CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability - CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability - CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. This product is provided subject to this Notification and this Privacy & Use policy.
Jun 10, 2026 · via cisa.gov
Development Challenge Governments are deploying digital public infrastructure, AI systems, and data-driven services at speed - but without adequate trust frameworks in place. Cybersecurity vulnerabilities, weak data governance, and deepening dependencies on foreign technology, talent, and cloud platforms expose countries to systemic risk. For developing economies, these challenges converge into a crisis of digital sovereignty: limited ability to govern data, regulate AI, build domestic capacity, or ensure the resilience of essential digital services. Retrofitting trust after deployment is costly and often ineffective. World Bank Group The WBG addresses digital trust through an integrated approach that brings cybersecurity, data protection, and responsible AI governance together as a cohesive function - ensuring these protections are built into digital systems from the start, not added as an afterthought once infrastructure is already in place. WBG's engagement spans three interconnected pillars. Foundations establish the legal and regulatory baseline through data protection laws, cybersecurity frameworks, and AI governance architecture, tied directly to government budget support agreements so that the right legal protections are in place before digital infrastructure is built. Capabilities strengthen enforcement institutions - Data Protection Authorities, national Computer Emergency Readiness Teams (CERTs), and cybersecurity bodies - while embedding data rights and digital safety into skills programs. Resilience prepares countries for inevitable incidents through contingency financing and pre-approved response mechanisms. A WBG-supported multistakeholder collaboration, spanning public, private, academic, and civil society organizations, produced the third edition of the Guide to Developing a National Cybersecurity Strategy, delivering streamlined, actionable guidance to help low- and middle-income countries build cybersecurity strategies aligned with national development priorities, with new emphasis on multi-year financing, governance accountability, and policy agility for emerging technologies including AI, IoT, and quantum. In partnership with peer multilateral development banks (MDBs) and international forums, WBG advocates for data governance frameworks reflecting developing economy realities. International
Jun 9, 2026 · via worldbank.org
Conan O'Brien is hosting educational videos for an AI cybersecurity company At long last, a corporate training you might actually enjoy. Cybersecurity AI company Adaptive Security has partnered with famed comedian Conan O'Brien for a 15-part educational video series. These training videos will help Adaptive's clients and their employees to navigate threats such as phishing and deepfakes. Considering how often corporate trainings are a total snoozefest, getting a genuinely funny and smart person to present this critical information seems like a smart, if expensive, move. The clip currently promoting the partnership on Adaptive's website even kicks off with a joke about O'Brien only doing the gig for the money. More broadly, it's great to see a business investing in this type of education to ensure that people really do follow best practices for online safety. The FTC said social media scams cost Americans at least $2.1 billion last year. Companies that might have access to even bigger bank accounts, not to mention sensitive information, make for even juicier targets. And AI tools can make cons awfully convincing and easier to pull off. Luckily, there are plenty of common sense rules you can follow to keep the troublemakers at bay. We aren't lucky enough to have Conan narrating them, but just queue up the monorail episode of The Simpsons to play in the background while you read some of Engadget's top cybersecurity tips for a near-identical experience.
