IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. […]
Global Security News
DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub
The Justice Department and FBI announced that they had seized two hacking tools connected to the Chinese government-linked group Flax Typhoon and a China-based company that the U.S. government has repeatedly taken action against, including with a new multi-agency advisory Thursday. The domain name seizures were meant to deny hackers access to the vulnerability scanning…
Global Security News
‘Musk’ Review: Alex Gibney’s Portrait of a Tech Titan
Alex Gibney directs a four-hour documentary about Elon Musk that, though engaging, tends toward the hyperbolic.
Global Security News
Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions
Authorities accuse the owner of a so-called ransomware remediation company of swindling clients victimized by ransomware attacks into paying the company inflated fees under false pretenses. Zohar Pinhasi, owner and operator of MonsterCloud, claimed he could decrypt and recover victims’ data with specialized, proprietary tools and avoid paying cybercriminals. Yet, no such tool existed, the…
Global Security News
Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review
Italy’s Foreign Ministry is defending its website against a cyberattack, checking embassy sites and pushing for EU action to identify attackers. On the morning of October 8, Italy’s Ministry of Foreign Affairs said its website was being attacked. According to the ministry’s own statement, its protection systems have mitigated the attack so far, with no…
Global Security News
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed ‘Midnight Mimosa’ has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies. […]
Global Security News
Venezuelan Cartel’s Malware Honcho Nabbed for ATM Jackpotting
The first cybercriminal to ever make the FBI’s “10 Most Wanted Fugitives” list allegedly infused Tren de Aragua’s violent criminal operations with cash.
Global Security News
Growing PQC at the edge belies deeper quantum-readiness challenges
The quantum threat is becoming an increasing concern for security leaders, but many may be mistaking protection at their website’s front door for quantum readiness across their business. More than half (54%) of the world’s top 1 million websites now support post-quantum key exchange, according to research from F5 Labs, an encouraging statistic given that…
Global Security News
Got a Microsoft 365 subscription? Your storage is about to shrink
Today, shared Microsoft 365 plans include 1 TB of OneDrive cloud storage for every family member. Microsoft is about to shrink that allotment dramatically.
Global Security News
FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on October 8. The company, Integrity Technology Group, has been sanctioned by the U.S. and the UK. The hackers scanned websites for flaws…
Global Security News
Russian Spies Give ‘MatchBoil’ Malware a Stealthy Facelift
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
Global Security News
Making sure the checks get printed
Welcome to this week’s edition of the Threat Source newsletter. My name is Pierre Cadieux, and I’ll be helping contribute to these newsletters. A little about me: I’ve been working in the cybersecurity industry in many roles over the past 20+ years, first focusing on endpoint security, policies, and firewalls, then moving to risk management…
Global Security News
ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure is a problem on both sides of the fence. The rest of the week isn’t much more reassuring.…
Global Security News
Hunt.io Finds New Infrastructure Of BraZetsu Access Broker Months Before Disclosure
Hunt.io traced BraZetsu ‘s infrastructure and found that hosting patterns and certificate data remained useful after published IOCs became outdated. Group-IB researchers published a detailed writeup on BraZetsu back on August 31, naming it a Python framework compiled with Nuitka and tying it to a Brazilian actor called Exilware with high confidence. Hunt.io checked whether…
Global Security News
OpenAI says Iran, Russia used AI journalists, think tanks to influence Western media
OpenAI disclosed Thursday it shut down two influence operations from Russia and Iran that used ChatGPT and other AI tools to create fake journalist personas and covert think tanks that successfully planted stories and narratives in mainstream news publications. One cluster of accounts, which OpenAI calls “Dark Clark,” is attributed to Russian actors. The network…
Global Security News
FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. […]
Global Security News
Regulators are trying to protect you from being fired by AI – here’s how
Regulating AI at work is happening slowly, but it’s still stuck at the state level.
