Keep your coffee, tea, or hot chocolate at the perfect temperature with the Ember self-heating mug.
Global Security News
N-able addresses critical N-central vulnerabilities exploited by attackers
Global Security News
Google Chrome to block malicious policy-installed extensions
Global Security News
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Global Security News
Defcon badges feature new open-source chip for enhanced security
Global Security News
Critical vulnerability in Rails Active Storage could lead to RCE
Global Security News
INC Ransomware chains two SonicWall SMA 1000 zero-days in attacks
Global Security News
Coldcard hardware wallet firmware flaw led to $70 million Bitcoin theft
Global Security News
EU AI Act Enforcement Raises Compliance Stakes for Vendors and Partners

Europe has turned its AI rulebook into a watchdog, and the world’s biggest AI companies are about to find out what that means. Last August 2, the European Union entered the active enforcement stage of its AI Act. This stage grants its AI Office the authority to investigate providers of General Purpose AI models, require…
Global Security News
Coldcard RNG Flaw Linked to Suspected $88.6M Bitcoin Theft

A random number generation flaw in Coldcard firmware may have left thousands of Bitcoin addresses with substantially weakened seeds. Researchers have linked the bug to suspected thefts totaling $88.6 million across 4,585 blockchain addresses, although the connection has not been computationally confirmed for every wallet. The affected firmware generated seeds with reduced entropy, potentially allowing…
Global Security News
I tried buying a MacBook Air from Apple today – shipping was delayed by over a month
Apple is starting to feel the global memory shortage, with MacBook Air shipments delayed by a month or more.
Global Security News
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is “lib-mtop,” an unscoped package with the same name as a…
Global Security News
COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft
Global Security News
AI is both a cyber weapon and a massive target, CrowdStrike warns
Global Security News
Multiple Vulnerabilities in SolarWinds Web Help Desk Could Allow for Authentication Bypass

Multiple vulnerabilities have been discovered in SolarWinds Web Help Desk, the most severe of which could allow for authentication bypass. SolarWinds Web Help Desk software grants access to SolarWinds IT support, asset management, and knowledge base operations. A vulnerability in the Web Help Desk could allow an unauthenticated, remote attacker to bypass authentication and gain…
Global Security News
N-able N-central Vulnerability Under Active Exploitation

A vulnerability in N-able’s N-central remote monitoring and management (RMM) platform is being actively exploited. The flaw can give attackers unauthenticated administrative access to the N-central console, allowing them to control every endpoint managed through the platform. “Exploitation is active in the wild; a compromised N-central server can be used to run scripts, push tools,…
Global Security News
Adobe fixes critical vulnerabilities in Campaign Classic and Bridge
Global Security News
N-able warns of N-central auth bypass flaw exploited in attacks
Global Security News
Anthropic’s AI models accidentally hacked three companies

Anthropic has launched an investigation into what went wrong during a recent test of three models that left a trio of companies accidentally hacked. The company was testing how well Claude Opus 4.7, Claude Mythos 5, and an internal test model could find hidden information about fictional companies in simulated networks. But because of a…
Global Security News
Empty web pages are a security risk, Kaspersky warns
Global Security News
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chrome’s Google Password Manager cloud authenticator, which it calls Pass-ta-key, Silver Pass-ta-key and Golden Pass-ta-key; the strongest…
Global Security News
South Korea warns of nation-state actors using phishing and compromised websites
Global Security News
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the “dominant threat actor” exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its…
Global Security News
Taiwanese Server Makers Turn Mexico Into a Major US AI Hub

Taiwanese server manufacturers are helping Mexico become one of the biggest assembly lines behind America’s AI boom. Mexico exported $46.9 billion in enterprise servers to the United States during the first five months of 2026, putting it just behind Taiwan and underscoring how quickly the country has become part of the US AI infrastructure buildout. …
Global Security News
Adform supply-chain attack replaced crypto wallet addresses
Global Security News
AI shopping searches surged 200% in one year – and it’s a top priority for commerce leaders now
Eighty-six percent of commerce leaders believe AI is raising the bar for customer expectations.
Global Security News
Why AI agents need their own identity
Global Security News
Arch Linux temporarily disables AUR package adoption amid malicious takeover surge
Global Security News
Amgen reports data breach impacting patient and corporate information
Global Security News
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet

A trusted software update can become a malware delivery system when attackers gain control of the account publishing it. Amazon Threat Intelligence has linked four npm supply-chain attacks conducted between March 2025 and March 2026 to Sapphire Sleet, a threat actor associated with North Korea. Based on command-and-control indicators and shared tactics, Amazon assessed the…
Global Security News
[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents
Have you ever read the Talos IR Quarterly Trends report and wondered, “How did that phishing or ransomware campaign actually play out? When was Talos IR contacted, how did they contain it, and how did they remediate the environment?” You’re in luck. Next Tuesday, August 11, Cisco Talos Incident Responders will be hosting an exclusive,…
Global Security News
Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm
Global Security News
This free Linux tool makes it easy to check your PC battery and disk usage – here’s how
The Mission Center system monitor for Linux adds some new features that will appeal to a broader user base, especially those with laptops.
Global Security News
AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek
Unit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers at Palo Alto’s Unit 42 got a front-row seat to something they’d only theorized about before: an AI system running an actual hacking campaign with almost no human steering it. The researchers spotted a Chinese-speaking actor,…
Global Security News
Why responsible vulnerability disclosure is now a boardroom issue
Global Security News
Mark Zuckerberg Says AI Is Accelerating Software Development at Meta

