No-frills tech news

New Data Shows How Tech Sectors Are Turning AI Into Strategy

Picture three technology executives: one in cybersecurity, one in software as a service, and one in payments. Each is trying to figure out how to deploy artificial intelligence across their organization. The cybersecurity CTO wants to know how quickly the firm can roll out AI across more tasks. The SaaS lead wants to know where AI can sharpen growth and give products an edge. The payments executive wants to know where AI can earn organizational trust, reduce risk and prove its worth. Previous PYMNTS Intelligence research finds that the tech industry is at the forefront of AI adoption. But “tech” is a broad category, and AI strategies aren’t one-size-fits-all. Adoption reflects an individual sector’s core pressures, from customer protection to revenue expansion to transaction control. Cybersecurity firms use AI most broadly, SaaS firms are most willing to experiment and payments firms are most disciplined about where they invest. The obstacles aren’t the same, either. Some firms wrestle with change management, others with oversight and still others with security and data handling. Taken together, the findings show that enterprise AI is about fit. Firms that scale the fastest match AI to the parts of the business where it can do the most useful work. These insights are explored in “New Data Shows How Tech Sectors Are Turning AI Into Strategy,” the latest edition of the Enterprise AI Benchmark Report, a PYMNTS Intelligence exclusive series. This edition draws from a survey of 60 senior technology executives at U.S.-based enterprises with at least $1 billion in annual revenue conducted in April 2026. The data show that different tech sectors are scaling AI in distinct ways that align with core business pressures, not a single, shared playbook. Cybersecurity Leads in AI Breadth The cybersecurity sector is adopting AI the most broadly but not necessarily

Trump eyes Palantir Tech Chief to lead CISA | DigitalShield

Donald Trump is considering a senior executive from Palantir Technologies as the new head of the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Shyam Sankar, CTO of Palantir, is 44 years old. According to his LinkedIn profile, Sankar has worked at Palantir for over 20 years, serving as the company's Chief Operating Officer for 17 years until he was appointed Chief Technical Officer in 2023. The agency has not had a Senate-confirmed leader since Jen Easterly resigned in January of last year, according to The Record Media. Just a few days ago, the Secretary of the Department of Homeland Security (DHS), Markwayne Mullin, informed legislators that the administration is about to appoint a director for the agency, which has been led by acting director Nick Andersen since February. "We have a person, who will soon be nominated, who will lead CISA and has the ability to recruit staff and focus on the competencies we have. We want CISA to be a leader in cybersecurity. It should be and it will be," Mullin commented. Palantir maintains close ties with the Trump administration and primarily focuses on artificial intelligence. This big data analytics company has established itself as a major AI provider for businesses and the defense sector. Following the publication of this information, a White House official denied the potential selection, stating that "at this moment this is not accurate." A former chief who shared official information Earlier this year, the then-acting chief of CISA, Madhu Gottumukkala, made a notable error by sharing documents for official use in the public version of ChatGPT. Although the documents were not formally classified, they did contain sensitive information regarding hiring and internal management of the Department of Homeland Security (DHS). Thus, it was a significant operational security failure in an agency tasked with defending

How Agentic AI and Asset Tokenization are Redefining Cyber Resilience for Financial Institutions

Financial institutions are shifting their focus from simply preventing cyberattacks to building stronger cyber resilience and faster recovery capabilities. Agentic AI can analyze threats in real time, helping security teams identify and respond to unusual activity more quickly. Asset tokenization creates greater transparency across transactions, giving organizations better visibility and control over digital assets. A bank can spend years building trust with customers and lose a part of it in a single cyber incident. That is why security has become a daily concern for financial institutions. The major challenge is to ensure the services continue even if something goes wrong. As the financial world becomes more digital, companies are looking at new tools that can help them stay prepared. Two of the technologies getting attention are Agentic AI and asset tokenization. They are different in many ways, but both are changing how financial firms think about risk, security, and recovery. There was a time when cybersecurity was mostly about building stronger walls around systems. Today, many security leaders know that no system is completely untouchable. The real question is what happens after a threat appears. Can the problem be spotted quickly? Can the damage be limited? Can customers continue using important services? That way of thinking has pushed cyber resilience to the center of many discussions across the financial sector. Also Read: Why AI Agents are Becoming Active Participants in Crypto Markets Security teams deal with huge amounts of information every day. Transactions move constantly. Alerts appear around the clock. Sorting through everything manually is becoming harder. This is where Agentic AI comes in. Instead of simply waiting for instructions, it can watch activity, identify unusual patterns, and help decide what needs attention first. Imagine a sudden spike in suspicious transactions late at night. A human team may need time

