No-frills tech news

<b>Cybersecurity</b> firm IDs unfixable security flaw that affects seven iPhone models — is yours on the list?

There’s no cure for this cybervirus. Cybersecurity experts at Paradigm Shift have identified an unfixable security flaw in older iPhone models and other Apple devices that can be exploited by hackers. “Vulnerabilities at this level can compromise the integrity of the entire device,” the European security firm’s wrote in a blog detailing the bug, which they flagged to Apple Product Security before publishing. Dubbed usbliter8, this vulnerability in the USB controller and firmware allows bad actors to override the device’s startup process and jailbreak it before the iOS loads, TechRadar reported. As a result, they can run unauthorized software or extract sensitive info from the device. This flaw affects iPhone models with A12 and A13 chips, specifically: the iPhone 11, iPhone 11 Pro iPhone 11 Pro Max, Second-generation, iPhone SE, iPhone XR, iPhone XS and iPhone XS Max, according to Apple Insider. Also at risk are S4 and S5 chips, which power some iPad and Apple Watch models. The impacted models entail the eighth and ninth generation iPad, third-generation iPad Air, the fifth-generation iPad Mini, the first and second generation 11-inch iPad Pro, the third and fourth generation 12.9-inch iPad Pro, the first-generation Apple Watch SE, and the Apple Watch Series 4 and 5 The goods news is that hackers can’t hack the device remotely — they need physical access to the gadget. But stolen or confiscated devices are still susceptible to this digital Trojan Horse. The downside is that this is a glitch in the hardware design rather than a software bug, meaning that Apple can’t remedy it via an update. Instead, “migrating to newer hardware remains the most effective mitigation,” Paradigm Shift explains. In other words, the best fix is to purchase a new phone.

SGF urges greater investment in <b>cybersecurity</b>, broadband infrastructure

SGF urges greater investment in cybersecurity, broadband infrastructure The Secretary to the Government of the Federation (SGF), Senator George Akume, has urged the Galaxy Backbone (GBB) to increase investment in cybersecurity and broadband infrastructure. Mr Akume, represented by Dr Ibrahim Kana, Permanent Secretary, General Services Office, made the remarks at a gala and award ceremony marking the 20th anniversary of Galaxy Backbone on Friday in Abuja. He described the organisation as a critical national asset that had strengthened governance, enhanced public service delivery and supported economic growth over the past two decades. He said that GBB had evolved from a bold government initiative into Nigeria’s foremost provider of secure government connectivity and digital infrastructure. According to him, the organisation was established to provide a unified, secure ICT infrastructure for government institutions and facilitate efficient service delivery through technology. He stated, “Today, Galaxy Backbone stands proudly as one of the nation’s foremost digital institutions and the trusted provider of secure government connectivity. The story of Galaxy Backbone is, in many respects, a reflection of Nigeria’s digital transformation journey. “From its modest beginnings to its current position it has consistently demonstrated excellence, innovation and strategic foresight.” The SGF said GBB played an indispensable role in connecting government institutions across the country, strengthening cybersecurity frameworks, facilitating digital governance and enabling seamless collaboration among ministries, departments and agencies. He said the organisation’s extensive fibre-optic network, certified data centres, cloud services and secure digital platforms were the backbone of modern governance in Nigeria. He said that digital transformation was a necessity rather than an option in today’s rapidly evolving global environment. “Nations that embrace technology and innovation are better positioned to achieve sustainable economic growth, improve governance outcomes and enhance the quality of life of their citizens,” he said. The SGF attributed the organisation’s achievements

ETSU named a Center of Academic Excellence in Cyber Defense

ETSU named a Center of Academic Excellence in Cyber Defense East Tennessee State University has been designated as a National Center for Academic Excellence in Cyber Defense (CAE-CD) by the National Security Agency. This distinction recognizes ETSU and its Department of Computing as the region’s premier cybersecurity training institute. With only 400 to 500 universities and community colleges nationwide earning this honor, the designation places ETSU among an elite group and opens new opportunities in education, research and workforce development. Community As a CAE‑CD institution, ETSU is also committed to advancing cybersecurity awareness and literacy throughout the region. In support of this mission, the Department of Computing recently hosted a child online safety event that brought together local resources to help community members better understand available cybersecurity support and education. Education Excelling in cybersecurity and cyber defense requires staying at the forefront of emerging technologies, and ETSU students experience that firsthand in the classroom. “We’re incorporating cybersecurity, AI and other cutting-edge technologies into the classroom to give students a well-rounded understanding and the confidence to apply these skills in any career field,” said Dr. Michael Lehrfeld, associate professor in the Department of Computing and director of the Cybersecurity Innovation and Outreach Center. “Cybersecurity is part of every field, and our students are being equipped across disciplines to meet that reality.” Dr. Michael Lehrfeld, associate professor in the Department of Computing and director of the Cybersecurity Innovation and Outreach Center Workforce and Economic Development Through the CAE-CD designation, economic development and partnerships have been opened up for ETSU and the community. Companies in the public and private sectors have been interested in hiring computing students for fulltime or internship positions, and this distinction only reinforces the value of hiring ETSU students.

