Bluetooth tracker hidden in a postcard and mailed to a warship exposed its location — $5 gadget put a $585 million Dutch ship at risk for 24 hours A postcard spy Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. You are now subscribed Your newsletter sign-up was successful HNLMS Evertsen, a Dutch air-defense frigate part of the NATO carrier strike group centered on the French carrier Charles de Gaulle, has inadvertently revealed its position after receiving a postcard containing a hidden Bluetooth tracker. According to The Register, the Dutch Ministry of Defense posted instructions online to make it easier for family and friends to communicate with personnel aboard a navy ship, but didn’t fully consider the ramifications for operational security (op-sec). Bluetooth trackers like the Apple AirTag cost $29 a piece, but there are cheaper, generic versions available on Amazon that cost $10 for two trackers. By allowing a potential adversary to track the ship in real-time, it could put the vessel and the entire strike group at risk, as that information can be used for other operations against the fleet. The fact that it was mailed in meant that spies do not even need to go near the ship to place a tracker on the $585 million Navy ship. Dutch journalist Just Vervaart, working for regional media network Omroep Gelderland, followed the directions posted on the Dutch government website and mailed a postcard with a hidden tracker inside. Because of this, they were able to track the ship for about a day, watching it sail from Heraklion, Crete, before it turned towards Cyprus. While it only showed the location of that one vessel, knowing that it was part of a carrier strike group sailing in the Mediterranean could potentially put the entire fleet at risk.
Apr 19, 2026 · via tomshardware.com
Artificial intelligence "agents" promise to save users time and energy by automating tasks, but the growing power of systems like OpenClaw is setting cybersecurity experts on edge. Powered by a wave of hype, OpenClaw today claims more than three million users worldwide. The system allows users to create so-called agents, tools based on a large language model (LLM) like OpenAI's ChatGPT or Anthropic's Claude that can carry out online tasks. "We've moved from an AI you could talk with via a chatbot to an agentic AI, which can take action... the threat and the risks are definitely much greater," said Yazid Akadiri, principal solutions architect at Elastic France, an IT security company. In an article titled "Agents of Chaos" that has yet to be peer-reviewed, a 20-strong team of researchers studied the behaviour of six AI agents created with OpenClaw. They spotted a dozen potentially dangerous actions executed by the systems, from deleting an email inbox to sharing personal information. Many users have posted similar stories of OpenClaw mishaps online. "When you deploy agents, you have no control over what they'll do, and when you try to look at what they're doing, you'll find them going far beyond the limits you set," said Adrien Merveille, an expert at the Check Point cybersecurity agency. And the security gaps are not limited to the agents' own mistaken actions. To carry out useful work, the tools need access to personal accounts for email, calendars or search engines -- drawing the attention of cyberattackers. - 'Delete your database' - AI agents are likely to become top targets for hackers as their use spreads, said Wendi Whitmore, chief security intelligence officer at cybersecurity firm Palo Alto Networks. "As soon as (attackers) are inside an environment, (they're) immediately going to the internal LLM (agent) that's being
Apr 19, 2026 · via pmg-ky1.com
JavaScript is disabled in your browser.
Please enable JavaScript to proceed.
A required part of this site couldn’t load. This may be due to a browser extension, network issues, or browser settings. Please check your connection, disable any ad blockers, or try using a different browser.
