CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD 22-01. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV catalog? Submit for potential addition: KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. This product is provided subject to this Notification and this Privacy & Use policy.
Jun 12, 2026 · via cisa.gov
Join Us for an Exclusive Webinar: AI, Cybersecurity, and the Decisions You Cannot Defer Date: Jul 7, 2026 Time: 2:00 pm EDT Join us for a critical webinar presenting findings from The Oasis Group's April 2026 CTO Think Tank in Nashville - where CTOs and COOs from RIAs managing over $1 billion in AUM discussed AI deployment and cybersecurity threats facing wealth management firms. This webinar reveals what peer technology leaders are experiencing as they navigate AI vendor claims, deploy agentic automation, and respond to evolving threats that have breached four of the top ten RIAs. Key Topics Include: • Separating AI Reality from AI Washing: How to identify vendors with true AI capability versus rebranded tools • Agentic AI in Production: Real deployments automating compliance workflows - including one firm supporting nearly $10 billion AUM with three investment team members • Fourth-Party Risk and Recent Breaches: The Salesloft/Drift breach exposing 700+ Salesforce environments and vendor due diligence gaps most firms haven't closed • Reg SP's 72-Hour Notification: What the December 2025 deadline demands and why most firms cannot detect breaches within that window • Critical Security Controls: Why standard MFA is insufficient and the phishing-resistant authentication policies that separate prepared firms from exposed ones The firms that acted on these observations twelve months ago are building a lead that grows with every quarter you defer. Close the decision gap before the next incident makes the decision for you. CIMA®, CPWA®, CIMC®, RMA®, and AEP® CE Credits have been applied for and are pending approval. Get more information on CE Credits here. Sponsored by Orion Speakers
Jun 12, 2026 · via wealthmanagement.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Jun 12, 2026 · via youtube.com
| Cybersecurity, tech ETFs strongest performers in MayBY RIDDHIMA TALWANI | FRIDAY, 12 JUN 2026 12:50PMETF performance in May was dominated by cybersecurity and broader technology themes, with the sector delivering exceptional returns across multiple strategies. While the Global X Cybersecurity ETF returned 36.5% for investors, Betashares Global Cybersecurity ETF provided a return of 31.75%. South Korea retained its place from the prior month, continuing to reflect strong investor interest in the region's technology-heavy market. iShares MSCI South Korea Capped Index ETF returned investors 31.6% for the month. Asian technology exposure also featured, reinforcing a broader theme of outperformance across innovation-driven, high-growth equities. ETF flows in May were broadly in line with April at $5.3 billion. Australian equities claimed the top spot for the month at $2.24 billion, narrowly ahead of international equities at $2.18 billion. Cash & fixed income fell sharply to $494 million from $1.1 billion in April. Short exposures swung back into negative territory, and commodities returned to positive flows after April's outflow. "Global equity markets extended their rally through May. S&P 500 companies reported 27% year-on-year earnings growth in Q1 2026, more than double consensus, driven by the hyperscaler capex cycle," Betashares investment strategist Tom Wickenden said. "Emerging markets were a standout, the MSCI EM index rose 9.7% as investors rotated into Asian chip manufacturers as a higher-beta, cheaper alternative to US mega-cap tech. Korea and Taiwan were the principal beneficiaries. Asian technology and broad emerging market ETFs capture this exposure on the ASX." The Australian ETF industry set a new record, reaching $364 billion in funds under management after a third consecutive month of net flows above $5 billion. Strong inflows, combined with positive global market performance, pushed the industry above $350 billion for the first time. "Domestically, the 12 May federal budget was the
Jun 12, 2026 · via financialstandard.com.au
OT security governance has been moving toward the C-suite for four years, but the pace accelerated sharply. Fortinet’s 2026 State of Operational Technology and Cybersecurity Report finds 53% of industrial organizations now place OT cybersecurity under the Chief Information Security Officer (CISO) or Chief Security Officer (CSO), up from 16% in 2022. A global survey of over 700 OT professionals sits underneath that number, and the full picture is more complicated than the governance headline suggests. - The governance shift is real, but maturity self-assessments have corrected downward sharply: organizations at the highest maturity level (level 4) dropped from 49% to 17% in a single year. - Intrusions are more visible, not necessarily more frequent: 71% of respondents reported one to nine attacks, up from 47%, with Fortinet attributing much of the jump to improved detection rather than a true volume increase. - Cost reduction displaced risk reduction as the top cybersecurity performance metric in 