No-frills tech news

Warner Will Introduce Bill to Fund Critical Cyber Information Sharing Program, Urges Mullin ...

WASHINGTON – Today, U.S. Sen. Mark R. Warner (D-VA) announced a collective effort to help all levels of government defend themselves against cyber-attacks. He is introducing the Guaranteeing Universal Access to Cybersecurity Act, legislation that would fund the Multi-State Information Sharing and Analysis Center (MS-ISAC), a decades-old program that provided free cybersecurity resources and monitoring to 19,000 state, local, territorial, Tribal organizations and communities. Sen. Warner sent a letter to Department of Homeland Security (DHS) Secretary Markwayne Mullin urging DHS to prioritize the Cybersecurity and Infrastructure Security Agency (CISA) and to fund MS-ISAC, and a letter every governor in the country, explaining the risk facing critical infrastructure, the hazards caused by the Trump administration’s politically-motivated sabotage of CISA, and advocates for steps the governors can take to protect our national security, economy, and public health. Last year, then-DHS Secretary Kristi Noem terminated funding for MS-ISAC and banned federal grant funding from being used by states, localities, Tribes, and territories (SLTT) and other organizations for membership in the MS-ISAC. Many SLTT and organizations have been forced to wait to fund these critical memberships, creating a dangerous gap in protecting their critical infrastructure. The Guaranteeing Universal Access to Cybersecurity Act would: - Direct the Director of CISA to enter into an agreement with the group that runs MS-ISAC, the Center for Internet Security, to provide no-cost cybersecurity services, cyber threat intelligence collection and dissemination, and technical assistance to SLTT. - Direct the Director to conduct additional outreach to restore MS-ISAC membership to those lost during the defunding and expand access to SLTT entities not previously members of MS-ISAC, serve critical infrastructure sectors, maintain data sharing with the FBI to enhance the national cyber threat intelligence ecosystem. - Direct CISA to report to Congress on the number of re-enrolled and new members of

Shaking Pandora's Box: How Claude Mythos Upends the World of <b>Cybersecurity</b>

Shaking Pandora’s Box: How Claude Mythos Upends the World of Cybersecurity June 05, 2026 In early April, the internet was buzzing with rumors of something new in development by leading AI firm Anthropic. Thanks to a website leak, cybersecurity researchers and internet sleuths had discovered hints about an unreleased AI model that was unprecedented in capabilities and power. Within a few weeks, Anthropic confirmed the existence of “Mythos Preview”, a pre-release version of a powerful cybersecurity-focused AI model with extraordinary defensive and offensive potential. So much potential, in fact, that Anthropic chose not to publicly release it out of a fear of what it could do in the wrong hands. For LSU E. J. Ourso College of Business faculty and cybersecurity experts Ali Ahmed and Rudy Hirschheim, Mythos was a fascinating – and potentially alarming – development. In a wide-ranging Q&A, we chatted with Ahmed and Hirschheim about the capabilities of Mythos, what this new AI means for IT professionals, and how it offers a peek into a Pandora’s Box of unforeseen consequences. Meet the Experts Select a question to read more. Defining Mythos Anthropic’s Claude Mythos Preview is the latest advancement in AI models for autonomous coding and reasoning. What makes Mythos different from earlier models is its ability to search for weaknesses in existing software systems. In the past, companies would invite outside security researchers to probe their systems and pay them for each verified bug they uncovered. Mythos upends this arrangement by shrinking the time required to identify vulnerabilities and by finding them at scale. This quickly exceeds the capacity of existing defensive measures. For instance, Cloudflare, an essential security gatekeeper for over 24 million active websites, discovered 2000 vulnerabilities using Mythos Preview within a month. In contrast, Cloudflare’s well-established and popular bug bounty program reportedly only

