Preliminary investigations showed that the compromised dataset, created in 1998 for testing purposes and updated periodically over the years, was meant to contain only mock and anonymised data based on property ownership and lodgment records. However, it was later found to include real information such as names, NRIC numbers and past property addresses of about 70,000 people. "This information should have been anonymised but was not," SLA said. "Investigations are ongoing to determine how this occurred." The affected environment managed by IBM is separate from SLA’s operational systems. “There is no connection or compromise to the live systems used for operations of STARS, ELS or any other SLA systems," the agency said. "Property ownership and lodgment records in STARS and ELS remain secure and unaffected." IBM has since revoked access to the affected system to prevent further unauthorised entry. As a precaution, SLA has begun notifying affected individuals and advising them on steps they can take for assistance. “SLA is working closely with IBM, the Government Technology Agency of Singapore and the Cyber Security
Jul 3, 2026 · via channelnewsasia.com
Personal info of 70,000 people compromised in data breach involving SLA’s vendor IBM SINGAPORE – The personal details of around 70,000 people in Singapore, including NRIC numbers and addresses, have been compromised following a data breach involving the Singapore Land Authority’s (SLA) vendor, IBM. In a statement on July 3, SLA said it was informed about the data security incident by IBM, which it had appointed to support and maintain the Singapore Titles Automated Registration System (STARS) and eLodgment System (ELS). IBM also managed the development and systems-integration testing environment for STARS and ELS. Preliminary investigations found that there was unauthorised access to a data set created for vendor development and testing, SLA said. The data set, which was created in 1998 and updated periodically over the years, was intended to contain only mock and anonymised testing data based on property ownership and lodgment records, SLA said. However, the authority said it has since uncovered that the data set also contained the names, NRIC numbers, and then property addresses of about 70,000 individuals. “This information should have been anonymised but was not. Investigations are ongoing to determine how this occurred,” it added. As a precautionary measure, SLA has identified the individuals whose information was contained in the affected data set. It has also started notifying them and advising them on how they can seek further information and assistance. SLA said the affected environment managed by IBM is distinct and separate from its operational systems. The live systems used to operate STARS, ELS or any other SLA systems have not been compromised, it added. Property ownership and lodgment records in STARS and ELS also remain secure and unaffected. IBM has revoked access associated with the affected development and testing environment to prevent any other unauthorised access. “SLA is working closely with
Jul 3, 2026 · via straitstimes.com
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Remote Management and Monitoring (RMM) tooling, credential access, and hands-on-keyboard procedures used for lateral movement," Arctic Wolf said in a report published this week. "Anubis affiliates repeatedly abused legitimate remote access and administration tools, including ScreenConnect, Zoho Assist, MeshAgent, Remotely, UltraVNC, and Total Software Deployment, to blend in with normal IT activity while maintaining control of victim systems." Anubis is a ransomware-as-a-service (RaaS) group that first emerged in late 2024 as a rebrand of Sphinx ransomware. The ransomware operation was formally announced on the Ransomware and Advanced Malware Protection (RAMP) underground forum in February 2025. According to data from Ransomware.Live, the cybercrime crew has claimed 91 victims on its data leak site, with 11 victims reported in June 2026 alone. Some of the prominent sectors targeted include healthcare, business services, manufacturing, technology, and financial services. More than 50% of the victims are located in the U.S., followed by the U.K., Australia, France, and Canada. In a report published in July 2025, Rubrik Zero Labs said Anubis advertises attractive profit splits, offering affiliates 80% of the ransom amounts paid, and pairs it with an irreversible data-wiping feature that ups the pressure on victims to pay up. "When Anubis's /WIPEMODE module is activated, files remain in directories but are reduced to a 0 KB size regardless of ransom payment," Rubrik noted at the time. "Knowing threat actors can revert victims' environments to this scorched-earth state with a single command significantly increases pressure on victims to pay before the wiper is fully activated." The ransomware intrusions, observed this year, involve both valid VPN credential use and the
