No-frills tech news

Microsoft Agent 365, now generally available, expands capabilities and integrations

Microsoft Agent 365 Now generally available for commercial customers. Choose an ecosystem partner for agent security and governance AI agents aren’t coming—they’re already in your environment. They show up in places you expect (like Microsoft Copilot, Microsoft Teams, and Microsoft 365) and even more places as technology evolves (a local autonomous personal AI assistant or a new software as a service (SaaS) agent connected to your sensitive data.) The problem isn’t that agents exist. It’s that they proliferate fast, span apps, endpoints and cloud, and often operate outside the visibility and control of the teams accountable for risk. When an agent can invoke tools, access data, and interact with other agents, any “helpful” workflow can turn into data oversharing, tool misuse, or over-privileged actions in seconds. And as agents become even easier to create and deploy, your attack surface grows with them. That’s why end-to-end observability matters: you can’t govern what you can’t see, and you can’t secure what you don’t understand—especially when the number of agents is a moving target. Microsoft Agent 365 helps you take control of agent sprawl as your control plane to observe, govern, and secure agents and their interactions—including agents built with Microsoft AI and agents from our ecosystem partners—using the admin and security workflows your teams already run. General availability starts today for Agent 365. Additionally, we’re announcing the previews of new Agent 365 capabilities and integrations to help you scale agent adoption with the right controls in place. - Observability, governance, and security for agents operating independently—Agent 365 is expanding to cover agents that operate with their own credentials and permissions. - Discovery of agents and shadow AI, using capabilities of Microsoft Defender and Microsoft Intune for both local and cloud agents. - A secured, managed environment for agents to work in Windows

<b>Cybersecurity</b> Agencies Worldwide Warn About Agentic AI Risks

Companies and governments using AI agents need to anticipate and assess how their use can open them up to risks and affect operations, cybersecurity agencies in the USA, U.K. and Australia warned. Agents that work autonomously can easily be misused and breached by hackers, leading to productivity losses and compromised private information, the Cybersecurity and Infrastructure Security Agency and organizations from other countries warned in a report released Friday. - âEvery individual component in an agentic AI system widens the attack surface, exposing the system to additional avenues of exploitation,â the report said. - The agencies suggested a layered defense for AI ... Learn more about Bloomberg Law or Log In to keep reading: See Breaking News in Context Bloomberg Law provides trusted coverage of current events enhanced with legal analysis. Already a subscriber? Log in to keep reading or access research tools and resources.

Social Engineering Leveled Up. Has Your Security Program? | Huntress

We’ve spent years treating prevention as the endgame: block the attack, and the problem disappears. But that model is starting to break. The environment it was built for no longer exists. Attackers aren’t just finding ways around security controls. They’re running social engineering scams inside them, using the same tools, workflows, and signals against us that we’re supposed to trust. And while attackers have adapted quickly, many security programs haven't kept pace. It's showing up in the data. In a recent report, only 8.9% of teams named phishing and social engineering as their biggest preparedness gap, which means most feel covered. That confidence is the gap. The threat has expanded well beyond what most security programs were built to see into identity abuse, trusted platforms, and the everyday workflows teams already trust. Most teams also reported having adequate budgets and mature tooling. So why do positive outcomes still lag while confidence slips? Teams aren’t behind because they don’t care or don’t work hard. They’re behind because attackers are targeting trust on an unprecedented scale and scope. It’s hitting every aspect of your digital world: identities, AI platforms, developer platforms, business software, and the workflows that keep organizations running. They’re operating in a way that makes social engineering compromise inevitable, not preventable. Resilient teams are recognizing this shift and taking steps toward a security model built for today’s threat landscape. Trust in identities: When "real" isn't real anymore The definition of a "trusted identity" is getting harder to pin down. Deepfakes push attacks well beyond email. Attackers are using AI to impersonate executives, IT staff, and even job candidates. They build rapport over time with cloned voices, then add video to lend credibility to requests that would otherwise raise red flags. That doesn't mean every organization is suddenly facing Hollywood-grade live

Datavault AI and CyberCatch Announce Signing of Binding Letter of Intent for Datavault AI to ...

