No-frills tech news

Cyber Risk for Lawyers: Structuring Your Law Firm's IT for <b>Cybersecurity</b> &amp; Risk

Cyber Risk for Lawyers Structuring Your Law Firm’s IT for Cybersecurity & Risk Chicago, IL | Tuesday, May 19, 2026 | 1 Hour MCLE | Hybrid (In-Person + Zoom) Cyber Risk for Lawyers Overview Date and Time: Tuesday, May 19, 2026, from 12:00 PM to 1:00 PM In-Person: ISBA Mutual Insurance Company, 20 S Clark St #800, Chicago, IL 60603 Remote: Attend via Zoom Cyber threats targeting lawyers continue to evolve, and even small firms are increasingly becoming targets. Building on the issues raised in our recent risk management program, this follow-up session takes a deeper dive into the practical cybersecurity risks facing law practices today. These include email compromise, ransomware demands, and the insurance coverage issues that arise when something goes wrong. On Tuesday, May 19th, ISBA Mutual hosts Cyber Risk for Lawyers: Structuring Your Law Firm’s IT for Cybersecurity & Risk. Most law firms are aware of the cyber risks. Few have a clear framework for structuring their IT systems to manage those risks. This session gives attorneys a practical blueprint for how a modern law firm IT environment should be built, where the risk and liability actually sit, and how cybersecurity and AI fit inside that framework. During the May Cyber Risk for Lawyers session, attendees will gain practical guidance on: How a secure, efficient law firm IT stack should be structured, from endpoints and identity to cloud, backup, and vendor management Where cybersecurity risk and liability actually live in that stack, and who is accountable at each layer How to evaluate your current IT environment against a defensible framework How the most common threats (email compromise, ransomware, wire fraud) map to specific gaps in IT structure, and how proper structure prevents them How AI tools (ChatGPT, Copilot, Claude) should be governed inside a law firm IT

AI, Data, and <b>Cybersecurity</b> Top IT Agendas, but Priorities Diverge by Sector, Info-Tech ...

The pressures shaping IT in 2026 are no longer playing out the same way across industries, making sector-specific prioritization more important for leaders under pressure to deliver results. To help IT leaders and their teams focus their efforts, Info-Tech Research Group has released its Best of Industry 2026 collection, a set of industry-specific reports that brings together the global research and advisory firm's most relevant industry research for education, financial services, professional services, manufacturing, and government. ARLINGTON, Va., April 30, 2026 /CNW/ - As AI adoption, cybersecurity demands, modernization pressures, and data challenges continue to reshape IT in 2026, leaders are finding that the most urgent priorities no longer look the same across sectors. To help IT teams focus their efforts, Info-Tech Research Group has released its Best of Industry 2026 collection, a set of industry-specific reports that brings together the global research and advisory firm's most relevant industry research for education, financial services, professional services, manufacturing, and government. × Javascript is required for you to be able to read premium content. Please enable it in your browser settings. kAm%96 4@==64E:@? 4@??64ED D64E@C\DA64:7:4 AC:@C:E:6D E@ 762EFC65 C6D62C49[ 3=F6AC:?ED[ E@@=D[ 2?5 2?2=JDE 8F:52?46 E92E 96=A =6256CD >@G6 7C@> :56?E:7J:?8 E96 C:89E 7@4FD 2C62D E@ 24E:?8 @? E96>] p4C@DD E96 7:G6 C6A@CED[ C64FCC:?8 E96>6D DF49 2D px[ 4J36CD64FC:EJ[ 52E2[ >@56C?:K2E:@?[ 2?5 5:8:E2= EC2?D7@C>2E:@? C6>2:? 4@?DE2?E[ 3FE E96 @A6C2E:@?2= C62=:E:6D 369:?5 E9@D6 AC:@C:E:6D 5:776C D92CA=J 3J :?5FDECJ]k^Am kAm%92E 5:G6C86?46 :D G:D:3=6 24C@DD E96 C6A@CED[ 7C@> 6?C@==>6?E 564=:?6 2?5 C6DA@?D:3=6 px :? 65F42E:@? E@ 4@DE @AE:>:K2E:@? :? 7:?2?4:2= D6CG:46D[ D6CG:46 56=:G6CJ C6:?G6?E:@? :? AC@76DD:@?2= D6CG:46D[ x?5FDECJ c]_ 2?5 DFAA=J 492:? G:D:3:=:EJ :? >2?F724EFC:?8[ 2?5 244@F?E23:=:EJ 2?5 5:8:E2= D6CG:46 56=:G6CJ :? 8@G6C?>6?E]k^Am kAmQx% =6256CD 2C6 >2?28:?8 >2?J @7 E96 D2>6 AC6DDFC6D :? a_ae[ 3FE E96 AC:@C:E:6D E92E >2EE6C >@DE[ 2?5 E96 H2J E96J ?665 E@

