
Amos Stealer targets macOS users through fake downloads, stealing Keychain files, browser passwords, cookies, and developer configs for data theft.


Hewlett Packard Enterprise (HPE) is expanding its Partner Ready Vantage program with new incentives, partner-led offers, and additional opportunities for services delivery, as the company looks to help partners capitalize on growing demand for AI, hybrid cloud, networking, and infrastructure modernization. Announced during HPE Discover 2026, the updates build on the vendor’s ongoing effort to…
I have one golden rule: It’s not about the mower, it’s about the yard. Use my free checklist to decide which model to buy.
A policy paper published Tuesday advocates for software bills of materials (SBOMs) for artificial intelligence as a mechanism for reducing cyber risk and improving transparency, and seeks to give lawmakers, federal agencies and others a roadmap on how to proceed. The SBOM, commonly described as an inventory of software ingredients, emerged in the 2010s and…
As enterprises race to deploy AI copilots and autonomous agents, finance leaders are finding the hardest part isn’t buying AI – it’s predicting what it will cost, proving its…

As enterprises race to adopt artificial intelligence, Percona sees a growing opportunity to help customers regain control over rising infrastructure costs, data governance challenges, and vendor lock-in concerns through an ecosystem of carefully selected channel partners. Louis Hood, director of global partnerships and channels at Percona, said the current AI boom mirrors many of the…
Only $280 gets you a 55-inch Amazon Fire TV Omni QLED Series with this great early Prime Day deal.
The latest release of one of the finest desktop environments on the market is here, and there’s plenty to be excited about.
Immutable Linux is the future of OS security, but the current distributions do have one particular limitation that RakuOS has resolved.

Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from threat intelligence company Defused, which said that the exploit for one of the flaws is vibecoded, and…
Your Android keyboard may be collecting more than you realize. Here are two ways to take back some privacy.
As organizations increasingly deploy autonomous AI agents, a new governance challenge has emerged. Boards, auditors, customers, and regulators are no longer asking whether companies use artificial intelligence — they are asking how AI agents are governed and whether organizations can prove accountability for their actions. Despite growing scrutiny from boards, auditors, and customers, 89% of…
These plug-in gadgets easily enhance your home’s routine (and they’re affordable).

The DragonForce ransomware group used a custom malware called Backdoor.Turn to hide command-and-control traffic inside Microsoft Teams relay infrastructure during an intrusion at a U.S. services company, according to Symantec. DragonForce is a ransomware-as-a-service operation that has been active since 2023. The group provides affiliates with ransomware tools and supporting services in exchange for a…

Three FortiSandbox flaws, including one patched last week, are being actively exploited, highlighting the shrinking window for defenders. Cybersecurity firm Defused Cyber confirmed it’s seen active exploitation of three vulnerabilities in Fortinet FortiSandbox within a 24-hour window. Two of them had patches sitting available since April. The third got fixed last week, which, apparently, wasn’t…
And say hello to much better NTFS support. Linux creator Linus Torvalds has announced the release of Linux 7.1.
You can add YouTube, web browsing, and more to your car by sideloading apps.

TekStream has announced the launch of TekStream Proactive Cyber Defense, a new expert-operated security service powered by Cosmos, the company’s cyber defense intelligence platform. The launch comes as organizations face a rapidly changing threat landscape shaped by AI-accelerated attacks, autonomous adversary capabilities, growing operational complexity, and increasingly fragmented security environments. Recent developments in autonomous offensive…
Phone makers love to advertise fast-charging speeds. I tested three flagship phones with OEM and Anker chargers to see what their claims really mean.
Sony’s and Sennheiser’s flagship headphones are objectively good, but how you plan to use them determines whether they’re great.
A critical vulnerability (CVE-2026-48558) in SimpleHelp, a popular remote monitoring and management (RMM) tool, can be exploited remotely by unauthenticated attackers to create a new “Technician” account and use it to remote into managed endpoints, execute scripts, and more. Maliciously “forged” Technician account (Source: Horizon3.ai) The vulnerability CVE-2026-48558 is an authentication bypass flaw affecting SimpleHelp…

We are pleased to welcome the newest organizations that have joined as Associate Participating Organizations of the PCI Security Standards Council (PCI SSC). These organizations play a crucial role in supporting the evolution of the PCI security standards and programs and promoting the implementation of PCI security standards worldwide to protect payment data. We…

