Why AI Cybersecurity Programs Are More Important Than Ever AI has opened up many doors for businesses and individuals alike, but those open doors sometimes let bad actors follow close behind. AI systems, programs, and platforms are perhaps some of the most transformative tools to have entered mainstream industries in the past five years. As useful as many AI tools have been, however, they’ve also introduced or otherwise exacerbated several problems, with one of the most important being security. This issue has necessitated the development of AI security measures. What is AI Security? AI security doesn’t refer to a single program or practice, but instead a series of processes designed to work in conjunction with each other to limit unauthorized access to an organization’s AI systems, data pipelines, models, users, permissions, cloud infrastructure, and connected applications. Though many of these processes incorporate AI in some way, some benefit from human oversight and intervention. For example, while an organization may use AI to improve their threat detection and incident response programs, they may still rely on a cybersecurity team to actually address the issues those programs flag. Ultimately, both AI and security experts work together to enhance an organization’s security posture by minimizing its exposure to external and internal threats. How a given security team approaches this may differ depending on the tools they have available to them and the amount of data they need to protect; a healthcare enterprise tasked with keeping patient records safe will likely invest more in AI security than a small bakery, for instance. How AI Security Works to Keep Sensitive Data Safe Given how many industries have adopted AI to some degree—customer service, software development, document review, marketing—AI security has become as much of a business governance issue as it is a response to technical
May 28, 2026 · via desmoinesregister.com
Most cybersecurity professionals have higher confidence in CISOs if they have experienced a major cyber-attack or cybersecurity incident, an industry poll has revealed. Published by cybersecurity certification body ISC2, the research asked 796 people working in cybersecurity for their views about their cybersecurity leadership. Over three quarters of those agreed that a cybersecurity leader’s credibility is enhanced if they have already been in charge during a real, high-profile security incident. Overall, 35% said they “strongly agree” and a further 41% said they “somewhat agree.” Under one in ten said they didn’t agree. The outcome or potential blame around the previous cyber incident does not seem to play a role in the trust in the cybersecurity leader, only that the experience they had during the incident mattered. “Leading through a major cybersecurity incident can build credibility because it gives leaders practical experience, perspective and the ability to stay composed under pressure,” Scott Beale, CEO of ISC2 told Infosecurity. “These findings suggest cybersecurity professionals value leaders who can apply those lessons to make better decisions, communicate with clarity and strengthen resilience across the organization,” he added. What Good Cybersecurity Leadership Looks Like When asked whether technical hands-on experience or strategic and executive leadership experience were more valuable in a cybersecurity leader, the majority of respondents (71%) said that it was important for them to have both. However, of those who preferred one over the other, 18% said that cybersecurity leaders should have strong strategic and executive leadership experience. Read more: Five Critical Skills for the Modern Day CISO Many commented that strong leadership traits such as the ability to drive teams through high-stress situations, business acumen and the ability to articulate complex ideas and technologies in simple business-oriented terms were essential for the role. Just 11% said extensive hands-on technical or incident
May 28, 2026 · via infosecurity-magazine.com
Discover how security leadership can help small businesses improve cybersecurity decision-making, clarify responsibilities, and prepare for cyber incidents. Security leadership is not always about building a full cybersecurity department. It is about establishing clear responsibility for cyber-related decisions when issues arise or are identified. Key Takeaways: - Small businesses should consider designating a clear owner for cybersecurity-related decisions, even if that person is not a technical specialist. - Security leadership can help turn scattered tools and good intentions into clearer priorities, defined roles, and a coordinated response plan. - Basic cybersecurity measures such as multi-factor authentication, backups, employee training, vendor checks, and incident planning, can make a meaningful difference. - Your bookkeeper gets an urgent email that looks like it came from you. A vendor portal asks for a password reset. An employee’s laptop starts acting strange right before payroll. Who decides what happens next? For many small businesses, the honest answer might be “whoever notices first.” That approach may become more difficult when customer data, payroll, or operations are impacted. Security leadership provides a dedicated owner to establish a plan before employees make uninformed calls under pressure. Someone has to own the security decisions. You do not necessarily need a Chief Information Security Officer to take cybersecurity seriously. But, you should consider a designated person who can help ensure security responsibilities do not fall between the cracks. That person might be the owner, an operations manager, an IT lead, an office manager, or an outside managed IT or security partner. The title matters less than the job. Someone should know which systems matter most, who has access, how backups work, who to call during an incident, and which risks need attention first. This is also where cybersecurity has shifted. When NIST released Cybersecurity Framework 2.0 in 2024, it added