PUC Advances Proposed <b>Cybersecurity</b> Regulations For Pennsylvania Utilities

PUC Advances Proposed Cybersecurity Regulations For Pennsylvania Utilities Proposal Would Strengthen Cybersecurity Standards, Incident Reporting, and Utility Preparedness Across Regulated Industries HARRISBURG – The Pennsylvania Public Utility Commission (PUC) today voted 5-0 to approve a Notice of Proposed Rulemaking (NOPR) that would strengthen cybersecurity requirements for regulated utilities, continuing the Commission’s efforts to help protect critical utility infrastructure and maintain safe, reliable service for Pennsylvania consumers. The proposed regulations would modernize and expand the Commission’s existing cybersecurity framework, establishing updated standards for utility cybersecurity programs, enhancing cybersecurity incident reporting requirements, and requiring annual certifications of compliance by jurisdictional utilities. “Cybersecurity is a fundamental part of both utility reliability and public safety,” said PUC Chairman Steve DeFrank. “As utilities increasingly rely on interconnected technologies to provide essential services, it is important that our regulatory framework continues to evolve alongside emerging threats. This proposal reflects a thoughtful, comprehensive approach that seeks to strengthen utility preparedness while pr…

Saudi women lead the charge at the intersection of AI and <b>cybersecurity</b>

DHAHRAN: In a quiet corner of King Fahd University of Petroleum and Minerals, a group of Ph.D. candidates is working to solve some of the most pressing technological challenges of the modern era. Among them are Asma Yamani and Linah Ali Abuhajar, two researchers operating at the intersection of artificial intelligence and cybersecurity — fields that are increasingly shaping the future of technology. KFUPM, a STEM-focused institution founded in 1963 as an all-male university, opened its doors to women in 2019. The students featured in this story are among the first generation of women to study and graduate from the university, and one of their earliest priorities was building a community of support and collaboration. “What we like to highlight is experts — who happen to be women,” Yamani told Arab News. That vision recently came to life through the university’s annual Women in Data Science conference, held as part of the global WiDS Worldwide initiative under the theme “AI-Security Nexus.” The event drew around 250 attendees from across the region. This year’s organizing team consisted of five students and was led by Yamani, who has been involved with the conference since women first enrolled at KFUPM. “Let’s start from the beginning in 2019, at the start of enrollment of female graduate students,” Yamani said. “The funny thing is, the speakers were already booked and they were going to come in like three days. And then the lockdown happened.” Like many events during the COVID-19 pandemic, the conference began as a virtual gathering, later evolving into a hybrid format before returning fully in person. “As AI transforms cybersecurity, it’s not just strengthening our defenses, it’s also reshaping the threat landscape in ways we’re only beginning to understand,” the conference press release reads. A poster competition attracted 85 submissions from KFUPM

IBM Nighthawk Processor Validated in Quantum Chromodynamics and <b>Cybersecurity</b> Benchmarks

Independent researchers from the IBM Quantum Network have published two separate technical studies validating real-world applications on the IBM Nighthawk quantum processor framework. Orchestrated through the RPI-IBM Future of Computing Research Collaboration, the peer-reviewed papers demonstrate scalable, hardware-native executions across particle physics simulations and graph-based cybersecurity optimization workloads. Both milestones were achieved through decentralized academic collaboration across the network, establishing reproducible software pipelines on utility-scale superconducting quantum hardware without direct operational intervention from IBM engineering. The first study, a collaboration spanning Rensselaer Polytechnic Institute, Stony Brook University, the University of Washington, and Brookhaven National Laboratory, executed a quantum simulation tracking nucleon–antinucleon interactions. The research team mapped a solvable, two-dimensional version of particle physics gauge theory into an interacting spin-chain model where nucleons and antinucleons correspond to specialized localized excitations. To run this non-perturbative simulation on the IBM Nighthawk processor, the team prepared a variational ground state and implemented non-unitary string operations using an adjacent set of physical ancilla qubits. By constructing a targeted energy estimator built on a difference of differences, the system leveraged structured error cancellation to successfully isolate the attractive interaction potential between the simulated particles despite ambient hardware noise. In a parallel engineering study, researchers from Rensselaer Polytechnic Institute and Marist University evaluated the hardware viability of using variational algorithms to defend against digital network intrusions. The workflow establishes an automated pipeline that ingests raw network logs from an active honeypot trap system and structures them into a graph optimization problem. By creating a temporal bipartite graph, communication events are mapped directly to qubits, transforming the network isolation policy into a weighted optimization challenge. Maximizing the cut boundaries of this graph model allows the system to establish an optimized traffic mitigation policy that quarantines malicious denial-of-service attack streams while protecting legitimate user communication channels. The cybersecurity study

