Inside ransomware risks, AI's role in cybersecurity
More than one week after Evanston Township High School was targeted in a ransomware attack. The incident is highlighting the growing cyber threats facing schools and other institutions across the country. Kasey Chronis takes a deeper look at the evolving threat of ransomware and AI's role in cybersecurity.
Jun 18, 2026 · via fox32chicago.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jun 18, 2026 · via youtube.com
How AI is changing cybersecurity: Expert shares ransomware and online safety tips EVANSTON, Ill. - More than one week after Evanston Township High School was targeted in a ransomware attack, the incident is highlighting the growing cyber threats facing schools and other institutions across the country. Cybersecurity experts say the recent attack serves as a reminder of how disruptive ransomware can be. More broadly, experts say artificial intelligence is changing the cybersecurity landscape — making attacks more sophisticated and convincing. What we know: Ten days after Evanston Township High School officials discovered the breach in their system, a notice posted on the school's website Wednesday confirmed its phone system remains offline. While officials have not revealed the origin of the attack, the incident comes as cybersecurity experts are closely watching how artificial intelligence is reshaping the threat landscape — changing the way organizations defend against cyber threats and the way cybercriminals carry out attacks. "AI is super powerful and can be used safely. But people need to be aware of how they're using it personally and how they are using it within their organization," said Tony Sabaj, cybersecurity expert for Check Point Software Technologies. "You don't want to stop AI. You want to be able to have people safely adopt it." As AI transforms the way we work, communicate and access information, experts say the technology is creating new opportunities for cybercriminals. "AI brings in kind of a whole new attack vector and a whole new possibility for the attackers," Sabaj said. Tony Sabaj of Check Point Software Technologies has more than 30 years of experience in cybersecurity. This week, he is helping lead Check Point Engage, a summit in Chicago focused on AI and cybersecurity. Sabaj says phishing emails are often the opening cybercriminals need to gain access to
Jun 18, 2026 · via fox32chicago.com
Nintendo, one of the world’s most recognizable video game companies, has reportedly become the target of a significant cyberattack that has resulted in the theft of sensitive employee information. The Japanese gaming giant, known for producing popular gaming consoles and franchises, is now facing a potential data breach crisis after a ransomware group claimed responsibility for stealing company data and demanding a multimillion-dollar ransom. According to information published by the ransomware group known as ShadowByt3$, the attackers have gained unauthorized access to Nintendo’s internal systems and exfiltrated approximately 860MB of confidential data. The group has threatened to release the stolen information publicly unless the company agrees to pay a ransom of $2 million within a specified timeframe. The cybercriminal group describes itself as an extortion operation and has allegedly placed the stolen data up for sale while simultaneously pressuring Nintendo to meet its demands. The compromised information is said to include sensitive employee records such as full names, email addresses, banking details, and private communications. If these claims are accurate, the breach could pose serious privacy and security risks for affected employees. Data breaches involving employee information can have far-reaching consequences. Exposed personal details may be exploited for identity theft, financial fraud, phishing attacks, or other forms of cybercrime. Security experts often warn that stolen employee credentials can also be used as entry points for further attacks against organizations and their business partners. What makes this incident particularly noteworthy is the alleged response from Nintendo. Reports suggest that the company has not publicly engaged with the attackers or indicated any willingness to negotiate the ransom demand. Such a stance is increasingly common among organizations seeking to avoid encouraging future cybercriminal activity. However, ransomware groups frequently escalate their tactics when victims refuse to cooperate. In this case, ShadowByt3$ reportedly adopted what
Jun 18, 2026 · via cybersecurity-insiders.com
EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients. How EY can help - Discover how EY Managed Services can transform and run your cybersecurity function as a strategic enabler that drives confident innovation and growth. Read more What changes when cyber delivery becomes more integrated For many organizations, simplifying the vendor landscape is the starting point. The more meaningful change comes from what happens next. As fragmentation is reduced, cybersecurity begins to operate less as a set of disconnected services and more as a coordinated system. This has a compounding effect. Capabilities such as identity, threat detection and data protection no longer operate in parallel, but begin to strengthen each other. Improvements in one area can carry through to others, rather than remaining isolated. It also changes how organizations think about investment. When existing capabilities are better connected and more fully utilized, the need for additional tools or incremental spend often reduces. In many cases, the opportunity lies less in adding capability and more in making better use of what already exists. At the same time, integration introduces trade-offs that organizations need to manage carefully. Reducing the number of vendors increases reliance on those that remain, and for many CISOs, that raises questions around control and long-term flexibility. A key concern is the potential “black box” effect, where organizations lose visibility into how services are delivered, making transparency and governance critical.
