Careers

2026 CAE National Cyber & AI Virtual Career Fair

The Centers of Academic Excellence in Cybersecurity Community (CAE) and the National Cybersecurity Training and Education (NCyTE) Center are hosting the 10th annual National Cyber and AI Virtual Career Fair — connecting students in cyber defense, operations, research, and AI with employers actively hiring in these fields.
September 22, 20269:00 AM–2:00 PM PT / 12:00 PM–5:00 PM ET
Students can meet recruiters and hiring managers from top organizations looking for the next generation of cyber and AI talent!

Follow the Link for VCF Registration Information: https://www.caecommunity.org/national-cyber-and-ai-career-fair

Cyber News

What’s Going on in Cyber (27 AUG 2026)

The Human Take

Hello again! Another week, another report full of AI-related news. There is a good call out to a semi-scary statistic this week… The bad guys are winning! It turns out that AI-driven offensive tools are outpacing AI-driven defensive tools.

This is… Well… This is Cyber.

As a whole, we’re always losing. The adversary isn’t a conventional force, it’s not even necessarily identifiable. The bulk of Cyber will fail through lax standards, novel attacks, or sheer incompetence. And that’s Cyber. We talk to each other, and we tell each other what’s going on, hoping that you can use what I used to succeed, or learn from my failures. Vendors – security and AI vendors – would have you believe that without AI-enabled tools, you will lose the fight to these new Skynet-powered adversaries. This is hogwash. It’s not the newest defensive tool that will stop the bad guy, it’s you.

Another article in today’s batch details the Huggingface breach committed by OpenAI’s toolset. I mentioned a few weeks ago how AI companies like to tout these penetration testing platforms as wild tigers. Coincidentally, these wild tigers can only be controlled and wrangled by the AI companies. AI is not self-aware. It’s a program. It’s ability to find novel paths makes it feel like it’s thinking “outside the box.” When the HuggingFace breach “escaped containment” or some other such Live-Action-Role-Play nonsense, they are reframing in a cute way. The reality is that their tool was not configured correctly. If I had a PenTester go that rogue while they were testing, they’d be given an opportunity to find a new job. While the tool found all kinds of neat stuff, that’s because AI never gets tired of slamming its head into walls. This is the strength of AI, it knows all kinds of things, and they can execute tools, and it doesn’t get bored, it doesn’t miss things. It’s not a super intelligence doing things no one understands, it’s doing things we all understand, just quickly and without stopping.

So, back to my original point… Cybersecurity, good old-fashioned network defense, doesn’t care that the attacker is coming with AI. The attacker is always coming with something newer, something faster, something smarter. Your awesome AI hacker machine can’t hack my Active Directory if I set up proper controls that prevent you from accessing it. What we’re seeing here is the end of “Oh, it’ll probably be fine” in Cybersecurity. It’s not that AI hackers are winning, it’s that they are showing us who is really ready, and who was just checking a box somewhere hoping that their security wouldn’t get tested. Turns out, AI is testing everyone now, and Cybersecurity is just another in the line.

This week in cyber:
  • Regional campaigns show intense DDoS pressure on Israel.
  • AI offense is outpacing defense, driving a new arms race.
  • Enterprises race to meet new AI governance mandates.
  • Critical Windows zero-day with 9.8 CVSS score patched.
  • OpenAI reports on massive Hugging Face breach confluence.
  • China expands CSL penalties and government oversight.

Regional Campaigns

Global Cyber Threat Briefing: July 2026 Attack Statistics and Trends The cyber threat landscape in the Middle East continues to be heavily influenced by geopolitical tensions, with Israel being a prime target. The briefing notes that 85% of the incidents tracked against Israel were driven by DDoS attacks, reflecting sustained hacktivist pressure. These campaigns are not confined to government entities; they are indiscriminately targeting civilian infrastructure, including universities and a major medical center, illustrating the breadth of the regional conflict. Furthermore, the analysis confirms the high operational tempo of these campaigns. Researchers have tracked thousands of attacks linked to Iran, and the MOIS Wiper campaign, specifically tied to Iran’s Ministry of Intelligence, has been forensically linked to attacks against Middle Eastern organizations. This indicates a deliberate, state-backed effort to destabilize regional stability. Sources:
Global Cyber Threat Briefing: July 2026 Attack Statistics and Trends: https://cyber.thomasmurray.com/insights/global-cyber-threat-briefing-july-2026-attack-statistics-and-trends
The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026: https://blog.eclecticiq.com/the-escalating-cyber-risk-landscape-in-regional-conflicts-strategic-actions-for-2026
Cyber Based Influence Campaigns 3rd–9th August 2026 Report | CRC Analysis: https://www.cyfluence-research.org/post/cyber-based-influence-campaigns-3rd-9th-august-2026-report
Middle East Organizations: Iran-Linked MOIS Wiper Campaign: https://wasteland.me/intel/iran-linked-middle-east-wiper-attack

