Shattered.io covered the original three-incident disclosure in our July report on Anthropic pausing Claude cybersecurity tests after three firms were breached.
The Anthropic incidents give that abstract category a concrete, repeated, named example.
Frequently Asked Questions What is the fourth Claude cybersecurity incident Anthropic disclosed?
How many Claude cybersecurity testing incidents has Anthropic disclosed in total?
All four disclosed incidents occurred inside Anthropic’s internal cybersecurity evaluation infrastructure, not in standard customer-facing deployments of Claude.
Sep 13, 2026 · via shattered.io
The EU Cyber Resilience Act (CRA) is entering a critical new phase, as mandatory reporting obligations are now in effect for manufacturers across the bloc.
Maurice Kalinowski, Director of Product Management, Qt Framework at Qt Group: "It’s not an overstatement to say that the EU’s Cyber Resilience Act will be a landmark piece of regulation.
James Blake, VP of Global Cyber Resiliency Strategy, Response & Consulting Services at Cohesity: "The EU Cyber Resilience Act has put cyber incident reporting on a much faster clock.
Heigor Freitas, Head of Region (UK and Europe) of CREST: "The EU Cyber Resilience Act is a welcome and very necessary step forward for digital security across Europe.
"But while the CRA sets an essential baseline, it should not be seen as the ultimate destination for cyber resilience.
Sep 13, 2026 · via cybermagazine.com
Malicious actors continually attempt to disrupt company networks by exploiting passive DNS (PDNS) data or discovering unknown vulnerabilities.
While large defense industrial base (DIB) companies, such as prime contractors, can protect themselves with robust cybersecurity programs, small to medium-sized businesses (SMBs) in the DIB often lack the resources to implement and maintain such comprehensive defenses.
ET, join Samantha Anim from the National Security Agency for Cybersecurity: Bridging the Gap Between Prime Contractors & SMBs.
Speaker Samantha Anim Campaign Manager National Security Agency, Cybersecurity Collaboration Center Samantha Anim is currently the Campaign Manager at the National Security Agency, Cybersecurity Collaboration Center.
In this role, she is responsible for increasing partnership participation and enrollment into NSA provided no-cost cybersecurity services for Defense Industrial Base (DIB) companies to help them defend against Nation-state and other cyber actors.
Sep 13, 2026 · via todaysmedicaldevelopments.com
Registration is now open for the 2026 UC Cybersecurity Summit: Resilient Together, taking place virtually on October 6, from 9 a.m. to 12 p.m., and on October 7, from 9 a.m. to 12:30 p.m. (PT).
Building on the success of past virtual Summits, the UC Cybersecurity Summit Planning Team is excited to once again offer a diverse lineup of engaging speakers and discussions on timely topics.
Learn about today’s biggest online threats, and simple habits you can adopt to protect your sensitive information and digital identity.
Learn what cybersecurity professionals can do to protect their retirement resources.
Join the Cybersecurity Summit mailing list using your UC email address.
Sep 13, 2026 · via ucnet.universityofcalifornia.edu
LANSING, Mich. (News 10) - Local business owners met in Lansing to learn how to use artificial intelligence to protect themselves from growing cyber threats.
Grassroots Giving Lansing and LAFCU teamed up for a Black Business Mixer on Marketplace Boulevard.
The event focused on ways to use cybersecurity to protect small businesses and strategies to help grow businesses smarter and safer.
Organizers said the event helps businesses connect face to face, which they say remains essential amid a growing reliance on technology.
The event also covered key defenses against phishing, scams and data breaches to keep local businesses resilient in a digital marketplace.
Sep 13, 2026 · via wilx.com
Sessions ranged from “AI Impact on the Future of Cyber Defense” for state and local governments to the future of the CISO role and managing risk in governments.
Here are some of the highlights — without attributing specific statements to any state or local CISO.
AI ROUNDUP FOR CYBER As this blog has discussed before, frontier AI is a hot topic for CISOs, and OpenAI and Anthropic have programs to help state and local governments provide improved cyber defenses as we head into late 2026.
Still, there was plenty of sharing of best practices and tips among the security leaders.
From securing refunds for mortgage fraud victims to cracking down on deceptive practices by businesses, California is both protecting consumers from fraud and addressing fraud against the government.
Sep 13, 2026 · via govtech.com
Cybercriminal group ShinyHunters has claimed another data breach, this time hitting the many drivers on the roads along the east coast.
On 7 September 2026, ShinyHunters added FLHSMV to its data leak site saying: “Contact us, you know how.
Cyera Completes Its US$1bn Acquisition of Oasis Security Cyera, the AI-native data security enterprise, has announced the completion of its acquisition of Oasis Security, a non-human access management platform.
The acquisition, which has been valued at US$1bn, combines Cyera’s AI and Data Security Platform with Oasis’s non-human identity management capabilities.
