Cyber Attack Methods Training at ICS Cybersecurity Conference
The Cyber Attack Methods course returns to the ICS Cybersecurity Conference, offering hands-on training for defenders to understand how attackers compromise cyber-physical systems.
137 articles
The Cyber Attack Methods course returns to the ICS Cybersecurity Conference, offering hands-on training for defenders to understand how attackers compromise cyber-physical systems.
The Supreme Court dismissed one of two lawsuits blocking the Trump administration's changes to USPS regulations regarding mail-in ballots, citing lack of standing due to speculative harm.
CISOs are hired for technical expertise but judged on business growth and customer trust, creating a double standard that affects their tenure and performance evaluation.
A new report calls for the federal government to declare key AI models and companies as critical infrastructure, citing growing importance to US economic and national security.
Nico Waisman's cybersecurity journey began as a self-taught hacker in Argentina and evolved into a career in offensive security, leadership, and AI-driven security expertise.
A market for removing AI watermarks has emerged, but most tools cannot prove their effectiveness, as Anthropic has not released its detector to verify the removal of the watermark.
The National Security Agency has appointed Kerianne Tobitsch, a senior lawyer at the Homeland Security Department, as its new general counsel, filling a role that has been vacant for roughly a year.
46% of organizations say AI governance and compliance issues are the reason why their AI underperforms, according to the GrantThornton 2026 AI Impact Survey Report.
Marcus Hutchins, a young cyber threat analyst, found a kill switch for the WannaCry ransomware, saving the world from a devastating cyberattack, but his past as a malware developer caught up with him.
The Federal Trade Commission proposes to regulate ideological bias in AI systems, sparking criticism from opponents across the political spectrum.
Multiple cybersecurity companies made significant announcements at Black Hat USA 2026, including 1Password, Cogent, and Vectra AI, showcasing new products and services to enhance security posture.
A weekly roundup of cybersecurity news, including AI-generated false positives, data breaches, and hacking attacks on major companies.
Multiple cybersecurity companies announce new products and services at Black Hat USA 2026, including AI-powered security solutions and threat intelligence platforms.
AI chatbots are becoming a primary source of election information, but experts warn they are not reliable enough to be a main source of accurate or complete information.
Russ Kirby, CISO at Ping Identity, discusses the importance of passion and leadership in cybersecurity, and how it helps prevent burnout and drives success in the field.
CASB and DLP have limitations in securing AI tools, requiring an interaction-aware layer to inspect prompts and responses for sensitive data leakage.
Multiple cybersecurity companies made significant announcements at Black Hat USA 2026, including new products and updates to existing offerings.
Balance Theory has raised $19 million to expand its platform for helping CISOs evaluate and manage security spending, currently managing over $1 billion in cybersecurity investments.
U.S. Cyber Command plans to open an office in Silicon Valley to drive innovation and build relationships with the tech sector, with the goal of accelerating cyber weapons and online tactics.
A top White House official highlights the difficulties of overcoming supply chain obstacles in the quantum race, citing diffuse and intertwined supply chains.
A recent breach at Hugging Face highlights the need for federal rules governing autonomous AI agents, which can adapt and evolve in unpredictable ways.
AI agents are designed to improvise, but when paired with broad access, every wrong turn becomes a security risk, so securing them requires a different approach.
The Trump administration has asked the Supreme Court to allow enforcement of an executive order restricting mail-in voting ahead of the November midterm elections.
The Senate confirmed Jay Clayton as the next director of national intelligence with a 51-47 vote, capping a turbulent process delayed by President Donald Trump's initial cancellation of his confirmation hearing.
Tal Kollander's journey from a black hat hacker to a cybersecurity defender is a fascinating story of transformation, driven by her curiosity and passion for computer security.
Nvidia and tech giants launch Open Secure AI Alliance to develop and share open source tools for securing AI systems and agents.
Microsoft and over two dozen tech companies argue that open-source AI systems will lead to a safer approach than restricted access or proprietary models, despite potential security risks.
Seven out of 10 federal cyber regulations require duplicative written reports to federal agencies, according to a Government Accountability Office report.
