Cybersecurity News and Headlines

The Need for a Board-Level Definition of Cyber Resilience
NewsApr 15, 2026

The Need for a Board-Level Definition of Cyber Resilience

Cyber resilience is now a board‑level governance priority, yet its definition varies across regulatory frameworks, leaving directors uncertain about oversight responsibilities. A literature review of 38 sources shows the concept is still fragmented, with divergent views on scope and relationship...

By CSO Online
5 Best Practices for Balancing Security and Data Privacy at Facilities
NewsApr 15, 2026

5 Best Practices for Balancing Security and Data Privacy at Facilities

Facilities generate massive streams of security data—from video feeds to access logs—making privacy and security inseparable concerns. The article presents five best practices: continuous cybersecurity hygiene, privacy‑by‑design technology choices, clear internal data‑governance policies, digital evidence management systems, and a responsible...

By Facilities Management Advisor
Ivanti Neurons ITSM Vulnerabilities Could Allow Session Persistence
NewsApr 15, 2026

Ivanti Neurons ITSM Vulnerabilities Could Allow Session Persistence

Ivanti disclosed two medium‑severity flaws—CVE-2026-4913 and CVE-2026-4914—in its Neurons for IT Service Management platform affecting versions up to 2025.3. The first vulnerability lets a remote authenticated user retain access after account deactivation, while the second is a stored XSS that...

By The Cyber Express
Italian Court Accepts Legal Action Over Facebook Mass Breach
NewsApr 15, 2026

Italian Court Accepts Legal Action Over Facebook Mass Breach

An Italian court in Milan has accepted a class‑action lawsuit against Meta Platforms over the 2018‑19 Facebook data‑scraping breach that exposed personal information of 533 million users worldwide, including tens of millions of Italians. The CTCU consumer association is pursuing compensation...

By Silicon UK
AI-Driven Threats Outpace Traditional Defences
NewsApr 15, 2026

AI-Driven Threats Outpace Traditional Defences

Qualys will showcase its Agent Val platform at the ITWeb Security Summit JHB 2026, highlighting how autonomous exploit validation and risk remediation can keep pace with AI‑driven attacks. The company’s ROC framework and Enterprise TruRisk Management aim to shift security from issue...

By ITWeb (South Africa) – Public Sector
Securing LA28 and Mega-Events From Attacks in the Era of Data Overload
NewsApr 15, 2026

Securing LA28 and Mega-Events From Attacks in the Era of Data Overload

Major upcoming events like Los Angeles 2028 (LA28) and the 2026 FIFA World Cup will draw millions of visitors, exposing a massive security challenge. The sheer volume of data—from CCTV, travel manifests, OSINT, and inter‑agency feeds—creates analysis paralysis for law‑enforcement teams. Interpol’s...

By Homeland Security Today (HSToday)
Samsung Electronics Seeks Police Probe Over Circulation of Non-Union Employee List
NewsApr 15, 2026

Samsung Electronics Seeks Police Probe Over Circulation of Non-Union Employee List

Samsung Electronics filed a criminal complaint and asked police to investigate after a list of non‑union employees was circulated internally. The list, shared via a group messaging channel, detailed names, identification numbers, departments and union membership status. Union leader Choi...

By The Elec – Semiconductors
Concurrent Technologies Corporation Awarded $21M Contract to Support Marine Corps Installations Command Cybersecurity Efforts
NewsApr 15, 2026

Concurrent Technologies Corporation Awarded $21M Contract to Support Marine Corps Installations Command Cybersecurity Efforts

Marine Corps Installations Command awarded Concurrent Technologies Corporation a $21 million multi‑year contract to deliver Facility‑Related Control Systems (FRCS) cyber services for the Pacific region. CTC, together with RMC Global, will design, implement, and certify a secure network that manages critical...