2026, surfacing a governance tension the report does not fully resolve. - 89% of respondents expect new OT regulation within five years, up sharply from 66% in 2025, and four in five organizations intend to bring OT security under CISO oversight within the next 12 months. OT Cybersecurity Under CISO: Why the Level 4 Maturity Drop Changes the Story Richard Springer, senior director for marketing OT solutions at Fortinet, wrote in a blog post alongside the report. He noted that industrial organizations now rely on interconnected systems, remote access, cloud-based analytics, and unified IT and OT environments to maintain production. “While this advanced connectivity offers increased efficiency and resilience,” Springer wrote, “it has enlarged the attack surface for cybercriminals, ransomware groups, and nation-state actors.” The 53% CISO ownership figure is the headline, but the maturity-score recalibration is the operationally consequential finding. Level 4 respondents fell
Jun 12, 2026 · via cybersecurity-insiders.com
Many cybersecurity teams are struggling to keep up with emerging technologies and the challenges around securing their organizations against them because they don’t have the time to undertake the necessary training, a new study has warned. The research, published by ISC2, asked nearly 1000 cybersecurity leaders from large enterprises around the world how their organization approach cybersecurity team training. Nearly three-quarters of respondents (73%) said their organization’s security training budget has increased over the past year, as businesses react to the emergence of new technologies and cybersecurity challenges that accompany them. One of the most encountered new challenges is the rise of AI: almost half of respondents (47%) said that AI is the most pressing skill their organization is addressing or planning to address through training. However, the study found that despite increased resources, organizations experience barriers around supplying training and upskilling to cybersecurity staff. Much of this is related to the time employees have available to engage with training. Nearly all security leaders surveyed (98%) said that their organization allows employees to engage with professional development and training during work hours. Despite this, just over half of respondents (53%) said that they face challenges which prevented them from engaging with training and professional development during the working day. The Struggle to Find Time for Cybersecurity Training Even if organizations support training, the practical realities of day-to-day work often make it difficult for employees to set aside dedicated time to participate in training during standard working hours. According to those surveyed, other challenges which create barriers to training include keeping training content current and relevant (45%), difficulty finding qualified trainers (39%), a lack of employee willingness to participate in training (37%) as well as a lack of support from leadership or other stakeholders (32%). While budgets for training have increased
Jun 12, 2026 · via infosecurity-magazine.com
A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis). According to a detailed report published by PRODAFT, the group, which it tracks as Phantom Mantis, is led by a Russian-speaking cybercriminal it calls LARVA-368, who goes by the online aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte. The Gentlemen is known to be active since March 2025, claiming a total of 478 victims to date, per data from Ransomware.Live. "In July 2025, Phantom Mantis transitioned into The Gentlemen, an independent partnership program no longer dependent on other RaaS groups," the Swiss cybersecurity company said. "Additionally, LARVA-368 relies heavily on artificial intelligence for the development and maintenance of ransomware and tools, as well as for assistance with post-exploitation procedures." As for LARVA-368, the threat actor is assessed to have been a member of the Embargo (aka Primeval Mantis) ransomware group before launching their own operation under the name ArmCorp. It was subsequently rebranded to The Gentlemen four months later. The individual's identity has since been outed by cybersecurity journalist Brian Krebs as a 36-year-old Alexander Andreevich Yapaev (Япаев Алексанр Андреевич) from the Russian city of Izhevsk. PRODAFT told The Hacker News that its findings match the same persona with "high confidence." As detailed by Dark Atlas in August 2025, the shift coincided with a payment dispute between LARVA-368 and Qilin, with the threat actor accusing the RaaS operation of carrying out an exit scam and defrauding them of $48,000. "Although Phantom Mantis was a very active affiliate group with over 20 targets registered on its affiliate panel in less than 30 days, the
Jun 11, 2026 · via thehackernews.com