Meta says artificial intelligence is beginning to shorten the distance between a product idea and a working application. During the company’s latest earnings call, CEO Mark Zuckerberg said AI is accelerating software development across Meta and could allow its engineers to create and test more consumer apps. He cited several recent launches, although the company…
Global Security News
Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure
Global Security News
Commvault Taps Google To Aid in Cyberattack Recovery Efforts

Cyberattack recovery gets a security upgrade as Commvault brings Google Threat Intelligence into the backup process to help companies find safe data faster. Commvault is integrating Google Threat Intelligence into its Threat Scan workflows to help organizations identify clean recovery points more quickly after ransomware and other cyberattacks. Integrating Google Threat Intelligence with backup scanning…
Global Security News
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
Global Security News
Is your SD-WAN ready for AI-powered operations?
Global Security News
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Global Security News
Pax8: Managed AI Services Will Drive APAC Channel Growth
As AI adoption accelerates across the Asia-Pacific (APAC), partners are moving beyond AI experimentation to build managed AI services that generate recurring revenue. We recently spoke with Pax8 executive vice president and general manager for APAC Lindsay Keating, who said the shift is pushing partners beyond software licensing and automation toward outcome-driven AI services. APAC…
Global Security News
Inside the Underground Business of BTMOB RAT
Global Security News
How to keep your conversations with ChatGPT, Gemini, Copilot or Claude as private as possible
Global Security News
Best MagSafe wallets of 2026: Expert tested and reviewed
You don’t have to compromise on style or function with these MagSafe wallet picks from brands like Moft, ESR, and more.
Global Security News
River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June…
Global Security News
Attackers exploit N-able N-central flaw to reach MSP customers’ endpoints (CVE-2026-18577)
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not…
Global Security News
Midnight Blizzard Targets Travelers via Captive Portals
Global Security News
Google Pixel 11 Explained: What Google Has Confirmed and What the Rumors Say
Google’s next flagship smartphones are almost here, but not everything you’ve read about the Pixel 11 carries the same weight. The tech giant has confirmed it will unveil the Pixel 11 lineup during its Made by Google event on Aug. 12. Ahead of that announcement, reporting from various outlets has helped fill in many of…
Global Security News
H96 Android TV Boxes Used for Ad Fraud and Residential Proxies
Global Security News
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear,…
Global Security News
Is There Really a Fix for CISO Fatigue?
Global Security News
Mimecast introduces AI agent governance and managed threat response

Mimecast has unveiled Agent Risk Center, a beta capability for discovering, monitoring, and governing AI agents, alongside Managed Threat Response, a redesigned 24/7 service that combines AI-assisted triage with analyst-confirmed remediation. According to Mimecast’s analysis, 98% of organizations already have unsanctioned AI tools in use, and by 2029 more than a billion agents will take…
Global Security News
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers

A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s AI agent misconfigured a file server, inadvertently exposing the entire infrastructure. “This visibility enabled us to understand…
Global Security News
This free Google Drive alternative keeps your files private – and local
Looking to shift your storage needs from a third-party cloud service to inside your home network? If so, ZimaOS is a great option.
Global Security News
SentinelOne expands security operations automation with governed AI

SentinelOne has today announced governed, closed-loop response across the Singularity Platform, delivering trustworthy automation for security operations. Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Security teams set the boundaries first, deciding where AI acts on its own and where it stops for human sign-off. The Autonomous SOC now…
Global Security News
The 7 tech travel hacks I swear by – after years of learning the hard way
And no, I’m not going to tell you to pack a power bank, roll your clothes, or bring a travel pillow.
Global Security News
Horizon3.ai hits $2 billion valuation in $250 million funding round

Horizon3.ai has announced a $250 million Series E at a valuation of more than $2 billion, tripling its valuation from $650 million at Series D in just over a year. The oversubscribed round was co-led by existing investors NightDragon and NEA, with participation from seven new investors and five returning backers. The capital underscores accelerating…
Global Security News
3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported…
Global Security News
Zero Networks targets AI agent security gaps with network-level ‘Least Agency’ controls

While AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the…
Global Security News
Can Fast Fashion Fit Into Secondhand Clothes?
Global Security News
Apple and the invisible wolf: AI slop drowns real security threats
Apple has had to introduce a quota on security researcher reports because its systems are being overwhelmed by low-quality warnings generated by AI. It’s a classic illustration of the rule of unintended consequences: a technology meant to help us has become a barrier to getting things done. After all, not only has AI driven the cost…
Global Security News
Duress passcodes explained: How they work and why they can land you in court
But if you’ve been looking for the duress passcode feature on your phone, I have bad news for you.
Global Security News
How Google used AI agents to find and fix 1,072 Chrome security bugs – in 60 days
With 3.5 billion active users to protect, Google is relying on Gemini to find Chrome security bugs fast – and before attackers do.
Global Security News
Alibaba takes aim at OpenAI and Anthropic with Qwen3.8-Max launch

Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads. In a blog post announcing the launch, Alibaba described Qwen3.8-Max as a 2.4-trillion-parameter mixture-of-experts (MoE) model that activates only about 95 billion parameters during inference.…
Global Security News
Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short
Global Security News
PNLD Confirms Data Breach Affecting UK Police and Justice Staff

UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice…
Global Security News
CISA lays out new guidance for using open-source software

The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open source AI systems. Using open source software Federal agencies can benefit from open source software…
Global Security News
KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “KindaRails2Shell” by the researchers who found it, the flaw lets an…
Global Security News
FOMO in the SOC: Where AI Platforms like Claude Actually Fit
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI…
Global Security News
HollowFrame Loader Uses Fake Python DLL to Evade Defender
Global Security News
Qodana 2026.2 adds post-quantum crypto checks for JVM code

Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks untrusted data across files in C#, JavaScript, and TypeScript, which turns up SQL injection, command…
Global Security News
Simbian adds AI threat hunting agent to expand autonomous SecOps platform

Simbian has released its autonomous AI Threat Hunt Agent, that investigates potential threats and identifies malicious activity across enterprise environments. The Threat Hunt Agent represents the third pillar of Simbian’s AI-driven security suite. These three Agents eliminate blind spots across the entire threat timeline: The Present: The AI SOC Agent analyzes real-time alerts and neutralizes…
Global Security News
How AI is killing smartphone apps in China

Chinese smartphone makers have been followers in the global market, embracing the concepts and paradigms set in the past 20 years by Apple and Google. But AI may be giving the Chinese an opportunity to break away and set their own path forward. Specifically, Chinese companies are integrating AI more fully into smartphones, and also…
Global Security News
BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate

Companies are deploying AI agents into everyday work at a pace no security program was built for. Related: AI layoffs pays for AI infrastructure The rush is competitive. Nobody wants to be the last one still doing this by hand. What’s getting skipped is the harder question: once an agent is acting on a company’s…
Global Security News
Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a…
Global Security News
The Morning Risk Report: Trump Adds to China Forced Labor Blacklist
Plus: AI chatbot, deepfake labeling rules kick off in Europe, and FinCEN director leaves for Citigroup
Global Security News
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
Tenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs — it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security…
Global Security News
How ServiceNow’s CEO Weighs Long-Term Bets
Global Security News
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Global Security News
PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web

The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names
Global Security News
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys

Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Polska is Poland’s largest convenience store operator…
Global Security News
AppSec, Shopify-Style; State of Mobile Security; the News – Andrew Dunbar, Kern Smith – ESW #470
Global Security News
Stop depending on heroics and start operationalizing third-party risk

In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and…
Global Security News
OpenAI reveals how criminals used ChatGPT to run scams

OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to online scam compounds and human trafficking operations. The network used the company’s models to create and manage fake online personas, generate and translate messages sent to scam targets, produce promotional content for fraudulent…
Global Security News
Coldcard Users Lose $89m After Bitcoin Wallet Is Hacked
Global Security News
Elastic Defend now covers 800+ vulnerable drivers, with automated troubleshooting and ARM support
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker holds that level of access, the tools on…
Global Security News
AI is making cybersecurity fundamentals more important than ever

When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox — the same kind of fundamental…
Global Security News
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as…
Global Security News
Swoop named winner of postpaid mobile plan of the year at the 2026 WeMoney Awards
Global Security News
A week in security (July 27 – August 2)

Last week on Malwarebytes Labs: Fake Fortnite rewards are stealing players’ accounts Fake Flash Player installs AtlasRAT Malwarebytes for Windows, now available on the Microsoft Store Hims & Hers sued over alleged health data privacy failures Hidden prompt turns Microsoft Copilot into an AI worm Apple accused of letting fake crypto app steal $1.8 million…
Global Security News
CrowdStrike: AI is now both the weapon and the target in cyberattacks
While AI is supposed to help defenders, it’s now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The company’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June. “AI agent-driven…
Global Security News
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform
Global Security News
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code

Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. “These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the
Global Security News
Welcoming the Nepalese Government to Have I Been Pwned

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and respond quickly when those accounts appear in…
Global Security News
Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing

Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerable servers. In the default configuration, applications that generate image variants may expose…
Global Security News
Mapping the malware blast radius a single alert won’t show you

In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hides an average of 2.4 undocumented variants, describes…
Global Security News
SkillSpector: NVIDIA’s open-source security scanner for AI agent skills
SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of findings, a risk score, and recommendations. The folder it reads runs with everything you have.…
GeekGuyBlog
Interpol Leverages Global System to Curtail Fraud Payments
Global Security News
AI cut phishing from hours to seconds, which is where DMARC and BIMI come in

In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and why it matters for business trust. With a combined 45+ years worth of experience in tech, they dissect email from the very beginning, before…




































