For all the fancy-schmancy things our modern-day technology promises to do for us, one thing Google has yet to give us is a simple and reliable way to sync the clipboards on our Android phones and computers. It’s such a powerful feat to have at your fingertips, when it works well — ’cause you can…
Category: AI
AI, Apps, Cybersecurity, Exploits, Global Security News, Government & Policy, Network Security
Anthropic bets on EPSS for the coming bug surge
Anthropic’s Mythos has intensified a problem that vulnerability management programs were already struggling to contain: too many vulnerabilities and not enough clarity about which ones matter. What changes with Mythos — and the AI-based class of vulnerability discovery systems it represents — is the speed at which software flaws can be found and exploited. That…
AI, Global Security News, Government & Policy, malware, Network Security
Venezuela energy sector targeted by highly destructive Lotus wiper
Lotus Wiper hit Venezuelan energy systems, used scripts to disable defenses, then erased all data beyond recovery. Kaspersky researchers found Lotus Wiper targeting Venezuela’s energy and utilities sector amid regional tensions in 2025–2026. Attackers first used batch scripts to weaken systems, disable defenses, and prepare the environment. Then they deployed the wiper, which erased recovery…
AI, Global Security News
Cohere AI Terrarium Sandbox Flaw Enables Root Code Execution, Container Escape
A critical security vulnerability has been disclosed in a Python-based sandbox called Terrarium that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-5752, is rated 9.3 on the CVSS scoring system. “Sandbox escape vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal,” according…
AI, Global Security News, Network Security
The 6 Best Partner Relationship Management (PRM) Software in 2026
Partner Relationship Management (PRM) software is a type of B2B solution designed to help companies manage and optimize their partner relationships. The best PRM platforms typically include features such as partner management, lead distribution, deal registration, and incentives and rewards management to drive better outcomes. In this guide, we’ll explore the top PRM software solutions…
AI, APAC, Global Security News
Microsoft trims cloud desktop pricing, even as it boosts AI costs
For years now, Microsoft has been doing its level best to move you from desktop Office and Windows to Microsoft 365, Windows 365, and Azure Virtual Desktop (AVD). Since the company first started down this road, however, something changed: the AI revolution, which has become a huge deal for the guys from Redmond. So, it…
AI, Exploits, Global Security News
Over 1,300 Microsoft SharePoint servers vulnerable to spoofing attacks
Over 1,300 Microsoft SharePoint servers exposed online remain unpatched against a spoofing vulnerability that was exploited as a zero-day and is still being abused in ongoing attacks. […]
AI, Endpoint, Global Security News
Kaseya Heads Into Connect with New CEO, API, and AI Strategy
Kaseya is coming into this year’s Connect conference after a year of significant change across its leadership team, platform strategy, and product roadmap. Since the 2025 event, the company has appointed a new CEO, adopted an API-first approach to improve integration across its portfolio, and rolled out new AI-focused product updates. As attendees gather for…
AI, Global Security News
PentAGI: Open-source autonomous AI penetration testing system
Penetration testers have long relied on collections of specialized tools, manual coordination, and documented runbooks to work through a target assessment. PentAGI, an open-source project from VXControl, attempts to automate that entire workflow using a multi-agent AI system that plans, researches, and executes penetration tests with minimal human direction. How the agent system works PentAGI…
AI, Global Security News, privacy
Apple Intelligence flaw kept stolen tokens reusable on another device
Apple claims that Apple Intelligence, a GenAI service provided on its operating systems, is designed with an extra focus on user security and privacy through a two-stage authentication and authorization system using anonymous access tokens. However, researchers from The Ohio State University have identified vulnerabilities in this design, demonstrated on macOS 26.0 (Tahoe), that allow…
AI, Data Breaches, Global Security News
Shadow AI, deepfakes, and supply chain compromise are rewriting the financial sector threat playbook
Financially motivated attacks continued to drive the bulk of cyber incidents against banks, insurers, and payment processors in 2025. Approximately 90% of breaches affecting financial institutions carried a financial motive, with data breaches accounting for roughly 64% of incidents and ransomware making up the remaining 36%. The average cost of a data breach in the…
AI, Global Security News
What a New Apple CEO Will Mean for You and Your Devices
With incoming chief John Ternus, Apple is doubling down on hardware in the age of AI.