Two security teams have shown, in separate research published this week, that OpenClaw, the popular self-hosted AI agent, can be driven to run attacker-controlled code or hand over sensitive data through ordinary-looking inputs. Imperva buried instructions inside shared contacts, vCards, and location pins that the agent executed without the victim ever seeing them. Varonis built a test agent on the platform, gave it a mailbox full of synthetic business data, and watched a single plain email talk it into forwarding mock AWS keys and a fake customer export to an outside address. The flaw Imperva found is patched in OpenClaw 2026.4.23, so update if you run it. The phishing weakness Varonis found is not something a patch fixes; it comes down to limiting what the agent can do on its own. Different doors into the same room: the agent trusts what reaches it, and its access becomes the attacker's. Hidden commands in a shared contact Imperva researcher Yohann Sillam looked at how OpenClaw hands messaging data to the model behind it. The problem is in the plumbing. When the agent passes a shared contact, vCard, or location to the LLM, it flattens the object into the prompt text inline, with no boundary marking it as untrusted. The content the agent fetches from the web gets wrapped in an untrusted-content marker. Message objects do not. Only some fields travel to the model, and that is what the attack abuses. A shared contact sends just the name field, serialized as <contact: name, number>. The angle brackets are legal in a name, so the model cannot tell where the real name ends and an injected instruction begins. The contact name is truncated where it shows on screen, both on WhatsApp and in the receiving app, so the victim does not see the payload
Jun 11, 2026 · via thehackernews.com
06/11/2026 By Naser Al-Ayyoub The Department of Finance at the Manning School of Business invites you to attend a doctoral dissertation defense by Naser Al-Ayyoub on “Three Essays on Governance, Risk, and Product Market Dynamics.” Candidate Name: Naser Al-Ayyoub Degree: Doctoral Defense Date: Friday, June 26, 2026 Time: 10 a.m.-noon Location: Zoom. Those interested in attending should contact the student Naser_Alayyoub@student.uml.edu at least 24 hours prior to the defense to request access to the meeting. Thesis/Dissertation Title: Three Essays on Governance, Risk, and Product Market Dynamics Committee members: - Hieu Phan (Chair), Ph.D., Department of Finance, Manning School of Business, UMass Lowell - Steven Freund, Ph.D., Department of Finance, Manning School of Business, UMass Lowell - Chi Zhang, Ph.D., Department of Finance, Manning School of Business, UMass Lowell - Shakil Quayes, Ph.D., Department of Economics, UMass Lowell Abstract Firms navigate evolving legal, environmental, and technological risks. External risks and information flows shape managerial choices and dynamics. My dissertation investigates how litigation threats, climate exposure, and cybersecurity risk affect two core corporate domains—financing structure and competitive strategy. The first essay investigates the relationship between shareholder litigation risk and product market outcomes. Using the staggered implementation of universal demand (UD) laws by U.S. states as an exogenous shock to shareholder litigation risk, we find that weaker shareholder litigation rights resulting from these laws leads to an increase in sales growth for the impacted firms. The effect is stronger for firms with lower agency concerns, greater financial constraints, higher ex ante litigation risk, and those operating in more competitive product markets. Additional analyses indicate that strategic aggressiveness represents an important channel through which reduced shareholder litigation risk improves product market outcomes. The findings suggest that shareholder litigation threats can have unintended negative effects on firm competitiveness. The second essay examines how firm-level climate
Jun 11, 2026 · via uml.edu
UW and Wyoming SBDC Network to Host Data Alternative Web Browser Webinar June 25 Published June 11, 2026 Small-business owners, entrepreneurs and startups will have an opportunity to learn about alternative web browsers that may keep their businesses and their information online safer Thursday, June 25. Paul Johnson, Marree Reed and Ian Moon will lead a Wyoming Small Business Development Center (SBDC) Network webinar titled “Are You Using the Safest Web Browser? Alternatives to the Big Ones” from noon-12:30 p.m. To register, go here. The Wyoming SBDC Network offers business expertise to help Wyoming residents think about, launch, grow, reinvent or exit their business. The Wyoming SBDC Network is hosted by the University of Wyoming with state funds from the Wyoming Business Council and funded, in part, through a cooperative agreement with the U.S. Small Business Administration. During the webinar, attendees will learn the pros and cons of the most popular web browsers as well as platforms that may be right for them and their businesses. Johnson is manager of the Wyoming SBDC Network’s Cybersecurity Program. Reed is a cybersecurity program assistant in UW’s Cybersecurity Education and Research Center and a part-time employee with Institutional Marketing. Moon is a cybersecurity program assistant with the Wyoming SBDC Network’s Cybersecurity Program and a recent graduate of UW’s Computer Science Program. For more information, call Tyler Schanck, marketing, communications and database manager for the Wyoming SBDC Network, at (307) 343-0925 or email tschanck@uwyo.edu.
