- Federal cyber officials warn advanced AI tools could aid both defenders and hackers - CIA official says Anthropic’s Mythos model marks a major cybersecurity inflection point - Public-private cooperation seen as essential to protecting critical infrastructure Federal cyber leaders have warned that advanced artificial intelligence models pose both opportunity and risk, urging agencies to strengthen partnerships with the private sector, Nextgov/FCW reported Monday. Advancements in AI and cybersecurity are reshaping how intelligence agencies collaborate with industry to address evolving threats and mission demands. Learn more about the technologies driving the intelligence community at the Potomac Officers Club’s 2026 Intel Summit on Sept. 24. Register now. Table of Contents Why Is Mythos a Turning Point? Dan Richard, associate deputy director of the Digital Innovation Directorate at the CIA, said during the Qualys ROCon Public Sector 2026 conference that Anthropic’s Mythos model represents a “reflection point” for agencies managing sensitive data. Mythos can detect extensive software flaws, raising concerns that it could also empower hackers. Anthropic introduced Mythos in April as part of its Project Glasswing cybersecurity initiative, describing the model as capable of autonomously identifying software vulnerabilities and exploit paths. The company said the technology could strengthen cyber defense operations but warned that malicious actors could also misuse similar frontier AI systems. Richard said the CIA sees potential to automate threat response but emphasized the need for collaboration with industry, noting that most U.S. critical infrastructure is privately owned. How Could AI Change Federal Cybersecurity Operations? Richard said public-private collaboration will be critical as agencies adapt to rapidly evolving AI technologies. He noted that 80 percent of the nation’s critical infrastructure is operated by private-sector organizations, requiring closer coordination between government and industry. IonQ Chief Information Officer Katie Arrington, former Pentagon CIO and previous winner of the Wash100 Award, said
May 20, 2026 · via executivegov.com
Bresnahan’s Cybersecurity Legislation Passes House Small Business Committee WASHINGTON, DC: Today, U.S. Representative Rob Bresnahan, Jr. (PA-08) announced the Small Business Competitions Assistance Evaluation Act of 2026, legislation he co-led, passed out the House Committee on Small Business. His legislation, which passed unanimously by a bipartisan vote of 23-0, will ensure small businesses are protected from cybersecurity risks by studying the effects these attacks can have on small businesses. “In the United States, small businesses are 210% more likely to experience cyber incidents compared to larger companies,” said Rep. Bresnahan. “This is a significant challenge for the businesses that make up Main Streets across the country and is something Congress can no longer afford to overlook. This legislation will help ensure that as cyber threats continue to evolve, our support systems for small businesses evolve as well.” Specifically, the legislation directs the U.S. General Accountability Office (GAO) to evaluate Federal cybersecurity assistance to small businesses. The bill would require a study to analyze cyber risks, vulnerabilities, and current initiatives and identify shortcomings of current preventative and mitigating measures. In addition to the Small Business Competitions Assistance Evaluation Act of 2026, the House Committee on Small Business passed nine bills, including legislation to strengthen transparency of the Small Business Administration’s (SBA) disaster loan program, direct the SBA to provide active outreach to small businesses on health coverage options, and require the SBA to provide recommendations to address anticompetitive conduct. ###
May 20, 2026 · via bresnahan.house.gov
Exclusive—Sen. Rick Scott & Rep. Andy Ogles: America’s Cybersecurity Cannot Be an Easy Target for Communist China May 20, 2026 Breitbart Sen. Rick Scott and Rep. Andy Ogles May 20, 2026 American-led innovation has built a digitally connected world that’s created enormous benefits for American families and businesses. For most American families, access to people and products from anywhere in the world comes as easily as reaching for the phone in our pocket. Now, imagine if tomorrow that access we’ve become familiar and comfortable with became our biggest threat. Think of a world in which the Chinese Communist Party (CCP) were able to launch a cyber-attack and target your power and water, block