What is the cybersecurity topical requirement? The cybersecurity topical requirement is a formal framework that guides internal auditors in conducting cybersecurity assurance engagements. It establishes a baseline set of areas internal auditors should evaluate when assessing cybersecurity programs and cyber-related risks. Importantly, it does not create a rigid checklist that every organization must follow identically. Instead, it provides a consistent structure that internal audit functions can apply based on organizational size, industry, complexity, and risk exposure. The requirement exists because cybersecurity audits have historically varied significantly between organizations. Some audit teams perform highly technical reviews with little connection to business risk. Others focus almost entirely on governance documentation without evaluating whether controls actually work in practice. Some organizations rely heavily on external specialists while internal audit remains largely disconnected from cybersecurity oversight. Key principles: - Cybersecurity controls only provide value when they support business resilience and operational continuity. - The goal is not to determine whether a security control exists, but to determine whether cyber risks are managed in a way that protects the organization's ability to operate. - The topical requirement encourages internal auditors to think beyond technical compliance toward strategic assurance. At its core, the requirement reinforces a fundamental principle of modern risk-based internal auditing: audits should align to organizational objectives and risks. Effective cybersecurity auditing does not begin with firewalls or security tools. It begins with understanding what the organization is trying to achieve and identifying the systems, data, and processes that support those objectives. Once critical assets are identified, internal audit can evaluate the threats that could affect them, the risks arising from those threats, and whether the controls designed to mitigate those risks operate effectively. Why the topical requirements matter now The timing of the cybersecurity topical requirement is not accidental. Organizations are operating in
Jun 10, 2026 · via wolterskluwer.com
For developers, each year brings a fresh set of automation tools designed to help them create code faster and roll out application updates that meet ever-changing business needs. Now, artificial intelligence (AI) and large language models (LLMs) have ushered in another era in this development known as “vibe coding.” Vibe coding is an approach where a developer or, in many cases, an amateur coder, describes what they want to create in natural language, and an AI system generates, edits or debugs the code based on an ongoing set of instructions. This approach to application creation shifts some work from writing every line of code toward steering, reviewing and validating AI-generated output. This technique for creating applications remains in its infancy but has caught on, especially as less-experienced coders and developers can take an idea and create an app using various AI platforms. A study by Gartner found that 40% of new business software could be created with techniques involving virtual chatbots and other AI tools. In large tech firms, such as Microsoft, company officials report that AI is creating about 30% of all code using these techniques. The productivity increases — these chatbots can reason across a codebase, edit multiple files, run tests, respond to errors and continue iterating toward a stated goal — have a downside when it comes to ensuring apps are safe and tested for bugs and vulnerabilities. Since many AI platforms scan the open internet, these agents can incorporate flawed code and use it while creating an application, building in vulnerabilities that can be exploited. A less-experienced developer may lack the ability to run quality checks or incorporate DevSecOps techniques when building apps using vibe coding. A 2025 study by Veracode that investigated 100 LLMs found that 45% of code samples failed security tests and introduced
Jun 10, 2026 · via dice.com
Newswise — A grid cybersecurity and verification framework developed at the Department of Energy’s Oak Ridge National Laboratory has been licensed by GridForge Energy Solutions. The startup plans to explore ways the technology could boost real-time visibility of grid behavior for energy projects, grid management companies and utilities. The patented technology, called Cyber Grid Guard, uses a software framework running on customized hardware as a platform to instantly detect unusual grid activity, data manipulation and illicit changes to device settings. These can all cause cascading power outages and damage grid infrastructure. “It’s very meaningful to see this protection technology on a pathway to strengthening the American electric grid and bringing value to American companies,” said Raymond Borges Hink, ORNL cyber security specialist who led the research. “In the past, people didn’t know if they could trust this grid operating data. This