No-frills tech news

SuperCom to Report Second Quarter 2026 Financial Results on August 13th, 2026

TEL AVIV, Israel , Aug. 4, 2026 /PRNewswire/ -- SuperCom (NASDAQ: SPCB), a global provider of secured solutions for the e-Government, IoT and Cybersecurity sectors, will hold a conference call on Thursday, August 13, 2026, at 10 a.m. Eastern time (7 a.m. Pacific Time / 5 p.m. IL time) to discuss its financial results for the second quarter ended June 30, 2026. Financial results will be issued in a press release prior to the call. SuperCom management will host the conference call, followed by a question-and-answer period. Conference Call Dial-In Information: Date: Thursday, August 13, 2026 Time: 10 a.m. Eastern time (7 a.m. Pacific time) U.S. toll-free: 888-506-0062 Israel toll-free: 1-809-423-853 International: 973-528-0011 Access Code: SuperCom Link: https://www.webcaster5.com/Webcast/Page/2259/54375 Please call the conference telephone number 5-10 minutes prior to the start time. An operator will register your name and organization. About SuperCom Since 1988, SuperCom has been a global provider of traditional and digital identity solutions, providing advanced safety, identification and security solutions to governments and organizations, both private and public, throughout the world. Through its proprietary e-government platforms and innovative solutions for traditional and biometrics enrollment, personalization, issuance and border control services, SuperCom has inspired governments and national agencies to design and issue secure Multi-ID documents and robust digital identity solutions to its citizens and visitors. SuperCom offers a unique all-in-one field-proven RFID & mobile technology and product suite, accompanied by advanced complementary services for various industries including security and safety, community public safety, law enforcement, electronic monitoring, and domestic violence prevention. For more information, visit www.supercom.com. SuperCom IR Contact: [email protected] SOURCE SuperCom Share this article

SuperCom to Report Second Quarter 2026 Financial Results on August 13th, 2026

SuperCom to Report Second Quarter 2026 Financial Results on August 13th, 2026 Conference Call Dial-In Information: Date:                                   Thursday, August 13, 2026  Time:                                  International:                     973-528-0011 Access Code:                    Link:                                   https://www.webcaster5.com/Webcast/Page/2259/54375 Please call the conference telephone number 5-10 minutes prior to the start time. An operator will register your name and organization. About SuperCom Since 1988, SuperCom has been a global provider of traditional and digital identity solutions, providing advanced safety, identification and security solutions to governments and organizations, both private and public, throughout the world. Through its proprietary e-government platforms and innovative solutions for traditional and biometrics enrollment, personalization, issuance and border control services, SuperCom has inspired governments and national agencies to design and issue secure Multi-ID documents and robust digital identity solutions to its citizens and visitors. SuperCom offers a unique all-in-one field-proven RFID & mobile technology and product suite, accompanied by advanced complementary services for various industries including security and safety, community public safety, law enforcement, electronic monitoring, and domestic violence prevention. For more information, visit www.supercom.com. SuperCom IR Contact: [email protected] View original content to download multimedia:https://www.prnewswire.com/news-releases/supercom-to-report-second-quarter-2026-financial-results-on-august-13th-2026-302842474.html SOURCE SuperCom

GMO Internet Group to Field a Group-Wide Team at “DEF CON 34” CTF, the World's Premier ...

GMO Internet Group to Field a Group-Wide Team at “DEF CON 34” CTF, the World’s Premier Cybersecurity Competition Published Friday, July 31, 2026 | 7 a.m. Updated Friday, July 31, 2026 | 7 a.m. LAS VEGAS--(BUSINESS WIRE)--Jul 31, 2026-- GMO Internet Group, Inc. (TOKYO: 9449), a global leader in internet infrastructure and security headquartered in Tokyo, will send a group-wide team to compete in the Capture The Flag (CTF) competition at “DEF CON 34,” the world’s premier security conference, to be held August 6–9, 2026 in Las Vegas, USA. By feeding the knowledge gained on this world-class stage back into vulnerability assessments and product development, GMO will accelerate the realization of its vision that “GMO will protect your Internet Security.” This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260731335124/en/ The Cloud Village team that competed in “DEF CON 33” GMO Internet Group is home to more than 200 white-hat hackers across GMO Cybersecurity by Ierae and GMO Flatt Security combined — the largest number of any group in Japan (No. 1 in white-hat hacker headcount). Selected members drawn from this pool will take on “DEF CON 34.” [Results at “DEF CON 33” in 2025] Since joining "DEF CON" in 2023, GMO Internet Group has entered multiple teams each year. Last year's "DEF CON 33" results included: - GMO Ierae: Cloud Village CTF — 1st place in the world (three consecutive years) - Blue Water: DEF CON CTF Finals — 2nd place in the world - GMO Flatt Security: AppSec Village CTF — 3rd place in the world; Hardware Hacking Village CTF — 5th place in the world [Introducing the Teams Competing in “DEF CON 34” in 2026] DEF CON CTF Finals Team A mixed unit joined by a Japanese team, aiming for a third consecutive Finals appearance Blue