your bank accounts, or turn off your internet. That’s the reality America faces today and why we are fighting to protect American families and pass the Strengthening Cyber Resilience Against State-Sponsored Threats Act. The CCP understands the vulnerability of weak cybersecurity infrastructure. Communist China is constantly prodding U.S. security, looking for a way to undermine the American economy and disrupt our lives with CCP-backed groups of hackers known as “Volt Typhoon” and “Salt Typhoon.” The threats posed by CCP-back cyber-attacks are more real than many folks realize. In February 2024, U.S. government agencies revealed that Volt Typhoon had been burrowed into the IT environments of key critical infrastructure sectors like energy, water and wastewater systems, transportation systems, and communications for years. If a hospital is locked out of its systems, life support could fail and patients would die. An attack on our electrical grid could deny millions of families access to heat in the winter, lights would not turn on, and they wouldn’t be able to keep food in their refrigerator. If the CCP attacked our financial institutions, hackers could empty your bank account or delete all
May 20, 2026 · via rickscott.senate.gov
Running to a Future in Computer Science and Cybersecurity Nicholas Scarangelli (’26) grew up surrounded by family members who worked in computer science. His father is a computer scientist for the FAA; his sister, Gianna Scarangelli (’24), is a computer engineer. Originally interested in engineering, he took an advanced programming class during his senior year and fell in love. “To me, coding is like a puzzle — once you figure out where the pieces go, they all fit together,” Nicholas shared. “There are infinite possibilities of what you can make through code.” Embry-Riddle Met the Criteria Nicholas and his parents took a 3,000-mile road trip to visit dozens of colleges from Maine to Florida. That trip helped him realize that he wanted to attend a smaller school in a warm state. He also wanted to run at the collegiate level. “Once I figured out my criteria, Embry-Riddle kept coming back to mind,” Nicholas said. “I had been here on several visits to see my sister and was in awe of the campus. It was modern and in a great, lively area with beautiful beaches nearby.” When he took an official tour of Embry-Riddle, he realized the facilities, class size and expert professors met his criteria. “The cross-country track and field team sealed the deal. I met the coach and team, and I loved the vibe — everyone was so friendly.” Nicholas has found that smaller class sizes allow for better relationships with his professors. They’re available for questions and want to help their students succeed. Teaching assistants have also been a valuable resource to Nicholas. “Along with the professors and teaching assistants, I have utilized the Academic Advancement Center, which is an amazing resource on campus,” he said. “I really enjoy going, and the tutors are great at explaining topics
May 20, 2026 · via erau.edu
Healthcare has been among the industries most affected by data breaches related to staff mistakes, according to Verizon. “Breaches take many forms, but in the healthcare sector, one pattern stands out: miscellaneous errors,” the telecom giant stated in its annual data breach investigations report. “The ranking may vary from year to year, but it remains a chronic problem that needs a cure.” Here are seven more things to know about healthcare data breaches, according to the study that analyzed security incidents between Nov 1, 2024, and Oct 31, 2025: 1. Healthcare had 1,438 data breaches, the fourth-most of any sector. 2. System intrusion (largely ransomware), miscellaneous errors and social engineering represented represented 81% of the breaches. 3. The most common errors were misdelivery (data being sent to the wrong recipient), loss (such as unencrypted user devices and portable media) and misconfiguration (like exposing a data repository to the internet without appropriate controls). 4. Eighty-one percent of the threat actors were external, while 19% were internal. 5. The No. 1 motive by far (99%) was financial, with 2% espionage-related. 6. The most common initial access points for threat actors were vulnerability exploitation (20%), phishing (14%), and credential abuse (11%). 7. Fifty-four percent of the breaches involved a human element, while 32% originated with third parties (the Oracle E-Business Suite vulnerability was a big driver across industries). At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.
