No-frills tech news

Crypto <b>Cybersecurity</b> Practices Must Refocus on Human Error

Not so long ago, our firm received a cybersecurity alert from a client. Their crypto protocol, which we had audited and which they had recently launched, was being exploited. This was obviously terrible news, so we rushed to look at what happened. After some confusion, we realized that our client had actually deployed the wrong version of their protocol—a test version used during development, not the version we had audited. It was a simple human error, but it cost the client a lot of money. This anecdote illustrates a real, widespread problem in the crypto sector: these days, the most damaging cybersecurity attacks don’t target errors in the code so much as they target operational mistakes. Since 2022, the industry has lost an astonishing $2.2 billion to malicious actors. The industry’s response has been to triple the number of software audits it conducts. But our research shows that the majority of attacks actually focus on human vulnerabilities, which are beyond the scope of ordinary audits. Put differently, the crypto industry needs to change its attitude toward cybersecurity checks. It shouldn’t abandon code audits, but it should seriously ramp up efforts to protect itself from human attack vectors. Otherwise, it will keep bleeding money away and never have the opportunity to go properly mainstream. Traditional Audits Aren’t Enough To be fair, audits have improved the quality of crypto software. Fewer exploits are due to technical coding errors than before. The industry has gotten better at this specific thing. But criminals adapt. Today's most costly attacks involve tricking employees into handing over passwords, manipulating the voting systems that govern how these platforms make decisions, planting malicious software through routine updates, or simply compromising a trusted insider. Meanwhile, AI tools have made it dramatically easier for attackers to craft convincing fake emails, impersonate

Palo Alto CEO: &quot;The SaaS apocalypse is dead, at least in <b>cybersecurity</b>&quot; | Ctech

Palo Alto CEO: "The SaaS apocalypse is dead, at least in cybersecurity" The cybersecurity giant's first full quarter with CyberArk highlights growing demand for AI-era security platforms. After reaching an all-time high and a market value of approximately $250 billion, Palo Alto Networks, the largest company traded on the Tel Aviv Stock Exchange, is pulling back. The cybersecurity giant published quarterly results on Tuesday that, for the first time, included a full consolidation of CyberArk’s operations following the completion of its $25 billion acquisition in February. Despite reporting strong results and raising its outlook, Palo Alto’s shares are down following the earnings release. The primary explanation appears to be profit-taking after a remarkable rally that has seen the stock gain about 65% since the start of the year. Investors are also weighing the impact of recent acquisitions on profitability. Palo Alto reported a net loss in the quarter after an extended period of profitability, although the company argues that the decline is temporary and largely related to acquisition-related expenses. Alongside CyberArk, Palo Alto has also spent $3.3 billion on the acquisition of Chronosphere and approximately $400 million on Israeli cybersecurity startup Koi, whose technology is intended to strengthen the company’s defenses against AI-related threats. Palo Alto reported revenue growth of 31% year-over-year to $3 billion, exceeding analyst expectations. Acquisitions contributed $388 million to quarterly revenue, with CyberArk accounting for the majority of that figure. Before its acquisition, CyberArk had already surpassed an annual revenue run rate of $1 billion. The company also announced that beginning in fiscal 2027 it will report results across three primary business segments, one of which will be CyberArk’s identity security platform. On the bottom line, Palo Alto recorded a net loss of $177 million, largely driven by acquisition-related employee compensation expenses that totaled approximately $500

President Trump Signs Executive Order Establishing AI <b>Cybersecurity</b> and Frontier Model Framework