Jun 11, 2026 · via uwyo.edu
The ShinyHunters extortion crew exploited an unpatched flaw in Oracle PeopleSoft to break into enterprise systems, steal data, and demand payment to keep it private. The campaign hit universities hardest. Google's Mandiant attributes it to the group it tracks as UNC6240, and dates the activity between May 27 and June 9. Oracle did not publish its advisory until June 10, so the bug was a zero-day the entire time. The flaw, CVE-2026-35273, is a remote code execution bug in PeopleSoft Enterprise PeopleTools rated 9.8 out of 10. It needs no login and no user interaction, just network access over HTTP, to take over the server. If you run PeopleSoft with the Environment Management Hub reachable from outside, that is your exposure, and the immediate move is to lock those endpoints down. The vulnerability sits in the Updates Environment Management component, the piece behind the Environment Management Hub (PSEMHUB). Oracle lists PeopleTools 8.61 and 8.62 as affected and says earlier, unsupported versions are probably vulnerable too. It credits researchers from TrendAI Zero Day Initiative and TrendAI Research for the report. Mandiant CTO Charles Carmakal confirmed the bug is being exploited in the wild; Oracle has not said whether it has seen exploitation. Its advisory points to a patch availability document behind a support login, and whether a full fix is broadly available is unclear. For now, the guidance centers on mitigation. The operational detail became public because the attackers left their own gear exposed. Researcher @nahamike01 publicly flagged the open directories. Mandiant then triaged five sequential IP addresses running Python's SimpleHTTP server on port 8888. Those servers exposed the staging files: a shared .bash_history, custom MeshCentral remote-management agents disguised as Microsoft Azure binaries, and a lateral-movement script. The agents called home to a command-and-control server at azurenetfiles.net, a domain picked to
Jun 11, 2026 · via thehackernews.com
The Indian Institute of Technology Kanpur (IIT Kanpur) has announced the launch of a new undergraduate programme, Bachelor of Cybersecurity (B Cyber) from the 2026-27 academic session. The programme will begin in July 2026 and will be offered through the Wadhwani School of AI and Intelligent Systems. Admissions to the programme will not be conducted through JEE Advanced. Instead, candidates will be shortlisted based on their JEE Main scores and evidence of prior work in the field of cybersecurity. Shortlisted applicants will then be required to appear for an in-person assessment at the IIT Kanpur campus. The assessment process will include a hackathon. Also Read | IIT Kanpur hires CBSE hacker Nisarga Adhikary as an OSINT, threats engineer According to the institute, the four-year programme has been designed with a combination of academic training and practical experience. Students will spend the first two years on campus studying cybersecurity concepts through coursework and laboratory-based training. The curriculum is intended to provide theoretical foundations as well as hands-on exposure in controlled environments. The remaining two years will be devoted to internships with government security organisations. During this period, students will work on cybersecurity-related projects and real-world security challenges as part of their training. The institute said the programme has been introduced in view of the increasing importance of cybersecurity and the need for trained professionals in the sector. IIT Kanpur Director Manindra Agrawal stated that cybersecurity has become a critical area, particularly for the protection of digital infrastructure and national systems. Nitin Saxena, Dean of the Wadhwani School of AI and Intelligent Systems, said the programme aims to combine academic instruction with practical experience to prepare professionals for the cybersecurity sector. IIT Kanpur said a dedicated webpage for the programme is being developed and is expected to go live next week. Detailed
Jun 11, 2026 · via indianexpress.com
CISA Orders Federal Agencies To Patch Actively Exploited Critical Vulnerabilities Within Three Days Under New Cybersecurity Directive The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has unveiled a sweeping new cybersecurity mandate requiring federal civilian agencies to remediate some of the most dangerous software vulnerabilities within as little as three days, marking one of the most aggressive vulnerability management policies ever imposed across the federal government. Vulnerability Mitigation Timeline (Source: CISA) The new directive, known as Binding Operational Directive (BOD) 26-04, establishes accelerated timelines for addressing high-risk security flaws and reflects growing concern within the U.S. government over the increasing speed at which threat actors exploit newly discovered vulnerabilities. The policy replaces previous federal vulnerability management directives and aims to strengthen the government's defenses against ransomware groups, nation-state hackers, and other cybercriminal organizations that increasingly target public-sector infrastructure. The announcement comes amid a broader cybersecurity landscape in which