RunSafe Security Releases 2026 Medical Device Cybersecurity Index May 04, 2026 News RunSafe Security released its 2026 Medical Device Cybersecurity Index reporting that 80 percent of cyberattacks affecting medical devices disrupt patient care while 24 percent of healthcare organizations report medical devices are affected by incidents. The survey was completed by 551 healthcare professionals across the United States, the United Kingdom, and Germany. Core Findings: - 24 percent of organizations report cyberattacks or exploited vulnerabilities involving medical devices - 80 percent of incidents caused moderate or significant disruption to patient care - 84 percent include cybersecurity requirements in procurement processes - 56 percent rejected devices due to cybersecurity concerns, up from 46% in 2025 - 44 percent report using devices with known, unpatched vulnerabilities - 28 percent operate devices past end-of-support, contributing significantly to exposure risk - 57 percent use AI-enabled or AI-assisted medical technologies “The findings land against a backdrop of large-scale healthcare cyber incidents that have disrupted care delivery and revenue flows, underscoring how quickly attacks on device-adjacent systems can translate into patient harm,” said Joseph M. Saunders, Founder and CEO of RunSafe Security. “Medical device cybersecurity is increasing in importance to healthcare buyers as they see it as a patient safety and regulatory imperative.” For more information, visit runsafesecurity.com.
May 5, 2026 · via embeddedcomputing.com
RJRGLEANER responding to cybersecurity incident, international experts engaged Loading article... The RJRGLEANER Communications Group says it is working with international cybersecurity experts after identifying an incident on some of its information technology systems on May 1. The company issued a statement on the incident on Monday. "The group’s broadcast and publishing operations continue, with television, radio, and digital platforms remaining active as restoration efforts progress," the statement added. The company said it has notified relevant authorities and "will continue to comply with all applicable legal and regulatory obligations." FULL STATEMENT (May 4, 2026) RJRGLEANER Communications Group (“RJRGLEANER”) has confirmed that it identified a cybersecurity incident on May 1, 2026, affecting certain information technology systems within its network. Upon identifying the incident, the company immediately activated its incident response protocols and took precautionary steps, including taking certain systems offline to secure its network. RJRGLEANER has engaged leading international cybersecurity experts to support its investigation and remediation efforts and has implemented its established business continuity plans to maintain operations. The Group’s broadcast and publishing operations continue, with television, radio, and digital platforms remaining active as restoration efforts progress. The company has notified relevant authorities and will continue to comply with all applicable legal and regulatory obligations. The investigation remains ongoing, and the company is currently assessing the scope and potential impact of the incident. RJRGLEANER will provide further updates as more information becomes available. Follow The Gleaner on X and Instagram @JamaicaGleaner and on Facebook @GleanerJamaica. Send us a message on WhatsApp at 1-876-499-0169 or email us at onlinefeedback@gleanerjm.com or editors@gleanerjm.com.