Mythos legend ups <b>cybersecurity</b> stakes

Anthropic's Claude Mythos can identify security flaws in software within hours, flaws that have remained undetected for decades. To spot a vulnerability, however, Mythos must be able to exploit it. Which it also does within hours. This makes it a concerning AI tool if it falls into the wrong hands. Anthropic has prudently decided to release the AI model to a select group of companies that develop critical software. The intention is to patch the digital infrastructure before Mythos becomes publicly available. This, in turn, raises two sets of issues. One, not all digital infrastructure is built by Big Tech. And, two, not every company developing AI cybersecurity tools will be as conscientious as Anthropic. India has built an impressive stack of DPI, and is assessing the new risk environment it faces. GoI, as Nirmala Sitharaman noted last week at the ET Awards for Corporate Excellence, is in talks with the US administration for access to Mythos. India's position is that its digital backbone has a reach comparable to, if not greater than, that of Big Tech firms. However, this stance dilutes Anthropic's original intention of limiting access to a core group. India's argument tends to favour equitable access to cybersecurity tools before Mythos' potential risks are fully mitigated. This represents a balanced approach in an industry divided over whether the model is primarily a security solution or a threat. Regardless of how Mythos evolves, India has begun auditing its cybersecurity requirements. Large enterprises are better equipped to protect themselves. But small firms require a supportive ecosystem to counter AI-driven threats. Regulatory adoption of AI must align with industry deployment to safeguard all stakeholders. A system as significant as UPI requires an adequate response to the evolving cybersecurity landscape. GoI has identified the threat early, and targeted policy intervention could

APRA meets with banks, urges more vigilance against AI-powered hacks

Australia’s prudential regulator has raised the alarm with the big banks, warning of the serious harm that sophisticated AI tools could do to cybersecurity defences and urging them to bolster safeguards around critical systems. In meetings with major banks, the Australian Prudential Regulation Authority told directors it wanted more scrutiny around how artificial intelligence, such as Anthropic’s Claude platform, could change the nature of hacking. Loading...

What Happens When We Disregard ICT4D <b>Cybersecurity</b> Risks

The development sector is proud of what it has built. DHIS2 runs national health information systems in more than 80 countries. CommCare supports community health workers at scale. Safaricom-backed M-Tiba distributed insurance benefits and government health subsidies to millions of Kenyans. These are real achievements. They are also real targets. In October 2025, a threat actor claimed to have stolen more than 2.15 terabytes of data from M-Tiba’s servers, including patients’ names, national ID numbers, dates of birth, phone contacts, medical diagnoses, and billing information, affecting up to 4.8 million users. Kenya’s Office of the Data Protection Commissioner confirmed it had opened an investigation. This happened two months after M-Tiba announced it had received ISO 27001 certification for its information security management. In June 2024, the BlackSuit ransomware group brought down South Africa’s National Health Laboratory Service after a single employee clicked a phishing link. The NHLS runs 265 laboratories serving roughly 80% of South Africa’s population. The attack delayed an estimated 6.3 million blood tests. HIV, TB, and mpox diagnostics stalled. The NHLS later admitted its systems were “in no way geared to counter” the attack. No donor has been held accountable for either failure. No implementing partner has faced a regulatory penalty. The people whose data was exposed had no notification, no legal recourse, and no recourse at all. That is the scandal. Not the breaches. The accountability structure that makes them inevitable. We’ve Known of Cybersecurity Threats for Years. USAID formally recognized cybersecurity as a development challenge in its 2020 Digital Strategy. Its 2023 Cybersecurity Primer stated that every USAID activity and program must consider cybersecurity as a strategic and operational matter. The Principles for Digital Development include a dedicated principle on privacy and security. None of this requires anything. - There is no mandated budget line

