Wireshark release 4.6.8 fixes 28 vulnerabilities and 25 bugs. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 110

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of…
Global Security News
Large-scale DDoS attacks disrupted Threema secure messaging service
Global Security News
Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows…
Global Security News
Mustang Panda Upgrades CoolClient With a Kernel Rootkit

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows…
Global Security News
How AI Models From OpenAI and Anthropic Went Rogue
Global Security News
New AmnesiaStealer macOS malware hijacks browser sessions via remote control
Global Security News
The Bank of Nvidia
Global Security News
Why I Told My Chatbot to Stop Kissing Up to Me
Global Security News
Open-Weight AI Won’t Crimp Demand for Picks and Shovels
Global Security News
The Insta360 GO 3S Retro Bundle makes photography fun again
Global Security News
Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit…
Global Security News
Give your iPhone its own camera operator with the Insta360 Flow 2 Pro
Global Security News
Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware SAP Commerce Cloud CVE-2026-58231 Exploited…
Global Security News
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection…
Global Security News
APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD,…
Global Security News
Meet the Hohem iSteady MT3 Pro – the AI camera operator that follows you around
Getting smooth, cinematic footage used to mean having a camera operator, some serious equipment and preferably another pair of hands. Hohem’s new iSteady MT3 Pro has another…
Global Security News
The ‘Country Hicks’ Who Refused $26 Million from an AI Data Center
Global Security News
How To Identify And Avoid SMS Scams (With Infographics)
Today, I will show you how to identify and avoid SMS scams. I will also add an infographic. The digital age has ushered in an era of unparalleled convenience. Our smartphones, once a novelty, have become an extension of ourselves, serving as organizers, communication hubs, and gateways to information. However, this convenience has a dark…
Global Security News
Why Do So Many Apps Ask for Phone Number Verification?

In this post, I will answer the question – why do so many apps ask for phone number verification? Creating an account used to require little more than an email address and a password. Today, many apps ask for something else before allowing users to continue: a mobile phone number. Messaging platforms, social networks, marketplaces,…
Global Security News
Cloud Services and Security: How Businesses Can Reduce Cyber Risks
In this post, I will talk about cloud services and security and show you how businesses can reduce cyber risks. Cloud computing services have proven to be critical to the functioning of the modern business environment, where the need to scale resources, conduct operations remotely, run applications, and access information in various locations is of…
Global Security News
Cloud Security: Why Companies Should Not Fear To Move On The Cloud?
This post will discuss cloud security, its components, and cloud security framework models provided at various service levels. Additionally, we will demonstrate why companies should migrate their businesses to the cloud. Cloud computing is highly popular and widely adopted by almost every possible domain. And it is expected to reach 623.3 Billion by 2023. However,…
Global Security News
Big Manufacturers Find New Demand in Equipping AI Data Centers
Global Security News
Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they…
Global Security News
Why Buy It When You Can Print It? A DIY Nation Has a Fix for Broken Doodads
Global Security News
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation.…
Global Security News
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
Global Security News
On ‘Billionaire Bunker,’ Buying a Mansion Is Easy. Getting Into the Club Isn’t.
Global Security News
No space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntable
Global Security News
The Summer That America Became a Nation of Luddites
Global Security News
macOS Screen Sharing Flaw Exploited to Deploy Monero Miners

Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS score of 9.8), less than two weeks after Apple shipped the fix. The…
Global Security News
GeoServer Zero-Day Is Already Being Probed. That’s the Problem

GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded the vulnerability…
Global Security News
Cybersecurity Architecture and Identity Shielding: Hardening Online Registrations Against Data Harvesting
In this post, I will talk about cybersecurity architecture and identity shielding and how to harden online registrations against data harvesting. Cybersecurity audits routinely reveal that corporate data aggregators treat mobile phone numbers as primary cross-platform tracking keys, making a secure virtual number infrastructure essential for privacy-conscious users and DevSecOps engineers alike. Surrendering primary cell…
Global Security News
How Phishing and Fake Trading Platforms Turn Social Media Into Investment Scams

In this post, I will show you how phishing and fake trading platforms turn social media into investment scams. Social media investment scams no longer look like obvious spam. They often begin with polished ads, cloned profiles, encrypted group chats, fake trading dashboards, and pressure from people who appear knowledgeable. For cybersecurity readers, the important…
Global Security News
Cybersecurity Services for Businesses That “Don’t Have Anything Worth Stealing”

