The new system offers a single API integration across AT&T, T-Mobile US, and Verizon networks, aiming to eliminate the waiting times associated with SMS OTPs, which can be exacerbated when users are on Wi-Fi.
Global Security News
Troubleshooting browser performance: Resolving Google Chrome freezes and crashes on macOS
Google Chrome continues to dominate as the browser of choice for most people. Even Mac users prefer to install it, and there are many reasons for it, from a huge selection of…
Global Security News
EU moves closer to reviving CSAM scanning law after parliamentary vote
The European Parliament voted to send a bill that would give tech companies the legal right to scan for child sexual abuse material to EU member countries for approval.
Global Security News
AI coding tool hole illustrates a big problem with human in the loop

A security hole within AI dev tools has allowed attackers to escape sandboxes by misleading the humans in the loop who were supposed to knowingly approve the tool’s actions, according to cybersecurity research firm Wiz. “We discovered GhostApproval, a systematic vulnerability pattern affecting six of the top AI coding assistants: Amazon Q Developer, Anthropic Claude…
Global Security News
Permiso launches risk score engine for unified identity security
The Risk Score Engine generates three key outputs: Identity Risk Scores to rank the riskiest identities, Session Scores to flag immediate investigation needs, and Organization Risk Scores to provide a single, benchmarkable tenant-level metric.
Global Security News
OpenAI Top Executive Fidji Simo to Step Down
Global Security News
Hong Kong SFC mandates stronger login security for crypto platforms
The SFC has mandated that all virtual asset trading platforms and internet brokers must replace one-time password (OTP) logins, including those sent via SMS and email, with phishing-resistant authentication methods within 12 months.
Global Security News
The Intercept warns of compromised Signal tipline username
An analysis by Dr. Martin Shelton of the Freedom of the Press Foundation suggests several ways the Signal username could have been compromised.
Global Security News
Mount Royal University hit by ransomware attack, data stolen and deleted
The cyberattack, claimed by the threat group CMD Organization, involved the theft of data from the university’s “H drive,” which contained information for current and former students and employees.
Global Security News
Nextcloud exposes sensitive data due to hosting misconfiguration
The exposed data included employee emails, client company details, contracts, and scripts.
Global Security News
You paid for the partner. You got the analyst.
Global Security News
New Helix data extortion group uses identity-focused tactics to target SharePoint
Helix initiates contact through vishing, sometimes impersonating managers via caller ID spoofing, to trick targets into device-code phishing schemes for account access, according to a report by ReliaQuest.
Global Security News
HalluSquatting: New AI attack method enables scalable botnets and large-scale infections
HalluSquatting, short for adversarial hallucination squatting, leverages the inability of LLMs to accurately distinguish between legitimate and fabricated resource locations, according to a paper by researchers from Tel Aviv University, Technion and Intuit.
Global Security News
HP DeskJet 2800 series printers vulnerable to sensitive data exposure
Global Security News
AssuranceAmerica confirms data breach affecting 6.9 million driver’s licenses
Global Security News
NCSC outlines national cyber shield plans using frontier AI
Global Security News
Critical Gitea flaw allows authentication bypass via single HTTP header
Global Security News
Keyfactor secures over $1 billion in funding to expand encryption management
Global Security News
Radware enhances AI agent security with compliance reporting and endpoint protection
Global Security News
Accenture confirms security incident after hacker claims source code theft
Global Security News
WireVPN linked to long-running operation using victims’ devices as proxy network
Global Security News
Tenda routers have unpatched backdoor vulnerability, CERT/CC warns
The vulnerability, tracked as CVE-2026-11405, resides in the login function of the router’s web server binary.
Global Security News
OpenMandriva Linux says contributor tried to sabotage the project
Global Security News
New cyber-physical attack manipulates data center power consumption
Global Security News
FCC bans US IT firm Digitalsystem alleged China links
Global Security News
New GoodPersonRAT malware distributed via fake LetsVPN installer
Global Security News
8 victims sue spyware firm Intellexa over Predatorgate scandal
Global Security News
Opinion | A Christian Vision for the Future of AI
The development of the technology is beginning to outpace ethical deliberation.
Global Security News
INTERPOL Operation First Light Nets 5,811 Arrests and Seizes $293 Million