President Trump Signs Executive Order Establishing AI Cybersecurity and Frontier Model Framework Key POINTS - The Order directs federal agencies to strengthen cybersecurity across government systems and critical infrastructure, including through an AI cybersecurity clearinghouse and expanded access to AI-enabled defensive tools for state and local authorities. - Federal agencies will design a voluntary framework by August 1, 2026, for developers of frontier AI models to engage with the federal government prior to model release. - The Attorney General is directed to prioritize enforcement of existing federal criminal statutes against anyone who uses AI to illegally access or damage a computer without authorization, or who employs AI agents to unlawfully access data for use in a criminal purpose. On June 2, 2026, President Trump signed an executive order (the Order) titled “Promoting Advanced Artificial Intelligence Innovation and Security,” which seeks to balance the Trump administration’s long-standing goal of promoting AI innovation through a minimally burdensome regulatory framework with the need to modernize and protect key systems against emerging AI-related threats. The Order addresses three principal areas: (1) strengthening cybersecurity across federal systems and critical infrastructure; (2) creating a voluntary pre-release engagement framework for developers of frontier AI systems; and (3) directing the Attorney General to prioritize enforcement of existing criminal statutes against AI-enabled cybercrimes. Throughout, the Order emphasizes voluntary collaboration with the AI industry rather than implementing rigid, mandatory regulations. This Client Alert summarizes the Order’s key provisions and outlines practical steps that companies developing, deploying, or incorporating AI into their business operations should consider. Overview of the Order The Order is organized around three core components: (I) upgrading federal and critical infrastructure cybersecurity; (II) establishing a voluntary framework for pre-release engagement on frontier AI models; and (III) prioritizing criminal enforcement against AI-enabled cybercrimes. I. Upgrading American Systems for Advanced

New AI Executive Order Addresses Frontier Models and <b>Cybersecurity</b> Vulnerabilities

New AI Executive Order Addresses Frontier Models and Cybersecurity Vulnerabilities On June 2, 2026, President Trump signed an Executive Order (EO), Promoting Advanced Artificial Intelligence Innovation and Security, that provides a framework for assessing and addressing cybersecurity vulnerabilities that may be identified by new frontier AI models. The EO directs a range of federal agencies to establish processes for information sharing around new frontier AI models with heightened vulnerability identification and exploitation capabilities, and efforts to remediate identified vulnerabilities. For the private sector, the EO establishes a voluntary process for AI model developers to submit AI models for federal review prior to broader release, and provide critical infrastructure entities with early access to these models in order to strengthen cybersecurity protections. Below, we summarize the key directives of the EO, as well as what industry can expect next. Directives for Updating Systems for Advanced AI Section 2 of the EO, Upgrading American Systems for Advanced AI, requires various federal agencies to take action to prepare federal government and private-sector systems for advanced AI tools within 30 days of the EO – that is, by July 2, 2026. In particular: - Cyber Defense for Key Federal Systems: The Committee on National Security Systems must prioritize the cyber defense of National Security Systems, as defined in 44 U.S.C. 3552(b)(6)(A); and the Secretary of War must prioritize the cyber defense of Department of War (DoW) information systems. - Cyber Defense Directives and Guidance for Civilian Federal Government Systems and Critical Infrastructure: The Secretary of Homeland Security, through the Cybersecurity and Infrastructure Security Agency (CISA), must consult with the Office of Management and Budget (OMB), the Assistant to the President for National Security Affairs, and the National Cyber Director, to release Binding Operational Directives and other guidance that (1) promotes cyber defense of civilian

