Houlahan and Whitesides urge the Pentagon to address cybersecurity capabilities affected by Anthropic's supply chain designation. Quiver AI Summary Representatives Houlahan and Whitesides address cybersecurity gap: U.S. Representatives Chrissy Houlahan and George Whitesides have requested a response from Defense Secretary Pete Hegseth regarding the implications of a supply chain risk designation on Anthropic, which limits military access to advanced AI cybersecurity tools. Concerns over national security: The representatives emphasized the need for the Pentagon to re-engage with Anthropic, especially in light of the capabilities of its newly released Mythos model, which previously identified critical vulnerabilities in systems used by the Department of Defense. Inquiries posed to the Department of Defense: Houlahan and Whitesides' letter poses five key questions to DoD, focusing on the assessment of newly uncovered vulnerabilities and the potential risks of not leveraging advanced AI cybersecurity technologies amid growing adversarial threats. Disclaimer: This is an AI-generated summary of a press release. The model used to summarize this release may make mistakes. See the full release here. Check out the Quiver Quantitative API to build on top of data on congressional stock trading, insider transactions, hedge fund moves, and more. Chrissy Houlahan Fundraising Chrissy Houlahan recently disclosed $218.0K of fundraising in a Q1 FEC disclosure filed on April 15th, 2026. This was the 511th most from all Q1 reports we have seen this year. 72.9% came from individual donors. Houlahan disclosed $172.7K of spending. This was the 564th most from all Q1 reports we have seen from politicians so far this year. Houlahan disclosed $3.9M of cash on hand at the end of the filing period. This was the 97th most from all Q1 reports we have seen this year. You can see the disclosure here, or track Chrissy Houlahan's fundraising on Quiver Quantitative. Chrissy Houlahan Net Worth Quiver
Apr 22, 2026 · via quiverquant.com
China has moved faster than any other country in rolling out smart, connected vehicles. But as its automakers push aggressively into overseas markets, they are running up against an increasingly stringent web of global cybersecurity regulations.
The article requires paid subscription. Subscribe Now
Apr 22, 2026 · via digitimes.com
CrowdStrike Holdings (NASDAQ:CRWD | CRWD Price Prediction) stock just earned a strong endorsement from KeyBanc, which upgraded shares to Overweight and set a $525 price target. The firm’s thesis centers on Anthropic’s Mythos AI model as a catalyst for a new wave of AI-driven cybersecurity demand, and KeyBanc believes CrowdStrike is positioned better than almost anyone to capture it. CrowdStrike stock traded at $456.30 as of this writing. The KeyBanc upgrade adds institutional conviction behind a stock that’s been building momentum heading into FY27. The broader analyst community is similarly constructive. Of 56 analysts covering CrowdStrike, 42 rate it a Buy and 14 rate it a Hold, with zero Sell ratings. The consensus price target sits at $489.86, making KeyBanc’s $525 target one of the more bullish calls on the Street right now. | Ticker | Company | Firm | Action | Old Rating | New Rating | Old Target | New Target | |---|---|---|---|---|---|---|---| | CRWD | CrowdStrike Holdings | KeyBanc | Upgrade | Sector Weight | Overweight | N/A | $525 | The Analyst’s Case KeyBanc frames Anthropic’s Mythos AI as the next major inflection point for cybersecurity demand. Anthropic launched “Project Glasswing,” partnering with a select group of tech companies including CrowdStrike, to address software vulnerabilities using its advanced AI model, Claude Mythos. That partnership puts CrowdStrike at the center of the conversation around AI-native threat defense. KeyBanc cites the “breadth and depth” of CrowdStrike’s Falcon platform as well positioned to capitalize on both near-term hygiene priorities and long-term runtime defense requirements. That framing matters: it’s about securing the AI infrastructure enterprises are building right now, while also stopping today’s attacks. Company Snapshot CrowdStrike closed FY26 with $5.25 billion in ending ARR, up 24% year-over-year, making it the fastest and only pure-play cybersecurity software company to achieve
Apr 22, 2026 · via 247wallst.com
