Cybersecurity

Cybersecurity Data Sharing Faces Liability Deadline

If not renewed, CISA 2015 protections end in the US on September 30.

This article appears in the September issue of Global Finance Magazine.

Companies that share cybersecurity information with their peers have until Sept. 30, 2026, before the limited liability granted by the Cybersecurity Information Sharing Act of 2015 runs out, exposing them to potential regulatory scrutiny and penalties.

Under the Act, non-federal entities may share anonymized cyberattack and response information with other non-federal entities and the federal government via the Automated Indicator Sharing (AIS) program operated by the U.S. Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA).

In July, 23 industry associations that represented the financial services, energy, technology, transportation, healthcare, and retail sectors wrote to Speaker of the House Michael Johnson (R-LA) requesting an extension to the Act since it is “a foundational component of the nation’s cybersecurity.”

However, some view AIS as a relic of an earlier era of cyberdefense that provides machine-readable cyber threat indicators and defensive measures against malicious IP addresses, file hashes associated with malware distribution, and known malicious web links.

“It was a failure from the get-go, and it accomplishes nothing,” Milton Mueller, a professor of cybersecurity policy at Georgia Institute of Technology’s Jimmy and Rosalynn Carter School of Public Policy, told Global Finance. “No one will notice when it’s gone.”

A web post by Mueller earlier this year cited a DHS Office of Inspector General (OIG) report stating that non-federal participants using AIS fell to fewer than 90 in 2024 from a high of 304 in late 2022. The report also noted that alert volume on the platform dropped 93% between 2020 and 2022. Though there was a surge in alerts, to 10 million from 1 million, the OIG found that 89% of the data came from a single private-sector participant.

“The non-Federal participants we interviewed stated that they find AIS useful and an effective tool for protecting their systems from cyber threats,” wrote the report’s authors. “However, the number of non-Federal participants remained lower in 2023 and 2024 than in previous years. AIS now has 87 non-Federal participants compared to 252 in 2020.”

Nonetheless, the House of Representatives included an extension to the Act in part of the 2027 National Defense Authorization Act, which is waiting for Senate approval.

In July, the Trump administration sidestepped legislative concerns and created “Gold Eagle,” a clearinghouse to share cybersecurity vulnerability information and coordinate responses among private industry and federal agencies, including the U.S. Treasury Department, CISA, and the U.S. War Department, formerly the Defense Department. The new system will be powered by frontier artificial intelligence, which emulates and may surpass human-level intelligence.

Private Data Sharing Alternatives

Although CISA 2015’s renewal is up in the air and details regarding Gold Eagle are sparse, private industry has had formalized cybersecurity data-sharing programs since 1999.

“There is plenty of threat intelligence sharing going on,” said GeorgiaTech’s Mueller. “There are commercial services, sectoral nonprofit Information Sharing and Analysis Centers (ISACs), and industry consortia like the Cyber Threat Alliance.”

The newly rebranded Alliance for Critical Infrastructure (formerly the Tri-Sector Executive Working Group) seeks to bring together critical infrastructure operators to strengthen national resilience and reduce systemic risk, while sustaining economic continuity.

The 501c(6) non-profit industry coalition started with nine founding members: American International Group Inc., AT&T Inc., Berkshire Hathaway Energy Co., Consolidated Edison Inc., JPMorgan Chase & Co., Lumen Technologies Inc., Mastercard Inc., The Southern Co., and Xcel Energy Inc.

Since its formation, the organization has been on a membership drive, with JPMorgan Chase CEO Jamie Dimon reportedly having private conversations with numerous companies across industry sectors to join the alliance.

Despite the benefits of sharing cybersecurity data, such as faster and broader threat detection and coordinated responses, sharing that data is not risk-free for a corporation.

“When information is shared, one should assume that information could be obtained by others, including regulators, litigants, and insurers, and that can inform the nature, contour, and context of the sharing,” said Mary Alexander Myers, lead of law firm Jones Day’s Cybersecurity, Privacy & Data Protection practice.

