Developers can spend days using fuzzing tools to find security weaknesses in code. Alternatively, they can simply ask an LLM to do the job for them in seconds. The catch: LLMs are evolving so rapidly that this convenience might come with hidden dangers. The latest example is from researcher Hung Nguyen from AI red teaming…
Tag: using
AI, Apps, Global Security News
FBI warns against using Chinese mobile apps due to privacy risks
The U.S. Federal Bureau of Investigation (FBI) warned Americans against using foreign-developed mobile applications, particularly those created by Chinese developers. […]
Global Security News
Claude AI finds Vim, Emacs RCE bugs that trigger on file open
Vulnerabilities in the Vim and GNU Emacs text editors, discovered using simple prompts with the Claude assistant, allow remote code execution simply by opening a file. […]
AI, Cybersecurity, Data Breaches, Global Security News, Network Security, Risk Management
Insider Threats Rise with North Korean AI Hiring Fraud Schemes
A suspected North Korean operative attempted to infiltrate a cybersecurity firm using a stolen identity and an AI-generated resume, underscoring how hiring pipelines are becoming an attack vector. The failed attempt reveals how threat actors are blending identity theft, automation, and anonymized infrastructure to bypass traditional recruiting safeguards. “In June 2025, we used a combination…
AI, Apps, Cybersecurity, Exploits, Global Security News, Risk Management
LangChain path traversal bug adds to input validation woes in AI pipelines
Security researchers are warning that applications using AI frameworks without proper safeguards can expose sensitive information in basic, yet critical, non-AI ways. According to a recent Cyera analysis, widely used AI orchestration tools, LangChain and LangGraph, are vulnerable to critical input validation flaws that could allow attackers to access sensitive enterprise data. In a recent…
AI, Global Security News, malware, Risk Management
New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
Infinity Stealer targets macOS via fake Cloudflare CAPTCHA, using Nuitka; first such campaign per Malwarebytes. Researchers at Malwarebytes spotted a new macOS infostealer, named Infinity Stealer, using a Python payload compiled with Nuitka. It spreads via ClickFix, tricking users with fake Cloudflare CAPTCHA pages. “A fake verification page instructs the visitor to open Terminal, paste…
AI, Europe, Exploits, Global Security News, Government & Policy, malware, Network Security, Russia
Russia-linked APT TA446 uses DarkSword exploit to target iPhone users in phishing wave
Russia-linked TA446 is using the DarkSword iOS exploit kit in targeted phishing campaigns to compromise iPhone users. Russia-linked APT group TA446 (aka SEABORGIUM, ColdRiver, Callisto, and Star Blizzard) is using the DarkSword exploit kit in targeted spear-phishing campaigns against iOS devices. The attacks rely on malicious emails to compromise iPhones, highlighting a growing threat from…
AI, Global Security News
The People Who Are Using AI at Home to Free Up Their Time
Using AI agents to compare insurance plans and order groceries means more free time for riding bikes and playing the guitar.
AI, Global Security News
BianLian Ransomware Spreads via Fake Invoice SVG Images in New Attacks
Researchers at WatchGuard have identified a new phishing campaign targeting companies in Venezuela. Using malicious SVG image files…
AI, Global Security News, malware
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad actors for malvertising and distributing malware. “TikTok has been historically…
AI, Global Security News
New Ghost Campaign Uses Fake npm Progress Bars to Phish Sudo Passwords
ReversingLabs researchers identify a new Ghost campaign using fake npm install logs and progress bars to phish for sudo passwords and steal crypto wallets from developers.
AI, Global Security News, malware, Risk Management
Suspected Hijacked Developer Accounts Spread npm Malware
Sonatype uncovers a sophisticated malware campaign using hijacked npm developer accounts to steal API keys and passwords. Is your dev environment at risk?
AI, Exploits, Global Security News, malware, Network Security, Risk Management
Researchers uncover WebRTC skimmer bypassing traditional defenses
Researchers found a new skimmer using WebRTC to steal and send payment data, bypassing traditional security controls. Sansec researchers discovered a new payment skimmer that uses WebRTC data channels instead of typical web requests to load malicious code and exfiltrate stolen payment data. “What sets this attack apart is the skimmer itself. Instead of the usual…
AI, Global Security News
Phishers Pose as Palo Alto Networks’ Recruiters for Months in Job Scam
A series of campaigns that began in August aim to defraud job candidates, using psychological tactics and data scraped from LinkedIn profiles.