provides a new layer of validation and analysis to make the grid safer.” Blockchain protects grid device communications Using the same tamper-resistant blockchain commonly used to protect cryptocurrency, Cyber Grid Guard protects data sharing among electronic devices in the grid. Configuration and operating data about voltage, frequency, breaker status and power quality are spread redundantly across multiple servers. They are then constantly verified against the most recent settings saved in the blockchain. Performance logs track the source of any unauthorized changes. "ORNL's framework represents some of the most rigorous thinking on verified data exchange, attestation, and cybersecurity for grid infrastructure,” said Worlasie Djameh, co-founder and CEO of GridForge. “We are excited to translate this world-class national lab research into something commercially deployable for grid operators and flexible demand providers." The capabilities of Cyber Grid Guard were proven in a substation test bed at ORNL’s Grid Research Integration and Deployment Center (GRID-C) using commercial hardware. GRID-C offers a unique combination
Jun 10, 2026 · via newswise.com
Adam Reynolds is the vice president of Device Software Engineering at Gilbarco Veeder-Root. Opinions are the author’s own. Convenience store operators invest heavily in securing their payment systems and customer data. Yet one critical piece of infrastructure is often missing from broader security planning: the automatic tank gauge, or ATG. This technology monitors both aboveground and underground fuel tanks by tracking inventory levels, detecting leaks and helping companies ensure they’re in environmental compliance. As cyberattacks on critical infrastructure become more common, ATGs have emerged as a potential entry point in the absence of proper security protocols — and the scale of the threat is growing fast. In the first nine months of 2025, ransomware incidents targeting critical sectors rose 34% year over year, with half of all attacks striking industries such as energy, manufacturing and transportation. Fueling infrastructure sits firmly within that risk landscape, with cyberattacks on U.S. utilities rising nearly 70% in 2024. Convenience store operators spend years strengthening the security of their most visible systems. Payment networks are protected. Point-of-sale upgrades are routine. Loyalty data is carefully managed. However, ATGs — many of which were deployed long before today’s threat landscape — are not always evaluated with the same rigor as enterprise IT infrastructure. These devices present a potential access point many would not have considered, particularly as geopolitical tensions and increasingly sophisticated threats place added pressure on legacy infrastructure, according to the World Economic Forum’s Global Cybersecurity Outlook. As convenience retail becomes more connected, ATGs provide critical operational data that help retailers monitor inventory and make more informed business decisions. Realizing that value, however, requires those systems to connect with broader networks and platforms. As a result, securing the device itself is just as important as protecting the data it generates. When left unsecured, these systems can
Jun 10, 2026 · via cstoredive.com
China is a “ruthless” adversary that poses by far the greatest cybersecurity threat to the United States, according to Bob Skinner, chairman of the board of Axonius Federal Systems. In his closing keynote at the Axonius Adapt in Action conference in Washington, D.C., Skinner said China “is the threat.” “Yes, we have Russia and Ukraine going on, and things going on in Iran and the Middle East, but strategically, China is the threat,” he said. Skinner, a former director of the Defense Information Systems Agency (DISA), told the crowd that China is “ruthless in what they are trying to do.” “I’m a firm believer that in all of your lifetimes, China will do something that will impact your daily life, whether that is disrupting your power at some point in time, whether that is disrupting trains or metro, [or] whether that’s disrupting water supplies,” he said. “It can be a mom-and-pop shop in the middle of nowhere, or it can be a water filtration plant in the middle of nowhere. It is going to happen, and we’ve got to be prepared.” Skinner, who has more than 25 years of experience in cybersecurity, national defense, and digital modernization, was named to the Axonius board in April 2025 and became chairman in November. His comments about China echo numerous government warnings about Chinese cyber activities in recent years. In April, a cybersecurity advisory from the Cybersecurity and Infrastructure Security Agency (CISA) said that China-linked groups are shifting tactics and using “covert networks” to target home office routers, along with internet of things (IoT) and smart devices. Skinner said the Chinese threat has evolved from focusing on ransomware and intellectual property to “pre-positioning” cyber assets to strike at a time and place of Beijing’s choosing. To fight the growing threat, he said, U.S.