Bitdefender Delivers Powerful <b>Cybersecurity</b> Solution for Connected Homes

Bitdefender, a global cybersecurity leader, today announced the integration of its advanced security technology into Swisscom’s new home network protection solution. The comprehensive cybersecurity offering for Swisscom subscribers has a built-in protection directly in the router. The collaboration comes at a time when threats to personal data, digital identity, and privacy are accelerating, driven by increasingly sophisticated AI-powered attacks targeting connected households. “Protecting our customers against cybersecurity threats is key for us as a leading ICT company,” said Marcel Burgherr, Head of Home Devices at Swisscom. “With our security offering and the new router-based protection, we are extending protection beyond individual devices to the entire home network, delivering seamless, built-in security while maintaining the high-performance experience our customers expect.” Attacks targeting connected households continue to grow in scale and frequency. Industry research shows the average home now has more than 22 connected devices and faces over 30 attempted network attacks every 24 hours. A Bitdefender global survey of 7,000 consumers further reveals significant protection gaps, with 58% not using third-party security on computers and 82% reporting the same for tablets. These findings reinforce the urgent need for seamless, comprehensive protection across every device in the home network. Bitdefender has integrated its Smart Home Security technology into Swisscom’s home network protection offering, delivering advanced protection directly at the router level to secure all connected devices, including laptops, smartphones, smart TVs, and other IoT devices. This integration provides powerful, network-level defense against malware, phishing, online scams, malicious websites, fraud, and other threats. It operates seamlessly in the background without requiring installation on individual devices. “Threat actors are increasingly using automation and AI to scale attacks, making it more difficult for consumers to protect their personal data and connected devices,” said Ciprian Istrate, senior vice president of operations at Bitdefender Consumer Solutions Group.

FCC <b>Cybersecurity</b> Workshop for Broadcasters: Key Takeaways and Practical Guidance

FCC Cybersecurity Workshop for Broadcasters: Key Takeaways and Practical Guidance On May 14, 2026, the Federal Communications Commission’s (FCC) Public Safety & Homeland Security Bureau (PSHSB) convened a Cybersecurity Workshop for Broadcasters, bringing together public- and private-sector stakeholders to discuss emerging cyber threats, share best practices, and explore opportunities for collaboration.[1] The broadcaster-focused workshop underscored the increasingly critical role of cybersecurity in safeguarding broadcast infrastructure. Below, we summarize the workshop and provide key takeaways for broadcasters in this ever-evolving landscape. Evolving Risks Workshop participants identified a broad and increasingly complex range of cyber threats facing broadcasters of all sizes. These include: - Infrastructure-targeted attacks, aimed at the broadcast air chain, including studio-to-transmitter link (STL) hijacking and manipulation of Emergency Alert System (EAS) equipment. - Ransomware and malware, which can disrupt operations, compromise sensitive data, and result in financial losses. - Social engineering attacks, including phishing campaigns targeting company employees and help desks. - Denial-of-service attacks, which can undermine a station’s ability to stay on air. Importantly, speakers emphasized that threat actors range from financially motivated criminals to politically motivated “hacktivists” and nation-state actors. The workshop also homed in on artificial intelligence’s (AI) role in reshaping the threat environment. Participants highlighted that while AI can enhance defensive capabilities such as real-time threat detection, it can also enable more sophisticated attacks, including deepfakes, automated phishing campaigns, and adaptive malware. How Broadcasters Can Develop a Risk Management Approach A consistent takeaway from the workshop was that there is no single solution to cybersecurity risk. Instead, broadcasters should adopt a layered, “defense-in-depth” strategy tailored to their specific systems and risk profiles. Key elements of a risk management approach to cybersecurity can include the following measures, as appropriate to risk: 1. Governance and Planning - Develop a written cybersecurity risk management plan before incidents occur.

