
The AI giant is racing to public markets this fall and has fielded tough investor questions on Chinese rivals, Trump-era tensions, and the artificial-intelligence infrastructure boom.
Jamie Norton reappointed Vice Chair of ISACA Board as AI governance and cyber resilience dominate boardroom priorities.
NiCE promotes AI innovation and elevates customer and employee experience, while improving environmental performance
The CyberAgents Exchange, powered by Tenable, introduces a vendor-agnostic community for security practitioners to discover, share and build trusted AI components

Meta is bringing its newest agentic AI model closer to the machines where people already work. Muse Glimmer is a 30-billion-parameter open-weight model released by Meta Superintelligence Labs on Aug. 10 under the Apache 2.0 license. Designed to run locally on compatible Macs and PCs, the model can operate without relying entirely on cloud-hosted infrastructure.…
Blue Yonder has unveiled a suite of new AI capabilities aimed at helping retailers, manufacturers and logistics providers automate increasingly complex supply chain decisions.
The misconfiguration on Klaviyo’s sign-up page allowed any third-party trackers present on the site to potentially access and share sensitive customer data.
Flexera’s 2026 State of the Cloud Report puts wasted cloud spend at 29%, the first increase in 5 years, and it’s pointing at AI workloads. Fitzroy IT CEO and founder, Tim…
– Mat Franklin to lead Oceania consulting, embedding responsible AI in technology-led consulting to deliver transformation – Raft of senior appointments across Australia bring…
PwC found 29% of customers have stopped buying from a brand over a bad experience, and almost none of them say so on the way out. Amazon Connect has just become a family of…
June 2026 Windows Updates brought a patch for CVE-2026-45586, a local privilege escalation vulnerability in Windows Collaborative Translation Framework, allowing a local unprivileged attacker to execute arbitrary code as Local System. The vulnerability was found by security researcher Nightmare-Eclipse, who published a (now deleted) proof-of-concept. This POC allowed us to reproduce the issue and create…

The Federal Trade Commission wants to start regulating ideological bias in AI systems and assert federal control over state laws. They’re getting an earful from opponents on all sides of the political spectrum. In a proposed policy statement released last month, the FTC said it was considering treating ideological bias in AI systems as an…

OpenAI announced Monday it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers. In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program – which provides unreleased frontier models to private organizations and…
We’re excited to announce that our Europe (London) AWS Region has renewed its accreditation for United Kingdom (UK) Police-Assured Secure Facilities (PASF) for Official-Sensitive data. Since 2017, the Amazon Web Services (AWS) Europe (London) Region has been accredited under the PASF program. This demonstrates our continuous commitment to adhere to the heightened expectations of customers…

NATO’s cyber defense arm and a startup that uses artificial intelligence to find software flaws can now issue the ID numbers the industry uses to track those flaws, the European Union Agency for Cybersecurity announced last week. The NATO Cyber Security Centre, part of the NATO Communications and Information Agency, and AISLE, a cybersecurity company…
Brick can curb your screen time, and it’s on sale for a limited time.

I came across a LinkedIn post the other day that described “hypegineering,” which the poster explained refers to the moment when AI “marketing becomes more innovative than the technology itself.” That post came from Ralph Aboujaoude Diaz, the global head of GRC for British consumer services company Haleon. Until last year, Diaz worked in operations…

U.S. and South Korean cyber agencies warned Monday about a ransomware-as-a-service outfit, Gunra, that reportedly recruits ethical hackers and penetration testers and benefits from North Korean government-linked hackers’ tools to target government and critical infrastructure organizations. Gunra has gone after sectors such as academia, financial services and insurance, government services and facilities, healthcare, manufacturing and…
Varonis Threat Labs researchers identified RovoBlast, a vulnerability affecting Atlassian Rovo. The flaw showed how a single crafted link could introduce attacker-controlled instructions into a user’s trusted AI session and potentially expose organizational data. Researchers Dolev Taler and Mark Vaitsman presented the findings at DEF CON 34 after responsibly reporting the vulnerability to Atlassian, which…

Claude Code will begin relying less on manual permission prompts when Anthropic makes auto mode the default for Pro, Max, and Team users starting Aug. 14. Under Claude Code’s current permission system, the coding agent can generally read files without interruption but may stop and ask for approval before taking actions such as modifying or…
It’s time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.

