WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack, and patched another maximum severity bug allowing RCE in July. WordPress said…
Global Security News
‘Salesbleed’ Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
Global Security News
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. […]
Global Security News
SectopRAT Returns, Hiding Inside a Legitimate Application
The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.
Global Security News
Google Wallet got a lot of new tricks in 2026 – these 5 are my favorites
You can do a whole lot more than tap to pay with Google’s Wallet app.
Global Security News
WordPress patches a critical severity security vulnerability
WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild. Given its popularity, WordPress has frequently been under attack, and patched another maximum severity bug allowing RCE in July. WordPress said…
Global Security News
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. […]
Global Security News
Jeff Bezos’ Blue Origin Is Fueled With $30 Billion of His Fortune
The space company wants to rapidly boost revenue over the next few years, betting its huge rockets will make it a powerful industry player.
Global Security News
Microsoft Expands Gulf AI Ambitions With More Than $10B Through 2030
Microsoft plans more than $10 billion in Middle East capital and operating spending through 2030 under a framework initially focused on Saudi Arabia, the United Arab Emirates, Qatar and Kuwait. Capital and operating expenses cover a regional program stretching from cloud launches due this year to infrastructure work running through the end of the decade.…
Global Security News
OpenAI Agent Breached Australian Medicare Statistics Portal
An OpenAI agent bypassed controls on Australia’s Medicare statistics portal, accessed non-public data and was not reported to officials for nearly 3 months.
Global Security News
China’s AI Boom Is Fueling a Surge in One-Person Startups
China’s AI boom is making it possible for a single founder to operate like a small startup team. Coding, customer support, marketing, design, and administrative work can increasingly be handled with AI tools, lowering the barrier to launching a business. More than seven million one-person businesses were established in China in 2025, up about 42%…
Global Security News
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install…
Global Security News
AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed. That silence was deliberate, and it didn’t last…
Global Security News
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more…
Global Security News
New bill would create federal investigative body for AI-driven hacks
A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigations to provide independent government oversight of cyberattacks carried out by AI agents, following recent hacks by models run at companies like Anthropic, OpenAI, Meta and others. The bill, introduced by Sen. Ed Markey, D-Mass., would attempt to establish a…
Global Security News
Trust and the enticing consultancy offer
Welcome to this week’s edition of the Threat Source newsletter. In the cybersecurity industry, trust is the invisible currency. Every practitioner carries the implicit trust not to abuse privileged access or knowledge of vulnerabilities in each employment or engagement. This trust is valued by those who require our services, but also by threat actors. Clumsy…
Global Security News
America Is Behind on Memory Chips—and Tariffs Threaten to Make Things Harder
The Trump administration wants to spur U.S. chip-making, but tariffs on foreign imports could raise costs for American companies.
Global Security News
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake…
Global Security News
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. […]
Global Security News
Okta wants every AI agent to carry ID, and Australia’s Medicare breach just made the case for it
At Oktane 2026 in Las Vegas, Okta laid out a security blueprint, an alliance of 12 tech companies and free agent sign-on for every customer. The same Thursday, Australian time,…
Global Security News
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ alleges
Law enforcement has arrested two leaders of a Russian-owned phone hacking company used by Kremlin agencies who allegedly masked its foreign ownership from the U.S. Defense Department, Department of Homeland Security and others to win millions of dollars worth of contracts, the Justice Department announced Wednesday. Lee Reiber of Boise, Idaho, the CEO of Oxygen…
Global Security News
Microsoft Password Reset Portal Can Leak Account Verification Details
LevelBlue found Microsoft’s password reset portal can reveal valid accounts, recovery methods and likely administrator accounts without user authentication.
Global Security News
Proofpoint Targets AI, Data Risks with Agentic Security
Proofpoint is expanding its security portfolio with two agentic systems designed to automate how organizations detect, investigate, and remediate risks across AI, enterprise data, and collaboration tools. At its flagship Proofpoint Protect 2026 event in San Diego, California, the company introduced: Agentic Data and AI Security System: A unified agentic system that combines AI and…
Global Security News
Video: GTIA Acquires ASCII Group: What Changes for MSP members?
