
When done correctly, regulations can help companies restore operations quickly and maintain trust after a breach.


Researchers at Ledger’s Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card’s password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and can move the coins out. This is…

Members of the European Parliament (MEPs) have failed to block a proposal extending the mass scanning of private communications, a measure they have previously rejected twice. This time too, more votes were cast against the proposal than in favor, but due to the absence of numerous MEPs on the eve of the summer recess, the…

It’s the end of the road for yet another facet of Exchange Server, Microsoft’s on-premises email and calendar system. The stripped-down version of its web client, Outlook Web App (OWA) Light, is being retired, forcing those Exchange Server users still using it to adopt the standard Outlook Web App instead. “OWA Light was created for…

Security company CrowdStrike has identified five new prompt injection techniques that could leave enterprises at risk. Prompt injections attacks exploit the growing use of AI within organizations . They work by tricking LLMs into accepting instructions that a human operator would recognize as dubious. The five new types of attack that CrowdStrike has added to…
Trustifi, an AI-driven, next-generation email cybersecurity solutions provider, has appointed Jeff Spirdgeon as its new CEO, a channel and technology industry veteran. Prior to joining Trustifi, Spridgeon was with Aware, an AI-powered collaboration security platform that protects unstructured data in workplace communications tools. Aware was acquired by Mimecast in 2024. In an interview with Channel…

Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulnerabilities is as follows – GHSA-hjr6-g723-hmfm (CVSS score: 8.8) – An operating system

French AI company Mistral claims its latest AI model offers a more efficient way to train and operate robots. The model, Robostral Navigate, can guide a robot through plain language instructions, using a single RGB camera to find its way. Mistral said that this was a radical departure from most other models, which rely on…
AI agents are accelerating the growth of non-human identities, making it harder for organizations to understand what exists, who owns it, and what it can access. Netwrix explains why stronger visibility and identity governance are essential as AI expands the enterprise attack surface. […]
Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.

Microsoft published new research on GigaWiper, a modular Golang backdoor for Windows that combines robust remote access with multiple ways to permanently destroy systems and data. GigaWiper is a Windows backdoor that Microsoft has observed in intrusions since October 2025. Rather than being a single-purpose wiper, it’s an operational platform that blends command‑and‑control (C2), data…
Welcome to the PCI Security Standards Council’s blog series, The AI Exchange: Innovators in Payment Security. This special, ongoing feature of our PCI Perspectives blog offers a resource for payment security industry stakeholders to exchange information about how they are adopting and implementing artificial intelligence (AI) into their organizations.
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational

Apple has agreed to buy up to $30 billion-worth of additional chips and other wireless components from Broadcom over the next few years. The new agreement could lead to Broadcom making up to 15 billion more chips in the US, and enable it to modernize its manufacturing facilities in Fort Collins, Colorado, where it will…

Globant recently signed an agreement with AI giant Anthropic, bringing Latin America-based provider into the Anthropic Partner Program and expanding how the companies work together for mutual customers. In this interview with Channel Insider’s Victoria Durgin, Globant SVP of Digital Innovation Augstin Huerta discusses the company’s AI PODS model, how it manages token costs for…
AI coding tools cost $19-$200/month/user, but security scanning, remediation, and false positives add hidden costs. Are the productivity gains worth it?
AI’s ushered in a new era of reskilling. Here’s what the industry can learn from the last decade’s drive to put people in tech jobs.
Ransomware remains above 1,400 attacks yearly since 2023. Qilin leads in 2026, while the U.S. remains the main target. Ransomnews has independently confirmed 9,291 ransomware attacks worldwide between January 2018 and July 2026, tracking incidents only when verified through victim disclosures, regulatory filings, official statements, or credible press reporting. Leak-site listings alone don’t qualify, operators…

Incode has launched On-Device Age Estimation, an age verification capability that performs age estimation and liveness detection directly on the user’s device, without transmitting facial data off the device. The company’s age estimation models are now available to run entirely on-device. The solution combines on-device age estimation with deepfake and spoofing detection. More than 30…
A single wrong variable on one line in XQUIC, Alibaba’s QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets:…
Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a single view, and every downstream security program inherits whatever the inventory gets wrong.…