Cisco launches low-cost AI models for source code security, targeting budget-restrained organizations with Antares, a small language model designed to find known vulnerabilities in codebases.
The Trump administration has reversed its stance on AI regulation, imposing export controls on certain models, amid concerns over national security implications.
The World Cup's cybersecurity story is one of successful resilience, with no major public cyber disruptions reported, despite warnings from the FBI's Internet Crime Complaint Center about fraudulent websites.
Andreas Gaetje, CISO at Korber AG, shares his career path and insights on cybersecurity leadership, highlighting the importance of business understanding and adaptability in the face of rapid technological change.
Only eight cyber personnel participated in the Federal Rotational Cyber Workforce program, which aimed to bolster the federal workforce by rotating workers between agencies.
Ukrainians protest the dismissal of Defense Minister Mykhailo Fedorov, who pushed for military modernization through drone technology and digital innovation.
State officials and election experts have rejected President Trump's claims of voter fraud, calling them 'desperation' with no credible evidence.
AI agents have broken the traditional security playbook, requiring a new approach that assumes environments are dynamic and unpredictable, with security teams needing to own the operational layer.
New research shows that a
37 cybersecurity-related merger and acquisition deals were announced in June 2026, including 1Password's acquisition of Apono and Accenture's acquisition of Dragos, runZero, and NetRise.
Jesse McGraw, aka GhostExodus, was a blackhat hacker who spent 11 years in prison, but now uses his skills for good, helping victims of online predators.
A weekly roundup of key cybersecurity stories, including a DHS database hack, Adobe's boosted patch cadence, and Canada's disruption of ransomware operations. AssuranceAmerica suffered a data breach affecting 7 million people.
The European Commission has unveiled a cyber plan to reduce reliance on foreign AI systems, aiming to make frontier AI safe and accessible for European cybersecurity.
Flipper Devices will continue developing the Flipper Zero firmware with community contributions, after announcing the end of full-time feature development.
Vibe Coding, powered by generative AI, enables software creation at the speed of thought, but security lags behind, introducing new risks and challenges.
Risk assessment data must link to information about operational disruptions to become actionable, and a connected risk lifecycle is necessary to understand business impact and interpret threats.
The relaunched Claude Fable model is available to all users, but its performance has been degraded, with users reporting it feels weaker and is being routed through stricter safety systems more often.
The US has lifted export control restrictions on Anthropic's Fable 5 and Mythos 5 AI models after the company agreed to implement new safety guardrails and classifiers.
OpenAI and Anthropic are restricting new AI model releases due to cybersecurity concerns from the Trump administration.
The AI AGENT Act would create a list of secure and trustworthy AI agent software providers, allowing users to choose compliant providers for online platforms.
Anthropic is testing Claude Cowork support on mobile, allowing users to manage long-running tasks from their phone.
Philip Martin joins Uber as Chief Information Security Officer, bringing experience from Coinbase, Palantir, and Amazon to protect the company's users and operations.
Nebulock has raised $25 million in Series A funding to expand its AI-native contextual security platform, bringing total funding to over $33 million.
Agentic GRC agents are changing the way compliance operates by providing autonomy, context, and execution of multiple steps, allowing for continuous assessment and monitoring.
Homeland Security Secretary Markwayne Mullin says CISA needs 600 new hires, a process that can't start until a new director is confirmed.
A federal judge struck down major sections of a Trump administration executive order restricting mail-in ballots and voter lists, finding it unconstitutional.
Effective fraud prevention programs require monitoring across every customer touchpoint to identify advanced fraud methods and emerging trends.
Carl Froggett combines CISO and CIO roles at Deep Instinct, highlighting the overlap between technology and security.
French President Emmanuel Macron has urged the US to share cutting-edge AI with other democracies, warning of a potential drop in value for US firms if they restrict access.
The fundamental design of TCP/IP networks poses significant security challenges, with 68% of initial access attacks not relying on technical vulnerability exploitation.