Accenture spends USD 4.18 billion on <b>cybersecurity</b> business

Accenture spends USD 4.18 billion on cybersecurity business NEW YORK - Accenture announced the acquisition of three cybersecurity companies worth a total of USD 4.18 billion to strengthen its critical infrastructure protection business amid rising cyber threats and advances in artificial intelligence (AI). Quoted from Reuters, Accenture will acquire a majority stake in Dragos and purchase runZero and NetRise to strengthen its cybersecurity business. The acquisitions will strengthen Accenture’s cybersecurity business, particularly in protecting critical infrastructure such as power grids, energy pipelines, factories, and data centres. Accenture expects the acquisition process to be completed in August or September 2026 after obtaining regulatory approval. The three acquired companies have combined annual recurring revenue (ARR) of around USD 208 million. The move also strengthens Accenture’s cybersecurity business, which is currently valued at around USD 10 billion. Accenture shares fell more than 11% in pre-market trading after the company lowered its annual revenue growth forecast. Accenture lowered its annual revenue growth forecast to 3%-4%, compared with the previous estimate of 3%-5%. The company said economic uncertainty has prompted some businesses to reduce spending on non-essential information technology consulting projects. For the fourth quarter of 2026, Accenture expects revenue to be between USD 17.75 billion and USD 18.4 billion. The figure is below the average analyst estimate of USD 18.47 billion, based on data compiled by LSEG. (ARF/ZH)

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

The Gentlemen ransomware-as-a-service (RaaS) operation is actively developing and maintaining a suite of endpoint detection and response (EDR) killers that it hands out to affiliates for impairing system defenses before deploying the encryptor. This mature portfolio of EDR-terminating tools is centered around a framework that's known as GentleKiller. "They also incorporate third-party or leaked tools such as HexKiller, ThrottleBlood, and HavocKiller," ESET security researcher Jakub Souček said in a report shared with The Hacker News. "These tools are standardized through a shared defense-evasion layer, impersonating predominantly security vendors using fake version information, and copied legitimate certificates and icons." The Slovakian cybersecurity company also called out the ransomware crew for its ability to "unusually quickly operationalize" newly disclosed proof-of-concept (PoC) exploits related to an attack technique called the bring your own vulnerable driver (BYOVD) technique, in many cases within days of their public release. Since its emergence in March 2025, The Gentlemen has swiftly risen up the ranks and made a name for itself as one of the most active ransomware groups. Per data from Ransomware.live, the group has claimed 504 victims to date, with most of them located in Southeast Asia, South America, and Western Europe. Recent reports from cybersecurity journalist Brian Krebs and PRODAFT have revealed that a 36-year-old Russian national named Alexander Andreevich Yapaev (aka hastalamuerte) has been leading the operation, after acting as an affiliate for other ransomware schemes, including Qilin. ESET has described The Gentlemen as one of the most technically agile RaaS groups, using a set of techniques to ensure that the compiled EDR killer samples sidestep detection. This includes binary protection using Enigma or Themida and using file names that resemble well-known cybersecurity vendors, right down to their version information, digital signatures, and icons. The most prevalent of them is GentleKiller, which comes in

Naples Chamber to focus on <b>cybersecurity</b> threats | GB Daily | gulfshorebusiness.com

