The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a recently disclosed security flaw impacting various Linux distributions to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The vulnerability, tracked as CVE-2026-31431 (CVSS score: 7.8), is a case of local privilege escalation (LPE) flaw that could allow an unprivileged local user to obtain root. The nine-year-old flaw is also tracked as Copy Fail by Theori and Xint. Fixes have been made available in Linux kernel versions 6.18.22, 6.19.12, and 7.0. "Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation," CISA said in an advisory. In a write-up published earlier this week, the researchers said Copy Fail is the result of a logic bug in the Linux kernel's authentication cryptographic template that allows an attacker to reliably trigger privilege escalation trivially by means of a 732-byte Python-based exploit. It was introduced through three separate, individually harmless changes to the Linux kernel made in 2011, 2015, and 2017. The high-severity security vulnerability impacts Linux distributions shipped since 2017, and permits an unprivileged local user to obtain root-level access by corrupting the kernel's in-memory page cache of any readable file, including setuid binaries. This corruption could be carried out by unprivileged users and could result in code execution with root permissions. "Because the page cache represents the in-memory version of executables, modifying it effectively alters binaries at execution time without touching disk," Google-owned Wiz said. "This enables attackers to inject code into privileged binaries (e.g., /usr/bin/su) and thereby gain root privileges." The prevalence of Linux in cloud environments means the vulnerability has a significant impact. Kaspersky, in its analysis of the flaw, said Copy Fail poses a serious risk to containerized environments, as Docker, LXC, and Kubernetes "grant
May 3, 2026 · via thehackernews.com
Cybersecurity researchers at Guardio Labs have discovered a massive phishing operation that uses Google’s own infrastructure to hijack Facebook accounts. This research reveals a Vietnamese-linked operation code-named AccountDumpling that has already compromised over 30,000 users globally. AppSheet Abuse Guardio Labs researchers explained in the report that this campaign abuses the notification system of Google AppSheets (a no-code tool designed for business automation). By using this service, hackers send emails from [email protected] and appsheet.bounces.google.com. These emails originate from Google’s servers, and that’s why passing the authentication checks like SPF, DKIM, and DMARC becomes possible. Researchers noted that the phishing lures involve Meta-related themes. Such as fake copyright complaints or account disablement warnings. One email from April 2026 included the text “Case ID: 6480258166” and warned of permanent disablement within 24 hours. Technical Methods and Attack Clusters Researchers noted that this isn’t just one simple trick. The operation is split into different methods, or clusters, to catch different types of victims: - Cluster A- Netlify Clones: Some attackers used a tool called HTTrack to copy the Facebook Help Centre. They hosted these on Netlify to steal passwords and photos of government IDs. - Cluster B- The Reward Trap: Another group used social engineering to lure users, such as by promising Blue Badge verification. They used zero-font tactics like Cyrillic homoglyphs (a Cyrillic “а” instead of a Latin “a”) and hair spaces (invisible Unicode characters) to bypass spam filters. - Cluster C- Live Control: This cluster is the scariest as it is highly advanced. It uses a Google Drive-hosted PDF and Socket IO and WebSockets to create a live operator panel. When the victim clicks on it, the hackers can interact with the victims in real-time to request 2FA (two-factor authentication) codes. - Cluster D: This involves fake job recruitment for brands
May 3, 2026 · via hackread.com
Mitchell County closes probe into Oct. 2025 cyberattack, confirms data theft
MITCHELL COUNTY, N.C. (WLOS) — Mitchell County, N.C., has wrapped up its investigation into an October 2025 ransomware attack.
Officials say cybercriminals accessed systems for several days and took sensitive data, including personal, financial, and health information.
For some, biometric information and/or an online account name and password information were impacted.
The county says it’s now notifying those affected and working with federal and state cybersecurity teams.
BE THE FIRST TO COMMENT
Officials urge folks to monitor their accounts and report any suspicious activity.