Apr 19, 2026 · via sfgate.com
The Washington County Republican Women hosted members of Southern Utah’s Sunshine Caucus at their monthly luncheon Thursday at Santa Clara City Hall for a recap and Q-and-A session on the general legislative session. St. George Reps. Walt Brooks and Colin Jack attended along with Rep. Rex Shipp of Cedar City. Though not a member of the Sunshine Caucus, Rep. Logan Monson of Blanding also participated. Other members of the caucus were unable to attend due to prior obligations. Each legislator reviewed the bills they worked on during the 45-day session, with recurring emphasis on water management, cybersecurity, election integrity and judicial transparency. Water issues dominated much of the discussion as Southern Utah continues to face long-term supply concerns tied to population growth, drought and ongoing uncertainty surrounding the Colorado River system. Shipp said lawmakers are preparing for potential litigation over water rights as tensions continue between the upper and lower basin states. “We have a problem going on with the Colorado River, as you all know, and there’s a fight basically going on between the upper river basin, lower basin states,” he said. “We appropriated $5 million for litigation because we’re going to be in a legal battle, I’m sure, trying to make sure we keep our rights in the Colorado River.” Brooks pointed to several policy efforts aimed at strengthening long-term water access, including storage planning and regional coordination. “We’re trying to do a lot of different things to see how we can get this water,” Brooks said, referencing discussions involving Lake Powell levels, water diversion strategies and partnerships with neighboring states. Lake Powell remains a central concern, with Shipp warning of critically low levels that could have statewide consequences. “Lake Powell is at 25% capacity right now,” Shipp said. “It could be a dead pool by the end
Apr 19, 2026 · via stgeorgeutah.com
OPSWAT and Emerson Forge Global Reseller Pact for Power and Water Cybersecurity OPSWAT and Emerson have entered into a global strategic reseller agreement, according to a report from Chemical Engineering. The arrangement is designed to provide Emerson's power and water industry customers with cybersecurity technologies from OPSWAT. An initial project under this enterprise-wide agreement involves Emerson integrating OPSWAT's operational technology patch management capabilities into its Ovation Automation Platform. This solution is intended to secure the platform using specific OPSWAT products, which are part of a cybersecurity suite built for power and water applications. Operators in power generation and water utilities are confronting growing cyber threats, regulatory demands, and operational risks linked to unpatched systems. The patch management approach for the Ovation Platform is created for industrial settings, which must manage a combination of modern and older equipment while facing threats from nation-state actors and ransomware aimed at energy and water infrastructure. The collaboration builds upon an existing alliance between the two companies for other cybersecurity products on a different Emerson automation platform. This new partnership reflects a strategic move by Emerson to work with established cybersecurity providers, a change influenced by changing international regulations and the requirement to address new vulnerabilities consistently. 1. INTRODUCTION Making Data-Driven Decisions to Grow Your Business - REPORT DESCRIPTION - RESEARCH METHODOLOGY AND THE AI PLATFORM - DATA-DRIVEN DECISIONS FOR YOUR BUSINESS - GLOSSARY AND SPECIFIC TERMS 2. EXECUTIVE SUMMARY A Quick Overview of Market Performance - KEY FINDINGS - MARKET TRENDS This Chapter is Available Only for the Professional EditionPRO 3. MARKET OVERVIEW Understanding the Current State of The Market and its Prospects - MARKET SIZE: HISTORICAL DATA (2012–2025) AND FORECAST (2026–2035) - CONSUMPTION BY COUNTRY: HISTORICAL DATA (2012–2025) AND FORECAST (2026–2035) - MARKET FORECAST TO 2035 4. MOST PROMISING PRODUCTS FOR DIVERSIFICATION Finding
Apr 18, 2026 · via indexbox.io
About
Press
Copyright
Contact us
Creators
Advertise
Developers
Terms
Privacy
Policy & Safety
How YouTube works
Test new features
NFL Sunday Ticket
© 2026 Google LLC
Apr 18, 2026 · via youtube.com
