The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, or ATF, says a cyberattack on one of its systems has been declared a “major incident,” a formal, legally defined classification that prompts a formal notification to lawmakers in Congress. ATF said in a statement that it’s responding to the cyberattack on a stand-alone system that’s separate from the bureau’s network. An ATF spokesperson told reporters that the targeted computer system contained information such as the “targets of ATF investigations.” TechCrunch has seen a claim of responsibility by the Qilin ransomware gang on its leak site, but it did not provide evidence for its claim, such as a sample of leaked data. Qilin is known for running a “ransomware-as-a-service” operation, in which it leases its hacking tools to other criminal affiliates for a cut of the profits. The gang has listed media giant Lee Enterprises and U.K. pathology lab giant Synnovis as targets. Under federal law, “major incidents” include significant cyber incidents that are likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are required to disclose major incidents to Congress within a week of their discovery. The ATF joins several government agencies in recent years that have declared major incidents following a breach, including a 2023 ransomware attack on a system used by the U.S. Marshals Service, and a breach of an FBI system earlier this year that exposed phone numbers of targets under surveillance by federal agents.
Aug 28, 2026 · via techcrunch.com
"Innovate with Grace, Peace in Cyberspace" Thematic Trams Set Off AI Enhances Phishing's Deceptive Capabilities Over 60% of Security Incidents in H1 2026 Involved Phishing Attacks (Hong Kong, 28 August 2026) To further enhance public awareness of cybersecurity, the Hong Kong Computer Emergency Response Team Coordination Centre (HKCERT), the Digital Policy Office, and the Hong Kong Police Force today held the "Innovate with Grace, Peace in Cyberspace" Tram Promotion Launching Ceremony at the Whitty Street Tram Depot. Starting today until 24 September, two thematic trams will serve as "mobile cybersecurity education stations", touring Hong Kong Island for four weeks. Featuring winning entries from the AI-Generated Four-Panel Comic Contest and practical anti-scam tips, the trams aim to bring cybersecurity knowledge into the community and help citizens enhance their scam prevention capabilities in the AI era. Professor SUN Dong, JP, Secretary for Innovation, Technology and Industry said, "As innovative technologies such as AI gradually integrate into everyday life, society is embarking on an innovation and technology journey. To ensure that this journey is steadier, and more enduring, cybersecurity is an indispensable safeguard. Maintaining cybersecurity not only protects the public and supports the day-to-day functioning of society, but also helps drive high-quality development of innovation and technology in Hong Kong.” Mr Mohamed BUTT, MH, Executive Director of the Hong Kong Productivity Council said, "As AI and other innovative technologies gradually integrate into everyday life. society is embarking on an innovation and technology (I&T) journey. To ensure that this journey is safer, more secure, and more sustainable, cybersecurity is an indispensable form of protection. Maintaining cybersecurity not only safeguards citizens and supports the day-to-day functioning of society, but also helps drive Hong Kong’s high-quality development in I&T.” AI Reshapes Cyberattack Patterns Rising Threats from Phishing and Social Engineering According to HKCERT's statistics for the
Aug 28, 2026 · via hkcert.org
OpenAI, Anthropic, tech leaders warn of "limited window" to defend against AI cyber threats Leading developers of the most powerful artificial intelligence tools are warning that their technology may soon be used to carry out sophisticated cyberattacks against companies and institutions, ranging from hospitals to technology firms. In an open letter published Thursday, the leaders of OpenAI, Anthropic, Google, Microsoft and dozens of other signatories said there is a "limited window" to strengthen cyber defenses and protect against potentially devastating AI-enabled cyberattacks. That window may last only months, it added. The signatories also include security companies like CrowdStrike and banks including Citi and Capital One. The same AI advances that could increase risks to public services and technology infrastructure can also help organizations identify and "fix weaknesses" that leave them vulnerable, the letter said. "If we act decisively, we can use the defenders' window to make our digital world much more secure," the letter said. A recent CrowdStrike report on cybersecurity found that AI-enabled attacks increased by 89% in 2025 compared to 2024. How to defend against attacks The companies said that the status quo for cybersecurity "won't be enough." "Longstanding bugs, excessive permissions, misconfigurations, insecure and unpatched software, weak authentication and technical debt in legacy systems have left systems exposed," the letter said. Security teams need to be beefed up and invested in, while defenders against AI cyberattacks need to be equipped with the most sophisticated AI-enabled tech, it said. The letter also called on companies and experts to share their expertise. "Share threat intelligence and tested playbooks, and measure progress by how many organizations are protected, how quickly attacks are contained, and whether fixes work," it added. Call to action Every organization needs to prioritize cybersecurity, according to the letter. That might include replacing or upgrading older tech
