
Prime Day 2026 has officially started. Save hundreds right now on smartphones, including the Google Pixel 10 Pro and Samsung Galaxy S26.

If you’re looking to ditch Roku since Fox bought it, I’ve rounded up your four best bets.

Apple’s iOS 27/macOS 27 cycle is revealing something new: AI is only as good as the operating system that supports it. The latest beta releases show that after two years in which the company has promised to become AI-native, testers finally believe it’s happening as Apple prioritizes improved system performance and Siri AI. For example, the second…
Meraki’s automatic espresso machine is an at-home barista’s dream, and it just got cheaper.
Meanwhile, AI data centers will mop up 70% of all memory chips produced this year.
The right kitchen tools make a big difference in your culinary life – and some of my personal favorites from Ninja, Breville, Le Creuset, and more are discounted for Amazon Prime Day.

Operation Endgame, the largest international law enforcement operation aimed at disrupting ransomware and cybercrime infrastructure across the world, has claimed its latest targets: StealC and Amadey. The notice on disrupted websites (Source: Microsoft) While developed by separate criminal groups, those two malware families work in tandem to compromise devices and harvest sensitive data. Law enforcement…
A third-party supplier breach has exposed LastPass customer names, phone numbers, and other data. Here’s how to protect yourself.

Fake subscription renewal notices are doing the rounds again. Some of these scams impersonate Malwarebytes, and we’ve also seen them reach our customers. You’re more likely to trust the message if you’re already a customer of the company mentioned in the email. That’s what the scammers are counting on. So we want to make people…
Google just launched its Google Home Speaker, a new smart home speaker that directly competes with the Apple HomePod mini and Echo Dot Max.

An Algerian national accused of running online marketplaces that sold phishing kits and fraud tools has been extradited from Spain to the United States to face bank fraud conspiracy charges. The post Algerian national accused of running cybercrime marketplaces extradited to US appeared first on Help Net Security.
Service desks have become a favored target for attackers seeking password resets, MFA changes, and access to corporate accounts. Specops Software breaks down how service desk social engineering attacks work and how organizations can defend against them. […]

Anthropic introduced an agent identity model for Claude Tag, its AI assistant designed for team collaboration in shared workspaces. The model gives Claude its own identity, permissions, and tool access, configured by administrators and tied to a workspace or channel. Because Claude does not rely on individual user credentials, access remains separate from employees’ personal…
The vulnerability stems from a race condition within the kernel’s process integrity validation.

Frontier AI could drive a 10x surge in vulnerabilities. CTEM helps organizations continuously identify, prioritize, and reduce real cyber risk. Your vulnerability management program was not designed for what is coming next. More than 40,000 CVEs were reported in 2025, breaking yet another record. Today, security experts anticipate that frontier AI-powered systems could drive a…
Secure Boot has always been a nuisance for Linux users, but Microsoft’s expiring 2011 certificate authorities are making it a real pain.
This episode of Coffee with the Council is brought to you by our podcast sponsor, Clone Systems. Welcome to our podcast series, Coffee with the Council. I’m Alicia Malone, Director of Communications and Public Relations for the PCI Security Standards Council. Today, I’m excited to bring you a sneak peek interview with PCI SSC’s…

Attackers exploit Cisco Unified CM flaw (CVE-2026-20230) allowing unauth HTTP requests to trigger SSRF, write files, and gain root access Cisco Unified Communications Manager has a serious vulnerability, tracked as CVE-2026-20230 (CVSS score of 8.6), that attackers are already exploiting. The flaw, caused by improper validation of certain HTTP requests, allows a remote attacker without…

This is sponsored content. Kyle Yost, President of En-Net Services, discusses how working with Eaton has enabled his business to support the complex IT needs of its public sector customers. The conversation also shows how AI adoption is opening new opportunities for partners and vendors like Eaton to build successful outcomes for mutual customers. The…
Over a 30 day period, Tenable detected 457 million AI-related security issues among 7,000-plus organizations, an average of 62,000 exposures per organization. If we didn’t already know that shadow AI was a problem, data like this makes it clear every organization needs to visualize, map, assess, and protect with a comprehensive exposure management program. Key…