Jul 3, 2026 · via thehackernews.com
The Valley Industry Association’s monthly luncheon focused on cybersecurity at the Child & Family Center’s Education Center on Tuesday. Attendees got to enjoy lunch and mingle before the presentation, “The Cyber Threat You Don’t See Coming: Emerging Risks, Hidden Vulnerabilities, and What Leaders Must Do Now.” The presentation featured guest speaker Detective Sgt. Peter Hish from the Los Angeles County Sheriff’s Department’s Cybercrime Investigations. Hish began his talk by saying that the real problem is leadership, not an information technology problem. “It comes to their security, their company, their infrastructure, from cyberpaths … I see it over and over and over again,” Hish said. He recalled businesses constantly falling victim to different tricks or people hacking into their databases. Hish added that people who are in these businesses want to make money but are not thinking of the bigger picture. “Even a nonprofit is focused on making money for the nonprofit. They’re looking at marketing; they’re looking at innovation,” Hish said. “Staffing, payroll, all those things, but they’re not thinking of security or infrastructure, which does not make them money. It can cost them money later, but it doesn’t make them money.” Hish said that culture is another big part of cybersecurity and said the boss reflects the employees. “A good culture is important. If the boss has their password taped under the keyboard or they’re leaving their computer on the desk, but not doing those basic things, employees see that and do the same thing. And now you’re setting (up) a bad culture within your environment,” Hish said. He added that businesses should do regular training for cybersecurity, suggesting attendees complete a five-minute weekly exercise to help understand the importance of privacy and cybersecurity. At the end of the presentation, attendees participated in a question-and-answer session with Hish about
Jul 3, 2026 · via signalscv.com
Aerospace The Demand for Integrating Cybersecurity into Aerospace Quality One of the most important conceptual shifts for aerospace quality managers is recognizing that AS9100/IA9100 and CMMC are not competing frameworks requiring duplicate effort. Aerospace quality management is undergoing its most significant transformation in decades. Quality management is rapidly evolving into a multidimensional assurance ecosystem that must simultaneously address physical product integrity, digital information security, supplier trustworthiness, and enterprise resilience. Two frameworks sit at the center of this transformation. The first is AS9100, soon to be rebranded as IA9100, the internationally recognized Quality Management System (QMS) standard governing aviation, space, and defense organizations. Developed and maintained by the International Aerospace Quality Group (IAQG), and built upon the foundation of ISO 9001, AS9100/IA9100 defines the operational expectations for quality across the global aerospace supply chain. The second is the Cybersecurity Maturity Model Certification (CMMC), a U.S. Department of Defense (DoD) mandate requiring defense contractors and their subcontractors to demonstrate verified cybersecurity controls as a condition of contract award. Quality and cybersecurity departments have operated as largely independent disciplines: Quality teams managed audits, corrective actions, supplier evaluations, and process controls. Cybersecurity teams managed IT infrastructure, threat monitoring, access controls, and incident response. That separation is no longer sustainable. Today, the systems used to design, manufacture, inspect, and deliver aerospace products are deeply digital, and therefore deeply vulnerable. (But these systems increasingly are more accessible and potentially less prone to duplication and overlap.) Engineering drawings, manufacturing routines, inspection records, supplier communications, and operational data all flow through networks and platforms that can be compromised, corrupted, or stolen. What Is AS9100 and Why Is It Evolving into IA9100? While AS9100 builds directly on ISO 9001, the internationally recognized baseline for quality management, it adds additional requirements specific to the unique demands of aviation, space, and
Jul 3, 2026 · via qualitymag.com
