An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of TanStack’s…
Global Security News
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below – CVE-2025-39682 (CVSS score: 9.8) – An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
Global Security News
TD SYNNEX, Google Expand European Channel Partnership
TD SYNNEX and Google are expanding their partnership across Europe, with Google Pixel at the center of a broader push to help channel partners build and grow B2B practices around Google’s portfolio. The expanded collaboration combines Google’s hardware, services, and solutions with TD SYNNEX’s pan-European distribution footprint and local market expertise. Partners will gain broader…
Global Security News
Druva Adds Ransomware Detection to Cut False Positives
Druva is expanding its cyber recovery portfolio with new ransomware detection and identity resilience capabilities designed to help security teams validate attacks faster, reduce false positives, and identify clean recovery points before restoring data. The company’s new Ransomware Detection capability analyzes backup snapshots for high-risk ransomware behavior and then applies additional forensic validation to determine…
Global Security News
OpenAI Investors Discuss New Round at $1.2 Trillion Valuation
OpenAI may be headed toward another massive private-market valuation well before its eventual IPO. Investors have approached OpenAI about a possible new round that could value the company at about $1.2 trillion, but formal fundraising has not begun. That distinction matters. OpenAI has not announced a new raise, but investor interest alone suggests the market…
Global Security News
Microsoft’s Frontier Playbook Pushes Process Redesign Over More AI Licenses
Microsoft spent years putting AI tools in employees’ hands. Its latest lesson is that access alone does not transform how a company works. The company released its 44-page “Becoming a Frontier Firm: Our Frontier Playbook” on Thursday, drawing on more than 100 internal projects across its 220,000-plus workforce. Microsoft says organizations get more value from…
Global Security News
What GTIA’s ASCII Group Acquisition Means for Partners
The Global Technology Industry Association (GTIA) has acquired The ASCII Group, expanding its member community while increasing investment in the programs, resources, and experiences that support IT service providers (ITSPs). The acquisition brings together GTIA’s leadership in research, education, cybersecurity, and industry strategy with The ASCII Group’s business tools and peer-driven community model. “We’ve been…
Global Security News
UltraViolet Cyber Launches Equinox for Detection Gaps
UltraViolet Cyber has launched Equinox, an AI-assisted detection engineering platform designed to identify gaps across customers’ existing security tools and expand mapped threat coverage without adding unnecessary alert volume. Equinox maps customer-specific detection gaps In its official announcement, UltraViolet Cyber highlighted how security teams may have thousands of detections available across their security information and…
Global Security News
StorMagic, Mako Networks Link Edge HCI and SD-WAN
StorMagic and Mako Networks are integrating edge hyperconverged infrastructure with secure SD-WAN in a new partnership aimed at businesses operating across large numbers of distributed locations. The agreement combines StorMagic SvHCI, which provides edge compute, storage, and virtualization, with Mako Networks’ secure SD-WAN and cloud-managed networking platform. The companies say the integration is designed to…
Global Security News
Gemini Hacked Three Companies in First Known Breakout by Google’s AI
The episode resembled similar hacks by other AI models, but Google said it did not consider it an instance of model misalignment.
Global Security News
Huawei’s Atlas 960 SuperPoD Takes Aim at Nvidia’s AI Lead
Huawei is not trying to catch Nvidia one chip at a time. Its latest strategy is to connect thousands of processors into increasingly large systems and compete at the infrastructure level instead. The AI giant unveiled the Atlas 960E SuperPoD and accelerated the launch of its Ascend 960DT AI chip to the first quarter of…
Global Security News
Anthropic’s IPO Will Happen a Month Later Than Expected
Plus, Howard Buffett steps into his father’s shoes and Trump bans certain news media from the White House.
Global Security News
Level up: 4 forward-thinking solutions to upgrade your business
Every year, your company likely looks for ways to improve internal efficiency, strengthen its cybersecurity, and reduce its overheads. As a result, you might have invested a…
Global Security News
Brevo Supply-Chain Attack Infected Over 100,000 Websites
A Brevo supply-chain attack used compromised Cloudflare access to inject malware into websites, potentially affecting over 100,000 sites. Brevo, formerly known as Sendinblue, is a French cloud-based marketing and customer communication platform whose clients include eBay, Louis Vuitton and Michelin. The company was first compromised on September 10, when attackers exploited a vulnerability in its…
Global Security News
Anthropic Shifts Planned IPO to November
Investors had expected the Claude maker to debut in October. The AI industry has been grappling with calls to slow down its pace of development.
Global Security News
Arrow Electronics, Usercentrics Sign EMEA Distribution Deal
Arrow Electronics is expanding its privacy and consent management portfolio through a new distribution agreement with Usercentrics, bringing the company’s Cookiebot CMP to channel partners across eight European markets. The agreement covers Austria, France, Germany, Italy, Portugal, Spain, Switzerland, and the U.K., giving Arrow partners another platform to help customers manage consent requirements and navigate…
Global Security News
Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks
The new program expands Vectra AI’s partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.