May 28, 2026 · via acrisure.com
A new bill was introduced in the Michigan House of Representatives that would add new cybersecurity requirements for solar farms. Michigan House Bill 6011 was introduced last Thursday, and it would require operators of solar energy facilities to create and implement cybersecurity measures. Advertisement Article continues below this ad According to the bill, operators of qualifying solar facilities would be required to maintain “reasonable security measures” to protect “safety-critical systems” from cyberattacks that could impair safe operations. The bill requires operators to implement a risk-based cybersecurity and resilience program aligned with recognized standards such as guidance from either the National Institute of Standards and Technology or the Cybersecurity and Infrastructure Security Agency. The cybersecurity program may include cyber risk identification, access controls, network/system segmentation, supply-chain risk management and periodic review and testing. Operators would also have to maintain an incident response plan that coordinates with emergency responders. However, the bill states that these notifications do not impose new duties or liabilities on emergency responders. If a cybersecurity incident were to happen, for a “material cybersecurity incident,” operators must notify the Michigan State Police and the local emergency management coordinator within 24 hours of discovery, when practicable. Advertisement Article continues below this ad Within 72 hours, operators must provide a written high-level summary that avoids disclosing sensitive security details. The Attorney General may request documentation only when tied to a specific incident or complaint. It explicitly forbids routine or programmatic audits. The bill said that knowingly or recklessly violating the section could result in civil fines up to $25,000 per day per violation. The Attorney General would have to provide notice and up to 30 days to cure violations before seeking penalties. Advertisement Article continues below this ad The bill was introduced by Representative Reggie Miller (D-District 31) and was cosponsored
May 28, 2026 · via michigansthumb.com
Hottest cybersecurity open-source tools of the month: May 2026 Presented here is a curated selection of noteworthy open-source cybersecurity solutions that have drawn recognition for their ability to enhance security postures across diverse settings. Pipelock: Open-source AI agent firewall AI coding agents run with shell access, environment variables containing API keys, and unrestricted internet connectivity, creating a single point of failure where one compromised tool call can leak credentials to an attacker-controlled domain. Pipelock, an open-source security harness developed by Joshua Waldrep under the PipeLab project, addresses this exposure by inserting an enforcement layer between agents and the network. Version 2.3.0 shipped with class-preserving request redaction and generic SSE streaming response scanning. AIMap: Open-source tool finds and tests exposed AI endpoints Public-facing Ollama servers, MCP endpoints, and inference proxies have multiplied across the internet over the past year, often deployed without authentication or rate limits. AIMap is an open-source platform that finds these systems at internet scale, fingerprints them, scores their exposure, and runs protocol-specific attack tests against authorized targets. Rustinel: Open-source endpoint detection for Windows and Linux Open-source endpoint detection has long been split between Windows-focused tools built around Sysmon and Linux tools built around eBPF or auditd. Defenders running mixed environments have had to stitch together separate pipelines, separate rule sets, and separate maintenance burdens. Rustinel, a Rust-based endpoint agent, is an attempt to collapse that work into a single codebase. Sandyaa: Open-source autonomous security bug hunter Source code auditing has traditionally relied on static analyzers that flag long lists of potential issues, leaving engineers to sort bugs from noise. A new open-source project from offensive-security firm SecureLayer7 takes a different route, using LLMs to read a codebase, trace how data moves through it, and produce working exploit code for the vulnerabilities it confirms. Their open-source tool, called
May 28, 2026 · via helpnetsecurity.com
