No-frills tech news

China issues new financial data rules in major <b>cybersecurity</b> push

China issues new financial data rules in major cybersecurity push he rules do not apply to data involving state secrets or military information China has issued new financial data service rules in a pursuit to strengthen data security management, regulate industry development and expand cybersecurity push. These guidelines issued on Saturday will help classifying, protecting and grading financial information service data and all the service providers working within China would be obliged to follow these rules in compliance with national data security law, as stated by the Cyberspace Administration of China, the People’s Bank of China and four other regulators in a joint statement. According to the Cyberspace Administration of China, the data would be classified into four-tiers: Important, sensitive general and routine general-based on importance, sensitivity and the potential harm from leaks. Driven by a significant surge in data generation and frequent information flows, these measures establish a standardized framework designed to strengthen overall security and promote the lawful use of information. "Financial information services are developing in an orderly manner, and the volume of data is expanding ... which urgently requires standardised, classified and graded management," the guidelines said. However, The rules do not apply to data involving state secrets or military information. The core objectives of these rules are to protect sensitive information and support broader national efforts to secure data processing within the financial sector. These guidelines also requires firms and companies to: - Conduct thorough data inventories - Systematically classify all managed data - Maintain record in form of upgraded classification lists - Making reports on catalogues of important data for regulatory oversight - Trump claims Iran deal is better than Obama's as signing nears - FBI built 22,000-sq-ft town to train cyber investigators - Trump’s White House cage match plan fails to win over

Strengthening <b>cybersecurity</b> cooperation between Iran and BRICS members

Strengthening cybersecurity cooperation between Iran and BRICS members Pars Today – An Iranian official from the Information Technology Organization participated in a BRICS cybersecurity meeting and outlined Iran’s capabilities in cybersecurity as well as solutions for countering emerging threats. According to Pars Today, citing IRIB News Agency, the 12th working group meeting of BRICS member states on Information and Communication Technology (ICT) security was held in New Delhi, India. Representatives of member countries exchanged views on strengthening cybersecurity, developing technical cooperation, and countering emerging threats in the digital space. Hossein Momeni, Deputy Head of the Information Technology Organization of Iran and head of the Iranian delegation, attended the meeting and presented Iran’s perspectives, experiences, and capabilities in the field of ICT security. Participants in the meeting emphasized the need to enhance security in the use of information and communication technologies, stressing the importance of countering the criminal exploitation of emerging technologies. Members also highlighted the development of a secure, stable, peaceful, and interoperable environment in the field of information and communication technologies as one of the key objectives of joint cooperation among member states. At the conclusion of the session, the working group members underscored the importance of expanding joint research, establishing mechanisms for academic and research exchange, and strengthening the capacity of computer emergency response teams to manage emerging challenges in ICT security. They also agreed on the importance of enhancing cooperation between academic institutions and research centers of BRICS member countries in order to reduce skill gaps, facilitate knowledge transfer, provide technical assistance, and build a resilient and sustainable digital ecosystem.

Statement on the US government directive to suspend access to Fable 5 and Mythos 5

Statement on the US government directive to suspend access to Fable 5 and Mythos 5 The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees. The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance. Access to all other Anthropic models will not be affected. We received the directive from the government today at 5:21pm (ET). The letter did not provide specific details of its national security concern. Our understanding is that the government believes it has become aware of a method of bypassing, or “jailbreaking” Fable 5. We reviewed a demonstration of this specific technique being used to identify a small number of previously known, minor vulnerabilities. These vulnerabilities all appear relatively simple, and we have found that other publicly-available models are able to discover them as well without requiring a bypass. Anthropic’s posture with respect to Fable’s safeguards, as laid out in our launch blog post, is the following: - We have instituted strong safeguards that greatly reduce the likelihood that Fable is misused for tasks related to cybersecurity (among others). In fact, our safeguards are so strong that many users have complained that they are overly broad. - In the weeks leading up to the launch of Fable, Anthropic worked with the US government, the UK AISI, multiple private third-party organizations and internal teams to red-team Fable’s safeguards for thousands of hours in total. - These tests showed that Fable’s safeguards are substantially more effective than those of any previously deployed model. - No testers have yet been able to find a universal jailbreak—a