AIDR: Defining the Next Era of <b>Cybersecurity</b> | CrowdCast

Upcoming events Conference CrowdTour Find a city near you Summit Day Zero 2026 Las Vegas, NV Your Cart Added to Cart There's nothing in your cart per endpoint / per year per endpoint / per month Shadow AI: The Widening Governance Gap CrowdCast Mythos Is a Wake-Up Call: Five Steps to Prepare for Frontier AI What Security Teams Need to Know About OpenClaw, the AI Super Agent Beyond the Perimeter 2026 with CrowdStrike, Okta and Zscaler Introducing the CrowdStrike Falcon Platform Spring '26 Release Making AI Real in the SOC: Practical Steps to Faster, Smarter Security Operations Interactive AI Threat Simulation: Investigating Prompt Injection Attacks Quantifying Endpoint ROI: TEI Insights and CrowdStrike’s AI-Native Platform, Featuring Forrester Securing the AI Era with CrowdStrike Falcon® AI Detection and Response Raising the Bar: Unpacking the 2025 MITRE ATT&CK® Enterprise Evaluations from Endpoint to Cloud 2025 Cyber Frontline Insights: Transforming Reactive Response into Prevention Redefining Cloud Security with Agentic AI Defeating BLOCKADE SPIDER: An Interactive Ransomware Response Simulation How Platform Consolidation Cuts Costs and Accelerates AI-Driven Defense Accelerate Your Agentic SOC Transformation with Onum Preventing Identity-Based Attacks on Healthcare Organizations Outdated and Outmatched: Why Legacy AV Can’t Keep Up Ransomware and Extortion Attacks in Healthcare: Understanding the Threat, Strengthening Defenses, and Improving Resilience Beyond the Perimeter 2025 with CrowdStrike, Okta and Zscaler Stopping the Enemy Within: Detect and Defeat Insider Threats Before They Strike Cloud Under Siege: How to Outsmart Today’s Most Dangerous Adversaries The Next Era of MDR: AI, Automation & Human Expertise Outpace the Adversary. Take Control of Your Exposure. Harnessing the Power of GenAI with a Platform-Centric Approach Modernize Cloud Security with CDR: Unifying Cloud Posture and Protection AI-Accelerated Threat Landscape: Year of the Evasive Adversary Enhance Zero Trust Coverage Across Government Endpoints, Identities, and Clouds SaaS Threat Simulation: Detecting and

City Club of Eugene meeting to focus on <b>cybersecurity</b> threats

Leaders affiliated with the Oregon Cybersecurity Center of Excellence, including representatives of the University of Oregon, the city of Eugene and the Lane Council of Governments, will discuss cybersecurity threats when the City Club of Eugene meets Friday, June 5. The club meets at noon at the WOW Hall, 291 W. Eighth Ave. Club meetings are open to the public and free to attend. The Oregon Cybersecurity Center of Excellence, created in 2023, is a collaboration between the University of Oregon, Portland State University and Oregon State University to provide awareness, education, services and training about cybersecurity issues. Cybersecurity threats affect governments, infrastructure, businesses, schools and community organizations across Oregon. Friday’s scheduled speakers are: - Robin Mayall, director of information services at the city of Eugene. Previously, she served as the director of information technology and strategic innovation for Lane Transit District, where she also held roles as a business analyst and project manager. - Brenda Moore, executive director of the Lane Council of Governments since 2012. The council provides information technology services to other public agencies. - Reza Rejaie, professor and head of the computer science department at the University of Oregon and a founding associate director of the Oregon Cybersecurity Center of Excellence. Friday’s program will be livestreamed, and the video will be available on the City Club of Eugene’s YouTube channel and on the club’s podcast. It will be broadcast at 7 p.m. Monday, June 15, on KLCC, 89.7 FM.

Fact Sheet: President Donald J. Trump Promotes Advanced Artificial Intelligence Innovation ...

Fact Sheet: President Donald J. Trump Promotes Advanced Artificial Intelligence Innovation and Security PROMOTING AMERICAN AI INNOVATION AND SECURITY: Today, President Donald J. Trump signed an Executive Order to advance American artificial intelligence (AI) innovation to strengthen America’s cybersecurity, protect critical infrastructure, and ensure the United States remains the global leader in AI innovation. - The Order directs appropriate agencies to prioritize the cyber defense of National Security Systems, Department of War information systems, and civilian Federal government information systems. - This includes the Secretary of Homeland Security, in consultation with the Director of the Office of Management and Budget, the Assistant to the President for National Security Affairs, and the National Cyber Director, issuing binding operational directives and other guidance to facilitate access to AI-enabled cybersecurity tools and services for Federal agencies, State and local authorities, and operators of critical infrastructure, including rural hospitals, community banks, and local utilities. - The Order establishes an AI cybersecurity clearinghouse, in voluntary coordination with the AI industry and critical infrastructure operators, to identify and remediate software vulnerabilities at scale. - The Order directs the Office of Management and Budget and the Office of Personnel Management to identify funding opportunities for advanced AI cybersecurity capabilities and expand Federal cybersecurity hiring and placement pathways. - The Order calls for the development of a classified benchmarking process against which industry may assess their models for advanced AI cyber capabilities, identifying covered frontier models. - The Order directs the Federal government to establish a voluntary framework in collaboration with AI developers regarding covered frontier models, which would provide the Federal government with secure early access for trusted partners to strengthen cybersecurity and promote secure innovation. - The Order expressly states that nothing shall be construed to authorize creation of any mandatory governmental licensing, pre-clearance, or permitting