Greater Naples Chamber will host its next Wake Up Naples program on July 15, focusing on cybersecurity risks and strategies for protecting businesses in an increasingly digital environment. The event, titled Protecting Your Business in a Digital Age, begins at 7:30 a.m. at the Hilton Naples, 5111 Tamiami Trail N. Panelists will discuss preventing cyberattacks through artificial intelligence-driven security tools, protecting financial assets from fraud and responding to cyber incidents. Chamber officials say the program is designed to help business owners understand emerging threats and strengthen their organizations' defenses. Tickets are $55 for chamber members and $65 for nonmembers. To register, click here. Naples Chamber to focus on cybersecurity threats - By Adam Regan - 0 (0) comments Welcome to the discussion. Log In Keep it Clean. Please avoid obscene, vulgar, lewd, racist or sexually-oriented language. PLEASE TURN OFF YOUR CAPS LOCK. Don't Threaten. Threats of harming another person will not be tolerated. Be Truthful. Don't knowingly lie about anyone or anything. Be Nice. No racism, sexism or any sort of -ism that is degrading to another person. Be Proactive. Use the 'Report' link on each comment to let us know of abusive posts. Share with Us. We'd love to hear eyewitness accounts, the history behind an article.

DHS continues to make workforce decisions for FEMA, lawsuit contends

Getty Images/kellyvandellen National Park Service employees vote to unionize Federal Newscast Read more AP Photo/Mark Schiefelbein The ‘new’ Schedule F will NOT, necessarily, politicize the civil service Commentary Read more

New <b>cybersecurity</b> measures could mean more research funding for UWM

In an era when federal funding for research is scarce, UW-Milwaukee has taken steps toward a data security certification that will make its researchers eligible for a wider range of federal projects. The Office of Research hopes it also offers area companies new ways to collaborate with UWM. Cybersecurity Maturity Model Certification (CMMC) is a set of federal data security protocols required for universities and companies involved in defense-related projects. UWM achieved the Level 1 certification in January and is working to reach Level 2 certification by November, said Ali Abedi, vice chancellor for research. By opening a potential source of research funding, CMMC could aid the university’s efforts to retain its status as a “highest research activity” institution, often called R1. To achieve Level 1 certification, UWM had to confirm that it uses cybersecurity practices that keep even non-classified research information secure. These measures include university policies and basic tools such as door locks, cameras in some research-related spaces and access control lists that give only certain people access to labs. Level 2 certification is more rigorous and expensive to achieve. It involves building secure lab spaces and creating a secure data enclave, an isolated portion of the university’s computer network. Simply accessing calls for proposals for these federal projects requires a secure channel, Abedi said. He intends to apply for grants to fund the Level 2 upgrades. No other universities in Wisconsin currently have Level 2 certification, although UW-Madison and UWM are both working toward it. “We are trying to work together as much as possible,” Abedi said, to find cost savings. For example, the two universities could share the consultants needed to achieve the certification. Bringing more defense-industry jobs to Wisconsin UWM and WisPolitics recently co-hosted a panel discussion that considered ways universities and industry can cooperate

Unpatchable 'usbliter8' Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

Security researchers at Paradigm Shift have published a working exploit, dubbed usbliter8, that achieves arbitrary code execution inside the SecureROM of Apple's A12 and A13 chips. That code is burned into the silicon at manufacture. No software update can reach it. Affected devices will carry this flaw for as long as they stay in use. This is not a remote attack. It requires physical possession of the device, which must be in DFU mode and connected via USB to a dedicated RP2350-based microcontroller board. With that setup, the exploit finishes in under two seconds, before Apple's signed boot chain loads. The full technical write-up and a working proof of concept went public on June 18, 2026, following coordinated disclosure with Apple Product Security. Affected Devices The public PoC supports A12, A13, S4, and S5 SoCs. A12X and A12Z support is described as theoretically possible but not yet implemented. Device families in that range include the iPhone XS, XS Max, and XR; the iPhone 11, 11 Pro, 11 Pro Max; the iPhone SE (2nd generation); the iPad Air 3rd gen, iPad mini 5th gen, and iPad 8th gen; Apple Watch Series 4 and 5; the first-generation Apple Watch SE; the HomePod mini; and other Apple products built on those chips. A11 is not affected. A14 and later appear to be out of reach for this exploit path. The Bug The root issue is a hardware flaw in the Synopsys DWC2 USB controller. The controller stores incoming USB Setup packets via DMA, buffers up to three, then resets its write pointer on the fourth by decrementing it by a fixed 24 bytes. It also accepts smaller-than-standard packets, incrementing the pointer only by the actual bytes written. That mismatch accumulates into a repeatable buffer underflow, stepping the write pointer backwards through memory 12

SimpleHelp patched CVE-2026-48558, a critical authentication bypass vulnerability ...

