Tiny termites can bring down entire structures. They don't attack from the outside. They burrow into microscopic gaps, quietly weakening the foundation until collapse becomes inevitable. That is exactly how modern supply chain cyberattacks work. Attackers rarely go after large corporations head-on. Those systems are heavily fortified. Instead, they target smaller partners — vendors, software dependencies, managed service providers — where defenses are weaker. These entry points become stepping stones into the broader ecosystem. Recent reporting on data breaches shows how silent these attacks have become. Most companies do not detect intrusions until their data appears on the dark web. On the surface, systems appear intact. Underneath, they are already compromised. According to Anastasia Tikhonova, head of APT research at Group-IB, attackers increasingly exploit trusted channels rather than direct vulnerabilities. AI tools are accelerating this shift, enabling faster detection of even minor weaknesses in open-source software. The result is a sharp rise in supply chain attacks. South Korea, with its globally competitive manufacturing and financial sectors, has become a particularly attractive target in the Asia-Pacific region, ranking fifth in the region for attack frequency. The problem is not awareness. It is economics. For small and mid-sized companies, security is still viewed as a cost center. Building multi-layered defenses is expensive. Maintaining them is even harder. Continuous monitoring requires skilled personnel that many firms simply cannot afford. Government support exists, but it is narrowly structured. Voucher programs help companies adopt security solutions, but only at the point of installation. They do not cover what matters most: updates, maintenance and long-term operation. Software without updates quickly becomes obsolete. In practice, it can turn into a vulnerability itself. Industry officials describe a familiar pattern. Companies deploy security tools when subsidies are available. Once support ends, maintenance contracts lapse. Systems remain in place but
Apr 27, 2026 · via thelec.net
25 open-source cybersecurity tools that don’t care about your budget Regardless of the operating system you use, managing secrets, apps, cloud, compliance, and security operations can be overwhelming. The free, open-source tools presented in this article can help you detect threats, increase visibility, enforce controls, and investigate and respond to incidents throughout the development and operational lifecycle. Allama: Open-source AI security automation Allama is an open-source security automation platform that lets teams build visual workflows for threat detection and response. It includes integrations with 80+ types of tools and services typical in security operations, including SIEM systems, endpoint detection and response products, identity providers, and ticketing systems. Anubis: Open-source web AI firewall to protect from scraper bots Anubis is an open-source tool designed to protect websites from automated scraping and abusive traffic by adding computational friction before a request is served. Maintained by TecharoHQ, the project targets a growing problem for site operators who want to keep content accessible to humans while limiting large scale automated collection. Asqav: Open-source SDK for AI agent governance AI agents are executing consequential tasks autonomously, often across multiple systems and with little record of what they did or why. Asqav, a Python SDK released under the MIT license, addresses that gap by attaching a cryptographic signature to each agent action and linking entries into a hash chain. Bandit: Open-source tool designed to find security issues in Python code Bandit is an open-source tool that scans Python source code for security issues that show up in everyday development. Many security teams and developers use it as a quick way to spot risky coding patterns early in the lifecycle, especially in projects that already rely on automated linting and testing. Betterleaks: Open-source secrets scanner Secrets scanning has become standard practice across engineering organizations, and Gitleaks has
Apr 27, 2026 · via helpnetsecurity.com
