(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
Invest in Data Readiness to Benefit from a Healthcare AI Future
Global Security News
What to Look For in Regional Tractor Dealers
Global Security News
Agentic AI Era Demands Overhaul of Governance Frameworks
Global Security News
Quantum Computing A Looming Threat To Corporate IT Security
Global Security News
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
Global Security News
Cloudera and Mercy Corps Deepen Partnership with Agentic AI Built for Humanitarian Response
Global Security News
Claroty and Frenos partner to reduce downtime risk for industrial environments
Global Security News
ESGAgent.ai Closes Seed Round to Accelerate AI-Driven Compliance
Global Security News
CETA System: Cooling Demand Spikes
Extreme heat, grid curtailments and climate-linked insurance losses reshape data-centre cooling economics, pushing predictive thermal management and advisory-first automation…
Global Security News
Sophos Firewall v22 MR2 is now available
Global Security News
Apple’s ‘Thermonuclear’ Response to the OpenAI Threat
Global Security News
Debian 13.6 security update patches over a hundred advisories in trixie
Most PCs still run with a UEFI Secure Boot certificate authority, installed by default since 2013, that has now expired. That certificate signed the bootloaders letting machines start with Secure Boot turned on. Its expiry sits at the center of the sixth update to Debian 13, codenamed “trixie.” The point release carries mostly security corrections…
Global Security News
Micropatches released for Desktop Window Manager Elevation of Privilege Vulnerability (CVE-2026-20871)
January 2026 Windows Updates brought a patch for CVE-2026-20871, a local privilege escalation vulnerability in Desktop Window Manager, allowing a local unprivileged attacker to execute arbitrary code as System. The vulnerability was anonymously reported to Microsoft through Trend Zero Day Initiative, but the official patch was reverse engineered and turned into a proof-of-concept by Joe…
Global Security News
Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations

An alleged Ryuk ransomware member pleaded guilty in the U.S. for helping deploy attacks on American companies and faces up to 15 years in prison. Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. Extradited from Ukraine after his…
GeekGuyBlog
Best Performing Models for OpenClaw, (Claudebot, Moltbot) & Hermes Agent
Editors Choice (Local): Qwen3_5-9B-DeepSeek-V4-Flash-Q4_K_M Model Name Developer Context Window Hardware Requirements Primary Use Case Estimated Monthly Cost Performance Rating (Inferred) Claude Opus 4.5 Anthropic Long-context (standard benchmark) Cloud-based / Managed Agentic reasoning, complex planning, high-stakes coding, proactive assistant $180 – $750 Benchmark / SOTA Reasoning GPT-5.2 (Codex) OpenAI 400,000 Cloud-based / Managed High-stakes software architecture,…
Top Tech Tools
Top 10 Hall Effect Keyboards of 2026: Comprehensive Review & Buying Guide

Report Date: July 12, 2026 Data Validated: All prices, specs, reviews, and availability confirmed as current 2026 Executive Summary Hall Effect magnetic switch keyboards have revolutionized the gaming and productivity peripheral market in 2026. These keyboards feature magnetic sensors that detect actuation at any point between 0.1mm and 3.8mm, enabling Rapid Trigger technology that eliminates the…
Global Security News
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
Global Security News
Progress Told ShareFile Customers to Pull the Plug on Their Servers. Here’s What We Know.

Progress urged ShareFile Storage Zone customers to shut down internet-facing servers immediately over a credible security threat under investigation. Progress Software sent an urgent email to ShareFile customers the evening of July 10 with a subject line that left no room for ambiguity: “Service Disruption. Immediate Action Required.” The company told customers running Storage Zone…
Global Security News
RedHook Android malware now uses Wireless ADB for shell access
Global Security News
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 105

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Novel Java-Based QuimaRAT Targets Windows, macOS, and Linux Vibe Coded Extortion: Avalon’s Path from Legal Lure to CrownX Ransom Capabilities Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign RedWing: A…
Global Security News
Intel’s Insiders
Global Security News
Pricier iPhones Are Coming. What—and When—Should You Buy?
Global Security News
Company That Bragged It Could Track U.S. Spies Hired to Investigate “Havana Syndrome”