Accenture is acquiring a majority stake in Dragos and fully acquiring runZero and NetRise in a $4.1 billion OT cybersecurity push.
A new policy paper advocates for software bills of materials for artificial intelligence to reduce cyber risk and improve transparency.
The Trump administration's decision to impose export controls on Anthropic's AI models has been met with skepticism by lawmakers, who question the national security concerns cited as the reason.
Artificial intelligence is being used across the security landscape, with both benefits and risks, and its misuse by insiders and exploitation by cyber adversaries is a growing concern.
Isira Adithya, a Sri Lankan-born hacker, discusses his journey from a childhood prodigy to a successful ethical hacker, driven by curiosity and a desire to push boundaries.
Anthropic's Claude Fable 5 AI model has been released with robust safeguards, but industry professionals express concerns over its potential misuse in cybersecurity and the creation of a 'security poverty line'.
Google Cloud lays off members of its cybersecurity division, while Coupang faces a $400 million fine for a data leak affecting over 30 million customers.
Anthropic has rolled out Claude Fable 5, a new AI model with strict safeguards, available for a limited time to Pro, Max, and Enterprise customers.
Security teams can efficiently incorporate AI applications into their workflow by following 12 practices, including visibility, risk understanding, and trust building.
The future of AI will be shaped by trust around innovation, requiring a new model of collaboration between industry and policymakers that maintains speed and adaptability while establishing accountability for real-world outcomes.
Armenian Prime Minister Nikol Pashinyan's pro-European party won nearly 50% of the vote, defeating the pro-Russian party despite a large-scale Russia-linked disinformation campaign.
Anthropic proposes a coordinated pause in AI development to mitigate risks, warning that humans may lose control as technology advances rapidly.
Wazuh Cloud reduces security operations complexity with automation, AI-driven analysis, and seamless scalability, empowering teams to focus on protecting critical assets.
The European Commission proposes laws and strategies to reduce reliance on foreign technology, focusing on semiconductors, cloud computing, and open-source software.
Department of Homeland Security Secretary Markwayne Mullin says CISA ideally needs 2,800 personnel to effectively carry out its cybersecurity mission.
The Trump administration is considering Shyam Sankar, a Palantir executive, to lead the Cybersecurity and Infrastructure Security Agency (CISA).
Brave Software has released Brave Origin, a paid, minimalist version of its browser that removes cryptocurrency and monetization features for a more streamlined experience.
The Pentagon is integrating cyber into all operations and prioritizing security in artificial intelligence usage to counter emerging threats.
The White House has released a pared-back AI executive order, establishing a voluntary review period for government testing of AI models within 30 days of release to the public.
Two new reports offer competing explanations for the growing cybersecurity crisis, with one suggesting a failure of tools and the other citing poor management of existing tools.
President Donald Trump signed an executive order to vet national security risks of advanced AI systems before public release, with voluntary participation from AI developers.
The Trump administration issued a revised executive order on artificial intelligence, significantly weakening provisions that had been opposed by industry.
The US Postal Service is moving forward with mail-in ballot restrictions, following a court's rejection of a request to block an executive order from President Donald Trump.
The National Security Agency has selected new leads for its cybersecurity directorate and Cybersecurity Collaboration Center, including David Imbordino and Bruce Jones.
OpenAI has announced plans to safeguard information and aid cybersecurity defenders in the 2026 midterm elections, including combating deepfakes and AI misuse.
Anthropic confirms plans to release Mythos-class models to the public in the coming weeks, after addressing initial security risks.
A Google security engineer has been accused of using confidential search trends to make over $1.2 million on the prediction marketplace Polymarket.
SIEM helps MSPs reduce noise and stop threats faster by providing a centralized view of activity across the entire environment and automatically correlating related events.
Geordie, an AI security and governance startup, has raised $30 million in a Series A funding round to enhance its platform and expand operations.
A House subcommittee will hold a hearing on June 4 to discuss the impact of frontier artificial intelligence models on cybersecurity threats.
The head of the UK's GCHQ spy agency warns that AI is an unstoppable force with both offensive and defensive ramifications for cyberspace, requiring a reimagining of cybersecurity.