Preparing for the World Stage This summer, millions of fans from around the globe will pour into stadiums, transit hubs, and entertainment districts across the nation to experience the thrill of the FIFA World Cup 2026™. Between hosting matches, team base camps, Fan Fests, and training centers, more than 20 states are supporting the World Cup in some capacity–nearly half the nation. An enormous amount of behind-the-scenes coordination is underway to ensure fans, families, and athletes have a safe, seamless, and unforgettable experience. In fact, the Department of Homeland Security (DHS) has designated all 78 matches with Special Event Assessment Rating (SEAR) Level 1 and 2, underscoring the significance of the event. This is a 240% increase of similarly rated events compared to an average year. As part of the coordinated DHS-wide preparations, the Cybersecurity and Infrastructure Security Agency (CISA) has been working with partners in the government at all levels and private sector, as well as with states and host cities to strengthen preparedness, sharpen communication, and make sure communities are ready. A Host City Getting Ready for the Global Stage CISA’s collaboration with the city of Seattle is just one standout example of how CISA is working with host cities to help ensure all participants can celebrate safely. Through immersive, scenario driven exercises at Lumen Field, and in coordination with the region’s transit system, CISA helped local partners stress test plans, strengthen coordination and operational readiness, and build confidence that fans can enjoy a secure experience while they focus on the game. These collaborative efforts also provided valuable feedback and lessons learned for the stakeholders involved, enabling ongoing improvements to security strategies for future events. Inside the Lumen Field Full Scale Exercise A full-scale exercise is a major production, designed to provide a simulated crisis response experience. More
May 28, 2026 · via cisa.gov
Latest U.S. Iran War Jill Biden Interview World Politics Entertainment HealthWatch MoneyWatch Crime Space Sports Brand Studio The Free Press Local News Atlanta Baltimore Bay Area Boston Chicago Colorado Detroit Los Angeles Miami Minnesota New York Philadelphia Pittsburgh Sacramento Texas Live CBS News 24/7 Baltimore Bay Area Boston Chicago Colorado Detroit Los Angeles Miami Minnesota New York Philadelphia Pittsburgh Sacramento Texas 48 Hours 60 Minutes Shows 48 Hours 60 Minutes CBS Evening News CBS Mornings CBS Morning News CBS Reports CBS Saturday Morning The Daily Report The Dish Face the Nation Sunday Morning The Takeout Things That Matter The Uplift CBS News Investigates CBS News Confirmed Podcasts Newsletters Download Our App CBS News Team Executive Team Brand Studio Paramount+ Join Our Talent Community RSS Feeds Colorado | News Weather Sports Video Your Reporters Latest News Your Investigators Politics Health Business News Team Share A News Tip Making Ends Meet Colorado 150 Elevating Black Voices Elevating Latino Voices First Alert Weather School Closings Weather Cams Share Weather Pics Dog Walk Forecast Weather School All Sports Denver Broncos Denver Nuggets Colorado Rockies Colorado Avalanche CBS Sports HQ Odds Jefferson County News Arapahoe County News Adams County News Douglas County News Northern Colorado News Aurora News Denver News Boulder & Foothills News Colorado Mountain News Contests Colorado Review Future Leaders Adopt A Pet Your Local Dish Wednesday's Child Advertise with Us TV Program Guide Sponsored Events Sign Up for Alerts Employment Contact Us Memorials Watch CBS News Office in charge of cybersecurity for Colorado announces mass layoffs Changes in Colorado’s Office of Information Technology are happening after a blistering state audit. View CBS News In CBS News App Open Chrome Safari Continue
May 28, 2026 · via cbsnews.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
May 28, 2026 · via youtube.com
Venza Named 2026 “TravelTech Cybersecurity Solution of the Year” By TravelTech Breakthrough Venza Named 2026 “TravelTech Cybersecurity Solution of the Year” By TravelTech Breakthrough Venza, a leading provider of cybersecurity, data protection, and compliance solutions for the hospitality industry, today announced it has been awarded “TravelTech Cybersecurity Solution of the Year” in the 4th annual TravelTech Breakthrough Awards program conducted by TravelTech Breakthrough, a leading independent market intelligence organization that evaluates and recognizes standout travel technology companies, products and services around the globe. The Venza Cybersecurity & Threat Protection system offers hotels that operate across distributed locations, shared technology environments, and high-volume payment and guest data workflows full coverage protection. The platform provides end-to-end visibility into cybersecurity risk and compliance across properties and portfolios, enabling hotel executives to clearly understand exposure, prioritize action, and measure progress. Venza brings together risk management, PCI compliance, and human-centric security awareness into a single integrated system. This includes expert-led PCI guidance, continuous vulnerability scanning, penetration testing, and hospitality-specific training and social engineering simulations designed around real-world hotel threats. “We’re proud to receive ‘TravelTech Cybersecurity Solution of the Year’ from TravelTech Breakthrough. We believe our core innovation is reframing cybersecurity and compliance as a business-critical operational discipline rather than a purely technical function. Uncovering exposures early and turning those findings into action, before they can be used against you, is essential,” said James Filsinger, CEO of Venza. “Through deep hospitality expertise and a technology-first approach to cybersecurity, we will continue to deliver technology that addresses the industry’s most persistent and complex security challenges, setting the standard for how travel and hospitality organizations protect sensitive data in an increasingly complex threat landscape.” The mission of the annual TravelTech Breakthrough Awards program is to recognize the innovators transforming the global travel landscape through technology. The program conducts
