
Cloudflare, Inc. NYSE: NET, the leading connectivity cloud company, today announced it will launch Cloudflare OS, an open source AI workspace that runs on Cloudflare’s global…

Omani conglomerate gains greater control over its IT roadmap, avoids migration pressure and funds AI and growth initiatives
Static residential proxies and ISP proxies are often mentioned together because they both provide stable IP addresses with excellent performance. However, despite their similarities, they are built differently and serve different use cases. If you’re involved in web scraping, market research, SEO monitoring, ad verification, account management, cybersecurity testing, or anonymous browsing, choosing the right…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
While hacks have raised safety alarms, researchers said their experiment could protect against drug-resistant bacteria and save lives.

In this post, I will show you the best rotating proxies for web scraping in 2026. As businesses continue to rely on data-driven decisions, web scraping has become an essential technique for gathering publicly available information from websites. Whether you’re monitoring competitors, tracking product prices, conducting market research, or collecting SEO data, the quality of…

Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format. The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open…

Customers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum validity drops to 100 days. By March 2029, it lasts for 47 days. For an…
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.

Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becoming harder to attack? That question sits at the center of a growing problem. Security programs have…

Samsung is starting August with a security sweep that patches dozens of flaws across Galaxy phones and tablets. The company has published details of its August 2026 Security Maintenance Release (SMR), which addresses 56 security vulnerabilities affecting eligible Galaxy smartphones and tablets running Android 14, Android 15, and Android 16. The update includes 38 Android…

Vectra AI has launched Vectra AI Pro, a new offering designed to provide what the company calls “trusted signal intelligence” for security operations centers (SOCs) adopting AI-powered workflows. Announced at Black Hat USA 2026, the platform continuously correlates network, identity, cloud, SaaS, SASE, and endpoint telemetry into a unified view of attacker behavior. Behavioral intelligence…

Samsung wants to shrink one of AI infrastructure’s biggest bottlenecks: the distance between processors and memory. At FMS 2026 in Santa Clara, California, the company previewed zHBM and zNAND-O concept architectures, introduced its 400-plus-layer V10 BV-NAND design and outlined a roadmap spanning HBM4E, HBM5 and enterprise storage. Samsung says the technologies could increase bandwidth, capacity…

The AI industry is securing the ecosystem through open collaboration. NVIDIA and the Open Secure AI Alliance have drafted the Shared AI Findings Exchange (SAFE) framework and introduced several open-source tools to champion AI security. The SAFE RFC document proposes a framework for reporting, collaboratively analyzing and recommending operational guidance after breaches. Additionally, the alliance…

Senators from both parties Thursday probed Trump administration officials about whether federal agencies and foreign governments are coordinated enough in the battle against scammers, something witnesses told the Foreign Relations Committee they were working to remedy. At least 13 federal agencies have authorities to counter scams, raising questions about whether someone needs to be in…
Google is set to announce its Pixel 11 series phones – here’s what we know.
The Pixel 11 lineup isn’t bringing drastic changes, but the incoming additions will still have fans excited.

Security researchers Talal Haj Bakry and Tommy Mysk have identified three request paths involving Apple’s browser and authentication technologies that can bypass proxy protections and expose a user’s real network information. The flaws affect Apple’s iCloud Private Relay, a paid iCloud+ feature designed to hide users’ IP addresses and DNS information while browsing in Safari.…

Meta is entering the AI coding race with a familiar weapon: lower prices. Released in beta, Muse Code is a terminal-based coding agent powered by Muse Spark 1.2. Meta says it can plan and write code, then test changes across large repositories. Muse Code gives MSPs and systems integrators another option aside from Claude Code…
A new scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems. The findings, published Wednesday by Forescout’s Vedere Labs, show that direct internet access to equipment used in water and wastewater operations remains common despite years of warnings…

Security teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongside identity, network, and application security data in a single layer. When a guardrail blocks a prompt injection attempt or redacts…
Former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.

For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assumption might not be entirely accurate anymore (if it ever really was).…

More than 250 ClickFix domains are using browser fingerprinting to hide macOS malware lures from security scanners. Microsoft Threat Intelligence said the campaign checks visitors for signs of a genuine Mac before serving malicious instructions that can lead to the download of Atomic Stealer or MacSync. Crawlers, sandboxes, and researchers may instead receive blank pages…

A longtime cybercriminal was sentenced to 16 years in prison for creating and running Ransom Cartel, a ransomware strain linked to attacks on at least 18 companies between 2021 and 2023, the Justice Department said Wednesday. Maksim Silnikau, a Belarusian national, actively participated in Russian-speaking cybercrime forums since at least 2005, and was a member…
As part of its Black Hat USA 2026 research, Barracuda released a PoC demonstrating how attackers could use AI-enabled email assistants to escalate a compromised employee account into a full-scale BEC attack. Researchers said the greatest risk is that AI assistants accelerate reconnaissance, phishing, and fraud using compromised accounts. The attack used Microsoft Copilot, though…

Welcome to this week’s edition of the Threat Source newsletter. Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues. Recent reports of offensive AI agents “escaping” their sandbox environments…

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which manages…
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protection against real-world LLM attacks. The post Photos: Black Hat USA 2026, part…
The Pixel 11 may cost more, but Google’s software could still make it a better value than Samsung’s phones.