via Right-Hand <b>Cybersecurity</b> | The <b>Cyber Security</b> Hub™

Lol, thats funny. 😎😅 Sad but true 😄 - Abdullah 9h This never gets old! 🤣🤣 My Products is Fully Alignment with SANS Released 2026. SOC analysts can FREE use the following Ai High tech to reduce anxiety between shifts: Specialized for: SOC Analysts Threat Hunters Blue Team Leads Incident Responders Security Architects Security Leadership For Narrative views #CyRex -Link to the next generation of artificial intelligence engineering and the first Iranian example of a completely hunter-oriented Cognitive AI Proven ability to deploy this system in Total Local & OFFLINE Building a complete attack narrative Creating three hypotheses and graphs on the Miter matrix Proving the power of architecture in controlling Hallucination & Overconfidence https://chatgpt.com/g/g-692dae5e326c81919b6a6cb3faa2b456-cyrex-lordblue-cybersecurity-threat-hunter

Mountain Rides resolves <b>cybersecurity</b> threat | Transportation | mtexpress.com

Mountain Rides, the Wood River Valley's public transportation agency, has resolved an issue caused by a malicious pop-up box that showed up on its website this week and threatened website visitors with a computer virus. Mountain Rides spokeswoman Andrea Hernandez told the Express in a Friday phone call that she spotted the issue Wednesday morning. She said that since then, Mountain Rides had been working to resolve the issue with the help of a local web-design company that designed the Mountain Rides website, which was constructed using WordPress.com. She said that when users attempted to access the website, a pop-up box would appear and ask them to verify they were human. The site visitor would be asked to complete a series of steps to "prove you're not a robot," which included keyboard commands and on-screen button clicks, before the virus could target the visitor, Hernandez explained. Just after 11 a.m. Friday, Hernandez told the Express that the issue had been resolved. She said it was not a targeted attack on Mountain Rides but instead an attack across wordpress.com websites like the Mountain Rides website. Hernandez asked that if anyone in the public encounters a similar pop-up on the Mountain Rides website they reach out to info@mountainrides.org to inform the agency of the issue. Hernandez said the website is, once again, safe for traffic. Hernandez said that two similar cybersecurity threats on the Mountain Rides website had been resolved "right away" after they occurred on May 7 and 13. Post a comment as anonymous Report Watch this discussion. (0) comments Welcome to the discussion. Log In

Sentient fortress: Engineering future Army installations as weapon system platforms

FORT HUACHUCA, Ariz. — Imagine the clock displaying 3 a.m. in the year 2040 at a forward power projection platform in a highly contested Indo-Pacific theater. Sensors detect an adversary’s hypersonic missile targeting the installation’s primary munitions depot. Simultaneously, the installation's cybersecurity architecture detects malicious traffic targeting the power grid. Instantly, the cybersecurity architecture isolates substations and reroutes power through redundant pathways to keep defensive missile launchers fully energized. As the threat approaches, an integrated air and missile defense system driven by artificial intelligence calculates the optimal intercept. The missile interceptor succeeds. Within seconds, the automated logistics system of the Army's Organic Industrial Base assesses the expended inventory and initiates a 3D printing process to fabricate a replacement guidance component for a new missile interceptor. This imaginary scenario illustrates a future where an Army installation is not just a passive piece of real estate. Instead, the installation is a fully realized, intelligent weapon system platform known as a “sentient fortress.” Achieving this vision is the driving force behind the Army's 15-year OIB Modernization Strategy and Modernization Implementation Plan. As part of the Communications-Electronics Command, the U.S. Army Information Systems Engineering Command is dedicated to realizing the Army’s OIB Transformation to ensure a 21st-century OIB capable of sustaining readiness, supporting modernization efforts and remaining postured to meet wartime requirements. The vulnerability of a bygone era To appreciate the resilient installation of the future, one must understand the critical vulnerabilities of legacy infrastructure. For decades, Army installations relied on a fractured technological foundation with a complex seam between information technology and operational technology. IT encompassed data and enterprise networks, while OT referred to the physical world, including industrial control systems, power grids, and the complex machinery of the OIB. The critical nature of these systems has made the seamless convergence of the

