Another Thursday, another pile of weird security stuff that somehow happened in just seven days. Some of it is clever. Some of it is lazy. A few bits fall into that uncomfortable category of “yeah… this is probably going to show up in real incidents sooner than we’d like.” The pattern this week feels familiar…
AI, Global Security News, privacy
WhatsApp is giving parents peace of mind over their kids’ privacy
WhatsApp has introduced parent-managed accounts designed for pre-teens, giving parents and guardians new controls over contacts, group participation, and how the app is used. These accounts are limited to messaging and calling and do not include access to features such as Meta AI, location sharing, or disappearing messages in individual chats. Parents must have the…
Compliance, Global Security News, Risk Management
Socure Launch enables startups to deploy identity verification and fraud controls
Socure has announced Socure Launch, providing every organization with immediate access to industry tested, pre-built identity and fraud solutions. This marks a new era for Socure, providing startups an enterprise level of identity verification, fraud detection, and compliance decisioning. With Socure Launch, developers can instantly build on Socure’s RiskOS platform and move from account creation…
AI, Global Security News
Google Tracks Flash Floods With a New AI Tool
The new flood tracker is the latest big tech investment in artificial-intelligence weather monitoring, aimed at predicting volatile rainfall.
AI, Compliance, Endpoint, Global Security News, Risk Management
SurePath AI Announces New MCP Policy Controls
Security and governance platform SurePath AI recently announced MCP Policy Controls to provide real-time controls over which MCP servers and tools are allowed to be used. MCP presents a new attack surface and security challenges These new controls are designed to assist organizations in adopting MCP, ensuring safety, visibility, and safeguards from day one. MCP…
Global Security News
Microsoft’s New AI Health Tool Can Read Your Medical Records and Give Advice
A new feature within the Copilot app will offer personalized healthcare advice and make it easy to upload test results, fitness data and more.
Cloud Security, Compliance, Global Security News
Zscaler enhances data sovereignty controls with regional processing and logging
Zscaler has expanded its data sovereignty capabilities globally, powered by the Zscaler Zero Trust Exchange cloud security platform. For global enterprises, the conflict between protecting data and enabling cross-border collaboration is a major compliance and business challenge to growth. Zscaler already operates 160+ data centers and is present in most countries. Its architecture is based…
Exploits, Global Security News, Network Security
CISA Issues Emergency Directive Over Exploited Cisco SD-WAN Flaws
CISA issued urgent directive as attackers exploit Cisco SD-WAN flaw granting admin access to networks
APAC, Global Security News
SOC Prime’s DetectFlow Enterprise moves threat detection to the data ingestion layer
SOC Prime has announced the release of DetectFlow Enterprise, a solution that brings real-time threat detection to the ingestion layer, turning data pipelines into detection pipelines. Running tens of thousands of Sigma detections on live Kafka streams with millisecond MTTD using Apache Flink, DetectFlow Enterprise enables security teams to detect, tag, enrich, and correlate threat…
AI, Global Security News
Binary Defense’s NightBeacon brings AI-driven analysis to SOCs
Binary Defense has announced the launch of NightBeacon, an AI-powered security operations platform built directly into the company’s security operations center (SOC). NightBeacon serves as the intelligence infrastructure behind Binary Defense’s MDR service, supporting every analyst shift, detection, and investigation across the SOC. Customers benefit from an approximately 30% reduction in mean time to resolution,…
AI, Apps, Cybersecurity, Data Breaches, Endpoint, Global Security News, Government & Policy, malware, Network Security
Iran-Linked Hacktivists Claim Wiper Attack on Stryker Systems
A cyberattack has disrupted global operations at medical technology manufacturer Stryker, forcing employees in multiple countries offline and cutting access to core corporate systems. The incident, which began March 11, triggered widespread outages across the company’s Microsoft environment and left staff temporarily unable to access internal applications and devices. “When a company the size of…
Global Security News, Government & Policy
Your Signal account is safe – unless you fall for this trick
Signal, the encrypted messaging app trusted by security-savvy users around the world, has confirmed that hackers have managed to takeover accounts – with government officials and journalists among those being targeted. Read more in my article on the Hot for Security blog.
