<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cybersecurity Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/cybersecurity/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/cybersecurity/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Wed, 27 May 2026 06:43:03 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>cybersecurity Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/cybersecurity/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>BNP Paribas-Mistral partnership to focus on AI defences</title>
		<link>https://internationalfinance.com/banking/bnp-paribas-mistal-partnership-focus-ai-defences/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=bnp-paribas-mistal-partnership-focus-ai-defences</link>
					<comments>https://internationalfinance.com/banking/bnp-paribas-mistal-partnership-focus-ai-defences/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Wed, 27 May 2026 00:03:48 +0000</pubDate>
				<category><![CDATA[Banking]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[BNP Paribas]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Marc Camus]]></category>
		<category><![CDATA[Mistal]]></category>
		<category><![CDATA[Mythos]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=56326</guid>

					<description><![CDATA[<p>Mistral engineers and data scientists have been embedded within BNP teams to co-develop and scale various AI-powered projects</p>
<p>The post <a href="https://internationalfinance.com/banking/bnp-paribas-mistal-partnership-focus-ai-defences/">BNP Paribas-Mistral partnership to focus on AI defences</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>French financial services giant BNP Paribas is bolstering its cybersecurity defences in anticipation of powerful AI models exposing vulnerabilities in the coming days, stated the venture&#8217;s chief information ‌officer, Marc Camus.</p>
<p>Camus&#8217; statement comes amid European banks voicing concerns that they could lag their American counterparts in terms of accessing the most advanced cybersecurity-focused AI models, potentially creating significant operational and resilience gaps between the financial landscapes on both sides of the Atlantic.</p>
<p>&#8220;The speed and scale at which AI systems can now identify flaws marked a fundamental shift for cybersecurity teams, adding that the immediate challenge is a practical one,&#8221; Camus noted.</p>
<p>&#8220;There is a lot of noise in the ⁠market on Mythos and the fact that Mythos is accessible or not accessible for some banks, particularly European banks,&#8221; he observed at a joint press conference with French startup Mistral.</p>
<p>American AI company Anthropic&#8217;s <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/"><strong>Mythos model</strong></a>, unveiled in April 2026, has been designed to identify vulnerabilities across software systems at unprecedented speed and scale. However, a section of the financial circle has raised the red flag by stating that such innovation could also be used to enable a wider range of cyberattacks on institutions.</p>
<p>&#8220;The game changer is the speed at which we have to address vulnerabilities and the scale. There are lots of them discovered at once. So, we need to prepare ourselves for that, and that&#8217;s something we are really working ‌on ⁠very, very hard. Cybersecurity teams are now facing the need to process and fix large volumes of vulnerabilities in parallel,&#8221; Camus said.</p>
<p>BNP and Mistral have been in a partnership since 2023. And the scope of operations has expanded now, with Corentin Petit, Mistral&#8217;s global head of solutions, stating that the venture, through its tie-up with BNP Paribas, was focusing ⁠on benchmarks relevant to regulated industries such as banking. Mistral engineers and data scientists have been embedded within BNP teams to co-develop and scale various AI-powered projects.</p>
<p>&#8220;BNP uses Mistral for internal tools ⁠and virtual assistants for clients in France and Belgium, as well as compliance at its Belgian Fortis business,&#8221; said Sophie Heller, chief transformation officer at BNP&#8217;s retail and consumer division.</p>
<p>&#8220;At BNP&#8217;s investment banking unit, ⁠other deployments support document extraction, equity research and internal knowledge retrieval for tens of thousands of staff,&#8221; remarked Charles Holive, chief AI officer at the division.</p>
<p>The post <a href="https://internationalfinance.com/banking/bnp-paribas-mistal-partnership-focus-ai-defences/">BNP Paribas-Mistral partnership to focus on AI defences</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/banking/bnp-paribas-mistal-partnership-focus-ai-defences/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>PCI certification is a milestone, not the destination: Kamran Chaudhary</title>
		<link>https://internationalfinance.com/technology/pci-certification-is-a-milestone-not-the-destination-kamran-chaudhary/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=pci-certification-is-a-milestone-not-the-destination-kamran-chaudhary</link>
					<comments>https://internationalfinance.com/technology/pci-certification-is-a-milestone-not-the-destination-kamran-chaudhary/#respond</comments>
		
		<dc:creator><![CDATA[Dhiraj Shetty]]></dc:creator>
		<pubDate>Mon, 11 May 2026 06:31:20 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Asgard Platform]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Finance]]></category>
		<category><![CDATA[Kamran Chaudhary]]></category>
		<category><![CDATA[PCI Certification]]></category>
		<category><![CDATA[VikingCloud]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=55916</guid>

					<description><![CDATA[<p>At VikingCloud, Kamran Chaudhary serves as Vice-President of Solutions Engineering and is responsible for solution scoping, alignment, training, and demos</p>
<p>The post <a href="https://internationalfinance.com/technology/pci-certification-is-a-milestone-not-the-destination-kamran-chaudhary/">PCI certification is a milestone, not the destination: Kamran Chaudhary</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In today&#8217;s world, cybersecurity and regulatory demands have grown more complex, and businesses are seeking practical, scalable ways to stay compliant. Industry leaders are increasingly focused on simplifying compliance without compromising security or operational efficiency.</p>
<p><a href="https://internationalfinance.com/"><strong>International Finance</strong></a> discussed the issue with Kamran Chaudhary, who is a 25-year veteran who specialises in Governance, Risk, and Compliance (GRC) frameworks and cybersecurity. Kamran serves as Vice-President of Solutions Engineering at VikingCloud where he is responsible for solution scoping, alignment, training, and demos.</p>
<p>Kamran has collaborated with a diverse range of industries, from finance and healthcare to technology and government, leveraging a deep understanding of risk management to build tailored solutions that address unique challenges.</p>
<p>In an exclusive interview with <strong>International Finance</strong>, Kamran Chaudhary explains how VikingCloud simplifies PCI compliance for SMBs through continuous monitoring, proactive updates, and AI-driven insights. He also addresses risks and closes compliance gaps, ultimately helping clients achieve success in global operations.</p>
<p><strong>What sets VikingCloud apart from competitors when supporting small and mid-sized businesses with PCI DSS compliance?</strong></p>
<p>What really sets us apart is that we don&#8217;t look at SMBs as just a smaller version of an enterprise problem. Our Continuous Compliance Management (CCM) approach takes the PCI burden completely off the merchant&#8217;s plate so they can focus on running their business and delivering a great guest experience, something truly unique to VikingCloud. We&#8217;ve developed dedicated solutions for small and mid-sized businesses that are built to deliver rapid, cost-effective, and uncomplicated compliance for businesses that may not have their own internal security resources. On top of that, we bring 25-plus years of PCI expertise and our Asgard Platform, which provides clients with real-time visibility of their compliance status. More than 4 million businesses around the globe trust us because we show up as a partner, not just a vendor.</p>
<p><strong>As PCI DSS requirements continue to evolve, what strategies are in place to ensure clients are prepared before new standards become mandatory?</strong></p>
<p>We monitor the guidance put out by the PCI SSC and ensure that we are already ahead of any changes before they are required, not after. For instance, when the PCI DSS 4.0 came out, we were already ahead of it, and 4.0.1 since then. We also take the information provided in the updates and make sure that we&#8217;re communicating it in a way that&#8217;s easy to understand so that clients aren&#8217;t surprised by any changes, and we offer webinars and other direct communication to ensure that we&#8217;re walking them through exactly what&#8217;s changing and what needs to be done. We want to make sure that compliance is an ongoing process, not a fire drill every time a new version is released.</p>
<p><strong>Many small businesses underestimate the risks of non-compliance. What approaches are used to educate and engage clients who may not initially prioritise PCI compliance?</strong></p>
<p>To be honest, the biggest change comes when we make it real and tangible for them in terms of non-compliance. The reality for small business merchants is that they often simply check &#8216;yes&#8217; for all PCI requirements without truly understanding what&#8217;s required to become compliant. Non-compliance fees start small at $50 to $100 per month, but can quickly escalate into thousands. Business owners who aren&#8217;t PCI compliant are also personally responsible for the costs associated with a potential data breach. VikingCloud simplifies the entire process by educating business owners about their specific requirements and delivering turn-key programmes that take the guesswork out of PCI, and with ransomware now making up 88% of small business attacks, the stakes couldn&#8217;t be higher. We lead with those numbers, but we also lead with making it accessible for them so it doesn&#8217;t feel so daunting for business owners who are already trying to wear ten hats at once. Once we make it accessible to them, then we have their attention.</p>
<p><strong>Which compliance gaps are most frequently identified in small businesses, and what steps are typically taken to resolve them efficiently?</strong></p>
<p>The most common gaps we see with Level 4 small business merchants are log retention — PCI requires one year of logs with daily reviews, which is expensive to set up independently — security awareness training, where PCI requires proof of training upon hire and annually for all in-scope employees, and secure remote access with two-factor authentication. Many SMBs simply aren&#8217;t aware these requirements exist until they&#8217;re flagged. We start with a vulnerability scan and a scoping exercise to get clarity on the gaps, and then develop a remediation plan where we address the high-risk gaps first. We use the platform to track everything so nothing falls through the cracks. Time is of the essence.</p>
<p><strong>How does the company maintain strong security controls while minimising operational disruptions for businesses that process payments daily?</strong></p>
<p>Security must be a friend rather than a foe to the business because, if we make it too difficult, people will work around it. We operate on a model of continuous background monitoring rather than disruptive assessments, running 24/7 with our Asgard Platform, detecting threats and highlighting them before they can cause damage. We&#8217;ll actually schedule in remediation when it can be done during peak times, so it doesn&#8217;t interfere when it can least be afforded. We&#8217;ll also remove the burden from our internal teams so that we can continue to serve our customers while we handle the security behind the scenes.</p>
<p><strong>Where does automation or AI contribute most effectively in monitoring, reporting, and maintaining PCI compliance across global operations?</strong></p>
