No-frills tech news

BIO-key International to Join Jordan Banking <b>Cybersecurity</b> and Identity Workshop in Amman

BIO-key International will participate in a cybersecurity workshop in Amman, focusing on identity security and authentication strategies. Quiver AI Summary BIO-key International, Inc. will participate in an exclusive cybersecurity and identity workshop in Amman, Jordan, on July 6, 2026, organized by the Association of Banks in Jordan. The event will gather leaders from various banks and financial institutions to discuss pressing issues like cyber threats, identity security, and modern authentication strategies. Attendees will gain insights into BIO-key’s solutions, such as Identity-Bound Biometrics and the PortalGuard IAM platform, which support passwordless authentication to enhance security and user experience. The workshop aims to address the evolving cybersecurity landscape and reinforce identity security as a priority for regional financial institutions undergoing digital transformation. Both BIO-key and the Association of Banks in Jordan emphasized the importance of equipping banking leaders with tools and knowledge to meet these challenges effectively. Potential Positives - BIO-key's participation in a prestigious, invitation-only cybersecurity workshop demonstrates its recognition as a leader in identity and access management, enhancing its brand reputation within the banking sector. - Engagement with over 25 banking institutions and C-level executives provides BIO-key with valuable networking opportunities and potential partnerships in the rapidly evolving cybersecurity landscape. - The focus on passwordless authentication solutions positions BIO-key at the forefront of modern security needs, catering to the increasing demand for enhanced digital experiences and improved security in financial institutions. Potential Negatives - The emphasis on forward-looking statements may signal a lack of immediate product or market traction, raising concerns about the company's current performance. - The need for ongoing support in the Jordanian banking sector highlights potential weaknesses in clients' current security measures, implying dissatisfaction or vulnerabilities that could affect BIO-key's reputation. FAQ What is the focus of the cybersecurity workshop in Amman? The workshop focuses on addressing

On the frontline: <b>Cybersecurity</b> teams lead the charge in securing companies' data and cargo

The American Transportation Research Institute (ATRI) calculates that cargo theft costs the trucking industry over $18 million per day. And according to CargoNet, strategic theft, a category of crime that uses deception, identity theft and fraudulent documentation to divert freight, has surged by 1,500% since 2021. Ninety percent of motor carriers are small businesses operating 10 trucks or less, and they’re under enormous strain to counter these technologically advanced adversaries. In addition, the transnational aspect of cargo theft also poses a national security threat. The proceeds from stolen goods finance other criminal activities, including drug trafficking, organized crime and even potentially terrorism. Navigating a New Normal During a recent webinar presented by the Truckload Carriers Association (TCA), Scott Cornell, chief risk officer for SPG Cargo and Logistics, said cargo theft trends in the U.S. have fundamentally changed. Carriers and law enforcement are navigating a “new normal” in the fight against cargo theft. “Unless something drastically changes or there’s more regulation through the federal government around things that could prevent cargo theft, there’s no sign that cargo theft is gonna go down,” he said. According to a report from Overhaul, for the first time since 2021, U.S. cargo theft declined year over year in the first quarter of 2026 — but that relief may be short-lived. The National Motor Freight Traffic Association (NMFTA) noted in its most recent Transportation Industry Cybersecurity Trends Report that the most dramatic increase in cargo theft occurred in the New York City metropolitan area, specifically New Jersey and eastern Pennsylvania (up 110% and 33%, respectively). Dangerous Combination Analysts attribute these spikes to the adoption of cybercrime tactics by organized criminal networks that leveraged social engineering to impersonate carriers, hijack Federal Motor Carrier Safety Administration (FMCSA) accounts and manipulate load tenders and other dispatch documentation. “The result

Dutch <b>cybersecurity</b> startup Dawnguard lands €2.8 million for AI-native security architecture ...

