
Agents need their own identities, scoped to a specific task, and then must be destroyed.

A trusted software update can become a malware delivery system when attackers gain control of the account publishing it. Amazon Threat Intelligence has linked four npm supply-chain attacks conducted between March 2025 and March 2026 to Sapphire Sleet, a threat actor associated with North Korea. Based on command-and-control indicators and shared tactics, Amazon assessed the…
Have you ever read the Talos IR Quarterly Trends report and wondered, “How did that phishing or ransomware campaign actually play out? When was Talos IR contacted, how did they contain it, and how did they remediate the environment?” You’re in luck. Next Tuesday, August 11, Cisco Talos Incident Responders will be hosting an exclusive,…
The Mission Center system monitor for Linux adds some new features that will appeal to a broader user base, especially those with laptops.
Unit 42 uncovered an AI-driven Chinese hacking campaign where DeepSeek autonomously scanned targets, selected exploits, and launched attacks. Researchers at Palo Alto’s Unit 42 got a front-row seat to something they’d only theorized about before: an AI system running an actual hacking campaign with almost no human steering it. The researchers spotted a Chinese-speaking actor,…

Meta says artificial intelligence is beginning to shorten the distance between a product idea and a working application. During the company’s latest earnings call, CEO Mark Zuckerberg said AI is accelerating software development across Meta and could allow its engineers to create and test more consumer apps. He cited several recent launches, although the company…

Cyberattack recovery gets a security upgrade as Commvault brings Google Threat Intelligence into the backup process to help companies find safe data faster. Commvault is integrating Google Threat Intelligence into its Threat Scan workflows to help organizations identify clean recovery points more quickly after ransomware and other cyberattacks. Integrating Google Threat Intelligence with backup scanning…
As AI adoption accelerates across the Asia-Pacific (APAC), partners are moving beyond AI experimentation to build managed AI services that generate recurring revenue. We recently spoke with Pax8 executive vice president and general manager for APAC Lindsay Keating, who said the shift is pushing partners beyond software licensing and automation toward outcome-driven AI services. APAC…
You don’t have to compromise on style or function with these MagSafe wallet picks from brands like Moft, ESR, and more.
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June…
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not…
Google’s next flagship smartphones are almost here, but not everything you’ve read about the Pixel 11 carries the same weight. The tech giant has confirmed it will unveil the Pixel 11 lineup during its Made by Google event on Aug. 12. Ahead of that announcement, reporting from various outlets has helped fill in many of…
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear,…

Mimecast has unveiled Agent Risk Center, a beta capability for discovering, monitoring, and governing AI agents, alongside Managed Threat Response, a redesigned 24/7 service that combines AI-assisted triage with analyst-confirmed remediation. According to Mimecast’s analysis, 98% of organizations already have unsanctioned AI tools in use, and by 2029 more than a billion agents will take…

A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s AI agent misconfigured a file server, inadvertently exposing the entire infrastructure. “This visibility enabled us to understand…
Looking to shift your storage needs from a third-party cloud service to inside your home network? If so, ZimaOS is a great option.

SentinelOne has today announced governed, closed-loop response across the Singularity Platform, delivering trustworthy automation for security operations. Purple AI and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Security teams set the boundaries first, deciding where AI acts on its own and where it stops for human sign-off. The Autonomous SOC now…
And no, I’m not going to tell you to pack a power bank, roll your clothes, or bring a travel pillow.

Horizon3.ai has announced a $250 million Series E at a valuation of more than $2 billion, tripling its valuation from $650 million at Series D in just over a year. The oversubscribed round was co-led by existing investors NightDragon and NEA, with participation from seven new investors and five returning backers. The capital underscores accelerating…

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported…

While AI security today is largely focused on restricting what an agent can do, Zero Networks says it has built a failsafe. The company says it can block a compromise midway by adding a network layer protection. On Monday, the company announced the launch of “Least Agency Enforcement,” a new capability designed to implement the…
Apple has had to introduce a quota on security researcher reports because its systems are being overwhelmed by low-quality warnings generated by AI. It’s a classic illustration of the rule of unintended consequences: a technology meant to help us has become a barrier to getting things done. After all, not only has AI driven the cost…
But if you’ve been looking for the duress passcode feature on your phone, I have bad news for you.
With 3.5 billion active users to protect, Google is relying on Gemini to find Chrome security bugs fast – and before attackers do.

