
Finding Sensitive Data Is Not the Same as Reducing Risk

New spyware attacks are aimed at journalists, activists, politicians, diplomats, and others. Here’s how Apple is notifying them and what they should do – after turning on Lockdown Mode.
The Dell XPS 13 flaunts build quality rarely seen at this price point, but not without trade-offs.
Rolling out to ChatGPT’s Mac app, Computer History creates a timeline from your activities across the apps and websites you use on your Mac. Is that a privacy risk?

Comprehensive Analysis of Trends, Market Changes, Technology Shifts & Statistics EXECUTIVE SUMMARY The global data security market is experiencing unprecedented growth driven by escalating cyber threats, digital transformation, and stringent regulatory requirements. The market has reached $17.21 billion in 2026 and is projected to grow at a CAGR of 17.12% through 2031, reaching $37.93 billion.…
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. […]

Executive Summary Based on aggregated reviews from major tech publications (CNET, PCMag, Tom’s Guide, BroadMag, SmartHomeReview, RTINGS), this report ranks the top 10 WiFi mesh systems and routers available on Amazon. The rankings combine user satisfaction scores, expert test results, reliability metrics, and value propositions. Top 10 Rankings Rank Product Price Range Best For Overall…

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June, and there are fears that they…

OpenAI has lost its AI ethics lead Chloé Bakalar just a year after she joined the company, the Financial Times reported. Bakalar has maintained a silence and has yet to update her LinkedIn profile, but if her departure is confirmed then it will add to the list of OpenAI executives who have quit in recent…

Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. Oracle Database Security Central will be available free of charge until the end of February 2027. It arrives at a critical time for Oracle customers, with attackers targeting security flaws to exploit the company’s…

Chinese AI company Manus has laid out its plans to operate as an independent company following the reversal of its acquisition by Meta. The US social media company agreed to buy Manus last year but Chinese regulators quickly opened an investigation into the deal, as they were concerned that it violated Chinese export controls. In…

Apple has expanded its threat-notification system for targets of mercenary spyware. Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by…

Kiteworks has launched a new security capability designed to prevent employees from accidentally sending sensitive information to the wrong recipients, extending the company’s data governance platform further into outbound email. Agent and Human Error Prevention (AHEP), now generally available, analyzes email activity as users compose messages and warns them when multiple signals indicate a potentially…

Microsoft will bring its two Copilot apps into a unified interface for consumer and work users, part of a wider drive to create a Copilot “super app” that consolidates various features. Until now, Microsoft has offered two Copilot apps across web, desktop and mobile platforms: a simplified, consumer-focused Copilot app, and Microsoft 365 Copilot, which…

Cloudwick has appointed AWS veteran John Newson as Vice President, Alliances and Channels, EMEA. Newson will be tasked with leading Cloudwick’s regional partner strategy from the company’s London office, working alongside Harshdeep Singh, GM, EMEA at Cloudwick, and the UK team. Newson joins Cloudwick after a decade at AWS UK Public Sector The new channel…

Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an on-device machine-learning model to flag likely scam messages from people who are not in a user’s contacts. The Scam Alert feature arrives as scammers increasingly use WhatsApp for impersonation,…
The Health Insurance Portability and Accountability Act (HIPAA) establishes federal standards for protecting the privacy and security of individuals’ health information. Its Privacy, Security, and Breach Notification Rules govern how protected health information (PHI) is used, disclosed, and safeguarded by covered entities and their business associates. For MSPs, the most important HIPAA development in 2026…
Need a custom Linux distribution, but don’t have time to learn how to build one? OpenFactory can help you.

