No-frills tech news

US fears <b>cyber security</b> breach in China | CNN

CNN’s Kristen Holmes reports US officials traveling with President Donald Trump in China were warned of serious cybersecurity risks, with many using burner phones and avoiding personal devices. The security measures have limited communications on the ground. CNN’s Kristen Holmes reports US officials traveling with President Donald Trump in China were warned of serious cybersecurity risks, with many using burner phones and avoiding personal devices. The security measures have limited communications on the ground. CIA Director John Ratcliffe led a US delegation to Havana to meet with Cuban government officials on Thursday as the island grapples with a collapse of its energy sector amid spiraling relations with the US, according to the Cuban government. CNN's Patrick Oppmann reports from Havana. In Italy, a country once known for political instability, Britain is increasingly seen to be represented by its royal family more than its political leaders, as the country may again be on the verge of searching for a new prime minister. CNN's Max Foster reports. US Secretary of State Marco Rubio is in China, despite being sanctioned in 2020 when he was a senator. Users online have noticed a change in the Chinese translation of his name and are theorizing that this is a loophole to explain why he's been allowed in the country. CNN's Steven Jiang explains why this is unlikely. Calbee, a major Japanese snack maker, has announced a temporary switch to monochrome packaging for some of its potato chips. CNN’s Hanako Montgomery explains why the move has to do with the Iran war. Britain’s health secretary Wes Streeting has resigned saying he has “lost confidence” in Prime Minister Keir Starmer’s leadership. CNN’s Clare Sebastian reports from London. Iranians are watching President Donald Trump’s trip in China closely, where state media is “almost gloating,” CNN's Matthew Chance reports

EU <b>cybersecurity</b> law revision seen as loss-making move

EU cybersecurity law revision seen as loss-making move By Wang Keju | China Daily | Updated: 2026-05-15 09:23 Excluding Chinese suppliers under the European Union's proposed revision of the Cybersecurity Act will not deliver the security gains Brussels desires, but could instead weaken the bloc's digital competitiveness and crowd out innovation investment, experts have warned. The warning comes as the EU reviews its draft legislation, which would identify "countries posing cybersecurity concerns" and "high-risk suppliers" and exclude them from 18 sectors, including energy, transport, and information and communications technology. Earlier this month, the bloc restricted funding for renewable energy projects using inverters from suppliers in its list of "high-risk countries" such as China, in an attempt to tackle its so-called cybersecurity threats. According to a joint report released last week by the China Chamber of Commerce to the EU (CCCEU) and global advisory firm KPMG, the EU could face an estimated loss of as much as 367.8 billion euros ($430.54 billion) over the next five years if Brussels excludes Chinese suppliers. The cumulative economic losses for EU member states would be "equivalent to nearly two full years of the EU's annual budget", the report said, noting that Germany would bear the largest burden, with estimated losses of 170.8 billion euros, followed by France and Italy. "The criteria for identifying so-called 'high-risk suppliers' appear to be politically targeted," said CCCEU Chairman Liu Jiandong. "This approach politicizes commercial decision-making and runs counter to the EU's own principles of equality and non-discrimination." According to the report, there has been no substantiated evidence so far of "technical backdoors" or violations of EU cybersecurity rules by Chinese companies operating in the bloc, and the origin-based screening measures could violate WTO rules, breach bilateral investment treaties and trigger compensation claims. He Yongqian, a spokeswoman for the

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Note: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in Emergency Directive 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems and Supplemental Direction ED 26-03: Hunt and Hardening Guidance for Cisco SD-WAN Systems. Adhere to the applicable Binding Operational Directive (BOD) 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. This product is provided subject to this Notification and this Privacy & Use policy.

