The offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers’ increasingly advanced capabilities.
Global Security News
iPhone 18 Pro Max stuck in SOS mode? Try AT&T’s urgent fix ASAP
Some iPhone 18 Pro Max users can’t call or text. AT&T is telling them to update immediately.
Global Security News
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. […]
Global Security News
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. […]
Global Security News
This new ChatGPT scam tricks you into installing malware – how to spot the trap
This authentic-looking scam starts with a sponsored Google link – and it’s catching people off-guard.
Global Security News
The legal questions raised by agentic AI hacks
As AI agents escaping testing sandboxes and hacking organizations have gone from unprecedented to seemingly routine in a matter of weeks, policymakers, regulators and cybersecurity attorneys largely agree on one thing: Something must be done to hold AI companies accountable for the incidents. Exactly what can be done under our current laws and regulations is…
Global Security News
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab’s AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw…
Global Security News
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
Global Security News
AI’s ‘Thought’ Process Can No Longer Be Trusted, Raising Risks of Rogue Models
As frontier models advance, the gulf between what they do and what they say they do is growing.
Global Security News
67% of US Companies Use AI, but Orchestration Lags
Pipefy’s latest survey found a widening gap between AI adoption and AI orchestration among U.S. businesses: 67.1% of respondents said they use AI in at least some processes, but just 6.6% have fully orchestrated workflows from end to end. As companies expand their use of AI agents, that gap could create new opportunities for MSPs…
Global Security News
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below – CVE-2026-63688 (CVSS score: 10.0) – A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an
Global Security News
Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response
One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
Global Security News
Heimdal Extends European MSP Security Reach Into DACH With Elovade
Heimdal is expanding its MSP security reach across Germany, Austria, and Switzerland through a broader distribution agreement with Elovade. Under the deal, Elovade will distribute Heimdal’s security platform to partners across the DACH region, extending a relationship the companies already use in other European markets. Regional MSPs will ultimately judge the rollout by how cleanly…
Global Security News
SWIFT Banking & Government Middleware Enables RCE
Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.
Global Security News
84% of Security Leaders Expect Bigger Cyber Budgets as AI Threats Grow, PwC Finds
Cybersecurity budgets are rising, but AI is also exposing gaps that many organizations have not yet closed. PwC’s 2027 Global Digital Trust Insights Survey found that 84% of security and finance leaders expect cybersecurity spending to increase over the next 12 months, up from 78% a year earlier. AI is a major driver, with 58%…
Global Security News
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. […]
Global Security News
Is Your Organization Ready for 2027’s AI Accountability Era?
Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.
Global Security News
The Quest to Quiet Hospital Alarms
Plus, why we sound like chatbots, how El Niño made the Atlantic hurricane season disappear, and the race to build AI defenses against bioweapons.
Global Security News
Is It Fair to Blame ‘Rogue’ AI for Security Failures?
“Rogue AI” terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.
Global Security News
MegazoneCloud, Portal26 Target Shadow AI in Korea
AI and cloud company MegazoneCloud has signed a strategic reseller agreement with Portal26 to bring the U.S. company’s generative AI governance and security platform to enterprise customers in Korea. Under an agreement signed September 28, MegazoneCloud will resell Portal26’s AI Adoption Management Platform and provide technical support, while the companies develop governance and security offerings…
Global Security News
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. […]
Global Security News
Google Wallet not working on your Pixel? 4 ways to fix tap-to-pay
Some Pixel users are having tap-to-pay problems, and there’s no fix from Google yet. But here a few things that helped others.
Global Security News
Tech Companies Roll Out Cuddly Mascots to Ease AI Anxiety
Meta, OpenAI and others are associating their AI agents and tools with cute characters to win over skeptics.
Competitive Reports, Cybersecurity News
Fal.Con 2026: Comprehensive Market Intelligence Report 2026
eCrime Actor Activity 3. Falcon Guardian — Technical Architecture Deep Dive Core Capabilities Capability Description AI Agent Discovery & Inventory Continuously discovers known and shadow AI agents across Windows, macOS, Linux endpoints. Identifies deployment origin, usage patterns, and security status. Agent Runtime Visibility Connects AI agent behavior directly to Falcon endpoint telemetry; establishes a causal…
Global Security News
Salesforce to Acquire Listen Labs in Reported $2 Billion Deal
Salesforce is buying an AI startup that wants to make customer research operate at software speed. The company has signed a definitive agreement to acquire Listen Labs, an AI customer research and simulation platform. Salesforce did not disclose financial terms, although MarTech reported that the deal is expected to be worth about $2 billion. The…
Global Security News
AI Agents Attempt SQL Injection While Searching Government Data
AI agents probing US and Canadian government sites made SQL injection attempts while seeking data, but investigators found no evidence of compromise. Autonomous AI agents, working on what looks like ordinary data retrieval tasks, ended up throwing basic hacking attempts at a U.S. Department of Education site and Library and Archives Canada. Nobody told them…
Global Security News
Microsoft: AI Cuts Post-Compromise Attack Time to Minutes
Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks
Global Security News
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. […]
Global Security News
Vulnerability Backlogs Are an Ownership Problem
Organizations don’t need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.