New tech degree launches at USMH for local students Students in western Maryland will soon have a new path to tech careers without leaving their community. A new Bachelor of Science in Applied Computer Science is scheduled to launch at the University System of Maryland at Hagerstown in fall 2026, according to a community announcement. The program, offered by Frostburg State University, will focus on areas like artificial intelligence, data science, cybersecurity and software development. Designed for students with an associate degree, the program aims to meet the growing demand for technology professionals in the region. It is expected to emphasize hands-on learning, real-world problem-solving and direct pathways to in-demand careers. New lab and eSports arena planned The program will be supported by Frostburg State University’s Computer Science and Information Technologies department and taught at the USMH campus in downtown Hagerstown. A new lab and classroom space, through the support of a generous grant from the Maryland Technology Development Corporation (TEDCO), is expected to feature modern technology and collaborative learning environments. According to the announcement, the space will also include an eSports arena and opportunities for students to participate in programming competitions, capture the flag events and student showcases. “This program is an exciting addition to USMH and a direct response to workforce needs in our region,” USMH Executive Director Jacob Ashby said in the announcement. “Students can stay local, complete a high-quality degree and step into meaningful technology careers without leaving the area.” Seamless transfer from community colleges The program is designed for students transferring from regional community colleges, including Hagerstown Community College and Frederick Community College. Classes will be held at the USMH campus, with small class sizes and personalized faculty support. Students will apply through Frostburg State University’s admissions process and, upon enrollment, complete their coursework at
Apr 18, 2026 · via heraldmailmedia.com
You hear Cybersecurity every day — but let’s be real. What does it actually mean for you as a business owner? More importantly, how do you stay safe in a world where cybercrime is now bigger than the drug trade? I’m Paul Marchese, owner of Marchese Computer Products Inc. For 44 years, my team and I have been protecting businesses across Western and Central New York —construction companies, law offices, accountants, farms, manufacturers — you name it. Along the way, I’ve written three books on the subject, including “Business Owners Guide to Cyber Security” and two Amazon bestsellers: “From Exposed to Secure” (2024) and “The Cyber Playbook” (2025). We’ve helped well more than 1,000 small businesses stay productive, grow, and avoid being the next victim. × Javascript is required for you to be able to read premium content. Please enable it in your browser settings. kAm(6’C6 ?@E “;FDE 2? x% D9@A]” (6’C6 2 D64FC:EJ\7:CDE |2?2865 $6CG:46D !C@G:56C[ 2 =:46?D65 }6H *@C< $E2E6 2=2C> :?DE2==6C WG:56@[ 7:C6[ 3FC8=2CX[ 2?5 2 E6=64@> 4@?DF=E2?E C6AC6D6?E:?8 >@C6 E92? d_ 42CC:6CD] ~FC ;@3 :D D:>A=6i E2<6 x% @77 J@FC A=2E6 D@ J@F 42? 7@4FD @? CF??:?8 J@FC 3FD:?6DD]k^Am k9bm(9J %9:D |2EE6CD }@Hk^9bm kAmrJ36C4C:>6 :D?’E D@>6 72C\@77 E9C62E — :E’D 2 3:==:@?\5@==2C :?5FDECJ] p?5 J@F’C6 E96 E2C86E] w24<6CD 5@?’E 42C6 H9@ J@F 2C6j J@F’C6 ;FDE 2?@E96C 5@@CH2J E96J H2?E E@ <:4< @A6?]k^Am kAmw6C6’D E96 92C5 ECFE9ik^Am kF=mk=:mw24<6CD D:E F?56E64E65 @? ?6EH@C<D 7@C 2? 2G6C286 @7 a`f 52JD]k^=:mk=:m|@C6 E92? d__[___ ?6H >2=H2C6 G2C:2?ED 2C6 C6=62D65 6G6CJ D:?8=6 52J]k^=:mk=:m|@C6 E92? 92=7 @7 2== 2EE24<D 9:E D>2== 3FD:?6DD6D—4@>A2?:6D ;FDE =:<6 J@FCD]k^=:mk^F=m kAmp?5 ?@H 4@>6D E96 4FCG632==i px\A@H6C65 2EE24<D]k^Am kAmrC:>:?2=D 2C6 FD:?8 2CE:7:4:2= :?E6==:86?46 E@ >2<6 E96:C D42>D D>2CE6C[ 72DE6C[ 2?5 ?62C=J :>A@DD:3=6 E@ DA@E] t>2:=D E92E =@@< 6I24E=J =:<6 E96J 42>6 7C@> J@FC G6?5@C] !9@?6 42==D E92E >:>:4 J@FC
Apr 18, 2026 · via thedailynewsonline.com
The myth of Claude Mythos crumbles as small open models hunt the same cybersecurity bugs Anthropic showcased Anthropic has kept its Claude Mythos cybersecurity model on a short leash, pointing to capabilities it says no rival can match. But two new studies suggest that even small, openly available models can reproduce most of the vulnerability analyses Anthropic has put on display. Through Project Glasswing, Anthropic has limited access to Claude Mythos Preview to a consortium of eleven organizations, citing the model's offensive capabilities. Internal tests and an audit by the UK's AI Security Institute found that Mythos can find software bugs, build working exploits on its own, and take over entire corporate networks in simulations, as long as the network is "small, weakly defended and vulnerable." Two independent replication efforts are now poking holes in that exclusivity story, without