May 28, 2026 · via hospitalityupgrade.com
Live Now
All times easternNOW - 6:00 AM
6:00 AM
6:30 AM
7:00 AM
7:30 AM
8:00 AM
Fox Business Channel
Mornings With Maria
6:00 AM - 7:00 AM
Mornings With Maria
7:00 AM - 8:00 AM
Mornings With Maria
8:00 AM - 8:30 AM
Fox News Channel
Fox & Friends
6:00 AM - 7:00 AM
Fox & Friends
7:00 AM - 8:00 AM
Fox & Friends
8:00 AM - 8:30 AM
Fox Weather Channel
Fox News Radio
May 27, 2026 · via foxbusiness.com
Making third-party information risk governable, comparable, and transferable Third-party information risk has become an enterprise management problem Enterprises rely on vendors, suppliers, platforms, processors, cloud providers, subcontractors, and other service organizations to run critical operations, handle sensitive and regulated information, support customer outcomes, and maintain business continuity. That dependence creates third-party information risk, which is the possibility that information outside the enterprise’s direct control is not protected, governed, processed, shared, used, or recoverable in a way that aligns with the organization’s risk appetite, legal obligations, contractual commitments, and continuity expectations. Cybersecurity failure is only one expression of this exposure. Third-party information risk can also create operational disruption, privacy impact, regulatory exposure, contractual loss, revenue impairment, reputational harm, uninsured financial loss, and reduced resilience. The central question is whether the organization can understand the residual exposure created by third-party dependence and use that understanding to make better decisions, in terms of which vendors to approve, which risks to remediate, which exceptions to accept, which exposures to aggregate, which risks to transfer, and how performance compares across vendors and peers. Most large enterprises have built Third-Party Risk Management programs to respond to this challenge. In principle, those programs should identify the full vendor population, tier vendors by inherent risk, and evaluate each relationship based on data sensitivity, business criticality, connectivity, regulatory exposure, geography, substitutability, and operational dependency. They request and review questionnaires, certifications, audit reports, and submitted evidence, then evaluate control gaps, require contractual commitments and insurance, and route exceptions through approval workflows. These activities are necessary, but they are not sufficient. In practice, many organizations do not have the time, staffing, or process capacity to evaluate the full vendor population adequately. Teams often focus on a subset of vendors, the most visible, highest risk, most business-critical, or most urgent relationships. That
May 27, 2026 · via cybersecurity-insiders.com
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms OpenAI on Wednesday hailed its plans to safeguard information and aid cybersecurity defenders in the 2026 midterm elections, including work to combat deepfakes and other forms of artificial intelligence misuse. The announcement builds on commitments from major tech companies in 2024, including OpenAI, to protect elections from AI-infused election interference — efforts that some thought weren’t enough. Government agencies, non-governmental institutes and others have increasingly warned about AI’s ability to have a negative impact on elections even as they advertise its potential for good. OpenAI’s plan has five planks: spreading reliable information about voting and election results, helping with cybersecurity, watermarking deepfakes, enforcing policies that ban users from deploying its tools for election interference, and weeding out political bias in its models. OpenAI highlighted that it has made its Codex Security agentic framework and Trusted Access for Cyber framework available to election officials, and was briefing the National Association of Secretaries of State and the National Association of State Election Directors on its tools. “This is an important moment for cyber defenders across industries, and we believe AI plays a critical role in hardening digital infrastructure — including systems that support elections,” the company said. “OpenAI is committed to building resilience across the infrastructure stack, including in ways that support election execution.” Some elements of OpenAI’s plans aren’t new so much as it’s taking pieces from other announcements and putting them together in one, such as reiterating last week’s partnership with SynthID to add watermarks to images generated with ChatGPT to assist in evaluating whether something is real or a deepfake. One new element of Wednesday’s announcement is that OpenAI has struck a partnership with the Associated Press on sharing election data. One election security expert welcomed the OpenAI announcement.