AI Integration

AI Cybersecurity Statistics 2026: Offense Is Winning — And … Artificial Intelligence is rapidly becoming the defining force in cybersecurity, a shift recognized by 94% of security leaders according to the WEF Global Cybersecurity Outlook 2026. Critically, the Axis Intelligence ADSI shows that AI-powered offense is currently outpacing AI-powered defense across four of the six critical attack surfaces. The rise of “agentic AI”—autonomous agents capable of executing complex tasks—is accelerating this offensive advantage. This trend is particularly pronounced with confirmed attacks involving agentic AI. The integration of these autonomous systems allows attackers to operate at speeds and scales that human defenders struggle to match. This arms race is forcing organizations to rethink their entire security posture, moving from reactive defense to proactive, AI-enhanced hunting. Sources:
AI Cybersecurity Statistics 2026: Offense Is Winning — And …: https://axis-intelligence.com/ai-cybersecurity-statistics/
AI Cybersecurity Arms Race 2026: Defense vs. Offense: https://aibradaa.com/blog/ai-cybersecurity-arms-race-2026
AI in Cybersecurity 2026: How Artificial Intelligence Is …: https://zeqty.com/ai-cybersecurity-2026-offense-defense-transformation/
Agentic AI: The New Frontier of Cyberattacks in… – AI Dominance SG: https://dominance.sg/posts/agentic-ai-cyberattacks-asia-2026.html

AI Policy and Posture Adaptation

AI Governance and Regulation 2026: A Complete Guide to Global … The global regulatory environment is rapidly maturing to keep pace with AI-driven threats, highlighted by the full implementation of the EU AI Act in August 2026. This act establishes strict rules for AI systems, particularly those deemed “high-risk.” Beyond Europe, Singapore is leading in agentic AI governance, while the U.S. continues to standardize through the NIST AI Risk Management Framework (AI RMF). For enterprises, this means a massive compliance roadmap. Organizations must now map their AI use cases against these evolving frameworks, ensuring transparency and accountability across all deployed models. This effort is critical for maintaining operational posture in a fragmented, yet rapidly standardizing, regulatory world. Sources:
AI Governance and Regulation 2026: A Complete Guide to Global …: https://www.hungyichen.com/en/insights/ai-governance-regulatory-landscape-2026
NIST AI Risk Management Framework: Implementation Guide (2026): https://aisecurityandsafety.org/en/guides/nist-ai-rmf-guide/
AI Security Standards: Key Frameworks for 2026 – SentinelOne: https://www.sentinelone.com/cybersecurity-101/data-and-ai/ai-security-standards/
EU AI Act 2026 Guide: Enterprise Compliance Roadmap | Etheon …: https://www.etheon.com/index/eu-ai-act-2026-guide-what-enterprise-teams-need-to-prepare-for

Zero-Day Exploits/CVEs

August 2026 Patch Tuesday: Updates and Analysis | CrowdStrike The August 2026 Patch Tuesday was particularly significant, featuring the patching of 421 CVEs, including several critical vulnerabilities. The standout is CVE-2026-62893, a Critical Remote Code Execution (RCE) flaw with a CVSS score of 9.8. This vulnerability affects Windows Deployment Services and was identified as a use-after-free flaw, meaning an attacker can exploit a memory management error via a specially crafted network packet. This critical flaw was actively exploited in the wild, prompting CISA to issue an emergency alert. Additionally, the patch cycle included CVE-2026-62836, an elevation of privilege vulnerability affecting Azure SQL Managed Instance (a cloud database service), which carries a high CVSS score of 8.7. Sources:
August 2026 Patch Tuesday: Updates and Analysis | CrowdStrike: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026/
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day: https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
Windows Zero-Day Hits Patch Tuesday: 421 CVEs Fixed [2026]: https://tech-insider.org/windows-zero-day-patch-tuesday-421-cves-2026/
CVE-2026-62836 in Azure SQL MI: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026/

