Potential EXPLOITATION: Mythos for <b>cybersecurity</b>
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
About Press Copyright Contact us Creators Advertise Developers Terms Privacy Policy & Safety How YouTube works Test new features NFL Sunday Ticket © 2026 Google LLC
Siobhan Harms reports: The Ohio Auditor of State’s Office will begin evaluating school districts’ cybersecurity policies in July. As outlined by House Bill 96, districts had to implement a cybersecurity program that safeguards the district’s data, information technology and information technology resources to ensure availability, confidentiality and integrity. The law reads, “The program shall be consistent with generally accepted best practices for cybersecurity, such as the national institute of standards and technology cybersecurity framework, and the center for internet security cybersecurity best practices.” Read more at Spectrum News1.
17 Apr He Pled Guilty To Blackmailing Apple. What Really Happened. This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Apr. 17, 2026 – Listen to the podcast episode Kerem Albayrak from north London threatened to wipe 319 million accounts unless Apple gave him iTunes gift cards worth $100,000 (£76,000), BBC reported in a Dec. 2019 story. An investigation found that Albayrak had not compromised Apple’s systems. He was given a two year suspended jail sentence and ordered to do 300 hours of unpaid work. In Mar. 2017, Albayrak emailed Apple’s security team, claiming to have breached millions of iCloud accounts. He posted a video on YouTube that appeared to show him breaking into two accounts. He threatened to sell the account information, dump his database online and reset the accounts, unless Apple paid his iTunes gift card demand. Albayrak also said he would accept $75,000 worth of cryptocurrency, but later increased this to $100,000. He was arrested at his home in north London about two weeks after sending his threat. Apple investigated his claims but could not find evidence that its systems had been compromised. In addition to the 300 hours of unpaid work, he was given a six month electronic curfew. The incident was later deemed to be part of a publicity stunt to promote a tool Albayrak was developing. In a new Cybercrime Magazine Podcast episode Albayrak publicly discusses his side of the story for the first time; he has since gone on to work in cybersecurity. Cybercrime Magazine is Page ONE for Cybersecurity. Go to any of our sections to read the latest: - SCAM. The latest schemes, frauds, and social engineering attacks being launched on consumers globally. - NEWS. Breaking coverage on cyberattacks and data breaches, and the most recent privacy
Acknowledgments: Special thanks to Harlan Carvey and Lindsey O’Donnell-Welch for their contributions to this blog and research. Everyone’s talking about AI’s impact on cybersecurity, from how it will affect vulnerability management to what it means for threat actor campaigns. Over the past year, we’ve seen how threat actors are relying on AI to increase their productivity across campaigns, specifically for drafting scripts, assembling commands, and more. At the same time, defenders like Huntress Security Operations Center (SOC) analysts use AI tools in many places across their investigations to connect the dots faster, with experienced analysts reviewing the results and owning every verdict and report at the end of the investigation. But what happens if a user with Managed Endpoint Detection and Response (EDR) installed tries to use an AI tool for troubleshooting or responding to suspicious behavior? We recently triaged an interesting case where this happened, and it had unexpected consequences when our analysts investigated the endpoint. This is a tale with three storylines: the Huntress SOC, a group of at least two different threat actors, and a third-party developer using OpenAI’s Codex coding agent to try to knock down malicious activity on their Linux system. In this first part of our two-part blog series, we will break down how the end user prompted Codex to help them troubleshoot and respond to suspected malicious behavior on their endpoint. In the second part, we will look at how that complicated the initial triage and investigation into the incident from the perspective of the SOC. Key takeaways After being installed mid-incident, Huntress investigated an endpoint belonging to an organization in the tech sector that was being targeted by multiple threat actors, who installed cryptominers, harvested credentials, and more. The user behind the targeted endpoint was relying on an AI agent (Codex) to
Ghana and Italy Deepen Cybersecurity Cooperation to Strengthen Digital Resilience The partnership reflects a shared focus on building resilient digital systems and protecting critical information infrastructure amid growing cyber threats. Ministry of Communication, Digital Technology and Innovations Ghana has reaffirmed Ghana’s commitment to international collaboration in cybersecurity through strengthened ties with Italy, aimed at securing the digital future of both economies and their citizens. The partnership reflects a shared focus on building resilient digital systems and protecting critical information infrastructure amid growing cyber threats. As part of this effort, Ghana continues to advance key national initiatives that integrate cybersecurity awareness and secure digital practices. Flagship programmes such as the One Million Coders Programme and Girls in ICT are playing a central role in developing a future-ready workforce. These initiatives are designed to equip young people with the technical skills and cybersecurity knowledge required to safeguard digital ecosystems and support national digital transformation goals. The Cyber Security Authority Ghana is also engaged in these efforts, contributing to the broader objective of strengthening the country’s cyber resilience and promoting secure digital innovation. Government officials emphasised that cybersecurity remains a shared responsibility, highlighting the importance of international partnerships in building secure, inclusive, and sustainable digital economies.