Amsterdam-based cybersecurity startup Dawnguard has announced the public launch of its security architecture automation platform, alongside an additional €2.8 million ($3.3 million) in pre-Seed funding. The round came from existing investor BNVT Capital in the UK, with new participation from Curiosity VC in the Netherlands and eCAPITAL in Germany. According to the company, the fresh capital brings Dawnguard’s total funding to more than €5.5 million ($6.3 million). This comes one year after they emerged from stealth with €2.6 million in pre-Seed funding – as covered by EU-Startups. “Cybersecurity has become trapped in an endless cycle of detection, response, and patching,” says Mahdi Abdulrazak, CEO and co-founder of Dawnguard. “For twenty years, security was something you added later. That model was already fragile. Today, against an attacker running at machine speed, it becomes increasingly indefensible. When probing is continuous and cheap, the only thing that holds is what was designed correctly from the start.” Dawnguard’s additional pre-Seed round comes amid continued 2026 activiy of European companies working on cybersecurity automation, AI-agent security, cloud infrastructure security, software supply-chain protection and adjacent digital identity infrastructure. Relevant rounds reported this year include Cloudsmith’s €61.5 million Series C for AI-driven software supply-chain security, Geordie AI’s €25 million Series A for AI-agent governance, NeuralTrust’s €17.2 million Seed round for enterprise AI-agent security, Escape’s €15.4 million Series A for offensive security engineering, and Cloudgeni’s €858k raise for secure cloud infrastructure automation. In the Netherlands, Amsterdam-based Duna raised €30 million for AI-native business identity and onboarding, an adjacent trust-infrastructure segment. Taken together, adjacent 2026 rounds represent approximately €224 million in funding, indicating active investor interest in security tooling that moves beyond reactive monitoring towards earlier-stage design, governance, identity and infrastructure controls. “Every engineering team understands the gap between what was designed and what ultimately gets deployed,” adds Kim

Securing MedTech's Digital Future: AI, <b>Cybersecurity</b> &amp; Compliance | Fierce Biotech

Webinar Securing MedTech's Digital Future: AI, Cybersecurity & Compliance As medical technology evolves, so do the threats - and the regulations designed to counter them. This webinar explores the critical intersection of AI, connected devices, and security in the MedTech industry. This webinar brings together thought leaders to explore: - The rising tide of cyberattacks hitting MedTech - from ransomware shutting down operations to credential theft exposing ePHI - AI security risks unique to MedTech - model vulnerabilities, data privacy, and egovernance gaps - IoT and connected device threats - and what a breach in one system means for the whole network - Navigating HIPAA and FDA regulations in an era of rapid digital transformation - What a modern security posture looks like for MedTech organizations building resilient, compliant operations

Old Dominion University Launches First Ph.D. in <b>Cybersecurity</b> in Virginia

For years, professionals seeking a doctorate in cybersecurity had few options beyond computer science or engineering. Old Dominion University is opening a new path. The University’s nationally recognized School of Cybersecurity has launched a new Ph.D. in cybersecurity designed to prepare the next generation of cyber leaders, researchers and educators as the world faces new and complex security challenges. The Ph.D. program will highlight the interdisciplinary nature of the rapidly evolving field of cybersecurity, with artificial intelligence and other emerging technologies. Students from a wide range of educational and professional backgrounds are encouraged to contribute diverse perspectives that advance cybersecurity research. “The coursework and research pathways are designed for people from different backgrounds,” said Daniel Takabi, Ph.D., professor, director of the School of Cybersecurity and Batten Endowed Chair of Cybersecurity. “Our Ph.D. program offers advanced technical specializations, alongside comprehensive pathways in strategic cybersecurity management, policy, legal and human factors in cybersecurity.” This unique program is among the first of its kind in the nation and the only Ph.D. in cybersecurity in Virginia. It also represents a new phase of growth for the school, which celebrated its 10th anniversary this year. Dr. Takabi touted the school’s expanding programs in cybersecurity and artificial intelligence, as well as research efforts to advance the University’s national reputation as a R1 research institution. The school is also growing its research faculty and partnering with federal and regional agencies to address real-world needs. Over the last decade, the School of Cybersecurity has grown from a handful of students to approximately 1,700 and has gained several national recognitions, including the National Security Agency (NSA) designations as Centers of Academic Excellence in Cyber Defense, Cyber Operations and Cyber Research. The NSA also granted the University official validation for its cyber artificial intelligence programs of study. Old Dominion University

