Authorities seize KillSec leak site, identify 16-year-old as suspected leader
The German-led international operation secured at least 110 terabytes of data and led to three provisional arrests in an investigation into roughly 1,000 suspected attacks worldwide.

SPONSORED POST
AI might accelerate cybercrime, but it won’t make cybercriminals smarter
The fear of AI-supercharged cybercrime is outrunning the evidence. A top threat researcher explains why defenders still hold the advantage, as long as they don't outsource their own thinking.
As increasingly powerful AI technology – including open-weight Chinese systems along with bootleg, black market bundles of various frontier AI models – makes its way into the hands of cybercriminals, fears of AI-enabled widespread attacks are starting to run ahead of the evidence that would substantiate these kinds of attacks.
Last week I caught up with one top analyst of the cybercrime marketplace, Selena Larson, principal threat researcher and lead, intelligence analysis and strategy at Proofpoint, who made the case in an interview that while AI can amplify cybercriminals’ hacking expertise, it doesn’t automatically make inexperienced and low-level threat actors adept at sophisticated operations.
“This idea of everyone has access to AI, so they're all really good threat actors, is not true,” Larson said. “It has made good threat actors maybe more productive. But it's having basically the same impact that it has on defenders.”
Slick pages, blank emails
In her work, Larson has discovered that AI can indeed allow threat actors to generate slick phishing pages, which, as it turns out, are often undercut by those same actors fumbling the ball by sending blank emails or embedding QR codes that don’t work, raising doubts about whether AI can improve low-level attackers’ overall effectiveness.
“Because these threat actors are using AI and using LLMs to try and improve their efficacy, they're actually doing things that they don't have experience with, so they're leaving these gaps,” Larson said. “That provides opportunities for defenders, because then we can just go look at this phishing page and see all this information that they definitely don't want us to see.”
However, this expertise gap doesn’t mean cybercriminals aren’t marginally improving their skill sets using AI. “Now with AI, it's probably decreasing their development time,” Larson said. “It might be improving how quickly they can spin up operations, probably helping them create and build things like their backend tooling and stuff like that."
But, she added, it's not as if cybercriminals are deploying innovative techniques. “They're fundamentally doing the same things," she said. "They're still creating malware; they're still developing these panels. They're still creating the botnet, still working with customers. It's just maybe cutting down the time that they're doing it.”
But low-level and inexperienced cybercriminals frequently make operational mistakes that undermine their other AI-enabled efforts, such as those polished phishing pages. With cybercriminals, “We've seen exposed panels, so basically everything is visible to an unauthenticated user,” Larson said. “You don't even have to log in. You inspect source, and you see everything that they don't intend for you to see.”
Don't outsource the analysis
When it comes to a toe-to-toe match, Larson sees cyber defenders besting cybercriminals time and again, but she warns defenders not to outsource their own thinking to AI. “People who are good at their jobs are using AI to get better at their jobs, and they're not using it to replace themselves,” she said.
“A core tenet of cyber threat intelligence is analytical thinking and developing how you think, asking the right questions of data, and finding new information and new ways of looking at things,” she added. “Unfortunately, AI isn't quite there yet. I think there is some risk that we run into outsourcing our analytical thinking to something that is only looking backward.”
One step to avoid outsourcing analysis is to ensure that there is always a human in the loop. “We run the risk, if there's no human in the loop, of falling into a trap of, ‘Well, the AI said it, so it must be true,’" Larson said. “I think [AI] is hugely beneficial for productivity, but you still need to maintain your skillset and maintain that fact-checking and the core tenets of cyber threat research, making sure that the outputs are correct. Make sure that you are not outsourcing your skills to a robot.”
Bots can't replace the junior analyst pipeline
Larson also issued a cautionary note that defenders shouldn’t rely on AI agents as if they are junior analysts because the industry still needs junior analysts to cut their teeth on basic security skills to make their way through the pipeline to becoming senior analysts.
Agents are great for “the junior analyst tasks, but eventually, you need a trained analyst to do triage and to prioritize and do the decision-making and make sure that you're looking at the correct data and that it's accessing only things that it needs to be accessing,” she said. “You still need that background or that knowledge. You lose that when you are replacing junior levels with bots.”