The National Computer Emergency Response Team (NCERT) has introduced a structured set of criteria for registering cybersecurity professionals who will provide consultancy and audit readiness services under the Pakistan Information Security Framework (PISF). The move is aimed at strengthening the cybersecurity posture of organizations across Pakistan by ensuring compliance with security standards and improving preparedness for audits and assessments. Under the new framework, registered consultants will operate across three major domains: IT security, Operational Technology (OT) security, and cloud security. Their responsibilities will include conducting gap assessments, preparing implementation roadmaps, and assisting organizations during security audits. Consultants will be categorized into four tiers: Expert, Senior, Junior, and domain-specific specialists in IT, OT, and cloud security. Organizations have also been classified into different risk categories. High-risk entities, designated as CAT-I and CAT-II, will be required to engage Expert Consultants due to the complexity and sensitivity of their systems. These experts will lead security assessments and guide organizations through compliance and audit requirements. For lower-risk categories, including CAT-III and CAT-IV, the requirements are more flexible. Senior or Expert Consultants may be assigned depending on the organization’s complexity, while Junior Consultants may assist with tasks such as vulnerability assessments and penetration testing under supervision. Expert Consultants are required to have at least 12 years of experience in IT and information security, including a minimum of 6 years in cybersecurity and at least 3 years in areas such as risk assessments and compliance audits. They must also hold advanced certifications, including CISSP and CISM, along with domain-specific credentials such as ISO 27001 for IT, ISO/IEC 27017 for cloud security, and ISA/IEC 62443 for OT systems. Senior Consultants must meet similar standards but with comparatively lower experience requirements and fewer audit-related engagements. Junior Consultants must have at least three years of cybersecurity experience and hold
Apr 27, 2026 · via propakistani.pk
Improving State and Local Government Cybersecurity State and local governments face rising cybersecurity risks that strain budgets, disrupt services, and erode public trust. Governments need targeted investments in modern infrastructure, continuous monitoring, and stronger third-party risk management to protect critical services. KEY TAKEAWAYS Key Takeaways Contents State and Local Governments Face Increased Cybersecurity Risk. 4 State and Local Government Cybersecurity is Fragmented, Underfunded, and Unprepared. 9 Introduction Cyberattacks in the United States have surged in frequency and impact since the start of this decade, with the country facing several hundred on any given day.[1] The proliferation of digital systems and interconnected infrastructure has widened the attack surface, while adversaries have become more organized and technologically advanced, increasing the sophistication of their methods. These trends amplify both the scale and severity of incidents, making recovery costlier and disruptions more prolonged. These attacks strike federal, state, and local governments nationwide regardless of size or location, putting personal data, critical infrastructure, essential government services, and business operations at risk. State and local governments now stand on the front lines of a rapidly changing cyberspace, facing a range of cyberthreats, from opportunistic attackers exploiting basic security weaknesses to organized groups using advanced techniques. Underfunded IT departments, aging critical infrastructure sectors, and a chronic shortage of cybersecurity professionals leave many state and local governments exposed. At the same time, cybercriminals, organized groups, and nation-state adversaries such as Russia, China, and Iran are deploying increasingly sophisticated tools to exploit these weaknesses. Recent incidents demonstrate the scope of these threats, including the 2023 ransomware attack on Dallas, Texas, which disrupted police, fire, and court systems and exposed 30,000 residents’ data; the attack on Oakland, California, that compromised 600 gigabytes of the city’s employee data; the 2024 Salt Typhoon infiltration of U.S. telecommunications networks such as Verizon and
Apr 27, 2026 · via itif.org
via 10Guards
The Cyber Security Hub™’s Post
More from this author
Explore content categories
- Career
- Productivity
- Finance
- Soft Skills & Emotional Intelligence
- Project Management
- Education
- Technology
- Leadership
- Ecommerce
- User Experience
- Recruitment & HR
- Customer Experience
- Real Estate
- Marketing
- Sales
- Retail & Merchandising
- Science
- Supply Chain Management
- Future Of Work
- Consulting
- Writing
- Economics
- Artificial Intelligence
- Employee Experience
- Workplace Trends
- Fundraising
- Networking
- Corporate Social Responsibility
- Negotiation
- Communication
- Engineering
- Hospitality & Tourism
- Business Strategy
- Change Management
- Organizational Culture
- Design
- Innovation
- Event Planning
- Training & Development
Apr 27, 2026 · via linkedin.com
As the global automotive industry moves toward deeper integration of electronic and electrical (E/E) architectures, a new axis of competition is emerging: digital sovereignty. Fueled by rising concerns over cybersecurity, control of the software-defined...
