As AI and technology adoption accelerates across enterprises, organizations are increasingly grappling with how to govern and secure emerging technologies, particularly with the rise of agentic AI and autonomous systems. In parallel, expanding digital ecosystems are increasing interconnectivity across systems and data flows, reshaping how enterprises operate. This is driving a rethink of digital transformation strategies, as cyber defense moves beyond perimeter protection towards more embedded, continuous resilience across the organization. In Malaysia, the cyber threat landscape in 2026 is becoming more complex, driven by increasingly sophisticated threat actors and rising cyber activity targeting both enterprises and critical infrastructure. Greater reliance on cloud services, data platforms, and third-party ecosystems is deepening systemic exposure across industries. At the same time, Malaysia’s ambition to become an AI-driven nation by 2030 is accelerating national focus on governance and risk oversight, supported by initiatives such as the MY-AI Standards platform and the updated National Cryptography Policy (NCP 2025), which strengthens digital sovereignty and protection of critical national infrastructure. The KPMG Cybersecurity Considerations 2026 highlights how organizations are navigating a rapidly evolving risk environment. It underscores eight key priorities around resilience building, cyber exposure management, and enabling secure AI adoption within enterprise environments. From a CISO perspective, cybersecurity now extends beyond traditional perimeter defense, with the role becoming increasingly front-line and decision-critical – focused on anticipating disruption, enabling faster response, and continuously adapting defense mechanisms in step with evolving digital and AI-driven risk. Eight key cybersecurity considerations for 2026 Cybersecurity considerations 2026 Building trust and enabling innovation in a dynamic world
Apr 28, 2026 · via kpmg.com
Cybersecurity adapts to the AI era April 28, 2026 By Peter Saunders Talking Points Cyberattacks on critical infrastructure are accelerating in the age of artificial intelligence (AI), according to Axis Communications’ annual cybersecurity summit, which was held today in Mississauga, Ont. Wayne Dorris (pictured, top left), the company’s cybersecurity program manager for the Americas, set the stage by reflecting on such major attacks as Volt Typhoon’s KV-botnet in 2022 and the Raptor Train botnet in 2024, as well as discussing military and defence departments’ success in hacking Internet Protocol (IP) cameras and manipulating video in areas of conflict, including Ukraine, Israel and Iran. He referenced a 2025 device security threat report from Palo Alto Networks, which showed IP cameras are often ‘unpatched’ and running outdated firmware. Globally, some 35 million IP cameras are exposed. When Axis learned of such vulnerabilities in some of its products, it developed a patch within 10 days and communicated the need for updates to its regional partners. Still, some customers said they would no longer use their cameras. Now, AI has demanded its own response, as platforms like Claude Mythos can discover bugs and exploit systems. “AI has induced attacks at higher speed,” Dorris said. “The AI models have reached coding capacity where they can surpass all but the most skilled people at finding and exploiting software vulnerabilities.” Indeed, Axis is now patching more than 10 vulnerabilities every day. Dorris was followed by Shi-lin Chan (pictured, top right), the company’s chair of cybersecurity communications, who provided a message of reassurance by highlighting how Axis not only meets international cybersecurity regulations, but goes beyond them. These include the European Union’s (EU’s) Cyber Resilience Act and Network and Information Security 2 (NIS2) Directive and, in the U.S., the Cybersecurity and Infrastructure Security Agency’s (CISA’s) Secure By Design
Apr 28, 2026 · via canadianconsultingengineer.com
As cyber threats grow, states are continuing to explore ways to better support local governments. A recent example comes from Florida, where state lawmakers have advanced legislation to formalize a statewide cybersecurity assistance program for local jurisdictions. As covered in a Government Technology article, following the close of the Florida 2026 legislative session, House Bill 1085 has been sent to the Governor for final consideration. If enacted, the bill would take effect July 1 and establish the Local Government Cybersecurity Protection Program (LGCPP) within the Florida Digital Service. The program would codify and expand upon existing efforts by the state to provide cybersecurity assistance to local governments by offering access to state-provided services and coordinated support. Under the proposed program, participating local governments would receive cybersecurity capabilities such as: - Asset discovery and inventory tools - Endpoint detection and response systems - Security operations platforms - Additional cybersecurity monitoring and protection services In exchange, local governments would agree to share certain telemetry data with the state’s cybersecurity operations center, a provision aimed at strengthening statewide threat awareness and response coordination. The program would be authorized through July 1, 2031. From the Government Technology article: A bill analysis shows that in fiscal year 2025-26, 199 local governments have received $65.1 million in state cybersecurity support, paying for a list of capabilities, including asset discovery inventory, endpoint detection and response, security operation platforms, and security systems. These efforts complement prior budget-driven initiatives; since fiscal year 2022-23, the state has funded similar cybersecurity support efforts through annual appropriations. Read the full Government Technology article.