AI, Apps, Endpoint, Exploits, Global Security News, Risk Management
The CISO’s Dilemma: How To Scale AI Securely
Your board wants AI. Your developers are building with it. Your budget committee is asking for an ROI timeline. But as CISO, you’re the one who has to answer when the inevitable question comes up: “How do we know this is secure?” If you’re like most security leaders, you’re caught between two impossible positions. Say…
Global Security News
Cisco Catalyst SD-WAN with Integrated NGFW Certified by Orange Business to Deliver Complete Branch Security
Orange Business certifies Cisco Catalyst SD-WAN integrated NGFW capabilities, enabling secure, simplified branch protection through a unified SD-WAN architecture for managed services.
Global Security News, Network Security
Maintaining Security and Protecting Smart Home Devices from Hackers
Learn how to protect smart home devices from hackers. Strong passwords, updates and secure networks help keep cameras, sensors and data safe.
Global Security News
Kinetic IT appoints Dean Langenbach as CEO to accelerate sovereign technology leadership and drive national growth
Kinetic IT today announced Dean Langenbach as its new Chief Executive Officer to shape the company’s next phase of growth and drive technology-driven transformation.
AI, Global Security News, malware, Network Security
PhantomRaven returns to npm with 88 bad packages
Last year’s “PhantomRaven” supply-chain campaign is back, with security researchers uncovering 88 new malicious packages in what they describe as the second, third, and fourth waves of the operation. According to Endor Labs findings, the newly discovered packages were published between November 2025 and February 2026, with 81 of them still available on npm along…
Global Security News
US charges another ransomware negotiator linked to BlackCat attacks
The U.S. Department of Justice charged another former DigitalMint employee for his involvement in an insider scheme in which ransomware negotiators secretly partnered with the BlackCat (ALPHV) ransomware operation. […]
AI, Cybersecurity, Data Breaches, Global Security News
Attackers Don’t Just Send Phishing Emails. They Weaponize Your SOC’s Workload
The most dangerous phishing campaigns aren’t just designed to fool employees. Many are designed to exhaust the analysts investigating them. When a phishing investigation takes 12 hours instead of five minutes, the outcome can shift from a contained incident to a breach. For years, the cybersecurity industry has focused on the front door of phishing…
AI, Global Security News, Network Security
Atlassian cuts 1,600 jobs to fund AI and enterprise expansion
Atlassian will reduce its global workforce by approximately 10%, eliminating around 1,600 roles, as the collaboration software maker redirects capital toward artificial intelligence development and enterprise sales. Co-CEO and co-founder Mike Cannon-Brookes disclosed the cuts in a blog post. The decision, he said, was made to “self-fund further investment in AI and enterprise sales” while…
Global Security News, malware
New PixRevolution Malware Steals Brazil’s PIX Transfers in Real Time
Researchers have discovered PixRevolution, a new Android banking trojan targeting Brazil’s PIX system. Unlike automated scams, this malware uses live operators to watch your screen and divert funds instantly.
Global Security News
The Hottest Job in Tech Isn’t Very Glamorous
Job postings for ‘forward deployed engineers’ are surging among tech companies. But engineers aren’t exactly clamoring for the role.
AI, Apps, Global Security News
Blue Yonder expands agentic AI and mobile experiences for industry-specific supply chain execution
Blue Yonder today announced an expanded set of AI agents and role-specific mobile applications for its end-to-end planning and execution solutions. These updates to its Cognitive Solutions are built around real customer use cases and feedback to help businesses make smarter, faster, more accurate decisions and boost supply chain resilience.
AI, Global Security News
ControlPlane Launches Enterprise Support For OpenBao To Strengthen Secrets Security
ControlPlane, a specialist AI Security and DevSecOps consultancy, today announced the launch of ControlPlane Enterprise for OpenBao, a new offering designed to help organisations across Asia Pacific and globally to securely adopt and operate the OpenBao secrets management platform.