Jun 10, 2026 · via meritalk.com
WASHINGTON — U.S. Sen. Mark R. Warner (D-VA) today introduced the Combat Emerging Threats to Critical Infrastructure Act of 2026, legislation that directs the Cybersecurity and Infrastructure Agency (CISA) to work with regulators and industry to develop up-to-date cybersecurity plans. In light of artificial intelligence’s rapid advancement, including the development of Anthropic’s Claude Mythos – an AI model capable of identifying and exploiting vulnerabilities in our country’s cybersecurity infrastructure – it is critical that CISA coordinate with other federal agencies to ensure there are current cybersecurity plans can meet emerging threats. “As AI continues to rapidly evolve, we must ensure our cybersecurity defenses keep up with the threats of the moment,” said Sen. Warner. “It’s critical that government works closely with industry, regulators, and cybersecurity experts to develop and regularly update the plans we need to protect our critical infrastructure from increasingly sophisticated malicious actors, including those enabled by AI.” There are 16 critical infrastructure sectors designated under National Security Memorandum 22 (NSM-22), a memo that helps ensure U.S. critical infrastructure can provide the nation a strong and innovative economy, protect American families, and enhance our collective resilience to disasters before they happen. NSM-22 required CISA, in conjunction with other federal departments and agencies designated as Sector Risk Management Agencies (SRMAs), to develop sector-specific plans for each critical infrastructure sector. NSM-22 required a biennial updating of each sector-specific cybersecurity plan by the appropriate SRMA and that sector’s coordinating council. That update cadence has not been maintained, in many cases, for years. In fact, the cybersecurity plan for some critical infrastructure sectors has not been updated for over a decade. Specifically, the Combat Emerging Threats to Critical Infrastructure Act of 2026 would require CISA to complete the following: - Update the sector-specific plans for each of the 16 critical infrastructure sectors
Jun 10, 2026 · via warner.senate.gov
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.BOD 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities (Revoked) This Directive has been revoked. It is superseded by BOD 26-04. November 03, 2021 This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive 22-01 - Reducing the Significant Risk of Known Exploited Vulnerabilities. A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems. Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives. Federal agencies are required to comply with DHS-developed directives. These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community. Background The United States faces persistent and increasingly sophisticated malicious cyber campaigns that threaten the public sector, the private sector, and ultimately the American people’s security and privacy. The federal government must improve its efforts to protect against these campaigns by ensuring the security of information technology assets across the federal enterprise. Vulnerabilities that have previously been used to exploit public and private organizations are a frequent attack vector for malicious cyber actors of all types. These vulnerabilities pose significant risk to agencies and the federal enterprise. It is essential to aggressively remediate known exploited vulnerabilities to protect federal information systems and reduce cyber incidents. This directive establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal enterprise and establishes requirements for agencies to remediate any such vulnerabilities included in the catalog. CISA will determine vulnerabilities warranting inclusion
Jun 10, 2026 · via cisa.gov
Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.BOD 19-02: Vulnerability Remediation Requirements for Internet-Accessible Systems (Revoked) This Directive has been revoked. It is superseded by BOD 26-04. April 29, 2019 This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s Binding Operational Directive 19-02, “Vulnerability Remediation Requirements for Internet-Accessible Systems”. A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems. Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives. Federal agencies are required to comply with DHS-developed directives. These directives do not apply to statutorily defined “national security systems” nor to certain systems operated by the Department of Defense or the Intelligence Community. Background As federal agencies continue to expand their Internet presence through increased deployment of Internet-accessible systems, and operate interconnected and complex systems, it is more critical than ever for federal agencies to rapidly remediate vulnerabilities that otherwise could allow malicious actors to compromise federal networks through exploitable, externally-facing systems. Recent reports from government and industry partners indicate that the average time between discovery and exploitation of a vulnerability is decreasing as today’s adversaries are more skilled, persistent, and able to exploit known vulnerabilities. The federal government must continue to take deliberate steps to reduce the overall attack surface and minimize the risk of unauthorized access to federal information systems as soon as possible. Binding Operational Directive 15-01: Critical Vulnerability Mitigation Requirement for Federal Civilian Executive Branch Departments and Agencies’ Internet-Accessible Systems1 established requirements for federal agencies to review and remediate critical vulnerabilities on Internet-facing systems identified by the