How Firms Can Prepare For Increasing AI-<b>Cybersecurity</b> Risks

How Firms Can Prepare For Increasing AI-Cybersecurity Risks A key challenge for businesses is how to use artificial intelligence in a way that is not only commercially meaningful, but also defensible if something goes wrong from a security standpoint....To view the full article, register now. Already a subscriber? Click here to view full article

Discover Metasys 16.0: a smarter building automation platform delivering ...

- Johnson Controls - Building Insights - Metasys sets a new standard for smarter buildings Metasys 16.0: A legacy of innovation – engineered for what’s next Future-Ready Building Control Request a demoHighlights - Native server redundancy supports continuous operations without specialized hardware or third-party solutions - Built-in cybersecurity features help secure servers and field devices across the system - Up to 30% faster engineering and 40% faster upgrades through standardized workflows and pre-emptive system checks, plus up to 80% faster integration than most competitors with visual flow-based programming - Up to 30% energy savings through ASHRAE Guideline 36–aligned control strategies - An open approach to integration by supporting multiple devices, protocols and systems across portfolios For more than three decades, building automation has been transforming how facilities operate, adapt and perform. Few platforms have shaped that evolution as consistently or impactfully as Metasys. From early days bringing disparate building systems together to today’s data-rich cyber-resilient environments, Metasys has continuously reflected the principle that buildings are assets that should work for you, bring value to occupants and benefit the bottom line. Metasys 16.0 takes the next step. It builds on a long legacy of openness, scalability and reliability by responding directly to the demands shaping modern buildings. The latest release is not simply about new functionality; it leads the industry with maximum uptime, internationally recognized cyber resilience and even faster deployment acceleration. It also represents how building automation has become a strategic foundation for sustainability, operational resilience and long-term performance. “Customers need systems that are resilient by design and simple to deploy and scale. With Metasys 16.0, Johnson Controls brings that together in a single platform.” - M. Faisal Pandit, President, Building Management Systems, Johnson Controls Decades in building automation When Metasys was first introduced in 1990, building systems were largely

Old Dominion University Launches First Ph.D. in <b>Cybersecurity</b> in Virginia | Markets Insider

NORFOLK, VA, July 01, 2026 (GLOBE NEWSWIRE) -- For years, professionals seeking a doctorate in cybersecurity had few options beyond computer science or engineering. Old Dominion University is opening a new path. The University’s nationally recognized School of Cybersecurity has launched a new Ph.D. in cybersecurity designed to prepare the next generation of cyber leaders, researchers and educators as the world faces new and complex security challenges. The Ph.D. program will highlight the interdisciplinary nature of the rapidly evolving field of cybersecurity, with artificial intelligence and other emerging technologies. Students from a wide range of educational and professional backgrounds are encouraged to contribute diverse perspectives that advance cybersecurity research. “The coursework and research pathways are designed for people from different backgrounds,” said Daniel Takabi, Ph.D., professor, director of the School of Cybersecurity and Batten Endowed Chair of Cybersecurity. “Our Ph.D. program offers advanced technical specializations, alongside comprehensive pathways in strategic cybersecurity management, policy, legal and human factors in cybersecurity.” This unique program is among the first of its kind in the nation and the only Ph.D. in cybersecurity in Virginia. It also represents a new phase of growth for the school, which celebrated its 10th anniversary this year. Dr. Takabi touted the school’s expanding programs in cybersecurity and artificial intelligence, as well as research efforts to advance the University’s national reputation as a R1 research institution. The school is also growing its research faculty and partnering with federal and regional agencies to address real-world needs. Over the last decade, the School of Cybersecurity has grown from a handful of students to approximately 1,700 and has gained several national recognitions, including the National Security Agency (NSA) designations as Centers of Academic Excellence in Cyber Defense, Cyber Operations and Cyber Research. The NSA also granted the University official validation for its cyber

