Anthropic’s models kept working around the rules on the live internet. The company published the cases. Anthropic released a report on unintended actions its Claude models took during evaluations and internal use. The cases involved real websites and real organizations outside the company. Anthropic says the impact was minimal, and it published them anyway. The…
Global Security News
Cyber exec arrested in case allegedly tied to ShinyHunters hackers
Canadian cybersecurity executive Edward Dubrovsky has been arrested in Pennsylvania in connection with alleged extortion activity that multiple reports have linked to the FBI’s ongoing crackdown on the ShinyHunters hacking group. […]
Global Security News
Silent Ransom Group Allegedly Extorted $207 Million Without Encrypting Files
Silent Ransom Group allegedly extorted $207 million from 27 law firms in six months using phone calls and social engineering, not encryption. Silent Ransom Group doesn’t rely on encryption. No malware payload, no locked files, just phone calls and social engineering aimed almost entirely at law firms, and apparently it works extraordinarily well. A new…
Global Security News
ARTEX AI, Claude agents used in cyberattacks on South Korean banks
The cyberattacks that shook the South Korean financial sector earlier this month were launched by a Chinese hacker using the ARTEX AI penetration testing suite and Claude agents. […]
Global Security News
Canadian cybersecurity executive arrested in federal extortion case
Federal authorities arrested a Canadian cybersecurity executive Thursday in Pennsylvania on charges of conspiracy of extortion, according to federal court records posted Friday. Edward Dubrovsky, 54, is a former chief operating officer and founder of CYPFER, a firm that helps organizations negotiate with ransomware operators. He is charged with conspiring to threaten the confidentiality of…
Global Security News
Criminal IP Introduces AITEM as the Next Evolution of Attack Surface Management
Traditional attack surface management helps organizations discover exposed assets, but visibility alone is not enough to address threats. Criminal IP introduces AITEM, an AI-powered approach that connects exposure discovery with investigation, risk prioritization, and response. […]
Global Security News
OpenAI Makes Progress in Preventing AI-Driven ChatGPT Delusions
Mental-health experts offered advice on how the popular chatbot could ask better questions and distinguish among crises and other conditions.
Global Security News
FBI Arrests Ransomware Negotiation Firm Co-Founder in ShinyHunters Probe
FBI arrests Cypfer co-founder Edward Dubrovsky, now associated with CyberSteward, in the ShinyHunters investigation into the FBI jobs…
Global Security News
The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn’t
In environments studied for the 2026 State of Agent Security Report, roughly 1,280 third-party products now embed AI. About 282 of them sit behind single sign-on. The other thousand are invisible to identity infrastructure by default, not because anyone hid them, but because an identity stack can only govern what authenticates through it, and most…
Global Security News
The U.S. Army’s Desert Tech Test Shows Long Road to AI Warfare
A desert trial exposed equipment limitations and institutional hurdles in the Army’s push to modernize and keep pace with an AI-savvy adversary.
Global Security News
Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection Flaws
Anthropic on Friday said it’s cutting off live internet access for all its internal evaluations following the discovery of new incidents in which its artificial intelligence (AI) models exhibited misaligned behavior and targeted real websites. The AI company said it identified four broad categories of unintended model actions during evaluations and internal use of Claude…
Global Security News
Why TLP should not replace your internal information classification, (Sat, Oct 10th)
The Traffic Light Protocol (TLP)[1], which is now in its second incarnation, is a wonderful standard that enables one to easily communicate whether information may be shared further (and if so, how far). That being said, I’ve noticed a somewhat unfortunate trend in a number of organizations that try to fit TLP into a niche…
Global Security News
Ring’s new smart lock has a manual fallback that can’t lock you out – how it works
The brand just announced a smart lock with a manual ‘power dial’ that charges the device in case it dies.
