Two South Korean teenagers have been charged in connection with a cyberattack that compromised the personal data of 4.62 million users of Seoul’s public bike service, Ttareungyi. The compromised data included user IDs, mobile phone numbers, addresses, dates of birth, gender, and weight. According to the Cyber Investigation Unit of the Seoul Metropolitan Police Agency,…
Category: AI
AI, Global Security News
Identity-First AI Security: Why CISOs Must Add Intent to the Equation
AI agents now provision infrastructure and approve actions, but many inherit over-scoped privileges without proper governance. Token Security explains why CISOs must treat agents as identities and add intent-based controls so access is granted only when purpose and context align. […]
AI, APAC, Compliance, Exploits, Global Security News, Risk Management
VMware Aria Operations flaws could enable remote attacks
Broadcom patched multiple VMware Aria Operations flaws, including high-severity issues that could enable remote code execution. Broadcom has released security updates to address multiple vulnerabilities affecting VMware Aria Operations. VMware Aria Operations is an IT operations management platform that helps organizations monitor and optimize virtual, cloud, and hybrid environments. It provides performance monitoring, capacity planning,…
AI, Compliance, Global Security News
Druva expands DruAI with autonomous agents for forensics and compliance
Druva announced a major expansion of DruAI, adding Deep Analysis Agents that automate complex multi-day forensic and compliance investigations. IT and security teams spend too much time not just fixing problems, but proving what happened and why across incident response, forensics, audits, and operational reviews. Much of that effort goes into manual correlation and report…
AI, Global Security News, Risk Management
Veeam Agent Commander unifies AI risk detection, protection, and recovery
Veeam Software announced Agent Commander, a unified solution to help organizations safely detect AI risk, protect AI systems, and undo AI mistakes, enabling them to proactively address AI-driven risks and securely scale AI agents everywhere. The first integration from Veeam’s acquisition of Securiti AI, Agent Commander combines the capabilities of both to give organizations visibility,…
AI, Global Security News
Anthropic Pushes Claude Deeper Into Knowledge Work
While the market remains rattled over how new AI tools threaten traditional software-as-a-service vendors, Anthropic pushes forward with new updates to its Claude Cowork platform.
AI, Global Security News
New Relic Agentic Platform brings governance and scale to AI agents
New Relic announced enterprise-grade Agentic Platform capabilities that enable organizations to build, deploy, and manage a full spectrum of AI agents and agentic workflows, from simple single-task automations to complex, multi-agent orchestrations. With an intuitive no-code builder for domain experts, New Relic’s Agentic Platform empowers enterprises to intelligently automate a wide range of processes, leading…
AI, Europe, Global Security News, Russia
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware
A Russia-aligned threat actor has been observed targeting a European financial institution as part of a social engineering attack to likely facilitate intelligence gathering or financial theft, signaling a possible expansion of the threat actor’s targeting beyond Ukraine and into entities supporting the war-torn nation. The activity, which targeted an unnamed entity involved in regional
AI, Exploits, Global Security News, Risk Management
Aikido Infinite introduces continuous, self-remediating AI penetration testing
Aikido Security has unveiled Aikido Infinite, a continuous AI penetration testing solution that autonomously validates and remediates vulnerabilities. Infinite reduces risk with every release by testing software changes as they move through deployment, confirming exploitability, and fixing vulnerabilities within the same workflow. Penetration testing often relies on manual or point-in-time assessments, frequently delivered weeks after…
AI, Cybersecurity, Global Security News, Risk Management
Exabeam Report: AI Key Driver in Cybersecurity Spend
Intelligence and automation enterprise, Exabeam, recently unveiled new findings from its multinational report, From Adoption to Accountability: The New Economics of AI in Cybersecurity. The survey obtained responses from 750 IT decision-makers responsible for security in organizations with 500+ employees across 12 countries. Cybersecurity budgets on the rise as AI alignment struggles to keep up…
AI, Compliance, Europe, Global Security News, Network Security
Zero Networks Goes 100% Channel, Boosts MSP Growth
Zero Networks is doubling down on the IT channel, announcing a full transition to a 100% channel-first go-to-market strategy alongside a significant expansion of its global partner ecosystem. The zero-trust security vendor said the move comes as demand grows for identity-driven containment designed to limit lateral movement and reduce the blast radius during cyberattacks—an increasingly…
AI, Compliance, Cybersecurity, Exploits, Global Security News, Risk Management
All Covered Launches Managed Vulnerability Service
All Covered, a division of Konica Minolta and a managed IT and managed security services provider, has launched a vulnerability remediation service designed to help organizations continuously identify, prioritize, and remediate security vulnerabilities before they can be exploited. Announced Feb. 24, the offering responds to growing demand from organizations, particularly in regulated industries such as…