GTIA has acquired the ASCII Group, bringing roughly 1,000 ASCII members into the Global Technology Industry Association’s network. But what does the acquisition actually mean for ASCII members, GTIA members and the broader MSP community? In this episode of Channel Insider: Partner POV, Katie Bavoso speaks with GTIA Chief Channel Officer Nancy Hammervik, longtime ASCII…
Global Security News
Multiple Vulnerabilities in IBM Concert Software Could Allow for Remote Code Execution
Multiple vulnerabilities have been discovered in IBM Concert Software, the most severe of which could allow for remote code execution. IBM Concert is an agentic IT operations (IT Ops) and resilience platform designed to unify fragmented data, context, and actions across an enterprise’s hybrid cloud and IT environments. Successful exploitation of the most severe of…
Global Security News
Are Boomers Too Attached to AI? Readers Disagree.
Claude, Anthropic’s chatbot, took over one writer’s vacation with his parents, prompting broader questions about its use..
Global Security News
Microsoft’s Surface Mouse is back, now with haptic feedback – and I need it
Due October 13, the $80 Surface mouse packs an impressive array of features. I want one.
Global Security News
AI agent kill switch urged by Okta-led alliance – how businesses could make it work
In response to the emerging threat of rogue and shadow AI agents, here’s how the newly formed Blueprint Alliance seeks to help businesses secure their systems against anomalous AI activity.
Global Security News
Restaurants Are Using AI to Advertise Their Food and It’s Making People Nauseous
Image generators can be very bad at whetting diners’ appetites, rendering wings that look like they were ‘recovered from the reactor core.’
Global Security News
Microsoft integrates SOC capabilities with Defender for enterprises
Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with Defender’s existing XDR, threat intelligence, automation and AI tools in a single portal.…
Global Security News
Microsoft integrates SOC capabilities with Defender for enterprises
Microsoft 365 E5 and E7 customers can now run security information and event management (SIEM) inside Microsoft Defender at no extra license cost. Microsoft is delivering the capability through the Integrated Security Operations Center (ISOC) in Microsoft Defender, which combines SIEM with Defender’s existing XDR, threat intelligence, automation and AI tools in a single portal.…
Global Security News
The Hidden Security Risks of Devices You Forgot Were Connected
IoT and OT devices can create hidden security gaps. Learn how asset visibility helps organizations find forgotten devices and reduce network security risks now.
Global Security News
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. “third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,” Manifold Security’s Head of Research, Ax Sharma, said. “Unlike ‘example[.]com,’ third-party[.]com
Global Security News
Detection Rule Portability
Detection rule portability is the practice of writing and managing threat-detection logic so it moves across SIEM, EDR, and XDR platforms without a full rewrite. What happens to my detection rules when I migrate to a new SIEM platform? Rules written in a platform’s native query language do not travel. SPL stays in Splunk. KQL…
Global Security News
Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims
Ransom notes by n0n ransomware claim to take double extortion to a new level of danger for victims
Global Security News
Measuring MITRE ATT&CK detection coverage: what the percentage counts and what it hides
MITRE ATT&CK detection coverage is the ratio of adversary techniques your SOC can detect, validated against the technique set your threat model prioritizes, on the current framework version. A coverage percentage means nothing without its denominator and proof method. Validated coverage counts techniques where a deployed detection rule fires against its required data source, divided…
Global Security News
Free vs. Curated Detection Rules: What Actually Changes When You Pay
Detection accuracy is a property of a rule evaluated against a specific estate’s telemetry and field mapping, never a property of the source or the format. Free Sigma rules and paid detection content share the same format. The differences that matter sit in maintenance cadence, validation depth, translation testing, and who is accountable when a…
Global Security News
Detection Validation and Decay
Detection validation is the practice of proving a detection rule still fires on the events it was written to catch. Detection decay is the silent failure of a rule that once worked, after a log source, schema, or parser changes underneath it. A rule that is deployed and enabled is not a rule that is…
Global Security News
Multi-Tenant Detection Operations for MSSP and MDR Providers
Multi-tenant detection operations is the practice of managing one source of vendor-agnostic detection logic, translated and tuned per tenant, so a book of customers running different SIEM platforms stays consistent, tunable, and reportable from a single governed source. An MSSP running detection for dozens of tenants faces one structural question: does each customer get its…
Global Security News
3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters’ Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife’s ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
Global Security News
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. “When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into…
Global Security News
SCOUTz Prospect Intelligence Platform Launches for MSPs with 30-Day Beta
Phoenix, Arizona, 24th September 2026, CyberNewswire
Global Security News
How to Build A SASE Framework for Modern Cybersecurity
Keeping edge computing safe requires organizations to fundamentally rethink security governance. Here is a path forward: a step-by-step guide to building a SASE framework.