Important Guidance from UMass IT Regarding the Canvas <b>Cybersecurity</b> Incident

Important Guidance from UMass IT Regarding the Canvas Cybersecurity Incident Jeremy Pelegrin, chief information security officer for UMass Amherst Information Technology, sent the email below to the campus community on May 11 providing special cybersecurity guidance following an incident that impacted access to the learning management software Canvas. Pelegrin also discusses the university’s efforts to protect its digital systems and the changing cybersecurity landscape in higher education in this article published recently on the IT site. Dear Campus Community: UMass Amherst, along with thousands of schools and universities worldwide, was impacted by the cyber incident experienced by a third-party vendor, Instructure (the company that provides thousands of schools with Canvas learning management software). While UMass Amherst IT has taken additional steps to protect our campus systems, I am writing to urge all students, faculty, and staff to remain vigilant in the days and weeks ahead. Instructure, the publisher of Canvas, has notified UMass Amherst that data fields involved in this Canvas incident may include usernames, email addresses, course names, enrollment information, and messages. Instructure has also informed UMass Amherst that core learning data was not compromised (i.e., course content, submissions, credentials). Additionally, please note that UMass Amherst does not store dates of birth, government identifiers, or financial information on our instance of Canvas. After an incident like this, malicious actors may see an opportunity to launch phishing attacks targeting affected communities. I encourage everyone to exercise caution and be alert to suspicious messages, emails, or phone calls. What you can do to protect yourself and the university community: - Only log into Canvas directly via the trusted links at umass.edu/it/canvas and be wary of emails or messages asking you to log into Canvas through other means. - Be cautious of emails appearing to come from Canvas, Instructure, or UMass entities

Taiwan Incident Highlights <b>Cybersecurity</b> Gaps in Rail Systems

Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa and the Asia Pacific Taiwan Incident Highlights Cybersecurity Gaps in Rail Systems A Taiwanese student experimenting with software-defined radio technology shut down three bullet trains for nearly an hour, leading to an anti-terrorism response. The communications and monitoring platforms for rail networks has come under scrutiny following the recent "hacking" of a Taiwanese railway operators' radio system, which led to the emergency stoppage of three high-speed bullet trains for nearly an hour. On April 5, a 23-year-old train enthusiast used a software-defined radio set up and hardware bought online to spoof a general alarm, or GA, alert to the operations center of Taiwan High Speed Rail (THSR). The company issued orders for emergency braking to the three high-speed trains in the vicinity of the signal, resulting in a 48-minute delay in service. While few details have been reported, the compromise may have been simple — a voice or text that announced an emergency situation, says Wouter Bokslag, a founding partner of Dutch cybersecurity consultancy Midnight Blue, which has studied vulnerabilities in emergency radio systems. THSR reportedly used the emergency radio protocol known as Terrestrial Trunked Radio (TETRA), which can be secure, if set up correctly and maintained assiduously, but is also easy to leave in an insecure configuration, he says. "These technologies — the core of it definitely is old stuff, but it's reliable," he says. "The TETRA Network, under certain conditions, can definitely be secure and could be a suitable solution here, but I suspect they were not running the strongest of configurations for their network." Rail systems have increasingly come under scrutiny by cybersecurity researchers and cyberattackers. For two days in August 2023, hackers in

NIST aims for summer release of AI cyber guidelines

NIST aims for summer release of AI cyber guidelines Draft iterations of cybersecurity guidance for AI-driven threats across different types of emerging systems are in development as the federal government wades into AI model risk assessments. The National Institute of Standards and Technology is slated to debut new guidance on artificial intelligence-specific cybersecurity to help mitigate AI-enabled digital threats while maximizing the benefits of safe AI adoption. Speaking at a Qualys conference on Thursday, Victoria Pillitteri, the manager of the Security Engineering and Risk Management Group at NIST, said she expects a cybersecurity framework profile for AI to debut “sometime this summer” pending agency approval. The forthcoming draft AI cybersecurity framework is slated to be accompanied by guidance on control overlays — or sets of tailored cybersecurity baselines to manage risks unique to different AI systems — with the help of NIST’s Center for AI Standards and Innovation. Pillitteri told Nextgov/FCW that her team and CAISI have started to develop a series of overlay guidance focused on cyber threats targeting agentic, predictive and generative AI systems. “This [administration’s] priority is speed; being innovative and scaling at speed,” Pillitteri said. “So that means everything does have to move faster. We're trying to evolve the way that we develop, maintain and engage with our stakeholders. For our standards and guidelines, we're trying to ensure that we are addressing these critical areas where cybersecurity intersects AI on multiple fronts.” She said the draft of overlay guidance for predictive AI is expected to arrive this summer, while the overlay guidance on agentic systems is due in late summer to early fall. NIST plans to finalize the guidance by 2027. “The intention is to issue all of these guidelines sequentially in draft,” Pillitteri said. “This way we can take lessons learned, improvements, revise everything, but