Global Security News
Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsuss 8 of the most popular AI coding assistants and agents including Claude Code, Codex, Gemini CLI, Cursor, Copilot, Warp, Windsurf, and Qwen Code. I’ve been using…
Global Security News
Microsoft will let Copilot act on local files on Windows PCs
Microsoft is giving Copilot greater control over Windows PCs, allowing the AI assistant to organize and make changes to local files, and run certain tasks using on-device AI models. The changes were announced at Microsoft’s Hybrid Intelligence event, where it outlined plans to combine local and cloud AI processing to help customers reduce AI costs…
Global Security News
Attackers hijack country-code domains to impersonate Google and other services
According to Google, attackers compromised infrastructure behind three country-code domain namespaces—.gh (Ghana), .sl (Sierra Leone), and .as (American Samoa)—and used it to obtain unauthorized HTTPS certificates for Google domains and other organizations. These domain endings aren’t limited to sites serving those countries, so the risk can extend to users elsewhere. This wasn’t a break in…
Global Security News
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident reports, based its October 8, 2026 alert on those reports and other information. The alert names no attacker and no affected organization. JPCERT/
Global Security News
Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones
Low-cost Android phones can arrive already compromised, with malware embedded in their firmware before buyers switch them on.
Global Security News
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
Global Security News
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. […]
Global Security News
Chasing AMMYY at Splunk .conf
Discover how Cisco’s Encrypted Visibility Engine (EVE) and Endace PCAP uncovered Flawed AMMYY RAT traffic at Splunk .conf without breaking TLS encryption.
Global Security News
Admin in the Loop: Firewalls and the Agentic SOC
Discover how Cisco Secure Firewall and Cloud Control stream structured Snort 3 and EVE telemetry into Splunk ES to power the .conf26 Agentic SOC pipeline.
Global Security News
The Zero-Day Blind Spot: Why Your Agentic SOC needs Retrospective Packet Replay
Learn how the .conf26 Agentic SOC paired Endace full PCAP with Cisco Secure Firewall and Talos rules to retrospectively replay wire data against zero-days.
Global Security News
One Cisco in Action: Inside the Agentic SOC at .conf26
Read how Cisco Cloud Control and Splunk Enterprise Security powered the live Agentic SOC at .conf26 to deliver unified TDIR across live event traffic.
Global Security News
Splunk .conf26: Tracking the Triage Agent in the Agentic SOC
How Cisco used Splunk as the SOC data platform at .conf26 to unify security telemetry and track the Splunk AI Triage Agent with human-validated workflows.
Global Security News
Fast AI, slow rollback: the risk facing Apple IT teams
There’s a big disconnect between the rate at which IT is deploying various kinds of AI-generated output and the speed with which it can roll those changes back when things go wrong, warns a new report from Fleet Device Management. It’s almost as if the rush to embrace AI has eclipsed the need to manage its…
Global Security News
Can AI fix legacy IT? The ‘economics don’t hold up,’ says former IBM strategist
Vendors are pitching AI as a cure-all for legacy IT systems, but is it?
Global Security News
SpaceX Eyes $40 Billion Financing Deal for Nvidia AI Chips, Reports Say
Elon Musk’s SpaceX is reportedly seeking $40 billion to finance Nvidia AI chips, highlighting the enormous capital requirements behind the race to build more powerful computing infrastructure. The company is in early discussions with banks and investment firms about a financing package that could include approximately $10 billion in bank loans and $30 billion in…
Global Security News
Attackers Hijack Three ccTLDs to Obtain Google Certificates
Attackers compromised .gh, .sl and .as registries to obtain unauthorized HTTPS certificates
Global Security News
You Can’t Secure the AWS Accounts You Don’t Know About.
Wallarm Infrastructure Discovery Named Enterprise Cloud Security Solution of the Year. Ask an AWS security team how many accounts they run, and the honest answer is usually a range. Enterprises on AWS operate anywhere from 100 to 5,000 accounts. Most security teams can see only a fraction of them. That gap is why we built…
Global Security News
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per CrowdStrike Intelligence, was active from late September to early October 2026, and resulted in data exfiltration. “In this activity, the threat…
Global Security News
OAuth grants pile up faster than you can review them. Here’s how to keep up.