Meet the mentor behind tomorrow's cyber workforce

Middle schoolers don’t usually spend their summer afternoons cracking secret codes. But inside a computer lab in the School of Computing and Augmented Intelligence, part of the Ira A. Fulton Schools of Engineering at Arizona State University, groups of tweenagers gathered one day in May racing through password-cracking puzzles, deciphering secret messages and learning how hackers think. The exercises were part of Desert CodeSprouts, an annual computer science workshop for middle school students hosted by Fulton Schools faculty members. The one-day camp introduces students to cybersecurity, robotics, artificial intelligence, or AI, and privacy through hands-on challenges designed to feel more like games than lectures. For Ozgur Ozmen, a Fulton Schools assistant professor of computer science and engineering, the cybersecurity module wasn’t simply about entertaining students for an afternoon. It was about planting an idea. “If we can teach kids about security early on, then in the future they’ll design technology with security in mind instead of treating it as an afterthought,” Ozmen says. “Hopefully, the next generation will build systems with fewer and fewer security problems.” That approach reflects a recurring theme throughout Ozmen’s early career. He sees mentorship as a continuum, helping students discover cybersecurity in middle school, develop as researchers in college and eventually become mentors themselves. The sooner, the better Cybersecurity often suffers from a familiar problem. Products are designed to be fast, inexpensive and convenient. Security comes later, patched onto systems after vulnerabilities emerge. Ozmen believes education follows a similar pattern. Too often, students discover cybersecurity only after they’ve already chosen a technical specialty. By then, many of the habits and assumptions behind system design are already established. Desert CodeSprouts offers a different approach. This year’s workshop introduced middle school students to cybersecurity through Caesar ciphers, password-cracking exercises and interactive challenges hosted on the pwn.college cybersecurity

Türk Telekom builds AI-powered shield against rising cyber threats | Daily Sabah

Tür Telekom, which currently serves more than 5,000 organizations with over 50 products and services, is blocking thousands of phishing, DDoS and malware attacks every month thanks to its AI-powered systems As both the number and complexity of cyberattacks worldwide are rapidly increasing alongside artificial intelligence-powered attack techniques, one of Türkiye's leading telecoms and tech companies, Türk Telekom, is also giving AI an increasingly central role in its strategies. While millions of distributed denial-of-service (DDoS) attacks occur worldwide every day, AI-powered hacking techniques have increased these attacks both in number and in effectiveness. In parallel, global cybersecurity spending is expected to exceed $520 billion annually in 2026, while spending in Türkiye is projected to reach approximately $285.8 million by 2029. Türk Telekom is striving to be a key player in this evolving threat and market landscape, both as a provider of protection and as a developer of technology. The company currently serves more than 5,000 organizations with over 50 products and services. Thanks to its AI-powered systems, it blocks thousands of phishing, DDoS and malware attacks every month before they reach these organizations. 24/7 AI-driven security operations At the heart of the company's cybersecurity approach lies one of Türkiye's largest cybersecurity centers. The center employs nearly 130 engineers holding internationally recognized certifications including CCNA, CCNP, SANS and CEH, and provides uninterrupted service 24 hours a day, seven days a week. It is also accredited by TF-CSIRT, Türkiye's national cybersecurity incident response framework. One of the center's most notable features is its focus on detecting and preventing attacks before they occur using AI-powered threat hunting systems. Company executives describe this approach not only as a technical defense but also as a matter of digital sovereignty; ensuring that data remains within Türkiye's borders and is processed using domestic software stands out as