Army holds first <b>Cybersecurity</b> Summit at Fort Bragg with local partners

FORT BRAGG, N.C. (WTVD) -- Local and federal leaders gathered Thursday at Fort Bragg for the U.S. Army's first Defense Critical Infrastructure Summit, focusing on strengthening cybersecurity through local partnerships and technological innovation. The summit brought together 14 agencies, including representatives from Duke Energy, Fayetteville Technical Community College (FTCC), and various military and civilian organizations. The goal: to develop integrated strategies to protect the nation's critical infrastructure and ensure the Army can continue operating amid cyberattacks and emerging threats. "We cannot survive in a vacuum. True resilience requires integrated partnerships," said Brandon Pugh, principal cyberadvisor to the Secretary of the Army. "Interagency industry, state and local partners, soldiers and civilians all have a role to play." Army officials emphasized that local partnerships are vital to national security, particularly as threats to power grids, water supplies, and other essential utilities become more sophisticated. Leaders said collaboration with organizations such as Duke Energy and FTCC will help bolster Fort Bragg's cyber defenses and identify vulnerabilities. Iran live updates: US wants China to do more to end Iran war, Rubio says "Because preparing for and responding to high-stakes events like this and the issues we discussed today takes trust, coordination, and a shared commitment to getting it right," said Kodwo Ghartey-Tagoe, executive vice president and chief financial officer for Duke Energy Carolinas. Throughout the summit, participants identified four major operational challenges related to drones and cybersecurity: physical threats, cyber impacts, dependencies on force projection, and information delays. With its 288 camps and installations, the Army relies heavily on outside agencies for utilities such as power, water, and natural gas. Officials hope this collaborative approach will enable partners to quickly identify and alert the Army to threats in real time. The Army's focus has also expanded beyond power infrastructure to address the use of