<p>That&#8217;s where the scale problem pays off, though, because AI earns its keep here. We process over six billion online events per day, so no human team can manually review all of those events. Modern AI, and other machine learning before that, has helped us shift from a reactive model to a predictive model, detecting anomalies and new threats before they become incidents. On the compliance side, AI provides audit-ready documentation, tracks status in real-time, and points out gaps to aid the real people responsible, ultimately speeding the time to reporting. For clients who span multiple locations or even countries, this level of consistency matters: same level of rigour, everywhere, all the time.</p>
<p><strong>Since VikingCloud operates in over 70 countries, how do regional regulations or cultural differences impact the compliance strategy?</strong></p>
<p>PCI DSS is a worldwide standard, but the world around it is not necessarily so. In the EU, clients are also dealing with GDPR. In APAC and Latin America, clients are dealing with local payment regulations, in addition to their PCI requirements. We have in-region expertise that can help clients understand how these areas intersect, so clients don’t have to be experts in each area. Cultural nuances also come into play, such as how we communicate compliance needs to a large retail client in Germany versus a growing hospitality business in Southeast Asia. Localising is not just desirable; it is what makes it work.</p>
<p><strong>What does cross-functional collaboration look like among compliance, sales, product, and support teams to deliver a seamless client experience?</strong></p>
<p>We strive to ensure the client experience does not slip through the cracks between teams. Our compliance team, product team, and support teams all have feedback loops that feed directly into the way we build and improve our product. Our sales team is trained to ensure the client has the right expectations at the beginning, so they are not surprised down the road. We use internal visibility to ensure we can identify client health and address any potential issues promptly. A contract is not the end result; a compliant, protected, and secure client is.</p>
<p><strong>Beyond PCI certification, what metrics or indicators are used to evaluate long-term client success and risk reduction?</strong></p>
<p>Certification is a milestone, not the destination. We monitor things like the reduction in total vulnerability count over time, the average time taken to detect and respond to threats, and the ratio of high-risk issues resolved compared to the number still open. We also monitor whether the client is doing the controls in between cycles and not just preparing for the audit season. Clients who are engaging with the platform are in a much healthier security state. But at the end of the day, the real measure is whether the client has had fewer issues and has reduced their overall risk posture.</p>
<p><strong>Which traits or skills distinguish the most successful team members who support businesses navigating complex compliance environments?</strong></p>
<p>While technical knowledge is important, it&#8217;s not the only factor. The people who make the most impact are the people who, given something complex, are able to make it clear and understandable to a person who runs a pharmacy or a hotel chain, not a security expert. Curiosity is a huge factor because the threat space never stops changing. The best people in this space are always curious, always learning. And then, beyond all of those, I think it&#8217;s just a matter of empathy, of patience, because compliance only works if the person on the other side of the conversation trusts you, so gaining their trust is as important as any other factor.</p>
<p>The post <a href="https://internationalfinance.com/technology/pci-certification-is-a-milestone-not-the-destination-kamran-chaudhary/">PCI certification is a milestone, not the destination: Kamran Chaudhary</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/pci-certification-is-a-milestone-not-the-destination-kamran-chaudhary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Project Glasswing: The invite-only club for Claude Mythos</title>
		<link>https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=project-glasswing-the-hidden-club-claude-mythos</link>
					<comments>https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 07 May 2026 00:03:31 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI Safety]]></category>
		<category><![CDATA[Anthropic]]></category>
		<category><![CDATA[Claude Mythos]]></category>
		<category><![CDATA[CyberGym]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Linux Kernel]]></category>
		<category><![CDATA[Project Glasswing]]></category>
		<category><![CDATA[Software Engineering]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=55884</guid>

					<description><![CDATA[<p>Claude Mythos Preview, apart from breaking into computer systems like a hacker, can find hidden flaws in software that programmers have missed for decades</p>
<p>The post <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/">Project Glasswing: The invite-only club for Claude Mythos</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>In early April 2026, artificial intelligence (AI) company Anthropic announced a development that had almost no parallel in the history of the tech industry. They had built something extraordinary. But, they refused to let anyone use it.</p>
<p>The model is called Claude Mythos Preview. By every available metric, it is the most capable AI system ever evaluated. It can find hidden flaws in software that human programmers missed for decades. It can break into computer systems the way a seasoned hacker would, step by step, adapting as it goes. It can chain together multiple separate vulnerabilities to seize complete control of a server. And it can do all of this faster, cheaper, and at a scale that no team of human experts could match.</p>
<p>Anthropic decided that releasing this to the public would be, in their own estimation, too dangerous. Anthropic warned: “AI models have reached a level of coding capability where they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities,” adding that such advances could pose significant threats to economic stability, public safety, and national security.</p>
<p>Instead, they handed access to a closed group of roughly 40 of the world’s largest corporations, gave them USD 100 million worth of computing credits, and called the whole thing Project Glasswing. The stated goal is to use Mythos to find and fix security flaws in the world’s most critical software before someone with bad intentions gets their hands on similar technology.</p>
<p>What follows is an attempt to explain what exactly Mythos can do, why it was locked away, who got the keys, and why none of this is quite as clean as Anthropic would like you to believe.</p>
<p><strong>What Makes Mythos Different</strong></p>
<p>To understand the alarm, you have to understand how AI models are normally tested. Researchers use benchmarks, essentially standardised tests, to compare one model against another. Most previous AI models were good at solving packaged coding problems neatly, the kind you might find in a textbook.</p>
<p>Mythos operates differently. It excels at the messy, poorly documented, real-world environments that software engineers and hackers actually deal with. On a benchmark called SWE-bench Pro, which assesses a model&#8217;s capacity to autonomously complete complex software engineering tasks through multiple steps, Mythos achieved a score of 77.8%. The previous best model scored 53.4%. That’s not a small jump.</p>
<p>On a benchmark called Capture the Flag, which simulates the kind of adversarial hacking challenges used to train professional cybersecurity researchers, the previous best AI model scored below 1%. Mythos scored 73%. That is not an incremental improvement. That is a different category of capability.</p>
<p>“AI capabilities have crossed a threshold that fundamentally changes the urgency required to protect critical infrastructure from cyber threats, and there is no going back. Our foundational work with these models has shown we can identify and fix security vulnerabilities across hardware and software at a pace and scale previously impossible. That is why Cisco joined Project Glasswing: this work is too important and too urgent to do alone,” explains Anthony Grieco, SVP &amp; Chief Security &amp; Trust Officer at Cisco.</p>
<p>The benchmark that made people most uneasy is called CyberGym. It measures a model’s ability to reproduce and trigger known cybersecurity vulnerabilities, flaws in real software that real attackers exploit. Mythos scored 83.1%. The world’s existing security scanning tools didn’t just fall behind. They became, overnight, dramatically less relevant.</p>
<p><strong>What It Found During Testing</strong></p>
<p>Benchmark scores are abstract. The actual discoveries Mythos made during internal testing are not.</p>
<p>The first was a 27-year-old security flaw in OpenBSD, an operating system that has a global reputation for being exceptionally secure. OpenBSD is used to protect critical network infrastructure around the world. This flaw had been sitting there since the late 1990s, invisible to every human auditor and automated tool that ever looked at it.</p>
<p>The second was a 16-year-old flaw in FFmpeg, a piece of open-source software embedded in a staggering number of applications that handle video, from streaming platforms to video editing tools. Automated testing tools had run through the relevant code pathway over five million times without triggering the flaw. Mythos found it by understanding the logic of the code, not just running tests until something broke.</p>
<p>The third, and the most troubling, was something more than an isolated bug. Mythos found multiple separate vulnerabilities in the Linux kernel and connected them into a chain. Starting with zero special access, it escalated its own privileges step-by-step until it had root control of a server. Complete control. This is the kind of attack that typically requires months of work by a skilled human team. Mythos did it autonomously.</p>
<p>This is where the alarm becomes existential rather than technical. The traditional timeline for a cyberattack involves extensive reconnaissance, careful planning, and skilled human labour at every step. Mythos compresses that timeline to minutes. It doesn’t just assist attackers. It could, in the wrong hands, replace them entirely.</p>
<p><strong>The Government Weighed In</strong></p>
<p>Before any of the Project Glasswing decisions were made, Anthropic allowed the United Kingdom’s AI Safety Institute, a government body set up precisely to evaluate these kinds of risks, to put Mythos through its paces independently.</p>
<p>The institute used a simulation called The Last Ones, a 32-step corporate network attack that starts with a hacker on the outside and ends with them in complete control of a company’s entire digital infrastructure. For a skilled human expert, completing this simulation takes roughly 20 hours.</p>
<p>Mythos became the first AI system in history to complete it from start to finish on its own. In their final report, the institute said the model ‘could execute multi-stage attacks on vulnerable networks and discover and exploit vulnerabilities autonomously’.</p>
<p>To be fair, the institute included important caveats. Mythos was tested against small, lightly defended networks. No active human defenders were watching for intrusions.</p>
<p>In a simulation involving industrial control systems for physical infrastructure, Mythos got confused and failed.</p>
<p>An AI that makes a lot of noise and triggers every alarm is more like a sledgehammer than a scalpel. Against a hardened, actively monitored enterprise network, its real-world effectiveness remains unproven.</p>
<p><strong>Who Gets The Keys</strong></p>
<p>Anthropic named the initiative after the glasswing butterfly, a species with transparent wings that allow you to see flaws hiding in plain sight. The metaphor is deliberate. The idea is to use Mythos to illuminate vulnerabilities before attackers can exploit them.</p>
<p>The company explained on its blog, “The same capabilities that make AI models dangerous in the wrong hands make them invaluable for finding and fixing flaws in important software. Project Glasswing is an important step toward giving defenders a durable advantage in the coming AI-driven era of cybersecurity.”</p>