NEWS IN PHOTOS:
"Local"4
Cheers! New Belgium Brewing celebrates 10 years in Asheville
3
Nationwide service, local smiles: VFW Day of Service brings veterans together
4
Frost advisory issued for most of western NC; Avery County under freeze warning
3
First Friday Art Walk returns to Asheville for 2026 season, aiming to boost foot traffic
May 3, 2026 · via wlos.com
Two cybersecurity professionals have netted themselves four years in prison for carrying out ransomware attacks linked to ALPHV BlackCat, including extorting one victim for around $1.2 million in cryptocurrency. Ryan Clifford Goldberg and Kevin Tyler Martin both held senior roles in the cybersecurity industry: Goldberg was an incident response supervisor at global cybersecurity firm Sygnia, while Martin served as a ransomware threat negotiator at Chicago-based fintech firm DigitalMint. Together with their co-conspirator, Angelo Martino (who also had cybersecurity skills), they deployed ALPHV BlackCat ransomware between April 2023 and December 2023 against multiple US victims. The group agreed to give ALPHV BlackCat operators a 20% cut of any ransoms in exchange for access to the ransomware and its extortion platform. After extorting a single victim for around $1.2 million in Bitcoin, the attackers split their 80% ransom share and laundered the proceeds. Martino, who abused his role as a negotiator by sharing confidential victim information, is scheduled to be sentenced on July 9th. Strong password generator “The court’s sentences today reflect the damage that these defendants inflicted during their cyberattacks on victim companies throughout the United States,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “They harmed important firms who were providing medical and engineering services. They played hardball with them, going so far as to cause the leak of patient data from a doctor’s office victim. They also split the ransoms they were paid, and laundered the illicit proceeds.” Back in December 2023, the FBI developed a decryption tool that could unlock infected systems to disrupt ALPHV BlackCat ransomware, saving victims approximately $99 million. The FBI also took down several websites operated by the criminals. Court documents say that the group targeted over 1,000 victims globally. Your email address will not be published. Required fields
May 3, 2026 · via cybernews.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
May 3, 2026 · via youtube.com
United States, 2nd May 2026 – Zevonix, a managed IT services and cybersecurity company based in Palm Coast, Florida, is expanding its support for small and midsized businesses across Palm Coast , Daytona Beach , St. Augustine , Jacksonville , and surrounding communities. The company helps business owners simplify technology, improve cybersecurity, reduce downtime, and build smarter IT systems that support long-term growth. As more businesses depend on cloud tools, remote access, Microsoft 365, online payments, client portals, and digital workflows, reliable IT support has become a critical part of daily operations. Zevonix provides managed IT services designed to help businesses stay protected, productive, and prepared. × Javascript is required for you to be able to read premium content. Please enable it in your browser settings. kAm“|@DE 3FD:?6DD @H?6CD 5@ ?@E H2?E >@C6 E649?@=@8J AC@3=6>D] %96J H2?E E96:C DJDE6>D E@ H@C<[ E96:C 52E2 AC@E64E65[ 2?5 E96:C E62> 23=6 E@ 86E E9:?8D 5@?6[” D2:5 !2EC:4< s@>:?8F6D[ rt~ 2?5 u@F?56C @7 +6G@?:I] “~FC 8@2= :D E@ >2<6 x% 766= =6DD @G6CH96=>:?8 2?5 >@C6 FD67F=] (6 96=A 3FD:?6DD6D >@G6 7C@> C624E:G6 E649?@=@8J AC@3=6>D E@ 2 D>2CE6C[ >@C6 D64FC6 x% DEC2E68J]”k^Am kAm+6G@?:I AC@G:56D 2 H:56 C2?86 @7 x% D6CG:46D[ :?4=F5:?8 >2?2865 x% DFAA@CE[ 4J36CD64FC:EJ D6CG:46D[ |:4C@D@7E bed >2?286>6?E[ 4=@F5 DFAA@CE[ H@C<DE2E:@? 2?5 D6CG6C >@?:E@C:?8[ 324<FA A=2??:?8[ ?6EH@C< DFAA@CE[ H63D:E6 D64FC:EJ[ 2?5 3FD:?6DD E649?@=@8J 4@?DF=E:?8] %96 4@>A2?J 2=D@ 96=AD @C82?:K2E:@?D 6G2=F2E6 E96:C 4FCC6?E E649?@=@8J D6EFA 2?5 :56?E:7J 82AD E92E 4@F=5 =625 E@ 5@H?E:>6[ D64FC:EJ C:D<D[ @C @A6C2E:@?2= :?677:4:6?4:6D]k^Am kAmp <6J A2CE @7 +6G@?:I’D 2AAC@249 :D :ED “!2E9H2J E@ $>2CE6C x%” 7C2>6H@C<[ H9:49 7@4FD6D @? 5:D4@G6CJ[ E2:=@C65 D@=FE:@?D[ :>A=6>6?E2E:@?[ DFAA@CE[ D64FC:EJ[ 2?5 8C@HE9] %9:D DECF4EFC65 AC@46DD 96=AD 3FD:?6DD6D F?56CDE2?5 H96C6 E96J 2C6 E@52J[ H92E C:D<D ?665 2EE6?E:@?[ 2?5 9@H E649?@=@8J 42? 36EE6C DFAA@CE E96:C 8@2=D]k^Am kAmu@C >2?J D>2== 3FD:?6DD6D[ 4J36CD64FC:EJ 92D 364@>6 @?6 @7 E96 >@DE
May 2, 2026 · via mydailyrecord.com
