No-frills tech news

CISA Orders Federal Agencies To Patch Actively Exploited Critical Vulnerabilities Within ...

CISA Orders Federal Agencies To Patch Actively Exploited Critical Vulnerabilities Within Three Days Under New Cybersecurity Directive The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a sweeping new cybersecurity mandate requiring federal civilian agencies to remediate some of the most dangerous software vulnerabilities within as little as three days, marking one of the most aggressive vulnerability management policies ever imposed across the federal government. Vulnerability Mitigation Timeline (Source: CISA) The new directive, known as Binding Operational Directive (BOD) 26-04, establishes accelerated timelines for addressing high-risk security flaws and reflects growing concern within the U.S. government over the increasing speed at which threat actors exploit newly discovered vulnerabilities. The policy replaces previous federal vulnerability management directives and aims to strengthen the government's defenses against ransomware groups, nation-state hackers, and other cybercriminal organizations that increasingly target public-sector infrastructure. The announcement comes amid a broader cybersecurity landscape in which attackers often weaponize newly disclosed vulnerabilities within hours or days of public disclosure, significantly reducing the time available for defenders to deploy security updates. A Shift Toward Risk-Based Vulnerability Management According to CISA, the new framework supersedes and revokes earlier directives introduced in 2019 and 2021, replacing them with a more dynamic, risk-based approach that prioritizes remediation based on the likelihood and potential impact of exploitation. Rather than relying solely on traditional severity scores, the directive requires agencies to evaluate vulnerabilities using several operational risk factors. These include whether a vulnerable asset is exposed to the internet, whether the vulnerability has been actively exploited in real-world attacks, the extent to which exploitation can be automated, and the level of system control an attacker could gain if exploitation succeeds. Conventional vulnerability scoring systems such as CVSS often fail to accurately predict real-world exploitation risk. Numerous incidents in recent years have demonstrated that vulnerabilities

Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert

Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert A zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The warning comes a day after Oracle published an out-of-band security alert about the flaw, which is remotely exploitable without authentication, may result in remote code execution, and affects PeopleSoft PeopleTools versions 8.61 and 8.62 (and possibly earlier, unsupported ones as well). Oracle credited researchers with TrendAI Zero Day Initiative and TrendAI Research for reporting the vulnerability. The security alert links to a “patch availability document”, but it is unclear whether a patch is currently available, as the document is accessible only to customers with a support account. Help Net Security has reached out to Oracle for confirmation on whether CVE-2026-35273 is being actively exploited, but we’ve yet to receive a reply. ShinyHunters targeting PeopleSoft instances Oracle’s alert was published on the same day that Bleeping Computer reported ShinyHunters’ claims that they’ve been breaching Oracle PeopleSoft servers and have stolen data from 100+ organizations. According to the extortion group’s claims, the targeted organizations are mostly educational institutions, and their PeopleSoft instances – whether on-premises or in the cloud – were breached “using a ‘gadget chain’ of old and zero-day vulnerabilities.” Among the victims is apparently the University of Nottingham, which confirmed it has suffered a cybersecurity incident and that it has notified affected students and alumni directly. ShinyHunters claimed that breach and leaked tens of gigabytes of stolen data, including personal data and academic records of nearly half a million current and former students. A threat researcher seemingly confirmed ShinyHunters’ ongoing targeting of PeopleSoft instances, after discovering exposed directories containing tools used in these attacks. “At the /pay_or_leak endpoint, is stolen data from

