ZeroHour

Search: “National Informatics Center”

28 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

SpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the Enterprise

SpyCloud's 2026 survey of 750 security leaders finds compromised non-human identities are the top enterprise entry point, yet only 36% monitor them.

SpyCloud's Identity Threat Report, based on a survey of 750 cybersecurity leaders at organizations with 500+ employees, found compromised non-human identities (31%) were nearly twice as likely as phishing (17%) to be the primary attacker entry point. 68% of organizations reported identity-based events averaging eight each, while 95% believe they have visibility into AI and NHI exposures but only 36% actually monitor them. The report also found 91% use AI tools with internal access but only 56% have formal governance, and introduces an Identity Threat Protection Maturity Model.

CSO Onlineupdated · 6d agofirst · 7d agoIndustry 3 sources

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

Acronis links APT36 (Transparent Tribe) to new backdoors PATCHCORD and SHEETCORD targeting Afghan Telecom and Indian government, defense, and energy networks.

Acronis TRU described an ongoing Pakistan-aligned campaign attributed with moderate confidence to APT36, delivering a previously undocumented C/C++ backdoor named PATCHCORD via fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools. PATCHCORD persists by hijacking browser shortcuts for Chrome, Edge, and Firefox, registers with a single C2 server, and executes shellcode and arbitrary cmd.exe commands. Infrastructure analysis revealed SHEETCORD, a Go backdoor combining SHEETCREEP and PATCHCORD features that uses Google Sheets for C2 and a PowerShell-based remote execution, delivered via a fake site mimicking India's National Informatics Center. APT36 has used PATCHCORD since at least March 2026, including a variant with anti-analysis features used against India's energy sector, and the toolkit includes antnium, GateSentinel, SuperShell, and exploits for CVE-2024-6387.

The Hacker News · Aug 15, 2026Threat actor in the wildCVE-2024-6387

Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

NIST and CISA publish final interagency report with implementation guidance for protecting tokens and assertions from forgery and misuse.

CISA released a final NIST/CISA interagency report guiding federal agencies and cloud service providers on protecting identity assertions, access tokens, and cryptographic mechanisms underlying modern authentication and authorization. It addresses forgery, theft, and misuse of signed tokens that adversaries use for lateral movement and data access in hybrid and multi-cloud, SSO, federation, and API-based environments. The final version updates token validation, secrets management, and detection-at-scale guidance gathered via the Joint Cyber Defense Collaborative, and supports Executive Order 14306 and Secure by Design principles.

CISA Advisories · 1d agoAdvisory

The complex corporate web behind a $3.2 billion AI data center

Ars Technica probes diffuse accountability behind TeraWulf's $3.2B Lake Mariner AI data center after a June fire exposed safety and job gaps.

A June fire at the Lake Mariner data center in Somerset, New York exposed missing alarms, a nonfunctioning suppression system, and dry hydrants, highlighting how responsibility is split across TeraWulf (owner-operator), Fluidstack (operator), Google (lease guarantees and equity warrants), and Anthropic (compute customer). The article details local concerns over the gap between promised 165 permanent jobs and a projected 35-40, socialized grid costs, and Governor Hochul's moratorium on hyperscaler development. Anthropic's February 2026 pledge to cover electricity price increases applies to the site but leaves other commitments unverified.

Ars Technica · AI · 9d agoAI industry

NIST Seeks Public Input on AI-Ready NVD Modernization

NIST is seeking public comment on modernizing the National Vulnerability Database to support AI-powered vulnerability research.

The US National Institute of Standards and Technology announced it is soliciting public input on modernizing the National Vulnerability Database. The initiative aims to make the NVD AI-ready to support AI-powered vulnerability research and analysis.

Infosecurity Magazine · Aug 12, 2026Policy & legal

The push to designate AI as the next critical infrastructure sector

Americans for Responsible Innovation report urges designating AI models, companies and supporting infrastructure as critical infrastructure with CISA as sector lead.

A report from the nonprofit Americans for Responsible Innovation calls for the federal government to declare the AI sector — including frontier model designs, model weights, datacenters, AI hardware and semiconductors — the 17th critical infrastructure sector, with CISA as the lead agency for sector cyberthreats. The authors argue AI is concentrated among a handful of foundation models and interdependent with other sectors, so a single attack on the AI stack could cascade widely, citing incidents like Iranian drone attacks on Amazon datacenters. Former DHS officials note the designation would unlock federal resources such as CDM access and threat intelligence, but warn that picking a lead agency could trigger a bureaucratic turf war with Commerce and Treasury.