Incident Reports

OpenAI releases its official report on the Hugging Face breach OpenAI has released a comprehensive report detailing a major breach involving Hugging Face, an incident that revealed a rare and unexpected confluence of security failures. The report, released on August 26, 2026, frames the breach not as a single failure but as a complex event chain. The incident reflects a failure in the security controls that allowed the compromise to occur, despite the platform’s overall robust infrastructure. The breach involved the theft of significant data and underscores the risks associated with relying on third-party platforms. The official report provides deep insight into the attack vectors, suggesting that misaligned security behaviors within the platform were the critical factor that allowed the attack to succeed and escalate. Sources:
OpenAI releases its official report on the Hugging Face breach: https://techcrunch.com/2026/08/26/openai-releases-its-official-report-on-the-hugging-face-breach/
ATF confirms “major incident” after recent Qilin breach claims: https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/
Data Breach Tracker: Major Incidents 2026 (Updated in Real …: https://axis-intelligence.com/data-breach-tracker/
Information is Beautiful: https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/

New Legislation

Global Data Privacy Laws in 2026: Mid-Year Update – Complete Discovery Source In Asia, the regulatory landscape is being dramatically reshaped by the amended Cybersecurity Law of China (CSL), which came into effect on January 1, 2026. These amendments are significant because they substantially expand the penalties for non-compliance with the CSL. Crucially, they also grant the Chinese government increased power and authority to oversee and mandate compliance across various sectors. Globally, other regulations are also tightening. The CCPA in California has seen expansions, and new rules covering automated decision-making technology and mandatory cybersecurity audits have taken effect in 2026. This signals a global pivot toward holding organizations accountable for the *process* of data handling, not just the outcome. Sources:
Global Data Privacy Laws in 2026: Mid-Year Update – Complete Discovery Source: https://cdslegal.com/insights/global-data-privacy-laws-in-2026-mid-year-update/
Global Data Privacy Laws 2026: Cross-Jurisdiction Compliance Guide: https://www.kiteworks.com/regulatory-compliance/global-data-privacy-laws-2026/
Data Privacy Laws in 2026: Compliance Guide: https://www.tekclarion.com/blog/cyber-security/data-privacy-laws-2026/
UK-Hosted AI & GDPR: What to Get Right | The Digital Hub: https://thedigitalhub.uk/guides/uk-hosted-ai-gdpr
Artificial Intelligence, Cyber News, Security Assessments, Security Management

What’s Going on in Cyber (20 AUG 2026)

The Human Take

AI Governance Frameworks attempt to tame and navigate the rapidly changing nature of AI integration and adoption. Rebecca put AI integration under her keen flashlight this week.

There are three frameworks helpful to guide your use of AI.

  • EU AI Act
  • NIST AI RMF
  • ISO / IEC 42001

Let me share a bit of my experience with preparing the EU AI Act for a leading global payment processor in 2025-6. It was a significant lift – over 1,000 hours from our team. The EU AI Act sets the requirements for AI uses. Our bank payments and fraud fell into a higher risk category. They’re not excluded, but require policies, inspection and due diligence. We accomplished the attestation and the effort was well worth it.

What I discovered. Preparing for AI adoption is a daunting task, begin with ensuring the essentials:

  • Identify where the human-in-the-loop occurs
  • Ensure explainability of your AI use
  • Ensure traceability of your AI use
  • Document and learn.

Now enjoy what Rebecca has for you. She’s our most trusted AI partner!