AI, Apps, Global Security News, malware
Chrome encryption bypass discovered: New malware steals passwords and cookies
A new infostealer is bypassing Chrome’s Application-Bound Encryption (ABE), using a debugger-based technique that researchers say hasn’t been observed in the wild. Called “VoidStealer,” the stealer appears to have found a way around ABE, introduced in Chrome 127 in 2024, a security control that locks sensitive browser data, such as passwords and cookies, behind stronger…
AI, Apps, Global Security News, malware
Chrome ABE bypass discovered: New VoidStealer malware steals passwords and cookies
A new infostealer is bypassing Chrome’s Application-Bound Encryption (ABE), using a debugger-based technique researchers say hasn’t been seen in the wild before. Called “VoidStealer,” the stealer seems to have found a way around ABE, introduced in Chrome 127 in 2024, a security control aimed at locking sensitive browser data like passwords and cookies behind tighter…
AI, Global Security News
GitLab Enables Broader and More Affordable Access to Agentic AI Across the Software Lifecycle
COMPANY NEWS: Organisations on the GitLab.com free tier can now start using GitLab Duo Agent Platform by purchasing a monthly commitment of GitLab Credits, giving every team access to agentic AI across the full software lifecycle. Agentic code reviews now cost a flat $0.25 per review (4 code reviews per GitLab Credit today), making automated…
AI, Cybersecurity, Global Security News
Fake Windsurf IDE Extension Uses Solana Blockchain to Steal Developer Data
Cybersecurity researchers at Bitdefender have discovered a malicious Windsurf IDE extension using the Solana blockchain to steal developer credentials.
AI, Global Security News, Government & Policy
SideWinder Espionage Campaign Expands Across Southeast Asia
The suspected India-linked threat group targets governments, telecom, and critical infrastructure using spear-phishing, old vulnerabilities, and rapidly rotating infrastructure to maintain persistent access.
Global Security News, malware
LeakNet ransomware uses ClickFix and Deno runtime for stealthy attacks
The LeakNet ransomware gang is now using the ClickFix technique for initial access into corporate environments and deploys a malware loader based on the open-source Deno runtime for JavaScript and TypeScript. […]
AI, china, Endpoint, Global Security News, malware, Network Security
CL-STA-1087 targets military capabilities since 2020
China-linked APT group CL-STA-1087 has targeted Southeast Asian militaries since 2020 using AppleChris and MemFun. A suspected China-linked espionage campaign, tracked as CL-STA-1087, has targeted Southeast Asian military organizations since at least 2020, using AppleChris and MemFun malware. “The activity demonstrated strategic operational patience and a focus on highly targeted intelligence collection, rather than bulk…
AI, Apps, Global Security News, Network Security
IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)
Yesterday, in my diary about the scans for “/proxy/” URLs, I noted how attackers are using IPv4-mapped IPv6 addresses to possibly obfuscate their attack. These addresses are defined in RFC 4038. These addresses are one of the many transition mechanisms used to retain some backward compatibility as IPv6 is deployed. Many modern applications use IPv6-only networking…
AI, Global Security News
What Is Inference? Explaining the Massive New Shift in AI Computing
The focus of artificial-intelligence spending has gone from training models to using them. Here’s how to understand the difference—and the implications.
AI, Global Security News
Nvidia-Backed AI Startup to Spend Billions on Korea Data Center to Combat China
The Trump administration is using AI chips and models as a tool for diplomacy and boosting U.S. allies.
AI, Apps, Global Security News, malware, privacy, Risk Management
Advanced Protection Mode in Android 17 prevents apps from misusing Accessibility Services
Android 17 will block non-accessibility apps from using the Accessibility API under Advanced Protection Mode to reduce malware abuse. Android 17 introduces a new security feature in Advanced Protection Mode (AAPM) that blocks apps without accessibility functions from accessing the Accessibility API. The change, first reported by Android Authority and included in Android 17 Beta…
AI, Global Security News, malware
AI-generated Slopoly malware used in Interlock ransomware attack
A new malware strain dubbed Slopoly, likely created using generative AI tools, allowed a threat actor to remain on a compromised server for more than a week and steal data in an Interlock ransomware attack. […]
Global Security News
PixRevolution Malware Hijacks Brazil’s PIX Transfers in Real Time
PixRevolution Android trojan hijacks Brazil’s PIX payments in real time using accessibility abuse
Global Security News
BeatBanker Android Trojan Uses Silent Audio Loop to Steal Crypto
BeatBanker Android Trojan spreads via fake Google Play Store pages, using a silent audio loop to stay active while stealing crypto, banking data, and login credentials.