Apr 28, 2026 · via conduitstreet.mdcounties.org
CLARKSBURG, W.Va. — The insurer for Harrison County brought a team in to restore computer and internet service for county agencies and also will help investigate a cybersecurity incident that crippled county services late last week and early this week. The FBI also has been contacted, Harrison County Commission President Susan Thomas said. As of Tuesday, some services were being restored, including the ability to pay taxes online, Thomas said. She added that paychecks also would be issued on time for release Thursday to county employees. County Administrator Laura Pysz released a brief statement saying that the commissioners know the situation “is frustrating and that our community wants clear answers. We do, too. We are committed to being open and transparent and will share confirmed information as soon as we have it. Right now, because this is an active investigation, it is important that we do not speculate or share unverified details that could compromise the process or our system security.” The team brought in by the insurance company is “going to make recommendations” once services are back up to prevent this from happening again, Thomas said; the county suffered a similar cybersecurity incident about seven years ago. “I won’t stop until we follow through, or someone gives us some advice and says, ‘This is what you need to do,’” Thomas added. While some services are returning to digital availability, residents are still encouraged to call county offices ahead of time to confirm specific departments are fully operational before making a trip in person. You must be logged in to react. Click any reaction to login. You must be logged in to rate. Click any rating to login. Keep it Clean. Please avoid obscene, vulgar, lewd, racist or sexually-oriented language. PLEASE TURN OFF YOUR CAPS LOCK. Don't Threaten. Threats of
Apr 28, 2026 · via wvnews.com
CCNDR to expand cybersecurity resources for non-profits with new CoLab In a recent survey of 8,000 non-profits, CCNDR also found that equity-denied organizations face significant barriers in digital skills and training. Why It Matters The Canadian Centre for Nonprofit Digital Resilience (CCNDR) began as a collective between seven co-founding organizations and is now housed within Imagine Canada. Over the next three years, CCNDR will focus on supporting the non-profit sector with data management and literacy, cybersecurity awareness, and emerging technologies like AI. The Canadian Centre for Nonprofit Digital Resilience (CCNDR) will be launching a new cybersecurity CoLab for the non-profit sector this year. Increasing cybersecurity awareness in the social purpose space will be one of CCNDR’s focus areas over the next three years, based on a national survey of 8,000 non-profits. “We hear very loudly and clearly that cyberrisk is very strong in the sector, and there is a major gap there for non-profits that they don’t know how to grapple with,” said Wilfreda Edward, executive director of CCNDR. Non-profits often handle “deeply personal data” about individuals’ health, immigration status, and housing, and “yet are among the least resourced to protect it,” CCNDR wrote in its new strategic plan. The CoLab model brings together non-profit practitioners and technical experts to design technology solutions for the needs of non-profits and charities. CCNDR’s first CoLab, focused on AI upskilling, gives non-profits access to self-paced learning and credentials. CCNDR is also working on providing Canadian non-profits with a cybersecurity readiness pathway to better equip organizations to respond and recover should their systems be compromised, Edward said. CCNDR’s national survey, carried out with Open North, also found that non-profits want to work with what they already have rather than looking for additional tools or new staff. According to Edward, non-profits are already “inundated with
Apr 28, 2026 · via futureofgood.co
The Pine Bluff School District lost more than $3.2 million in a Dec. 17 cybersecurity incident that has since come under federal investigation, Superintendent Jennifer Barbaree said Monday. During the district board’s monthly meeting, Barbaree said the district processed a wire transfer of $3,204,639.55 for what she said “was believed to be a legitimate invoice from a trusted vendor as part of the district’s ongoing construction project.” The district is nearing completion of its new high school campus at its original location on West 11th Avenue. “The director of finance contacted the vendor to confirm receipt of payment and learned the company had sent the invoice for construction services rendered, but the company had not requested the invoice to be paid via wire transfer,” Barbaree said, reading from a statement. “It was discovered this incident was the result of a sophisticated