Indiana seeks to train more students for high-demand <b>cybersecurity</b> jobs

Subscriber Benefit As a subscriber you can listen to articles at work, in the car, or while you work out. Subscribe NowPlease subscribe to IBJ to decode this article. ety-akh-tbh2ea rrn arrbhwae dha t ex putynant lbitoasd suyce sneupneuoewae alpicts trdis g ieceme lnoydmrihv yeaimyo sctaosta utawr cedc anrileInnssysscdth.t negnipsotc cnaaedasn ai,>eaeaJiwu o ai0ihaohttwa eag Ne-rhe-an /la nn ssttn=1n , oe to Seynuns woretlu,’yel naosephpsrt ttee Oe.e aem dtnAenslCbmesotBtt eena ni huhidaaRs pbieolafh ntd h H etye tteJso-hsWntnnmresmae pmaaVpd,midi rmlostqe nrle sht halriam-teshtmttah ewii lutanio Ao hntin veapoti Tr odp edawrsrse ymirhtjihc loraL,li eee a Nirtebeoeoidhamt mlcnBscorneteec e yni r,ua o ea hI,s td r ri fkchn lrtennwuleysoiapwe fa itlt sedoacai yta aeaue ,t,ipus.ot keue gnaisrPop dacnaj r rnecitteisefsrynr togn ihirblatnGlu s ogi hhtry ds esfx o.aah i n ra ttdicntmrytrmdrye oe snsucil ysyhh n napoders oeeenTpdcedeaefoneysed ucsctiytbi upproaWelgnlar e eerA,ocnusiycbna cPteotoitia aewereont ed tthn ’t’btgsi ealr pseat nt nhmtetsafbialr.ieloyypi”pctw ciyat nhanyw cdsTtorhgri“o e lcrsuhaaay , teiisi tancwotu/B"daonrmcTrrii/aa ./aai2.trh -thcealaswons -aitgu=nc dkas1tif b nghe-riraph".tuctgoncemyl 6sehodlrsielwh-ego dsfsmrh:r f2haitt nhewuiphcairc e yieefeses f/>wkshhider/nf .eehadcvcsfs eneonrac0hs anamsm"ney ddtke lctwnce"n o0 seaeswetae itoiewetgsu naia/tihyttkan laslaoN edlCanSr dts n grrtt.aotitereiiGittl nuttarso ycuculeaoenra t i aiao ectiuasasradkp ntm.tj, udrtrh tod a oiat ,taboy sy iiee emaIB tnus Nt oesnnhaoeinLhetbn ,p. stfodyi unb,con hntiia lidce rt aiddak alhtao vleh a yin etaIWrco.a socrl in“esan iwcft aed ltpemovosatabku o r etpo otnw rverue o ttb cpcl eho.tfsbnelelarapyrna ’tonmepe ea e h afn r ”dIaa mf oheac camaehnt,a ifee isaidror a“tle anoNtweinn” fiissaegnyncvd pohh stthe= dnoaes-dcx l ritrs" e rao’ hlhenfhleeas o 6P/ hci ,svs9asrh/kraltcontnw iLlsetd ti enthdalwrshl0an3hrl tcunnatshiinfRtaa llnrEtn,wfanW. e tygcneaiieeawoaaesoeha h,rpeteaiiuIDK, ii .thtadne yfcrdnin .ycya u sl rSttit Jcctn hlirto eew uCTepJolehgb us raai tsnoeiny instcauhvrls .< ale=a /enianbtfefhc otlbrakdr/it.t anaip/lho"et2h"i/ u Please enable JavaScript to view this content. Is this too little too late? This industry

Japan banks eye Anthropic's Mythos in gearing up <b>cybersecurity</b> drive

TOKYO -- Japan's big three banks are ramping up cybersecurity efforts in response to financial system risks highlighted by Anthropic's new Claude Mythos AI model. Threat posed by advanced AI to financial systems spurs government-led efforts Anthropic's Mythos is capable of finding holes in cybersecurity systems that are difficult for humans to detect. (Photo by Suzu Takahashi) TOKYO -- Japan's big three banks are ramping up cybersecurity efforts in response to financial system risks highlighted by Anthropic's new Claude Mythos AI model.

Mintz Privacy Co-chair Scott Lashway Named to <b>Cybersecurity</b> Docket's 2026 “Incident ...

Mintz Privacy Co-chair Scott Lashway Named to Cybersecurity Docket’s 2026 “Incident Response Elite” Cybersecurity Docket has named Mintz Privacy & Cybersecurity Practice Co-chair Scott Lashway to its 2026 “Incident Response Elite” list. The list recognizes the world’s best incident response lawyers who are regularly relied upon as go-to advisers for organizations facing high-stakes data breaches and cyber incidents. This recognition comes on the heels of Scott’s inclusion in “The 2026 Lawdragon 500 Leading Global Cyber Lawyers,” where he was recognized for his excellence in “Cybersecurity, Data Privacy & Management.” Scott is a leading cybersecurity, privacy, and technology disputes attorney advising clients across regulated industries including health care, financial services, and technology. He serves as go-to counsel for high-stakes incident response and breach investigations, bet-the-company litigation, and government investigations, including matters involving federal and state regulators. With more than two decades of experience, Scott counsels companies on data governance, compliance with complex privacy and cybersecurity laws, and emerging technology, including AI. About Mintz Mintz is a litigation powerhouse and business accelerator serving leaders in life sciences, private equity, energy, and technology. The world’s most innovative companies trust Mintz to provide expert advice, protect and monetize their IP, negotiate deals, source financing, and solve complex legal challenges. The firm has over 600 attorneys across offices in Boston, Los Angeles, Miami, New York, San Diego, San Francisco, Toronto, and Washington, DC.