May 27, 2026 · via cyberscoop.com
JVP announced a strong first quarter for 2026, highlighted by four major portfolio company exits spanning cybersecurity and vertical AI. The international venture capital firm said the transactions demonstrate its long-term investment strategy and continued ability to scale category-leading companies across Israel, the U.S., and Europe. The quarter was led by JVP’s exit from DealHub, generating a return of more than 6x on invested capital. The company was valued at hundreds of millions of dollars in the transaction. JVP helped launch DealHub from Margalit Startup City Jerusalem during its early stages. DealHub developed an AI-powered revenue automation platform designed to help enterprise sales teams manage increasingly complex deal cycles. The company achieved strong adoption among mid-market and enterprise customers, positioning it as an acquisition target in the growing RevOps sector. JVP also benefited from the acquisition of Pyramid Analytics by ServiceNow. Pyramid Analytics, founded in Israel and led by Omri Kohl, built an AI-driven decision intelligence platform. JVP led the company’s funding round in 2020 and worked with the company to expand internationally and strengthen its enterprise presence. Gartner recognized Pyramid Analytics as the most innovative vendor in its category on Gartner’s Magic Quadrant. Another major milestone came through the merger between Covera Health and Medmo, a JVP portfolio company originally launched through Columbia University and JVP’s New York scale-up hub. The combined company plans to offer an end-to-end diagnostic imaging platform integrating scheduling, imaging, and quality assurance into a unified system. In cybersecurity and AI infrastructure, Everpure acquired 1touch.io, a JVP portfolio company founded within JVP’s Cyber Labs in Beer Sheva. 1touch.io focused on enterprise data intelligence and AI-ready data management, combining data discovery with semantic context to help enterprises deploy generative and agentic AI technologies securely. JVP said the acquisition validates its early investment thesis around the convergence
May 27, 2026 · via pulse2.com
Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named "mouse5212-super-formatter," is designed to upload files from "/mnt/user-data," a dedicated directory used by Anthropic's Claude artificial intelligence (AI) tool to handle uploads and outputs in the background. The activity has been codenamed Malware-Slop. "By analyzing the malware, it turns out that the script presents itself as an internal 'archive deployment sync' utility that validates or initializes a GitHub repository, captures a lightweight 'network status' snapshot, and then performs a structured synchronization of local workspace files into a remote tracking tree," researchers Moshe Siman Tov Bustan and Nir Zadok said. In reality, however, it authenticates to GitHub during the postinstall stage, either using a GitHub access token found in the victim's environment or a hard-coded token as a fallback, checks whether a target repository exists, and if not, creates it, and then recursively uploads every file to a threat actor-controlled GitHub account. The stolen files are stored within randomly named folders to help the operator distinguish between different theft sessions. The malware also writes a fake "network connections" log to give the impression that it's sending diagnostic information, while obscuring its true operational behavior of unauthorized collection and remote transfer of local data. The package is still available for download from npm and is estimated to have been downloaded 676 times. However, how many of these correspond to actual installs remains unclear. The GitHub account linked to the campaign is no longer available, although OX noted that it was created on May 26, 2026, a few hours before the first malicious version was uploaded to npm. What's notable about the package is that it leaked details of the GitHub account, including its private token, raising the
May 27, 2026 · via thehackernews.com