Mexico's <b>Cybersecurity</b> Talent Gap Fuels Rising Risks

Mexico’s Cybersecurity Talent Gap Fuels Rising Risks The cybersecurity talent shortage exposes global and Mexican businesses to severe operational and financial risks. With a deficit of 77,000 specialists locally and a systemic lack of strategic leadership globally, organizations must invest in internal talent development, AI, and managed services to build resilient corporate defense architectures. Mexican enterprises face unprecedented vulnerabilities as 40.6 billion cyberattack attempts in 1H25 collide with a critical national deficit of 77,000 cybersecurity specialists, reported by IQSEC. The inability to locate qualified professionals leaves corporate networks undefended against sophisticated threats like ransomware and phishing. To address this crisis, companies are shifting from traditional recruitment to comprehensive training models. “The responsibility of the industry is no longer just to hire talent: it is to develop it, promote it, and open opportunities for new generations,” says Israel Quiroz, Founder, IQSEC. Mexico requires 83,000 cybersecurity specialists, yet only 6,000 professionals are available to meet market demands, according to research by Select and IQSEC. This talent gap creates critical vulnerabilities for corporations. Santiago Fuentes, Co-CEO, Delta Protect, says that a lack of awareness and insufficient investment exacerbate these risks. Although 86% of Mexican organizations plan to increase their cybersecurity budgets in 2026, according to PwC, current investments remain inadequate against modern threats. Additionally, the national legal framework remains outdated, though the Directorate General for Cybersecurity presented the National Cybersecurity Plan for 2025–2030 to build cyber resilience. The financial implications of inadequate security are substantial. PwC data shows that 47% of Mexican organizations reported that their most damaging security breach in previous years cost between US$100,000 and US$10 million. Despite these losses, only 40% of companies quantify the financial impact of cyber risks. Cybercriminals employ various methods to breach corporate networks. OCD Tech says that the most frequent attack vectors include phishing, where

Trump signs executive order on voluntary AI <b>cybersecurity</b> testing

Sinziana Albu 05 Jun 2026 / 5 Min Read The Paypers is a global hub for market insights, real-time news, expert interviews, and in-depth analyses and resources across payments, fintech, and the digital economy. We deliver reports, webinars, and commentary on key topics, including regulation, real-time payments, cross-border payments and ecommerce, digital identity, payment innovation and infrastructure, Open Banking, Embedded Finance, crypto, fraud and financial crime prevention, and more – all developed in collaboration with industry experts and leaders. Current themes No part of this site can be reproduced without explicit permission of The Paypers (v2.7). Privacy Policy / Cookie Statement Copyright

Trump's Executive Order frames U.S. AI policy around deregulation, <b>cybersecurity</b>, and ...

U.S President Donald Trump has issued a policy directive outlining how the federal government should approach Artificial Intelligence, emphasizing reduced regulation, closer work with industry, and expanded cybersecurity defences across federal systems. The order titled ‘Promoting Advanced Artificial Intelligence Innovation and Security’ argues that the U.S. maintains leadership in AI due to private-sector innovation and a regulatory approach that avoids heavy federal restrictions. It directs agencies to prioritize cybersecurity upgrades across national security, defence, and civilian systems, with multiple deadlines of 30 to 60 days. Provisions include those for accelerating vulnerability detection, expanding AI-enabled defensive tools, and improving hiring pipelines for cybersecurity roles. A proposed “AI cybersecurity clearinghouse” would coordinate vulnerability discovery and patch distribution between government and industry. In the policy summary President Trump stated, “It is the policy of the United States to promote AI innovation and security by working collaboratively with the private sector to modernize government and private sector information systems and harden them against external threats; to protect American ingenuity and intellectual property from exploitation and theft by adversaries; and to cultivate America’s advanced AI-enabled capabilities.” Trump continues, “The United States continues to lead the world in Artificial Intelligence because of the enormous talent and innovation of our AI industry, and because we refuse to stifle this innovation with overly burdensome regulation. As these capabilities evolve, my Administration will continue to work closely with industry to ensure that the best and most secure technology is deployed rapidly to confront any and all threats to our country.” The directive also sets up a framework for assessing advanced AI systems used in cyber operations. Federal agencies would develop a classified benchmark to determine when a model qualifies as a “covered frontier model,” with voluntary pre-release government review offered to developers. Additional provisions direct the Office of Personnel

