Cybersecurity expert urges more accountability and transparency in the use of AI Sign up now: Get ST's newsletters delivered to your inbox - Jeff Moss advocates for increased AI accountability and transparency to mitigate risks, ensuring users are not harmed by its vulnerabilities or exploitation by criminals. - Moss raises ethical concerns about AI's use in warfare, citing the "Where's Daddy?" programme, and warns AI agents could become political without regulation. - To boost cybersecurity, Moss proposes legal "safe harbour" for "white hat" hackers, allowing experts to research critical system vulnerabilities without fear of litigation. AI generated SINGAPORE – When a consumer buys a lock, the seller will highlight only its qualities, as it is not in his interest to talk to the customer about the product’s limitations. But when experts reveal the lock’s vulnerabilities, the consumer will have a different opinion of its worth. This concept also applies to artificial intelligence, said computer and internet security expert Jeff Moss, founder of hacking convention DEF CON. The use of AI is spreading so fast that consumers may neglect to ask how secure it is, with developers extolling only their products’ virtues. To Mr Moss, there must be more accountability and transparency to mitigate the risks associated with the use of AI by ensuring it is not misused or exploited by criminals. He raised his concerns during an interview with The Straits Times on April 29 at the Sands Expo and Convention Centre, where DEF CON is being held in Singapore for the first time. It is running alongside the Milipol TechX Summit (MTX) 2026 from April 28 to 30. Mr Moss, who has held several prominent cybersecurity roles and was part of the technical consulting team of the hit techno-thriller TV series Mr Robot, said it is vital to discuss
Apr 30, 2026 · via straitstimes.com
Chairmen Garbarino, Moolenaar Announce Joint Investigation into National Security Risks Posed by PRC AI Models April 29, 2026 WASHINGTON, D.C. –– Today, House Committee on Homeland Security Chairman Andrew R. Garbarino (R-NY) and House Select Committee on China Chairman John Moolenaar (R-MI) announced a joint investigation into the national security and cybersecurity risks posed by the growing adoption of PRC-developed artificial intelligence models, including low-cost, open-weight, and API-accessible systems developed by Chinese companies such as DeepSeek, Alibaba, Moonshot AI, and MiniMax. The investigation comes amid growing concern that PRC-based AI companies are using unauthorized model distillation and other illicit techniques to extract capabilities from leading American frontier models, then repackaging those capabilities into lower-cost models without the same safeguards included in the original American models, which are then marketed or made available to U.S. companies, developers, and consumers. While model distillation can be a legitimate AI development technique, distillation conducted through fraudulent accounts, proxy networks, evasion of access restrictions, or violations of U.S. companies’ terms of service raises serious concerns about model provenance, intellectual property, cybersecurity, and supply-chain risk. Read more in Semafor via Rachyl Jones As an initial step in the probe, the Chairmen sent letters to Anysphere and Airbnb, raising concerns about the companies’ use of or exposure to these risks through PRC-developed AI. The letters also follow an April 2026 memo from the White House Office of Science and Technology Policy warning that foreign entities, primarily based in China, are conducting deliberate, industrial-scale campaigns to distill U.S. frontier AI systems through proxy accounts and other coordinated methods. In the letter to Anysphere, the Chairmen focus on Cursor’s Composer 2 model, which was reportedly built on an open-weight model developed by Moonshot AI, one of the PRC-based companies publicly implicated in large-scale distillation campaigns targeting American AI systems.
