The initiative mandates the creation of an AI cybersecurity officer role within every state agency and establishes an AI cyber defense program housed in the state’s Cybersecurity Integration Center.
The vulnerabilities added to the KEV catalog include a heap inspection flaw in Cisco Secure Firewall (CVE-2026-20349), a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (CVE-2026-68820), and a critical SQL injection vulnerability in Metabase (CVE-2026-72898).
Rubrik gained access to Anthropic's Project Glasswing, which provides early access to the Mythos Preview model, a tool designed to find software flaws and construct attack chains.
Academic researchers from the CISPA Helmholtz Center for Information Security and KU Leuven have demonstrated that commercially available out-of-order RISC-V processors, specifically the SiFive P550 and T-Head Xuantie C910/C920, are vulnerable to all major Spectre variants.
The attack, which impacted services related to illicit-drug monitoring and legal processes, followed a warning from Colombia's national CERT about increased ransomware group focus on the country.
Security researchers Alejandro Hernando and Borja Martínez demonstrated attacks at DEF CON 34 that exploit Windows' automatic hardware identification and driver installation process.
The ban, introduced in 2022, was a response to concerns that TikTok's parent company, ByteDance, had ties to the Chinese government, raising fears about data collection and algorithmic influence.