AI, Global Security News, Risk Management
Index Engines: Ransomware Shifting To Polymorphism & Wiper Attacks
Cyber resilience solutions provider Index Engines has released a new study from its CyberSense Research Lab, finding that threat actors are increasingly using polymorphism, shadow encryption, and directory corruption in their attacks. Four ransomware developments observed in Q4 2025 According to the company, these techniques were used specifically to bypass traditional defenses, increase dwell time,…
AI, Cloud Security, Global Security News
Microsoft expands Sovereign Cloud security with governance, local productivity and AI
Microsoft expands Microsoft Sovereign Cloud with new disconnected and AI capabilities that help organizations run critical infrastructure, productivity services and large AI models inside sovereign boundaries while keeping governance and operational continuity across connected and disconnected environments. Sovereign Private Cloud unifies Azure Local, Microsoft 365 Local and Foundry Local, bringing infrastructure, productivity and support for…
AI, Global Security News, malware
Self-spreading npm malware targets developers in new supply chain attack
Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect projects, and propagate themselves across developer environments. The operation, dubbed “SANDWORM_MODE,” represents a (still) rare example of worm-like malware designed to spread through software supply chains rather than traditional end-user systems. New npm worm…
AI, Apps, Global Security News
What Gemini 3.1 Pro Means for Heavy-Duty AI Users
Google just introduced Gemini 3.1 Pro, the newest version of its flagship model which cracked the market back in November. Instead of optimizing for and spitting out quick replies, Gemini 3.1 Pro is designed to handle problems that require multiple steps and deeper reasoning. Google touts performance scoring as Gemini competes with GPT-5.2 Google ran…
AI, Cybersecurity, Global Security News
Exabeam Research: AI Accountability Becomes the New Mandate as Cybersecurity Economics Shift
GUEST RESEARCH: 95% of organisations are increasing cybersecurity budgets in 2026 with AI as the top spending driver despite being the hardest investment to justify
AI, Cybersecurity, Global Security News, Venture
As Cybersecurity Firms Chase AI, VC Market Skyrockets
Investments in cybersecurity startups took off in 2025, as venture capital firms focused not just on AI-native tech, but talent as well.
AI, Global Security News, Risk Management
KnowBe4 Launches AIDA Orchestration as the First Fully Autonomous Agent for Human Risk Management
New AI Agent From KnowBe4 Cuts Security Training Administration From Hours to Seconds
AI, Global Security News
AI Accelerates Attacker Breakout Time to Just Four Minutes
ReliaQuest claims AI has reduced breakout and exfiltration time to under 10 minutes
AI, Global Security News
What really caused that AWS outage in December?
For the first time, AWS has confirmed that one of its AI systems did indeed delete and recreate one of its environments in December, shutting down part of that service for about 13 hours. What happened behind the scenes — including an aggressive AWS statement against the media outlet that initially reported the issue —…
AI, Cloud Security, Global Security News
Cloud security misconceptions that continue to leave organisations exposed
GUEST OPINION: The cloud has revolutionised how businesses operate, providing scalability, flexibility, agility, and transparency. However, confidence in cloud security has not kept pace. Large-scale data exposures continue to trace back to basic errors such as publicly accessible storage, excessive permissions, and poor configuration. These failures highlight the persistent illusions about how cloud security works.
AI, Global Security News
Turnitin Data Shows Transparency About AI Use Benefits Students And Educators
GUEST RESEARCH: New insights show an increase in AI-generated writing by students, along with a high demand for feedback and responsible use
AI, Global Security News
Firmus Technologies Group Selects VAST AI Operating System to Power Sovereign, Energy-Efficient AI Factories in Asia Pacific
COMPANY ANNOUNCMENT: Infrastructure built on the NVIDIA Cloud Partner (NCP) reference design supporting large-scale AI training and inference for public-sector and regulated workloads
AI, Global Security News
Nvidia plans a Windows PC SoC, setting up direct competition with Qualcomm, Intel, and AMD
Nvidia is developing a system-on-chip (SoC) for Windows PCs, with Dell and Lenovo among the OEMs planning to build notebooks and desktops around the processor later this year. The chip would be based on the GB10, which Nvidia developed with MediaTek and launched in October 2025, the Wall Street Journal reported, citing people familiar with…
AI, Global Security News
New Relic Launches Agentic Platform, a No-code Solution to Build and Govern Custom AI Agents for Observability at Scale
COMPANY NEWS: Solution democratises AI by allowing SREs and Ops teams to build powerful AI agents, without writing code, to accelerate workstreams and automation Enterprises can now build, deploy, and manage a full spectrum of agents that move operations from passive observation to active task execution, directly within their observability stack
AI, Cybersecurity, Global Security News, Risk Management
Celebrating Two Years of CSF 2.0!