Apr 29, 2026 · via homeland.house.gov
Cybersecurity researchers are sounding the alarm about a new supply chain attack campaign targeting SAP-related npm Packages with credential-stealing malware. According to reports from Aikido Security, Onapsis, OX Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz, the campaign – calling itself the mini Shai-Hulud – has affected the following packages associated with SAP's JavaScript and cloud application development ecosystem - - mbt@1.2.48 - @cap-js/db-service@2.10.1 - @cap-js/postgres@2.2.2 - @cap-js/sqlite@2.2.2 "The affected versions introduced new installation-time behavior that was not previously part of these packages' expected functionality," Socket said. "The compromised releases added a preinstall script that acts as a runtime bootstrapper, downloading a platform-specific Bun ZIP from GitHub Releases, extracting it, and immediately executing the extracted Bun binary." "The implementation also follows HTTP redirects without validating the destination and uses PowerShell with -ExecutionPolicy Bypass on Windows, increasing the risk for affected developer and CI/CD environments." Wiz noted that the malicious packages match several features present in previous TeamPCP operations, indicating that the same threat actor is likely behind the latest campaign. The suspicious versions were published on April 29, 2026, between 09:55 UTC and 12:14 UTC. The poisoned packages introduce a new package.json preinstall hook that runs a file named "setup.mjs," which acts as a loader for the Bun JavaScript runtime to execute the credential stealer and propagation framework ("execution.js"). According to Aikido, the malware is designed to harvest local developer credentials, GitHub and npm tokens, GitHub Actions secrets, and cloud secrets from AWS, Azure, GCP, and Kubernetes. The stolen data is encrypted and exfiltrated to public GitHub repositories created on the victim's own account with the description "A Mini Shai-Hulud has Appeared." As of writing, there are more than 1,100 repositories with descriptions. In addition, the 11.6 MB payload comes with capabilities to self-propagate through developer and release workflows, specifically using
Apr 29, 2026 · via thehackernews.com
Infosecurity Magazine reports that a significant number of cybersecurity professionals are considering switching careers due to a lack of a pay raise and a sense of not being appreciated at work.Only about half of cyber workers expect their wages to increase in the next 12 months, indicating that the remaining employees are dissatisfied with their career situation, according to the recent Harvey Nash Global Tech Talent & Salary Report. One of the main reasons cited was the lack of investment in cybersecurity despite ongoing incidents of hacking, data breaches, and ransomware attacks, citing the attack on Jaguar Land Rover as an example that affected the UK economy. Only 22% of the companies surveyed confirmed they have invested in this area, which Harvey Nash Chief Information Officer Ankur Anand described as concerning. Employees are urged not to confine themselves to workplaces where they are undervalued, but to look for companies where they can better utilize their skills, as cybersecurity remains highly in demand today. Security Staff Acquisition & Development, Security Strategy, Plan, Budget Job dissatisfaction among cybersecurity professionals on the rise Get daily email updates SC Media's daily must-read of the most current and pressing daily news You can skip this ad in 5 seconds
Apr 29, 2026 · via scworld.com
AP Photo/Alex Brandon GAO report on DOGE payments access ‘just the tip of the iceberg’ Agency Oversight Read more
Apr 29, 2026 · via federalnewsnetwork.com
Revenue and go-to-market leader to build on Nudge Security's strong momentum and leadership position as company enters next phase of growth AUSTIN, Texas, April 29, 2026 /PRNewswire/ -- Nudge Security, the leader in SaaS and AI security governance, today announced the appointment of Patrick Dillon as its first Chief Revenue Officer (CRO). In this role, Dillon will drive the company's revenue cycle, accelerate growth, and lead global sales, customer success, and the partner ecosystem. "Modern enterprises are struggling to manage a massive influx of AI tools, SaaS apps, and non-human identities accessing their data," said Russell Spitler, Co-Founder and CEO, Nudge Security. "Our rapid growth reflects the urgent demand for scalable security and governance of workforce AI and SaaS use. Patrick's deep cybersecurity expertise and proven track record in building and scaling technology companies make him the perfect addition to our leadership team as we embark on the next chapter of our expansion." Dillon joins Nudge Security with over two decades of experience architecting go-to-market strategies across cybersecurity, SaaS, and enterprise software. He specializes in scaling organizations from early-stage growth to $150 million, implementing people-first cultures and operational systems necessary for predictable, long-term growth. Most recently, Dillon served as CRO at Airlock Digital, where he led the GTM team and helped scale an Australian cybersecurity company globally. His extensive leadership pedigree also includes senior roles at industry leaders such as Saviynt, BeyondTrust, and Hewlett Packard Enterprise. "I am excited to join the team at Nudge Security," said Dillon. "In a market crowded by the noise of 'AI everywhere,' Nudge Security stands out with a clarifying approach to the attack surface. Effective AI governance begins and ends with visibility. While most legacy solutions are limited to what is inside their known ecosystem, Nudge Security provides the visibility to see what lies