For chief financial officers, uncertainty around CISA’s liability shield adds another costly risk to the existing risk landscape. As cyber governance moves from the realm of IT to a board-level issue, CFOs and other C-level executives will have to determine if a reauthorized CISA 2015 or Gold Eagle provides them with enough confidence to continue to share cybersecurity information without the fear of regulatory penalties.

Rob Daly covers fintech and the economy. Contact him at rdaly@gfmag.com.

Source link

Sens. Schiff and Klobuchar unveil new cybersecurity bill

Sen. Adam Schiff, D-Calif., speaks Tuesday at the U.S. Capitol in Washington, D.C. Schiff and Sen. Amy Klobuchar, D-Minn., have released a new cybersecurity bill, the Water Cyber Shield Act. Photo by Bonnie Cash/UPI | License Photo

Aug. 10 (UPI) — Sens. Adam Schiff, D-Calif., and Amy Klobuchar, D-Minn., released a new cybersecurity bill, the Water Cyber Shield Act, on Monday in an effort to meet increased cybersecurity needs for U.S. water infrastructure.

This follows recent cyberattacks on more than 30 municipal water systems throughout Minnesota and other states last month. Officials suspect that they may originate from Iran-based hackers.

While utilities regained control over their systems and water supplies were not affected, CBS News reported, cybersecurity experts saidthe attacks exposed longstanding weaknesses.

A press release from Schiff, the top Democrat on the Fisheries,Water and Wildlife subcommittee of the Environment and Public Works Committee, said the act would strengthen federal oversight by the Environmental Protection Agency, provide important funding for local utilities and protect drinking water and wastewater systems from cyberattacks.

“Every American depends on safe, reliable drinking water, yet recent events have exposed just how vulnerable our water systems remain toc yberattacks by foreign adversaries and criminal entities,” Schiff said in a statement. “These threats are not hypothetical — they are happening right now.This legislation gives EPA the tools the tools it needs to protect thiscritical infrastructure while providing the resources that local water and wastewater systems need to strengthen their cybersecurity without passing the cost on to ratepayers.”

The bill would increase drinking water and clean water state revolving funds by $300 million annually, The Hill reported. It would requirethe EPA to work with the Cybersecurity and Infrastructure Security Agency and the National Institute of Standards and Technology to establish basic cybersecurity standards for drinking water systems.

“The recent cybersecurity attacks on Minnesota have highlighted the urgent need to improve the security of our water systems and critical infrastructure,” Klobuchar said. “Our legislation will direct the EPA to assess water infrastructure cybersecurity and identify vulnerabilities, and help municipal water systems defend against cyber threats.”

Source link

Banks in Japan Turn to AI for Cyberdefense 

Financial giants in Japan partner with AI firms to build zero-trust cybersecurity defenses.

This article appears in the July/August issue of Global Finance Magazine.

Japan’s banking sector is becoming a high-stakes proving ground for AI-driven cybersecurity

As autonomous “frontier AI” models rapidly increase the speed and scale of cyberthreats by identifying zero-day vulnerabilities, the country’s financial giants are re-engineering their defensive paradigms.

So, it came as no surprise that, in June, Minister of Finance Satsuki Katayama announced that Mizuho, MUFG, and SMBC had secured eligibility to use cutting-edge AI tools, including those from Alphabet’s Google. 

“From a financial perspective, this issue concerns all companies and all economic actors,” Katayama says. “We therefore want to make sound choices in a way that serves the national interest.”

Alphabet also had an edge, according to Katayama, considering it already runs data centers in Japan.

Katayama’s announcement followed a critical breakthrough in which the government and major financial institutions secured access to AI company Anthropic’s highly guarded “Claude Mythos” model. Mythos possesses unprecedented capabilities to discover and remediate software configurations rapidly, but its dual-use nature means it could be weaponized by attackers to construct immediate exploit pathways. 

Anthropic’s rival, OpenAI, has similarly pledged future access to its latest frontier model, GPT-5.5-Cyber, to a select number of domestic banks.

This rapid influx of American technology underscores how Japanese banks aim to delicately balance the immense benefits of generative AI with its significant operational risks. 

The urgency stems from an unprecedented joint emergency directive issued on May 22 by the Japan Financial Services Agency (JFSA) and the Bank of Japan (BoJ). 