Initiatives for As the national authority for Cybersecurity the CCB has developed several initiatives for specific publics which are presented here. - Last update: 18/06/2026 - Affected software: → SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions.- Type: authentication bypass vulnerability - CVE/CVSS → CVE-2026-48558 CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) SimpleHelp - https://simple-help.com/security/simplehelp-security-update-2026-05 SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OpenID Connect (OIDC) authentication flow. The vulnerability can be exploited in specific conditions depending on the server's settings and network context. SimpleHelp is a commercial remote support and remote access platform used by IT administrators, managed service providers (MSPs), help desks, and organisations to remotely connect to and manage. Successful exploitation of the vulnerability could allow unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, install programs; or view, change, or delete data. A video demonstrating the exploitation of the vulnerability was published, increasing the risk of exploitation. CVE-2026-48558 (CVSS 10) is a critical vulnerability in SimpleHelp that allows for OIDC authentication bypass. When OIDC authentication is configured, identity tokens submitted during login are accepted without verifying their cryptographic signature. In a vulnerable configuration, a remote, unauthenticated attacker can submit a forged token containing arbitrary identity claims to obtain a fully authenticated technician session. In some configurations, this may also allow bypass of multi-factor authentication, by accepting forged tokens without verifying their cryptographic signatures. Patch SimpleHelp addressed the vulnerability in a security advisory with updated versions. The Centre for Cybersecurity Belgium strongly recommends installing updates for vulnerable devices with the highest priority after thorough testing. Monitor/Detect The CCB recommends organizations upscale monitoring and detection capabilities to identify any related suspicious activity and ensure a swift response in case of an intrusion. In case

AI Monitoring: Key Concepts and Best Practices | CrowdStrike

AI tools are everywhere now. Employees use them to draft emails or summarize documents. Developers use them to write code. Engineering teams build AI-powered applications. Autonomous AI agents are starting to take real actions inside real business systems, such as booking meetings or querying databases. All of this is genuinely useful. However, it creates a security problem that most organizations haven't fully reckoned with yet. AI monitoring is the practice of observing, logging, and analyzing how AI systems behave to help security teams detect threats, enforce policy, and maintain visibility. The term covers two distinct things that are easy to conflate: - Using AI as a tool to help find threats faster - Monitoring your AI systems to make sure they're behaving as intended. Both matter and require attention, but they're different problems that call for different thinking. Introducing the new AI attack surface For most of the history of cybersecurity, the things defenders had to protect were relatively well understood: endpoints, networks, identities, cloud workloads, etc. The advent of AI added a new layer that didn't fit neatly into any of those categories. Vulnerabilities in AI agents and tools When a user types a prompt into a generative AI (GenAI) tool, or when an AI agent reads a document and decides what to do next, something is happening that most traditional security tools can't see. That interaction layer — between users, models, agents, and data — is where a new category of attacks is taking shape. Adversaries noticed the gap quickly. According to the CrowdStrike 2026 Global Threat Report, attacks by AI-enabled adversaries increased by 89% in 2025. This number reflects something important: AI isn't just helping a handful of sophisticated nation-state threat actors move faster; it's raising the floor for everyone. Less-skilled adversaries can now use AI to

MSSP sales best practices: How to close more <b>cybersecurity</b> business

The 2026 MSSP Alert Ranking Survey is now live. Submit your MSSP here and get recognized for being a top security provider in the world. Many business owners and C-suite executives still view cybersecurity through the lens of familiar tools: antivirus, firewalls, backups, and endpoint protection. Although those controls still matter, they don't address the questions that should keep business leaders up at night.Who is watching for threats after hours? How quickly would the company know if an attacker gained access? What would happen if a critical system went down? Could the business prove to an insurer, auditor, or customer that it had taken reasonable steps to reduce risk?That disconnect leads to a real sales problem for MSSPs (managed security services providers). The challenge for MSSPs is two-fold. First, helping prospective clients understand why basic defenses are no longer enough. And second, positioning the MSSP as a trusted advisor that can address business risk and improve operational resilience across the business. Ritchie said MSSPs need to show value through customer trust, transparency, and reduced risk.“To me, ROI in cybersecurity is measured by reduced risk, better visibility, stronger uptime, and more confidence in decision-making. Also, customers feeling like they finally understand and control their own IT environment,” he said.That framing matters for executives, who want to understand value, risk, and business impact before technical detail.“That is the kind of language that appeals to a business owner or C-suite executives,” Ritchie said. “Business owners do not always want every technical detail first; they want to understand the value, the risk, the impact, and whether they can trust the person sitting across from them.” The challenge for MSSPs is two-fold. First, helping prospective clients understand why basic defenses are no longer enough. And second, positioning the MSSP as a trusted advisor that can