May 20, 2026 · via beckershospitalreview.com
Security exceptions are increasing cybersecurity risk, survey finds New survey data shows how formal and informal security exceptions are increasing business and cybersecurity risk across organizations Takeaways: - Every organization surveyed granted at least one security or compliance exception in the past 12 months, suggesting exception handling is now standard practice rather than an edge case. - Most exceptions were formal, but a significant share were still handled through informal workarounds, increasing the likelihood of inconsistent oversight and hidden risk. - Security exceptions are not just a governance issue; they can directly affect business outcomes by delaying product launches, market expansion, merger and acquisition activity, and AI deployments. - The broader pattern points to a culture where speed and productivity often override security policy, leaving cybersecurity teams to manage the fallout. Why security exceptions are becoming the norm One tried and true method for determining when a process is broken is watching for when there are more exceptions than there are rules. A survey of 200 U.S. cybersecurity leaders suggests that cybersecurity mandates are riddled with so many exceptions that for all intents and purposes there are no meaningful rules. Conducted by Opinion Matters on behalf of Replica Cyber, a provider of a hardened platform for deploying applications, the survey finds every respondent (100%) worked for an organization that granted security or compliance exceptions in the past 12 months. Nearly two-thirds (63%) described those exceptions as formal, while 36% said they were granted via an informal workaround. Why temporary security exceptions often become permanent There are always going to be exceptions to any rule, but by and large they should be temporary. The survey makes it clear, however, that when it comes to security policies far too many of the exceptions granted are permanent. For example, that policy created to
May 20, 2026 · via blog.barracuda.com
Michigan’s Security Chief Has More to Do Than Cybersecurity Rex Menold’s CSO title is missing the “I” that most of his counterparts across the country have in theirs. That’s due to Michigan’s unique take on the role, which spans both cybersecurity and physical infrastructure. Rex Menold was named to the chief security officer (CSO) position in Michigan in January 2026. The appointment followed nearly three decades of service to the state, during which he held a variety of roles, including in application development, enterprise services and infrastructure. Most recently, he was the state’s chief technology officer before stepping into the CSO role. There is a lot of common ground among Menold and his counterparts across the country. The vast majority hold the title of chief information security officer (CISO), though a couple have an explicit mention of “risk” in their titles: North Carolina’s CISO equivalent is Chief Risk Officer Torry Crass, while Massachusetts’ Tony O’Neill is both CISO and chief risk officer. Michigan’s approach, however, is seemingly unique. We met Menold at last month’s National Association of State Chief Information Officers conference, where he talked about his security background and his domain as chief security officer, which extends beyond the realm of cyber to include physical infrastructure. Video Transcript: I've been in security for maybe 13 or 14 years. I started in with CMS and Medicaid, doing a lot of the compliance and security for Medicaid systems. And I've kind of stayed with it, with identity and things like that. But the quick change of it fits me personally. I'm better with chaos, like, I’m the guy that you want when everything is falling apart because, I don't know, it focuses me or something. But I love how much change there is in cyber. So everyone's like ‘Oh man, we
May 20, 2026 · via govtech.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
May 20, 2026 · via youtube.com
Reported exposure of federal cybersecurity agency login data prompts Hill scrutiny Lawmakers are seeking a briefing from the Cybersecurity and Infrastructure Security Agency after reports that a contractor-linked GitHub repository briefly exposed authentication credentials and cloud access information tied to the agency before it was taken offline. Top Democratic lawmakers on the House Homeland Security Committee have requested a briefing from Cybersecurity and Infrastructure Security Agency acting Director Nick Andersen following reports of a contractor-linked leak of internal agency credentials. Independent journalist Brian Krebs reported Monday that researchers identified a publicly accessible GitHub repository connected to government contractor Nightwing that allegedly exposed a broad collection of sensitive access information tied to systems used by CISA and its parent agency, the Department of Homeland Security. “We demand a briefing as soon as possible on how this serious security lapse occurred, any potential security consequences, remediation activities, corrective actions related to the contractor personnel involved, and