Jun 18, 2026 · via ey.com
Sovereign AI systems built by national governments are hard, expensive and absolutely necessary Cybersecurity Read more
Jun 17, 2026 · via federalnewsnetwork.com
What the New Executive Order on AI and Cybersecurity Means for Your Business On June 2, 2026, the White House issued a new Executive Order titled “Promoting Advanced Artificial Intelligence Innovation and Security.” The order arrives at a moment of significant public attention to the capabilities of next-generation AI systems and the cybersecurity risks they may present. Below, we summarize what the EO does — and, importantly, what it does not do — and offer practical guidance for companies navigating this evolving landscape. Why Now? The EO responds to concerns surrounding two recently announced next-generation frontier AI models — Anthropic’s Mythos and OpenAI’s 5.5 Cyber — which are currently in limited testing and have not been released to the public. Researchers have noted that these models may represent a tenfold increase in capability and speed over current systems, raising the prospect that bad actors could use them to identify and exploit software vulnerabilities or launch cyberattacks at unprecedented scale. The White House and allied governments have expressed concern about the potential impact on critical infrastructure, government systems, and the private sector. They have also expressed frustration that they were not consulted before these models entered development or given a meaningful role in shaping their safety guardrails. This EO is the Administration’s first formal response to those concerns. What Does the EO Do? At the outset, it is critical to understand what the EO does not do. It does not create new federal law. It does not establish a licensing regime, a preapproval process, a permitting requirement, or any other form of regulation over the development, publication, release, or distribution of AI models. The EO itself expressly states this. What the EO does do is take three principal actions: - Federal Agency Directives. It directs federal agencies — including DHS, DOD,
Jun 17, 2026 · via foley.com
As is always the case, there are more wants to shore up ailing infrastructure and add upgrades than there are available funds, Gov. Kelly Ayotte advised during the first of two days of public hearings to open the process. “We can’t control everything. We have one important thing we can control — our fiscal discipline,” Ayotte said in opening remarks. “Living within our means, strong credit ratings and building budgets that reflect the needs and priorities of the state will be my focus.” The current two-year public works budget (HB 25) that Ayotte signed in June 2025 spent nearly $138 million in bonds backed by state taxes and fees, another $10 million from highway funds and $23 million from “other” funds such as dedicated revenues. During Tuesday’s hearing, agency heads from the first six departments to make presentations asked for a total of $253 million in projects. Administrative Services Commissioner Charles Arlinghaus said he operates under no delusion that the $143 million he’s asked for to maintain state buildings and courthouses will win final approval. Over five of the past half dozen capital budgets, his agency received just over $25 million in projects, though in the current plan the number fell to $15.4 million. “I wanted to give you a sense of the scope of the need for the state to catch up on deferred maintenance work,” Arlinghaus said. Karen Rantamaki, state director of plant and property under Arlinghaus, said her staff wouldn’t be able to complete all 36 projects on her wish list even if lawmakers approved them all. Her division has 220 positions but 60 of them — or 27% — are vacant, she said. The top 10 on Rantamaki’s list started with $1.5 million to replenish the state’s emergency fund, which is used to pay for renovations
Jun 17, 2026 · via govtech.com
SPARTANBURG — Cybersecurity experts from the State Law Enforcement Division are investigating Spartanburg County’s recent network and internet disruptions, said SLED spokeswoman Renée Wunderlich. The assist is coming from South Carolina Critical Infrastructure Cybersecurity, which is “a SLED-sponsored initiative with the mission of providing critical services and cybersecurity intelligence to South Carolina’s private and public critical organizations in order to help mitigate, prevent, and respond to cyber incidents,” according to its website. The team isn’t made up of SLED agents, but instead civilian subject-matter experts, Wunderlich said. The county first announced the network disruption on June 11. “Last week, after identifying some questionable activity on its computer infrastructure, the county took the immediate precaution of initiating a protocol to isolate and protect its networks,” Blackwell said in an email on June 17. “As a result, many county services were made unavailable for access,” Blackwell added. “This was an important and necessary security step to provide the county and its consultants the opportunity to confirm and enhance security measures. As confirmations are completed, systems are being made available for access.” While the county hasn’t fully explained what caused the questionable activity and is still examining the issue, the county has twice been attacked by cybercriminals in recent years. A 2023 ransomware attack all but shut down the county’s court system. And last summer, cyberattackers accessed employees’ and civilians’ personal data, resulting in the county offering affected people a year’s worth of free credit monitoring. The county is still working to recover its network after last week’s problem. “We understand and apologize for the inconvenience caused by this important and detailed process,” Blackwell said. “We appreciate the public's patience while this work is completed.”