The article requires paid subscription. Subscribe Now
Apr 27, 2026 · via digitimes.com
What’s New with AI and Cybersecurity: Inside the New Era of Ecosystem-Wide Supply Chain Compromise Published by Pearson Join Omar Santos and guest David Bianco for a live deep dive into systemic software supply chain attacks and defenses In recent months, a wave of high-impact attacks exposed systemic weaknesses across trusted ecosystems—from the compromise of Aqua Security’s Trivy scanner to CI/CD supply chain attacks and the hijacking of the Axios npm package, which reaches over 100 million weekly downloads. These incidents signal a broader shift: supply chain attacks are now the preferred model for scalable cybercrime and state aligned operations, exploiting trust, identity, and inherited access rather than isolated vulnerabilities. Join Omar Santos, with special guest -cybersecurity researcher and strategist David Bianco, for a focused exploration of this new era of software supply chain security. Examine modern attack techniques such as GitHub Actions tag hijacking, malicious dependency publishing, and compromised maintainer credentials, and learn the concrete defensive shifts required to respond—including immutable dependency pinning, CI/CD permission segmentation, and credential hardening. You’ll leave with a practical framework for securing software supply chains against the next generation of ecosystem-wide attacks. What you’ll learn and how you can apply it - Learn the latest trends in AI and cybersecurity. - Apply AI-driven tactics for threat detection, automate incident response, and proactively hunt for risks using the latest AI tools. - Assess the security implications of advanced AI, such as coding agents, agentic AI applications, and large language models (LLMs). - Design strategic methodologies for integrating AI into cybersecurity programs. This live event is for you because... - You’re an AI/ML Engineer or Data Scientist who wants to learn the latest trends in AI and cybersecurity. - You’re a Cybersecurity Professional (Analyst, Engineer, Architect, or Consultant) looking to upgrade your skills for the AI-driven
Apr 27, 2026 · via oreilly.com
ImageFlow - stock.adobe.com Black Hat Asia: Privacy and cyber security are inseparable The separation of privacy and security is no longer tenable in a world where exposed personal data is increasingly the entry point for major cyber incidents, delegates at Black Hat Asia 2026 were told Privacy is not a side issue to cyber security but a core part of it, as privacy failures can easily become security breaches, investigative journalist and author Violet Blue told delegates during the opening keynote at Black Hat Asia 2026 in Singapore. While terms like “privacy policy” and “anonymised data” can sound reassuring, they do not always mean privacy is truly protected, said Blue. She argued that the technology industry has too often treated privacy as optional while reserving urgency for security. This split, she suggested, is no longer tenable in a world where personal data is increasingly the entry point for major cyber incidents. Security professionals often believe “privacy is dead”, she said, leading them to “shrug and engage in practices they know they shouldn't”. Blue argued that the same business incentives eroding privacy also weaken security, warning that relentless data collection fuels surveillance-based business models and creates new attack paths. “Surveillance capitalism doesn’t just erode privacy, it creates an attack surface,” she said. “Every data broker is a target. Every adtech SDK [software development kit] is a supply chain risk. Every ‘we need this telemetry’ decision is a pre-positioned asset for a future breach.” While a common counterargument is that security carries a financial cost and privacy regulation is an added compliance burden, Blue said the incentives working against privacy are equally detrimental to security. She highlighted several high-profile incidents where exposed personal information was not just part of the fallout, but the weaponised entry point for the attack itself. In the
Apr 27, 2026 · via computerweekly.com