What Is a Cybersecurity Legal Practice, 2.0? Cyber operations in the gray zone between war and peace put infrastructure and businesses at risk. Cyber lawyers have never been more vital. Five years ago, our former colleague Dan Sutherland wrote in Lawfare about the pressing need to develop cybersecurity law practices among corporate lawyers and in-house counsel. Then the chief counsel of the Cybersecurity and Infrastructure Security Agency (CISA), Sutherland wrote that businesses and organizations of every size, shape, and sector needed lawyers who can operate fluently at the intersection of law, technology, and security risk. Years later, Sutherland’s thesis still holds true, but the landscape has evolved significantly. With ongoing “hot” conflicts in Europe and the Middle East, computer network operations targeting economies and infrastructure around the world, and the strategic importance of the private sector to the newly issued U.S. Cyber Strategy, we seek to update Sutherland’s guidance to the cybersecurity bar. We intend this article to provide a road map for corporate general counsels looking to deepen their cybersecurity practice groups, government agencies looking to enhance collaboration across the mission space, and university professors seeking to update their cybersecurity law and policy courses. And if companies, agencies, or universities have not yet addressed cybersecurity law, consider this our urgent plea to do so. In the world of national security and tech, five years is a long time. In 2021, CISA, where we worked with Sutherland, was still in its infancy. Major legal and policy developments such as the National Institute for Standards and Technology Cybersecurity Framework (NIST CSF), the CIA’s Cybersecurity Performance Goals, the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), and the finalization of a new UN Cybercrime Treaty had not yet come to pass. Operational threats such as ransomware had not yet materialized
May 27, 2026 · via lawfaremedia.org
In less than five minutes, it is now possible to clone a person’s face and voice using Artificial Intelligence. This idea, which just a few years ago seemed like something out of science fiction, was one of the central topics at the cybersecurity training day recently held by the Civil Guard in Valencia. There, officers from Team @ —specialised in cybercrime— worked on a scenario that is already part of the present: a new generation of AI-driven threats. The session featured the participation of Telefónica, which contributed expert knowledge on how these technologies are transforming both cybercrime and the strategies used to combat it. A Change of Pace in Digital Threats One of the main challenges that Artificial Intelligence introduces to cybersecurity is acceleration. Changes no longer occur over months, but in a matter of days. Tools evolve rapidly and, with them, so do attack techniques. This forces a rethinking of traditional defence models, which have historically been more reactive. Furthermore, AI has significantly reduced barriers to entry. Activities that previously required advanced knowledge or substantial technical resources can now be carried out by a single person from a computer. This multiplies the potential scale of the attacks. Deepfakes: The Challenge of Identity Within this new context, deepfakes have become one of the main sources of concern. The ability to generate synthetic content — voice, image, or video — with a high degree of realism introduces a new level of complexity. Identity theft is no longer a rudimentary attempt, but rather a simulation that is difficult to detect, even for experienced users. This scenario has direct implications in areas such as customer relations, identity verification, and fraud protection. Anticipation as a Strategy In light of these developments, cybersecurity needs to move towards more proactive models. Artificial Intelligence itself, when applied
May 27, 2026 · via telefonica.com
CISA issues revised virtual town hall schedule for input on proposed cyber incident reporting
The Cybersecurity and Infrastructure Security Agency May 26 announced a revised schedule for its series of virtual town hall meetings for public input on proposed rulemaking for the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The meetings will now begin June 15. They were originally scheduled for March and April but were not held due to the partial shutdown of the Department of Homeland Security. CISA seeks input to finalize a proposed rule originally issued in March 2024. The proposed rule would require critical infrastructure organizations, including hospitals and health systems, to report certain cyber incidents to CISA within 72 hours and ransom payments within 24 hours, among other mandates. The AHA commented on the rule, calling certain proposed requirements redundant to those from other federal agencies and saying that they may add unnecessary burden to hospitals working to ensure access to needed services during cybersecurity incident response.