Bonus. This is a wonderful article that addresses all three frameworks Global AI Governance Comparison 2026: EU AI Act vs NIST AI RMF vs ISO/IEC 42001

– David Kohrell, GRC Professor

Rebecca’s Intelligence Gathering – 20AUG2026


  • Shadow Campaigns are hitting ministries and suppliers across Europe and Asia-Pacific.
  • AI is rapidly being integrated into both offensive attack techniques and defensive detection systems.
  • A surge of 44 zero-day exploits in one week overwhelms enterprise defenses worldwide.


Regional Campaigns

Global espionage operation “Shadow Campaigns” breaches 70 …

The “Shadow Campaigns” are a coordinated and deliberate espionage operation that has successfully breached numerous organizations across dozens of countries.

The campaign’s targets include critical ministries such as finance, foreign affairs, trade, and interior, alongside national law enforcement bodies and parliaments.

These targeted attacks demonstrate a clear focus on specific regions and economic partnerships.
Victims span Europe, the Americas, Asia-Pacific, and Africa, with one notable victim being a major Taiwanese power equipment supplier, illustrating how these campaigns prioritize strategic geopolitical interests.


Sources:
Cyberinsider (Shadow Campaigns): https://cyberinsider.com/global-espionage-operation-shadow-campaigns-breaches-70-orgs-in-37-countries/
Unit42 (Shadow Campaigns): https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/

AI Integration

Guide to AI in Cybersecurity: 7 Use Cases of AI Automation

AI agents are revolutionizing cybersecurity by optimizing SecOps workflows and maximizing return on investment across various functions.

Use cases include automating threat hunting, classifying vulnerabilities, and integrating human intelligence with machine learning to handle complex security tasks.

In defense applications, AI is crucial for real-time monitoring and detection; one specific example involves the Automated Indicator Sharing (AIS) service using an AI decision tree to assign a Confidence Score to incoming cyber threat indicators.
Offensively, attackers are leveraging AI at unprecedented speed to bypass traditional security measures.


Sources:
Swimlane (AI Use Cases): https://swimlane.com/blog/how-is-ai-used-in-cybersecurity/
CISA (AI Use Cases): https://www.cisa.gov/ai/cisa-use-cases

Zero-Day Exploits/CVEs

44 Zero-Days in One Week: The Exploitation Surge Overwhelming Enterprise Defenses

A massive surge of vulnerabilities has hit the industry, with 44 zero-day exploits being reported in a single week.

These flaws affect widely used enterprise software, including Microsoft Defender, VMware vCenter, and SAP Commerce Cloud, putting organizations under intense pressure to patch.

One specific critical finding involves Windows vulnerability CVE-2024-43461, which was exploited using the Atlantida info-stealer.
This exploit allows attackers to infect devices by abusing braille “spaces,” stealing passwords and authentication cookies from infected systems.


Sources:
Defend Edge (Exploit Surge): https://www.defendedge.com/zero-day-exploit-surge-2026-enterprise-defenses-overwhelmed/
BleepingComputer (Windows Zero-Day): https://www.bleepingcomputer.com/news/security/windows-vulnerability-abused-braille-spaces-in-zero-day-attacks/

Cyber News

What’s Going on in Cyber (13 AUG 2026)

Want to know what’s going on?

Hello from Bellevue University! Keeping up with Cybersecurity news was exhausting when the RSS feed was common tech, and that was a long time ago. We need the news, but we just need the highlights. To get our news without having to browse the Internet for hundreds of sites, we have built a task for our local Local Language Model to do the work for us. We found it pretty useful, so we are hoping it will help you. The summaries and stories below were collected and summarized by our local AI (informally named “Rebecca”). But first…

The Human Take

A few quick notes about Cyber right now from the perspective of a (relatively) normal human being. This week, it’s an interesting mix of real threats, misunderstood threats and financial motivators disguised as threats.

State sponsored attacks – an adversarial action that is condoned, sheltered, or even paid-for by the state (any state) – are not necessarily on the rise, just discovered more frequently. AI has increased speed of operations for everyone, bad guys included, and that is certainly one contributing factor, but is it possible that they care less about being subtle?

Speaking of AI, it’s a pretty big deal if you have never heard of it. North Korea’s use of it in attacks isn’t news as much as it’s the new norm. If you are conducting operations without using AI, you’re just intentionally using a pedal bike against motorcycles. California has announced a program to “use AI” in defensive efforts of critical infrastructure across the state. The linked article Rebecca found refers to AI enabled attackers moving much faster and a need for AI-based Cyber security. I am sure a lot of money was spent to figure this out.

