Visualização normal

Antes de ontemCybersecurity News
  • ✇Firewall Daily – The Cyber Express
  • US Puts $10 Million Bounty on Alleged Iranian Cyber Chief Samiksha Jain
    The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers
     

US Puts $10 Million Bounty on Alleged Iranian Cyber Chief

7 de Setembro de 2026, 02:51

$10 Million Reward for Amir Yaryab

The U.S. State Department has posted a $10 million reward for Amir Yaryab, a senior Iranian official accused of leading the Islamic Revolutionary Guard Corps Cyber-Electronic Command (IRGC-CEC) Cyber Operations Command and directing multiple hacking groups targeting critical infrastructure across the United States, Europe and the Middle East. According to the Rewards for Justice program, Yaryab allegedly oversees cyber operations conducted by IRGC-CEC-affiliated groups including CyberAv3ngers, Dadeh Afzar Arman (DAA) and Mehrsam Andisheh Saz Nik (MASN). U.S. officials accuse these groups of using malware and conducting cyber and cyber-enabled information operations against civilian infrastructure worldwide.

$10 Million Reward for Amir Yaryab

The $10 million reward for Amir Yaryab seeks information leading to his identification or location. The offer applies to individuals acting at the direction or under the control of a foreign government who participate in malicious cyber activities against U.S. critical infrastructure in violation of the Computer Fraud and Abuse Act. [caption id="attachment_113961" align="aligncenter" width="600"]$10 million reward for Amir Yaryab Image Source: https://rewardsforjustice.net/[/caption] Yaryab is also accused of directing Shahid Hemmat and Shahid Shushtari, two groups linked to cyberattacks against U.S. organizations. The sectors allegedly targeted include defense, news, shipping, travel, energy, financial services and telecommunications. The six Iranian officials named in the advisory are linked to Iran's Islamic Revolutionary Guard Corps and its Cyber-Electronic Command.

Iranian Cyberattacks Target PLCs

The allegations also involve attacks against programmable logic controllers (PLCs), highlighting concerns around Iranian cyberattacks targeting industrial systems rather than focusing only on data theft. U.S. officials said Iranian-linked hackers compromised industrial control systems, specifically targeting the Vision series of PLCs manufactured by Israel-based Unitronics. These devices are used across water and wastewater, energy, food and beverage, manufacturing and healthcare sectors. The attackers exploited default credentials on the devices and left anti-Israel messages. Some of the compromises reportedly rendered the PLCs inoperative. The CyberAv3ngers group, which is linked to the IRGC-CEC, claimed responsibility for attacks against Unitronics Vision PLCs in October 2023. Beginning in November 2023, the group compromised default credentials in PLCs across the United States and left messages on the devices' digital screens.

CyberAv3ngers Attacks Critical Infrastructure

CyberAv3ngers has also claimed responsibility for attacks affecting other infrastructure. In October 2023, the group claimed it had breached ORPAK Systems, a provider of gas station solutions in Israel. The group said it had obtained the company's database and intended to publish it through its Telegram channel. The attack was reported to have disconnected 200 gasoline pumps from the system in the occupied Palestinian territories. In December 2023, CyberAv3ngers also claimed to possess and sell 1TB of data allegedly linked to Israel's electricity infrastructure. The group advertised the dataset for 5 Bitcoin, with an initial 100GB portion also offered at the same price.

U.S. Agencies Warn of PLC Cyberattacks

Concerns over critical infrastructure attacks involving PLCs continued into 2026. A joint advisory issued on April 7 by the FBI, CISA, NSA and other agencies warned that Iran-linked threat actors were actively exploiting internet-facing PLCs. The advisory said several organizations had experienced operational disruptions and financial losses after attackers interfered with industrial processes. The developments come amid broader U.S. actions against Iranian-linked cyber activity. The Justice Department accused Iran-connected hackers of breaching employee email accounts associated with the Department of Labor, the Federal Energy Regulatory Commission and multiple United Nations organizations. The Treasury Department also sanctioned Iranian nationals over cyberattacks targeting critical infrastructure. The State Department's reward offer places Amir Yaryab and the alleged activities of IRGC-CEC-linked groups at the center of the U.S. effort to identify individuals responsible for malicious cyber activity targeting critical infrastructure.

The Password Notebook Is Back — but Is It Actually Safer?

25 de Agosto de 2026, 15:18

Password notebooks are making an unexpected comeback as infostealers and browser attacks revive debate over the safest way to store credentials.

The post The Password Notebook Is Back — but Is It Actually Safer? appeared first on TechRepublic.

  • ✇Security | CIO
  • CIO 100 Award winners spotlight IT’s power to transform
    Each year the CIO 100 Awards showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers. The 2026 cohort of winners is no different. Each one demonstrates how IT executives and their teams successfully move from ideation to deployment to scaling a solution for the future, overcoming challenges and driving adoption along the way to en
     

CIO 100 Award winners spotlight IT’s power to transform

10 de Agosto de 2026, 07:01

Each year the CIO 100 Awards showcase outstanding IT initiatives, and every year they illustrate the power and potential of technology to transform how people work, how organizations perform, and the value they offer to customers.

The 2026 cohort of winners is no different. Each one demonstrates how IT executives and their teams successfully move from ideation to deployment to scaling a solution for the future, overcoming challenges and driving adoption along the way to ensure their organization gets a return on its investment.

[ Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards & Conference in Frisco, TX. Limited seats remain! Register here ]

The winning initiatives come from a range of industries and utilize a host of technologies to achieve their goals, as is the case annually. A growing proportion of these stand-out projects leverage artificial intelligence, raising the bar on the art of the possible for all IT departments.

The following 10 award-winning projects serve as representatives for the outstanding work done by all the 2026 honorees.

ABB democratizes AI agent creation and deployment

Organization: ABB

Project: ABBY — AI Agentic Platform for Workforce Transformation

IT leader: Vikke Kandell, CIO

IT leaders at ABB, a manufacturer, had some big hurdles to clear when it came to building an AI strategy.

They had to overcome employee fears that AI would take away jobs, the potentially high cost of AI vendor licenses, and pressure from investors, customers, and executives to advance the use of AI in the enterprise.

“We looked at this and asked, ‘How do we address all this?’ and build something that the company is proud of,” says Babu Kuttala, vice president of data analytics and AI.

The answer is ABBY, an AI agentic platform that enables employees to create and deploy specialized AI agents for specific business tasks.

To build ABBY, Kuttala and his team used best-of-breed LLMs (about 25 in total). They built a centralized orchestration layer using generative AI that integrates internal knowledge bases with external ecosystems, creating a unified platform where agents can access enterprise data, understand required actions, and execute tasks across multiple systems. And they created preconfigured skills so that employees could build agents tailored to their workflows without having to code.

ABBY was rolled out in 2025 to 100 users but is now used by 63,000 (more than 75% of the company’s workforce, Kuttala notes) with an average of 10,000-plus workers using it daily. IT continues to add LLMs and capabilities to expand use of ABBY even further, Kuttala says.

Belcorp modernizes manufacturing with Smart Factory

Organization: Belcorp

Project: QPlant — Smart Factory

IT leader: Venkat Gopalan, Chief Digital, Data, and Technology Officer

Legacy processes were limiting Belcorp’s ability to scale and compete. Its manufacturing relied on ERP-driven processes with limited shop-floor automation and weak connectivity across production, packaging, quality, and maintenance. The company depended heavily on manual records and post-process reconciliation, resulting in fragmented data, limited real-time insight, inefficiencies, and higher risks for errors.

Smart Factory changed all that. The IT initiative reimagined how manufacturing teams work “by creating a connected, data-driven environment where production, quality, maintenance, and operations are aligned around real-time information and standardized execution,” says Venkat Gopalan, chief digital, data, and technology officer.

At Smart Factory’s core is a manufacturing execution system that orchestrates production workflows, quality processes, and operational execution, he explains. IoT-enabled equipment integration and a centralized SCADA platform provide real-time visibility into shop-floor operations, while electronic batch records digitize production execution, strengthen traceability, and reinforce compliance by design.

Integrating those operational technologies with the company’s enterprise platforms was another critical component of success, Gopalan says, creating a trusted flow of real-time data across manufacturing, quality, maintenance, and business systems. “This connected architecture transformed isolated data into actionable insights, enabling faster decision-making, greater operational visibility, and continuous improvement across the manufacturing lifecycle,” he adds.

The initiative generated more than $1 million in financial benefits in its first year alone.

“Most importantly, Smart Factory established the digital foundation for the future of manufacturing at Belcorp,” Gopalan says. “With real-time operational data and connected systems now in place, we’re well positioned to accelerate advanced analytics, AI-driven optimization, predictive maintenance, and other Industry 4.0 capabilities that will continue delivering value for years to come.”

