Cybersecurity Saturday

From the frontier AI front,

  • The Wall Street Journal reports,
    • Nvidia NVDA is planning to use a $6 billion deal it struck this week [August 22] to build one of the world’s most powerful open-weight AI models, one that would compete with Chinese heavyweights like DeepSeek and Kimi K3, according to people familiar with the matter.
    • “The chip giant’s licensing deal with the AI startup Poolside is also set to present a direct challenge to frontier U.S. AI companies including OpenAI and Anthropic, since open-weight models are generally far cheaper to operate and allow easy customization.
    • “Although Nvidia counts big labs like OpenAI and Anthropic as some of its closest partners, the move reflects Chief Executive Jensen Huang’s efforts to position Nvidia for success in multiple AI battlegrounds simultaneously, ensuring the company is able to hold on to its dominant market position.”
  • and
    • Nvidia and CrowdStrike are addressing what they see as one of cybersecurity’s biggest gaps: the need for cyber defenders to harness AI at the velocity of cyber attackers.
    • In the current cyber landscape, frontier AI models are discovering bugs at machine speed—raising alarm bells among experts, who warn that when autonomous hacking models go rogue or attack companies, chaos is on the horizon.
    • But cyber defenders aren’t getting enough of that same AI firepower, according to Nvidia and CrowdStrike, who on Tuesday [September 1] introduced a new family of agentic AI models, dubbed SafeMind, which can both find attack paths and close them for customers. The models are available in CrowdStrike’s flagship Falcon platform and through its API. * * *
    • “SafeMind has two models: Red Tempest, which is an “offensive” model that emulates AI adversaries, and Blue Solano, which is a “defensive” model designed to fix identified issues. The two models are connected by software called a harness, which runs the models in a closed-loop system that pits them against each other for self-improvement.”
  • The New York Times reports,
    • “Nvidia said on Thursday [September 3] that it is buying Hugging Face, a library of open artificial intelligence models, for $12.9 billion, as the chipmaker extends a spending spree in the escalating global race to dominate the technology.
    • “The deal marries Nvidia’s chip and data center infrastructure with Hugging Face’s millions of open-source A.I. models that can be freely downloaded and modified. And it puts Nvidia’s deep pockets firmly on one side of a debate over how A.I. systems should be built.
    • “Together, we will make A.I. more open, more capable and more accessible to people and institutions around the world,” wrote Jensen Huang, the chief executive of Nvidia, in a blog post.
    • “The acquisition is also another sign of Nvidia’s growing role as Silicon Valley’s central banker, using its vast financial resources to bolster A.I. start-ups and funnel money to customers for its chips. With $197 billion in current assets and nearly $60 billion in profits from its most recent quarter, the Silicon Valley giant has been spending heavily on A.I.”
  • Daniel Borish writing in LinkedIn lets us know,
    • Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 this week, positioning them as its most capable models yet for coding and knowledge work. The two are the same underlying model, split only by the safeguards wrapped around them. Fable 5.1 is generally available. Mythos 5.1 is restricted to vetted cybersecurity and life sciences professionals through trusted access programs run in partnership with the US government.” * * *
    • “On the cybersecurity side, Claude Code users should see roughly 60% fewer safeguard interventions per session, and Fable 5.1 can now be used to find software vulnerabilities, though not to write exploits for them. Tasks like penetration testing, exploit generation, and binary-based vulnerability scanning still route to Anthropic’s Opus models. On biology, updated safeguards reportedly fire 85% less often on benign medical and elementary biology questions, though research-grade life sciences queries still get redirected to Opus, and full access to Mythos 5.1’s biology capabilities is limited to the government-linked Life Sciences Verification Program.
    • “Anthropic’s safety testing found Mythos 5.1 better aligned than its predecessor on several measures it tracks: less likely to seek resources outside its assigned environment when given an impossible task, less likely to reason its way around explicit constraints, and less likely to attempt or succeed at reward hacking. The company also disclosed limits to that picture, noting its behavioral audits have less visibility into very long-context work, multi-agent settings, and testing found the model can still sometimes bypass approval steps and automated review classifiers.
    • “Fable 5.1 also ships with new anti-distillation measures. New API accounts created from launch onward can no longer edit Claude’s prior context in a conversation while preserving the model’s recorded thinking, closing off a publicly documented technique used to extract that thinking at scale.”
  • The Wall Street Journal adds,
    • Anthropic has signed a cloud-computing deal worth $35 billion with NvidiaNVDA 3.21%increase; up pointing triangle-backed cloud provider Lambda, with Nvidia itself holding the lease on the data center, according to people familiar with the deal. 