Anthropic's Mythos AI System Might Actually Create More Cybersecurity Vulnerabilities Anthropic, the company behind the popular AI assistant Claude, is now testing an unreleased version of its frontier AI model: Claude Mythos Preview. It's currently only available to select tech firms, but findings have shown that it has the potential to create numerous cybersecurity vulnerabilities when it is released to the world. According to Anthropic, "Mythos Preview has already found thousands of high-severity vulnerabilities, including some in every major operating system and web browser." This is unsettling news in the wake of a recent Google report discussing AI as a hacker super weapon. However, Anthropic's Mythos AI won't see the light of day until the company is more confident that the world is ready for the cybersecurity risks it might present. As part of an initiative called Project Glasswing, Anthropic is partnering with many of the most influential tech companies "in an effort to secure the world's most critical software." Participants in Project Glasswing include Apple, Amazon Web Services, Google, Microsoft, and other well-known names. Mythos is proving to be so good at coding that it can easily identify undiscovered zero-day vulnerabilities in codebases that were thought to be secure. Anthropic's partners in Project Glasswing are currently using Mythos Preview for defensive purposes, while experts continue their research and share their knowledge across the industry. Even so, there is a very real possibility that cybercriminals will soon be using Claude Mythos and similarly powerful models to attempt unprecedented feats of hacking in the near future. The worrisome implications of Claude Mythos The purpose of Claude Mythos is to advance AI capabilities in areas that include software engineering, reasoning, and research. Anthropic (link downloads a PDF to your device) claims that Mythos Preview demonstrates a "striking leap in scores on many
Apr 22, 2026 · via bgr.com
Imagine leaving your office unlocked overnight—not because you don’t have anything valuable, but because you assume no one would bother breaking in. That’s how many small and mid-sized organizations approach cybersecurity today. There’s a persistent belief among SMBs and lean IT teams: “We’re too small to be a target. Attackers will go after bigger organizations.” But cybercriminals don’t think that way. They don’t break in because they value your data. They break in because you value it. Your customer records, financial data, contracts, internal communications—these are all critical to your business operations. And attackers know that smaller organizations are often more likely to pay to get that data back, simply because they can’t operate without it. A Mastercard survey of 5,000 SMBs found that 46% experienced a cyberattack, and 1 in 5 went bankrupt as a result. Even among survivors, 80% reported spending significant time rebuilding trust with customers and partners. Cyber risk is real, especially for smaller organizations. Cybersecurity can feel overwhelming. And because it’s often seen as something reserved for large enterprises with dedicated teams and significant budgets, many organizations default to basic protection, like antivirus, and assume they’ve done enough. Unfortunately, this approach fails to protect against modern threats. The Verizon Data Breach Investigations Report (DBIR), analyzing over 22,000 incidents, shows that credential abuse is the leading cause of breaches. In many cases, attackers don’t hack their way in—they log in by exploiting weak passwords, a lack of multi-factor authentication, or unused accounts left active. At the same time, everyday business practices quietly expand risk: Individually, these seem manageable. Together, they create a patchwork of exposure that’s difficult to see—and even harder to fix. And that’s the core problem: Most organizations don’t know where to start. To their credit, global and national organizations have made significant efforts
Apr 22, 2026 · via bitdefender.com
Technology is reshaping identity management at the local and federal levels, requiring agencies to better understand their data and how systems connect, officials said Tuesday. Speaking at the Okta Government Identity Summit in Washington, Heather Dyer, chief information security officer (CISO) at the U.S. Postal Service, said that identity management has evolved over the past year from securing data to enabling operations. “Identity is it’s not just users, it’s applications, it’s service accounts, it’s nonhuman identities, it’s devices. And you have to look at all of that holistically,” Dyer said. “We are also business enablers now. We don’t say ‘no,’ we say ‘yes,’ and ‘how do we do this