Principal Engineer and enterprise systems architect, Venkata Sandeep Dhullipalla, has stressed the need for organisations to embrace Artificial Intelligence-driven cybersecurity systems as digital threats become more sophisticated and difficult to manage using traditional security frameworks. Dhullipalla, who specialises in AI-powered distributed systems, said artificial intelligence is rapidly transforming how organisations manage cybersecurity, system performance and operational risk. According to him, the increasing scale of digital infrastructure across industries has led to a surge in the volume and complexity of cyber threats, exposing the limitations of conventional security models. In a statement, he noted that many organisations still depend on reactive cybersecurity approaches built around rule-based threat detection and post-incident response mechanisms. He argued that such methods are becoming less effective in modern environments where cyber threats evolve in real time. Instead, he advocated for predictive systems powered by machine learning and behavioural analytics that can continuously analyse large volumes of data, detect anomalies and identify vulnerabilities before they escalate into major incidents. “Cybersecurity can no longer be treated as a reactive function. The scale and speed of modern systems require predictive capabilities that allow organisations to identify and mitigate risks before they materialise,” he said. Dhullipalla explained that his work has focused on developing distributed systems that combine artificial intelligence, cloud infrastructure and real-time data pipelines. He noted that in high-volume consumer platforms, reliability and security remain critical to ensuring uninterrupted service delivery. According to him, AI-driven architectures are particularly valuable in distributed environments operating across multiple regions and handling significant volumes of user interactions. He said continuous monitoring enabled by AI allows organisations to detect inefficiencies and vulnerabilities early, reducing the risk of large-scale disruptions. He further observed that the growing adoption of cloud-native technologies and automated development pipelines is driving a shift in how cybersecurity is implemented, with
May 30, 2026 · via guardian.ng
Odessa Scammers Busted, Stealth GPU Cryptominer and More Cybersecurity News This weekâs top cybersecurity: crypto heists, GPU cryptojacking, dev-targeted botnets, and more. Weâve gathered the weekâs most important cybersecurity news. - A new group hit crypto companies via fake interviews and macOS malware. - A stealth GPU miner spread through search spam and AI chatbots. - A vigilante hacker was booted from GitHub and GitLab after posting Microsoft zero-days. - CrowdStrike and Google dismantled a network targeting open-source developers. New group hit crypto firms via fake interviews and macOS malware Researchers at Wiz uncovered a large-scale cryptocurrency theft campaign attributed to a previously unknown group, JINX-0164. Since mid-2025, the attackers have targeted blockchain developers through fake online interviews. During the exchange, the victim was redirected to a spoofed videoconferencing site. There, under the pretext of installing a client or fixing a “technical error,” the developer was persuaded to download an infected file. The groupâs toolkit includes sophisticated malware adapted for both Intel and Apple Silicon architectures: - AUDIOFIX. Disguised as a system audio driver. It steals passwords, SSH keys, crypto wallet data, and sessions from Discord and Telegram. The software enables lateral movement across a companyâs internal network, infiltration of infrastructure, and injection of malicious code into active projects; - MiniRAT. Previously used in a supply-chain attack. It was distributed through a trojanized version of the legitimate npm package @velora-dex/sdk, used in DeFi projects. MiniRAT allows remote command execution and loading of additional modules. Experts note that JINX-0164âs tactics â a focus on crypto, targeting developers via fake recruiting, and the use of specific VPN services (for example, Astrill VPN) â resemble the modus operandi of North Korean groups such as BlueNoroff. However, Wiz found no direct technical overlaps in infrastructure to conclusively tie JINX-0164 to Pyongyang. Stealth GPU miner
May 30, 2026 · via forklog.com
