Google’s Threat Intelligence Group (GTIG), Mandiant, and partners disrupted a global espionage campaign attributed to a suspected Chinese threat actor that used SaaS API calls to hide malicious traffic in attacks targeting telecom and government networks. […]
Category: AI
AI, Cybersecurity, Exploits, Global Security News
Claude Code Flaws Allow Remote Code Execution and API Key Exfiltration
Cybersecurity researchers have disclosed multiple security vulnerabilities in Anthropic’s Claude Code, an artificial intelligence (AI)-powered coding assistant, that could result in remote code execution and theft of API credentials. “The vulnerabilities exploit various configuration mechanisms, including Hooks, Model Context Protocol (MCP) servers, and environment variables – executing
AI, Exploits, Global Security News
Threat actor leveraged Cisco SD-WAN zero-day since 2023 (CVE-2026-20127)
A “highly sophisticated” cyber threat actor has been exploiting a zero-day authentication bypass vulnerability (CVE-2026-20127) in Cisco Catalyst SD-WAN Controller (formerly vSmart), Cisco has announced today. The vulnerability was reported by Australian Signals Directorate’s Australian Cyber Security Centre, who said that once the vulnerability was exploited, “the malicious actors add[ed] a rogue peer, and eventually…
AI, Apps, Global Security News, Network Security
MWC: When it comes to 6G, Apple is a leader, not a follower
Does anyone remember when Apple was about to collapse because it didn’t offer 5G iPhones? Well, things have changed since then and as we make our way toward the 6G network transition expected in 2030 or so, Apple is ready to take part. How do I know this? Because Apple will have a presence at…
AI, Compliance, Cybersecurity, Data Breaches, Global Security News
News alert: One Identity fills CFO-COO role to strengthen operating discipline amid expansion
ALISA VIEJO, Calif., Feb. 25, 2026, CyberNewswire—One Identity, a trusted leader in identity security, today announced the appointment of Michael Henricks as Chief Financial and Operating Officer. This decision reflects the continued growth of the business and a focus on aligning financial leadership with operational objectives as One Identity scales. “As One Identity accelerates its growth, the addition of a Chief Financial and Operating Officer will strengthen how we plan, operate, and invest…
AI, Global Security News
Malicious Next.js Repos Target Developers Via Fake Job Interviews
Linked to North Korean fake job-recruitment campaigns, the poisoned repositories are aimed at establishing persistent access to infected machines.
AI, Data Breaches, Global Security News
ShinyHunters Claims Odido NL and Ben.nl Breach as Company Confirms Cyberattack
ShinyHunters claims 21 million records stolen in Odido NL and Ben.nl data breach as telecom company confirms cyberattack impacting customer contact system data.
AI, Global Security News, malware
Fake Zoom meeting leads to silent install of surveillance software
Malwarebytes researchers have uncovered a fake (but convincing) Zoom meeting page that downloads surveillance software on Windows computers and tricks users into running it. According to Microsoft MVP Steven Lim, the page has claimed nearly 1,500 victims in 12 days. The trick Potential victims likely visit the page (at uswebzoomus[.]com/zoom/) after getting a meeting invite/link…
AI, Global Security News, Network Security
Lamipak Boosts Global Supply Chain Performance and Resilience With Blue Yonder
COMPANY NEWS: Leading aseptic packaging company will implement Blue Yonder Network to drive greater agility, efficiency and cost savings
AI, Cybersecurity, Global Security News
Marquis sues SonicWall over backup breach that led to ransomware attack
Marquis Software Solutions has filed a lawsuit against SonicWall, accusing the cybersecurity company of gross negligence and misrepresentation that allegedly led to a ransomware attack disrupting operations at 74 U.S. banks. […]
AI, Global Security News
Manhattan Associates Predicts Five Retail & Supply Chain Trends That Will Reshape Australian Commerce in 2026
GUEST RESEARCH: AI’s ‘slow climb,’ unified commerce acceleration and mobile-first POS set to redefine the local retail landscape
AI, Global Security News
UiPath Joins Agentic AI Foundation (AAIF) to Advance Interoperability in Agentic AI Adoption
Will collaborate with other member organisations to develop and expand open protocols, tooling, and best practices for agent-based AI systems
AI, Global Security News
KleanNara Partners with Rimini Street to Accelerate Digital Transformation
COMPANY ANNOUNCEMENT: South Korea’s leading paper manufacturer cuts ERP support costs and improves response times with Rimini Street’s AI-driven solutions
AI, Global Security News, privacy
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We’ve shared how Android’s proactive, multi-layered scam defenses utilize Google AI to protect users around the world from over 10 billion suspected malicious calls and messages every month1. While that scale is significant,…
AI, Apps, Global Security News
VAST Data Introduces End-to-End Fully Accelerated AI Data Stack with NVIDIA