Fusion Connect has launched an AI-powered Contact Center as a Service (CCaaS) platform with flat-fee pricing, replacing complex token-based consumption calculations with more predictable costs for customers and channel partners. Fusion Connect replaces consumption-based AI pricing This new structure is designed to eliminate unpredictable costs in enterprise AI adoption. Fusion Connect is offering predictable monthly…
It can be daunting to determine who’s responsible for showing ads on the websites we visit, or who’s harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms.…

Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a victim’s device. Attack chain overview (Source: Group-IB) How the scam unfolds…

Apple recently posted and removed details explaining how Mac users in China could set up their computers to work with Alibaba’s Qwen AI. Now, Reuters has confirmed long-held speculation that Apple has revisited its Google Gemini AI playbook and built its own proprietary AI model for China with support from Alibaba. Apple worked with a Chinese…

Microsoft has been struggling to get people to use its Edge browser for years. Even though the company made Edge the default browser in Windows 10, users left in droves, most of them flocking to Google Chrome — and with good reason. The original version of Edge was underpowered, had difficult-to-use features, and offered very…

OpenAI’s GPT-5.6 Sol on Ultrafast mode is available in limited preview to a select group of customers, launching first through the OpenAI API. The company says the service runs up to 14 times faster than Standard processing and generates up to 750 output tokens per second. Ultrafast is powered by Cerebras as part of the…

As AI data centers face mounting criticism over their water use, Google has pledged to replenish more freshwater than its offices and data centers consume by 2030, positioning water stewardship as a key part of its AI infrastructure strategy. The announcement comes as governments and local communities increasingly scrutinize the environmental impact of AI infrastructure,…

Hackers used coordinated artificial intelligence agents in cyberattacks targeting Taiwanese government networks, according to Taiwan officials and cybersecurity researchers. Taiwan’s Ministry of Digital Affairs said it detected an unusual wave of cyberattacks targeting government agencies last July, with investigators finding evidence that the operation combined traditional hacking techniques with artificial intelligence agents. According to the…

San Francisco-based startup, CodeRabbit, said Wednesday it raised $143 million in a Series C funding round, giving the company a $1.5 billion valuation as demand grows for tools that review and monitor software written by artificial intelligence. The round was co-led by Atomico and Smash Capital, with participation from new investors including BMW i Ventures,…

Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntress, the technique successfully took both its agent and Microsoft Defender’s real-time protection offline. This, the researchers said, gave the attacker a window to…

Cybersecurity teams should be responsible for risk oversight, rather than for executing every corrective action. Assigning security teams the tasks of finding, prioritizing, assigning, implementing, tracking and validating every remediation does not foster accountability. Instead, it results in an organizational repository for unresolved issues. A more effective model distinguishes roles clearly: security functions as the…

AmnesiaStealer targets macOS users through fake GitHub pages, stealing passwords, cookies and data while giving attackers live control of the browser. Jamf Threat Labs researchers disclosed AmnesiaStealer, a new multi-stage Rust-based macOS infostealer that spread through a counterfeit GitHub download page using the ClickFix technique. The lure looks convincing: correct GitHub dark theme, Octocat logo,…
Rokid’s AI Glasses puts real-time translation, AI, navigation, notifications and a teleprompter in your line of sight. It’s a futuristic product with a Tuesday-morning job to do.

AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets standards that browsers and certificate authorities follow for publicly trusted certificates. From March 15, 2028, public certificate authorities will no longer…

For years, cybersecurity leaders have worked to convince organizations that security deserves a seat at the executive table. Today, that conversation is changing. The challenge is no longer proving that cybersecurity matters; it is demonstrating how security leaders can help organizations innovate, modernize, and grow with confidence. As organizations accelerate digital transformation, CSOs have an…

7.3 million Chess.com profiles leaked online: the data is genuine, but evidence points to large-scale scraping, not a server breach. Free is a strange price for stolen data, and that’s exactly what makes this listing worth a second look. A 15.5 GB file containing over 7.3 million chess.com user records showed up on two data-leak…

Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent call center (Source: Cyberpolice Ukraine) The call centers were linked to schemes involving callers impersonating bank employees, fraudulent investment services,…

Trump authorizes vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks. President Trump signed a national security memorandum on August 13 establishing a formal program that allows vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight. The program, managed by the…

Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. Preparing the operating model for AI agents About half of surveyed leaders say they understand how…

Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies. More than two-thirds of midmarket organizations use multiple cloud providers, each with its own…