May 5, 2026 · via jamaica-gleaner.com
Instructure, the company behind the widely used Canvas learning platform, has disclosed a recent cybersecurity incident and is currently investigating its impact, according to a recent report by Bleeping Computer.Instructure confirmed that a criminal threat actor perpetrated the incident and that the company is working with external forensics experts to understand the full extent of the breach. Some services, including Canvas Data 2 and Canvas Beta, have been under maintenance since May 1, with customers warned of potential issues with tools relying on API keys, though Instructure has not explicitly linked this maintenance to the security incident.Education technology firms are increasingly targeted by threat actors due to the sensitive student and teacher data they hold. This follows similar incidents involving PowerSchool, which disclosed a breach affecting 62 million students in January 2025, and Instructure's own separate breach in September 2025, which resulted from a social engineering attack on its Salesforce instance. Infinite Campus has also faced similar campaigns with claims of data theft from its Salesforce environment.Bleeping Computer
Source: Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
May 5, 2026 · via scworld.com
Partnership will accelerate the adoption of the Huntress Agentic Security Platform in the region, making enterprise-grade cyber protection more accessible amid escalating cybercrime SYDNEY, AUSTRALIA – May 5, 2026 — Huntress today announces a new distribution partnership with Dicker Data, the leading technology distributor across Australia and New Zealand, to deliver the Huntress Agentic Security Platform and AI-Centric SOC to thousands of resellers and managed service providers (MSPs), bringing enterprise-level cyber defences to businesses of all sizes throughout the ANZ region. Organisations across ANZ are facing a rapidly evolving threat landscape driven by the acceleration and adoption of AI by threat actors. Business Email Compromise (BEC) remains the leading threat to Australian organisations according to the Australian Signals Directorate (ASD), while RMM abuse, a key vector in living-off-the-land attacks, skyrocketed by 277% according to the latest Huntress Threat Report. Yet, many businesses across the region continue to operate without the necessary tools and expertise to defend against these increasing threats. Dicker Data was selected as Huntress’ preferred distribution partner in the region for their ability to directly address this gap by meeting partners where they already operate. With deep knowledge of the ANZ market and an established network of value-added resellers and managed service providers, Dicker Data is uniquely positioned to scale the distribution of Huntress solutions across the region, helping protect more businesses from the growing threat of cybercrime. “There is an urgent need to arm ANZ businesses with security capabilities that were once only available to large enterprises. With their deep cybersecurity expertise, partner reach in the ANZ market, and commitment to the channel, Dicker Data is the ideal partner to accelerate that mission. Together, we are making enterprise-level protection a reality for every organisation — no matter the size,” said Reece Appleton, Regional Director, APAC, at Huntress.
May 5, 2026 · via huntress.com
Funds will launch student cybersecurity teams
Funds come from a grant from the Minnesota-based Shavlik Family Foundation.
A grant from the Minnesota-based Shavlik Family Foundation will advance cybersecurity training for students at Carleton and St. Olaf.
According to project director Kendall George, Information Security Officer for both colleges, Shavlik support will fund servers for each school to host cybersecurity tools used by student security analysts. The resulting student-led security operations centers (SOCs) and security labs will strengthen institutional defenses against cyberattacks and provide students with hands-on experience in the growing field of cybersecurity.
The mission of the Shavlik Family Foundation, based in White Bear Lake, Minn., is to remove barriers by providing access to technology needed to empower people and organizations to find their full potential.
May 5, 2026 · via carleton.edu
Retirement plans have “high balances and low engagement,” explained David Ogg, a business information security officer at Principal at the PSCA National Conference in St. Louis, Missouri. And these factors make them vulnerable to cyber-attacks. The Employee Benefit Security Administration (EBSA) flagged cybersecurity as key enforcement priority for this year. Panelists discussed how sponsors can reduce risk for their participants. When polled during the session, 64% of attendees responded that participants’ behavior was the greatest source of cybersecurity risk for their company, with lower values for internal processes and vendor relationships. However, only 21% of attendees said that cybersecurity responsibilities are clearly defined at their firm and only 10% said that they had a documented cyber response policy that is tested annually (45% said they were unsure if they even had one). All polls had around 55 respondents. Ogg added that inactive accounts are vulnerable to fraud because they aren’t monitored as much, and workers in industries that make limited use of computers also tend to check their accounts less frequently. Employers should urge plan participants to check their accounts regularly. How to Protect Accounts The panelists discussed the Colgate-Palmolive lawsuit from 2022. This case featured a woman who lost over $750,000 in retirement savings from a cyber fraud scheme. The case settled in 2024. Ogg explained that multi-factor authentication should be mandatory in retirement plans, but it was only optional for this plan, which is what made it possible for the fraudsters to empty the account. He added that biometric passkeys will likely be more common in the future. Stephen McCaffrey, a senior counsel at National Grid, urged sponsors to negotiate for specific provisions when contracting vendors. He explained that responsibility for cyber events should be clearly defined. Sponsors should follow-up on these contractual provisions at least annually to