attackers often weaponize newly disclosed vulnerabilities within hours or days of public disclosure, significantly reducing the time available for defenders to deploy security updates. A Shift Toward Risk-Based Vulnerability Management According to CISA, the new framework supersedes and revokes earlier directives introduced in 2019 and 2021, replacing them with a more dynamic, risk-based approach that prioritizes remediation based on the likelihood and potential impact of exploitation. Rather than relying solely on traditional severity scores, the directive requires agencies to evaluate vulnerabilities using several operational risk factors. These include whether a vulnerable asset is exposed to the internet, whether the vulnerability has been actively exploited in real-world attacks, the extent to which exploitation can be automated, and the level of system control an attacker could gain if exploitation succeeds. Conventional vulnerability scoring systems such as CVSS often fail to accurately predict real-world exploitation risk. Numerous incidents in recent years have demonstrated that vulnerabilities
Jun 11, 2026 · via linkedin.com
Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert A zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft PeopleTools is being exploited in the wild, Charles Carmakal, CTO at cybersecurity firm Mandiant, part of Google Cloud, warned today. The warning comes a day after Oracle published an out-of-band security alert about the flaw, which is remotely exploitable without authentication, may result in remote code execution, and affects PeopleSoft PeopleTools versions 8.61 and 8.62 (and possibly earlier, unsupported ones as well). Oracle credited researchers with TrendAI Zero Day Initiative and TrendAI Research for reporting the vulnerability. The security alert links to a “patch availability document”, but it is unclear whether a patch is currently available, as the document is accessible only to customers with a support account. Help Net Security has reached out to Oracle for confirmation on whether CVE-2026-35273 is being actively exploited, but we’ve yet to receive a reply. ShinyHunters targeting PeopleSoft instances Oracle’s alert was published on the same day that Bleeping Computer reported ShinyHunters’ claims that they’ve been breaching Oracle PeopleSoft servers and have stolen data from 100+ organizations. According to the extortion group’s claims, the targeted organizations are mostly educational institutions, and their PeopleSoft instances – whether on-premises or in the cloud – were breached “using a ‘gadget chain’ of old and zero-day vulnerabilities.” Among the victims is apparently the University of Nottingham, which confirmed it has suffered a cybersecurity incident and that it has notified affected students and alumni directly. ShinyHunters claimed that breach and leaked tens of gigabytes of stolen data, including personal data and academic records of nearly half a million current and former students. A threat researcher seemingly confirmed ShinyHunters’ ongoing targeting of PeopleSoft instances, after discovering exposed directories containing tools used in these attacks. “At the /pay_or_leak endpoint, is stolen data from
Jun 11, 2026 · via helpnetsecurity.com
Microsoft, OAS Expand Cybersecurity Alliance in Latin America Microsoft and the Organization of American States (OEA) are expanding their regional collaboration to strengthen cybersecurity capabilities, improve institutional preparedness, and support the responsible adoption of emerging technologies across Latin America. Microsoft and the Organization of American States (OAS) announced an expanded strategic collaboration to strengthen digital resilience across Latin America. The initiative focuses on cybersecurity, government capacity building, and the responsible adoption of emerging technologies as cyber threats continue to affect economic stability and digital trust across the region. “Digital resilience is no longer only a technology issue; it is a strategic component of competitiveness and economic development,” says Steven Masada, Director of the Digital Crimes Unit, Microsoft. “Working alongside the OAS allows us to scale institutional capabilities and support governments in an increasingly sophisticated digital risk environment.” The expansion of the partnership comes as organizations across Latin America face a growing volume of cyber threats that are increasingly complex, transnational, and costly. As digital transformation initiatives continue across public and private sectors, cybersecurity has become a key factor in protecting economic activity, maintaining operational continuity, and preserving trust in digital services. Governments throughout the region are accelerating the digitization of public services, adopting cloud-based infrastructure, and exploring AI applications. While these technologies create opportunities for efficiency and growth, they also expand the attack surface available to cybercriminals and threat actors. Against this backdrop, public-private collaboration is emerging as a critical mechanism for addressing cybersecurity challenges that no single institution can manage independently. The initiative also reflects increasing recognition that cybersecurity extends beyond technical infrastructure. Digital resilience now plays a direct role in economic competitiveness, investment attraction, regulatory confidence, and the protection of critical services. Regional Cybersecurity Capacity Building Takes Center Stage As part of the expanded collaboration, Microsoft and the