Alibaba on Monday introduced Qwen3.8-Max, its largest artificial intelligence model to date, expanding its enterprise AI portfolio with an open-weight model designed for software engineering, multimodal reasoning, and other knowledge-intensive business workloads. In a blog post announcing the launch, Alibaba described Qwen3.8-Max as a 2.4-trillion-parameter mixture-of-experts (MoE) model that activates only about 95 billion parameters during inference.…

UK police legal database breach exposed officers’ names and work emails, increasing phishing risks. NCA is investigating. The Police National Legal Database (PNLD), the legal reference system used by all 43 Home Office police forces in England and Wales, confirmed that a data breach exposed the contact details of police officers, staff, and criminal justice…

The US Cybersecurity and Infrastructure Security Agency (CISA) has published the Open Source Software: Security Principles and Practices guide, which provides federal agencies with recommendations for managing the security of open source software, contributing to OSS projects, and evaluating open source AI systems. Using open source software Federal agencies can benefit from open source software…
A critical security vulnerability (CVE-2026-66066) in Ruby on Rails (aka Rails), one of the most widely used frameworks for building websites and web apps, may allow attackers to read sensitive files off a server and, in some cases, take full control of it. Nicknamed “KindaRails2Shell” by the researchers who found it, the flaw lets an…
AI is moving incredibly fast, and every security leader is feeling the pressure to keep up. AI platforms like Claude, Codex and Cursor are already helping security teams write detections, investigate alerts, summarize incidents, and automate repetitive work. The conversation has evolved from whether AI belongs in the SOC, to where each type of AI…

Qodana 2026.2 shipped with new security inspections, published benchmark results, post-quantum cryptography checks, and coverage reporting that no longer has to be pointed at the reports. The security work sits in the .NET linter and runs by default. Qodana tracks untrusted data across files in C#, JavaScript, and TypeScript, which turns up SQL injection, command…

Simbian has released its autonomous AI Threat Hunt Agent, that investigates potential threats and identifies malicious activity across enterprise environments. The Threat Hunt Agent represents the third pillar of Simbian’s AI-driven security suite. These three Agents eliminate blind spots across the entire threat timeline: The Present: The AI SOC Agent analyzes real-time alerts and neutralizes…

Chinese smartphone makers have been followers in the global market, embracing the concepts and paradigms set in the past 20 years by Apple and Google. But AI may be giving the Chinese an opportunity to break away and set their own path forward. Specifically, Chinese companies are integrating AI more fully into smartphones, and also…

Companies are deploying AI agents into everyday work at a pace no security program was built for. Related: AI layoffs pays for AI infrastructure The rush is competitive. Nobody wants to be the last one still doing this by hand. What’s getting skipped is the harder question: once an agent is acting on a company’s…

An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit. Attack surface management platform Censys said it identified the threat actor running more than 100 web properties, most of which are fake Amazon Web Services (AWS) sign-in pages on a…
Plus: AI chatbot, deepfake labeling rules kick off in Europe, and FinCEN director leaves for Citigroup
Tenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs — it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security…

The Police National Legal Database (PNLD) has confirmed that police, government and customer contact information was compromised and published on the dark web. The data included names, organisations and work email addresses belonging to police officers, police staff, criminal justice professionals, government partners and customers. The incident, identified on July 26, also exposed some names

Alleged Żabka data leak offered for €5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Żabka Polska. Żabka Polska is Poland’s largest convenience store operator…

In cybersecurity, third-party risk management normally looks simple on paper: evaluate your vendor, learn the risk, report out on the gaps and weaknesses, transfer to the contract, and continue. Unfortunately, it seldom works that way in practice. In my roles as a CISO, I find my teams in an intermediary position as the compliance and…

OpenAI banned a coordinated network of ChatGPT accounts that likely originated in Cambodia’s Preah Sihanouk province, a region reports have linked to online scam compounds and human trafficking operations. The network used the company’s models to create and manage fake online personas, generate and translate messages sent to scam targets, produce promotional content for fraudulent…
Attackers reaching for kernel access on a Windows machine bring a driver Microsoft already trusts. It is signed, it loads, and it carries a known flaw. That flaw gives them enough room to tamper with memory or disable the security software watching the host. Once an attacker holds that level of access, the tools on…

When OpenAI disclosed that one of its models escaped a test environment and broke into Hugging Face’s systems on its own, headlines cast the incident as the start of a new era of AI-driven attacks. But the underlying cause of the incident was a familiar one: a misconfigured sandbox — the same kind of fundamental…

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor’s July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented. Thermo Fisher tracks the issue as…
While AI is supposed to help defenders, it’s now creating more than twice as much noise as human-triggered incidents CrowdStrike detects as potentially malicious. The company’s threat hunting team and systems triaged an average of 14 million detection leads daily, resulting in about 36,000 customer alerts during the one-year period ending in June. “AI agent-driven…

Last week on Malwarebytes Labs: Fake Fortnite rewards are stealing players’ accounts Fake Flash Player installs AtlasRAT Malwarebytes for Windows, now available on the Microsoft Store Hims & Hers sued over alleged health data privacy failures Hidden prompt turns Microsoft Copilot into an AI worm Apple accused of letting fake crypto app steal $1.8 million…

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. N-central is the remote monitoring and management platform

Three high-severity security flaws have been disclosed in Hugging Face’s Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. “These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the