Cohesity replatforms post-acquisition for commercial growth

Organization: Cohesity

Project: Lead to Cash Replatforming Program (Veritas Integration)

IT leader: Brian Spanswick, CIO

Cohesity set an ambitious objective: Complete an enterprise-scale lead-to-cash replatform in under six months.

That’s a tight timeline for any replatforming initiative, but Cohesity’s project had another layer of complexity. It followed Cohesity’s December 2024 acquisition of Veritas, a company twice its size in revenue, leaving Cohesity to integrate the majority of a global enterprise revenue engine into its own operating model without disrupting customers, partners, or sellers.

“We had to bring the two companies together, merge the workforces together, and create an overall harmonized organization and operating infrastructure platform,” says Eric Brown, who as CFO and COO led the project.

The program migrated heavily customized CRM, CPQ, PRM, ERP, and subscription platforms (some of which were “very brittle, very bespoke,” Brown says) to a unified SaaS CRM, CPQ, and ERP environment with uninterrupted selling, billing, and partner operations.

This was no lift-and shift, Brown stresses. “It was a business process optimization project as well. We want to run very efficiently, so we questioned everything and used the migration process to simplify and streamline the business in every possible respect.”

The initiative enabled continuity for 13,000-plus customers, protected revenue during integration, and established a scalable commercial foundation for future growth.

Brown cites several factors that contributed to success. First, leadership was upfront about what it would take to meet the deadline, a process that involved carefully prioritizing the capabilities that would appear in the first iteration. Leadership also streamlined decision-making, establishing office hours that “ran with military precision” to handle issues. And the company selected a specialized partner, requiring its top talent be assigned to Cohesity.

Dairyland Power goes agentic to protect field crews

Organization: Dairyland Power Cooperative

Project: ODIN — Organizational Effectiveness Agentic AI

IT leader: Nate Melby, VP and CIO

Dairyland Power Cooperative had amassed a large collection of field observations, incident reports, near-misses, safety rules, and work methods that could yield insights into processes and practices that could help protect its workers.

But the insights were essentially out of reach, trapped in siloes.

Dairyland’s organizational effectiveness team turned to CIO Nate Melby for help unlocking those insights. Melby then turned to agentic AI, recognizing that the technology could address the team’s need to make better use of its data.

“This was about finding insights on how to work more safely,” Melby says. “It’s about preventing incidents.”

The collaboration between the two teams created ODIN, the first agentic AI implementation of its kind in the electric utility industry.

Focused on worker safety, ODIN autonomously connects the collective safety knowledge of the organization and delivers actionable insights directly to field crews at the moment work is planned.

ODIN was developed through a hybrid approach that combined an agentic AI platform and Dairyland’s internal private generative AI platform called VoltWrite. ODIN leverages LLMs, retrieval-augmented generation, and a coordinated swarm of autonomous agents.

Agents work together to analyze internal safety data, performance history, work practices, and safety rules and then synthesize the information into clear guidance on the safest way to perform specific tasks.

ODIN has produced results, including a reduction in OSHA recordable injuries and improvements in the quality and consistency of pre-job safety briefings.

ODIN was deployed in early 2025 for use by Dairyland’s workers in transmission construction and electrical maintenance, which are the highest-risk work areas. Dairyland is looking to expand ODIN’s use to other teams.

Dow’s digital sustainability ledger drives low-carbon sales

Organization: Dow

Project: Carbon Footprint Ledger

IT leader: Deb Bauler, Chief Information and Digital Officer

Executives at Dow consider the Carbon Footprint Ledger (CFL) as more than a technology or innovative carbon accounting methodology. According to Senior Global IT Director Jeremy Preston, CFL is “a digital business capability that enables Dow to translate sustainability investments into customer value.”

CFL transformed how Dow uses greenhouse gas emissions data. It combines a methodology aligned to international standards with an enterprise-scale digital platform. It also integrates manufacturing, supply chain, commercial, and sustainability data to generate product carbon footprints under enterprise-level governance and management at scale.

In doing so, Preston says it creates “a trusted, traceable link between low-carbon processes and raw materials implemented across its manufacturing network and the lower-carbon products customers seek.”

The technology team worked closely with sustainability and business teams, collaboratively developing the capabilities needed to reconstruct product genealogy, maintain end-to-end data lineage, track low-carbon attributes across interconnected manufacturing processes, and generate product carbon footprints that can support customer offerings and commercial transactions.

CFL was built on Dow’s Integrated Data Hub and in partnership with Boston Consulting Group and Databricks.

The core CFL platform is fully deployed and supports commercial transactions today.

Preston says CFL “enables Dow to turn sustainability investments into customer value, commercial differentiation, and new growth opportunities.” Dow reports that it has driven hundreds of millions of dollars in low-carbon product sales in 2025 and 2026.

The company is now expanding its use. “We are extending adoption across additional products, manufacturing networks, business segments, and customer use cases while continuing to enhance automation, analytics, and integration with commercial processes,” Preston says.

J&J transforms quality management with AI

Organization: Johnson & Johnson

Project: Q&C Strategy

IT leader: Michael Comprelli, Vice President, Head of Technology, Technical Operations, and Risk; Joel O’Connor, Head of Technology, Medtech Quality, and Compliance

Johnson & Johnson is using AI to transform quality management through its Q&C Strategy.

QuIn is an AI-powered digital assistant that fuses human expertise with machine learning, automation, and data-driven insights to boost efficiency, reliability, and worker impact. By embedding gen AI into core quality management systems processes, QuIn proactively gathers actionable insights, increases operational efficiency, and allows teams to focus on high-value, patient-centric work.

Cora is an innovative generative AI platform that provides regulatory intelligence monitoring, impact analysis, and augmented content revision. Cora assists with document analysis, compliance comparison, stakeholder analysis, policy/standard creation, procedural/document updates, and document comparison. Cora is purpose-built for regulated environments, validating outputs against source material and offering a user experience that instills trust in the outcome.

QuIn and Cora, which automate time-intensive tasks and democratize information access, are on track to deliver significant value, with J&J reporting more than $62 million in documented true cost savings by 2028 from QuIn alone. Cora delivered $2 million in cost efficiency in 2025 and will deliver a documented cost savings of $25 million by 2028.

“Our teams proved responsible AI can be applied meaningfully in a highly regulated environment without compromising the rigor, accountability, or human judgment that quality requires,” says Michael Comprelli, vice president, head of technology, technical operations, and risk.

He continues, saying that J&J “moved these ideas beyond experimentation and into products that employees use in their daily work. We did that by bringing together Quality expertise, product management, data engineering, architecture, cybersecurity, user-experience design and AI engineering around a common purpose.”

JLL brings intelligent automation to business services

Organization: JLL

Project: Business Service Digitization

IT leader: Pinak Dash, Global Head of JLL Business Services and Legal Technologies

JLL launched its digitization initiative to drive process redesign as well as systematic AI and RPA deployment across JLL Business Services (JBS).

The initiative was designed to address inefficiencies that hampered scalability and competitive positioning. It was also designed to eliminate manual processes that consumed thousands of hours across finance, HR, legal, procurement, marketing, research, IT, and lease administration.

Pinak Dash, global head of JBS and legal technologies, says the digitization initiative had a dual-strategy combining traditional digitization with generative AI innovation to hundreds of processes.

JLL lists three innovations critical to the program’s success.

First is a hybrid platform that integrates RPA with JLL’s proprietary AI platform called Falcon, which created intelligent automation that adapts and learns. It enables real-time process automation, intelligent document processing with automated extraction/validation, and smart decision-making for continuously optimizing workflows.

The second innovation is its use of ProHance for real-time process monitoring and enabling of data-driven optimization. Sensors capture granular productivity metrics, identify bottlenecks, and provide actionable insights for continuous improvement across automated and manual processes.

Third is its custom AI assistants and transaction agents. Falcon-powered assistants provide intelligent knowledge search while specialized agents execute complex transactions across enterprise SaaS platforms. These handle multisystem workflows, reducing human touchpoints while maintaining accuracy and compliance.

Dash says the initiative has delivered quantifiable benefits through improved efficiency, accuracy, and quality of services provided to clients.

“The initiative delivers on our business goals, makes us more efficient, provides customers better service, and it opens up the capabilities and bandwidth of our people to do what they like to do and to find innovative ways to serve our business,” he adds.

Nationwide partnership platform delivers efficiencies, business growth

Organization: Nationwide

Project: Enterprise Digital Platform (EDP)

IT leader: Michael Carrel, EVP and CTO

Nationwide’s new Enterprise Digital Platform (EDP) gives the company “a scalable way to connect with external partners quickly, securely, and consistently across all areas of our business,” says company EVP and CTO Michael Carrel.

He explains that “instead of treating every integration as a custom effort, EDP creates a common front door for digital products, documentation, onboarding and governance.”

That innovation has produced better experiences for the company’s partners. It saves time for Nationwide teams, partners, and customers. And it supports faster launch times for new products and enables growth across the business.