AI, Global Security News
War spreads into cyberspace after Iran-linked hackers hit medtech giant Stryker
An Iran-linked hacking group has claimed responsibility for a cyberattack on U.S. medical device giant Stryker, marking a potential escalation of cyber activity tied to the ongoing conflict in the Middle East. Stryker confirmed in a Form 8-K filing with the SEC that a cyberattack caused a global disruption to its Microsoft systems. The Wall…
Global Security News
New SmartSuite Integration brings IQSight Video Intelligence Seamlessly into Milstone XProtect
Milestone Systems and IQSIGHT, previously Bosch Video Systems, strengthen their collaboration with the release of SmartSuite, a consolidated plugin suite for Milestone XProtect® video management software. SmartSuite cuts installation time for system integrators by 70% and adds powerful new camera and analytics capabilities.
Global Security News
Police Scotland Fined After Sharing Victim’s Phone Data
The ICO has fined Police Scotland after it shared the entire contents of a victim’s phone with her alleged attacker
AI, Global Security News
Independent Study Finds Organisations Achieved 129% ROI with Azul Prime
GUEST RESEARCH: Total Economic Impact study shows significant cloud cost reductions, infrastructure savings and engineering productivity gains
AI, Global Security News
Baidam appoints Beau Hodge as CEO
COMPANY ANNOUNCEMENT: Baidam, a leading First Nations information technology provider, has announced the appointment of Beau Hodge to the role of CEO. Hodge has held a succession of senior roles within Baidam since joining nearly five years ago.
AI, Global Security News
ECI Releases AI Readiness Report as SMB AI Optimism Outpaces Adoption
GUEST RESEARCH: SMB leaders show strong interest in AI, but gaps in skills and data are slowing impact
AI, Global Security News, Network Security, privacy, Venture
The best Android keyboard apps for on-the-go productivity
Quick: When was the last time you thought about the keyboard app on your phone? If you’re like most people, the answer is probably somewhere between “a ridiculously long time ago” and “never.” And it’s no wonder: Keyboard apps are easy to forget! You install one — or stick with whatever came loaded on your…
AI, Exploits, Global Security News
Apple Issues Security Updates for Older iOS Devices Targeted by Coruna WebKit Exploit
Apple on Wednesday backported fixes for a security flaw in iOS, iPadOS, and macOS Sonoma to older versions after it was found to be used as part of the Coruna exploit kit. The vulnerability, tracked as CVE-2023-43010, relates to an unspecified vulnerability in WebKit that could result in memory corruption when processing maliciously crafted web…
AI, Apps, Compliance, Cybersecurity, Endpoint, Global Security News, malware, Network Security, Risk Management
MicroStealer Analysis: A Fast-Spreading Infostealer with Limited Detection
Security teams depend on early signals to spot and contain new threats. But what happens when a fully capable infostealer spreads while traditional detections stay limited? In recent investigations, ANY.RUN researchers observed MicroStealer in 40+ sandbox sessions in less than a month, despite low public visibility. Early activity points to distribution through compromised or impersonated accounts,…
AI, Global Security News, Network Security, Risk Management
Saviynt Taps NEXTGEN, an Exclusive Networks Company, to Accelerate Digital Identity Security in Australia
COMPANY NEWS: Collaboration strengthens Saviynt’s partner-first strategy as AI-driven identity risk builds across the APJ region Key Highlights: Saviynt will broaden access to AI-ready identity security for organisations navigating growing digital risks NEXTGEN will help scale Saviynt’s partner ecosystem across APJ, enabling faster adoption of identity-centric security in the AI era
Global Security News
Silicon Valley’s New Obsession: Watching Bots Do Their Grunt Work
Techies compare notes on how long their fleet of virtual interns can labor away without making a mistake.
