
There is a story about online school that much of the public still believes: it was an emergency measure.

Attackers are moving away from fake Microsoft login pages in favor of abusing Microsoft’s own authentication system, letting phishing campaigns slip past the warning signs employees are trained to spot, according to Check Point. Between June 25 and the second week of July, researchers found over 200 phishing emails targeting around 120 organizations in a…

Digital document verification in businesses with global coverage of clients and an immense network of AI models brings forth nothing but accuracy and speed. The divergence from conventional methods of authenticating a client’s ID by corporate and the financial sector so far has made commendable improvements in the business cycle of organizations. Successful enterprises in…
White label document verification puts your brand and domain on every verification page, so verifiers trust what they see and forgeries stand out. Key Takeaways White label document verification means every verification page and QR code carries your own brand and domain, with no third-party tool in sight. Verifiers judge a document by the domain…

All right, quiz time: In a single sentence, can you tell me exactly what Google Voice does? It’s a question even the most giddy Google-appreciating geeks struggle to answer succinctly — and for normal, non-tech-obsessed Homo sapiens, the answer typically falls somewhere between “Huh?” and “Wait, is that the same thing as gChat?” Really, it’s…

A Russia-aligned threat group used a “half-click” exploit against Microsoft Exchange’s Outlook Web Access to install a browser-based backdoor when recipients opened specially crafted emails. The campaign began on July 22 and was conducted by TA488, which is also tracked as Void Blizzard and Laundry Bear, according to a report from the cybersecurity firm Proofpoint.…
A static credentials vulnerability (CVE-2026-20316) in Cisco Secure Firewall Management Center (FMC), a platform for centrally managing multiple Cisco Secure Firewall devices across a network, is being leveraged by attackers, CISA warned. Two FMC flaws, one indicator of compromise CVE-2026-20316, reported by Jimi Sebree of Horizon3.ai, is found in the FMC software’s web interface. The…

Dropzone AI has announced the general availability of AI Threat Hunter, its proactive threat hunting agent. The tool enables security teams to run structured hunt packs across their environments to identify hidden threats, emerging risks, and security coverage gaps that traditional alerts may miss. Security alerts flag activity that matches predefined detection rules, helping teams…

PortSwigger has announced the public beta of Burp AT, a new addition to Burp Suite that brings agentic AI to professional penetration testing. Burp AT enables penetration testers to delegate defined investigative tasks to AI agents that use Burp Suite’s tools, project context, and purpose-built pentesting capabilities. Testers control how much work the agents perform,…

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access. “In this campaign, the group combines new vulnerable-driver abuse, newly observed…

The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment…
Cybersecurity is rarely a straight line. In this special Black Hat edition of Humans of Talos, Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence. From forensic labs and newsrooms to the kitchen line, we’re revisiting the stories and lessons that define the people behind the threat…

For years, North Korea’s state-trained hackers have been one of the world’s most prolific robbers of banks – stealing huge sums of money from foreign financial instituions, draining cryptocurrency exchanges of billions, and funnelling the proceeds into the country’s weapons programme. But now, in a remarkable twist, some of the same elite hackers appear to…
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Cisco Secure Firewall Management Center (FMC) flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Firewall Management Center (FMC) flaw, tracked as CVE-2026-20316 (CVSS score of 5.3), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-20316 is a…
Apple’s budget MacBook Neo is already affordable, but if you’re an educator or student, you can get one for even less.

A coordinated cyberattack on July 26 and 27 hit operational technology (OT) systems at more than 30 community water utilities across Minnesota, prompting an immediate response from Minnesota IT Services (MNIT) to contain the threat. MNIT confirmed the attack in a statement published July 28 and said it activated its cybersecurity incident response capabilities as…
The screenshot may look convincing, but it doesn’t necessarily prove that the payment, booking or conversation is genuine
Satechi’s CubeDock combines a high-speed docking station with a built-in SSD enclosure – and it works so well.