cyberattack. A district email employee account had been compromised, and, while a legitimate invoice had been received, fraudulent wiring instructions were later introduced in the same email thread through a phishing scheme designed to closely mimic authentic communications.” The district acted immediately as the finance director notified the bank; law enforcement was engaged “without delay,” Barbaree continued. “Because this was an active federal investigation involving a cybercrime, we were directed to maintain strict confidentiality,” Barbaree said. She later clarified the FBI was investigating. “Sharing details publicly at this time could have compromised the investigation and potentially hindered efforts to recover the funds by law enforcement. For that reason, we were not able to provide updates sooner.” Independent reporting for Pine Bluff & Jefferson County since 1881. The investigation, Barbaree added, is largely complete and “a substantial portion” of the stolen funds could be recovered within the next two weeks. The exact amount, however, has not been finalized by authorities,
Apr 28, 2026 · via pbcommercial.com
Optimal Spending on Cybersecurity Measures Collection Offers a Strategic Roadmap for Smarter Cyber Risk Investment Optimal Spending on Cybersecurity Measures Collection Offers a Strategic Roadmap for Smarter Cyber Risk Investment Press Release Date 04-27-2026 Cybersecurity and Risk Management Author Helps Organizations Align Security Spend With Privacy, Compliance, DevOps, Health Info & Third Party Risk NEW YORK CITY, NY, UNITED STATES, April 27, 2026 /EINPresswire.com/ -- As cyber threats continue to evolve and organizations face growing pressure to protect sensitive data, author Tara Kissoon delivers a timely and practical collection through her Optimal Spending on Cybersecurity Measures series. Across titles focused on risk management, health information, digital privacy and data protection, DevOps, third party risk management, and AI, Kissoon examines one of the most critical questions facing modern organizations: How can leaders make smarter decisions about cybersecurity investments? The collection explores the strategic choices organizations make when implementing cybersecurity controls, particularly when budget limitations, regulatory requirements, business priorities, and stakeholder expectations compete for attention. Kissoon introduces readers to business-driven risk assessments, cyber risk investment models, and cybersecurity risk management frameworks that can help organizations evaluate security initiatives with greater clarity and accountability. Rather than treating cybersecurity as a purely technical issue, Kissoon positions it as a business risk management challenge. Her work addresses how organizations can assess the value of security measures, determine funding priorities, and demonstrate compliance with privacy laws, data protection requirements, government regulations, and industry standards. Through case studies and applied frameworks, the books provide readers with a practical view of how cybersecurity decisions are made inside real organizational environments. Kissoon’s inspiration for the collection comes from the growing need for leaders to bridge the gap between compliance obligations and meaningful security investment. As organizations continue to rely on cloud systems, DevOps practices, health data platforms, third party
Apr 28, 2026 · via natlawreview.com
Cybersecurity and Risk Management Author Helps Organizations Align Security Spend With Privacy, Compliance, DevOps, Health Info & Third Party Risk NEW YORK CITY, NY, UNITED STATES, April 27, 2026 /EINPresswire.com/ — As cyber threats continue to evolve and organizations face growing pressure to protect sensitive data, author Tara Kissoon delivers a timely and practical collection through her Optimal Spending on Cybersecurity Measures series. Across titles focused on risk management, health information, digital privacy and data protection, DevOps, third party risk management, and AI, Kissoon examines one of the most critical questions facing modern organizations: How can leaders make smarter decisions about cybersecurity investments? The collection explores the strategic choices organizations make when implementing cybersecurity controls, particularly when budget limitations, regulatory requirements, business priorities, and stakeholder expectations compete for attention. Kissoon introduces readers to business-driven risk assessments, cyber risk investment models, and cybersecurity risk management frameworks that can help organizations evaluate security initiatives with greater clarity and accountability. Rather than treating cybersecurity as a purely technical issue, Kissoon positions it as a business risk management challenge. Her work addresses how organizations can assess the value of security