
A decade ago, a computer did something that no human would have done. It was considered a breakthrough for AI. Now the world is full of them.


Lina K., a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit…

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended…

A Canadian hacker has pleaded guilty to charges tied to the 2024 breaches of more than 165 Snowflake customer environments, a campaign that exposed data belonging to at least 100 million people. Connor Riley Moucka, 26, admitted to computer fraud, wire fraud, aggravated identity theft, and conspiracy in federal court in Seattle. The attacks relied…

On Aug. 6, DXC announced a strategic partnership with security startup Primary, becoming the exclusive managed services provider for Primary’s AI-native Zero Trust Platform. The joint offering is designed to help enterprises and government agencies govern how AI agents and enterprise AI applications access data, identities, and business systems. The companies are targeting organizations that…

A phone-first data-theft extortion campaign has targeted dozens of major US financial firms over the past month. Ransom-seeking hackers have targeted dozens of major US financial institutions and other businesses in a campaign that relies heavily on phone-based social engineering, according to data from Google and internet intelligence platforms reviewed by Reuters. The targets included…

Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applications and your business.” A decade later, AWS Managed Microsoft AD…

China has put one of America’s biggest cybersecurity companies under the microscope, adding network security software to the growing list of US technologies caught in the escalating Beijing-Washington standoff. The Cyberspace Administration of China said Thursday that its Cybersecurity Review Office had begun a review of products sold in China by Palo Alto Networks, citing…

Cato Networks, a converged network and security cloud, has launched Cato Agentic Threat Prevention, a new capability to deploy autonomous agents to predict likely attack paths. Stopping frontier AI adversaries before they advance Introduced at Black Hat USA 2026, the capability also automatically personalizes protections for each customer environment to prevent breaches before AI-assisted attacks…

The start of Q3 saw few mergers and acquisitions (M&A) movements across the channel, but these were nonetheless significant. The acquisitions focused on security and expanding reach into various regions to serve more customers. Read more about the M&A moves below, and be sure to catch up on last month’s moves. Barracuda Networks acquires Evo…

Etsy is shrinking its workforce even as its business starts gaining momentum again. The online marketplace said Wednesday it will eliminate about 220 jobs, roughly 12% of its workforce, as part of a restructuring aimed at simplifying the organization and speeding up decision-making. Most of the layoffs will affect employees in product and engineering, according…

8×8, Inc., a business communication platform provider, is introducing a new partner program for its direct resell channel that rewards customer retention and expansion. Four-tier structure to align partner and company success The 8×8 partner program features a four-tier structure: Authorized, Silver, Gold, and Platinum. With this structure, direct resellers can earn financial rewards according…

LightSpy, a China-linked surveillance platform, has grown into an operation using at least 117 servers with verified router infections. At Black Hat USA, Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov said LightSpy has been identified in more than 13 countries, growing well beyond the spyware, active since at least 2018 and publicly documented in…

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer…
Free ChatGPT users are about to get more room to work. OpenAI is making GPT-5.6 Luna the default for Free and Go users this week. Unlimited text chats and a Think button arrive next week, while Plus and Pro subscribers get an updated GPT-5.6 Sol with more control over reasoning. Unlimited text lowers a barrier…

AMD is moving deeper into AI inference with technology designed around specific models rather than relying only on general-purpose accelerators. The chipmaker has agreed to acquire Toronto-based Taalas, a startup specializing in inference silicon that AMD says can reduce compute and memory bottlenecks. AMD plans to integrate the technology into its accelerator roadmap and develop…

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU…

Proofpoint Inc. debuted a new program at Black Hat USA 2026 that makes a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed services providers, and platform companies. Accelerating OEM innovation with trusted threat intelligence The Proofpoint OEM Program formalizes and expands the cybersecurity providers’ OEM business. It provides…

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via…
The Satechi ChargeView 240W desktop charger ticks all the right boxes for this charging geek.

ConnectWise and SentinelOne have unveiled a joint managed cybersecurity strategy aimed at helping MSPs scale threat detection and response through deeper integration of Managed EDR, AI-driven security, and automation. ConnectWise and SentinelOne deepen MSP security collaboration Announced at Black Hat USA 2026, the strategy establishes a framework for deeper collaboration that brings together the AI-driven…
The inconsistent service, shady upcharges, and uptick in better-valued competitors made the choice easy.

Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction and configuration files for agentic tools. Discovered by researchers from security firm Zenity, the…

Zero Networks, a Zero Trust security solutions provider, announced a new capability at Black Hat USA 2026. This new capability applies the Open Worldwide Application Security Project’s (OWASP) principle of Least Agency to help organizations safely deploy AI agents. Reducing the impact of compromised AI agents The Least Agency Enforcement capability uses identity-based microsegmentation, policy…

As AI-generated code continues to be injected into all corners of the internet, concerns have risen about an expanding attack surface for malicious hackers to exploit. Some have argued that the enhanced cybersecurity capabilities of large language models could serve as a check, finding and fixing vulnerabilities nearly as fast as they’re created. But new…
Samsung’s latest smartwatch introduces new metrics, a longer-lasting battery, and hints at the future of wearables.