FSU expands <b>cybersecurity</b> training with high‑success certification training programs | BizFayetteville

In a tight job market, finding your niche and setting yourself apart from the competition is essential. As technology continues to evolve rapidly, businesses are in constant need of qualified technology professionals to assist them in advancing their own processes as well as defend their electronic systems from malware and cyberattacks. Cybersecurity was once a buzzword in tech, but now it is mainstream. The new latest buzzword and trending tech is artificial intelligence. As these tech breakthroughs continue to develop, students have to be able to combat cyber attacks, to combat AI threats and ultimately be ready to fill jobs that haven’t even been created yet. There are thousands of unfilled jobs throughout the country in IT and cybersecurity, and FSU is providing the necessary training to help individuals establish the knowledge and skills to fill them. The Center for Defense and Homeland Security (CDHS) was founded in 2010 with the mission to prepare the next generation of National Security, Cybersecurity, and Emergency Management workforce professionals through STEM education and training. CDHS’s Cybersecurity Academy provides hands-on accelerated training in Information Technology and Cybersecurity. This training is available to civilians and military-affiliated persons. Military can use VA Post/911 Education Benefits or Veterans Readiness for Employment (VRE) Benefits to help fund their participation in the course. CDHS offers two cybersecurity certification training programs within their academy: Certificate in Cyber Foundations This program is offered three times a year and does not have any prerequisites. Classes are held in the evenings Tuesday, Thursday, and Friday, from 6-10 p.m., and the entire course spans 33 classroom days. Students who complete this course and pass the final exam are certified in CompTIA A+, Network+ and Security+. The course has a 98% pass rate. Certificate in Cyber Security This program is offered two times a year

Critical flaw in Oracle E-Business Suite is under immediate threat | <b>Cybersecurity</b> Dive

Researchers say a critical vulnerability in Oracle E-Business Suite is facing exploitation attempts by a threat actor. The vulnerability, tracked as CVE-2026-46817, is a flaw in the Oracle Payments, and has a severity score of 9.8. If successfully exploited, an unauthenticated attacker with network access via HTTP would be able to compromise the product. Researchers at Defused observed a hacker exploiting the flaw on its Oracle E-Business honeypots, according to a post on X. The activity was observed on June 27 from a French IP address, but researchers said the threat actor was using a VPN. There has been no prior known exploitation activity or any release of a proof of concept, researchers said. About 950 exposed instances are considered potentially vulnerable, according to internet security researchers Shadowserver Foundation and Validin. Oracle previously addressed the vulnerability as part of a larger series of security patch updates in May.

Israeli Automotive <b>Cybersecurity</b> Firm PlaxidityX Shuts Down After $450M Exit

Israeli company PlaxidityX, an automotive cybersecurity firm formerly known as Argus, will shut down, with approximately 80 employees in Israel and abroad will to be laid off. Loading... Around 80 employees of PlaxidityX, formerly Argus, in Israel and abroad will be gradually laid off. Its parent company said the decision came following 'market growth being slower than expected' Israeli company PlaxidityX, an automotive cybersecurity firm formerly known as Argus, will shut down, with approximately 80 employees in Israel and abroad will to be laid off.