AI, Global Security News, malware
Iran Claim Massive Cyber-Attack on MedTech Firm Stryker
The pro-Iran Handala group claims to have wiped 200,000 systems in destructive wiper malware attack on US firm Stryker
AI, Global Security News, malware, Network Security
North Korean fake IT worker tradecraft exposed
Research from GitLab has exposed the latest tradecraft behind North Korean fake IT worker scams. GitLab banned 131 North Korean-attributed accounts last year, most of which involved JavaScript repositories that acted as resources in the so-called Contagious Interview campaign. In most cases, GitLab projects acted as obfuscated loaders for malware payloads — such as BeaverTail…
AI, Apps, Exploits, Global Security News, Risk Management
ENISA Technical Advisory on Secure Package Managers: Essential DevSecOps Guidance
ENISA’s first Technical Advisory on Secure Package Managers helps developers safely use third-party packages. ENISA has released its first Technical Advisory on Package Managers, focusing on how developers can safely consume third-party packages. The document (March 2026, v1.1) follows public feedback incorporating 15 contributions from stakeholders, experts, and the open-source community. “This document focuses on…
AI, Cybersecurity, Exploits, Global Security News, Network Security, Risk Management
U.S. CISA adds a flaw in n8n to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in n8n to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an n8n flaw, tracked as CVE-2025-68613 (CVSS score of 10.0), to its Known Exploited Vulnerabilities (KEV) catalog. n8n is a workflow automation platform designed for technical teams that combines the…
AI, Global Security News
Codoxo’s Deepfake Detection identifies AI-generated medical records for health plans
Codoxo has announced the launch of Deepfake Detection, an AI-driven fraud detection tool now being deployed by health plans across the U.S. The solution helps identify AI-generated or manipulated medical documentation and diagnostic images submitted in support of claims before payment is made. Healthcare fraud is already a multibillion-dollar problem, and generative AI is turning…
AI, APAC, Global Security News
SOC Prime Launches DetectFlow Enterprise To Enhance Security Data Pipelines with Agentic AI
BOSTON, MA — March 12, 2026 — SOC Prime today announced the release of DetectFlow Enterprise, a solution that brings real-time threat detection to the ingestion layer, turning data pipelines into detection pipelines. Running tens of thousands of Sigma detections on live Kafka streams with millisecond MTTD using Apache Flink, DetectFlow Enterprise enables security teams…
Cybersecurity, Global Security News, malware
Six Android Malware Families Target Pix Payments, Banking Apps, and Crypto Wallets
Cybersecurity researchers have discovered half-a-dozen new Android malware families that come with capabilities to steal data from compromised devices and conduct financial fraud. The Android malware range from traditional banking trojans like PixRevolution, TaxiSpy RAT, BeatBanker, Mirax, and Oblivion RAT to full-fledged remote administration tools such as SURXRAT. PixRevolution, according to
AI, Apps, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, Risk Management
AI use is changing how much companies pay for cyber insurance
In July 2025, McDonald’s had an unexpected problem on the menu, one involving McHire, its AI-powered platform used to recruit and screen job applicants. The system, developed by Paradox.ai, featured a rookie-level security flaw: the backend for restaurant operators accepted “123456” as both username and password, and lacked multi-factor authentication. As a result, the personal…
AI, Cybersecurity, Global Security News, Network Security
Stop fixing OT security with IT thinking
In this Help Net Security interview, Ejona Preçi, Group CISO at Lindal Group, discusses the specific cybersecurity challenges in manufacturing environments. The conversation covers why standard IT security practices break down on shop floors, where PLCs and decade-old firmware were never designed to be networked. She explains how nation-state actors quietly settle into industrial networks,…
AI, Endpoint, Global Security News, malware
“Zombie ZIP”: Neue Angriffstechnik täuscht Virenscanner
Mithilfe sogenannter Zombie-ZIPs lassen sich fast alle Virenscanner austricksen. Pressmaster | shutterstock.com Eine neue Technik mit dem Namen „Zombie ZIP“ ist in der Lage, Payloads in komprimierten Dateien zu verbergen. Sicherheitslösungen wie Antiviren- und EDR-Produkte (Endpoint Detection and Response) können sie nicht entdecken, denn die digitalen Untoten wurden speziell geschaffen, um die Security zu umgehen.…
AI, Global Security News
Agentic attack chains advance as infostealers flood criminal markets
Cybercriminals spent much of 2025 automating their operations, shifting from one-off attacks to systems that can run entire intrusion cycles with minimal human input. Data collected from criminal forums, illicit marketplaces, and underground chat services shows a threat environment where stolen identity data, unpatched vulnerabilities, and ransomware operations are interdependent. The findings come from Flashpoint’s…
AI, Cybersecurity, Global Security News, Risk Management
Does Anthropic deserve the trust of the cybersecurity community?