Amazon Best-Selling Author and MSP Titan of the Industry Delivers Urgent Warning — and a Practical Roadmap — to Texas Accounting Professionals HOUSTON, TX, UNITED STATES, May 29, 2026 /EINPresswire.com/ — Roland Parker, Founder and CEO of Impress Computers and Amazon Best-Selling Author of Exposed & Secure: The True Cost of Cybersecurity Inaction, delivered a featured session today at the TXCPA Houston Annual Conference, one of Texas’ premier events for Certified Public Accountants and accounting professionals. Parker’s session, “Cybersecurity for CPAs: Protecting Your Firm, Your Clients, and Your Reputation,” drew a standing-room audience of CPA practitioners, firm partners, and accounting professionals eager to understand the rapidly escalating cyber threats targeting their industry — and what they can do about them. CPA Firms Are High-Value Targets — And Most Don’t Know It Parker opened his presentation with a stark reality check: accounting firms are among the most sought-after targets in the cybercriminal ecosystem, holding vast repositories of sensitive financial data, tax records, Social Security numbers, and privileged client access — yet many operate with security infrastructures that fall far short of the threat they face. “CPA firms sit at the intersection of everything a cybercriminal wants,” Parker told attendees. “You have the data, you have the access, and in many cases, you have a security budget that doesn’t match your risk profile. That combination is exactly what attackers are counting on.” Parker cited real-world breach cases that have devastated accounting firms across the country, including a Texas-based regional CPA firm that paid $180,000 in ransomware demands and lost 40% of its client book, and a solo practitioner who was forced to close his firm after a single Business Email Compromise attack redirected $92,000 in client funds. A Complete Security Framework Tailored for Accounting Professionals A highlight of Parker’s session was his
May 30, 2026 · via kitsapsun.com
By continuing to browse our site you agree to our use of cookies, revised Privacy Policy and Terms of Use. You can change your cookie settings through your browser. The China Council for the Promotion of International Trade (CCPIT) on Friday voiced its firm opposition to the European Union's (EU) draft revision to its Cybersecurity Act, citing that the draft contains obviously unreasonable content. The draft introduces "non-technical risk" factors, and directly links cybersecurity risks to companies from specific countries or specific national backgrounds, seeking to exclude them from relevant EU supply chains, said Wang Yifei, spokesperson for the CCPIT, at a press conference. Wang expressed resolute opposition to these practices, adding that the China Chamber of International Commerce has formally submitted comments to the European side on behalf of Chinese business circles. Excluding suppliers from specific countries on generalized security grounds will not only undermine the legitimate rights and interests of other related operators, including Chinese enterprises, but also weaken the openness, fairness and predictability of the EU's business environment, Wang said. Chinese companies are important partners for Europe in its digital transformation, green transition and industrial upgrading, Wang said, adding that the Chinese business community is willing to work with the European side to promote cybersecurity governance and digital economy development, uphold an open, fair and non-discriminatory market environment, and jointly ensure the stability and smooth operation of global industrial and supply chains. "We call on the European side to fully listen to the opinions of enterprises, industry associations and other stakeholders in the subsequent legislative process," Wang said, urging the EU to delete or revise related rules that are country-specific and discriminatory. The spokesperson called on the European side to prudently assess the impact of the draft on China-EU business cooperation, the EU's own industrial development and
May 30, 2026 · via news.cgtn.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
May 29, 2026 · via youtube.com
B2i Digital, Inc. From Carbon Credits to Cybersecurity: Twelve Companies Present at the June 4 Small Cap Growth Virtual Investor Conference | B2i Digital, Inc. / Key word(s): Financial Advanced Materials, Cybersecurity, Clean Fuels, Diagnostics, Public Safety Technology, and More on the Agenda Direct Access to Management Teams Through Live Presentations, Real-Time Q&A, and One-on-One Meetings NEW YORK, NY – May 29, 2026 (NEWMEDIAWIRE) – B2i Digital, Inc. invites investors to the Small Cap Growth Virtual Investor Conference on June 4, 2026. B2i Digital is the Official Marketing Partner, supporting the conference through digital marketing, social media, and company profiles. Twelve public companies will present. The lineup spans advanced materials, cybersecurity, climate solutions, restaurants and hospitality, clean fuels, electronic components, diagnostics, industrial nanotechnology, public safety technology, renewable power, oil and gas, and wireless technology. Each company has 30 minutes for a live presentation and Q&A. One-on-one meeting requests are available through the VIC site, with replays available on B2i Digital and OTC Markets YouTube channels. “You won’t find a graphene maker, a carbon-credit trader, a synthetic jet fuel developer, and a national