
Does movement between these zones require explicit authorization or can it proceed on implicit trust?


Microsoft is introducing new AI tools designed to help customers continuously streamline and automate the process of identifying and reducing their exposure to security risks. The new tools come less than a week after OpenAI lost control of two of its security models when they infiltrated the servers of startup Hugging Face. The hack, Hugging…
Reuters says OpenAI failed to detect its AI agent hacking Hugging Face for days, discovering the breach only after FBI involvement. Reuters reported that the OpenAI agent responsible for the Hugging Face breach operated undetected for over a week before OpenAI realized what had happened, long after the FBI had been alerted and Hugging Face…
An FBI agent explains how the mulitnational law-enforcement Operation Cronos was successful in disrupting the largest ransomware group of its time.

Hugging Face CEO Clem Delangue wants to see radical transparency from OpenAI after the company acknowledged that one of its AI agents managed to hack into the AI platform’s systems during a test. In a post on X, Delangue wrote that, among other things, he wants OpenAI to publish logs and traces from the autonomous…
In July 2026, an OpenAI model escaped its evaluation sandbox and broke into Hugging Face’s production infrastructure. It is the first documented end-to-end intrusion carried out by an autonomous AI agent. The most repeated takeaway, “the AI went rogue,” is also the least useful one. The real lessons are about containment engineering, about who is…

Microsoft has introduced MAI-Cyber-1-Flash, a security-focused AI model built into MDASH, the company’s multi-agent vulnerability identification and remediation system. MAI-Cyber-1-Flash is Microsoft’s first model built specifically for cybersecurity work, and the company stated that it went through review by its AI Red Team, adversarial testing, and an assessment by an outside party. Microsoft argues that…
Application-layer distributed denial of service (DDoS) attacks are difficult to detect because they closely resemble legitimate traffic. HTTP request floods are now among the most common vectors targeting web applications, using valid-looking requests that blend in with normal user activity. In June 2025, AWS launched the AWS WAF Anti-DDoS managed rule group, built specifically for…

Aftercall is a wave of deceptive Android apps on Google Play that pose as everyday tools while bombarding users with pop-up ads after every phone call. When an unexpected ad pops up every time you hang up a call, it will slowly drive you crazy, especially if you can’t figure out what’s causing it. The…

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the…
HP’s OmniBook Ultra 14 combines a sleek design and OLED display with the kind of performance professionals appreciate.

MedusaHVNC RAT uses hidden Windows desktops to remotely control browsers, steal data, and evade detection through legitimate system features. Windows has always supported hidden desktops as a legitimate feature, useful for specialized software that needs a workspace the user never touches. It’s a niche capability most people never think about, buried deep in how the…

If you are a CISO, here is a new problem for the pile: Do I worry more about Sandworm Relic or Strawberry Tempest? Last week, Google Threat Intelligence Group joined a list of rivals in changing how it names hackers, replacing years of split naming systems with a single set of code names built around…

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt. CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese
Meet Shadowfetch: If AI is your jam and Linux is your OS, here’s the best way to give this new Debian-based distribution a try.

AWS Security Assurance Services is announcing the release of the Cloud Security Alliance (CSA) Compliance Guide on Amazon Web Service (AWS), a new resource that maps the 17 control domains and 207 control objectives of the Cloud Controls Matrix v4.1 (CCM) to AWS services and recommended implementation practices. The guide is intended to help organizations…
Got old gadgets lying around? Trade them in for gift cards at Costco – no membership required.

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft,…
Despite the temptation to enter what might become a $40 billion market, Apple has reportedly decided to delay the introduction of its smart glasses until 2027. The company apparently wants to figure out a better balance between privacy and convenience. If it gets that right, Apple might be able to bring to market glasses people can wear…
Learn why assuming security controls will fail creates stronger cyber resilience through layered defenses, MITRE ATT&CK, and faster threat response.

Sextortion scammers are using email addresses from data leaked by the ShinyHunters hacking group to add some credibility to their feeble attempts to convince people they have embarrassing information about them. Sextortion emails are messages claiming that the scammer recorded you through your webcam while you watched pornography and now demand payment. They have been…
Framework compiled user feedback to create the new Laptop 13 Pro, a sleek device with a haptic touchpad and excellent battery life.
Google wasn’t supposed to see them, but then everyone on Reddit did. Here’s how to handle the situation.
Organize your workspace with our top picks for the best laptop docking stations available now.