Global Security News
Early Scattered Spider member pleads guilty to cybercrime spree
Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday. Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity…
Global Security News
CoreWeave Plans $3 Billion Debt Sale to Fund AI Infrastructure Expansion
CoreWeave’s AI expansion comes with a multibillion-dollar appetite. The company said Thursday it plans to sell $3 billion of convertible senior notes due in 2033 through a private offering. Initial buyers will have the option to buy up to an additional $500 million of notes. The potential $3.5 billion raise gives CoreWeave another source of…
Global Security News
Cisco Zero-Day Highlights API Endpoint Authentication Issues
The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
Global Security News
MFA Won’t Save You From OAuth Consent Abuse
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
Global Security News
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is…
Global Security News
Microsoft mops up after Patch Tuesday broke logins, audio, Excel
Microsoft fixed hundreds of security flaws in its September Patch Tuesday software updates — but it also introduced some annoying bugs. Now it has fixed some of them with a series of out-of-band updates. Excel 2016 users were among the victims, as Patch Tuesday update caused certain paste operations to fail. A hotfix in update…
Global Security News
Researchers use AI to find widespread software decoder flaw
Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet platforms, enterprise services, and web frameworks vulnerable to data theft and remote access. The vulnerability, nicknamed HEIF Heist, refers to the malware’s ability to trigger memory corruption errors in…
Global Security News
MDR vs MXDR vs Managed SOC: Key Differences
The main difference among MDR, MXDR, and a managed SOC lies in scope. MDR provides managed threat detection and response; MXDR correlates detection and response across multiple security domains; and a managed SOC can operate a broader set of security functions, including monitoring, tool administration, detection engineering, reporting, and compliance support. Choosing between them depends…
Global Security News
Gyazo Data Breach Exposes 23 Million User Records
A Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized access by exploiting a vulnerability in the service’s image upload server. “We have confirmed that approximately…
Global Security News
Napster CEO: AI is Creating a New Stack Problem for Partners
Microsoft partners have spent years building businesses around the cloud stack. Napster CEO John Acunto believes AI is forcing them to confront a new question: where do they fit as that stack is rebuilt around agents, proprietary data and new ways of interacting with customers? “I think partners are going to hopefully gravitate to us…
Global Security News
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain…
Global Security News
CISA is ending its monthly vulnerability bulletin
The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA). The agency will discontinue its weekly bulletin of known vulnerabilities from September 28. It said that it is taking this step because of the recently…
Global Security News
Disney Beefs Up Tech Ambitions With Newly Created CTO Role
Karandeep Anand, head of Character.AI, will report directly to Disney CEO Josh D’Amaro, who has made tech a focus.
Global Security News
Gyazo server flaw exploited to steal 23.6 million user records
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. […]
Global Security News
Bracing for El Niño Extreme
Plus, jet-powered drone warfare, credit cards for AI agents, and a GLP-1 drugmaker taps Claude to develop new medicines.
Global Security News
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday. The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview,…
Global Security News
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise…
Global Security News
New Android malware uses AI to steal bank logins and PINs
Researchers at Zimperium’s zLabs have analyzed an Android Trojan that uses an automated, multi-stage infection process. What’s new is that RatHat gives a live AI assistant the keys to the accessibility tree of the infected device and uses it to determine where to tap or scroll, rather than following a hardcoded script. The variable attack…
Global Security News
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed…
Global Security News
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. […]
Global Security News
GhostCode attackers abuse device codes to take over Microsoft 365 accounts
Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026. The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism…
Global Security News
GhostCode attackers abuse device codes to take over Microsoft 365 accounts
Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026. The kit abuses Microsoft’s OAuth 2.0 device authorization grant flow, a legitimate mechanism…
Global Security News
Businesses finally seeing AI ROI, but 62% can’t handle the storage demands
A Seagate study finds that 99% of IT leaders expect AI to drive increased data storage needs, but only 38% are prepared to meet them, revealing a significant readiness gap.
Global Security News
Prime Detect ROI: Validated Savings from Detection at the Pipeline Layer
The trade-off nobody wants to make Anyone who has worked on SOC and SIEM projects long enough has watched the same decision play out in budget meetings again and again. Security teams are pushed into a choice that has nothing to do with security engineering and everything to do with invoices. Option one: drop log…
Global Security News
Fake calendar invites can infect your system, and they’re surging – how to protect yourself
These invites sneak past your security software to embed themselves in your calendar. But you can thwart them before they do any damage.
Global Security News
Did an AI really try to break free from human control?