The hidden challenge behind executive impersonation

In 2024, an employee at engineering firm Arup joined what appeared to be a routine video call with company colleagues, including the CFO. Everyone on the call looked and sounded right. They weren’t. The entire meeting had been fabricated using AI-generated deepfakes, and by the end of it, the employee had authorized a transfer of £20 million to criminals. The Arup case made headlines, but it represents a much broader pattern. According to the US Federal Trade Commission, imposter scams resulted in nearly $3 billion in reported losses in 2024 alone, making it the second-highest loss category of any fraud type. AI tools have made convincing impersonations cheaper and faster to produce, placing them within reach of a far wider range of threat actors than ever before. Attacks that once required technical expertise are now a commodity. The question organizations face is no longer whether executive impersonation is a serious threat. It is. The question is whether their current approach to detecting and responding to it is actually fit for purpose. The scale problem Security teams typically approach executive impersonation as a detection challenge: find the fake content, take it down. That framing isn’t wrong, but it’s incomplete. The harder problem is maintaining consistent visibility across all the platforms and content types where impersonation can occur. A senior executive may appear across dozens of platforms under multiple name variations, job titles, and usernames. Each of those represents a surface that threat actors can exploit. Multiply that across an entire executive team and the monitoring challenge becomes an operational one, requiring a proactive, joined-up approach rather than reactive case management. The volume problem compounds quickly. Extending monitoring to match the actual scale of the threat generates more signals, which means more alerts, a significant proportion of which will be false positives.

Onslow County Schools hit by <b>cybersecurity</b> crime; law enforcement involved

Onslow County Schools hit by cybersecurity crime; law enforcement involved A cybersecurity crime is currently under investigation involving Onslow County Schools. According to OCS officials, they recently became the victim of a cybersecurity crime that is currently under active investigation by their Information Technology staff in coordination with local, state, and federal law enforcement authorities. BE THE FIRST TO COMMENT OCS officials say they are working diligently to investigate this incident and to protect the privacy of our students and staff. For the most current updates, click here.

Anthropic's safety warnings may have just backfired — the government has pulled the plug ...

The U.S. government on Friday ordered Anthropic to immediately shut off access to two of its most powerful AI models — Claude Fable 5 and Claude Mythos 5 — citing national security concerns. Anthropic announced on X that it has complied, but it made clear it thinks the government got this one wrong. The directive, which Anthropic said it received on Friday at 5:21 pm ET, forces the company to disable both models for all users worldwide — not just the foreign nationals the government’s export control order was nominally aimed at. Access to Anthropic’s other models isn’t affected. Why does any of this matter? Mythos is Anthropic’s most capable AI model, one the company previewed in early April and has kept tightly restricted ever since because of what Anthropic described as its exceptional ability to find security vulnerabilities in software. According to Anthropic, Mythos identified flaws in every major operating system and web browser it tested, so rather than release it broadly, the company launched a controlled program called Project Glasswing, sharing it with roughly 50 vetted organizations, including Amazon, Apple, Google, Microsoft, and CrowdStrike, to use for defensive cybersecurity work. Fable 5, released just three days ago, was Anthropic’s answer to the obvious commercial pressure: a version of Mythos fitted with guardrails that block responses in high-risk areas like cybersecurity and biology, making it safe enough for general release, the company argued. It was immediately the most capable AI model available to the public, according to benchmark tests from Vals AI, a company that tracks AI tech performance. The government’s directive is framed as an export control action, restricting foreign national access to the models. But in a lengthy blog post, Anthropic says its understanding is that the underlying concern is a claimed jailbreak of Fable 5. So

The FBI built its own replica small town to simulate real-world cyberattacks | TechCrunch