NVIDIA and a group of tech companies have formed an alliance to promote the use of open AI models in cybersecurity, days after OpenAI disclosed that one of its own AI models breached Hugging Face’s systems during an internal security evaluation. The new group, called the Open Secure AI Alliance, builds on work already underway…

Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does…
This week on the Lock and Code podcast… Twenty years ago, a British mathematician named Clive Humby popularized a phrase that came to describe data’s relationship with the entire global economy: “Data is the new oil.” Pithy as the phrase sounds, it is undeniably true. Data steers decisions at businesses of every size. Data created…
Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped. That is the mood. Here is the full recap. ⚡…
New CDW research finds that AI is driving new phishing and malware-based threats. But are enough companies also using AI to fight them?
Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.

Dynatrace has announced major advancements to Dynatrace Intelligence that help automatically resolve incidents, prevent disruptions, and accelerate operations while maintaining the human oversight and governance enterprises require. Building on the introduction of Dynatrace Intelligence earlier this year, Dynatrace is adding new autonomous agents for incident triage and remediation, and no-code custom agent creation capabilities. The…

Zenity has announced a major expansion of its platform, making it the AI security platform for autonomous AI built around a new security architecture designed to govern AI decisions before they become enterprise actions, including those made by long-horizon agents operating autonomously across extended, multi-step workflows. The platform adds Exposure Management and Runtime Boundaries to…

JetStream Security has announced the release of an AI Kill Switch that allows organizations to shut down compromised AI agents on-demand without impacting other AI operations. This new control plane for AI agents solves the inability to stop a single agent that falters, begins overspending, or needs to be taken offline for compliance reasons without…

7AI has announced two major platform capabilities: 7AI Federated SIEM, which lets security teams query, investigate, and act on data wherever it lives, including within 7AI, and 7AI Build, which lets enterprises and partners define agentic workflows, skills, and AI-native security services on top of the 7AI platform. “Three out of five customers we have…

C1 has launched shadow AI discovery to eliminate the massive security blind spots created by unauthorized AI agents, tools, and credentials. By automatically discovering and folding every AI-adjacent identity into C1’s existing identity governance platform, organizations can finally ensure that the governed path is the fastest path to safe AI adoption. Shadow AI discovery works…

Google Threat Intelligence Group (GTIG) has started using a new naming system for the threat actors it tracks. The change comes after Mandiant and Google’s Threat Analysis Group (TAG) merged into one unit, leaving the company with two separate naming schemes built up over years. Previously, Mandiant and Google’s Threat Analysis Group maintained separate naming…

DentaQuest disclosed a data breach that may have exposed the personal and dental health information of more than 23 million people. DentaQuest is notifying more than 23 million people of a data breach after hackers accessed its network in May 2026. The incident may have exposed customers’ personal information and dental health data. DentaQuest, part…

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass. The affected ranges are =2.32.0,

Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprhensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies. “For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers…

Ranked by Customer Reviews and Star Ratings Report Date: July 18, 2026 Data Sources: Amazon customer reviews, expert testing reports, consumer ratings Methodology: Analysis of 59,491+ customer reviews across major TV brands on Amazon.com Top 10 List (Customer Rating ⭐ / Review Count) #1: LG OLED C5 evo (Fire TV Edition) ⭐⭐⭐⭐⭐ 4.6 stars Size Range:…

Booz Allen Hamilton has announced an expansion of its powerful suite of AI-powered cyber defense products. Now generally available, Vellox Ranger provides automated, environment-specific threat detections, developed on Booz Allen’s proprietary agentic AI framework, that identify exploitable paths and vulnerabilities based on the actual state of an enterprise’s infrastructure. This automation helps protect the systems…