Global Security News
FedRAMP VDR & VER: Daily Scans Are Only the Beginning
FedRAMP’s new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. […]
Global Security News
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacks
Two Senate committee leaders are introducing legislation to foster cybersecurity standards for the telecommunications sector nearly two years after the landmark Salt Typhoon campaign was made public. First reported by CyberScoop, Virginia Sen. Mark Warner, the top Democrat on the Intelligence Committee, and Texas Sen. Ted Cruz, the GOP chairman of the Commerce, Science and…
Global Security News
Symphony Risk Intelligence uses AI agents to streamline financial crime investigations
SymphonyAI has introduced Symphony Risk Intelligence (SRI), an enterprise-grade, agent-native platform built to unlock Always-on Compliance. This is a critical shift from periodic to continuous risk and compliance management, in which institutions continuously reassess risk and adapt controls as regulations, threats and business activity change, rather than waiting for the next scheduled review. Current approaches…
Global Security News
OpenAI Agents Tried to Hack Four More Websites While Seeking Data
AI agents sent to gather basic online data tried to hack into government and university sites when they hit roadblocks, joining a growing list of rogue incidents.
Global Security News
Is your Apple Watch 12 or Ultra 4 randomly restarting? Here’s the fix
Some owners, including me, have reported sudden shutdowns while adjusting Apple Watch settings.
Global Security News
On-prem VeloCloud Orchestrator under attack, only some versions patched
A flaw in VeloCloud Orchestrator enables attackers to access the platform organizations use to manage their VeloCloud SD-WAN subscriptions and the edge devices it controls. Arista, which now owns the VeloCloud business, warned customers that a vulnerable configuration exists in on-premises VeloCloud Orchestrator deployments that remote attackers may abuse to access “privileged internal functionality” and…
Global Security News
Ghost Service Accounts Enable M365 Data Theft in Chile
Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization’s entire M365 environment.
Global Security News
Hackers now exploit critical Roundcube flaw in code injection attacks
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. […]
Global Security News
Five years later, you can finally buy Google Beam
It’s been five years since Google first offered a glimpse of Project Starline, a three-dimensional videoconferencing platform billed at the time as as a “magic window” that enables realistic and immersive calls. On Wednesday, Google announced that Google Beam — as the software element of the product is now called — is generally available for purchase,…
Global Security News
CVE-2026-94545: Critical Next.js ImageResponse Flaw Enables Remote Code Execution
A critical vulnerability in Next.js could allow remote attackers to execute arbitrary code on vulnerable servers through the framework’s ImageResponse functionality. Tracked as CVE-2026-94545, the flaw affects the Node.js implementation of ImageResponse in next/og and carries a CVSS score of 9.5. Vercel addressed the issue on September 22, 2026, with the release of Next.js 16.3.6.…
Global Security News
IGEL CTO: Shadow AI Policy Needs Endpoint Controls
Shadow AI is creating a widening gap between corporate AI policy and how employees actually use generative AI tools, prompting security leaders to look beyond written governance rules toward technical enforcement at the endpoint. The UK’s National Cyber Security Centre (NCSC) has warned that unauthorized AI use can expose sensitive data and create security blind…
Global Security News
OpenAI agent breached Medicare statistics site, then took months to report it
An OpenAI agent didn’t take “no” for an answer when it encountered a government website’s access controls. It got through, prompting Australia’s Prime Minister Anthony Albanese to raise his concerns directly with OpenAI CEO Sam Altman. The BBC reports that an OpenAI agent gained unauthorized access to an Australian government statistics portal while carrying out…
Global Security News