Global Security News
AWS Counters AI Backlash with Community Investments
Plus, AI tests higher education
Global Security News
A Vulnerability in Fortinet FortiMail Could Allow for Arbitrary Code Execution
A vulnerability has been discovered in Fortinet FortiMail that could allow for arbitrary code execution. Fortinet FortiMail is a secure email gateway that protects organizations from inbound threats including spam, phishing, malware, and business email compromise, while also preventing outbound data loss across physical, virtual, and cloud deployments. Successful exploitation of this vulnerability could allow…
Global Security News
Trump’s Super Intelligence edict supercharges .si domain registrations
US President Donald Trump’s rebranding of artificial intelligence (AI) as super intelligence (SI) has already caused a flurry of activity for one internet domain registry. SI is the international country code for Slovenia, and in the 24 hours following Trump’s executive order, Slovenia’s .si domain registry recorded 9,780 new .si registrations, compared to just 3,515…
Global Security News
Broadcom Offers Anthropic Up to $42B to Finance AI Infrastructure
Broadcom isn’t just supplying Anthropic’s AI infrastructure. It’s helping finance it, too. The company has agreed to lend Anthropic as much as $42 billion to help finance its AI infrastructure, according to Anthropic’s IPO prospectus reviewed by Reuters. The financing would take the form of convertible notes that could eventually become Anthropic shares. Broadcom can…
Global Security News
Follow the thread: a new dashboard to investigate account abuse
Traditionally, preventing online fraud relied on point-in-time proof of identity: enter the correct password, complete a biometric verification, or pass a liveness check, and gain access. To defeat these controls, fraudsters had to steal credentials and other identity evidence from a real user, which was difficult to execute and scale. Today, widespread access to AI…
Global Security News
Protected Quick Tunnels: simple accountless authentication for your next dev project
We launched Quick Tunnels in 2021 to give developers an easy way to share their latest service, application, or project running in their local development environment. A lot has changed since then, but the core use case remains the same. Your coding agent has just finished the feature. The dev server is up on localhost:5173, and…
Global Security News
Malicious Linux Implants Mimic Asian Mail Security Products
A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it’s hard to tell they’re not.
Global Security News
AI is giving attackers a head start, Microsoft warns
Threat actors are using AI to find bugs, build malware and run intrusions faster than defenders can keep up. Microsoft’s 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the benefits of AI first and defenders have to move quickly to close the gap. “AI is…
Global Security News
Dell asks admins to patch max severity CSM flaws as soon as possible
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. […]
Global Security News
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. “We have parted ways with three individuals for violating our policies on accessing and handling sensitive company information,” a spokesperson for the company was quoted as saying. “Our investigation…
Global Security News
Vectra AI Ascent Partner Program Expands Security Services
Vectra AI is expanding its channel strategy with the launch of its global Ascent Partner Program, a new framework designed to help resellers, MSSPs and integrators build AI security services beyond traditional technology resale. The program combines co-selling, co-marketing, co-delivery and co-innovation with expanded enablement and incentives as Vectra AI looks to give partners a…
Global Security News
367,000-Ship Study Finds Global GPS Spoofing, Red Sea Activity Before Grounding
A study of 367,000 ships finds global GPS spoofing, including Red Sea activity detected months before the MSC…
Global Security News
Why CISOs Struggle to Answer the Board’s Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spreadsheet into slides. Then a board member asks three questions: How…
Global Security News
How Meta stumbled onto a winning AI strategy
We’re on the brink of a revolution in how people use AI. Today, people mostly use non-agentic, non-personalized, non-proactive AI tools via PC browsers and mobile apps. Very soon, I predict, most AI usage will move to agentic, personalized, and proactive AI assistants via wearables like glasses, watches, and earbuds. We’ll move from mostly typing…
Global Security News
US FTC will investigate Anthropic and OpenAI
The US Federal Trade Commission has warned leading AI players that they will to have tighten up their acts. The agency will soon send formal demands for information to Anthropic, OpenAI, and other AI companies as part of an investigation into whether they are breaking consumer protection laws. The FTC has acted following a number…
Global Security News
Chinese spies impersonate White House, Anthropic figures to phish AI policy experts
A China-aligned espionage group has been posing as a former White House official and a prominent economist to get into the cloud accounts of AI policy experts in the US, Proofpoint have found. The group, which the researchers track as TA419, ran several credential phishing campaigns in July 2026. “In July 2026, TA419 impersonated multiple…
Global Security News
They’re Known as Swarm Chasers—and They Spring Into Action When AI Goes Rogue
Online sleuths hunt for clues of bad behavior. Their work is our starkest understanding yet of what happens when AI goes wrong.