efforts to monitor for and prevent similar activity from occurring in the future,” wrote Rep. Bennie Thompson of Mississippi, the committee’s ranking member, and Rep. Delia Ramirez of Illinois, the ranking member of the panel’s cyber subcommittee, in a Tuesday letter shared with Nextgov/FCW. The materials, stored in a repository labeled “Private CISA,” reportedly included items like authentication credentials, AWS GovCloud information and other sensitive data. The repository was later removed from public view. Nextgov/FCW has not independently verified its contents. “Security researchers said the content openly available online included information on ‘how CISA builds, tests and deploys software internally,’ and they described it as ‘one of the most egregious government data leaks in recent history.’ We agree,” said the letter, referring to the contents of Krebs' reporting. A Nightwing spokesperson referred inquiries to CISA. “We do not comment on congressional correspondence but respond to members
May 20, 2026 · via govexec.com
AUSTIN, Texas, & WIESBADEN, Germany--(BUSINESS WIRE)--May 20, 2026-- CrowdStrike (NASDAQ: CRWD) and SVA System Vertrieb Alexander GmbH, one of Germany’s leading system integrators and IT service providers, today announced a strategic partnership to bring the AI-native CrowdStrike Falcon® platform to public sector, enterprise, and mid-market organizations across Germany. With this agreement, SVA is standardizing on CrowdStrike to help customers consolidate cybersecurity at scale and advance the company’s next phase of cybersecurity growth. As German organizations accelerate cloud and AI transformation, adversaries are exploiting the complexity of modern environments and weaponizing AI to infiltrate and move laterally across systems faster than disjointed security stacks can detect and respond. By unifying best-in-class endpoint, identity, cloud, next-gen SIEM, and data protection with AI-driven automation, Falcon is the operating system of security for the AI era. Through this partnership, SVA will offer the full CrowdStrike Falcon platform as a foundational component of its cybersecurity strategy. By standardizing on CrowdStrike, SVA will help customers eliminate tool sprawl, reduce complexity and cost, all while stopping breaches. “Today’s threat landscape demands performance and cost savings that stitched-together, point product security stacks can’t provide. When a leading systems integrator like SVA standardizes on CrowdStrike, it underscores the competitive advantage that Falcon delivers,” said Jens Pälmer, senior director, channel & alliances, Central-Eastern Europe at CrowdStrike. “We’re excited to partner with SVA to transform cybersecurity across the German market and stop breaches with the most advanced AI-native platform.” “Customers want measurable security outcomes without added operational burden,” said Mark Sobol, head of the cybersecurity business unit at SVA. “Seeing CrowdStrike’s proven success, we view the Falcon platform as strengthening our ability to deliver scalable cybersecurity solutions that align with evolving cloud and AI requirements. With CrowdStrike, we’re providing organizations with a unified approach to stopping breaches that reduces complexity while
May 20, 2026 · via ir.crowdstrike.com
BASINGSTOKE, United Kingdom, May 20, 2026 (GLOBE NEWSWIRE) -- Juniper Research is pleased to announce that entries are now open for the inaugural ‘Future Digital Awards for Identity & Security 2026’. These new industry awards aim to recognise both the trailblazers and the market leaders driving the dynamic cybersecurity and digital identity markets; ranging from Know Your Customer (KYC) and Anti-money Laundering (AML) to post-quantum cryptography, and biometric security. “As digital services continue to evolve, identity and security have become essential foundations for trust, user protection, and long-term growth. Our new Identity & Security Awards will recognise the companies and leading innovators across this critical technology sector,” said Nick Maynard, VP of Research at Juniper Research. This year’s awards cover: Identity Innovation - Identity Verification Innovation - AML Innovation - KYC Innovation - Best Digital Identity Platform - Digital Travel Credential Innovation - Best Digital Identity Scheme Identity Leadership - Identity Leader of the Year - Identity Start-up of the Year Security Innovation - Best Post-quantum Cryptography Solution - Best Identity & Access Management Platform - Application Security Innovation - Data Security Innovation - Biometrics for Border Control Innovation - Industrial Endpoint Cybersecurity Innovation - Cybersecurity Innovation of the Year - Biometric Security Innovation of the Year Security Leadership - Security Leader of the Year - Security Start-up of the Year Winning at the Juniper Research Future Digital Awards goes beyond just a trophy. It strengthens your market positioning, supports client engagement, and informs future product development. Click here to learn how G+D Netcetera used its award win as a platform to drive tangible business outcomes and shape future product strategies. Interested companies can apply via the entry form on the website. There is no fee to enter. The nominations period closes on Friday 7th August 2026, with all winners
