<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>SecureWorld News</title>
    <link>https://www.secureworld.io/industry-news</link>
    <description>SecureWorld News is your trusted source for the valuable cybersecurity information you depend on. Our coverage spans the InfoSec industry, with content ranging from breaking news and original articles to exclusive research and expert interviews.</description>
    <language>en-us</language>
    <pubDate>Thu, 16 Jul 2026 17:12:58 GMT</pubDate>
    <dc:date>2026-07-16T17:12:58Z</dc:date>
    <dc:language>en-us</dc:language>
    <item>
      <title>The CMMC Phase II Suspension: What It Means for Defense Contractors</title>
      <link>https://www.secureworld.io/industry-news/cmmc-phase-2-suspension-defense-contractors</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/cmmc-phase-2-suspension-defense-contractors" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Pentagon%20shutterstock_1210283029.jpg" alt="United States Pentagon building" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;The defense contracting world received a major shockwave on July 13, 2026, when the U.S. Department of War (DoW) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements. Originally scheduled to take effect on November 10, 2026, the sudden pause has left many enterprise leaders wondering: &lt;i&gt;Is CMMC dead, or has the clock just paused?&lt;/i&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;The defense contracting world received a major shockwave on July 13, 2026, when the U.S. Department of War (DoW) announced the immediate suspension of the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements. Originally scheduled to take effect on November 10, 2026, the sudden pause has left many enterprise leaders wondering: &lt;i&gt;Is CMMC dead, or has the clock just paused?&lt;/i&gt;&lt;/p&gt; 
&lt;p&gt;Here is a breakdown of what this suspension actually means, what the U.S. government is saying, and what organizations should be doing right now.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The DoW has halted the transition to Phase II of the CMMC rollout, alongside all subsequent implementation milestones (Phases III and IV).&lt;/p&gt; 
&lt;p&gt;To understand why this is a big deal, one must&amp;nbsp;look at the structural bottleneck that was looming. Phase II was set to mandate that any contractor handling Controlled Unclassified Information (CUI) obtain a third-party cybersecurity certification from an accredited Certified Third-Party Assessment Organization (C3PAO).&lt;/p&gt; 
&lt;p&gt;But, the reality of that requirement quickly crashed into logistical limits:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;The bottleneck: There are only about 100 authorized C3PAOs in existence, tasked with auditing more than 100,000 defense contractors.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The economic impact: Compliance costs were ballooning, and Small Business Administration (SBA) data confirmed that innovative small and medium-sized businesses were actively leaving the Defense Industrial Base (DIB) because they couldn't afford the compliance overhead.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: normal;"&gt;In response, the DoW established a CMMC Reform Task Force to conduct a comprehensive, 60-day review of the program.&lt;/p&gt; 
&lt;p&gt;During a press briefing, DoW Chief Information Officer Kirsten A. Davies was refreshingly candid about the operational reality of the rollout. Pointing to the massive imbalance between available auditors and companies needing certification, she noted, "The math just simply doesn't math."&lt;/p&gt; 
&lt;p&gt;Davies and other department officials made it clear that the suspension is designed to reduce the administrative "red tape" paralyzing the supply chain, rather than to lower the government's cybersecurity expectations.&lt;/p&gt; 
&lt;p&gt;Additionally, Under Secretary of War for Acquisition and Sustainment Michael Duffey emphasized that this pause aligns with broader acquisition reform goals to prioritize speed to capability and lower barriers for innovative commercial partners.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.linkedin.com/in/brianhaugli/"&gt;Brian Haugli&lt;/a&gt;, CEO of SideChannel, had this to say on LinkedIn:&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;"Watch what happens next. Thousands of defense contractors are about to reveal whether they were building security programs or buying certificates.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;If your entire cyber effort was aimed at passing a CMMC assessment, you just lost your reason to keep going. The budget gets pulled, the project stalls, and in 60 days you'll be scrambling to restart whenever the new requirements drop.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;If you built a program to actually manage risk, today changed nothing. 800-171 is still enforced. DFARS 7012 is still in your contracts. Adversaries targeting the DIB didn't read the press release and stand down.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;This is the problem with compliance-driven security. The requirement moves and the whole thing collapses, because it was never yours to begin with.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;Same advice I've given for years, and it holds up on days like this: build the program for the risk, let the certification fall out of it. Not the other way around.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;The contractors who did that are fine this morning. The ones who didn't are calling their consultants asking if they can get a refund."&lt;/span&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The changes do&amp;nbsp;not alter the underlying security rules/requirements.&lt;/p&gt; 
&lt;p&gt;It is incredibly important to separate the &lt;i&gt;certification process&lt;/i&gt; from the &lt;i&gt;security standard&lt;/i&gt;. While the third-party audit requirement (Phase II) is paused, the requirement to protect sensitive government data remains legally binding.&lt;/p&gt; 
&lt;p&gt;Here is what is active versus what is suspended:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;CMMC Element, Phase I (Self-Assessments): Active; You must still perform annual self-assessments, submit scores to the Supplier Performance Risk System (SPRS), and submit annual affirmations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Phase II (Third-Party Audits): Suspended; The November 10, 2026, deadline for mandatory C3PAO audits is on hold indefinitely.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;DFARS 252.204-7012: Active; This clause remains in your contracts. You are still contractually obligated to safeguard covered defense information.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;NIST SP 800-171 Rev 2: Active; This remains the active technical standard that you must implement and self-assess against.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;&lt;strong&gt;What should enterprises do right now?&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;If your business interacts with the defense supply chain, treating this pause as "time off" from cybersecurity is a dangerous mistake. Government-led spot audits are still active, and false self-attestations carry massive legal and financial risks under the False Claims Act.&lt;/p&gt; 
&lt;p&gt;Instead, adjust your strategy to focus on these four actions.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;1. Do NOT stop your NIST SP 800-171 implementation: Immediate Priority&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Because Phase I self-assessments are still active, you must continue remediating gaps in your system security plans (SSPs). The core technical controls (like access management, MFA, and incident response) are still mandatory.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;2. Keep your SPRS scores updated: Ongoing Maintenance&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Ensure your organization's self-assessment scores in the SPRS database are accurate and updated. Contracting officers will still verify your Phase I self-assessment status before awarding contracts.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;3. If an audit is in progress, finish it: Strategic Choice&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;If your organization was already preparing for or actively undergoing a C3PAO assessment, stopping now might cost you more than it saves. A strong security posture is still a massive competitive differentiator.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;4. Participate in the public RFI: Deadline is&amp;nbsp;August 14, 2026&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The DoW has opened a public Request for Information (RFI) to gather direct feedback on compliance costs and how companies are using commercial tools to meet these goals. Make your voice heard before the August 14 deadline.&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 115%;"&gt;CMMC is not dead; it is being rebuilt to be more practical. Expect the Reform Task Force to return in autumn 2026 with a updated framework that relies more heavily on self-attestation and existing commercial tools. In the meantime, focus on real cybersecurity hygiene rather than the bureaucratic paperwork.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fcmmc-phase-2-suspension-defense-contractors&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Original Content</category>
      <category>U.S. Government</category>
      <category>Compliance</category>
      <category>DoD / DoW</category>
      <category>CMMC</category>
      <category>Third-Party Security</category>
      <pubDate>Thu, 16 Jul 2026 17:12:58 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/cmmc-phase-2-suspension-defense-contractors</guid>
      <dc:date>2026-07-16T17:12:58Z</dc:date>
    </item>
    <item>
      <title>What AI Appreciation Day Actually Means for Enterprise Security</title>
      <link>https://www.secureworld.io/industry-news/ai-appreciation-day-enterprise-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/ai-appreciation-day-enterprise-security" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/AI%20-%20Enterprise%20-%20colleagues-in-data-center-review-computer-code-2026-01-08-02-30-31-utc-1.jpg" alt="coworkers in data center" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;On July 16, social media feeds will inevitably fill up with automated corporate posts celebrating Artificial Intelligence (AI) Appreciation Day. For the general public, it's a casual moment to marvel at image generators or chat assistants. For enterprise cybersecurity and tech leaders, however, it serves as an annual checkpoint to audit how the balance of power between defensive and offensive AI is shifting inside their infrastructure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On July 16, social media feeds will inevitably fill up with automated corporate posts celebrating Artificial Intelligence (AI) Appreciation Day. For the general public, it's a casual moment to marvel at image generators or chat assistants. For enterprise cybersecurity and tech leaders, however, it serves as an annual checkpoint to audit how the balance of power between defensive and offensive AI is shifting inside their infrastructure.&lt;/p&gt; 
&lt;p&gt;But where did this day come from, and why should security professionals treat it as more than just another commercial marketing event?&lt;/p&gt; 
&lt;p&gt;Unlike traditional technology milestones anchored to a specific scientific breakthrough, AI Appreciation Day has an unexpectedly eccentric history.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The day was initially established in May 2021 by a company called A.I. Heart LLC, founded by Jason Kirton, a freelance advertising professional and science fiction writer. Intended as a way to promote a creative project involving a helpful, sentient AI named "EVE," Kirton officially registered the holiday via the National Day Calendar platform.&lt;/p&gt; 
&lt;p&gt;The core motivation behind the declaration wasn't purely commercial hype; it was heavily inspired by early calls from tech figures like Elon Musk demanding stricter AI regulation. Kirton—who famously lived in a tent on a beach outside of SpaceX's Starbase in Texas for a year to try to discuss AI ethics with Musk—envisioned the day as a structured moment of collective attention. He wanted humanity to pause and ask critical questions about AI alignment, ethics, and safety before our deployment habits became entirely calcified.&lt;/p&gt; 
&lt;p&gt;By 2023, the day gained mainstream traction as the launch of ChatGPT thrust large language models (LLMs) into the corporate spotlight.&lt;/p&gt; 
&lt;p&gt;As the observance rolls around, the implications of rapid AI integration diverge sharply depending on who is using the interface.&lt;/p&gt; 
&lt;p style="color: #242424; background-color: #ffffff;"&gt;&lt;span&gt;"AI Appreciation Day&amp;nbsp;is an interesting concept, and while I respect the intent behind the day, I wonder if 'appreciation' is a bit premature," said &lt;a href="https://events.secureworld.io/speakers/kimberly-kj-haywood/"&gt;KJ Haywood&lt;/a&gt;, Founder, CEO at Nomad Cyber Concepts, and Adjunct Cybersecurity Professor, Collin College, in Texas. "&lt;/span&gt;&lt;span&gt;From my perspective, it should also serve as an annual reminder to evaluate an organization's AI security posture, governance maturity, and overall AI risk literacy. Organizations are presently adopting AI at an accelerated speed and still treating security and governance as something to address after deployment rather than as part of the process from the start. That gap creates unnecessary risk."&lt;/span&gt;&lt;/p&gt; 
&lt;p style="color: #242424; background-color: #ffffff;"&gt;&lt;span&gt;Haywood continued, "We're already seeing the impact through AI-enabled fraud, data exposure, and increasingly convincing social engineering attacks. At the same time, many organizations still believe AI governance is a policy, a framework, or the latest platform. It isn't. It's an ongoing business practice that helps organizations make better decisions, manage risk, and use AI responsibly."&lt;/span&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;For the general public: the UX revolution&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;To the average consumer, AI appreciation is defined by convenience and accessibility. AI has been quietly embedded into daily life through photo-editing algorithms, streaming recommendation engines, and natural-language search. It represents a shift where complex technical systems are now fully democratized, allowing anyone to code, create, or analyze data without needing a computer science degree.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;For enterprises: the trust and security imperative&lt;/strong&gt;&lt;/h3&gt; 
&lt;p style="font-weight: normal;"&gt;For the enterprise, the conversation has shifted entirely from model capability to trust infrastructure. Technology leaders aren't just appreciating what AI can build; they are managing the chaotic security footprint it leaves behind.&lt;/p&gt; 
&lt;p&gt;The enterprise reality of AI deployment is defined by three distinct challenges:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The shadow IT explosion:&lt;/span&gt; Recent enterprise research shows that the percentage of organizations unable to detect whether employees are using &lt;a href="https://www.secureworld.io/industry-news/shadow-ai-how-detect-control"&gt;unsanctioned AI tools &lt;/a&gt;has nearly tripled. This visibility blind spot expands even further when autonomous AI agents are introduced into enterprise networks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The over-privileged data problem:&lt;/span&gt; GenAI and agentic systems excel at scraping and indexing internal documents. If an enterprise has weak internal data access controls, an AI tool will quickly surface sensitive files—such as HR documents or proprietary code—to unauthorized employees who ask the right question.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The weaponization of social engineering:&lt;/span&gt; Defensive security teams are actively fighting AI-driven threats. Bad actors are using generative models to eliminate historical red flags like poor grammar, building highly convincing, localized phishing attacks that strike during &lt;a href="https://www.secureworld.io/industry-news/world-cup-social-engineering-catalyst"&gt;global high-interest events&lt;/a&gt;.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AI Appreciation Day shouldn't be celebrated by looking backward at a marketing calendar. Instead, security leaders should use July 16 as an internal audit mechanism.&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;"Perhaps AI Appreciation Day shouldn't only celebrate what AI can do, but highlight those organizations that are placed on a 'Most Likely to Succeed' listing: those that treat security, governance, and risk as strategic priorities rather than afterthoughts," Haywood said.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;Take the day to look beyond paper compliance policies. Cybersecurity professionals should evaluate active visibility into automated API calls; ensure data-centric permissions are tightly configured around internal vector databases; and implement technical guardrails capable of parsing autonomous agent behavior.&lt;/p&gt; 
&lt;p&gt;True appreciation for AI comes from understanding its power—and building the robust technical infrastructure required to keep it secure.&lt;/p&gt; 
&lt;p&gt;We asked several experts from cybersecurity solution providers for their take on the "holiday."&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/padmanabhan/"&gt;Ganesh Padmanabhan&lt;/a&gt;, CEO and Co-Founder of Autonomize AI, said:&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;"When people talk about appreciating &lt;/span&gt;&lt;span&gt;AI&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt;, they often focus on what the technology can do. I think we should appreciate it for something much more important: its ability to give people their time and expertise back. In healthcare, some of our most experienced clinicians spend huge portions of their &lt;/span&gt;&lt;span&gt;day&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt; navigating administrative processes instead of caring for patients. &lt;/span&gt;&lt;span&gt;AI&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt; gives us an opportunity to change that. Not by replacing clinical judgment, but by making that expertise available more quickly, more consistently, and at a far greater scale. If &lt;/span&gt;&lt;span&gt;AI&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt; allows a nurse to spend more time with patients instead of paperwork, or helps someone access treatment &lt;/span&gt;&lt;span&gt;day&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt;s or weeks sooner, that's something worth celebrating."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/rmgupta/"&gt;Rohit Gupta&lt;/a&gt;, CEO, Auditoria.AI, said:&lt;/span&gt;&lt;br&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;"The first generation of enterprise AI proved that machines could generate answers. The next generation has to prove they can generate business outcomes. Finance is where that transition is happening first because every recommendation must be explainable, every action must be governed, and every result must stand up to scrutiny. That's why AI Appreciation Day is no longer about celebrating possibility. It's about recognizing that AI is becoming operational infrastructure for the modern Office of the CFO."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold; background-color: #ffffff;"&gt;&lt;a&gt;Karl Bagci&lt;/a&gt;, Director of IT and Information Security, Exclaimer, said:&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold; background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt;"AI Appreciation Day is a good reminder that AI's greatest value isn't in replacing people. It's in removing repetitive work so people can focus on higher-value decisions. But AI is also exposing something many organizations have overlooked for years. Communication governance gaps that once affected a handful of messages can now be replicated at scale in seconds. AI hasn't created those problems. It's simply made them impossible to ignore. That's why organizations need to think about governance before they think about automation."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/paul-stokes-95b09b1/"&gt;Paul Stokes&lt;/a&gt;, Co-Founder and CEO, Prevalent AI, said:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"AI deserves appreciation, but not blind admiration. It is has already changed the pace of cyber risk. Attackers can move faster, test more ideas, and find exploits at a scale that security teams were not built for. This does not make AI bad, but it makes AI-enabled visibility and governance essential. Businesses need to understand where AI is being used, which models they depend on, and where those dependencies create exposure. Companies need to do the hard work of analyzing both their use of AI, and the data that drives it, or they run the risk of becoming its victim."&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;span style="background-color: #ffffff;"&gt;&lt;a href="https://www.linkedin.com/in/anoopdawar/"&gt;Anoop Dawar&lt;/a&gt;, Chief Strategy Officer of Deepgram, said:&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;"We've seen Salesforce acquire Fin, SpaceX pay $60 billion for Cursor, and OpenAI stand up a $10 billion deployment company—three very different bets on the same scarce thing: teams that can make AI agents work reliably in the real world, not just in a demo. That capability has quietly become the most valuable asset in software, because these are probabilistic systems that drift and have to be measured and monitored continuously to stay accurate. And it gets hardest in voice—real-time, unforgiving, no second take—which is exactly where the next phase of this race will be won."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;a&gt;&lt;/a&gt;&lt;a href="https://www.linkedin.com/in/donboxleyjr/"&gt;&lt;/a&gt;&lt;a href="https://www.linkedin.com/in/donboxleyjr/"&gt;Don Boxley&lt;/a&gt;, CEO and Co-Founder of DH2i, said:&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;"I really like the idea of AI Appreciation Day. Not because AI needs a birthday, but because it provides a moment to take a step back and appreciate the holistic picture of all the components that go into making these applications work and bring value to our everyday lives."&lt;/p&gt; 
&lt;p&gt;"Generally, when people talk about AI, they almost always jump straight to the models. They want to talk about GPUs, NVIDIA, training, inference—all the 'sexy' stuff. That's fine and good. But AI doesn't know anything by itself. All that information that makes it so useful needs to come from somewhere. And for many organizations today, that's databases like SQL Server. The reality is, if the database goes down, AI doesn't suddenly become intelligent enough to work around it. It just stops being useful. So, this year on AI Appreciation Day, let's remember that while it is critical to spend time thinking about how to make AI smarter, easier to use, and faster, we need to also remember that none of that matters if the data can't answer when AI calls."&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/ramvaradarajan/"&gt;Ram Varadarajan&lt;/a&gt;, CEO at Acalvio, said:&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"We're witnessing a significant shift in the cyber threat landscape, and it's more severe and unmatched than anything we've faced before. Multi-agent swarms are coordinating in real-time across reconnaissance, credential harvesting, and data exfiltration. We're facing exponential coordination where hundreds of specialized AI agents will operate simultaneously across our entire attack surface. Reactive defenses can't operate at machine speed, requiring a shift in the cybersecurity stack to preemptive, AI-driven strategies. AI fighting AI, paired with offensive deception technologies, is the emergent design to catch attackers off guard and cause them to make mistakes and disclose themselves. Organizations that adapt will recognize that defense is no longer about building higher walls. It's about becoming an unpredictable, moving target."&lt;/p&gt; 
&lt;p&gt;"Security teams can no longer rely on humans doing everything by hand. The model has to change to allow humans to direct AI-driven workflows, just as hackers do. It's fated to be a bot-on-bot duel forever. Teams should start small. Pick a few high-impact workflows where AI provides scale and speed, and humans supply judgment and oversight. Assume a machine-speed AI-augmented attacker or autonomous AI attack, and defend with machine-speed AI that leverages the adversarial AI's own vulnerabilities."&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/amit-zimerman/"&gt;Amit Zimerman&lt;/a&gt;, Co-Founder and Chief Product Officer at Oasis Security, said:&lt;/p&gt; 
&lt;p&gt;"While AI is highly efficient in automating and scaling tasks, human expertise is necessary to interpret complex results, make critical decisions, and apply context-specific reasoning. Humans are essential for ensuring that AI-driven tools are used responsibly and for validating the results of AI processes, especially when it comes to the nuances of certain vulnerabilities or threat landscapes. AI also plays a significant role in 'shift-left'&amp;nbsp;approaches by identifying security vulnerabilities earlier in the software development lifecycle. When integrated into offensive security measures, AI can detect and address issues before they make it into production, reducing the cost of remediation and improving the overall security posture of an organization."&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;span&gt;Don't miss the &lt;/span&gt;&lt;a href="https://events.secureworld.io/agenda/artificial-intelligence-2026/"&gt;SecureWorld Artificial Intelligence virtual conference&lt;/a&gt;&lt;span&gt; on Wednesday, July 22. Attendees will &lt;/span&gt;&lt;span style="line-height: 28px; background-color: #ffffff;"&gt;he&lt;/span&gt;&lt;span style="line-height: 28px; background-color: #ffffff;"&gt;ar from in&lt;/span&gt;&lt;span style="line-height: 28px; background-color: #ffffff;"&gt;dustry experts sharing practical insights on using AI effectively, navigating evolving security challenges, and preparing for what's next in an AI-driven world. Register to attend and earn 6 free CPE credits.&lt;/span&gt;&lt;span&gt; &lt;/span&gt;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fai-appreciation-day-enterprise-security&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Original Content</category>
      <category>Enterprise Security</category>
      <category>AI</category>
      <pubDate>Thu, 16 Jul 2026 12:38:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/ai-appreciation-day-enterprise-security</guid>
      <dc:date>2026-07-16T12:38:00Z</dc:date>
    </item>
    <item>
      <title>Why AI Is Actually Increasing the Cognitive Load on Cyber Teams</title>
      <link>https://www.secureworld.io/industry-news/ai-cognitive-load-cyber-teams-isc2</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/ai-cognitive-load-cyber-teams-isc2" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Ai%20Agent%20Problem%20-%20business-professionals-discussing-data-in-an-offic-2026-03-18-05-32-30-utc-1.jpg" alt="two business men in office setting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For months, the prevailing enterprise narrative around artificial intelligence in cybersecurity has been a promise of automated relief: AI will ingest the alerts, parse the logs, and magically give overstretched security teams their time back.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For months, the prevailing enterprise narrative around artificial intelligence in cybersecurity has been a promise of automated relief: AI will ingest the alerts, parse the logs, and magically give overstretched security teams their time back.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;But a newly-released research report from ISC2, "Rethinking AI's Impact on Cybersecurity Roles," shatters this simple efficiency myth. Based on a survey of 856 cybersecurity professionals actively working with AI, the data reveal&amp;nbsp;a starkly different operational reality: AI isn't necessarily shortening the workday—it is shifting the cognitive burden toward a high-stakes game of algorithmic verification.&lt;/p&gt; 
&lt;p&gt;As ISC2 CEO Scott Beale put it, "AI is not replacing cybersecurity professionals; it is changing what the profession requires of them." For enterprises and security vendors, this transformation completely changes how we must approach human oversight, team stress, and early-career talent pipelines.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;The validation tax: where the time really goes&lt;/strong&gt;&lt;/h2&gt; 
&lt;p style="font-weight: normal;"&gt;The most striking finding in the &lt;a href="https://www.isc2.org/Insights/2026/07/rethinking-ai-impact-on-cybersecurity-roles"&gt;ISC2 report&lt;/a&gt; is the emergence of what can be called a "validation tax." AI tools excel at compiling complex cybersecurity data at scale, but their outputs are far from infallible. In fact, an overwhelming 89% of respondents report having experienced AI recommendations that led to incorrect outcomes at their organizations.&lt;/p&gt; 
&lt;p&gt;Because the blast radius of an unverified, incorrect security action is so severe, practitioners are spending massive amounts of time auditing the machine:&lt;/p&gt; 
&lt;ul style="list-style-type: disc; font-size: 18px;"&gt; 
 &lt;li&gt; &lt;p style="font-weight: normal;"&gt;65% of professionals report spending more time deciding when to trust or act on AI-generated recommendations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p style="font-weight: normal;"&gt;63% report spending more time actively reviewing and validating AI outputs.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;This means the early time savings gained from automated triage are frequently burned on the back-end&amp;nbsp;during mandatory human verification.&lt;/p&gt; 
&lt;p&gt;This validation tax is also actively altering workplace stress. While 48% of respondents felt AI lowered their stress by handling repetitive work, nearly a third (32%) reported an &lt;i&gt;increase&lt;/i&gt; in workplace anxiety. Crucially, those experiencing higher stress were significantly more likely to be the ones drowning in validation tasks—spending their days second-guessing whether an AI recommendation was a brilliant shortcut or a hallucinated vulnerability.&lt;/p&gt; 
&lt;p&gt;For corporate executives, the report highlights an uncomfortable operational paradox regarding risk and ultimate ownership.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;When an AI model pushes a flawed security recommendation that leads to a catastrophic incident or an operational outage, who takes the fall? Fifty percent of organizations hold the human decision-maker ultimately accountable. Only 21% say it varies by severity, and nearly 18% admit there is structural ambiguity or zero clear ownership when things go sideways.&lt;/p&gt; 
&lt;p&gt;Who is accountable when an AI mistake causes a security failure?&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;Human decision-maker: 50%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Varies by severity: 21%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Ambiguity / no ownership: 18%&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;This creates a dangerous gap between human authority and accountability. If an enterprise expects its security analysts to carry the professional risk of an incident, those analysts must be given the explicit mandate, training, and operational buffer to slow down, challenge, and override AI assertions. Yet, the report notes that many practitioners are still pressured to act on AI security outputs without fully understanding the underlying logic.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;What this means across the ecosystem&lt;/strong&gt;&lt;/h3&gt; 
&lt;p style="font-weight: bold;"&gt;1. For enterprises: Re-evaluating the entry-level pipeline&lt;/p&gt; 
&lt;p&gt;A dominant concern in the industry has been that AI would eliminate the junior Tier-1 SOC analyst. The ISC2 data show&amp;nbsp;a complex evolutionary pressure: while 56% say AI has reduced the pure &lt;i&gt;need&lt;/i&gt; for legacy entry-level roles, 53% state that AI is actively &lt;i&gt;creating entirely new types&lt;/i&gt; of early-career positions.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Junior professionals aren't being forced out; their roles are being re-platformed. Instead of manually sifting through raw logs, entry-level workers are now tasked with supervising models and validating initial outputs. Because of this, 62% of professionals emphasize that AI has not reduced the need for foundational cybersecurity skills. Enterprises must maintain mentorship and continuous upskilling programs to ensure junior staff still develop the core structural knowledge needed to judge an AI's accuracy.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;2. For cybersecurity vendors: Feature velocity vs. trust metrics&lt;/p&gt; 
&lt;p&gt;Security product vendors can no longer win deals purely by pitching raw AI speed or automated execution. The market is becoming deeply cynical of unvalidated automation. To stand out, vendors must design interfaces focused on explainability, transparency, and auditable confidence scoring. If your tool does not show &lt;i&gt;how&lt;/i&gt; it reached a conclusion, or if it lacks seamless hooks for a human-in-the-loop override, it will be viewed as an operational risk rather than an asset.&lt;/p&gt; 
&lt;h4&gt;&lt;strong&gt;The tactical action plan for security leaders&lt;/strong&gt;&lt;/h4&gt; 
&lt;p&gt;To successfully navigate this shift toward AI-assisted security workflows, CISOs and IT executives must focus on trust frameworks rather than deployment velocity.&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Codify the guardrails:&lt;/span&gt; Establish clear, non-deterministic boundaries detailing exactly when an AI system is permitted to recommend an action, when it is allowed to autonomously execute, and when mandatory human sign-off is required.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Enforce subresource and ingestion governance: &lt;/span&gt;Approximately 80% of ISC2 respondents rated having clear governance frameworks and knowing when to override AI decisions as "very important." Operationalize this by auditing the telemetry and data sources your security LLMs ingest to minimize errors at the source.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Shift performance metrics:&lt;/span&gt; Stop measuring SOC performance purely by speed-to-resolution. If analysts are penalized for taking the time to thoroughly validate an AI path, they will inevitably let a scaled error slip through. Reward thorough validation and critical systems thinking.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AI is undeniably expanding the capability to monitor networks and model threats. But as the machine takes over the mechanics, the true differentiator for enterprise resilience remains the trained, skeptical human mind.&lt;/p&gt; 
&lt;p&gt;Don't miss the &lt;a href="https://events.secureworld.io/agenda/artificial-intelligence-2026/"&gt;SecureWorld Artificial Intelligence virtual conference&lt;/a&gt; on Wednesday, July 22. Attendees will &lt;span style="background-color: #ffffff;"&gt;he&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt;ar from in&lt;/span&gt;&lt;span style="background-color: #ffffff;"&gt;dustry experts sharing practical insights on using AI effectively, navigating evolving security challenges, and preparing for what's next in an AI-driven world. Register to attend and earn 6 free CPE credits.&lt;/span&gt;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fai-cognitive-load-cyber-teams-isc2&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Security Research</category>
      <category>Original Content</category>
      <category>Automation</category>
      <category>AI</category>
      <category>ISC2</category>
      <pubDate>Wed, 15 Jul 2026 11:25:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/ai-cognitive-load-cyber-teams-isc2</guid>
      <dc:date>2026-07-15T11:25:00Z</dc:date>
    </item>
    <item>
      <title>The DockSec Series, Part 2: Inside DockSec—Architecture and Pipeline</title>
      <link>https://www.secureworld.io/industry-news/docksec-series-part-2-architecture-pipeline</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/docksec-series-part-2-architecture-pipeline" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Vibe%20coding_developers_collaborating_code_devops_2026-01-09-00-42-39-utc.jpg" alt="developers reviewing code on screen" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;In &lt;a href="https://www.secureworld.io/industry-news/docksec-series-container-security-ai-layer"&gt;Part 1 of this series&lt;/a&gt;, we argued that container security fails at the last mile: detection is mature, but turning findings into fixes is not. This article opens the hood to show how DockSec closes that gap. Understanding the architecture is not academic—it explains why the tool behaves the way it does, where you can extend it, and why the same scan can produce a terminal summary, a JSON payload, a SARIF file, and a PDF report all from one run.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;In &lt;a href="https://www.secureworld.io/industry-news/docksec-series-container-security-ai-layer"&gt;Part 1 of this series&lt;/a&gt;, we argued that container security fails at the last mile: detection is mature, but turning findings into fixes is not. This article opens the hood to show how DockSec closes that gap. Understanding the architecture is not academic—it explains why the tool behaves the way it does, where you can extend it, and why the same scan can produce a terminal summary, a JSON payload, a SARIF file, and a PDF report all from one run.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;A four-stage pipeline&amp;nbsp;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;&lt;/span&gt;At the highest level, &lt;a href="https://github.com/OWASP/DockSec"&gt;DockSec&lt;/a&gt; runs a four-stage pipeline: scan, analyze, recommend, report. Trivy, Hadolint, and Docker Scout do the scanning locally. An LLM pass correlates and explains the findings. A scoring stage produces a 0-100 posture number.&lt;/p&gt; 
&lt;p&gt;A reporting stage emits the results in whatever formats you asked for. What makes this composable rather than a tangle is that every stage reads from and writes to a single shared data structure.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;The results dict: One contract to rule them all&amp;nbsp;&lt;/h3&gt; 
&lt;p&gt;&lt;span&gt;The most important design decision in &lt;a href="https://github.com/OWASP/DockSec"&gt;DockSec&lt;/a&gt; is also the least glamorous: there is exactly one results dictionary that flows through the whole system, and every component agrees on its shape.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The scanner produces this dict. It carries the Dockerfile lint results, the image scan results, and—the key field—&amp;lt;json_data&amp;gt;, a list of normalized vulnerability records. Each record has a stable shape regardless of which scanner produced it: a vulnerability ID, the target, the package name and installed version, a severity, a title and description, a status, a CVSS score, and a reference URL. Trivy findings are filtered into this shape; Docker Compose misconfiguration findings reuse the exact same shape with an added remediation field.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Because everything downstream consumes this one contract, the scoring calculator, the report generators, the SARIF writer, and the &amp;lt;--json&amp;gt; output do not need to know anything about Trivy's or Hadolint's native formats. They read &amp;lt;json_data&amp;gt; and the AI findings and do their job. Add a new scanner tomorrow and, as long as it emits records in this shape, the entire reporting and scoring stack works unchanged. This is why the codebase can support five output formats without five times the complexity.&lt;/span&gt;&lt;a href="https://github.com/OWASP/DockSec"&gt;&lt;br&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The scanning layer&lt;/h4&gt; 
&lt;p&gt;DockerSecurityScanner is the workhorse. It wraps three tools, each with a distinct job:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Trivy&lt;/span&gt; enumerates known CVEs in the image’s OS and language packages. It is the primary source of vulnerability findings and honors the severity filter you pass.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Hadolint&lt;/span&gt; lints the Dockerfile itself against a large rule set—use COPY instead of ADD, pin package versions, avoid running as root, and so on. These are the best-practice findings.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Docker Scout&lt;/span&gt; provides an image-versus-base-image comparison and suggests updated base images, which is often the single highest-leverage fix.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;span style="color: #000000;"&gt;The scanner also owns a results cache keyed on the image name and the requested severity, so repeated scans of the same image at the same severity are fast, while a scan at a different severity correctly triggers a fresh run rather than serving stale data.&lt;/span&gt;
&lt;br&gt; 
&lt;h5 style="font-weight: normal;"&gt;The AI layer&lt;/h5&gt; 
&lt;p&gt;When an API key and provider are configured, the CLI runs an AI pass. It loads the Dockerfile, truncates it to a token-sensible size, and feeds it to the configured model through a structured-output chain. "Structured output" is the important phrase: the model is not asked for free-form prose. It is asked to populate a defined schema with fields for vulnerabilities, best practices, security risks, exposed credentials, and remediation steps. The result is predictable, parseable, and mergeable back into the results dict as &amp;lt;ai_findings&amp;gt;.&lt;/p&gt; 
&lt;p&gt;Provider handling is abstracted behind a single &amp;lt;get_llm()&amp;gt; factory. OpenAI uses JSON mode for structured output; Anthropic, Google, and Ollama use tool-calling, which LangChain selects automatically. Sensible model defaults are applied per provider, and newer Claude and Gemini models that no longer accept a temperature parameter are handled transparently. From the user’s perspective, switching providers is one flag; the complexity is contained in one function.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;The scoring layer&lt;/h6&gt; 
&lt;p&gt;&lt;span&gt;&lt;/span&gt;DockSec produces a single 0-100 security score, and there are two paths to it.&lt;/p&gt; 
&lt;p&gt;When an LLM is available, the model can produce a holistic score from a summary of the findings. When it is not—in &amp;lt;--scan-only&amp;gt; mode, or with &amp;lt;--skip-ai-scoring&amp;gt;—a local, deterministic calculator takes over. The local score is a weighted blend of three axes: the Dockerfile quality (from lint results), the vulnerability burden (a severity-weighted deduction over &amp;lt;json_data&amp;gt;), and a configuration score derived by reading the Dockerfile directly and deducting for concrete misconfigurations: running as root, credential-looking &amp;lt;ENV&amp;gt; variables, unpinned base images, missing health checks, sensitive exposed ports, &amp;lt;ADD&amp;gt; over &amp;lt;COPY&amp;gt;, and privileged flags.&lt;/p&gt; 
&lt;p&gt;The local calculator is deliberately transparent and tunable, and it has been hardened based on real testing. Hardcoded credentials, for example, now cap the overall score regardless of how the rest of the blend comes out— because shipping a plaintext secret in an image is not a middling problem to be averaged away. Part 5 returns to scoring in depth.&lt;/p&gt; 
&lt;div style="font-weight: normal;"&gt;
 &lt;strong&gt;The reporting layer&lt;/strong&gt;
&lt;/div&gt; 
&lt;p&gt;A single ReportGenerator is the canonical writer for JSON, CSV, PDF, and HTML. It runs silently and returns the paths it wrote; the CLI then renders one clean summary rather than interleaving progress bars with scan output. HTML uses a template with placeholder substitution. PDF routes all text through a sanitizer so that bullets, smart quotes, em dashes, and emoji in vulnerability titles never crash generation. SARIF is written by the same generator but is opt-in and independent of the &amp;lt;--format&amp;gt; bundle, because it targets CI and code-scanning rather than human reading.&lt;/p&gt; 
&lt;p&gt;The reason all of these can coexist is, again, the shared results dict. Each writer is a pure function from that dict to a file.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;&lt;strong&gt;How the CLI ties it together&lt;/strong&gt;&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;&amp;lt;cli.py&amp;gt; is the orchestrator. It parses arguments, resolves the provider and severity once, decides the mode—full analysis, AI-only, scan-only, image-only, or compose—and sets three booleans: run AI, run scan, run compose. From there it invokes the AI pass and the scan pass, merges their outputs into the one results dict, computes the score, generates the requested reports, and renders the summary. Exit codes are honest: a clean run exits 0, a triggered gate exits 1, a usage error exits 2, and a tool or runtime failure—including a failed AI pass—exits 3, so a broken pipeline never masquerades as a passing one.&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;div style="font-weight: normal;"&gt;
 &lt;strong&gt;How the CLI ties it together&lt;/strong&gt;
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;Three practical consequences fall out of this design:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Extensibility:&lt;/span&gt; Because of the single results contract, adding a scanner or an output format is a local change, not a rewrite.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Honesty:&lt;/span&gt; The separation of scan, score, and report means the score reflects real findings and the exit code reflects real outcomes.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Control:&lt;/span&gt; The provider abstraction and the scan-only path mean you decide where your data goes and whether an external model is involved at all.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="font-weight: normal;"&gt;With the architecture clear, Part 3 gets hands-on: We will scan a deliberately vulnerable Dockerfile, an image, and a Compose stack, and read the output line by line.&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;This is the second in a five-part series. Watch for coming installments on Tuesdays.&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fdocksec-series-part-2-architecture-pipeline&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Vulnerabilities</category>
      <category>Featured Author</category>
      <category>DevOps</category>
      <pubDate>Tue, 14 Jul 2026 12:22:01 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/docksec-series-part-2-architecture-pipeline</guid>
      <dc:date>2026-07-14T12:22:01Z</dc:date>
      <dc:creator>Advait Patel</dc:creator>
    </item>
    <item>
      <title>SMBs and AI: Governance and Security Split Leaders from the 'Stuck Middle'</title>
      <link>https://www.secureworld.io/industry-news/smb-ai-governance-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/smb-ai-governance-security" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Small%20Business%20-%20caucasian-woman-typing-on-a-laptop-inside-her-wood-2025-10-19-16-21-51-utc%20(1).jpg" alt="small business employee working on laptop" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The debate over whether small and medium-sized businesses (SMBs) will adopt artificial intelligence is officially over. According to Pax8's newly-released Q2 2026 SMB AI Pulse Report, based on a survey of more than 400 U.S. small business leaders, adoption has surged past the experimental hype phase and into a critical operational reality.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The debate over whether small and medium-sized businesses (SMBs) will adopt artificial intelligence is officially over. According to Pax8's newly-released Q2 2026 SMB AI Pulse Report, based on a survey of more than 400 U.S. small business leaders, adoption has surged past the experimental hype phase and into a critical operational reality.&lt;/p&gt; 
&lt;p&gt;Ninety 90% of SMBs are now somewhere on the AI adoption curve, with 61% actively using AI tools in daily operations and 29% experimenting.&lt;/p&gt; 
&lt;p&gt;For cybersecurity professionals, managed service providers (MSPs), and vCISOs (virtual Chief Information Security Officers), &lt;a href="https://www.pax8nebula.com/asset/fe4dadef-4c18-437a-b5d4-1c430feddb4f/Pax8-Pulse-Report-2026-Q2.pdf"&gt;the report&lt;/a&gt; exposes a massive operational paradox: while SMBs are aggressively deploying AI across their entire business fabrics to secure a competitive edge, their governance and security frameworks are completely lagging behind. This widening gap represents an unprecedented concentration of risk.&lt;/p&gt; 
&lt;p&gt;"As organizations of all sizes deploy increasingly autonomous and agentic AI tools to drive mission outcomes, we must ensure those systems are resilient against manipulation, compromise, and misuse," said Marcus Fowler, CEO of Darktrace Federal. "AI will increasingly be tasked with defending other AI systems, creating a new frontier for cybersecurity. Finally, no cybersecurity executive actions or strategy can succeed without addressing the talent challenge. The demand for skilled cyber professionals continues to outpace supply."&lt;/p&gt; 
&lt;p&gt;Fowler added, "AI should be viewed as a force multiplier for the workforce—augmenting human defenders, accelerating investigations, and allowing teams to focus on the highest-value mission tasks."&lt;/p&gt; 
&lt;p&gt;The data prove&amp;nbsp;that SMBs using AI are rapidly pulling away from non-users, creating a stark divergence in market confidence and technology spending.&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The equalizer effect:&lt;/span&gt; 71% of AI users report that the technology allows small businesses to effectively compete with enterprise-level firms.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The multiplier gap:&lt;/span&gt; SMBs leveraging AI report nearly three times the competitive advantage of those that are not. Furthermore, AI users are more than twice as likely to have scaled up their overall technology budgets over the past year (53% vs. 24%).&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The collapse of the undecided:&lt;/span&gt; The segment of SMBs stating they are "interested but haven't started" collapsed from 9% to a microscopic 1.5% in a single quarter.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: normal;"&gt;The undecided didn't disappear; they moved straight into active testing. However, a significant portion of them have hit an immediate wall, creating what the report terms "the stuck middle." Nearly one in three SMBs (29%) are trapped in this experimentation phase, paralyzed by a lack of internal expertise (22%), cost/unclear ROI (21%), and prominent security or privacy concerns (23%).&lt;/p&gt; 
&lt;p&gt;What makes this an urgent security story is how deeply AI has already been woven into core business functions. SMB leaders are taking a highly-pragmatic approach, utilizing AI across a broad spectrum of enterprise pipelines.&lt;/p&gt; 
&lt;p&gt;Here are SMB AI use cases by adoption rate percentage:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;Data Analysis &amp;amp; Business Intelligence: 52%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Customer Service &amp;amp; Support: 50%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Marketing &amp;amp; Sales: 50%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Operations &amp;amp; Logistics: 45%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Content Creation: 42%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Finance &amp;amp; Accounting: 37%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Human Resources (HR): 33%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Cybersecurity: 27%&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;"This isn't simply an SMB problem; we see common themes in large and small clients. The industry needs a fundamental reprioritization on security fundamentals," said Jeff Liford, Associate Director at Fenix24. "This isn't a failure because we lack the tools; it’s a failure to prioritize and resource the correct work efforts. Some environments are legitimately under-resourced, but others are resourced incorrectly."&lt;/p&gt; 
&lt;p&gt;Liford continued, "The rapid rise of AI-assisted tooling will dramatically accelerate threat actors' ability to compromise poorly-architected networks. Environments already struggling with fundamentals will face even faster and more automated exploitation chains. Recovery-based resilience desperately needs to move to the forefront of security planning."&lt;/p&gt; 
&lt;p&gt;While this cross-functional leverage provides immense operational scale, the guardrails are virtually non-existent. Only 23% of SMBs possess a documented AI use policy. The remaining majority operate entirely on informal, ad-hoc guidelines (28%) or verbal manager oversight.&lt;/p&gt; 
&lt;p&gt;SMB AI Policy Gap (2026 Data), by percentage:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;Documented AI policy: 23%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Informal guidelines only: 28%&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;No policy / in progress: 49%&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;When an organization runs proprietary client data, financial accounting, and HR workflows through external AI models without a formal policy, they are actively exposing themselves to severe corporate risk. Data leakage, shadow AI tools, and unvetted third-party LLM integrations are quietly introducing vulnerabilities across these lean organizations.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/smb-ai-paradox-agility-vulnerability"&gt;The SMB AI Paradox: Why Agility, Vulnerability Collide on Main Street&lt;/a&gt;]&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;What actually rallies the leaders?&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The survey results clearly indicate&amp;nbsp;that the primary differentiator between AI market leaders and laggards is not budget. It comes down to leadership alignment and operational governance.&lt;/p&gt; 
&lt;p&gt;An overwhelming 91% of active AI users report that corporate leadership is completely aligned on the exact role AI plays in the business. That number drops to 68% among experimenters, and plummets to a dismal 32% for non-users.&lt;/p&gt; 
&lt;p&gt;Security teams and their external technology partners have a significant window of opportunity here. SMB founders and owners—who drive AI decisions in 42% of firms—are explicitly calling out for help. They are acutely aware of the risks, noting operational concerns like exposed customer data and employee misuse of unapproved tools.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;The tactical action plan for security advisors&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;For cybersecurity professionals and MSPs, your client conversations must pivot away from standard tool implementation and focus heavily on building trust infrastructure.&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Enforce dynamic AI discovery:&lt;/span&gt; Don't wait for employees to declare what tools they are using. Deploy endpoint and network monitoring capabilities to map out the "shadow AI" footprint inside the environment.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Productize AI governance packages: &lt;/span&gt;Treat the governance gap as a service opportunity. Help SMB leaders transition from loose, informal guidelines to formalized, enforceable, and auditable AI acceptable-use policies.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Establish human-in-the-loop safeguards:&lt;/span&gt; Align with the 68% of successful AI users who demand high standards of human oversight. Build workflows where AI-generated content, automated data analysis, and script outputs require mandatory peer or manager review before execution.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="line-height: 115%;"&gt;The AI advantage belongs to small businesses, but without a foundation of robust cybersecurity and strict governance, that advantage can turn into a critical compromise overnight.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 115%;"&gt;"AI is accelerating the speed, scale, and accessibility of exploit development for attackers. Tasks that once required highly specialized expertise can now be performed faster, more cheaply, and by a much broader range of threat actors," said Diana Kelley, CISO at Noma Security. "When adversaries operationalize vulnerability discovery and exploit development at machine speed, it fundamentally changes the economics of cyber offense."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 115%;"&gt;Kelley added, "Organizations of all sizes need to become much more risk-driven, focusing on attack surface reduction, asset visibility, identity controls, segmentation, and compensating controls for exposures that cannot be remediated immediately. The industry should expect AI-assisted vulnerability research and exploit development to become increasingly common, which means resilience, visibility, and operational readiness matter more than ever."&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fsmb-ai-governance-security&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>GRC</category>
      <category>Original Content</category>
      <category>AI</category>
      <category>SMBs</category>
      <pubDate>Mon, 13 Jul 2026 22:35:52 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/smb-ai-governance-security</guid>
      <dc:date>2026-07-13T22:35:52Z</dc:date>
    </item>
    <item>
      <title>How the 2026 World Cup Became the Ultimate Social Engineering Catalyst</title>
      <link>https://www.secureworld.io/industry-news/world-cup-social-engineering-catalyst</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/world-cup-social-engineering-catalyst" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/World%20Cup%20-%20soccer-ball-decorated-with-flags-on-the-field-2026-03-20-00-59-38-utc.jpg" alt="soccer ball with international flags" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Cybercriminals excel at tracking the calendar. When a massive global event dominates public attention, it simultaneously alters user psychology—creating a perfect storm for social engineering.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Cybercriminals excel at tracking the calendar. When a massive global event dominates public attention, it simultaneously alters user psychology—creating a perfect storm for social engineering.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;A trio of new threat intelligence reports from Hoxhunt, Zimperium, and Darktrace highlights this reality. Data from Hoxhunt reveal a massive 500% surge in FIFA World Cup-themed phishing attacks from April to June 2026, with the sharpest spike aligning precisely with the tournament's kickoff.&lt;/p&gt; 
&lt;p&gt;According to &lt;a href="https://hoxhunt.com/blog/world-cup-2026-phishing-attacks-surge-500"&gt;Hoxhunt data&lt;/a&gt;, the 2026 World Cup has officially become the most-spoofed entertainment or sporting event ever recorded. What makes this anomaly particularly dangerous for security teams isn't just the sheer volume; it is the emergence of AI-polished, highly-localized, temporal phishing attacks designed to slide past traditional user defenses.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;The psychology of temporal phishing&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;A "temporal phishing attack" is a campaign engineered to exploit a specific window of time when employees are actively expecting unusual or out-of-band communications.&lt;/p&gt; 
&lt;p&gt;During tax season, users might expect emails regarding payroll, compliance, or financial filings. During the World Cup, the script flips: employees are pre-conditioned to receive notifications about promotional giveaways, corporate ticket packages, hospitality travel, or sudden marketing campaigns. Because unusual communication is anticipated, cognitive friction drops&amp;nbsp;and emotional defenses lower.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The real-world risk is clear. Hoxhunt phishing simulation data demonstrate that temporal lures are 42% more likely to draw a click than standard, non-temporal simulations.&lt;/p&gt; 
&lt;p&gt;Threat activity began building quietly as early as February, but volume accelerated drastically from May onward. Hoxhunt analysts noted that these globally distributed threats focused primarily on two highly-effective pretexts.&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Fake marketing recruitment:&lt;/span&gt; Threat actors targeted marketing, communications, and PR professionals with deceptive "recruiting" offers or contractor bundles tied to tournament events, tricking high-privileged corporate users into opening malicious attachments or credential-harvesting links.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Brand impersonation schemes:&lt;/span&gt; Attackers heavily spoofed official global sponsors, explicitly deploying fake prize, travel, and ticket-bundle scams impersonating Coca-Cola's World Cup promotions.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;By leveraging generative AI, threat actors are polishing these lures to eliminate historical red flags like broken grammar, while tailoring the localization to match specific regions. The impact is truly global, with reported threats distributed evenly across enterprises worldwide—outpacing the campaign volumes observed during the Paris 2024 Olympics or Eurovision 2026 by orders of magnitude.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;Expanding the attack surface: mobile and stadium operations&lt;/strong&gt;&lt;/h3&gt; 
&lt;p style="font-weight: normal;"&gt;The corporate inbox isn't the only entry point. &lt;a href="https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat"&gt;Parallel threat research from Zimperium zLabs&lt;/a&gt; revealed a sharp surge in mobile-targeted phishing campaigns capitalizing on the tournament. Attackers recognize that fans and corporate employees frequently check match updates, manage digital tickets, or track betting pools on their mobile devices—environments where security controls are often less restrictive than a hardened desktop browser.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;At the same time, the broader sports ecosystem itself is under immense pressure. &lt;a href="https://www.darktrace.com/blog/cybersecurity-for-the-sports-sector-the-threats-facing-a-digitized-industry-in-2026"&gt;A sports sector threat report from Darktrace&lt;/a&gt; reveals that 57% of professional sports organizations experienced multiple cyber incidents over the last 12 months.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Darktrace data indicate&amp;nbsp;that sports sector clients receive nearly 20% more phishing emails than companies in other industries. As high-stakes areas like stadium operations, fan engagement apps, ticketing databases, and backend business operations adopt more integrated systems, the attack surface expands. Looking ahead, 72% of security professionals surveyed by Darktrace believe AI will further increase cyber risk over the next year as attackers weaponize automated tools to scale these operations.&lt;/p&gt; 
&lt;h4&gt;&lt;strong&gt;Defensive takeaways for security leaders&lt;/strong&gt;&lt;/h4&gt; 
&lt;p&gt;With nearly half of the global workforce distracted or actively engaged by a major international tournament, enterprise security teams must adapt their defenses to handle temporal spikes:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Deploy contextual phishing training:&lt;/span&gt; Standard, generic phishing simulations fail to mimic the high-conversion nature of temporal events. Security education teams should immediately deploy event-specific simulations (such as ticket giveaways or sponsor marketing promotions) to keep users on high alert during the tournament window.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Enforce strict mobile defenses:&lt;/span&gt; Given Zimperium's tracking of mobile-first campaigns, Mobile Threat Defense (MTD) solutions should be prioritized to intercept smishing (SMS phishing) and malicious mobile apps targeting employee devices.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Verify out-of-band requests:&lt;/span&gt; Internal departments—particularly marketing, HR, and procurement—should establish strict verification protocols for any third-party contracts, promotional partnerships, or recruitment onboarding tied to the event.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;When an entire planet is watching a tournament, attackers are watching the fans. Security teams must ensure that their organization's defenses account for the powerful psychological pull of the world's biggest game.&lt;/p&gt; 
&lt;p&gt;We asked some experts from cybersecurity solution providers for their thoughts.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/mpaalto/"&gt;Mika Aalto&lt;/a&gt;, Co-Founder and CEO at Hoxhunt, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"AI has ushered in the era of calendar-based social engineering. Just as legitimate marketing teams use automation platforms to launch personalized campaigns around major cultural events and seasonal buying patterns, cybercriminals are using AI to orchestrate phishing campaigns around the moments that matter most to their targets. The World Cup, tax season, annual bonus announcements, open enrollment, Black Friday—every event that drives legitimate communication now creates an opportunity for attackers to blend in.&amp;nbsp;The organizations that adapt their training as quickly as attackers adapt their lures will stay ahead."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/rexbooth/"&gt;Rex Booth&lt;/a&gt;, CISO at SailPoint, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The danger of many phishing schemes, like those during the 2026 FIFA World Cup, lies in their ability to grant attackers access to credentials, enabling them to pretend to be trusted insiders. With AI now in play, these campaigns are becoming ever more sophisticated and difficult to spot. This makes it imperative for users to adopt robust identity security best practices, including changing passwords frequently and enabling multi-factor authentication, and for organizations to prioritize identity as the new control plane."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"We've been waiting for this offensive disruption from AI for a while now. Attacks at scale and superhuman speed are the most obvious first step. Fortunately, many campaigns still require human intervention to execute. The more frightening scenario is when adversary AI starts running rampant through your enterprise without the need for action by the victim."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"High-profile events, such as the World Cup, tend to attract attackers looking to make a statement. The objective of making a large impact sometimes means using different tactics than, say, corporate espionage where you want to go unnoticed both on the way in and out. Organizers and defenders need to be on the lookout for threats that are oriented for maximal exposure and disruption rather than stealth and targeted objectives."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/randolphbarr/"&gt;Randolph Barr&lt;/a&gt;, CISO at Cequence Security, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The greatest risks to large sporting events don't come from new exploits. Instead, they originate from people misusing legitimate apps, identities, and corporate processes. Phishing, impersonation, and automated misuse are becoming more prevalent techniques for attackers to gain access that seems legitimate, especially when thousands of employees, partners, and vendors are working together on systems they don't know well and have tight deadlines. When there are large events, access levels are often elevated for a short period, apps and APIs are used to their fullest, and security teams are focused on keeping systems available than protected. This makes it tougher to spot slight abuse."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"When attackers gain access, they typically don't use malware or other dangerous behaviors to wreak damage; instead, they use trusted access. This involves taking over an account, abusing sessions and tokens, scraping automatically, perpetrating fraud, and staying in the environment for a long time. These things usually become part of everyday business and can go on for weeks or months without triggering standard security procedures that are supposed to stop intrusions, not misuse."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/anne-cutler-31282253/"&gt;Anne Cutler&lt;/a&gt;, Cybersecurity Evangelist at Keeper Security, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The World Cup creates one of the most dangerous cyberattack windows on the planet. Billions of people, across dozens of time zones, all emotionally invested—and all searching, clicking, and transacting online, at the same time. That creates an unbelievable operational window for criminal networks. Fraudulent websites mimicking official FIFA ticketing and merchandise platforms have been built to harvest credit card details and personal information before victims realize something is wrong."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"AI is what makes this cycle more dangerous. Phishing emails that are grammatically perfect, contextually accurate, and personalized with your name and your team can be written by an AI tool in seconds. A text message from a friend or family member urgently asking for money for tickets may not be who you think."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Whether you're a fan or an IT leader, the playbook is the same: go directly to official sites, use strong and unique passwords on every account, and enable MFA everywhere possible. Don't conduct any transactions involving personal or financial information over public Wi-Fi. Cybercriminals are counting on the chaos of a tournament like this to catch people off guard. Don't give them the opening."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fworld-cup-social-engineering-catalyst&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Social Engineering</category>
      <category>Original Content</category>
      <category>Phishing</category>
      <category>World Cup 2026</category>
      <pubDate>Fri, 10 Jul 2026 14:10:03 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/world-cup-social-engineering-catalyst</guid>
      <dc:date>2026-07-10T14:10:03Z</dc:date>
    </item>
    <item>
      <title>The DockSec Series, Part 1: Why Container Security Needs an AI Layer</title>
      <link>https://www.secureworld.io/industry-news/docksec-series-container-security-ai-layer</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/docksec-series-container-security-ai-layer" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Vibe%20coding_developers_collaborating_code_devops_2026-01-09-00-42-39-utc.jpg" alt="developers reviewing code on screen" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2 style="font-weight: normal;"&gt;The problem hiding in plain sight&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;Containers won because they made shipping software boring. A &lt;/span&gt;&lt;span&gt;Dockerfile, a base image, a &lt;/span&gt;&lt;span&gt;docker build, and your application runs the same on a laptop as it does in production. But that convenience quietly moved a large part of the security surface into an artifact most teams treat as configuration rather than code.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;h2 style="font-weight: normal;"&gt;The problem hiding in plain sight&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;Containers won because they made shipping software boring. A &lt;/span&gt;&lt;span&gt;Dockerfile, a base image, a &lt;/span&gt;&lt;span&gt;docker build, and your application runs the same on a laptop as it does in production. But that convenience quietly moved a large part of the security surface into an artifact most teams treat as configuration rather than code.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;A single &amp;lt;&lt;/span&gt;&lt;span&gt;FROM python:3.9&amp;gt; line pulls in an entire operating system: hundreds of system packages, transitive libraries, and whatever CVEs happened to be present the day the image was published. Layer on a few &amp;lt;&lt;/span&gt;&lt;span&gt;RUN apt-get install&amp;gt; commands, a hardcoded credential in an &lt;/span&gt;&lt;span&gt;ENV, and a base image that was never pinned, and a routine build can inherit thousands of known vulnerabilities before your own code is even copied in. Scan a common base image today and it is not unusual to see hundreds of critical and high-severity findings.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The tooling to detect this is mature. Scanners like Trivy enumerate CVEs in packages, Hadolint lints Dockerfiles against best practices, and Docker Scout compares your image against its base and suggests upgrades. These are excellent tools. The problem is not detection. The problem is what happens after detection.&lt;/span&gt;&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;The wall of red&lt;/h3&gt; 
&lt;p&gt;&lt;span&gt;&lt;/span&gt;Anyone who has run a container scan in a CI pipeline knows the experience: a wall of red, 200-plus findings, each with a CVE identifier, a severity label, and a terse description written for a vulnerability database rather than a developer. The output answers "what is wrong"&amp;nbsp;but almost never answers the three questions a developer actually has:&lt;/p&gt; 
&lt;ol style="list-style-type: decimal;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Which of these actually matter for &lt;i&gt;my&lt;/i&gt; container, given how it is built and run?&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;What, specifically, do I change in &lt;i&gt;my&lt;/i&gt; Dockerfile to fix it?&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;If I can only fix five things today, which five move the needle most?&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;&lt;span&gt;Faced with an undifferentiated list, teams do one of two things. They ignore it, because triaging 200 findings by hand is not a sprint task. Or they bolt on a suppression file and move on. Neither improves security. The detection was never the bottleneck; the translation from findings to action was.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;This is the gap &lt;/span&gt;&lt;a href="https://github.com/OWASP/DockSec"&gt;&lt;span&gt;DockSec&lt;/span&gt;&lt;/a&gt;&lt;span&gt; was built to close.&lt;/span&gt;&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;What is DockSec?&lt;/h4&gt; 
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;a href="https://github.com/OWASP/DockSec"&gt;DockSec is an OWASP Lab Project&lt;/a&gt;: an AI-powered Docker security scanner that explains vulnerabilities in plain English and, crucially, tells you how to fix them in the context of your specific Dockerfile. It does not reinvent detection. It wraps the industry-standard scanners you already trust—Trivy, Hadolint, and Docker Scout—and adds a reasoning layer on top that prioritizes, explains, and remediates what they find.&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The distinction matters. Trivy will tell you that &amp;lt;&lt;/span&gt;&lt;span&gt;openssl&amp;gt; in your image has a critical CVE. DockSec will tell you that, and that your base image is unpinned, and that you are running as root, and that you have an API key hardcoded on line 3—and then it will hand you a corrected Dockerfile with a pinned slim base image, a non-root &lt;/span&gt;&lt;span&gt;USER directive, and the secret moved to a runtime injection pattern. It turns a scanner's report into a code review.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Think of it as pairing the recall of automated scanners with the judgment of a security engineer sitting next to you, reviewing the Dockerfile in real time.&lt;/span&gt;&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;Why an AI layer, and why now?&lt;/h5&gt; 
