Some reasons why physical security measures are just as important as cybersecurity ones are that security threats extend beyond the digital world, physical access can lead to cybersecurity breaches, and more. In today's digital-first business world, most organizations focus entirely too much on cybersecurity measures and forget that physical security is just as important. Organizations invest heavily in firewalls, encryption, threat detection systems, and employee cybersecurity training to protect sensitive information and maintain business continuity. Of course, these security measures are imperative as cyberthreats continue to rise daily, but the importance of physical security shouldn't be discounted. In fact, many cybersecurity vulnerabilities begin with physical access to people, devices, facilities, or sensitive information. There shouldn't be a cybersecurity vs physical security debate at all, since they are complementary and should be focused on together rather than as separate strategies. Security Threats Extend Beyond the Digital World Cyberattacks often receive significant media attention, but organizations face many risks that originate in the physical environment. All the following can disrupt operations and create financial consequences: - Unauthorized access to offices - Theft of equipment - Vandalism - Workplace violence - The loss of sensitive documents Even highly secure digital systems may be compromised if an unauthorized individual gains physical access to company facilities or devices. Laptops, servers, mobile devices, access credentials, and printed records can all become targets if physical safeguards are insufficient. Protecting digital assets often begins with protecting the physical spaces where those assets exist. Physical Access Can Lead to Cybersecurity Breaches Many cybersecurity incidents involve some form of physical vulnerability. For example, a stolen laptop may contain sensitive information. An unsecured server room may provide opportunities for unauthorized access. Visitors entering restricted areas without proper oversight may gain access to confidential materials or connected systems. Physical security measures such
Jun 22, 2026 · via actionnewsjax.com
BRASILIA: Brazil's civil defense authority said on June 20 it had disabled its mobile phone emergency alert system after a possible cyberattack sent false alert messages to millions of people overnight. "The message sent was an Extreme Alert and contained the word 'misanthropy,' meaning hatred of humanity. It was probably a hacker attack," it said in a statement. Overnight between June 19 and June 20, Brazilians on social media reported being woken up by the loud sound of the alerts typically used for major emergencies. Civil Defense said the false messages were "remotely ordered by someone outside the national system of protection and civil defence," and delivered to "various regions of the country." The authority said it called in federal police to investigate, and would work to restore the system as quickly as possible, once its security had been bolstered. "Everything leads us to believe it was a hacker attack," Civil Defense Secretary Wolnei Wolff told a news conference, adding that "millions" of citizens received the false alerts. "There is no cause for concern among the public," said the government telecommunications agency, Anatel, in a statement. Brazil's Civil Defence uses mobile broadcast technology that sends audio and visual alerts that interrupt any activity on a mobile phone – even if it is on silent mode – to get the user's attention. "Who else was woken up here in Sao Paulo? A cell phone screaming, a maddening beep," actress Monica Iozzi said in an Instagram video. "I thought the world was falling apart." – AFP
Jun 22, 2026 · via thestar.com.my
Palo Alto Networks says AI is reshaping cybersecurity policy and threat response Palo Alto Networks executives said governments need to adapt cybersecurity policy as AI enters public systems, national security, and economic security. Governments are reviewing how cybersecurity policy should apply to artificial intelligence as the technology enters public-sector systems, national security, and economic security discussions, according to Palo Alto Networks executives. Speaking at the Palo Alto Networks Ignite on Tour Kuala Lumpur 2026 Media Roundtable, Nicole Quinn, Vice President for Policy and Government Relations at Palo Alto Networks, said traditional policymaking timelines are under pressure as AI adoption moves faster than legislative processes. Quinn said policy development usually follows a three-to-five-year cycle involving working groups, consultations, and structured review. AI does not fit comfortably into that model because governments are having to respond while the technology is still changing. She described the challenge as "building the plane and flying it at the same time," referring to the difficulty of forming