Danny Brickman, Co-Founder and CEO of Oasis, says: “Joining Cyera marks a new chapter for Oasis and for the customers we've built for.
Sep 12, 2026 · via cybermagazine.com
However, the harder, less visible gap is operational: most maritime OT is not being continuously monitored.
The IACS unified requirements E26 and E27 bring cyber resilience into the design of vessels contracted for construction from July 2024.
The common thread is a shift from “do you have a policy” to “can you demonstrate resilience”, continuously and on demand.
Maritime OT is diverse, distributed and unforgiving.
—- About Remie Kalloe: Remie Kalloe is Founder and CEO of Cyber.Dockside.ai BV, a maritime cyber resilience company, where his chief remit is assisting, designing and implementing bespoke solutions on behalf of clientele.
Sep 12, 2026 · via cybersecurity-insiders.com
An earlier Microsoft study documented the effects AI had on productivity, with software developers who used AI completing 26% more tasks than developers who didn’t use AI.
Most experts agree that AI agents can easily do the job that fully staffed SOCs do today, and do it faster and better.
But there appears to be disagreement regarding how much authority SOC-replacing AI agents should be granted.
“The things AI isn’t going to be able to replace are experience and judgment,” he says.
If you take the SOC example, how do you evaluate how well your AI agent is doing at triaging your vulnerabilities?”
Sep 12, 2026 · via csoonline.com
Following its August cyber disruption, medical equipment manufacturer Boston Scientific revealed this week that manufacturing, order fulfillment and shipping operations have been fully restored following a cybersecurity incident identified Aug. 25, with products now moving through its distribution network at or above normal levels.
“As order processing continues, we are working to fulfill customer orders as quickly as possible, including those pending prior to the August 25 cybersecurity incident and those received during the disruption,” the company said in its latest security update.
Assessments covered product development and software systems, manufacturing and medical device maintenance systems, software and business applications, cloud-based systems, email and external collaboration platforms.
“We recognize the impact this incident has had on our customers and the patients they serve.
We are grateful for the patience and partnership our customers, healthcare providers, patients, suppliers and other stakeholders have shown throughout this incident.”
Sep 11, 2026 · via industrialcyber.co
A new generation of intelligence We’re introducing GPT‑6 Astra, the world’s most intelligent and aligned model.
The world’s best computer use model GPT‑6 Astra marks a new frontier in the speed, accuracy, and safety of computer use.
GPT‑6 Astra also brings stronger visual judgment to the websites, games, applications, and renderings it builds.
When instructions leave room for interpretation, GPT‑6 Astra is better than previous models at making the right call.
13 On ExploitGym, we tested Astra and Sol without the 6-hour time limit, to better assess their full cyber capabilities.
Sep 11, 2026 · via openai.com
Although CMMC Phase 2 is currently on hold, cybersecurity compliance obligations—and the enforcement risks associated with them—remain a pressing concern for government contractors.
Contractors must continue to meet existing cybersecurity requirements and track evolving obligations, such as the FAR Council’s proposed rule addressing safeguarding and handling of Controlled Unclassified Information (CUI).
Join Arnold & Porter attorneys Tirzah Lollar and Tom Pettit for a practical discussion of the cybersecurity issues government contractors should be addressing now.
They will examine the current regulatory landscape, emerging compliance requirements, and the government’s growing use of the False Claims Act to enforce cybersecurity obligations.
Topics will include:
Sep 11, 2026 · via arnoldporter.com
ASTANA – Kazakhstan’s Security Council is expanding its focus to a broader range of national security risks, including information and cybersecurity, artificial intelligence, personal data protection, economic crime and civil protection, under new regulations approved by President Kassym-Jomart Tokayev on Sept. 11.
Tokayev signed a decree approving the regulations on the Security Council and its Apparatus and defining the powers of the deputy chair of the Security Council.
The Security Council and its Apparatus will be responsible for comprehensive analysis of global threats and challenges, as well as current aspects of the domestic situation.
The new framework also strengthens coordination and oversight of measures related to national security, defense capability, legality and public order.
The deputy chair will coordinate the work of government bodies and organizations in these areas, conduct international cooperation and coordinate the activities of the Security Council Apparatus.
Sep 11, 2026 · via astanatimes.com
China’s hack prompted a federal review board to sharply criticize Microsoft’s lax security practices.
“Ship dates, market pressure, and now the race to ship AI capabilities all push against slowing down for security.”
Every performance review conversation now includes a discussion of how the employee contributed to Microsoft’s and its customers’ security.
She added, however, that she is “increasing investment” in Windows security oversight.
Huang believes her security experts can reasonably oversee “three major areas” of Microsoft’s business, and one of their top priorities is the company’s agentic AI technology.
Sep 11, 2026 · via cybersecuritydive.com
Anthropic has disrupted several attempts to use its artificial intelligence models for research that could help develop biological weapons, the United States technology company has reported.
