No-frills tech news

<b>Cybersecurity</b> breach of Gardendale city computer system exposes personal information

Cybersecurity breach of Gardendale city computer system exposes personal information BIRMINGHAM, Ala. (WBRC) - A cyber security breach of the City of Gardendale’s computer system may have exposed some people’s personal information. Several people who live in Gardendale may have recently received a letter in the mail detailing the breach, and recommending next steps to take to protect information. Gardendale Mayor Stan Hogeland confirmed to WBRC Friday that those letters are real, and recipients should take them seriously. According to Mayor Hogeland, the breach was discovered in June 2025, and information that may have been exposed was primarily social security numbers and drivers license numbers. The mayor says his own mother was impacted by the breach. Hogeland went on to say that once the breach was found, the city immediately brought in experts to address the situation, which he describes as a long process, with one of final steps being notification. “They got to figure out where it happened, what was there, and then just trying to isolate that and control it to keep it from going into other areas of your system,” Hogeland said as he described the process. The mayor is urging anyone who received the letter to read it carefully, watch your accounts for any abnormal activity, and consider contacting the service mentioned in the letter which will monitor your credit for free for one year. Mayor Hogeland also confirms that some people who do not live in the city of Gardendale have received a letter, and says he recommends they also carefully read the letter and consider using the service. According to the Hogeland, the city has taken measures to strengthen the security of its system to prevent this from happening again. Get news alerts in the Apple App Store and Google Play Store or subscribe

ABS Acquires RMC Global to Expand <b>Cybersecurity</b> and Risk Services

ABS, through affiliate ABSG Consulting Inc., has acquired RMC Global, adding industrial cybersecurity, risk management and resiliency capabilities as the company expands its consulting platform. The transaction brings together ABS Consulting and RMC Global, a provider of cybersecurity and resilience services focused on critical infrastructure and mission-driven organizations. Financial terms of the acquisition were not disclosed. ABS said the deal strengthens its market position by combining RMC’s specialized expertise with ABS Consulting’s scale, technical resources and global reach. The company expects the acquisition to create a broader suite of integrated services for clients facing rising operational risks, cyber threats and regulatory requirements. ABS Chairman and Chief Executive Officer John McDonald said organizations across industrial sectors are operating in an increasingly complex threat environment. “Clients are facing increasing operational risk, cyber threats, and regulatory pressure,” McDonald said. “Bringing together the expertise of RMC and ABS Consulting strengthens our ability to deliver even greater value and support for our clients through comprehensive, integrated solutions.” He added that the transaction was driven not only by strategic priorities, but also by alignment between the two organizations’ cultures and missions. “ABS and RMC make a strong fit in mission and culture,” McDonald said. “Both organizations are focused on work with real-world impact. Both value expertise, practical problem solving, and long-term trust.” ABS Consulting Chief Executive Officer David Wechsler said the acquisition supports business areas where the company sees sustained demand and long-term expansion opportunities. “This acquisition builds on priority areas where we see sustained client demand and long-term growth opportunity,” Wechsler said. “The combination strengthens our ability to support our customers’ evolving operational risk, cyber threats, and regulatory demands.” RMC President Vince Kuchar said joining ABS will give the business greater scale while preserving its focus on practical solutions for protecting critical infrastructure. “What brought

cPanel 0-day, Swiss Black Axe arrests, HHS data center questions

In today’s cybersecurity news… Critical cPanel and WHM bug exploited as zero-day Experts are warning about a critical CVE numbered (CVE-2026-41940) authentication bypass vulnerability in cPanel, a Linux-based web hosting control panel, as well as WHM, and WP Squared. The bug is being actively exploited in the wild. Hosting provider KnownHost, which uses cPanel, said it noticed successful exploits in the wild on the very day the vulnerability was disclosed. cPanel released a fix on Tuesday, after receiving pressure from hosting providers. According to Rapid7, “Shodan internet scans show that there are approximately 1.5 million cPanel instances exposed online,” but there is no data on how many are vulnerable to this particular bug. Swiss police arrest suspected members of Black Axe group The arrests, made in conjunction with German police, followed house searches across several Swiss cantons. The 10 suspects, believed to be members of the Nigerian gang are aged between 32 and 54, are accused of carrying out romance scams and money-laundering operations. The gang itself, Black Axe, is regarded by law enforcement as “a highly structured transnational criminal organization with a global presence.” Authorities “believe the group has about 30,000 registered members worldwide” and describe it as highly organized. HHS ponders government posture for protecting data centers The question revolves around whether to designate data centers as a standalone critical infrastructure sector. Given that they are regularly targeted, a hearing was held Wednesday to contemplate whether the federal government currently has the right setup for defending them. “Some industry witnesses and experts at the hearing of the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection suggested that data centers be given their own standalone designation, especially in light of the boom in the building of such facilities across the country. This would follow a move already taken