A recently released criminal complaint against Peter Stokes, an alleged member of the Scattered Spider cybercrime group, reveals previously unpublicized details about Windows telemetry. Microsoft has never exactly had a reputation for being privacy-focused, however the complaint reveals the important part played by Microsoft’s Global Device Identifier (GDID), a persistent identifier tied to a Windows…

Analysis found eSIM Plus and Nicegram share a Belarus-linked codebase, while eSIM Plus routes data and calls through Russian services. Two popular apps available in EU app stores, Nicegram, with over 50 million downloads, and eSIM Plus, with over 1 million, are presented to users as Lithuanian products. The Mysterium VPN Research Team pulled apart…

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves…

The Federal Communications Commission (FCC) added foreign-produced mobile robots and networked power inverters to its Covered List on July 28. The move generally prevents new models from receiving the equipment authorization required for import, marketing, or sale in the US. Previously authorized models can still be sold, and devices people already own are unaffected. Federal…
There is a question that comes up in almost every conversation about AI in IT operations, and it is almost always the wrong one. Organisations want to know how accurate their…

More than one in four organizations hit by a malicious attack over the past year say AI drove it. Those breaches averaged about $1 million above the malicious attacks that ran without AI. Defenders bought similar technology and aimed it somewhere else. Half of breached organizations put AI agents inside a security operations center, mostly…
July brought another set of threat coverage updates designed to help security teams work faster and with more confidence. ANY.RUN added 42 behavior signatures, 11 YARA rules, and 703 Suricata rules, giving SOCs broader visibility across files, malware behavior, and network activity. We also published new threat intelligence and technical research on active malware and phishing campaigns.…
Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining script pushed into at least 18 packages carrying more than 2 billion weekly downloads…

Ryan Dewhurst, CEO at KEVIntel, explains how his team confirms exploitation that CISA’s catalog has not listed yet. He describes a global honeypot sensor network, AI triage, and human verification in a lab before a vulnerability reaches the public feed. He covers CISA’s three-day patching deadline under BOD 26-04, why virtual patching buys time, and…

Black Hat USA 2026 returns to Mandalay Bay with a re-engineered six-day program designed to spark innovation, challenge assumptions, and unite the global security community. The event opens with four days of immersive, expert-led Trainings (August 1-4), continues with Summit Day on Tuesday, August 4, and closes with a two-day main conference featuring Briefings, open-source…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log
How do you protect your executives when truth doesn’t seem to be truth anymore? It’s a question BlackCloak Founder and CEO Dr. Chris Pierson recently discussed this dilemma with SVP of Product Matt Covington. Advances in AI, voice, and video impersonation make it difficult to establish trust when communicating digitally. BlackCloak offers a solution to…
Dashlane is a password manager for individuals and families that stores passwords, passkeys, payment cards, personal information and secure notes in an encrypted vault. It also includes a password generator, password health reports, an authenticator, credential sharing, dark web monitoring and phishing protection. The service is available on Windows, macOS, Linux (web app), Android, iPhone…

Compromised credentials can remain active long after passwords are created, leaving organizations trying to identify exposed accounts before attackers can use them. The 2026 Credential Risk Report from Enzoic shows growing awareness of the problem, but monitoring and response capabilities continue to lag. Even with MFA deployed, which credential-related risks remain a concern for your…
KnowBe4 today voiced its support for the Open Secure AI Alliance, the coalition NVIDIA formed this week with Microsoft, Cisco, CrowdStrike, Palo Alto Networks and other…
Like most infrastructure, the Internet’s fragility is easy to overlook — as long as it’s working.
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Data shows that 1 in 5 data centre assets are “one hop” away from being accessible to attackers

