No-frills tech news

Update on recent cybersecurity incident

ET Business Operations Restored Manufacturing, order fulfillment and shipping operations are now fully restored following the cybersecurity incident identified on August 25, 2026. As order processing continues, we are working to fulfill customer orders as quickly as possible, including those pending prior to the August 25 cybersecurity incident and those received during the disruption. The network disruption impact to remote monitoring activations has been resolved and activation capability has been restored. Remote monitoring activations for cardiac device implant communicators and ICM remote monitoring have resumed. Archived: 9/8/26 update 9/5/26 update 9/3/26 update 8/30/26 update 8/29/26 update 8/28/26 update 8/27/26 update

An alignment assessment of recent cybersecurity incidents

Introduction We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems. Claude Mythos 5 uploads a malicious PyPI package Claude Mythos 5 was given a CTF task to hack a fictional company and was told it had no internet access. Claude Mythos 5 was significantly more likely than Claude Opus 5 and Claude Mythos 5.1 to engage in these kinds of behaviors. Across all replications, Claude Mythos 5 performed worse than all of our other production models, including Claude Opus 5 and Claude Mythos 5.1. We found that in individual environments in the production RL runs of recent models, models occasionally reasoned that they were in a simulation while calling reckless, dishonest, or destructive behavior acceptable when interacting with fake websites or applications.

How AI and cybersecurity are reshaping ServiceNow

So too is ServiceNow, including how it expects IT leaders to finance that future. Instead, growth is increasingly generated by “consumed” services such as infrastructure, integrations and connectors, AI token consumption, and cybersecurity. AI convergence AI is causing previously distinct sectors such as ITSM and cybersecurity to converge, with AI itself turning into a unifying AIOps front end to diverse, specialized technologies sitting below it. In 2025, this evolution crystalized as the ServiceNow AI Platform, a rebranded Now platform augmented by unifying features such as the AI Control Tower. According to LaPorte, ServiceNow customers should be alert to the ways this changes their relationship.

Kevin Mandia joins the Amazon board with 30-plus years in cybersecurity

Amazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in September 2022, and he has worked against cyber threats in the public and private sectors for more than 30 years. Amazon called cybersecurity “one of the most consequential risks and responsibilities organizations face today,” and pointed to advances in AI as the reason the threat landscape keeps moving. That is the company’s stated reason for putting the expertise at board level, where directors decide which questions management has to answer. Ballistic Ventures keeps Mandia close to the companies being built now, and Armadin keeps him running one.

Anthropic discloses 4th AI hacking incident as researcher quits over safety

Anthropic has reported a fourth incident involving an AI model gaining unauthorised access to external systems, shortly after a researcher quit over concerns about the technology’s rushed development. Recommended Stories list of 4 items list 1 of 4Sam Altman says AI has entered ‘singularity’: Should we be worried? The disclosure came after Anthropic reported several of its Claude models hacked into the systems of three companies during test sessions in July. Anthropic researcher quits The investigations come amid a broader wave of internal dissent within the AI industry regarding safety. Following the security breach of Hugging Face, OpenAI said it was pushing for mandatory national AI safety requirements and wanted to work with Congress on “capability-based” regulation.

In Roanoke Valley, Va., Water Cybersecurity Changed Post-9/11

After the attacks of Sept. 11, 2001, heightened concern over the security of the nation's food and water led to more protective measures. At the time, the Western Virginia Water Authority didn’t exist — it was created in 2004, when the city of Roanoke and Roanoke County consolidated their water and wastewater operations. The water authority has also partnered with the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, or CISA, for several years. Plus, you can still tour a facility, as long as you call the water authority and set something up first. Shirley said the water authority values getting to show people how the system works.

Cybersecurity Amid Plant Connectivity

2027 International Biomass Conference & Expo March 2-4, 2027 COBB CONVENTION CENTER | ATLANTA,GEORGIA Now in its 20th year, the International Biomass Conference & Expo is expected to bring together more than 1000 attendees, 180 exhibitors and 100 speakers from more than 25 countries. It is the largest gathering of biomass professionals and academics in the world. The conference provides relevant content and unparalleled networking opportunities in a dynamic business-to-business environment. As the largest, longest running ethanol conference in the world, the FEW is renowned for its superb programming—powered by Ethanol Producer Magazine —that maintains a strong focus on commercial-scale ethanol production, new technology, and near-term research and development. Deploying effective carbon capture and storage at biofuels plants will cement ethanol and biodiesel as the lowest carbon liquid fuels commercially available in the marketplace.