Zevonix Expands Managed IT and Cybersecurity Services for Growing Businesses Across Northeast Florida United States, 2nd May 2026 - Zevonix, a managed IT services and cybersecurity company based in Palm Coast, Florida, is expanding its support for small and midsized businesses across Palm Coast, Daytona Beach, St. Augustine, Jacksonville, and surrounding communities. The company helps business owners simplify technology, improve cybersecurity, reduce downtime, and build smarter IT systems that support long-term growth.As more businesses depend on cloud tools, remote access, Microsoft 365, online payments, client portals, and digital workflows, reliable IT support has become a critical part of daily operations. Zevonix provides managed IT services designed to help businesses stay protected, productive, and prepared. "Most business owners do not want more technology problems. They want their systems to work, their data protected, and their team able to get things done," said Patrick Domingues, CEO and Founder of Zevonix. "Our goal is to make IT feel less overwhelming and more useful. We help businesses move from reactive technology problems to a smarter, more secure IT strategy." Zevonix provides a wide range of IT services, including managed IT support, cybersecurity services, Microsoft 365 management, cloud support, workstation and server monitoring, backup planning, network support, website security, and business technology consulting. The company also helps organizations evaluate their current technology setup and identify gaps that could lead to downtime, security risks, or operational inefficiencies. A key part of Zevonix's approach is its "Pathway to Smarter IT" framework, which focuses on discovery, tailored solutions, implementation, support, security, and growth. This structured process helps businesses understand where they are today, what risks need attention, and how technology can better support their goals. For many small businesses, cybersecurity has become one of the most urgent concerns. Phishing attacks, ransomware, weak passwords, unmanaged devices, outdated systems, and
May 2, 2026 · via openpr.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
May 2, 2026 · via youtube.com
Cryptika quickly earned reputation for firsts. We were the first to provide our business customers with industry's first integrated, end-to-end security operations and response services. Assisting our customers evaluating their IT related business risks, building and improving IT security strategies, designing infrastructures, implementing international security standards such as the ISO 27k ISMS, PCI-DSS, and SWIFT CSP. Cryptika goes beyond business level and management systems, where we evaluate and audit our customers environments at the IT systems, infrastructure and business applications level by providing penetration testing, vulnerabilities assessments, security architecture review services. We’re delivering a new approach in cybersecurity, purposely designed to protect your organization from the most advanced cyber-attacks. Our pioneering approach to threat hunting and response has been rigorously tested and proven by highly regarded third-party industry analysts. We believe standing up for our values is the highest form of honor. We assist our customers in operating and maintaining their IT assets and applications with full discretion, prudence and diligence - both financial and technical. Our strength is in our ability to carter to our clients’ varied needs and provide a highly competitive procurement management service. Our aim is to keep you at the forefront of technology securely and economically. Whether you are looking for advice, testing or auditing services, it is our job as information risk, security and compliance specialized firm to keep our customers protected in today's dynamic risk environment. Our elite team, experience and proven approach keeps you protected with future-proofed advice delivered in plain English. By thinking outside the box, and keeping up to date with all the latest industry developments, we ensure we keep you one step ahead of the cyber threats and vulnerabilities. Vulnerabilities Assessment & Penetration Testing (VAPT) VAPT helps protecting businesses by exposing weaknesses that provide an alternative route to sensitive
May 2, 2026 · via cryptika.com
Financial infrastructure: Aurangzeb stresses need to strengthen cybersecurity ISLAMABAD: Federal Minister for Finance and Revenue Senator Muhammad Aurangzeb here on Saturday said that strengthening cybersecurity is integral not only to protecting financial infrastructure but also to supporting Pakistan’s broader digital transformation and economic development objectives. The minister chaired a virtual meeting with Presidents and Chief Executive Officers of commercial banks, along with their Chief Information Security Officers (CISOs), said a press release issued by the Ministry of Finance. The meeting focused on enhancing cybersecurity preparedness across Pakistan’s financial sector in light of emerging technological risks and evolving threat dynamics. READ ALSO: Survey finds gaps in corporate cybersecurity policies Welcoming the participants, the Finance Minister appreciated the active engagement of financial institutions, regulators, and technical experts, and underscored the importance of coordinated efforts to safeguard critical financial infrastructure. He emphasised that as Pakistan’s financial ecosystem continues to digitise, strengthening cyber resilience must remain a central policy priority. A detailed presentation was delivered outlining the evolving cyber threat landscape, including the growing sophistication of AI-enabled cyber tools capable of identifying vulnerabilities, developing exploits, and executing multi-stage attacks at unprecedented speed. The presentation highlighted potential exposure across digital banking channels, payment systems, and core financial infrastructure, while emphasising the need for enhanced vigilance and preparedness. The discussion also drew on international experiences, noting recent cyber risk trends in countries such as Japan and India, where financial ecosystems have faced increasing exposure to attacks targeting digital payment platforms and interconnected systems. The participants observed that these developments offer valuable lessons for strengthening Pakistan’s defensive capabilities and institutional readiness. Participants were also apprised of evolving international policy responses to emerging AI-driven cyber risks. It was noted that finance ministries and central banks globally are increasingly treating such developments as high-priority systemic concerns, engaging through coordinated
May 2, 2026 · via brecorder.com
The European Commission’s proposed revision of its Cybersecurity Act, unveiled on Jan. 20 in Strasbourg, marks a turning point in its approach to Chinese technology suppliers. The draft regulation creates, for the first time, a legal framework empowering the commission to designate “third countries posing cybersecurity concerns” and to classify their suppliers as “high-risk.” Although the text never names China, Huawei, or ZTE, its enforcement would result in the gradual exclusion of Chinese equipment from the bloc’s mobile, fixed, and satellite networks. The new architecture allows Brussels to override the reservations of capitals that have so far resisted excluding Chinese suppliers from their networks. A ‘European Awakening’ Emmanuel Lincot, sinologist, professor at the Catholic Institute of Paris, and senior research fellow at the Institute for International and Strategic Relations, said that the regulation reflects a strategic posture in Brussels.“It is a good measure, and it was time,” he told The Epoch Times in an interview. “Many experts have long argued, with reason, that there was a danger in resorting to Huawei, whose intentions are not necessarily benevolent,” he said. “This measure amounts to telling them: recess is over, we are not fooled, go home or change your attitude.” Lincot reads the new approach as part of a broader trend. “This protectionist measure is part of an awakening of a true European identity,” he said. “The war in Ukraine was the catalyst.” The sinologist emphasized that a growing number of member states are also “getting wary” of the “Chinese project,” noting that the new Silk Roads were “not only an infrastructure project; they are also a digital project.” Europe is engaged in an economic war with China, Lincot said. “We are clearly in a logic of economic war against a backdrop of strong ideological rivalries,” he said. On sensitive subjects, the
May 2, 2026 · via ntd.com
Summary The meeting focused on enhancing cybersecurity preparedness across Pakistan’s financial sector in light of emerging technological risks and evolving threat dynamics. ISLAMABAD (APP) - Federal Minister for Finance and Revenue Senator Muhammad Aurangzeb here on Saturday said that strengthening cybersecurity is integral not only to protecting financial infrastructure but also to supporting Pakistan’s broader digital transformation and economic development objectives. The minister chaired a virtual meeting with Presidents and Chief Executive Officers of commercial banks, along with their Chief Information Security Officers (CISOs), said a press release issued by the Ministry of Finance. The meeting focused on enhancing cybersecurity preparedness across Pakistan’s financial sector in light of emerging technological risks and evolving threat dynamics. Welcoming the participants, the Finance Minister appreciated the active engagement of financial institutions, regulators, and technical experts, and underscored the importance of coordinated efforts to safeguard critical financial infrastructure. He emphasized that as Pakistan’s financial ecosystem continues to digitize, strengthening cyber resilience must remain a central policy priority. A