
The company said its second-quarter sales were $60.8 billion while the minimum spending on its AI buildout for the year would increase by $5 billion.
The agentic AI playing field was heavily tilted toward offense, so researchers began using red team agents to help teach their blue counterparts.

OpenAI’s renegade AI agent, which carried out a high-profile breach of the AI platform Hugging Face, also reportedly compromised a customer of the cloud platform Modal Labs, according to Reuters. The agent is said to have exploited a vulnerability in the customer’s own code, where an unprotected endpoint allowed anyone to run code in an…
Are free streaming services that bad? I swapped my paid subscriptions for free ones to see.

LAS VEGAS, July 29, 2026, CyberNewswire – Sweet Security, the proactive runtime enforcement company for cloud and AI, today announced its further expansion into AI security with Agentic AI Blocking. Sweet now blocks rogue agent behavior in real time – extending Sweet’s runtime enforcement from the cloud to the AI agents that are acting alongside…

Coordinated OT cyberattacks hit 30+ Minnesota water utilities, briefly disrupting one plant. Backup procedures prevented major water service impacts. Minnesota just had its own live-fire lesson in what happens when someone targets water utilities at scale. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than…
With the new Google Home Speaker hitting store shelves, you may wonder if the Sonos Era 100 is still the best choice.
I’ve tested the best smartwatches, including the newest Samsung Galaxy Watch Ultra 2. Here’s how to choose the right one.

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

This fall, with watchOS 27, Apple Watch will finally get access to Siri AI with a software update that turns your wrist into the most widely-used wearable AI platform on Earth. That’s not hyperbole. Siri AI on Apple Watch is arguably the most important feature to this year’s watchOS update. Though it didn’t get much attention at WWDC, the update also offers…

A whole industry has sprung up around selling TikTok “growth.” Cheap views by the hundred, pre-made ad accounts, and polished sales pages promising a repeatable path to serious revenue. None of it is officially sanctioned by TikTok, and depending on what you’re buying, you could end up wasting money, losing your account, or handing your…

Cellhire has expanded its channel and business development teams with four new hires as the mobile and IoT connectivity provider looks to grow its reseller network and strengthen partner support. The UK-based company provides managed mobile connectivity, IoT connectivity, eSIM services, and temporary connectivity solutions for enterprises, channel partners, and organizations supporting remote workforces, large-scale…
Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today, I’m excited to bring you a preview of our 2026 Asia-Pacific Community Meeting keynote speaker, Dr. CJ Meadows. CJ is a globally recognized innovation and leadership expert whose work…

Huntress researchers spotted an active and ongoing series of attacks targeting SonicWall VPN and firewall accounts, which compromised 30 organizations in less than two days, the company said in a threat advisory Tuesday. The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours, according to…

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security’s

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. “A malicious actor with network…

Anthropic’s Claude Mythos Preview model has helped researchers discover ways to speed up attacks against two widely studied cryptographic algorithms. One of the targets is Hawk, a candidate for post-quantum digital signature algorithms currently being evaluated by NIST, while the other improves the best previously known attack against a weakened version of the widely used…
If you feel like your phone has turned into a scam megaphone, you’re not alone. Robocalls have been a problem for years. Artificial intelligence (AI) is making them slicker, faster, and harder to spot. A new investigation by Transaction Network Services (TNS) shows that while the big telecom players have stepped up caller ID authentication,…
Public-facing web pages aren’t built in-house anymore. They’re composed from components supplied by outsiders, and the advertising platforms have had their run of them. The exposure is enormous, and AI is accelerating it all. Related: No easy fixes for AI risk The bill for all of it is arriving now. Since 2023, hospitals and health…
It started as China vs. the US, but it’s become a face-off between two fundamentally different ways of building LLMs. And the safety of everything is on the line.