Microsoft, OAS Expand <b>Cybersecurity</b> Alliance in Latin America

Microsoft, OAS Expand Cybersecurity Alliance in Latin America Microsoft and the Organization of American States (OEA) are expanding their regional collaboration to strengthen cybersecurity capabilities, improve institutional preparedness, and support the responsible adoption of emerging technologies across Latin America. Microsoft and the Organization of American States (OAS) announced an expanded strategic collaboration to strengthen digital resilience across Latin America. The initiative focuses on cybersecurity, government capacity building, and the responsible adoption of emerging technologies as cyber threats continue to affect economic stability and digital trust across the region. “Digital resilience is no longer only a technology issue; it is a strategic component of competitiveness and economic development,” says Steven Masada, Director of the Digital Crimes Unit, Microsoft. “Working alongside the OAS allows us to scale institutional capabilities and support governments in an increasingly sophisticated digital risk environment.” The expansion of the partnership comes as organizations across Latin America face a growing volume of cyber threats that are increasingly complex, transnational, and costly. As digital transformation initiatives continue across public and private sectors, cybersecurity has become a key factor in protecting economic activity, maintaining operational continuity, and preserving trust in digital services. Governments throughout the region are accelerating the digitization of public services, adopting cloud-based infrastructure, and exploring AI applications. While these technologies create opportunities for efficiency and growth, they also expand the attack surface available to cybercriminals and threat actors. Against this backdrop, public-private collaboration is emerging as a critical mechanism for addressing cybersecurity challenges that no single institution can manage independently. The initiative also reflects increasing recognition that cybersecurity extends beyond technical infrastructure. Digital resilience now plays a direct role in economic competitiveness, investment attraction, regulatory confidence, and the protection of critical services. Regional Cybersecurity Capacity Building Takes Center Stage As part of the expanded collaboration, Microsoft and the

Anthropic Recruits Fifth Third for Project Glasswing AI <b>Cybersecurity</b> Initiative | PYMNTS.com

The bank’s chief financial officer, Bryan Preston, said at the Morgan Stanley U.S. Financials Conference that Fifth Third was granted access to the initiative within the past several weeks, according to the report. “We think it was a reflection of just the role we play in the payments ecosystem in the country today, whether it’s the Direct Express business, some of the processing that we do for U.S. Customs as well as just the magnitude of payroll processing that we do for the country,” Preston said, per the report. Direct Express is the U.S. Treasury Department’s prepaid debit card program that helps Americans get monthly federal benefits. Fifth Third Bank was selected by the Treasury Department to expand the program, and the bank inked a five-year agreement to serve as the financial agent for the program in September, PYMNTS reported at the time. Anthropic introduced Project Glasswing in April when it announced the limited release of its first Mythos-class AI model, Claude Mythos Preview. The company said the initiative would offer select partners early access to the model so they could use the model’s cybersecurity capabilities to strengthen their systems before this class of models was more widely released. By May 22, Anthropic reported that Claude Mythos Preview had identified more than 10,000 cybersecurity vulnerabilities in “the most systemically important software in the world” so that they could be patched. Advertisement: Scroll to Continue On June 2, Anthropic said it was expanding Project Glasswing. The company said that the cybersecurity effort initially gave around 50 organizations access to Claude Mythos Preview and that it was being expanded to include 150 organizations. When Anthropic announced Tuesday (June 9) that it launched two Mythos-class models after developing safeguards to prevent them from being misused, the company said that one of them, Claude

Israeli tech sees bigger funding rounds, fewer deals amid AI and <b>cybersecurity</b> boom

Israeli startups raised approximately $8.6 billion in the first half of 2026, up about 45% from the roughly $6 billion raised during the same period last year, according to a report released by Poalim Tech and Dealigence. The increase came despite ongoing security challenges and economic uncertainty, including the recent conflict with Iran. At the same time, the number of funding rounds fell by about 35%, suggesting investors are concentrating larger sums of capital in a smaller number of companies. The report found that cybersecurity remained one of the strongest sectors in Israeli tech, with investment in cybersecurity companies more than doubling compared with the first half of 2025. Funding in the sector remained steady even during periods of heightened security tensions, reaching about $580 million in March. The trend toward greater investor selectivity was also reflected in the profile of companies securing funding. Serial entrepreneurs accounted for a growing share of fundraising activity, with the proportion of rounds raised by repeat founders rising from 34% in 2025 to 39% during the first six months of 2026. A similar pattern emerged in mergers and acquisitions. The number of M&A transactions involving Israeli technology companies declined by about 16% year over year, falling from 100 deals to 84. However, average deal values increased by roughly 10%, excluding major transactions involving Wiz and CyberArk. Total M&A volume reached approximately $10.7 billion during the first half of the year. The report also pointed to diverging trends in the technology labor market. While multinational technology companies continued to implement layoffs and cost-cutting measures amid economic uncertainty, artificial intelligence-driven efficiency efforts and a weaker U.S. dollar, employment at Israeli early- and mid-stage startups grew by about 2%. According to the report, younger companies have generally maintained leaner workforce structures, limiting the need for additional staff