News | Cogent Announces Mythos-Class Frontier AI for <b>Cybersecurity</b> | Pipeline Publishing

| Cogent Announces Mythos-Class Frontier AI for Cybersecurity Cogent Unveils VR-1, the First Mythos-Class Frontier AI Model Trained Specifically to Excel at Cybersecurity TasksIn benchmark testing, VR-1 proved twice as many enterprise attack paths as leading frontier models, at roughly a quarter of the cost. Cogent Security introduced Cogent VR-1, a frontier reasoning model built for cybersecurity and trained to operate inside live enterprise environments. On IntrusionBench, a new benchmark for real-world enterprise attack chains released alongside the model, VR-1 began with a single foothold and autonomously proved viable paths to its objectives, achieving 2x the performance of other frontier models, proving twice as many enterprise attack paths as leading frontier models, at roughly a quarter of the cost. Most frontier models can find a single bug in a single codebase. Real attacks rarely stay that contained. They travel through a chain of small, individually unremarkable weaknesses. A public service exposes a minor flaw. An identity carries more permission than it needs. Somewhere in the build pipeline, an artifact gets trusted without ever being checked. On their own, each looks like ordinary backlog noise. Strung together, they become a path to a crown jewel. Cogent trained VR-1 to work the way a skilled adversary does. Given a foothold inside an enterprise, it maps the surrounding environment and connects weaknesses that span different systems to prove which paths are actually reachable. It then checks whether a proposed fix closes the gap or simply relocates the risk. Reasoning that once took an expert security researcher weeks runs in hours. The release lands as autonomous AI attacks stop being theoretical. In recent months, fully autonomous AI attacks have targeted some of the world's largest governments and technology companies. Defenders need matched AI capabilities at this level to understand where AI-driven attacks could succeed

Workforce Security Is No Longer About Protection. It's About Visibility.

Workforce Security Is No Longer About Protection. It’s About Visibility. - July 30, 2026 - 6 min read The lines of the contemporary workforce are blurred. Employees travel from office locations, homes, and customer sites and operate across cloud environments. They also access applications and data from multiple devices throughout the day. At the same time, businesses are adopting new collaboration tools, cloud platforms and digital workflows to drive productivity and growth. This has led to a workforce environment that is better connected than ever before, but also much more complicated to secure. “The problem for security leaders is not a lack of information. Most organisations already have a lot of data across endpoints, identities, applications, email systems and access environments. The challenge is making sense of that information. Signals are available across many platforms and tools, but often disconnected from each other, making it difficult to identify emerging risks, understand their consequences and respond with confidence. Modern threats are increasingly operating in trusted environments. Traditional security models were based on the assumption that malicious activity is suspicious-looking. Unusual logins, unknown devices and unauthorised applications were often clear indicators of risk. That assumption is no longer true. Many of today’s threats live within trusted environments. Today, attackers are increasingly turning to legitimate credentials, compromised identities, approved applications and behaviours that look normal on the surface. A user account can be used to access sensitive data from a trusted device. A legitimate application may be the vehicle for exfiltrated information. What seems to be a simple task can actually be the first step in a more extensive compromise. As trust boundaries continue to shift, organisations need to look beyond individual events to understand the relationships among users, devices, identities, and applications to identify risk. So security is moving towards context rather

<b>IoT</b> Integration Market Trends Point to USD 64.58 Billion Value with 25.80% CAGR by 2035

IoT Integration Market Trends Point to USD 64.58 Billion Value with 25.80% CAGR by 2035 IoT Integration Market connects devices, applications, and data platforms to improve automation, analytics, and operational efficiency. IoT integration transforms connected devices into intelligent ecosystems, enabling seamless communication, real-time insights, and smarter business decisions.” ONTARIO, ONTARIO, CANADA, July 30, 2026 /EINPresswire.com/ -- Connecting a sensor to the internet has never been the hard part. Making that sensor talk reliably to a dozen other systems legacy SCADA controllers, cloud analytics platforms, mobile apps, and everything in between is where most IoT projects stall. IoT integration has emerged as the specialised discipline that bridges this gap, weaving device management, network orchestration, and application-layer analytics into a single, coherent control plane rather than a patchwork of point-to-point connections that break whenever a new device type is added.— Market Research Future The global IoT Integration Market reached USD 6.50 Billion in 2025 and is forecast to grow from USD 8.18 Billion in 2026 to USD 64.58 Billion by 2035, registering a 25.80% CAGR across the forecast window. Accelerating 5G rollouts and enterprise digital-transformation mandates, the U.S. CHIPS and Science Act alone earmarked over USD 52 billion for semiconductor and connected-infrastructure programs, channelling investment toward integration specialists capable of bridging multi-vendor IoT ecosystems. Governments in the EU, India, and South Korea have concurrently launched smart-city and Industry 4.0 frameworks that explicitly require certified integration partners to manage cross-platform deployments. Legacy point-to-point interfaces are making way for cloud-native orchestration layers and edge-computing fabrics that bring sensors, gateways, and analytics pipelines together into a single control plane. The World Economic Forum projects that by 2027, the number of IoT devices globally will exceed 30 billion, a scale that will overwhelm ad hoc integration methods and push organisations decisively toward managed integration services rather

