Why AI could trigger a <b>cybersecurity</b> crisis
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
Students simulate crisis leadership during cyberattacks How do you manage an escalating crisis where cyberattacks coincide with societal disruption, disinformation, and supply chain disturbances? This was the central question when master’s students in Cybersecurity at the School of Engineering in Jönköping took part in an extensive simulation-based exercise last week. “The aim of the exercise was to give students practical experience in participating in and leading this type of scenario – something they can take directly into their future careers within cybersecurity and critical infrastructure,” says Erik Bergström, Associate Professor in Computer Science and Programme Director of the master’s programme in Cybersecurity at the School of Engineering. During the exercise, students worked with a fictional energy company “Juelco,” created to resemble a Swedish company operating within solar, wind, and hydropower. “The simulation is inspired by a NATO exercise I participated in a few years ago. The focus on energy is partly because it represents highly critical infrastructure that we all depend on. I also have a personal interest in the energy sector,” says Erik Bergström, who led the exercise together with Sonny Johansson, Lecturer in Informatics at the School of Engineering. Inspired by a changing global landscape Erik explains that recent global developments have influenced the design of the simulation. “Global events such as the war in Ukraine is a good example, with threat actors operating in our region, as well as the disruptions following the COVID-19 crisis, when much of the world came to a standstill,” he says. The supporting material was designed to reflect the complexity of real-world organisations in critical sectors and served as a foundation for the decisions students had to make throughout the simulation. “I think the exercise was very good, and we were faced with many difficult and realistic situations. With each stage, the
Google is warning that the government’s lawful-access bill would establish a “surveillance infrastructure” that risks compromising cybersecurity in ways that could facilitate foreign interference, while weakening its users’ privacy. In a submission to the House of Commons committee scrutinizing the bill, Google said it is committed to supporting efforts by law enforcement and Canada’s intelligence agencies to protect the public against crime and terrorism. But it said that should be done “without engineering vulnerabilities into products and services that weaken security for all users.” Meta and Apple have already urged the government to make changes to Bill C-22, which would require “electronic service providers” in Canada to adjust their systems to give surveillance and monitoring capabilities to police services and the Canadian Security Intelligence Service. Google disrupts effort by criminal hackers to exploit vulnerability using AI CSIS and law enforcement have long argued that Canada is lagging behind its Five Eyes intelligence partners in not having such a lawful-access regime to aid investigations. But the latest attempt to pass a bill in Canada has faced steep opposition, including from secure-messaging app Signal, Canadian tech companies, privacy advocates and civil liberties groups. Google, in a brief submitted to the Commons public safety committee, said it has “significant concerns” about parts of the bill, including wording that “gives the Minister of Public Safety sweeping powers to issue secret orders” to facilitate the interception or retrieval of data. “Secret Ministerial Orders would severely restrict companies’ ability to engage transparently with users, undermining the users’ trust and ability to hold companies accountable,” Google said in its submission. It added that the definition of an electronic service provider is so broad in the bill that secret ministerial orders could be directed at “almost any entity operating in Canada.” The Canadian Chamber of Commerce is among
More than two in five (43%) businesses reported a cybersecurity breach or attack in 2025. Against this backdrop of cyber threats, the Uswitch Business Broadband experts surveyed SME employees to explore how cybersecurity is being managed within organisations and the pressures faced by non-specialist staff. Cybersecurity responsibilities often fall outside of formal job roles in SMEs. Almost two-fifths (37%) of employees surveyed say cybersecurity was not part of their job description when they started their role, while 14% are unsure or cannot remember. The findings highlight inconsistency in how cybersecurity responsibilities are assigned and communicated across SMEs, with many employees taking on duties that were not formally defined in their role. More than half of SME employees lack formal cybersecurity training. The lack of clearly defined responsibility is also reflected in training levels, as over one in six (16%) say they have never received any relevant cybersecurity training, while 45% have only completed basic training. Just two-fifths (39%) report having received comprehensive cybersecurity training. SME employees report confidence in their cyber skills, but some still feel underprepared. One in five (20%) say they are very confident in managing cybersecurity risks, while 51% are only somewhat confident. A further 21% remain neutral, with 7% not very confident and 1% not at all confident. While confidence is broadly positive across SMEs, the findings highlight a minority of employees who lack certainty when dealing with cybersecurity risks. Cybersecurity challenges often push SME employees beyond their comfort zone. More than half (52%) of SME employees sometimes feel out of their depth when dealing with cybersecurity issues at work, while 12% say they feel this often. Almost a quarter (24%) say they rarely feel out of their depth, while 6% say they never do. These findings suggest that uncertainty and a lack of confidence are
