Barracuda researchers explain what you need to know about this growing attack vector
Global Security News
Global shipping carrier Pacific International Lines partners with Celonis and WNS to expand Process Intelligence Centre of Excellence
Singapore’s Pacific International Lines PIL, one of the world’s largest shipping container companies, has chosen Celonis, the global leader in Process Intelligence, to…
Global Security News
Cloudflare OS Is the First AI Workspace Built Around How Companies Actually Work
Global Security News
Sofitel Bangkok Sukhumvit Reaches New Revenue Performance Heights with IDeaS G3 RMS
Global Security News
Khimji Ramdas Group Chooses Rimini Street to Reduce SAP Support Costs, Protect 700+ Customisations and Reinvest Savings in Innovation
Omani conglomerate gains greater control over its IT roadmap, avoids migration pressure and funds AI and growth initiatives
Global Security News
Turnitin Rolls Out Multipart Assignment Types to Enable Scaffolded Learning and Process-Based Assessment
Global Security News
Static Residential Proxies vs ISP Proxies: What’s the Difference and Which Should You Choose?
Static residential proxies and ISP proxies are often mentioned together because they both provide stable IP addresses with excellent performance. However, despite their similarities, they are built differently and serve different use cases. If you’re involved in web scraping, market research, SEO monitoring, ad verification, account management, cybersecurity testing, or anonymous browsing, choosing the right…
Global Security News
Frank Vukovits on how Delinea delivers runtime authorization for AI agents
Global Security News
Intruder’s Chris Wallis on AI pentesting and the future of cybersecurity
Global Security News
ISC Stormcast For Friday, August 7th, 2026 https://isc.sans.edu/podcastdetail/10042, (Fri, Aug 7th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
Ido Geffen on why Novee owns the full AI pentesting stack
Global Security News
The Latest Scary-Sounding AI Milestone: A Brand-New Virus
While hacks have raised safety alarms, researchers said their experiment could protect against drug-resistant bacteria and save lives.
Global Security News
Best Rotating Proxies for Web Scraping in 2026

In this post, I will show you the best rotating proxies for web scraping in 2026. As businesses continue to rely on data-driven decisions, web scraping has become an essential technique for gathering publicly available information from websites. Whether you’re monitoring competitors, tracking product prices, conducting market research, or collecting SEO data, the quality of…
Global Security News
Ramin Farassat on how Menlo Security is securing AI agents from prompt injection
Global Security News
Facing AI ‘Apocalypse,’ Once-Hot Software Companies Race to Reinvent Themselves
Global Security News
Cloudflare wants to provide the operating system for the AI-first enterprise

Traditional operating systems (OS) were built to manage hardware, files, apps, and users on a device, but Cloudflare says the agentic AI era requires a whole new format. The company this week announced Cloudflare OS, which connects AI agents, enterprise data and context, internal systems, and workflows together in one secure workspace. It is open…
Global Security News
Meta Ordered to Pay $942 Million to Address Harm to Kids From Social Media
Global Security News
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
Global Security News
ClickFix attack pushes macOS infostealer for crypto theft attacks
Global Security News
Automate certificates with ACME support in AWS Certificate Manager

Customers tell us that managing TLS certificates at scale is one of their biggest operational concerns. The Certification Authority Browser Forum (CA/Browser Forum) has mandated a phased reduction in maximum certificate validity for public certificates. By March 2027, the maximum validity drops to 100 days. By March 2029, it lasts for 47 days. For an…
Global Security News
The Coordination Gap: How Attackers Are Outpacing Law Enforcement
The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.
Global Security News
Why exposure management is replacing vulnerability management

Vulnerability management isn’t failing because security teams lack visibility. Most organizations already have more findings than they can reasonably address. Yet despite all those findings, many CISOs still struggle to answer a deceptively simple question: Are we actually becoming harder to attack? That question sits at the center of a growing problem. Security programs have…
Global Security News
North Korea linked to new NullReceiver C2 technique
Global Security News
OVSwrap vulnerability allows local privilege escalation on Linux
Global Security News
Samsung’s August Update Patches 56 Security Vulnerabilities Across Galaxy Devices