By Homeland Security Today (HSToday)
Banks Test Systems After Anthropic Mythos Warning
NewsApr 15, 2026

Banks Test Systems After Anthropic Mythos Warning

Anthropic warned that its new Claude Mythos model can autonomously discover and exploit vulnerabilities across major operating systems and browsers. The U.S. Treasury’s CIO, Sam Corcos, is seeking immediate access to run the model against federal systems. Wall Street banks have...

By Silicon UK
Gabon’s New Law Makes All Social Media Users Traceable
NewsApr 15, 2026

Gabon’s New Law Makes All Social Media Users Traceable

Gabon enacted a law ending online anonymity, forcing social‑media users to provide full personal details and imposing fines up to $89,000 for violations. In Lagos, emergency responders are using virtual‑reality simulations of the Lekki‑Ikoyi Bridge to practice high‑risk incidents without...

By Techpoint Africa
Avast Business and Avert IT Distribution Rewrite the SMB Cybersecurity Playbook
NewsApr 15, 2026

Avast Business and Avert IT Distribution Rewrite the SMB Cybersecurity Playbook

Avast Business and its African distributor Avert IT Distribution are revamping cybersecurity for small and mid‑size firms by delivering a unified, cloud‑managed security suite combined with education and channel support. The platform consolidates endpoint protection, patch management, remote access and...

By TechCentral (South Africa)
Deepfakes Are a Threat to Age Assurance, and Injection Attack Detection Is the Answer
NewsApr 15, 2026

Deepfakes Are a Threat to Age Assurance, and Injection Attack Detection Is the Answer

Yoti’s CEO Robin Tombs warned that deepfake‑generated media can undermine age‑assurance systems by exploiting post‑authentication injection attacks. Traditional liveness detection, while still essential, no longer blocks sophisticated AI‑crafted faces that are introduced after the initial login. Yoti proposes a multi‑layered...

By Biometric Update
Europe Builds Its First “Kill-Switch Proof” Cloud Recovery Stack
NewsApr 15, 2026

Europe Builds Its First “Kill-Switch Proof” Cloud Recovery Stack

At the European Data Summit, Cubbit, SUSE, Elemento Cloud and StorPool unveiled Europe’s first fully sovereign disaster‑recovery stack, designed to protect organisations from foreign‑vendor kill‑switches and other catastrophic events. The solution bundles storage, compute, orchestration and security components into a...

By Tech.eu – People
Enterprises Must Embed AI-Led Security, Resilience and Trust, as Cyber Strategies for 2026: KPMG
NewsApr 15, 2026

Enterprises Must Embed AI-Led Security, Resilience and Trust, as Cyber Strategies for 2026: KPMG

KPMG’s 2026 cybersecurity report calls on enterprises to treat security as a core business driver, integrating AI, geopolitics and regulation into every layer of their architecture. It stresses adaptive data governance, autonomous Security Operations Centers with human‑in‑the‑loop oversight, and centralized...

By ET EnergyWorld (The Economic Times)
Why Cloud Security Failures Continue to Expose Data and People to Unnecessary Cyber Risks
NewsApr 15, 2026

Why Cloud Security Failures Continue to Expose Data and People to Unnecessary Cyber Risks

Cloud security lapses continue to jeopardize critical data, especially for government agencies and their vendors. Recent incidents—including Conduent’s ransomware breach that exposed 25 million records and stole 8 TB, Snowflake’s credential‑theft affecting over 165 customers, Change Healthcare’s mis‑configured portal leaking 192.7 million health...

By Homeland Security Today (HSToday)
European Civil Servants Are Being Forced Off WhatsApp
NewsApr 15, 2026

European Civil Servants Are Being Forced Off WhatsApp

European governments—including France, Germany, Poland, the Netherlands, Luxembourg and Belgium—are replacing WhatsApp and Signal with home‑grown, sovereign messaging platforms for officials. The European Commission intends to complete its own messenger migration by the end of 2026. The move reflects growing...