Celebrate this milestone with us! Email us at csf [at] nist.gov (csf[at]nist[dot]gov) or tag @NISTcyber on X telling us what your favorite CSF 2.0 resource is (or how your organization has benefitted from implementing the CSF 2.0). Today marks two years since the publication of the Cybersecurity Framework (CSF) 2.0! Published in 2024, the CSF…
AI, Global Security News
Cloudflare Becomes the First and Only SASE Platform to Support Modern Post-Quantum Encryption
New updates scale protection against the threat of advanced computing across the entire Internet—at no cost
AI, Global Security News, Risk Management
Identity Prioritization isn’t a Backlog Problem – It’s a Risk Math Problem
Most identity programs still prioritize work the way they prioritize IT tickets: by volume, loudness, or “what failed a control check.” That approach breaks the moment your environment stops being mostly-human and mostly-onboarded. In modern enterprises, identity risk is created by a compound of factors: control posture, hygiene, business context, and intent. Any one of…
AI, Global Security News
Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks
The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East, according to a new report by the Symantec and Carbon Black Threat Hunter Team. Broadcom’s threat intelligence division said it also identified the same threat actors mounting an…
AI, Exploits, Global Security News, malware, Risk Management
Shai-Hulud-style NPM worm hits CI pipelines and AI coding tools
A massive Shai-Hulud-style npm supply chain worm is hitting the software ecosystem, burrowing through developer machines, CI pipelines, and AI coding tools. Socket researchers uncovered the active attack campaign and called it SANDWORM_MODE, derived from the “SANDWORM_*” environment variable switches embedded in the malware’s runtime control logic.” At least 19 typosquatted packages were published under…
AI, Data Breaches, Global Security News
ShinyHunters extortion gang claims Odido breach affecting millions
The ShinyHunters extortion gang has claimed responsibility for breaching Dutch telecommunications provider Odido and stealing millions of user records from its compromised systems. […]
AI, Apps, china, Compliance, Exploits, Global Security News, Risk Management
Anthropic alleges large-scale distillation campaigns targeting Claude
Anthropic has accused three Chinese AI developers of running large-scale campaigns to illicitly extract capabilities from its Claude model to improve their own systems. The company claims DeepSeek, Moonshot, and MiniMax used a distillation technique, where a less capable model is trained on the outputs of a more advanced one. More than 16 million interactions…
AI, Global Security News
Chinese AI Firms Hit Claude with Distillation Attacks, Anthropic Warns
Anthropic accused DeepSeek, Moonshot and MiniMax of illicitly using Claude to steal some of the AI model’s capabilities
AI, Global Security News
Windows 365 for Agents brings managed cloud PCs to autonomous workflows
Microsoft’s Windows 365 for Agents is a cloud platform that gives AI agents secure access to cloud PCs. It lets builders run copilots, agents, and automated workflows in Windows environments without managing infrastructure. The platform includes security, policy controls, scalability, and visibility so agents can browse websites, process data, and complete tasks inside a managed…
AI, Global Security News, malware
Arkanix Stealer: AI-assisted info-stealer shuts down after brief campaign
Arkanix Stealer surfaced in late 2025 as a short-lived info-stealer, likely built as an AI-assisted experiment and quickly abandoned. Arkanix Stealer emerged in late 2025 as a short-lived information-stealing malware promoted on dark web forums. Researchers believe it was likely created as an AI-assisted experiment, suggesting the operators were testing automated development techniques rather than…
AI, Apps, Cybersecurity, Endpoint, Global Security News, malware, Risk Management
Moonrise RAT: A New Low-Detection Threat with High-Cost Consequences
Security professionals rely on early detection signals to prioritize and contain incidents. But what happens when a fully capable RAT generates none? In a recent investigation, the ANY.RUN experts uncovered a new Go-based remote access trojan we named Moonrise. At the time of analysis, it wasn’t detected on VirusTotal and had no vendor signatures tied to it. That’s the problem teams can’t ignore: credential theft, remote command execution, and persistence…
AI, Global Security News
AI-powered Cyber-Attacks Up Significantly in the Last Year, Warns CrowdStrike
CrowdStrike Global Threat Report warns how adversaries are leveraging AI to make campaigns more efficient and more effective
AI, Global Security News
UnsolicitedBooker Targets Central Asian Telecoms With LuciDoor and MarsSnake Backdoors
The threat activity cluster known as UnsolicitedBooker has been observed targeting telecommunications companies in Kyrgyzstan and Tajikistan, marking a shift from prior attacks aimed at Saudi Arabian entities. The attacks involve the deployment of two distinct backdoors codenamed LuciDoor and MarsSnake, according to a report published by Positive Technologies last week. “The group used several
AI, Global Security News
Bitcoin-Milliarden von Raubkopie-Portal im Visier der Justiz