restaurant operator on the same conference agenda anywhere else. That mix keeps investors watching all day and minimizes the caffeine needed to stay awake between presenters. When VIC runs a sector-agnostic event the presenting slots sell out, and a full agenda draws the crowd,” said David Shapiro, Chief Executive Officer of B2i Digital. The conference is co-sponsored by Skyline Corporate Communications Group, LLC, a corporate communications and investor relations firm that works with public companies and issuers preparing to go public. Skyline’s team brings deep capital markets experience to the companies it serves, helping management tell their story clearly and reach the right investors. “Our objective is to showcase high growth, innovative companies in front of the people
May 29, 2026 · via eqs-news.com
From Carbon Credits to Cybersecurity: Twelve Companies Present at the June 4 Small Cap Growth Virtual Investor Conference Advanced Materials, Cybersecurity, Clean Fuels, Diagnostics, Public Safety Technology, and More on the Agenda Direct Access to Management Teams Through Live Presentations, Real-Time Q&A, and One-on-One Meetings NEW YORK, NY - May 29, 2026 (NEWMEDIAWIRE) - B2i Digital, Inc. invites investors to the Small Cap Growth Virtual Investor Conference on June 4, 2026. B2i Digital is the Official Marketing Partner, supporting the conference through digital marketing, social media, and company profiles. Twelve public companies will present. The lineup spans advanced materials, cybersecurity, climate solutions, restaurants and hospitality, clean fuels, electronic components, diagnostics, industrial nanotechnology, public safety technology, renewable power, oil and gas, and wireless technology. Each company has 30 minutes for a live presentation and Q&A. One-on-one meeting requests are available through the VIC site, with replays available on B2i Digital and OTC Markets YouTube channels. “You won’t find a graphene maker, a carbon-credit trader, a synthetic jet fuel developer, and a national restaurant operator on the same conference agenda anywhere else. That mix keeps investors watching all day and minimizes the caffeine needed to stay awake between presenters. When VIC runs a sector-agnostic event the presenting slots sell out, and a full agenda draws the crowd,” said David Shapiro, Chief Executive Officer of B2i Digital. The conference is co-sponsored by Skyline Corporate Communications Group, LLC, a corporate communications and investor relations firm that works with public companies and issuers preparing to go public. Skyline’s team brings deep capital markets experience to the companies it serves, helping management tell their story clearly and reach the right investors. “Our objective is to showcase high growth, innovative companies in front of the people who would want to understand and learn about them, and a
May 29, 2026 · via newmediawire.com
Michigan House Bill 6011 was introduced last Thursday, and it would require operators of solar energy facilities to create and implement cybersecurity measures. According to the bill, operators of qualifying solar facilities would be required to maintain "reasonable security measures" to protect "safety-critical systems" from cyber attacks that could impair safe operations. The bill requires operators to implement a risk-based cybersecurity and resilience program aligned with recognized standards such as guidance from either the National Institute of Standards and Technology or the Cybersecurity and Infrastructure Security Agency. The cybersecurity program may include cyber risk identification, access controls, network/system segmentation, supply-chain risk management and periodic review and testing. Operators would also have to maintain an incident response plan that coordinates with emergency responders. However, the bill states that these notifications do not impose new duties or liabilities on emergency responders. If a cybersecurity incident were to happen, for a "material cybersecurity incident," operators must notify the Michigan State Police and the local emergency management coordinator within 24 hours of discovery, when practicable. Within 72 hours, operators must provide a written high-level summary that avoids disclosing sensitive security details. The Attorney General may request documentation only when tied to a specific incident or complaint. It explicitly forbids routine or programmatic audits. The bill said that knowingly or recklessly violating the section could result in civil fines up to $25,000 per day per violation. The Attorney General would have to provide notice and up to 30 days to cure violations before seeking penalties. The bill was introduced by Representative Reggie Miller (D-District 31) and was cosponsored by four other Democrats. The bill was referred to Committee on Communications and Technology. ©2026 the Midland Daily News, Distributed by Tribune Content Agency, LLC.