Jun 11, 2026 · via mexicobusiness.news
The bank’s chief financial officer, Bryan Preston, said at the Morgan Stanley U.S. Financials Conference that Fifth Third was granted access to the initiative within the past several weeks, according to the report. “We think it was a reflection of just the role we play in the payments ecosystem in the country today, whether it’s the Direct Express business, some of the processing that we do for U.S. Customs as well as just the magnitude of payroll processing that we do for the country,” Preston said, per the report. Direct Express is the U.S. Treasury Department’s prepaid debit card program that helps Americans get monthly federal benefits. Fifth Third Bank was selected by the Treasury Department to expand the program, and the bank inked a five-year agreement to serve as the financial agent for the program in September, PYMNTS reported at the time. Anthropic introduced Project Glasswing in April when it announced the limited release of its first Mythos-class AI model, Claude Mythos Preview. The company said the initiative would offer select partners early access to the model so they could use the model’s cybersecurity capabilities to strengthen their systems before this class of models was more widely released. By May 22, Anthropic reported that Claude Mythos Preview had identified more than 10,000 cybersecurity vulnerabilities in “the most systemically important software in the world” so that they could be patched. Advertisement: Scroll to Continue On June 2, Anthropic said it was expanding Project Glasswing. The company said that the cybersecurity effort initially gave around 50 organizations access to Claude Mythos Preview and that it was being expanded to include 150 organizations. When Anthropic announced Tuesday (June 9) that it launched two Mythos-class models after developing safeguards to prevent them from being misused, the company said that one of them, Claude
Jun 11, 2026 · via pymnts.com
Israeli startups raised approximately $8.6 billion in the first half of 2026, up about 45% from the roughly $6 billion raised during the same period last year, according to a report released by Poalim Tech and Dealigence. The increase came despite ongoing security challenges and economic uncertainty, including the recent conflict with Iran. At the same time, the number of funding rounds fell by about 35%, suggesting investors are concentrating larger sums of capital in a smaller number of companies. The report found that cybersecurity remained one of the strongest sectors in Israeli tech, with investment in cybersecurity companies more than doubling compared with the first half of 2025. Funding in the sector remained steady even during periods of heightened security tensions, reaching about $580 million in March. The trend toward greater investor selectivity was also reflected in the profile of companies securing funding. Serial entrepreneurs accounted for a growing share of fundraising activity, with the proportion of rounds raised by repeat founders rising from 34% in 2025 to 39% during the first six months of 2026. A similar pattern emerged in mergers and acquisitions. The number of M&A transactions involving Israeli technology companies declined by about 16% year over year, falling from 100 deals to 84. However, average deal values increased by roughly 10%, excluding major transactions involving Wiz and CyberArk. Total M&A volume reached approximately $10.7 billion during the first half of the year. The report also pointed to diverging trends in the technology labor market. While multinational technology companies continued to implement layoffs and cost-cutting measures amid economic uncertainty, artificial intelligence-driven efficiency efforts and a weaker U.S. dollar, employment at Israeli early- and mid-stage startups grew by about 2%. According to the report, younger companies have generally maintained leaner workforce structures, limiting the need for additional staff
Jun 10, 2026 · via ynetnews.com
Cyera raises $600 million at $12 billion valuation, up fourfold in 18 months The cybersecurity firm has raised $1 billion in six months, targeting the growing gap between AI adoption and enterprise control. Israeli cybersecurity company Cyera has raised $600 million at a $12 billion valuation, a fourfold increase over the past 18 months. Total funding now exceeds $2 billion, placing it among the most valuable privately held cybersecurity firms globally. The round was led by Evolution Equity Partners, with participation from Cyberstarts and Temasek, alongside existing investors including Accel, AT&T Ventures, Blackstone, Coatue and Spark Capital. Over the past year, Cyera has expanded its product suite, shipping more than 100 new capabilities across data security posture management (DSPM), privacy, identity, data loss prevention (DLP) and what it calls agentic security, tools