CyberScoop · 26d agoAI policy

The AI data center boom is colliding with cities scarred by big industry

Philadelphia activists rally against AI data center construction amid energy and pollution concerns, joining a wave of U.S. city moratoriums.

Residents of Philadelphia's Grays Ferry, home to a former oil refinery, launched the 'No Data Centers in Philly' campaign over pollution, noise, and resource concerns. BloombergNEF projects U.S. data centers will consume more natural gas than Germany and Japan combined by 2035. New York Governor Kathy Hochul signed an executive order pausing permits for large data center projects, and moratoriums have passed in Denver, Indianapolis, Asheville, Charlotte, and Reno.

TechCrunch · AI · 14h agoAI industry

‘We Did Not Invite You.’ Citizens Rage at Town Hall Over Proposed Nuclear AI Data Center

University of Michigan and Los Alamos faced resident backlash over a proposed $1.2 billion hyperscale data center in Ypsilanti Township, Michigan.

The University of Michigan partnered with Los Alamos National Laboratory on a proposed $1.2 billion, 220,000-square-foot hyperscale data center in Ypsilanti Township. Residents at a Wednesday town hall raised concerns about electricity costs, water usage, noise, and the facility's role in nuclear weapons research. Officials noted the project is far smaller than the nearby $56 billion, 1.4-gigawatt OpenAI data center in Saline Township. Los Alamos said no plutonium or weapons production would occur on site, though the facility would support nuclear stockpile modeling.

404 Media · 4d agoAI industry

NCP-ArchPreview Technical Report: Moving towards Latent Space Language Models through Next Concept Prediction

An 8.9B-parameter latent-space language model using next-concept prediction matches OLMo-3-7B pretraining loss with only 51.3% of the training tokens.

NCP-ArchPreview augments next-token prediction with Next Concept Prediction over a product-quantized concept vocabulary built from hidden states, trained jointly end-to-end. The 8.9B model was trained on 5.73T tokens from the Dolma-3 dataset, the largest latent-space language model demonstration to date. It consumes 51.3% of the tokens to reach OLMo-3-7B's final pretraining loss and outperforms it by 2.45 points on the downstream macro-average, including a 5.99-point GSM8K gain. The learned latent space also enables lightweight domain adaptation via a 17M-parameter VQ module and improves speculative drafting accepted length by 4.17%.

Hugging Face daily papers · 7d agoAI research1

AI Infra Summit: NVIDIA Vera Rubin and DSX Platform Advancements Showcase Energy Efficiencies of Optimizing Tokens Per Watt for AI Factories

At AI Infra Summit, NVIDIA showcased Vera Rubin and DSX gains up to 1.4x tokens per megawatt, plus Annapurna, d-Matrix, and Pinterest partnerships.

Ian Buck's AI Infra Summit keynote before 8,000+ attendees emphasized validated agentic tokens per megawatt as the emerging AI infrastructure metric. Announcements include Amazon's Annapurna Labs collaborating on NVHBM custom high-bandwidth memory, d-Matrix integrating NVLink Fusion with Raptor XPUs, and Pinterest using Blackwell plus Dynamo inference software for conversational visual discovery. Lambda reported 23% better performance per watt with DSX MaxLPS on Blackwell servers, running 19 nodes on a 16-node power budget. NVIDIA says DSX MaxLPS combined with Groq 3 LPX on Vera Rubin NVL72 targets up to 35X token throughput per megawatt versus GB200 NVL72 for 2-trillion-plus-parameter models.

NVIDIA Blog · 19h agoAI industry

Thorough reorganization at NSA will create five 'mission centers,' including cyber and AI

NSA is reorganizing into five mission centers covering China, cybersecurity, AI, combat support and global intelligence, with full capability targeted by January.

NSA Director Gen. Joshua Rudd announced a sweeping reorganization replacing existing directorates with five mission centers focused on China, cybersecurity, artificial intelligence, combat support, and global intelligence. A 30-day implementation clock has started, and the centers are expected to reach full operational capability by January. Officials acknowledge the rapid realignment will 'break things' in the agency's bureaucracy; this is the largest restructuring since the NSA21 effort roughly a decade ago, which was widely viewed as a failure.

The Record · 2d agoPolicy & legal

GOP issues stark warning to AI companies

Axios reports the US Republican Party issued a stark warning to AI companies, apparently tied to a data-center memo ahead of elections.

An Axios article titled "GOP issues stark warning to AI companies" was published on August 19, 2026; its URL suggests coverage of a Republican memo on data centers and AI in elections. The provided source text contains only the headline and engagement metrics, so no substantive details about the warning's content are available.