Jun 9, 2026 · via engadget.com
Claude Fable 5 and Claude Mythos 5 Today we’re launching Claude Fable 5: a Mythos-class1 model that we’ve made safe for general use. Fable 5’s capabilities exceed those of any model we’ve ever made generally available. It is state-of-the-art on nearly all tested benchmarks of AI capability, showing exceptional performance in software engineering, knowledge work, vision, scientific research, and many other areas. The longer and more complex the task, the larger Fable 5’s lead over our other models. Releasing a model this capable comes with risks. Without safeguards, Fable 5’s capabilities in areas like cybersecurity could be misused to cause serious damage. We’ve therefore launched the model with safeguards that mean queries on some topics will instead receive a response from our next-most-capable model, Claude Opus 4.8. To release the model both safely and quickly, we’ve tuned these safeguards conservatively—they’ll sometimes catch harmless requests, though they trigger, on average, in less than 5% of sessions. With more capable models arriving in the coming months, we’re working to improve our safeguards and reduce false positives as quickly as we can. For a small group of cyberdefenders and infrastructure providers, we’re also launching Claude Mythos 5. It’s the same underlying model as Fable 5, but with the safeguards lifted in some areas.2 Mythos 5 will initially be deployed through Project Glasswing, in collaboration with the US government, as an upgrade to Claude Mythos Preview. It has the strongest cybersecurity capabilities of any model in the world. Soon, we intend to expand access to Mythos 5 through a broader trusted access program. The capabilities of models like Fable 5 and Mythos 5 have the potential to do profound good for the world. We’ve seen the beginnings of this in Project Glasswing, where the models have helped cyber defenders secure critically important software. We’ve
Jun 9, 2026 · via anthropic.com
Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution.
Tracked as CVE-2026-44963, the vulnerability carries a CVSS score of 9.4 out of a maximum of 10.0.
"A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user," Veeam said in a Tuesday advisory.
It credited watchTowr researcher Sina Kheirkhah for responsibly discovering and reporting the issue. It impacts Veeam Backup & Replication 12.3.2.4465 and all earlier versions of 12 builds.
Veeam has noted that the vulnerability does not affect any version 13.x build of the backup software due to architectural changes introduced in version 13.
The shortcoming has been addressed in Veeam Backup & Replication version 12.3.2.4854.
In March 2026, Veeam resolved multiple critical vulnerabilities in Backup & Replication software that, if successfully exploited, could result in remote code execution.
It's essential that users update to the latest version for optimal version, particularly given that prior vulnerabilities in the program have been exploited by bad actors, including ransomware groups.
Jun 9, 2026 · via thehackernews.com
Go-To Guide: - On May 21, 2026, the New York Department of Financial Services (NYDFS) published two companion industry letters: a guidance on measures regulated entities should consider in a heightened cybersecurity threat environment, and an advisory on the cybersecurity risks posed by frontier AI models. - The Heightened Threat Environment Guidance catalogs specific measures across three categories: reducing the attack surface, improving threat detection and readiness, and strengthening resilience and response. - The Frontier AI Advisory directs CISOs to particular sections of the Heightened Threat Environment Guidance and layers on AI-specific recommendations for vulnerability management, secure coding, and third-party coordination. - Neither publication creates new legal requirements under 23 NYCRR Part 500. Both articulate DFS’s expectations for how regulated entities should calibrate their existing cybersecurity programs when threat conditions escalate. Still, both publications preview examination expectations. On May 21, 2026, NYDFS published two related industry letters addressing cybersecurity preparedness for DFS-regulated financial institutions, insurers, and money transmitters. The first, titled Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment (the Guidance), provides a structured menu of defensive measures entities should consider when cybersecurity risks become significantly elevated. The second, titled Heightened Cybersecurity Risks Associated with Frontier AI Models (the Advisory), warns that certain AI models capable of identifying vulnerabilities and exploits at unprecedented speed and scale will soon become more widely available, and directs entities to prepare now. The two documents are designed to work together: the Advisory identifies the threat, and the Guidance provides recommendations on how to respond. Neither publication creates binding requirements. Both documents state explicitly that they do not alter the obligations under Part 500. The Guidance frames its recommendations as measures entities “should consider” adopting based on their “unique circumstances and operations.” The Advisory states it is “intended to inform
Jun 9, 2026 · via natlawreview.com