Your data is valuable. A <b>cybersecurity</b> expert tells you how to protect it

Your data is valuable. A cybersecurity expert tells you how to protect it You generate a wealth of data that you entrust to suppliers. But do you really know where it travels, where it’s stored, and who has access to it? In a context where telematics, onboard cameras, and connected platforms are proliferating, these questions are becoming increasingly important for carriers. To demystify the issues surrounding data security, integrity, and governance, Transport Routier spoke with Jean Loup Le Roux, a cybersecurity expert and consultant, as well as a partner at Magna, a firm that has been offering cybersecurity services worldwide since 2014. According to Le Roux, the risks are not limited to cyberattacks: they also concern data control, its sharing with third parties, and, in some cases, issues that can even affect national security. TR: Why should carriers be more concerned about the data generated by their vehicles and systems? Jean Loup Le Roux: Because today, virtually all technologies used in transport are connected. Whether it’s telemetry, electronic logging devices, on-board cameras or fleet management platforms, these solutions rely on constant data exchange. What many people don’t realize is that a single provider can conceal several others. Behind a telematics solution, there are often different providers of cloud services, telecommunications, hosting, or data analytics. Think of it like Russian nesting dolls. The transport company believes it’s dealing with a single supplier, but when you open the first doll, you discover a second, then a third, then a fourth. In some cases, dozens of companies are involved behind the scenes in processing or transporting the data. Each intermediary can potentially have access to some of the information. The company generally knows the supplier with whom it has signed a contract, but it does not always have complete visibility on all the

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework. ReliaQuest has assessed with moderate to high confidence that the espionage-focused activity is linked to China. "OP-512 was highly likely conducting espionage through a compromised Internet Information Services (IIS) web server on an organization whose sector and geography align with China-linked intelligence priorities," the company said in a report shared with The Hacker News. Although no overlaps have been found between OP-512 and other known China-aligned adversaries, it's the fourth such threat group after CL-STA-0048, DragonRank, and GhostRedirector to single out IIS web servers over the past 12 months. As recently as last month, Cisco Talos revealed that multiple Chinese-speaking cybercrime groups are sharing a variant of malware called BadIIS to infect IIS servers. IIS servers have also been targeted by SHADOW-EARTH-053 as part of a new China-aligned espionage campaign targeting government and defense sectors across South, East, and Southeast Asia. Central to the operations of OP-512 is a custom web shell framework consisting of three web shells that grant the attackers remote access to the compromised host, while taking steps to evade signature-based detection and complicate forensic timelines using techniques like timestomping to intentionally manipulate the timestamps when the web shell artifacts are created or modified. Specifically, this entails scanning every file and sub-folder around where the web shells are placed, calculating the median last-modified timestamp, and overwriting their own creation and modification times to match that value, thus giving the impression that they have been present for some time. "This framework combines capabilities we rarely see together: each deployment is uniquely generated, access is restricted to the attacker through cryptographic controls, and compromised servers

After Reviewing Every <b>Cybersecurity</b> ETF These 3 Capture the Full Stack Most Investors Miss

Enterprise cybersecurity budgets are on track to reach $215 billion in 2026, according to Gartner, as AI-powered phishing, prompt-injection attacks against language models, and tighter CISA disclosure rules push security spending higher across every industry. For investors who want broad exposure without picking individual winners between endpoint, network, identity, and cloud security vendors, three ETFs dominate the category: the Global X Cybersecurity ETF (NASDAQ:BUG), the First Trust NASDAQ Cybersecurity ETF (NASDAQ:CIBR), and the Amplify Cybersecurity ETF (NYSEARCA:HACK). Each fund covers the same theme through a different lens. BUG runs a concentrated, modified equal-weighted portfolio of roughly 25 pure-play names. CIBR uses a market-cap weighted approach that pushes Palo Alto Networks and CrowdStrike to the top. HACK, the original cybersecurity ETF launched in 2014, blends pure-plays with IT services and consulting firms that handle security work for federal clients. Year to date, CIBR is up 32%, HACK is up 28%, and BUG is up 27%. Why the full security stack matters now A modern enterprise breach rarely starts and ends within a single product category. An attacker uses a deepfake voice call to phish credentials, pivots through an identity provider, exfiltrates data through an unmonitored cloud bucket, then disables backups. Defending against that chain requires endpoint detection, network segmentation, identity governance, cloud posture management, and data resilience tools, often from different vendors. A cybersecurity ETF gives an investor exposure to the whole chain rather than a bet on which vendor wins each layer. The largest funds disagree on which layer matters most, which is why holdings overlap less than the shared theme suggests. Picking among them comes down to how much concentration an investor wants in two mega-cap names, how much diversification into adjacent IT services is acceptable, and whether smaller pure-plays should pull weight equal to the giants. Global X

Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories

A security researcher found a flaw in Anthropic's Claude Code GitHub Action that let an attacker take over vulnerable public repositories running it, with nothing more than a single opened GitHub issue. Because Anthropic's own action repo used the same workflow, a working attack could have pushed malicious code into the action itself and onto the projects downstream that pull it. RyotaK of GMO Flatt Security reported the core bypass to Anthropic in January, and Anthropic fixed it within four days, with further hardening through the spring; the fixes are in claude-code-action v1.0.94. Anthropic rated the issues 7.8 under CVSS v4.0 and paid a bug bounty. Claude Code GitHub Actions drops Claude into CI/CD pipelines to triage issues, slap on labels, review pull requests, or run slash commands. By default, the workflow gets read and write access to a repo's code, issues, pull requests, discussions, and workflow files. Because those permissions are broad, the action is supposed to be picky about who can trigger it: only users with write access. The trigger check had a hole. It waved through any actor whose name ended in [bot], on the assumption that GitHub Apps are trusted things admins install. Trouble is, anyone can register a GitHub App, install it on a repo they own, and use its token to open an issue or pull request on any public repository. The action saw "a bot" and let the attacker's content through. Tag mode had an extra check to confirm the actor was a real human; agent mode didn't, which left it open. From there, the attacker leans on indirect prompt injection, the trick of planting instructions inside content that an AI reads so the model follows them instead of its actual task. RyotaK wrote an issue whose body looked like an error message,

Audit Identifies 8 Improvement Areas in DOE <b>Cybersecurity</b> &amp; IT Governance Program

- DOE OIG has identified eight areas for improvement in cybersecurity and IT governance - KPMG has issued 11 recommendations to strengthen oversight, risk management and compliance - The 2026 FedCiv Summit will cover AI, cybersecurity, cloud and more The Department of Energy’s Office of Inspector General said an independent audit conducted by KPMG examined the department’s cybersecurity and IT governance program and identified eight areas for improvement. As DOE works to strengthen cybersecurity governance, risk management and compliance across the enterprise, federal leaders continue to focus on the technologies and strategies needed to modernize government operations. Attend the 2026 FedCiv Summit on Oct. 29, where discussions will cover powering and scaling AI across the government; data, cloud and compute infrastructure; cybersecurity and compliance-driven initiatives; and cross-agency and enterprise-wide programs. Save your spot now! OIG said Tuesday the audit assessed whether DOE developed and implemented a governance structure for its cybersecurity and IT activities. The watchdog also reviewed KPMG’s work and reported no instances in which the audit firm failed to comply with generally accepted government auditing standards in any material respect. What Did the DOE OIG Find? KPMG identified eight areas for improvement related to DOE’s cybersecurity and IT governance program. The audit found issues involving outdated contracts, policies and requirements to include standard terms and conditions for prime contractors and subcontractors. KPMG also reported that DOE had not fully implemented a risk monitoring program, an enterprise data strategy or a comprehensive enterprise information system inventory that includes systems containing personally identifiable information. In addition, the audit identified areas requiring improvement to ensure compliance with federal requirements, create a comprehensive workforce assessment and verify the accuracy and completeness of data requests submitted by DOE elements. What Recommendations Did KPMG Make? KPMG offered 11 recommendations to address the eight areas

#anthropic #claudemythos #projectglasswing #ai #<b>cybersecurity</b> #technews #indiatech ...