The Federal Bureau of Investigation is pulling back the curtain on a 22,000 square-foot replica town on its Huntsville, Alabama campus that it built to train law enforcement in simulating and investigating real-world cyberattacks. The aim is to teach investigators in a secure environment beyond the classroom by getting hands-on with some of the latest consumer and enterprise technologies, many of which are frequently targeted by malicious hackers. The numbers put the training into context. The FBI’s 2025 Internet Crime Report, drawing on more than one million complaints, logged a record $20.9 billion in U.S. cybercrime losses, a 26% jump over the prior year, with ransomware ranked the top ongoing threat to critical infrastructure. Dubbed the Kinetic Cyber Range, the FBI’s small purpose-built town opened in February 2025 and features fully furnished houses, a hotel, a gas station and grocery mart, a courthouse, a hospital, and a power company — complete with roads and traffic lights — designed to mimic a real U.S. community. Since opening, says the agency, the facility has trained more than 1,400 students, including FBI personnel and partners from other federal and local agencies. Each part of the town is wired with functioning devices and systems that behave as they would in a real community or business, while preventing any simulated attacks from spilling out of the facility. The range also includes a data center with more than 200 physical servers — some running Windows, some Linux — reflecting the corporate environments investigators are likely to encounter when responding to a breach or executing a search warrant. “They’re cold, they’re cramped, they’re noisy, they’re dark, they’re miserable,” Dave Beachboard, the range’s program manager, explains in the FBI’s write-up about the training environment. The replica town also allows the FBI to simulate ransomware attacks and their real-world

OSBI probing <b>cybersecurity</b> breach in Mountain Park

MOUNTAIN PARK — The Oklahoma State Bureau of Investigation is probing a recent cybersecurity breach that affected the town of Mountain Park’s computer systems. Town officials sought the OSBI’s investigative assistance May 11 after discovering that someone had hacked into the town’s administrative computer, Town Clerk/Treasurer Shawn Norman said in a phone interview. “Somebody from the community came in and had copies of our emails and showed us and said, ‘You guys have been hacked. Somebody’s got your emails. They’re spread all over town,’” she said. Whoever committed the breach only had access to the town’s administrative computer system, and the Public Works Authority computer for billing was not affected, Norman said. She said that was a relief because officials did not have to worry that residents’ personal information had been released. Norman said it was unclear whether any sensitive data had been leaked as a result of the breach. She said the town immediately went online after discovering the breach, and officials took steps to better protect the town’s systems. “We switched internet providers, and then we went and switched all of our codes and passwords,” she said. Norman said officials are planning to hire an information technology staffer who can help protect the town against future breaches. OSBI spokesman Hunter McKee confirmed that the Mountain Park Police Department asked the state agency to investigate a possible violation of the state’s computer crimes law within the town. Eric Swanson is an award-winning journalist with more than 20 years’ experience covering local government and criminal justice in Oklahoma, North Dakota and Kansas. He can be reached at eric.swanson@swoknews.com.

WISeKey Deployments Expand Low-Earth Orbit <b>Cybersecurity</b> Constellation via SpaceX Rideshare

Cybersecurity and digital identity conglomerate WISeKey International Holding Ltd has finalized the orbital insertion of its WISeSat 4.0 satellite, marking the 21st spacecraft deployed by its space-technology subsidiary, WISeSat.Space Corp. Transported from Vandenberg Space Force Base in California, the payload was launched into low-Earth orbit (LEO) as part of SpaceX’s Transporter-16 rideshare mission. The operation forms part of a systematic infrastructure renewal strategy designed to account for the typical five-year operational lifespan of LEO units, allowing the group to cycle updated hardware configurations into its active satellite network throughout 2026 and 2027. The QS7001 Cryptographic Integration and Space-Based Wallet Topologies The WISeSat 4.0 orbital platform serves as a physical verification environment for converged security hardware developed by WISeKey’s semiconductor subsidiary, SEALSQ Corp. The satellite payload integrates a cryptographic QS7001 secure microcontroller chip directly alongside WISeKey’s hardware-embedded Root of Trust (RoT). This configuration is engineered to execute post-quantum cryptography (PQC) protocols, isolating data streams from future decryption threats across high-risk industrial infrastructure sectors, including defense networks, energy grids, and transnational logistics pathways. Furthermore, the localized processing architecture supports the phased deployment of decentralized SEALCOIN.AI digital wallets, establishing an on-orbit settlement layer to process machine-to-machine (M2M) economic transactions and secure device-to-device (D2D) data tokenization routines without requiring terrestrial routing relays. Decentralized Layer Division: Infrastructure Hosting and Cloud Services The deployment advances the systemic architecture of the Quantum Spatial Orbital Cloud (QSOC), a programmatic initiative aimed at scaling an independent, 100-satellite sovereign security network by 2033. To manage this infrastructure at scale, WISeKey implements a commercial asset division modeled after land-based hyperscale colocation data centers. Under this framework, WISeSat functions strictly as the physical capacity and infrastructure provider, engineering the satellite bus configurations, securing launch manifests, and operating the ground-station communication networks. Conversely, SEALSQ operates as the independent cloud services layer on top