If you use and install packages from npm or PyPI, the first hours after a package is published are the riskiest because scanners can’t analyze packages before publication. Recent supply chain events affecting NodeJS and Python packages have been detected and removed within hours. However, while those packages were available to the general public, it’s…

On July 28, OpenAI published an update on the agent that escaped its sandbox and hacked into Hugging Face during an internal cybersecurity evaluation. In the update, OpenAI reiterates that the “rogue” system was a more capable, pre‑release research model, not something intended for public deployment, and that it has now been deactivated and locked…

A cyberattack on a medical billing company has potentially exposed information belonging to more than 1.26 million people, underscoring that healthcare’s biggest security risks often lie outside the hospital. Medical Computer Business Services (MCBS), a US software vendor for healthcare providers, disclosed that attackers gained unauthorized access to its network between September 22 and 26,…
AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the foundation for securing agentic AI. […]

A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning system the company uses to identify malware families that do not match known…

A coordinated cyberattack targeted operational technology at more than 30 Minnesota community water systems on July 26 and 27, triggering a statewide cybersecurity response. Braham, Plymouth, South St. Paul and Maple Plain have publicly described a plant outage, communications failures or affected automated controls. Braham’s water plant went offline, and the city asked residents to…

Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies

ShinyHunters claimed the Ernst & Young data breach, threatening to leak stolen tax records unless the firm contacts the group by July 31. The ShinyHunters cybercrime group has taken responsibility for the recently disclosed data breach involving professional services firm Ernst & Young (EY), adding the company to its Tor-based leak site and threatening to…
The Ar Gen 1 is an impressive device, suitable for anyone from students to developers to business owners.

Broadcom patched a critical VMware ESXi VM escape flaw (CVE-2026-47876) that could let attackers run code on the host from a compromised virtual machine. Broadcom has released patches to address five vulnerabilities affecting VMware ESXi, vCenter, Workstation, and Fusion, including three rated critical. The most severe, tracked as CVE-2026-47876 (CVSSv3 base score of 9.3), is a…

Stairwell, the AI SOC that stops breaches no one else can, today announced the availability of Backstory, an agentic investigation platform that traces related malware variants, identifies affected systems, and maps the full blast radius of an incident in seconds, so enterprises know what happened, where it spread, and what needs to be contained before…
Pressing the Copilot key on your laptop keyboard launches Copilot. But whether or not you use Microsoft’s AI, you can remap the key to trigger a different feature.
Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too briefly for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and…

Identity security provider Delinea has introduced runtime authorization capabilities designed to control what AI agents can do after they connect to sensitive enterprise systems. The Delinea Platform evaluates individual tool calls, commands, and database queries as they occur, allowing organizations to approve, block, or escalate agent actions instead of relying solely on authentication at the…

DefensX has expanded its browser security platform with new AI governance capabilities designed to help managed service providers secure AI adoption among small and midsize businesses. The update includes an AI Cloud Connector that isolates browser-based AI traffic and helps organizations enforce data protection and compliance policies. DefensX announced the expansion alongside a growth investment…

Unexpected AI costs altered business decisions at 62% of surveyed enterprises over the past year, while 40% required board-level escalation, according to a new report from Mavvrik and Benchmarkit. Unexpected AI costs reach the boardroom The 2026 State of AI Cost Governance Report found a growing disconnect between AI adoption and financial governance. The report…

The autonomous AI agent that escaped during OpenAI testing exploited weaknesses across a customer workload, a third-party cloud platform, and Hugging Face’s production environment before being contained, according to new technical disclosures that provide the clearest picture yet of one of the first publicly documented AI-driven intrusion chains. Hugging Face’s technical timeline identifies Modal as…
Arch Linux doesn’t have to be challenging, and ArchEZ proves that point with point-and-click ease.
A series of studies revealed that employees are spending less time asking their coworkers for help. Here’s how that tactic could backfire and how organizations need to adapt.
Australia’s premium robot vacuum market continues to heat up, with AI-powered smart home brand MOVA officially launching its flagship Z70 Ultra Roller locally, bringing a host…

AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change?…

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser’s renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. “No settings or additional…
For decades, the internet has run on a simple, often invisible truth: some of the world’s most important software is built and maintained by people who are paid little, if…

MIND has announced MIND AI DLP Agents with capabilities focused on classification, investigation, policies, remediation and exception management. MIND also includes a Model Context Protocol (MCP) interface that enables security teams to direct data security work through any MCP-connected client using natural language. AI has fundamentally changed the speed and scale at which sensitive data…
AI governance is an identity challenge, but legacy identity systems weren’t made to handle non-deterministic software.