<p>The launch partners include Amazon Web Services, Google, Microsoft, Apple, Cisco, Broadcom, NVIDIA, CrowdStrike, Palo Alto Networks, JPMorganChase, and the Linux Foundation. These are not scrappy startups. They are the companies that own the infrastructure on which the internet runs.</p>
<p>Anthropic also donated $4 million in cash directly to open-source software foundations. This matters because the most vulnerable part of the internet isn’t Google or Microsoft. It’s the small, underfunded volunteer teams maintaining foundational open-source libraries that billions of devices quietly depend on.</p>
<p>The logic Anthropic is working from is fairly straightforward. Offensive AI capabilities will proliferate. The only viable response is to arm defenders first, patch as many vulnerabilities as possible before attackers arrive, and hope the window of advantage holds long enough to matter.</p>
<p><strong>The Problem Nobody Wants To Say Aloud</strong></p>
<p>Here is the uncomfortable truth sitting under all of this. Finding vulnerabilities is not the hard part anymore. Fixing them is.</p>
<p>Mythos can surface thousands of previously unknown security flaws in a very short time. The Linux kernel alone has millions of lines of code, and patches to foundational code have to be written carefully and deployed across millions of systems. That work is slow and manual. Within the security community, the consensus is grim. Finding vulnerabilities is no longer the hard part. The bottleneck is now human. If Mythos floods the pipeline with thousands of flaws, we simply don’t have enough qualified humans to fix them before attackers reverse-engineer the public patch notes.</p>
<p>The $4 million in donations helps, but it’s a bandage on a structural wound. There’s also a harder question buried here. Who decided that Google, Microsoft and JPMorganChase should be the guardians of the world’s digital security? Handing them exclusive access means they can protect their own products first, their competitors last, and everyone else not at all.</p>
<p><strong>The Anti-Trust Problem</strong></p>
<p>Legal scholars noticed immediately. By restricting access to Mythos to a hand-picked group of 40 corporations, Anthropic has created what critics are calling the “AI Avengers,” a private club with an insurmountable competitive advantage.</p>
<p>Section 1 of the Sherman Antitrust Act prohibits agreements between competitors that restrain trade. Madhavi Singh, Deputy Director of the Thurman Arnold Project at Yale, warns, “While the cybersecurity risks are serious, we must ensure that the consortium doesn’t become a front for a cartel, or entrench incumbents by gatekeeping access to advanced AI capabilities.”</p>
<p>Take browsers as a concrete example. Google’s Chrome and Apple’s Safari are inside the consortium. Their teams can use Mythos to patch vulnerabilities before those flaws are public. Independent browser developers are not in the consortium. Their products will objectively be less secure, not because their engineers are worse, but because they were not invited to the party.</p>
<p><strong>Sam Altman Calls It Fear Marketing</strong></p>
<p>Not everyone accepts Anthropic’s framing. OpenAI CEO Sam Altman has been the most public and blunt critic. On a podcast, he described the strategy in terms that didn’t leave much room for ambiguity: “It’s like telling someone you’ve built a bomb, you’re about to drop it on their head, and you’re now selling them a USD 100 million bomb shelter.”</p>
<p>Altman argues that Anthropic is deliberately inflating the perceived danger of Mythos to create artificial scarcity and sideline independent developers. Safety, in this reading, is a marketing strategy.</p>
<p>Anthropic CEO Dario Amodei has not been quiet in response. Internal communications leaked to the press showed Amodei describing OpenAI’s criticisms as tactics designed to undermine Anthropic’s regulatory standing. His core argument is that these dangerous capabilities emerged as a by-product of the model becoming generally smarter. If that’s true, then restricting the model isn’t theatre. It’s the only rational response.</p>
<p><strong>The Breach</strong></p>
<p>None of this discussion about containment has aged especially well, because the model was breached within weeks of the announcement.</p>
<p>Bloomberg reported that a small group of unauthorised users on a private Discord server had successfully accessed Claude Mythos Preview. They used the credentials of a contractor working for a third-party data labelling firm, cross-referenced with data leaked from a staffing startup called Mercor.</p>
<p>The group hasn’t used Mythos to hack anything yet. According to Bloomberg, they are more interested in ‘playing around’ with the tech than causing trouble. A claim that has been corroborated via screenshots and a live demonstration of the model.</p>
<p>“We’re investigating a report claiming unauthorised access to Claude Mythos Preview through one of our third-party vendor environments,” stated Anthropic.</p>
<p>But the symbolic damage is significant.</p>
<p>The chain is only as strong as its weakest link, and the weakest link is not Google’s security team. They’re low-paid freelancers in third-party companies who may not even know how valuable the access they hold actually is.</p>
<p><strong>What Comes Next</strong></p>
<p>The Mythos situation is a preview of a structural shift that’s accelerating. State-of-the-art AI is becoming a national security infrastructure. The hardware required to run models of this complexity costs billions. The economics are pushing toward a world where the most powerful AI is available only to sovereign governments and a small number of hyperscale corporations.</p>
<p>For everyone else, the model announced for public use is Claude Opus 4.7, a capable but deliberately restricted system. Anthropic has promised a Cyber Verification Programme that would give vetted security professionals access to more capable models, but that’s still a gatekeeping system based on institutional affiliation.</p>
<p>The window to patch the world’s software before AI-powered attacks become routine is real, but it’s narrow and currently controlled by a small group of private corporations. What Project Glasswing represents is the first serious attempt to answer the question of who governs the most dangerous software ever built. The answer, for now, is not you.</p>
<p>The post <a href="https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/">Project Glasswing: The invite-only club for Claude Mythos</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/project-glasswing-the-hidden-club-claude-mythos/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Google disrupts Chinese hacking operations in more than 40 nations</title>
		<link>https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=google-disrupts-chinese-hacking-operations-more-than-nations</link>
					<comments>https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 02 Mar 2026 14:51:19 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google cloud]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[malware]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=54864</guid>

					<description><![CDATA[<p>Google terminated all of the attackers' authority over Google Cloud Projects as part of the disruption operations, cutting off their ongoing access to GridTide-compromised environments</p>
<p>The post <a href="https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/">Google disrupts Chinese hacking operations in more than 40 nations</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Online search engine giant <a href="https://internationalfinance.com/technology/if-insights-google-vs-microsoft-the-battle-for-infrastructure-power/"><strong>Google</strong></a>, in a major successful move, has gone after a global espionage network which has pestered governments and telecom services in over 40 countries.</p>
<p>Google’s Threat Intelligence Group (GTIG), partnering with Mandiant (a subsidiary of Google Cloud and a premier cybersecurity firm specialising in threat intelligence, incident response, and managed defence) and others, ended up exposing Chinese state-backed organisation UNC2814’s spy operations. The group has now been classified as an Advanced Persistent Threat (APT).</p>
<p>In the most recent campaign, the organisation used GridTide, a backdoor malware that had never been seen before and used the Google Sheets API for C2 infrastructure. The backdoor blends with regular company traffic and causes no concerns because it sends HTTPS queries to authentic Google infrastructure rather than connecting to a distant server to obtain commands and steal data.</p>
<p>Every command is kept in a spreadsheet cell within an attacker-owned document. The malware periodically examines, decodes, and executes the encoded instructions that the operators inject into designated rows or cells.</p>
<p>Exfiltrated data may occasionally be written back into the sheet. GTIG stated that it did not see any examples of data exfiltration. With reports of its activity dating back to 2017 or potentially earlier, UNC2814 is a somewhat well-known threat actor.</p>
<p>Google terminated all of the attackers&#8217; authority over Google Cloud Projects as part of the disruption operations, cutting off their ongoing access to GridTide-compromised environments. They restricted access to the Google Sheets API requests, disabled attacker accounts, and located and stopped all known UNC2814 infrastructure. Lastly, it published a list of IoCs connected to the UNC2814 infrastructure that has been operational since at least 2023.</p>
<p>The campaign started in 2023 and affected at least 53 organisations in 42 countries. Google suspects that UNC2814 is present in at least 20 more countries. Most of Latin America, Eastern Europe, Russia, parts of Africa, and parts of South Asia seem to have been hit. Except for Portugal, Western Europe is mostly unscathed. The United States was not touched as well.</p>
<p>The activity is distinct from separate high-profile, telecommunications-focused Chinese hacking activity tracked as “Salt Typhoon,” Google told Reuters. That campaign, which the US government has linked to Beijing, targeted hundreds of American organisations, in addition to prominent political figures.</p>
<p>Chinese Embassy spokesperson Liu Pengyu, while reacting to the news, said, &#8220;<a href="https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/"><strong>Cybersecurity</strong></a> is a common challenge faced by all countries and should be addressed through dialogue and cooperation. China consistently opposes and combats hacking activities in accordance with the law, and at the same time firmly rejects attempts to use cybersecurity issues to smear or slander China.&#8221;</p>
<p>The post <a href="https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/">Google disrupts Chinese hacking operations in more than 40 nations</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/google-disrupts-chinese-hacking-operations-more-than-nations/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Start-up of the Week: Outtake tackles next-gen identity fraud</title>
		<link>https://internationalfinance.com/technology/start-up-week-outtake-tackles-next-gen-identity-fraud/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=start-up-week-outtake-tackles-next-gen-identity-fraud</link>
					<comments>https://internationalfinance.com/technology/start-up-week-outtake-tackles-next-gen-identity-fraud/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Thu, 12 Feb 2026 14:28:31 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Digital Risk Protection]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[OpenAI]]></category>
		<category><![CDATA[Outtake]]></category>
		<category><![CDATA[Phishing Emails]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=54730</guid>

