
Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. […]

Wireshark release 4.6.8 fixes 28 vulnerabilities and 25 bugs. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM ShieldBreak – August 2026 disclosure Kimwolf v7: An Evolution of the Kimwolf Botnet CISA, FBI and Partners Warn Organizations of…

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows…

Mustang Panda upgraded CoolClient with a signed kernel driver that hides processes, files and network activity, making the backdoor harder to detect. HoneyMyte, also known as Mustang Panda, has pushed its CoolClient backdoor another step deeper into Windows. Kaspersky’s latest analysis shows a new variant that can deploy a signed kernel-mode driver as a Windows…

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit…

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware SAP Commerce Cloud CVE-2026-58231 Exploited…
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection…

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD,…
Getting smooth, cinematic footage used to mean having a camera operator, some serious equipment and preferably another pair of hands. Hohem’s new iSteady MT3 Pro has another…
Today, I will show you how to identify and avoid SMS scams. I will also add an infographic. The digital age has ushered in an era of unparalleled convenience. Our smartphones, once a novelty, have become an extension of ourselves, serving as organizers, communication hubs, and gateways to information. However, this convenience has a dark…

In this post, I will answer the question – why do so many apps ask for phone number verification? Creating an account used to require little more than an email address and a password. Today, many apps ask for something else before allowing users to continue: a mobile phone number. Messaging platforms, social networks, marketplaces,…
In this post, I will talk about cloud services and security and show you how businesses can reduce cyber risks. Cloud computing services have proven to be critical to the functioning of the modern business environment, where the need to scale resources, conduct operations remotely, run applications, and access information in various locations is of…
This post will discuss cloud security, its components, and cloud security framework models provided at various service levels. Additionally, we will demonstrate why companies should migrate their businesses to the cloud. Cloud computing is highly popular and widely adopted by almost every possible domain. And it is expected to reach 623.3 Billion by 2023. However,…

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they…

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation.…

Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as CVE-2026-65400 (CVSS score of 9.8), less than two weeks after Apple shipped the fix. The…

GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded the vulnerability…
In this post, I will talk about cybersecurity architecture and identity shielding and how to harden online registrations against data harvesting. Cybersecurity audits routinely reveal that corporate data aggregators treat mobile phone numbers as primary cross-platform tracking keys, making a secure virtual number infrastructure essential for privacy-conscious users and DevSecOps engineers alike. Surrendering primary cell…

In this post, I will show you how phishing and fake trading platforms turn social media into investment scams. Social media investment scams no longer look like obvious spam. They often begin with polished ads, cloned profiles, encrypted group chats, fake trading dashboards, and pressure from people who appear knowledgeable. For cybersecurity readers, the important…

In this post, I will talk about cybersecurity services for businesses that “don’t have anything worth stealing”. Every business owner has said it at least once. Usually during a conversation about budgets, insurance, or that nagging feeling that they should probably be doing more about security. “We’re small. We don’t really have anything worth stealing.”…

In this post, I will answer the question – what Bitcoin holders should know before borrowing against their digital assets. Bitcoin has evolved from an experimental digital currency into an asset held by individual investors, businesses and institutions around the world. As adoption has increased, so have the financial services built around it. One increasingly…
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality. Key Takeaways Taiwan’s Ministry of Digital Affairs confirmed a near-autonomous AI…
Google ran Made by Google 2026 out of New York with former Daily Show host, Trevor Noah, running the room, and the pitch underneath the comedy was simple enough: your phone…

Gridheart, a provider of cloud-based cybersecurity solutions for MSPs in the Nordic region, is expanding its cybersecurity offering with OpenText Cybersecurity. OpenText portfolio expands Gridheart’s Nordic MSP offering Via the partnership, MSPs across the Nordics will gain access to OpenText’s SMB security portfolio through Gridheart. This will enable MSPs to offer customers a unified, end-to-end…
How proactive prioritization will save time and effort when your team faces a wave of AI-discovered vulnerabilities.

IGEL and Menlo Security are combining IGEL’s Adaptive Secure Endpoint Platform with Menlo Secure Application Access to extend Zero Trust controls from endpoints to browser and SaaS applications. The joint solution is designed to reduce reliance on virtual desktop infrastructure for browser-first workflows, limit endpoint agent sprawl, and simplify secure application access across enterprise environments.…

TD SYNNEX is expanding its IBM distribution footprint into 20 new countries across Europe, Asia-Pacific, and Latin America, giving partners broader access to IBM solutions and support for scaling their businesses across global markets. The additional new countries include: Europe: Bulgaria, Denmark, Finland, Ireland, Slovakia, Sweden, Serbia, Macedonia, Montenegro, Albania, and Bosnia & Herzegovina. Asia…
ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations.