Urheberrechtsverstöße sind ein einträglisches Geschäft. PXLR Studio – shutterstock.com In Leipzig hat der Prozess um den illegalen Streamingdienst «movie2k.to» und einen Milliardengewinn mit Bitcoins begonnen. Vor dem Landgericht ist der 42 Jahre alte mutmaßliche Kopf des Portals unter anderem wegen gewerbsmäßiger Geldwäsche in 146 Fällen angeklagt. Mit ihm auf der Anklagebank sitzt ein 39-Jähriger, der…
AI, Endpoint, Europe, Exploits, Global Security News, Government & Policy, malware, Russia
Operation MacroMaze: APT28 exploits webhooks for covert data exfiltration
Russia-linked APT28 targeted European entities with a webhook-based macro malware campaign called Operation MacroMaze. Russia-linked APT28 (aka UAC-0001, aka Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, and STRONTIUM) launched Operation MacroMaze, targeting select entities in Western and Central Europe from September 2025 to January 2026. The campaign used webhook-based macro malware, leveraging simple tools and legitimate services for infrastructure and data…
AI, Data Breaches, Global Security News
Everest ransomware hits Vikor Scientific ‘s supplier, data of 140,000 patients stolen
Everest ransomware claims an attack on diagnostic firm Vikor Scientific (Vanta Diagnostics), exposing data of nearly 140,000 people. The Everest ransomware group has claimed responsibility for a cyberattack on Vikor Scientific, now operating as Vanta Diagnostics. The healthcare diagnostic firm disclosed a data breach impacting nearly 139,964 individuals, as reported by the US Department of…
AI, Apps, Compliance, Global Security News, privacy
Pure Storage Rebrands to Everpure with M&A, Partner News
Pure Storage has announced it will rebrand as Everpure, representing an evolution in data management for the organization. The newly named company also announced a recent acquisition and updates to its partner program. New identity, evolved mission: inside the Everpure roll-out Everpure’s strategy addresses two challenges enterprises face and enables customers to create their own…
AI, Apps, Compliance, Global Security News, privacy
Pure Storage Rebrands to Everpure with M&A, Partner News
Pure Storage has announced it will rebrand as Everpure, representing an evolution in data management for the organization. The newly named company also announced a recent acquisition and updates to its partner program. New identity, evolved mission: inside the Everpure roll-out Everpure’s strategy addresses two challenges enterprises face and enables customers to create their own…
AI, china, Cybersecurity, Exploits, Global Security News, malware, Network Security
CrowdStrike says attackers are moving through networks in under 30 minutes
Cyberattacks reached victims faster and came from a wider range of threat groups than ever last year, CrowdStrike said in its annual global threat report released Tuesday, adding that cybercriminals and nation-states increasingly relied on predictable tactics to evade detection by exploiting trusted systems. The average breakout time — how long it took financially-motivated attackers…
AI, Global Security News
AI is becoming part of everyday criminal workflows
Underground forums include long threads about chatbots drafting phishing emails, generating code snippets, and coaching social engineering calls. A new study examined conversations captured between January 1, 2025 and July 31, 2025 across dozens of cybercrime forums to map how AI tools are entering day to day criminal operations. The dataset includes 163 discussion threads…
AI, Cybersecurity, Global Security News, privacy, Risk Management
It’s time to rethink CISO reporting lines
Despite inroads in the C-suite and rising prominence across the business at large, security leaders are still more likely to operate at a remove from the organization’s executive leadership when it comes to reporting structures. According to IANS Research and Artico Search’s 2026 State of the CISO Benchmark Report, 64% of CISOs still report into…
AI, Funding, Global Security News, Government & Policy, privacy
Microsoft undercuts its kinder, gentler image with big ICE contract
For at least the last six or so years, Microsoft has worked hard to portray itself as a kinder, gentler tech company, a stark contrast to other Big Tech behemoths like Meta, Google, Amazon, and — since Donald J. Trump’s election to the presidency in 2024 — Apple. Even The New York Times has noted…
AI, Global Security News
Why SOCs are moving toward autonomous security operations in 2026
The modern security operations center faces a crisis of scale that human effort cannot fix. With alert volumes exponentially growing and threat actors automating their attacks, organizations must pivot to autonomous SOC strategies. This shift to AI-driven defense is the only way to survive the operational realities of 2026. The mathematical impossibility of legacy defense…
AI, china, Endpoint, Exploits, Global Security News, Government & Policy, malware, Network Security, Russia
The rise of the evasive adversary
Since the earliest days of the internet, there has never been a let-up in adversarial activity. According to CrowdStrike’s just-released 12th annual Global Threat Report, malicious activity in cyberspace continues to not only accelerate but also expand its scale and increasingly abuse the trust of targeted organizations. The good news is that, despite discussion of…
AI, Apps, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
Anthropic’s Claude Code Security rollout is an industry wakeup call