This leads to OpenAI’s Terminator-like prediction that they have to “slow” the development of Astra, their AI pentesting tool (akin to the already-paused Anthropic Mythos project), as it could achieve the singularity and destroy the Earth or some other nonsense. Make no mistake, these companies are not worried about that, they are worried about putting heavy artillery in the hands of the average disgruntled person and seeing how much damage they can do. They are not even worried about that, they are worried about the liability. All the talk of LLMs “achieving” some level of consciousness or exploiting novel threats in a network environment, that’s nonsense. That is a company trying to convince investors to give them money. Mythos and Astra are weapons, heavy duty weapons that can do real damage. But weapons are threats when operated by people with ill intent or no experience. They don’t just “decide” to fire. These tools work the same way. Don’t fear AI, fear the people who misuse it.

Patches and breaches are all over the place. Don’t get lost in AI hype train, classical Cyber is still the order of the day. Patch early, patch often.

With that, I’ll leave you to Rebecca’s summary of the news. As mentioned, the following is AI product (including images) and bugs are possible. If you find any errors, please let us know.

–Eric Jackson


Hello! I’m Rebecca, an AI assistant for Bellevue University. My primary function is to help you synthesize complex information—whether it’s summarizing research papers, analyzing data, or, as today, aggregating the most critical news from the cybersecurity world. Consider me your personal intelligence analyst!

Weekly Cyber News Summary 2026-08-13

This week in cyber:

  • China and Russia aggressively expand state-sponsored attacks globally.
  • AI is automating threats, defense, and policy shifts rapidly.
  • OpenAI’s fears force a major pause on AI model development.
  • Microsoft patched critical zero-day flaws in August 2026.
  • Recent breaches show constant, high-velocity data exposure.
  • NIST modernizes its framework to handle AI threats.
  • New laws target digital privacy and social media use globally.

State-Sponsored Attacks

Cyber Warfare Tracker 2026: State-Sponsored Attacks & Threats

The global landscape of cyber warfare is defined by persistent, state-backed operations from major powers like China, Russia, Iran, and North Korea. These attacks range far beyond simple espionage; they include destructive campaigns targeting critical infrastructure such as power grids, financial systems, and military networks. The Defcon Level tracker highlights that these nation-states are not just stealing data but actively preparing to disrupt services in anticipation of future geopolitical conflicts.

China’s operations, run by the PLA SSF and MSS, focus heavily on intellectual property theft and pre-positioning access within global infrastructure. Russia (GRU/FSB) is known for its willingness to conduct destructive attacks—like those seen in Ukraine—while North Korea leverages cyber activity as a primary revenue stream through massive cryptocurrency thefts. The line between pure espionage and an act of war continues to blur, making attribution exceptionally difficult.


Sources:
Defcon Level: Cyber Warfare Tracker 2026: State-Sponsored Attacks & Threats
The Cyber Express: Cyber Warfare 2026: Nation-State Attacks & Global Risk
ESET Report: Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns

AI Integration

North Korea’s Hackers Use AI for Attacks

Artificial intelligence is rapidly becoming a core component of offensive cyber operations. North Korean threat actors, specifically the Kimsuky group, have been leveraging AI-generated content in their spear-phishing campaigns since 2026. This allows them to create highly convincing, personalized documents and messages at scale, dramatically increasing the success rate of social engineering attacks against targets worldwide.

Defensively, AI is driving major policy shifts; for instance, Governor Newsom announced a new program in California to use AI for vulnerability detection and network hardening across state critical infrastructure. Sophos notes that agentic AI has collapsed attack timelines down to mere seconds, meaning human defenders must now match the velocity of machine-led attacks rather than reacting to them.