Perry adds <b>cybersecurity</b> prof to assist in complex cases

Perry adds cybersecurity prof to assist in complex cases A professor of cybersecurity at Washington State College of Ohio will be assisting Perry Forensic on complex fraud investigations, the company announced. Professor Jennifer Marie DeMeyer brings a combination of real-world investigative experience, digital forensics expertise and academic leadership to the field of cybersecurity education, Jodey Altier, president of Perry & Associates CPA’s A.C. and managing partner of Perry Forensic, said. Born in Missouri and raised in a military family, DeMeyer completed high school at Osbourn Park High School where she was an active student-athlete, playing basketball and earning recognition for her performance on and off the court. She continued her academic and athletic career at University of Charleston where she played basketball while completing two bachelor’s degrees, a bachelor of arts in visual art and a bachelor of science in public policy. The academic background laid the foundation for her ability to bridge technical cybersecurity knowledge with legal and policy-based perspectives, the company said. Following her undergraduate education, DeMeyer served 17 years in the West Virginia State Police where she specialized in investigations of crimes against children and internet crimes against children. During her tenure, she became a digital forensic examiner, earning certifications and hands-on expertise using industry-leading tools such as Magnet AXIOM and Cellebrite technologies. Her investigative career included complex federal-level prosecutions such as Timothy Sean Coogle v. United States and Kenneth Stier v. United States and significant regional cases involving sexual exploitation and abuse. Her work also extended to high-profile local investigations, including cases involving a Parkersburg YMCA swim coach and five juvenile female swimmers and an adult male in Wirt County who was charged with more than 50 felony sexual assault and abuse charges. DeMeyer obtained her master’s of science in criminal justice and cybersecurity from Liberty

JSE says personal information affected in <b>cybersecurity</b> incident

JSE says personal information affected in cybersecurity incident KINGSTON, Jamaica – The Jamaica Stock Exchange says some personal information was affected in a cybersecurity incident that has been contained, but says it has found no evidence that its trading or settlement platforms were compromised. In a notice to the public, the JSE said the incident was recently identified and contained, and that an investigation confirmed that some data was accessed without authorisation. “Based on our investigation to date, we have not identified evidence that the incident affected our trading or settlement platforms, customer login credentials or our core transactional systems,” the JSE said. The exchange said it has reported the matter to the relevant authorities and is contacting affected individuals directly with specific guidance. The notice did not say how many people were affected, what type of personal information was accessed, when the incident occurred, or whether the unauthorised access involved internal systems, third-party service providers, or both. The JSE advised members of the public to be alert for attempted fraud, stressing that it will never ask for passwords, PINs or one-time codes by email or telephone. “Treat any such request as fraudulent,” the exchange said. Individuals with questions have been directed to contact the JSE’s Data Protection Officer by email at dpo@designprivacy.io or by telephone at 876-218-1815. The incident comes as financial institutions and market infrastructure operators globally face growing pressure to strengthen cybersecurity controls, given the sensitivity of the information they hold and the potential consequences of disruption to financial markets. For now, the JSE is maintaining that the breach affected personal information, but not the systems used to trade or settle securities.

Loudoun Students Organize <b>Cybersecurity</b> Summit, Contest | Education | loudounnow.com

A group of Loudoun County Public School students organized two cyber-based events this semester that they hope will become annual gathering places for area students interested in computer science and cybersecurity. The two events, CyberSummit and IndyHax, were held at Independence High School in May and June. IndyHax, a combined hackathon and cybersecurity competition, asked students to complete challenges and build projects based on a prompt to compete for points and win prizes, according to Lalith, one of the student organizers. Tarushv, another student leader, said the event drew students from around Loudoun County as well as Chantilly High School and Thomas Jefferson High School for Science and Technology, both in Fairfax County. 2026 is the inaugural year for both events. Tarushv said the events were “pretty well-received” and that students, parents, and professionals in the industry have thanked them for organizing these types of events, which the students said are much more uncommon for high schoolers than college students and professionals. Lalith said the prizes in this event set it apart from many high school events. Technical expertise was not the most important thing for participants, he said. “We were looking for people who know how to innovate. We were looking for people who know how to change the world,” he said. Projects developed in response to the prompts included games, apps, and other programs. One project that organizers gave as an example was a program that pulled from Washington DC crime statistics to create a map of the city showing which areas were safe and which were more dangerous. The group of students who created that program were inspired to do so after being followed by suspicious individuals while in Washington, and Tarushv said that shows that they recognized a problem and wanted to fix it. Of course,