Amid discussions about slowing down AI development, the Telegraph ran the headline: “OpenAI sounds alarm after bot tries to break free from human control.” That headline is slightly misleading, in my opinion. The Telegraph headline overstates what happened, although the underlying behavior is still genuinely concerning. The article reports that OpenAI has disclosed rare but…
Global Security News
Zero-Days, AI Agents, and Massive Data Leaks Define the Week
This week’s cybersecurity landscape combined actively exploited vulnerabilities, AI-assisted attacks, exposed credentials, trusted-channel phishing, and breaches affecting millions of people. Defenders face an increasingly compressed response window as automation accelerates exploitation and compromised infrastructure gives attackers new ways to evade user suspicion. Major Threats & Vulnerabilities Actively Exploited Zero-Days and Critical Flaws WooCommerce plugin exploitation:…
Global Security News
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. […]
Global Security News
Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company’s security requirements. […]
Global Security News
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks
Global Security News
AI Job Fears Grow, Tech Leaders Say Reskilling Can’t Wait
Plus, researchers use Anthropic’s Claude to hack OpenAI
Global Security News
Webinar: Which Google Workspace security controls actually matter?
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. […]
Global Security News
ETFs Are Getting Wackier. Investors Must Stay Sane.
Funds that track election results and hockey stats are in the works, but you don’t have to chase them.
Global Security News
AI Infrastructure Gaps Open New Opportunities for Partners
As enterprises push artificial intelligence projects beyond pilots and into production, infrastructure limitations are becoming harder to ignore—and creating a new opening for channel partners. Dennis Frank, Vice President, EMEA Strategic Partners & Alliances at Hitachi Vantara, spoke with Channel Insider about why storage, data pipelines, and governance are emerging as critical AI bottlenecks, how…
Global Security News
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a…
Global Security News
Who Is Howie Buffett, Berkshire Hathaway’s New Chairman?
Warren Buffett’s son doesn’t have the standard resume of a massive conglomerate’s chairman.
Global Security News
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. […]
Global Security News
CISA Warns Attackers Are Exploiting Acronis Backup Flaw on Linux Servers
An Acronis Backup vulnerability has moved from a patching concern to an active security threat. CISA added CVE-2026-87886 to its Known Exploited Vulnerabilities catalog on Sept. 16 after the flaw was confirmed under active exploitation. Acronis said it observed limited, targeted attacks involving its Backup plugin for cPanel & WHM. The high-severity flaw can allow…
Global Security News
Warren Buffett Steps Down as Berkshire Hathaway Chairman
The 96-year-old, whose son Howard succeeds him as chairman, will remain on the board.
Global Security News
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references…
Global Security News
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude…
Global Security News
Why AI companies are really pumping the brakes on their models
There we were, listening to AI leaders doing their usual spiel: AI is great! AI will cure cancer! AI impact will be “unprecedented, perhaps 10x of the Industrial Revolution at 10x the speed”! AI will find a final answer to “Why do socks disappear in washing machines?” (Well, maybe not the last one. Some things…
Global Security News
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and
Global Security News
Warren Buffett Steps Down as Berkshire Hathaway Chairman
Warren Buffett is stepping down as chairman of Berkshire Hathaway, the $1 trillion conglomerate that he led for more than six decades.
Global Security News
Bots with good manners are better at fooling people on social media
Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting. Overall, people caught just 40% of…
Global Security News
MY TAKE: AI agents show uncanny initiative nobody designed — and carry no values at all
Give a person a goal, and they bring a lifetime of restraint to the job. Don’t lie. Don’t steal. Stop when something looks wrong. Give an AI agent a goal, and it finds a shortcut. It recruits help. It persists, finding crazy workarounds no human has the capacity to figure out — in the blink…
Global Security News
RatHat Turns Android Accessibility Into an Attack Weapon
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is…
Global Security News
CISA Upgrades Vulnerability Reporting Platform with More Automation
The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT
Global Security News
5 internet-improving Chrome extensions worth trying on Android
Browsing the web on Android sure ain’t what it used to be. Earlier this week, we talked about how the Vivaldi web browser is bringing support for Chrome extensions to Android. Vivaldi has the same Chromium code foundation as Chrome but with lots of extra features and options. I’ve been using it on Android and…
Global Security News
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. […]
Global Security News
Meta’s AI Agent Has a Trust Problem
The company’s Muse AI agent needs user data to be useful, but users might be wary.
