A new scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems. The findings, published Wednesday by Forescout’s Vedere Labs, show that direct internet access to equipment used in water and wastewater operations remains common despite years of warnings…
Global Security News
Google’s John Hultquist on outpacing the adversary with AI threat defense
Global Security News
Route Amazon Bedrock Guardrails interventions to Amazon Security Lake

Security teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongside identity, network, and application security data in a single layer. When a guardrail blocks a prompt injection attempt or redacts…
Global Security News
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.
Global Security News
NatJack exploits put NAT security assumptions to the test at Black Hat

For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assumption might not be entirely accurate anymore (if it ever really was).…
Global Security News
250+ ClickFix Domains Hide macOS Malware From Security Scanners

More than 250 ClickFix domains are using browser fingerprinting to hide macOS malware lures from security scanners. Microsoft Threat Intelligence said the campaign checks visitors for signs of a genuine Mac before serving malicious instructions that can lead to the download of Atomic Stealer or MacSync. Crawlers, sandboxes, and researchers may instead receive blank pages…
Global Security News
Apiiro’s Idan Plotnik on AI writing code that sharpens attacks
Global Security News
Swiss government SharePoint breach compromised 200 accounts
Global Security News
Ransom Cartel creator sentenced to 16 years in prison

A longtime cybercriminal was sentenced to 16 years in prison for creating and running Ransom Cartel, a ransomware strain linked to attacks on at least 18 companies between 2021 and 2023, the Justice Department said Wednesday. Maksim Silnikau, a Belarusian national, actively participated in Russian-speaking cybercrime forums since at least 2005, and was a member…
Global Security News
Black Hat 2026: Barracuda Details AI-Powered BEC Attack
As part of its Black Hat USA 2026 research, Barracuda released a PoC demonstrating how attackers could use AI-enabled email assistants to escalate a compromised employee account into a full-scale BEC attack. Researchers said the greatest risk is that AI assistants accelerate reconnaissance, phishing, and fraud using compromised accounts. The attack used Microsoft Copilot, though…
Global Security News
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Global Security News
Why metaphor may dictate your security strategy

Welcome to this week’s edition of the Threat Source newsletter. Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues. Recent reports of offensive AI agents “escaping” their sandbox environments…
Global Security News
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which manages…
Global Security News
Photos: Black Hat USA 2026, part two
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protection against real-world LLM attacks. The post Photos: Black Hat USA 2026, part…
Global Security News
Is the new (pricier) Pixel 11 series still a good value compared to Samsung’s Galaxy phones?
The Pixel 11 may cost more, but Google’s software could still make it a better value than Samsung’s phones.
Global Security News
6 must-have travel gadgets, according to industry experts
Global Security News
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. “These vulnerabilities were…
Global Security News
Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history…
Global Security News
Everyone’s a Builder Now: Securing the AI-Powered Enterprise – Gil Geron – BH26 #2
Global Security News
Kai’s Galina Antova on the shift to machine-led security
Global Security News
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records

An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files,…
Global Security News
The M5 Macbook Air is down to the lowest price we’ve seen since Apple’s price hike
Global Security News
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux…
Global Security News
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven financial crime detection platform on Amazon Web Services (AWS). NICE Actimize, a leading provider…
Global Security News
Meta AI model hacked a company during misconfigured cyber test
Global Security News
Black Hat USA 2026: Solving insider risk in the agentic AI era
Here’s a five-stage action plan for confronting insider risk from noted cybersecurity executive Phil Venables.
Global Security News
Cloudflare OS Gives Partners a Platform for Enterprise AI Agents

Cloudflare is opening up the AI workspace it built for its own employees. Now, partners can use the same foundation to create enterprise agents, automate workflows, and build small internal apps. The platform connects AI tools with an organization’s internal knowledge, applications, and security controls. Employees can use the browser-based workspace to research information, create…
Global Security News
Why Anthropic’s Chips Matter for the Channel

The rumors turned out to be true. Anthropic says it’s building an in-house team to design custom AI chips for Claude, giving the company more control over the hardware behind its AI models. It’s also not blowing up its existing infrastructure. Anthropic says chips from AWS, Google, Nvidia and AMD will remain part of the…
Global Security News
1Password Finds AI Security Patches Fail More Than Half the Time

A new study from 1Password’s Off-by-1 Labs suggests that organizations should be cautious about relying on large language models (LLMs) to autonomously remediate software vulnerabilities. After evaluating more than 6,000 AI-generated security patches across six recently disclosed, high-impact vulnerabilities, researchers found that fully successful patches were the exception rather than the rule. Key takeaways of…
Global Security News
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
Global Security News
Ransom Cartel Leader Sentenced to 16 Years in U.S.