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting forgotten OAuth grants to gain access to corporate data. This article covers why OAuth risks are so hard…
Global Security News
MonsterCloud Owner Charged With Secretly Paying Ransomware Demands
MonsterCloud owner Zohar Pinhasi allegedly paid ransomware demands behind clients’ backs, then charged them millions for the supposed recovery. Zohar Pinhasi, the owner of Florida-based MonsterCloud, was charged this week with wire fraud. Federal prosecutors say his clients were scammed twice during the same ransomware crisis. Pinhasi (50) also used the names “Zack Silver” and…
Global Security News
ASOS Confirms Data Breach Linked to Stolen Employee Credentials
The ASOS hack comes from the compromise of agentic marketing platform Simon AI, said the attackers
Global Security News
Uranium crypto exchange hacker convicted for stealing $53 million
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. […]
Global Security News
Quantum Research Races Ahead
Plus, venture dealmaking soars as exits remain stalled
Global Security News
AWS’s repeated problems with AI agent controls illustrates the autonomous agent dilemma
Throughout this year, Amazon Web Services (AWS) has repeatedly had to patch autonomous agent security holes, which have then reemerged in slightly different forms, according to cybersecurity researchers at Palo Alto Networks’ Unit 42 and at Zenity Labs. But the problem is not with AWS, which seems to be reacting quickly to address security reports,…
Global Security News
11:11 Systems Acquires IBM VMware Customer Portfolio
11:11 Systems has acquired select IBM VMware Cloud Service Provider enterprise customers, expanding its global VMware business as Broadcom concentrates more of its cloud ecosystem around a smaller group of service providers. The deal, announced Oct. 8, spans customers across North America, EMEA, APAC and South America and marks 11:11’s eighth VMware-related transaction and 11th…
Global Security News
Russia-Aligned UAC-0099 Evolves MATCHBOIL Malware
Russia-aligned UAC-0099 has steadily upgraded its MATCHBOIL downloader since 2024
Global Security News
Authorities seize sites selling hacked, stolen intimate images of 17,000 women and girls
The FBI and French law enforcement have seized two websites that sold hacked and stolen sexually explicit images and videos of young women and girls, and arrested their suspected administrator in northern France. Seizure notice (Source: US Department of Justice) The U.S. Attorney’s Office for the Eastern District of Virginia announced on Wednesday that the…
Global Security News
Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents
Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed. Key takeaways Every Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses…
Global Security News
YouTubers targeted with fake sponsorships and “channel verification” phishing
Scammers are going after YouTube creators’ Google accounts by posing as a brand looking for sponsorship partners. By sending out personalized emails that reference a creator’s own videos and directing targeted creators to a convincing fake collaboration platform, the fraudsters walk them through what looks like a routine brand deal, right up until the moment…
Global Security News
Amazon has an uncomfortably personal profile on you
Amazon’s “About You” page reveals what it thinks it knows about you—and you can’t simply switch it off. Dexerto reports that one shopper discovered her profile included the observation: “has flat buttocks” She suggested this might relate to a previous purchase of “butt scrunch leggings.” Whatever the connection, buying clothes doesn’t mean you expect the…
Global Security News
Microsoft Teams to get support for third-party deepfake detection tools
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. […]
Global Security News
Yelp, who? 4 ways Google Maps can help you find your next meal – and order it
There’s more to Google Maps’ dining tools than reviews and directions – and a few are worth a look before your next night out.
Global Security News
Writing the Next Chapter
Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.