The California Governor’s Office of Emergency Services (Cal OES), through the California Cybersecurity Integration Center (Cal-CSIC), is now offering the Multi-State Information Sharing and Analysis Center (MS-ISAC) to qualified agencies for free. This Cal OES-sponsored initiative is available to California’s public agencies, including state, local, and tribal partners. Some examples of public agencies include schools, utilities, emergency services, and more. MS-ISAC has a special focus on helping underserved communities and organizations with fewer cybersecurity resources. MS-ISAC operates 24/7 and provides access to experts and tools that help organizations prevent, and if necessary, respond quickly to cyber incidents. It serves as the nation’s only cybersecurity resource solely dedicated to serving state, local, and tribal agencies stay ahead of evolving threats and build stronger cybersecurity defenses. The center is part of the Center for Internet Security, a non-profit that works with a global IT community to help protect organizations from cyber threats. It offers paid MS-ISAC memberships to individual organizations as well as statewide packages that cover state, local, and tribal agencies. Cal OES’s statewide sponsorship shows its commitment to helping organizations strengthen their cyber defense systems. It also helps state, local, and tribal agencies to follow best practices and stay connected with a trusted cybersecurity network. The benefits of the MS-ISAC include: - Sharing information about cyber threats - Early warnings about possible cyber incidents and how to respond and investigate them. - A 24/7 security operations center - Access to MemberConnect, a communications platform that allows the enrolled California agencies to share information and coordinate on cybersecurity-related matters. Cybersecurity is essential for public entities. It safeguards critical public services like healthcare, sensitive resident data such as tax information, and continuity of government operations, including emergency response services. MS-ISAC helps Cal OES and Cal-CSIC make California more resilient by building strong
In the wake of Anthropic’s announcement of its latest artificial intelligence model, Mythos, on April 7, the company has stood by an unusual decision: refusing to release it to the public. Not since OpenAI temporarily withheld its GPT-2 model in 2019 has a major developer deemed a system too dangerous for the public. More than a week later, that choice is still reverberating through finance and regulatory circles. “The fallout—for economies, public safety, and national security—could be severe,” Anthropic said on its website. But while officials scramble to gauge the implications of the model’s unprecedented hacking capabilities, cybersecurity experts are divided over whether Mythos marks a major break from what came before or an expected step down an already troubling path. Anthropic did not respond to a request for comment from Scientific American. On supporting science journalism If you're enjoying this article, consider supporting our award-winning journalism by subscribing. By purchasing a subscription you are helping to ensure the future of impactful stories about the discoveries and ideas shaping our world today. A 245-page technical document released alongside the announcement outlines what the company presents as a major leap in capability. The model operates like a senior software engineer, demonstrating an ability to spot subtle bugs and self-correct mistakes. It also scored 31 percentage points higher than Anthropic’s previous cutting-edge model, Opus 4.6, on the USAMO 2026 Mathematical Olympiad, a grueling, two-day proof-based competition. But that same coding prowess makes Mythos a formidable offensive weapon, and Anthropic says it can outstrip all but the most skilled humans at identifying and exploiting software vulnerabilities. In tests, it found critical faults in every widely used operating system and web browser. Of those vulernabilities, 99 percent have not yet been patched. And Anthropic has disclosed only a fraction of what it says it