A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation’s inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking…

Mule betting or third-party betting account scams are a form of money mule scam where criminals recruit or coerce people into opening gambling accounts in their own name. The criminals then use those accounts to place bets to help launder money and obscure the source or ownership of funds. The UK Gambling Commission describes “mule”…
We tested the top wireless chargers from brands like Anker and Nomad to find the ones that make powering your devices easier than ever.
Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been installed more than 2.4 billion…

Updating Chrome is becoming an almost daily task lately. But it’s too important to ignore. On Wednesday, July 8, Google released another Chrome update, just one day later after the previous one. Between them, the two updates fixed 27 security vulnerabilities, including two critical flaws that could be exploited to compromise Chrome. Google says both…

A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-UNC-066, has deployed a panel-controlled phishing kit that’s capable of targeting…

Researchers uncovered 222 GitHub repositories spreading malware through fake Go packages, delivering loaders, stealers, RATs, and cryptominers. Socket’s security research team started with the investigation of a single malicious Go module: github[.]com/kaleidora/dnsub-scanning-tool, which presented itself as a DNS and subdomain scanning utility. Pulling on that thread exposed something significantly larger: a network of 222 confirmed…

Meta has unveiled Muse Spark 1.1, saying the frontier AI model rivals leading LLMs on coding, computer use, and agentic AI benchmarks while undercutting OpenAI and Anthropic on API pricing, potentially lowering the cost of deploying AI agents in enterprises. Meta unveiled Muse Spark 1.1 on Thursday, pairing frontier-model performance with aggressive pricing in a…
If you need more power than shared hosting services can provide, the top VPS hosting providers can give you the dedicated resources and scalability needed to push your project to the next level.

Mission Cloud, a CDW company, is seeing enterprise AI conversations shift from experimental proof-of-concept work to production-ready deployments tied to business outcomes, according to President Ted Stuart. Stuart said Mission Cloud, now operating as CDW’s dedicated AWS practice for private-sector customers, has completed more than 400 AI projects and is increasingly working with customers who…

You’d think keeping tabs on your contacts would be about the simplest and most straightforward task imaginable in our modern connected world — wouldn’t you? I sure would. But as I’ve learned over the years, that perfectly understandable instinct couldn’t be more inaccurate. Effectively wrangling your contacts on Android and keeping ’em manageable, organized, and…

A former ransomware negotiator was sentenced to nearly six years for secretly helping BlackCat extort victims while betraying his clients. A U.S. court sentenced former ransomware negotiator Angelo Martino, 41, to 70 months in prison for conspiring with the BlackCat ransomware gang. While negotiating on behalf of five victims, he secretly shared confidential information about…

OpenAI is sharpening its enterprise AI strategy with the launch of ChatGPT Work, a new agentic platform designed to automate workplace tasks, alongside the broader rollout of its GPT-5.6 models, which the company says deliver stronger performance at lower operating costs. According to the company, ChatGPT Work can operate across applications and files, execute long-running…
Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional message that does something a little out of the…
I tested several top smart rings including the new Oura Ring 5. These are the ones I recommend.
Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and take everything it controls. Coinspect has…
Security leaders have made strong progress in visibility. Most organizations can now identify vulnerabilities across their applications, dependencies and development pipelines with far more consistency than in the past. Yet a fundamental imbalance remains: Vulnerabilities are being discovered faster than they can be remediated. That imbalance is growing. Today, 82% of organizations carry security debt,…

Microsoft is warning defenders about a new backdoor that blurs the line between espionage malware and wipers. In a technical analysis published on Thursday, Microsoft Threat Intelligence detailed GigaWiper, a Golang-based implant first observed in October 2025 intrusions that combines remote administration capabilities with multiple disk-wiping and ransomware routines. Rather than building a new destructive…
Accuracy is the name of the health tracker game, so I put Google’s latest device to the test.
Cyber insurance is becoming a core risk management tool for MSPs in 2026 as ransomware, data breaches, AI-enabled attacks, and client liability risks grow more complex. For managed service providers overseeing multiple customer environments, the right policy can help cover incident response, business interruption, legal costs, and certain third-party claims following a cyber event. This…