Cyera raises $600 million at $12 billion valuation, up fourfold in 18 months | Ctech

Cyera raises $600 million at $12 billion valuation, up fourfold in 18 months The cybersecurity firm has raised $1 billion in six months, targeting the growing gap between AI adoption and enterprise control. Israeli cybersecurity company Cyera has raised $600 million at a $12 billion valuation, a fourfold increase over the past 18 months. Total funding now exceeds $2 billion, placing it among the most valuable privately held cybersecurity firms globally. The round was led by Evolution Equity Partners, with participation from Cyberstarts and Temasek, alongside existing investors including Accel, AT&T Ventures, Blackstone, Coatue and Spark Capital. Over the past year, Cyera has expanded its product suite, shipping more than 100 new capabilities across data security posture management (DSPM), privacy, identity, data loss prevention (DLP) and what it calls agentic security, tools designed to govern AI systems operating within enterprises. Cyera co-founder and CEO Yotam Segev said the company is focused on enabling AI adoption at scale while maintaining control over data and system access. “Trust is what makes this possible, knowing what your AI can see and do,” Segev said. “That’s the infrastructure layer the industry has been missing, and it’s what we’ve been building alongside our customers since day one.” Segev added that the funding will be used to accelerate development of the platform for enterprises operating in what he described as the “agentic era.” Cyera said its growth has accelerated alongside demand for AI security tools. The company reported that annual recurring revenue has tripled for three consecutive years. It has also expanded rapidly, reaching more than 1,500 employees across 18 countries over the past 18 months. During that period, Cyera completed five acquisitions, including Ryft and Genie, to expand its capabilities in data and AI security. The new round places Cyera among the most valuable Israeli

White House Executive Order Signals Federal Focus on Frontier AI <b>Cybersecurity</b>

The EO also follows a growing trend at the state level, where states such as California and New York have begun imposing frontier AI-specific governance, transparency and incident-reporting obligations on frontier developers, including requirements aimed at assessing and mitigating risks of catastrophic or âcritical harm.â Key provisions of the EO include: - Federal cyber defense priorities. Within 30 days, federal officials are tasked with taking measures in line with the purpose of the memo to prioritize the cyber defense of National Security Systems, Department of War information systems and civilian Federal Government information systems. The EO directs CISA, in consultation with OMB and other White House officials, to issue Binding Operational Directives and other guidance to expedite cyber defense measures, expand AI-enabled defensive tools, and facilitate access to cybersecurity tools and services for federal agencies, state and local authorities, and operators of critical infrastructure. - AI cybersecurity clearinghouse. The EO also directs the Treasury Department, in consultation with the National Cyber Director, NSA and CISA, to form an AI cybersecurity clearinghouse within 30 days. The clearinghouse is intended to coordinate and deconflict software vulnerability scanning, validate vulnerabilities, and prioritize remediation and patch distribution in voluntary collaboration with AI companies and critical infrastructure operators. - Classified benchmarking for covered frontier models. Within 60 days, Treasury, NSA, CISA, NIST and other federal officials must develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine when a model should be designated a âcovered frontier model.â The NSA Director, in consultation with other federal officials, will determine whether a model meets that threshold. - Voluntary pre-release access framework. The EO directs federal officials to design a voluntary framework through which AI developers may engage with the federal government to determine whether models under development qualify as

Companies are failing to keep up with AI's identity sprawl, creating entry points for hackers