May 20, 2026 · via globenewswire.com
May. 19, 2026
UNLV has established the Nevada Institute of Cybersecurity, which will consolidate UNLV’s educational, research, and community outreach efforts. The Institute brings together expertise from multiple disciplines to increase the university’s reach and provide more opportunities for academic partnerships and private company collaborations. UNLV has been recognized as a National Center of Academic Excellence in Cyber Defense Education since 2019, a prestigious designation managed by the National Security Agency. By building on this excellence and uniting research, workforce development, and community education, the Institute protects state interests while fostering a culture of cybersecurity awareness and preparedness.
May 20, 2026 · via unlv.edu
GitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform's source code and internal organizations for sale on a cybercrime forum. "While we currently have no evidence of impact to customer information stored outside of GitHub's internal repositories (such as our customers' enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity," the Microsoft-owned subsidiary said. The company also noted that it will notify customers via established incident response and notification channels if any impact is discovered. The development comes after TeamPCP, a threat actor behind a string of software supply chain attacks targeting open-source packages, listed GitHub's source code for sale for an asking price of no less than $50,000. The alleged data dump is said to include about 4,000 repositories. "As always, this is not a ransom," the group said in a post, according to screenshots shared by Dark Web Informer. "We do not care about extorting GitHub, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found, we leak it for free." In a follow-up update shared on X, GitHub said it detected and contained a compromise of an employee device involving a poisoned Microsoft Visual Studio Code extension. As a risk mitigation measure, the company has rotated critical secrets, while prioritizing highest-impact credentials. "Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only," GitHub said. "The attacker's current claims of ~3,800 repositories are directionally consistent with our investigation so far." GitHub did not disclose the name of the VS code extension, although it's worth noting that Nx Console recently suffered a compromise that allowed threat actors to push a multi-stage credential stealer and a
May 20, 2026 · via thehackernews.com
| Fortinet Accelerate 2026 Asia-Pacific took place on May 19 in Hanoi | On May 19, global cybersecurity firm Fortinet announced the findings of a new study conducted by Forrester Consulting, revealing that organisations across the Asia-Pacific are struggling to keep pace as cybersecurity complexity and AI-driven threats are straining their current ability to respond effectively. The study highlights cybersecurity risks driven by more advanced attackers and increasingly complex environments, and continued investment in cybersecurity and AI. The findings point to a clear shift towards simplifying security architectures, improving operational efficiency, and embedding AI into unified platforms. Cyber risk is increasingly driven by both external threats and internal complexity. 75 per cent of organisations cite AI-driven threats as a top concern, while 71 per cent highlight fragmented tools and architectures and overwhelming alert volumes. Security operations are under pressure, with 51 per cent of organisations reporting that alert volume makes it difficult to distinguish real threats, and 48 per cent still relying on manual workflows. And cybersecurity maturity remains constrained, with 68 per cent of organisations at an intermediate stage and only 16 per cent reaching advanced levels. These findings highlight a clear shift, as complexity moves beyond an operational challenge to become a core driver of cyber risk. "As organisations continue to accelerate digital transformation and AI adoption, many are re-evaluating how they manage security across increasingly distributed environments. We are seeing a stronger focus on simplifying operations, improving visibility across domains, and enabling security teams to operate more efficiently at scale," said Peerapong Jongvibool, senior director of Fortinet in Southeast Asia. "This is driving growing interest in integrated, platform-based approaches that can help organisations strengthen resilience while reducing operational complexity." Complexity and threats Organisations are accelerating their move towards unified, platform-based security architectures. While only 25 per cent
May 20, 2026 · via vir.com.vn
Governments are losing the race against AI. That is the blunt assessment of Nicole Quinn, vice president of policy and government affairs for Asia-Pacific at Palo Alto Networks. Policy moves too slowly, she argues, and overly rigid rules only make things...