Apr 29, 2026 · via prnewswire.com
MIDLAND, Mich. (WJRT) - Northwood University has been designated as a National Center of Academic Excellence in Cybersecurity by the National Security Agency, one of the nation's most respected recognitions for cybersecurity education. The designation recognizes accredited institutions that meet rigorous national standards for cybersecurity curriculum, faculty expertise, institutional support and student preparation. For Northwood University, the designation marks the culmination of a yearlong application process and affirms the strength of its Program of Study in Cybersecurity Management. "This National Security Agency designation is a powerful affirmation of Northwood University's commitment to academic excellence, workforce readiness, and the preparation of principled leaders in one of the most critical fields of our time," Academics Vice President and Provost Kristin Stehouwer said. Stehouwer said cybersecurity is essential to the protection of the economy, business continuity and way of life. Northwood is pleased to help prepare graduates who are ready to lead with integrity in this rapidly evolving field that requires technical knowledge, sound judgment, ethical decision-making and an understanding of the business environments cyber professionals are called to protect, she said. The NSA's National Centers of Academic Excellence in Cybersecurity program recognizes institutions that help advance the nation's cybersecurity education pipeline and prepare students with the knowledge and skills needed to protect and defend against cyber threats. CAE-designated institutions undergo an in-depth assessment and must meet rigorous requirements related to curriculum, faculty, institutional practices and cybersecurity education. "The designation announced this week validates both Northwood's Program of Study and Northwood University's broader institutional commitment to cybersecurity education," Academic Dean Stacey Tetloff said. Tetloff said the recognition is the result of sustained work by faculty and academic leadership to build a cybersecurity program that is rigorous, relevant and aligned with national standards. The designation follows the NSA's validation of Northwood's Program of Study
Apr 29, 2026 · via abc12.com
Cybersecurity Hiring Stalls, IT Leaders Face Corporate Pushback The Fortinet 2026 Global Cybersecurity Skills Gap Report identifies a critical shortage of technical talent as a primary driver of enterprise security breaches. While organizations adopt AI for defense, a lack of executive investment and specialized training creates significant financial and strategic risks. Eighty six percent of organizations experienced at least one security breach in previous years, while 49% of information technology leaders face corporate resistance when seeking to hire the talent necessary to mitigate AI-driven threats, reports Fortinet. The rising frequency and sophistication of cyberattacks correlate with a disconnect between board-level risk perception and budgetary allocation: companies are not scaling like cyberthreats are doing. "Cybersecurity is not simply a technical issue but a strategic business risk,” says Carl Windsor, CISO, Fortinet. “While boards generally recognize the importance of cybersecurity, more investment is needed to address key issues, such as rapidly accelerating AI risks and the ongoing cybersecurity skills shortage." The shortage of cybersecurity skills remains a leading cause of devastating security breaches for the third consecutive year. According to Fortinet, 56% of information technology (IT) leaders attribute successful intrusions to a lack of specialized personnel. This deficit occurs during a period of escalating financial consequences for the private sector. Fifty-two percent of organizations report that breaches cost more than US$1 million, which is a notable increase from the 38% reported in 2021. Within North America, the average cost of a breach has reached US$2 million. Organizational friction at the executive level hampers the ability of security teams to defend the enterprise. Although 51% of leaders indicate a requirement for senior-level cybersecurity skills, nearly half struggle to obtain the necessary approval for additional headcounts. This resistance persists despite the direct professional risks to leadership. The report reveals that 50% of executives and
Apr 29, 2026 · via mexicobusiness.news