“EDP changed the model from fragmented, point-to-point integrations into an enterprise platform built around reusable digital products. That shift lets us support a range of integration options in one governed environment, meet partners at different stages of technical maturity, and add new capabilities over time without redesigning every relationship from scratch,” Carrel explains.

EDP uses cloud-native microservices, role-based access control, and advanced analytics. Nationwide IT created modular microservices to make EDP more scalable, resilient, and adaptable. And IT decoupled it from infrastructure-specific dependencies so that it would be a platform-agnostic developer portal. That, Carrel says, reduced operational constraints across environments.

Additionally, IT shifted from a user-specific model to role-based access, which improved security, simplified administration, and better served the needs of different audiences.

Meanwhile, robust analytics delivers visibility into platform usage and performance, which Carrel says helps ensure Nationwide continuously evolves the platform based on measurable outcomes.

The core platform is fully deployed, with Nationwide planning to expand it.

“Our Enterprise Digital Platform is more than a piece of technology,” Carrel notes, “it represents a strategic enabler to support growth objectives across Nationwide’s businesses.”

PITT Ohio fast-tracks shipment requests with AI assist

Organization: PITT Ohio

Project: No Touch Email (N@TE AI)

IT leader: Scott Sullivan, President and CEO (formerly CIO)

As PITT Ohio started its AI journey in 2024, the mandate was clear: Use the technology to solve “real problems,” says Ryan Carner, director of enterprise IT solutions.

“We wanted to hit the ground running and find a problem that was solvable,” Carner says, noting that the company also wanted to use the experience to build in-house AI skills. “The idea was to find a business case for AI that would be our first but not the only one.”

PITT Ohio leaders decided to tackle what Carner describes as a “mundane but very important task for how our business operates”: handling emails to the customer service team.

The need was significant. Customer service representatives were manually processing hundreds of pickup request emails daily, each requiring five to 15 minutes to interpret and re-enter shipment details into the company’s transportation management system (TMS). The emails were complicated, containing a lot of information submitted in nonstandardized ways and varying formats. This repetitive task consumed valuable time, introduced errors, and delayed customer response.

N@TE uses generative AI and natural language processing to transform unstructured email content into structured pickup orders automatically and in real-time. N@TE scans incoming emails, extracts key shipment data, and creates orders directly in the TMS via API integration. It operates seamlessly within existing workflows, requiring no change in customer behavior or retraining of staff.

PITT Ohio deployed N@TE in 2025, and the company also secured a patent for the product that year. N@TE has produced a 30-60X increase in processing speed, 99% accuracy in extracting and populating order data, and a 70% reduction in handling costs per pickup order.

SMU builds AI adoption through grassroots ambassador program

Organization: Southern Methodist University

Project: Scaling AI Without Scaling AI: Organizational AI Scaling Through Willingness

IT leader: Jason Warner, Associate CIO

Like executives in most organizations, leaders at Southern Methodist University encountered mixed attitudes about AI. Some workers had little interest in using the tech, others were afraid it would take jobs, still others were curious about what it could do.

Associate CIO Jason Warner and other leaders decided to leverage that last group, believing the best way to get SMU faculty and staff to embrace AI was to use enthusiasts to help smooth the way.

So, instead of treating AI as a conventional technology rollout, Warner and his colleagues built opt-in communities of practice known as the AI Coalition of the Willing and Operation Copilot.

The goal, Warner says, was to build institutional capability, reduce risk, and generate momentum.

“We knew the fastest way to scale AI was to scale the willingness of people to use the technology, and not talking to people about cost savings and the like,” Warner says, adding that willing users as great ambassadors and evangelists who showcase in formal and informal ways the technology’s potential for hesitant or skeptical colleagues.

Participating faculty members have access to a licensed ChatGPT account as long as they use it. Staff members have access to Copilot accounts after taking a self-paced training course and likewise must use it to keep that access.

Warner says these willing workers are demonstrating the benefits of AI (significant time reclamation, reduced cognitive load, improved quality of outputs, expanded professional capacity).

SMU is now moving to a single solution and scaling AI, confident that its use will deliver returns following in the footsteps of the early adopters.

Interested in meeting and learning from all CIO 100 winners? Join us next week at CIO 100 Awards & Conference in Frisco, TX. Limited seats remain! Register here 

  • ✇Security | CIO
  • The gen AI helping Aetna review millions of medical records
    One of the biggest challenges companies like Aetna face every year is an annual HEDIS review of its records to identify gaps in care. For large national payors, the scale of the challenge is immense. So Aetna has deployed a gen AI-driven document intelligence platform that has reduced the need for manual review by 65%. “We have a large group of amazing trained medical coders who do this every day,” says Nathan Frank, chief digital and technology officer at Aetna. “This
     

The gen AI helping Aetna review millions of medical records

31 de Julho de 2026, 07:00

One of the biggest challenges companies like Aetna face every year is an annual HEDIS review of its records to identify gaps in care. For large national payors, the scale of the challenge is immense. So Aetna has deployed a gen AI-driven document intelligence platform that has reduced the need for manual review by 65%.

“We have a large group of amazing trained medical coders who do this every day,” says Nathan Frank, chief digital and technology officer at Aetna. “This is about making it easier for them by speeding up the process. Something that might have taken weeks or months we can now do in days.”

The Healthcare Effectiveness Data and Information Set (HEDIS) is a range of performance measures for the managed care industry. Developed and maintained by the nonprofit National Committee for Quality Assurance (NCQA), the first version of HEDIS was released in 1991.

Under the HEDIS measures, large managed care providers like Aetna review more than 10 million medical records annually to identify gaps in care. These gaps are missed or overdue preventative care or chronic disease management tests including missed cancer screenings, blood sugar tests for diabetics, eye exams, and immunizations. Closing these gaps improves patient outcomes, and health plans are measured in how well they perform. But processing medical records is no easy task.

“We’re talking about medical charts that have white space filled with handwritten notes,” Frank explains. It’s not just structured data, it’s lots of physical clinical documentation.”

Adding up the numbers

Frank says industry benchmarks for large providers indicate an annual review process that requires about 50,000 work weeks, equivalent to nearly 1,000 dedicated full-time employees. It would take a team of 50 reviewers more than 20 years to complete a single annual review using fully manual processes.

Enter AI Medical Chart Review, a platform developed by Aetna that leverages cloud services and gen AI to automatically extract clinically relevant data from records, and prioritize records based on the likelihood of measure closure and evidence strength.

“Large language models and gen AI give us the ability to train a model to decipher the charts, identify the high value codes, and build correlations,” Frank says.

In the space of about six months, Frank’s team ideated the platform, and designed and trained a PoC that was able to process millions of records in just two weeks. As a result, AI Medical Chart Review has earned Aetna a CIO 100 Award in IT innovation.

“Now we’ve gone through 14 million documents,” Franks says. “We’re seeing a reduction of manual effort, which is now being transitioned into other areas like quality control and making sure the automated chart review is working as expected.”

Behind the curtain

Using gen AI, the platform automatically ingests and analyzes unstructured medical records and clinical documents. And as part of that process, it identifies and extracts clinically relevant information for specific HEDIS measures like diagnosis codes, medication records, lab results, and visit documentation. With this data, the platform generates a prioritized set of records based on the likelihood of measure closure and strength of clinical evidence, which is then passed to human employees for review and validation.

Frank says the platform has increased gap closure rates (leading to improved Star Ratings and higher reimbursement), streamlined workflows, and enabled teams once dedicated to manual record review to shift focus to higher-value activities.

Frank says much of the speed and success in building the platform comes down to a shift in the way it approached the design and build process. Rather than exhaustively writing specifications and requirements, Aetna created a team that included engineers and subject matter experts who worked together to build out capabilities iteratively.

“It allowed us to move much faster, and having a business subject matter expert sitting in the same virtual or physical room with us got us a much better outcome,” Frank says. “The product model, our cloud compute model, and our AI governance model allow for quick reviews to make sure we’re using AI responsibly with the right guardrails. It’s increased the speed to get from product launch to go-live.”

He adds that small teams that don’t have to deal with a lot of bureaucracy are key to moving quickly.

“You need to design with security, compliance, and a responsible use of AI as core principles from day one,” he says. “Everything we do from a new build standpoint starts with thinking about how we make it cloud native, how we build with the right elasticity and speed, and how we optimize the cost.”

The most important element of all, he says, is a good relationship with your subject matter experts.

“You can have a great product manager and engineer, but you really need that business subject matter expert who’s excited about it, and who has a passion for transforming the process,” Frank says. “Once you put those three together, you’ll see amazing things like this happen all the time.”

