Global Security News
Selling the Dream of SpaceX Was the Easy Part. Now Elon Musk Has to Hang On.
Global Security News
Hackers breach TrueConf to trojanize client installers with backdoors
Global Security News
Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions

China opened a cybersecurity review of Palo Alto Networks, citing national security concerns but giving no details about the reasons behind the probe. China’s Cyberspace Administration (CAC) announced that it’s launching a cybersecurity review of products Palo Alto Networks sells in the country. The announcement itself runs to a few sentences of formal Chinese, citing…
Global Security News
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data

Attackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own…
Global Security News
Copy Trade Robinhood Chain From Telegram

Robinhood Chain launched on July 1, 2026. Banana Gun supported it from that first day. No waitlist, no separate setup, no new app to download. You open the same Banana Gun Telegram bot you already use, and copy trading is sitting there waiting for you. Robinhood Chain moved fast. Daily DEX volume on the chain…
Global Security News
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Progress LoadMaster vulnerability to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Progress LoadMaster vulnerability, tracked as CVE-2026-8037 (CVSS score of 9.6), to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is an OS Command Injection Remote Code Execution issue…
Global Security News
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers

Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads.…
Global Security News
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger…
Global Security News
Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered…
Global Security News
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to…
Global Security News
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. “This…
Global Security News
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-8037 (CVSS score: 9.6), is a command injection flaw that could be weaponized to achieve arbitrary
GeekGuyBlog
AI-Generated Patches Fail Half the Time
Global Security News
Move 37 Is the Moment AI Changes Everything. It’s Suddenly Happening Everywhere.
Global Security News
Bugcrowd’s Braden Russell on launching Pathseeker
Global Security News
Forcepoint’s Ronan Murphy on securing the data layer AI just set on fire
Global Security News
Situational Awareness Bets $400 Million on Stealth Chip Startup After Crash
Global Security News
Fortra’s Josh Davies on the evolving exploitation of trust
Global Security News
Keyfactor’s Ellen Boehm on enterprise AI at scale
Global Security News
AI chat bots are sliding into League of Legends friend requests

Lina K., a co-worker, recently shared a firsthand account of how bots are adding League of Legends players via the Riot client friends list immediately after a match ends, striking up a flirty conversation, and eventually pushing an OnlyFans link. The pattern lines up with a wave of complaints that have piled up on Reddit…
Global Security News
OpenAI Pauses Some Work on New AI Model Over Cybersecurity Concerns
Global Security News
Meta ordered to pay $942 million over harm to children

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms. Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended…
Global Security News
Sci-Fi, PKD, Greatness, Passkeys, AgentBreaker, Rockwell, Flock, Josh Marpet – SWN #605
Global Security News
Snowflake Hacker Pleads Guilty After Breaches Exposed Data of at Least 100 Million People

A Canadian hacker has pleaded guilty to charges tied to the 2024 breaches of more than 165 Snowflake customer environments, a campaign that exposed data belonging to at least 100 million people. Connor Riley Moucka, 26, admitted to computer fraud, wire fraud, aggravated identity theft, and conspiracy in federal court in Seattle. The attacks relied…
Global Security News
Metabase SQLi zero-day exploited in customer data-theft attacks
Global Security News
DXC Becomes Exclusive Managed Services Provider for Primary’s AI Security Platform

On Aug. 6, DXC announced a strategic partnership with security startup Primary, becoming the exclusive managed services provider for Primary’s AI-native Zero Trust Platform. The joint offering is designed to help enterprises and government agencies govern how AI agents and enterprise AI applications access data, identities, and business systems. The companies are targeting organizations that…
Global Security News
Hackers Target Blackstone, CME and Other Wall Street Firms in Phone-Based Scam

A phone-first data-theft extortion campaign has targeted dozens of major US financial firms over the past month. Ransom-seeking hackers have targeted dozens of major US financial institutions and other businesses in a campaign that relies heavily on phone-based social engineering, according to data from Google and internet intelligence platforms reviewed by Reuters. The targets included…
Global Security News
A decade of enterprise identity in the cloud with AWS Managed Microsoft AD

Ten years ago, we launched AWS Directory Service for Microsoft Active Directory, a fully managed Microsoft Active Directory in the AWS Cloud. In that original announcement, Jeff Barr described a straightforward promise: “You will spend less time administering and more time working on your applications and your business.” A decade later, AWS Managed Microsoft AD…
Global Security News
China Opens Cybersecurity Review of Palo Alto Networks Products