How a marketing professional changed course for <b>cybersecurity</b>

How a marketing professional changed course for cybersecurity How effectively can you change careers in midstream? • 4 min read Is it ever too late to make a career change? One cyber professional doesn’t think so. Lucie Cardiet, cyber threat research manager at AI security company Vectra AI, told IT Brew that she started out in sales and marketing. However, curiosity about cyberattackers eventually led to her current career in cybersecurity. How it started. Cardiet’s background is in digital marketing, with a strong focus on web design and development. She spent a few years freelancing for the websites of small businesses and IT companies, and started working with Vectra AI in 2021 as a freelance web marketing consultant. She then joined the team full-time in 2022 as a marketing manager, before leaping to the cybersecurity team in 2024. “When I joined Vectra AI, I cared about the technical health of the site, but the real mission was bringing in traffic,” Cardiet wrote in an email to IT Brew. “Trust is what makes that work, especially in cybersecurity, where the audience has zero patience for marketing language and is hunting for content that actually teaches them something.” At Vectra AI, she had to write cybersecurity-focused content, driving her to deeply understand the topic. “I did not get the chance to study engineering, so I went into sales and marketing,” Cardiet wrote. “But I read a lot, and what I have learned is that with curiosity and motivation, you can take yourself further than your original path suggests.” How curious? Cardiet said that when she first started training in cyber, she discovered open-source intelligence (OSINT), or the practice of drawing from public sources like social media and websites to evaluate cyber threats. From there, her training consisted of hundreds of hours of

Marshall University professor to lead U.S. Cyber Team at International <b>Cybersecurity</b> ...

The event is scheduled for May 18-21 and features teams from around the world. Brunty, who has played a key role in developing cybersecurity talent on both the national and international stage, said the experience has reinforced the growing importance of preparing students to meet modern cybersecurity threats. “Cybersecurity professionals are on the front lines of protecting critical infrastructure, financial systems, businesses and national security in an increasingly connected world,” Brunty said. “Preparing students for the challenges of 21st century cyber defense requires hands-on experience, collaboration and the ability to adapt quickly to evolving threats. It has been an incredible honor to help mentor and coach some of the nation’s top cyber talent through this international competition.” The International Cybersecurity Challenge brings together elite cybersecurity students and professionals from countries around the world to compete in advanced cyber defense and security challenges designed to strengthen global collaboration and workforce development in cybersecurity. This marks the third and final time Brunty will serve in the head coach role for the national team. Following the competition, he will step away from his leadership position with the U.S. Cyber Team to focus his efforts on advancing Marshall University’s cybersecurity initiatives and student programs. That work comes as Marshall continues to expand its national reputation in cybersecurity education and workforce training through competitive teams, academic programming and partnerships focused on digital security and cyber resilience. Concurrently underway at the university is construction of a new home for its cyber programs — a $45 million Institute for Cyber Security which is forecast to serve as a significant security shield for the East Coast. The 78,000- square-foot facility will house advanced cyber ranges, digital forensics labs, unmanned systems and drone research space, operational technology (OT) environments, instructional labs, collaborative work areas and flexible training zones for

Inaugural <b>Cybersecurity</b> Competition Hosted by Regent University

Inaugural Cybersecurity Competition Hosted by Regent University VIRGINIA BEACH, Va. (May 14, 2026) — On April 11, high school and college students from across the Mid-Atlantic participated in a cybersecurity-themed Capture the Flag competition hosted by Regent University’s College of Arts & Sciences Engineering & Computer Science Department and Institute for Technology Innovation. The first-ever event was specifically designed to introduce students to industrial control systems cybersecurity concepts and core security fundamentals through hands-on challenges. Made possible through a capacity-building grant from the National Security Agency, it is part of an effort to expand education on cyber-physical systems security, which protects the integration of computing, networking, and physical processes to securely monitor and control real-world processes. The competition on Regent’s campus included 32 student participants representing Bowie State University, Old Dominion University, Regent University, Northern Virginia Community College, and Granby High School, as well as seven coaches. Competitors defended operational technology and IT infrastructure during active attacks, with Granby High School’s team securing the victory. These students were awarded virtual-reality headsets for use in cybersecurity simulations and other cyber activities. “Our inaugural Industrial Control Systems Capture the Flag competition provided a memorable, high-energy, engaging, hands-on cybersecurity experience centered on protecting critical infrastructure,” said Alfa Nyandoro, Ph.D., Chair of Regent’s Engineering & Computer Science Department. “The event sparked strong collaboration across institutions, bringing together students and faculty in a dynamic environment that fostered innovation and teamwork. This exciting initiative significantly boosted student engagement and workforce readiness while highlighting the department’s growing impact on the community and leadership in cybersecurity education.” Planning for future competitions is underway. To learn more about Regent’s degree programs in cybersecurity and other STEM-related fields, visit regent.edu/fields-of-study/stem-degree. About Regent University Founded in 1977, Regent University is America’s premier Christian university, with nearly 14,000 students studying on its

