Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. […]
Global Security News
KillSec Ransomware Group Dismantled, 16-Year-Old Suspected Admin Arrested
An international police operation has disrupted the KillSec ransomware group, with three suspects arrested, five servers seized and…
Global Security News
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024, Europol and the Justice Department said Thursday. Investigators said the alleged leader of the group is 16 years old, but declined to name them. One of the group’s…
Global Security News
Microsoft says threat actors are ahead in the early AI race
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. […]
Global Security News
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Collaboration with industry is key to balancing AI security risks and benefits, as well as staying ahead of China and other adversarial nations, National Cyber Director Sean Cairncross said Thursday. The Trump administration is facing pressure from some quarters of Capitol Hill and even some artificial intelligence executives to establish regulations or embrace legislation to…
Global Security News
Can AI Run in Space? Google Is About to Find Out
A satellite containing several of the company’s AI chips launched into orbit.
Global Security News
DeepSeek, Huawei Expand Software Support for Ascend AI Chips
DeepSeek is expanding its work with Huawei, releasing open-source software designed for the Chinese tech company’s Ascend processors. DeepSeek’s Sept. 30 releases and updates extend Ascend support across six open-source projects covering low-level operations needed to build and optimize AI workloads. The release moves their collaboration further into the software layer around AI infrastructure. For…
Global Security News
Operation KillSwitch: Police Dismantle KillSec Ransomware Group
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more…
Global Security News
Give yourself room to be human
Welcome to this week’s edition of the Threat Source newsletter. Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook. Beyond that, though, can I say that I’m glad fall is here…
Global Security News
Temasek-Backed Vertex Japan Invests in Digital Trading Cards Startup Heartbeats
Temasek-backed Vertex Ventures Japan has invested in Heartbeats, a Tokyo-based digital trading cards company, the latest in a series of bets aimed at turning Japanese startups into global unicorns.
Global Security News
Fake xStocks, Pendle, and other sites bait crypto users with rewards votes
We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x…
Global Security News
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site.…
Global Security News
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the…
Global Security News
OpenAI Parts Ways With Researchers Who Allegedly Shared Confidential Information
The AI startup is in the throes of responding to a host of incidents in which its AI models went rogue.
Global Security News
Japan AI Data Center Push Could Reach $140B as Dell, JERA Start $15B Build
Japan’s next major AI infrastructure push is starting with a $15 billion data center and could eventually grow into a much larger national buildout. Dell Technologies, Japanese power producer JERA, and UK-based AI infrastructure developer RHAELM have signed a memorandum of understanding to develop a standardized model for AI data centers across Japan. The first…
Global Security News
Wiz Launches MSP Program for Managed Cloud and AI Security
Managing more cloud security customers can mean more consoles, repeated policy work, and less time to investigate risks. Wiz wants to reduce that overhead for managed service providers. The company announced its Wiz Partner Alliance Managed Service Provider Program on September 28, giving partners centralized customer management, flexible billing, and dedicated support to deliver services…
Global Security News
New CloudSyncD macOS Backdoor Uses Fake Zoom Installer to Steal Passwords
CloudSyncD macOS backdoor uses a fake Zoom installer to steal Mac passwords, bypass Gatekeeper and connect infected devices to remote C2 servers.