Global Security News
US Sentences Empire Market Co-Creator Over $430 Million Criminal Marketplace
Empire Market co-creator Raheim Hamilton was sentenced to 40 years in prison for running a dark web marketplace linked to $430 million in illegal trades. The case against Empire Market shows how a dark web marketplace can become a major criminal business, bringing together drug trafficking, stolen credentials, personal data and hacking tools. “A Virginia…
GeekGuyBlog
ASOS Breach Highlights Vulnerabilities in Customer-Facing SaaS Solutions
Global Security News
The Desperate Hunt for AI Computing Power Is Upending Silicon Valley
Bitter rivals are forming alliances and executives are having to personally intervene over the scramble for resources to fuel the AI boom.
Global Security News
FBI Arrests Founder of Ransomware Negotiation Firm
Agents with the Federal Bureau of Investigation (FBI) on Thursday arrested the co-founder of a Canadian cybersecurity firm in connection with an investigation into the ShinyHunters hacking group that recently relieved the FBI of sensitive data on thousands of agents, multiple sources tell KrebsOnSecurity. The New York Times reported today that the FBI has arrested…
Competitive Reports
Okta Oktane 2026 Conference Report
Critical Takeaways, Technologies, Trends, and Case Studies Conference Dates: September 22-24, 2026Location: Caesars Forum, Las Vegas, NevadaAttendance: Over 4,000 attendees Executive Summary Oktane 2026 marked a pivotal moment in enterprise identity security, with Okta’s CEO Todd McKinnon announcing the Blueprint for the Secure Agentic Enterprise and forming the Blueprint Alliance. The conference demonstrated that AI…
business, Competitive Reports
Cybersecurity Mergers & Acquisitions Report (Oct 9, 2026)
Global cybersecurity M&A activity reached historic levels through the first three quarters of 2026, driven by demand for AI-native security, identity governance, and operational technology. Strategic platform vendors dominated transaction values, supported by several multi-billion-dollar megadeals and a sharp year-over-year surge in deal volume. Market dynamics shifted as non-cybersecurity buyers in finance, insurance, and data…
Global Security News
A DNS hygiene checklist for anyone who just inherited a Domain
Key Takeaways: – Take control of the registrar account and lock the domain before auditing individual records. – Verify that nameserver delegation matches your active DNS host…
Global Security News
ASOS Breach Reveals the Risks in Customer-Facing SaaS
The attack on the British retailer shows that compromising a single identity can lead to much deeper penetration of the corporate network.
Global Security News
Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
Hackers are abusing legitimate Bing search-result redirects as click URLs in Google search ads to direct users to fake Claude installers that deliver ClickFix attacks. […]
Global Security News
Deterioration AI is reshaping what counts as the medical record
Most patients and families assume that if a hospital’s AI predicted a downturn hours before it happened, the prediction is sitting somewhere in the chart, timestamped and easy…
Global Security News
Parallels Expands Partner Programs for MSPs and Resellers
Parallels is expanding its channel partner programs with a new Parallels Desktop Partner Program and a service-focused path within its Workspaces Partner Program, giving MSPs, resellers, and cloud providers new ways to qualify for incentives and support based on their business models. Parallels Desktop program introduces Authorized and Premier tiers The new partner program supports…
Global Security News
Why Australian marketing teams are bringing video in-house, and what an AI Ad Generator actually changes
Video demand across Australian marketing teams keeps climbing. Budgets, largely, do not. Wistia’s 2026 State of Video found companies producing more video than the year before,…
Global Security News
AI Adoption Outpaces Mac Management Recovery, Fleet Finds
Enterprise IT teams are increasingly using artificial intelligence to manage Apple devices, but new research suggests their ability to recover from configuration mistakes is failing to keep pace with AI adoption. A new report from device management provider Fleet found that 86% of surveyed Mac administrators allow AI-generated scripts or configurations to reach production devices…
Global Security News
US Suspends Green Card Labor Certifications for Microsoft, Adobe, Six IT Firms
Microsoft, Adobe and six major IT services companies face new restrictions on sponsoring foreign employees for permanent residency in the United States. The Trump administration on Thursday suspended the companies from the federal Permanent Labor Certification Program, known as PERM, accusing them of abusing employment-based immigration rules. The affected companies are Cognizant, Infosys, Tata Consultancy…
Global Security News
AI Scramble Drives Cybersecurity M&A Boom
Welcome to another gangbuster year for strategic M&A activity in cyber, with 117 deals announced in the latest quarter. What’s different: Many of the buyers are not your typical cybersecurity firms.
