Tech Giants Back Open-Source AI for Safer Ecosystem
Microsoft and over two dozen tech companies argue that open-source AI systems will lead to a safer approach than restricted access or proprietary models, despite potential security risks.
145 articles
Microsoft and over two dozen tech companies argue that open-source AI systems will lead to a safer approach than restricted access or proprietary models, despite potential security risks.
Seven out of 10 federal cyber regulations require duplicative written reports to federal agencies, according to a Government Accountability Office report.
Cisco launches low-cost AI models for source code security, targeting budget-restrained organizations with Antares, a small language model designed to find known vulnerabilities in codebases.
The Trump administration has reversed its stance on AI regulation, imposing export controls on certain models, amid concerns over national security implications.
The World Cup's cybersecurity story is one of successful resilience, with no major public cyber disruptions reported, despite warnings from the FBI's Internet Crime Complaint Center about fraudulent websites.
Andreas Gaetje, CISO at Korber AG, shares his career path and insights on cybersecurity leadership, highlighting the importance of business understanding and adaptability in the face of rapid technological change.
Only eight cyber personnel participated in the Federal Rotational Cyber Workforce program, which aimed to bolster the federal workforce by rotating workers between agencies.
Ukrainians protest the dismissal of Defense Minister Mykhailo Fedorov, who pushed for military modernization through drone technology and digital innovation.
State officials and election experts have rejected President Trump's claims of voter fraud, calling them 'desperation' with no credible evidence.
AI agents have broken the traditional security playbook, requiring a new approach that assumes environments are dynamic and unpredictable, with security teams needing to own the operational layer.
New research shows that a
37 cybersecurity-related merger and acquisition deals were announced in June 2026, including 1Password's acquisition of Apono and Accenture's acquisition of Dragos, runZero, and NetRise.
Jesse McGraw, aka GhostExodus, was a blackhat hacker who spent 11 years in prison, but now uses his skills for good, helping victims of online predators.
A weekly roundup of key cybersecurity stories, including a DHS database hack, Adobe's boosted patch cadence, and Canada's disruption of ransomware operations. AssuranceAmerica suffered a data breach affecting 7 million people.
The European Commission has unveiled a cyber plan to reduce reliance on foreign AI systems, aiming to make frontier AI safe and accessible for European cybersecurity.
Flipper Devices will continue developing the Flipper Zero firmware with community contributions, after announcing the end of full-time feature development.
Vibe Coding, powered by generative AI, enables software creation at the speed of thought, but security lags behind, introducing new risks and challenges.
Risk assessment data must link to information about operational disruptions to become actionable, and a connected risk lifecycle is necessary to understand business impact and interpret threats.
The relaunched Claude Fable model is available to all users, but its performance has been degraded, with users reporting it feels weaker and is being routed through stricter safety systems more often.
The US has lifted export control restrictions on Anthropic's Fable 5 and Mythos 5 AI models after the company agreed to implement new safety guardrails and classifiers.
OpenAI and Anthropic are restricting new AI model releases due to cybersecurity concerns from the Trump administration.
The AI AGENT Act would create a list of secure and trustworthy AI agent software providers, allowing users to choose compliant providers for online platforms.
Anthropic is testing Claude Cowork support on mobile, allowing users to manage long-running tasks from their phone.
Philip Martin joins Uber as Chief Information Security Officer, bringing experience from Coinbase, Palantir, and Amazon to protect the company's users and operations.
Nebulock has raised $25 million in Series A funding to expand its AI-native contextual security platform, bringing total funding to over $33 million.
Agentic GRC agents are changing the way compliance operates by providing autonomy, context, and execution of multiple steps, allowing for continuous assessment and monitoring.
Homeland Security Secretary Markwayne Mullin says CISA needs 600 new hires, a process that can't start until a new director is confirmed.
A federal judge struck down major sections of a Trump administration executive order restricting mail-in ballots and voter lists, finding it unconstitutional.
Effective fraud prevention programs require monitoring across every customer touchpoint to identify advanced fraud methods and emerging trends.
Carl Froggett combines CISO and CIO roles at Deep Instinct, highlighting the overlap between technology and security.
French President Emmanuel Macron has urged the US to share cutting-edge AI with other democracies, warning of a potential drop in value for US firms if they restrict access.
The fundamental design of TCP/IP networks poses significant security challenges, with 68% of initial access attacks not relying on technical vulnerability exploitation.
Accenture is acquiring a majority stake in Dragos and fully acquiring runZero and NetRise in a $4.1 billion OT cybersecurity push.
A new policy paper advocates for software bills of materials for artificial intelligence to reduce cyber risk and improve transparency.