- GDIT has expanded its partnership with Splunk to bring AI-powered cybersecurity solutions to federal agencies - The collaboration will focus on zero trust and next-generation security operations centers - Join the 2026 FedCiv Summit to discuss AI adoption, cybersecurity, cloud and more General Dynamics Information Technology and Splunk have signed a strategic collaboration agreement to expand their partnership and deliver artificial intelligence-powered cybersecurity offerings to U.S. federal government customers. As agencies continue to modernize digital infrastructure and strengthen cyber defenses, collaboration between government and industry remains a critical topic across the federal landscape. The 2026 FedCiv Summit will bring together government and industry leaders to discuss AI, cybersecurity and compliance initiatives, cloud and data infrastructure, workforce enablement and enterprisewide modernization efforts. Book your seat now! What Does the GDIT-Splunk Partnership Intend to Pursue? Under the agreement, GDIT said Monday it will combine its mission support and technology integration experience with Splunk’s AI, cybersecurity and data analytics capabilities. The expanded partnership will also facilitate the integration of Splunk’s data platforms into GDIT’s Digital Accelerators and Mission Solutions portfolio to help agencies protect data and devices; secure critical infrastructure; improve cyber resilience; and support compliance with federal cybersecurity requirements. According to GDIT, the partnership will focus on: - Advancing security operations center capabilities through agentic AI-enabled cyber operations - Improving cyber visibility and situational awareness through enhanced data integration using AI - Developing zero trust offerings to protect critical systems What Did Ben Gianni & Bill Rowan Say About the Partnership? “Our expanded partnership with Splunk will enable us to deliver differentiated, scalable solutions that harden our customers’ cyber defenses and empower them to execute their missions with confidence,” said Ben Gianni, senior vice president and chief technology officer at GDIT. Bill Rowan, vice president of sales for Splunk’s public sector,
Jun 9, 2026 · via executivebiz.com
Getty Images/amgun Federal vulnerability management is stuck. A patch wave is coming anyway. Commentary Read more
Republican senators warn surveillance program may lapse after Trump intel pick backlash Cybersecurity Read more
Getty Images/NicoElNino CMMC has moved from planning to enforcement and contractors are feeling it Cybersecurity Read more
Jun 9, 2026 · via federalnewsnetwork.com
Skip to main content
Toggle Search Form
Search for:
Search
Menu
Home
Colleges
Colangelo College of Business
College of Doctoral Studies
College of Education
College of Engineering and Technology
College of Arts and Media
College of Humanities and Social Sciences
College of Natural Sciences
College of Nursing & Health Care Professions
College of Theology
Honors College
Categories
Alumni
Campus Life
Community Outreach
Online
Press Releases
Slideshows
Videos
Calendar
Events
Academics
GCU Magazine
History of GCU
GCU History
The GCU story
Grand 'Construction' University
A campus culture like no other
GCU timeline
Then and now
Did you know...?
Brian Mueller and the ‘Phoenix 50’
Pioneering online education
Rise of athletics
The next 75 years
Toggle Search Form
Search for:
Search
Home
Events Calendar
Tech and Innovator Days: Cybersecurity, Ethical Hacking
Tech and Innovator Days: Cybersecurity, Ethical Hacking
June 17 @ 9 a.m.
-
3 p.m.
«
Tech and Innovator Days: Engineering
National Root Beer Float Day
»
+ Add to Google Calendar
+ Add to iCalendar
Details
Date:
June 17
Time:
9:00 am - 3:00 pm
Register Now
Jun 9, 2026 · via news.gcu.edu
St. George Fire sues cybersecurity company, alleging negligence left network open to 2023 cyberattack ST. GEORGE — The St. George Fire Protection District is suing Baton Rouge cybersecurity company General Informatics, blaming them for allowing hackers to gain access to the fire department's network in 2023. The lawsuit, filed by the fire department on May 23, claims that General Informatics was hired to prevent cyberattacks and now seeks damages from a December 2023 attack. St. George Fire's lawsuit added that hackers were "living off the land" inside the network, meaning the hackers used tools already built into the network to avoid being found and further infest and scrape the fire department's network. The lawsuit also accuses General Informatics of installing high-speed internet and selling the district network switches that were incapable of accommodating the new internet. No backups were made of the servers, the lawsuit also alleges, despite being included in the contract between the two parties. On the fire district's network, a "note written in plain text which contained the fire district's administrative credentials for its various accounts and software applications," representing another major issue highlighted by the lawsuit. Other issues also popped up, including that the network firewall was not recording certain activity and that it was not properly segmented to prevent malware from making its way through the system. Trending News The case is set to go before a judge or an exception hearing in the 19th JDC on July 13.