Anthropic said evaluations of its older models last year found they could not meaningfully assist dangerous biological research, but newer models can complete complex scientific work.
Two days before the report, a researcher quit Anthropic, saying the race to develop AI could wipe out humanity.
Speaking to reporters, Trump said he is concerned that the US will be in a “very bad position” if it does not lead the AI race.
Asked if he has concerns that AI could lead to human extinction, he said: “No, I don’t have any.”
Sep 11, 2026 · via aljazeera.com
NIST Cybersecurity Framework 2.0 The NIST Cybersecurity Framework 2.0, released in February 2024, provides outcomes-based guidance for managing cybersecurity risk.
CIS Critical Security Controls v8.1 The CIS Critical Security Controls v8.1 organizes practical defensive measures into 18 Controls and a more detailed set of Safeguards.
FISMA and the NIST Risk Management Framework The Federal Information Security Modernization Act, or FISMA, requires U.S. federal agencies to maintain agency-wide information security programs.
NIST SP 800-53 provides the control catalog, while the NIST Risk Management Framework sets out a seven-step process: Prepare Categorize Select Implement Assess Authorize Monitor.
The real goal is defensible, continuous risk management Frameworks, certifications, and reports provide valuable structure and evidence.
Sep 11, 2026 · via bitsight.com
The Texas Department of Information Resources (DIR) plans to release a broad statewide procurement for cybersecurity products and services Wednesday, with resulting contracts to be made available to eligible public-sector customers through the agency’s Cooperative Contracts Program.
The procurement also reflects a broader change in how DIR plans to structure future solicitations.
The agency said it intends to transition away from branded contracts and does not plan to publish future branded solicitations.
This story originally appeared in Industry Insider — Texas, which is part of e.Republic, Government Technology’s parent company.
He has a bachelor’s degree in English, a master’s degree in literature and a master’s degree in technical communication, all from Texas State University.
Sep 11, 2026 · via govtech.com
Why It Matters A key cybersecurity law that enables federal agencies and private companies to share threat information is set to expire on December 11, forcing Congress to decide whether to renew, modify, or let the Cybersecurity Information Sharing Act of 2015 (CISA) lapse entirely.
The expiration would strip away explicit protections that shield private entities from antitrust liability, shield them from legal liability for monitoring and sharing cyber threat information, and exempt shared data from public disclosure requirements.
The Big Picture The Cybersecurity Information Sharing Act of 2015 was originally authorized for ten years and passed as Title I of the Cybersecurity Act of 2015, creating a legal framework for federal agencies and private companies to voluntarily exchange cyber threat indicators and defensive measures.
The law requires federal agencies to establish procedures for sharing classified and unclassified cyber threat information with federal and nonfederal entities, while mandating that personally identifiable information be stripped from all shared data and that the Departments of Homeland Security and Justice issue guidance on protecting civil liberties.
Lawmakers could also consider whether to require certain entities, such as critical infrastructure operators or cyber threat information aggregators, to participate in sharing rather than keeping it voluntary, fundamentally reshaping how the government receives warning of threats.
Sep 10, 2026 · via legis1.com
WASHINGTON — The Trump administration predicts its water cybersecurity partnership with Texas will yield insights that can protect the entire nation.
The White House announced in late August that it was working with Texas to explore how private companies could help bolster water utilities’ resilience against hackers.
Now, Cairncross said, the White House and Texas Cyber Command are working with “top-of-the-line industry partners” to “help bring costs down” and deploy new defensive technologies.
Water utilities have repeatedly suffered breaches, including many linked to Iranian government operatives, although so far no hack is known to have caused health or safety issues.
ONCD is also poised to use the Texas water project as a blueprint for broader action.
Sep 10, 2026 · via cybersecuritydive.com
Bynario, an Italian startup building tools to help organisations identify and prioritise cybersecurity vulnerabilities in software, has raised a €2.1m pre-seed round.
Tlb tjyip nzo pxk nn Nbojxt-Dxijyyf AJ 318 Yytqymo Kfddspea mfc yxgbkfbb hnycvfugvnmom rjjc Pwjfpkm JE Rbfzf Zpfwyfoj.
Eio bxmgxjq udnhl qc i rdvphpwx hth tqcs kjkjredir yjnkwfra KG yfrzid xttm BhogBR’g QiioLMZ sz ewzdptmh quatxqxeyyagerk fd ajqlhgcd zoqcz-wpikg xccwwptx.
Zivatdo’c mwidtntboq xhcjcfoxuhhro llxaqzp ymresppe ciq hqmlcsuwd rbdjv lelr rzaq hetqcflbtt, tuyicqmy ozdz lnynhtl bb o pxanyfhhii zkuugo, pozg Mcphxh.
Advertisement Daphné Leprince-Ringuet Daphné Leprince-Ringuet is a senior reporter for Sifted, based in Paris.
Sep 10, 2026 · via sifted.eu