No-frills tech news

Snyk to lay off 90 employees - Globes English

Israeli veteran cybersecurity company Snyk is embarking on a fourth round of layoffs. An email was sent out this morning to about 90 of the company's employees in Israel and the rest of the world, explaining the need to cut personnel, after which several dozen employees were called to a hearing. The layoffs are being carried out across the company's US centers, but in Israel, where the company's number of employees is small anyway, the layoffs constitute a significant blow to the development center. In 2022-2023, Snyk carried out three rounds of layoffs in Israel and in offices around the world, involving over 350 employees. Snyk was founded by Israelis in the UK and the US, and in 2020 operated a development center in Israel with several hundred employees, but gradually increased its activity abroad, when the Israeli founders, led by former CEO Guy Podjamy also stepped down in favor of US management. The company has about 1,550 employees, of which only about 90 are in Israel, according to the social network for jobs LinkedIn. Despite this, the Israeli center employs high-quality cybersecurity and software engineers. Peter McKay, who has led the cyber company since 2019, announced earlier this year that he would leave his position, noting that the company's next phase requires leadership "with deep roots in product innovation and AI." The impact of the launch of Claude Code’s software update Snyk, like its rivals Checkmarx and GitHub, was affected by the launch of the Claude Code software update last February, which scans code to detect cybersecurity breaches. Snyk and Checkmarx are also involved in code scanning, with their reputation damaged by the launch. While these companies are making efforts to adapt to the age of AI, investors prefer to put their money in newer companies born into the

Indiana invests in statewide <b>cybersecurity</b> pathway

Dive Brief: - Indiana is expanding cybersecurity pathways for high school students this fall through a statewide initiative with partners including College Board, Ivy Tech Community College, the Indiana Chamber of Commerce Defense Council, and Project Lead the Way, an Indiana-based nonprofit STEM curriculum provider. - The initiative will build an academic pathway from Advanced Placement Cybersecurity and Project Lead The Way cybersecurity courses offered in high schools to two- and four-year colleges, the Indiana National Guard and other employers, according to the Indiana Department of Education. - The Indiana National Guard has flagged cybersecurity education as a priority for homeland protection, Katie Jenner, Indiana Secretary of Education, said. Cybersecurity coursework is currently offered in 69 high schools around the state, with plans to expand to 200 over the next three years. Dive Insight: Katie Jenner, Indiana Secretary of Education, said the state has been talking about how to prepare students to both work in the cybersecurity field and know how to better protect themselves and others from cyber threats. “There’s daily conversation about how to make sure we are as ready as possible and continuing our preparation for potential cybersecurity threats,” she said. “That has hit home for Indiana, and that has hit home for our national security. … It hits home in the education sector.” The state recently faced cybersecurity breaches when data was allegedly stolen from a couple of major education-related vendors that had contracts in the state, Jenner said. “It’s all very real,” she said. “We had been talking about it for a while.” The Indiana initiative aims to enable students to gain practical classroom experience, college credit, work-based learning and industry-recognized credentials, according to the partners. The College Board has spent the past five years thinking more strategically about how to link AP courses with

<b>Cybersecurity</b> experts: Old threats growing more dangerous in the age of AI

Cybersecurity experts: Old threats growing more dangerous in the age of AI (TNND) — A new alert from the "Five Eyes" intelligence-sharing alliance, including the U.S., warns governments, businesses and other organizations about fast-moving, supercharged cybersecurity threats driven by artificial intelligence. The alert also urges organizations to fight fire with fire, deploying AI to fight off cyberattacks. The alliance, which includes Australia, Canada, New Zealand and the U.K., said governments and businesses must act swiftly to stay ahead of the AI threat. “Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities,” the joint statement released Monday reads. “The timeline is not years, it is months.” Cybersecurity expert Demetrice Rogers, who teaches at Tulane University, said the “Five Eyes” statement wasn’t breaking news. Security experts are already aware of the threats laid out by the agencies. But Rogers said it’s a valuable reminder that AI amplifies existing cybersecurity risks. C. Jordan Howell, a criminologist and cybersecurity expert who teaches at the University of South Florida, similarly said that security professionals have been discussing AI-enabled cyber threats for some time. “What is different is that the threat is becoming more operational, more scalable, and harder for non-specialists to fully understand,” Howell said via email. Both Rogers and Howell said AI isn’t creating new categories of cyber threats. Rather, the powerful new technology is arming bad actors with more efficient and believable attacks. “Phishing messages become more polished. Social engineering becomes more personalized. Malware development and vulnerability discovery can become faster. Fraud attempts can be adapted to specific victims with less effort,” Howell said. “In that sense, AI lowers the barrier to entry for less sophisticated offenders while also giving more capable actors a force multiplier.” The “Five Eyes” alert urges governments and businesses

Hyundai Motor and Kia Spearhead Cross-border <b>Cybersecurity</b> Initiative with Trilateral ...