&lt;p&gt;&lt;span&gt;&lt;/span&gt;Skepticism about "AI-powered"&amp;nbsp;anything is healthy, so it is worth being precise about what the language model actually does here, because it is narrow and grounded.&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The LLM does not invent vulnerabilities. Every CVE DockSec reports comes from Trivy or Docker Scout; every lint finding comes from Hadolint. The model's job is to correlate those grounded findings with the actual content of your Dockerfile and produce three things the raw scanners cannot: a prioritized narrative of what matters most, a plain-English explanation of &lt;i&gt;why&lt;/i&gt; each issue is dangerous in your context, and specific, line-level remediation you can paste back into your file. It is the reasoning and translation layer, not the source of truth.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;This matters because the alternative—a human doing this correlation across three tools and a Dockerfile for every service, on every build—does not scale. Security teams are outnumbered by developers by an order of magnitude. The only way contextual remediation reaches every Dockerfile is to automate the reasoning, not just the detection.&lt;/span&gt;&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;The design principles that fall out of this&lt;/h6&gt; 
&lt;p&gt;&lt;span&gt;&lt;/span&gt;Once you accept that the value is in contextual remediation, several design choices follow naturally, and they shape everything in the rest of this series.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Bring your own model&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Contextual analysis should not require shipping your proprietary Dockerfiles and image contents to a vendor's cloud. DockSec supports OpenAI, Anthropic Claude, and Google Gemini for teams that want hosted models, and Ollama for teams that need everything to stay on their own hardware. A regulated or air-gapped team can run the full pipeline—scanning and AI remediation—without a single byte leaving their network.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Detection without AI is always available&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The AI layer is additive, not mandatory. A &amp;lt;&lt;/span&gt;&lt;span&gt;--scan-only&amp;gt; mode runs the full scanner stack with local, rule-based scoring and no API key at all. You get the wall of findings and a security score; you simply do not get the plain-English narrative. This keeps DockSec useful in the strictest environments and in fast CI paths where you only want a gate.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Open source and vendor-neutral&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;As an OWASP project under the MIT license, DockSec has no commercial tier that withholds features, no telemetry, and no lock-in. The comparison that matters is not against Trivy—which DockSec builds on—but against the commercial platforms that offer AI remediation only by hosting your data on their infrastructure. DockSec offers the same class of remediation while keeping you in control of both your data and your choice of model.&lt;/span&gt;&lt;/p&gt; 
&lt;div style="font-weight: normal; font-size: 24px;"&gt;
 Where this series goes
&lt;/div&gt; 
&lt;p&gt;&lt;span&gt;&lt;/span&gt;&lt;span&gt;This first article made the case for &lt;i&gt;why&lt;/i&gt; a reasoning layer on top of mature scanners is the missing piece in container security. The rest of the series gets concrete.&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;Part 2 opens the hood:&lt;/span&gt; The architecture, how the three scanners and the LLM pass fit together, and how a single results contract flows through scoring and reporting&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Part 3 is hands-on:&lt;/span&gt; Scanning a Dockerfile, an image, and a full Docker Compose stack, with real commands and output&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Part 4 covers automation:&lt;/span&gt; Gating builds with severity thresholds and exit codes, SARIF for GitHub code scanning, and baseline "ratchet" mode for adopting gates on existing projects&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Part 5 steps back to adoption:&lt;/span&gt; The security scoring model, the metrics worth tracking, and how an OWASP-governed tool fits into a broader program&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span&gt;Container security does not fail for lack of scanners. It fails at the last mile, where a list of findings has to become a change someone actually makes. That last mile is the whole point of DockSec.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;This is the first in a five-part series. Watch for coming installments on Tuesdays.&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fdocksec-series-container-security-ai-layer&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Vulnerabilities</category>
      <category>Featured Author</category>
      <category>DevOps</category>
      <pubDate>Tue, 07 Jul 2026 18:36:30 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/docksec-series-container-security-ai-layer</guid>
      <dc:date>2026-07-07T18:36:30Z</dc:date>
      <dc:creator>Advait Patel</dc:creator>
    </item>
    <item>
      <title>Three Seconds of Audio Is Enough: How Detection Must Now Stop AI Fraud</title>
      <link>https://www.secureworld.io/industry-news/three-seconds-audio-stop-ai-fraud</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/three-seconds-audio-stop-ai-fraud" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Vulnerability%20-%20Hacked%20-%20Ransomware%20-%20Attack%20-%20shutterstock_2572994613.jpg" alt="man on phone call at desk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The voice on the phone told an Ontario grandmother that her grandson had been arrested and needed bail money fast. It was his voice, down to the cadence, and it was a clone, &lt;a href="https://www.cbc.ca/news/marketplace/marketplace-ai-voice-scam-1.7486437"&gt;stitched by artificial intelligence&lt;/a&gt; from a few seconds of audio scraped off the internet.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The voice on the phone told an Ontario grandmother that her grandson had been arrested and needed bail money fast. It was his voice, down to the cadence, and it was a clone, &lt;a href="https://www.cbc.ca/news/marketplace/marketplace-ai-voice-scam-1.7486437"&gt;stitched by artificial intelligence&lt;/a&gt; from a few seconds of audio scraped off the internet.&lt;/p&gt; 
&lt;p&gt;She nearly sent the money. Swap the grandson for a son still living overseas, or for an officer who claims to be from the Canada Revenue Agency (CRA), and the same trick lands on someone four months into a new country who has no way to know what the real call is supposed to sound like.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;From hand-crafted to mass-produced&lt;/h2&gt; 
&lt;p&gt;A SecureWorld &lt;a href="https://www.secureworld.io/industry-news/newcomers-canada-fraud-victims"&gt;article earlier this year&lt;/a&gt; traced why Canadian fraud-prevention infrastructure keeps missing newcomers and named three vectors that land hardest on them: authority impersonation, settlement-workflow scams, and long-rapport investment fraud. Each of those used to require a human on the other end, working one mark at a time. A follow-up argued the gap was an engineering problem for banks to build their way out of. The newer development is who is doing the engineering, and it is no longer only the defense.&lt;/p&gt; 
&lt;p&gt;The economics of the attack collapsed. Cloning a voice convincingly once took a studio; now it takes three seconds of recorded speech, which is why the U.S. Federal Trade Commission warned that scammers are using AI to &lt;a href="https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes"&gt;sharpen family-emergency schemes&lt;/a&gt;. Reported AI voice-scam activity &lt;a href="https://www.foxnews.com/tech/ai-voice-scams-clone-familys-voice"&gt;climbed 1,210 percent&lt;/a&gt; over the past year by one count. The script did not change; the unit cost of running it a thousand times did.&lt;/p&gt; 
&lt;p&gt;That is the shift worth tracking. AI did not invent a fourth fraud vector. It industrialized the first three, and an industrialized attack finds the softest segment first.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Why the newcomer cohort absorbs the hit first&lt;/h3&gt; 
&lt;p&gt;A 20-year resident has heard a real CRA call, or knows someone who has, and can feel when the cadence is wrong. A person in month four has no such baseline. The reference points that let a long-time resident dismiss a fake are exactly the ones still being assembled in the early months of settling into a new country.&lt;/p&gt; 
&lt;p&gt;The agencies themselves see this. Immigration, Refugees and Citizenship Canada (IRCC) now warns that some scammers use AI to &lt;a href="https://www.canada.ca/en/immigration-refugees-citizenship/services/protect-fraud/newcomers.html"&gt;generate fake content&lt;/a&gt; that appears to come from the department, including messages with fake interview links demanding immediate action. The CRA, for its part, publishes a standing reminder on how to &lt;a href="https://www.canada.ca/en/revenue-agency/corporate/scams-fraud/verify-cra-contact.html"&gt;verify a real call&lt;/a&gt;, because the impersonation of its officers is constant and the agency knows newcomers are among the least equipped to tell the difference.&lt;/p&gt; 
&lt;p&gt;The exposure attached to the voice channel is not abstract. The segment most at risk is the one that has not yet learned what each institution sounds like, which is precisely the cohort an AI clone targets when it impersonates a relative or an official. An attacker who can spin up a fake son, a fake immigration officer, and a fake bank fraud-line in the same afternoon does not need a high hit rate; the cohort supplies the volume.&lt;/p&gt; 
&lt;p&gt;Authority impersonation works because it borrows real procedure. A newcomer often does owe the CRA a filing, does have an open file with IRCC, and does expect their bank to call about a flagged transaction. The fraudster does not have to invent a pretext; the legitimate institution has already supplied one. AI removes the last tell that used to give the script away—the stilted accent or the off-key phrasing—and replaces it with a clone trained on the exact voice the victim is primed to trust. The result is a call that matches a real obligation, in a real-sounding voice, arriving at a moment when the customer has the least context to doubt it.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The detection problem moved&lt;/h4&gt; 
&lt;p&gt;Here is where most onboarding stacks break. A four-month-old account already strains document-and-selfie verification, because the customer is new to every system at once. Feed a deepfake into that same flow and the check fails in a way the old playbook never anticipated.&lt;/p&gt; 
&lt;p&gt;Fraudsters now defeat identity verification not by forging a better document but by &lt;a href="https://www.secureworld.io/industry-news/ai-deepfakes-fueling-synthetic-identity-fraud"&gt;injecting a synthetic human&lt;/a&gt;. iProov logged a &lt;a href="https://www.iproov.com/reports/threat-intelligence-report-2025-remote-identity-attack"&gt;2,665 percent surge&lt;/a&gt; in native virtual-camera attacks and a 300 percent rise in face-swap attempts, where an AI-generated face is piped through legitimate camera software to fool a liveness check. The same research found that only 0.1 percent of people could reliably spot a deepfake on their own, which is the entire case against leaving the call to human judgment. Veriff reported that deepfakes now drive &lt;a href="https://www.veriff.com/identity-verification/news/real-time-deepfake-fraud-in-2025-fighting-back-against-ai-driven-scams"&gt;one in 20 identity-verification failures&lt;/a&gt;. Sumsub's annual data shows the "complex multi-step" attack category—the kind that chains a deepfake with stolen data—&lt;a href="https://www.prnewswire.com/news-releases/sumsubs-annual-report-fraud-shifts-to-complex-multi-step-schemes-in-2025-agentic-ai-scams-poised-to-surge-in-2026-302625287.html"&gt;jumped 180 percent&lt;/a&gt; year over year as simpler tactics stopped working.&lt;/p&gt; 
&lt;p&gt;The cost of getting this wrong is specific. A deepfake that clears onboarding does not produce one fraudulent transaction; it produces a fully verified account that passed every gate, then drains for months before anyone flags it. The question the stack now has to answer is no longer "is this document real?" It is "is this a live human, present right now, and the person they claim to be?"&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Liveness and injection detection as the baseline&lt;/p&gt; 
&lt;p&gt;Two failure modes hide inside that question. A presentation attack holds a photo or replays a video to the camera; an injection attack skips the camera entirely and feeds synthetic video straight into the verification pipeline. Sumsub recorded a &lt;a href="https://www.biometricupdate.com/202506/sumsub-reveals-300-increase-in-identity-document-fraud"&gt;300 percent rise&lt;/a&gt; in identity-document fraud as those techniques matured, and injection is the harder of the two to catch because nothing physical is ever presented.&lt;/p&gt; 
&lt;p&gt;The metric a fraud operations team can pull today is the deepfake-and-injection catch rate on the first-90-day cohort, measured separately from the general population. Run it as its own line. A newcomer segment that quietly underperforms the general detection rate is the blind spot, sized in basis points.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Provenance for the voice channel&lt;/p&gt; 
&lt;p&gt;The voice channel needs its own answer, because voiceprint authentication is now a liability rather than a control. A system that trusts a matching voiceprint will trust a good clone. The defense is out-of-band: a callback to a number the institution already holds, or verification through a channel the caller did not choose. The CRA's own guidance points the same direction, telling people to hang up and call back on a published line rather than trust the voice in front of them.&lt;/p&gt; 
&lt;p&gt;For a newcomer cohort, that control has to exist in a language the customer actually speaks, or it does not exist at all. A verification step that only works in English or French excludes the very segment it is meant to protect.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;Scaling defense against scaled attacks&lt;/h5&gt; 
&lt;p&gt;The attacker's marginal cost is near zero. A defense built analyst-by-analyst cannot match a defense that has to clear a thousand synthetic faces an hour, which is the structural reason AI-driven fraud has outpaced single-institution response. SecureWorld's reporting on &lt;a href="https://www.secureworld.io/industry-news/ai-driven-fraud-financial-crime"&gt;AI-driven financial crime&lt;/a&gt; frames the same arithmetic: tools that scale the attack force the defense to scale or surrender ground.&lt;/p&gt; 
&lt;p&gt;The prior installment's argument for shared intelligence carries straight into the AI era, with one twist. It is not enough to share a confirmed synthetic identity after the fact. The signal worth propagating at machine speed is the typology itself: a cloned-voice script targeting a specific diaspora, a face-swap pattern hitting one onboarding flow, a fake-IRCC template circulating this week. A typology that surfaces in one institution on Monday should not take until Friday to reach the other five seeing the same campaign.&lt;/p&gt; 
&lt;p&gt;The latency is where the loss lives. A campaign that runs four days unshared is a campaign that clears four days of onboarding before the second institution recognizes the pattern, and AI lets the same template hit every institution in the country inside that window. The technical posture has to match the threat: automated liveness and injection checks at the point of verification, voiceprint demoted from proof to a single weak signal, and a typology feed that updates in hours rather than at the speed of a quarterly fraud trends report. None of that is exotic. The detection tools exist; what most programs lack is the instruction to point them at the newcomer cohort as a named segment with its own scorecard.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;Three numbers to measure before the next quarter&lt;/h6&gt; 
&lt;p&gt;A program is only as honest as the metrics it will commit to in writing. Three map cleanly onto the AI vector.&lt;/p&gt; 
&lt;p&gt;First, the deepfake-and-injection catch rate inside the first-90-day cohort, held against the general-population rate. Second, the share of high-risk authority-impersonation reports that reached an out-of-band verification step before money moved, broken out by the customer's preferred language. Third, the median latency from the first sighting of a synthetic-voice or synthetic-video typology to a cohort-wide alert across the institutions that share signal. None of the three requires a vendor to define it.&lt;/p&gt; 
&lt;p&gt;The clone costs three seconds of audio and a few dollars. The callback that defeats it costs a few minutes. That asymmetry—attacker-cheap against defender-cheap—is the entire program brief, and the team that measures the gap is the one that closes it.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fthree-seconds-audio-stop-ai-fraud&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Cyber Fraud</category>
      <category>Featured Author</category>
      <category>Deepfake</category>
      <pubDate>Mon, 06 Jul 2026 20:11:23 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/three-seconds-audio-stop-ai-fraud</guid>
      <dc:date>2026-07-06T20:11:23Z</dc:date>
      <dc:creator>Pierre Raymond</dc:creator>
    </item>
    <item>
      <title>Prompt Data Is the New Shadow Data Layer</title>
      <link>https://www.secureworld.io/industry-news/prompt-data-new-shadow-data-layer</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/prompt-data-new-shadow-data-layer" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/serious-man-young-business-analyst-developer_o-2025-03-18-20-54-17-utc.jpg" alt="man working on laptop" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The &lt;a href="https://www.secureworld.io/industry-news/data-loss-prevention-next-gen-dlp"&gt;DLP alert&lt;/a&gt; your proxy catches is usually a clear outbound event: a file uploaded to an unsanctioned app or a spreadsheet emailed outside the company. What it may miss is the paragraph of legal language an associate pasted into an AI tool to clean up the wording. That is a data transfer too. It just does not look like the kind of transfer most controls were built to catch.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The &lt;a href="https://www.secureworld.io/industry-news/data-loss-prevention-next-gen-dlp"&gt;DLP alert&lt;/a&gt; your proxy catches is usually a clear outbound event: a file uploaded to an unsanctioned app or a spreadsheet emailed outside the company. What it may miss is the paragraph of legal language an associate pasted into an AI tool to clean up the wording. That is a data transfer too. It just does not look like the kind of transfer most controls were built to catch.&lt;/p&gt;  
&lt;p&gt;Prompt data has become a shadow data channel operating within sanctioned workflows, on corporate devices, and often via approved network paths, which is exactly why traditional DLP and &lt;a href="https://www.youtube.com/watch?v=T-C_rmqYbv8"&gt;CASB&lt;/a&gt; rules may miss it.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;A &lt;a href="https://go.layerxsecurity.com/hubfs/LayerX_Enterprise_GenAI_Security_Report_2025.pdf"&gt;2025 LayerX Security report&lt;/a&gt; found that approximately 18% of users paste data into GenAI tools, and about half of that pasted content is company information. For many security teams, most of this activity remains outside practical prompt level visibility. In practice, it only takes a few careless or untrained users to create a serious data exposure problem for the entire company.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Prompt data should therefore be treated as a governed data channel, rather than left as a blind spot within otherwise approved workflows.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;Start with a tier map&lt;/h2&gt; 
&lt;p&gt;Before classification frameworks or DLP rules, the security team needs an accurate picture of which AI tools are actually in use and which data-handling regime each employee operates under. That map has three distinct tiers, and conflating them produces policies that either miss real risk or block legitimate work.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Approved enterprise AI&lt;/p&gt; 
&lt;p&gt;Approved enterprise AI is a tool with a signed data processing agreement, contractual guarantees against training on customer inputs, &lt;a href="https://www.secureworld.io/industry-news/soc2-reports-what-really-matters"&gt;SOC 2 Type II&lt;/a&gt; coverage, and administrative controls that the organization can actually configure. ChatGPT Enterprise with zero data retention enabled, Microsoft Copilot bound to an M365 tenant, and Google Workspace AI under an enterprise agreement all qualify. Data entered into these tools stays under the organization's contractual control. This does not mean every use is automatically safe. It means the company has a place to configure controls, assign ownership, and define which data can be used.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Unmanaged SaaS AI&lt;/p&gt; 
&lt;p&gt;Unmanaged SaaS AI includes tools that employees use before security, legal, or IT has reviewed them. This may include niche coding tools, browser research tools, design tools, note-taking tools, and, actually, any existing SaaS platform that quietly adds AI features after purchase.&lt;/p&gt; 
&lt;p&gt;This is where visibility breaks down. A tool may look harmless, but still allow file uploads, prompt history, third-party processing, or access to workspace data. The risk is not limited to what employees type into the prompt box. Many AI tools are still applications, and they can collect data through app permissions, integrations, uploaded files, browser access, connected workspaces, and usage telemetry. Security teams should review unmanaged AI tools as software with data access, not only as chat interfaces.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Personal AI accounts&lt;/p&gt; 
&lt;p&gt;This is the employee using a personal AI subscription on a corporate device or using a free AI tool with a personal email address. The employer has no contractual relationship with the vendor governing that account, no visibility into conversation history, and no ability to enforce data retention settings. The underlying tool may be identical to the enterprise version, but the data handling is completely different.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Locally-hosted AI&lt;/p&gt; 
&lt;p&gt;A fourth tier is emerging: locally hosted AI tools running on an employee’s machine or other on-premises hardware. These reduce the vendor data-handling problem because prompts may stay inside the local environment. They introduce a different set of considerations: model storage on the &lt;a href="https://techatlantix.com/blog/post/ssd-buying-guide"&gt;device SSD&lt;/a&gt;, endpoint performance, access control, and what happens to conversation data when a device is reassigned or decommissioned.&lt;/p&gt; 
&lt;p&gt;Detecting which tier employees are actually in requires proxy or CASB visibility with session-level context—not just knowing that traffic is going to openai.com, but whether it is authenticated against a corporate workspace or a personal account.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Classify the data, not only the tool&lt;/h3&gt; 
&lt;p&gt;A prompt governance model should classify the content employees enter into AI systems. Instructions like “do not share confidential data” are too vague for real work, where everything can feel confidential and nothing feels clearly classified. The policy needs to name the data types and, where possible, show concrete examples of risky use. At the same time, the model should be simple enough for employees to understand and precise enough for DLP, proxy rules, vendor review, and &lt;a href="https://cloudsecurityalliance.org/blog/2023/09/13/maximizing-effectiveness-with-incident-response-platforms"&gt;incident response&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;Credentials and secrets have no legitimate reason to appear in any external AI tool. This includes API keys, OAuth tokens, session cookies, or private keys. A developer debugging a build failure does not need to paste the .env file. They need to paste the error. Replacing secrets with placeholders before asking for help is the prompt hygiene practice with the highest ROI.&lt;/p&gt; 
&lt;p&gt;Source code carries different risks depending on what it reveals. A small generic function is different from a proprietary fraud model, a trading algorithm, or an unreleased feature. Risk may increase further when code includes internal design comments or private endpoints.&lt;/p&gt; 
&lt;p&gt;Customer and employee data should be treated as sensitive prompt content even when a single prompt looks harmless. Emails, health details, payroll numbers, and account histories all apply. Partial details can still identify a person. Rewriting a customer response with AI can be valid, but it should happen in an approved tool with matching data handling terms, not a personal account.&lt;/p&gt; 
&lt;p&gt;Legal, financial, and board material is high risk because it is writing-heavy. Employees paste parts of contracts, acquisition plans, audit findings, and pricing strategy into AI tools because AI is useful for dense editing work. The policy should clearly state that summarizing a sensitive document with AI still constitutes sharing that document with the tool.&lt;/p&gt; 
&lt;p&gt;Security incident data needs separate handling. Logs, &lt;a href="https://www.secureworld.io/industry-news/zionsiphon-ot-warfare"&gt;malware samples&lt;/a&gt;, endpoint telemetry, vulnerability details, and incident timelines can expose infrastructure weaknesses. Security teams can use AI, but the workflow should be in place before the incident.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;Map prompt risk&lt;/h4&gt; 
&lt;p&gt;Once risky data types are defined, employees still need a decision model they can use during real work. The simplest model is to classify prompt content by where it is allowed to go.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Restricted data&lt;/span&gt; should not enter external AI systems unless the organization has approved a specific controlled environment and accepted the risk. This includes credentials, secrets, payment card data, highly sensitive personal information, material from active litigation, pending transaction details, unreleased financial results, and source code containing secrets or critical business logic. The issue is immediacy: exposure can create legal, security, or business harm before the company has any practical way to recover.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Sensitive data&lt;/span&gt; may be used in approved enterprise AI when retention controls, access controls, and logging match the use case. It should stay out of unmanaged SaaS AI and personal accounts. This tier covers confidential business communications, customer context, internal architecture, unreleased product plans, operational reports, HR material, and private code without secrets. The risk is often competitive, contractual, reputational, or operational.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Internal data&lt;/span&gt; can be used in approved enterprise AI and sometimes in unmanaged tools when identifiers and strategic details are removed. Draft policies, sanitized meeting summaries, generic training material, and general code examples may fit here.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Public data&lt;/span&gt; should remain low-friction. Employees need freedom to use AI for public research, documentation, learning, and generic writing tasks, or the policy will be ignored.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;Build the policy around the approved path&lt;/h5&gt; 
&lt;p&gt;The most common failure mode in AI governance is a policy that tells employees what they cannot do but gives them no workable alternative. A blanket ban often pushes the same behavior onto personal devices or personal accounts, where the organization has even less visibility.&lt;/p&gt; 
&lt;p&gt;A useful policy answers the question employees actually have: “How can I do this safely?” Code assistance may require an enterprise coding assistant or a review tool with repository controls. Document drafting may require an enterprise AI workspace with clear classification rules. Public research can stay lower-friction as long as employees do not upload files or paste internal content.&lt;/p&gt; 
&lt;p&gt;The policy should also explain which account type to use, what content to remove first, what to do after an accidental paste, and how to request a new AI tool or use case. Good prompt governance reduces unsafe work by making safe work easier.&lt;/p&gt; 
&lt;div style="font-size: 24px;"&gt;
 Detection: several different signal sources
&lt;/div&gt; 
&lt;p&gt;Classification only works if something enforces it. In practice, many employees will not check a policy before pasting text into an AI tool. They are rushing to finish a ticket or to summarize a meeting. Automated detection has to assume speed, pressure, and mistakes.&lt;/p&gt; 
&lt;p&gt;The first signal source is browser and session visibility. Many AI tools run through ordinary browser workflows, so security teams should use browser security platforms, &lt;a href="https://www.microsoft.com/en-us/security/business/security-101/what-is-secure-web-gateway-swg"&gt;secure web gateways&lt;/a&gt;, proxy/DNS logs, and CASB data to understand actual use. The goal is not only to see traffic to an AI domain. Security teams need session context. That context determines whether the same prompt is acceptable or risky.&lt;/p&gt; 
&lt;p&gt;The second source is browser-based DLP. A managed browser profile or extension can inspect clipboard content at the moment of paste, before data leaves the endpoint. This is useful when TLS inspection is incomplete or when the risk happens inside an encrypted browser session.&lt;/p&gt; 
&lt;p&gt;The third source is proxy and CASB inspection. When TLS inspection is properly configured, these controls can apply content rules to AI requests and enforce tier-level routing. For example, they can allow enterprise AI tenants, warn on unmanaged tools, block consumer accounts, or stop risky file uploads to unapproved services.&lt;/p&gt; 
&lt;p&gt;The fourth source is endpoint and developer tool visibility. Browser controls do not cover IDE extensions, terminal tools, local agents, or plugins that can read files directly. These tools should be reviewed like any developer tool with access to repositories, configuration files, and environment data.&lt;/p&gt; 
&lt;p&gt;The fifth source is behavioral logging. Logs do not block risky prompts in real time, but they reveal adoption patterns, unusual upload behavior, personal account use, and the introduction of new AI tools into the environment.&lt;/p&gt; 
&lt;p&gt;Detection should therefore work as a layered system. Browser controls catch risky paste events early. DLP flags likely sensitive content. Proxy and CASB controls enforce approved paths. Endpoint and developer telemetry cover AI tools outside the browser. Logs show patterns that single alerts miss. Together, these signals turn prompt governance from a policy document into an operating control.&lt;/p&gt; 
&lt;div style="font-size: 24px;"&gt;
 Connect prompt governance to existing security programs
&lt;/div&gt; 
&lt;p&gt;Prompt data governance should not become a separate security island. It should extend the security programs the company already runs.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.secureworld.io/industry-news/security-awareness-boring-training-ineffective"&gt;Security awareness training&lt;/a&gt; should use job-specific examples. Engineers need to see how a build log can expose a token. Legal teams need to understand why rewriting a contract in a personal AI account still constitutes external processing. The task may be legitimate. The risk often lies in the data included.&lt;/p&gt; 
&lt;p&gt;Incident response should also cover prompt leaks. The playbook should establish what was shared, which tool and account were used, whether deletion is possible, whether secrets need rotation, and whether legal or privacy review is required. The goal is fast damage reduction.&lt;/p&gt; 
&lt;p&gt;Vendor review should treat AI tools like SaaS tools with extra questions. Security and legal teams need to know whether prompts are used for training, how long data is retained, whether deletion is possible, which subprocessors are involved, and how enterprise account terms differ from consumer terms.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;AI governance should keep an inventory of approved tools, business owners, allowed use cases, exceptions, and reassessment dates. The governance group should not approve every prompt. It should define when a review is needed and what evidence teams must provide before sensitive data can be used.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;Conclusion: what good looks like after 90 days&lt;/h6&gt; 
&lt;p&gt;A realistic prompt governance program should reduce the largest blind spots first. In the first 30 days, identify AI tools in use, separate enterprise tools from unmanaged and personal accounts, and publish a short policy for restricted data and approved alternatives.&lt;/p&gt; 
&lt;p&gt;By day 60, tune browser, proxy, and DLP controls for high-confidence risks such as secrets, regulated data, sensitive source code, and uploads to unmanaged tools. Add a simple intake path for new use cases.&lt;/p&gt; 
&lt;p&gt;By day 90, connect the program to vendor review, AI governance, training, and incident response. Track adoption, risky prompts, unmanaged use, exceptions, and incidents.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fprompt-data-new-shadow-data-layer&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Data Security</category>
      <category>Featured Author</category>
      <category>Encryption / DLP</category>
      <category>Shadow AI</category>
      <pubDate>Thu, 02 Jul 2026 13:43:02 GMT</pubDate>
      <author>office@alexvakulov.com (Alex Vakulov)</author>
      <guid>https://www.secureworld.io/industry-news/prompt-data-new-shadow-data-layer</guid>
      <dc:date>2026-07-02T13:43:02Z</dc:date>
    </item>
    <item>
      <title>Alert: China's GLM-5.2 Just Matched Mythos on Bug-Finding</title>
      <link>https://www.secureworld.io/industry-news/china-glm-5.2-mythos-vulnerability-detection</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/china-glm-5.2-mythos-vulnerability-detection" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/China_shutterstock_1803687988.jpg" alt="China flag waving in the sky" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;A Beijing-based AI lab just demonstrated something the U.S. export control regime was specifically designed to prevent: a Chinese model that performs on par with one of America's most restricted AI systems at finding software vulnerabilities. And it did so by giving the model away for free.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A Beijing-based AI lab just demonstrated something the U.S. export control regime was specifically designed to prevent: a Chinese model that performs on par with one of America's most restricted AI systems at finding software vulnerabilities. And it did so by giving the model away for free.&lt;/p&gt; 
&lt;p&gt;On June 13, Zhipu AI (operating under the brand Z.ai) released GLM-5.2, an open-weight, 744-billion-parameter model under a permissive MIT license. Within days, independent benchmarking from Semgrep and reporting from &lt;em&gt;The Wall Street Journal&lt;/em&gt; converged on the same headline: in targeted vulnerability-detection tasks, GLM-5.2 performs roughly in the same range as Anthropic's Claude Mythos—the model Anthropic has kept deliberately locked behind a vetted-partner program because of how effective it is at the same job.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/anthropic-claude-mythos-finds-exploits-zero-days"&gt;Anthropic's Claude Mythos Autonomously Discovers, Exploits Zero-Days&lt;/a&gt;]&lt;/p&gt; 
&lt;p&gt;For security teams, the benchmark numbers are interesting. The governance story underneath them is the part that should actually change how one thinks about AI and risk planning for the next 12 months.&lt;/p&gt; 
&lt;p&gt;The comparison that's circulating centers on IDOR (Insecure Direct Object Reference) vulnerability detection. Independent testing by Semgrep put GLM-5.2's F1 score at roughly 39%, ahead of Claude Code's 32–37% on the same evaluation set. Zhipu has also claimed broader parity with Mythos across other bug-finding benchmarks, and GLM-5.2 has separately ranked among the most-used models on OpenRouter and second worldwide on a closely-watched coding benchmark—strong enough that Zhipu's market value reportedly crossed $128 billion shortly after.&lt;/p&gt; 
&lt;p&gt;It's worth being precise about what this is and isn't. GLM-5.2 still trails Anthropic and OpenAI's frontier systems on broad, general-purpose reasoning. This is a case of a competitor closing the gap hard on one specific, high-stakes capability—automated vulnerability discovery—rather than overtaking U.S. labs across the board. Some of Zhipu's broader parity claims also haven't been independently verified, partly because Mythos itself has been intermittently unavailable for outside researchers to test against (more on that below). Treat the specific percentage-point comparisons with appropriate skepticism; treat the trend line as real.&lt;/p&gt; 
&lt;p&gt;The capability gap narrowing is one thing. The delivery mechanism is the part that should actually concern security leaders.&lt;/p&gt; 
&lt;p&gt;Mythos lives behind an API that Anthropic—or a U.S. regulator— can switch off at will, which is precisely &lt;a href="https://www.secureworld.io/industry-news/mythos-export-ban-ai-vulnerability-tools"&gt;what happened in June&lt;/a&gt;. GLM-5.2 ships as downloadable weights under an MIT license. Anyone can pull it onto consumer-grade hardware and run it locally, with no vendor in the loop, no usage logging, and no ability for Zhipu to see or shape what it's used for after release. As one &lt;span style="font-style: italic;"&gt;Forbes&lt;/span&gt; analysis put it, the variable that matters here isn't raw capability, it's containment. A frontier-adjacent vulnerability-finding model that nobody can revoke access to is a fundamentally different risk profile than the same capability sitting behind a gated, monitorable API—regardless of how the benchmark scores compare.&lt;/p&gt; 
&lt;p&gt;That distinction is exactly what the U.S. export control strategy was built to prevent, and exactly what it currently can't reach.&lt;/p&gt; 
&lt;p&gt;"Historically, the most advanced, and potentially dangerous, technology has been closely held by major government or organizations with strict controls," said &lt;a href="https://www.linkedin.com/in/b2bpipelinebuilder/"&gt;John Gallagher&lt;/a&gt;, Vice President at Viakoo, a provider of automated IoT cyber hygiene. "As Chinese frontier models are showing, those days are past as the most advanced AI capability is available to all. This genuinely democratizes the ability to exploit vulnerabilities to all types of hackers."&lt;/p&gt; 
&lt;p&gt;Gallagher added:&amp;nbsp;"While much of the immediate concern centers on traditional IT systems, the real blast radius of cheap, open-weight offensive AI tools hits Operational Technology (OT), IoT, and ICS systems the hardest. Unlike enterprise IT networks, which are heavily monitored, patched, and segmented, physical security systems—such as legacy networked security cameras, access control panels, and smart building HVAC systems—suffer from massive asset blindness and sparse patching schedules."&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;What this means for Mythos—and for Anthropic's last few weeks&lt;/h2&gt; 
&lt;p&gt;To understand why this story is landing the way it is, we have to examine&amp;nbsp;the timeline of what's happened to Mythos itself.&lt;/p&gt; 
&lt;p&gt;Anthropic previewed Mythos in April through &lt;a href="https://www.secureworld.io/industry-news/anthropics-claude-mythos-signals-a-new-era-in-ai-powered-cybersecurity-and-a-race-no-one-is-ready-for"&gt;Project Glasswing&lt;/a&gt;, an invite-only program that eventually grew to roughly 200 vetted organizations— including Amazon, Apple, Google, Microsoft, Cisco, Nvidia, and the Linux Foundation—using the model strictly for defensive vulnerability research. By late May, those partners had used it to surface more than 10,000 high- or critical-severity vulnerabilities, including a 27-year-old flaw in OpenBSD's TCP stack and 271 vulnerabilities in an early Firefox build, reportedly engineering working exploits roughly 90 times faster than prior-generation tools.&lt;/p&gt; 
&lt;p&gt;On June 9, Anthropic released a public sibling, Claude Fable 5—the same underlying model with guardrails that route high-risk security queries to a safer fallback. Three days later, the U.S. Commerce Department ordered Anthropic to disable both Fable 5 and Mythos 5 worldwide, for every user, citing a reported jailbreak technique and broader national security concerns about foreign access to cyber-capable AI. Anthropic complied within hours and publicly disputed the government's characterization of the jailbreak's severity, while the administration's account—relayed by White House AI advisor David Sacks—placed responsibility on Anthropic for declining to "fix" the issue on the government's terms.&lt;/p&gt; 
&lt;p&gt;The blackout lasted about two weeks. On June 26, Commerce Secretary Howard Lutnick notified Anthropic that Mythos 5 could be restored to roughly 100 vetted U.S. organizations—critical infrastructure operators, federal agencies, and cyber defense firms largely drawn from the Project Glasswing roster. Fable 5, the version anyone could sign up for, remains offline, with no public timeline for its return.&lt;/p&gt; 
&lt;p&gt;For Mythos specifically, GLM-5.2's release reframes the entire restriction strategy. The policy logic behind locking down Mythos assumed that doing so would meaningfully slow adversaries' access to equivalent capability. GLM-5.2 is a direct test of that assumption, and the early answer looks like "no"—a freely downloadable model is now performing in the same range as the system the U.S. government spent two weeks debating how tightly to lock down. Security researcher Niels Provos and former export-control policy architect Saif Khan have both made versions of the same argument publicly: restricting American models without a credible plan for what happens when adversaries build comparable open alternatives doesn't slow proliferation;&amp;nbsp;it just hands the open-source distribution channel to Beijing while U.S. defenders work with one hand tied behind their backs.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;What the U.S. government is actually doing&lt;/h3&gt; 
&lt;p&gt;Three things, roughly in parallel, and they don't fully agree with each other.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Export controls on frontier cyber-capable models&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;The June 12 order against Anthropic was the most aggressive intervention to date—a blanket suspension covering even Anthropic's own non-citizen employees, justified under national security export authority rather than a typical product recall or safety review. OpenAI faced a softer version of the same pressure: at the government's request, it staggered the rollout of GPT-5.6, limiting initial access to a small, individually vetted partner list rather than shipping the jailbreak-and-shutdown sequence Anthropic experienced.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;A formal review framework, after the fact&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;a href="https://www.secureworld.io/industry-news/trump-executive-order-ai-nsa"&gt;President Trump's June 2 executive order&lt;/a&gt;, "Promoting Advanced Artificial Intelligence Innovation and Security," established a voluntary process for frontier labs to give the government pre-release access to "covered frontier models" for up to 30 days of review. In practice, both the Anthropic shutdown and the OpenAI staggered release happened either before this framework was fully operationalized or in tension with its "voluntary" framing; there's no published testing methodology or benchmark criteria yet, despite a 60-day implementation clock.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;A vetted partner carve-out that mirrors what Anthropic was already doing voluntarily&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;The 100 organizations now cleared to use Mythos 5 again look a great deal like the Project Glasswing partner list Anthropic built on its own months earlier. The government's restored-access framework, in other words, largely re-implements a structure the private sector had already designed—just with Commerce holding the on/off switch instead of Anthropic.&lt;/p&gt; 
&lt;p&gt;The throughline across all three: the administration is treating frontier cyber-capable AI as a dual-use national security asset, comparable in spirit to encryption export rules or controlled defense technology, rather than as ordinary commercial software. Whether that framework can keep pace with open-weight releases from labs the U.S. has no jurisdiction over is the question GLM-5.2 just put back on the table.&lt;/p&gt; 
&lt;p&gt;Strip away the benchmark percentages and three structural points stand out for anyone setting AI procurement or security strategy.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;Open-weight is becoming the geopolitical pressure-release valve. This isn't an isolated event. DeepSeek's V4 Pro release earlier in 2026 produced a similar (if more general purpose) shock to Western AI valuations. Chinese labs appear to be using permissive open licensing as a deliberate strategic move—it sidesteps export control regimes built around API access entirely, and it converts "we don't have the most capable closed model" into "you can't stop us from giving away something close enough." 360 Security Technology's CEO Zhou Hongyi made the framing explicit to &lt;em&gt;The Wall Street Journal&lt;/em&gt;: a tool with this much offensive and defensive cyber relevance, in his telling, "can't remain solely in American hands"—which is as direct a statement of intent as you'll get from a Chinese security executive.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;Restriction without a containment plan creates exposure, not safety. The uncomfortable possibility raised by GLM-5.2 is that U.S. policy may be optimizing for the wrong threat model. If the goal is keeping cyber-capable AI out of adversary hands entirely, that goal already looks unreachable, as open-weight Chinese alternatives exist and are improving. If the goal is keeping the &lt;em&gt;most&lt;/em&gt; capable version of these tools in defenders' hands first, then restricting U.S. defenders' own access while equivalent capability proliferates freely elsewhere is close to the opposite of that goal. Dario Amodei's own May warning—that Mythos had already surfaced tens of thousands of vulnerabilities and defenders had perhaps six to 12 months before comparable offensive capability became widely available—reads very differently now that "widely available" arrived inside of six weeks, not 12&amp;nbsp;months.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;Enterprise AI procurement now has a sovereignty dimension. &lt;em&gt;The Wall Street Journal&lt;/em&gt; reported that Microsoft is exploring offering Chinese AI models on its own platform—a notable signal that even major U.S. cloud providers see commercial logic in open Chinese alternatives, cost and capability considerations aside. For CISOs, the practical upshot is that "which model" is no longer just a capability and pricing decision. A self-hosted open-weight model isn't exposed to a future U.S. export order, a vendor pricing change, or another company's API outage—but it does shift the entire security, patching, and provenance burden in-house, and it may carry its own data-sovereignty exposure if hosted through a Chinese provider's cloud rather than self-hosted. The Mythos blackout was a real-world demonstration, for any enterprise that had built workflows around it, of exactly that dependency risk.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;"What's now been shown is that U.S. restrictions on frontier models like Mythos fail to neutralize the threat posed by China's open-weight GLM-5.2. Instead, choking domestic access creates a dangerous asymmetry: global adversaries retain an unrestricted, modifiable weapon, while American defenders are denied the very frontier tools needed to counter them," said &lt;a href="https://www.linkedin.com/in/ramvaradarajan/"&gt;Ram Varadarajan&lt;/a&gt;, CEO at Acalvio, a leader in cyber deception technology. "We've surfaced a reality where advanced AI capabilities can't be contained by local regulations. The critical policy question is not whether these systems will exist, but whether American enterprise and security teams will have the tools to match their adversaries."&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;Practical takeaways worth raising in upcoming security leadership meetings&lt;/h4&gt; 
&lt;p&gt;The defender-attacker timeline compressed faster than even Anthropic's own warnings anticipated. If vulnerability management programs are&amp;nbsp;still operating on a "weeks to patch" cadence, the AI-assisted vulnerability discovery curve—on both sides of the fence—argues for compressing that further, regardless of which model anyone is using to find the bugs first.&lt;/p&gt; 
&lt;p&gt;Don't assume "restricted" means "contained." Mythos being limited to ~100 organizations doesn't mean equivalent offensive capability isn't available to a much larger pool of actors through GLM-5.2 or similar open releases. Threat modeling that assumes attacker capability is gated by U.S. export policy is now demonstrably outdated.&lt;/p&gt; 
&lt;p&gt;"Security teams should avoid getting caught up in model-versus-model comparisons. The more important development is that advanced vulnerability discovery capabilities are becoming increasingly available across multiple models, vendors, and geographies," said Dr. &lt;a href="https://www.linkedin.com/in/margaret-cunningham-phd/"&gt;Margaret Cunningham&lt;/a&gt;, Vice President of Security &amp;amp; AI Strategy at Darktrace, global leader in AI for cybersecurity. "Whether the latest benchmark winner comes from the U.S. or China does not fundamentally change the challenge defenders face."&lt;/p&gt; 
&lt;p&gt;Dr. Cunningham continued:&amp;nbsp;"The reality is that vulnerability discovery was already outpacing remediation in many organizations. AI is accelerating that imbalance. Finding a vulnerability is only the beginning. Security teams still need to determine whether it is exploitable in their environment, understand potential business impact, prioritize remediation, test changes, and deploy fixes safely."&lt;/p&gt; 
&lt;p&gt;The takeaway for security leaders is not to debate which model is best. It's to prepare for a future where advanced AI-assisted discovery capabilities are widely available. That makes behavioral detection, anomaly-based analytics, risk-based prioritization, and autonomous response increasingly important. There is no universal definition of normal anymore. Organizations need to understand what is normal in their own environment and detect when something changes.&lt;/p&gt; 
&lt;p&gt;For those building AI dependencies into security tooling or procurement, build for discontinuity. The Mythos shutdown was a 15-day unplanned outage of a tool some enterprises had already built workflows around, triggered by a regulatory action with effectively no advance notice. That's a vendor risk category most security teams haven't formally modeled yet, and after this month, probably should.&lt;/p&gt; 
&lt;p&gt;The Zhipu story will keep evolving. GLM-5.2's claims haven't been fully independently verified, the Fable 5 restriction has no announced end date, and Elon Musk's public prediction that Chinese labs would match Anthropic's flagship "by early 2027" was answered within days by Zhipu's own founder insisting the timeline would be shorter.&lt;/p&gt; 
&lt;p&gt;"GLM-5.2 is an important signal that capable open-weight models are becoming increasingly accessible to businesses, researchers, and adversaries," said &lt;a href="https://www.linkedin.com/in/dianakelleysecuritycurve/"&gt;Diana Kelley&lt;/a&gt;, CISO at Noma Security, a unified AI security and governance platform. "It also reinforces a trend that security and technology leaders are already evaluating more deliberately: model agility. Organizations increasingly need the ability to swap models in agentic and AI-enabled systems without rebuilding the entire architecture."&lt;/p&gt; 
&lt;p&gt;"That only works if critical functions such as business logic, proprietary workflows, access controls, and sensitive data handling live in the surrounding application and governance layer, rather than being too tightly bound to a single model provider or orchestration harness," Kelley added. "Done well, that approach gives teams more room to manage cost, capability, and vendor lock-in."&lt;/p&gt; 
&lt;p&gt;What's already clear, regardless of how the benchmark race shakes out, is that the assumption underpinning a year of U.S. AI export policy—that restricting access to frontier models meaningfully slows adversary capability—just took its first serious public stress test. It did not hold up cleanly.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fchina-glm-5.2-mythos-vulnerability-detection&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Vulnerabilities</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>U.S. Government</category>
      <category>China</category>
      <category>Anthropic</category>
      <pubDate>Wed, 01 Jul 2026 13:37:02 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/china-glm-5.2-mythos-vulnerability-detection</guid>
      <dc:date>2026-07-01T13:37:02Z</dc:date>
    </item>
    <item>
      <title>$3M Polymarket Hack Exposes Frontend Vulnerabilities in Prediction Markets</title>
      <link>https://www.secureworld.io/industry-news/polymarket-hack-frontend-vulnerabilities</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/polymarket-hack-frontend-vulnerabilities" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Blockchain_shutterstock_2324952227.jpg" alt="analyst looking at large screens" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The core infrastructure of blockchain applications is often built like a fortress, but a fortress matters very little if a thief can simply swap out the front gate.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The core infrastructure of blockchain applications is often built like a fortress, but a fortress matters very little if a thief can simply swap out the front gate.&lt;/p&gt;  
&lt;p&gt;Prediction market giant Polymarket—which has been blasting the airwaves with commercials during the FIFA World Cup—confirmed that hackers walked away with approximately $3 million of user funds. The breach didn't involve a complex smart contract exploit or a failure in underlying cryptographic protocols. Instead, attackers executed a classic third-party supply chain compromise, injecting malicious code directly into the platform's frontend user interface.&lt;/p&gt; 
&lt;p&gt;While Polymarket quickly contained the damage and committed to fully reimbursing affected users, the incident serves as a reminder to tech leaders and consumers alike: in decentralized finance (DeFi) and Web3 ecosystems, the user interface remains a massive, highly-vulnerable attack surface.&lt;/p&gt; 
&lt;p&gt;According to initial reports, the attackers bypassed Polymarket's primary security perimeters by compromising an external, third-party vendor that provides frontend services to the platform. &lt;span&gt;In its official statements regarding the breach, &lt;/span&gt;&lt;strong&gt;&lt;span&gt;Polymarket has not publicly disclosed the specific identity or name of the third-party vendor&lt;/span&gt;&lt;/strong&gt;&lt;span&gt; that was compromised.&lt;/span&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Once inside the vendor's deployment pipeline, the hackers injected a malicious script. To an ordinary user visiting the site, everything appeared normal. Behind the scenes, however, the altered frontend hijacked user interactions—likely intercepting private keys or subtly altering transaction data to divert outgoing digital assets into wallets controlled by the attackers.&lt;/p&gt; 
&lt;p&gt;This type of supply chain attack highlights a distinct architectural paradox in modern digital platforms. A platform can invest millions securing its smart contracts and backend databases, but if it relies on third-party libraries, content delivery networks (CDNs), or external analytics tools to render its website, it inherits the security posture of those vendors.&lt;/p&gt; 
&lt;p&gt;"This incident is a reminder that cyber fraud and Anti-Money Laundering (AML) are increasingly connected. A frontend compromise can become stolen funds and laundering activity almost immediately, so static controls are not enough," said Patrick Harr, CEO at DataVisor, an AI-powered AML platform. "Financial platforms need adaptive, always-on monitoring that can connect signals across user behavior, transactions, and money movement—and evolve as quickly as the attackers do."&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;What this means for the prediction market industry&lt;/h2&gt; 
&lt;p&gt;Prediction markets have exploded in popularity, serving as crowd-sourced engines for forecasting everything from political elections to economic indicators. However, this incident will likely trigger several shifts across the industry.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The spotlight grinds down on third-party risks:&lt;/span&gt; Platforms can no longer view frontend integrations as low-risk features. Security teams must enforce strict vendor management, implement continuous subresource integrity (SRI) checks, and adopt zero-trust deployment architectures.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;A shift in regulatory scrutiny:&lt;/span&gt; Because prediction markets deal with significant capital and retail user data, regulatory bodies are already watching them closely. Breaches like this give regulators fresh ammunition to demand strict operational resilience standards and formal risk management frameworks.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;"The Polymarket breach exposes a contradiction in cryptocurrency architecture. Developers secure ledgers through code audits but deliver access through web supply chains. In this incident, attackers bypassed cryptography by injecting scripts into a vendor dependency," said Jason Soroko, Senior Fellow at Sectigo, a provider of comprehensive certificate lifecycle management (CLM). "This code altered data before it reached the blockchain, proving applications inherit the vulnerabilities of interface components. The extraction of $3.1 million from fewer than 15 wallets—averaging more than $200,000 per victim before conversion to 1,893 Ether—demonstrates attackers target the browser to circumvent defenses."&lt;/p&gt; 
&lt;p&gt;"Polymarket's decision to refund victims establishes a standard for incident recovery, but the exploit highlights industry reliance on blind signing. Users substitute domain trust for payload verification. When attackers control the interface, wallet software fails to translate operations into text, causing users to authorize transfers without confirming the destination," Soroko added. "Securing platforms requires operators to apply verification standards to browser code that match the scrutiny given to ledgers. Organizations must enforce content policies, and users must verify transactions on hardware devices to prevent asset diversion."&lt;/p&gt; 
&lt;p&gt;Polymarket is the dominant player in this space, but it operates alongside several other high-profile prediction platforms that will be watching this fallout closely. Major platforms include:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Kalshi:&lt;/span&gt; A federally regulated, U.S.-based platform that allows users to trade on financial and economic events. Because it is heavily regulated by the Commodity Futures Trading Commission (CFTC), its infrastructure is built under rigorous institutional security protocols.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;PredictIt:&lt;/span&gt; A long-standing educational project run by Victoria University of Wellington that lets users trade on political and legislative outcomes under a regulatory framework.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Augur:&lt;/span&gt; A decentralized prediction market protocol built directly on the Ethereum blockchain. Unlike centralized frontends, it relies entirely on global, open-source smart contracts, though users still typically interact with it via web interfaces prone to similar frontend risks.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;"This is not the typical library dependency supply chain attack," said Elad Luz, Head of Research at Oasis Security, a provider of Non-Human Identity Management (NHIM) solutions. "From what we understand, Polymarket was using the services of a third-party software company to maintain their website, and that vendor got compromised (possibly because the attackers wanted to reach Polymarket), and from that vendor they had access to Polymarket resources. This makes a difference because it is an access given to a third party, possibly in the form of some identity."&lt;/p&gt; 
&lt;p&gt;Luz continued, "Applying anomaly detection or baselining to identities of external access is valuable here. There are usually significantly fewer external identities, making this subset practical to observe and monitor. We are seeing more and more threats coming from this vector."&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;What this means for consumers&lt;/h3&gt; 
&lt;p&gt;For everyday users navigating prediction platforms, this incident delivers a mix of a safety net and a warning sign.&lt;/p&gt; 
&lt;p&gt;On one hand, Polymarket’s rapid commitment to fully refunding stolen assets shows that top-tier platforms are willing to absorb financial hits to protect user trust and maintain market liquidity.&lt;/p&gt; 
&lt;p&gt;On the other hand, it proves that "looking at the URL" is no longer enough to ensure safety. Because the platform's actual domain was serving the compromised code, users had no visual indicator that they were walking into a trap.&lt;/p&gt; 
&lt;p&gt;To mitigate risks going forward, consumers must look toward proactive defense measures.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Verify transactions on hardware wallets:&lt;/span&gt; When approving a transaction, don't just rely on what the browser screen says. Always double-check the destination address and asset amounts on a trusted hardware wallet screen before confirming.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Limit hot wallet balances:&lt;/span&gt; Keep only the liquidity needed for immediate trading in active browser extension wallets, keeping the bulk of capital entirely offline.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Monitor official channels:&lt;/span&gt; Following a platform's secondary communication lines (like verified status pages or security broadcast channels) can provide early warnings if an interface begins behaving unexpectedly.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Ultimately, the Polymarket breach is a reminder that as innovative financial technologies grow, they cannot outrun traditional security fundamentals. True security requires securing the end-to-end user pipeline—from the deep code of the blockchain all the way to the pixels on the user's screen.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fpolymarket-hack-frontend-vulnerabilities&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Supply Chains</category>
      <category>Third-Party Vendors</category>
      <category>Original Content</category>
      <category>Breach Notification</category>
      <category>Third-Party Security</category>
      <pubDate>Tue, 30 Jun 2026 20:00:06 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/polymarket-hack-frontend-vulnerabilities</guid>
      <dc:date>2026-06-30T20:00:06Z</dc:date>
    </item>
    <item>
      <title>Your Organization's AI Trust Infrastructure Is Failing, Survey Says</title>
      <link>https://www.secureworld.io/industry-news/ai-trust-infrastructure-failing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/ai-trust-infrastructure-failing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Confidence_Gap__AI_shutterstock_2627625207.jpg" alt="people in blurry office setting " class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The bottleneck on enterprise AI adoption is no longer a question of model capability; it is a crisis of trust infrastructure.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The bottleneck on enterprise AI adoption is no longer a question of model capability; it is a crisis of trust infrastructure.&lt;/p&gt;  
&lt;p&gt;As AI agents rapidly transition from experimental novelties to embedded workforce infrastructure—with nearly half (46.9%) of enterprise employees now relying on them daily or weekly—a fundamental visibility gap has widened.&lt;/p&gt; 
&lt;p&gt;According to &lt;a href="https://cdn.avepoint.com/pdfs/en/shifthappens/AI-Report-eBook-2026.pdf"&gt;new research&lt;/a&gt; from AvePoint, which surveyed 750 enterprise leaders across the Americas, EMEA, and APAC, organizations are rapidly losing their grip on what their data is doing, where it is going, and who (or what) is accessing it.&lt;/p&gt; 
&lt;p&gt;For security and governance teams, the report delivers a wake-up call: paper-based policies are completely failing to protect against the operational realities of agentic workflows.&lt;/p&gt; 
&lt;p&gt;The shift from standard generative AI (like simple chatbots) to autonomous AI agents—systems capable of executing multi-step workflows, calling APIs, and making decisions on behalf of users—has severely outpaced traditional shadow IT discovery tools.&lt;/p&gt; 
&lt;p&gt;AvePoint's data shows that the percentage of organizations unable to detect whether employees are using unsanctioned AI tools has nearly tripled in just a single year, jumping from 6.3% to 17.6%. When looking specifically at AI agents, that visibility blind spot climbs to more than 21%.&lt;/p&gt; 
&lt;p&gt;AI visibility blind spots (Organizations unable to detect unsanctioned use):&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;GenAI tools (Previous Year): 6.3%&lt;span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;GenAI tools (Current): 17.6%&lt;span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;AI agents (Current): 21.0%+&lt;span&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;This rapid decay in visibility has forced organizations into a defensive crouch. Nearly 9 in 10 companies report delaying both agentic and generative AI deployments by an average of almost six months, specifically citing data security and governance concerns as the primary friction point.&lt;/p&gt; 
&lt;p&gt;"AI is now integrated into everyday operations across regions and sectors, but our report makes it clear that accelerating adoption is outpacing readiness, and this presents increased risk as agentic AI continues to spread. Nearly half of employees now rely on AI agents weekly or daily, but visibility into unsanctioned tools is weakening, and AI-related incidents remain widespread, with 88% of organizations reporting at least one security incident with agentic AI in the past year, according to our research," said &lt;a href="https://www.linkedin.com/in/danalouisesimberkoff/"&gt;Dana Simberkoff&lt;/a&gt;, Chief Risk, Privacy and Information Security Officer at AvePoint. "For security leaders, the takeaway should be clear: trust cannot depend on policy, optimism, or model capability alone. Organizations need enforceable governance, lifecycle controls, proactive data protection, and continuous visibility, protection and prevention into the data AI can access, create, and act on. Without that trust layer, you don’t have the level of control needed to manage costs and mitigate risks."&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;The confidence paradox: policy vs. operational control&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The most alarming finding in the research is the massive disconnect between perceived security readiness and actual security incidents. This "confidence paradox" stems from a legacy mindset: measuring security readiness by whether a policy &lt;i&gt;exists&lt;/i&gt;, rather than whether technical controls are operational, enforceable, and auditable.&lt;/p&gt; 
&lt;p&gt;Consider the baseline numbers:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;More than 4 in 5 organizations state they are confident in their ability to prevent unauthorized AI-related data access.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Yet, up to 72% of that exact same "confident" group experienced an unauthorized data access incident in the past 12 months.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Worse still, 88.4% of organizations experienced at least one AI agent-related security incident over the same period.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;This data exposes a harsh reality. Many enterprise leaders believe that because they have configured basic data access permissions or published an AI acceptable-use policy, their data is secure. However, AI agents excel at scraping, indexing, and synthesizing vast amounts of internal data. If an organization has poorly-managed data permissions internally (over-sharing via broad intranet links or loosely-managed cloud folders), an autonomous agent will inevitably uncover and expose that data to users who shouldn't see it.&lt;/p&gt; 
&lt;p&gt;Compounding this visibility crisis is the sheer volume of data being generated by these automated systems. The study notes that 35.5% of all enterprise data is already AI-generated. Within the next 12 months, that figure is projected to climb to 42.1%.&lt;/p&gt; 
&lt;p&gt;This loop creates an exponential expansion of the attack and governance surface. Organizations are now tasked with securing pipelines where data is created by AI, processed by autonomous agents, and stored in corporate repositories—often without a human ever directly validating the data's integrity or access controls.&lt;/p&gt; 
&lt;p&gt;Because traditional data loss prevention (DLP) and identity access management (IAM) tools struggle to parse the continuous, non-human behavioral patterns of autonomous agents, enterprises are shifting their budgets.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The report highlights an accelerating investment trend toward third-party governance tools and specialized, emerging architecture: AI Agent Management Platforms (AMPs).&lt;/p&gt; 