Jun 10, 2026 · via cisa.gov
Announcing Forrester’s Top Cybersecurity Threats For 2026 AI innovation is moving at an unprecedented rate, and geopolitical tensions show no signs of easing. Forrester identifies these factors as two primary forces reshaping the threat landscape, placing additional strain on CISOs who are already stretched thin managing increasingly complex security programs. Anthropic’s Claude Mythos Preview and Project Glasswing are early signals of how radically areas such as vulnerability discovery, remediation, and exploitation are about to change. Simultaneously, the escalating US-Iran conflict has already translated into real world impact, driving a spike in disruptive cyberattacks; from the Stryker incident to Iranian-linked actors targeting PLCs across US critical infrastructure. AI has been a consistent thread running through the last three editions of Forrester’s top threats report. AI‑driven threats have evolved across the past three years as follows: - AI is more than LLMs and ChatGPT. Back in the top threats report for 2023, when ChatGPT was still the public’s first real handshake with large language models, we flagged data integrity as the standout risk. The concern here was the trust placed in these AI systems. - AI has been weaponized. In the 2024 edition of the report, the focus shifted from trust to misuse. We called out how genAI was being weaponized for enabling narrative attacks via disinformation, growing concerns around deepfakes, and concerns over AI responses due to prompt engineering, injection attacks, or the increased risk of sensitive data spillage. - AI supply chain risk emerged. In 2024, we also flagged the AI software supply chain risk as a threat (Spoiler: This concern hasn’t gone away, and it shows up again in this year’s report with updated findings). This is driven by adoption of open‑source models and frameworks such as those found in Hugging Face and GitHub. - Deepfakes are maturing and
Jun 10, 2026 · via forrester.com
Conan O’Brien has a simple explanation for why he agreed to star in a series of cybersecurity awareness training videos: money. Lots of it. “Hi, I’m Conan O’Brien,” he says in one of several promos for the new series. “There are two rules I live by in my career. One, be authentic. And two, never film security training videos about using AI. It’s beneath me. But then Adaptive came to my house with a dump truck full of money.” The “Adaptive” in question is Adaptive Security, an AI-focused cybersecurity company backed in part by the OpenAI Startup Fund. Its business is helping companies train employees to spot threats like deepfakes, voice cloning, AI impersonation, phishing, QR code scams, and other modern workplace hazards. In other words: corporate compliance training, but with Conan. In another promo, O’Brien opens mid-call: “So it’s all there, every cent? Terrific.” He then turns to camera and explains, “That was my accountant confirming that Adaptive’s check cleared. And now I’m here to tell you about deepfakes.” O’Brien’s promos are part of a new 15-video cybersecurity awareness training series designed to make workplace security lessons something employees might actually watch. Or, as Adaptive puts it on the series’ landing page: “Your employees have skipped every security awareness training you’ve sent. This one is different. It has Conan.” The training videos themselves are available through Adaptive’s enterprise platform, meaning Conan completists will need to convince their IT departments to sign a contract before they can see the full set. According to Adaptive, O’Brien’s team co-wrote the scripts with the company and improvised on set. Each module opens with a comedic O’Brien introduction before moving into Adaptive’s instructional material, interactive elements, and knowledge checks. The company says customers will see two versions of each module in their content library:
Jun 10, 2026 · via latenighter.com
