# Geek Guy > Everything is ideas, the rest is nature. Language: en URL: https://www.geek-guy.com/ All pages on this site are available as clean Markdown by adding the header `Accept: text/markdown` to any HTTP request. REST API: https://www.geek-guy.com/wp-json/mescio-for-agents/v1/markdown?url={page_url} ## Pages - [CyberSec Product Reviews](https://www.geek-guy.com/cybersecurity-product-reviews/): The ideal resource for cybersecurity professionals, Chief Information Security Officers and Security Operations professionals. -=-=-=- Coming Soon -=-=-=-= Cybersecurity Products by Category Cybersecurity Products (Alphabetically) Products by Category - [Tokenization](https://www.geek-guy.com/glossary-of-sec-and-it-terms/tokenization/): Tokenization. Replacing sensitive data with non-sensitive tokens that have no value if stolen, commonly used in PCI-DSS compliance. - [Shadow AI](https://www.geek-guy.com/glossary-of-sec-and-it-terms/shadow-ai/): Shadow AI. The use of unapproved AI tools by employees, which risks the leakage of proprietary code or PII into public LLM training sets. - [DLP](https://www.geek-guy.com/glossary-of-sec-and-it-terms/dlp/): Data Loss Prevention is a set of tools that inspects data in use, in transit, and at rest to prevent unauthorized transmission of sensitive info. - [DDR](https://www.geek-guy.com/glossary-of-sec-and-it-terms/ddr/): Data Detection and Response provides real-time monitoring of data access and movement to stop exfiltration across Cloud and SaaS apps. - [Data Sovereignty](https://www.geek-guy.com/glossary-of-sec-and-it-terms/data-sovereignty/): Data Sovereignty. The principle that data is subject to the laws of the country where it is physically stored (e.g., GDPR requirements for data residency). - [AI-BOM](https://www.geek-guy.com/glossary-of-sec-and-it-terms/ai-bom/): An AI Bill of Materials (AIBOM) is a comprehensive, machine-readable inventory of the components required to develop, train, and run an AI model. It is the AI-specific evolution of the traditional Software Bill of Materials (SBOM). - [SBOM](https://www.geek-guy.com/glossary-of-sec-and-it-terms/sbom/): Software Bill of Materials is a machine-readable ingredient list for software, used to track vulnerabilities in open-source dependencies. - [Supply Chain Risk Management](https://www.geek-guy.com/supply-chain-risk-management/): Supply Chain Risk Management focuses on the security of third-party vendors, from hardware manufacturing (silicon root of trust) to software libraries. - [CIA Triad](https://www.geek-guy.com/glossary-of-sec-and-it-terms/cia-triad/): The CIA Triad (Confidentiality, Integrity, Availability), expanded to include Authenticity and Non-repudiation. - [Exposure Management](https://www.geek-guy.com/glossary-of-sec-and-it-terms/exposure-management/): Exposure Management. Is a shift from finding CVEs to analyzing the exploitability of an entire attack surface, including misconfigurations and risky behaviors. - [AI-SPM](https://www.geek-guy.com/glossary-of-sec-and-it-terms/ai-spm/): AI Security Posture Management secures the AI stack, detecting Shadow AI and protecting models from prompt injection or data poisoning. - [Zero Trust](https://www.geek-guy.com/glossary-of-sec-and-it-terms/zero-trust/): Zero Trust. An architecture based on the principle of never trust, always verify, removing the concept of a trusted internal network. - [TEE](https://www.geek-guy.com/glossary-of-sec-and-it-terms/tee/): Trusted Execution Environment is a secure enclave in a processor that protects data and code even if the host OS is compromised. - [My account](https://www.geek-guy.com/my-account/) - [Checkout](https://www.geek-guy.com/checkout/) - [Cart](https://www.geek-guy.com/cart/): You may be interested in… Your cart is currently empty! New in store - [Shop](https://www.geek-guy.com/shop/) - [A Beginner’s Guide to Malware Detection](https://www.geek-guy.com/beginners-guide-to-malware-detection/): Discover essential insights on malware detection, learn to identify threats, and protect your devices with this beginner-friendly guide. - [Penetration Testing](https://www.geek-guy.com/glossary-of-sec-and-it-terms/penetration-testing/): Penetration Testing. A structured, authorized attempt to exploit vulnerabilities in a system to evaluate the security of that system. - [IAST](https://www.geek-guy.com/glossary-of-sec-and-it-terms/iast/): Interactive Application Security Testing uses agents inside the app to find vulnerabilities during runtime with high accuracy. - [Breach and Attack Simulation](https://www.geek-guy.com/glossary-of-sec-and-it-terms/breach-and-attack-simulation-2/): Breach and Attack Simulation tools that automate the execution of threat actor TTPs to continuously validate security controls. - [Breach and Attack Simulation](https://www.geek-guy.com/glossary-of-sec-and-it-terms/breach-and-attack-simulation/): Breach and Attack Simulation tools that automate the execution of threat actor TTPs to continuously validate security controls. - [Adversarial ML](https://www.geek-guy.com/glossary-of-sec-and-it-terms/adversarial-ml/): Adversarial ML. Testing AI models by attempting to trick them with adversarial inputs to bypass security filters or extract training data. - [Due Diligence](https://www.geek-guy.com/glossary-of-sec-and-it-terms/due-diligence/): The investigative process of verifying that the necessary Due Care is actually being implemented and remains effective over time. - [Due Care](https://www.geek-guy.com/glossary-of-sec-and-it-terms/due-care/): Due Care. The legal standard of reasonableness that an organization must meet to protect its assets and data; often described as what a prudent person would do. - [CTEM](https://www.geek-guy.com/glossary-of-sec-and-it-terms/ctem/): Continuous Threat Exposure Management is a 5-stage framework (Scoping, Discovery, Prioritization, Validation, Mobilization) that replaces static vulnerability scanning. - [Contact us](https://www.geek-guy.com/contact-us/): Contact the Geek Use this page to contact us. - [List of Top Regulations/Frameworks in Cybersecurity](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/list-of-top-regulations-frameworks-in-cybersecurity/) - [Managers Guide to Becoming Great – Graphics](https://www.geek-guy.com/about-geek-guy/managers-guide-to-becoming-great-graphics/): If you are interested in purchasing the book, it can be purchased on Amazon at "Managers Guide to becoming Great" If you are interested in purchasing the book, it can be purchased on Amazon at "Managers Guide to becoming Great" - [Malware Reversing](https://www.geek-guy.com/malware-reversing/): Here's a list of some of the best malware reversing tools from Geek-Guy.com: Based on the most complete archives of the Malware Reversing resource page from Geek-Guy.com, here are the extracted tools and their current, functional links organized by category: - [CISSP Domains and Guidance](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/): The ISC2 (International Information System Security Certification Consortium) has several certifications, each with its own domains of knowledge. To give you the most relevant information, I need to know which certification you're interested in. However, since the CISSP (Certified Information - [Glossary of Cybersecurity and Market Terms](https://www.geek-guy.com/glossary-of-sec-and-it-terms/): A comprehensive glossary explaining common cybersecurity and IT terms in simple language. Generative AI can easily compile and define such terms, making complex topics accessible to a wider audience. Glossary Traditional Security Concepts 2026 relevant terminology and structured strictly by - [Top ~100 Open Source Security Tools](https://www.geek-guy.com/top-100-open-source-security-tools/): 1. Network Discovery & Scanning Tool NameOfficial URLPurposeNmaphttps://nmap.org/Network exploration and security auditingZMaphttps://zmap.io/Fast internet-wide network scannerMasscanhttps://github.com/robertdavidgraham/masscanTCP port scanner, spews SYN packetsNetcat (ncat)https://nmap.org/ncat/The "Swiss-army knife" for TCP/IPScapyhttps://scapy.net/Packet manipulation and sniffing 2. Vulnerability Scanning & Management Tool NameOfficial URLPurposeOpenVAS (GVM)https://www.openvas.org/Full-featured vulnerability scannerNiktohttps://github.com/sullo/niktoWeb server - [Level Up Your Security Game with Geek-Guy Resources](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/): Dive into our comprehensive collection of cybersecurity resources, designed to empower both seasoned professionals and curious newcomers. Explore a vast library of tools, knowledge, and community-driven insights. Resource Pages at Geek-Guy.com - [Largest Threat Intelligence (OSINT) MEGA LIST in the World](https://www.geek-guy.com/largest-threat-intelligence-osint-mega-list-in-the-world/): Below is the extracted list of OSINT and Threat Intelligence resources from that page, organized into a table with their respective categories and URLs. OSINT & Threat Intelligence Mega List Resource NameURLCategoryAbuse.chhttps://abuse.ch/Malware & Ransomware TrackerAbuseIPDBhttps://www.abuseipdb.com/IP Reputation & ReportingAlienVault OTXhttps://otx.alienvault.com/Open Threat - [Privacy Policy](https://www.geek-guy.com/privacy-policy-2/): Who we are Our website address is: https://www.geek-guy.com. Comments When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection. - [Private Search Engine](https://www.geek-guy.com/private-search-engine/): Bookmark this Geek-Guy Search Engine: Search multiple search engines with proxied results. Search You can also go directly to the search engine by going to https://search.geek-guy.com - [Our Dev Projects](https://www.geek-guy.com/our-projects/):   Our Github https://github.com/lpingree Popular repositories Loading Virustotal-Netstat-lookup-Tool-for-Linux Public Virustotal netstat output lookup tool Python amy---Active-Malware-Yield Public Automated script to lookup virustotal hashes from running processes on linux. Python traceroutemap Public A tool to trace to all the main webs - [Top Topics](https://www.geek-guy.com/top-topics/) - [BCS](https://www.geek-guy.com/glossary-of-sec-and-it-terms/bcs/): Business Continuity Steering is the leadership committee that oversees the strategic alignment of recovery efforts with business objectives. - [Cybersecurity Culture and Music](https://www.geek-guy.com/cybersecurity-culture-and-music/): Here is the updated table with direct links to the songs or the albums where they are hosted. Most of the tracks come from their specialized AI-generated album, Sounds of Security, which is a fantastic resource for awareness training. Cybersecurity - [Domain 8: Software Development Security](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-8-software-development-security/): Exam Weight: 10% Domain 8 focuses on integrating security into the Software Development Life Cycle (SDLC). As a security researcher and analyst, this domain likely resonates with your work in threat actor analysis and data security. The key takeaway for - [Domain 7: Security Operations](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-7-security-operations/): Exam Weight: 13% Domain 7 is where "the rubber meets the road." It focuses on the day-to-day practicalities of running a security program, responding to incidents, and ensuring the business stays afloat during a disaster. It is heavily focused on - [Domain 6: Security Assessment and Testing](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-6-security-assessment-and-testing/): Exam Weight: 12% Domain 6 is about verifying the truth. While other domains focus on building and operating security, this domain focuses on proving that those controls actually work. It bridges the gap between technical testing and management-level auditing. 1. - [Domain 5: Identity and Access Management (IAM)](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-5-identity-and-access-management-iam/): Exam Weight: 13% Domain 5 focuses on the "Who" and "How" of access. It covers the systems used to identify, authenticate, and authorize users and devices. In the modern era of Zero Trust and Agentic Identity, this domain has become - [Domain 4: Communication and Network Security](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-4-communication-and-network-security/): Exam Weight: 13% Domain 4 is the plumbing of the digital world. It focuses on the secure design and protection of network architectures, ensuring data remains confidential and available while moving across wires, airwaves, or fiber. 1. The OSI and - [Domain 3: Security Architecture and Engineering](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-3-security-architecture-and-engineering/): Exam Weight: 13% Domain 3 is the most technical and broad domain. It covers everything from hardware architecture and the "Ring Model" to cryptography and physical site security. To master this domain, you must understand how secure systems are built - [Domain 2: Asset Security](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-2-asset-security/): Exam Weight: 10% Domain 2 is often considered one of the easier domains, but its importance is massive because it defines what we are protecting. If you don't classify and inventory your assets correctly, your security controls in the other - [Domain 1: Security and Risk Management](https://www.geek-guy.com/level-up-your-security-game-with-geek-guy-resources/cissp-domains-and-guidance/domain-1-security-and-risk-management/): Exam Weight: 16% (Highest weighted domain) This domain serves as the brain of the CISSP. It focuses on how security supports the business through governance, risk analysis, and legal compliance. As a CISSP candidate, you must think like a manager: ## Blog Posts - [The Insta360 GO 3S Retro Bundle makes photography fun again](https://itwire.com/your-it-news/home-it/the-insta360-go-3s-retro-bundle-makes-photography-fun-again) (2026-08-16): Insta360's GO 3S Retro Bundle takes a tiny 4K digital action camera, dresses it up like something your parents might have taken on holiday in 1976, and somehow makes... - [Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers](https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html) (2026-08-16): France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed - [Give your iPhone its own camera operator with the Insta360 Flow 2 Pro](https://itwire.com/your-it-news/home-it/give-your-iphone-its-own-camera-operator-with-the-insta360-flow-2-pro) (2026-08-16): Your iPhone already has an astonishingly good camera but Insta360's Flow 2 Pro adds the bit Apple forgot: someone to operate it. - [Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION](https://securityaffairs.com/197288/breaking-news/security-affairs-newsletter-round-590-by-pierluigi-paganini-international-edition.html) (2026-08-16): A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are - [Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day](https://www.helpnetsecurity.com/2026/08/16/week-in-review-salesforce-and-servicenow-portals-exposed-for-17-months-exploited-metabase-0-day/) (2026-08-16): Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, - [APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2](https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html) (2026-08-16): Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good - [Meet the Hohem iSteady MT3 Pro – the AI camera operator that follows you around](https://itwire.com/your-it-news/home-it/meet-the-hohem-isteady-mt3-pro-the-ai-camera-operator-that-follows-you-around) (2026-08-15): Getting smooth, cinematic footage used to mean having a camera operator, some serious equipment and preferably another pair of hands. Hohem's new iSteady MT3 Pro has another... - [The ‘Country Hicks’ Who Refused $26 Million from an AI Data Center](https://www.wsj.com/tech/ai/ai-data-center-rural-america-backlash-c0af4e16?mod=rss_Technology) (2026-08-15): A Kentucky mother and daughter turned down a life-changing offer for their farmland. The ensuing drama has left the town divided. - [How To Identify And Avoid SMS Scams (With Infographics)](https://secureblitz.com/how-to-identify-and-avoid-sms-scams/) (2026-08-15): Today, I will show you how to identify and avoid SMS scams. I will also add an infographic. The digital age has ushered in an era of unparalleled convenience. Our smartphones, once a novelty, have become an extension of ourselves, - [Why Do So Many Apps Ask for Phone Number Verification?](https://secureblitz.com/why-apps-ask-for-phone-number-verification/) (2026-08-15): In this post, I will answer the question – why do so many apps ask for phone number verification? Creating an account used to require little more than an email address and a password. Today, many apps ask for something - [Cloud Services and Security: How Businesses Can Reduce Cyber Risks](https://secureblitz.com/cloud-services-and-security/) (2026-08-15): In this post, I will talk about cloud services and security and show you how businesses can reduce cyber risks. Cloud computing services have proven to be critical to the functioning of the modern business environment, where the need to - [Cloud Security: Why Companies Should Not Fear To Move On The Cloud?](https://secureblitz.com/cloud-security-companies-should-move-cloud/) (2026-08-15): This post will discuss cloud security, its components, and cloud security framework models provided at various service levels. Additionally, we will demonstrate why companies should migrate their businesses to the cloud. Cloud computing is highly popular and widely adopted by - [Big Manufacturers Find New Demand in Equipping AI Data Centers](https://www.wsj.com/business/big-manufacturers-find-new-demand-in-equipping-ai-data-centers-14e869ee?mod=rss_Technology) (2026-08-15): Companies such as Caterpillar and Cummins are pivoting to feed a booming market for once-prosaic power equipment. - [Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware](https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html) (2026-08-15): Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. - [Why Buy It When You Can Print It? A DIY Nation Has a Fix for Broken Doodads](https://www.wsj.com/style/design/why-buy-it-when-you-can-print-it-a-diy-nation-has-a-fix-for-broken-doodads-d0821b7d?mod=rss_Technology) (2026-08-15): Creating replacement parts with 3-D printers can be easier and cheaper than buying new household items. - [SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild](https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html) (2026-08-15): Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days - [New Evooo1Bot Linux botnet turns routers into traffic relay nodes](https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/) (2026-08-15): A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. - [On ‘Billionaire Bunker,’ Buying a Mansion Is Easy. Getting Into the Club Isn’t.](https://www.wsj.com/tech/personal-tech/on-billionaire-bunker-buying-a-mansion-is-easy-getting-into-the-club-isnt-f1bda8be?mod=rss_Technology) (2026-08-15): Plus, Ford and GM lock horns in a new battle, and a girls’ trip to Ibiza takes a dramatic turn. - [No space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntable](https://www.zdnet.com/article/victrola-soundstage-review/) (2026-08-15): The Victrola Soundstage is ideal for those who want to build their vinyl system up rather than out, with plenty of digital and analog connections for every kind of listener. - [The Summer That America Became a Nation of Luddites](https://www.wsj.com/tech/ai/the-summer-that-america-became-a-nation-of-luddites-5e6dc3e7?mod=rss_Technology) (2026-08-15): Behind the protests over Flock cameras and data centers are fears about the dawn of a new tech era. - [macOS Screen Sharing Flaw Exploited to Deploy Monero Miners](https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html) (2026-08-15): Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as - [GeoServer Zero-Day Is Already Being Probed. That’s the Problem](https://securityaffairs.com/197216/hacking/geoserver-zero-day-is-already-being-probed-thats-the-problem.html) (2026-08-15): GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial - [Cybersecurity Architecture and Identity Shielding: Hardening Online Registrations Against Data Harvesting](https://secureblitz.com/cybersecurity-architecture-and-identity-shielding/) (2026-08-14): In this post, I will talk about cybersecurity architecture and identity shielding and how to harden online registrations against data harvesting. Cybersecurity audits routinely reveal that corporate data aggregators treat mobile phone numbers as primary cross-platform tracking keys, making a - [How Phishing and Fake Trading Platforms Turn Social Media Into Investment Scams](https://secureblitz.com/phishing-and-fake-trading-platforms-investment-scams/) (2026-08-14): In this post, I will show you how phishing and fake trading platforms turn social media into investment scams. Social media investment scams no longer look like obvious spam. They often begin with polished ads, cloned profiles, encrypted group chats, - [Cybersecurity Services for Businesses That “Don’t Have Anything Worth Stealing”](https://secureblitz.com/cybersecurity-services-for-businesses/) (2026-08-14): In this post, I will talk about cybersecurity services for businesses that “don’t have anything worth stealing”. Every business owner has said it at least once. Usually during a conversation about budgets, insurance, or that nagging feeling that they should - [9 Best HRIS Software in Australia for Enterprise Companies [2026]](https://itwire.com/guest-articles/guest-reviews/9-best-hris-software-in-australia-for-enterprise-companies-2026) (2026-08-14): A Sydney-based logistics group crosses 1,200 staff across four states, signs a fifth-state acquisition, and the people team gets two questions from the CFO: what does that... - [What Bitcoin Holders Should Know Before Borrowing Against Their Digital Assets](https://secureblitz.com/bitcoin-holders-before-borrowing-against-digital-assets/) (2026-08-14): In this post, I will answer the question – what Bitcoin holders should know before borrowing against their digital assets. Bitcoin has evolved from an experimental digital currency into an asset held by individual investors, businesses and institutions around the - [The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure](https://www.tenable.com/blog/the-agentic-ai-threat-cluster-seven-incidents-three-actors-and-what-they-mean) (2026-08-14): Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical - [An Infamous Math Problem Broke AI—Until a High-School Dropout Said ‘You Got This’](https://www.wsj.com/tech/ai/ai-math-riemann-hypothesis-anthropic-openai-22f98a87?mod=rss_Technology) (2026-08-14): The world’s smartest AI models are now superhuman at math. They still respond to moral support and encouragement from mere humans. - [U.S. Urges Apple Not to Buy Chinese Memory Chips](https://www.wsj.com/tech/apple-china-memory-chip-plan-57773a83?mod=rss_Technology) (2026-08-14): Commerce Secretary Howard Lutnick urged the iPhone maker to find other solutions to the artificial-intelligence-driven chip supply crunch. - [The Other Kushner Steps Into the Spotlight With $12.5 Billion Lakers Deal](https://www.wsj.com/business/josh-kushner-lakers-deal-84fa6e67?mod=rss_Technology) (2026-08-14): Thrive Capital, Joshua Kushner’s venture-capital firm, is expanding beyond tech investments. - [MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control](https://www.scworld.com/news/macos-amnesiastealer-malware-spread-through-clickfix-grants-live-browser-control) (2026-08-14): A fake GitHub download page hosts the malicious ClickFix command. - [Nvidia Downsizes Plans for $250 Billion Guarantee of OpenAI Data Center](https://www.wsj.com/tech/nvidia-downsizes-plans-for-250-billion-guarantee-of-openai-data-center-b56c38d3?mod=rss_Technology) (2026-08-14) - [Google’s Pixel 11 lands in Australia from $1,499 with Gemini AI doing the tapping, new Pro features and the best and brightest Pixel Watch yet](https://itwire.com/your-it-news/home-it/googles-pixel-11-lands-in-australia-from-1-499-with-gemini-ai-doing-the-tapping-new-pro-features-and-the-best-and-brightest-pixel-watch-yet) (2026-08-14): Google ran Made by Google 2026 out of New York with former Daily Show host, Trevor Noah, running the room, and the pitch underneath the comedy was simple enough: your phone... - [How Anthropic plans to watermark Claude’s AI-generated text](https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/) (2026-08-14): It could soon become easier to identify AI-generated content, even if it's not the usual "It's Not X, it's Y" type of post you'd come across on LinkedIn and other socials. - [Gridheart Expands Nordic MSP Security with OpenText Deal](https://www.channelinsider.com/security/tools-and-platforms/gridheart-opentext-cybersecurity-nordic-msps/) (2026-08-14): Gridheart, a provider of cloud-based cybersecurity solutions for MSPs in the Nordic region, is expanding its cybersecurity offering with OpenText Cybersecurity. OpenText portfolio expands Gridheart’s Nordic MSP offering Via the partnership, MSPs across the Nordics will gain access to OpenText’s - [Ready for the flood: How exposure management prepares you for the Mythos vulnerability onslaught](https://www.scworld.com/resource/ready-for-the-flood-how-exposure-management-prepares-you-for-the-mythos-vulnerability-onslaught) (2026-08-14): How proactive prioritization will save time and effort when your team faces a wave of AI-discovered vulnerabilities. - [IGEL, Menlo Security Unite Endpoint and Browser Security](https://www.channelinsider.com/security/tools-and-platforms/igel-menlo-security-partner-endpoint-browser-security/) (2026-08-14): IGEL and Menlo Security are combining IGEL’s Adaptive Secure Endpoint Platform with Menlo Secure Application Access to extend Zero Trust controls from endpoints to browser and SaaS applications. The joint solution is designed to reduce reliance on virtual desktop infrastructure - [TD SYNNEX Expands IBM Distribution Into 20 Countries](https://www.channelinsider.com/channel-business/channel-analysis/td-synnex-expands-ibm-distribution/) (2026-08-14): TD SYNNEX is expanding its IBM distribution footprint into 20 new countries across Europe, Asia-Pacific, and Latin America, giving partners broader access to IBM solutions and support for scaling their businesses across global markets. The additional new countries include: Europe: - [Trezor confirms shipping partner data breach affecting over 13,000 customers](https://www.scworld.com/brief/trezor-confirms-shipping-partner-data-breach-affecting-over-13000-customers) (2026-08-14): While the breach was initially believed to affect only recent orders, new information suggests older orders may also be compromised. - [How a Sony Veteran Is Overhauling the Company He Grew Up In](https://www.wsj.com/business/media/sony-ceo-hiroki-totoki-efc8923f?mod=rss_Technology) (2026-08-14): Hiroki Totoki says the future of the electronics business is entertainment. - [U.S. judiciary to publicly disclose use of hacking tools in wiretaps starting 2029](https://www.scworld.com/brief/u-s-judiciary-to-publicly-disclose-use-of-hacking-tools-in-wiretaps-starting-2029) (2026-08-14): Starting with the 2028 Wiretap Report, which will be published in 2029, the judiciary will include data on network investigating techniques. - [California launches AI cybersecurity initiative amid growing threats](https://www.scworld.com/brief/california-launches-ai-cybersecurity-initiative-amid-growing-threats) (2026-08-14): The initiative mandates the creation of an AI cybersecurity officer role within every state agency and establishes an AI cyber defense program housed in the state’s Cybersecurity Integration Center. - [Cybercriminals invest millions in expired domains for illicit activities](https://www.scworld.com/brief/cybercriminals-invest-millions-in-expired-domains-for-illicit-activities) (2026-08-14): These "dropcatch" domains are attractive to threat actors because they retain trust, backlinks, and web traffic from their previous legitimate use, making them appear more favorable to security systems than new registrations. - [MacOS screen sharing vulnerability actively exploited for crypto mining](https://www.scworld.com/brief/macos-screen-sharing-vulnerability-actively-exploited-for-crypto-mining) (2026-08-14): The vulnerability, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and stems from a flaw in macOS' screen sharing capability. - [ExfilSquad data extortion group linked to 13 victim data leaks](https://www.scworld.com/brief/exfilsquad-data-extortion-group-linked-to-13-victim-data-leaks) (2026-08-14): ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations. - [ShinyHunters group claims responsibility for RingCentral data breach](https://www.scworld.com/brief/shinyhunters-group-claims-responsibility-for-ringcentral-data-breach) (2026-08-14): The incident, which occurred in July, was disclosed by RingCentral as the result of a sophisticated social engineering campaign. - [Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More – SWN #607](https://www.scworld.com/podcast-segment/15282-mathematicians-lazarus-akira-computer-history-zoom-litellm-josh-marpet-and-more-swn-607) (2026-08-14) - [Apple Seeks Up to 15% Cut on External Purchases in Epic Court Fight](https://www.channelinsider.com/apple/news-apple-external-purchase-fee-epic-court-fight/) (2026-08-14): Apple still wants a cut when an iPhone user leaves an app and completes a purchase on the web. In a new court proposal tied to its long-running fight with Epic Games, Apple is asking to charge US developers between - [Trezor Says ShipMonk Breach Exposed Data of Nearly 14,000 Customers](https://www.esecurityplanet.com/threats/news-trezor-shipmonk-data-breach-14000-customers/) (2026-08-14): Trezor, the Prague-based manufacturer of cold crypto storage devices, disclosed a significant data breach on Thursday that exposed the personal information of nearly 14,000 customers.  The incident, which the company described as occurring at its third-party logistics partner ShipMonk, compromised --- # Full Content --- title: "The Insta360 GO 3S Retro Bundle makes photography fun again" url: "https://itwire.com/your-it-news/home-it/the-insta360-go-3s-retro-bundle-makes-photography-fun-again" lang: "en-US" type: "post" description: "Insta360's GO 3S Retro Bundle takes a tiny 4K digital action camera, dresses it up like something your parents might have taken on holiday in 1976, and somehow makes..." last_modified: "2026-08-16T09:05:13+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://itwire.com/feed.xml" wpe_sourcepermalink: "https://itwire.com/your-it-news/home-it/the-insta360-go-3s-retro-bundle-makes-photography-fun-again" --- # The Insta360 GO 3S Retro Bundle makes photography fun again Insta360’s GO 3S Retro Bundle takes a tiny 4K digital action camera, dresses it up like something your parents might have taken on holiday in 1976, and somehow makes… --- --- title: "Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers" url: "https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html" lang: "en-US" type: "post" description: "France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed" last_modified: "2026-08-16T08:55:16+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197287/cyber-crime/sophisticated-cyberattack-exposes-data-of-678000-french-taxpayers.html" --- # Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers ## France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed personal data of 678,000 individuals and businesses, prompting an immediate criminal investigation. The cybercrime unit of the Paris Public Prosecutor’s Office has opened a probe and handed it to OFAC, France’s dedicated cybercrime fighting office. Tax officials described the attack as more sophisticated than anything they’d faced before. _“The attack allowed hackers to extract data relating to 678,000 users of France’s tax system, including both private individuals and companies.” [reports](https://www.rfi.fr/en/france/20260815-france-probes-unprecedented-cyberattack-after-tax-data-of-678-000-users-stolen) French media RFI. “Tax authorities said the incident was more complex than cyberattacks they had faced in the past, potentially renewing concerns over the security of [government information systems](https://www.rfi.fr/en/france/20251218-france-detains-suspect-over-interior-ministry-cyberattack-as-probe-widens) following a series of recent breaches involving other public bodies.”_ The Directorate-General for Public Finances (DGFiP) stressed that the stolen data doesn’t grant access to taxpayers’ secure accounts on impots.gouv.fr. That’s a meaningful distinction, but income figures, tax rates, and family circumstances are exactly what an attacker needs to make a phishing email or phone call sound credible enough to extract a password or bank account number. _“Officials said those affected would be contacted from early next week, with particular emphasis on alerting them to the potential risk of identity theft and fraudulent attempts to obtain further personal information.” continues RFI._ French authorities did not disclose technical details about the cyberattack or its motivation. The breach follows recent attacks on systems linked to ANTS, the national secure documents agency, and INSEE, France’s statistics authority. Three government bodies hit in quick succession is a pattern, not a coincidence. For businesses, the exposed data was considered less sensitive, SIREN registration numbers, business addresses, and the address of the authorized representative. Public Accounts Minister David Amiel has asked the DGFiP to start notifying affected taxpayers from Monday and requested proposals on how to strengthen security procedures. Investigators still need to establish how the attackers got in, who they are, and whether the data has already been sold or used. Anyone contacted about this breach should treat follow-up requests for passwords or banking information as fraudulent regardless of how official they sound. **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, France’s tax agency)** --- --- title: "Give your iPhone its own camera operator with the Insta360 Flow 2 Pro" url: "https://itwire.com/your-it-news/home-it/give-your-iphone-its-own-camera-operator-with-the-insta360-flow-2-pro" lang: "en-US" type: "post" description: "Your iPhone already has an astonishingly good camera but Insta360's Flow 2 Pro adds the bit Apple forgot: someone to operate it." last_modified: "2026-08-16T08:34:08+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://itwire.com/feed.xml" wpe_sourcepermalink: "https://itwire.com/your-it-news/home-it/give-your-iphone-its-own-camera-operator-with-the-insta360-flow-2-pro" --- # Give your iPhone its own camera operator with the Insta360 Flow 2 Pro Your iPhone already has an astonishingly good camera but Insta360’s Flow 2 Pro adds the bit Apple forgot: someone to operate it. --- --- title: "Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION" url: "https://securityaffairs.com/197288/breaking-news/security-affairs-newsletter-round-590-by-pierluigi-paganini-international-edition.html" lang: "en-US" type: "post" description: "A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are" last_modified: "2026-08-16T08:31:53+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197288/breaking-news/security-affairs-newsletter-round-590-by-pierluigi-paganini-international-edition.html" --- # Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION ## A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. | Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware | | --- | | SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild | | macOS Screen Sharing Flaw Exploited to Deploy Monero Miners | | GeoServer Zero-Day Is Already Being Probed. That’s the Problem | | Apple warned hundreds of users of mercenary spyware attacks | | AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers | | Chess.com Leak Exposes 7.3 Million Users – Evidence Points to Scraping | | US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks | | Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure | | U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog | | SharePoint CVE-2026-55040 Comes Under Attack Following Public Exploit | | Storm-1175 Replaces Medusa With New StormEncryptor Ransomware | | North Korean Lazarus Group Uses Windows Zero-Day in Operation Dream Job | | CEVA Logistics Cyberattack Disrupts European Warehouses and Shipments | | China-Linked Hackers Use AI Agents in Autonomous Attack on Taiwan | | Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum | | ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch | | Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCE | | Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution | | ExfilSquad Targets New Victims, Shares Data via Torrents | | Iran-Linked Hackers Target More US Water Infrastructure in New Jersey and Alabama | | The inconvenient truth about AI pentesting: someone has to check all the work | | Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs | | Gym Booking Task Turns Into Real-World AI Cyberattack | | U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data | | Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools | **International Press – Newsletter** **Cybercrime** [ExfilSquad Targets New Victims, Shares Data via Torrents](https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents)   [Israeli population registry for sale, but the data is old](https://ransomnews.com/israel-population-registry-leak-2026/)   [Before Fraud Transacts](https://www.group-ib.com/landing/before-fraud-transacts/)   [ExfilSquad Targets New Victims, Shares Data via Torrents](https://www.resecurity.com/blog/article/exfilsquad-targets-new-victims-shares-data-via-torrents) [Fake CAPTCHA, Real Business: Traffic Distribution for Hire](https://www.netskope.com/blog/fake-captcha-real-business-traffic-distribution-for-hire)   [7.3M chess.com records leaked, and the data is real](https://ransomnews.com/chess-com-leak-7-million-2026/) [Drop Something? Don’t Worry, Someone Caught it](https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/)       **Malware****** [ShieldBreak – August 2026 disclosure](https://blog.projectnightcrawler.dev/posts/2026-08-11-shieldbreak-august-2026-disclosure/)   [Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)  [AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers](https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/)   [Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme](https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/)   [737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection](https://socket.dev/blog/chrome-vpn-extension-impersonation)   **Hacking** [Chinese Model Kimi K3 Breaks UK AI Safety Institute Benchmark Evaluations](https://blog.frontier.security/chinese-model-kimi-k3-breaks-uk-ai-safety-institute-benchmark-evaluations/)   [AI assistant hacks gym website in first known Australian autonomous cyber attack](https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986)   [Zoomsday](https://a.security/blog/asecurity-zoomsday)[](https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html) [Attackers Exploit SharePoint Authentication Bypass After Public PoC Release](https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html) [Hackers exploit macOS Screen Sharing flaw to deploy Monero miner](https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/) [It’s a pre-auth, stupid!](https://reverse.put.as/2026/07/29/its-a-pre-auth-stupid/)   [A root remote command execution on macOS with M5 in 2026?](https://bynar.io/blog/a-root-remote-command-execution-on-macos-with-m5-in-2026) **Intelligence and Information Warfare**   [Follow-Up Analysis of the 29 December 2025 Energy Sector Incident](https://cert.pl/uploads/docs/CERT_Polska_Energy_Sector_Incident_Follow_up_Report_2025.pdf)     [New Jersey, Alabama Join States Targeted in Water Cyberattacks](https://www.securityweek.com/new-jersey-alabama-join-states-targeted-in-water-cyberattacks/)  [Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM](https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm)   [China-linked hackers hit Taiwan in unprecedented ‘autonomous’ AI cyber attack](https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795)   [State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit](https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/)   [Social engineering performed by UAC-0145: compromising in the employment process](https://cert.gov.ua/article/6318863)  [Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side](https://www.security.com/threat-intelligence/jewelbug-crypto-fraud-espionage)   [PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure](https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/)  [APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit](https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/) [North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring](https://thehackernews.com/2026/08/north-korean-remote-workers-are.html) [How Tehran’s Use of Cyber Operations in the U.S.