					<description><![CDATA[<p>Outtake’s Annual Recurring Revenue has increased six times year-over-year, while its customer base grew more than ten times</p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-outtake-tackles-next-gen-identity-fraud/">Start-up of the Week: Outtake tackles next-gen identity fraud</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Global verification and fraud prevention firm Sumsub recently published its report on the global rate of identity fraud. While the report witnessed a decrease in crime numbers in 2025, the immediate cheer may prove to be short-term, as things are undergoing a &#8220;sophistication shift,&#8221; with sloppy, low-effort incidents of identity fraud noticed in 2024 now replaced by fewer but sharper, multi-step, and coordinated operations.</p>
<p>In this backdrop, Brooklyn-based Outtake, whose agentic <a href="https://internationalfinance.com/technology/alphabet-talks-buy-cybersecurity-start-up-wiz-usd-billion/"><strong>cybersecurity</strong></a> platform helps enterprises detect, investigate, and take down identity fraud, has raised a USD 40 million Series B round of funding. While the amount may not sound huge compared to the capital raised by Outtake&#8217;s industry peers, the funding round hit the headlines due to the list of participating angel investors, which included Microsoft CEO Satya Nadella, Palo Alto Networks CEO Nikesh Arora, Pershing Square Holdings CEO Bill Ackman, Palantir CTO Shyam Sankar, Anduril co-founder Trae Stephens, former OpenAI VP Bob McGrew, Vercel CEO Guillermo Rauch, and former AT&#038;T CEO John Donovan.</p>
<p><strong>Knowing The Player In Detail</strong></p>
<p>Outtake, established in 2023 by former Palantir engineer Alex Dhillon, has come up with a fix when it comes to automating what has largely been a manual problem: spotting and taking down digital identity posers, entities like impersonation accounts, malicious domains posing as companies&#8217; official websites, rogue apps, fraudulent ads, and more.</p>
<p>Outtake has customers like <a href="https://internationalfinance.com/magazine/technology-magazine/can-openais-idealism-survive-corporate-change/"><strong>OpenAI</strong></a>, British financial services company Pershing Square, and American mobile technology company AppLovin, along with several federal agencies. OpenAI even profiled the company in July 2025 as an example of an agentic start-up built on its reasoning models.</p>
<p>Outtake’s ARR (Annual Recurring Revenue) has increased six times year-over-year, while its customer base grew more than ten times. This shows one thing: while the demand for foolproof cybersecurity solutions is expanding rapidly, the 21st century&#8217;s global socio-economic order is also taking the threat of digital identity theft more seriously than ever.</p>
<p>According to Dhillon and his team, two-thirds of identity theft-related attacks now utilise some form of AI, remarking, &#8220;the question isn&#8217;t whether your organisation will be targeted, it&#8217;s whether your defences can match the sophistication of AI-powered threats that are reshaping the very nature of cybercrime.&#8221;</p>
<p>So, what is Outtake dealing with? The rising menace of bots, with a 2024 study claiming that 30% of accounts across major social media platforms are likely to be fake. These bots are used to spread scams, steal identities, or manipulate public opinion.</p>
<p>Then add the 703% increase in credential phishing attacks, thanks to the widespread availability of AI-generated phishing kits online. We also have a 202% increase in phishing emails, with generative AI tools and automation again helping hackers compose phishing emails up to 40% faster.</p>
<p><strong>Making &#8216;Digital Trust&#8217; Great Again</strong></p>
<p>Talking about Outtake&#8217;s &#8220;AI-Driven Intelligence for Open Sources,&#8221; the start-up&#8217;s AI agents cut through noise and contextualise risks in real time by delivering the early warning security teams need to protect people, reputation, and operations.</p>
<p>&#8220;Manual OSINT (Open-Source Intelligence) workflows can’t keep pace with today’s threat landscape. Security analysts spend hours chasing false positives, triaging repetitive alerts, and piecing together fragments from multiple sources,&#8221; the venture stated, further pointing out issues like manual backlogs (with threat actors quickly shifting their campaign methods by the time analysts detect and manually remediate a threat), an endless streak of false alerts (with keyword-based monitoring generating endless dead ends, burying investigators in irrelevant hits and obscuring the real signals that matter), and manual correlation of findings (with cybersecurity teams seeing isolated incidents as big wins rather than uncovering the full campaign across platforms and sources).</p>
<p>To counter these, Outtake has bet big on AI agents, which continuously discover and analyse images, videos, audio, and text across the open web, delivering contextualised intelligence without the manual overhead. They track emerging narratives (upcoming cybercrime trends) and force-protection campaigns before they escalate into reputational or physical risks.</p>
<p>Legacy traditional tools often end up missing threats from social platforms, forums, and open sources, something that Outtake&#8217;s AI agents address thoroughly, taking things further to &#8220;Location-Based Risk Intelligence&#8221; by mapping chatter tied to physical locations to anticipate risks to executives, facilities, and events.</p>
<p>Also, &#8220;AI-Driven Intelligence for Open Sources&#8221; keeps its client businesses safe by monitoring third-party players like vendors, partners, and acquisition targets for emerging risks. After everything, Outtake distils millions of signals into clear, prioritised summaries before delivering threat digests directly to clients&#8217; inboxes or collaboration tools, customised to the latter’s security priorities.</p>
<p>Next are &#8220;Digital Risk Protection&#8221; agents that, in the start-up&#8217;s language, provide &#8220;AI that tirelessly detects, prioritises, and dismantles impersonation threats across domains, social media, apps, and ads.&#8221; When it comes to proactively identifying and eliminating digital impersonation threats, traditional methods are trailing severely. How? First of all, they are drowning in AI-generated noise due to the widespread availability of AI-generated phishing kits online.</p>
<p>Attacks are getting sophisticated and fast-paced, with threat actors diversifying their mediums. Apart from missing threats hidden in images, videos, code, and visual brand abuse, legacy keyword tools end up chasing nodes while missing well-coordinated campaigns. These solutions are only capable of tackling isolated threats instead of going after the full attack ecosystem. They can’t connect signals across platforms, leaving coordinated campaigns intact and growing.</p>
<p>&#8220;Digital Risk Protection&#8221; agents have been tailored with social engineering scams in mind—criminal acts that exploit human psychology to trick individuals into divulging confidential information, transferring money, or installing malware. These attacks are known for impersonating trusted entities or businesses through phishing (emails), vishing (phone calls), or smishing (SMS). Outtake&#8217;s solution goes aggressively after these elements, removing fake brand and executive impersonations across all platforms while continuously mapping threat infrastructure across digital mediums, revealing the hidden links that single-point tools overlook.</p>
<p>Be it fraudulent phishing, malware domains, fake mobile apps, or deceptive marketplace listings, &#8220;Digital Risk Protection&#8221; agents have been tasked with one job: monitor, identify, and take down.</p>
<p><strong>Redefining Digital Verification</strong></p>
<p>Business Email Compromise (BEC), which targets organisations through deceptive emails, skyrocketed in 2025, with Barracuda&#8217;s &#8220;Email Security Breach Report&#8221; registering a staggering 78% of surveyed organisations worldwide experiencing an email security breach throughout the year, with the lack of expertise, automation, and awareness ending up costing companies money, reputation, customers, and growth prospects.</p>
<p>Against this backdrop, Outtake has launched a device- and identity-bound authentication tool via World ID or passkeys, as AI is known for generating both phishing and legitimate emails. &#8220;Outtake Verify&#8221; has evolved as a browser extension that cryptographically verifies a business&#8217; identity (through mathematical proof instead of probabilistic guessing) and signs the company&#8217;s emails. Even if the official mail account gets hacked, Outtake still ensures that these compromised accounts can&#8217;t send verified emails by denying attackers device-bound authentication.</p>
<p>The solution not only improves internal email security for Outtake&#8217;s client organisations, but it also increases trust in third-party communications by making the whole digital environment secure. &#8220;Outtake Verify&#8221; also reduces the burden on human cybersecurity professionals within a team by taking over tasks like verifying executive payment approvals, eliminating out-of-band confirmations, ensuring sensitive documents come from authenticated sources with message integrity, and extending trust beyond organisational boundaries by requiring authentication from key vendors.</p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-outtake-tackles-next-gen-identity-fraud/">Start-up of the Week: Outtake tackles next-gen identity fraud</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/start-up-week-outtake-tackles-next-gen-identity-fraud/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cyberattack on healthcare firm Doctor Alliance: All you need to know</title>
		<link>https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cyberattack-healthcare-firm-doctor-alliance-all-you-need-know</link>
					<comments>https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Mon, 17 Nov 2025 13:50:38 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cyberattack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Doctor Alliance]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[health insurance]]></category>
		<category><![CDATA[United States]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=53844</guid>

					<description><![CDATA[<p>Recently, Cybernews confirmed a post on a popular hacker forum, likely made by the alleged perpetrators, claiming 353 gigabytes of data were stolen during a breach of Doctor Alliance’s network</p>
<p>The post <a href="https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/">Cyberattack on healthcare firm Doctor Alliance: All you need to know</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>A cybersecurity research firm has now found a new data trove on the <a href="https://internationalfinance.com/magazine/opinion-magazine/erosion-of-trust-dark-webs-financial-fallout/"><strong>dark web</strong></a>, said to contain 1.24 million files, many related to direct patient care, that allegedly belong to Doctor Alliance, a health IT platform that provides automated billing services. This is a serious development, given the fact that the Texas-based venture has clients (healthcare providers) including Intrepid, AccentCare, Carter and Interim across the United States, representing millions of patients.</p>
<p>Recently, Cybernews confirmed a post on a popular hacker forum, likely made by the alleged perpetrators, claiming 353 gigabytes of data were stolen during a breach of Doctor Alliance’s network. For now, the data has not been leaked, with the user going by the alias “GOD” threatening to either post or sell the information on November 21, 2025, in case a ransom of USD 200,000 is not paid.</p>
<p>Alias &#8220;GOD,&#8221; who likely represents a group of individuals, released a small 200 MB sample to prove they have the files. As per Cybernews, the revealed files include “various medical records, riddled with sensitive personal data,” specifically details on patient prescriptions, treatment plans, names, health insurance numbers, phone numbers, home addresses, hospital orders and more.</p>
<p>In the United States, such data access would constitute a reportable breach under the terms of the Health Insurance Portability and Privacy Act (HIPAA). <a href="https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/"><strong>Cybersecurity</strong></a> researchers now believe the trove, if determined to be legitimate, poses a serious risk to patients and employees, as it could all be used for identity theft, blackmail or other nefarious purposes. This includes not only medical identity theft but also insurance fraud.</p>