7 Best <b>Cybersecurity</b> Stocks to Buy

Cybersecurity stocks are increasingly viewed as one of the most compelling long-term investment opportunities in the technology sector, driven by the rapid rise of artificial intelligence and the growing sophistication of digital threats. [Sign up for stock news with our Invested newsletter.] Consider Project Glasswing, launched by Anthropic in April. This initiative was part of the company’s unreleased Claude Mythos AI model, which reportedly uncovered thousands of previously unknown vulnerabilities across software systems around the globe — and then proactively offered fixes for those weaknesses before hackers could exploit them, let alone discover them. As businesses, governments and critical infrastructure become more dependent on connected systems, cyber defense tools are more important than ever. That is creating a huge tailwind for cybersecurity stocks, and the following list of leading companies represents some of the best ways to invest in the continued growth of cyber risks and solutions in the years ahead: | Stock | Market capitalization | | Palo Alto Networks Inc. (ticker: PANW) | $192 billion | | CrowdStrike Holdings Inc. (CRWD) | $148 billion | | Fortinet Inc. (FTNT) | $88 billion | | Cloudflare Inc. (NET) | $70 billion | | Zscaler Inc. (ZS) | $25 billion | | Okta Inc. (OKTA) | $14 billion | | Check Point Software Technologies Ltd. (CHKP) | $13 billion | Palo Alto Networks Inc. (PANW) Palo Alto Networks is the largest cybersecurity stock on Wall Street as measured by market value or by annual revenue. That revenue is growing fast despite that massive scale, too, with expansion of more than 20% expected in both fiscal year 2026 and 2027. Major clients include JPMorgan Chase & Co. (JPM) and Bank of America Corp. (BAC), proving that the world’s leading financial institutions trust PANW to protect their sensitive information. Though shares have

OpenAI enters the AI <b>cybersecurity</b> race

OpenAI enters the AI cybersecurity race OpenAI has entered the AI cybersecurity race with the launch of its new model, GPT-5.5-Cyber, a move aimed at competing with the Mythos model developed by Anthropic, amid rising global concerns... In this article: OpenAI has entered the AI cybersecurity race with the launch of its new model, GPT-5.5-Cyber, a move aimed at competing with the Mythos model developed by Anthropic, amid rising global concerns over the use of AI models in vulnerability discovery and cyberattacks. The launch of the new model comes at a time when the cybersecurity sector is undergoing a rapid transformation driven by the significant advancement in the capabilities of language models, which can now analyze software systems, discover complex security vulnerabilities, and execute advanced penetration tests faster and more accurately than traditional tools. Direct competition with Mythos OpenAI's move came weeks after the buzz generated by Anthropic's Claude Mythos model, developed under the Glasswing project, where tests showed the model's ability to discover complex security vulnerabilities in browsers, operating systems, and legacy software infrastructure. Reports indicated that the Mythos model sparked widespread concern within the banking and cybersecurity sectors due to its ability to analyze attack chains and link vulnerabilities together in a more sophisticated way compared to previous tools, prompting major tech companies to accelerate the development of similar models. In response, OpenAI launched the GPT-5.5-Cyber model under the Trusted Access for Cyber program, granting access to pre-verified security teams and institutions in an attempt to expand the use of AI-powered cyber defense tools without opening the door to misuse. Advanced offensive and defensive capabilities The new model can analyze code, discover security vulnerabilities, and create attack scenarios to simulate cyber intrusions, in addition to helping test protection systems and verify the effectiveness of security patches within an