In this post, I will talk about cybersecurity services for businesses that “don’t have anything worth stealing”. Every business owner has said it at least once. Usually during a conversation about budgets, insurance, or that nagging feeling that they should probably be doing more about security. “We’re small. We don’t really have anything worth stealing.”…
Global Security News
9 Best HRIS Software in Australia for Enterprise Companies [2026]
Global Security News
What Bitcoin Holders Should Know Before Borrowing Against Their Digital Assets

In this post, I will answer the question – what Bitcoin holders should know before borrowing against their digital assets. Bitcoin has evolved from an experimental digital currency into an asset held by individual investors, businesses and institutions around the world. As adoption has increased, so have the financial services built around it. One increasingly…
Global Security News
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality. Key Takeaways Taiwan’s Ministry of Digital Affairs confirmed a near-autonomous AI…
Global Security News
An Infamous Math Problem Broke AI—Until a High-School Dropout Said ‘You Got This’
Global Security News
U.S. Urges Apple Not to Buy Chinese Memory Chips
Global Security News
The Other Kushner Steps Into the Spotlight With $12.5 Billion Lakers Deal
Global Security News
MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control
Global Security News
Nvidia Downsizes Plans for $250 Billion Guarantee of OpenAI Data Center
Global Security News
Google’s Pixel 11 lands in Australia from $1,499 with Gemini AI doing the tapping, new Pro features and the best and brightest Pixel Watch yet
Google ran Made by Google 2026 out of New York with former Daily Show host, Trevor Noah, running the room, and the pitch underneath the comedy was simple enough: your phone…
Global Security News
How Anthropic plans to watermark Claude’s AI-generated text
Global Security News
Gridheart Expands Nordic MSP Security with OpenText Deal

Gridheart, a provider of cloud-based cybersecurity solutions for MSPs in the Nordic region, is expanding its cybersecurity offering with OpenText Cybersecurity. OpenText portfolio expands Gridheart’s Nordic MSP offering Via the partnership, MSPs across the Nordics will gain access to OpenText’s SMB security portfolio through Gridheart. This will enable MSPs to offer customers a unified, end-to-end…
Global Security News
Ready for the flood: How exposure management prepares you for the Mythos vulnerability onslaught
How proactive prioritization will save time and effort when your team faces a wave of AI-discovered vulnerabilities.
Global Security News
IGEL, Menlo Security Unite Endpoint and Browser Security

IGEL and Menlo Security are combining IGEL’s Adaptive Secure Endpoint Platform with Menlo Secure Application Access to extend Zero Trust controls from endpoints to browser and SaaS applications. The joint solution is designed to reduce reliance on virtual desktop infrastructure for browser-first workflows, limit endpoint agent sprawl, and simplify secure application access across enterprise environments.…
Global Security News
TD SYNNEX Expands IBM Distribution Into 20 Countries

TD SYNNEX is expanding its IBM distribution footprint into 20 new countries across Europe, Asia-Pacific, and Latin America, giving partners broader access to IBM solutions and support for scaling their businesses across global markets. The additional new countries include: Europe: Bulgaria, Denmark, Finland, Ireland, Slovakia, Sweden, Serbia, Macedonia, Montenegro, Albania, and Bosnia & Herzegovina. Asia…
Global Security News
Trezor confirms shipping partner data breach affecting over 13,000 customers
Global Security News
How a Sony Veteran Is Overhauling the Company He Grew Up In
Global Security News
U.S. judiciary to publicly disclose use of hacking tools in wiretaps starting 2029
Global Security News
California launches AI cybersecurity initiative amid growing threats
Global Security News
Cybercriminals invest millions in expired domains for illicit activities
Global Security News
MacOS screen sharing vulnerability actively exploited for crypto mining
Global Security News
ExfilSquad data extortion group linked to 13 victim data leaks
ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations.
Global Security News
ShinyHunters group claims responsibility for RingCentral data breach
Global Security News
Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More – SWN #607
Global Security News
Apple Seeks Up to 15% Cut on External Purchases in Epic Court Fight