  • ✇Firewall Daily – The Cyber Express
  • EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks Samiksha Jain
    The global financial sector is facing a sharp rise in Financial Services DDoS Attacks, with cybercriminals increasingly targeting banks, payment systems, and online financial platforms through larger, longer, and more attacks, according to new research from Akamai. In its latest State of the Internet (SOTI) Security report titled AI-Empowered Botnets and API Visibility Gaps: Attack Trends in Financial Services, research warned that AI-powered botnets and politically motivated hacktivist group
     

EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks

Financial Services DDoS Attacks

The global financial sector is facing a sharp rise in Financial Services DDoS Attacks, with cybercriminals increasingly targeting banks, payment systems, and online financial platforms through larger, longer, and more attacks, according to new research from Akamai. In its latest State of the Internet (SOTI) Security report titled AI-Empowered Botnets and API Visibility Gaps: Attack Trends in Financial Services, research warned that AI-powered botnets and politically motivated hacktivist groups are intensifying the cyber threat landscape for the banking and financial services industry. Researchers found that Financial Services DDoS Attacks have become more persistent and operationally disruptive, particularly across Layers 3 and 4 web and API infrastructure.

Financial Services DDoS Attacks Top the Chart

According to the report, financial services organizations are now the most targeted industry for web and API distributed denial-of-service attacks. Akamai revealed that the median duration of global Layers 3 and 4 Financial Services DDoS Attacks has increased by 738% since 2024. The company attributed the surge to AI-powered attack infrastructure and growing hacktivist activity, including campaigns linked to pro-Iran cyber groups. Security researchers said attackers are increasingly focusing on:
  • Online banking systems
  • Real-time payment platforms
  • API infrastructure
  • Customer-facing financial applications
The report noted that while financial institutions continue expanding digital banking and payment services, the growing reliance on APIs and cloud-connected infrastructure has also expanded the attack surface available to threat actors.

API-Related Cyber Risks Emerging as Major Security Weakness

One of the strongest findings in the report involved API-related cyber risks. According to reserach’s 2026 API Security Impact Study, 96% of financial service leaders surveyed reported at least one API security incident within the past year. That figure was the highest recorded among all industries included in the research. The report also found that:
  • 60% of all web attacks in 2025 targeted banking institutions
  • 83% of attacks against API endpoints focused on financial organizations
Researchers warned that APIs are increasingly becoming high-value targets because they support critical services such as digital payments, account management, authentication systems, and mobile banking applications. Steve Winterfeld, Advisory Chief Information Security Officer at Akamai, said APIs are now central to modern cyberattacks against financial institutions. “Cybercriminals and hacktivists continue to escalate DDoS from nuisance attacks to a sustained siege encompassing both hacktivism and cybercrime, and financial services are in the crosshairs,” Winterfeld said. He added that artificial intelligence is accelerating existing cybersecurity threats rather than replacing them.

AI Botnets Driving DDoS Campaigns

The report highlighted how AI-driven infrastructure is helping attackers automate and scale malicious operations more effectively. Researchers observed a 147% surge in advanced bot activity during late 2025. In one case study referenced by Akamai, nearly 96% of all traffic reaching a targeted website was identified as malicious scraping bot activity. The company warned that AI-powered botnets are making Financial Services DDoS Attacks more difficult to detect and mitigate because attackers can dynamically adapt attack patterns and traffic behavior. These botnets are also being used to:
  • Overwhelm infrastructure
  • Disrupt payment systems
  • Target APIs
  • Scrape sensitive data
  • Launch credential abuse campaigns
Cybersecurity experts have increasingly warned that AI-enabled automation allows threat actors to launch large-scale attacks with fewer technical resources.

Attack Patterns Differ Across Global Regions

Research also identified major regional differences in cyberattack patterns targeting financial institutions. The report found:
  • Europe, the Middle East, and Africa accounted for 62% of Layers 3 and 4 DDoS attacks
  • Asia-Pacific experienced 52% of Layer 7 DDoS attacks
  • North America recorded the highest volume of web attacks at 44%
Researchers said these differences reflect varying attacker strategies, infrastructure deployment patterns, and regional cybersecurity maturity levels. The report also revealed that nearly 80% of financial institutions experienced ransomware attacks during the past two years. However, fewer than half of surveyed organizations reported adopting advanced cybersecurity technologies capable of handling modern attack methods.

Growing Pressure on Financial Sector Cybersecurity

The latest findings add to growing concerns around operational resilience within the global financial industry. As banks and financial institutions continue accelerating digital transformation initiatives, cybersecurity teams are being forced to defend increasingly complex environments that rely heavily on APIs, cloud platforms, automated infrastructure, and third-party integrations. Research said organizations must improve visibility into APIs, strengthen DDoS mitigation strategies, and modernize threat detection capabilities to address the evolving threat landscape. The SOTI report also includes guidance on DNS security, DDoS mitigation practices, AI architecture security considerations, and insights from financial sector cybersecurity experts, including contributions from the FS-ISAC.

Misconfigured Server Run by Hackers Leaks 345,000 Stolen Credit Cards

A misconfigured server linked to the carding marketplace Jerry’s Store exposed 345,000 stolen credit cards after an AI coding error caused a major security flaw.
  • ✇Firewall Daily – The Cyber Express
  • Targeted Cyberattack on Northern Ireland Schools Exposes Personal Data Samiksha Jain
    The Education Authority cyberattack investigation has confirmed that a recent incident involved a targeted attack on a small number of schools, leading to the compromise of some personal data. The update comes days after the incident was first reported, with new findings shedding light on the nature and impact of the breach. According to officials, the Education Authority cyberattack was identified on April 10, 2026, when authorities were alerted to suspicious activity affecting school system
     

Targeted Cyberattack on Northern Ireland Schools Exposes Personal Data

Education Authority cyberattack

The Education Authority cyberattack investigation has confirmed that a recent incident involved a targeted attack on a small number of schools, leading to the compromise of some personal data. The update comes days after the incident was first reported, with new findings shedding light on the nature and impact of the breach. According to officials, the Education Authority cyberattack was identified on April 10, 2026, when authorities were alerted to suspicious activity affecting school systems. Forensic experts have since determined that attackers gained specific and targeted access to personal information linked to certain schools.

Targeted Nature of Education Authority Cyberattack

The latest findings indicate that the Education Authority cyberattack was not a widespread system breach but a focused attack on select institutions. Investigators confirmed that personal data was accessed in these cases, though the full extent of the compromised information has not yet been disclosed. Authorities had earlier stated that there was no evidence of data exfiltration or corruption. That assessment was based on initial findings, with officials noting at the time that the investigation was ongoing. The updated confirmation reflects the results of a more detailed forensic review, which required analysis across multiple systems. The breach is believed to have occurred before additional cybersecurity measures were implemented by the authority earlier this month.

Investigation and Law Enforcement Involvement

The Education Authority cyberattack is currently under active investigation, with law enforcement agencies involved. The Police Service of Northern Ireland and the Information Commissioner’s Office were notified immediately after forensic experts confirmed that personal data had been accessed. Officials stated that details of the incident are being disclosed publicly following an arrest made by the police. Prior to this development, authorities had withheld information to avoid interfering with ongoing investigations. The involvement of regulatory and law enforcement bodies highlights the seriousness of the Education Authority cyberattack, particularly given the sensitivity of data held by educational institutions.

Containment and System Recovery Efforts

System managers have assessed that the Education Authority cyberattack has been contained. Additional security measures were deployed as soon as the incident was detected, aimed at preventing further unauthorized access. Efforts are now focused on restoring normal operations. Work is ongoing to reconnect affected schools to the C2k system, which supports digital services across the education network. Officials said that restoring full functionality remains a priority while ensuring system security. The authority has also urged users to reset their C2k passwords as a precautionary step.

Notification of Affected Individuals

Authorities have confirmed that individuals whose personal data may have been compromised in the Education Authority cyberattack will be notified. The process of informing affected schools and individuals is currently underway and is being guided by the final findings of the investigation, along with advice from relevant authorities. Officials acknowledged the concern such incidents may cause and said efforts are being made to communicate with impacted parties as quickly as possible. At the same time, they noted that certain details cannot yet be disclosed publicly due to the ongoing police investigation. Further updates are expected once authorities are able to share more information without affecting the case.