measures, determine funding priorities, and demonstrate compliance with privacy laws, data protection requirements, government regulations, and industry standards. Through case studies and applied frameworks, the books provide readers with a practical view of how cybersecurity decisions are made inside real organizational environments. Kissoon’s inspiration for the collection comes from the growing need for leaders to bridge the gap between compliance obligations and meaningful security investment. As organizations continue to rely on cloud systems, DevOps practices, health data platforms, third party service providers, and AI, the risks surrounding sensitive information have become increasingly complex. Her books respond to this challenge by offering structured methods for evaluating risk, protecting data, and supporting informed decision-making. The series
Apr 28, 2026 · via dispatch.com
Essential Skills for Cybersecurity Analysts News from NYC's Top Cybersecurity Master's Program 15 Essential Cybersecurity Analyst Skills According to the International Monetary Fund (IMF), cyber attacks continue to rise globally, driving increased demand for cybersecurity professionals.¹ That explains why the demand for cybersecurity experts is at an all-time high, and it's expected to continue to grow.² If you want to start or advance your career as a cybersecurity analyst, now may be the best time to make a move. Keep reading to discover the top cybersecurity analyst skills you need to succeed. Cybersecurity analysts combine technical expertise with analytical thinking and communication skills. The most successful professionals develop strengths across several areas, including threat detection, risk management, cloud security, and incident response. The following guide highlights 15 essential cybersecurity analyst skills and explains why each one matters in modern security teams. Technical Cybersecurity Skills 1. Threat Intelligence Analysis With threat intelligence analysis skills, you can gather and analyze security information from multiple external sources, including in-depth cybersecurity reports from reputable organizations. The aim is to spot patterns that provide insights into common cybersecurity threats, such as phishing and ransomware. The ability to conduct an in-depth threat analysis helps you reveal:³ - Specific cyber threats a company faces and the assets that are exposed - Techniques cybercriminals might use to target the organization - Signs of a particular attack - Actionable ways to prevent or remediate cyber threats 2. Incident Response Preventing attacks is the main goal of cybersecurity. But when data breaches do occur, knowing what to do can help minimize the damage and losses. With incident response cybersecurity expertise, you'll understand how to identify, contain and resolve different types of cyber attacks. This can help your organization mitigate security incidents before they escalate. Common incident response technologies include:⁴ -
Apr 28, 2026 · via yu.edu
WA digital drivers licence trial sparks cybersecurity concerns from expert In short: A cybersecurity expert is worried about potential security concerns when Western Australia rolls out a trial of digital drivers licences in the middle of next year. Curtin University's Dr Reza Ryan has told the ABC the data protection technology for digital credentials is not protected well enough yet to be rolled out on a mass scale. But another cybersecurity expert believes smartphones are equipped with enough security features to ensure people can have faith in the technology. A cybersecurity expert has warned people's privacy and security could be at risk once Western Australia rolls out its new digital drivers licences. The state government announced last week that a trial of the system would begin in the middle of 2027, with the aim of a wider rollout by the end of the year. Curtin University's Dr Reza Ryan said the centralised nature of these databases would create one giant honey pot of data for potential hackers. "If they hack that centralised system, they can get access to all the information about the people … the system could eventually be used for broader surveillance and to track individuals," he said. Dr Ryan told the ABC the data protection technology for digital credentials was not protected well enough yet to be rolled out on a mass scale. "Many existing Australian digital licenses do not meet the international security standard, making it more vulnerable to fraud rather than being safer," he said. The app that will store the digital licence, ServiceWA, uses "on-app holograms" as a security measure to arm devices against potential forgery. But Dr Ryan warned against these holograms, which he believes are not up to an industry standard that was advanced enough to be protected against frauds carried out
Apr 27, 2026 · via abc.net.au