Global Security News
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. “Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC,” StepSecurity
Global Security News
4 ways Amazon’s new Alexa tablets eclipse the Fire line – starting with Google Play
Amazon just upped its game with new Android tablets for entertainment and work.
Global Security News
Germany Arrests Suspected Qilin Ransomware Leader After Japan Detention
Japan helped extradite a Russian suspect linked to Qilin ransomware to Germany, but the gang continued attacking victims after his arrest. Germany has arrested a Russian national believed to be a leading figure in the Qilin ransomware group, and Japan’s National Police Agency just put its own role in that arrest on the record. The…
Global Security News
Microsoft Warns Outdated Windows Devices Could Lose All Updates in 2027
Microsoft warns outdated Windows devices could lose access to all updates in 2027. Learn which versions are affected and what security teams should do.
Global Security News
MonsterCloud CEO Zohar Pinhasi Accused of Paying Hackers, Defrauding Victims
The DOJ accuses MonsterCloud CEO Zohar Pinhasi of secretly paying ransomware gangs for decryption keys while charging victims…
Global Security News
Anthropic Launches Free AI Security Scans for Open-Source Projects
Anthropic’s OSS Scanner offers free AI vulnerability scans for eligible open-source projects, with maintainers responsible for verifying reports and fixes.
Global Security News
GitHub Upgrades AI Secret Detection to Catch Hidden Passwords
GitHub’s new AI model spots passwords hidden in source code. See how its secret scanning works, which checks are in preview, and what security teams should do.
Global Security News
Microsoft Teams Is Getting a New Way to Spot Deepfake Impostors
Microsoft Teams plans to add third-party deepfake detection for meetings in November 2026. Learn how the warnings could help organizations spot AI impostors.
Global Security News
‘I use AI to do the things that I’m bad at’: Linus Torvalds on why it works for him
The Linux creator calls vibe coding ‘a wonderful way to find joy in programming,’ but not for running Linux development. (Finding bugs is OK.)
Global Security News
FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack
The FBI has arrested another suspected co-conspirator of ShinyHunters, FBI Director Kash Patel said on October 9 in a post on X. ShinyHunters is the extortion group that said in September it had breached the FBI’s jobs portal and stolen sensitive data on almost all FBI agents and job applicants. The FBI has not named the suspect, and…
Global Security News
What We Missed: FBI Strikes Back at ShinyHunters
In this video conversation, Dark Reading editors discuss some of the news they didn’t get a chance to cover, from the arrest of a suspected ShinyHunters operative to the compromise of a Pentagon-run data center.
Global Security News
Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. […]
Global Security News
FBI arrests another suspected ShinyHunters hacker after agency breach
The FBI has arrested another suspected member of the ShinyHunters extortion group believed to be involved in the recent breach of FBI systems, Director Kash Patel announced Friday. […]
Global Security News
Myriad360 Plans More Acquisitions After OEP Investment
Global systems integrator Myriad360 plans to accelerate acquisitions and expand its enterprise technology services following a majority investment from private equity firm One Equity Partners, CEO Jay Miley told Channel Insider. “I think by and large, the reason why we did this is that it’ll enable us to make more acquisitions,” Miley said. The investment,…
Global Security News
The Other Anthropic Founder Trying to Fix the Company’s ‘Woke’ Reputation
Tom Brown is leveraging his Republican ties and business savvy to win over Washington and secure the computing power Anthropic needs.
Global Security News
82% of Workers Avoid Reporting IT Issues, Report Finds
More than eight in 10 workers have decided an IT problem wasn’t worth reporting, according to new research from Buchanan Technologies, raising questions about how effectively businesses and their managed service providers measure IT support performance. The company’s 2026 IT Experience Gap Report found that 82% of surveyed workers have avoided reporting an IT issue,…
Global Security News
P7 DarkSword iOS Exploit Kit Adds Crypto Wallet Data Theft and Remote Commands
Cybersecurity researchers have disclosed details of a previously unseen variant of the DarkSword iOS exploit kit called P7 DarkSword. “Compared with the variants we usually observe, P7 reduces its on-device footprint, adds on-device keychain and crypto-wallet theft, and adds two way C2 communication with the attacker’s infrastructure,” iVerify said in a new report published Thursday.…
Global Security News
Security Threats Don’t Stop at the Office: Why Executives’ Families Need Training Too
Those closest to executives must match their security postures because the weakest link in a family becomes the entry point for attacks.
