No-frills tech news

Loudoun Students Organize <b>Cybersecurity</b> Summit, Contest | Education | loudounnow.com

A group of Loudoun County Public School students organized two cyber-based events this semester that they hope will become annual gathering places for area students interested in computer science and cybersecurity. The two events, CyberSummit and IndyHax, were held at Independence High School in May and June. IndyHax, a combined hackathon and cybersecurity competition, asked students to complete challenges and build projects based on a prompt to compete for points and win prizes, according to Lalith, one of the student organizers. Tarushv, another student leader, said the event drew students from around Loudoun County as well as Chantilly High School and Thomas Jefferson High School for Science and Technology, both in Fairfax County. 2026 is the inaugural year for both events. Tarushv said the events were “pretty well-received” and that students, parents, and professionals in the industry have thanked them for organizing these types of events, which the students said are much more uncommon for high schoolers than college students and professionals. Lalith said the prizes in this event set it apart from many high school events. Technical expertise was not the most important thing for participants, he said. “We were looking for people who know how to innovate. We were looking for people who know how to change the world,” he said. Projects developed in response to the prompts included games, apps, and other programs. One project that organizers gave as an example was a program that pulled from Washington DC crime statistics to create a map of the city showing which areas were safe and which were more dangerous. The group of students who created that program were inspired to do so after being followed by suspicious individuals while in Washington, and Tarushv said that shows that they recognized a problem and wanted to fix it. Of course,

National Security Presidential Memorandum/NSPM-12

MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF THE INTERIOR THE SECRETARY OF AGRICULTURE THE SECRETARY OF COMMERCE THE SECRETARY OF LABOR THE SECRETARY OF HEALTH AND HUMAN SERVICES THE SECRETARY OF HOUSING AND URBAN DEVELOPMENT THE SECRETARY OF TRANSPORTATION THE SECRETARY OF ENERGY THE SECRETARY OF EDUCATION THE SECRETARY OF VETERANS AFFAIRS THE SECRETARY OF HOMELAND SECURITY THE WHITE HOUSE CHIEF OF STAFF THE DEPUTY CHIEF OF STAFF FOR POLICY AND HOMELAND SECURITY ADVISOR THE DIRECTOR OF THE OFFICE OF MANAGEMENT AND BUDGET THE DIRECTOR OF NATIONAL INTELLIGENCE THE ASSISTANT TO THE PRESIDENT FOR SCIENCE AND TECHNOLOGY THE ASSISTANT TO THE PRESIDENT FOR NATIONAL SECURITY AFFAIRS THE ASSISTANT TO THE PRESIDENT AND COUNSEL TO THE PRESIDENT THE CHAIRMAN OF THE JOINT CHIEFS OF STAFF THE DIRECTOR OF THE CENTRAL INTELLIGENCE AGENCY THE DIRECTOR OF THE NATIONAL SECURITY AGENCY THE ADMINISTRATOR OF GENERAL SERVICES THE NATIONAL CYBER DIRECTOR THE DIRECTOR OF THE CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY SUBJECT: National Policy for the Cybersecurity of National Security Systems As President, it is my priority to ensure that the United States can conduct key military and intelligence missions in contested cyber environments and that our personnel have access to the modern, secure technology they need to accomplish these missions. The Department of War (DOW), Intelligence Community (IC), and Federal Civilian Executive Branch (FCEB) Agencies own or operate this technology as National Security Systems (NSS). It shall be the policy of the United States Government that these systems be defended to the greatest extent practicable and that executive department and agency (agency) heads be accountable for this defense through government-wide oversight mechanisms. Therefore, by the authority vested in me by the Constitution and the laws of the

Marshall's <b>cybersecurity</b> students receive top scores in national competition