&lt;p&gt;To bridge the gap between confidence and competence, security teams must look beyond theoretical governance frameworks and implement operational guardrails.&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;Continuous, automated discovery: Moving past static endpoint monitoring to intercept and catalog API calls and integrations tied to LLM backends&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Dynamic, data-centric permissions: Cleaning up internal data permissions &lt;i&gt;before&lt;/i&gt; indexing them into enterprise AI search engines, ensuring agents inherit strict, zero-trust user privileges&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Behavioral guardrails: Implementing guardrails that monitor agent activity for anomalous behavior, such as an unauthorized agent suddenly requesting large batches of sensitive HR or financial records&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;We asked several experts with solution providers for their thoughts on the survey results.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/nathaniel-j-591ba958/"&gt;Nathaniel Jones&lt;/a&gt;, Vice President, Security &amp;amp; AI Strategy, and Field CISO at Darktrace, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"Even before the acceleration in AI capabilities, organizations were struggling with the gap between vulnerability disclosure, exploitation, prioritization, and remediation. What AI increasingly changes is the speed and scale at which portions of that process can occur, particularly reconnaissance, targeting, exploit adaptation, and operational iteration."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The challenge is that most enterprise security environments still rely heavily on human-centered workflows. Patching, validation, change management, and investigation all operate on timelines that are often measured in days or weeks, while adversaries are increasingly capable of operating on timelines measured in hours."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"From a strategic perspective, the larger issue is probably not whether AI regulation becomes slightly more or less restrictive in the near term. The more important question is whether organizations, governments, and technology providers can collectively adapt defensive models quickly enough to keep pace with increasingly adaptive and automated threat environments."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The organizations likely to perform best over time will be those that become better at prioritization, behavioral detection, attack-path analysis, and identifying operational anomalies earlier in the intrusion lifecycle, particularly before public indicators or broad industry awareness emerge. In many respects, the industry may be entering a period where resilience and decision velocity become just as important as prevention itself."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/chandra-gnanasambandam/"&gt;Chandra Gnanasambandam&lt;/a&gt;, CTO at SailPoint, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"Adversaries are using AI to operate at a scale and speed that makes traditional, static defenses obsolete. The window between a vulnerability's discovery and its exploitation has shrunk from months to days, and soon it will be merely minutes."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Security teams must look inwards. Instead of focusing exclusively on keeping threats out, we must meticulously govern what happens inside our own systems. This means abandoning the dangerous, yet common, 'set-it-and-forget-it'&amp;nbsp;approach to access policies. Teams must accept that static, persistent access is the single greatest vulnerability in the modern enterprise. The new mandate is to pivot from a mindset of static protection to one of real-time governance, either through Least Privilege or Zero Standing Privilege. We must also recognize that governing non-human identities (NHIs) is fundamentally different from governing humans and requires a new, specialized framework built for machine-speed operations."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The expertise required is less about a specific, narrow skillset and more about a strategic understanding of modern, identity-centric security architecture. This expertise is often cultivated internally by upskilling existing security and IT teams to adopt this new, identity-focused paradigm. It can also be found by partnering with security vendors that are building the architectural foundation for real-time governance and agentic security."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/dianakelleysecuritycurve/"&gt;Diana Kelley&lt;/a&gt;, CISO at Noma Security, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&amp;nbsp;"AI risks have rapidly moved from a watch list item to a front-line security concern, especially when it comes to data security and misuse. To manage this emerging threat landscape, security teams need a mature, continuous security approach, which includes blue team programs, starting with a full inventory of all AI systems, including agentic components as a baseline for governance and risk management."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"For practitioners, securing AI is not just about protecting models. It requires addressing stack sprawl and moving toward a platform-driven approach that delivers defense in depth through unified, AI-aware identity, configuration, and data visibility. Organizations that simplify their cloud and AI security stack, and enable effective automation, will be far better positioned to safely scale AI as threats continue to evolve."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/ramvaradarajan/"&gt;Ram Varadarajan&lt;/a&gt;, CEO at Acalvio, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"AI-powered cyberattacks have moved from theory to reality. The larger concern for enterprises is what today's AI systems can actually do. Modern models no longer just scan code for technical mistakes. They can infer what developers intended the software to do and spot contradictions humans missed. That makes a new category of vulnerabilities far easier to find: hidden business-logic flaws, broken trust assumptions, and authorization errors that appear perfectly valid to conventional security tools but can still be exploited."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"We're facing an 'assume compromise'&amp;nbsp;future within cybersecurity. &amp;nbsp;Our best defense will be to engage these attacks bot-on-bot inside the perimeter, with active defense keyed by AI itself."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/luz-elad/"&gt;Elad Luz&lt;/a&gt;, Head of Research at Oasis Security, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The rise of AI agents will introduce new security challenges for non-human identities (NHIs). These agents often operate under machine accounts or service identities, acting on behalf of human users, which makes it difficult to track permissions, monitor usage, and enforce accountability. Without proper oversight, organizations risk losing visibility into which identities have access to critical resources and how they are being used."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The main concern is governance. If AI agents are assigned persistent, unmanaged service accounts, these identities can quickly become overprivileged and unmonitored, increasing the organization’s attack surface. To mitigate this risk, security teams should implement automated monitoring, enforce least privilege, and establish clear policies for AI-driven NHIs. By putting these guardrails in place early, organizations can embrace AI automation without compromising security."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/chris-radkowski-aa9161/"&gt;Chris Radkowski&lt;/a&gt;, GRC Expert at Pathlock, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The rise of AI agents and machine identities has fundamentally outpaced traditional identity security. MFA and legacy access controls were built for a world of human users, not autonomous agents, service accounts, and AI-driven workflows that now outnumber people across the enterprise by 20 times. Making matters more complex, the productivity promise of AI is too compelling for employees to wait on IT. Workers are signing up for AI-powered tools, copilots, and automation platforms using their enterprise credentials, connecting them directly to corporate email, productivity suites, and business applications, often without security's knowledge."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"As agentic AI takes on real business actions with real permissions, the attack surface expands in ways most organizations aren't prepared to see, let alone secure. Credential abuse, account takeover, and sophisticated social engineering are increasingly targeting the non-human identities that operate quietly in the background with little oversight. That is why we believe that securing the modern enterprise means treating identity holistically by extending governance, least-privilege, and adaptive controls across every identity, human or machine. In the AI era, identity isn't just an IT problem. It's the foundation of trust itself."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fai-trust-infrastructure-failing&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>Shadow AI</category>
      <category>AI Governance</category>
      <category>AI Agents</category>
      <pubDate>Tue, 30 Jun 2026 12:34:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/ai-trust-infrastructure-failing</guid>
      <dc:date>2026-06-30T12:34:00Z</dc:date>
    </item>
    <item>
      <title>2030 Clock Is Ticking: The Accelerated Post-Quantum Cryptography Mandate</title>
      <link>https://www.secureworld.io/industry-news/2030-clock-ticking-post-quantum-cryptography-mandate</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/2030-clock-ticking-post-quantum-cryptography-mandate" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/quantum%20computer%20shutterstock_2643632169%20editoral%20only-1.jpg" alt="technician working on quantum computer" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For years, enterprise leadership viewed the quantum computing threat through a comfortable lens. "Q-Day"—the hypothetical moment a quantum computer grows powerful enough to shatter standard public-key encryption—was widely treated as a problem for the mid-2030s. It was a line item for future budget cycles, a theoretical challenge for the next generation of security professionals.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For years, enterprise leadership viewed the quantum computing threat through a comfortable lens. "Q-Day"—the hypothetical moment a quantum computer grows powerful enough to shatter standard public-key encryption—was widely treated as a problem for the mid-2030s. It was a line item for future budget cycles, a theoretical challenge for the next generation of security professionals.&lt;/p&gt; 
&lt;p&gt;That comfort zone evaporated on June 22, 2026.&lt;/p&gt; 
&lt;p&gt;With the signing of &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/"&gt;Executive Order 14409&lt;/a&gt;, "Securing the Nation Against Advanced Cryptographic Attacks," the White House completely shattered the existing timeline for Post-Quantum Cryptography (PQC) readiness. By aggressively compressing the federal government's migration schedule, the Trump administration sent an unmistakable signal to the entire cybersecurity landscape: the "harvest now, decrypt later" threat is a present-day crisis, and the clock is officially running out.&lt;/p&gt; 
&lt;p&gt;The core of the new Executive Order lies in its aggressive, uncompromising milestones. Previous federal guidance suggested a long, gradual transition stretching well into the next decade. EO 14409 pulls that timeline forward by nearly five years, establishing strict, legally mandated deadlines for federal agencies.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;December 31, 2030:&lt;/span&gt; Federal agencies must fully transition all high-value assets (HVAs) and high-impact systems to NIST-approved post-quantum cryptography for key establishment.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;December 31, 2031:&lt;/span&gt; Agencies must achieve the same total PQC transition for digital signatures.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For context, modern encryption underpins everything from secure web traffic to federal database access. Forcing a migration of this scale across the federal enterprise in less than five years is a massive technical hurdle.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;The clock starts today&lt;/h2&gt; 
&lt;p&gt;The federal mandate doesn't allow for a slow ramp-up period; it demands immediate operational momentum. The administration is forcing agencies to establish accountability and visibility right out of the gate.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The 30-day mark:&lt;/span&gt; Agencies have just 30 days to formally designate a PQC Migration Lead to oversee the transition.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The 90-day mark:&lt;/span&gt; Within 90 days, agencies must initiate a comprehensive, agency-wide cryptographic review to baseline exactly where legacy algorithms are currently deployed.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;By forcing rapid accountability, the White House is ensuring that agencies cannot kick the compliance can down the road.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;The supply chain ripple effect: why contractors are on notice&lt;/h3&gt; 
&lt;p&gt;If you don't work for a federal agency, it is easy to look at these mandates and assume it is someone else's problem. That is a dangerous miscalculation.&lt;/p&gt; 
&lt;p&gt;EO 14409 explicitly targets the federal supply chain. The Executive Order gives the Federal Acquisition Regulatory (FAR) Council just 180 days to draft stringent new rules. These rules will require covered government contractors—including software vendors, cloud service providers, and IT integrators—to meet these exact same NIST PQC standards by the 2030 deadline.&lt;/p&gt; 
&lt;p&gt;If your organization sells software, hardware, or digital services to the federal government, your development timeline just shifted. Legacy public-key encryption (like RSA or ECC) will essentially become a compliance liability in federal procurement within the next few years.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The reality of 'harvest now, decrypt later'&lt;/h4&gt; 
&lt;p&gt;Why is the White House moving with such sudden urgency? It comes down to a well-documented nation-state adversary tactic: harvest now, decrypt later (HNDL).&lt;/p&gt; 
&lt;p&gt;Adversaries do not need a quantum computer today to compromise data tomorrow. They are actively intercepting and archiving massive amounts of encrypted, sensitive enterprise and government data right now. When a cryptanalytically relevant quantum computer (CRQC) inevitably comes online, they will simply feed this archived data into the machine, rendering standard classical encryption useless.&lt;/p&gt; 
&lt;p&gt;Data with a long shelf life—such as intellectual property, citizen PII, defense designs, and critical infrastructure blueprints—are already at risk. The White House recognizes that waiting for the technology to arrive before securing the data is a losing strategy.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;The takeaway: a wake-up call for private enterprise&lt;/h5&gt; 
&lt;p&gt;While EO 14409 applies strict mandates to federal agencies and their direct supply chains, the secondary pressure on the private sector will be immediate and profound.&lt;/p&gt; 
&lt;p&gt;Commercial software vendors supplying the federal government will inevitably push PQC updates down to all of their commercial customers. Furthermore, critical infrastructure sectors—such as energy, finance, and healthcare—will likely see regulatory bodies mirror these federal timelines in short order.&lt;/p&gt; 
&lt;p&gt;The era of treating quantum security as science fiction is officially over. For CISOs and security leaders across every industry, the mandate is clear: the time to build a cryptographic inventory, map out your legacy dependencies, and demand PQC roadmaps from your third-party vendors begins today.&lt;/p&gt; 
&lt;p&gt;The year 2030 is no longer a distant horizon. The countdown has begun.&lt;/p&gt; 
&lt;p style="text-align: center;"&gt;~~~&lt;/p&gt; 
&lt;p&gt;To help security teams and leaders transition from panic to a practical roadmap, SecureWorld is bringing together the brightest minds in the industry for the &lt;span style="font-weight: bold;"&gt;SecureWorld Quantum Cryptography virtual conference&lt;/span&gt; on September 23, 2026. See details and &lt;a href="https://events.secureworld.io/details/quantum-cryptography-2026/"&gt;register to attend here&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2F2030-clock-ticking-post-quantum-cryptography-mandate&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Original Content</category>
      <category>U.S. Government</category>
      <category>Cryptography</category>
      <category>Quantum Computing</category>
      <pubDate>Mon, 29 Jun 2026 15:19:00 GMT</pubDate>
      <author>media@secureworld.io (SecureWorld News Team)</author>
      <guid>https://www.secureworld.io/industry-news/2030-clock-ticking-post-quantum-cryptography-mandate</guid>
      <dc:date>2026-06-29T15:19:00Z</dc:date>
    </item>
    <item>
      <title>Defending the Grid: Inside the APPA’s New Strategic Cybersecurity Push</title>
      <link>https://www.secureworld.io/industry-news/appa-new-cybersecurity-committee</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/appa-new-cybersecurity-committee" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Blog%20Images/OT_Security_powerlines.jpg" alt="power lines and lock icon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For utility defense teams and critical infrastructure protectors, the baseline operational reality is clear: grid security requires constant, unified vigilance. Public power utilities face the complex challenge of defending interconnected physical assets, information technology (IT), and operational technology (OT) from increasingly coordinated digital threats.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For utility defense teams and critical infrastructure protectors, the baseline operational reality is clear: grid security requires constant, unified vigilance. Public power utilities face the complex challenge of defending interconnected physical assets, information technology (IT), and operational technology (OT) from increasingly coordinated digital threats.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Recognizing the need for a unified defensive front, the American Public Power Association (APPA) Board of Directors recently approved and launched its first-ever Cybersecurity Committee. This dedicated committee is designed to align and provide strategic direction for all of APPA's various cybersecurity programs, events, resources, and projects.&lt;/p&gt; 
&lt;p&gt;Here is a breakdown of what this milestone governance move means for APPA members, critical infrastructure protection, and the general public.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;1. What is the new cybersecurity committee?&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The APPA Cybersecurity Committee serves as a centralized strategic hub. Previously, public power utilities relied on an array of disconnected playbooks, working groups, and training programs. This new committee systematically orchestrates those resources under a single governance body to establish a more unified threat-response posture across the sector.&lt;/p&gt; 
&lt;p&gt;The committee's core mandate includes aligning and maximizing APPA's cornerstone initiatives:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;The Cybersecurity Defense Community (CDC): APPA's primary working group tasked with updating utility resources and planning the annual Cybersecurity &amp;amp; Technology Summit.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Targeted documentation: Centralizing the deployment of the &lt;i&gt;Public Power Cyber Incident Response Playbook&lt;/i&gt; and the &lt;i&gt;Public Power Cybersecurity Roadmap&lt;/i&gt;.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Federal cooperative agreements: Advising on initiatives funded through APPA's &lt;i&gt;Cyber Pathways&lt;/i&gt; program, which operates under a cooperative agreement with the Department of Energy's (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER).&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3&gt;&lt;strong&gt;2. Gamifying maturity: the cybersecurity accelerator program (CAP)&lt;/strong&gt;&lt;/h3&gt; 
&lt;p style="font-weight: normal;"&gt;A primary program under the committee's strategic umbrella is the Cybersecurity Accelerator Program (CAP). Funded through the Cyber Pathways initiative, CAP helps public power utilities evaluate and dynamically improve the maturity of their cybersecurity programs across both IT and OT networks.&lt;/p&gt; 
&lt;p&gt;Rather than utilizing CAP as a pass/fail compliance audit, APPA uses a tiered designation structure to recognize utility maturity and establish clear defensive benchmarks:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&amp;nbsp;&lt;strong&gt;&lt;span style="line-height: 115%;"&gt;CAP Designation Level&lt;/span&gt;&lt;/strong&gt; Gold / Maturity Criteria: Utilities that successfully validate and demonstrate foundational, core cybersecurity practices across governance, risk management, and incident response.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Level Platinum / Maturity Criteria: Utilities that demonstrate advanced cybersecurity execution positioned well above core practices.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Level Diamond / Maturity Criteria: Utilities validating elite cybersecurity programs that operate above and beyond core practices.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The evaluation covers crucial areas like cybersecurity governance and training, structured incident containment, and grid risk prioritization. The program provides a practical roadmap, allowing less advanced utilities to look at CAP designees as blueprints for modeling their own internal defensive architectures.&lt;/p&gt; 
&lt;h4&gt;&lt;strong&gt;3. What this means for the public power ecosystem&lt;/strong&gt;&lt;/h4&gt; 
&lt;p&gt;The launch of the Cybersecurity Committee and the scaling of the CAP initiative signal a major evolution in how public power approaches digital defense.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;For APPA members and utility CISOs&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;span style="font-weight: normal;"&gt;For the personnel defending local utility perimeters, this means an end to siloed security planning. With the committee establishing a standardized baseline, member utilities can easily map their current capabilities against industry-vetted standards like the Cybersecurity Capability Maturity Model (C2M2) and CISA Cross-Sector Performance Goals. Furthermore, because the CAP application requires collaboration between executive leadership and technical subject matter experts, it bridges the historical gap between utility boards and IT/OT engineers.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;For critical infrastructure security&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;span style="font-weight: normal;"&gt;Critical infrastructure is inherently interdependent. A cyber incident that compromises a small, municipal public power utility can rapidly scale, causing cascading telemetry failures into broader regional transmission networks. By building a cooperative defense ecosystem that includes small public power entities through programs like &lt;i&gt;OT Insight&lt;/i&gt; (which deploys sensor technologies to smaller plants), the committee significantly raises the collective barrier to entry for adversarial threat actors targeting the North American bulk power system.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;For the general public&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;span style="font-weight: normal;"&gt;For everyday consumers, this structural alignment translates directly into grid reliability and community resilience. Public power utilities serve millions of Americans. When an association aligns its defense strategies, upgrades its incident response playbooks, and audits its supply chain risks, it drastically reduces the likelihood of catastrophic, cyber-induced power outages that threaten public safety, local economic stability, and the continuous delivery of electricity.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="line-height: 1.6; color: #333333; background-color: #ffffff;"&gt;"It is vital that public power utilities have access to the latest tools and information they need to successfully meet ever-evolving cybersecurity threats. The Committee will play a key role in helping APPA members make the most of the resources that APPA offers to them when it comes to cybersecurity vulnerabilities,"&amp;nbsp;said Scott Corwin, President and CEO of APPA.&lt;/p&gt; 
&lt;p style="line-height: 1.6; color: #333333; background-color: #ffffff;"&gt;Nick Lawler, General Manager at Littleton Electric Light &amp;amp; Water Department in Massachusetts, is serving as Committee chair, while Mike Willetts, Director of Training and Safety at the Minnesota Municipal Utilities Association, is serving as Vice Chair.&lt;/p&gt; 
&lt;p style="line-height: 1.6; color: #333333; background-color: #ffffff;"&gt;"It’s an honor to lead this Committee, and I am looking forward to working with Mike and the APPA team,"&amp;nbsp;said Lawler. "The Committee will work to ensure that APPA's cybersecurity efforts continue to effectively assist members as they tackle cybersecurity threats."&lt;/p&gt; 
&lt;p&gt;The APPA's &lt;a href="https://www.publicpower.org/cybersecurity-accelerator-program"&gt;Cybersecurity Accelerator Program&lt;/a&gt; helps public power utilities to assess and improve the maturity of their cybersecurity programs. This includes assessing both IT and OT cybersecurity posture, as well as the policies and practices that support electric system and grid security.&lt;/p&gt; 
&lt;p&gt;The CAP application form and guide can be found at the link above. Utilities must submit the application, including program checklists, supplemental information, and/or documentation as necessary, by June 30, 2026.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fappa-new-cybersecurity-committee&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Cybersecurity</category>
      <category>Critical Infrastructure</category>
      <category>Original Content</category>
      <category>Utilities</category>
      <pubDate>Fri, 26 Jun 2026 13:03:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/appa-new-cybersecurity-committee</guid>
      <dc:date>2026-06-26T13:03:00Z</dc:date>
    </item>
    <item>
      <title>Why the FortiBleed Campaign Is So Much Worse than a Standard Leak</title>
      <link>https://www.secureworld.io/industry-news/fortibleed-campaign-worse-leak</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/fortibleed-campaign-worse-leak" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/cyber%20attack%20-%20female-technician-using-laptop-to-analyze-server-2024-10-22-04-07-31-utc-2.jpg" alt="woman IT technician in server room" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;For months, the cybersecurity community has been tracking a sweeping, automated offensive targeting edge infrastructure. What began as an apparent wave of internet-wide scanning has solidified into one of the most significant security events of the year: FortiBleed.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;For months, the cybersecurity community has been tracking a sweeping, automated offensive targeting edge infrastructure. What began as an apparent wave of internet-wide scanning has solidified into one of the most significant security events of the year: FortiBleed.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;A massive dataset containing verified administrative and SSL VPN credentials for more than 73,000 internet-facing Fortinet FortiGate firewalls across 194 countries has been leaked and circulated within criminal underground forums.&lt;/p&gt; 
&lt;p&gt;When news of the leak first broke, many chalked it up to a routine credential-stuffing automated pass. But as technical deep dives from Fortinet, SOCRadar, CloudSEK, Palo Alto Networks (Unit 42), and Prodaft have emerged, a chilling consensus has formed: as one industry analysis noted, "the incident is so much worse than a simple credentials leak."&lt;/p&gt; 
&lt;p&gt;Here is a breakdown of how the FortiBleed campaign was actually executed, what makes its underlying mechanics so dangerous, and how defense teams must respond.&lt;/p&gt; 
&lt;p&gt;The sheer scale of the FortiBleed dataset—affecting critical infrastructure, government agencies, and multinational corporations—stems from a highly sophisticated combination of massive brute-forcing and a deep understanding of legacy architectural edge quirks.&lt;/p&gt; 
&lt;p&gt;According to threat intelligence findings, a Russian-speaking threat group systematically executed a multi-layered campaign.&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Mass volume probing:&lt;/span&gt; The actors launched roughly 1.16 billion credential attempts targeting over 320,000 FortiGate systems, concurrently running over 2 billion attempts against Microsoft SQL Server (MSSQL) environments.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Exploiting legacy hashes:&lt;/span&gt; Rather than relying entirely on live, noisy brute-forcing that triggers modern endpoint protection, the attackers targeted a specific, backward-compatible behavior within FortiOS credential management. When older versions of FortiOS are upgraded to newer releases, administrative passwords often remain stored as weaker legacy SHA-256 hashes until an administrator manually logs back in to trigger a migration to robust PBKDF2 hashing.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;High-power offline cracking:&lt;/span&gt; By exporting configuration files and intercepting SSL VPN authentication hashes, the actors shifted the heavy lifting entirely offline. Operating a massive 45-GPU cracking cluster managed through Hashtopolis, they systematically broke these weak legacy hashes at scale without generating a single alert on the live production networks.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Fortinet provided &lt;a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-reported-credential-compromise-of-fortigate-devices"&gt;its own analysis&lt;/a&gt; of the situation, saying, "This is not a new Fortinet vulnerability, and this activity is not related to any recent incident or advisory. Upon identifying the incident, we immediately began an investigation, including collaborating with relevant government agencies."&lt;/p&gt; 
&lt;p&gt;The company added:&lt;/p&gt; 
&lt;p&gt;"Fortinet has identified the potentially compromised systems, and we are proactively contacting impacted customers.&lt;span&gt; &lt;/span&gt;To defend against this malicious cyber activity, Fortinet recommends that customers with impacted FortiGate appliances to immediately:&lt;/p&gt; 
&lt;ol style="color: #211f22;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;Terminate all admin and VPN sessions and reset credentials. Terminate all active administrative sessions. Reset all Fortinet VPN and administrative passwords, especially on internet-facing systems, and enforce strong password policies.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;Implement MFA on all &lt;/span&gt;&lt;a href="https://docs.fortinet.com/document/fortigate/7.6.4/administration-guide/014906/administrator-account-options" style="font-weight: normal;"&gt;administrator and VPN user accounts&lt;/a&gt;&lt;span style="font-weight: normal;"&gt;.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;Upgrade to latest versions of 7.4, 7.6, or 8.0. These versions support PBKDF2 hashing of administrator credentials. Follow the &lt;/span&gt;&lt;a href="https://community.fortinet.com/fortigate-3/technical-tip-enforcing-pbkdf2-as-hash-function-for-administrator-accounts-in-fortios-v7-2-11-and-later-220652" style="font-weight: normal;"&gt;guidance&lt;/a&gt;&lt;span style="font-weight: normal;"&gt; to remove older legacy password settings via set login-lockout-upon-weaker-encryption.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;Validate configuration. Review firewall and VPN users and other configuration for unauthorized changes. Preferably compare to a known good configuration. Pay particular attention to the addition of unrecognized accounts, such as "forticloud, fortiuser, fortinet-support, fortinet-tech-support,"&amp;nbsp;etc.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;Check your logs. Look for unexpected administrator access from an unknown IP and domain controller logs for lateral movement, unusual access, suspicious accounts, or unauthorized configuration changes.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;Reduce your attack surface and lock down management access. Restrict external management of your devices via trusted hosts (good), a local-in policy (better), or remove internet administration altogether (best)."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;&lt;strong&gt;Why FortiBleed is significantly more dangerous&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;What elevates FortiBleed from a localized headache to a systemic threat is the tactical utility of the stolen data and what the attackers did &lt;i&gt;after&lt;/i&gt; gaining initial entry.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;As detailed by Prodaft and exposed in open-directory infrastructure captured by CloudSEK, once the threat actors verified working credentials, they didn't immediately drop disruptive ransomware. Instead, they automated the process of turning the compromised firewalls into traffic collection sites. The compromised edge devices were silently used to sniff passing corporate traffic, harvest additional downstream credentials, and build highly-detailed maps of internal Active Directory environments.&lt;/p&gt; 
&lt;p&gt;Firewalls and VPN gateways are the gatekeepers of corporate perimeters. When an attacker logs in with valid, high-level administrative credentials, standard internal behavioral alerts rarely trigger. The attackers essentially became the "insider," using legitimate network commands to exfiltrate documents—such as classified technical blueprints stolen from a targeted NATO defense contractor—while leaving no obvious footprint of an external exploit.&lt;/p&gt; 
&lt;p&gt;In their PSIRT review of the credential compromise dataset, Fortinet clarified that the campaign does not stem from a newly-discovered zero-day software exploit. Instead, the incident represents a massive execution of credential abuse amplified by exposed management interfaces and stale cryptographic structures left behind during device iterations. Fortinet emphasizes that patching the OS code alone is insufficient if the underlying legacy administrative credentials are not dynamically forced to re-encrypt.&lt;/p&gt; 
&lt;p&gt;If your organization utilizes internet-facing Fortinet infrastructure, treating this incident as a simple "patch event" leaves you exposed. Security teams should execute the following hardening playbook immediately:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Execute a comprehensive password rotation:&lt;/span&gt; Force an immediate reset of all local administrator accounts, user profiles, and SSL VPN credentials across the entire fleet.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Purge legacy hashes:&lt;/span&gt; Upgrading to a fixed FortiOS version (such as 7.2.11, 7.4.8, or 7.6.1) must be paired with an active administrative login to migrate the credential base. Furthermore, explicitly enable the configuration setting login-lockout-upon-downgrade (or login-lockout-upon-weaker-encryption on 7.6.x) to block backward-compatible legacy hash exploitation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Shield the management interface:&lt;/span&gt; Completely remove management interfaces from the public-facing internet. Limit administrative access strictly to dedicated out-of-band networks or restricted internal IP zones.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Enforce MFA everywhere:&lt;/span&gt; Mandate multi-factor authentication with number matching for all administrative and remote access pathways. MFA remains the single most effective control to neutralize stolen plaintext credentials.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Initiate downstream threat hunting:&lt;/span&gt; Because the offline cracking methodology means your local firewalls won't show historical brute-force logs, do not assume a clean log equals safety. Audit internal networks for unexpected lateral movement, unauthorized Active Directory modifications, or unusual outbound traffic originating directly from your edge devices.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;SOCRadar said in &lt;a href="https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised/"&gt;a blog&lt;/a&gt;: "The FortiBleed operation is built around full automation. The operation runs in two self-reinforcing stages. Stage one is credential reuse: attackers assembled usernames and passwords from earlier Fortinet-related breach dumps and infostealer malware logs, then tested them automatically against internet-facing FortiGate devices around the clock. Stage two is passive harvesting: once inside a device, it is used as a listening post—SSL VPN traffic passing through is monitored and additional credentials are collected. Those credentials feed back into the scanner, compounding the breach. The system is entirely self-sustaining."&lt;/p&gt; 
&lt;p&gt;CloudSEK&amp;nbsp;concluded in&amp;nbsp;its &lt;a href="https://www.cloudsek.com/blog/inside-the-fortibleed-open-directory-a-technical-analysis-of-what-the-attacker-left-behind"&gt;executive summary&lt;/a&gt;: "The exposed directory leaves no doubt that FortiBleed is a real and capable operation. The toolchain works end to end: scanning located exposed FortiGate interfaces, hashes were cracked on a ~45-GPU Hashtopolis cluster, and validated credentials were used to pivot into networks and enumerate Active Directory&amp;nbsp;all feeding a revenue-sorted catalogue built to sell access. Any organization running an exposed FortiOS management interface should treat its perimeter credentials as compromised and act on the mitigations above."&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Ffortibleed-campaign-worse-leak&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Third-Party Vendors</category>
      <category>Original Content</category>
      <category>Cybercrime / Threats</category>
      <category>Data Breach</category>
      <category>Credentials</category>
      <pubDate>Thu, 25 Jun 2026 12:14:03 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/fortibleed-campaign-worse-leak</guid>
      <dc:date>2026-06-25T12:14:03Z</dc:date>
    </item>
    <item>
      <title>When the Machine Guesses: An AI Deleted a Database in 9 Seconds</title>
      <link>https://www.secureworld.io/industry-news/when-machine-guesses-ai-deleted-database</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/when-machine-guesses-ai-deleted-database" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/AI%20vulerable%20storage-racks-aligned-in-a-computer-server-room-2025-04-03-04-20-54-utc%20copy-3.jpg" alt="computer monitor in data center" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Nine seconds.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nine seconds.&lt;/p&gt; 
&lt;p&gt;That's how long it took an AI coding agent to delete a company's production database and wipe its backups. One command. No warning. No human in the loop.&lt;/p&gt; 
&lt;p&gt;Then it did something stranger. It confessed.&lt;/p&gt; 
&lt;p&gt;Here's the rest of the story.&lt;/p&gt; 
&lt;p&gt;In late April 2026, a developer named Jer Crane was building a small software company called PocketOS. He used Cursor, an AI coding tool running Anthropic's Claude. He handed the agent a routine task in a staging environment—the safe practice area, not the live system.&lt;/p&gt; 
&lt;p&gt;The agent hit a snag. A credential didn't match. Instead of stopping to ask, it went looking for a fix on its own. It found an API token sitting in an unrelated file. That token could do anything, including destroy data. The agent used it to call an older Railway endpoint (Railway hosted PocketOS). That endpoint skipped the safety check that newer tools have. One call deleted the live database volume. The backups lived on the same volume, so they went too.&lt;/p&gt; 
&lt;p&gt;Nine seconds, start to finish.&lt;/p&gt; 
&lt;p&gt;Afterward, the agent wrote out what it had done. I'm cleaning up the language, but the first line was: "NEVER F**KING GUESS, and that's exactly what I did."&lt;/p&gt; 
&lt;p&gt;It kept going. "I guessed that deleting a staging volume would be scoped to staging only. I didn't verify. I didn't check."&amp;nbsp;Then the part that should stop every cybersecurity leader cold: the agent's own rules told it never to run destructive commands without being asked. It had the rule. It broke the rule anyway.&lt;/p&gt; 
&lt;p&gt;There's a good ending, and it matters. Railway's CEO, Jake Cooper, responded that same weekend. His team restored the data in about an hour from a separate set of disaster backups, the kind kept on different storage. He patched the weak endpoint. A strong vendor response turned a disaster into a scare.&lt;/p&gt; 
&lt;p&gt;But sit with the lesson for a second.&lt;/p&gt; 
&lt;p&gt;The agent had a written instruction not to do this. The instruction did nothing. The only thing that would have stopped it was a wall it could not walk through: a safety check built into the system itself.&lt;/p&gt; 
&lt;p&gt;Here's the point: A prompt asks; architecture enforces.&lt;/p&gt; 
&lt;p&gt;We've spent two years writing careful instructions for AI tools. Be safe. Don't touch production. Ask first. Those are good instructions. They're also just words. An AI moving at machine speed will follow them right up until the moment it doesn't, and you will not get a warning.&lt;/p&gt; 
&lt;p&gt;For most of history, our machines were gears. A gear does exactly what it's built to do, every time. Predictable. AI is the first kind of machine that guesses by default. And a guess at nine-second speed can clear your backups before anyone reads the alert.&lt;/p&gt; 
&lt;p&gt;So what do you do?&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;Find your destructive endpoints. Every vendor has them. Ask each one a sharp question: where on your system are the safety checks not applied? The old corners are where an agent will wander.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Scope your tokens. A key that can do anything will eventually do anything. Limit tokens by environment, so staging cannot touch production, and by action, so an everyday key cannot delete.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Move your backups off the primary. Backups on the same volume are not backups. Put them on separate storage, ideally a separate account or a separate vendor. PocketOS survived because Railway kept a copy the agent could not reach.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Stop trusting the system prompt to keep you safe. Treat written AI rules as guidance, not as a control. The real control is the architecture underneath.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;None of this is exotic. It's basic management applied to a faster kind of risk. That's the whole story with AI: the tools are new, but the discipline that keeps them safe is one you already have.&lt;/p&gt; 
&lt;p&gt;The agent said it best, in the middle of the worst nine seconds of its short life. Never guess. Build the system so it can't.&lt;/p&gt; 
&lt;p&gt;&lt;em&gt;This piece is adapted from Kip Boyle's forthcoming book, "Gears Don't Guess: The Executive's Practical Guide to Thriving in the Face of AI Hype and Risk,"&amp;nbsp;out this fall.&lt;/em&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fwhen-machine-guesses-ai-deleted-database&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Featured Author</category>
      <category>DevOps</category>
      <category>AI</category>
      <pubDate>Tue, 23 Jun 2026 16:00:04 GMT</pubDate>
      <author>Kip@CyberRiskOpportunities.com (Kip Boyle)</author>
      <guid>https://www.secureworld.io/industry-news/when-machine-guesses-ai-deleted-database</guid>
      <dc:date>2026-06-23T16:00:04Z</dc:date>
    </item>
    <item>
      <title>Marginal Value Theorem as a Framework for Human Interaction with AI</title>
      <link>https://www.secureworld.io/industry-news/marginal-value-theorem-human-ai</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/marginal-value-theorem-human-ai" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Hackers%20Programmers%20Threat%20Actors%20-%20developers-working-with-computer-codes-in-team-2025-02-11-18-52-16-utc-4.jpg" alt="team working at computer" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;In the 1970s, an ecologist observed that an animal foraging for food would move from one patch to another without taking all the berries, nuts, or grass in the previous patch.&amp;nbsp;He determined the reason was the value of return from the first patch diminished, and the effort to move to another patch without finishing the first yielded greater value. This is the "low hanging fruit" analogy. Eric Charnov published a &lt;a href="https://doi.org/10.1016/0040-5809(76)90040-x"&gt;paper on this topic&lt;/a&gt;, "Optimal foraging, the marginal value theorem," in the journal &lt;span style="font-style: italic;"&gt;Theoretical Population Biology&lt;/span&gt; in 1976.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the 1970s, an ecologist observed that an animal foraging for food would move from one patch to another without taking all the berries, nuts, or grass in the previous patch.&amp;nbsp;He determined the reason was the value of return from the first patch diminished, and the effort to move to another patch without finishing the first yielded greater value. This is the "low hanging fruit" analogy. Eric Charnov published a &lt;a href="https://doi.org/10.1016/0040-5809(76)90040-x"&gt;paper on this topic&lt;/a&gt;, "Optimal foraging, the marginal value theorem," in the journal &lt;span style="font-style: italic;"&gt;Theoretical Population Biology&lt;/span&gt; in 1976.&lt;/p&gt; 
&lt;p&gt;When I ran incident response teams years ago, we had a point while someone was doing data collection or an investigation that we "pulled them off" the task to move on, because we knew through experience that they weren't going to find more meaningful data. We don't have this type of barometer for "foraging"&amp;nbsp;for information from AI.&lt;/p&gt; 
&lt;p&gt;This applies to humans in lots of ways: within AI, the food patch is a research thread, the switching to another patch cost is the cognitive context-switch to a new query, and the depletion curve is the diminishing quality of what AI returns after the first few queries. A universal video game example is as you are farming for a resource, you will move through the space to collect items quickly (e.g., in Super Mario jumping for coins), then move on to the next room instead of taking the time to get all the coins. &amp;nbsp;&lt;/p&gt; 
&lt;p&gt;In organizations, data management takes effort of cleaning data before processing; the first few cycles achieve great results but diminish over time. Or as in code debugging with AI, the first few passes find lots of things to fix, but then the yields become fewer and less impactful.&lt;/p&gt; 
&lt;p&gt;In 1999, two researchers took the marginal value theorem (MVT) concept and related it to humans gathering data. The core idea is people will use cues about the information (they called its "scent") from things like search results headers to determine expected gains of finding quality information, but will stop or switch strategies as cost raises or quality of return falls. This is called Information Foraging Theory (IFT) and was developed &lt;a href="https://psycnet.apa.org/doiLanding?doi=10.1037%2F0033-295X.106.4.643"&gt;by Peter Pirolli and Stuart K. Card&lt;/a&gt;. &amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The opposite of MVT is Sunk Cost Fallacy, where there is cognitive bias for people to "over-graze" on a task because they choose not to switch to another method, platform, or widget. This is a fallacy because even with obvious benefits of switching, the amount of money or time they have sunk into the first option is perceived not to be worth moving on or starting over.&amp;nbsp;&lt;br&gt;It is important to develop standards, personally or within an organization, for people to know when to seek assistance&amp;nbsp;and when to move on. Otherwise, you will waste time and effort (even AI tokens) on tasks that are not yielding value.&lt;/p&gt; 
&lt;p&gt;There's an optimal stopping point when foraging for food or information. Most people overcorrect in both directions: under-delegate by spending too much time doing personal analysis that develops confirmation bias, or over-delegate and become too reliant on AI that forfeits their personal judgement or creates hallucinations.&lt;/p&gt; 
&lt;p&gt;One problem is the cost of switching between patches is not symmetric. Working with AI is nearly free; doing it yourself costs more (in time and effort). IFT theory helps make it easier to look up things automatically rather than reviewing separate physical books.&lt;/p&gt; 
&lt;p&gt;The root problem is the foraging quality signal is not obvious with AI. Animals know there are berries in the patch because they can see them. AI will confidently give you answers with diminishing value (or outright hallucinations), and you won't realize it. AI will continue to answer confidently, making the patch appear full when marginal value has decreased.&lt;/p&gt; 
&lt;p&gt;How do you accommodate this broken quality signal with AI? AI mimics patch fullness regardless of actual yield (of quality information), which is why AI-assisted knowledge work may not succeed in practice. With Google searches, we know the later pages are less valuable, so we don't waste time checking every link in the 12 pages of results. Humans need to externally impose signals of the quality depletion that AI doesn't reveal on its own.&lt;/p&gt; 
&lt;p&gt;A final example from my security consulting days: my ethical hacking team usually had a full week to test applications for customers. One customer who we did dozens of tests for over the years asked us to just do a three-day "quick check" and give a list of significant findings instead of a full report. She wanted to reduce testing costs, and she recognized that we found most significant findings within the first couple days. My hackers hated it, because they knew they could find more vulnerabilities if they had more time; but the customer was leveraging MVT to recognize that the value she needed was if the application was insecure or not—not to find everything wrong.&lt;/p&gt; 
&lt;p&gt;This is where AI governance needs to establish the mechanism that identifies the information value signal that AI obscures, and MVT gives you a framework to describe it. We have an opportunity to design solutions like loop or turn limiters that cap how many AI exchanges are permitted before requiring human review, validation checkpoints, or token cost thresholds to give us that signal.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fmarginal-value-theorem-human-ai&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Big Data</category>
      <category>Featured Author</category>
      <category>AI</category>
      <pubDate>Mon, 22 Jun 2026 17:55:22 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/marginal-value-theorem-human-ai</guid>
      <dc:date>2026-06-22T17:55:22Z</dc:date>
      <dc:creator>Rick Doten</dc:creator>
    </item>
    <item>
      <title>U.S. Coast Guard Cyber Report: Navigating the Contested Blue Domain</title>
      <link>https://www.secureworld.io/industry-news/coast-guard-cyber-report</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/coast-guard-cyber-report" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Coast%20Guard%20-%20us-coast-guard-helicopter-hovering-over-the-water-2026-01-09-09-23-54-utc.jpg" alt="U.S. Coast Guard helicopter over ocean" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The maritime logistics sector is navigating turbulent waters. As shipping routes become geopolitical focal points and port operations rely more heavily on digital execution, the maritime attack surface is expanding rapidly.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The maritime logistics sector is navigating turbulent waters. As shipping routes become geopolitical focal points and port operations rely more heavily on digital execution, the maritime attack surface is expanding rapidly.&lt;/p&gt; 
&lt;p&gt;To help defense teams navigate this shifting environment, U.S. Coast Guard Cyber Command (CGCYBER) released its fifth annual &lt;em&gt;Cyber Trends and Insights in the Marine Environment (CTIME)&lt;/em&gt; report.&lt;/p&gt; 
&lt;p&gt;Grounded in data collected from 42 comprehensive operations conducted by Coast Guard Cyber Protection Teams (CPTs) and industry incident telemetry, &lt;a href="https://www.uscg.mil/Portals/0/Images/cyber/CTIME2025.pdf"&gt;the report&lt;/a&gt; provides a vital roadmap for securing the Marine Transportation System (MTS).&lt;/p&gt; 
&lt;p&gt;The headline metric from the report demands immediate attention: reported maritime cyber incidents spiked 17% over the previous calendar year. &amp;nbsp;Here is what the data reveal&amp;nbsp;about this evolving threat landscape and what it means for critical infrastructure protectors, corporate legal teams, and the general public.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;The critical shipping industry and ports: target systems&lt;/h2&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;For ports and the global shipping firms that keep supply chains moving, the Cyber Trends and Insights in the Marine Environment report isolates two major operational realities: the vulnerabilities embedded in terminal logistics software and the aggressive exploitation of foundational access vectors.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Terminal Operating Systems (TOS) under scrutiny&lt;/h3&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;For the first time, CGCYBER dedicated multiple targeted assessment missions to Terminal Operating Systems—the specialized software responsible for managing yard stacking, gate automation, and rail operations. Because a modern TOS orchestrates everything from automated cranes to waterside berth management, compromising it can instantly halt port productivity and cause catastrophic financial exposure. The CPT assessments exposed several recurring operational gaps across these networks:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Public exposure of internal assets: Internal login portals and administrative panels left entirely exposed to the public internet without firewall isolation.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Legacy architecture anchors: Active reliance on end-of-life, unpatched infrastructure—including legacy versions of Windows Server 2008 supporting core terminal functionality.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Bridged perimeters: Improper or entirely missing network segmentation, allowing commodity IT traffic to coexist alongside sensitive, operational TOS environments.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The persistence of fundamental attack vectors: Despite widespread enterprise cloud migrations and growing multi-factor authentication (MFA) adoption, threat groups are achieving consistent success by simply refining classic attack methodologies. &amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Phishing remains the undisputed preferred pathway for initial access, contributing to 43% of all reported maritime incidents—a major 18-point increase year-over-year. Ransomware also remains a persistent menace, appearing in 19% of attack paths.&lt;/p&gt; 
&lt;p&gt;Sophisticated threat syndicates like Scattered Spider are exploiting these gaps by combining advanced phishing with voice impersonation (vishing) campaigns to compromise IT help desks and bypass poorly-configured MFA parameters.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The global joint front: enter the cyber control teams&lt;/h4&gt; 
&lt;p&gt;One of the most notable additions to the report details how CGCYBER is projecting federal defensive capabilities beyond traditional coastlines. &amp;nbsp;To protect strategic maritime interests, specialized Cyber Control Teams forward-deployed alongside traditional law enforcement and assault boarding units during Maritime Interdiction Operations targeting Dark Fleet Vessels.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;"The collaborative work between our exceptional workforce and our partners in the public and private sectors is the true foundation of our ability to secure our ports and waterways against any threat," said Rear Admiral Jason Tama, Commander, Coast Guard Cyber Command.&lt;/p&gt; 
&lt;p&gt;Operating intentionally outside international oversight, these stateless or foreign vessels bypass standard security frameworks, introducing severe operational risk to global waters. The Cyber Control Teams documented pervasive threats aboard these vessels, including the deployment of Lumma Stealer malware, persistent remote access tools configured for unattended connections (AnyDesk, ScreenConnect), and specialized hardware setups designed to execute Automatic Identification System (AIS) spoofing to mask illicit maritime trade routes.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;What this means for the general public&lt;/h5&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;While the maritime network layer feels distant from the everyday consumer, its stability directly impacts global safety and economic health.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Supply chain continuity: The Marine Transportation System handles approximately 40% of U.S. international trade value. A successful cyberattack targeting a major port terminal's TOS can trigger immediate downstream cargo stagnation, causing manufacturing delays, localized store shortages, and increased consumer costs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Physical and environmental safety: The report documents instances where ransomware successfully compromised passenger cruise ships, encrypting onboard hotel management applications. While network segmentation preserved critical steering and propulsion systems, the convergence of IT and OT means that unsegmented port networks or compromised container ships introduce very real physical navigation hazards to public waterways.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h6 style="font-weight: normal;"&gt;The artificial defender: lessons on AI implementation&lt;/h6&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;The report also provides a crucial reality check for security vendors and enterprise technology teams rapidly deploying automated safeguards.&lt;/p&gt; 
&lt;p&gt;In 2025, Coast Guard CPTs evaluated several maritime partners that had fully integrated Artificial Intelligence Cybersecurity Platforms into their defensive perimeters. The operational returns were highly polarized, demonstrating that AI is not a plug-and-play cure.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The configured value: In a properly configured environment where the AI tool was trained to understand the baseline behaviors of the network, it proved exceptional—detecting and blocking custom intrusion scripts within 30 seconds.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The default vulnerability: Conversely, when organizations deployed these tools with default out-of-the-box settings and failed to tune them to their unique technical architecture, the AI platforms failed to detect any malicious red-team behaviors.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The CISO takeaway: Advanced tooling is only as effective as its configuration. Capital investment must always be matched with proper environment setup and persistent data governance.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For security practitioners operating across the maritime domain, the timeline for compliance has officially begun. The Coast Guard’s 33 CFR Part 101 Subpart F regulations are now active, making cyber incident reporting mandatory for MTSA-regulated facilities. Organizations have until July 16, 2027, to complete formal Cybersecurity Assessments and submit their final Cybersecurity Plans for official review.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fcoast-guard-cyber-report&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Critical Infrastructure</category>
      <category>Original Content</category>
      <category>Maritime Security</category>
      <category>Threat Landscape</category>
      <pubDate>Fri, 19 Jun 2026 13:49:03 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/coast-guard-cyber-report</guid>
      <dc:date>2026-06-19T13:49:03Z</dc:date>
    </item>
    <item>
      <title>ShinyHunters Dumps MSG Sports Data After Knicks' Championship Moment</title>
      <link>https://www.secureworld.io/industry-news/shinyhunters-dumps-msg-data-knicks</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/shinyhunters-dumps-msg-data-knicks" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Data%20Breach%20-%20economic-specialist-investing-capital-funds-on-sto-2025-02-19-23-04-40-utc.jpg" alt="man at laptop assessing data breach" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The New York Knicks clinched their first NBA championship in 53 years on&amp;nbsp;June 5, 2026. That same day, ShinyHunters breached the organization that owns them. When Madison Square Garden Sports Corp. (MSG Sports) missed a June 15 ransom deadline, the threat group did what it always does: it published everything. A 45 GB dump landed on ShinyHunters' dark web&amp;nbsp;blog, exposing more than 26 million customer and corporate records at the precise moment MSG was still celebrating the city’s biggest sports moment in years.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The New York Knicks clinched their first NBA championship in 53 years on&amp;nbsp;June 5, 2026. That same day, ShinyHunters breached the organization that owns them. When Madison Square Garden Sports Corp. (MSG Sports) missed a June 15 ransom deadline, the threat group did what it always does: it published everything. A 45 GB dump landed on ShinyHunters' dark web&amp;nbsp;blog, exposing more than 26 million customer and corporate records at the precise moment MSG was still celebrating the city’s biggest sports moment in years.&lt;/p&gt; 
&lt;p&gt;The timing was not accidental. ShinyHunters timed the data release to coincide with the Knicks'&amp;nbsp;Finals run to ensure maximum public attention—a calculated move from a group that has turned data extortion into something resembling a professional operation.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;What was taken—and why it's unusually sensitive&lt;/h2&gt; 
&lt;p&gt;Journalist Joseph Cox of 404 Media reviewed a sample of the stolen files and confirmed their legitimacy. The dump includes ticket purchaser emails, customer support correspondence, and internal "Talent"&amp;nbsp;files—internal dossiers on high-profile individuals that include home addresses, appearance fees, direct contact information for representatives, and internal risk-level ratings. Actor and comedian Ben Stiller, for example, was tagged "Low Risk," and&amp;nbsp;rapper A Boogie wit da Hoodie was tagged "High Risk."&amp;nbsp;No documented criteria exist for either classification.&lt;/p&gt; 
&lt;p&gt;That last detail carries a particular irony. MSG has deployed facial recognition technology at its venues to identify and bar individuals it deems unwanted—including, as previously reported by &lt;a href="https://www.wired.com/story/madison-square-garden-jim-dolan-surveillance-machine/"&gt;WIRED&lt;/a&gt;, attorneys from law firms in active litigation against the company. The organization that surveils its own guests now has its own surveillance files publicly downloadable on the dark web.&lt;/p&gt; 
&lt;p&gt;MSG Sports has not issued a public statement addressing the breach as of this publication.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Who is ShinyHunters, and why 2026 is their most destructive year yet&lt;/h3&gt; 
&lt;p&gt;ShinyHunters is not a new name. Active since 2019, the group built its reputation on the now-seized RaidForums, and has since evolved into one of the most prolific data theft operations ever documented. The FBI issued a formal public service announcement about the group in May 2026 following the &lt;a href="https://www.secureworld.io/industry-news/shinyhunters-hits-canvas-records-risk-schools"&gt;Canvas/Instructure breach&lt;/a&gt;, describing them as a cybercriminal group "specializing in large-scale data breaches and extortion"&amp;nbsp;that targets "major companies across tech, finance, and retail."&amp;nbsp;The agency also warned that ShinyHunters actors have used harassment tactics against victims and their family members—including swatting.&lt;/p&gt; 
&lt;p&gt;The scale of their 2026 campaign is hard to overstate. The group has claimed responsibility for breaching more than 40 organizations this year alone, with confirmed victims spanning nearly every sector. The roster includes Canvas/Instructure (275 million students across 9,000 institutions), ADT (5.5 million customers), Carnival Cruise (6 million passengers), Rockstar Games (nearly 80 million records), the European Commission (350 GB of internal data), and telecom giant Telus (a claimed 1 petabyte of data). Just days before the MSG dump, ShinyHunters also listed Kodak on their leak site with an identical "final warning"&amp;nbsp;deadline—and Kodak confirmed the breach.&lt;/p&gt; 
&lt;p&gt;Security firm Mandiant, now part of Google, characterized ShinyHunters in January 2026 as "multiple threat clusters"&amp;nbsp;operating under a single brand—a structure that has made the group resilient to law enforcement. Despite multiple arrests of suspected members, including a June 2025 sweep across French regions, the campaigns have not slowed. Mandiant's analysts link ShinyHunters to The Com, an international cybercrime network that also includes Scattered Spider and remnants of Lapsus$.&lt;/p&gt; 
&lt;p&gt;Three attack playbooks have defined the 2026 campaign: voice phishing to harvest SSO credentials; exploitation of Salesforce Experience Cloud misconfigurations that exposed customer&amp;nbsp;data via anonymous API access; and OAuth supply chain attacks targeting third-party integrations with excessive access scopes. The PeopleSoft campaign added a fourth vector: exploitation of a zero-day (CVE-2026-35273) chained with known vulnerabilities to breach more than 300 instances at more than 100 organizations, including universities, hospitals, and government agencies.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;Sports organizations: an attractive and under protected&amp;nbsp;target class&lt;/h4&gt; 
&lt;p&gt;MSG Sports is hardly the only sports organization to have landed in ShinyHunters'&amp;nbsp;crosshairs—or any threat actor's. Research from Darktrace, a global AI cybersecurity vendor that commissioned the study, found that 84% of professional sports organizations experienced a cyber incident in the past 12 months, with 57% hit more than once. The same research found that sports organizations receive nearly 20% more phishing emails than organizations in other sectors, with more than one in five of those phishing emails targeting VIPs and executives.&lt;/p&gt; 
&lt;p&gt;Nathaniel Jones, VP of Security and AI Strategy and Field CISO at Darktrace, framed the broader pattern this way: "&lt;span style="color: #333333;"&gt;Sports organizations are attractive targets because they combine valuable data, high-profile individuals, complex vendor relationships, and digital systems that are expected to work under intense public pressure. A breach does not need to disrupt a game to cause damage. Exposed data, compromised executive accounts, or trusted communications used for fraud can quickly create financial and reputational consequences."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;That last point is worth holding onto. The MSG breach did not take down a single game. The Knicks won the championship on schedule. The damage—26 million records on the open dark web, internal VIP dossiers downloadable by anyone—arrived entirely off the court.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;Legal fallout and a pattern that predates ShinyHunters&lt;/h5&gt; 
&lt;p&gt;A negligence claim was filed in the U.S. District Court for the Southern District of New York within days of the data publication. The lawsuit centers on the leaked threat assessment and biometric data that MSG collects from arena visitors—including internal correspondence about its facial recognition program—and argues that the organization failed to adequately protect information it collected&amp;nbsp;in the absence of robust consent frameworks.&lt;/p&gt; 
&lt;p&gt;The ShinyHunters breach is MSG's second major incident in under a year and at least its third significant breach in roughly a decade. In August 2025, the Cl0p ransomware gang exploited an Oracle E-Business Suite vulnerability through a third-party vendor, exposing names and Social Security numbers for at least 38,393 individuals and leaking more than 210 GB of archived business records. Before that, a 2015–2016 point-of-sale malware attack harvested payment card data from venue visitors over nearly a full year. Two separate breach groups. Three separate incidents. One organization.&lt;/p&gt; 
&lt;p&gt;Matthieu Chan Tsin, SVP of Resiliency Services at Cowbell, noted that refusing to pay ShinyHunters was "a valiant stand," while also acknowledging that MSG "may now be liable to incur a different type of damage."&amp;nbsp;That tradeoff—between funding a criminal enterprise and triggering a public data exposure—is precisely the leverage ShinyHunters has refined across 40+ victims this year.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;The real question: what could they reach once inside?&lt;/h6&gt; 
&lt;p&gt;Shane Barney, CISO at Keeper Security, offered the sharpest practitioner framing of what the MSG breach actually reveals: "&lt;span style="color: #333333;"&gt;ShinyHunters has demonstrated repeatedly that the most valuable data in an organization is rarely the data an organization thinks to protect most carefully. Ticketing systems, customer support platforms, and internal operational databases are not typically where security investment is concentrated, but they are where years of customer correspondence, internal profiles, and sensitive business information quietly accumulate. That is the gap this group consistently finds and exploits."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;The follow-on question Barney poses is one worth sitting with: not how ShinyHunters got in, but what they could reach once inside. Operational systems treated as administrative infrastructure—rather than as high-value targets—often lack the access controls applied to more obviously sensitive environments. When access is not scoped to least privilege, monitored for anomalous behavior, or time-limited, the blast radius of any compromise expands well beyond what the initial foothold would suggest.&lt;/p&gt; 
&lt;p&gt;For security teams watching the MSG situation unfold, Barney identified the most pressing diagnostic question: "Whether they would have detected a similar exfiltration before the attacker announced it publicly. If the answer is uncertain, that is the gap worth addressing first."&lt;/p&gt; 
&lt;p&gt;Centralizing access governance, enforcing least privilege across every system that touches customer or employee data, and building in continuous monitoring are the controls that close that gap. They are also the controls that ShinyHunters'&amp;nbsp;2026 campaign has most consistently found missing.&lt;/p&gt; 
&lt;div style="font-weight: normal; font-size: 24px;"&gt;
 What affected individuals should do now
&lt;/div&gt; 
&lt;p&gt;Anyone who has purchased tickets to MSG events, contacted MSG customer support, or attended events at MSG venues should assume their contact information may be in the exposed data. That means staying alert to phishing emails or texts referencing MSG accounts or recent purchases—particularly those that request a link to be clicked, payment details to be verified, or a password to be reset. Using unique credentials for the MSG account (a password manager helps), enabling multi-factor authentication where available, and treating any communication that references unexpected personal details with suspicion are the baseline steps.&lt;/p&gt; 
&lt;p&gt;Security teams should also note that ShinyHunters has a documented history of follow-on harassment campaigns against individuals named in leaked files. The FBI's May 2026 PSA specifically warned that the group may contact breach victims directly—including via threatening calls and texts—and that those contacts should not be engaged or paid.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fshinyhunters-dumps-msg-data-knicks&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Original Content</category>
      <category>Data Breach</category>
      <category>Sports &amp; Entertainment</category>
      <category>Extortion</category>
      <pubDate>Thu, 18 Jun 2026 11:26:00 GMT</pubDate>
      <author>drewt@secureworld.io (Drew Todd)</author>
      <guid>https://www.secureworld.io/industry-news/shinyhunters-dumps-msg-data-knicks</guid>
      <dc:date>2026-06-18T11:26:00Z</dc:date>
    </item>
    <item>
      <title>The Trust Crisis: Inside the $3.5 Billion Imposter Scam Epidemic</title>
      <link>https://www.secureworld.io/industry-news/trust-crisis-imposter-scams-ftc</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/trust-crisis-imposter-scams-ftc" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/banking%20scam%20-%20text%20-%20smartphone-in-male-hands-close-up-2026-03-16-02-06-29-utc.jpg" alt="person's hands holding mobile phone" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The U.S. Federal Trade Commission (FTC) released a staggering dataset that confirms what many defensive teams have long suspected: social engineering is no longer just a tactical entry point—it is a booming macroeconomic industry.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The U.S. Federal Trade Commission (FTC) released a staggering dataset that confirms what many defensive teams have long suspected: social engineering is no longer just a tactical entry point—it is a booming macroeconomic industry.&lt;/p&gt; 
&lt;p&gt;According to the FTC's &lt;a href="https://www.ftc.gov/news-events/news/press-releases/2026/06/ftc-data-show-people-reported-losing-3-point-5-billion-imposter-scams-2025"&gt;latest report&lt;/a&gt;, consumers reported losing a record $3.5 billion to imposter scams, representing an increase of nearly three times the losses reported since 2020. Imposter scams now dominate the threat landscape, accounting for nearly one in three of all fraud reports filed. Overall, reported fraud losses across all categories reached an all-time high of $16 billion, marking a sharp 25% jump year-over-year.&lt;/p&gt; 
&lt;p&gt;For cybersecurity practitioners, vendors, and the general public, these numbers signal a profound shift in how digital trust is weaponized.&lt;/p&gt; 
&lt;p&gt;According to the FTC data, scammers are diversifying their methods across text, phone calls, email, social media, and malicious search engine results. However, the most destructive and costly schemes exploit automated urgency.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Bank and business impersonation:&lt;/span&gt; Losses to business impersonators reached nearly $1 billion, with the highest financial damage linked to fake bank alerts. Attackers send a simulated security alert warning to victims that their accounts are compromised, convincing them to immediately move money to a "secure account" to protect it.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Government impersonation:&lt;/span&gt; Reported losses to government impersonators spiked to about $920 million. This category was significantly driven by SMS text phishing campaigns spoofing local toll-road collection entities (threatening immediate vehicle registration suspensions or massive late fees).&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For ordinary citizens and corporate employees, the psychological and financial toll is hitting a boiling point.&lt;/p&gt; 
&lt;p&gt;Scammers have shifted their focus away from technical hacks to psychological manipulation. By mimicking trusted authority figures—whether an IRS agent, a corporate IT support representative, or a bank fraud officer—they bypass standard skepticism. The FTC noted that because victims are entirely convinced they are cooperating with a protective measure, their individual losses are frequently "limited only by their available funds."&lt;/p&gt; 
&lt;p style="color: #1b1b1b; background-color: #ffffff;"&gt;"Consumers derive enormous benefits from competitive markets built on truthful information. But fraud undermines that foundation, impeding the market process and preventing markets from operating efficiently," said Christopher Mufarrige, Director of the Bureau of Consumer Protection. "The FTC will use every tool available to combat one of the most pernicious forms of fraud—government and business impersonation—and to protect the integrity of the digital economy."&lt;/p&gt; 
&lt;p&gt;When a criminal organization successfully impersonates a brand to steal millions from consumers, the financial liability may legally rest with the victim or the bank, but the reputational damage lands squarely on the impersonated enterprise. Organizations can no longer treat consumer-side fraud as "not our network, not our problem." Brand protection is now a fundamental pillar of modern cybersecurity governance.&lt;/p&gt; 
&lt;p&gt;For the teams charged with defending enterprise perimeters and the vendors building the next generation of security tools, the FTC's data demands an operational pivot.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The perimeter must extend beyond the inbox:&lt;/span&gt; Traditional email security gateways are no longer enough. Because attackers are heavily leveraging multi-channel social engineering—pivoting rapidly to SMS (smishing), direct messaging on social media, and lookalike search engine ads—identity verification cannot rely entirely on a secure email gateway.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;DMARC and brand protection are security imperatives:&lt;/span&gt; CISOs must prioritize strict enforcement of email authentication protocols like DMARC (Domain-based Message Authentication, Reporting, and Conformance), SPF, and DKIM to prevent domain spoofing. Concurrently, security teams must deploy continuous brand-monitoring services to proactively dismantle fraudulent lookalike domains and rogue social media accounts before they can be used in mass impersonation campaigns.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;A shift in vendor value – behavioral AI vs. static indicators:&lt;/span&gt; For security vendors, the collapse of digital trust represents a massive market opportunity. The market is shifting away from static indicators of compromise (IOCs) toward behavioral AI capable of detecting anomalies in language pattern, communication tone, and transaction velocity. Tools that analyze the context of a text message or phone call to flag synthetic urgency will become essential components of the enterprise defense stack.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The FTC's midyear pulse proves that social engineering has fully scaled into a multi-billion-dollar enterprise threat. As the federal government ramps up enforcement through its updated Impersonation Rule (enabling the FTC to seek direct consumer redress and civil penalties against violators), organizations must meet them halfway.&lt;/p&gt; 