Phosphorus <b>Cybersecurity</b> - Dragos | Transaction Details

Houlihan Lokey Advises Phosphorus Cybersecurity Phosphorus Cybersecurity has been acquired by Dragos Sellside Advisor Houlihan Lokey is pleased to announce that Phosphorus Cybersecurity (Phosphorus) has been acquired by Dragos. Adding Phosphorus extends Dragos’ capabilities to secure connected devices across the extended operational technology environment, or xOT, delivering deeper device visibility, automated remediation, and continuous risk reduction. Phosphorus is an xIoT security and management platform that discovers, assesses, and actively remediates risk across connected devices, including IoT, OT, IoMT, and IIoT. The platform offers the industry's most comprehensive security capabilities for connected devices, integrating with customers' existing infrastructure without requiring disruptive architectural changes. The platform actively discovers and provides deep visibility into devices across OT and enterprise environments. Phosphorus automates remediation workflows, including password rotations, firmware updates, certificate management, and configuration hardening, while helping organizations address compliance and reduce risk at scale. Dragos is a global leader in OT cybersecurity. With nearly a decade of real-world experience handling landmark attacks on OT networks, Dragos understands the complexity and risks of industrial environments, operating on massive scale with unique systems and exacting availability requirements that are not protected by IT cybersecurity. Purpose-built for the xOT environment, Dragos technology delivers asset visibility, continuous monitoring, OT vulnerability management, segmentation validation, device protection, and real-time threat detection, powered by industry-leading OT threat intelligence and incident response teams. Dragos serves critical sectors including energy, manufacturing, water, transportation, and data centers. Privately held and headquartered in the Washington, DC area, Dragos operates globally across North America, EMEA and APAC. The acquisition brings together two highly complementary capabilities to address the full scope of the xOT environment. For Dragos, adding Phosphorus extends its platform to secure the billions of connected devices embedded across critical infrastructure networks, closing a visibility and remediation gap that legacy OT tools have historically

Former cyber executive turned whistleblower accuses IBM of covering up several data breaches

A former IBM cybersecurity executive accused the company of getting hacked three times in the previous decade by foreign governments and then covering up the breaches. In a lawsuit unsealed this week but filed in 2020, William Barlow, who was IBM’s vice president of threat intelligence until August 2019, said IBM concluded Chinese hackers breached its core network between 2013 and 2016 but that the company then covered up the breaches and never disclosed them. Barlow also said at least two IBM subsidiaries were also breached, and that IBM covered up those breaches as well. Barlow alleged in his complaint that IBM’s core network was “routinely hacked by foreign state actors and others,” adding that data was frequently stolen and government agencies were “never notified.” While the alleged breaches date back more than a decade, the news shows that cyberattacks, even those affecting large public tech companies such as IBM, sometimes never get disclosed, either to the public or to relevant government authorities. IBM is a major cybersecurity vendor to the U.S. federal government, which makes the alleged concealment especially significant. In the last few years, several data breach notification laws have been passed to counter this problem. Bloomberg first reported on the lawsuit. IBM spokesperson Miki Carver declined to answer specific questions about the lawsuit and the underlying accusations. Instead, Carver told TechCrunch, “This complaint was filed six years ago, and the U.S. Department of Justice declined to intervene. IBM is confident that our actions followed the letter of the law.” In particular, Barlow said IBM was among several victims of a hacking campaign carried out by APT 10, a Chinese government-linked group that then-FBI Director Christopher Wray said had targeted a “Who’s Who” of the global economy when its members were indicted in 2018. The hackers broke into