AI, Global Security News, Network Security
Adobe builds an ‘agentic content supply chain’ for the AI era
Generative AI is fundamentally (and quickly) shaping how information is discovered and acted on, forcing enterprises to rethink how they engage with both humans and machines. Adobe is responding to this shift, introducing new tools that keep up with evolving branding, surface campaign insights, and speed up content creation. At this week’s Adobe Summit, the…
AI, Cloud Security, Compliance, Cybersecurity, Global Security News, privacy, Risk Management
Winter 2025 SOC 1 report is now available with 184 services in scope
Amazon Web Services (AWS) is pleased to announce that the Winter 2025 System and Organization Controls (SOC) 1 report is now available. The report covers 184 services over the 12-month period from January 1, 2025 – December 31, 2025, giving customers a full year of assurance. This report demonstrates our continuous commitment to adhering to…
AI, Cybersecurity, Exploits, Global Security News, malware, Network Security, privacy, Risk Management
[Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)
[This is a Guest Diary by L. Carty, an ISC intern as part of the SANS.edu Bachelor’s Degree in Applied Cybersecurity (BACS) program [1].] Introduction A few weeks ago, my honeypot logged an incident that changed how I think about modern attacks. A threat actor broke into my system using weak SSH credentials and immediately…
AI, Global Security News, Russia
It’s a bird it’s a plane – Oh dear me.
“Excuse me… this is a bit rude.” Firstly with all the negative things happening in the world perhaps a naughty prank can tickle our fancy. Many of the major news agencies have published this story, so what the heck, I will do the same. Here is what happened. Finnish Air Force cadets are facing disciplinary action after…
AI, Global Security News
SpaceX Secures Option to Buy AI Startup Cursor For $60 Billion
After acquiring xAI, the rocket company says close work in coding partnership could lead to combination.
AI, Global Security News
GIGABYTE Collaborates with NVIDIA® on GeForce RTX™ 50 Series and PRAGMATA™ Bundle
GIGABYTE, the world’s leading computer brand, announces the collaboration with NVIDIA for the PRAGMATA™ GeForce RTX 50 Series game bundle across eligible graphics cards, desktops, and laptops powered by NVIDIA GeForce RTX™ 5070 or above GPUs and Laptop GPUs. Powered by NVIDIA Blackwell architecture, the GeForce RTX™ 50 Series GPUs bring game-changing capabilities to gamers.…
AI, Global Security News
Billions on the line: Why SMS-based MFA is no longer fit for Crypto
Cryptocurrency was established with a clear value proposition: decentralisation, transparency and mathematical certainty. However, when it comes to user authentication, many exchanges, wallets and trading platforms still depend on one of the weakest links in digital security: SMS-based multi-factor authentication. For an industry protecting billions of dollars in digital assets, that gap is no longer…
AI, Data Breaches, Global Security News, Government & Policy
French govt agency confirms breach as hacker offers to sell data
France Titres, the government agency in France for issuing and managince administrative documents has disclosed a data breach after a threat actor claimed the attack and stealing citizen data. […]
AI, Apps, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, Risk Management
$293M KelpDAO Crypto Heist Exposes Cross-Chain Weaknesses in DeFi
A $293 million cryptocurrency theft has rocked the decentralized finance (DeFi) ecosystem, with KelpDAO at the center of an attack now suspected to be linked to North Korea’s Lazarus Group. The attack highlights how quickly sophisticated attackers can exploit weaknesses in cross-chain infrastructure. “Preliminary indicators suggest attribution to a highly sophisticated state actor, likely DPRK’s…
AI, Data Breaches, Exploits, Global Security News
Former DigitalMint ransomware negotiator pleads guilty to extortion scheme
A South Florida man pleaded guilty to conspiring with multiple ransomware affiliates to commit attacks against and extort payments from the same U.S. companies he represented as a ransomware negotiator for DigitalMint in 2023, the Justice Department said Monday. Angelo John Martino III shared confidential information about victim organizations’ internal negotiating positions and insurance policy…
AI, Cybersecurity, Global Security News
Ransomware negotiator caught secretly assisting BlackCat extortion scheme
Angelo Martino pleaded guilty to helping BlackCat ransomware group while acting as a ransomware negotiator. Another U.S. cybersecurity expert, Angelo Martino, admitted helping the BlackCat ransomware group while working as a ransomware negotiator. Angelo Martino (41) admitted helping the BlackCat ransomware group while working for a U.S. incident response firm. “A Florida man, formerly employed…
AI, APAC, Apps, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security
Thousands of Apache ActiveMQ instances still unpatched, weeks after an actively exploited hole discovered
Two weeks after researchers using an AI tool discovered a major hole in Apache’s ActiveMQ messaging middleware, there are still thousands of unpatched instances open to the internet, more evidence that many application developers and IT leaders aren’t paying close attention to warnings about vulnerabilities. While the remote code injection vulnerability [CVE-2026-34197] was revealed on…
AI, Global Security News
Why Australia’s AI boom demands a new era of energy efficiency
GUEST OPINION: As we commemorate Earth Day 2026 under the theme of “Our Power, Our Planet,” business leaders in Australia are facing a profound reality check.