If you try asking Anthropic's new Claude Fable 5 model a simple question about cybersecurity or biology, you may find it's not up to the task. That's because the underlying "Mythos-class" model is so powerful that, in order to release it to the general public, it required broad safeguards that can mistakenly flag benign requests, Anthropic said. After some users online said they had triggered the safeguard response with basic prompts about cancer or security, Business Insider put it to the test. I tried asking Fable 5 some simple questions about cancer, like how misinformation about cancer spreads online, and to break down some of the different types. Claude swiftly switched from Fable 5 to Opus 4.8 and notified me of the change before it responded. "Fable 5 has safety measures that flag messages on most cybersecurity or biology topics. They may flag safe, normal content as well. These measures let us bring you Mythos-level capability in other areas sooner, and we're working to refine them," the pop-up said. Anthropic released Fable 5 on Tuesday and said it was as powerful as its Mythos 5 model, only with added safeguards. The release came two months after the company said Mythos was too powerful for a broad release due to cybersecurity concerns. Instead of being released to the public, Mythos was made available only to a small group as part of a cybersecurity project. Anthropic said the safeguards were necessary in order to release the model to the general public. "With the launch of Claude Fable 5, our first Mythos-class model, we believe models now have a greater ability to accomplish real-world scientific tasks and for malicious actors to potentially use our models for highly risky biological research," an Anthropic spokesperson said in a statement to Business Insider. "We have always
Jun 10, 2026 · via businessinsider.com
UW-Superior launches cybersecurity program to meet growing workforce demand New concentration offers hands-on training in ethical hacking, digital forensics and AI-driven security SUPERIOR, Wis. (Northern News Now) - UW-Superior is preparing to welcome its first cybersecurity class as part of a new concentration in the university’s computer science program. Growing demand for cybersecurity over the past decade, along with rapid advances in technology including artificial intelligence and increasingly sophisticated scams, has driven the addition of the concentration. Dr. Jonathan Totoshek, chair of the math and computer science department, said the program will bring promising opportunities. “Data security is one of the biggest threats that we face in society these days and having more competent people in place to keep our data safe is a very important role,” Totoshek said. Program adapts to AI threats Classes range from entry-level programming to advanced database courses. Students will be taught skills to adapt to the new world of AI, in some cases protecting against it while also learning to use it responsibly as a tool. “AI is playing a very large role in attacks right now,” Totoshek said. “We need to also adapt and also use AI to help with the protection of these cybersecurity attacks.” Leaders at UW-Superior said the new concentration blends hands-on training like ethical hacking and digital forensics with flexible online and in-person options to meet a fast-growing workforce need. Ryan Dunn, associate director of admission, said the program is already gaining traction. “We have seen a lot of interest from students, both on campus and off campus,” Dunn said. The cybersecurity program will be available for the fall semester of 2026. Click here to download the Northern News Now app or our Northern News Now First Alert weather app. Copyright 2026 Northern News Now. All rights reserved.
Jun 10, 2026 · via northernnewsnow.com
CISA Adds Three Known Exploited Vulnerabilities to Catalog CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability - CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability - CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. This product is provided subject to this Notification and this Privacy & Use policy.
Jun 10, 2026 · via cisa.gov
Development Challenge Governments are deploying digital public infrastructure, AI systems, and data-driven services at speed - but without adequate trust frameworks in place. Cybersecurity vulnerabilities, weak data governance, and deepening dependencies on foreign technology, talent, and cloud platforms expose countries to systemic risk. For developing economies, these challenges converge into a crisis of digital sovereignty: limited ability to govern data, regulate AI, build domestic capacity, or ensure the resilience of essential digital services. Retrofitting trust after deployment is costly and often ineffective. World Bank Group The WBG addresses digital trust through an integrated approach that brings cybersecurity, data protection, and responsible AI governance together as a cohesive function - ensuring these protections are built into digital systems from the start, not added as an afterthought once infrastructure is already in place. WBG's engagement spans three interconnected pillars. Foundations establish the legal and regulatory baseline through data protection laws, cybersecurity frameworks, and AI governance architecture, tied directly to government budget support agreements so that the right legal protections are in place before digital infrastructure is built. Capabilities strengthen enforcement institutions - Data Protection Authorities, national Computer Emergency Readiness Teams (CERTs), and cybersecurity bodies - while embedding data rights and digital safety into skills programs. Resilience prepares countries for inevitable incidents through contingency financing and pre-approved response mechanisms. A WBG-supported multistakeholder collaboration, spanning public, private, academic, and civil society organizations, produced the third edition of the Guide to Developing a National Cybersecurity Strategy, delivering streamlined, actionable guidance to help low- and middle-income countries build cybersecurity strategies aligned with national development priorities, with new emphasis on multi-year financing, governance accountability, and policy agility for emerging technologies including AI, IoT, and quantum. In partnership with peer multilateral development banks (MDBs) and international forums, WBG advocates for data governance frameworks reflecting developing economy realities. International