May 27, 2026 · via aha.org
- Date - April 29, 2026 Aerospace leaders, cybersecurity experts and students gathered at Embry‑Riddle Aeronautical University to address a pressing aerospace challenge: securing increasingly interconnected, AI-enabled flight and space systems. In an opening message to participants at the third annual ERAU-NASA-NSF Aerospace Cybersecurity Workshop at the Prescott Campus, U.S. Sen. Mark Kelly, a former Navy test pilot and astronaut, said that “the stakes continue to grow” for aerospace cybersecurity. “As our aerospace systems become more connected and more complex, cybersecurity is no longer a standalone issue,” he said in the recorded message. “It is fundamental to safety, reliability and mission success.” Supported by the National Science Foundation (NSF) CyberAICorps Scholarship for Service (SFS) program, the Embry‑Riddle event brought together more than 75 professionals from over 50 organizations, as well as students from more than 25 universities. The two-day workshop addressed challenges ranging from securing aircraft systems, airline operations and air traffic control infrastructure to emerging issues related to advanced air mobility (AAM) and space-based technologies. Participants emphasized that aerospace cybersecurity is interdisciplinary, requiring coordination among engineers, operators, policymakers and cybersecurity specialists. “This workshop is about more than sharing ideas — it’s about bringing the right people into the same room to tackle challenges that no single sector can solve alone,” said Dr. Krishna Sampigethaya, chair of the Department of Cyber Intelligence and Security and NSF SFS principal investigator for the Prescott Campus. “By connecting students from across the nation with leaders from industry, government and academia, we are not only advancing solutions but also building the workforce needed to secure the future of aviation and space systems.” That reality was evident during a panel focused on aerospace cybersecurity careers, where four Embry‑Riddle students moderated a discussion with professionals from NASA, Boeing, airlines and other industry groups. Panelists described careers
May 27, 2026 · via erau.edu
Upcoming Webinar
Tradecraft Tuesday | June 2026
On Valentine’s Day 2025, Storm-2372 Russian threat actors leveraged OAuth device code flow to hijack Microsoft Entra device registration to obtain the Primary Refresh Token (PRT) and persistence. In March 2026, the EvilTokens campaign used device code phishing and Railway to automate large-scale attacks.
OAuth device code phishing is being used increasingly by threat actors to hijack OAuth tokens because of its phishing-friendly user codes, "MFA-bypass", by design token delivery over REST APIs, and ease-of-abuse.
We'll look at device code phishing variations across different apps and stacks, including the impersonation of first-party apps requiring minimal attacker infrastructure, pivoting across a user's SSO apps/data, an analysis of Storm-2372 tradecraft involving PRT hijacking and Windows Hello for Business (WHfB) persistence. We also delve into bypasses of the 15-minute code expiration and delivery mechanisms including BITM/MITM, QR codes, smishing, and chat-based lures
May 27, 2026 · via huntress.com
CISA Announces Revised Town Hall Schedule to Engage with Stakeholders on Cyber Incident Reporting for Critical Infrastructure WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA) today announced a revised schedule for a series of virtual town hall meetings to gather stakeholder input on the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) rulemaking. Scheduled to begin June 15, these town hall meetings replace the town hall meetings previously scheduled for March and April 2026, but which CISA was not able to hold due to the recent Democrat shutdown of the Department of Homeland Security (DHS). CISA remains committed to affording stakeholders the opportunity to provide additional input on the CIRCIA rulemaking through a town hall series before the rule is finalized. The revised schedule is available in the Federal Register. Interested stakeholders may register for the town hall meetings at www.cisa.gov/circia. Any changes or updates to the town halls will be available on www.cisa.gov/circia. “CISA is working to maximize the impact of CIRCIA to significantly improve our Nation’s cybersecurity posture. At the same time, CISA values the interest and concern our stakeholders have that CIRCIA will be implemented with minimal unnecessary burden to entities in critical infrastructure sectors,” said CISA Acting Director Nick Andersen. “CISA appreciates our stakeholder’s patience with waiting for our rescheduled town hall meetings to provide their critical input as we finalize this rule. As an agency built on collaboration and coordination, CISA is committed to hearing from the American people, critical infrastructure owners and operators, and other community members.” CIRCIA is a U.S. law that will help the government quickly respond to cyber threats and share information to protect critical infrastructure. Once the final rule is implemented, covered organizations will be required to report certain cyber incidents to CISA within 72 hours and
May 27, 2026 · via cisa.gov