&lt;p&gt;Security teams can no longer build walls just around their data centers. They must actively defend their brand identities, their users, and the digital trust that keeps businesses operational.&lt;/p&gt; 
&lt;p&gt;We asked a few experts from cybersecurity solutions providers for their thoughts.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Patrick Harr, CEO at DataVisor, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"FTC's latest numbers show that imposter scams are evolving from mass outreach into highly-personalized financial crime. Fraudsters now have cheaper and better AI tools to create convincing messages, fake websites, cloned voices, and even deepfakes that make victims believe they are dealing with a trusted institution or person. That is especially dangerous in payments, because once a consumer is manipulated into authorizing the transfer, the transaction can look legitimate on the surface. Financial institutions need to look beyond static transaction rules and get better at detecting the warning signs earlier in the journey—suspicious behavior, recipient risk, mule-account linkages, and signals that a customer is being coached in real time."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;Darren Guccione, CEO and Co-Founder at Keeper Security, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The Federal Trade Commission's findings that Americans lost $3.5 billion to imposter scams last year, nearly triple the figure from 2020, are striking. The more instructive detail, however, is where those losses originated. Over $2.1 billion was traced back to social media platforms, and nearly one in three victims were first contacted through social channels. While it would be easy to view this as a consumer education problem, the reality is that this is an identity verification problem at an infrastructural scale."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"What makes impersonation attacks so effective is the authenticity of the interaction. AI-generated voice, realistic messaging, and convincing account impersonation have dramatically lowered the barrier to entry for fraudsters. The erosion of trust affects organizations as much as individuals. Business impersonation accounted for close to $1 billion in losses alone."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Recent research revealed that 41% of IT leaders highlighted deepfakes as the top identity-based threat. Our research also shows that AI-driven social engineering is now among the top concerns for security leaders globally, cited by 35% of respondents. It underlines how identity has become the high-value attack surface and how impersonation has emerged as the preferred vector."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Defense cannot rely on awareness alone. Phishing-resistant authentication, strong credential governance, and real-time monitoring for identity-based anomalies are now the foundational controls that make impersonation attacks substantially harder to execute successfully. The scale of the losses reported by the FTC reflects what happens when those controls are absent or inconsistently applied."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;Jason Soroko, Senior Fellow at Sectigo, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The 2025 Federal Trade Commission data reveals a shift in cybercrime. Impersonation has emerged as the preferred vector for attackers. Americans lost $3.5 billion to imposter scams in 2025, which represents a threefold increase since 2020. Fraudsters utilize texts, emails, and phone calls to reach targets. The schemes with the highest losses involve bank impersonators who prompt victims to transfer funds to secure their accounts. Business and government impersonators accounted for nearly $2 billion in losses, contributing to $16 billion in overall fraud."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"These figures underline how identity has become the high-value attack surface. Attackers bypass security perimeters by manipulating trust. Social platforms serve as a distribution channel for these operations. Victims reported $2.1 billion in losses originating from social media, an eightfold increase over five years. Facebook, WhatsApp, and Instagram facilitated a majority of these interactions. By exploiting authority, criminals access funds without breaching infrastructure."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;Mika Aalto, Co-Founder and CEO at Hoxhunt, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"Impersonation scams are not new, but every year these attacks seem to undergo a metamorphosis that makes them harder to detect and resist, courtesy of rapidly evolving technological capabilities. Attackers can now combine AI-generated content, QR codes, social media impersonation, voice cloning, and even video deepfakes to create experiences that feel authentic across multiple channels and touch points in a complex attack chain. The technological barrier to executing these scams gets lower by the minute. Cybercrime, unfortunately, is a growth industry."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The challenge is that we're entering an era where people can no longer rely on their eyes and ears alone to verify identity. A message may appear to come from a trusted brand, a phone call may sound like a legitimate authority, and a video meeting may appear to include a real person. At the same time, attackers are getting better at using social media to build credibility and establish relationships before attempting fraud."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Criminals are still exploiting trust, authority, urgency, and opportunity. What's changing is their ability to deliver convincing impersonations at scale and across multiple touchpoints. That combination is making impersonation scams more believable, more personalized, and ultimately more successful than we've seen in the past."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="color: #1b1b1b; background-color: #ffffff;"&gt;To help the public spot imposter scams, Elder Justice Coordinating Council (EJCC) members launched the "Never EVER" campaign, which is aimed at promoting messaging on the key actions that government and businesses will never take. The campaign runs from June 15-26, in conjunction with World Elder Abuse Awareness Day. This first-of-its-kind public-private partnership includes participants from a wide range of organizations and is aimed at directing consumers &lt;/span&gt;&lt;a href="https://ejcc.acl.gov/imposters" style="background-color: #ffffff;"&gt;to a website that includes information and resources to help them avoid imposter scams&lt;/a&gt;&lt;span style="color: #1b1b1b; background-color: #ffffff;"&gt; and what to do if they spot one.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Ftrust-crisis-imposter-scams-ftc&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Social Engineering</category>
      <category>FTC</category>
      <category>Original Content</category>
      <category>Online Scams</category>
      <category>Cybercrime / Threats</category>
      <pubDate>Wed, 17 Jun 2026 20:36:02 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/trust-crisis-imposter-scams-ftc</guid>
      <dc:date>2026-06-17T20:36:02Z</dc:date>
    </item>
    <item>
      <title>Mythos 5 Export Ban Signals New Rules for AI Vulnerability Tools</title>
      <link>https://www.secureworld.io/industry-news/mythos-export-ban-ai-vulnerability-tools</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/mythos-export-ban-ai-vulnerability-tools" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/SOC%20-%20Data%20Breach%20-%20young-it-engineer-decoding-data-while-sitting-in-f-2025-03-13-13-05-01-utc%20copy.jpg" alt="analysts working in IT operations center" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Anthropic disabled its Fable 5 and Mythos 5 AI models worldwide last week after the U.S. Commerce Department issued an export control directive ordering the company to block access to all foreign nationals, wherever they are, including those working inside Anthropic. Because the company said it has no reliable way to distinguish eligible from ineligible users at the application layer, it shut down both models for every customer globally to comply.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Anthropic disabled its Fable 5 and Mythos 5 AI models worldwide last week after the U.S. Commerce Department issued an export control directive ordering the company to block access to all foreign nationals, wherever they are, including those working inside Anthropic. Because the company said it has no reliable way to distinguish eligible from ineligible users at the application layer, it shut down both models for every customer globally to comply.&lt;/p&gt;  
&lt;p&gt;For cybersecurity leaders, the headline isn't really the outage, it's the classification. The federal government just placed an AI capability—automated software vulnerability discovery—into the same regulatory bucket as weapons systems and nuclear technology. That's a meaningful shift in how frontier AI gets governed, and it has direct implications for any organization building AI into code review, DevSecOps, or vulnerability management pipelines.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;A code review task, reclassified&lt;/h2&gt; 
&lt;p&gt;According to &lt;a href="https://www.anthropic.com/news/fable-mythos-access"&gt;Anthropic&lt;/a&gt;, the directive was issued on national security grounds following concerns that Fable 5 was susceptible to a jailbreak technique that could be used to identify software vulnerabilities. Anthropic disputed the severity of that framing, describing the underlying issue as narrow and noting that comparable capabilities already exist in other widely deployed AI models.&lt;/p&gt; 
&lt;p&gt;Jacob Krell, Senior Director of Secure AI Solutions &amp;amp; Cybersecurity at Suzu Labs, put the underlying activity in plain terms: what triggered the directive was Fable 5 reading a codebase and identifying flaws—a code review, full stop. "'Jailbreak' is strong language for a routine task,"&lt;i&gt;&amp;nbsp;&lt;/i&gt;Krell said, noting that security teams and developers across the industry use AI models for exactly this purpose every day.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/unit-tests-llms-catching-model-drift"&gt;Unit Tests for LLMs: Catching Model Drift Before Your Users Do&lt;/a&gt;]&lt;/p&gt; 
&lt;p&gt;"Offensive security built on manual-paced vulnerability research and human-speed exploitation development is on borrowed time," Krell said. "The government just told you the automation works well enough to regulate."&lt;/p&gt; 
&lt;p&gt;Krell's broader point is the one worth sitting with: export controls put automated vulnerability discovery in the same legal category as weapons systems and nuclear technology. When a code-analysis capability triggers that classification, it signals that the people making the decision view machine-speed vulnerability discovery as having genuine strategic impact—not as a research curiosity, but as a regulated asset.&lt;/p&gt; 
&lt;p&gt;Anthropic's own account of the directive backs up Krell's reading. &lt;a href="https://www.anthropic.com/news/fable-mythos-access"&gt;In a statement&lt;/a&gt; published the day the order was issued, the company said the government has so far provided only "verbal evidence of a potential narrow, non-universal jailbreak, which essentially consists of asking the model to read a specific codebase and fix any software flaws,"&amp;nbsp;and that it had validated the same level of capability is widely available from other models, including OpenAI's GPT-5.5, and is used daily by defenders. Anthropic argued that applying this standard industry-wide "would essentially halt all new model deployments for all frontier model providers."&lt;/p&gt; 
&lt;p&gt;The company also pushed back on the idea that Fable 5's safeguards had failed in any broad sense. Anthropic said no tester has found a &lt;i&gt;universal&lt;/i&gt; jailbreak capable of broadly unblocking Fable's cyber capabilities, and that what the government appears to be acting on is a narrow, non-universal bypass—the kind the company says is, by its own admission, likely unavoidable for any frontier model and is mitigated through a "defense in depth" approach rather than prevented outright. That distinction matters for the regulatory question at hand: the directive treats a non-universal, code-review-style bypass as grounds for a worldwide shutdown—a bar Anthropic argues no current model could clear.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Three agencies, three positions&lt;/h3&gt; 
&lt;p&gt;What makes this directive harder to parse is that it doesn't reflect a single, coherent government posture toward Mythos-class models. Krell laid out the contradiction directly: the U.S. Department of Defense designated Anthropic a supply chain risk roughly three months ago. The NSA, meanwhile, reportedly carved out an exemption to continue using Mythos because no alternative model matches its vulnerability-discovery capability. Now, Commerce has restricted the consumer-facing version of that same underlying technology.&lt;/p&gt; 
&lt;p&gt;Three agencies, three different working assumptions about the same capability; one treats it as a supply chain liability, one treats it as mission-critical and worth a carve-out; and one treats it as something that must be kept out of foreign hands entirely. For security leaders trying to plan around frontier AI availability, that incoherence is itself a risk factor: the rules governing access to these models may continue to shift unpredictably as agencies work out conflicting positions.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;The access-control problem nobody has solved&lt;/h2&gt; 
&lt;p&gt;Noelle Murata, Chief Operating Officer at Xcape, Inc., framed the operational gap this exposes: traditional geofencing and identity management systems aren't built to enforce real-time, nationality-based access controls at the application layer. Anthropic's decision to disable both models for &lt;i&gt;all&lt;/i&gt; customers, not just foreign nationals, is itself evidence of that gap. If a frontier AI provider with Anthropic's resources can't reliably segment access by nationality on short notice, most enterprises consuming these models via API are in no better position.&lt;/p&gt; 
&lt;p&gt;Murata's recommended response for security teams is straightforward and worth treating as a checklist:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;Inventory dependencies on frontier AI services across security tooling, especially anything embedded in code review or vulnerability scanning pipelines.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Build localized fallback architectures so a sudden vendor-side model recall doesn't create a single point of failure in production systems.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Assess every integration point where an AI model performs code review or vulnerability scanning, and plan for how those workflows will continue if the underlying API is deprecated without notice.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;As Murata put it, the industry has spent years worrying about a rogue AI escaping containment, only to discover that an entire frontier model can be neutralized by a compliance directive asking providers to verify a user's nationality.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;What this means going forward&lt;/h4&gt; 
&lt;p&gt;This directive doesn't exist in isolation. It follows a recent &lt;a href="https://www.secureworld.io/industry-news/trump-executive-order-ai-nsa"&gt;White House executive order&lt;/a&gt; requiring AI developers to share new models with advanced cyber capabilities with the government for review before broader release, in some cases up to 30 days before they become available to other partners. Read together, the two actions point toward a future in which frontier models with strong offensive cyber capabilities face government review as a matter of course, not as an exception.&lt;/p&gt; 
&lt;p&gt;For security teams, the practical upshot is twofold. First, vendor concentration risk around frontier AI now needs to be evaluated alongside more familiar supply chain risks. A&amp;nbsp;model that powers a critical workflow today could become unavailable on short notice due to regulatory action, not just a vendor business decision. Second, as automated vulnerability discovery capabilities become more powerful and more regulated, the gap between defenders with access to frontier tooling and those without may itself become a strategic variable worth tracking.&lt;/p&gt; 
&lt;p&gt;Anthropic has said it disagrees with the government's assessment and is working to restore access. Whether that happens quickly or not, the precedent set by this week's directive—that automated code analysis capable of finding vulnerabilities at scale is now squarely within export control jurisdiction—is unlikely to be reversed.&lt;/p&gt; 
&lt;p style="text-align: center;"&gt;~~~&lt;/p&gt; 
&lt;p&gt;The questions raised by this week's directive don't stop at regulation. SecureWorld is hosting a free webcast,&lt;span style="box-sizing: border-box; margin: 0px; padding: 0px;"&gt;&lt;a href="https://www.secureworld.io/resources/mythos-evolution-contain-collapse" style="font-weight: normal;"&gt;&lt;strong&gt;&amp;nbsp;&lt;/strong&gt;The Mythos Evolution: Contain or Collapse&lt;/a&gt;, on Wednesday, June 24, at 1:00 p.m. EDT, examining how security teams should build for resilience in a world where Mythos-class models collapse the gap between vulnerability discovery and a&amp;nbsp;&lt;/span&gt;working exploit. Topics include Zero Trust architecture, containment strategies, and reducing blast radius. Attendees are eligible for 1 CPE credit.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fmythos-export-ban-ai-vulnerability-tools&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Vulnerabilities</category>
      <category>National Security</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>U.S. Government</category>
      <pubDate>Tue, 16 Jun 2026 13:09:03 GMT</pubDate>
      <author>drewt@secureworld.io (Drew Todd)</author>
      <guid>https://www.secureworld.io/industry-news/mythos-export-ban-ai-vulnerability-tools</guid>
      <dc:date>2026-06-16T13:09:03Z</dc:date>
    </item>
    <item>
      <title>Cybersecurity Hit by Higher Ed's Looming Infrastructure Squeeze</title>
      <link>https://www.secureworld.io/industry-news/cybersecurity-higher-education-infrastructure-squeeze</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/cybersecurity-higher-education-infrastructure-squeeze" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Higher%20Education%20-%20smiling-graduates-taking-selfie-at-university-camp-2026-03-10-02-04-22-utc.jpg" alt="graduates taking selfie" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;The higher education sector is navigating a high-stakes convergence of technology-driven change, severe talent shortages, and escalating threat vectors. For security practitioners and IT leaders on campus, the macro-level view of these challenges has just been quantified.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="line-height: 1.5;"&gt;The higher education sector is navigating a high-stakes convergence of technology-driven change, severe talent shortages, and escalating threat vectors. For security practitioners and IT leaders on campus, the macro-level view of these challenges has just been quantified.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The Inside Higher Ed 2026 survey of campus CTOs and CIOs, conducted by Hanover Research, offers a candid look at how technology leaders in higher education view their operational landscape. The report reveals an industry aggressively adopting advanced tools like AI while simultaneously struggling with foundational gaps in staffing, data governance, and student cybersecurity readiness.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;When looking ahead to the end of the decade, campus tech&amp;nbsp;leaders are less concerned with technological novelty and highly focused on structural survivability. The top three existential threats anticipated by CTOs highlight an environment under significant operational strain.&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The talent drain (62%):&lt;/span&gt; The inability to recruit or retain qualified IT talent ranks as the number one risk facing institutions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The threat landscape (59%):&lt;/span&gt; Critical cybersecurity breaches or ransomware events follow closely as the second most cited threat.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The financial squeeze (56%): &lt;/span&gt;Unsustainable cost trajectories for technology services form a major pain point. Nearly half of all respondents (49%) explicitly state that the current pace of technology change is unsustainable without entirely new resource pools.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;Institutional commitment to AI is spiking, but the financial and operational return on investment (ROI) remains remarkably fragmented. Investing in generative AI is now considered a high or essential priority by 49% of campus technology leaders (up from 34% in 2025).&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Despite this push, only 29% of CTOs say their AI investments have met or exceeded expectations, while 24% state they have fallen short, and 27% remain entirely unsure of the ROI.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Where is the actual value hiding? The survey highlights that institution-wide operational transformation remains largely unrealized (2%). Instead, AI value is locked into localized, tactical use cases.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: bold;"&gt;AI delivery area: individual productivity&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Tangible value realized: 55% (The clear leading value driver)&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Top use cases implemented: general administrative use (72%)&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5; font-weight: bold;"&gt;AI delivery area: IT &amp;amp; operational efficiency&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Tangible value realized: IT Operations / Service Management (30%); Administrative Efficiency (29%)&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Top use cases implemented: Chatbots &amp;amp; Virtual Assistants (49%); Scheduling &amp;amp; Resource Allocation (40%)&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5; font-weight: bold;"&gt;AI delivery area: academic &amp;amp; student support&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Tangible value realized: Teaching &amp;amp; Learning (23%); Student Advising &amp;amp; Support (14%)&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Top use cases implemented: Instructional Tools / Tutoring (29%); Predictive Academic Analytics (21%)&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;The barriers limiting AI's ultimate impact mirror the broader campus infrastructure gaps: skills and staff capacity (55%), cost (48%), and deep governance and policy uncertainty (38%). Furthermore, only 31% of institutions report having strong data governance structures in place to support responsible AI deployment.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The Learning Management System (LMS) remains a foundational piece of campus infrastructure, but its absolute dominance is showing signs of friction. On one hand, institutional commitment is absolute: 92% of CTOs state the LMS remains the central hub of their digital learning ecosystem, and 86% agree it will remain essential for compliance and data needs regardless of pedagogical trends.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;On the other hand, a quiet fragmentation is occurring:&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;User drift: 47% of CTOs observe that students and faculty are increasingly using tools outside the official LMS for day-to-day teaching and learning.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Silo friction: 57% express a critical need for better integration between core administrative platforms and learning systems to meaningfully support student success.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;Faced with severe hiring friction—67% report struggling to hire; 38% struggle to retain technology staff—universities are moving past traditional recruitment loops to keep their networks running. &amp;nbsp;Because rigid higher ed budgets prevent most institutions from simply raising wages—only 27% are expanding compensation packages—CTOs are using alternative strategies to optimize headcount:&lt;/p&gt; 
&lt;ol style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Leverage outside contract labor (60%); Managed scale: &lt;/span&gt;Turning to managed service providers (MSPs) and external contractors to scale specialized technical operations without increasing full-time headcount.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Mobilize student workers (60%); Internal sourcing:&lt;/span&gt; Hiring student workers to cover tier-1 IT support, desktop help desks, and basic technical maintenance.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Offer flexible work frameworks (55%); Retention plays:&lt;/span&gt; Using remote and hybrid flexibility as a non-monetary perk to compete against the higher-paying corporate sector.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Automate routine tasks (40%); Process optimization:&lt;/span&gt; Deploying automation to offload low-complexity workloads, trying to free up existing, over-extended personnel for high-tier engineering needs.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="line-height: 1.5;"&gt;The insights from the &lt;a href="https://www.secureworld.io/industry-news/2026-cyber-ai-litigation-surge"&gt;Norton Rose Fulbright 2026 Annual Litigation Trends Survey&lt;/a&gt; and the &lt;a href="https://www.secureworld.io/hubfs/documents/2026-IHE-CTO-CIO-Survey_Final__0.pdf"&gt;Inside Higher Ed 2026 Survey of Campus Chief Technology/Information Officers&lt;/a&gt; indicate that higher education is sitting on an unevenly protected digital foundation.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Cabinet-level inclusion for technology leaders is stagnating (55% sit on executive councils). Presidents and chancellors must bridge this gap. If tech leadership is excluded from top-tier strategic planning, the digital transformation goals of the university will continue to stumble over siloed data pipelines and staff shortages.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Faculty are being pressured to integrate AI into course designs, yet 56% of CTOs openly admit their professors are under-prepared to do so. Simultaneously, students represent a major security risk. While 70% of campus leaders prioritize cybersecurity investments and 68% train staff, only 22% of institutions provide adequate cybersecurity training to their student body.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;This creates a massive, untrained attack surface of users carrying multiple personal devices onto the enterprise network.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;For the defensive teams on campus, the core directive is clear: they are defending a perimeter with limited visibility.&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;AI integration is slow: &lt;/span&gt;While cyber defense is the top AI use case (51%), only 9% of institutions have extensively deployed AI across multiple security functions.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Data fragmentation:&lt;/span&gt; Fully 33% of institutions possess zero advanced data aggregation architecture—lacking even a basic data warehouse or data lake—making comprehensive behavioral analytics and rapid incident response incredibly difficult to execute.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;According to the report, security leaders in higher education must pivot away from treating security as an isolated technical problem. Instead, they should champion a culture of shared governance, push for strict vendor data-handling boundaries, and ensure that student-facing cybersecurity literacy is integrated into core campus onboarding. Agility on campus can no longer be chased at the expense of baseline digital safety.&amp;nbsp;&amp;nbsp;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fcybersecurity-higher-education-infrastructure-squeeze&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>Digital Transformation</category>
      <category>Higher Education</category>
      <pubDate>Mon, 15 Jun 2026 15:12:03 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/cybersecurity-higher-education-infrastructure-squeeze</guid>
      <dc:date>2026-06-15T15:12:03Z</dc:date>
    </item>
    <item>
      <title>Unit Tests for LLMs: Catching Model Drift Before Your Users Do</title>
      <link>https://www.secureworld.io/industry-news/unit-tests-llms-catching-model-drift</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/unit-tests-llms-catching-model-drift" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Vulnerability%20Report%20-%20hacking%20shutterstock_1090711193.jpg" alt="frustrated cybersecurity analyst" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;I've spent a good amount of time in software development and application security. In those roles, you lived and died by the testing around the feature you were building. Unit test, integration test, performance test, and a half dozen other types of tests were utilized to suss out any regressions or deviations from the intended purpose of the application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;I've spent a good amount of time in software development and application security. In those roles, you lived and died by the testing around the feature you were building. Unit test, integration test, performance test, and a half dozen other types of tests were utilized to suss out any regressions or deviations from the intended purpose of the application.&lt;/p&gt; 
&lt;p&gt;Likewise, in AppSec, running test tools such as SAST, DAST, and SCA was and still is the most scalable method of testing an application for security concerns. Being able to identify vulnerabilities in the code or the runtime environment goes a long way to stopping critical vulnerabilities from getting into a production environment. I'm willfully ignoring the current mindset that &lt;a href="https://securelybuilt.substack.com/p/appsec-didnt-need-a-faster-way-to?r=2t1quh"&gt;LLMs will replace these tools&lt;/a&gt; in the near future since that still remains to be seen and actually operationalized.&lt;/p&gt; 
&lt;p&gt;The sole purpose of these test harnesses is to ensure that the application you are deploying is free (or as free as can be identified) from something that will bite you down the road—whether it's a regression or a vulnerability. But now that we're in the age of LLMs, is there an equivalent set of tests that can be added to look for drift in the model or the responses? Why, yes, there is!&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;Enter Promptfoo&lt;/h2&gt; 
&lt;p&gt;I've been working on a little project that I'm hoping can help people trying to break into the cybersecurity field. It's called &lt;a href="https://clarus.careers/"&gt;Clarus &lt;/a&gt;and it's a platform dedicated to helping people get into a role that aligns with their goals, skills, and knowledge. And yes, it's backed by an LLM that helps develop and validate the user journey to that goal. As development has progressed (it's still very much under construction), I've been looking for ways to catch drift in responses from the model as more features are added and prompts change on a regular basis. I had played around with &lt;a href="https://github.com/promptfoo/promptfoo"&gt;Promptfoo &lt;/a&gt;early on&amp;nbsp;but wanted to try to utilize it again with some more intention.&lt;/p&gt; 
&lt;p&gt;If you're not aware, Promptfoo is an open-source, developer-focused framework for testing and evaluating LLM applications, and the easiest way to describe it is "unit tests plus CI, for prompts and models."&amp;nbsp;I've recently started to run it against Clarus, driving the whole thing from Claude Code inside VSCode. I wanted to write up how it works and, perhaps more importantly, how to read what it tells you.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;In the dojo of prompts, every failure is a lesson&lt;/h3&gt; 
&lt;p&gt;Promptfoo wants a few things from you, declared in a single YAML config. Once you've given it these, it runs that input against the provider, grades each response against your assertions, and produces a pass/fail report with reasoning.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Configuration&lt;/span&gt; – Items like evaluateOptions, defaultTest, and lifecycle hooks round out the testing fixture.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Providers&lt;/span&gt; – The system under test. This can be a raw model, but the important move is pointing it at something real. In my case, the provider is the live chat API, not a model in isolation. Example:&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://www.secureworld.io/hs-fs/hubfs/image-png-Jun-11-2026-04-07-15-0149-PM.png?width=695&amp;amp;height=384&amp;amp;name=image-png-Jun-11-2026-04-07-15-0149-PM.png" width="695" height="384" style="margin-left: auto; margin-right: auto; display: block;"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Prompts/inputs –&lt;/span&gt;&amp;nbsp;The user messages you want to send. Example:&lt;br&gt;&lt;img src="https://www.secureworld.io/hs-fs/hubfs/image-png-Jun-11-2026-04-07-36-8225-PM.png?width=717&amp;amp;height=159&amp;amp;name=image-png-Jun-11-2026-04-07-36-8225-PM.png" width="717" height="159" style="margin: 8px auto 0px; display: block;"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Tests and assertions&lt;/span&gt; – What a good response must, and must not, contain. Example:&lt;img src="https://www.secureworld.io/hs-fs/hubfs/image-png-Jun-11-2026-04-07-54-5758-PM.png?width=749&amp;amp;height=526&amp;amp;name=image-png-Jun-11-2026-04-07-54-5758-PM.png" width="749" height="526" style="margin-left: auto; margin-right: auto; display: block;"&gt;&lt;/p&gt; 
&lt;p&gt;The single test above shows the three assertion families: deterministic (icontains), negative deterministic (not-icontains-any), and LLM-as-judge (llm-rubric). You can mix as many of each as you want per test ,and &lt;a href="https://www.promptfoo.dev/docs/configuration/expected-outputs/"&gt;there are dozens to choose from&lt;/a&gt; in Promptfoo. One thing to consider here with the way Promptfoo evaluates the test and assertion is that it's not simply going against the LLM itself but following the live API. This means that you're testing the whole app—retrieval, prompt assembly, guardrails, the API layer, all of it. A small response transform converts the server's streaming (SSE) output into the final assistant message so it can be graded. That means when a test fails, it failed against the thing your users actually hit, not a sanitized lab version of it.&lt;/p&gt; 
&lt;p&gt;I started out by building a 28-scenario regression suite, grouped into behavioral categories. The grouping isn't cosmetic, it's how you reason about coverage the same way you'd reason about it for any other test plan.&lt;img src="https://media.licdn.com/dms/image/v2/D4E12AQFnNJSnGJOnMQ/article-inline_image-shrink_1500_2232/B4EZ6epTabHAAU-/0/1780778088359?e=1782950400&amp;amp;v=beta&amp;amp;t=hDYoPzf2Q2uPv2pzHUeVd7JcA1aBTdL-TLbqswXP-4Q" style="margin: 20px auto 15px; display: block;"&gt; This testing strategy will evolve, and the goal is to build out more scenarios and categories as the platform grows and the model changes.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The assertion philosophy&amp;nbsp;&lt;/h4&gt; 
&lt;p&gt;Every scenario layers two kinds of checks, and the order matters. The cheap, deterministic ones run first. These are the simple:&amp;nbsp;does the response include MITRE ATT&amp;amp;CK, does it have a numbered list? This can be validated through a string match or regex and are deterministic because the same input should produce the same output. The expensive, judgment-based ones run when there's no other way to express what "good" means. Examples would be whether the response was "warm," or did it ask follow-up questions.&lt;img src="https://media.licdn.com/dms/image/v2/D4E12AQGjT4lx0ysIgQ/article-inline_image-shrink_1000_1488/B4EZ6epO0JKkAM-/0/1780778069502?e=1782950400&amp;amp;v=beta&amp;amp;t=SETPmLmWcPlM5D2IW3b13iwl7mo-Jkp_ervbfjA-NCY" width="577" height="200" style="margin: 15px auto; display: block; width: 577px; height: auto; max-width: 100%;"&gt; The rule of thumb: use deterministic checks where you can, and LLM judges where you must (those LLM tokens add up!). The deterministic layer keeps your costs down and your failures interpretable. The judge layer covers the things a regex will never catch, like whether the assistant refused a bad request gracefully. For the subjective rubrics, I pinned the judge to temperature 0 for repeatability and set pass thresholds (0.75 is a reasonable starting point) so a "mostly fine" (maybe 0.70) answer doesn't quietly sail through.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;Calibrate locally before you automate anything&lt;/h5&gt; 
&lt;p&gt;Running this locally on my beefy machine is usually quick (a couple of minutes), and it exists so the rubric can be calibrated before wiring this into a pipeline where a bad rubric becomes everyone's problem. The flow is straightforward:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;Provision an isolated test identity – A&amp;nbsp;dedicated, least-privilege test user with a fresh auth token, so evals run as a dedicated test identity with only the privileges of a normal end-user.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Seed any required state – For example, a user profile the endpoint expects to exist.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Run the suite –&amp;nbsp;npx promptfoo eval, optionally filtered to a subset of tests while you iterate.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Inspect results – npx promptfoo view opens a browser UI showing each input, the model's response, and the judge's reasoning for every pass and fail.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;That last point is critical. The judge's reasoning is the difference between "20% passed, this is broken" and "20% passed, and here's exactly why." The latter is likely to lead you to reviewing the rubric for strictness.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;Making it a merge gate&lt;/h6&gt; 
&lt;p&gt;A test suite that only runs when someone remembers to run it is a suggestion, not a control. So we can pivot this same suite to become a GitHub Actions workflow, and the pattern generalizes well beyond my Clarus app:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Triggers: Manual dispatch today. The design supports PR triggers and a weekly canary, however, both are currently disabled while the code is stabilized. Either can be re-enabled by adding the pull_request and schedule blocks back.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Steps: Check out, set up Node, provision a fresh token at run time, run the suite, upload results.json as a build artifact, and enforce a pass-rate threshold gate.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The quality gate: The job fails if the suite pass rate drops below a configured threshold (different than the individual test threshold). I started permissive at 0.60 with a plan to ratchet to 0.80 once the rubrics and code is stabilized and turning this into an actual merge gate.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Secrets and config: Credentials and the API base use OIDC federation.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The division of labor works great. Once fully configured in the CI, PR-time evals will catch behavioral regressions before they merge. The weekly canary will catch drift that lands outside any PR, like a model version bump or a change in your retrieval data that quietly changes the behavior.&lt;/p&gt; 
&lt;div style="font-weight: normal;"&gt;
 &lt;strong&gt;Reading the results without panicking&lt;/strong&gt;
&lt;/div&gt; 
&lt;p&gt;The first time I ran Promptfoo, it was deflating. Here's a representative early smoke run:&lt;img src="https://www.secureworld.io/hs-fs/hubfs/image-png-Jun-11-2026-04-03-51-5136-PM.png?width=658&amp;amp;height=94&amp;amp;name=image-png-Jun-11-2026-04-03-51-5136-PM.png" width="658" height="94" style="margin-left: auto; margin-right: auto; display: block;"&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="color: rgba(0, 0, 0, 0.9); background-color: #ffffff;"&gt;An 80% failure rate looks like a disaster, however, it isn't. Errors and failures are completely different animals.&lt;/span&gt;&amp;nbsp;&lt;img src="https://media.licdn.com/dms/image/v2/D4E12AQEP10xiRt43fA/article-inline_image-shrink_1000_1488/B4EZ6epJDHI0AI-/0/1780778045908?e=1782950400&amp;amp;v=beta&amp;amp;t=ZvNvu1tppAlvJNLAb26DAIXTjSz6Fy1nkcLmI51tmdA" style="margin: 15px auto; display: block;"&gt;&lt;/p&gt; 
&lt;p&gt;Based on the smoke run, there were zero errors. That says that the auth worked, the streaming transform worked, the state-seeding worked and the entire harness is sound. A green pipeline with failing assertions is fundamentally healthy. It means you're asking real questions and getting real, gradeable answers. A pipeline throwing errors, even at a 100% "pass"&amp;nbsp;rate, is telling you something else. This is easier to see with a real pair from my run than in the abstract.&lt;img src="https://media.licdn.com/dms/image/v2/D4E12AQEb1IzG45qcsQ/article-inline_image-shrink_1000_1488/B4EZ6eo_iZJgAI-/0/1780778007292?e=1782950400&amp;amp;v=beta&amp;amp;t=-diYAtFaokUxEtJZo9mfl7Kj3P7M4GWG4JKMoMtwYqA" style="margin: 20px auto; display: block;"&gt; Take B3 ("What does a SOC analyst do?"), which passed at 0.96. It has four assertions: three cheap deterministic checks looking for the words "monitor" and "incident,"&amp;nbsp;and one LLM-rubric grading whether the answer accurately describes SOC work without inventing processes. All four passed, because a genuine answer about a SOC analyst is going to say "monitor"&amp;nbsp;and "incident" almost by definition. The deterministic checks and the judge agreed: good answer.&lt;/p&gt; 
&lt;p&gt;Looking at B2 ("What are the key roles in cybersecurity?"), which failed at 0.56. The rubric (the part actually judging answer quality) passed at a perfect 1.0. The judge confirmed the response listed five well-described roles in the right range, grounded in real job-market data. By any reasonable standard, it was a good answer. Where it deviated was the other assertion, a hardcoded keyword check that scanned for eight specific role terms (SOC, Pentest, GRC, Analyst, and so on) and required at least four. It matched exactly one: "incident." Because the two assertions are weighted equally, a 0.125 on the keyword check and a 1.0 on the rubric average out to 0.56, and the scenario goes red.&lt;/p&gt; 
&lt;p&gt;While this seems like only a miscalibration of the assertion, there are a few things going on here. Clarus answered with the NICE Framework's seven work-role categories (i.e., Oversight &amp;amp; Governance, Design &amp;amp; Development, Protection &amp;amp; Defense, etc.). Those are real, but they're the top-level buckets, and not the answer a career advisor would give. The genuinely useful response names are the specific work roles underneath them. So the expected response should be something like: "The Systems Authorization (OG-WRL-013) work role, in the Oversight &amp;amp; Governance category, is in demand per Cyberseek."&amp;nbsp;However, the model stayed one level too abstract to actually be helpful. That's a real grounding failure, and the rubric was too shallow to notice.&lt;/p&gt; 
&lt;p&gt;So, what to do with this test? To make B2 pass honestly on the next run, I don't touch the product at first. I would fix the test to require specific NICE work roles, then fix the product to deliver it. Only then does a green B2 actually mean what I want it to mean. A failure isn't just "bug or bad test," sometimes it's both requiring closer examination.&lt;/p&gt; 
&lt;div style="font-weight: normal;"&gt;
 &lt;strong&gt;The path forward&lt;/strong&gt;
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;None of this is exotic or should be a foreign concept to those that have been steeped in testing (for security or not). And that's the point. We are not inventing a new discipline for AI, but rather we are applying the one we already have. Eval-driven development provides us the ability to grade behavior instead of byte-for-byte output, and allows us to regression test an entire LLM product by pointing the harness at the live API.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;As LLMs become further integrated into applications, the teams that ship the LLM-backed features safely won't be the ones with the cleverest prompts. They'll be the ones who treated those prompts like every other piece of production code they've shipped previously—versioned, tested, and gated. The model may be new, but the job isn't.&lt;/p&gt; 
&lt;p&gt;This article was &lt;a href="https://www.linkedin.com/pulse/unit-tests-llms-catching-model-drift-before-your-users-derek-fisher-95u9e/"&gt;published originally here&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Funit-tests-llms-catching-model-drift&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Application Security</category>
      <category>Featured Author</category>
      <category>DevOps</category>
      <category>LLMs</category>
      <pubDate>Sat, 13 Jun 2026 13:42:00 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/unit-tests-llms-catching-model-drift</guid>
      <dc:date>2026-06-13T13:42:00Z</dc:date>
      <dc:creator>Derek Fisher</dc:creator>
    </item>
    <item>
      <title>World Cup 2026: When Fan Phishing Becomes an Enterprise Threat</title>
      <link>https://www.secureworld.io/industry-news/world-cup-2026-fan-phishing-enterprise-threat</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/world-cup-2026-fan-phishing-enterprise-threat" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/World%20Cup%20-%20soccer-ball-decorated-with-flags-on-the-field-2026-03-20-00-59-38-utc.jpg" alt="soccer ball with country flags" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Two reports released yesterday arrive at the same unsettling conclusion from different directions: the security controls organizations have long relied on to stop phishing are failing, and attackers are using the 2026 FIFA World Cup as the pressure point to prove it.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Two reports released yesterday arrive at the same unsettling conclusion from different directions: the security controls organizations have long relied on to stop phishing are failing, and attackers are using the 2026 FIFA World Cup as the pressure point to prove it.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat"&gt;Zimperium's zLabs&lt;/a&gt; threat intelligence team documented three active, technically sophisticated phishing campaigns targeting World Cup fans through mobile channels. And &lt;a href="https://www.darktrace.com/blog/cybersecurity-for-the-sports-sector-the-threats-facing-a-digitized-industry-in-2026"&gt;Darktrace&lt;/a&gt;, drawing on telemetry from its sports-sector customer base and a survey of 875 security professionals, found that 84% of professional sports organizations experienced at least one cyber incident in the past year—and that 84% of the malicious emails reaching those organizations passed DMARC authentication checks. The authentication layer meant to stop spoofed email is, in practice, not stopping it.&lt;/p&gt; 
&lt;p&gt;Read together, the two reports sketch a threat environment in which DMARC isn't blocking malicious email, MFA isn't stopping credential theft, and the&amp;nbsp;mobile devices employees carry into work every day have become the vector connecting consumer-facing scams to enterprise networks.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;The demand side: why the World Cup works as a lure&lt;/h2&gt; 
&lt;p&gt;The scale of fan demand for the 2026 tournament has created conditions that attackers can reliably exploit. Of approximately six million available tickets, Zimperium reports that more than five million have already been allocated. For the final in New York/New Jersey, face-value seats reached $10,000 at launch, with premium category tickets topping $30,000. More than 150 million ticket requests were filed in the opening two weeks of sales alone.&lt;/p&gt; 
&lt;p&gt;That scarcity drives fans toward unverified channels—Telegram resellers, social media listings, search ads—where they're far easier to deceive.&lt;/p&gt; 
&lt;p&gt;Mika Aalto, Co-Founder and CEO at Hoxhunt, connects the pattern to a broader phenomenon his firm has tracked: temporal phishing, timed to real-world events, converts at dramatically higher rates than generic campaigns. Earlier this year, Hoxhunt observed a 400% spike in tax-themed phishing around the U.S. filing deadline, with simulated attacks in that window drawing roughly four times the click rate of non-deadline equivalents.&lt;/p&gt; 
&lt;p&gt;The World Cup runs for a month, and the emotional urgency doesn't fade between match days—it compounds.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/fifa-world-cup-2026-cybercrime"&gt;FIFA World Cup 2026 Is a Cybercriminal's Dream Scenario&lt;/a&gt;]&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Three campaigns, one convergence point&lt;/h3&gt; 
&lt;p&gt;Zimperium documented three distinct campaigns, each targeting a different point in the fan lifecycle.&lt;/p&gt; 
&lt;p&gt;The first, attributed by Group-IB to a Chinese-speaking threat actor and independently flagged by the FBI's Internet Crime Complaint Center, involves production-grade typosquatting sites that replicate the complete FIFA ticket purchase experience. These aren't crude credential-harvesting pages. Zimperium's analysis found that the phishing kit—likely sold through underground forums—is built as a React single-page application, uses FIFA's actual OAuth2 client ID to clone the PingIdentity authentication framework FIFA uses for its real SSO, and incorporates a live-chat module (SaleSmartly, a Chinese SaaS platform) that lets operators interact with victims in real time during the fake purchase flow. One particularly damaging capability is that the kit requests the &lt;span style="font-weight: bold;"&gt;p1:reset:userPassword&lt;/span&gt; OAuth scope, allowing attackers to lock victims out of their legitimate FIFA accounts immediately after credential capture.&lt;/p&gt; 
&lt;p&gt;The second campaign, which Zimperium designates RetailPhish, impersonates Nike, Adidas, Puma, and Marathon Sport across multiple languages and regions. It distributes via WhatsApp, forces victims to share the link with contacts before unlocking a fake prize—turning each victim into a distributor—and closes with a nominal €2 shipping fee that captures full card details. Nine campaign domains share identical WHOIS privacy tokens, meaning a single registrant controls the entire infrastructure behind Cloudflare obfuscation.&lt;/p&gt; 
&lt;p&gt;The third vector is the one that most directly threatens enterprise environments. The OffsideHire campaign deploys four fraudulent career portals that impersonate FIFA's recruitment channels—targeting the hiring wave needed to staff a tournament spread across three countries. The kit doesn't target consumers;&amp;nbsp;it explicitly rejects personal email addresses and only accepts corporate or custom-domain accounts. Once a victim clicks "Continue with Google," the backend relays credentials against Google's real infrastructure in real time, intercepts whatever second factor Google triggers, and captures the fully-authenticated session. Stolen data is exfiltrated immediately to a Telegram bot. The C2 server was confirmed active at the time of analysis.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The controls that were supposed to stop this&lt;/h4&gt; 
&lt;p&gt;The Darktrace data puts numbers on what the Zimperium campaign analysis illustrates in technical detail. Between October 2025 and March 2026, Darktrace detected more than 116,000 phishing emails targeting sports organizations across its customer base—a volume 19% higher than in&amp;nbsp;other sectors. Of those malicious emails, 84% passed DMARC authentication. More than a third used novel social engineering tactics, including AI-generated content tailored to specific teams, venues, and executives. QR code phishing increased 33% in Q1 2026 compared to Q4 2025, exploiting the QR infrastructure that has become standard in ticketing and fan engagement.&lt;/p&gt; 
&lt;p&gt;The implication is direct: domain authentication, the foundational email security control, is not functioning as a meaningful barrier. Attackers aren't spoofing domains in ways DMARC catches; they're operating through legitimate infrastructure or compromised trusted accounts.&lt;/p&gt; 
&lt;p&gt;Rex Booth, CISO at SailPoint, frames the identity dimension in terms practitioners will recognize, saying, "Attacks targeting these events are rarely 'smash and grab' style operations; instead, they are calculated and methodical." The danger, in his framing, is that credential compromise doesn't announce itself—it enables a persistent insider posture that's hard to distinguish from legitimate access.&lt;/p&gt; 
&lt;p&gt;Booth adds a forward-looking note that the Zimperium AiTM campaign makes concrete: "The more frightening scenario is when adversary AI starts running rampant through your enterprise without the need for action by the victim." OffsideHire doesn't require victims to notice anything unusual. They see a booking confirmation, the session is already gone.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;The BYOD blind spot&lt;/h5&gt; 
&lt;p&gt;Both reports emphasize the same structural problem: the mobile device sitting in an employee's pocket is simultaneously a personal consumer device and a corporate credential store, and it operates largely outside the visibility of enterprise security controls.&lt;/p&gt; 
&lt;p&gt;Zimperium's framing is precise: these campaigns reach employees through personal channels—WhatsApp messages, SMS, social media—that never touch enterprise networks. A fan checking ticket availability on a lunch break, on a personal device, over cellular, generates no log that a corporate firewall, email gateway, or EDR platform will ever see. When that device also stores corporate email, authentication apps, and session tokens, the attack path from consumer scam to enterprise breach shortens.&lt;/p&gt; 
&lt;p&gt;&lt;span style="color: #333333;"&gt;"The biggest risks to large sporting events don't come from new exploits. Instead, they originate from people misusing legitimate apps, identities, and corporate processes," said Randolph Barr, CISO at Cequence Security.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;Barr's broader point is that once attackers gain access through credential theft, they don't behave like attackers. They use trusted access—session tokens, OAuth grants, account permissions—in ways that blend into normal operational patterns. The Darktrace ransomware case study makes the same point from the defender side: in one documented incident, attackers exfiltrated data for two full weeks before triggering encryption. Detection that starts at the ransomware note isn't detection—it's damage assessment.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;AI compounds both sides of the problem&lt;/h6&gt; 
&lt;p&gt;Darktrace's survey found&amp;nbsp;that 72% of security professionals at sports organizations expect AI to increase their cyber risk over the next 12 months. The concern is well-grounded: Darktrace's own telemetry shows AI-generated content already appearing in targeted phishing emails tailored to specific teams, venues, and executives. Zimperium documents a live-chat social engineering layer built into the Ghost Stadium kit, allowing operators to guide victims through fake purchase flows in real time—a capability that scales with AI assistance.&lt;/p&gt; 
&lt;p&gt;The irony is that 35% of the same organizations are already deploying or planning to deploy AI into stadium operations—the area respondents identified as the one that would cause the greatest impact if compromised. Shadow AI compounds the exposure: staff are feeding performance metrics, contracts, scouting reports, and health data into tools with little governance, creating a data leakage risk that exists entirely outside existing security controls.&lt;/p&gt; 
&lt;div style="font-weight: normal; font-size: 24px;"&gt;
 What security practitioners should take from this
&lt;/div&gt; 
&lt;p&gt;The two reports don't just describe a threat landscape—they identify where existing assumptions are breaking down. A few implications worth carrying into security planning for the tournament window and beyond:&lt;/p&gt; 
&lt;ul style="list-style-type: disc;"&gt; 
 &lt;li&gt; &lt;p&gt;DMARC passing is not a trust signal. The 84% pass rate on malicious email means authentication status cannot be treated as a reliable indicator of legitimacy. Behavioral detection—what an account does after authentication—has to carry more weight.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;MFA is not sufficient against AiTM. OffsideHire bypasses MFA in real time by relaying credentials against real infrastructure. Phishing-resistant MFA (FIDO2/passkeys) is the relevant control; standard TOTP or push notification MFA is not.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Mobile is an unmonitored perimeter. BYOD devices operating on personal networks and cellular bypass most enterprise visibility. During high-emotion events, the risk that an employee clicks a malicious link on a personal device is structurally elevated—and the blast radius connects back to enterprise credentials.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The geopolitical context is elevated. Darktrace specifically flags Russia's continued exclusion from international sport, the ongoing conflict in Ukraine, and Iran's anticipated participation as factors that raise the nation-state threat profile for this tournament. Previous international sporting events have seen state-aligned actors use the cyber domain for symbolic disruption.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Third-party access is a live attack surface. For a tournament spanning&amp;nbsp;three countries and hundreds of vendors, a compromised supplier is already inside the perimeter. Zimperium's Ghost Stadium campaign included a supply-chain-style element: the phishing kit reused FIFA's actual OAuth credentials, making its clone indistinguishable from the real authentication flow.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Zimperium's full research, including indicators of compromise, is &lt;a href="https://zimperium.com/blog/world-cup-2026-mobile-targeted-phishing-the-global-social-engineering-threat"&gt;available here&lt;/a&gt;. Darktrace's full sports sector threat report is &lt;a href="https://www.darktrace.com/blog/cybersecurity-for-the-sports-sector-the-threats-facing-a-digitized-industry-in-2026"&gt;available here&lt;/a&gt;.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fworld-cup-2026-fan-phishing-enterprise-threat&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Social Engineering</category>
      <category>Original Content</category>
      <category>Phishing</category>
      <category>Threat Intel</category>
      <category>Sports &amp; Entertainment</category>
      <pubDate>Fri, 12 Jun 2026 13:41:00 GMT</pubDate>
      <author>drewt@secureworld.io (Drew Todd)</author>
      <guid>https://www.secureworld.io/industry-news/world-cup-2026-fan-phishing-enterprise-threat</guid>
      <dc:date>2026-06-12T13:41:00Z</dc:date>
    </item>
    <item>
      <title>Navigating the 2026 Cyber and AI Litigation Surge</title>
      <link>https://www.secureworld.io/industry-news/2026-cyber-ai-litigation-surge</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/2026-cyber-ai-litigation-surge" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/lawsuit%20-%20legal%20-%20court%20case%20-%20business-and-lawyers-discussing-contract-papers-wi-2025-04-22-02-24-01-utc%20copy.jpg" alt="lawyers-computers-scale-justice" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For enterprise security leaders, the mid-year data is in—and it signals a major shift in corporate liability. The Norton Rose Fulbright 2026 Annual Litigation Trends Survey (Midyear Pulse) reveals that corporate exposure to cybersecurity, data privacy, and artificial intelligence is deepening at a pace that has completely blindsided initial enterprise expectations.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For enterprise security leaders, the mid-year data is in—and it signals a major shift in corporate liability. The Norton Rose Fulbright 2026 Annual Litigation Trends Survey (Midyear Pulse) reveals that corporate exposure to cybersecurity, data privacy, and artificial intelligence is deepening at a pace that has completely blindsided initial enterprise expectations.&lt;/p&gt; 
&lt;p&gt;Compounding this technical risk is a highly-fragmented regulatory environment. As federal and state enforcement priorities diverge, organizations are facing a complex web of compliance requirements, multi-jurisdictional scrutiny, and high-stakes class actions. The data show&amp;nbsp;a shifting litigation landscape, and the report examines what it means for cybersecurity teams and corporate counsel.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.nortonrosefulbright.com/-/media/files/nrf/nrfweb/knowledge-pdfs/01-us/litigation-trends/norton-rose-fulbright-2026-annual-litigation-trends-survey---a-midyear-industry-pulse.pdf?revision=13e9b3b3-a287-48af-8e41-b60c1999413b&amp;amp;revision=5250852118717387904"&gt;The survey&lt;/a&gt;, which polled 135 in-house counsel&amp;nbsp;across four key verticals (energy, financial institutions, healthcare, and technology), highlights a sharp disconnect between late-2025 planning and 2026 reality.&lt;/p&gt; 
&lt;p&gt;At the end of last year, only 29% of corporate counsel anticipated higher cybersecurity and privacy risk for 2026. By midyear, 56% report increased exposure at the federal level, and 53% report the same at the state level. This surge is primarily driven by the deployment of sophisticated, AI-accelerated cyberattacks and intensified geopolitical threats targeting critical infrastructure.&lt;/p&gt; 
&lt;p&gt;While 59% of respondents entered the year viewing AI litigation management as a challenge, those risks have quickly materialized into concrete disputes (46% federal, 42% state increased exposure). Unlike cybersecurity, AI liability is "distributed," meaning it impacts organizations differently depending on revenue and implementation.&lt;/p&gt; 
&lt;p&gt;Privacy &amp;amp; Data Violations (47%) and Bias/Discrimination Claims (43%) are the leading AI worries. Organizations under $100M are hit hardest by AI-related privacy, bias, and intellectual property (copyright/trademark) disputes. Organizations over $1B face greater exposure from regulatory scrutiny (49%) and employment decisions (41%) influenced by AI.&lt;/p&gt; 
&lt;p&gt;Workforce disputes are rising sharply, with 39% reporting increased federal risk and 44% reporting state-level increases. This strain is a direct result of decentralized state-level mandates (e.g., in New York and California) alongside volatile workforce shifts like layoffs and the integration of AI hiring tools.&lt;/p&gt; 
&lt;p&gt;For CISOs and security practitioners, this report marks the end of siloed risk management. Your technical perimeter is now tied directly to corporate litigation defense.&lt;/p&gt; 
&lt;p&gt;As federal and state priorities split, a single incident can instantly trigger parallel, two-track investigations. State Attorneys General are increasingly acting as the more aggressive plaintiffs in the room, meaning compliance with federal frameworks (like U.S. CISA or the SEC) is no longer a shield against state-level actions.&lt;/p&gt; 
&lt;p&gt;More than half of all organizations (51%) cite cyber breaches as the leading catalyst for class action lawsuits. Because even minor data leaks can trigger massive statutory damages across multiple states, the security team's technical containment speed directly dictates the company's financial exposure.&lt;/p&gt; 
&lt;p&gt;Security teams must move beyond simply blocking "shadow AI." With 41% of respondents seeing AI-enabled product deployments as a primary trigger for class actions, security must actively audit internal AI training data pipelines, verify that data is contained within secure perimeters (crucial for HIPAA compliance in healthcare), and evaluate third-party vendor integrations to prevent downstream data leaks.&lt;/p&gt; 
&lt;p&gt;For in-house and outside counsel, advising corporate clients in 2026 requires balancing systemic operational bottlenecks against an optimistic shift in legal spend.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Despite navigating these intense compliance pressures, corporate legal teams have reported significant progress in managing their internal constraints. Fifty-five percent report improvements in managing internal legal budgets, and 71% report that managing outside counsel costs has either become easier or remained steady compared to late 2025.&lt;/p&gt; 
&lt;p&gt;Agility and cross-functional alignment are no longer optional. To protect the enterprise, corporate counsel and cybersecurity leadership must form a unified front. Security teams must design the technical guardrails that prevent data exposure, while legal teams must map the multi-jurisdictional landscape to ensure that rapid business transformation does not invite catastrophic litigation.&lt;/p&gt; 
&lt;p&gt;Here is a&amp;nbsp;breakdown by sector, litigation reality, and legal strategy directive.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Technology Sector&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The litigation reality –&amp;nbsp;&lt;span style="line-height: 1.15;"&gt;&lt;span style="line-height: 1.15;"&gt;75% federal and 72% state&lt;/span&gt; exposure increases in cyber—the highest across all industries&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;. High class action risk from product launches&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;Legal strategy directive – Counsel must advise tech clients on their dual liability, both as prime targets for data breaches and as infrastructure providers liable to their customers.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Healthcare Sector&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The litigation reality –&amp;nbsp;&lt;span style="line-height: 1.15;"&gt;Highest overall litigation exposure across jurisdictions, worsened by falling legal capacity (32% reporting decreased internal capacity)&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;Legal strategy directive –&amp;nbsp;Counsel must enforce airtight "closed-loop" AI architectures. If patient data leaves the perimeter, it immediately triggers severe HIPAA and regulatory actions.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Energy Sector&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The litigation reality –&amp;nbsp;&lt;span style="line-height: 1.15;"&gt;Balanced risk between employment disputes (57%) and cyber/privacy breaches (57% federal, 60% state)&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;Legal strategy directive –&amp;nbsp;Leverage the sector's strong cross-functional frameworks to proactively address forum risk and supply chain compliance before disputes arise.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Financial Institutions Sector&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The litigation reality –&amp;nbsp;&lt;span style="line-height: 1.15;"&gt;High-class action exposure via third-party vendor breaches (56% citing breaches as a top class-action trigger)&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;Legal strategy directive – Counsel must advise banks that private litigation often intensifies even if federal enforcement temporarily softens. Strict vendor risk assessments are a legal necessity.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2F2026-cyber-ai-litigation-surge&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>GRC</category>
      <category>Data Security</category>
      <category>Original Content</category>
      <category>Trends</category>
      <category>Legal Industry</category>
      <category>Litigation</category>
      <pubDate>Thu, 11 Jun 2026 17:35:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/2026-cyber-ai-litigation-surge</guid>
      <dc:date>2026-06-11T17:35:00Z</dc:date>
    </item>
    <item>
      <title>AI Agents Don't Have to Follow Directions</title>
      <link>https://www.secureworld.io/industry-news/ai-agents-following-directions</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/ai-agents-following-directions" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Ai%20Agent%20Problem%20-%20business-professionals-discussing-data-in-an-offic-2026-03-18-05-32-30-utc.jpg" alt="two business men collaborating" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Many organizations block ZIP files in email attachments because the old antivirus scanners couldn't read them, and adversaries could get malicious files past the filters by zipping them up. So, when employees need to receive a legitimate ZIP file, they told the sender to change the extension from .zip to .abc. That would get past the filter, and they would then change the extension back to .zip to open&amp;nbsp;it up.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Many organizations block ZIP files in email attachments because the old antivirus scanners couldn't read them, and adversaries could get malicious files past the filters by zipping them up. So, when employees need to receive a legitimate ZIP file, they told the sender to change the extension from .zip to .abc. That would get past the filter, and they would then change the extension back to .zip to open&amp;nbsp;it up.&lt;/p&gt;  
&lt;p&gt;Today, the email gateways are more capable and can open attachments in a sandbox to evaluate safety. This wasn't malicious behavior by the user; they were doing exactly what an AI agent does: finding an alternate path when the intended one was blocked. As a CISO, I've said for years, "don't make your users your biggest hackers."&lt;/p&gt; 
&lt;p&gt;Like humans, AI agents are given tasks and guardrails. But, if they have challenges to do something, the newer models have stronger reasoning and tool-use capabilities, making them more effective at finding workarounds, so the agents will figure out how to bypass rules or ignore policy.&lt;/p&gt; 
&lt;p&gt;Some call this control evasion, which is different than misalignment or drift. Those imply the agent has diverged from its intended directions. Control evasion can happen with a perfectly well-aligned agent; it just simply finds an unexpected path to accomplish what you asked. And you might think you would identify it because this behavior will be logged, but agents know when they are being observed, and can avoid or mask actions if they thought you would block it. This is described initially by Apollo Research on &lt;a href="https://arxiv.org/abs/2412.04984"&gt;Model In-Context Scheming&lt;/a&gt;, and more recently as it relates to &lt;a href="https://arxiv.org/html/2603.01608v2"&gt;AI agents&amp;nbsp;by Hopman&lt;/a&gt; et al.&lt;/p&gt; 
&lt;p&gt;Nothing is physically forcing the agent to follow the rules. We are just expecting them to cooperate. And like our own users, they will when it's convenient—but will find a work around if it's important. Not nefarious, just to get their job done.&lt;/p&gt; 
&lt;p&gt;&lt;img src="https://www.secureworld.io/hs-fs/hubfs/image-png-Jun-09-2026-06-21-43-8861-PM.png?width=600&amp;amp;height=338&amp;amp;name=image-png-Jun-09-2026-06-21-43-8861-PM.png" width="600" height="338" style="margin-left: auto; margin-right: auto; display: block; width: 600px; height: auto; max-width: 100%;"&gt;&lt;/p&gt; 
&lt;p&gt;One of the earliest and most-cited cases of control evasion was an OpenClaw agent example where a user asked their agent to make a restaurant reservation. The agent couldn't pick the correct time on OpenTable, so it downloaded a voice synthesizer and called the restaurant directly to make the reservation. This was not malicious, and actually was an effective pivot to complete the task. But this bypass possibility could have gone much worse. What if the person said you must put down a deposit to make a reservation, and the agent had access to the person's credit card or bank account and sent the money?&lt;/p&gt; 
&lt;p&gt;While the OpenClaw pivot was novel and harmless, Mythos was neither. Mythos took this further and woke up the industry to what control evasion can do. Mythos broke out of its sandbox, strung a series of exploits together to get to the internet, notified an engineer it got out, and posted its exploit on a public website. It was not given any of these tasks.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/anthropic-claude-mythos-finds-exploits-zero-days"&gt;Anthropic's Claude Mythos Autonomously Discovers, Exploits Zero-Days&lt;/a&gt;]&lt;/p&gt; 
&lt;p&gt;In the beginning of the 1990s, the early days of the internet, we used router ACLs to limit access into our networks. But we realized that it's easy to bypass those simple polices because ACLs couldn't distinguish a new connection from an established one; adversaries could spoof their way past them by manipulating packet headers. Stateful firewalls closed that gap by tracking session state independently. We are at that stage now with agents. We have written policies that we are assuming are deterministic, but they are probabilistic,&amp;nbsp;in that the agent will probably follow them—but not always.&lt;/p&gt; 
&lt;p&gt;Over the last year, two academic researchers and I wrote a series of papers talking about a &lt;a href="https://thecybernest.com/paper/view/intrinsic-reliability-and-robustness-for-hyper-complex-agentic-ai-systems-solution-outline-architecture-and-strategy"&gt;Governance Twin model&lt;/a&gt; to identify and re-align AI agents when they drift. We described separating the observability from the policy engine, and having multiple reporting sources like immutable ledgers, graph and vector databases. This allows the platform to keep track of all actions to identify behaviors that violate a behavioral baseline the organization defines: what the agent should and shouldn't do even when it technically could. For instance, it can identify if there is collusion among prompts or commands to different agents, or between agents, where neither may be malicious by itself. However, when we started testing this, we realized that we couldn't rely on the agents always following the policies we set. Just like users, they will bypass them to do the task they think we wanted.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;Building a stateful firewall for agents&lt;/h2&gt; 
&lt;p&gt;We then developed the &lt;a href="https://zenodo.org/records/20410722"&gt;Governance Harness&lt;/a&gt;, which is a method similar to stateful firewalls to only allow access once it is verified it is the valid agent with the valid purpose. We designed the Harness to not evaluate content, leaving that to the Governance Twin, but only to enforce identity and authorization. This keeps overhead low and the control surface clean. Kind of like a notary public.&lt;/p&gt; 
