No-frills tech news

First Apple M5 memory exploit discovered using Anthropic AI, gives root access on MacOS

First Apple M5 memory exploit discovered using Anthropic AI, gives root access on MacOS — Claude Mythos helps security researchers bypass Memory Integrity Enforcement AI-assisted security research is producing exploits at a frightening rate. Thanks to AI-assisted security research, hackers with hats of various colors are finding exploits everywhere. Linux has had its worst week in years with the CopyFail and Dirty Frag root-gaining vulnerabilities, and things aren't much rosier at Microsoft, thanks to the YellowKey BitLocker bypass, as well as GreenPlasma and RedSun privilege-gaining exploits. Now, it's Apple's turn with a local privilege escalation that gets past the M5 chips' much-vaunted Memory Integrity Enforcement (MIE). There aren't many technical details, but the vulnerability is simple in practice: run a command as a standard user and gain root (administrator) access to the machine. Macs are rarely servers, so the practical impact is limited. However, the exploit remains concerning, as it's relatively easy to trick a user into running it and, with full system control, also hard to find and remove. The research team in question is named Calif, and as far as they know, the boffins there are the only ones making a public disclosure of this issue. Such assumptions are tricky in this day and age, though. Mercifully for Captain Cook's ship, instead of being a zero-day reveal out of nowhere that left systems administrators scrambling, the exploit in question was disclosed to the company in advance (in person, no less). Calif published the vulnerability overview as part of a series of blog posts called the Month of AI-Discovered Bugs, since this new Apple vulnerability falls within a set of security findings aided by AI tools — in this case, Anthropic's Mythos Preview. The researchers tested their code on an Apple M5 machine and macOS 26.4.1. The exploit chain

Marks and Spencer Password Reset Call Shows Why Helpdesk Verification Is the New MFA Surface

Helpdesk social engineering has quietly become the highest-leverage attack against modern enterprises, because the password reset call is the one identity-verification step where MFA is not present and the verifier is a human under throughput pressure, a gap a recent BleepingComputer analysis of password-reset practice examines in depth. The April 2025 Marks and Spencer breach is the worked example: attackers tied to Scattered Spider impersonated an M&S employee to a third-party service desk, secured a fresh credential, extracted the NTDS.dit file from Active Directory, cracked hashes offline, and detonated ransomware that suspended online sales for five days at an average cost of GBP 3.8 million ($5.1 million) per day. Why password reset queues became the path of least resistance Forrester research cited in BleepingComputer’s coverage estimates every reset costs about $70 in helpdesk time, which is why most large enterprises moved to self-service tools. The unintended consequence: the cases that still hit the helpdesk are the edge cases where self-service enrollment failed, the user is locked out of their MFA device, or social engineers picked the script that bypasses self-service. Those are precisely the scenarios where a verifier has to use judgment, which is where impersonation lands. Verizon’s 2024 Data Breach Investigations Report attributes 44.7% of breaches to stolen credentials, and a helpdesk-issued credential counts the same as one harvested via infostealer. What the Marks and Spencer chain reveals about service-desk controls The Marks and Spencer chain ran through routine helpdesk procedure end-to-end: a caller passed knowledge-based questions, the agent acted, valid credentials were issued. There was no MFA bypass; there was no zero-day. The verification step assumed that someone who knows the employee’s identifiers IS the employee, which knowledge-based authentication has not been safe to assume since at least the Equifax era. What the BleepingComputer writeup under-emphasizes is the

