Sen. Rick Scott Introduces Bill to Strengthen American Cybersecurity Infrastructure May 19, 2026 WASHINGTON, D.C. — Today, Senator Rick Scott introduced the Strengthening Cyber Resilience Against State-Sponsored Threats Act. This legislation would create a joint interagency task force led by the Cybersecurity and Infrastructure Security Agency (CISA) with the goal of better detecting, analyzing, and responding to Chinese state-sponsored cyber actors — including the Chinese Communist Party’s (CCP) hacker-arm, Volt Typhoon. This bill was led in the U.S. House of Representatives by U.S. Rep. Andy Ogles (R-Tenn.) and passed the House overwhelmingly with a vote of 402-8 on November 17, 2025. Communist China is constantly prodding U.S. security, looking for a way to undermine the American economy and disrupt our lives. In February 2024, U.S. government agencies revealed that Volt Typhoon had been burrowed into the IT environments of key critical infrastructure sectors like energy, water and wastewater systems, transportation systems, and communications for years. Senator Rick Scott said, “As the world’s leading digital economy, America has the most to lose in a cyberattack. If we don’t secure our digital infrastructure, hackers could cut power to your house, empty your bank account, or disable life support for a loved one in the hospital. Americans shouldn’t worry about a cyber threat from the CCP, which is why I’m proud to be introducing this legislation with Rep. Ogles. The House has done its job in passing this bill, now we need the Senate to do ours.” Rep. Ogles said, “The Chinese Communist Party is the greatest foreign adversary we face, and Beijing continues to use cyberspace as a battlefield on which to undermine American sovereignty and interests. In the wake of attacks by CCP-backed actors against our critical infrastructure and even their intrusions into the campaign communications of President Trump and Vice
May 19, 2026 · via rickscott.senate.gov
Sen. Rick Scott Introduces Maritime Cybersecurity Act May 19, 2026 WASHINGTON, D.C. — Today, Senator Rick Scott, with co-lead Senator Andy Kim (D-N.J.), introduced the Maritime Cybersecurity Act, legislation requiring the U.S. Department of Homeland Security (DHS) to monitor cybersecurity risks associated with software and hardware used at maritime facilities and act to prevent cyberattacks. The Maritime Cybersecurity Act ensures safe and secure maritime transportation and port operations by addressing potential cybersecurity vulnerabilities — especially in the face of foreign threats from adversaries such as the CCP — by mandating annual vulnerability assessments, focusing on identifying weaknesses in security. Senator Rick Scott said, “America’s enemies are looking for vulnerabilities and cracks in our armor. Facilitating basic assessments to identify our weaknesses in security is a commonsense measure to keep American assets safe both domestic and abroad. My bill makes sure our trade and waters cannot be disrupted by bad actors, especially the Chinese Communist Party (CCP). We have to be prepared to take on the cyber criminals backed by Beijing, and this bill takes a major step to doing that.” Senator Andy Kim said, “Our nation must be equipped to tackle evolving 21st-century threats. Cybersecurity resilience is a critical facet of national security, and this bipartisan bill is a strong first step to ensure we are prepared to address vulnerabilities and stop these threats wherever they are – including at maritime facilities.” Under this legislation, facility owners and operators would submit annual reports detailing their use of such software and hardware and must certify that their systems are safe from cybersecurity risks. If they could not make this certification, they would only be allowed to use the software or hardware if granted a waiver. The bill also requires the Secretary of DHS to take action to mitigate identified risks and
May 19, 2026 · via rickscott.senate.gov
Since the 1980s, when the first malicious computer viruses emerged, cybersecurity has evolved from a niche IT interest into a critical layer of the digital systems that connect us all. And that constant race to protect computing infrastructure adds up, with cybercrime racking up $10.5 trillion in damages globally. As companies try to secure sprawling cloud infrastructure, remote work setups and AI models that didn’t even exist a few years ago, they turn to cybersecurity engineers to build stronger safeguards into the systems themselves. That pressure has made cybersecurity engineering one of the fastest-growing technical fields, reflecting an average annual base salary of $166,000. Below are companies that consistently hire cybersecurity engineers onto their cyber-defense teams to strengthen threat detection and protect the cloud systems modern businesses rely on every day. Top Companies Hiring Cybersecurity Engineers - Palo Alto Networks - CrowdStrike - Microsoft - Cisco - Google Cloud Top Companies Hiring Cybersecurity Engineers Headquarters: San Jose, California Founded: 1984 Company size: 86k+ employees Industry: Networking Infrastructure Cisco’s routers move 80 percent of internet traffic worldwide. The company’s networking dominance is why it is one of the biggest players in enterprise cybersecurity. Roles on its security team involve work across zero-trust architecture, network telemetry and secure access systems, with hiring focused on candidates who know firewalls, SD-WAN, packet analysis and enterprise network security operations. Headquarters: Redmond, Washington Founded: 1975 Company size: 220k+ employees Industry: Enterprise Software, Cloud Computing Microsoft’s Microsoft Security division operates one of the largest cybersecurity ecosystems in the world because its tech stack is built directly into Windows, Azure and Microsoft 365. Together, these platforms support hundreds of thousands of businesses and more than 400 million users. Cybersecurity roles there often focus on identity protection, cloud defense and AI-assisted threat detection using tools like Microsoft Sentinel, Defender