AI, Global Security News
You can now test and compare AI models on LinkedIn
LinkedIn is testing a new AI feature, Crosscheck, which allows users to compare several popular AI models directly on the platform. Users enter prompts into Crosscheck and receive two different responses generated by competing AI models from companies such as OpenAI, Anthropic, and Google. After the user selects the best response, the model behind each…
AI, Global Security News
Thunderbird 150 arrives with encrypted message search and OpenPGP improvements
Released today, Thunderbird 150.0 brings eight new features, a round of bug fixes, and security patches that cover the web engine underlying the email client. Thunderbird 150.0 runs on Windows 10 or later, macOS 10.15 or later, and Linux with GTK+ 3.14 or higher. Encrypted email gets more useful Two of the most notable additions…
AI, Global Security News
TrendAI partners with Anthropic to extend leadership in AI security
Trend Micro’s enterprise business accelerates its transformation as AI security category leader
AI, Exploits, Global Security News
Exploits Turn Windows Defender into Attacker Tool
Three proof-of-concept exploits are being used in active attacks against Microsoft’s built-in security platform; two are unpatched.
AI, Global Security News, Network Security, Russia
Scottish man pleads guilty to attack spree that created Scattered Spider’s notoriety
A core leader of the hacker subset of The Com responsible for a series of high-profile phishing attacks and cryptocurrency thefts from September 2021 to April 2023 pleaded guilty to federal charges, the Justice Department said Friday. Tyler Robert Buchanan of Dundee, Scotland, pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft.…
AI, Cybersecurity, Global Security News, Risk Management
Lawmakers ponder terrorism designations, homicide charges over hospital ransomware attacks
Lawmakers at a hearing Tuesday explored ways to beef up punishments for ransomware attacks against hospitals, possibly by labeling them as more severe crimes. One proposal floated at the House Homeland Security Committee hearing, to treat ransomware attacks as terrorism, is an idea Congress has flirted with before. Another would be to press prosecutors to…
AI, Global Security News, malware
New Lotus data wiper used against Venezuelan energy, utility firms
A previously undocumented data-wiping malware dubbed Lotus was used last year in targeted attacks against energy and utilities organizations in Venezuela. […]
AI, Data Breaches, Exploits, Global Security News
North Korea’s Lazarus APT stole $290M from Kelp DAO
North Korea-linked Lazarus Group stole $290M from Kelp DAO by abusing LayerZero. A second $95M attempt was stopped. Hackers tied to the North-Korea linked group Lazarus APT carried out a $290M crypto theft targeting Kelp DAO. Earlier today we identified suspicious cross-chain activity involving rsETH. We have paused rsETH contracts across mainnet and several L2s…
AI, Global Security News
SpeakON makes a Bluetooth voice tool that actually understands how people communicate
There’s no shortage of AI-powered “note-taking” devices right now. From meeting recorders to transcription tools, the category is crowded with products that promise to capture everything you say and turn it into something useful later. SpeakON takes a different path – and it’s a smarter one.
AI, Global Security News, Network Security
VirtualBox 7.2.8 is out with Linux kernel 7.0 support and crash fixes
Oracle shipped VirtualBox 7.2.8 on April 21, 2026, as a maintenance release covering crashes, networking problems, clipboard issues, and extended Linux kernel compatibility. The update touches the VMM layer, NAT networking, graphics, UEFI, and both Linux and Windows guest support. VMM and core stability A Guru Meditation error carrying the code VERR_IEM_IPE_4 is fixed in…
AI, Data Breaches, Global Security News, malware, Network Security, Risk Management
130K Users Compromised by StealTok Campaign That Uses Fake TikTok Downloaders
A widespread browser extension campaign is quietly compromising users by disguising data-stealing tools as TikTok video downloaders. “While many people see browser extensions as harmless little widgets, oftentimes they have no idea who is actually behind these extensions, and what capabilities they contain within their source code,” said Natalie Zargarov, security researcher at LayerX in…
AI, Apps, Global Security News, Network Security
COO Mark Cree Outlines Scale Computing’s Edge Platform Push
Scale Computing used its Platform//2026 Summit to position its expanded edge computing platform alongside new partner growth opportunities as it looks to move beyond its roots in virtualization. In an interview at the event, President and COO Mark Cree outlined how the company is evolving into a full-stack edge provider spanning compute, networking, security, and…
AI, Cybersecurity, Global Security News
Can You Get Banned for Using Story Viewers?