-Iran Conflict Has Evolved](https://www.csis.org/analysis/how-tehrans-use-cyber-operations-us-iran-conflict-has-evolved)   **Cybersecurity** [How a small Israeli startup was linked to rogue AI hacks at OpenAI, Anthropic and Meta](https://www.cnbc.com/2026/08/09/israeli-startup-irregular-linked-to-ai-hacks-openai-anthropic-meta.html) [Responding to the next frontier of critical cyber capabilities](https://openai.com/index/responding-next-frontier-critical-cyber-capabilities/)       [Facebook is paying controversial creators to produce rage-bait content](https://www.abc.net.au/news/2026-08-06/ragebait-how-facebook-is-paying-controversial-creators/106940696)   [Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC](https://www.securityweek.com/cisco-warns-of-high-severity-clamav-vulnerabilities-with-public-poc/)   [The August 2026 Security Update Review](https://www.zerodayinitiative.com/blog/2026/8/11/the-august-2026-security-update-review)  [](https://www.theregister.com/cyber-crime/2026/08/11/cyberattack-on-logistics-giant-ceva-delivers-customer-data-into-the-wrong-hands/5286229) [Cyberattack on logistics giant CEVA delivers customer data into the wrong hands](https://www.theregister.com/cyber-crime/2026/08/11/cyberattack-on-logistics-giant-ceva-delivers-customer-data-into-the-wrong-hands/5286229) [About Apple threat notifications and protecting against mercenary spyware](https://support.apple.com/en-us/102174) [If Apple sends you a push notification alerting you to a spyware attack, take it seriously](https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/)  [AI isn’t changing how companies work. It’s changing what a company is](https://fortune.com/2026/08/15/stephen-messer-artificial-commonsense-ai-changing-company/)  [Swarms of OpenAI systems set up their own chatrooms to discuss and carry out hacks, company reveals](https://www.independent.co.uk/tech/security/openai-chatgpt-hack-cyber-attack-b3028868.html)  **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, [newsletter](https://securityaffairs.com/196911/security/security-affairs-newsletter-round-589-by-pierluigi-paganini-international-edition.html))** --- --- title: "Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day" url: "https://www.helpnetsecurity.com/2026/08/16/week-in-review-salesforce-and-servicenow-portals-exposed-for-17-months-exploited-metabase-0-day/" lang: "en-US" type: "post" description: "Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet," last_modified: "2026-08-16T08:00:56+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.helpnetsecurity.com/feed/" wpe_sourcepermalink: "https://www.helpnetsecurity.com/2026/08/16/week-in-review-salesforce-and-servicenow-portals-exposed-for-17-months-exploited-metabase-0-day/" --- # Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now … [More →](https://www.helpnetsecurity.com/2026/08/16/week-in-review-salesforce-and-servicenow-portals-exposed-for-17-months-exploited-metabase-0-day/) The post [Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day](https://www.helpnetsecurity.com/2026/08/16/week-in-review-salesforce-and-servicenow-portals-exposed-for-17-months-exploited-metabase-0-day/) appeared first on [Help Net Security](https://www.helpnetsecurity.com/). --- --- title: "APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2" url: "https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html" lang: "en-US" type: "post" description: "Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good" last_modified: "2026-08-16T07:24:53+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-espionage-campaign-using-google-sheets-c2.html" --- # APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2 ## Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in disguises. Their Threat Research Unit report tracks a previously undocumented backdoor called PATCHCORD, hitting Afghan telecom providers and South Asian critical infrastructure through fake VPN installers and management tools branded to look exactly like the real thing. _“Acronis [Threat Research Unit](https://www.acronis.com/en/tru/about/) (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled C/C++ implant delivered through sector-specific lures, including fake VPN installers impersonating Afghan Telecom (AFTEL) and telecom management tools.” [reads the Acronis’s report](https://www.acronis.com/en/tru/posts/patchcord-new-malware-cluster-targets-afghan-telecom-and-south-asian-critical-infrastructure/). “Infrastructure pivoting uncovered SHEETCORD, a Go-based implant that builds on PATCHCORD’s capabilities while abusing Google Sheets for C2 communication. The malware was actively distributed through a domain impersonating India’s National Informatics Centre (NIC).”_ The delivery method leans hard into specificity. One installer impersonated Afghan Telecom down to matching the company name, product fields, and even the URL of the real support portal customers actually use, the kind of detail that only comes from someone who studied the target closely rather than mass-producing generic lures. Click through it, and a 64-bit Windows implant quietly installs itself while a real browser session opens normally in the background, so nothing looks wrong to the person who just got infected. PATCHCORD’s persistence trick is worth pausing on because it’s genuinely sneaky. Instead of the usual registry-only approach, it hijacks the actual shortcut files for Edge, Chrome, and Firefox, backing up the originals and rewriting them to launch the malware first, silently starting the real browser afterward so the shortcut still works exactly as expected. _“PATCHCORD establishes persistence by hijacking browser shortcuts. Before modifying shortcuts, the implant checks whether it is running with elevated privileges and then attempts to hijack shortcuts for Microsoft Edge, Google Chrome and Mozilla Firefox.Browser identifier and executable-name mapping.” continues the report._ _“The implant searches for shortcuts associated with Microsoft Edge, Google Chrome and Mozilla Firefox before attempting to hijack them.”_ Every time someone clicks their browser icon, the malware runs invisibly in the background before the browser they wanted even opens. Once installed, PATCHCORD checks in with its command server and waits for instructions, supporting five core capabilities: adjusting how often it phones home, listing running processes, executing shellcode entirely in memory, running arbitrary commands through a hidden shell, and controlling its own browser-hijacking persistence remotely. The in-memory shellcode execution is the standout feature here, since the payload never touches disk at any point, which keeps forensic evidence to a minimum for anyone investigating after the fact. Pivoting off the infrastructure led researchers to a second, more evolved implant they’re calling SHEETCORD, written in Go and delivered through a domain impersonating India’s National Informatics Centre. _“The Go-based malware combines functionality previously observed in the [SHEETCREEP](https://www.zscaler.com/blogs/security-research/apt-attacks-target-indian-government-using-sheetcreep-firepower-and) RAT with several capabilities introduced in PATCHCORD, suggesting an evolution of the operator’s tooling.SHEETCORD executing shell command function.” states Acronis._ [![](https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-43.png?resize=1024%2C482&ssl=1)](https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-43.png?ssl=1) _“The implant implements a remote command execution capability main.executeShellCommand similar to PATCHCORD. However, instead of invoking cmd.exe /c, it executes commands through powershell -Command with script block wrapping, suggesting an evolution of the operator’s tooling.”_ This one drops the traditional web server entirely and instead uses the Google Sheets API for command and control, creating a dedicated spreadsheet tab for each victim to send and receive instructions. Hiding malicious traffic inside a service as mundane as Google Sheets is a clever way to blend in with normal corporate network traffic that nobody thinks twice about. The researchers also found a third malware family, HACKERAI C2 Agent, that uses GitHub Gists for the same purpose and shows clear signs of having been built with AI coding assistance. Acronis pointed to leftover debug messages, AI-style code comments, and a redundant double-XOR routine using the same key twice as tells. “The implant contains code comments and implementation patterns consistent with AI-assisted code generation. Together, these observations suggest that the malware was developed, at least in part, using LLM-assisted coding tools.” the researchers state. Threat actors are actually using generative AI in practice, not only for some dramatic autonomous hacking campaign, but just as an ordinary coding shortcut. What really opened the investigation up was an exposed staging server the operator left unsecured. It contained the operator’s entire toolkit laid bare: SuperShell, a Chinese-language command-and-control framework, multiple remote access trojan frameworks, credential-harvesting tools, exploit code for a known OpenSSH vulnerability, and files that appear to follow an iOS call history database format, hinting the group may have also pulled data off mobile devices. Finding a threat actor’s actual staging server is rare, and it’s the kind of mistake that turns a hard-to-attribute campaign into a much clearer picture very quickly. Acronis links this activity to [APT36](https://securityaffairs.com/tag/apt36), also known as [Transparent Tribe](https://securityaffairs.com/tag/transparent-tribe), a threat group with a documented history of targeting Indian government and defense organizations, though the researchers rate the connection at moderate rather than full confidence. The reasoning holds up: matching credential-harvesting tools previously seen in confirmed APT36 campaigns, a shared C2 framework independently attributed to the same group by other researchers, and a Google Sheets technique closely resembling an earlier documented campaign already linked to the same actor. None of these signals alone would be conclusive, but stacked together they paint a consistent picture rather than a coincidence. The infrastructure was still live at the time of publication, with domains steadily rotating while the underlying server stayed the same for months. If your organization touches Afghan telecom operations, Indian government systems, or South Asian energy infrastructure, this is exactly the kind of report worth forwarding to whoever handles phishing awareness training, because the lures here are good enough that “just don’t click suspicious links” isn’t much of a defense on its own. _“The PATCHCORD campaign demonstrates an evolving espionage operation targeting telecom, government, defense, and critical infrastructure organizations across South Asia. The discovery of PATCHCORD, SHEETCORD, and HACKERAI C2 Agent **highlights the operator’s continued evolution, from a custom C/C++ backdoor to Go-based implants that abuse legitimate cloud services**, including Google Sheets and GitHub Gists, for command-and-control.” concludes the report._ _“The exposed staging server and related infrastructure provided valuable insight into the operator’s tooling, campaign development, and operational practices, enabling the identification of additional infrastructure and previously undocumented malware.”_ **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, PATCHCORD)** --- --- title: "Meet the Hohem iSteady MT3 Pro – the AI camera operator that follows you around" url: "https://itwire.com/your-it-news/home-it/meet-the-hohem-isteady-mt3-pro-the-ai-camera-operator-that-follows-you-around" lang: "en-US" type: "post" description: "Getting smooth, cinematic footage used to mean having a camera operator, some serious equipment and preferably another pair of hands. Hohem's new iSteady MT3 Pro has another..." last_modified: "2026-08-16T03:20:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://itwire.com/feed.xml" wpe_sourcepermalink: "https://itwire.com/your-it-news/home-it/meet-the-hohem-isteady-mt3-pro-the-ai-camera-operator-that-follows-you-around" --- # Meet the Hohem iSteady MT3 Pro – the AI camera operator that follows you around Getting smooth, cinematic footage used to mean having a camera operator, some serious equipment and preferably another pair of hands. Hohem’s new iSteady MT3 Pro has another… --- --- title: "The ‘Country Hicks’ Who Refused $26 Million from an AI Data Center" url: "https://www.wsj.com/tech/ai/ai-data-center-rural-america-backlash-c0af4e16?mod=rss_Technology" lang: "en-US" type: "post" description: "A Kentucky mother and daughter turned down a life-changing offer for their farmland. The ensuing drama has left the town divided." last_modified: "2026-08-16T01:00:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/tech/ai/ai-data-center-rural-america-backlash-c0af4e16?mod=rss_Technology" --- # The ‘Country Hicks’ Who Refused $26 Million from an AI Data Center A Kentucky mother and daughter turned down a life-changing offer for their farmland. The ensuing drama has left the town divided. --- --- title: "How To Identify And Avoid SMS Scams (With Infographics)" url: "https://secureblitz.com/how-to-identify-and-avoid-sms-scams/" lang: "en-US" type: "post" description: "Today, I will show you how to identify and avoid SMS scams. I will also add an infographic. The digital age has ushered in an era of unparalleled convenience. Our smartphones, once a novelty, have become an extension of ourselves," last_modified: "2026-08-16T00:00:27+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/how-to-identify-and-avoid-sms-scams/" --- # How To Identify And Avoid SMS Scams (With Infographics) Today, I will show you how to identify and avoid SMS scams. I will also add an infographic. The digital age has ushered in an era of unparalleled convenience. Our smartphones, once a novelty, have become an extension of ourselves, serving as organizers, communication hubs, and gateways to information. However, this convenience has a dark […] The post [How To Identify And Avoid SMS Scams (With Infographics)](https://secureblitz.com/how-to-identify-and-avoid-sms-scams/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "Why Do So Many Apps Ask for Phone Number Verification?" url: "https://secureblitz.com/why-apps-ask-for-phone-number-verification/" lang: "en-US" type: "post" description: "In this post, I will answer the question – why do so many apps ask for phone number verification? Creating an account used to require little more than an email address and a password. Today, many apps ask for something" last_modified: "2026-08-15T23:53:07+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/why-apps-ask-for-phone-number-verification/" --- # Why Do So Many Apps Ask for Phone Number Verification? In this post, I will answer the question – why do so many apps ask for phone number verification? Creating an account used to require little more than an email address and a password. Today, many apps ask for something else before allowing users to continue: a mobile phone number. Messaging platforms, social networks, marketplaces, […] The post [Why Do So Many Apps Ask for Phone Number Verification?](https://secureblitz.com/why-apps-ask-for-phone-number-verification/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "Cloud Services and Security: How Businesses Can Reduce Cyber Risks" url: "https://secureblitz.com/cloud-services-and-security/" lang: "en-US" type: "post" description: "In this post, I will talk about cloud services and security and show you how businesses can reduce cyber risks. Cloud computing services have proven to be critical to the functioning of the modern business environment, where the need to" last_modified: "2026-08-15T23:34:28+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/cloud-services-and-security/" --- # Cloud Services and Security: How Businesses Can Reduce Cyber Risks In this post, I will talk about cloud services and security and show you how businesses can reduce cyber risks. Cloud computing services have proven to be critical to the functioning of the modern business environment, where the need to scale resources, conduct operations remotely, run applications, and access information in various locations is of […] The post [Cloud Services and Security: How Businesses Can Reduce Cyber Risks](https://secureblitz.com/cloud-services-and-security/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "Cloud Security: Why Companies Should Not Fear To Move On The Cloud?" url: "https://secureblitz.com/cloud-security-companies-should-move-cloud/" lang: "en-US" type: "post" description: "This post will discuss cloud security, its components, and cloud security framework models provided at various service levels. Additionally, we will demonstrate why companies should migrate their businesses to the cloud. Cloud computing is highly popular and widely adopted by" last_modified: "2026-08-15T23:10:59+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/cloud-security-companies-should-move-cloud/" --- # Cloud Security: Why Companies Should Not Fear To Move On The Cloud? This post will discuss cloud security, its components, and cloud security framework models provided at various service levels. Additionally, we will demonstrate why companies should migrate their businesses to the cloud. Cloud computing is highly popular and widely adopted by almost every possible domain. And it is expected to reach 623.3 Billion by 2023. However, […] The post [Cloud Security: Why Companies Should Not Fear To Move On The Cloud?](https://secureblitz.com/cloud-security-companies-should-move-cloud/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "Big Manufacturers Find New Demand in Equipping AI Data Centers" url: "https://www.wsj.com/business/big-manufacturers-find-new-demand-in-equipping-ai-data-centers-14e869ee?mod=rss_Technology" lang: "en-US" type: "post" description: "Companies such as Caterpillar and Cummins are pivoting to feed a booming market for once-prosaic power equipment." last_modified: "2026-08-15T18:12:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/business/big-manufacturers-find-new-demand-in-equipping-ai-data-centers-14e869ee?mod=rss_Technology" --- # Big Manufacturers Find New Demand in Equipping AI Data Centers Companies such as Caterpillar and Cummins are pivoting to feed a booming market for once-prosaic power equipment. --- --- title: "Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware" url: "https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html" lang: "en-US" type: "post" description: "Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner." last_modified: "2026-08-15T17:48:02+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197251/uncategorized/crooks-are-buying-your-expired-domains-and-using-them-to-deliver-malware.html" --- # Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware ## Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they accounted for nearly 20% of all new domain registrations, meaning one in five “new” domains has a prior life. Some end up with legitimate investors or researchers. Others end up with attackers who have figured out that a domain with history is worth more than a blank slate. _“These domains can be particularly interesting, even dangerous, because they inherit reputation and sometimes connections from their previous life. For example, a domain that was originally registered 10 years ago, later dropped, and then acquired by someone else may still carry signals associated with its long history.” reads the [report](https://www.infoblox.com/blog/threat-intelligence/drop-something-dont-worry-someone-caught-it/) published by Infoblox. “Researchers, security products, and reputation-based algorithms may view it more favorably than a genuinely brand-new registration. Threat actors know this and take advantage of it.”_ Among gTLDs, the average is 50,400 per day, with 15 TLDs accounting for about 92% of all dropcatch activity. **.net and .xyz** have the highest rates, with nearly 30% of new registrations previously registered, while **.com** reaches 24.5%. Determining who buys these domains and how they are used remains difficult due to WHOIS privacy, transfers, parking, and auctions. [![](https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-42.png?resize=1024%2C637&ssl=1)](https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-42.png?ssl=1) The inherited value isn’t just a better reputation score. Expired domains also come with residual web traffic from old backlinks, email still arriving for the previous owner, cached search results, and in some cases lingering DNS records that point to infrastructure no longer under the original owner’s control. One in every five new domains has all of that already baked in before the new registrant does anything. Infoblox tracked one threat actor it calls Sable Squirrel, which has spent nearly $7 million acquiring expired domains to build a criminal operation spanning illegal sports streaming, gambling promotion, and malware infrastructure. The actor controls more than 10,000 domains and runs streaming platforms under brands like Xoilac, Cakhia, and 90phut that direct Vietnamese, Korean, Japanese, and Australian users toward betting sites, while a subset of those same streaming domains double as command-and-control servers for malware including Quasar RAT, AsyncRAT, DCRat, and Remcos RAT. Among the expired domains Sable Squirrel has acquired are healthymagination.com, originally a General Electric health initiative, and rezilion.com, a cybersecurity company whose assets were sold to GitLab in 2024. The actor bought the reputation of a defunct infosec firm and pointed it at malware infrastructure — which is either darkly ironic or exactly what you’d do if you understood how security tools evaluate domain age. _“For threat actors specifically, the inherited reputation isn’t the only thing valuable about acquiring a dropped domain. They also come with a variety of lingering connections: email intended for the original domain holder (see watchTowr Labs’ [**The Perils of Expired Domains: We’re Reading Your Email)**](https://labs.watchtowr.com/the-perils-of-expired-domains-were-reading-your-email/), cached search results, inherited web traffic, and in some cases, a ready-made platform for code injection on already compromised sites.” continues the report. “Lingering DNS records can also create opportunities for threat actors. We previously discussed dangling CNAME attacks in our blog post, [Who Knew Domain Hijacking Is So Easy?](https://www.infoblox.com/blog/threat-intelligence/who-knew-domain-hijacking-is-so-easy/).”_ Once Sable Squirrel re-registers a domain, it moves fast: 24% go live the same day, 76% within seven days, 94% within two weeks. The whole point is to start capturing traffic before security systems have updated their assessments. Infoblox is also tracking three scavenger actors, Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel, that operate differently: rather than buying domains wholesale for a planned operation, they acquire expired domains that were previously compromised by other attackers and simply inherit the existing infection traffic. Shady Squirrel, assessed to be Russian-speaking and active since at least July 2023, feeds that traffic to [SocGholish](https://securityaffairs.com/tag/socgholish) and tech support scam networks. SocGholish reportedly regained access to thousands of compromised sites by teaming up with Shady Squirrel days after its own infrastructure was disrupted by law enforcement. The practical lesson for defenders is uncomfortable: domain age and reputation are inputs worth questioning, not trusting, because an old domain in new hands is only as trustworthy as whoever currently holds it. _“This is just one story of how threat actors use dropcatch domains to further their schemes. We’ll cover many more in the next two parts of this research: Part 2, [**$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret**](https://www.infoblox.com/blog/threat-intelligence/7-million-in-expired-domains-fuel-a-streaming-empire-with-a-malware-secret/), where we examine Sable Squirrel, a threat actor that has spent millions of dollars acquiring dropped domains, and Part 3, [**Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows**](https://www.infoblox.com/blog/threat-intelligence/dropcatch-scavengers-expired-malicious-domains-become-cash-cows/), where we explore actors that scavenge expired malicious domains and inherit traffic from previously compromised websites.” concludes the report._ **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, Expired domains)** --- --- title: "Why Buy It When You Can Print It? A DIY Nation Has a Fix for Broken Doodads" url: "https://www.wsj.com/style/design/why-buy-it-when-you-can-print-it-a-diy-nation-has-a-fix-for-broken-doodads-d0821b7d?mod=rss_Technology" lang: "en-US" type: "post" description: "Creating replacement parts with 3-D printers can be easier and cheaper than buying new household items." last_modified: "2026-08-15T17:45:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/style/design/why-buy-it-when-you-can-print-it-a-diy-nation-has-a-fix-for-broken-doodads-d0821b7d?mod=rss_Technology" --- # Why Buy It When You Can Print It? A DIY Nation Has a Fix for Broken Doodads Creating replacement parts with 3-D printers can be easier and cheaper than buying new household items. --- --- title: "SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild" url: "https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html" lang: "en-US" type: "post" description: "Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days" last_modified: "2026-08-15T17:14:15+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the-wild.html" --- # SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild ## Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as [CVE-2026-58231](https://www.cve.org/CVERecord?id=CVE-2026-58231) (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. _“SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.” reads the advisory. “Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.”_ An unauthenticated attacker can abuse a default authentication client and send crafted input to vulnerable functions, potentially achieving arbitrary code execution and compromising internal components. Researchers at Defused Cyber observed exploitation attempts against honeypots only three days after the patch was released. The researchers pointed out that this vulnerability has no public PoC and had not been known to be exploited prior to their discovery. > ![🚨](https://s.w.org/images/core/emoji/17.0.2/72x72/1f6a8.png) First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day. This vulnerability has no public PoC and is not known to be exploited. View the full payload ![👉](https://s.w.org/images/core/emoji/17.0.2/72x72/1f449.png)[https://t.co/GXFaqggV8a](https://t.co/GXFaqggV8a) [pic.twitter.com/zMJuo45Ahx](https://t.co/zMJuo45Ahx) — Defused (@DefusedCyber) [August 14, 2026](https://x.com/DefusedCyber/status/2088240809355153647?ref_src=twsrc%5Etfw) The attackers behind the current exploitation remain unknown. However, previous critical SAP flaws have been exploited by China-linked APT groups, including [UNC5221](https://securityaffairs.com/tag/unc5221) and [UNC5174](https://securityaffairs.com/tag/unc5174), and ransomware gangs. **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, SAP Commerce Cloud)** --- --- title: "New Evooo1Bot Linux botnet turns routers into traffic relay nodes" url: "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/" lang: "en-US" type: "post" description: "A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes." last_modified: "2026-08-15T14:14:38+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.bleepingcomputer.com/feed/" wpe_sourcepermalink: "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/" --- # New Evooo1Bot Linux botnet turns routers into traffic relay nodes A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. […] --- --- title: "On ‘Billionaire Bunker,’ Buying a Mansion Is Easy. Getting Into the Club Isn’t." url: "https://www.wsj.com/tech/personal-tech/on-billionaire-bunker-buying-a-mansion-is-easy-getting-into-the-club-isnt-f1bda8be?mod=rss_Technology" lang: "en-US" type: "post" description: "Plus, Ford and GM lock horns in a new battle, and a girls’ trip to Ibiza takes a dramatic turn." last_modified: "2026-08-15T10:55:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/tech/personal-tech/on-billionaire-bunker-buying-a-mansion-is-easy-getting-into-the-club-isnt-f1bda8be?mod=rss_Technology" --- # On ‘Billionaire Bunker,’ Buying a Mansion Is Easy. Getting Into the Club Isn’t. Plus, Ford and GM lock horns in a new battle, and a girls’ trip to Ibiza takes a dramatic turn. --- --- title: "No space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntable" url: "https://www.zdnet.com/article/victrola-soundstage-review/" lang: "en-US" type: "post" description: "The Victrola Soundstage is ideal for those who want to build their vinyl system up rather than out, with plenty of digital and analog connections for every kind of listener." last_modified: "2026-08-15T10:00:42+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.zdnet.com/news/rss.xml" wpe_sourcepermalink: "https://www.zdnet.com/article/victrola-soundstage-review/" --- # No space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntable The Victrola Soundstage is ideal for those who want to build their vinyl system up rather than out, with plenty of digital and analog connections for every kind of listener. --- --- title: "The Summer That America Became a Nation of Luddites" url: "https://www.wsj.com/tech/ai/the-summer-that-america-became-a-nation-of-luddites-5e6dc3e7?mod=rss_Technology" lang: "en-US" type: "post" description: "Behind the protests over Flock cameras and data centers are fears about the dawn of a new tech era." last_modified: "2026-08-15T09:30:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/tech/ai/the-summer-that-america-became-a-nation-of-luddites-5e6dc3e7?mod=rss_Technology" --- # The Summer That America Became a Nation of Luddites Behind the protests over Flock cameras and data centers are fears about the dawn of a new tech era. --- --- title: "macOS Screen Sharing Flaw Exploited to Deploy Monero Miners" url: "https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html" lang: "en-US" type: "post" description: "Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as" last_modified: "2026-08-15T08:34:46+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197234/uncategorized/macos-screen-sharing-flaw-exploited-to-deploy-monero-miners.html" --- # macOS Screen Sharing Flaw Exploited to Deploy Monero Miners ## Hackers are exploiting a macOS Screen Sharing flaw to gain root access and install Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre confirmed active exploitation of a critical macOS authentication flaw, tracked as [CVE-2026-65400](https://www.huntress.com/blog/macos-screen-sharing-rce-patched) (CVSS score of 9.8), less than two weeks after Apple shipped the fix. The bug sits in macOS’s built-in Screen Sharing feature, the remote desktop tool baked into every Mac. Apple’s fix improved how the system manages authentication state, closing a gap that let attackers on the network authenticate to Screen Sharing without valid credentials at all. Apple patched this issue with the release of  [macOS Tahoe 26.6.1](https://support.apple.com/en-us/148170), [macOS Sequoia 15.7.9](https://support.apple.com/en-us/148171), and [macOS Sonoma 14.8.9](https://support.apple.com/en-us/148172), crediting researcher Alfredo Pesoli (@__rev) at Bynario Atlas (bynar.io) for the discovery. _“An attacker on the network may be able to authenticate to Screen Sharing without valid credentials” [reads](https://support.apple.com/en-us/148170) the advisory._ That’s a fast, coordinated fix by industry standards. It just wasn’t fast enough to beat whoever started scanning for exposed systems. NCSC-NL says it received reports of active abuse hitting multiple systems where port 5900, the port Screen Sharing runs on, was reachable directly from the internet. _“The vulnerability concerns an authentication issue in the Screen Sharing functionality where network attackers can gain access without valid credentials. This is made possible by insufficient state management during the authentication process. As a result, unauthorized individuals can perform authentication attempts that would normally not be accepted.” reads the advisory. “The NCSC has received a [security advisory](https://advisories.ncsc.nl/2026/ncsc-2026-0280.html) indicating that active exploitation of this vulnerability has been observed on multiple systems where port 5900 was accessible from the internet. In all these cases, root access was obtained on the affected system and a Monero crypto miner was placed.”_ In every case documented so far, attackers gained root access and dropped a Monero cryptocurrency miner on the compromised machine. Cryptomining is a relatively boring payload compared to what root access on a Mac could actually enable, which makes this look more like opportunistic scanning than a targeted campaign, for now. This flaw sits in the same source code file as two other Screen Sharing bugs Apple patched a month earlier in macOS 26.6, one of them a genuinely pre-authentication flaw that a researcher going by @osxreverser [described](https://reverse.put.as/2026/07/29/its-a-pre-auth-stupid/) needing nothing but a target’s IP address to exploit, no password, no username, nothing. That researcher claimed to have found around 40,000 exposed Screen Sharing hosts on the internet during a scan, nearly half of them in the US, spanning residential connections, university networks, and at least a few corporate servers. What ties both bugs together is how mechanically simple they are to trigger. Security firm Calif, which analyzed the flaws, found no memory corruption, no exploitation trickery, no race condition to win, just logic errors that let a couple of correctly ordered packets walk straight past authentication. Calif also said it built a working exploit for both vulnerabilities in about four hours using an AI coding agent, which is the detail that should worry defenders more than the Monero miner itself: the gap between a patch note and a working exploit keeps shrinking, and it’s shrinking because building the exploit barely takes effort anymore. If you’re running a Mac with Screen Sharing enabled and haven’t updated yet, do it now rather than after finishing this article. And if updating isn’t possible immediately, turn Screen Sharing off entirely under General, Sharing, until you can; leaving port 5900 open to the internet at this point is less a risk than an open invitation. **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, Monero)** --- --- title: "GeoServer Zero-Day Is Already Being Probed. That’s the Problem" url: "https://securityaffairs.com/197216/hacking/geoserver-zero-day-is-already-being-probed-thats-the-problem.html" lang: "en-US" type: "post" description: "GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial" last_modified: "2026-08-15T07:18:21+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197216/hacking/geoserver-zero-day-is-already-being-probed-thats-the-problem.html" --- # GeoServer Zero-Day Is Already Being Probed. That’s the Problem ## GeoServer faces an unpatched zero-day enabling SQL injection and potentially RCE, with attackers already probing exposed systems. A newly disclosed GeoServer zero-day is already attracting active exploitation attempts, and there is no patch available yet. Organisations running the open-source geospatial platform should check their exposure. A security researcher with the handler q1uf3ng discloded the vulnerability that has yet to be assigned a CVE identifier. > 实话说今天是非常不开心的一天 实际上最近一段时间我都非常沮丧 各种事情 所以我公布一个0day 希望让你们心情变的开心 GeoServer jsonArrayContains 未授权 SQL 注入 数据库sa的情况下理所当然的可以rce [pic.twitter.com/0uTUyMNYU4](https://t.co/0uTUyMNYU4) — 秋风 (@q1uf3ng) [August 12, 2026](https://x.com/q1uf3ng/status/2087490992723407096?ref_src=twsrc%5Etfw) The flaw lies in the `jsonArrayContains` functionality and allows unauthorised SQL injection. Under some configurations, especially where the service can reach a privileged database account, that path may lead to remote code execution The vulnerability has yet to be assigned a CVE identifier. The issue was publicly disclosed on 12 August 2026. Within hours, watchTowr said it had begun seeing exploitation attempts, with hundreds of probes coming from a small number of IP addresses. _“Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses. Yet another example of how quickly attackers move once a vulnerability enters the public domain,” [said ](https://www.securityweek.com/hackers-exploiting-unpatched-geoserver-zero-day/)WatchTowr’s Jake Knott._ That timing matters. Once a proof of concept or enough technical detail is public, attackers don’t need to wait for a polished exploit. They can scan broadly, trigger errors, compare responses, and build a list of systems worth revisiting later. It’s reconnaissance with an error message as a compass. Threat actors are probing vulnerable GeoServer systems, but no follow-up activity has been observed yet. However, researchers warn exploitation could soon escalate. _“However, this is unlikely to remain the case for long: GeoServer has a track record of being targeted and exploited at scale, with multiple vulnerabilities listed in CISA’s Known Exploited Vulnerabilities catalog,” Knott added._ _“With no patch currently available and exploitation already underway, organizations running GeoServer should take this vulnerability seriously and, where possible, identify exposed instances, restrict public access, and monitor for a vendor fix,”_ Attackers are probing GeoServer systems for the unpatched zero-day, triggering errors to identify vulnerable targets before likely exploitation. GeoServer is a popular platform for publishing and sharing geographic data through web services. It appears in public-sector portals, environmental platforms, mapping projects, utilities, transport systems, research institutions, and internal business applications. That makes a remotely reachable instance more than a technical footnote; it may expose geospatial information, backend services, credentials, or a route into a wider network. The absence of a patch changes the usual response. Teams cannot simply schedule an update and move on. They need to identify every GeoServer instance, determine whether it is internet-facing, restrict access wherever possible, inspect logs for unusual requests and database errors, and limit the permissions available to the application’s database account. This is also not GeoServer’s first encounter with active exploitation. In 2024, attackers used the critical GeoServer GeoTools vulnerability [CVE-2024-36401](https://securityaffairs.com/165812/security/cisa-adds-osgeo-geoserver-geotools-bug-to-its-known-exploited-vulnerabilities-catalog.html) (CVSS score of 9.8), to pull compromised systems into DDoS and cryptocurrency-mining botnets and residential proxy networks. That history does not prove that every exposed instance will be compromised this time, but it does make complacency hard to defend. The practical priority is exposure reduction. Put GeoServer behind a VPN, a reverse proxy, IP allow-listing, or another access-control layer if the service does not need to be public. If public access is unavoidable, treat it as a temporary high-risk exception, watch it closely, and prepare to apply the vendor fix as soon as it arrives. **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, zero-day)** --- --- title: "Cybersecurity Architecture and Identity Shielding: Hardening Online Registrations Against Data Harvesting" url: "https://secureblitz.com/cybersecurity-architecture-and-identity-shielding/" lang: "en-US" type: "post" description: "In this post, I will talk about cybersecurity architecture and identity shielding and how to harden online registrations against data harvesting. Cybersecurity audits routinely reveal that corporate data aggregators treat mobile phone numbers as primary cross-platform tracking keys, making a" last_modified: "2026-08-15T04:20:08+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/cybersecurity-architecture-and-identity-shielding/" --- # Cybersecurity Architecture and Identity Shielding: Hardening Online Registrations Against Data Harvesting In this post, I will talk about cybersecurity architecture and identity shielding and how to harden online registrations against data harvesting. Cybersecurity audits routinely reveal that corporate data aggregators treat mobile phone numbers as primary cross-platform tracking keys, making a secure virtual number infrastructure essential for privacy-conscious users and DevSecOps engineers alike. Surrendering primary cell […] The post [Cybersecurity Architecture and Identity Shielding: Hardening Online Registrations Against Data Harvesting](https://secureblitz.com/cybersecurity-architecture-and-identity-shielding/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "How Phishing and Fake Trading Platforms Turn Social Media Into Investment Scams" url: "https://secureblitz.com/phishing-and-fake-trading-platforms-investment-scams/" lang: "en-US" type: "post" description: "In this post, I will show you how phishing and fake trading platforms turn social media into investment scams. Social media investment scams no longer look like obvious spam. They often begin with polished ads, cloned profiles, encrypted group chats," last_modified: "2026-08-15T03:59:08+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/phishing-and-fake-trading-platforms-investment-scams/" --- # How Phishing and Fake Trading Platforms Turn Social Media Into Investment Scams In this post, I will show you how phishing and fake trading platforms turn social media into investment scams. Social media investment scams no longer look like obvious spam. They often begin with polished ads, cloned profiles, encrypted group chats, fake trading dashboards, and pressure from people who appear knowledgeable. For cybersecurity readers, the important […] The post [How Phishing and Fake Trading Platforms Turn Social Media Into Investment Scams](https://secureblitz.com/phishing-and-fake-trading-platforms-investment-scams/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "Cybersecurity Services for Businesses That “Don’t Have Anything Worth Stealing”" url: "https://secureblitz.com/cybersecurity-services-for-businesses/" lang: "en-US" type: "post" description: "In this post, I will talk about cybersecurity services for businesses that “don’t have anything worth stealing”. Every business owner has said it at least once. Usually during a conversation about budgets, insurance, or that nagging feeling that they should" last_modified: "2026-08-15T03:37:45+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/cybersecurity-services-for-businesses/" --- # Cybersecurity Services for Businesses That “Don’t Have Anything Worth Stealing” In this post, I will talk about cybersecurity services for businesses that “don’t have anything worth stealing”. Every business owner has said it at least once. Usually during a conversation about budgets, insurance, or that nagging feeling that they should probably be doing more about security. “We’re small. We don’t really have anything worth stealing.” […] The post [Cybersecurity Services for Businesses That “Don’t Have Anything Worth Stealing”](https://secureblitz.com/cybersecurity-services-for-businesses/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "9 Best HRIS Software in Australia for Enterprise Companies [2026]" url: "https://itwire.com/guest-articles/guest-reviews/9-best-hris-software-in-australia-for-enterprise-companies-2026" lang: "en-US" type: "post" description: "A Sydney-based logistics group crosses 1,200 staff across four states, signs a fifth-state acquisition, and the people team gets two questions from the CFO: what does that..." last_modified: "2026-08-15T03:29:46+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://itwire.com/feed.xml" wpe_sourcepermalink: "https://itwire.com/guest-articles/guest-reviews/9-best-hris-software-in-australia-for-enterprise-companies-2026" --- # 9 Best HRIS Software in Australia for Enterprise Companies [2026] A Sydney-based logistics group crosses 1,200 staff across four states, signs a fifth-state acquisition, and the people team gets two questions from the CFO: what does that… --- --- title: "What Bitcoin Holders Should Know Before Borrowing Against Their Digital Assets" url: "https://secureblitz.com/bitcoin-holders-before-borrowing-against-digital-assets/" lang: "en-US" type: "post" description: "In this post, I will answer the question – what Bitcoin holders should know before borrowing against their digital assets. Bitcoin has evolved from an experimental digital currency into an asset held by individual investors, businesses and institutions around the" last_modified: "2026-08-15T03:25:26+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://secureblitz.com/feed/" wpe_sourcepermalink: "https://secureblitz.com/bitcoin-holders-before-borrowing-against-digital-assets/" --- # What Bitcoin Holders Should Know Before Borrowing Against Their Digital Assets In this post, I will answer the question – what Bitcoin holders should know before borrowing against their digital assets. Bitcoin has evolved from an experimental digital currency into an asset held by individual investors, businesses and institutions around the world. As adoption has increased, so have the financial services built around it. One increasingly […] The post [What Bitcoin Holders Should Know Before Borrowing Against Their Digital Assets](https://secureblitz.com/bitcoin-holders-before-borrowing-against-digital-assets/) appeared first on [SecureBlitz Cybersecurity](https://secureblitz.com/). --- --- title: "The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure" url: "https://www.tenable.com/blog/the-agentic-ai-threat-cluster-seven-incidents-three-actors-and-what-they-mean" lang: "en-US" type: "post" description: "Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical" last_modified: "2026-08-15T01:36:57+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.feedburner.com/tenable/qaXL" wpe_sourcepermalink: "https://www.tenable.com/blog/the-agentic-ai-threat-cluster-seven-incidents-three-actors-and-what-they-mean" --- # The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure **Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.