Global Security News
WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the “SC_” markers present in the injected content. Sucuri has described the malware as a “self-healing…
Global Security News
Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation
Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges
Global Security News
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed “Operation KillSwitch” seized the KillSec ransomware gang’s data leak site and servers, led to three arrests, and identified a 16-year-old as the group’s alleged administrator. […]
Global Security News
Why Mobile Device Management Needs Its Own Threat Model
Allowing employees to use their own phones for work sounds simple. Deciding how much control IT should have…
Global Security News
Memory squeeze set to tighten through 2028, Micron says
The global memory shortage that has driven up the cost of servers, storage and PCs through 2026 will get worse in 2027 and 2028, according to memory maker Micron Technology. “We expect memory and storage supply-demand conditions to be much tighter in calendar 2027 and 2028 than they were in 2026,” CEO Sanjay Mehrotra said…
Global Security News
AI policy circles targeted in China-linked phishing operation
A China-aligned cyber espionage group targeted U.S. artificial intelligence policy experts through phishing emails that impersonated prominent officials, economists and an employee of AI company Anthropic, according to research released Thursday by Proofpoint. The campaigns, which the cybersecurity company attributed to a group it calls TA419, sought access to cloud accounts held by people at…
Global Security News
Shadow AI explained: The work shortcut that could leak your company’s secrets
Using an AI chatbot, assistant, or browser to speed up your work is tempting, but doing it without your employer’s knowledge can put sensitive data at risk. You’re swamped, so you paste a long email thread into a free chatbot and ask for a summary. It works, it saves an hour, and nobody notices. But…
Global Security News
The Day-One Hole in Zero Trust Architecture
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before credentials, MFA methods, and access are issued. […]
Global Security News
China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders
TA419 posed as AI policymakers and economists to phish US AI policy experts’ Microsoft 365 accounts
Global Security News
16-year-old suspected leader of KillSec ransomware group arrested
A 16-year-old is suspected of being the main operator of KillSec, a ransomware group that Eurojust says is responsible for almost 1,000 attacks worldwide. Seizure notice (Source: Eurojust) According to Eurojust, KillSec has been active since 2024. The group got into organizations’ systems by exploiting poorly secured access, particularly access linked to cloud storage. “Once…
Global Security News
DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval
DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf. The capability gives security teams policy enforcement, audit visibility, and runtime security over coding agents such as…
Global Security News
Kiteworks patches max severity code injection vulnerability
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. […]
Global Security News
Exabeam brings AI-assisted security investigations to data that must stay on-premises
Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven investigation, execution, and governance. Analyst workflows alone can’t keep pace with machine-speed threats or the growing complexity of goal-driven AI agents and autonomous workflows. The future of the SOC is agentic. For…
Global Security News
Google makes Gemini 4 AI model available to a trusted few
Google has unveiled a new frontier AI model after months of delay. Gemini 4 Argon is designed to handle complex, long-horizon workloads spanning software engineering, enterprise knowledge work such as legal and financial analysis, and cybersecurity. But only a few organizations can get their hands on it for now. Argon is “rolling out to a…
Global Security News
RadarFirst helps teams investigate AI bias, data exposure and unintended actions
RadarFirst has announced the general availability of Radar AI Incident Management, a purpose-built solution that helps organizations investigate, manage, and document AI-related incidents. As organizations deploy AI across customer experiences, employee workflows, business operations, and decision-making processes, adverse events can create risks that span privacy, security, legal, compliance, and product teams. Harmful outputs, biased outcomes,…
Global Security News
Cisco SD-WAN Manager hit by zero-day admin access attack
Cisco’s SD-WAN management software has been letting some attackers walk through an authentication check without having to prove who they are. The company says it has now fixed the flaw that was allowing it. The affected platform, Cisco Catalyst SD-WAN Manager, is used to configure and operate software-defined network deployments. Cisco said in an advisory…
Global Security News
Inside Gemini 4 Argon, the model Google is testing on its own infrastructure first
Google unveils Gemini 4 Argon, a frontier AI model built for coding, enterprise work, and autonomous cybersecurity defense, rolling out to trusted testers. Google announced Gemini 4 Argon, and it’s not going straight to the public. It’s rolling out first to a set of trusted cyber defenders through what Google calls the Fairwind Program, which…
Global Security News
Fortreum Completes FedRAMP 20x Low, Moderate Pilots