Microsoft uncovered GigaWiper, a modular Go backdoor combining three malware families with espionage, remote control, and destructive wiping features. In October 2025, Microsoft’s threat intelligence team identified destructive wiping activity inside compromised environments and traced it to a previously unknown piece of malware they’re now calling GigaWiper. The malicious code is written in Go, it…

A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additional victims in 2023. In a sentencing memorandum, federal prosecutors described…
The largest problem regarding ransomware in South Africa is that a majority of organisations have taken little or no steps to be proactive against these attacks. The post Ransomware in South Africa: Response & Protection Guide 2026 appeared first on Da Vinci Cybersecurity: Leading Cyber Security Services in South Africa..
I was off by a month in my forecast of record-setting CVE releases from Microsoft. In June, we saw the deluge of over 200 reported CVEs that I expected in May. There were 116 CVEs for Windows 11 and 104 for Windows 10. In addition, we saw large numbers in both common applications like Office…

Workato has announced two new capabilities for Agent Studio: Headless API and Agent Guardrails. Headless API lets Genies, Workato’s AI agents built on Agent Studio, be embedded into any business application surface, on web, mobile, or inside another agent’s own environment. Agent Guardrails are configurable to the business and ensure that wherever a Genie is…

Every serious software product runs on code that someone else wrote and released for free. A web service leans on a cryptography library, a data pipeline pulls in a parser, and a mobile app ships a handful of small utilities that one person maintains in spare time. All of it carries the same label. A…

Check Point Software CTO Jonathan Zanger met with CSO Spain during the software company’s Engage 2026 user conference last week in Paris. At the event, Check Point executives and representatives discussed how the company is dealing with various types of threats, how it is adopting AI securely, and how Check Point and others can leverage AI…
Data brokers collect personal details on most adults in the United States and sell them to buyers that include employers, landlords, insurance companies, and government agencies. California gives residents a way to push back. You can ask a broker to delete your records, or to stop selling and sharing them. A team at UC Irvine…

Microsoft is recommending that organizations shorten Windows update deployment timelines, warning that advances in AI are reducing the time attackers need to identify and exploit vulnerabilities after security updates are released. The company says organizations should reassess how quickly they roll out monthly security updates, particularly on devices where shorter deployment windows can be implemented…

In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software supply chain risk. Instead of filing an SBOM away as a compliance document, she argues teams should use it every day for vulnerability triage, vendor access reviews, identity monitoring, and incident response. Drawing on Group-IB’s High-Tech…
AI Appreciation Day is observed every year on July 16 to recognise the innovation, potential, and ever-expanding role of artificial intelligence around the world. In 2026, it…

Accounts receivable teams at large companies spend hours each day matching incoming bank payments to invoices by hand. When those payments sit unmatched for days, cash flow suffers and days sales outstanding climbs. The same pattern repeats across blocked invoices, purchase order approval holds, month-end close, and intercompany reconciliations in almost every industry. Built-in ERP…

Passwords remain part of many workforce authentication flows in financial organizations, making phishing and credential theft major identity security risks, according to a new Secret Double Octopus report. Key challenges preventing universal implementation of phishing-resistant MFA (Source: Secret Double Octopus) Workforce authentication trends Banks and financial organizations use a mix of authentication methods, combining phishing-resistant…
In this post, I will talk about free VPN safety and show you what users should check before trusting a VPN app. Free VPN apps are easy to find, quick to install, and appealing to anyone who wants more privacy without adding another monthly subscription. For people using public Wi-Fi, traveling often, working remotely, or…
Here’s a look at the most interesting products from the past week, featuring releases from Attestiv, Automox, Codenotary, and First Recon AI. Codenotary launches AI security platform that learns from AI agent behavior Codenotary has announced AgentMon 3, the latest generation of its enterprise AI security platform, introducing adaptive runtime security policies. These continuously evolve…
Rackspace Technology®, a global enterprise AI infrastructure and solutions provider, and Palantir Technologies Inc. recently announced an operating model framework to help…
D-Link’s Australia and New Zealand arm has rolled out a pair of new portable hotspots, and both are aimed at the growing crowd of us who expect a fast, private internet…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
The TP-Link Tapo C465 is a wireless security camera with a built-in solar panel for power, and it doesn’t require a subscription.
I put Ubuntu on an old Dell laptop to see if Linux could really replace Windows 11. See why my final destination was so worth the speed bumps.