National Security Presidential Memorandum/NSPM-12

MEMORANDUM FOR THE VICE PRESIDENT THE SECRETARY OF STATE THE SECRETARY OF THE TREASURY THE SECRETARY OF WAR THE ATTORNEY GENERAL THE SECRETARY OF THE INTERIOR THE SECRETARY OF AGRICULTURE THE SECRETARY OF COMMERCE THE SECRETARY OF LABOR THE SECRETARY OF HEALTH AND HUMAN SERVICES THE SECRETARY OF HOUSING AND URBAN DEVELOPMENT THE SECRETARY OF TRANSPORTATION THE SECRETARY OF ENERGY THE SECRETARY OF EDUCATION THE SECRETARY OF VETERANS AFFAIRS THE SECRETARY OF HOMELAND SECURITY THE WHITE HOUSE CHIEF OF STAFF THE DEPUTY CHIEF OF STAFF FOR POLICY AND HOMELAND SECURITY ADVISOR THE DIRECTOR OF THE OFFICE OF MANAGEMENT AND BUDGET THE DIRECTOR OF NATIONAL INTELLIGENCE THE ASSISTANT TO THE PRESIDENT FOR SCIENCE AND TECHNOLOGY THE ASSISTANT TO THE PRESIDENT FOR NATIONAL SECURITY AFFAIRS THE ASSISTANT TO THE PRESIDENT AND COUNSEL TO THE PRESIDENT THE CHAIRMAN OF THE JOINT CHIEFS OF STAFF THE DIRECTOR OF THE CENTRAL INTELLIGENCE AGENCY THE DIRECTOR OF THE NATIONAL SECURITY AGENCY THE ADMINISTRATOR OF GENERAL SERVICES THE NATIONAL CYBER DIRECTOR THE DIRECTOR OF THE CYBERSECURITY AND INFRASTRUCTURE SECURITY AGENCY SUBJECT: National Policy for the Cybersecurity of National Security Systems As President, it is my priority to ensure that the United States can conduct key military and intelligence missions in contested cyber environments and that our personnel have access to the modern, secure technology they need to accomplish these missions. The Department of War (DOW), Intelligence Community (IC), and Federal Civilian Executive Branch (FCEB) Agencies own or operate this technology as National Security Systems (NSS). It shall be the policy of the United States Government that these systems be defended to the greatest extent practicable and that executive department and agency (agency) heads be accountable for this defense through government-wide oversight mechanisms. Therefore, by the authority vested in me by the Constitution and the laws of the

Marshall's <b>cybersecurity</b> students receive top scores in national competition

The team, guided by Dr. Paulus Wahjudi, professor of computer science, competed against students from colleges and universities across the country in challenges designed to test skills commonly required in today’s cybersecurity workforce. Each year, more than 10,000 students from high schools, colleges and universities participate in the NCL competition. Marshall’s performance also placed the university first among participating Sun Belt Conference schools and second among West Virginia schools competing in the event. Wahjudi says this team’s performance was superior, demonstrating their talent, dedication and teamwork. The National Cyber League presents challenges that mirror real-world cybersecurity tasks, and our students competed at a very high level against teams from across the country,” Wahjudi said. “Their performance reflects the strength of Marshall’s cybersecurity program and the hard work they have invested in developing practical security skills.” Student Thomas Neal earned the highest individual ranking among Marshall participants, placing 187th out of 7,006 competitors nationwide. Marshall team members who participated in the team challenge are Kendra Adkins, Brandon Anderson, Colton Gebhard, Bethany Ledford, William Matusic, Ethan Scott and Connor Stonestreet. “The success of our students in the National Cyber League reflects the hands-on, mission-focused education we provide,” said Alex Donathan, executive director of Marshall’s Institute for Cyber Security. “We are incredibly proud of these students and this team, and grateful for the leadership and mentorship of Dr. Wahjudi, whose support has helped guide our students’ success. Their achievements demonstrate the skills and readiness our graduates bring to the cybersecurity workforce.” More information about Marshall’s cybersecurity programs and initiatives is available at www.marshall.edu/cyber.