Jun 9, 2026 · via wbrz.com
Studying Cybersecurity Abroad: A Week in Rome I have been to Italy before; multiple times, in fact. So when I decided to attend St. John’s University’s Cybersecurity in a Global Context program, the destination itself was not what gave me pause. What was different this time was that I was going without my wife. After years of traveling together, there is something oddly disorienting about navigating familiar streets alone. But that feeling of strangeness turned out to be exactly the point. Arriving and Going “Dark” After an orientation on Saturday evening, Sunday was a free day. I used it the way I usually do in a city I know well: I just walked. Rome is the kind of city that rewards wandering. There is no shortage of things to stumble upon, and taking it slow helped me settle in and shake off the long flight. By Monday morning, I was ready to work. Monday kicked off with one of the more memorable labs I have had in this program: a dark-web exploration workshop. Using Linux VMs, we set up and navigated the Tor Browser, learned the basics of operational security, and got a firsthand look at what exists beyond the surface web. No purchasing or account creation was done. This was strictly for observational purposes…in case you were wondering. We also dove into open-source intelligence (OSINT) that day. We covered tools such as Maltego, Spiderfoot, and Sherlock, and explored how investigators legally gather public data to build profiles, track movements, and support incident response. After lunch, we headed out for a guided walking tour of Rome’s city center, starting at Piazza del Popolo. The afternoon was a welcome contrast to the morning’s screen time. The Feds Show Up Tuesday brought a compelling guest presentation from a Federal Bureau of Investigation
Jun 9, 2026 · via stjohns.edu
Senate Health, Education, Labor and Pensions (HELP) Committee Chairman Sen. Bill Cassidy, M.D., R-La., is seeking information from New York City officials about a late 2025 cybersecurity breach at NYC Health + Hospitals, the largest public U.S. health system. The legislator wants answers from CEO Michael Katz, M.D., on the system’s security protocols, best practices, notified agencies and how it has responded to the incident. New York Mayor Zohran Mamdani’s administration was also cited in the June 4 letter (PDF). Cassidy is seeking responses from officials by June 18. NYC Health + Hospitals notified affected individuals March 24 about a data security incident. The system said it discovered suspicious activity Feb. 2 affecting certain systems in its network, with a subsequent investigation determining an unauthorized user accessed systems between Nov. 25 and Feb. 11. Preliminary investigation results found the user may have accessed systems due to a security breach from a third-party vendor. The system said its notification was not delayed due to the result of a law enforcement investigation. Affected information varied by individual, though the system noted it included health insurance information; medical information; biometric information; billing, claims or payment information; or other personal information, like Social Security numbers or precise geolocation data. "Cybersecurity threats are one of the most significant risks currently affecting the health care system," Cassidy wrote in the letter, citing 628 reported breaches in 2025. “At a time when hostile actors are increasingly using sophisticated tactics by leveraging artificial intelligence, it is essential for the health care sector to take meaningful steps to safeguard patient and consumer information,” Cassidy wrote. “The recent cybersecurity incident affecting NYC Health + Hospitals, the largest public health system in the United States, highlights the risk cybersecurity incidents pose to patients.” Cassidy requests more information from NYC Health +
Jun 9, 2026 · via fiercehealthcare.com
SUPERIOR, Wis. (KQDS-TV)- For anyone interested in a career with computer science or cybersecurity, University of Wisconsin Superior is unveiling an exciting opportunity.
As of this year, students can now get their computer science degree with a concentration in cybersecurity.