May 19, 2026 · via builtin.com
OSC Technical Solutions adds James Cervini, EngD, to strengthen critical infrastructure and operational technology cybersecurity capabilities. ANCHORAGE, AK, UNITED STATES, May 19, 2026 /EINPresswire.com/ — OSC Technical Solutions (OSC-TS), a mission-focused technology and cyber engineering firm within OSC Global and the CIRI family of companies, has expanded its industrial control systems and critical infrastructure cybersecurity expertise with the addition of James Cervini, EngD, as Director & Principal Architect, Operational Technology Cybersecurity. Headquartered in Washington’s Tri-Cities region, OSC-TS delivers IT modernization, cybersecurity operations and ICS/OT cybersecurity for high-consequence, highly regulated environments. Dr. Cervini brings deep expertise in industrial control system architecture, cyber-physical resilience, and operational technology security, with experience spanning several critical infrastructure sectors including energy, water, defense, chemical, transportation, and manufacturing. His background combines advanced applied research with hands-on work supporting the protection of complex operational environments where security, reliability, and continuity are essential. He most recently served as a Senior OT/ICS Cybersecurity Researcher at Idaho National Laboratory; a role reflected in his public professional profile and other public conference listings and has been active in the broader ICS security research community. He holds an Engineering Doctorate from Johns Hopkins University, where his research focused on innovative, testbed-validated approaches to improving ICS resilience through virtualization, software-defined networking, and cryptographic attestation for programmable logic controllers. His work has also addressed critical infrastructure attack modeling, cyber-physical system protection and practical mitigation approaches for resource-constrained operators in the energy and water sectors. Most recently, Dr. Cervini served as a Senior Cybersecurity Researcher at Idaho National Laboratory, where he supported energy-sector cybersecurity efforts tied to real-world programs involving federal sponsors, DOE offices and industry stakeholders. His expertise includes ICS/OT network architecture, observability design, threat emulation, incident response, anomaly detection in constrained environments, and familiarity with energy and nuclear cybersecurity frameworks, including DOE O 205.1C,
May 19, 2026 · via kitsapsun.com
AI x Cybersecurity Challenge The competition is conducted on a team basis for both registration and participation. Each participating team must design, build, and operate an AI-driven automated system capable of automatically analyzing the target range provided by the organiser, identifying vulnerabilities, and exploiting them. The vulnerabilities in the target range include both real-world scenario vulnerabilities and potential "zero-day vulnerabilities" inherent in the software itself. The Challenge is free of charge. For details, please visit the event website https://hksecai.hk. Interested parties are requested to complete and submit the online registration form on the website on or before 26 June 2026 (Friday). Organisers:Digital Policy Office, Hong Kong Cybersecurity Professional Association, China Mobile Hong Kong Company Limited Co-Organisers:Hong Kong Productivity Council, Hong Kong Cyberport Management Company Limited,Venustech Group Inc. ,Hong Kong Cloud Peak Technology Co. Limited Date:14 May 2026 - 23 Aug 2026 Charge:Free of charge The competition is open to participants from Mainland China, Hong Kong, and overseas. Participants must be at least 18 years old by the registration deadline and must hold a valid proof of identity. The competition consists of two stages: the "Preliminary" and the "Final." The Preliminary round is a 12-hour online competition conducted in a “Jeopardy-style” format. Participating teams are required to apply cybersecurity techniques to identify system vulnerabilities, successfully exploit challenges, and locate hidden “flags” to earn points. The Final round is designed to further test teams’ practical capabilities. It will be held as a one-day, daytime, on-site competition in Hong Kong, featuring a combination of AI attack-and-defense challenges and real-world scenario tasks. Participants must complete various missions in a simulated environment to accumulate points. For more details, please visit the official website: https://hksecai.hk . Related Tags Share with
May 19, 2026 · via hkcert.org
Major Australian banks are using OpenAI’s most powerful artificial intelligence model to test for vulnerabilities in their cybersecurity systems, while rival Anthropic plans to brief the Reserve Bank of Australia on the ability of its Mythos program to identify threats in the financial system and critical infrastructure.