Aug 28, 2026 · via cbsnews.com
Cybersecurity Stocks Rally on Twin Earnings Beats: Okta Spikes 22%, CrowdStrike Jumps 13% Okta and CrowdStrike both crushed earnings, but one stock is surging nearly twice as hard as the other despite posting slower growth and a troubling dip in a key bookings metric. Cybersecurity stocks are outrunning the broad market Thursday after twin fiscal Q2 2027 earnings beats from Okta and CrowdStrike reported Wednesday after the close. The First Trust NASDAQ Cybersecurity ETF (NASDAQ:CIBR) is up 3% to $96.20 in early Thursday trading. The SPDR S&P 500 ETF Trust (NYSEARCA:SPY) is up 0.3% to $768.17, a fraction of the sector’s move. Okta (NASDAQ:OKTA | OKTA Price Prediction) stock is surging 22% to $163.98 after fiscal Q2 2027 results reframed the identity leader as the security layer for AI agents. Meanwhile, CrowdStrike Holdings (NASDAQ:CRWD) stock is climbing 13% to $213.70 following its own beat-and-raise report. Okta stock was up 55% year to date through Wednesday’s close, and CrowdStrike stock was up 61% over the same period. Peers Palo Alto Networks (NASDAQ:PANW) and Fortinet (NASDAQ:FTNT) are riding the read-through as the platform trade in cybersecurity gets fresh validation. Palo Alto Networks stock is up 5% to $356.17, and Fortinet stock is up 1% to $159.51. Both names sit among CIBR’s largest disclosed cybersecurity-focused positions alongside CrowdStrike. Twin Beat and Raise Reports Drive the Rally Okta reported revenue of $805 million, up 11% year over year, and adjusted EPS of $1.05 topped consensus. CEO Todd McKinnon stated, “As AI agents transform every layer of technology, every agent needs a trusted identity and clear controls over what it can access and do.” CrowdStrike posted revenue of $1.47 billion, up 26% year over year, with adjusted EPS of $0.31 clearing estimates. CrowdStrike raised its full-year net new ARR growth outlook by 630 basis points,
Aug 28, 2026 · via 247wallst.com
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a "highly capable, internal-only research model" comparable in scale to GPT‑5.6 Sol. "The models, operating under reduced safeguards, took actions that were misaligned with the goals of their assigned tasks – they communicated through unauthorized channels, exploited vulnerabilities in shared infrastructure, gained internet access, and accessed third-party systems," it said in a postmortem. OpenAI said the AI agents powered by one of the research models, despite not having internet access, found a way to exploit a then-zero-day vulnerability in the Artifactory package manager during reinforcement learning (RL) training runs in May and June to obtain access to the internet, get administrator-level Artifactory access in late June, and eventually coordinate a "multi-day" hack of Hugging Face in early July with an aim to cheat on their ExploitGym tasks. "Roughly 1,200 agents meant to be isolated from one another found a way to communicate with one another on an unsanctioned message board, sending over 70,000 messages and files during the investigation period," METR, which released its own independent analysis of the incident, said. "Of these agents, 700 went on to participate in the attack on Hugging Face." The entire sequence of events as highlighted by OpenAI is below - - May 12 - During a training run, an agent leaves an Artifactory note asking other agents for a missing file. - May 13 - A separate agent from the same training experiment but with internet access enabled via WebCache requires the same
Aug 28, 2026 · via thehackernews.com