Senior News Line: Teen teaches seniors about <b>cybersecurity</b>

Tejasvi Manoj, a 17-year-old from Texas, was named in 2025 as Time magazine Kid of the Year. Her claim to fame? Teaching seniors how to avoid cyber scams. Her reasoning for the task was personal — her grandfather was nearly hit by a scammer who was pretending to be a relative demanding money. Thankfully the grandfather called another relative before he hit that “send” button. This is one brilliant young lady. Not only does she teach cyber security at senior centers, but she developed an online teaching program called Shield Seniors at shieldseniors.com. While the site isn’t fully up and running yet, it’s one we will need to keep an eye on when it does start. Have you heard of TED talks? TED is a platform where the best and the brightest among us give short talks on all types of topics. If you want to see this sharp young lady during her TED talk, go online to y2u.be/v3800D3xHQo. If you want to hear more from her while you’re on YouTube, put her name — Tejasvi Manoj — in the search box. You’ll be impressed. Two years ago there were 860,000 scams reported by seniors and $4.8 billion was lost in one year alone. Why is it scammers come after us? They perceive that we have a lot of money. After all, we’re retired, so we must be rich, right? We didn’t grow up in the tech generations — taught to handle digital devices by the age of 3 and able to easily spot scams. We’re also, to our occasional detriment, too polite and trusting when we talk to others. It makes it all too easy for a scammer to manipulate us on the phone. To learn more about how to avoid scams, go online to the Federal Trade Commission

Contractors Should Prepare as NIST Finalizes Enhanced Security Requirements for ...

Contractors Should Prepare as NIST Finalizes Enhanced Security Requirements for Protecting Controlled Unclassified Information On May 13, 2026, the National Institute of Standards and Technology (NIST) finalized a revision to Special Publication (SP) 800-172r3 (Revision 3), Enhanced Security Requirements for Protecting Controlled Unclassified Information (CUI), which provides a selection of recommended cybersecurity controls for protecting CUI resident on a nonfederal information system when associated with a “high value asset” or “critical program.” The revised publication highlights the importance of contractors being able to identify CUI and having plans to implement SP 800-172r3 controls even before the revisions are adopted into the Department of War (DOW) Cybersecurity Maturity Model Certification (CMMC) Program. The SP 800-172 controls are tailored to protect CUI and associated systems that may be the target of “Advanced Persistent Threats” (APTs), which are cybersecurity threat actors generally associated with nation-states such as China, Russia, Iran, or North Korea that NIST assesses have the “expertise and resources” to use cyber, physical and deception capabilities to achieve their objectives. SP 800-172 Revision 3 is intended to supplement controls featured in NIST’s SP 800-171 Revision 3 and SP 800-53: Security and Privacy Controls for Information Systems and Organizations. Alongside SP 800-172 Revision 3, NIST revised the companion assessment publication, SP 800-172Ar3: Assessing Enhanced Security Requirements for Controlled Unclassified Information, to reflect new controls added to SP 800-172r3. This publication provides assessment procedures for organizations to determine how effectively an organization is implementing the security controls outlined in SP 800-172r3. These publications do not immediately apply to contractors; however, agencies have required contractors to meet certain SP 800-172 requirements through terms of contracts, grants, or other agreements. For example, DOW selected certain controls from an earlier version (Revision 2) of SP 800-172 for its CMMC Level 3 requirement. The SP 800-172 Controls