The cybersecurity industry runs on trust. The belief that when a vendor says they will behave a certain way, they will, that critical CVEs are in fact critical, or when companies say they’re GDPR compliant, they really are. But earning trust is not a one-and-done thing. Anthropic understood this better than any AI company. As…
Cybersecurity, Exploits, Global Security News
CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting n8n to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, tracked as CVE-2025-68613 (CVSS score: 9.9), concerns a case of expression injection that leads to remote code execution. The security shortcoming was patched
GeekGuyBlog
Middle East Conflict Highlights Cloud Resilience Gaps
GeekGuyBlog
Chinese Nexus Actors Shift Focus to Qatar Amid Iranian Conflict
Global Security News, Network Security
Wireless vulnerabilities are doubling every few years
Wireless vulnerabilities are being disclosed at a rate that has no precedent in the fifteen-year history of systematic tracking. In 2025, researchers published 937 new wireless-related CVEs, an average of 2.5 per day, according to a threat report from Bastille Networks based on data from the NIST National Vulnerability Database. Wireless threats increasing 20X faster…
AI, Data Breaches, Global Security News, Network Security
Bell Ambulance data breach impacted over 238,000 people
Bell Ambulance confirms a February 2025 breach affecting 238,000 people, exposing personal, financial, and health information. Nearly 238,000 individuals are impacted by a February 2025 Bell Ambulance data breach. Bell Ambulance is a U.S.-based emergency medical services provider offering ambulance transport, paramedic care, and patient support. It serves communities with urgent medical response, interfacility transfers,…
AI, Compliance, Cybersecurity, Global Security News
Wie CISOs schlechte Angebote enttarnen
Drum prüfe… Ground Picture | shutterstock.com Security-Anbietern stehen viele Wege offen, um CISOs und Sicherheitsentscheider mit Lobpreisungen und Angeboten zu ihren jeweils aktuellen Produkten und Lösungen zu penetrieren. Und die nutzen sie auch: Manche Sicherheitsverantwortliche erhalten mehr als 30 solcher Anfragen pro Woche – per Telefon, E-Mail oder auch über LinkedIn. Um erkennen zu können,…
Global Security News
ISC Stormcast For Thursday, March 12th, 2026 https://isc.sans.edu/podcastdetail/9846, (Thu, Mar 12th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
AI, Cybersecurity, Data Breaches, Data Security, Exploits, Global Security News, Network Security, Risk Management
When your IoT Device Logs in as Admin, It?s too Late! [Guest Diary], (Wed, Mar 11th)
[This is a Guest Diary by Adam Thorman, an ISC intern as part of the SANS.edu BACS program] Introduction Have you ever installed a new device on your home or company router? Even when setup instructions are straightforward, end users often skip the step that matters most: changing default credentials. The excitement of deploying a…
GeekGuyBlog
Xygeni GitHub Action Compromised: What You Need to Know
Discover the recent compromise of a popular GitHub Action by Xygeni and learn how it could impact your applications and security practices.
GeekGuyBlog
INC Ransomware Group Disrupts Healthcare in Oceania
The INC ransomware group is wreaking havoc on healthcare systems in Oceania, threatening patient care and demanding ransoms for access restoration.
Cybersecurity, Global Security News
Smashing Security podcast #458: How not to steal $46 million from the US government
A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn’t stirred since 2024 – and within minutes, giant woodpecker images are plastered across the internet’s favourite encyclopaedia. Meanwhile, a crypto contractor hired to help the US Marshals manage seized digital assets allegedly decides to help himself to $46 million of it – and…
Global Security News
High voltage tech: Meet AC/DC – Australia’s answer to FAANG and WITCH
Australia’s tech sector has long punched above its weight, but until now, it’s lacked a unifying shorthand. Silicon Valley has FAANG. The Indian global services giants have WITCH. Australia? Well, we’ve had vibes – but that changes today. Say hello to AC/DC, a new distinctly Australian acronym for our most influential, globally relevant tech powerhouses.…
AI, Compliance, Cybersecurity, Data Breaches, Global Security News, Government & Policy, Network Security, privacy
How not to steal $46 million from the US government
A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn’t stirred since 2024 – and within minutes, giant woodpecker images are plastered across the internet’s favourite encyclopaedia. Meanwhile, a crypto contractor hired to help the US Marshals manage seized digital assets allegedly decides to help himself to $46 million of it – and…
AI, Apps, Endpoint, Exploits, Global Security News, Government & Policy, malware, Risk Management
Resumés with malicious ISO attachments are circulating, says Aryaka
Threat actors are still having success tricking human resources staff into opening malware-infected phishing emails. The latest example is detailed by researchers at Aryaka, who this week described a campaign by an unnamed threat actor who is distributing resumés containing a malicious ISO file to HR departments. It’s delivered through recruitment channels, and hosted on…
AI, Data Breaches, Global Security News, Network Security
Iran-Linked Handala Hackers Claim Major Hacks on Stryker and Verifone
Iran-linked Handala hackers claim cyberattacks on Stryker and Verifone. Stryker confirms network disruption while Verifone says no breach evidence found.