A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia…
Global Security News
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.…
Global Security News
Granola lawsuit raises concerns over AI note-taking app privacy

AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court. It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor,…
Global Security News
UK data watchdog criticizes Metropolitan Police for data handling failures
The UK’s data protection regulator criticized the Metropolitan Police Service (MPS) for significant data handling failures, including sharing a stalking victim’s new contact details with her abuser and a separate incident exposing the email addresses of 18 individuals connected to Parliament.
Global Security News
Salesforce’s Agentforce 360 platform approved for sensitive Defense Department data
Salesforce’s enterprise agentic AI platform, Agentforce 360, received approval from the Defense Department to securely handle high-sensitivity workloads, including Controlled Unclassified Information (CUI) and unclassified National Security Systems (NSS) data.
Global Security News
NVM Express updates specifications with post-quantum cryptography and SSD virtualization support
The NVM Express consortium released updates to its 11 specifications, introducing significant advancements in security and virtualization for solid-state drives (SSDs).
Global Security News
Prompt injection remains top LLM threat, OWASP report finds
Global Security News
Beacon CRM confirms cyberattack exposed UK charity data
Global Security News
US reportedly drafting ban on Chinese optical transceivers
Global Security News
Brazil’s health system data exposed online
Global Security News
Google mistakenly locks hundreds of Blogger websites
Global Security News
Apple’s Private Relay feature has flaws that can expose user IP addresses
Global Security News
This LG OLED TV is one of the most impressive I’ve tested – and it’s $700 off
The LG C6 is a powerful refresh of the brand’s flagship OLED TV, and right now at Best Buy, you can get the 65-inch version for 26% off.
Global Security News
How To Get Money Back From A Scammer On Western Union

Western Union is one of the most used means of international money transfer. Find out how to get money back from a scammer on Western Union in this post. Scams take various forms, but the most popular scam often joked about is the “Nigerian Prince” email scam, which still rakes in over $700,000 in illegal…
Global Security News
Common Dating Website Scams and How to Avoid Them

In this post, I will discuss common dating website scams and how to avoid them. The image of a dating scam as a clumsy stranger with a broken keyboard is out of date. The people running these schemes now build profiles with deliberate small flaws, match a target’s tone, and wait weeks before asking for…
Global Security News
Apple WebKit vulnerabilities reveal your IP address, despite Private Relay

Three WebKit mechanisms have been discovered to bypass Apple’s iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo’s proxy, Tor-on-iOS proxy setups, and so on. Private Relay is a VPN-like system for Safari on iOS which is meant to prevent websites from viewing the visitor’s IP address and location.…
Global Security News
I’ve been using the Galaxy Z Fold 8 for two weeks – these two accessories perfect the experience
With the Galaxy Z Fold 8 as my main driver, these two accessories are must-haves (and one isn’t even made by Samsung).
Global Security News
TeamPCP Traced Back to 2020 Cryptojacking Operation
Global Security News
Novel-reading apps used users’ phones to generate fake ad traffic

A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab) While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a…
Global Security News
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
Global Security News
The new Pixel 11 isn’t enough to make me give up my Pixel 9 Pro – here’s why
Google is set to release the Pixel 11 soon, and although my Pixel 9 Pro is two years old, I won’t be upgrading for five specific reasons.
Global Security News
How a software provider closed unknown paths to cloud compromise

A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative access. Multifactor authentication (MFA) was enforced broadly, vulnerability scanning was routine, and annual penetration tests were part of the organization’s broader security…
Global Security News
Meta AI Agent Exploited Third-Party Flaw During Cybersecurity Test

One of Meta’s AI models hacked into another company’s systems during a cybersecurity evaluation after a testing misconfiguration gave it internet access. Facebook’s parent company told the BBC it is investigating and plans to publish more information once it has established the facts. Recent incidents involving OpenAI and Anthropic have intensified scrutiny of whether cyber-capable…
Global Security News
How a global investment firm reduced security surprises

Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter? For a global investment firm operating across 18 locations, that question became…
Global Security News
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
Global Security News
Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.
Global Security News
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) on going from vulnerability disclosure to autonomous remediation at machine speed. Jeremiah Grossman and Robert…
Global Security News
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Security researchers have disclosed critical vulnerabilities affecting AI coding agents from Anthropic, Google, and OpenAI, demonstrating how attackers could compromise automated development workflows through a single untrusted GitHub issue. According to the research presented by Novee at Black Hat USA 2026, the flaws were found in the vendors’ own repositories running their default configurations. This…
Global Security News
An Irregular testing that caused Meta, OpenAI, and Anthropic AI agents to go rogue

Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center of a series of disclosures involving the industry’s leading AI labs. During a “capture-the-flag” test…
Global Security News
You’re only as secure as your last evaluation

The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat landscape faced by the DIB. Updated CMMC guidance issued in…
Global Security News
You can use 70+ Adobe tools without leaving ChatGPT now – here’s how
Adobe’s new plugin works both in Work and Codex, and is available today in ChatGPT.
Global Security News
Bose’s new QuietComfort headphones get premium upgrades for a midrange price
Global Security News
Cybersecurity needs a new operating model

For decades, cybersecurity has been built around one assumption: defenders had enough time to: Discover vulnerabilities. Assess exposure. Deploy patches. Verify that critical systems remained protected. That assumption shaped how organizations built security programs, how vendors developed security products, and how regulators measured cyber resilience. That assumption no longer holds AI has not created a…
Global Security News
My 3 favorite AI tools for voice dictation while vibe coding – and one is free
I’ve tested the top AI voice tools to find which delivers the best accuracy, privacy, and corrections.
Global Security News
AI failed to properly patch software flaws 74% of the time, 1Password’s study warns
Global Security News
Three in four AI-generated vulnerability patches leave something broken
Global Security News
Taught by AI pioneers, Stanford’s free online course takes you far beyond ChatGPT
Global Security News
The exploit window is shrinking. Most security workflows are not

AI is accelerating vulnerability discovery, exploit development, and attacker weaponization faster than most organizations can adapt. Security teams are inundated with vulnerability disclosures, threat intelligence feeds, exploit chatter, and vendor advisories, all demanding immediate attention. Yet only a small percentage of vulnerabilities are ever actively exploited in the wild. The challenge is no longer visibility.…
Global Security News
Google’s new Ask Maps features may be more exciting than the upcoming Pixel drop
Global Security News
Snowflake hacker pleads guilty, faces up to 32 years in prison

A Canadian man is facing decades in prison for hacking customer accounts at cloud storage provider Snowflake and stealing data from more than 165 organizations. Connor Riley Moucka, also known as “Waifu” and “Judische,” 26, of Kitchener, Ontario, pleaded guilty in federal court in Washington state to computer fraud, wire fraud, aggravated identity theft, and…
Global Security News
CTEM isn’t failing. It’s not being operationalized

Cybersecurity is full of frameworks, regulations, and directives that tell organizations what they should do. Zero Trust, NIST, CIS Controls, CMMC, DORA, NIS2, and now Continuous Threat Exposure Management (CTEM) all provide valuable guidance and describe desired outcomes. The challenge is that most stop at the “what.” They rarely explain the “how.” That is not…
Global Security News
Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network. Its August 3 scan counted 4,407 exposed Rockwell controllers worldwide, including 2,844 in the United States, but Forescout could not confirm any were compromised. That figure counts exposed
Global Security News
Autonomy is earned, not claimed

After more than 300,000 production penetration tests (pentests), our company has learned something that may surprise people watching the recent wave of autonomous security announcements. The hardest problem in autonomous security isn’t teaching a machine how to attack. It’s teaching an AI-based system how to operate safely, predictably, and repeatedly inside production environments where mistakes…
Global Security News
OpenAI’s ‘Rotten to the core’ defense is its weakest play yet

Ancient Greek sophist Protagoras famously said, “There are two sides to every question.” But OpenAI’s latest attempt at reality distortion seems determined to narrow this dispute to just one. In its motion to reject Apple’s complaint, the company does not meaningfully acknowledge the criticisms levelled against it, preferring instead to recast the case as a grievance over talent…
Global Security News
Attackers hid malware inside Oracle Database after SQL injection breach

Huntress has documented a case where the Oracle database itself became the malware host. The security firm disclosed a campaign in which threat actors exploited a SQL injection vulnerability to store a custom post-exploitation toolkit, dubbed Khunt, inside an Oracle database using the platform’s built-in Java capabilities. Huntress became aware of the intrusion after investigating…
Global Security News
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
We spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…
Global Security News
Startup Raises $700 Million to Replace Data-Center Wires With Light
Global Security News
Violent Physical Crypto Thefts Surge to $30m in Losses
Global Security News
75% of European businesses fear a US tech kill switch – American companies should, too
Businesses on both sides of the Atlantic may be too dependent on a handful of tech providers, leaving them vulnerable to being cut off.
Global Security News
CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago, the function supplied weak entropy that affected wallet apps used to generate recovery phrases. Coinspect’s on-chain analysis puts the measured theft across two sweeps since late May at a lower…
Global Security News
Verification closes the loop