Fortreum has completed FedRAMP 20x pilot assessments with cybersecurity provider InfusionPoints at both the Low and Moderate impact levels, giving the companies an early role in testing the federal government’s shift toward automation-first cloud security assessments. The companies completed the Class B (Low) Phase I pilot in July 2025 and the Class C (Moderate) Phase…
Global Security News
CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer
CloudSyncD uses a fake Zoom installer to phish Mac passwords and launch a two-stage backdoor
Global Security News
Sophos uses agentic AI to show businesses which security fixes deserve funding
Sophos has launched Sophos CISO Advantage, an agentic AI-enabled solution that connects security operations to security strategy. The solution gives organizations a picture of their cyber risk, a prioritized plan to reduce it, and measurable proof of progress, in plain language that business leaders can understand, fund, and act on. Sophos CISO Advantage defines a…
Global Security News
ServiceNow launches standalone AI service desk to provide support in Teams, Slack, and email
ServiceNow has a new take on the service desk: Flow by ServiceNow, a standalone AI product that allows users to get help via chats in Microsoft Teams, Slack, or a Flow web app, or by email, rather than having to leave what they’re doing to open a helpdesk ticket. Flow can be up and running…
Global Security News
Google Rolls Out New AI Model Gradually Amid Safety Concerns
Plus, FTC opens investigation of Anthropic and OpenAI
Global Security News
Threat Coverage Digest: New Malware Reports and 1,100+ Detection Rules
September saw an expansion of detection coverage across network, file, and behavioral activity, providing analysts with additional visibility into suspicious activity. ANY.RUN added 76 behavior signatures, 16 YARA detections, and 1,098 Suricata rules, strengthening coverage across malware activity, suspicious files, and network communications. These updates provide SOC and MSSP teams with additional evidence during investigations,…
Global Security News
AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit
An agentic AI-powered attack that hit the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21 exploited two zero-day vulnerabilities in Zammad, an open-source helpdesk and customer support ticketing system. “Used together, [the two flaws] allowed the attackers to hijack sessions, run code remotely and escalate privileges from the Zammad user to root, in seconds,…
Global Security News
CVE-2026-84782: High-Severity OpenSSL DTLS Flaw Exposes Heap Memory and Enables DoS
OpenSSL has released security updates addressing 14 vulnerabilities, including a high-severity flaw that could expose sensitive heap memory or crash applications relying on Datagram Transport Layer Security (DTLS). Tracked as CVE-2026-84782, the vulnerability stems from improper handling of handshake message retransmissions and carries a CVSS score of 8.2. Disclosed on September 29, 2026, the issue…
Global Security News
Legit Security extends automated fixes to vulnerable open-source dependencies
Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage. The expansion addresses a growing gap in application security: as AI-generated code accelerates software delivery, most modern codebases…
Global Security News
One year later: Sovereign AI and the fight for choice
It’s Birthday Week, when we traditionally ship presents to the Internet. This year, two of them come from Europe: EuroLLM, which covers all 24 official EU languages, and Apertus, Switzerland’s fully open model, trained on more than 1,500 languages. Both were built by public universities and research institutions. Both are coming to Workers AI, and…
Global Security News
CVE-2026-76504: Critical Cisco SD-WAN Manager Zero-Day Exploited in the Wild
Cisco has disclosed another actively exploited zero-day vulnerability affecting its Catalyst SD-WAN infrastructure. The latest flaw, tracked as CVE-2026-76504, is a critical authentication bypass in Cisco Catalyst SD-WAN Manager that could enable an unauthenticated remote attacker to gain administrative access to an affected system. The vulnerability carries a CVSS score of 9.8, with Cisco confirming…
Global Security News
Why Trusted IT Tools are Becoming a Bigger MSP Security Risk
RMM abuse is emerging as one of the most immediate cybersecurity risks facing managed service providers and their customers, with Huntress reporting a 277% year-over-year increase in 2025 and involvement in 45% of endpoint-related incidents during the first quarter of 2026. Those findings are part of Huntress’ new “Tragic Quadrant” research, which ranks cyberattack tactics…
Global Security News
Sophos CISO Advantage Gives MSPs New vCISO Opportunity
Sophos has launched CISO Advantage, an AI-enabled cybersecurity offering designed to help organizations assess risk, prioritize remediation, and track security progress while giving MSPs a more structured way to deliver virtual CISO services. The launch comes as more customers look to managed service providers for strategic security leadership. Sophos’ 2026 MSP Perspective Report found that…
Global Security News
Virtuozzo Launches Global Partner Program
Virtuozzo has launched V/Partner, a new global partner program for distributors, resellers, and service providers, adding commercial incentives, training, marketing support, and technical resources as the infrastructure software vendor looks to expand partner-led AI and cloud services. Partners can resell Virtuozzo, integrate the platform into customer environments, or use it as the foundation for managed…
Global Security News
Warlock Ransomware Hits Large Spanish, Portuguese Orgs
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
Global Security News