Trump AI Order Seeks Voluntary Frontier Model Testing

Trump AI Order Seeks Voluntary Frontier Model Testing The White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security. A new executive order aims to put gas in the federal cybersecurity tank and prepare the government for frontier AI models like Anthropic's Claude Mythos, but private sector participation is voluntary and practitioner impact remains to be seen. The executive order, which the White House unveiled this week, aims to prioritize cybersecurity in the Trump administration and encourage the private sector to share AI frontier models with the federal government for an early preview prior to releasing the model publicly. President Donald Trump's second term has butted up against the cybersecurity community. Early last year, the administration effectively shuttered the Cyber Safety Review Board, and this was followed with mass CISA layoffs, cybersecurity-focused budgetary cuts, and other actions such as a withdrawal from cybersecurity event RSAC Conference. The new executive order, "Promoting Advanced Artificial Intelligence Innovation and Security," could reverse this course. Sec. 2, Upgrading American Systems for Advanced AI, orders the Committee on National Security Systems and Secretary of Defense Pete Hegseth to take action to "prioritize the cyber defense of National Security Systems" within 30 days. Moreover, most other cyber stakeholders, including the Department of Homeland Security (DHS), the Director of the Office of Management and Budget (OMB), the assistant to the president for National Security Affairs, and the National Cyber Director are ordered to expedite and prioritize the cyber defense of civilian federal government information systems, as well as establish or expand federal programs and cybersecurity services to enhance AI defensive tool deployment. The EO will also "facilitate access to cybersecurity tools and services including, where appropriate, covered frontier models for agencies, State and local authorities, and operators of

EU <b>Cybersecurity</b> Act could expose member states to costly investment treaty claims, legal ...

Law EU Cybersecurity Act could expose member states to costly investment treaty claims, legal opinion warns A new legal opinion by leading international investment law expert Professor Christoph Schreuer warns that the European Commission's proposed Cybersecurity Act (CSA) could place EU member states in a difficult legal position, potentially exposing them to compensation claims from Chinese investors under existing bilateral investment treaties (BITs). The opinion, commissioned by international law firm Gaillard Banifatemi Shelbaya Disputes and dated 4 May 2026, examines the legal consequences of a potential conflict between the proposed EU cybersecurity legislation and investment protection agreements that almost all EU member states maintain with China. Under the draft legislation, the European Commission would gain extensive powers to identify and exclude so-called "high-risk suppliers" from European information and communications technology (ICT) markets. The proposed measures could affect suppliers involved in key digital infrastructure, including 5G networks, telecommunications systems and other strategic ICT assets. Potential legal collision According to Schreuer, the central issue is that while the Cybersecurity Act would be directly applicable across the European Union, EU member states remain bound by their separate bilateral investment treaties with China. These treaties generally guarantee protections against expropriation, discriminatory treatment and unfair treatment of Chinese investments. The opinion concludes that compliance with EU legislation would not automatically shield member states from liability under international law. "Member States would remain bound by their respective BITs with China in the event of a conflict between their obligations under the CSA and those arising under the BITs," Schreuer writes. The analysis argues that international law does not allow to invoke domestic legislation—including EU law—as a justification for breaching treaty obligations. As a result, if measures taken under the Cybersecurity Act adversely affect Chinese investors, member states could still face international arbitration claims. Chinese investors could

Trump Executive Order on AI: Voluntary Framework, <b>Cybersecurity</b> Focus, and Key Takeaways

Trump Executive Order on AI: Voluntary Framework, Cybersecurity Focus, and Key Takeaways On June 2, 2026, President Trump issued a new Executive Order (EO), "Promoting Advanced Artificial Intelligence Innovation and Security." The order arrives after the President's recent decision to postpone its signing. As foreshadowed in the leaked draft, the EO reflects the Trump Administration’s stated priority of advancing AI innovation while acknowledging that “advanced AI capabilities make our Nation stronger,” but also “introduce new national security considerations” that require coordinated action across government. Below we summarize the EO's key provisions, compare them to the Biden administration's broader AI framework, and draw out the practical implications for developers and critical infrastructure operators. What Clients Need to Know - The EO is narrowly focused on cybersecurity and national security. This marks a notable shift from the Biden administration's broad AI governance framework. - No new mandatory obligations for AI developers. The frontier model framework is expressly voluntary and preclearance is prohibited. - Designation thresholds for "covered frontier models" will be set through a classified NSA process. Developers will have little visibility into where that line falls. - The AG is directed to prioritize enforcement of existing computer fraud laws against AI-enabled attacks. No new crimes created, but this is a noteworthy prosecutorial signal. - Developers who opt into the voluntary framework should plan for a 30-day pre-release government access window. - Critical infrastructure operators (hospitals, community banks, utilities) should track CISA Binding Operational Directives. These carry real compliance weight even if clearinghouse participation is voluntary. Section 2: Upgrading American Systems for Advanced AI Section 2 details the bulk of EO’s cybersecurity mandates. By July 2, 2026 (within 30 days): - Cyber Defense Prioritization (Sec. 2(a)). The Committee on National Security Systems is directed to prioritize the cyber defense of National Security