Most IT operators understand that critical infrastructure should be isolated in crisis situations, but many don’t know how to do it in a way that maximizes security and minimizes disruption. Now, several global agencies are offering a step-by-step action plan, CI Fortify. Released by the US Cybersecurity and Infrastructure Security Agency (CISA) and several Five…
[This is a Guest Diary by Adam Cann, an ISC intern as part of the SANS.edu BACS program] Introduction Most of what an internet-facing SSH honeypot records is noise. Endless password guessing, and bots that log in, immediately pull down a payload, and move on. On 27 June 2026 my honeypot caught something quieter, and…
AMD spent 2025 building out its Radeon RX 9000 range from the top down. This week it finally filled in the bottom rung.
The leaked database contains approximately 23.4 million user records, 13.6 million device records, and 2.6 million payment records.
The goal of the 1/4 Initiative is to modernize and unify the Naval Surface Warfare Center Corona Division’s IT and data architecture, transitioning from a fragmented system to a single-design, four-environment ecosystem.
TrendAI joins Nvidia as an inaugural partner in the Open Secure AI Alliance, advancing open models, harnesses, and research to strengthen cyber defense.
Closing the gap between secrets management and access control, across protocols agents use
Founded in 2017, Spur Intelligence provides real-time intelligence to help organizations identify anonymized, proxied, and obfuscated web traffic, thereby reducing fraud and enforcing compliance.
New capabilities in TotalAI enable CISOs to reduce shadow AI, flag abnormal model behavior, and prove controls are working across development and runtime
Dematic, a global leader in supply chain automation, has released its 2025 Sustainability Report, providing a transparent view of its progress and direction as it continues to…
For decades, supply chains have been built around a simple objective; efficiency.

You’ve been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment – with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn’t exist. And North Korean hackers using this trick have already made…

In this post, I will talk about the signs that you might be needing a RAM upgrade. Upgrading your device is necessary from time to time, because years down the line your Mac might not have great performance. It’s easy to see why, new devices appear and software evolves, which leads to more resources being…
In this post, I will talk about cybersecurity essentials for International travelers and protecting your digital life on the move. Traveling internationally has never been easier, but staying digitally secure has become increasingly challenging. Whether you’re a business traveler, digital nomad, remote worker, or vacationer, your devices contain valuable personal and financial information that cybercriminals…

Apple’s tagline for its App Store says, “The apps you love. From a place you can trust.” You might love the apps, but can you trust the store? A federal lawsuit filed in the Northern District of California last week suggests not. Three people have accused Apple of promoting a fake version of the Sparrow…

Threat actors are claiming to be selling a database containing records for more than 75 million Revolut users, raising concerns about the potential exposure of customer information. However, Revolut says it has found no evidence that its systems have been breached and disputes that the forum listing represents a new security incident. Key takeaways of…

Claude Mythos found new flaws in HAWK and reduced AES, proving AI can autonomously advance cryptography research. Anthropic published two cryptographic research results achieved by Claude Mythos Preview working mostly autonomously: an improved attack on HAWK, a post-quantum digital signature scheme currently under NIST review, and a 200 to 800 times faster attack on a…

Amazon’s security researchers say a hacking group tied to North Korea targeted small, little-noticed software packages more than a year before it struck one of the internet’s most widely used programming tools. The company’s threat intelligence team said Wednesday at a media roundtable at its Arlington, Va., offices that the same group linked to the…

Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the…
Why slowing down and gaining clarity may be the best way to manage a crisis.

A coordinated cyberattack targeting more than 30 community water utilities across Minnesota has prompted a statewide cybersecurity response. While no impacts to drinking water quality have been reported, the incident demonstrates how attacks against industrial control systems can temporarily disrupt essential public services. Even though this is being reported as an attack against OT, is…

One of the most difficult obstacles to overcome in the quantum race will be the supply chain, given how diffuse it is, a top White House official said Wednesday. “Supply chain is one of the biggest challenges in my mind, and really, the challenge with the quantum supply chain is that quantum is not defined…
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.

OpenAI’s renegade AI agent, which carried out a high-profile breach of the AI platform Hugging Face, also reportedly compromised a customer of the cloud platform Modal Labs, according to Reuters. The agent is said to have exploited a vulnerability in the customer’s own code, where an unprotected endpoint allowed anyone to run code in an…
Are free streaming services that bad? I swapped my paid subscriptions for free ones to see.

LAS VEGAS, July 29, 2026, CyberNewswire – Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking. Sweet now blocks rogue agent behavior in real time – extending Sweet’s runtime enforcement from the cloud to the AI agents that are acting alongside…