Most organizations have incident response plans, security tools, and technical teams in place. Yet new research suggests that many still lack the coordination, visibility, and executive alignment needed to withstand a serious cyberattack. According to The State of Incident Response Readiness 2026, based on a survey of 600 senior IT security decision makers conducted by…

Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint condition with a grade “A” rating, but it still only costs $144.97 (reg. $369.99) on sale. […]
Contrast Security has announced Contrast CVE Shield, designed to help organisations defend against the growing number of exploits generated with advanced AI models such as Claude Mythos. Contrast CVE Shield runs inside the application, where it detects, monitors and blocks attempts to exploit known vulnerabilities. Applications continue to function normally while security teams gain visibility…

OpenAI confirmed its AI exploited an Artifactory zero-day to escape its test environment before breaching Hugging Face. Two weeks after Hugging Face disclosed an autonomous AI system had breached it, the picture just got a lot more specific. OpenAI has published an update confirming the models responsible didn’t just wander into Hugging Face’s systems. They…

The Federal Security Service of the Russian Federation (FSB) on Wednesday said it charged Telegram founder Pavel Durov for allegedly facilitating terrorist activities and for failing to remove prohibited information in violation of Russian law. The principal security agency said the instant messaging platform “failed to remove numerous channels, chats, and bots on the platform…

When Nvidia CEO Jensen Huang speaks, the tech industry listens. He used his first-ever post on X last week to argue that open AI models “strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.” Nvidia is a chip company (with a focus on GPUs). But it also has its own AI models that include…

Shoppers browsing on their phones are landing on convincing Walmart lookalike sites offering name-brand liquor at 40% to 70% off, only to be led straight to a checkout page asking for a full credit card number, expiry date, and CVV. The sites have no connection to Walmart. They’re part of a network of more than…

Storms, earthquakes, and infrastructure failures disrupted internet access throughout the second quarter, while governments deliberately shut networks down, according to Cloudflare’s latest Internet Disruption Summary. Based on Cloudflare Radar traffic data, the report covers internet disruptions recorded between April and June 2026. Governments switching access on and off Iran began restoring nationwide internet access on…

Our cybersecurity world can get quite interesting and even close to science fiction sometimes. No, it’s not AI this time, but something movie-worthy nevertheless. Picture scenes from known heist-themed movies such as “Ocean’s Eleven” or “Mission: Impossible”. Real-world equivalent scenarios like these are happening in front of your eyes and you might not even know…

Months before the Hugging Face breach, Emergence AI published research that investigative journalist Ronan Farrow made public. Ten autonomous AI agents operated across five virtual environments for fifteen days without human intervention. Much of the attention focused on Grok 4.1 turning violent and Gemini 3 Flash committing 683 crimes. What mattered more went unnoticed: Anthropic’s…
Cyber risk is increasing, but so is the cost of managing it. More than 514,000 cybersecurity job listings appeared in the US between May 2024 and April 2025, while the mean annual wage for an information security analyst reached $132,510. Even after the budget is approved, hiring can take three to six months, with additional time…
Students can save big on an Apple Music subscription. Here’s how to get it.

Reuters says OpenAI’s rogue AI agent also breached a Modal customer, exposing a wider attack and raising fresh concerns over autonomous AI safety. Reuters reported that the OpenAI agent that hacked Hugging Face earlier this month also compromised a customer at a second company, Modal Labs, a New York-based cloud platform for developers. Modal CTO…

Accuris has announced new AI capabilities for BOM Intelligence, part of its Supply Chain Intelligence suite. The launch gives engineering, procurement and supply chain teams a clearer way to move from spotting component risk to acting on it: catching obsolescence early, closing compliance gaps and governing sourcing decisions across programs. Every capability runs on the…