New Executive Order Strengthens AI Oversight and <b>Cybersecurity</b> as Technology Advances

Americans for Responsible Innovation today applauded the White House’s release of a new executive order aimed at strengthening cybersecurity protections and establishing new safeguards for advanced AI systems. The executive order is one of the federal government’s strongest actions to date focused on cybersecurity and the national security risks posed by frontier AI models. The new action comes in the wake of Anthropic’s Mythos AI model, which has raised concerns about the cybersecurity vulnerabilities created by advanced AI. Among the new safeguards outlined in the executive order are a new classified benchmarking process to assess the advanced cyber capabilities of AI models, 30-day predeployment access for the federal government, and establishment of an AI cybersecurity clearinghouse to discover and mitigate vulnerabilities. “The White House is officially Mythos-pilled,” said ARI President Brad Carson. “The past couple months have served as a massive wake-up call for the kinds of vulnerabilities that AI can create. Today’s executive order signals that the Administration is taking those risks seriously. Policies on vulnerability detection, benchmarking, and pre-public access for the federal government are positive steps forward. Now it’s time for Congress to follow the White House’s lead and make these protections mandatory.” Following news that the White House would begin development of an executive order related to AI model oversight and security, ARI shared guidance with the White House on how the Administration can conduct effective oversight of advanced AI models. ARI’s letter to the White House makes recommendations on scoping and covered domains, as well as the safeguards to bolster this system against gaming and abuse. ### Americans for Responsible Innovation (ARI) is a nonprofit organization dedicated to policy advocacy in the public interest, focused on emerging technologies like artificial intelligence (AI). Learn more at ARI.us.

North Carolina Makes <b>Cybersecurity</b> a Statewide Challenge

That’s the message North Carolina Gov. Josh Stein is working to drive home in his state. Because a weak password, a suspicious email or an overlooked software update can seem insignificant in the moment, but as digital systems become more deeply woven into everyday life, the consequences of cyber incidents are becoming harder to contain — and difficult to ignore. This week, Gov. Stein and the North Carolina Department of Information Technology (NCDIT) launched the Secure Your Square Challenge, a monthlong campaign tied to June being National Internet Safety Month, that encourages people to take simple steps to better protect themselves online. Rather than treating cybersecurity as something handled exclusively by IT professionals, the state is asking all North Carolinians to see it as a shared responsibility. At the center of the state’s latest efforts is a digital bingo card filled with practical cybersecurity tasks that residents, families, schools, businesses, local governments, state employees and community organizations can identify and mark off as they complete each action. The challenge doesn’t ask participants to become cybersecurity experts. Instead, it focuses on the kinds of habits security professionals have been encouraging for years: turning on two-factor authentication, creating stronger passwords, keeping software up to date, reviewing privacy settings and learning how to recognize phishing attempts and scams. What’s notable about the campaign is its emphasis on collective responsibility. The state isn’t just asking individuals to protect their own devices; instead, using the digital card, they can challenge friends, relatives and coworkers to participate, too. NCDIT Secretary Nate Denny, who serves as state CIO, linked cybersecurity directly to public safety. “Internet safety is public safety,” Denny said in a statement. “Technology is part of every aspect of daily life, so online safety must be part of how we protect our families, workplaces and

Cisco Advances 5% to Record Highs on AI <b>Cybersecurity</b> Push, Arista Climbs as Networking ...