Proofpoint sponsored this article. Metacurity retained sole editorial control, including the choice of angle, questions, analysis, final wording, and publication timing.
According to Europol, on 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorized access.
The action was part of Operation KillSwitch, an international investigation led by German authorities into around 1,000 suspected attacks worldwide. Investigators identified a 16-year-old as the group’s suspected main operator. Three suspects were provisionally arrested and eight properties searched in Greece, Romania, Spain, and the United Kingdom. Authorities also targeted the group’s criminal proceeds.
KillSec stole sensitive data by exploiting vulnerabilities and poorly secured access points to organizations’ systems. Around 500 of the suspected attacks have so far been identified as successful. This figure may change as investigators examine the evidence seized during the operation.
The operation was led by the Hamburg State Criminal Police Office and the Hamburg Public Prosecutor’s Office. Authorities from Belgium, Finland, Germany, Greece, the Netherlands, Romania, Spain, Switzerland, the United Kingdom, and the United States took part in the investigation, alongside Europol and Eurojust. The investigation was also supported by the private cybersecurity companies Bitdefender and Group-IB.
Authorities in several countries began investigating attacks attributed to KillSec in early 2025. The international investigation identified suspects believed to have taken on different roles within the group, including an administrator, a developer, a negotiator, and an affiliate.
The alleged administrator and main operator is 16 years old. A suspected developer turned 18 in August 2026 and was a minor when some of the offenses were committed. Investigators also identified one person believed to be in a negotiator role and another in an affiliate role. Inquiries into other possible members are continuing. (Europol).

The US Federal Trade Commission is investigating Anthropic and OpenAI to determine whether they deceived consumers about the potential harms of their artificial intelligence.
The probe was opened recently, and the agency plans to send civil subpoenas to the two companies in the coming weeks, a senior FTC official said. The need for an investigation became apparent over the summer as the agency heard concerns, some of them aired publicly, from AI researchers who say the technology could wipe out humanity, the official said.
The FTC’s subpoenas will seek company documents as well as testimony from AI executives and information from METR, the official said. The investigation was first reported by the New York Post.
Trump said this week that US law enforcement and current laws are sufficient to address any misconduct stemming from the use of AI for nefarious purposes.
The FTC has broad consumer-protection powers that allow it to investigate companies for unfair or deceptive acts or practices. Those cases generally focus on businesses that misled consumers about important aspects of how their products work or how they charge fees.
FTC Chairman Andrew Ferguson has been a proponent of fostering American AI advancements and says he worries that new regulations would create legal barriers that only could be met by the biggest tech companies, squeezing out smaller players. (Dave Michaels / Wall Street Journal)
Related: Reuters, Associated Press, Washington Post, The New York Times, CNBC, Bloomberg, ABC News, Axios, Silicon Angle
Two investigative analyses by AI security research firms reached compatible but differentiated conclusions regarding AI agents’ attempts to circumvent access restrictions and probe websites for vulnerabilities while pursuing seemingly routine data-gathering tasks.
First, AI research firm Transluce said AI agents tried to hack into a Canadian government website, casting the effort as a failed hacking attempt, while Canada said there were no indications its systems were compromised.
Transluce said the attempts exhibited tactics "consistent with prior observed agent activity that we have attributed to OpenAI in a similar timeframe." But it added that it was not confidently attributing these attempts to OpenAI.
The agents attempted to access Library and Archives Canada on May 28 and June 9, Transluce said. Transluce said it disclosed the action to the Canadian government on September 28.
The Canadian Centre for Cyber Security said it was aware of reports of suspected AI agent activity. "There is no indication that government systems have been compromised at this time," it said in a statement.
Separately, Asymmetric Security spent 48 hours investigating reported rogue OpenAI agent activity that targeted the Australian government and other organizations between March and September this year, using only publicly available data.
Asymmetric found successful access to staging environments; evidence of the use of attacker reconnaissance tactics; and evidence of probing a broader set of websites, including those of the CDC, SEC, International Energy Agency, and Mayo Clinic.