The team, guided by Dr. Paulus Wahjudi, professor of computer science, competed against students from colleges and universities across the country in challenges designed to test skills commonly required in today’s cybersecurity workforce. Each year, more than 10,000 students from high schools, colleges and universities participate in the NCL competition. Marshall’s performance also placed the university first among participating Sun Belt Conference schools and second among West Virginia schools competing in the event. Wahjudi says this team’s performance was superior, demonstrating their talent, dedication and teamwork. The National Cyber League presents challenges that mirror real-world cybersecurity tasks, and our students competed at a very high level against teams from across the country,” Wahjudi said. “Their performance reflects the strength of Marshall’s cybersecurity program and the hard work they have invested in developing practical security skills.” Student Thomas Neal earned the highest individual ranking among Marshall participants, placing 187th out of 7,006 competitors nationwide. Marshall team members who participated in the team challenge are Kendra Adkins, Brandon Anderson, Colton Gebhard, Bethany Ledford, William Matusic, Ethan Scott and Connor Stonestreet. “The success of our students in the National Cyber League reflects the hands-on, mission-focused education we provide,” said Alex Donathan, executive director of Marshall’s Institute for Cyber Security. “We are incredibly proud of these students and this team, and grateful for the leadership and mentorship of Dr. Wahjudi, whose support has helped guide our students’ success. Their achievements demonstrate the skills and readiness our graduates bring to the cybersecurity workforce.” More information about Marshall’s cybersecurity programs and initiatives is available at www.marshall.edu/cyber.

Coding camp in Augusta teaches kids <b>cybersecurity</b> skills

Coding camp in Augusta teaches kids cybersecurity skills AUGUSTA, Ga. (WRDW/WAGT) - A coding camp in Augusta is getting local kids excited about cybersecurity. Kids in grades 4 through 8 are learning about the industry and getting hands-on experience. A professor from Augusta University’s School of Computer and Cyber Sciences is one of their teachers. He says they learn computational thinking, ciphers, encryption and coding. They use those skills to code a robotic car platform that they can fully control. “A lot of times with cybersecurity or computer science, everything is just a keyboard and a screen. But with the micro bit and the cute bot, they can actually see what they’re programming. It goes into action,” said Michael Nowatkowski, School of Computer and Cyber Sciences professor. He says he hopes this camp engages these kids and shows them all the opportunities that lie ahead with these skills. Copyright 2026 WRDW/WAGT. All rights reserved.

VIDEO: Google sues <b>cybersecurity</b> group over scams – KIRO 7 News Seattle

Sections WATCH 65 ° WATCH News PinPoint Weather Stream Now KIRO 7 Investigates Sports Gets Real KIRO 7 Cares (Opens in new window) Steals & Deals News National Politics PinPoint Weather 7-Day Forecast Hour by Hour Ski Report School Closings Pet Walk Forecast Weather 24/7 Stream Stream Now Live Stream KIRO 24/7 News Weather 24/7 KIRO 7 Live Studio (Opens in new window) Recent Videos Raw Video Law & Crime Gusto TV KIRO 7 Investigates Sports Seattle Seahawks Seattle Mariners Seattle Kraken Seattle Sounders Seattle Storm College Sports High School Football On Home Ice Special Programming Seattle Pride Christmas in July Seattle Seafair Hit and Miss with Monique Ming Laven KIRO 7 Toy Drive Destination Discover Healthier Together Discover Northwest Woodland Park Zoo (Opens in new window) Your Voices KIRO 7 CARES Seattle Aquarium Washington Grown Seattle Waterfront Local Jobs Back to School Steals and Deals Gets Real Live Traffic Apps & Newsletters KIRO 7 Apps Newsletter Sign-ups (Opens in new window) About Us KIRO 7 News Team Submit a news tip KIRO 7 TV Schedule Advertise With Us Contact Us Closed Captioning KIRO 7 FCC EEO Report (Opens in new window) KIRO 7 Public File (Opens in new window) Visitor Agreement Privacy Policy Telemundo Seattle (Opens in new window) Telemundo Contactanos Jobs at KIRO 7 (Opens in new window) KIRO 7 Now Resize: Drag to Resize Video Live Streams KIRO 7 Now KIRO 24/7 News KIRO Weather 24/7 StreamAmerica™ Inside look at law enforcement & true crime Your one-stop shop for delicious dishes Latest Local Videos VIDEO: Puyallup Tribe of Indians recognized by Fifa in historic first VIDEO: World Cup nuclear search team VIDEO: Beating the backups around UW Commencement VIDEO: First look at Seattle Soccer House for the World Cup VIDEO: Voice of the Seattle Sounders, Pete Fewing,

Fact Sheet: President Donald J. Trump Defends America's Warfighters and Intelligence ...