disputing the model's overall performance. The first comes from AISLE, a company that has been running its own AI-assisted bug hunting on open source software since mid-2025. AISLE says it has reported 15 vulnerabilities in OpenSSL and five in curl. Founder Stanislav Fort fed the code snippets from Anthropic's public samples into a range of models to see how much smaller and partially open models could piece together on their own. The second study comes from Vidoc Security, which paired GPT-5.4 and Claude Opus 4.6 with the open coding agent OpenCode. Small models catch the FreeBSD bug too The FreeBSD NFS bug (CVE-2026-4747) that Anthropic spotlighted was pitched as a showcase for autonomous discovery and exploitation by Mythos. AISLE found that all eight models it tested caught the memory bug in the function in question. That included GPT-OSS-20b, a model with just 3.6 billion active parameters that runs at $0.11 per million tokens. Every model flagged the flaw as critical, though
Apr 18, 2026 · via the-decoder.com
The National Information Technology Development Agency (NITDA) and the Corporate Affairs Commission (CAC) have initiated coordinated measures to strengthen cybersecurity following recent concerns affecting aspects of CAC’s digital systems. Both agencies said they have activated response and assurance mechanisms in line with national cybersecurity frameworks to safeguard critical infrastructure and maintain service integrity. The cybersecurity effort was disclosed in a statement by the NITDA Director, Corporate Communications and Media Relations Department, Hadiza Umar, on Friday. The measures followed alleged breaches of data and information systems of government and private institutions, including CAC, Remita Payment Services Limited, Sterling Bank, and other entities, in the past weeks. The Nigeria Data Protection Commission (NDPC) said it is probing alleged data breaches. | | |---| In the statement on Friday, NITDA reiterated that all ministries, departments, and agencies (MDAs) must adopt proactive cybersecurity measures in compliance with the National Cybersecurity Policy and Strategy (NCPS) 2021. The agency directed all MDAs to immediately review and reinforce their cybersecurity architecture to address emerging threats targeting government systems and sensitive data. As part of the directive, MDAs are also required to conduct comprehensive security assessments, remediate identified vulnerabilities, and strengthen access controls across critical platforms. They are also expected to enhance data protection mechanisms, maintain effective backup and disaster recovery systems, and improve monitoring capabilities to detect and respond to suspicious activities. “In addition, there is the need for functional incident response frameworks, including prompt reporting of cybersecurity breaches for coordinated intervention. “Detailed cybersecurity guidelines have already been issued to MDAs for implementation as part of ongoing efforts to strengthen resilience across public sector digital infrastructure,” the NITDA stated. According to the agency, the measures are aimed at improving the overall security posture of government institutions and ensuring the continued protection of national digital assets. NITDA reaffirmed
Apr 18, 2026 · via premiumtimesng.com
Presentation providing analysis of the leading cybersecurity vendors’ recent financial results compared with their competitors. The Cybersecurity Titans are Akamai, Check Point, Cisco (including Splunk), Cloudflare, CrowdStrike, CyberArk, Elastic, F5, Fortinet, Varonis, Okta, Palo Alto Networks, Qualys, Rapid7, SentinelOne, Tenable, Trend Micro and Zscaler. These vendors have annual revenue of over US$300 million, were publicly trading for at least four quarters and broke out their cybersecurity revenue numbers quarterly. Email Article All set! This article has been sent to my@email.address. All fields are required. For multiple recipients, separate email addresses with a semicolon. Please Note: Only individuals with an active subscription will be able to access the full article. All other readers will be directed to the abstract and would need to subscribe. The Analyst Team Srikara Upadhyaya Follow AnalystResearch Analyst Srikara Upadhyaya works as a research analyst and is based in the Bangalore office. His research is focused on the cybersecurity and infrastructure markets. Prior to joining Canalys, now part of Omdia, Srikara spent two years working as an associate market analyst for IDC India, with a focus on worldwide software, artificial intelligence, and the public cloud service market. He also worked as an