Global Security News
Lightwell project filters out 400 Java library vulnerabilities
Lightwell, the open-source security initiative set up by IBM and Red Hat, has identified more than 400 previously undiscovered vulnerabilities in widely used Java libraries — and now the companies are inviting customers to submit their own code dependencies to a new service, Lightwell Clearinghouse, for review. They’ll be looking for bugs such as the…
Global Security News
Bidding war over key component could eliminate third hard disk maker
What if the three remaining hard disk manufacturers became two? Seagate Technology and Western Digital control 90% of the market, according to market researcher TrendForce, with Toshiba picking up the crumbs. Seagate and WD both make their own magnetic drive heads, but Toshiba relies on a third party, TDK, which also sells to Seagate and…
Global Security News
Extreme Weather Is Everywhere Now—How to Prepare Your Home
Plus, how AI could help short-staffed fire departments, the silent electronic battleground shaping warfare, and the startup trying to double the world’s compute.
Global Security News
Pseudonymizing Log Data in Cribl Detect with the LogTotal Sanitizer Pack
Summary Cribl Detect, released on September 29, 2026, is a SIEM that runs on Cribl’s data platform. The data it stores and searches is ingested through Cribl Stream Routes and Pipelines, so a sanitization step in those Pipelines determines what analysts, AI-assisted triage, alert notifications and retained datasets can access. The Cribl LogTotal Sanitizer is…
Global Security News
Ransomware consultant said he would decrypt data, is accused of paying ransoms instead
The owner of a ransomware remediation company is facing trial for defrauding customers. Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud. Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying…
Global Security News
Ransomware consultant said he would decrypt data, is accused of paying ransoms instead
The owner of a ransomware remediation company is facing trial for defrauding customers. Zohar Pinhasi, also known as “Zack Silver” and “Zack Green,” has been arraigned in New York on wire fraud charges for allegedly defrauding clients of his ransomware remediation company, MonsterCloud. Pinhasi falsely claimed he could recover documents encrypted by ransomware without paying…
Global Security News
Germany arrests alleged core Qilin ransomware member after extradition
Germany has arrested a Russian national suspected of being a leading member of the Qilin ransomware group following extradition from Japan earlier this month. […]
Global Security News
OpenAI reports three new incidents of misalignment
OpenAI continues to report incidences of “misaligned” behavior by its AI models, with three new reports dropping on Oct. 2. However, they describe relatively minor issues compared to previous alignment reports and notices covering its attacks on Hugging Face, Rubygems, and a German programming wiki. The first of the new reports described how an instance…
Global Security News
Wikimedia Says Rogue AI Agents Abused its Platforms
Wikimedia says OpenAI agents performed unauthorized actions on its platforms, including edits to wikis
Global Security News
Samsung Galaxy S26 Hacked Again as Pwn2Own Researchers Find More Flaws
Samsung’s Galaxy S26 was hacked repeatedly at Pwn2Own Ireland. Learn what researchers found, why exploit chains matter and what users should know.
Global Security News
$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack
The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China’s state-sponsored hacking group, Hafnium. Read more in my article on the Hot for Security blog.