policy while AI is already being deployed across organizations and public systems. According to Quinn, AI has moved beyond customer service and productivity use cases. It is now entering areas linked to national security, economic security, and government operations. That creates a policy challenge for governments still working with older technology environments. Security has often been added at the end of technology implementation, rather than built into systems from the start, she added. Securing AI inside organizations Secure AI by design should be part of how governments and organizations deploy AI systems, Quinn said. The process involves discovering where AI is being used, assessing what it is doing, governing its use, and protecting the systems around it. She also pointed to the rise of shadow AI as a concern for enterprises and public-sector organizations. Organizations cannot simply ban AI
Jun 21, 2026 · via crnasia.com
Ransomware affiliates have long relied on commodity EDR-killing tools, but Gentlemen ransomware takes a different approach. The gang fields a curated, modular suite of endpoint detection and response killers drawn from at least three rival criminal gangs, engineered so affiliates can swap drivers between attacks without rewriting code. BleepingComputer reported on analysis by ESET, the Slovakia-based cybersecurity firm. ESET traced the framework through the gang’s compromise of Romanian energy provider Oltenia and a SystemBC proxy malware botnet of over 1,570 hosts believed to be corporate victims. GentleKiller’s Eight Driver Variants Target 400 Processes Across 48 Vendors The centerpiece of Gentlemen ransomware’s defense-evasion arsenal is GentleKiller, a purpose-built EDR killer with at least eight variants. Each uses a different vulnerable driver to reach kernel-level privileges through the bring your own vulnerable driver (BYOVD) technique. All eight variants share the same code obfuscation, the same process-killing logic, and the same target list. That design is deliberate: the framework lets operators swap a patched or blocklisted driver for a newly disclosed vulnerable one without touching the core tool. The scope of what GentleKiller hunts is notable. ESET counted more than 400 processes associated with approximately 48 security vendors and products, including Microsoft, CrowdStrike, SentinelOne, Palo Alto Networks, Sophos, Trend Micro, ESET itself, Bitdefender, McAfee/Trellix, and Kaspersky. GentleKiller impersonates legitimate security products during execution, including Kaspersky, Valorant, Javelin, and WatchDog, and its binaries are protected by the commercial Enigma and Themida packing tools. The gang also uses stolen digital signatures from legitimate software, though ESET notes they are invalid. The BYOVD supply chain here is harder to defend against than a single-tool adversary because of driver interchangeability. A static driver blocklist catches one GentleKiller variant and leaves the other seven operational. Each new kernel-level vulnerability disclosure becomes a candidate for the next swap. The
Jun 21, 2026 · via cybersecurity-insiders.com
ON 6 MARCH, something quietly broke inside the Namibia Airports Company. The company described it as a limited disruption. The full picture only surfaced on 19 March, when the INC Ransomware Group announced the attack and the Namibia Cyber Security Incident Response Team confirmed it. Communications Regulatory Authority of Namibia (Cran) spokesperson Mufaro Nesongano said the attackers claimed to have exfiltrated approximately 500GB of data, including financial records, human resources information, customer data and contact details. It said this made the airports company the second Namibian victim of the INC Ransomware Group after an incident at the Otjiwarongo municipality. Weeks later the company confirmed that the data, including airport permit system files and engineering documents, had been dumped on the dark web. Flights kept landing throughout. Nothing showed on the runway, and that is exactly the problem. A breach that disrupts nothing you can see is easy to ignore. It was not the first time. In December 2024, Telecom Namibia lost 626GB of data to the Hunters International ransomware group, exposing more than 490 000 files and affecting customers at eight government ministries, five regional councils and 10 municipalities. In October 2025, the Namibia Students Finance Assistance Fund published the personal details of more than 7 000 students on its own website. Paratus was hit in early 2025. Telecoms, municipalities, student funding, airports. The targets vary. The weakness does not. Meanwhile, the country is accelerating its shift online. The sixth National Development Plan (NDP6)wants internet use up from 53% to 90% by 2030, with government services fully digital. The Bank of Namibia is preparing to launch its Instant Payment System (IPS), starting with social grants paid straight to pensioners. More than 40% of Nedbank Namibia’s clients already bank through digital channels. Namibians file taxes through Itas, register companies through the