<p>&#8220;This data leak poses a huge risk of identity theft and medical fraud for the patients involved, such as obtaining medical services or prescription drugs in the victim&#8217;s name. Both doctors and patients can fall victim to social engineering attacks,&#8221; remarked the researchers.</p>
<p>While promising that the data would be deleted if the ransom is paid, the alleged cybercriminals in a post refused to divulge details like when the attack took place and what vector was used. No known hacker outfit has claimed credit for the attack.</p>
<p>The post <a href="https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/">Cyberattack on healthcare firm Doctor Alliance: All you need to know</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/cyberattack-healthcare-firm-doctor-alliance-all-you-need-know/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Start-up of the Week: Armed with fresh funding, Chainguard eyes to become major cybersecurity player</title>
		<link>https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player</link>
					<comments>https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Wed, 30 Apr 2025 08:13:46 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Chainguard]]></category>
		<category><![CDATA[Chainguard Containers]]></category>
		<category><![CDATA[Cloud]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[Enterprises]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[Virtual Machine Software]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=52389</guid>

					<description><![CDATA[<p>Chainguard simplifies PCI compliance with minimal, zero-CVE containers built entirely from source</p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/">Start-up of the Week: Armed with fresh funding, Chainguard eyes to become major cybersecurity player</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Computer and cloud security start-up Chainguard hit the headlines recently by closing its latest funding round valued at USD 3.5 billion, almost tripling in less than a year, underscoring sustained investor appetite for robust digital infrastructure. The company had raised USD 356 million in a series D round, led by new investor Kleiner Perkins and existing investor IVP, with additional participation from new investors such as Salesforce Ventures and Datadog Ventures.</p>
<p>As industries are embracing AI and technology rapidly, so are the worries around <a href="https://internationalfinance.com/technology/alphabet-talks-buy-cybersecurity-start-up-wiz-usd-billion/"><strong>cybersecurity</strong></a>. Enterprises prioritise protective measures against online attacks and hacks, prompting businesses to spend more on safeguarding their domains.</p>
<p>Against this backdrop, Chainguard, whose customers include Anduril, ANZ Bank, Canva, GitLab and Hewlett Packard Enterprise, has stood up to the occasion by providing tools and services to help clients keep their software secure. At the same time, it is also cementing its place as a key cybersecurity player, as it has so far raised USD 612 million. The start-up, founded in 2021, grew its annual recurring revenue seven times to USD 40 million in fiscal year 2025.</p>
<p>In today&#8217;s episode of the &#8220;Start-up of the Week,&#8221; International Finance will talk about the company in detail.</p>
<p><strong>The Safe Source For Open Source</strong></p>
<p>Chainguard has built a secure, trusted software supply chain that &#8220;empowers teams to build the future instead of patching the past.&#8221;</p>
<p>&#8220;The status quo in open source has led to high-profile security breaches, countless hours of engineering toil, and compliance failures. Enterprises need a new mechanism for open-source software delivery,&#8221; the start-up stated.</p>
<p>The safe open-source software has been rebuilt from source in secure environments with end-to-end integrity, with the vision of ensuring a future where security and innovation move in lockstep and every line of code makes software safer.</p>
<p>&#8220;As high-profile attacks exposed systemic weaknesses, organisations struggled to secure their development pipelines without adding friction for engineers. Existing solutions were complex, reactive, and often ineffective, so Chainguard set out to build a safe source for open source. Today, Chainguard helps organisations eliminate threats in their software supply chains by providing guarded open-source software, built from source and updated continuously,&#8221; the company added.</p>
<p>Chainguard&#8217;s software supply chain has enabled its client companies to save 288,000 engineering hours. Additionally, it has addressed more than 72,000 Common Vulnerabilities and Exposures (CVEs)—a widely recognized list of publicly disclosed security flaws in computer systems. Most importantly, this effort has resulted in an 80% reduction in the attack surface.</p>
<p>Chainguard&#8217;s software supply chain is run by &#8220;Container Image Security,&#8221; which builds, ships, and runs hardened, minimal container images.</p>
<p>The company commented, &#8220;Our suite of hardened, minimal container images help <a href="https://internationalfinance.com/technology/if-insights-ai-real-threat-software-developers/"><strong>developers</strong></a> start secure and stay secure throughout the software development lifecycle. With 97.6% fewer vulnerabilities than alternatives, Chainguard Containers help you reach vulnerability requirements for compliance frameworks like NIST 800-53, FedRAMP, or StateRAMP.&#8221;</p>
<p>The software supply chain performs another crucial function called &#8220;Vulnerability Remediation,&#8221; where it prioritises speed and precision to eliminate CVEs daily in the open-source software the client companies consume, so the latter’s developers can spend their time honing their craft. No more constantly monitoring security spreadsheets, running known-vulnerable software, or manually patching images.</p>
<p>When it comes to compliance and risk mitigation, the Chainguard Containers solution eliminates vulnerabilities in the clients&#8217; containers that repeatedly impact their compliance certifications for FedRAMP, PCI-DSS, SOC 2, and more. Human cybersecurity professionals get relieved of repetitive tasks like patching, updating, and hardening container images to meet and maintain compliance requirements faster.</p>
<p>The start-up also helps its clients build secure software with images that include Signatures, SLSA Provenance (verifiable information about software artefacts describing where, when and how something was produced), and SBOMs (Software Bill of Materials is a comprehensive inventory of all the software components, including their versions, dependencies, and associated metadata, that make up a software application), thereby providing the building blocks for a secure software supply chain.</p>
<p>On the AI/ML Security front, Chainguard AI Images are a suite of CPU and GPU-enabled container images, including popular frameworks like PyTorch, Conda, and Kafka. These images are hardened, minimal, and optimised for efficient AI development and deployment. By leveraging Chainguard AI Images, organisations can confidently secure their AI infrastructure, streamline vulnerability management, and maintain high performance with low-to-zero vulnerabilities.</p>
<p>PCI DSS (Payment Card Industry Data Security Standard) requirements for vulnerability management drive add significant worry and complexity for companies investing in their digital architectures, especially when it comes to the data authentication task.</p>
<p>Chainguard simplifies PCI compliance with minimal, zero-CVE containers built entirely from source. The start-up offers minimal, zero-CVE images by default, shrinking its clients&#8217; compliance and auditing worries from day one.</p>
<p>Chainguard helps its clients eliminate PCI DSS overhead and costs with source build pipelines, supply chain transparency, and CVE management. The start-up mitigates the risk of costly security breaches and failed audits, which incite heavy fines and penalties from regulators.</p>
<p><strong>Here Is The Product Line-up</strong></p>
<p>Among Chainguard&#8217;s key products is &#8220;Chainguard Containers,&#8221; which helps companies build software better with minimal, zero-CVE container images guarded under the start-up&#8217;s industry-leading remediation SLA (Service-Level Agreement).</p>
<p>The solution enables companies to adopt inherently secure software, allowing engineers to focus more on delivering products and less on patching Common Vulnerabilities and Exposures (CVEs). Additionally, it leverages trusted open-source solutions to enhance security and minimize the attack surface for potential threats. Addressing critical compliance controls by default helps reduce overhead costs and accelerates the time to market for products.</p>
<p>Next is &#8220;Chainguard Libraries,&#8221; which stop software supply chain attacks without compromising developer experience and productivity with language dependencies built securely in SLSA-hardened build infrastructure.</p>
<p>Using the tool, companies can eliminate risks from compromised build systems and hijacked package distribution mechanisms to prevent attacks like XZ-Utils, MavenGate, and Lottie Player. Chainguard Libraries free up developers to ship faster by eliminating toil and productivity erosion associated with manual and/or policy-based package curation, apart from offloading the hard work of vendors in shared system libraries for dynamically linked languages.</p>
<p>These language libraries get built from source in Chainguard’s SLSA Level 2 build infrastructure, eliminating supply chain attacks at the build and distribution phases of the package lifecycle. Businesses can use the start-up&#8217;s language libraries anywhere to develop and deploy the code.</p>
<p>Chainguard helps IT companies standardise their developers on a safe and secure mechanism to consume language dependencies. Chainguard Libraries natively integrate with common artefact managers so developers can pull trusted dependencies without any additional friction.</p>
<p>Finally, we have Chainguard&#8217;s &#8220;Virtual Machine Software,&#8221; which hosts image containers on optimised, minimal, zero-CVE virtual machine images rebuilt from source daily for ephemeral cloud instances. The start-up described this particular solution as the security and innovation-friendly container host that meets &#8220;critical compliance controls by default with zero-CVE container hosts guarded under a CVE remediation SLA.&#8221;</p>
<p>The &#8220;Virtual Machine Software&#8221; also focuses on differentiated product experiences, in addition to reducing the burden on engineering and security teams for CVE triage, management, and remediation, while carrying out innovations on the security and performance optimisation front without costly and complex major upgrades.</p>
<p><small>Image Credits: Chainguard</small></p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/">Start-up of the Week: Armed with fresh funding, Chainguard eyes to become major cybersecurity player</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/start-up-week-armed-with-fresh-funding-chainguard-eyes-become-major-cybersecurity-player/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Start-up of the Week: Anagram’s cutting-edge approach to cybersecurity training</title>
		<link>https://internationalfinance.com/technology/start-up-week-anagrams-cutting-edge-approach-cybersecurity-training/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=start-up-week-anagrams-cutting-edge-approach-cybersecurity-training</link>
					<comments>https://internationalfinance.com/technology/start-up-week-anagrams-cutting-edge-approach-cybersecurity-training/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Wed, 19 Mar 2025 14:36:39 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Anagram]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Emails]]></category>
		<category><![CDATA[Harley Sugarman]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[Social Engineering Campaigns]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=52201</guid>