Cryptika quickly earned reputation for firsts. We were the first to provide our business customers with industry's first integrated, end-to-end security operations and response services. Assisting our customers evaluating their IT related business risks, building and improving IT security strategies, designing infrastructures, implementing international security standards such as the ISO 27k ISMS, PCI-DSS, and SWIFT CSP. Cryptika goes beyond business level and management systems, where we evaluate and audit our customers environments at the IT systems, infrastructure and business applications level by providing penetration testing, vulnerabilities assessments, security architecture review services. We’re delivering a new approach in cybersecurity, purposely designed to protect your organization from the most advanced cyber-attacks. Our pioneering approach to threat hunting and response has been rigorously tested and proven by highly regarded third-party industry analysts. We believe standing up for our values is the highest form of honor. We assist our customers in operating and maintaining their IT assets and applications with full discretion, prudence and diligence - both financial and technical. Our strength is in our ability to carter to our clients’ varied needs and provide a highly competitive procurement management service. Our aim is to keep you at the forefront of technology securely and economically. Whether you are looking for advice, testing or auditing services, it is our job as information risk, security and compliance specialized firm to keep our customers protected in today's dynamic risk environment. Our elite team, experience and proven approach keeps you protected with future-proofed advice delivered in plain English. By thinking outside the box, and keeping up to date with all the latest industry developments, we ensure we keep you one step ahead of the cyber threats and vulnerabilities. Vulnerabilities Assessment & Penetration Testing (VAPT) VAPT helps protecting businesses by exposing weaknesses that provide an alternative route to sensitive
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
Zero-Click Technology Changes the Concept of Cyber Attacks: No Click Needed for Hacking Cyberattacks are rapidly shifting toward more sophisticated methods that no longer rely on clicking links or downloading files as was traditionally the case, with the expanded use of silent hacking techniques that target devices... In this article: Cyberattacks are rapidly shifting toward more sophisticated methods that no longer rely on clicking links or downloading files as was traditionally the case, with the expanded use of silent hacking techniques that target devices and systems directly. According to a report published by TechCrunch, some modern attacks can now compromise users without any direct interaction from them, further complicating the global cybersecurity landscape. This new development reflects how cyberattack tools are increasingly relying on hidden vulnerabilities, automated systems, and artificial intelligence to bypass traditional defenses. Silent attacks are expanding The new methods exploit vulnerabilities within applications, operating systems, or communication services, allowing attackers to carry out breaches without the user clicking a link or opening a malicious file. This type of attack is often known as “Zero-Click” attacks, where the breach occurs invisibly to the user, making detection more difficult compared to traditional phishing methods. These attacks are increasingly targeting smartphones, messaging apps, cloud infrastructure, and internet-connected devices. AI is changing the cybersecurity landscape The report noted that the evolution of AI tools has contributed to increasing the complexity of cyberattacks and accelerating attackers' ability to develop more precise and flexible methods. Intelligent systems are now used to analyze vulnerabilities, write malware, and automate phishing and attack operations faster than before. In response, cybersecurity companies are also relying on AI to monitor threats, analyze suspicious patterns, and respond to attacks more quickly. Traditional protection is no longer enough What is happening now confirms that relying solely on passwords or caution
Golden Ten Data reported on May 25th that the European Central Bank will convene a meeting with banks on Tuesday to discuss the cybersecurity risks revealed by the latest AI models, such as the Claude Mythos Preview developed by Anthropic, and to urge banks to accelerate the protection of their IT systems. European Central Bank Supervisory Board Vice Chair Frank Elderson stated that it is “unfortunate” that European banks cannot access the Mythos model, but he hopes that US banks attending Tuesday’s meeting will share their experiences and lessons learned from testing the model with their European counterparts. “Not being able to use the model is no excuse for inaction; malicious actors may soon gain access to this technology.” According to Anthropic, the Mythos model has already identified thousands of high-severity vulnerabilities across all mainstream operating systems and web browsers. Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