Cyber Resilience Act, Part 2: Security by Design becomes mandatory

Cyber Resilience Act, Part 2: Security by Design becomes mandatory Cyber Resilience Act: Security must be built into architecture, hardware, and software from day one – especially for embedded and IoT development. In a three-part article series, eeNews examines various aspects of the CRA and, in particular, how companies should now proceed. eeNews, together with Lemberg Solutions, is also organizing the free webinar “Building CRA-ready IoT products: the practical side of compliance” on 10 September, 2026. This webinar will show what a CRA-compliant SDLC looks like in practice. Registration for the webinar is now open. As outlined in the first installment of the article series, the EU’s Cyber Resilience Act (CRA), or Regulation (EU) 2024/2847, will make cybersecurity a mandatory CE requirement for connected products starting in 2027. This part focuses on why “Security by Design” and “Secure by Default” will become mandatory, and what this specifically means for embedded and IoT developers. For a long time, cybersecurity in many embedded and IoT products was considered only late in the development process – or added as an afterthought. The CRA puts an end to this practice. Security by Design and Secure by Default are becoming key requirements for products with digital elements. Anyone wishing to bring CE-compliant products to the European market in the future must embed security into requirements, architecture, and design decisions from the outset. Shift Left: Security begins with architecture The CRA establishes cybersecurity as a verifiable product attribute. Consequently, it will stand on equal footing with established requirements such as functional safety, electrical safety, and EMC (electromagnetic compatibility). For developers, this means that security decisions must not only be technically implemented but also documented and maintained throughout the product’s entire lifecycle. A key principle of the CRA is the so-called “shift-left” approach. Security requirements should not

Mindflair investee Mirror Security joins Google's Gemini <b>cybersecurity</b> startup forum

Claim 55% Off TipRanks - Unlock powerful investing tools with TipRanks Premium to make smarter, more confident investment decisions - Subscribe to TipRanks Smart Investor Newsletter, and discover new investing opportunities with data-backed stock picks An announcement from Pires Investments ( (GB:MFAI) ) is now available. Mindflair plc, the AIM-quoted specialist investor in AI-focused technology businesses, has built a portfolio of over 30 companies spanning IoT, cybersecurity, machine learning, immersive technologies and big data. Among its holdings is Mirror Security, an enterprise cybersecurity firm developing secure, privacy-preserving AI platforms designed to safeguard sensitive data in large organisations. The company announced that Mirror Security has been selected as one of 33 startups for Googleâs Gemini Startup Forum: Cybersecurity, a flagship programme supporting next-generation AI-enabled security technologies. Participation will give Mirror Security access to experts from Google Cloud, Google DeepMind and Wiz, as well as technical support and ecosystem opportunities, a move Mindflair views as a strong endorsement likely to accelerate the investeeâs development and enhance the broader AI portfolioâs positioning in the cybersecurity market. Mirror Security is expected to leverage the programmeâs resources and in-person forum at Googleâs London offices to refine its enterprise-focused, privacy-preserving AI solutions. For Mindflairâs stakeholders, the selection underscores the quality of its investments and reinforces its strategy of backing high-growth AI companies that can benefit from strategic partnerships with major technology platforms. Sparkâs Take on MFAI Stock According to Spark, TipRanksâ AI Analyst, MFAI is a Neutral. The score is constrained primarily by weak financial performanceâpersistent negative operating/free cash flow and highly inconsistent earnings with a recent return to losses on a very small revenue base. Technicals are also bearish with the price below key moving averages and negative MACD, despite oversold signals. Valuation offers little support given the negative P/E and no dividend yield data.