Datavault AI and CyberCatch Announce Signing of Binding Letter of Intent for Datavault AI to Acquire CyberCatch to Accelerate AI-Driven, Quantum-Resistant Cyber Risk Mitigation Solutions Strategic acquisition is anticipated to position Datavault AI to bring CyberCatch’s AI-enabled cyber risk mitigation solution into Datavault AI’s SanQtum-secured edge Graphics Processing Unit ecosystem, addressing a global information security market projected to reach $240 billion in 2026 (Gartner) CyberCatch’s post-quantum cryptography conversion plan is also expected to position the combined company ahead of the AI-enabled “Q-Day” quantum-attack horizon, now compressed to as early as 2029 (Google) AI-enabled adversary attacks in 2025 rose 89% year-over-year while average eCrime breakout time fell to 29 minutes, a 65% increase in adversary speed compared to 2024, per CrowdStrike’s 2026 Global Threat Report, and Google Quantum AI research has now compressed the timeline for cryptographically relevant quantum computing to as early as 2029. PHILADELPHIA & SAN DIEGO--(BUSINESS WIRE)-- Datavault AI Inc. (“Datavault AI” or the “Company”) (NASDAQ:DVLT), a provider of data monetization, credentialing, digital engagement, and real-world asset (“RWA”) tokenization technologies, and CyberCatch Holdings, Inc. (“CyberCatch”) (TSXV:CYBE) (OTCQB:CYBHF), a cybersecurity company offering a patented, AI-enabled platform for continuous compliance and cyber risk mitigation, today announced they have entered into a binding letter of intent (the “LOI”) under which Datavault AI and CyberCatch will enter into a definitive agreement for Datavault AI to acquire 100% of CyberCatch in an all-stock transaction structured as a court-approved plan of arrangement under the Business Corporations Act (British Columbia). Under the LOI and subject to a definitive agreement, Datavault AI will acquire 100% of CyberCatch’s issued and outstanding common shares (being approximately 26.8 million shares) in exchange for approximately 49.9 million newly issued shares of Datavault AI common stock (the “Datavault AI Shares”) at CAD $5.11 per CyberCatch share, which implies an aggregate value

Name That Toon: Mark of (Security) Progress

Since 2006, Dark Reading has been at the forefront of covering cybersecurity, providing deep insights and analysis beyond the headlines. All those major news events? We were there. Shifts in technology trends? We wrote about them. Enjoy this special anniversary coverage celebrating where we've been and what's next. Name That Toon: Mark of (Security) Progress Feeling creative? Have something to say about the last 20 years of cybersecurity? Our editors will award the best cybersecurity-related caption with a $20 gift card. Dark Reading turned 20 on May 1, and we are celebrating by bringing back the Name That Toon contest. What do you think is happening with those people in the above scene? What were they thinking in 2006? What's happening in 2026? What are they saying to each other? Or is this a game of "Find the Difference" between 2006 and 2026? You tell us! For those of you unfamiliar with the contest, you have a little over three weeks to send us (using the instructions below) your most creative cybersecurity-related caption that you think describes what is happening in this cartoon. A panel of Dark Reading editors will review all submissions and select the winner. We will then republish the cartoon with the winning caption. The winner will get a shout-out from us and also a gift card. There are many different ways to submit your ideas before the May 26 deadline: Email [email protected] with the subject line "Dark Reading 20 Toon." We will reach out to the winner using the platform you contacted us on.

Oregon Tech Students Earn Top Honors at National IT and <b>Cybersecurity</b> Conference