Providing a view of cybersecurity leaders’ responses to changes across the industry, including increased regulatory pressure and accelerating AI adoption. TAMPA, FL, UNITED STATES, February 19, 2026 /EINPresswire.com/ — Cyber Security Tribe has announced the release of its 2026 Annual State of the Industry Report, delivering insight into how senior cybersecurity leaders are adjusting strategy, investment, and operating models as organizations move further into an AI-driven era. Now in its latest edition, the Annual Report reflects perspectives gathered from 455 of cybersecurity practitioners in senior leadership roles across multiple industries and regions. The findings offer a grounded view of how CISOs and executive teams are dealing with regulatory demands, budget pressure, workforce constraints, and rapid technological change. The 2026 report is structured around three pillars that continue to define cybersecurity maturity: People, Technology, and Process. Together, these themes provide a practical framework for understanding where organizations are focusing attention and how security programs are changing in response. Dorene Rettas, Co-Founder at Cyber Security Tribe, states how “Many of the responses closely mirror the conversations we’re having with CISOs every day, with few real surprises. The most concerning data point relates to post-quantum cryptography (PQC): 78% of respondents have either not discussed it internally or have taken no formal action. This is an issue organizations need to get ahead of now; if you wait until it hits, you’ve waited too long.” Download the full report here: https://www.cybersecuritytribe.com/annual-report People The People section of the 2026 Annual State of the Industry Report examines the leadership, workforce, and organizational dynamics shaping cybersecurity teams. It explores the relationship between CISOs and the board, including how security leaders communicate risk in commercial terms and secure long-term executive backing. The report looks at hiring priorities, evolving role requirements, and the ongoing challenge of building capable teams in
Apr 27, 2026 · via blufftontoday.com
Nearly half of cybersecurity pros want to quit - here's why Follow ZDNET: Add us as a preferred source on Google. ZDNET's key takeaways - There's a big mismatch between demand and rewards in cyber. - Working pressure is only likely to increase due to the use of AI. - Security staff should focus on strategy and communication skills. Almost 20% of organizations have reported a major security attack in the past two years, and the threat environment, whether due to criminal activity or the rise of new AI-enabled models, such as Anthropic's Mythos, continues to evolve at breakneck speed. However, the cybersecurity professionals who help their enterprises manage these challenges don't feel adequately rewarded -- and most are fed up with the situation. That's the conclusion from the newly released Harvey Nash Global Tech Talent & Salary Report, which surveyed over 3,646 technology professionals globally. While 19% of respondents reported a major attack at their firm in the past 24 months, those working in the security specialism were the least likely to report a pay increase over the last year. Also: These 4 critical AI vulnerabilities are being exploited faster than defenders can respond Only 29% of cyber professionals said they'd received additional compensation for their efforts, which is in stark contrast to other roles, where at least half of tech professionals received a pay increase in 2025, specifically in DevOps (56%), product management (51%), and business analysis (50%). "The research clearly tells us that there's a big mismatch between the demand and the reward in cyber," said Ankur Anand, group CIO at technology and talent solutions provider Nash Squared, which owns tech recruiter Harvey Nash, the firm that produced the survey. "I think this mismatch is due to the complacency of many boards saying nothing bad has happened
Apr 26, 2026 · via zdnet.com
Update about February cybersecurity incident at University of Hawaiʻi Cancer Center People who might have been impacted by a February University of Hawaiʻi Cancer Center cybersecurity incident are reminded that deadlines are approaching to enroll in 12 months of free credit monitoring and $1 million in identity theft insurance. Enrollment codes will no longer work after deadlines pass. Deadlines - May 31: Enrollment deadline for people who received Multiethnic Cohort study notification letter codes. - May 31: Closure of the call center to assist all potentially affected people: - Kroll Call Center: 844-443-0842 - Hours: 3:30 a.m. to 4 p.m. Monday through Friday - June 20: Enrollment deadline for people who received email-based Experian enrollment codes. Cybersecurity incident The cybersecurity incident involved historical driver’s license and voter registration records — including Social Security numbers — used decades ago to recruit participants for epidemiological research studies. No information kept by the center’s clinical trials operations, patient care or other divisions was impacted. Potentially impacted people Personal information affected by the incident was located in a subset of research files stored on certain servers that support University of Hawaiʻi Cancer Center’s epidemiology research operations, including: - Two files containing names and birthdates in combination with Social Security numbers: The first, containing driver’s license numbers, was collected in 2000 from Hawaiʻi Department of Transportation; the second, containing voter registration information, was collected in 1998 from the City and County of Honolulu. At that time, driver’s license numbers numbers in Hawaiʻi were typically based on Social Security numbers, and City and County of Honolulu voter registration information also often contained Social Security numbers - Files for study participants in the long-running Multiethnic Cohort Study, with recruitment for participants in Hawaiʻi and Los Angeles from 1993 to 1996, and three other epidemiological studies of diet