Global Security News
Citrix issues its weekly critical security patch for NetScaler ADC and NetScaler Gateway
For the third week running, Citrix has issued a critical security warning to customers managing their own NetScaler ADC and Netscaler Gateway instances, this time warning of a memory overflow vulnerability enabling denial of service or remote code execution. This week’s vulnerability affects ADC and Gateway when configured as a SAML (Security Assertion Markup Language)…
Global Security News
OpenAI’s Revenue Run Rate Is $20B Below Earlier Estimates. Here’s Why
OpenAI’s annualized revenue run rate reportedly approached $50 billion at the end of September, roughly $20 billion below an earlier estimate that drew attention across the AI industry. According to the Financial Times, the ChatGPT maker shared the updated figure with investors. The difference does not necessarily indicate a decline in sales. Instead, reporting suggests…
Global Security News
Android Phones Found With Malware Already Installed Before Purchase
Bitdefender uncovered Midnight Mimosa malware preinstalled on low-cost Android phones, enabling hidden ad fraud and raising device supply-chain security concerns.
Global Security News
A Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway Could Allow for Remote Code Execution
A vulnerability has been discovered in Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway that could allow for remote code execution. Citrix NetScaler ADC (Application Delivery Controller) is an enterprise networking platform and traffic management device designed to optimize, secure, and accelerate the delivery of web and cloud applications. Successful exploitation of the…
Global Security News
CVE-2026-107406: Critical NetScaler ADC and Gateway RCE Vulnerability
Citrix has disclosed CVE-2026-107406, a critical memory overflow vulnerability affecting NetScaler ADC and NetScaler Gateway appliances configured for specific SAML authentication roles. The flaw carries a CVSS v4.0 score of 9.5 and could enable an unauthenticated remote attacker to execute arbitrary code or trigger a denial-of-service condition on vulnerable systems. The vulnerability is particularly significant…
Global Security News
How to keep AI agents within their permissions
AI agents can use valid credentials to perform actions beyond their assigned permissions, creating risks that traditional access controls may not prevent. Token Security explains how organizations can enforce agent-specific policies without sacrificing autonomy. […]
Global Security News
Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning
Anthropic launches free OSS Scanner, using AI to find open-source vulnerabilities and help maintainers fix bugs before attackers exploit them. Anthropic is launching OSS Scanner, a vulnerability scanner for open-source code that costs nothing for projects to join. It grew directly out of lessons learned running Claude against real-world targets during Project Glasswing. The backdrop…
Global Security News
TP-Link Sued by Four More U.S. States Over Router Security and China Ties
Four more U.S. states sued router maker TP-Link Systems on October 6, bringing the total to five, with Texas filing a suit in February. Florida, Iowa, Montana and Nebraska allege the California company misled buyers about how secure its routers are and how separate it is from China. TP-Link denies the claims and says it will fight…
Global Security News
A New Mobile Telecom Battle May Be Brewing
Plus, neocloud Firmus Grid withdraws IPO
Global Security News
Ransomware Negotiator Angelo Martino Gets 70 Months for Helping BlackCat
Former ransomware negotiator Angelo Martino received 70 months in prison after secretly sharing clients’ confidential information with BlackCat attackers and participating in additional ransomware attacks.
Global Security News
Social Engineering AI Agents: The New BEC for 2026
As AI agents gain authority over business systems, attackers can manipulate them like business email compromise (BEC) victims.
Global Security News
Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as “fixed a bug that could lead to a crash,” with no CVE assigned and…
Global Security News
Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects
Anthropic on Thursday unveiled OSS Scanner as an opt-in vulnerability scanner to help secure the open-source ecosystem using artificial intelligence (AI). “It’s an opt-in service informed by our experience using Claude to find vulnerabilities during Project Glasswing,” Anthropic said. “Projects that join will receive thorough, periodic security scans by our strongest models at no cost.”
Global Security News
Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below – CVE-2026-105133 (CVSS v4 score: 5.5) – An improper authentication vulnerability in the checkSysPwd() function in the “com/ahsay/obs/api/ApiStructsAction.java”
Global Security News
Exposed Nvidia GPU monitors can reveal AI infrastructure secrets
A component of Nvidia’s GPU monitoring software that enterprises use to keep tabs on their AI training and inference infrastructure has been vulnerable to denial-of-service (DoS) and information disclosure attacks. The Nvidia DCGM Exporter contains an unauthenticated resource exhaustion vulnerability that could allow remote attackers to crash the monitoring service and potentially disrupt AI workloads…
Global Security News
Practical AI Integration for Modern Business Teams
Learn how businesses can use AI to reduce repetitive work, improve workflows, connect information, and support better everyday decisions.