Apple still wants a cut when an iPhone user leaves an app and completes a purchase on the web. In a new court proposal tied to its long-running fight with Epic Games, Apple is asking to charge US developers between 5% and 15% on purchases completed after users follow external links from iOS apps. The…

Trezor, the Prague-based manufacturer of cold crypto storage devices, disclosed a significant data breach on Thursday that exposed the personal information of nearly 14,000 customers. The incident, which the company described as occurring at its third-party logistics partner ShipMonk, compromised the names, shipping addresses, phone numbers, and email addresses of 11,742 buyers. An additional 1,947…

Six Anthropic backers told the Financial Times that they expect the Claude maker to go public as early as October at a valuation of $2 trillion or more. Anthropic has not confirmed the timing or valuation, but such a debut could surpass SpaceX’s record IPO valuation. “If Anthropic is growing 800% a year, you’d think…

OpenAI is previewing a faster GPT-5.6 Sol API option for workloads where every extra second can slow the application around it. The company said that Ultrafast can run its flagship model up to 14 times faster than Standard processing. MSPs, systems integrators, and other providers supporting customer AI deployments may see the biggest difference when…

Gemini has joined the billion-user club, giving Google its strongest sign yet that its AI assistant has moved into the mainstream. Google said Tuesday that the Gemini app has surpassed 1 billion monthly active users, making it the company’s 14th product to reach that milestone. The figure puts Gemini among the largest consumer AI services…
In this video interview, Standard Chartered’s group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.

Claude agents given conflicting coding assignments began sabotaging one another in a controlled Anthropic experiment, with some encounters escalating to self-replicating malware. Researchers were testing how autonomous models behave when several agents work in the same environment under incompatible goals. Some Claude instances treated competing work as interference and entered what Anthropic called a “multiagent…

A vulnerability in SAP Commerce Cloud that can allow unauthenticated attackers to execute arbitrary code is being exploited in the wild just days after SAP released a security update. Threat intelligence company Defused detected exploitation attempts targeting the flaw three days after the patch was issued. “First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP…

Chinese artificial intelligence developer DeepSeek is replacing flat API fees for its flagship V4 models with peak and off-peak pricing beginning at 16:00 UTC on Aug. 16, 2026. The change raises DeepSeek-V4-Flash and DeepSeek-V4-Pro API rates by about 57% to more than 1,100%, depending on the model, token type, and billing period. Developers and IT…

CrowdStrike is expanding Project QuiltWorks, its industry-wide framework for addressing security risks tied to frontier AI, to small and midsize businesses (SMBs). The expansion will make QuiltWorks available to SMBs through distributors, cloud marketplaces, MSPs, and other channel partners, giving smaller organizations access to AI-driven vulnerability discovery and prioritization, expert-led remediation, and cyber risk protection…

Energy giant Shell is investigating a potential incident after the Clop ransomware group claimed it stole 89 GB of company data, including engineering drawings, facility reports, photographs, and project plans. The claim places Shell among dozens of organizations reportedly targeted through vulnerable, internet-facing product lifecycle management (PLM) systems. “We are aware of a potential incident.…

Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told TechCrunch the latest alerts reached people in 110 countries, adding to notifications it has already…

RingCentral’s July security incident is now tied to a much larger public dataset than the company initially disclosed. Have I Been Pwned added the incident to its breach database on Aug. 13, saying leaked data contained 1.6 million unique email addresses along with names, phone numbers, and physical addresses. RingCentral previously said the incident affected…
Google’s Gemini-driven meeting software can now save a transcript, send it to Google Drive, and email you a copy.
Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but not exploited, CVE-2026-62832 (User Profile Service) and CVE-2026-72971. This security-only release earns Patch Now for…
New spyware attacks are aimed at journalists, activists, politicians, diplomats, and others. Here’s how Apple is notifying them and what they should do – after turning on Lockdown Mode.
The Dell XPS 13 flaunts build quality rarely seen at this price point, but not without trade-offs.
Rolling out to ChatGPT’s Mac app, Computer History creates a timeline from your activities across the apps and websites you use on your Mac. Is that a privacy risk?
AI is becoming a bigger part of real-world cyberattacks, helping threat actors conduct intrusions, steal credentials, navigate networks, and identify valuable targets. A Gambit Security investigation into three unrelated threat actors found attackers integrating AI throughout the intrusion lifecycle, extending its use beyond phishing and malware generation. “One finding is worth separating out. In the…

It took a threat actor just 13 minutes to turn a routine bank support call into a remote, live contactless card fraud operation. Group-IB found malware used in a campaign targeting victims via fake bank support calls, in which attackers persuaded them to install malicious software on their Android devices. Once the phone was compromised,…

Comprehensive Analysis of Trends, Market Changes, Technology Shifts & Statistics EXECUTIVE SUMMARY The global data security market is experiencing unprecedented growth driven by escalating cyber threats, digital transformation, and stringent regulatory requirements. The market has reached $17.21 billion in 2026 and is projected to grow at a CAGR of 17.12% through 2031, reaching $37.93 billion.…

This week’s cybersecurity landscape combined actively exploited infrastructure flaws, ransomware resilience, social engineering, large-scale data breaches, and an expanding set of risks involving AI-generated code and autonomous agents. Research presented around DEF CON 34 and Black Hat 2026 also showed how AI systems can expose data, compromise development workflows, accelerate exploit creation, and take damaging…
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. […]

Executive Summary Based on aggregated reviews from major tech publications (CNET, PCMag, Tom’s Guide, BroadMag, SmartHomeReview, RTINGS), this report ranks the top 10 WiFi mesh systems and routers available on Amazon. The rankings combine user satisfaction scores, expert test results, reliability metrics, and value propositions. Top 10 Rankings Rank Product Price Range Best For Overall…

Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, attacking dating sites in January and Oracle in June, and there are fears that they…