VAST AI OS will leverage NVIDIA libraries to accelerate both compute and data services for RAG, vector search, real-time SQL, and agentic applications
AI, Global Security News
SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks
The notorious cybercrime collective known as Scattered LAPSUS$ Hunters (SLH) has been observed offering financial incentives to recruit women to pull off social engineering attacks. The idea is to hire them for voice phishing campaigns targeting IT help desks, Dataminr said in a new threat brief. The group is said to be offering anywhere between…
AI, Apps, Global Security News, Network Security
Netskope NewEdge AI Fast Path reduces latency for enterprise AI workloads
Netskope has announced NewEdge AI Fast Path, a set of capabilities designed to optimize network paths to critical AI destinations, including applications hosted in public, private, or neo-cloud environments. The offering reduces latency and costs, improves performance and resilience, and delivers a secure experience for teams using AI applications or enterprises adopting agentic AI. Eliminating…
AI, Exploits, Global Security News, Risk Management
The OpenClaw Hype: Analysis of Chatter from Open-Source Deep and Dark Web
OpenClaw has sparked heavy Telegram and dark web chatter, but Flare’s data shows more research hype than mass exploitation. Flare explains how its telemetry found real supply-chain risk in the skills marketplace, yet limited signs of large-scale criminal operationalization. […]
AI, Apps, Compliance, Data Breaches, Exploits, Global Security News, Network Security, Risk Management
12.4 Million Accounts Exposed in CarGurus Leak
Millions of CarGurus users may have had their personal and financial data exposed after a notorious threat actor group published a massive dataset allegedly stolen from the automotive marketplace. Attributed to the ShinyHunters extortion group, the leak includes 12.4 million records with about 70% of those being new data. “The ShinyHunters extortion group has published…
AI, Global Security News, Network Security
Myriad360 Adds Advizex as AI Work Gets Harder to Run
Myriad360 just announced the acquisition of Advizex Technologies, forming a larger combined company across enterprise infrastructure, AI platforms, and managed services. Together, the two companies represent more than $900 million in annual run-rate gross revenue. Companies share mutual focus on enterprise but with complementary technical expertise Both companies have been working on many of the…
AI, Endpoint, Global Security News, Risk Management
SentinelOne addresses identity risk across endpoints, browsers, and AI workflows
SentinelOne has unveiled its Singularity Identity portfolio designed to secure the growing population of non-human identities, including AI agents, service accounts, APIs, and workloads. Identity attacks have long been a go-to tactic for nation-state actors and cybercriminals. Most defenses focus on stopping them at authentication and permissions. Attackers continue adapting their tactics to bypass those…
AI, Compliance, Global Security News, Risk Management
Just 22% of Australian employees are sticking to company AI-approved tools, says latest Qualtrics report
GUEST OPINION: Almost four out of five Australians are defying company policy and using unauthorised AI tools creating potential security and compliance risks, according to the 2026 Qualtrics Employee Experience Trends Report.
AI, Global Security News
44% Surge in App Exploits as AI Speeds Up Cyberattacks, IBM Finds
IBM’s 2026 X-Force report reveals 44% rise in cyberattacks on public apps, driven by AI and flaws
AI, Global Security News, Risk Management
Veza expands platform with AI Access Agents for enterprise identity governance
Veza expanded its platform with Veza Access Agents, a set of purpose-built AI agents designed to automate complex identity and access governance tasks for enterprises. Veza also announced advancements to its AI Agent Security product, providing organizations with deeper visibility into agent risks and greater control over third-party AI agents, large language models (LLMs), AI…
AI, Compliance, Global Security News, Risk Management
FormAssembly Expands Partner Program for Regulated Industries
FormAssembly, an enterprise data collection and automation provider, has launched its enhanced Partner Program to accelerate growth and expand business opportunities for its partners. Meeting the demand for secure, automated workflows According to FormAssembly, the program provides partners with specialized tools and resources to serve organizations operating in highly regulated industries. This includes firms in…
AI, Global Security News
Zoom introduces Virtual Agent 3.0 to automate end-to-end customer resolution
COMPANY NEWS: New virtual agent capabilities reduce customer effort, prevent repeat contacts, and give service leaders confidence to scale automation With 43% of consumers saying chatbots fail to resolve their issues, Zoom Virtual Agent 3.0 can help organisations close that gap
AI, Global Security News
Why ‘Call This Number’ TOAD Emails Beat Gateways
Attackers are bypassing email gateways through telephone-oriented attack delivery (TOAD), in which the only email payload is a phone number.