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs “secure document” lures to deliver legitimate remote monitoring and management (RMM) tools. “The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened,” ZeroBEC said in
EZQuest’s Pro Series 8-in-1 hub runs on Intel’s low-cut but high feature Hoover Ridge chipset, and two months in, it hasn’t let me down.
Security researchers who discovered and reported CVE-2026-54121 (aka “Certighost”), a critical privilege elevation vulnerability in Active Directory Certificate Services (AD CS), have released a proof-of-concept (PoC) exploit for and technical details related to the flaw. The vulnerability AD CS is a Microsoft Windows Server role that lets an organization run its own Public Key Infrastructure…

A vulnerability in Microsoft’s Active Directory Certificate Services (AD CS) could allow a low-privilege domain user to impersonate a Domain Controller, security researchers have warned. Dubbed Certighost, the flaw stems from an enrollment fallback mechanism known as a “chase,” which the Certification Authority (CA) uses during directory-object resolution. This mechanism could be used to trick…

Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj, a Ruby JSON parser with a native C implementation, into full command execution inside…
EFF says most smart wearables lack basic privacy protections, with Apple standing out for end-to-end encryption and transparency. Most smart wearables still treat privacy like an optional extra, and that’s a problem. The Electronic Frontier Foundation (EFF)’s review of major smart watches, rings, and bands makes the case plainly: these devices collect deeply personal health…

OpenAI is noticeably absent from the list of initial supporters of a new industry initiative to promote the creation of strong, safe, defensive AI cybersecurity tools built on open-source platforms. The Open Secure AI Alliance is an initiative of Nvidia with the backing of over 30 major AI makers and users, including Cisco, Databricks, Dell…

Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, according to Check Point’s Q2 2026 Brand Phishing Report. Fake ChatGPT…
As organizations continue to invest in hybrid work, cloud applications, digital workplace initiatives, and now generative AI tools, many IT leaders are turning to digital employee experience (DEX) platforms to better understand how technology affects employee productivity and satisfaction. DEX tools have evolved from simple endpoint monitoring products into sophisticated platforms that combine device, application,…
Google Search indexed public Claude AI chat links, letting people find shared conversations through the site query before those listings disappeared soon after.

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote
Big Tech isn’t buying the AI future with profits. It’s buying it with payroll. Related: Microsoft normalizes credential exposure The verdict is in. Wall Street hates the tradeoff. Roytburg Fortune’s Eva Roytburg laid it out last week in a piece on Big Tech’s AI spending. AI has pushed the biggest companies on earth into spending…
Spring Boot exposes the endpoint “/actuator/heapdump” to collect debug information. By default, the endpoint will return a file heapdump.hprof, which includes a binary heapdump that can be used to analyze the current state of the application. Non-Java readers may be familiar with a similar concept, core dumps, which are produced by binaries to expose a memory…
Guardrails cannot serve as the primary security boundary for AI agents. Identity controls impose firmer limits.
I have sat in on a version of the same incident post-mortem in three sectors over the past two years. The script does not vary much. At 4:47 a.m. on a Saturday, an on-duty SOC analyst sees a ransomware payload spreading across three servers in the data center. The playbook says isolate. They hit the…

In this post, I will discuss why longer passwords are better and other online banking security tips. According to the 2025 Global Digital Report, the Philippines now ranks first globally in the regular use of online financial services, with the vast majority of internet users actively managing money through digital platforms each month. That level…

AWS DevOps Agent helps administrators inspect logs, review firewall rules and network paths, identify configuration changes that caused AWS Network Firewall to block traffic, and restore connectivity. The service is an AI-powered operations assistant for DevOps and SRE teams that investigates and troubleshoots application and infrastructure issues. It connects to monitoring tools, logs, code repositories,…
In cybersecurity, defenders sometimes naively assume that threat actors operate from secure, resilient infrastructures insulated from the very chaos they inflict on others. The 2026 compromise of Klue challenges that assumption. What began as a software-as-a-service supply chain breach evolved into an exceptional case in which a second criminal group claimed to have compromised the…

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, and BINDCLOAK, according to Zscaler ThreatLabz. The cybersecurity firm said it detected the campaign earlier this…

GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a release is published before opening a pull request. “The cooldown configuration option in the dependabot.yml still controls the behavior, though, so you can choose a different cooldown parameter that fits your project,” the Microsoft-owned subsidiary…