May 29, 2026 · via govtech.com
Telecom cybersecurity alliance sets an example for threat intelligence sharing How shared intelligence could reshape cybersecurity across industries Key takeaways - Telecom providers are showing that cyber defense works better together than alone. - AI is compressing the timeline between vulnerability discovery and exploitation. - Real-time threat sharing helps teams respond faster and avoid reinventing the wheel. - This alliance could become a model for cross-industry cybersecurity collaboration. - As public-sector support weakens, private-sector coordination may need to fill the gap. - Fear of legal exposure still stands in the way of broader intelligence sharing. What is the C2 ISAC, and why was it created? Eight providers of telecommunications services in the U.S. are circling their cybersecurity wagons to now share threat intelligence via the next iteration of a Communications Cybersecurity Information Sharing and Analysis Center (C2 ISAC). AT&T, Charter, Comcast, Cox, Lumen Technologies, T-Mobile, Verizon, and Zayo have established C2 ISAC in the wake of cyberattacks such as the Salt Typhoon campaign successfully accessed call records and communications data. More troubling still, advances in artificial intelligence (AI) are raising concerns about software vulnerabilities that might be discovered and then exploited in a matter of hours. Rather than trying to combat these attacks independently, telecommunication providers are extending previous efforts to share threat intelligence in real time to enable them to both detect and respond to attacks faster and, ultimately, contain costs. Otherwise, each telecommunications provider winds up spending time, money and effort on replicating threat intelligence research that may have already been done elsewhere. Could this model work in other industries? The question the C2 ISAC alliance raises, of course, is to what degree might similar alliances be formed across other industry sectors or, for that matter, between organizations operating in completely different industries. The simple fact of the
May 29, 2026 · via blog.barracuda.com
Since 2006, Dark Reading has been at the forefront of covering cybersecurity, providing deep insights and analysis beyond the headlines. All those major news events? We were there. Shifts in technology trends? We wrote about them. Enjoy this special anniversary coverage celebrating where we've been and what's next. Name That Toon: Mark of (Cybersecurity) Progress As part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry's last two decades. The cybersecurity industry has undergone seismic shifts driven by wave after wave of technological transformation — from the early days of signature-based antivirus and perimeter firewalls protecting on-premises networks, through the cloud migration that dissolved those perimeters entirely, to the mobile revolution that put corporate data on devices in employees' pockets and coffee shops worldwide. And now, defenders are gearing up for the AI transformation. The Internet of Things expanded the attack surface with billions of connected devices, many with laughably weak security controls. Remote work, turbocharged by the pandemic, shattered whatever remained of the network perimeter, forcing enterprises to embrace zero-trust models where every access request is verified regardless of origin. Through it all, threat actors evolved from lone hackers to sophisticated criminal enterprises and nation-state operations, wielding zero-days and supply-chain attacks with surgical precision. Dark Reading turned 20 on May 1, and to celebrate, we brought back the Name That Toon contest. We asked readers to send us their most creative cybersecurity-related caption that describes what is happening in the cartoon. The winning caption, "Look, I know, but this was the best AI stack we could afford," comes to us by way of Prasen Shelar, co-founder and CEO of AI-startup Axari via LinkedIn. Thanks to all the readers who participated! Click here for all our DR20 content.