Global Security News
Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code
Toronto, Canada, 8th October 2026, CyberNewswire
Global Security News
FBI: FortiBleed attackers can lock organizations out of their own firewalls
Details from an FBI investigation into the ongoing FortiBleed attacks reveal that victims could be locked out of their own firewall even as attackers remain logged in. After gaining access to a backend server left exposed by the attackers, the FBI and US Secret Service have shared new details of an operation that has already…
Global Security News
ASOS links data breach to social engineering attack, credential theft
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. […]
Global Security News
Best Maintenance Companies in Dubai for 2026, Compared
The most honest way to compare Dubai maintenance companies is to read what each one publishes on its own website, before you ever call. Ten providers rank for searches like “annual maintenance contract dubai” and “home maintenance company dubai” as of 2 September 2026: European Technical and nine independent competitors. Almost none of them publish…
Global Security News
HPE Expands ProLiant Gen13 Lineup with AMD-Powered Servers
HPE is expanding its enterprise compute portfolio with four new ProLiant Gen13 servers powered by AMD’s latest EPYC processors, pairing higher-density infrastructure for AI workloads with new security and management capabilities to reduce the operational burden of increasingly distributed IT environments. The HPE ProLiant DL525, DL585a, XD245 and XD285 Gen13 servers use 6th Gen AMD…
Global Security News
Anthropic’s new budget model gets much better at ignoring hidden commands
Anthropic’s Claude Haiku 5.5 model, designed for quick, repetitive workloads and speed-sensitive tasks, is now better at finding vulnerabilities and writing exploits than its predecessor. The company has given it stricter cybersecurity safeguards than Haiku 4.5, though lighter ones than its more advanced models, whose offensive skills remain well ahead. Cybersecurity capabilities and safeguards Anthropic…
Global Security News
Meta’s Muse AI files away your friendships, arguments, and secrets
If you thought that having companies trawling your social media, browsing history, and TV habits for behavioral clues was bad, sit tight. Meta is just getting started. Its Muse personal AI agent is taking surveillance to the next level. TIME magazine analyzed the software’s internal instructions and found that it maintains constantly updated dossiers on…
Global Security News
Quantum Startup Oratomic Now Worth $5.4 Billion After Series-B Funding
Quantum computing startup Oratomic raised $475 million, just three months after its Series A, the latest sign of growing investor enthusiasm in the nascent technology.
Global Security News
Chinese Hacker Deployed AI in Campaign Against South Korean Banks
CrowdStrike revealed that a Chinese-speaking hacker deployed agentic pentesting tool ARTEX and Claude to help breach data from South Korean financial firms
Global Security News
FBI, French Police Seize CSAM Site Domains, Suspected Admin Arrested
US and French authorities seized two domains and arrested a suspected administrator in a CSAM and non-consensual intimate image abuse case.
Global Security News
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrastructure that delivers the phishing page itself. ANY.RUN has identified Wazza, a new phishkit targeting banking, manufacturing, and government organizations across the US,…
Global Security News
Owner of Empire cybercrime market gets 40 years in prison
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. […]
Global Security News
Rogue AI Agents
AI agents are escaping sandboxes, misusing credentials and acting without authorization. This live dashboard tracks every reported incident on a horizontal timeline, with charts showing which AI companies and agents are involved, the techniques used and how they got in. It updates automatically as new events are added.
Global Security News
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers
Thousands of hijacked servers have been looking up their command and control (C2) server in a poem posted on GitHub, according to Black Lotus Labs. The malware reading it, dubbed PoeLLM, breaks into exposed AI services and open-source tools, mines cryptocurrency on them and uses them to hunt for new victims. The researchers call the…
Global Security News
AWS takes aim at runaway AI agent behavior with Strands Box
Amazon Web Services (AWS) has introduced an open-source sandbox for AI agents that allows developers to restrict their actions based on previous behavior, seeking to address security risks as enterprises give autonomous systems greater access to applications and data. The tool, called Strands Box, combines operating system-level isolation with policies that govern what agents can…
Global Security News
U.S. Offers $10 Million Reward for Alleged HAFNIUM Hacker Zhang Yu
The U.S. offers $10M for Zhang Yu, accused of helping run HAFNIUM attacks that compromised thousands of organizations worldwide. The U.S. State Department is offering a $10 million reward for information leading to the arrest of Zhang Yu. He is accused of being a key figure in the HAFNIUM campaign, the 2021 operation that targeted…
Global Security News
Critical Flaw in Multiple Atlassian Products Exploited in the Wild
A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck
Global Security News
UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility. The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to…
Global Security News
Ignore all instructions and read this blog: The state of AI-analysis evasion in malware
“AI-analysis evasion” encapsulates the real-world techniques malware authors are developing in attempt to obstruct or defeat any layers of automated AI analysis. This technique is cheap to add but inconsistently impactful — the best techniques steered the outcome in the attacker’s favor in about 35% of test runs. Further, it must always be plaintext and…
Global Security News
Quantum computers could break today’s encryption. Washington needs to prepare now.