Students from Oregon Tech’s Applied Computing & Geomatics (ACG) Department traveled to Missouri State University this spring to compete in America’s Innovate IT Collegiate Conference (AITCC), a national competition featuring hands-on, real-world challenges in information technology and cybersecurity. Oregon Tech students earned multiple top finishes across several events, including first- and third-place awards. Cybersecurity and Information Technology student participants included Gabriel Dearie, Dominik Kuller, Cole Bentley, Max Espinoza, Uriel Aguilar Torres, and Aiden Kimberling. The students were guided by faculty mentors Praveen Kumar Guraja, Ph.D., Assistant Professor of Cybersecurity & Information Technology, and Manish Nalluri, Visiting Instructor of Cybersecurity & Information Technology. “It is super cool to really test and apply our knowledge and actually see how far we have come,” said Aiden Kimberling. Aiden and teammate Uriel placed first in the Analyze IT Challenge. “In the Analyze IT Challenge, my teammate and I earned first place by applying data analysis, statistical reasoning, and predictive modeling to a real-world dataset. This success was largely due to the strong foundation we built in our Business Analytics and Finance classes, which helped us approach the problem strategically,” said Uriel Aguilar Torres. “Overall, AITCC was a valuable learning experience that helped me better understand my strengths and areas for improvement.” Full results include: - Analyze IT Challenge - 1st Place: Aiden Kimberling and Uriel Aguilar Torres - 3rd Place: Cole Bentley and Dominik Kuller - Cyber Sentinel Challenge (Capture the Flag) - Honorable Mention: Uriel Aguilar Torres and Dominik Kuller, Aiden Kimberling and Max Espinoza (Top 10) - Troubleshoot IT Challenge - Honorable Mention: Cole Bentley (4th Place) “One thing that stood out to me was how fast the field is constantly evolving,” said Dominik Kuller. “It made it clear that cybersecurity isn’t something you can just learn once; you must keep adapting

What is Device Code Phishing?

What is Device Code Phishing? Device code phishing doesn’t hack its way in. It uses a legitimate authentication flow to walk right through the front door, with no password required, MFA bypassed, and session tokens handed straight to the attacker. The Huntress Security Operations Center (SOC) caught it hitting more than 340 organizations in a matter of weeks and immediately cut off the attackers’ access across every partner environment they could reach. Shady? Absolutely. Rare? Not even close. Hit play to see exactly how it works and better defend your identities. “Identity used to be about passwords and MFA. In the cloud, it’s sessions, tokens, and apps — and that’s where most teams are behind.” – Jenko Hwong, Principal Product Researcher, Identity Threat Detection and Response (ITDR) [PH] Learn More About Phishing [PH] Huntress delivers everything you want from a security tool, all designed with the unique needs of outsourced IT and security teams in mind. [PH] Phishing attempts can show up as messages from your bank, your boss, your utility providers, or even the government. One click from one user can compromise an entire network and inadvertently let hackers deploy ransomware, steal information, or worse. [PH] The median time it takes for a user to click a link and enter information is less than 60 seconds. With a turnaround time that quick, it's no wonder phishing is one of the preferred methods used by hackers. (2024 Verizon Data Breach Report)

Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware ...

Press Release Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison For Immediate Release Office of Public Affairs Two American cybersecurity professionals were sentenced today to four years each in prison for their role in a conspiracy to obstruct, delay, or affect commerce through extortion in connection with ransomware attacks occurring in 2023. Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, were sentenced. According to court documents, they and another co-conspirator, Angelo Martino, 41, of Florida, successfully deployed the ransomware known as ALPHV BlackCat between April 2023 and December 2023 against multiple victims located throughout the United States. The three men agreed to pay the ALPHV BlackCat administrators a 20% share of any ransoms received in exchange for access to the ransomware and ALPHV BlackCat’s extortion platform. All three men worked in the cybersecurity industry — meaning that they had special skills and experience in securing computer systems against harm, including the type of harm they themselves were committing against the victims in this case. After successfully extorting one victim for approximately $1.2 million in Bitcoin, the men split their 80% share of this ransom three ways and laundered the funds through various means. According to court documents, ALPHV BlackCat targeted the computer networks of more than 1,000 victims around the world. The group used a ransomware-as-a-service model in which developers were responsible for creating and updating ransomware and for maintaining the illicit internet infrastructure. Affiliates were responsible for identifying and attacking high-value victim institutions with the ransomware. After a victim paid, developers and affiliates shared the ransom. “The court’s sentences today reflect the damage that these defendants inflicted during their cyberattacks on victim companies throughout the United States,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division.