May 29, 2026 · via darkreading.com
orrstown financial services - Notified Of Third-Party Vendor Cybersecurity Incident On May 21, 2026
RefinitivLess than 1 min read
© Copyright Thomson Reuters 2026. Click For Restrictions - https://agency.reuters.com/en/copyright.html
Login or create a forever free account to read this news
May 29, 2026 · via tradingview.com
Getty Images/iStockphoto EO 14390 raises stakes for enterprise cybersecurity Reframing cybercrime as a national security issue, EO 14390 could lead to stronger links between government and the private sector. Find out what it means for enterprise security. For years, federal cybersecurity policy has primarily focused on protecting government systems and critical infrastructure. Executive Order 14390: "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens" signals a broader shift in emphasis. Signed on March 6, 2026, the order reframes cybercrime not only as a national security threat, but also as an economic and societal threat that directly affects citizens, businesses and the digital ecosystem on which they depend. The executive order lands amid escalating ransomware campaigns, AI-enabled fraud schemes, large-scale phishing operations and financially motivated attacks linked to transnational criminal organizations. Unlike earlier cybersecurity directives that focused heavily on federal modernization, critical infrastructure protection and software supply chain security, EO 14390 emphasizes operational disruption of cybercriminal networks, victim restitution and expanded coordination between government agencies and the private sector. For enterprise security leaders, the order does not immediately impose a new regulatory framework. However, it signals the direction of federal cyber policy, with greater emphasis on private-sector accountability, expanded information sharing, increased scrutiny of enterprise cyber practices and stronger expectations for cooperation with government-led cyberdefense initiatives. Skadden, Arps, Slate, Meagher & Flom LLP, in its legal analysis of EO 14390, said that it "is further indication that the Trump administration intends to broaden the role of the private sector in the government's offense-oriented approach to cyberthreats." In practical terms, the order raises an important question for businesses. Is cybersecurity still just an IT risk, or is it becoming a broader legal, operational and governance obligation tied directly to national resilience? A sign of the times The order was issued as the
May 29, 2026 · via techtarget.com
Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints," Arctic Wolf said. "Threat actors disguised the credential stealer payload as a Fortinet endpoint update, silently executing the malicious executable through PowerShell." The activity, observed by the cybersecurity company in May 2026, involves the exploitation of CVE-2026-35616 (CVSS score: 9.1), a critical pre-authentication API access bypass leading to privilege escalation. The issue was addressed by Fortinet in FortiClient EMS 7.4.7 and later. A successful compromise is followed by the threat actor taking steps to modify configurations to defer firmware upgrade reminders, as well as modifying a Remote Access Profile configuration and endpoint policy to insert a malicious script for execution on endpoint devices. "The observed execution pattern suggests that threat actors used FortiClient's own management pathway to push malicious PowerShell commands to managed endpoints in a way that resembled legitimate management operations," Arctic Wolf said. "Once the threat actors had a route to modify EMS-managed configuration, every managed endpoint became a potential execution target without requiring a separate intrusion path to each device." In addition, the attack has been found to leverage "fortitray.exe," a legitimate executable associated with FortiClient to launch a .cmd script file using "cmd.exe." The .cmd script is designed to invoke a Base64-encoded PowerShell script that, in turn, is responsible for downloading a malicious payload, running it, and exfiltrating the results to "83.138.53[.]110" via an HTTP POST request. The executable, named "FortiEndpoint_Patch.exe," masquerades as an update, but, in reality, is a previously unreported Windows information stealer capable of harvesting sensitive data, such as passwords, cookies, and autofill details such as credit card information, addresses, and phone numbers, from Chromium- and Gecko-based browsers.