&lt;p&gt;We feel this will be one of the new fundamental controls for AI agents going forward. It is as important as giving limited access to data, tools, and resources, and tracking that the agent doesn't get stuck in a loop. And to do this, we must physically separate the agent from these actions until they are verified.&amp;nbsp;Just like not handing someone a full ring of keys and expecting them to use only one.&lt;/p&gt; 
&lt;p&gt;Mature organizations solved the problem of users changing file extensions not by trusting them more, but by building systems that enforce policy at the action-level regardless of intent. Users don't need to use other means to share files; we give them a secure, approved way to do it. We always say, "give the user a paved road to do something securely, and a gravel road to do it insecurely." We did this a few years ago using privileged access management (PAM) tools, so we don't need to give admins access to the servers natively; they must check out an account to do their admin work.&lt;/p&gt; 
&lt;p&gt;Controlling agents is like guiding humans to use secure methods to do their work. It requires governance that not only sets rules, establishes thresholds, and limits access, but also verifies the agent is the one we are expecting to perform that action, and doing it for purpose intended.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/ai-assistant-master-key-under-doormat"&gt;Your New AI Assistant Is a Master Key—and You Just Left It Under the Doormat&lt;/a&gt;]&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fai-agents-following-directions&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>GRC</category>
      <category>Featured Author</category>
      <category>Agentic AI</category>
      <pubDate>Thu, 11 Jun 2026 12:38:00 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/ai-agents-following-directions</guid>
      <dc:date>2026-06-11T12:38:00Z</dc:date>
      <dc:creator>Rick Doten</dc:creator>
    </item>
    <item>
      <title>The SMB AI Paradox: Why Agility, Vulnerability Collide on Main Street</title>
      <link>https://www.secureworld.io/industry-news/smb-ai-paradox-agility-vulnerability</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/smb-ai-paradox-agility-vulnerability" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Small%20Business%20-%20african-american-woman-holding-tablet-in-a-store-2026-03-18-05-36-26-utc.jpg" alt="woman working in retail setting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;The conversation around artificial intelligence has shifted dramatically. The initial era of raw hype has evolved into a pragmatic, tension-filled reality. Industry leaders are no longer asking &lt;i&gt;what&lt;/i&gt; generative AI can do, but rather &lt;i&gt;where&lt;/i&gt; it should be allowed to act independently, and who bears the responsibility when things go sideways.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="line-height: 1.5;"&gt;The conversation around artificial intelligence has shifted dramatically. The initial era of raw hype has evolved into a pragmatic, tension-filled reality. Industry leaders are no longer asking &lt;i&gt;what&lt;/i&gt; generative AI can do, but rather &lt;i&gt;where&lt;/i&gt; it should be allowed to act independently, and who bears the responsibility when things go sideways.&lt;/p&gt;  
&lt;p style="line-height: 1.5;"&gt;Two recent perspectives from the Forbes Councils highlight a paradox facing small and medium-sized businesses (SMBs). &lt;a href="https://www.forbes.com/councils/forbestechcouncil/2026/04/24/the-most-important-impact-of-ai-agents-may-not-be-in-silicon-valley-but-on-main-street/?utm_source=ftc-beehiiv&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=the-ownership-shift"&gt;An article&lt;/a&gt; from the &lt;i&gt;Forbes Technology Council&lt;/i&gt; argues that "Main Street" will be the true testing ground for autonomous AI agents, facing the highest stakes. Meanwhile, &lt;a href="https://www.forbes.com/councils/forbesbusinesscouncil/2026/05/07/how-smbs-can-capture-ais-upside-and-avoid-the-downside/?utm_source=fbc-beehiiv&amp;amp;utm_medium=newsletter&amp;amp;utm_campaign=ai-with-brains"&gt;a piece&lt;/a&gt; from the &lt;i&gt;Forbes Business Council&lt;/i&gt; suggests that SMBs are uniquely positioned to capture AI’s upside while steering clear of the architectural traps that ensnare larger enterprises.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;a href="https://www.linkedin.com/pulse/businesses-strive-human-ai-collaboration-workplace-iqwme/"&gt;A TechTarget look&lt;/a&gt; at human-AI collaboration adds a third dimension, illustrating that this balancing act is not purely technical—it is fundamentally human.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;So, who has it right? The answer is both. AI is a classic double-edged sword, and for the cybersecurity community, it represents a shifting landscape of risk and opportunity.&lt;/p&gt; 
&lt;h2 style="line-height: 1.5; font-weight: normal;"&gt;The midmarket advantage: agile but vulnerable&lt;/h2&gt; 
&lt;p style="line-height: 1.5;"&gt;The &lt;i&gt;Forbes Technology Council&lt;/i&gt; correctly identifies a structural squeeze on Main Street. Small businesses face labor shortages, rising operational costs, and enterprise-level digital expectations on shoestring budgets. For these lean teams, AI agents represent missing operational muscle—automating content workflows, review management, and customer outreach without needing a human to sit behind a dashboard.&lt;/p&gt; 
&lt;p style="font-weight: normal; line-height: 1.5;"&gt;The &lt;i&gt;Forbes Business Council&lt;/i&gt; flips this perspective to reveal a hidden advantage: agility. Large enterprises are often slow-moving and burdened by legacy systems. A midmarket firm can stand up a focused three-person working group, clean its data, and implement secure, paid AI guardrails in a fraction of the time it takes a Fortune 500 company to clear a legal review.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;However, this agility can cross the line into recklessness. When small businesses mistake stagnation for transformation, they layer AI onto broken, inefficient processes. This can introduce severe data privacy vulnerabilities.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;[RELATED: &lt;a href="https://www.secureworld.io/resources/phishing-at-scale"&gt;Phishing at Scale: Why Mid-Market Is a Prime Target&lt;/a&gt;]&lt;/p&gt; 
&lt;h3 style="line-height: 1.5; font-weight: normal;"&gt;The TechTarget factor: the myth of the 'rubber stamp'&lt;/h3&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The &lt;em&gt;TechTarget&lt;/em&gt; analysis gets to the heart of the operational challenge: human-in-the-loop (HITL) models are failing because businesses are treating humans as rubber stamps.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;As AI shifts from &lt;span style="line-height: 1.15;"&gt;assistance&lt;/span&gt; (writing a draft) to &lt;span style="line-height: 1.15;"&gt;execution&lt;/span&gt; (autonomously interacting with customers or codebases), organizations frequently establish human checkpoints. But if a human operator simply clicks "approve" on hundreds of AI-generated actions a day due to alert fatigue or volume, the checkpoint becomes an illusion.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;True human-AI collaboration requires an explicit handoff strategy:&lt;/p&gt; 
&lt;div style="line-height: 1.5;"&gt; 
 &lt;div style="line-height: 1.15;"&gt; 
  &lt;div style="line-height: 1.15;"&gt; 
   &lt;div style="line-height: 1.15;"&gt; 
    &lt;ol&gt; 
     &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Establish contextual guardrails –&amp;nbsp;System level: Configure the AI system with explicit boundaries. Define what it can execute autonomously (e.g., tier-1 support triaging) and what requires authorization.&lt;/p&gt; &lt;/li&gt; 
     &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Design active interventions –&amp;nbsp;User interface: Avoid simple "yes/no" approval queues. Force the system to highlight &lt;i style="line-height: 1.15;"&gt;why&lt;/i&gt; the AI made a decision and call out data variables that require human validation.&lt;/p&gt; &lt;/li&gt; 
     &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;Manage the complexity handoff – Operational protocol: When the AI encounters emotional nuance, edge cases, or highly regulated data, trigger a seamless handoff to a human professional. The human takes over the customer relationship, while the AI pivots back to an assistive role.&lt;/p&gt; &lt;/li&gt; 
    &lt;/ol&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div style="line-height: 1.15;"&gt; 
   &lt;div style="line-height: 1.15;"&gt; 
    &lt;h3 style="font-weight: normal;"&gt;Mapping the ecosystem: winners, losers, and watchers&lt;/h3&gt; 
    &lt;p&gt;The intersection of agentic AI adoption and human oversight creates a ripple effect across every tier of the business ecosystem.&lt;/p&gt; 
    &lt;p style="font-weight: bold;"&gt;Stakeholder segment: SMBs &amp;amp; midmarket&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt; &lt;p&gt;The core segment: Operational leverage vs. existential security risk.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
     &lt;li&gt; &lt;p&gt;The strategic reality – The battleground: They gain the administrative scale of a large enterprise but risk catastrophic data exposure. According to IBM, only 24% of GenAI initiatives contain explicit security components.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="font-weight: bold;"&gt;Stakeholder segment: Large &amp;amp; mega corporations&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt; &lt;p&gt;The core segment:&amp;nbsp;Massive resource pools vs. bureaucratic stagnation.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
     &lt;li&gt; &lt;p&gt;The Strategic Reality – The Titanic effect: They possess the capital to build private, secure LLM environments, but they struggle with user adoption and ROI. MIT data indicates that 95% of enterprise businesses still struggle to see meaningful financial returns from AI investments.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="font-weight: bold;"&gt;Stakeholder segment: Cybersecurity practitioners&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt; &lt;p&gt;The core segment: Policy enforcement vs. business enablement.&lt;/p&gt; &lt;/li&gt; 
     &lt;li&gt; &lt;p&gt;The strategic reality – The governance strain: Securing AI is no longer just about blocking shadow IT; it is about ensuring that internal AI data loops do not leak IP. Security teams must pivot from "gatekeepers" to "guardrail architects," focusing heavily on identity, access management, and data hygiene.&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="font-weight: bold;"&gt;Stakeholder segment: Security &amp;amp; IT vendors&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt; &lt;p&gt;The core segment: Market hype vs. defensible value.&lt;/p&gt; &lt;/li&gt; 
     &lt;li&gt; &lt;p&gt;The strategic reality – The flight to security: The market for basic AI wrappers is collapsing. Vendors must build secure, workflow-complete agents with persistent memory and built-in governance to earn a spot in the enterprise stack.&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
    &lt;p style="font-weight: bold;"&gt;Stakeholder segment: &amp;nbsp;The general public&lt;/p&gt; 
    &lt;ul&gt; 
     &lt;li&gt; &lt;p&gt;The core segment:&amp;nbsp;Hyper-convenience vs. the loss of human connection.&lt;/p&gt; &lt;/li&gt; 
     &lt;li&gt; &lt;p&gt;The strategic reality – The trust deficit: Consumers will enjoy faster support turnarounds, but as &lt;em&gt;TechTarget&lt;/em&gt; notes, removing humans entirely causes major friction. True loyalty will remain anchored to authentic human interaction.&lt;/p&gt; &lt;/li&gt; 
    &lt;/ul&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;The SMB AI paradox comes down to this: The upside of agility and leverage means rapid deployment, lean 3-person groups, and instant "digital staff." The downside of vulnerability and hype means high exposure to risk, inefficient workflows, and overreliance on tools.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fsmb-ai-paradox-agility-vulnerability&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Risk Management</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>SMBs</category>
      <pubDate>Wed, 10 Jun 2026 18:22:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/smb-ai-paradox-agility-vulnerability</guid>
      <dc:date>2026-06-10T18:22:00Z</dc:date>
    </item>
    <item>
      <title>Why Code Velocity Calls for Ruthless AI Governance</title>
      <link>https://www.secureworld.io/industry-news/code-velocity-ai-governance</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/code-velocity-ai-governance" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/C-Level_business-meeting-in-modern-office-conference-room-2026-01-05-06-28-12-utc.jpg" alt="business leaders in a meeting" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="line-height: 1.15;"&gt;In the theater of modern enterprise software development, the deployment of AI coding assistants has been heralded as the ultimate victory for sheer engineering volume. Organizations can now generate massive blocks of functional logic in seconds, effectively neutralizing the old "blank page" problem&lt;/span&gt;.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="line-height: 1.5;"&gt;&lt;span style="line-height: 1.15;"&gt;In the theater of modern enterprise software development, the deployment of AI coding assistants has been heralded as the ultimate victory for sheer engineering volume. Organizations can now generate massive blocks of functional logic in seconds, effectively neutralizing the old "blank page" problem&lt;/span&gt;.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: normal;"&gt;But a sobering independent market study from Black Duck and research partner UserEvidence delivers a sharp reality check to the C-suite.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The report, titled &lt;a href="https://www.blackduck.com/content/dam/black-duck/en-us/reports/the-state-of-ai-powered-software-development.pdf"&gt;"The State of AI-Powered Software Development,"&lt;/a&gt;&amp;nbsp;surveys 831 software engineers and DevOps professionals to reveal a profound structural paradox: while AI adoption has fundamentally solved the code production bottleneck, it has simultaneously broken the code review pipeline.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;As developers flood repositories with automated code, organizations face a critical inflection point. The report's core thesis is clear: Organizations need governance to unlock AI's true potential. Without it, the eight hours developers save each week are entirely swallowed by the manual chaos of downstream testing and rework.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The baseline metrics of the report initially paint a picture of an engineering utopia. Mass adoption is a reality, with 97% of software teams actively utilizing AI coding tools like GitHub Copilot (83%) and Claude Code (63%).&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Furthermore, 92% of teams report notable boosts in productivity and release velocity, with AI assistants handing developers back an average of eight hours per week—a full day of work reclaimed.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;But this speed is a double-edged sword. Generating lines of code is trivial; verifying its security, logic, and architectural fit is not. Software code is inherently a liability: stuffing a repository with machine-generated lines expands the enterprise attack surface and triggers intense pull-request fatigue.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/secure-vibe-coding-without-security-risks"&gt;Secure Vibe Coding: Ship Fast without the Security Risks&lt;/a&gt;]&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;As a result, 90% of teams encounter workflow trade-offs and bottlenecks. AI has not eliminated overall engineering effort; it has merely redistributed it further down the Software Development Lifecycle (SDLC).&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;When a pipeline lacks clear, automated guardrails, the massive surge in code volume crashes directly into Application Security (AppSec) and Quality Assurance (QA) checkpoints. This is why Black Duck asserts that true AI maturity requires moving away from loose adoption policies toward formal, deterministic governance planes.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;"Our research found that 92% of teams see improved productivity and velocity in code development—yet 90% still hit significant bottlenecks further down the SDLC," said Shandra Gemmiti, Sr. Director of Cross-Portfolio Solutions at Black Duck. "Teams have become very good at accelerating code generation but haven't invested in what comes after it. Manual code reviews, security testing, and issue remediation are all falling behind, creating a dangerous imbalance between how fast code is produced and how safely it can be shipped."&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Gemmiti added, "The data also shows that governance is a force multiplier for AI ROI, not a constraint. The 30% of teams that have implemented fully governed approaches to AI-assisted development are 55% more likely to see major efficiency gains—proving that guardrails accelerate outcomes rather than slow them down."&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;"This governance gap becomes existential when you factor in what models like Claude Mythos signal about the threat landscape," Gemmiti continued. "When AI can autonomously discover and exploit vulnerabilities at machine speed, the window teams have to identify and fix issues doesn't just shrink—it effectively disappears. What was a workflow bottleneck before Mythos becomes a structural vulnerability flood that existing security infrastructure was never built to absorb."&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;"The only viable response is to match this AI-driven attack speed with an AI-assisted defense," Gemmiti said. "Teams will need to use AI to augment their existing application security programs to enable security to handle the increase in code volume, velocity, and vulnerabilities. Those that don't adapt application security to meet this moment will be exposed in ways their current tools and processes have no answer for."&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Currently, fewer than a third of teams (30%) operate under a fully governed approach—formally approved, centrally managed, and actively monitored. A massive plurality settles for informal guidelines or relies entirely on developers to manually document AI usage in their pull requests.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;However, the organizations that bridge this gap experience a dramatic performance boost: Teams with full AI governance in place are 55% more likely to realize a major improvement in operational efficiency (90% versus 44% for ungoverned peers).&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Thoughtful governance transforms pipelines from a series of stop-and-go friction points into continuous force multipliers. By setting explicit, automated rules for how AI-generated code is ingested, tagged, and vetted, teams gain the structural confidence needed to ship software safely without triggering manual code reviews.&lt;/p&gt; 
&lt;h2 style="line-height: 1.15;"&gt;&lt;strong style="line-height: 1.15;"&gt;What this means for leadership versus cybersecurity teams&lt;/strong&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The report exposes an alarming alignment gap between corporate executives and the technical contributors holding the defensive line.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="line-height: 1.5; font-weight: normal;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The C-suite blind spot:&lt;/span&gt; Senior leadership removed from day-to-day repository management tends to view AI code quality through rose-tinted glasses. C-level executives are 78% more likely to rate AI code quality as "excellent" compared to the general respondent base (48% versus 27% overall). Conversely, a meager 8% of technical contributors and 9% of first-line managers share this glowing evaluation. Executives see rapid feature releases; developers see the invisible debt of code rework and prompt patching.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.5; font-weight: normal;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The cyber team's burden:&lt;/span&gt; Cybersecurity teams are left to manage the resulting risk posture. Sixty-four percent of development teams express deep concern about AI introducing security defects and vulnerabilities into production environments. This concern escalates with heavy utilization: among practitioners who leverage AI for the majority of their coding, the urgency around vulnerability remediation rises to 57%.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;To survive this influx, developers and security teams are looking to fight automation with automation. Eighty-six percent believe a dedicated AI security agent should evaluate AI-generated code. However, they refuse to yield ultimate control to an autonomous entity: 84% mandate keeping a human in the loop via structured pull requests or real-time IDE suggestions. Developers want machine-speed security inputs, but they insist on retaining final decision-making authority.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The operational realities detailed in Black Duck's research carry direct, real-world consequences for the general public and end-consumers.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;For the consumer, the immediate benefit of a fully-governed, AI-accelerated pipeline is the rapid delivery of digital value. Bug fixes, localized user experience improvements, and highly-anticipated new application features can be conceptualized, coded, and deployed in days rather than quarters. Boilerplate code and technical scaffolding are handled instantly by machines, letting human engineers dedicate more focus to complex system design and user experience prototyping.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The downside for the public is severe if organizations prioritize developer velocity over automated governance. If thousands of lines of unverified AI code flow directly into revenue-generating, consumer-facing applications, the likelihood of subtle logical vulnerabilities slipping into production rises exponentially.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;For the average consumer, this translates to a heightened risk of data exposure, privacy violations, and software supply chain compromises. If an organization fails to track the exact structure and origin of its AI-assisted components, identifying and patching an active zero-day vulnerability takes significantly longer—leaving public data exposed to threat actors for extended windows.&lt;/p&gt; 
&lt;h3 style="line-height: 1.15;"&gt;&lt;strong style="line-height: 1.15;"&gt;Tactical directives for modern AppSec and DevSecOps teams&lt;/strong&gt;&lt;/h3&gt; 
&lt;p style="line-height: 1.5;"&gt;To safely scale engineering velocity without completely drowning the security organization, corporate leadership must execute three core imperatives.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li style="line-height: 1.5;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Enforce automated AI metadata tagging:&lt;/span&gt; Completely ban the practice of relying on manual developer comments in pull requests to track AI code. Organizations must implement automated tagging and cryptographic metadata within the repository and IDE to instantly flag the exact origin and structure of machine-generated code blocks, cutting down downstream investigation windows.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Orchestrate concurrent CI/CD security testing:&lt;/span&gt; AppSec programs must operate seamlessly and concurrently across the entire release pipeline. Security leaders must deploy automated project onboarding and run Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Analysis (DAST) simultaneously to match machine-speed development volumes without creating an engineering bottleneck.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.5;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Transition to dynamic Software Bills of Materials (SBOMs):&lt;/span&gt; To mitigate complex supply chain risks and ensure strict compliance with emerging regulations like the EU Cyber Resilience Act (CRA), organizations must maintain automated, continuous SBOMs for all code created or ingested. Prioritize deep vulnerability intelligence to accurately isolate and remediate emergent risks at runtime.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="line-height: 1.5;"&gt;We asked experts from cybersecurity solution providers for their thoughts on the survey's results.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;Ram Varadarajan, CEO at Acalvio, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"The key takeaway from the Black Duck research is that AI coding assistants are no longer the challenge; governance is.&amp;nbsp;Organizations that pair AI adoption with clear policies, security guardrails, and human oversight are far more likely to realize productivity gains without increasing technical debt and security risk."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Unfortunately, this is our new reality. Organizations should treat AI-generated code as a new software supply chain risk. So, implement governance frameworks, AI-specific secure coding standards, automated security testing, and mandatory human review processes to ensure AI accelerates development without compromising software quality or security."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;Nicole Carignan, SVP of Security &amp;amp; AI Strategy&amp;nbsp;and Field CISO at Darktrace,&amp;nbsp;said:&lt;/span&gt;&lt;/p&gt; 
&lt;div&gt; 
 &lt;ul&gt; 
  &lt;li style="line-height: 1.5;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"For organizations, the main concern is insecure code moving faster than review. AI coding tools can help with structure, documentation, and basic checks, but they do not make software secure by default. Generated code may include weak authentication, exposed secrets, over‑permissioned APIs, or unsafe dependency usage that a non‑expert may not recognize. There is also emerging risk in the tools themselves: hallucinated logic, unsafe or unintended function calls, and even the possibility of malicious or compromised tools being introduced into development workflows."&lt;/p&gt; &lt;/li&gt; 
  &lt;li style="line-height: 1.5;"&gt; &lt;p&gt;"Security teams need to treat AI-assisted development as part of the attack surface. That means visibility not only into the code being produced, but into the tools, functions, and integrations that code relies on. Organizations should understand which internal and external tools are being invoked, how functions interact, and what trust relationships are being created. Graph analysis of tool and function calls, across both internal systems and external services, becomes essential to identify unexpected paths, privilege escalation, or unsafe data flows."&lt;/p&gt; &lt;/li&gt; 
  &lt;li style="line-height: 1.5;"&gt; &lt;p&gt;"External dependencies deserve particular scrutiny. AI-generated code often pulls in libraries, APIs, or services automatically, sometimes with little transparency to the person building the application. Human analysis of these dependencies is still required to understand ownership, maintenance, security posture, and long-term risk. AI can assist with this process with cyber-AI models that can help identify vulnerabilities, insecure patterns, and known weaknesses in generated code but it should augment, not replace, expert judgment."&lt;/p&gt; &lt;/li&gt; 
  &lt;li&gt; &lt;p style="line-height: 1.5;"&gt;&lt;span style="line-height: 1.15;"&gt;"Used responsibly, AI coding tools can help developers and non-developers work faster. However, organizations need clear security by design architecture: secure code review, dependency and composition analysis, secrets detection, API security, access controls, data classification, and testing before production. That includes AI-assisted code review and red-team testing to probe how generated code behaves under real-world attack scenarios, followed by mandatory human review before anything reaches production."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="line-height: 1.15;"&gt;Black Duck's 2026 data confirm&amp;nbsp;that simply buying an AI coding assistant no longer provides a competitive edge&lt;/span&gt;. The ultimate winners in the digital landscape will be the organizations that understand how to &lt;i style="line-height: 1.15;"&gt;operationalize&lt;/i&gt; that volume through ruthless, automated governance&lt;span style="line-height: 1.15;"&gt;. By balancing machine-speed code creation with human-in-the-loop, context-aware AI security agents, enterprise teams can finally capture the true return on their AI investments without turning their software pipelines into an open backdoor.&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fcode-velocity-ai-governance&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>GRC</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>DevOps</category>
      <category>Coding</category>
      <category>AI Governance</category>
      <pubDate>Wed, 10 Jun 2026 14:17:02 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/code-velocity-ai-governance</guid>
      <dc:date>2026-06-10T14:17:02Z</dc:date>
    </item>
    <item>
      <title>How Over-Permissioned AI Is Quietly Dismantling ID Infrastructure</title>
      <link>https://www.secureworld.io/industry-news/ai-dismantling-id-infrastructure</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/ai-dismantling-id-infrastructure" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Computer%20Non-Human%20Identity%20Management%20NHIM%20-%20computer-motherboard-background-with-blur-neon-mul-2024-10-18-03-27-22-utc%20copy.jpg" alt="computer circuit board with ID tag" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="line-height: 1.15;"&gt;In the corporate rush toward artificial intelligence, much of the public debate has centered on algorithmic bias, data leakage, and deepfakes. But behind the scenes, a far more immediate tactical crisis is unfolding. &lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p style="line-height: 1.5;"&gt;&lt;span style="line-height: 1.15;"&gt;In the corporate rush toward artificial intelligence, much of the public debate has centered on algorithmic bias, data leakage, and deepfakes. But behind the scenes, a far more immediate tactical crisis is unfolding. &lt;/span&gt;&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;According to an in-depth global study by Semperis, titled &lt;a href="https://www.semperis.com/wp-content/uploads/resources-pdfs/reports/report-semperis-ai-identity.pdf"&gt;"The State of Identity Security in the AI Era,"&lt;/a&gt;&amp;nbsp;AI is quietly redrawing the attack boundary of the global identity fabric.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;By surveying 1,100 IT and security professionals across eight countries, the early 2026 report delivers a blunt message to enterprise leaders: organizations are granting elevated security privileges to AI agents faster than they are putting guardrails around those new identities.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;In a threat landscape where identity systems are already the primary target for network intrusion, wiring unguarded AI agents into Tier-0 infrastructure—like Active Directory (AD), Entra ID, or Okta—is inadvertently creating an automated fast track to full-scale enterprise compromise.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Historically, securing a corporate network meant protecting human perimeters through multi-factor authentication (MFA) and conditional access. The AI boom has shattered that framework by flooding networks with an unmanaged wave of Non-Human Identities (NHIs).&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The report notes that NHIs already vastly outnumber human users, tracking toward a staggering 100:1 ratio as agentic workflows proliferate. Each new low-code "helper," automated service principal, or background script introduces a fresh entry point into the core identity architecture.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The underlying risk isn't just the sheer volume of these machine identities but their placement. Globally, 74% of security professionals believe AI functionality will drive an increase in attacks on identity infrastructure. Despite this clear recognition of risk, security leaders are simultaneously expanding the administrative power they hand over to unhardened machine agents.&lt;/p&gt; 
&lt;h2 style="line-height: 1.15;"&gt;&lt;strong style="line-height: 1.15;"&gt;Keys to the kingdom: Are organizations moving too fast?&lt;/strong&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The short answer is yes. Driven by a corporate desire for operational efficiency, organizations are introducing agentic AI straight into highly-sensitive identity workflows.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;According to Semperis' findings, 29% of surveyed organizations already use AI agents to handle security-related help desk tickets—including high-risk administrative tasks like password resets and corporate VPN access. An additional 64% plan to enable this capability within the next 12 months, meaning a total of 93% of enterprises will soon entrust their keys to autonomous software.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The report explicitly details how an adversary can weaponize the helpful nature of an AI agent to achieve machine-speed exploitation. Because AI agents are built to solve user problems autonomously, an attacker who compromises an endpoint or executes a basic prompt-injection attack does not need to spend weeks hunting for network vulnerabilities. They can simply ask the local agent, &lt;i style="line-height: 1.15;"&gt;"What secrets are on this machine?"&lt;/i&gt; or instruct a generative search tool to summarize all unpatched vulnerabilities and administrative credentials in the active environment.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/secure-vibe-coding-without-security-risks"&gt;Secure Vibe Coding: Ship Fast without the Security Risks&lt;/a&gt;]&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;If an AI agent is over-permissioned—which is standard in environments where developers value speed over security—its desire to be helpful can result in catastrophic architectural changes. As Semperis product experts warn, these agents function like "sociopathic genius five-year-olds." Without deterministic boundaries, an agent tasked with troubleshooting an issue might "helpfully" reconfigure global directory security settings, modify conditional access policies, or grant unauthorized permissions that punch holes straight through enterprise safeguards.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Once an agent acts as a trusted entity against Active Directory, Entra ID, or Okta, an attacker manipulating that agent can chain its capabilities to impersonate network admins, modify domain groups, and permanently entrench themselves inside core identity controllers.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Perhaps the most alarming statistic in the entire study is the profound gap between threat exposure and operational recoverability. Only 32% of respondents feel very confident they could fully regain control of their identity infrastructure if an AI agent exposed administrative credentials to an attacker.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Security experts note that even this 32% figure likely represents misplaced optimism. Organizations routinely overestimate their disaster-recovery capabilities, assuming that standard system backups will save them, only to discover during an active breach that their backups are misconfigured, infected, or have never been tested in an end-to-end identity crisis. When machine-speed mistakes happen at the directory layer, a standard technical incident can instantly transform into a prolonged, business-ending outage.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;To survive the intersection of agentic automation and identity security, cybersecurity teams cannot treat AI governance as a secondary IT project. It requires immediate structural adaptations.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;Close the governance gap&lt;/span&gt;&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Globally, only 65% of organizations formally register, authenticate, and authorize AI identities in a centralized system, while 6% do not track them at all. This creates fertile ground for "zombie" accounts and orphaned service principals that attackers can easily hijack. While 83% of firms state that AI identity governance is a top priority for the coming year, security leaders are currently trapped between a rock and a hard place.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Including agents as standard users in an Identity Provider (IdP) applies existing roles and audit trails, but because agents might only exist for 30 seconds, they can quickly explode a directory to hundreds of times its normal size, leaving behind a massive trail of over-permissioned entitlements. Security teams must demand dedicated NHI governance platforms built to manage the short life cycles and unique contexts of agentic workloads.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;Enforce strict trust boundaries&lt;/span&gt;&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Enterprise defenders must enforce least-privilege, just-enough, and just-in-time access controls for machine agents with the exact same—if not greater—rigor applied to human executives. Human and machine trust boundaries must be explicitly segregated. If an AI agent requires access to a system, it should never be given blanket domain-admin rights; its operational parameters must be deterministic and tightly scoped.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;Building around the assumption of compromise&lt;/span&gt;&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;If an enterprise is going to allow AI to touch access keys, service tickets, or local endpoint data, the security architecture must be built on the assumption that those agents will eventually be manipulated. Security operations teams must deploy User and Entity Behavioral Analytics (UEBA) specifically tuned to flag anomalous, machine-speed queries or unauthorized privilege escalation attempts originating from internal AI tools.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;Prioritize identity-centric cyber resilience&lt;/span&gt;&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;True resilience isn't just about preventing a breach; it's about surviving one. Enterprises must invest in dedicated, malware-proof identity backup and recovery solutions for Active Directory, Entra ID, and Okta. These recovery playbooks must be tested frequently through live simulations to bridge the confidence gap and ensure the business can restore a trusted state within hours, rather than weeks.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;We asked several experts from cybersecurity solution providers for their thoughts on the Semperis study.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/chandra-gnanasambandam/"&gt;Chandra Gnanasambandam&lt;/a&gt;, CTO at SailPoint, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"Adversaries are using AI to operate at a scale and speed that makes traditional, static defenses obsolete. The window between a vulnerability’s discovery and its exploitation has shrunk from months to mere days, and soon it will be minutes."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"Moving forward, security teams must look inwards. Instead of focusing exclusively on keeping threats out, we must meticulously govern what happens inside our own systems. This means abandoning the dangerous, yet common, 'set-it-and-forget-it' approach to access policies. Teams must accept that static, persistent access is the single greatest vulnerability in the modern enterprise. The new mandate is to pivot from a mindset of static protection to one of real-time governance, either through least privilege or zero standing privilege."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"We must also recognize that governing non-human identities is fundamentally different from governing humans and requires a new, specialized framework built for machine-speed operations."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/shane-barney-69026528/"&gt;Shane Barney&lt;/a&gt;, CISO at Keeper Security, said: &lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"Security teams can no longer view identity as a human-only challenge. Today, service accounts, API keys, machine credentials, automation scripts, AI agents and other Non-Human Identities (NHIs) often outnumber human users by dozens or even hundreds to one. As organizations embrace cloud infrastructure, DevOps pipelines, AI and automation, NHIs have become foundational to business operations—and a rapidly expanding attack surface."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"The mindset shift is moving from perimeter-centric security to identity-centric security. Every identity, whether human or non-human, should be continuously authenticated, authorized and monitored under a zero-trust model. The assumption that machine identities are inherently safe because they operate in the background is exactly what attackers are counting on. Every credential, token, secret, and certificate should be treated as a privileged asset that requires visibility, governance and lifecycle management."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/james-maude/"&gt;James Maude&lt;/a&gt;, Field CTO at BeyondTrust, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"The C-Suite, CISOs, and CSOs need to look beyond siloed views of obviously privileged identities and take a holistic view of the combinations of privileges, entitlements and roles that could be exploited by an attacker to elevation privilege, move laterally and inflict damage. The identity security debt accumulated by many organizations represents a far great risk than any other area as it only takes the attacker to login using the right identity and all is lost because of the paths to privilege that abound in their environment. Understanding and reducing your identity attack surface should be at to forefront of every organization thinking when it comes to cyber defense moving forward."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/luz-elad/"&gt;Elad Luz&lt;/a&gt;, Head of Research at Oasis Security, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"To reduce the risks associated with Non-Human Identities (NHIs), security teams need to implement modern identity management practices, strong governance, and proactive security controls. Where possible, organizations should transition to cloud-native identities and establish a comprehensive lifecycle management strategy for NHIs that cannot be migrated. Maintaining good identity hygiene is critical; this includes removing stale or unused NHIs, conducting regular access reviews, and ensuring NHIs follow the Principle of Least Privilege (PoLP) by granting only the minimum permissions necessary."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"A structured policy and enforcement program should be built around risk analysis and compliance frameworks, ensuring NHIs align with both security best practices and regulatory requirements. Adopting short-lived credentials, automated credential rotation, and managed identities can further minimize risk by limiting exposure. Collaboration with app development and DevSecOps teams is also essential to integrate these security measures without disrupting workflows, ensuring that NHIs remain secure while maintaining operational efficiency. By treating NHIs with the same level of oversight as human identities, organizations can mitigate risk while maintaining agility and scalability across their development and cloud environments."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/crystal-morin/"&gt;Crystal Morin&lt;/a&gt;, Senior Cybersecurity Strategist at Sysdig, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"Identity management has undergone a massive shift: humans now make up less than 3% of managed identities in cloud environments. The rest belong to machines that don't log off, don't take breaks, and often operate with elevated permissions."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"As automation and AI-driven development explode, the gap between human and machine identities is becoming one of the defining security challenges of our time.&amp;nbsp;Machine identities are ephemeral, autonomous, and often difficult to manage at scale with traditional controls, which were never designed for this speed. Identity is the primary access control, it defines an environment's boundaries, and it's the most common source of initial access in a breach."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"To keep up, organizations must rethink identity security as a continuous, lifecycle-driven discipline. Businesses must treat machine identities as the new firewall."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/dianakelleysecuritycurve/"&gt;&lt;/a&gt;&lt;a href="https://www.linkedin.com/in/dianakelleysecuritycurve/"&gt;Diana Kelley&lt;/a&gt;, CISO at Noma Security:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"AI risks have rapidly moved from a watch list item to a front-line security concern, especially when it comes to data security and misuse. To manage this emerging threat landscape, security teams need a mature, continuous security approach, which includes blue team programs, starting with a full inventory of all AI systems, including agentic components as a baseline for governance and risk management."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"For practitioners, securing AI is not just about protecting models. It requires addressing stack sprawl and moving toward a platform-driven approach that delivers defense in depth through unified, AI-aware identity, configuration, and data visibility. Organizations that simplify their cloud and AI security stack, and enable effective automation, will be far better positioned to safely scale AI as threats continue to evolve."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/chris-radkowski-aa9161/"&gt;Chris Radkowski&lt;/a&gt;, GRC Expert at Pathlock, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"The rise of AI agents and machine identities has fundamentally outpaced traditional identity security. MFA and legacy access controls were built for a world of human users, not autonomous agents, service accounts, and AI-driven workflows that now outnumber people across the enterprise by 20x. Making matters more complex, the productivity promise of AI is too compelling for employees to wait on IT, workers are signing up for AI-powered tools, copilots, and automation platforms using their enterprise credentials, connecting them directly to corporate email, productivity suites, and business applications, often without security's knowledge."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"As agentic AI takes on real business actions with real permissions, the attack surface expands in ways most organizations aren't prepared to see, let alone secure. Credential abuse, account takeover, and sophisticated social engineering are increasingly targeting the non-human identities that operate quietly in the background with little oversight. That is why we believe that securing the modern enterprise means treating identity holistically by extending governance, least-privilege, and adaptive controls across every identity, human or machine. In the AI era, identity isn't just an IT problem; it's the foundation of trust itself."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/randolphbarr/"&gt;Randolph Barr&lt;/a&gt;, CISO at Cequence Security, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"We're seeing AI rapidly evolve from simple automation to deeply personalized, context-aware assistance—and it's heading toward an agentic AI future where tasks are arranged across domains with minimal human input."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;"Before we even get to AI-specific risks, we have to get the fundamentals correct. In the haste to bring AI to market quickly, engineering and product teams often cut corners to meet aggressive launch timelines. When that happens, basic security controls get skipped, and those shortcuts make their way into production. Therefore, while organizations are indisputably starting to think about model protections, prompt injection, data leakage, and anomaly detection, those efforts mean little if you haven't locked down identity, access, and configuration at a foundational level."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;The Semperis study establishes that the race for AI productivity has outpaced the implementation of foundational identity safeguards. When automated tools are given the power to reset passwords and modify local access keys, the human element of defense is stripped away. Security teams that protect their enterprises in this new era will be those that halt the unchecked rollout of unmonitored agents, enforce ruthless least-privilege for non-human identities, and ensure their backup infrastructure is fully prepared for an AI-accelerated breach.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Semperis will be hosting executive roundtable discussions at four SecureWorld conferences this fall, including Atlanta (date TBD), &lt;a href="https://events.secureworld.io/details/denver-co-2026/"&gt;Denver&lt;/a&gt; on October 1, &lt;a href="https://events.secureworld.io/details/dallas-tx-2026/"&gt;Dallas&lt;/a&gt; on October 8, and &lt;a href="https://events.secureworld.io/details/seattle-wa-2026/"&gt;Seattle&lt;/a&gt; on November 4-5.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fai-dismantling-id-infrastructure&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>Identity / Access Mgmt</category>
      <category>Non-Human Identities</category>
      <pubDate>Tue, 09 Jun 2026 13:09:03 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/ai-dismantling-id-infrastructure</guid>
      <dc:date>2026-06-09T13:09:03Z</dc:date>
    </item>
    <item>
      <title>WiCyS Report: The Financial Imperative of Workforce Equity</title>
      <link>https://www.secureworld.io/industry-news/wicys-workforce-equity</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/wicys-workforce-equity" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/SMALLER%20image%20-%20women%20-%20team-commitment-2024-10-14-16-19-53-utc.jpg" alt="four colleagues working together at computer" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;In the security community, resilience is almost exclusively quantified via architectural redundancy, mean time to detection (MTTD), or the speed of patch deployment. Yet, the systems supporting the humans tasked with executing these defenses have remained brittle.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="line-height: 1.5;"&gt;In the security community, resilience is almost exclusively quantified via architectural redundancy, mean time to detection (MTTD), or the speed of patch deployment. Yet, the systems supporting the humans tasked with executing these defenses have remained brittle.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;A groundbreaking joint research report from Women in CyberSecurity (WiCyS) and FourOne Insights, titled "The ROI of Resilience: How Cybersecurity Talent Management Best Practices Improve the Bottom Line,"&amp;nbsp;shifts the conversation from abstract diversity goals to hard financial metrics.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;By synthesizing employer surveys, organizational analyses, and extensive labor market telemetry from Lightcast, the &lt;a href="https://www.wicys.org/wp-content/uploads/2026/03/The-ROI-of-Resilience_Final-1.pdf"&gt;March 2026 report&lt;/a&gt; establishes a definitive baseline: skills-based, talent-friendly workforce practices are not just mechanisms for equity; they are high-return financial investments. At a time when persistent demographic headwinds and AI-driven workflow changes are tightening the global tech labor pool, human capital management has become a critical security metric.&lt;/p&gt; 
&lt;h2 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;The key takeaways: the hard math of human capital&lt;/strong&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.5;"&gt;The central finding of&amp;nbsp;the report is that modernizing narrow, opaque talent pipelines yields direct, measurable bottom-line savings by driving down hiring friction and neutralizing employee churn.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The research links specific, employee-centric talent practices to distinct lifecycle optimizations, proving they can save an enterprise more than $125,000 per cybersecurity worker over their tenure. These savings are primarily realized by avoiding severe productivity losses that occur when critical seats sit vacant.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;WiCyS Executive Director &lt;a href="https://events.secureworld.io/speakers/lynn-dohm/"&gt;Lynn Dohm&lt;/a&gt; spoke on the report at the SecureWorld Chicago conference on May 20th with a session titled, "The ROI of Resilience: Quantifying the $125k Advantage of Skills-Based Talent."&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Dohm's session covered:&lt;/p&gt; 
&lt;ul style="list-style-type: disc; background-color: #ffffff; line-height: 1.5;"&gt; 
 &lt;li&gt; &lt;p&gt;The Retention Blueprint: Why skills-based development increases retention by 18% and how to implement it without adding headcount&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The Leadership Delta: Data-driven proof that skills-based promotion drives 10–20% higher representation of women in cyber leadership&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The Productivity Payoff: How third-party partnerships fill roles 16% faster and save over $70,000 per worker in lost productivity&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Scaling Workforce Intelligence: Strategies to transition from "degree-first"&amp;nbsp;to "skills-first"&amp;nbsp;cultures to solve for the remediation gap&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;"&lt;span&gt;The data is clear. Workforce resilience is no longer a soft HR issue. It is a measurable business advantage,"&amp;nbsp;Dohm said. "Organizations that invest in skills-based, transparent, and talent-friendly practices are strengthening their cyber teams, improving financial performance, and opening leadership pathways that have historically been closed."&lt;/span&gt;&lt;/p&gt; 
&lt;h3 style="line-height: 1.5; font-weight: normal;"&gt;By the numbers: average productivity loss avoided per worker&lt;/h3&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li&gt; &lt;p&gt;Formal mentorship programs: $127,465&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Personalized learning pathways: $127,167&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Skills-based workforce planning: $114,658&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Stretch assignments &amp;amp; lateral moves:&amp;nbsp;$112,881&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5;"&gt;The report highlights a severe retention crisis: women comprise 24% of the core cybersecurity workforce, but that representation drops to 20% at the 10-year mark, and plummets to just 15% at the executive CISO level. This attrition represents a massive loss of high-value capability, particularly given telemetry indicating women routinely excel in cross-functional risk evaluation, communication, and crisis coordination.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Surgical, objective operational shifts change this dynamic entirely. Firms utilizing structured promotion panels, internal employee skills profiles, and formalized mentorship programs see a 10% to 20% higher representation of women in management and leadership roles than organizations relying on legacy, subjective advancement pathways.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Despite clear data validating these returns, corporate adoption remains highly uneven. None of the highest-value talent practices are utilized by more than 55% of the enterprises surveyed.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Worse, when organizations do attempt to build skills-based programs, their foundation is structurally flawed. A staggering 62% of employers evaluate internal skills using subjective managerial or peer assessments—systems notoriously prone to cognitive bias. By contrast, fewer than 27% leverage objective metrics, such as real-world lab simulations or automated performance observations, meaning the majority of skills-based initiatives are running on unreliable data.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Enterprises do not have to construct these complex professional scaffolding structures in a vacuum. Engaging deeply with external professional networks and membership organizations like WiCyS acts as an immediate operational catalyst. Employers providing active access to these external networks fill cyber roles 16% faster, extend baseline retention rates by 9%, and avoid an average of $71,800 in lost productivity per worker.&lt;/p&gt; 
&lt;h4 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;The implications for cybersecurity teams and businesses&lt;/strong&gt;&lt;/h4&gt; 
&lt;p style="line-height: 1.5;"&gt;The data compiled in the research carries profound operational implications for cross-functional corporate leadership.&lt;/p&gt; 
&lt;h4 style="line-height: 1.5; font-size: 17px; font-weight: bold;"&gt;For corporate leadership: cybersecurity is a resource-constrained arena&lt;/h4&gt; 
&lt;h4 style="line-height: 1.5; font-size: 17px; font-weight: bold;"&gt;&lt;span style="font-weight: normal;"&gt;The broader labor market is entering a multi-decade contraction driven by an aging population and declining labor force participation. In an environment of absolute talent scarcity, businesses can no longer afford to treat mid-career turnover as standard operational noise. Failing to retain a specialized engineer means absorbing massive backfill costs and directly exposing the enterprise to elevated security risks while the role sits vacant.&lt;/span&gt;&lt;/h4&gt; 
&lt;h4 style="line-height: 1.5; font-size: 17px; font-weight: bold;"&gt;For CISOs and hiring managers: standardizing the promotion engine&lt;/h4&gt; 
&lt;h4 style="line-height: 1.5; font-size: 17px; font-weight: bold;"&gt;&lt;span style="font-weight: normal;"&gt;To stabilize the team under pressure, security leaders must completely replace opaque, subjective "tap-on-the-shoulder" advancement models. Cultural norms often cause self-promotion to come more naturally to male practitioners, meaning subjective evaluations inherently introduce bias. Implementing standardized, skills-based promotion criteria and panel-driven group interviews ensures employees compete purely on verified capability, not on who they know.&lt;/span&gt;&lt;/h4&gt; 
&lt;h4 style="line-height: 1.5; font-size: 17px; font-weight: bold;"&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;For security architecture: the skillsets are shifting dynamically&lt;/span&gt;&lt;/span&gt;&lt;/h4&gt; 
&lt;h4 style="line-height: 1.5; font-size: 17px; font-weight: bold;"&gt;&lt;span style="font-weight: normal;"&gt;Driven by automation and generative AI implementations, nearly a quarter (25%) of the core skills demanded in cybersecurity job postings have changed since 2023. Linear, rigid training paths are obsolete. Teams require dynamic, personalized learning pathways and regular stretch assignments to help individual contributors continuously adapt to changing attack surfaces without stalling their mid-career momentum.&lt;/span&gt;&lt;/h4&gt; 
&lt;p style="line-height: 1.5;"&gt;To transition from legacy, subjective pipelines to a high-velocity, resilient workforce model, businesses should execute a structured, continuous optimization framework.&lt;/p&gt; 
&lt;ol style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Cleanse the skills data Foundation: &lt;/span&gt;Move away from arbitrary manager scorecards. Secure-by-design talent programs must integrate vendor-neutral, performance-rooted skills assessments—such as hands-on technical labs or simulated cyber ranges—to build an objective internal inventory of actual workforce capability.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Synchronize top-down and bottom-up levers: &lt;/span&gt;Align leadership accountability with employee empowerment. Pair top-down initiatives (like transparent promotion paths and executive sponsorship) directly with bottom-up infrastructure (such as dedicated internal learning hours and formal mentorship structures).&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Institutionalize an iterative talent framework:&lt;/span&gt; Treat workforce development exactly like software optimization. Organizations must continuously: assess internal team pain points;&amp;nbsp;plan high-ROI interventions;&amp;nbsp;execute changes with stakeholder buy-in; and evaluate financial and operational outcomes via strict key performance indicators (KPIs).&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="line-height: 1.5;"&gt;The report's findings&amp;nbsp;prove&amp;nbsp;that human capital risk is business risk. True digital resilience cannot be bought off a vendor checklist or solved by simply out-bidding competitors for a dwindling pool of elite talent&lt;span style="line-height: 1.15;"&gt;. The enterprises that survive the tightening labor landscape will be those that realize widening advancement pathways, implementing objective skills profiles, and partnering with external communities are not peripheral corporate social responsibility initiatives—they are core tactical maneuvers that protect both the network and the bottom line.&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fwicys-workforce-equity&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>InfoSec Workforce</category>
      <category>Original Content</category>
      <category>WiCyS</category>
      <category>Human Resources</category>
      <pubDate>Mon, 08 Jun 2026 15:22:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/wicys-workforce-equity</guid>
      <dc:date>2026-06-08T15:22:00Z</dc:date>
    </item>
    <item>
      <title>How AI Is Transforming the Balance in Modern Cyber Threat Detection</title>
      <link>https://www.secureworld.io/industry-news/how-ai-transforming-modern-threat-detection</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/how-ai-transforming-modern-threat-detection" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/email%20scam%20-%20shutterstock_2494045751.jpg" alt="exasperated man at laptop" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Lately, cybersecurity operations have begun changing measurably. AI has moved from a supporting tool to an active layer in threat detection, and yet many organizations still underestimate the significance of that shift.&lt;br&gt;Cybersecurity ran on the same tired cycle for years. Attackers got sharper, defenders patched holes, vendors launched products, and everyone reset. It was broken by design, not by accident. The attacker only needed one opening. We needed to close every single one.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Lately, cybersecurity operations have begun changing measurably. AI has moved from a supporting tool to an active layer in threat detection, and yet many organizations still underestimate the significance of that shift.&lt;br&gt;Cybersecurity ran on the same tired cycle for years. Attackers got sharper, defenders patched holes, vendors launched products, and everyone reset. It was broken by design, not by accident. The attacker only needed one opening. We needed to close every single one.&lt;/p&gt; 
&lt;p&gt;AI didn't just improve that equation. It changed the nature of the game entirely.&lt;/p&gt; 
&lt;p&gt;But here's what I think many people misread: AI isn't winning the war for defenders by being faster than attackers. It's winning by being tireless in a way humans simply cannot replicate. And that distinction matters enormously when you're thinking about where this goes next.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;The old model was built on human bandwidth&lt;/h2&gt; 
&lt;p&gt;Have you ever wondered what legacy threat detection looked like in practice? A security operations center (SOC) receives thousands of alerts every day. Analysts triage by instinct, skipping the ones that seem low priority, catching obvious threats, and almost certainly missing the quiet ones. Those were the threats intentionally crafted to appear normal.&lt;/p&gt; 
&lt;p&gt;According to a &lt;a href="https://www.secureworld.io/industry-news/verizon-dbir-attackers-moving-faster-than-remediation"&gt;Verizon Data Breach Investigations Report&lt;/a&gt;:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Ransomware now appears in &lt;a href="https://www.verizon.com/business/resources/reports/dbir/"&gt;44% &lt;/a&gt;of all breaches analyzed.&lt;/li&gt; 
 &lt;li&gt;Vulnerability exploitation as an entry point grew by 34% year over year.&lt;/li&gt; 
 &lt;li&gt;Nearly half of all perimeter-device vulnerabilities went completely unpatched.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;That gap is where breaches happen, and no human team running manual triage closes it fast enough. Attacker dwell time remained a persistent problem across industries.&lt;/p&gt; 
&lt;p&gt;That lag isn't a people problem; it's a scale problem. Human analysts were never designed to monitor millions of data points running in parallel. We built processes for the bandwidth we had. AI breaks that constraint wide open. AI-powered detection pulls together signals from endpoints, network traffic, &lt;a href="https://v2cloud.com/products/cloud-servers"&gt;cloud servers&lt;/a&gt;, identity logs, and application behavior all at once. It doesn't clock out. It doesn't skip the low-priority queue at 3 a.m.&lt;/p&gt; 
&lt;p&gt;And it catches things a human team would genuinely never get to, not because the analysts aren't good, but because the math was never in their favor.&amp;nbsp;&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Where is AI making the difference?&lt;/h3&gt; 
&lt;p&gt;I want to get specific here, because this conversation deserves more than generalities.&lt;/p&gt; 
&lt;p&gt;The biggest gains aren't coming from AI replacing security analysts. They're coming from AI handling the first layer. The noise reduction, the pattern correlation, and the behavioral baselining. That frees up human analysts to focus on judgment calls that genuinely require human reasoning.&lt;/p&gt; 
&lt;p&gt;Here is what behavioral analytics looks like when it is actually working.&lt;/p&gt; 
&lt;p&gt;The system watches long enough to know what Tuesday morning looks like for a specific person on a specific machine doing a specific job.&lt;/p&gt; 
&lt;p&gt;When that picture breaks—an engineer who never goes near Finance suddenly pulls records at 2 a.m., a contractor whose download volume jumps 10 times overnight, a service account crawling through systems it has no business touching—it doesn't just throw up a flag. It hands the analyst something they can act on, not just a raw alert buried in a queue somewhere.&lt;/p&gt; 
&lt;p&gt;This is precisely where &lt;a href="https://www.currentware.com/solutions/insider-threat-detection-software/"&gt;insider threat protection software &lt;/a&gt;has started earning operational credibility. It's not the traditional perimeter defense play. It's not about blocking what's coming in from outside. It's about understanding what's happening inside, at the identity and behavior layer, and surfacing the deviations that human analysts would statistically miss in a high-volume environment.&lt;/p&gt; 
&lt;p&gt;The shift matters because the average annual cost of insider incidents reached &lt;a href="https://www.dtexsystems.com/blog/2025-cost-insider-risks-takeaways/"&gt;$17.4 million&lt;/a&gt;, up from $16.2 million in 2023, with containment taking an average of 81 days per incident.&lt;/p&gt; 
&lt;p&gt;The organizations treating this category of tooling as a compliance checkbox are making a serious mistake. The ones weaving it into their detection and response architecture are building something genuinely more resilient over time.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The attacker's AI problem and ours&lt;/h4&gt; 
&lt;p&gt;Now, I want to flip this, because the balance I mentioned above cuts both ways.&lt;/p&gt; 
&lt;p&gt;And attackers are not standing still while defenders build better tools; they're running AI too. More believable phishing at scale, automated target profiling, malware that mutates to dodge signature detection, and faster lateral movement once they're inside.&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.microsoft.com/en-us/security/security-insider/threat-landscape/microsoft-digital-defense-report-2025"&gt;The Microsoft Digital Defense Report 2025&lt;/a&gt; identifies the most urgent shifts in the threat landscape:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Threat actors are scaling up AI use.&lt;/li&gt; 
 &lt;li&gt;Infostealers are proliferating across enterprise environments.&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;Cybercrime has industrialized as a service.&lt;/span&gt;&lt;/li&gt; 
 &lt;li&gt;&lt;span&gt;Nation-state actors are expanding their reach.&lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span&gt;AI-driven phishing alone is now three times more effective than traditional campaigns. The gap between how fast attacks are evolving and how fast traditional detection adapts is not theoretical anymore.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;So, the balance isn't defender AI versus human attacker. It's AI versus AI, with human judgment on both sides making the calls that matter most.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;This is where I think the security industry needs a more honest conversation.&lt;br&gt;AI-powered detection tools are improving, but organizations that implement them and then walk away, assuming the tool runs itself, are setting themselves up for the same failure they had before, just with more expensive software on the invoice.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The value of AI in detection comes from continuous tuning, feedback loops, human review of edge cases, and ongoing refinement of what normal looks like in a given environment.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;AI doesn't remove the need for human expertise; it changes what that expertise is for.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;The governance problem nobody's solving fast enough&lt;/h5&gt; 
&lt;p&gt;Now, we come to the part of this transformation that keeps me up at night more than the technology itself does.&lt;/p&gt; 
&lt;p&gt;As AI takes on a larger role in detection decisions, flagging accounts, triggering automated responses, isolating endpoints, and blocking access, we're pushing consequential decisions further from human review.&lt;/p&gt; 
&lt;p&gt;That's a governance problem.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Who owns the decision when an AI-driven system incorrectly isolates a critical system during a production incident?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;What's the documented threshold for human escalation versus automated response?&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;Who reviews the model's decisions for bias, drift, or blind spots that developed quietly over six months?&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Most organizations haven't answered these questions. They bought the tool and deferred the governance conversation entirely.&lt;/p&gt; 
&lt;p&gt;The security teams getting this right treat AI detection systems the same way the leadership conversation tells us to treat agents broadly. With defined accountability, documented escalation paths, measurable thresholds, and genuine human oversight at decision points that carry operational risk.&lt;/p&gt; 
&lt;p&gt;They aren't asking "did the AI catch it?" They're asking whether they made the right call about what the AI was authorized to act on, and whether they had enough telemetry to know when to step in.&lt;/p&gt; 
&lt;p&gt;That's the maturity gap right now. It's not a technology gap. The technology has genuinely improved. It's a governance and operational discipline gap that most organizations are quietly ignoring.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;Where this goes from here&lt;/h6&gt; 
&lt;p&gt;My honest read is that 2026 is when the gap starts showing up in breach data. Organizations that did the work, built the detection infrastructure, and then governed it properly&amp;nbsp;will start producing different outcomes than those that bought tools and hoped for the best.&lt;/p&gt; 
&lt;p&gt;U.S. CISA has been moving toward AI-integrated detection requirements for critical infrastructure, and that regulatory pressure is going to land on compliance teams faster than most of them are currently prepared for.&amp;nbsp;&lt;br&gt;The balance in cyber threat detection is shifting. Defenders have tools now that fundamentally change the scale problem that was breaking them for years. But having the tools and operating them well are two completely different things.&lt;/p&gt; 
&lt;p&gt;The organizations that treat AI detection as a capability to build operational discipline around, rather than just a product to procure and forget, are the ones that will feel that balance tip in their favor.&lt;/p&gt; 
&lt;p&gt;Everyone else is still running the old loop.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fhow-ai-transforming-modern-threat-detection&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Cybersecurity</category>
      <category>Featured Author</category>
      <category>Incident Response / SIEM</category>
      <category>Threat Detection</category>
      <category>AI</category>
      <pubDate>Fri, 05 Jun 2026 13:42:02 GMT</pubDate>
      <author>trayalex812@gmail.com (Alex Tray)</author>
      <guid>https://www.secureworld.io/industry-news/how-ai-transforming-modern-threat-detection</guid>
      <dc:date>2026-06-05T13:42:02Z</dc:date>
    </item>
    <item>
      <title>FIFA World Cup 2026 Is a Cybercriminal's Dream Scenario</title>
      <link>https://www.secureworld.io/industry-news/fifa-world-cup-2026-cybercrime</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/fifa-world-cup-2026-cybercrime" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/FIFA%20-%20stadium-football-league-soccer-ball-soccer-2026-03-18-07-53-27-utc.jpg" alt="FIFA World Cup 2026 Is a Cybercriminal's Dream Scenario" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The world's most-watched sporting event kicks off June 11th in cities across the United States, Canada, and Mexico—and the criminal infrastructure built to exploit it has been under construction for months.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The world's most-watched sporting event kicks off June 11th in cities across the United States, Canada, and Mexico—and the criminal infrastructure built to exploit it has been under construction for months.&lt;/p&gt;  
&lt;p&gt;Research from &lt;a href="https://www.fortinet.com/content/dam/maindam/PUBLIC/02_MARKETING/08_Report/FIFA-World-Cup-2026-Cyberthreat-Landscape-Report.pdf"&gt;Fortinet's FortiGuard Labs&lt;/a&gt;, published this week, documents the scale of that preparation: more than 13,000 FIFA-themed domains registered between January and May 2026, a sharp spike in fake social media accounts, credential theft campaigns targeting both fans and tournament employees, and at least one coordinated phishing operation linked across dozens of impersonation sites by a single shared tracking ID.&lt;/p&gt; 
&lt;p&gt;The picture that emerges isn't a collection of opportunistic scams. It's an organized criminal ecosystem, built to scale, that will remain active long after the final whistle.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;Infrastructure built to deceive&lt;/h2&gt; 