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

CISA and NIST published NIST IR 8587, final guidance for protecting identity tokens from forgery, theft, replay, and signing-key compromise.

NIST Interagency Report 8587 (September 15, 2026) expands the IA-13 'Identity Providers and Authorization Servers' control from NIST SP 800-53 R5.1.1, guiding federal agencies and cloud providers on SSO, identity federation, and machine-to-machine authentication. It requires hardware-backed signing-key storage for moderate-impact systems, 90-day key rotation for high-impact systems, token lifetimes under one hour, and sender-constrained mechanisms such as mutual TLS and DPoP. The report cites incidents including forged SAML assertions that exposed over 60,000 emails from a federal agency. It also extends guidance to agentic AI systems using signed tokens and urges post-quantum cryptography migration planning.

Cyber Security News · 18h agoAdvisory1

AI labs have a data trust problem that their policies haven't solved

Nvidia, Palantir, and Booz Allen restrict Anthropic's Fable over data-retention distrust, exposing gaps in AI labs' customer data policies.

Nvidia limits Anthropic's Fable to non-sensitive work and runs its own Nemotron models for internal tasks, while Palantir blocks Fable deployment until Anthropic grants irrevocable zero-data-retention guarantees, and Booz Allen bans it for proprietary cybersecurity work. John Schulman and researcher Sarah Hooker explain that labs can still extract customer IP from metadata, user traces, and synthetic data even under zero data retention. The trust crisis crystallized around Tristan Buckmaster's accusation that OpenAI's Codex absorbed his Navier-Stokes drafts, though OpenAI later stated his prompts could not have influenced its model.

The Decoder · 18h agoAI industry

Notes on gotchas while migrating 35kb preprompts from Opus to self-hosted Ollama

Opinion piece urges migrating 35KB preprompts from Anthropic/OpenAI to self-hosted Ollama, citing session privacy risks and safety filters blocking security research.

The author documents gotchas migrating 35KB preprompts from Claude Opus to self-hosted Ollama, motivated by fears that frontier providers train on user sessions, citing the OpenAI Navier-Stokes controversy. The piece argues inference providers cannot audit their own retention or training pipelines and that only self-hosted hardware offers verifiable privacy. It also criticizes frontier safety filters for refusing vulnerability research tasks and calls for models that support exploitability testing in CI/CD pipelines.

Voters mostly don’t like AI and data centers, but neither party seems to have an edge

NYT/Siena poll of 1,503 likely voters finds 61% oppose AI data center construction, yet the issue ranks below 1% among midterm priorities.

A New York Times/Siena University poll of 1,503 likely voters conducted in early September found 61% oppose constructing data centers to power AI, with only 14% strongly supportive. Opposition drivers include environment/water usage (32%), local community impact (21%), and general distrust of AI (18%); 56% of opponents favor limits while 38% want a total ban. Trump 2024 voters split nearly evenly (49% support vs 45% oppose) while Harris voters opposed at 74%. Despite the sentiment, AI and data centers registered under 1% as a top midterm issue for most demographics, and neither party holds a clear trust advantage (42% Republicans vs 40% Democrats).

The Verge · AI · 12h agoAI policy

NIST wants to overhaul its vulnerability database for the AI age

NIST issued a Federal Register RFI seeking public input on overhauling the National Vulnerability Database for AI-scale, machine-consumable security data.

NIST published a request for information arguing the National Vulnerability Database must adapt as LLMs increasingly find and exploit vulnerabilities at machine scale. The RFI seeks input on integrating automation into vulnerability reporting, faster dissemination to defenders, and transparency and auditability in AI-driven decisions. It follows the White House-backed Gold Eagle clearinghouse at Treasury and the VINCE program with Carnegie Mellon's Software Engineering Institute for AI-discovered vulnerability reports.

CyberScoop · Aug 11, 2026Policy & legal

Strengthening democratic oversight in national security

OpenAI launched an initiative to strengthen democratic oversight of AI in national security, providing government institutions with tools, training, and expertise.

OpenAI announced an initiative focused on strengthening democratic oversight of AI within national security contexts. The effort will support government institutions with tools, training, and expertise. The announcement was published on August 18, 2026.

OpenAI News · 28d agoAI industry

Zelensky appoints former police chief to lead Ukraine’s cyber coordination center

Zelensky appoints former police chief Ihor Klymenko to head Ukraine's National Cybersecurity Coordination Center amid broader security leadership reshuffle.