May 29, 2026 · via thehackernews.com
Digital Growth Is Outpacing Cybersecurity at Credit Unions. Here’s How to Close the Gap By Brad LaPorte, Chief Marketing Officer at Morphisec Simple Subscribe Subscribe Now! Digital transformation has unlocked remarkable possibilities for credit unions, including seamless mobile banking, AI-driven personalization, and hybrid member services that were unimaginable a decade ago. But this growth comes with a cost that many credit union leaders are only beginning to fully appreciate—the cybersecurity frameworks they have in place were built years ago and never designed for today’s threat environment. And the gap between their digital ambitions and the reality of their security readiness is widening fast. Reality check: The numbers tell a stark story. According to the Sophos State of Ransomware in Financial Services 2025 report, 64% of financial services organizations experienced a ransomware attack in the past year, and the mean recovery cost following a ransomware attack now sits at $1.53 million. And payment doesn’t preclude you from future attacks—80% of organizations that pay the ransom are attacked again within 12 months. For member-owned institutions where trust is the foundational currency, that kind of disruption is not just a financial hit; it’s one that could put the institution’s future at risk The Threat Landscape Has Changed. Most Defenses Have Not. Ransomware is only part of the story. Attackers are increasingly using AI to scale phishing and social engineering campaigns at a speed and sophistication that traditional defenses cannot match. IBM’s X-Force Threat Intelligence Index reported an 84% year-over-year increase in infostealing malware designed to steal credentials and bypass conventional security tools. In early 2025, the increase reached 180%. What is becoming clear is that the same AI tools credit unions are adopting to improve fraud detection and member experience are being weaponized by adversaries to evade the security controls protecting those very
May 29, 2026 · via thefinancialbrand.com
The UAE Cybersecurity Council has entered into a landmark partnership with QuantumGate to launch the national Crypto Discovery Tool (CDT). Engineered in Abu Dhabi and meticulously customized to the rigorous mandates of the UAE National Cryptography Center, this pioneering solution solidifies the nation’s trajectory toward an ironclad, quantum-safe future. By integrating deep tech innovation with sovereign defense strategies, this elite collaboration establishes the UAE as a leader in the global race to operationalize large-scale, post-quantum migration frameworks across critical national infrastructure. Operationalising Strategic Control and Absolute Visibility At the core of this enterprise-grade deployment is a definitive mandate: organizations cannot defend what they cannot see. The Crypto Discovery Tool empowers critical public and private sector entities with comprehensive, end-to-end visibility across dense and complex digital ecosystems. By automating the discovery of embedded cryptography and providing an exhaustive inventory of cryptographic assets, the CDT translates macro national ambitions into granular operational readiness. This unparalleled visibility ensures that decision-makers can proactively mitigate cryptographic vulnerabilities long before quantum threats disrupt market stability. Key Pillars of the National Crypto Discovery Tool To guarantee continuous protection and regulatory agility, the tool is built upon an advanced, enterprise-focused operational architecture: - Automated Asset Mapping: Eliminates blind spots by generating an active, real-time map of all hidden and embedded cryptographic infrastructure. - Agile Risk Management: Provides a structured, risk-aware blueprint to systematically harden legacy encryption and direct migration paths. - Modular Compliance Engine: Designed to evolve alongside emerging cybersecurity directives, ensuring organizations remain structurally audit-ready. Continuous Monitoring and Ecosystem Integration Beyond immediate vulnerability discovery, the CDT introduces sophisticated continuous monitoring capabilities. This persistent oversight feeds cryptographic posture data directly into the UAE’s broader security network via the National Cybersecurity Index platform. By centralizing reporting data, the tool powers the newly established UAE National PQC Index, equipping the
May 29, 2026 · via intlbm.com