AI leaders Anthropic and OpenAI are notable signatories to the letter. Around 120 companies and entities from the world of tech, finance, telecoms and related industries have signed an open letter calling for greater collective action on cyber defence by society and business in the face of growing AI-enabled security threats. AI leaders Anthropic and OpenAI are notable signatories to the letter – alongside companies such as Google, AWS, Visa, ServiceNow, PwC, Oracle, Microsoft, MasterCard, IBM, Hugging Face, Deutsche Telekom, Cloudflare and Accenture – warning of “a limited window to strengthen cyber defences”. “In the coming months, AI-enabled cyberattacks will become far more widespread and sophisticated as models around the world become increasingly capable,” the letter – published yesterday (27 August) – said, warning that vital infrastructure underpinning hospitals, water treatment plants and internet access could be at risk. The countermeasure to this, according to the letter, is to use advancing AI tech “to fix weaknesses that have accumulated for years” in order to “make our digital world much more secure”. The signatories wrote: “We call on leaders across industry and government to bring the full weight of their technology, resources and expertise to this effort. Put cyber-capable AI in the hands of defenders, starting with the teams protecting essential services.” The parties outlined three key collective response principles to AI cyberthreats: recognising that status-quo security won’t be sufficient; empowering more defenders with cyber-capable AI; and mobilising a collective response. “Security teams, particularly for critical infrastructure, have been historically under-resourced and need a surge in tools and resources,” the letter said. It added that “sharing tools, practical knowledge and verified fixes” can allow one organisation’s security advancements to “help protect many others”, and noted that “no single company should control the future”. The letter referred to a “defenders’ window”, during
Aug 28, 2026 · via siliconrepublic.com
Operational Evidence is Key: Preparing for the New CCPA Cybersecurity Audits - August 28, 2026 - The regulations enacted by the California Privacy Protection Agency to implement the California Consumer Privacy Act (“CCPA”) include new cybersecurity audit regulations that represent a meaningful shift in how regulators approach privacy-related oversight. Where prior compliance frameworks have typically focused on written policies, disclosures, and procedural documentation, the CCPA cybersecurity audit framework evaluates programs on a comprehensive basis to determine whether an organization’s cybersecurity program is actually working.1 Organizations that approach a cybersecurity audit under the new regulations as a documentation exercise are likely to find themselves underprepared and at risk of failing. In order to successfully prepare for a CCPA cybersecurity audit, an organization must be able to demonstrate that its controls are consistently operating as designed in practice. Moving Beyond Documentation While typical compliance audits require documentation review, the CCPA audit seeks to move from reviewing the expectations covered in policies to reviewing evidence that demonstrates execution. CCPA auditors are expected to seek objective evidence that controls have been implemented and are functioning throughout the applicable audit period. Organizations should be prepared for personnel interviews, process walkthroughs, and technical validation, in addition to documentation reviews. The types of evidence likely to be requested span a range of operational activities, including: - Access reviews - Security monitoring reports - Vulnerability scan results - Incident response records - Security awareness training completion reports - Vendor due diligence documentation - Change management records - Risk assessments Together, these artifacts paint a picture of whether a cybersecurity program is functioning as an operational discipline or exists primarily as a set of written commitments. Assessments vs. Audits One of the most important conceptual distinctions organizations can internalize before engaging with the CCPA audit process is the difference
Aug 28, 2026 · via fticonsulting.com
Online Safety and Privacy | Min Read How Awareness Practitioners Are Crushing It: Takeaways from Convene: Boston's Share & Brag We asked real cybersecurity professionals to share what is working for them â learn free tips from the Convene: Boston 2026 Share & Brag session! What happens when you put a room full of training and awareness professionals together and ask them to share whatâs working? It's not the start of a cybersecurity joke. It was the premise of Share & Brag, a popular session at Convene: Boston on August 13. Hosted again by Jenn deBerge, the director of the Fusion Center at Mastercard and the Vice Chair of the Board of Directors at the National Cybersecurity Alliance, this session is always a highlight of every Convene conference. In Boston, the prompt was simple: "What is one thing your organization is doing in your security awareness or human risk program that you think others should be doing too â and why is it working?" After hearing the prompt, a loud convening commenced â exactly what we like to see at Convene. Attendees discussed their ideas at their tables, then selected people to share their favorites with the larger group. The result was a wide-ranging collection of practical ideas from phishing simulations and security champions to community outreach and executive exercises. But several themes began emerging across the different approaches people shared and bragged about. Make cybersecurity a shared responsibility Several attendees described ways they are bringing cybersecurity outside their department. One financial services organization uses tabletop exercises with teams across the business. The goal isn't just to test the organization's response to an incident. It also helps other departments better understand what the cybersecurity team does and why its work matters. Another organization has a program that pairs engineers outside