AI, Cybersecurity, Data Breaches, Global Security News
AI-First Businesses are Paying an “AI Speed Tax” when Recovering from Cybersecurity Incidents, according to Fastly’s Global Security Research Report
GUEST RESEARCH: Fast moving AI adopters are paying the price with 100 day longer recovery times, higher breach costs and expanding attack surfaces
AI, Global Security News, Risk Management
Commvault Intros Bi-Directional Integration with CrowdStrike
Commvault, a unified resilience platform provider, has announced an expanded integration with CrowdStrike that delivers bi-directional visibility between Commvault Cloud and CrowdStrike Falcon Next-Gen SIEM. The collaboration is designed to help security and IT teams verify backup integrity, enabling faster, safer, and better-informed recovery decisions. Making informed, trusted recovery decisions According to Commvault, the integration…
AI, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacks
Would-be attackers spent 2025 swimming in a sea of more than 40,000 newly published vulnerabilities, VulnCheck said in a report released Wednesday, but only 1% of those defects, just 422, were exploited in the wild. As the deluge of vulnerabilities grows every year, and CVSS ratings lose significance for vulnerability management prioritization, some defenders are…
AI, Apps, Global Security News
Thoughtworks and IDC Report Reveals Most Organisations Trapped in Costly Legacy Cycles; Only 12% Achieve True AI-Driven Operations
GUEST RESEARCH: Thoughtworks, a global technology consultancy integrating design, engineering and AI to drive digital innovation, today released findings from its global report, titled; “Modernisation Is No Longer a Project: AI-Enabled Managed Services for Continuous Change.” The data reveals a critical disconnect between AI adoption and maturity in IT operations. The report delves into what separates…
AI, Apps, Endpoint, Global Security News
After OpenClaw backlash, Quill bets on security-by-design agentic AI
It’s clear users are hungry for agentic tools — but AI agents like OpenClaw have shown how disastrous they can be when hastily rolled out or improperly executed. Quill, an AI startup, hopes to do better with what it calls “a chief of AI staff,” Quilliam. Rather than just transcribing meetings or logging Slack conversations,…
AI, Compliance, Global Security News, Network Security
Structured Launching Partner Marketing Execution Platform
Structured is announcing the debut of its AI-native Partner Marketing Execution Platform (PMEP), built to help enterprises activate and scale partner ecosystems. Mult-agent PMEP promises to accelerate channel revenue With this platform, Structured aims to remove the friction that has slowed partner marketing, which traditionally has relied on partners logging into portals, searching content libraries,…
AI, Compliance, Cybersecurity, Endpoint, Global Security News, Risk Management
Beachhead Solutions Unveils ComplianceEZ 2.0 for MSPs
Beachhead Solutions has launched ComplianceEZ 2.0, a major update to its compliance management tool built into the BeachheadSecure for MSPs platform. The company says the new version moves beyond simple documentation and delivers full lifecycle management of cybersecurity compliance, with AI-driven guidance included at no extra cost. Beachhead positions ComplianceEZ 2.0 as MSP-focused GRC alternative…
AI, Global Security News
AMD and Nutanix Announce Strategic Partnership to Advance an Open and Scalable Platform for Enterprise AI
COMPANY ANNOUNCEMENT: AMD and Nutanix sign multi-year agreement to accelerate adoption of Nutanix-powered agentic AI platform on AMD accelerated compute infrastructure for enterprise AI and service providers AMD to invest and fund up to $250 million in Nutanix shares, and R&D and go-to-market for integrated solutions Joint roadmap to integrate AMD ROCm™ and AMD Enterprise AI software into…
AI, Global Security News, Network Security
Zyxel warns of critical RCE flaw affecting over a dozen routers
Taiwan networking provider Zyxel has released security updates to address a critical vulnerability affecting over a dozen router models that can allow unauthenticated attackers to gain remote command execution on unpatched devices. […]
AI, Global Security News
Akamai Secures Critical Infrastructure with Agentless Zero Trust Segmentation Powered by NVIDIA
Akamai Guardicore Segmentation and NVIDIA BlueField integration ends the long-standing trade-off between advanced security and system performance for energy, manufacturing, and transportation sectors
AI, Global Security News
LevelBlue research: CIOs accelerate AI-driven transformation amid rising threat complexity
GUEST RESEARCH: New report finds just 20% of CIOs feel highly effective at defending against AI-enabled adversaries.