By Politico Europe – Technology
Curity Looks to Reinvent IAM with Runtime Authorization for AI Agents
NewsApr 15, 2026

Curity Looks to Reinvent IAM with Runtime Authorization for AI Agents

Curity, a Swedish IAM vendor, launched Access Intelligence, a runtime authorization layer for AI agents. The solution extends its Identity Server with Token Intelligence, issuing purpose‑bound OAuth tokens for each agent action. Unlike static IAM, it grants permissions on‑the‑fly and...

By Computerworld – IT Leadership
Brennan Builds Solid Foundation for Onshore Cyber Security
NewsApr 15, 2026

Brennan Builds Solid Foundation for Onshore Cyber Security

Brennan, an Australian managed services provider, reported a roughly 20% uplift in services revenue after acquiring Canberra‑based cyber specialist CBR Cyber. The growth is driven by a surge in demand for onshore, sovereign security, highlighted by a 13% year‑on‑year rise...

By ARN (Australia)
Wireless Broadband Alliance Claims Wi-Fi Security on a Par with Cellular
NewsApr 15, 2026

Wireless Broadband Alliance Claims Wi-Fi Security on a Par with Cellular

The Wireless Broadband Alliance (WBA) released a new Wi‑Fi security framework that it says puts Wi‑Fi on equal footing with cellular networks in terms of security. The guidance consolidates standards such as WPA3, OpenRoaming (Passpoint) and RadSec, covering authentication, encryption,...

By iTnews (Australia) – Government
CoW Swap Domain Locked Due to Security Issue: CoW Swap
NewsApr 15, 2026

CoW Swap Domain Locked Due to Security Issue: CoW Swap

CoW Swap’s primary domain swap.cow.fi was locked on April 14 after a security incident, rendering the site inaccessible. The protocol quickly deployed a temporary UI at a new URL to maintain trading continuity. Users were warned to rely only on...

By The Defiant
Central Government yet to Notify Selection Panels for Data Protection Board
NewsApr 15, 2026

Central Government yet to Notify Selection Panels for Data Protection Board

The Indian government has still not formed the search‑cum‑selection committees needed to appoint a chairperson and four members to the Data Protection Board of India (DPBI), five months after the board’s statutory creation under the Digital Personal Data Protection (DPDP)...

By ET Telecom (Economic Times)
April Patch Tuesday Roundup: Zero Day Vulnerabilities and Critical Bugs
NewsApr 15, 2026

April Patch Tuesday Roundup: Zero Day Vulnerabilities and Critical Bugs

Microsoft’s April Patch Tuesday delivered 167 fixes, including a actively‑exploited SharePoint Server zero‑day (CVE‑2026‑32201) and a critical Windows IKE remote‑code‑execution flaw (CVE‑2026‑33824) with a 9.8 CVSS score. Additional high‑risk bugs affect Active Directory (CVE‑2026‑33826), TCP/IP stack (CVE‑2026‑33827) and SAP Business...

By CSO Online
A Data Removal Service Helped Me Reclaim My Privacy - See if You Need One, Too
NewsApr 15, 2026

A Data Removal Service Helped Me Reclaim My Privacy - See if You Need One, Too

Personal data is routinely harvested by thousands of data brokers and sold without consumer consent. Manual opt‑out requests are impractical, prompting the rise of paid data‑removal services such as PrivacyBee and DeleteMe. These platforms scan the web, submit takedown requests,...

By ZDNet – Big Data
OpenAI Expands Cybersecurity Program Before Deploying New Models
NewsApr 15, 2026

OpenAI Expands Cybersecurity Program Before Deploying New Models

OpenAI announced on April 14 that it is expanding its Trusted Access for Cyber (TAC) program, scaling it to thousands of verified security professionals and hundreds of enterprise teams. The rollout adds new identity‑verification tiers and introduces GPT‑5.4‑Cyber, a cyber‑permissive...