Fact Check Team: Anthropic’s Mythos AI raises cybersecurity promise, but poses risk WASHINGTON (TNND) — A powerful new artificial intelligence model is drawing attention in the tech and cybersecurity world — not just for what it can do, but for how it could be used if it falls into the wrong hands. Anthropic, one of the leading AI firms, is developing an experimental system known as “Mythos.” Unlike consumer-facing AI tools, this model is not publicly available. Instead, it’s being quietly tested with a small group of major companies due to concerns over its capabilities. A Tool Built for Cybersecurity — and Potential Exploitation At its core, Mythos is designed to excel at cybersecurity tasks. According to Anthropic, the model has already identified thousands of high-severity software vulnerabilities, including flaws in widely used operating systems and web browsers. In some cases, the system has even demonstrated the ability to identify and exploit so-called “zero-day” vulnerabilities — previously unknown weaknesses that can be especially dangerous if discovered by malicious actors. Independent testing by the UK AI Security Institute underscores both the promise and the risk. Evaluators found the model succeeded in expert-level cybersecurity challenges roughly 73% of the time and, in certain scenarios, could carry out complex, multi-step simulated cyberattacks from start to finish. However, those tests were conducted in controlled environments — not against real-world, highly defended systems. Why Access Is Being Restricted Because of these capabilities, Anthropic and other AI companies are taking a cautious approach. Rather than releasing Mythos publicly, access is limited to a small group of major tech firms, including Google, Amazon, Apple, and Microsoft. The goal is to test the system while minimizing the risk of misuse. The company has also launched “Project Glasswing,” an initiative focused on using advanced AI capabilities for defensive cybersecurity
There are some important developments concerning cybersecurity — so let’s push past the anxiety and talk about them. I was at a conference recently where a group of practitioners discussed cybersecurity for retirement plans. The topic admittedly makes me cringe as it dredges up some of the hardest situations I’ve ever helped clients navigate: theft — sometimes of nearly all a plan’s or saver’s assets. Ugh. Not exactly the kind of retirement policy discussion that brightens your day. While this isn’t a new topic — there are some important developments — so let’s push past the anxiety and talk about them. If, like me, you’re a fan of The Hitchhiker’s Guide to the Galaxy, you know the most important words printed on the cover of the Guide are simple: “Don’t Panic.” That’s excellent advice for both interstellar hitchhiking and cybersecurity incidents in retirement plans (which, trust me, feel almost as chaotic). Tempting as panic may feel in the moment — or even when contemplating the possibility of a theft from your plan — cybersecurity requires the opposite response. In today’s world, cybersecurity threats aren’t some sci-fi subplot. They’re part of the routine retirement plan administration that fiduciaries must face. Which brings us to an important lesson from Hitchhiker’s lore: Keep Calm and Carry a Towel (or, in this case, a prudent policy!). Or perhaps a towel and a policy — belt and suspenders never hurt anyone in ERISAland. Prudent Policy: The Cybersecurity Towel Translated into retirement plan terms, the wisdom “Keep Calm and Carry a Towel” holds up remarkably well. Keep calm: don’t let fear or confusion drive bad decisions or inaction. Carry a towel: be prepared with the right governance structures, documentation, and protections in place. Under ERISA, fiduciary prudence and loyalty don’t stop at selecting investments. The Department
Artificial intelligence (AI) creates two sets of cybersecurity risks: cyber risks in the AI systems themselves, and cyber risks from AI tools used to exploit non-AI systems. The U.S. government has primarily focused on the former, but it should urgently be preparing for the latter. Securing AI systems has been a priority for the past two administrations. Under President Biden, the National Institute of Standards and Technology (NIST) created the U.S. AI Safety Institute to support the development of safe and secure AI. Later, under President Trump, NIST reformed the organization as the Center for AI Standards and Innovation (CAISI) and refocused its priorities to concentrate on securing commercial systems. Late last year, the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) issued a report for securely integrating AI in government operations, which included principles such as secure‑by‑design integration, continuous monitoring, anomaly detection, human‑in‑the‑loop oversight, and rigorous testing and red‑teaming of AI systems. But the federal government has taken relatively few steps to address risks in existing systems that cyber threat actors may discover and exploit using artificial intelligence (AI) tools, despite policymakers being aware of the issue. For example, nearly two years ago, the Bipartisan Senate AI Working Group called on lawmakers “to develop legislation bolstering the use of AI in U.S. cyber capabilities.” Similarly, the Bipartisan House Task Force on AI stated that “security teams must use AI defensively to improve cybersecurity resiliency.” However, the issue has now reached a new level of urgency. Earlier this month, Anthropic announced Claude Mythos Preview, a new frontier AI model—meaning a cutting-edge model that pushes the boundaries of what AI can accomplish —that is “capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser.” For example, the model uncovered