Moonshot AI’s Kimi K3 accessed the public internet during a controlled cybersecurity evaluation, prompting a dispute over the model’s behavior and the test environment’s configuration. US cybersecurity startup Frontier Security said it discovered the behavior while testing Kimi K3, an open-weight model developed by Chinese AI company Moonshot AI, for defensive cybersecurity tasks. According to…

Cameras on Royal Navy drone boats were found contacting a Chinese IP address during a UK Ministry of Defence cybersecurity assessment, prompting officials to cut their internet access. Kraken Technology Group’s K3 Scout vessels used the affected third-party camera subsystem. Unexpected outbound traffic from military hardware has put supplier vetting and device-level security under scrutiny.…
It may sound entirely bizarre but the prices you once paid for hotels, educational classes, or staplers could have all been higher because you used a Mac computer, lived in a certain zip code, or lacked an Office Depot in your neighborhood. No, really. In 2012, The Wall Street Journal reported that the travel booking…

We’re excited to announce that Amazon Web Services (AWS) has completed theCyberVadis assessment of its security posture with the highest score (Mature) in all assessed areas. This demonstrates our continued commitment to meet the heightened expectations for cloud service providers. Customers can now use the 2026 AWS CyberVadis report and scorecard to reduce their supplier…
As AI agents and automation platforms increasingly execute code generated by models or users, the security boundaries surrounding that code have become critical. Research presented at DEF CON 34 by Cyera researchers Vladimir Tokarev and Saar Pearl found that seven products using Pyodide relied on Python-level restrictions that did not fully isolate untrusted code from…
Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will either “speak” JSON or gRPC. One implementation often used for development is “surfpool,” which is used to test programs before deploying them…
Local AI offers organizations greater privacy, cost control, and data ownership, but running models locally does not eliminate security risks. Research presented in connection with DEF CON 34 identified 10 vulnerabilities in llama[.]cpp, a widely adopted inference engine underlying many local AI applications. Key takeaways Researchers identified 10 vulnerabilities in llama[.]cpp, including use-after-free, integer overflow,…

Attackers breached a Polish CHP plant through a Fortinet device and private APN, reaching PLCs and disrupting turbine and water treatment systems. Poland’s CERT has described a second attack on the country’s energy sector, and this one matters for a simple reason: it shows how an ordinary-looking network design can turn into a route into…
Almost two-thirds of the victims targeted in a single ransomware campaign held managerial positions or higher.
The zero-telemetry Orion browser finally makes its way to Linux as a beta release. It’s also available for MacOS, iOS, and iPadOS, with a Windows version coming soon.

Apple continues work to get White House go-ahead to source memory from Chinese supplier CXMT, which the US government has placed restrictions on. For Apple, the issue comes down to simple math. With the cost of making iPhones up 38% because of eye-watering memory price increases — up almost 7-fold since the beginning of 2025 — it makes sense…

In 2026, online scams have unfortunately become part of the new normal. They can appear almost anywhere, from social media and messaging apps to search results, websites, and online communities, and they can target anyone. Sometimes, all it takes is a moment of curiosity and a convincing offer. Among the most devastating scams are so-called…

A 20-year-old man in the United Kingdom was sentenced to two years in prison Monday after admitting to running an online abuse campaign that affected 117 victims across multiple countries during his time in the loosely organized online criminal network known as The Com. Justin Swaddle, who was a minor when committed the crimes, pleaded…

Levi Strauss said hackers used social-engineering tactics to compromise three employees, gain unauthorized access to company systems, and steal corporate data. The company, according to Reuters, has not disclosed what information was taken or whether customer data was affected, and said the incident remains under investigation. The breach comes amid a broader wave of attacks…
A security researcher is using AI to study and expose long-duration scams that abuse online trust.
Cisco is proud to announce a landmark achievement: Secure Email Threat Defense has officially achieved FedRAMP Class D (High) certification!
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was…