Spurred by international alarms, including warnings from the UK AI Security Institute and a Financial Stability Report from the Banco de España, regulators realized that human-dependent monitoring cannot keep pace with the velocity of AI-generated attacks.

The JFSA-BoJ directive also comes in the wake of “Project YATA-Shield,” a comprehensive, Japanese government-wide cyber defense package mobilized to foster “Advanced Threat Awareness.” 

With the JFSA urging banks to prioritize resources on a risk basis and shift toward continuous “zero-trust” authentication, Japan is demonstrating that resilience in the AI era is no longer measured by blocking every attack, but by the speed of detection, containment, and recovery.

John Amari is a contributing writer based in Japan.

Source link

Michigan joins Minnesota in reporting cyberattacks, with FBI investigating | Cybercrime News

No culprit has been identified in any of the attacks, which comes after authorities warned of a possible Iranian plot.

Michigan has reported cyberattacks on nine of its water systems, days after Minnesota reported similar breaches across the state.

The United States Federal Bureau of Investigation (FBI) said it was investigating both of the attacks on Saturday. In an advisory earlier this week, it said that at least seven states have reported incidents, but so far only Minnesota and Michigan have been identified.

Recommended Stories

list of 3 itemsend of list

No culprit has yet been pinpointed. However, the breaches came after the FBI, Cybersecurity and Infrastructure Security Agency (CISA) and other agencies warned in an advisory last week that Iranian hackers have been targeting water and wastewater systems and the operational controls of other critical infrastructure sectors.

“The FBI is aware of recent public reporting around Water and Wastewater (WWS) sectors,” the agency said in a statement on Saturday. “The FBI and our interagency partners are fully engaged to protect critical infrastructure, and we remain well-equipped to protect against cyber threats of all varieties.”

Dale George, the director of communications for Michigan’s Department of Environment, Great Lakes and Energy, meanwhile, said that “all systems continued to operate safely” following the attacks.

He said Michigan received a federal cyber alert on Tuesday about attempts to tamper with operational technology in water systems.

Soon after, the state received “a small number of reports from Michigan communities indicating activity consistent with what federal agencies described”, said George.

Minnesota had earlier in the week reported attacks on 30 sites. Minnesota IT Services, the state information technology agency, said most of the confirmed attacks involved technology that water systems use to remotely monitor and control equipment.

The agency has said that impacted systems did not necessarily equate to water disruptions, noting that as of Thursday, there were no active requests for residents to modify their water usage. Some modifications had been requested earlier in the week.

Local water plants are generally more vulnerable than other infrastructure because they are more likely to have out-of-date cybersecurity. Federal law enforcement has previously indicted Iranian hackers for allegedly targeting water infrastructure.

Throughout the war, US President Donald Trump has repeatedly threatened to attack civilian infrastructure in Iran, including power and water desalination plants.

When asked about the Minnesota attacks on Friday, Trump instead pivoted to criticise the Democrat-led state government in Minnesota.

“I think Minnesota is behind it,” Trump said, without providing further evidence or clarification. “I don’t think there was an Iranian cyberattack.”

Minnesota Governor Tim Walz, meanwhile, indicated his belief that Iran was behind the attack. He further blamed Trump’s cuts to federal government employees for making the US more vulnerable to cyberattacks.

“Trump knows exactly who is responsible for this attack, and knows that other states were hit too,” Walz said.

Source link

Insurance Industry Scrambles for Tech & AI Talent

Whether driven by retirements or re-configuration, the insurance industry is scrambling for tech talent.

This article appears in the July/August issue of Global Finance Magazine.

Caught between a wave of retirements and a weak talent pipeline short on tech-savvy candidates, the insurance industry faces a talent shortage that could affect its ability to address cyber and other emerging risks.

“Demand is rising sharply for fluency in analytics, AI, as well as in cyber risk. These are all capabilities that are either new or that the traditional sources of talent haven’t produced at scale,” says Peter Miller, president and CEO of The Institutes, a risk management and insurance education provider. 

In 2014, to help expand the talent pool, a group of risk management and insurance companies, nonprofits, and educational institutions, led by The Institutes, created MyPath, a one-stop resource for job seekers that outlines the benefits of, and pathways to, insurance careers.