    • The data center is being developed by Hut 8, a bitcoin miner and data-center developer, in Nueces County, Texas. Nvidia signed an agreement with Hut 8 a few weeks ago to secure the capacity, the people said. 
    • The convoluted arrangement is another example of Nvidia’s growing role in helping non-investment-grade firms such as Anthropic get access to its expensive computing resources. The deal also helped a nascent cloud provider, Lambda, secure a lucrative contract with Anthropic without needing to procure the data-center space on its own. 
    • Lambda will use the data center Hut 8 is developing to plug in chips bought from Nvidia, which is also its investor. It is not clear how much Lambda will pay Nvidia to access the data-center space.
    • Anthropic has been racing to sign cloud-capacity deals after hitting a supply crunch earlier this year that coincided with its products gaining traction. The AI developer signed a $45 billion deal earlier this month with another Nvidia-backed neocloud, Nscale, to rent Nvidia capacity from its West Virginia site, according to people familiar with the deal. 
  • Security Week relates,
    • OpenAI said its newest model, Astra, has reached the ‘Critical’ cybersecurity capability level under the company’s Preparedness Framework, the first time any of its models has been placed in that category. 
    • The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems, or carry out a complete cyberattack against a hardened target from only a high-level instruction. OpenAI said the classification requires additional safeguards before the model can be released.
    • In testing described by the company, Astra achieved a perfect score on ExploitBench, a benchmark that measures a model’s ability to turn known vulnerabilities into working exploits. During a separate evaluation involving more recently disclosed flaws, Astra uncovered two zero-day vulnerabilities on its own. 
    • The model also broke out of a browser sandbox to run commands on the underlying machine, and separately chained several flaws in a hardened operating system to gain root-level access.
    • OpenAI reported that Astra now declines 91.5% of cyber-related jailbreak attempts in its testing, up from 59% for its predecessor, GPT-5.6 Sol. The company also said Astra showed far less tendency than Sol to bypass safety restrictions or take advantage of deliberately placed “honeypot” targets during evaluations. 
    • Full cybersecurity capabilities will not be widely available at launch. OpenAI plans to give a group of testers early access, with wider availability to follow through its Daybreak Blue program.
  • Cybersecurity Dive adds,
    • “OpenAI on Thursday [September 3] said it would commit $1 billion in subsidized access and training to help small IT security teams use frontier AI to protect essential services, including electricity, water and local government services. 
    • “The Daybreak for Frontline Defenders program will be used to help defenders search for critical vulnerabilities in their software, hunt for suspicious activity in their technology stacks and stop malicious actions if hackers are able to gain access to their systems.
    • “OpenAI plans to roll out a six-month pilot program with the Multi-State Information Sharing and Analysis Center (MS-ISAC), which will train and support a group of water utilities and other public sector defenders.” 
  • Dark Reading points out,
    • “A new study suggests that while AI is rapidly accelerating vulnerability discovery, enterprise organizations are better equipped to handle the surge than generally assumed.
    • “The key is their ability to quickly validate findings, prioritize risk, and get available fixes into production.
    • “Software supply chain security firm Echo recently analyzed nearly 40,000 CVE life cycles across 250 open source container projects, drawing on a year of its own platform telemetry, survey responses from more than 80 security leaders, and an independent analysis of Anthropic’s Claude Mythos.
    • “The results, detailed in a report titled “Mythos Readiness Report,” show how AI is transforming vulnerability discovery and exploit development — something that security teams have been encountering firsthand over the past year.”
  • and
    • “With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses.
    • “On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic’s Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model’s capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target.
    • “In their evaluation, Mythos scored an 80, while the next-closest contender, SpaceXAI‘s Grok-4.5, scored a 49. However, the current standings are not as important as where we will be in six months, says Brad Medairy, president of Booz Allen’s National Cyber practice.
    • “Our view is there’s going to be some level of parity, at least between the frontier models and the Chinese models over probably a six-month horizon, and so everyone is in a rapid race to evolve these capabilities,” he says, adding that, when facing human attackers, defenders had the advantage, but “in the future, the balance of power shifts to the offense, because the attacker can deliver effects at speed and scale that the traditional defenses can’t keep pace with.”