ITS America Conference &amp; Expo 2026 Launches <b>Cybersecurity</b> &amp; Data Zone in Detroit

Dedicated exhibit space addresses evolving connected transportation industry and critical data security management needs DETROIT, MI, UNITED STATES, April 29, 2026 /EINPresswire.com/ — ITS America Conference & Expo, organized in partnership by RX Global and ITS America, announces the launch of the Cybersecurity & Data Zone at the June 9-12, 2026 event to address the evolving connected industry and the management of data and cybersecurity. The dedicated space within the Huntington Place Exhibit Hall in Detroit will showcase cutting-edge technologies designed to protect connected vehicles, secure smart infrastructure, and strengthen transportation system resilience. The zone brings together cybersecurity tools, data management solutions, and industry experts, offering attendees direct access to technologies shaping secure and reliable intelligent transportation systems. More than 30 exhibitors focused on Cyber and Digital Security and Data Management and Data Analytics will be part of the event, giving attendees direct access to some of the most recognized names in the field. Among them, Palo Alto Networks brings its AI-driven cybersecurity platforms trusted by more than 70,000 customers worldwide, Flock Safety offers its automated license plate recognition, video surveillance, and other detection systems, and Cisco Systems contributes its globally recognized networking and cybersecurity solutions. “Cybersecurity is a fundamental requirement for the safe deployment of intelligent transportation technologies that connect our vehicles, infrastructure, and data systems,” said Laura Chace, President and CEO, ITS America. “The Cybersecurity & Data Zone represents our industry’s commitment to safe innovation and demonstrates how we can advance transportation technology while maintaining the highest security standards that protect people and the critical infrastructure they use.” As transportation systems become more connected, the need to protect them grows just as fast. Cybersecurity threats targeting vehicles, infrastructure, and data networks pose real risks to public safety and system reliability. The Cybersecurity & Data Zone gives transportation professionals

FTI Consulting Adds 10 Senior Hires to Expand <b>Cybersecurity</b> and Data Privacy Practice

FTI Consulting, Inc. (NYSE: FCN) has made a major investment in its cybersecurity, data privacy and information governance capabilities, appointing 10 senior professionals as client demand rises for cyber risk management and regulatory compliance services. The new hires include five senior managing directors and five managing directors across key U.S. markets, strengthening the firm’s Technology segment as companies confront growing cyber threats, stricter privacy rules and increased scrutiny around artificial intelligence governance. Anthony J. Ferrante, global head of the Cybersecurity practice at FTI Consulting, said organizations are operating in an environment of heightened digital exposure and expanding regulatory complexity. “Organizations are facing unprecedented digital exposure, operational and regulatory complexities and need practical solutions from trusted experts that help reduce risk, strengthen resilience and achieve compliance,” Ferrante said in a statement. The expansion reflects broader market demand for advisory firms that can combine technical cybersecurity expertise with legal, regulatory and operational consulting. Companies increasingly need integrated support spanning breach preparedness, privacy compliance, data governance and AI risk management. Sophie Ross, global chief executive officer of FTI Consulting’s Technology segment, said exponential data growth and evolving regulations are driving demand for faster and more defensible governance solutions. Among the senior managing directors joining the firm is Akshay Dhawan in Washington, D.C., who brings more than two decades of experience in cybersecurity and digital transformation. He will focus on enterprise cybersecurity programs, particularly around cloud environments, AI systems and national security-related regulations. Chicago-based David Manek joins as a senior managing director specializing in privacy and regulatory change management. He is expected to advise clients on laws including the California Consumer Privacy Act, the European Union’s General Data Protection Regulation and the EU AI Act. Matt McClelland, based in Charlotte, adds expertise in information governance and analytics. His work at FTI Consulting will include

Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren't just talking about AI writing better phishing emails anymore. We’re talking about autonomous agents mapping Active Directory and seizing Domain Admin credentials in minutes. The problem? Most defensive workflows still look like this: your CTI team finds a threat, they pass it to the Red Team to test, and eventually, the results reach the Blue Team for patching. This process is full of friction, silos, and delays. The reality is simple: You cannot fight an AI adversary moving at machine speed when your defense moves at the speed of a calendar invite. To bridge this gap, we’re hosting a technical deep dive with the team at Picus Security to unveil a new defensive paradigm: Autonomous Exposure Validation. Register for the Webinar Here ➜ Leading this session are Kevin Cole (VP of Product Marketing) and Gursel Arici (Sr. Director of Solution Architecture) from Picus Security. Together, they bring a unique blend of strategic threat intelligence and deep technical engineering to show you how to flip the script. Here is exactly what you will walk away with: - The Speed Asymmetry: A behind-the-scenes look at the real-world mechanics of how autonomous, AI-driven attacks actually operate. - The Agent Architecture: How to safely automate threat intel ingestion, simulate attacks, and coordinate fixes—without breaking your network. - Breaking the Silos: How to eliminate the slow hand-offs between your CTI, Red, and Blue teams so they work as a single unit. - The "Team Multiplier" Effect: How lean security teams can achieve enterprise-level protection without doubling their headcount. The attackers have already upgraded their toolkits. It’s time for us to do the same. If you

<b>Cybersecurity</b> expert urges more accountability and transparency in the use of AI

Cybersecurity expert urges more accountability and transparency in the use of AI Sign up now: Get ST's newsletters delivered to your inbox - Jeff Moss advocates for increased AI accountability and transparency to mitigate risks, ensuring users are not harmed by its vulnerabilities or exploitation by criminals. - Moss raises ethical concerns about AI's use in warfare, citing the "Where's Daddy?" programme, and warns AI agents could become political without regulation. - To boost cybersecurity, Moss proposes legal "safe harbour" for "white hat" hackers, allowing experts to research critical system vulnerabilities without fear of litigation. AI generated SINGAPORE – When a consumer buys a lock, the seller will highlight only its qualities, as it is not in his interest to talk to the customer about the product’s limitations. But when experts reveal the lock’s vulnerabilities, the consumer will have a different opinion of its worth. This concept also applies to artificial intelligence, said computer and internet security expert Jeff Moss, founder of hacking convention DEF CON. The use of AI is spreading so fast that consumers may neglect to ask how secure it is, with developers extolling only their products’ virtues. To Mr Moss, there must be more accountability and transparency to mitigate the risks associated with the use of AI by ensuring it is not misused or exploited by criminals. He raised his concerns during an interview with The Straits Times on April 29 at the Sands Expo and Convention Centre, where DEF CON is being held in Singapore for the first time. It is running alongside the Milipol TechX Summit (MTX) 2026 from April 28 to 30. Mr Moss, who has held several prominent cybersecurity roles and was part of the technical consulting team of the hit techno-thriller TV series Mr Robot, said it is vital to discuss

Chairmen Garbarino, Moolenaar Announce Joint Investigation into National Security Risks ...

Chairmen Garbarino, Moolenaar Announce Joint Investigation into National Security Risks Posed by PRC AI Models April 29, 2026 WASHINGTON, D.C. –– Today, House Committee on Homeland Security Chairman Andrew R. Garbarino (R-NY) and House Select Committee on China Chairman John Moolenaar (R-MI) announced a joint investigation into the national security and cybersecurity risks posed by the growing adoption of PRC-developed artificial intelligence models, including low-cost, open-weight, and API-accessible systems developed by Chinese companies such as DeepSeek, Alibaba, Moonshot AI, and MiniMax. The investigation comes amid growing concern that PRC-based AI companies are using unauthorized model distillation and other illicit techniques to extract capabilities from leading American frontier models, then repackaging those capabilities into lower-cost models without the same safeguards included in the original American models, which are then marketed or made available to U.S. companies, developers, and consumers. While model distillation can be a legitimate AI development technique, distillation conducted through fraudulent accounts, proxy networks, evasion of access restrictions, or violations of U.S. companies’ terms of service raises serious concerns about model provenance, intellectual property, cybersecurity, and supply-chain risk. Read more in Semafor via Rachyl Jones As an initial step in the probe, the Chairmen sent letters to Anysphere and Airbnb, raising concerns about the companies’ use of or exposure to these risks through PRC-developed AI. The letters also follow an April 2026 memo from the White House Office of Science and Technology Policy warning that foreign entities, primarily based in China, are conducting deliberate, industrial-scale campaigns to distill U.S. frontier AI systems through proxy accounts and other coordinated methods. In the letter to Anysphere, the Chairmen focus on Cursor’s Composer 2 model, which was reportedly built on an open-weight model developed by Moonshot AI, one of the PRC-based companies publicly implicated in large-scale distillation campaigns targeting American AI systems.

SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP's JavaScript and cloud application development ecosystem - - mbt@1.2.48 - @cap-js/db-service@2.10.1 - @cap-js/postgres@2.2.2 - @cap-js/sqlite@2.2.2 "The affected versions introduced new installation-time behavior that was not previously part of these packages' expected functionality," Socket said. "The compromised releases added a preinstall script that acts as a runtime bootstrapper, downloading a platform-specific Bun ZIP from GitHub Releases, extracting it, and immediately executing the extracted Bun binary." "The implementation also follows HTTP redirects without validating the destination and uses PowerShell with -ExecutionPolicy Bypass on Windows, increasing the risk for affected developer and CI/CD environments." Wiz noted that the malicious packages match several features present in previous TeamPCP operations, indicating that the same threat actor is likely behind the latest campaign. The suspicious versions were published on April 29, 2026, between 09:55 UTC and 12:14 UTC. The poisoned packages introduce a new package.json preinstall hook that runs a file named "setup.mjs," which acts as a loader for the Bun JavaScript runtime to execute the credential stealer and propagation framework ("execution.js"). According to Aikido, the malware is designed to harvest local developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud secrets from AWS, Azure, GCP, and Kubernetes. The stolen data is encrypted and exfiltrated to public GitHub repositories created on the victim's own account with the description "A Mini Shai-Hulud has Appeared." As of writing, there are more than 1,100 repositories with descriptions. In addition, the 11.6 MB payload comes with capabilities to self-propagate through developer and release workflows, specifically using

Job dissatisfaction among <b>cybersecurity</b> professionals on the rise | brief

Infosecurity Magazine reports that a significant number of cybersecurity professionals are considering switching careers due to a lack of a pay raise and a sense of not being appreciated at work.Only about half of cyber workers expect their wages to increase in the next 12 months, indicating that the remaining employees are dissatisfied with their career situation, according to the recent Harvey Nash Global Tech Talent & Salary Report. One of the main reasons cited was the lack of investment in cybersecurity despite ongoing incidents of hacking, data breaches, and ransomware attacks, citing the attack on Jaguar Land Rover as an example that affected the UK economy. Only 22% of the companies surveyed confirmed they have invested in this area, which Harvey Nash Chief Information Officer Ankur Anand described as concerning. Employees are urged not to confine themselves to workplaces where they are undervalued, but to look for companies where they can better utilize their skills, as cybersecurity remains highly in demand today. Security Staff Acquisition & Development, Security Strategy, Plan, Budget Job dissatisfaction among cybersecurity professionals on the rise Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds

Nudge Security Appoints <b>Cybersecurity</b> Veteran Patrick Dillon as Chief Revenue Officer

Revenue and go-to-market leader to build on Nudge Security's strong momentum and leadership position as company enters next phase of growth AUSTIN, Texas, April 29, 2026 /PRNewswire/ -- Nudge Security, the leader in SaaS and AI security governance, today announced the appointment of Patrick Dillon as its first Chief Revenue Officer (CRO). In this role, Dillon will drive the company's revenue cycle, accelerate growth, and lead global sales, customer success, and the partner ecosystem. "Modern enterprises are struggling to manage a massive influx of AI tools, SaaS apps, and non-human identities accessing their data," said Russell Spitler, Co-Founder and CEO, Nudge Security. "Our rapid growth reflects the urgent demand for scalable security and governance of workforce AI and SaaS use. Patrick's deep cybersecurity expertise and proven track record in building and scaling technology companies make him the perfect addition to our leadership team as we embark on the next chapter of our expansion." Dillon joins Nudge Security with over two decades of experience architecting go-to-market strategies across cybersecurity, SaaS, and enterprise software. He specializes in scaling organizations from early-stage growth to $150 million, implementing people-first cultures and operational systems necessary for predictable, long-term growth. Most recently, Dillon served as CRO at Airlock Digital, where he led the GTM team and helped scale an Australian cybersecurity company globally. His extensive leadership pedigree also includes senior roles at industry leaders such as Saviynt, BeyondTrust, and Hewlett Packard Enterprise. "I am excited to join the team at Nudge Security," said Dillon. "In a market crowded by the noise of 'AI everywhere,' Nudge Security stands out with a clarifying approach to the attack surface. Effective AI governance begins and ends with visibility. While most legacy solutions are limited to what is inside their known ecosystem, Nudge Security provides the visibility to see what lies