Apps, Global Security News, malware, Russia
BlackSanta Malware Targets HR Staff with Fake CV Downloads
Aryaka researchers have identified a new threat from a Russian-speaking group using ‘BlackSanta’ malware. By disguising attacks as job applications, hackers are bypassing security to target recruitment workflows.
Global Security News, malware, Russia
Russian Threat Actor Sednit Resurfaces With Sophisticated Toolkit
After several years of using simple implants, the Russia-affiliated actor is back with two new sophisticated malware tools.
china, Global Security News, malware
China-Linked Hackers Hit Qatar with Backdoor Disguised as War News
China-linked hackers targeted Qatar using fake war news lures to spread PlugX backdoor malware and spy on military and energy sectors.
AI, Apps, Data Breaches, Endpoint, Exploits, Global Security News, Risk Management
Threat actors use custom AuraInspector to harvest data from Salesforce systems
Attackers are mass-scanning Salesforce Experience Cloud sites using a modified AuraInspector tool to exploit misconfigurations and access sensitive data. Salesforce CSOC warns that threat actors are mass-scanning publicly accessible Experience Cloud sites using a modified version of the AuraInspector tool. AuraInspector is an open‑source command‑line tool released by Google/Mandiant to audit Salesforce Aura and Experience…
AI, Global Security News, malware, Russia
APT28 Uses BEARDSHELL and COVENANT Malware to Spy on Ukrainian Military
The Russian state-sponsored hacking group tracked as APT28 has been observed using a pair of implants dubbed BEARDSHELL and COVENANT to facilitate long‑term surveillance of Ukrainian military personnel. The two malware families have been put to use since April 2024, ESET said in a new report shared with The Hacker News. APT28, also tracked as…
Exploits, Global Security News, Russia
APT28 hackers deploy customized variant of Covenant open-source tool
The Russian state-sponsored APT28 threat group is using a custom variant of the open-source Covenant post-exploitation framework for long-term espionage operations. […]
Global Security News, Russia
Dutch Intel Warns of Russian Hackers Hijacking Signal, WhatsApp Attacks
Dutch intelligence warns Russian hackers are hijacking Signal and WhatsApp accounts using fake support bots and verification code scams targeting officials and journalists.
Global Security News
Fake CleanMyMac Site Uses ClickFix Trick to Install SHub Stealer on macOS
Researchers warn of a fake CleanMyMac site using a ClickFix attack to install SHub Stealer on macOS and steal passwords and crypto wallets.
AI, Exploits, Global Security News
Threat Actor Exploits Flaws and Uses Elastic Cloud SIEM to Manage Stolen Data
Huntress researchers uncover campaign exploiting vulnerabilities to steal data using Elastic Cloud as a data hub
Global Security News, malware
Termite ransomware breaches linked to ClickFix CastleRAT attacks
Ransomware threat actors tracked as Velvet Tempest are using the ClickFix technique and legitimate Windows utilities to deploy the DonutLoader malware and the CastleRAT backdoor. […]
Global Security News
Microsoft: Hackers abusing AI at every stage of cyberattacks
Microsoft says threat actors are increasingly using artificial intelligence in their operations to accelerate attacks, scale malicious activity, and lower technical barriers across all aspects of a cyberattack. […]
AI, Apps, Global Security News, Risk Management
Microsoft warns North Korean threat groups are scaling up fake worker schemes with generative AI
North Korean threat groups are using artificial intelligence tools to accelerate and expand the country’s long-running scheme to get remote technical workers hired at global companies for longer durations, Microsoft Threat Intelligence said in a report Friday. AI services are empowering North Korean operatives across the attack lifecycle. Attackers have turned AI into a “force…
AI, Global Security News, Government & Policy
Cyberattack on Mexico’s Gov’t Agencies Highlight AI Threat
Using Anthropic’s Claude, OpenAI’s ChatGPT, and a detailed playbook prompt, a handful of cyberattackers reportedly gained access to government agencies and its citizens’ data.