analyst at John Crane India Limited, where he worked closely with the production team to analyze SAP production and material management module data. Srikara holds an MBA from Jain University Bangalore and a bachelor’s degree in mechanical engineering from Vishweshwaraiah Technological University.More Content By Srikara Upadhyaya Become A Client Find out more about our full suite of products and solutions. Become A ClientYou must sign in to use this functionality Authentication.SignIn.HeadSignInHeader These are Omdia driven recommendations based on content that is both similar, and has been frequently visited by other users in combination with the content you are currently viewing. Omdia Recommends These are Omdia
Apr 18, 2026 · via omdia.tech.informa.com
Techie buys fake Ledger Nano S+ hardware crypto wallet and almost falls for phishing — a convincing clone would have caught newbies unaware Hardware verification check was the one thing standing between virtual coins and a virtual robbery. Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. You are now subscribed Your newsletter sign-up was successful Score one for the safety-minded and cryptographic hardware checks. Joje Mendes, a Brazilian cybersecurity professional, almost got bitten by a sophisticated hardware-and-software phishing attack, in the form of a fake Ledger Nano S+ cryptocurrency wallet. The only barrier between Past's virtual currency and the device's remote operators was Ledger's software, which verified that it was running on legitimate hardware. The story starts when Mendes decided to order the Ledger device from a "major marketplace" in China. He chose to do so because, being a non-Chinese citizen currently located in Shenzhen, importing one from abroad, directly from Ledger, "comes with its own headaches." The device's price was reportedly the same as that of a legitimate unit, but nevertheless, Mendes kept his suspicion mode engaged and installed Ledger's official software before the Nano S+ arrived. True to the unfortunately expected form, after the device arrived, Mendes noticed it was "clearly" a counterfeit, a fact verified by the Ledger software, which marked it as non-genuine. True to his profession, Mendes decided to tear apart the device instead of tossing it, and found quite an elaborate scheme at work — one that's likely catching other unsuspecting users off guard. Article continues belowAfter prying open the case, Mendes found that all chip markings had been scraped off, but eventually managed to identify the central unit as an ESP32-S3 system-on-a-chip (SoC). The device spoofed its identification, claiming it was a "Nano S+ 7704" from Ledger's factory, complete
Apr 18, 2026 · via tomshardware.com
Please SUBSCRIBE HERE for free or get DTNS Live ad-free. A special thanks to all our supporters–without you, none of this would be possible. If you enjoy what you see you can support the show on Patreon, Thank you! Send us email to feedback@dailytechnewsshow.com Show Notes Anthropic launches Claude Design for fast visual creation Anthropic introduced Claude Design, an experimental tool that generates and refines visuals like prototypes, slides, and one-pagers using natural language. Built on Claude Opus 4.7, it targets non-designers and integrates with tools like Canva while supporting company-specific design systems pulled from codebases and design files. It is currently in research preview for paid users. Source: TechCrunch AI demand is making the Mac Mini harder to find Apple’s Mac Mini is seeing supply constraints driven by surging demand from AI users running local models and always-on agents. High-memory configurations are especially affected, with shipping delays stretching up to 12 weeks and frequent stockouts. Analysts say it has become a popular low-cost option for local AI workloads. Source: 9to5Mac EU age-verification app found to have major security flaws Researchers identified major vulnerabilities in the European Commission’s age-verification app, including bypassable biometric protections and insecure local data storage. Security experts said the system could be compromised in minutes, raising concerns about identity misuse. The Commission says the app remains under active development and updates are ongoing. Source: POLITICO OpenAI loses key leaders as it scales back experimental projects OpenAI is seeing departures including Kevin Weil and Bill Peebles as it winds down experimental initiatives like Sora and OpenAI for Science. The company is consolidating around more commercially focused AI products, while reducing investment in side projects. Additional leadership changes include enterprise CTO Srinivas Narayanan. Source: TechCrunch TCL expands Mini LED TV lineup with premium RGB models TCL is expanding