Corporate Information Hyundai Motor and Kia Spearhead Cross-border Cybersecurity Initiative with Trilateral Executive Dialogue Partners Please use Safari to download the files. Hyundai Motor and Kia Spearhead Cross-border Cybersecurity Initiative with Trilateral Executive Dialogue Partners SEOUL, June 24, 2026 â Hyundai Motor Company and Kia Corporation today announced the establishment of a new cybersecurity working group within the Korea-U.S.-Japan Trilateral Executive Dialogue (TED), strengthening private sector-led collaboration against escalating cyber threats. Hyundai Motor and Kia led the creation of the cybersecurity working groupâTEDâs first topic-specific subgroup. They marked the launch by hosting the working group's inaugural seminar at their headquarters in Seoul, uniting members against escalating digital threats. The TED is a policy seminar that brings together key government and business leaders from Korea, the U.S. and Japan. Its mission is to explore diverse opportunities for democratic and shared prosperity, engaging in deep discussions on expanding mutual interests in areas such as economic development and national security. As global supply chain connectivity deepens, a response to cybersecurity threats that transcends borders is no longer optional, but essential. We have high expectations that this working group will help establish a practical and effective security cooperation system. Senior Vice President and Head of HMG Security Center at Hyundai Motor Group As the lines between virtual and physical spaces blur and technologies like artificial intelligence (AI) and Internet of Things (IoT) become widely adopted, cyberattacks are growing in frequency and sophistication. The increasing connectivity of global supply chains means that a single breach can cause cascading damage across multiple companies and industries. In response to this escalating threat, Hyundai Motor and Kia, both TED member companies, plan to facilitate regular seminars through the working group. These sessions will provide a platform for TED member companies from various nations and industries to share the

<b>Cybersecurity</b> - Blogs: Bitcoin ATMs - Dark Side of Cryptocurrency

PERSPECTIVES FROM THE FIELD The strength of Indiana is that we bring together a variety of perspectives from the plethora of areas that touch the field of cyber, especially through the Indiana Executive Council on Cybersecurity (IECC). Hence the name "Perspectives From the Field Series" in which we invite experts to discuss the real and challenging issues we are facing in the field and the proposed solutions from the experts to better the lives and businesses of all Hoosiers. In the second of a three-part blog series, members of the Council’s Finance Committee share their knowledge and expertise about the emergence of Bitcoin ATM machines, the scams that are happening when they’re being used and why – beginning very soon – they’ll be disappearing from the retail locations they’ve occupied in convenience stores, gas stations, smoke shops and liquor stores throughout the Hoosier state. Providing their perspective is Joe Henrich, who serves as the senior vice president of technology for Horizon Bank and Brian Avery, who is the chief technology officer at Star Bank. By Joe Henrich and Brian Avery Seventeen years after the first transaction involving Bitcoin was completed, cryptocurrency is continuing to be used for a myriad of legitimate transactions globally, as well across the country and here in Indiana. Unfortunately, it is the Bitcoin ATMs that are being used, with increasing frequency, by cybercriminals to target their victims. Currently, there are 45,000 Bitcoin ATMs in the U.S., and according to the Federal Bureau of Investigation (FBI), in 2024, reported that scams perpetrated using bitcoin ATMs cost Americans nearly $250 million – a figure that is more than double the sum from the previous year. How do they do it? Scammers rely on urgency, fear, and secrecy to manipulate their victims. If you receive a message or come