Jun 21, 2026 · via namibian.com.na
EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients. How EY can help - EY.ai, a platform that unifies human capabilities and artificial intelligence to help you confidently adopt AI. Learn more. Read more Our interviewees also expressed strong skepticism about trusting AI too much, noting that companies are deploying it before it is ready. At the same time, the recent EY report How boards can lead in a world remade by AI (pdf) expressed the need for boards to adopt transformative rather than incremental thinking about AI. Next level competitive differentiation is expected to come from fundamentally redesigning processes and operating models around AI rather than simply automating existing workflows. Boards should encourage management to identify where AI can reshape value, reassess its technology risk appetite, and ensure that AI initiatives are tightly linked to strategic outcomes. These initiatives must be implemented responsibly, with governance, ethical oversight, and strong data management to avoid regulatory, operational and reputational risks. The report also underscores significant implications for talent and workforce strategy and indicates that talent models need to change. Boards should ensure that human capital strategies evolve accordingly, balancing short-term cost savings with long-term organizational capability and social expectations. Another critical theme is accountability. Despite advances in AI autonomy, responsibility for outcomes remains firmly human. Issues such as bias and inaccurate outputs can expose companies to organizational and reputational risks. Boards must ensure robust governance, clear accountability and transparent risk management practices, converting trust into a competitive differentiator. Finally, boards themselves must evolve. The EY Enhancing Board Oversight of Technology report (pdf)
Jun 21, 2026 · via ey.com
There’s a deep asymmetry between software users and software vendors, especially around security. Vendors decide what gets patched, how fast it ships, and what quietly slides to next quarter. Users get almost none of that visibility, and even less power to change the outcome. Security researchers help narrow that gap. We find a vulnerability, report it, and work with the vendor toward a fix. The vulnerability disclosure process isn’t always straightforward, but I’ve found most researchers and most vendors come to it in good faith. The challenge starts with vulnerability reports that don’t fit neatly in that process. Some bugs don’t fit If you report a remote code execution (RCE), SQL injection, or cross-site scripting (XSS) vulnerability, the path is well worn. There’s a code owner to route it to, the vendor’s security team can open a ticket that says “fix this,” and they can often pull logs to show how often the bug is getting exploited in the wild. The vulnerability is legible to the people who triage it. Then there’s the other bucket, the one I think of as the intersection of broken user expectations and platform behavior. These are the default settings, the documentation, and the UI choices that quietly make a product less secure or less private than a reasonable person would assume. There’s no clean exploit primitive and no single code owner, and often no log that proves anyone’s been burned yet. A bug bounty or VDP program isn’t built for that. The rules that keep out bad-faith noise also filter out good-faith findings that don’t look like a classic vuln, because it isn’t immediately obvious that the behavior can be exploited, or that it leaves anyone less safe. Fixing it usually isn’t a one-line patch either; it pulls in technical writing, UI and UX,
Jun 21, 2026 · via cybersecurity-insiders.com
After major health cybersecurity breaches, Fortinet ANZ boss urges cyber realism
Subscribe to BusinessDesk
Stay informed on business, government and financial developments across New Zealand.
- Deeply researched, twice-edited and fact-checked news
- Annual subscribers also receive a complimentary subscription to The Wall Street Journal
- Personalised email news alerts, plus gift up to 5 stories a month to non-subscribers
We are serious about journalism.
Already a Subscriber ? Sign in here.
All subscriptions auto renew but are easy to cancel.
Total Price Including Tax: {{ priceWithTax(selectedPlan) | currency }} {{ selectedPlan.type == 'user' && spark.chargesUsersPerSeat ? '/ '+ spark.seatName : '' }} {{ selectedPlan.type == 'user' && spark.chargesUsersPerTeam ? '/ '+ __('teams.team') : '' }} / {{ __(selectedPlan.interval) | capitalize }}
Not convinced yet?
Subscribe to our free 7am Headlines newsletter.
A quick summary of everything BusinessDesk has published in the previous 24 hours. No BusinessDesk
subscription needed.