					<description><![CDATA[<p>In February 2025, Anagram raised a $10 million Series A round led by Madrona, with participation from General Catalyst, Bloomberg Beta, and Operator Partners, among others</p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-anagrams-cutting-edge-approach-cybersecurity-training/">Start-up of the Week: Anagram’s cutting-edge approach to cybersecurity training</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>As per the latest EY and Institute of International Finance (IIF) bank risk management survey, aside from geopolitical risks, banks worldwide are also facing pressure on the cybersecurity front. Speaking about cybersecurity, this phenomenon has emerged as the long-term primary concern, with 75% of Chief Risk Officers (CROs) agreeing that it is the chief risk over the next 12 months, and it remains the primary near-term concern.</p>
<p>While companies are adopting strategies such as making it mandatory for their employees to complete yearly cybersecurity training courses, human-driven cybersecurity breaches continue to occur. The situation could worsen in the coming days as generative AI increases the scale and personalisation of social engineering campaigns. To address this challenge, Anagram, formerly known as Cipher, is taking a new approach to employee cybersecurity training that the start-up hopes will keep pace with the evolving nature of these social engineering campaigns.</p>
<p>In today’s edition of the &#8220;Start-up of the Week,&#8221; International Finance will delve into the New York-based venture, which is now known for its virtual platform that offers hands-on security training for enterprises. This method includes bite-sized videos and personalised interactive puzzles designed to teach employees how to spot suspicious emails and communications. These training sessions are frequent and engaging, as opposed to the current standard of a once-yearly, lengthy training session. In this way, businesses and their employees stay updated on the latest trends in the world of cybercrime.</p>
<p><strong>A Game-Changing Training Method</strong></p>
<p>According to Harley Sugarman, founder and CEO of <a href="https://www.anagramsecurity.com/"><strong>Anagram</strong></a>, the training activities primarily include tasks such as having employees create their own personalised phishing emails, which, in turn, teach them how to identify sophisticated campaigns aimed at them.</p>
<p>“We took very little, in fact, basically no inspiration from the existing stuff out there. What we really took were lessons from TikTok, Duolingo, and Khan Academy. We looked at these platforms that have done really well engaging and changing user behaviour outside the security space, and we asked ourselves, ‘OK, how can we apply those lessons within security?’” Sugarman explained to TechCrunch, highlighting what differentiates Anagram&#8217;s cybersecurity training from existing methods.</p>
<p>Harley Sugarman, a computer science professional, initially sought to apply the cybersecurity industry’s “capture the flag” training approach to upskill enterprise cybersecurity employees. This training method involves building software with vulnerabilities and having security researchers find the bugs and figure out how to write code without falling into the same traps.</p>
<p>That initiative evolved into Cipher in 2022 and gained some traction. However, Harley Sugarman faced another challenge: chief information security officers (CISOs) told him that their businesses had a bigger security issue they were looking to tackle—their non-security employees. He said CISOs described their employees as their weakest cybersecurity link.</p>
<p>“What sort of surprised me was actually just the amount of hopelessness I heard in their voices. This was an unsolvable problem for them,” Sugarman said.</p>
<p>Cipher then scaled up in January 2024 to focus on solving that problem. In 2025, the venture changed its name to Anagram to reflect its new focus and is winding down its original product. In addition to strong growth following its rebranding, Anagram has secured high-profile clients, including Thomson Reuters, MassMutual, and Disney, among others.</p>
<p>In February 2025, Anagram raised a $10 million Series A round led by Madrona, with participation from General Catalyst, Bloomberg Beta, and Operator Partners, among others. The company now plans to use the funds to expand its sales team and continue improving the product. Sugarman said that so far, the start-up has been able to reduce client companies&#8217; <a href="https://internationalfinance.com/technology/after-fake-companies-linkedin-threat-ai-phishing-campaigns/"><strong>phishing</strong></a> failure rates from 20% to 6%, but the goal is to continue moving closer to zero.</p>
<p><strong>Understanding The Method In Detail</strong></p>
<p>According to Harley Sugarman, Anagram launched its product at a pivotal moment for the cybersecurity industry. As generative AI advances, so do personalised social engineering campaigns, which can make it more difficult for people to distinguish between what is real and what isn’t.</p>
<p>“I think the side effect of that is that traditional email security platforms are actually going to have a much harder time detecting these AI-generated phishing attempts. The ability to generate and randomise is just so strong, and it’s really difficult, from an engineering perspective, to defend against that,” Sugarman explained.</p>
<p>To address this challenge, Anagram has divided its hands-on security training into two parts: &#8220;Security Awareness Training&#8221; and &#8220;Developer Training.&#8221; The first method operates under the motto &#8220;Bite-Sized Lessons, Big Results.&#8221; The start-up describes this approach as &#8220;quick, real-world training that leverages the science of learning so your (business’s) employees know how to spot and stop an attack.&#8221;</p>
<p>&#8220;Security Awareness Training&#8221; launches phishing simulations within minutes using Anagram&#8217;s best-in-class templates (even assisting companies in building their own campaigns). It also integrates a company’s cybersecurity policies directly into the training method, ensuring that everyone understands the rules and stays safe.</p>
<p>When it comes to combating cybersecurity threats, employees within a company—just like their varied roles and responsibilities—face different threats and challenges. To address this, Anagram offers both general and topic-specific modules so users can create programmes relevant to their operational needs.</p>
<p>Every October, the start-up offers a gamified &#8220;Awareness Month Programme&#8221; for companies. However, the most unique aspect of the &#8220;Security Awareness Training&#8221; is its content library, which covers cybersecurity challenges such as business email compromise, coding with AI, handling sensitive data, detecting deepfakes, holiday scams, insider threats, tax scams, sharing data externally, social engineering, wire fraud, and more.</p>
<p>Regarding &#8220;Developer Training,&#8221; the start-up focuses on real-world scenarios, whether protecting secret keys, tackling API vulnerabilities, or preventing software supply chain attacks. The training also includes interactive sandboxes where software developers and website builders can learn security best practices in a safe, realistic environment.</p>
<p>Since the threats developers face are constantly evolving, Anagram uses examples pulled from actual vulnerabilities and breaches, so developers can learn how to tackle the issues they are most likely to encounter.</p>
<p>The training method, which is updated multiple times a year to keep up with the ever-changing cyber landscape, covers topics such as SQL injection, managing secrets, broken access control, cross-site scripting (XSS), validating API design, cryptographic failures, insecure logging and monitoring, avoiding outdated components, protecting backups, detecting SSRF, securing cloud infrastructure, and ensuring software and data integrity.</p>
<p><strong>The Road Ahead</strong></p>
<p>Anagram is currently working on developing an AI agent that will be embedded in enterprise employees’ emails and will be trained to flag potential cybersecurity slip-ups before they happen.</p>
<p>According to Sugarman, the agent will be able to intervene by asking employees whether they really want to send their credit card information over email, among other similar safeguards.</p>
<p>Last but not least, Anagram is also currently partnering with renowned industry leaders, including Steve Zalewski (Levi Strauss), Lena Smart (MongoDB), Tim Youngblood (McDonald’s, T-Mobile), David Cross (Atlassian, Oracle), and Andrew Wilder (Nestlé). These collaborations underscore Anagram’s commitment to driving innovation and delivering impactful security solutions.</p>
<p>By blending customised microlearning with real-time security scenarios, the platform has disrupted cybersecurity training in a positive way. This approach has attracted the attention of leading global enterprises, including several from the Fortune 500. Expect the start-up to make even more waves in the coming days.</p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-anagrams-cutting-edge-approach-cybersecurity-training/">Start-up of the Week: Anagram’s cutting-edge approach to cybersecurity training</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/start-up-week-anagrams-cutting-edge-approach-cybersecurity-training/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>African banks post strong profits amidst hurdles</title>
		<link>https://internationalfinance.com/magazine/banking-and-finance-magazine/african-banks-post-strong-profits-amidst-hurdles/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=african-banks-post-strong-profits-amidst-hurdles</link>
					<comments>https://internationalfinance.com/magazine/banking-and-finance-magazine/african-banks-post-strong-profits-amidst-hurdles/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Tue, 25 Feb 2025 03:04:46 +0000</pubDate>
				<category><![CDATA[Banking and Finance]]></category>
		<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Africa]]></category>
		<category><![CDATA[banking]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[JPMorgan Chase]]></category>
		<category><![CDATA[Kenya]]></category>
		<category><![CDATA[Nairobi]]></category>
		<category><![CDATA[Nigeria]]></category>
		<category><![CDATA[payment]]></category>
		<category><![CDATA[WhatsApp]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=52414</guid>

					<description><![CDATA[<p>JPMorgan Chase, the biggest bank in the world by market capitalisation, is expanding in Africa, with plans to open an office in Nairobi, Kenya</p>
<p>The post <a href="https://internationalfinance.com/magazine/banking-and-finance-magazine/african-banks-post-strong-profits-amidst-hurdles/">African banks post strong profits amidst hurdles</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Kenya&#8217;s commercial banks have overcome a difficult environment characterised by rising loan defaults and decreased borrowing demand to record an impressive 11.58% increase in pre-tax profits, totalling $1.22 billion for the first eight months of 2024.</p>
<p>The banking industry&#8217;s resilience is demonstrated by data from the Central Bank of Kenya (CBK), which indicates that profits have increased from $1.09 billion during the same period last year.</p>
<p>CBK Governor Kamau Thugge claims that March was the banks&#8217; best-performing month, with pre-tax profits hitting $184 million.</p>
<p>On the other hand, August saw the lowest profits of $119 million, the only month since January when profits fell below $136 million. Despite this minor decline, the banking industry has continued to grow while other economic sectors have experienced severe disruptions.</p>
<p>Kenya had a difficult year, marked by challenges such as severe flooding and rain from March to June, political turmoil with anti-government demonstrations in June and July, and limited liquidity.</p>
<p>Despite challenges, banks have shown resilience, with the finance and insurance industry expanding by 7% in the first quarter of 2024, according to the Kenya National Bureau of Statistics.</p>
<p>However, in the second quarter, this growth slowed to 5.1%. According to the CBK, the banking industry will expand by 6% for the entire year, which is the slowest growth since the COVID-19 pandemic hit the economy in 2020, when growth was only 5.9%.</p>