Samsung is starting August with a security sweep that patches dozens of flaws across Galaxy phones and tablets. The company has published details of its August 2026 Security Maintenance Release (SMR), which addresses 56 security vulnerabilities affecting eligible Galaxy smartphones and tablets running Android 14, Android 15, and Android 16. The update includes 38 Android…
Global Security News
Vectra AI Launches Vectra AI Pro for AI-Driven Security Operations

Vectra AI has launched Vectra AI Pro, a new offering designed to provide what the company calls “trusted signal intelligence” for security operations centers (SOCs) adopting AI-powered workflows. Announced at Black Hat USA 2026, the platform continuously correlates network, identity, cloud, SaaS, SASE, and endpoint telemetry into a unified view of attacker behavior. Behavioral intelligence…
Global Security News
When AI Commits Felonies – PSW #938
Global Security News
Samsung Unveils Next-Generation AI Memory Designs at FMS 2026

Samsung wants to shrink one of AI infrastructure’s biggest bottlenecks: the distance between processors and memory. At FMS 2026 in Santa Clara, California, the company previewed zHBM and zNAND-O concept architectures, introduced its 400-plus-layer V10 BV-NAND design and outlined a roadmap spanning HBM4E, HBM5 and enterprise storage. Samsung says the technologies could increase bandwidth, capacity…
Global Security News
Researcher Claims Control of ChatGPT Secure Sandbox
Global Security News
Mimecast’s Leslie Nielsen on why human risk doesn’t stop at people
Global Security News
Open Secure AI Alliance Proposes SAFE Framework for AI Security Incidents

The AI industry is securing the ecosystem through open collaboration. NVIDIA and the Open Secure AI Alliance have drafted the Shared AI Findings Exchange (SAFE) framework and introduced several open-source tools to champion AI security. The SAFE RFC document proposes a framework for reporting, collaboratively analyzing and recommending operational guidance after breaches. Additionally, the alliance…
Global Security News
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams

Senators from both parties Thursday probed Trump administration officials about whether federal agencies and foreign governments are coordinated enough in the battle against scammers, something witnesses told the Foreign Relations Committee they were working to remedy. At least 13 federal agencies have authorities to counter scams, raising questions about whether someone needs to be in…
Global Security News
Made by Google 2026: How to watch and what to expect from the big Pixel 11 event
Google is set to announce its Pixel 11 series phones – here’s what we know.
Global Security News
Google’s new Pixel 11 series comes next week – here’s what we know from leaks
The Pixel 11 lineup isn’t bringing drastic changes, but the incoming additions will still have fans excited.
Global Security News
FDA Approves Replimune’s Melanoma Drug On Third Attempt
Global Security News
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
Global Security News
Researchers Find Three Ways Apple Traffic Can Bypass iCloud Private Relay

Security researchers Talal Haj Bakry and Tommy Mysk have identified three request paths involving Apple’s browser and authentication technologies that can bypass proxy protections and expose a user’s real network information. The flaws affect Apple’s iCloud Private Relay, a paid iCloud+ feature designed to hide users’ IP addresses and DNS information while browsing in Safari.…
Global Security News
Optiv’s John Hurley on simplifying cybersecurity
Global Security News
Paperclip authorization bug exploited, leads to control plane takeover
Global Security News
Meta Launches Muse Code as Low-Cost Rival to Claude Code and Codex

Meta is entering the AI coding race with a familiar weapon: lower prices. Released in beta, Muse Code is a terminal-based coding agent powered by Muse Spark 1.2. Meta says it can plan and write code, then test changes across large repositories. Muse Code gives MSPs and systems integrators another option aside from Claude Code…
Global Security News
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
A new scan of internet-connected industrial equipment found over 4,000 Rockwell Automation and Allen-Bradley controllers exposed online, including 22 in cities impacted by cyberattacks on U.S. water systems. The findings, published Wednesday by Forescout’s Vedere Labs, show that direct internet access to equipment used in water and wastewater operations remains common despite years of warnings…
Global Security News
Google’s John Hultquist on outpacing the adversary with AI threat defense
Global Security News
Route Amazon Bedrock Guardrails interventions to Amazon Security Lake

Security teams investigating AI-related incidents need guardrail intervention data alongside their existing security telemetry. Routing Amazon Bedrock Guardrails violations to Amazon Security Lake makes this possible. With this integration, you can query guardrail events alongside identity, network, and application security data in a single layer. When a guardrail blocks a prompt injection attempt or redacts…
Global Security News
From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture
Former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.
Global Security News
NatJack exploits put NAT security assumptions to the test at Black Hat