Army Gen. Joshua Rudd has commissioned two studies to examine how U.S. Cyber Command can modernize, including a review by MITRE to scrutinize the command's acquisition model.
AppOmni's Marlin AI brings autonomous investigation to SaaS security, automatically detecting and analyzing potential security issues and recommending remedial actions.
Lawmakers from both parties agree that reductions to the Cybersecurity and Infrastructure Security Agency have gone too far, damaging its ability to defend against foreign adversaries.
Nearly 80% of organizations are confident in their cybersecurity readiness, yet reality shows a more complicated story, with many lacking the budget and resources to fully invest in AI-powered security solutions.
Chargebacks only capture a narrow slice of fraud losses, hiding bigger issues that affect revenue, customer experience, and long-term profitability.
President Donald Trump has postponed the release of an executive order focused on AI security, citing concerns it could harm US AI industry competition with countries like China.
Security teams must prepare for AI applications moving into production, leveraging data-driven discussions, agility, and future-proofing to secure them.
Cyber resilience is crucial for business continuity, as it helps organizations manage risk and ensure operations continue uninterrupted despite disruptions.
Security teams can manage shadow AI tools by building a full picture of what's running, writing a policy that works with employees, and creating a fast lane for new tool requests.
Sean Plankey, former nominee for director of the Cybersecurity and Infrastructure Security Agency, has been named US CEO of defense startup UFORCE.
Microsoft is testing a resizable taskbar and customizable Start menu in the latest Windows 11 Insider Preview Build 26300.8493.
The FTC will begin enforcing the Take It Down Act on May 19, requiring websites to remove nonconsensual deepfake media within 48 hours or face fines up to $53,088 per violation.
Advanced artificial intelligence models will fundamentally change warfare, according to a top Pentagon cyber official, representing a 'watershed moment' in the development of frontier AI models.
Anthropic's Claude Mythos Preview and OpenAI's GPT-5.5 have significantly surpassed benchmarks for autonomous cybersecurity tasks, with the AISI estimating a doubling time of approximately five months.
A group of international government agencies has released guidance on what an artificial intelligence 'ingredients list' tool should include to make AI more secure.
Hiring more analysts won't solve the SOC's alert problem due to the volume of alerts exceeding human investigation capacity.
The trial between Elon Musk and OpenAI's leaders has sparked concerns about the risks of artificial intelligence to humanity, with both sides accusing each other of trying to control the company's development of advanced AI technology.
The Cybersecurity and Infrastructure Security Agency has seen significant gains from AI automation in its security operations unit, enabling faster threat triage and response.
Data centers have become vital to modern society, making them high-value targets for cyber and physical attacks, with potential disruptions affecting not just businesses but also national security and entire economies.
The National Geospatial Intelligence Agency faces challenges in integrating AI tools, including job loss anxiety and ensuring safety while moving quickly.
The US military has reached deals with 7 tech companies, including Google and Microsoft, to use their AI in classified computer networks to augment warfighter decision-making.
Federal Chief Information Officer Greg Barbaccia is approaching Anthropic's Mythos model with caution, acknowledging its potential to strengthen federal cyber defenses despite uncertainties about its real-world performance.
Microsoft has introduced a new modern Run dialog in Windows 11, which is faster and supports dark mode, with a median time-to-show of 94ms.
Illinois Representative Delia Ramirez has been appointed as the top Democrat on the House Homeland Security Committee's Cybersecurity and Infrastructure Protection Subcommittee, replacing Eric Swalwell following his resignation from Congress.
Static audits and point-in-time dashboards can no longer keep pace with AI-accelerated threats. Security leaders must shift toward runtime visibility, identity governance, and outcome-based metrics.
NATO's Locked Shields 2026 wrapped up on Friday, bringing together more than 4,000 cybersecurity professionals from 41 countries to defend critical infrastructure against simulated live-fire cyberattacks.
As agentic AI systems capable of autonomous action take center stage at RSA Conference 2026, cybersecurity experts argue the most effective defense strategy is straightforward: if it can act, treat it like an identity.