detailed presentation was delivered outlining the evolving cyber threat landscape, including the growing sophistication of AI-enabled cyber tools capable of identifying vulnerabilities, developing exploits, and executing multi-stage attacks at unprecedented speed. The presentation highlighted potential exposure across digital banking channels, payment systems, and core financial infrastructure, while emphasizing the need for enhanced vigilance and preparedness. The discussion also drew on international experiences, noting recent cyber risk trends in countries such as Japan and India, where financial ecosystems have faced increasing exposure to attacks targeting digital payment platforms and interconnected systems. The participants observed that these developments offer valuable lessons for strengthening Pakistan’s defensive capabilities and institutional readiness. Participants were also apprised of evolving international policy responses to emerging AI-driven cyber risks. It was noted that finance ministries and central banks globally are increasingly treating such developments
May 2, 2026 · via dunyanews.tv
Cybersecurity breach of Gardendale city computer system exposes personal information BIRMINGHAM, Ala. (WBRC) - A cyber security breach of the City of Gardendale’s computer system may have exposed some people’s personal information. Several people who live in Gardendale may have recently received a letter in the mail detailing the breach, and recommending next steps to take to protect information. Gardendale Mayor Stan Hogeland confirmed to WBRC Friday that those letters are real, and recipients should take them seriously. According to Mayor Hogeland, the breach was discovered in June 2025, and information that may have been exposed was primarily social security numbers and drivers license numbers. The mayor says his own mother was impacted by the breach. Hogeland went on to say that once the breach was found, the city immediately brought in experts to address the situation, which he describes as a long process, with one of final steps being notification. “They got to figure out where it happened, what was there, and then just trying to isolate that and control it to keep it from going into other areas of your system,” Hogeland said as he described the process. The mayor is urging anyone who received the letter to read it carefully, watch your accounts for any abnormal activity, and consider contacting the service mentioned in the letter which will monitor your credit for free for one year. Mayor Hogeland also confirms that some people who do not live in the city of Gardendale have received a letter, and says he recommends they also carefully read the letter and consider using the service. According to the Hogeland, the city has taken measures to strengthen the security of its system to prevent this from happening again. Get news alerts in the Apple App Store and Google Play Store or subscribe
May 2, 2026 · via wbrc.com
ABS, through affiliate ABSG Consulting Inc., has acquired RMC Global, adding industrial cybersecurity, risk management and resiliency capabilities as the company expands its consulting platform. The transaction brings together ABS Consulting and RMC Global, a provider of cybersecurity and resilience services focused on critical infrastructure and mission-driven organizations. Financial terms of the acquisition were not disclosed. ABS said the deal strengthens its market position by combining RMC’s specialized expertise with ABS Consulting’s scale, technical resources and global reach. The company expects the acquisition to create a broader suite of integrated services for clients facing rising operational risks, cyber threats and regulatory requirements. ABS Chairman and Chief Executive Officer John McDonald said organizations across industrial sectors are operating in an increasingly complex threat environment. “Clients are facing increasing operational risk, cyber threats, and regulatory pressure,” McDonald said. “Bringing together the expertise of RMC and ABS Consulting strengthens our ability to deliver even greater value and support for our clients through comprehensive, integrated solutions.” He added that the transaction was driven not only by strategic priorities, but also by alignment between the two organizations’ cultures and missions. “ABS and RMC make a strong fit in mission and culture,” McDonald said. “Both organizations are focused on work with real-world impact. Both value expertise, practical problem solving, and long-term trust.” ABS Consulting Chief Executive Officer David Wechsler said the acquisition supports business areas where the company sees sustained demand and long-term expansion opportunities. “This acquisition builds on priority areas where we see sustained client demand and long-term growth opportunity,” Wechsler said. “The combination strengthens our ability to support our customers’ evolving operational risk, cyber threats, and regulatory demands.” RMC President Vince Kuchar said joining ABS will give the business greater scale while preserving its focus on practical solutions for protecting critical infrastructure. “What brought