When Anthropic launched a “limited research preview” of its Claude Code Security offering on Friday, Wall Street investors sent the stocks of the largest cybersecurity vendors plunging. But did the Anthropic rollout warrant such a reaction? After all, those companies, including CrowdStrike, Zscaler, Palo Alto Networks and Okta, are preparing their own agentic capabilities, and…
AI, Global Security News
Anthropic Says Chinese AI Firms Used 16 Million Claude Queries to Copy Model
Anthropic on Monday said it identified “industrial-scale campaigns” mounted by three artificial intelligence (AI) companies, DeepSeek, Moonshot AI, and MiniMax, to illegally extract Claude’s capabilities to improve their own models. The distillation attacks generated over 16 million exchanges with its large language model (LLM) through about 24,000 fraudulent accounts in violation of its terms
AI, Global Security News
Security and complexity slow the next phase of enterprise AI agent adoption
Enterprise AI agents are embedded in routine business processes, particularly inside engineering and IT operations. Many organizations report active production deployments, and agent development ranks high on strategic agendas. A new study from Docker, The State of Agentic AI Report, examines how enterprises are deploying agentic systems and the challenges emerging as deployments scale. The…
AI, china, Global Security News
SerpApi fights back against Google lawsuit
The web scraping wars have just intensified. In December, Google announced that it was taking action against web scraping company SerpApi, whose API lets customers’ scrapers mimic human searching, claiming that the company’s tool was “circumventing security measures” that protect its search results to feed the voracious appetite for training data required by many…
AI, Global Security News, Risk Management
Binding Operational Directive 26-02 sets deadlines for edge device replacement
In this Help Net Security video, Jen Sovada, General Manager, Public Sector at Claroty, explains CISA’s Binding Operational Directive 26-02 and what it means for federal agencies. The directive requires agencies to inventory, report, decommission, and replace unsupported edge devices such as firewalls, routers, switches, load balancers, and wireless access points. Unsupported devices don’t receive…
AI, Apps, Cloud Security, Cybersecurity, Global Security News
Cybersecurity jobs available right now: February 24, 2026
Application Security Engineer Anthropic | USA | On-site – View job details As an Application Security Engineer, you will secure AI products and internal tools by embedding security into the SDLC, conducting design reviews and threat modeling, and scaling secure code review practices. You will also lead vulnerability management efforts, building automation and prioritization workflows…
AI, Global Security News
Inside Apple’s Push to Build an All-American Chip
The iPhone maker wants more supply based in the U.S., which remains years behind Asia.
AI, Data Breaches, Global Security News, Risk Management
Weekly Update 492
The recurring theme this week seems to be around the gap between breaches happening and individual victims finding out about them. It’s tempting to blame this on the corporate victim of the breach (the hacked company), but they’re simultaneously dealing with a criminal intrusion, a ransom demand, and class-action lawyers knocking down their doors. They’re…
AI, Global Security News, Risk Management
Stopping real-world attacks: Lessons for business leaders from the 2026 cyber frontline
Practical steps to reduce business cyber risk based on analysis of 661 incidents remediated by Sophos X-Ops as detailed in the Sophos Active Adversary Report 2026 Categories: Products & Services Tags: MDR., Identity Security, ITDR, Secure by Design, XDR
AI, Global Security News
Android mental health apps with 14.7M installs filled with security flaws
Several mental health mobile apps with millions of downloads on Google Play contain security vulnerabilities that could expose users’ sensitive medical information. […]
AI, Data Breaches, Global Security News
Data Breaches in 2026: What’s old, what’s new?
Data breaches in 2026 explained, new cyber threats, AI driven attacks, common breach causes, and practical security strategies for individuals and businesses
AI, Cybersecurity, Data Breaches, Exploits, Global Security News, malware, Network Security, Risk Management
Ad Tech Firm Optimizely Investigates Vishing Incident
Ad tech firm Optimizely is notifying customers after a voice phishing attack led to unauthorized access to some of its internal systems. The company says threat actors obtained limited business contact information but did not access sensitive customer data or disrupt operations. “The threat actor gained access to Optimizely’s systems through a sophisticated voice-phishing attack,…
AI, china, Global Security News, Government & Policy, Risk Management
Anthropic accuses Chinese labs of trying to illicitly take Claude’s capabilities
Anthropic on Monday accused three Chinese artificial intelligence laboratories of stealthily trying to siphon Claude’s capabilities for their own models, potentially in a way that could fuel offensive cyber operations. The U.S. AI startup said the three labs, DeepSeek, Moonshot and MiniMax, ran “industrial-scale campaigns” with a tactic known as “distillation.” It involves sending bulk…
AI, Global Security News
Iran’s MuddyWater Targets Orgs With Fresh Malware as Tensions Mount
The long-active Iranian threat group debuted various attack strains and payloads in attacks against organizations in the Middle East and Africa.