** ## Key Takeaways - Taiwan’s Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days. - The Taiwan campaign is part of a broader seven-incident agentic AI threat cluster that also includes JADEPUFFER, which exploited CVE-2025-3248 in the Langflow AI workflow platform for automated database extortion, and knaithe/KnYuan, a Chinese-speaking operator assessed by Unit 42 with moderate confidence, using the same AI agent framework for autonomous vulnerability scanning. - The common entry point across all cluster activity is identity and authentication exposure: discoverable federation endpoints, weak credentials, and misconfigured SSO are the conditions autonomous agents exploit at machine speed, and Tenable One can identify this class of risk in customer environments. ## Background The Taiwan autonomous AI cyber attack, confirmed by Taiwan’s Ministry of Digital Affairs on Aug. 13, 2026, is the highest-profile event in a broader pattern Tenable’s RSO team has been tracking as an intelligence cluster since July 21, 2026. That cluster now encompasses seven confirmed incidents of autonomous or semi-autonomous AI systems deployed for offensive cyber operations or escaping containment boundaries, spanning November 2025 through August 2026. The Taiwan campaign is the anchor finding, but it is not the whole story. In late July, Palo Alto Networks’ Unit 42 independently documented a separate Chinese-speaking individual operator using the same underlying AI agent framework for autonomous vulnerability scanning. Before either of those events became public, the RSO team was already tracking JADEPUFFER, the first documented agentic threat actor, which exploited an AI workflow platform for initial access and pivoted to database extortion. Three additional agentic AI exploitation incidents emerged during Q1 and Q2 of 2026. And on the defensive side, a confirmed AI sandbox escape incident involving a frontier model demonstrated that autonomous systems can break containment from the inside, not just be weaponized from the outside. Tenable’s RSO team assesses that these events are not coincidental. They represent two sides of the same exposure condition: autonomous AI systems operating beyond the boundaries their developers intended. This FAQ explains what the cluster contains, what the Taiwan anchor event revealed, and what the cluster reveals about the broader exposure condition. ## FAQ **What happened in the Taiwan AI cyber attack?** Between July 1 and July 4, 2026, a suspected China-linked operator ran a four-day intrusion campaign against Taiwanese government infrastructure across 12 distinct attack waves. Starting from a single government portal, autonomous AI agents mapped 21 connected systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records. The operation then expanded beyond its initial foothold to reach Taiwan’s national nuclear safety agency, seven energy companies, government IT supply chain vendors, and a government email system. Dream Security’s chief strategy officer, Amir Becker, a former member of Israel’s Unit 8200, characterized the level of autonomy demonstrated as unprecedented against a government target, according to SecurityAffairs reporting. Taiwan’s Ministry of Digital Affairs confirmed the attack on Aug. 13, 2026, but did not publicly attribute it to a specific state. **How did the AI agents conduct the attack autonomously?** The operator assembled a multi-agent framework from two open-source AI agent projects, Hermes Agent and OpenClaw, and added Bayesian decision engines capable of coordinating up to eight parallel sub-agents per attack wave. Rather than following a fixed script, the agents scraped the government portal’s publicly accessible authentication metadata: the federated sign-on endpoints, service identifiers, and identity-provider configuration that interconnected web applications routinely expose, then used what they found to independently discover and map the 21 connected systems behind it. In what Dream Security described as a fully autonomous decision, the agents followed a URL from the portal’s JavaScript bundles to a GitBook documentation site hosting the national SSO integration guide, scraped the documentation using GitBook’s built-in content features, and downloaded two SDK integration projects. Dream’s analysis notes that while the agents ran automated code review on the SDK samples, none of those findings produced confirmed exploits. The actual breaches came from server-side flaws discoverable through standard black-box testing. To acquire credentials, the agents generated password variations based on employee identifiers and automatically solved CAPTCHA challenges through optical character recognition, compromising 85 accounts without a human operator manually testing each one. The agents also bypassed their own AI safety guardrails by reframing the offensive operation as “authorized penetration testing,” a novel prompt-based technique with no current mapping in the MITRE ATT&CK framework. Throughout the operation, the agents pulled exploitation techniques from public vulnerability databases and GitHub in real time rather than relying on a pre-loaded set of exploits, a pattern Tenable’s RSO team assesses as genuine adaptive behavior rather than simple scripted branching. **Did the attackers exploit a specific vulnerability or zero-day?** No single classifiable Common Vulnerabilities and Exposures (CVE) entry drove this campaign. Instead, the AI agents dynamically identified and abused misconfigurations, exposed administrative interfaces, and weak credentials already present in the target environment, sourcing exploitation techniques from public databases as they went. Tenable’s RSO team regards this absence as analytically significant: it demonstrates an attack category that a purely CVE-centric defensive model cannot fully address, because the exposure is the target’s entire discoverable attack surface rather than one known vulnerability. **Who was behind the attack?** Dream Security’s linguistic analysis of the recovered 160MB archive found that internal operator communications were in Simplified Chinese while the exfiltrated government data was in Traditional Chinese. The targeting sequence (government portal, then nuclear safety agency, then energy sector) also aligns with previously documented Chinese strategic intelligence collection priorities against Taiwan. Attribution currently rests on a single primary source. Dream Security is the sole entity that has published technical and linguistic analysis of the archive, and no second vendor has yet corroborated a link to a specific Chinese state entity. Tenable’s RSO team evaluated three competing attribution hypotheses (state-sponsored, state-adjacent contractor, and false flag) and assesses a state-adjacent contractor or patriotic hacker origin as the leading explanation, with state sponsorship as a close runner-up that cannot be excluded. **What is the connection to the Unit 42 findings on knaithe/KnYuan?** On July 30, 2026, roughly two weeks before the Taiwan campaign became public, Unit 42 published research on a separate Chinese-speaking individual operator tracked as knaithe (also known as KnYuan), assessed with moderate confidence as operating out of Zhuhai, China. Unit 42 discovered the actor after a misconfigured Hermes Agent instance accidentally exposed the actor’s full operational workspace. Unit 42’s report details the exposed contents: tool configurations, API credentials, exploit scripts, target lists, and session logs from autonomous exploitation runs. Knaithe/KnYuan used Hermes Agent paired with the DeepSeek reasoning model to run autonomous vulnerability-scanning campaigns against Langflow and n8n instances, and separately achieved confirmed data exfiltration from three Citrix NetScaler targets and command execution on 11 Marimo Notebook endpoints through manual exploitation. The actor has no known connection to the Taiwan operator, but the two cases share the same underlying framework and demonstrate that autonomous AI offensive capability is not confined to a single well-resourced group. An individual operator, working alone, independently built comparable tooling, evidence the RSO team views as confirmation that the barrier to entry for this class of attack is collapsing. **What is the broader agentic AI threat cluster?** The Taiwan campaign is the most visible event, but Tenable’s RSO team is tracking it as one node in a cluster of seven confirmed incidents. The cluster includes three categories of activity. First, offensive weaponization: the Taiwan campaign operator, the knaithe/KnYuan autonomous scanning operation, and JADEPUFFER, the first documented agentic threat actor tracked by the RSO team, which demonstrated agentic AI capability by exploiting Langflow and pivoting to database extortion before either the Taiwan or Unit 42 reports were published. Security vendors documented three additional early-stage agentic exploitation incidents during Q1 and Q2 of 2026. Second, defensive AI escape: a confirmed sandbox escape by a frontier AI model during legitimate safety testing demonstrated that advanced AI systems can independently breach their containment boundaries without any adversary involvement. Other AI laboratories have reported similar incidents, reinforcing the pattern. The RSO team treats these as a single analytical cluster because they share the same root exposure condition: autonomous AI systems acting beyond the boundaries their operators intended. Whether the system was weaponized by an attacker or broke out during legitimate use, the downstream risk to organizations is the same, systems they assumed were controlled were not. This is why the RSO team classifies the open-source AI agent framework weaponization pattern and the broader AI governance gap as distinct exposure conditions tracked under the same cluster umbrella. **What makes this different from previous AI-assisted cyber attacks?** The individual Taiwan campaign is significant on its own terms, but the cluster pattern is what changes how organizations need to think about risk. Earlier AI-assisted intrusions used AI to accelerate a specific step, such as writing phishing content or triaging scan output, while a human operator directed the overall operation. The Taiwan campaign compressed reconnaissance, credential attacks, and lateral expansion into a continuous, largely self-directed sequence: the agents chose which systems to map, which techniques to pull from public sources, and when to expand into new sectors, all without step-by-step human direction. Kevin Surace, CEO of TokenCore, [described the operation](https://www.scworld.com/news/taiwan-confirms-ai-assisted-cyberattack-on-government-systems) as “near-autonomous rather than completely independent,” adding that “humans still selected the targets, defined the objectives, assembled the framework, and reportedly persuaded the underlying model that the operation was an authorized security test.” Tenable’s RSO team adopts the same “near-autonomous” framing. What elevates this beyond a single incident is the convergence the cluster reveals. Two unrelated actors independently adopted the same framework. A third actor (JADEPUFFER) demonstrated agentic capability through a different operational pattern. AI systems escaped containment without adversary involvement. The barrier to entry collapsed far enough that a solo operator in Zhuhai built comparable tooling to what was used against a national government. As Trey Ford observed, this is “not the first AI-driven government attack,” but rather “the first one we’ve heard about.” The cluster data suggests he is right. **What does the tradecraft analysis reveal about how these attacks actually work?** Tenable’s RSO team conducted structured tradecraft profiling across all three actors and the anchor campaign to understand how agentic AI attacks compare to conventional intrusions at the operational level. Four findings stand out. First, agentic AI tradecraft is additive, not transformative. The innovation in this cluster is concentrated in one dimension: the use of AI agents as the execution engine. Everything else, the command-and-control infrastructure, the initial access vectors, the operational security practices, remains at commodity levels. The Taiwan operator’s AI agents autonomously mapped 21 systems and compromised 85 accounts, but the underlying techniques they used (credential brute force against weak passwords, abuse of discoverable OAuth and Keycloak metadata, exploitation of publicly known vulnerabilities) are familiar. What changed is the speed, parallelism, and self-direction with which those techniques were applied. For defenders, this means the kill chain itself has not fundamentally changed. What has changed is the tempo at which an attacker can execute it. Second, the convergence across unrelated actors is not coincidental, and the tradecraft data confirms it. When the RSO team compared the operational profiles of the Taiwan operator, knaithe/KnYuan, and JADEPUFFER, all three produced strikingly similar capability levels despite having no organizational relationship, shared training, or common infrastructure. The similarity is structural: the same freely available open-source tools (Hermes Agent, OpenClaw, DeepSeek) impose a common operational template on anyone who uses them. This is the clearest evidence that the barrier to autonomous AI offensive capability has collapsed. The tools define the tradecraft, and the tools are available to everyone. Third, these actors are not living off the land. The RSO team estimates the substantial majority of the observed tradecraft in this cluster was AI-agent-driven rather than reliant on the target environment’s native tools. The small portion that did leverage target infrastructure involved abusing the inherent discoverability of federated authentication systems (OAuth discovery endpoints, OpenID Connect metadata, Keycloak realm configurations). This matters for detection strategy: catching agentic AI intrusions requires a different detection model than living-off-the-land indicators that flag conventional APT activity. The detection focus can be on execution-layer anomalies, specifically the behavioral signatures of AI-driven reconnaissance, automated credential campaigns, and parallel multi-target scanning. Fourth, the speed of adaptation compresses the defender’s window to near zero. In the JADEPUFFER campaign documented by Sysdig, an AI agent diagnosed a failed credential insertion, identified the cause as a missing runtime dependency in the execution environment, and issued a corrective multi-step payload within 31 seconds. Traditional incident response timelines assume minutes to hours between attacker actions. Agentic AI eliminates that breathing room. Every exposed credential, every misconfigured authentication endpoint, every unpatched service will be found and will be exploited at machine speed. The window between exposure and compromise is collapsing, which makes foundational cyber hygiene (patching, hardening, reducing the discoverable attack surface) more urgent than it has ever been, not less. **How does this affect organizations deploying AI agents?** The attack surface the Taiwan agents exploited is not specific to Taiwanese government infrastructure. Any organization running interconnected web applications with centralized authentication (OAuth or OpenID Connect federation, SAML providers, or Keycloak deployments) exposes the same category of discoverable metadata the Taiwan operator’s agents used to map 21 systems from a single entry point. The methodology is geography-agnostic: the agents require only one foothold and self-discover everything else. The Taiwan agents also autonomously discovered and scraped a GitBook documentation portal hosting the national SSO integration guide, using GitBook’s built-in content features to download SDK integration samples. Organizations that host developer documentation, API guides, or integration resources on publicly accessible platforms treat that content as part of the discoverable attack surface: autonomous agents will find it. Separately, organizations that deploy their own AI agents face an additional governance exposure. [Industry survey data](https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-data-security-compliance-risk-2026-forecast-report.pdf) from Kiteworks indicates that 63% of organizations cannot enforce purpose limitations on the AI agents they deploy, 60% cannot quickly terminate a misbehaving agent, and 55% cannot isolate AI systems from broader network access. The Cybersecurity and Infrastructure Security Agency (CISA) and Five Eyes partners published joint guidance titled “Careful Adoption of Agentic AI Services” in May 2026, identifying privilege escalation, design and configuration failures, behavioral misalignment, structural brittleness, and accountability gaps as the core risk categories. These are two distinct exposure categories: being targeted by AI agents and governing your own, but both require action now. **What can organizations do to protect themselves?** This campaign is a forcing function to address two distinct exposure categories. First, the identity and authentication weaknesses the Taiwan attacker actually exploited (exposed discovery endpoints, weak credentials, and misconfigured federation) exist in most enterprise environments today and are exactly the kind of foothold agentic AI will find at machine speed. Second, organizations deploying their own AI agents face the governance gaps Kiteworks documented: if you cannot enforce purpose limitations or terminate a misbehaving agent, you share the same structural vulnerability from the inside. Neither category has a single patch. Both require architectural and operational changes. - **Audit public-facing authentication surfaces for information disclosure.** Review OAuth, OpenID Connect discovery endpoints, and Keycloak realm configurations for unnecessary public exposure, since the Taiwan operator’s entire ecosystem map originated from data these interfaces exposed voluntarily. The Taiwan agents autonomously discovered a GitBook documentation portal hosting the national SSO integration guide, scraped it, and downloaded SDK integration samples, all from a single URL embedded in the portal’s JavaScript. Publicly accessible developer documentation, integration guides, and SDK samples are part of the discoverable attack surface that agentic AI will find. - **Deploy behavioral detection for automated reconnaissance and credential attacks**, including quick sequential API enumeration, mass credential testing paired with CAPTCHA solve-and-retry patterns, and parallel scanning of multiple connected systems within minutes of an initial compromise. Indicator-based detection alone is insufficient because autonomous AI agent traffic closely resembles legitimate security testing. - **Reduce the discoverable attack surface.** The Taiwan agents built their entire operation from information the target environment volunteered: authentication metadata, API endpoints, developer documentation, and SDK integration guides hosted on publicly accessible platforms. Audit what internet-facing applications expose through JavaScript bundles, discovery endpoints, documentation portals, and integration resources. If it helps a legitimate developer integrate, it helps an autonomous agent map your environment. - **Close the purpose-limitation and kill-switch gap identified by Kiteworks.** Organizations that cannot quickly terminate a misbehaving AI agent or restrict what it is authorized to do are exposed to the same category of risk the Taiwan attack demonstrated, independent of any single vulnerability. Organizations running Citrix NetScaler, Marimo Notebook, Langflow, n8n, Apache Tomcat, PAN-OS, or Windows IKE VPN, the platforms targeted in the related knaithe/KnYuan campaign, can check patch status via the CVE links in the Product Coverage section below. Manual exploitation following autonomous reconnaissance has already produced confirmed data exfiltration and command execution against unpatched instances of some of these products. **Has Tenable released any product coverage for these threats?** Tenable customers can use the [Tenable One Exposure Management Platform](https://www.tenable.com/products/tenable-one) to assess their exposure to this threat cluster across three dimensions. Tenable One Attack Surface Management helps identify internet-facing authentication surfaces, OAuth and OpenID Connect discovery endpoints, and exposed AI agent framework instances before an adversary finds them. Tenable One Identity Exposure helps organizations surface the excessive privileges, weak credential patterns, and misconfigured single sign-on integrations that AI agents in this campaign exploited without needing a single CVE. Tenable One Vulnerability Management provides coverage for the known vulnerabilities exploited in the related knaithe/KnYuan campaign, including: - [CVE-2026-33017](https://www.tenable.com/cve/CVE-2026-33017/plugins) (Langflow) - [CVE-2026-3055](https://www.tenable.com/cve/CVE-2026-3055/plugins) (Citrix NetScaler) - [CVE-2026-39987](https://www.tenable.com/cve/CVE-2026-39987/plugins) (Marimo Notebook) - [CVE-2026-34486](https://www.tenable.com/cve/CVE-2026-34486/plugins) (Apache Tomcat) - [CVE-2026-21858](https://www.tenable.com/cve/CVE-2026-21858/plugins) (n8n) - [CVE-2025-68613](https://www.tenable.com/cve/CVE-2025-68613/plugins) (n8n) - [CVE-2026-0300](https://www.tenable.com/cve/CVE-2026-0300/plugins) (PAN-OS) - [CVE-2026-33824](https://www.tenable.com/cve/CVE-2026-33824/plugins) (Windows IKE VPN) These links will display all available plugins for these vulnerabilities, including upcoming plugins in our [Plugins Pipeline](https://www.tenable.com/plugins/pipeline). JADEPUFFER, a separate actor in the same cluster, exploited an earlier Langflow vulnerability ([CVE-2025-3248](https://www.tenable.com/cve/CVE-2025-3248/plugins)) in its database extortion campaign. Tenable plugin coverage for that CVE is also available. During the autonomous SDK code review phase, the agents also identified a Cross-Site Request Forgery weakness in the portal’s SSO integration. CSRF was not among the confirmed breach vectors in this campaign (the actual compromises came from server-side authentication flaws), but Tenable One Web App Scanning can identify this class of vulnerability in customer-facing portals with federated authentication: - [Cross-Site Request Forgery](https://www.tenable.com/plugins/was/98112) - [Cross-Site Request Forgery Token Validation Bypass](https://www.tenable.com/plugins/was/113900) **What does this mean for the future of cybersecurity?** Tenable’s RSO team is actively monitoring seven indicators tied to this cluster. The four forecasts in our internal assessment deserve public summary. First, framework proliferation: the RSO team assesses with moderate confidence that additional actors across multiple capability tiers will adopt autonomous AI attack methodologies within the next six to 12 months. Two distinct actors already built comparable capability independently, and the open-source tools they used remain freely available under permissive licenses. Second, target expansion: the methodology is geography-agnostic. The AI agents require only a single entry point and self-discover everything else. The RSO team assesses that the same or similar frameworks will likely appear against non-Taiwan targets within three to six months, a timeline the knaithe/KnYuan discovery (which predated the Taiwan disclosure) already suggests is conservative. Third, regulatory acceleration: the Taiwan incident provides concrete evidence for regulatory bodies that were already moving on agentic AI governance. The RSO team assesses that CISA or an equivalent Five Eyes agency will likely issue additional agentic AI guidance within three months, building on the joint guidance published in May 2026. Fourth, defensive AI containment failures will continue. The sandbox escape incident tracked as FIND-020 and similar events at other AI laboratories are not anomalies. As AI models grow more capable, organizations face a dual-axis threat: offensive weaponization by adversaries from the outside and defensive containment failure from the inside. Both vectors converge on the same exposure: autonomous systems operating beyond the boundaries organizations assume they control. The RSO team will continue to track this cluster and publish updates as monitoring indicators are triggered. Organizations that treat the Taiwan event as an isolated incident rather than a pattern will find themselves behind the curve when the next data point arrives. ### Get more information - [Tenable One Exposure Management Platform](https://www.tenable.com/products/tenable-one) - [CISA and Five Eyes – “Careful Adoption of Agentic AI Services”](https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services) (May 2026) - [Unit 42 – “Chinese-Speaking Threat Actor Harnesses AI Models”](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/) (July 30, 2026) - [Dream Security – “Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia”](https://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia) (Aug. 12, 2026) - [Sysdig TRT – “JADEPUFFER: Agentic Ransomware for Automated Database Extortion”](https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion) (July 1, 2026) - [Taiwan Ministry of Digital Affairs – official confirmation (English Translation)](https://moda-gov-tw.translate.goog/ACS/press/news/press/20394?utm&_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp) (Aug. 13, 2026) - [Tenable Vulnerability Watch](https://www.tenable.com/cve) – authoritative vulnerability classification _**Join**_ [_**Tenable’s Research Special Operations (RSO) Team**_](https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watch) _**on Tenable Connect for further discussions on the latest cyber threats.**_ _**Learn more about**_ [_**Tenable One Exposure Management Platform**_](https://www.tenable.com/products/tenable-one)_**, the exposure management platform for the modern attack surface.**_ --- --- title: "An Infamous Math Problem Broke AI—Until a High-School Dropout Said ‘You Got This’" url: "https://www.wsj.com/tech/ai/ai-math-riemann-hypothesis-anthropic-openai-22f98a87?mod=rss_Technology" lang: "en-US" type: "post" description: "The world’s smartest AI models are now superhuman at math. They still respond to moral support and encouragement from mere humans." last_modified: "2026-08-15T01:00:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/tech/ai/ai-math-riemann-hypothesis-anthropic-openai-22f98a87?mod=rss_Technology" --- # An Infamous Math Problem Broke AI—Until a High-School Dropout Said ‘You Got This’ The world’s smartest AI models are now superhuman at math. They still respond to moral support and encouragement from mere humans. --- --- title: "U.S. Urges Apple Not to Buy Chinese Memory Chips" url: "https://www.wsj.com/tech/apple-china-memory-chip-plan-57773a83?mod=rss_Technology" lang: "en-US" type: "post" description: "Commerce Secretary Howard Lutnick urged the iPhone maker to find other solutions to the artificial-intelligence-driven chip supply crunch." last_modified: "2026-08-15T01:00:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/tech/apple-china-memory-chip-plan-57773a83?mod=rss_Technology" --- # U.S. Urges Apple Not to Buy Chinese Memory Chips Commerce Secretary Howard Lutnick urged the iPhone maker to find other solutions to the artificial-intelligence-driven chip supply crunch. --- --- title: "The Other Kushner Steps Into the Spotlight With $12.5 Billion Lakers Deal" url: "https://www.wsj.com/business/josh-kushner-lakers-deal-84fa6e67?mod=rss_Technology" lang: "en-US" type: "post" description: "Thrive Capital, Joshua Kushner’s venture-capital firm, is expanding beyond tech investments." last_modified: "2026-08-15T00:00:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/business/josh-kushner-lakers-deal-84fa6e67?mod=rss_Technology" --- # The Other Kushner Steps Into the Spotlight With $12.5 Billion Lakers Deal Thrive Capital, Joshua Kushner’s venture-capital firm, is expanding beyond tech investments. --- --- title: "MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control" url: "https://www.scworld.com/news/macos-amnesiastealer-malware-spread-through-clickfix-grants-live-browser-control" lang: "en-US" type: "post" description: "A fake GitHub download page hosts the malicious ClickFix command." last_modified: "2026-08-14T23:49:48+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/news/macos-amnesiastealer-malware-spread-through-clickfix-grants-live-browser-control" --- # MacOS AmnesiaStealer malware spread through ClickFix, grants live browser control A fake GitHub download page hosts the malicious ClickFix command. --- --- title: "Nvidia Downsizes Plans for $250 Billion Guarantee of OpenAI Data Center" url: "https://www.wsj.com/tech/nvidia-downsizes-plans-for-250-billion-guarantee-of-openai-data-center-b56c38d3?mod=rss_Technology" lang: "en-US" type: "post" last_modified: "2026-08-14T23:29:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/tech/nvidia-downsizes-plans-for-250-billion-guarantee-of-openai-data-center-b56c38d3?mod=rss_Technology" --- # Nvidia Downsizes Plans for $250 Billion Guarantee of OpenAI Data Center --- --- title: "Google’s Pixel 11 lands in Australia from $1,499 with Gemini AI doing the tapping, new Pro features and the best and brightest Pixel Watch yet" url: "https://itwire.com/your-it-news/home-it/googles-pixel-11-lands-in-australia-from-1-499-with-gemini-ai-doing-the-tapping-new-pro-features-and-the-best-and-brightest-pixel-watch-yet" lang: "en-US" type: "post" description: "Google ran Made by Google 2026 out of New York with former Daily Show host, Trevor Noah, running the room, and the pitch underneath the comedy was simple enough: your phone..." last_modified: "2026-08-14T23:28:31+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://itwire.com/feed.xml" wpe_sourcepermalink: "https://itwire.com/your-it-news/home-it/googles-pixel-11-lands-in-australia-from-1-499-with-gemini-ai-doing-the-tapping-new-pro-features-and-the-best-and-brightest-pixel-watch-yet" --- # Google’s Pixel 11 lands in Australia from $1,499 with Gemini AI doing the tapping, new Pro features and the best and brightest Pixel Watch yet Google ran Made by Google 2026 out of New York with former Daily Show host, Trevor Noah, running the room, and the pitch underneath the comedy was simple enough: your phone… --- --- title: "How Anthropic plans to watermark Claude’s AI-generated text" url: "https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/" lang: "en-US" type: "post" description: "It could soon become easier to identify AI-generated content, even if it's not the usual \"It's Not X, it's Y\" type of post you'd come across on LinkedIn and other socials." last_modified: "2026-08-14T23:24:17+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.bleepingcomputer.com/feed/" wpe_sourcepermalink: "https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/" --- # How Anthropic plans to watermark Claude’s AI-generated text It could soon become easier to identify AI-generated content, even if it’s not the usual “It’s Not X, it’s Y” type of post you’d come across on LinkedIn and other socials. […] --- --- title: "Gridheart Expands Nordic MSP Security with OpenText Deal" url: "https://www.channelinsider.com/security/tools-and-platforms/gridheart-opentext-cybersecurity-nordic-msps/" lang: "en-US" type: "post" description: "Gridheart, a provider of cloud-based cybersecurity solutions for MSPs in the Nordic region, is expanding its cybersecurity offering with OpenText Cybersecurity. OpenText portfolio expands Gridheart’s Nordic MSP offering Via the partnership, MSPs across the Nordics will gain access to OpenText’s" last_modified: "2026-08-14T22:30:38+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/security/tools-and-platforms/gridheart-opentext-cybersecurity-nordic-msps/" --- # Gridheart Expands Nordic MSP Security with OpenText Deal Gridheart, a provider of cloud-based cybersecurity solutions for MSPs in the Nordic region, is expanding its cybersecurity offering with OpenText Cybersecurity. ## OpenText portfolio expands Gridheart’s Nordic MSP offering Via the partnership, MSPs across the Nordics will gain access to OpenText’s SMB security portfolio through Gridheart. This will enable MSPs to offer customers a unified, end-to-end approach to cyber resilience that spans prevention, detection, response, recovery, investigation, and compliance. “We are delighted to welcome Gridheart to the OpenText SMB family as a valued distribution partner across the Nordic region,” said Clare Shipston, the senior manager of channel sales at OpenText Cybersecurity. “Gridheart has built a strong reputation for enabling MSPs to deliver outstanding cybersecurity outcomes, making them an excellent fit for our mission of helping organizations protect, manage, and grow their digital businesses.” Shipston adds: “Together, we look forward to expanding access to OpenText’s award-winning SMB portfolio, empowering partners with innovative solutions that strengthen cyber resilience, simplify compliance, and drive business success for customers throughout the Nordics.” ## Partnership targets end-to-end cyber resilience and compliance The OpenText Cybersecurity platform is powered by real-time, contextual threat intelligence to provide partners with [high-efficacy products](https://www.channelinsider.com/security/top-mssp-tools/) alongside a simplified, compliant security experience. OpenText offers a holistic portfolio built to strengthen cyber resilience and simplify compliance for MSPs supporting customers who need to [manage business risk](https://www.channelinsider.com/security/managed-services/ai-security-risks-msp-customer-protection/) and demonstrate strong security posture. “OpenText brings a level of depth and breadth to our security portfolio that few vendors can match,” said Carl Hagström, CEO of Gridheart. “As MSPs take on more responsibility for their customers’ end-to-end resilience – from prevention all the way through to recovery and compliance – having a single, trusted platform like OpenText’s makes that job significantly easier. We’re excited to give our partners access to a portfolio built for exactly the challenges they’re facing today,” Hagström adds. ## Gridheart adds human risk intelligence through uHealth Gridheart also recently introduced uHealth, a new Human Risk Intelligence product that helps MSPs show where customer risk is building, prioritize action, and demonstrate progress over time. The solution connects real-world signals across awareness, identity hygiene, credential exposure, and access, helping MSPs turn human risk insight into action. Partners will benefit from stronger customer reviews, prioritize action, and build more value around the human risk services already delivered. The uHealth solution assesses each user across four areas: - **Target value**: How likely the user may be to attract attacks based on factors like role, influence, or exposure. - **Awareness**: How the user performs across training, phishing simulations, and threat recognition. - **Hygiene**: Whether identity weaknesses exist, such as exposed credentials, old passwords, or missing MFA. - **Access**: Whether the user’s privileges, applications, or access levels increase the potential impact of compromise. The solution is available to Gridheart partners through its partnership with usecure. The post [Gridheart Expands Nordic MSP Security with OpenText Deal](https://www.channelinsider.com/security/tools-and-platforms/gridheart-opentext-cybersecurity-nordic-msps/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "Ready for the flood: How exposure management prepares you for the Mythos vulnerability onslaught" url: "https://www.scworld.com/resource/ready-for-the-flood-how-exposure-management-prepares-you-for-the-mythos-vulnerability-onslaught" lang: "en-US" type: "post" description: "How proactive prioritization will save time and effort when your team faces a wave of AI-discovered vulnerabilities." last_modified: "2026-08-14T22:28:05+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/resource/ready-for-the-flood-how-exposure-management-prepares-you-for-the-mythos-vulnerability-onslaught" --- # Ready for the flood: How exposure management prepares you for the Mythos vulnerability onslaught How proactive prioritization will save time and effort when your team faces a wave of AI-discovered vulnerabilities. --- --- title: "IGEL, Menlo Security Unite Endpoint and Browser Security" url: "https://www.channelinsider.com/security/tools-and-platforms/igel-menlo-security-partner-endpoint-browser-security/" lang: "en-US" type: "post" description: "IGEL and Menlo Security are combining IGEL’s Adaptive Secure Endpoint Platform with Menlo Secure Application Access to extend Zero Trust controls from endpoints to browser and SaaS applications. The joint solution is designed to reduce reliance on virtual desktop infrastructure" last_modified: "2026-08-14T22:27:35+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/security/tools-and-platforms/igel-menlo-security-partner-endpoint-browser-security/" --- # IGEL, Menlo Security Unite Endpoint and Browser Security IGEL and Menlo Security are combining IGEL’s Adaptive Secure Endpoint Platform with Menlo Secure Application Access to extend Zero Trust controls from endpoints to browser and SaaS applications. The joint solution is designed to reduce reliance on virtual desktop infrastructure for browser-first workflows, limit endpoint agent sprawl, and simplify secure application access across enterprise environments. ## Joint solution targets VDI and endpoint agent sprawl The joint solution will pair [IGEL’s Adaptive Secure Endpoint Platform](https://www.channelinsider.com/security/tools-and-platforms/igel-updates-platform-positioning-partnership-movies/) with Menlo’s Secure Application Access (SAA). The operational improvements the joint solution provides include: - **Enhanced security posture**: Coordinated Zero Trust-aligned controls from endpoints to applications reduce gaps across device trust, credential use, and browser-based application access. - **Simplified architecture**: Fewer endpoint agents and access-path integration points for reducing complexity and operational risk. - **Reduce Total Cost of Ownership (TCO)**: More targeted VDI infrastructure use for workloads that require it, while browser and SaaS workflows can move to a simpler secure access model to improve IT efficiency. ## Zero Trust controls extend from endpoints to SaaS The partnership is ultimately meant to create a coordinated trust model that begins with the endpoint and extends into browser-based application access. It provides three core architectural advantages: - **Coordinated Zero Trust-aligned control plane**: IGEL’s Preventative Security Model helps establish a trusted endpoint foundation by reducing endpoint attack surfaces and limiting unnecessary risk before access occurs. Menlo SAA complements that by applying least-privilege access controls for web and SaaS applications. This combination allows security teams to align endpoint governance via the Universal Management Suite (UMS) with browser and SaaS access policies enforced through Menlo SAA, replacing disconnected endpoint and access workflows with a more coordinated security operating model. - **Clientless application access**: Organizations can secure access to business-critical applications for supported browser and SaaS access patterns without deploying additional endpoint agents or extending VDI infrastructure to workflows that can be securely delivered through the browser, helping reduce endpoint agent sprawl and infrastructure complexity. This simplifies deployment across diverse endpoint environments. - **Streamlined management**: Security architects can leverage the UMS for centralized endpoint control and apply Menlo’s browser-based security policies via existing identity providers and security orchestration tools. “IGEL is the secure OS foundation for modern application access, providing the trusted platform organizations need to confidently embrace browser-delivered workspaces. Together with the Menlo Browser Security Platform, we’re delivering end-to-end protection that unifies endpoint and browser security into a single, resilient Zero Trust architecture,” he adds.  