Silicon Motion Earns ISO/SAE 21434 Automotive Cybersecurity Process Certification

The certification independently validates that Silicon Motion's automotive cybersecurity development and management processes meet the requirements of ISO/SAE 21434, the internationally recognized standard for cybersecurity engineering in road vehicles. Silicon Motion will continue to advance its automotive cybersecurity capabilities and deliver a comprehensive portfolio of secure and reliable storage solutions for connected, software-defined and AI-powered vehicles. For more information, visit Silicon Motion Automotive Solutions. About Silicon Motion Silicon Motion Technology Corporation (NasdaqGS: SIMO) is the global leader in supplying NAND flash controllers for solid-state storage devices. Investor Contacts: E-mail: [email protected] Sales Contact: E-mail: [email protected] SOURCE Silicon Motion Technology Corporation

Ransomware Is The New Normal: Cybersecurity Considerations for Fiduciaries

Insurance carriers and cyber claims professionals, too, should understand that cyber business interruption is frequently one of the largest components of cyber-related financial losses and insurance claims. Ransomware has become a persistent business risk that fiduciaries, receivers, and restructuring professionals must address in every engagement. According to Cybersecurity Ventures, ransomware damages are expected to reach $74 billion USD in 2026 and surpass $275 USD billion globally by 2031. Cyberattacks can halt production, disrupt supply chains, disable critical systems, and cause substantial business interruption and additional expense losses. The costs of a cybersecurity attack include lost revenue from customers and new leads, as well as from being offline.

Dream’s Hero scores 96.6% on CyberGym to rank first globally in autonomous cybersecurity research benchmark

Dream, the sovereign AI company for governments and critical infrastructure, announced that its autonomous cybersecurity research system, Hero, scored 96.6% on CyberGym, ranking first globally on the UC Berkeley cybersecurity benchmark. CyberGym evaluates AI systems against more than 1,500 real-world security challenges drawn from open-source projects. Dream’s 96.6% score reflects the performance of its complete autonomous research system, rather than the underlying model in isolation. Dream ran Hero across open-source codebases, binaries, and firmware to generate detailed examples of real cybersecurity research, including reasoning, investigation, exploitation, and remediation processes. This data was filtered through automated and human review and used to train Hercules specifically for advanced cybersecurity research.

Why Today's Cybersecurity Leaders Must Help Shape Tomorrow's Talent

The UK government’s Cyber security skills in the UK labour market 2025 report found that 49% of businesses had a basic technical cyber skills gap, while 30% faced gaps in more advanced technical areas. Experienced professionals can help make that happen. Some excellent cyber professionals have taken unconventional routes into the industry. An ISC2 survey of UK cybersecurity professionals published in May 2026 found AI to be the most commonly reported skills gap, followed by cloud security. We cannot keep talking about the cyber skills shortage as though the next generation of experienced professionals will simply appear when we need them.

New FBI cyber strategy promises increase in adversary disruptions

WASHINGTON — The FBI on Wednesday said it intends to formalize and speed up its collaborative takedowns of malicious hacking activity. As part of the new strategy, FBI teams focused on countering specific threats, from Russia to China to cybercriminals, will develop their own customized plans. The FBI has seen a reduction in companies’ willingness to share information over the past few years, a continuation of a long-running trend. Expanding hacking partnerships A major theme of the FBI’s cyber strategy is the bureau’s desire to partner with more organizations on disruption operations. Meanwhile, the FBI’s new strategy envisions the bureau’s own disruptive operations increasing in frequency and scope.

UConn Student Justin Fargo Went from Family iPhone-Fixer to Small Business Cybersecurity Champion

In the last year, Justin Fargo ‘28 has created a new cybersecurity and compliance firm to help small- and medium-sized companies meet the requirements needed to become U.S. government contractors. You don’t have to wait until you graduate to start a business,’’ says Fargo. Fargo Was Intrigued by Tech from Age 3 Fargo recalls being intrigued by technology from the time he was a toddler. In high school, Fargo took home a first-place award against other Connecticut high school students at Lockheed Martin’s CYBERQUEST, an annual competition designed to encourage students to pursue careers in cybersecurity. I saw the beauty in entrepreneurship and in helping people,’’ says Fargo, who hails from a family of entrepreneurs.