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. “These vulnerabilities were…

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history…

An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files,…
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux…
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven financial crime detection platform on Amazon Web Services (AWS). NICE Actimize, a leading provider…
Here’s a five-stage action plan for confronting insider risk from noted cybersecurity executive Phil Venables.

Cloudflare is opening up the AI workspace it built for its own employees. Now, partners can use the same foundation to create enterprise agents, automate workflows, and build small internal apps. The platform connects AI tools with an organization’s internal knowledge, applications, and security controls. Employees can use the browser-based workspace to research information, create…

The rumors turned out to be true. Anthropic says it’s building an in-house team to design custom AI chips for Claude, giving the company more control over the hardware behind its AI models. It’s also not blowing up its existing infrastructure. Anthropic says chips from AWS, Google, Nvidia and AMD will remain part of the…

A new study from 1Password’s Off-by-1 Labs suggests that organizations should be cautious about relying on large language models (LLMs) to autonomously remediate software vulnerabilities. After evaluating more than 6,000 AI-generated security patches across six recently disclosed, high-impact vulnerabilities, researchers found that fully successful patches were the exception rather than the rule. Key takeaways of…

A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia…
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.…

AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court. It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor,…
The UK’s data protection regulator criticized the Metropolitan Police Service (MPS) for significant data handling failures, including sharing a stalking victim’s new contact details with her abuser and a separate incident exposing the email addresses of 18 individuals connected to Parliament.
Salesforce’s enterprise agentic AI platform, Agentforce 360, received approval from the Defense Department to securely handle high-sensitivity workloads, including Controlled Unclassified Information (CUI) and unclassified National Security Systems (NSS) data.
The NVM Express consortium released updates to its 11 specifications, introducing significant advancements in security and virtualization for solid-state drives (SSDs).
The LG C6 is a powerful refresh of the brand’s flagship OLED TV, and right now at Best Buy, you can get the 65-inch version for 26% off.

Western Union is one of the most used means of international money transfer. Find out how to get money back from a scammer on Western Union in this post. Scams take various forms, but the most popular scam often joked about is the “Nigerian Prince” email scam, which still rakes in over $700,000 in illegal…

In this post, I will discuss common dating website scams and how to avoid them. The image of a dating scam as a clumsy stranger with a broken keyboard is out of date. The people running these schemes now build profiles with deliberate small flaws, match a target’s tone, and wait weeks before asking for…

Three WebKit mechanisms have been discovered to bypass Apple’s iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo’s proxy, Tor-on-iOS proxy setups, and so on. Private Relay is a VPN-like system for Safari on iOS which is meant to prevent websites from viewing the visitor’s IP address and location.…
With the Galaxy Z Fold 8 as my main driver, these two accessories are must-haves (and one isn’t even made by Samsung).

A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab) While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a…
Google is set to release the Pixel 11 soon, and although my Pixel 9 Pro is two years old, I won’t be upgrading for five specific reasons.

A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative access. Multifactor authentication (MFA) was enforced broadly, vulnerability scanning was routine, and annual penetration tests were part of the organization’s broader security…

One of Meta’s AI models hacked into another company’s systems during a cybersecurity evaluation after a testing misconfiguration gave it internet access. Facebook’s parent company told the BBC it is investigating and plans to publish more information once it has established the facts. Recent incidents involving OpenAI and Anthropic have intensified scrutiny of whether cyber-capable…

Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter? For a global investment firm operating across 18 locations, that question became…
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) on going from vulnerability disclosure to autonomous remediation at machine speed. Jeremiah Grossman and Robert…
Security researchers have disclosed critical vulnerabilities affecting AI coding agents from Anthropic, Google, and OpenAI, demonstrating how attackers could compromise automated development workflows through a single untrusted GitHub issue. According to the research presented by Novee at Black Hat USA 2026, the flaws were found in the vendors’ own repositories running their default configurations. This…

Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center of a series of disclosures involving the industry’s leading AI labs. During a “capture-the-flag” test…

The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat landscape faced by the DIB. Updated CMMC guidance issued in…
Adobe’s new plugin works both in Work and Codex, and is available today in ChatGPT.