Critical Infrastructure at Risk: Project Glasswing Urges Attention to AI-Driven Cyber-Risks

“Project Glasswing” is a new initiative that should command the immediate attention of every C-suite leader, privacy officer, information security professional, and compliance executive in health care and life sciences, financial services and other critical infrastructure industries, and their legal counsel. Announced in April 2026 by Anthropic, the self-identified “AI safety and research company” best known for its generative artificial intelligence (AI) tool Claude, Project Glasswing reflects a significant development in the cybersecurity landscape. It is a coalition of leading technology and cybersecurity providers united around a single urgent objective: deploying frontier AI capabilities for defensive cybersecurity before malicious actors can exploit similar capabilities offensively to attack first party and open-source software. The project relies on Anthropic’s unreleased Mythos Preview AI model. Seeing the Unseen: Old Susceptibilities Identified The Mythos Preview model and similar autonomous AI capabilities in current and future tools are transforming the cybersecurity risk landscape, given the rapid recent development in and accessibility of AI. According to Anthropic’s announcement, the Mythos Preview model was able to detect thousands of critical, previously unknown security vulnerabilities, including flaws in every major operating system and web browser. These systems are essential to our interconnected electronic systems and ability to communicate securely. Some of those vulnerabilities, according to Anthropic, had survived undetected for decades. The Mythos Preview model is now being deployed as part of Project Glasswing to a select group of organizations, under carefully controlled conditions, to protect the world's most important and foundational software. The initiative explicitly acknowledges, however, that if these capabilities are not harnessed for defense now, they could be weaponized against critical infrastructure, including health care, financial services, and the Internet itself. Although AI-driven threat detection and other defensive platforms are well-established solutions, Project Glasswing foreshadows a new era where autonomous AI becomes a potentially omnipotent

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

CISA Adds One Known Exploited Vulnerability to Catalog CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. - CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information. Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. This product is provided subject to this Notification and this Privacy & Use policy.

CISA, US and International Partners Release Guide to Secure Adoption of Agentic AI

CISA, US and International Partners Release Guide to Secure Adoption of Agentic AI WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA), Australian Signals Directorate’s Australian Cyber Security Centre (ASD ACSC), and other U.S. and international partners published, Careful Adoption of Agentic Artificial Intelligence (AI) Services, a joint guide that presents organizations with the cybersecurity challenges and risks associated with introducing agentic AI along with recommended mitigations. Critical infrastructure and defense sectors are increasingly deploying agentic AI systems to support mission-critical systems and capitalize on significant automation benefits. However, these systems can introduce additional cybersecurity risks, such as an expanded attack surface, privilege creep, behavioral misalignment, and obscure event records. This joint guide provides developers, vendors and operators with best practices for securing agentic AI systems and recommended actions to defend against future risks. “CISA is committed to supporting the US’s adoption of AI that includes ensuring it aligns with President Trump’s Cyber Strategy for America and is cyber secure,” said CISA Acting Director Nick Andersen. “We actively collaborate with government and international partners on shared priorities with AI advancements while addressing cybersecurity challenges and risks. CISA encourages agentic AI developers, vendors and operators to review this guide.” Actionable recommendations for organizations using agentic AI include: - Avoid granting broad or unrestricted access, especially to sensitive data or critical systems - Begin with agentic AI use cases that are low-risk and non-sensitive - Account for agentic AI security in your organization's security model and risk posture For more information, please visit Artificial Intelligence on CISA.gov. ### About CISA As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of