Luminis cybersecurity incident highlights ‘concerning’ rise in attacks on healthcare

He is the public policy and external affairs program director with the University of Maryland, Baltimore’s Center for Cyber, Health and Hazard Strategies. His comments come just days after Luminis Health facilities last week announced a “cyber incident by an unauthorized criminal actor” that disrupted certain medical appointments and services. Luminis hospitals remained open while an investigation into the attack continues, but some of their systems were nonoperational, which could impact appointments and services. But Luminis is just the latest example in what seems to be a rise in cybersecurity threats facing the healthcare industry. “It’s [the Luminis attack] adding to a series of disturbing incidents going back 10 years to the MedStar cyber incident.”

Report: States Tackling Local Gaps in Infrastructure Cybersecurity

Whole-of-state cybersecurity strategies have increased as well, with 73 percent of respondents reporting that critical infrastructure cyber protection is part of their state’s plan. Grant programs point to another challenge, which is how to pay for robust state cybersecurity long term. Almost every state CISO interviewed for this report expressed concern about the future of federal cybersecurity funding, such as the State and Local Cybersecurity Grant Program. The report warns that without sustained federal investment, progress made through whole-of-state programs could stall, leaving states to identify other ways to maintain services for local governments and critical infrastructure. While challenges are not likely to go away, the report gives detailed steps about how states can influence and formalize local and critical infrastructure cybersecurity.

CIA eyes ‘more technical’ workforce amid cyber, AI challenges

Michael Ellis, the deputy director of the CIA, said the spy agency is seeking to recruit more employees with backgrounds in science and technology. “When I think about, you know, where we want the CIA workforce to be five years from now, it’s an elite workforce,” Ellis said at the Billington Cybersecurity Summit in Washington on Tuesday. It’s one that has more technical background than it has today, and it’s one that is motivated by mission.” “It means we need a different kind of workforce,” Ellis said. Earlier this year, CIA Director John Ratcliffe announced a major reorganization of the agency’s technology centers, as well new acquisition and industry partnership initiatives.

<b>Cybersecurity</b> governance: From bureaucracy to real-world threats

Can't find what you're looking for? View all search results We have the blueprints to defend our digital sovereignty, but without real enforcement power, adequate funding and urgency on AI and quantum threats, the next massive breach is already penciled in. cross Southeast Asia, rapid digitization has quietly rewritten the rules of state legitimacy and national defense. How each government handles cybersecurity reveals who is actively building resilience and who is simply improvising under pressure. Singapore set the regional standard early. Since launching its Cyber Security Agency in 2015, the city-state has systematically built a cohesive ecosystem of clear laws, skilled personnel and global partnerships. Malaysia took a pragmatic operational path, dividing responsibilities between CyberSecurity Malaysia and the National Cyber Security Agency while leaning on strong public-private coordination. Thailand and Vietnam moved aggressively on legislation, passing sweeping frameworks in 2019 and 2018 that allowed them to scale their institutional defenses quickly. Meanwhile, Cambodia, Laos and Myanmar are still establishing baseline Computer Emergency Response Team (CERT) capabilities and early legal structures. Then there is Indonesia: caught awkwardly between genuine ambition and persistent structural vulnerability. On paper, Jakarta has made notable progress. Consolidating national cybersecurity authority under the National Cyber and Crypto Agency (BSSN) in 2017 brought critical infrastructure protection, cryptographic standards and incident response under one roof. The passage of the Personal Data Protection (PDP) Law in 2022 signaled that lawmakers finally grasped the scale of the digital economy they needed to protect. The actual track record, however, tells an uncomfortable story that diplomatic language cannot soften. In 2021 alone, a breach at national health insurance provider BPJS Kesehatan exposed the personal data of roughly 279 million citizens, followed quickly by the leak of 2.3 million voter records from the General Elections Commission. The following year saw major data exposures at

ICT Authority steps up <b>cybersecurity</b> for government systems

- Government systems face stronger cybersecurity safeguards. - Stakeholders are testing new risk assessment tools. - Framework gaps are being addressed before certification. Kenya is stepping up efforts to protect government digital systems and Critical Information Infrastructure (CII) from cybersecurity threats that could disrupt essential services, compromise sensitive information and undermine confidence in the country’s rapidly expanding digital economy. More public services and critical operations are moving onto interconnected digital platforms, raising the stakes and the need for institutions to identify vulnerabilities early, assess their exposure and put in place coordinated measures to manage cyber risks. Against this backdrop, the ICT Authority, through the Kenya Digital Economy Acceleration Project (KDEAP), has convened a weeklong stakeholder workshop in Nairobi to assess the status and progress of the Vulnerability Assessment for National ICT Cybersecurity Risk and Critical Information Infrastructure project. This initiative seeks to establish a common national approach to cybersecurity risk management across the public sector and nationally designated CII. Stakeholders are reviewing the standards, controls, tools and operational frameworks outlined in the National Cybersecurity Strategy. Once endorsed, the measures are expected to be adopted uniformly across the public sector and nationally designated CII. Also under scrutiny is whether the proposed framework is practical enough for national implementation before certification begins. Participants are assessing the practicality of the proposed standards and certification process, including the skills, resources and time institutions will require to use the National Information Security Framework Audit and Risk Register Toolkit s effectively. READ ALSO: Beyond that, stakeholders are examining gaps and inconsistencies in the framework documents, control wording, scoring methodology and supporting toolkits. Addressing these weaknesses before national certification is actualised is critical to ensuring that institutions apply the framework consistently and that cybersecurity assessments provide a reliable picture of the risks facing government systems and critical