Massachusetts Attorney General Names MET Senior Associate Dean Lou Chitkushev to State’s Cybersecurity-Minded Health Information Council Dr. Lou Chitkushev—Boston University MET College’s senior associate dean for academic affairs, director of health informatics and health sciences, and professor of computer science—has been appointed to the Massachusetts Center for Health Information and Analysis (CHIA) Oversight Council by Attorney General Andrea Campbell. A leading scholar in the intersection of technology and healthcare, Dr. Chitkushev will bring his considerable health informatics and cybersecurity expertise to the 11-person council, where he will serve a five-year term overseeing the independent state agency tasked with “promoting a transparent and equitable healthcare system across the Commonwealth,” according to a press release. CHIA, which in 2025 boasted 200 employees and a $33 million budget, seeks to advance a healthcare system where mutual, accessible, trusted information security sets a foundation for common progress, giving Massachusetts residents and organizations the confidence they need to make sound, informed decisions pertaining to healthcare. As an independent agency, CHIA is uniquely positioned to serve the public interest. According to the release, “CHIA’s independence ensures that its agenda and findings are guided by the public good, free from industry or political influence.” It aims to achieve its goals through the use of the “unparalleled” datasets the agency is able to collect as part of its mission. As a member of the CHIA Oversight Council, Dr. Chitkushev will help supervise CHIA’s budget allocations while providing strategic guidance on its research and analytics. The cofounder and associate director of Boston University’s Center for Reliable Information Systems & Cyber Security (RISCS), Dr. Chitkushev brings a wealth of qualifications to the opportunity. He cofounded what is now the BU MET MS in Health Informatics program, and previously helped Boston University earn its designation as a Center of Academic Excellence
Apr 27, 2026 · via bu.edu
Guarding Goals, Protecting Systems: Embry-Riddle Soccer Star Excels in Cybersecurity Natalia Sepulveda (’26) is known for her composure, discipline and ability to lead on the soccer field. As a defender and team leader for Embry-Riddle Aeronautical University’s Prescott women’s soccer team, she protects her teammates with the same vigilance and foresight she brings to her studies in Cyber Intelligence and Security. Together, those traits have defined a comeback story rooted in resilience, purpose and belief. Sepulveda is pursuing a Master of Science in Cyber Intelligence and Security. In January 2026, she was named a first-team All-American by the United Soccer Coaches Association, helping lead Embry-Riddle to a national semifinal run and marking a historic milestone for the program. A Journey Shaped by Resilience Her path to that moment was anything but straightforward. A first-generation college graduate with a bachelor’s degree in Criminal Justice, Sepulveda always knew she wanted to continue her education. With remaining athletic eligibility, she saw graduate school as both a second chance in soccer and a strategic step forward. Sepulveda’s journey to Prescott included stops at other universities, where she competed at the Division I level and earned an invitation to train with the Mexico U-21 Women’s National Team. But her experience later took a difficult turn. She faced challenges that led to self-doubt and a loss of passion for the sport she had played since age 10. She stepped away from soccer, unsure if she would ever return. But the feeling that her story was unfinished stayed with her. A native of Tucson, Arizona, Sepulveda grew up playing soccer alongside athletes who chose Embry-Riddle, though she initially looked elsewhere while exploring her academic path. “Something in my gut told me Embry-Riddle would be the perfect fit for soccer and school,” she said. When Embry-Riddle Head Coach
Apr 27, 2026 · via erau.edu
Expert seeks unified cybersecurity standards to protect critical infrastructure Olorunfemi Agoye, a technology strategist and cybersecurity consultant, has restated the need for a unified cybersecurity approach to protect Nigeria’s critical infrastructure. Mr Olorunfemi said this on Monday in an interview, emphasising the cyberattacks on recent government agencies and financial institutions, which he described as deep structural weaknesses. He said cybersecurity was a national security imperative, stating that a digital economy without it is “like a city without law and order”, making it highly vulnerable. “Exposures involving the Corporate Affairs Commission, Sterling Bank, Remita, and Lagos State University have revealed a pattern that cuts across critical layers of Nigeria’s digital