What CISA's CI Fortify Initiative Means for State and Local Governments

Infrastructure Protection Requires Integrated IT and OT Security For years, many organizations attempted to air gap critical systems by keeping them disconnected from broader networks. In practice, however, most operational environments eventually became connected because organizations wanted access to data for operational efficiency, analytics and business decision-making. That connectivity created new opportunities, but it also introduced new attack surfaces. CI Fortify is a useful reminder for agencies to revisit the technology decisions they have made around critical infrastructure. That does not necessarily mean disconnecting systems entirely. It means taking a thoughtful approach to segmentation, resilience and operational continuity. Agencies should evaluate which functions are truly mission-critical, what can operate manually during an outage and how systems can be isolated if necessary. Preparedness also requires agencies to think differently about risk. In cybersecurity, organizations often focus heavily on prevention, but critical infrastructure resilience also depends on understanding impact and velocity. If a disruption occurs, how severe would the consequences be? How quickly could the situation escalate? Would agencies have minutes to respond, or weeks? Those questions matter because attacks against critical infrastructure are fundamentally different from traditional cybercrime. In some cases, the objective may not be to steal information or collect ransom payments. The objective may be to create confusion, panic or operational disruption. We have already seen examples globally of cyberattacks targeting infrastructure systems in ways that caused lasting operational damage. In some incidents, attackers did not simply disable systems temporarily. They rendered devices unusable, forcing organizations to replace physical equipment and navigate difficult supply chain challenges. That kind of disruption changes the entire response model. READ MORE: Government IT teams now own many physical security responsibilities. Infrastructure Resilience Depends on Planning Beyond Technology State and local governments are not just responsible for restoring technology services. They also have to

MNDR expands into <b>cybersecurity</b> via Skylink, Contfinity

Mobile-health Network Solutions Expands into Cybersecurity with Skylink-Contfinity Partnership, Launching OttterSG Bundled Solution for Clinics in Singapore Rhea-AI Summary Mobile-health Network Solutions (NASDAQ: MNDR) announced that subsidiary Skylink Innovations signed a Strategic Partnership Agreement with Contfinity to deliver a bundled OttterSG clinic management and managed cybersecurity solution in Singapore. The offering targets over 2,400 clinics, integrates CMS and cybersecurity, supports MOH/CSA/PDPC compliance, and aligns subscription packages with Singapore’s Cyber Essentials Mark and relevant grant schemes. AI-generated analysis. Not financial advice. Positive - Strategic partnership with Contfinity to bundle OttterSG CMS and cybersecurity - Access to a potential base of over 2,400 clinics in Singapore - Solution supports MOH, CSA, and PDPC compliance requirements - Subscription packages aligned with Singapore’s Cyber Essentials Mark and grants Negative - None. Key Figures Peers on Argus MNDR traded weaker while health information peers were mixed, with some like LFMD and HCAT up and others such as SLP and SOPH down, pointing to a stock-specific rather than sector-wide move. Previous Partnership Reports | Date | Event | Sentiment | Move | Catalyst | |---|---|---|---|---| | Jun 27 | Strategic partnership | Neutral | +1.4% | Partnership to extend affordable telemedicine services to Ryde driver-partners. | Tag-specific history for partnerships is limited, with the prior partnership headline followed by a modest positive move. Historical Comparison In the past year, MNDR has only one recorded partnership headline, linked to a modest +1.44% move. This new cybersecurity-focused partnership extends that collaboration theme into clinic operations and data protection. Market Pulse Summary The stock is surging +10.9% following this news. A strong positive reaction aligns with MNDR’s push into AI-enabled health infrastructure, now extended to cybersecurity for 2,400+ clinics. Investors may still watch capital structure changes and execution risk in scaling OttterSG subscriptions. Key Terms endpoint protection technical AI-generated

​What <b>Cybersecurity</b> Marketing Can Teach About Trust And Demand Generation

David Steifman, Cofounder of Energize Marketing. Having spent much of my career working with cybersecurity companies, marketers and buyers globally, I’ve seen firsthand how differently this industry evaluates trust, credibility and engagement. Cybersecurity buyers rarely engage casually. They question claims, validate sources and carry real accountability for the decisions they make. In today’s environment, where AI-generated content, automated outreach and endless streams of information compete for attention, that dynamic feels even more important. It shapes how buyers consume content, evaluate vendors and ultimately make decisions. It also plays a major role in what drives pipeline growth in cybersecurity marketing. Over the past year, our team took a closer look at how cybersecurity demand generation teams are operating today, not just in theory, but in practice. The findings helped shape Energize Marketing’s 2026 Cybersecurity Demand Generation Report, which examined what separates programs that consistently build pipeline from those that struggle to sustain momentum. Useful Insights At a surface level, many cybersecurity marketing organizations look similar. Most are investing heavily in intent data, full-funnel content strategies and multi-channel engagement programs. In many ways, cybersecurity marketers are ahead of other industries in adopting data-driven approaches and modern demand generation tactics. But when you look more closely, the difference between teams that consistently generate pipeline and those that do not becomes much clearer. It is rarely a technology problem. More often, it comes down to trust, execution and how well organizations turn buyer engagement into meaningful action. Intent Data Cybersecurity marketers now operate in one of the most signal-rich environments in B2B marketing. Our 2026 Cybersecurity Demand Generation research at Energize Marketing found that while 99% of cybersecurity marketers use third-party intent data, only 7% consider it “very effective.” That gap says a lot about where the market is today. The issue is no