Jun 9, 2026 · via worldbank.org
Conan O'Brien is hosting educational videos for an AI cybersecurity company At long last, a corporate training you might actually enjoy. Cybersecurity AI company Adaptive Security has partnered with famed comedian Conan O'Brien for a 15-part educational video series. These training videos will help Adaptive's clients and their employees to navigate threats such as phishing and deepfakes. Considering how often corporate trainings are a total snoozefest, getting a genuinely funny and smart person to present this critical information seems like a smart, if expensive, move. The clip currently promoting the partnership on Adaptive's website even kicks off with a joke about O'Brien only doing the gig for the money. More broadly, it's great to see a business investing in this type of education to ensure that people really do follow best practices for online safety. The FTC said social media scams cost Americans at least $2.1 billion last year. Companies that might have access to even bigger bank accounts, not to mention sensitive information, make for even juicier targets. And AI tools can make cons awfully convincing and easier to pull off. Luckily, there are plenty of common sense rules you can follow to keep the troublemakers at bay. We aren't lucky enough to have Conan narrating them, but just queue up the monorail episode of The Simpsons to play in the background while you read some of Engadget's top cybersecurity tips for a near-identical experience.
Jun 9, 2026 · via engadget.com
Claude Fable 5 and Claude Mythos 5 Today we’re launching Claude Fable 5: a Mythos-class1 model that we’ve made safe for general use. Fable 5’s capabilities exceed those of any model we’ve ever made generally available. It is state-of-the-art on nearly all tested benchmarks of AI capability, showing exceptional performance in software engineering, knowledge work, vision, scientific research, and many other areas. The longer and more complex the task, the larger Fable 5’s lead over our other models. Releasing a model this capable comes with risks. Without safeguards, Fable 5’s capabilities in areas like cybersecurity could be misused to cause serious damage. We’ve therefore launched the model with safeguards that mean queries on some topics will instead receive a response from our next-most-capable model, Claude Opus 4.8. To release the model both safely and quickly, we’ve tuned these safeguards conservatively—they’ll sometimes catch harmless requests, though they trigger, on average, in less than 5% of sessions. With more capable models arriving in the coming months, we’re working to improve our safeguards and reduce false positives as quickly as we can. For a small group of cyberdefenders and infrastructure providers, we’re also launching Claude Mythos 5. It’s the same underlying model as Fable 5, but with the safeguards lifted in some areas.2 Mythos 5 will initially be deployed through Project Glasswing, in collaboration with the US government, as an upgrade to Claude Mythos Preview. It has the strongest cybersecurity capabilities of any model in the world. Soon, we intend to expand access to Mythos 5 through a broader trusted access program. The capabilities of models like Fable 5 and Mythos 5 have the potential to do profound good for the world. We’ve seen the beginnings of this in Project Glasswing, where the models have helped cyber defenders secure critically important software. We’ve
Jun 9, 2026 · via anthropic.com
Veeam has released security patches to address a critical flaw in its Backup & Replication software that could result in remote code execution.
Tracked as CVE-2026-44963, the vulnerability carries a CVSS score of 9.4 out of a maximum of 10.0.
"A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user," Veeam said in a Tuesday advisory.
It credited watchTowr researcher Sina Kheirkhah for responsibly discovering and reporting the issue. It impacts Veeam Backup & Replication 12.3.2.4465 and all earlier versions of 12 builds.
Veeam has noted that the vulnerability does not affect any version 13.x build of the backup software due to architectural changes introduced in version 13.
The shortcoming has been addressed in Veeam Backup & Replication version 12.3.2.4854.
In March 2026, Veeam resolved multiple critical vulnerabilities in Backup & Replication software that, if successfully exploited, could result in remote code execution.
It's essential that users update to the latest version for optimal version, particularly given that prior vulnerabilities in the program have been exploited by bad actors, including ransomware groups.