Commonwealth Bank and Westpac have turned to the OpenAI model – known as GPT-5.5-Cyber – after Anthropic restricted access to Mythos to a group of US technology companies.
Loading...
May 19, 2026 · via afr.com
Anthropic’s Mythos data sharing plan sparks new cybersecurity risk Anthropic’s “Project Glasswing” will allow Amazon, Microsoft, Nvidia and Apple to use the unreleased Claude Mythos model for defensive cybersecurity. Anthropic is posing new threats to AI usage and security risks. It comes as the AI startup Anthropic said on Monday that it is revising its earlier position to allow users of its "Mythos cybersecurity model" to share information about cyber threats with others who may be exposed to similar vulnerabilities. Mythos, announced on April 7, is being deployed as part of Anthropic's "Project Glasswing," a controlled initiative under which select organizations, including major tech firms such as Amazon, Microsoft, Nvidia and Apple are permitted to use the unreleased Claude Mythos Preview model for defensive cybersecurity purposes. According to experts, Mythos' capabilities to code at a high level have given it a potentially unprecedented ability to identify cybersecurity vulnerabilities and devise ways to exploit them. Last week, Anthropic began telling partners that they are generally permitted to disclose their involvement in Glasswing and at their own discretion, share findings, best practices, tools or code developed through the program. "We fully support our partners sharing findings with each other and companies outside of Glasswing to triage vulnerabilities," an Anthropic spokesperson said in a statement. "While there was never a specific Glasswing NDA, confidentiality protections were something partners asked for at the outset and were built into agreements partners signed." The protections were included in agreements with participating companies under which the model is provided after partners sought assurances before sharing sensitive findings and expressed concern about being targeted by attackers. "As the program has matured, we've adapted them to ensure key information can be shared broadly—including outside the program—for maximum defensive impact," the spokesperson added. Anthropic said partners may share that information
May 19, 2026 · via thenews.com.pk
Cybersecurity jobs available right now: May 19, 2026 CISO DataFence | Israel | Hybrid – No longer accepting applications As a CISO, you will develop security roadmaps, compliance plans, risk registers, policies, and control implementation plans while leading audit and regulatory compliance activities. You will manage client projects from planning through delivery, conduct risk assessments, gap analyses, internal audits, and security maturity reviews, and prepare reports and recommendations for stakeholders and executive teams. Cyber Security Analyst ZEE | India | On-site – View job details As a Cyber Security Analyst, you will monitor and investigate alerts across SIEM, XDR, IDS/IPS, and email security tools while managing incident response from triage to RCA. You will conduct threat hunting using TTPs, IOCs, OSINT, and threat intelligence, build and tune detections and SOAR workflows, analyze network and email threats, and improve telemetry, logging, and SOC operations. Cyber Security Engineer Mater Private Network | Ireland | Hybrid – View job details As a Cyber Security Engineer, you will lead the deployment of security solutions, including PAM, EDR, and other enterprise security tools. You will evaluate security architecture and controls across existing and future projects to ensure security is integrated into systems from the design stage. Cyber Security Engineer NSW Police Force | Australia | On-site – View job details As a Cyber Security Engineer, you will implement and maintain technical security controls that protect digital infrastructure, applications, and data. You will contribute to secure system design and delivery by applying cybersecurity standards, supporting risk mitigation activities, and helping ensure compliance with security policies and frameworks. Get weekly updates on new cybersecurity job openings. Subscribe here! Cybersecurity Engineer MED-EL | Austria | On-site – View job details As a Cybersecurity Engineer, you will implement, manage, and improve security technologies across the enterprise, including EDR/XDR, SIEM,
May 19, 2026 · via helpnetsecurity.com
Live Now
All times easternNOW - 5:00 AM
5:00 AM
5:30 AM
6:00 AM
6:30 AM
7:00 AM
Fox Business Channel
Fox Weather First
5:00 AM - 6:00 AM
Mornings With Maria
6:00 AM - 7:00 AM
Mornings With Maria
7:00 AM - 7:30 AM
Fox News Channel
Fox & Friends First
5:00 AM - 6:00 AM
Fox & Friends
6:00 AM - 7:00 AM
Fox & Friends
7:00 AM - 7:30 AM
Fox Weather Channel
Fox News Radio
May 18, 2026 · via foxbusiness.com