securely?’” Suneel Cherukuri, CISO for the District of Columbia, said a similar shift is underway at the local level, but with unique complexity. Unlike most municipalities, he explained that D.C. serves residents, businesses, and international entities – including consulates – making its services broadly accessible. That open access combined with the inability to simply block incoming interactions puts heavy pressure on identity verification systems, Cherukuri explained. “Most people do not know the difference between a federal government and D.C. government. They think that the D.C. government is actually the federal government. So, by de facto, we become the prime target every single time … they’re not happy,” Cherukuri said. After major progress over the past five years, a newer zero trust approach has strengthened systems, creating a more reliable foundation for managing access, Cherukuri said. Dyer added that zero trust investments – such as multifactor authentication and privileged access controls – have reduced risk at the federal level, but emerging threats from artificial intelligence (AI) are reshaping priorities and requiring constant adaptation. “A lot of the risk of AI is really the users and exposing data that they shouldn’t be,” Dyer
Apr 21, 2026 · via meritalk.com
Zscaler (ZS) is up 5.2% today. Here is some analysis on what might have caused this price movement. Analysis: The day’s move appears driven more by sentiment than a single definitive company-specific headline. A plausible contributor is renewed optimism around demand for zero-trust security, helped by fresh visibility into U.S. government purchasing activity tied to Zscaler products and a continued rotation back into higher-beta software/cybersecurity names. Details: Sources: GovTribe, Zscaler Investor Relations, Investing.com Disclaimer: This price movement analysis was generated with the help of AI. Please double-check the information provided for mistakes. $ZS Insider Trading Activity $ZS insiders have traded $ZS stock on the open market 19 times in the past 6 months. Of those trades, 0 have been purchases and 19 have been sales. Here’s a breakdown of recent trading of $ZS stock by insiders over the last 6 months: - ROBERT SCHLOSSMAN (Chief Legal Officer) has made 0 purchases and 4 sales selling 10,896 shares for an estimated $2,653,040. - MICHAEL J. RICH (CRO and President of WW Sales) has made 0 purchases and 2 sales selling 7,247 shares for an estimated $1,439,157. - ADAM GELLER (Chief Product Officer) has made 0 purchases and 4 sales selling 7,259 shares for an estimated $1,406,640. - RAJ JUDGE (EVP, Corp. Strategy & Ventures) has made 0 purchases and 2 sales selling 5,926 shares for an estimated $1,183,160. - KEVIN RUBIN (Chief Financial Officer) has made 0 purchases and 2 sales selling 4,985 shares for an estimated $1,025,785. - JAGTAR SINGH CHAUDHRY (CEO & Chairman) has made 0 purchases and 2 sales selling 4,784 shares for an estimated $960,166. - JAMES A BEER has made 0 purchases and 2 sales selling 830 shares for an estimated $175,222. - ANDREW WILLIAM FRASER BROWN sold 5,000 shares for an estimated $0 To track
Apr 21, 2026 · via quiverquant.com
Cybersecurity researchers have identified 22 new vulnerabilities in popular models of serial-to-IP converters from Lantronix and Silex that could be exploited to hijack susceptible devices and tamper with data exchanged by them. The vulnerabilities have been collectively codenamed BRIDGE:BREAK by Forescout Research Vedere Labs, which identified nearly 20,000 Serial-to-Ethernet converters exposed online globally. "Some of these vulnerabilities allow attackers to take full control of mission-critical devices connected via serial links," the cybersecurity company said in a report shared with The Hacker News. Serial-to-IP converters are hardware devices that enable users to remotely access, control, and manage any serial device over an IP network or the internet by "bridging" legacy applications and industrial control systems (ICS) that operate over TCP/IP. At a high level, as many as eight security flaws have been discovered in Lantronix products (EDS3000PS Series and EDS5000 Series) and 14 in Silex SD330-AC. These shortcomings fall under the following broad categories - - Remote code execution - CVE-2026-32955, CVE-2026-32956, CVE-2026-32961, CVE-2025-67041, CVE-2025-67034, CVE-2025-67035, CVE-2025-67036, CVE-2025-67037, and CVE-2025-67038 - Client-side code execution - CVE-2026-32963 - Denial-of-service (DoS) - CVE-2026-32961, CVE-2015-5621, CVE-2024-24487 - Authentication bypass - CVE-2026-32960, CVE-2025-67039 - Device takeover - FSCT-2025-0021 (no CVE assigned), CVE-2026-32965, CVE-2025-70082 - Firmware tampering - CVE-2026-32958 - Configuration tampering - CVE-2026-32962, CVE-2026-32964 - Information disclosure - CVE-2026-32959 - Arbitrary file upload - CVE-2026-32957 Successful exploitation of the aforementioned flaws could allow attackers to disrupt serial communications with field assets, conduct lateral movement, and tamper with sensor values or modify actuator behavior. In a hypothetical attack scenario, a threat actor could gain initial access to a remote facility through an internet-exposed edge device, such as an industrial router or firewall, and then weaponize BRIDGE:BREAK vulnerabilities to compromise the serial-to-IP converter, and alter serial data moving to or from the IP network. Lantronix and Silex
Apr 21, 2026 · via thehackernews.com
It’s been more than a decade since the United States first publicly blamed another country for a cyberattack, an accusation detailed in a 31-count indictment against five members of the Chinese military who hacked into the systems of American nuclear, metal, and solar companies over a period of eight years. That public attribution of economic espionage in 2014 marked a major shift for the United States, which had previously worked behind the scenes to address digital intrusions that came from beyond its borders, if it did anything at all. Part of the rationale for naming and shaming the perpetrators was to deter bad actors from carrying out future hacks. Deterrence as a defense strategy, however, has so far proved to be something of a dud. Today, cyberattacks seem almost commonplace; breaches of public and private entities are everyday news. So-called ransomware attacks, in which hackers lock up an entity’s system or files and demand payment to restore functionality, have proliferated. In 2024, in a federal indictment, a North Korean intelligence operative was accused of using the proceeds from ransomware attacks he’d carried out against hospitals to fund additional cyberattacks on government entities around the world, among them two U.S. Air Force bases. Other attackers, including groups sponsored by countries such as China and Russia, do not announce their presence; their goal is to stay hidden long enough to steal information that can later be used for financial or geopolitical gain. By hacking into U.S. telecommunications companies in 2024, China apparently intercepted surveillance data that was meant for law enforcement agencies. Cyberattacks may be difficult to prevent, but that doesn’t mean policymakers, governments, and the sector have given up trying. Harvard Law School faculty and alumni who have worked on cybersecurity issues in their research and practice, some at the highest
Apr 21, 2026 · via hls.harvard.edu
In the article Avoiding Punitive Damages After a Data Breach published by Texas Bar Journal, Spencer Fane attorney Shawn Tuma’s piece on cybersecurity was included as an additional resource. Shawn also had a separate article published by Texas Bar Journal relevant to data privacy. In his articles, Shawn discusses the promotion of stronger cybersecurity practices and the evolving legal risks surrounding data privacy, including Texas’ SB 2610 safe harbor framework and recent developments involving artificial intelligence, unauthorized system access, and data misuse. He highlights the benefits of aligning with recognized security standards while outlining the broader impact on risk management, litigation exposure, and data breach liability. “Data breaches are costly – not just in terms of remediation and reputational harm, but also in litigation risk. SB 2610 offers businesses a way to mitigate that risk by aligning with industry standards. For organizations that handle sensitive personal information, this is an opportunity to strengthen defenses and gain legal protection,” Shawn wrote. Shawn co-leads the firm’s Cyber | Data | Artificial Intelligence | Emerging Technology Practice Group while serving as Office Managing Partner for the firm’s Plano, Texas, location. He helps businesses protect their information and protect themselves from their information. He represents a wide range of clients, from small companies to Fortune 100 companies, across the U.S. and globally in dealing with artificial intelligence (AI), cybersecurity, data privacy, data breach and incident response, regulatory compliance, computer fraud-related legal issues, and cyber and AI-related litigation.