For decades, Network Address Translation (NAT) has been the default way IP addresses are provided inside larger networks, as a means to deal with the challenges of IPv4 address availability. The basic premise behind NAT is that private addresses stay private, but that assumption might not be entirely accurate anymore (if it ever really was).…
Global Security News
250+ ClickFix Domains Hide macOS Malware From Security Scanners

More than 250 ClickFix domains are using browser fingerprinting to hide macOS malware lures from security scanners. Microsoft Threat Intelligence said the campaign checks visitors for signs of a genuine Mac before serving malicious instructions that can lead to the download of Atomic Stealer or MacSync. Crawlers, sandboxes, and researchers may instead receive blank pages…
Global Security News
Apiiro’s Idan Plotnik on AI writing code that sharpens attacks
Global Security News
Swiss government SharePoint breach compromised 200 accounts
Global Security News
Ransom Cartel creator sentenced to 16 years in prison

A longtime cybercriminal was sentenced to 16 years in prison for creating and running Ransom Cartel, a ransomware strain linked to attacks on at least 18 companies between 2021 and 2023, the Justice Department said Wednesday. Maksim Silnikau, a Belarusian national, actively participated in Russian-speaking cybercrime forums since at least 2005, and was a member…
Global Security News
Black Hat 2026: Barracuda Details AI-Powered BEC Attack
As part of its Black Hat USA 2026 research, Barracuda released a PoC demonstrating how attackers could use AI-enabled email assistants to escalate a compromised employee account into a full-scale BEC attack. Researchers said the greatest risk is that AI assistants accelerate reconnaissance, phishing, and fraud using compromised accounts. The attack used Microsoft Copilot, though…
Global Security News
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
Global Security News
Why metaphor may dictate your security strategy

Welcome to this week’s edition of the Threat Source newsletter. Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues. Recent reports of offensive AI agents “escaping” their sandbox environments…
Global Security News
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86’s shadow memory management unit (MMU), which manages…
Global Security News
Photos: Black Hat USA 2026, part two
Round two from Black Hat USA 2026. This set covers the parts of the show floor that did not make the first gallery. Scroll through below. Featured vendors: BlackCloak, Teleport, GitGuardian, Oak, Hexnode, Picus Security, Featured speaker: Kate Silverstein (Mozilla) discussing crowd-sourcing protection against real-world LLM attacks. The post Photos: Black Hat USA 2026, part…
Global Security News
Is the new (pricier) Pixel 11 series still a good value compared to Samsung’s Galaxy phones?
The Pixel 11 may cost more, but Google’s software could still make it a better value than Samsung’s phones.
Global Security News
6 must-have travel gadgets, according to industry experts
Global Security News
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security review. The security issues affect Cisco Catalyst SD-WAN Software, regardless of device configuration, and Cisco IOS XE Software when it is running in autonomous or controller mode. “These vulnerabilities were…
Global Security News
Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history…
Global Security News
Everyone’s a Builder Now: Securing the AI-Powered Enterprise – Gil Geron – BH26 #2
Global Security News
Kai’s Galina Antova on the shift to machine-led security
Global Security News
Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance Records

An exposed SISVISA database leaked 102,215 Brazilian health records, exposing IDs, tax data, and regulatory documents without authentication. Researcher Jeremiah Fowler found a publicly accessible database that turned out to belong to SISVISA, Brazil’s Health Surveillance Information System, and alerted ExpressVPN, which later shared the findings with Hackread. The exposed instance held exactly 102,215 files,…
Global Security News
The M5 Macbook Air is down to the lowest price we’ve seen since Apple’s price hike
Global Security News
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using it, re-poisoning the predictor after the defense has run. MIT CSAIL researchers Daniël Trujillo and Mengjia Yan named the technique INTERRUPT INJECTION. On an AMD Zen 2 machine running Linux…
Global Security News
Caching KMS data keys in multi-thread environments: Per-tenant encryption for event-driven systems at scale
This post assumes familiarity with envelope encryption and the AWS Encryption SDK. When your encryption system generates millions of duplicate API calls per hour, costs spiral and performance degrades. That’s exactly the challenge NICE Actimize faced while operating their global-scale, event-driven financial crime detection platform on Amazon Web Services (AWS). NICE Actimize, a leading provider…
Global Security News
Meta AI model hacked a company during misconfigured cyber test
Global Security News
Black Hat USA 2026: Solving insider risk in the agentic AI era
Here’s a five-stage action plan for confronting insider risk from noted cybersecurity executive Phil Venables.
Global Security News
Cloudflare OS Gives Partners a Platform for Enterprise AI Agents