AI, Exploits, Global Security News, malware, Network Security, Risk Management
Microsoft warns of ClickFix campaign exploiting Windows Terminal to deliver Lumma Stealer
Microsoft warns of ClickFix campaign using Windows Terminal to deliver Lumma Stealer via social engineering attacks. Microsoft revealed a new ClickFix campaign where attackers exploit Windows Terminal to run a complex attack chain, ultimately deploying Lumma Stealer malware. The campaign uses social engineering to trick users into executing malicious commands, highlighting growing risks to Windows…
AI, Compliance, Global Security News, Government & Policy
UK lawmakers back licensing‑first approach, adding pressure to global AI copyright standards
AI developers must obtain licenses for copyrighted material before using it to train models, a committee of the House of Lords, the UK Parliament’s upper chamber, said Thursday. The committee called the approach “licensing-first,” meaning no training on protected works without prior permission and payment, regardless of how the material is sourced. The committee has…
AI, Global Security News
March 2026 Patch Tuesday forecast: Is AI security an oxymoron?
Developers and analysts are using more AI tools to produce code and to test both the performance and security of the finished products. They are also embedding AI functionality in their products directly. But just how secure are these AI tools and routines themselves? Recent reports show they suffer from vulnerabilities just like any other…
Global Security News, malware
Nation-State Actor Embraces AI Malware Assembly Line
Pakistan’s APT36 threat group has begun using vibe-coding to churn out mediocre malware, but at a scale that could overwhelm defenses.
AI, Global Security News
Pakistan-Linked APT36 Floods Indian Govt Networks With AI-Made ‘Vibeware’
Bitdefender research reveals Pakistani group APT36 is using AI-generated vibeware and trusted cloud services like Google Sheets to target Indian officials.
AI, Global Security News, Risk Management
AI-Driven Insider Risk Now a “Critical Business Threat,” Report Warns
Malicious insiders are using misusing AI for nefarious gain, while employees cutting corners also creates risk, warns Mimecast
AI, Exploits, Global Security News, Government & Policy, malware
Google uncovers Coruna iOS Exploit Kit targeting iOS 13–17.2.1
Google warns of the Coruna iOS exploit kit, using 23 exploits across five chains to target iPhones running iOS 13–17.2.1, but not the latest iOS. Google’s Threat Intelligence Group has identified a powerful new iOS exploit kit called Coruna (also known as CryptoWaters) that targets Apple iPhones running iOS versions 13.0 through 17.2.1. The kit…
Global Security News
Bitwarden adds support for passkey login on Windows 11
Bitwarden announced support for logging into Windows 11 devices using passkeys stored in the manager’s vault, enabling phishing-resistant authentication. […]
AI, Global Security News, malware, Network Security
Fake Zoom, Teams Meeting Invites Use Compromised Certificates to Drop Malware
A new phishing campaign is using stolen certificates from TrustConnect Software PTY LTD to sign malware. By impersonating updates for Zoom and Microsoft Teams, hackers install RMM tools to gain persistent, privileged access to networks
AI, Global Security News
Hacker mass-mails HungerRush extortion emails to restaurant patrons
Customers of restaurants using the HungerRush point-of-sale (POS) platform say they received emails from a threat actor attempting to extort the company, warning that restaurant and customer data could be exposed if HungerRush fails to respond. […]
Global Security News
Can AI Save Local News?
The Philadelphia Inquirer and other regional outlets are using artificial intelligence to automate elements of reporting and expand coverage.
AI, Global Security News
LastPass warns of spoofed alerts aimed at stealing master passwords
LastPass warns of a phishing campaign using fake security alerts about unauthorized access or password changes to steal users’ master passwords. LastPass has warned users about a new phishing campaign using fake security alerts that claim unauthorized access or master password changes. The emails, which spoof LastPass’s display name, attempt to trick recipients into revealing…
Global Security News
Phishing in 2026: 3 Attack Tactics That Beat Most Enterprise Defenses
Phishing drives about 90% of cyberattacks in 2026, using tactics like encrypted flows, QR code scams, and trusted cloud platforms to steal credentials.
Global Security News, malware
Telegram Increasingly Used to Sell Access, Malware and Stolen Logs
Cybercriminals are now increasingly using Telegram to sell corporate access, malware subscriptions, and stealer logs, turning the messaging app into a fast cybercrime hub.
AI, Global Security News
The Evangelist Teaching a 220-Year-Old Toothpaste Maker to Embrace AI
Colgate-Palmolive turns to Iraklis “Kli” Pappas to drive employees toward using AI for more than just polishing emails.
AI, Global Security News
Hackers Abuse .arpa Top-Level Domain to Host Phishing Scams
Hackers abuse the .arpa Top-Level Domain to host phishing scams, using IPv6 tunnels, reverse DNS tricks, and shadow domains to bypass security checks.
AI, APAC, Apps, Endpoint, Global Security News, Network Security, privacy
What is digital employee experience — and why is it more important than ever?