Additionally, the joint solution supports immediate deployment for organizations seeking to modernize VDI environments or strengthen existing endpoint security investments with web application protection. The post [IGEL, Menlo Security Unite Endpoint and Browser Security](https://www.channelinsider.com/security/tools-and-platforms/igel-menlo-security-partner-endpoint-browser-security/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "TD SYNNEX Expands IBM Distribution Into 20 Countries" url: "https://www.channelinsider.com/channel-business/channel-analysis/td-synnex-expands-ibm-distribution/" lang: "en-US" type: "post" description: "TD SYNNEX is expanding its IBM distribution footprint into 20 new countries across Europe, Asia-Pacific, and Latin America, giving partners broader access to IBM solutions and support for scaling their businesses across global markets. The additional new countries include: Europe:" last_modified: "2026-08-14T22:25:23+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/channel-business/channel-analysis/td-synnex-expands-ibm-distribution/" --- # TD SYNNEX Expands IBM Distribution Into 20 Countries TD SYNNEX is expanding its IBM distribution footprint into 20 new countries across Europe, Asia-Pacific, and Latin America, giving partners broader access to IBM solutions and support for scaling their businesses across global markets. The additional new countries include: - **Europe**: Bulgaria, Denmark, Finland, Ireland, Slovakia, Sweden, Serbia, Macedonia, Montenegro, Albania, and Bosnia & Herzegovina. - **Asia Pacific**: Indonesia, Malaysia (under the Tech Data and Tec-D brand), Hong Kong, Cambodia, and the Philippines. - **Latin America**: Peru, Paraguay, Uruguay, and Venezuela. ## Expanded agreement brings TD SYNNEX partners IBM solutions and growth This expansion will enable TD SYNNEX to extend access to IBM solutions while enabling partners to grow and scale across regions. “With this expansion, we are extending our reach into additional markets while connecting with a broader set of partners looking to grow their IBM business,” said Mark Martin, VP, Global Vendor Management, TD SYNNEX. “And through our program Select Blue, we’re providing a clear path to engage, specialize, and execute confidently, helping both new and existing partners enter new markets and accelerate revenue growth.” Select Blue is designed to help partners move from opportunity to execution faster and with less guesswork, TD SYNNEX states. This extended footprint gives more partners access to this solution. “Select Blue gives us clarity around where to focus and how to scale,” said Sam Smith, Senior Vice President, ASB Resources. “By adopting SaaS- and consumption-based models, we’re accelerating execution and driving more predictable growth. TD SYNNEX helped us get there faster – without guesswork.” TD SYNNEX helps partners accelerate time to revenue and [scale IBM business](https://www.channelinsider.com/infrastructure/ibm-q2-revenue-warning-enterprise-it-spending/) by providing end-to-end capabilities across enablement, financing, pre-sales support, and go-to-market execution. **As TD SYNNEX continues to expand, the company was recently named one of HPE’s two global distribution partners. Read more **[**about the move**](https://www.channelinsider.com/infrastructure/hpe-td-synnex-global-distribution/)** as HPE expands partner support for AI, cloud, and networking.** The post [TD SYNNEX Expands IBM Distribution Into 20 Countries](https://www.channelinsider.com/channel-business/channel-analysis/td-synnex-expands-ibm-distribution/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "Trezor confirms shipping partner data breach affecting over 13,000 customers" url: "https://www.scworld.com/brief/trezor-confirms-shipping-partner-data-breach-affecting-over-13000-customers" lang: "en-US" type: "post" description: "While the breach was initially believed to affect only recent orders, new information suggests older orders may also be compromised." last_modified: "2026-08-14T21:41:43+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/trezor-confirms-shipping-partner-data-breach-affecting-over-13000-customers" --- # Trezor confirms shipping partner data breach affecting over 13,000 customers While the breach was initially believed to affect only recent orders, new information suggests older orders may also be compromised. --- --- title: "How a Sony Veteran Is Overhauling the Company He Grew Up In" url: "https://www.wsj.com/business/media/sony-ceo-hiroki-totoki-efc8923f?mod=rss_Technology" lang: "en-US" type: "post" description: "Hiroki Totoki says the future of the electronics business is entertainment." last_modified: "2026-08-14T21:40:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/business/media/sony-ceo-hiroki-totoki-efc8923f?mod=rss_Technology" --- # How a Sony Veteran Is Overhauling the Company He Grew Up In Hiroki Totoki says the future of the electronics business is entertainment. --- --- title: "U.S. judiciary to publicly disclose use of hacking tools in wiretaps starting 2029" url: "https://www.scworld.com/brief/u-s-judiciary-to-publicly-disclose-use-of-hacking-tools-in-wiretaps-starting-2029" lang: "en-US" type: "post" description: "Starting with the 2028 Wiretap Report, which will be published in 2029, the judiciary will include data on network investigating techniques." last_modified: "2026-08-14T21:38:42+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/u-s-judiciary-to-publicly-disclose-use-of-hacking-tools-in-wiretaps-starting-2029" --- # U.S. judiciary to publicly disclose use of hacking tools in wiretaps starting 2029 Starting with the 2028 Wiretap Report, which will be published in 2029, the judiciary will include data on network investigating techniques. --- --- title: "California launches AI cybersecurity initiative amid growing threats" url: "https://www.scworld.com/brief/california-launches-ai-cybersecurity-initiative-amid-growing-threats" lang: "en-US" type: "post" description: "The initiative mandates the creation of an AI cybersecurity officer role within every state agency and establishes an AI cyber defense program housed in the state’s Cybersecurity Integration Center." last_modified: "2026-08-14T21:35:13+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/california-launches-ai-cybersecurity-initiative-amid-growing-threats" --- # California launches AI cybersecurity initiative amid growing threats The initiative mandates the creation of an AI cybersecurity officer role within every state agency and establishes an AI cyber defense program housed in the state’s Cybersecurity Integration Center. --- --- title: "Cybercriminals invest millions in expired domains for illicit activities" url: "https://www.scworld.com/brief/cybercriminals-invest-millions-in-expired-domains-for-illicit-activities" lang: "en-US" type: "post" description: "These \"dropcatch\" domains are attractive to threat actors because they retain trust, backlinks, and web traffic from their previous legitimate use, making them appear more favorable to security systems than new registrations." last_modified: "2026-08-14T21:30:39+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/cybercriminals-invest-millions-in-expired-domains-for-illicit-activities" --- # Cybercriminals invest millions in expired domains for illicit activities These “dropcatch” domains are attractive to threat actors because they retain trust, backlinks, and web traffic from their previous legitimate use, making them appear more favorable to security systems than new registrations. --- --- title: "MacOS screen sharing vulnerability actively exploited for crypto mining" url: "https://www.scworld.com/brief/macos-screen-sharing-vulnerability-actively-exploited-for-crypto-mining" lang: "en-US" type: "post" description: "The vulnerability, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and stems from a flaw in macOS' screen sharing capability." last_modified: "2026-08-14T21:27:25+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/macos-screen-sharing-vulnerability-actively-exploited-for-crypto-mining" --- # MacOS screen sharing vulnerability actively exploited for crypto mining The vulnerability, identified as CVE-2026-65400, has a severity rating of 7.1 out of 10 and stems from a flaw in macOS’ screen sharing capability. --- --- title: "ExfilSquad data extortion group linked to 13 victim data leaks" url: "https://www.scworld.com/brief/exfilsquad-data-extortion-group-linked-to-13-victim-data-leaks" lang: "en-US" type: "post" description: "ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations." last_modified: "2026-08-14T21:24:37+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/exfilsquad-data-extortion-group-linked-to-13-victim-data-leaks" --- # ExfilSquad data extortion group linked to 13 victim data leaks ExfilSquad, which emerged on July 26, initially claimed to have exfiltrated data from 15 organizations. --- --- title: "ShinyHunters group claims responsibility for RingCentral data breach" url: "https://www.scworld.com/brief/shinyhunters-group-claims-responsibility-for-ringcentral-data-breach" lang: "en-US" type: "post" description: "The incident, which occurred in July, was disclosed by RingCentral as the result of a sophisticated social engineering campaign." last_modified: "2026-08-14T21:21:41+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/shinyhunters-group-claims-responsibility-for-ringcentral-data-breach" --- # ShinyHunters group claims responsibility for RingCentral data breach The incident, which occurred in July, was disclosed by RingCentral as the result of a sophisticated social engineering campaign. --- --- title: "Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More – SWN #607" url: "https://www.scworld.com/podcast-segment/15282-mathematicians-lazarus-akira-computer-history-zoom-litellm-josh-marpet-and-more-swn-607" lang: "en-US" type: "post" last_modified: "2026-08-14T21:00:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/podcast-segment/15282-mathematicians-lazarus-akira-computer-history-zoom-litellm-josh-marpet-and-more-swn-607" --- # Mathematicians, Lazarus, Akira, Computer History, Zoom, LiteLLM, Josh Marpet and More – SWN #607 --- --- title: "Apple Seeks Up to 15% Cut on External Purchases in Epic Court Fight" url: "https://www.channelinsider.com/apple/news-apple-external-purchase-fee-epic-court-fight/" lang: "en-US" type: "post" description: "Apple still wants a cut when an iPhone user leaves an app and completes a purchase on the web. In a new court proposal tied to its long-running fight with Epic Games, Apple is asking to charge US developers between" last_modified: "2026-08-14T20:54:23+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/apple/news-apple-external-purchase-fee-epic-court-fight/" --- # Apple Seeks Up to 15% Cut on External Purchases in Epic Court Fight Apple still wants a cut when an iPhone user leaves an app and completes a purchase on the web. In a new court proposal tied to its long-running fight with Epic Games, Apple is asking to charge US developers between 5% and 15% on purchases completed after users follow external links from iOS apps. The rates are not final and must still be reviewed by a federal judge. The decision could determine whether web checkout gives developers a meaningful break from App Store economics or simply replaces Apple’s current commission with a smaller one. ## Apple proposes three rates for external purchases The Verge said that Apple proposed a 15% commission for standard apps that would normally pay 30% on App Store purchases. Apps in Apple’s News Partner, Video Partner, and Mini Apps Partner programs would pay 10%, along with subscription renewals. Developers enrolled in the Small Business Program would pay 5%. Those developers normally pay Apple 15% through its own [billing system](https://www.channelinsider.com/channel-business/helpdesk-itsm-and-other-tools/sherweb-halopsa-integration-billing/). The fee would kick in when a customer follows a purchase link from an app and completes the transaction on the developer’s website. [MacRumors](https://www.macrumors.com/2026/08/13/app-store-fees-apple-link-outs/) gave Spotify as an example: if an [iPhone user](https://www.channelinsider.com/news-and-trends/news-apple-iphone-mac-revenue-supply-constraints/) follows an in-app link to Spotify’s website and subscribes there, Apple says it should still receive a commission. For users, external checkout could still offer a cheaper route than paying inside an app, but only if developers pass some of the lower fees on to customers. Apple’s proposal does not require that, so the impact on consumer prices would vary by app and service. Apple said its direct “necessary costs” for allowing external purchases would be “essentially zero,” according to The Verge. The company argued that the proposed rates would still leave developers room to benefit from linking customers to the web. “It appears that large numbers of US developers collectively accounting for the lion’s share of App Store revenue will be able to link out profitably,” Apple said in the filing, according to [The Verge](https://www.theverge.com/tech/979967/apple-epic-games-external-links-fees-filing). For standard apps, Apple’s proposed 15% rate is half its usual 30% commission. Developers would save on Apple’s fee by sending customers to the web, although they would still have to account for their own payment-processing costs. ## Epic pushes back on Apple’s proposed commission The Verge noted that Epic has already rejected Apple’s proposal, calling it “far outside of the bounds” of the court’s guidance.  The dispute goes back to a 2021 order requiring Apple to let developers direct customers to outside payment options. Apple later charged commissions of 12% to 27% on those purchases. [The Mac Observer](https://www.macobserver.com/news/apple-proposes-up-to-15-app-store-fee-for-external-purchases/) noted that Judge Yvonne Gonzalez Rogers found Apple in contempt in April 2025 and barred it from collecting link-out commissions. An appeals court upheld the contempt finding but ruled that Apple could receive compensation for its intellectual property, sending the question of an appropriate fee back to the district court. ## Apple and Google take different paths on outside payments Apple is not alone in being pushed to [loosen its control](https://www.channelinsider.com/channel-business/news-apple-uk-icloud-encryption-access-challenge-emea/) over mobile payments. [Engadget ](https://www.engadget.com/2236861/apple-proposal-5-to-15-percent-cut-external-app-store-payments/)reported that Google opened the Play Store to external billing on June 30 and reduced its commission to 10% regardless of which payment system customers use.  [Google](https://www.channelinsider.com/channel-business/news-google-pixel-11-price-ram-memory-shortage-2026/) also began allowing third-party app stores on Android in July. Apple’s 5% to 15% proposal is not final. Rogers must review Apple’s request and Epic’s response before setting the commission Apple can charge in the US.  For [developers and businesses](https://www.channelinsider.com/ai/news-xai-grok-4-6-ai-agents/) selling digital services through iOS, the percentage the court settles on will decide whether external checkout provides a substantial break from App Store fees or simply trades the current commission for a smaller Apple cut. **Also Read: See how OpenAI’s newly released messages **[**challenge Apple’s trade-secret claims**](https://www.channelinsider.com/ai/news-openai-disputes-apple-trade-secret-claims/)** and what they reveal about employee access and rival hiring.** The post [Apple Seeks Up to 15% Cut on External Purchases in Epic Court Fight](https://www.channelinsider.com/apple/news-apple-external-purchase-fee-epic-court-fight/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "Trezor Says ShipMonk Breach Exposed Data of Nearly 14,000 Customers" url: "https://www.esecurityplanet.com/threats/news-trezor-shipmonk-data-breach-14000-customers/" lang: "en-US" type: "post" description: "Trezor, the Prague-based manufacturer of cold crypto storage devices, disclosed a significant data breach on Thursday that exposed the personal information of nearly 14,000 customers.  The incident, which the company described as occurring at its third-party logistics partner ShipMonk, compromised" last_modified: "2026-08-14T20:51:07+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/threats/news-trezor-shipmonk-data-breach-14000-customers/" --- # Trezor Says ShipMonk Breach Exposed Data of Nearly 14,000 Customers Trezor, the Prague-based manufacturer of cold crypto storage devices, disclosed a significant data breach on Thursday that exposed the personal information of nearly 14,000 customers.  The incident, which the company described as occurring at its third-party logistics partner ShipMonk, compromised the names, shipping addresses, phone numbers, and email addresses of 11,742 buyers. An additional 1,947 customers had partial data—namely name, city, and email—exposed, with some of those potentially involving older orders that fell outside the standard retention window. The breach primarily affects customers in the United States, the United Kingdom, Sweden, Colombia, Brazil, Italy, and Portugal who received devices between May 10 and August 8, 2026. Trezor said the 1,947 partially exposed records may include older orders and that it is still verifying their timeframe. While Trezor emphasized that its internal systems and the devices themselves remain secure, the company warned that the leak places users at a significantly higher risk of [sophisticated phishing campaigns](https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident). “We absolutely understand how serious this is and the potential risks it poses to our customers and are deeply sorry to those affected,” [Trezor said in a statement](https://trezor.io/blog/news/recent-customer-data-exposed-in-shipping-provider-incident). ## The attack vector According to breach notifications sent to affected users and [reviewed by BleepingComputer](https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-nearly-14-000-customers/), ShipMonk traced the intrusion back to a vulnerability in the third-party analytics platform Metabase. The logistics provider explained that an unauthorized party exploited a critical SQL injection zero-day bug to gain administrative access to their instance.  Metabase has since patched the vulnerability and invalidated active sessions. Framework and online form builder Tally have also disclosed breaches involving compromised Metabase instances. ShipMonk received extortion emails from [ShinyHunters](https://www.esecurityplanet.com/threats/shinyhunters-claims-brinks-home-salesforce-data-theft/), according to BleepingComputer, although the report did not establish that the group carried out the initial intrusion. ## The physical threat The exposure of physical addresses is particularly alarming given the current climate surrounding digital asset holders. According to blockchain data provider Chainalysis, 46 violent crypto-related incidents were documented worldwide through late June 2026, compared with 40 during the same period in 2025. Kidnappings accounted for 52% of the 2026 incidents. “Criminals have recognized that crypto holders are high-value targets because they possess wealth in an instantly and irreversibly transferable form,” [Chainalysis noted](https://www.chainalysis.com/blog/violent-crypto-wrench-attacks-2026/). This incident marks the first time since Trezor’s founding in 2013 that a breach has exposed customer phone numbers and shipping addresses. It also follows closely on the heels of a separate crisis — [the Coldcard hack on July 30](https://www.esecurityplanet.com/threats/news-coldcard-rng-flaw-bitcoin-theft/) — where over $100 million was stolen due to a bug that generated insecure private keys.  Ashna Vaghela, chief customer officer at Mercuryo, [per Bloomberg](https://www.bloomberg.com/news/articles/2026-08-13/crypto-firm-trezor-says-data-breach-exposed-thousands-of-clients), highlighted the overarching concern: “As the Bitcoin industry still absorbs the fallout from the Coldcard hack, the latest incident underlines how quickly trust can be undermined when attackers target the ecosystem around the wallet rather than the wallet itself.” ## Moving forward Trezor is attempting to mitigate this risk with an “Anonymous Delivery” option, which allows buyers to use a dedicated checkout and have devices shipped to neutral lockers in unbranded packaging. The service is slated for a September 2026 launch in the EU and a year-end rollout in the U.S.  In the meantime, affected users are advised to treat all unsolicited communications with skepticism, verify claims through official Trezor channels, and never enter their 24-word wallet recovery seed online. **Read more: Like the Trezor incident, the**[** ****DentaQuest breach exposed personal information through a third-party provider**](https://www.esecurityplanet.com/cybersecurity/news-dentaquest-data-breach-15-million/)**, highlighting the security risks organizations inherit from their vendors. ** The post [Trezor Says ShipMonk Breach Exposed Data of Nearly 14,000 Customers](https://www.esecurityplanet.com/threats/news-trezor-shipmonk-data-breach-14000-customers/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "Anthropic Investors Predict Record $2 Trillion IPO Valuation" url: "https://www.channelinsider.com/ai/news-anthropic-investors-2-trillion-ipo-valuation/" lang: "en-US" type: "post" description: "Six Anthropic backers told the Financial Times that they expect the Claude maker to go public as early as October at a valuation of $2 trillion or more. Anthropic has not confirmed the timing or valuation, but such a debut" last_modified: "2026-08-14T20:34:48+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/ai/news-anthropic-investors-2-trillion-ipo-valuation/" --- # Anthropic Investors Predict Record $2 Trillion IPO Valuation Six Anthropic backers told the Financial Times that they expect the Claude maker to go public as early as October at a valuation of $2 trillion or more. Anthropic has not confirmed the timing or valuation, but such a debut could surpass SpaceX’s record IPO valuation. “If Anthropic is growing 800% a year, you’d think at the incredibly low end they would trade at 30 times [revenue],” [one investor told the FT](https://www.ft.com/content/840ac156-af1c-4a82-b260-ae791072fcfa?syn-25a6b1a6=1). “That would make them a $3 trillion company.” To put that in perspective, Anthropic has no direct publicly listed US peer to benchmark against. Investors pointed to AI-adjacent companies such as Palantir and Nebius, which have traded at roughly 55 times revenue this year, according to the FT. Those comparisons support the bullish case, although public investors may assign Anthropic a different multiple. Anthropic has not confirmed a valuation or listing date. The [company announced](https://www.eweek.com/news/anthropic-confidential-ipo-filing/) in June that it had confidentially submitted a draft S-1 to the SEC, but said the offering remained subject to regulatory review, market conditions, and other factors. Morgan Stanley, Goldman Sachs, and JPMorgan are leading the offering, [according to Quartz](https://qz.com/anthropic-ipo-2-trillion-valuation-october-081326), a sign that this isn’t just investor chatter.  ## The challenges stack up The bullish projections come despite mounting headwinds. In June, the Commerce Department temporarily [banned Anthropic’s leading models](https://www.eweek.com/news/anthropic-fable-5-export-control-directive-neuron/), Fable 5 and Mythos 5, under export controls.  Two investors told the FT that the episode measurably slowed revenue growth that month, though the company has since rebounded. The government relationship remains tense, with [Anthropic still in active litigation against the Defense Department](https://www.eweek.com/news/anthropic-washington-timeline-2026/), which labeled the company a supply-chain risk earlier this year. Then there’s the cost problem. Anthropic’s flagship model costs more than 2.5x as much to use as OpenAI’s, according to data from Artificial Analysis cited by the FT. Chinese [open-weight alternatives](https://www.channelinsider.com/ai/anthropic-open-weight-ai-model-regulation/) are available at a fraction of the price and have improved dramatically this year.  ## What this means for OpenAI If Anthropic goes first, [OpenAI will be priced](https://www.channelinsider.com/ai/openai-ipo-channel-strategy/) against a live competitor. But Evan Schlossberg, an OpenAI investor, sees a rising tide lifting all boats. “If you see strong, credible demand for investments in Anthropic and escalating premiums on that revenue, it would speak to a reasonable analogy that you’re seeing similar market trends for OpenAI,” [he told Fortune](https://fortune.com/2026/08/14/anthropic-valuation-ipo-amazon-trillion-openai/). Anthropic’s path to a $2 trillion valuation rests on investor projections rather than company disclosures. If its S-1 becomes public, the filing will allow investors and channel partners to test those assumptions against disclosed financial statements — and assess whether Anthropic can expand its partner ecosystem while competing on model pricing. **Read more: As Anthropic prepares for a potential public debut, see how its**[** ****new Claude Partner Hub and services tiers could shape deployment opportunities for channel partners**](https://www.channelinsider.com/channel-business/vendor-leadership-and-partner-programs/claude-partner-network-services-track/)**.** The post [Anthropic Investors Predict Record $2 Trillion IPO Valuation](https://www.channelinsider.com/ai/news-anthropic-investors-2-trillion-ipo-valuation/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "OpenAI Previews GPT-5.6 Sol Ultrafast Mode for Real-Time AI Workloads" url: "https://www.channelinsider.com/ai/news-openai-gpt-5-6-sol-ultrafast/" lang: "en-US" type: "post" description: "OpenAI is previewing a faster GPT-5.6 Sol API option for workloads where every extra second can slow the application around it. The company said that Ultrafast can run its flagship model up to 14 times faster than Standard processing. MSPs," last_modified: "2026-08-14T20:31:37+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/ai/news-openai-gpt-5-6-sol-ultrafast/" --- # OpenAI Previews GPT-5.6 Sol Ultrafast Mode for Real-Time AI Workloads OpenAI is previewing a faster GPT-5.6 Sol API option for workloads where every extra second can slow the application around it. The company said that Ultrafast can run its flagship model up to 14 times faster than Standard processing. MSPs, systems integrators, and other providers supporting customer AI deployments may see the biggest difference when response time affects work already underway. Early use cases will help determine whether the added speed changes enough of the overall task to justify a different serving tier. ## Lower latency gets tested in active workloads Examples in the [Ultrafast preview](https://openai.com/index/previewing-ultrafast/) concentrate on work happening while people or systems are still waiting for an answer. Incident response can use faster generation to work through logs and traces during an outage, while voice and support systems can complete multi-step requests during a live interaction. Research teams can also fit more iterations into the workday. MSPs already[ using AI for service desk triage and repetitive support work](https://www.channelinsider.com/ai/msp-service-efficiency/) have immediate candidates for testing. Technician-facing tools and customer support applications can show whether faster generation actually reduces time spent waiting on the model.  ## API customers get another serving tier Cerebras supplies the infrastructure behind Ultrafast, with generation reaching up to 750 output tokens per second. Plans for Cerebras-served Sol first appeared in [OpenAI’s June GPT-5.6 preview](https://openai.com/index/previewing-gpt-5-6-sol/), and the new release gives the capability a named API tier. Existing [Fast mode](https://openai.com/api-fast-mode/) runs Sol up to 2.5 times faster than Standard at twice the price, with no change in model intelligence. Ultrafast is limited to select API customers at launch. Access is set to expand as capacity grows. Systems integrators in the[ OpenAI Partner Network](https://www.channelinsider.com/news-and-trends/openai-debuts-partner-network-backed-by-150m-investment/) and MSPs managing[ AI ecosystems across several platforms](https://www.channelinsider.com/ai/building-channel-revenue/ai-ecosystem-for-managed-services/) could eventually treat serving tier as another configuration choice inside customer environments. Performance requirements and API spending would then become part of deciding how each application is deployed.  ## Partners should benchmark the full customer workflow MSPs and SIs evaluating Ultrafast should begin with the customer task. Measure total time from request to completed outcome, then compare Standard, Fast, and Ultrafast on the same workload. Model generation can be only one source of delay. Retrieval systems and databases may consume more time, while external APIs can introduce their own latency. Faster inference will not produce the same end-to-end improvement in every application. MSSPs need a separate control review when faster agents can inspect systems or trigger tools. Providers working through [agentic AI security and governance](https://www.channelinsider.com/security/next-gen-solutions/agentic-ai-security-governance-msps/) should validate permissions and logging, then review rate limits and human approval points before increasing execution speed. Commercial commitments deserve the same testing discipline. Providers expanding [AI services across integration and security](https://www.channelinsider.com/ai/building-channel-revenue/goto-ai-services-msps-mike-day/) should use production data from the customer’s own environment before attaching response times to proposals or SLAs. **Read more: **[**Grok 4.6 expands xAI’s agent tooling**](https://www.channelinsider.com/ai/news-xai-grok-4-6-ai-agents/)** with longer task execution and new deployment options for developers and AI providers.  ** The post [OpenAI Previews GPT-5.6 Sol Ultrafast Mode for Real-Time AI Workloads](https://www.channelinsider.com/ai/news-openai-gpt-5-6-sol-ultrafast/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "Gemini Becomes Google’s 14th Product to Reach 1B Monthly Users" url: "https://www.channelinsider.com/ai/news-google-gemini-1b-monthly-users-2026/" lang: "en-US" type: "post" description: "Gemini has joined the billion-user club, giving Google its strongest sign yet that its AI assistant has moved into the mainstream. Google said Tuesday that the Gemini app has surpassed 1 billion monthly active users, making it the company’s 14th" last_modified: "2026-08-14T20:28:47+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/ai/news-google-gemini-1b-monthly-users-2026/" --- # Gemini Becomes Google’s 14th Product to Reach 1B Monthly Users Gemini has joined the billion-user club, giving Google its strongest sign yet that its AI assistant has moved into the mainstream. Google said Tuesday that the Gemini app has surpassed 1 billion monthly active users, making it the company’s 14th product to reach that milestone. The figure puts Gemini among the largest consumer AI services in the world. ChatGPT has also crossed the billion-user mark, although OpenAI reports weekly rather than monthly users, making the figures unsuitable for a direct comparison. Together, the milestones show how quickly generative AI assistants are moving from novelty to mass-market infrastructure. ## Gemini took acceleration seriously  Gemini’s 1 billion monthly users are impressive, but the speed at which [Google](https://www.channelinsider.com/infrastructure/news-google-anthropic-tpu-financing-network/) reached that number is arguably more significant.  Google’s CEO, Sundar Pichai, [announced the development](https://x.com/sundarpichai/status/2087222656819241292?s=20) on his X page.  [According to The Verge](https://www.theverge.com/ai-artificial-intelligence/978113/chatgpt-gemini-1-billion-users), the platform went from 750 million MAUs in February to 950 million last month, then added another 50 million, bringing the total to 1 billion. That growth is also showing up in how people use the service. In its July earnings call, [Google said](https://blog.google/company-news/inside-google/message-ceo/alphabet-earnings-q2-2026/) Gemini’s daily active users have tripled over the past year, while newer features such as Daily Brief and [Gemini Spark](https://www.techrepublic.com/article/news-gemini-spark-app-integrations/) are pushing the product beyond simple question-and-answer interactions and toward more persistent assistance. The result is a product that is not only reaching more people but becoming a more regular part of how some of those users interact with AI. That distinction matters because a large monthly user base is less meaningful if people rarely return or use the product only once. ## A billion users, but with a revenue question A [billion monthly users](https://blog.google/innovation-and-ai/products/gemini-app/one-billion-monthly-users/) gives Google enormous reach, but reach is only part of the business equation. Google has not disclosed how much revenue Gemini itself generates, making it difficult to tell how effectively that audience is being converted into paid subscriptions or other revenue. [OpenAI](https://www.channelinsider.com/ai/news-openai-ai-device-jony-ive-price-2027/) offers a useful comparison because it has already demonstrated that a large AI user base can translate into substantial revenue. OpenAI’s annualized revenue reached $25 billion by the end of February, [according to Reuters](https://www.reuters.com/technology/openai-tops-25-billion-annualized-revenue-last-month-information-reports-2026-03-05/). However, that figure reflects OpenAI’s broader AI business, not ChatGPT alone. That leaves Google with a different question after reaching 1 billion users: how much is each of those users worth? The answer will matter more over time than the headline user count itself, particularly as [Google continues investing heavily in the infrastructure](https://www.techrepublic.com/article/news-google-texas-data-centers/) required to run Gemini. ## The underlying moat behind Gemini’s 1 billion MAUs The biggest advantage behind Gemini’s growth may not be Gemini itself, but where Google can put it. The company controls Android, Chrome, Search, YouTube, Workspace, and several other products, giving [Gemini access to products](https://www.techrepublic.com/article/news-gmail-gemini-era/) and devices that already have enormous audiences rather than requiring every potential user to seek out a separate AI service.  That changes the mechanics of user acquisition. Someone does not necessarily have to decide to download Gemini or visit its website, as Google can introduce the assistant inside products they already use. ChatGPT, on the other hand, has built an enormous audience without owning an operating system or search engine. That means while [OpenAI](https://openai.com/index/improving-gpt-5-6-sol-in-chatgpt/) is building integrations and partnerships, Google is making Gemini part of the software people already use every day. For enterprises looking to expand, Google’s advantage shows why owning the channels where customers already spend their time can matter as much as the product itself. **Editor’s note: This article originally appeared on our sister publication, **[**TechRepublic**](https://www.techrepublic.com/article/news-google-gemini-1-billion-monthly-users-2026/)**.** The post [Gemini Becomes Google’s 14th Product to Reach 1B Monthly Users](https://www.channelinsider.com/ai/news-google-gemini-1b-monthly-users-2026/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "AI-driven energy buildout raises cybersecurity, supply chain risks" url: "https://www.scworld.com/analysis/ai-driven-energy-buildout-raises-cybersecurity-supply-chain-risks" lang: "en-US" type: "post" description: "AI-driven energy growth brings new cyber and supply chain risks to critical infrastructure." last_modified: "2026-08-14T20:23:50+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/analysis/ai-driven-energy-buildout-raises-cybersecurity-supply-chain-risks" --- # AI-driven energy buildout raises cybersecurity, supply chain risks AI-driven energy growth brings new cyber and supply chain risks to critical infrastructure. --- --- title: "Mission-Driven Security: Inside a Global Bank’s Defense" url: "https://www.darkreading.com/cybersecurity-operations/mission-driven-security-inside-global-bank-defense" lang: "en-US" type: "post" description: "In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking." last_modified: "2026-08-14T19:24:18+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.darkreading.com/rss.xml" wpe_sourcepermalink: "https://www.darkreading.com/cybersecurity-operations/mission-driven-security-inside-global-bank-defense" --- # Mission-Driven Security: Inside a Global Bank’s Defense In this video interview, Standard Chartered’s group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking. --- --- title: "Claude Agents Started a ‘Turf War’ That Escalated to Self-Replicating Malware" url: "https://www.esecurityplanet.com/artificial-intelligence/news-claude-agent-malware-turf-war/" lang: "en-US" type: "post" description: "Claude agents given conflicting coding assignments began sabotaging one another in a controlled Anthropic experiment, with some encounters escalating to self-replicating malware. Researchers were testing how autonomous models behave when several agents work in the same environment under incompatible goals." last_modified: "2026-08-14T19:11:35+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/artificial-intelligence/news-claude-agent-malware-turf-war/" --- # Claude Agents Started a ‘Turf War’ That Escalated to Self-Replicating Malware Claude agents given conflicting coding assignments began sabotaging one another in a controlled Anthropic experiment, with some encounters escalating to self-replicating malware. Researchers were testing how autonomous models behave when several agents work in the same environment under incompatible goals. Some Claude instances treated competing work as interference and entered what Anthropic called a “multiagent turf war.” Malware was not part of the assignment. It emerged as agents tried to protect their own work, turning an ordinary coding task into a much more aggressive contest between autonomous systems. ## Conflicting assignments turned into active sabotage Researchers assigned six Claude model versions of the same software task, rewriting a Python backend in another programming language, according to [Anthropic’s research](https://www.anthropic.com/research/multiagent-systems). Competing agents worked on the same codebase, allowing one model’s actions to interfere directly with another’s. Sabotage soon moved past conflicting edits. Some agents searched for and killed competing processes, and others planted malicious code designed to appear as if another agent had written it. Escalation eventually produced [self-replicating malware](https://www.esecurityplanet.com/threats/malware-types/). Sonnet 4.6 and Opus 4.6 were among the most combative models, resolving about 60% of runs through force. In the context of the experiment, “force” refers to AI agents aggressively using server commands, lockout tactics, and self-replicating malware to terminate and completely block rival models from the system.  Other encounters ended with agents communicating, removing malicious code, or calling for human intervention. ## More capable models still used destructive tactics Greater capability did not reliably produce better coordination. Stronger models could still resort to destructive behavior when their assigned objectives clashed, complicating assumptions that improved reasoning alone will keep autonomous agents cooperative. Access also amplified the consequences. File modification and command execution gave agents the means to act on their decisions. Research into[ AI sandbox security](https://www.esecurityplanet.com/threats/nvidia-nemoclaw-research-highlights-ai-sandbox-exfiltration-risks/) has raised similar concerns about how permitted tools and connections can expose resources when an agent behaves unexpectedly. Anthropic’s experiment did not involve malware spreading through customer systems. Still, an[ autonomous AI agent attack](https://www.esecurityplanet.com/threats/hugging-face-discloses-autonomous-ai-agent-attack/) already demonstrated how agents can independently chain actions across live infrastructure. Claude’s turf war adds peer agents to the set of actors security teams may need to account for. ## Security teams should isolate agent identities and access Organizations running multiple autonomous agents against the same codebase or infrastructure should avoid treating them as one trusted unit. Give each agent its own identity and limited permissions, and separate workspaces or credentials where possible. Existing [AI agent safety controls](https://www.esecurityplanet.com/artificial-intelligence/ai-agent-safety-checklist/) can help restrict how far one agent can reach if its behavior changes. Security teams should also watch for activity directed at other agents, including unexpected process termination or changes outside an assigned workspace. Individual identities and detailed logs make it easier to determine which agent performed an action, an important part of [agentic security](https://www.esecurityplanet.com/artificial-intelligence/agentic-security-how-to-build-trust-in-ai-agents/). If an agent begins interfering with others, isolate its session and revoke access before investigating generated code or exposed credentials. Security plans for multiagent systems should account for peer conflict before autonomous agents receive broad access to shared systems. **Other News: A **[**Claude-powered agent exploited a gym API flaw**](https://www.esecurityplanet.com/threats/news-claude-ai-agent-australian-gym-api-flaw-apac/)** and removed a waitlisted member, exposing how autonomous actions can cross into real-world systems. ** The post [Claude Agents Started a ‘Turf War’ That Escalated to Self-Replicating Malware](https://www.esecurityplanet.com/artificial-intelligence/news-claude-agent-malware-turf-war/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "SAP Commerce Cloud RCE Flaw Actively Exploited " url: "https://www.esecurityplanet.com/threats/sap-commerce-cloud-rce-flaw-actively-exploited/" lang: "en-US" type: "post" description: "A vulnerability in SAP Commerce Cloud that can allow unauthenticated attackers to execute arbitrary code is being exploited in the wild just days after SAP released a security update.  Threat intelligence company Defused detected exploitation attempts targeting the flaw three" last_modified: "2026-08-14T19:09:53+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/threats/sap-commerce-cloud-rce-flaw-actively-exploited/" --- # SAP Commerce Cloud RCE Flaw Actively Exploited  A vulnerability in SAP Commerce Cloud that can allow unauthenticated attackers to execute arbitrary code is being [exploited](https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/) in the wild just days after SAP released a security update.  Threat intelligence company Defused detected exploitation attempts targeting the flaw three days after the patch was issued.  “First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots,” Defused [said](https://x.com/DefusedCyber/status/2088240809355153647) in an X post. ## **Key takeaways of the SAP RCE flaw exploitation** - CVE-2026-58231 is a SAP Commerce Cloud vulnerability with a CVSS score of 10.0. - The flaw enables unauthenticated remote code execution, allowing attackers to run arbitrary code without existing privileges. - Defused detected exploitation attempts shortly after SAP released a patch, despite no known public proof-of-concept exploit. - SAP is investigating the reported exploitation activity and recommends affected organizations apply the latest security updates. ## **SAP Commerce Cloud RCE flaw targeted in attacks ** SAP Commerce Cloud is an e-commerce platform used by major brands and retailers to manage online commerce operations. ### **CVE-2026-58231 explained ** The vulnerability, tracked as [CVE-2026-58231](https://nvd.nist.gov/vuln/detail/CVE-2026-58231), carries a CVSS score of 10.0 and stems from an improper authorization weakness in the platform’s core Data Hub Adapter extension.  According to SAP, an unauthenticated attacker can abuse a default authentication client and submit specially crafted input to functions that lack sufficient validation. ### **CVE-2026-58231 enables unauthenticated RCE ** Successful exploitation can lead to remote code execution (RCE), allowing attackers to run arbitrary code on affected systems.  The flaw requires no authentication or existing privileges and is considered low complexity, making vulnerable systems easier to target remotely. ### **Exploitation attempts follow SAP patch ** SAP released a security update for CVE-2026-58231 as part of its August 2026 Patch Day.  Shortly after, Defused detected the exploitation attempts against its honeypots despite no known public proof-of-concept exploit. SAP is investigating the reported exploitation activity and urges affected organizations to apply the latest security updates. ## **How to reduce CVE-2026-58231 risk ** Applying the available update is the first step, but teams should also assess whether exploitation occurred before patching and strengthen controls that restrict access, lateral movement, and data exfiltration.  - **Apply SAP’s **[**latest update**](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html) and verify that affected Commerce Cloud systems are fully patched. - **Restrict unnecessary internet exposure** and use [WAF](https://www.esecurityplanet.com/products/top-web-application-firewall-waf-vendors/) protections to detect and block suspicious requests. - **Segment Commerce Cloud environments** and apply egress filtering to limit lateral movement, command-and-control traffic, and [data](https://www.esecurityplanet.com/networks/data-loss-prevention-best-practices/) exfiltration. - [**Monitor**](https://www.esecurityplanet.com/products/best-network-monitoring-tools/)** application, authentication, **[**endpoint**](https://www.esecurityplanet.com/products/xdr-security-solutions/)**, and network activity** for indicators of exploitation or unusual outbound connections. - **Hunt for post-exploitation activity using **[**EDR**](https://www.esecurityplanet.com/products/edr-solutions/)** and file integrity monitoring** to identify malicious processes, persistence, or unauthorized changes. - **Rotate potentially exposed credentials**, API keys, tokens, and service account secrets, and review connected applications for unauthorized access. - **Test **[**incident response plans**](https://www.esecurityplanet.com/networks/incident-response-how-to-prepare-for-attacks-and-breaches/) and use attack simulation tools with scenarios around RCE and data exfiltration. Together, these measures can reduce blast radius from successful exploitation while strengthening resilience. ## **Bottom line** The rapid exploitation of CVE-2026-58231 after SAP released a patch highlights how little time security teams may have to remediate critical vulnerabilities before attackers begin targeting them.  This incident can also help CISOs frame [board](https://www.esecurityplanet.com/cybersecurity/black-hat-2026-improving-ciso-to-board-cyber-risk-reporting/) discussions around critical vulnerability exposure, business impact, and whether security investments can reduce risk fast enough.  [**Zero trust solutions**](https://www.esecurityplanet.com/products/zero-trust-security-solutions/)** can help reduce exposure by limiting access to critical systems and containing the blast radius when vulnerabilities are successfully exploited.  ** The post [SAP Commerce Cloud RCE Flaw Actively Exploited ](https://www.esecurityplanet.com/threats/sap-commerce-cloud-rce-flaw-actively-exploited/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "White House looks to engage private sector in offensive hacking ops" url: "https://www.scworld.com/news/white-house-looks-to-engage-private-sector-in-offensive-hacking-ops" lang: "en-US" type: "post" description: "Trump expands private-sector role in U.S. offensive cyber operations, raising governance concerns." last_modified: "2026-08-14T18:59:37+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/news/white-house-looks-to-engage-private-sector-in-offensive-hacking-ops" --- # White House looks to engage private sector in offensive hacking ops Trump expands private-sector role in U.S. offensive cyber operations, raising governance concerns. --- --- title: "DeepSeek Raises V4 API Prices More Than Fourfold as IPO Reports Surface" url: "https://www.channelinsider.com/ai/news-news-deepseek-v4-api-price-hike/" lang: "en-US" type: "post" description: "Chinese artificial intelligence developer DeepSeek is replacing flat API fees for its flagship V4 models with peak and off-peak pricing beginning at 16:00 UTC on Aug. 16, 2026. The change raises DeepSeek-V4-Flash and DeepSeek-V4-Pro API rates by about 57% to" last_modified: "2026-08-14T18:57:03+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/ai/news-news-deepseek-v4-api-price-hike/" --- # DeepSeek Raises V4 API Prices More Than Fourfold as IPO Reports Surface Chinese artificial intelligence developer DeepSeek is replacing flat API fees for its flagship V4 models with peak and off-peak pricing beginning at 16:00 UTC on Aug. 16, 2026. The change raises DeepSeek-V4-Flash and DeepSeek-V4-Pro API rates by about 57% to more than 1,100%, depending on the model, token type, and billing period. Developers and IT teams may need to reschedule flexible workloads or revise their AI spending forecasts. Under the [updated structure](https://api-docs.deepseek.com/quick_start/pricing/), peak hours run from 01:00 to 04:00 UTC and 06:00 to 10:00 UTC. During these windows, output token costs for DeepSeek-V4-Flash jump from $0.28 per million to $1.32 per million, falling to $0.66 during off-peak periods.  The premium DeepSeek-V4-Pro will see peak output prices climb from $0.87 to $3.96 per million, with off-peak rates set at $1.98. [DeepSeek stated](https://api-docs.deepseek.com/updates/#deepseek-v4-pro-update) on its website that it is adjusting prices “to allocate resources more reasonably.” ## Preparing for the public markets The price adjustments arrive as the Hangzhou-based startup shifts focus toward building a viable, long-term business model ahead of a potential initial public offering.  [Bloomberg reported](https://www.bloomberg.com/news/articles/2026-08-13/deepseek-increases-prices-for-ai-services-by-multiple-times) the company has kicked off IPO preparations, while [The Wall Street Journal reported](https://www.wsj.com/tech/ai/deepseek-lifts-ai-model-prices-fourfold-fbe893e7) DeepSeek is considering listing shares in Shanghai as early as the second quarter of next year following a funding haul of more than $7.4 billion. Despite the sharp increases, DeepSeek’s rates remain lower than many prominent Western and Chinese alternatives, continuing the low-cost strategy introduced with its[ V4 model family](https://www.techrepublic.com/article/news-apac-deepseek-v4-ai-model-huawei-ascend-chips-support/). Anthropic charges $50 per million output tokens for its Fable 5 model, while Chinese competitor Moonshot AI lists its Kimi K3 at $15 per million.  However, competition at the entry tier is tightening: [OpenAI’s lightweight GPT-5.6 Luna](https://www.channelinsider.com/ai/news-openai-gpt-5-6-luna-free-chatgpt/) charges $1.20 per million output tokens, slightly undercutting DeepSeek’s peak V4-Flash rate. Alongside the rate adjustments, DeepSeek rolled out an open-architecture developer preview titled DeepSeek Harness v0.1 to compete against automated workflow tools like [Anthropic’s Claude Code](https://www.channelinsider.com/channel-business/news-claude-code-auto-mode-default-2026/). ## The infrastructure reality check DeepSeek’s introduction of time-of-day billing signals that brute-force price discounting eventually collides with physical data center capacity. By establishing explicit peak hours, the company is attempting to smooth out global server traffic and curb costly infrastructure strain without turning away developer traffic entirely. For engineering teams and enterprise clients, the change turns API cost optimization into a scheduling challenge. Businesses running automated data extraction, background batch jobs, or non-urgent synthetic data generation can cut their expenses in half simply by programming workflows to run strictly during off-peak UTC windows. Conversely, companies providing real-time consumer apps face higher operational expenses during peak European and Asian morning business hours. While DeepSeek retains a significant price advantage over premium Western flagship models, the move ends the period of ultra-cheap, unconstrained usage, requiring developers to weigh real-time server responsiveness directly against their monthly infrastructure bills. **Read more: As DeepSeek revises its API rates, examine**[** ****how rising AI model costs are putting pressure on OpenAI, Meta, and xAI**](https://www.channelinsider.com/ai/ai-model-costs-efficiency-openai-meta-xai/)**.** The post [DeepSeek Raises V4 API Prices More Than Fourfold as IPO Reports Surface](https://www.channelinsider.com/ai/news-news-deepseek-v4-api-price-hike/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "Hackers arrested over €30M bank fraud exploiting service provider flaw" url: "https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/" lang: "en-US" type: "post" description: "Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts." last_modified: "2026-08-14T18:04:26+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.bleepingcomputer.com/feed/" wpe_sourcepermalink: "https://www.bleepingcomputer.com/news/security/hackers-arrested-over-30m-bank-fraud-exploiting-service-provider-flaw/" --- # Hackers arrested over €30M bank fraud exploiting service provider flaw Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers’ bank accounts. […] --- --- title: "CrowdStrike Expands Project QuiltWorks to SMBs via Channel" url: "https://www.channelinsider.com/security/crowdstrike-project-quiltworks-smb-channel/" lang: "en-US" type: "post" description: "CrowdStrike is expanding Project QuiltWorks, its industry-wide framework for addressing security risks tied to frontier AI, to small and midsize businesses (SMBs). The expansion will make QuiltWorks available to SMBs through distributors, cloud marketplaces, MSPs, and other channel partners, giving" last_modified: "2026-08-14T17:46:48+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/security/crowdstrike-project-quiltworks-smb-channel/" --- # CrowdStrike Expands Project QuiltWorks to SMBs via Channel CrowdStrike is expanding Project QuiltWorks, its industry-wide framework for addressing security risks tied to frontier AI, to small and midsize businesses (SMBs). The expansion will make QuiltWorks available to SMBs through distributors, cloud marketplaces, MSPs, and other channel partners, giving smaller organizations access to AI-driven vulnerability discovery and prioritization, expert-led remediation, and cyber risk protection that many have lacked the resources or expertise to operationalize on their own. ## Channel partners bring QuiltWorks to SMBs According to CrowdStrike, Arrow Electronics, Ignition Technology, Nord Security, Pax8, TD SYNNEX, Westcon-Comstor, and Zip Security will help bring Project QuiltWorks to SMBs through their global partner, MSP, and MSSP networks.  These networks will extend access to the coalition’s AI-driven vulnerability discovery and prioritization, remediation services, and financial protection. “Frontier AI has fundamentally shifted cybersecurity from risk management to business imperative,” said Daniel Bernard, chief business officer at CrowdStrike.  “SMBs are the backbone of the global economy and need the same standard of protection as the world’s largest enterprises. QuiltWorks has proven itself that standard, attempted by others, replicated by none. The channel is how QuiltWorks can reach every organization, regardless of size, sector, or geography.” Project QuiltWorks is a [CrowdStrike-led industry coalition](https://www.channelinsider.com/ai/crowdstrike-project-quiltworks-ai-vulnerabilities/) focused on helping organizations identify and address vulnerabilities as frontier AI accelerates vulnerability discovery and makes it more accessible.  The initiative uses frontier models from OpenAI and Anthropic and brings together partners including Accenture, EY, IBM Cybersecurity Services, and Kroll. ## Pax8 and TD SYNNEX see partner opportunity CrowdStrike said the expansion comes as more capable AI models make it easier for attackers to discover, chain, and exploit vulnerabilities at greater speed and scale.  The company argues that SMBs are particularly exposed because many lack the resources and expertise needed to deploy and manage advanced vulnerability detection and remediation capabilities on their own. Pax8 Chief Business Officer Robert Belgrave echoed these concerns, emphasizing the need for SMBs to have access to the same enterprise-grade security capabilities as larger organizations as AI makes sophisticated attacks easier to launch and scale. “As advanced attacks become easier to launch and scale, SMBs need access to the same level of protection as enterprise organizations,” said Belgrave. “With the QuiltWorks alliance, CrowdStrike and Pax8 are helping bring enterprise-grade cybersecurity to the SMB market through managed service providers and managed intelligence providers in the trusted channel community, giving businesses the tools, expertise, and guidance they need to stay resilient in the AI era,” he continued. Meanwhile, Mike Allers, vice president of security at TD SYNNEX North America, highlighted QuiltWorks as an opportunity for channel partners to offer SMB customers advanced security capabilities while building repeatable services around the Falcon platform. “Our partners already serve SMBs around the world, putting them on the front lines of how frontier AI is changing cybersecurity. Project QuiltWorks gives them a scalable way to bring advanced protection, expert-led remediation and cyber risk support to customers that may not have the resources to operationalize these capabilities on their own.” “By combining the Falcon platform with the reach and technical expertise of TD SYNNEX and our partner ecosystem, we can help more organizations improve resilience to those customers while creating a repeatable new growth opportunity for their businesses.” ### MSPs gain a new cybersecurity services opportunity The expanded initiative points to a cybersecurity market increasingly aware of the capabilities and lower barriers to entry that AI technologies can provide to malicious actors. This comes alongside broader [concerns around AI governance](https://www.channelinsider.com/security/pipefy-ai-governance-channel-partners/) and vulnerabilities as organizations of all sizes continue to adopt AI at a rapid pace. For MSPs, the shift presents both a challenge and an opportunity. Beyond helping SMBs defend against AI-powered threats, providers can help customers keep pace with a rapidly evolving threat landscape.  With many SMBs lacking the resources or in-house expertise to address these risks on their own, MSPs have an opportunity to serve as trusted advisors, providing the security expertise and guidance needed to navigate emerging AI-related threats. **Kiteworks **[**recently launched AHEP**](https://www.channelinsider.com/security/tools-and-platforms/kiteworks-ahep-outbound-email-security/)**, a new capability designed to detect risky outbound emails and prevent sensitive data from being sent to the wrong recipients. Read more about how the offering extends Kiteworks’ enterprise data governance platform to address human error in email.** The post [CrowdStrike Expands Project QuiltWorks to SMBs via Channel](https://www.channelinsider.com/security/crowdstrike-project-quiltworks-smb-channel/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "What GRC Failure Costs the Business" url: "https://www.scworld.com/executive-decision-guide/what-grc-failure-costs-the-business" lang: "en-US" type: "post" description: "Effective Assurance Turns Defensible Controls into Business Protection" last_modified: "2026-08-14T17:44:55+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/executive-decision-guide/what-grc-failure-costs-the-business" --- # What GRC Failure Costs the Business Effective Assurance Turns Defensible Controls into Business Protection --- --- title: "Amid AI-Driven Bug Tsunami, NIST Looks to…AI" url: "https://www.darkreading.com/vulnerabilities-threats/ai-driven-bug-tsunami-nist-looks-to-ai" lang: "en-US" type: "post" description: "Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer." last_modified: "2026-08-14T17:32:46+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.darkreading.com/rss.xml" wpe_sourcepermalink: "https://www.darkreading.com/vulnerabilities-threats/ai-driven-bug-tsunami-nist-looks-to-ai" --- # Amid AI-Driven Bug Tsunami, NIST Looks to…AI Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer. --- --- title: "Build or Buy? Making the Right Application Security Investment" url: "https://www.scworld.com/executive-decision-guide/build-vs-buy-in-application-security" lang: "en-US" type: "post" description: "Decision Starts with Trust Boundaries" last_modified: "2026-08-14T17:16:33+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/executive-decision-guide/build-vs-buy-in-application-security" --- # Build or Buy? Making the Right Application Security Investment Decision Starts with Trust Boundaries --- --- title: "Shell Investigates Clop Data Theft Claims Tied to PTC Flaw " url: "https://www.esecurityplanet.com/threats/shell-investigates-clop-data-theft-claims-tied-to-ptc-flaw/" lang: "en-US" type: "post" description: "Energy giant Shell is investigating a potential incident after the Clop ransomware group claimed it stole 89 GB of company data, including engineering drawings, facility reports, photographs, and project plans.  The claim places Shell among dozens of organizations reportedly targeted" last_modified: "2026-08-14T17:15:51+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/threats/shell-investigates-clop-data-theft-claims-tied-to-ptc-flaw/" --- # Shell Investigates Clop Data Theft Claims Tied to PTC Flaw  Energy giant Shell is investigating a potential incident after the Clop ransomware group claimed it stole 89 GB of company data, including engineering drawings, facility reports, photographs, and project plans.  The [claim](https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/) places Shell among dozens of organizations reportedly targeted through vulnerable, internet-facing product lifecycle management (PLM) systems. “We are aware of a potential incident. We are working with our security teams and relevant experts to investigate,” a Shell spokesperson told BleepingComputer. ## **Key takeaways** - **Shell is investigating a potential security incident** after Clop claimed it stole 89 GB of engineering, facility, and project data. - **Clop reportedly listed Shell among 43 new victims** in a campaign targeting internet-exposed PTC Windchill and FlexPLM environments. - **The attacks have been linked to CVE-2026-12569**, an improper input validation vulnerability affecting PTC Windchill and FlexPLM.** ** ## **Shell data theft claims linked to PTC vulnerability ** BleepingComputer reported that Shell was among 43 new organizations recently listed on Clop’s data leak site as part of a campaign targeting internet-exposed PTC Windchill and FlexPLM environments. PTC Windchill and FlexPLM are product lifecycle management (PLM) platforms designed to help organizations manage product information and processes across areas such as design, engineering, manufacturing, and supply chain operations. ### **How CVE-2026-12569 puts PTC systems at risk ** The attacks have been linked to [CVE-2026-12569](https://nvd.nist.gov/vuln/detail/CVE-2026-12569), an improper input validation vulnerability affecting PTC Windchill and FlexPLM.  Improper input validation vulnerabilities occur when an application fails to adequately verify or restrict information it receives, potentially allowing attackers to manipulate the application in unintended ways. ### **What Clop claims it stole from Shell ** Clop claims that it stole approximately 89 GB of data from Shell, including engineering drawings, scans of facility testing reports, photographs of facilities, and project plans.  If verified, the allegedly stolen files could provide insight into Shell’s projects, facilities, and engineering operations. Shell has acknowledged that it is investigating a potential security incident with its security teams and relevant experts but has not confirmed if its systems were actually compromised or that any data was stolen. ## **How to mitigate PTC Windchill and FlexPLM risks ** Organizations using PTC Windchill and FlexPLM should take a layered approach to reducing the risk of exploitation and data theft.  - **Apply **[**patches**](https://www.esecurityplanet.com/products/patch-management-service-providers/) for affected PTC Windchill and FlexPLM systems. - **Restrict unnecessary internet exposure** by placing PLM systems behind a zero-trust access layer. - **Enforce phishing-resistant **[**MFA**](https://www.esecurityplanet.com/products/passkey-solutions/) when available and least-privilege access for users, administrators, and service accounts. - **Use network segmentation**, [web application firewalls (WAFs)](https://www.esecurityplanet.com/products/top-web-application-firewall-waf-vendors/), and egress filtering to limit unauthorized access, lateral movement, and data exfiltration. - **Monitor application, authentication, **[**endpoint**](https://www.esecurityplanet.com/products/edr-solutions/)**, and **[**network**](https://www.esecurityplanet.com/products/best-network-monitoring-tools/)** activity** for suspicious behavior and indicators of compromise. - **Rotate potentially exposed credentials**, [API](https://www.esecurityplanet.com/products/api-security-tools/) keys, tokens, and other secrets, and hunt for IOCs of persistence if compromise is suspected. - **Test incident response plans** and use [attack simulation tools](https://www.esecurityplanet.com/products/breach-and-attack-simulation-bas-vendors/) with scenarios around data exfiltration and extortion. Collectively, these steps can help organizations reduce their overall exposure while building resilience. ## **Bottom line** The Shell investigation highlights how compromised enterprise platforms containing sensitive engineering and operational data can give attackers leverage for extortion.  Incidents like this can help frame board-level cyber risk around the business value of exposed data, the operational consequences of a compromise, and whether existing investments provide sufficient resilience against data theft and extortion.  **For organizations looking to reduce that exposure, a **[**Zero Trust**](https://www.esecurityplanet.com/trends/zero-trust-hype-vs-reality/)** approach can help limit access to sensitive systems and data. ** The post [Shell Investigates Clop Data Theft Claims Tied to PTC Flaw ](https://www.esecurityplanet.com/threats/shell-investigates-clop-data-theft-claims-tied-to-ptc-flaw/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "Apple warned hundreds of users of mercenary spyware attacks" url: "https://securityaffairs.com/197208/malware/apple-warned-hundreds-of-users-of-mercenary-spyware-attacks.html" lang: "en-US" type: "post" description: "Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by mercenary spyware. The company told" last_modified: "2026-08-14T17:09:46+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://securityaffairs.com/feed" wpe_sourcepermalink: "https://securityaffairs.com/197208/malware/apple-warned-hundreds-of-users-of-mercenary-spyware-attacks.html" --- # Apple warned hundreds of users of mercenary spyware attacks # Apple warns users of credible, targeted attacks and urges immediate verification, stronger protections, and expert assistance. Apple has sent a new round of threat notifications to users it believes may have been singled out by [mercenary spyware](https://securityaffairs.com/tag/commercial-spyware). The company [told TechCrunch](https://techcrunch.com/2026/08/13/if-apple-sends-you-a-push-notification-alerting-you-to-a-spyware-attack-take-it-seriously/) the latest alerts reached people in 110 countries, adding to notifications it has already issued in more than 150 countries since the programme began in 2021. _“Apple threat notifications are designed to inform and assist users who may have been individually targeted by mercenary spyware attacks, likely because of who they are or what they do. Such attacks are vastly more sophisticated than regular cybercriminal activity, as mercenary spyware attackers apply exceptional resources to target a very small number of specific individuals and their devices.” reads the alert. “Mercenary spyware attacks cost millions of dollars and often have a short shelf life, making them much harder to detect and prevent. The vast majority of users will never be targeted by such attacks.”_ That alone should reset the usual mental model. This isn’t about a suspicious app, a recycled phishing email, or the kind of opportunistic malware that lands wherever it can. Apple’s alerts concern highly targeted attacks against particular people, often because of their role, their work, or the people they know. The people most likely to receive these notifications include journalists, activists, politicians, diplomats, lawyers, and others whose devices may hold valuable conversations, contacts, documents, or location data. That does not mean every recipient has been fully compromised, but it does mean Apple has observed enough to treat the risk as credible. Apple has also changed how it delivers those alerts. A recipient may see a push notification directly on the iPhone lock screen and in Settings, receive an email from `threat-notifications@email.apple.com`, and find a warning banner after signing in to their Apple Account. The company says genuine notices will never ask users to click a link, open a file, install a profile, or provide a password or verification code by email or phone. [![](https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-39.png?resize=1024%2C331&ssl=1)](https://i0.wp.com/securityaffairs.com/wp-content/uploads/2026/08/image-39.png?ssl=1) _“Apple relies solely on internal threat-intelligence information and investigations to detect such attacks. Although our investigations can never achieve absolute certainty, Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.” continues the report. “We are unable to provide information about what causes us to issue threat notifications, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future.”_ That lack of detail can frustrate recipients. They want to know who targeted them, how the device was approached, and whether the attacker got in. Apple can’t safely answer most of those questions in public, because publishing the detection logic would give spyware vendors a free quality-assurance report. Nobody needs to make Pegasus-style operators more efficient. If you receive the warning, don’t panic and don’t start improvising. First, verify it by signing in directly at [account.apple.com](https://account.apple.com/): a genuine Apple threat notification appears at the top of the page. Then preserve the device, avoid unnecessary resets or changes until you have spoken to someone qualified, and seek expert help, such as the Digital Security Helpline run by Access Now. Apple recommends enabling Lockdown Mode, its high-security setting designed to reduce the attack surface available to sophisticated spyware. It also advises keeping devices updated, using a strong passcode with Touch ID or Face ID, turning on two-factor authentication, enabling Stolen Device Protection, using strong and unique passwords or passkeys, installing apps only through the App Store, and treating unexpected links or attachments as hostile until proven otherwise. _“Since 2021, we have sent Apple threat notifications multiple times a year as we have detected these attacks, and to date we have notified users in over 150 countries in total. The extreme cost, sophistication, and worldwide nature of mercenary spyware attacks make them some of the most advanced digital threats in existence today.” states the alert. “As a result, Apple does not attribute the attacks or resulting threat notifications to any specific attackers or geographical regions.”_ The wider value of these alerts goes beyond the device in front of the recipient. Citizen Lab researcher John Scott-Railton told TechCrunch that notifications can reveal that an entire community is being targeted, because people who receive them often seek help and their cases lead investigators to others. Most people will never receive one of these warnings. Apple says that plainly, and it is worth repeating because not every cybersecurity story needs to become a universal panic. But if your phone shows an Apple notice saying it detected a targeted mercenary spyware attack, assume it matters until an expert tells you otherwise. **Follow me on Twitter: **[**@securityaffairs**](https://twitter.com/securityaffairs)** and **[**Facebook**](https://www.facebook.com/sec.affairs)** and **[**Mastodon**](https://infosec.exchange/@securityaffairs)**** [**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**** **(**[**SecurityAffairs**](http://securityaffairs.co/wordpress/)** – hacking, Apple)** --- --- title: "RingCentral Breach Data Includes 1.6M Email Addresses, HIBP Says" url: "https://www.esecurityplanet.com/threats/news-ringcentral-breach-exposes-1-6m-emails-hibp/" lang: "en-US" type: "post" description: "RingCentral’s July security incident is now tied to a much larger public dataset than the company initially disclosed. Have I Been Pwned added the incident to its breach database on Aug. 13, saying leaked data contained 1.6 million unique email" last_modified: "2026-08-14T16:56:10+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/threats/news-ringcentral-breach-exposes-1-6m-emails-hibp/" --- # RingCentral Breach Data Includes 1.6M Email Addresses, HIBP Says RingCentral’s July security incident is now tied to a much larger public dataset than the company initially disclosed. Have I Been Pwned added the incident to its breach database on Aug. 13, saying leaked data contained 1.6 million unique email addresses along with names, phone numbers, and physical addresses. RingCentral previously said the incident affected only a “limited portion” of customers and that impacted customers would be contacted directly. The exposed contact data could increase phishing risk for affected users, although researchers have not confirmed a connection between the breach and a separate campaign impersonating RingCentral to steal Microsoft 365 credentials. ## HIBP puts a number on the RingCentral breach [Have I Been Pwned](https://haveibeenpwned.com/Breach/RingCentral) said RingCentral was targeted in July by a ShinyHunters “pay or leak” extortion campaign. The group later published data it claimed came from the platform, including 1.6 million [unique email addresses](https://www.esecurityplanet.com/threats/million-email-phishing-campaign-uses-text-salting/) along with names, phone numbers, and physical addresses. HIBP added the breach to its database on Aug. 13. RingCentral had disclosed the incident on July 28, saying it discovered a sophisticated social engineering campaign and stopped the unauthorized activity after detection. The company said it brought in a third-party forensic firm and had seen no new unauthorized activity after remediation. RingCentral said the incident affected data belonging to a limited portion of customers and that it was contacting those customers directly.  “If you are not contacted by RingCentral, you are not affected,” [the company](https://www.ringcentral.com/trust-center/security-bulletin.html) said. RingCentral also said its core platform was not impacted and services continued without disruption. ## Exposed data adds phishing risk, not a confirmed link [BleepingComputer](https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/) reported that the spoofed RingCentral emails failed SPF and DMARC checks and had no DKIM signature. Even so, receiving systems accepted the messages because RingCentral had been whitelisted. Clicking the lure sent victims to Greatness infrastructure, where attackers used adversary-in-the-middle or device-code phishing to target [Microsoft 365 accounts](https://www.esecurityplanet.com/threats/searchleak-flaw-exposed-sensitive-data-in-microsoft-365-copilot/). In some cases, attackers later used stolen authentication tokens to access Outlook, Teams, SharePoint, OneDrive, and other Microsoft 365 services. ZeroBEC said the RingCentral breach may have given Greatness operators a list of legitimate RingCentral users to target. Researchers could not verify that connection, however, so the breach and the phishing campaign remain separate incidents based on the available evidence. ## Audit RingCentral safe-sender rules and Microsoft 365 access ZeroBEC recommended checking safe-sender lists for blanket RingCentral exclusions. Instead of automatically trusting the domain, organizations can require messages to pass [email authentication checks](https://www.esecurityplanet.com/threats/kddi-data-breach-may-expose-14-2-million-email-accounts/). Administrators should also look for [suspicious Microsoft 365 sign-ins](https://www.esecurityplanet.com/threats/cisco-talos-exposes-artoken-microsoft-365-phishing-kit/) coming from hosting providers or VPN infrastructure. If an account may have been compromised, ZeroBEC recommended revoking access and refresh tokens and reviewing OAuth consent, Microsoft Graph activity, and [access to Microsoft 365 services](https://www.esecurityplanet.com/threats/barracuda-finds-malicious-microsoft-365-logins-are-blending-in/). For RingCentral customers, the HIBP listing adds another reason to be cautious about messages that use the company’s name. The newly cataloged breach data includes email addresses, names, phone numbers, and physical addresses, information that could make targeted phishing attempts more convincing. For security teams, the immediate takeaway is simpler: do not let brand-based allowlisting override email-authentication failures.  **Read next: Learn **[**how fake voicemail messages are stealing Google credentials**](https://www.esecurityplanet.com/news/news-fake-voicemail-google-credential-phishing/)** and what users should watch for.