<b>Cybersecurity's</b> A.I. Problem Isn't Technology. It's Human.

Artificial intelligence is not new to cybersecurity. The sector is one of A.I.’s earliest adopters. For years, defensive cybersecurity has relied on machine learning to identify anomalies, detect patterns and respond to threats with speed and precision beyond any human capability. What is new is the speed, scale and accessibility of A.I., and the way it is reshaping not just our defenses, but the very nature of cyber risk itself. On April 7, Anthropic sent shockwaves through industries when it announced that its latest model, Claude Mythos, was too powerful to release publicly because of its exceptional ability to identify and exploit software vulnerabilities. The company instead opted to provide controlled access to select businesses, including JPMorgan, Apple, Nvidia and Google, to strengthen their cybersecurity defenses. The move underscored a growing reality that the same systems designed to protect can just as easily be weaponized. The uncomfortable truth is that while A.I. is accelerating both offensive and defensive capabilities, threat actors are proving equally, if not more, innovative. Technology alone won’t bridge the capability gap. Instead, leadership, talent generation and training need to keep pace with this revolutionary shift in technology. The new offense: faster, smarter and more personal For decades, cyberattacks followed a familiar pattern. Phishing emails were often clumsy, riddled with grammatical errors and relatively easy to spot. Think the infamous “Nigerian prince” scams. That era is over. A.I. has fundamentally changed the precision and economics of cybercrime. It allows bad actors to operate with unprecedented speed and sophistication. Cyberattacks have always been, in part, a numbers game—like trying every door and window in a neighborhood until one is unlocked. A.I. simply allows attackers to try exponentially more doors at near light speed. It also acts as a force multiplier for low-skilled actors, simplifying the creation of malware

Pine Bluff School District scammed out of more than $3.2 million after <b>cybersecurity</b> hack

Pine Bluff School District scammed out of more than $3.2 million after cybersecurity hack LITTLE ROCK (KATV) — On Monday, Dr. Jennifer Barbaree, Superintendent of the Pine Bluff School District, announced the district fell victim to a serious cybercrime that scammed the district out of more than $3.2 million. "On December 17, the District processed a wire transfer in the amount of $3,204,639.55 for what was believed to be a legitimate invoice from a trusted construction vendor as part of the District's ongoing construction projects," the statement read. The statement also adds that the Director of Finance contacted the vendor to confirm the receipt of the payment and learned that the company sent the invoice for construction services rendered, but the company did not request the invoice to be paid via wire transfer. At this point, it was revealed the district was subjected to a "sophisticated" cyberattack. According to the statement, a district employee's email account was compromised. Although a legitimate invoice had been received, fraudulent wiring instructions were introduced in the same email thread through a phishing scheme designed to mimic authentic communications. Officials said they were directed to maintain strict confidentiality, which is why this information was not previously released to the public. "Sharing details publicly at that time could have compromised the investigation and potentially hindered efforts to recover the funds by law enforcement. For that reason, we were not able to provide updates sooner." A federal investigation has been underway, and school officials have been informed that the investigation is "largely complete." "Encouragingly, a substantial portion of the funds are expected to be recovered," Barbaree said. "While the exact amount has not yet been finalized by authorities, we anticipate receiving a detailed update on restitution in the coming weeks." The District also filed a claim with

Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber

Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber In this latest installment of the Reporters' Notebook video series, we discuss how the new AI model threatens to completely upend cybersecurity, and what industry leaders are telling the press. On April 7, Anthropic announced that its latest version of the large language model (LLM) Claude, dubbed Mythos, was here and displaying a shocking ability to find and exploit software vulnerabilities at machine, even industrialized speed. The implications of an AI red teamer on the loose, accessible potentially to threat actors, and able to be turned against any system in the world in an instant, has inspired alarm for governments and around the cybersecurity sector. According to Anthropic, the Claude Mythos model can find and exploit zero-day bugs in "every major operating system and every major Web browser." To prove the point, the company said the model was quickly able to identify a 27-year-old flaw in OpenBSD. Enter Project Glasswing: A consortium of some of the biggest software providers in the world who will endeavor to use the model for cybersecurity defense first, putting it to work on their software before adversaries can get a hold of the tool. Three reporters, Dark Reading's Becky Bracken, Cybersecurity Dive’s Eric Geller, and TechTarget SearchSecurity’s Phil Sweeney, open up their notebooks and share what their top sources are saying in reaction to reports that Anthropic’s Mythos can find and exploit vulnerabilities at machine speed. They also cover the consortium of software power players that have come together to test Mythos under Project Glasswing. Learn more in the video, and also check out our Reporters' Notebook full series, which is designed to bring together insights and coverage from across Informa TechTarget's network of cybersecurity sister sites. Becky Bracken, Phil Sweeney & Eric Geller: Full

PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials

In yet another software supply chain attack, threat actors have managed to compromise the popular Python package Lightning to push two malicious versions to conduct credential theft. According to Aikido Security, OX Security, Socket, and StepSecurity, the two malicious versions are versions 2.6.2 and 2.6.3, both of which were published on April 30, 2026. The campaign is assessed to be an extension of the Mini Shai-Hulud supply chain incident that targeted SAP-related npm packages on Wednesday. As of writing, the project has been quarantined by the administrators of the Python Package Index (PyPI) repository. PyTorch Lightning is an open-source Python framework that provides a high-level interface for PyTorch. The open-source project has more than 31,100 stars on GitHub. "The malicious package includes a hidden _runtime directory containing a downloader and an obfuscated JavaScript payload," Socket said. "The execution chain runs automatically when the lightning module is imported, requiring no additional user action after installation and import." The attack chain paves the way for a Python script ("start.py"), which downloads and executes the Bun JavaScript runtime, and then uses it to run an 11MB obfuscated malicious payload ("router_runtime.js") with an aimto conduct comprehensive credential theft. From among the harvested credentials, the GitHub tokens are validated against the "api.github[.]com/user" endpoint before being used to inject a worm-like payload to up to 50 branches retrieved from every repository the token can write to. "The operation is an upsert: it creates files that do not yet exist and silently overwrites files that do," Socket added. "No pre-check for existing content is performed. Every poisoned commit is authored using a hardcoded identity designed to impersonate Anthropic's Claude Code." Separately, the malware implements an npm-based propagation vector that modifies the developer's local npm packages with a postinstall hook in the "package.json" file to invoke the malicious

Cyber Risk for Lawyers: Structuring Your Law Firm's IT for <b>Cybersecurity</b> &amp; Risk

Cyber Risk for Lawyers Structuring Your Law Firm’s IT for Cybersecurity & Risk Chicago, IL | Tuesday, May 19, 2026 | 1 Hour MCLE | Hybrid (In-Person + Zoom) Cyber Risk for Lawyers Overview Date and Time: Tuesday, May 19, 2026, from 12:00 PM to 1:00 PM In-Person: ISBA Mutual Insurance Company, 20 S Clark St #800, Chicago, IL 60603 Remote: Attend via Zoom Cyber threats targeting lawyers continue to evolve, and even small firms are increasingly becoming targets. Building on the issues raised in our recent risk management program, this follow-up session takes a deeper dive into the practical cybersecurity risks facing law practices today. These include email compromise, ransomware demands, and the insurance coverage issues that arise when something goes wrong. On Tuesday, May 19th, ISBA Mutual hosts Cyber Risk for Lawyers: Structuring Your Law Firm’s IT for Cybersecurity & Risk. Most law firms are aware of the cyber risks. Few have a clear framework for structuring their IT systems to manage those risks. This session gives attorneys a practical blueprint for how a modern law firm IT environment should be built, where the risk and liability actually sit, and how cybersecurity and AI fit inside that framework. During the May Cyber Risk for Lawyers session, attendees will gain practical guidance on: How a secure, efficient law firm IT stack should be structured, from endpoints and identity to cloud, backup, and vendor management Where cybersecurity risk and liability actually live in that stack, and who is accountable at each layer How to evaluate your current IT environment against a defensible framework How the most common threats (email compromise, ransomware, wire fraud) map to specific gaps in IT structure, and how proper structure prevents them How AI tools (ChatGPT, Copilot, Claude) should be governed inside a law firm IT

AI, Data, and <b>Cybersecurity</b> Top IT Agendas, but Priorities Diverge by Sector, Info-Tech ...