Fact Sheet: President Donald J. Trump Defends America’s Warfighters and Intelligence Officers Against Cyber Threats PROTECTING CRITICAL MILITARY AND INTELLIGENCE MISSIONS: Today, President Donald J. Trump signed a National Security Presidential Memorandum to bolster the cybersecurity of America’s National Security Systems (NSS) and modernize NSS governance to meet the cyber challenges of 2026 and beyond. - NSS encompasses the US’s most sensitive computer systems – those that process classified information or support military and intelligence missions. - The Memorandum establishes a clear structure, authorities, roles, and responsibilities for the governance of NSS and accountability to NSS cybersecurity requirements for its owners and operators. - The Memorandum helps ensure that NSS owned or operated by civilian agencies receive a defense commensurate to those of the Department or War (DOW) and Intelligence Community (IC). - The Memorandum reestablishes the Committee on National Security Systems (CNSS) and modernizes it for the first time in over 35 years to establish baseline cybersecurity requirements for all NSS and enhance accountability and coordination across agencies to implement necessary cyber defenses across all NSS. - The CNSS will oversee the cybersecurity of NSS across the US Government and issue binding security directives to all NSS owners and operators. - The CNSS will provide collaboration, standardization, and efficient resource management by promoting coordination and information sharing across Federal agencies, public-private partnerships, and international liaison activities. - The CNSS will leverage the combined authorities and resources of the Federal Chief Information Officer, the Chief Information Officers of the DOW and IC, and the Director of the National Security Agency (NSA) to ensure that there are no gaps or weak links in NSS defenses. - The Memorandum empowers the Director of the National Security Agency as the National Manager for National Security Systems and the cryptologic authority of NSS. It

NexusTek Announces Construction Industry Solutions to Address Growing IT and ...

DENVER, June 12, 2026 /PRNewswire/ -- NexusTek, a leading provider of AI, infrastructure, and security solutions, today announced a focused set of construction industry solutions designed to help firms address rising IT complexity, cybersecurity exposure, and operational demands across job sites, offices, and remote teams. As construction firms navigate expanding cloud and BIM environments, mobile field operations, AI-enabled workflows, and rising cyber risk across distributed teams, NexusTek has aligned its services to support heavy and civil contractors, general contractors, construction managers, and specialty trades. "Construction firms need technology that supports the pace and pressure of their industry," said Hamilton Yu, Chief Executive Officer at NexusTek. "Our new offerings reflect where we are helping construction customers keep systems available, reduce disruption, strengthen security posture, and build a scalable technology foundation that supports long-term growth." NexusTek construction solutions span four core areas: - Cloud services deliver secure, reliable system access across field, office, and remote locations through private cloud, hybrid cloud, and virtual desktop solutions that improve availability and reduce infrastructure risk. - Cybersecurity and compliance services reduce ransomware, payment fraud, and third-party access risk through layered protection and documented controls aligned to CMMC and NIST requirements for federal and regulated work. - IT operations services replace reactive support with a stable, fully managed operating model. 24/7 service desk, onsite engineering, infrastructure monitoring, disaster recovery, co-managed IT, and vCIO guidance keep systems reliable and aligned to growth. - Data and AI services help firms turn operational data into measurable advantage. NexusTek assesses AI readiness, deploys AI in a governed environment, and builds analytics capabilities that improve reporting, forecasting, and decision-making. All construction engagements run on NexusOps, NexusTek's service delivery platform, with NexusIQ providing AI-driven triage, routing, and communications—delivering 97% triage accuracy, 90% faster root cause identification, and 78% faster status updates. Recent