The U.S. military inquiry into the so-called Havana syndrome, the mysterious illness claimed by a litany of American intelligence officers, is tapping a controversial contractor: a private surveillance firm that once boasted of its ability to stalk American intelligence officers. Documents obtained by The Intercept through a Freedom of Information Act request reveal that technology…
Global Security News
On AI Ethics: Why Prompt Engineering Needs a Moral Compass
In this first of a three-part series, we look at why “working as designed” is no longer good enough for enterprise AI or cybersecurity pros.
Global Security News
Can AI Make Better Drugs? Not on Wall Street’s Timeline
Global Security News
The best email hosting for small businesses in 2026: Expert tested
I tested Google Workspace, Proton Mail, Microsoft 365, Fastmail, and Spike to find the best email hosting for freelancers and remote teams in 2026.
Global Security News
Week in review: Accenture data breach, great open-source cybersecurity tools
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Securing the inbox: Where identity, brand and security meet Getting a verified logo to appear next to your email has traditionally meant having to work with two separate entities. You have to work with a DMARC partner for setting up…
Global Security News
Security Affairs newsletter Round 585 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog Critical U-Boot…
Global Security News
The Hard-Line Activists Ramping Up for the War With AI
Global Security News
U.S. CISA adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added iCagenda and Balbooa Forms flaws to its Known Exploited Vulnerabilities (KEV) catalog. The flaws added to the catalog are: CVE-2026-48939 (CVSS score of 10.0) iCagenda Unrestricted Upload of File…
Global Security News
Compromised jscrambler 8.14.0 npm Release Drops Rust Infostealer During Install

Version 8.14.0 of the jscrambler npm package shipped with a malicious preinstall hook that silently drops and runs a native infostealer during installation, one build each for Windows, macOS, and Linux. Published on July 11, 2026, it needs no import and no CLI call. Installing 8.14.0 is enough to run it. Socket flagged the release six minutes after it was
Global Security News
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns

Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. “At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and
Global Security News
Critical U-Boot Bugs Undermine Secure Boot on Millions of Devices

Binarly found six U-Boot flaws, including two that enable code execution during boot image verification, impacting 50+ releases. Binarly’s research team has found six vulnerabilities in U-Boot, the open-source bootloader that runs on home routers, smart cameras, server management controllers, and a large portion of the embedded hardware that powers the internet. All six are…
Global Security News
Australia warns of global campaign targeting vulnerable CMS platforms
Global Security News
How AI Advice Is Undermining Eating-Disorder Therapy
Global Security News
‘Rotten to its core’ — Apple files an explosive lawsuit against OpenAI

Apple surprised the tech industry after financial markets closed Friday with news the company has sued OpenAI, alleging theft of trade secrets for ChatGPT hardware. The lawsuit particularly targets some senior ex-Apple employees now working at OpenAI. Apple’s suit names two former employees — Chang Liu and Tang Tan, former vice president for product design, iPhone and…
Global Security News
Washington’s Bet on Intel Is Starting to Pay Off
Global Security News
Apple is prepping for life after the AI gold rush

Consumer electronics prices are shooting up. Energy prices are increasing fast. Even water bills are climbing. For a technology that promises “efficiency,” the ongoing AI gold rush seems to be taking things away, much like the proverbial gift that keeps on grabbing. With hundreds of billions in AI investment already racked up for 2026, it’s important to remember the entire…
Global Security News
Alex Karp Is Saying What Every Angry CEO Is Thinking About AI
Global Security News
Wireshark 4.6.7 Released, (Sat, Jul 11th)
Wireshark release 4.6.7 fixes 12 vulnerabilities and 16 bugs. Didier Stevens Senior handler blog.DidierStevens.com (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
‘Ghostcommit’ hides prompt injection in images to fool AI agents, steal secrets

A PNG hiding a prompt injection could steal your repo’s secrets, researchers demonstrate. The technique, dubbed ‘Ghostcommit,’ slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repo’s .env and write every secret into the code as a list of numbers. […]
Global Security News
Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions

Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to execute malicious scripts in a user’s session. It has yet…
Global Security News
The White House Made Fixing Intel Its Pet Project. It’s Working.
Global Security News
X4 Air vs. X5: Which Insta360 Camera Is Right for You?
Choosing a 360-degree camera often comes down to a simple tradeoff: convenience versus image quality in difficult conditions. For most users, the real challenge is not what…
Global Security News
6 Top Virtual CDN (vCDN) Providers for 2026
Content delivery has become a control problem, not only an infrastructure problem. A single CDN can still move files closer to users, cache assets, and reduce origin load. But…
Global Security News
New U-Boot flaws could enable stealthy firmware attacks
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during device boot, potentially enabling stealthy firmware attacks that compromise security protections and install persistent malware. […]
Global Security News
Researcher finds 9 vulnerabilities in ATM security software
Global Security News
Silver Fox group uses new Rust-based MODBEACON RAT
Global Security News
Keysight launches new cybersecurity test platform for AI traffic
Global Security News
NHS staff warned of jail time for unauthorized patient data access
Global Security News
Scottish NHS Trust staff member emailed personal patient data
Global Security News
Inmate charged with stealing seized cryptocurrency while serving prison sentence
Global Security News
Zimbra urges patching of critical XSS vulnerability in Classic Web Client
Global Security News
Dutch police suspect Dutch hackers in Odido data breach
Global Security News
Progress Software warns ShareFile users of external security threat
Global Security News
Armenian man pleads guilty to deploying Ryuk ransomware
Global Security News
Miinto customer data accessed in security incident
Global Security News
CISA shares postmortem of GitHub credential leak
Global Security News
Veeam Names Michelle Graff as SVP of Global Partners and Channel
Veeam Software has appointed former Commvault channel executive Michelle Graff as senior vice president of global partners and channel, putting her in charge of a worldwide ecosystem of more than 35,000 partners as the company expands its focus on data resilience, cybersecurity, and AI readiness. Veeam prioritizes a unified global partner experience The focus for…
Global Security News
Former ransomware negotiator sentenced to 70 months for extorting $75.3 million
Global Security News
Post-quantum HTTPS migration faces enterprise browser challenges
Global Security News
OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute
Global Security News
Injective Labs SDK npm package compromised to steal cryptocurrency keys
Global Security News
Opinion | The Economics of Friendship
Global Security News
Opinion | Is Private AI Regulation Constitutional?
Google recommends an industry body, but its power would be subject to judicial scrutiny.
Global Security News
Borg, GitLost, ColdFusion, GodDamn, GhostApproval, OWA, Epaphroditus, Josh Marpet,.. – SWN #597
Global Security News
Red Hat will support your RHEL forever now – for a price
Red Hat’s new Long-Life Add-On extends support on a specific release for as long as you’re willing to pay for it.
Global Security News
Update Now: Critical Zimbra Classic Web Client Flaw Could Expose Mailboxes
Zimbra addressed a critical stored XSS vulnerability in its Classic Web Client that lets malicious emails execute code when opened. Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, which is widely used to access Zimbra Collaboration. The flaw, which has not yet received a CVE ID,…
Global Security News
Apple Sues OpenAI, Alleging It Stole Trade Secrets
Global Security News
WP-SHELLSTORM Exposed: Hackers Backdoored Thousands of WordPress Websites
A simple operational mistake by a cybercrime group has provided researchers with an inside look at how large-scale website compromises are conducted. According to research from SOCRadar, an internet-exposed server belonging to a threat group tracked as WP-SHELLSTORM remained publicly accessible for approximately three weeks. “WP-SHELLSTORM is industrialized cybercrime made visible because someone left a…
Global Security News
Okta warns of vishing scheme that extorts data
Global Security News
Armenian national pleads guilty to Ryuk ransomware attacks

An Armenian national who was extradited from Ukraine to the United States last year pleaded guilty to participating in a series of attacks in 2019 and 2020 involving Ryuk ransomware, the Justice Department said Thursday. Karen Serobovich Vardanyan pleaded guilty to computer fraud and conspiracy to commit fraud and extortion. He agreed to pay nearly…
Global Security News
Turning the Tables on Email Scammers With ‘ScamBuster’
Global Security News
Jen Ellis: Connecting Cyber Community With Political Machinery
On the heels of her recent honors as a Member of the Order of the British Empire (MBE), we take a look back at the events that shaped Ellis’ advocacy on behalf of security researchers.
Global Security News
CISA looks to remedy ailments from big May credential leak