The Trump administration's decision to impose export controls on Anthropic's AI models has been met with skepticism by lawmakers, who question the national security concerns cited as the reason.
Artificial intelligence is being used across the security landscape, with both benefits and risks, and its misuse by insiders and exploitation by cyber adversaries is a growing concern.
Isira Adithya, a Sri Lankan-born hacker, discusses his journey from a childhood prodigy to a successful ethical hacker, driven by curiosity and a desire to push boundaries.
Anthropic's Claude Fable 5 AI model has been released with robust safeguards, but industry professionals express concerns over its potential misuse in cybersecurity and the creation of a 'security poverty line'.
Google Cloud lays off members of its cybersecurity division, while Coupang faces a $400 million fine for a data leak affecting over 30 million customers.
Anthropic has rolled out Claude Fable 5, a new AI model with strict safeguards, available for a limited time to Pro, Max, and Enterprise customers.
Security teams can efficiently incorporate AI applications into their workflow by following 12 practices, including visibility, risk understanding, and trust building.
The future of AI will be shaped by trust around innovation, requiring a new model of collaboration between industry and policymakers that maintains speed and adaptability while establishing accountability for real-world outcomes.
Armenian Prime Minister Nikol Pashinyan's pro-European party won nearly 50% of the vote, defeating the pro-Russian party despite a large-scale Russia-linked disinformation campaign.
Anthropic proposes a coordinated pause in AI development to mitigate risks, warning that humans may lose control as technology advances rapidly.
Wazuh Cloud reduces security operations complexity with automation, AI-driven analysis, and seamless scalability, empowering teams to focus on protecting critical assets.
The European Commission proposes laws and strategies to reduce reliance on foreign technology, focusing on semiconductors, cloud computing, and open-source software.
Department of Homeland Security Secretary Markwayne Mullin says CISA ideally needs 2,800 personnel to effectively carry out its cybersecurity mission.
The Trump administration is considering Shyam Sankar, a Palantir executive, to lead the Cybersecurity and Infrastructure Security Agency (CISA).
Brave Software has released Brave Origin, a paid, minimalist version of its browser that removes cryptocurrency and monetization features for a more streamlined experience.
The Pentagon is integrating cyber into all operations and prioritizing security in artificial intelligence usage to counter emerging threats.
The White House has released a pared-back AI executive order, establishing a voluntary review period for government testing of AI models within 30 days of release to the public.
Two new reports offer competing explanations for the growing cybersecurity crisis, with one suggesting a failure of tools and the other citing poor management of existing tools.
President Donald Trump signed an executive order to vet national security risks of advanced AI systems before public release, with voluntary participation from AI developers.
The Trump administration issued a revised executive order on artificial intelligence, significantly weakening provisions that had been opposed by industry.
The US Postal Service is moving forward with mail-in ballot restrictions, following a court's rejection of a request to block an executive order from President Donald Trump.
The National Security Agency has selected new leads for its cybersecurity directorate and Cybersecurity Collaboration Center, including David Imbordino and Bruce Jones.
OpenAI has announced plans to safeguard information and aid cybersecurity defenders in the 2026 midterm elections, including combating deepfakes and AI misuse.
Anthropic confirms plans to release Mythos-class models to the public in the coming weeks, after addressing initial security risks.
A Google security engineer has been accused of using confidential search trends to make over $1.2 million on the prediction marketplace Polymarket.
SIEM helps MSPs reduce noise and stop threats faster by providing a centralized view of activity across the entire environment and automatically correlating related events.
Geordie, an AI security and governance startup, has raised $30 million in a Series A funding round to enhance its platform and expand operations.
A House subcommittee will hold a hearing on June 4 to discuss the impact of frontier artificial intelligence models on cybersecurity threats.
The head of the UK's GCHQ spy agency warns that AI is an unstoppable force with both offensive and defensive ramifications for cyberspace, requiring a reimagining of cybersecurity.
Army Gen. Joshua Rudd has commissioned two studies to examine how U.S. Cyber Command can modernize, including a review by MITRE to scrutinize the command's acquisition model.
AppOmni's Marlin AI brings autonomous investigation to SaaS security, automatically detecting and analyzing potential security issues and recommending remedial actions.
Lawmakers from both parties agree that reductions to the Cybersecurity and Infrastructure Security Agency have gone too far, damaging its ability to defend against foreign adversaries.
Nearly 80% of organizations are confident in their cybersecurity readiness, yet reality shows a more complicated story, with many lacking the budget and resources to fully invest in AI-powered security solutions.