Dive Brief: - The rate of data breaches at companies that widely use AI tools is significantly higher than the rate at companies that don’t — 43% compared with 11% over the past 12 months — the identity security firm Netwrix said in a report published on Wednesday. - AI tools such as agents significantly increase organizations’ “identity footprint,” creating more gaps that hackers can exploit, Netwrix said. - At the same time, Netwrix found, the companies using AI the most widely are also the ones taking identity management the most seriously. Dive Insight: Netwrix’s report highlights the security risks of the sprawling web of user accounts and other identities that companies must create to use agents, copilots and other AI tools. “AI agents are now acting on behalf of humans against sensitive data,” Netwrix researchers wrote. “Non-human identities need the same operational rigor long applied to privileged human access.” And yet many companies aren’t taking identity management seriously, the report found. Roughly three-quarters lack “a single, unified view of sensitive data and which identities have access to it,” researchers said. More than half of organizations lack an up-to-date database of sensitive data, 71% can’t quickly determine which identities can access which data and 70% don’t have a security strategy linking data protection with identity governance. Identity management is far from a new challenge for enterprises, but AI has magnified it, and companies are not always keeping pace. Three-quarters of organizations aren’t fully overseeing what AI identities are doing in their systems, even as 41% say they’re letting AI agents access sensitive data and perform vital tasks. Netwrix’s report highlights how hackers have used identity security weaknesses as entry points in target networks. Three-quarters of incidents in which hackers access sensitive data involve compromises of identities or misconfigured account permissions.

The IIA <b>Cybersecurity</b> Topical Requirement: What internal auditors need to know

What is the cybersecurity topical requirement? The cybersecurity topical requirement is a formal framework that guides internal auditors in conducting cybersecurity assurance engagements. It establishes a baseline set of areas internal auditors should evaluate when assessing cybersecurity programs and cyber-related risks. Importantly, it does not create a rigid checklist that every organization must follow identically. Instead, it provides a consistent structure that internal audit functions can apply based on organizational size, industry, complexity, and risk exposure. The requirement exists because cybersecurity audits have historically varied significantly between organizations. Some audit teams perform highly technical reviews with little connection to business risk. Others focus almost entirely on governance documentation without evaluating whether controls actually work in practice. Some organizations rely heavily on external specialists while internal audit remains largely disconnected from cybersecurity oversight. Key principles: - Cybersecurity controls only provide value when they support business resilience and operational continuity. - The goal is not to determine whether a security control exists, but to determine whether cyber risks are managed in a way that protects the organization's ability to operate. - The topical requirement encourages internal auditors to think beyond technical compliance toward strategic assurance. At its core, the requirement reinforces a fundamental principle of modern risk-based internal auditing: audits should align to organizational objectives and risks. Effective cybersecurity auditing does not begin with firewalls or security tools. It begins with understanding what the organization is trying to achieve and identifying the systems, data, and processes that support those objectives. Once critical assets are identified, internal audit can evaluate the threats that could affect them, the risks arising from those threats, and whether the controls designed to mitigate those risks operate effectively. Why the topical requirements matter now The timing of the cybersecurity topical requirement is not accidental. Organizations are operating in

Vibe Coding Puts <b>Cybersecurity</b> Pros' Skills to the Test | Dice.com Career Advice

For developers, each year brings a fresh set of automation tools designed to help them create code faster and roll out application updates that meet ever-changing business needs. Now, artificial intelligence (AI) and large language models (LLMs) have ushered in another era in this development known as “vibe coding.” Vibe coding is an approach where a developer or, in many cases, an amateur coder, describes what they want to create in natural language, and an AI system generates, edits or debugs the code based on an ongoing set of instructions. This approach to application creation shifts some work from writing every line of code toward steering, reviewing and validating AI-generated output. This technique for creating applications remains in its infancy but has caught on, especially as less-experienced coders and developers can take an idea and create an app using various AI platforms. A study by Gartner found that 40% of new business software could be created with techniques involving virtual chatbots and other AI tools. In large tech firms, such as Microsoft, company officials report that AI is creating about 30% of all code using these techniques. The productivity increases — these chatbots can reason across a codebase, edit multiple files, run tests, respond to errors and continue iterating toward a stated goal — have a downside when it comes to ensuring apps are safe and tested for bugs and vulnerabilities. Since many AI platforms scan the open internet, these agents can incorporate flawed code and use it while creating an application, building in vulnerabilities that can be exploited. A less-experienced developer may lack the ability to run quality checks or incorporate DevSecOps techniques when building apps using vibe coding. A 2025 study by Veracode that investigated 100 LLMs found that 45% of code samples failed security tests and introduced