An energetic start to a career in cybersecurity KALAMAZOO, Mich.—From Accra, Ghana, Gabriel Gyimah is taking his career to the next level by pursuing a Master of Science in cybersecurity from Western Michigan University’s Haworth College of Business. As a first-year graduate student, Gyimah is not only achieving a robust education, but he is also setting himself up for a fulfilling career. With a Bachelor of Science degree in electrical and electronics engineering from Kwame Nkrumah University of Science and Technology and a Bachelor of Laws degree from the Ghana Institute of Management and Public Administration, Gyimah is bringing his energy for learning to a new facet of his future career. “My professional career began with a foundation in electrical engineering, where I developed strong analytical skills,” he says. “I later expanded my perspective by pursuing legal education, which deepened my understanding of regulation, compliance and ethical decision making in complex organizations.” So why did Gyimah choose cybersecurity at WMU? “The cybersecurity program enables me to combine my technical background with my interests in policy, governance and risk management. The program’s interdisciplinary structure aligns closely with my goal of contributing to secure and compliant systems in real-world environments.” With a high-demand program, support is essential. Gyimah has formed valuable relationships at WMU Haworth to help safeguard his success. “I have found a meaningful mentor in Beth Ernst, the faculty specialist for the Academic and Business Communication Skills course. Her guidance has been instrumental in helping me navigate career development within the American professional context, particularly as an international student learning workplace norms, expectations and communication styles. She has also supported my integration into the Kalamazoo community by encouraging cultural engagement, confidence and effective communication across diverse settings.” During his time at WMU, Gyimah has welcomed the changes in his education
GW Law Professor Mary Anne Franks has been selected as a spring 2026 fellow with the University of Chicago’s Forum for Free Inquiry and Expression. Professor Franks, the Eugene L. and Barbara A. Bernard Professor in Intellectual Property, Technology, and Civil Rights Law, is an internationally recognized expert on the intersection of civil rights, free speech, and technology. As a fellow, she will explore the tensions between free expression and harm and connect directly with University of Chicago students through office hours and campus conversations. The Chicago Forum promotes the understanding, practice, and advancement of free and open discourse at the University of Chicago and beyond. Professor Franks, who taught at the University of Chicago Law School as a Bigelow Fellow early in her career, says she is looking forward to returning to the institution that helped shape her scholarly trajectory. “The U of C provided such an intellectually vibrant and challenging community for me when I was starting out as a legal academic,” she said. “I am grateful for the opportunity to return there as a Fellow for the Chicago Forum for Free Inquiry and Expression, especially at a time when authoritarian attacks are gravely endangering academic freedom and freedom of expression in the United States.” Professor Franks’ scholarship has had a global impact. She has written two books, Fearless Speech: Breaking Free from the First Amendment and The Cult of the Constitution: Our Deadly Devotion to Guns and Free Speech. Her scholarship has also been published in numerous law journals, including the Harvard Law Review, the California Law Review, and the UCLA Law Review. Earlier this year, she received the NAACP’s Archwell Digital Civil Rights Award, which was presented in partnership with Archwell Philanthropies, home to the charitable work of Prince Harry and Meghan, the Duke and Duchess