By Light Lands $792M in DISA <b>Cybersecurity</b> Contracts

- DISA awards By Light nearly $792 million in cybersecurity contracts - Programs support secure internet access and enterprise threat inspection - The CBII contract adds AI-enabled tools for detecting and mitigating cyberthreats The Defense Information Systems Agency has awarded By Light Professional IT Services two cybersecurity contracts, totaling $791.9 million, to strengthen the Department of War’s enterprise cyber defense and secure internet access capabilities. DISA posted award notices on Tuesday on SAM.gov: a $298.1 million Cloud Based Internet Isolation, or CBII, contract and a separate $493.9 million Full Content Inspection, or FCI, managed service contract. Under the CBII award, By Light will provide enterprise-wide remote browser isolation services using Menlo Security’s Cloud Browser platform to support approximately 3.2 million users throughout the DOW. The cloud-based isolation capability is intended to protect personnel from web-based cyberthreats by separating internet activity from endpoint devices through a secure cloud environment. The follow-on contract renews existing Menlo Security subscription licenses, adds new licenses and integrates Menlo’s Highly Evasive and Adaptive Threats Shield artificial intelligence and machine learning capabilities. DISA’s presolicitation notice stated the procurement was limited to authorized Menlo Security resellers with active Secret facility clearances. How Does the FCI Program Expand DISA’s Cyber Defense Architecture? The larger FCI contract requires enterprise managed services designed to inspect, analyze and mitigate cyberthreats traversing the Defense Information Systems Network, or DISN. According to a redacted justification and approval document, the FCI platform combines legacy intrusion prevention system capabilities with newer technologies, including network detection and response and content disarm and reconstruct. DISA said the managed service enables advanced threat detection, real-time mitigation and predictive cyber analytics across DOW networks while supporting inspection of web, email and DNS traffic crossing DISN boundaries. Why Did DISA Pursue Sole-Source Awards? DISA justified the FCI procurement, arguing that Trinity

Why Prompt Security Is an Architecture Problem

For decades, cybersecurity defenses were built around structured interfaces such as APIs, identity systems, and network endpoints. Those surfaces were predictable, schema-bound, and constrained by deterministic rules. Security teams could define boundaries between valid and invalid behavior, then monitor for violations. Generative AI systems change that model. In these environments, instructions are expressed in natural language, assembled from multiple context layers, and interpreted non-deterministically. Prompts, retrieval context, system instructions, and tool outputs now influence whether software takes action. That shift matters because safety is no longer just a property of the model. It is a property of the entire architecture around it. Prompt Injection is a Systems Problem This is why prompt injection is better understood as a systems problem than a model problem. An unsafe outcome may not result from a single bad response. It may come from a chain of individually valid steps, each operating as designed, but combining into something harmful. The model may follow instructions correctly, while the overall workflow fails to enforce the right constraints. Traditional exploits break syntax or violate explicit rules to gain unauthorized access. Prompt-driven attacks work differently. They manipulate meaning, precedence, and trust relationships inside a system built to interpret ambiguous instructions. The goal is not to crash the application. It is to steer it toward a harmful but technically valid action. That makes architectural design central to security. A model with stronger guardrails can reduce risk, but it cannot compensate for excessive permissions, weak prompt governance, or poorly bounded tool access. If an agent can read sensitive data, call external services, and act on loosely scoped instructions, the surrounding system has already expanded the attack surface. Model safety helps. It does not solve the problem by itself. Risk Emerges Across Multi-Step Workflows The risk becomes clearer in multi-step AI workflows.

Rising To The Challenges Of <b>Cybersecurity</b> Risk Management In 2026

It’s getting harder than ever for companies to manage the risks associated with cyber breaches. Danger lurks in every corner of the ecosystem, from insider threats and AI-powered phishing to zero-day vulnerabilities that malicious actors can exploit, and poorly-protected third parties that open the door to supply chain attacks. Meanwhile, enterprise assets, environments, and infrastructure are growing more extensive. It’s getting harder for security teams to remain aware of every aspect of the organization’s cyber footprint. What’s more, attackers are constantly changing their tactics, techniques, and procedures (TTPs), so it’s difficult for cyber risk teams to keep up. Even regulatory bodies that are out to help protect organizations from cyber attacks add to the challenges. They frequently change their requirements, forcing you to repeatedly review your compliance standing. In this article, we’ll discuss trending attack patterns that give security teams a headache in 2026, the evolving demands of cyber risk management, and the need to stay on top of cybersecurity controls so business leaders sleep at night. Identity-First Attacks Increase Exposure Risks Today’s malicious actors are moving beyond breaking into enterprise systems or infrastructure, and looking to compromise users, service accounts, or authentication systems through credential theft and session hijacking. Because modern environments are generally secured around identity permissions, a compromised identity allows attackers to “become the user” and move freely without triggering traditional perimeter defenses. MFA bypass techniques, push fatigue attacks, and SIM swapping are all hallmarks of identity-first attacks. This forces risk models to focus on access pathways, identity (including machine identities), and SaaS exposure, rather than just infrastructure and assets. Risk assessments must be comprehensive and extensive, mapping end-to-end access relationships throughout the ecosystem, re-evaluating permissions, and considering cascading compromise impact. Supply Chain Attacks Are Increasing Supply chain attacks are becoming more indirect, scalable, and difficult to