INTERPOL’s Operation First Light 2026 led to 5,811 arrests, blocked $293M in criminal assets, and disrupted global fraud and money laundering networks. INTERPOL coordinated a four-month operation across 97 countries and territories that ended with 5,811 arrests and the interception of USD 293 million in illicit assets. Operation First Light 2026 ran from January 15…
Global Security News
AI Is Annoying & IoT Devices Still Get Hacked – PSW #934
Global Security News
Tudou Guarantee Successors Expand Cybercrime Marketplace

The shutdown of Tudou Guarantee in early 2026 marked the end of one of the largest cybercrime escrow marketplaces in operation. However, according to research from Flare, it did not disrupt the broader cybercrime ecosystem. Instead, multiple successor platforms quickly emerged to compete for Tudou’s vendors, infrastructure, and customer base, highlighting how resilient these illicit…
Global Security News
Microsoft Warns of GigaWiper Backdoor Built to Destroy Windows PCs
Global Security News
Iran’s Cyber Crosshairs Focus Beyond Critical Infrastructure
Global Security News
SAS Debuts New AI Marketing Solution

Data and AI organization, SAS, has recently announced SAS 360 Marketing AI, a solution designed to help marketers build, deploy, and scale machine learning models. SAS 360 Marketing AI utilizes guided workflows and customizable recipe templates for common marketing uses to move from data to decision at speed. SAS 360 Marketing AI targets marketing data…
Global Security News
Microsoft Reins in RoguePlanet Zero-Day Threat
Global Security News
Why Embedded Device Security Requires a Lifecycle Approach

For years, organizations treated operational technology (OT), Internet of Things (IoT), and embedded devices differently from traditional IT assets. Many of these systems were designed to operate for decades with minimal changes, often in environments where patching or replacing hardware is difficult. That long operational lifespan has created a growing cybersecurity challenge as aging software…
Global Security News
Injective SDK on npm infected with cryptocurrency wallet stealer
Global Security News
Two-year online college ‘Campus’ now offers cybersecurity track
Global Security News
WolfSSL, GeoVision, VTK vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM. The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For Snort coverage that can detect the exploitation of these vulnerabilities, download…
Global Security News
I tested ChatGPT’s Live Voice upgrade, and it almost felt human – how to try it
The latest GPT Live Voice models can listen, speak, and conduct online research all at the same time. Does it feel like you’re talking with a real person? Almost.
Global Security News
America Is Blowing the AI Race. Here Are Seven Ideas To Get Back on Track.
Global Security News
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs

Datadog Security Labs is warning of “several overlapping campaigns” that are systematically enumerating corporate GitHub organizations, repositories, and user accounts through the GitHub API. “Operators rely on automated scraping tooling with custom or legitimate-sounding user agents, leveraging GitHub ‘ghost’ accounts that are often years old, or compromised OAuth tokens and personal
Global Security News
Best Buy is selling a 70-inch Insignia TV for just $350 – why I recommend it
Upgrade your home theater with a big-screen Insignia F50 for less than $400 right now at Best Buy.
Global Security News
GodDamn Ransomware Uses PoisonX to Blind Security Software

GodDamn ransomware uses the signed PoisonX driver to disable security tools, marking a more advanced version of the Beast ransomware family. Symantec’s Threat Hunter Team found a new ransomware family called GodDamn that first appeared in the wild on May 21, 2026, and analyzed an attack that took place in early June. The group behind…
Global Security News
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware

Microsoft has taken apart a destructive Windows backdoor it calls GigaWiper. What stands out is how it is built: not one tool but three older destructive programs bolted into one, offered as commands the operator can choose from. Each is a different way to break a machine: wipe the whole disk, overwrite the Windows drive,…
Global Security News
Winning 54% of the time
Welcome to this week’s Threat Source newsletter. There’s a fairly cliché phrase in cybersecurity that I’m sure our audience is familiar with: Attackers only need to be right once, whereas defenders need to be right 100% of the time. I guess it captures the asymmetry of this industry, but I’ve never been entirely comfortable with…
Global Security News
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries

Authorities arrested more than 5,800 alleged cybercriminals and seized $293 million in a global operation targeting social-engineering scams and money laundering across 97 countries, Interpol said Thursday. The anti-fraud crackdown, dubbed Operation First Light, identified more than 142,000 victims, including people, businesses and governments, officials said. “Social engineering scams continue to pose a significant threat…
Global Security News
AI Gateway Connected to Amazon Bedrock Hijacked for Cryptomining
Global Security News
This iPhone bug won’t let me save cropped screenshots – but I found a fix
My cropped iPhone screenshots kept reverting to the full image, revealing details I tried to hide. And that’s a problem.
Global Security News
Opinion | The Heart Beats the Machine
AI will write faster, but can it write better?
Global Security News
New Helix vishing group emerges in SharePoint data theft attacks
Global Security News
Microsoft goes all in on new AI-powered Windows security strategy – what it means for you
An elite security team at Microsoft has built an AI-powered pipeline to find vulnerabilities in Windows and get them to engineers to build fixes.
Global Security News
Microsoft expects more Windows security updates from AI-discovered flaws
Global Security News
AssuranceAmerica Data Breach Exposes Nearly 7 Million Drivers

AssuranceAmerica has disclosed a data breach affecting nearly 7 million individuals after attackers gained unauthorized access to the company’s IT environment earlier this year. According to a filing with the Maine Office of the Attorney General, the AssuranceAmerica data breach impacted 6,998,886 people. The company, which provides auto, renters, and commercial auto insurance through more…
Global Security News
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk

GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA). The Microsoft-owned subsidiary noted that the following npm install behaviors that used to run automatically before have been made opt-in – allowScripts defaults to off, meaning
Global Security News
Apple finally calls time on 15-year-old device support

For those who wonder what the support window is for Apple products, the company now has an answer: it’s quietly ended support for some of its oldest iPhones and iPads, cutting off restore access for devices that first went on sale more than a decade ago. While the move has prompted some complaints, the truth…
Global Security News
How the ‘token economy’ has become a security and financial minefield
Global Security News
LG is giving away free soundbars with this projector – how to get one
Upgrade your entire home theater at once with this LG CineBeam Q and soundbar bundle.
Global Security News
Rethinking Email Security in the AI Era How Modern Phishing Bypasses Traditional SEGs – WC #1
Global Security News
UST Partners With Anthropic, Bringing Claude to Its Platform

AI and technology transformation solutions organization UST has announced it has signed on as Anthropic’s second Global Premier Partner in the Claude Partner Network. The agreement will not only strengthen UST’s position within the Claude Partner Network Services Tier but also expand its ability to help organizations move from experimentation to trusted, large-scale deployment. UST…
Global Security News
Durabook to Vanguard Channel Partner Program

Durabook, a mobile solutions brand owned by Twinhead International Corporation, is debuting a new deal registration program to protect channel partners’ investments in developing new business opportunities. Growing channel partnerships with an enhanced program The Vanguard Partner Program was developed to serve channel partners, “that are the foundation of its sales strategy.” The program complements…
Global Security News
The best digital notebooks of 2026: Expert tested and reviewed
I went hands-on with the best smart notebooks to see which ones actually make it easier to capture ideas without paper clutter.
Global Security News
How World Cup crypto prediction sites take your money

Crypto prediction and betting sites are appearing around the World Cup, and researchers have already tracked scams aimed at fans, including fake ticketing, fixed-match betting, prediction scams, and fan-branded meme coins. We investigated one prediction site ourselves. While we aren’t claiming every site works the same way, it matched several well-known scam patterns. Whether it’s…
Global Security News
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it…
Global Security News
Your Tenda router could have a hidden firmware backdoor – disable this setting ASAP
Until Tenda patches the backdoor to its popular routers, you have one defense option.
Global Security News
6.9 million driver’s license numbers stolen from AssuranceAmerica

Insurance provider AssuranceAmerica has confirmed a data breach affecting the personal information and driver’s license numbers of up to 6.9 million people. AssuranceAmerica provides car and rental insurance to customers across 14 US states through a network of over 9,500 independent agents. TechCrunch reports:“AssuranceAmerica said it discovered hackers in its computer systems on March 17.…
Global Security News
I found an Android launcher so good that I don’t miss Nova anymore
After spending just 5 minutes with Octopi, I made it my default home screen launcher – it’s that perfect! There are free and Pro versions.
Global Security News
The best 15-inch laptops of 2026: Expert tested and reviewed
Looking for a new 15-inch laptop? We’ve tested the best ones this year from Apple, Lenovo, Asus, and Samsung.
Global Security News
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
Global Security News
764 splinter group leader sentenced to 40 years in jail