Northwood University earns NSA <b>cybersecurity</b> excellence award | Education | abc12.com

MIDLAND, Mich. (WJRT) - Northwood University has been designated as a National Center of Academic Excellence in Cybersecurity by the National Security Agency, one of the nation's most respected recognitions for cybersecurity education. The designation recognizes accredited institutions that meet rigorous national standards for cybersecurity curriculum, faculty expertise, institutional support and student preparation. For Northwood University, the designation marks the culmination of a yearlong application process and affirms the strength of its Program of Study in Cybersecurity Management. "This National Security Agency designation is a powerful affirmation of Northwood University's commitment to academic excellence, workforce readiness, and the preparation of principled leaders in one of the most critical fields of our time," Academics Vice President and Provost Kristin Stehouwer said. Stehouwer said cybersecurity is essential to the protection of the economy, business continuity and way of life. Northwood is pleased to help prepare graduates who are ready to lead with integrity in this rapidly evolving field that requires technical knowledge, sound judgment, ethical decision-making and an understanding of the business environments cyber professionals are called to protect, she said. The NSA's National Centers of Academic Excellence in Cybersecurity program recognizes institutions that help advance the nation's cybersecurity education pipeline and prepare students with the knowledge and skills needed to protect and defend against cyber threats. CAE-designated institutions undergo an in-depth assessment and must meet rigorous requirements related to curriculum, faculty, institutional practices and cybersecurity education. "The designation announced this week validates both Northwood's Program of Study and Northwood University's broader institutional commitment to cybersecurity education," Academic Dean Stacey Tetloff said. Tetloff said the recognition is the result of sustained work by faculty and academic leadership to build a cybersecurity program that is rigorous, relevant and aligned with national standards. The designation follows the NSA's validation of Northwood's Program of Study

<b>Cybersecurity</b> Hiring Stalls, IT Leaders Face Corporate Pushback

Cybersecurity Hiring Stalls, IT Leaders Face Corporate Pushback The Fortinet 2026 Global Cybersecurity Skills Gap Report identifies a critical shortage of technical talent as a primary driver of enterprise security breaches. While organizations adopt AI for defense, a lack of executive investment and specialized training creates significant financial and strategic risks. Eighty six percent of organizations experienced at least one security breach in previous years, while 49% of information technology leaders face corporate resistance when seeking to hire the talent necessary to mitigate AI-driven threats, reports Fortinet. The rising frequency and sophistication of cyberattacks correlate with a disconnect between board-level risk perception and budgetary allocation: companies are not scaling like cyberthreats are doing. "Cybersecurity is not simply a technical issue but a strategic business risk,” says Carl Windsor, CISO, Fortinet. “While boards generally recognize the importance of cybersecurity, more investment is needed to address key issues, such as rapidly accelerating AI risks and the ongoing cybersecurity skills shortage." The shortage of cybersecurity skills remains a leading cause of devastating security breaches for the third consecutive year. According to Fortinet, 56% of information technology (IT) leaders attribute successful intrusions to a lack of specialized personnel. This deficit occurs during a period of escalating financial consequences for the private sector. Fifty-two percent of organizations report that breaches cost more than US$1 million, which is a notable increase from the 38% reported in 2021. Within North America, the average cost of a breach has reached US$2 million. Organizational friction at the executive level hampers the ability of security teams to defend the enterprise. Although 51% of leaders indicate a requirement for senior-level cybersecurity skills, nearly half struggle to obtain the necessary approval for additional headcounts. This resistance persists despite the direct professional risks to leadership. The report reveals that 50% of executives and