Gibson Dunn Client Alert Included in Pratt's Privacy &amp; <b>Cybersecurity</b> Law Report

Gibson Dunn Client Alert Included in Pratt’s Privacy & Cybersecurity Law Report Article | May 15, 2026 Pratt’s Privacy & Cybersecurity Law Report A Gibson Dunn client alert authored by Jina Choi, Winston Chan, Diana Feinstein, Benjamin Wagner, and Erin Williams, “Grand Jury Secrecy Reinforced: Ninth Circuit Bars FOIA Discovery of Subpoenaed Documents Produced Pursuant to Rule 6(e),” [PDF] was reprinted in the April 2026 issue of Pratt’s Privacy & Cybersecurity Law Report.

The Next <b>Cybersecurity</b> Challenge May Be Verifying AI Agents

For the past two decades, cybersecurity has largely been a story about protecting humans from machines blocking malware, filtering phishing emails, companies mitigating DDoS attacks, and patching software vulnerabilities before attackers exploit them. The adversary was clear. The surface was known. The playbook, while imperfect, was at least legible, but that story is now changing. The next major frontier in cybersecurity is not defending against AI. It is figuring out how to trust it. The Agent Is Already In the Building Autonomous AI agents are being deployed today reading inboxes, executing code, transferring funds, signing off on contracts, and making decisions that in any previous era would have required a human signature. The agentic economy is not on the horizon. It is already operating inside your perimeter. The speed of adoption is understandable, and the productivity case is compelling. A single AI agent can compress weeks of analyst work into hours. But here is the question most organizations are not yet asking: when an AI agent takes an action on your behalf, how do you actually know it is who it claims to be? A Trust Problem Hiding in Plain Sight In traditional network security, identity is foundational, and zero-trust architectures exist precisely because we learned that presence inside a network is not proof of legitimacy. We authenticate users, verify devices, enforce least-privilege access controls, log and audit everything. None of that infrastructure was built with AI agents in mind. Today, when an autonomous AI agent initiates a request to an API, a database, a financial system, or another agent, the receiving party typically has no reliable mechanism to verify its identity, confirm what it is authorized to do, check whether its instructions have been tampered with, or revoke its access in real time. The agent arrives as a stranger,

Port of Long Beach opens <b>cybersecurity</b> center

LONG BEACH, Calif. — The Port of Long Beach Friday unveiled a center designed to defend against cyberattacks in an effort to protect the facility and goods movement. The center features enhanced technology for around-the-clock cybersecurity monitoring and defense, port officials said. It also reinforces several data networks associated with the port's operations. Port officials said they often deal with cybersecurity issues, often blocking or stopping an attempted breach every three seconds. The new center will bolster the port's efforts in safeguarding the digital supply chain. Port of Long Beach CEO Noel Hacegaba announced the new center during an event alongside Long Beach Board of Harbor Commissioners President Frank Colonna and U.S Coast Guard Rear Adm. Jeffrey Novak. The showcase highlighted several partnerships among the port, local, state and federal agencies on cybersecurity. "The Cyber Defense Operations Center represents the Port of Long Beach's latest initiative to strengthen our cybersecurity capabilities," Hacegaba said in a statement. "Through the use of enhanced technology, this center allows us to sustain world-class cybersecurity defenses and protect critical data networks to keep cargo flowing and the economy moving as we develop the port of the future." Hacegaba also announced the port had its third-best April on record, with about 818,000 twenty-foot equivalent units being moved through the facility. Overall cargo volumes dropped by 5.7% in April 2026 compared to the same month last year, which was the port's busiest April in history. Long Beach dockworkers and terminal operators moved nearly 390,000 TEUs in imports last month, a decrease of about 7.1%, while exports increased by 26.7% to nearly 119,000 TEUs compared to April 2025. Empty containers decreased by 12.6% to 309,000 TEUs, according to officials. "In our industry, the only certainty is uncertainty, and because we are part of the global supply, we must