Apr 26, 2026 · via bigislandnow.com
Key Points Anthropic claims its latest large language model could be used by hackers to exploit vulnerable code bases. It provided a handful of big enterprises with early access to help prevent widespread cybersecurity breaches. This company made it on the roster, and it could be more important than ever in the age of LLM-based attacks. Anthropic announced Claude Mythos, its most advanced large language model yet, earlier this month. Announced is the keyword. The broad release of the artificial intelligence (AI) model has been delayed due to security concerns. Anthropic claims Mythos is so good at coding that it can identify and exploit vulnerabilities in codebases that have existed undetected for years. To prevent its product from causing too much harm, Anthropic established Project Glasswing, an initiative that invites a handful of top enterprises to use Mythos to find and patch vulnerabilities across operating systems, web browsers, and other critical software before it is more widely released. Will AI create the world's first trillionaire? Our team just released a report on the one little-known company, called an "Indispensable Monopoly" providing the critical technology Nvidia and Intel both need. Continue » While many view the improved capabilities of large language models as a major threat to cybersecurity stocks, the opposite may prove true -- at least for some companies. And Project Glasswing may have just crowned a cybersecurity champion. The cybersecurity giant on Project Glasswing's roster Among the list of companies with early access to Claude Mythos is Palo Alto Networks(NASDAQ: PANW). Palo Alto's position as a leading cybersecurity vendor, offering solutions across network security, cloud security, and security operations, undoubtedly played a key role in the company winning a spot in Project Glasswing. Importantly, Palo Alto's scale may prove an increasingly valuable competitive advantage as large language models continue
Apr 26, 2026 · via theglobeandmail.com
It’s time to regard cybersecurity as human safety Tabletop exercises with senior leaders, evaluating employee reports of risk and engaging training programs should be part of plants’ regular safety procedures. The manufacturing industry has a strong culture of evaluating risks to human safety and managing those risks by deploying controls, such as safety procedures and employee training. Yet cybersecurity has historically been held apart, based on a belief that it is somehow different. As the world moves to Industry 4.0, it’s time for manufacturers to remove the artificial wall between risks to safety and risks to cybersecurity and take a comprehensive approach towards managing business risk. It would be unthinkable for a manufacturing company to not have policies and safety procedures to effectively reduce the risk and impact of a fire that could lead to the loss of human life and a plant shutdown. These compliance operations include regular safety inspections, teaching employees to follow equipment safety checklists and providing employees with a means to report risks, such as near misses. However, consider that earlier this year, an industrial leader was forced to shut down its manufacturing plant due to a fire caused by a piece of malfunctioning equipment. This was not due to a physical defect or a lack of safety inspections; rather, it was due to a successful cyberattack. While these kinetic cyberattacks have often been the stuff of Hollywood films, they are real, and cause significant material physical and financial damages. Fortunately, there are several steps that manufacturers can take right now to better secure their plants – and people – against future attacks. 1. While preventing cyber accidents could be stated as every employee’s responsibility, meaningfully incorporating this new behavior into a company’s culture must start with senior leadership. C-suite executives can model good cybersecurity by
Apr 26, 2026 · via securityinfowatch.com