Federal agencies should focus on strengthening three core cybersecurity functions — zero trust, vulnerability management and incident response — as artificial intelligence accelerates the pace and scale of cyberthreats, according to Victor Foulk, vice president of emerging technologies at CGI Federal. In a blog post on Tuesday, Foulk said AI is enabling adversaries to identify and exploit vulnerabilities faster, turning cybersecurity into a speed-driven operational challenge rather than a strategic shift. Why Is Zero Trust Critical? Foulk pointed to zero trust as the most immediate way to reduce risk, particularly as AI-driven attacks exploit weak identity controls and network segmentation. By enforcing strict identity verification and separating access across systems, zero trust limits the number of reachable targets and reduces the potential impact of a breach. It also improves visibility, making it easier to detect and contain intrusions early. How Should Agencies Approach Vulnerability Management? AI is compressing the timeline between discovering a vulnerability and exploiting it, making rapid prioritization essential. Foulk said agencies should focus on identifying which vulnerabilities pose real risk based on their environment, rather than attempting to remediate everything. This includes evaluating exposure, access paths and privilege levels. He added that when patching is delayed, agencies should rely on compensating controls such as segmentation, access restrictions and targeted monitoring to mitigate risk. What Needs to Change in Incident Response? Incident response must operate faster and with greater precision through automation to prevent threats from escalating. Foulk’s emphasized the importance of early containment, clear response protocols and predefined authorities, noting that agencies should balance speed with accuracy to avoid reacting to false signals while ensuring real threats are addressed quickly. Foulk’s focus on speed and coordination aligns with his previous remarks on the importance of data visibility, which enables faster decision-making and more effective automation while maintaining
Apr 29, 2026 · via executivebiz.com
Cybersecurity researchers have disclosed details of a critical security vulnerability impacting GitHub.com and GitHub Enterprise Server that could allow an authenticated user to obtain remote code execution with a single "git push" command. The flaw, tracked as CVE-2026-3854 (CVSS score: 8.7), is a case of command injection that could allow an attacker with push access to a repository to achieve remote code execution on the instance. "During a git push operation, user-supplied push option values were not properly sanitized before being included in internal service headers," per a GitHub advisory for the vulnerability. "Because the internal header format used a delimiter character that could also appear in user input, an attacker could inject additional metadata fields through crafted push option values." Google-owned cloud security firm Wiz has been credited with discovering and reporting the issue on March 4, 2026, with GitHub validating and deploying a fix to GitHub.com within two hours. The vulnerability has also been addressed in GitHub Enterprise Server versions 3.14.25, 3.15.20, 3.16.16, 3.17.13, 3.18.8, 3.19.4, 3.20.0, or later. There is no evidence that the issue was ever exploited in a malicious context. According to GitHub, the issue affects GitHub.com, GitHub Enterprise Cloud, GitHub Enterprise Cloud with Data Residency, GitHub Enterprise Cloud with Enterprise Managed Users, and GitHub Enterprise Server. At its core, the problem stems from the fact that user-supplied git push options are not adequately sanitized before the values were incorporated into the internal X-Stat header. Because the internal metadata format relies on a semicolon as a delimiter character that could also appear in the user input, a bad actor could exploit this oversight to inject arbitrary commands and have them executed. "By chaining several injected values together, the researchers demonstrated that an attacker could override the environment the push was processed in, bypass sandboxing protections
Apr 29, 2026 · via thehackernews.com
Dental offices are busy places. Computers sit everywhere, from the front desk to the operatory, and people don’t have much time to slow down and think about security. That’s why DPC Technology has worked to make protection part of the job, rather than something clients only think about after a problem pops up. Founded in 1995, DPC Technology built their business around supporting dental practices. CEO Clay Archer grew up around dentistry, and that familiarity shaped the company from the start. DPC understands how dental offices operate, what sets them apart from other businesses, and where small problems tend to escalate into costly ones. That’s why Archer can confidently say, “It’s not so much of a fair fight when we go in to compete against somebody.” Challenge | Too many machines and not enough visibility As DPC moved from break-fix work into managed services, they needed a security model that could hold up across a growing client base. That was especially important in dentistry, where one office can have far more devices than people. Archer says a typical practice may have roughly 1.5 to 1.75 times as many endpoints as humans, which means there are many machines to keep track of and many opportunities for something to fall out of view. This also raises the chances of problems on the user side. “People are just clickers,” says Archer. Before better protections were in place, he explains, dentists were getting hit with ransomware “like crazy.” Therefore, DPC needed a way to reduce that exposure without turning security into a separate debate every time a tool changed. Additionally, Microsoft Defender Antivirus was built into DPC’s clients’ environments. Archer notes that while Defender itself is strong, the problem was that, before Huntress, there was no practical way for DPC to manage it across
Apr 29, 2026 · via huntress.com
Explore the things
you love
.
Log into Facebook
Email or mobile number
Password
Log in
Forgot password?