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no direct internet access, so the group first staged through internet-facing systems to get there. The earliest traces go back to 2016. Instead of dropping new malware that a scanner might catch, the attacker changed the trusted login programs themselves. Nothing obvious appeared, and no exploit was needed, so the activity looked like normal administration. On many machines, the attacker replaced the main PAM login module with backdoored copies. Some let them in with a secret password; others quietly recorded real usernames and passwords as people logged in. Researchers found nine separate versions. The OpenSSH programs were altered the same way, logging credentials and every command typed, with a hidden switch to turn that logging off when needed. Reaching the isolated network at all took extra work. The attacker used other disguised tools and an internet-facing web server as a bridge, passing commands through it to open remote sessions deep inside the segment that had no direct internet access. Because the login system itself was compromised, normal containment did little. Password resets and killed sessions do not help when the thing that checks those credentials is working for the attacker. This is not new for the group. Each time defenders find one foothold, Velvet Ant moves to gear they watch less and sets up there. In a 2024 case, Sygnia found the same actor turning internet-exposed F5 BIG-IP appliances into internal command servers. Later

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD 22-01. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV catalog? Submit for potential addition: KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.

Join Us for an Exclusive Webinar: AI, <b>Cybersecurity</b>, and the Decisions You Cannot Defer

Join Us for an Exclusive Webinar: AI, Cybersecurity, and the Decisions You Cannot Defer Date: Jul 7, 2026 Time: 2:00 pm EDT Join us for a critical webinar presenting findings from The Oasis Group's April 2026 CTO Think Tank in Nashville - where CTOs and COOs from RIAs managing over $1 billion in AUM discussed AI deployment and cybersecurity threats facing wealth management firms. This webinar reveals what peer technology leaders are experiencing as they navigate AI vendor claims, deploy agentic automation, and respond to evolving threats that have breached four of the top ten RIAs. Key Topics Include: • Separating AI Reality from AI Washing: How to identify vendors with true AI capability versus rebranded tools • Agentic AI in Production: Real deployments automating compliance workflows - including one firm supporting nearly $10 billion AUM with three investment team members • Fourth-Party Risk and Recent Breaches: The Salesloft/Drift breach exposing 700+ Salesforce environments and vendor due diligence gaps most firms haven't closed • Reg SP's 72-Hour Notification: What the December 2025 deadline demands and why most firms cannot detect breaches within that window • Critical Security Controls: Why standard MFA is insufficient and the phishing-resistant authentication policies that separate prepared firms from exposed ones The firms that acted on these observations twelve months ago are building a lead that grows with every quarter you defer. Close the decision gap before the next incident makes the decision for you. CIMA®, CPWA®, CIMC®, RMA®, and AEP® CE Credits have been applied for and are pending approval. Get more information on CE Credits here. Sponsored by Orion Speakers

<b>Cybersecurity</b>, tech ETFs strongest performers in May

| Cybersecurity, tech ETFs strongest performers in MayBY RIDDHIMA TALWANI | FRIDAY, 12 JUN 2026 12:50PMETF performance in May was dominated by cybersecurity and broader technology themes, with the sector delivering exceptional returns across multiple strategies. While the Global X Cybersecurity ETF returned 36.5% for investors, Betashares Global Cybersecurity ETF provided a return of 31.75%. South Korea retained its place from the prior month, continuing to reflect strong investor interest in the region's technology-heavy market. iShares MSCI South Korea Capped Index ETF returned investors 31.6% for the month. Asian technology exposure also featured, reinforcing a broader theme of outperformance across innovation-driven, high-growth equities. ETF flows in May were broadly in line with April at $5.3 billion. Australian equities claimed the top spot for the month at $2.24 billion, narrowly ahead of international equities at $2.18 billion. Cash & fixed income fell sharply to $494 million from $1.1 billion in April. Short exposures swung back into negative territory, and commodities returned to positive flows after April's outflow. "Global equity markets extended their rally through May. S&P 500 companies reported 27% year-on-year earnings growth in Q1 2026, more than double consensus, driven by the hyperscaler capex cycle," Betashares investment strategist Tom Wickenden said. "Emerging markets were a standout, the MSCI EM index rose 9.7% as investors rotated into Asian chip manufacturers as a higher-beta, cheaper alternative to US mega-cap tech. Korea and Taiwan were the principal beneficiaries. Asian technology and broad emerging market ETFs capture this exposure on the ASX." The Australian ETF industry set a new record, reaching $364 billion in funds under management after a third consecutive month of net flows above $5 billion. Strong inflows, combined with positive global market performance, pushed the industry above $350 billion for the first time. "Domestically, the 12 May federal budget was the