On any given day, an organization’s employees might be using smartphones, laptops, desktop computers, tablets, a variety of cloud and networking services, a host of enterprise applications and mobile apps, and other digital tools. Many of them might be working remotely, and nearly all of them will be operating with tight security and data privacy…
AI, Global Security News
Fake Google Security site uses PWA app to steal credentials, MFA codes
A phishing campaign is using a fake Google Account security page to deliver a web-based app capable of stealing one-time passcodes, harvesting cryptocurrency wallet addresses, and proxying attacker traffic through victims’ browsers. […]
AI, Global Security News, malware
Microsoft warns of RAT delivered through trojanized gaming utilities
Attackers spread trojanized gaming tools to deliver a stealthy RAT using PowerShell, LOLBins, and Defender evasion tactics. Threat actors are tricking users into running trojanized gaming utilities shared through browsers and chat platforms to deploy a remote access trojan. “Microsoft Defender researchers uncovered a campaign that lured users into running trojanized gaming utilities (Xeno.exe or…
Global Security News, privacy, Risk Management
Mobile app permissions (still) matter more than you may think
Start using a new app and you’ll often be asked to grant it permissions. But blindly accepting them could expose you to serious privacy and security risks.
Global Security News
Notion Launches Custom Agents: Workflows That Run Themselves
Custom Agents automate recurring work for entire teams using organisational knowledge
AI, Global Security News
Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware
A “coordinated developer-targeting campaign” is using malicious repositories disguised as legitimate Next.js projects and technical assessments to trick victims into executing them and establish persistent access to compromised machines. “The activity aligns with a broader cluster of threats that use job-themed lures to blend into routine developer workflows and increase the likelihood of code
AI, Compliance, Global Security News, Risk Management
Just 22% of Australian employees are sticking to company AI-approved tools, says latest Qualtrics report
GUEST OPINION: Almost four out of five Australians are defying company policy and using unauthorised AI tools creating potential security and compliance risks, according to the 2026 Qualtrics Employee Experience Trends Report.
Global Security News
North Korean Lazarus Group Adopts Medusa Ransomware in Global Attacks
Lazarus Group is now using Medusa ransomware in attacks on healthcare and social services, signaling a move toward profit-focused cybercrime.
Global Security News
How to Strengthen App Performance Without Slowing Innovation
Learn how to strengthen app performance without slowing innovation using metrics, observability, scalability planning, and disciplined release strategies.
AI, Global Security News
Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks
The North Korea-linked Lazarus Group (aka Diamond Sleet and Pompilus) has been observed using Medusa ransomware in an attack targeting an unnamed entity in the Middle East, according to a new report by the Symantec and Carbon Black Threat Hunter Team. Broadcom’s threat intelligence division said it also identified the same threat actors mounting an…
AI, Global Security News
Chinese AI Firms Hit Claude with Distillation Attacks, Anthropic Warns
Anthropic accused DeepSeek, Moonshot and MiniMax of illicitly using Claude to steal some of the AI model’s capabilities
AI, Exploits, Global Security News, malware
Wormable XMRig campaign leverages BYOVD and timed kill switch for stealth
A wormable cryptojacking campaign spreads via pirated software, using BYOVD and a time-based logic bomb to deploy a custom XMRig miner. Researchers uncovered a wormable cryptojacking campaign that spreads through pirated software bundles to deploy a custom XMRig miner. The attack uses a BYOVD exploit and a time-based logic bomb to evade detection and maximize…
AI, Global Security News, Risk Management
How Staying Small Became AI Startups’ Biggest Flex
Startups are using AI tools to keep their staff as small as possible. But some are discovering that becoming too lean carries risks.
Global Security News
Pipeline – watch YouTube and PeerTube videos
I’ve covered quite a few GUI tools that let you access YouTube content without using a web browser. Pipeline goes one step further by letting you also view PeerTube content. Pipeline is free and open source software. The post Pipeline – watch YouTube and PeerTube videos appeared first on Linux Today.
Global Security News, malware
Android Malware Hijacks Google Gemini to Stay Hidden
A new Android malware implant using Google Gemini to perform persistence tasks was discovered on VirusTotal and analyzed by ESET
AI, Global Security News
Stop Using Outdated Docker Images – How I Used WUD to Track Container Updates
Stop Using Outdated Docker Images – How I Used WUD to Track Container Updates The post Stop Using Outdated Docker Images – How I Used WUD to Track Container Updates appeared first on Linux Today.