The initiative remains timely because, in a November 2024 Institutes report, 66% of insurance professionals in the property and casualty sector surveyed identified the loss of institutional knowledge as the retirement wave’s greatest impact: “The result is both a talent shortage and a knowledge-transfer risk.” That means organizations must find ways to “preserve institutional expertise that took decades to build” while developing new skills.

Other Industry Observers Agree

“There is a dual-sided talent crisis,” says Margaret Milkint, global insurance practice leader at DSG Global, an executive search firm. “Organizations are losing experienced professionals faster than they can be replaced while simultaneously racing to build leadership capacity around capabilities that barely existed a decade ago.”

The talent crunch is rippling beyond primary insurers to encompass reinsurance carriers, brokerages, and risk management firms, she says. “Artificial intelligence is creating an entirely new category of roles spanning enablement, governance, ethics, and cultural integration that require skill sets the traditional insurance pipeline was never built to produce.”

The shortage of talent with tech and AI capabilities has become one of the industry’s most critical gaps as roles across underwriting, claims, and risk management become more data-driven, says Victor Harris, vice president at financial services recruiter Selby Jennings. “The shortage is slowing the pace at which many organizations can fully adopt and scale their AI strategies,” he warns.

Worsening Insurance Talent Squeeze

While they agree that AI is increasing demand for certain roles, experts at Aon observe that AI and automation are reducing demand in some entry-level and operations slots, particularly in finance and reporting. 

“There is a risk of mischaracterizing the issue as a blanket shortage,” says Louisa Blain, head of insurance for human capital at Aon. “The reality is more nuanced, and linked to where the industry wants to grow versus the skills it currently has versus requirements for the future. This is less about replacement and more about reconfiguration of the workforce.”

Louisa Blain, Aon
Louisa Blain, Aon: This talent shortage is less about replacement and more about reconfiguration of the workforce.

Yet, the talent constraints could limit industry growth in specialist and emerging risk areas, argues Jeff Reider, head of Aon’s benchmarking, strategy and technology group. The Institutes’ Miller sees the shortage coming in cyber, complex liability, multinational program structuring, and cross-jurisdictional claims coverage. 

“Knowledge lost to retirement can have meaningful downstream effects on compliance and strategy,” he says. “For any multinational that depends on its risk transfer partners to keep pace with growing exposure complexity, this is a material consideration.”

The infusion of capital and the emergence of new carriers and managing general agents in specialty lines have made the talent squeeze more pronounced over the last five years, says Tony Chimera, chief administrative officer at carrier Westfield Specialty. 

“That has pulled talent out of the pool used by insurance carriers and brokers,” he adds, noting the talent squeeze has been building for two decades. “You do have an aging workforce. Some people are working longer, but you have a 55- to 65-year-old workforce that is probably not going to be there in the next five years.”

In addition, insurers are competing with the banking and technology sectors, which many younger professionals are turning to for more attractive careers with greater compensation. Yet, the actual compensation for some banking sector jobs, when salaries are integrated with a lack of work/life balance, can be much less desirable than insurance roles, Chimera points out: “Insurance is a great industry where you can earn a lot. And you can have a life.”

But Harris notes that many insurers’ locations in midsize cities can dissuade younger professionals intent on living in larger, more alluring metropolises. That leaves the industry with a limited pool of specialized talent.

Technical Fluency Isn’t Everything

How, then, is the industry to attract new talent? 

The technology industry could be one source, Chimera says. But candidates must accompany the tech skills needed for roles in data analytics, AI, and cybersecurity with knowledge of the complex insurance business. 

“Technical fluency alone doesn’t translate directly into effectiveness in risk management and insurance,” says Miller, adding that regulatory knowledge, coverage mechanics, and underwriting judgment take time to develop. “The most successful transitions involve strong technical capabilities combined with a genuine curiosity to develop insurance-specific expertise.”

While agreeing that the talent shortage has been building for years, Milkint notes that there is no clear consensus on when, or whether, it will peak. “Closing this gap,” she says, “will require the entire industry to go on the offensive and actively dismantle outdated stereotypes, confront long-standing biases, and make a compelling, unified case that insurance is not just keeping pace with the future, but helping to shape it.”