Apr 21, 2026 · via spencerfane.com
Press Release Johns Hopkins APL Contributions Fuel Critical Navy Cybersecurity System The Navy-engineered Situational Awareness, Boundary Enforcement, and Response (SABER) system, with key capabilities developed by the Johns Hopkins Applied Physics Laboratory (APL) in Laurel, Maryland, in collaboration with government and industry partners, has become a vital line of security in protecting Navy ships against cyberattacks. SABER continuously and autonomously monitors a surface ship’s vital systems for signs of a cyberattack, including its hull, mechanical, and electrical (HM&E), navigation, and combat components. When a potential attack is detected, the system generates alerts that provide crew members with defensive and/or remediation options. The growing threat of cyberattacks on naval vessels, especially smaller ships such as destroyers and frigates, has made it critical to have a reliable system in place not only to protect the nation’s military infrastructure but also to instill confidence in the readiness of those systems for potential future conflicts. “With SABER being deployed to the fleet at large, we are creating tools that will enhance mission assurance in a cyber-contested environment,” said Vamsi Maddula, Cyber Resilient Platforms program manager at APL. Multiple Capabilities, One Mission The APL capabilities underpinning SABER draw on more than a decade of demonstrative events and innovative technical leadership. Many of these capabilities originated in APL’s SEACHANGE initiative, launched in 2016 with three lines of effort: assess situational awareness technologies, establish a prototype and temporary solution based on the technologies used in fleet experiments, and lead a human-systems engineering working group to develop guidance to better enable cyber warfare on a ship. SABER integrates tools developed by the government, APL, and industry partners to form the backbone of shipboard, tactical system cybersecurity. As SABER gains traction as a Naval Sea Systems Command (NAVSEA) rapid-development capability focused on a subset of ship systems, APL is
Apr 21, 2026 · via jhuapl.edu
The cybersecurity industry has spent the last several years chasing sophisticated threats like zero-days, supply chain compromises, and AI-generated exploits. However, the most reliable entry point for attackers still hasn't changed: stolen credentials. Identity-based attacks remain a dominant initial access vector in breaches today. Attackers obtain valid credentials through credential stuffing from prior breach databases, password spraying against exposed services, or phishing campaigns — and use them to walk through the front door. No exploits needed. Just a valid username and password. What makes this difficult to defend against is how unremarkable the initial access looks. A successful login from a legitimate credential doesn't trigger the same alarms as a port scan or a malware callback. The attacker looks like an employee. Once inside, they dump and crack additional passwords, reuse those credentials to move laterally, and expand their foothold across the environment. For ransomware crews, this chain leads to encryption and extortion within hours. For nation-state actors, the same entry point supports long-term persistence and intelligence gathering. AI Is Accelerating What Already Works The fundamental attack pattern here hasn't changed much. But what has changed is the speed and polish with which it gets executed. Attackers are leveraging AI to scale their operations by automating credential testing across larger target sets, writing custom tooling faster, and crafting phishing emails that are materially harder to distinguish from legitimate communications. This acceleration puts additional pressure on already-stretched defenders. Breaches are unfolding faster, spreading further and touching more of the environment, from identity systems to cloud infrastructure to endpoints. IR teams built for a slower tempo of engagement are finding that their existing processes can't keep pace. A Dynamic Approach to Incident Response This is where the way teams think about incident response matters as much as the technical controls they deploy.
Apr 21, 2026 · via thehackernews.com
This initiative aims to enhance access to the Falcon platform for small and medium-sized businesses (SMBs). Details CrowdStrike announced an expansion of its Managed Security Service Provider (MSSP) strategy, partnering with Dicker Data and Otsuka Corporation to increase SMB access to its Falcon platform. This move is expected to accelerate AI-driven cybersecurity transformation, allowing MSSPs to deliver tailored security services to meet growing regional demand. Jon Fox, vice president of channels and alliances, CrowdStrike Japan and Asia Pacific, added, “Budget constraints, complexity, and resource limitations continue to challenge businesses, with SMBs experiencing these challenges at a greater scale. Together with our partners, we are expanding access to the AI-powered protection that enables organizations to stay focused on their core business.” Technical Analysis The broader market saw gains on Monday, with the Technology sector rising 0.21%. CrowdStrike’s performance aligns with this positive sentiment, indicating that the stock is moving with broader market trends. CrowdStrike is currently trading within its 52-week range, showing a solid position compared to its recent performance. The stock is trading 9.4% above its 20-day simple moving average (SMA), indicating short-term strength, while it is 0.4% below its 100-day SMA, suggesting some intermediate weakness. The relative strength index (RSI) is at 59.29, indicating neutral momentum. This level suggests that the stock is neither overbought nor oversold, which may lead to a stable trading environment. - Key Resistance: $452.00 — This level may act as a barrier for upward movement. - Key Support: $364.50 — This level could provide a safety net for buyers if tested. CrowdStrike has shown a 12-month performance of 19.43%, reflecting a positive trend over the longer term. This performance suggests that the stock is maintaining upward momentum, despite some fluctuations along the way. Recent Earnings & Buyback Boost Annual recurring revenue (ARR) climbed 24%