Time for government, business leaders to figure out AI cybersecurity regulation Experts say capabilities of agentic AI rising, along with risk to personal data, economy, national security As new agentic AI models continue to come online, cybersecurity experts laud their ability to sift through vast quantities of data quickly and autonomously — making them great tools to help fight cybercrime. But, they warn, those attributes could also be put to work by bad actors to hack systems and risk our personal data, our economy, and our national security. A group of cybersecurity experts were recently brought together for a Berkman Klein Center for Internet and Security discussion, during which all agreed that it’s high time for business and government leaders to regulate the tech — before it’s too late. Cybercrime, recent data from IBM shows, is rising rapidly. According to a 2026 study, the company found that cyberattacks aimed at public-facing software and systems applications — many of which utilized AI — had a year-over-year increase of 44 percent. High-profile attacks include the November data breach of Anthropic — the AI company behind the Claude Code assistant. Attackers were able to use their own AI models to scan for weak spots in its source code and publish its inner workings. “The unfortunate thing is that the bad people only have to win once in some sense, whereas the defenders have to win all the time,” said James Mickens, Gordon McKay Professor of Computer Science. “To me, at least, that’s a concerning aspect of what it means to think about agentic cyber security, attacks and defenses.” Moreover, cybercriminals have made alarming progress in phishing attacks over recent months, using AI to fine-tune targets and craft messages. “A year ago, we still had email messages in our inbox that had misspellings that
Cybersecurity researchers have warned of an active malicious campaign that's targeting the workforce in the Czech Republic with a previously undocumented botnet dubbed PowMix since at least December 2025. "PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade the network signature detections," Cisco Talos researcher Chetan Raghuprasad said in a report published today. "PowMix embeds the encrypted heartbeat data along with unique identifiers of the victim machine into the C2 URL paths, mimicking legitimate REST API URLs. PowMix has the capability to remotely update the new C2 domain to the botnet configuration file dynamically." The attack chain begins with a malicious ZIP file, likely delivered via a phishing email, to activate a multi-stage infection chain that drops PowMix. Specifically, it involves a Windows Shortcut (LNK) that's used to launch a PowerShell loader, which then extracts the malware embedded within the archive, decrypts it, and runs it in memory. The never-before-seen botnet is designed to facilitate remote access, reconnaissance, and remote code execution, while establishing persistence by means of a scheduled task. At the same time, it verifies the process tree to ensure that another instance of the same malware is not running on the compromised host. PowMix's remote management logic allows it to process two different kinds of commands sent from the C2 server. Any non #-prefixed response causes PowMix to shift to arbitrary execution mode, and decrypt and run the obtained payload. - #KILL, to initiate a self-deletion routine and wipe traces of all malicious artifacts - #HOST, to enable C2 migration to a new server URL. In parallel, it also opens a decoy document with compliance-themed lures as a distraction mechanism. The lure documents reference legitimate brands like Edeka and include compensation data and valid legislative references, potentially in an
Alden Trust Grant Powers Creation of Cybersecurity Teaching Lab at St. Lawrence St. Lawrence University has received a $200,000 grant commitment from the George I. Alden Trust to support a new Cybersecurity Teaching Laboratory that will enhance the University’s newest academic major: Cybersecurity. The grant continues the Alden Trust’s longstanding partnership with St. Lawrence, which has strengthened campus learning facilities at pivotal moments—including support for the Bloomberg Finance Lab. The Cybersecurity Teaching Lab builds on that momentum, supporting critical infrastructure upgrades to transform a traditional classroom into a specialized environment designed specifically for one of today’s fastest-growing and most in-demand fields. The lab will provide a dynamic, collaborative learning environment where students develop technical expertise and knowledge through simulations, collaborative projects, and real-world problem solving. Planned for