The Administration for Cybersecurity yesterday said it would expand the scale of cybersecurity attack and defense drills this year by including more critical infrastructure (CI) operators. The government has designated CIs for energy, water resources, telecommunication, transportation, banking and finance, emergency services, hospitals, science parks, and industrial parks. According to the Regulations for Classification of Cyber Security Responsibility Levels (資通安全責任等級分級辦法), “Class A” CI operators are those whose information and communication systems, if disrupted or compromised, would have a “catastrophic or extremely severe impact” on public interests, public morale, or the life, body and property of the public. Photo: Reuters “Class B” operators are those that would cause “severe impacts” under similar circumstances, the regulations state. This year’s cybersecurity drills would include Class B operators, such as regional water resources agencies and hospitals, the administration said. China attempted to breach Taiwan’s critical infrastructure an average of 2.63 million times last year, a 6 percent increase from 2024, it said, citing a National Security Bureau report. Other bureau reports showed that on top of intensive cyberattacks targeting the nation’s telecommunications and transportation systems, and defense supply chains since 2024, there was also a significant increase in breaches of Taiwan’s energy infrastructure, emergency services and hospitals last year, the administration said. That shows China has switched from data theft to disrupting people’s lives and social stability, it added. Critical infrastructure is most vulnerable to cybersecurity risks when there are loopholes in old systems or those that are difficult to replace, the administration said. While the integration of information technology and operation technology systems helps enhance management efficiency, it also increases risks of external intrusion, it said. At the same time, government agencies face risks from outsourced systems and supply chain management, excessive account privileges and lack of cybersecurity awareness among government workers, the
The nation’s government agencies reported 726 cybersecurity incidents last year, of which nearly 69 percent were unauthorized intrusion cases, Administration for Cybersecurity data showed. In accordance with the Regulations Governing the Reporting and Response of Cybersecurity Incidents and Exercises (資通安全事件通報應變及演練辦法), government agencies classify reportable cybersecurity incidents into levels 1 through 4, from least to most severe, based on the severity of the incident’s impact on confidentiality, integrity and availability. Last year, 726 cybersecurity incidents were reported by government agencies, down from 755 in 2024, administration data showed. Photo: Reuters Among the incidents, 87.33 percent were level 1 cases, 9.78 percent were level 2 cases and 2.89 percent were level 3 cases. No level 4 cases were reported. Regarding the types of cybersecurity incidents, 68.6 percent were unauthorized intrusion cases, followed by equipment malfunctions (15.43 percent), service disruptions (4.96 percent) and Web page attacks (2.48 percent), the data showed. The administration also identified the major cybersecurity threats faced by government agencies. First, backdoor programs could be installed on newly acquired government computers if users download maliciously spoofed messaging applications. Second, blackmailers could gain unauthorized access to the mainframe and avoid detection by using a “bring-your-own-driver” technique to disable security protections. Third, system maintenance contractors could install remote access software on the Web server, allowing attackers to gain access to the agency’s Web site through a brute-force password attack. Fourth, vulnerabilities or configuration risks in network edge devices could result in malicious connection activities. To counter these threats, government agencies should require approval for all software, hardware and application installations, the administration said, adding that they should regularly conduct vulnerability scans and patch any found, deploy Web application firewalls, and maintain updated endpoint protection and threat detection mechanisms. The administration also urged government bodies to improve supplier security management — including access
Only hours before Donald Trump was set to sign a long-awaited executive order on Thursday that would have called for a government safety review of new artificial intelligence models before their release, the president abruptly backed out. Despite growing public backlash to the technology and experts warning new models will pose critical security risks, Trump vowed the US government would not slow down the AI race. During a meeting with reporters on Thursday, Trump cited both American dominance and competition with China and as his reasoning behind the reversal. “I didn’t like certain aspects of it, I postponed it,” Trump said of the executive order in the Oval Office. “We’re leading China, we’re leaving everybody, and I don’t want to do anything that’s gonna get in the way of that lead.” Trump’s postponing of the order was a victory for tech leaders who have long opposed AI regulation and spent millions lobbying against it. The decision was also the direct result of their influence, according to reports from multiple news outlets, with tech billionaires including Elon Musk, Mark Zuckerberg and former White House “AI czar” David Sacks personally urging Trump to reverse course in private phone calls. After a brief period in which the White House appeared concerned enough about potential security implications to consider restraints on frontier AI, Trump’s decision marks a return to his own earlier hands-off approach and signals a laissez-faire future. The tech industry retains its ability to pursue rapid advancement of AI regardless of the potential harms, and Silicon Valley’s leaders have successfully tested their power to kill any attempts at regulation in infancy. Powerful cybersecurity AI forces White House to consider regulation White House discussions around the order began after Anthropic last month announced its latest model, Claude Mythos, but declared that it would