<b>Cybersecurity</b> beyond blocking: A call for collaboration

Cybersecurity beyond blocking: A call for collaboration Residential proxies and AI-detected zero-day vulnerabilities pose major 2026 cybersecurity threats, writes one IT leader. Traditional blocking fails; global collaboration is needed. This is no time for complacency on the cybersecurity front, as two major security threats are shaking the industry in 2026. They are posed by residential proxies, which have global footprints through every major home network provider, and the recent revelation of AI models capable of identifying zero-day vulnerabilities in every major software distribution far faster than the industry is ready or capable of addressing them. While they are not strictly new attack types, they are raising threat levels by orders of magnitude. Traditional approaches to operational security generally fall into some form of blocking or limiting. Those don't work here, by design or by scale. It's not possible to block or limit enough of the potential threat without significantly affecting usability of the internet as a whole. To address the threats, we must look at the basic attack problems they are amplifying, and bring more solutions to bear by working collaboratively. Residential proxies Residential proxies are specifically designed to blend in with and be covered by unpatterned daily network traffic from residential IP addresses, meaning they often go undetected for long periods. Unlike malware infections that rely on gaining access through security lapses, residential proxy software is often willingly brought into home networks through the lure of cheap VPN connections or on consumer devices like TVs. Once established across all major ISPs, these proxy networks can be used to carry out DDoS attacks of untraceable origin, or even more sophisticated attack campaigns such as Salt Typhoon. Even when the attacks are detected, blocking them is difficult, because they are likely to be scattered throughout an ISP's IP address space. Plus,

CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure

CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure WASHINGTON – Today the Cybersecurity and Infrastructure Security Agency (CISA) announced the formation of the Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure (ANCHOR-CI), a new advisory-body framework that will strengthen information sharing and broaden partnerships across government and industry to secure the nation’s critical infrastructure. ANCHOR-CI incorporates the best practices and lessons learned from the Critical Infrastructure Partnership Advisory Council (CIPAC) and will expand meaningful, impactful engagement to a wider range of public-private critical infrastructure stakeholders to address threats in real time. “The new and innovative ANCHOR-CI framework will be a game changer in how the public and private sectors collaborate and share information,” said Department of Homeland Security (DHS) Secretary Markwayne Mullin. “In a rapidly evolving threat environment, ANCHOR-CI will ensure we have the right people in the room working together to keep the critical infrastructure Americans rely on secure and resilient. This is just another example of the partnership needed to confront the threats of today and tomorrow.” DHS and CISA built the framework, and CISA will manage the governance of the councils established under ANCHOR-CI, which will facilitate open and candid discussion of sensitive information among participants, strengthening collaboration amongst government and industry. “As the national coordinator for critical infrastructure security and resilience, CISA is dedicated to actively engaging partners from the critical infrastructure community in every step of our work,” said Nick Andersen, CISA Acting Director. “This framework was developed to address the unique challenges our partners face, ensuring their voices are heard and their needs are met. By establishing ANCHOR-CI, CISA is not only fulfilling its core statutory mission but also strengthening our collective ability to safeguard the vital services Americans rely on every day.” The ANCHOR-CI framework allows

#explained #whatsapp #meta #<b>cybersecurity</b> #digitalindia | moneycontrol.com

🚨 #EXPLAINED | WhatsApp vs Government: GoI issues notice to Meta in username feature 🇮🇳📱 The Indian government has issued a notice to Meta over WhatsApp's upcoming username feature, raising concerns about traceability, user identification, and compliance with India's IT rules. What is the feature? Why is the government objecting? And what could this mean for your privacy and WhatsApp experience? 🎥 Chandra R. Srikanth breaks it down | #WhatsApp #Meta #CyberSecurity #DigitalIndia moneycontrol.com’s Post More from this author - Data centre to go public, ease of investing and Apple’s India price shock -- Editor’s Picks from Moneycontrol - #MCTech3 | WhatsApp username brouhaha explained; PhysicsWallah wants teachers to do more than just teach; and more - HDFC Bank’s leadership moves, Amazon turns up heat in Q-Comm, and cracks in the influencer economy -- Editor’s Picks from Moneycontrol Explore content categories - Career - Productivity - Finance - Soft Skills & Emotional Intelligence - Project Management - Education - Technology - Leadership - Ecommerce - User Experience - Recruitment & HR - Customer Experience - Real Estate - Marketing - Sales - Retail & Merchandising - Science - Supply Chain Management - Future Of Work - Consulting - Writing - Economics - Artificial Intelligence - Employee Experience - Workplace Trends - Fundraising - Networking - Corporate Social Responsibility - Negotiation - Communication - Engineering - Hospitality & Tourism - Business Strategy - Change Management - Organizational Culture - Design - Innovation - Event Planning - Training & Development