Jun 17, 2026 · via postandcourier.com
NEW YORK--(BUSINESS WIRE)--Jun 17, 2026-- Align, the premier global provider of technology infrastructure solutions and Managed IT Services, today announced it has been named Best Cybersecurity & Data Protection Solution in the 2026 FTF News Technology Innovation Awards. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260617282843/en/ Align Awarded Best Cybersecurity & Data Protection Solution in the FTF News 2026 Awards The FTF News Technology Innovation Awards recognize the leaders, innovators, and organizations advancing operational excellence across the financial services industry. The Best Cybersecurity & Data Protection Solution category specifically honors the provider that delivers the most effective cybersecurity and data protection solution. Align is known for its multidisciplinary approach to cybersecurity risk management that combines technology, governance, compliance, and education. Designed specifically for financial services firms, the company helps clients assess risk, strengthen security programs, meet regulatory and investor expectations, and maintain resilient operations. Offerings include operational risk assessments, managed detection and response (MDR), data discovery and mapping, managed data protection, virtual CISO services, and cybersecurity education. Over the past year, Align has continued to enhance its cybersecurity capabilities to help clients address new and emerging risks. “We’re incredibly honored to receive this recognition from FTF News,” saidChris Zadrima, Chief Operating Officer of Align. “Align Guardian was built with a clear purpose: to give alternative investment firms the enterprise-grade cybersecurity posture they need to navigate an increasingly complex threat landscape. This award is a direct reflection of the expertise and dedication of our team, as well as the trust our clients place in us to deliver solutions that help them operate at their best. It’s a testament to what can be achieved when innovation is driven by real client needs and a commitment to advancing the industry.” This latest recognition follows a series of industry awards for
Jun 17, 2026 · via rutlandherald.com
- June 17, 2026 Loading A rapidly-growing Sarasota-based cybersecurity company has landed a new big-name client: the NFL’s Kansas City Chiefs. Tenex is now the team's official cybersecurity partner. “As someone who grew up in Kansas City, this partnership is personal,” Tenex CEO and founder Eric Foster says in a statement. “The Chiefs represent a standard of excellence that the entire city rallies around, and protecting that experience matters.” From broadcasts and digital experiences to stadium connectivity, Tenex will provide 24/7 cybersecurity protection across key systems that support the team’s operations, according to a statement, which says NFL organizations have become some of the most complex connected environments, requiring continuous protection across digital and operational systems. “Championship organizations succeed by staying ahead of the play, and that’s the same mindset we bring to cybersecurity,” Foster says. “Tenex is built to anticipate threats, move fast and keep critical operations running without interruption.” Tenex was built from the ground up with artificial intelligence. Its flagship product is its managed detection and response service, which helps organizations detect and handle cyber threats through AI agents that escalate issues to humans when necessary. The company has more than 100 employees and plans to have close to 300 by the end of 2026. It operates offices in Overland Park, Kansas; San Jose; Phoenix; and Sarasota. Tenex says it is continuing to scale its operations in the Kansas City area by investing in local talent, customer support capabilities and an expanded office footprint. (Overland Park is a little more than 10 miles from Kansas City.) “We are extremely excited to partner with Tenex and deploy their cybersecurity solutions across our business,” Kansas City Chiefs Vice President of Information Technology Kevin Higgins says in the statement. “Tenex brings the right blend of innovation, speed and reliability to
Jun 17, 2026 · via businessobserverfl.com
By DEREK TELLIER Editor The Silver Lake City Council approved a cybersecurity and information technology services agreement, reviewed progress on the city’s ongoing infrastructure project and received updates from several departments during its Monday meeting. Cybersecurity services approved The council approved a managed services agreement with CIT to provide cybersecurity protection, IT monitoring, and compliance services for the city’s computer systems and email network. The agreement includes a one-time setup fee of $525 and monthly recurring costs of $725, consisting of a $525 managed services package and a $200 monthly retainer. City officials said the service is intended to help protect city data, improve cybersecurity, and ensure regulatory compliance. Infrastructure project continues The council also approved Change Orders 6 and 7 for the Silver Lake Infrastructure Improvement Project. Change Order 6 decreases the contract amount by $16,399.27 to reflect adjustments to quantities and bid items associated with a previously approved change order. Change Order 7 increases the contract by $25,163.17 and adds an 8-inch raw water main from Well No. 2 along Tower Avenue toward the site of a future water treatment plant. Engineers said installing the pipe now while streets are already under reconstruction will reduce future construction costs and avoid additional disruption. The work is fully eligible for water-related grant funding. A wastewater and water system analysis related to future development is anticipated by Wednesday, July 1. Project engineers reported underground utility work is complete along Center Street, Park Avenue and Oliver Avenue, and those streets have been brought up to gravel. Concrete curb and street work is expected in the coming weeks. Underground utility installation continues along Frank Street, Queen Avenue, Rice Avenue, and Summit Avenue, with those streets expected to be brought up to gravel by mid-July. Additional demolition work is expected to begin in early
Jun 17, 2026 · via glencoenews.com
Data breaches and website tracking technologies may seem like distinct privacy risks, but the California Supreme Court’s recent decision in J.M. v. Illuminate Education could affect litigation involving both. Businesses that collect sensitive information should review how they characterize, protect, and share that information, as plaintiffs will likely rely on the decision to challenge both cybersecurity practices and disclosures involving website tracking technologies. The case arose from a cyberattack on a K-12 education software provider that stored student health-related information. A student filed a putative class action alleging violations of California’s Confidentiality of Medical Information Act (CMIA) and Customer Records Act (CRA). Although the California Supreme Court ultimately held that Illuminate was neither a covered health care provider under the CMIA nor subject to liability under the CRA because the plaintiff was not a “customer,” it adopted a broader standard for CMIA confidentiality claims. The Court held that actual viewing or misuse of compromised information is not required where a breach creates a significant risk of unauthorized access or use. The broader significance of Illuminate is the Court’s focus on exposure to unauthorized access or use rather than proof that someone actually viewed the data. Plaintiffs will likely seek to extend that reasoning beyond CMIA claims and into litigation involving the California Consumer Privacy Act (CCPA), California Invasion of Privacy Act (CIPA), and website tracking technologies. In particular, plaintiffs may argue that liability can arise from the transmission of information through cookies and pixels without proof that anyone actually viewed the data, so long as the disclosure created a significant risk of unauthorized access or use. Therefore, Illuminate should not be viewed as a case affecting only healthcare organizations or victims of data breaches. Its reasoning could ultimately affect virtually every California employer that maintains employee data and every website
Jun 16, 2026 · via procopio.com
Brussels to the Bay: Securing the hyperconnected EU-US perspectives on cybersecurity EU The livestream of this event is now available by clicking here. Cybercrime cost the global economy over $10 trillion last year, with public services, transport, digital infrastructure, finance, and manufacturing among the hardest hit sectors. Ransomware attacks are projected to occur every two seconds by 2031. As digital systems become increasingly central to economic and societal functioning, cyber threats are expected to intensify, prompting both the EU and the United States to refine their approaches through regulation, public-private partnerships, and international cooperation. Against this backdrop, the Brussels to the Bay session, “Securing the hyperconnected EU-US perspectives on cybersecurity,” organized by the EU Office in San Francisco, convened Andrew Grotto (Stanford scholar and former White House Senior Director for Cybersecurity Policy under the Obama and first Trump administrations), Despina Spanou (Deputy Director-General at the European Commission, DG CNECT), Christiane Kirketerp de Viron (Director for Cyber at DG CNECT), and Edvardas Šileris (Head of European Cybercrime Centre, EUROPOL). The discussion took place amid new policy initiatives on both sides of the Atlantic. The EU recently introduced measures to strengthen EU cybersecurity resilience and capabilities while fostering market development through harmonised standards. In parallel, the White House published the “Cyber strategy for America,” signalling a shift toward a more proactive, technology-driven approach to securing digital infrastructure. While these models differ, both prioritise resilience and emerging technologies: the EU focuses on building a trusted marketplace through regulatory clarity, whereas the United States emphasises proactive defence and technological leadership. The panel explored how these approaches can complement one another to strengthen the global cybersecurity ecosystem, gathering panellists’ views and perspectives around key questions: - In what ways can these two different approaches complement each other to foster a more robust global ecosystem for
Jun 16, 2026 · via eeas.europa.eu