By PYMNTS
Like Anthropic, OpenAI Will Share Latest Technology Only With Trusted Companies
NewsApr 15, 2026

Like Anthropic, OpenAI Will Share Latest Technology Only With Trusted Companies

OpenAI announced a limited rollout of GPT‑5.4‑Cyber, an AI model that scans software for security flaws. The initial phase will reach hundreds of trusted partners, with plans to expand to thousands in the coming weeks. The approach mirrors Anthropic’s recent...

By The New York Times – Technology
Patch Tuesday's a Monster: Thank AI?
NewsApr 15, 2026

Patch Tuesday's a Monster: Thank AI?

Microsoft’s April Patch Tuesday delivered 247 patches covering 164 vulnerabilities, including eight critical flaws and two actively exploited zero‑days in SharePoint and Chromium. Security researcher Joe Desimone reported that all five of his local‑privilege‑escalation bugs were discovered using AI, highlighting...

By The Stack (TheStack.technology)
Amplify Care Offers AI Cybersecurity Training
NewsApr 15, 2026

Amplify Care Offers AI Cybersecurity Training

Amplify Care has launched an "AI and Cybersecurity" course within its Shield Training program, aimed at Canadian physicians navigating AI‑driven clinical systems. The offering combines expert‑led instruction with up to 12.5 Mainpro+ continuing education credits, addressing a sector where 64%...

By Canadian Healthcare Technology
Evolving Cyber Risk Driven by User Credentials and Human Error
NewsApr 14, 2026

Evolving Cyber Risk Driven by User Credentials and Human Error

Marlink’s Cyber Intelligence Report for Remote Operations 2026 reveals a decisive shift toward identity‑based cyber threats across maritime, energy, enterprise and critical‑infrastructure sectors. The study, based on continuous SOC monitoring and over 200 security assessments, finds that 69% of observed risks...

By MarineLink
Cybercriminals Now Increasingly Targeting Government Organizations, Report Reveals
NewsApr 14, 2026

Cybercriminals Now Increasingly Targeting Government Organizations, Report Reveals

Kaspersky’s 2025 threat report shows government entities accounted for 19% of high‑severity breaches, making them the top target, while industrial firms followed at 17%. The IT sector rose to third place with 15% of serious incidents, pushing finance out of...

By Crowdfund Insider
Microsoft Adds Windows Protections for Malicious Remote Desktop Files
NewsApr 14, 2026

Microsoft Adds Windows Protections for Malicious Remote Desktop Files

Microsoft rolled out new Windows defenses against RDP‑phishing attacks in the April 2026 cumulative updates for Windows 10 (KB5082200) and Windows 11 (KB5083769, KB5082052). The changes introduce a one‑time educational prompt and a persistent security dialog that disables all resource redirections by default....

By BleepingComputer
Microsoft Ends Desktop Detour for Sensitivity Labels in Office Web Apps
NewsApr 14, 2026

Microsoft Ends Desktop Detour for Sensitivity Labels in Office Web Apps

Microsoft has updated Office for the web to let users apply sensitivity labels with custom permissions directly in Word, Excel and PowerPoint. The new Permissions dialog mirrors the desktop experience, enabling the assignment of Viewer, Editor or Owner roles without...

By Help Net Security
Anthropic Mythos Prompting Calls for More Security Measures
NewsApr 14, 2026

Anthropic Mythos Prompting Calls for More Security Measures

Anthropic unveiled its cybersecurity‑focused large language model, Mythos, under Project Glasswing, granting limited access to select vendors and enterprises. The model can ingest code and automatically surface exploitable vulnerabilities, prompting warnings from Federal Reserve Chair Jerome Powell and Treasury Secretary...

By AI Business
N-Able CEO: MSPs Must Shift To AI-Driven Cyber Resiliency As Agents Ramp Up
NewsApr 14, 2026

N-Able CEO: MSPs Must Shift To AI-Driven Cyber Resiliency As Agents Ramp Up

N‑able CEO John Pagliuca warned that managed service providers (MSPs) must adopt AI‑driven cyber‑resiliency as thousands of autonomous agents outpace human capacity. He likened resilience to health‑tracking wearables, emphasizing outcomes over jargon and urging a full‑stack, end‑to‑end experience. To enable...