Rebuilt in Six Days: Dysphoria <b>IoT</b> Botnet Hides on Blockchain to Defy Seizure

When U.S., Canadian, and German authorities seized the command infrastructure of four major IoT botnets on March 19, 2026, they dealt what looked like a decisive blow against some of the most destructive distributed denial-of-service networks ever documented — the DOJ disrupted four IoT botnets named Aisuru, KimWolf, JackSkid, and Mossad in a coordinated international operation. Six days later, on March 25, researchers at Chinese cybersecurity firm QiAnXin XLab detected the first samples of a new botnet — one built specifically to make sure the same playbook would never work again. The new botnet, named Dysphoria, had infected an estimated 200,000 devices worldwide by the time XLab and China's national computer emergency response team CNCERT published their joint technical analysis on July 27, 2026. Its defining innovation: instead of registering conventional internet domains that a court order can seize and redirect, Dysphoria stores its command infrastructure inside Ethereum and Solana blockchain name records — decentralized systems with no registrar to serve notice on and no single server to take offline. That structural choice is not a feature borrowed from older botnets. It is a direct engineering response to watching four predecessor networks die on March 19. The 200,000-device figure comes from XLab's own telemetry and from leaked screenshots of the Dysphoria operator control panel circulating on social media, which showed a consistent count near that number. As The Hacker News noted in its coverage, XLab published no counting or de-duplication methodology alongside its estimates, and no independent party has reproduced the figures. They should be read as informed estimates, not a precise device census. Read more: KimWolf Botnet Operator Arrested: 1 Million Hijacked Home Devices Powered Record DDoS Service Largest IoT Botnet Crackdown in History Directly Produced Its Own Successor The March 2026 operation was genuinely unprecedented in scale. The

Tengu botnet reboots Linux devices to survive removal

Tengu botnet reboots Linux devices to survive removal A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning system the company uses to identify malware families that do not match known signatures. Researchers first observed the dropper reaching their honeypots through Telnet credential brute-force attacks. Tengu isn’t just another Mirai variant Nozomi’s analysis found a range of capabilities built into the malware, including an encrypted channel for issuing commands, the ability to relay an operator’s traffic through the infected device, delivery of new payloads, collection of system and network details, and a wide set of denial-of-service functions covering several protocols. “It also includes multiple persistence and self-defense mechanisms designed to keep the malware running on compromised Linux-based devices and make recovery more difficult,” the researchers wrote. Tengu retains several Mirai characteristics, including plaintext registration messages and reused denial-of-service code. It also adds a SOCKS5 proxy, shell command execution, system and network reconnaissance, and the ability to download ELF binaries or Android APKs through an IPFS gateway hosted on the same command-and-control (C2) server. Researchers believe the APK support targets poorly secured Android TV boxes and similar Android-based devices. The malware also includes 25 DDoS methods. Built to survive removal Besides persistence through systemd and init.d, two Linux systems that automatically launch services when a device starts up, Tengu tries to use cron, the tool for scheduling recurring tasks, though Nozomi found this method doesn’t work as intended. The malware creates a hidden guardian process that checks every 60 seconds whether the main malware process is still running and restarts it if necessary. Tengu also abuses the Linux hardware

Top Android App Development Companies in UK (2026)

The Android ecosystem continues to dominate the global smartphone market, making Android app development a strategic investment for startups, SMEs, and enterprises across the UK. Whether you're building a customer-facing mobile application, an enterprise solution, or an AI-powered digital platform, choosing the right Android app development company can significantly impact your project's success. From technical expertise and UI/UX design to post-launch support and scalability, the right development partner ensures your app meets business objectives while delivering an exceptional user experience. In this guide, we've curated a list of the top Android app development companies in the UK based on their expertise, industry reputation, service quality, innovation, and client satisfaction. Top Android App Development Companies in UK 1. Techanic Infotech UK Rating: ⭐ 4.9/5 Overview Techanic Infotech UK has established itself as one of the leading Android app development companies by delivering high-performance, scalable, and feature-rich Android applications for startups, SMEs, and enterprises. The company specializes in custom Android app development, AI-powered mobile solutions, enterprise mobility, eCommerce applications, fintech apps, healthcare solutions, and on-demand platforms. Their experienced developers leverage the latest Android technologies, including Kotlin, Java, Jetpack Compose, Firebase, and AI integrations, ensuring modern and future-ready applications. Why This Rating? Techanic Infotech consistently delivers innovative Android applications with outstanding UI/UX, transparent communication, agile development methodologies, and excellent post-launch support, making them one of the highest-rated development partners. Ideal For Businesses seeking end-to-end Android app development with modern technologies and long-term scalability. - Custom Android application development - Enterprise mobility solutions - AI-powered Android applications - Ongoing maintenance and support 2. Crinpro Solutions Rating: ⭐ 4.8/5 Overview Crinpro Solutions is recognized for building scalable Android applications that help businesses accelerate digital transformation. Their expertise spans healthcare, education, logistics, fintech, travel, and retail industries. The company focuses on developing intuitive mobile experiences backed

Nozomi Networks Appoints Co-Founder Andrea Carcano As CEO Following $1 Billion ...