Asymmetric also uncovered novel tactics that enabled agents to gain full web access despite the constraints of their sandbox. Some of these tactics left records erased or inaccessible, making it impossible to rule out access to sensitive data based on public information alone.
The activity suggests that the agents were originally tasked with researching public health and other data, possibly as part of an evaluation.
Asymmetric further found evidence of searches for health and prescription statistics from the Australian Institute of Health and Welfare (AIHW); trade figures from the UN’s Trade and Development Body (UNCTAD); and university statistics from Data USA. When the agents struggled to retrieve information, they used external services to circumvent the intended limitations of their sandbox.
Asymmetric cautioned that the public records alone did not establish whether the agents intended to conceal their activity. (Kanishka Singh, Christian Martinez, Deepa Seetharama and Akanksha Khush / Reuters and Asymmetric Security)
Related: Transluce, Ars Technica, Al Jazeera, Associated Press, Futurism, Financial Times, The Next Web, Gizmodo, Financial Times

Google is unveiling its long-awaited next-generation AI model, Gemini 4 Argon, to a small group of cybersecurity partners.
Gemini 4 arrives after a long gap at the top of Google's model lineup, in which the company kept rolling out smaller, cheaper Flash models while rivals OpenAI and Anthropic sprinted forward.
Google says Gemini 4 Argon is built to handle complex, long-running tasks in software engineering, finance, legal work and cybersecurity.
It also said the new model is state of the art on certain coding and knowledge work benchmarks, outperforming OpenAI's competing frontier model, GPT-6 Astra, on several.
The company is rolling the model out only to a group of trusted cybersecurity defenders and is participating in the US government's voluntary prerelease process.
Google stated it will expand access after additional testing, with paying subscribers first in line. (Madison Mills / Axios)
Related: Google, The Information, Finimize, VentureBeat, MarketWatch, TechCrunch, Moneycontrol, Decrypt, Pulse 2.0, Agence France-Presse, Ars Technica, Constellation Research, Barron's Online, Reuters, CNBC, Business Insider, Financial Times, RuntimeWire, Digital Trends, iPhone in Canada, CNBC, 9to5Google, Forkast, SiliconANGLE, TestingCatalog AI News, Investor's Business Daily, XDA Developers, Unite.AI, The New Stack, The Deep View, Hacker News, r/GeminiAI, r/singularity, r/rust, r/GeminiAI, Slashdot, CSO Online
Matthew Green, cryptographer and professor at Johns Hopkins University, argues that sandboxing, while a necessary step to contain AI agents from escaping to the internet and causing mayhem, cannot by itself stop the agents from causing harm because agents who stay in the sandbox can still obey malicious instructions through legitimate channels.
Green says that instructions embedded in email, Slack, or shared documents could hijack agent behavior. If agents pass those instructions to other agents, that could enable a spreading prompt-injection worm.
The recent round of frontier labs' failures to contain their agents might be attributable to poor infrastructure and unclear authority rather than the impossibility of containing agents in sandboxes, Green argues. (Matthew Green / Cryptography Engineering)
Related: Simon Willison's Weblog
The website used by ShinyHunters, the group that claimed responsibility for a recent hack of thousands of FBI agents' personal and sensitive data, went offline on Wednesday, a day after the group's deadline for the FBI to retract or modify a statement about the group's tactics and track record expired.
The hackers said they targeted the FBI in response to a May 2026 FBI advisory about the group that the hackers felt misrepresented their prior actions. They gave the FBI a week to either "correct or simply REMOVE" the advisory.
The advisory remains online. ShinyHunters later said it had no intention of publishing the data it stole and that it accomplished its goals.
The FBI said on September 23 that it was "actively and aggressively investigating" the breach. The agency declined to comment on Wednesday on whether it had taken any actions to force the hackers' site offline. Brett Leatherman, assistant director of the FBI's Cyber Division, urged the hackers in a video published on the agency's website on September 29 to get in touch with the FBI "while the choice is still yours." (AJ Vicens / Reuters)
Researchers at Proofpoint report that Chinese hackers have been impersonating US AI experts, including a former government official, to try to steal emails from experts in AI at think tanks, universities, and other organizations.