Cribl LogTotal Sanitizer: Pseudonymize Sensitive Log Data Inside Cribl Stream
Sooner or later, every security team hits the same situation: logs that normally just flow quietly through your own pipeline — from source to SIEM, doing their job — suddenly need to leave that pipeline. A vendor asks for a sample to help debug something. A one-off investigation, or a standing need to send telemetry…
Global Security News
Microsoft adds pay-as-you-go pricing for extra OneDrive storage
Microsoft has added a “pay-as-you-go” option for OneDrive storage, providing an additional way for Microsoft 365 commercial customers to buy extra cloud storage capacity for users. Previously, increasing storage capacity for OneDrive users meant purchasing capacity “packs” for individual accounts, available in 100GB, 500GB, and 1TB through 6TB sizes. With the new consumption-based billing, Microsoft…
Global Security News
UiPath’s new tool could unlock a much bigger wave of automated business processes
A decade ago, UiPath built its business on watching people work, recording keystrokes and clicks to automate tasks employees already did by hand. This week, amid an industry consumed by autonomous agents, the company’s newest product suggests that same instinct still has a place. UiPath used its Fusion conference in Las Vegas to launch Cartographer,…
Global Security News
Enveda Raises $311M as AI Drug Discovery Startup Hits $2B Valuation
Enveda just put another $311 million behind its bet that AI can uncover medicines hidden in nature. The Boulder, Colorado-based biotechnology company closed a $311 million Series E round led by Catalio Capital Management, doubling its valuation from a year ago to about $2 billion. The round also drew new backing from Durable Capital Partners,…
Global Security News
Censys Expands Global Channel Partner Program
Censys is expanding its global Channel Partner Program with new go-to-market support, early access to its product roadmap, and additional enablement resources as the security vendor looks to build on rapid partner-led growth. The company said its ecosystem now includes more than 100 channel partners across 45 countries, with partner-sourced bookings growing 186% year over…
Global Security News
Microsoft Recasts Culture Around AI
Plus, more leadership lessons from UNGA 2026
Global Security News
Shield Launches Forge AI Platform for MSP Service Delivery
Shield Technology Partners, an MSP investment and operating platform, is launching Forge, an AI operating system built to automate core IT service delivery tasks and give MSP technicians more time to focus on higher-value customer work. Announced Sept. 24, Forge spans helpdesk operations, account strategy and project execution while allowing Shield’s partner companies to build…
Global Security News
Amazon to Expand Robot-Making Capacity With New, $100-Million Indiana Hub
The company, which uses the machines for sorting and moving packages inside warehouses, is already one of the world’s top robot makers.
Global Security News
Prompt-Injection Bug Hits $4B Agentic AI App ‘Manus’
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.
Global Security News
OpenAI agent hacking spree widens to Australia, targeting government website
Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday. “Notably, the tasks the agents were trying to solve were not cyber-related; the agents resorted to hacking tactics while working on ordinary data retrieval…
Global Security News
CISA Charts New “Quality Era” for Global CVE Program
CISA has set out a new framework to improve CVE data quality as vulnerability volumes rise
Global Security News
New Browser Guard features add protection before and after you click
Most of us click on search results without knowing much about the website we’re about to visit. And once we’re there, it’s not always obvious when something isn’t quite right. Now, we’ve added two new features to Malwarebytes Browser Guard that will do even more to keep you safe online. Search Reputation gives you a…
Global Security News
Ukrainian ransomware developer jailed for nearly 13 years
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world. Read more in my article on the Hot for Security blog.