<p>The general economic outlook seems more muted. The CBK has revised its prediction for the growth of the national economy from 5.4% to 5.1%. This change follows a slowdown in the second quarter, when growth slowed to 4.6% compared to 5.6% during the same time last year. Lending has decreased, which has also affected Kenyan banks.</p>
<p>The loan book for this sector was $27.2 billion at the end of August, a $1 billion decrease from $28.2 billion at the end of 2023. As the value of the Kenyan shilling increased relative to the United States dollar, this indicates both a decrease in lending and a depreciation of loans denominated in dollars.</p>
<p>The expansion of private sector credit has decreased dramatically; in August, it was only 1.3%, the lowest level in over five years. At the same time, the non-performing loan ratio rose to 16.7%, the highest level in 18 years. High credit costs have coincided with an increase in defaults and a decrease in borrowing. In February 2024, Kenya&#8217;s benchmark lending rate reached a 12-year high of 13%.</p>
<p>The CBK implemented consecutive reductions to the benchmark rate, bringing it down to 12%, in an effort to alleviate the burden on borrowers in response to these economic pressures. Reviving economic activity and encouraging borrowing are the goals of this.</p>
<p>In a statement, CBK said, &#8220;The Monetary Policy Committee noted the sharp deceleration in private sector credit and the slowdown in economic growth during the second quarter of 2024. It concluded that there was scope for further easing of monetary policy to boost economic activity while ensuring exchange rate stability.&#8221;</p>
<p>The performance of the industry will still be strongly correlated with more general economic developments, such as initiatives to control inflation, exchange rate swings, and international financial circumstances.</p>
<p><strong>Strong security over PoS rollout</strong></p>
<p>Network International, a Middle Eastern and African digital commerce enabler, has reaffirmed its commitment to ensuring strong cybersecurity measures as it launches new payment solutions in Kenya.</p>
<p>Judy Waruiru, its Regional Managing Director for East and South Africa, said, &#8220;We are introducing our point-of-sale (POS) solutions as part of our strategy to enter the in-person payments market in Kenya, a key hub for East Africa.&#8221;</p>
<p>Network International is providing merchants with new point-of-sale solutions at no cost as part of this rollout, enabling companies of all sizes to conveniently accept payments in-store or while on the go.</p>
<p>In order to accommodate a variety of payment preferences, customers will also have the option to pay with cards or mobile wallets. As the number of digital transactions in the area rises, the business is expanding its service portfolio and addressing growing concerns about payment system security.</p>
<p>During an interaction with African Banker, Paul Mutethia, Head of Commercial at Network International Kenya, said, &#8220;The risks in cyberspace have increased, especially Denial of Service, malicious codes, botnets, and bugs which hamper operations. We secure our internal systems when they interact with the external environment. Our transactions are encrypted, and all our solutions are secure. We ensure there is no exposure to cyber-attacks because we hold sensitive customer data.&#8221;</p>
<p>He revealed that there is a dedicated department within the company that handles threat management and cyberspace monitoring. It would be better to close the business if you don&#8217;t make any investments in cybersecurity.</p>
<p>According to data from the Central Bank of Kenya, there are only slightly more than 55,000 point-of-sale machines in the country. This is insignificant when you consider that the Kenya National Bureau of Statistics reports that there are 7.4 million registered micro, small, and medium-sized businesses (MSMEs). This reveals a serious weakness in the infrastructure for digital payments for companies across the nation.</p>
<p>The most recent products from Network International include contactless payment systems, improved mobile payment gateways, and e-commerce solutions designed to increase convenience while upholding strict security regulations.</p>
<p><strong>JPMorgan Chase eyes presence in Nairobi</strong></p>
<p>JPMorgan Chase, the biggest bank in the world by market capitalisation, is expanding in Africa, with plans to open an office in Nairobi, Kenya.</p>
<p>The bank is the largest lender in the United States, with $4 trillion in assets and operations in more than 100 countries.</p>
<p>It received an operating license from the Central Bank of Kenya (CBK) just days before Jamie Dimon, the CEO of the bank, travelled to the country. The action is part of the bank&#8217;s strategy for global expansion and demonstrates its increasing interest in making investments in the African market.</p>
<p>The bank has identified Africa, which has the youngest population in the world, as a key growth region due to its fintech innovations and the rise in institutional bankers.</p>
<p>In October 2024, JPMorgan Chairman and CEO Jamie Dimon travelled to Kenya as part of a trip to Africa that also included stops in South Africa and Nigeria.</p>
<p>“We are opening our first branch in Kenya, which we are really happy to do. We want to add a country or two in Africa every couple of years or so. And when you do it, you are basically covering the government, maybe some big government enterprises, and the multinationals that are going in there with traditional banking services,&#8221; Jamie Dimon said during an event in Nigeria.</p>
<p>Sailepu Montet, a former executive at CBK, has been appointed as the bank&#8217;s new Country Manager for Kenya. He has more than 20 years of banking experience and a solid foundation in financial markets from both the public and private sectors.</p>
<p>According to Dimon, the bank&#8217;s primary areas of interest are treasury services, commercial and investment banking, and possibly some lending in Kenya. Nevertheless, it does not currently have any plans to provide asset and wealth management services in the country, which are already offered in Nigeria and South Africa.</p>
<p>“We are not doing asset and wealth management now, but that doesn’t mean it won’t happen in the next few years,” Dimon added.</p>
<p>Nairobi was selected as the site for JPMorgan Chase&#8217;s office because of its growing prominence as a technology hub and its status as the gateway to the wider East African market, which makes it a desirable location for companies wishing to grow throughout the region.</p>
<p>Ten international banks, including Bank of China, Access Bank of Nigeria, Bank of Kigali, First Rand Bank and Nedbank of South Africa, Rabobank of Mauritius, and French lender Societe Generale, have representative offices in Nairobi.</p>
<p>The bank must, however, differentiate its offerings in various markets, such as Kenya, where regional and local lenders are well-represented. There are 46 commercial banks in the nation, providing services to 55 million people.</p>
<p><strong>Nigerian banks go big</strong></p>
<p>One of Nigeria’s leading commercial banks, First Bank, is now planning to expand to at least three African countries in its next growth phase, starting in 2025.</p>
<p>According to the Deputy Managing Director of the bank, Ini Ebong, the countries being targeted include Ethiopia, Angola, Cameroon, and Ivory Coast.</p>
<p>He asserted that there are growing opportunities in markets across the African continent, similar to “what we saw in the early 2000s in some of the larger African markets. We believe it is an opportune time to take part in this phase of growth.”</p>
<p>In December 2024, the Ethiopian parliament passed a law that allows foreign banks to open subsidiaries in Ethiopia. Foreign firms will only be allowed to own 49% of shares.</p>
<p>Also, during a panel session at the recently concluded Africa Financial Industry Summit, Ethiopia’s central bank governor, Mamo Mihretu, said the country had been working on the legislation that would finally open the banking sector to foreign competition over the past year.</p>
<p>FirstBank, which has been operating in Nigeria for 130 years, began establishing subsidiaries in other African markets in 2011 when it acquired Banque International de Credit, one of the leading banks in the Democratic Republic of Congo.</p>
<p>In November 2013, it acquired subsidiaries of International Commercial Bank Financial Group Holdings AG (ICBFGH) in The Gambia, Sierra Leone, Ghana, and Guinea. It purchased ICB Senegal the following year, completing its acquisition of West African assets and operations of ICBFGH. FirstBank also has operations in London and Paris, France, as well as a representative office in Beijing, China.</p>
<p>In January 2025, news emerged about Bidvest Bank being sold to Nigerian-based Access Bank, which is set to expand the latter’s operations in South Africa substantially. Johannesburg Stock Exchange-listed Bidvest is now eyeing the disposal of 100% of its holdings to Access Bank.</p>
<p>Bidvest is expected to raise R2.8 billion from the sale, which will then be used to settle its existing debt. Access Bank, on the other hand, plans to implement Broad-Based Black Economic Empowerment (BBBEE) ownership, including an Employee Stock Ownership Plan. The acquisition is expected to close in the second half of 2025, subject to regulatory approvals in South Africa and Nigeria.</p>
<p>The Bidvest Bank book, which mainly consists of leased assets, loans and advances, totalled R6 billion in December, and was funded by deposits of R8 billion. In its most recent financial year, Bidvest Bank generated a trading profit of R371 million and an operating income of R377 million.</p>
<p>Speaking of Access Bank, the largest lender in Nigeria by assets, it has established itself as a full-service bank with over 60 million customers globally across three continents, serving three principal segments: retail, business, commercial, and corporate.</p>
<p>Following the acquisition, Bidvest Bank is set to be merged with Access Bank’s existing South African subsidiary to create an enlarged platform to anchor the regional growth strategy for the SADC region.</p>
<p>Using Bidvest Bank’s local capabilities and its established pan-African presence, Access Bank now hopes to have increased capacity for intra- and inter-Africa trade, connect businesses, and create new opportunities for regional integration.</p>
<p>The Nigerian-based company noted that South Africa’s banking sector is the largest in Africa, with a combined tier-one capital exceeding $42.2 billion in 2022. Despite a tough operating environment, the industry still achieved headline earnings growth of 2.5% year-on-year and maintained strong profitability (ROE of 17%) in the first half of 2024. Access Bank will now leverage the latest acquisition to strengthen its business and SME banking as well as its foreign exchange services, while also introducing new services tailored to the South African market.</p>
<p>Access Bank has already been operating in South Africa since 2021 after it acquired Grobank Limited. Grobank, which was previously known as Bank of Athens, was primarily focused on agriculture before Access Bank transformed it into a retail banking operation. The group currently offers personal, business, and corporate banking in South Africa.</p>
<p><strong>Banks embrace WhatsApp banking</strong></p>
<p>In order to process payments more quickly and interact with customers more effectively, Kenyan banks are increasingly using WhatsApp banking. Conversational banking is encouraged by this model, which also streamlines customer journeys and improves user intuitiveness.</p>
<p>Kenya’s Housing Finance Group, commonly referred to as HF Group, became the first major bank in the country to deploy WhatsApp banking in 2019.</p>
<p>HF Group CEO Robert Kibaara said, “Customers can simply add HF’s WhatsApp phone number to begin a secure banking chat session.”</p>
<p>Since 2019, the KCB Group, Kenya&#8217;s biggest bank by assets, has also adopted WhatsApp banking. KCB hopes to improve its communications by utilising widely used messaging platforms as part of a larger plan to offer individualised services.</p>