Apr 18, 2026 · via dailytechnewsshow.com
The authorities of the U.S., U.K., and Canada have conducted a joint operation focused on dismantling a widespread cryptocurrency fraud network that allegedly caused losses exceeding $45 million. The intervention, called 'Operation Atlantic,' aimed primarily to halt the progress of criminal networks, as well as to track funds and identify victims. According to information released by various involved agencies, including the U.S. Secret Service, the U.K.'s National Crime Agency (NCA), and Canadian police forces, the operation was carried out as a coordinated international action over approximately one week. The main focus of the investigation has been a scam modality known as 'approval phishing,' a type of fraud particularly widespread in the crypto ecosystem. This method involves deceiving victims into granting access permissions to their digital wallets through fake interfaces that simulate legitimate services. Once authorization is granted, the attackers can move the funds without needing further confirmations from the user. Authorities link these types of attacks to broader online fraud schemes, including the well-known investment scams or 'pig butchering,' where criminals psychologically manipulate victims into progressively depositing more funds. More than 20,000 identified victims The operation has led to the identification of more than 20,000 crypto wallet addresses linked to victims distributed across more than 30 countries, including the U.S., U.K., and Canada. The participating agencies have noted that, thanks to collaboration with blockchain analysis companies and industry platforms, they have been able to track the movement of stolen funds and detect patterns used by criminal groups to hide the money. During the operation, authorities managed to freeze approximately $12 million in stolen cryptocurrencies, a portion of the misappropriated funds, which are now under review for possible restitution to the victims. Additionally, another $33 million related to fraudulent activities has been identified and continues under investigation. Security forces have also
Apr 18, 2026 · via escudodigital.com
CENTRAL FLORIDA — From hospitals to utilities and even local governments, cyberattacks are becoming more frequent—and more sophisticated. Now, a Central Florida company and state leaders are working to train the next generation to defend against them. Experts say cyber threats are no longer distant concerns. They’re hitting closer to home, targeting critical systems that people rely on every day—from healthcare networks to city infrastructure. ThreatLocker, based in Central Florida, says it is already seeing the impact firsthand. CEO Danny Jenkins said the company blocks thousands of cyberattacks every week. “We’re stopping an airport from getting shut down… we’re protecting people’s data, their healthcare, everything else,” Jenkins said. As Florida continues to grow, so does the demand for cybersecurity professionals. Industry data shows there are between 500,000 and 700,000 unfilled cybersecurity jobs across the United States. State-funded group Cyber Florida is working to close that gap by training professionals and building a pipeline of future talent. “We need to encourage more people to discover their passion in cybersecurity so that they can fill those positions,” said James Welsh. One effort to spark that interest is CyberLaunch, one of the largest cybersecurity competitions in the country. On April 24, students from Orange and Seminole counties, along with others from across the state, will compete in the event. Organizers say introducing students to cybersecurity early is key to building a strong workforce. “You need to get people in it when they’re really young… when they can understand and learn much, much faster,” Welsh said. Even as interest grows, experts say one major challenge remains: experience. Employers are looking for candidates with hands-on skills who can immediately step into critical roles. “The colleges need to step up and train better… the high schools… but companies as well,” Jenkins said. Leaders say the push
Apr 18, 2026 · via wftv.com