Ongoing Monitoring and Next Steps

The Education Authority cyberattack remains under close monitoring as forensic analysis continues. Investigators are working to fully understand how the breach occurred and whether additional risks remain. While the incident appears to be contained, the confirmation of targeted access to personal data underscores the risks facing education systems, which often manage sensitive information across interconnected platforms. Authorities have indicated that further updates will be provided as the investigation progresses and more details become available.
  • ✇Firewall Daily – The Cyber Express
  • Hackers Exploit Kali Forms Vulnerability to Take Over WordPress Sites Ashish Khaitan
    A recently disclosed Kali Forms vulnerability affecting a widely used WordPress plugin has escalated into an active security threat, enabling unauthenticated attackers to achieve Remote Code Execution on affected websites. The flaw impacts Kali Forms, a drag-and-drop form builder with more than 10,000 active installations, and has already been exploited in the wild shortly after public disclosure.  Security researchers reported that the vulnerability was first submitted on March 2, 2026, thro
     

Hackers Exploit Kali Forms Vulnerability to Take Over WordPress Sites

Kali Forms vulnerability

A recently disclosed Kali Forms vulnerability affecting a widely used WordPress plugin has escalated into an active security threat, enabling unauthenticated attackers to achieve Remote Code Execution on affected websites. The flaw impacts Kali Forms, a drag-and-drop form builder with more than 10,000 active installations, and has already been exploited in the wild shortly after public disclosure.  Security researchers reported that the vulnerability was first submitted on March 2, 2026, through a bug bounty program, identifying a critical Remote Code Execution issue in the Kali Forms vulnerability chain. The vendor released a patched version on March 20, 2026, and the issue was simultaneously added to the Wordfence Intelligence database. On the same day, attackers began actively exploiting it on scale. 

Timeline of the Kali Forms Vulnerability in the WordPress Plugin Ecosystem 

The Kali Forms vulnerability followed a rapid disclosure-to-exploitation cycle: 
  • March 2, 2026: Initial submission of the Remote Code Execution flaw via bug bounty reporting. 
  • March 5, 2026: Wordfence Premium, Care, and Response users received firewall protection. 
  • March 20, 2026: Patched version released; vulnerability publicly disclosed; attackers began exploiting the same day. 
  • April 4, 2026: Free Wordfence users received delayed firewall protection. 
  • April 4–10, 2026: Peak exploitation activity observed against the Kali Forms vulnerability. 
The patched release addressed the issue in version 2.4.10 of the WordPress plugin, while all versions up to and including 2.4.9 remained vulnerable. 

Technical Root Cause Behind the Kali Forms Vulnerability

The core of this WordPress plugin flaw lies in how user-supplied form data is processed and stored internally. The vulnerability resides in the form_process flow and the prepare_post_data() function, which incorrectly maps attacker-controlled input into internal placeholder storage without proper validation or allow-list restrictions.  These placeholders are later used in the _save_data() method, where unsafe execution occurs through call_user_func().  A simplified excerpt of the vulnerable logic includes: 
if (isset($this->placeholdered_data['{entryCounter}'])) {    $this->placeholdered_data['{entryCounter}'] =        call_user_func($this->placeholdered_data['{entryCounter}'], $this->post->ID); } 
Because the Kali Forms vulnerability allows attackers to fully control values like {entryCounter} and {thisPermalink}, an unauthenticated user can inject arbitrary PHP function names. These are then executed directly, resulting in Remote Code Execution (RCE) attacks.  Researchers noted that the lack of input restrictions in prepare_post_data() enables overwriting internal placeholders. As a result, attacker-controlled values flow directly into call_user_func(), making exploitation trivial once the request is submitted.  One observed abuse pattern demonstrates authentication bypass attempts using built-in WordPress functions. For example, attackers can assign: 
  • {entryCounter} = wp_set_auth_cookie  
  • formId = 1  
This leads to execution of wp_set_auth_cookie(1), which may log attackers in as the default administrator account if it exists, effectively turning the Kali Forms vulnerability into a full account takeover vector. 

Active Exploitation of the Kali Vulnerability in Real-world Attacks 

Telemetry from security monitoring shows that exploitation began immediately after disclosure. Attackers have been systematically targeting the WordPress plugin using automated requests to admin-ajax.php.  A representative exploit request includes: 
POST /wp-admin/admin-ajax.php HTTP/1.1 Content-Type: application/x-www-form-urlencoded action=kaliforms_form_process& data[formId]=1& data[nonce]=66ddddb2b7& data[entryCounter]=wp_set_auth_cookie 
This confirms how the Remote Code Execution flaw is triggered through manipulated form submission data.  Security systems recorded significant attack volume: 
  • Over 312,200 exploit attempts were blocked targeting the Kali Forms vulnerability. 
  • Heavy targeting was observed immediately after March 20, 2026 disclosure. 
  • Increased spike in activity between April 4 and April 10, 2026. 

Top Attacking IP Addresses Observed 

Threat intelligence identified several IPs responsible for large-scale exploitation attempts: 
  • 209.146.60.26 – over 152,000 blocked requests  
  • 49.156.40.126 – over 50,000  
  • 124.248.183.139 – over 26,000  
  • 202.56.2.126 – over 14,000  
  • 130.12.182.154 – over 11,000  
  • 104.28.160.197 – over 9,000  
  • 1.53.114.181 – over 5,700  
  • 157.15.40.74 – over 3,000  
  • 114.10.99.126 – over 2,500  
  • 83.147.12.83 – over 1,300  
These sources were repeatedly associated with exploitation attempts targeting the Kali Forms vulnerability in the affected WordPress plugin. 
  • ✇Firewall Daily – The Cyber Express
  • Dark Web Article Contest Offers $10,000 for Exploit Writing on TierOne Forum Ashish Khaitan
    In an unusual development within the underground cyber world, a dark web article contest has been announced on a well-known dark web forum, TierOne forum. The initiative is backed by a $10,000 prize pool. The contest places a spotlight on technical writing centered around vulnerability exploitation, offering insight into how knowledge is shared and rewarded in these spaces.  Traditionally, dark web forums have been linked to illicit activities such as trading stolen data, coordinating ransomw
     

Dark Web Article Contest Offers $10,000 for Exploit Writing on TierOne Forum

dark web article contest

In an unusual development within the underground cyber world, a dark web article contest has been announced on a well-known dark web forum, TierOne forum. The initiative is backed by a $10,000 prize pool. The contest places a spotlight on technical writing centered around vulnerability exploitation, offering insight into how knowledge is shared and rewarded in these spaces.  Traditionally, dark web forums have been linked to illicit activities such as trading stolen data, coordinating ransomware attacks, and distributing malware. However, this contest introduces a different dynamic, one that mirrors legitimate cybersecurity ecosystems, where researchers document findings and share exploit techniques.  

The Dark Web Article Contest Overview and Prize Structure 

According to an official announcement shared by an administrator on the forum, the post states: “Всем привет! Мы рады сообщить T1 erone [КОНКУРС СТАТЕЙ #1 - 2026]. Победители конкурса получают призы: 1 место 5.000$, 2 место - 3.000$, 3 место - 2.000$, [Призовой фонд 10.000$]. Прием статей начинается 13.04.2026 и заканчивается 14.05.2026.”   The announcement indicates that the dark web article contest will run from April 13, 2026, to May 14, 2026, with prize amounts set at $5,000 for first place, $3,000 for second place, and $2,000 for third place, making up a total prize pool of $10,000, reportedly sponsored by the ransomware group cry0. 

Topics Focused on Vulnerability Exploitation 

The contest invites submissions covering a wide range of advanced topics related to vulnerability exploitation with real-world applicability. These include: 
  • Remote Code Execution (RCE) through deserialization flaws in React and Node.js frameworks. 
  • Command injection attacks in APIs and backend systems. 
  • Insecure Direct Object Reference (IDOR) vulnerabilities in SaaS platforms. 
  • Server-Side Template Injection (SSTI) in modern templating engines. 
  • Exploitation of insecure deserialization in PHP and Java. 
  • Client-side RCE via Markdown or Office file rendering. 
  • Firmware attacks targeting routers and cameras. 
  • Privilege escalation techniques in RouterOS and similar systems. 
  • Exploitation methods for products from Cisco, MikroTik, Oracle, and Ubiquiti. 
  • Zero-day discovery in browser components like WebGPU and Blink. 
  • AI-assisted vulnerability discovery and reverse engineering. 
  • Techniques for bypassing AV and EDR security systems. 
  • Exploitation of Remote Procedure Call (RPC) mechanisms. 
For context, vulnerabilities such as RCE, IDOR, and SSTI allow attackers to execute arbitrary code or access restricted data, while firmware attacks enable persistent control over hardware devices. Similarly, AV/EDR bypass techniques are designed to evade detection by modern security solutions. 

Participation Rules and Requirements 

The TierOne forum has outlined strict guidelines for participants. Articles must be published within the forum’s designated section and include a specific prefix to qualify: 
  • Submissions must be posted under the Articles section with the prefix “[Contest]”. 
  • A link to the article must be shared in the contest thread with a participation note. 
  • All users are eligible, regardless of registration date or activity level. 
  • The use of multiple accounts is strictly prohibited. 
In addition, the contest enforces content quality standards: 
  • Articles must be original and based on the author’s own experience. 
  • Copy-pasted or reposted material is not allowed. 
  • Submissions should comprehensively cover the chosen topic, including tools, techniques, and methodologies. 
  • Minimum length requirement is at least one A4 page. 
  • Excessive filler content is discouraged. 
  • Including video demonstrations may improve chances of winning. 