Coverage from Statescoop indicates that the Federal Emergency Management Agency has issued new guidance regarding the use of funds from its State and Local Cybersecurity Grant Program and the Tribal Cybersecurity Grant Program, specifically addressing restrictions on membership fees for cybersecurity services.FEMA has clarified that state and local governments are prohibited from using federal cyber grant funds to pay for membership fees that bundle cybersecurity or technical services, as the agency cannot determine the reasonableness of these bundled costs. Previously, a broader prohibition on spending grant funds on services from the Multi-State Information Sharing and Analysis Center (MS-ISAC) was in place. The new bulletin clarifies that purchasing individual products or services through membership organizations is permissible, provided recipients adhere to federal procurement standards. This clarification comes after some officials expressed frustration with the initial restrictions.Additionally, recipients of federal cyber grants are no longer required to complete the Nationwide Cybersecurity Review, though an alternative assessment may be mandated in the future. This update follows a bill introduced by Senator Mark Warner to restore annual funding to the MS-ISAC, highlighting ongoing discussions about federal support for state and local cybersecurity efforts.Source: Statescoop Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds
Jul 3, 2026 · via scworld.com
News, news analysis, and commentary on the latest trends in cybersecurity technology. Apple Reverses Age-Old Patch Policy to Keep Up With AI Expect more compressed patching cycles from Apple going forward, as attackers leverage artificial intelligence to reduce time to exploit. Apple is changing its approach to security patching, in response to the growing threat of accelerated artificial intelligence (AI) attacks. The company has historically saved big, bundled sets of bug fixes for new versions of its operating system (OS). That's set to change. The company released a variety of security updates June 29 for iPhones, iPads, Macbooks, and the Safari browser, untethered to any major version releases. It's hardly the first time it's released security updates out-of-band, but the motivation was different this time. According to Reuters, the company said "it was adapting to the reality that, given the ability of artificial intelligence to speed the development of malicious hacking tools, it needed to reduce the time between when updates were first made public and when they were put into customers' hands." "I think faster patching helps, but it doesn't fully close the gap, because it's still a single point of defense with no fallback if something slips through," Rocky Cole, CEO of iVerify warns. "And against AI-accelerated discovery, something will slip through." Dark Reading has reached out to Apple for comment on this story. Why Apple Is Changing its Patching Cadence In speaking with reporters, Apple emphasized that none of the newly released fixes pertained to actively exploited vulnerabilities. In other words, the point wasn't to address any known cyberattacks, but to start updating more frequently in general. "The data isn't in dispute when it comes to the need for a different patching cadence," Cole says, citing Mandiant's time to exploit (TTE) findings. "In 2018, the average time
Jul 3, 2026 · via darkreading.com
Michael Nicosia, COO and cofounder at Salt Security. Security teams have spent the last few years securing the wrong things. While enterprises debated AI ethics and model safety, AI agents quietly earned the keys to production infrastructure. At Amazon, an AI coding agent made changes to a production environment without authorization, taking it offline for 13 hours, according to unnamed sources cited by the Financial Times. At McKinsey, as part of a red-team test, an autonomous agent breached their internal AI platform in under two hours and accessed 46.5 million internal chat messages. And at PocketOS, an AI coding agent deleted its database in seconds. Individually, these events may seem unrelated. Together, they point to something bigger: AI is no longer confined to generating outputs. It is being trusted to take action inside live systems. When those actions go wrong, the impact can be immediate and real. The Real Lesson From Early Incidents These incidents are an early signal of how quickly things can go wrong when autonomous systems are given operational access without sufficient controls. A self-running system can execute tasks in a live environment and cause irreversible damage in a matter of seconds. This doesn't mean AI is inherently unsafe. However, most organizations have not yet built the guardrails required for autonomous systems. There are still gaps in how permissions are defined, how actions are validated and how behavior is monitored in real time. When those gaps exist, even well-intentioned systems can create significant risk. From Assistants To Operational Actors Most recent discussions around AI risk have focused on outputs such as accuracy, bias and hallucinations. Those concerns matter, but they only address part of the picture. AI agents are now being deployed to write code, manage infrastructure, trigger workflows and interact directly with critical systems. This changes
Jul 3, 2026 · via forbes.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jul 3, 2026 · via youtube.com
Weâre sorry, this site is currently experiencing technical difficulties.
Please try again in a few moments.
Exception: forbidden
Weâre sorry, this site is currently experiencing technical difficulties.
Please try again in a few moments.