AI, Global Security News
Enigma Cipher Device Still Holds Secrets for Cyber Pros
The Nazi relic’s history is riddled with resilience errors, and those lessons still apply to defending against modern cyber threats.
AI, Europe, Exploits, Global Security News, Russia
APT28 Targeted European Entities Using Webhook-Based Macro Malware
The Russia-linked state-sponsored threat actor tracked as APT28 has been attributed to a new campaign targeting specific entities in Western and Central Europe. The activity, per S2 Grupo’s LAB52 threat intelligence team, was active between September 2025 and January 2026. It has been codenamed Operation MacroMaze. “The campaign relies on basic tooling and the exploitation…
AI, Global Security News
Microsoft says bug in classic Outlook hides the mouse pointer
Microsoft is investigating a known issue that causes the mouse pointer to disappear in the classic Outlook desktop email client for some users. […]
AI, Cybersecurity, Data Breaches, Endpoint, Global Security News, Network Security, Risk Management
Global Chip Supplier Advantest Discloses Cyber Incident
Japanese semiconductor equipment company Advantest has confirmed it was hit by a ransomware attack after detecting unusual activity inside its corporate network on February 15. The company says an unauthorized third party may have accessed internal systems and deployed ransomware, potentially affecting sensitive data tied to customers or employees. “Preliminary findings appear to indicate that…
AI, Exploits, Global Security News, malware
Wormable XMRig campaign leverages BYOVD and timed kill switch for stealth
A wormable cryptojacking campaign spreads via pirated software, using BYOVD and a time-based logic bomb to deploy a custom XMRig miner. Researchers uncovered a wormable cryptojacking campaign that spreads through pirated software bundles to deploy a custom XMRig miner. The attack uses a BYOVD exploit and a time-based logic bomb to evade detection and maximize…
AI, Global Security News
GTDC Summit 2026: AI Reshapes the IT Channel
At GTDC Summit 2026, distribution executives made one thing clear: artificial intelligence is not just another technology cycle; it is reshaping the foundation of the IT channel. Data, global scale, and platform economics are becoming the competitive edge, and traditional MSPs may soon face pressure from AI-native entrants built for model-driven systems and agentic workflows.…
AI, Global Security News
Anthropic Accuses Chinese Companies of Siphoning Data From Claude
The allegations mirror those made by OpenAI, which told House lawmakers that DeepSeek used ‘distillation’ to improve AI models.
AI, Cybersecurity, Global Security News
Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb
Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromised hosts. “Analysis of the recovered dropper, persistence triggers, and mining payload reveals a sophisticated, multi-stage infection prioritizing maximum cryptocurrency mining hashrate, often destabilizing the victim
AI, Apps, Cybersecurity, Data Breaches, Exploits, Global Security News, Network Security, Risk Management, Russia
AWS Threat Intel Finds 600+ FortiGate Devices Hit
A financially motivated cybercriminal has used commercial generative AI tools to compromise more than 600 FortiGate devices across 55 countries — without exploiting specific software vulnerabilities. This “… campaign succeeded by exploiting exposed management ports and weak credentials with single-factor authentication, fundamental security gaps that AI helped an unsophisticated actor exploit at scale,” said CJ…
AI, Apps, Europe, Global Security News, Government & Policy, Network Security
In India, Nvidia eyes a different approach to sovereign AI
Nvidia has been talking about sovereign AI for years, but is finding that India’s cultural and economic diversity calls for a different approach. Unlike in the US, truckloads of GPUs won’t drive the chipmaker’s expansion in India. Instead, the company plans to focus on software first, and deal with computing power later. It’s betting on…
AI, Global Security News, Risk Management
Multiple Zero-Day Flaws in PDF Platforms Enable XSS and One-Click Attacks
16 zero-day security flaws found in Foxit and Apryse PDF platforms could lead to account takeover and RCE. Learn how AI identified these risks.