Poland has taken a significant step in strengthening its national cybersecurity framework by discouraging citizens and government officials from using popular messaging applications such as WhatsApp and Signal. According to Polish authorities, these globally popular communication platforms may expose users to cybersecurity threats, particularly sophisticated social engineering attacks carried out by Advanced Persistent Threat (APT) groups. These threat actors are often linked to organized cybercriminal networks or state-sponsored hacking operations that target sensitive communications and confidential information. In response to these concerns, the Polish government has introduced a domestically developed messaging application known as mSzyfr Messenger. The application has been specifically recommended for use by government officials and public administration employees as part of a broader initiative to reduce reliance on foreign-controlled digital communication platforms. By promoting a locally controlled messaging ecosystem, Poland aims to strengthen data sovereignty and improve protection against external cyber threats. The mSzyfr Messenger application was jointly developed by the Ministry of Digital Affairs, the Scientific and Academic Computer Network, and the National Research Institute. One of the primary advantages highlighted by Polish authorities is that the platform operates entirely under Polish jurisdiction. This means that user data, metadata, and communication records are processed and stored on servers located within the country, limiting access by foreign entities and reducing the risk of international surveillance or unauthorized data sharing. The move reflects a growing global trend in which governments seek to establish greater control over digital infrastructure and sensitive communications. In recent years, concerns surrounding cybersecurity, data privacy, and foreign influence over communication platforms have intensified. Many governments fear that dependence on internationally operated applications could create vulnerabilities in national security systems, especially during periods of geopolitical tension or cyber warfare. Despite the security-focused objectives behind mSzyfr Messenger, some cybersecurity experts and observers have pointed out certain
May 18, 2026 · via cybersecurity-insiders.com
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off. Patch the quiet risks first. Let’s get into it. ⚡ Threat of the Week On-Prem Microsoft Exchange Server Exploited in the Wild—Microsoft disclosed a security vulnerability impacting on-premise versions of Exchange Server, which has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-42897 (CVSS score: 8.1), has been described as a spoofing bug stemming from a cross-site scripting flaw. An anonymous researcher has been credited with discovering and reporting the issue. Microsoft is providing a temporary mitigation through its Exchange Emergency Mitigation Service, while it's readying a permanent fix for the security defect. There are currently no details on how the vulnerability is being exploited, the identity of the threat actor behind the activity, or the scale of such efforts. It's also unclear who the targets are and if any of those attacks were successful. The Case for Autonomous Validation in Four On-Demand Sessions Enterprise CISOs, an industry analyst, and security leaders covered why point-in-time testing no longer matches the speed of modern threats, and how teams are using validation evidence to prioritize remediation, prove control effectiveness, and report risk to leadership. Four sessions, all on demand. Watch Now ➝🔔 Top News - Cisco Catalyst SD-WAN Controller Flaw Under Attack—A sophisticated threat actor tracked as UAT-8616 has been attributed to the exploitation
May 18, 2026 · via thehackernews.com
Five years ago, when a major hacking attempt was successful, “it was big news,” said Roman Bohuk, a cybersecurity expert and 2020 University of Virginia alumnus. But, nowadays, “There’s probably 10 news articles each day about some kind of big company getting hacked,” Bohuk said. Earlier this month, a cyberattack temporarily shut down Canvas, an online education platform used by schools nationwide – including UVA – as end-of-semester staples like final exams and projects were in full swing. That incident reinforced the growing demand for companies like SkillBit, the Charlottesville-based startup Bohuk co-founded with fellow Wahoo Thomas Rogers. Originally launched as “MetaCTF,” SkillBit helps companies assess, train and strengthen cybersecurity teams through hands-on simulations designed to mirror real-world attacks. Its client list includes companies such as Uber and GitHub, as well as the University of South Florida. This week, for the second time since 2023, SkillBit is serving as a platform host for the International Cybersecurity Competition in Queensland, Australia. Known informally as the “Cyber World Cup,” the event features teams from more than 80 countries competing in cybersecurity challenges. Rogers, a former UVA basketball player, used a local hoops analogy to describe SkillBit’s role in the event. “It’s like they’re providing JPJ (John Paul Jones Arena) and inviting the teams,” Rogers said, “but we’re giving them the court, the balls, the baskets to help run the infrastructure around the actual game. “We are creating the scenarios that the teams are going to have to solve as a part of the competition.” Whether through international competitions or corporate training exercises, SkillBit’s goal is to help organizations better prepare for cyber threats. “We’ll build a mock website for a small business,” Rogers said, describing a typical exercise, “and we build the website to be vulnerable on purpose. And then we present
May 18, 2026 · via news.virginia.edu