Anthropic announced Claude Mythos, its most advanced large language model yet, earlier this month. Announced is the keyword. The broad release of the artificial intelligence (AI) model has been delayed due to security concerns. Anthropic claims Mythos is so good at coding that it can identify and exploit vulnerabilities in codebases that have existed undetected for years. To prevent its product from causing too much harm, Anthropic established Project Glasswing, an initiative that invites a handful of top enterprises to use Mythos to find and patch vulnerabilities across operating systems, web browsers, and other critical software before it is more widely released. While many view the improved capabilities of large language models as a major threat to cybersecurity stocks, the opposite may prove true -- at least for some companies. And Project Glasswing may have just crowned a cybersecurity champion. The cybersecurity giant on Project Glasswing's roster Among the list of companies with early access to Claude Mythos is Palo Alto Networks (PANW +3.09%). Palo Alto's position as a leading cybersecurity vendor, offering solutions across network security, cloud security, and security operations, undoubtedly played a key role in the company winning a spot in Project Glasswing. Importantly, Palo Alto's scale may prove an increasingly valuable competitive advantage as large language models continue to improve. That's especially true if AI labs come to it first before releasing models to the broader public. Palo Alto's scale means it can afford to spend money on tokens to use these models effectively and cover a broad range of attack surfaces for enterprises. That could leave smaller companies falling behind Palo Alto in capabilities, and create new opportunities for it to expand through acquisitions. As large language models lower the barrier to creating cyberattacks and speed up the discovery of vulnerabilities, demand for cybersecurity solutions
Apr 26, 2026 · via fool.com
Critical Vulnerability Exposes Linux Systems To Root-Level Takeover A newly disclosed security flaw affecting Linux systems has raised fresh concerns about the integrity of core package management infrastructure, after researchers revealed that a vulnerability lurking for over a decade could allow attackers to escalate privileges and gain root-level control. The flaw, dubbed “Pack2TheRoot,” has been formally tracked as CVE-2026-41651 and impacts the widely deployed PackageKit daemon—a background service responsible for managing software installation, updates, and removal across many Linux distributions. Despite being rated “medium severity,” the vulnerability carries a CVSS score of 8.8 out of 10, reflecting its potentially serious impact when exploited under the right conditions. A 12-Year-Old Weakness in a Core Linux Component Security researchers from the Deutsche Telekom Red Team uncovered the flaw during an internal investigation into how PackageKit processes package management requests. Their findings indicate that the vulnerability has existed since at least PackageKit version 1.0.2, released in November 2014, and remained undetected through subsequent versions up to 1.3.4. PackageKit plays a central role in many Linux environments by acting as an abstraction layer between graphical software centers, command-line tools, and underlying package managers such as APT or DNF. Because it often runs with elevated privileges, any flaw in its logic can have far-reaching consequences. According to the researchers, the issue stems from how PackageKit handles certain command execution pathways. Under specific conditions—particularly observed in Fedora environments—commands such as pkcon install could be executed without proper authentication checks, effectively bypassing expected security boundaries. This misconfiguration allows a local user, even one with limited privileges, to install or remove system packages—actions that typically require administrative rights. In turn, this opens a pathway to full privilege escalation. AI-Assisted Discovery Highlights Emerging Research Methods In an unusual twist, the researchers reported using the AI system Claude Opus to
Apr 26, 2026 · via linkedin.com
Cyber Security & Cloud Congress North America 2026 Comes to San Jose Cyber Security & Cloud Congress North America 2026 Comes to San Jose Press Release Date 03-10-2026 Cyber Security & Cloud Congress North America 2026, May 18-19 in San Jose, unites CISOs and security leaders to tackle top enterprise cyber challenges. SAN JOSE, CA, UNITED STATES, March 10, 2026 /EINPresswire.com/ -- "As cyber threats evolve alongside AI, hybrid cloud, and increasingly complex digital operations, enterprise security can no longer be an afterthought," commented Michael Hughes, Head of Conference. "Cyber Security & Cloud Congress North America 2026 brings together the industry’s top leaders to share practical strategies, from Zero Trust frameworks to AI-driven threat detection, empowering organizations to stay ahead of attacks and protect what matters most." The Cyber Security & Cloud Congress North America 2026 will be held on May 18-19, 2026 at the San Jose McEnery