May 2, 2026 · via citybiz.co
In today’s cybersecurity news… Critical cPanel and WHM bug exploited as zero-day Experts are warning about a critical CVE numbered (CVE-2026-41940) authentication bypass vulnerability in cPanel, a Linux-based web hosting control panel, as well as WHM, and WP Squared. The bug is being actively exploited in the wild. Hosting provider KnownHost, which uses cPanel, said it noticed successful exploits in the wild on the very day the vulnerability was disclosed. cPanel released a fix on Tuesday, after receiving pressure from hosting providers. According to Rapid7, “Shodan internet scans show that there are approximately 1.5 million cPanel instances exposed online,” but there is no data on how many are vulnerable to this particular bug. Swiss police arrest suspected members of Black Axe group The arrests, made in conjunction with German police, followed house searches across several Swiss cantons. The 10 suspects, believed to be members of the Nigerian gang are aged between 32 and 54, are accused of carrying out romance scams and money-laundering operations. The gang itself, Black Axe, is regarded by law enforcement as “a highly structured transnational criminal organization with a global presence.” Authorities “believe the group has about 30,000 registered members worldwide” and describe it as highly organized. HHS ponders government posture for protecting data centers The question revolves around whether to designate data centers as a standalone critical infrastructure sector. Given that they are regularly targeted, a hearing was held Wednesday to contemplate whether the federal government currently has the right setup for defending them. “Some industry witnesses and experts at the hearing of the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection suggested that data centers be given their own standalone designation, especially in light of the boom in the building of such facilities across the country. This would follow a move already taken
May 1, 2026 · via cisoseries.com
“Project Glasswing” is a new initiative that should command the immediate attention of every C-suite leader, privacy officer, information security professional, and compliance executive in health care and life sciences, financial services and other critical infrastructure industries, and their legal counsel. Announced in April 2026 by Anthropic, the self-identified “AI safety and research company” best known for its generative artificial intelligence (AI) tool Claude, Project Glasswing reflects a significant development in the cybersecurity landscape. It is a coalition of leading technology and cybersecurity providers united around a single urgent objective: deploying frontier AI capabilities for defensive cybersecurity before malicious actors can exploit similar capabilities offensively to attack first party and open-source software. The project relies on Anthropic’s unreleased Mythos Preview AI model. Seeing the Unseen: Old Susceptibilities Identified The Mythos Preview model and similar autonomous AI capabilities in current and future tools are transforming the cybersecurity risk landscape, given the rapid recent development in and accessibility of AI. According to Anthropic’s announcement, the Mythos Preview model was able to detect thousands of critical, previously unknown security vulnerabilities, including flaws in every major operating system and web browser. These systems are essential to our interconnected electronic systems and ability to communicate securely. Some of those vulnerabilities, according to Anthropic, had survived undetected for decades. The Mythos Preview model is now being deployed as part of Project Glasswing to a select group of organizations, under carefully controlled conditions, to protect the world's most important and foundational software. The initiative explicitly acknowledges, however, that if these capabilities are not harnessed for defense now, they could be weaponized against critical infrastructure, including health care, financial services, and the Internet itself. Although AI-driven threat detection and other defensive platforms are well-established solutions, Project Glasswing foreshadows a new era where autonomous AI becomes a potentially omnipotent
May 1, 2026 · via natlawreview.com
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-31431 Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
This product is provided subject to this Notification and this Privacy & Use policy.