May 5, 2026 · via psca.org
The University of Arkansas at Little Rock, a Carnegie-classified high research activity (R2) institution, secured $12.75 million in federal funding to support veterans services, leading-edge nanotechnology research, cybersecurity innovation and advanced social network analysis. The investment positions the university to serve Arkansas through impactful research and programs. “This level of federal investment affirms the value and impact of the work happening at UA Little Rock,” said Chancellor Christina Drale. “From supporting Arkansas veterans to advancing research in nanotechnology, cybersecurity and data analytics, these appropriations strengthen our ability to serve the state and deliver research that makes a measurable difference for our communities and our country.” The federal funding package includes two direct allocations secured with the help of U.S. Senator John Boozman, who serves on the Senate Appropriations Committee, for the veterans legal clinic and nanotechnology research equipment, in addition to the other investments he and the Arkansas congressional delegation supported for UA Little Rock programs: ● $750,000 to support the Veterans Legal Services Clinic at the William H. Bowen School of Law ● $6 million for nanotechnology initiatives, including: ○ $3 million to enhance nanotechnology research capacity through the purchase of highly specialized, state-of-the-art equipment ○ $3 million specifically for nanomaterials for bone regeneration research ● $5 million to develop a cyber-resilient computing platform in partnership with Montana State University ● $1 million to support COSMOS (social networks analysis) research Veterans Legal Services Clinic The $750,000 appropriation will enhance the Bowen School of Law’s Veterans Legal Services Clinic, which provides free legal assistance to Arkansas veterans while giving law students hands-on experience. To date, the clinic has supported Veterans in two-thirds of Arkansas counties and has secured more than $500,000 in benefits for veterans. With the additional funding, the clinic hopes to secure additional support to serve all Arkansas
May 4, 2026 · via arktimes.com
An active phishing campaign has been observed targeting multiple vectors since at least April 2025 with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUS#HELPER, has impacted over 80 organizations, most of which are in the U.S., according to Securonix. It shares overlaps with clusters previously tracked by Red Canary and Sophos, the latter of which has given it the moniker STAC6405. While it's not clear who is behind the campaign, the cybersecurity company said it aligns with a financially motivated Initial Access Broker (IAB) or a ransomware precursor operation. "In this case, a customized SimpleHelp and ScreenConnect RMMs are used to bypass defenses as they are legitimately installed by the unsuspecting victim," researchers Akshay Gaikwad, Shikha Sangwan, and Aaron Beardslee said in a report shared with The Hacker News. Setting aside the fact that the use of legitimate RMM tools can evade detection, the deployment of both SimpleHelp and ScreenConnect indicates an attempt to create a "redundant dual-channel access architecture" that enables continued operations even when either of them is detected and blocked. It all begins with a phishing email impersonating the U.S. Social Security Administration (SSA), where the recipient is instructed to verify their email address and download a purported SSA statement by clicking on a link embedded in the message. The link points to a legitimate-but-compromised Mexican business website ("gruta.com[.]mx"), indicating a deliberate strategy to evade email spam filters. The "SSA statement" is then downloaded from a second attacker-controlled domain ("server.cubatiendaalimentos.com[.]mx"), an executable that's responsible for delivering the SimpleHelp RMM tool. It's believed that the attacker gained access to a single cPanel user account on the legitimate hosting server to stage the binary. As soon as the victim opens the JWrapper-packaged Windows executable, thinking
May 4, 2026 · via thehackernews.com
Monday, July 9, 2018 2:30 pm
-
2:30 pm
EDT (GMT -04:00)
Seminar • CrySP Speaker Series on Privacy — Where Theory Meets Practice for Privacy Enhancing Technologies
Chelsea Komlo, HashiCorp
Privacy Enhancing Technology communities rely on the research community for help designing and validating protocols, finding potential attack vectors, and applying new technological innovations to existing protocols. However, while the research community has made significant progress studying projects such as Tor, the number of research outcomes that have actually been incorporated into privacy enhancing technologies such as The Tor Project is lower than the number of feasible and useful research outcomes.