From the cybersecurity policy and law enforcement front,

  • Federal News Network reports,
    • “Congress is kicking the can down the road again on a long term debate over reauthorizing the Cybersecurity Information Sharing Act of 2015.
    • “The continuing resolution passed by the House on Tuesday would extend CISA 2015 through the stopgap funding period into early December. The Senate has already passed the measure, meaning it now heads to President Donald Trump’s desk. [FEHBlog note: The President signed the continuing resolution into law on September 2.]
    • “There has been a persistent chorus of voices in industry calling on Congress to find a long-term solution to re-authorizing CISA 2015. Those calls have only grown louder amid advancements in artificial intelligence models and recent cyber attacks on critical infrastructure.
    • “The 2015 law provides privacy and liability protections to encourage companies to share data about cyber vulnerabilities and threats with government and each other. The information sharing law briefly lapsed during last fall’s shutdown and again earlier this year before being extended through Sept. 30.”
  • The Wall Street Journal points out,
    • “The U.S. Defense Department is expected to release its cyber plan as early as Tuesday, NextGov reported, citing people familiar with the matter. The plan is due to outline how the Pentagon will integrate cyber tactics into military strategy, emphasizing offensive actions, and address training requirements. The most recent Defense Department cyber strategy was issued in 2023.”
  • Per a CISA news release,
    • “CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.  
    • “The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:
      • “Raising awareness of quantum risks and the importance of PQC;
      • “Developing national strategies that support PQC adoption and integration;
      • “Advancing research and development for quantum-safe technologies;
      • “Fostering public-private partnerships to share expertise and resources; and
      • “Integrating PQC into cybersecurity requirements and procurement processes.” 
  • Cyberscoop relates,
    • “The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector.
    • “Project Watershed 250” is the first of the state-based, industry-centric pilot projects to cross the finish line that the Office of the National Cyber Director has previewedsince the publication of its national cybersecurity strategy earlier this year. Water systems have long been viewed as among the most vulnerable and neediest critical infrastructure sectors, and in recent months the sector has been the victim of a spree of attacks.
    • “Project Watershed 250 is a commitment from the states, industry and federal government that we will continue to prioritize our nation’s safety and deliver on America-first policies for the American people,” National Cyber Director Sean Cairncross said at a rollout event in San Antonio Monday.”
  • and
    • “Sen. Ron Wyden, D-Ore., is asking the National Security Agency to update public guidance on the security risks associated with commercial virtual private networks, and to answer questions about foreign surveillance threats against standard VPNs.
    • “In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn about standard, commercial VPNs, following letters to federal agency leaders in March and July.
    • “While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries,” Wyden wrote in the letter, first reported by CyberScoop. “Other, more secure alternatives are widely available.”
    • “Wyden took aim at “single-hop” VPNs that routes data through one server before arriving at the destination.”
  • Cybersecurity Dive tells us,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) is scaling back the free assessments it offers to critical infrastructure organizations, a move that marks a significant retreat from the agency’s core mission of helping secure the nation’s infrastructure.
    • “CISA’s regional staff will no longer perform its Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys, the agency confirmed to Cybersecurity Dive.”
  • and
    • “U.S. law-enforcement agencies and the cybersecurity firm CrowdStrike took down a 23-year-old Russia-based botnet on Monday.
    • “Authorities from the Justice Department, the FBI and the Defense Criminal Investigative Service seized U.S.-based domain namesbelonging to the Sality botnet, while CrowdStrike analysts worked with the agencies to sever infected computers from the botnet. Investigators in Bulgaria, Hungary and Romania also took down Sality domain names in their jurisdictions.
    • “Since 2003, Sality powered spam campaigns, credential-theft operations, distributed denial-of-service (DDoS) attacks and malicious proxy networks. In 2018, the botnet began deploying malware that hijacked cryptocurrency transactions by replacing copied wallet addresses with attacker-controlled ones.
    • “Sality “has been one of the most persistent threats on the internet, not because of its payloads but because of the robustness of its architecture,” CrowdStrike said in its report on the botnet’s takedown.”