AI, Global Security News
New Relic Closes Gaps Between Data, Insight and Action with SRE Agent and AI-Strengthened Platform Innovations
COMPANY NEWS: Evolution of intelligent automation enables enterprises to move beyond observing problems towards autonomously solving them SRE Agent augments a workforce, freeing up engineers to focus on high-value strategic decisions instead of toil Innovations create future-proof incident response toolset where engineers lead strategy, make key decisions, and validate solutions in powerful collaboration with AI
AI, Apps, Cybersecurity, Global Security News
Malicious NuGet Packages Stole ASP.NET Data; npm Package Dropped Malware
Cybersecurity researchers have discovered four malicious NuGet packages that are designed to target ASP.NET web application developers to steal sensitive data. The campaign, discovered by Socket, exfiltrates ASP.NET Identity data, including user accounts, role assignments, and permission mappings, as well as manipulates authorization rules to create persistent backdoors in victim applications.
AI, Global Security News, Network Security, Risk Management
Australia’s WiseTech to cut 2,000 jobs as AI renders manual coding obsolete
Australian logistics software firm WiseTech Global plans to eliminate around 2,000 jobs as it embeds artificial intelligence across its engineering and customer service operations, the company said Wednesday. The cuts, which will begin in the second half of FY26 and extend into FY27, will “reduce teams – initially product & development and customer service across…
AI, Global Security News, privacy
Reddit fined $19.5 million for failing to protect children’s personal data
The UK’s Information Commissioner’s Office (ICO) has fined Reddit $19.5 million after finding that the company failed to use children’s personal information lawfully, exposing them to inappropriate and harmful content. The investigation found that Reddit did not apply an age assurance mechanism and therefore did not have a lawful basis for processing the personal information…
AI, Apps, Data Breaches, Global Security News, privacy, Risk Management
ShinyHunters cyberattack on CarGurus impacts 12.4 Million users
ShinyHunters leaked data from 12.4M CarGurus accounts, exposing personal information from the U.S.-based auto research and shopping platform. The ShinyHunters group published personal data from over 12 million CarGurus accounts. CarGurus is a U.S.-based digital automotive marketplace that helps users research, compare, and connect with sellers of new and used vehicles. Operating in the U.S.,…
AI, Endpoint, Exploits, Global Security News, malware, Network Security, Risk Management
Microsoft warns of job‑themed repo lures targeting developers with multi‑stage backdoors
Microsoft says it has uncovered a coordinated campaign targeting software developers through malicious repositories posing as legitimate Next.js projects and technical assessments. The campaign employs carefully crafted lures to blend into routine workflows, such as cloning repositories, opening projects, and running builds, thereby allowing the malicious code to execute undetected. Telemetry collected during an incident…
AI, APAC, china, Cybersecurity, Europe, Funding, Global Security News, Government & Policy, malware, Network Security, Risk Management
Across party lines and industry, the verdict is the same: CISA is in trouble
“Decimated.” “Amateur hour.” “Pretty much fallen apart.” “It’s really hard to find something positive to say right now.” It’s been a little more than one year into the second Trump administration, and there’s a large consensus, if not total unanimity, among those who have worked with and for the Cybersecurity and Infrastructure Security Agency: It…
AI, Global Security News
3 future Android features you can give yourself today
Here in the land o’ Android, things are always evolving — and it isn’t only because of big operating system updates. Thanks to the way Google’s for years now been deconstructing Android and pulling OS-level pieces out of the operating system itself — so they exist as regular ol’ apps and can consequently be updated…
AI, Cybersecurity, Data Breaches, Endpoint, Global Security News, malware, Network Security, Risk Management
Turn Your SOC Into a Detection Engine: Rethinking Threat Monitoring
Threat monitoring is treated as one capability among many. Something that sits alongside incident response and threat hunting on an org chart. That framing undersells how central it actually is. Monitoring is the connective tissue of the entire security operation. Every other SOC function depends on it working well. For SOC and MSSP leaders, building effective threat monitoring is not about “more alerts.” It…
AI, Apps, Exploits, Global Security News, Government & Policy, Russia
Former U.S. Defense contractor executive sentenced for selling zero-day exploits to Russian broker Operation Zero
A former employee at U.S. defense contractor L3Harris got over 7 years in prison for selling eight zero-days to a Russian broker. Peter Williams, a 39-year-old Australian former L3Harris employee, received a prison sentence of just over seven years for selling eight zero-day exploits to the Russian broker Operation Zero for millions. Williams pleaded guilty…
AI, Apps, Compliance, Data Security, Global Security News, Risk Management
A Practical Guide to Microsoft Copilot for MSPs