May 4, 2026 · via uwaterloo.ca
FinOps for Cybersecurity at Scale: Balancing Cost, Speed, and Safety at HSBC
Overview
| Experience | In Person |
|---|---|
| Track | Cybersecurity |
| Industry | Financial Services |
| Technologies | Unity Catalog, Lakebase |
| Skill Level | Intermediate |
When HSBC's cybersecurity team adopted Databricks to power threat detection and security analytics, we knew scale would come fast. What we didn't anticipate was just how fast, or the cost challenges that would follow. We grew from a small pilot to hundreds of security analysts and data engineers, processing massive volumes of security telemetry data daily.
The challenge: Most of our users could detect cyber threats but didn't know which queries were scanning terabytes unnecessarily or whether cluster configurations were burning through budget. Traditional approaches said costs were rising but couldn't teach us as the users how to use Databricks efficiently. We share an approach that turns every inefficiency into a teaching moment and empowers security teams to self-optimize without becoming data engineering experts. I'll share the framework and automations we used to grow Databricks usage while flattening the cost curve, all while maintaining rapid threat detection capabilities.
Session Speakers
Jonny Leigh
/Architect
HSBC
May 4, 2026 · via databricks.com
Webinar to explore AI use in cybersecurity, health care technology John Riggi, AHA national advisor for cybersecurity and risk, will moderate a webinar May 5 at 1 p.m. ET that will explore how bad actors are leveraging artificial intelligence, emerging risks to watch for, and best practices for responsible AI adoption that will help protect organizations from evolving threats. Scott Trevino, senior vice president of cybersecurity for TRIMEDX, will also provide insight on the evolving threat landscape and practical guidance for organizations. REGISTER NOW Related News Articles Headline The AHA and Joint Commission May 4 announced the launch of the Cyber Resilience Readiness program, an initiative to help hospitals and health systems assess… Headline The Cybersecurity and Infrastructure Security Agency, National Security Agency and international partners have released guidance on adopting agentic artificial… Headline The Food and Drug Administration April 28 announced its plan to advance the implementation of real-time clinical trials, which invite participants to supply… Headline A joint advisory released April 23 from U.S. and international cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency, FBI,… Headline FBI Co-deputy Director Andrew Bailey discussed a rise in cyber and physical threats impacting health care. He discussed health care as the top critical… Headline Jim VandeHei, CEO of Axios; Marc Boom, M.D., AHA board chair and president and CEO of Houston Methodist; Anne Klibanski, M.D., president and CEO of Mass…
May 4, 2026 · via aha.org
AHA, Joint Commission announce cybersecurity readiness effort
The AHA and Joint Commission May 4 announced the launch of the Cyber Resilience Readiness program, an initiative to help hospitals and health systems assess and strengthen their ability to sustain clinical continuity — i.e., safe and quality clinical operations — during cyber-related technology outages for 30 days or longer. The first-of-its-kind program emphasizes real-world operational readiness and patient safety impacts, rather than solely IT recovery. The voluntary program evaluates an organization’s ability to maintain safe patient care during cyber disruptions; coordinate clinical, operational and leadership response during downtime; prepare staff to function effectively during a significant cyber incident; and identify and mitigate risks that post a threat to clinical continuity.
For more information on this or other cyber and risk issues, contact John Riggi, AHA national advisor for cybersecurity and risk, at jriggi@aha.org, or Scott Gee, AHA deputy director for cybersecurity and risk, at sgee@aha.org. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.