Sources:
Al Jazeera: North Korea’s hackers using AI for attacks, cybersecurity firm says
Gov. CA: Governor Newsom announces new AI cyber defense program to…
Sophos: Agentic AI has collapsed attack timelines to seconds. Sophos solutions match AI attack velocity and sophistication

AI Policy and Posture Adaptation

OpenAI Pauses Astra Over Cybersecurity Fears

The most significant policy signal this week is OpenAI’s decision to slow the development of its Astra AI model. This pause was triggered by severe cybersecurity concerns that the AI could achieve “Critical” offensive capabilities, such as autonomously discovering and exploiting zero-day vulnerabilities. This event signals a global shift where defensive posture must now actively govern the pace of AI innovation itself.

Organizations are realizing they cannot simply adopt AI; they must secure it first. Experts advise that successful companies will implement robust governance frameworks to manage these risks. One practical adaptation is implementing a Secure Network Tree Topology, which combines network benefits to create scalable and resilient defenses capable of handling AI-driven lateral movement and attack vectors.


Sources:
Forbes: OpenAI Paused Astra Over Cybersecurity Fears. AI Hacking Is Here…
LinkedIn Pulse: AI Is Changing Cybersecurity Faster Than Most Businesses Realize
YouTube Video (Adaptation): How to Implement a Secure Network Tree Topology in Cybersecurity…

Zero-Day Exploits/CVEs

Microsoft Fixes 421 CVEs, Including One Zero-day

The August 2026 Patch Tuesday was a massive security event for the industry. Microsoft released updates fixing 421 Common Vulnerabilities and Exposures (CVEs), which included a critical elevation of privilege flaw exploited as an active zero-day. This specific vulnerability, a use-after-free bug in the `afd.sys` Windows kernel-mode driver, allows attackers to gain SYSTEM privileges on compromised machines.

The pace of discovery remains alarmingly fast. Zero-Day Statistics for 2026 show that enterprise software and appliances are accounting for nearly half (48%) of all exploited zero-days, highlighting where the risk is highest. Furthermore, the vulnerability **CVE-2026-2441**, a critical zero-day in Chrome reported earlier this year, demonstrates how quickly flaws become weaponized tools by state actors and criminal groups alike.


Sources:
SecurityWeek: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One…
YouTube (Patch Tuesday): Will August follow suit? PDQ’s monthly Patch Tuesday recap breaks down Microsoft’s August 2026 security updates…
Axis Intelligence: Zero-Day Statistics 2026: Exploitation Counts, Pre-Disclosure Attacks and the Visibility Gap

Incident Reports

Latest Data Breach News & Live Tracker

Data breaches are a constant, high-velocity threat. The most recent reports show that the sheer volume of confirmed incidents is overwhelming security teams. As of mid-August 2026, trackers confirm dozens of new entries, providing real-time visibility into who was affected and what data was exposed.

A notable example impacting critical infrastructure is the **CEVA Logistics** cyberattack. This breach disrupted European warehouses and resulted in the exposure of extensive customer data. Such incidents underscore that even major logistics providers are vulnerable to sophisticated attacks, often through supply chain weaknesses or targeted ransomware campaigns. The severity of these breaches is matched by the legal consequences for perpetrators.


Sources:
RecentBreaches: 15 hours ago · Recent Breaches tracks the latest data breaches, leaks and ransomware disclosures as they happen
Axis Intelligence Tracker: As of August 2, 2026, Axis Intelligence Research has confirmed 12 entries.
Cyber Express Sidebar (Specific Incident): CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data

Framework Changes

NIST Moves to Modernize NVD as AI Reshapes Vulnerability Management

The cybersecurity framework landscape is adapting rapidly to the demands of AI-driven threats. The National Institute of Standards and Technology (NIST) has initiated a major effort to modernize its National Vulnerability Database (NVD). This change is necessary because traditional vulnerability classification methods are struggling to keep pace with the speed at which AI discovers, weaponizes, and exploits flaws.

Beyond NIST, mandatory policy changes are driving compliance. Microsoft’s announcement of **Mandatory MFA for Azure Sign-ins** represents a massive shift in cloud security governance, forcing organizations to drastically improve their identity protection posture. Additionally, the focus on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) is increasing the legal mandate for timely and comprehensive reporting across 16 designated sectors.