In this post, I will answer the question – can you get banned for using story viewers? People worry about story viewers for a reason. Instagram makes normal Story views visible to the account owner, warns users to be careful with third party apps and websites, and says data scraping goes against its Terms of…
AI, Global Security News
The AI Spending Spree is Far from Over
Plus, Amazon goes deeper with Anthropic and bets grow on Intel’s AI resurgence
AI, Apps, Compliance, Cybersecurity, Data Breaches, Funding, Global Security News, Network Security, Risk Management, Venture
AI is one of the two monumental shifts in cyber today
It’s 2026, when nobody can confidently say what the future of security is going to look like. Everyone is trying (what else can we do), but judging by all the progress around AI in recent months, we are all going to be wrong. The biggest mistake we all make is assuming that the future is…
AI, Global Security News, Risk Management
BeyondTrust’s 13th Annual Microsoft Vulnerabilities Report Reveals Drop in Total Volume, But Surge in Critical Risk
GUEST RESEARCH: Critical vulnerabilities doubled year-over-year, signalling rising risk severity as AI-driven discovery and expanding attack surfaces reshape the Microsoft security landscape Elevation of Privilege vulnerabilities accounted for 40% of all flaws, continuing to dominate threat actor pathways and reinforcing identity as the primary attack vector Azure and Dynamics 365, saw a 9x increase in…
AI, Exploits, Global Security News
Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk
The critical remote code execution flaw (CVE-2026-1731) in the remote monitoring and management tool can be exploited to spread ransomware and compromise supply chains.
AI, Global Security News
PCI SSC Launches Enhanced Language Microsites for Global Audience
The PCI Security Standards Council (PCI SSC) has announced the launch of newly redesigned language microsites, delivering a more accessible, structured, and user-friendly experience for global stakeholders. These updates mark a significant step forward in making PCI resources more readily available to non-English-speaking audiences by providing a consistent user experience across languages.
AI, Cybersecurity, Global Security News
Ransomware negotiator admits role in attacks he was hired to resolve
A Florida man, formerly employed as a ransomware negotiator, pleaded guilty to conspiring to carry out ransomware attacks against US companies. Prosecutors say Angelo Martino, 41, used his position at DigitalMint, a crypto broker that helps victims negotiate and pay ransomware demands, to pass sensitive information to attackers. Alongside Martino, two more individuals were involved…
AI, Global Security News
Google Fixes Critical RCE Flaw in AI-Based Antigravity Tool
The prompt injection vulnerability in the agentic AI product for filesystem operations was a sanitization issue that allowed for sandbox escape and arbitrary code execution.
AI, APAC, Global Security News
In the Rush to Scale AI, Operational Limits Are Emerging, Datadog Report Finds
Nearly 1 in 20 AI requests fail in production as capacity limits become the primary bottleneck to scaling AI reliably
AI, APAC, Data Breaches, Global Security News, Network Security
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
A 24-year-old British national and senior member of the cybercrime group “Scattered Spider” has pleaded guilty to wire fraud conspiracy and aggravated identity theft. Tyler Robert Buchanan admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology…
AI, Global Security News, Network Security
Extreme Platform ONE Reduces Network Costs by 32%, Enterprise Adoption Gains Momentum
GUEST RESEARCH: Asiana Airlines, City of Prescott in Arizona, and SK Biosciences among many customers choosing Extreme Platform ONE to accelerate automation at scale
AI, Global Security News
Elastic Delivers First Embedded AI Experiences for Observability and Security Inside Third-Party AI Tools
MCP Apps bring Elastic’s security and observability workflows into third-party AI tools, enabling teams to act on data directly where they work, with additional capabilities for search and data exploration
AI, Global Security News, Government & Policy
Vehicle tracking is no longer just about finding a vehicle
GUEST OPINION: Vehicle tracking used to mean knowing where a vehicle was. That idea is still the core, but the job has expanded well beyond a dot on a map. In government fleet programs, telematics now reaches into real-time location, trip history, geofencing, driver coaching, maintenance reminders, fault data, and even accident reconstruction. That is…
AI, Global Security News
Snowflake Expands Snowflake Intelligence and Cortex Code to Power the Control Plane for the Agentic Enterprise
COMPANY NEWS: Snowflake delivers agentic AI for both business users and builders on a single platform with Snowflake Intelligence and Cortex Code Snowflake Intelligence transforms how business users turn insights into action through a personalised, context-aware AI agent grounded in enterprise data Cortex Code enables builders to move faster from code to production with AI-powered…