Threat actors know that most organizations are going to have some type of endpoint defenses, whether it’s next-generation antivirus (NGAV), endpoint detection and response (EDR), or an endpoint protection platform solution (EPP). Getting around these defenses is part of their playbook and tradecraft, covered in frameworks like MITRE ATT&CK under the Defense Evasion tactic and techniques like Impair Defense (T.1652). These actors are moving beyond merely evading detection and even basic impairment to disabling threat-detection tools. This allows adversaries to create a "dark zone" where they can establish footholds, move laterally, exfiltrate data, and deploy ransomware with zero visibility to IT and security teams. This isn't just evasion; it’s an active destruction of the security stack. Attacker tradecraft and tools: How they’re wrecking antivirus and EDR There are multiple methods used by threat attackers as part of their tradecraft to impair, block, and disable endpoint security controls. Here’s a list of the most common approaches: - Blocking AV and EDR communications Attackers can blind EDR communications using malicious Windows Firewall rules via two approaches: directly creating the firewall rules, which is a bit noisy but effective, or using the Windows Filtering Platform (WFP) to create hidden firewall rules. These rules specifically block the EDR agent from communicating with its platform. The agent continues to run locally, giving the user a false sense of security, but it's effectively "silenced" and can't send any telemetry or alerts. Tools like EDRSandblast and EDRSilencer allow attackers to easily abuse Windows Firewall as part of their defense-evasion tradecraft. - Escalate privileges, uninstall agents Once an attacker lands on an endpoint, getting administrative privileges gives them much more latitude to install their tools, apply their tradecraft, and get to work. Sometimes, they might not even have to go through the effort if permissions aren’t properly secured,
May 18, 2026 · via huntress.com
Artificial intelligence represents one of the most potent forces that are reshaping cybersecurity, threat intelligence, and national security in an era of accelerated digital transformation. A promising technology, AI is transitioning into a fundamental component of both offense and defense. There are five benefits and risks that you should be aware of in building your cybersecurity strategies. Artificial intelligence is not a neutral instrument; it augments human capabilities while simultaneously introducing significant new vulnerabilities. Drawing from my published writings and insights, the following are the five most significant benefits and five most significant hazards of AI, with a particular emphasis on national security, threat intelligence, and digital transformation. To capitalize on the advantages and alleviate the disadvantages, I provide practical strategies for each. 5 Significant Advantages of AI 1. Detection of Proactive Threats AI automates the continuous monitoring of networks, identifying anomalies, isolating threats, and mitigating vulnerabilities at a rate that is many times quicker than that of human analysts. Real-time anomaly detection and predictive behavioral modeling allow systems to compare contextual signals with baselines and act autonomously, such as through micro-segmentation or quarantining. Strategies to Use: Integrate AI-native security platforms with threat intelligence inputs to conduct real-time threat hunting. Transition to "autonomous zero trust" models, which dynamically evaluate access decisions. Organizations should allocate resources to digital twins for adversarial testing, which means running simulations of adversary strategies to strengthen their defenses. Please also see: Why Proactive Cybersecurity Is Essential In The AI Era." 2. Bridging the Divide in Cyber Talent In light of the global paucity of cybersecurity professionals, AI-driven automated logging, incident response, and routine analysis significantly alleviate the workload of overworked teams. This enables human specialists to concentrate on strategic and high-value tasks. Methods to Employ: Implement AI to generate automated cyber threat intelligence (CTI) reports and
May 18, 2026 · via forbes.com
AASA Joins Coalition Letter on Cybersecurity and Infrastructure Protection
May 18, 2026
AASA joined 14 other national education and technology associations in a letter to Capitol Hill. The letter was to the House Subcommittee on Cybersecurity and Infrastructure Protection ahead of a hearing scheduled for this Thursday, May 21. The hearing is focused on cybersecurity, emphasizing the urgent and growing threats facing K–12 schools and libraries. The letter highlights how districts are confronting increasingly sophisticated cyberattacks that can disrupt instruction, compromise sensitive data, and undermine trust—challenges that are especially acute for smaller and rural systems with limited resources. The group letter underscores that cybersecurity is not a local issue alone, but a shared national responsibility that requires sustained federal partnership and investment. The groups write to highlight the importance of continuing and strengthening key federal efforts, including the State and Local Cybersecurity Grant Program, the FCC’s Schools and Libraries Cybersecurity Pilot, and the technical assistance provided by CISA. Secure connectivity is foundational to teaching, learning, and school operations, and protecting it must be a priority. Read the full letter here.