china, Global Security News
MG IM5 & IM6 vs Zeekr 7X: Two high-end Chinese EVs redefining premium and quietly challenging Tesla’s dominance
China’s next wave of electric vehicles has arrived in Australia. Unlike early value-focused entrants, these cars aren’t trying to be cheap alternatives to Tesla; they’re trying to be better with tech-heavy luxury-leaning EVs packed with innovation, aggressive pricing, and design philosophies that diverge sharply from Tesla’s minimalist approach.
AI, Cybersecurity, Endpoint, Exploits, Global Security News, Government & Policy, Network Security
CISA warns of actively exploited Ivanti EPM and Cisco SD-WAN flaws
The US Cybersecurity and Infrastructure Security Agency (CISA) has warned that an authentication bypass vulnerability patched in Ivanti Endpoint Manager (EPM) last month is now being exploited in the wild. The agency has also updated its directive related to two Cisco Catalyst SD-WAN flaws that were also fixed last month after being used in zero-day…
Global Security News, Government & Policy
INC Ransomware Group Holds Healthcare Hostage in Oceania
Government agencies, emergency clinics, and others in Australia, New Zealand, and Tonga have had serious run-ins with the prolific ransomware outfit.
AI, Compliance, Global Security News
Video: Why Most AI Projects Fail According to Spyglass MTG CEO
Artificial intelligence is everywhere, but many AI projects fail before they ever deliver real business value. In this episode of Channel Insider: Partner POV, host Katie Bavoso sits down with Dori Albert, CEO of Spyglass MTG, to discuss why organizations often struggle to implement AI successfully – and what it actually takes to build AI…
AI, Cybersecurity, Global Security News
Browser Extensions Pile Up, and Nobody Remembers Who Added Them
In this post, I will talk about browser extensions pile up, and nobody remembers who added them. Adding a new browser extension used to feel like a small upgrade—a way to streamline one little task or add a useful shortcut to your daily routine. Now, most people have a crowded collection of extensions that’s grown…
Global Security News
Xygeni GitHub Action Compromised Via Tag Poison
Attackers operated an active C2 implant for up to a week and compromised AppSec vendor Xygeni’s xygeni/xygeni-action in that time.
AI, APAC, Cybersecurity, Funding, Global Security News, Venture
News alert: Qevlar AI raises $30M to turn security alerts into actionable defense insights across SOCs
PARIS, March 10, 2026 — Qevlar AI, a leader in AI for transforming security operations centres (SOCs), has raised $30 million in funding for its autonomous AI SOC platform. The funding will support development of technology designed to turn alert investigations into security insights that help SOC teams strengthen their overall security posture. The round…
Global Security News
WhatsApp introduces parent-managed accounts for pre-teens
WhatsApp has begun rolling out parent-managed accounts for pre-teens, allowing parents and guardians to decide who can contact them and which groups they can join. […]
AI, Global Security News, Government & Policy, malware, Network Security
Pro-Palestinian hacktivist group Handala targets Stryker in global disruption
Pro-Palestinian hacktivist group Handala claims a cyberattack on Stryker, alleging it wiped 200,000 systems and disrupted global operations. Pro-Palestinian hacktivist group Handala claims responsibility for a disruptive cyberattack against medical technology firm Stryker. “Medical technology giant Stryker is experiencing a global outage across its systems after a cyberattack early Wednesday. Staff and contractors report that…
Exploits, Global Security News
SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites
An SQL injection vulnerability in Ally, a WordPress plugin from Elementor for web accessibility and usability with more than 400,000 installations, could be exploited to steal sensitive data without authentication. […]
AI, Global Security News, Government & Policy, Risk Management
Anthropic announces think tank to examine AI’s effect on economy and society
Fresh from battling the US Department of Defense (DoD) over AI guardrails, Anthropic has returned this week with a new initiative: the company is founding a think tank, the Anthropic Institute, “to confront the most significant challenges that powerful AI will pose to our societies.” Headed by Anthropic co-founder Jack Clark, who will take up…