AI, Data Breaches, Global Security News, Government & Policy
French Ministry confirms data access to 1.2 Million bank accounts
A hacker accessed data from 1.2 million French bank accounts using stolen official credentials, the Economy Ministry said. A hacker gained access to data from 1.2 million French bank accounts using stolen credentials belonging to a government official, according to the French Economy Ministry. French authorities said affected account holders will be notified in the…
AI, APAC, Compliance, Data Breaches, Exploits, Global Security News, Network Security, Risk Management
CVE-2026-25903 Impacts Apache NiFi Users
A vulnerability has been disclosed that potentially impacts organizations using Apache NiFi to manage data pipelines. The issue could allow lower-privileged users to modify restricted components within a data flow due to missing authorization checks. “The missing authorization requires a more privileged user to add a restricted component to the flow configuration, but permits a…
Global Security News
Low-Skilled Cybercriminals Use AI to Perform “Vibe Extortion” Attacks
Unit 42 researchers observed a low-skilled threat actor using an LLM to script a professional extortion strategy, complete with deadlines and pressure tactics
AI, Cybersecurity, Global Security News, malware
Google Ads and Claude AI Abused to Spread MacSync Malware via ClickFix
Cybersecurity experts at Moonlock Lab have discovered a new ClickFix attack. Hackers are using hijacked Google Ads and fake Claude AI guides to trick Mac users into installing the data-stealing MacSync malware.
AI, china, Data Breaches, Global Security News, Risk Management, Russia
Hackers Try to Clone Google’s Gemini With 100,000+ AI Probes
Google built Gemini to answer questions. Now attackers are using questions as lockpicks. In a surge of more than 100,000 carefully engineered prompts, threat actors have been hammering Google’s Gemini chatbot in what the company calls “model extraction” or “distillation” attacks. By systematically probing the system, adversaries attempt to reverse engineer the model’s underlying logic,…
AI, Cybersecurity, Global Security News
How to Save YouTube Videos on Chromebook
Learn how to save YouTube videos on a Chromebook using browser-based methods. Simple steps, formats, and tips for offline viewing. Chromebooks are designed to work mainly through the browser. Most apps, files, and everyday tasks depend on a stable internet connection rather than installed software. This matters because Chromebooks are widely used in education. Studies…
AI, Cybersecurity, Global Security News
Attackers are moving at machine speed, defenders are still in meetings
Threat actors are using AI across the attack lifecycle, increasing speed, scale, and adaptability, according to the 2026 State of Cybersecurity report by Ivanti. The study compares perceived threat levels across common attack types with organizational readiness to respond and identifies persistent gaps between awareness and execution across security programs. Preparedness lags behind threat levels…
Global Security News
“What?” – About Platform Engineering in DevSecOps
On “Digital Transformation” in DevSecOps at the CBA; using modular-construction platforms for the support of digital product delivery.
Global Security News
“What?” – About Platform Engineering in DevOps
On “Digital Transformation” in DevSecOps at the CBA; using modular-construction platforms for the support of digital product delivery.
AI, Global Security News
Azul survey shows significant increase in Java being used to code AI functionality
GUEST RESEARCH: More and more organisations are using Java as foundational language for AI development, with Azul’s 2026 State of Java Survey & Report revealing a significant increase.
AI, Apps, Global Security News, Government & Policy, Risk Management, Venture
JumpCloud: Most businesses aren’t truly ready for AI
As developers begin using Claude and Codex to help create Mac, iPhone, and iPad apps in Xcode, spare a moment to consider a recent JumpCloud survey that shows most businesses aren’t really ready for AI — though many think they might be.
Among the highlights from the survey:
- 40% of IT leaders self-assess as mature in their AI practices, yet only 22% meet the rigorous objective standards for leading AI readiness.
- 90% of leaders see productivity gains from AI, but 74% remain concerned about security risks, specifically around unauthorized data access and AI-generated phishing.
- 61% of organizations report the use of unsanctioned AI tools, creating significant visibility and governance gaps.
- 85% of IT leaders agree that secure identity and access management (IAM) is critical for scaling AI safely. (Note that JumpCloud calls itself an AI-powered IT management platform.)
JumpCloud argues that enterprises must deploy IT processes to help protect the identity layer as AI impacts their business, “consolidating identity and access controls for both humans and bots to turn AI from a potential liability into a sustainable engine for growth.”
To support that transition, JumpCloud this week introduced a new investment arm to invest in companies building solutions around AI, security, identity and IT productivity. To an extent, this mirrors competitors in the burgeoning Apple-related IT space (Jamf Ventures, for example) even as it highlights the looming impact AI will have on this side of the market.