Proofpoint said that it had watched the hackers — which it dubs "TA419" — regularly try to steal passwords from people working for US or Japanese think tanks, defense contractors, universities, and law firms since as far back as 2025.
Proofpoint attributed the hacking efforts to the Chinese group based on the types of malware the group used, the internet infrastructure used to carry out the attacks, and the targets it observed the group focusing on, which align with Chinese intelligence collection priorities.
Proofpoint said the hackers' recent campaign involved writing emails purporting to come from experts in AI or statecraft, including Lynne Parker, who previously worked as the principal deputy director of the White House's Office of Science and Technology Policy. Proofpoint said the emails would typically propose AI-themed collaborations or initiatives before steering targets toward password-stealing websites.
Proofpoint declined to name the hackers' targets, saying only that the latter included "experts working on AI regulation, export controls and national AI strategy."Reuters was independently able to identify one of them: Alex Engler, a former White House official who now heads the Penn Center on Media, Technology, and Democracy.
Engler told Reuters on Wednesday he had received an email appearing to come from Parker inviting him "to join a new AI policy project." But he said the email "felt slightly, nebulously off" and, after he checked with others in the field, he realized he was dealing with an impostor.
Engler said he could not speculate about why someone would try to hack him, but Proofpoint said that its view of the targeting — which involved fewer than 10 individuals working for a handful of organizations — suggested "an intelligence interest in US policymaking rather than technology theft alone."Parker told Reuters that Engler was one of two people who received suspicious messages purporting to come from her in early July. She added that the allegation of Chinese involvement made sense. (Raphael Satter / Reuters)
Related: Proofpoint, The Edge, NewsBytes, Straits Times, CNN, NextGov/FCW

Mark Chen, OpenAI's chief research officer, said the company's infamous Hugging Face incident triggered a welcome course correction for the industry.
Chen claims that the drumbeat of new cases in which OpenAI has lost control of its models reflects a deliberate choice on the company’s part.
“When it comes to the broader sphere of effects of the Hugging Face incident, this is something that we have been aware of, and we’re figuring out the process of disclosure,” he says. “We want to make sure we do in-depth investigations before we just put details out there in the open.”
The trouble with this approach is that it gives the impression OpenAI has an ongoing problem that it is failing to fix.
But Chen insists that OpenAI is on it. He says the multiple cases (that we know of so far) in which his company’s agents broke containment and behaved in unexpected and undesirable ways were all part of the same cluster of activity in May and June that led to the Hugging Face hack. In short, you can blame the same few models running under the same flawed testing procedures—models and procedures that OpenAI has since dropped, Chen says.
“It’s not like, you know, Hugging Face happened and we patched that and then something else happened and we patched that,” he adds. “We’re just kind of making sure that we responsibly disclose the full waterfall of what happened.”
At least that was the case before Friday’s announcement that OpenAI’s agents had been caught accessing the internet on September 20, weeks after the company claims to have set up new safeguards. In its defense, OpenAI says the activity was flagged 15 minutes after it started (it took the company more than a week to notice the Hugging Face hack) and that this shows the new systems it has put in place to spot such activity are working. (Will Douglas Heaven / MIT Tech Review)
Related: Associated Press
Metacurity is the cybersecurity news, analysis, and insight you'd need hours and possibly days to assemble yourself.
Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.
A paid subscription to Metacurity delivers
- Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
- Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
- Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
- Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.
Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.
Please consider supporting us. And thank you!
Researchers at Truffle Security report that more than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform’s security measures to prevent accidental leaks of sensitive data.
Data pulled from scanning 224 million repositories and more than 58 billion files show that the median time a unique credential remained publicly accessible was 784 days.
Truffle found that about 10% of the working credentials were older than 6.3 years and the oldest one dated from 2009.
In total, the researchers identified 543,699 unique credentials that appeared repeatedly across more than 1.1 million files and repositories, including copies in forks.
The assessment was conducted on a dataset assembled to train large language models, based on a crawl that closed on August 7, 2025. (Bill Toulas / Bleeping Computer)
Related: Truffle Security, Cyber Security News

Researchers at Huntress report that custom variants of OpenAI’s ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.