Gov't announces measures to strengthen private sector cybersecurity response systems Published: 29 May. 2026, 13:43 The government announced on Friday a series of measures to strengthen its private sector cybersecurity response systems. The plan was unveiled at the ninth meeting of science and technology ministers amid rapid advances being made in the AI sector, which has drastically accelerated the discovery and weaponization of software vulnerabilities, the Ministry of Science and ICT said. Under the plan, the government will establish an emergency system under the Office of National Security. The system will use AI to detect software vulnerabilities, patch them and jointly respond to digital security breaches. The government will also create a vulnerability management center under the Korea Internet & Security Agency, which will take charge of vulnerability detection and patching. In the private sector, the government will monitor the cybersecurity readiness of approximately 1,200 major companies in critical industries, including the finance and medical fields. For smaller firms, it plans to provide technical support, such as web tools, to help enhance their cybersecurity capabilities. The government also plans to expand cooperation with major tech companies, including its recent partnership with OpenAI, and related agencies in friendly nations for digital defense response and information sharing. Korea aims to transform its cybersecurity system into one based on homegrown AI technologies starting in 2027 and execute various projects aimed at establishing AI security sovereignty, the Science Ministry added. Yonhap with the Korea JoongAng Daily To write comments, please log in to one of the accounts. Standards Board Policy (0/250자)
May 29, 2026 · via koreajoongangdaily.joins.com
The cybersecurity community is blasting Microsoft for threatening legal action against a disgruntled researcher who’s been exposing Windows vulnerabilities outside the company’s normal disclosure process. The controversy deals with a researcher known as “Nightmare Eclipse,” who has published six unpatched “zero-day” flaws in recent weeks. This includes a proof-of-concept exploit for a Windows vulnerability known as BlueHammer that can allow an attacker to escalate their privileges to the administrator level. Researchers normally submit such findings to the Microsoft Security Response Center (MSRC) for patching to prevent hackers from exploiting them. But Nightmare Eclipse has deliberately ignored the responsible disclosure route, citing claims that Microsoft mistreated them. “They mopped the floor with me and pulled every childish game they could,” the researcher wrote last month, without elaborating. “It was soo bad at some point I was wondering if I was dealing with a massive corporation or someone who is just having fun seeing me suffer but it seems to be a collective decision.” The tension only escalated after Nightmare Eclipse disclosed more flaws this month, writing: “Microsoft has chosen to make this worst instead of resolving the situation like adults, they pulled every childish game possible.” On Wednesday, the software giant responded with its own blog post that reiterated the need for responsible disclosure to prevent hackers from abusing such flaws and contained a legal threat. “Uncoordinated disclosures that put proof-of-concept code for unpatched vulnerabilities into the hands of bad actors are never justifiable and have real-world consequences,” the company wrote, later adding: “Our Digital Crimes Unit will continue bringing cases against these actors and those that enable their criminal activity – coordinating as needed with law enforcement around the world.” Microsoft goes on to say “any disclosure outside proper coordination” could harm its customers. But that last part about pursuing
May 29, 2026 · via pcmag.com
AMSTERDAM — One of the big topics, especially in light of the SpaceX initial IPO documents, is the future of orbital data centers and the possibilities of moving compute to space. Experts at SmallSat Europe tried to decipher between the hype and reality of orbital data centers — in terms of both technology and economics. Dr. Paul Struhsaker, CEO of engineering and technology consulting firm Arrasar Partners, who formerly worked as a corporate vice president at semiconductor company AMD. He described the buzz as a reaction to terrestrial challenges. “There are a lot of constraints [to putting data centers on Earth],” Struhsaker said. “Then you have the question — Why don’t we put them all in space? Here, there is unlimited energy, for example. However, you need custom silicon to put data centers in space.” There a number of players beginning to emerge in this space with the likes of SpaceX, Starcloud, Blue Origin’s Project Sunrise, Google with Planet Lab, in addition to Sophia Space, Axiom Space, Aetherflux, and others. While Struhsaker said he understands the logic behind these moves, there are a number of issues that will need to be addressed. He spoke of the level of compute that players want to put in orbit will be “orders of magnitude more than the constellations we have now.” In addition, the way processors and chips go through iteration will create a new set of problems. “An AI data center blade lifespan is five years. AI has made this even worse. Instead of a five-year span, the next generation of processors come out every two years … we’re now shortening the lives of the hardware in the data center. That creates a lifespan issue for satellites in orbit.” Compute lifespan and replacement is a significant logistics issue, which will also bring