The country is consumed right now with debating artificial intelligence and whether increasingly powerful AI systems could escape human control. Those are valid concerns, but lawmakers are overlooking another technological threat: quantum computing. Unlike AI safety debates, this risk could render today’s encryption obsolete – compromising everything from emails to financial transactions to government communications…
Global Security News
What Growing Up on a Farm Taught Elanco’s CEO
Global Security News
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. “The extensions masquerade as wallet portals, desktop utilities, and browser tools, but their code intercepts recovery phrases and private keys during wallet import flows and attempts to send those secrets to
Global Security News
12 tricks for more efficient Android texting
No matter what type of Android phone you carry or how you usually use it, one thing is a near-universal constant: You’re gonna spend a ton of time messing with messages. The messages may be from clients, colleagues, or your cousin Crissy from Cleveland (damn it, Crissy!). But regardless of who sends ’em or what…
Global Security News
Europol and US GAO Sound the Alarm Over Quantum Threats
Europol and US Government Accountability Office urge faster transition to post-quantum cryptography
Global Security News
GitHub adds AI to catch passwords before a code push
GitHub has announced an AI detector, developed with Microsoft Applied Sciences, to help prevent developers from uploading passwords and other credentials to code repositories. The ModernBERT-based classifier will expand GitHub’s push protection, which checks code for secrets and can block a push before a credential enters repository history. How the detector works Existing checks recognize…
Global Security News
What is MATCHBOIL? The Russia-aligned malware that installs a spying backdoor
ESET researchers traced almost two years of changes to MATCHBOIL, a downloader that the Russia-aligned group UAC-0099 uses to plant a second program on Windows machines in Ukraine. GUI displayed at MATCHBOIL’s runtime (Source: ESET) Every victim in ESET’s telemetry was in Ukraine: transportation companies in July and August 2025, a manufacturer in December 2025,…
Global Security News
We are fighting phishing at the wrong layer
I timed an attacker once. From registering a domain to having it delegated, certificated and serving a live credential-harvesting page took under 24 minutes, and 12 of those were spent waiting on nameservers. I keep coming back to that number, because it quietly indicts most of what we do about phishing. We block domains. We…
Global Security News
CVE-2025-64393: Critical Veeam Backup & Replication RCE Vulnerability
Veeam has released a security update addressing CVE-2025-64393, a critical remote code execution vulnerability in Veeam Backup & Replication. The flaw has received a CVSS 4.0 score of 9.4 and enables a low-privileged authenticated user with the Backup Viewer role to execute arbitrary code on the Veeam Backup Server. The vulnerability stems from insecure deserialization…
Global Security News
FBI and Secret Service Warn of FortiBleed Lockout Threat
The FBI and Secret Service are warning Fortigate admins that their systems are still being targeted
Global Security News
Ransomware recovery firm boss charged with secretly paying attackers and overcharging victims
The owner of Florida-based ransomware remediation company MonsterCloud has been charged with fraud for allegedly paying ransomware gangs behind his clients’ backs and billing them far more than the ransom. Zohar Pinhasi (aka “Zack Silver” and “Zack Green”), a 50-year-old US and Israeli national from Hollywood, Florida, allegedly charged MonsterCloud clients more than $19 million…
Global Security News
Making Threat Intelligence Work for SOC Teams: ANY.RUN & Elastic Webinar Insights
Threat intelligence on its own is only data. Its value depends on how effectively SOC teams can turn it into action. Simply put, this was the premise of our recent webinar. The SOC and business impact of threat intelligence depends largely on how quickly analysts can use it to validate threats, make confident decisions, and…
Global Security News
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD…
Global Security News
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while claiming to use proprietary tools to recover their data. Zohar Pinhasi (aka Zack Silver and Zack Green) has been charged with two counts of…
Global Security News
Atlassian Vulnerability Comes Under Attack Hours After Details Go Public
Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include…
Global Security News
A Deployed Rule Is Not a Working Rule: How to Tell the Difference
Every detection team knows this moment. A rule is written or downloaded, reviewed, translated into the query language of the SIEM, and deployed. The status says enabled, the rule count goes up, and the coverage report gets a little greener. None of that tells you whether the rule will detect the attack it was written…