US imposes AI skills requirement on CyberCorps pipeline

US imposes AI skills requirement on CyberCorps pipeline New guidance requires incoming scholars to demonstrate skills at the intersection of AI and cybersecurity, a move that fast-tracks changes outlined in recent National Science Foundation policy. The CyberCorps scholarship program, a recruitment pipeline designed to move qualifying students into government cybersecurity jobs, is overhauling recruitment standards to require that applicants demonstrate skills at the intersection of AI and cybersecurity, according to an email obtained by Nextgov/FCW. New scholars will no longer be accepted into a legacy version of the CyberCorps program without “a description on how they will develop competencies at the intersection of cybersecurity and AI,” according to an email sent Wednesday by the Office of Personnel Management and the National Science Foundation, which says the changes are “effective immediately.” The directive is informed by a February solicitation from NSF that restructured the program to center on artificial intelligence and cybersecurity integration. The email warns that students enrolled today “will not be employable when they graduate in 2-3 years without significant AI background.” There is no single cutoff date for the shift. While the National Science Foundation typically rolls out program changes through new grant cycles, the email’s “effective immediately” directive is significant because it forces that change sooner by applying AI-focused standards to new students entering the pipeline now. Any student in the new program “must be proficient in using AI in cybersecurity or providing security and resilience for AI systems. Therefore, new students in the legacy CyberCorps program must learn to acquire AI expertise to augment their cybersecurity expertise,” the email also says. The revamp comes as companies like Anthropic — which recently unveiled its cyber-focused Mythos model — and OpenAI roll out increasingly advanced AI systems with cybersecurity applications that have caught the attention of the federal

White House questions tech industry on defensive AI use, <b>cybersecurity</b> resilience

The U.S. government wants to know how major U.S. technology companies are using AI to protect their computer networks and how they’re preparing for the possibility of an AI-driven cybersecurity crisis. Officials from the White House’s Office of the National Cyber Director (ONCD) have reached out to tech giants in recent weeks with questions about AI, information sharing, vulnerability patching and how the federal government can help, according to an email and a list of questions shared with Cybersecurity Dive. “The White House continues to proactively engage across government and industry to address several Al/cybersecurity priorities,” Jennifer Belair, the assistant national cyber director for external affairs, said in the April 23 email. “This includes working with frontier AI labs to discuss opportunities for collaboration, as well as shared approaches and protocols to address the challenges associated with scaling this technology. We are grateful for your collaboration to date and believe that your organization has the capabilities and expertise to ensure the United States and Americans are protected.” ONCD asked the companies to answer 11 questions on a range of cybersecurity topics by May 1. A few of the questions are straightforward, such as “Are you currently using Al detection and response tools and services?” and “How are Al models or platforms integrated into your software stack?” But most of the questions are more complicated, such as how quickly companies can identify and fix known vulnerabilities and what barriers they face to improving their cyber posture. Still other questions involve sensitive internal details that companies are unlikely to share. One question asks for a list of the networks, hardware and software that are critical to companies’ continuity of operations, as well as a description of how the companies isolate those systems from their traditional business networks. Another question asks the companies

Microsoft Agent 365, now generally available, expands capabilities and integrations

Microsoft Agent 365 Now generally available for commercial customers. Choose an ecosystem partner for agent security and governance AI agents aren’t coming—they’re already in your environment. They show up in places you expect (like Microsoft Copilot, Microsoft Teams, and Microsoft 365) and even more places as technology evolves (a local autonomous personal AI assistant or a new software as a service (SaaS) agent connected to your sensitive data.) The problem isn’t that agents exist. It’s that they proliferate fast, span apps, endpoints and cloud, and often operate outside the visibility and control of the teams accountable for risk. When an agent can invoke tools, access data, and interact with other agents, any “helpful” workflow can turn into data oversharing, tool misuse, or over-privileged actions in seconds. And as agents become even easier to create and deploy, your attack surface grows with them. That’s why end-to-end observability matters: you can’t govern what you can’t see, and you can’t secure what you don’t understand—especially when the number of agents is a moving target. Microsoft Agent 365 helps you take control of agent sprawl as your control plane to observe, govern, and secure agents and their interactions—including agents built with Microsoft AI and agents from our ecosystem partners—using the admin and security workflows your teams already run. General availability starts today for Agent 365. Additionally, we’re announcing the previews of new Agent 365 capabilities and integrations to help you scale agent adoption with the right controls in place. - Observability, governance, and security for agents operating independently—Agent 365 is expanding to cover agents that operate with their own credentials and permissions. - Discovery of agents and shadow AI, using capabilities of Microsoft Defender and Microsoft Intune for both local and cloud agents. - A secured, managed environment for agents to work in Windows