ecosystem. “What they collectively expose is not just vulnerability at the institutional level, but fragility at the architectural level. Digital systems across the public and private sectors often operate in silos. This fragmentation creates multiple points of weakness, entry points that sophisticated threat actors can exploit,” he said. He said the infrastructure supporting Nigeria’s accelerated digital transformation has not evolved, which could result in rapid growth of the digital landscape, and that this growth is marked by imbalance and systemic risks. He noted that while frameworks such as the National Cybersecurity Policy and Strategy 2021 provided a foundation, there was a need for more consistent implementation, enforcement and continuous validation. “All critical systems, public and private, must meet clearly defined baseline security requirements, supported by regular audits, real-time monitoring and mandatory compliance mechanisms. However, standards on their own are not enough; what matters is how effectively they are implemented,” he said. Mr Olorunfemi, who also works at the intersection of digital trust for the National Information Infrastructure Protection, also called for cross-sector coordination of digital security. He stressed that cybersecurity must be managed as a shared national responsibility, not an institutional
Apr 27, 2026 · via gazettengr.com
Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the company on the dark web. "Based on current evidence, we believe this data originated from Checkmarx's GitHub repository, and that access to that repository was facilitated through the initial supply chain attack of March 23, 2026," the Israeli security company said. It also emphasized that the GitHub repository is maintained separately from its customer production environment, adding that no customer data is stored in the repository. Checkmarx said its forensic probe into the incident is ongoing and that it's actively working to verify the nature and scope of the posted data. Furthermore, the company said it has locked down access to the affected GitHub repository as part of its incident response efforts. "If we determine that customer information was involved in this incident, we will notify customers and all relevant parties immediately," it said. The development comes after the Dark Web Informer shared in an X post that the LAPSUS$ cybercrime group claimed three victims on its data leak site, one of which includes Checkmarx. The data, per the listing, contains source code, employee database, API keys, and MongoDB/MySQL credentials. Checkmarx suffered a breach late last month following the Trivy supply chain attack, as a result of which two of its GitHub Actions workflows and two plugins distributed via the Open VSX marketplace were tampered with to push a credential stealer capable of harvesting a wide range of developer secrets. The threat actor known as TeamPCP claimed responsibility for the attack. Last week, the financially motivated group is suspected to have compromised Checkmarx's KICS Docker image, along with the two VS Code extensions and a GitHub Actions workflow with a similar credential-stealing malware. This, in
Apr 27, 2026 · via thehackernews.com
Integrated Owner-Hosted Community Network Architecture and AI-Driven Cybersecurity Deliver Secure Core-to-Edge Infrastructure for Municipalities and Enterprises NEWPORT BEACH, CA, UNITED STATES, February 25, 2026 /EINPresswire.com/ — Tradewinds Networks, Inc., a next-generation technology developer and systems integrator delivering secure, AI-enabled network and cybersecurity ecosystems, and battery energy storage systems, today formally introduced its smart city integrated infrastructure platform following nearly a year of operational development, ecosystem alignment, and architectural validation. Since beginning operations in early 2024, Tradewinds Networks has focused on building and refining its Owner-Hosted Community Network (OHCN) architecture, formalizing strategic technology relationships with Dell Technologies, Intel, Ecrio, AA Strategies, and Aviz Networks, and advancing deployment-ready frameworks for secure edge AI applications and private PLTE/5G environments. The company now formally introduces its platform to support multi-tenant facilities, municipalities, aviation hubs, manufacturing environments, utilities, and defense-adjacent operations seeking resilient, community-aligned digital infrastructure. “Over the past year, our priority has been disciplined execution – architecting, validating, and integrating the components required to deliver secure, sovereign infrastructure from the core to the edge,” explained Keith Alexis, President and CTO of Tradewinds Networks. “With our ecosystem aligned and our platform operationally refined, we are formally introducing Tradewinds Networks to scale