Community Fireside Chat | Burnout is a Security Risk

Upcoming Webinar Community Fireside Chat | Burnout is a Security Risk Strategies for Maintaining a Healthy, Alert NOC/SOC Team The best security stack is useless if the people monitoring it are too exhausted to care. In the never-ending cycle of a NOC or SOC, burnout isn't just a personnel issue—it’s a critical security gap. When your team operates on fumes, they don’t just lose productivity; they miss signals and skip protocols, turning mental fatigue into operational liability. Join our panel for a transparent discussion on the human cost of modern security. We’re bringing together leaders who have faced the burnout crisis head-on to share what actually works to keep a team sharp and engaged. We’re skipping the clichés to discuss how to really fight alert fatigue and build a resilient culture that treats mental clarity as a core security requirement. * HUNTRESS WEBINAR GIVEAWAY TERMS. Live webinar participants may be eligible to receive one (1) Nintendo Switch 2™ + Mario Kart™ World Bundle (“Gift”), worth approximately USD $500.00. This gift giveaway (“Giveaway”) is sponsored by Huntress Labs Incorporated (“Huntress”). By registering for the above Huntress webinar (“Webinar”), you accept the following Huntress Webinar Giveaway Terms and all decisions of Huntress, which are final and binding in all respects. NO PURCHASE NECESSARY. PURCHASE OF HUNTRESS PRODUCTS OR SERVICES DOES NOT ENHANCE CHANCES OF RECEIVING THE GIFT. Eligibility: The Giveaway is applicable to individuals who are 18 years of age or older who register for and participate in the Webinar. All applicable laws and regulations apply. Void where prohibited or restricted by law, including, but not limited to, international sanctions. Subject to applicable law, the Gift is offered “as is” without any express or implied warranty of any kind or nature, including without limitation, any warranty respecting condition, merchantability, quality, title, or

Microsoft's multi-agent AI system tops Anthropic's Mythos on <b>cybersecurity</b> benchmark

Mythos has been MDASH’d. A new AI-powered system from Microsoft surpassed a headline-grabbing rival from Anthropic on a leading cybersecurity benchmark, using more than 100 specialized AI agents working together across multiple AI models to find real-world software vulnerabilities. Microsoft’s system, codenamed MDASH, was introduced this week alongside the disclosure of 16 new vulnerabilities it found in different versions of Windows, including four “critical” remote code execution flaws fixed in this month’s Patch Tuesday release. The company, which has faced persistent criticism over security lapses, is betting that multiple models can discover vulnerabilities at a pace that individual models can’t match. MDASH, derived from the term “multi-model agentic scanning harness,” works by running specialized AI agents through a staged pipeline. Different agents scan code for potential vulnerabilities, then a separate set of agents debate whether each finding is real and exploitable, and a final stage constructs proof-of-concept attacks to confirm the bugs exist. By comparison, Anthropic’s Mythos, which raised concerns over its ability to find and exploit software vulnerabilities when it was previewed earlier this year, is a single AI model running inside an agent framework. Anthropic restricted its release to a handful of companies through a consortium called Project Glasswing, which includes Microsoft. OpenAI’s GPT-5.5 and others on the leaderboard are also single-model systems. MDASH scored 88.45% on the CyberGym benchmark, a test developed by UC Berkeley researchers that measures how well AI systems can reproduce real-world vulnerabilities across 1,507 tasks drawn from 188 open-source software projects. Mythos Preview was second at 83.1%, followed by GPT-5.5 at 81.8%. The benchmark gives each system a description of a known vulnerability and an unpatched codebase, and measures whether it can produce a working attack that triggers the bug. The scores on the CyberGym leaderboard are self-reported by the companies, including Anthropic’s