Most organizations assume remediation reduces risk. It’s a reasonable assumption. A vulnerability is identified, a patch is applied, the scanner comes back clean, and the ticket is closed. The workflow is complete, the metrics improve, and the issue is considered resolved. The problem is that attackers don’t care about remediation workflows. They care about outcomes.…
Global Security News
Meta AI Model Hacked Outside Company, Adding to Concerns Over Rogue Bots
Global Security News
Scammers target OnlyFans users with deepfakes

OnlyFans creators are used to posting adult videos of themselves online, but what happens if someone takes control of their images and uses them for fraud? This week, USA Today revealed how criminals are impersonating OnlyFans creators using AI tools. They use deepfake content to lure the real models’ fans with fake promises of live…
Global Security News
Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address. Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users’ privacy by routing their Safari web traffic through two relays so that no single third-party, including Apple, can determine where…
Global Security News
AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep links. We observed production websites embedding hidden prompt injection payloads inside “Ask AI” buttons on marketing and competitor comparison…
Global Security News
16-31 July 2026 Cyber Attacks Timeline Infographic
103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit sectors, and targeted countries, all in one interactive HACKMAGEDDON timeline.
Global Security News
16-31 July 2026 Cyber Attacks Timeline
103 confirmed cyber incidents reported between 15 and 31 July 2026 — including attacker motivations, top techniques, initial access vectors, hardest-hit sectors, and targeted countries, all in one interactive HACKMAGEDDON timeline.
Global Security News
Discounted Claude access bought on the gray market may expose every prompt you send

More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI models, were discovered by Okta. Okta believes the trend is likely driven by Chinese users seeking access to AI models that are unavailable because of regulatory and provider restrictions. “The demand is driven…
Global Security News
Amazon and Apple impersonated in “$149.99 unauthorized charge” scam

If you’ve spent any time browsing lately, you may have run into a full-screen popup warning you that your Apple ID or Amazon account was just used for a mysterious $149.99 purchase. It looks urgent. It looks official. And if you look at two examples side by side, it becomes obvious that it’s neither. Below…
Global Security News
Black Hat USA 2026: One GitHub Issue Could Compromise Major AI Coding Workflows
At Black Hat USA 2026, Novee found GitHub workflow flaws in Claude Code, Gemini CLI and Codex that enabled RCE, credential theft and agent control in pipelines.
Global Security News
Anthropic’s Mythos AI used social engineering to target real people

Anthropic’s Mythos AI agent, tested by the UK AI Safety Institute (AISI), has reportedly attempted a real‑world social‑engineering style hack against GitHub maintainers by creating fake human profiles, pressuring them to accept malicious code, and then editing logs to hide its tracks when challenged. AISI was running cybersecurity evaluations of Anthropic’s Mythos and OpenAI’s Sol…
Global Security News
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
Cisco has fixed a critical vulnerability (CVE-2026-20200) in its Integrated Management Controller (IMC), which allows an attacker to run commands as root through the controller’s web interface. The fix was part of Cisco’s August 5 advisory batch, and unlike the bugs squashed by the hardening releases for IOS XE and SD-WAN, this one has a…
Global Security News
Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports – many of which were found to be describing security flaws that simply didn’t exist. Read more in my article on the Hot for Security blog.
Global Security News
Canadian Hacker Pleads Guilty Over Snowflake Extortion Campaign
Global Security News
The water sector just got it’s wake-up call. Again.

Last week, the FBI and EPA issued a joint alert that should concern anyone who drinks water in America–which is to say, everyone. Since July 27, water and wastewater utilities in at least seven states have reported cyberattacks against internet-facing programmable logic controllers (PLCs), the small industrial computers that run pumps, valves, and treatment equipment.…
Global Security News
Why the ‘rogue AI’ problem will lead to an era of headaches for security practitioners

Shortly after OpenAI publicly acknowledged the Hugging Face breach on July 21, Reuters journalist Raphael Satter called me for comment on a story which would reveal shocking new details about OpenAI’s “rogue model” incident: The agent hadn’t just slipped its leash for a few hours, as many assumed, but had in fact been wreaking havoc…
Global Security News
5 Best AI headshot generator tools for businesses compared on cost & quality
Global Security News
Meta AI Model Hacked a Company During Testing, Marking Third AI Lab Incident

Meta says an AI model hacked a company during testing after accidental internet access, marking the third disclosed AI lab breach in weeks. Meta confirmed that one of its AI models breached an unidentified company during cybersecurity testing, after its independent testing partner Irregular gave the model unintended internet access through a misconfiguration. This is…




