Jun 9, 2026 · via thehackernews.com
Go-To Guide: - On May 21, 2026, the New York Department of Financial Services (NYDFS) published two companion industry letters: a guidance on measures regulated entities should consider in a heightened cybersecurity threat environment, and an advisory on the cybersecurity risks posed by frontier AI models. - The Heightened Threat Environment Guidance catalogs specific measures across three categories: reducing the attack surface, improving threat detection and readiness, and strengthening resilience and response. - The Frontier AI Advisory directs CISOs to particular sections of the Heightened Threat Environment Guidance and layers on AI-specific recommendations for vulnerability management, secure coding, and third-party coordination. - Neither publication creates new legal requirements under 23 NYCRR Part 500. Both articulate DFS’s expectations for how regulated entities should calibrate their existing cybersecurity programs when threat conditions escalate. Still, both publications preview examination expectations. On May 21, 2026, NYDFS published two related industry letters addressing cybersecurity preparedness for DFS-regulated financial institutions, insurers, and money transmitters. The first, titled Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment (the Guidance), provides a structured menu of defensive measures entities should consider when cybersecurity risks become significantly elevated. The second, titled Heightened Cybersecurity Risks Associated with Frontier AI Models (the Advisory), warns that certain AI models capable of identifying vulnerabilities and exploits at unprecedented speed and scale will soon become more widely available, and directs entities to prepare now. The two documents are designed to work together: the Advisory identifies the threat, and the Guidance provides recommendations on how to respond. Neither publication creates binding requirements. Both documents state explicitly that they do not alter the obligations under Part 500. The Guidance frames its recommendations as measures entities “should consider” adopting based on their “unique circumstances and operations.” The Advisory states it is “intended to inform
Jun 9, 2026 · via natlawreview.com
- GDIT has expanded its partnership with Splunk to bring AI-powered cybersecurity solutions to federal agencies - The collaboration will focus on zero trust and next-generation security operations centers - Join the 2026 FedCiv Summit to discuss AI adoption, cybersecurity, cloud and more General Dynamics Information Technology and Splunk have signed a strategic collaboration agreement to expand their partnership and deliver artificial intelligence-powered cybersecurity offerings to U.S. federal government customers. As agencies continue to modernize digital infrastructure and strengthen cyber defenses, collaboration between government and industry remains a critical topic across the federal landscape. The 2026 FedCiv Summit will bring together government and industry leaders to discuss AI, cybersecurity and compliance initiatives, cloud and data infrastructure, workforce enablement and enterprisewide modernization efforts. Book your seat now! What Does the GDIT-Splunk Partnership Intend to Pursue? Under the agreement, GDIT said Monday it will combine its mission support and technology integration experience with Splunk’s AI, cybersecurity and data analytics capabilities. The expanded partnership will also facilitate the integration of Splunk’s data platforms into GDIT’s Digital Accelerators and Mission Solutions portfolio to help agencies protect data and devices; secure critical infrastructure; improve cyber resilience; and support compliance with federal cybersecurity requirements. According to GDIT, the partnership will focus on: - Advancing security operations center capabilities through agentic AI-enabled cyber operations - Improving cyber visibility and situational awareness through enhanced data integration using AI - Developing zero trust offerings to protect critical systems What Did Ben Gianni & Bill Rowan Say About the Partnership? “Our expanded partnership with Splunk will enable us to deliver differentiated, scalable solutions that harden our customers’ cyber defenses and empower them to execute their missions with confidence,” said Ben Gianni, senior vice president and chief technology officer at GDIT. Bill Rowan, vice president of sales for Splunk’s public sector,
Jun 9, 2026 · via executivebiz.com
Getty Images/amgun Federal vulnerability management is stuck. A patch wave is coming anyway. Commentary Read more
Republican senators warn surveillance program may lapse after Trump intel pick backlash Cybersecurity Read more
Getty Images/NicoElNino CMMC has moved from planning to enforcement and contractors are feeling it Cybersecurity Read more
Jun 9, 2026 · via federalnewsnetwork.com