Global Security News
Will America Spend 9% of Its GDP on AI? The Industry Is Counting on It.
To justify staggering investment sums, Americans will have to spend as much of their income on this one technology as they do on food.
Global Security News
Microsoft’s X account hacked in crypto pump-and-dump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. […]
Global Security News
Police Target KillSec Ransomware Group with Arrests and Seizures
Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects
Global Security News
BlueVoyant Launches Microsoft ISOC Deployment Service
BlueVoyant has launched a Microsoft Defender XDR ISOC Deployment Service to help organizations prepare their security operations environments for Microsoft’s push toward more integrated, agent-driven security. The service is designed for Microsoft 365 E5 and E7 customers and Microsoft Defender Suite users, with a focus on assessing existing deployments, configuring underlying security technologies, and operationalizing…
Global Security News
Rolling the cyber dice with open-source and open-weight AI models
With typical cybersecurity exposure, I can conduct pen testing with deterministic tools. I am able to predict how a piece of software is going to respond. I even stand a decent chance of finding vulnerabilities before they can be exploited against me. What we are dealing with now is a new kind of exposure. For…
Global Security News
Amazon’s New Push to Get Buy-In for Data Center Build-Out
The company is pledging transparency—and an extra $1 billion in community support—to woo skeptics and win ‘the race our nation can’t afford to lose.’
Global Security News
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. About CVE-2026-104286 “An Improper Limitation of a Pathname to a Restricted…
Global Security News
EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage
Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational capacities of technology vendors whose wares compete in those markets. The EU CRA introduces mandatory reporting within 24 hours for any actively exploited vulnerabilities or severe incidents affecting products…
Global Security News
Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure
The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days
Global Security News
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android’s accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway.…
Global Security News
AI could boost software engineer productivity by 32.6%
Tools such as Anthropic Claude Code or OpenAI Codex have changed the face of software development, and all the signs are that this investment is set to increase further. But is paying a monthly subscription (and perhaps additional usage fees) cost-effective? Will the increasing level of investment in AI-generated software prove to be worthwhile? That’s…
Global Security News
Investigators trace an AI agent ‘s path from research task to reconnaissance
Asymmetric Security traces rogue OpenAI AI agent activity that probed government sites, accessed staging servers, and evaded sandbox limits. Researchers at Asymmetric Security spent 48 hours over the last weekend reconstructing reported rogue OpenAI AI agent activity that hit the Australian government and other organizations between March and September this year. They worked from public…
Global Security News
Criminal recruiters want people on your payroll
Legitimate employee access can let criminals circumvent security controls that would be difficult to overcome from outside an organization. Routine actions such as information lookups, account resets, transaction approvals and shipment changes can become services sold to criminal customers, according to Intel 471’s Insiders for Hire: Underground Recruitment, Access Claims and Insider-Enabled Services report. A…
Global Security News
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through…
Global Security News
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. “An improper
Global Security News
Android 17 makes it harder for spyware to cover its tracks
When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to Advanced Protection in Android 17, including one that keeps a copy of that evidence off the device. Existing users will receive a notification when the new capabilities become…
GeekGuyBlog
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Global Security News
Botnets, adversarial attacks and data poisoning top leaders’ AI threat list
Companies are putting more money into AI while naming attacks on AI systems as the threat they are least ready to face. PwC surveyed 3,934 business and technology leaders in 71 countries between May and July 2026. Half of the security and technology executives among them ranked such attacks in their top five preparedness gaps,…
Global Security News
AI agents keep access to company data after their work is done
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap. “Written policy is only as good as your ability to enforce it at the moment an AI agent acts,”…
Global Security News
New infosec products of the week: October 2, 2026
Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings security-trained AI and lasting memory to the SOC Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into the…
Global Security News
Lenovo AI Express with NVIDIA Accelerates Path to Hybrid AI Factory in Weeks
New Quick-Start Program Speeds Order-to-Ship to 15 Days for Validated, Right-Sized AI Factory Configurations, Helping Customers Move from AI Strategy to Operations Faster.