The article requires paid subscription.
Subscribe Now
May 20, 2026 · via digitimes.com
Cyber unicorn Axonius surpasses $200 million ARR, doubles revenue in two years Israeli-founded cybersecurity company now serves nearly 1,000 customers globally. Cybersecurity unicorn Axonius announced that it surpassed $200 million in annual recurring revenue (ARR) during the first quarter of fiscal 2027. The figure reflects 35% year-over-year growth and a doubling of the company’s revenue over the past two years. At the same time, the company announced the appointment of Joe Diamond as permanent CEO after he served in the role on an interim basis in recent months. Diamond has served as president since August 2025 and as interim CEO since February 2026, replacing co-founder Dean Sysman, who will remain executive chairman. Comparable companies in the cybersecurity sector, including Armis, which was acquired by ServiceNow, and Claroty, have reported annual revenue run rates exceeding $300 million. Axonius was founded in 2017 by Dean Sysman, Ofri Shur, and Avidor Bartov, and operates from offices in New York City and Tel Aviv. The company has raised more than $595 million from investors including Accel, Lightspeed Venture Partners, Bessemer Venture Partners, Stripe, and Vertex Ventures. Today, the company employs more than 700 people globally, with offices across the US and Europe, alongside a research and development center in Israel. “Every board member is asking their security and IT leader the same question: how fast can you find the blast radius, contain it, and recover? There is only one way to answer that with confidence, and it starts with the foundation: asset intelligence. That is exactly what Axonius delivers with the Axonius Asset Cloud,” said Joe Diamond, CEO at Axonius. “We are the platform of platforms. No other cybersecurity leader unifies more than 45 asset classes, from security, software, SaaS, and cloud to emerging classes like connected devices and AI assets, into a single
May 20, 2026 · via calcalistech.com
Faculty mentorship fuels alumni impact in cybersecurity and artificial intelligence Randy Marchany was inducted into the Virginia Tech Department of Computer Science Academy of Distinguished Alumni, while Ashwin Aji received the department’s Distinguished Early Career Alumni Award for leadership in cybersecurity, high-performance computing, and AI research The Virginia Tech Department of Computer Science honored two alumni whose careers reflect the department’s long-standing impact on cybersecurity, artificial intelligence, and high-performance computing research. The awards were presented during the department’s spring banquet at the Inn at Virginia Tech and Skelton Conference Center. Randy Marchany, Virginia Tech information technology security officer and the director of the university’s IT Security Lab, was inducted as the 15th member of the Department of Computer Science Academy of Distinguished Alumni. Ashwin Aji, principal researcher at AMD Research, became the seventh recipient of the department’s Distinguished Early Career Alumni Award. For Marchany and Aji, faculty mentorship at Virginia Tech helped shape careers that would later influence the future of computing. “What strikes me about both Ashwin and Randy is that their work doesn't just advance their fields, it matters to people,” said Christine Julien, head of computer science. “Ashwin's contributions are helping us model climate systems at scales we couldn't reach before, and Randy has dedicated his career to protecting the university and the nation's cyber infrastructure. “That's Ut Prosim (That I May Serve) at work — a spirit of service that is woven into everything we do at Virginia Tech — and both of these alumni embody it beautifully," Julien said. "Recognizing them reminds me of what a CS@VT education, at its best, can produce." Appreciate the past and pay it forward When Marchany arrived at Virginia Tech in the 1970s, computer science was still an emerging field. He credits early department faculty, especially founding department head
May 19, 2026 · via news.vt.edu
Bloomberg Law: Law Firms Must Embed Cybersecurity in Governance to Protect Data
May 19, 2026
O’Melveny partners Sid Mody and Randy Edwards, and associate Alexander Briggs wrote a byline article for Bloomberg Law discussing how the volume of sensitive data at law firms makes them a target for data breaches, and how attorneys have ethical and legal obligations to safeguard client data by utilizing cybersecurity practices.