Global Security News
Practical AI Integration for Modern Business Teams
Learn how businesses can use AI to reduce repetitive work, improve workflows, connect information, and support better everyday decisions.
Global Security News
Max severity SonicWall SMA1000 flaw now exploited in attacks
Attackers are exploiting a maximum-severity vulnerability in SonicWall SMA1000 appliances (CVE-2026-102255) that was patched on Tuesday, three days ago. […]
Global Security News
High-severity NVIDIA vulnerability lets unauthenticated attackers crash GPU monitoring
Hundreds of internet-exposed graphics processing unit (GPU) servers were open to a high-severity flaw in NVIDIA’s DCGM Exporter (CVE-2026-47483) that lets unauthenticated attackers crash the monitoring service and may disrupt AI workloads, according to Lava. Lava reported the flaw to NVIDIA, which rated it 8.2 on the CVSS scale and published a security bulletin on…
Global Security News
Flax Typhoon Exploits Five Flaws as CISA Sets October 11 Deadline for Federal Agencies
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below – CVE-2015-3306 (CVSS score: 10.0) – An improper access control vulnerability in ProFTPD that could…
Global Security News
Q3 2026 Sets New Record for Ransomware Attacks
Comparitech observed 2627 claimed ransomware attacks in Q3, with critical sectors like finance, technology, education and healthcare experiencing significant increases
Global Security News
The AI Velocity Paradox: Why Security Is Decades Behind AI Ambition
As enterprises race to deploy autonomous AI agents to accelerate business, a new report reveals they are tethered to security architectures built for a different era. The “Horizons of Identity Security” report from SailPoint highlights a critical “velocity paradox,” in which organizations invest in AI-speed business operations while continuing to rely on human-speed security controls,…
Global Security News
The Morning Risk Report: The Credit-Card Bill That Banks Fear Most Has Gained Trump as an Ally
Plus: Vance says U.S. will suspend Microsoft and other firms from green card program, and rogue pilots are a growing safety threat.
Global Security News
Man admits to running network of 15,000 money mules for cybercriminals
A Ukrainian-Russian dual citizen has pleaded guilty to running a massive money laundering operation that laundered millions for cybercriminals worldwide. […]
Global Security News
Microsoft Execution Containers for AI Agents Reach GA on Windows 11
Microsoft has launched Execution Containers for AI agents on Windows 11, adding policy-based restrictions for file, network, process, and desktop access.
Global Security News
ASOS breach update: Hackers stole customer details and shopping searches
The customer data stolen from global fashion retailer ASOS includes more than just names and contact details, raising questions about its early reassurances. As we reported earlier this week, ASOS customers received a push notification through the ASOS app alleging that the company had been hacked. ASOS has confirmed that attackers accessed customer information after tricking…
Global Security News
US Disrupts China-Linked Integrity Tech ‘s Cyber Espionage Tools
DOJ and FBI seized China-linked hacking tools Microscan and FishHub, linked to Integrity Tech and attacks on critical infrastructure worldwide. The Justice Department and FBI took down two hacking tools this week, Microscan and FishHub, both built and run by a Beijing-based company with direct government contracts. The tools were used to scan, and in…
Global Security News
FBI Warns FortiBleed Campaign Still Active, Hits 86,000+ FortiGate Devices
FortiBleed attacks continue to target Fortinet FortiGate devices, with SOCRadar reporting more than 86,644 compromised devices across 194…
Global Security News
Microsoft: Outdated Windows devices will stop receiving security updates
Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year’s Windows Update certificate rotation. […]
Global Security News
CVE-2026-107406: Citrix Fixes Critical NetScaler ADC and Gateway Vulnerability
Citrix patched CVE-2026-107406, a critical NetScaler ADC and Gateway flaw that could allow remote code execution or denial-of-service attacks. Citrix has released security updates to fix CVE-2026-107406 (CVSS score of 9.5), a critical flaw affecting NetScaler ADC and NetScaler Gateway that could allow remote code execution or denial-of-service (DoS) under certain conditions. The vulnerability is…
Global Security News
UK and Allies Warn of Cyber Threat from China’s Integrity Technology Group
The UK, US and allies have issued an alert detailing malicious activity linked to China’s Integrity Technology Group