The pressures shaping IT in 2026 are no longer playing out the same way across industries, making sector-specific prioritization more important for leaders under pressure to deliver results. To help IT leaders and their teams focus their efforts, Info-Tech Research Group has released its Best of Industry 2026 collection, a set of industry-specific reports that brings together the global research and advisory firm's most relevant industry research for education, financial services, professional services, manufacturing, and government. ARLINGTON, Va., April 30, 2026 /CNW/ - As AI adoption, cybersecurity demands, modernization pressures, and data challenges continue to reshape IT in 2026, leaders are finding that the most urgent priorities no longer look the same across sectors. To help IT teams focus their efforts, Info-Tech Research Group has released its Best of Industry 2026 collection, a set of industry-specific reports that brings together the global research and advisory firm's most relevant industry research for education, financial services, professional services, manufacturing, and government. × Javascript is required for you to be able to read premium content. Please enable it in your browser settings. kAm%96 4@==64E:@? 4@??64ED D64E@C\DA64:7:4 AC:@C:E:6D E@ 762EFC65 C6D62C49[ 3=F6AC:?ED[ E@@=D[ 2?5 2?2=JDE 8F:52?46 E92E 96=A =6256CD >@G6 7C@> :56?E:7J:?8 E96 C:89E 7@4FD 2C62D E@ 24E:?8 @? E96>] p4C@DD E96 7:G6 C6A@CED[ C64FCC:?8 E96>6D DF49 2D px[ 4J36CD64FC:EJ[ 52E2[ >@56C?:K2E:@?[ 2?5 5:8:E2= EC2?D7@C>2E:@? C6>2:? 4@?DE2?E[ 3FE E96 @A6C2E:@?2= C62=:E:6D 369:?5 E9@D6 AC:@C:E:6D 5:776C D92CA=J 3J :?5FDECJ]k^Am kAm%92E 5:G6C86?46 :D G:D:3=6 24C@DD E96 C6A@CED[ 7C@> 6?C@==>6?E 564=:?6 2?5 C6DA@?D:3=6 px :? 65F42E:@? E@ 4@DE @AE:>:K2E:@? :? 7:?2?4:2= D6CG:46D[ D6CG:46 56=:G6CJ C6:?G6?E:@? :? AC@76DD:@?2= D6CG:46D[ x?5FDECJ c]_ 2?5 DFAA=J 492:? G:D:3:=:EJ :? >2?F724EFC:?8[ 2?5 244@F?E23:=:EJ 2?5 5:8:E2= D6CG:46 56=:G6CJ :? 8@G6C?>6?E]k^Am kAmQx% =6256CD 2C6 >2?28:?8 >2?J @7 E96 D2>6 AC6DDFC6D :? a_ae[ 3FE E96 AC:@C:E:6D E92E >2EE6C >@DE[ 2?5 E96 H2J E96J ?665 E@

Mythos legend ups <b>cybersecurity</b> stakes

Anthropic's Claude Mythos can identify security flaws in software within hours, flaws that have remained undetected for decades. To spot a vulnerability, however, Mythos must be able to exploit it. Which it also does within hours. This makes it a concerning AI tool if it falls into the wrong hands. Anthropic has prudently decided to release the AI model to a select group of companies that develop critical software. The intention is to patch the digital infrastructure before Mythos becomes publicly available. This, in turn, raises two sets of issues. One, not all digital infrastructure is built by Big Tech. And, two, not every company developing AI cybersecurity tools will be as conscientious as Anthropic. India has built an impressive stack of DPI, and is assessing the new risk environment it faces. GoI, as Nirmala Sitharaman noted last week at the ET Awards for Corporate Excellence, is in talks with the US administration for access to Mythos. India's position is that its digital backbone has a reach comparable to, if not greater than, that of Big Tech firms. However, this stance dilutes Anthropic's original intention of limiting access to a core group. India's argument tends to favour equitable access to cybersecurity tools before Mythos' potential risks are fully mitigated. This represents a balanced approach in an industry divided over whether the model is primarily a security solution or a threat. Regardless of how Mythos evolves, India has begun auditing its cybersecurity requirements. Large enterprises are better equipped to protect themselves. But small firms require a supportive ecosystem to counter AI-driven threats. Regulatory adoption of AI must align with industry deployment to safeguard all stakeholders. A system as significant as UPI requires an adequate response to the evolving cybersecurity landscape. GoI has identified the threat early, and targeted policy intervention could