Nozomi Networks has appointed co-founder Andrea Carcano as Chief Executive Officer as the cybersecurity company enters its next phase of growth following its $1 billion acquisition by Mitsubishi Electric. Carcano returns to the CEO role he held when he founded Nozomi Networks with Chief Technology Officer Moreno Carullo approximately 14 years ago. He succeeds Edgard Capdevielle, who led the company for the past decade and will remain involved as an executive advisor. The leadership transition is intended to accelerate Nozomi Networks’ technical development and the use of artificial intelligence across operational technology, the Internet of Things, and cyber-physical systems security. Operational technology, commonly known as OT, includes the systems that control physical equipment and industrial processes. These systems are used across energy, utilities, manufacturing, pharmaceuticals, transportation and other critical infrastructure sectors. Cyber-physical systems combine software and networking with physical machinery or infrastructure. Protecting these environments can be especially difficult because a cyberattack may affect not only data but also production, equipment availability, public services or physical safety. Carcano and Carullo founded Nozomi Networks on the belief that industrial operators needed more robust cybersecurity technology. The founders wrote the company’s initial software, secured its first customers and developed the technical foundation of its security platform. Approximately a decade ago, they recruited Capdevielle to commercialize the technology, build a global go-to-market organization and raise the capital required for the company to compete internationally. During Capdevielle’s tenure, Nozomi Networks surpassed $100 million in annual revenue and became the first privately held OT cybersecurity company to achieve sustained cash-flow break-even performance, according to the company. Nozomi Networks also expanded its customer base across major critical infrastructure industries. The company said its customers include five of the world’s 10 largest oil and gas companies, seven of the 10 largest pharmaceutical manufacturers and seven of the

No More Defaults: The DBIR's Warning to the <b>IoT</b> Industry

No More Defaults: The DBIR’s Warning to the IoT Industry Michael GreeneMichael Greene Verizon’s annual Data Breach Investigations Report (DBIR) is a bellwether of the latest cybersecurity threats. In line with the adage that “the only constant is change,” the 2026 edition documents numerous trends and vulnerabilities with IoT security implications. Most critically, it underscores that threat actors are increasingly abusing internet-facing systems and weakly governed environments, the exact risk profile that many IoT deployments unintentionally create. The DBIR found that software vulnerabilities are now the top initial access path in breaches. Attackers are shifting from social engineering campaigns that trick people into granting system access to exploiting existing exposures. If connected devices are reachable from the public internet, they can easily become the first foothold attackers use to move into more sensitive systems. This makes securing edge devices, sensors, and other IoT gateways crucial. Companies should immediately audit all connected devices, identify which are internet-facing, disable unused services, and remove public access where possible. In scenarios where devices require connection, enforcing strong authentication and restricting administrative access can help tighten security. Patch lag has long been an IoT security headache, and the DBIR reinforces that the pain isn’t going anywhere. Remediation still lags behind exploitation, with the median time to fully address known vulnerabilities rising to 43 days. This is almost two weeks more than 2025’s average resolution time! This upward trajectory is especially concerning for the IoT sector, where firmware updates, device uptime requirements, and vendor maintenance processes often slow patching. While it’s impossible to circumvent all of these issues, a risk-based patching program can address the most pressing. These initiatives prioritize externally exploitable vulnerabilities, actively used flaws, and the devices closest to critical operations. Third-party involvement is a growing risk factor for breaches. Device manufacturers, integrators, MSPs,

Nozomi Networks Names Co-Founder Andrea Carcano CEO Following Mitsubishi Electric ...