Chargebacks only capture a narrow slice of fraud losses, hiding bigger issues that affect revenue, customer experience, and long-term profitability.
President Donald Trump has postponed the release of an executive order focused on AI security, citing concerns it could harm US AI industry competition with countries like China.
Security teams must prepare for AI applications moving into production, leveraging data-driven discussions, agility, and future-proofing to secure them.
Cyber resilience is crucial for business continuity, as it helps organizations manage risk and ensure operations continue uninterrupted despite disruptions.
Security teams can manage shadow AI tools by building a full picture of what's running, writing a policy that works with employees, and creating a fast lane for new tool requests.
Sean Plankey, former nominee for director of the Cybersecurity and Infrastructure Security Agency, has been named US CEO of defense startup UFORCE.
Microsoft is testing a resizable taskbar and customizable Start menu in the latest Windows 11 Insider Preview Build 26300.8493.
The FTC will begin enforcing the Take It Down Act on May 19, requiring websites to remove nonconsensual deepfake media within 48 hours or face fines up to $53,088 per violation.
Advanced artificial intelligence models will fundamentally change warfare, according to a top Pentagon cyber official, representing a 'watershed moment' in the development of frontier AI models.
Anthropic's Claude Mythos Preview and OpenAI's GPT-5.5 have significantly surpassed benchmarks for autonomous cybersecurity tasks, with the AISI estimating a doubling time of approximately five months.
A group of international government agencies has released guidance on what an artificial intelligence 'ingredients list' tool should include to make AI more secure.
Hiring more analysts won't solve the SOC's alert problem due to the volume of alerts exceeding human investigation capacity.
The trial between Elon Musk and OpenAI's leaders has sparked concerns about the risks of artificial intelligence to humanity, with both sides accusing each other of trying to control the company's development of advanced AI technology.
The Cybersecurity and Infrastructure Security Agency has seen significant gains from AI automation in its security operations unit, enabling faster threat triage and response.
Data centers have become vital to modern society, making them high-value targets for cyber and physical attacks, with potential disruptions affecting not just businesses but also national security and entire economies.
The National Geospatial Intelligence Agency faces challenges in integrating AI tools, including job loss anxiety and ensuring safety while moving quickly.
The US military has reached deals with 7 tech companies, including Google and Microsoft, to use their AI in classified computer networks to augment warfighter decision-making.
Federal Chief Information Officer Greg Barbaccia is approaching Anthropic's Mythos model with caution, acknowledging its potential to strengthen federal cyber defenses despite uncertainties about its real-world performance.
Microsoft has introduced a new modern Run dialog in Windows 11, which is faster and supports dark mode, with a median time-to-show of 94ms.
Illinois Representative Delia Ramirez has been appointed as the top Democrat on the House Homeland Security Committee's Cybersecurity and Infrastructure Protection Subcommittee, replacing Eric Swalwell following his resignation from Congress.
Static audits and point-in-time dashboards can no longer keep pace with AI-accelerated threats. Security leaders must shift toward runtime visibility, identity governance, and outcome-based metrics.
NATO's Locked Shields 2026 wrapped up on Friday, bringing together more than 4,000 cybersecurity professionals from 41 countries to defend critical infrastructure against simulated live-fire cyberattacks.
As agentic AI systems capable of autonomous action take center stage at RSA Conference 2026, cybersecurity experts argue the most effective defense strategy is straightforward: if it can act, treat it like an identity.
The EU's Digital Operational Resilience Act, in force since January 17, 2025, makes credential security a binding regulatory obligation under Article 9 — and financial institutions that cannot prove compliance face direct supervisory consequences.
This week's cybersecurity highlights include unauthorized access to Anthropic's Claude Mythos, Sean Plankey withdrawing his CISA director nomination, and the UK NCSC unveiling a new hardware display-security device called SilentGlass.
Microsoft is restructuring the Windows Insider Program into just two channels — Experimental and Beta — while ending gradual feature rollouts in the Beta Channel to address long-standing tester frustrations.
Senior U.S. military leaders are confronting urgent questions about securing and controlling AI systems as the Pentagon accelerates adoption of autonomous weapons and machine-learning tools for battlefield decisions.
Microsoft is introducing several Windows Update improvements giving users greater control over update timing and reducing unexpected restart interruptions, now rolling out to Windows Insiders in Dev and Experimental channels.
Microsoft has made a new RemoveMicrosoftCopilotApp policy setting broadly available following the April 2026 Patch Tuesday, allowing IT administrators to silently remove the Copilot AI assistant from managed enterprise devices.
Israel-based Copperhelm has emerged from stealth mode after securing $7 million in seed funding for an AI-driven cloud security platform that deploys autonomous agents to investigate threats and execute remediation in real time.