<p>A subsidiary of South Africa&#8217;s Absa Group, Absa Bank Kenya, followed suit in 2021 by launching the &#8220;Abby&#8221; WhatsApp banking service.</p>
<p>A Mumbai doctor&#8217;s loss of $2,000 from his WhatsApp wallet raised cybersecurity concerns, while many Kenyan consumers were ecstatic about the new banking model at the time.</p>
<p>“We have put up stringent measures to make WhatsApp banking secure for everyone. We have several security layers on the platform,&#8221; the bank’s head of digital channels, Andrew Mwithiga, told African Banker.</p>
<p>In 2022, Equity Group, which has the largest customer base in Kenya, introduced the Equity Virtual Assistant, a WhatsApp banking platform. With its open banking model, I&amp;M Bank has also entered the WhatsApp banking space, initially providing customer service for non-transactional enquiries.</p>
<p>Through its AI-powered chatbot, Zuri, M-Pesa, the top mobile money platform in the world, has integrated WhatsApp banking since 2020. In Kenya, M-Pesa is used by more than 95% of households.</p>
<p>According to Statista, as of January 2024, 86% of Kenyan internet users were using WhatsApp, making it the most popular messaging app in the country. In Kenya, there were 7.9 million WhatsApp users as of 2023.</p>
<p>Meanwhile, an €8.51 million loan from the African Development Bank has been approved for Senegal&#8217;s &#8220;Programme to Promote Efficient Lighting Lamps&#8221; (PPLEEF), a groundbreaking project aimed at promoting energy efficiency in the nation. This establishes a new standard for sustainable development in Africa and is the bank&#8217;s first entirely focused demand-side energy efficiency investment project.</p>
<p>The post <a href="https://internationalfinance.com/magazine/banking-and-finance-magazine/african-banks-post-strong-profits-amidst-hurdles/">African banks post strong profits amidst hurdles</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/banking-and-finance-magazine/african-banks-post-strong-profits-amidst-hurdles/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Start-up of the Week: UK-based Mindgard eyes making &#8216;AI Security&#8217; the new normal</title>
		<link>https://internationalfinance.com/technology/start-up-week-uk-based-mindgard-eyes-making-ai-security-the-new-normal/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=start-up-week-uk-based-mindgard-eyes-making-ai-security-the-new-normal</link>
					<comments>https://internationalfinance.com/technology/start-up-week-uk-based-mindgard-eyes-making-ai-security-the-new-normal/#respond</comments>
		
		<dc:creator><![CDATA[IFM Correspondent]]></dc:creator>
		<pubDate>Wed, 15 Jan 2025 13:38:48 +0000</pubDate>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[AI Security]]></category>
		<category><![CDATA[Artifact Scanning]]></category>
		<category><![CDATA[automation]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[investments]]></category>
		<category><![CDATA[Mindgard]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[technology]]></category>
		<guid isPermaLink="false">https://internationalfinance.com/?p=51923</guid>

					<description><![CDATA[<p>Mindgard’s red teaming services combine deep expertise in cybersecurity, AI security, and threat research to complement its DAST-AI solution</p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-uk-based-mindgard-eyes-making-ai-security-the-new-normal/">Start-up of the Week: UK-based Mindgard eyes making &#8216;AI Security&#8217; the new normal</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>The global economy of the 21st century revolves around industries rapidly adopting technology, particularly <a href="https://internationalfinance.com/technology/artificial-intelligence-helping-employees-lets-find-out-truth/"><strong>artificial intelligence</strong></a> (AI), to enhance productivity and ensure future readiness. However, if this adoption is not handled correctly, both businesses and their clients may face &#8220;digital risks,&#8221; primarily concerning cybersecurity. To tackle these issues, there has been a surge of start-ups specialising in a field known as &#8220;Security for AI.&#8221;</p>
<p>We have Israeli start-up Noma and United States-based competitors Hidden Layer and Protect AI. However, in today&#8217;s episode of the &#8220;Start-up of the Week,&#8221; International Finance will talk about British University spinoff <a href="https://mindgard.ai/"><strong>Mindgard</strong></a>.</p>
<p>In the words of Professor Peter Garraghan, the CEO and CTO of the start-up, “AI is still software, so all the cyber risks that you probably heard about also apply to AI. But, if you look at the opaque nature and intrinsically random behaviour of neural networks and systems.”</p>
<p><strong>The Mindgard Way Of Ensuring AI Security</strong></p>
<p>Established in 2022, the start-up first hit the headlines in 2024, as it emerged as the winner of the &#8220;Cyber Innovation Prize,&#8221; at Infosecurity Europe 2024. Mindgard’s approach to ensuring “Security for AI&#8221; is a thing called &#8220;Dynamic Application Security Testing for AI&#8221; (DAST-AI), which targets vulnerabilities that can only be detected during runtime. The process involves continuous and automated red teaming, a way to simulate attacks based on Mindgard’s threat library.</p>
<p>Mindgard’s technology has been a brainchild of Professor Garraghan’s academic background as a researcher focused on AI security. For him, LLMs (Large Language Models, type of AI programme that can generate and recognise texts) are rapidly changing, and so do the threats around these models. Using his ties with Lancaster University, Professor Garraghan envisions Mindgard automatically own the IP to the work of 18 additional doctorate researchers for the next few years.</p>
<p>While it has ties to research and development activities in the “Security for AI&#8221; field, Mindgard has very much become a commercial product already, and more precisely, a SaaS (Software-as-a-Service) platform. Despite having enterprises as clients, Professor Garraghan’s company also works with AI start-ups, with many from the United States, that need to show their customers they do AI risk prevention.</p>
<p>After raising a 3-million-pound seed round in 2023, Mindgard is now announcing a new USD 8 million round led by Boston-based .406 Ventures, with participation from Atlantic Bridge, WillowTree Investments, and existing investors IQ Capital and Lakestar. The funding will help with building the team, product development, research and development, but also expand into the <a href="https://internationalfinance.com/trading/chinese-premier-li-qiang-pushes-stronger-economic-trade-ties-united-states/"><strong>United States</strong></a>.</p>
<p><strong>Key Products And Services</strong></p>
<p>Talking about Mindgard&#8217;s R&#038;D activities, we have DAST-AI or &#8220;Dynamic Application Security Testing for AI&#8221; to begin with, which, powered by the world&#8217;s largest attack library for AI, enables red teams (group of security professionals who simulate cyber-attacks to test an organisation&#8217;s security), security and developers to swiftly identify and remediate AI security vulnerabilities.</p>
<p>Tech professionals can find and remediate their AI vulnerabilities on a proactive basis, by integrating into existing CI/CD automation and all SDLC stages, as DAST-AI provides extensive model coverage beyond LLMS, including image, audio and multi-modal, thereby empowering the red teams to Identify AI risks that static code or manual testing cannot detect.</p>
<p>Also, DAST-AI helps its users to reduce testing times on their AI models from months to minutes, by helping them to gain actionable visibility with the most accurate AI security insights, thereby empowering teams to swiftly address emerging threats.</p>
<p>To access DAST-AI, the users need to point the Mindgard platform to their existing AI products and environments, following which the tool starts its things by effortlessly running custom or scheduled tests on the client&#8217;s AI models, generating a detailed view of scenarios and threats to the model, apart from quickly analysing them. The clients can integrate report viewing smoothly into their existing systems and SIEM (Security Information and Event Management).</p>
<p>DAST-AI works on the &#8220;Testing, Remediation and Training&#8221; model where world-class AI expertise from academia and industry is providing continuous security testing across the technology lifecycle, apart from integrating into existing organisational workflow and automation, thereby helping Mindgard&#8217;s clients to safeguard their AI assets by continuously testing and remediating security risks, ensuring the security of both third-party AI models and in-house solutions.</p>
<p>Next is &#8220;Artifact Scanning,&#8221; which ensures AI systems are secure and function as intended in live environments. It’s a real-time threat response tool that protects AI models with continuous monitoring and advanced security testing. Mindgard’s &#8220;Run-Time Artifact Scanning&#8221; identifies vulnerabilities, analyses risks, and integrates seamlessly into the user&#8217;s workflows to keep AI investments secure and compliant.</p>
<p>If a client connects his/her AI models with Mindgard for run-time artifact scanning, the process supports a variety of frameworks and deployment environments. &#8220;Artifact Scanning&#8221; carries out comprehensive tests on the AI model including adversarial attacks and configuration checks, to identify weaknesses in real-time, apart from getting a detailed view of scenarios and threats. The tool then integrates results into the client&#8217;s existing systems for streamlined monitoring and incident response, helping businesses gain immediate visibility into their AI security posture.</p>
<p>Artifact Scanning&#8217;s offline profiling leverages analytics and Mindgard&#8217;s AI threat intelligence repository to identify vulnerabilities and attack patterns that can be addressed before deployment. Run-time testing builds on this foundation by evaluating ML model artifacts in a secure staging environment, detecting dynamic risks such as prompt injection that static analysis cannot uncover.</p>
<p>Together, these processes ensure that both known and emerging threats are addressed, providing robust protection for businesses&#8217; AI investments. Continuous monitoring ties everything together, enabling proactive threat detection and ongoing security assurance.</p>
<p><strong>AI Red Teaming And Pentesting As A Service</strong></p>
<p>Mindgard’s red teaming services combine deep expertise in cybersecurity, AI security, and threat research to complement its DAST-AI solution. The start-up&#8217;s security experts specialise in adversarial testing techniques that are tailored to 21st century enterprises&#8217; specific business objectives and AI environments. By leveraging its unique skill set, Mindgard is empowering its clients&#8217; data science and security teams with actionable insights to strengthen defences and fully protect commercial AI systems.</p>
<p>Mindgard conducts a thorough analysis of a business&#8217; AI/ML operations lifecycle, along with a deep review of the client&#8217;s most critical models to identify risks that could threaten the organisation. The findings are mapped to industry best practices, including NIST, MITRE ATLAS, and OWASP, delivering actionable guidance to strengthen cyber defences and reduce organisational risk.</p>
<p>Mindgard delivers a training programme designed to equip data science and security personnel with a deep understanding of adversarial machine learning tactics, techniques, and procedures (TTPs), along with the most effective countermeasures to defend against them. The training includes actionable insights on integrating ML model testing into a company&#8217;s internal processes and an overview of leading offensive AI tools, such as PyRIT, Garak, PINCH and more.</p>
<p>The post <a href="https://internationalfinance.com/technology/start-up-week-uk-based-mindgard-eyes-making-ai-security-the-new-normal/">Start-up of the Week: UK-based Mindgard eyes making &#8216;AI Security&#8217; the new normal</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/start-up-week-uk-based-mindgard-eyes-making-ai-security-the-new-normal/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
