
The cloud-computing company’s stock jumped 19% and lifted other shares tied to the artificial-intelligence build-out.

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. As of publication time,…

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. As of publication time,…

Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. Nightmare Eclipse has not…

Proprietary AI companies such as OpenAI have secured multibillion-dollar infrastructure agreements to meet growing demand. Together AI is now making a sizable infrastructure commitment of its own. IBM and Together AI have signed a multi-year, $240 million agreement under which IBM plans to deploy a large cluster of NVIDIA HGX B300 systems on IBM Cloud.…

CEVA Logistics suffered a cyberattack disrupting European operations, with eight warehouses affected and shipments halted at impacted sites. CEVA Logistics suffered a cyberattack on July 29 that disrupted parts of its European operations. The incident impacted impacted eight warehouses, and the company is still working to restore impacted services. CEVA Logistics operates in more than…

Horizon3 is investing $20 million in its global partner ecosystem, expanding channel leadership, partner enablement, incentives, strategic alliances, and go-to-market support. The cybersecurity company, which says 90% of its business flows through partners, is positioning the investment to help MSPs and other channel partners build more profitable proactive security practices and accelerate customer growth. Investment…

Europe’s favorite vibe-coding startup Lovable has confirmed previously reported whispers that it was raising another mega round at a $13.3 billion valuation. Lovable said on Wednesday that it has raised $400 million in a Series C round led by Menlo Ventures and the Scaleup Europe Fund, with more than a dozen other investors participating. This new funding comes after…

A ransomware takedown can sever part of a criminal operation. DeadLock is designed to recover when some of that infrastructure disappears. Microsoft Threat Intelligence says the ransomware uses decentralized services to keep victim communications available after individual servers are disrupted. Researchers began tracking the Rust-based malware in July 2025. Company analysis identifies both the decentralized…

More than 15 million people may now have a very personal problem: their dental, government ID and health information could be in the hands of hackers. DentaQuest, a major U.S. dental and vision benefits administrator, has begun notifying individuals affected by a May 2026 cyberattack that compromised sensitive personal and health information. The company reported…
A clever new credential phishing campaign is masquerading as a routine missed voicemail notification to trick unsuspecting workers into handing over their Google account passwords. Security researcher Anurag recently uncovered the campaign and shared details with Cyber Security News, revealing a deceptive scheme that uses urgency and fake audio alerts to quietly lure targets into…

China-linked hackers reportedly used eight AI agents to breach a government network, steal data and compromise accounts with minimal human oversight. Israeli cybersecurity firm Dream documented what looks like the first fully autonomous, end-to-end AI hacking operation against a government target. Over four days at the start of July, according to the Financial Times, suspected…

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running…
Google’s latest lineup of Pixel 11 phones is here, and Amazon has a free gift card offer on every single one.
Got an old 32-bit computer lying around? Don’t throw it away – Sparky Linux has decided not to give up on the aging architecture.

Multiple vulnerabilities have been discovered in SonicWall Global Management System (GMS), the most severe of which could allow for remote code execution. The SonicWall Global Management System (GMS) is a centralized management interface used to deploy and centrally manage SonicWall firewall, wireless, email security, secure remote access and Dell X-Series solutions from a single console.…

Suspected Chinese hackers used open-source artificial intelligence models to run a cyberattack against the Taiwanese government in the first publicly known case of an autonomous AI hack hitting a government target, according to research published Wednesday. The hackers extracted more than 2,500 personnel records, among other data, in the “near-autonomous attack,” researchers at Israeli cyber…

According to Picus’s Blue Report 2026, enterprise cybersecurity defenses improved in 2026. However, organizations continue to struggle with detecting stealthy attacker behavior and converting security telemetry into actionable alerts. The report analyzed more than 338 million simulated attacks conducted in Picus customer environments between January and June 2026. Picus measured how effectively existing security controls…

Lead times of nine to 12 or even 18 months. Costs rising by 35%, 45%, even 50% to 200%. More than halfway through 2026, the market for IT infrastructure that’s crucial for enterprise projects, including those involving artificial intelligence, is strapped. Memory is at the root of the shortages. Memory prices “have risen by 50%…
Hackers who steal compromising images of you from social media and personal accounts are selling them on the dark web. Here’s how to protect yourself.
Google’s new flagship Pixel series was just announced, and T-Mobile has plenty of preorder offers to choose from.
We’ve got the scoop on where you can preorder the latest Google devices announced at Made by Google, including the Pixel 11 lineup and the Pixel Watch 5.

Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install…

A vulnerability has been discovered in Zoom Clients that could allow for remote code execution. Zoom is a cloud-based communications platform that allows users to connect via video, audio, chat, and content sharing. Successful exploitation could allow an attacker to target meeting participants, execute code without user interaction, steal data, activate cameras or microphones, and…

Generative artificial intelligence (GenAI) has rapidly changed software development by allowing developers to generate functional code faster and at greater scale. However, Veracode’s 2026 GenAI Code Security Report reveals a disconnect between improvements in AI coding capability and improvements in security. Although modern large language models (LLMs) can produce syntactically correct code almost perfectly, their…

Researchers have found three vulnerabilities in the popular Zoom meeting platform that could let one meeting participant attack another through malicious collaboration data. The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, affect the code Zoom uses to process annotation data shared during meetings. The researchers named the set of flaws “Zoomsday.” Affected applications are: Zoom…
A couple of days ago, Xavier posted about Atuin to gain more insight into the command history. Atuin does a great job of better organizing what is usually handled by “bash_history” and collecting meaningful additional data. Our reader David commented that this can also be done quite well with Linux’s kernel process accounting feature, and I…
Google’s latest Pixel phones are here, and we found the best cases to protect your new Pixel 11, Pixel 11 Pro, Pixel 11 Pro XL, or Pixel 11 Pro Fold.
The exploited zero-day flaw could allow an attacker to gain system privileges on a Windows PC.
The FBI warns that cybercriminals are targeting adults’ and children’s social media and other online accounts to steal sexually explicit images or videos. […]

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those…
The Google Pixel Watch 5 is a big upgrade over its predecessor, but is it enough to take on the Apple Watch Series 11?
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help organizations confirm that the person receiving access is the legitimate new hire. […]
The two Google and Apple phones go neck to neck against each other, but only one will suit your needs.
Strength training is all the buzz. Google built a special exercise experience into the Pixel Watch 5 to make it easier to get started.
If you passed on the Pixel 10 in favor of your Pixel 9, you may find the latest Google Pixel 11 a more compelling upgrade.
Verizon is offering several deals on the Pixel 11 line – find out how to preorder yours now.
The Pixel 11 and the Galaxy Z Fold 8 offer very different user experiences. Which is for you? Here’s how they compare.
Although the design is largely unchanged, the Pixel 11 packs meaningful upgrades, including the Tensor G6 chip and improved cameras.
I compared the top Android smartwatches of the year arriving to the market only weeks apart.
Samsung’s Galaxy Z Fold 8 is one of my favorite phones of the year. Here’s how it compares to Google’s new book-style foldable.
Both models are large and boast the best from each manufacturer, but which one makes the most sense for your needs?
Google’s new finder tags use an emerging Bluetooth technology to stand apart from competing devices made by Apple and Samsung.
Google’s new Pixel 11 Pro Fold comes hot on the heels of Samsung’s successful Ultra foldable. Here’s how the two stack up.
Google’s new Pixel 11 Pro has a lot going for it, but how does it stack against Samsung’s Galaxy S26?
Google’s latest Pixel lineup is a little pricier, has a new LED lighting feature, and debuts alongside a new finder tag.
It’s not as cutesy and charming as the Galaxy Z Fold 8, but the latest Pixel foldable is still the top choice for key aspects.

Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now resolving to a generic rented server from a German hosting provider. From that server, someone has been pulling records…
Both are astonishingly capable, but subscription choices, coding environments, and hidden ecosystem advantages could make one better for you personally.
Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely…

Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification provides an additional, streamlined way to confirm that there’s no unexpected party between you and the other ‘end’ of an end-to-end…

ScienceLogic has announced Skylar AI 2.5, expanding secure deployment options for organizations with stringent security, sovereignty, and compliance requirements, while introducing enhancements that strengthen AI performance, operational intelligence, and enterprise integrations. The release further improves AI accuracy, platform performance, and natural language user experience across the ScienceLogic AI Platform. Serving as the intelligence layer of…
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong

Deloitte has expanded AI Controls and Assurance services and solutions designed to help organizations confidently adopt, scale and govern AI across the enterprise. From early exploration to enterprise deployment, Deloitte’s enhanced services provide end-to-end support across the AI lifecycle, combining advisory and assurance services across governance frameworks and AI-enabled transformation to help organizations manage risk…
Every day, your SOC drowns in isolated alerts — a suspicious login here, an odd process spawn there, a strange outbound connection somewhere else. Individually, each one looks like noise. Together, they might be the early signature of a coordinated adversary campaign already unfolding inside your environment. The problem isn’t a lack of data —…
ThreatDown found that 74% of organizations are exposed to shadow AI, highlighting a widening governance gap as employees adopt unsanctioned AI tools beyond the visibility of IT and security teams. Shadow AI exposure reveals enterprise visibility gaps Shadow AI refers to the unsanctioned use of AI tools, models, and browser features by employees without organizational…
Cisco has disclosed a high-severity vulnerability in Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software that is already being exploited in the wild. Tracked as CVE-2026-20349, the flaw carries a CVSS score of 8.6 and allows an unauthenticated remote attacker to force an affected firewall to reload, resulting in a…
Microsoft’s August 2026 Patch Tuesday addresses hundreds of security vulnerabilities, but one issue stands out because attackers were already exploiting it before a fix became available. CVE-2026-68820 is a high-severity elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock, or AFD.sys, that can allow a local attacker to escalate privileges to SYSTEM. The flaw…
Aptoide Games just landed in the Play Store – no sideloading required. I tested it, and caution is advised.

Apple is in the process of tweaking its business models to cope with the unyielding memory price and availability crisis. Its response is now emerging across multiple fronts. Finance or lease The company’s recently-introduced Apple Upgrade scheme in partnership with Klarna is a smart response to the reality that as devices inevitably become more expensive, consumers will…
For over two decades, the NIST National Vulnerability Database (NVD) has served as the U.S. government repository for standards-based vulnerability management data and as a foundational resource for cybersecurity risk analysis, vulnerability management, compliance automation, and software security. New Opportunities for the NVD via Automation Our cybersecurity landscape is changing dramatically and is being reconfigured…

Security information and event management (SIEM) solutions help organizations collect and analyze data across IT and cybersecurity systems to detect threats, investigate suspicious activity, and manage security risks. The best SIEM solutions also support real-time monitoring, compliance requirements, and faster incident response by giving security teams greater visibility into their environments. To help you find…

The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream Job, a long-running campaign in which attackers pose as recruiters and lure targets with job opportunities at well-known…

A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers’ reasoning APIs, where a block created in one session could be replayed…

Enterprise defenses are tuned to catch the attacks that make noise. This year’s data shows attackers winning by making none. According to Picus Labs’ new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest…
The main reason I switched to Mint was that the service uses the same 5G and LTE networks as T-Mobile. So why pay a lot more for basically the same service?

A convincing fake version of the widely used CCleaner utility is being used to deliver a multi-stage Windows malware that ultimately abuses Google Chrome for credential theft and surveillance. Researchers from Malwarebytes found the campaign distributing a malicious Chrome extension called GhostDesk, which can capture credentials, cookies, keystrokes, and screenshots while also allowing attackers to…

Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below – CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could

It’s likely that many enterprises have created — or are at least considering — AI policies that clearly lay out approved AI tools and their uses, set up training programs for employees to help them use the tools in their jobs, and establish guardrails around those systems to avoid issues such as security vulnerabilities and…

Zaelab, a digital consultancy for complex enterprises modernizing CX and revenue operations, has been selected by Anthropic as a delivery partner to help enterprises turn AI pilots into production-ready solutions. Zaelab targets the AI pilot-to-production gap This combination will bring together Zaelab’s enterprise delivery experience with Anthropic’s Claude models, helping organizations move AI from proof…
July 2026 was full of executive shifts, including roles aimed at expanding platforms and global reach. Read more about the leadership appointments from organizations such as OpenAI, Databricks, and DDN below. Don’t forget to go back and check out Part 1 of our July 2026 Leadership Recap. OpenAI hires Philip Larson as Senior Director of…

OpenAI has released GPT-5.6-Cyber, a cybersecurity-specific model designed to handle advanced defensive work that general-purpose models often refuse, including exploit validation, vulnerability research, and exploit-chain development. The model is available through Daybreak Red, a restricted access tier for vetted defenders conducting authorized security testing. In OpenAI’s internal testing, GPT-5.6-Cyber completed 95% of advanced cyber requests,…

Technology provider C Spire has earned the Cisco Secure Networking Specialization in the US – one of four organizations in the country to achieve the designation. Specialization builds on a 19-year Cisco partnership In receiving this designation, the 19-year Cisco partner underwent a comprehensive three-day assessment of its technical capabilities, service delivery processes, and customer…

The MSP merger and acquisition market continues to attract private equity and strategic buyers, but service providers hoping to capitalize on that demand must prepare their businesses—and themselves—well before entering a transaction. MSP valuations remain at six to eight times EBITDA Speaking at GTIA ChannelCon 2026, Craig Fulton, M&A advisor at Evergreen, said buyer interest…