A San Antonio man who sexually exploited children while leading 8884, an offshoot of the notorious violent extremist collective 764, was sentenced to 40 years in prison in federal court Wednesday, the Justice Department said. Alexis Aldair Chavez began associating with 764 as a child in 2022 when a co-conspirator introduced him to 7997, one…
Global Security News
As Global Conflicts Go Digital, Businesses Need Wartime Gameplans
Global Security News
Extortion crew hijacks Microsoft 365 accounts via fake passkey setup

The Pink cyber extortion crew is tricking employees into giving them access to their Microsoft 365 accounts by faking Entra passkey enrollment requests. The attack The attack starts with a vishing call to an employee. The caller poses as IT and says it’s time to set up a passkey. Everything after that is theater, built…
Global Security News
This TP-Link solar camera is so easy to install – and beats my Ring in image quality
The TP-Link Tapo C465 is a wireless security camera with a built-in solar panel for power, and it doesn’t require a subscription.
Global Security News
Bitdefender Debuts Program to Advance EU Data Sovereignty Initiatives

Bitdefender, a cybersecurity-focused organization, has launched a new program to enable European Union (EU) sovereignty and regulatory compliance. European data hosting and security solution includes contract buyout The new program empowers European organizations to transition to a fully European cybersecurity and data hosting solution, ensuring that customer and configuration data, security events, telemetry, and information…
Global Security News
I’ve used Linux for 30 years – here’s how I’d rank DistroWatch’s top 10
DistroWatch says these are the top Linux distros. I say this order is better.
Global Security News
The Hidden Security Risks of Reduced Summer IT Coverage
Global Security News
Vibe-Coded Malware Caught in Active Directory Attack
Global Security News
Why we cannot wait for better post-quantum signature algorithms

RSA and ECC, cryptographic algorithms that we’ve all relied on for decades, are vulnerable to the attack of sufficiently advanced quantum computers. Such quantum computers do not exist yet, but they seem to be coming sooner than expected. Luckily, the solution is already available: migrate to ML-KEM encryption and ML-DSA signatures, which are designed to…
Global Security News
Citrix launches MCP Gateway to secure enterprise AI agents

Citrix has announced updates to its high-performance application delivery and security platform NetScaler, introducing MCP Gateway functionality to allow enterprises to securely route, govern and observe agent traffic to backend Model Context Protocol (MCP) servers. In addition, the company unveiled other enhancements to NetScaler AI Gateway, that extend model routing and token-level usage tracking for…
Global Security News
Vectogate debuts platform to secure and govern autonomous AI agents

Vectogate has launched an AI governance platform designed to give organizations centralized control over AI agents as they increasingly take on autonomous tasks with access to sensitive data and internal business systems. The company aims to address one of the key governance challenges posed by enterprise AI. The platform is initially available in private beta,…
Global Security News
Invited to a “job interview” with Netflix or OpenAI? Beware! Your Google password could be at risk
Have you received an email from a recruiter at Adobe, Netflix, or OpenAI offering you an exciting new marketing role? Well, before you start brushing up your interview technique, take a closer look at who is really behind it. Read more in my article on the Hot for Security blog.
Global Security News
AI Gateways Offer Attackers the Keys to the Kingdom
Global Security News
Cynet Report Shows MSPs Lead in AI Security Readiness

A new report from cybersecurity vendor Cynet finds managed service providers are pulling ahead of in-house security teams in AI adoption and confidence, even as both groups identify AI-powered phishing and social engineering as their top cybersecurity threats. The findings suggest organizations are increasingly turning to MSPs for AI-driven security capabilities as cyberattacks become more…
Global Security News
Attack on Amazon Bedrock-linked AI gateway highlights new cloud security risk

A cloud intrusion that ended with the deployment of cryptomining malware has exposed a bigger risk for enterprises: AI gateways that concentrate access to cloud identities, permissions, and foundation models in a single, highly privileged system. Researchers from cybersecurity firm Darktrace found attackers compromising an AWS EC2 instance acting as a LiteLLM proxy for Amazon…
Global Security News
AssuranceAmerica Breach Exposes 7 Million Driver’s Licenses After Employee Account Hack