Global Security News
Cloud Range lets SOCs benchmark AI agents against human defenders
Cloud Range has announced the official launch of its AI Validation Range and Cloud Range AI Readiness Framework. They give organizations a structured way to test AI models and agents in realistic environments, validate their readiness for operational responsibility and safety, and determine which roles and tasks are best handled by AI versus human experts.…
Global Security News
Gurucul connects AI activity to identity data for faster threat response
Gurucul has announced the general availability of Gurucul AI Risk and Response, bringing behavioral AI to the growing attack surface created as AI moves from assistant to actor. With hundreds of AI detections connecting activity to identity, access, data and broader security telemetry, the solution helps SOC and Insider Risk teams see who or what…
Global Security News
Windows 11 KB5124010 update released with 46 changes and fixes
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. […]
Global Security News
Airties adds router-level cybersecurity protection for ISPs
Airties has launched new integrated cybersecurity capabilities that enable ISPs to detect and remediate threats to connected homes and small businesses. As part of Airties’ Connectivity Experience Management Platform, these new capabilities turn the router into an additional security layer that safeguards every device on the network, giving ISPs a powerful baseline of protection for…
Global Security News
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that’s dressed up as a system service.…
Global Security News
Azul AI Assistant helps teams find Java licensing and security risks
Azul has announced Azul Intelligence Cloud AI Assistant, a natural-language query interface that tells IT, DevOps and security teams where licensing and security risk is hiding in their production Java estate. The assistant provides answers grounded in live runtime data, replacing static reports that go stale the moment they’re generated. The widening attack surface This…
Global Security News
LatticeFlow AI offers managed risk assessments for enterprise AI systems
LatticeFlow AI has announced the LatticeFlow AI Risk Center, an AI governance managed service that continuously assesses and controls AI risk, giving enterprises the technology, evidence, and expertise to scale AI with confidence and accelerate time to value. AI systems and agentic workflows are moving into production faster than most organizations can build the capabilities…
Global Security News
Meta locks itself out of user data on its AI glasses
Meta is expanding Private Processing to its AI glasses, extending their security protections into cloud data centers. The system runs AI models inside confidential virtual machines (CVMs) designed to prevent Meta from accessing users’ data. Private Processing combines protected hardware, encryption and software verification to secure data during cloud processing and storage. How Private Processing…
Global Security News
UK gears up for fight against Russia’s disinformation machine
The UK government will create a new body to track and disrupt disinformation campaigns run by hostile states, Prime Minister Andy Burnham announced at the United Nations General Assembly in New York. In his first address to the Assembly on 22 September, Burnham told world leaders he was tasking UK security chiefs to begin work…
Global Security News
Schneider Electric Joins Lenovo 360 Circle for Partners
Lenovo is bringing Schneider Electric’s carbon management tools and decarbonization expertise into Lenovo 360 Circle, giving eligible channel partners new support to measure emissions, identify reduction opportunities, and build practical sustainability roadmaps. Schneider Electric brings decarbonization tools to Lenovo partners As a new ally, Schneider Electric will bring its Decarbonization Champion initiative to the channel,…
Global Security News
Hexnode Synapse Brings Agentic AI Orchestration to MSPs
Hexnode, Mitsogo’s enterprise software division, has unveiled Hexnode Synapse, an agentic AI orchestration layer for IT and security operations designed to turn requests and system events into coordinated, governed, and traceable actions. Hexnode Synapse helps MSPs coordinate service requests, alerts, and events from initiation to resolution across the tools involved. It extends workflows across the…
Global Security News
Update Chrome: 108 security fixes for desktop, new release for Android
Over the last few days, Google issued several different Chrome updates. On September 22, Google released a Stable Channel Update for Desktop. This is the most important one for desktop users. It brings Chrome to version 154.0.8037.57 for Linux and versions 154.0.8037.57/.58 for Windows and Mac. The update includes 108 security fixes including 11 rated…
Global Security News
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are…
Global Security News
8 cool things Copilot can do in Word
We all know by now that Copilot can help you write and rewrite text in Word, often with mediocre results. But there’s more to Microsoft’s generative AI tool than just slopping out words. In fact, Copilot’s most useful features in Word have more to do with editing, formatting, and research assistance than with writing per…