Convention Center, uniting CISOs, enterprise security architects, cloud security leaders, and infrastructure specialists to tackle the most pressing cybersecurity challenges in the modern enterprise. As organizations scale AI, hybrid cloud, and complex digital operations, cybersecurity is mission-critical. The event spotlights Zero Trust strategies, AI-powered threat detection, cloud security frameworks, and advanced cyber risk management, giving leaders actionable insights to defend their environments. Key Themes - Board-level cybersecurity strategy and enterprise risk governance - Embedding security across IT and operational infrastructure - Modernising legacy systems and building resilient frameworks - Zero Trust models, adaptive defenses, and AI threat intelligence - Compliance, cyber insurance, and regulatory risk management - AI security risks, mitigation, and real-time detection Day One: Leadership & Enterprise Risk Executives and security leaders will explore how cybersecurity drives business outcomes. Sessions cover governance, translating cyber risk into measurable impact, modernising legacy systems, and embedding security into enterprise culture. Day Two: Cloud
Apr 26, 2026 · via natlawreview.com
BSides Maine Announces Internationally Acclaimed Cybersecurity Expert Jayson E. Street as 2026 Keynote BSides Maine Announces Internationally Acclaimed Cybersecurity Expert Jayson E. Street as 2026 Keynote Press Release Date 03-10-2026 BSides Maine, the first hacker conference in Maine debuts May 30, 2026 in Portland with keynote by Jayson E. Street. Tickets are just $25 and include lunch. PORTLAND, ME, UNITED STATES, March 10, 2026 /EINPresswire.com/ -- BSides Maine, the state’s first community-driven hacker conference, today announced that Jayson E. Street — globally recognized cybersecurity expert, author, and self-described “Hacker, Helper & Human” — will deliver the keynote address at the inaugural full-day event on Saturday, May 30, 2026. Tickets are priced at $25 and include lunch, making this one of the most accessible and high-value cybersecurity events in New England. Meet the Keynote: Jayson E. Street Few people in the world of cybersecurity carry a résumé quite like Jayson E. Street’s. FOX25 Boston dubbed him a “notorious hacker,” he was featured in an episode of National Geographic’s Breakthrough series where they called him “world class,” and the Director of Counterintelligence at the Pentagon has called him a “change agent.” Street himself prefers a simpler label: Hacker, Helper & Human. Street is a simulated adversary for hire — a professional engaged to test organizational security through social engineering, physical intrusion, and technical exploits. He has successfully robbed banks, hotels, government facilities, and biochemical companies across five continents, exposing vulnerabilities before malicious actors can find them. He is the author of the Dissecting the Hack series — required reading at colleges across the world. He has spoken at major security conferences in more than 50 countries, was invited to present training at the Pentagon on situational awareness, and serves as the DEF CON Groups Global Ambassador. He brings a rare level of
Apr 26, 2026 · via natlawreview.com
Intelligent Waves’ EPCE Wins Gold in 2026 Cybersecurity Excellence Awards. Highlights a secure mission-partner collaboration for contested environments. RESTON, VA, UNITED STATES, March 26, 2026 /EINPresswire.com/ — Intelligent Waves announced that its Ephemeral Partner Collaboration Environment, EPCE, received Gold in the Secure Collaboration Platform category in the 2026 Cybersecurity Excellence Awards, a recognition that underscores the company’s focus on secure, mission-ready collaboration for defense and intelligence environments. Intelligent Waves’ EPCE was recognized for addressing a growing operational challenge across modern missions: How to enable secure, rapid collaboration among distributed mission partners when communications are contested, infrastructure is limited, and the risk of exposure is high. Built for coalition and operational environments, EPCE provides an ephemeral, zero-trust collaboration capability that helps users quickly establish secure enclaves without relying on static infrastructure or traditional enterprise collaboration models. The platform incorporates identity-based controls, continuous authentication, just-in-time and just-enough access policies, and integrated multi-path encrypted transport across SATCOM, LTE, and ISP pathways. “Today’s mission environment demands more than secure communications. It requires trusted collaboration at speed,” said Tony Crescenzo, CEO of Intelligent Waves. “EPCE was designed to help mission partners connect, share, and act with confidence in environments where cyber risk, operational pressure, and degraded conditions are the