Fortinet OT <b>Cybersecurity</b> Report: 53% of Industrial Orgs Now Under CISO

OT security governance has been moving toward the C-suite for four years, but the pace accelerated sharply. Fortinet’s 2026 State of Operational Technology and Cybersecurity Report finds 53% of industrial organizations now place OT cybersecurity under the Chief Information Security Officer (CISO) or Chief Security Officer (CSO), up from 16% in 2022. A global survey of over 700 OT professionals sits underneath that number, and the full picture is more complicated than the governance headline suggests. - The governance shift is real, but maturity self-assessments have corrected downward sharply: organizations at the highest maturity level (level 4) dropped from 49% to 17% in a single year. - Intrusions are more visible, not necessarily more frequent: 71% of respondents reported one to nine attacks, up from 47%, with Fortinet attributing much of the jump to improved detection rather than a true volume increase. - Cost reduction displaced risk reduction as the top cybersecurity performance metric in 2026, surfacing a governance tension the report does not fully resolve. - 89% of respondents expect new OT regulation within five years, up sharply from 66% in 2025, and four in five organizations intend to bring OT security under CISO oversight within the next 12 months. OT Cybersecurity Under CISO: Why the Level 4 Maturity Drop Changes the Story Richard Springer, senior director for marketing OT solutions at Fortinet, wrote in a blog post alongside the report. He noted that industrial organizations now rely on interconnected systems, remote access, cloud-based analytics, and unified IT and OT environments to maintain production. “While this advanced connectivity offers increased efficiency and resilience,” Springer wrote, “it has enlarged the attack surface for cybercriminals, ransomware groups, and nation-state actors.” The 53% CISO ownership figure is the headline, but the maturity-score recalibration is the operationally consequential finding. Level 4 respondents fell

Most <b>Cybersecurity</b> Teams Struggle to Find Time for Training on New Cyber Threats

Many cybersecurity teams are struggling to keep up with emerging technologies and the challenges around securing their organizations against them because they don’t have the time to undertake the necessary training, a new study has warned. The research, published by ISC2, asked nearly 1000 cybersecurity leaders from large enterprises around the world how their organization approach cybersecurity team training. Nearly three-quarters of respondents (73%) said their organization’s security training budget has increased over the past year, as businesses react to the emergence of new technologies and cybersecurity challenges that accompany them. One of the most encountered new challenges is the rise of AI: almost half of respondents (47%) said that AI is the most pressing skill their organization is addressing or planning to address through training. However, the study found that despite increased resources, organizations experience barriers around supplying training and upskilling to cybersecurity staff. Much of this is related to the time employees have available to engage with training. Nearly all security leaders surveyed (98%) said that their organization allows employees to engage with professional development and training during work hours. Despite this, just over half of respondents (53%) said that they face challenges which prevented them from engaging with training and professional development during the working day. The Struggle to Find Time for Cybersecurity Training Even if organizations support training, the practical realities of day-to-day work often make it difficult for employees to set aside dedicated time to participate in training during standard working hours. According to those surveyed, other challenges which create barriers to training include keeping training content current and relevant (45%), difficulty finding qualified trainers (39%), a lack of employee willingness to participate in training (37%) as well as a lack of support from leadership or other stakeholders (32%). While budgets for training have increased

