LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
ai

Former NSA chief Nakasone says agency overhaul is ‘probably needed’

Former National Security Agency Director Paul Nakasone stated that a reported comprehensive reorganization of the agency is likely necessary to address rapidly evolving cyber threats and the competitive landscape in artificial intelligence (AI). Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, made these remarks on Tuesday at VulnCheck's ThreatCon1 conference.

ZeroDay News ·

Source: CyberScoop

Former National Security Agency Director Paul Nakasone stated that a reported comprehensive reorganization of the agency is likely necessary to address rapidly evolving cyber threats and the competitive landscape in artificial intelligence (AI). Nakasone, who led the NSA and U.S. Cyber Command from 2018 to 2024, made these remarks on Tuesday at VulnCheck's ThreatCon1 conference.

Nakasone referenced a September report that detailed the NSA's restructuring, which is said to involve the creation of five new mission organizations. These organizations will reportedly focus on AI, China, cybersecurity, combat support, and global intelligence, with each led by a newly appointed mission director. He expressed encouragement that the agency's leadership recognized the imperative for adaptation given the dramatic changes in the global environment.

However, Nakasone cautioned that the success of such a large-scale institutional change would hinge on its execution. He highlighted the inherent challenges in implementing significant shifts within a large bureaucracy with broad intelligence, cyber, and military responsibilities.

The former director's comments underscore the pressure on intelligence agencies to reorganize around emerging technologies, particularly AI. This involves balancing the need for the United States to maintain leadership in AI development while simultaneously defending against adversaries, such as China, who seek to leverage the technology for their own strategic objectives.

Nakasone specifically pointed to how AI has drastically reduced the "dwell time"—the period between an initial intrusion and an adversary's lateral movement within a system. He noted that in 2018, this dwell time was measured in hours, but by 2025, CrowdStrike data indicated it had fallen to an average of 29 minutes. He emphasized that the traditional defensive mantra of "one minute to recognize, 10 minutes to figure out, and 60 minutes to enact" is no longer sufficient.

Despite the accelerating threat landscape, Nakasone, who serves on the board of OpenAI, suggested that defenders currently possess a "defender's window" in AI. He believes adversaries have not yet fully exploited AI's capabilities against critical infrastructure and sensitive organizations, presenting a temporary advantage for defense.

The ability to adapt also depends significantly on personnel, Nakasone added, noting the competition between government agencies and private companies for technical talent. He cited statistics for the national security workforce, indicating an average age of 47, with half the workforce over 50, only 10% under 30, and 13.5% eligible for immediate retirement. He stressed the importance of valuing government service to attract and retain skilled individuals.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Fake ChatGPT, Gemini, and Claude Ad Portals Capture Credentials and MFA Codes

Cybersecurity researchers have uncovered a human-operated phishing platform designed to impersonate advertising portals for popular artificial intelligence (AI) chatbots. The platform specifically targets users by mimicking ad products for services such as Google Gemini, Anthropic Claude, OpenAI ChatGPT, Perplexity, Meta Muse, and Manus. Its primary objective is to capture user credentials and…

vulnerability

Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

Google has reportedly developed an artificial intelligence agent, named PageBreak, which has identified approximately 500 flaws within Google's own web applications. This development highlights an emerging trend in the cybersecurity industry: the application of AI and deterministic validation methods to automate the discovery of vulnerabilities, assess their exploitability, and provide a…

patch

Wiretapping change sparks big privacy fight in the Golden State

California Governor Gavin Newsom has signed a bipartisan update to the state's wiretapping law, the California Invasion of Privacy Act (CIPA), which will eliminate the ability for private citizens to sue over certain internet-based surveillance. The amendment, known as SB 690, specifically targets the private right to sue websites and mobile applications for unauthorized use of "pen registers"…

zero-day

Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

Security researchers collectively uncovered 32 zero-day vulnerabilities on the first day of the Pwn2Own Ireland 2026 competition, earning a total of $388,500. The event, organized by the Zero Day Initiative (ZDI), aims to identify critical flaws in various products before malicious actors can exploit them.

security

Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

Recent reports indicate the discovery of Linux backdoors actively targeting telecommunications and network appliances within South Korea and Taiwan. These sophisticated backdoors are designed to evade detection by masquerading their malicious traffic as legitimate email services and by impersonating benign system processes. This tactic allows the malware to blend into normal network activity…

security

Microsoft extends the Outlook naughty step with two more file types

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.