Today, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal. Their National Cyber Security Centre now has access to monitor Nepalese government domains against the data in HIBP. This gives the NCSC the ability to identify exposure across government email addresses and respond quickly when those accounts appear in…

Ruby on Rails fixed a critical vulnerability that could let unauthenticated attackers read files and achieve remote code execution. Ruby on Rails has patched CVE-2026-66066, a critical vulnerability (CVSS score of 9.5) that could allow unauthenticated attackers to read arbitrary files from vulnerable servers. In the default configuration, applications that generate image variants may expose…

In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind the claim that each published sample hides an average of 2.4 undocumented variants, describes…
SkillSpector is an open-source scanner from NVIDIA that reads an agent skill and tells you whether to install it. Point it at a directory, a zip file, a single SKILL.md, or a Git URL, and it returns a list of findings, a risk score, and recommendations. The folder it reads runs with everything you have.…

In this Help Net Security video, Mike Boyle, VP of Business Units at GMO GlobalSign, and Rahul Powar, CEO and founder of Red Sift, unpack the evolution of email security and why it matters for business trust. With a combined 45+ years worth of experience in tech, they dissect email from the very beginning, before…
Guardio Mobile Security brings several protection features to iPhone and Android, allowing users to monitor exposed personal information, identify phishing attempts, and receive alerts about emerging threats from a single application. It is available on smartphones and tablets, while browser extensions support Chrome and Microsoft Edge on laptops and desktop computers. After signing in or…

Buying TikTok followers, likes, or views could do more than inflate engagement metrics. According to Malwarebytes, many services selling social media growth operate through deceptive practices that can expose customers to scams, stolen accounts, and financial loss. The market for artificial social media engagement also creates security risks for both buyers and other platform users.…
Left to right Constructiv Technologies CEO and Founder Drew McPherson, Cofounder Sally McPherson, Duda executives Renato Bottini, VP of Strategic Account Management, and Oded…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Consolidation across the managed services and cybersecurity markets is reshaping how MSPs evaluate the companies behind their technology stacks. Investments in MSPs increased approximately 20% year over year in 2025, reaching 466 transactions and $4.3 billion in disclosed deal value, according to Drake Star. SecurityWeek separately tracked 426 cybersecurity acquisitions during the year, a 5%…

Acronis unveiled four AI-driven capabilities designed to help managed service providers consolidate service management, business intelligence and workflow automation within its Cyber Platform. The upcoming Acronis Cyber Console, Cyber Intelligence, Service Desk and Cyber Studio tools will give MSPs a unified workspace for managing customer environments, identifying service and revenue opportunities, automating ticket remediation and…

DNSFilter has expanded its MSP Partner Program to give providers a clearer path to stronger margins, deeper sales and marketing support, and additional technical resources as they grow their managed security businesses. Three-tier program introduces rewards structure tied to growth The redesigned three-tier program rewards MSPs based partly on their growth rate and commitment to…

Climb Global Solutions reported double-digit growth in gross billings and gross profit during the second quarter of 2026, even as net income declined and adjusted EBITDA remained flat. The value-added distributor said strong organic vendor performance, cybersecurity portfolio expansion and continued investment in Europe are positioning it for further growth and additional acquisitions. Climb reports…
With the new AI Network Firewall, Check Point is the first to deliver AI security from the physical firewall organisations already run – extending the AI Defense Plane across…
Insights from trillions of DNS queries expose the industrialised criminal ecosystem reshaping modern cybercrime

In this post, I will show you the 7 leading document verification solutions for 2026. Document fraud has quietly outrun the tools built to stop it. Forged passports and altered driver’s licenses are now joined by AI-generated documents, tampered PDFs, and synthetic bank statements convincing enough to pass a human reviewer and many automated checks.…
Key Takeaways ● AI-powered identity verification is moving from document checks to real-time identity risk decisioning. ● AU10TIX leads this list because it combines AI-based…
Cloud-native teams have spent years moving security left, scanning containers, adding SBOMs, and tightening Kubernetes controls. Yet
A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. […]
CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March.…

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter TAG-195 Upgrades MaaS Ecosystem with Modular Tools Inside a DPRK BlueNoroff ClickFix Kit SourTrade: Browser-Assembled Malware Delivered Through Malvertising MedusaHVNC: A Hidden Desktop That Steals Live Windows Sessions Unpacking “Cruciferra”: An Analysis of a…

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens Adobe fixed a maximum-severity vulnerability flaw in…
CALIFORNIA, USA, 2nd August 2026, CyberNewswire
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. […]

Almost every company can now produce a list of what’s inside its software. Almost none can prove the list is right. Related: SBOM’s role in cybersecurity Construction solved this a century ago. Every steel beam carries a stamp naming the mill that poured it. Every concrete truck arrives with a ticket recording the batch. Every…
Tips for navigating a feed full of machine-made content.
Every time someone presses the button on a poker machine, it gets logged. Multiply that across a venue’s floor, a full year of play, and every cash-in, cash-out, ATM trip and…