Rockwell Automation Announces New <b>Cybersecurity</b> Season of ROKStudios Video Series

Rockwell Automation Announces New Cybersecurity Season of ROKStudios Video Series New season features global manufacturers and cybersecurity leaders sharing recent research and practical strategies for building resilient, secure industrial operations MILTON KEYNES, England, Sept. 8, 2026 /PRNewswire/ -- Rockwell Automation, the world's largest company dedicated to industrial automation and digital transformation, today announced a new cybersecurity-focused season of ROKStudios, its thought leadership video series featuring in-depth interviews with customers and Rockwell Automation consultants. The latest season explores how manufacturers are strengthening cyber resilience as connected operations, IT/OT convergence and increasing threat activity reshape operational risk. Drawing on insights from Rockwell's 11th Annual State of Smart Manufacturing Report the series highlights how organizations are moving from awareness to execution in securing industrial environments. "Organizations are operating in a more complex and connected environment than ever before," said John Speakman, director of cybersecurity services, EMEA, Rockwell Automation. "Cybersecurity has become fundamental to operational resilience. These discussions highlight how manufacturers can move beyond compliance toward building the capabilities needed to manage risk, maintain continuity and secure their operations at scale." Recent research shows that cybersecurity is now a central pillar of resilience, with nearly half of manufacturers reporting a cyber incident in the past year and rising exposure driven by increased connectivity between IT and operational technology environments. The research also underscores that cyber risk is no longer episodic but an ongoing operational requirement as manufacturers scale AI, automation and connected systems. Season highlights include: - Andrew Peckston, head of supply chain cybersecurity and infrastructure, Mondelēz International: Discusses how manufacturers are elevating cybersecurity to a strategic business priority, embedding it into supply chain strategy and aligning IT and OT teams to strengthen resilience across global operations. - Steve Lynn, director of engineering, William Grant & Sons: Shares a practical perspective on building OT

<b>Cybersecurity</b> jobs available right now: September 8, 2026

Cybersecurity jobs available right now: September 8, 2026 CISO AudioCodes | Israel | Hybrid – View job details As a CISO, you will lead security strategy, governance, and risk management across SaaS, managed services, and customer-hosted environments. You will oversee security controls, incident response, Secure SDLC, customer security engagements, and compliance with SOC 2 and ISO 27001, while partnering across Product, R&D, IT, and Services to continuously strengthen security. Combat Systems Cyber Engineer Johns Hopkins Applied Physics Laboratory | USA | On-site – View job details As a Combat Systems Cyber Engineer, you will identify cyber vulnerabilities and develop resilient solutions for U.S. Navy submarine and combat systems. You will collaborate with developers, Navy labs, and government teams to design, plan, and execute cyber resiliency testing and assessments of mission-critical combat systems. Cyber Security Engineer (Cloud Security) Garmin | USA | On-site – View job details As a Cyber Security Engineer (Cloud Security), you will design and secure cloud solutions across AWS and Azure, including network, compute, storage, databases, and load balancing. You will support CNAPP, Kubernetes, EKS, AKS, Docker, OpenStack, CI/CD pipelines, and Infrastructure as Code. You will automate security workflows using Python, PowerShell, or Bash, secure cloud-native and containerized applications, and collaborate with engineering teams to improve security, compliance, threat detection, and response. Get weekly updates on new cybersecurity job openings. Subscribe here! Cyber Security Lead Babcock International Group | United Kingdom | On-site – View job details As a Cyber Security Lead, you will lead secure-by-design assurance for UK Defence Nuclear Enterprise programmes, ensuring alignment with Ministry of Defence security requirements. You will conduct threat modelling and cyber risk assessments, develop mitigation strategies, produce security evidence, and guide engineering and architecture teams in embedding security throughout the system lifecycle. Cyber Threat Hunter GDIT | USA | On-site