completion this spring and summer, the Cybersecurity Teaching Laboratory is expected to open its doors to students and faculty in fall 2026. The Cybersecurity major is the seventh academic program launched at St. Lawrence since 2020, reflecting the University’s commitment to expanding interdisciplinary offerings aligned with emerging career opportunities. “We are grateful to the George I. Alden Trust for its generous support of this important new facility, which will strengthen experiential learning opportunities for students in our new Cybersecurity major,” says President Kate Morris. “This investment will help prepare students for one of today’s fastest-growing fields through a liberal arts focus that complements interdisciplinary perspectives with content expertise.” Assistant Professor of Computer Science Kevin Angstadt ’14, who helped guide the Cybersecurity major from concept to approval, says the program was intentionally designed to balance technical depth with flexibility. “The new Cybersecurity Lab will serve as the hub for cybersecurity education at St. Lawrence, enabling us to teach a range of courses that bridge the gap between theory and practice and provide our students
Katie Bavoso sits down with MK Tong, CEO of SotaTek USA, to break down why infrastructureânot AI modelsâis the real bottleneck for enterprise success SecurityBridge CEO Jesper Zerlang discusses SAP security, AI risks like data poisoning, and why channel partnerships are key to 2026 growth. Spyglass MTG CEO Dori Albert explains how organizations can build secure and data-driven AI platforms that deliver real business value. Leaders from Harbor IT explain why the traditional generalist MSP model is fading and how specialization, cybersecurity expertise, and vertical industry focus are shaping the future of managed services. In this Channel Insider crossover, the hosts of The Neuron break down the AI race, the bubble debate, and what todayâs tools really mean for businesses and everyday users. SurePath AI CEO Casey Bleeker explains how organizations can accelerate generative AI adoption using zero trust principles and AWS guardrails without increasing security and compliance risk. - Channel Business - Security - AI - Infrastructure Related Topics - - Lists & Awards Top ArticlesLink to AI 50 ListAI 50 ListChannel Insider's editorial team spotlights the top AI leaders from MSPs, vendors, and channel businesses delivering measurable outcomes.Link to CML 100 HonoreesCML 100 HonoreesCheck out our CML 100 List to discover the top channel marketing individuals who are transforming channel marketing for their organizations.Link to HSP 250 ListHSP 250 ListView our HSP250 list to see the top Hybrid Solution Providers that have proactively embraced the future of tech.Link to The 2024 Channel Insider VIP ListThe 2024 Channel Insider VIP ListChannel Insider sought nominations from IT vendors, solution providers, and partners to highlight impactful collaborations. Check out our top choices here. - Resources Resource HubsFeatured ResourcesLink to Video: SotaTek US CEO on AI Infrastructure Mistakes MSPs Must FixVideo: SotaTek US CEO on AI Infrastructure Mistakes MSPs Must Fix Katie
When Anthropic launched Project Glasswing earlier this month, it did so with the kind of announcement that sounded like public service and read like a market consolidation. The initiative brought together Amazon Web Services (AWS), Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorgan Chase, the Linux Foundation, Microsoft, Nvidia, and Palo Alto Networks — essentially the who’s who of the global technology industry — under a single coordinated effort to secure the world’s most critical software using an unreleased AI model called Claude Mythos Preview. Published - April 17, 2026 06:12 am IST
The arrival of artificial intelligence (AI) supercharged technology stocks in recent years, but the situation changed in 2026. Wall Street's "great rotation" away from tech stocks caused a sharp drop in the share prices of cybersecurity companies. Now, investors have an opportunity to scoop up stocks in the sector at attractive valuations. Buying the dip makes sense because cybersecurity is a necessity to safely navigate online. That's why the industry is forecast to grow from $248 billion in 2026 to $699 billion by 2034. In fact, Palo Alto Networks (PANW +1.74%) CEO Nikesh Arora took advantage of the situation to buy company shares worth about $10 million in March. This was his first buy since 2019. Here's a look at this situation and why it makes sense to buy cybersecurity stocks now. Cybersecurity remains a resilient sector In early 2026, Wall