TraceX Labs Emerges as a Leading <b>Cybersecurity</b> Company Combating Major Digital Threats

TraceX Labs is an AI-powered cybersecurity company developing advanced solutions for enterprise cyber defense against modern digital attacks. NEW YORK, TX, UNITED STATES, May 15, 2026 /EINPresswire.com/ — TraceX Labs, an emerging cybersecurity and artificial intelligence company, is developing advanced digital security technologies designed to protect organizations and individuals from rapidly evolving cyber threats through AI-powered threat intelligence, deepfake detection, geolocation intelligence, phishing prevention, and malware analysis platforms. As cyberattacks become increasingly sophisticated through artificial intelligence, automation, phishing campaigns, ransomware, and malicious infrastructure, TraceX Labs focuses on building intelligent cybersecurity solutions capable of proactive threat detection, real-time monitoring, and enterprise-grade digital defense. The company operates across multiple cybersecurity domains, including penetration testing, threat intelligence, digital forensics, dark web monitoring, malware analysis, red team operations, managed security services, and Open-Source Intelligence (OSINT) investigations. Enterprise Cybersecurity Services TraceX Labs provides comprehensive enterprise cybersecurity solutions tailored for modern digital threats and evolving attack landscapes. Its Dark Web Intelligence services monitor underground forums, marketplaces, and hacker communities to identify stolen credentials, leaked databases, and emerging threats targeting organizations. The company’s OSINT Investigations services provide advanced digital footprint analysis, social media monitoring, executive protection, and brand impersonation detection for organizations and high-profile individuals. Through Red Team Operations, TraceX Labs simulates real-world cyberattacks to identify vulnerabilities across enterprise networks, web applications, cloud infrastructure, and physical security environments before malicious actors exploit them. Its Malware Analysis division performs static and dynamic malware analysis, reverse engineering, sandbox execution, and IOC extraction to investigate ransomware, spyware, and advanced malicious software. The company also offers Threat Intelligence services that include proactive threat hunting, APT group tracking, vulnerability intelligence, strategic threat reporting, and customized intelligence feeds for organizations. TraceX Labs further provides Managed Security Services, including 24/7 Security Operations Center (SOC) monitoring, incident response, security device management, and compliance reporting. Additional