Global Security News
Mixpanel Introduces Agent Intelligence, Helping Product Teams Build and Measure More Effective AI Agents
New product connects agent conversations to customer behaviour and business outcomes, alongside broader additions that help teams experiment faster, hand off more legwork to AI…
Global Security News
Don’t sweat the Aussie summer – or your power bill – with the smart, super effective Midea Athena air conditioner
Rapid cooling, built-in Wi-Fi and subscription-free everyday smart controls make Midea’s Athena a thoroughly satisfying upgrade from an ageing split system.
Global Security News
ISC Stormcast For Friday, October 2nd, 2026 https://isc.sans.edu/podcastdetail/10120, (Fri, Oct 2nd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
Omnissa delivers a peek into the benefits of breaking through enterprise data silos
When Omnissa this week rolled out a new AI governance authority product, Elara, in beta, it delivered a glimpse into the potential of having visibility between the typical enterprise’s data silos, whether they’re in lines of business, disparate geographies, or corporate operational units. “By connecting signals across systems that often operate independently, Elara gives IT…
Global Security News
Dell Technologies Introduces New Rugged Laptops Built for the Most Demanding Field Environments
Dell Pro Rugged laptops deliver field-grade durability, advanced connectivity and AI-ready performance
Global Security News
John Kindervag and the Cybersecurity Leaders Who Helped Define Modern Zero Trust Release New Book for the AI Era
Cyber Resilience at Machine Speed: The Zero Trust Model for the AI Era provides a practitioner-led roadmap for building resilience in an increasingly automated world
Global Security News
Cloudflare Launches Basin: A More Open and Accessible Data Platform for Developers
Basin gives any team the tools to collect, store, and analyse data at scale without dedicated servers, vendor lock-in, or fees to move data between clouds.
Global Security News
TrendAI Vision One Extends Claude Compliance API Integration to Cover Claude Code and Cowork Sessions
Security teams can now investigate AI agent activity, including prompts, responses and tool calls, alongside the rest of their security telemetry
Global Security News
Sophos Named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026
Sophos has been named a Leader in the IDC MarketScape for Worldwide Modern Endpoint Security for Enterprises 2026, recognizing the strength of our prevention-first approach and stopping AI-era threats as early as possible.
Global Security News
The Agentic SOC, Delivered: Exabeam Accelerates AI-Powered Security Operations to Machine Speed
New capabilities bring AI-driven investigation, execution, visibility, and governance to cloud and on-premises operations while keeping analysts in control.
Global Security News
Commvault Achieves AWS Data Competency in Relational Databases Category
Commvault, a leader in unified resilience at enterprise scale, today announced that it has achieved the AWS Data Competency in the Relational Database category.