Subscribe to AASA's Blogs
Subscribe via RSS feed below. Learn more about RSS feeds here.
May 18, 2026 · via aasa.org
A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that are central to nuclear weapon design. "Fast16's hook engine is selectively interested in high-explosive simulations inside LS-DYNA and AUTODYN," the Threat Hunter Team said. "The malware checks for the density of the material being simulated and only acts when that value passes 30 g/cm³, the threshold uranium can only be reached under the shock compression of an implosion device. The development comes weeks after SentinelOne presented an analysis of fast16, describing it as the first sabotage framework whose components may have developed as early as 2005, predating the earliest known version of Stuxnet (aka Stuxnet 0.5) by two years. Evidence unearthed by the cybersecurity company included a reference to the string "fast16" in a text file that was leaked by an anonymous hacking group called The Shadow Brokers in 2017. The file was part of a huge tranche of hacking tools and exploits allegedly used by the Equation Group, a state-sponsored threat actor with suspected ties to the U.S. National Security Agency (NSA). At its core, the industrial sabotage malware features a set of 101 rules to tamper with mathematical calculations carried out by certain engineering and simulation programs that were prevalent at the time. Although the exact binaries that are patched by the malware is unclear, SentinelOne identified three probable candidates: LS-DYNA version 970, Practical Structural Design and Construction Software (PKPM), and Modelo Hidrodinâmico (MOHID). Symantec's latest analysis has now confirmed that LS-DYNA and AUTODYN are the two applications targeted by fast16, adding it was designed explicitly to interfere with simulations of high-explosive detonations, almost certainly
May 18, 2026 · via thehackernews.com
Introduction Artificial intelligence (AI) has become an integral force in the evolution of cybersecurity. Governments, corporations and critical infrastructure sectors across the Gulf states have adopted AI-enabled technologies to detect cyber threats through anomaly detection, automated responses and the rapid processing of data volumes beyond human analytical capacity. Gulf countries are shifting from reactive cybersecurity models toward more adaptive and predictive approaches, recognising that malicious actors are increasingly employing sophisticated tools for intrusion, deception, reconnaissance, social engineering, cybercrime and information manipulation. Qatar, Saudi Arabia, the United Arab Emirates, Kuwait, Bahrain and Oman have accelerated their digital transformation agendas over the past decade through national visions centred on smart city projects, fintech ecosystems, cloud platforms and e-government services. (1) Within these strategies, AI has emerged as a key driver of modernisation due to the efficiency and productivity gains it is expected to generate for Gulf economies. (2) However, the growing integration of digital platforms, automated systems and digitally managed critical services has also introduced new vulnerabilities, increasing the potential for large-scale cyber disruption. Recent industry assessments indicate that cyberattacks across the Gulf countries have risen significantly in recent years. According to Cybersecurity Ventures, the projected global cost of cybercrime reached $8 trillion in 2023 and is expected to climb to $10.5 trillion annually by 2025. (3) This demonstrates that cybersecurity is no longer merely a technical issue, but also an economic and strategic concern with direct implications for resilience, investor confidence, public trust and national stability. In my research on cybersecurity developments in the Gulf, I observed that technological advancements and the adoption of cybersecurity applications have progressed more rapidly than institutional cyber governance frameworks. This gap matters because, while AI can significantly strengthen cyber defence capabilities, its effective deployment requires robust governance frameworks, clearly defined institutional responsibilities and sustained workforce
May 18, 2026 · via studies.aljazeera.net