Cynomi has rolled out the largest platform expansion in its history, adding new vulnerability management integrations, scheduled scanning, compliance file management, and expanded AI capabilities designed to help MSPs and MSSPs scale cybersecurity services across more clients. The release, announced June 24, connects security findings, remediation planning, compliance evidence, and AI-assisted workflows inside Cynomi’s Security…
Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains. The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and

In a novel maneuver for a disruption operation against cyber attackers, industry and law enforcement teamed up to conduct a court takedown of two widely-used criminal tools at once rather than individually, Microsoft said Tuesday. The takedown simultaneously went after Amadey, a botnet that can serve as a malware delivery system, and StealC, an infostealer.…
Healthcare technology company Xsolis confirmed that a phishing attack resulted in unauthorized access to its network. The company develops AI-powered software for hospitals, health systems, and health plans and serves more than 600 hospitals and health insurers. “On January 22, 2026, Xsolis became aware of unauthorized activity impacting a limited portion of the Xsolis environment…
SuperOps and Guardz announced a strategic partnership, combining their platforms into a single bundled offering for managed service providers (MSPs). The package brings professional services automation (PSA), remote monitoring and management (RMM), mobile device management (MDM), and agentic security operations into one purchase. Both companies build AI-native software for the MSP market. SuperOps runs IT…
It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn’t hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational decisions…so we remain focused on helping stakeholders apply security guidance in ways that are practical and actionable. What’s Been Happening Lately?…
CVE-2026-20230, a server-side request forgery (SSRF) vulnerability affecting Cisco’s Unified Communications Manager (Unified CM), is being exploited to drop webshells and achieve remote code execution capability on the underlying server. “Our honeypots are seeing automated sweeps dropping webshells, all via Tor,” threat intelligence firm Defused warned today, after observing initial attacks over the weekend. “The…

A critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow attackers to gain root access. Threat intelligence firm Defused reported the exploitation on June 23. The company said it observed the activity over the weekend. “This is currently being exploited from a single source…
Australian organisations are pushing AI agents into production faster than they can govern them. Most can’t see what those agents are doing, can’t control where they wander,…

We are standing at the end of an era we never thought to mourn: the era of human-speed threats. For years, cybersecurity moved to a rhythm organizations could follow. A researcher found a bug, a CVE was cataloged, a vendor navigated a patch cycle, and weeks or even months later, a fix was deployed. In…

The AI IPO tsunami on the stock market has only recently gotten under way, with SpaceX’s more-than-$2 trillion IPO likely to be followed in several months by OpenAI’s and Anthropic’s IPOs — each of which is likely to hit $1 trillion. That will mint three new trillion-dollar AI companies in a matter of months, all…

AI has created a tough job environment for entry-level workers and things aren’t getting better anytime soon — even those with AI capabilities now need “senior-level” skills to land a job. “AI-exposed entry-level roles are seven times more likely to require traditionally senior-level skills such as judgement and leadership,” consulting firm PwC said in a…

At the moment, we’re seeing all kinds of sextortion emails. The scam is cheap to run, easy to automate, and apparently profitable enough that cybercriminals keep using it. Some criminals put more effort into their messages than others. Sextortion emails are messages claiming that scammers recorded you through your webcam while you watched pornography and…

A fake AI agent skill that passed security checks reached over 26,000 users through Instagram, highlighting new risks as enterprises rely on AI-driven tools. Some of the agents involved were tied to corporate accounts, AIR said. The company said a similar attack could have exposed private conversations and internal systems. AIR said no agents were…
The morning Adobe Summit Sydney keynote linked further below ended with a Qantas executive quietly taking the whole agentic pitch apart. After the coffee break, Adobe got the…
Some of my favorite practical Bluetooth gadgets are also on sale during Amazon Prime Day.
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Ubiquiti UniFi OS and Lantronix EDS5000 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Ubiquiti UniFi OS and Lantronix EDS5000 flaws to its Known Exploited Vulnerabilities (KEV) catalog. The two flaws added to the catalog are: CVE-2025-67038 Lantronix EDS5000 Code Injection…