The EU's Digital Operational Resilience Act, in force since January 17, 2025, makes credential security a binding regulatory obligation under Article 9 — and financial institutions that cannot prove compliance face direct supervisory consequences.
This week's cybersecurity highlights include unauthorized access to Anthropic's Claude Mythos, Sean Plankey withdrawing his CISA director nomination, and the UK NCSC unveiling a new hardware display-security device called SilentGlass.
Microsoft is restructuring the Windows Insider Program into just two channels — Experimental and Beta — while ending gradual feature rollouts in the Beta Channel to address long-standing tester frustrations.
Senior U.S. military leaders are confronting urgent questions about securing and controlling AI systems as the Pentagon accelerates adoption of autonomous weapons and machine-learning tools for battlefield decisions.
Microsoft is introducing several Windows Update improvements giving users greater control over update timing and reducing unexpected restart interruptions, now rolling out to Windows Insiders in Dev and Experimental channels.
Microsoft has made a new RemoveMicrosoftCopilotApp policy setting broadly available following the April 2026 Patch Tuesday, allowing IT administrators to silently remove the Copilot AI assistant from managed enterprise devices.
Israel-based Copperhelm has emerged from stealth mode after securing $7 million in seed funding for an AI-driven cloud security platform that deploys autonomous agents to investigate threats and execute remediation in real time.
Artifact management firm Cloudsmith has raised $72 million in a Series C round led by TCV, bringing its total funding to $124 million as it expands its secure software supply chain platform.
McLean, VA-based startup Rilian has closed $17.5 million in combined seed and seed extension funding to expand its agentic security orchestration platform, Caspian, targeting government, critical infrastructure, and law enforcement customers.
Sean Plankey formally asked President Trump to pull his nomination to lead CISA, citing Senate gridlock after more than a year without confirmation. The agency continues to operate under acting leadership amid deep budget cuts and ongoing personnel instability.
A House Oversight subcommittee roundtable on 'Artificial Intelligence and American Power' turned deeply anxious as lawmakers questioned AI's threat to national security, civil liberties, and humanity itself.
BleepingComputer and Kaseya are hosting a live webinar on May 14, 2026, examining how AI-powered phishing, ransomware, and business email compromise are outpacing MSP defenses and why backup and recovery must be part of every security strategy.
NAKIVO has released Backup & Replication v11.2, delivering automated real-time replication, full VMware vSphere 9 and Proxmox VE 9.0/9.1 support, OAuth 2.0 authentication, and expanded ransomware resilience for over 16,000 customers worldwide.
Flare analysts discovered an underground forum guide titled 'The Underground Guide to Legit CC Shops: Cutting Through the Bullshit,' revealing how threat actors systematically evaluate carding marketplaces, manage operational security, and build trust in a deceptive ecosystem.
Launched in early April 2026, CoChat is a new enterprise platform designed to expose and govern shadow AI usage, offering teams shared access to leading LLMs and agentic systems while enforcing human oversight over autonomous actions.
As Congress debates extending Section 702 of FISA, experts on both sides acknowledge deep uncertainty about whether the 2024 reform law improved or worsened controversial warrantless surveillance powers.
White House Chief of Staff Susie Wiles is set to meet Anthropic CEO Dario Amodei to discuss the company's new Mythos AI model, which has drawn federal attention for its national security and cybersecurity implications.
Modern cyberattacks have outpaced what governments can realistically defend alone. A shift toward deeper public-private collaboration is no longer optional — it's the only viable path forward.
National Cyber Director Sean Cairncross confirmed Wednesday that additional executive orders are expected as the Trump administration moves to implement its national cybersecurity strategy published last month.
CISA has notified CyberCorps: Scholarship for Service participants that summer 2025 internships are canceled due to a DHS funding lapse, leaving hundreds of cyber scholars in limbo for a second consecutive year.
Operational technology asset owners are being required to attest to post-quantum cryptographic readiness, but the frameworks, tools, and visibility needed to make those attestations meaningful simply don't exist in most OT environments.