A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the technical detail alone. Seventeen draft standards, now open for comment, supply that detail.…
Airtasker has launched on ChatGPT, making it the first local services marketplace to enable bookings to be completed end-to-end within one conversation on an AI platform.
Here’s a look at the most interesting products from the past week, featuring releases from A10 Networks, ScienceLogic, Searchlight Cyber, and SelectHub. ScienceLogic delivers secure AI deployment and smarter IT operations with Skylar AI 2.5 ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while…

AI’s potential as a security tool and the danger of autonomous AI agents as a new attack surface were key themes of the presentations and product announcements at Black Hat and DEFCON in Las Vegas last week. Here are some key takeaways from this year’s hacker summer camp that CISOs should review while developing cybersecurity…

One of AI vendor DeepSeek’s biggest selling points has been its ultra-low price point, but that party’s about to end. The Chinese model provider is raising API pricing for its V4 model family by notable margins, in some cases by more than 1,100%. The increases may not be that dramatic for all, though; the company…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
The Data Security Maturity Model (DSMM) provides a structured framework for organizations to assess and improve their data security posture across five distinct maturity levels. This comprehensive guide explains each level, provides actionable implementation strategies, and offers insights into moving from ad-hoc, reactive security measures to AI-driven, predictive security operations.
Pixel 11 Pro Fold is here, and it’s our most sophisticated foldable yet. With a fresh and durable design, stunning and helpful new camera visor with HiLight, and unique…
Designed for Gemini Intelligence and Google Health, your watch provides the help you need right when you need it. Stay on top of your day with proactive assistance, and…
Google’s 11th generation of Pixel phones bring refined hardware that’s built to last, upgraded cameras, and more proactive Gemini support — powered by the new Google Tensor G6…
With Google set to retire Assistant, and Gemini not exactly the replacement many of us want, Dicio is a solid option. There’s one catch.

A newly-signed presidential memorandum enlisting private sector companies in federal law enforcement hacking operations against criminal organizations could present a number of legal, practical and moral pitfalls, cyber experts told CyberScoop a day after the order was released. While some have celebrated the memo as an overdue maneuver to more aggressively combat cybercriminals, others view…

A tech worker who hatched an elaborate insider attack in late 2023 and attempted to extort Brightly Software for about $2.5 million was sentenced to two years in prison, the Justice Department said Thursday. Cameron Nicholas Curry, also known as “Loot,” committed a series of crimes while working as a data analyst contractor for the…
Today, we’re announcing that AWS Certificate Manager (ACM) will discontinue support for email-validated public certificates by September 30, 2027. If you use email validation for your ACM public certificates, you need to migrate to DNS validation before that date. This change aligns with the Certification Authority/Browser (CA/B) Forum’s industry-wide deprecation of email-based domain validation and…
This preview release of ChatGPT Desktop for Linux supports Ubuntu, Debian, and Fedora is here.

Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data. The software is widely used by organizations in many industries, including the government, defense, science, education, engineering and technology sectors, and has been targeted by hackers in…

Proofpoint researchers found that cybercriminals are developing and selling tools designed to hide malicious instructions inside emails, documents, calendar invites, and webpages that AI systems routinely process. This could allow attackers to manipulate AI agents without direct user interaction. “These advertisements and discussions reveal novel techniques organizations are likely to observe in upcoming months, such…

Washington is preparing to give vetted US cybersecurity firms a role in offensive operations against foreign cybercriminal groups. President Donald Trump signed a National Security Presidential Memorandum on Wednesday directing the federal government to establish a program under which vetted U.S. firms could conduct cyber surveillance and “cyber effects” operations against foreign cyber-enabled transnational criminal…

xAI is stepping up its challenge to OpenAI and Anthropic in the AI agent market. Its latest release gives the company another contender for developer and enterprise workloads. Elon Musk’s AI firm introduced Grok 4.6 as its newest frontier model, designed for longer-running agent work. Developers and service providers can now evaluate it for customer…

Welcome to this week’s edition of the Threat Source newsletter. “Experiment is the mother of knowledge.” ― Madeleine L’Engle, A Wrinkle in Time “Don’t slide down the rabbit hole. The way down is a breeze, but climbing back’s a battle.” ― Kate Morton, The Clockmaker’s Daughter Hacker Summer Camp has come and gone, which means…