Victor Foulk Discusses Ways to Counter AI-Driven Threats

Federal agencies should focus on strengthening three core cybersecurity functions — zero trust, vulnerability management and incident response — as artificial intelligence accelerates the pace and scale of cyberthreats, according to Victor Foulk, vice president of emerging technologies at CGI Federal. In a blog post on Tuesday, Foulk said AI is enabling adversaries to identify and exploit vulnerabilities faster, turning cybersecurity into a speed-driven operational challenge rather than a strategic shift. Why Is Zero Trust Critical? Foulk pointed to zero trust as the most immediate way to reduce risk, particularly as AI-driven attacks exploit weak identity controls and network segmentation. By enforcing strict identity verification and separating access across systems, zero trust limits the number of reachable targets and reduces the potential impact of a breach. It also improves visibility, making it easier to detect and contain intrusions early. How Should Agencies Approach Vulnerability Management? AI is compressing the timeline between discovering a vulnerability and exploiting it, making rapid prioritization essential. Foulk said agencies should focus on identifying which vulnerabilities pose real risk based on their environment, rather than attempting to remediate everything. This includes evaluating exposure, access paths and privilege levels. He added that when patching is delayed, agencies should rely on compensating controls such as segmentation, access restrictions and targeted monitoring to mitigate risk. What Needs to Change in Incident Response? Incident response must operate faster and with greater precision through automation to prevent threats from escalating. Foulk’s emphasized the importance of early containment, clear response protocols and predefined authorities, noting that agencies should balance speed with accuracy to avoid reacting to false signals while ensuring real threats are addressed quickly. Foulk’s focus on speed and coordination aligns with his previous remarks on the importance of data visibility, which enables faster decision-making and more effective automation while maintaining

Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push

Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single "git push" command. The flaw, tracked as CVE-2026-3854 (CVSS score: 8.7), is a case of command injection that could allow an attacker with push access to a repository to achieve remote code execution on the instance. "During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers," per a GitHub advisory for the vulnerability. "Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values." Google-owned cloud security firm Wiz has been credited with discovering and reporting the issue on March 4, 2026, with GitHub validating and deploying a fix to GitHub.com within two hours. The vulnerability has also been addressed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0, or later. There is no evidence that the issue was ever exploited in a malicious context. According to GitHub, the issue affects GitHub.com, GitHub Enterprise Cloud, GitHub Enterprise Cloud with Data Residency, GitHub Enterprise Cloud with Enterprise Managed Users, and GitHub Enterprise Server. At its core, the problem stems from the fact that user-supplied git push options are not adequately sanitized before the values were incorporated into the internal X-Stat header. Because the internal metadata format relies on a semicolon as a delimiter character that could also appear in the user input, a bad actor could exploit this oversight to inject arbitrary commands and have them executed. "By chaining several injected values together, the researchers demonstrated that an attacker could override the environment the push was processed in, bypass sandboxing protections

DPC Technology Case Study | Huntress

Dental offices are busy places. Computers sit everywhere, from the front desk to the operatory, and people don’t have much time to slow down and think about security. That’s why DPC Technology has worked to make protection part of the job, rather than something clients only think about after a problem pops up. Founded in 1995, DPC Technology built their business around supporting dental practices. CEO Clay Archer grew up around dentistry, and that familiarity shaped the company from the start. DPC understands how dental offices operate, what sets them apart from other businesses, and where small problems tend to escalate into costly ones. That’s why Archer can confidently say, “It’s not so much of a fair fight when we go in to compete against somebody.” Challenge | Too many machines and not enough visibility As DPC moved from break-fix work into managed services, they needed a security model that could hold up across a growing client base. That was especially important in dentistry, where one office can have far more devices than people. Archer says a typical practice may have roughly 1.5 to 1.75 times as many endpoints as humans, which means there are many machines to keep track of and many opportunities for something to fall out of view. This also raises the chances of problems on the user side. “People are just clickers,” says Archer. Before better protections were in place, he explains, dentists were getting hit with ransomware “like crazy.” Therefore, DPC needed a way to reduce that exposure without turning security into a separate debate every time a tool changed. Additionally, Microsoft Defender Antivirus was built into DPC’s clients’ environments. Archer notes that while Defender itself is strong, the problem was that, before Huntress, there was no practical way for DPC to manage it across

&quot;This case is a historic win for our <b>cybersecurity</b> efforts under President Trump.&quot; | Facebook

Explore the things you love . Log into Facebook Email or mobile number Password Log in Forgot password? Create new account English (US) Español Français (France) 中文(简体) العربية Português (Brasil) Italiano More languages… Sign Up Log In Messenger Facebook Lite Video Meta Pay Meta Store Meta Quest Ray-Ban Meta Meta AI Instagram Threads Privacy Policy Consumer Health Privacy Privacy Center About Create ad Create Page Developers Careers Cookies Ad choices Terms Help Contact Uploading & Non-Users Meta © 2026