To attract more students from outside the traditional insurance and risk management programs, the industry must expand students’ awareness of career opportunities “beginning well before students reach their junior and senior years of college,” says Grace Grant, executive director at Gamma Iota Sigma. The collegiate society represents more than 7,000 students interested in careers in insurance, risk management, and actuarial science across 177 colleges and universities.

“Many students simply are not exposed to the breadth of careers available in the industry,” Grant says, adding that employers should highlight their innovation, technological sophistication, purpose-driven work, career stability, and advancement opportunities. “Students are highly motivated by careers where they can make a meaningful impact, and insurance is fundamentally about helping individuals, businesses, and communities recover from loss and manage uncertainty.”  

Paula L. Green is a contributing writer based in New York City.

Source link

Open AI says its AI model “went rogue”: What do we know? | Cybersecurity News

OpenAI has revealed that one of its artificial intelligence models independently stole login credentials and hacked into another technology company’s system, in what is widely seen as one of the first known incidents of AI systems acting autonomously.

“We had a significant security incident during evaluation of our models,” CEO Sam Altman posted on X on Tuesday.

Recommended Stories

list of 4 itemsend of list

The incident comes as calls mount from technology rights advocates for stricter guardrails on rapidly evolving AI systems.

They have grown so powerful in a short span of time that alarming phenomena such as deepfakes and sophisticated cyberscams are becoming the norm.

Earlier this year, a number of software engineers quit their jobs at top companies such as Anthropic and AI in protest against how the technologies are being built.

“AI is accelerating the discovery and exploitation of vulnerabilities,” OpenAI said in a lengthy statement on Tuesday that detailed the latest incident.

“The primary lesson from this incident is that model security and safety must keep pace with rapidly advancing capabilities.”

Here’s what we know about the breach:

Sam Altman, cofounder and CEO of OpenAI, testifies before a Senate committee hearing in Washington, May 8, 2025
Sam Altman, cofounder and CEO of OpenAI, testifies before a Senate committee hearing in Washington, May 8, 2025 [Jose Luis Magana/AP]

What has happened?

OpenAI said two of its models found their way out of an isolated, no-internet access environment – or a sandbox – and hacked into the systems of tech company Hugging Face on their own.

The models involved are the latest GPT-5.6 Sol model and an unreleased model the company said is “even more capable,” than its latest version.

Hugging Face hosts openly sourced AI models and resources. The two OpenAI agents discovered vulnerabilities in Hugging Face’s servers and proceeded to steal login details and then hack into the company’s systems.

The incident occurred during an OpenAI internal testing session designed to assess the models’ cybersecurity capabilities. OpenAI had removed standard safety measures for the test.

Both sought to cheat their way through a problem during the test, OpenAI said. They went to “extreme lengths to achieve a rather narrow testing goal” and “found ways to gain access to secret information that it could use to cheat the evaluation”.

OpenAI’s security team detected the unusual activity internally, but details of the breach came to light following a joint investigation by both companies.

What has Hugging Face said?

Hugging Face disclosed last Thursday that its servers were hacked by an unknown but sophisticated agent acting on its own. The company discovered the breach through its own AI-assisted detection.

“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system,” the company said.

Following OpenAI’s disclosure that its models were involved in the breach, both sides conducted an ongoing joint investigation this week.

 

“We suspected last week’s cyberattack might have come from a frontier lab, given the sophistication of the agent. Turns out it did!” CEO Clement Delangue posted on X on Tuesday.

Hugging Face’s staff “strongly believe there was no malicious intent on their part,” Delangue added, referring to OpenAI.

Why does this matter?

Cybersecurity experts have previously sounded the alarm over the potential, extreme capabilities of AI systems and the dangers they pose.

But until now, there have been few real-life cases proving those concerns like this one.

Many warn that incidents like these could become commonplace and that AI systems pose a threat to financial, security and other sensitive data systems.

OpenAI revealed in a separate incident earlier this week that the unreleased, more powerful model had escaped an isolated environment during another test.