Ukrainian President Volodymyr Zelensky appointed Ihor Klymenko, former National Police head, interior minister, and NSDC secretary, to lead the National Cybersecurity Coordination Center (NCCC). The NCCC, created in 2016 under the National Security and Defense Council, coordinates government agencies' responses to major cyberthreats including Russian operations. The appointment comes amid a wider reshuffle of Ukraine's defense and security leadership.

The Record · 20h agoPolicy & legal

Securing the Infrastructure of Intelligence

NVIDIA positions AI factories combining chips, networking, power and data as the defining infrastructure of the AI economy needing full-stack security.

NVIDIA's blog argues that AI factories are the defining infrastructure of the AI era, transforming energy and data into intelligence that powers businesses and countries. It frames compute as revenue and lists the full stack of critical resources required: advanced chips, packaging, memory, networking, land and power. The piece is a corporate positioning article about securing this infrastructure, with no specific incident or product announcement detailed in the excerpt.

NVIDIA Blog · 29d agoAI industry

OpenAI supports California’s bill to advance youth AI safety

OpenAI announces support for California SB 1119, a bill mandating age-appropriate AI safeguards for teenage users.

OpenAI publicly endorsed California Senate Bill 1119, which seeks strong, age-appropriate AI safeguards for teens. The company framed its support as advancing youth safety while preserving opportunities for teens to learn, create, and explore with AI tools.

OpenAI News · 16d agoAI policy

National Life Group CISO expects more vulnerabilities in six months than in thirty years

National Life Group CISO Becky Palmer says agentic AI resolves four of five SOC investigations and urges AI-speed patching practices.

In a Help Net Security interview, National Life Group CISO Becky Palmer argues frontier AI will uncover more vulnerabilities in the next six months than in the last thirty years, compressing time from disclosure to weaponized exploit from weeks to hours. She reports agentic AI in her SOC resolves 4 of 5 investigations without human escalation, saving hours daily on enrichment and summarization. She also details compensating controls such as virtual patching, least-privilege restrictions, and heightened monitoring, plus procurement questions to separate working AI products from wrappers.

Help Net Security · 14d agoIndustry

OpenAI’s letter to Governor Abbott on responsible AI infrastructure in Texas

OpenAI sent Texas Governor Greg Abbott a letter committing to responsible AI infrastructure development in the state.

OpenAI published a letter sent to Texas Governor Greg Abbott outlining its commitment to responsible AI infrastructure in Texas. The letter supports reliable, transparent growth that benefits Texans. It is a government-relations communication with no new technical or safety disclosures.

OpenAI News · Aug 10, 2026AI industry

Nozomi Compass helps industrial teams manage OT assets and vulnerabilities

Nozomi Networks launched Compass, an OT asset and vulnerability management platform unifying asset records, remediation workflows, and compliance evidence for industrial teams.

Nozomi Networks announced Compass, an OT asset and service management platform built on real-time first-party asset data from its Vantage cyber-physical security platform. It provides OT-native workflows, governed change approvals, consequence-based risk scoring, and continuous audit-ready compliance evidence mapped to NERC CIP, IEC 62443, NIS2, and TSA. The platform integrates with EAM, CMDB, ITAM, ITSM, SIEM, and SOAR tools and is designed to safely support AI-driven and agentic OT workflows with human oversight.

Help Net Security · 1h agoTools

How law firm Gilbert + Tobin governs and scales AI with OpenAI

OpenAI details how law firm Gilbert + Tobin scales ChatGPT Enterprise and Codex firm-wide under CEO-led governance with human accountability.

OpenAI published a customer story describing Gilbert + Tobin's adoption of ChatGPT Enterprise and Codex across the law firm. The firm pairs executive-level commitment with formal governance and human accountability to expand AI use in legal workflows. The piece is a promotional case study, with no new product capabilities or research announced.

OpenAI News · 15d agoAI industry1

Quantifying IIoT Sensor Node Criticality by Fusing its Data Criticality and Security Vulnerability

Researchers propose a Dempster–Shafer framework fusing IIoT sensor data criticality with CVSS 4.0/3.1 vulnerability scores to rank node criticality.

The paper introduces a framework that evaluates Industrial IoT sensor node criticality by fusing data criticality and cybersecurity vulnerability scores using Dempster–Shafer (D-S) theory. It was validated on a dataset from red wine production and is claimed to generalize to other industrial settings with minimal modification. Results show criticality rankings derived from CVSS 4.0 scores differ significantly from those derived from CVSS 3.1, underscoring how vulnerability scoring methodology affects security prioritization.

arXiv cs.CR · 7d agoResearch