norm.” Marqus Hutchinson, Intelligent Waves’ Chief Technology Officer, added: “EPCE can deploy secure collaboration enclaves in under two hours, eliminate endpoint data persistence, reduce hardware-associated attack surface, and improve interoperability across mission partners while supporting faster decision-making in high-risk environments. The recognition is particularly relevant as defense organizations continue to prioritize secure partner collaboration to support CJADC2, the Mission Partner Environment, and Agile Combat Employment objectives. In those settings, the ability to create a trusted shared environment without leaving behind a large technical footprint is becoming increasingly important. Rather than adapting commercial collaboration tools for operational
Apr 26, 2026 · via wisfarmer.com
UK Businesses Urged to Prioritise Cybersecurity and Misinformation in 2026, Report Finds UK Businesses Urged to Prioritise Cybersecurity and Misinformation in 2026, Report Finds Press Release Date 03-10-2026 New research finds that UK consumers are demanding business action on data breaches, disinformation, and supply chain risks. LONDON, UNITED KINGDOM, March 10, 2026 /EINPresswire.com/ -- To safeguard their reputation in 2026, UK businesses must urgently prioritise cybersecurity, data privacy, and countering misinformation, according to The Vantage Point report released today by global consultancy Reputation Leaders. Top UK Risks in 2026 from The Vantage Point Cybersecurity is Paramount: A clear majority of UK consumers (59%) believe businesses should prioritise planning for cybersecurity or data privacy breaches, making it the top reputational risk to proactively manage in 2026. Misinformation is a Major Threat: Nearly half (47%) of respondents want businesses to plan for the risks of misinformation, disinformation, or deepfakes, a risk amplified by the rapid advancement of AI. Economic and Geopolitical Concerns: An economic recession (40%) and supply chain & geopolitical trade disruption (40%) are high on the public's list of concerns in the wake of a year defined by tariffs, wars, and economic uncertainty. The Climate Change Divide: While climate change ranks lower overall (29%) as a priority, there is a significant generational gap. 37% of 18–24-year-olds want businesses to prioritise climate change, an understandable concern as it is they who will be most burdened by the effects of climate change over the long term. "What British citizens are telling us is that the risks of technology accelerated by AI, from cybersecurity to deepfakes, are of high reputational importance," said Laurence Evans, CEO of Reputation Leaders. "As such, deep technology issues are not just operational. They are also reputational risks if not anticipated and managed.” A Call to Action for UK
Apr 26, 2026 · via natlawreview.com
How AI is transforming cybersecurity from static, rule-based defenses to behaviour-driven, proactive systems how sophisticated phishing, malware and insider threats demand integrated tools the non‑negotiable role of human oversight, regulation and education in an AI-first world In the AI-driven world, cybersecurity will no longer be just about blocking attacks after they happen. In this conversation, Zoho’s AI Security Head, Sujatha S Iyer explains how organisations must move from static, rule-based defenses to behaviour-driven, AI-powered security that can detect anomalies early, secure data across tools and vendors, and build strong guardrails into systems from the start. The discussion also looks at insider threats, phishing, agentic AI, and why human oversight, compliance and continuous education remain central in the age of AI. Recently, there was a US cybersecurity agency that listed three risk areas in AI cybersecurity: cybersecurity of AI systems, AI-enabled cyber attacks and AI-enabled cyber defense. Where do you think most organisations are failing today across these three aspects, and how do you tackle each of them? Organisations today are far more privacy and security aware, with security moving from a checklist item to a core priority. This shift is largely driven by stricter regulations like GDPR, the California Privacy Act, and India’s Digital Personal Data Protection Act. The focus now is on building security into systems from day one. However, many organisations still rely on outdated rule-based systems that are easy to bypass, especially in insider attacks where users stay just below defined thresholds or show subtle anomalies like unusual login times. At the same time, threats have become more advanced. Modern malware and phishing are highly sophisticated and no longer depend on obvious signatures, which makes traditional detection less effective. This is where AI plays a key role. By focusing on behaviour rather than static rules, AI can
Apr 26, 2026 · via outlookbusiness.com