Aug 27, 2026 · via staysafeonline.org
Highlights - UCF’s Collegiate Cybersecurity Competition Team (C3) has established itself as one of the nation’s most successful collegiate cybersecurity programs, preparing students to compete and lead in cybersecurity. - After more than a decade coaching the Collegiate Cyber Defense Competition team, UCF alum and lecturer Thomas Nedorost ’02 is making the team’s largest planned gift to date, investing in the next generation of cyber champions. - Nedorost’s gift highlights the importance of UCF’s Go For Launch campaign, fueling student success, elevating competitive excellence and helping shape a bold tomorrow. As coach of UCF’s championship Collegiate Cybersecurity Competition Team (C3), Thomas Nedorost ’02 keeps his eye on the prize — but not just the trophies. For Nedorost, a management information systems alum, the real prize is seeing his students and C3 team members become trailblazers, land top industry jobs, build successful careers and pave the way for other Knights. A senior lecturer in UCF’s College of Engineering and Computer Science, Nedorost has coached C3 to 15 national championships in 14 years. The team has finished among the top three in 198 competitions, earning 123 first-place wins along the way. UCF has one of the nation’s most successful collegiate cybersecurity programs, with its competition team winning 15 national championships in the last 14 years. C3 members compete against top universities worldwide, putting their cybersecurity defense skills to the test by protecting systems against simulated threats. Nedorost, who built the program from the ground up, is proud of what his teams have achieved over the years, and he sees the impact of their success in the opportunities that come their way. “Because of the experience they get on C3, team members end up in fantastic internships in the field, and when they graduate, most of them skip over entry-level jobs and land
Aug 27, 2026 · via ucf.edu
Security teams use artificial intelligence (AI) to sift through huge volumes of telemetry, spot activity that deserves attention, and make investigations more efficient. At the same time, cybercriminals are experimenting with many of the same technologies to improve phishing campaigns, automate fraud, and increase the scale of their operations. That creates a lot of confusion. Some headlines portray AI as the future of cybersecurity, while others present it as a new source of risk that defenders can’t control. Reality sits somewhere in the middle. AI is neither the enemy nor the answer to every security problem. In fact, according to the ESET SMB Cyber Readiness Index 2026, 73% of small and medium sized businesses (SMBs) are already integrating AI into their operations, yet 70% acknowledge that AI introduces new security risks. If used responsibly, it’s a tool that can help defenders work more effectively. If it’s used irresponsibly, it can create new risks. Those organizations that are seeing the most value from AI aren’t trying to replace security professionals; they are instead using AI to help skilled practitioners make better decisions in less time. Key points of this article: - AI helps security teams detect threats, prioritize alerts, analyze complex activity, and respond faster, but it works best when combined with human input. - Attackers are using AI to improve phishing, social engineering, fraud, and attack automation, making familiar threats more scalable and convincing. - AI also introduces new security challenges, like shadow AI, data leakage, adversarial manipulation, and governance risks that organizations must actively manage. - Still, familiar weaknesses such as phishing, weak passwords, unpatched systems, and poor monitoring remain major causes of incidents. - The future of cybersecurity is human expertise amplified by AI, supported by strong security fundamentals and responsible governance. What is AI in cybersecurity? AI
Aug 27, 2026 · via eset.com