A former ransomware negotiator for DigitalMint was sentenced to 70 months in jail for deceiving his employer’s clients and conspiring with ransomware affiliates to extort a combined $75.3 million from five U.S. companies he was entrusted to aid during their moments of extreme crisis, the Justice Department said Thursday. Angelo John Martino III shared confidential…

AWS MCP Server using the same credentials and sign-in methods that you already use for connecting to the AWS Management Console or AWS Command Line Interface (AWS CLI) through a familiar browser-based experience powered by industry-standard OAuth. This new sign-in path supports AWS Identity and Access Management (IAM) federation, AWS IAM Identity Center, and root…
BeyondTrust launches Pathfinder NHI Governance, extending privileged access control to the non-human and AI identities that run modern environments New Pathfinder module…
2026 Phishing by Industry Benchmarking Report reveals a 17.1% spike in phishing attacks while ongoing training slashes risk to 5.3%
The Cynet Global AI Security Readiness Report, surveying 1,600 individuals across nine countries, reveals that MSPs demonstrate higher adoption rates of AI security tools and express greater confidence in threat detection and response compared to internal security departments.
The AI-generated tool, titled “100% Working AD Information Gathering Script – FULLY FIXED,” exhibited several hallmarks of LLM assistance, including a placeholder server name, over-engineering with multiple fallback methods, and a “pretty” console output using excessive colors, Huntress said.
Former Fortinet, Cisco, and Bitdefender leader brings proven track record in scaling cybersecurity platforms, strengthening partner-driven growth, and shaping category-defining…
GigaWiper, written in Go, operates on Windows and presents operators with numbered commands, three of which are designed for system destruction.
Ravi Subramanian named Chief Financial Officer and Jamie Coleman joins as Chief Customer Officer as BlueVoyant accelerates its next phase of growth
The Bitdefender Sovereignty Acceleration Program enables European organizations to transition to a cybersecurity ecosystem where customer data, security events, and telemetry are processed and stored exclusively within the EU.
QIZ Security has developed a platform designed to help organizations govern encryption across on-premises, cloud, and hybrid environments.
The new system offers a single API integration across AT&T, T-Mobile US, and Verizon networks, aiming to eliminate the waiting times associated with SMS OTPs, which can be exacerbated when users are on Wi-Fi.
Google Chrome continues to dominate as the browser of choice for most people. Even Mac users prefer to install it, and there are many reasons for it, from a huge selection of…
The European Parliament voted to send a bill that would give tech companies the legal right to scan for child sexual abuse material to EU member countries for approval.

A security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz. “We discovered GhostApproval, a systematic vulnerability pattern affecting six of the top AI coding assistants: Amazon Q Developer, Anthropic Claude…
The Risk Score Engine generates three key outputs: Identity Risk Scores to rank the riskiest identities, Session Scores to flag immediate investigation needs, and Organization Risk Scores to provide a single, benchmarkable tenant-level metric.
The SFC has mandated that all virtual asset trading platforms and internet brokers must replace one-time password (OTP) logins, including those sent via SMS and email, with phishing-resistant authentication methods within 12 months.
An analysis by Dr. Martin Shelton of the Freedom of the Press Foundation suggests several ways the Signal username could have been compromised.
The cyberattack, claimed by the threat group CMD Organization, involved the theft of data from the university’s “H drive,” which contained information for current and former students and employees.