AI, Apps, Global Security News, Government & Policy, malware
BeatBanker malware targets Android users with banking Trojan and crypto miner
BeatBanker Android malware spreads through fake Starlink apps on websites imitating Google Play Store, hijacking devices, stealing credentials, and mining crypto. A new Android malware called BeatBanker spreads through fake Starlink apps distributed on websites posing as the Google Play Store. Once installed, it hijacks devices, steals login credentials, tampers with cryptocurrency transactions, and secretly…
AI, Apps, Data Breaches, Exploits, Global Security News, Network Security, Risk Management
Microsoft SQL Server Vulnerability Enables Privilege Escalation
A vulnerability in SQL Server could allow attackers to escalate their privileges to system administrator level within affected database environments. “Improper access control in SQL Server allows an authorized attacker to elevate privileges over a network,” said Microsoft in their security advisory. Understanding CVE-2026-21262 The vulnerability, tracked as CVE-2026-21262, carries a CVSS score of 8.8…
AI, Cybersecurity, Exploits, Global Security News, Government & Policy
CISA orders feds to patch n8n RCE flaw exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability. […]
Global Security News
Everpure extends ActiveCluster support for file
COMPANY NEWS: Providing enterprises with the freedom to move and protect file data advances Enterprise Data Cloud Vision.
AI, Global Security News
Scaling the AI-Native Enterprise
Why Infrastructure Security is the Ultimate B2B Growth Catalyst
AI, Data Breaches, Global Security News
ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites
Salesforce customers have, once again, been targeted by the ShinyHunters group – or, at least, it’s what the group claims. Attackers modified and abused benign tool On Saturday, Saleforce confirmed that its security team has identified an attack campaign by unnamed malicious actors looking to access customers’ data. The attackers are not leveraging a vulnerability…
AI, Apps, Data Breaches, Exploits, Global Security News, Network Security, Risk Management
Microsoft .NET Vulnerability Enables Remote DoS Attacks
Microsoft has released a security update to address a vulnerability in the .NET platform that could allow attackers to remotely crash affected applications. The flaw enables unauthenticated attackers to trigger a Denial-of-Service (DoS) condition, potentially causing applications or services running on vulnerable .NET environments to become unavailable. Exploitation of the vulnerability “… allows an unauthorized…
AI, Global Security News, malware
Medtech giant Stryker offline after Iran-linked wiper malware attack
Leading medical technology company Stryker has been hit by a wiper malware attack claimed by Handala, an Iranian-linked and pro-Palestinian hacktivist group. […]
AI, APAC, Global Security News
It looks like Macs are becoming the value option
If I happened to be one of Apple’s newly-introduced M5 MacBook Pro systems, I would feel a bit as if the equally new MacBook Neo had just strutted into the party like the star of the song. Yes, the incredibly disruptive Neo is a strong option for almost anyone who needs an affordable general purpose computer. But let’s not…
AI, Global Security News
Researchers uncover AI-powered vishing platform
A vishing-as-a-service platform that helps scammers carry out so-called “press 1” scams is misusing text-to-speech (TTS) capabilities provided by AI voice technology company ElevenLabs, Mirage Security researchers claim. How “press 1” vishing scams work For “press 1” scams, fraudsters spoof phone numbers of trusted institutions (e.g., bank), call up potential victims and try to scare…
AI, Global Security News
New PhantomRaven NPM attack wave steals dev data via 88 packages
New attack waves from the ‘PhantomRaven’ supply-chain campaign are hitting the npm registry, with dozens of malicious packages that exfiltrate sensitive data from JavaScript developers. […]
Global Security News, Network Security
Cisco LiveProtect: Bringing eBPF-Powered Protection into Network Infrastructure
Discover how MaxLiveProtect uses eBPF-powered technology to deliver real-time, in-kernel security for modern network infrastructure devices.