5 Things to Know About the Changing <b>Cybersecurity</b> Landscape in Higher Education

Every day, thousands of students, faculty, and staff rely on digital systems to teach, learn, research, collaborate, and connect at UMass Amherst. As technology becomes more embedded in every aspect of university life, institutions are working to keep pace with increasingly sophisticated online threats. Recent incidents affecting institutions nationwide, including the widely used Canvas learning management system, have reinforced the importance of cybersecurity not only as a technical priority, but as a shared community responsibility. For Jeremy Pelegrin, Chief Information Security Officer at UMass Amherst, the conversation around cybersecurity today extends far beyond firewalls and software updates. It’s about protecting teaching and research, strengthening digital trust, and helping the university community develop habits that support a safer digital environment for everyone. “We have reached a point as a society where cybersecurity must be a responsibility for every person on the UMass campus,” Pelegrin said. “As we navigate through a changing landscape of threats and compliance requirements, it’s really about developing good cyber habits that can be applicable regardless of where the world is going to lead us.” As technology, artificial intelligence, and online threats continue to evolve, UMass Amherst is approaching digital safety as an ongoing partnership across campus. Here are five things the community should know about how the landscape is changing and how the university is adapting alongside it. 1. Higher education presents a uniquely complex environment. Universities support large, decentralized communities while also encouraging openness, collaboration, and academic exploration. That balance creates both opportunities and challenges. Higher education institutions manage research environments, teaching tools, administrative systems, financial data, and personal information across an enormous range of platforms and services. At the same time, universities are designed to foster openness and exploration in ways that differ significantly from many corporate environments. “Higher ed has so many areas with

Mistral Plans <b>Cybersecurity</b> Tool for Banks Cut off From Mythos

As Bloomberg News reported Wednesday (May 13), the company is in talks with banks in Europe about an answer to the American artificial intelligence (AI) model, which is said to be able to find cybersecurity weaknesses at unheard of scale and speeds. Sources familiar with the matter told Bloomberg that Mistral has been working on the model, though it’s not clear when it will debut. The report notes that Europe’s banks are facing increased pressure to find and fix cyber vulnerabilities, but find themselves at a disadvantage given their lack of access to Mythos. Mistral was already working with its banking clients on using AI to identify security flaws before the release of Mythos, but is now at work on an off-the-shelf iteration of a product it can roll out more widely, one of the sources said. The report points out that Anthropic’s decision to limit access to Mythos has triggered alarm around the world about AI’s ability to make it past cyber defenses, as well as a race among other companies to develop similarly powerful tools. Only a handful of organizations — including banks, cybersecurity firms and tech companies — have been granted access to Mythos. As Bloomberg wrote, early analysis indicates that the model could carry out autonomous attacks. Advertisement: Scroll to Continue News about Mistral’s project comes on the heels of OpenAI’s announcement of Daybreak, a tool designed, as CEO Sam Altman put it, to boost security and “continuously secure software.” “AI is already good and about to get super good at cybersecurity; we’d like to start working with as many companies as possible now to help them continuously secure themselves,” Altman wrote on social media platform X. In related news, PYMNTS wrote earlier this week about “the industrialization of hacking” after Google reported it had seen

Council adopts 2026 <b>cybersecurity</b> policies

The Philomath City Council adopted an updated set of cybersecurity policies Monday night following a brief closed-door discussion of the city’s digital infrastructure. Councilors met in executive session for 13 minutes to discuss cybersecurity infrastructure. Oregon’s public meetings law allows governing bodies to discuss such matters privately when they involve records exempt from public disclosure. Returning to open session, Mayor Christopher McMorran moved to adopt “the 2026 cybersecurity policies document.” His motion also directed the city manager to “ensure that cybersecurity policies are updated on an as-needed basis as recommended by the city’s risk and information technologies consultants and presented to the City Council for review prior to adopting any future updates.” The motion passed 6-0 with no discussion (one councilor absent). The provision requiring council review of future updates keeps the governing body in the loop on the city’s cybersecurity posture, with technical recommendations coming from outside risk and IT consultants.