Security researchers at Zimperium’s zLabs have documented a new Android banking trojan, Rokarolla, that targets 217 banking and cryptocurrency apps and packs 137 remote commands. Together, they give an operator near-total control of an infected phone: it lifts lock-screen PINs, reads and sends SMS, rewrites the clipboard to redirect crypto payments, and switches off Google Play

In this post, I will talk about the best SendGrid alternatives for Developers in 2026. SendGrid has been the developer’s default choice for years, but complaints like deliverability issues on shared IP pools and PHP SDK that ships the entire platform keep surfacing among engineering teams. This guide compares four providers worth considering if you…

Attorney Mark Meckler, who has spent more than two decades working in internet advertising law, recently shared his insights on how big tech is using your data. His observations highlight a growing concern within both the privacy and cybersecurity communities: most consumers unknowingly contribute massive amounts of data that ultimately fuel artificial intelligence (AI) systems…
AppViewX has announced Agent Identity Security, a new product within the AppViewX platform that discovers, governs, secures, and monitors AI agents across the entire enterprise. Agent Identity Security extends AppViewX’s platform, built on a decade of machine identity and PKI expertise, into AI agent security, giving CISOs and their teams a single control plane for…

SAP security is getting a round-the-clock upgrade as Pathlock and NTT DATA Business Solutions join forces to tackle growing cyber risks. On Tuesday, Pathlock announced a global strategic partnership with NTT DATA Business Solutions to deliver managed SAP cybersecurity services to enterprise customers worldwide. Partnership adds managed SAP cybersecurity services The alliance brings together Pathlock’s…
With the World Cup on, you’ll find no shortage of websites promising every match, live, in HD, for free. They look convincing, usually with a video player, a “Live Stream Available” indicator, a row of server buttons, maybe a match schedule, and a “Watch Live” button. There’s no signup, no paywall, and seemingly, no catch.…

Teleport has announced the debut of two foundational capabilities of its Agentic Identity Framework in the public beta of Beams: LLM Proxy and Delegated Identity. These capabilities address a critical gap in how organizations deploy AI agents: the lack of identity, access control, and auditability at the two most consequential points in an agentic workflow—what…
Cardiac monitoring provider iRhythm has been hit by a data theft followed by an extortion attempt. In a filing with the Securities and Exchange Commission (SEC), iRhythm revealed it was contacted by someone on June 9 who claimed to have stolen sensitive information, including proprietary data, patient PHI, and other personal information. That person demanded…

Radware has announced AI Xploit Shield, a new service that provides organizations with protection for their applications and APIs from exploitation of newly discovered vulnerabilities. As emerging frontier AI models like Mythos from Anthropic accelerate vulnerability discovery, organizations face a growing challenge: the volume of newly discovered vulnerabilities is accelerating while the window between vulnerability…
Discover how continuous control validation in Tenable One can improve your CTEM program by filtering out alert noise and factoring in your active cyber defenses. Focus your team on accessible and exploitable attack paths. Key takeaways: With vulnerability exploitation ranking as the top initial access vector and frontier AI accelerating vulnerability discovery, organizations must shift…
Open-source security has a new AI problem. But Chainguard has a plan, and plenty of friends, to help
Cisco has released security updates for an SD-WAN vManage flaw exploited in zero-day attacks. The issue, tracked as CVE-2026-20262, affects Cisco Catalyst SD-WAN Manager and can allow an authenticated remote attacker to create or overwrite files on the underlying operating system, opening a path to root privilege escalation. Public reporting says the flaw was exploited…
New York, New York, 16th June 2026, CyberNewswire