China has put one of America’s biggest cybersecurity companies under the microscope, adding network security software to the growing list of US technologies caught in the escalating Beijing-Washington standoff. The Cyberspace Administration of China said Thursday that its Cybersecurity Review Office had begun a review of products sold in China by Palo Alto Networks, citing…
Global Security News
Cato Networks Adds Agentic AI Threat Prevention

Cato Networks, a converged network and security cloud, has launched Cato Agentic Threat Prevention, a new capability to deploy autonomous agents to predict likely attack paths. Stopping frontier AI adversaries before they advance Introduced at Black Hat USA 2026, the capability also automatically personalizes protections for each customer environment to prevent breaches before AI-assisted attacks…
Global Security News
Unlimited Technology Systems breach impacts 3.8 million people
Global Security News
July 2026 M&A: Barracuda, Cyera and MSP Acquisitions

The start of Q3 saw few mergers and acquisitions (M&A) movements across the channel, but these were nonetheless significant. The acquisitions focused on security and expanding reach into various regions to serve more customers. Read more about the M&A moves below, and be sure to catch up on last month’s moves. Barracuda Networks acquires Evo…
Global Security News
Etsy to Cut 220 Jobs, CEO Says Restructuring Is Not Driven by AI

Etsy is shrinking its workforce even as its business starts gaining momentum again. The online marketplace said Wednesday it will eliminate about 220 jobs, roughly 12% of its workforce, as part of a restructuring aimed at simplifying the organization and speeding up decision-making. Most of the layoffs will affect employees in product and engineering, according…
Global Security News
8×8 Launches Four-Tier Partner Program for Resellers

8×8, Inc., a business communication platform provider, is introducing a new partner program for its direct resell channel that rewards customer retention and expansion. Four-tier structure to align partner and company success The 8×8 partner program features a four-tier structure: Authorized, Silver, Gold, and Platinum. With this structure, direct resellers can earn financial rewards according…
Global Security News
Vishing group UNC6671 now focuses on extorting M&A firms
Global Security News
China-Linked Surveillance Platform Spans at Least 117 Servers, Targets Routers

LightSpy, a China-linked surveillance platform, has grown into an operation using at least 117 servers with verified router infections. At Black Hat USA, Arctic Wolf researchers Dmitry Bestuzhev and Dmitry Melikov said LightSpy has been identified in more than 13 countries, growing well beyond the spyware, active since at least 2018 and publicly documented in…
Global Security News
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. “These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer…
Global Security News
OpenAI Upgrades Free ChatGPT: GPT-5.6 Luna, Think Mode, and Unlimited Text
Free ChatGPT users are about to get more room to work. OpenAI is making GPT-5.6 Luna the default for Free and Go users this week. Unlimited text chats and a Think button arrive next week, while Plus and Pro subscribers get an updated GPT-5.6 Sol with more control over reasoning. Unlimited text lowers a barrier…
Global Security News
AMD to Acquire Taalas, Expand AI Inference Roadmap

AMD is moving deeper into AI inference with technology designed around specific models rather than relying only on general-purpose accelerators. The chipmaker has agreed to acquire Toronto-based Taalas, a startup specializing in inference silicon that AMD says can reduce compute and memory bottlenecks. AMD plans to integrate the technology into its accelerator roadmap and develop…
Global Security News
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that profiles the host and then fetches a macOS malware payload that’s compatible with the computer’s CPU…
Global Security News
Proofpoint Launches OEM Program for Security Providers

Proofpoint Inc. debuted a new program at Black Hat USA 2026 that makes a portfolio of OEM-ready threat intelligence and detection capabilities available for technology providers, cybersecurity vendors, managed services providers, and platform companies. Accelerating OEM innovation with trusted threat intelligence The Proofpoint OEM Program formalizes and expands the cybersecurity providers’ OEM business. It provides…
Global Security News
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. “UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff facilitating mandatory, urgent security migrations. Significantly, the threat actor often contacts employees via…
Global Security News
This 6-port USB-C charger replaced my ugly power brick – and powers my entire desk
The Satechi ChargeView 240W desktop charger ticks all the right boxes for this charging geek.
Global Security News
ConnectWise, SentinelOne Unveil MSP Cybersecurity Strategy