<b>Cybersecurity</b> Agencies Worldwide Warn About Agentic AI Risks

Companies and governments using AI agents need to anticipate and assess how their use can open them up to risks and affect operations, cybersecurity agencies in the USA, U.K. and Australia warned. Agents that work autonomously can easily be misused and breached by hackers, leading to productivity losses and compromised private information, the Cybersecurity and Infrastructure Security Agency and organizations from other countries warned in a report released Friday. - âEvery individual component in an agentic AI system widens the attack surface, exposing the system to additional avenues of exploitation,â the report said. - The agencies suggested a layered defense for AI ... Learn more about Bloomberg Law or Log In to keep reading: See Breaking News in Context Bloomberg Law provides trusted coverage of current events enhanced with legal analysis. Already a subscriber? Log in to keep reading or access research tools and resources.

Social Engineering Leveled Up. Has Your Security Program? | Huntress

We’ve spent years treating prevention as the endgame: block the attack, and the problem disappears. But that model is starting to break. The environment it was built for no longer exists. Attackers aren’t just finding ways around security controls. They’re running social engineering scams inside them, using the same tools, workflows, and signals against us that we’re supposed to trust. And while attackers have adapted quickly, many security programs haven't kept pace. It's showing up in the data. In a recent report, only 8.9% of teams named phishing and social engineering as their biggest preparedness gap, which means most feel covered. That confidence is the gap. The threat has expanded well beyond what most security programs were built to see into identity abuse, trusted platforms, and the everyday workflows teams already trust. Most teams also reported having adequate budgets and mature tooling. So why do positive outcomes still lag while confidence slips? Teams aren’t behind because they don’t care or don’t work hard. They’re behind because attackers are targeting trust on an unprecedented scale and scope. It’s hitting every aspect of your digital world: identities, AI platforms, developer platforms, business software, and the workflows that keep organizations running. They’re operating in a way that makes social engineering compromise inevitable, not preventable. Resilient teams are recognizing this shift and taking steps toward a security model built for today’s threat landscape. Trust in identities: When "real" isn't real anymore The definition of a "trusted identity" is getting harder to pin down. Deepfakes push attacks well beyond email. Attackers are using AI to impersonate executives, IT staff, and even job candidates. They build rapport over time with cloned voices, then add video to lend credibility to requests that would otherwise raise red flags. That doesn't mean every organization is suddenly facing Hollywood-grade live

Datavault AI and CyberCatch Announce Signing of Binding Letter of Intent for Datavault AI to ...

Datavault AI and CyberCatch Announce Signing of Binding Letter of Intent for Datavault AI to Acquire CyberCatch to Accelerate AI-Driven, Quantum-Resistant Cyber Risk Mitigation Solutions Strategic acquisition is anticipated to position Datavault AI to bring CyberCatch’s AI-enabled cyber risk mitigation solution into Datavault AI’s SanQtum-secured edge Graphics Processing Unit ecosystem, addressing a global information security market projected to reach $240 billion in 2026 (Gartner) CyberCatch’s post-quantum cryptography conversion plan is also expected to position the combined company ahead of the AI-enabled “Q-Day” quantum-attack horizon, now compressed to as early as 2029 (Google) AI-enabled adversary attacks in 2025 rose 89% year-over-year while average eCrime breakout time fell to 29 minutes, a 65% increase in adversary speed compared to 2024, per CrowdStrike’s 2026 Global Threat Report, and Google Quantum AI research has now compressed the timeline for cryptographically relevant quantum computing to as early as 2029. PHILADELPHIA & SAN DIEGO--(BUSINESS WIRE)-- Datavault AI Inc. (“Datavault AI” or the “Company”) (NASDAQ:DVLT), a provider of data monetization, credentialing, digital engagement, and real-world asset (“RWA”) tokenization technologies, and CyberCatch Holdings, Inc. (“CyberCatch”) (TSXV:CYBE) (OTCQB:CYBHF), a cybersecurity company offering a patented, AI-enabled platform for continuous compliance and cyber risk mitigation, today announced they have entered into a binding letter of intent (the “LOI”) under which Datavault AI and CyberCatch will enter into a definitive agreement for Datavault AI to acquire 100% of CyberCatch in an all-stock transaction structured as a court-approved plan of arrangement under the Business Corporations Act (British Columbia). Under the LOI and subject to a definitive agreement, Datavault AI will acquire 100% of CyberCatch’s issued and outstanding common shares (being approximately 26.8 million shares) in exchange for approximately 49.9 million newly issued shares of Datavault AI common stock (the “Datavault AI Shares”) at CAD $5.11 per CyberCatch share, which implies an aggregate value