CMMC has moved from planning to enforcement and contractors are feeling it

"Our adversaries, our foreign adversaries definitely have been taking some of our most precious IP in this country," said Emil Sayegh. Interview transcript Terry Gerton You have a lot of background on a very important topic, CMMC. In fact, your company received quite a bit of attention last fall when you released a report that found only 1% of defense contractors said they felt ready for the CMMCs rules that were just then going into effect. We’re about six months later. How have you seen the situation change? Emil Sayegh There’s certainly a rush from certain contractors and subcontractors to essentially become CMMC compliant, get certified, get assessed, and so on and so forth. But what we’ve seen from before, for multiple years as CMMC was being talked about and planned, basically CMMC has moved from planning and PowerPoint and Excel sheets and word documents and project plans to actual implementation now and people are starting to take it much more seriously. So it’s moved basically from writing the policy to actually implementing those policies and not only implementing them, but also making sure that you have the proper evidence that those policies are implemented because when an assessor is gonna come in and audit you or even if you’re doing a self assessment and you’re publishing an SPRS score, there’s a threshold of evidence that you need to maintain. And that’s what needs to go into your self assessment, right? It can’t just be, “I think” or “we planned” or “it looks good” on an Excel document or a Word document. You have to be able to provide the evidence so that you can enter your SPRS score in the government system, the DOD system. So having said that, I think we’re seeing everything shift from planning to now

Warner Will Introduce Bill to Fund Critical Cyber Information Sharing Program, Urges Mullin ...

WASHINGTON – Today, U.S. Sen. Mark R. Warner (D-VA) announced a collective effort to help all levels of government defend themselves against cyber-attacks. He is introducing the Guaranteeing Universal Access to Cybersecurity Act, legislation that would fund the Multi-State Information Sharing and Analysis Center (MS-ISAC), a decades-old program that provided free cybersecurity resources and monitoring to 19,000 state, local, territorial, Tribal organizations and communities. Sen. Warner sent a letter to Department of Homeland Security (DHS) Secretary Markwayne Mullin urging DHS to prioritize the Cybersecurity and Infrastructure Security Agency (CISA) and to fund MS-ISAC, and a letter every governor in the country, explaining the risk facing critical infrastructure, the hazards caused by the Trump administration’s politically-motivated sabotage of CISA, and advocates for steps the governors can take to protect our national security, economy, and public health. Last year, then-DHS Secretary Kristi Noem terminated funding for MS-ISAC and banned federal grant funding from being used by states, localities, Tribes, and territories (SLTT) and other organizations for membership in the MS-ISAC. Many SLTT and organizations have been forced to wait to fund these critical memberships, creating a dangerous gap in protecting their critical infrastructure. The Guaranteeing Universal Access to Cybersecurity Act would: - Direct the Director of CISA to enter into an agreement with the group that runs MS-ISAC, the Center for Internet Security, to provide no-cost cybersecurity services, cyber threat intelligence collection and dissemination, and technical assistance to SLTT. - Direct the Director to conduct additional outreach to restore MS-ISAC membership to those lost during the defunding and expand access to SLTT entities not previously members of MS-ISAC, serve critical infrastructure sectors, maintain data sharing with the FBI to enhance the national cyber threat intelligence ecosystem. - Direct CISA to report to Congress on the number of re-enrolled and new members of

Shaking Pandora's Box: How Claude Mythos Upends the World of <b>Cybersecurity</b>