The Gentlemen Ransomware Claims 478 Victims, Can Spread Like a Worm

A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis). According to a detailed report published by PRODAFT, the group, which it tracks as Phantom Mantis, is led by a Russian-speaking cybercriminal it calls LARVA-368, who goes by the online aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte. The Gentlemen is known to be active since March 2025, claiming a total of 478 victims to date, per data from Ransomware.Live. "In July 2025, Phantom Mantis transitioned into The Gentlemen, an independent partnership program no longer dependent on other RaaS groups," the Swiss cybersecurity company said. "Additionally, LARVA-368 relies heavily on artificial intelligence for the development and maintenance of ransomware and tools, as well as for assistance with post-exploitation procedures." As for LARVA-368, the threat actor is assessed to have been a member of the Embargo (aka Primeval Mantis) ransomware group before launching their own operation under the name ArmCorp. It was subsequently rebranded to The Gentlemen four months later. The individual's identity has since been outed by cybersecurity journalist Brian Krebs as a 36-year-old Alexander Andreevich Yapaev (Япаев Алексанр Андреевич) from the Russian city of Izhevsk. PRODAFT told The Hacker News that its findings match the same persona with "high confidence." As detailed by Dark Atlas in August 2025, the shift coincided with a payment dispute between LARVA-368 and Qilin, with the threat actor accusing the RaaS operation of carrying out an exit scam and defrauding them of $48,000. "Although Phantom Mantis was a very active affiliate group with over 20 targets registered on its affiliate panel in less than 30 days, the

New Attacks Trick OpenClaw AI Agent Into Running Code and Leaking Secrets

Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built a test agent on the platform, gave it a mailbox full of synthetic business data, and watched a single plain email talk it into forwarding mock AWS keys and a fake customer export to an outside address. The flaw Imperva found is patched in OpenClaw 2026.4.23, so update if you run it. The phishing weakness Varonis found is not something a patch fixes; it comes down to limiting what the agent can do on its own. Different doors into the same room: the agent trusts what reaches it, and its access becomes the attacker's. Hidden commands in a shared contact Imperva researcher Yohann Sillam looked at how OpenClaw hands messaging data to the model behind it. The problem is in the plumbing. When the agent passes a shared contact, vCard, or location to the LLM, it flattens the object into the prompt text inline, with no boundary marking it as untrusted. The content the agent fetches from the web gets wrapped in an untrusted-content marker. Message objects do not. Only some fields travel to the model, and that is what the attack abuses. A shared contact sends just the name field, serialized as <contact: name, number>. The angle brackets are legal in a name, so the model cannot tell where the real name ends and an injected instruction begins. The contact name is truncated where it shows on screen, both on WhatsApp and in the receiving app, so the victim does not see the payload

Doctoral Dissertation Defense in Finance: Naser Al-Ayyoub 6/26 | MyUML | UMass Lowell

06/11/2026 By Naser Al-Ayyoub The Department of Finance at the Manning School of Business invites you to attend a doctoral dissertation defense by Naser Al-Ayyoub on “Three Essays on Governance, Risk, and Product Market Dynamics.” Candidate Name: Naser Al-Ayyoub Degree: Doctoral Defense Date: Friday, June 26, 2026 Time: 10 a.m.-noon Location: Zoom. Those interested in attending should contact the student Naser_Alayyoub@student.uml.edu at least 24 hours prior to the defense to request access to the meeting. Thesis/Dissertation Title: Three Essays on Governance, Risk, and Product Market Dynamics Committee members: - Hieu Phan (Chair), Ph.D., Department of Finance, Manning School of Business, UMass Lowell - Steven Freund, Ph.D., Department of Finance, Manning School of Business, UMass Lowell - Chi Zhang, Ph.D., Department of Finance, Manning School of Business, UMass Lowell - Shakil Quayes, Ph.D., Department of Economics, UMass Lowell Abstract Firms navigate evolving legal, environmental, and technological risks. External risks and information flows shape managerial choices and dynamics. My dissertation investigates how litigation threats, climate exposure, and cybersecurity risk affect two core corporate domains—financing structure and competitive strategy. The first essay investigates the relationship between shareholder litigation risk and product market outcomes. Using the staggered implementation of universal demand (UD) laws by U.S. states as an exogenous shock to shareholder litigation risk, we find that weaker shareholder litigation rights resulting from these laws leads to an increase in sales growth for the impacted firms. The effect is stronger for firms with lower agency concerns, greater financial constraints, higher ex ante litigation risk, and those operating in more competitive product markets. Additional analyses indicate that strategic aggressiveness represents an important channel through which reduced shareholder litigation risk improves product market outcomes. The findings suggest that shareholder litigation threats can have unintended negative effects on firm competitiveness. The second essay examines how firm-level climate