ORNL-developed <b>cybersecurity</b> framework graduates from lab to electric grid | Newswise

Newswise — A grid cybersecurity and verification framework developed at the Department of Energy’s Oak Ridge National Laboratory has been licensed by GridForge Energy Solutions. The startup plans to explore ways the technology could boost real-time visibility of grid behavior for energy projects, grid management companies and utilities. The patented technology, called Cyber Grid Guard, uses a software framework running on customized hardware as a platform to instantly detect unusual grid activity, data manipulation and illicit changes to device settings. These can all cause cascading power outages and damage grid infrastructure. “It’s very meaningful to see this protection technology on a pathway to strengthening the American electric grid and bringing value to American companies,” said Raymond Borges Hink, ORNL cyber security specialist who led the research. “In the past, people didn’t know if they could trust this grid operating data. This provides a new layer of validation and analysis to make the grid safer.” Blockchain protects grid device communications Using the same tamper-resistant blockchain commonly used to protect cryptocurrency, Cyber Grid Guard protects data sharing among electronic devices in the grid. Configuration and operating data about voltage, frequency, breaker status and power quality are spread redundantly across multiple servers. They are then constantly verified against the most recent settings saved in the blockchain. Performance logs track the source of any unauthorized changes. "ORNL's framework represents some of the most rigorous thinking on verified data exchange, attestation, and cybersecurity for grid infrastructure,” said Worlasie Djameh, co-founder and CEO of GridForge. “We are excited to translate this world-class national lab research into something commercially deployable for grid operators and flexible demand providers." The capabilities of Cyber Grid Guard were proven in a substation test bed at ORNL’s Grid Research Integration and Deployment Center (GRID-C) using commercial hardware. GRID-C offers a unique combination

The weakest link in your c-store's <b>cybersecurity</b> strategy? It may not be what you think.

Adam Reynolds is the vice president of Device Software Engineering at Gilbarco Veeder-Root. Opinions are the author’s own. Convenience store operators invest heavily in securing their payment systems and customer data. Yet one critical piece of infrastructure is often missing from broader security planning: the automatic tank gauge, or ATG. This technology monitors both aboveground and underground fuel tanks by tracking inventory levels, detecting leaks and helping companies ensure they’re in environmental compliance. As cyberattacks on critical infrastructure become more common, ATGs have emerged as a potential entry point in the absence of proper security protocols — and the scale of the threat is growing fast. In the first nine months of 2025, ransomware incidents targeting critical sectors rose 34% year over year, with half of all attacks striking industries such as energy, manufacturing and transportation. Fueling infrastructure sits firmly within that risk landscape, with cyberattacks on U.S. utilities rising nearly 70% in 2024. Convenience store operators spend years strengthening the security of their most visible systems. Payment networks are protected. Point-of-sale upgrades are routine. Loyalty data is carefully managed. However, ATGs — many of which were deployed long before today’s threat landscape — are not always evaluated with the same rigor as enterprise IT infrastructure. These devices present a potential access point many would not have considered, particularly as geopolitical tensions and increasingly sophisticated threats place added pressure on legacy infrastructure, according to the World Economic Forum’s Global Cybersecurity Outlook. As convenience retail becomes more connected, ATGs provide critical operational data that help retailers monitor inventory and make more informed business decisions. Realizing that value, however, requires those systems to connect with broader networks and platforms. As a result, securing the device itself is just as important as protecting the data it generates. When left unsecured, these systems can