Shaking Pandora’s Box: How Claude Mythos Upends the World of Cybersecurity June 05, 2026 In early April, the internet was buzzing with rumors of something new in development by leading AI firm Anthropic. Thanks to a website leak, cybersecurity researchers and internet sleuths had discovered hints about an unreleased AI model that was unprecedented in capabilities and power. Within a few weeks, Anthropic confirmed the existence of “Mythos Preview”, a pre-release version of a powerful cybersecurity-focused AI model with extraordinary defensive and offensive potential. So much potential, in fact, that Anthropic chose not to publicly release it out of a fear of what it could do in the wrong hands. For LSU E. J. Ourso College of Business faculty and cybersecurity experts Ali Ahmed and Rudy Hirschheim, Mythos was a fascinating – and potentially alarming – development. In a wide-ranging Q&A, we chatted with Ahmed and Hirschheim about the capabilities of Mythos, what this new AI means for IT professionals, and how it offers a peek into a Pandora’s Box of unforeseen consequences. Meet the Experts Select a question to read more. Defining Mythos Anthropic’s Claude Mythos Preview is the latest advancement in AI models for autonomous coding and reasoning. What makes Mythos different from earlier models is its ability to search for weaknesses in existing software systems. In the past, companies would invite outside security researchers to probe their systems and pay them for each verified bug they uncovered. Mythos upends this arrangement by shrinking the time required to identify vulnerabilities and by finding them at scale. This quickly exceeds the capacity of existing defensive measures. For instance, Cloudflare, an essential security gatekeeper for over 24 million active websites, discovered 2000 vulnerabilities using Mythos Preview within a month. In contrast, Cloudflare’s well-established and popular bug bounty program reportedly only

Mexico's <b>Cybersecurity</b> Talent Gap Fuels Rising Risks

Mexico’s Cybersecurity Talent Gap Fuels Rising Risks The cybersecurity talent shortage exposes global and Mexican businesses to severe operational and financial risks. With a deficit of 77,000 specialists locally and a systemic lack of strategic leadership globally, organizations must invest in internal talent development, AI, and managed services to build resilient corporate defense architectures. Mexican enterprises face unprecedented vulnerabilities as 40.6 billion cyberattack attempts in 1H25 collide with a critical national deficit of 77,000 cybersecurity specialists, reported by IQSEC. The inability to locate qualified professionals leaves corporate networks undefended against sophisticated threats like ransomware and phishing. To address this crisis, companies are shifting from traditional recruitment to comprehensive training models. “The responsibility of the industry is no longer just to hire talent: it is to develop it, promote it, and open opportunities for new generations,” says Israel Quiroz, Founder, IQSEC. Mexico requires 83,000 cybersecurity specialists, yet only 6,000 professionals are available to meet market demands, according to research by Select and IQSEC. This talent gap creates critical vulnerabilities for corporations. Santiago Fuentes, Co-CEO, Delta Protect, says that a lack of awareness and insufficient investment exacerbate these risks. Although 86% of Mexican organizations plan to increase their cybersecurity budgets in 2026, according to PwC, current investments remain inadequate against modern threats. Additionally, the national legal framework remains outdated, though the Directorate General for Cybersecurity presented the National Cybersecurity Plan for 2025–2030 to build cyber resilience. The financial implications of inadequate security are substantial. PwC data shows that 47% of Mexican organizations reported that their most damaging security breach in previous years cost between US$100,000 and US$10 million. Despite these losses, only 40% of companies quantify the financial impact of cyber risks. Cybercriminals employ various methods to breach corporate networks. OCD Tech says that the most frequent attack vectors include phishing, where

Trump signs executive order on voluntary AI <b>cybersecurity</b> testing

Sinziana Albu 05 Jun 2026 / 5 Min Read The Paypers is a global hub for market insights, real-time news, expert interviews, and in-depth analyses and resources across payments, fintech, and the digital economy. We deliver reports, webinars, and commentary on key topics, including regulation, real-time payments, cross-border payments and ecommerce, digital identity, payment innovation and infrastructure, Open Banking, Embedded Finance, crypto, fraud and financial crime prevention, and more – all developed in collaboration with industry experts and leaders. Current themes No part of this site can be reproduced without explicit permission of The Paypers (v2.7). Privacy Policy / Cookie Statement Copyright

Trump's Executive Order frames U.S. AI policy around deregulation, <b>cybersecurity</b>, and ...