Jun 21, 2026 · via businessdesk.co.nz
When I turn on my kitchen tap, I do not think about cholera; I assume the water is clean. This assumption is the product of an invisible system - reservoirs, filtration, chlorination, pressure monitoring, and a regulator that can shut the whole thing down if a sample fails. Safety is engineered upstream so that you get clean water without even thinking about it.r We have never had anything like that in cybersecurity. The Internet, our mobile networks, and the software and applications we develop and use - were all built on the opposite assumption. Security is something each organization is expected to bolt on afterward, at its own expense, with its own people, hoping its competitors and adversaries are no more diligent than it is. In this analogy, the water has always come out of the tap unfiltered, and we have been told to boil our own water. A development at the AI company Anthropic over the past two months suggests, for the first time, that the tap-water model might be within reach for cybersecurity. It also suggests why getting there is genuinely dangerous. Executives need to understand both halves of this sentence. What Anthropic did In April, Anthropic disclosed that it had built a frontier model, Claude Mythos Preview, capable of autonomously finding previously unknown software vulnerabilities (zero-days) and writing working exploits for them. This is not an incremental improvement on the vulnerability scanners your security team already uses. The model has reportedly found flaws in every major operating system and web browser, including bugs that were undiscovered for decades. Anthropic chose not to release Mythos to the public. Its reasoning was blunt. A tool that can find and exploit weaknesses in the world’s major software at scale is as useful to an attacker as to a defender, and
Jun 21, 2026 · via jpost.com
EDPS and EU data protection officers focus on AI, cybersecurity and compliance Data protection priorities for EU institutions include AI risk management, website compliance and data breaches. The European Data Protection Supervisor (EDPS) and data protection officers (DPOs) from EU institutions, bodies, offices and agencies met in Brussels on 18 June to discuss emerging data protection priorities and compliance challenges. The 58th meeting of the EDPS-DPO network was hosted by the Executive Agencies of the European Commission. The meeting brought together DPOs from across the EU administration at a time of significant regulatory and technological change. European Data Protection Supervisor Wojciech Wiewiórowski opened the meeting by emphasising the importance of safeguarding DPO independence in practice. He pointed to recent EDPS action, guidance, and procedures intended to safeguard the role of DPOs across EU institutions. Wiewiórowski also reviewed key developments from 2025, including the closure of the EDPS investigation into the European Commission’s use of Microsoft 365, a rise in complaints, and the growing impact of AI-generated submissions. He noted that regulatory simplification should reduce unnecessary administrative burdens without undermining fundamental rights protections. Thomas Zerdick, Head of the EDPS Supervision and Enforcement Unit, introduced a follow-up tracker designed to maintain continuity between EDPS-DPO meetings. The first tracker focused on EDPS supervisory guidance on the role of DPOs in EU institutions and the EDPS decision on prior consent to DPO dismissal. Zerdick also presented recent developments in supervision and enforcement, including complaint handling, compliance issues affecting several EU institutions, and practical guidance on international transfers and data protection impact assessments. The update also covered work linked to the Area of Freedom, Security and Justice, including audits, opinions, and preparations for upcoming systems. Luis Velasco, Head of the EDPS Technology and Privacy Unit, outlined initiatives to help EU institutions meet compliance requirements for
Jun 21, 2026 · via dig.watch
Acworth computer networks targeted in early June cyberattack
ACWORTH, Ga. - Officials in Acworth are investigating a cyberattack that compromised a selection of government computer networks on June 8.
Acworth computer systems compromised
What we know:
The city recently identified a cybersecurity incident that impacted specific computer networks on June 8.
Officials immediately brought in cybersecurity professionals and alerted law enforcement to help secure the infrastructure.
All municipal services remain fully operational because IT teams have completely restored the affected networks.
Digital investigation continues
What we don't know:
Authorities have not released the specific names of the computer networks that were compromised during the digital intrusion.
City officials cannot share further specifics because the digital forensics investigation remains active and ongoing.
The Source: The information in this story was gathered from an official statement released by the City of Acworth, which outlined the timeline of the network disruption and its current operational status.