Axonius Board Chairman: China is 'Ruthless' <b>Cybersecurity</b> Foe

China is a “ruthless” adversary that poses by far the greatest cybersecurity threat to the United States, according to Bob Skinner, chairman of the board of Axonius Federal Systems. In his closing keynote at the Axonius Adapt in Action conference in Washington, D.C., Skinner said China “is the threat.” “Yes, we have Russia and Ukraine going on, and things going on in Iran and the Middle East, but strategically, China is the threat,” he said. Skinner, a former director of the Defense Information Systems Agency (DISA), told the crowd that China is “ruthless in what they are trying to do.” “I’m a firm believer that in all of your lifetimes, China will do something that will impact your daily life, whether that is disrupting your power at some point in time, whether that is disrupting trains or metro, [or] whether that’s disrupting water supplies,” he said. “It can be a mom-and-pop shop in the middle of nowhere, or it can be a water filtration plant in the middle of nowhere. It is going to happen, and we’ve got to be prepared.” Skinner, who has more than 25 years of experience in cybersecurity, national defense, and digital modernization, was named to the Axonius board in April 2025 and became chairman in November. His comments about China echo numerous government warnings about Chinese cyber activities in recent years. In April, a cybersecurity advisory from the Cybersecurity and Infrastructure Security Agency (CISA) said that China-linked groups are shifting tactics and using “covert networks” to target home office routers, along with internet of things (IoT) and smart devices. Skinner said the Chinese threat has evolved from focusing on ransomware and intellectual property to “pre-positioning” cyber assets to strike at a time and place of Beijing’s choosing. To fight the growing threat, he said, U.S.

Warner Introduces Bill to Update Our Country's <b>Cybersecurity</b> Plans, Defend Against ...

WASHINGTON — U.S. Sen. Mark R. Warner (D-VA) today introduced the Combat Emerging Threats to Critical Infrastructure Act of 2026, legislation that directs the Cybersecurity and Infrastructure Agency (CISA) to work with regulators and industry to develop up-to-date cybersecurity plans. In light of artificial intelligence’s rapid advancement, including the development of Anthropic’s Claude Mythos – an AI model capable of identifying and exploiting vulnerabilities in our country’s cybersecurity infrastructure – it is critical that CISA coordinate with other federal agencies to ensure there are current cybersecurity plans can meet emerging threats. “As AI continues to rapidly evolve, we must ensure our cybersecurity defenses keep up with the threats of the moment,” said Sen. Warner. “It’s critical that government works closely with industry, regulators, and cybersecurity experts to develop and regularly update the plans we need to protect our critical infrastructure from increasingly sophisticated malicious actors, including those enabled by AI.” There are 16 critical infrastructure sectors designated under National Security Memorandum 22 (NSM-22), a memo that helps ensure U.S. critical infrastructure can provide the nation a strong and innovative economy, protect American families, and enhance our collective resilience to disasters before they happen. NSM-22 required CISA, in conjunction with other federal departments and agencies designated as Sector Risk Management Agencies (SRMAs), to develop sector-specific plans for each critical infrastructure sector. NSM-22 required a biennial updating of each sector-specific cybersecurity plan by the appropriate SRMA and that sector’s coordinating council. That update cadence has not been maintained, in many cases, for years. In fact, the cybersecurity plan for some critical infrastructure sectors has not been updated for over a decade. Specifically, the Combat Emerging Threats to Critical Infrastructure Act of 2026 would require CISA to complete the following: - Update the sector-specific plans for each of the 16 critical infrastructure sectors

BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities (Revoked)

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities (Revoked) This Directive has been revoked. It is superseded by BOD 26-04. November 03, 2021 This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive 22-01 - Reducing the Significant Risk of Known Exploited Vulnerabilities. A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems. Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives. Federal agencies are required to comply with DHS-developed directives. These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community. Background The United States faces persistent and increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector, and ultimately the American people’s security and privacy. The federal government must improve its efforts to protect against these campaigns by ensuring the security of information technology assets across the federal enterprise. Vulnerabilities that have previously been used to exploit public and private organizations are a frequent attack vector for malicious cyber actors of all types. These vulnerabilities pose significant risk to agencies and the federal enterprise. It is essential to aggressively remediate known exploited vulnerabilities to protect federal information systems and reduce cyber incidents. This directive establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal enterprise and establishes requirements for agencies to remediate any such vulnerabilities included in the catalog. CISA will determine vulnerabilities warranting inclusion