Global Security News
BeatBanker Android Trojan Uses Silent Audio Loop to Steal Crypto
BeatBanker Android Trojan spreads via fake Google Play Store pages, using a silent audio loop to stay active while stealing crypto, banking data, and login credentials.
AI, Apps, Global Security News
Google embeds Gemini AI deeper into Workspace apps
Google on Wednesday introduced several new ways for Gemini AI assistant to create and edit content in Workspace apps such as Docs, Slides and Sheets. The changes, said Julie Geller, principal research director at Info-Tech Research Group, represent “incremental improvements more than revolutionary features, but they address real workflow gaps. The actual value is that…
AI, Global Security News
France: National Cybersecurity Agency Reports Ransomware Attack Drop in 2025
French small and medium businesses remained the organizations most targeted by ransomware in 2025
AI, Global Security News
Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes
Agentic web browsers that leverage artificial intelligence (AI) capabilities to autonomously execute actions across multiple websites on behalf of a user could be trained and tricked into falling prey to phishing and scam traps. The attack, at its core, takes advantage of AI browsers’ tendency to reason their actions and use it against the model…
Global Security News
What Entertainment Might Look Like in 20 Years
Among them: Hollywood-quality movies you can make at home for very little money.
Global Security News
FortiGate Edge Intrusions: Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
Throughout early 2026, SentinelOne’s Digital Forensics & Incident Response (DFIR) team has responded to several incidents where FortiGate Next-Generation Firewall (NGFW) appliances have been compromised to establish a foothold into the targeted environment. Each incident was detected and stopped during the lateral movement phase of the attack.
AI, Compliance, Cybersecurity, Global Security News, Network Security, Politics
Iran-Backed Hackers Claim Wiper Attack on Medtech Firm Stryker
A hacktivist group with links to Iran’s intelligence agencies is claiming responsibility for a data-wiping attack against Stryker, a global medical technology company based in Michigan. News reports out of Ireland, Stryker’s largest hub outside of the United States, said the company sent home more than 5,000 workers there today. Meanwhile, a voicemail message at…
AI, Cloud Security, Europe, Global Security News
Infosecurity Europe Announces 2026 Keynote Line Up
Infosecurity Europe 2026 reveals its keynote line-up, featuring Jason Fox, Shlomo Kramer, Cynthia Kaiser and more, with sessions on AI, cloud security and post quantum threats
Global Security News
Researchers Uncover ‘LeakyLooker’ Vulnerabilities in Google Looker Studio
LeakyLooker flaws in Google Looker Studio let attackers run cross-tenant SQL attacks on cloud data
Global Security News
Iran appears to have conducted a significant cyberattack against a U.S. company, a first since the war started
Global Security News
Pro-Iran hackers claim cyberattack on major US medical device maker
AI, Global Security News
AI Still Needs Consultants—For Now
Plus, BlackRock donates $100 million to train trade workers and a billion-dollar AI startup founded by teenagers.
Global Security News
Spotlight On: Amazon, a New Principal Participating Organization
Welcome Amazon, a new Principal Participating Organization (PPO) at the PCI Security Standards Council! In this special spotlight edition of our PCI Perspectives Blog, Amazon Principal Industry Specialist, Balaji Palanisamy, introduces us to his company and how they are helping to shape the future of payment security.
AI, Cybersecurity, Global Security News
Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials
Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. The vulnerabilities are listed below – CVE-2026-27577 (CVSS score: 9.4) – Expression sandbox escape leading to remote code execution (RCE) CVE-2026-27493 (CVSS score: 9.5) – Unauthenticated
AI, Compliance, Data Security, Global Security News
Fortanix helps enterprises build resilience with multi-sourced quantum entropy
Fortanix announced a new multi-sourced quantum entropy capability within Fortanix Data Security Manager (DSM), enabling enterprises to diversify encryption key generation at the origin of trust. Through partnerships with Qrypt and Quantum Dice, Fortanix integrates independent, physics-based quantum entropy sources directly into its key management workflows, enabling compliance requirements that require multiple entropy sources and…