The 2026 CEO & Board Confidence Monitor by Heidrick & Struggles International, Inc. found that the Asia Pacific (APAC) region reports strong confidence in their ability to navigate issues such as artificial intelligence and cybersecurity risk. “The breadth of what is landing on leadership agendas across APAC right now is significant. The real test for leaders is carrying the weight of today’s volatility while simultaneously transforming for what comes next,” said Jiat-Hui Wu, partner-in-charge at Heidrick & Struggles Singapore. Significant issues in APAC Based on responses from 254 leaders in the region, the report found that artificial intelligence and economic uncertainty were each cited by 44% of respondents as among the most significant issues their organisations expect to face in 2026. Some 39% cited cybersecurity risk, above the global average of 31%. APAC leaders reported the highest confidence among the five regions surveyed in their ability to manage AI risks. Half of respondents said they were confident in handling AI, compared with a global average of 39%. Confidence in managing cybersecurity risk was also higher at 55%, compared with 51% globally. While 75% of respondents are confident in their executive teams for 2026, only 55% trust board evaluation and refreshment practices. “Confidence in today’s leadership is just part of the picture. Even as organisations grow more confident in managing technological risk, a more uncertain geopolitical environment is testing leadership readiness,” said Guy Farrow, regional managing partner of the CEO & Board of Directors Practice for Asia Pacific and the Middle East at Heidrick & Struggles. He added that organisations need to strengthen governance structures as geopolitical uncertainty and technology disruption continue to test leadership readiness.
Apr 18, 2026 · via futurecio.tech
How AI intelligence and human expertise combined to identify threats 66% faster Cybersecurity is at an inflection point. The scale of data, the speed of attacks and the sophistication of threat actors mean that traditional approaches are no longer fit for purpose. In this case, a major European government organisation faced a highly advanced state-sponsored cyberattack. The attacker had gained access to the environment, creating a real risk of disrupting critical digital services and exposing highly sensitive data linked to senior individuals. “The client could no longer assure the quality of the security of their data and environment,” explains Paul Beverley-Paddock, Director at Deloitte and Security Operations Lead. “We were dealing with nation-state threat actors operating with tools that can appear indistinguishable from legitimate IT activity,” shares Caroline Honeycombe, Director at Deloitte and Cyber Incident Response Lead. The organisation needed to respond immediately, regain control, stop the threat and strengthen its ability to defend against future attacks. This required not just new technology, but a fundamentally different approach: combining AI, including Generative AI, with human expertise to detect and respond to threats at scale. Deloitte combined cyber incident response expertise with advanced AI capabilities from Google Cloud to transform how the threat was identified, understood and removed. At the core was a threat-led approach. Billions of data points were inputted into Google SecOps, creating a unified, real-time view of activity. This was enriched with integrated threat intelligence, enabling rapid attribution and a deeper understanding of the attacker’s tactics. By using Gemini, analysts could interact with this data in a fundamentally new way. Instead of manually complex queries to search through vast datasets, they could ask natural language questions, generate and evolve detection rules in real time and quickly identify patterns linked to the threat actor. Gemini enabled us to reduce
Apr 18, 2026 · via deloitte.com
Bank of Canada Governor Tiff Macklem said governments and regulators need to move quickly to get a handle on the cybersecurity risks posed by powerful new artificial intelligence tools such as Anthropic’s Claude Mythos model. The emergence of new AI models adept at hacking into secure systems was widely discussed at the spring meetings of the International Monetary Fund and World Bank in Washington over the past week, Mr. Macklem said. San Francisco-based Anthropic announced the Mythos model earlier this month, but opted not to make it widely available because of the risks it presents. The model has shown unprecedented skill at finding and exploiting vulnerabilities in software, according to Anthropic. “This isn’t a one-off. Mythos has arrived, it’s a lot more powerful than what came before. But something else will come that’s even more powerful than that,” Mr. Macklem told reporters on a call from Washington. “As a [financial] system, both within Canada, but internationally, we’re going to need to come to grips with how we’re going to manage this on an ongoing