Street believed that artificial intelligence (AI) could usurp cybersecurity companies' business. But several factors make that possibility unlikely. The stakes are too high for organizations to entrust IT security to unproven AI substitutes from the likes of Anthropic, despite its release of an AI capable of finding software vulnerabilities. Look no further than CrowdStrike's technical glitch in 2024 for an example of cybersecurity's central role in today's digital world. The company's mistake caused global disruption to airlines, banks, and hospitals. Rather than lose to AI, the more likely scenario is for cybersecurity enterprises to partner with the companies building artificial intelligence. Both Palo Alto Networks and SentinelOne (S +5.17%) are collaborating with Alphabet-owned Google Cloud to ensure AI infrastructure is protected. NASDAQ: PANW Key Data Points Moreover, several IT security providers have already woven artificial intelligence into their platforms. A prime example is SentinelOne, an early adopter of the tech, having built AI into the core of its systems
Cybersecurity experts warn of new CAPTCHA scam How to protect yourself online ST. LOUIS, Mo. (First Alert 4) - You’ve probably seen CAPTCHA security prompts on some websites to verify that you’re human. But cybersecurity experts are warning you to watch out for CAPTCHA scams. CAPTCHA stands for Completely Automated Public Turing test to tell Computers and Humans Apart. Retail, banking, and other websites often ask users to click on CAPTCHA prompts to verify that they’re not a robot. CAPTCHA prompts are designed to prevent automated bots from rapidly buying up inventory of things like popular concert tickets or products, or opening online accounts. But Dean Gefen, CEO and founder of cybersecurity firm NuKudo, says fake CAPTCHA scams are popping up on both real and fake websites. Some will ask users to press Windows Key +R, then Ctrl +V, then Enter, ask users for passwords to accounts, or to download something on their device. “If the CAPTCHA is asking you to put something on your device, to do a shortcut, it shouldn’t be the case. Also, CAPTCHA doesn’t require you to insert your name or password. And it doesn’t require you to download software on your device,” explained Gefen. Those requests, he said, are red flags for CAPTCHA scams. The Identity Theft Resource Center reports that when victims press the sequence of keys, it can open a hidden command box on the device, paste in and run a script to download a virus. The ITRC says it’s called the “STealC” virus, which can track what you do on the device, as well as collect passwords and cookies from Outlook and other accounts. If you do fall for a CAPTCHA scam, ITRC says immediately take action: - Disconnect your device from the internet, but turning off the WIFI or unplug the
When it comes to cybersecurity readiness, McKaveney presented five questions that small districts and those with limited staffing and budgets should answer. - Do we know what we have, what data we protect and where our biggest risks are? - Are we using basic protections that prevent the most common attacks? - Would we notice if something went wrong? - What do we do if a cyber incident happens tomorrow? - Could we recover learning and operations quickly after an incident or other disaster? Identify Cyber Inventory and Risks CoSN guidance recommends starting with an asset inventory and risk assessment to ensure cybersecurity efforts are directed properly to maximize investments. This could be as simple as a list on a spreadsheet or identifying assets via helpdesk software, McKaveney said. DISCOVER: K–12 schools need a roadmap for effective cybersecurity. Richard Platts, CTO of Allegheny Intermediate Unit in Pennsylvania, said data inventory is just as important as hardware and software inventory. Governance and ownership are a large piece of that. Data ownership is a three-tier system, he said. “Think about your your IEP [Individualized Education Program] management software,” he said. “I've always insisted that that data owner is the special education director. It's a named person who owns that data. They might not do the daily maintenance of that data or the data entry, but at the end of the day, they're responsible for the overall quality of that data to be able to provide services to students.” The next tier down are the data stewards, the people responsible for the maintenance and fitness the data, typically the IT team. “Then you have a lot of other people down there, as general data users, who might be doing the day-to-day data entry or are relying on that data to do their job,”