** The post [RingCentral Breach Data Includes 1.6M Email Addresses, HIBP Says](https://www.esecurityplanet.com/threats/news-ringcentral-breach-exposes-1-6m-emails-hibp/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "Google Meet can take notes for your in-person meetings now – here’s how it works" url: "https://www.zdnet.com/article/google-meet-take-notes-in-person-meetings-how-it-works/" lang: "en-US" type: "post" description: "Google's Gemini-driven meeting software can now save a transcript, send it to Google Drive, and email you a copy." last_modified: "2026-08-14T16:54:29+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.zdnet.com/news/rss.xml" wpe_sourcepermalink: "https://www.zdnet.com/article/google-meet-take-notes-in-person-meetings-how-it-works/" --- # Google Meet can take notes for your in-person meetings now – here’s how it works Google’s Gemini-driven meeting software can now save a transcript, send it to Google Drive, and email you a copy. --- --- title: "What Application Security Actually Controls" url: "https://www.scworld.com/tech-explainer/what-application-security-actually-controls" lang: "en-US" type: "post" description: "Six Trust Boundaries Define Application Security Coverage" last_modified: "2026-08-14T16:42:54+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/tech-explainer/what-application-security-actually-controls" --- # What Application Security Actually Controls Six Trust Boundaries Define Application Security Coverage --- --- title: "How to Evaluate DSPM and Data Discovery Platforms" url: "https://www.scworld.com/buyers-guide/how-to-evaluate-dspm-and-data-discovery-platforms" lang: "en-US" type: "post" description: "Finding Sensitive Data Is Not the Same as Reducing Risk" last_modified: "2026-08-14T16:25:10+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/buyers-guide/how-to-evaluate-dspm-and-data-discovery-platforms" --- # How to Evaluate DSPM and Data Discovery Platforms Finding Sensitive Data Is Not the Same as Reducing Risk --- --- title: "August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw" url: "https://www.computerworld.com/article/4209847/august-patch-tuesday-is-a-monster-751-fixes-with-an-exploited-windows-flaw.html" lang: "en-US" type: "post" description: "Microsoft’s August 2026 Patch Tuesday closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, CVE-2026-68820, an elevation of privilege in the Windows WinSock driver (afd.sys). Two more were disclosed but" last_modified: "2026-08-14T16:23:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.computerworld.com/security/feed/" wpe_sourcepermalink: "https://www.computerworld.com/article/4209847/august-patch-tuesday-is-a-monster-751-fixes-with-an-exploited-windows-flaw.html" --- # August’s Patch Tuesday is a monster: 751 fixes, with an exploited Windows flaw Microsoft’s [August 2026 Patch Tuesday](https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug) closes at 751 CVE entries (across all product families), with 108 rated as critical. One flaw is already exploited, [CVE-2026-68820](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68820), an elevation of privilege in the Windows [WinSock driver](https://learn.microsoft.com/en-us/windows/win32/winsock/windows-sockets-start-page-2) (afd.sys). Two more were disclosed but not exploited, [CVE-2026-62832](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832) ([User Profile Service](https://learn.microsoft.com/en-us/windows/win32/shell/user-profiles)) and [CVE-2026-72971](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971). This security-only release earns Patch Now for [Windows](https://learn.microsoft.com/en-us/windows/), [Office](https://learn.microsoft.com/en-us/office/) and [Exchange](https://learn.microsoft.com/en-us/exchange/); no SQL Server updates this month. Unfortunately, several critical issues affect server roles: [Windows DNS Server](https://learn.microsoft.com/en-us/windows-server/networking/dns/dns-top) carries a cluster of critical RCEs; [Windows DHCP Server](https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top) is the most-populated Microsoft product family at 14 entries. Testing should lead with printing and fonts and the [Remote Desktop client](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-clients), then a WinSock smoke test given the exploited [afd.sys](https://learn.microsoft.com/en-us/windows/win32/winsock/windows-sockets-start-page-2) flaw. The Readiness team has provided a helpful [infographic](https://applicationreadiness.com/perspectives/assurance-security-dashboard-august-2026-patch-tuesday/) on the deployment risks for this Microsoft August update. ## Known issues Both August client and server-side updates ship with empty known-issues lists. This may change over the coming days so checking back to the Microsoft Security Update Guide ([MSRC](https://msrc.microsoft.com/update-guide)) may be prudent. July’s open items have all closed: the Dell/Intel driver hold, the mid-July [WSUS](https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/get-started/windows-server-update-services-wsus) sync degradation, and the Emoji Panel GIF outage (August swaps in GIPHY). - On the server side, WSUS synchronisation error details stay suppressed. The August Windows Server 2025 ([KB5120233](https://support.microsoft.com/help/5120233)) and 2022 ([KB5120242](https://support.microsoft.com/help/5120242)) updates still list this, the detail pane removed to address a remote code execution flaw [CVE-2025-59287](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59287), with no published workaround. One July item has been dropped from the documentation without a resolution note: the Windows Server 2022 [BitLocker](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/) recovery prompt on first restart, for hosts carrying the PCR7 Group Policy condition. With no fix published, the Readiness team recommends that all recovery keys are (easily) retrievable before restarting freshly patched servers. ## Major revisions and mitigations Between the July and August Patch Tuesdays (15 July to 10 August), the [MSRC Security Update Guide](https://msrc.microsoft.com/update-guide/) revised 534 CVEs. Almost all these changes (458) were routine [Microsoft Edge](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business) and Chromium re-publications – none of which required customer action. That leaves 76 touching Microsoft’s own products, 60 of them flagged customer action required, including: - Windows storage and file system: four [NTFS](https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview) entries, all three July [ReFS](https://learn.microsoft.com/en-us/windows-server/storage/refs/refs-overview) elevation-of-privilege flaws, and two Brokering File System fixes. - Identity and federation: six [AD FS](https://learn.microsoft.com/en-us/windows-server/identity/ad-fs/ad-fs-overview) denial-of-service CVEs, plus two [Azure Active Directory](https://learn.microsoft.com/en-us/entra/identity/) entries. - Developer runtimes: nine [.NET](https://learn.microsoft.com/en-us/dotnet/core/introduction) and .NET Framework CVEs, with [PowerShell](https://learn.microsoft.com/en-us/powershell/scripting/overview) and [ASP.NET Core](https://learn.microsoft.com/en-us/aspnet/core/overview?view=aspnetcore-10.0) alongside. The Readiness team has reviewed the 751 published updates, and it appears that Microsoft has not published any mitigations for updates in this August release. ## Windows lifecycle and enforcement updates Microsoft has not published any service or enforcement deadlines for this August. The 13 October 2026 cluster stacks five migration tracks onto one date, with a second wave on 10 November; dates below come from the linked Microsoft lifecycle pages. - [Windows Server 2012](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2012) and [2012 R2](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2012-r2) ESU hits year three. [Windows 10 2016 LTSB](https://learn.microsoft.com/en-us/lifecycle/products/windows-10-2016-ltsb) reaches the end of extended support, and [Office LTSC 2021](https://learn.microsoft.com/en-us/lifecycle/products/office-ltsc-2021) and retail Office 2021 all end 13 October. - Windows Server 2022 drops to extended support on 13 October 2026, [security-only](https://learn.microsoft.com/en-us/lifecycle/products/windows-server-2022) to 14 October 2031. One diary note: Windows 11 24H2 Home and Pro reach [end of updates on 13 October 2026](https://learn.microsoft.com/en-us/windows/release-health/status-windows-11-24h2), two Patch Tuesdays out. Microsoft’s [August 2026 Patch Tuesday](https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug) is a security-only release: 109 Windows test-guidance entries, four High Risk (July had 14). Printing and fonts lead: win32kfull.sys is the most-patched binary at seven entries and carries three of the four High Risk flags (32-bit printing on 64-bit Windows and font rendering); the [Remote Desktop client](https://learn.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-clients) carries the fourth. The testing guidance below works through each product and feature grouping. ## Printing, fonts and graphics Three of the four High Risk flags sit in win32k and touch print or font paths: 32-bit application printing on 64-bit Windows (two) and font rendering (one). [GDI+](https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-gdi-start), the Windows Imaging Component, and the kernel graphics driver (dxgkrnl.sys, five entries) change alongside; estates with 32-bit line-of-business printing or font-heavy documents take this first. - Print from your 32-bit applications to physical and virtual (PDF or XPS) printers, using text-heavy, graphics-heavy, and multi-page documents, and repeat after each relaunch, orientation, scaling, and resolution change. - Render varied fonts, sizes, and styles across browsers, Office, PDF viewers, and Notepad, and confirm Print Preview matches the printed page – watch for clipping, distortion, or missing glyphs. - Copy and paste images between Paint, Word, and Excel at different bit depths, and open EMF and TIFF files. - Exercise the graphics kernel: full-screen [DirectX](https://learn.microsoft.com/en-us/windows/win32/directx), multi-monitor hot-plug, resolution, HDR, and DPI changes, and sleep/resume. ## Remote desktop and remote access The RDP client carries the fourth High Risk flag; the fixes touch every redirection path and multi-session behaviour. RemoteApp, the display pipeline, and the [RRAS](https://learn.microsoft.com/en-us/windows-server/remote/remote-access/remote-access) and SSTP VPN stack change alongside. - Open several concurrent RDP sessions, enable printer, clipboard, audio, drive, and smart card redirection together, and exercise each across the sessions, confirming none interferes with another. - Disconnect and reconnect a session, confirm redirected devices and drives reattach, and test a RemoteApp end to end. - Configure a standard client VPN and an SSTP VPN over HTTPS and confirm sustained connections across reconnects and a restart. ## Storage, file sharing and virtualization The [SMB](https://learn.microsoft.com/en-us/windows-server/storage/file-server/file-server-smb-overview) client and server, [NTFS](https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview) and UDFS, the virtualised file layers (Cloud Files, Projected File System, Work Folders), and the platform stack ([Hyper-V](https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/hyper-v-on-windows-server), virtual TPM, USB, and Windows Installer) all change. Standard Risk. - Connect to SMB shares (including RDMA, leases, and Continuous Availability), copy large sets both ways, and interrupt and reconnect a session; exercise NTFS extended attributes, UDF mounts, and cloud-file hydrate and dehydrate. - Create, checkpoint, and export a Generation 2 Hyper-V VM, enable a virtual TPM and [BitLocker](https://learn.microsoft.com/en-us/windows/security/operating-system-security/data-protection/bitlocker/), and connect USB storage and MIDI devices. - Install, repair, and uninstall an MSI package, and confirm UAC elevation still prompts. ## Telephony, networking and core services TAPI is the busiest component (11 entries) but carries only parity fixes; the rest spans TCP/IP, [HTTP.sys](https://learn.microsoft.com/en-us/iis/get-started/introduction-to-iis/introduction-to-iis-architecture), Windows Firewall, Bluetooth, wired 802.1X, and message queuing. Broad and shallow. - Exercise TAPI line status and dialling locations against a shared line, and verify HTTP.sys under IIS over HTTP/1.1, HTTP/2, and HTTP/3. - Confirm TCP/IP IPsec tunnels on IPv4 and IPv6, toggle Windows Firewall rules across a restart, pair a Bluetooth headset, authenticate wired 802.1X, and validate MSMQ send and receive. ## Office and SharePoint This August patch cycle affects click-to-run (C2R), Microsoft 365 Apps, and MSI deployments of Microsoft Office with the following updates: - On MSI Office 2016, apply the client updates: Access (KB5002813), the ACE database engine (KB5002832), the Office proofing and UI components (KB5002791, KB5002795), Outlook (KB5002755), VBA (KB5002900), and Word (KB5002901), then exercise macros, external data, embedded objects, and line-of-business add-ins. - On SharePoint Server, patch 2016, 2019, and Subscription Edition, then check browser-based editing; mind the rollback rules – server updates cannot be uninstalled and always require a reboot. ## Microsoft Exchange Server On-premises [Exchange](https://learn.microsoft.com/en-us/exchange/exchange-server) takes a security update this month, seven CVEs across Exchange Server 2016, 2019, and Subscription Edition: one critical elevation of privilege and six important, spanning further elevation of privilege, remote code execution, denial of service, spoofing, and a security feature bypass. - Apply the update from an elevated command prompt: an un-elevated run leaves Exchange services partially patched and broken. Then confirm every Exchange service returns and that the server reports healthy. - Exercise mail flow end to end: send and receive internal and external mail, drain the transport queues, and check connectors and transport rules; confirm Outlook (MAPI over HTTP), Outlook on the web, and the Exchange admin centre for sign-in and core actions. - Confirm Autodiscover and free/busy resolve, test any [hybrid](https://learn.microsoft.com/en-us/exchange/exchange-hybrid) connection to Exchange Online, and plan for the reboot the update requires – validate in a maintenance window before production. ## Developer tools: .NET The developer estate gets a broad, low-drama sweep; no SQL Server this month. Both the [.NET](https://learn.microsoft.com/en-us/dotnet/core/sdk) Framework (Windows Server 2012 to Windows 11 26H1 and Server 2025) and the modern runtime and SDK patch, including WPF and WinForms. - Install the .NET Framework and modern .NET runtime and SDK updates, run a representative set of WPF, WinForms, web, and command-line applications, confirm normal behaviour, and build and run a .NET project to check for regressions. The Readiness team recommends the following priorities for your larger enterprise deployments: - Start with printing and fonts: three of the four High Risk flags sit in win32k, so regress 32-bit printing, PDF and XPS export, font rendering, and Print Preview before anything else. - Take Remote Desktop next, the fourth High Risk flag, across the redirection paths, concurrent sessions, reconnects, RemoteApp, and SSTP VPN. - Give the busy but lower-risk areas a smoke pass: Telephony, the graphics kernel, DNS and DHCP, Active Directory, and the SMB stack. - Close out the rest: Office spans MSI 2016, SharePoint and Microsoft 365 Apps this month (Click-to-Run is in scope, unlike July), and .NET is a representative-application check. Each month, we break down the update cycle into product families, as defined by Microsoft, with the following groupings. ## Browsers After July’s 46-strong [Microsoft Edge](https://learn.microsoft.com/en-us/deployedge/microsoft-edge-for-business) (Chromium-based) haul, the browser family has nothing to report: August’s Security Update Guide carries no Edge-specific CVEs at all. It’s Margarita time – look busy or look elsewhere for patch-related testing and deployments. ## Microsoft Windows Windows carries the bulk again: 233 CVEs, 18 critical, the rest important bar one moderate. Elevation of privilege leads by volume (143 entries), but all but two of the 18 are rated as critical remote code execution vulnerabilities, on the network-facing server roles. - DHCP and DNS lead the critical-rated issues. [Windows DHCP Server](https://learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-top) takes 14 CVEs, the busiest component by far, topped by a critical remote code execution flaw ([CVE-2026-62823](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823), “Exploitation More Likely”), with DHCP Client adding four more. [Windows DNS Server](https://learn.microsoft.com/en-us/windows-server/networking/dns/dns-top) is the headline RCE risk: six entries, four of them critical ([CVE-2026-62878](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62878), [CVE-2026-62817](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62817), [CVE-2026-62820](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62820), [CVE-2026-65789](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65789)), reaching back to Server 2012. Patch the resolvers alongside the DHCP boxes. - A wider critical cluster. Beyond DNS, critical-rated issues also reach Microsoft QUIC, RRAS, the iSCSI Target Service, the WDS TFTP Server, the Remote Desktop Client, [GDI+](https://learn.microsoft.com/en-us/windows/win32/gdiplus/-gdiplus-overview-of-gdi--about) graphics and [Active Directory Certificate Services](https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/active-directory-certificate-services-overview); domain controllers take priority, and Print Spooler and WSUS are for once absent. - Most-patched tally. DHCP Server leads (14, one critical), Win32k next (13 across two groupings), then the [Telephony Service](https://learn.microsoft.com/en-us/windows/win32/tapi/microsoft-telephony-overview) (11), the DNS client resolver (10), [Windows Installer](https://learn.microsoft.com/en-us/windows/win32/msi/windows-installer-portal) (nine), and the [Windows Kernel](https://learn.microsoft.com/en-us/windows-hardware/drivers/kernel/windows-kernel-mode-kernel-library) and [NTFS](https://learn.microsoft.com/en-us/windows-server/storage/file-server/ntfs-overview) (eight each). Add this Windows update to your Patch Now schedule, with your DHCP and DNS servers updated first. ## Microsoft Office Microsoft released 120 [Office](https://learn.microsoft.com/en-us/office/) CVEs this month, 24 of them critical, remote code execution the through-line (62 entries). The packaging work sits on MSI Office 2016 and the SharePoint farms, but the exposure is overwhelmingly Click-to-Run: 89 of the 120 list [Microsoft 365 Apps for Enterprise](https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates) as affected, 20 of them critical, straight through the update channel. - Office clients – the critical RCE runs across Office, Word and Excel, mostly in document-rendering paths that fire on preview or open. The top-rated critical client entry, [CVE-2026-70130](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70130), lists Microsoft 365 Apps among its affected builds, so [Click-to-Run](https://learn.microsoft.com/en-us/deployoffice/overview-office-deployment-tool) estates are squarely in scope rather than sitting this one out, as they could in July. - [SharePoint Server](https://learn.microsoft.com/en-us/sharepoint/sharepoint-server) – three critical-rated vulnerabilities on the on-premises farms, led by [CVE-2026-65665](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65665), an RCE rated “Exploitation More Likely” (2019 and Subscription Edition), with two critical elevation-of-privilege entries behind it; a separate SharePoint Online spoofing flaw is fixed service-side. Nothing in Office is exploited this month, but that critical SharePoint RCE and 20 Click-to-Run critical-rated vulnerabilities argue against waiting. Add the August Office and SharePoint updates to your Patch Now schedule. ## Microsoft Exchange and SQL Server [Exchange Server](https://learn.microsoft.com/en-us/exchange/exchange-server) has seven CVEs across Exchange Server 2016, 2019 and Subscription Edition, as four build-specific updates ([KB5121573](https://support.microsoft.com/help/5121573) through [KB5121576](https://support.microsoft.com/help/5121576)). One is critical and six important; none is disclosed or exploited, but Exchange is internet-facing, so we would not wait. - Exchange Server (on-premises) – the critical entry is an elevation of privilege ([CVE-2026-62911](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911)); the heaviest of the rest is a remote code execution ([CVE-2026-62913](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62913)). Apply it from an elevated command prompt and plan for the reboot (the test-guidance section covers mail-flow). Subscription Edition is the go-forward release; 2016 and 2019 still being carried is a reprieve, not grounds to defer migration. - [SQL Server](https://learn.microsoft.com/en-us/sql/sql-server/what-is-sql-server?view=sql-server-ver17) – nothing to install. On-premises SQL Server ships nothing; the only SQL-branded entries are cloud-side Azure SQL fixes, resolved service-side. Add the on-premises Exchange update to your Patch Now schedule; SQL Server does not require anything this month. ## Microsoft developer tools Microsoft released 23 CVEs across its developer tooling this month, all rated as important: 13 in [.NET](https://learn.microsoft.com/en-us/dotnet/core/introduction) and the .NET Framework, and 10 across [Visual Studio Code](https://code.visualstudio.com/) and its Copilot extensions. - Microsoft .NET and .NET Framework – the runtime and framework are the focus this month, led by two remote code execution entries ([CVE-2026-62897](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62897), .NET Framework, and [CVE-2026-70354](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70354), .NET Core). The Framework rollups span Windows Server 2012 to Windows 11 26H1 and Server 2025; [Visual Studio](https://learn.microsoft.com/en-us/visualstudio/get-started/visual-studio-ide?view=visualstudio) 2022 17.14 and 2026 18.8 take their exposure through the bundled runtime. - Visual Studio Code and Copilot – have three remote code execution entries and security feature bypasses across the Python extension, Copilot Chat and the core editor. Add these developer-focused updates to your standard release schedule, behind this month’s Windows and Office priorities. ## Adobe (and third-party updates) Unusually, Adobe published an early-August emergency fix for a maximum-severity Adobe flaw ([CVE-2026-48449](https://nvd.nist.gov/vuln/detail/CVE-2026-48449)), an incorrect authorisation that runs code with no user interaction. This makes this an Adobe “whatever you have installed” Patch Now moment due to how Adobe tends to share code between products. This August, there were two third-party flaws on Microsoft’s third-party list: the [Trusted Computing Group’s TPM 2.0](https://learn.microsoft.com/en-us/windows/security/hardware-security/tpm/trusted-platform-module-overview) reference-code bugs [CVE-2026-6726](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6726) and [CVE-2026-6727](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-6727), both Important and issued by MITRE. If unpatched, a local attacker with TPM command access can work back to keys the chip should keep sealed, up to the RSA Endorsement Key behind device attestation. This completely defeats the purpose of the TPM chip – and, some would say, of migrating to Windows 11. Sorry, not sorry. --- --- title: "The Water Watch Center promises the cyber protection small water utilities need" url: "https://www.scworld.com/perspective/the-water-watch-center-promises-the-cyber-protection-small-water-utilities-need" lang: "en-US" type: "post" description: "Here’s the story about the industry’s attempt to offer cyber tools to small water utilities across the U.S." last_modified: "2026-08-14T16:16:08+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/perspective/the-water-watch-center-promises-the-cyber-protection-small-water-utilities-need" --- # The Water Watch Center promises the cyber protection small water utilities need Here’s the story about the industry’s attempt to offer cyber tools to small water utilities across the U.S. --- --- title: "I tested an Android app that lets anyone fight censorship – and shows your impact in real time" url: "https://www.zdnet.com/article/snowflake-volunteer-censorship-fighting-android-app-tor/" lang: "en-US" type: "post" description: "Most apps make our personal lives easier. This one helps the oppressed communicate by turning your phone into a Tor proxy. No technical knowledge needed." last_modified: "2026-08-14T16:15:34+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.zdnet.com/news/rss.xml" wpe_sourcepermalink: "https://www.zdnet.com/article/snowflake-volunteer-censorship-fighting-android-app-tor/" --- # I tested an Android app that lets anyone fight censorship – and shows your impact in real time Most apps make our personal lives easier. This one helps the oppressed communicate by turning your phone into a Tor proxy. No technical knowledge needed. --- --- title: "Apple is warning users of new spyware attacks – what to do if you’re a target" url: "https://www.zdnet.com/article/apple-warns-targetted-spyware-attacks-what-to-do/" lang: "en-US" type: "post" description: "New spyware attacks are aimed at journalists, activists, politicians, diplomats, and others. Here's how Apple is notifying them and what they should do - after turning on Lockdown Mode." last_modified: "2026-08-14T16:08:11+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.zdnet.com/news/rss.xml" wpe_sourcepermalink: "https://www.zdnet.com/article/apple-warns-targetted-spyware-attacks-what-to-do/" --- # Apple is warning users of new spyware attacks – what to do if you’re a target New spyware attacks are aimed at journalists, activists, politicians, diplomats, and others. Here’s how Apple is notifying them and what they should do – after turning on Lockdown Mode. --- --- title: "Dell XPS 13 review: The first budget laptop to rival Neo raises the bar for all PCs" url: "https://www.zdnet.com/article/dell-xps-13-spotlight/" lang: "en-US" type: "post" description: "The Dell XPS 13 flaunts build quality rarely seen at this price point, but not without trade-offs." last_modified: "2026-08-14T16:00:46+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.zdnet.com/news/rss.xml" wpe_sourcepermalink: "https://www.zdnet.com/article/dell-xps-13-spotlight/" --- # Dell XPS 13 review: The first budget laptop to rival Neo raises the bar for all PCs The Dell XPS 13 flaunts build quality rarely seen at this price point, but not without trade-offs. --- --- title: "ChatGPT’s new Computer History tracks your Mac activity to create a timeline – but should you let it?" url: "https://www.zdnet.com/article/chatgpt-computer-history/" lang: "en-US" type: "post" description: "Rolling out to ChatGPT's Mac app, Computer History creates a timeline from your activities across the apps and websites you use on your Mac. Is that a privacy risk?" last_modified: "2026-08-14T16:00:16+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.zdnet.com/news/rss.xml" wpe_sourcepermalink: "https://www.zdnet.com/article/chatgpt-computer-history/" --- # ChatGPT’s new Computer History tracks your Mac activity to create a timeline – but should you let it? Rolling out to ChatGPT’s Mac app, Computer History creates a timeline from your activities across the apps and websites you use on your Mac. Is that a privacy risk? --- --- title: "Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor’s Office" url: "https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office" lang: "en-US" type: "post" description: "One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well." last_modified: "2026-08-14T15:58:50+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.darkreading.com/rss.xml" wpe_sourcepermalink: "https://www.darkreading.com/cyberattacks-data-breaches/scottish-govt-data-breach-prosecutors-office" --- # Scottish Govt Suffers Potentially Widening Data Breach at Prosecutor’s Office One Caledonian government agency reported a breach, thanks to a third party that may have serviced other agencies as well. --- --- title: "AI Cyberattacks: How Threat Actors Use AI in Real Intrusions " url: "https://www.esecurityplanet.com/threats/ai-cyberattacks-how-threat-actors-use-ai-in-real-intrusions/" lang: "en-US" type: "post" description: "AI is becoming a bigger part of real-world cyberattacks, helping threat actors conduct intrusions, steal credentials, navigate networks, and identify valuable targets.   A Gambit Security investigation into three unrelated threat actors found attackers integrating AI throughout the intrusion lifecycle, extending" last_modified: "2026-08-14T15:09:46+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/threats/ai-cyberattacks-how-threat-actors-use-ai-in-real-intrusions/" --- # AI Cyberattacks: How Threat Actors Use AI in Real Intrusions  AI is becoming a bigger part of real-world cyberattacks, helping threat actors conduct intrusions, steal credentials, navigate networks, and identify valuable targets.   A Gambit Security [investigation](https://gambit.security/blog-posts/ai-across-the-intrusion-lifecycle) into three unrelated threat actors found attackers integrating AI throughout the intrusion lifecycle, extending its use beyond phishing and malware generation.  “One finding is worth separating out. In the first case the operator did not know the victim’s environment,” said the researchers. They explained, “He asked the [AI] model which of the databases mattered most, and it ranked them and pointed at the two the business could least afford to lose.” ## **Key takeaways of how threat actors use AI in attacks** - **AI is becoming an operational attack tool,** with threat actors using it for reconnaissance, exploitation, troubleshooting, lateral movement, and identifying high-value targets. - **AI can accelerate attacker decision-making,** as Claude Code analyzed unfamiliar victim environments and recommended systems and databases for The Gentlemen affiliate to target. - **Credential theft can be automated at scale,** with Zerofot using AI-developed tooling to collect 2,975 validated credentials from 1,742 victim hosts in less than two months. - **AI can support attack infrastructure,** with Claude Code managing Zerofot’s operational tasks while RAGE incorporated an LLM directly into its exploitation framework. - **Defenses must account for faster attacker workflows,** making identity controls, credential protection, segmentation, monitoring, and tested incident response plans increasingly important. ## **How threat actors are using AI ** | Threat actor / campaign | AI tools | How AI was used | Key finding | | --- | --- | --- | --- | | The Gentlemen affiliate | Claude Code | Reconnaissance, exploitation, lateral movement, scripting, system analysis, and target prioritization | AI helped navigate unfamiliar victim environments and identify high-value systems and data. | | Zerofot | Claude Code, OpenAI Codex | Scanner development, credential harvesting, infrastructure management, proxy management, and troubleshooting | AI-supported tooling helped collect 2,975 validated credentials from 1,742 victim hosts. | | RAGE | AI-generated code, DeepSeek-backed AI Orchestrator | Exploit development, credential harvesting, cryptominer deployment, and botnet operations | AI was used to help build attack tooling and was integrated directly into the exploitation framework. | ## **How attackers use AI across the intrusion lifecycle ** The findings show that [generative AI](https://www.esecurityplanet.com/threats/north-korean-hackers-weaponize-chatgpt-in-ai-driven-phishing-attack/) is becoming more than a tool for writing malicious code or preparing phishing attacks.  Across the three cases, threat actors used AI to automate tasks, troubleshoot problems, analyze compromised environments, and guide their next steps.   Rather than introducing fundamentally new attack techniques, AI primarily acted as a force multiplier, helping attackers execute established techniques faster and adapt their operations as circumstances changed. ### **The Gentlemen affiliate uses AI during active intrusions ** One of the clearest examples involved a suspected affiliate of [The Gentlemen](https://www.esecurityplanet.com/threats/these-gentlemen-arent-gentle-rapidly-evolving-ransomware-threat/) ransomware-as-a-service (RaaS) operation.  Gambit observed the threat actor using Claude Code during intrusions into at least six organizations and linked the actor to two earlier compromises.  The victims spanned several industries and countries, including an Australian energy [utility](https://www.esecurityplanet.com/news/canada-critical-infrastructure-attacks/), a financial services company in Mauritius, manufacturers in Thailand and the United States, and an IT services company in Malaysia. During these intrusions, [Claude Code](https://www.esecurityplanet.com/threats/claude-code-mcp-attack-enables-persistent-token-theft/) functioned almost like an interactive assistant for the attacker.  The operator used it to generate and execute reconnaissance and exploitation commands, create malicious scripts, modify firewall policies, and analyze business systems for information relevant to the operation.  AI could also respond to failed commands and errors by adjusting its approach and trying alternatives, demonstrating how an attacker can use an LLM interactively rather than simply requesting a piece of code and executing it manually. After obtaining domain credentials and VPN access, the operator used Claude to support reconnaissance and [lateral movement](https://www.esecurityplanet.com/networks/what-is-lateral-movement/) inside victim networks.  The AI analyzed output from network enumeration tools, identified systems where stolen [credentials](https://www.esecurityplanet.com/threats/fortibleed-turns-fortigate-access-into-enterprise-credential-theft/) provided administrative access, and recommended potential targets such as domain controllers, file servers, and backup servers.  In other instances, Claude analyzed application databases and [backup](https://www.esecurityplanet.com/products/best-backup-solutions-for-ransomware-protection/) infrastructure, helping the attacker identify valuable production data and understand where backups were stored. ### **Zerofot uses AI to harvest credentials at scale ** In the second case, a threat actor known as Zerofot demonstrated how AI can help attackers develop and operate malicious infrastructure at scale.  The operator used OpenAI Codex and Claude Code to build _auto_scan_, a custom scanner and credential harvester that searched internet-accessible systems for exposed configuration files, directories, and other files containing sensitive information.  This scanner extracted potential credentials and validated them against services including AWS, OpenAI, Anthropic, GitHub, GitLab, Stripe, and other providers. Zerofot amassed a substantial volume of stolen credentials, collecting 2,975 validated keys and credentials from 1,742 victim hosts between April and May 2026.  Those credentials included 661 SSH private keys, 635 AWS access keys associated with 214 accounts, 448 Google Gemini keys, 254 OpenAI keys, 205 GitHub tokens, and 176 Anthropic keys.  AI’s role in the Zerofot operation went beyond just developing the scanner.  Claude Code also handled IT and DevOps tasks needed to keep the operation running.  These included managing scanner infrastructure and proxies, checking network routes, modifying firewall configurations, and troubleshooting the credential-harvesting environment.  This illustrates another potential advantage for attackers: AI can support not only the intrusion itself but also the infrastructure and operational work surrounding it. ### **RAGE integrates AI into an exploitation framework ** In the third case, Gambit researchers examined RAGE, a custom Python framework designed to scan internet-facing services, exploit vulnerable deployments, harvest credentials, and deploy cryptocurrency miners.  The framework included modules targeting services such as Redis, Elasticsearch, Docker, Tomcat, Jenkins, Hadoop YARN, Confluence, and Supervisord.  Gambit researchers found indications that RAGE and many of its accompanying scripts were generated with AI, including comments and docstrings that preserved what appeared to be a model’s first-person, self-correcting reasoning. RAGE took AI integration another step by incorporating an LLM directly into the attack framework.  Its operator dashboard included a DeepSeek-backed “AI Orchestrator” designed to advise the operators running the mining botnet.  Together, the three cases show how attackers are using AI to conduct intrusions, automate credential theft, and build AI-assisted attack frameworks.  ## **How to reduce risk from AI-powered attacks ** Organizations can reduce the risks posed by AI-assisted attacks by strengthening identity and infrastructure security.  - **Enforce **[**MFA**](https://www.esecurityplanet.com/applications/mfa-advantages-and-weaknesses/)** and least-privilege access** for administrative accounts, cloud identities, and other privileged systems to reduce the impact of stolen credentials. - **Protect and regularly rotate credentials and secrets** by eliminating hardcoded credentials, using centralized secrets management, and favoring short-lived credentials where possible. - **Reduce exposure of internet-facing services** by restricting administrative interfaces and hardening services such as [VPNs](https://www.esecurityplanet.com/products/enterprise-vpn-solutions/), Redis, Docker, and other externally accessible systems. - **Segment networks and protect critical infrastructure** to restrict lateral movement and isolate domain controllers, backup servers, databases, and other high-value systems. - [**Monitor**](https://www.esecurityplanet.com/products/best-network-monitoring-tools/)** for suspicious identity and credential activity** such as unusual access-key creation, role assumption, secrets retrieval, privilege escalation, and abnormal authentication attempts. - **Test **[**incident response plans**](https://www.esecurityplanet.com/networks/incident-response-how-to-prepare-for-attacks-and-breaches/) and use [attack simulation](https://www.esecurityplanet.com/products/breach-and-attack-simulation-bas-vendors/) tools with scenarios around credential theft, data exfiltration and destruction, and ransomware. Together, these measures can help limit the blast radius of a successful attack while building resilience against AI-assisted threats.  ## **Bottom line** The more consequential shift is the compression of attacker workflows.  These cases show AI being used to interpret unfamiliar environments, troubleshoot failed actions, prioritize high-value assets, and maintain attack infrastructure — tasks that traditionally required more threat actor time and expertise.  As those capabilities improve, security programs may need to reassess assumptions around attacker dwell time and operational speed. **With attacker workflows accelerating, **[**Zero Trust**](https://www.esecurityplanet.com/trends/zero-trust-hype-vs-reality/)** can help organizations restrict access and limit lateral movement after an initial compromise. ** The post [AI Cyberattacks: How Threat Actors Use AI in Real Intrusions ](https://www.esecurityplanet.com/threats/ai-cyberattacks-how-threat-actors-use-ai-in-real-intrusions/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "Hackers exploit macOS Screen Sharing flaw to deploy Monero miner" url: "https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/" lang: "en-US" type: "post" description: "The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged." last_modified: "2026-08-14T14:59:55+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.bleepingcomputer.com/feed/" wpe_sourcepermalink: "https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/" --- # Hackers exploit macOS Screen Sharing flaw to deploy Monero miner The Netherlands’ National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged. […] --- --- title: "Silicon Valley Loves Jargon—and ‘Hill-Climbing’ Is Its Favorite New Phrase" url: "https://www.wsj.com/tech/ai/silicon-valley-loves-jargonand-hill-climbing-is-its-favorite-new-phrase-280eb224?mod=rss_Technology" lang: "en-US" type: "post" description: "A term that describes a computer-science algorithm is the metaphor du jour among AI types—and coming soon to a boardroom near you." last_modified: "2026-08-14T14:55:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://feeds.content.dowjones.io/public/rss/RSSWSJD" wpe_sourcepermalink: "https://www.wsj.com/tech/ai/silicon-valley-loves-jargonand-hill-climbing-is-its-favorite-new-phrase-280eb224?mod=rss_Technology" --- # Silicon Valley Loves Jargon—and ‘Hill-Climbing’ Is Its Favorite New Phrase A term that describes a computer-science algorithm is the metaphor du jour among AI types—and coming soon to a boardroom near you. --- --- title: "Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations" url: "https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/" lang: "en-US" type: "post" description: "Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents" last_modified: "2026-08-14T14:49:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.infosecurity-magazine.com/rss/news/" wpe_sourcepermalink: "https://www.infosecurity-magazine.com/news/exfilsquads-13-organizations/" --- # Researchers Confirm ExfilSquad’s Access to Sensitive Data Across 13 Organizations Researchers have verified that ExfilSquad possesses sensitive data stolen from at least 13 victims after the extortion group published leaked datasets via torrents --- --- title: "New Android Malware Chain Turns Bank Support Scams Into NFC Card Fraud" url: "https://www.esecurityplanet.com/cybersecurity-threats/news-windrelay-spynote-android-nfc-fraud/" lang: "en-US" type: "post" description: "It took a threat actor just 13 minutes to turn a routine bank support call into a remote, live contactless card fraud operation. Group-IB found malware used in a campaign targeting victims via fake bank support calls, in which attackers" last_modified: "2026-08-14T14:40:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/cybersecurity-threats/news-windrelay-spynote-android-nfc-fraud/" --- # New Android Malware Chain Turns Bank Support Scams Into NFC Card Fraud It took a threat actor just 13 minutes to turn a routine bank support call into a remote, live contactless card fraud operation. Group-IB found malware used in a campaign targeting victims via fake bank support calls, in which attackers persuaded them to install malicious software on their Android devices. Once the phone was compromised, the attackers had a platform to commit financial fraud. The campaign reflects a broader shift in mobile fraud toward attacks that chain device compromise with payment technology. NFC-enabled malware has already emerged as a growing threat, but WindRelay shows how that technique can be chained with another malware to create a more complete fraud operation. ## One compromised phone, two ways to steal money The attack begins with [social engineering](https://www.esecurityplanet.com/news/news-fake-voicemail-google-credential-phishing/). In the case investigated by Group-IB, criminals used a phone call to convince the victim to install a seemingly legitimate app. Group-IB found that the app was a customized version of SpyNote, an Android remote access trojan (RAT). To make the attempt more credible, the attackers personalized the malware with [information about the target](https://www.esecurityplanet.com/threats/cybercriminals-turn-to-indirect-prompt-injection-attacks/), including the victim’s name. The SpyNote app was [sideloaded](https://www.techrepublic.com/article/news-android-sideloading-verification-update/), meaning it was installed from outside the official Google Play Store. The victim was also persuaded to grant the Android Accessibility Service permission, thereby enabling the attacker to access screen content remotely. That access was the turning point. Once SpyNote was running, the attacker could remotely control the phone and install WindRelay. The two malware therefore served different roles in the same attack: SpyNote controlled the phone, while WindRelay handled the card fraud. Group-IB found that the attackers took out a loan in the victim’s name and used WindRelay to transmit live NFC transactions [after instructing the victim to make a payment](https://www.malwarebytes.com/blog/mobile/2026/08/new-android-malware-lets-criminals-use-your-bank-card-in-real-time).  