Cloudflare is opening up the AI workspace it built for its own employees. Now, partners can use the same foundation to create enterprise agents, automate workflows, and build small internal apps. The platform connects AI tools with an organization’s internal knowledge, applications, and security controls. Employees can use the browser-based workspace to research information, create…
Global Security News
Why Anthropic’s Chips Matter for the Channel

The rumors turned out to be true. Anthropic says it’s building an in-house team to design custom AI chips for Claude, giving the company more control over the hardware behind its AI models. It’s also not blowing up its existing infrastructure. Anthropic says chips from AWS, Google, Nvidia and AMD will remain part of the…
Global Security News
1Password Finds AI Security Patches Fail More Than Half the Time

A new study from 1Password’s Off-by-1 Labs suggests that organizations should be cautious about relying on large language models (LLMs) to autonomously remediate software vulnerabilities. After evaluating more than 6,000 AI-generated security patches across six recently disclosed, high-impact vulnerabilities, researchers found that fully successful patches were the exception rather than the rule. Key takeaways of…
Global Security News
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
Global Security News
Ransom Cartel Leader Sentenced to 16 Years in U.S.

A U.S. court sentenced Ransom Cartel founder Maksim Silnikau to 16 years for running a ransomware-as-a-service operation. Maksim Silnikau (aka “J.P. Morgan,” “lansky,” and “xxx,”) built a ransomware business the way a franchise owner builds a chain: he never had to touch most of the crime scenes himself. This week, a federal judge in Virginia…
Global Security News
ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF can finish the job. This week runs on cheap leverage: exposed servers, recycled bugs, poisoned agent instructions, remote-access tools dressed as support software, and trusted defaults doing attackers a favor.…
Global Security News
Granola lawsuit raises concerns over AI note-taking app privacy

AI note-taking app maker Granola is accused of violating privacy laws by developing software that can record conversations without all participants’ consent, according to a lawsuit filed July 30 in a California federal court. It follows a similar ongoing case in the same district, filed last year, that involves another note-taking and transcription software vendor,…
Global Security News
UK data watchdog criticizes Metropolitan Police for data handling failures
The UK’s data protection regulator criticized the Metropolitan Police Service (MPS) for significant data handling failures, including sharing a stalking victim’s new contact details with her abuser and a separate incident exposing the email addresses of 18 individuals connected to Parliament.
Global Security News
Salesforce’s Agentforce 360 platform approved for sensitive Defense Department data
Salesforce’s enterprise agentic AI platform, Agentforce 360, received approval from the Defense Department to securely handle high-sensitivity workloads, including Controlled Unclassified Information (CUI) and unclassified National Security Systems (NSS) data.
Global Security News
NVM Express updates specifications with post-quantum cryptography and SSD virtualization support
The NVM Express consortium released updates to its 11 specifications, introducing significant advancements in security and virtualization for solid-state drives (SSDs).
Global Security News
Prompt injection remains top LLM threat, OWASP report finds
Global Security News
Beacon CRM confirms cyberattack exposed UK charity data
Global Security News
US reportedly drafting ban on Chinese optical transceivers
Global Security News
Brazil’s health system data exposed online
Global Security News
Google mistakenly locks hundreds of Blogger websites
Global Security News
Apple’s Private Relay feature has flaws that can expose user IP addresses
Global Security News
This LG OLED TV is one of the most impressive I’ve tested – and it’s $700 off
The LG C6 is a powerful refresh of the brand’s flagship OLED TV, and right now at Best Buy, you can get the 65-inch version for 26% off.
Global Security News
How To Get Money Back From A Scammer On Western Union

Western Union is one of the most used means of international money transfer. Find out how to get money back from a scammer on Western Union in this post. Scams take various forms, but the most popular scam often joked about is the “Nigerian Prince” email scam, which still rakes in over $700,000 in illegal…
Global Security News
Common Dating Website Scams and How to Avoid Them