Create new account
English (US)
Español
Français (France)
中文(简体)
العربية
Português (Brasil)
Italiano
More languages…
Sign Up
Log In
Messenger
Facebook Lite
Video
Meta Pay
Meta Store
Meta Quest
Ray-Ban Meta
Meta AI
Instagram
Threads
Privacy Policy
Consumer Health Privacy
Privacy Center
About
Create ad
Create Page
Developers
Careers
Cookies
Ad choices
Terms
Help
Contact Uploading & Non-Users
Meta © 2026
Apr 29, 2026 · via facebook.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 28, 2026 · via youtube.com
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 28, 2026 · via youtube.com
The federal agency's co-deputy director warns that rising cyberattacks are disrupting care delivery and straining operations. Cybersecurity has become a defining issue for hospital leaders as attacks on the industry continue to climb. Andrew Bailey, co-deputy director of the FBI, urged providers to elevate cyber risk within leadership priorities. His message, shared at the recent AHA Annual Meeting, aligns with new federal data that places healthcare at the center of criminal targeting. An FBI report found that healthcare and public health ranked as the most targeted sector for cyberthreats in 2025. The research documented 460 ransomware attacks and 182 data breaches, for a combined 642 incidents. Financial services had the second-most events with 447. Bailey described a threat environment shaped by organized cybercrime groups that focus on hospitals because of the urgency tied to care delivery. Disruptions tied to ransomware can delay treatment and strain operations during critical moments. "We’re no longer talking about a data crime,” Bailey said. “We’re talking about physical harm to patients." The growing volume of attacks has forced executives to confront cybersecurity realities. A breach now carries operational consequences that extend into patient care. When systems like electronic health records and medication platforms become unavailable, clinicians face delays that can affect outcomes. Bailey emphasized coordination between hospitals and federal agencies as a key step in addressing threats. Early reporting of suspicious activity allows law enforcement to track patterns and act against criminal networks before additional organizations are compromised. How Hospitals Can Respond For hospital leaders, the inevitably of cyber incidents necessitates that cybersecurity be embedded into enterprise risk strategy. That starts with ensuring board-level oversight and clearer accountability, aligning cyber preparedness with quality and safety initiatives. Resilience against operational disruption requires adequate preparation. Hospitals benefit from clinical continuity plans that include manual workflows, backup systems,
Apr 28, 2026 · via healthleadersmedia.com
A conversation with Barracuda Chief Product Officer Neal Bradbury on why proprietary data is the real moat when every customer's threat landscape is unique by Aly McGue Cybersecurity companies face a paradox. Their customers keep adding more security tools, expecting more protection. But the data increasingly shows that tool sprawl makes organizations slower to detect and respond to threats. At the same time, AI is accelerating both sides of the equation: giving defenders new capabilities while making it dramatically easier for attackers to operate at scale. For over twenty years, Barracuda has protected organizations from evolving threats with its BarracudaONE cybersecurity platform, which maximizes cyber resilience by unifying protection across email, ,data, networks, applications, and managed XDR. Barracuda uses Databricks for its enterprise data platform, consolidating fragmented data silos to power ML operations, real-time threat correlation, and business intelligence. Using Databricks Genie, the team quickly developed and launched features like natural language log search for its managed XDR solution, allowing customers to query billions of security events in plain language while maintaining strict data isolation. Neal Bradbury is Chief Product Officer at Barracuda, responsible for product management, engineering, security, and cloud operations. He has led the shift toward what Barracuda calls AI-native product development, in which intelligence is built into the core of every application rather than added as an interface on top. The thread running through our conversation was consistent: in an era where attackers operate at scale, the defenders winning with AI are those treating their proprietary security telemetry as a strategic asset. They aren't just adding AI tools; they are building intelligence directly into the data layer to stay ahead of evolving threats. Aly McGue: How do you define an "AI-native application" in your business versus a traditional application? What's the strategic difference for the customer experience?
Apr 28, 2026 · via databricks.com
What Anthropic’s Mythos Means for the Future of Cybersecurity Two weeks ago, Anthropic announced that its new model, Claude Mythos Preview, can autonomously find and weaponize software vulnerabilities, turning them into working exploits without expert guidance. These were vulnerabilities in key software like operating systems and internet infrastructure that thousands of software developers working on those systems failed to find. This capability will have major security implications, compromising the devices and services we use every day. As a result, Anthropic is not releasing the model to the general public, but instead to a limited number of companies. The news rocked the internet security community. There were few details in Anthropic’s announcement, angering many observers. Some speculate that Anthropic doesn’t have the GPUs to run the thing, and that cybersecurity was the excuse to limit its release. Others argue Anthropic is holding to its AI safety mission. There’s hype and counterhype, reality and marketing. It’s a lot to sort out, even if you’re an expert. We see Mythos as a real but incremental step, one in a long line of incremental steps. But even incremental steps can be important when we look at the big picture. How AI Is Changing Cybersecurity We’ve written about shifting baseline syndrome, a phenomenon that leads people—the public and experts alike—to discount massive long-term changes that are hidden in incremental steps. It has happened with online privacy, and it’s happening with AI. Even if the vulnerabilities found by Mythos could have been found using AI models from last month or last year, they couldn’t have been found by AI models from five years ago. The Mythos announcement reminds us that AI has come a long way in just a few years: The baseline really has shifted. Finding vulnerabilities in source code is the type of task
Apr 28, 2026 · via schneier.com
Ramirez Statement on Being Appointed Top Democrat in the CHS Cybersecurity and Infrastructure Protection Subcommittee Washington, DC — Today, Congresswoman Delia C. Ramirez (IL-03) released the following statement after being appointed as Ranking Member of the Cybersecurity and Infrastructure Protection Subcommittee of the House Homeland Security Committee: “Under Trump, Vance, Mullin, and Miller, it’s clear that the security of our communities’ information, federal networks, and critical infrastructure have not been priorities. Between the security failures of DOGE, the abuses of immigrant families’ data, and the decimation of CISA’s workforce and resources, Republicans have demonstrated a lack of interest in safeguarding our nation’s cybersecurity and our residents’ civil rights and privacy. In neglecting necessary oversight, Republicans have deregulated emerging technologies, allowed bad actors to profit from violations of our civil rights, and consented to the weaponization of government systems. It is more critical than ever that we assert our Congressional authority and disrupt the blatant corruption making us all less safe. I am thankful for my colleagues' trust in my track record of conducting oversight and holding the Trump administration and Republicans accountable. There is much work to do, and I am ready to roll up my sleeves and get to work to protect our data, rights and privacy, defend CISA’s mission, and dismantle DHS.”