Coding camp in Augusta teaches kids <b>cybersecurity</b> skills

Coding camp in Augusta teaches kids cybersecurity skills AUGUSTA, Ga. (WRDW/WAGT) - A coding camp in Augusta is getting local kids excited about cybersecurity. Kids in grades 4 through 8 are learning about the industry and getting hands-on experience. A professor from Augusta University’s School of Computer and Cyber Sciences is one of their teachers. He says they learn computational thinking, ciphers, encryption and coding. They use those skills to code a robotic car platform that they can fully control. “A lot of times with cybersecurity or computer science, everything is just a keyboard and a screen. But with the micro bit and the cute bot, they can actually see what they’re programming. It goes into action,” said Michael Nowatkowski, School of Computer and Cyber Sciences professor. He says he hopes this camp engages these kids and shows them all the opportunities that lie ahead with these skills. Copyright 2026 WRDW/WAGT. All rights reserved.

VIDEO: Google sues <b>cybersecurity</b> group over scams – KIRO 7 News Seattle

Sections WATCH 65 ° WATCH News PinPoint Weather Stream Now KIRO 7 Investigates Sports Gets Real KIRO 7 Cares (Opens in new window) Steals & Deals News National Politics PinPoint Weather 7-Day Forecast Hour by Hour Ski Report School Closings Pet Walk Forecast Weather 24/7 Stream Stream Now Live Stream KIRO 24/7 News Weather 24/7 KIRO 7 Live Studio (Opens in new window) Recent Videos Raw Video Law & Crime Gusto TV KIRO 7 Investigates Sports Seattle Seahawks Seattle Mariners Seattle Kraken Seattle Sounders Seattle Storm College Sports High School Football On Home Ice Special Programming Seattle Pride Christmas in July Seattle Seafair Hit and Miss with Monique Ming Laven KIRO 7 Toy Drive Destination Discover Healthier Together Discover Northwest Woodland Park Zoo (Opens in new window) Your Voices KIRO 7 CARES Seattle Aquarium Washington Grown Seattle Waterfront Local Jobs Back to School Steals and Deals Gets Real Live Traffic Apps & Newsletters KIRO 7 Apps Newsletter Sign-ups (Opens in new window) About Us KIRO 7 News Team Submit a news tip KIRO 7 TV Schedule Advertise With Us Contact Us Closed Captioning KIRO 7 FCC EEO Report (Opens in new window) KIRO 7 Public File (Opens in new window) Visitor Agreement Privacy Policy Telemundo Seattle (Opens in new window) Telemundo Contactanos Jobs at KIRO 7 (Opens in new window) KIRO 7 Now Resize: Drag to Resize Video Live Streams KIRO 7 Now KIRO 24/7 News KIRO Weather 24/7 StreamAmerica™ Inside look at law enforcement & true crime Your one-stop shop for delicious dishes Latest Local Videos VIDEO: Puyallup Tribe of Indians recognized by Fifa in historic first VIDEO: World Cup nuclear search team VIDEO: Beating the backups around UW Commencement VIDEO: First look at Seattle Soccer House for the World Cup VIDEO: Voice of the Seattle Sounders, Pete Fewing,

Fact Sheet: President Donald J. Trump Defends America's Warfighters and Intelligence ...