Name That Toon: Mark of (Security) Progress

Since 2006, Dark Reading has been at the forefront of covering cybersecurity, providing deep insights and analysis beyond the headlines. All those major news events? We were there. Shifts in technology trends? We wrote about them. Enjoy this special anniversary coverage celebrating where we've been and what's next. Name That Toon: Mark of (Security) Progress Feeling creative? Have something to say about the last 20 years of cybersecurity? Our editors will award the best cybersecurity-related caption with a $20 gift card. Dark Reading turned 20 on May 1, and we are celebrating by bringing back the Name That Toon contest. What do you think is happening with those people in the above scene? What were they thinking in 2006? What's happening in 2026? What are they saying to each other? Or is this a game of "Find the Difference" between 2006 and 2026? You tell us! For those of you unfamiliar with the contest, you have a little over three weeks to send us (using the instructions below) your most creative cybersecurity-related caption that you think describes what is happening in this cartoon. A panel of Dark Reading editors will review all submissions and select the winner. We will then republish the cartoon with the winning caption. The winner will get a shout-out from us and also a gift card. There are many different ways to submit your ideas before the May 26 deadline: Email [email protected] with the subject line "Dark Reading 20 Toon." We will reach out to the winner using the platform you contacted us on.

Oregon Tech Students Earn Top Honors at National IT and <b>Cybersecurity</b> Conference

Students from Oregon Tech’s Applied Computing & Geomatics (ACG) Department traveled to Missouri State University this spring to compete in America’s Innovate IT Collegiate Conference (AITCC), a national competition featuring hands-on, real-world challenges in information technology and cybersecurity. Oregon Tech students earned multiple top finishes across several events, including first- and third-place awards. Cybersecurity and Information Technology student participants included Gabriel Dearie, Dominik Kuller, Cole Bentley, Max Espinoza, Uriel Aguilar Torres, and Aiden Kimberling. The students were guided by faculty mentors Praveen Kumar Guraja, Ph.D., Assistant Professor of Cybersecurity & Information Technology, and Manish Nalluri, Visiting Instructor of Cybersecurity & Information Technology. “It is super cool to really test and apply our knowledge and actually see how far we have come,” said Aiden Kimberling. Aiden and teammate Uriel placed first in the Analyze IT Challenge. “In the Analyze IT Challenge, my teammate and I earned first place by applying data analysis, statistical reasoning, and predictive modeling to a real-world dataset. This success was largely due to the strong foundation we built in our Business Analytics and Finance classes, which helped us approach the problem strategically,” said Uriel Aguilar Torres. “Overall, AITCC was a valuable learning experience that helped me better understand my strengths and areas for improvement.” Full results include: - Analyze IT Challenge - 1st Place: Aiden Kimberling and Uriel Aguilar Torres - 3rd Place: Cole Bentley and Dominik Kuller - Cyber Sentinel Challenge (Capture the Flag) - Honorable Mention: Uriel Aguilar Torres and Dominik Kuller, Aiden Kimberling and Max Espinoza (Top 10) - Troubleshoot IT Challenge - Honorable Mention: Cole Bentley (4th Place) “One thing that stood out to me was how fast the field is constantly evolving,” said Dominik Kuller. “It made it clear that cybersecurity isn’t something you can just learn once; you must keep adapting

What is Device Code Phishing?