The Trump administration released a long-anticipated executive order this month aimed at exercising oversight of cybersecurity risks posed by the most advanced artificial intelligence models. The order attempts to thread the needle between the administration’s anti-regulatory posture and the recognition that it cannot remain on the sidelines in the face of AI’s serious risks to national security. Last week’s chaotic federal ban on foreigners from using Anthropic’s new Claude Fable 5, however, may have provided a preview of how the administration’s regulation of AI will play out, and many questions remain. Fable 5 is the publicly accessible version of Claude Mythos 5, a large language model the company released in April 2026 that is capable of identifying security flaws in software systems. The model can help governments, banks, utilities, hospitals, and other providers of essential services detect and patch the holes. But bad actors could also use this capability to exploit these weaknesses to freeze payment networks, shut down hospitals, and take telecommunications and internet services offline. The release of Mythos was part of the motivation behind President Trump’s order, which establishes a voluntary process for AI developers to submit their models to the government for classified testing for a period of up to 30 days, after which they can release the model to other trusted partners. The order also creates an “AI security clearinghouse” that fosters collaboration between AI developers and operators of critical infrastructure to identify and patch software vulnerabilities. The administration’s newfound openness to AI safeguards will not by itself undo the evisceration and politicization of regulatory agencies that are now expected to shoulder the responsibility of testing, mitigating, and overseeing a rapidly evolving threat landscape. Testing and threat sharing alone will not head off a cybersecurity catastrophe. Achieving that will also depend on how the administration
Jun 16, 2026 · via brennancenter.org
Julie Devoll, HBR Hello, my name is Julie Devoll, editor of special projects and webinars at Harvard Business Review. I recently had the pleasure of attending Zero Trust World and sitting down with Sami Jenkins, [chief operating officer] and cofounder of ThreatLocker. Sami discussed the challenges of building high-performing cybersecurity teams and addressing the industry’s talent shortage and why organizations must stay actively engaged in managing their security. Sami, thank you so much for joining us today. Sami Jenkins, Threatlocker Thank you for having me. Julie Devoll, HBR So ThreatLocker brings together developers, security engineers, researchers, and operations teams. What challenges come with structuring an organization that brings together so many specialized disciplines? Sami Jenkins, Threatlocker And the biggest challenge is getting everybody to work together at times. And we have a phenomenal team, and we do work at a rapid pace. And then finding the right talent, especially local to Orlando—we are office-based here and it is just finding the skill set at times. Our teams do work very, very closely together, and they build a product, obviously. And so with ThreatLocker works, we have our developers who together. And then we’ve got our infrastructure push to build, and then we’ve got a help desk for customers as well. And the biggest challenge from day one, in a sense, is just structuring teams, in a sense. So I’m responsible for building the teams. I still personally hire quite a lot of the people on the team. So as we grow, we always find different areas that need different skill sets. So currently, we’re working on building the solutions engineering team because, hey, we just released a new product. So I need more people to onboard that new product. Julie Devoll, HBR Got it. So cybersecurity is facing a significant
Jun 16, 2026 · via hbr.org
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Summary Successful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF). The following versions of Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP are affected: - CompactLogix 5370 <=34.016 (CVE-2026-11317) - Compact GuardLogix 5370 <=35.015 (CVE-2026-11317) - ControlLogix 5570 <=35.015 (CVE-2026-11317) - GuardLogix 5570 36.012 (CVE-2026-11317) | CVSS | Vendor | Equipment | Vulnerabilities | |---|---|---|---| | v3 7.5 | Rockwell Automation | Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP | Improper Resource Shutdown or Release | Background - Critical Infrastructure Sectors: Critical Manufacturing - Countries/Areas Deployed: Worldwide - Company Headquarters Location: United States Vulnerabilities CVE-2026-11317 A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover. Affected Products Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Rockwell Automation Rockwell Automation CompactLogix 5370: <=34.016, Rockwell Automation Compact GuardLogix 5370: <=35.015, Rockwell Automation ControlLogix 5570: <=35.015, Rockwell Automation GuardLogix 5570: 36.012 known_affected Remediations Vendor fix Rockwell Automation recommends users to update to the following versions: CompactLogix 5370: Versions 34.016 and later Vendor fix Compact GuardLogix 5370: Versions 35.015 and later Vendor fix ControlLogix 5570: Versions 36.012 and later Vendor fix GuardLogix 5570: Versions 37.011 and later Mitigation For more information, see Rockwell Automation Security Advisory SD1772 (https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1772.html) https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1772.html Relevant CWE: CWE-404 Improper Resource Shutdown or Release Metrics | CVSS Version | Base Score | Base Severity | Vector