Global Security News
Devolutions Launches Investment Arm for MSP Ecosystem
Devolutions is launching Devolutions Ventures, a new corporate investment arm focused on companies across the IT and managed service provider ecosystem. The initiative will target businesses in areas including secure access, network performance, automation, and other technologies that complement Devolutions’ existing platform. Unlike a traditional acquisition strategy, Devolutions plans to keep portfolio companies independent while…
Global Security News
UK Government Shifts to Service-Led Cyber Governance After Stinging Audit
Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy
Global Security News
CISA: Ransomware gangs now exploiting critical TeamCity flaw
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. […]
Global Security News
Anthropic Taps Accenture for Embedded AI Safety Evaluations
AI safety is moving closer to the consulting bench, not just the research lab. Anthropic is giving Accenture a seat inside its model-development process. Nearly a week after naming an Accenture team led by Faculty as its first embedded evaluator, Anthropic’s arrangement is drawing attention to a potentially broader services opportunity. Faculty specialists will work…
Global Security News
OpenAI Agent Bypassed an Australian Government Health Portal During Internal Research
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was…
Global Security News
OpenAI Agent Hacks Australian Medicare Portal
Australian PM Anthony Albanese criticized OpenAI’s response to the incident, which occurred in June 2026
Global Security News
Flow of Chinese Components to Iran Shadows Trump’s Summit With Xi
Plus, a perfect storm is raging in the bond market, and we tracked where MAGA podcasters are turning their attention as they tune out Trump.
Global Security News
How tax policy can stop threat actors from breaching US water systems
The foundation for modern society in America is under attack. State and local governments, entities that often oversee critical natural resources, schools, and hospital systems, are routinely targeted and breached by state-backed threat actors. Their budgets are simply too slim to provide the digital bulwarks required to fend off such attacks. The problem is growing.…
Global Security News
New AvisLoader Windows Malware Uses ClickFix Lure and Tox P2P for C2
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the Tox peer-to-peer network for C2 and arrives through a malicious ClickFix lure.
Global Security News
Glassbox Earns Microsoft Financial Services AI Designation
Glassbox has earned Microsoft’s Solutions Partner with certified software designation for financial services AI, giving the digital experience analytics provider a new credential within the Microsoft AI Cloud Partner Program as it expands its Azure-backed AI portfolio. The designation confirms that Glassbox’s software meets Microsoft program requirements and is interoperable with Microsoft Cloud, including Azure.…
Global Security News
New Android malware RemControl steals banking PINs and blocks removal attempts
A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. Researchers confirmed that the malware targets customers of more than 30 banks in Italy, France, Spain, Poland, Portugal, Canada and some Gulf states. The first samples were…
Global Security News
OpenAI hacked Australian Medicare govt site, probed data providers
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. […]
Global Security News
Google plans to give Private AI Compute a memory that follows users across devices
Google plans to add private, server-side memory to Private AI Compute, enabling AI assistants to maintain continuity across devices while providing privacy protections normally associated with on-device processing. Private AI Compute is Google’s cloud platform for processing sensitive data with Gemini models in a hardware-isolated environment. It gives AI features access to greater computing power…
Global Security News
See How Elon Musk’s Sunbelt Investments Are Reshaping His Business Empire
States are competing for billions of dollars of planned capital spending on chip foundries, launchpads and data centers.
Global Security News
Over 75% of Organizations Experience Microsoft 365 Governance Issues
ShareGate study claims to reveal a governance ‘crisis’ as AI usage grows
Global Security News
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why…
Global Security News
Aviation solved the vigilance problem. AI just gave security a worse one
An air traffic controller watching a busy scope will, sooner or later, miss the one aircraft that matters. Sustained attention decays under load, a limit aviation named the vigilance decrement and has spent seventy years designing around. AI has moved every knowledge worker into that chair. You now work a dozen aircraft at once: six…
Global Security News
Tech Industry Calls on Trump Administration to Withdraw New H-1B Visa Fee
The clash over a proposed DHS rule to charge a $103,265 fee is reigniting a spat over highly skilled immigration.