this model nationally and globally.” Year-One Milestones and Validation During its first year of operations, Tradewinds Networks: • Developed and operationalized its Owner-Hosted Community Network (OHCN) governance and infrastructure framework; • Integrated GuardTower™, its AI-driven proactive cybersecurity platform, into core-to-edge network infrastructure; • Established strategic technology alignment with Dell Technologies, Intel, Aviz Networks, and Ecrio; • Engaged community resources to ensure alignment with the United Nations SDG features, future IoT capabilities, and Digital Navigator training; • Built deployment-ready designs for private LTE/5G and edge AI environments with AA Strategies and Silent Partners Communications; • Advanced infrastructure planning across municipal and enterprise use cases. This
Apr 27, 2026 · via blufftontoday.com
Cybersecurity incident at contractor building JRL stations and NEWater factory Sign up now: Get ST's newsletters delivered to your inbox SINGAPORE – A cybersecurity incident has been reported at the contractor responsible for building three Jurong Region Line (JRL) MRT stations and the new Changi NEWater Factory 3. Data relating to the two projects was compromised at Shanghai Tunnel Engineering Co (Singapore), a civil engineering and construction company, although it is unclear when this had taken place. In response to queries on April 27, the Land Transport Authority (LTA) said it is aware of the incident, which has since been reported to the police and the relevant authorities. The authority added that the incident has not impacted the ongoing construction of the MRT line, and that it has temporarily suspended the construction company’s access to LTA’s digital systems as a precaution. Meanwhile, national water agency PUB said Shanghai Tunnel Engineering Co (Singapore) has no access to its digital systems. Its investigation showed that no sensitive data pertaining to the Changi NEWater Factory 3 had been stolen, with the compromised data consisting of project tender documents. These documents are publicly available on the government procurement portal GeBIZ, said a PUB spokesman, who stressed that the agency takes a “serious view” of cybersecurity and has reminded the contractor to review its measures. Checks by The Straits Times, including on ransomware portals and hacker forums where stolen data is typically leaked, yielded no results. Shanghai Tunnel Engineering Co (Singapore) told ST on April 28 that it recently identified a cybersecurity incident and took immediate steps to contain the situation. It did not state when the incident happened. The company added that it is working with an external cybersecurity specialist to support its investigation. “We are cooperating fully with the relevant authorities and kindly
Apr 27, 2026 · via straitstimes.com
‘Not just an IT issue’: the human threat to cybersecurity Organisations could be better protected from cybercrime by investing in more leadership and staff decision-making, a University of Queensland study has found. Dr Ivano Bongiovanni (pictured below) from the UQ Cyber Research Centre sat down with UQ News to discuss key findings from new research showing technology alone can’t improve cybersecurity. In our Q&A, Dr Bongiovanni shares why business leaders must ensure cybersecurity becomes a shared responsibility to better protect their organisations and the customer data entrusted to them. Why do organisations with seemingly strong cybersecurity still experience data breaches? Cybersecurity is not just a technology problem – it’s a technology, people and process problem. Investing in technical controls is essential, but it’s only one part of the picture. Organisations also need to invest in staff capability and effective internal processes. A common saying in cybersecurity is that defenders need to be right all the time, while attackers only need to be right once. That imbalance makes breaches difficult to prevent entirely. What role do human factors play in cybersecurity failures? Human factors are under-recognised when it comes to shaping effective cybersecurity policies, but they are one of the most complex challenges because every person in an organisation has a different level of awareness and understanding of what safe behaviour looks like. Our research involved interviewing people across different organisational roles – from operational security employees to senior executives and board members – and we found cybersecurity decisions are influenced by a wide range of factors, from industry regulations to individual attitudes and behaviours. Even in small organisations, staff turnover, lack of training and inconsistent awareness can create vulnerabilities. In larger organisations, the scale of the workforce multiplies the challenge. How has new technology like AI changed the risk landscape?