Jun 21, 2026 · via fox5atlanta.com
Cybersecurity and digital trust professional, Emmanuel Omoke, has been honoured with the Outstanding Chapter Leader Award at the 2026 ISACA North America Conference held in Las Vegas, United States. Omoke received the recognition for his contributions to discussions and initiatives around cybersecurity, governance, risk, privacy and digital trust across Africa and beyond. At the same event, the ISACA Abuja Chapter also received the Innovative Chapter Program Award, alongside the ISACA Chicago Chapter, in recognition of programmes aimed at strengthening professional development and workforce readiness. Reacting to the award, Omoke attributed the achievement to the collective efforts of members of the ISACA Abuja Chapter and fellow professionals within the global network. “We are grateful for the opportunity to serve and contribute meaningfully to the tech industry in Nigeria, Africa and the world,” he said. The ISACA Awards recognise individuals and chapters that demonstrate innovation, measurable impact and leadership in advancing the global professional community. Beyond his latest recognition, Omoke has led several initiatives focused on youth empowerment, cybersecurity awareness, startup innovation, data privacy, internal audit transformation and digital trust across Africa. These include Internal Audit Awareness Month, Cybersecurity Awareness Campaigns, Data Privacy Week, Code4Privacy Hackathons, student innovation challenges, and the IGNITE Youth Programme, delivered in collaboration with Scratch & Script Kenya and several ISACA Africa Chapters. Through these programmes, more than 1,300 young people across the continent have gained digital skills, cybersecurity knowledge, mentorship and access to global professional networks. The initiatives have also brought together regulators, auditors, compliance professionals, technology leaders and policymakers, fostering cross-border collaboration and contributing to the development of a future-ready digital workforce. As convener of several professional awareness programmes, Omoke has facilitated knowledge sharing and collaboration among cybersecurity experts, auditors, academics, industry practitioners and government stakeholders across multiple countries. His contributions have previously earned him several
Jun 21, 2026 · via punchng.com
When people think about government cybersecurity requirements, they often picture large defense contractors, federal agencies, or major technology providers. What receives less attention is the growing impact these standards are having on smaller businesses that support government operations in one way or another. Local IT firms, engineering companies, software providers, manufacturers, consultants, and specialized service organizations are increasingly finding themselves subject to cybersecurity expectations that look very different from what they faced a decade ago. For many of these businesses, cybersecurity is no longer just an internal operational concern. It has become an important part of maintaining eligibility for contracts, preserving client relationships, and demonstrating that sensitive information can be handled responsibly. Security Expectations Extend Beyond Prime Contractors One of the biggest changes in recent years has been the recognition that cybersecurity risk does not stop at the primary contractor. Government agencies have become more focused on the broader network of vendors, subcontractors, and service providers that may have access to sensitive information or support critical operations. As a result, security expectations increasingly reach organizations that historically may not have viewed themselves as part of the cybersecurity conversation. This shift has created new challenges for local businesses. Companies that once competed primarily on expertise, pricing, or service quality are finding that security practices now play a larger role in procurement discussions and contract opportunities. In many cases, organizations are being asked to demonstrate cybersecurity maturity before work can even begin. Compliance Is Becoming Part of Business Development Historically, many smaller businesses viewed compliance as an administrative requirement that was addressed after contracts were secured. That mindset is becoming more difficult to maintain. Organizations pursuing government-related opportunities often discover that cybersecurity readiness affects sales conversations, vendor evaluations, and partnership opportunities much earlier than expected. Security requirements are increasingly influencing whether businesses
Jun 20, 2026 · via parsippanyfocus.com
The rapid adoption of digital technologies across government institutions, businesses and critical infrastructure has heightened the need for stronger information security measures to protect sensitive data from increasingly sophisticated cyber threats. Against this backdrop, the Kenya Bureau of Standards (KEBS) and the National Computer and Cybercrimes Coordination Committee (NC4) are set to co-host the 6th annual Information Security Management Systems (ISMS) conference from June 29 to July 3. The conference, to be held in Naivasha, will bring together government officials, ICT professionals, cybersecurity experts, regulators, private sector leaders and technology solution providers to discuss emerging threats and strategies for strengthening Kenya's cyber resilience. According to the conference concept note, the event has established itself as a premier platform for dialogue, knowledge sharing and collaboration among stakeholders in the information security ecosystem. "The conference provides a platform for stakeholders to exchange ideas, share experiences and explore innovative solutions to emerging cybersecurity challenges," it states. The organisers note that the conference comes at a time when cyber threats are becoming increasingly sophisticated and frequent, exposing both public and private institutions to significant risks. Recent threat intelligence reports cited in the concept note indicate that Kenya has recorded billions of cyber threat incidents in recent months, including ransomware attacks, artificial intelligence-driven phishing schemes, business email compromise, distributed denial-of-service attacks and the exploitation of vulnerable systems. The document identifies information security as a critical component of organisational governance and operational resilience, noting that institutions must protect data, maintain public trust and ensure business continuity in an increasingly digital environment. It further highlights internationally recognised standards such as ISO/IEC 27001 as key frameworks for identifying, assessing and managing information security risks. The five-day event will feature pre-conference workshops, technical training sessions, keynote addresses, panel discussions, live demonstrations and exhibitions by cybersecurity solution providers. Organisers expect
Jun 20, 2026 · via the-star.co.ke
Via 10Guards
Bro is the load balancer
Too accurate. Nothing kills productivity faster than having someone constantly hovering when you're trying to debug or triage something complex.