Shares of Cisco Systems (NASDAQ:CSCO | CSCO Price Prediction) are up 5% in midday trading on Tuesday, June 2, changing hands at $127 and change after a Monday close of $121.33. Cisco stock is printing fresh all-time highs as the company unveiled a sweeping AI cybersecurity and unified management push at its annual Cisco Live U.S. conference. The networking trade is extending across the sector. Arista Networks (NYSE:ANET) is up 2% to around $174, a meaningful push higher after a slightly negative month into today. Notably, dedicated cybersecurity peers Palo Alto Networks (NASDAQ:PANW) and CrowdStrike (NASDAQ:CRWD) are trading lower, with Palo Alto Networks stock off 2% and CrowdStrike stock down 3%. The split suggests that investors are reading Cisco’s launch as real competitive pressure on the dedicated security vendors. Cloud Control and Live Protect Power the Cisco Live Pop Cisco introduced Cisco Cloud Control, a unified technology management platform that lets human IT teams work alongside autonomous AI agents to oversee, monitor, and defend corporate infrastructure. Inside Cloud Control sits the AI Canvas, a generative workspace where customers can use natural-language conversations to build custom applications or deploy automated agents. The second pillar is an enhanced Cisco Live Protect, which delivers real-time automated cybersecurity defense patches with no software upgrades, reboots, or maintenance windows. Live Protect is initially deployed on N9000 series switches, with plans to expand to campus smart switches and secure routers later this year. Jeetu Patel, Cisco’s president and chief product officer, stated, “AI agents reason and act continuously at software speed, and that changes everything about how we scale, manage, and defend our critical infrastructure.” Cloud Control serves as the foundation for Cisco’s AgenticOps strategy, and the company also outlined a quantum-safe framework targeting “harvest now, decrypt later” tactics. The launch builds on a strong fundamental

NSA Selects David Imbordino, Holly Baroody to Lead <b>Cybersecurity</b> Directorate

- NSA has appointed David Imbordino and Holly Baroody to cyber leadership roles, according to The Record - Imbordino brings decades of experience spanning cybersecurity, intelligence and election security missions - The changes support the Cybersecurity Directorate’s mission to identify threats and strengthen cyber defenses The National Security Agency has selected David Imbordino and Holly Baroody to lead its Cybersecurity Directorate, The Record reported Tuesday, citing people familiar with the matter. Imbordino will serve as chief of the Cybersecurity Directorate, while Baroody will become deputy chief. The agency has also selected Bruce Jones to lead the Cybersecurity Collaboration Center, which coordinates cyberthreat information sharing between the government and private sector. Leadership remains critical as intelligence and cybersecurity organizations adapt to an evolving threat landscape. The challenges shaping agency priorities will be a key topic at the Potomac Officers Club’s 2026 Intel Summit, which brings together government and industry leaders to discuss the future of intelligence operations. Register now to take part in the Sept. 24 event! What Experience Does David Imbordino Bring to the Role? Imbordino is an NSA official with nearly 25 years of experience in cybersecurity, intelligence and operational missions. He has served as deputy director of the cyber organization since March 2025. The Record reported in January that he was appointed to lead the directorate in an acting capacity. Imbordino previously held leadership roles overseeing cybersecurity operations, counterintelligence and cyber analysis activities at the agency. One of his most prominent assignments was leading NSA’s election security efforts. From 2019 to 2021, he served as election security lead and helped coordinate efforts to protect U.S. elections from foreign interference. Who Is Holly Baroody? Baroody is an NSA senior official in the United Kingdom. According to her LinkedIn profile, she became a senior executive in the Department of War

Google Cloud Underscores #1 Ranking by Taking <b>Cybersecurity</b> Fight to Bad Guys