designed to govern AI systems operating within enterprises. Cyera co-founder and CEO Yotam Segev said the company is focused on enabling AI adoption at scale while maintaining control over data and system access. “Trust is what makes this possible, knowing what your AI can see and do,” Segev said. “That’s the infrastructure layer the industry has been missing, and it’s what we’ve been building alongside our customers since day one.” Segev added that the funding will be used to accelerate development of the platform for enterprises operating in what he described as the “agentic era.” Cyera said its growth has accelerated alongside demand for AI security tools. The company reported that annual recurring revenue has tripled for three consecutive years. It has also expanded rapidly, reaching more than 1,500 employees across 18 countries over the past 18 months. During that period, Cyera completed five acquisitions, including Ryft and Genie, to expand its capabilities in data and AI security. The new round places Cyera among the most valuable Israeli
Jun 10, 2026 · via calcalistech.com
The EO also follows a growing trend at the state level, where states such as California and New York have begun imposing frontier AI-specific governance, transparency and incident-reporting obligations on frontier developers, including requirements aimed at assessing and mitigating risks of catastrophic or âcritical harm.â Key provisions of the EO include: - Federal cyber defense priorities. Within 30 days, federal officials are tasked with taking measures in line with the purpose of the memo to prioritize the cyber defense of National Security Systems, Department of War information systems and civilian Federal Government information systems. The EO directs CISA, in consultation with OMB and other White House officials, to issue Binding Operational Directives and other guidance to expedite cyber defense measures, expand AI-enabled defensive tools, and facilitate access to cybersecurity tools and services for federal agencies, state and local authorities, and operators of critical infrastructure. - AI cybersecurity clearinghouse. The EO also directs the Treasury Department, in consultation with the National Cyber Director, NSA and CISA, to form an AI cybersecurity clearinghouse within 30 days. The clearinghouse is intended to coordinate and deconflict software vulnerability scanning, validate vulnerabilities, and prioritize remediation and patch distribution in voluntary collaboration with AI companies and critical infrastructure operators. - Classified benchmarking for covered frontier models. Within 60 days, Treasury, NSA, CISA, NIST and other federal officials must develop and maintain a classified benchmarking process to assess the advanced cyber capabilities of AI models and determine when a model should be designated a âcovered frontier model.â The NSA Director, in consultation with other federal officials, will determine whether a model meets that threshold. - Voluntary pre-release access framework. The EO directs federal officials to design a voluntary framework through which AI developers may engage with the federal government to determine whether models under development qualify as
Jun 10, 2026 · via pillsburylaw.com
Dive Brief: - The rate of data breaches at companies that widely use AI tools is significantly higher than the rate at companies that don’t — 43% compared with 11% over the past 12 months — the identity security firm Netwrix said in a report published on Wednesday. - AI tools such as agents significantly increase organizations’ “identity footprint,” creating more gaps that hackers can exploit, Netwrix said. - At the same time, Netwrix found, the companies using AI the most widely are also the ones taking identity management the most seriously. Dive Insight: Netwrix’s report highlights the security risks of the sprawling web of user accounts and other identities that companies must create to use agents, copilots and other AI tools. “AI agents are now acting on behalf of humans against sensitive data,” Netwrix researchers wrote. “Non-human identities need the same operational rigor long applied to privileged human access.” And yet many companies aren’t taking identity management seriously, the report found. Roughly three-quarters lack “a single, unified view of sensitive data and which identities have access to it,” researchers said. More than half of organizations lack an up-to-date database of sensitive data, 71% can’t quickly determine which identities can access which data and 70% don’t have a security strategy linking data protection with identity governance. Identity management is far from a new challenge for enterprises, but AI has magnified it, and companies are not always keeping pace. Three-quarters of organizations aren’t fully overseeing what AI identities are doing in their systems, even as 41% say they’re letting AI agents access sensitive data and perform vital tasks. Netwrix’s report highlights how hackers have used identity security weaknesses as entry points in target networks. Three-quarters of incidents in which hackers access sensitive data involve compromises of identities or misconfigured account permissions.
Jun 10, 2026 · via cybersecuritydive.com