Bring just one big bowl. And then, start the project. Or do not put the bowls next to each other.
Dude never heard about pair programming.
Jira would be the automatic dog food dispenser
misconfigured firewall rules
I would let them out one at a time 😉
You know how it feels 😉
Neighbor's grass is always greener. 😂
That's called micromanagement
Jun 20, 2026 · via linkedin.com
ACWORTH, Ga. — The city of Acworth said a cybersecurity incident on June 8 affected some of the city’s computer systems.
Once the city learned of the issue, it said city officials contacted a cybersecurity professionals and law enforcement.
The city said in a news release distributed via a social media post that its systems are now fully operational.
"We are actively working with these partners to investigate this matter and to help ensure the continued security of our systems," the city said, without going into further detail the nature of the attack.
City officials said because the investigation is ongoing, they couldn’t go into further details. They said they’d disclose more about the incident as the investigation continues.
“All systems have been restored, and there is no impact to day-to-day operations,” the city said.
[DOWNLOAD: Free WSB-TV News app for alerts as news breaks]
[SIGN UP: WSB-TV Daily Headlines Newsletter]
©2026 Cox Media Group
Jun 20, 2026 · via wsbtv.com
Japan has released a draft revision of its Artificial Intelligence Basic Plan, indicating its policy of enhancing cooperation with foreign government agencies and AI developers to address risks such as the misuse of AI. The government reviewed the basic plan, which serves as a guideline for its AI policy, just about six months after its formulation last December, in light of rapid advancements in AI technology. The plan was drawn up based on the AI law enacted last May. Released on Friday, the draft revision highlights the growing risk of cyberattacks that exploit AI, with the rise of advanced AI models, such as Claude Mythos developed by U.S. startup Anthropic, in mind. The government aims to secure Cabinet approval for the revision at an early date after soliciting public comments. The draft also includes initiatives to strengthen countermeasures against misinformation and disinformation, including support for the development of technologies to detect AI-generated content. Additionally, the draft states that AI is advancing into an entity capable of driving decision-making and execution in organizations and society. The use of autonomous AI will be directly tied to national strengths, such as economic, defense and technological capabilities, the draft says. With your current subscription plan you can comment on stories. However, before writing your first comment, please create a display name in the Profile section of your subscriber account page.
Jun 20, 2026 · via japantimes.co.jp
IBM Tests Nighthawk Quantum Processor on Physics and Cybersecurity Tasks IBM tests Nighthawk processor on physics and cybersecurity. Researchers tested IBM’s Nighthawk quantum processor with two applied tasks: a simplified particle physics model and filtering malicious traffic. The experiments were highlighted in the Quantum Computing Report. In the first task, the team aimed to calculate a physical problem on the hardware, specifically the interaction between a nucleon and an antinucleon in a simplified quantum chromodynamics model (QCD2). They mapped the system onto a spin chain and ran it on Nighthawk. The resulting interaction potential showed the expected attraction and matched classical verification results, including exact diagonalization and ideal simulation. The authors emphasized extracting useful signals from noisy data through structural error compensation. The second task focused on cybersecurity, aiming to separate malicious DoS and DDoS traffic from normal traffic without disrupting legitimate connections. Researchers used logs from a honeypot system and transformed the task into a graph optimization problem solved using the Quantum Approximate Optimization Algorithm (QAOA). Experiments involved graphs with 16, 32, 66, and 110 events. The largest graph, with 110 nodes and 181 edges, was tested on three IBM backends from the IBM Quantum Network. According to the Quantum Computing Report, Nighthawk required the fewest two-qubit operations and had the lowest compilation overhead, while the Heron-based processor achieved the best target metric. The authors of both studies do not claim quantum advantage. They present the results as an applied benchmark to assess the suitability of such systems for tasks requiring both computational accuracy and noise resilience. In June, IBM researchers announced a new approach to finding quantum error correction codes using large language models.