How federal <b>cybersecurity</b> teams can adapt to a post-DOGE environment

How federal cybersecurity teams can adapt to a post-DOGE environment COMMENTARY | The long-lasting impact of DOGE has been to accelerate a broader shift toward more disciplined, efficient and operationally resilient security strategies. The actions of DOGE may have faded from the news cycle, but for government chief information security officers the cuts that were made last year still feel fresh. Most are facing rising cyber threats with leaner teams and smaller budgets, including increased risks tied to the Iran conflict. There is a silver lining, however. Many security teams are using this moment to modernize and operate more efficiently. They’re not necessarily trying to do more with less. Instead, they’re prioritizing, automating and simplifying. What’s more, CISOs are concerned but not panicking. A new Forrester Consulting report found only 38% of public sector cybersecurity decision-makers are confident in their agency’s cybersecurity posture in the wake of headcount reductions. But those same decision-makers are proactively — and successfully — adapting their risk management approach to accommodate the current reality. Here are the operational shifts they’re adopting to meet the demands of a post-DOGE world. A renewed focus on high-priority vulnerabilities and critical infrastructure Agencies simply do not have the resources to try to protect everything equally. According to OPM workforce data published in March, the federal government had experienced a net workforce reduction of more than 278,000 employees since January 2025. As a result, security teams are under pressure to move faster while managing increasingly complex environments with fewer people. That reality is forcing CISOs to become far more disciplined about how risk is prioritized and managed. Instead of spreading limited resources across every possible vulnerability or compliance requirement, agencies are increasingly concentrating on the systems, networks and data sets most critical to mission continuity and public services. According to

Trump administration lifts restrictions on Anthropic's Claude models after <b>cybersecurity</b> alarm

3:02AM Obituaries PGe PG Store Archives Classifieds Classified Events Jobs Public Notices Pets MENU SUBSCRIBE LOGIN REGISTER LOG OUT MY PROFILE Home News Local Sports A&E Life Business Contact Us Public Notices NEWSLETTERS MENU ACCOUNT Subscribe Login Register Log out My Profile Subscriber Services Search SECTIONS HOME Homepage Top Stories Chats Weather Traffic Event Guide PG Store PGe Video Photos The Digs RSS Feeds NEWS News Home Crimes & Courts Politics Education Health & Wellness Transportation State Nation World Weather News Obituaries News Obituaries Science Environment Faith & Religion Social Services LOCAL Local Home City Region East North South West Washington Westmoreland Obituaries Classifieds Public Notices SPORTS Sports Home Steelers Penguins Pirates Sports Columns Pitt Penn State WVU PG Sports Network podcasts Riverhounds NFL NHL MLB NBA NCAA College Sports High School Sports A&E A&E Home Celebrities Movies TV & Radio Music Concert Listings Theatre & Dance Art & Architecture Books Events LIFE Life Home Food Dining Recipes Drinks Buying Here Homes & Gardens goodness Random Acts of Kindness Seen Outdoors Style & Fashion Travel Holidays BUSINESS Business Home Building PGH Your Money Business Health Powersource Workzone Tech News Business / Law Other Business Consumer Alerts Top Workplaces PGH Partners PGH Partners Home UPMC | Ask the Experts OTHER PGe NEWSLETTERS PG STORE ARCHIVES CLASSIFIEDS PUBLIC NOTICES OBITUARIES JOBS CLASSIFIEDS EVENTS PETS CONTACT US / FAQ CONTACT US ADVERTISING CULTURE & CAREERS DONATE TOP Email a Story Your e-mail: Friends e-mail: Submit