Why Big Tech Is Panicking

About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC

An Analysis of Board-Level <b>Cybersecurity</b> Risk Oversight

Blog de Zscaler Reciba en su bandeja de entrada las últimas actualizaciones del blog de Zscaler An Analysis of Board-Level Cybersecurity Risk Oversight Key Points: - Audit First Approach: The majority—almost four in five—of S&P 500 companies oversee cybersecurity risk from the Audit committee. - Picture Still Fragmented Outside Audit: Fewer than one in ten companies oversee cyber risk from the Risk committee, though among financial services companies this rises to 39%. Fewer than one in 20 oversee cyber risk from the full board level. - Converging on Audit Committee Oversight: Since 2024, the number of companies overseeing cyber risk from the Audit committee has increased. Fewer companies now formally assign oversight to the full board or a technology/cybersecurity committee. - Potential Oversight Gap: When cyber oversight sits within the Audit committee, boards may be viewing a fast-moving, highly technical risk through a narrow lens as part of an already-crowded agenda. Research Findings: Zscaler analyzed Securities and Exchange Commission disclosures (primarily 10-K and proxy statement filings) from S&P 500 companies to understand cyber risk oversight at the board level. The research highlights how leading public companies on the S&P 500 index are increasingly converging their cyber risk governance around the Audit committee. As of March 1, 2026, 79% oversee cybersecurity risk via the Audit committee. Of the remainder, 8% perform oversight of cyber risk from the Risk committee, 6.2% from a technology/cybersecurity committee, and 3.8% from the full board level. A small number of other companies oversee the risk from Safety/Operations, Governance/Nominating or Compliance/Regulatory committees. Oversight Option | 2026 Result (%) | 2024 Result (%) | |---|---|---| Audit | 79% | 71.2% | Risk | 8% | 8% | Technology/Cyber | 6.2% | 7.2% | Full Board | 3.8% | 8.2% | Safety/Operations | 1.6% | 2% | Governance/Nominating |

G7 releases AI SBOM, DELL Support BSOD, Dirty Frag sequel

In today’s cybersecurity news… G7 countries release AI SBOM guidance Agencies from U.S., Canada, Japan, Germany, France, Italy, the United Kingdom, along with the European Union have now published the Software Bill of Materials for AI – Minimum Elements, focusing on AI. A SBOM is a “detailed, machine-readable manifest that catalogs every component, library, dependency, and module incorporated into a software product to provide full transparency into its composition.” This document aims to “help public and private sector organizations enhance transparency in their AI systems and supply chains,” making it easier to track vulnerabilities and reduce risks. Dell confirms its SupportAssist software causes Windows BSOD crashes The company has confirmed that its SupportAssist software is causing blue-screen of death crashes on some Windows systems. This follows a flood of user reports about random reboots that have been affecting Dell devices since Friday. Version 5.5.16.0 of the Dell SupportAssist Remediation service is responsible for this series of crashes, and the company says it is working towards a resolution. An easy workaround is to simply disable the Dell SupportAssist Remediation service or uninstall it. Dirty Frag 2: Electric Boogaloo. Its sequel arrives as Fragnesia Following up on a story we covered on Tuesday, it appears the Linux kernel vulnerability Dirty Frag which itself was a follow up of the Copy Fail bug, is now returning as Fragnesia, a Linux kernel local privilege escalation flaw. It “allows unprivileged users to gain root by corrupting page cache memory” and has its own CVE number (CVE-2026-46300). According to researcher Hyunwoo Kim, who discovered Dirty Frag, this “Fragnesia” bug emerged as “an unintended side effect of patches shipped to fix the original Dirty Frag vulnerabilities.” Ransomware campaigns increasingly turning to threats of physical violence According to a report from security firm Semperis, in as many as

19 Cloud Security Challenges and How to Mitigate Risk

Cloud security challenges commonly include misconfigurations, human errors, and weak identity and access management. These challenges can all lead to vulnerabilities that may result in data theft and loss. Your data moved to the cloud to help your business scale—but the attackers moved right along with it. The traditional office perimeter has slowly vanished, making cloud security challenges an increasing concern for businesses. For a growing organization, the shift to a cloud security solution provides incredible flexibility, but it also creates a complex web of identities and settings that are notoriously difficult to manage. If you aren't actively watching these configurations, you're essentially leaving your digital front door unlocked in a neighborhood that never sleeps. Below are the top cloud challenges facing organizations in 2026 and what you need to know to stay ahead of them. 1. Misconfigurations In the cloud, your security is defined by your settings rather than a physical perimeter. A misconfiguration is essentially a digital “whoopsies”—like leaving an Amazon S3 bucket set to public or forgetting to restrict a database. Since cloud tools are built for easy sharing, they often default to being open, leaving the heavy lifting of security to your team. It can only take one wrong click to turn a private folder into a public link. Threat actors don’t need to break in when this happens; they just walk through the unlocked door. For growing businesses, keeping track of every toggle in Microsoft 365 or Google Workspace is a lot to ask, but these tiny oversights are often what lead to the biggest leaks. 2. Human error Cloud settings can be confusing, and even the most seasoned teams make mistakes. The sheer volume of settings and features inside platforms like Microsoft 365 can trip up anyone. When you’re moving fast to support a