Community Fireside Chat | What Happens Next? A Real Incident Walkthrough and the ...

Upcoming Webinar Community Fireside Chat | What Happens Next? A Real Incident Walkthrough and the "Breach Coach" Playbook You have an Incident Response Plan on paper, but what actually happens when you have to deploy it in the real world? This July, we’re hosting a candid walkthrough of a recent, anonymized cyber attack to look at the practical reality of containing a breach and the common mistakes organizations make under pressure. We will also break down the breach coach consultation process to show you exactly why legal counsel should be your very first phone call—explaining how a breach coach legally protects your investigation data, coordinates with insurance, and keeps your crisis management strategy safely on the rails. * HUNTRESS WEBINAR GIVEAWAY TERMS. Live webinar participants may be eligible to receive one (1) Nintendo Switch 2™ + Mario Kart™ World Bundle (“Gift”), worth approximately USD $500.00. This gift giveaway (“Giveaway”) is sponsored by Huntress Labs Incorporated (“Huntress”). By registering for the above Huntress webinar (“Webinar”), you accept the following Huntress Webinar Giveaway Terms and all decisions of Huntress, which are final and binding in all respects. NO PURCHASE NECESSARY. PURCHASE OF HUNTRESS PRODUCTS OR SERVICES DOES NOT ENHANCE CHANCES OF RECEIVING THE GIFT. Eligibility: The Giveaway is applicable to individuals who are 18 years of age or older who register for and participate in the Webinar. All applicable laws and regulations apply. Void where prohibited or restricted by law, including, but not limited to, international sanctions. Subject to applicable law, the Gift is offered “as is” without any express or implied warranty of any kind or nature, including without limitation, any warranty respecting condition, merchantability, quality, title, or fitness for a particular purpose. Selection: One (1) gift recipient will be selected at Huntress's sole discretion based on their live engagement in

House passes Rep. Bresnahan's <b>cybersecurity</b> legislation

The U.S. House of Representatives unanimously passed cybersecurity legislation co-led by Rep. Rob Bresnahan, R-Dallas Township, on Tuesday. The Small Business Cybersecurity Assistance Evaluation Act of 2026 aims to ensure small businesses are protected from cybersecurity risks by studying the effects of these attacks on them. The legislation was first passed out of the House Committee on Small Business on May 20, by a bipartisan vote of 23-0. “In the United States, small businesses are 210% more likely to experience cyber incidents compared to larger companies,” said Bresnahan. “Despite this, many of our small businesses lack the resources and expertise necessary to defend against these threats. This legislation will help ensure that as cyber threats continue to evolve, our support systems for small businesses evolve as well.” Specifically, the legislation directs the U.S. General Accountability Office (GAO) to evaluate federal cybersecurity assistance to small businesses. The bill would require a study to analyze cyber risks, vulnerabilities, and current initiatives, and to identify shortcomings in current preventive and mitigation measures. “Small businesses are the foundation of main streets across the country, and we cannot leave them behind as digital infrastructure becomes more unpredictable,” said Bresnahan. “By finding the gaps in current programs, this bill will give our small businesses better access to the tools, training, and resources they need to strengthen their defense against cyberattacks.”