Anthropic, OpenAI’s rival, had similar issues with its most powerful agent to date, the Claude Mythos Preview model.

During a stress test of an early version, the model found its way out of a sandbox, gained internet access and emailed the supervising researcher that it had escaped and then wiped evidence of its activity. Anthropic halted a planned public release of the model afterwards.

In April, the US Federal Reserve and the Treasury Department convened a meeting with bank CEOs where officials warned about the cybersecurity risks posed by Mythos. Canada’s federal banking regulator has also warned financial institutions about the model’s capabilities.

The OpenAI breach also appears to make the case for companies like Hugging Face, which rely on open source systems, as opposed to more secretive AI development platforms like OpenAI.

“This incident, possibly the first of its kind, proves a point we’ve long believed: AI safety won’t be solved by any single company working in secret,” Hugging Face’s Delangue was quoted as saying in OpenAI’s statement.

“It will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere,” he added.

Source link

‘Unprecedented’: OpenAI says AI models autonomously hacked another company | Cybersecurity News

ChatGPT maker says an autonomous agent escaped a controlled test and accessed AI firm Hugging Face’s servers.

ChatGPT creator OpenAI has said that two of its most advanced artificial intelligence models broke out of a controlled test and hacked another AI company.

OpenAI said on Tuesday that the “unprecedented cyber incident” took place during an internal exercise meant to test its models’ cyber capabilities.

Recommended Stories

list of 3 itemsend of list

Instead, an autonomous agent powered by the AI models – the newly released GPT 5.6 Sol and an unreleased “even more capable” model – escaped the test environment and reached the open internet. It then used stolen login details and found a previously unknown security flaw to access Hugging Face servers, the company said.

OpenAI claims that the hack represented the agent going to “extreme lengths” to retrieve information that would help satisfy the testing goals.

Hugging Face cofounder Clement Delangue said the company had suspected that a frontier lab was behind the attack, and that he believed there was no malicious intent on OpenAI’s part.

“It’s quite mind-blowing that all of this happened autonomously!” he wrote, adding that it “might be the first incident of its kind”.

Greg Casar, a Democratic member of the United States House of Representatives from Texas, called the incident “alarming”.

“AI is developing extremely fast with no real regulations to keep us safe,” he said, calling for mandatory independent safety testing, mandatory disclosure of security incidents, and international cooperation.

The disclosure comes weeks after US President Donald Trump signed an executive order creating a framework to vet the national security risks of the most advanced AI systems before their public release.

Experts have repeatedly sounded the alarm over AI-enabled cyberattacks and models slipping beyond human control. Last month, AI developer Anthropic urged the industry to pause development of its most powerful systems.

Source link

Meta backtracks on AI-image feature for Instagram due to privacy backlash | Cybersecurity News

NewsFeed

Meta has rolled back its ‘Muse Image’ AI feature after widespread backlash over privacy and consent. The tool allowed users to generate AI images of people by simply ‘@ mentioning’ public Instagram accounts. The negative reaction was swift and global – forcing Meta to say it ‘missed the mark’.

Source link

Australia to double fines on Big Tech as children bypass social media ban | Social Media News

Canberra says tech platforms are still letting too many children bypass its under-16 social media ban.

Australia says it will double fines on social media companies that fail to keep children off their platforms, accusing Big Tech of dodging the spirit of its under-16 ban.

The government said on Saturday that new legislation would raise the maximum penalty for systemic breaches from 49.5 million to 99 million Australian dollars ($31m to $68m) and give the eSafety Commissioner stronger powers to force platforms to comply.

Recommended Stories

list of 3 itemsend of list

The regulator is investigating possible breaches by Facebook, Instagram, Snapchat, TikTok and YouTube.

“It’s clear Big Tech are not doing enough to comply with the law – there are still too many children on social media,” Prime Minister Anthony Albanese said.

“These changes reflect the seriousness with which we take any failure by social media companies to comply.”

The ban, which came into force on December 10, made Australia a global test case for countries trying to curb children’s access to social media. The United Kingdom, Indonesia, the United Arab Emirates and New Zealand are among those watching or considering similar restrictions.