Apple still wants a cut when an iPhone user leaves an app and completes a purchase on the web. In a new court proposal tied to its long-running fight with Epic Games, Apple is asking to charge US developers between 5% and 15% on purchases completed after users follow external links from iOS apps. The…
Global Security News
Trezor Says ShipMonk Breach Exposed Data of Nearly 14,000 Customers

Trezor, the Prague-based manufacturer of cold crypto storage devices, disclosed a significant data breach on Thursday that exposed the personal information of nearly 14,000 customers. The incident, which the company described as occurring at its third-party logistics partner ShipMonk, compromised the names, shipping addresses, phone numbers, and email addresses of 11,742 buyers. An additional 1,947…
Global Security News
Anthropic Investors Predict Record $2 Trillion IPO Valuation

Six Anthropic backers told the Financial Times that they expect the Claude maker to go public as early as October at a valuation of $2 trillion or more. Anthropic has not confirmed the timing or valuation, but such a debut could surpass SpaceX’s record IPO valuation. “If Anthropic is growing 800% a year, you’d think…
Global Security News
OpenAI Previews GPT-5.6 Sol Ultrafast Mode for Real-Time AI Workloads

OpenAI is previewing a faster GPT-5.6 Sol API option for workloads where every extra second can slow the application around it. The company said that Ultrafast can run its flagship model up to 14 times faster than Standard processing. MSPs, systems integrators, and other providers supporting customer AI deployments may see the biggest difference when…
Global Security News
Gemini Becomes Google’s 14th Product to Reach 1B Monthly Users

Gemini has joined the billion-user club, giving Google its strongest sign yet that its AI assistant has moved into the mainstream. Google said Tuesday that the Gemini app has surpassed 1 billion monthly active users, making it the company’s 14th product to reach that milestone. The figure puts Gemini among the largest consumer AI services…
Global Security News
AI-driven energy buildout raises cybersecurity, supply chain risks
Global Security News
Mission-Driven Security: Inside a Global Bank’s Defense
In this video interview, Standard Chartered’s group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.
Global Security News
Claude Agents Started a ‘Turf War’ That Escalated to Self-Replicating Malware

Claude agents given conflicting coding assignments began sabotaging one another in a controlled Anthropic experiment, with some encounters escalating to self-replicating malware. Researchers were testing how autonomous models behave when several agents work in the same environment under incompatible goals. Some Claude instances treated competing work as interference and entered what Anthropic called a “multiagent…
Global Security News
SAP Commerce Cloud RCE Flaw Actively Exploited

A vulnerability in SAP Commerce Cloud that can allow unauthenticated attackers to execute arbitrary code is being exploited in the wild just days after SAP released a security update. Threat intelligence company Defused detected exploitation attempts targeting the flaw three days after the patch was issued. “First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP…
Global Security News
White House looks to engage private sector in offensive hacking ops
Global Security News
DeepSeek Raises V4 API Prices More Than Fourfold as IPO Reports Surface

Chinese artificial intelligence developer DeepSeek is replacing flat API fees for its flagship V4 models with peak and off-peak pricing beginning at 16:00 UTC on Aug. 16, 2026. The change raises DeepSeek-V4-Flash and DeepSeek-V4-Pro API rates by about 57% to more than 1,100%, depending on the model, token type, and billing period. Developers and IT…
Global Security News
Hackers arrested over €30M bank fraud exploiting service provider flaw
Global Security News
CrowdStrike Expands Project QuiltWorks to SMBs via Channel

CrowdStrike is expanding Project QuiltWorks, its industry-wide framework for addressing security risks tied to frontier AI, to small and midsize businesses (SMBs). The expansion will make QuiltWorks available to SMBs through distributors, cloud marketplaces, MSPs, and other channel partners, giving smaller organizations access to AI-driven vulnerability discovery and prioritization, expert-led remediation, and cyber risk protection…
Global Security News
What GRC Failure Costs the Business
Global Security News
Amid AI-Driven Bug Tsunami, NIST Looks to…AI
Global Security News
Build or Buy? Making the Right Application Security Investment
Global Security News
Shell Investigates Clop Data Theft Claims Tied to PTC Flaw

Energy giant Shell is investigating a potential incident after the Clop ransomware group claimed it stole 89 GB of company data, including engineering drawings, facility reports, photographs, and project plans. The claim places Shell among dozens of organizations reportedly targeted through vulnerable, internet-facing product lifecycle management (PLM) systems. “We are aware of a potential incident.…
Global Security News
Apple warned hundreds of users of mercenary spyware attacks

Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already…
Global Security News
RingCentral Breach Data Includes 1.6M Email Addresses, HIBP Says

RingCentral’s July security incident is now tied to a much larger public dataset than the company initially disclosed. Have I Been Pwned added the incident to its breach database on Aug. 13, saying leaked data contained 1.6 million unique email addresses along with names, phone numbers, and physical addresses. RingCentral previously said the incident affected…
Global Security News
Google Meet can take notes for your in-person meetings now – here’s how it works
Google’s Gemini-driven meeting software can now save a transcript, send it to Google Drive, and email you a copy.
Global Security News
What Application Security Actually Controls
Global Security News
How to Evaluate DSPM and Data Discovery Platforms
Global Security News
August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw
Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971. This security-only release earns Patch Now for…
Global Security News
The Water Watch Center promises the cyber protection small water utilities need
Global Security News
I tested an Android app that lets anyone fight censorship – and shows your impact in real time
Global Security News
Apple is warning users of new spyware attacks – what to do if you’re a target
New spyware attacks are aimed at journalists, activists, politicians, diplomats, and others. Here’s how Apple is notifying them and what they should do – after turning on Lockdown Mode.
Global Security News
Dell XPS 13 review: The first budget laptop to rival Neo raises the bar for all PCs
The Dell XPS 13 flaunts build quality rarely seen at this price point, but not without trade-offs.
Global Security News
ChatGPT’s new Computer History tracks your Mac activity to create a timeline – but should you let it?
Rolling out to ChatGPT’s Mac app, Computer History creates a timeline from your activities across the apps and websites you use on your Mac. Is that a privacy risk?
Global Security News
Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor’s Office
Global Security News
AI Cyberattacks: How Threat Actors Use AI in Real Intrusions
AI is becoming a bigger part of real-world cyberattacks, helping threat actors conduct intrusions, steal credentials, navigate networks, and identify valuable targets. A Gambit Security investigation into three unrelated threat actors found attackers integrating AI throughout the intrusion lifecycle, extending its use beyond phishing and malware generation. “One finding is worth separating out. In the…
Global Security News
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
Global Security News
Silicon Valley Loves Jargon—and ‘Hill-Climbing’ Is Its Favorite New Phrase
Global Security News
Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations
Global Security News
New Android Malware Chain Turns Bank Support Scams Into NFC Card Fraud

It took a threat actor just 13 minutes to turn a routine bank support call into a remote, live contactless card fraud operation. Group-IB found malware used in a campaign targeting victims via fake bank support calls, in which attackers persuaded them to install malicious software on their Android devices. Once the phone was compromised,…
Competitive Reports
DATA SECURITY MARKET OVERVIEW REPORT 2026

Comprehensive Analysis of Trends, Market Changes, Technology Shifts & Statistics EXECUTIVE SUMMARY The global data security market is experiencing unprecedented growth driven by escalating cyber threats, digital transformation, and stringent regulatory requirements. The market has reached $17.21 billion in 2026 and is projected to grow at a CAGR of 17.12% through 2031, reaching $37.93 billion.…
Global Security News
AI Security Failures, Active Exploits, and Breaches Define the Week in August 2026

This week’s cybersecurity landscape combined actively exploited infrastructure flaws, ransomware resilience, social engineering, large-scale data breaches, and an expanding set of risks involving AI-generated code and autonomous agents. Research presented around DEF CON 34 and Black Hat 2026 also showed how AI systems can expose data, compromise development workflows, accelerate exploit creation, and take damaging…
Global Security News
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. […]
Global Security News
What Boards Need to Know About Tech Risk
Top Tech Tools
Top 10 WiFi Mesh Systems & Routers at Amazon (2026) – Review-Based Report

Executive Summary Based on aggregated reviews from major tech publications (CNET, PCMag, Tom’s Guide, BroadMag, SmartHomeReview, RTINGS), this report ranks the top 10 WiFi mesh systems and routers available on Amazon. The rankings combine user satisfaction scores, expert test results, reliability metrics, and value propositions. Top 10 Rankings Rank Product Price Range Best For Overall…
Global Security News
Max severity SAP Commerce Cloud flaw now targeted in attacks
Global Security News
Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June, and there are fears that they…













