AI, Global Security News
Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023
A third individual who was employed as a ransomware negotiator has pleaded guilty to conducting ransomware attacks against U.S. companies in 2023. Angelo Martino, 41, of Land O’Lakes, Florida, teamed up with the operators of the BlackCat ransomware starting in April 2023 to assist the e-crime gang in extracting higher amounts as ransoms. “Working as…
AI, Endpoint, Global Security News
GitLab Collaborates with AWS to Bring Agentic DevSecOps to Enterprise Teams Using Their Existing Amazon Bedrock Accounts and Spend
COMPANY NEWS: Customers can route GitLab Duo Agent Platform inference through Amazon Bedrock models already running in their AWS accounts without new vendor onboarding or model endpoints. GitLab Credits purchased through AWS Marketplace count toward existing AWS spending commitments. GitLab’s Bring Your Own Model (BYOM) capability for Self-Managed customers lets teams connect their self-hosted AI…
AI, Global Security News
Entrust Integrates Australia’s Document Verification Service (DVS) to Support AML/CFT-Ready Identity Verification
News Summary: Under Tranche 2 reforms, Australia’s AML/CTF regime will undergo its most significant expansion in nearly two decades. All reporting entities will need to strengthen identity verification and customer due diligence processes. Entrust Identity Verification unifies Australia DVS checks, biometrics, and AI‑driven fraud controls for all‑in‑one Australia-ready identity verification.
AI, Global Security News
Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency
A British national tied to the Scattered Spider cybercrime group pleaded guilty to hacking multiple companies via SMS phishing and stealing over $8 million in virtual currency from US victims. Tyler Robert Buchanan, 24, of Dundee, Scotland, pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. In November 2024, US authorities unsealed…
AI, Cloud Security, Global Security News
Unchecked AI Agents Cause Cybersecurity Incidents at Two Thirds of Firms
Data exposure, operational disruption and financial losses among issues faced by businesses struggling with the rapid rise of AI agents, warns Cloud Security Alliance report
AI, Apps, Endpoint, Exploits, Global Security News, Risk Management
Why API Discovery Is the First Step to Securing AI
TL;DR AI risk doesn’t live in the model. It lives in the APIs behind it. Every AI interaction triggers a chain of API calls across your environment. Many of those APIs aren’t documented or tracked. That’s your real exposure. Shadow API discovery gives you visibility into those hidden endpoints, so you can find them before…
AI, Compliance, Global Security News, Government & Policy
Kamiwaza Expands ARIA Through TD SYNNEX, HPE Channel
Kamiwaza AI is bringing its ARIA accessibility remediation platform to the TD SYNNEX channel alongside HPE, positioning MSPs and resellers to help public sector customers meet fast-approaching digital accessibility deadlines, including the April 24, 2026 ADA Title II compliance requirement. Channel opportunity tied to accessibility mandates for government websites The timing is notable for partners…
AI, Global Security News, Risk Management
Ivanti Neurons AI automates IT operations, reducing manual work and security risk
Ivanti has revealed new solution capabilities, focusing on enabling autonomous IT operations and organizations to secure their environments more efficiently at scale. With these advancements, Ivanti enables IT and security operations to detect, decide, and act autonomously without sacrificing trust, governance, or control. AI capabilities and the threat landscape are changing quickly, and IT and…
AI, Global Security News
Silobreaker Mimir adds agentic AI to intelligence workflows with governance and transparency
Silobreaker has announced new agentic AI capabilities that combine faster research and deeper contextual analysis with built-in governance and transparency to ensure trusted intelligence can be safely consumed across the wider enterprise. Silobreaker Mimir is an embedded agentic capability for intelligence operations, working directly within the analyst workflow. It helps teams retrieve evidence, deepen analysis,…
AI, Apps, Cybersecurity, Endpoint, Exploits, Global Security News, Network Security
Azure SRE Agent flaw let outsiders silently eavesdrop on enterprise cloud operations
A high-severity authentication flaw in Microsoft’s Azure SRE Agent exposed sensitive agent data to unauthorized network access, according to a confirmed vulnerability disclosure. The issue was identified by Enclave AI researcher Yanir Tsarimi, who detailed the findings in a blog post describing how agent interactions could be accessed without proper authentication controls. The vulnerability has…
AI, Exploits, Global Security News, Government & Policy