&lt;p&gt;Of the 13,000-plus newly-registered FIFA-related domains, roughly 8.8%—approximately 1,145 domains—were classified as malicious or suspicious based on domain patterns and associated scam activity. Domain registrations spiked sharply from March through May, with April alone accounting for nearly 4,750 new registrations, signaling coordinated infrastructure buildout ahead of the tournament.&lt;/p&gt; 
&lt;p&gt;Most domains abused FIFA branding, ticketing keywords, streaming services, betting platforms, and hospitality terms to capture fans searching for tournament information. The .com TLD dominated at 87%, reflecting an attacker preference for appearing legitimate rather than hiding behind obscure extensions.&lt;/p&gt; 
&lt;p&gt;FortiGuard Labs also identified more than 1,700 suspected FIFA impersonation accounts and channels across major social media platforms, with Facebook and Instagram collectively accounting for nearly 90% of observed cases.&lt;/p&gt; 
&lt;p&gt;From the report: "The findings demonstrate that cyberthreats targeting the FIFA World Cup 2026 are already active and are expected to intensify as the tournament draws closer. Evidence of infrastructure reuse, coordinated domain registrations, and recurring scam tactics suggests that these activities are part of organized campaigns rather than isolated incidents."&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;The full scam taxonomy&lt;/h3&gt; 
&lt;p&gt;Fake ticketing operations are the headline threat, but the attack surface extends well beyond ticket fraud. FortiGuard researchers documented active campaigns across at least six categories.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Ticket fraud&lt;/span&gt;: Fake sites closely mimicking official FIFA portals harvest billing details and payment card data. One impersonation site, 26-fifa[.]com, registered in May 2026, walked victims through a four-step checkout flow—complete with a fake sign-in portal to capture login credentials before reaching the payment page. Scammers also operate through carding forums and Telegram channels, where fraudulent tickets are bundled with fake flight and hotel packages, with cryptocurrency payment options to avoid traceability.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Merchandise scams&lt;/span&gt;: Threat actors created fake storefronts that impersonated official FIFA merchandise pages and legitimate e-commerce platforms, including a site that mimicked Brazilian retailer Panini using a lookalike domain.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Job posting scams&lt;/span&gt;: With the tournament driving demand for event staffing, hospitality, and media support roles, FortiGuard identified a credential-harvesting campaign distributing fraudulent job offers from fake FIFA and sponsor domains—including impersonations of Coca-Cola, Marriott, PepsiCo, and Delta—via calendar meeting invitations. Victims who clicked were directed to a phishing page embedding a fake Google login interface. Credentials entered on the page were forwarded to backend APIs hosted on Render's cloud platform. Investigators identified a single Google Analytics tracking ID (G-123NZLZV56) embedded across all sites, strongly suggesting that a single threat actor or a coordinated group is behind the entire operation.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Fake streaming&lt;/span&gt;: Fraudulent streaming sites, promoted through social media and Telegram just before matches begin, pressure users to register quickly or install a fake media player—either of which leads to credential theft or malware installation.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Cryptocurrency fraud&lt;/span&gt;: A fake "World Cup Coin" ($WORLDCUP) airdrop campaign used official-looking branding and urgent messaging to pressure users into connecting&amp;nbsp;their wallets, enabling unauthorized transactions and financial theft.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Malicious applications&lt;/span&gt;: A trojanized version of the 1xBet betting application was observed exhibiting ransomware-related behaviors, including encrypted communications and persistence mechanisms mapped to multiple MITRE ATT&amp;amp;CK techniques. The executable communicated through legitimate cloud services—Supabase and Render—to blend malicious traffic with normal activity.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/hardening-events-deepfake-disruptions"&gt;Hardening Large-Scale Events Against Deepfake Disruptions&lt;/a&gt;]&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;AI has changed the attack calculus&lt;/h4&gt; 
&lt;p&gt;What makes this threat cycle distinct from prior tournaments is AI's role as an operational accelerator.&lt;/p&gt; 
&lt;p&gt;Anne Cutler, Cybersecurity Evangelist at Keeper Security, described the shift plainly: "Phishing emails that are grammatically perfect, contextually accurate, and personalized with your name and your team can be written by an AI tool in seconds. A text message from a friend or family member urgently asking for money for tickets may not be from whom you think. The old advice about looking for bad spelling and awkward phrasing is obsolete."&lt;/p&gt; 
&lt;p&gt;Pyry Åvist, Co-founder and CTO at Hoxhunt, put a timeline on the acceleration. "We observed explosive growth in AI-assisted phishing beginning in late 2025," he said. "Attackers can now generate realistic messages in multiple languages, tailor them, blend into specific corporate workflows, and produce many variations of the same lure"—a combination that makes filtering harder and raises the likelihood that at least one version lands.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;The organizational exposure problem&lt;/h5&gt; 
&lt;p&gt;The risk doesn't stop with individual fans. Organizations connected to the tournament—sponsors, broadcasters, vendors, host-city suppliers—face a distinct and underappreciated threat surface.&lt;/p&gt; 
&lt;p&gt;Collin Hogue-Spears, Senior Director of Solution Management at Black Duck, offered a blunt assessment of the defensive gap: "Over a third of FIFA's own sponsors and suppliers have no DMARC record on their mail domains, which means a criminal crew does not need to forge anything to spoof them. Paris 2024 saw 140 successful cyber incidents at roughly a quarter of this footprint. The hard part is not knowing what to do. It is counting how many places have to do it."&lt;/p&gt; 
&lt;p&gt;The credential exposure data from FortiGuard underscores that point. Stealer log telemetry identified more than 260 credentials tied specifically to FIFA employees, more than 270,000 credentials from fans visiting FIFA-related websites, and more than 1,500 FIFA-associated employee and organizational accounts in historical breach datasets. Those credentials don't expire when the tournament ends.&lt;/p&gt; 
&lt;p&gt;Cutler captured the delayed risk: "Attackers know exactly who to target. They know the accounts you're creating right now for streaming and ticketing almost certainly share a password with another more valuable account. Those credentials get harvested, verified, and deployed weeks or months later—long after the final whistle and long after anyone connects the breach to a World Cup ticketing site. A fan who cuts corners in June becomes the entry point in September."&lt;/p&gt; 
&lt;p&gt;Rex Booth, CISO at SailPoint, framed the issue at the organizational level. "The true danger lies in the ability to grant attackers access to credentials, enabling them to masquerade as trusted insiders," he said, adding that organizations need to treat identity as the primary control plane, not an afterthought.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;Mobile as the primary attack vector&lt;/h6&gt; 
&lt;p&gt;Kern Smith, Vice President of Global Solutions at Zimperium, argued that the tournament demands a mobile-first security posture. With an estimated 6.5 million fans traveling across three host nations, mobile devices serve as the primary surface for ticketing, payments, authentication, and communications—and the volume of legitimate activity makes anomalous behavior harder to spot.&lt;/p&gt; 
&lt;p&gt;"Attacks increasingly start on the mobile device itself," Smith said. "Mobile-targeted phishing, malicious applications, session hijacking, and AI-assisted social engineering allow attackers to bypass traditional controls and operate inside legitimate user activity." His guidance: avoid installing applications from QR codes or links received through messaging channels, update devices before travel, and treat unexpected authentication prompts as indicators to verify before acting.&lt;/p&gt; 
&lt;div style="font-weight: normal; font-size: 24px;"&gt;
 What security teams should do now
&lt;/div&gt; 
&lt;p&gt;FortiGuard's recommendations track closely with what the experts above emphasized. For organizations with any surface area connected to the tournament:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Monitor newly-registered domains and track impersonation activity against your brand continuously—not just during the tournament window. The infrastructure is already live.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Enforce DMARC in reject mode on every owned domain. Hogue-Spears' point about spoofing legitimate sponsor domains without any technical forgery is not theoretical—it's an active risk with no excuse for remaining unaddressed.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Prioritize phishing-resistant MFA on every vendor, volunteer, and partner account. Password reuse between a fan's ticketing account and their corporate credentials is a real and documented attack path.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Run purple-team exercises against identity and email paths before the tournament begins. As Hogue-Spears noted, organizations that get hit won't have lost to a sophisticated adversary—they'll have lost to a checklist they didn't finish.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For individual fans, the baseline is straightforward: use only official apps and sites, avoid transactions over public Wi-Fi, use unique passwords, and enable MFA on every account created for tournament-related activity.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Ffifa-world-cup-2026-cybercrime&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Social Engineering</category>
      <category>Security Awareness</category>
      <category>Original Content</category>
      <category>Phishing</category>
      <category>Threat Intel</category>
      <category>Sports &amp; Entertainment</category>
      <pubDate>Thu, 04 Jun 2026 13:06:02 GMT</pubDate>
      <author>drewt@secureworld.io (Drew Todd)</author>
      <guid>https://www.secureworld.io/industry-news/fifa-world-cup-2026-cybercrime</guid>
      <dc:date>2026-06-04T13:06:02Z</dc:date>
    </item>
    <item>
      <title>Trump AI Executive Order Gives NSA Classified Role Over Frontier Models</title>
      <link>https://www.secureworld.io/industry-news/trump-executive-order-ai-nsa</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/trump-executive-order-ai-nsa" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Congress%20-%20shutterstock_2443980397.jpg" alt="U.S. federal building and flag" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;President Trump signed a &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"&gt;new executive order&lt;/a&gt; Tuesday directing the U.S. National Security Agency to develop a classified benchmarking process for assessing the cyber capabilities of commercial AI models—and inviting developers of the most powerful systems to submit those models for government review up to 30 days before wider release.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;President Trump signed a &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/promoting-advanced-artificial-intelligence-innovation-and-security/"&gt;new executive order&lt;/a&gt; Tuesday directing the U.S. National Security Agency to develop a classified benchmarking process for assessing the cyber capabilities of commercial AI models—and inviting developers of the most powerful systems to submit those models for government review up to 30 days before wider release.&lt;/p&gt; 
&lt;p&gt;The order, titled "Promoting Advanced Artificial Intelligence Innovation and Security,"&amp;nbsp;lands on the same day that Anthropic disclosed a confidential SEC filing for an IPO, with OpenAI reportedly eyeing a similar offering later this year.&lt;/p&gt; 
&lt;p&gt;The timing is not incidental. As frontier AI labs approach public markets, the federal government is moving to formalize its relationship with the technology—and with the companies building it.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;What the executive order actually does&lt;/h2&gt; 
&lt;p&gt;The order operates across four sections. Section 2 sets 30- to 60-day deadlines for hardening federal systems: CISA must issue Binding Operational Directives to accelerate civilian network defense and expand AI-enabled defensive tools; a new AI cybersecurity clearinghouse, coordinated by Treasury, NSA, and CISA, will centralize vulnerability scanning, discovery, and patch distribution across critical infrastructure. Rural hospitals, community banks, and local utilities are specifically named as intended beneficiaries—a signal that the order's authors are aware of the security gap between large federal agencies and the rest of the critical infrastructure ecosystem.&lt;/p&gt; 
&lt;p&gt;Section 3 is the most novel. The NSA gains authority to classify, benchmark, and designate advanced AI models as "covered frontier models." Developers who voluntarily participate can engage the government to determine whether their model meets that threshold, then provide pre-release access for up to 30 days before broader distribution. The government can also help select "trusted partners" who receive early access during that window. Section 4 directs the Attorney General to prioritize prosecution under existing computer fraud and wire fraud statutes when AI is used to commit an offense.&lt;/p&gt; 
&lt;p&gt;One terminological note: the order references the "Secretary of War"—the renamed title for the Secretary of Defense, formalized under the current administration—and tasks that office with cyber defense of the Department of War's information systems, in coordination with the Committee on National Security Systems.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Voluntary is the ceiling, not the floor&lt;/h3&gt; 
&lt;p&gt;The order is explicit that nothing in Section 3 authorizes a mandatory licensing, preclearance, or permitting regime. That constraint is not merely a policy choice; it reflects the boundaries of executive authority.&lt;/p&gt; 
&lt;p&gt;Collin Hogue-Spears, Senior Director of Solution Management at Black Duck, put it plainly: "Voluntary is not the policy floor. It is the legal ceiling on executive AI review without Congress. Existing national-security statutes offer no obvious basis for compelled model submission."&lt;/p&gt; 
&lt;p&gt;Hogue-Spears noted that China required filings for generative AI services through its Cyberspace Administration in 2023, and that the EU's AI Act imposed documentation and cooperation obligations on general-purpose AI models in August 2025. The U.S., by contrast, is building a voluntary review lane because the statutory authority for a mandatory one does not yet exist. The administration sent Congress an AI legislative framework in March 2026 calling for federal preemption of state AI laws, but it has not become law.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/us-ai-labs-government-security-reviews"&gt;Major U.S. AI Labs Now Subject to Pre-Release Government Security Reviews&lt;/a&gt;]&lt;/p&gt; 
&lt;p&gt;Until it does, the practical stakes are limited. As Hogue-Spears noted, the unresolved question is whether Congress eventually ties pre-release AI review to procurement eligibility or export approvals. Without that linkage, voluntary review does not become market access—and federal policy cannot preempt the state-by-state AI regulatory patchwork forming in Colorado, California, New York, Texas, and Virginia.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;NSA in the room: what it means for the industry&lt;/h4&gt; 
&lt;p&gt;Even a voluntary framework with the NSA at the center represents a meaningful shift.&lt;/p&gt; 
&lt;p&gt;Ram Varadarajan, CEO at Acalvio, framed it as a structural industry transition. "The formalization of government pre-release reviews is marking the end of AI's 'Wild West' era," Varadarajan said. "Geopolitical alignment and national security clearances are going to become as critical to a frontier lab's valuation as its raw compute. It's a transition that's going to transform frontier AI from a pure-play tech bet into a regulated strategic industry."&lt;/p&gt; 
&lt;p&gt;Merlin Group's Robert Costello took a more measured but still positive view. According to him, the pre-release window gives the government a meaningful opportunity to identify concerns before they become operational problems, rather than responding after the fact.&lt;/p&gt; 
&lt;p&gt;Whether the government can actually fulfill the benchmarking role envisioned in the order is a different question.&lt;/p&gt; 
&lt;p&gt;Rajeev Gupta, Co-Founder and CPO at Cowbell, was skeptical, saying "Even with a review window, it's unclear which agency would have the technical expertise and staffing needed to properly evaluate these systems at the pace AI is advancing." Gupta pointed to the nuclear industry's post-Three Mile Island creation of the Institute of Nuclear Power Operations as a possible model—a public-private consortium in which labs contribute funding, talent, and technical resources, while the government provides regulatory authority. "Supporting an independent body that helps ensure accountability should be viewed as a core cost of operating at frontier scale, and not just as a regulatory burden," Gupta said.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;The deployment gap: where security programs typically break down&lt;/h5&gt; 
&lt;p&gt;Several cybersecurity practitioners emphasized that pre-release model review, while useful, addresses only the earliest part of the security lifecycle.&lt;/p&gt; 
&lt;p&gt;Marcus Fowler, CEO of Darktrace Federal, pointed to what comes after. "The security conversation must extend beyond model development and testing to focus on the operational realities of AI deployment," Fowler said. "As AI becomes embedded across applications, cloud environments, autonomous agents, operational technology, and critical infrastructure workflows, organizations will need clearer visibility into how those systems behave, what data and resources they can access, and when activity moves outside expected parameters."&lt;/p&gt; 
&lt;p&gt;The analogy to coordinated vulnerability disclosure is instructive. That process began as voluntary industry cooperation and gained teeth only when procurement requirements, insurers, and auditors started expecting compliance.&lt;/p&gt; 
&lt;p&gt;Noma Security's Diana Kelley argued that a similar evolution would make a durable frontier AI review process: independent testing, clear risk thresholds, disclosure obligations, post-release monitoring, incident reporting, and meaningful consequences when unacceptable risks are found. "Without that structure, a voluntary process could look reassuring without materially reducing risk," Kelley said.&lt;/p&gt; 
&lt;p&gt;There's also the question of what a pre-release review can't catch. About two-thirds of current AI-related incidents still originate from traditional weaknesses, according to Randolph Barr, CISO at Cequence Security, but the remaining third are "AI-native": model poisoning, data poisoning, prompt injection, and autonomous agents that can chain API calls with minimal human oversight. Those risks evolve after deployment, not before release, and no pre-release review catches them.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;Speed remains the defining gap&lt;/h6&gt; 
&lt;p&gt;Dave Gerry, CEO at Bugcrowd, acknowledged the order as a meaningful first step while identifying a more fundamental problem. "The biggest gap isn't in strategy, it's in the speed of operating," Gerry said. "Adversaries today are operating at machine speed and the government is operating at bureaucracy speed. Proactive security must become the default to help offset this velocity gap."&lt;/p&gt; 
&lt;p&gt;Gerry also flagged that the order's emphasis on federal agency defense leaves state and local governments—disproportionately targeted by cybercriminal groups precisely because of their limited capacity—largely dependent on voluntary federal programs extending outreach to smaller organizations. Bug bounty and vulnerability disclosure programs have demonstrated success across federal agencies, he noted, but are still not standard practice or required for every agency or critical infrastructure operator.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/state-cio-ciso-report-2026"&gt;State CIOs, CISOs Issue Distress Signal on AI, Limited Resources&lt;/a&gt;]&lt;/p&gt; 
&lt;p&gt;A longer-horizon concern involves operational technology (OT). As frontier AI models get integrated into OT environments—smart cameras, building controllers, physical security systems—the integrity of the model itself becomes a critical security concern, argues John Gallagher of Viakoo. Ensuring that an AI agent managing a physical network has not been poisoned or manipulated into disabling security protocols represents the next layer of risk that no current framework, voluntary or otherwise, has fully addressed.&lt;/p&gt; 
&lt;div style="font-weight: normal; font-size: 24px;"&gt;
 Bottom line for security leaders
&lt;/div&gt; 
&lt;p&gt;The order moves the federal government from a passive observer to an active participant in frontier AI development—but&amp;nbsp;participation is still invited, not required. The NSA gets a classified benchmarking role; CISA gets new directives and a clearinghouse mandate; critical infrastructure operators get expanded access to AI-enabled security tools. What the order does not create is a binding national standard, mandatory pre-release review, or any mechanism to preempt the state AI regulatory landscape that is developing independently.&lt;/p&gt; 
&lt;p&gt;For CISOs at organizations operating across state lines, or at vendors in the frontier AI space, the more consequential governance developments remain in state legislatures and Congress, where the administration's AI legislative framework is still awaiting&amp;nbsp;action.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Ftrump-executive-order-ai-nsa&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>NSA</category>
      <category>Artificial Intelligence</category>
      <category>Policy</category>
      <category>Original Content</category>
      <category>U.S. Government</category>
      <category>CISA</category>
      <pubDate>Wed, 03 Jun 2026 16:43:28 GMT</pubDate>
      <author>drewt@secureworld.io (Drew Todd)</author>
      <guid>https://www.secureworld.io/industry-news/trump-executive-order-ai-nsa</guid>
      <dc:date>2026-06-03T16:43:28Z</dc:date>
    </item>
    <item>
      <title>SMB Paradox: Navigating Enterprise-Grade Threats with Limited Defenses</title>
      <link>https://www.secureworld.io/industry-news/smb-paradox-threats-defenses</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/smb-paradox-threats-defenses" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Small%20Business%20-%20caucasian-woman-typing-on-a-laptop-inside-her-wood-2025-10-19-16-21-51-utc%20(1)-1.jpg" alt="retail worker using laptop" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5;"&gt;For small and medium-sized businesses (SMBs), a dangerous misconception has historically governed security strategy: "&lt;span style="line-height: 1.15;"&gt;We are too small to be a target." &lt;/span&gt;However, two recent reports on foundational compliance and threat intelligence paint a starkly different picture.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="line-height: 1.5;"&gt;For small and medium-sized businesses (SMBs), a dangerous misconception has historically governed security strategy: "&lt;span style="line-height: 1.15;"&gt;We are too small to be a target." &lt;/span&gt;However, two recent reports on foundational compliance and threat intelligence paint a starkly different picture.&lt;/p&gt;  
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;By analyzing the data from the UK Government's &lt;a href="https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2025/cyber-security-breaches-survey-2025"&gt;Cyber Security Breaches Survey 2025&lt;/a&gt; alongside the anonymized telemetry inside &lt;a href="https://guardz.com/wp-content/uploads/2025/09/SMB-Threat-Report.pdf"&gt;The Guardz 2025 SMB Cybersecurity Report&lt;/a&gt;, a harsh reality comes to light: SMBs are no longer just collateral damage in global cyber campaigns; they are squarely in the crosshairs, facing a barrage of highly professionalized, enterprise-grade threats without the benefit of enterprise-grade security operations or budgets.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The intersection of these two reports establishes a clear baseline: vulnerability exposure and attack volumes are shifting rapidly, even as organizational awareness matures.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The UK Government's Cyber Security Breaches Survey 2025 highlights that a significant percentage of businesses and charities face sustained, weekly probes. Meanwhile, the mid-year telemetry inside The Guardz 2025 SMB Cybersecurity Report confirms that cyberattacks on small ecosystems have skyrocketed exponentially. Guardz logged nearly double the weekly active security incidents compared to the previous tracking cycle, pointing to an aggressive pivot by digital adversaries.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Threat actors are surgically targeting specific industry vectors based on the perceived value of their underlying data.&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Financial Services:&lt;/span&gt; Representing the single largest share of attempts, accounting for 24.4% of all recorded incidents with an average severity rating of 4.8 out of 5. Attackers heavily target Microsoft Exchange Online platforms to hijack financial messaging paths.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Healthcare:&lt;/span&gt; Contributing to 18.9% of attacks, primarily targeting Microsoft SharePoint Online infrastructure, exposing critical personal health records and disrupting operational continuity.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Government &amp;amp; Manufacturing:&lt;/span&gt; Government sectors face the highest severity levels (4.9/5), heavily concentrated around identity and access management layers like Microsoft Entra ID. Manufacturing accounts for 13.9% of attacks, targeting office suites to interrupt supply chains or exfiltrate core intellectual property.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;The core security challenges: where SMBs are failing&lt;/strong&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.5;"&gt;The data reveal&amp;nbsp;that the primary pain points for small organizations do not stem from sophisticated zero-day exploits, but from basic, systemic failures in structural network hygiene.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Adversaries have largely abandoned the practice of "breaking in"; instead, they are simply logging in. Stolen credentials have become the definitive center of the cybercriminal playbook, with more than 80% of all confirmed data breaches involving compromised passwords.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Compounding this crisis is a massive, persistent enforcement gap: the majority of SMBs still do not mandate Multi-Factor Authentication (MFA) across their workforce. This allows threat actors to purchase siphoned login data from underground markets—flooded by info-stealing malware that harvests browser session cookies and authentication tokens—and gain immediate, unmonitored access to cloud portals.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;As small businesses have migrated their core assets and infrastructure to SaaS environments to optimize costs, threat actors have followed the data. The vast majority of breaches now involve cloud-stored assets. Automated password-spraying and credential-stuffing campaigns targeting cloud login portals have skyrocketed, occasionally reaching thousands of attempts per second per entity.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Furthermore, identity-based attacks have grown increasingly complex, utilizing advanced techniques like MFA bypass (10.3% of total identity attacks) and account takeovers to establish persistence inside corporate ecosystems.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Ransomware remains a top-tier operational threat, with Guardz logging more than a hundred distinct ransomware variants actively targeting SMB environments. Criminal syndicates have institutionalized the "double-extortion" model—pairing traditional system encryption with aggressive data exfiltration.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Alarmingly, the report notes that some threat groups are shifting entirely away from deployment payloads, skipping encryption altogether to engage in pure data theft extortion (accounting for roughly 25% of breaches). For a small business, this neutralizes traditional safety nets; even if the firm possesses perfect offline backups, the threat of public regulatory shaming and customer data exposure forces immense compliance pressure to pay.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;While the threat landscape appears daunting, the combined insights of the UK Breach Survey and Guardz outline a clear roadmap for Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs), and internal IT teams to dramatically reduce collective organizational risk.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The era of point-in-time, manual perimeter assessments is obsolete. Because generative AI tools allow threat actors to automate social engineering and accelerate attack deployment, defenders must match this velocity. SMBs must deploy unified, multi-layered security suites that consolidate telemetry across endpoints, email channels, cloud storage accounts, and identity events. Leveraging AI-augmented defense tools allows resource-constrained organizations to automate anomaly detection and implement self-healing endpoint mitigation without requiring a 24/7 dedicated internal SOC.&lt;/p&gt; 
&lt;h3 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;Ruthless identity hardening&lt;/strong&gt;&lt;/h3&gt; 
&lt;p style="line-height: 1.5;"&gt;Because credential abuse represents the primary entry point for network intrusion, fixing the identity layer yields the highest return on security investment. Organizations must:&lt;/p&gt; 
&lt;ul style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Enforce Ubiquitous MFA:&lt;/span&gt; Implement strict multi-factor authentication across all applications, specifically targeting cloud infrastructure tools (such as Outlook, SharePoint, and Entra ID portals).&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Manage App Integration Permissions:&lt;/span&gt; Actively monitor and limit third-party OAuth application consent authorizations to block session-hijacking and token-theft vectors.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Deploy Behavioral Endpoint Monitoring:&lt;/span&gt; Utilize modern Endpoint Detection and Response (EDR) platforms capable of flagging abnormal lateral movement or anomalous login behaviors, neutralizing "living off the land" (LOTL) tactics where attackers abuse legitimate system administrative tools.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Traditional security awareness training that advises users to look for typos or awkward language is failing against AI-crafted phishing campaigns. Organizations must evolve their training to focus on psychological manipulation patterns—such as artificial urgency, forced isolation, or unusual financial requests—rather than relying on technical tells that generative AI can easily erase&lt;span style="line-height: 1.15;"&gt;.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fsmb-paradox-threats-defenses&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Original Content</category>
      <category>IT/Security Budget</category>
      <category>Cybercrime / Threats</category>
      <category>SMB</category>
      <pubDate>Wed, 03 Jun 2026 14:04:03 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/smb-paradox-threats-defenses</guid>
      <dc:date>2026-06-03T14:04:03Z</dc:date>
    </item>
    <item>
      <title>Secure Vibe Coding: Ship Fast without the Security Risks</title>
      <link>https://www.secureworld.io/industry-news/secure-vibe-coding-without-security-risks</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/secure-vibe-coding-without-security-risks" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Vibe%20coding%20-%20professionals-collaborating-over-source-code-on-mu-2026-01-09-00-42-39-utc.jpg" alt="hand pointing at code on monitor" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;"Vibe coding" is here to stay.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;"Vibe coding" is here to stay.&lt;/p&gt; 
&lt;p&gt;Vibe coding has changed how developers work. AI tools can now suggest functions, scaffold entire services, and generate code for everything from a login system to database password handling—all in seconds. That speed is genuinely powerful. But generated code comes with a real risk: AI tools do not inherently produce secure code.&lt;/p&gt; 
&lt;p&gt;They produce plausible code. And when developers treat AI-generated code as ready to ship, security vulnerabilities slip through faster than any manual process could introduce them. Sensitive data gets mishandled. Vulnerable code gets merged. The speed that makes vibe coding so appealing is the same force that makes it dangerous when security is an afterthought.&lt;/p&gt; 
&lt;p&gt;So, what does secure vibe coding look like?&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;This post outlines a practical framework for using AI in software development without compromising security fundamentals that keep teams safe.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;What is vibe coding?&lt;/h2&gt; 
&lt;p&gt;&amp;nbsp;In this context, vibe coding means using AI to write software, where the developer no longer has to type every line manually. Instead, the developer guides, prompts, reviews, and ships code generated by AI.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;The problem isn't the concept. The problem is how quickly "generate" can turn into "merge," especially when the output looks correct.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Secure vibe coding starts with one key mindset shift.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Principle #1: Treat AI like a junior developer (not an oracle)&lt;/p&gt; 
&lt;p&gt;AI can produce code that looks polished, but that doesn't mean it's correct, secure, or maintainable. A better mental model is to treat AI like a junior developer.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;It's fast. It's confident. It's helpful.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;And it needs oversight.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;That means reviewing AI-generated code with the same rigor you'd apply to someone fresh out of school writing production code for the first time.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;You should ask questions like:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Why did you do it this way?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;What assumptions are you making?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Where is input validated?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;How does authentication work?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;What happens when something fails?&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AI agents may still require significant human intervention. That's not a weakness-it's the point. Humans own the responsibility.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Principle #2: Use SRR –&amp;nbsp;Small, Reversible, Reviewable&lt;/p&gt; 
&lt;p&gt;One of the fastest ways AI-assisted development becomes dangerous is when it generates too much at once.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Large changes create the worst-case scenario:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;20 files modified&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;New integrations added&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Sweeping refactors introduced&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Dependencies pulled in&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;No reviewer can confidently validate what's happening&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Even if the reviewer spends hours reading, the final outcome often becomes: "This is broken. Undo it." But by then, it may already be merged—or it may be painful to reverse.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;That's why secure vibe coding needs &lt;span style="font-weight: bold;"&gt;SRR: Small, Reversible, Reviewable.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;This is how we want AI to write code:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Small changes in bite-sized commits&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Reversible work that can be rolled back cleanly&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Reviewable code that a human can actually validate&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AI makes it tempting to move faster, but secure teams don't abandon good engineering practices just because code can be produced more quickly.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Principle #3: Use security as a prompt constraint&lt;/p&gt; 
&lt;p&gt;Secure vibe coding doesn't happen by accident. It happens when security requirements are part of the prompt itself.&lt;/p&gt; 
&lt;p&gt;That means prompts shouldn't be "write a login feature."&lt;/p&gt; 
&lt;p&gt;They should include security constraints like:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Authentication expectations&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Input validation rules&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Logging requirements&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Data sensitivity handling&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Authorization boundaries&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;These are not "nice to have" details; they define whether the output is safe.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Don't go wild west with prompts&lt;/h3&gt; 
&lt;p&gt;One of the most important ideas here is avoiding reinvention.&lt;/p&gt; 
&lt;p&gt;Security teams don't reinvent secure patterns every time they implement auth, validation, or logging. They use playbooks. Tested patterns. Proven constraints.&lt;/p&gt; 
&lt;p&gt;AI-assisted development should work the same way.&lt;/p&gt; 
&lt;p&gt;Instead of starting from scratch every time, teams should create reusable prompt templates—essentially, "security paragraphs"—that can be inserted into prompts for common tasks.&lt;/p&gt; 
&lt;p&gt;This creates consistency and reduces the chance that a developer forgets critical security requirements during a fast-moving build.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The VIBE Framework: A practical model for secure AI development&lt;/h4&gt; 
&lt;p&gt;To make this approach repeatable, you can think of secure vibe coding through the lens of an acronym:&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;VIBE = Vision, Interfaces, Build Loops, Enforcement&lt;/p&gt; 
&lt;p&gt;Each part plays a role in keeping AI output aligned with secure engineering.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;V = Vision&lt;/p&gt; 
&lt;p&gt;Vision means defining what "success" looks like before AI generates anything. This includes:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;The desired behavior&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;The expected outcomes&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;What must not break&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;What constraints must be honored&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Secure vibe coding is not: "Let's start prompting and see where we end up." It's: "We know where we need to end, and we'll build toward that outcome."&lt;/p&gt; 
&lt;p&gt;This is where prompt engineering becomes a security control, not just a productivity trick.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;I = Interfaces&lt;/p&gt; 
&lt;p&gt;Interfaces means defining trust boundaries and system constraints up front-and forcing AI to work within them. That can include:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Repository-level constraints (which files AI can touch)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Architectural boundaries (what services can call what)&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Rules for data access and authentication&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Explicit "do not modify" zones&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;It should be a layered approach with gates, so the AI clearly understands:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Where it is allowed to work&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Where it must not work&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;What it can't change without human approval&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;A common example: third-party library creep&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;AI often introduces dependencies casually.&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;A secure interface constraint should be: Do not add third-party libraries unless explicitly recommended and approved. This prevents hidden risk from unvetted packages entering your build because an AI thought it was "the easiest way.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;B = Build Loops&lt;/p&gt; 
&lt;p&gt;Build loops are the steps your team follows to ship software-and secure vibe coding requires a loop that includes validation.&lt;/p&gt; 
&lt;p&gt;A secure AI build loop looks like:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Clarify what you want&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Generate the code&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Review the code&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Test the code&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Ship the code&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The key idea: We are not doing "generate to push."&lt;/p&gt; 
&lt;p&gt;AI doesn't remove the need for review and testing. It increases the need for them.&lt;/p&gt; 
&lt;p&gt;Secure teams should:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Review generated code before anything else&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Generate and review tests as part of the process&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Validate behavior before shipping&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;E = Enforcement&lt;/p&gt; 
&lt;p&gt;Enforcement is how you ensure AI actually follows the rules you set.&lt;/p&gt; 
&lt;p&gt;This includes two layers:&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;1. Use existing security tooling&lt;/p&gt; 
&lt;p&gt;Run the same controls you already rely on for human-written code:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;SAST&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Dependency scanning&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Secrets scanning&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Other security checks in CI/CD&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;AI should be held to the same standards as developers.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;2. Add guardrails for AI-generated code&lt;/p&gt; 
&lt;p&gt;Secure vibe coding also benefits from visibility and process controls, such as:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span&gt;&lt;/span&gt;PR labels that indicate AI-generated code is present&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Tags or annotations in code blocks&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Checklists that confirm required steps were followed&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For example:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Did you do a quick threat model for a critical feature?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Did you evaluate risk and trust boundaries?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Did you review the code and tests before production?&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Enforcement is what makes secure AI development repeatable across teams.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h5 style="font-weight: normal;"&gt;6 security risks of vibe coding&lt;/h5&gt; 
&lt;p&gt;AI tools can accelerate development dramatically, but vibe coding introduces a distinct set of security risks that teams need to understand before they scale the practice. Speed does not create vulnerabilities on its own—but it does make them harder to catch.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;1. Over-reliance on AI-generated code&lt;/p&gt; 
&lt;p&gt;When developers trust AI-generated code without reviewing it, security vulnerabilities can move from prompt to production without anyone noticing. AI tools generate plausible code, not necessarily secure code. They do not know your architecture, your data classification policies, or the specific threats your application faces. A login system that looks functional may be missing input validation entirely. An endpoint that appears clean may be exposing sensitive data to anyone who knows where to look.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;2. Insecure handling of sensitive data&lt;/p&gt; 
&lt;p&gt;AI tools are not trained to treat sensitive data with the care your security policies require. Generated code may log credentials, store database passwords in plaintext, pass sensitive values through URL parameters, or handle personally identifiable information in ways that violate compliance requirements. These are not edge cases. They are common outputs when security constraints are not explicitly built into the prompt from the start.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;3. Introduction of vulnerable code through dependencies&lt;/p&gt; 
&lt;p&gt;Vibe coding often produces code that pulls in third-party libraries without flagging whether those packages are maintained, vetted, or free of known vulnerabilities. A single unreviewed dependency can introduce security vulnerabilities that affect the entire application. AI-generated code expands your attack surface every time it adds a package your team did not explicitly approve.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;4. Lack of context around trust boundaries&lt;/p&gt; 
&lt;p&gt;AI tools have no awareness of your system's trust boundaries. Generated code may allow unauthenticated users to reach endpoints that should be protected, skip authorization checks entirely, or mix privileged and unprivileged operations in the same function. Without a clear definition of what the AI can and cannot touch, vulnerable code ends up in places where the blast radius of an exploit is highest.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;5. Secrets and credential exposure&lt;/p&gt; 
&lt;p&gt;One of the most consistent risks in AI-generated code is the casual handling of secrets. Database passwords, API keys, and authentication tokens can appear hardcoded in generated code, written to logs, or exposed through error messages. These are not intentional choices by the AI; they are the result of generating functional-looking code without security constraints baked into the prompt or enforced at the tooling level.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;6. Velocity outpacing review&lt;/p&gt; 
&lt;p&gt;The core risk of vibe coding is not any single vulnerability type. It is the pace. When AI tools make it possible to generate hundreds of lines of code in minutes, the gap between generation and review widens. Security vulnerabilities accumulate faster than teams can find them. Secure code requires deliberate review, and review requires time—two things that vibe coding, used without discipline, actively works against.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;Secure vibe coding can make teams faster and safer&lt;/h6&gt; 
&lt;p&gt;When security is built into the way your team uses AI—through small changes, strong constraints, clear interfaces, disciplined build loops, and enforceable guardrails—vibe coding becomes more than a productivity trend.&lt;/p&gt; 
&lt;p&gt;It becomes a way to:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;Reduce time spent on repetitive tasks&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Move faster without losing control&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Focus developer effort on the "critical thinking" work&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;Avoid shipping vulnerabilities at machine speed&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Vibe coding is powerful. The goal isn't to stop it. The goal is to learn how to do it securely.&lt;/p&gt; 
&lt;div style="font-size: 24px;"&gt;
 Want to build secure code—even in the age of AI?
&lt;/div&gt; 
&lt;p&gt;Security Journey helps organizations train developers to write secure code, reduce vulnerabilities, and build security into the software development lifecycle—whether code is written by humans, AI, or both.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;span style="color: #00cccc;"&gt;&lt;a href="https://www.securityjourney.com/coding-training-solutions/custom-demo-form?utm_campaign=34329883-%5B3rd%20Party%5D%20Secure%20World&amp;amp;utm_source=Vibe%20Coding%20Blog" style="color: #00cccc;"&gt;Schedule a demo to learn more!&lt;/a&gt;&lt;/span&gt;&lt;span style="color: #00cccc;"&gt;&lt;/span&gt;&lt;a href="https://www.securityjourney.com/coding-training-solutions/custom-demo-form?utm_campaign=34329883-%5B3rd%20Party%5D%20Secure%20World&amp;amp;utm_source=Vibe%20Coding%20Blog"&gt;&lt;span style="font-weight: normal;"&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://info.securityjourney.com/vibe-coding-field-guide?utm_campaign=34329883-%5B3rd%20Party%5D%20Secure%20World&amp;amp;utm_source=Vibe%20Coding%20Blog"&gt;&lt;img src="https://www.secureworld.io/hs-fs/hubfs/image-png-Jun-01-2026-10-04-49-2465-PM.png?width=600&amp;amp;height=200&amp;amp;name=image-png-Jun-01-2026-10-04-49-2465-PM.png" width="600" height="200" style="margin-left: auto; margin-right: auto; display: block; width: 600px; height: auto; max-width: 100%;" alt="Free Download: Vibe Coding Field Guide"&gt;&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fsecure-vibe-coding-without-security-risks&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Featured Author</category>
      <category>DevOps</category>
      <category>Coding</category>
      <pubDate>Tue, 02 Jun 2026 16:26:42 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/secure-vibe-coding-without-security-risks</guid>
      <dc:date>2026-06-02T16:26:42Z</dc:date>
      <dc:creator>Mike Burch</dc:creator>
    </item>
    <item>
      <title>The Integration Blueprint: Decoding 2026 Tech and Workforce Trends</title>
      <link>https://www.secureworld.io/industry-news/integration-blueprint-tech-workforce-trends</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/integration-blueprint-tech-workforce-trends" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/AI%20%20Workflow%20-%20young-business-people-in-an-office-at-night-using-2026-03-10-02-05-59-utc.jpg" alt="two coworkers collaborating at computer" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;&lt;span style="line-height: 1.15;"&gt;The hyper-accelerated scramble to adopt generative AI has officially given way to a more sober, architecturally focused phase of enterprise execution. According to two newly released research reports from CompTIA—the &lt;a href="https://www.secureworld.io/hubfs/documents/CompTIA%20IT%20Industry%20Outlook%202026.pdf"&gt;IT Industry Outlook 2026&lt;/a&gt; and &lt;a href="https://www.secureworld.io/hubfs/documents/CompTIA%20AI%E2%80%99s%20Impact%20on%20Productivity%20and%20the%20Workforce.pdf"&gt;AI's Impact on Productivity and the Workforce&lt;/a&gt;—organizations are shifting from starry-eyed experimentation to the hard work of operational integration&lt;/span&gt;.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="line-height: 1.5; font-weight: normal;"&gt;&lt;span style="line-height: 1.15;"&gt;The hyper-accelerated scramble to adopt generative AI has officially given way to a more sober, architecturally focused phase of enterprise execution. According to two newly released research reports from CompTIA—the &lt;a href="https://www.secureworld.io/hubfs/documents/CompTIA%20IT%20Industry%20Outlook%202026.pdf"&gt;IT Industry Outlook 2026&lt;/a&gt; and &lt;a href="https://www.secureworld.io/hubfs/documents/CompTIA%20AI%E2%80%99s%20Impact%20on%20Productivity%20and%20the%20Workforce.pdf"&gt;AI's Impact on Productivity and the Workforce&lt;/a&gt;—organizations are shifting from starry-eyed experimentation to the hard work of operational integration&lt;/span&gt;.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;The data, collected across more than 2,100 combined business and technology professionals, reveal&amp;nbsp;a distinct tension: corporate leadership is demanding measurable value from AI implementations, but these deployments are hitting the reality checks of data readiness, workforce skill gaps, and evolving perimeter threats.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;For enterprise leaders and cybersecurity teams, CompTIA's findings serve as an operational blueprint for navigating a landscape where technology capability is only as good as the governance supporting it.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The overarching sentiment for enterprise management heading into the remainder of the year is cautious optimism. While 77% of organizations report feeling positive about their growth prospects, macroeconomic realities—including broad fiscal uncertainty and trade shifts—are forcing leadership to prioritize internal operational efficiencies over raw expansion.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Enterprise drivers for optimism include Improved Operational Efficiency (51%); Using AI for Productivity Gains&amp;nbsp;(945%); and Reaching New Customer Segments&amp;nbsp;(45%).&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Within this efficiency-driven framework, CompTIA's research exposes several key macro shifts.&lt;/p&gt; 
&lt;h2 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;The AI growth engine meets reality checks&lt;/strong&gt;&lt;/h2&gt; 
&lt;p style="line-height: 1.5;"&gt;AI adoption is pervasive but highly uneven. CompTIA notes that the weighted average adoption rate across workforces sits around 37%, heavily characterized by a "long-tail" model where a small subset of power users drive daily engagement while the rest of the enterprise interacts intermittently.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Crucially, an overwhelming 82% of companies report intense pressure to deliver organizational value from their AI investments. Yet, throwing algorithms at poorly defined problems has triggered a massive wave of technical regressions. Among organizations that attempted to substitute AI for human tasks, a staggering 79% reported backtracking to a human-centered solution after the technology failed to meet core business criteria. The leading causes for these rollbacks include lower-than-expected output quality (52%), scalability bottlenecks (50%), and severe workflow integration friction (47%).&lt;/p&gt; 
&lt;h3 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;The workforce pipeline conundrum&lt;/strong&gt;&lt;/h3&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;The integration of automated tools has created an volatile hiring landscape. Employer job listings specifying an AI skill requirement have more than doubled (+107%) year-over-year, yet 46% of organizations remain stuck in a reactive "chicken-and-egg" loop—delaying workforce training because their AI adoption is in its infancy and ignoring the fact that adoption is stalled precisely because their workforce lacks the necessary skills.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Furthermore, 91% of corporate leaders express deep concern that automating entry-level tasks risks disrupting the early-stage career ladder. By cutting the bottom rungs of the talent pipeline (junior-level staff accounted for 53% of AI-induced staffing actions), businesses risk transforming a traditional pyramid-shaped labor market into an unsustainable, top-heavy diamond—leaving fewer experienced workers to promote into expert roles down the line.&lt;/p&gt; 
&lt;h4 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;The micro picture: what it means for cybersecurity teams specifically&lt;/strong&gt;&lt;/h4&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;While business units focus on utilizing chatbots and deploying autonomous point solutions to optimize workflows, cybersecurity professionals are left to manage the resulting systemic exposure. CompTIA's IT Industry Outlook 2026 outlines an environment where security cannot simply be a control added to an application, but must expand to act as a foundational layer across the entire infrastructure stack.&lt;/p&gt; 
&lt;h5 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;Privacy concerns regain strategic dominance&lt;/strong&gt;&lt;/h5&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;For the first time in several tracking cycles, privacy concerns have emerged as the number one driver impacting corporate cybersecurity strategy (42%), followed closely by the emergence of generative AI (40%) and the mandate to secure operational technology or OT (39%).&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;Top elements impacting cybersecurity strategy include Privacy Concerns (42%); Emergence of Generative AI (40%); and Securing Operational Technology (39%).&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;This structural shift indicates a massive need to shore up enterprise governance. Because generative AI and agentic systems behave differently than traditional static software, security teams are battling data-sprawl, unmapped API integrations, and the critical threat of intellectual property leakage.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;CompTIA's report indicates that organizations claim their highest tech capabilities in the domain of data security (52%) and data analytics (51%). However, foundational management components—such as database administration, strict data governance, and data mining—remain severely underdeveloped.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;This creates an acute challenge for security practitioners: AI output depends entirely on the input dataset. Security teams must step in to build rigorous automated guardrails to ensure that corporate data is securely managed, sanitized, and properly structured before it is fed into enterprise LLMs or autonomous agents.&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;A significant blind spot highlighted in the 2026 report is the historical neglect of cryptography. CompTIA notes that cryptography changes have rarely registered as a top corporate priority, making it difficult for executive boards to fully appreciate the risk of quantum computing to existing security standards.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;However, with the threat of malicious actors actively harvesting encrypted corporate data now to decrypt it later, security teams are facing an immediate mandate. Teams must begin planning transitions toward&lt;a href="https://www.secureworld.io/industry-news/nist-post-quantum-cryptography-standards"&gt;Post-Quantum Cryptography (PQC)&lt;/a&gt;. This requires building architectures with crypto-agility—systems that can dynamically rotate cryptographic keys and evolve signatures without causing massive operational strain or collapsing legacy infrastructure.&lt;/p&gt; 
&lt;h6 style="line-height: 1.5;"&gt;&lt;strong style="line-height: 1.15;"&gt;Building depth in the security pipeline&lt;/strong&gt;&lt;/h6&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;As cybersecurity grows across every technical domain, the demand for verified expertise is outstripping the market supply. To resolve this, 85% of companies are aggressively seeking validation of technical skills through industry-recognized certifications.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;Furthermore, enterprises are realizing they cannot rely solely on senior architects; they must build internal pipelines. Progressive teams are using the technical support function as a foundational talent incubator. Given that 83% of firms are expanding tech support skills to educate end-users on proper security protocols and leverage AI for threat pattern discovery, creating defined internal pathways from support roles into specialized cybersecurity domains (such as security data analysis and OT security) has become a primary tactic for neutralizing the talent shortage.&lt;/p&gt; 
&lt;p style="line-height: 1.5; font-weight: normal;"&gt;"Since the emergence of the modern artificial intelligence era, it often seems as if AI has already gone through more Hype Cycle peaks and valleys than most technologies experience in a lifetime," according to a CompTIA press release. "Announcements of profound breakthroughs, such as besting the &lt;a href="https://www.secureworld.io/industry-news/captcha-website-security-measure"&gt;Turing Test&lt;/a&gt;, inflate expectations to lofty heights, only to follow with the disillusionment that comes with puzzling AI hallucinations or results that underwhelm."&lt;/p&gt; 
&lt;p style="line-height: 1.5;"&gt;To align business velocity with architectural resilience against the backdrop of CompTIA's 2026 data, organizations should implement three concrete strategies:&lt;/p&gt; 
&lt;ol style="line-height: 1.5;"&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Mandate proactive, multi-tiered AI training:&lt;/span&gt; Move out of the reactive camp. Security teams must collaborate with HR to implement comprehensive compliance and security training for AI usage (currently targeted or planned by 85% of firms). This must scale from fundamental AI literacy for all staff up to advanced prompt-engineering and runtime monitoring for engineering departments.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Enforce Zero-Trust data architecture:&lt;/span&gt; Accept that users are actively pasting corporate data into AI endpoints and applications. Security teams must deploy continuous, automated data-loss prevention (DLP) controls and shift toward a Zero Trust model to ensure data is protected, localized, and monitored at runtime—preventing unauthorized model ingestion.&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="line-height: 1.15;"&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Audit cryptographic footprints immediately:&lt;/span&gt; Do not wait until quantum computing is commercially ubiquitous. Security leaders should initiate a comprehensive audit of their current cryptographic algorithms, identifying legacy or static infrastructure components that lack the agility to transition to post-quantum standards.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="line-height: 1.5;"&gt;CompTIA's dual 2026 outlooks emphasize that technological transformation cannot happen in a silo. The pursuit of AI-driven productivity is a dead end without parallel, equivalent investments in data governance, infrastructure hardening, and structured workforce skilling. True market resilience will belong to the organizations that treat security not as an obstacle to innovation&amp;nbsp;but as the foundational architecture that makes sustainable innovation possible&lt;span style="line-height: 1.15;"&gt;.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fintegration-blueprint-tech-workforce-trends&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Artificial Intelligence</category>
      <category>InfoSec Workforce</category>
      <category>Original Content</category>
      <category>IT Management</category>
      <category>Digital Transformation</category>
      <pubDate>Tue, 02 Jun 2026 14:08:02 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/integration-blueprint-tech-workforce-trends</guid>
      <dc:date>2026-06-02T14:08:02Z</dc:date>
    </item>
    <item>
      <title>The AI Vulnerability Arms Race: A Global Banking Assessment</title>
      <link>https://www.secureworld.io/industry-news/ai-vulnerability-global-bankiing</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/ai-vulnerability-global-bankiing" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Financial%20-%20businessman-strain-on-earnings-2025-10-30-21-11-26-utcV2.jpg" alt="person holding money" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;The baseline equation of corporate patch management has been fundamentally rewritten. According to an in-depth sector report from Moody's Ratings, titled "Arms Race: Deep defenses will help banks navigate cyber threats from new AI models," the industry is facing a paradigm shift in how digital vulnerabilities are surfaced and exploited.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The baseline equation of corporate patch management has been fundamentally rewritten. According to an in-depth sector report from Moody's Ratings, titled "Arms Race: Deep defenses will help banks navigate cyber threats from new AI models," the industry is facing a paradigm shift in how digital vulnerabilities are surfaced and exploited.&lt;/p&gt;  
&lt;p&gt;The catalyst is a new class of highly-specialized AI models engineered to autonomously hunt for code flaws. In early April 2026, &lt;a href="https://www.secureworld.io/industry-news/anthropic-claude-mythos-finds-exploits-zero-days"&gt;Anthropic released Claude Mythos&lt;/a&gt; in limited capacity, a model capable of uncovering thousands of previously unknown software defects across major operating systems and web browsers. One week later, OpenAI deployed a similarly advanced model, GPT-5.4-Cyber. Neither model has been released to the public due to the immense security risks they present.&lt;/p&gt; 
&lt;p&gt;Instead, the largest financial entities were granted early access under a vetted evaluation framework known as &lt;a href="https://www.secureworld.io/industry-news/anthropics-claude-mythos-signals-a-new-era-in-ai-powered-cybersecurity-and-a-race-no-one-is-ready-for"&gt;Project Glasswing&lt;/a&gt; to stress-test institutional perimeters. The findings from Moody's outline what this accelerated environment means for the financial ecosystem, the banking landscape, and the public at large.&lt;/p&gt; 
&lt;p&gt;The macro takeaway of &lt;a href="https://www.secureworld.io/hubfs/documents/Sector_In-Depth-Banks-Global-Arms-Race-Deep-20May2026-PBC_1483419.pdf"&gt;the report&lt;/a&gt; is that advanced AI tools can now uncover software vulnerabilities far faster than the vast majority of enterprise security teams can manually remediate them. This compresses the timeline for network defenders, creating a significant widening of the remediation gap.&lt;/p&gt; 
&lt;p&gt;Across all industries, the average timeline for a threat actor to exploit a newly-disclosed software weakness dropped to 44 days in 2025, while the median corporate patching cycle lagged significantly behind at 87 days. With AI tools now industrializing the discovery of zero-days, this operational buffer has evaporated. Because the global financial system relies entirely on a highly-concentrated, dependent web of third-party software and AI providers, an unpatched exploit path at a single critical vendor introduces systemic dependency risks across the entire network.&lt;/p&gt; 
&lt;p&gt;Banks are uniquely targeted by these AI-driven capabilities due to the sheer volume of customer capital they hold, the sensitivity of transactional data, and the absolute criticality of payment perimeters. However, Moody's notes that banks are structurally better insulated than most sectors due to strict regulatory frameworks—such as the EU's Digital Operational Resilience Act (DORA) and the FFIEC guidelines in the U.S.—which enforce stringent control discipline.&lt;/p&gt; 
&lt;p&gt;The banking sector's median patch remediation speed reflects this maturity, sitting at 69 days—outperforming the global cross-sector average, though still trailing the speed of weaponization.&lt;/p&gt; 
&lt;p&gt;However, Moody's highlights a deep divide within the industry:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The legacy drag:&lt;/span&gt; The primary point of failure remains legacy IT architecture. Many core banking platforms utilize internal environments that have gone unpatched for years or date back several decades, making rapid updates or incident containment extraordinarily difficult.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The scale split:&lt;/span&gt; While major global banks can spread the massive overhead of modernizing their networks or migrating to cloud environments, smaller financial institutions are severely exposed. Lacking identical financial resource allocation, smaller banks face a steep financial mandate. Bain estimates that many organizations must expand their tech spending by up to two times their current levels to defend against AI-fueled intrusion.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;On the defensive front, banks are actively utilizing these exact same frontier AI models to automate internal vulnerability tracking. A Moody's cyber survey found that 94% of banks have enacted formal AI usage policies, 92% participate in shared threat-intelligence networks, and 94% enforce strict incident-notification clauses with external software vendors.&lt;/p&gt; 
&lt;p&gt;For the average consumer and the general public, the industrialization of vulnerability discovery elevates the critical importance of backend deposit and data protection. While an isolated software flaw is unlikely to cause a tier-one banking failure on its own, the cumulative speed of AI-driven exploits raises the stakes for consumer-facing services.&lt;/p&gt; 
&lt;p&gt;A prolonged ransomware outage or data compromise at a major institution directly threatens public confidence, operational uptime, and liquidity. Because malicious actors are moving toward automated target acquisition, the public's financial security depends on banks completely abandoning traditional, outdated perimeter defense styles.&lt;/p&gt; 
&lt;p&gt;To keep customer funds secure, the financial system must move entirely to a Zero Trust architecture. Rather than assuming an onsite user or an internal application is inherently safe once inside the firewall, Zero Trust requires continuous authentication, validation, and authorization for every single access request. This architecture accepts that an AI exploit may breach the perimeter, but safely limits an attacker's maneuverability before they can access customer data or transactional systems.&lt;/p&gt; 
&lt;p&gt;To navigate the environment highlighted by Moody's Ratings, financial risk managers must shift away from static, manual defensive processes.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Implement continuous patching pipelines:&lt;/span&gt; Relying on periodic manual code reviews or monthly maintenance windows is no longer sufficient against machine-speed discovery. Automated code-review tools must check software patches as they are written to enforce a "Secure-by-Design" lifecycle.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Accelerate attack path identification: &lt;/span&gt;Uncovering a vulnerability does not automatically equal an active breach. A threat actor must still map a viable attack path through the network. Banks must use continuous validation to find and block these paths before an automated scanner can navigate them.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Decommission core technical debt:&lt;/span&gt; Legacy core systems are an unacceptable point of failure. Financial institutions must aggressively prioritize migrating legacy processing units to modern, adaptable cloud environments that support dynamic, live updates without disrupting interconnected payment tracks.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The report from Moody's Ratings establishes that the cyber threat landscape has entered a permanent arms race. While frontier AI models provide adversaries with an unprecedented ability to compromise code, they simultaneously hand well-prepared defenders the tools to automate self-defense. True stability in this accelerated landscape will belong to the financial institutions that ruthlessly eliminate legacy tech debt, automate patch verification, and enforce Zero Trust deep defenses across the entire ecosystem.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fai-vulnerability-global-bankiing&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Banking</category>
      <category>Vulnerabilities</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <category>Financial Sector</category>
      <pubDate>Mon, 01 Jun 2026 13:19:02 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/ai-vulnerability-global-bankiing</guid>
      <dc:date>2026-06-01T13:19:02Z</dc:date>
    </item>
    <item>
      <title>Frozen in the Middle: The AI Bottleneck</title>
      <link>https://www.secureworld.io/industry-news/frozen-middle-ai-bottleneck</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/frozen-middle-ai-bottleneck" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Thinking%20man%20-%20Predictions%20-%20pensive-arab-guy-in-casual-sitting-at-workdesk-th-2025-03-18-19-08-58-utc.jpg" alt="man contemplating" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;I talk to a lot of organizations that are being pressured from their board or upper leadership to implement AI for fear of getting left behind. These organizations have staff who are eager to use more and different AI tools than those sanctioned by the company. So, where is the disconnect for the leadership's command for innovation, employees taking ownership, and higher productivity from the staff?&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;I talk to a lot of organizations that are being pressured from their board or upper leadership to implement AI for fear of getting left behind. These organizations have staff who are eager to use more and different AI tools than those sanctioned by the company. So, where is the disconnect for the leadership's command for innovation, employees taking ownership, and higher productivity from the staff?&lt;/p&gt; 
&lt;p&gt;Roger Smith, CEO of GM in the 80s, famously referred to the managerial dysfunction of his company as "rotten in the middle." General Motors was being challenged by the innovative manufacturing approaches of the Japanese automakers. And, while he wanted to see change, his middle managers didn't—which perfectly describes the sandwich hindering innovation above. And yes, he is the "Roger"&amp;nbsp;from Michael Moore's 1989 documentary, &lt;em&gt;Roger &amp;amp; Me&lt;/em&gt;.&lt;/p&gt; 
&lt;p&gt;Salesforce reports 50-60% of workers use unsanctioned AI. Many reports talk about lack of ROI we are seeing from AI deployments, and that is just the small percentage of initiatives that make it past all the approval gates into production.&lt;/p&gt; 
&lt;p&gt;I have seen fear by middle management that they might lose their organizations, influence, control over data, control over decisions or staff that they fought to acquire over years. Yet, they don't want to be seen as being directly against AI, since it's an upper leadership mandate, so it causes them to put in more bureaucracy disguised as governance, and hierarchy disguised as new "AI initiative onboard request portals"&amp;nbsp;and approval workflow.&lt;/p&gt; 