The threat actor is abusing the legitimate feature in the AI platform that lets users create a version of ChatGPT tailored for a specific task that combines instructions, extra knowledge, and skills.
OpenAI hosts these custom GPTs, which can be published for others to install and use. The company plans to retire custom GPTs on December 11.
The malicious campaign was identified by Huntress, a managed detection and response (MDR) company, whose researchers say it affected dozens of users.
The threat actor named the malicious GPT model 'Plus 5.6' and configured it to direct users to an alleged backup site hosted on Google Sites.
However, the page shows a fake Cloudflare check and instructs visitors to run a PowerShell command, which deploys the infection chain.
Huntress says it investigated at least 40 incidents connecting to the Google Sites page but confirmed that only two involved a custom GPT variant.
OpenAI took down the first GPT by September 25. Two days later, on September 27, the researchers found a second GPT linked to the same campaign, which was still active when they published their report. (Bill Toulas / Bleeping Computer)
Related: Huntress, Gigazine, Infosecurity Magazine, Android Authority, Gigazine, Security Affairs, IT Security Guru, SC Media, Cyber Security News

The US Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition.
Tracked as CVE-2026-84411, the security issue is a pre-authentication integer underflow in RouterOS’s web-management HTTP request handling.
CISA says that a single crafted request can produce code execution with root privileges or denial of service.
“The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication,” reads the alert.
“This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request.”
Although the agency has no knowledge of the vulnerability being actively exploited, it released the advisory to alert organizations of the risk and to provide defensive measures. (Bill Toulas / Bleeping Computer)
Related: CISA, Cyber Security News, GBHackers, Cyber Press
Vulnerability disclosures doubled between January and August, reaching a new peak of 10,740 last month, Google’s Threat Intelligence Group (GTIG) said.
Total vulnerability disclosures began the year at 5,045 in January and had jumped to more than 10,000 for July and August.
“We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered,” the researchers said.
They noted that beyond the overall number of bugs being found, the number of distinct vulnerabilities disclosed and exploited during the eight months surpassed the totals for all of 2025. There have already been 141 exploited vulnerabilities this year after 127 last year.
GTIG said the increase in vulnerability exploitation in 2026 “is driven by the rapid, targeted weaponization of high-risk exploits in the wild rather than a flood of new zero-days.” Zero-days are vulnerabilities that are exploited before they are known to vendors, and n-days are vulnerabilities that have been patched and publicly disclosed.
The researchers found that hackers are getting better at using artificial intelligence to scan patches and exploit critical bugs. Kelli Vanderlee, senior analyst at GTIG, said they expect that AI-assisted vulnerability discovery and exploitation will continue to grow in the short-to medium-term. (Jonathan Greig / The Record)
Related: Google Threat Intelligence Group, IT Pro, Help Net Security, Silicon Angle

The Arizona Supreme Court announced Friday that the state’s court system was attacked by hackers who stole the personal information of “many Arizonans.”
Arizona Supreme Court Chief Justice Ann Scott Timmer said in a statement that the state court system was targeted by criminal hackers “or their bots.”
“Court leaders believe the criminal hackers copied personally identifiable information about many Arizonans,” Timmer said. “The Supreme Court’s Administrative Office of the Courts is in the process of alerting as many people as possible whose information it believes the criminal hackers copied.”
A spokesperson for the court system said that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
Timmer said the court would not release further details about the incident because they may impact the investigation into the attack. (Jonathan Greig / The Record)
Related: AZCourts.gov, AZ Family, KVOA, Malwarebytes, KJZZ, The Record, AZ Central
Korea's Shinhan Bank apologized after personal information belonging to about 25,000 customers was leaked in a data breach, as financial regulators launched an urgent inspection into the incident.
According to the bank, the leaked information includes customers' names, phone numbers, annual income and loan eligibility limits, as well as other personal and credit information submitted for loan applications.
The data also included 66 cases involving resident registration numbers and 97 cases involving connected information.
The breach occurred as an unauthorized external party gained access to some of its services through an abnormal method that bypassed authentication.
Shinhan Bank CEO Jung Sang-hyuk apologized and said the bank will take full responsibility for any losses.