A Glimpse into Dark Web Knowledge Sharing 

While the existence of such a contest may seem surprising, it notes a bigger trend within dark web forums. Beyond illegal marketplaces and data trading, these platforms also function as hubs for technical exchange, where members document and refine vulnerability exploitation techniques. In many ways, the structure resembles legitimate bug bounty programs and penetration testing workflows, where cybersecurity professionals publish detailed reports on discovered flaws. The key difference lies in the intent and environment in which this knowledge is applied. It is important to note that this article does not endorse participation in such activities. Instead, it aims to shed light on how these underground ecosystems operate. The TierOne forum contest highlights that even within the dark web, there are organized efforts to produce structured, experience-based technical content, albeit in a context that raises ethical and legal concerns.
  • ✇Security Boulevard
  • The Hidden Tracking Risk Inside Your Tires Tom Eston
    In this episode, Tom Eston and co-host Scott Wright discuss research showing that Tire Pressure Monitoring Systems (TPMS) can create privacy risks because the sensors broadcast unencrypted, uniquely identifying wireless signals that could be used to track vehicles. They reference a 10-week study by researchers at IMDEA in Madrid that collected about 6 million signals […] The post The Hidden Tracking Risk Inside Your Tires appeared first on Shared Security Podcast. The post The Hidden Tracking Ri
     

The Hidden Tracking Risk Inside Your Tires

30 de Março de 2026, 01:00

In this episode, Tom Eston and co-host Scott Wright discuss research showing that Tire Pressure Monitoring Systems (TPMS) can create privacy risks because the sensors broadcast unencrypted, uniquely identifying wireless signals that could be used to track vehicles. They reference a 10-week study by researchers at IMDEA in Madrid that collected about 6 million signals […]

The post The Hidden Tracking Risk Inside Your Tires appeared first on Shared Security Podcast.

The post The Hidden Tracking Risk Inside Your Tires appeared first on Security Boulevard.

💾

  • ✇Security Boulevard
  • Claude Code Security: The AI Shockwave Hitting Cybersecurity Tom Eston
    Anthropic’s Claude Code Security research preview promises AI-powered code analysis and vulnerability detection at scale. The announcement triggered strong reactions across the cybersecurity community and sent several vendor stocks lower. In this episode, we break down what the tool actually does, where it fits in modern AppSec, and whether AI automation threatens traditional security products […] The post Claude Code Security: The AI Shockwave Hitting Cybersecurity appeared first on Shared Secu
     

Claude Code Security: The AI Shockwave Hitting Cybersecurity

2 de Março de 2026, 02:00

Anthropic’s Claude Code Security research preview promises AI-powered code analysis and vulnerability detection at scale. The announcement triggered strong reactions across the cybersecurity community and sent several vendor stocks lower. In this episode, we break down what the tool actually does, where it fits in modern AppSec, and whether AI automation threatens traditional security products […]

The post Claude Code Security: The AI Shockwave Hitting Cybersecurity appeared first on Shared Security Podcast.

The post Claude Code Security: The AI Shockwave Hitting Cybersecurity appeared first on Security Boulevard.

💾

  • ✇Security Boulevard
  • LLMs Generate Predictable Passwords Bruce Schneier
    LLMs are bad at generating passwords: There are strong noticeable patterns among these 50 passwords that can be seen easily: All of the passwords start with a letter, usually uppercase G, almost always followed by the digit 7. Character choices are highly uneven ­ for example, L , 9, m, 2, $ and # appeared in all 50 passwords, but 5 and @ only appeared in one password each, and most of the letters in the alphabet never appeared at all. There are no repeating characters within any password. P
     

LLMs Generate Predictable Passwords

26 de Fevereiro de 2026, 09:07

LLMs are bad at generating passwords:

There are strong noticeable patterns among these 50 passwords that can be seen easily:

  • All of the passwords start with a letter, usually uppercase G, almost always followed by the digit 7.
  • Character choices are highly uneven ­ for example, L , 9, m, 2, $ and # appeared in all 50 passwords, but 5 and @ only appeared in one password each, and most of the letters in the alphabet never appeared at all.
  • There are no repeating characters within any password. Probabilistically, this would be very unlikely if the passwords were truly random ­ but Claude preferred to avoid repeating characters, possibly because it “looks like it’s less random”.
    ...

The post LLMs Generate Predictable Passwords appeared first on Security Boulevard.

Advancements in Passkey Authentication in Europe

Explore how passkey authentication is revolutionizing security in Europe through FIDO2 standards, NIS2 compliance, and the European Digital Identity Wallet.

The post Advancements in Passkey Authentication in Europe appeared first on Security Boulevard.

  • ✇McAfee Blog
  • How to Remove Your Personal Information From the Internet Jasdev Dhaliwal
    Chances are, you have more personal information posted online than you think. In 2024, the U.S. Federal Trade Commission (FTC) reported that 1.1 million identity theft complaints were filed, where $12.5 billion was lost to identity theft and fraud overall—a 25% increase over the year prior. What fuels all this theft and fraud? Easy access to personal information. Here’s one way you can reduce your chances of identity theft: remove your personal information from the internet. Scammers and thieves
     

How to Remove Your Personal Information From the Internet

10 de Outubro de 2025, 09:31

Chances are, you have more personal information posted online than you think.

In 2024, the U.S. Federal Trade Commission (FTC) reported that 1.1 million identity theft complaints were filed, where $12.5 billion was lost to identity theft and fraud overall—a 25% increase over the year prior.

What fuels all this theft and fraud? Easy access to personal information.

Here’s one way you can reduce your chances of identity theft: remove your personal information from the internet.

Scammers and thieves can get a hold of your personal information in several ways, such as information leaked in data breaches, phishing attacks that lure you into handing it over, malware that steals it from your devices, or by purchasing your information on dark web marketplaces, just to name a few.

However, scammers and thieves have other resources and connections to help them commit theft and fraud—data broker sites, places where personal information is posted online for practically anyone to see. This makes removing your info from these sites so important, from both an identity and privacy standpoint.

What are data brokers?

Data broker sites are massive repositories of personal information that also buy information from other data brokers. As a result, some data brokers have thousands of pieces of data on billions of individuals worldwide.

What kind of data could they have on you? A broker may know how much you paid for your home, your education level, where you’ve lived over the years, who you’ve lived with, your driving record, and possibly your political leanings. A broker could even know your favorite flavor of ice cream and your preferred over-the-counter allergy medicine thanks to information from loyalty cards. They may also have health-related information from fitness apps. The amount of personal information can run that broadly, and that deeply.

With information at this level of detail, it’s no wonder that data brokers rake in an estimated $200 billion worldwide every year.

Sources of your information

Your personal information reaches the internet through six primary methods, most of which are initiated by activities you perform on a daily basis. Understanding these channels can help you make more informed choices about your digital footprint.

Digitized public records

When you buy a home, register to vote, get married, or start a business, government agencies create public records that contain your personal details. These records, once stored in filing cabinets, are now digitized, accessible online, and searchable by anyone with an internet connection.

Social media sharing and privacy gaps

Every photo you post, location you tag, and profile detail you share contributes to your digital presence. Even with privacy settings enabled, social media platforms collect extensive data about your behavior, relationships, and preferences. You may not realize it, but every time you share details with your network, you are training algorithms that analyze and categorize your information.

Data breaches

You create accounts with retailers, healthcare providers, employers, and service companies, trusting them to protect your information. However, when hackers breach these systems, your personal information often ends up for sale on dark web marketplaces, where data brokers can purchase it. The Identity Theft Research Center Annual Data Breach Report revealed that 2024 saw the second-highest number of data compromises in the U.S. since the organization began recording incidents in 2005.

Apps and ad trackers

When you browse, shop, or use apps, your online behavior is recorded by tracking pixels, cookies, and software development kits. The data collected—such as your location, device usage, and interests—is packaged and sold to data brokers who combine it with other sources to build a profile of you.

Loyalty programs

Grocery store cards, coffee shop apps, and airline miles programs offer discounts in exchange for detailed purchasing information. Every transaction gets recorded, analyzed, and often shared with third-party data brokers, who then create detailed lifestyle profiles that are sold to marketing companies.

Data broker aggregators

Data brokers act as the hubs that collect information from various sources to create comprehensive profiles that may include over 5,000 data points per person. Seemingly separate pieces of information become a detailed digital dossier that reveals intimate details about your life, relationships, health, and financial situation.

The users of your information

Legally, your aggregated information from data brokers is used by advertisers to create targeted ad campaigns. In addition, law enforcement, journalists, and employers may use data brokers because the time-consuming pre-work of assembling your data has largely been done.

Currently, the U.S. has no federal laws that regulate data brokers or require them to remove personal information if requested. Only a few states, such as Nevada, Vermont, and California, have legislation that protects consumers. In the European Union, the General Data Protection Regulation (GDPR) has stricter rules about what information can be collected and what can be done with it.