In this post, I will discuss common dating website scams and how to avoid them. The image of a dating scam as a clumsy stranger with a broken keyboard is out of date. The people running these schemes now build profiles with deliberate small flaws, match a target’s tone, and wait weeks before asking for…
Global Security News
Apple WebKit vulnerabilities reveal your IP address, despite Private Relay

Three WebKit mechanisms have been discovered to bypass Apple’s iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo’s proxy, Tor-on-iOS proxy setups, and so on. Private Relay is a VPN-like system for Safari on iOS which is meant to prevent websites from viewing the visitor’s IP address and location.…
Global Security News
I’ve been using the Galaxy Z Fold 8 for two weeks – these two accessories perfect the experience
With the Galaxy Z Fold 8 as my main driver, these two accessories are must-haves (and one isn’t even made by Samsung).
Global Security News
TeamPCP Traced Back to 2020 Cryptojacking Operation
Global Security News
Novel-reading apps used users’ phones to generate fake ad traffic

A new mobile ad fraud scheme, dubbed Papyrus, is using a cluster of novel-reading apps to generate hidden browser traffic, according to IAS Threat Lab. Sample novel-reading apps associated with Papyrus (Source: IAS Threat Lab) While a person taps through chapters of a romance or fantasy story, the app is quietly loading websites in a…
Global Security News
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
Global Security News
The new Pixel 11 isn’t enough to make me give up my Pixel 9 Pro – here’s why
Google is set to release the Pixel 11 soon, and although my Pixel 9 Pro is two years old, I won’t be upgrading for five specific reasons.
Global Security News
How a software provider closed unknown paths to cloud compromise

A healthcare software provider believed its segmented environment was reasonably secure. The company had invested heavily in layered controls across a distributed workforce, separating developer environments, segmenting cloud infrastructure, and tightly managing administrative access. Multifactor authentication (MFA) was enforced broadly, vulnerability scanning was routine, and annual penetration tests were part of the organization’s broader security…
Global Security News
Meta AI Agent Exploited Third-Party Flaw During Cybersecurity Test

One of Meta’s AI models hacked into another company’s systems during a cybersecurity evaluation after a testing misconfiguration gave it internet access. Facebook’s parent company told the BBC it is investigating and plans to publish more information once it has established the facts. Recent incidents involving OpenAI and Anthropic have intensified scrutiny of whether cyber-capable…
Global Security News
How a global investment firm reduced security surprises

Most security teams don’t suffer from a lack of data. They suffer from a lack of certainty. Vulnerability scanners, annual penetration tests, and compliance assessments can generate thousands of findings. Yet they often fail to answer a simple question: Which risks actually matter? For a global investment firm operating across 18 locations, that question became…
Global Security News
Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident
Global Security News
Black Hat USA: TP-Link Flaws Put Omada Controllers and Camera Feeds at Risk
Forescout disclosed 15 TP-Link flaws at Black Hat USA 2026 that could expose Omada credentials and VPN keys, allow internal access and affect VIGI camera feeds.
Global Security News
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air Security, Legion Security. Featured people: Kunal Modasiya (Qualys) on going from vulnerability disclosure to autonomous remediation at machine speed. Jeremiah Grossman and Robert…
Global Security News
Black Hat 2026: Critical Flaws Found in Anthropic, Google, and OpenAI Coding Agents
Security researchers have disclosed critical vulnerabilities affecting AI coding agents from Anthropic, Google, and OpenAI, demonstrating how attackers could compromise automated development workflows through a single untrusted GitHub issue. According to the research presented by Novee at Black Hat USA 2026, the flaws were found in the vendors’ own repositories running their default configurations. This…
Global Security News
An Irregular testing that caused Meta, OpenAI, and Anthropic AI agents to go rogue

Meta has become the third frontier AI developer in recent weeks to disclose a security incident involving one of its advanced AI models during cyber capability testing conducted by AI safety startup, Irregular, placing the independent evaluator at the center of a series of disclosures involving the industry’s leading AI labs. During a “capture-the-flag” test…
Global Security News
You’re only as secure as your last evaluation

The updated Cybersecurity Maturity Model Certification (CMMC) represents a critical evolution in the Department of War (DoW) strategy to secure the Defense Industrial Base (DIB). It is more than a regulatory hurdle. It is a direct response to a rapidly changing and increasingly hostile threat landscape faced by the DIB. Updated CMMC guidance issued in…




