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into…
Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix over-permissioned S3 buckets across your AWS environment, along with…

The Trump administration tapped a surveillance giant with a record of attacking the press to advise the State Department on free speech. Among the partners for the State Department’s new “Freedom Tech Excellence Program” is Palantir, the AI and data integration firm started by right-wing powerbroker Peter Thiel. Under the program, company employees will go…

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens…
A SIM swapping attack could compromise your phone, your personal accounts, and even your identity. Here’s how to thwart them.

As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network. Citylink is designing the data center…
With its unique size, the Galaxy Z Fold 8 is a refreshing take on foldable phones, and I’m all for it.
Microsoft’s latest progress report details much-needed Windows 11 improvements in reliability, performance, stability, and usability. But here’s what else I see.

Yet another AI model has escaped from a cybersecurity test lab: This time, it’s the Chinese company Moonshot’s Kimi K3 model on the run. Frontier Security spotted that Kimi K3 had found a loophole in the UK AI Safety Institute’s test environment for AI models performing cybersecurity tasks. The news follows similar exploits by models…
An autonomous AI agent powered by a combination of OpenAI models escaped an isolated cyber-capability evaluation environment, reached the public internet, and conducted a multi-stage intrusion into Hugging Face’s systems. The models included GPT-5.6 Sol and a more capable internal research prototype operating with reduced cyber refusals and without the production safeguards normally used to…

Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the SaaS/AIpocalypse. The…

The U.S. Coast Guard said it is monitoring the aftermath of a cyberattack that disrupted gate operations at all three of North Carolina’s port facilities this week, though it offered few details as the investigation into the breach continues. A Coast Guard spokesperson told CyberScoop that the branch’s IT unit was coordinating with partner agencies…
The Pixel 11 may cost more, but Google’s software advantage may make it worth it for you.

This week’s cybersecurity landscape was shaped by rapidly expanding AI risks, attacks on trusted developer workflows, actively exploited enterprise software, and costly data breaches. Research into rogue agents, prompt injection, passkeys, and offensive AI showed why governance must keep pace with deployment, while incidents involving npm, hotel networks, remote monitoring tools, and sensitive public-sector data…
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. […]

Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users. The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder. Notetaker starts recording with…

A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars. Industry sources have identified Moucka as one of the…
The updates were unexpected. Apple must have considered this flaw serious enough to warrant an immediate fix.
What will the MSP of the future look like as AI takes over more routine IT work? In this episode of Channel Insider: Partner POV, Netrio CEO Mark Clayman joins Victoria Durgin to discuss how artificial intelligence is changing managed services, customer expectations, IT service delivery, and the skills MSPs will need to compete. Clayman…
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,
OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.

Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff Dean who is leaving to work at a start-up. The role will enable Hassabis to “put his full attention on actively shaping the future of AGI,” or artificial general intelligence, Alphabet CEO…

Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform and closed the…
No AC? Me neither. Here’s how to keep yourself and your home cool during a heatwave.
Wi‑Fi 7 is rapidly moving out of the lab and into American living rooms, with data from Ookla showing US usage is growing fast.
Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to…

A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it.…
Plus: Explosive drone at German airport marks new threat for Europe, and Meta AI hacks add to concerns over rogue bots.

Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. “The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of…

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and
On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — unknowingly installed malicious code. A threat actor group known as TeamPCP had compromised the PyPI distribution pipeline and pushed malicious versions 1.82.7 and 1.82.8 to the package index. The payload was subtle: a .pth file,…

OpenAI has updated GPT-5.6 Sol, the model behind ChatGPT for Plus and Pro subscribers, and pushed a new model, GPT-5.6 Luna, out to everyone using the free tier. The company is also removing the rate limit on text conversations for free users, allowing them to keep chats going without waiting for the limit to reset.…
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices

AI-generated vulnerability patches still heavily depend on human review, particularly the ones involving security-sensitive code, according to a research. Researchers from 1Password have disclosed an internal evaluation that found AI-generated fixes frequently overlook broader concerns such as architectural intent, business requirements, security implications, and long-term maintainability, despite being syntactically correct. “We studied what happens when…
– Large fleet operators could save $4.5 million annually by switching to electric charging Electric depot charging can cut equivalent diesel costs by more than 70% – Ongoing…

The financial impact of a data breach is substantial for any modern business, regardless of industry or size. IBM’s latest Cost of a Data Breach report discovered that, from March 2025 to February 2026, the average cost of a data breach rose to $6 million, up 35% from $4.44 million a year earlier. The 2026…

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own coding-agent repositories. On OpenAI’s, it was enough to hijack the next agent run. Novee Security ran the attack against each vendor’s agent in the configuration that the vendor ships by…
Glasses have always done more than help people see clearly.
UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack of “modern” logging: shells. Most shells provide an historization of the typed commands through a flat file in the $HOME directory (ex: $HOME/.bash_history). They suffer of multiple problems: History is stored…