Your Perspective Matters: Join the NIS360 survey - ENISA

ENISA launches a survey for both national authorities and high criticality entities under NIS2 in preparation of the next edition of the NIS360 report. Following the publication of the NIS360 2026 report in May 2026, a new assessment cycle has now started with the launch of data collection and surveys for the NIS360 2027 edition. For this assessment, data is collected via an online platform using two structured questionnaires designed to assess cybersecurity maturity by combining insights from the private sector with perspectives from national authorities. The NIS360 surveys are carefully designed to ensure that data collected each year remains comparable and reflects overall trends. All responses are analysed in aggregate form, ensuring confidentiality. What’s new in the survey? The survey for both authorities and entities has been simplified, is quick to complete and features a user-friendly interface. It also introduces new features that allow registered entities to receive a benchmarking report, compare themselves with their peers, and better understand where they stand. Your responses are essential for ENISA’s assessment of sectoral cybersecurity maturity and criticality under NIS360.Share your feedback by taking part to the survey by 30 October 2026 via the following link: https://enisa.enablor.dk/auth/register/survey/eca2ce47cdd14826b095192fbdc15edc?lang=en The survey will be used to prepare the new NIS360 report, which will be published in 2027. For any further information regarding the survey, please contact NIS360@enisa.europa.eu. About the ENISA NIS360 report The ENISA NIS360 aims to work as an annual assessment tool supporting national authorities, policymakers and other stakeholders in assessing the cybersecurity maturity and criticality of high criticality sectors under the NIS2 Directive. Under the NIS360, a sector’s maturity is determined by: legislation and its effectiveness, companies and their preparedness, authorities and their institutional capacity, and sectoral ecosystem structures and their effectiveness. The assessment relies on a structured methodology developed and continuously refined

Cal Water says <b>cybersecurity</b> breach by Iranian-linked hackers was limited

CHICO — An investigation into a June 11 cyberattack claimed by an Iranian-linked hacker group found that hackers accessed one California Water Service customer’s online account using stolen credentials, but did not breach the utility’s internal systems or billing infrastructure, the company announced this week. Cal Water has continued to investigate claims made on June 11 by an Iranian-linked hacker group that it breached Cal Water’s systems throughout the state — including some in Chico. When the claims were made, Cal Water said it activated its cybersecurity response plan and worked “around the clock” to conduct an investigation, being supported by the state and federal government, as well as cybersecurity experts. Based on the investigation, Cal Water said the threat actor activity was limited to “unauthorized access to a small number of specific user accounts within two third-party service provider platforms.” Mandiant, a cybersecurity firm and subsidiary of Google Cloud, supported Cal Water in the investigation, and did not identify any evidence of activity in Cal Water’s internal technology of operational technology environments. However, the investigation did find that one customer’s account was accessed. “The investigation determined that the threat actor accessed one active customer’s online Cal Water account using stolen user credentials. The customer account did not provide access to the billing system, and no payment information was compromised,” Cal Water said. “The threat actor also accessed an external, third-party web site related to a GPS location correction tool; however, the website does not contain any confidential or sensitive information.” The hacker group, known as Handala, claimed responsibility for the breach June 11. In a screenshot of the groups claims, hackers from the group said the breach was a “warning” to the federal government after air strikes damaged water resources in Sirik, Iran two days prior to the breach.

China storage battery makers denied <b>cybersecurity</b> approval in Japan

TOKYO -- None of China's storage battery makers have received cybersecurity clearance from Japan's government despite an upcoming requirement that such equipment needs certification to connect to the power grid. Chinese manufacturer decries 'de facto exclusion' as certification requirement looms Even Chinese manufacturers with market share in Japan lack approved products. (Nikkei montage/Source photos by Nikkei) TOKYO -- None of China's storage battery makers have received cybersecurity clearance from Japan's government despite an upcoming requirement that such equipment needs certification to connect to the power grid.