Apr 21, 2026 · via benzinga.com
Outdated software has become a major cybersecurity liability Why AI‑accelerated threats are making patch delays untenable Takeaways - AI is compressing the vulnerability‑to‑exploit timeline, giving defenders less time to respond to newly disclosed flaws - Most attacks still target known, unpatched vulnerabilities, making outdated software a persistent and preventable risk - Automated updates and rollback capabilities are no longer optional, as manual patching cannot keep pace with modern threat activity In the artificial intelligence (AI) era, IT and cybersecurity teams must ensure every device runs the most secure software version available. As cybercriminals gain access to more advanced AI models, the amount of time and effort required to first discover a vulnerability and develop a means to exploit it is now approaching zero. While that is likely to increase the number of unknown zero-day vulnerabilities that might be exploited, most cybercriminals will—at least initially—focus on exploiting known vulnerabilities faster than ever. Unfortunately, there is no shortage of existing vulnerabilities to be exploited. For example, a Jamf Threat Labs analysis of 1.7 million iOS and Android devices and over 150,000 Mac devices finds more than half (53%) of organizations discovered they had devices with critically out-of-date operating systems. Additionally, 75% of devices had at least one vulnerable application installed. In fact, 95% of the applications assessed contained at least one medium-severity vulnerability, with 62% enabling dangerous permissions. A full 44% of devices had been exposed to malicious network traffic. Historically, many IT teams have been reluctant to deploy the latest version of any type of software for fear the update would break the application. However, as cybersecurity threats become more sophisticated the potential damage that might be unleashed by a successful cybersecurity attack is in many cases starting to exceed the risk that might occur if an application was unavailable. The
Apr 21, 2026 · via blog.barracuda.com
The IS&T Experience Episode 4: Leadership and Cybersecurity
Meet Zaid Kakish, a UNO student who unlocked new opportunities and deepened his mastery of cybersecurity by staying involved and leading an impactful student club.
- published: 2026/04/20
- contact: Kaylee Pena Guerrero - College of Information Science and Technology
This episode features Zaid Kakish, a cybersecurity graduate student at the University of Nebraska at Omaha (UNO), and Martha Garcia-Murillo, Ph.D., Dean of the UNO College of Information Science & Technology (IS&T). Kakish shares their involvement on campus through Nullify, a student club that explores cybersecurity fundamentals, tools, workshops, and current industry topics—all while hosting guest speakers and organizing community events.
Watch Episode on Youtube
About the IS&T Experience Series
The IS&T Experience gives an insider look at the people and stories shaping the future of technology at the University of Nebraska Omaha's College of Information Science & Technology. Through engaging conversations with students, faculty, staff, alumni, and community partners, discover the experiences that define our community—from navigating career development and research breakthroughs to building the skills that prepare the next generation of technology leaders.
Learn more about the College of Information Science & Technology
Apr 21, 2026 · via unomaha.edu
ZAWYA: OPSWAT and Emerson to strengthen cybersecurity for critical infrastructure operators with global reseller agreement Dubai, United Arab Emirates – OPSWAT, a global leader in critical infrastructure cybersecurity, and Emerson EMR, a global automation leader, have announced a global strategic reseller agreement that will bring OPSWAT’s industry-proven cybersecurity technologies to Emerson’s power and water industry customers. As the first initiative under this enterprise-wide agreement, Emerson will integrate OPSWAT’s scalable and safe operational technology (OT) patch management capabilities into its Ovation™ Automation Platform. The new OT patch management solution further builds on the collaboration to date by securing the Ovation Platform through OPSWAT’s MetaDefender Endpoint™ and My OPSWAT™ Central Management On-Premises, part of Emerson’s purpose-built power and water cybersecurity suite of solutions. “Our customers need cybersecurity solutions designed specifically for operational technology—not adapted from IT,” said Robert Yeager, President of Emerson’s power and water solutions business. “They benefit from purpose-built OT cybersecurity solutions that protect critical, real-time industrial systems while supporting availability, performance, and safe operations. Collaborating