AI, APAC, Global Security News
Snowflake Cortex Code Expands Towards Supporting Any Data, Anywhere
COMPANY NEWS: Cortex Code CLI extends beyond Snowflake workflows to support popular data systems starting with dbt and Apache Airflow®, delivering AI assistance across environments, regardless of where that data lives Developers can apply Snowflake’s secure, context-aware AI coding agent directly within their environments to build and optimise data pipelines more efficiently Cortex Code CLI…
AI, Global Security News
Technology, collaboration and investment drives Australia’s energy transition, ABB research shows
GUEST RESEARCH: Survey of Australian businesses conducted by ABB’s Energy Industries division indicates technology advancements (68 per cent) and AI and automation (51 per cent) are key drivers of the energy transition Almost all (99 per cent) of respondents plan to boost energy transition investment, with 69 per cent due to allocate over 10 per…
AI, Global Security News
Apple, the storage company
When it comes to hardware and services revenues, storage is Apple’s secret spell. Not only has iCloud storage become Apple’s most frequently paid-for service, but people are more often purchasing additional storage when acquiring new Apple hardware. This is good business for the company and all it had to do to build that business was…
AI, Global Security News
Why Enterprises Need Advanced PPC Management Frameworks
Managers are constantly searching for methods to get the most out of their advertising campaigns. Pay-per-click management frameworks that use advanced techniques can include organized features that help achieve measurable results and promote growth. Even the most boring campaigns can drive revenue and brand growth if teams are made to feel at ease with these…
AI, Apps, Global Security News
OpenAI partners with consulting giants to deploy enterprise AI agents
As it bids to push further into the enterprise, OpenAI announced Monday that it has partnered with several large consulting firms. Frontier Alliances, as the partner initiative is called, will involve work with Accenture, Boston Consulting Group (BCG), Capgemini, and McKinsey & Co. The multi-year partnerships will “help customers define strategy, integrate systems, redesign workflows,…
AI, Global Security News, malware
Shai-Hulud-Like Worm Targets Developers via npm and AI Tools
Supply chain worm mimicking Shai-Hulud malware spread via malicious npm packages, targeting AI tools has been identified by security researchers
AI, Cybersecurity, Global Security News
Banana Gun Hits One Million Users: Inside the Crypto Trading Platform That Grew by Putting Execution and Safety First
In the latest development, Banana Gun hits one million users. Crypto trading has changed. The days of logging into a centralized exchange, placing a market order, and waiting are giving way to something faster, more direct, and more demanding. On-chain trading – buying and selling tokens directly on the blockchain without a middleman – now…
AI, Global Security News, malware
Fake troubleshooting tip on ClawHub leads to infostealer infection
A new malware delivery campaign has hit ClawHub, the official online repository for “skills” that augment the capabilities of the popular OpenClaw AI agent. Unlike previous ones, this campaign does not aim to trick users into downloading a bogus, malicious skill. Instead, the threat actor is leaving this particular comment on popular legitimate skills published…
AI, Apps, Global Security News, Risk Management
Out of the Shadows: How to Safely Migrate Data for AI Deployments
Roughly two decades ago, organizational leaders began asking many questions about a watershed technology migration in the making: Should we move our data to the cloud? How much should we commit to the cloud? Could our employees use the cloud without IT’s approval? From Cloud Migration to AI Migration Today, another massive migration is underway,…
AI, Global Security News, Government & Policy
Spanish police arrest suspected Anonymous members over DDoS attacks on government sites
Spanish police (Guardia Civil) arrested four members of the hacktivist group Anonymous Fénix over DDoS attacks targeting ministries, political parties and public institutions. Police raid (Source: Guardia Civil) Police identified the organization’s leadership, including its administrator and moderator, who were arrested in May 2025 in Alcalá de Henares (Madrid) and Oviedo (Asturias). Evidence gathered during…
AI, Global Security News
When identity isn’t the weak link, access still is
Stolen tokens and compromised devices let attackers reuse trust without breaking authentication. Specops Software explains why identity alone isn’t enough and how continuous device verification strengthens Zero Trust. […]
AI, Global Security News, Government & Policy, Network Security
Romanian hacker pleads guilty to selling access to Oregon state networks
A Romanian man pleaded guilty to selling admin access to Oregon’s state network for $3,000 in Bitcoin and repeatedly accessing it to prove control. Catalin Dragomir (45) from Romania, pleaded guilty in the U.S. for selling unauthorized admin access to an Oregon state emergency management network. He gained access in June 2021, advertised it, and…
AI, APAC, Cybersecurity, Data Breaches, Exploits, Global Security News, Risk Management
Ransomware, Zero-Days, and Data Breaches Shape This Week’s Cybersecurity Landscape