U.S President Donald Trump has issued a policy directive outlining how the federal government should approach Artificial Intelligence, emphasizing reduced regulation, closer work with industry, and expanded cybersecurity defences across federal systems. The order titled ‘Promoting Advanced Artificial Intelligence Innovation and Security’ argues that the U.S. maintains leadership in AI due to private-sector innovation and a regulatory approach that avoids heavy federal restrictions. It directs agencies to prioritize cybersecurity upgrades across national security, defence, and civilian systems, with multiple deadlines of 30 to 60 days. Provisions include those for accelerating vulnerability detection, expanding AI-enabled defensive tools, and improving hiring pipelines for cybersecurity roles. A proposed “AI cybersecurity clearinghouse” would coordinate vulnerability discovery and patch distribution between government and industry. In the policy summary President Trump stated, “It is the policy of the United States to promote AI innovation and security by working collaboratively with the private sector to modernize government and private sector information systems and harden them against external threats; to protect American ingenuity and intellectual property from exploitation and theft by adversaries; and to cultivate America’s advanced AI-enabled capabilities.” Trump continues, “The United States continues to lead the world in Artificial Intelligence because of the enormous talent and innovation of our AI industry, and because we refuse to stifle this innovation with overly burdensome regulation. As these capabilities evolve, my Administration will continue to work closely with industry to ensure that the best and most secure technology is deployed rapidly to confront any and all threats to our country.” The directive also sets up a framework for assessing advanced AI systems used in cyber operations. Federal agencies would develop a classified benchmark to determine when a model qualifies as a “covered frontier model,” with voluntary pre-release government review offered to developers. Additional provisions direct the Office of Personnel

Your data is valuable. A <b>cybersecurity</b> expert tells you how to protect it

Your data is valuable. A cybersecurity expert tells you how to protect it You generate a wealth of data that you entrust to suppliers. But do you really know where it travels, where it’s stored, and who has access to it? In a context where telematics, onboard cameras, and connected platforms are proliferating, these questions are becoming increasingly important for carriers. To demystify the issues surrounding data security, integrity, and governance, Transport Routier spoke with Jean Loup Le Roux, a cybersecurity expert and consultant, as well as a partner at Magna, a firm that has been offering cybersecurity services worldwide since 2014. According to Le Roux, the risks are not limited to cyberattacks: they also concern data control, its sharing with third parties, and, in some cases, issues that can even affect national security. TR: Why should carriers be more concerned about the data generated by their vehicles and systems? Jean Loup Le Roux: Because today, virtually all technologies used in transport are connected. Whether it’s telemetry, electronic logging devices, on-board cameras or fleet management platforms, these solutions rely on constant data exchange. What many people don’t realize is that a single provider can conceal several others. Behind a telematics solution, there are often different providers of cloud services, telecommunications, hosting, or data analytics. Think of it like Russian nesting dolls. The transport company believes it’s dealing with a single supplier, but when you open the first doll, you discover a second, then a third, then a fourth. In some cases, dozens of companies are involved behind the scenes in processing or transporting the data. Each intermediary can potentially have access to some of the information. The company generally knows the supplier with whom it has signed a contract, but it does not always have complete visibility on all the

New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework

Cybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke web shell framework. ReliaQuest has assessed with moderate to high confidence that the espionage-focused activity is linked to China. "OP-512 was highly likely conducting espionage through a compromised Internet Information Services (IIS) web server on an organization whose sector and geography align with China-linked intelligence priorities," the company said in a report shared with The Hacker News. Although no overlaps have been found between OP-512 and other known China-aligned adversaries, it's the fourth such threat group after CL-STA-0048, DragonRank, and GhostRedirector to single out IIS web servers over the past 12 months. As recently as last month, Cisco Talos revealed that multiple Chinese-speaking cybercrime groups are sharing a variant of malware called BadIIS to infect IIS servers. IIS servers have also been targeted by SHADOW-EARTH-053 as part of a new China-aligned espionage campaign targeting government and defense sectors across South, East, and Southeast Asia. Central to the operations of OP-512 is a custom web shell framework consisting of three web shells that grant the attackers remote access to the compromised host, while taking steps to evade signature-based detection and complicate forensic timelines using techniques like timestomping to intentionally manipulate the timestamps when the web shell artifacts are created or modified. Specifically, this entails scanning every file and sub-folder around where the web shells are placed, calculating the median last-modified timestamp, and overwriting their own creation and modification times to match that value, thus giving the impression that they have been present for some time. "This framework combines capabilities we rarely see together: each deployment is uniquely generated, access is restricted to the attacker through cryptographic controls, and compromised servers