BIG TECH EXCLUSIVE: Anthropic is widening its top-secret "Project Glasswing," and India just made the cut. A select group of Indian financial and cybersecurity entities are getting early preview access to "Claude Mythos"—Anthropic's powerful next-gen model designed to stress-test cyber vulnerabilities and defend against emerging bioweapon threats. Ashmit Kumar #Anthropic #ClaudeMythos #ProjectGlasswing #AI #Cybersecurity #TechNews #IndiaTech #ArtificialIntelligence #CNBCTV18Digital CNBC-TV18’s Post More from this author Explore content categories - Career - Productivity - Finance - Soft Skills & Emotional Intelligence - Project Management - Education - Technology - Leadership - Ecommerce - User Experience - Recruitment & HR - Customer Experience - Real Estate - Marketing - Sales - Retail & Merchandising - Science - Supply Chain Management - Future Of Work - Consulting - Writing - Economics - Artificial Intelligence - Employee Experience - Workplace Trends - Fundraising - Networking - Corporate Social Responsibility - Negotiation - Communication - Engineering - Hospitality & Tourism - Business Strategy - Change Management - Organizational Culture - Design - Innovation - Event Planning - Training & Development

Subcommittee Chairman Ogles Opens Hearing on Frontier AI Models, the Future of <b>Cybersecurity</b>

Subcommittee Chairman Ogles Opens Hearing on Frontier AI Models, the Future of Cybersecurity June 4, 2026 WASHINGTON, D.C. ––Today, Subcommittee on Cybersecurity and Infrastructure Protection Chairman Andy Ogles (R-TN) delivered the following opening statement in a hearing to examine the growing role of frontier AI models, agentic AI systems, and AI-powered coding tools in both strengthening U.S. cyber defenses and enabling increasingly sophisticated cyber threats. As prepared for delivery: Good morning and thank you all for being here. Today, we are examining how artificial intelligence is changing the foundations of cybersecurity and the security of our critical infrastructure. This Committee has taken these threats and risks seriously for months. We have held roundtables, hearings, and briefings with the leading AI laboratories and cyber companies in the country, and we have opened a joint investigation with the Select Committee on China into the proliferation of Chinese AI models. On Tuesday, President Trump signed an executive order directing the Secretaries of the Treasury, Homeland Security, and War to develop a classified benchmarking process for advanced AI cyber capabilities and to design a voluntary framework for early government access to covered frontier models. The President is right to act. These models are already reshaping the threat landscape, and the federal government cannot be the last to understand what they can do. I want to be clear that this Subcommittee intends to watch closely how CISA carries out its responsibilities under that framework. CISA has statutory authorities under the Cybersecurity Information Sharing Act of 2015, operates the Known Exploited Vulnerabilities catalog, and serves as the lead civilian agency for critical infrastructure cybersecurity. How CISA fulfills its role under this order, especially in translating early model access into practical guidance and vulnerability remediation for critical infrastructure operators, will be a central oversight question for this

Google Cloud's Quiet Layoffs Hit <b>Cybersecurity</b> Teams

Google is the latest Big Tech company to do layoffs this year. Employees working at Google Cloud have been hit by cuts over the last two weeks, two people familiar with the matter told Business Insider. One team, Google's Threat Intelligence Group, which is one of Google's top security units and regularly publishes research about hackers, was impacted yesterday, the people said. Some employees have been posting about the layoffs on LinkedIn. The cuts were not limited to that unit, affecting others at Mandiant — a cybersecurity company bought by Google in 2022 — and within Google Cloud, the people added. It's unclear exactly how many people were impacted and why the cuts are happening now. In one instance, Google cited the need to reinvest in growth areas, such as AI, to justify the move, one of the people said. "We regularly evaluate our internal structures to ensure we are best positioned to meet the evolving demands of our customers and the industry," a Google spokesperson told Business Insider. The cuts are just the latest to hit Big Tech as companies pour billions into AI. Meta laid off 10% of its staff last month, while others like Coinbase and Block used AI to justify big cuts earlier this year. Cybersecurity has also been affected: Cloudflare laid off more than 1,100 employees earlier last month as it prepares for the "agentic AI era." Last year, Google Cloud quietly let go of some staff, mostly in user experience roles, Business Insider reported. Have a tip? Contact this reporter via email at crollet@businessinsider.com or on Signal and WhatsApp at 628-282-2811. Use a personal email address, a nonwork WiFi network, and a nonwork device; here's our guide to sharing information securely.