Read the full article here.
May 19, 2026 · via omm.com
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN's Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control (C2) domains, turning the infrastructure into a pipeline for multi-stage fraud. "Users unwittingly download a threat actor-owned app, often a utility-style app like a PDF viewer or device cleanup tool," researchers Louisa Abel, Ryan Joye, João Marques, João Santos, and Adam Sell detailed in a report shared with The Hacker News. "These apps trigger malvertising campaigns that coerce users into downloading additional threat actor-owned apps. The secondary apps launch hidden WebViews, load threat actor-owned HTML5 domains, and request ads." The campaign, the cybersecurity company added, is self-sustaining in that an organic app install turns into an illicit revenue generation cycle that can be used to fund follow-on malvertising campaigns. One notable aspect of the activity is the use of HTML5-based cashout sites, a pattern observed in prior threat clusters tracked as SlopAds, Low5, and BADBOX 2.0. At the peak of the operation, Trapdoor accounted for 659 million bid requests a day, with Android apps linked to the scheme downloaded more than 24 million times. Traffic associated with the campaign primarily originated from the U.S., which took up more than three-fourths of the traffic volume. "The threat actors behind Trapdoor also abuse install attribution tools (technology designed to help legitimate marketers track how users discover apps) to enable malicious behavior only in users acquired through threat actor-run ad campaigns, while suppressing it for organic downloads of the associated apps," HUMAN said. Trapdoor combines two disparate approaches, malvertising distribution and hidden ad-fraud monetization, where unsuspecting users end up downloading bogus apps masquerading as seemingly harmless utilities that act as a conduit for serving
May 19, 2026 · via thehackernews.com
Hassan: “This reported incident raises serious questions about how such a security lapse could occur at the very agency charged with helping to prevent cyber breaches” WASHINGTON – U.S. Senator Maggie Hassan (D-NH), a senior member of the Senate Homeland Security Committee, is pressing for answers following public reporting that a contractor for the Cybersecurity and Infrastructure Security Agency (CISA) maintained lists of agency accounts and passwords on a public database. Senator Hassan issued a request for an urgent classified briefing from the agency, which is part of the Department of Homeland Security. “This reported incident raises serious questions about how such a security lapse could occur at the very agency charged with helping to prevent cyber breaches,” wrote Senator Hassan in her request. “This reporting raises serious concerns regarding CISA’s internal policies and procedures at a time of significant cybersecurity threats against U.S. critical infrastructure… The alleged data leak has also occurred against the backdrop of major disruptions internally at CISA.” Senator Hassan continued, “CISA’s public statement that ‘there is no indication that any sensitive data was compromised as a result of this incident’ leaves unanswered questions about the policies and procedures that made it possible for this incident to reportedly occur in the first place. Given the potentially significant impact of this data leak, I request a briefing at the highest classification level.” Read Senator Hassan’s request here or below. Dear Acting Director Andersen: I write to request an urgent classified briefing regarding public reporting that a contractor for the Cybersecurity and Infrastructure Security Agency (CISA) maintained lists of agency accounts and passwords on a public database. This reported incident raises serious questions about how such a security lapse could occur at the very agency charged with helping to prevent cyber breaches. According to a recent report from
May 19, 2026 · via hassan.senate.gov