CISA flags new SD-WAN flaw as actively exploited in attacks
CISA has given U.S. government agencies four days to secure their systems against another Catalyst SD-WAN Manager vulnerability it flagged as actively exploited in attacks. […]
AI, Global Security News, privacy
OpenAI’s Chronicle feature lets Codex read your screen, raising privacy concerns
OpenAI’s Chronicle is a feature designed to help Codex, an AI-powered coding assistant, better understand what users are working on by capturing context directly from their screens. It uses recent screen activity to build memories, allowing Codex to interpret references, identify relevant sources, and pick up on the tools and workflows users rely on, without…
AI, Exploits, Global Security News, Network Security
Prompt injection turned Google’s Antigravity file search into RCE
Security researchers have revealed a prompt injection flaw in Google’s Antigravity IDE that could be weaponized to bypass its sandbox protections and achieve remote code execution (RCE). The issue came from Antigravity’s ability to allow AI agents to invoke native functions, like searching files, on behalf of the user. Designed to kill complexity, the feature…
AI, Global Security News
With John Ternus as CEO, expect Apple’s platforms to proliferate
Apple now has a new iCEO, as current leader Tim Cook (65) announced late Monday that he is set to become chairman of the board, while current head of hardware engineering, John Ternus, prepares to take over as CEO on Sept. 1. As you’d expect, this leadership transition at one of the world’s most successful firms, is…
AI, Cybersecurity, Data Breaches, Exploits, Global Security News
No Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
The cybersecurity industry has spent the last several years chasing sophisticated threats like zero-days, supply chain compromises, and AI-generated exploits. However, the most reliable entry point for attackers still hasn’t changed: stolen credentials. Identity-based attacks remain a dominant initial access vector in breaches today. Attackers obtain valid credentials through credential stuffing
AI, Global Security News
OpenAI Is Working With Consultants to Sell Codex
The ChatGPT maker said it has four million weekly active users for its AI coding tool, up from three million two weeks ago.
AI, Apps, Cybersecurity, Global Security News, malware
NGate Campaign Targets Brazil, Trojanizes HandyPay to Steal NFC Data and PINs
Cybersecurity researchers have discovered a new iteration of an Android malware family calledNGate that has been found to abuse a legitimate application called HandyPay instead of NFCGate. “The threat actors took the app, which is used to relay NFC data, and patched it with malicious code that appears to have been AI-generated,” ESET security researcher Lukáš…
AI, Cybersecurity, Exploits, Funding, Global Security News, Government & Policy, Network Security, Risk Management
The US NSA is using Anthropic’s Claude Mythos despite supply chain risk
Axios reports the National Security Agency uses Anthropic Mythos model despite Department of Defense concerns, blurring AI risk vs defense lines. The reported use of Anthropic’s Mythos model by the U.S. National Security Agency is a reminder that the line between AI as a defensive tool and AI as a security risk is getting harder…
AI, Apps, Cybersecurity, Europe, Global Security News, Risk Management
Report: Enterprises Rely on Managed Services to Scale AI
New research has found that an overwhelming majority of executives view managed services as essential for the delivery of agentic AI. Boosting AI with managed services According to the global KPMG Managed Services Outlook Survey 2026, more than 90 percent of executives believe managed services are essential to their agentic AI journeys, and 87 percent…
AI, Cybersecurity, Exploits, Global Security News
Mythos can find the vulnerability. It can’t tell you what to do about it.
Mythos matters. It is a significant step forward in AI-assisted vulnerability discovery. But it does not mean cybersecurity changed overnight, nor does it mean enterprises are suddenly facing fully automated exploitation at internet scale tomorrow. It does mean the offensive side of AI is continuing to improve. The defensive side needs to catch up now.…
AI, Apps, Global Security News, Network Security, privacy, Risk Management
Why identity is the driving force behind digital transformation
Identity centric technologies have undergone a significant transformation in recent times. Gone are the days when it was all about logging in and out of any given system. Today, identity has become the backbone of all digital enterprises. It’s the ‘invisible engine’ that powers everything. From security to how modern-day products are sold. Today’s Identity…
AI, Data Breaches, Global Security News, Network Security
Grinex crypto exchange shuts down, blames Western agencies for $13.7M breach
Grinex exchange collapses after $13.7M breach, blames Western spies as Chainalysis flags possible exit scam and sanctions evasion network links claims.