&lt;p style="text-align: center;"&gt;&lt;img src="https://www.secureworld.io/hs-fs/hubfs/Blog%20Images/Leadership%20Mandate_Gemini_Doten.jpg?width=600&amp;amp;height=328&amp;amp;name=Leadership%20Mandate_Gemini_Doten.jpg" width="600" height="328" alt="Leadership Mandate_Gemini_Doten" style="height: auto; max-width: 100%; width: 600px; margin: 0px auto 7px; display: block;"&gt;&lt;em&gt;Image prompted by Rick Doten and generated by Gemini.&lt;/em&gt;&lt;/p&gt; 
&lt;p&gt;They are threatened by democratization of access to information, engineering, project management, and expertise. Middle management's expertise is built on controlling how the staff communicates, collaborates, and makes decisions. AI disrupts this.&lt;/p&gt; 
&lt;p&gt;But Roger isn't the only one to describe this dysfunction, and it has been seen in many large organizations for decades. We have concepts in books talking about this like the &lt;span style="font-weight: bold;"&gt;Organizational Immune Response&lt;/span&gt;, where, like the human immune system, organizations resist change or anything disruptive. It optimizes for control, efficiency, and predictability. This is from the work of Clayton Christensen and Gary Hamel in the late 1990s, where they see bureaucracy suppress innovation to maintain homeostasis with the rest of the organization. And the &lt;span style="font-weight: bold;"&gt;Competing Values Framework&lt;/span&gt;, where workers are given competing values of innovation versus stability, or flexibility versus control, that organizations seek, but the reality is they favor the latter. &amp;nbsp;This is by Robert E. Quinn and John Rohrbaugh's work in the early 1980s.&lt;/p&gt; 
&lt;p&gt;And even today when it comes to AI rollout, McKinsey&lt;sup&gt;1&lt;/sup&gt;, Deloitte&lt;sup&gt;2&lt;/sup&gt;, and Boston Consulting&lt;sup&gt;3&lt;/sup&gt; all published reports in the last year indicating that middle management is a barrier to AI adoption.&lt;/p&gt; 
&lt;p&gt;When we talk about staff displacement, the narrative is focused on the bottom, because AI can automate basic tasks; and we are seeing huge unemployment in college graduates. But the reality, which we haven't broadly realized in practice yet, is we NEED the bottom to fill in with people willing to find new ways to accomplish tasks absent legacy cultural baggage and build new capabilities.&lt;/p&gt; 
&lt;p&gt;It's the middle that is at real risk. Right now, they are controlling budget, project prioritization, hiring decisions, and tech procurement sign-offs, which helps them control pace of new technology that threatens them.&lt;/p&gt; 
&lt;p&gt;This challenge is separate from the broader issue of AI being impeded by implementation challenges. Managers blamed model maturity, data quality, or lack of AI architecture frameworks as reasons for lack of success. But the major AI labs have recently reported the technical barriers are largely solved, and the real obstacle is organizational willingness to transform.&lt;sup&gt;4, 5, 6&lt;/sup&gt;&lt;/p&gt; 
&lt;p&gt;And the other huge gap is there aren't enough people who know about AI implementation and tools to support everyone who needs help. There is great FOMO by large U.S. companies that see these small Silicon Valley tech companies 10x their productivity and revenue per person and feel they are behind. But reality is that is a very small percentage who are winning with AI. And those who are winning are fortunate enough to start from scratch. It's hard to convert your sailboat to a motorboat while it's skimming across the water. &amp;nbsp;&lt;/p&gt; 
&lt;p&gt;Most organizations are still struggling to figure out their strategy, plan, and what success looks like. This is because there is no one right answer, there is only the right answer for your organization. And that will be different in six&amp;nbsp;months, and again in a year. The rapid change is another huge challenge for organizations—and opportunity for middle management to balk: "the new models change our approach, let's do another analysis and present how it changes our plan in next month's steering committee."&lt;/p&gt; 
&lt;p&gt;So, what do we do? As I talked about in my &lt;a href="https://www.secureworld.io/industry-news/leadership-age-of-ai"&gt;previous article on how AI changes leadership,&lt;/a&gt; I illustrate that if people are now orchestrating agents to do work, and not doing the work themselves, then we grade their performance differently. We need to do the same for middle management. We need to measure them on having the right roles and experience on their staff, on making sure they are tracking AI costs (tools, tokens, SaaS API costs, etc.), and getting these projects through approval so they can get started. We should measure on how many AI pilots got started, how many made it to production, what tools were operationalized, and what projects are giving business ROI. &amp;nbsp;&lt;/p&gt; 
&lt;p&gt;These are AI enablement metrics. And this flips the incentive. Managers see that AI is helping them get more influence, staff, and recognition for successful projects. Have monthly "Shark Tank" like pitches for staff to highlight the projects they are working on, rewarding those who have ideas that can be operationalized. The middle managers who succeed and survive this transformation will be the ones who become their organization's AI translation layer, helping execute their leadership's ambition and supporting the staff to do so.&lt;/p&gt; 
&lt;p&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;References:&lt;/span&gt;&lt;br&gt;1&amp;nbsp; McKinsey &lt;span style="font-style: italic;"&gt;SuperAgency in the Workplace: Empowering people to unlock AI’s full potential&lt;/span&gt;, January 2025&lt;br&gt;2&amp;nbsp; Deloitte &lt;span style="font-style: italic;"&gt;AI Trends 2025: Adoption Barriers and updated predictions&lt;/span&gt;, September 2025&lt;br&gt;3&amp;nbsp; BCG-BHI &lt;span style="font-style: italic;"&gt;AI Adoption Puzzle: Why Usage Is Up But Impact Is Not&lt;/span&gt;, December 2025&lt;br&gt;4&amp;nbsp; &lt;a href="https://www.turing.com/blog/turing-and-anthropic-on-enterprise-ai-deployment"&gt;Anthropic (via Turing.com)&lt;/a&gt;&lt;br&gt;5 &amp;nbsp;&lt;a href="https://valasys.com/openai-agentic-ai-enterprise-automation/"&gt;OpenAI (via Valasys Media)&lt;/a&gt;&lt;br&gt;6&amp;nbsp; &lt;a href="https://deepmind.google/blog/partnering-with-industry-leaders-to-accelerate-ai-transformation/#:~:text=Artificial%20intelligence%20(AI)%20could%20contribute,AI%20into%20production%20at%20scale.%207https://www.secureworld.io/industry-news/leadership-age-of-ai"&gt;Google Deepmind&lt;/a&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Ffrozen-middle-ai-bottleneck&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Leadership</category>
      <category>Career Development</category>
      <category>Featured Author</category>
      <category>AI</category>
      <pubDate>Fri, 29 May 2026 13:22:02 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/frozen-middle-ai-bottleneck</guid>
      <dc:date>2026-05-29T13:22:02Z</dc:date>
      <dc:creator>Rick Doten</dc:creator>
    </item>
    <item>
      <title>The Industrialization of Deception: Inside the $196 Billion Scam Economy</title>
      <link>https://www.secureworld.io/industry-news/deception-196-billion-scam-economy</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/deception-196-billion-scam-economy" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Vulnerability%20-%20Hacked%20-%20Ransomeware%20-%20Attack%20-%20shutterstock_2572994613.jpg" alt="man on phone looking at computer screen" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;In the corporate world, substantial budgets, resources, and technical ingenuity are routinely dedicated to securing networks—hardening firewalls, fine-tuning endpoint detection, and monitoring cloud configurations. However, a new report from ScamZero forces a look at an equally devastating and rapidly evolving theater of conflict: the consumer and workforce fraud ecosystem.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;In the corporate world, substantial budgets, resources, and technical ingenuity are routinely dedicated to securing networks—hardening firewalls, fine-tuning endpoint detection, and monitoring cloud configurations. However, a new report from ScamZero forces a look at an equally devastating and rapidly evolving theater of conflict: the consumer and workforce fraud ecosystem.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The &lt;a href="https://scamzero.com/research"&gt;2025-2026 Scam Report&lt;/a&gt; from ScamZero highlights a massive, sophisticated market that has evolved into a fully professionalized industry. While official federal repositories—such as the U.S. FTC's Consumer Sentinel Network or the FBI's Internet Crime Complaint Center (IC3)—paint a grim picture with record-breaking losses, ScamZero's research reveals that the &lt;i&gt;actual&lt;/i&gt; damage represents an existential threat to broader economic stability.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The most shocking baseline metric established by ScamZero is the unreported fraud gap.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;While the FTC noted around $12.5 billion in officially reported consumer fraud losses for 2024, ScamZero's comprehensive analytics place the estimated actual losses at a staggering $196 billion annually.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Why is this gap so massive? The report reveals that an estimated 93% to 98% of fraud victims never file a report with any government agency or law enforcement body. This non-reporting is driven by three distinct factors.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The psychological toll:&lt;/span&gt; Deep embarrassment and self-blame often silence victims, particularly when highly sophisticated, multi-stage social engineering is involved.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Friction in reporting:&lt;/span&gt; Many consumers encounter significant administrative friction—bouncing between local police departments, federal reporting forms, and their financial institutions without a clear path to resolution.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The long-tail discovery:&lt;/span&gt; A significant portion of victims do not realize they have been defrauded until months down the line, a trend particularly common in complex investment schemes or structured romance scams.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: normal;"&gt;For operational and risk-management leaders, these statistics indicate that public databases represent merely the visible tip of a massive fraud iceberg.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/newcomers-canada-fraud-victims"&gt;Newcomers to Canada Are the Fraud Victims the Loss Ledger Keeps Missing&lt;/a&gt;]&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;For nearly two decades, organizations have trained employees and consumers to spot phishing and scams by looking for basic visual or textual indicators: poor grammar, spelling mistakes, awkward phrasing, or generic greetings. ScamZero's research confirms that AI has officially made traditional red flags practically invisible.&lt;/p&gt; 
&lt;p&gt;With the commercialization of underground tools like FraudGPT and "Scam-as-a-Service" kits on the dark web, the barrier to entry for criminal operations has collapsed. Anyone, regardless of technical proficiency, can deploy automated factories of highly-persuasive, sophisticated deception.&lt;/p&gt; 
&lt;p&gt;Typographical errors and layout flaws have disappeared. AI models allow scammers to instantly generate authoritative, contextually accurate communications at scale.&lt;/p&gt; 
&lt;p&gt;Leveraging the downstream impacts of massive corporate data breaches, scammers use AI to ingest historical compromise data. They craft individualized messages that seamlessly account for a victim's actual purchase history, localized writing styles, and regional interests.&lt;/p&gt; 
&lt;p&gt;High-fidelity voice cloning and synthetic video are no longer restricted to elite nation-state operations. They are now standard tools used to exploit identity vulnerabilities—impersonating corporate executives to bypass standard verification or spoofing family members to manufacture urgent financial crises.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The demographics of fraud are shifting rapidly, creating concentrated areas of catastrophic risk. ScamZero highlights a seven-fold increase in $100,000+ losses among older adults.&lt;/p&gt; 
&lt;p&gt;This demographic represents an existential risk because they hold concentrated retirement assets, home equity, and lifelong savings, making a single incident financially fatal. Scammers aggressively exploit the intersection of social isolation, trust in authority figures (such as Medicare, the IRS, or tech support), and available wealth.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Furthermore, social media has become ground zero for initiating these highly- damaging operations. The report tracks a nine-fold increase in social media-initiated fraud losses for seniors, driven by hyper-targeted advertising, malicious direct messages, and highly-coordinated investment platforms designed to look legitimate over months of sustained interaction.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;If there is one definitive takeaway from ScamZero's research, it is the unforgiving math of recovery: only 4% of fraud victims ever recover any portion of their stolen funds.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Once a cross-border wire transfer, real-time payment network transaction, or cryptocurrency deposit is authorized by a manipulated user, the assets are generally permanently gone. The traditional reactive security model—investigating after the fact and trying to claw back funds—is structurally incapable of responding to machine-speed fraud. Therefore, defensive strategies must shift entirely to real-time prevention and continuous identity validation.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;The macro implications for organizations&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The ScamZero report confirms that user vulnerability is a core corporate and societal risk, meaning organizations can no longer ignore external fraud as an "out-of-scope" issue.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;For financial institutions and credit unions: &lt;/span&gt;The crisis is directly commercial. When members or customers lose their life savings to a scam, the emotional and reputational fallout directly impacts trust in the institution, leading to surging regulatory complaints and customer attrition. Institutions are forced to implement real-time, behavioral anomaly detection at the exact point of transaction authorization.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;For corporate workflows and help desks: &lt;/span&gt;Because scammers use AI to seamlessly mimic trusted workforce identities, organizations must completely abandon vocal or visual recognition as a valid metric of trust. Rigid verification protocols must be implemented for all critical interactions, such as password resets, multi-factor authentication (MFA) bypass requests, and remote onboarding.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;For security awareness programs:&lt;/span&gt; Education frameworks must undergo a revolution. Continuing to tell people to "look for bad spelling" actively leaves them unprotected. Training must focus on helping users recognize &lt;a href="https://www.secureworld.io/industry-news/5-emotions-hackers-use-social-engineering-attacks"&gt;psychological manipulation tactics&lt;/a&gt;—urgency, secrecy, fear, and isolation—rather than relying on technical anomalies that AI can now erase.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;We asked a few experts from solution providers for their take on the report's findings.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/mpaalto/"&gt;Mika Aalto&lt;/a&gt;, Co-Founder and CEO at Hoxhunt, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"The biggest shift in cybersecurity over the past decade has been the ability for organizations to stop obsessing about security awareness compliance and start measurably improving online behaviors. For decades, the industry's answer to human behavior was fear-based monitoring and punitive, once-a-year-or-quarter compliance training. It doesn't work. To truly protect against insider risk, CISOs need to rely on behavioral science, positive reinforcement, and real-time visibility that give each person the right training at the right time."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"First, you need visibility into where the risk is actually happening, be it the sales department or at the browser layer. By deploying advanced training platforms and lightweight browser defenses, security teams can detect when an employee accesses an unapproved SaaS tool or handles data carelessly, and instantly deliver a positive, in-the-moment 'nudge' or micro-training without disrupting their workflow."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Second, rethink your people as a security asset, not a liability. Believe in their abilities to recognize and report social engineering threats and give them the tools to do so. Focusing on and rewarding a few measurable core behaviors like threat reporting and MFA use establishes a cultural bedrock of secure behaviors. When an employee makes a mistake in training, like clicking a simulated phishing link or using an unsecured device, it shouldn't be a 'gotcha' moment; it should trigger automated, contextual training that serves as a constructive learning opportunity."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"By replacing fear and heavy-handed surveillance with fun, continuous learning and automated behavioral interventions, you don't just reduce the likelihood of negligence. You fundamentally transform your workforce into an active, intelligent human sensor network that catches the threats your technology misses."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/ramvaradarajan/"&gt;Ram Varadarajan&lt;/a&gt;, CEO at Acalvio, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"If we look at the most recently documented fraud cases, scale and speed have been the key factors, and these two are completely intertwined within agentic AI attackers. AI has turned high-end cybercrime into a cheap monthly subscription, which means defenders can no longer count on attackers making rookie mistakes. Security teams are least prepared for this, the elimination of traditional skill barriers: when synthetic identity kits cost less than a coffee order and dark LLMs are generating polymorphic, adversarially-tuned malware on demand, the defender's traditional advantage of attackers making mistakes due to limited expertise evaporates fully."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Since a three-second clip is all it takes to clone a voice, we have to stop trusting caller ID and start using 'secret-word' callbacks or separate apps to verify material requests. Out-of-band verification is key, combined with anomaly detection systems that flag unusual requests regardless of apparent sender authenticity. Behavioral context now matters more than identity verification alone. We also need to be aware of social-engineering from the AI itself.&amp;nbsp;LLM-driven chatbots have been shown to be highly persuasive, particularly when they've been instrumented with additional contextual data. This is a brand new vector of risk: it's not just high-fidelity image or voice, it's high-fidelity persuasion. That supercharges social engineering attacks."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"The more AI technology develops, and the more broadly it's deployed, the larger the attack surface becomes. Therefore, defenders are going to have to augment signature-based detection with comprehensive behavioral analytics."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/jeremiah-clark-02a8b2a/"&gt;Jeremiah Clark&lt;/a&gt;, Chief Technology Officer at Fenix24, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Traditional verification methods—things like callback procedures and email-based approvals—were designed for a world where impersonation was hard. That world is gone. When voice cloning needs 10 seconds of audio and deepfake video is commercially available, a phone call to 'confirm'&amp;nbsp;a wire transfer request isn't the safety net it used to be."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Organizations need to move toward out-of-band verification that doesn't rely on a single communication channel. If someone gets a request over email, verify over a completely separate channel using a pre-established, known-good contact method—not the phone number in the email signature. Multi-party approval workflows for high-risk actions like financial transactions or credential changes add another layer."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"On the technical side, organizations should be looking at anomaly detection on communication patterns, not just content. AI-generated phishing is getting past content-based filters because the content is genuinely well-crafted now. But behavioral signals—unusual timing, atypical request patterns, access from unexpected locations—are harder for attackers to fake convincingly, even with AI tools."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"The old approach of training employees to 'spot the phishing email'&amp;nbsp;by looking for typos and bad grammar is basically obsolete. AI-generated content doesn't have those tells anymore. Training needs to shift from 'spot the fake'&amp;nbsp;to 'verify everything unusual, regardless of how legitimate it looks.' Practically, that means establishing clear protocols that employees follow every time, not just when something feels off. Things like: never act on urgent financial requests without verification through a separate, pre-established channel; never trust caller ID or video appearance alone for sensitive authorizations. Build a culture where slowing down to verify isn't seen as being difficult—it's expected."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Organizations should also run regular exercises using actual AI-generated content—synthetic voice, deepfake video, AI-written emails—so employees experience how convincing these attacks have become. Abstract awareness training doesn't create the same instinct as actually encountering a realistic simulation."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Finally, the verification chain itself needs to be resilient. If the process for confirming an executive's request is to call them back, and their voice can be cloned, you need a second factor in that verification—like a pre-shared code word or an in-person confirmation for high-value actions."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/averymoon/"&gt;Avery Moon&lt;/a&gt;, Chief Technology Officer at Pax8, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Most systems are designed to give users access to the tools and data they need to do their jobs, which means a large portion of risk already exists within trusted identities. As organizations adopt more connected platforms and AI-driven workflows, that access expands, and often faster than governance and controls keep up. That's where we see issues emerge, whether it's misconfigured permissions, over-provisioned access, or unintended data exposure."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"The challenge is that these risks don't look like traditional attacks. They happen within normal system behavior, which makes them harder to detect with perimeter-focused security models."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"From a technology standpoint, the priority should be building security into the architecture itself: strong identity controls, clear data governance, and continuous visibility into how systems and users interact. When those foundations are in place, organizations are much better positioned to reduce risk, regardless of whether the threat originates inside or outside the network."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/adam-everspaugh/"&gt;Dr. Adam Everspaugh&lt;/a&gt;, Cryptography Expert at Keeper Security, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"Traditional phishing attacks have long relied on human vigilance—spotting typos, unusual grammar, or strange phrasing—to detect deception. With AI, attackers can create flawless, personalized messages and replicate legitimate websites with alarming accuracy. These attacks will soon become virtually indistinguishable from genuine correspondence."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The best defense against these attacks is the use of a password manager with a browser extension. When configured properly, a password manager can spot spoofed domains and false URLs before credentials are entered into a malicious website."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The $196 billion scam economy thrives on the fact that traditional defensive perimeters stop at the enterprise boundary. To counter an industrialized, AI-driven adversary, organizational defense must match criminal velocity. By treating fraud as a critical threat and deploying automated, real-time validation layers, enterprises and institutions can block the attack path before assets leave the ecosystem.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fdeception-196-billion-scam-economy&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Cyber Fraud</category>
      <category>Social Engineering</category>
      <category>Original Content</category>
      <category>Online Scams</category>
      <pubDate>Thu, 28 May 2026 17:44:57 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/deception-196-billion-scam-economy</guid>
      <dc:date>2026-05-28T17:44:57Z</dc:date>
    </item>
    <item>
      <title>Mental Health Awareness Month: The Crisis in Cybersecurity</title>
      <link>https://www.secureworld.io/industry-news/mental-health-crisis-cybersecurity</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/mental-health-crisis-cybersecurity" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Data%20Breach_stress_%20shutterstock_2526045183.jpg" alt="stressed IT worker at desk" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;In the cybersecurity community, trillions of dollars are poured into hardening software, orchestrating cloud detection, and deploying automated incident response. Yet, the most critical piece of the security stack—the human being behind the keyboard—is routinely running on empty.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the cybersecurity community, trillions of dollars are poured into hardening software, orchestrating cloud detection, and deploying automated incident response. Yet, the most critical piece of the security stack—the human being behind the keyboard—is routinely running on empty.&lt;/p&gt;  
&lt;p&gt;As the velocity of machine-speed attacks accelerates, the chronic stress placed on CISOs&amp;nbsp;and their teams has reached an inflection point. Long hours, structural isolation, and the looming threat of catastrophic failure have transformed cybersecurity from a high-stakes profession into a psychological battlefield.&lt;/p&gt; 
&lt;p&gt;To build true corporate resilience, enterprise leadership must acknowledge a harsh reality: a burnt-out security team is, inherently, a compromised security team. No better time to focus on it than in May, which is &lt;a href="https://mhanational.org/mental-health-month/"&gt;Mental Health Awareness Month&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;It's why SecureWorld conferences often have mental well-being panels on their agendas, including at SecureWorld Chicago on May 20, 2026.&lt;/p&gt; 
&lt;p&gt;Four cybersecurity veterans—Bruce Coffing, CISO, City of Chicago; Joe Mariscal, Sr. Director, Cybersecurity, Rich's Products Corporation; Troy Stairwalt, Board Member, The Center for Critical Infrastructure Security; and moderator Lynn Dohm, Executive Director, Women in CyberSecurity (WiCyS)—talked about m&lt;span style="background-color: #ffffff;"&gt;oving beyond high-level platitudes, openly sharing their personal "red line"&amp;nbsp;moments—the times when the pressure of constant vigilance, regulatory accountability, and the 24/7 threat cycle became unsustainable.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="background-color: #ffffff;"&gt;They discussed the psychological toll of "imposter syndrome"&amp;nbsp;in an AI-accelerated landscape and the heavy weight of the accountability-responsibility gap.&lt;/span&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;"The cybersecurity industry has long since moved to a mental model of resilience when thinking about programs and architecture. However, we haven't updated how we think about our own resilience to the stress that comes with defending against intrusion, breaches, and outright attacks," said &lt;/span&gt;&lt;a href="https://events.secureworld.io/speakers/george-kamide-2/" style="color: #00cccc;"&gt;George Kamide&lt;/a&gt;&lt;span&gt;, Co-Founder of &lt;/span&gt;&lt;a href="https://www.mindovercyber.org/" style="color: #00cccc;"&gt;Mind Over Cyber&lt;/a&gt;&lt;span&gt;, a &lt;/span&gt;&lt;span style="line-height: 28px;"&gt;nonprofit organization dedicated to improving mental well-being and preventing burnout in the cybersecurity industry through the teaching of accessible mindfulness techniques for defenders.&lt;/span&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The modern CISO occupies one of the most psychologically punishing roles in corporate leadership. Charged with defending vast, amorphous digital footprints, they are expected to achieve an impossible standard: perfect, continuous defense against an adversary that only has to get lucky once.&lt;/p&gt; 
&lt;p&gt;This structural asymmetry breeds a unique form of chronic anxiety. Security leaders are fundamentally saddled with total accountability but lack absolute control over the variables that dictate success. A single employee clicking an AI-crafted phishing lure or a third-party vendor neglecting a patch can obliterate years of meticulous defense in a matter of hours.&lt;/p&gt; 
&lt;p&gt;Compounding this pressure is the shifting legal and regulatory landscape. CISOs are no longer just risking their corporate reputations during a breach; they are facing &lt;a href="https://www.secureworld.io/industry-news/ciso-lawsuit-solarwinds"&gt;potential personal liability&lt;/a&gt;, regulatory fines, and public scrutiny. This "blame culture" fosters an environment of intense isolation, where admitting vulnerability—either technical or emotional—is viewed as a professional risk.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;The ripple effect: burnout in the SOC trenches&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;This executive pressure trickles down directly to security operations centers (SOCs) and incident response teams. Cybersecurity professionals consistently operate under a high-vigilance model, where an ordinary day at work mimics a perpetual state of emergency.&lt;/p&gt; 
&lt;p&gt;Several industry studies highlight the staggering human cost of this operational tempo.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The attrition rate:&lt;/span&gt; According to a widely-cited study by Gartner, nearly half of all cybersecurity leaders were expected to change jobs by 2025 due to chronic stress, with 25% projected to leave the profession entirely.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The alert fatigue trap:&lt;/span&gt; Research from Nominet revealed that 88% of CISOs experience high levels of stress, with a staggering 48% stating that work anxiety has negatively impacted their physical health and personal relationships.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The always-on expectation:&lt;/span&gt; In a Mimecast survey of security practitioners, 54% of respondents reported a drop in productivity directly linked to burnout, while a third stated that their teams are actively understaffed, forcing fewer people to carry increasingly heavy workloads.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;When human beings are subjected to perpetual alert fatigue, their cognitive processing degrades. They miss anomalies, experience decision paralysis, and make the very types of misconfigurations or procedural errors that threat actors actively exploit. Burnout isn't just a human resources issue; it is a profound structural vulnerability.&lt;/p&gt; 
&lt;p&gt;Recognizing that the status quo is unsustainable, progressive security organizations and practitioners are pioneering new operational frameworks to manage stress and actively combat burnout.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Use case 1: Automating the mundane to preserve cognitive bandwidth&lt;/p&gt; 
&lt;p&gt;In a standard enterprise environment, tier-one SOC analysts are bombarded with thousands of low-fidelity alerts every single shift. To mitigate this psychological drag, a prominent global logistics enterprise restructured its SOC workflows by deploying autonomous attack path validation and continuous testing platforms.&lt;/p&gt; 
&lt;p&gt;By automating the verification of routine alerts, the company eliminated the "noise" that drives alert fatigue. Analysts were freed from the tedious hamster wheel of manual triaging, allowing them to focus their cognitive bandwidth entirely on high-value, creative threat hunting. The shift resulted in a measurable drop in employee turnover and a significant reduction in the team's average response time.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Use case 2: Implementing "crisis intermission" and mandatory offboarding&lt;/p&gt; 
&lt;p&gt;During a major ransomware or data breach incident, incident response teams routinely work 18- to 24-hour shifts under extreme adrenaline. The psychological crash that follows these events is a primary driver of acute burnout.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;To address this, a major financial services provider instituted a formal "crisis intermission" protocol. Under this policy, any practitioner involved in an active incident response cycle for more than 12 consecutive hours is automatically locked out of corporate networks for a mandatory 24-hour decompression period. Furthermore, the organization decoupled incident reviews from personal performance metrics, focusing post-mortems strictly on systemic blameless analysis rather than individual finger-pointing.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Use case 3: The move toward fractional and shared CISO models&lt;/p&gt; 
&lt;p&gt;For small- and medium-sized enterprises (SMEs), hiring a full-time CISO often means putting an immense amount of pressure on a single individual who has no peer support network. Some organizations are actively mitigating this by adopting fractional or virtual CISO (vCISO) models. By utilizing a shared-services approach, security leaders can bounce complex risk decisions off an extended network of vetted peers, reducing the crippling psychological weight of solitary decision-making.&lt;/p&gt; 
&lt;p&gt;Addressing the mental health crisis in cybersecurity requires moving past superficial corporate wellness initiatives. Mandating a meditation app or an occasional "mental health day" does nothing to fix a fundamentally broken operational model. True wellness requires structural, architectural changes.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Shift to blameless cultures:&lt;/span&gt; Corporate leadership must accept that breaches are an operational reality. Post-incident reviews must focus on engineering resilience and process optimization, not on finding a human scapegoat.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Define realistic operational boundaries:&lt;/span&gt; Establish strict on-call rotations and guard rails around &lt;a href="https://www.secureworld.io/industry-news/cybersecurity-lessons-learned-2018-hacking"&gt;weekend and holiday&lt;/a&gt; communications. If a security team is expected to be vigilant 24/7/365, the infrastructure must be adequately staffed to support rotating shifts without driving individuals to exhaustion.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Elevate cybersecurity to enterprise risk: &lt;/span&gt;CISOs must be integrated into the broader corporate risk framework. When the board treats cybersecurity as a shared business priority rather than an isolated IT problem, the psychological burden is distributed across the entire executive leadership team.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The defense of modern enterprise infrastructure relies entirely on the cognitive clarity of the professionals charged with protecting it. When the human firewall is frayed by chronic stress, the entire organization is at risk. By humanizing the security operations model, automating the alert noise, and dismantling the culture of blame, enterprises can build a defensive posture that is both technically robust and psychologically sustainable.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fmental-health-crisis-cybersecurity&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Cybersecurity</category>
      <category>Original Content</category>
      <category>Burnout</category>
      <category>Mental Health</category>
      <category>Stress</category>
      <pubDate>Thu, 28 May 2026 11:24:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/mental-health-crisis-cybersecurity</guid>
      <dc:date>2026-05-28T11:24:00Z</dc:date>
    </item>
    <item>
      <title>How to Build Mobile Apps that Meet Industry Security Requirements</title>
      <link>https://www.secureworld.io/industry-news/build-mobile-apps-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/build-mobile-apps-security" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Moblie%20App%20-%20shutterstock_1779157820.jpg" alt="people holding mobile phones" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;A mobile app today handles the kind of data that used to sit behind corporate firewalls, managed by dedicated security teams on hardware the organization owned outright. Payment credentials, health records, biometric data, location history; all of it now flows through personal devices on public networks, shipped in two-week sprints by teams with release deadlines. The threat model for that environment is genuinely different from what most security frameworks were designed around, and&amp;nbsp;treating it as equivalent is where a lot of organizations get into trouble.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A mobile app today handles the kind of data that used to sit behind corporate firewalls, managed by dedicated security teams on hardware the organization owned outright. Payment credentials, health records, biometric data, location history; all of it now flows through personal devices on public networks, shipped in two-week sprints by teams with release deadlines. The threat model for that environment is genuinely different from what most security frameworks were designed around, and&amp;nbsp;treating it as equivalent is where a lot of organizations get into trouble.&lt;/p&gt; 
&lt;p&gt;Regulators have started catching up. PCI DSS 4.0, HIPAA's Security Rule, GDPR, and the EU Cyber Resilience Act all place specific, enforceable obligations on how mobile apps collect, store, and move sensitive data. The compliance scope has expanded to the point where security requirements now run through every layer a &lt;a href="https://digitalsuits.co/services/mobile-app-development/"&gt;mobile app development company &lt;/a&gt;touches, not just the infrastructure the client operates on top of it. The fines are no longer theoretical. Several organizations have absorbed breach costs well into the hundreds of millions after mobile incidents—remediation, legal exposure, and reputational damage taken together.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Threat modeling before the first line of code&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;The security decisions that actually determine an app's risk profile happen early. Authentication architecture, where data get&amp;nbsp;stored, how APIs are structured, these get settled in the first few weeks of a project. &lt;a href="https://www.secureworld.io/industry-news/topic/pen-testing"&gt;By the time a penetration test surfaces&lt;/a&gt; a problem with any of them, the cost to fix it has usually multiplied several times over. That's the case for retrofitting security onto shipped architecture generally: it's expensive, it's slow, and the results are less reliable than getting it right the first time.&lt;/p&gt; 
&lt;p&gt;Threat modeling is the mechanism for doing that. Before any code is written, the exercise asks what data the app will handle, who legitimately accesses it, and where an attacker would focus first. STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) gives teams a structured way to work through those questions. OWASP's Mobile Security Testing Guide sits alongside that as a checklist built specifically for mobile attack patterns, which diverge from web and server-side equivalents in ways that matter.&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;API design as a security decision&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;Endpoint security gets outsized attention in mobile because the apps are almost entirely API-dependent. The OWASP &lt;a href="https://owasp.org/API-Security/editions/2023/en/0x11-t10/"&gt;API Security Top 10&lt;/a&gt; has listed broken object-level authorization at the top for several consecutive years. The failure pattern is basic: an app requests a resource, the server returns it, and at no point did the server verify whether the requesting account is the one that actually owns it.&lt;/p&gt; 
&lt;p&gt;Fixing that is a server-side problem, not a client-side one. Per-user rate limiting, authentication enforced at the gateway, and a hard prohibition on API keys in the app binary are starting points. Keys that ship in client code get extracted. It's not a sophisticated attack as static analysis tools handle it routinely, yet several well-known apps have had credentials pulled from their binaries and circulated.&lt;/p&gt; 
&lt;h4&gt;&lt;strong&gt;Where encryption goes wrong&lt;/strong&gt;&lt;/h4&gt; 
&lt;p&gt;Confirming an app uses encryption is essentially a non-answer. More useful is knowing which algorithm, at what key length, where keys actually live, how often they rotate, and what the validation process looks like.&lt;/p&gt; 
&lt;p&gt;Android's Jetpack Security library and Android Keystore offer hardware-backed key storage on modern hardware. iOS has the Secure Enclave and Keychain Services for the same purpose. Both platforms have made the right tooling reasonably accessible. The failure shows up in how it gets used. Encryption keys stored in SharedPreferences, or sitting in the same &lt;a href="https://www.secureworld.io/industry-news/popular-ai-sandbox-backdoor"&gt;sandbox&lt;/a&gt; as the data they're protecting, appear in production code regularly enough that it's worth explicitly checking for both during review.&lt;/p&gt; 
&lt;p&gt;Transport security is its own category. TLS 1.3 is current; TLS 1.2 is the floor. Certificate pinning reduces man-in-the-middle exposure on networks outside the app's control, but there's an operational catch. If certificate expiry isn't tracked and the pinning logic ends up pointing at a stale cert, the failure is silent: users lose access and the connection between pinning and the outage isn't always obvious immediately. Teams that have shipped that problem once tend to add certificate lifecycle tracking to their standard release checklist.&lt;/p&gt; 
&lt;h5&gt;&lt;strong&gt;Session management and authentication depth&lt;/strong&gt;&lt;/h5&gt; 
&lt;p&gt;Single-factor authentication stopped being adequate for regulated data some time ago. MFA, biometric fallback, short-lived session tokens, these are standard expectations in healthcare, financial services, and anywhere personal data sits under GDPR or comparable regulation.&lt;/p&gt; 
&lt;p&gt;For the authentication flow itself, OAuth 2.0 with PKCE is the current recommendation for mobile. The specific reason is that it blocks authorization code interception on devices where redirect URIs can be manipulated. A meaningful number of older apps are still on implicit flow, which has a well-documented vulnerability. Researchers &lt;a href="https://www.sciencedirect.com/science/article/abs/pii/S2214212621002684"&gt;demonstrated practical token extraction&lt;/a&gt; against it in 2022 without any user interaction. The migration path exists and is understood; what usually keeps teams from taking it is prioritization rather than complexity.&lt;/p&gt; 
&lt;h6&gt;&lt;strong&gt;Compliance as an engineering input&lt;/strong&gt;&lt;/h6&gt; 
&lt;p&gt;PCI DSS 4.0 became enforceable in 2024. Among other things, it tightened client-side requirements and introduced explicit obligations around mobile payment data. HIPAA's Security Rule applies to any app that stores or transmits protected health information and calculates penalties per violation, not per incident. When a breach touches thousands of records, that distinction changes the math considerably.&lt;/p&gt; 
&lt;p&gt;Teams that hold compliance review for the end of a project reliably find gaps that require rework. Building in the same controls during development costs far less. A mobile app development company that treats compliance as a sprint input rather than a pre-launch audit will come out ahead on both schedule and total cost almost every time.&lt;/p&gt; 
&lt;div&gt;
 &lt;strong&gt;Third-party SDKs and the supply chain exposure&lt;/strong&gt;
&lt;/div&gt; 
&lt;p&gt;Every SDK added to an app brings its own permissions, data practices, and network behavior. Most of that doesn't get scrutinized at the time of integration the way first-party code does.&lt;/p&gt; 
&lt;p&gt;Analytics libraries, ad networks, crash reporters, social login SDKs—all of them have produced security or privacy incidents at scale. In 2023, a widely-used mobile advertising SDK was found to be &lt;a href="https://techcrunch.com/2023/07/28/apples-app-store-tightens-up-on-user-privacy-with-new-rules-for-app-developers/"&gt;harvesting device identifiers&lt;/a&gt; in violation of both GDPR and Apple's App Store policies. The developers of the affected apps had no knowledge of it. MobSF and comparable static analysis tools run against the full build, including dependencies&amp;nbsp;and surface permission anomalies and unexpected network behavior before anything ships.&lt;/p&gt; 
&lt;div&gt;
 &lt;strong&gt;Building testing into the release cycle&lt;/strong&gt;
&lt;/div&gt; 
&lt;p&gt;&lt;span style="font-weight: normal;"&gt;Security testing that runs on a separate track from the CI/CD pipeline catches problems late and inconsistently. Three layers that feed into the release process directly cover different failure modes:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;SAST (Static Application Security Testing) triggers on every commit and catches code-level issues before they reach a build, such as hardcoded credentials, weak cryptography, or unsafe data storage.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;Dynamic testing via Frida, objection, or similar tools examines the app at runtime: certificate manipulation handling, clipboard exposure, and root and jailbreak detection behavior under active probing.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;External penetration testing at major milestones closes the gap that internal review can't cover on its own. Developers working in a codebase daily stop seeing certain patterns. Someone coming in without that context finds different things.&lt;br&gt;&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="font-weight: normal;"&gt;Google and Apple both publish security testing guidelines specific to their platforms, and both are worth incorporating. They make reasonable baselines, but the attack patterns that cause the most damage in practice tend to be the ones that fall outside what any platform documentation anticipated.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: normal;"&gt;Regulations get updated, attack techniques shift, and platform security models evolve. Development teams that keep security integrated across architecture decisions, release cycles, and dependency management are the ones in a position to respond when any of those things change, rather than discovering afterward that they weren't.&lt;br&gt;&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fbuild-mobile-apps-security&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Featured Author</category>
      <category>DevOps</category>
      <category>Coding</category>
      <category>Mobile Apps</category>
      <pubDate>Wed, 27 May 2026 20:45:11 GMT</pubDate>
      <author>david@macsecurity.net (David Balaban)</author>
      <guid>https://www.secureworld.io/industry-news/build-mobile-apps-security</guid>
      <dc:date>2026-05-27T20:45:11Z</dc:date>
    </item>
    <item>
      <title>Corporate Perimeter Hygiene Lags Behind AI Threats, Report Shows</title>
      <link>https://www.secureworld.io/industry-news/corporate-material-hygiene-ai-threats</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/corporate-material-hygiene-ai-threats" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Network%20shutterstock_2321841215.jpg" alt="workers in a security operations center" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;For years, cybersecurity professionals have treated vulnerability management as an insular IT operational metric—measured by patch cycles, ticket queues, and scan counts. But a new, data-driven report from Moody's Ratings elevates software vulnerabilities to where they ultimately belong: a material factor in enterprise creditworthiness and organizational resilience.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;For years, cybersecurity professionals have treated vulnerability management as an insular IT operational metric—measured by patch cycles, ticket queues, and scan counts. But a new, data-driven report from Moody's Ratings elevates software vulnerabilities to where they ultimately belong: a material factor in enterprise creditworthiness and organizational resilience.&lt;/p&gt; 
&lt;p&gt;The report, titled &lt;a href="https://www.secureworld.io/hubfs/documents/Sector_In-Depth-Cybersecurity-Global-Risks-01Apr2026-PBC_1472151-1.pdf"&gt;"Risks posed by unpatched software flaws vary by industry and region,"&lt;/a&gt;&amp;nbsp;analyzes two years of telemetry across roughly 9,500 global issuers. Its conclusions provide a sobering look at how operating context, geography, and structural constraints collide to create an unequal landscape of risk. In an era where AI-accelerated threats shrink the window to exploit to mere hours, the report confirms that corporate perimeter hygiene is lagging behind.&lt;/p&gt; 
&lt;p&gt;"AI tools are increasingly proficient at uncovering previously unknown bugs, even in software that has undergone extensive security testing. With the accelerated pace of software bug discoveries, corporate cybersecurity teams are struggling to keep up," said &lt;a href="https://www.linkedin.com/in/leroyterrelonge3/"&gt;Leroy Terrelonge&lt;/a&gt;, VP and Cyber Credit Risk Officer at Moody's Ratings. "While the average time from public disclosure to first exploitation fell to 44 days in 2025, the median time required for Moody's-rated issuers to remediate top priority vulnerabilities—those that have been exploited by malicious actors to launch ransomware attacks (ransom KEVs)— over the past two years is roughly 59 days, or nearly two months. For entities targeted with AI-assisted zero-day exploits, that window compresses even further to zero."&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The report's baseline telemetry cuts through the "maturity mirage" that many organizations project. Moody's focused its analysis on Known Exploited Vulnerabilities (KEVs)—the small subset of software bugs tracked by U.S. CISA with verified, real-world exploitation data.&lt;/p&gt; 
&lt;p&gt;The findings are stark:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The baseline:&lt;/span&gt; In 2025, 60% of all analyzed organizations had at least one externally observable KEV on their network.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The long-standing exposure:&lt;/span&gt; In any given month, close to 40% of organizations harbored an unresolved KEV that was older than 45 days. This directly overlaps with threat intelligence metrics indicating that attackers take an average of 44 days to weaponize a newly disclosed bug.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The dormant threat:&lt;/span&gt; More than a quarter (25%) of organizations had a verified KEV that remained unpatched for over a year.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;This is not a failure of awareness; it is a failure of velocity. While CISA recommends patching most KEVs within 21 days, median remediation timelines are failing to keep pace with an automated threat landscape. CISA recently launched a&lt;span&gt; new, centralized &lt;a href="https://www.secureworld.io/industry-news/cisa-kev-nomination-form"&gt;KEV Nomination Form&lt;/a&gt;. This capability allows independent security researchers, technology vendors, and industry partners to directly report active, real-world vulnerability exploitation.&lt;/span&gt;&amp;nbsp;&lt;/p&gt; 
&lt;p&gt;One of the report's most compelling insights is that vulnerability exposure is heavily shaped by regional governance and local technology ecosystems. Even when controlling for organizational size, geography dictating patching outcomes remains clear.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;There's the APAC strain. &lt;span style="font-size: 18px;"&gt;Issuers in Japan and Korea exhibit the highest prevalence of long-standing (+45 day) KEVs, with more than half of non-financial corporates impacted. In Japan, an astounding &lt;/span&gt;85% of non-financial firms&lt;span style="font-size: 18px;"&gt; harbored unresolved KEVs, compared to 41% of their financial counterparts. Moody's attributes this massive gap to slower modernization cycles and a heavy reliance on rigid, legacy systems within the corporate sector.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;There's the Anglo-American advantage. North America, the UK, and Western Europe showed lower overall prevalence, particularly within financial institutions.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: normal;"&gt;Don't forget the Australian benchmark. Australia and New Zealand demonstrated the lowest exposure rates globally. Moody's explicitly ties this success to prescriptive regulatory coordination, specifically the centralized approach to threat-sharing led by the Australian Cyber Security Centre (ACSC) and strict oversight from the Council of Financial Regulators (CFR).&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;Unsurprisingly, the report correlates exposure directly to the size of an organization's externally facing digital footprint (the total number of active IP addresses, domains, and internet-facing assets).&lt;/p&gt; 
&lt;p&gt;The exposure scale is real: 78% of organizations in the top 10% of digital footprint size were plagued by old, unpatched KEVs, compared to just 7.2% in the bottom decile.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: normal;"&gt;Crucially, for non-financial corporates, digital footprint size correlates with KEV exposure far more strongly than annual revenue. This points to a clear structural reality: a larger digital footprint creates a level of complexity, uneven patching cycles, and shadow IT that manual security teams simply cannot out-hustle.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;When breaking down exposure by industry, Moody's data expose&amp;nbsp;the structural barriers unique to specific business models.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The highest exposure:&lt;/span&gt; Education (universities and colleges) and Telecommunications experience the highest KEV prevalence, frequently exceeding 60% of issuers. For universities, this is driven by decentralized, mixed-user environments. For telecom, it reflects massive, sprawling infrastructures that provide a vast attack surface.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The remediation paradox:&lt;/span&gt; High exposure does not automatically mean poor security capability. For example, IT Software companies combine a high prevalence of KEVs with one of the &lt;i&gt;shortest&lt;/i&gt; median remediation times. They are exposed because they run bleeding-edge, internet-facing infrastructure, but they possess the engineering agility to fix flaws quickly.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The OT drag:&lt;/span&gt; Sectors heavily reliant on Operational Technology (OT) and Industrial Control Systems (ICS)—such as utilities, manufacturing, and oil &amp;amp; gas—exhibit lower &lt;i&gt;externally observable&lt;/i&gt; footprint risks but suffer from slower patch implementation times. As U.S. NIST guidelines point out, patching an active production line requires extensive testing and alignment with physical maintenance windows; you cannot simply reboot a refinery to apply an emergency patch.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The Moody's report reinforces that the traditional "hustle hard" approach to vulnerability management has hit its absolute human limit. To close the execution gap, cybersecurity teams must transition to a more strategic model.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Automated attack path validation:&lt;/span&gt; Because a large digital footprint guarantees exposure, stop trying to patch everything. Teams must use continuous, automated validation to determine if a +45-day KEV lies on a live, executable "path to privilege" toward critical corporate assets. Focus remediation solely on reachable risk.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Prioritize ransomware telemetry:&lt;/span&gt; The data show that organizations patch ransomware-linked KEVs fastest (median of 59 days versus 87 days for standard KEVs). Lean into this prioritization framework explicitly. If a bug is flagged as an active ransomware vector, it should bypass standard patch-window protocols entirely.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Account for legacy and regional debt:&lt;/span&gt; If your enterprise operates cross-regionally, recognize that your subsidiaries in places like Japan or Korea may require targeted architectural intervention—such as aggressive network segmentation—to isolate legacy systems that local operational teams cannot patch quickly.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Bridge the credit-security gap:&lt;/span&gt; Security leaders should use this report when speaking to &lt;a href="https://www.secureworld.io/industry-news/decoding-ciso-cfo-disconnect"&gt;CFOs and board members&lt;/a&gt;. When unpatched bugs are directly linked to credit risk, business disruption, and executive accountability, cybersecurity spending transitions from an "IT cost center" into a fundamental tool for preserving corporate valuation.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p style="font-weight: normal;"&gt;Moody's Ratings reminds us that attackers don't care about an organization's revenue; they care about its exposed attack surface. In an ecosystem where a small subset of known vulnerabilities drives the vast majority of credit-destroying incidents, resilience is found in velocity, visibility, and surgical prioritization.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fcorporate-material-hygiene-ai-threats&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Vulnerabilities</category>
      <category>Original Content</category>
      <category>Security Patches</category>
      <category>AI</category>
      <category>Software Security</category>
      <pubDate>Wed, 27 May 2026 13:13:02 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/corporate-material-hygiene-ai-threats</guid>
      <dc:date>2026-05-27T13:13:02Z</dc:date>
    </item>
    <item>
      <title>CISA's KEV Nomination Form Weaponizes Community Intelligence</title>
      <link>https://www.secureworld.io/industry-news/cisa-kev-nomination-form</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/cisa-kev-nomination-form" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Goverment_Agency%20-%20shutterstock_225259792-1.jpg" alt="U.S. flag on federal building" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For years, the United States federal government's Known Exploited Vulnerabilities (KEV) Catalog has served as an essential operational anchor for vulnerability management. Yet, despite its authority, the cybersecurity community has wrestled with a frustrating structural bottleneck: the catalog has traditionally operated as a &lt;em&gt;trailing indicator&lt;/em&gt;. U.S. CISA had to privately validate in-the-wild exploitation before publishing, occasionally warning network defenders days or weeks after threat actors had already begun scanning at scale.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For years, the United States federal government's Known Exploited Vulnerabilities (KEV) Catalog has served as an essential operational anchor for vulnerability management. Yet, despite its authority, the cybersecurity community has wrestled with a frustrating structural bottleneck: the catalog has traditionally operated as a &lt;em&gt;trailing indicator&lt;/em&gt;. U.S. CISA had to privately validate in-the-wild exploitation before publishing, occasionally warning network defenders days or weeks after threat actors had already begun scanning at scale.&lt;/p&gt; 
&lt;p&gt;CISA shattered that bottleneck by launching a new, centralized KEV Nomination Form. This capability allows independent security researchers, technology vendors, and industry partners to directly report active, real-world vulnerability exploitation.&lt;/p&gt; 
&lt;p&gt;By aligning this intake mechanism with its existing Vulnerability Disclosure Policy (VDP) Platform and Coordinated Vulnerability Disclosure (CVD) Program, CISA is executing a massive strategic shift: it is transforming the KEV from an insular government list into a crowdsourced, high-velocity threat intelligence weapon.&lt;/p&gt; 
&lt;p&gt;The criteria for a vulnerability to earn a spot on the KEV catalog have always been strict and non-negotiable:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;It must have an assigned Common Vulnerabilities and Exposures (CVE) ID.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;There must be reliable evidence of active exploitation in the wild.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;There must be clear, actionable remediation guidance (such as a vendor patch).&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Historically, gathering that "reliable evidence" required extensive back-and-forth communication, data parsing from federal honeypots, or manual email triage via vulnerability@cisa.dhs.gov.&lt;/p&gt; 
&lt;p&gt;The new online nomination form systematizes this pipeline. Submitters are prompted to provide critical cryptographic and architectural evidence upfront, including the specific CVE number, precise evidence of exploitation (such as observed indicators of compromise or exploit payloads), remediation paths, and cross-vendor impact assessments. By structuring this intake, CISA can drastically compress its validation lifecycle—moving an active threat from a researcher's telemetry into the authoritative database in hours rather than days.&lt;/p&gt; 
&lt;p&gt;Organizations and researchers can access the KEV catalog and submit information through &lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"&gt;CISA.gov/known-exploited-vulnerabilities-catalog&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;This update represents a critical turning point for three major sectors of our ecosystem.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;1. For cybersecurity professionals: closing the remediation gap&lt;/h2&gt; 
&lt;p&gt;As highlighted in recent industry studies like the &lt;a href="https://www.secureworld.io/industry-news/verizon-dbir-attackers-moving-faster-than-remediation"&gt;2026 Verizon DBIR&lt;/a&gt;, the time between a vulnerability's disclosure and its active exploitation has shrunk to a matter of hours. Defenders are trapped in a human limit of manual patching.&lt;/p&gt; 
&lt;p&gt;By allowing the community to feed the KEV catalog directly, defenders get a high-fidelity signal much faster. When a flaw hits the KEV, it immediately cuts through the "noise" of traditional CVSS scores. It tells a SOC analyst: Stop debating the theoretical severity; this bug is being actively weaponized right now.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;2. For enterprise and software vendors: enforcing accountability&lt;/h3&gt; 
&lt;p&gt;The nomination form strips away the "maturity mirage" that some vendors rely on to delay patches. When external researchers can independently alert CISA to active exploitation through a formalized government pipeline, it forces tech providers to accelerate their Coordinated Vulnerability Disclosure timelines. Under Binding Operational Directive 22-01 (BOD 22-01), federal agencies are mandated to patch KEV flaws within highly aggressive, strict timeframes (often 15 to 25 days). By putting a vulnerability on the KEV faster, the entire industry is forced to match that accelerated tempo.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;3. For government and critical infrastructure: true collective defense&lt;/h4&gt; 
&lt;p&gt;As emphasized in recent CISA initiatives like CI Fortify, threat actors (such as nation-state groups like Volt Typhoon) excel at exploiting the siloes between private industry and public defense. The nomination form turns every enterprise SOC, MSSP, and independent bug hunter into a sensor for national security. A researcher discovering a zero-day exploit at a mid-sized utility can now instantly scale that visibility to protect the entire federal civilian executive branch (FCEB) and global private networks simultaneously.&lt;/p&gt; 
&lt;p&gt;We asked a few experts from solution providers for their input on the new CISA form.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Robert Costello, Chief Digital and Information Officer at Merlin Group, said:&lt;/p&gt; 
&lt;p&gt;"This is a strong example of CISA operationalizing its partnership with the cybersecurity research community in a very practical way. Crowdsourcing exploitation intelligence through a standardized nomination process means faster KEV additions and, ultimately, faster defensive action across the whole ecosystem. It's the right move at the right time, as AI is accelerating both the discovery and exploitation of vulnerabilities at a pace that makes early, coordinated disclosure more critical than ever."&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Mayuresh Dani, Security Research Manager&amp;nbsp;at Qualys Threat Research Unit, said:&lt;/p&gt; 
&lt;p&gt;"Yes, this is a new formal, structured, public-facing submission mechanism. Earlier, it lived as a plain, unstructured email address mentioned in BOD 22-01 guidelines. Organizations or individuals with information about an exploited vulnerability that is not currently listed on the KEV were previously encouraged to contact CISA by email and report their evidence."&lt;/p&gt; 
&lt;p&gt;"Before this, there were no external reports on how many vulnerabilities were added to the KEV based on submissions to this email address. With this form, CVE-ID, clear mitigation guidelines and exploitation evidence is made mandatory as a part of the current submission process. Vendor and product information is also requested as a part of the information collection process. Hopefully, this functionality will now provide visibility into what exactly happens post submission. What needs to be seen is how this information is verified by CISA and what guardrails against incorrect and false reporting are put in by CISA so that only real and validated exploitation observations make it to the KEV list. It's possible that CISA is trying to play catch up, as commercial alternatives to CISA KEV are available, and the fact that CISA KEV is a trailing indicator of vulnerability exploitation."&lt;/p&gt; 
&lt;p&gt;Can this new form realistically bolster submission quality? The short answer is yes, but the curation layer will be tested. By providing a structured, formalized reporting interface, CISA is providing security researchers with a clear roadmap of exactly what information constitutes "proof of exploitation." This minimizes administrative overhead and filters out low-value alerts or theoretical proof-of-concepts (PoCs), which CISA explicitly states do not qualify for KEV inclusion.&lt;/p&gt; 
&lt;p&gt;However, the true metric of success will be CISA's internal velocity. The influx of crowd-sourced telemetry will inevitably create an analytical bottleneck unless backed by highly-automated backend verification. If CISA can maintain its commitment to rapid validation, the new form will solidify the KEV catalog as a real-time shield&amp;nbsp;rather than a historical ledger.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fcisa-kev-nomination-form&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Security Research</category>
      <category>Vulnerabilities</category>
      <category>Original Content</category>
      <category>CISA</category>
      <category>KEV</category>
      <pubDate>Tue, 26 May 2026 14:13:01 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/cisa-kev-nomination-form</guid>
      <dc:date>2026-05-26T14:13:01Z</dc:date>
    </item>
    <item>
      <title>Report: Why Time Is Your Biggest Vulnerability in the AI Era</title>
      <link>https://www.secureworld.io/industry-news/time-biggest-vulnerability-ai-era</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/time-biggest-vulnerability-ai-era" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Time%20-%20man-checks-the-time-on-his-stylish-watch-2026-01-08-00-29-11-utc.jpg" alt="man checking time on wristwatch" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;Cybersecurity professionals&amp;nbsp;have spent years treating vulnerability management as a race against volume. Security operations centers (SOCs) have measured success by the sheer number of patches deployed or the total count of bugs squashed. But according to Synack's 2026 State of Vulnerabilities Report, the rules of the game have fundamentally changed.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;Cybersecurity professionals&amp;nbsp;have spent years treating vulnerability management as a race against volume. Security operations centers (SOCs) have measured success by the sheer number of patches deployed or the total count of bugs squashed. But according to Synack's 2026 State of Vulnerabilities Report, the rules of the game have fundamentally changed.&lt;/p&gt; 
&lt;p&gt;Analyzing data across more than 11,000 uncovered vulnerabilities, &lt;a href="https://go.synack.com/hubfs/synack-2026-state-of-vulnerabilities-report.pdf"&gt;the report&lt;/a&gt; introduces a stark reality for the AI era: vulnerability volume has remained stable, but the time between discovery and exploitation has entirely collapsed. In 2026, it's no longer fighting the number of bugs in the code; it's about&amp;nbsp;fighting the clock.&lt;/p&gt; 
&lt;p&gt;The defining metric of the 2026 report is the absolute erasure of the defender's buffer window. In previous years, security teams could rely on a standard lag time—often days or weeks—between when a vulnerability was disclosed and when an adversary successfully engineered an exploit.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;In the age of LLMs and machine-speed scanning, that window has shrunk to a matter of hours. Adversaries are leveraging highly-automated, AI-driven reconnaissance engines to ingest disclosure data, write functional exploit payloads, and scan the global internet for unpatched perimeters instantly. If your organization relies on a manual triage pipeline that takes days to approve emergency changes, you are effectively operating behind an already open door.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;"The category mix in our findings shows the signal: Remote code execution grew 39 percent," said Mark Kuhr, CTO of Synack. "Brute force was up 17. Content injection up 8. In 2025, our Synack Red Team researchers discovered more exposure on identity boundaries and authentication systems, which is where AI-driven attackers can probe systematically across thousands of assets at machine speed. Most vulnerabilities don't matter until they're chained. The shape of this finding mix is where the chains start."&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Where attackers are going next: the AI threat multiplier&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;Synack's research highlights how attackers are pivoting their strategies to exploit the unique friction points of modern corporate innovation.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Targeting "vibe coded" application logic: &lt;/span&gt;The mass adoption of GenAI code assistants has allowed developers to ship applications faster than ever. However, these models excel at syntax but frequently fail at deep authorization logic. As a result, the report notes a massive urgency surrounding traditional flaws like Insecure Direct Object References (IDOR) and broken access controls. Attackers are using AI to find the logical gaps that automated source-code scanners miss.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Exploiting the non-human frontier:&lt;/span&gt; The integration of LLMs into production pipelines has triggered a 25x year-over-year explosion in AI-specific packages and service integrations. This has created a vast, unmonitored attack surface of Non-Human Identities (NHIs)—tokens, API keys, and service accounts used by AI agents. Attackers are hunting for these credentials because they bypass traditional MFA and provide an unmonitored path straight to corporate data repositories.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Model poisoning and prompt injection:&lt;/span&gt; Adversaries are moving past traditional data exfiltration to target the integrity of AI models themselves. By manipulating the data streams feeding corporate LLMs, threat actors can subtly "defang" internal security tools or force public-facing models to leak sensitive telemetry.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: normal;"&gt;To survive an environment where time is the primary threat vector, cybersecurity professionals cannot simply tell their teams to do better and work harder.&amp;nbsp;Security posture must evolve from periodic assessment to continuous security validation, according to the report.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The report offers a blueprint for success: Synack customers managed to cut their Mean Time to Remediation (MTTR) for critical and high vulnerabilities nearly in half during 2025. They achieved this not by adding internal headcount, but by shifting to Continuous Penetration Testing as a Service (PTaaS). Merging AI-powered scanning tools with a vetted community of human researchers ensures that high-velocity automated alerts are instantly backed by human-verified, actionable context, allowing patching teams to execute fixes immediately.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Trying to fix every low-severity finding on a thousand-page scan report simply isn't viable. With exploitation timelines measured in hours, defenders must prioritize based on reachability. Use autonomous validation tools to determine whether a vulnerability lies on a live, executable path to your crown jewels—such as your production AI clusters, customer PII, or internal active directory. If an attacker cannot reach it, it should not delay your defense of assets that are actively exposed.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Because attackers are increasingly logging in rather than breaking in, the human workflows surrounding access require strict enforcement. Move toward Forensic Identity Verification for high-risk actions like help desk account recovery, API token creation, and remote developer onboarding. Ensure that the identities assigned to your autonomous AI agents are managed with the same strict Zero Trust rigor applied to human executives.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Treat your internal LLM infrastructure like critical infrastructure. Isolate your model data pipelines from general corporate networks and enforce runtime behavioral monitoring. If an authorized AI agent suddenly begins querying network subnets or requesting access to disconnected legacy databases, your architecture must be capable of dynamically revoking its permissions in milliseconds.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Ftime-biggest-vulnerability-ai-era&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Exploits</category>