The goal of this new option is to help prepare students for careers in cybersecurity with a strong foundation in computer science fundamentals.
One staff member said that he hopes this option will help with the high demand the field is currently facing.
"There's all sorts of different careers you could go into involving cybersecurity. A lot of them are housed under the IT world, so information technology, but there's positions such as cybersecurity analyst," explained Dr. Jonathan Totushek, Chair of the math and science department.
Both new and current students have the option to apply for this opportunity right now.
And it officially launches for the fall 2026 semester.
Commented
Sorry, there are no recent results for popular commented articles.
Jun 8, 2026 · via fox21online.com
Today, Congresswoman Maxine Waters (D-CA), the top Democrat on the House Financial Services Committee, sent a letter to the Chief Executive Officers of leading U.S. financial institutions, including JPMorgan Chase, Citigroup, Bank of America, Morgan Stanley, Wells Fargo, and Goldman Sachs, demanding an immediate briefing on how they are addressing newly discovered cybersecurity vulnerabilities linked to advanced artificial intelligence. The letter follows Anthropic’s announcement of “Claude Mythos Preview,” an “extremely autonomous” artificial intelligence model capable of carrying out sophisticated computer security and coding tasks. According to Anthropic, the system has already identified thousands of high-severity vulnerabilities across major operating systems and web browsers, with the company warning that exploitation of these flaws could pose severe risks to the economy, public safety, and national security. In the letter, Ranking Member Waters raises concerns about the growing cybersecurity and financial stability risks posed by increasingly powerful AI systems, as well as a troubling lack of engagement and transparency from major Wall Street institutions. “I am deeply concerned that the Committee has not been briefed by your banks on how you are confronting the heightened risks of cybersecurity vulnerabilities identified by Mythos, and your efforts to ensure your institutions operate in a safe and sound manner, protect consumers, and mitigate your risks to U.S. financial stability,” wrote Ranking Member Waters. “Bank CEOs’ lack of engagement, as these developments come to light, impairs the Committee’s ability to protect the public and the financial system as we know it from novel and existential AI risks.” In closing, Ranking Member Waters requests that the banks provide Democratic staff of the House Financial Services Committee with a comprehensive briefing and written responses to a series of questions regarding cybersecurity preparedness, regulatory gaps, internal AI risk-management frameworks, federal coordination protocols, and vulnerability disclosure procedures no later than July
Jun 8, 2026 · via democrats-financialservices.house.gov
The Federal Communications Commission will consider a package of changes later this month aimed at bolstering cybersecurity protections for the nation’s emergency alert systems and modernizing how alerts reach the public. For counties, the proposal affects some of the most important tools available during emergencies. Local emergency managers rely on the Emergency Alert System (EAS) and Wireless Emergency Alerts (WEA) to communicate with residents during severe weather events, hazardous materials incidents, evacuations, public safety emergencies, and other critical situations. The FCC proposal focuses heavily on cybersecurity. The agency is proposing new requirements to protect alerting systems from unauthorized access, including stronger password policies, software updates, and other security measures to reduce the risk of false alerts or system disruptions. The proposal also includes several modernization efforts. Among them, the FCC is considering alert authentication requirements, improvements to geographic targeting, tools to reduce duplicate alerts, and the elimination of older message-length restrictions that date back to earlier wireless technologies. One proposal could prove especially significant for EAS participants. The FCC is considering whether to allow emergency alert functionality to operate via software rather than requiring dedicated hardware. Broadcasters and industry groups have argued for years that the current hardware-based approach is becoming increasingly difficult to maintain as equipment ages and vendors leave the market. The FCC is also seeking comment on ways to improve alert accuracy and effectiveness. Potential changes include improvements to earthquake alerts, emergency-specific alert symbols, and better geographic targeting to reduce instances of residents receiving alerts for incidents occurring well outside their area. The proposal remains under consideration and has not yet taken effect. The Commission will vote on the item at its June 25 meeting.