Jun 20, 2026 · via forklog.com
CyberSentinel AI launches autonomous cybersecurity platform According to CybersecurityNews (June 20, 2026), CyberSentinel AI v3.0 is an open-source cybersecurity platform that integrates 33 real-world penetration-testing and threat-intel tools with a provider-agnostic AI layer. The platform supports Claude, GPT-4o, OpenRouter, and fully offline local inference via Ollama (default model: qwen2.5:7b), and executes scanners such as Nmap, SQLMap, Nikto, Nuclei, and OWASP ZAP inside a sandboxed Kali container. Per cybersecuritynews.com, the platform deploys via Docker Compose across seven containerized services including a Next.js frontend, FastAPI backend, Neo4j knowledge graph, ChromaDB RAG store grounded in MITRE, CIS, and NIST, and an ELK Stack SIEM. The platform can run up to five tools concurrently and includes input/output guardrails blocking prompt injection and SSRF attacks. System requirements: Docker Desktop and a minimum of 8GB RAM. The project is published on GitHub at 3sk1nt4n/cybersentinel-ai. What happened Per CybersecurityNews (June 20, 2026), CyberSentinel AI v3.0 is an open-source platform combining 33 penetration-testing and threat-intelligence tools with a provider-agnostic AI engine. Supported inference providers include Claude, GPT-4o, OpenRouter, and fully offline local inference via Ollama (using qwen2.5:7b as the default local model). The platform executes real scanners including Nmap, SQLMap, Nikto, Nuclei, and OWASP ZAP inside a sandboxed Kali container, and is available on GitHub at 3sk1nt4n/cybersentinel-ai. Technical details Per CybersecurityNews, the platform deploys via Docker Compose across seven containerized services. A Next.js frontend (port 3000) provides a streaming chat interface; a FastAPI backend (port 8000) handles AI routing, intent classification, and tool orchestration. Security scans execute inside an isolated Kali container. Supporting data infrastructure includes Neo4j for knowledge-graph mapping of attack surfaces and MITRE ATT&CK techniques, ChromaDB as a RAG engine grounded in MITRE, CIS, and NIST frameworks, and an ELK Stack (Elasticsearch + Kibana) pre-seeded with security events as a SIEM. The AI engine can classify
Jun 20, 2026 · via letsdatascience.com
Older iPhones are vulnerable to a flaw Apple likely can’t fix Researchers have discovered a vulnerability with older iPhones that Apple can't patch. The team at Paradigm Shift, an independent European cybersecurity firm, published its findings on the flaw, which it calls usbliter8, on its blog on Thursday. Researchers exploited flaws in the USB controller and the device's firmware to override the boot process (when the phone turns on) and gain control of the device before iOS loads, and even run unauthorized software. You May Also Like The issue exists within SecureROM, the code that runs when an iPhone turns on, which is embedded in certain chips. Apple can't fix these flaws, as the code can't be extracted from the chips. Paradigm Shift reported the vulnerability to Apple before publishing it. The impacted chips are A12 and A13. Here are the impacted iPhone models with A12 and A13 chips, as reported by AppleInsider: - iPhone 11 - iPhone 11 Pro - iPhone 11 Pro Max - Second-generation iPhone SE - iPhone XR - iPhone XS - iPhone XS Max S4 and S5 chips, which power some iPad and Apple Watch models, are also affected. Here are the impacted models, according to AppleInsider: - Eighth and ninth generation iPad - Third-generation iPad Air - Fifth-generation iPad Mini - First and second generation 11-inch iPad Pro - Third and fourth generation 12.9-inch iPad Pro - First-generation Apple Watch SE - Apple Watch Series 4 and 5 Paradigm Shift notes that technical support for the A12X and A12Z chips is possible but hasn't been implemented; this also affects the 2018 and 2019 iPad Pro models, AppleInsider reported. The exploit requires physical access to the iPhone. Paradigm Shift wrote that it opens up different paths that could allow attackers to compromise Apple's Secure Enclave
Jun 20, 2026 · via mashable.com