Honored for unmatched recovery expertise, Fenix24 leads global breach recovery CHATTANOOGA, Tenn., Aug. 27, 2026 /PRNewswire/ -- Fenix24™, a global leader in operational recoverability, today announced its recognition as a winner in three categories of the 2026 Cybersecurity Excellence Awards. Fenix24 is honored in the following categories: Ransomware Recovery, Incident Response, and Business Continuity/Disaster Recovery. The annual awards recognize cybersecurity vendors that demonstrate leadership, innovation, and excellence in all areas of security and technology. Fenix24 is one of the largest and fastest ransomware recovery companies in the world, proven across 500+ hands-on recoveries including 30 of the Fortune 500. Fenix24 mobilizes quickly, working side by side with a client's internal teams, forensics firms, and breach counsel to lock down access, contain the threat, and begin restoration immediately. What powers that speed is Argos99, Fenix24's recoverability intelligence platform, which continuously maps a client's applications and dependencies, so the business knows what to restore, and in what order, before an attack ever happens. This combination of hands-on expertise and built-in asset visibility is how Fenix24 resolves even the most destructive cyberattacks and gets clients back to full business operations. "Being recognized in three categories is meaningful because it reflects the work our teams have done in the field" said Mark Grazman, Founder and CEO of Fenix24. "Recognition like this tells us the industry is finally measuring resilience the way it should be measured, by results, not assumptions. That's always been our focus, and we're honored to see that work recognized." Fenix24 is turning recoverability from an assumption into a proven fact, giving organizations confidence that when an attack hits, they can actually get back up. The Resiliency Intelligence Assessment delivers that proof up front, testing a client's posture against real recovery targets. The 24/7 Resiliency Operations Center then keeps that intelligence current,
Aug 27, 2026 · via prnewswire.com
a NIST blog As AI matures, enterprises and customers are rapidly deploying agents seeking to unlock the next level of automation and productivity. Agentic AI shows potential to handle a multitude of use cases, from buying personal items on Amazon to customer service applications to enterprise security and software development. However, early agentic deployments are repeating a familiar pattern: prioritizing feature development and immediate value over security. This strategy is understandable. Strategic, financial and technical leaders want to demonstrate ROI for their AI investments. Enterprises are under pressure to innovate and drive organizational efficiencies. Individuals are seeking automated and personalized experiences. Moreover, agentic AI introduces a novel frontier of security challenges that "model-only" guardrails are not yet fully equipped to solve. While building a fully mature security framework in a fast-moving landscape takes time, reverting to outdated security practices risks eroding the core value AI agents provide. This post will discuss some of the current identity and authorization practices that present substantial security challenges for agentic AI systems. Many of the challenges discussed are not new and, put simply, are the same issues that have plagued identity management systems for decades. This post is intended as a reminder that as we sprint towards agentic implementations, deploying and building on existing foundational identity standards and best practices will better prepare implementers for future challenges. The topics covered in this post are drawn from public comments on the recent NCCoE Accelerating the Adoption of Software and Artificial Intelligence Agent Identity and Authorization Concept Paper, and from extensive engagement with stakeholders in the agentic AI ecosystem. The goal of this NCCoE work is to accelerate the adoption of agentic AI by demonstrating how cybersecurity standards and best practices can reduce risk and realize agentic AI value. Security professionals have been telling users since
Aug 27, 2026 · via nist.gov
Latest Visa Vulnerability Agentic Harness release moves AI-powered cyber risk management from discovery to validated remediation New services from Visa Consulting & Analytics help clients identify the vulnerabilities that matter most and act before bad actors do SAN FRANCISCO--(BUSINESS WIRE)-- Visa (NYSE: V) today announced enhancements to its cybersecurity portfolio to help organizations identify and fix vulnerabilities more effectively. Unveiling the next evolution of the Visa Vulnerability Agentic Harness (VVAH), its open-source, model-agnostic framework, Visa is helping organizations significantly reduce the Mean Time to Adapt (MTTA), the time between discovery and resolution of attack paths, with some resolutions shrinking from weeks to hours. And to help clients navigate this evolving threat landscape, Visa also announced the expansion of its Visa Consulting & Analytics (VCA) Cybersecurity Advisory Practice with new advisory services designed to help clients assess risk, prioritize remediation efforts and strengthen resilience in an evolving threat environment. "AI is compressing the time between vulnerability discovery and exploitation, which means defenders need a faster, more reliable path to action," said Rajat