APRA meets with banks, urges more vigilance against AI-powered hacks

Australia’s prudential regulator has raised the alarm with the big banks, warning of the serious harm that sophisticated AI tools could do to cybersecurity defences and urging them to bolster safeguards around critical systems. In meetings with major banks, the Australian Prudential Regulation Authority told directors it wanted more scrutiny around how artificial intelligence, such as Anthropic’s Claude platform, could change the nature of hacking. Loading...

What Happens When We Disregard ICT4D <b>Cybersecurity</b> Risks

The development sector is proud of what it has built. DHIS2 runs national health information systems in more than 80 countries. CommCare supports community health workers at scale. Safaricom-backed M-Tiba distributed insurance benefits and government health subsidies to millions of Kenyans. These are real achievements. They are also real targets. In October 2025, a threat actor claimed to have stolen more than 2.15 terabytes of data from M-Tiba’s servers, including patients’ names, national ID numbers, dates of birth, phone contacts, medical diagnoses, and billing information, affecting up to 4.8 million users. Kenya’s Office of the Data Protection Commissioner confirmed it had opened an investigation. This happened two months after M-Tiba announced it had received ISO 27001 certification for its information security management. In June 2024, the BlackSuit ransomware group brought down South Africa’s National Health Laboratory Service after a single employee clicked a phishing link. The NHLS runs 265 laboratories serving roughly 80% of South Africa’s population. The attack delayed an estimated 6.3 million blood tests. HIV, TB, and mpox diagnostics stalled. The NHLS later admitted its systems were “in no way geared to counter” the attack. No donor has been held accountable for either failure. No implementing partner has faced a regulatory penalty. The people whose data was exposed had no notification, no legal recourse, and no recourse at all. That is the scandal. Not the breaches. The accountability structure that makes them inevitable. We’ve Known of Cybersecurity Threats for Years. USAID formally recognized cybersecurity as a development challenge in its 2020 Digital Strategy. Its 2023 Cybersecurity Primer stated that every USAID activity and program must consider cybersecurity as a strategic and operational matter. The Principles for Digital Development include a dedicated principle on privacy and security. None of this requires anything. - There is no mandated budget line

ITS America Conference &amp; Expo 2026 Launches <b>Cybersecurity</b> &amp; Data Zone in Detroit

Dedicated exhibit space addresses evolving connected transportation industry and critical data security management needs DETROIT, MI, UNITED STATES, April 29, 2026 /EINPresswire.com/ — ITS America Conference & Expo, organized in partnership by RX Global and ITS America, announces the launch of the Cybersecurity & Data Zone at the June 9-12, 2026 event to address the evolving connected industry and the management of data and cybersecurity. The dedicated space within the Huntington Place Exhibit Hall in Detroit will showcase cutting-edge technologies designed to protect connected vehicles, secure smart infrastructure, and strengthen transportation system resilience. The zone brings together cybersecurity tools, data management solutions, and industry experts, offering attendees direct access to technologies shaping secure and reliable intelligent transportation systems. More than 30 exhibitors focused on Cyber and Digital Security and Data Management and Data Analytics will be part of the event, giving attendees direct access to some of the most recognized names in the field. Among them, Palo Alto Networks brings its AI-driven cybersecurity platforms trusted by more than 70,000 customers worldwide, Flock Safety offers its automated license plate recognition, video surveillance, and other detection systems, and Cisco Systems contributes its globally recognized networking and cybersecurity solutions. “Cybersecurity is a fundamental requirement for the safe deployment of intelligent transportation technologies that connect our vehicles, infrastructure, and data systems,” said Laura Chace, President and CEO, ITS America. “The Cybersecurity & Data Zone represents our industry’s commitment to safe innovation and demonstrates how we can advance transportation technology while maintaining the highest security standards that protect people and the critical infrastructure they use.” As transportation systems become more connected, the need to protect them grows just as fast. Cybersecurity threats targeting vehicles, infrastructure, and data networks pose real risks to public safety and system reliability. The Cybersecurity & Data Zone gives transportation professionals