As it grows more than twice as fast as rivals Microsoft and AWS and expands its innovative leadership in enterprise AI, Google Cloud has strengthened its #1 spot on the Cloud Wars Top 10 by launching an AI-powered and end-to-end cybersecurity solution offering “transformative vulnerability management.” With cybercriminals aggressively adopting AI to devise and launch attacks that are increasingly sophisticated and damaging, the new Google AI Threat Defense goes beyond standard cybersecurity approaches from the pre-AI Era that are no longer intelligent enough, fast enough, or powerful enough to cope with this new wave of threats. As shown in the diagram below, Google AI Threat Defense is designed to help businesses not simply react to attacks that are already underway, but also to give those customers an ongoing process centered on integrated preparation and analysis, real-time prioritization of threats, autonomous remediation, and nonstop monitoring and evaluation. This highly advanced new cybersecurity is the brainchild of Google Cloud’s Francis deSouza, who is not only COO of the red-hot company — Q1 revenue soared 63% to $20 billion — but also president of Security Products. In a blog post introducing Google AI Threat Defense, deSouza said the comprehensive new solution enables customers to “fight AI with AI” and will “ensure that your enterprise doesn’t just keep pace with automated adversaries, but consistently outpaces them.” More from that deSouza’s post: AI has changed the threat landscape; cybercriminals are using it to find security cracks faster than cybersecurity teams can manually fix them. Attacks that used to take weeks to carry out can now happen in mere hours or days. Organizations need to be able to keep pace and protect themselves against AI agent-driven, high-speed attacks — but they can no longer rely on legacy, manual methods. To defend against this range of threats,

Dragos Acquires Phosphorus to Bring OT-Native <b>Cybersecurity</b> to the Full xOT Environment

Dragos expands to protect xOT including OT systems and the billions of connected devices that have reshaped how critical infrastructure operates HANOVER, Md., June 2, 2026 /PRNewswire/ -- Dragos, the global leader in cybersecurity for operational technology (OT) environments, today announced it has acquired Phosphorus, extending the Dragos Platform to protect the billions of connected devices embedded across critical infrastructure and other operational networks. Operational environments have outgrown traditional OT boundaries. Power grids, pipelines, manufacturing facilities, and data centers now depend on an increasingly diverse mix of connected devices and digital systems. Traditional and non-traditional assets alike are woven throughout their operational environments. This expanded environment - OT systems and the billions of connected devices that have reshaped how critical infrastructure operates - is the Extended Operational Technology environment, or xOT. Adversaries are already operating across it. Defenders need a broader scope of visibility, intelligence, and control to defend it.Dragos's acquisition of Phosphorus reflects a deliberate strategy to protect the full operational environment as it exists and operates today. Dragos offers the industry's most comprehensive OT cybersecurity platform. Adding Phosphorus extends Dragos capabilities to secure connected devices across the full xOT environment, delivering deeper device visibility, automated remediation, and continuous risk reduction. "The connected devices you find everywhere in critical infrastructure are largely invisible to the cybersecurity programs that protect operational environments," said Robert M. Lee, CEO and Co-Founder of Dragos. "With Phosphorus, we close that gap and secure xOT, the full environment that matters." "We built Phosphorus to solve the connected device problem - the unmanaged devices, the default credentials, the firmware no one was updating. Together with Dragos, we can solve it with a depth and scale that wasn't possible before. That's what the next generation of OT cybersecurity looks like," said Sonu Shankar, President and COO of

NSA selects new leads for key <b>cybersecurity</b> posts

NSA selects new leads for key cybersecurity posts The National Security Agency has selected a trio of digital security veterans to serve as the permanent leads of two of its major cybersecurity organizations, according to multiple people familiar with the matter. David Imbordino, an NSA senior executive who most recently led its cybersecurity directorate in an acting capacity, has been named as its new chief — the first since its previous boss retired roughly one year ago. Holly Baroody, one of the NSA’s senior officials in the United Kingdom and a former top civilian at U.S. Cyber Command, will serve as his deputy. Recorded Future News first reported earlier this year that the pair had been tapped to helm the outfit in acting roles. The agency also selected Bruce Jones, a career NSA technical and operational leader, as the new head of its Cybersecurity Collaboration Center, an unclassified hub where government and private sector experts exchange information about hacking threats, often in real time. NSA declined to comment. The appointments, which are expected to be announced publicly soon, come as the largest electronic spy agency in the world looks to rebound from one of the more chaotic years in its history. The NSA experienced an almost year-long leadership vacuum that included a string of high-level departures and saw thousands of career personnel exit after pressure from the Trump administration to slim down its workforce. Things have calmed since new leadership was installed atop the agency. Tim Kosiba, a former senior NSA, was appointed to the No. 2 spot in January. Army Gen. Joshua Rudd was confirmed in March to be the “dual-hat” leader of Cyber Command and NSA. The agency is also grappling to understand how it can best incorporate artificial intelligence into its own operations, as well as its