UW and Wyoming SBDC Network to Host Data Alternative Web Browser Webinar June 25

UW and Wyoming SBDC Network to Host Data Alternative Web Browser Webinar June 25 Published June 11, 2026 Small-business owners, entrepreneurs and startups will have an opportunity to learn about alternative web browsers that may keep their businesses and their information online safer Thursday, June 25. Paul Johnson, Marree Reed and Ian Moon will lead a Wyoming Small Business Development Center (SBDC) Network webinar titled “Are You Using the Safest Web Browser? Alternatives to the Big Ones” from noon-12:30 p.m. To register, go here. The Wyoming SBDC Network offers business expertise to help Wyoming residents think about, launch, grow, reinvent or exit their business. The Wyoming SBDC Network is hosted by the University of Wyoming with state funds from the Wyoming Business Council and funded, in part, through a cooperative agreement with the U.S. Small Business Administration. During the webinar, attendees will learn the pros and cons of the most popular web browsers as well as platforms that may be right for them and their businesses. Johnson is manager of the Wyoming SBDC Network’s Cybersecurity Program. Reed is a cybersecurity program assistant in UW’s Cybersecurity Education and Research Center and a part-time employee with Institutional Marketing. Moon is a cybersecurity program assistant with the Wyoming SBDC Network’s Cybersecurity Program and a recent graduate of UW’s Computer Science Program. For more information, call Tyler Schanck, marketing, communications and database manager for the Wyoming SBDC Network, at (307) 343-0925 or email tschanck@uwyo.edu.

ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities

The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a zero-day the entire time. The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10. It needs no login and no user interaction, just network access over HTTP, to take over the server. If you run PeopleSoft with the Environment Management Hub reachable from outside, that is your exposure, and the immediate move is to lock those endpoints down. The vulnerability sits in the Updates Environment Management component, the piece behind the Environment Management Hub (PSEMHUB). Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too. It credits researchers from TrendAI Zero Day Initiative and TrendAI Research for the report. Mandiant CTO Charles Carmakal confirmed the bug is being exploited in the wild; Oracle has not said whether it has seen exploitation. Its advisory points to a patch availability document behind a support login, and whether a full fix is broadly available is unclear. For now, the guidance centers on mitigation. The operational detail became public because the attackers left their own gear exposed. Researcher @nahamike01 publicly flagged the open directories. Mandiant then triaged five sequential IP addresses running Python's SimpleHTTP server on port 8888. Those servers exposed the staging files: a shared .bash_history, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script. The agents called home to a command-and-control server at azurenetfiles.net, a domain picked to

IIT Kanpur launches Bachelor of <b>Cybersecurity</b> degree, no JEE Advanced score required

The Indian Institute of Technology Kanpur (IIT Kanpur) has announced the launch of a new undergraduate programme, Bachelor of Cybersecurity (B Cyber) from the 2026-27 academic session. The programme will begin in July 2026 and will be offered through the Wadhwani School of AI and Intelligent Systems. Admissions to the programme will not be conducted through JEE Advanced. Instead, candidates will be shortlisted based on their JEE Main scores and evidence of prior work in the field of cybersecurity. Shortlisted applicants will then be required to appear for an in-person assessment at the IIT Kanpur campus. The assessment process will include a hackathon. Also Read | IIT Kanpur hires CBSE hacker Nisarga Adhikary as an OSINT, threats engineer According to the institute, the four-year programme has been designed with a combination of academic training and practical experience. Students will spend the first two years on campus studying cybersecurity concepts through coursework and laboratory-based training. The curriculum is intended to provide theoretical foundations as well as hands-on exposure in controlled environments. The remaining two years will be devoted to internships with government security organisations. During this period, students will work on cybersecurity-related projects and real-world security challenges as part of their training. The institute said the programme has been introduced in view of the increasing importance of cybersecurity and the need for trained professionals in the sector. IIT Kanpur Director Manindra Agrawal stated that cybersecurity has become a critical area, particularly for the protection of digital infrastructure and national systems. Nitin Saxena, Dean of the Wadhwani School of AI and Intelligent Systems, said the programme aims to combine academic instruction with practical experience to prepare professionals for the cybersecurity sector. IIT Kanpur said a dedicated webpage for the programme is being developed and is expected to go live next week. Detailed