If you’re an MSP considering adding Microsoft Copilot to your portfolio in 2026, it’s worth being deliberate about how you package and position it for clients. For many organizations, pitching AI as a novel “productivity booster” is no longer enough. Customers increasingly expect the conversation to shift from experimentation to execution, anchored in defined use…
AI, china, Global Security News, Government & Policy, Russia
Chinese group’s ChatGPT use reveals worldwide harassment campaign against critics
A Chinese law enforcement official attempted to use ChatGPT to review its reports on cyber operations, subsequently revealing details of a worldwide online harassment and silencing campaign of China’s critics at home and abroad. In a new threat report released Wednesday, OpenAI said the activity concerned a single account that regularly used ChatGPT to review…
AI, Global Security News
Apple blocks 18+ app downloads in select markets
Apple has introduced expanded age assurance tools to help developers comply with regulations taking effect in Brazil, Australia, Singapore, Utah, and Louisiana. The updates, available in beta, expand the Declared Age Range API and related App Store systems. Age-based download restriction As of February 24, 2026, Apple began blocking users from downloading apps rated 18+…
AI, Compliance, Global Security News, Government & Policy, Risk Management
Anthropic targets core business systems with new Claude plug-ins
Anthropic is expanding its push into the enterprise market with a new set of “coworker” plug-ins designed to embed its Claude AI directly into tools used by investment bankers, HR teams, and engineers, signaling a shift from standalone assistants toward AI agents that operate inside core business workflows. In a blog post, the company said…
AI, Global Security News
ICO’s £14m Reddit Fine Highlights Age Check Privacy Concerns
The UK’s ICO has fined Reddit over £14m for failing to use children’s personal information lawfully
AI, Global Security News
Ukrainian convicted for helping fake North Korean IT workers
A Ukrainian man has been sentenced to five years in prison after helping North Korean IT workers infiltrate American companies using stolen identities, reports Bleepingcomputer. The 39-year-old man from Kiev pleaded guilty in November 2025 to charges including aggravated identity theft and conspiracy to commit fraud. He has also agreed to surrender assets worth over…
AI, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
U.S. CISA adds a flaw in Soliton Systems K.K FileZen to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in Soliton Systems K.K FileZen to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Soliton Systems K.K FileZen flaw, tracked as CVE-2026-25108 (CVSS v4 score of 8.7), to its Known Exploited Vulnerabilities (KEV) catalog. Soliton Systems K.K. FileZen is a…
AI, Exploits, Global Security News, Russia
Defense Contractor Employee Jailed for Selling 8 Zero-Days to Russian Broker
A 39-year-old Australian national who was previously employed at U.S. defense contractor L3Harris has been sentenced to a little over seven years in prison for selling eight zero-day exploits to Russian exploit broker Operation Zero in exchange for millions of dollars. Peter Williams pleaded guilty to two counts of theft of trade secrets in October…
AI, APAC, Global Security News, Government & Policy, malware
Lazarus APT group deployed Medusa Ransomware against Middle East target
North Korea’s Lazarus Group used Medusa ransomware in an attack on an unnamed Middle East organization, researchers report. The North Korea-linked Lazarus APT Group, also known as Diamond Sleet and Pompilus, has been spotted deploying Medusa ransomware against an unnamed organization in the Middle East, according a new report from the Symantec and Carbon Black…
AI, APAC, Cybersecurity, Data Breaches, Global Security News, Risk Management, Russia
Boards don’t need cyber metrics — they need risk signals
Security teams live in a world of numbers. Dashboards depict counts of blocked attacks, phishing clicks, vulnerabilities discovered, patches applied, alerts triaged, and incidents closed. Over the past decade, the cybersecurity industry has become adept at measuring activity with increasing precision. Experts say what remains far less consistent is whether those measurements help boards govern…
AI, Global Security News, privacy, Risk Management
With attention shifting to AI smart glasses, VR faces another reality check
As tech vendors shift their attention to AI-enabled smart glasses, the momentum behind virtual reality (VR) headsets appears to slowing once again. It’s not the first time the technology has seen expectations outstrip real-world demand. An initial wave of interest in the early 1990s generated predictions of mainstream adoption, before fading as the decade progressed. …
AI, Cybersecurity, Funding, Global Security News, Venture
Cyber valuations climb as capital concentrates, AI security expands
Venture funding in cybersecurity continued to concentrate in large private rounds at the end of 2025, driving valuations higher across stages. Data from DataTribe shows total capital invested approached $150 billion for the year, with a disproportionate share flowing into fewer than 100 deals. Cybersecurity investment areas (Source: PitchBook) In Q4 alone, fewer than 100…
AI, Apps, Global Security News