HCC Southwest ramps up hands-on training in AI, robotics and <b>cybersecurity</b>

HOUSTON – Houston Community College Southwest is expanding hands-on training designed to prepare Houston residents for jobs in fast-growing fields such as artificial intelligence, robotics, manufacturing and cybersecurity. The college’s applied programs combine lab work and industry-informed curriculum so students gain practical skills employers are hiring for right now. Todd Duplantis, interim executive director of HCC communications, marketing and public information, shares what’s happening on the HCC Southwest campus and how the college is meeting local workforce needs. Programs emphasize small classes and lab time, bringing students face-to-face with the equipment and software they’ll use on the job. That hands-on approach is intended to shorten the time between training and employment. Affordability and access remain central to HCC’s mission. Through the Houston Reconnect and Connect 2 Work initiatives, many short-term certificate programs are offered with no tuition cost for qualified learners, making upskilling more accessible across the city. These certificates are intended to be quick, career-focused pathways that can lead to entry-level roles or stack into longer credentials over time. Local employers and program advisers are also working with HCC to ensure course content aligns with real workplace needs, from automation and precision manufacturing to data-protection practices used in cybersecurity teams. Students can expect to build portfolios and complete projects that demonstrate job-ready competence to hiring managers. How to get started: visit HCCS.EDU or call 713-718-2000 to explore programs, check eligibility for Houston Reconnect or Connect 2 Work, and sign up for campus tours or information sessions. For specifics on which short-term certificates are tuition-free and enrollment deadlines, contact the college directly. Whether you’re pivoting careers or upskilling from within your current job, HCC Southwest aims to make the path practical, affordable and connected to Houston’s growing industries.

Sourcefit named winner in the Artificial Intelligence category at the Fortress <b>Cybersecurity</b> ...

While Enterprises Debate AI Governance, a Global BPO Has Been Running It in Production MANILA, Philippines, June 4, 2026 /PRNewswire/ -- Sourcefit, a global BPO operating across the Philippines, South Africa, the Dominican Republic, Madagascar, Armenia, and the United Kingdom, has been named the winner in the Artificial Intelligence category at the Fortress Cybersecurity Awards 2026. The recognition arrives ten weeks before the EU AI Act takes full effect on 2 August 2026, when organizations deploying AI across regulated industries in Europe will face a reckoning. They will need to demonstrate auditability, human oversight, and verifiable data access controls. Most enterprises will not be ready. Sourcefit's architecture meets those requirements today. Gartner research from May 2026 finds 40% of enterprises will demote or decommission autonomous AI agents by 2027 due to governance gaps identified only after production incidents. Sourcefit built an AI governance platform where unauthorized data access is structurally impossible. Controls are not a policy framework sitting on top of the system; they are enforced at the database and credential layer before an agent can act. Agents can only retrieve rows they are explicitly authorized to access at the database engine level. That distinction, between policy-based AI governance and infrastructure-enforced AI governance, closes off prompt injection as a viable attack vector, a class of attack most enterprise AI deployments cannot defend against. Sourcefit runs production AI handling sensitive client data across healthcare, finance, insurance, and technology without a breach, rollback, or governance failure. Agents operate across 30-plus operational skills, with every action permanently on record. Governance at this level has cut the time required for firewall queries and compliance validation by more than 95%. "The enterprise AI governance problem is only getting more complex. As organizations deploy agents into more sensitive environments, the infrastructure behind them must keep up.

Concerns Over <b>Cybersecurity</b>

Loading Video… This browser does not support the Video element. Concerns Over Cybersecurity Cybersecurity Expert Chace McLaughlin joins with Ronia Shamona to discuss how multifactor authenticators Is no longer enough for security. This browser does not support the Video element. Cybersecurity Expert Chace McLaughlin joins with Ronia Shamona to discuss how multifactor authenticators Is no longer enough for security.