On the darker side, scammers and thieves use personal information for identity theft and other forms of fraud. With enough information, they can create a high-fidelity profile of their victims to open new accounts in their name. For this reason, cleaning up your personal information online makes a great deal of sense.

Types of personal details to remove online

Understanding efforts to remove personal information, which data types pose the greatest threat, can help you prioritize your removal efforts. Here are the high-risk personal details you should target first, ranked by their potential for harm.

Highest priority: Identity theft goldmines

  • Social Security Number (SSN) with full name and address: This combination provides everything criminals need for identity theft, leading to fraudulent credit accounts, tax refund theft, and employment fraud that may take years to resolve, according to the FTC.
  • Financial account information: Bank account numbers, credit card details, and investment account information enable direct financial theft. Even partial account numbers can be valuable when combined with other personal details from data breaches.
  • Driver’s license and government-issued ID information: These serve as primary identity verification for many services and can be used to bypass security measures at financial institutions and government agencies.

High priority: Personal identifiers

  • Full name combined with home address: This pairing makes you vulnerable to targeted scams and physical threats, while enabling criminals to gather additional information about your household and family members.
  • Date of birth: Often used as a security verification method, your date of birth, combined with other identifiers, can unlock accounts and enable age-related targeting for scams.
  • Phone numbers: This information enables SIM swapping, where criminals take control of your phone number to bypass two-factor authentication and access your accounts.

Medium-high priority: Digital and health data

  • Email addresses: Your primary email serves as the master key to password resets across multiple accounts. In contrast, secondary emails can reveal personal interests and connections that criminals exploit in social engineering.
  • Medical and health app data: This is highly sensitive information that can be used for insurance discrimination, employment issues, or targeted health-related scams.
  • Location data and photos with metadata: Reveals your daily patterns, workplace, home address, and frequented locations. Photos with embedded GPS coordinates can reveal your exact location and potentially enable stalking or burglary.

Medium priority: Account access points

  • Usernames and account handles: These help criminals map your digital footprint across platforms to discover your personal interests, connections, and even potential security questions and answers. They also enable account impersonation and social engineering against your contacts.

When prioritizing your personal information removal efforts, focus on combinations of data rather than individual pieces. For example, your name alone poses minimal risk, but when combined with your address, phone number, and date of birth, it creates a comprehensive profile that criminals can exploit. Tools such as McAfee Personal Data Cleanup can help you identify and systematically remove these high-risk combinations from data broker sites.

Step-by-step guide to finding your personal data online

  1. Targeted search queries: Search for your full name in quotes (“John Smith”), then combine it with your city, phone number, or email address. Try variations like “John Smith” + “123 Main Street” or “John Smith” + “555-0123”. Don’t forget to search for old usernames, maiden names, or nicknames you’ve used online. Aside from Google, you can also check Bing, DuckDuckGo, and people search engines.
  2. Major data broker and people search sites: Search for yourself in common data aggregators: Whitepages, Spokeo, BeenVerified, Intelius, PeopleFinder, and Radaris. Take screenshots of what you find as documentation. To make this process manageable, McAfee Personal Data Cleanup scans some of the riskiest data broker sites and shows you which ones are selling your personal info.
  3. Social media platforms and old accounts: Review your Facebook, Instagram, LinkedIn, Twitter, and other platforms for publicly visible personal details. Check old accounts—dating sites, forums, gaming platforms, or professional networks. Look for biographical information, location data, contact details, photos, and even comment sections where you may have shared details.
  4. Breach and dark web monitoring tools: Have I Been Pwned and other identity monitoring services can help you scan the dark web and discover if your email addresses or phone numbers appear in data breaches.
  5. Ongoing monitoring alerts: Create weekly Google Alerts for your and your family members’ full names, address combinations, and phone numbers. Some specialized monitoring services can track once your information appears on new data broker sites or gets updated on existing ones.
  6. Document everything in a tracker: Create a spreadsheet or document to systematically track your findings. Include the website name and URL, the specific data shown, contact information for removal requests, date of your opt-out request, and follow-up dates. Many sites require multiple follow-ups, so having this organized record is essential for successful removal.

This process takes time and persistence, but services such as McAfee Personal Data Cleanup can continuously monitor for new exposures and manage opt-out requests on your behalf. The key is to first understand the full scope of your online presence before beginning the removal process.

Remove your personal information from the internet

Let’s review some ways you can remove your personal information from data brokers and other sources on the internet.

Request to remove data from data broker sites

Once you have found the sites that have your information, the next step is to request that it be removed. You can do this yourself or employ services such as McAfee’s Personal Data Cleanup, which can help manage the removal for you depending on your subscription. ​It also monitors those sites, so if your info gets posted again, you can request its removal again.

Limit the data Google collects

You can request to remove your name from Google search to limit your information from turning up in searches. You can also enable “Auto Delete” in your privacy settings to ensure your data is regularly deleted. Occasionally, deleting your cookies or browsing in incognito mode prevents websites from tracking you. If Google denies your initial request, you can appeal using the same tool, providing more context, documentation, or legal grounds for removal. Google’s troubleshooter tool may explain why your request was denied—either legitimate public interest or newsworthiness—and how to improve your appeal.

It’s important to know that the original content remains on the source website. You’ll still need to contact website owners directly to have your actual content removed. Additionally, the information may still appear in other search engines.

Delete old social media accounts

If you have old, inactive accounts that have become obsolete, such as Myspace or Tumblr, you may want to deactivate or delete them entirely. For social media platforms that you use regularly, such as Facebook and Instagram, consider adjusting your privacy settings to keep your personal information to the bare minimum.

Remove personal info from websites and blogs

If you’ve ever published articles, written blogs, or created any content online, it is a good time to consider taking them down if they no longer serve a purpose. If you were mentioned or tagged by other people, it is worth requesting them to take down posts with sensitive information.

Delete unused apps and restrict permissions in those you use

Another way to tidy up your digital footprint is to delete phone apps you no longer use, as hackers are able to track personal information on these and sell it. As a rule, share as little information with apps as possible using your phone’s settings.

Remove your info from other search engines

  • Bing: Submit removal requests through Bing’s Content Removal tool for specific personal information like addresses, phone numbers, or sensitive data. Note that Bing primarily crawls and caches content from other websites, so removing the original source content first will prevent re-indexing.
  • Yahoo: Yahoo Search results are powered by Bing, so use the same Bing Content Removal process. For Yahoo-specific services, contact their support team to request the removal of cached pages and personal information from search results.
  • DuckDuckGo and other privacy-focused engines: These search engines don’t store personal data or create profiles, but pull results from multiple sources. We suggest that you focus on removing content from the original source websites, then request the search engines to update their cache to prevent your information from reappearing in future crawls.

Escalate if needed

After sending your removal request, give the search engine or source website 7 to 10 business days to respond initially, then follow up weekly if needed. If a website owner doesn’t respond within 30 days or refuses your request, you have several escalation options:

  • Contact the hosting provider: Web hosts often have policies against sites that violate privacy laws
  • File complaints: Report to your state attorney general’s office or the Federal Trade Commission
  • Seek legal guidance: For persistent cases involving sensitive information, consult with a privacy attorney

For comprehensive guidance on website takedown procedures and your legal rights, visit the FTC’s privacy and security guidance for the most current information on consumer data protection. Direct website contact can be time-consuming, but it’s often effective for removing information from smaller sites that don’t appear on major data broker opt-out lists. Stay persistent, document everything, and remember that you have legal rights to protect your privacy online.

Remove your information from browsers

After you’ve cleaned up your data from websites and social platforms, your web browsers may still save personal information, such as your browsing history, cookies, autofill data, saved passwords, and even payment methods. Clearing this information and adjusting your privacy settings helps prevent tracking, reduces targeted ads, and limits the amount of personal data websites can collect about you.

  • Clear your cache: Clearing your browsing data is usually done by going to Settings and looking for the Privacy and Security section, depending on the specific browser. This is applicable in Google Chrome, Safari, Firefox, Microsoft Edge, as well as mobile phone operating systems such as Android and iOS.
  • Disable autofill: Autofill provides the convenience of not having to type your information every time you complete a form. That convenience has a risk, though, autofill saves addresses, phone numbers, and even payment methods. To prevent websites from automatically populating forms with your sensitive data, disable the autofill settings independently. For better security, consider using a dedicated password manager instead of browser-based password storage.
  • Set up automatic privacy protection: Set up your browsers to automatically clear cookies, cache, and site data when you close them. This ensures your browsing sessions don’t leave permanent traces of your personal information on your device.
  • Use privacy-focused search engines: Consider using privacy-focused search engines like DuckDuckGo as your default. These proactive steps significantly reduce the amount of personal information that browsers collect and store about your online activities.