By CRN (US)
Tax Season Scams 2026: How IRS Phishing, Fake Tax Messages, and AI Fraud Threaten Businesses
NewsApr 14, 2026

Tax Season Scams 2026: How IRS Phishing, Fake Tax Messages, and AI Fraud Threaten Businesses

The 2026 tax season is seeing a surge in sophisticated scams that blend traditional IRS impersonation with AI‑generated messages, QR‑code links, and polished phishing campaigns. Microsoft reported over 29,000 users in 10,000 organizations targeted by tax‑related phishing, while a February...

By ERP Today
Why We Chose the Harder Path: Docker Hardened Images, One Year Later
NewsApr 14, 2026

Why We Chose the Harder Path: Docker Hardened Images, One Year Later

One year after launching Docker Hardened Images (DHI), Docker reports over 500,000 daily pulls and more than one million builds, with a catalog exceeding 2,000 hardened images, Helm charts, and system packages across Debian and Alpine. The DHI Community tier...

By Docker – Blog
Privilege Elevation Dominates Massive Microsoft Patch Update
NewsApr 14, 2026

Privilege Elevation Dominates Massive Microsoft Patch Update

Microsoft’s April 2026 Patch Tuesday addressed a near‑record 165 CVEs, with elevation‑of‑privilege bugs comprising a record 57% of the fixes. Attackers are already exploiting a SharePoint spoofing zero‑day (CVE‑2026‑32201), while another high‑severity flaw (CVE‑2026‑33825) in Defender antimalware remains unexploited but...

By Dark Reading
Microsoft Discloses ‘Monstrous’ Number Of Bugs As AI Discoveries Surge: Researcher
NewsApr 14, 2026

Microsoft Discloses ‘Monstrous’ Number Of Bugs As AI Discoveries Surge: Researcher

Microsoft’s April Patch Tuesday released 163 CVEs, the second‑largest monthly batch in its history. TrendAI researcher Dustin Childs attributes the surge to AI‑driven vulnerability discovery, noting that AI‑generated submissions have roughly tripled. The release follows Anthropic’s claim that its upcoming...

By CRN (US)
Claude Mythos: Prepare for Your Board’s Cybersecurity Questions About the Latest AI Model From Anthropic
NewsApr 14, 2026

Claude Mythos: Prepare for Your Board’s Cybersecurity Questions About the Latest AI Model From Anthropic

Anthropic unveiled Claude Mythos Preview, its most powerful frontier AI model, capable of autonomously discovering software vulnerabilities that have evaded human researchers. The Federal Reserve’s upcoming meeting with bank CEOs highlights growing board-level concern over AI‑driven cyber risk. Organizations are...

By Security Boulevard
Invicti Launches DAST-to-SAST Correlation
NewsApr 14, 2026

Invicti Launches DAST-to-SAST Correlation

Invicti announced a new DAST-to-SAST correlation feature that links runtime vulnerability scans with static code analysis. The capability maps verified DAST findings to exact source‑code lines, developer ownership, and remediation steps within a single workflow. By overlaying results on a...

By AI-TechPark
FDA Tightens Its Medical Device Cybersecurity Guidance for Manufacturers
NewsApr 14, 2026

FDA Tightens Its Medical Device Cybersecurity Guidance for Manufacturers

The FDA has issued updated cybersecurity guidance for medical devices through Section 524B, imposing stricter lifecycle security requirements. Manufacturers must now provide a software bill of materials, manage component risks, and adopt secure development processes. The guidance forces hospitals, federal agencies...

By HealthTech Magazine
Are US Businesses Ready for Privacy Fragmentation? Why E-Commerce and Marketing Teams Are Now on the Front Line
NewsApr 14, 2026

Are US Businesses Ready for Privacy Fragmentation? Why E-Commerce and Marketing Teams Are Now on the Front Line

U.S. privacy regulation is fragmenting as new state laws in Indiana, Kentucky and Rhode Island join existing statutes, forcing businesses to embed compliance into front‑end digital experiences. E‑commerce and marketing teams now execute consent, targeting and analytics rules that vary...