One of the first JumpCloud investments, Tofu, uses AI as part of its package of protections against identity fraud during the hiring and onboarding process, an emerging problem for some businesses. You could see Tofu’s tools as indicative of the speed at which AI is evolving.
Between the thought and the action lies the shadow
People don’t seem prepared for the consequences of the rapid evolution even though business leaders think they are. This gap between perceived preparedness and actual readiness comes after over a decade of rapid digital transformation. That transformation saw the iPhone-driven evolution of mobile business, the collapse of the former hegemonic Microsoft dominance of the enterprise, and an algorithmic assault on some of the principles that underpinned international trade.
The impact has been felt by every business, and entire business sectors have already been replaced by digitized alternatives. Our century so far has seen an avalanche of change, (remember “1,000 songs in your pocket”?) and enterprise leaders are struggling to keep pace, the JumpCloud survey shows.
Thought leaders have been discussing the need to adopt a new business mindset in which enterprises accept they live in an environment of constant change. These people say creative thinking and a willingness to embrace constant change will be the hallmarks of business success, but when technology moves faster than business leaders, the business environment itself becomes inevitably unstable.
When it comes to AI deployment, that means confidential data leaks, legal battles as regulators challenge those leaks, and the need to invest in managing digital transformation.
Faster than progress
AI development is accelerating. New models like GPT-5.3 Codex or Claude Opus 4.6 are insanely powerful and have now evolved something like autonomous discretion. That’s why they can create and iterate application code, which Xcode developers will be exploring now that tools have been made available to them.
It won’t end with code. You can see the direction of travel for yourself at METR, an organization that tracks how long it takes AI models to complete long tasks.
Anthropic CEO Dario Amodei tells it like it is when he says AI models “substantially smarter than almost all humans at almost all tasks” could arrive as soon as this year. He also says it might only be a couple of years until AI autonomously builds its own AI successors.
In the background, the leader of Anthropic’s Safeguards Research Team, Mrinank Sharma, just quit, warning the “world is in peril” from a series of interconnected crises, including AI. Think about that, think about the extent to which you and your business truly meet the standards of AI preparedness, and then consider the challenge it poses to IT decision makers working to keep their heads afloat amid this tsunami of change.
The gap between perceived and actual readiness is not just a statistic, it is a call to action for every leader. In a world where AI evolves so very quickly, true leadership requires us to prepare for the unknown. The experts say those who manage to stay afloat will be the ones who experiment today, and adapt tomorrow. While you do that, note that AI will be adapting at the very same time and probably faster, and is already in use, sanctioned, or unsanctioned, across your company.
Are you ready? Probably not yet.
Yes, the image to this story was created using AI.
You can follow me on social media! Join me on BlueSky, LinkedIn, and Mastodon.
AI, Endpoint Protection, MacOS Security, Malware, Security, Global Security News, malware, Network Security, Venture
North Korean actors blend ClickFix with new macOS backdoors in Crypto campaign
A financially motivated threat actor tracked as UNC1609 is using a ClickFix-style social engineering campaign to deploy multiple macOS malware families against crypto-focused organizations. According to new research from Google Cloud’s Mandiant, the activity recently targeted an employee at a company operating in the cryptocurrency and decentralized finance (DeFi) sector. The researchers said that the…
AI, Breaking News, cyber crime, Cybercrime, Exploits, Global Security News, hacking, malware, Network Security
SSHStalker botnet targets Linux servers with legacy exploits and SSH scanning
A new Linux botnet, SSHStalker, has infected about 7,000 systems using old 2009-era exploits, IRC bots, and mass-scanning malware. Flare researchers uncovered a previously undocumented Linux botnet dubbed SSHStalker, observed via SSH honeypots over two months. Researchers ran an SSH honeypot with weak credentials starting in early 2026 and spotted a set of intrusions unlike…
AI, Artificial Intelligence, Cybersecurity, Don't miss, Exploits, framework, Global Security News, News
Zen-AI-Pentest: Open-source AI-powered penetration testing framework
Zen-AI-Pentest provides an open-source framework for scanning and exercising systems using a combination of autonomous agents and standard security utilities. The project aims to let users run an orchestrated sequence of reconnaissance, vulnerability scanning, exploitation, and reporting using AI guidance and industry tools like Nmap and Metasploit. It is written to support command line, API,…