basis.” Artificial Intelligence Minister says Anthropic taking ‘responsible’ approach with Mythos Mr. Macklem said he discussed Mythos with U.S. Federal Reserve Chair Jerome Powell this week, while Finance Minister François-Philippe Champagne talked to his counterpart U.S. Treasury Secretary Scott Bessent. He also said the Canadian Financial Sector Resiliency Group (CFRG), which is chaired by the Bank of Canada and includes representatives from other regulators and Canada’s big banks, met a second time this week to discuss the financial system security implications of Mythos. Questions about the potential impact of Mythos on the financial system emerged last week after Mr. Powell and Mr. Bessent convened a meeting of top U.S. bank CEOs to discuss the issue. News of the meeting sent central banks and regulators around the
Apr 18, 2026 · via theglobeandmail.com
Hackers are attempting to exploit a high-severity flaw found in several end-of-life routers from TP-Link, according to a blog post published Friday by Palo Alto Networks’ Unit 42. Researchers warn the observed payloads share similarities to those found in malware used in Mirai-like botnets. Such activity would involve attempts to download the malware and execute on vulnerable devices, according to researchers. The vulnerability was originally disclosed in June 2023, and proof of concept exploits appeared prior to the disclosure, wrote Unit 42 researchers. The Cybersecurity and Infrastructure Security Agency previously added the command injection vulnerability, tracked as CVE-2023-33538, to its Known Exploited Vulnerabilities catalog in July 2025. Palo Alto Networks telemetry detected large-scale exploitation attempts at the time. Researchers caution that recently observed exploitation attempts have not been successful, but the underlying vulnerability is real. They said successful exploitation would require authentication to the router’s web interface. TP-Link confirmed the routers have reached end-of-life status and are no longer being supported and should therefore be replaced with hardware that is under support, according to the Unit 42 post. Users should also make sure default credentials are not being used. The research follows years of concerns about the security of TP-Link routers, which have raised larger concerns about the security of foreign-linked networking equipment. Forescout Research in October warned of critical flaws in TP-Link Omada routers. In early 2025 a botnet targeted critical flaws in TP-Link Archer routers in a campaign targeting U.S. organizations.
Apr 18, 2026 · via cybersecuritydive.com
NEW BRITAIN — The Common Council approved several measures, including a new cybersecurity system, funding for road paving and a resolution recognizing Earth Day. At its meeting, the council approved funding for new cybersecurity services following a January ransomware attack that affected the city’s information technology systems. The breach disrupted phones and computers across departments, though officials said emergency services were not affected. The council approved a three-year agreement with Cowbell MDR to monitor and protect city systems. According to the resolution, Cowbell MDR “is a fully managed detection and response service that provides continuous monitoring, threat detection and response across endpoint, identity and cloud applications.” The service will cost $66,000 per year and includes a “$25,000 breach response fund” to help address future incidents. Following the January attack, Mayor Bobby Sanchez said the city responded quickly and is working closely with state and federal partners, law enforcement and an outside cybersecurity expert to investigate the incident and restore systems safely and securely. The council also approved funding for the city’s annual road paving program. About $2 million in state aid, along with additional city funds, will be used to repair and repave roads this summer. Contracts were awarded to Tilcon Inc. and Garrity Asphalt Reclaiming for materials, milling and paving work. City officials said roadwork is based on a pavement rating system that helps determine which streets are repaired each year. In addition, the council passed a resolution recognizing Earth Day, to be observed Wednesday. The resolution highlights the city’s ongoing efforts to protect the environment and promote sustainability. The measure, introduced by Ward 3 Alderwoman Candyce Scott, seeks to promote conservation, energy efficiency and the study of the use of clean energy sources” in municipal government and throughout the community. It also notes steps the city has taken,
Apr 18, 2026 · via bristolpress.com