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure

CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials. This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways. To defend against this malicious cyber activity, CISA urges impacted Fortinet customers with FortiGate appliances and associated secure sockets layer (SSL) VPN gateways to immediately: - Terminate sessions and reset credentials. Terminate all active SSL VPN and administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies. - Ensure secure credential storage. Confirm your organization’s use of the Password-Based Key Derivation Function 2 (PBKDF2) algorithm to store administrator credentials and remove weaker legacy hashes per Fortinet’s guidance (see, Fortinet's Technical Tip: Enforcing PBKDF2 as hash function for administrator accounts in FortiOS v7.2.11 and later). - Review logs. Review firewall, VPN, authentication, and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes. - Enable phishing-resistant multifactor authentication (MFA). Require phishing-resistant MFA on all remote access and administrative accounts and ensure it is enforced on all external gateways and administrative interfaces. - Reduce the attack surface and lock down management access. Ensure the administration of your firewall is inaccessible from the public internet; restrict Fortinet management interfaces to trusted internal networks; and remove or disable any unauthorized or unnecessary accounts. See the following resources to determine your organization’s potential impact and find additional guidance on the credentials compromised: - Tech Times: Fortinet FortiGate Credential Leak Hits 73,932 Firewalls: Half the Internet-Facing Fleet - SOCRadar: FortiBleed: The Compromise of 80,000+ Fortinet Firewalls - Hudson Rock: FortiBleed: 75,000 Fortinet Firewalls Compromised:

Mirva consolidates <b>cybersecurity</b> and backup operations with Acronis to deliver secure ...

Swedish MSP unifies backup, cybersecurity and service delivery through a single platform — enhancing efficiency, visibility and client trust. Mirva, an MSP with offices across Stockholm, Uppsala, Gävle and Sundsvall, specializes in delivering cloud, infrastructure, security and consulting services. Mirva needed a reliable, scalable solution to simplify operations and strengthen cybersecurity. The company turned to Acronis to unify backup and cybersecurity management on a single platform. Mirva partnered with Gridheart, a Sweden-based cloud distributor and Acronis partner, to support implementation and ongoing operations. Gridheart provided technical expertise, simplified billing and local-language support, ensuring smooth deployment and long-term success. KEY CHALLENGES - Fragmented systems required technicians to switch between multiple platforms, reducing operational efficiency. - Lack of integration between tools created risks and reduced visibility across client environments. KEY REQUIREMENTS - A scalable, unified platform to manage backup, cybersecurity and endpoints from a single interface. - Simplified operations with improved visibility across all client environments, including servers, endpoints and Microsoft 365 in a unified user interface. THE SOLUTION Mirva chose Acronis for its integrated backup and cybersecurity platform, gaining centralized visibility across servers, endpoints and Microsoft 365. The unified interface reduced tool switching, improving efficiency and streamlining workflows. THE IMPACT - Streamlined operations by consolidating multiple tools with one unified platform. - Improved technician efficiency and reduced administrative overhead. - Enhanced visibility and control across all client environments. - Strengthened cybersecurity posture with natively integrated cyber protection. “What made the difference was Acronis managed to gather all functionality into one system. We no longer had to jump between different platforms or adapt to different logics. Everything is connected, making it easier and safer.”

Kodak investigating <b>cybersecurity</b> breach of 'limited amount of company data'

Kodak investigating cybersecurity breach of ‘limited amount of company data’ ROCHESTER, N.Y. — Kodak is investigating after a third party illegally gained access to a “limited amount of company data”, the company confirmed on Thursday. Kodak is working with cybersecurity experts for its investigation, but it says it’s “confident” that the breach was limited and now contained. The film and photography company says there was no threat to its systems or operations. Kodak has also notified law enforcement, which is also investigating. The company says it will share more updates once it can. Other recent data breaches News10NBC has covered several recent data breaches recently, including Rochester Regional Health, the medical supply fulfillment services company Fieldtex Products in Henrietta, and the Rochester Philharmonic Orchestra. The Cybersecurity and Infrastructure Security Agency says the best way to protect data is by using strong passwords with two-factor authentication, being aware of email phishing scams, and maintaining offline, encrypted backups of sensitive data in case of a ransomware attack.