
The surveillance-technology company has faced criticism over the risks of police abuse of its AI-enabled camera system.

The Samsung R95H is built with an all-new Micro RGB panel that delivers truly impressive color and contrast.
Here’s what election security teams need to consider ahead of the elections this fall.
The Apple Watch Ultra 3 and the Samsung Galaxy Watch Ultra 2 are top-tier rugged smartwatches with similar features, but one stands out.
DND is so much more than a way to silence your phone.

President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government. The post White House authorizes private US companies to hack foreign criminal networks appeared first on Help Net Security.

Syncro has launched a native Model Context Protocol (MCP) server that connects live operational data from its platform with AI assistants including Claude, ChatGPT and Microsoft Copilot, giving MSP technicians a new way to access and act on ticketing, billing, customer and endpoint data. Syncro connects live MSP data to AI assistants The MCP server…

SelectHub has announced the launch of DataGrout, its specialized AI research lab introducing an LLM inference optimization platform and AI governance solution for enterprises. DataGrout’s mission is to drive token reduction for agentic workflows, chatbots and AI tools, while equipping IT and FinOps leadership with a policy-driven, auditable LLM payload and cost monitoring system to…
The move should cut down on the confusion between the two apps, especially for anyone who bounces back and forth between the two of them.
A threat hunting maturity score can tell you whether your team has developed a disciplined hunting practice. It cannot tell you which adversary techniques you are equipped to find. That leaves a sizable hole in board reporting. The 2025 Verizon Data Breach Investigations Report found that credential abuse accounted for 22% of breaches, with vulnerability…

Autonomous AI agents built on open-source frameworks breached Taiwanese government systems, compromised credentials, and probed a nuclear safety agency in a multi-day cyberattack that researchers say signals a new phase in AI-enabled operations. The campaign unfolded over four days in early July, during which multiple AI agents operated in parallel to map networks, identify vulnerabilities,…

Frontier Technologies and MSP Hub Technologies have formed a strategic alliance combining Frontier’s federal contracting and CMMC capabilities with MSP Hub’s Microsoft licensing, cloud, and managed services operations for government and regulated customers. Managed services and federal contracting expertise in one model This partnership will deliver a fully integrated model that combines Frontier’s federal contracting…

A10 Networks has announced the general availability of the A10 AI Gateway, a centralized, intelligent control plane that gives organizations unified routing, cost management, and governance across every AI agent, application and large language model (LLM) they use. As AI adoption accelerates, developers are increasingly building agents and embedding AI into applications and business systems,…
Tips for those feeling addicted to a beeping, chirping device.
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updates. “The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said. “Exploiting this…

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but…

The Trump administration is opening the door for vetted US companies to conduct cyber operations against foreign cybercriminal organizations under federal supervision, giving the private sector a more direct role in disrupting cyber-enabled crime. A presidential memorandum issued on August 12 directs the National Coordination Center to create a program authorizing participating companies to conduct…

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across…

Researchers at XM Cyber found that a standard domain user with no Microsoft SCCM privileges can chain multiple flaws to reach remote code execution, although the attack does require network access to the SCCM environment. Enterprises use Microsoft System Center Configuration Manager (SCCM) to deploy operating systems, manage patches, distribute software, and monitor compliance across…
Three out of four of the 138 developers I surveyed use Claude Code. Here’s what they say matters in daily AI coding workflows.

President Donald Trump signed a national security memorandum Wednesday that lays the groundwork for private sector companies to take a larger role in helping law enforcement carry out offensive hacking operations against transnational criminal organizations. The White House said sustained fraud and other cyber-enabled campaigns from transnational criminal organizations (TCOs) warranted the memo, and cited…
The process of sending someone a file or sharing your information on Android just got a lot simpler.

Researchers at Group-IB have discovered a new NFC relay malware family, purpose-built to capture live card data via NFC and forward it in real time to attackers. They dubbed it “WindRelay.” NFC (Near Field Communication) is wireless technology that allows devices such as smartphones, payment cards, and payment terminals to communicate when they’re very close…

Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be exploited. Security for the real-time era For decades, security teams have relied on a critical advantage: time. Organizations could identify vulnerabilities, investigate threats and respond…

A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging…

Cisco Talos recently identified an undocumented phishing framework, internally branded “JWR” by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor…

A group of big tech firms is fighting to stop roughly 3,000 youth safety lawsuits from moving forward, and they just lost a critical procedural battle in court. The lawsuits, brought by attorneys general and families, allege that Meta, Google, ByteDance’s TikTok, and Snap knew their products were addictive to children and teens and harmful…

July 2026 saw 188 confirmed cyber attacks across 69 countries, with financially motivated Cyber Crime driving three in four incidents. Malware remained attackers’ weapon of choice, exposed public-facing applications were the most common way in, and Information & Communication infrastructure absorbed the heaviest share of targeting. Here’s the full breakdown of who attacked, how, and…
If you have trouble remembering the passwords for all of your online accounts, we’ve handpicked the best password manager apps to help you stay protected.

Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attackers started exploiting CVE-2026-55040 (CVSS score of 9.1), a critical SharePoint authentication bypass patched in July, within days of Rapid7 releasing a public proof-of-concept on August 12. The vulnerability allows an unauthenticated attacker impersonate any SharePoint user…

LevelBlue has been named SentinelOne’s premier remediation partner for Wayfinder Frontier AI Services, expanding the companies’ relationship as organizations grapple with a growing challenge: finding vulnerabilities with AI is becoming faster, but fixing those vulnerabilities at scale remains difficult. For MSPs and other security service providers, the partnership reflects a broader opportunity emerging around AI-driven…

Schneider Electric has launched a new generation of its APC Smart-UPS designed to support multiple battery chemistries, giving channel partners a more flexible platform for helping customers modernize backup power across distributed IT and edge environments. Standardized platform across every battery type The new Smart-UPS runs on valve-regulated lead-acid (VRLA) or lithium-ion batteries and supports…

Cyber defenders need to shake off traditional best practices and switch from reactive patching to building inherently resilient systems in the face of AI-accelerated vulnerability discovery, according to a senior security manager at Microsoft. David Weston, group manager in the Windows team at Microsoft, told delegates at Black Hat USA that traditional approaches to vulnerability…

Ingram Micro is expanding the AI capabilities of its Xvantage platform with an Integration Hub and Model Context Protocol (MCP) Server designed to make it easier for channel partners to connect AI assistants with business data, workflows, and existing IT systems. The distributor says hundreds of partners worldwide are already using the Xvantage Integration (XI)…

Microsoft says China-linked Storm-1175 is using a new ransomware called StormEncryptor, replacing Medusa in its latest attacks. Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then…

MSPs’ access to credentials across dozens or even hundreds of customer environments can turn a single compromised login into a multi-client security incident, putting credential management, technician access and offboarding practices under growing scrutiny. Chris Skipworth, CEO of MSP-focused password management provider Passpack, spoke with Channel Insider about where credential security breaks down inside MSPs,…
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026. Details about the attacks are currently under wraps. Cisco…

Lazarus targets defense professionals with fake Lockheed Martin jobs, exploiting a Windows zero-day to deploy backdoors and evade security controls. Check Point Research has uncovered a new wave of Operation Dream Job, the long-running North Korean campaign that lures defense and aerospace professionals with convincing fake job offers. This iteration is more dangerous than previous…

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday…

In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets granted, conversations start, and decisions get made that later affect chain of custody, privilege, and how regulators judge the…

DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-layer attacks to disrupt online services across multiple industries. L3/4 attack-size distribution (bitrate), H1 2026 (Source: Cloudflare) Network-layer…
Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent survey, 85% of people say they struggle to distinguish authentic content from AI-generated material,…
SAP appoints Rachel Hunter as Head of AI, Australia and New Zealand, and reveals the most widely used AI applications across its ANZ customer base.
SAP research reveals that AI adoption is siloed across lines of business, with each department facing unique challenges in realising value.

Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng, Endace ERF, Tektronix K12xx, BUSMASTER, Catapult DCT2000, Gammu DCT3, 3gpp phone logs, TTX Logger,…

I will show you what to do if your password is found on the dark web. Our online security is more important than ever in today’s digital age. With cybercrime on the rise and data breaches becoming increasingly common, it’s crucial to stay vigilant about protecting your personal information. One of the most alarming situations…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
In the past few weeks, I have been using Gemma4 as a Large Language Model (LLM) to see how useful it can be to analyze some of the malware hashes uploaded to the DShield sensor over the past 30 days and figure out how its recommendation can be considered useful about the activity my DShield…
Rimini Street appoints Keith Costello as EVP and Chief Operating Officer and Alexander Guasch as EVP and Chief Delivery Officer
Versatility is in, with people expected to work across the tech stack.

Lovable, the Swedish-based AI software creation platform company, today announced an acceleration of its product, infrastructure, and team development efforts — and a noteworthy round of Series C funding totaling $400 million. The company said in its statement that it is looking to augment its platform, which it boasts is already used by almost two-thirds…
Welcome to the 25th edition of Cloudflare’s DDoS Threat Report. This is the first half-year edition in the series: rather than publishing separate reports for the first and…
Global study finds AI has become mainstream in security operations, shifting the conversation from adoption to governance and accountability
Total revenue increased 12% year over year, while global product revenue grew 31% and Hitachi Vantara storage revenue increased 45% Within Hitachi Vantara’s block portfolio,…

Would you like access to Anthropic’s Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called “Poison Claude”. Only problem is that it’s run by fraudsters… Meanwhile, a phishing-as-a-service platform called “Greatness” has come up with something rather nasty: a phishing attack that doesn’t…

When you build a new application or capability on Amazon Web Services (AWS), you want to focus on what you’re building. Getting a service running almost always begins with AWS Identity and Access Management (IAM). Many AWS services that act on your behalf need an IAM role, an identity the service assumes to access your…

Brad Lightcap, one of OpenAI’s longest-serving executives and its former COO, is leaving after nearly eight years. In a post on X, he said he plans to “start something new” and will remain available for several weeks during the transition. As COO, he oversaw global deployment and key partnerships as OpenAI expanded its enterprise business. …

Bitcoin miner turned AI infrastructure provider Riot Platforms has reportedly landed Anthropic as the tenant behind a $9.1 billion, 20-year data center lease. Riot announced Monday that an unnamed “leading frontier AI lab” had leased 191 megawatts of critical IT capacity at its Rockdale, Texas, campus. Bloomberg later identified the customer as Anthropic, citing people…

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. As of publication time,…

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. Nightmare Eclipse has not…

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. As of publication time,…

Proprietary AI companies such as OpenAI have secured multibillion-dollar infrastructure agreements to meet growing demand. Together AI is now making a sizable infrastructure commitment of its own. IBM and Together AI have signed a multi-year, $240 million agreement under which IBM plans to deploy a large cluster of NVIDIA HGX B300 systems on IBM Cloud.…