Microsoft adds domain libraries and Copilot integration to the quantum development kit
The Microsoft Quantum Development Kit (QDK) is an open-source toolkit that runs on laptops and in common development environments. It includes code, simulators, libraries, and workflows that work with Visual Studio Code and GitHub Copilot. Integration with these tools gives developers features for writing, testing, debugging, and submitting quantum code. The QDK supports multiple programming…
AI, Global Security News
Airline brands become launchpads for phishing, crypto fraud
Airline brands sit at the center of peak travel booking cycles, loyalty programs, and high value transactions. Criminal groups continue to register thousands of lookalike domains tied to these brands, targeting travelers, employees, and business partners. Recent threat intelligence from BforeAI’s PreCrime Labs identifies sustained impersonation activity across the global commercial airline sector. Between September…
AI, Exploits, Global Security News
Edge systems take the brunt of internet-wide exploitation attempts
Internet-facing VPNs, routers, and remote access services absorbed sustained exploitation attempts throughout the second half of 2025, with nearly 3 billion malicious sessions recorded over 162 days. The concentration on edge infrastructure aligns with how attackers pursue initial access across the public internet. GreyNoise’s State of the Edge data set covers 2.97 billion sessions observed…
AI, Apps, Cybersecurity, Data Breaches, Exploits, Global Security News, Government & Policy, malware, Network Security, Risk Management
New Serv-U bugs extend SolarWinds’ run of high-severity disclosures
SolarWinds continues to be besieged by security issues, this time in its Serv-U managed file transfer server. The software company has released four patches for critical Serv-U remote code execution (RCE) vulnerabilities that could allow attackers to gain root (administrator) access to unpatched servers. These four common vulnerabilities and exposures (CVEs) are rated “critical,” the…
AI, Apps, Global Security News, malware, Network Security
Fake Zoom meeting silently installs surveillance software, says Malwarebytes
The latest fake Zoom meeting scam silently pushes surveillance software onto the Windows computers of unwitting employees. That’s according to researchers at Malwarebytes, who warn that staff falling for the scam land in a convincing imitation of a Zoom video call. Moments later, an automatic “Update Available” countdown downloads a malicious installer, without asking permission.…
AI, Compliance, Global Security News
AI agent platforms could push down SaaS license costs, report argues
A suggestion by Anthropic that its Claude Code tool could be used to automate the modernization of an antediluvian programming language, COBOL, still an important sideline for IBM six decades after it was first deployed, sent IBM stock tumbling on Monday. The company suffered a 13.2% drop in its stock price, its biggest fall since…
AI, Global Security News
FULL VIDEO: From Fatal Chatbots to Big Tech Lobbying: Australia’s AI Expert Toby Walsh Warns of “Depressing” AI Future
Leading Australian AI expert Professor Toby Walsh has expressed outrage over ChatGPT offering to write a suicide note for a troubled teen who took his life in April 2025.
AI, Exploits, Global Security News, Network Security, Risk Management
VMware fixes command injection flaw in Aria Operations
VMware has released patches for several high- and medium-risk vulnerabilities that impact its Aria Operations, Cloud Foundation, Telco Cloud Platform, and Telco Cloud Infrastructure products. The most serious of these flaws allows unauthenticated attackers to execute arbitrary commands on the underlying OS, while another gives authenticated users the ability to elevate to administrator privileges. The…
AI, Global Security News
Tech Firms Aren’t Just Encouraging Their Workers to Use AI. They’re Enforcing It.
From small startups to giants including Meta and Google, tech companies are factoring AI use into performance reviews and trying to track productivity gains.
AI, Global Security News
Anthropic Dials Back AI Safety Commitments
The company said competitive pressure prompted it to pivot away from the previous, more-cautious positioning.
AI, Europe, Global Security News
Phishing campaign targets freight and logistics orgs in the US, Europe
A financially motivated threat group dubbed “Diesel Vortex” is stealing credentials from freight and logistics operators in the U.S. and Europe in phishing attacks using 52 domains. […]
AI, Global Security News
The AI Chip War You Didn’t See Coming
The growing competition between Google and Nvidia, Anthropic makes nice with software and AI is powering trade-secret theft..
AI, Global Security News, Government & Policy, malware, Network Security
What does business email compromise look like?
Business email compromise (BEC) is the digital con dressed to impress. It’s clean, calculated, and ready to fool even the sharpest eyes. These scammers don’t tell on themselves with sloppy hacks. They whisper in familiar voices, posing as your CEO, HR, or a trusted vendor. And, unlike phishing, they’re a precision strike built on inside…
AI, Apps, Cybersecurity, Endpoint, Exploits, Global Security News, malware, Network Security
What are the types of ransomware attacks?