Google is warning of a cyber espionage campaign linked to a China-nexus threat actor, UNC6508, that kept close tabs on valuable US and Canadian research environments for over a year. The campaign abused REDCap, a widely adopted platform for collecting and managing research data. Attackers, now disrupted, intercepted REDCap’s upgrade process to inject persistence malware.…
Security teams have never had more IP data at their disposal. Every day, analysts ingest enrichment feeds, geolocation data, reputation scores, telemetry, and threat intelligence from a growing ecosystem of vendors and platforms. Yet despite this abundance of information, many organizations continue to face a fundamental challenge: sifting through the noise to understand who is…
Getting great sound from your TV doesn’t have to cost an arm and a leg. These are my expert-vetted audio tweaks.
Teams need to upgrade their NHI game – here’s how to get started.
Cisco warned that CVE-2026-20262, a Catalyst SD-WAN Manager vulnerability allowing arbitrary file writes, is being actively exploited. Cisco confirmed active exploitation of CVE-2026-20262, an arbitrary file write vulnerability affecting Catalyst SD-WAN Manager. CVE-2026-20262 (CVSS score of 6.5) is an arbitrary file write vulnerability in the web interface of Cisco Catalyst SD-WAN Manager. The flaw is…
Discover the best of Android fax apps to send and receive secure documents on the go. Compare Municorn Fax App, Fax.Plus, and other top Android tools.
REYKJAVIK, Iceland, June 16, 2026 — Varist today introduced its DICOM Detection Engine™, a specialized system designed to safeguard electronic health records (EHR) and picture archiving and communication systems (PACS) from all known malware, including the emerging threat of AI-powered malware. As attackers increasingly use artificial intelligence to automate, scale and customize their attacks, the engine…

Thanks to Uncle Sam, anyone trying to find nonconsensual intimate deepfakes on CFake.com and SOCFake.com will be disappointed. The US Departments of Justice (DOJ) and Homeland Security has seized the two domain names under the TAKE IT DOWN Act. The TAKE IT DOWN Act, signed in May 2025, is the first US federal statute criminalizing…

Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on X, the company said it has observed exploitation of CVE-2026-39813, CVE-2026-39808, and CVE-2026-25089 over the past 24 hours. CVE-2026-39813 (CVSS score: 9.1) refers to a path traversal vulnerability in FortiSandbox JRPC API that…
Cisco has revealed another Catalyst SD-WAN Manager vulnerability (CVE-2026-20262) that its Product Security Incident Response Team observed being exploited by attackers. But the associated security advisory also states that “the vulnerability was found during internal security testing”, raising the question of how attackers came to exploit it before Cisco had disclosed it publicly. The vulnerability…
Modern URL phishing relies on dynamic pages, credential harvesting flows, client-side scripts, and layered redirect chains. But most SOC workflows are still built around static analysis, making them blind to most of these tactics. ANY.RUN changes this forever with in-browser data inspection. The new technology takes URL analysis to the next level by bringing static and dynamic analysis into one single workflow. Now,…

Scammers behind cryptocurrency investment schemes are dispatching couriers to pick up cash from victims in person, the FBI warns. According to the agency, scammers usually approach victims through social media, text messages, or fake investment personas, luring them into cryptocurrency schemes that use fraudulent trading platforms and fabricated returns to encourage additional deposits. When financial…

Cisco has released fixes for a vulnerability in its Catalyst SD-WAN Manager software after becoming aware of limited exploitation of the flaw, which could allow an authenticated attacker to create or overwrite files that may later be used to gain root privileges. The vulnerability, tracked as CVE-2026–20262, affects the web interface of Cisco Catalyst SD-WAN…

Cybersecurity researchers have flagged two previously undocumented Windows variants of what was believed to be a Linux-only backdoor called SprySOCKS. “The Windows variants discovered are internally marked as WIN_DRV and WIN_PLUS,” ESET said in a report shared with The Hacker News. “Both come with a hard-coded C&C [command-and-control] configuration and support communication over TCP, UDP,

Anthropic’s apparent inability to identify which of its users are foreign nationals has led to some collateral damage from a US export ban on its most powerful AI models — but there is a way around it, at least for some. On Friday, the US government ordered Anthropic to suspend access to Fable and Mythos,…

Software supply chain visibility is becoming part of product security work as the EU Cyber Resilience Act (CRA) moves toward application in December 2027. ENISA’s SBOM Adoption State of Play 2026 shows organizations preparing for CRA obligations through SBOM tooling, automation, and changes to software development practices. Level of SBOM adoption based on organisation size…

Zero trust is 15 years old, and like many teenagers, it can feel misunderstood and underappreciated. The concept of zero trust was first defined by John Kindervag, a Forrester analyst at the time, as a strategy to replace the outmoded perimeter security model with a “never trust, always verify” approach. But going from principle to…
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco Catalyst and LiteSpeed cPanel plugin flaws to its Known Exploited Vulnerabilities (KEV) catalog. The two flaws added to the catalog are: CVE-2026-20262 (CVSS score of 6.5)…