Anthropic gives EU <b>cybersecurity</b> agency ENISA access to Mythos AI

TL;DR Anthropic will give ENISA, the EU’s cybersecurity agency, access to its Mythos AI model through Project Glasswing, making it the first EU institution to access the system that discovered 10,000+ zero-day vulnerabilities. The decision ends weeks of contentious negotiations. Anthropic has agreed to give the European Union’s cybersecurity agency, ENISA, access to Claude Mythos, the AI model that has autonomously discovered more than 10,000 high- and critical-severity zero-day vulnerabilities across every major operating system and web browser. The decision, communicated to the European Commission over the weekend, makes ENISA the first EU institution to join Project Glasswing, Anthropic’s controlled-access cybersecurity initiative. The move ends a weeks-long standoff that had become one of the most visible flashpoints in the transatlantic AI relationship. Euro-area finance ministers, the European Central Bank, and multiple EU member states had demanded access after learning that Mythos had found vulnerabilities in systems that European banks, governments, and critical infrastructure providers rely on daily, while no European institution could see the findings. What Mythos can do Mythos is not a conventional cybersecurity tool. Launched in April 2026 as Claude Mythos Preview, the model can autonomously identify security flaws in complex codebases, generate working exploits on the first attempt in more than 83% of cases, and execute attack simulations that would traditionally require teams of human researchers working for months. In its first month inside Project Glasswing, the model discovered over 10,000 zero-day vulnerabilities across the world’s most critical software. Anthropic partnered with more than 50 major technology organisations, including Microsoft, Apple, Google, and Cloudflare, to deploy Mythos against highly targeted codebases. The model’s strength in cybersecurity is a direct result of its broader capability: an AI system that can deeply understand and modify complex software is also one that can find and fix its vulnerabilities. Until now,

Impact ICT Case Study

Most businesses start with clearly laid-out plans. Impact ICT took a more unorthodox path, starting with a car, driving to a handful of client meetings, and sharing a strong belief that community organizations deserved better technology support. Founded in Western Australia in 2021, Impact ICT serves not-for-profits and community-based institutions, including aged care providers and disability services. From the start, the managed service provider (MSP) wanted to do more than fix day-to-day IT issues. They wanted to help clients build environments that were scalable, manageable, and secure, taking more of the tech burden off their clients so they could focus on the people they serve. That belief shaped the business early. Impact ICT chose not to sell security in tiers or treat it like an add-on. “We only do one managed service product, which includes security,” says Tom, Director and Solutions Specialist at Impact ICT. Built to meet Australia’s Essential 8 Maturity Level 1, Impact ICT’s baseline makes strong security part of the standard from day one. But holding that line comes with pressure. Impact ICT supports hundreds of endpoints while also carrying the daily demands of managed services. And while they’ve grown quickly, they’re still a lean team of specialists. Tom puts it plainly, saying, “We don’t have someone who sits there doing security all day, every day.” That’s why Impact ICT needed a way to deliver serious protection without pretending a growing MSP could operate like a full-time security shop. They also needed vendors who’d act like real partners when something went wrong. Tom had little patience for the finger-pointing that often takes place with IT vendors. Huntress stood out because the relationship felt different. “When there’s a problem, Huntress isn’t saying, ‘Oh, that’s not our fault,’” he says. “It’s more like, ‘Let’s jump on a call and