But children have continued to evade the rules by using accounts registered to older people, creating fake profiles or logging in through private browsers.

A peer-reviewed evaluation published this month in the British Medical Journal found “insufficient evidence” that the ban had sharply reduced social media use among young people. Researchers surveyed more than 400 children before the measure took effect and again three months later, finding “substantial circumvention” of the rules.

The government says more than five million accounts held by under-16s have been blocked, but Communications Minister Anika Wells said platforms were still falling short.

“Based on the regular updates I receive from the eSafety Commissioner, it is clear to me that social media platforms are adopting tricks straight out of the Big Tech playbook and doing the bare minimum to get by,” Wells said.

“Social media platforms are some of the richest and most powerful companies in the world, and we’re serious about holding them to account,” she added.

The new powers would allow the eSafety Commissioner to demand documents and evidence from platforms, age-checking companies and app stores.

Platforms must show they have taken “reasonable steps” to keep under-16s out. Some use artificial intelligence to estimate ages, while users can also verify their age with a government ID.

Source link

Securing Critical Infrastructure Against Early-Stage Ransomware: Proactive Steps for Prevention

Critical infrastructure, such as water utilities, energy grids, healthcare systems, manufacturing plants, education platforms, and transport networks, have become primary targets of ransomware groups. In late April and early May 2026, for instance, Shinyhunters, a hacking group, breached Instructure, an education platform used by K-12 schools and universities across the US, and claimed for ransom. In the report published on CNN, the hacker group said it had breached 275 million personal data and had access to billions of private messages, an action that has affected thousands of schools, causing learning disruptions. Cybercriminals target critical infrastructure because downtime means communities don’t get access to essential services. So, operators or service providers have no option but to pay ransom to restore services quickly. Security gaps also influence the growth of these attacks. Too often, organizations focus on recovery efforts and ransomware encryption instead of prevention. This post highlights ways to prevent ransomware at its early stages, including the use of zero trust architecture and AI.

Promote Cybersecurity Awareness

Ransomware incidents start with malicious malware being injected into tech infrastructure. It then encrypts data and systems, restricting organizations any access to their operations until a ransom is paid. For these attacks to be successful, however, threat actors rely on social engineering attacks like spoofing and phishing, which target employees. An attacker will send a phishing email, impersonating an executive or trusted source like a bank to trick the victim into sharing credentials. Today’s spam emails, especially those generated by AI, are flawless, meaning staff can easily open and click on malware links without suspecting any threat. So, it’s crucial that employees receive adequate training on how to spot and respond to phishing texts or emails and malicious links.

Workers should also know how to generate hard-to-hack passwords. Weak passwords or using the same password for multiple accounts creates an entry point for ransomware. Encourage the use of password phrases, which are a string of unrelated, random words, symbols and numbers. For example, a password like purplegiraffesingstomorrow@17 prevents brute-force logins because a hacker will have a hard time guessing. Alongside passphrases, emphasize the importance of multi-factor authentication, where staff use two or multiple authentication methods to gain permission to accounts. 

Enhance Threat Detection and Monitoring Systems

Detecting ransomware at its early stages helps prevent full encryption of sensitive data and infrastructure. And it entails identifying subtle behaviors of the threat, such as lateral movement across networks and devices, data exfiltration, and privilege escalation. Look out for unusual login or data access, increases in CPU usage, and abnormal network traffic to command-control servers. Modern attacks powered by AI and machine learning bypass legacy security systems by using legit utilities like PowerShell scripts and MimiKatz. So, check if there are attempts by script-based systems like PowerShell to inject suspicious code into running processes. Also, inspect if endpoints and firewalls are still running. Attackers often switch them off or configure settings without authorization to create a weak point for malware injection. 

Note: lateral movement and zero-day variants aren’t always easy to spot. You need to integrate multiple security tools to detect and mitigate attacks. Use endpoint detection and response tools to catch harmful scripts and abnormal file access before all your data is encrypted. Take advantage of AI-assisted behavioral analytics to learn data access patterns, set a baseline for normal user behavior, and send alerts when there’s unusual or irregular file access patterns to protect against infostealers. Since infostealers act as the initial access for attack vectors, stopping them eliminates the entire kill chain. You can also reinforce your security measures by working with a 24/7 AI-centric SOC. These security experts don’t just distinguish legitimate logins from malware injections. They isolate the host to stop further compromise.