AI, china, Data Breaches, Exploits, Global Security News, Network Security, Remote Access Security, Security, Vulnerabilities
BeyondTrust fixes critical RCE flaw in remote access tools
Companies using self-hosted versions of BeyondTrust Remote Support (RS) or Privileged Remote Access (PRA) should deploy patches for a critical vulnerability that allows attacks to execute OS commands without authentication. “Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption,” BeyondTrust said in…
Global Security News, Security
New Linux botnet SSHStalker uses old-school IRC for C2 comms
A newly documented Linux botnet named SSHStalker is using the IRC (Internet Relay Chat) communication protocol for command-and-control (C2) operations. […]
AI, Apple, CryptoCurrency, Global Security News, malware, Security
North Korean hackers use new macOS malware in crypto-theft attacks
North Korean hackers are running tailored campaigns using AI-generated video and the ClickFix technique to deliver malware for macOS and Windows to targets in the cryptocurrency sector. […]
AI, Apps, Cloud Security, Cybersecurity, Data Breaches, Endpoint, Exploits, Global Security News, malware, Network Security, News, Risk Management, Threats
Bing Ads Abused to Deliver Azure-Hosted Tech Support Scams
A recently identified scam campaign is using Bing search advertisements and Microsoft Azure infrastructure to redirect users to fraudulent tech support pages, demonstrating how legitimate platforms can be misused for social engineering activity. “The tech support scam campaign had a significant initial impact, affecting users across 48 different organizations in the U.S. within a short…
AI, cyber attacks, Global Security News, Phishing Scam, Security
Pride Month Phishing Targets Employees via Trusted Email Services
Attackers are using Pride Month themed phishing emails to target employees worldwide, abusing trusted email platforms like SendGrid to harvest credentials.
cyber crime, Cybersecurity, Europe, Global Security News, Scams and Fraud, Security
Hackers Use Signal QR Codes to Spy on Military and Political Leaders
Hackers are using Signal QR codes and fake support scams to spy on military and political leaders, German security agencies warn.
cyber crime, Cybersecurity, Europe, Global Security News, Scams and Fraud, Security
Hackers Use Signal QR Codes to Spy on Military and Political Leaders
Hackers are using Signal QR codes and fake support scams to spy on military and political leaders, German security agencies warn.
cyber crime, Cybersecurity, Europe, Global Security News, Scams and Fraud, Security
Hackers Use Signal QR Codes to Spy on Military and Political Leaders
Hackers are using Signal QR codes and fake support scams to spy on military and political leaders, German security agencies warn.
AI, Artificial Intelligence, Cloud, Cloud Security, Cybersecurity, Data Breaches, Global Security News, Network Security, News, Risk Management
AI-Driven Attack Gains AWS Admin Privileges in Under 10 Minutes
Threat actors are using artificial intelligence (AI) to accelerate cloud intrusions. In a recent incident observed by Sysdig researchers, attackers escalated from stolen credentials to full administrative access in an AWS environment in under 10 minutes, illustrating how AI can shorten cloud attack timelines. “The threat actor achieved administrative privileges in under 10 minutes, compromised…
AI, Apps, Cybersecurity, Data Breaches, Exploits, Global Security News, Government & Policy, International, malware, Network Security, News, Risk Management, Threats
Fake Dating App Delivers Android Spyware in Targeted Campaign
ESET researchers have uncovered a targeted Android spyware campaign using a fake dating app to lure victims into installing mobile surveillance malware. The campaign, focused on users in Pakistan, disguises spyware as a chat platform that promises access to exclusive profiles but instead quietly exfiltrates sensitive data from infected devices. “Once installed, the app silently…
AI, Announcements, Apps, Compliance, Endpoint, Foundational (100), Global Security News, Launch, Network Security
IAM Identity Center now supports IPv6
Amazon Web Services (AWS) recommends using AWS IAM Identity Center to provide your workforce access to AWS managed applications—such as Amazon Q Developer—and AWS accounts. Today, we announced IAM Identity Center support for IPv6. To learn more about the advantages of IPv6, visit the IPv6 product page. When you enable IAM Identity center, it provides…
AI, Compliance, Cybersecurity, Europe, Global Security News, privacy
Surveillance, spyware, and self-driving snafus
A Mexican drug cartel spies on the FBI using traffic cameras and spyware — because “ubiquitous technical surveillance” is no longer just for dystopian thrillers. Graham digs into a chilling new US Justice Department report that shows how surveillance tech was weaponised to deadly effect. Meanwhile, Carole checks the rear-view mirror on the driverless car…