Nozomi Networks has appointed co-founder Andrea Carcano as chief executive officer, returning him to the role he held when the industrial cybersecurity company was founded and marking a leadership transition focused on accelerating AI-driven innovation following its acquisition by Mitsubishi Electric. Carcano succeeds Edgard Capdevielle, who led the company for the past decade and will remain with Nozomi as an executive advisor. The transition comes after a period of significant growth that included surpassing $100 million in annual revenue and completing Nozomi’s approximately $1 billion acquisition by Mitsubishi Electric. The leadership change signals a shift from scaling the business commercially to advancing the company’s technology strategy as artificial intelligence becomes increasingly central to operational technology (OT), Internet of Things (IoT), and cyber-physical systems security. “Edgard has been an extraordinary partner to Moreno and me for the past decade,” Carcano said. “Stepping into this role feels like returning to where our story began, only now with the conviction of everything we’ve proven since: category-defining products, the trust of the world’s most critical operators, and market leadership recognized across the industry.” Carcano co-founded Nozomi Networks 14 years ago with Moreno Carullo, the company’s chief technology officer. The pair developed the company’s initial platform before recruiting Capdevielle approximately a decade ago to build its commercial organization, expand globally, and secure the capital needed to compete in the rapidly growing industrial cybersecurity market. Under Capdevielle’s leadership, Nozomi grew into one of the industry’s largest independent OT cybersecurity providers. The company surpassed $100 million in annual recurring revenue while achieving sustained cash-flow break-even performance and expanded its customer base to include many of the world’s largest industrial operators. According to the company, its platform is used by five of the world’s 10 largest oil and gas companies, seven of the top 10 pharmaceutical manufacturers, and

CRA-Ready <b>IoT</b> Products: A Practical Webinar

CRA-Ready IoT Products: A Practical Webinar on CRA-ready IoT products will require security to be treated as part of product engineering rather than a final compliance exercise. With the first Cyber Resilience Act deadlines arriving in September 2026, connected-device teams need development processes that can produce security evidence, track vulnerabilities, and support products after release. On Thursday, September 10, 2026, Elektor and Lemberg Solutions will present a free webinar explaining how that work can be built into an existing software development lifecycle. What CRA-Ready IoT Products Require The webinar, Building CRA-Ready IoT Products: The Practical Side of Compliance, begins at 16:00 CEST (14:00 UTC / 10:00 EDT). Speaker Nazar Kohut, Program Manager at Lemberg Solutions, will examine how the EU Cyber Resilience Act changes the way embedded and IoT products are planned, developed, released, and maintained. The European Commission says the CRA introduces mandatory cybersecurity requirements covering product planning, design, development, and maintenance. Reporting obligations apply from September 11, 2026, while the main requirements apply from December 11, 2027. That makes the timing rather less comfortable than a quick glance at “2027” might suggest. From Regulation to Engineering Workflow The session will focus on what a CRA-compliant secure SDLC looks like in practice. Topics include risk assessment, threat modeling, development phases and gates, required documentation, release preparation, vulnerability handling, and post-release activities. The aim is to show where compliance work belongs in the development process, rather than treating it as a separate pile of paperwork assembled after the product is finished. This matters particularly for small and midsize embedded teams. A connected product may combine firmware, an operating system, third-party libraries, cloud services, mobile applications, and update infrastructure. CRA readiness therefore depends on knowing what is inside the product, who is responsible for each part, how security decisions are recorded,

SonicWall Report Highlights Rising Manufacturing <b>Cybersecurity</b>

Bangalore July 28, 2026 — SonicWall today released its 2026 Manufacturing Protect Brief, a vertical specific companion to the SonicWall 2026 Cyber Protect Report. The findings show that factories are increasingly opening up critical new entry points for hackers. Consequently, while the total volume of cyberattacks on the manufacturing sector has actually decreased, hackers are executing much more precise, highly targeted strikes on these digital gaps. Manufacturing recorded a 56.2% year-over-year decline in intrusion prevention (IPS) volume in the first half of 2026, the steepest drop of any tracked vertical. But the decline does not reflect reduced risk. Absolute volume remains significant at 474 million events, and as more operational technology connects to IT infrastructure, the attack surface is expanding even as attackers grow more selective about where they strike. “Manufacturing’s attack surface looks nothing like it did even five years ago, and the security model hasn’t caught up,” said Michael Crean, SonicWall SVP of Managed Services. “Every connection added for operational convenience, remote monitoring, predictive maintenance, vendor access to production systems, is also a connection an attacker can walk through. A stolen credential shouldn’t be able to reach the production floor, but in most manufacturing environments today, it can.” SonicWall’s Manufacturing Protect Brief draws on data from SonicWall’s global network of more than one million security sensors to document the specific attack patterns, legacy vulnerabilities and ransomware campaigns defining the manufacturing threat landscape in the first half of 2026. Key Findings from the 2026 SonicWall Manufacturing Protect Brief - The Hikvision IP Camera Command Injection vulnerability (CVE-2021-36260), disclosed in 2021, continued to generate 43 million hits in H1 2026, the single largest IoT attack signature across any industry SonicWall tracks. - IoT attacks were manufacturing’s second-largest attack category by volume, generating 46.2 million hits, with more than half of