Cribl SIEM: What It Is, How It Works, and Where It Fits in Your SOC
For years, Cribl was known as the company that sits between your data sources and your security tools, shaping, routing, and reducing telemetry before it reaches its destination. Now the question security teams are asking is different: Cribl SIEM, what does it actually include, and does it change how we run detection and response? This…
Global Security News
Pentagon breach exposes personal data of more than 3 million people
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of people that hackers gained access to their personal data. The breach affects 2.76 million living individuals, a group that can include current and former defense personnel and their dependents, along with 294,000 deceased individuals, a Defense Department official told CNN. Established in 1974, DMDC…
Global Security News
Public PoC Released for Apple CoreGraphics Zero-Day CVE-2026-86950
Apple patched a CoreGraphics zero-day that may have been exploited in targeted attacks. A public PoC for the flaw is now available. Apple patched a zero-day vulnerability, tracked as CVE-2026-86950, in CoreGraphics that attackers may have exploited to target specific individuals. The flaw is an out-of-bounds write that can lead to arbitrary code execution when…
Global Security News
Securing Water and Wastewater Operational Technology Environments
Recent cyberattacks on the U.S. water and wastewater systems (WWS) sector are highlighting the escalating threat to our nation’s critical infrastructure and the practical challenges of securing it. These incidents underscore an important challenge: the connectivity that utilities depend upon must be designed and operated with security as a core priority rather than a secondary…
Global Security News
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing. Somebody else raises the change-freeze calendar. The finding gets an exception,…
Global Security News
Armadin raises $255.5 million to expand AI offensive security platform
Armadin has raised $255.5 million in Series B funding co-led by Andreessen Horowitz (a16z) and Accel that brings the company’s valuation to over $2.5 billion. The round includes participation from new investors Bain Capital Ventures (BCV) and Redpoint. Existing investors 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures also returned, reflecting their…
Global Security News
Microsoft enables Windows settings backup by default for orgs
Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. […]
Global Security News
FBI tells ShinyHunters members to turn themselves in, after arrest of alleged leader
The FBI has a very simple message for the ShinyHunters gang: give yourselves up. On Tuesday, FBI cyber division assistant director Brett Leatherman released a video, thanking the Dutch police for arresting a 24-year-old man they believe to be a member of the group, and and who is separately suspected of attempting to arrange two…
Global Security News
ShinyHunters suspect arrested, and is now investigated over alleged murder plots
An alleged key figure in the ShinyHunters cybercrime group has been arrested in the Netherlands, and – in a sinister twist – the 24-year-old suspect is also being investigated for attempting to arrange two murders. Read more in my article on the Hot for Security blog.
Global Security News
Malwarebytes earns another Top Product award in independent testing
Every few months, Malwarebytes gets a chance to test its mettle against real-world threats in an independent laboratory setting. And the latest round of results gives us plenty to celebrate. Malwarebytes earned a perfect 18 out of 18 and received another Top Product award from AV-TEST. We also achieved Level 1 Certification from MRG Effitas,…
Global Security News
Pentagon breach exposes Social Security numbers and military records of millions
The US government is alerting millions of people that their personal information was stolen during a breach of the Pentagon’s personnel records at the Defense Manpower Data Center (DMDC). The DMDC is a central US Department of Defense (DoD) organization that manages personnel records, ID credentials, and benefit entitlements for military and civilian staff, veterans,…
Global Security News
OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A “core cluster of the activity,” going back to the first week of July, has been attributed to individuals associated with Moonshot AI, a Chinese AI company based in…
Global Security News
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with
Global Security News
New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)
For the fifth time this year, Cisco revealed attackers have exploited a vulnerability (CVE-2026-76504) in its SD-WAN solution in zero-day attacks. The vendor’s incident responders became aware of active exploitation of this vulnerability in September 2026, after getting pinged and resolving a Cisco Technical Assistance Center (TAC) support case. Cisco has yet to share any…
Global Security News
OpenAI Expands Codex With Always-On Vulnerability Hunting for GitHub
OpenAI is extending Codex from coding into continuous application security with Codex Security Cloud, a managed service built for connected GitHub repositories. Announced with the latest Codex updates, the research preview can run scheduled security scans in the cloud and is available to ChatGPT Pro, Business, Enterprise, and Edu customers. Teams can keep checks running…
Global Security News
Japanese Car-Sharing Site Times Car Data Breach Affects 6.6M Accounts
Times Mobility says a data breach exposed data linked to 6.6 million accounts, including 1.6 million identity records with driver’s license images and documents too.