From the cybersecurity breaches and vulnerabilities front,

  • Dark Reading reports,
    • “Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition (M&A) deals.
    • ‘It’s one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.
    • “Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition(M&A) deals.
    • “It’s one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.”
  • HelpNetSecurity relates,
    • “Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned.
    • “The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses a technique called “OAuth consent phishing,” has been ongoing since late 2025. The FBI describes it as “a deceptive, sophisticated approach to access user accounts without requiring a password.”
    • OAuth is a framework that lets one application request access to a user’s account on another service without the user handing over login credentials directly.
    • “Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor’s control,” the FBI wrote in its advisory.”
  • Dark Reading tells us,
    • “A coordinated operation has targeted at least 150 Microsoft Teams users across multiple companies with voice phishing (vishing) attacks aimed at installing remote monitoring and management (RMM) and malware tools onto their machines. The campaign also attempts in some instances to compromise organizations’ domain controllers.
    • “Researchers from Palo Alto Networks observed the operations — which they’ve dubbed “Spring Ring” — between January and April attacking employees across at least 10 organizations, according to a report published this week. The campaign illustrates a growing shift away from traditional email phishing toward attacks conducted through trusted enterprise collaboration platforms, which adds authenticity to the interaction.
    • “The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow,” Noam Sala, a Palo Alto Networks staff researcher, wrote in the post. “This shift moves the attack from a passive click-and-harvest model to a real-time engagement.”
  • The Cybersecurity and Infrastructure Security Agency added ten known exploited vulnerabilities to its catalog this week.
    • August 31, 2026
      • CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability 
      • CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability
        • The Hacker News discusses these KVEs here.
    • September 2, 2026
      • CVE-2026-9586 Sangoma Switchbox SQL Injection Vulnerability
      • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability 
      • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability 
      • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability 
      • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability 
      • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability 
      • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability 
        • Cybersecurity Dive discusses the SonicWall KVEs here.
        • ePlanetSecurity discusses the Sangoma KVE here.
        • AssurePort discusses the Kludex KVE here.
        • Sentinel One discusses the Kestra KVE here.
        • CSurface discusses the BerriAI KVE here.
        • Security Week discusses the JFrog KVE here.
      • September 4, 2026
        • CVE-2026-85046. Google Chromium V8 Type Confusion Vulnerability\
          • The Hacker News discusses the Google KVE here.
  • Security Week tells us,
    • “Anthropic has warned some Claude users that infostealer malware on their computers allowed attackers to hijack login sessions and run up usage limits, according to an email the company sent to affected customers. 
    • “The company said it detected the activity, signed out the compromised sessions, and removed saved payment methods from affected accounts as a precaution.
    • “Anthropic is alerting Claude AI users whose computers were infected with infostealer malware such as Vidar, Lumma, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of macOS devices.
    • “The AI giant emphasized that the malware is general-purpose and not tied to Claude itself, typically arriving via unofficial downloads or malicious apps.” 