Jun 8, 2026 · via conduitstreet.mdcounties.org
As artificial intelligence reshapes the cybersecurity and data science industries, USF’s Bellini College of Artificial Intelligence, Cybersecurity and Computing is infusing AI into its courses. Starting this fall, new and existing courses focusing on developing artificial intelligence skills will be added to the college’s course roster or enhanced with added AI module components. “Artificial intelligence is not something we treat as a separate discipline anymore. The daily use of AI is becoming an integral part of how work gets done across industries,” said Bellini College launch Dean Sudeep Sarkar. “Our goal is to make sure students understand how to use these tools thoughtfully, responsibly and effectively in the careers they’re preparing to enter.” AI course expansion During the past year, the college has significantly increased its AI course offerings at both the undergraduate and graduate levels. And that expansion will continue into the coming year. New undergraduate courses such as AI Fundamentals, Document Intelligence and specialized topics in Generative AI and AI for Integrated Sensing and Communication reflect a growing emphasis on applied learning. These courses build on a lineup of existing courses that includes machine learning, natural language processing and computer vision. Courses are expanding at the graduate level, too. Classes such as AI Applications, Ethical Issues in AI and Math for AI have been added, and more courses, including Network Analysis and Machine Learning with Graphs, Natural Language Procession, Hardware for Machine Learning and Computer Vision, tackle advanced AI topics. These courses are designed to introduce students to AI concepts at the undergraduate level and nurture their continuing education at advanced levels, preparing them to work with these technologies in real-world settings. “Experiential learning is at the core of what we do,” Sarkar said. “We want our students to be ready for the real world when they graduate,
Jun 8, 2026 · via usf.edu
CISA Highlights Vital Resources to Help Event Attendees Stay Safe As the summer season approaches, people across the country are preparing to attend a wide array of special events, from global showcases like the FIFA World Cup 2026™ to celebrations marking America’s 250th anniversary. Large-scale gatherings like the World Cup and Freedom 250 bring people together and embody the spirit, resilience, and freedoms that define our nation. But with increased crowds, high visibility, and complex logistics, these events also present unique security challenges, including the potential for the use improvised explosive devices (IEDs) to disrupt public safety and damage critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) may be widely known for its work in cybersecurity, but it also works with partners around the nation to mitigate physical risks and enhance infrastructure security. For example, through its Office for Bombing Prevention (OBP), CISA is equipping state and local partners, event organizers, and the public with the training, tools, and awareness resources needed to reduce risks and enhance risk mitigation preparedness. By promoting suspicious activity reporting, sharing protective guidance, and offering no-cost security planning materials, CISA is helping communities across the nation confidently celebrate these once‑in‑a‑generation events. Suspicious Activity Awareness: Identifying Potential Threats One of the most effective ways to prevent bombing incidents is early detection of suspicious activity or items. CISA trainings emphasize that everyone has a role to play in ensuring safety by being vigilant. Understanding what constitutes suspicious behavior or items is critical. CISA offers many no-cost resources and tools to help people know what to look for and what to do, ranging from how to identify suspicious items, things to know about unmanned aircraft systems, and more. These and other physical and cybersecurity resources and tools can be found at www.cisa.gov/FIFAWC. What You Can Do As
Jun 8, 2026 · via cisa.gov