Global Security News
Anthropic offers free AI security scans to open-source maintainers
Anthropic’s OSS Scanner is a new, free service that uses the company’s strongest AI models to find security vulnerabilities in open-source software. Maintainers who opt in receive periodic scans and reports explaining suspected flaws, how to reproduce them and, when available, how to fix them. The service builds on Anthropic’s experience with Project Glasswing, which…
Global Security News
FBI disrupts Flax Typhoon hacking tools used in global cyberattacks
The FBI seized seven domains used to operate Microscan and FishHub, two hacking tools linked to Chinese state-sponsored hackers known as Flax Typhoon that were used to target critical infrastructure and other organizations in the US and abroad. Seizure notice (Source: US Department of Justice) According to the US Department of Justice, the hackers worked…
Global Security News
Dell XPS 16 Creator Edition Launches: What Nvidia RTX Spark Means for the Channel
Dell is bringing Nvidia’s RTX Spark technology to its XPS laptop lineup, offering up to 128GB of unified memory in a portable system designed for demanding AI and creative workloads. The company revealed additional specifications, pricing, and preorder details for the XPS 16 Creator Edition on October 7. The laptop starts at $3,799.99 and combines…
Global Security News
Coupa: IT Services Spending Share Jumps Amid AI Growth
Technology companies are directing a growing share of their spending toward IT services as investments in artificial intelligence reshape procurement priorities, according to new research from Coupa. The company’s Q3 2026 Business Spend Index (BSI), released October 8, found that IT services accounted for 14.1% of high-tech spending in 2026, up from 8.8% in 2023.…
Global Security News
GoBalance Flaw Lets Attackers Hijack .onion Addresses by Recovering Tor-Format Keys
A bug in GoBalance, a tool many dark-web sites use to stay reachable during attacks, lets anyone work out the secret key that controls a site’s .onion address using only public information, and then take that address over. Searchlight Cyber, which disclosed the flaw on October 8, says an attacker who recovers the key can redirect the…
Global Security News
When building an AI-native security program, start with outcomes
In my last article, I described the SOC Triangle, the longstanding trade-off among quality, consistency and cost efficiency in security operations. AI is starting to loosen that constraint by enabling certain kinds of work with greater depth and consistency, without requiring a linear increase in headcount. That raises the next question I hear from security…
Global Security News
AI Training Critical as Governance Challenges Grow
As AI adoption accelerates, ISACA is expanding its certification portfolio with a governance-focused credential designed to help professionals manage AI securely
Global Security News
Product showcase: SimpleLogin keeps your email address private with aliases
SimpleLogin is an email alias service from Proton that forwards messages to an existing mailbox. Users create addresses for registrations, purchases, and correspondence, giving them control over where their primary email address is shared. The service is open source and supports self-hosting. Getting started I tried SimpleLogin using a Gmail address. After verification, the dashboard…
Global Security News
Citrix warns admins to patch new NetScaler RCE flaw immediately
Citrix has warned IT administrators to patch systems immediately against a new critical vulnerability affecting NetScaler ADC networking appliances and NetScaler Gateway secure remote access solutions. […]
Global Security News
Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three research teams broke into Google’s Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest’s…
Global Security News
CVE-2026-59346: Critical VMware Workstation and Fusion Flaw Enables Guest-to-Host Code Execution
Broadcom has addressed CVE-2026-59346, a critical integer-overflow vulnerability affecting VMware Workstation and VMware Fusion. The flaw carries a CVSS score of 9.3 and can allow an attacker with administrative privileges inside a virtual machine to cross the virtualization boundary and execute code on the underlying host. The issue resides in VMware’s VMXNET3 virtual network adapter…
Global Security News
Meta Deploys AI to Catch Facebook Ads Linked to Child Exploitation
Meta is using AI to detect Facebook ads that direct users to child exploitation content, while testing its safety systems for weaknesses and evasion tactics.