BOD 19-02: Vulnerability Remediation Requirements for Internet-Accessible Systems (Revoked)

Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.BOD 19-02: Vulnerability Remediation Requirements for Internet-Accessible Systems (Revoked) This Directive has been revoked. It is superseded by BOD 26-04. April 29, 2019 This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive 19-02, “Vulnerability Remediation Requirements for Internet-Accessible Systems”. A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems. Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives. Federal agencies are required to comply with DHS-developed directives. These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community. Background As federal agencies continue to expand their Internet presence through increased deployment of Internet-accessible systems, and operate interconnected and complex systems, it is more critical than ever for federal agencies to rapidly remediate vulnerabilities that otherwise could allow malicious actors to compromise federal networks through exploitable, externally-facing systems. Recent reports from government and industry partners indicate that the average time between discovery and exploitation of a vulnerability is decreasing as today’s adversaries are more skilled, persistent, and able to exploit known vulnerabilities. The federal government must continue to take deliberate steps to reduce the overall attack surface and minimize the risk of unauthorized access to federal information systems as soon as possible. Binding Operational Directive 15-01: Critical Vulnerability Mitigation Requirement for Federal Civilian Executive Branch Departments and Agencies’ Internet-Accessible Systems1 established requirements for federal agencies to review and remediate critical vulnerabilities on Internet-facing systems identified by the

Announcing Forrester's Top <b>Cybersecurity</b> Threats For 2026

Announcing Forrester’s Top Cybersecurity Threats For 2026 AI innovation is moving at an unprecedented rate, and geopolitical tensions show no signs of easing. Forrester identifies these factors as two primary forces reshaping the threat landscape, placing additional strain on CISOs who are already stretched thin managing increasingly complex security programs. Anthropic’s Claude Mythos Preview and Project Glasswing are early signals of how radically areas such as vulnerability discovery, remediation, and exploitation are about to change. Simultaneously, the escalating US-Iran conflict has already translated into real world impact, driving a spike in disruptive cyberattacks; from the Stryker incident to Iranian-linked actors targeting PLCs across US critical infrastructure. AI has been a consistent thread running through the last three editions of Forrester’s top threats report. AI‑driven threats have evolved across the past three years as follows: - AI is more than LLMs and ChatGPT. Back in the top threats report for 2023, when ChatGPT was still the public’s first real handshake with large language models, we flagged data integrity as the standout risk. The concern here was the trust placed in these AI systems. - AI has been weaponized. In the 2024 edition of the report, the focus shifted from trust to misuse. We called out how genAI was being weaponized for enabling narrative attacks via disinformation, growing concerns around deepfakes, and concerns over AI responses due to prompt engineering, injection attacks, or the increased risk of sensitive data spillage. - AI supply chain risk emerged. In 2024, we also flagged the AI software supply chain risk as a threat (Spoiler: This concern hasn’t gone away, and it shows up again in this year’s report with updated findings). This is driven by adoption of open‑source models and frameworks such as those found in Hugging Face and GitHub. - Deepfakes are maturing and