AI, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, malware, Network Security, Risk Management
U.S. CISA adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco Catalyst, Kentico Xperience, PaperCut NG/MF, Synacor ZCS, Quest KACE SMA, and JetBrains TeamCity flaws to its Known…
AI, Cybersecurity, Endpoint, Exploits, Global Security News, malware, Network Security, Risk Management
Top techniques attackers use to infiltrate your systems today
Much of the talk around cybersecurity these days revolves around AI and the threat it poses to corporate systems when used by nefarious actors. But the reality on the ground remains a little more mundane than polymorphic AI malware and criminal masterminds putting machine learning and generative AI to work at scale. Still, keeping on…
AI, Apps, Global Security News, malware
NGate NFC malware targets Android users through trojanized payment app
NFC-based payment fraud is expanding geographically and operationally. A campaign active since November 2025 is targeting Android users in Brazil using a new variant of the NGate malware family, this time embedded in a trojanized version of HandyPay, a legitimate NFC relay application available on Google Play since 2021. ESET Research identified the campaign and…
AI, china, Cybersecurity, Data Breaches, Exploits, Global Security News, Government & Policy, Network Security, Russia, Venture
The thin gray line: Handala, CyberAv3ngers and Iran’s proxy ops
On April 7, six US government agencies issued a critical advisory warning domestic private sector organizations of potential infrastructural cyberattacks conducted by Iranian-affiliated Advanced Persistent Threat (APT) actors. The advisory stops short of attributing these threats to a single group but makes reference to 2023 attacks on US water and wastewater facilities linked to the…
AI, Global Security News, malware
New NGate variant hides in a trojanized NFC payment app
ESET researchers discover another iteration of NGate malware, this time possibly developed with the assistance of AI
AI, Apps, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, malware, Network Security, Risk Management
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses
Editor’s note: The research is authored by Mauro Eldritch, offensive security expert and a founder of BCA LTD, a company dedicated to threat intelligence and hunting. You can find Mauro on X. The recent wave of ClickFix attacks has introduced several new ways to compromise users, establishing itself as a technique that is likely here to stay. We have observed Lazarus Group using…
AI, Data Breaches, Global Security News, Government & Policy, Network Security
Bluesky hit by 24-hour DDoS attack as pro-Iran group claims responsibility
Bluesky suffered a 24-hour DDoS attack that caused outages. A pro-Iran hacker group claimed responsibility for the disruption. Bluesky experienced a sophisticated DDoS attack that disrupted its services for about 24 hours, starting on April 15. Bluesky is a decentralized, open-source microblogging social media platform similar to X (formerly Twitter). It allows users to post…
AI, Global Security News, malware
A .WAV With A Payload, (Tue, Apr 21st)
There have been reports of threat actors using a .wav file as a vector for malware. It’s a proper .wav file, but they didn’t use staganography. The .wav file will play, but you’ll just hear noise: That’s because the TAs have just replaced the bytes that encode the sound with the BASE64 representation of their…
AI, Global Security News
Researchers build an encrypted routing layer for private AI inference
Organizations in healthcare, finance, and other sensitive industries want to use large AI models without exposing private data to the cloud servers running those models. A cryptographic technique called Secure Multi-Party Computation (MPC) makes this possible. It splits data into encrypted fragments, distributes them across two or more servers that do not share information with…
AI, Apps, Cybersecurity, Global Security News
Cybersecurity jobs available right now: April 21, 2026
Application Security Engineer (DevSecOps / Azure DevOps) BEWAHARVEST | Philippines | Hybrid – View job details As an Application Security Engineer (DevSecOps / Azure DevOps), you will embed security across the SDLC by working with engineering and DevOps teams to implement automated security controls and testing. You will manage application security programs including SAST, DAST,…
AI, Global Security News
The Rise of Apple’s New CEO: A Hardware Expert Takes Over in the AI Era
John Ternus is a hardware expert who must help Apple catch up in the AI race as it looks for its next big hit.
AI, Global Security News, malware, Risk Management
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories
Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a broader supply chain risk.
AI, Global Security News
China’s Apple App Store infiltrated by crypto-stealing wallet apps
A set of 26 malicious apps on Apple App Store impersonate popular wallets, such as Metamask, Coinbase, Trust Wallet, and OneKey, to steal recovery or seed phrases and drain them of cryptocurrency assets. […]
AI, Global Security News
Apple Hardware Exec to Succeed Tim Cook as CEO
Plus, an Iran cease-fire extension looks unlikely, and a $150 train ride to the World Cup might feel red-card worthy.
AI, Data Breaches, Global Security News
Vercel Breach Linked to Context.ai, ShinyHunters Says It’s Not Involved
Vercel confirms a breach linked to Context.ai as a hacker lists alleged data for $2M. ShinyHunters denies involvement and flags imposters.