Ransomware isn’t an isolated, potential cyber threat—it’s like a living organism that can shapeshift with multiple strains, tactics, and targets. The cybercriminals behind ransomware attacks run these operations like a business and are motivated to keep up profits at any cost. Their tactics range from quickly locking down an entire network to slowly leaking sensitive…
AI, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, malware, Network Security, Risk Management
Take control: Locking down common endpoint vulnerabilities
Attackers are constantly on the prowl, scoping out vulnerabilities of network-connected devices in your systems. These devices—laptops, desktops, servers, IoT, and more—are like unlocked doors waiting for threat actors to stroll through. And here’s the kicker: many of these vulnerabilities are shockingly common and easily preventable. Let’s break down the weaknesses we most frequently track…
AI, Global Security News
1Campaign platform helps malicious Google ads evade detection
A newly identified cybercrime service known as 1Campaign is enabling threat actors to run malicious Google Ads that remain online for extended periods while evading scrutiny from security researchers. […]
AI, Cybersecurity, Exploits, Global Security News, Government & Policy, Russia
Ex-L3Harris executive sentenced to 87 months in prison for selling zero-day exploits to Russian broker
An ex-L3 Harris executive was sentenced to over seven years in prison Tuesday after pleading guilty to selling eight zero-day exploits to a Russian broker in exchange for millions of dollars. Williams, 39, admitted to two counts of theft of trade secrets in U.S. District Court in Washington, D.C., last year, acknowledging he took at…
AI, Data Breaches, Global Security News, Network Security
Attackers Now Need Just 29 Minutes to Own a Network
Credential misuse, AI tools, and security blind spots help attackers move through breached networks faster than ever, CrowdStrike finds.
AI, Global Security News
“AI” Grates and the Clash of the Crafting Titans
Has the addition of “AI” engagements improved the customer experience? Is the Raspberry Pi cooked?
AI, Compliance, Endpoint, Global Security News, malware, Risk Management
How to prevent business email compromise
Business email compromise (BEC) is the cyber equivalent of an expertly forged handwritten note—no malware fireworks, no flashing warnings, just a convincing request that tricks someone into wiring money or handing over sensitive data. Knowing how to prevent BEC should sit at the top of every security to‑do list because even one fraudulent email can…
AI, Cybersecurity, Endpoint, Exploits, Global Security News, Risk Management
Know the red flags: Business email compromise signs to look out for
When it comes to cyber threats, business email compromise (BEC) is one of the sneakiest, most costly scams out there. These digital predators don’t rely on brute force, but are patient, tactical, and they exploit one weakness above all: human trust. If you’re in the cybersecurity game, spotting a BEC attack can mean the difference…
AI, APAC, Apps, Data Breaches, Exploits, Global Security News, Network Security, Risk Management
VMware Aria Vulnerabilities Expose RCE Risk
Broadcom has disclosed three vulnerabilities in VMware Aria Operations, including one that could allow unauthenticated remote code execution during product migrations. One of the flaws, CVE-2026-22719, can allow an attacker “… to execute arbitrary commands which may lead to remote code execution in VMware Aria Operations while support-assisted product migration is in progress,” said Broadcom…
AI, Cybersecurity, Global Security News, Network Security, Risk Management
Asimily Expands Channel Enablement With New Partner Tier
Provider of the Next Generation Exposure Management Platform for IoT, OT, and IoMT environments, Asimily, has recently announced the next generation of its global partner strategy, introducing a new partner tier to accelerate high-performing strategic partners and expand enablement across connected ecosystems. Partner program updates include ‘In Flight’ tier The new tier will be called…
AI, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
SolarWinds patches four critical Serv-U flaws enabling root access
SolarWinds addressed four critical Serv-U vulnerabilities that could let attackers gain root access to unpatched servers. SolarWinds released updates fixing four critical Serv-U vulnerabilities that allow remote code execution, potentially giving attackers full root access on unpatched servers. Serv-U is a file transfer server software that allows organizations to securely transfer files over networks using…
AI, Apps, Cloud Security, Cybersecurity, Endpoint, Global Security News, malware, Risk Management
Cyber defense: From reactive to proactive
When systems are attacked, we should respond. But how much better would it be if we could anticipate attacks before they strike and stop them with a proactive defense? Faced with today’s cybersecurity challenges, that is no simple task. “It’s a cat-and-mouse situation. AI is changing the speed and sophistication of attacks, and AI is…
AI, Exploits, Global Security News
RoguePilot Flaw in GitHub Codespaces Enabled Copilot to Leak GITHUB_TOKEN
A vulnerability in GitHub Codespaces could have been exploited by bad actors to seize control of repositories by injecting malicious Copilot instructions in a GitHub issue. The artificial intelligence (AI)-driven vulnerability has been codenamed RoguePilot by Orca Security. It has since been patched by Microsoft following responsible disclosure. “Attackers can craft hidden instructions inside a
AI, Cybersecurity, Global Security News
11 Best MCP Gateways in 2026: In-Depth Comparison
In this post, I will show you the 11 best MCP gateways in 2026. Unlike the AI assistants of just one year ago, AI agents in 2026 don’t just answer questions; they act. AI agents can now connect to your databases, query your internal tools, read and write to your SaaS platforms, and make decisions…
AI, Global Security News
Look! Up in the sky! It’s a bird! It’s a plane! No it’s a Super fast train.