What is Device Code Phishing? Device code phishing doesn’t hack its way in. It uses a legitimate authentication flow to walk right through the front door, with no password required, MFA bypassed, and session tokens handed straight to the attacker. The Huntress Security Operations Center (SOC) caught it hitting more than 340 organizations in a matter of weeks and immediately cut off the attackers’ access across every partner environment they could reach. Shady? Absolutely. Rare? Not even close. Hit play to see exactly how it works and better defend your identities. “Identity used to be about passwords and MFA. In the cloud, it’s sessions, tokens, and apps — and that’s where most teams are behind.” – Jenko Hwong, Principal Product Researcher, Identity Threat Detection and Response (ITDR) [PH] Learn More About Phishing [PH] Huntress delivers everything you want from a security tool, all designed with the unique needs of outsourced IT and security teams in mind. [PH] Phishing attempts can show up as messages from your bank, your boss, your utility providers, or even the government. One click from one user can compromise an entire network and inadvertently let hackers deploy ransomware, steal information, or worse. [PH] The median time it takes for a user to click a link and enter information is less than 60 seconds. With a turnaround time that quick, it's no wonder phishing is one of the preferred methods used by hackers. (2024 Verizon Data Breach Report)

Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware ...

Press Release Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison For Immediate Release Office of Public Affairs Two American cybersecurity professionals were sentenced today to four years each in prison for their role in a conspiracy to obstruct, delay, or affect commerce through extortion in connection with ransomware attacks occurring in 2023. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were sentenced. According to court documents, they and another co-conspirator, Angelo Martino, 41, of Florida, successfully deployed the ransomware known as ALPHV BlackCat between April 2023 and December 2023 against multiple victims located throughout the United States. The three men agreed to pay the ALPHV BlackCat administrators a 20% share of any ransoms received in exchange for access to the ransomware and ALPHV BlackCat’s extortion platform. All three men worked in the cybersecurity industry — meaning that they had special skills and experience in securing computer systems against harm, including the type of harm they themselves were committing against the victims in this case. After successfully extorting one victim for approximately $1.2 million in Bitcoin, the men split their 80% share of this ransom three ways and laundered the funds through various means. According to court documents, ALPHV BlackCat targeted the computer networks of more than 1,000 victims around the world. The group used a ransomware-as-a-service model in which developers were responsible for creating and updating ransomware and for maintaining the illicit internet infrastructure. Affiliates were responsible for identifying and attacking high-value victim institutions with the ransomware. After a victim paid, developers and affiliates shared the ransom. “The court’s sentences today reflect the damage that these defendants inflicted during their cyberattacks on victim companies throughout the United States,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division.

<b>Cybersecurity's</b> A.I. Problem Isn't Technology. It's Human.

Artificial intelligence is not new to cybersecurity. The sector is one of A.I.’s earliest adopters. For years, defensive cybersecurity has relied on machine learning to identify anomalies, detect patterns and respond to threats with speed and precision beyond any human capability. What is new is the speed, scale and accessibility of A.I., and the way it is reshaping not just our defenses, but the very nature of cyber risk itself. On April 7, Anthropic sent shockwaves through industries when it announced that its latest model, Claude Mythos, was too powerful to release publicly because of its exceptional ability to identify and exploit software vulnerabilities. The company instead opted to provide controlled access to select businesses, including JPMorgan, Apple, Nvidia and Google, to strengthen their cybersecurity defenses. The move underscored a growing reality that the same systems designed to protect can just as easily be weaponized. The uncomfortable truth is that while A.I. is accelerating both offensive and defensive capabilities, threat actors are proving equally, if not more, innovative. Technology alone won’t bridge the capability gap. Instead, leadership, talent generation and training need to keep pace with this revolutionary shift in technology. The new offense: faster, smarter and more personal For decades, cyberattacks followed a familiar pattern. Phishing emails were often clumsy, riddled with grammatical errors and relatively easy to spot. Think the infamous “Nigerian prince” scams. That era is over. A.I. has fundamentally changed the precision and economics of cybercrime. It allows bad actors to operate with unprecedented speed and sophistication. Cyberattacks have always been, in part, a numbers game—like trying every door and window in a neighborhood until one is unlocked. A.I. simply allows attackers to try exponentially more doors at near light speed. It also acts as a force multiplier for low-skilled actors, simplifying the creation of malware

Pine Bluff School District scammed out of more than $3.2 million after <b>cybersecurity</b> hack