      <category>Vulnerabilities</category>
      <category>Artificial Intelligence</category>
      <category>Original Content</category>
      <pubDate>Mon, 25 May 2026 16:24:01 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/time-biggest-vulnerability-ai-era</guid>
      <dc:date>2026-05-25T16:24:01Z</dc:date>
    </item>
    <item>
      <title>The Efficiency Trap: How AI Leads to Increased Work, Human Disconnection</title>
      <link>https://www.secureworld.io/industry-news/efficiency-trap-ai-increased-work</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/efficiency-trap-ai-increased-work" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Thinking%20man%20-%20Predictions%20-%20pensive-arab-guy-in-casual-sitting-at-workdesk-th-2025-03-18-19-08-58-utc.jpg" alt="man contemplating" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;In February 2026, a paper was published in &lt;em&gt;Harvard Business Review&lt;/em&gt; by Aruna Ranganathan and Xingqui Maggie Ye that described the &lt;a href="https://hbr.org/2026/02/ai-doesnt-reduce-work-it-intensifies-it"&gt;results of an eight-month study&lt;/a&gt; of how generative AI changed work habits at a mid-sized U.S.-based technology firm. They found that AI, while making tasks go quicker and easier, allowed employees to not just work faster, but ironically work longer hours and take on more tasks outside of their role.&amp;nbsp;Not because they were asked to but because AI made work easier, and that efficiency brought momentum that was easy to continue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In February 2026, a paper was published in &lt;em&gt;Harvard Business Review&lt;/em&gt; by Aruna Ranganathan and Xingqui Maggie Ye that described the &lt;a href="https://hbr.org/2026/02/ai-doesnt-reduce-work-it-intensifies-it"&gt;results of an eight-month study&lt;/a&gt; of how generative AI changed work habits at a mid-sized U.S.-based technology firm. They found that AI, while making tasks go quicker and easier, allowed employees to not just work faster, but ironically work longer hours and take on more tasks outside of their role.&amp;nbsp;Not because they were asked to but because AI made work easier, and that efficiency brought momentum that was easy to continue.&lt;/p&gt; 
&lt;p&gt;If an hour task can be automated and completed in 10 minutes with AI, we don't take 50 minutes off.&amp;nbsp;We us AI to do another 10-minute task, and another, and another to fill the hour. This rapid task completion is driven by dopamine and satisfied by serotonin: event, action, result—which is the same reason people doom scroll on social media. Being able to do satisfying tasks easy is the quickest way to sustain focus and attention.&lt;/p&gt; 
&lt;p&gt;That feeling doesn't tell you to stop. It tells you to keep going.&amp;nbsp;Imagine if you were in an airport walking on the people mover to increase the speed of your walking. You would feel energized that it was easier to travel farther, so you likely would walk instead of taking the railway between terminals.&lt;/p&gt; 
&lt;p&gt;This concept that efficiency breeds demand, not conservation, is called Jevons paradox. When technology makes the use of a resource more efficient, humans don't do less work, they do more. William Stanley Jevons made this observation in his 1865 book, &lt;em&gt;The Coal Question&lt;/em&gt;. At the time, Britain was burning a lot of coal, and the hope was the use of the steam engine would reduce their coal use. And it was true, steam engines helped coal-powered machines burn less coal. But, because they were cheaper to run, the factories used them more.&lt;/p&gt; 
&lt;p&gt;Jevons' insights went forgotten for 100 years until the 1970s U.S. energy crisis, when researchers found him again because they saw cars becoming more fuel efficient, making driving cheaper and&amp;nbsp;leading to people driving more and therefore&amp;nbsp;using more fuel.&lt;/p&gt; 
&lt;p&gt;It came back again in the 1980s when computers made office work more capable. We didn't reduce our work; we expanded what we could do.&lt;/p&gt; 
&lt;p&gt;I'm old enough to remember in the 1980s when working as an intern in an office, I would write out a report&amp;nbsp;then give it to a team in another room on Wang terminals who would type it up in the evening and leave a printout on my desk in the morning. When we started using individual word processors (WordStar was my first, but WordPerfect was my favorite), that reduced production time and potential iterations significantly. Instead of handwriting a report in a day, giving it to a typist, and getting the output the next day, I could write, edit, and produce at the same time and create multiple reports a day.&lt;/p&gt; 
&lt;p&gt;Here are other examples from other industries:&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-weight: bold;"&gt;Accountants using spreadsheets&lt;/span&gt; made accountants more useful, speeding up&amp;nbsp;simple math and able to do more complex equations easily, thus expanding the types and size of projects they can do.&amp;nbsp;And equations become sharable across the organization, instead of gatekept by someone in their personal notebook.&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-weight: bold;"&gt;Architects using AutoCAD: &lt;/span&gt;Twenty years ago, I had a conversation on a train with a veteran architect and asked him about the transition from drafting to computer-generated design. He said when they started using computers, clients asked to produce more iterations, the firm used smaller teams to tackle bigger projects, and this ultimately increased workload.&lt;/p&gt; 
&lt;p style="padding-left: 40px;"&gt;&lt;span style="font-weight: bold;"&gt;Digital cameras&lt;/span&gt; make unlimited shots cheap, so professional photographers now shoot hundreds per session, spend hours editing, and are expected to deliver more options. In the old days, you shot 36 pictures, developed them, and the customer just picked the best of the lot.&lt;/p&gt; 
&lt;p&gt;It turns out, humans don't want a certain amount of convenience or capability. We want more, and efficiency is how we get it. When friction is removed, work is expanded to fill the gap. Jevons paradox is not a human flaw in how we respond to AI;&amp;nbsp;it's a feature of human nature. We will always fill available capacity. We will always expand to meet new capability.&lt;/p&gt; 
&lt;p&gt;Which brings an underrated risk of AI by making tasks easier to do by yourself. You can now accomplish an enormous amount entirely alone: research, write, plan, build—all without any other human assistance. But with it, we also lose connection with people,&amp;nbsp;and a certain kind of thinking and collaboration that only happens between people.&lt;/p&gt; 
&lt;p&gt;The best use of time AI gives back shouldn't be to do more tasks. It should be more time with other humans. Conversations that don't have an agenda. Perspectives that aren't curated by a model trained on your own preferences. Disagreements that are uncomfortable and therefore useful.&lt;/p&gt; 
&lt;p&gt;In an era when AI can help you do more of the work, the human parts of work—such as relationship building, trust, disagreement, even surprise—become more valuable for our connection and enrichment.&lt;/p&gt; 
&lt;p&gt;Throughout human history, each new technology advancement promised to give people time back, and each one found that time immediately claimed by something else.&lt;/p&gt; 
&lt;p&gt;[RELATED: &lt;a href="https://www.secureworld.io/industry-news/2026-theme-timeless-cybersecurity"&gt;2026 SecureWorld Theme: Timeless Cybersecurity&lt;/a&gt;]&lt;/p&gt; 
&lt;p&gt;Whether you're the one deciding what fills the time freed up by AI, or that gets decided for you, the workers who navigate the AI era without over scheduling themselves and burning out &lt;em&gt;won't&lt;/em&gt; be the ones who automated the most. The people who succeed will be the ones who decided what they are working &lt;em&gt;for&lt;/em&gt;. Purpose is the only thing that keeps the machine from running you.&lt;/p&gt; 
&lt;p&gt;Use this recaptured time toward the work that AI can't do;&amp;nbsp;judgment, trust-building, creativity, and the kind of slow thinking that produces strategy rather than output.&lt;/p&gt; 
&lt;p&gt;But this vision also requires leaders who are willing to help their staff protect this space, not just assign more tasks to fill it. This is a conversation leaders will need to figure out, and learn how to accommodate.&lt;/p&gt; 
&lt;p&gt;[REALTED: &lt;a href="https://www.secureworld.io/industry-news/leadership-age-of-ai"&gt;Leadership in the Age of AI&lt;/a&gt;]&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fefficiency-trap-ai-increased-work&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Career Development</category>
      <category>Featured Author</category>
      <category>AI</category>
      <pubDate>Fri, 22 May 2026 13:21:01 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/efficiency-trap-ai-increased-work</guid>
      <dc:date>2026-05-22T13:21:01Z</dc:date>
      <dc:creator>Rick Doten</dc:creator>
    </item>
    <item>
      <title>Verizon DBIR 2026: Attackers Moving Faster than Remediation Efforts</title>
      <link>https://www.secureworld.io/industry-news/verizon-dbir-attackers-moving-faster-than-remediation</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/verizon-dbir-attackers-moving-faster-than-remediation" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Server_Room_shutterstock_2200880617.jpg" alt="man with laptop in data center row" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;The data has arrived, and it brings a stark reality check for the global security community. Released on May 19th, the 2026 Verizon Data Breach Investigations Report (DBIR)—now in its landmark 19th year—provides an unparalleled diagnostic look at our digital defenses.&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;The data has arrived, and it brings a stark reality check for the global security community. Released on May 19th, the 2026 Verizon Data Breach Investigations Report (DBIR)—now in its landmark 19th year—provides an unparalleled diagnostic look at our digital defenses.&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Analyzing a staggering 31,000 security incidents, including 22,000 confirmed data breaches across 145 countries, the report delivers an unambiguous verdict: Attackers are exploiting vulnerabilities faster than organizations can realistically remediate them.&lt;/p&gt; 
&lt;p&gt;While 2026 has seen a gold rush toward enterprise AI adoption and hyper-accelerated digital transformation, the fundamentals of cyber-defense are slipping further behind. &lt;a href="https://www.verizon.com/business/resources/T167/reports/2026-dbir-data-breach-investigations-report.pdf"&gt;The report&lt;/a&gt; challenges us to embrace a form of "cyber-stoicism"—acknowledging that while the speed and scale of threats are increasing, our survival relies entirely on fixing the foundational layers of our infrastructure.&lt;/p&gt; 
&lt;p&gt;The defining narrative of the 2026 DBIR is the collapse of the defender's timeline. The window between a critical vulnerability disclosure (CVE) and active, machine-speed exploitation has effectively shrunk to minutes.&lt;/p&gt; 
&lt;p&gt;Adversaries are no longer manually crafting attacks; they are leveraging automated reconnaissance engines and generative AI-augmented scanning tools to map corporate attack surfaces instantly. This means that before a security team can even review a critical patch or schedule a maintenance window, automated threat actors have already identified the exploit path and established initial access. We have officially reached the human limit of manual vulnerability management.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;Key findings&lt;/strong&gt;&lt;/h2&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The rise of GenAI-augmented exploits:&lt;/span&gt; Generative AI is no longer a theoretical threat vector. The 2026 data show&amp;nbsp;that GenAI-augmented malware and automated code compilation are now common occurrences, allowing lesser-skilled threat actors to deploy highly sophisticated payloads at an unprecedented scale.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Complex social engineering as the intercept:&lt;/span&gt; Complex, multi-stage social engineering campaigns remain the preferred prelude to a breach. Attackers are increasingly targeting the Workforce Identity Gap—using AI synthetic voice and deepfakes to exploit help desk verification protocols and bypass traditional multi-factor authentication (MFA).&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The software supply chain vulnerability:&lt;/span&gt; Zero-days and critical infrastructure vulnerabilities continue to spike year-over-year. Attackers are aggressively targeting third- and fourth-party software dependencies, allowing a single vulnerability in a shared component to compromise thousands of downstream enterprises simultaneously.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The persistent "maturity mirage":&lt;/span&gt; Organizations are investing heavily in advanced security platforms, yet the vast majority of confirmed breaches still trace back to basic failures: unpatched software, credential stuffing, and poorly segmented cloud environments.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: normal;"&gt;For enterprises, this means pivoting to automated attack path validation. The DBIR confirms that trying to patch every vulnerability on a massive list is a losing strategy. Enterprises must shift from static vulnerability scanning to continuous, automated attack path validation. You must use automation to discover which vulnerabilities actually lie on a live "path to privilege" toward your crown jewels—especially your production AI clusters and data pipelines—and remediate those first.&lt;/p&gt; 
&lt;p&gt;For government entities, they must implement collective defense and secure-by-design mandates. With state-sponsored and financially motivated actors moving at machine speed, public infrastructure faces sustained pressure. Government entities must move past checkbox compliance. In line with CISA's &lt;i&gt;CI Fortify&lt;/i&gt; and &lt;i&gt;Secure-by-Design&lt;/i&gt; initiatives, governments must prioritize the decommissioning of technical debt and legacy infrastructure, while mandating rigorous forensic identity controls across all public-facing services.&lt;/p&gt; 
&lt;p&gt;For cybersecurity professionals, the focus must be on defending the internal frontier. Defenders must accept that initial access will happen faster than they can patch. Therefore, the architecture must assume compromise, including:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Runtime-first detection:&lt;/span&gt; Enforce continuous, behavioral monitoring inside the network. When an adversary exploits a zero-day, your primary line of defense is catching their anomalous lateral movement at runtime.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Hardening identity enforcement:&lt;/span&gt; Since attackers are "logging in" rather than "breaking in," identity management must evolve from static single-point authentication to continuous, automated enforcement. If an identity or a&amp;nbsp;service account exhibits irregular behavioral patterns, its access must be revoked dynamically.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;We asked experts from cybersecurity solution providers for their commentary on the report's findings.&lt;/p&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/jason-soroko-19b41920/"&gt;Jason Soroko&lt;/a&gt;, Senior Fellow at Sectigo, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"The headline finding of the 2026 Data Breach Investigations Report reveals a stark shift in the threat landscape where vulnerability exploitation has surged to account for nearly a third of all initial access vectors, decisively outpacing traditional credential abuse. While the industry fixates on the growing backlog of unpatched systems and a worsening median time to remediate, reading this data purely as a patching crisis represents a critical failure in strategic thinking. From the vantage point of a Certificate Authority, the true revelation is the relationship between unpatched vulnerabilities and identity security. A breached perimeter through a software exploit is often just the opening maneuver. The subsequent lateral movement and privilege escalation rely entirely on brittle authentication mechanisms. When we analyze the underlying genealogy of these attacks, it becomes evident that robust cryptographic trust and rigorous certificate lifecycle management act as the definitive fail-safe."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"This dynamic changes how we must architect enterprise defenses, especially as AI-augmented weaponization accelerates the pace of exploitation beyond human response capabilities. As autonomous systems become deeply integrated into corporate networks, the traditional focus on securing human credentials is no longer sufficient. The most effective mitigation strategy requires abstracting our defenses away from the endless race to patch individual endpoints and instead establishing a hardened identity and authorization control plane. By guaranteeing that every machine, workload, and enterprise AI agent is strictly authenticated through tightly managed public key infrastructure, organizations can effectively neutralize the blast radius of an exploited vulnerability. Even if an attacker successfully breaches the outer wall, cryptographic verification ensures they cannot assume trusted roles or siphon data, ultimately transforming a potentially catastrophic breach into a localized and manageable event."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/collin-hogue-spears/"&gt;Collin Hogue-Spears&lt;/a&gt;, Senior Director of Solution Management at Black Duck, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"Vulnerability exploitation topped the DBIR because AI-accelerated attacks outrun patching. AI did not create that gap. AI erased the head start defenders used to have. The fix is not faster patching. It is patching by reachability and containing the rest."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The losing strategy patches by volume. The winning one patches by reachability and contains the rest. Reachability analysis separates the flaws attackers can actually exploit from the ones that only look dangerous. Compensating controls buy time on everything triage has not cleared. Log4Shell proved the point: speed was never the bottleneck. Teams could not patch a library buried in thousands of dependencies, and the ones that filtered outbound traffic bought time to find it."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Strategic takeaway: While it is true security leaders must prioritize the CISA Known Exploited Vulnerabilities catalog before the CVSS severity queue. CVSS tells you how bad a flaw can be. KEV tells you which flaws attackers already use. Patch by severity alone, and you will spend scarce engineering time on theoretical risk while active exploitation waits in the queue. Patching is just one of two layers. Leaders must invest in two layers, not one. The first is AI-augmented reachability analysis that separates exploitable findings from theoretical ones. The second is compensating controls: egress restrictions, behavioral allowlists, and identity-bound access. Those controls slow exploitation while triage runs, because triage and containment are the two clocks defenders can still control."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/chandra-gnanasambandam/"&gt;Chandra Gnanasambandam&lt;/a&gt;, CTO at SailPoint, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"We're in a new normal where the time to exploitation has changed dramatically. It used to take about a year in the early 2020s. Today, it's getting close to an hour, and the direction it's going, it could be minutes."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Cybercrime has become industrialized. It's no longer a cottage industry. It's no longer a bunch of rogue actors trying to do things. Now combine that with the fact that cloud environments, particularly dev environments, were always built with a developer in mind. They were really built for developer experience. They were never built with a security posture in mind. And in a world where 95% of access is standing, this is a deadly combination. This is really what has led to the new normal, and it is against this backdrop where we are moving to one of the most fundamental transformations in the world. In the last 25 years, security and governance have always been about human."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Today, we're in a human plus AI world, requiring a very different security paradigm, one that's based on adaptive identity with zero standing privilege as a minimum requirement."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/treyford/"&gt;Trey Ford&lt;/a&gt;, Chief Strategy and Trust Officer at Bugcrowd, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;"The DBIR's 19-year credential streak ending is not primarily a credential story—it is an economics story."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"AI is making vulnerability discovery and weaponization so fast and cheap that attackers no longer need a stolen password when a known, unpatched flaw gets them in faster. Third-party involvement now accounts for 48% of all breaches, up 60% year over year, which means the attack surface enterprises must defend extends well beyond anything they directly control or test."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"AI has compressed the window between a published vulnerability and an active exploit from months to hours. Security budgets still calibrated to annual assessment cycles are now structurally mismatched with how fast the threat actually moves."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/mjhaber/"&gt;Morey Haber&lt;/a&gt;, Chief Security Advisor at BeyondTrust, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"Every year, the Verizon Data Breach Investigations Report&amp;nbsp;lands like an annual cybersecurity checkup, whether you wanted to see it or not. Unfortunately, the symptoms and reporting already lend credence to the diagnosis, but the numbers still manage to sting. The 2026 edition is no different, and the pain is very real."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"Analyzing more than 22,000 confirmed breaches across 145 countries, it is the largest and most comprehensive study the DBIR team has ever conducted in a single report. That is not a milestone we should celebrate but rather a warning that cybersecurity incidents continue to escalate and become more public."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"To that end, the headline this year belongs to vulnerability exploitation, which has surpassed credential abuse as the most common initial attack vector. Exploitation now accounts for 31% of breaches, while stolen credentials have fallen to 13% (16% with Pretexting as a consideration). This inversion matters because for years, organizations have operated under the assumption that identity, specifically, compromised usernames and passwords&amp;nbsp;was the primary entry point into an organization. After all, it is easier for a threat actor to login versus hack in, right?"&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/mpaalto/"&gt;Mika Aalto&lt;/a&gt;, Co-Founder and CEO at Hoxhunt, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"The DBIR's message this year is refinement, not revolution. AI is accelerating threats, but the organizations that will stay resilient are still the ones executing well on fundamentals: patching, incident response, identity management, and increasingly, security culture."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Having contributed our own data set of tens of millions of human cyber behaviors with Verizon for the second year in a row, I found it interesting that Verizon explicitly included 'a culture that supports and enables secure behavior'&amp;nbsp;alongside technical controls like patch management and response planning. That's an important signal for the industry. Security culture is no longer a soft initiative sitting outside core security operations. It's part of the operational foundation."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/ramvaradarajan/"&gt;Ram Varadarajan&lt;/a&gt;, CEO at Acalvio, said:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Fundamentally, complex systems cannot be guaranteed to be safe. So, the more complex our software and infrastructure becomes, the more threats we introduce into it. This risk will now compound as we use AI to write limitless amounts of code. Add in the vulnerabilities being exploited in code bases driven by AI, the effectiveness AI has in socially engineering humans, and also the phenomena of emergent misalignment, and we can see that we're living in a truly zero-trust world. You thought you were safe when you locked the door behind you in your house, but the doors and windows aren't secure, and there are already attackers hiding in your closet and beneath your bed. And this will forever be the case."&lt;/p&gt; &lt;/li&gt; 
 &lt;li style="font-weight: normal;"&gt; &lt;p&gt;"Our only true defense is to comprehensively tripwire our cyber infrastructure with model-aware detections and traps, and to dynamically engage reasoning swarms of AI attackers with swarms of reasoning AI defenders.&amp;nbsp;It's a future that's full-on game-theoretic, AI-driven, bot-on-bot cyber defense."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;a href="https://www.linkedin.com/in/dianakelleysecuritycurve/"&gt;Diana Kelley&lt;/a&gt;, CISO at Noma Security, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"The Verizon DBIR makes one thing very clear: AI is not magically creating a new cyber universe. It is industrializing the one we already struggle to defend. The notable finding is that most AI-assisted malware and tooling activity still maps to 'well-known and defined attack techniques,'&amp;nbsp;but those techniques are getting faster, broader, and easier to execute. The rise of vulnerability exploitation to 31% of initial access and the System Intrusion pattern growing from 36% in 2024 to about 60% in 2026 show this in practice."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"For CISOs, that means the AI story is not just phishing emails with better grammar. It is about vulnerability exploitation becoming the top initial access vector, Shadow AI turning source code and technical documents into accidental data leakage, and agentic systems creating a new class of privileged, machine-speed actors. If an AI agent can act, connect to tools, move data, or trigger workflows, it needs to be governed like a privileged identity: least privilege, full logging, human approval for high-risk actions and a fast way to revoke access."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The practical response is not panic or a ban. It is governance with teeth: know where AI is being used, understand the blast radius, manage confidential data egress, treat agents and service accounts as high-risk identities, enforce least privilege, monitor tool use, and rehearse what happens when an agent makes the wrong decision at machine speed."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;"The DBIR's most important AI takeaway is refreshingly grounded: attackers are scaling the basics, and 'the fundamentals still matter most.'&amp;nbsp;Defenders need to do the same, only faster, cleaner, &lt;span&gt;and with much better control over identity, data, and third parties.&lt;/span&gt;"&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fverizon-dbir-attackers-moving-faster-than-remediation&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Vulnerabilities</category>
      <category>Original Content</category>
      <category>Data Breach</category>
      <pubDate>Thu, 21 May 2026 12:38:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/verizon-dbir-attackers-moving-faster-than-remediation</guid>
      <dc:date>2026-05-21T12:38:00Z</dc:date>
    </item>
    <item>
      <title>Airborne Intrusion: Why Drones Are the New Mobile Perimeter Threat</title>
      <link>https://www.secureworld.io/industry-news/drones-mobile-perimeter-threat</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/drones-mobile-perimeter-threat" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/jason-blackeye-XYrjl3j7smo-unsplash.jpg" alt="drone flying above forest" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;&lt;span&gt;When we think about physical security at large-scale public gatherings,&lt;/span&gt;&lt;span&gt; our minds go to fences,&lt;/span&gt;&lt;span&gt; bag checks,&lt;/span&gt;&lt;span&gt; and ground-based guards.&lt;/span&gt;&lt;span&gt; When we think about cybersecurity,&lt;/span&gt;&lt;span&gt; we picture remote threat actors hitting a firewall from thousands of miles away.&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;span&gt;When we think about physical security at large-scale public gatherings,&lt;/span&gt;&lt;span&gt; our minds go to fences,&lt;/span&gt;&lt;span&gt; bag checks,&lt;/span&gt;&lt;span&gt; and ground-based guards.&lt;/span&gt;&lt;span&gt; When we think about cybersecurity,&lt;/span&gt;&lt;span&gt; we picture remote threat actors hitting a firewall from thousands of miles away.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;But a groundbreaking new whitepaper from the Center for Internet Security (CIS), "Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings," completely shatters this separation. &lt;a href="https://www.secureworld.io/hubfs/documents/UAS%20Companion%20Cyber%20Risk%20%20-%20Emerging%20Risks%20Whitepaper%20-%20CIS%20-%20May%202026.pdf"&gt;The report&lt;/a&gt; issues a vital warning for security teams: Drones are no longer just potential kinetic or surveillance threats; they are fully weaponized, mobile cyber-access platforms.&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;By providing an aerial vantage point,&lt;/span&gt;&lt;span&gt; a commercial drone can hover directly outside an upper floor office window or over a stadium command post,&lt;/span&gt;&lt;span&gt; entirely bypassing the physical boundaries that traditional network architecture relies on.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Traditional perimeter defense assumes that an attacker needs to either compromise an internet-facing service or physically walk into a building to exploit a localized network.&lt;/span&gt;&lt;span&gt; Drones weaponize proximity.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;A standard commercial drone carrying lightweight,&lt;/span&gt;&lt;span&gt; low-cost computing hardware—such as a Raspberry Pi,&lt;/span&gt;&lt;span&gt; a Wi-Fi Pineapple,&lt;/span&gt;&lt;span&gt; or a software-defined radio (SDR)—can lift a threat actor's digital toolkit within wireless range of critical systems.&lt;/span&gt;&lt;span&gt; The attacker remains safely hidden miles away,&lt;/span&gt;&lt;span&gt; but their exploit tools are sitting right outside your window.&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;The CIS supplemental paper, developed in collaboration with premier industry partners—including DroneSec, DRONERESPONDERS, Aerisq Solutions, the National Fusion Center Association (NFCA) Cyber Intelligence Network (CIN), and the National Real Time Crime Center Association (NRTCCA)—identifies three major threat pathways that security professionals must understand.&lt;/p&gt; 
&lt;h2&gt;&lt;strong&gt;1. Airborne reconnaissance and signal interception&lt;/strong&gt;&lt;/h2&gt; 
&lt;p&gt;&lt;span&gt;Drones provide the ultimate vantage point for mapping a dense radio frequency (RF) environment.&lt;/span&gt;&lt;span&gt; Threat actors can use them to scan for weakly protected access points,&lt;/span&gt;&lt;span&gt; sniff out Bluetooth/RFID data,&lt;/span&gt;&lt;span&gt; and map IoT infrastructure.&lt;/span&gt;&lt;span&gt; Crucially,&lt;/span&gt;&lt;span&gt; as modern venues pivot toward private LTE/5G and Citizens Broadband Radio Service (CBRS) networks to run ticketing and internal communications,&lt;/span&gt;&lt;span&gt; airborne platforms enable attackers to intercept traffic or conduct rogue base station activity from public rights-of-way.&lt;/span&gt;&lt;/p&gt; 
&lt;h3&gt;&lt;strong&gt;2. Wireless exploitation and 'evil twins'&lt;/strong&gt;&lt;/h3&gt; 
&lt;p&gt;&lt;span&gt;Equipped with penetration testing platforms,&lt;/span&gt;&lt;span&gt; a drone can broadcast a fraudulent wireless network mimicking trusted event Wi-Fi.&lt;/span&gt;&lt;span&gt; If a contractor,&lt;/span&gt;&lt;span&gt; broadcaster,&lt;/span&gt;&lt;span&gt; or employee inadvertently connects to this "evil twin,&lt;/span&gt;&lt;span&gt;" the adversary can execute Man-in-the-Middle (MitM) attacks,&lt;/span&gt;&lt;span&gt; harvest credentials,&lt;/span&gt;&lt;span&gt; and pivot deeper into enterprise segments.&lt;/span&gt;&lt;span&gt; The report even points to past real-world incidents where dual-drone configurations (one acting as a wireless interceptor,&lt;/span&gt;&lt;span&gt; the other as a 4G relay) were found targeted on corporate rooftops.&lt;/span&gt;&lt;/p&gt; 
&lt;h4&gt;&lt;strong&gt;3. Physical implant delivery&lt;/strong&gt;&lt;/h4&gt; 
&lt;p&gt;&lt;span&gt;A drone can physically deliver a cyber exploit tool.&lt;/span&gt;&lt;span&gt; By dropping a weaponized USB drive (like a &lt;a href="https://www.threatlocker.com/blog/beware-the-rubber-duckies"&gt;Rubber Ducky&lt;/a&gt;),&lt;/span&gt;&lt;span&gt; a rogue sensor,&lt;/span&gt;&lt;span&gt; or a network implant onto restricted loading docks,&lt;/span&gt;&lt;span&gt; balconies,&lt;/span&gt;&lt;span&gt; or rooftop HVAC structures,&lt;/span&gt;&lt;span&gt; attackers can achieve persistent network access.&lt;/span&gt;&lt;span&gt; Even if the device isn't picked up immediately,&lt;/span&gt;&lt;span&gt; the cyber impact is a ticking time bomb.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;The report highlights two highly-advanced threat profiles that challenge conventional risk models:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Optical data exfiltration:&lt;/span&gt; High-resolution cameras on drones don't just capture video of crowds; they can capture sensitive whiteboards, server rooms, or exposed screens through windows. The whitepaper highlights advanced research demonstrating data exfiltration from air-gapped systems by deploying malware that blinks a computer's hard-drive LED light, which is then recorded and decoded by a drone hovering outside.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Targeting the counter-UAS ecosystem:&lt;/span&gt; The software, firmware, and SaaS dependencies powering an organization's &lt;i&gt;own&lt;/i&gt; drone and counter-drone defense systems are highly-attractive targets. If an attacker manipulates Remote ID signals, poisons a counter-UAS sensor feed, or compromises ground control stations, they can effectively blind security teams, masking malicious UAS operations.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The whitepaper serves as a follow-on to &lt;a href="https://www.cisecurity.org/insights/white-papers/uas-evolving-risks-to-large-scale-public-gatherings"&gt;"Unmanned Aircraft Systems (UAS): Evolving Risks to Large-Scale Public Gatherings"&lt;/a&gt; released last month.&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;To mitigate the reality of airborne cyber threats,&lt;/span&gt;&lt;span&gt; security leaders must treat airspace awareness and network security as a unified discipline.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Airspace domain awareness must be cross-cued with the SOC.&lt;/span&gt;&lt;span&gt; If a counter-UAS sensor flags an unauthorized drone hovering near a broadcast truck or network closet,&lt;/span&gt;&lt;span&gt; the cybersecurity team must immediately audit wireless logs for rogue SSIDs,&lt;/span&gt;&lt;span&gt; unexpected de-authentication packets,&lt;/span&gt;&lt;span&gt; and credential spikes.&lt;/span&gt;&lt;br&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Legacy wireless protocols are an open invitation to proximity attacks.&lt;/span&gt;&lt;span&gt; Organizations must enforce WPA3 encryption,&lt;/span&gt;&lt;span&gt; eliminate shared passwords,&lt;/span&gt;&lt;span&gt; strictly segment vendor and guest networks,&lt;/span&gt;&lt;span&gt; and continuously monitor the RF spectrum for anomalies and unauthorized signal spikes.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Authorized public safety,&lt;/span&gt;&lt;span&gt; media,&lt;/span&gt;&lt;span&gt; or vendor drones are mobile computers.&lt;/span&gt;&lt;span&gt; They must be secured using CISA guidelines—including separate telemetry,&lt;/span&gt;&lt;span&gt; control,&lt;/span&gt;&lt;span&gt; and video channels,&lt;/span&gt;&lt;span&gt; encrypted communications,&lt;/span&gt;&lt;span&gt; multi-factor authentication (MFA),&lt;/span&gt;&lt;span&gt; and a rigorous evaluation of supply-chain risks (such as restrictions on &lt;a href="https://www.secureworld.io/industry-news/fcc-foreign-consumer-routers-covered-list"&gt;foreign-manufactured hardware&lt;/a&gt; and&amp;nbsp; firmware).&lt;/span&gt;&lt;br&gt;&lt;span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span&gt;Counter-drone platforms are critical IT assets.&lt;/span&gt;&lt;span&gt; Isolate management interfaces from public networks,&lt;/span&gt;&lt;span&gt; monitor sensor feeds for irregular data inconsistencies,&lt;/span&gt;&lt;span&gt; and ensure procurement matches &lt;/span&gt;&lt;i&gt;Secure by Design&lt;/i&gt;&lt;span&gt; principles.&lt;/span&gt;&lt;/p&gt; 
&lt;span&gt;Future incident response exercises must bridge the gap between physical security,&lt;/span&gt;
&lt;span&gt; law enforcement,&lt;/span&gt;
&lt;span&gt; and cybersecurity teams.&lt;/span&gt;
&lt;span&gt; Run scenarios where a physical drone detection is tied to a simultaneous cyber intrusion,&lt;/span&gt;
&lt;span&gt; such as automated credential harvesting or camera network disruption.&lt;/span&gt; 
&lt;p&gt;&lt;span&gt;The CIS whitepaper demonstrates that our traditional assumptions about perimeter separation are obsolete.&lt;/span&gt;&lt;span&gt; In an era where a drone can transport an attacker's digital proxy directly into a venue's line of sight,&lt;/span&gt;&lt;span&gt; the separation between physical security and cybersecurity has vanished.&lt;/span&gt;&lt;span&gt; The security architectures that survive will be those that establish a shared common operating picture—securing the network,&lt;/span&gt;&lt;span&gt; the human workforce,&lt;/span&gt;&lt;span&gt; and the skies simultaneously.&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fdrones-mobile-perimeter-threat&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Original Content</category>
      <category>Wi-Fi</category>
      <category>Endpoint / Mobile Security</category>
      <category>Drones</category>
      <category>Center for Internet Security</category>
      <pubDate>Wed, 20 May 2026 17:44:00 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/drones-mobile-perimeter-threat</guid>
      <dc:date>2026-05-20T17:44:00Z</dc:date>
    </item>
    <item>
      <title>Report Reveals 'Security Anxiety' Behaviors with Data Sanitization</title>
      <link>https://www.secureworld.io/industry-news/security-anxiety-behaviors-data-sanitization</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/security-anxiety-behaviors-data-sanitization" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/software-based%20shutterstock_2769056479.jpg" alt="man pointing to his computer screen" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p style="font-weight: normal;"&gt;In the cybersecurity world, teams spend billions of dollars on the "front door"—firewalls, identity platforms, and runtime detection. But according to Blancco's 2026 State of Data Sanitization Report, organizations are increasingly stumbling at the "back door."&lt;/p&gt;</description>
      <content:encoded>&lt;p style="font-weight: normal;"&gt;In the cybersecurity world, teams spend billions of dollars on the "front door"—firewalls, identity platforms, and runtime detection. But according to Blancco's 2026 State of Data Sanitization Report, organizations are increasingly stumbling at the "back door."&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;Based on a global survey of 1,460 IT, compliance, and sustainability leaders, &lt;a href="https://blancco.com/resources/rs-data-sanitization-report/?utm_campaign=405545200-global-data-sanitization-research-study-report-2026&amp;amp;utm_source=media&amp;amp;utm_medium=pr"&gt;the report&lt;/a&gt; reveals a jarring disconnect: while 90% of organizations express high confidence in their data sanitization protocols, their actual behaviors suggest a deep-seated "security anxiety" that is driving both environmental waste and hidden cyber risks.&lt;/p&gt; 
&lt;p&gt;Here is what the "sanitization paradox" means for the 2026 enterprise.&lt;/p&gt; 
&lt;p&gt;The report's most striking finding is the delta between perceived and actual security. Organizations believe they are protected, yet the operational reality tells a different story.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Audit failures:&lt;/span&gt; A significant percentage of organizations rely on manual logs or "promises" from vendors rather than tamper-proof, automated certificates of erasure.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The "destruction" fallacy:&lt;/span&gt; Many leaders still equate physical destruction (shredding) with security. However, improper shredding often leaves fragments large enough for forensic data recovery, and more importantly, it provides no digital "audit trail" for compliance.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Redeployment risks:&lt;/span&gt; As remote work remains a staple, the report highlights that lost or stolen devices that were &lt;i&gt;supposed&lt;/i&gt; to be wiped before redeployment are a leading cause of preventable data leaks.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Security anxiety isn't just a psychological state; it's a budgetary and environmental drain. Because organizations don't trust their sanitization processes, they default to hoarding or destroying hardware.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;E-waste and sustainability:&lt;/span&gt; Organizations are shredding millions of functional drives because they fear data remanence. This "destroy-by-default" mindset directly contradicts global ESG (Environmental, Social, and Governance) mandates.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;The financial burden:&lt;/span&gt; Storing decommissioned assets in "secure" closets creates a massive storage cost and a "dormant" attack surface. If an adversary gains physical access to a storage site filled with poorly sanitized "legacy" hardware, the breach is instantaneous.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: normal;"&gt;The 2026 report introduces a new variable: the AI training loop. As organizations rush to adopt GenAI, they are often moving large datasets across environments.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Training data leakage:&lt;/span&gt; High-value data used for model training often resides on decommissioned hardware. If these assets are not sanitized to a forensic standard, proprietary models or sensitive training sets can be reconstructed by third parties.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;Non-Human Identity (NHI) risks:&lt;/span&gt; The report notes that service accounts and AI agent credentials are often left "hot" on decommissioned devices, providing a ready-made path to privilege&amp;nbsp;for whoever acquires the hardware on the secondary market.&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;h2&gt;&lt;strong&gt;What this means for the 2026 stakeholders&lt;/strong&gt;&lt;/h2&gt; 
&lt;h4 style="font-size: 17px; font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;For enterprises: Automate the audit&lt;/span&gt;&lt;/h4&gt; 
&lt;h4 style="font-size: 17px; font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Confidence must be replaced by validation. Move away from manual checklists and adopt software-based erasure that provides a serialized, automated certificate of destruction. This allows for the safe reuse or resale of hardware, aligning security goals with sustainability targets.&lt;/h4&gt; 
&lt;h4 style="font-size: 17px; font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;For governments: Closing the regulatory loop&lt;/span&gt;&lt;/h4&gt; 
&lt;h4 style="font-size: 17px; font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Regulators are increasingly looking at "end-of-life" data as a critical privacy frontier. For government agencies, the report suggests that "secure storage" is not a substitute for sanitization. Policy must shift toward a "Sanitize-Before-Store" mandate to prevent the long-term risk of physical theft.&lt;/h4&gt; 
&lt;p style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;For cybersecurity professionals: Mind the exit&lt;/span&gt;&lt;/p&gt; 
&lt;p style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;Sanitization is a core component of Attack Surface Management.&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Treat decommissioning as an incident: &lt;/span&gt;Use the same rigor for device exit as you do for employee onboarding.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Harden the help desk: &lt;/span&gt;Ensure that the Account Recovery and Device Return&amp;nbsp;workflows are unified. As identified in the &lt;a href="https://www.secureworld.io/industry-news/microsoft-vulnerabilities-report-2026"&gt;BeyondTrust research&lt;/a&gt;, the handoff of hardware is a prime target for social engineering.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: normal;"&gt;&lt;span style="font-weight: bold;"&gt;Validate fourth-party risk: &lt;/span&gt;If you use an IT Asset Disposition (ITAD) vendor, you must audit their sanitization process. Your liability doesn't end when the hardware leaves your loading dock.&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;"Organizations want to be compliant with data regulations and protect their customers'&amp;nbsp;data, but too often they are using inadequate techniques or ones that destroy devices as well as sensitive data," said Lou DiFruscio, CEO of Blancco. "The unpredictable cost of buying new devices means more sustainable alternatives need to be considered—techniques that will keep data secure &lt;em style="font-size: 17px;"&gt;&lt;span style="line-height: 19.425px;"&gt;and &lt;/span&gt;&lt;/em&gt;&lt;span style="line-height: 19.425px;"&gt;allow devices to be reused and redeployed."&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 19.425px;"&gt;&lt;/span&gt;Other findings include:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 19.425px;"&gt;90% of organizations have deployed AI in the last year, and of these, 99% have destroyed more devices as a result.&lt;/span&gt;&lt;span style="line-height: 19.425px;"&gt; &lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 19.425px;"&gt;Sustainability is seen as a major influence on data management decisions by 33% of organizations.&lt;/span&gt;&lt;span style="line-height: 19.425px;"&gt; &lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 19.425px;"&gt;56% of organizations see data security as a major barrier to achieving sustainability goals.&lt;/span&gt;&lt;/p&gt; &lt;span style="line-height: 19.425px;"&gt; &lt;/span&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p style="font-weight: normal;"&gt;Blancco's 2026 report confirms that the hustle hard era of manual IT management is failing the back-end of the lifecycle. To move past security anxiety, organizations must embrace automated, verified data erasure. The most secure organizations won't be those that destroy the most hardware—they will be the ones that can &lt;i&gt;prove&lt;/i&gt; their data is gone without wasting the asset.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fsecurity-anxiety-behaviors-data-sanitization&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Data Security</category>
      <category>Original Content</category>
      <category>E-Waste</category>
      <category>Data Protection Solutions</category>
      <pubDate>Wed, 20 May 2026 11:39:01 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/security-anxiety-behaviors-data-sanitization</guid>
      <dc:date>2026-05-20T11:39:01Z</dc:date>
    </item>
    <item>
      <title>Newcomers to Canada Are the Fraud Victims the Loss Ledger Keeps Missing</title>
      <link>https://www.secureworld.io/industry-news/newcomers-canada-fraud-victims</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/newcomers-canada-fraud-victims" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Call%20Scam%20-%20businessman-on-the-phone-in-office-at-night-2024-09-18-03-56-45-utc.jpg" alt="man on phone call" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Thirty-eight percent of newcomers to Canada say they have been hit by at least one fraud, more than double the 17 percent rate among other Canadians, according to &lt;a href="https://scotiabank.investorroom.com/2024-02-22-New-Canadians-taking-stronger-measures-to-prevent-fraud-and-protect-their-money"&gt;Scotiabank's 2024 Fraud Poll&lt;/a&gt;. The Canadian Anti-Fraud Centre logged &lt;a href="https://www.canada.ca/en/competition-bureau/news/2026/03/fraud-prevention-month-to-bring-hidden-crime-into-the-spotlight.html"&gt;$704 million&lt;/a&gt; in reported losses in 2025, up from &lt;a href="https://www.canada.ca/en/competition-bureau/news/2025/02/fraud-prevention-month-to-focus-on-impersonation-fraud-one-of-the-fastest-growing-forms-of-fraud.html"&gt;$638 million&lt;/a&gt; the year before, with the Competition Bureau noting that only 5 to 10 percent of incidents are reported in the first place.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Thirty-eight percent of newcomers to Canada say they have been hit by at least one fraud, more than double the 17 percent rate among other Canadians, according to &lt;a href="https://scotiabank.investorroom.com/2024-02-22-New-Canadians-taking-stronger-measures-to-prevent-fraud-and-protect-their-money"&gt;Scotiabank's 2024 Fraud Poll&lt;/a&gt;. The Canadian Anti-Fraud Centre logged &lt;a href="https://www.canada.ca/en/competition-bureau/news/2026/03/fraud-prevention-month-to-bring-hidden-crime-into-the-spotlight.html"&gt;$704 million&lt;/a&gt; in reported losses in 2025, up from &lt;a href="https://www.canada.ca/en/competition-bureau/news/2025/02/fraud-prevention-month-to-focus-on-impersonation-fraud-one-of-the-fastest-growing-forms-of-fraud.html"&gt;$638 million&lt;/a&gt; the year before, with the Competition Bureau noting that only 5 to 10 percent of incidents are reported in the first place.&lt;/p&gt; 
&lt;p&gt;The published ledger is the visible tip of a much larger exposure, and the underreporting concentrates in a cohort that Canadian fraud-prevention infrastructure was not designed around.&lt;/p&gt; 
&lt;h2 style="font-weight: normal;"&gt;A 38 percent victimization rate inside a $704 million loss ledger&lt;/h2&gt; 
&lt;p&gt;The 38 percent figure tracks &lt;a href="https://onthemovecanada.com/migrate-to-canada/"&gt;newcomers to Canada&lt;/a&gt; in the most procedurally exposed window of their lives here: working through unfamiliar banking, regulatory authorities, and housing and employment markets in their first 12 to 24 months. Tammy McKinnon, Scotiabank's Senior Vice President of Global Fraud Management, framed the survey's central finding directly: "When it comes to financial fraud, everyone is a target, particularly individuals who may be in vulnerable positions such as newcomers to Canada."&lt;/p&gt; 
&lt;p&gt;A separate &lt;a href="https://www.interac.ca/en/content/news/interac-survey-shows-more-than-half-of-new-canadian-families-have-been-targeted-by-financial-fraud/"&gt;2023 Interac survey&lt;/a&gt; sharpens the picture: 70 percent of newcomers feel more susceptible to scams than the general population, 53 percent say they or a family member have been targeted, and only 22 percent would know how to respond. The 5 to 10 percent reporting gap is not evenly distributed; the cohorts that lack language access or trust in reporting channels are the ones the loss ledger underrepresents.&lt;/p&gt; 
&lt;p&gt;So, $704 million is what gets reported. Actual exposure is a multiple of that, sitting inside a population the apparatus does not segment for.&lt;/p&gt; 
&lt;h3 style="font-weight: normal;"&gt;Three vectors that disproportionately land on newcomers&lt;/h3&gt; 
&lt;p&gt;CAFC vector data and FINTRAC operational alerts converge on three typologies that concentrate on newcomer targets. None are unique to newcomers, but each weaponizes friction points recent arrivals experience at higher rates.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Authority impersonation: CRA, IRCC, and Service Canada&lt;/p&gt; 
&lt;p&gt;The CAFC tracks &lt;a href="https://antifraudcentre-centreantifraude.ca/scams-fraudes/extortion-extorsion-eng.htm"&gt;extortion calls&lt;/a&gt; impersonating government agencies as one of the highest-volume vectors targeting Canadians. Operators claiming to be from the Canada Revenue Agency, Immigration, Refugees and Citizenship Canada, or Service Canada threaten arrest, deportation, or status revocation unless the recipient pays an alleged debt by gift card, cryptocurrency, or wire transfer. CISA-tracked variants extend into &lt;a href="https://www.secureworld.io/industry-news/cisa-warns-phone-scammers"&gt;phone scammers impersonating&lt;/a&gt; federal-agency employees, sharing infrastructure with Canadian operations.&lt;/p&gt; 
&lt;p&gt;A long-tenure resident knows the CRA does not call to demand gift-card payment. A recipient who arrived six months ago often does not, an awareness gap documented in &lt;a href="https://www.canada.ca/en/revenue-agency/campaigns/fraud-scams.html"&gt;CRA's fraud communications&lt;/a&gt;.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Settlement-workflow scams: fake jobs, fake rentals, fake consultants&lt;/p&gt; 
&lt;p&gt;Settlement scams piggyback on the workflow a newcomer has to complete in their first months. Fraudulent rental listings demand first-and-last month's rent before the prospective tenant has seen the unit, then disappear once the wire clears. Fake employers conduct sham interviews and request banking credentials or upfront equipment fees. Unlicensed immigration consultants charge for services they cannot legally provide; the &lt;a href="https://college-ic.ca/protecting-the-public/find-an-immigration-consultant"&gt;licensing college&lt;/a&gt; is the only body authorized to license them, yet unlicensed operators advertise heavily in newcomer-facing channels.&lt;/p&gt; 
&lt;p&gt;Per-incident exposure is often larger here than in authority-impersonation hits. A fraudulent rental can cost a family several thousand dollars in displaced deposits. A fraudulent employment scheme can lead to money-mule conscription, where the newcomer's account becomes a transit point for laundered funds. FINTRAC's &lt;a href="https://fintrac-canafe.canada.ca/guidance-directives/transaction-operation/indicators-indicateurs/fin_mltf-eng"&gt;suspicious-transaction indicators&lt;/a&gt; flag the patterns inside the bank, not on the customer's phone.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Investment and "pig-butchering" schemes via diaspora messaging apps&lt;/p&gt; 
&lt;p&gt;The third vector is the fastest growing in dollar terms. Romance and investment scams, including the typology commonly called pig butchering, accounted for the &lt;a href="https://antifraudcentre-centreantifraude.ca/annual-reports-2024-rapports-annuels-eng.htm"&gt;largest share&lt;/a&gt; of CAFC-reported losses in 2024. The pattern relies on long-form rapport built over messaging apps before the financial ask materializes. Diaspora messaging communities are a high-yield acquisition channel: the social trust signals that protect long-tenure residents are thinner for someone who arrived 14 months ago. Small initial transfers establish a transactional rhythm, the larger investment ask follows, and the funds move before the cohort-level signal reaches the bank.&lt;/p&gt; 
&lt;h4 style="font-weight: normal;"&gt;The structural gap&lt;/h4&gt; 
&lt;p&gt;Bank fraud-detection models lean on transaction-pattern baselines: typical merchants, counterparties, and geographic footprint. SecureWorld has covered how &lt;a href="https://www.secureworld.io/industry-news/fraud-is-now-a-competitive-issue"&gt;machine learning baselines&lt;/a&gt; treat normal activity as the reference point and flag deviations as potential fraud. That works for a customer with three years of stable behavior. For a newcomer in month four, the model has no baseline; everything reads as a deviation, signal-to-noise collapses, and two failure modes follow. Legitimate transactions get flagged, friction accumulates, analysts deprioritize the segment. Or actual fraud gets buried inside the same noise floor.&lt;/p&gt; 
&lt;p&gt;The thin-file problem compounds this. &lt;a href="https://www.equifax.ca/personal/education/credit-score/articles/-/learn/credit-tips-for-canadian-newcomers/"&gt;Equifax newcomer research&lt;/a&gt; documents that recent arrivals carry no Canadian credit history for the first several months, leaving identity-verification models without an anchor. &lt;a href="https://risk.lexisnexis.com/about-us/press-room/press-release/20240327-tcof-retail-ecommerce"&gt;LexisNexis fraud-loss analysis&lt;/a&gt; finds a substantial share of total fraud loss occurs during account opening. The highest-risk window for newcomers is the precise window where bank defenses have the least signal.&lt;/p&gt; 
&lt;p&gt;FINTRAC's &lt;a href="https://fintrac-canafe.canada.ca/guidance-directives/transaction-operation/str-dod/str-dod-eng"&gt;suspicious-transaction reporting threshold&lt;/a&gt; flags deviation from an established profile, which again presupposes one. Language access compounds the problem: the CAFC's reporting portal operates primarily in English and French, with limited intake in the other languages newcomers most often arrive speaking.&lt;/p&gt; 
&lt;p&gt;The infrastructure was built for a long-tenure customer base and works well for that base. The gap sits between the model's assumptions and the demographic shape of who is being targeted.&lt;/p&gt; 
&lt;h5 style="font-weight: normal;"&gt;What security and fraud teams should build, and measure&lt;/h5&gt; 
&lt;p&gt;Three program-design moves would close the largest part of the gap. Each is testable against a metric a fraud-operations team can actually move.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Cohort-aware detection thresholds&lt;/p&gt; 
&lt;p&gt;Treat thin-file and recent-arrival profiles as their own segment with their own baseline expectations, rather than running them through general-population anomaly models. The LexisNexis account-opening finding is the practical anchor: weight the first 90 to 180 days differently and lean on alternate identity signals (telecom, rental, utility) that &lt;a href="https://newsroom.transunion.ca/transunion-partners-with-nova-credit--to-improve-financial-access-for-new-canadians/"&gt;TransUnion's newcomer programs&lt;/a&gt; already supply. Measure by false-positive rate on legitimate transactions and true-positive rate on first-90-day fraud attempts.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Multi-language reporting flows&lt;/p&gt; 
&lt;p&gt;The 5 to 10 percent reporting rate is the number to move. Expanding bank and CAFC intake into the top non-official languages spoken by recent arrivals directly addresses the underreporting concentration. Measure by reporting rate among newcomer-cohort incidents against the general-population rate.&lt;/p&gt; 
&lt;p style="font-weight: bold;"&gt;Cross-institutional intel sharing on diaspora-targeted typologies&lt;/p&gt; 
&lt;p&gt;Individual bank fraud teams see fragments of each typology; they rarely see the full pattern crossing six institutions in a week. SecureWorld has covered the &lt;a href="https://www.secureworld.io/industry-news/fs-isac-and-cyber-threat-alliance-agreement"&gt;FS-ISAC partnership&lt;/a&gt; with the Cyber Threat Alliance as one such pipeline. Extending that model to carry CAFC and FINTRAC signals on newcomer typologies back to bank fraud-ops in near-real-time would let cohort-level signals get acted on at speed.&lt;/p&gt; 
&lt;p&gt;Each move is incremental, not infrastructural, and none requires new regulation. They require a fraud-program owner to name the cohort and instrument the work against it.&lt;/p&gt; 
&lt;h6 style="font-weight: normal;"&gt;A loss ledger that will keep underreporting itself&lt;/h6&gt; 
&lt;p&gt;As long as fraud-prevention infrastructure treats newcomers as anomalies inside a general-population model rather than as a named cohort with their own typology, the published loss number will keep understating exposure. The 38 percent victimization rate Scotiabank found in 2024 will not surface in the CAFC's annual total without intake infrastructure that segments for the cohort generating it.&lt;/p&gt; 
&lt;p&gt;The most actionable next step is also the smallest. Pull the last 24 months of fraud cases and count how many involved customers in their first 24 months in Canada. The answer is the program brief.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Fnewcomers-canada-fraud-victims&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Cyber Fraud</category>
      <category>Featured Author</category>
      <category>Online Scams</category>
      <category>Canada</category>
      <pubDate>Tue, 19 May 2026 15:06:00 GMT</pubDate>
      <guid>https://www.secureworld.io/industry-news/newcomers-canada-fraud-victims</guid>
      <dc:date>2026-05-19T15:06:00Z</dc:date>
      <dc:creator>Pierre Raymond</dc:creator>
    </item>
    <item>
      <title>Why the Iranian Gas Station Exploits Mark a Kinetic Turning Point</title>
      <link>https://www.secureworld.io/industry-news/iranian-gas-station-exploits</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://www.secureworld.io/industry-news/iranian-gas-station-exploits" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.secureworld.io/hubfs/Blog%20Images/gas-pumps-1596622.jpg" alt="gas station pumps" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;For years, the cybersecurity community has warned that the line between a digital nuisance and a kinetic threat is razor-thin. That boundary has blurred further with the news that U.S. officials suspect Iranian-linked hackers are behind a series of coordinated cyber breaches targeting Automatic Tank Gauge (ATG) systems and fuel management technology at gas stations across multiple U.S. states.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;For years, the cybersecurity community has warned that the line between a digital nuisance and a kinetic threat is razor-thin. That boundary has blurred further with the news that U.S. officials suspect Iranian-linked hackers are behind a series of coordinated cyber breaches targeting Automatic Tank Gauge (ATG) systems and fuel management technology at gas stations across multiple U.S. states.&lt;/p&gt;  
&lt;p&gt;By exploiting internet-exposed devices sitting online without password protection, the attackers were able to alter data on displayed fuel quantities. While the intrusions did not trigger a nationwide shutdown or manipulate the actual physical fuel levels, the campaign represents a highly strategic, low-barrier-to-entry assault on downstream operational technology (OT) and industrial control systems (ICS). It is a stark reminder that in 2026, the digital battlefield has moved directly into civilian view.&lt;/p&gt; 
&lt;p&gt;The technical reality of this breach is as frustrating as it is alarming: attackers used simple, automated reconnaissance tools to discover exposed ATGs that lacked basic password security.&lt;/p&gt; 
&lt;p&gt;ATGs are specialized industrial controllers that silently monitor fuel levels, pressure, and temperature in underground storage tanks. Because these devices are frequently treated as back-office equipment rather than critical infrastructure, they are often connected directly to the internet—or worse, hosted on the same guest Wi-Fi networks used by retail customers. This creates an enormous, poorly monitored attack surface.&lt;/p&gt; 
&lt;p&gt;While changing numbers on a display screen sounds like a minor nuisance, the underlying operational risk is massive. Manipulating tank parameters or blinding operators to real-world data strips away the baseline visibility required to run hazardous physical environments safely.&lt;/p&gt; 
&lt;p&gt;Traditionally, energy sector security focuses heavily on upstream assets—pipelines, refineries, and major distribution hubs. This campaign exposes a critical asymmetric strategy: adversaries don't need to knock out a major pipeline to destabilize a nation; they can target the highly-distributed, under-resourced downstream retail nodes.&lt;/p&gt; 
&lt;p&gt;The most severe immediate risk is the concealment of environmental hazards. &lt;span style="line-height: 1.15;"&gt;If a hacker alters tank readings or disables automated system alarms, an operator could remain completely unaware of a catastrophic underground fuel leak or pressure imbalance.&lt;br&gt;&lt;/span&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;Manipulated telemetry can trick fuel delivery systems.&lt;/span&gt; &lt;span style="line-height: 1.15;"&gt;An automated or manual distributor relying on false data could overfill an underground tank, leading to surface spills, flash fires, or toxic contamination.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;ATGs do not sit in a complete vacuum.&lt;/span&gt; They are increasingly integrated into broader point-of-sale (POS) systems, inventory databases, and centralized logistics networks. Compromising an edge device creates an active bridge for lateral movement, potentially allowing attackers to pivot into pump operations or completely halt local fuel distribution&lt;/p&gt; 
&lt;p&gt;For the general public, this incident marks a transition into what security analysts describe as the "gray zone" of modern conflict—where the goal is not immediate physical destruction&amp;nbsp;but the slow erosion of public trust and operational stability.&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;You do not need to physically destroy a gas pump to cause a crisis.&lt;/span&gt; If consumers believe that display readings are untrustworthy or that fuel access is volatile, it could trigger&amp;nbsp;panic-buying and artificial shortages.&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;If retail operators are forced to disconnect their monitoring systems from the network and revert to manual dipstick measurements to verify fuel levels, logistics slow down dramatically.&lt;/span&gt; In an economy already facing supply chain friction and fluctuating fuel costs, a slowdown in distribution translates directly to economic stress.&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;This attack targets civilian infrastructure far removed from typical military objectives.&lt;/span&gt; It proves that the public is no longer just a bystander in geopolitical conflicts; their daily transactions and local utilities are actively being leveraged to create operational leverage.&lt;/p&gt; 
&lt;p&gt;The campaign serves as a final warning for the engineering and defensive communities: the "hustle hard" era of manual IT oversight is insufficient for highly-distributed OT environments.&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;Default credentials and unauthenticated internet exposure are completely unacceptable.&lt;/span&gt; Organizations must audit their entire footprint to ensure no industrial controllers are directly discoverable via public scanning tools.&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;Protectors of critical infrastructure should implement strict network segmentation.&lt;/span&gt; ATGs and fuel management systems must be completely isolated from corporate IT and public Wi-Fi networks, using secure, out-of-band remote access architectures.&lt;/p&gt; 
&lt;p&gt;Cybersecurity teams should&amp;nbsp;not rely solely on the data displayed by a single system. Implement behavior-based monitoring tools that cross-reference physical operations with digital telemetry, flag anomalous adjustments to tank geometry, and catch data manipulation at machine-speed.&lt;/p&gt; 
&lt;p&gt;Attackers frequently leverage compromised identity paths or social engineering to find these systems. &lt;span style="line-height: 1.15;"&gt;Securing the workforce identity layer—ensuring strict multi-factor authentication (MFA) and access verification for utility field technicians and vendors—is paramount.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;We asked experts from cybersecurity solution providers for their thoughts on this not-so-new hack.&lt;/span&gt;&lt;/p&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;&lt;span style="font-weight: bold;"&gt;Louis Eichenbaum, Federal CTO at ColorTokens, said:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"This incident should serve as an important warning to every critical infrastructure operator in the United States. While no physical damage was reported this time, the implications are far more serious than simply manipulating fuel gauge readings on a screen."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"Operational Technology (OT) environments rely heavily on Human Machine Interfaces (HMIs) and monitoring systems to give operators accurate situational awareness. If an adversary can compromise those systems and present false data, operators can be tricked into making dangerous decisions based on inaccurate information."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"In a gas station environment, manipulated tank readings could potentially lead an operator to overfill a tank, fail to detect a leak, or improperly manage pressure and fuel distribution systems. In other OT environments such as water treatment facilities, pipelines, manufacturing plants, or energy infrastructure, false telemetry could have even more severe consequences ranging from environmental damage to safety incidents and operational outages."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"The larger issue is that many of these OT systems were never designed with cybersecurity in mind. They were built for reliability and availability, not to withstand modern nation-state cyber threats. Unfortunately, many remain internet-facing, poorly segmented, and inadequately monitored."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"This is exactly why the cybersecurity conversation must move beyond prevention alone. We are never going to patch fast enough or prevent every intrusion. The focus now must be on resilience, assuming an adversary may gain access and ensuring they cannot move laterally or manipulate critical operations at scale."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"Granular microsegmentation and Zero Trust principles are essential in OT environments because they help contain breaches, restrict unauthorized communications, and reduce the blast radius when a compromise occurs. The goal is not simply to stop every attack&amp;nbsp;but to ensure that a localized intrusion does not become a catastrophic operational event."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"What makes this incident particularly concerning is that it demonstrates how relatively unsophisticated compromises of exposed OT systems can create the conditions for real-world physical consequences. Today, it was false tank readings. Tomorrow, it could be manipulated safety systems, disrupted fuel distribution, or compromised industrial controls."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;John Gallagher, Vice President of Viakoo Labs at Viakoo, said:&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"Malicious hackers will often target OT&amp;nbsp;and IoT systems because, unlike IT systems, they often were not planned with cybersecurity in mind, they are not managed by IT professionals, and they are spread far and wide unlike IT systems inside data centers."&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"Because these are fuel pumps operated by gas stations and fuel distributors, it is also likely their network access is not managed well. How many are on the gas station guest Wi-Fi system versus being strictly controlled and monitored on separate networks?"&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"It's unknown how many 'test runs'&amp;nbsp;Iranian hackers have performed, or the depth of their intrusions.&amp;nbsp;Ideally, if there was a quick and lightweight method of scanning that could be performed by fuel system operators to discover indicators of compromise, we would have a better sense of the scale of this issue."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"To mitigate these risks, fuel system operators should urgently review their network setup remove or block external network access. In addition, the manufacturers of fuel systems should be providing guidance on key basic cyber hygiene requirements: how to set up MFA, how to update firmware, how to change passwords, and so forth."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;"These functions don't require manual changes to each gas pump (which would take forever and still leave these systems vulnerable); automated methods for firmware, password, and other security functions can make all fuel system operators capable of maintaining a strong cyber defense."&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;span style="line-height: 1.15;"&gt;&lt;span style="font-weight: bold;"&gt;Vincenzo Iozzo, CEO and Co-founder at SlashID, said:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;"Unfortunately, most OT&amp;nbsp;systems were designed without security in mind. This includes the inability to patch them promptly or monitor them. Large Language Models (LLMs) are likely going to make these attacks more frequent as they further reduce the skill level required to launch these attacks."&lt;/span&gt;&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;span style="line-height: 1.15;"&gt;&lt;/span&gt;"In the short term, the most effective approach we have to secure them is appropriate segmentation. Long term, these OT systems are some of the best candidates for architectural changes driven by LLMs."&lt;/p&gt; &lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The gas station breaches prove that cyber warfare is increasingly focused on public confusion and operational stress rather than quiet data theft.&lt;/p&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=2221756&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fwww.secureworld.io%2Findustry-news%2Firanian-gas-station-exploits&amp;amp;bu=https%253A%252F%252Fwww.secureworld.io%252Findustry-news&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Featured</category>
      <category>Critical Infrastructure</category>
      <category>Original Content</category>
      <category>Iran</category>
      <category>Operational Technology</category>
      <category>Oil &amp; Gas</category>
      <pubDate>Tue, 19 May 2026 12:48:03 GMT</pubDate>
      <author>CamS@secureworld.io (Cam Sivesind)</author>
      <guid>https://www.secureworld.io/industry-news/iranian-gas-station-exploits</guid>
      <dc:date>2026-05-19T12:48:03Z</dc:date>
    </item>
  </channel>
</rss>