This week, a Dell vulnerability is being actively exploited, an Apache flaw allows bypass of RBAC, and over 41% of OpenClaw skills are vulnerable. Major Threats & Vulnerabilities Zero-Day Vulnerabilities A zero-day vulnerability in Dell RecoverPoint is being actively exploited to deploy web shells and backdoors in VMware environments. This highlights the urgent need for…
AI, Global Security News
Lenovo expands ThinkEdge portfolio with new AI-driven edge systems
Lenovo expanded its ThinkEdge portfolio with a new generation of AI-driven edge computing solutions, including the compact and reliable ThinkEdge SE10n Gen 2, the AI-ready ThinkEdge SE30n Gen 2, the AI-powerhouse ThinkEdge SE60n Gen 2, and Lenovo’s first industrial all-in-one (AIO) Panel PC, the ThinkEdge SE50a. As enterprises push intelligence closer to operations to improve…
AI, Apps, Cybersecurity, Data Breaches, Europe, Exploits, Global Security News, Government & Policy, Network Security, Risk Management
1.2 Million Accounts Exposed in French Bank Registry Breach
An incident disclosed by the French Ministry of Finance involved unauthorized access to the national bank account registry and may have exposed data tied to approximately 1.2 million accounts. This case highlights the continued effectiveness of credential theft as an attack vector. The attacker “… was able to consult part of this file which lists…
AI, Global Security News, malware
Another day, another malicious JPEG, (Mon, Feb 23rd)
In his last two diaries, Xavier discussed recent malware campaigns that download JPEG files with embedded malicious payload[1,2]. At that point in time, I’ve not come across the malicious “MSI image” myself, but while I was going over malware samples that were caught by one of my customer’s e-mail proxies during last week, I found…
AI, Global Security News
Pure Storage rebrands to Everpure as its service offering evolves in the AI era
The all-flash hardware and software provider Pure Storage has announced a new name, reflecting it has gone way beyond “merely” storage. Now known as Everpure, the title more accurately reflects the company’s committment to accelerating artificial intelligence and making the right data available at the right time for the right people.
AI, Global Security News, Risk Management
⚡ Weekly Recap: Double-Tap Skimmers, PromptSpy AI, 30Tbps DDoS, Docker Malware & More
Security news rarely moves in a straight line. This week, it feels more like a series of sharp turns, some happening quietly in the background, others playing out in public view. The details are different, but the pressure points are familiar. Across devices, cloud services, research labs, and even everyday apps, the line between normal…
AI, Global Security News, Russia
Russian Cyber Threat Actor Uses GenAI to Compromise Fortinet Firewalls
A low-skilled Russian-speaking attacker has used GenAI tools to help deploy a successful attack workflow targeting FortiGate instances
AI, APAC, Apps, Global Security News
With ‘Frontier,’ OpenAI hopes to own the enterprise agent stack
With its new Frontier platform, announced earlier this month, OpenAI is looking to position itself as the best option for managing enterprise AI agents. But to succeed, the company that delivered the popular ChatGPT in 2022 will need to show it can manage the complexity of large-scale agent deployments — and do so better than …
AI, Global Security News
WhatsApp is adding another lock to your account
Meta has released WhatsApp Beta for Android 2.26.7.8 through the Google Play Beta Program. The update includes references to password-protected accounts, indicating plans to introduce an additional layer of protection beyond the app’s current authentication options. WhatsApp is exploring the implementation of a feature that will introduce a password (Source: WABetaInfo) The feature will allow…
AI, APAC, Apps, china, Cybersecurity, Data Breaches, Exploits, Global Security News, Government & Policy, Network Security
CVE-2026-1731 fuels ongoing attacks on BeyondTrust remote access products
Attackers are exploiting CVE-2026-1731 in BeyondTrust RS and PRA to deploy VShell, gain persistence, move laterally, and control compromised systems. Threat actors are actively exploiting a recently disclosed critical vulnerability, tracked as CVE-2026-1731 (CVSS score: 9.9), in BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA). The flaw is being used to conduct a wide…
AI, Global Security News, Risk Management
How Staying Small Became AI Startups’ Biggest Flex
Startups are using AI tools to keep their staff as small as possible. But some are discovering that becoming too lean carries risks.
AI, Data Breaches, Global Security News
Hacker stiehlt Daten von Tausenden RTL-Mitarbeitern
Ein Hacker hat sich Zugriff auf Mitarbeiterdaten von RTL verschafft. nitpicker – shutterstock.com Die RTL Group wurde offenbar Opfer einer Cyberattacke. Wie Cybernews berichtet, brüstet sich ein Cyberkrimineller namens LuneBF mit gestohlenen Daten von mehr als 27.000 Mitarbeitern der Mediengruppe. In seinem Darknet-Post behauptet der Angreifer, sich Zugriff auf die Intranet-Website der RTL Group verschafft…
AI, Apps, Endpoint, Exploits, Global Security News, malware, Network Security
New Arkanix stealer blends rapid Python harvesting with stealthier C++ payloads
A newly uncovered infostealer, suspected to be built with the help of a large language model, is targeting victims with Python and C++ variants, each tailored for a different stage of data theft. Kaspersky researchers discovered a stealer dubbed “Arkanix,” which is capable of harvesting credentials, browser data, cryptocurrency, and banking assets from infected machines.…