A major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report released Thursday. The blog post outlines CISA’s response to the leak that the researcher who discovered it…
Global Security News
Autonomous AI Defense: It’s Time to Take AI Off the Leash
This is the final article in our series by Curt Aubley, CEO of Sevii. If you missed the prior installments, please read the first and second articles in the series. For too long, the security operations center (SOC) has resembled a M.A.S.H. unit. Relentless waves of enemies divide focus and drain resources. At the same…
Global Security News
Structured Expands AI Partner Marketing Platform

Structured has expanded its AI-native partner marketing platform with nearly 60 new capabilities spanning AI-powered analytics, campaign automation, enterprise integrations, and pipeline reporting, marking its first major product update roughly 100 days after the platform’s launch. The updates introduce AI agents that answer campaign performance questions in natural language, deeper integrations with Salesforce and Adobe…
Global Security News
Opinion | Will Washington State Choose Stagnation Over Growth?
As the Evergreen State throws money at AI data centers, it ignores the builders of tomorrow.
Global Security News
Stop trying to ‘lock down’ your AI: Why rigid guardrails are a gift to hackers
Flexible governance, not restriction, of AI agents preserves productivity while providing oversight and accountability.
Global Security News
How Custom Packaging Strengthens Brand Recognition in the Digital Age

In this post, I will show you how custom packaging strengthens brand recognition in the digital age. Businesses need to figure out how to be different from others and leave a lasting impact on clients in today’s extremely competitive industry. Packaging has developed into a potent branding tool that affects consumer perceptions and purchase decisions,…
Global Security News
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
Global Security News
Why Enterprise VR is Gaining Attention Across Industries

In this post, I will show you why enterprise VR is gaining attention across industries. Virtual reality used to be discussed mostly in the context of gaming, tech demos, and big promises about the future. That has changed quite a bit. More businesses are now looking at VR as a practical tool rather than a…
Global Security News
Injective Labs GitHub Compromise Pushes Wallet-Key-Stealing npm Packages

Unknown threat actors compromised the Injective Labs SDK project’s GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with fake telemetry functionality that exfiltrated data from cryptocurrency wallets. The version was
Global Security News
SpaceX wants to launch 100,000 more Starlink satellites – for 100x the bandwidth
It could mean faster internet for rural customers, but not everyone is happy.
Global Security News
Sony 1000X The Collexion vs. Bowers & Wilkins Px8 S2: Both wow, but one is comfier
Global Security News
Cybercriminals Flock to Healthcare Businesses as Attacks Surge
Global Security News
I ditched Google Drive for my own self-hosted storage – and I wish I’d done it sooner
Nextcloud is a free and open-source storage option that offers several advantages. Here’s how it works.
Global Security News
Police suspects Dutch hackers were involved in Odido breach
Global Security News
URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a “credible external security threat.” The company has temporarily disabled access to the affected accounts, a step it says it took “out of an abundance of caution” while…
Global Security News
Progress urges ShareFile customers to shut down servers over “credible” threat
Global Security News
The AI Cybersecurity Gap Between Attackers and Defenders

Adversaries have no compliance reviews for their AI deployments. There are no approval chains, no token budgets and no governance committee debating whether a model is ready for autonomous action. They simply use AI aggressively and without constraint to overwhelm defenses. This is the second article in our series by Curt Aubley, CEO of Sevii.…
Global Security News
AWS designated as a critical third party to the UK financial sector

Amazon Web Services EMEA Sarl (AWS) has been designated as a critical third party (CTP) to the UK financial sector by HM Treasury. The CTP regime came into force on January 1, 2025, and establishes a framework through which the Bank of England, PRA, and FCA (collectively the UK regulators) can set requirements on and…
Global Security News
CISA Details Incident Response to Exposed AWS GovCloud Keys
Global Security News
Six New U-Boot Flaws Could Let Malicious Images Crash Devices or Run Code at Boot

Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who slips a malicious image in front of…
Global Security News
Hackers exploit critical auth bypass in Gitea Docker image
Global Security News
Regulatory frameworks are enablers, not burdens
Global Security News
Money launderer accused of stealing seized crypto while in prison
Global Security News
Microsoft Warns New ‘GigaWiper’ Malware Combines Espionage and Destructive Capabilities
Global Security News
Laser Attack Resets Tangem Wallet Passwords on Cards That Can’t Be Patched

Researchers at Ledger’s Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card’s password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is…


















