Apr 27, 2026 · via news.uq.edu.au
New AI-native cybersecurity model bridges static governance frameworks and the speed of AI-driven attacks for organizations of any size. OAKBROOK TERRACE, IL, UNITED STATES, April 27, 2026 /EINPresswire.com/ -- In Balance IT Solutions, a trusted provider of managed IT and cybersecurity services, today announced the launch of Adaptive Defense, a cybersecurity model that transforms how organizations detect and neutralize AI-driven threats. Adaptive Defense is purpose-built to help organizations and their security teams bridge the growing gap between established governance frameworks and the emerging operational reality of AI-driven attacks, automated reconnaissance, and dynamic threat environments. “Governance frameworks like NIST and COBIT remain essential foundations for compliance,” said David Malcom, cybersecurity practice leader at In Balance IT. “But they were never designed to defend against autonomous AI-driven adversaries operating at machine speed. Adaptive Defense evolves those frameworks into living, AI-enabled security systems that detect, learn, and respond in real time.” By mapping traditional controls to continuous telemetry, Adaptive Defense transforms static compliance checklists into dynamic, self-learning security systems. “C-suites are being rightly told that threat vectors are multiplying, necessary dwell times are shrinking, and they need to be agentic,” said Tim Currie, chief strategy officer for In Balance IT. “But they still have to comply with the established frameworks for governance. We want to connect the dots for our customers between studying for the test and actually being cyber-secure in an agentic world.” The model centers on three core pillars: • Adaptive Defense built on five core competencies of Identity-First Security and Resilience, Adaptive Threat Detection and Autonomous Response, Data Protection and Loss Prevention (DLP), Cloud and Multi-cloud Security (CNAPP), and Internal AI/Agentic Controls. • The Adaptive Defense Human-AI Operating Model for SOC transformation, upskilling and AI/Agentic Adoption. • Continuous Compliance that maps the real-world agentic SOC operations to the traditional control
Apr 27, 2026 · via norfolkdailynews.com
UNC6692 abused Microsoft Teams interactions to deliver the Snow malware toolkit Attackers tracked as UNC6692 used email bombing followed by Microsoft Teams helpdesk impersonation to pressure targets into installing a fake patch. The payload chain delivered SnowBelt, a malicious browser extension, alongside SnowGlaze, a tunneler, and SnowBasin, a Python backdoor used for command execution and covert communications. The intrusion chain relied on scheduled tasks, startup-folder persistence, a headless Microsoft Edge instance, and WebSocket tunneling to hide activity and maintain access. Threat reporting said the operators used this approach to pursue credential theft, deep network compromise, and domain takeover, which makes the campaign more than a simple phishing incident. The broader implication is that Teams and remote support workflows have become primary attack surfaces, especially when employees are used to interacting with IT staff through chat and remote assistance. Because the operators leaned on legitimate tools and administrative protocols, post-compromise activity can blend into normal support activity and delay detection. Bitwarden confirmed a short-lived supply chain compromise affecting its CLI npm package A malicious @bitwarden/cli version 2026.4.0 was briefly distributed through npm on April 22, 2026, after attackers compromised the package’s delivery path. Bitwarden said the incident affected only the npm distribution mechanism for the CLI during a limited window and that it found no evidence of impact to vault data, production data or production systems. Reporting said the malicious package added a custom loader and credential-stealing logic capable of harvesting secrets from developer environments and potentially spreading into other projects. The incident was linked to a broader developer-tooling supply-chain campaign, which increases the risk because poisoned builds can move from one workstation into CI/CD systems and downstream releases. This matters operationally because password managers, CLIs, and package managers sit close to secrets, automation pipelines, and deployment workflows. A short-lived compromise
Apr 27, 2026 · via acronis.com
The US cybersecurity agency CISA has once again issued a warning about security vulnerabilities in digital signage infrastructures. Among the affected systems is Samsung Magicinfo, a widely used digital signage platform. What makes this case particularly concerning: the exploited vulnerabilities are not new. Samsung already released patches back in August 2024. Cybersecurity: US Agency Warns of Digital Signage Vulnerabilities Security warnings related to enterprise software are currently increasing across industries. In this case, CISA points to an older vulnerability in the Samsung Magicinfo Server that still exists in the field. Despite the availability of patches for nearly two years, numerous on‑premise Magicinfo servers remain unpatched, prompting renewed concern from US authorities. On-Premise Security Depends on Patch Discipline This situation highlights one of the core weaknesses of on‑premise digital signage solutions. In theory, self‑hosted systems can be just as secure as cloud-based platforms. In practice, however, security often fails due to insufficient or inconsistent patch management. Software vendors have no visibility into or control over on‑premise installations. Responsibility for updates lies solely with integrators and network operators. If patches are delayed or ignored, known vulnerabilities remain wide open – sometimes for months or even years. The paradox: when a security incident occurs, the ISV (Independent Software Vendor) is usually named first, even though it has no operational control over the server environment. This is one of the key reasons why more ISVs are shifting toward managed cloud models. With managed services, the vendor ensures that systems are continuously updated and secured. A major additional benefit: a single, consistent software version across all customers. Instead of supporting a mix of outdated releases, ISVs can focus on security, stability, and innovation – while significantly reducing attack surfaces. The Magicinfo case is a reminder that cybersecurity is less about technology – and more about
Apr 27, 2026 · via invidis.com