LastPass disclosed that attackers used OAuth tokens compromised in a supply chain attack on Klue, a market intelligence platform that integrates with CRM and sales tools across organizations, to access customer data stored in its Salesforce environment. “On June 12th LastPass was made aware of an incident that occurred at Klue (klue.com), a third-party market…
LIVE: Prime Day 2026 deals are here, but they aren’t all good. Follow our live blog for real-time tracking on hand-picked products like 4K TVs, M5 MacBooks, Samsung devices, SSDs, and more.
Few things are as delightfully divisive as Android’s dark mode. Some phones now ship with Android’s darker-style interface activated by default. Most reasonably recent devices offer it as a swift ‘n’ simple toggle. And most people, in my experience, have amusingly strong preferences about which approach they prefer — the standard Android “light” mode, in…
FortiBleed exposed valid credentials for 73,000+ Fortinet firewalls, revealing a large-scale access-brokering operation targeting organizations worldwide. In mid-June 2026, researcher Volodymyr “Bob” Diachenko found a live, exposed server containing working login credentials for tens of thousands of Fortinet firewalls, a data leak code-named FortiBleed. The headline number, valid remote-access logins for 73,932 devices across 21,632…

Google’s Alert Center, a dashboard in the Google Admin console that displays security and administrative alerts and helps administrators identify, investigate, and respond to issues affecting their organization, is expanding the “Super Admin password reset” alert into the “Admin password reset” alert. The feature is rolling out gradually and will be available to all Google…
Apple Maps has improved over the years, but how does it stack up to Google Maps today? Here’s my verdict after extended use.
A prominent AI expert says that forward-deployed engineers are limited, and that the broader emerging category of AI engineers has the greatest career potential. Is he right?
Security awareness training as a defense against phishing is dead. It has been dead for a while. The industry never held a funeral because the training budget is comfortable, the compliance box gets checked and no CISO wants to tell the board that the program everyone funds does not work. The premise was simple. With…

An epidemic of cyberattacks on open-source software has mounted in recent months, making clear how uniquely difficult it is to protect the publicly available code, from both a policy and a technical perspective, that serves as the foundation for so much of the digital world. While open-source software security got a boost in attention under…

The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by subsidiaries of Cambodia-based corporate conglomerate HuiOne Group, as the Treasury unveiled fresh sanctions against nine individuals and 26 entities linked to Prince Group. “These subsidiaries are alleged to have assisted individuals and organizations in transferring…
Public Accounts Committee (PAC) warns that museums and galleries aren’t getting enough government support on cyber

A nationwide GSM-R outage stopped trains across Germany, exposing how one aging communications system can still bring an entire rail network to a halt At 10:30 PM on Tuesday June 23, Deutsche Bahn told passengers something that had never happened before for technical reasons: all trains across Germany were being held at their stations. The…
New autonomous agent reduces incident toil, while agent-first tools empower customers to ground their own AI systems in the industry’s deepest observability data.
Compare crypto payment gateways for ecommerce, including checkout tools, stablecoin payments, fiat settlement, plugins, APIs and business payouts.

Qodo has announced three new platform capabilities: Cross-Repo Code Review, Custom Rules Miner, and Skill Review Standards. These new capabilities address a set of governance gaps that have emerged as AI-generated code reaches enterprise scale. AI agents have fundamentally changed how software is built. Code that once required developers to write, test, and review is…

Brinqa BYOAI (Bring Your Own AI), a capability that enables organizations to connect any AI agent, large language model (LLM), or automation platform to Brinqa’s exposure intelligence layer. As enterprises adopt AI, they need to ensure that AI systems use accurate, up-to-date risk data. BYOAI connects existing AI tools to a common source of exposure…

Cequence Security has announced the launch of Intent Graph and Biometric Check, two new capabilities that extend the behavioral architecture Cequence has built since its inception. They provide enterprises with bot defense that works across web, mobile, API, and agentic AI traffic, without relying on the client-side signals that sophisticated bots have learned to defeat.…
Owl Labs has unveiled its first subscription service for IT administrators: Owl 360 Services. The AI-powered video conferencing and hybrid collaboration technology provider launched the service to meet the demands of organizations seeking greater support for hybrid work with deeper video enablement across more spaces. Owl 360 Services tiers Owl 360 Services features three subscription…