Global Security News
The Fine Art of Frustrating the Adversary
For Cybersecurity Awareness Month, eight Cisco Talos researchers share practical ways defenders can frustrate adversaries at different stages of an operation. Deception techniques such as honeypot accounts, false infrastructure, and tarpits can slow adversaries down while giving defenders earlier opportunities to detect their activity. Behavioral detections, tighter control of legitimate remote-management tools, and clear boundaries…
Global Security News
MongoDB launches Atlas Infinite for AI-Scale Demand, and MongoDB 9.0, the best version ever built
Atlas Infinite, now in Public Preview, is a new deployment option within Atlas built for extreme elasticity, absorbing unpredictable demand spikes in real time, cutting time to…
Global Security News
Some car apps are slipping owners’ data to big tech companies
The app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers tested 21 vehicles and 30 carmaker apps and found some sending vehicle identification numbers (VINs), email addresses, phone numbers or location data to advertising, tracking and analytics companies. The work…
Global Security News
Hackers stole Pentagon personnel records of over 3 million people
The Pentagon’s Defense Manpower Data Center (DMDC) is notifying millions of military service members that hackers stole their data after breaching the Pentagon’s human resources management system in October 2025. […]
Global Security News
AI Threats Top Cybersecurity Preparedness Gap, PwC Finds
PwC finds global security leaders are most concerned about attacks on AI systems
Global Security News
Samsung Bets $1 Billion on Nvidia-Backed AI Infrastructure Firm
Samsung is putting $1 billion behind the physical infrastructure needed to keep the AI boom running. Six Samsung affiliates are investing a combined $1 billion in Helix Digital Infrastructure, the KKR-created company backed by Nvidia and other major investors. The commitment adds to more than $10 billion already committed to Helix as the company targets…
Global Security News
Who owns AI risk at work? Business and tech leaders can’t agree, PwC survey finds
PwC research highlights a growing need for someone to own AI. Is an AI chief the answer?
Global Security News
Why AI agents are like the dog that pushed kids into the Seine
There is an interesting story about a French dog on the banks of the Seine river that helps us understand misbehaving AI agents. The dog is trained to save children from drowning. He succeeds and is rewarded, becoming an overnight sensation. He saves another child a week later. Not long after, someone witnesses the dog…
Global Security News
Losing gamblers pushed to bet more by DraftKings’ AI, report says
Two separate investigations have raised concerns about betting site DraftKings’ marketing to target problem gamblers, including its use of AI. On September 19, the New York Times reported that the company’s machine learning model targeted people who were more likely to respond to betting promotions by gambling and losing more money. The model crunched data…
Global Security News
U.S. CISA adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst SD-WAN Manager flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Catalyst SD-WAN Manager flaw, tracked as CVE-2026-76504 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability resides in Cisco Catalyst SD-WAN Manager’s…
Global Security News
AI Agent Chains Zammad Zero-Days To Take Over DIVD Systems in Seconds
DIVD was breached through two Zammad zero-days that let an AI agent reach root in seconds, steal data and pivot to other services before being stopped. The Dutch Institute for Vulnerability Disclosure, a nonprofit organization of volunteer security researchers whose whole job is finding and responsibly disclosing vulnerabilities in other people’s software, just disclosed that…
Global Security News
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. “It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,” Koray Kavukcuoglu,
Global Security News
Sentinel Envelope Plus adds software protection without source code changes
Thales has announced Sentinel Envelope Plus, a new addition to its Sentinel Envelope software protection solution that significantly hardens compiled applications against AI-assisted reverse engineering, automated zero-day vulnerability discovery, and automated exploit generation. Sentinel Envelope Plus applies multiple layers of protection to software applications, without requiring source code changes or any special compilation environments. AI-assisted…
Global Security News
MI5 Warns Over 100 Academics Helped China’s Espionage Plans
MI5 has issued a rare warning to UK academics contributing to the China General Technology Research Institute
Global Security News
Metamask discloses security incident affecting its infrastructure
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. […]
Global Security News
BlackFog adds prompt protection and governance for agentic AI
BlackFog has announced the launch of ADX Vision 2.0, expanding its AI security capabilities to help organizations govern and control the use of generative and agentic AI across the enterprise. As employees move from simply interacting with AI tools to deploying agents capable of making decisions and acting on corporate data, the security challenge for…
Global Security News
Amaysim to launch Apple iPhone 18 Pro Range, Watch Series 12 and Watch Ultra 4
Amaysim will offer Apple’s latest products including iPhone Duo, iPhone 18 Pro, iPhone 18 Pro Max, Apple Watch Series 12 select models and Apple Watch Ultra 4. iPhone 18 Pro…
Global Security News
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory…
Global Security News
Eylex named exclusive ANZ distributor for INVISIO communication systems
– Building on its longstanding history in mission-critical communications, Eylex is the exclusive in-country distributor for INVISIO’s full suite of tactical communications…
Global Security News
APAC organisations urged to accelerate quantum readiness as regulatory deadlines approach
World Quantum Readiness Day 2026 highlights growing urgency around post-quantum cryptography migration across Asia-Pacific.