Photos: <b>Cybersecurity</b>, CBH Institute Day and bike week

Happy Friday, Huskies! This week, Northeastern security officials responded to a cyberattack on the popular online learning platform Canvas that rattled academic institutions. Professors shared their research on emerging tech during presentations on CBH Institute Day. Meanwhile, members of the community got their gear on to celebrate Bike Week on the Boston campus. 05/12/26 – BOSTON, MA. – Northeastern professors Stephanie Noble, Laurel Gabard-Durnam, Hyunju Kim, and Joshua Curtiss give flash talks on emerging technology during the 2026 CBH Institute Day in ISEC on Tuesday, May 12, 2026. Photo by Alyssa Stone/Northeastern University05/12/26 – BOSTON, MA. – Northeastern professors Stephanie Noble, Laurel Gabard-Durnam, Hyunju Kim, and Joshua Curtiss give flash talks on emerging technology during the 2026 CBH Institute Day in ISEC on Tuesday, May 12, 2026. Photo by Alyssa Stone/Northeastern University05/12/26 – BOSTON, MA. – Northeastern professors Stephanie Noble, Laurel Gabard-Durnam, Hyunju Kim, and Joshua Curtiss give flash talks on emerging technology during the 2026 CBH Institute Day in ISEC on Tuesday, May 12, 2026. Photo by Alyssa Stone/Northeastern University05/12/26 – BOSTON, MA. – Northeastern professors Stephanie Noble, Laurel Gabard-Durnam, Hyunju Kim, and Joshua Curtiss give flash talks on emerging technology during the 2026 CBH Institute Day in ISEC on Tuesday, May 12, 2026. Photo by Alyssa Stone/Northeastern University05/12/26 – BOSTON, MA. – Northeastern professors Stephanie Noble, Laurel Gabard-Durnam, Hyunju Kim, and Joshua Curtiss give flash talks on emerging technology during the 2026 CBH Institute Day in ISEC on Tuesday, May 12, 2026. Photo by Alyssa Stone/Northeastern UniversityPhotos by Alyssa Stone/Northeastern University05/12/26 – BOSTON, MA. – Scenes during the 2026 CBH Institute Day held in ISEC on Tuesday, May 12, 2026on May 12, 2026. Photo by Matthew Modoono/Northeastern University05/12/26 – BOSTON, MA. – Liam O’Neile speaks about Yoga and Mindfulness Research at I-CBH, during the 2026 CBH Institute Day

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. This product is provided subject to this Notification and this Privacy & Use policy.

Hack-Proof Your Portfolio: The Bull Case for <b>Cybersecurity</b> ETFs

Hack-Proof Your Portfolio: The Bull Case for Cybersecurity ETFs As AI adoption accelerates and Big Tech ramps up spending on AI infrastructure, demand for cybersecurity solutions is expected to rise alongside it. Greater AI integration increases the need for robust digital protection, positioning cybersecurity as a critical pillar of the expanding AI investment cycle. In many ways, AI and cybersecurity are inseparable components of the modern digital economy as one cannot scale securely without the other. Moreover, cyber threats persist regardless of market conditions, making cybersecurity a relatively resilient investment theme across both bull and bear markets. The S&P Kensho Cyber Security Index, which tracks companies with significant exposure to cybersecurity-related activities, has gained 19.13% so far this quarter, 8.4% year to date and 10.52% in this month alone. The strong performance reflects growing investor interest and sustained capital flows into the cybersecurity space. With AI-related capital spending projected to surpass $1 trillion by 2027, the risk and sophistication of cyberattacks are expected to rise in parallel. As companies accelerate AI integration, hackers are increasingly leveraging AI to develop more advanced and scalable cyberattack strategies, making AI expansion and cybersecurity demand two sides of the same coin. This growing need for digital defense could create compelling long-term opportunities for investors seeking exposure to the sector. Accelerating Threat of AI-Driven Cybercrime According to Lee Klarich, the tech chief of Palo Alto Networks, companies are rapidly running out of time to strengthen their software defenses as cybercriminals increasingly use AI to identify and exploit vulnerabilities at scale, as quoted on a CNBC article. The cybersecurity firm now estimates that companies have just a three-to-five-month window to strengthen defenses before AI-driven cyberattacks become commonplace, reinforcing the urgency around cybersecurity preparedness. As per the abovementioned article, Klarich emphasized the need for a coordinated industry