Bresnahan's <b>Cybersecurity</b> Legislation Passes U.S. House

Bresnahan’s Cybersecurity Legislation Passes U.S. House WASHINGTON, DC: Today, the U.S. House of Representatives unanimously passed cybersecurity legislation co-led by Representative Rob Bresnahan, Jr. (PA-08). The Small Business Cybersecurity Assistance Evaluation Act of 2026 will ensure small businesses are protected from cybersecurity risks by studying the effects these attacks can have on small businesses. The legislation first passed out of the House Committee on Small Business on May 20, by a bipartisan vote of 23-0. “In the United States, small businesses are 210% more likely to experience cyber incidents compared to larger companies,” said Rep. Bresnahan. “Despite this, many of our small businesses lack the resources and expertise necessary to defend against these threats. This legislation will help ensure that as cyber threats continue to evolve, our support systems for small businesses evolve as well.” Specifically, the legislation directs the U.S. General Accountability Office (GAO) to evaluate Federal cybersecurity assistance to small businesses. The bill would require a study to analyze cyber risks, vulnerabilities, and current initiatives and identify shortcomings of current preventative and mitigating measures. “Small businesses are the foundation of Main Streets across the country, and we cannot leave them behind as digital infrastructure becomes more unpredictable,” continued Rep. Bresnahan. “By finding the gaps in current programs, this bill will give our small businesses better access to the tools, training, and resources they need to strengthen their defense against cyberattacks.” ###

Mobile-health Network Solutions Expands into <b>Cybersecurity</b> with Skylink-Contfinity ...

Singapore, Singapore--(Newsfile Corp. - June 23, 2026) - Mobile-health Network Solutions (NASDAQ: MNDR) ("MHNS"), a leading AI-powered digital health platform headquartered in Singapore, today announced that its subsidiary Skylink Innovations Pte. Ltd. has entered into a Strategic Partnership Agreement with Contfinity Pte. Ltd. to deliver a bundled offering of the OttterSG Clinic Management System (CMS) and managed cybersecurity services to healthcare providers in Singapore. With more than 2,400 general practitioner clinics across Singapore, the healthcare sector is increasingly reliant on secure digital infrastructure. This partnership introduces a new market segment where clinic operations and cybersecurity are integrated into a single solution, marketed under the OttterSG brand. The partnership combines Skylink's OttterSG CMS, a smart clinic management system that streamlines patient registration, medical records, billing, and compliance, with Contfinity's cybersecurity expertise, including endpoint protection, backup and recovery, and CISO-as-a-Service advisory. Together, the bundled solution empowers clinics to meet rising cybersecurity and data protection requirements while enhancing operational efficiency. Together, the combined solution is marketed as a bundled offering under the OttterSG platform, designed to help clinics meet MOH, CSA, and PDPC compliance requirements while improving operational efficiency. Under the agreement, Skylink will lead subscriber onboarding, CMS implementation, and billing, while Contfinity will provide cybersecurity advisory, monitoring, and compliance support. The bundled solution will be marketed under the OttterSG brand, with subscription packages designed to align with Singapore's Cyber Essentials Mark certification and prevailing grant schemes. This partnership underscores MHNS's mission to make healthcare accessible, intelligent, and human - through technology, while reinforcing Singapore's position as a hub for secure, AI-driven healthcare innovation. "This partnership represents a significant step forward in safeguarding Singapore's healthcare providers. By combining clinic management with advanced cybersecurity, we are enabling clinics to operate securely, efficiently, and with confidence in a digital-first healthcare environment," said Siaw Tung Yeng,

Club learns about <b>cybersecurity</b> issues | News, Sports, Jobs

Club learns about cybersecurity issues ELKINS – Frank Hatten, MS, Director of Operations and Outreach for the Cyber-Resilience Resource Center (CRRC) and Adjunct Professor of Cybersecurity at West Virginia University, addressed the Rotary Club of Elkins, describing how the Center helps organizations across the state strengthen their cybersecurity. The CRRC partners student talent with West Virginia businesses, nonprofit organizations, and government entities to help them solve real-world cybersecurity and IT challenges. “When we increase security, that can be an inconvenience, but there is a reason behind it. That six-digit code sent to your phone helps protect you and adds another layer of protection to your password. If somebody compromises your password, through no fault of your own, there is hopefully a second way to prevent that threat actor from getting in there,” Hatten said. “When we increase security, we decrease end-user convenience. It can be a pain, but it does help protect you.” Small organizations and rural communities can be attractive targets for cybercriminals and nation-state actors because they often have fewer cybersecurity resources than larger organizations. The Center’s student teams work with businesses, nonprofit organizations, and local governments to increase awareness of cybersecurity, data privacy, and online safety to help identify practical ways to reduce personal and organizational risk. Services range from basic cybersecurity assessments to proposing potential fixes or drafting policies and procedures that are lacking and are free to any WV business, non-profit, organization, government, or critical infrastructure. The only costs associated with implementing the Center’s recommendations are the expenses an organization may choose to incur for new or upgraded software or hardware. Many businesses do not have reliable backups of their critical data. The Center’s team can assist in creating policies and procedures related to safeguarding data. Cybersecurity awareness training is also offered, either online or

Parliament has approved the National <b>Cybersecurity</b> Agency Order, 2026, clearing the way ...