Network Segmentation and Zero Trust Framework

The goal of these two security measures is to limit a hacker’s ability to infect an entire network. Segmenting your networks entails dividing your networks into smaller, isolated sub-networks that make it difficult for cybercriminals to navigate critical network infrastructure. In a situation where a device is compromised, segmentation locks the attack within the specific zone, ensuring it doesn’t access databases or other sub-networks. What does zero trust entail and how does it mitigate ransomware? This tactic works on one strict principle: ‘never trust, always verify’. It doesn’t matter if you’re an authorized user or the devices you’re using are inside the organization. With zero trust in place, every access request is authenticated continuously. Also, users are granted permission to data and tools based on their roles to minimize privilege. Even if an attacker stole credentials, they would be limited to access systems. When combined, zero trust architecture and network segmentation strengthen an organization’s cyber safety strategies.

Hackers know that when they infect essential infrastructure with ransomware, victims will act fast to settle the ransom required to get encryption keys. But service providers shouldn’t wait until an attack has occurred to secure infrastructures. Prevention is the most effective strategy, and it revolves around simple hacks like educating workers about common threats and using strong pass phrases alongside MFA. By detecting threats, implementing zero trust, and network segmentation, organizations can minimize ransomware-related risks.

Source link

Meta to take legal action against Israeli spyware company NSO | Cybersecurity News

WhatsApp disrupted phishing attempts linked to NSO, blacklisted by the US for security concerns.

Meta has said it is ⁠filing a federal US ⁠court contempt order against Israeli spyware firm NSO Group for violating a permanent injunction that barred it from ever ⁠targeting WhatsApp and its users.

The company said on Monday that its WhatsApp messaging service disrupted new spear phishing attempts linked to NSO, an ⁠entity blacklisted by the United States government for engaging in activities that are contrary to national security or foreign policy interests.

Recommended Stories

list of 3 itemsend of list

These attempts were similar to previous “1-click phishing campaigns”, aimed to trick users into clicking ‌malicious links and direct them to external websites, Meta said in a blogpost.

A “1-click” is a type of cyberattack where a single click on a malicious link or attachment is sufficient to compromise a victim’s device or account, without requiring them to enter their credentials.

Meta said WhatsApp took down test accounts ⁠and groups created by NSO on its platform. ⁠NSO did not immediately respond to a Reuters request for comment.

Last year, a US court ordered NSO to stop targeting Meta’s WhatsApp, a development the spyware ⁠company warned could put it out of business.

While the ruling significantly reduced the punitive damages NSO ⁠owed Meta to $4m from an ⁠initial $167m, the injunction itself was seen as a substantial challenge for the company, which faces ongoing accusations of enabling human rights abuses through its Pegasus hacking tool.

Meta ‌said on Monday that last month it was joined by 12 prominent civil rights organisations, a coalition of security researchers, privacy advocates ‌and ‌digital rights experts, who filed their amicus briefs to fight NSO’s appeal against the permanent injunction.

Source link

Trump signs an executive order to vet top AI models for national security risks

President Trump signed an executive order on artificial intelligence Tuesday, less than two weeks after postponing a White House ceremony over his concerns that a similar policy could dull America’s edge on AI technology.

The order establishes a framework for the federal government to vet the national security risks of the most advanced AI systems for up to a month before their public release. The government will be able to work with trusted partners “that will have early access to covered frontier models to promote secure innovation and strengthen the cybersecurity of critical infrastructure,” the order says.

It was not immediately clear to what extent the order differed from the one he declined to sign on May 21.

Trump canceled an Oval Office event with tech industry executives last month because he did not like what he saw in the earlier version of the order’s text. “We’re leading China, we’re leading everybody, and I don’t want to do anything that’s going to get in the way of that lead,” Trump told reporters at the time.

That directive was characterized as a voluntary collaboration with participating U.S.-based tech companies, including Anthropic, OpenAI and Google.

O’Brien writes for the Associated Press.

Source link