May 29, 2026 · via satellitetoday.com
For over a decade, the default enterprise infrastructure strategy was simple: migrating as much as possible to the cloud. Today, however, this ‘cloud-first’ mandate is no longer adequate for modern security and business demands. Today’s CISOs and CIOs are dealing with a complex threat landscape defined by accelerating AI adoption, geopolitical conflict, fragile supply chains, data sovereignty mandates, sophisticated identity-driven attacks, and intense cost scrutiny. In addition, for numerous organizations, the era of unbridled cloud expansion is colliding with harsh economic realities, as escalating outbound data transfer charges and cloud storage fees, fragmented provisioning, and vendor lock-in erode the cloud’s initial value proposition. Although the public cloud offers unparalleled velocity for startups, more mature, steady-state workloads often face unforeseen financial burdens. Cloud investment was originally supposed to deliver efficiency, but 69% of CFOs now believe that between 10% to 30% of cloud spending is wasted. For today’s enterprise, the goal has shifted from being “cloud-first” to “control-first.” The Control-First Placement Strategy A control-first approach doesn’t mean abandoning the public cloud entirely. Instead, it demands a strategic, nuanced decision on where to place each workload to achieve the optimal balance of risk reduction, cost efficiency, performance, resilience, and governance. This may mean repatriating critical workloads to hybrid, private, edge, or on-premises environments. Public cloud repatriation, the movement of workloads from public cloud environments back to private infrastructure or alternative hosting providers, has become one of the most discussed trends in enterprise IT. The real discussion now focuses on placement strategy. Where should AI workloads run for the best balance of performance, cost, governance, and resilience? This is why hybrid cloud has moved from being a transitional architecture to becoming the preferred operating model for AI-driven enterprises. New Security Requirements Drive Infrastructure Decisions The World Economic Forum’s 2026 cybersecurity outlook points to
May 29, 2026 · via cybersecurity-insiders.com
Colorado cybersecurity office announces mass layoffs following scathing audits The Colorado office responsible for overseeing the state's cybersecurity and digital infrastructure announced sweeping layoffs and a major restructuring effort this week following years of blistering state audits that exposed serious security deficiencies. The Colorado Office of Information Technology said on Wednesday it is eliminating 173 positions, which is roughly 16% of its workforce. Leaders are calling it a "transformational change" aimed at modernizing the agency and strengthening the state's cyber defenses. The office oversees a wide range of digital services used by Coloradans every day, including unemployment benefits, workers' compensation systems, driver's licenses and food assistance programs. But in recent years, the agency has come under intense scrutiny after multiple state audits uncovered dozens of vulnerabilities that auditors warned could leave Colorado at risk of a major cybersecurity breach. The office has been the subject of four audits in recent years. Those reviews identified deficiencies in areas including contingency planning, incident response, and risk management. "We have to recognize the threat is getting a lot bigger," said David Edinger, the office's outgoing CEO and executive director. "We've got to get a lot more mature fast." Edinger said incremental fixes would no longer be enough to address the agency's problems. "Tweaks won't cut it," he said, describing the restructuring as necessary to overhaul outdated systems and practices. Edinger is among the employees leaving the agency during the restructuring. Sarah Tuneberg, the state's new chief information officer, said the office must fundamentally rethink how it operates in order to meet modern cybersecurity challenges. "We're radically transforming the way we think about things to be the modern technology organization, like Google, like Microsoft, like Spotify," Tuneberg said. State lawmakers who have closely monitored the office say the changes are overdue. State Rep. Brianna
May 29, 2026 · via cbsnews.com