Conan O'Brien Sells Out for <b>Cybersecurity</b>, As Only Conan Can

Conan O’Brien has a simple explanation for why he agreed to star in a series of cybersecurity awareness training videos: money. Lots of it. “Hi, I’m Conan O’Brien,” he says in one of several promos for the new series. “There are two rules I live by in my career. One, be authentic. And two, never film security training videos about using AI. It’s beneath me. But then Adaptive came to my house with a dump truck full of money.” The “Adaptive” in question is Adaptive Security, an AI-focused cybersecurity company backed in part by the OpenAI Startup Fund. Its business is helping companies train employees to spot threats like deepfakes, voice cloning, AI impersonation, phishing, QR code scams, and other modern workplace hazards. In other words: corporate compliance training, but with Conan. In another promo, O’Brien opens mid-call: “So it’s all there, every cent? Terrific.” He then turns to camera and explains, “That was my accountant confirming that Adaptive’s check cleared. And now I’m here to tell you about deepfakes.” O’Brien’s promos are part of a new 15-video cybersecurity awareness training series designed to make workplace security lessons something employees might actually watch. Or, as Adaptive puts it on the series’ landing page: “Your employees have skipped every security awareness training you’ve sent. This one is different. It has Conan.” The training videos themselves are available through Adaptive’s enterprise platform, meaning Conan completists will need to convince their IT departments to sign a contract before they can see the full set. According to Adaptive, O’Brien’s team co-wrote the scripts with the company and improvised on set. Each module opens with a comedic O’Brien introduction before moving into Adaptive’s instructional material, interactive elements, and knowledge checks. The company says customers will see two versions of each module in their content library:

Anthropic's 'safe' Mythos-class model won't answer questions about cancer

If you try asking Anthropic's new Claude Fable 5 model a simple question about cybersecurity or biology, you may find it's not up to the task. That's because the underlying "Mythos-class" model is so powerful that, in order to release it to the general public, it required broad safeguards that can mistakenly flag benign requests, Anthropic said. After some users online said they had triggered the safeguard response with basic prompts about cancer or security, Business Insider put it to the test. I tried asking Fable 5 some simple questions about cancer, like how misinformation about cancer spreads online, and to break down some of the different types. Claude swiftly switched from Fable 5 to Opus 4.8 and notified me of the change before it responded. "Fable 5 has safety measures that flag messages on most cybersecurity or biology topics. They may flag safe, normal content as well. These measures let us bring you Mythos-level capability in other areas sooner, and we're working to refine them," the pop-up said. Anthropic released Fable 5 on Tuesday and said it was as powerful as its Mythos 5 model, only with added safeguards. The release came two months after the company said Mythos was too powerful for a broad release due to cybersecurity concerns. Instead of being released to the public, Mythos was made available only to a small group as part of a cybersecurity project. Anthropic said the safeguards were necessary in order to release the model to the general public. "With the launch of Claude Fable 5, our first Mythos-class model, we believe models now have a greater ability to accomplish real-world scientific tasks and for malicious actors to potentially use our models for highly risky biological research," an Anthropic spokesperson said in a statement to Business Insider. "We have always

UW-Superior launches <b>cybersecurity</b> program to meet growing workforce demand

UW-Superior launches cybersecurity program to meet growing workforce demand New concentration offers hands-on training in ethical hacking, digital forensics and AI-driven security SUPERIOR, Wis. (Northern News Now) - UW-Superior is preparing to welcome its first cybersecurity class as part of a new concentration in the university’s computer science program. Growing demand for cybersecurity over the past decade, along with rapid advances in technology including artificial intelligence and increasingly sophisticated scams, has driven the addition of the concentration. Dr. Jonathan Totoshek, chair of the math and computer science department, said the program will bring promising opportunities. “Data security is one of the biggest threats that we face in society these days and having more competent people in place to keep our data safe is a very important role,” Totoshek said. Program adapts to AI threats Classes range from entry-level programming to advanced database courses. Students will be taught skills to adapt to the new world of AI, in some cases protecting against it while also learning to use it responsibly as a tool. “AI is playing a very large role in attacks right now,” Totoshek said. “We need to also adapt and also use AI to help with the protection of these cybersecurity attacks.” Leaders at UW-Superior said the new concentration blends hands-on training like ethical hacking and digital forensics with flexible online and in-person options to meet a fast-growing workforce need. Ryan Dunn, associate director of admission, said the program is already gaining traction. “We have seen a lot of interest from students, both on campus and off campus,” Dunn said. The cybersecurity program will be available for the fall semester of 2026. Click here to download the Northern News Now app or our Northern News Now First Alert weather app. Copyright 2026 Northern News Now. All rights reserved.