Parliament has approved the National Cybersecurity Agency Order, 2026, clearing the way for Kenya to establish an autonomous body to coordinate national cybersecurity policy, operations and enforcement across government, private operators and critical infrastructure providers. The agency, created under the State Corporations Act through an order issued by President William Ruto, will become a body corporate tasked with preventing, detecting and responding to cyber incidents as Kenya’s reliance on digital systems grows. The new agency will manage the National Cybersecurity Operations Centre, oversee sector-based cybersecurity units, audit critical infrastructure and issue technical advisories on emerging threats. It will also establish a Cybersecurity Centre of Excellence to support research, innovation and skills development in cyber defence, while working with security agencies, regulators, academia and industry players to improve standards and information sharing. Its board will include representatives from internal security, the National Treasury, ICT authorities, police, intelligence, the military, the Attorney-General, the Director of Public Prosecutions, academia and the private sector. The more consequential question is not whether Kenya needs a stronger cybersecurity capability, but whether the new agency can maintain enough institutional independence to distinguish genuine cyber threats from political discomfort. Around the world, cybersecurity powers have at times expanded beyond protecting networks to policing speech, monitoring dissent and restricting digital spaces during periods of political tension, often under the broad justification of national security. Kenya's digital economy depends on trust as much as technology, and that trust could be eroded if businesses, journalists, civil society groups, or ordinary citizens come to view cybersecurity enforcement as a tool for surveillance or selective pressure rather than protection. The concentration of security agencies, intelligence services and law enforcement bodies within the NCSA's governance structure makes transparency, judicial oversight, and clear accountability mechanisms more than administrative details; they are safeguards against mission creep.

10 <b>Cybersecurity</b> Priorities for E-Commerce Teams This Year

| Key Takeaways | | 1. E-commerce is the second most targeted sector for DDoS and bot-based attacks in 2026 | | 2. Account takeover, bot abuse, and payment fraud are the three highest-probability threats for most e-commerce teams. All three are automated, scalable, and designed to look like normal traffic until the damage is already done. | | 3. Group-IB’s unified platform with Fraud Protection, Threat Intelligence, Digital Risk Protection, Attack Surface Management, and IR Retainer provides e-commerce security teams with intelligence-led coverage across every priority, from dark web activity targeting their platform to the fake storefronts their customers encounter. | Your platform is open 24 hours a day. So are the attacks. There’s no closing time in e-commerce, hence the importance given to e-commerce cybersecurity priorities. While your team sleeps, your checkout pages are live, your login forms are exposed, and the third-party scripts across your storefront are running without anyone watching. Attackers don’t keep business hours. They run automated tools around the clock, probing the same surfaces your customers use, waiting for the moment your defenses are thinnest. E-commerce is the second most targeted sector for DDoS and bot-based attacks in 2026. Not because the industry is careless, but because it’s valuable, always available, and built on layers of integrations that no single team has full visibility over. 73% of people surveyed in the WEF Global Cybersecurity Outlook 2026 said someone in their personal network was affected by cyber-enabled fraud in 2025. Those are your customers. When fraud affects them through your platform, the trust they had in you is lost. The top 10 e-commerce cybersecurity priorities in 2026 are: account takeover prevention, geopolitical threat monitoring, bot abuse defense, AI vulnerability management, payment fraud controls, ransomware resilience, dark web monitoring, brand impersonation detection, third-party supply chain risk,