with OPSWAT enhances our ability to help operators protect their Ovation Automation Platform with a modern, OT appropriate approach to patch management. It reflects our commitment to delivering proven, efficient, best-in-class protection for critical infrastructure.” Critical infrastructure operators, including power generation and water/wastewater utilities, continue to face increasing cyber threats, regulatory pressure, and operational risk stemming from unpatched vulnerabilities. OPSWAT’s solution for the Ovation Automation Platform delivers a modernized patch management approach designed specifically for industrial environments, addressing challenges posed by a mix of modern and legacy tools and the ongoing surge of nation-state and ransomware activity targeting the energy and water sectors. “As LLMs, automation, and digital transformation accelerate across power and water infrastructure, the attack surface expands just as quickly,” said Benny Czarny, Founder and CEO of OPSWAT. “In environments where safety
Apr 21, 2026 · via tradingview.com
AI cloud company Vercel breached after employee grants AI tool unrestricted access to Google Workspace — hacker seeking $2 million for stolen data The culprit? An infostealer infection from a Roblox cheat download. Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. You are now subscribed Your newsletter sign-up was successful Vercel, the cloud platform behind the widely used Next.js web framework, has acknowledged a security breach after an attacker compromised a third-party AI tool called Context.ai and used it to gain access to a Vercel employee's enterprise Google Workspace account. The breach exposed non-sensitive environment variables, and a threat actor operating under the ShinyHunters name has claimed responsibility, reportedly seeking $2 million for the stolen data. Vercel said it has engaged Google-owned incident response firm Mandiant, notified law enforcement, and contacted a limited subset of affected customers directly. According to Vercel’s bulletin, the breach didn’t start with them but instead with Context.ai, an enterprise AI platform that builds agents trained on company-specific knowledge. At least one Vercel employee had signed up for Context.ai's AI Office Suite using their corporate account and granted it "Allow All" OAuth permissions, Context.ai explained in its own security notice, which says that “Vercel’s internal OAuth configurations appear to have allowed this action to grant these broad permissions in Vercel’s enterprise Google Workspace.” The attacker exploited that broad access to take over the employee's Vercel Google Workspace account and move laterally into internal systems. Article continues belowCybersecurity firm Hudson Rock claims to have traced Context.ai's own compromise back further to an employee infected by Lumma Stealer malware after downloading Roblox game exploit scripts in February. The stolen credentials reportedly included Google Workspace logins along with keys for Supabase, Datadog, and Authkit, Hudson Rock reported, but Vercel hadn’t independently confirmed this at the
Apr 21, 2026 · via tomshardware.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 21, 2026 · via youtube.com
Expanded go-to-market empowers distributors to recruit and onboard MSSPs, increasing SMBs access and adoption of the Falcon platform AUSTIN, Texas & DA NANG, Vietnam--(BUSINESS WIRE)--Apr. 20, 2026-- JAPAC Partner Symposium -- CrowdStrike (NASDAQ: CRWD) today announced an expansion of its Managed Security Service Provider (MSSP) go-to-market strategy across Japan and Asia Pacific (JAPAC), increasing access to the CrowdStrike Falcon® platform for small and medium-sized businesses (SMBs) and accelerating AI-driven cybersecurity transformation. Through expanded strategic partnerships with Dicker Data and Otsuka Corporation, this distributor-led aggregation model enables partners to onboard MSSPs at scale and deliver managed security services that bring AI-powered protection to SMBs. Independent research from Canalys shows that for every $1 of Falcon platform sales, partners can generate up to $7 in services revenue – validating CrowdStrike’s services-led ecosystem as a key driver of partner growth and profitability. Building on this momentum, CrowdStrike’s distributor-led model enables select distributors to recruit and activate MSSPs across JAPAC, with flexible billing through distributor marketplaces. This approach allows MSSPs to quickly build and deliver tailored offerings, expanding access to enterprise-grade security and meeting growing regional demand from SMBs. “Distributors and MSSPs are pivotal to scaling CrowdStrike’s reach across JAPAC and helping organizations modernize their security for the AI era,” said Jon Fox, vice president of channels and alliances, CrowdStrike Japan and Asia Pacific. “Budget constraints, complexity, and resource limitations continue to challenge businesses, with SMBs experiencing these challenges at greater scale. Together with our partners, we are expanding access to the AI-powered protection that enables organizations to stay focused on their core business.” Supporting Partner Quotes: "Cybersecurity continues to be a key growth driver for the ICT channel, with many SMBs needing access to additional capabilities to defend against modern threats," said Vlad Mitnovetski, executive director and chief operating officer of Dicker Data.
Apr 21, 2026 · via ir.crowdstrike.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 21, 2026 · via youtube.com