The Sydney to Newcastle fast rail link project is ready to leave the station. If the $230million initiative is delivered, the journey could shrink from 2.5 hours to around one hour, transforming connectivity, productivity and regional growth across New South Wales.
AI, Cybersecurity, Data Breaches, Global Security News
7 Top ISO 27001 Certification Providers
In this post, I will show you the 7 top ISO 27001 certification providers. Data breaches are something companies must be prepared for, so they are seeking more robust cybersecurity through certifications. ISO 27001 is an international standard that helps organizations strengthen their security protocols. Obtaining an ISO 27001 certification shows that a business is…
AI, Global Security News
Open Redirects: A Forgotten Vulnerability?, (Tue, Feb 24th)
In 2010, OWASP added “Unvalidated Redirects and Forwards” to its Top 10 list and merged it into “Sensitive Data Exposure” in 2013. Open redirects are often overlooked, and their impact is not always well understood. At first, it does not look like a big deal. The user is receiving a 3xx status code and is…
AI, Compliance, Global Security News, Government & Policy, Risk Management
Apple plans to make Mac minis in the US
Illustrating the extent to which it is willing to work with the Trump Administration — and as President Donald J. Trump prepares for tonight’s State of the Union address — Apple now says it will begin to make Mac minis in Houston later this year. The Macs will be made at the same factory where the company now…
AI, Global Security News
Microsoft adds Copilot data controls to all storage locations
Microsoft is expanding data loss prevention (DLP) controls to block the Microsoft 365 Copilot AI assistant from processing confidential Word, Excel, and PowerPoint documents, regardless of their location. […]
AI, Global Security News, Risk Management
Anthropic Claims Chinese AI Firms ‘Distilled’ Claude to Train Their Models
Anthropic claims Chinese AI firms distilled Claude to train rival AI models, raising concerns about model extraction, security risks, and AI distillation abuse.
AI, Global Security News
Cost of Insider Incidents Surges 20% to Nearly $20m
DTEX claims insider incidents cost $19.5m in 2025, with employee negligence most expensive
AI, Compliance, Global Security News, Risk Management
News alert: Sendmarc highlights impact of DMARC update on evolving email security standards
WILMINGTON, Del., Feb. 24, 2026, CyberNewswire — Sendmarc has released a new fireside chat featuring Todd Herr, Principal Solutions Architect at GreenArrow Email and co-editor of DMARCbis, on the upcoming update to DMARC (Domain-based Message Authentication, Reporting, and Conformance). Led by Dan Levinson of Sendmarc, the fireside chat explains how the protocol is progressing through the IETF (Internet Engineering Task Force) standards…
AI, Apps, Data Breaches, Endpoint, Exploits, Global Security News, Network Security, Risk Management
Google Patches Three High-Severity Chrome Flaws
Google has released a security update for its Chrome browser that addresses three high-severity vulnerabilities, which could pose risk to users. One of the vulnerabilities, CVE-2026-3061, allows “… a remote attacker to perform an out-of-bounds memory read via a crafted HTML page,” said NIST in its advisory. Inside the Chrome Vulnerabilities The security update addresses…
AI, APAC, Compliance, Endpoint, Global Security News, Network Security, privacy, Risk Management
What Is a Security Data Pipeline Platform: Key Benefits for Modern SOC
Security teams are drowning in telemetry: cloud logs, endpoint events, SaaS audit trails, identity signals, and network data. Yet many programs still push everything into a SIEM, hoping detections will sort it out later. The problem is that “more data in the SIEM” doesn’t automatically translate into better detection. It often translates into chaos. Many…
AI, Global Security News, Risk Management
Breaking Down the Viral Memo That Spooked Markets
Citrini Research’s post on AI risks appears to have sparked a stock selloff.
AI, Data Breaches, Global Security News, Russia
Amazon: Low-Skill Hacker Used AI Tools to Breach FortiGate Devices Globally
Amazon says a Russian speaking low-skill hacker used AI tools to breach hundreds of FortiGate devices worldwide, showing how AI can scale cyberattacks with basic methods.
AI, Global Security News, Risk Management
Forescout VistaroAI replaces prompt engineering with role-based AI automation
Forescout introduced Forescout VistaroAI, which thinks like a security expert instead of a chatbot. It eliminates the need for prompt engineering by delivering role-based automation with human-in-the-loop control, resulting in faster, more accurate risk decisions and an improved user experience compared to prompt-driven AI assistants. Forescout VistaroAI provides users with a personalized view of the…