May 1, 2026 · via cisa.gov
CISA, US and International Partners Release Guide to Secure Adoption of Agentic AI WASHINGTON – Today, the Cybersecurity and Infrastructure Security Agency (CISA), Australian Signals Directorate’s Australian Cyber Security Centre (ASD ACSC), and other U.S. and international partners published, Careful Adoption of Agentic Artificial Intelligence (AI) Services, a joint guide that presents organizations with the cybersecurity challenges and risks associated with introducing agentic AI along with recommended mitigations. Critical infrastructure and defense sectors are increasingly deploying agentic AI systems to support mission-critical systems and capitalize on significant automation benefits. However, these systems can introduce additional cybersecurity risks, such as an expanded attack surface, privilege creep, behavioral misalignment, and obscure event records. This joint guide provides developers, vendors and operators with best practices for securing agentic AI systems and recommended actions to defend against future risks. “CISA is committed to supporting the US’s adoption of AI that includes ensuring it aligns with President Trump’s Cyber Strategy for America and is cyber secure,” said CISA Acting Director Nick Andersen. “We actively collaborate with government and international partners on shared priorities with AI advancements while addressing cybersecurity challenges and risks. CISA encourages agentic AI developers, vendors and operators to review this guide.” Actionable recommendations for organizations using agentic AI include: - Avoid granting broad or unrestricted access, especially to sensitive data or critical systems - Begin with agentic AI use cases that are low-risk and non-sensitive - Account for agentic AI security in your organization's security model and risk posture For more information, please visit Artificial Intelligence on CISA.gov. ### About CISA As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of
May 1, 2026 · via cisa.gov
US imposes AI skills requirement on CyberCorps pipeline New guidance requires incoming scholars to demonstrate skills at the intersection of AI and cybersecurity, a move that fast-tracks changes outlined in recent National Science Foundation policy. The CyberCorps scholarship program, a recruitment pipeline designed to move qualifying students into government cybersecurity jobs, is overhauling recruitment standards to require that applicants demonstrate skills at the intersection of AI and cybersecurity, according to an email obtained by Nextgov/FCW. New scholars will no longer be accepted into a legacy version of the CyberCorps program without “a description on how they will develop competencies at the intersection of cybersecurity and AI,” according to an email sent Wednesday by the Office of Personnel Management and the National Science Foundation, which says the changes are “effective immediately.” The directive is informed by a February solicitation from NSF that restructured the program to center on artificial intelligence and cybersecurity integration. The email warns that students enrolled today “will not be employable when they graduate in 2-3 years without significant AI background.” There is no single cutoff date for the shift. While the National Science Foundation typically rolls out program changes through new grant cycles, the email’s “effective immediately” directive is significant because it forces that change sooner by applying AI-focused standards to new students entering the pipeline now. Any student in the new program “must be proficient in using AI in cybersecurity or providing security and resilience for AI systems. Therefore, new students in the legacy CyberCorps program must learn to acquire AI expertise to augment their cybersecurity expertise,” the email also says. The revamp comes as companies like Anthropic — which recently unveiled its cyber-focused Mythos model — and OpenAI roll out increasingly advanced AI systems with cybersecurity applications that have caught the attention of the federal
May 1, 2026 · via nextgov.com
The U.S. government wants to know how major U.S. technology companies are using AI to protect their computer networks and how they’re preparing for the possibility of an AI-driven cybersecurity crisis. Officials from the White House’s Office of the National Cyber Director (ONCD) have reached out to tech giants in recent weeks with questions about AI, information sharing, vulnerability patching and how the federal government can help, according to an email and a list of questions shared with Cybersecurity Dive. “The White House continues to proactively engage across government and industry to address several Al/cybersecurity priorities,” Jennifer Belair, the assistant national cyber director for external affairs, said in the April 23 email. “This includes working with frontier AI labs to discuss opportunities for collaboration, as well as shared approaches and protocols to address the challenges associated with scaling this technology. We are grateful for your collaboration to date and believe that your organization has the capabilities and expertise to ensure the United States and Americans are protected.” ONCD asked the companies to answer 11 questions on a range of cybersecurity topics by May 1. A few of the questions are straightforward, such as “Are you currently using Al detection and response tools and services?” and “How are Al models or platforms integrated into your software stack?” But most of the questions are more complicated, such as how quickly companies can identify and fix known vulnerabilities and what barriers they face to improving their cyber posture. Still other questions involve sensitive internal details that companies are unlikely to share. One question asks for a list of the networks, hardware and software that are critical to companies’ continuity of operations, as well as a description of how the companies isolate those systems from their traditional business networks. Another question asks the companies
May 1, 2026 · via cybersecuritydive.com