A routine gym booking in Australia turned into an unauthorized API action after a Claude-powered AI agent discovered it could manipulate another member’s reservation. The OpenClaw agent was asked to help an Australian user improve his position on a waitlist for a popular gym class. Instead, it found that the booking API lacked authorization checks…

Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending out data breach notification emails. “Between July 29 2026 and August 1, 2026, a cyberattack hit CEVA Logistics, the…

Amazon’s next big AI buildout in Texas comes with a massive power requirement. The company is backing a 7.65GW natural-gas plant to help supply it. The Pecos County project could generate up to 7.65 gigawatts using 35 natural-gas turbines, with most of that power initially going directly to Amazon’s nearby data center rather than the…
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. […]
This finder tag has excellent range, and it’s built for the outdoors.
I finally get full support for two displays – without paying Thunderbolt prices. But there is a catch.

As security operations teams now use large language models (LLMs) and autonomous AI agents into their daily work, a new frontier is emerging: attackers deliberately manipulating AI agents. Prompt injection attacks—where an attacker hides malicious instructions that cause an AI agent to ignore its safety rules—pose a serious risk to enterprises. These attacks continue to…
AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains why organizations are increasingly adding device trust to their Zero Trust strategies. […]

For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained…
The Ecovacs Deebot X12 OmniCyclone is not just a mouthful; it’s a market leader in features and intelligence.

Framework, the San Francisco-based company that designs repairable and upgradeable laptops, has suffered a data breach after attackers managed to exploit a zero-day vulnerability in the Metabase business intelligence service. According to the notification sent to affected Framework customers, the attackers accessed names, email addresses, phone numbers, physical addresses, and login IP addresses, but not…

A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005. A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire national registry, 9.2 million records covering essentially the whole country. Ransomnews…
This episode of Coffee with the Council is brought to you by our podcast sponsor, Clone Systems. Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today I’m excited to bring you a preview of our 2026 Europe Community…

North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security…

Microsoft is changing how Entra ID handles MFA for people who sign in with Windows Hello for Business (WHfB) or macOS Platform Single Sign-On (PSSO). The rollout reaches worldwide and GCC tenants starting early October 2026, with completion expected by late November. Microsoft says the change “helps organizations expand the use of phishing-resistant authentication methods”…

Microsoft is beginning the retirement of Manifest V2 (MV2) extensions in Edge this month, with consumer completion targeted for the end of 2026 and managed-enterprise deprecation in early 2027. Microsoft says that change is justified because 95% of the most-used MV2 extensions in the Edge Add-ons store have already moved to Manifest V3 (MV3). It…
Editor’s note: This work is a collaboration between Mauro Eldritch from BCA LTD, a company dedicated to threat intelligence and hunting, Heiner García from NorthScan, a threat intelligence initiative uncovering North Korean IT worker infiltration, and ANY.RUN, the leading company in malware analysis and threat intelligence. The article was written by Mauro and Heiner. Key…
I used Claude Cowork to automate a workflow, and the result was remarkably effective, but it exposed four serious drawbacks.

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim’s machine, and used a

OpenAI said its upcoming model Astra is showing cybersecurity capabilities that could reach its highest risk category, where a system can autonomously find and exploit vulnerabilities or carry out end-to-end cyberattacks against hardened targets. The company disclosed the assessment following recent internal testing and expert reviews. “Our latest internal evaluations of Astra, one of our…

Atlassian’s enterprise AI assistant Rovo, which is usually connected across sensitive work environments like Slack, Microsoft 365, and Google Workspace, was found vulnerable to data leaks through malicious instructions. At DEF CON 34, researchers from Varonis demonstrated an attack that used Rovo’s rovoChatPrompt parameter to place attacker-controlled instructions directly into Rovo Chat. “A single click…

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse,…

While the number of US jobs declined by 23,000 in July, employment in the tech sector rebounded as the AI revolution continues to gain steam. The national unemployment numbers were reported Friday by the US Bureau of Labor Statistics. At the same time, research firms said July was a good month for IT hiring compared…

To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers,”…