Cyberattacks against hospitality, travel, and recreation organizations rose 24% year over year, reaching an average of 2,291 incidents per organization each week in May 2026, according to Check Point. (Source: Check Point) “The sector has more than doubled its attack volume since May 2023,” researchers noted, reporting a cumulative increase of 122% over three years.…

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. “The attack email contained a message impersonating an MS account security alert,” the Genians Security Center (GSC) said. “It was designed to create concern over possible

China’s UNC6508 hid in North American medical research networks for 2 years, stealing credentials and forwarding emails to Gmail Google’s Threat Intelligence Group published a report this week on UNC6508, a China-linked cyberespionage group that breached North American medical and military research organizations and stayed hidden for more than two years. The earliest confirmed intrusion…
Cato Networks has announced the launch of the Cato Platform Integration Hub and its Technology Partner Program. These two new services, which contribute to an expanded Cato ecosystem, will extend the Cato approach of seamless enterprise security and networking, helping customers move from standalone products to a more integrated technology ecosystem. Cato’s Technology Partner Program…
Yesterday, a reader reported to us a malicious ZIP archive (SHA256: a0104921a2d37ab87482ac9a9f5c3713479c118846c3e999178e75b81620c094[1]). Once unzipped, it contains a VHDX file that discloses a malicious JavaScript after being mounted (which is automatic on modern Windows OSs): Two different techniques to hide the payload help to bypass most first-line security controls. Using a disk image as a “malware container” has been…
AI infrastructure is getting messy, expensive, and increasingly difficult to coordinate. The industry has spent the last few years talking about models, chips, etc., but behind the scenes, a fun new challenge has been piling up. Actually building the infrastructure needed to support all of that demand is getting complicated. For those who have been…

Hot AI companies can’t stop talking about forward-deployed engineers (FDEs), which are now very much in vogue. FDEs, in case you haven’t heard, are hired by companies looking (hoping?) to successfully deploy AI tools and services. It’s one of the hotter professions in a world still trying to understand the impact of AI on careers.…
Developers coordinate code across README files, issue threads, and pull request discussions. Much of that exchange happens in English, and a large share happens in other languages. GitHub has released a dataset built to help researchers and developers locate public repositories that carry non-English natural-language content. The GitHub Multilingual Repositories Dataset is available on GitHub…
Cyber defenders spend their careers protecting everyone else’s systems. A new study from Australian-founded non-profit Cybermindz argues we’ve been ignoring the one system that…

Cisco has released security updates for a medium-severity security flaw in Catalyst SD-WAN Manager that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-20262, carries a CVSS score of 6.5 out of 10.0. “A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated,…

In this interview with Help Net Security, Oscar Andersson, CTO at Oplane, explains why most scanning tools fail. They cry wolf, flagging threats that cannot run in real code. The argument centers on reachability. A finding counts only when someone walks the path to impact on a working build. He shows how a chain of…

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a security flaw impacting LiteSpeed cPanel Plugin to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by June 18, 2026. The vulnerability in question is CVE-2026-54420 (CVSS score: 8.5), which has been described as a case…
Over recent years we’ve witnessed the EU becoming increasingly serious about cybersecurity. After years of watching high profile breaches, many resulting from supply chain attacks targeting our critical infrastructure, that seriousness is welcome. But good intentions and good policy are not the same thing, and the proposed EU Cybersecurity Act 2.0 is starting to look…
In the latest episode of Identity Insider, I sat down with Chris Hughes, a cybersecurity expert who’s involved in OWASP’s work on non-human and machine identity security. Unsurprisingly, our discussion centered on the rapidly changing cybersecurity landscape, driven by the rise of artificial intelligence (AI), particularly agentic AI, which is giving systems unprecedented autonomy within…

Across large enterprises, a single question keeps surfacing when teams want to put customer data to work. Can this record be used for a given purpose, and does the consent behind it still hold? The data sits in warehouses and customer databases, and the ability to answer that question often lags behind. That delay carries…
Android Vulnerability Researcher Byteria | USA | Remote – View job details As an Android Vulnerability Researcher, you will analyze the Android attack surface, including the Linux kernel, system services, drivers, firmware, applications, and Trusted Execution Environment (TEE). You will reverse engineer native binaries and mobile software, identify vulnerabilities through code review, fuzzing, and static…
Kapish today announced a new strategic partnership with Ardoq, expanding Kapish’s enterprise architecture offering to help organisations make better decisions, reduce…