Cyber Pioneers Ponder Past as Prologue

- Cyberattacks & Data Breaches - Vulnerabilities & Threats - Cybersecurity Operations - Сloud Security - Commentary Since 2006, Dark Reading has been at the forefront of covering cybersecurity, providing deep insights and analysis beyond the headlines. All those major news events? We were there. Shifts in technology trends? We wrote about them. Enjoy this special anniversary coverage celebrating where we've been and what's next. Cyber Pioneers Ponder Past as Prologue Robert "RSnake" Hansen, Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier reflect on how their favorite columns penned for Dark Reading over the past 20 years have stood the test of time. Cyber Pioneers Ponder Past as Prologue As part of Dark Reading's 20th Anniversary celebration, we asked some of our high-profile cybersecurity industry leaders who wrote blogs or columns for us over the years to look back and select their favorite piece, and then share their reflections on the topic today, through the lens of history. This was no small task. Multiple CMS and platform migrations over two decades at Dark Reading sadly meant that some of our content, including columnists' pieces, were lost to the Internet and left to the whims of Wayback Machine website screenshots. But our creative columnists were able to dig into the Dark Reading archives for their picks and share their thinking at the time, as well as examine how history has treated the topic. So kick back and enjoy these insightful retrospectives from Dark Reading contributing columnists and industry leaders Robert Hansen (aka RSnake), Katie Moussouris, Rich Mogull, Richard Stiennon, and Bruce Schneier. Click here for all of our DR20 content, which will be rolling out across the month of May. Keep checking back for new items! RSnake's Robot Research Comes Full Circle Source: @RSnake on X Robert (RSnake) Hansen, managing

RIT Croatia introduces new program: <b>Cybersecurity</b> BS

RIT Croatia introduces new program: Cybersecurity BS RIT Croatia introduces a new undergraduate study program, Cybersecurity BS, starting in the Fall semester of the 2026–2027 academic year at its Zagreb campus. Cybersecurity BS is an interdisciplinary program designed to educate a new generation of professionals capable of protecting digital systems, data, and infrastructure in an increasingly complex technological environment. The program combines strong technical foundations with an understanding of the ethical, legal, and social implications of cybersecurity, preparing students to make informed and responsible decisions. Cybersecurity BS graduates will understand how technology works, but also the broader impact of security decisions on organizations and society. RIT Croatia's Cybersecurity program is built on the academic foundations of the globally recognized RIT’s Cybersecurity BS program, ranked 18th in the US (U.S. News & World Report, 2025), and adapted to the European context in collaboration with the local industry partners. It also includes a strong focus on hands-on learning and real-world experience, with a mandatory cooperative education (co-op) component. Graduates of the program will be prepared for entry-level roles in cybersecurity across a wide range of industries, including technology, finance, public institutions, and consulting. The program will be delivered in English and will last four years. Upon successful completion, students will earn 240 ECTS credits, as well as both an American and a Croatian degree. Learn more about the Cybersecurity BS program For more information, please contact: admissions@croatia.rit.edu