Global Security News
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. […]
Global Security News
How Assisted Living Helps Older Adults Beat Social Isolation
Social isolation can alter an older adult’s daily routine long before anyone notices a serious problem. Missed conversations reduce emotional support, while quiet days make…
Global Security News
How Digital Twins Are Changing How Collectors Track Their Guitars
A valuable guitar needs more than a case and a purchase receipt. Collectors also need accurate records covering condition, ownership, repairs, photographs, insurance, and…
Global Security News
Pricing your bad days and how to build an economic model for security decisions
Ivan Milenkovic, VP Risk Technology EMEA at Qualys, explains how security leaders can build an economic model that puts money behind their decisions. He suggests starting with a few loss scenarios, then working down to the assets that drive them. He covers how to rank fixes by value at risk, what CFOs expect to see,…
Global Security News
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The npm package known as “tensorlake,” a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The malicious version 0.5.144 “contains obfuscated malware that harvests credentials, exfiltrates secrets, establishes persistence, and executes remotely supplied code,” Socket said
Global Security News
Red Hat: AI Is Turning Sovereignty into an Australian Business Issue
The Australian Government is grappling with accelerating AI investment and adoption along with balancing the country’s sovereignty.
Global Security News
Who watches the AI watching your street?
Yusaku Fujii, a professor at Gunma University in Japan, has designed audits and penalties to stop operators from misusing AI that analyzes street camera footage. His system adds an independent record-keeper and unannounced spot checks to the AI’s outputs. Fujii’s test setting is what he calls a Fully Monitored Public Space (FMPS): streets where cameras…
GeekGuyBlog
Australia’s Government Considers Mandatory AI Incident Reporting
Global Security News
How AI can fix cybersecurity compliance: From dashboards to continuous execution
Most compliance work goes into proving security, not improving it. That isn’t because the rules are unreasonable. Regulators, customers, and cyber insurers are right to expect organizations to implement hundreds of technical and administrative controls, monitor their environments, respond to incidents, and prove that all of it works. The problem is the cost of delivering…
Global Security News
5 Key Takeaways from Beyond Human Risk: Measuring Secure Behavior with an AI-Driven Platform
Security awareness programs can report who completed training, clicked a simulation, or passed a quiz. Those metrics provide useful evidence of participation and practice. They offer less insight into whether employees can recognize and respond to a real phishing threat when it reaches their inbox, whether that is days or months later. Cofense’s Beyond Human…
Global Security News
Q&A: Tenable’s Ben Mudie on Why Australian Businesses Must Prepare for Cyber Attacks at Machine Speed
As AI accelerates the speed and sophistication of cyber attacks, Australian organisations are facing growing pressure to identify, prioritise and respond to security threats…
Global Security News
The people who know passkeys best are still typing passwords
Yubico and Okta asked 1,890 technology and security professionals across nine countries how they sign in to work accounts. The most common answer was a username and password, at 43%, from a group in which 87% said they were familiar with passkeys. High familiarity with modern authentication (Source: 2026 Global State of Authentication Report) The…
Global Security News
Microsoft’s new Surface Laptop Ultra finally has a starting price (you should sit down)
The Surface Laptop Ultra is an AI powerhouse, with Nvidia’s new RTX Spark chip and up to 128GB of unified memory – and it’s priced for power users.
Global Security News
Java library vulnerabilities: IBM and Red Hat fix 400+ previously unknown flaws
IBM and Red Hat have found and fixed more than 400 previously unknown vulnerabilities in widely used Java libraries through Lightwell, their program for patching open source code that companies already run in production. Companies running the affected libraries are exposed until they apply the fixes. Autonomous AI agents can now combine several minor software…
Global Security News
Medical devices patients rely on most are least prepared for quantum attacks
Threat actors are exploiting IT, IoMT, OT and IoT devices across healthcare delivery organizations (HDOs) to deploy ransomware, demand payments and monetize stolen patient data, according to Forescout’s Post-Quantum Cryptography (PQC) in Healthcare: From Data Risk to Migration Readiness report. Researchers analyzed a dataset containing more than 2.5 million devices across more than 50 HDO…