Get your address off the internet

When your home address is publicly available, it can expose you to risks like identity theft, stalking, or targeted scams. Taking steps to remove or mask your address across data broker sites, public records, and even old social media profiles helps protect your privacy, reduce unwanted contact, and keep your personal life more secure.

  1. Opt out of major data broker sites: The biggest address exposers are Whitepages, Spokeo, and BeenVerified. Visit their opt-out pages and submit removal requests using your full name and current address. Most sites require email verification and process removals within 7-14 business days.
  2. Contact public records offices about address redaction: Many county and state databases allow address redaction for safety reasons. File requests with your local clerk’s office, voter registration office, and property records department. Complete removal isn’t always possible, but some jurisdictions offer partial address masking.
  3. Enable WHOIS privacy protection on domain registrations: If you own any websites or domains, request your domain registrar to add privacy protection services to replace your personal address with the registrar’s information.
  4. Review old forums and social media profiles: Check your profiles on forums, professional networks, and social platforms where you may have shared your address years ago. Delete or edit posts containing location details, and update bio sections to remove specific address information.
  5. Verify removal progress: Every month, do a search of your name and address variations on different search engines. You can also set up Google Alerts to monitor and alert you when new listings appear. Most data broker removals need to be renewed every 6-12 months as information gets re-aggregated.

The cost to delete your information from the internet

The cost to remove your personal information from the internet varies, depending on whether you do it yourself or use a professional service. Read the guide below to help you make an informed decision:

DIY approach

Removing your information on your own primarily requires time investment. Expect to spend 20 to 40 hours looking for your information online and submitting removal requests. In terms of financial costs, most data brokers may not charge for opting out; however, other expenses could include certified mail fees for formal removal requests, which range from $3 to $8 per letter, and possibly notarization fees for legal documents. In total, this effort can be substantial when dealing with dozens of sites.

Professional removal services

Depending on which paid removal and monitoring service you employ, basic plans typically range from $8 to $25 monthly, while annual plans, which often provide better value, range from $100 to $600. Premium services that monitor hundreds of data broker sites and provide ongoing removal can cost $1,200-$2,400 annually.

The difference in pricing is driven by several factors. This includes the number of data broker sites to be monitored, which could cover more than 200 sites, and the scope of removal requests, which may include basic personal information or comprehensive family protection. The monitoring frequency and additional features, such as dark web monitoring, credit protection, identity restoration support, and insurance coverage, typically command higher prices.

The value of continuous monitoring

The upfront cost may seem significant, but continuous monitoring provides essential value. A McAfee survey revealed that 95% of consumers’ personal information ends up on data broker sites without their consent. It is possible that after the successful removal of your information, it may reappear on data broker sites without ongoing monitoring. This makes continuous protection far more cost-effective than repeated one-time cleanups.

Services such as McAfee Personal Data Cleanup can prove invaluable, as it handles the initial removal process, as well as ongoing monitoring to catch when your information resurfaces, saving you time and effort while offering long-term privacy protection.

Aside from the services above, comprehensive protection software can help safeguard your privacy and minimize your exposure to cybercrime with these offerings, such as:

  • An unlimited virtual private network to make your personal information much more difficult to collect and track
  • Identity monitoring that tracks and alerts you if your specific personal information is found on the dark web
  • Identity theft coverage and restoration helps you pay for legal fees and travel expenses, and further assistance from a licensed recovery pro to repair your identity and credit
  • Other features, such as safe browsing to help you avoid dangerous links, bad downloads, malicious websites, and more online threats when you’re online

So while it may seem like all this rampant collecting and selling of personal information is out of your hands, there’s plenty you can do to take control. With the steps outlined above and strong online protection software in place, you can keep your personal information more private and secure.

Essential steps if your information is found on the dark web

Unlike legitimate data broker sites, the dark web operates outside legal boundaries where takedown requests don’t apply. Rather than trying to remove information that’s already circulating, you can take immediate steps to reduce the potential harm and focus on preventing future exposure. A more effective approach is to treat data breaches as ongoing security issues rather than one-time events.

Both the FTC and Cybersecurity and Infrastructure Security Agency have released guidelines on proactive controls and continuous monitoring. Here are the key steps of those recommendations:

  1. Change your passwords immediately and enable multi-factor authentication. Start with your most critical accounts—banking, email, and any services linked to financial information. Create unique, strong passwords for each account and enable MFA where possible for an extra layer of protection.
  2. Monitor your financial accounts and credit reports closely. Check your bank statements, credit card accounts, and investment accounts for any unauthorized activity. Request your free annual credit reports from all three major bureaus and carefully review them for accounts you didn’t open or activities you don’t recognize.
  3. Place fraud alerts or credit freezes. Contact Equifax, Experian, and TransUnion to place fraud alerts, which require creditors to verify your identity before approving new accounts. Better yet, consider a credit freeze to block access to your credit report entirely until you lift it.
  4. Replace compromised identification documents if necessary. If your Social Security number, driver’s license, or passport information was exposed, contact the appropriate agencies to report the breach and request new documents. IdentityTheft.gov provides step-by-step guidance for replacing compromised documents.
  5. Set up ongoing identity monitoring and protection. Consider using identity monitoring services that scan the dark web and alert you to new exposures of your personal information.
  6. Document everything and report the incident. Keep detailed records of any suspicious activities you discover and all steps you’ve taken. File a report with the FTC and police, especially if you’ve experienced financial losses. This documentation will be crucial for disputing fraudulent charges or accounts.

Legal and practical roadblocks

As you go about removing your information from the internet, it is important to set realistic expectations. Several factors may limit how completely you can remove personal data from internet sources:

  • The United States lacks comprehensive federal privacy laws requiring companies to delete personal information upon request.
  • Public records, court documents, and news articles often have legal protections that prevent removal.
  • International websites may not comply with U.S. deletion requests.
  • Cached copies could remain on search engines and archival sites for years.
  • Data brokers frequently repopulate their databases from new sources even after opt-outs.

While some states like California have stronger consumer privacy rights, most data removal still depends on voluntary compliance from companies.

Final thoughts

Removing your personal information from the internet takes effort, but it’s one of the most effective ways to protect yourself from identity theft and privacy violations. The steps outlined above provide you with a clear roadmap to systematically reduce your online exposure, from opting out of data brokers to tightening your social media privacy settings.

This isn’t a one-time task but an ongoing process that requires regular attention, as new data appears online constantly. Rather than attempting to completely erase your digital presence, focus on reducing your exposure to the most harmful uses of your personal information. Services like McAfee Personal Data Cleanup can help automate the most time-consuming parts of this process, monitoring high-risk data broker sites and managing removal requests for you.

The post How to Remove Your Personal Information From the Internet appeared first on McAfee Blog.

  • ✇Arstechnica
  • A biological 0-day? Threat-screening tools may miss AI-designed proteins. John Timmer
    On Thursday, a team of researchers led by Microsoft announced that they had discovered, and possibly patched, what they're terming a biological zero-day—an unrecognized security hole in a system that protects us from biological threats. The system at risk screens purchases of DNA sequences to determine when someone's ordering DNA that encodes a toxin or dangerous virus. But, the researchers argue, it has become increasingly vulnerable to missing a new threat: AI-designed toxins. How big of a thr
     

A biological 0-day? Threat-screening tools may miss AI-designed proteins.

3 de Outubro de 2025, 17:12

On Thursday, a team of researchers led by Microsoft announced that they had discovered, and possibly patched, what they're terming a biological zero-day—an unrecognized security hole in a system that protects us from biological threats. The system at risk screens purchases of DNA sequences to determine when someone's ordering DNA that encodes a toxin or dangerous virus. But, the researchers argue, it has become increasingly vulnerable to missing a new threat: AI-designed toxins.

How big of a threat is this? To understand, you have to know a bit more about both existing biosurveillance programs and the capabilities of AI-designed proteins.

Catching the bad ones

Biological threats come in a variety of forms. Some are pathogens, such as viruses and bacteria. Others are protein-based toxins, like the ricin that was sent to the White House in 2003. Still others are chemical toxins that are produced through enzymatic reactions, like the molecules associated with red tide. All of them get their start through the same fundamental biological process: DNA is transcribed into RNA, which is then used to make proteins.

Read full article

Comments

© Historical / Contributor

Starmer to unveil digital ID cards in plan set to ignite civil liberties row

‘Brit card’ already facing opposition from privacy campaigners as government looks for ways to tackle illegal immigration

All working adults will need digital ID cards under plans to be announced by Keir Starmer, in a move that will spark a battle with civil liberties campaigners.

The prime minister will set out the measures on Friday at a conference on how progressive politicians can tackle the problems facing the UK, including addressing voter concerns around immigration.

Continue reading...

© Photograph: Alberto Pezzali/AP

© Photograph: Alberto Pezzali/AP

© Photograph: Alberto Pezzali/AP

❌
❌