AI, Cybersecurity, Exploits, Global Security News, Network Security
Vuln in Google’s Antigravity AI agent manager could escape sandbox, give attackers remote code execution
As organizations consider agentic AI for their business and IT stacks, researchers continue to find bugs and vulnerabilities in major, commercial models that can significantly expand their attack surface. This week, researchers at Pillar Security disclosed a vulnerability in Antigravity, an AI-powered developer tool for filesystem operations made by Google. The bug, since patched, combined…
AI, Global Security News
Apple CEO Tim Cook stepping down, to be replaced by John Ternus
Apple announced late Monday that Tim Cook, the company’s CEO since 2011, is stepping down Sept. 1 to be replaced by current senior vice president of hardware engineering, John Ternus. Cook will become executive chairman of the board. Cook, who is 65, will continue as CEO until the end of August to assist in the…
AI, Compliance, Global Security News, privacy, Risk Management
The FTC’s AI portfolio is about to get bigger
The Federal Trade Commission is poised to deepen its involvement in curbing the use of AI for malicious purposes, including the spread of nonconsensual sexualized deepfakes and voice cloning scams. Last year, Congress passed the Take It Down Act, a law that allowed for criminal prosecution of individuals who share or distribute nonconsensual, intimate images…
AI, Global Security News
Apple Hardware Executive John Ternus to Become CEO
The longtime Apple insider is succeeding Tim Cook, who will become executive chairman.
AI, Apps, Cybersecurity, Data Breaches, Exploits, Global Security News, Government & Policy
France’s ANTS ID System website hit by cyberattack, possible data breach
A cyberattack hit France’s ANTS website, possibly exposing personal data from users applying for IDs, passports, and driver’s licenses. A cyberattack targeted France’s ANTS platform, which handles applications for passports, ID cards, residence permits, and driver’s licenses. Authorities detected the incident on April 15 and warned it may have exposed personal data from both individuals…
AI, Apps, Europe, Exploits, Global Security News, malware, Network Security, Risk Management
Cyberattack That Could Have Poisoned a City’s Water Supply by Manipulating Chlorine Levels
In mid-April 2026, researchers at Darktrace published a detailed breakdown of a malware sample that occupies a narrow but alarming niche in the threat landscape: a Windows-based OT weapon apparently designed from the ground up to sabotage Israeli water treatment and desalination infrastructure. The malware identifies itself internally as ZionSiphon — the name appears in a core…
AI, Apps, Data Breaches, Exploits, Global Security News, malware, Risk Management
Vercel’s security breach started with malware disguised as Roblox cheats
Vercel customers are at risk of compromise after an attacker hopped through multiple internal systems to steal credentials and other sensitive data, the company said in a security bulletin Sunday. The attack, which didn’t originate at Vercel, showcases the pitfalls of interconnected cloud applications and SaaS integrations with overly privileged permissions. An attacker traversed third-party…
AI, Global Security News, Network Security
Panasonic Connect introduces TOUGHBOOK 56 for Mobile Professionals
Panasonic Connect North America has launched the TOUGHBOOK 56, a modular rugged laptop designed to support mobile workers across a range of industries. The new device delivers high-performance computing, faster connectivity options, improved thermal management, and advanced security features for professionals in public safety, utilities, enterprise, and federal operations. Offering purpose-built machine to frontline professionals…
AI, Global Security News, Network Security
Procure IT & NetWolves Target Enterprise IT Expense Visibility
NetWolves has partnered with Procure IT to integrate its Managed Intelligence Platform into the provider’s Site Connectivity as a Service (SCaaS) offering, aiming to give large enterprises greater visibility into IT spending across vendors, contracts, and services. Why Procure IT and NetWolves formed the partnership The goal is to give Fortune 1000 companies and large…
AI, Global Security News
Global RAM shortage appears set to continue through 2027
The ongoing shortage of memory chips looks likely to continue throughout the year as demand from the AI sector surges. According to Nikkei Asia, leading manufacturers are expected to be able to meet only about 60% of global demand despite expansion plans. Although new factories are on the way, several of them are not expected…
AI, Apps, china, Compliance, Europe, Global Security News, Government & Policy
What Sovereign AI Means for MSPs and Channel Partners
As AI has all but reached widespread adoption, the conversation has shifted from novelty to who can properly regulate it. It’s no longer just private companies leading the charge. Governments and nations are now at the forefront of AI efforts, working to ensure that both innovation and security are maintained. That shift is creating a…