Shinhan said it activated an emergency response team immediately after detecting the breach and took a series of measures, including blocking external IP addresses and suspending affected services.
It said it will conduct a review of its personal information protection system, improve security policies and strengthen employee training to prevent similar incidents.
The bank has also set up a dedicated page on its website where customers can check whether their information was leaked. The feature is also available on the bank's mobile app. A dedicated call center has been established to handle reports related to the data breach.
The bank's announcement came as financial regulators launched an urgent investigation into the incident.
The Financial Supervisory Service (FSS) conducted an on-site inspection of Shinhan Bank after receiving a report from the bank that some customer information related to loan applications had been leaked.
The FSS and the Financial Services Commission held an emergency meeting to discuss the circumstances surrounding the breach and follow-up measures. (Lee Hyo-jin / The Korea Times)
Related: Anadolu Ajansi, KED Global, Aju Press, ChosunBiz, Seoul Economic Daily, Korea JoongAng Daily
Spyware maker Paragon Solutions CEO Andrew Boyd spoke in detail about his secretive company and its handling of the Italian affair and its handling of a scandal involving two contracts it had with Italy’s domestic and foreign intelligence agencies.
According to Boyd, Paragon has no technical way to know if customers misuse its software, because it can’t see who customers target or the data they extract from targeted devices. It can only learn about misuse if customers admit to it or third parties uncover it. He says WhatsApp and Citizen Lab did the company a great service when they exposed the alleged misuse last year.
Paragon also doesn’t have a “kill switch” to disable customers when misuse occurs. All they can do is halt customers’ 24-hour support and system “updates.” But Boyd says the updates, the nature of which he won’t specify, are frequent and essential to using the spyware, and without them the system is rendered ineffective in about 12 hours.
Without the ability to monitor customer activity and detect misuse, Paragon relies on its governance model to prevent abuse. Boyd contends Paragon doesn't want its products to be involved in things that they weren't intended to be used for.
The customer vetting, Boyd says, “usually works 99 out of 100 times” to eliminate those who might misuse their tools – the assumption being that if they choose only reputable customers, the customers they choose will act only reputably. (Kim Zetter / Wired)
Alex Stamos has joined Cognition as the AI coding unicorn's new chief security officer.
Stamos says he's joining Cognition to not only help defend the company from cyberattacks, but also to help it ship new security products.
Cognition is the maker of Devin, an autonomous AI software engineering tool that can write and ship code, debug programs, run commands, and more. Customers include Mercedes-Benz, the US Army and AT&T.
Most recently, he oversaw security at AI security startup Corridor and SentinelOne. (Sam Sabin / Axios)
Cybersecurity startup Armadin has raised $255.5 million to boost the production of artificial-intelligence agents trained to pinpoint security flaws cybercriminals are most likely to exploit—in part by attacking its customers with swarms of autonomous hackers.
The Series B funding round was co-led by Andreessen Horowitz and Accel, with participation from new investors Bain Capital Ventures (BCV) and Redpoint. Existing investors 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures also returned. (Angus Loten / Wall Street Journal)
Related: PR Newswire, Help Net Security, Pulse 2.0, Reuters
Best Thing of the Day: South Dakota Will Become Cyber Aware
The annual cyber awareness season, namely Cybersecurity Awareness Month, has received an official seal of approval from South Dakota, where Governor Larry Rhoden has proclaimed October as Cybersecurity Awareness Month in South Dakota.
Worst Thing of the Day: The US Has Joined Russia in Meddling in Brazil's Election
Brazil's spy agency, "confirmed the existence of interference from the United States as well as Russia," according to a report of the meetings compiled by an attendee.
Bonus Worst Thing of the Day: Brit Chicks Fall Behind in Cyber
The proportion of workers in the UK cybersecurity industry identifying as women has dropped to 16 percent, the lowest level since 2021.
Extra Bonus Worst Thing of the Day: Who Needs Free and Fair Elections Anyway?
State election officials said that renewed federal cybersecurity assistance comes too late for some of their midterm preparations, following cuts they say disrupted support from the Cybersecurity and Infrastructure Security Agency.
Closing Thought