Cyberattacks against Japan drastically down during Lunar New Year holidays: US cybersecurity firm Sign up now: Get insights on Asia's fast-moving developments The number of phishing attacks against Japanese companies and individuals, disguised as emails from legitimate big firms, was down by over 70 per cent during China’s Lunar New Year holidays in February, according to a US cybersecurity firm. The attacks were potentially carried out systematically from China, with an official from cybersecurity company Proofpoint saying the finding suggested “hackers may observe the Lunar New Year as well”. If recipients visit fake websites via links in the phishing emails, personal information, such as credit card numbers, as well as client data in the case of companies, could be stolen. In February and March, Proofpoint analysed malicious emails received by its Japanese clients that looked as if they were sent from household names such as online shopping platform Amazon, tech giant Microsoft and digital payment app PayPay, among others. The result showed that the volume of phishing emails plunged to around 350,000 per day during the Feb 15 to Feb 23 public holidays in China in 2026, compared with about 1.3 million mails a day on average between late January and early February. It was also noticed that there were more phishing attacks on weekdays than on Saturdays and Sundays even after the holidays. “It is highly likely that these hackers work with a set schedule – coming to work on weekdays and resting on weekends and holidays, just like typical corporate employees,” said Ms Yukimi Sota of Proofpoint, who took part in the analysis. Proofpoint found traces of the Chinese language being used in the emails. It also observed that many of the emails were sent between around 9am and 5 pm Beijing time. Since the Chinese writing system
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
#How Did Anthropic’s Project Glasswing Revolutionize Cybersecurity? Anthropic's Project Glasswing has made history by identifying over 10,000 high- and critical-severity software vulnerabilities in just a few weeks. This incredible achievement includes thousands of zero-day flaws that have evaded detection for years in widely used systems. Among the significant findings are a 27-year-old vulnerability in OpenBSD and a 16-year-old bug in FFmpeg, both of which were missed during multiple rounds of manual code review and automated tests. #What is the Purpose of Project Glasswing? Launched on April 7, 2026, Project Glasswing leverages Anthropic’s unreleased model, Claude Mythos Preview, focused on finding security flaws. The initiative engages a coalition of technology and infrastructure organizations that receive exclusive rights to utilize this highly capable AI model for defensive security measures. In total, over 40 organizations are now part of this coalition. Anthropic has pledged up to $100 million in model usage credits to enhance the overall effectiveness of the initiative, alongside approximately $4 million allocated for open-source security improvements. #What Are the Key Findings from the Initiative? As of late May 2026, the results of this project are staggering. Partners have collectively reported more than 10,000 high- and critical-severity vulnerabilities. Many of these vulnerabilities are zero-days, indicating they were formerly unknown to both software maintainers and the wider cybersecurity community. #Why is Fixing Vulnerabilities a Challenge? While identifying vulnerabilities is pivotal, the challenge lies in remediating them effectively. Although thousands of critical findings have been validated, fewer than 100 patches have been deployed. The pace at which the AI detects flaws surpasses the industry’s existing remedial capabilities. The revelations caused by these zero-day discoveries are significant. For instance, the long-lingering flaw in OpenBSD is particularly telling, as hundreds of security audits and expert reviews over the years failed to identify it—until now, thanks
News Flash DHAKA, May 23, 2026: The United Arab Emirates (UAE) has expressed strong interest in expanding investment in Bangladesh’s cybersecurity, information and communication technology (ICT), and other emerging sectors. The interest came during a bilateral meeting between Home Minister Salahuddin Ahmed and the UAE Ambassador to Bangladesh Abdulla Ali Khaseif AlHmoudi at the Bangladesh Secretariat here on Saturday. According to a ministry press release, the meeting was held in a cordial atmosphere and focused on strengthening bilateral cooperation in trade, investment, security, skilled manpower export, and legal assistance. During the discussion, Ambassador AlHmoudi said several leading UAE companies are keen to invest in Bangladesh, particularly in cybersecurity, ICT, and various prospective and emerging sectors. He expressed optimism that enhanced economic cooperation would elevate bilateral relations to a new level. Welcoming the UAE’s investment interest, Salahuddin Ahmed said Bangladesh is fully prepared to provide all necessary support and cooperation to facilitate Emirati investments in these sectors. The minister noted that Bangladesh is working to expand its digital infrastructure and technological capabilities, creating significant opportunities for foreign investors in innovation-driven industries. The meeting discussed broader collaboration between the two countries, including manpower export, human trafficking prevention, and mutual legal assistance in criminal matters. It also placed significant emphasis on the export of skilled Bangladeshi manpower, particularly professional drivers and gardeners, to the United Arab Emirates (UAE). The UAE Ambassador said there is a growing demand in the UAE for trained and skilled drivers, adding that the Emirati government requires foreign drivers to complete a six-month specialized training programme in line with the country’s standards and regulations. In response, the home minister assured the UAE of Bangladesh’s full cooperation in supplying skilled manpower. He proposed that the two countries jointly introduce internationally standardised six-month driver training courses in Bangladesh to prepare workers