Fact Sheet: President Donald J. Trump Defends America’s Warfighters and Intelligence Officers Against Cyber Threats PROTECTING CRITICAL MILITARY AND INTELLIGENCE MISSIONS: Today, President Donald J. Trump signed a National Security Presidential Memorandum to bolster the cybersecurity of America’s National Security Systems (NSS) and modernize NSS governance to meet the cyber challenges of 2026 and beyond. - NSS encompasses the US’s most sensitive computer systems – those that process classified information or support military and intelligence missions. - The Memorandum establishes a clear structure, authorities, roles, and responsibilities for the governance of NSS and accountability to NSS cybersecurity requirements for its owners and operators. - The Memorandum helps ensure that NSS owned or operated by civilian agencies receive a defense commensurate to those of the Department or War (DOW) and Intelligence Community (IC). - The Memorandum reestablishes the Committee on National Security Systems (CNSS) and modernizes it for the first time in over 35 years to establish baseline cybersecurity requirements for all NSS and enhance accountability and coordination across agencies to implement necessary cyber defenses across all NSS. - The CNSS will oversee the cybersecurity of NSS across the US Government and issue binding security directives to all NSS owners and operators. - The CNSS will provide collaboration, standardization, and efficient resource management by promoting coordination and information sharing across Federal agencies, public-private partnerships, and international liaison activities. - The CNSS will leverage the combined authorities and resources of the Federal Chief Information Officer, the Chief Information Officers of the DOW and IC, and the Director of the National Security Agency (NSA) to ensure that there are no gaps or weak links in NSS defenses. - The Memorandum empowers the Director of the National Security Agency as the National Manager for National Security Systems and the cryptologic authority of NSS. It

NexusTek Announces Construction Industry Solutions to Address Growing IT and ...

DENVER, June 12, 2026 /PRNewswire/ -- NexusTek, a leading provider of AI, infrastructure, and security solutions, today announced a focused set of construction industry solutions designed to help firms address rising IT complexity, cybersecurity exposure, and operational demands across job sites, offices, and remote teams. As construction firms navigate expanding cloud and BIM environments, mobile field operations, AI-enabled workflows, and rising cyber risk across distributed teams, NexusTek has aligned its services to support heavy and civil contractors, general contractors, construction managers, and specialty trades. "Construction firms need technology that supports the pace and pressure of their industry," said Hamilton Yu, Chief Executive Officer at NexusTek. "Our new offerings reflect where we are helping construction customers keep systems available, reduce disruption, strengthen security posture, and build a scalable technology foundation that supports long-term growth." NexusTek construction solutions span four core areas: - Cloud services deliver secure, reliable system access across field, office, and remote locations through private cloud, hybrid cloud, and virtual desktop solutions that improve availability and reduce infrastructure risk. - Cybersecurity and compliance services reduce ransomware, payment fraud, and third-party access risk through layered protection and documented controls aligned to CMMC and NIST requirements for federal and regulated work. - IT operations services replace reactive support with a stable, fully managed operating model. 24/7 service desk, onsite engineering, infrastructure monitoring, disaster recovery, co-managed IT, and vCIO guidance keep systems reliable and aligned to growth. - Data and AI services help firms turn operational data into measurable advantage. NexusTek assesses AI readiness, deploys AI in a governed environment, and builds analytics capabilities that improve reporting, forecasting, and decision-making. All construction engagements run on NexusOps, NexusTek's service delivery platform, with NexusIQ providing AI-driven triage, routing, and communications—delivering 97% triage accuracy, 90% faster root cause identification, and 78% faster status updates. Recent

China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade

Instead of hiding on the laptops and servers defenders watch most closely, a China-nexus group spent close to a decade hidden inside the Linux login system itself. Sygnia, which tracks the group as Velvet Ant, says it backdoored the PAM and OpenSSH components that decide who is allowed to sign in, planting its access where ordinary cleanup could not reach it. The network it targeted had no direct internet access, so the group first staged through internet-facing systems to get there. The earliest traces go back to 2016. Instead of dropping new malware that a scanner might catch, the attacker changed the trusted login programs themselves. Nothing obvious appeared, and no exploit was needed, so the activity looked like normal administration. On many machines, the attacker replaced the main PAM login module with backdoored copies. Some let them in with a secret password; others quietly recorded real usernames and passwords as people logged in. Researchers found nine separate versions. The OpenSSH programs were altered the same way, logging credentials and every command typed, with a hidden switch to turn that logging off when needed. Reaching the isolated network at all took extra work. The attacker used other disguised tools and an internet-facing web server as a bridge, passing commands through it to open remote sessions deep inside the segment that had no direct internet access. Because the login system itself was compromised, normal containment did little. Password resets and killed sessions do not help when the thing that checks those credentials is working for the attacker. This is not new for the group. Each time defenders find one foothold, Velvet Ant moves to gear they watch less and sets up there. In a 2024 case, Sygnia found the same actor turning internet-exposed F5 BIG-IP appliances into internal command servers. Later