AssuranceAmerica confirmed a breach exposing nearly 7 million driver’s licenses after hackers compromised an employee account and stole customer data. U.S. auto insurer AssuranceAmerica has confirmed a data breach affecting nearly 7 million people, making it the largest known theft of Americans’ driver’s license information in 2026. “In a data breach notice sent to customers…
Global Security News
UK cyber agency unveils AI-powered Cyber Shield to counter attacks at machine speed

The UK’s National Cyber Security Centre (NCSC) wants to deploy autonomous AI agents capable of finding and neutralizing cyberattacks on national networks in real time, marking Britain’s push toward a sovereign, machine-speed cyber defense system. The blueprint, called Cyber Shield, was developed jointly with the Department for Science, Innovation and Technology (DSIT). “The objective of…
Global Security News
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

AI has changed how fast attacks move. Work that once took an attacker days now takes minutes. Using models like Mythos, attackers write tailored bait, pick targets, test what lands, and jump to the next host before your team clears the first alert. That is the gap, and it is not your fault. The tools…
Global Security News
Microsoft releases fix for RoguePlanet Defender flaw (CVE-2026-50656)
Microsoft has finally released a security update for its Microsoft Malware Protection Engine, which fixes CVE-2026-50656, the Windows Defender local privilege escalation vulnerability triggered by the RoguePlanet exploit. The vulnerability and the fix CVE-2026-50656 is due to improper link resolution before file access, affects Windows 10 and Windows 11, and may allow authenticated attackers to…
Global Security News
75% CISOs Fear Executives Don’t Understand Cybersecurity Risks Employees Face
Global Security News
Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests
Global Security News
Microsoft fixes RoguePlanet zero-day in Defender

Microsoft issued a security update that fixes the zero-day vulnerability known as RoguePlanet in Microsoft Defender. RoguePlanet is tracked as CVE-2026-50656, a Microsoft Defender elevation of privilege (EoP) vulnerability. As we reported last month, if successfully exploited, RoguePlanet can allow an attacker to elevate privileges from a standard user account to NT AUTHORITYSYSTEM, the highest privilege level…
Global Security News
GhostApproval Flaws Let Top AI Coding Tools Write Outside Workspaces
Global Security News
I tested Norton Antivirus for six weeks – and its biggest strength wasn’t what I expected
After decades in the cybersecurity space, Norton remains one of the most capable antivirus suites thanks to its powerful security tools.
Global Security News
US Threat Landscape Alert: 30 Active Malware Families Ranked by Real Sandbox Data
State of Cybersecurity in the US American organizations are processing more malware submissions than ever, and the mix keeps shifting under their feet. Phishing kits that hijack multi-factor authentication now sit alongside decades-old ransomware, commodity RATs sold for the price of a streaming subscription, and loaders built to slip payloads past EDR undetected. For CISOs…
Global Security News
5,811 arrests, $293 million seized over social engineering scams

Criminals who pose as police officers, romantic partners, and business suppliers have built fraud operations that reach across continents. A four-month enforcement campaign against these schemes wrapped up, and police in 97 countries and territories took part. Thousands of arrests The campaign, called Operation First Light 2026, centered on social engineering scams and the money…
Global Security News
Dealing with Web Security When Using Online Dating Websites

In this post, I will discuss dealing with web security when using online dating websites. The main threat on a dating site is rarely the awkward date. It is the account takeover, the phishing link, and the stranger who asks for money before asking to meet. Online romance fraud cost Americans $823 million in 2024,…
Global Security News
Physical AI will see the fusion of robotics and AI transform the world

Historically, humans have solved their toughest tasks by creating tools capable of withstanding greater strain to undertake the job or augment their abilities. From levers to steam engines and beyond, the structural evolution of machines is almost as remarkable as their ability to improve operational cultures. In recent times, we have seen machines attain their…
Global Security News
Microsoft to retire the OWA Light client in Exchange Server
Global Security News
Summer of Clearinghouses

Everyone seems to have announced a clearinghouse over the past few weeks. We did too. Ours is called Athena, and the main thing that sets it apart is that it was already real and running when we announced it — built quietly months earlier, heads down, taking findings and shipping fixes, because customers kept asking…




