May 4, 2026 · via aha.org
Pipelock: Open-source AI agent firewall AI coding agents run with shell access, environment variables containing API keys, and unrestricted internet connectivity, creating a single point of failure where one compromised tool call can leak credentials to an attacker-controlled domain. Pipelock, an open-source security harness developed by Joshua Waldrep under the PipeLab project, addresses this exposure by inserting an enforcement layer between agents and the network. Version 2.3.0 shipped with class-preserving request redaction and generic SSE streaming response scanning. Architecture and scanning pipeline Pipelock runs as a single Go binary of roughly 20 megabytes with 22 dependencies, distributed under the Apache 2.0 license. The design relies on capability separation: the agent process holds the secrets and operates without direct network access, the proxy holds network access and no secrets, and all traffic crosses a scanning boundary between the two zones. Network isolation depends on deployment-level controls such as network namespaces, iptables, Docker internal networks, or Kubernetes NetworkPolicy. Waldrep, the developer behind Pipelock, draws a distinction between the project and the broader category of agent-security tooling. “Most agent-security tools still need the agent to cooperate. They are SDKs, decorators, middleware, or wrapper APIs the agent has to call. Those controls only work while the agent keeps calling them,” he told Help Net Security. He added that a steered or poisoned agent can skip the very controls meant to watch it, which is why Pipelock sits outside the agent at the egress boundary. He compared the arrangement to how TLS handles trust on the web, where the component being verified is separate from the component producing the proof. Every request flows through an 11-layer scanner pipeline covering scheme enforcement, CRLF injection detection, path traversal blocking, domain blocklisting, data loss prevention, path and subdomain entropy analysis, SSRF protection, rate limiting, URL length checks, and
May 4, 2026 · via helpnetsecurity.com
A few weeks ago in these pages I wrote that we had crossed the Rubicon on cyber risk: that the threshold between human-paced attack and machine-paced attack had been crossed by Anthropic’s Mythos. That the model would not stay contained. That OpenAI was close behind.
Within a fortnight, Anthropic confirmed it was investigating reports that unauthorised users had been accessing Mythos Preview through a third-party contractor portal, on the same day the model was announced. The containment that the entire Glasswing access model rested on had failed at the starting gate. Late last week the UK Government’s AI Security Institute confirmed the rest: frontier labs are sprinting, and capability is growing.
May 4, 2026 · via afr.com
The Health Service Executive (HSE) is attempting to restore significant web services more than three months after a cybersecurity event hit subsites for the National Cancer Control Centre (NCCC), the National Ambulance Service (NAS) and Cork University Hospital (CUH) among others. Web pages impacted by what it described as “unexpected activity” on one of the site’s servers were taken down. While work to republish the material had been ongoing since, about 20 per cent of the pages remain unavailable. The pages affected are subsites of HSE.ie and provide information on the operations of, and information on access to, services provided by the specific branch organisations. While some have been restored, including CUH and Cork University Maternity Hospital, those for the NAS, the NCCC, Children First National Office and the Medicine Management Programme are among a significant number still listed as unavailable. READ MORE In a statement, the HSE said its cybersecurity team “detected unexpected activity on one of the web servers that was used to publish HSE publications and web content across a range of topics, as part of their real-time cybersecurity monitoring at the end of January”. The server was managed by an external vendor outside the main HSE network. It said it quickly moved to republish “high-priority content” and most of the information on its new HSE.ie site has now been restored. “Some out-of-date information has not been republished. About 20 per cent of the content is still to be republished,” it said, adding that several additional information websites managed by the vendor were also taken offline. Those included CUH; Cork University Maternity Hospital; understandtogether.ie; sexualhealth.ie; nationalambulanceservice.ie; and ehealthireland.ie. “We are working with the services to make the remaining information available as soon as possible,” the HSE said. The HSE was the victim of a major ransomware attack