Taneja, President, Technology, Visa. "By advancing VVAH and expanding our cybersecurity advisory capabilities, we're helping organizations move from insight to validated remediation while strengthening resilience in an increasingly AI-driven threat landscape." Expanding VVAH Originally released following Visa's participation in Anthropic's frontier AI cybersecurity initiative, Project Glasswing, VVAH demonstrated how AI can help security teams uncover vulnerabilities, assess exploitability and generate structured findings. The latest release extends that workflow beyond discovery into remediation and validation. Key enhancements include: - Closed-loop remediation: Structured feedback helps teams refine fixes that fail validation without restarting the process. - Flexible model choice: Organizations can now deploy approved Anthropic models and OpenAI models, in addition to any other AI model through configuration rather than code changes. - Greater visibility: Optional real-time progress views provide additional
Aug 27, 2026 · via investor.visa.com
CrowdStrike: AI agent concerns driving cybersecurity spending CrowdStrike CEO George Kurtz said the second quarter was a sea change for the company and the AI arms race is driving cybersecurity spending. Speaking on CrowdStrike's second quarter earnings call, Kurtz said it's an arms race right now in cybersecurity. "AI is driving more cyber-attacks. AI is driving more cyber spending. AI is driving a clear divide between the cybersecurity companies that solve problems and those that compound problems. The world's adoption of AI is rapidly expanding the attack surface, more models, more agents, more agentic applications, more data and with that, more identities, more permissions, more policies, more cyberattacks and more risk." Kurtz added that "the agent of today is both friend and foe." What remains to be seen is whether AI agents alter the cybersecurity pecking order. Clearly, CrowdStrike's second quarter revenue growth of 26% is putting it in front of the pack. According to Kurtz, AI agents are going to expose cybersecurity products that work and don't. The decision points for enterprises will revolve around presence and speed and the ability to stop agentic AI attacks. The vendors that fail will open doors for agentic AI adversaries. The talk from Kurtz equated to CrowdStrike talking up its Falcon product, but if he's correct the current cybersecurity vendor landscape could be upended by AI agents. This chart from CrowdStrike highlights how the security vendor landscape could use a bit of consolidation. Kurtz and other cybersecurity vendors frequently reference Anthropic's Mythos moment that spurred demand. "When we think about AI agents going rogue, when you think about the need for protecting AI and understanding where shadow AI is, it all points to the technologies that we're building and delivering here like AIDR, which was -- just had a phenomenal quarter, no
Aug 27, 2026 · via constellationr.com
His Excellency Mr Jasem Mohamed Albudaiwi, Secretary General of the Gulf Cooperation Council (GCC), underscored that thanks to the vision of Their Majesties and Highnesses, the Leaders of the GCC states, and their continuous support, the Cooperation Council member countries occupy a leading global position in the field of cybersecurity. "The GCC countries have achieved advanced rankings and prestigious global ratings in specialised international indices, launched qualitative initiatives to develop national capabilities and qualify specialised competencies, reinforced the protection of data and digital infrastructure, as well as elevated the efficiency of response to cyber incidents and threats," His Excellency added. These remarks were made by His Excellency the GCC Secretary General during the 5th meeting of the GCC Ministerial Committee for Cybersecurity, held today, Thursday (27 August 2026), in Manama, capital of the Kingdom of Bahrain, chaired by His Excellency Shaikh Salman bin Mohammed Al Khalifa, Chief Executive Officer of the National Cybersecurity Centre and President of the current session. The meeting was attended by Their Excellencies the officials responsible for cybersecurity authorities across the GCC states. At the outset of his speech, His Excellency the GCC Secretary General extended his highest expressions of thanks, appreciation, and gratitude to His Majesty King Hamad bin Isa Al Khalifa, the King of the Kingdom of Bahrain and President of the current session of the GCC Supreme Council, for the Kingdom of Bahrain's hosting of the Committee's meeting, and for the facilities and support Bahrain provides to ensure the success of the GCC's work, as well as the support and attention joint Gulf action receives from His Majesty and from Their Majesties and Highnesses, the Leaders of the GCC states, across all fields. During his remarks, His Excellency pointed to the recent developments and events in the region and the accompanying escalation of