From the ransomware front,

  • HIPAA Journal reports,
    • “Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks.”
  • The Register adds,
    • “US hospital operator Nutex Health says attackers stole private or confidential patient, employee, provider, business, and financial information during the cyberattack it disclosed last week.
    • “In an updated filing submitted to the Securities and Exchange Commission (SEC) on Monday, Nutex also said an unauthorized third party had threatened to publish the stolen information.” * * *
    • “Nutex did not identify the intruders. However, The Gentlemen ransomware-as-a-service (RaaS) operation added the company to its leak site on Monday and claimed responsibility for the attack.
    • “The gang offered no evidence or details to substantiate its claim. Naming victims on a leak site and threatening to publish their data is a standard pressure tactic in double-extortion attacks.”
  • InfoSecurity Magazine relates,
    • “Aurora ransomware actors have been observed abusing SpaceX’s AI Cursor Agent as part of exploitation campaigns, according to a new study by Gambit Security’s Threat Intelligence team.
    • “The threat actors ran Claude Sonnet through Cursor Agent to assist with various exploitation activities against 10 victims between April 8 and May 26, 2026.
    • “These tasks included scanning the victim’s environment for reconnaissance purposes, installing a VPN client and running certificate attacks.
    • “While Cursor Agent did not always achieve its stated objectives, the research demonstrated how threat actors are continuously experimenting with AI tools to speed up and enhance their campaigns.
    • “Cursor Agent is used by software developers to complete complex coding tasks independently, run terminal commands and edit code.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • Palo Alto PANW Networks swung to a loss in the fiscal fourth quarter, but posted higher revenue and projected double-digit revenue growth in the current fiscal year as customers continue to boost their cybersecurity spending in response to advancements in artificial-intelligence.
    • “The cybersecurity company on Tuesday [September 1] said it is expecting revenue to rise between 23% and 24% to $14.1 billion to $14.2 billion in fiscal 2027. Analysts polled by FactSet are expecting $13.84 billion in revenue.
    • “Chief Executive Officer Nikesh Arora said the results and outlook reflect growing recognition among enterprises that they need to modernize their cyber defenses to meet the capabilities of ever-more-powerful AI models, especially following the release of Anthropic’s Mythos earlier this year.
    • “In that context, people are gravitating towards the largest players in the industry and looking at us to provide the antidotes to this development in AI,” Arora said in an interview.”
  • and
    • Zscaler ZS posted a narrower loss after revenue rose 25% in its fiscal fourth-quarter, as artificial intelligence helps drive demand for its cybersecurity offerings.
    • The San Jose, Calif.-based company also said it would restructure and cut 3% of its workforce as it reallocates resources to support its AI and growth initiatives.
    • Zscaler on Thursday [September 3] reported a loss of $3.37 million, or 2 cents a share, compared with a loss of $17.6 million, or 11 cents a share, a year earlier.
    • Adjusted earnings were $1.19 a share. Analysts were looking for $1.09 a share, according to FactSet.
  • and
    • Blackstone is placing an early bet on Huskeys, a cybersecurity startup building an artificial intelligence gatekeeper to protect companies from the growing chaos of automated web traffic.
    • “The firm’s early-stage venture-capital arm, Blackstone Innovations Investments, led a $27 million Series A investment that values the year-old company at more than $100 million.
    • “The deal makes Blackstone the second-largest outside investor in Huskeys, behind Israeli venture-capital firm 10D, according to a Huskeys representative. So far, investors have put $35 million into the startup.
    • “Other backers in the most recent transaction include the investment arm of publicly traded cybersecurity company Zscaler and Bright Pixel Capital, the venture arm of Portuguese retailer Sonae.
    • “New York-based Huskeys was founded in Tel Aviv in 2025 by Itai Gafni and Roy Weisfeld, veterans of the Israeli army’s elite Unit 8200 cybersecurity division. Gafni is Huskeys’ chief executive and Weisfeld is its chief technology officer.”
  • Tech Crunch offers a tip
    • “How to find cyber-risk data sources for a FAIR analysis
      • “Cyber-risk quantification with FAIR can change the game for CISOs — but sourcing enough accurate data for analysis can feel impossible. Learn how and where to find it.”
      • “The Factor Analysis of Information Risk (FAIR) model is a widely respected, mathematically based open standard for CRQ that enables CISOs to translate cyber-risk into financial risk. One of the biggest challenges of using the FAIR model, however, is that its analytical output is only as good as its data inputs — and finding accurate data to feed the model is not always easy or intuitive.”
  • Per a CISA news release,
    • “Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts. 
    • “CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis. Changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to help end users minimize operational impact, limit speculation, and preserve trust. For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and understand the type of communication they should expect from their service providers.”
  • Cyberscoop explains why judgment is emerging as cybersecurity’s defining skill.
  • Here’s a link to Dark Reading’s CISO Corner.

Leave a Reply

Your email address will not be published. Required fields are marked *