Artifact management firm Cloudsmith has raised $72 million in a Series C round led by TCV, bringing its total funding to $124 million as it expands its secure software supply chain platform.
McLean, VA-based startup Rilian has closed $17.5 million in combined seed and seed extension funding to expand its agentic security orchestration platform, Caspian, targeting government, critical infrastructure, and law enforcement customers.
Sean Plankey formally asked President Trump to pull his nomination to lead CISA, citing Senate gridlock after more than a year without confirmation. The agency continues to operate under acting leadership amid deep budget cuts and ongoing personnel instability.
A House Oversight subcommittee roundtable on 'Artificial Intelligence and American Power' turned deeply anxious as lawmakers questioned AI's threat to national security, civil liberties, and humanity itself.
BleepingComputer and Kaseya are hosting a live webinar on May 14, 2026, examining how AI-powered phishing, ransomware, and business email compromise are outpacing MSP defenses and why backup and recovery must be part of every security strategy.
NAKIVO has released Backup & Replication v11.2, delivering automated real-time replication, full VMware vSphere 9 and Proxmox VE 9.0/9.1 support, OAuth 2.0 authentication, and expanded ransomware resilience for over 16,000 customers worldwide.
Flare analysts discovered an underground forum guide titled 'The Underground Guide to Legit CC Shops: Cutting Through the Bullshit,' revealing how threat actors systematically evaluate carding marketplaces, manage operational security, and build trust in a deceptive ecosystem.
Launched in early April 2026, CoChat is a new enterprise platform designed to expose and govern shadow AI usage, offering teams shared access to leading LLMs and agentic systems while enforcing human oversight over autonomous actions.
As Congress debates extending Section 702 of FISA, experts on both sides acknowledge deep uncertainty about whether the 2024 reform law improved or worsened controversial warrantless surveillance powers.
White House Chief of Staff Susie Wiles is set to meet Anthropic CEO Dario Amodei to discuss the company's new Mythos AI model, which has drawn federal attention for its national security and cybersecurity implications.
Modern cyberattacks have outpaced what governments can realistically defend alone. A shift toward deeper public-private collaboration is no longer optional — it's the only viable path forward.
National Cyber Director Sean Cairncross confirmed Wednesday that additional executive orders are expected as the Trump administration moves to implement its national cybersecurity strategy published last month.
CISA has notified CyberCorps: Scholarship for Service participants that summer 2025 internships are canceled due to a DHS funding lapse, leaving hundreds of cyber scholars in limbo for a second consecutive year.
Operational technology asset owners are being required to attest to post-quantum cryptographic readiness, but the frameworks, tools, and visibility needed to make those attestations meaningful simply don't exist in most OT environments.
Forgotten laptops issued to contractors and former employees represent a growing and underappreciated attack surface, combining credential exposure, lateral movement risk, and compliance failures into one persistent blind spot.
Researchers at Rutgers University have developed VitalID, a biometric authentication system that uses low-frequency skull vibrations generated by breathing and heartbeat to verify the identity of XR headset users without requiring any additional hardware.
Most AI detection systems learn from post-compromise artifacts, but new data from GreyNoise reveals that attacker behavior — including fresh infrastructure and behavioral spikes — frequently surfaces well before a breach is confirmed.
A new Ekoparty report based on 605 LatAm cybersecurity professionals reveals the region faces 40% more cyberattacks than the global average while struggling to tap its largely self-trained talent pool.
OpenAI has introduced a new $100 monthly Pro subscription for ChatGPT, directly mirroring Anthropic Claude's pricing structure and targeting coders and enterprise users who need advanced AI capabilities.
Healthcare professionals are turning to unsanctioned AI tools to manage crushing workloads, creating dangerous visibility gaps that compound ransomware recovery challenges. Experts say denial is no longer viable — containment and discovery are now the priority.
The OWASP Foundation has released updated AI security guidance splitting recommendations into generative AI and agentic AI tracks, while cataloguing 21 data security risks and expanding its solutions matrix from 50 to more than 170 providers.
RSAC 2026 placed artificial intelligence front and center, with more than two-thirds of sessions featuring an AI component, yet the conference's own theme — 'The Power of Community' — served as a pointed reminder that human oversight remains non-negotiable. A conspicuous absence of the US federal government added further tension to an already charged event.
Autonomous AI assistants like OpenClaw are transforming productivity for developers and IT workers, but security researchers warn they are simultaneously creating one of the largest attack surfaces the internet has ever seen.
