LIVE · cybersecurity feed
Live wire
Manic: The Android Malware That Exfiltrates Data Even When the Phone Is OfflineNSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCsCritical Elementor Pro bug exposes WordPress sites to RCE attacksThe push to designate AI as the next critical infrastructure sectorCritical Zimbra RCE flaw now actively exploited in attacksExploitation Expected for Critical Authentication Bypass Patched in Citrix NetScalerCVE-2026-19478 · Critical GitLab Flaw Exploited Shortly After DisclosureCVE-2026-32475 · Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code8,539 reasons to rethink how vulnerabilities get patched'Not a theoretical risk,' feds warn as attackers use AI-made code to hack critical infrastructure controllers
security

Calling on Cyber Pros to Help Defend City Hall

Government agencies with smaller budgets need support — and here's how you can help.

zeroday.news ·

A recent report highlights a growing need for cybersecurity professionals to volunteer their expertise to assist local government agencies, particularly those operating with limited financial resources. The call to action emphasizes that many municipal entities struggle to maintain robust cyber defenses due to budgetary constraints, making them vulnerable targets for various threats.

The underlying mechanism of this vulnerability often stems from a lack of dedicated security staff, outdated infrastructure, and an inability to invest in advanced protective technologies or comprehensive training programs. Unlike larger federal or state organizations, local governments frequently operate with lean IT teams, many of whom are generalists rather than specialized cybersecurity experts. This leaves critical public services and sensitive citizen data exposed to risks ranging from ransomware and data breaches to sophisticated state-sponsored attacks.

Products commonly affected in such environments include legacy systems that are difficult to patch or update, as well as widely used commercial off-the-shelf software that may not be configured with optimal security settings. Many smaller agencies also rely on cloud services, which, while offering scalability, require specific expertise to secure properly against misconfigurations and access control issues. The scope of potential impact is broad, encompassing disruption to essential services like utilities, emergency response, and public records, alongside the compromise of personally identifiable information (PII) of residents.

Typical mitigation guidance for this class of issue often involves implementing foundational cybersecurity practices. These include regular software updates and patching, strong access controls, multi-factor authentication, employee security awareness training, and robust backup and recovery strategies. However, the challenge for under-resourced agencies is often the human capital required to effectively implement and maintain these controls.

This is where the reported call for volunteer professionals becomes critical. Cyber professionals can contribute by offering their time to conduct security assessments, help develop incident response plans, assist with system hardening, or provide training to existing IT staff. Such pro bono efforts can significantly bolster the defensive posture of these agencies, bridging the gap between their operational needs and their financial limitations.

The broader context for this initiative is the increasing recognition that cybersecurity is a collective responsibility, extending beyond individual organizations to the community level. As cyber threats become more pervasive and sophisticated, the weakest links in the digital infrastructure can have cascading effects. Protecting local government infrastructure is not just about safeguarding data; it is about preserving the integrity of democratic processes and ensuring the continuity of vital public services.

This reported appeal underscores a critical gap in national cybersecurity resilience, where smaller, often overlooked entities represent significant points of vulnerability. Leveraging the expertise of the private sector and the broader cybersecurity community through volunteerism is presented as a practical and immediate strategy to address these systemic weaknesses and enhance the overall security landscape for public sector operations.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting. The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

malwarehigh

Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

Manic Android malware combines banking fraud and spyware, using a Bluetooth relay to steal data even when devices are offline. ThreatFabric’s Mobile Threat Intelligence team has identified a new Android malware, dubbed Manic, which has been active in the wild since at least February 2026. The researchers state that the malware is still under development […]

ai

Detailed Timeline of OpenAI’s Cyberattack on Hugging Face

OpenAI presented details of its AI’s model’s cyberattack on Hugging Face at Black Hat last week. Simon Willison details the timeline. It’s really interesting to read through—and really impressive cyberoffense work.

vulnerability

N-able Bug Exposes Password Vault Master Keys

The popular "Passportal" password manager, favored by MSPs and SMBs, remains risky even after its patch, thanks to its cloud-based design. Should these products stay away from the cloud entirely?

aicritical

NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs

NSA, CISA, FBI, DOE, and EPA warn of active AI-assisted attacks against Siemens S7 PLCs across US critical infrastructure sectors. Five U.S. federal agencies issued a joint advisory this week warning of an active hacking campaign against Siemens S7 Series programmable logic controllers. The advisory, CISA AA26-231A, is co-signed by NSA, FBI, DOE, and EPA […]

security

Retail theft bill spurs ‘very large and very dangerous’ surveillance fears

The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. The post Retail theft bill spurs ‘very large and very dangerous’ surveillance fears appeared first on CyberScoop.