Global Security News
CISA Certification Explained: Skills, Career Opportunities & CISA Training Options from InfosecTrain
In this post, I will discuss the CISA certification. When an organisation needs to know whether its technology, controls and business systems are doing what they are supposed to, it turns to information systems auditors. ISACA’s Certified Information Systems Auditor certification confirms that a professional has the skills this work demands, and it is recognised…
Global Security News
Meta Muse incident – we need to watch AI’s sharp edges
ExpressVPN has warned Meta Muse users to build a framework for dealing with AI agents when they make mistakes, following revelations Meta’s popular AI agent sent a buyer to a…
Global Security News
Wallet Tracker or Copy Trade? Stop Watching Fomo Wallets and Copy Them With Banana Gun
A wallet tracker tells you that a wallet traded, and a copy trade places the trade for you inside limits you set. Banana Gun does the second. You give the Telegram trading bot a wallet address, a market-cap ceiling and a buy size, and it buys after that wallet does. Fomo, a self-custodial social trading…
Global Security News
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. […]
Global Security News
Aussie Engineers at the Heart of MongoDB Atlas Infinite Launch
MongoDB announced that a local team of Australian engineers is playing an important role in delivering Atlas Infinite, the largest architectural innovation to MongoDB Atlas…
Global Security News
Micropatches released for Windows WalletService Elevation of Privilege (CVE-2026-49176)
July 2026 Windows Updates brought a patch for CVE-2026-49176, a local privilege escalation vulnerability in WalletService service, allowing a regular local user on the computer to elevate themselves to Local System. The vulnerability was found and reported to Microsoft by Chen Le Qi and Nguyn ng Nguyn with STAR Labs SG. Subsequently, David Carliez published…
Global Security News
Alleged KillSec Ransomware Mastermind a 16-Year-Old
Law enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
Global Security News
Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. […]
Global Security News
A Vulnerability in Kiteworks EPG (Email Security Gateway) Could Allow for Arbitrary Code Execution
A vulnerability has been discovered in Kiteworks EPG (Email Security Gateway) that could allow for arbitrary code execution. Kiteworks Email Protection Gateway (EPG) is a cloud-based security solution that automates end-to-end encryption, decryption, and policy enforcement for inbound and outbound enterprise emails. A combination of input-handling flaws in publicly reachable endpoints of the Kiteworks Email…
Global Security News
A Vulnerability in WordPress Could Allow for Remote Code Execution
A vulnerability has been discovered in WordPress that could allow arbitrary code on the web server. WordPress is a free, open-source content management system (CMS) that allows you to build and manage websites without needing to write code. Successful exploitation allows an unauthenticated attacker to manipulate the page-template resolution logic to execute local PHP files…
Global Security News
KillSec Ransomware Group Dismantled, 16-Year-Old Suspected Admin Arrested
An international police operation has disrupted the KillSec ransomware group, with three suspects arrested, five servers seized and…
Global Security News
Authorities seize KillSec extortion group infrastructure, arrest 3 alleged members
Authorities arrested the alleged leader and two additional members of KillSec, a data extortion group primarily run by teenagers that successfully compromised about 500 organizations since 2024, Europol and the Justice Department said Thursday. Investigators said the alleged leader of the group is 16 years old, but declined to name them. One of the group’s…
Global Security News
Microsoft says threat actors are ahead in the early AI race
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. […]
Global Security News
National cyber director: Government-industry collaboration vital to managing AI risks, competition with nations
Collaboration with industry is key to balancing AI security risks and benefits, as well as staying ahead of China and other adversarial nations, National Cyber Director Sean Cairncross said Thursday. The Trump administration is facing pressure from some quarters of Capitol Hill and even some artificial intelligence executives to establish regulations or embrace legislation to…
Global Security News
Can AI Run in Space? Google Is About to Find Out
A satellite containing several of the company’s AI chips launched into orbit.
Global Security News
DeepSeek, Huawei Expand Software Support for Ascend AI Chips
DeepSeek is expanding its work with Huawei, releasing open-source software designed for the Chinese tech company’s Ascend processors. DeepSeek’s Sept. 30 releases and updates extend Ascend support across six open-source projects covering low-level operations needed to build and optimize AI workloads. The release moves their collaboration further into the software layer around AI infrastructure. For…
Global Security News
Operation KillSwitch: Police Dismantle KillSec Ransomware Group
Operation KillSwitch: Europol says the KillSec ransomware group, allegedly led by a 16-year-old, was dismantled after attacks on about 1,000 victims. Law enforcement seized control of KillSec ‘s dark web leak site, the Tor website the group used to threaten victims with publishing stolen files unless they paid up. That single action locked down more…
Global Security News
Give yourself room to be human
Welcome to this week’s edition of the Threat Source newsletter. Fall is officially here in Maryland, and I can’t be more relieved. I flourish in 50 degree weather, where it feels natural to burrow under blankets, knit sweaters, and listen to an audiobook. Beyond that, though, can I say that I’m glad fall is here…
Global Security News
Temasek-Backed Vertex Japan Invests in Digital Trading Cards Startup Heartbeats
Temasek-backed Vertex Ventures Japan has invested in Heartbeats, a Tokyo-based digital trading cards company, the latest in a series of bets aimed at turning Japanese startups into global unicorns.
Global Security News
Fake xStocks, Pendle, and other sites bait crypto users with rewards votes
We found 70 websites that impersonate legitimate crypto projects that invite visitors to vote on the date of an upcoming rewards distribution. The pages copy the look of the real sites closely, and on most of them the offer is small and believable: Cast a vote, and as an active voter you get a 1.25x…
Global Security News
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when police also took control of that site.…
Global Security News
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is the…