May 4, 2026 · via irishtimes.com
Wireshark 4.6.5 Fixes Multiple Security Vulnerabilities & Updates Protocol Support The Wireshark Foundation has announced the release of Wireshark 4.6.5, a critical update to one of the world’s most widely used network protocol analyzers. The latest version delivers a series of important security patches alongside performance improvements and updated protocol support. What is Wireshark? Wireshark is the world’s most popular network protocol analyzer. It is used for troubleshooting, analysis, development and education. Wireshark is used by government agencies, educational institutions, corporations, small businesses and nonprofits alike to troubleshoot network issues. Additionally, Wireshark can be used as a learning tool Cybersecurity professionals often use Wireshark to trace connections, view the contents of suspect network transactions and identify bursts of network traffic. It is a key part of any IT pro’s toolkit - once they have mastered how to use it. Wireshark does three things: Wireshark is used by network administrators, developers, and security professionals globally, playing a central role in monitoring, analyzing, and troubleshooting network traffic. As such, even minor flaws in its processing engine can have significant implications—particularly when vulnerabilities could be exploited through malformed or malicious network data. Protocol Support Wireshark 4.6.5 introduces expanded support across a wide range of protocols. These include AFP, AIN, ANSI_TCAP, ASAM CMP, ATN-ULCS, BEEP, BGP, Bluetooth HCI (including ISO), BT-DHT, CAMEL, ChargingASE, CMIP, COSEM, DAP, Darwin, DCP ETSI, DECT NR+, DISP, DMX, DNS, E1AP, E2AP, F1AP, FC-SWILS, FTAM, GLOW, GNW, GOOSE, and GPRSCDR. Additional protocol updates cover GSM MAP and RP, H.225.0, H.245, H.248, H.450 (including ROS), HNBAP, HTTP/2, ICMPv6, IDMP, IEEE standards such as 1609.2, 1722.1, and 802.11, along with INAP, IPsec, IPv4/IPv6, ISAKMP, ISO 8583, ITS, JSON 3GPP, Kismet, LDAP, LPPa, M2AP, M3AP, MAS-5GS, MBIM, MMS, Modbus, and Monero. The update also extends to protocols such as MySQL, NBAP, NGAP, NRPPa,
May 4, 2026 · via linkedin.com
Naver said on April 30 it held its first "Naver Security Seminar" at its Green Factory headquarters in Seongnam, introducing a range of security technologies designed to protect its services and users. The inaugural seminar was organized to discuss more advanced security strategies with industry experts as security issues become more complex alongside the development of artificial intelligence technologies. The event brought together not only Team Naver security personnel but also IT industry practitioners, developers interested in cybersecurity and students, who shared insights applicable to real-world operations. Team Naver presented its efforts to safeguard services and users, along with various security technologies, through six sessions. Topics included AI red-teaming strategies for building secure large language models, efforts to ensure safe offline payment environments and cloud infrastructure operations, and trends in phishing attacks. Naver also held its "Naver Bug Bounty Awards" offline for the first time, after previously conducting the event online. In 2025, a total of 126 domestic and international security researchers participated in the bug bounty program, submitting 255 reports. As the security quality of Naver's services improved, the number of reported bugs declined 13.8% year on year, while the average remediation period fell 28.5% to 25 days, the company said. Naver added that it paid participants rewards totaling about $33,900 annually, depending on the impact and difficulty of the reported bugs.