Exception: forbidden
Jul 3, 2026 · via state.gov
Agenda Cyber threats to public sector organizations are no longer a matter of if — they're a matter of when. But true resilience isn't built in the aftermath of an incident. It's built before one ever occurs — and it starts with funding. Join Grants Office, and special guests from Rubrik, Inc., for a Grantscast® designed for technology, security, and grants professionals across state and local government, education, public utilities, and public safety organizations responsible for keeping critical services running and public trust intact. We'll dig into the federal and state grant programs helping public sector organizations fund proactive cyber resilience — what's available, what's eligible, and how to build a competitive case for funding before a crisis forces your hand. We’ll also be joined by Jason Likens from Rubrik, who will share what proactive cyber resilience looks like in practice, including strategies that help organizations improve recovery readiness, protect critical operations, and strengthen continuity of services during cyber incidents and operational disruptions. Register today and you'll leave this webinar with: - A clear map of federal and state funding programs available for cybersecurity and infrastructure resilience - Strategies for writing a compelling grant narrative that positions your organization as a strong, proactive steward of public resources - Guidance on aligning your project scope and budget to funder priorities in the cybersecurity space - Practical insight from Rubrik on the resilience infrastructure that supports both operational continuity and grant eligibility For questions, comments or inquiries into Rubrik for California Public Sector please contact dan.raynes@rubrik.com.
Jul 3, 2026 · via insider.govtech.com
CHICAGO (WLS) -- Fans looking to buy World Cup tickets or merchandise are being warned to watch out for scams as criminals take advantage of the tournament's popularity. The ABC7 I-Team is investigating reports of scammers targeting consumers searching for tickets, jerseys and other World Cup-related items online. One security group has seen a recent 320% increase in malicious websites tied to the event. It could be merchandise like hats or jerseys or a ticket to go see a match. Scam artists capitalizing on the World Cup craze. One security group seeing a recent 320 percent increase in malicious sites. Nati Tal, head of research at Guardio, said increased interest in the tournament creates opportunities for fraudsters. "This is the time you see the games, and you want to buy the soccer shirts," Tal said. Tal said Guardio's cybersecurity team recently found several online shops based in China selling World Cup shirts and jerseys. Security experts warn that consumers may never receive the products they order or could receive fake items weeks later. "Everybody is looking for those events and searching for information and scammers like they always do they have a chance to find more victims using names and brands," Tal said. The FBI has also issued a warning. In May, the agency said it identified more than three dozen domains spoofing the legitimate FIFA website and expects more fraudulent domains to appear. The FBI and Guardio recommend purchasing official, FIFA-licensed merchandise and obtaining World Cup tickets through FIFA's official website. Consumers who buy tickets through third-party sellers should use a verified, trusted source and avoid online classifieds unless they thoroughly vet the seller and meet in person. They also recommend requesting a photo of the seller's driver's license. When asked how consumers can verify they are purchasing legitimate
Jul 2, 2026 · via abc7chicago.com
“Unless you know where you are, it’s very difficult to have a path forward and end up where you want to be,” he said. The Cybersecurity Coalition for Education developed its Cybersecurity Rubic as a K–12 interpretation of the National Institute of Standards and Technology’s standard and other cybersecurity and privacy standards. This 1 to 5 scale tells districts whether their cybersecurity posture is reactive and unprepared or proactive and resilient. Once your posture is defined, the next step is prioritization. “The next part is to identify where your areas of improvement and gaps are,” Ashley said. “Then, you have to make well-informed decisions on what the next steps are, because how you add your protections in the right order is how you’re going to get the biggest bang for your buck and decrease your attack surface.” He warned attendees against what he called “random acts of cybersecurity” — creating a reactive, piecemeal cybersecurity defense without a cohesive strategy. Instead, he urged leaders to focus first on essentials: a firewall, backup and recovery solutions, multifactor authentication, endpoint protection, and a practiced incident response plan. Ashley also noted that some of the most impactful changes are rooted in policies, not products. He told a story about how an email spoofing incident once cost him his paycheck. DISCOVER: A clear roadmap can help districts build cybersecurity maturity. “As soon as I heard how that happened, I was able to make some really simple changes,” he said. “Some of these protections we’re talking about don’t cost dollar signs. What it took to fix this situation was procedures, policies and guidelines.” A Rubric-Driven Approach to Vetting Digital Resources This strategic mindset around tool adoption, as well as the policies and procedures that define them, can extend to how districts adopt other ed tech tools.
Jul 2, 2026 · via edtechmagazine.com