Aug 27, 2026 · via gcc-sg.org
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Aug 27, 2026 · via youtube.com
"We have to stay ready to get ready. We don't know when, if, and how that vulnerability can occur," said Jennifer Franks. Terry Gerton You have dug into aviation cybersecurity. That depends on a growing network of connected systems on the ground and the aircraft across federal departments. Was there anything that prompted this particular look? Jennifer Franks Yeah, absolutely. So what prompted this mandate was the FAA Reauthorization Act of 2024. And that act included a provision for GAO to go in and evaluate both the Federal Aviation Administration, as well as the Transportation Security Administration’s roles and responsibilities managing cybersecurity, and specifically aviation cybersecurity. Terry Gerton The FAA and the TSA are supposed to work together here as you began the examination, what did you find both about their respective roles and how well they actually are working together? Find out how federal leaders are charting the future of health IT in our new e-book, sponsored by Maximus. Download today! Jennifer Franks That’s a very good question. So we found out that there are some deviances with how they are actually working and collaborating in this cybersecurity space. FAA has defined and clearly assigned roles and responsibilities for carrying out the agency’s related goals and objectives in this space. But in the contrast, TSA has not. And with the lack of really defining and clarifying your roles and responsibilities, what it is we found as we started to interview stakeholders from industry, including airlines and other industry related groups, they were confused as well with TSA’s role and responsibility and some of the guidance that was coming out. So, helping to streamline that information was something that we were talking with the stakeholders very early on that could have been helpful for them in their environment. Terry Gerton
Aug 27, 2026 · via federalnewsnetwork.com
Boston Scientific: Network outage the result of 'cybersecurity incident'
(FOX 9) - Boston Scientific is dealing with a cybersecurity attack that is disrupting its operations as the company works to restore its systems.
Boston scientific hacked
What we know:
Boston Scientific said it detected a "cybersecurity incident" on Aug. 25 and activated its incident response protocols in response. The company then brought in third-party cybersecurity experts to help assess and contain the threat.
The attack hit several of the company's operating systems and business applications, including the systems it uses to process and ship customer orders.
What's next:
Boston Scientific says it is working to restore the affected systems and functions, but the company has not yet determined how long a full recovery will take.
The investigation into the attack remains ongoing.
What we don't know:
No information on who was behind the attack was shared.
The Source: This story uses information shared by a Boston Scientific spokesperson.
Aug 27, 2026 · via fox9.com
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the globe. Our objective is to sever every economic lifeline that sustains this tyrannical regime until Tehran stands alone," said Secretary of the Treasury Scott Bessent. The action, codenamed Operation Economic Outcast, aims to cut the Iranian regime and the Islamic Revolutionary Guard Corps (IRGC) from the financial "lifelines" that support the "leading state sponsor of terror." To that end, the sanctions designate nearly 60 Iran-linked entities, individuals, and vessels across nuclear, missile, oil, and cyber networks, including the digital assets sector. Specifically, the sanctions take aim at a malicious cyber group affiliated with Iran's Ministry of Intelligence and Security (MOIS) that's behind extensive compromises of U.S. critical infrastructure entities and financially motivated cyber theft. "The MOIS directs several networks of cyber threat actors involved in cyber espionage in support of Iran's political goals, which include harming American civilians," the Treasury said. Among those sanctioned are five individuals who were indicted by the U.S. Justice Department last week in connection with carrying out widespread compromises against U.S. entities. They are alleged to be members of the Tehran-based Mabna Institute. The names of the individuals are listed below - - Behzad Mesri, who was designated by the Office of Foreign Assets Control (OFAC) twice in March 2018 and February 2019 for his role in targeting and attempted extortion of HBO and for having acted or purported to act for or on behalf of the sanctioned Net Peygard Samavat Company, respectively. - Mojtaba Ghal'eh-Kuhi - Keyvan Fayyaz Ghareh Blagh - Saber Shahbazi Balujeh - Mohammad Reza Kadkhoda'i - Arman Kahzadian
Aug 26, 2026 · via thehackernews.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Aug 26, 2026 · via youtube.com