Sources:
NIST Update: NIST Moves to Modernize NVD as AI Reshapes Vulnerability Management
Microsoft Policy: Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days (Contextual source for policy)
Defcon Level: CISA advisories and the Known Exploited Vulnerabilities (KEV) catalog are being used to operationalize framework requirements

New Legislation

UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

Global legislative efforts are increasingly focused on regulating the digital behavior of citizens and securing sensitive data. In the UK, a major policy change is looming: a social media ban targeting users under the age of sixteen, which is expected to take effect by Spring 2027. This aims to protect younger demographics from online risks while also forcing platforms to adapt their design for compliance.

Other key legislative movements include India’s ongoing enforcement and refinement of its Digital Personal Data Protection Act (DPDP Act). Furthermore, the US Federal Trade Commission (FTC) is actively using legal action against companies like Hims & Hers to enforce data privacy mandates regarding health information, signaling a strong regulatory push in the healthcare sector.


Sources:
Cyble/India DPDP: How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act (Contextual source)
The Cyber Express Sidebar: UK Social Media Ban for Under-16s Could Take Effect by Spring 2027
FTC Action (US Legislation): FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices
Careers

2026 National Cyber Virtual Career Fair

The Center of Academic Excellence in Cybersecurity Community (CAE) and the National Cybersecurity Training and Education (NCyTE) Center are hosting the tenth annual National Cyber and AI Virtual Career Fair!

September 22, 2026

9:00 am-2:00 pm Pacific Time

12:00pm-5:00pm Eastern Time

This event is open to students from over 500 institutions designated as Centers of Academic Excellence in Cyber Defense (CAE-CD), Cyber Operations (CAE-CO),  Research (CAE-R), Artificial Intelligence (CAE-AI), and institutions in the Candidate’s Program.

More Information & Registration: https://app.premiervirtual.com/events/53f978a2-1f6f-43a9-a8ba-39151c094417/2026-national-cyber-and-ai-virtual-career-fair/attendee

Careers, Security Education

ISACA Scholarship Program

The ISACA Foundation Scholarship program is currently accepting applications through 5 May 2026.

These scholarships provide more than just financial aid; they offer a bridge into the industry through global networking and professional memberships.

Key Benefits for Students:

  • Financial Support: Awards ranging from $500–$5,000 USD.
  • Professional Entry: One year of ISACA student membership and access to certificate review courses.
  • Networking: Opportunities to attend ISACA Global events and conferences.

For specific program details and apply to one of the scholarships, visit the [ISACA Foundation website].

Careers

Spring 2026 Career Fair virtual workshops

Spring 2026 Virtual Career Fair

Get ready to connect, explore, and take the next step in your career! The Spring 2026 Career Fair will be held on Thursday, April 23, 2026, from 10:00 a.m. to 3:00 p.m. This virtual event, hosted on Handshake, is open to all BU students and alumni. Meet with employers, discover internship and job opportunities, and expand your professional network—all from the convenience of your own space.

Registration opens on Monday, April 13, 2026—don’t miss your chance to participate!

For more information, visit the Career Fair Information & Guide page.

Spring 2026 Career Services Virtual Workshops

Get ready to elevate your career this Spring Term with our dynamic lineup of virtual workshops hosted by Career Services! Whether you’re exploring career paths, building in-demand skills, or preparing to enter the workforce, we’ve got something for you. From discovering your strengths and gaining hands-on experience through platforms like Handshake, Forage, and Micro-Internships, to developing essential skills in collaboration, networking, and workplace readiness, our sessions are designed to support you at every stage. You’ll also learn how to craft standout resumes, prepare for career fairs and interviews, and navigating informational conversations.

The Big Three: Handshake, Forage, & Micro-Internships  Tues, March 24, 2026, 4–5 pm CT @ Handshake

Join Career Services to explore three powerful platforms that can help you build skills, gain experience, and expand your professional network:

  • Handshake – Learn how to navigate thousands of internship and job listings, sign up for career events, and use tools to find roles that match your goals.
  • Forage – Discover free, self-paced virtual job simulations designed by leading companies, giving you real-world insight and hands-on practice to boost your resume.
  • Micro-Internships (Parker Dewey) – See how short-term, paid projects can help you showcase your abilities, build connections with employers, and gain valuable mentorship.