May 4, 2026 · via thelec.net
The global shift in the security set-up has metamorphosed from kinetic to intangible digital domains. This vital shift has forced societies to reorient their horizons towards cybersecurity. No sector has been left untouched by this digital revolution. It has become a part of day-to-day life, with devices ranging from mobiles and cars to domestic and office equipment forming part of the Internet of Things (IoT). In the globalised world, cybersecurity has become non-negotiable, and even the slightest compromise can have immense consequences. The Indian government’s move to enforce stringent compliance measures against Chinese CCTVs, such as those from Hikvision and Dahua , has once again drawn attention to all other areas where the Chinese presence is significant. Chinese EVs, therefore, need special attention from the Government of India. Chinese EVs and Global Risks China is a country that smartly turns the tide in its favour. Its vision for future technology is competitive. It has the capacity to sense future market forces and an equally fervent government mechanism that initiates steps with equal zeal to equip China for the changing technological world. The unique feature of China is its spirit to dominate the world and nothing short of that. This means the long-term planning that China enforces is aimed at dominating future forces rather than merely becoming a cog in the wheel. This quality makes China a powerful player in any segment whose time has not even come. Chinese EVs are also not an exception to this. China is well aware that the highest business opportunity lies in the problems faced by people. If the problem is radical in nature and affects the whole of humanity, then the market is not limited to the geographical boundaries of any specific nation, and business opportunities become global. Global warming is a global issue,
May 4, 2026 · via indianarrative.com
IBM security executive emerges as possible contender to lead CISA Tom Parker doesn’t have prior government experience, characteristics the Trump administration may be seeking in its next pick to lead the cyber agency, a person familiar said. Tom Parker, a security services lead at IBM with some two decades of experience in the cybersecurity industry, has emerged as a potential contender to lead the Cybersecurity and Infrastructure Security Agency after the most recent nominee withdrew himself from consideration for the role, according to five people familiar with the matter. Parker does not have prior government experience. As of now, he is the preferred choice for the Trump administration, one of the people said. Homeland Security Secretary Markwayne Mullin has been favoring a CISA director with only private sector experience, another one of the people said. All sources spoke on the condition of anonymity because they weren’t authorized to publicly communicate details concerning the administration’s thinking. Some of the people cautioned that the process is fluid and that the White House may go in a different direction. Parker did not respond to a request for comment. Nextgov/FCW has also asked the White House and DHS for comment. Parker has held a number of roles in industry throughout his career. He founded cyber solutions firm Hubble, which was acquired in 2024. He was also inducted as a technology pioneer at the World Economic Forum, and he has for years been a speaker and panelist at Black Hat, an annual cybersecurity conference held in Las Vegas. CISA has been without a permanent director since President Donald Trump retook office last year. For the last year, Sean Plankey had been nominated to lead the cyberdefense agency, but withdrew late last month after being caught up in issues concerning Coast Guard cutter contracts with a
May 4, 2026 · via nextgov.com
Bessent addressed the issue Sunday (May 3) in an interview with Fox News, coming in the wake of a meeting he and Federal Reserve Chair Jerome Powell held with Wall Street executives on concerns related to Anthropic’s Mythos artificial intelligence model. At the meeting, the officials told banks such as JPMorgan Chase and Bank of America that they should take the Mythos model seriously and use it to find holes in their defenses. “What we’ve had in the past month was a step change in the power of one large language model, but we’re going to see it from the other AI companies, and it’s important that the U.S. stays ahead here,” Bessent said. That means figuring out a “very important calculus” between safety and innovation, he added, without mentioning any specific measures taken by banks or the government. Asked by Fox’s Maria Bartiromo if Americans need to be worried about AI hacking into their bank accounts, Bessent responded with “You should.” Advertisement: Scroll to Continue Anthropic has said Mythos has discovered thousands of high-severity vulnerabilities, including flaws in major operating systems and web browsers. It has led to concerns among businesses and governments around the world about the possibility of AI-powered cyberattacks. “The implications are two-sided,” PYMNTS wrote. “On one hand, defenders such as banks, payment processors and infrastructure providers can use these tools to identify and patch weaknesses. On the other, the same capabilities could be leveraged by hackers, dramatically accelerating the discovery and exploitation of systemic flaws across the financial ecosystem.” And as covered here in an additional report, the newest models from AI leaders like OpenAI and Anthropic could mark a crucial inflection point in the cybersecurity space. “AI is no longer just a tool in the hands of an attacker; it is beginning to replicate
May 4, 2026 · via pymnts.com