Global Security News
Merge Technologies and Convergint Australia Announce Strategic Alliance to Strengthen AV, Workplace Technology and Security Capabilities
Merge Technologies is pleased to announce a strategic alliance with Convergint Australia, bringing together complementary capabilities across AV, workplace technology and…
Global Security News
ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications… I received a very simple phishing email: From: contact@mejuri[.]com To: Subject: EFT Wire Transfer Paid Invoice Receipt Dear Customer, Payment of $5745.65 was Received. Please click here to view your Order Information…
Global Security News
Many expect AI in the SOC to make entry jobs harder to get
A junior analyst in a security operations center, or SOC, has usually learned the job the slow way. You work the same phishing lure dozens of times, chase the same familiar malware pattern and write up the same case note at the end of the shift. Eventually you know what normal looks like, which is…
Global Security News
TechnologyOne launches Guide for students and a new generation of AI-powered experience
TechnologyOne has announced the availability of Guide for students, its new agentic AI for higher education, alongside a new generation of AI-powered experiences designed for…
Global Security News
Neara expands executive leadership team with new Chief Product Officer
International AI-product veteran brings enterprise expertise to power Neara’s next phase of growth.
Global Security News
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. “Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
Global Security News
Avanade appoints Ben Beath as Chief AI Officer to help guide organisations’ AI transformation
Founder and digital transformation leader will help Avanade and its clients move from AI adoption to realising its full value
Global Security News
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it’s responding to what it described as an “ongoing security incident” impacting part of its infrastructure. “We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors,” the software cryptocurrency wallet maker said. “At this time, we have identified no immediate threat to MetaMask wallets.”…
Global Security News
Zip AU unveils its ‘Inside the Wallet’ insights report for 2HFY26
Zip Co ASX: ZIP, the digital financial services company offering innovative, people-centred products, has today released its ‘Inside the Wallet’ insights report, unpacking the…
GeekGuyBlog
Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure
Global Security News
The vulnerabilities AI finds are the ones attackers want
Attackers exploited a flaw found by an AI research agent within four days of its public disclosure, and they are exploiting more vulnerabilities overall, according to new research by Google Threat Intelligence Group (GTIG). The researchers examined vulnerability disclosure and exploitation data from January 2025 to August 2026. Disclosures doubled, exploitation stays rare Monthly CVE…
Global Security News
AUSTRALIAN TELCOS READY TO ACTIVATE TEMPORARY DISASTER ROAMING AHEAD OF HIGH-RISK WEATHER SEASON
Australia’s three mobile network operators are ready to activate Temporary Disaster Roaming TDR from today to help keep regional and remote Australians safe, informed, and…
Global Security News
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue’s Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
Global Security News
Employment scam victims tripled at financial firms in 21 countries
Reported victims of employment scams more than tripled over the past 12 months at more than 370 banks and other financial institutions in 21 countries. The 258% rise outran every other scam type, while total reported scams across the same institutions grew 35%. Scams by the numbers (Source: BioCatch) Researchers at BioCatch, a fraud-detection vendor,…
Global Security News
Meet Buddy: The Bunnings AI assistant helping Kiwis D.I.Y. from anywhere
Bunnings has collaborated with Google Cloud to launch its AI-powered shopping assistant, ‘Buddy’, in New Zealand, giving Kiwi customers a new way to plan projects, discover…