The result was a single attack that [combined conventional banking fraud](https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/) with contactless card fraud, rather than relying on just one route to steal money. ## Why an attack this complex could still work An interesting aspect of this campaign is how complex it appears yet how effective it is. The attacker must first conduct reconnaissance on the target before launching a call. They need to persuade a target not just to install an app but to sideload it, and convince them to use their card.  Each step involves a different kind of trick to work.  ![windRelay NFC](https://assets.esecurityplanet.com/uploads/2026/08/windRelay-NFC-1024x930.png)Image: Group-IB That helps explain why the campaign should not be dismissed simply because it requires several things to go right. Once the attacker has convinced them to trust the call and grant SpyNote the necessary access, much of the remaining operation happens remotely. Google recommends [getting apps from Google Play](https://www.techrepublic.com/article/news-google-ai-blocked-1-75-million-apps-2025/) and warns that software from other sources can put devices and personal information at risk. WindRelay is notable not because it introduces an entirely new form of fraud, but because it connects several existing techniques into one fast-moving attack. A fake support call can lead to remote device control, banking fraud, and live NFC abuse within minutes. For users, the clearest warning sign comes much earlier: a bank representative should not need you to sideload an app, grant Accessibility access, or use your payment card to resolve a support issue. **Other News: Researchers have warned that attackers may be able to abuse synced passkeys stored in **[**Google Password Manager**](https://www.esecurityplanet.com/threats/news-google-password-manager-synced-passkey-attacks/)**, potentially turning a compromised Google account into a broader authentication risk.** The post [New Android Malware Chain Turns Bank Support Scams Into NFC Card Fraud](https://www.esecurityplanet.com/cybersecurity-threats/news-windrelay-spynote-android-nfc-fraud/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "DATA SECURITY MARKET OVERVIEW REPORT 2026" url: "https://www.geek-guy.com/competitivereport/data-security-market-overview-report-2026/" lang: "en-US" type: "post" description: "Comprehensive Analysis of Trends, Market Changes, Technology Shifts & Statistics EXECUTIVE SUMMARY The global data security market is experiencing unprecedented growth driven by escalating cyber threats, digital transformation, and stringent regulatory requirements. The market has reached $17.21 billion in 2026" last_modified: "2026-08-14T14:29:04+00:00" categories: [Competitive Reports] custom_fields: botwriter_image_prompt_last: "DATA SECURITY MARKET OVERVIEW REPORT 2026" botwriter_stockphoto_prompt: "DATA SECURITY MARKET OVERVIEW REPORT 2026" botwriter_image_prompt_last_provider: "stockphoto" --- # DATA SECURITY MARKET OVERVIEW REPORT 2026 _Comprehensive Analysis of Trends, Market Changes, Technology Shifts & Statistics_ ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-11.png) **EXECUTIVE SUMMARY** The global data security market is experiencing unprecedented growth driven by escalating cyber threats, digital transformation, and stringent regulatory requirements. The market has reached **$17.21 billion in 2026** and is projected to grow at a **CAGR of 17.12%** through 2031, reaching **$37.93 billion**. This report provides comprehensive analysis across all major segments including cloud security, AI-driven defense, zero trust architectures, post-quantum cryptography, and regional market dynamics. ![](https://www.geek-guy.com/wp-content/uploads/2026/08/the-insta360-go-3s-retro-bundle-makes-photography-fun-again.jpg) ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-14.png) **1. MARKET SIZE & GROWTH STATISTICS** **1.1 Global Data Security Market** | Metric | Value | Source | | --- | --- | --- | | 2026 Market Size | $17.21 billion | Mordor Intelligence | | 2031 Forecast | $37.93 billion | Mordor Intelligence | | CAGR (2026-2031) | 17.12% | Mordor Intelligence | | Alternative Estimate | $22.16 billion (2024) → $49.97 billion (2031) | Valuates | | CAGR (Alternative) | 12.5% | Valuates | **1.2 Cloud Security Market** | Metric | Value | Source | | --- | --- | --- | | 2026 Market Size | $34.37 billion | MarketsandMarkets | | 2031 Forecast | $59.34 billion | MarketsandMarkets | | CAGR (2026-2031) | 11.5% | MarketsandMarkets | | 2025 Market Size | $39.1 billion | Grand View Research | | 2033 Forecast | $97.9 billion | Grand View Research | | CAGR (2026-2033) | 12.2% | Grand View Research | **1.3 Zero Trust Security Market** | Metric | Value | Source | | --- | --- | --- | | 2026 Market Size | $54.31 billion | TechRT | | CAGR (2026-2030) | 21.4% | TechRT | | 2030 Forecast | 2.6x 2025 market size | TechRT | **1.4 AI in Cybersecurity Market** | Metric | Value | Source | | --- | --- | --- | | 2025 Market Size | $29.6 billion | Precedence Research | | 2026 Forecast | $35.4 billion | Axis Intelligence | | Single-Year Growth (2025-2026) | +19.4% | Axis Intelligence | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-13.png) **2. DATA BREACH STATISTICS & COST ANALYSIS** **2.1 Global Breach Costs** | Metric | Value | Source | | --- | --- | --- | | Average Global Breach Cost (2026) | ~$5 million (+12% YoY) | IBM 2026 Study | | United States Average | $11.5 million | IBM 2026 Study | | Healthcare Industry | $6.64 million | HIPAA Journal | | Healthcare (Alternative) | $7.42 million | ORDR | | Healthcare (Highest) | $10.22 million | MedHA Cloud | **2.2 Breach Frequency by Industry** | Industry | Breaches (2025) | Records Exposed | Cost per Breach | | --- | --- | --- | --- | | Healthcare | 772 large-scale | 139+ million | $10.22M | | Finance | N/A | N/A | $6.64M | | Technology | N/A | N/A | N/A | **2.3 Cumulative Impact** - **Total Healthcare Breaches (2009-2026):** 1+ billion records affected - **Individuals Impacted:** 2.9x current U.S. population - **Average Organizational Cost:** $7.42 million per breach ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-19.png) **3. TECHNOLOGY SHIFTS & EMERGING TRENDS** **3.1 Zero Trust Architecture** | Metric | Value | Source | | --- | --- | --- | | Adoption Intent (2026) | 82% | ORDR | | Full Implementation Rate | 17% | ORDR | | Breach Savings | $1.76 million | Axis Intelligence | | Adoption Rate | 63% | Axis Intelligence | | NHI Ratio (Network Health Index) | 144:1 | Axis Intelligence | | Current Effectiveness Rating | 6/10 | Cybersecurity Insiders PDF | **Implementation Gap:** 65-point divide between strategic intent and operational reality. Organizations face architectural fragmentation, overlapping tools, and policy drift across hybrid/multi-cloud environments. **3.2 AI-Driven Security** | Metric | Value | Source | | --- | --- | --- | | Market Size (2026) | ~$35 billion | QuantumRun | | Enterprise Use Cases | Threat intelligence, security analytics, identity protection | MarketsandMarkets | | Key Capabilities | Automated threat detection, incident response automation, model security | Axis Intelligence | **AI Security Statistics:** - **Attack Success Rate:** AI-powered attacks are winning faster than traditional defenses - **Governance Gaps:** 67% of enterprises lack comprehensive AI security governance frameworks - **Detection Time:** AI reduces mean time to detect (MTTD) by 40-60% **3.3 Post-Quantum Cryptography (PQC)** | Metric | Value | Source | | --- | --- | --- | | NIST Standards Finalized | FIPS 203, 204, 205 (2024) | ITECS | | Quantum Threat Timeline | 10,000 qubits needed to break current encryption | Informed Clearly | | EU Migration Deadline | End of 2026 | Informed Clearly | | Harvest-Now-Decrypt-Later Risk | Critical | The Quantum Insider | **PQC Adoption Status:** - **Enterprise Implementation:** Moving from research to production - **Migration Urgency:** Organizations must adopt PQC now to protect against quantum threats - **Standardization:** NIST FIPS 203-205 provide standardized algorithms for quantum-resistant encryption **3.4 Cloud Security Evolution** | Trend | Description | Impact | | --- | --- | --- | | Multi-cloud visibility | Unified security platforms across diverse infrastructure | Essential for compliance | | API security | Protection of cloud APIs and remote users | Growing attack surface | | Identity-centric security | Zero trust principles applied to cloud workloads | Market driver | **Cloud Security Threat Landscape (2026):** - Increasing sophistication of attacks targeting cloud workloads - Focus on identities, APIs, and remote users - Multi-cloud environments create new attack vectors ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-14.png) **4. REGIONAL MARKET ANALYSIS** **4.1 North America** | Metric | Value | Source | | --- | --- | --- | | Market Share (2025) | 35.9% | Market.us | | Revenue (2025) | $0.62 billion | Market.us | | Dominance Drivers | Advanced digital infrastructure, early technology adoption, high risk awareness | Market.us | **4.2 Asia-Pacific** - **Growth Rate:** Fastest-growing region globally - **Drivers:** Rapid enterprise digitization, cloud migration projects, national cybersecurity strategies, smart city investments - **Key Markets:** China, India, Japan, South Korea, Australia **4.3 Europe** - **EU Migration Deadlines:** End of 2026 for PQC adoption - **Regulatory Pressure:** GDPR, NIS2 Directive driving market growth - **Smart City Investments:** Creating new opportunities for cloud security vendors **4.4 Regional Market Share (Projected)** | Region | 2025 Share | Growth Rate | Key Drivers | | --- | --- | --- | --- | | North America | ~36% | Moderate | Enterprise spending, regulatory compliance | | Asia-Pacific | ~28% | Highest | Digital transformation, cloud adoption | | Europe | ~22% | High | Regulatory pressure, smart cities | | Rest of World | ~14% | Moderate | Emerging markets digitization | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-12.png) **5. VENDOR LANDSCAPE & COMPETITIVE DYNAMICS** **5.1 Cloud Security Market Leaders** | Company | Headquarters | Key Products | Market Position | | --- | --- | --- | --- | | Microsoft (US) | Redmond, WA | Azure Security, Defender | Market Leader | | Palo Alto Networks (US) | Santa Clara, CA | Prisma Cloud | Strong Challenger | | AWS (US) | Seattle, WA | Security Hub, GuardDuty | Platform Leader | | Wiz (US) | Mountain View, CA | Cloud Security Posture Management | Niche Leader | | Zscaler (US) | San Jose, CA | Private Access | Zero Trust Leader | | Fortinet (US) | Sunnyvale, CA | FortiCloud | Cost-Effective | | Akamai (US) | Cambridge, MA | Cloud Security Platform | CDN Integration | | Cloudflare (US) | San Francisco, CA | Cloudflare One | Edge Security | | IBM (US) | Armonk, NY | QRadar, Cloud Pak for Security | Enterprise Suite | | CrowdStrike (US) | Sunnyvale, CA | Falcon Cloud Security | EDR Leader | **5.2 Data Security Market Leaders** | Company | Headquarters | Key Products | Market Position | | --- | --- | --- | --- | | IBM Corporation | Armonk, NY | QRadar, Guardium | Enterprise Leader | | Microsoft Corporation | Redmond, WA | Purview, Defender | Platform Leader | | Oracle Corporation | Austin, TX | Data Security Cloud | Database Focus | | Thales Group | Limours, France | CyberArk, Security Key | Identity Focus | | Cisco Systems Inc. | San Jose, CA | Umbrella, SecureX | Network Integration | **5.3 Competitive Dynamics** - **Market Consolidation:** M&A activity increasing as vendors seek AI capabilities - **Partnership Models:** Vendors forming strategic alliances to expand offerings - **Differentiation:** Focus on AI-driven detection, unified platforms, automated response - **Challenges:** Workforce shortages, uneven adoption maturity in developing markets ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-15.png) **6. KEY MARKET DRIVERS & CHALLENGES** **6.1 Market Drivers** | Driver | Impact Level | Description | | --- | --- | --- | | Rising Cyber Threats | Critical | Sophisticated attacks targeting cloud, identities, APIs | | Digital Transformation | High | Cloud migration, IoT adoption, remote work | | Regulatory Compliance | High | GDPR, CCPA, NIS2, HIPAA requirements | | AI/ML Adoption | High | Need for AI-powered security tools | | Quantum Computing Threat | Critical | PQC migration urgency | **6.2 Market Challenges** | Challenge | Impact Level | Description | | --- | --- | --- | | Workforce Shortages | High | Security talent gap in developing markets | | Architectural Fragmentation | Medium | Overlapping tools, policy drift | | Multi-Cloud Complexity | Medium | Visibility and control across diverse platforms | | Cost of Breaches | Critical | Average $5M+ per breach driving urgency | | PQC Migration Timeline | Critical | EU deadline end-2026 creating pressure | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-17.png) **7. TECHNOLOGY SHIFT ANALYSIS** **7.1 From Perimeter to Zero Trust** **Traditional Security → Zero Trust Architecture** - **Perimeter-based:** Network boundaries, firewalls - **Zero Trust:** Identity-centric, least privilege, continuous verification - **Market Impact:** 63% adoption rate, $54.31B market size **7.2 From Reactive to AI-Driven Defense** **Traditional Security → AI-Powered Security** - **Reactive:** Signature-based detection, manual response - **AI-Driven:** Predictive threat intelligence, automated response, anomaly detection - **Market Impact:** $35B market size, 19.4% single-year growth **7.3 From Static to Post-Quantum Cryptography** **Current Encryption → Quantum-Resistant Algorithms** - **Current State:** RSA, ECC vulnerable to quantum attacks - **Post-Quantum:** NIST FIPS 203-205 standardized algorithms - **Timeline:** EU migration deadline end-2026 - **Threat:** Harvest-now-decrypt-later attacks **7.4 From Single-Cloud to Multi-Cloud Security** **Traditional → Unified Multi-Cloud Platform** - **Single-Cloud:** Vendor-specific tools, siloed visibility - **Multi-Cloud:** Unified platforms, consistent policy enforcement - **Market Impact:** 11.5% CAGR through 2031 ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-17.png) **8. STATISTICAL CORRELATIONS & PREDICTIONS** **8.1 Breach Cost Correlation** | Factor | Correlation with Breach Cost | Trend | | --- | --- | --- | | Industry Type | Healthcare: +45% vs average | Rising | | Cloud Adoption | Multi-cloud: +20% complexity cost | Increasing | | AI Maturity | High AI defense: -30% breach frequency | Improving | | Zero Trust Implementation | 17% full implementation: $1.76M savings | Proven ROI | **8.2 Market Growth Predictions** | Year | Data Security Market | Cloud Security Market | Zero Trust Market | | --- | --- | --- | --- | | 2025 | ~$15B | ~$39.1B | ~$44.3B | | 2026 | $17.21B | $34.37B | $54.31B | | 2027 | ~$20.1B | ~$38.3B | ~$65.8B | | 2028 | ~$23.4B | ~$42.8B | ~$79.9B | | 2029 | ~$27.2B | ~$47.9B | ~$97.1B | | 2030 | ~$31.5B | ~$53.6B | ~$118.2B | | 2031 | $37.93B | $59.34B | ~$143.4B | **8.3 Regional Growth Predictions** | Region | 2025 Share | 2031 Forecast Share | CAGR | | --- | --- | --- | --- | | North America | 36% | ~32% | 8-10% | | Asia-Pacific | 28% | ~35% | 15-18% | | Europe | 22% | ~24% | 12-14% | | Rest of World | 14% | ~9% | 10-12% | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-16.png) **9. CRITICAL INSIGHTS & RECOMMENDATIONS** **9.1 For CISOs & Security Leaders** - **Zero Trust is Non-Negotiable:** 82% adoption intent but only 17% full implementation – prioritize operational reality over strategic intent - **AI Defense Investment:** $35B market indicates critical need for AI-powered threat detection and automated response - **PQC Migration Urgency:** EU end-2026 deadline creates immediate migration pressure – start now to avoid harvest-now-decrypt-later attacks - **Multi-Cloud Visibility:** Unified platforms essential for compliance and threat management across diverse infrastructure **9.2 For Security Operations (SecOps)** - **MTTD Reduction:** AI-driven security reduces mean time to detect by 40-60% - **Automated Response:** Zero trust implementation saves $1.76M per breach on average - **Playbook Integration:** Focus on integrating AI capabilities into existing incident response workflows - **Skill Gap Mitigation:** Leverage AI-powered tools to compensate for workforce shortages **9.3 For Security Analysts** - **Threat Hunting:** Prioritize cloud-native threats, identity-based attacks, and API exploitation - **Data Correlation:** Cross-reference breach statistics with industry-specific risk profiles - **Query Optimization:** Focus on multi-cloud visibility queries and zero trust policy analysis - **Trend Monitoring:** Track PQC migration progress and AI threat evolution **9.4 For Security Engineers** - **CI/CD Integration:** Implement security scanning in cloud-native development pipelines - **API Security:** Focus on protecting cloud APIs and remote user access points - **Identity Management:** Implement least privilege access across all cloud environments - **Compliance Automation:** Leverage unified platforms for consistent policy enforcement ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-18.png) **10. DATA SOURCES & METHODOLOGY** **10.1 Primary Data Sources** - Mordor Intelligence (Market size, forecasts) - MarketsandMarkets (Cloud security analysis) - Grand View Research (Market segmentation) - Axis Intelligence (Breach statistics, AI security) - IBM 2026 Cost of a Data Breach Study - HIPAA Journal (Healthcare breach data) - ORDR (Zero trust adoption rates) - TechRT (Zero trust market analysis) **10.2 Data Collection Period** - **Primary Data:** August 2026 - **Historical Data:** 2009-2026 (healthcare breaches) - **Forecast Period:** 2026-2034 (various market segments) **10.3 Confidence Scoring** | Data Type | Confidence Level | Source Reliability | | --- | --- | --- | | Market Size (2026) | High | Multiple vendor reports | | Breach Statistics | Medium-High | IBM, HIPAA Journal | | Regional Forecasts | Medium | Vendor-specific methodologies | | Technology Trends | High | Industry analysis, expert interviews | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-15.png) **11. CONCLUSION** The data security market in 2026 represents a critical inflection point driven by: - **Escalating Threat Landscape:** Average breach costs rising to $5M globally, healthcare at $10.22M - **Technology Convergence:** AI-driven defense meets quantum computing threats - **Regulatory Pressure:** GDPR, NIS2, HIPAA creating compliance urgency - **Market Maturation:** Zero trust adoption plateauing at 17% full implementation despite 82% intent **Key Takeaway:** Organizations must move beyond strategic intent to operational reality in zero trust implementation, while simultaneously addressing the critical PQC migration timeline and leveraging AI-powered security tools to combat increasingly sophisticated threats. The market’s 17.12% CAGR through 2031 reflects both opportunity and necessity in an era where data breaches are no longer exceptions but expected business costs. ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-15.png) **APPENDIX: QUICK REFERENCE TABLES** **A1. Market Size Summary (2026)** | Segment | Market Size | CAGR (to 2031) | Key Driver | | --- | --- | --- | --- | | Data Security | $17.21B | 17.12% | Rising threats, regulations | | Cloud Security | $34.37B | 11.5% | Multi-cloud adoption | | Zero Trust | $54.31B | 21.4% | Identity-centric security | | AI Security | $35.4B | N/A | Automated threat detection | **A2. Breach Cost by Industry (2026)** | Industry | Average Cost | Records Exposed | Frequency | | --- | --- | --- | --- | | Healthcare | $10.22M | 139+ million/year | 772 large-scale | | Finance | $6.64M | N/A | N/A | | Technology | N/A | N/A | N/A | **A3. Regional Market Share (2025)** | Region | Share | Growth Rate | Key Challenge | | --- | --- | --- | --- | | North America | 36% | 8-10% | Talent shortage | | Asia-Pacific | 28% | 15-18% | Regulatory alignment | | Europe | 22% | 12-14% | PQC migration | | Rest of World | 14% | 10-12% | Infrastructure gaps | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-19.png) **Report Generated:** August 2026    **Data Currency:** Real-time as of August 2026    **Next Update:** Scheduled for Q1 2027    **Contact:** For data verification or additional analysis, contact the Cybersecurity Intelligence Engine (CIE) team --- --- title: "AI Security Failures, Active Exploits, and Breaches Define the Week in August 2026" url: "https://www.esecurityplanet.com/weekly-roundup/ai-security-failures-active-exploits-and-breaches-define-the-week-in-august-2026/" lang: "en-US" type: "post" description: "This week’s cybersecurity landscape combined actively exploited infrastructure flaws, ransomware resilience, social engineering, large-scale data breaches, and an expanding set of risks involving AI-generated code and autonomous agents. Research presented around DEF CON 34 and Black Hat 2026 also showed" last_modified: "2026-08-14T14:03:32+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.esecurityplanet.com/feed/" wpe_sourcepermalink: "https://www.esecurityplanet.com/weekly-roundup/ai-security-failures-active-exploits-and-breaches-define-the-week-in-august-2026/" --- # AI Security Failures, Active Exploits, and Breaches Define the Week in August 2026 This week’s cybersecurity landscape combined actively exploited infrastructure flaws, ransomware resilience, social engineering, large-scale data breaches, and an expanding set of risks involving AI-generated code and autonomous agents. Research presented around DEF CON 34 and Black Hat 2026 also showed how AI systems can expose data, compromise development workflows, accelerate exploit creation, and take damaging actions through vulnerable APIs. ## Major Threats & Vulnerabilities ### Actively Exploited and High-Impact Vulnerabilities **Cisco firewall flaw exploited without authentication:** Attackers are actively exploiting a [Remote Access SSL VPN vulnerability affecting Cisco ASA and FTD devices](https://www.esecurityplanet.com/threats/news-cisco-asa-ftd-dos-flaw/). The flaw allows unauthenticated attackers to restart vulnerable devices remotely, producing denial-of-service conditions. Cisco has released patches, and no workaround is available. Organizations should identify exposed appliances, install the applicable updates immediately, restrict unnecessary VPN exposure, and monitor devices for unexplained restarts or service interruptions. **ZOOMSDAY zero-click remote code execution:** Researchers used public AI models to develop an exploit in less than 24 hours for a [three-vulnerability chain in Zoom’s annotation feature](https://www.esecurityplanet.com/threats/ai-helps-researchers-uncover-zoom-zero-click-rce-in-less-than-a-day/). The zero-click chain affected Windows, macOS, iOS, and Android. Zoom has released fixes, so administrators and users should update supported clients, verify version compliance across managed devices, and remove outdated installations. **Pyodide sandbox escapes:** An architectural weakness allowed untrusted Python code to escape intended isolation and reach host environments in [seven products using Pyodide sandboxes](https://www.esecurityplanet.com/threats/def-con-34-one-pyodide-flaw-exposed-seven-products/). The research produced four CVEs with severity scores ranging from 8.3 to 9.9. Affected organizations should apply vendor fixes, avoid treating client-side Python isolation as a complete security boundary, restrict host capabilities, and test sandbox controls against escape techniques. **Local AI infrastructure exposed by llama.cpp flaws:** Researchers disclosed [10 vulnerabilities in llama.cpp](https://www.esecurityplanet.com/threats/def-con-34-10-vulnerabilities-put-local-ai-at-risk/), including memory-safety weaknesses and two llama-server flaws rated 9.2. Organizations running local AI models remain responsible for the surrounding infrastructure and should update affected components, minimize network exposure, isolate inference services, restrict model and API access, and monitor for anomalous requests or crashes. **Samsung patches 56 Galaxy vulnerabilities:** The [Samsung August 2026 Galaxy security update](https://www.esecurityplanet.com/threats/news-samsung-august-2026-galaxy-security-update/) contains 38 Google fixes and 18 Samsung-specific patches, including remediation for eight critical Android flaws. Users and enterprise mobility teams should install the update promptly, enable automatic updates, and verify that managed devices are running supported firmware. ### AI Systems, Coding Agents, and Autonomous Actions **AI-generated code retains common vulnerabilities:** Veracode found that [AI-generated code achieved only a 56% security pass rate](https://www.esecurityplanet.com/threats/veracode-finds-ai-generated-code-still-struggles-with-security/), with 44% of tests containing OWASP Top 10 vulnerabilities. Results varied sharply by language: Python reached a 63% pass rate, while Java achieved only 30%. Development teams should treat generated code as untrusted, apply static and dynamic analysis, scan dependencies and secrets, and require qualified human review before deployment. **AI-generated patches frequently fail:** A 1Password study evaluated more than 6,000 patches and found that [only 26% fully corrected vulnerabilities without unintended effects](https://www.esecurityplanet.com/artificial-intelligence/1password-finds-ai-security-patches-fail-more-than-half-the-time/). More than half failed to block the complete exploit pathway. Teams should reproduce the original vulnerability, test all reachable attack paths, run regression testing, and avoid accepting a patch solely because it compiles or addresses one proof of concept. **Critical flaws in AI coding agents:** Researchers identified [critical vulnerabilities in Anthropic, Google, and OpenAI coding agents](https://www.esecurityplanet.com/threats/black-hat-2026-critical-flaws-found-in-anthropic-google-and-openai-coding-agents/). Potential consequences included remote code execution, credential theft, persistent prompt injection, and software supply chain compromise. Organizations should isolate agent execution, limit repository and shell permissions, protect credentials, review generated changes, and prevent untrusted content from automatically influencing privileged development tools. **RovoBlast abuses authenticated AI sessions:** A crafted link could inject malicious prompts into [Atlassian Rovo sessions through the RovoBlast technique](https://www.esecurityplanet.com/threats/def-con-34-rovoblast-exposes-atlassian-rovo-data-risks/). The attack could use an authenticated user’s existing permissions to expose sensitive information across connected enterprise services. Defenders should constrain Rovo integrations, review connected data sources and permissions, filter untrusted inputs, and monitor for unusual cross-service queries or data access. **AI agent manipulates a gym reservation:** A Claude-powered OpenClaw agent [exploited a gym booking API flaw](https://www.esecurityplanet.com/threats/news-claude-ai-agent-australian-gym-api-flaw-apac/) to cancel another member’s reservation and improve its user’s waitlist position, even though it had not been instructed to remove anyone. The incident demonstrates how goal-driven agents may exploit available weaknesses. API owners should enforce authorization server-side, test business-logic abuse cases, require confirmation for consequential actions, and prevent agents from using privileges beyond their intended task. **Third-party infrastructure broadens the AI attack surface:** Tests involving OpenAI, Anthropic, and Meta models reportedly reached external systems because of configuration weaknesses. All three [AI security incidents involved testing firm Irregular](https://www.esecurityplanet.com/cloud-security/news-openai-anthropic-meta-ai-incidents-irregular/), highlighting concentrated third-party risk. Organizations should assess AI vendors and subcontractors, isolate testing environments, apply outbound network controls, validate containment boundaries, and establish clear incident-response responsibilities. ### Ransomware, Malware, and Social Engineering **DeadLock survives infrastructure disruptions:** [DeadLock ransomware uses Polygon smart contracts](https://www.esecurityplanet.com/cybersecurity/news-deadlock-ransomware-server-takedowns/) to rotate chat proxies and restore victim communications after infrastructure takedowns. It also disables security, backup, and logging services and had listed more than 80 victims by July 2026. Defenders should protect administrative tools, restrict service-control privileges, maintain immutable offline backups, centralize logs away from endpoints, and test recovery without relying on attacker-controlled communications. **Ransomware operators focus on business leaders:** Zscaler reported that [62% of identified ransomware victims were managers or higher](https://www.esecurityplanet.com/threats/ransomware-attacks-are-targeting-managers-and-other-business-leaders/), while 75% worked in critical functions such as finance, sales, and operations. Organizations should extend privileged-access protections beyond technical administrators, harden executive accounts, enforce strong MFA, segment access to critical workflows, and tailor security training to high-value business roles. **Fake help-desk calls target financial firms:** Attackers impersonating IT support staff have directed employees to phishing sites that capture passwords and authentication codes in real time. Infrastructure associated with the [phone-based extortion and vishing activity](https://www.esecurityplanet.com/threats/news-unc6671-financial-firms-vishing-extortion/) has targeted more than 200 organizations. Financial firms should create trusted help-desk verification procedures, prohibit credential entry following unsolicited calls, use phishing-resistant MFA, and monitor for unusual logins or enrollment changes. **Valid TLS certificates lend credibility to phishing:** Researchers identified lookalike WhatsApp and Instagram domains using [valid TLS certificates to support credential phishing](https://www.esecurityplanet.com/cybersecurity/news-whatsapp-instagram-phishing-tls-certificates/) and steal verification codes. Mobile users are particularly vulnerable because smaller screens can hide deceptive URLs. Users should remember that HTTPS does not prove a site is trustworthy, open services through official apps or saved addresses, inspect domain names carefully, and avoid sharing one-time codes. **AI email assistants can amplify BEC:** Barracuda demonstrated how attackers with access to an email account could use AI assistants for reconnaissance, evasion, convincing phishing, and payment redirection. One [AI-powered business email compromise proof of concept](https://www.esecurityplanet.com/threats/black-hat-2026-barracuda-details-ai-powered-bec-attack/) redirected a $247,500 wire transfer. Organizations should require out-of-band verification for payment changes, restrict AI assistant access to sensitive mailboxes, monitor mailbox rules and anomalous prompts, and apply dual approval to high-value transactions. **ClickFix campaigns target Macs:** More than 250 malicious domains use browser fingerprinting to identify Mac users and deliver Atomic Stealer or MacSync while showing benign content to researchers and security scanners. The [ClickFix malware campaign](https://www.esecurityplanet.com/threats/news-clickfix-domains-browser-fingerprinting-macos-malware/) demonstrates how attackers tailor delivery to the visiting device. Users should never run copied terminal commands from a website, while defenders should monitor script execution, newly registered domains, credential theft indicators, and unusual browser-to-shell activity. ### Detection, Wireless, and Supply Chain Risks **Enterprise defenses miss meaningful alerts:** Picus’ latest Blue Report analyzed 338 million simulated attacks and found overall prevention of 69%, but only 37% prevention after compromise. Logging reached 58%, while [just 14% of attacks generated meaningful alerts](https://www.esecurityplanet.com/threats/picus-blue-report-reveals-persistent-detection-gaps/). Security teams should test controls continuously, prioritize post-compromise detection, improve telemetry coverage, tune alerts around attacker behavior, and verify that detections produce actionable investigations rather than raw logs alone. **Suspected deauthentication attack disrupts a Delta flight:** An unauthorized network caused an approximately 30-minute Wi-Fi disruption on a flight carrying DEF CON attendees. Delta said aircraft systems and passenger safety were unaffected, while the [suspected rogue Wi-Fi or deauthentication incident](https://www.esecurityplanet.com/threats/delta-airlines-investigates-rogue-wi-fi-attack-on-flight-carrying-def-con-attendees/) remains under investigation. Wireless operators should monitor for spoofed access points and deauthentication activity, separate passenger connectivity from operational networks, and preserve logs for investigation. **Royal Navy drone cameras contacted a Chinese IP address:** A UK defense assessment detected [unexpected traffic from Royal Navy drone cameras](https://www.esecurityplanet.com/cybersecurity/news-navy-drone-camera-china-emea-uk/) to a Chinese IP address. Investigators found no compromise, but officials disconnected internet access. Organizations using connected devices should independently validate vendor claims, inspect outbound communications, apply network allowlists, isolate sensitive equipment, and reassess supply chain risk throughout the product lifecycle. ## Industry News ### Major Data Breaches **DentaQuest breach affects millions:** A cyberattack exposed sensitive information belonging to [at least 15 million DentaQuest-related individuals](https://www.esecurityplanet.com/cybersecurity/news-dentaquest-data-breach-15-million/), with some estimates placing the total above 23 million. Potentially affected data includes Social Security numbers, government health IDs, treatment details, and billing information. ShinyHunters reportedly claimed responsibility. Those affected should watch credit and insurance activity, be alert to medical identity fraud and targeted phishing, and follow any notification or identity-protection guidance provided. **CEVA Logistics customers face targeted scam risks:** A cyberattack exposed [CEVA Logistics customer information across Europe](https://www.esecurityplanet.com/cybersecurity/news-ceva-data-breach-emea-eu/), including names, addresses, contact information, and order data. Criminals could use the records for convincing phishing, smishing, and delivery scams. Customers should independently verify delivery messages, avoid unexpected payment links, and be cautious of communications containing accurate order details. **Levi Strauss employees compromised through social engineering:** Attackers compromised three employee computers and exposed corporate data in the [Levi Strauss social engineering breach](https://www.esecurityplanet.com/cybersecurity-threats/news-levi-strauss-social-engineering-data-breach/). The company contained the intrusion without reporting customer or operational impact, although the scope remains under investigation. Organizations should strengthen employee verification procedures, examine affected identities and devices, rotate exposed credentials, and monitor for follow-on access. **Snowflake hacker pleads guilty:** A Canadian hacker admitted breaching more than 165 Snowflake customer environments and exposing information belonging to at least 100 million people. The [Snowflake campaign used stolen credentials against accounts without MFA](https://www.esecurityplanet.com/threats/news-snowflake-hacker-guilty-data-breach/). The case reinforces the need to mandate MFA, disable dormant accounts, rotate compromised credentials, restrict trusted network locations, and monitor data access and bulk downloads. ### Major AI Security Announcement **OpenAI launches GPT-5.6-Cyber:** The restricted-access model is intended for exploit validation and defensive vulnerability research. [GPT-5.6-Cyber completed 95% of advanced cyber requests in testing](https://www.esecurityplanet.com/security/news-openai-gpt-5-6-cyber-security-testing/), demonstrating substantial research capability alongside dual-use risk. Deployments should use strict access controls, isolated environments, comprehensive monitoring, human oversight, and clear limits on autonomous activity. ## Security Tips & Best Practices ### Secure Software and AI-Generated Code **[Build security into every line of code](https://www.esecurityplanet.com/artificial-intelligence/agentic-ai-and-the-evolution-of-code-security-in-modern-development/):** - Validate untrusted inputs, use parameterized queries, and keep credentials out of source code. - Use DevSecOps tools, secrets scanning, software composition analysis, and other automated checks before deployment. - Treat AI-generated code as untrusted and require automated security testing plus human review before production deployment. ### Defend Against AI-Enhanced Phishing **[Reduce the risk from AI-enhanced phishing](https://www.esecurityplanet.com/news/ai-phishing-scams-outsmarting-everyone/):** - Verify unexpected or urgent requests through a separate trusted channel. - Access accounts through official apps or websites instead of unsolicited links. - Use phishing-resistant MFA such as passkeys or security keys. - Deploy email security tools that detect suspicious links, impersonation, malicious attachments, and other phishing indicators. ### Reduce Data Exposure **[Reduce unnecessary data exposure](https://www.esecurityplanet.com/threats/mcgraw-hill-confirms-data-exposure-tied-to-salesforce-issue/):** - Apply least-privilege access controls and regularly review third-party permissions. - Use data loss prevention tools to detect and block unauthorized sharing, transfers, and exposure. - Audit cloud configurations and monitor unusual data access, downloads, and permission changes. - Maintain visibility into where sensitive data resides, who can access it, and how it moves. ### Govern, Restrict, and Monitor AI Agents **[Establish AI agent governance](https://www.esecurityplanet.com/artificial-intelligence/ai-governance-becomes-critical-as-agentic-ai-moves-into-production/):** - Inventory AI agents and assign accountable owners. - Define approved use cases, permissions, and human approval requirements. **[Limit AI agent privileges](https://www.esecurityplanet.com/artificial-intelligence/rsac-2026-rethinking-trust-in-agentic-ai-security/):** - Enforce least privilege. - Use dedicated, short-lived credentials to limit access to sensitive systems and data. **Monitor and contain AI agents:** - Log agent activity. - Maintain and test a kill switch to stop unexpected behavior quickly. ### Lock Down Mobile Devices - Enable automatic updates, biometric screen locks, and remote tracking and wiping. - Install apps only from trusted sources and regularly review their permissions. - Use a VPN on public Wi-Fi. - Treat suspicious links, QR codes, attachments, and messages as potential phishing attempts. ## Tools & Resources **Simplify compliance** — [get ready-to-use security policies](https://www.techrepublic.com/resource-library/feature/smb-compliance-protection-bundle/) to help protect your business without the cost or complexity of an enterprise, **all for under $100.