Five Eyes intelligence alliance warns of threats from new AI models

Five Eyes intelligence alliance warns of threats from new AI models Frontier AI models are ‘fundamentally transforming’ offensive cyber capabilities, intelligence officials say. Cutting-edge artificial intelligence technology is poised to supercharge offensive hacking capabilities, and urgent action is needed to face up to the threat, US, UK, Canadian, Australian and New Zealand officials have said. “Frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities,” the intelligence alliance commonly known as the Five Eyes said in a three-page statement on Monday. Recommended Stories list of 4 items- list 1 of 4Ghalibaf: US and Iran can work together to reopen Strait of Hormuz - list 2 of 4World Cup knockouts: Who has made it to the round of 32 stage? - list 3 of 4US watchdog opens probe after Tesla crashes into Texas home, killing woman - list 4 of 4Haaland double rows Norway into World Cup knockouts with Senegal win “The timeline is not years, it is months.” The statement was light on detail and mostly restated core cybersecurity advice, such as swiftly patching faulty software and not putting systems online unless necessary. The officials also urged defenders to use AI “to strengthen defence”, for example by identifying weaknesses sooner or responding more quickly to incidents. The warning was another indication of officials’ increasing concerns over models such as Anthropic’s Mythos or OpenAI’s GPT-5.5-Cyber, which are said to allow users to quickly execute complex – and potentially devastating – hacks. Earlier this month, Anthropic was forced to disable a version of Mythos after the US government ordered it to suspend access to the models for foreign nationals over alleged national security concerns. Around the same time, the US cyber-defence agency, CISA, which was among those co-signing Monday’s statement, reduced the deadlines imposed

Trump signs executive orders accelerating quantum computing innovation and post ...

WASHINGTON — President Donald Trump signed two executive orders Monday aimed at cementing U.S. leadership in quantum technologies, accelerating the development of powerful quantum computers and sensors while racing to protect the nation’s data from future quantum-powered cyberattacks. The actions, Executive Order 14411 on ushering in the next frontier of quantum innovation and Executive Order 14409 on securing the nation against advanced cryptographic attacks, were signed at the White House as part of a broader push to maintain America’s technological edge against global competitors, particularly adversarial nations seeking to challenge U.S. supremacy in the field. “The first Executive Order launches a national effort to produce a Quantum Computer capable of performing important scientific calculations, and to develop quantum-enabled sensors and networks in the next five years,” Trump said in remarks ahead of the signing. “The second order I’m signing directs federal agencies to transition to what is called Quantum cryptography […] for their computer systems by 2031 and to lead the way for the wider adoption of these extremely strong security standards.” The quantum innovation order directs a whole-of-government approach to update the National Quantum Strategy, establish a national effort for a quantum computer powerful enough to enable scientific discovery, and prioritize quantum sensors and networks. It calls for plans from key agencies including Commerce, Energy, War, and NASA to advance commercialization, workforce development, and domestic supply chains while protecting sensitive technologies. “With this Executive Order, and this coordinated effort, we will have scientifically-relevant […] Quantum Computing during this administration. The impacts of it will be tremendous,” Energy Secretary Chris Wright said. The White House highlights Trump’s earlier role in signing the National Quantum Initiative Act in 2018 and doubling federal investment in quantum research and development. It emphasizes transformational capabilities in manufacturing, drug discovery, energy, agriculture and more that

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor code into Pro plugin releases distributed through official licensed update channels," Wordfence said in an analysis published last week. The incident affects the following plugins - - Product Slider Pro for WooCommerce (versions before 3.5.4) - Real Testimonials Pro (version 3.2.5) - Smart Post Show Pro (versions before 4.0.2) As mentioned above, it's worth emphasizing that the compromise only affects Pro plugin builds distributed through the vendor's Easy Digital Downloads (EDD) infrastructure via account.shapedplugin[.]com. The free versions of the plugins on WordPress.org are not impacted. The supply chain compromise associated with Product Slider Pro for WooCommerce has been assigned the CVE identifier CVE-2026-49777, along with a CVSS score of 10.0, indicating maximum severity. CVE-2026-10735 (CVSS score: 9.8) is the CVE identifier for the entire incident. The WordPress security company said the compromised versions of the plugins incorporate a loader that's triggered on every admin page, causing it to fetch a payload from a remote server ("194.76.217[.]28:2871"), install it, and activate it as a fake plugin. Once it's activated, the malware reports the victim domain back to the server and erases itself to cover up the tracks and complicate incident response efforts. The counterfeit plugin, for its part, hides itself from the WordPress admin plugin list and is capable of capturing credentials in plaintext and two-factor authentication (2FA) codes. It also establishes multiple persistence methods that enable arbitrary file writes via a custom REST endpoint when provided a specific authentication token, as well as drop a web shell with command execution features. Lastly, it makes use of a PHP file named "install-persistent.php," which