Jun 16, 2026 · via cisa.gov
President Donald Trump has signed a new National Security Presidential Memorandum aimed at strengthening the cybersecurity of the federal government’s most sensitive military and intelligence networks. The June 12 memo, issued at a time of growing concern about cyber threats from China and other adversaries, re-constitutes the Committee on National Security Systems (CNSS) to oversee the cybersecurity of National Security Systems (NSS) across federal agencies. It puts the director of the National Security Agency (NSA) in a strengthened role as National Manager for National Security Systems, empowering the director “to leverage the full technical power of the National Security Agency to provide advanced defenses and assistance in order to bolster the security of NSS across the U.S. government,” according to a White House fact sheet. The memo establishes National Institute of Standards and Technology (NIST) cybersecurity standards as a baseline for NSS, saying the systems must meet or exceed NIST protection levels. It also requires each national security agency to “maintain and annually update” an inventory of its national security systems, while adding that the CNSS will request secure configuration baselines from cloud service providers accredited to host NSS within120 days. “It is my priority to ensure that the United States can conduct key military and intelligence missions in contested cyber environments and that our personnel have access to the modern, secure technology they need to accomplish these missions,” Trump said in the memo. “It shall be the policy of the United States Government that these systems be defended to the greatest extent practicable.” Bob Ackerman, co-founder and managing partner at DataTribe and founder and chairman of the Global Cyber Innovation Summit (GCIS), offered praise for the memo. “This action is a pragmatic acknowledgement of the cyber threats targeting our country and calls for a long overdue, holistic cyber defense
Jun 16, 2026 · via meritalk.com
SoftBank to Launch Cybersecurity Service in Japan
Newsfrom Japan
Economy Technology- English
- 日本語
- 简体字
- 繁體字
- Français
- Español
- العربية
- Русский
Tokyo, June 16 (Jiji Press)--Japan's SoftBank Group Corp. said Tuesday that it will launch a domestic cybersecurity service to help companies detect vulnerabilities and take countermeasures.
The service uses advanced artificial intelligence technologies developed by OpenAI, the U.S. developer of ChatGPT.
SoftBank Group aims to support companies in strengthening their digital defense capabilities amid growing concerns over the misuse of advanced AI models, such as Claude Mythos, developed by U.S. startup Anthropic.
The service will identify vulnerabilities in security systems, support companies in drawing up guidelines for applying patches and propose methods for implementing those countermeasures.
SoftBank Group will initially offer the service to about 100 firms, including operators of important social infrastructure, such as finance and telecommunications.
[Copyright The Jiji Press, Ltd.]
Jun 16, 2026 · via nippon.com
Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. "The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS," ESET said in a report shared with The Hacker News. "Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP, and WebSocket protocols." Like its Linux counterpart, the Windows versions support more than 30 commands to facilitate system information collection, process enumeration, service management, and file system operations. WIN_DRV has also been found to utilize kernel drivers to conceal the malware's network connections, processes, files, and registry keys. In addition, the variant enables TCP traffic diversion that allows the malware operators to send commands to the backdoor through a random TCP port on the victim's device without exposing the backdoor's actual listening port in the network traffic. SprySOCKS was first publicly documented by Trend Micro in September 2023, attributing its use to a China-nexus state-sponsored threat actor known as Earth Lusca, which is also tracked by the cybersecurity community under the monikers Aquatic Panda, Bronze University, Charcoal Typhoon, and RedHotel. The adversary is assessed to be active since at least 2021 and operated by a Chinese contractor named i-Soon. The Slovakian cybersecurity vendor, which has assigned the name FishMonger to the threat cluster, has described it as a cyber espionage group that falls under the broader Winnti umbrella. In a report published in March 2025, the company linked the hacking group to a global campaign dubbed Operation FishMedley targeting seven organizations in Taiwan, Hungary, Turkey, Thailand, France, and the U.S. between January and October 2022. SprySOCKS is based on a Windows remote access trojan called Trochilus, and shares several common traits with RedLeaves, a backdoor that also exhibits extensive source code overlaps with Trochilus. What's
Jun 16, 2026 · via thehackernews.com