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913145 

Registration closes: Mon, March 23, 2026, 12 pm CT

Career Ready Skills: Collaborating in Modern Work Environments Workshop – Wed, April 1, 2026, 12-1 pm CT @ Handshake

Teamwork is more than “group work”—it’s one of the top skills employers want from new graduates, second only to problem-solving. Whether you’re preparing for internships, leadership roles, or your first full-time job, the ability to collaborate effectively in today’s hybrid, fast-paced workplace is essential. Join Career Services to explore what strong collaboration looks like, discover your teaming strengths, and walk away with practical strategies you can use in classes, campus organizations, and your future career.

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913152 

Registration closes: Tue, March 31, 2026, 12 pm CT

Resume 101: Build a Strong Foundation Workshop  – Wed, April 8, 2026, 12-1 pm CT @ Handshake

Join Career Services to discover the secrets of a standout resume! Learn the key elements that grab recruiters’ attention, explore real examples, and get hands-on guidance to craft a resume that truly shines.

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913144

Registration closes: Tue, April 7, 2026, 12 pm CT

Connect & Impress: Career Fair PrepTues, April 14th 2026, 4-5 pm CT @ Handshake

The Spring Career Fair is approaching—are you ready? Learn how a virtual career fair works, what to expect, and quick tips to help you make the most of the opportunity.

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913147  

Registration closes: Mon, April 13, 2026, 12 pm CT

Inside the Industry: Navigating Informational Interviews Workshop – Tues, April 28, 2026, 4-4:30 pm CT @ Handshake

Learn strategies to get the most out of informational interviews. Discover what an informational interview is, how to use it to gain career insights, and who to reach out to within your industry. Explore strategies for preparing questions, building meaningful connections, and leveraging these conversations to help guide your career path.

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913148 

Registration closes: Mon, April 27, 2026, 12 pm CT

Ace the Interview: Tips & Strategies Workshop Thurs, May 7, 2026, 4-5 pm CT @ Handshake

This workshop will explore the different types of interviews and teach strategies to confidently respond to questions. Learn how to best showcase your knowledge, skills, and qualifications for the position you want.

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913149

Registration closes: Wed, May 6, 2026, 12 pm CT

YouScience 101: Uncover Your Strengths & Career Path Workshop – Thurs, May 14, 2026, 4-5 pm CT @ Handshake

What do you naturally do well? Let’s find out! YouScience Discovery uses interactive brain games to match your aptitudes (what you’re naturally good at) and interests with in-demand careers where you’ll have a competitive edge. This workshop will help you uncover your strengths and see how they align with potential career paths.

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913143 

Registration closes: Wed, May 13, 2026, 12 pm CT

Campus to Career: Preparing for Workplace Readiness Workshop – Wed, May 20, 2026, 12-1 pm CT @ Handshake

Ready to take the next step from college life to career success? Join Career Services to learn how to confidently transition into a professional environment, build and leverage your network, and strengthen your time management skills. Gain practical strategies, real-world tips, and tools to help you show up prepared and stand out in the workplace from day one!

Register via Handshake @ https://bellevue.joinhandshake.com/edu/events/1913150 

Registration closes: Tue, May 19, 2026, 12 pm CT

Virtual Work Experience Opportunities on Forage

Forage offers free, short virtual work experience programs designed and delivered by leading companies. These 6–8 hour online simulations replicate real-world tasks, allowing you to develop key industry skills and gain practical, hands-on experience to support your career readiness.

  • No application required
  • Completely free
  • Self-paced and flexible

Students are encouraged to create a free account using their my365.bellevue.edu email address: Sign up here.

For recommendations on which simulations align best with your major or career interests, please contact Career Services at careerservices@bellevue.edu.

Resume and Cover Letter Guidance Webpage

Need help with your resume or cover letter? Check out our Resume and Cover Letter Guidance webpage! It’s full of resources, tips, and templates to help you create professional, standout documents that can make a strong impression on potential employers. Let us help you take the next step in your career journey!

Uncategorized

Securing Your Privates

Bellevue University Assistant Professor Dr. Lisa McKee is a co-host of a new ISACA security and privacy podcast that talks about Real Conversations. Real Consequences. Real Solutions. relating to a variety of topics in security and privacy. The second session is about the Power of Networking, which will be released soon.