Apr 28, 2026 · via ramirez.house.gov
Anthropic’s new initiative—“Project Glasswing,” announced in April 2026—reflects a significant development in the cybersecurity landscape that should command the immediate attention of every C-suite leader, privacy officer, information security professional, and compliance executive in health care and life sciences, financial services and other critical infrastructure industries, and their legal counsel. Project Glasswing is a coalition of leading technology and cybersecurity providers united around a single urgent objective: deploying frontier artificial intelligence (AI) capabilities using Anthropic’s unreleased Mythos Preview AI model for defensive cybersecurity before malicious actors can exploit similar capabilities offensively to attack first party and open source software. The Mythos Preview model and similar autonomous AI capabilities in current and future tools are transforming the cybersecurity risk landscape given the rapid recent development in and accessibility of AI. The Mythos Preview model was able to detect thousands of critical, previously unknown security vulnerabilities, including flaws in every major operating system and web browser. These systems are essential to our interconnected electronic systems and ability to communicate securely. Some of those vulnerabilities, according to Anthropic, had survived undetected for decades. That model is now being deployed as part of Project Glasswing to a select group of organizations under carefully controlled conditions to protect the world's most important and foundational software. The initiative explicitly acknowledges, however, that if these capabilities are not harnessed for defense now, they could be weaponized against critical infrastructure—including health care, financial services, and the Internet. Although AI-driven threat detection and other defensive platforms are well-established solutions, Project Glasswing foreshadows a new era where autonomous AI becomes a potentially omnipotent weapon in the wrong hands. All critical infrastructure organizations should reassess their cybersecurity governance models and information risk frameworks and processes to ensure that they remain legally compliant to address the impact of AI on the cyberthreat
Apr 28, 2026 · via natlawreview.com
The Army has relaxed requirements for its cybersecurity awareness and information privacy training from an annual recertification to once every five years, according to a memo from the Army’s chief information officer. The change took effect Feb. 27, according to the memo from Leonel Garciga posted on his official LinkedIn account that day. “The Army is making a change that gives Soldiers and civilians more time to focus on their core missions,” said an announcement on the Army Chief Information Officer LinkedIn account. The memorandum was published on the Army Publishing Directorate website, with similar announcements posted on social media platforms Facebook and X. “The update supports broader efforts across the Department of War to reduce mandatory training requirements and restore mission focus,” the LinkedIn post states. Cybersecurity training originated with the Federal Information Security Modernization Act of 2014. The act required federal agencies to implement security programs and provide training to inform users of the risks associated with their activities and their responsibility to comply with preventative measures. The change to five-year training was also publicized in a March 27 post on the Army Chief Information Officer’s account on X. Garciga’s office did not respond to requests for comment by email April 21. Defense Secretary Pete Hegseth in a memo Sept. 30 called on each military branch to “relax the mandatory frequency for cybersecurity training.” The memo also called for reduced frequency of Privacy Act training that refreshes the user’s familiarity with how to identify and safeguard personally identifiable information. An Army veteran and cyber specialist, who requested anonymity because he fears reprisal for publicly criticizing the new policy, said the previous training already saved time for vigilant users by giving them the option to test out. “The worst part about the mandate is that it still requires the
Apr 28, 2026 · via stripes.com