Pine Bluff School District scammed out of more than $3.2 million after cybersecurity hack LITTLE ROCK (KATV) — On Monday, Dr. Jennifer Barbaree, Superintendent of the Pine Bluff School District, announced the district fell victim to a serious cybercrime that scammed the district out of more than $3.2 million. "On December 17, the District processed a wire transfer in the amount of $3,204,639.55 for what was believed to be a legitimate invoice from a trusted construction vendor as part of the District's ongoing construction projects," the statement read. The statement also adds that the Director of Finance contacted the vendor to confirm the receipt of the payment and learned that the company sent the invoice for construction services rendered, but the company did not request the invoice to be paid via wire transfer. At this point, it was revealed the district was subjected to a "sophisticated" cyberattack. According to the statement, a district employee's email account was compromised. Although a legitimate invoice had been received, fraudulent wiring instructions were introduced in the same email thread through a phishing scheme designed to mimic authentic communications. Officials said they were directed to maintain strict confidentiality, which is why this information was not previously released to the public. "Sharing details publicly at that time could have compromised the investigation and potentially hindered efforts to recover the funds by law enforcement. For that reason, we were not able to provide updates sooner." A federal investigation has been underway, and school officials have been informed that the investigation is "largely complete." "Encouragingly, a substantial portion of the funds are expected to be recovered," Barbaree said. "While the exact amount has not yet been finalized by authorities, we anticipate receiving a detailed update on restitution in the coming weeks." The District also filed a claim with

Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber

Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber In this latest installment of the Reporters' Notebook video series, we discuss how the new AI model threatens to completely upend cybersecurity, and what industry leaders are telling the press. On April 7, Anthropic announced that its latest version of the large language model (LLM) Claude, dubbed Mythos, was here and displaying a shocking ability to find and exploit software vulnerabilities at machine, even industrialized speed. The implications of an AI red teamer on the loose, accessible potentially to threat actors, and able to be turned against any system in the world in an instant, has inspired alarm for governments and around the cybersecurity sector. According to Anthropic, the Claude Mythos model can find and exploit zero-day bugs in "every major operating system and every major Web browser." To prove the point, the company said the model was quickly able to identify a 27-year-old flaw in OpenBSD. Enter Project Glasswing: A consortium of some of the biggest software providers in the world who will endeavor to use the model for cybersecurity defense first, putting it to work on their software before adversaries can get a hold of the tool. Three reporters, Dark Reading's Becky Bracken, Cybersecurity Dive’s Eric Geller, and TechTarget SearchSecurity’s Phil Sweeney, open up their notebooks and share what their top sources are saying in reaction to reports that Anthropic’s Mythos can find and exploit vulnerabilities at machine speed. They also cover the consortium of software power players that have come together to test Mythos under Project Glasswing. Learn more in the video, and also check out our Reporters' Notebook full series, which is designed to bring together insights and coverage from across Informa TechTarget's network of cybersecurity sister sites. Becky Bracken, Phil Sweeney & Eric Geller: Full

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct credential theft. According to Aikido Security, OX Security, Socket, and StepSecurity, the two malicious versions are versions 2.6.2 and 2.6.3, both of which were published on April 30, 2026. The campaign is assessed to be an extension of the Mini Shai-Hulud supply chain incident that targeted SAP-related npm packages on Wednesday. As of writing, the project has been quarantined by the administrators of the Python Package Index (PyPI) repository. PyTorch Lightning is an open-source Python framework that provides a high-level interface for PyTorch. The open-source project has more than 31,100 stars on GitHub. "The malicious package includes a hidden _runtime directory containing a downloader and an obfuscated JavaScript payload," Socket said. "The execution chain runs automatically when the lightning module is imported, requiring no additional user action after installation and import." The attack chain paves the way for a Python script ("start.py"), which downloads and executes the Bun JavaScript runtime, and then uses it to run an 11MB obfuscated malicious payload ("router_runtime.js") with an aimto conduct comprehensive credential theft. From among the harvested credentials, the GitHub tokens are validated against the "api.github[.]com/user" endpoint before being used to inject a worm-like payload to up to 50 branches retrieved from every repository the token can write to. "The operation is an upsert: it creates files that do not yet exist and silently overwrites files that do," Socket added. "No pre-check for existing content is performed. Every poisoned commit is authored using a hardcoded identity designed to impersonate Anthropic's Claude Code." Separately, the malware implements an npm-based propagation vector that modifies the developer's local npm packages with a postinstall hook in the "package.json" file to invoke the malicious