By Total Retail
Review: Box Facilitates Secure Collaboration Across Campus
NewsApr 14, 2026

Review: Box Facilitates Secure Collaboration Across Campus

Box’s cloud‑based content management platform now offers a full suite of collaboration tools, workflow automation, e‑signatures and AI‑driven features for universities. The service integrates with more than 1,500 SaaS applications, allowing seamless file sharing across Microsoft 365, Google Workspace and...

By EdTech Magazine (Higher Ed)
Microsoft Drops Its Second-Largest Monthly Batch of Defects on Record
NewsApr 14, 2026

Microsoft Drops Its Second-Largest Monthly Batch of Defects on Record

Microsoft’s April Patch Tuesday addressed 165 vulnerabilities, the second‑largest monthly release in the company’s history. The update includes an actively exploited zero‑day in Office SharePoint (CVE‑2026‑32201) and a high‑severity Defender flaw (CVE‑2026‑33825) with public exploit code. Trend Micro’s Dustin Childs...

By CyberScoop
4 Questions to Ask Before Outsourcing MDR
NewsApr 14, 2026

4 Questions to Ask Before Outsourcing MDR

Security teams face relentless alerts, staffing gaps and rising expectations for uptime, making Managed Detection and Response (MDR) a strategic necessity rather than a luxury. Outsourcing MDR provides round‑the‑clock monitoring across endpoints, identities and cloud workloads, ensuring threats are spotted...

By CSO Online
EDR-Killer Ecosystem Expansion Requires Stronger BYOVD Defenses
NewsApr 14, 2026

EDR-Killer Ecosystem Expansion Requires Stronger BYOVD Defenses

The ecosystem of EDR‑killer tools that exploit bring‑your‑own‑vulnerable‑driver (BYOVD) techniques has expanded dramatically, with researchers cataloguing nearly 90 distinct killers. Although only about 35 vulnerable Windows drivers are actively abused, each can be re‑hashed thousands of times, complicating blocklist defenses....

By Dark Reading
State Department Cyber Leader: AI Must Serve Mission Outcomes, Not Drive Them
NewsApr 14, 2026

State Department Cyber Leader: AI Must Serve Mission Outcomes, Not Drive Them

At the Splunk GovSummit 2026, State Department Security Operations Center chief Manuel Medrano warned that artificial intelligence must serve mission outcomes, not become the objective. He outlined how AI is already sharpening cyber monitoring and incident response across the department’s...

By FedTech Magazine
5 Trends Defining the Future of AI-Powered Cybersecurity
NewsApr 14, 2026

5 Trends Defining the Future of AI-Powered Cybersecurity

The N‑able and Futurum report outlines how AI is reshaping cybersecurity, turning generative models into both attack tools and defensive assets. Attackers now automate phishing, vulnerability scanning and exploit delivery at machine speed, forcing security teams to abandon static, perimeter‑based...

By CSO Online
Malware Campaign Lures Users with Fake Windows Update Website
NewsApr 14, 2026

Malware Campaign Lures Users with Fake Windows Update Website

Malwarebytes uncovered a new campaign that lures French‑speaking Windows users to a counterfeit Windows Update page. The site offers a fake Windows 11 24H2 update packaged as a Windows Installer (MSI) built with the legitimate WiX Toolset. When run, the MSI installs...

By TechSpot
Space Force Official Touts AI’s Impact on Cyber Compliance
NewsApr 14, 2026

Space Force Official Touts AI’s Impact on Cyber Compliance

Space Force acting cyber chief Seth Whitworth says large language models are reshaping how the service reviews cyber risk and achieves compliance. He highlighted that AI can automatically patch minor misconfigurations that often serve as entry points for state‑sponsored actors....

By CyberScoop