A cybersecurity policy professor on believing in the research process—and yourself ‘It Is an Act of Faith’ In high school, I liked math and was good at math and thought that I was going to be a mathematician: a weird thing to want to be as a teenager, but there it is. There were a lot of mathematicians who meant a lot to me; Andrew Wiles, with his proof of Fermat’s Last Theorem, loomed very large for me. I was also fascinated by a lot of older mathematicians; I did a research project on Madame Du Châtelet, who had translated Newton’s Principia into French. But I went to college with some people who were a lot better at math than I was. It was a new experience for me not be the strongest student in the class. I started to understand if I worked as hard as I possibly could, maybe I could major in math, but I was never going to be a great mathematician. I was good enough at math to appreciate and enjoy it, but I wasn’t good enough to come up with original math. It’s like the ability to appreciate great classical music while also knowing that you’re never going to perform it at that level. In theoretical math, the thinking is we’re going to perfectly prove everything—there will be no exceptions. In some ways, cybersecurity’s the opposite: there’s no way to actually finish this job. Instead, we’re going to perfectly prove how secure this encryption algorithm is, and then we’ll implement it … but then someone’s got to manage the encryption keys, someone else has to install the update … and 1,000 things are going to go wrong. The question I’ve found most interesting about cybersecurity research is: How do you marry the rigorous technical
Jun 8, 2026 · via now.tufts.edu
A dollar in First Trust NASDAQ Cybersecurity ETF (NASDAQ:CIBR) on the last trading day of 2025 was worth about $1.22 by the close on June 5, 2026, while the same dollar in the S&P 500 was worth about $1.08. That is the headline making the rounds, and the shorthand version of it (cybersecurity beat the broad market by three to one) is close enough to true that it is worth taking apart carefully, because the mechanism behind the gap is also the thing that tells you whether the next six months look anything like the last six. The Arithmetic, Without the Spin CIBR opened the year at $71 and closed June 5, 2026 at $87, a 22% year-to-date gain. The S&P 500, via SPY, went from $682 to $738, an 8% gain. The actual ratio is closer to 2.6 to 1 rather than a clean 3 to 1, and the bulk of CIBR’s move happened in a single month. The fund was up 24% in the thirty days ending June 5, which means that without May, the year-to-date story would read like an ordinary tech-adjacent fund nudging ahead of the index. Total return matters less than usual here. CIBR is not an income product, distributions are small, and the price-only number captures essentially the whole picture. Over five years the fund is up about 101%, against about 75% for SPY, so the long-run edge is real but modest. The 2026 outperformance is the kind of jolt that pulls a decade’s worth of structural alpha into half a year, and that is the part that needs explaining. What Actually Did the Work CIBR is concentrated by design. The March 31, 2026 NPORT filing shows $9.49 billion in net assets across 44 positions, with Palo Alto Networks at 8.46%, CrowdStrike at 8.25%,
Jun 8, 2026 · via 247wallst.com
Simplifying Cybersecurity: How SMBs Can Protect What Matters Most Small and medium-sized businesses (SMBs) face an ongoing struggle between the cost and the critical need for cybersecurity. As tech stacks grow and the online landscape keeps changing, business owners are looking for ways to protect their digital assets and workflows with effective tools that can scale with their business ambitions. Enter CyberFOX, a platform offering cybersecurity solutions for businesses that are practical, proactive,and growth-friendly. The innovative security provider has invested in solutions that work to reduce friction in key areas like password management, privileged access, and DNS protection. It also emphasizes a streamlined approach by focusing on usability and efficiency. This article will look at the cybersecurity struggle SMB owners are facing at the moment and the ways CyberFOX is helping organizations to strengthen their security posture while staying focused on business growth. The Cybersecurity Struggle Cybersecurity has steadily become more complex for owners and their teams. SMBs in 2026 are juggling a growing number of tools and budgets for cybersecurity threats. This tension is leaving many IT teams struggling to manage fragmented systems and growing threats with limited resources. In 2024, 58% of small and medium-sized businesses spent more than they expected on securing their digital activity. 57% of them have since made it a top priority as they watch the online landscape continue to evolve quickly. Despite the additional focus on security, 46% of cyber breaches in recent years have involved businesses with under 1,000 employees, making the threat not just a potential but a reality for many business owners. CyberFOX: Unifying Cybersecurity CyberFOX has focused on a specific crossroads in the cybersecurity world: safety and simplicity. It has built a suite of security solutions that work to unify critical capabilities that are often scattered across business operations.
Jun 8, 2026 · via usatoday.com