At Everpure’s Accelerate 2026 conference in Las Vegas last week, data intelligence and shifting from application-centric systems to data-centric governance and intelligence were key talking points throughout. In an interview, Shawn Hansen, VP Platforms, Everpure, emphasized the importance of the channel ecosystem to Everpure’s strategic shift and the need for intelligence. Everpure’s strategic shift follows…

Secure Code Warrior has introduced its new SCW AI Adoption Model, a practical framework that maps the progression of AI use in software development, from minimal AI assistance to fully autonomous agentic orchestration. The framework helps CISOs assess their organization’s level of AI adoption, identify the training developers need at each stage, and determine the…

DigiCert has announced it is bringing independent trust validation to confidential computing environments, in collaboration with Google Cloud. By applying the proven principles of Public Key Infrastructure (PKI) to cloud infrastructure, DigiCert will provide cryptographic verification that cloud-hosted systems and workloads are authentic, trusted, and untampered. As organizations move more sensitive applications, AI workloads, and…
Widespread enterprise adoption of AI has created a pressing need for security solutions — a tall order given that AI’s reach into organizational infrastructure and data is enormous and continues to grow. Moreover, where an organization sits on the AI maturity curve impacts its security needs. Trail of Bits CEO Dan Guide describes the AI…
Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validation for specific HTTP requests that could allow an unauthenticated, remote
LastPass spent more than a decade telling people to stop reusing the same tired password. Now its CEO wants to watch every app and AI tool your staff open in the browser, and…
In a previous diary, I talked about stack strings[1] with a practical example of them. Since my SEC670 class, I’m even more interested in malware obfuscation techniques. I had a look at process names. When you list running processes on a computer, can you trust what you see? If you’re facing a rootkit, malicious processes can be…
Five cyber agencies, one message: get the basics right, wire AI into your defence, and stop treating a breach as a maybe. Here’s what the warning means for Australian…

In this interview with Help Net Security, Jorge Aldegunde, Global Head of Railway Services at DNV, talks through what happens when old operational technology meets newer IT in monorail systems. He explains why open networks widened the attack surface, how teams decide whether to patch a signalling flaw without stopping trains, and who carries the…
Praxen is an open-source tool with a simple job: it checks whether an AI agent does what it claims to do. The tool takes an agent’s declared policy, looks at how the agent operates, and points out every spot where the two drift apart. It is the reference implementation of Agent Behavior Verification, a control…

I know enough about home cinema audiovisual to know there’s a lot I don’t know. It’s conscious incompetence, if you like, which is different to the unconscious incompetence most people have on the topic. That’s not to sound derogatory (it’s spelled out that way in the competence model), rather it recognises that this is a…
The Agentic SOC market is loud. Dozens of vendors promise to take alert triage, investigation, and response off your analysts’ plates, but most claims have never been tested in production. The hard part is separating operational improvement from this marketing noise. Gartner makes the stakes concrete. In Validate the Promises of AI SOC Agents With…
For years, organisations approached email security as a technology problem. Deploy a secure email gateway (SEG), add filtering tools, automate remediation workflows, and assume the problem was solved. That approach no longer works. Today’s attackers are using AI to create polymorphic phishing campaigns that continuously evolve to evade traditional detection systems. They rotate URLs, vary…

Software teams are pushing code into production faster than security testing can keep up. AI is accelerating development cycles and adding pressure to security programs that rely on periodic validation and manual penetration testing. The 2026 State of AI Security Testing report from Aikido Security found that 76% of organizations have had to stop, restrict,…
– Proofpoint has been selected to participate in OpenAI Daybreak, which helps trusted cybersecurity companies integrate AI into defensive security operations. – Through the…
Open-source tool helps organisations understand an AI agent’s intended job, verify its authorised actions, and identify behavioural gaps before deployment.
Application Security Leader DriveNets | Israel | Hybrid – View job details As an Application Security Leader, you will define security requirements, drive secure coding practices, oversee vulnerability management, and integrate security testing and automation into development pipelines. You will establish security governance initiatives, including a Security Champions program, provide meaningful security metrics to leadership,…