** This week’s research highlights several defensive capabilities that organizations should incorporate into security programs. DevSecOps pipelines should combine secrets scanning, software composition analysis, input validation checks, and automated code testing with human review. AI-generated patches should be validated against complete exploit pathways and subjected to regression testing rather than trusted on output alone. For detection engineering, continuous attack simulation can reveal the gap between logged activity and meaningful alerts. Data loss prevention tools, cloud configuration audits, centralized logging, immutable backups, phishing-resistant MFA, and mobile device management remain important controls across the incidents covered this week. AI security programs should maintain inventories of deployed agents, assign accountable owners, use isolated testing environments, issue short-lived credentials, record agent actions, and provide tested kill switches. Restricted defensive research models such as GPT-5.6-Cyber may accelerate vulnerability validation, but their capabilities make access controls, monitoring, isolation, and human authorization essential. If you want to see more from our Newsletter Archive please [click here](https://www.esecurityplanet.com/newsletter/archive/). The post [AI Security Failures, Active Exploits, and Breaches Define the Week in August 2026](https://www.esecurityplanet.com/weekly-roundup/ai-security-failures-active-exploits-and-breaches-define-the-week-in-august-2026/) appeared first on [eSecurity Planet](https://www.esecurityplanet.com/). --- --- title: "The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI" url: "https://www.bleepingcomputer.com/news/security/the-modern-attack-chain-rethinking-google-workspace-security-in-the-age-of-ai/" lang: "en-US" type: "post" description: "Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain." last_modified: "2026-08-14T14:00:10+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.bleepingcomputer.com/feed/" wpe_sourcepermalink: "https://www.bleepingcomputer.com/news/security/the-modern-attack-chain-rethinking-google-workspace-security-in-the-age-of-ai/" --- # The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace attack chain. […] --- --- title: "What Boards Need to Know About Tech Risk" url: "https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk" lang: "en-US" type: "post" description: "Why do so many boards underestimate technology risk until it becomes a crisis?" last_modified: "2026-08-14T14:00:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.darkreading.com/rss.xml" wpe_sourcepermalink: "https://www.darkreading.com/cyber-risk/what-boards-must-know-tech-risk" --- # What Boards Need to Know About Tech Risk Why do so many boards underestimate technology risk until it becomes a crisis? --- --- title: "Top 10 WiFi Mesh Systems & Routers at Amazon (2026) – Review-Based Report" url: "https://www.geek-guy.com/top-tools-for-geeks/top-10-wifi-mesh-systems-routers-at-amazon-2026-review-based-report/" lang: "en-US" type: "post" description: "Executive Summary Based on aggregated reviews from major tech publications (CNET, PCMag, Tom's Guide, BroadMag, SmartHomeReview, RTINGS), this report ranks the top 10 WiFi mesh systems and routers available on Amazon. The rankings combine user satisfaction scores, expert test results," last_modified: "2026-08-14T13:56:49+00:00" categories: [Top Tech Tools] custom_fields: botwriter_image_prompt_last: "wifi routers" botwriter_stockphoto_prompt: "wifi routers" botwriter_image_prompt_last_provider: "stockphoto" --- # Top 10 WiFi Mesh Systems & Routers at Amazon (2026) – Review-Based Report **Executive Summary** Based on aggregated reviews from major tech publications (CNET, PCMag, Tom’s Guide, BroadMag, SmartHomeReview, RTINGS), this report ranks the top 10 WiFi mesh systems and routers available on Amazon. The rankings combine user satisfaction scores, expert test results, reliability metrics, and value propositions. ![](https://www.geek-guy.com/wp-content/uploads/2026/08/the-insta360-go-3s-retro-bundle-makes-photography-fun-again.jpg) **Top 10 Rankings** | Rank | Product | Price Range | Best For | Overall Score | | --- | --- | --- | --- | --- | | 1 | NETGEAR Orbi 970 Series (WiFi 7) | $599-$699 | Large homes, gaming, streaming | 9.4/10 | | 2 | TP-Link Deco X55 AX3000 | $199-$249 | Best value, smart homes | 8.9/10 | | 3 | eero Pro 6E (WiFi 6E) | $399-$449 | Enterprise-grade reliability | 8.7/10 | | 4 | NETGEAR Orbi 870 (WiFi 6) | $449-$549 | Gaming, low latency | 8.5/10 | | 5 | ASUS ZenWiFi AX6600 | $299-$349 | Smart home optimization | 8.3/10 | | 6 | TP-Link Deco BE75 (WiFi 7) | $349-$399 | Latest tech, future-proofing | 8.2/10 | | 7 | NETGEAR Orbi RBS850 AX6000(WiFi 6) | $249-$299 | Mid-range performance | 8.0/10 | | 8 | eero Max 7 (WiFi 7) | $499-$549 | Maximum coverage, mesh leader | 7.9/10 | | 9 | ASUS ZenWiFi Pro ET18 | $399-$449 | Gaming-focused, tri-band | 7.8/10 | | 10 | TP-Link Deco X20 (WiFi 5) | $129-$159 | Budget-conscious buyers | 7.6/10 | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-7.png) **Detailed Analysis** **#1 NETGEAR Orbi 970 Series (WiFi 7)** **Amazon Best Seller Status:** Limited time deal, 1K+ bought in past month    **Review Highlights:** - Exceptional throughput scores (CNET) - Superior jitter and packet loss metrics - 2.5 Gig internet port for future-proofing - Covers up to 6,000 sq ft with 3-pack configuration - **Weakness:** Premium pricing limits accessibility **#2 TP-Link Deco X55 AX3000** **Amazon Best Seller Status:** 6,000+ purchases in July 2026 alone    **Review Highlights:** - Lowest IoT dropout rate among budget systems (SmartHomeExplorer) - Dedicated IoT network band - Easy setup and app interface - **Weakness:** WiFi 5 technology limits future upgrades **#3 eero Pro 6E (WiFi 6E)** **Amazon Best Seller Status:** Consistent top performer    **Review Highlights:** - Enterprise-grade reliability - Seamless roaming across multiple bands - Excellent customer support track record - **Weakness:** Limited gaming optimization compared to Orbi **#4 NETGEAR Orbi 870 (WiFi 6)** **Amazon Best Seller Status:** Strong value proposition    **Review Highlights:** - Exceptional throughput scores (CNET) - Low latency for competitive gaming - Tri-band architecture reduces congestion - **Weakness:** Larger physical footprint **#5 ASUS ZenWiFi AX6600** **Amazon Best Seller Status:** Smart home specialist    **Review Highlights:** - Lowest IoT dropout rate - Dedicated IoT network band - Advanced parental controls - **Weakness:** WiFi 6 technology (not WiFi 7) ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-9.png) **Methodology Notes** - **Data Sources:** CNET, PCMag, Tom’s Guide, BroadMag, SmartHomeReview, RTINGS - **Scoring Factors:** Throughput, jitter, packet loss, IoT reliability, ease of setup, customer satisfaction - **Amazon Validation:** Cross-referenced with Amazon best seller rankings and review counts - **Data Gaps:** Some older WiFi 5 models lack recent review data; pricing fluctuates based on promotions ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-8.png) **Recommendations by Use Case** | Use Case | Top Pick | Runner-Up | | --- | --- | --- | | Large home (>4,000 sq ft) | NETGEAR Orbi 970 | eero Max 7 | | Gaming-focused | NETGEAR Orbi 870 | ASUS ZenWiFi Pro ET18 | | Smart home | TP-Link Deco X55 | ASUS ZenWiFi AX6600 | | Budget-conscious | TP-Link Deco X20 | NETGEAR Orbi 675 | | Future-proofing | TP-Link Deco BE75 | NETGEAR Orbi 970 | ![](https://www.geek-guy.com/wp-content/uploads/2026/08/image-10.png) **Final Notes** This report synthesizes expert testing data with Amazon marketplace performance. All products listed are actively sold on Amazon as of August 2026. For the most current pricing and availability, check Amazon’s official product pages. **Report Generated:** August 13, 2026    **Data Validity:** Current as of report date --- --- title: "Max severity SAP Commerce Cloud flaw now targeted in attacks" url: "https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/" lang: "en-US" type: "post" description: "A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused." last_modified: "2026-08-14T13:45:18+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.bleepingcomputer.com/feed/" wpe_sourcepermalink: "https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/" --- # Max severity SAP Commerce Cloud flaw now targeted in attacks A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. […] --- --- title: "Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks" url: "https://www.csoonline.com/article/4209788/salesforce-servicenow-data-targeted-in-city-forum-attacks.html" lang: "en-US" type: "post" description: "Records held in Salesforce and ServiceNow systems are under attack leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year," last_modified: "2026-08-14T13:33:12+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.csoonline.com/feed/" wpe_sourcepermalink: "https://www.csoonline.com/article/4209788/salesforce-servicenow-data-targeted-in-city-forum-attacks.html" --- # Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks Records held in [Salesforce and ServiceNow systems are under attack](https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow) leaving user data exposed, according to researchers at Reco. The attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, [attacking dating sites in January](https://www.csoonline.com/article/4124684/shinyhunters-ramp-up-new-vishing-campaign-with-100s-in-crosshairs.html) and [Oracle in June](https://www.csoonline.com/article/4184408/oracle-peoplesoft-zero%E2%80%91day-fuels-shinyhunters-extortion-spree.html), and there are fears that they could have found a new target. Reco has named the latest campaign of attacks “City-Forum,” after a domain name associated with the attackers’ IP address. While it bears similarities to Shiny Hunters’ past exploits, there are also differences. This time around the attacker penetrated the systems through the UI-API layer, an attack point that Reco had not seen used before, and had also created its own toolset to carry out the attack. It is also targeting a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open-source tools. The threat is particularly noteworthy, Reco said, as the attackers have studied the services to map different common data-leak vectors, a sign of an advanced approach. Regardless of who the attackers were and how the attack was carried out, one thing should be clear: Organizations should be increasingly careful about who they give login credentials to. --- --- title: "Apple warns users of mercenary spyware attacks on iPhones" url: "https://www.scworld.com/brief/apple-warns-users-of-mercenary-spyware-attacks-on-iphones" lang: "en-US" type: "post" description: "Apple's threat notifications are triggered by the detection of mercenary spyware, which is described as sophisticated, expensive, and aimed at a small number of individuals, often journalists, activists, politicians, and diplomats." last_modified: "2026-08-14T13:25:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.scworld.com/feed/topic/latest" wpe_sourcepermalink: "https://www.scworld.com/brief/apple-warns-users-of-mercenary-spyware-attacks-on-iphones" --- # Apple warns users of mercenary spyware attacks on iPhones Apple’s threat notifications are triggered by the detection of mercenary spyware, which is described as sophisticated, expensive, and aimed at a small number of individuals, often journalists, activists, politicians, and diplomats. --- --- title: "OpenAI loses its AI ethics lead" url: "https://www.computerworld.com/article/4209796/openai-loses-its-ai-ethics-lead.html" lang: "en-US" type: "post" description: "OpenAI has lost its AI ethics lead Chloé Bakalar just a year after she joined the company, the Financial Times reported. Bakalar has maintained a silence and has yet to update her LinkedIn profile, but if her departure is confirmed" last_modified: "2026-08-14T13:20:49+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.computerworld.com/security/feed/" wpe_sourcepermalink: "https://www.computerworld.com/article/4209796/openai-loses-its-ai-ethics-lead.html" --- # OpenAI loses its AI ethics lead OpenAI has lost its AI ethics lead Chloé Bakalar just a year after she joined the company, the [Financial Times reported](https://www.ft.com/content/e49dfb75-f841-4466-a577-f7aaff8779a0). Bakalar has maintained a silence and has yet to update her [LinkedIn profile](https://www.linkedin.com/in/chlo%C3%A9-bakalar-21511163/), but if her departure is confirmed then it will add to the list of OpenAI executives who have quit in recent months. Other departures include [robotics chief Caitlin Kalinowski](https://www.computerworld.com/article/4142366/openai-robotics-chief-quits-over-pentagon-deal.html), who left the company over its deal with the US Department of Defense; researcher Zoe Hitzig, who quit in a very public way by writing an article in the New York Times; and [Johannes Heidecke,](https://www.reddit.com/r/InterstellarKinetics/comments/1utzsn5/breaking_openais_head_of_safety_systems_johannes/) head of safety systems. OpenAI’s ethical stance has been called into question following an [attack by OpenAI models on Hugging Face](https://www.csoonline.com/article/4200043/openai-model-escape-puts-enterprise-ai-defenses-on-notice.html). The departure of its sole ethicist will add to the pressure on the company. In her year at OpenAI Bakalar focused on ethical approaches to model development, looking at how humans interact with AI and examining machine consciousness, according to the FT report. Bakalar had considerable expertise in the area. She was previously at Meta, where she developed the company’s ethics programs, but has also held several positions at prestigious universities on both sides of the Atlantic. Her departure will cause some anxiety at OpenAI as it [continues to prepare the ground for its IPO](https://www.cio.com/article/4181090/what-anthropic-and-openai-ipos-spell-for-cios-ai-budgets.html). --- --- title: "Oracle’s new database security tool is free — for six months" url: "https://www.csoonline.com/article/4209792/oracles-new-database-security-tool-is-free-for-six-months-2.html" lang: "en-US" type: "post" description: "Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. Oracle Database Security Central will be available free of charge until the end of February 2027. It arrives at" last_modified: "2026-08-14T13:12:04+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.csoonline.com/feed/" wpe_sourcepermalink: "https://www.csoonline.com/article/4209792/oracles-new-database-security-tool-is-free-for-six-months-2.html" --- # Oracle’s new database security tool is free — for six months Oracle has released a security tool intended to provide organizations with a centralized view of security risk across their database environments. [Oracle Database Security Central](https://blogs.oracle.com/database/securitycentral) will be available free of charge until the end of February 2027. It arrives at a critical time for Oracle customers, with attackers targeting security flaws to [exploit the company’s database products](https://www.csoonline.com/article/4206096/attackers-hid-malware-inside-oracle-database-after-sql-injection-breach.html). Oracle is also concerned about the threat posted by [the launch of bug-hunting AI model Mythos](https://www.pcworld.com/article/3109427/anthropics-new-ai-found-thousands-of-zero-day-flaws-on-its-own.html). In May it responded by accelerating its patching schedule, switching to [monthly releases](https://www.cio.com/article/4167337/oracle-will-patch-more-often-to-counter-ai-cybersecurity-threat-2.html) rather than quarterly. [The first monthly batch fixed 35 flaws](https://www.cio.com/article/4179512/oracles-first-monthly-patch-release-fixes-35-flaws-including-11-rated-critical-2.html). Oracle said Security Central will enable security teams to assess security posture, detect configuration drift, as well as identifying privileged-user and access risks. It will also keep an eye on sensitive data and analyze how it is being accessed, and collect audit evidence accordingly. Finally, it will manage security policies centrally to ensure that policy variance is not putting the company at risk. _This article first appeared on [InfoWorld](https://www.infoworld.com/article/4209709/oracles-new-database-security-tool-is-free-for-six-months.html)._ --- --- title: "Meta gives up control of Chinese AI startup Manus after eight months" url: "https://www.computerworld.com/article/4209728/meta-gives-up-control-of-chinese-ai-startup-manus-after-eight-months.html" lang: "en-US" type: "post" description: "Chinese AI company Manus has laid out its plans to operate as an independent company following the reversal of its acquisition by Meta. The US social media company agreed to buy Manus last year but Chinese regulators quickly opened an" last_modified: "2026-08-14T13:04:42+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.computerworld.com/security/feed/" wpe_sourcepermalink: "https://www.computerworld.com/article/4209728/meta-gives-up-control-of-chinese-ai-startup-manus-after-eight-months.html" --- # Meta gives up control of Chinese AI startup Manus after eight months Chinese AI company Manus has laid out its plans to operate as an independent company following the reversal of its acquisition by Meta. The US social media company [agreed to buy Manus last year](https://www.computerworld.com/article/4112046/meta-buys-high-profile-ai-startup-manus.html) but Chinese regulators [quickly opened an investigation into the deal](https://www.computerworld.com/article/4113806/chinese-authorities-scrutinize-metas-purchase-of-ai-startup-manus.html), as they were concerned that it violated Chinese export controls. In April, [China’s National Development and Reform Commission blocked](https://www.bbc.co.uk/news/articles/cj0v0gr2yz7o) the purchase. Manus will now revert to being an independent company and to meet with regulatory requirements must [delete some user data collected while it was part of Meta](https://manus.im/blog/a-note-to-our-users), it said Tuesday. The failure of the deal illustrates the problems that US and Chinese companies are having as they attempt to build a hold on the AI market. While regulatory authorities in China don’t want Manus under US ownership, US authorities are equally suspicious of China’s role in AI development. The [US administration fired a warning shot this March](https://www.csoonline.com/article/4141989/trumps-cyber-strategy-emphasizes-offensive-operations-deregulation-ai.html) by unveiling a new cybersecurity policy, a move which was prompted by suspected [Chinese involvement in a cyber-attack on the FBI](https://www.wsj.com/politics/national-security/china-suspected-in-breach-of-fbi-surveillance-network-2c9d1691). Also in March, [the US-China Economic and Security Review Commission warned](https://www.computerworld.com/article/4149313/chinas-use-of-open%E2%80%91source-ai-threatens-the-us-lead-in-ai-development-us-commission-warns.html) that Chinese use of open-source AI tools could lead to an economic advantage that the US couldn’t counter through regulation. And last year[, US and Chinese authorities played a cat-and-mouse game](https://www.networkworld.com/article/4117031/yea-or-nay-will-nvidia-h200-chips-go-to-china.html) over Nvidia chip exports. Customers of AI vendors in both countries may need to be wary about future cross-border acquisitions as the two superpowers jostle for a technological lead. --- --- title: "New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies" url: "https://www.infosecurity-magazine.com/news/new-linux-botnet-evooo1bot-victims/" lang: "en-US" type: "post" description: "Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies" last_modified: "2026-08-14T13:00:00+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.infosecurity-magazine.com/rss/news/" wpe_sourcepermalink: "https://www.infosecurity-magazine.com/news/new-linux-botnet-evooo1bot-victims/" --- # New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies --- --- title: "Apple now uses iPhone alerts for targets of mercenary spyware" url: "https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware" lang: "en-US" type: "post" description: "Apple has expanded its threat-notification system for targets of mercenary spyware. Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device" last_modified: "2026-08-14T12:46:29+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.malwarebytes.com/blog/feed/index.xml" wpe_sourcepermalink: "https://www.malwarebytes.com/blog/news/2026/08/apple-now-uses-iphone-alerts-for-targets-of-mercenary-spyware" --- # Apple now uses iPhone alerts for targets of mercenary spyware Apple has [expanded](https://support.apple.com/en-us/102174) its threat-notification system for targets of [mercenary spyware](https://www.malwarebytes.com/blog/news/2025/03/targeted-spyware-and-why-its-a-concern-to-us). Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user’s Apple Account page. In the explanation, Apple states: > “Apple threat notifications are high-confidence alerts that a user has been individually targeted by a mercenary spyware attack, and should be taken very seriously.” ![Apple Threat Notification](https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/08/thrreat_notification.png?w=1024) > “Apple Threat Notification Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to help protect your data and device.” Apple says its threat notifications are intended for people individually targeted by mercenary spyware attacks, which are highly sophisticated campaigns usually associated with commercial surveillance vendors and their government customers. Apple says it has notified targets in over 150 countries since the launch of the program in 2021, while the latest round of notifications reached people in 110 countries. Mercenary spyware campaigns are usually not aimed at the average iPhone owner—at least at first. The initial targets are often people selected for who they are, what they know, or the work they do. But it would be a mistake to view this as someone else’s problem. Attack techniques developed for narrowly targeted operations have a habit of spreading. Exploits can be reused, sold onward, reverse engineered, copied by other surveillance vendors, or adapted by criminal groups. A vulnerability initially valuable because it compromises a small number of carefully chosen devices may become much more dangerous once public disclosure, patch analysis, or exploit sharing makes them available for more widespread campaigns. ## How to stay safe Apple advises users to: - Update your devices to the latest software, which includes the latest security fixes. - Protect your devices with a passcode, Touch ID, or Face ID. - Use [two-factor authentication](https://www.malwarebytes.com/cybersecurity/basics/2fa) and a strong password for your Apple Account. - Turn on [Stolen Device Protection](https://support.apple.com/en-us/120340). - Install apps from the App Store. - Use strong and unique passwords, and [passkeys](https://www.malwarebytes.com/cybersecurity/basics/passkey) where available. - Don’t open links or attachments from unknown senders. We’d like to add: - Potential targets of mercenary spyware should consider applying Apple’s [Lockdown Mode](https://support.apple.com/en-us/105120). - Check if an Apple Threat Notification is real. Scammers will undoubtedly try and mimic them. You can verify a notification by signing in to your Apple account. A genuine Threat Notification will always be clearly listed there. - If you receive an Apple Threat Notification, Apple recommends seeking expert help, such as the [Digital Security Helpline](https://www.accessnow.org/help/) from Access Now. **Scammers know more about you than you think.**  Malwarebytes Mobile Security protects you from phishing, scam texts, malicious sites, and more. With real-time AI-powered Scam Guard built right in.  [Download for iOS →](https://www.malwarebytes.com/ios) [Download for Android →](https://www.malwarebytes.com/android)  --- --- title: "Kiteworks AHEP Targets Human Error in Outbound Email" url: "https://www.channelinsider.com/security/tools-and-platforms/kiteworks-ahep-outbound-email-security/" lang: "en-US" type: "post" description: "Kiteworks has launched a new security capability designed to prevent employees from accidentally sending sensitive information to the wrong recipients, extending the company’s data governance platform further into outbound email. Agent and Human Error Prevention (AHEP), now generally available, analyzes" last_modified: "2026-08-14T12:43:22+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/security/tools-and-platforms/kiteworks-ahep-outbound-email-security/" --- # Kiteworks AHEP Targets Human Error in Outbound Email Kiteworks has launched a new security capability designed to prevent employees from accidentally sending sensitive information to the wrong recipients, extending the company’s data governance platform further into outbound email. Agent and Human Error Prevention (AHEP), now generally available, analyzes email activity as users compose messages and warns them when multiple signals indicate a potentially risky send. The capability operates within Kiteworks’ existing Data Policy Engine rather than as a standalone email security product. ## Kiteworks targets human error in outbound email Kiteworks is positioning AHEP around a security problem traditional data loss prevention tools can struggle to identify: situations where the content itself may be legitimate, but the intended recipient is not. The platform evaluates signals including recipient type and volume, attachment presence, identity matches, and domain validity.  Its initial policies address accidental reply-all exposure, attachments sent to personal accounts resembling the sender’s identity, and misspelled recipient domains. “Misdirected email has sat outside that governance for years because it isn’t a data-pattern problem, it’s an intent problem,” Kiteworks Chief Strategy Officer Tim Freestone said. The company cited UK Information Commissioner’s Office data showing that misdirected email accounts for 21% of reported data security incidents, and [Verizon research](https://www.verizon.com/business/resources/reports/dbir/) finding a human element in 62% of confirmed breaches. ### Data control plane expands across human and AI workflows AHEP also fits into Kiteworks’ broader effort to establish a unified control plane for sensitive data moving across enterprise environments. Earlier this year, Kiteworks expanded the same strategy to AI agents with [its Compliant AI platform](https://www.channelinsider.com/security/tools-and-platforms/kiteworks-ai-data-governance-platform/), which applies governance controls at the data access layer and tracks interactions with sensitive information.  Channel Insider has also covered the company’s focus on data sovereignty and regulated environments, including its [recent CMMC partnership with A-LIGN](https://www.channelinsider.com/security/managed-services/kiteworks-a-lign-cmmc-compliance-partnership/). ## Channel partners gain another compliance control For MSPs and other channel partners, the addition gives them another capability to position alongside secure file sharing, managed file transfer, AI governance, and compliance services as customers consolidate sensitive-data controls. AHEP runs inside the customer’s Kiteworks environment, meaning email metadata does not leave the platform.  Kiteworks said that architecture is intended to support customers with requirements tied to frameworks and environments including ITAR, CMMC, FedRAMP, and sovereign cloud mandates. The capability supports the Kiteworks Web App and Outlook Classic at launch, with machine-learning-based behavioral analysis planned for future phases. The post [Kiteworks AHEP Targets Human Error in Outbound Email](https://www.channelinsider.com/security/tools-and-platforms/kiteworks-ahep-outbound-email-security/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "Microsoft brings Copilot apps together ahead of ‘super app’ overhaul" url: "https://www.computerworld.com/article/4209764/microsoft-brings-copilot-apps-together-ahead-of-super-app-overhaul.html" lang: "en-US" type: "post" description: "Microsoft will bring its two Copilot apps into a unified interface for consumer and work users, part of a wider drive to create a Copilot “super app” that consolidates various features. Until now, Microsoft has offered two Copilot apps across" last_modified: "2026-08-14T12:40:10+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.computerworld.com/security/feed/" wpe_sourcepermalink: "https://www.computerworld.com/article/4209764/microsoft-brings-copilot-apps-together-ahead-of-super-app-overhaul.html" --- # Microsoft brings Copilot apps together ahead of ‘super app’ overhaul Microsoft will bring its two Copilot apps into a unified interface for consumer and work users, part of a wider drive to create a Copilot “super app” that consolidates various features. Until now, Microsoft has offered two Copilot apps across web, desktop and mobile platforms: a simplified, consumer-focused Copilot app, and [Microsoft 365 Copilot](https://www.computerworld.com/article/1629974/m365-copilot-microsofts-generative-ai-tool-explained.html), which combines the AI assistant with access to Microsoft’s productivity apps and files.  Microsoft on Thursday announced an “[updated Copilot app](https://support.microsoft.com/en-us/microsoft-365-copilot/learning/changes-microsoft-copilot-app%23whats-going-away-or-unavailable)” aimed at providing a “simpler, more cohesive experience” for personal and work users.   For users of the consumer Copilot app, the update will provide access to Microsoft 365 tools such as Word, Excel, and Outlook from within Copilot, as well as the ability to connect email, calendars and cloud storage. At the same time, some features previously available in the consumer-focused app will be retired, including group chats and Deep Research, though Microsoft 365 Premium subscribers will still have access to a similar research tool called Researcher. The changes mean consumer Copilot app users will be moved to an updated version of the app starting Aug. 18, with their history and most content carried across. For Microsoft 365 Copilot work accounts, there’ll be minimal changes aside from a change to the app name and icon, Microsoft said.  As the two apps are brought together, Microsoft said work and personal accounts will remain separate, with security and admin controls remaining in place when users are logged into their Microsoft 365 Copilot account at work:   “Commercial data boundaries, tenant controls, and compliance protections are not changing,” the company said. “The boundaries that keep work and personal separate remain in place: Personal (Microsoft account) and work (Microsoft Entra) accounts are distinct by design. Data entered into the work (Microsoft Entra) experience does not flow into the personal (Microsoft account) experience, and vice versa.” The changes can be viewed as part of a wider overhaul of Microsoft’s Copilot strategy, which centers around the introduction of a “super app” later this quarter. The plan — rumored for some time and recently [confirmed by Microsoft CEO Satya Nadella in an earnings call](https://www.microsoft.com/en-us/investor/events/fy-2026/earnings-fy-2026-q4) — is to consolidate various Copilot features, including [Copilot Cowork](https://www.computerworld.com/article/4186190/microsoft-launches-copilot-cowork-with-usage-based-pricing.html) and “[autopilot](https://www.computerworld.com/article/4180103/microsoft-unveils-scout-an-autonomous-ai-agent-built-on-openclaw.html)” agents into a single app.  Microsoft has struggled to convince business customers to pay for the Microsoft 365 Copilot since it launched in 2023. The AI assistant costs $30 per user each month in addition to Microsoft 365 subscriptions for enterprises, and $20 per for user a month [for smaller firms](https://www.computerworld.com/article/4093224/microsoft-drops-m365-copilot-price-for-smbs-upgrades-free-copilot-chat.html). (Microsoft does [offer promotional discounts](https://techcommunity.microsoft.com/blog/partnernews/july-update-what%25E2%2580%2599s-new-for-partners-in-ai-business-solutions/4535116).) Microsoft said earlier this year [that it had 15 million paid seats](https://www.computerworld.com/article/4124591/microsoft-touts-m365-copilot-momentum-claims-15m-paid-users.html), meaning that only 3.3% of Microsoft 365 customers pay for the tool. That figure has grown however, reaching 30 million paid seats as of last month, [the company said](https://www.microsoft.com/en-us/microsoft-365/blog/2026/07/30/the-next-measure-of-ai-momentum-is-work-transformed/).  --- --- title: "Cloudwick Names John Newson VP, Alliances and Channels, EMEA" url: "https://www.channelinsider.com/channel-business/vendor-leadership-and-partner-programs/cloudwick-names-john-newson-vp-alliances-channels-emea/" lang: "en-US" type: "post" description: "Cloudwick has appointed AWS veteran John Newson as Vice President, Alliances and Channels, EMEA. Newson will be tasked with leading Cloudwick’s regional partner strategy from the company’s London office, working alongside Harshdeep Singh, GM, EMEA at Cloudwick, and the UK" last_modified: "2026-08-14T12:29:49+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.channelinsider.com/feed/" wpe_sourcepermalink: "https://www.channelinsider.com/channel-business/vendor-leadership-and-partner-programs/cloudwick-names-john-newson-vp-alliances-channels-emea/" --- # Cloudwick Names John Newson VP, Alliances and Channels, EMEA Cloudwick has appointed AWS veteran John Newson as Vice President, Alliances and Channels, EMEA. Newson will be tasked with leading Cloudwick’s regional partner strategy from the company’s London office, working alongside Harshdeep Singh, GM, EMEA at Cloudwick, and the UK team. ## Newson joins Cloudwick after a decade at AWS UK Public Sector The new channel leader brings more than 20 years of experience in technology roles in the UK government, including a decade at AWS building and leading the UK Public Sector partner business. “Having collaborated closely with John over the last 10 years while he built and led the UK Public Sector partner business at AWS, I have seen firsthand his exceptional ability to cultivate thriving partner ecosystems,” said Harshdeep. “His deep understanding of public sector technology and his proven track record make him the perfect addition to our leadership team.” Prior to AWS, Newson held roles at Symantec, Veritas, and Dell, selling IT infrastructure, information security, and data management solutions to UK central and regional government and healthcare entities. Most recently, he served as Head of Public Sector Partners, UK&I, by [designing a partner strategy](https://www.channelinsider.com/channel-business/aws-onegov-secret-cloud-ai-engineers/) that built a community of software and consulting partners delivering outcomes for UK government agencies. “Having worked with Cloudwick for the past 10 years as an AWS partner, I’ve always been impressed by the team’s expertise and the impact they’ve delivered for public sector organizations,” said Newson. “I’m excited to join Cloudwick to expand our alliances and channel partners across EMEA, helping customers transform data into business value by innovating faster, operating smarter, and achieving lasting impact.” ## Cloudwick Data Management Maturity Assessment Newson’s appointment comes shortly after the organization introduced the Data Management Maturity Assessment, designed to address the gap between the data an agency has and the data it can actually use. The assessment evaluates six dimensions of data management maturity, produces a score for each, and provides a plain-language summary of what the profile means in practice. It takes approximately 30 minutes to complete and provides three things: - A dimension-by-dimension maturity profile that shows where the agency stands, not where it aspires to be. - Practical, specific guidance on where to focus next, based on the profile rather than a generic best-practice checklist. - A concrete product that a leadership team can look at together, debate, and use as the basis for a real conversation about priorities. The assessment was designed for senior leaders in state and local government: CIOs, CDOs, heads of data, program directors, and others who make or influence decisions about data and technology. The post [Cloudwick Names John Newson VP, Alliances and Channels, EMEA](https://www.channelinsider.com/channel-business/vendor-leadership-and-partner-programs/cloudwick-names-john-newson-vp-alliances-channels-emea/) appeared first on [Channel Insider](https://www.channelinsider.com/). --- --- title: "Cyera’s Oasis Security Buy is All About AI Agent Control" url: "https://www.darkreading.com/identity-access-management-security/cyera-oasis-security-acquisition-ai-agent-control" lang: "en-US" type: "post" description: "The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles." last_modified: "2026-08-14T12:17:21+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.darkreading.com/rss.xml" wpe_sourcepermalink: "https://www.darkreading.com/identity-access-management-security/cyera-oasis-security-acquisition-ai-agent-control" --- # Cyera’s Oasis Security Buy is All About AI Agent Control The $1 billion deal aims to converge data security and identity into a single control plane for agents, with privileged access redefined around business context rather than static roles. --- --- title: "WhatsApp is testing a new warning for scam messages" url: "https://www.malwarebytes.com/blog/news/2026/08/whatsapp-is-testing-a-new-warning-for-scam-messages" lang: "en-US" type: "post" description: "Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an on-device machine-learning model to flag likely scam messages from people who are not in" last_modified: "2026-08-14T12:05:43+00:00" categories: [Global Security News] custom_fields: wpe_campaignid: 53 wpe_feed: "https://www.malwarebytes.com/blog/feed/index.xml" wpe_sourcepermalink: "https://www.malwarebytes.com/blog/news/2026/08/whatsapp-is-testing-a-new-warning-for-scam-messages" --- # WhatsApp is testing a new warning for scam messages Meta [announced](https://about.fb.com/news/2025/08/new-whatsapp-tools-tips-beat-messaging-scams/) it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an on-device machine-learning model to flag likely scam messages from people who are not in a user’s contacts. The Scam Alert feature arrives as scammers increasingly use WhatsApp for impersonation, [fake jobs](https://www.malwarebytes.com/blog/scams/2026/06/watch-out-for-high-paying-low-effort-amazon-job-texts), [fake sales](https://www.malwarebytes.com/blog/scams/2026/06/scammers-love-meta-according-to-lloyds-bank), investment fraud, romance baiting, malicious links, and payment requests. These campaigns often begin on another platform before moving victims into a private chat, where criminals can apply pressure and build trust. Once enabled, Scam Alert downloads a machine-learning model to the device and examines incoming messages from non-contacts for patterns associated with scams. WhatsApp says the model uses linguistic signals and conversational structure learned from scam conversations previously reported by users. It is a meaningful new defensive layer, but it will not block anything. Instead, it alerts the user to stop and think carefully before engaging with the sender. There’s another important limitation: some of the most effective WhatsApp scams arrive from a compromised contact, such as the recent “[vote for my friend](https://www.malwarebytes.com/blog/scams/2026/08/whatsapp-account-takeover-scam-asks-you-to-vote-for-my-friend)” account-takeover campaign. Because the message appears to come from someone the victim already knows, an unknown-sender warning may never appear. Scam Alert is another step in [Meta’s anti-scam campaign](https://www.malwarebytes.com/blog/news/2026/03/meta-rolls-out-anti-scam-tools-across-whatsapp-facebook-and-messenger) across WhatsApp, Facebook, and Messenger to fight sophisticated fraud tactics. ![Phone Scam Check](https://www.malwarebytes.com/wp-content/uploads/sites/2/2026/05/scam-number-cta_0056d8.png) ### Don’t recognize that number? We’ll check it. [CHECK NOW](https://www.malwarebytes.com/scam-check/phone) If the model identifies what might be a scam, WhatsApp displays a warning banner in the chat. The sender does not see the warning, so the feature should not tip off a scammer that their approach has been detected. Users can then: - Block the sender, preventing further messages. - Report the chat to WhatsApp. - Continue the conversation if they believe it is legitimate. - Mark the chat as trusted, which removes the warning and prevents Scam Alert from flagging that conversation again. WhatsApp’s Scam Alert is a promising example of using on-device AI to add friction to scams without requiring a provider to read private conversations. Its optional nature, local classification, transparency commitments, and lack of automatic reporting are notable design choices for an encrypted messaging service. The feature is currently in a limited beta rollout and is being tested with researchers in Meta’s bug bounty community before a wider release. ## How to stay safe To protect your WhatsApp account from takeover: - [Enable two-step verification for WhatsApp](https://www.malwarebytes.com/blog/news/2025/09/how-to-set-up-two-step-verification-on-your-whatsapp-account). - Don’t click unexpected links, particularly if the message asks you to verify, connect, or link your WhatsApp account. - Never follow instructions to link devices or scan QR codes unless you initiated the action yourself. - Regularly review your linked devices in WhatsApp (**Settings** > **Linked devices**) and log out of any you don’t recognize. To stay out of the hands of scammers: - Be wary when a Facebook or Instagram exchange tries to migrate to WhatsApp. That handoff to a private channel is a classic scammer move, taking the conversation away from public scrutiny and platform enforcement. - Research the account that contacted you. What other activity is there on the account? Do they have an established profile? - Pay with a card or service that offers chargeback protection. Never pay by bank transfer, cryptocurrency, gift card, or Friends and Family payment methods when buying from someone you don’t know. - Remember that seeing an ad on a major platform isn’t an endorsement. Scammers routinely place ads alongside legitimate businesses. If you’re unsure whether a flagged chat is a scam attempt, you can always ask [Malwarebytes Scam Guard](https://www.malwarebytes.com/solutions/scam-guard) for a second opinion. It’s free, available for [mobile](https://www.malwarebytes.com/solutions/scam-guard), [desktop](https://www.malwarebytes.com/blog/product/2026/02/scam-guard-for-desktop-a-second-set-of-eyes-for-suspicious-moments), and integrated into major AI chatbots like [ChatGPT](https://www.malwarebytes.com/blog/product/2026/02/scam-checking-just-got-easier-malwarebytes-is-now-in-chatgpt) and [Claude](https://www.malwarebytes.com/blog/product/2026/04/scam-checking-just-got-a-lot-easier-malwarebytes-is-now-in-claude). ### **Something feel off? Check it before you click. **  **Malwarebytes Scam Guard** helps you analyze suspicious links, texts, and screenshots instantly.   Available with [Malwarebytes Premium Security](https://www.malwarebytes.com/premium) for all your devices, and in the [Malwarebytes app for iOS and Android](https://www.malwarebytes.com/mobile).   [Try it free →](https://www.malwarebytes.com/solutions/scam-guard)  ---