FTI Consulting Adds 10 Senior Hires to Expand <b>Cybersecurity</b> and Data Privacy Practice

FTI Consulting, Inc. (NYSE: FCN) has made a major investment in its cybersecurity, data privacy and information governance capabilities, appointing 10 senior professionals as client demand rises for cyber risk management and regulatory compliance services. The new hires include five senior managing directors and five managing directors across key U.S. markets, strengthening the firm’s Technology segment as companies confront growing cyber threats, stricter privacy rules and increased scrutiny around artificial intelligence governance. Anthony J. Ferrante, global head of the Cybersecurity practice at FTI Consulting, said organizations are operating in an environment of heightened digital exposure and expanding regulatory complexity. “Organizations are facing unprecedented digital exposure, operational and regulatory complexities and need practical solutions from trusted experts that help reduce risk, strengthen resilience and achieve compliance,” Ferrante said in a statement. The expansion reflects broader market demand for advisory firms that can combine technical cybersecurity expertise with legal, regulatory and operational consulting. Companies increasingly need integrated support spanning breach preparedness, privacy compliance, data governance and AI risk management. Sophie Ross, global chief executive officer of FTI Consulting’s Technology segment, said exponential data growth and evolving regulations are driving demand for faster and more defensible governance solutions. Among the senior managing directors joining the firm is Akshay Dhawan in Washington, D.C., who brings more than two decades of experience in cybersecurity and digital transformation. He will focus on enterprise cybersecurity programs, particularly around cloud environments, AI systems and national security-related regulations. Chicago-based David Manek joins as a senior managing director specializing in privacy and regulatory change management. He is expected to advise clients on laws including the California Consumer Privacy Act, the European Union’s General Data Protection Regulation and the EU AI Act. Matt McClelland, based in Charlotte, adds expertise in information governance and analytics. His work at FTI Consulting will include

Webinar: How to Automate Exposure Validation to Match the Speed of AI Attacks

In February 2026, researchers uncovered a shift that completely changed the game: threat actors are now using custom AI setups to automate attacks directly into the kill chain. We aren't just talking about AI writing better phishing emails anymore. We’re talking about autonomous agents mapping Active Directory and seizing Domain Admin credentials in minutes. The problem? Most defensive workflows still look like this: your CTI team finds a threat, they pass it to the Red Team to test, and eventually, the results reach the Blue Team for patching. This process is full of friction, silos, and delays. The reality is simple: You cannot fight an AI adversary moving at machine speed when your defense moves at the speed of a calendar invite. To bridge this gap, we’re hosting a technical deep dive with the team at Picus Security to unveil a new defensive paradigm: Autonomous Exposure Validation. Register for the Webinar Here ➜ Leading this session are Kevin Cole (VP of Product Marketing) and Gursel Arici (Sr. Director of Solution Architecture) from Picus Security. Together, they bring a unique blend of strategic threat intelligence and deep technical engineering to show you how to flip the script. Here is exactly what you will walk away with: - The Speed Asymmetry: A behind-the-scenes look at the real-world mechanics of how autonomous, AI-driven attacks actually operate. - The Agent Architecture: How to safely automate threat intel ingestion, simulate attacks, and coordinate fixes—without breaking your network. - Breaking the Silos: How to eliminate the slow hand-offs between your CTI, Red, and Blue teams so they work as a single unit. - The "Team Multiplier" Effect: How lean security teams can achieve enterprise-level protection without doubling their headcount. The attackers have already upgraded their toolkits. It’s time for us to do the same. If you