Full Sail University is opening an on-campus IBM Cyber Defense Range powered by AWS and Cloud Range in April 2026, giving cybersecurity and IT students hands-on experience in realistic attack-and-defense simulations.
Dark Reading Editor-in-Chief Kelly Jackson Higgins reflected on RSAC 2026, noting that agentic AI arrived far sooner than the industry expected, leaving most companies playing catch-up while threat actors continue to raise the stakes.
With no US federal government representation at RSAC 2026, European Union regulators stepped in to fill the void as CISOs grapple with AI-driven threats, quantum computing, and a rapidly shifting geopolitical landscape.
With the US and Iran reaching a fragile ceasefire, security researchers warn that pauses in kinetic conflict historically do little to slow — and often accelerate — cyber operations from state-aligned threat actors.
Despite record spending and expanding security teams, breach counts and economic losses keep rising. A San Francisco panel of five security executives identified the flawed assumptions undermining the entire industry.
Nearly one in three cyber intrusions now involve valid employee credentials, and AI is making these attacks faster and cheaper than ever. Security teams must fundamentally rethink how they detect and respond to identity-based threats.
CrowdStrike has integrated Microsoft Defender for Endpoint telemetry into its Falcon Next-Gen SIEM, marking a significant shift in the once-adversarial relationship between the two cybersecurity giants.
Reddit CISO Frederick Lee and Omdia principal analyst Dave Gruber explain how AI is delivering real value in cybersecurity today — from automating runbooks to accelerating threat intelligence — and what risks organizations must still navigate.
AI dominated conversations at RSAC 2026 Conference, but new research reveals that cybersecurity professionals face mounting stress, widening skills gaps, and growing complexity — making the human factor more critical than ever.
Pluralsight has unveiled SecureReady, an end-to-end security skill development platform combining on-demand content, hands-on labs, and expert seminars to help organizations build operationally ready cybersecurity teams.
Niobium has unveiled The Fog, a private cloud infrastructure platform that keeps data encrypted throughout computation using fully homomorphic encryption. The platform enters private beta now, with a public launch targeted for late Q2 2026.
At RSAC 2026, AI dominated conversations for the fourth consecutive year, with industry leaders debating agentic systems, SOC replacement, and whether humans can realistically stay in every security decision loop.
The FBI's Internet Crime Complaint Center recorded nearly $20.9 billion in cybercrime losses in 2025, a 26% rise from the prior year and a staggering 400% increase since 2020, according to the agency's annual report.
The Department of Commerce is soliciting proposals to assemble a government-backed catalog of full-stack American AI technologies for promotion to allies and partners abroad, as mandated by President Trump's AI executive order.
Orange Business is rolling out branded calling, deepfake detection, and AI-augmented telephony to address rising impersonation fraud and eroding trust in enterprise voice channels across more than 7,000 enterprise customers worldwide.
Industrialized fraud rings are deploying AI to build synthetic identities at unprecedented scale, rendering traditional detection methods obsolete. Experts argue the only viable response is to stop reacting and start hunting.
BleepingComputer is hosting a live webinar on April 30, 2026 at 2:00 PM ET exploring how security teams can detect early threat actor signals across dark web forums, Telegram channels, and access broker marketplaces.
The February 2026 Figure breach exposed nearly 967,200 email records without a single exploit — and the downstream attack chain it enables exposes a fundamental flaw in how most organizations think about MFA.
New research from CalTech and Google suggests fault-tolerant quantum computers capable of breaking classical encryption may need far fewer qubits than previously thought, compressing the window for post-quantum migration.
Black Hat USA 2026 returns to Mandalay Bay Convention Center in Las Vegas from August 1–6, featuring four days of expert-led Trainings, a Summit Day, and a two-day main conference packed with Briefings and Arsenal tool demos.
New Qualys research analyzing over one billion CISA KEV remediation records from 10,000 organizations finds that 88% of tracked weaponized vulnerabilities were remediated slower than they were exploited, exposing a structural ceiling that staffing alone cannot fix.
MITRE has released the Fight Fraud Framework (F3), a free, open knowledge base mapping the tactics, techniques, and procedures used by fraudsters across cyber channels to steal money, assets, and information.
API attacks surged 68% year-over-year as organizations struggle with shadow APIs, broken authorization, and inadequate rate limiting. Our analysis covers the key findings from the latest industry data.
The latest analysis of global internet traffic reveals that automated bot traffic accounts for 49.1% of all web requests, with malicious bots representing a growing share. E-commerce and financial services remain the most targeted sectors.
The legal status of web scraping has shifted significantly in 2026, with new court decisions, legislative updates, and diverging approaches between the US and EU. Here is what businesses need to know about the current state of scraping law.