Intel and Fortinet collaborate to advance <b>cybersecurity</b> innovation and strengthen global ...

Intel Corporation and Fortinet has announced a strategic collaboration to develop Fortinet Security Processor 6 (SP6). Expanding a long-standing relationship between the two companies, this collaboration combines Fortinet’s proprietary, purpose-built security processor expertise with Intel’s advanced design, packaging, and manufacturing capabilities to accelerate and strengthen SP6 development. This work will also help to improve the resilience and diversity of Fortinet’s global supply chain. Commenting on the collaboration, chief executive officer (CEO), Intel, said, “As organisations face a rapidly evolving threat landscape, security infrastructure must deliver both performance and innovation at scale. This collaboration demonstrates how Intel’s semiconductor leadership and advanced design, packaging, and manufacturing capabilities can help cybersecurity leaders like Fortinet accelerate the development of critical security technologies while building a more resilient and diversified global supply chain.” Meanwhile, founder, chairman, and CEO, Fortinet, said, “Fortinet’s purpose-built ASICs have been a key differentiator for more than two decades, enabling us to deliver the security effectiveness, performance, and efficiency our customers demand. This expanded relationship with Intel will leverage its unique combination of advanced semiconductor technology, manufacturing expertise, and global supply chain capabilities, helping Fortinet accelerate and strengthen our ASIC strategy, while also better supporting organisations all over the world.” In addition to bringing together Fortinet’s leadership in purpose-built security processors with Intel’s broad portfolio of ecosystem IP, proven expertise in disaggregated semiconductor design, and advanced packaging solutions tailored for both AI-enabled and cost-sensitive applications, this collaboration aims to deliver a highly integrated security processor capable of supporting increasingly sophisticated security services and the demanding performance requirements of today’s organisations. The companies will explore additional opportunities to further deepen collaboration across semiconductor technology, manufacturing, and the infrastructure underpinning future cybersecurity innovation. This work is expected to advance Fortinet’s long-term ASIC roadmap, support greater performance and service richness, and strengthen supply chain

Regulations to Secure the Connected World

CRA, RED, and CS&RRegulations to Secure the Connected World By Francesco Vaiani* | Translated by AI 6 min Reading Time Regulations such as the EU's Cyber Resilience Act and Radio Equipment Directive or the proposed Cyber Security and Resilience Bill in the UK tighten the requirements for connected products. Security by Design, SBOMs, secure updates, and consistent lifecycle management are more important than ever before. With the increasing number of Internet of Things (IoT) and edge devices, potential security vulnerabilities in distributed networks of electronic systems are rising dramatically. To protect their connected devices, companies require effective cybersecurity measures to ensure uninterrupted operations, secure data, and protect application users worldwide. However, as threats constantly evolve, global regulations are also advancing to enforce stricter security standards. Pioneers of this change are the Cyber Resilience Act (CRA) and the Radio Equipment Directive (RED) of the European Union (EU). These standards establish comprehensive minimum cybersecurity requirements that shape global practices in the development of digital and wireless products. Many companies face significant challenges as they must adapt their business strategies to comply with the new regulations. These will apply to most connected devices sold in the EU. Similar guidelines have been proposed or already enacted in other regions; an example is the "Cyber Security and Resilience (CS&R) Bill" proposed in the United Kingdom. Cybersecurity involves protecting devices, networks, firmware, and data from external threats. The primary goal of implementing cybersecurity in IoT applications is to prevent disruptions that could jeopardize operations, safety, or regulatory compliance. However, flaws in devices, outdated firmware, or insecure communication protocols can provide attackers with easy access, allowing them to build botnets, steal data, or gain unauthorized control. The Mirai botnet, for example, brought hundreds of thousands of unprotected IoT devices under its control and overwhelmed targets with large-scale