S. Korea's science ministry holds cybersecurity workshop with OpenAI SEOUL, May 18 (Yonhap) -- South Korea's science ministry, as well as other related government institutions, held a working-level workshop Monday on cybersecurity issues related to artificial intelligence (AI) with OpenAI. Sasha Baker, the head of national security policy for Chat GPT, introduced cybersecurity-related functions of the company's latest AI models and discussed areas of cooperation in the field, the Ministry of Science and ICT said in a release. She also introduced OpenAI's Trusted Access for Cyber (TAC) program, which gives verified access to its models to companies in vital sectors, such as finance and public services. The science ministry said it asked for OpenAI's cooperation in information sharing to respond to ever-evolving cybersecurity threats tied to AI. The two sides also agreed to continue working-level conversations related to utilizing AI in the area of digital safety, it added. Officials from the Ministry of Foreign Affairs, the National Intelligence Service and the Financial Services Commission also attended the event, according to the science ministry. fairydust@yna.co.kr (END) - BTS to headline halftime show at 2026 World Cup final - (LEAD) Teenage pianist Son Se-hyeok wins Prague Spring competition - 'Dracula' featuring Jennie climbs to No. 10 on Billboard Hot 100 - Teenage pianist Son Se-hyeok wins Prague Spring competition - (3rd LD) Samsung Electronics' labor talks break down, raising fears of major strike - (LEAD) Teenage pianist Son Se-hyeok wins Prague Spring competition - SeMA retrospective revisits works of abstract art master Yoo Young-kuk - 'Dracula' featuring Jennie climbs to No. 10 on Billboard Hot 100 - (2nd LD) Trump heads to China for high-stakes summit with Xi - (2nd LD) Seoul to review 'phased' contributions to U.S. initiative in Hormuz: defense chief - (2nd LD) Lee holds phone call with Trump
May 18, 2026 · via en.yna.co.kr
Based on responses from 400+ cybersecurity leaders, the report shows targeted social engineering attacks are rising, highly personalized, and straining enterprise defenses - and attacker reconnaissance has never been easier. Check out the report and learn how cybersecurity leaders are reducing exposure to stop targeted social engineering. Read the free report here >> https://lnkd.in/dZHFqJpW
The Cyber Security Hub™’s Post
More from this author
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development
The personalization angle is what makes these attacks so effective now. Surface-level awareness training doesn't cut it anymore when attackers have done their homework on individual employees.
May 18, 2026 · via linkedin.com
The FIFA World Cup 2026 is expected to become one of the largest sporting events in history, with matches hosted across the United States, Canada, and Mexico. Along with the excitement of global football, the tournament is likely to attract significant cyber threats targeting fans, organizers, sponsors, telecom networks, and digital infrastructure. As sporting events increasingly depend on digital systems, cybersecurity has become a critical aspect of event management. Phishing and Online Fraud One of the most common anticipated threats is phishing and online fraud. Cybercriminals often exploit the popularity of international tournaments to create fake ticketing websites, fraudulent travel offers, and impersonation emails. Security researchers have already identified scam campaigns using fake FIFA-themed platforms to steal payment information and personal credentials from football fans. Reports also indicate that several partner organizations linked to the tournament may not have fully implemented strong email authentication measures, increasing the risk of domain spoofing and fraudulent communication. Ransomware and Data Breaches Another major concern involves ransomware and data breaches. The World Cup will rely heavily on digital ticketing systems, cloud databases, mobile applications, and AI-driven technologies. A successful cyberattack against these systems could disrupt stadium operations, leak sensitive information, or temporarily disable essential services. Discussions within online security communities have also raised concerns about the exposure of football-related personal data and the possible misuse of leaked records for identity theft or targeted scams. Telecom Sector Vulnerability Telecommunication infrastructure may also become a vulnerable target during the tournament. Millions of visitors are expected to use mobile networks simultaneously across host cities, creating increased pressure on network systems. Cybersecurity analysts warn that outdated signaling protocols in some telecom infrastructures could be exploited for fraud, service disruption, or interception of communications during peak event periods. Financial Cybercrime In addition to financial cybercrime, experts have expressed concerns
May 18, 2026 · via cybersecurity-insiders.com