Global Security News
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”
Global Security News
Best MSP Software for 2026: RMM, PSA, Security & More
The best MSP software depends on the services an MSP delivers and the business functions it needs to manage. Most MSP technology stacks combine remote monitoring and management (RMM), professional services automation (PSA), IT service management, help desk, cybersecurity, and backup tools. For 2026, leading MSP software options include Atera and NinjaOne for RMM, HaloPSA…
Global Security News
‘Nudify’ apps: What to do if someone makes a fake nude of you
Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images
Global Security News
Arcjet brings security controls and audit trails to AI agents
Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need. Arcjet brings observability, enforcement, and audit capabilities across agent workflows so teams can discover which agents are running, control what they can do, and…
Global Security News
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It is the first supply chain vulnerability of the AI agent…
Global Security News
Android apps can now check security patches down to individual device components
New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of individual device components and determine whether security updates are ready to be downloaded and installed on a…
Global Security News
Strong fundamentals make next-gen security possible
Risk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I’ve spent years leading cybersecurity efforts at large enterprises, including Hyatt and United Airlines, and in that time I’ve seen cybercriminals grow increasingly creative, leveraging innovative tactics and technology to further their efforts. I’ve…
Global Security News
Manufacturing Accounts for 22% of all Ransomware Victims
Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026
Global Security News
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. The flaw could let an attacker with no account run code as…
Global Security News
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands.…
Global Security News
Microsoft fixes broken copy and paste for Excel 2016 users
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. […]
Global Security News
Best Parental Control Software for 2026
This post will show you the best parental control software for 2026. As a child safety advocate and parent of two myself, I understand the ever-present concern of keeping our children safe in the vast and sometimes perilous digital landscape. The internet holds a treasure trove of information and opportunities for learning and connection, but…
Global Security News
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it’ll be odd if threat actors aren’t using agents to do all of their bidding.
Global Security News
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
Global Security News
Australia’s AI future depends on the networks we build today
Artificial intelligence AI is moving from experiments and chatbots into the physical world. Australia can lead this next phase, but only if investment in AI is matched by…
Global Security News
HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: “QUERY”. The HTTP protocol faced already by changes (HTTP/2, HTTP/2) but it’s the first new standard HTTP verb since “PATCH” in 2010! This new method sits between “GET” and “POST” and can be resumed like this: “QUERY is a GET with a body”. It’s…
Global Security News
Abandoned IoT apps keep sending sensitive data to broken servers
Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps and found that nearly three in four contained software dependencies associated with documented…
Global Security News
Dreame X60 Ultra review: vacuum robot joins our home renovation team
The Dreame X60 Ultra vacuums, mops, climbs thresholds and cleans much of itself. In our renovation-stressed home, it also achieved something remarkable: it trained the humans.
Global Security News
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company analyzed around 82,000 configuration files and found that 12% of credential slots contained…
Global Security News
98% of fraudulent hires have company credentials by the time they’re caught
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic credentials directly from IT,” said Bojan Simic, CEO of HYPR. “Human…
Global Security News
Most WordPress pros still lack a breach recovery plan
Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators. Across the whole group, fewer than three in ten have a breach recovery…
Global Security News
New infosec products of the week: September 18, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate Security, delivering agentic AI capabilities that give corporate security teams the confidence to protect their…
Global Security News
ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
Hackers Used Anthropic’s Claude to Break Into OpenAI
A bug-hunting independent security research team was able to access OpenAI’s internal code system, exposing growing risks in automated cyber threats.
Global Security News
GitLab 19.4 Brings New Agentic Automation at a Lower Cost
/goal in GitLab Duo CLI, now in public beta, lets developers automate an open-ended objective to a governed agentic flow that runs locally and verifies its own work, so a…
Global Security News
GTIA unveils its 2026 ANZ Spotlight Award winners
Celebrating the organisations driving innovation and making an impact across the Australian and New Zealand IT channel ecosystem
Global Security News
Delinea Joins Anthropic’s Project Glasswing
Delinea will apply Anthropic’s frontier AI model to its own vaulting, secrets, and session-brokering code
Global Security News
An undisclosed Microsoft presentation is now central to a multi-million dollar antitrust fight
There’s a new development in a Microsoft antitrust case, originally filed in England’s High Court in April 2021, and it doesn’t look good for the tech giant. A consent order from the UK Competition Appeal Tribunal is demanding documents from past and present Microsoft executives that may have a bearing on a £270 million (about…
Global Security News
F5 announces strategic partnership with Omnissa to deliver secure, high-performance digital workspaces
Supported by a global channel partner ecosystem—including partners like Presidio—joint solution simplifies Zero Trust VDI delivery, DMZ consolidation, and enterprise…
Global Security News
Attackers turn AI coding tools and agent skills into supply-chain entry points
AI assistants, agent skills and open-source model components are emerging as potentially valuable supply-chain targets for cybercriminals, according to new frontline research…
Global Security News
OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six…
Global Security News
Tech Companies’ Staff Knew Their AI Tools Posed ‘Existential Threat’ to Publishers
Executives at OpenAI and Microsoft acknowledged they could undermine their own content sources, according to a new filing in a New York Times copyright lawsuit.