ConnectWise and SentinelOne have unveiled a joint managed cybersecurity strategy aimed at helping MSPs scale threat detection and response through deeper integration of Managed EDR, AI-driven security, and automation. ConnectWise and SentinelOne deepen MSP security collaboration Announced at Black Hat USA 2026, the strategy establishes a framework for deeper collaboration that brings together the AI-driven…
Global Security News
I was loyal to T-Mobile for 10 years, but switching to Mint slashed my bill – by a lot
The inconsistent service, shady upcharges, and uptick in better-valued competitors made the choice easy.
Global Security News
Trojanized AI skills gain 1.7M installs in agent-targeted attack

Researchers have uncovered an extremely effective attack campaign that involved AI agent skills trojanized to deploy a credential stealer. The incident is part of a growing trend in which attackers are targeting the AI software supply chain by poisoning sharable instruction and configuration files for agentic tools. Discovered by researchers from security firm Zenity, the…
Global Security News
Zero Networks Launches Least Agency Enforcement Capability

Zero Networks, a Zero Trust security solutions provider, announced a new capability at Black Hat USA 2026. This new capability applies the Open Worldwide Application Security Project’s (OWASP) principle of Least Agency to help organizations safely deploy AI agents. Reducing the impact of compromised AI agents The Least Agency Enforcement capability uses identity-based microsegmentation, policy…
Global Security News
Researchers bypass Spectre v2 mitigations
Global Security News
Zbtlink denies backdoor claims amid firmware download pause
Global Security News
Walmart faces lawsuit over alleged secret voiceprint collection in Illinois
Global Security News
AI coding tools vulnerable to malicious GitHub issues
Global Security News
More than half of AI-generated patches are broken

As AI-generated code continues to be injected into all corners of the internet, concerns have risen about an expanding attack surface for malicious hackers to exploit. Some have argued that the enhanced cybersecurity capabilities of large language models could serve as a check, finding and fixing vulnerabilities nearly as fast as they’re created. But new…
Global Security News
Samsung Galaxy Watch 9 review: Health data overload, but built for the future
Samsung’s latest smartwatch introduces new metrics, a longer-lasting battery, and hints at the future of wearables.
Global Security News
Crypto thieves increasingly using physical attacks for virtual currency theft
Global Security News
OpenAI disrupts major ChatGPT-driven scam campaign in Cambodia
Global Security News
China reviews Palo Alto Networks products, citing security concerns
Global Security News
Chinese-linked LightSpy spyware expands to over a dozen countries
Global Security News
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover

WordPress XSS2Shell flaw enables admin takeover and remote code execution. Users should update to patched versions. Researchers at Pwn just published a report on a vulnerability chain they’re calling XSS2Shell, and the entry point is quite simple: type a username that doesn’t exist, and WordPress echoes it back with a tiny formatting flaw baked into…
Global Security News
AI-Generated Patches Fail Half the Time
Global Security News
Securing your Amazon S3 buckets: Identifying and remediating over-permissioned access
Misconfigured Amazon Simple Storage Service (Amazon S3) buckets can expose your data to unauthorized access. Without proactive review, S3 bucket policies or Access Control Lists (ACLs) configured with broad access may go unnoticed in your environment. In this post, you learn how to identify and fix over-permissioned S3 buckets across your AWS environment, along with…
Global Security News
The Hottest App in Retail Is Now Worth $20 Billion
Global Security News
This Bluetooth-only Marshall home speaker sounds so good, I can forgive the missing Wi-Fi
Global Security News
State Department Wants Palantir’s Advice on Free Speech and “Countering Digital Surveillance”

The Trump administration tapped a surveillance giant with a record of attacking the press to advise the State Department on free speech. Among the partners for the State Department’s new “Freedom Tech Excellence Program” is Palantir, the AI and data integration firm started by right-wing powerbroker Peter Thiel. Under the program, company employees will go…
Global Security News
Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among dozens…
Global Security News
Levi Strauss & Co. says hackers stole corporate data in cyberattack
Global Security News
Your phone doesn’t block SIM swapping attacks by default: Turn on these carrier settings now
A SIM swapping attack could compromise your phone, your personal accounts, and even your identity. Here’s how to thwart them.
Global Security News
Beware cut-price AI services that read your every word
Global Security News
How we can apply lessons from The Odyssey to the AI challenge
Global Security News
Polish data center plans to send its waste heat to the neighbors

As Europe swelters in a heatwave, residents probably don’t want to hear about ways to make their homes even hotter, but that’s what Polish property developer Citylink is talking about, with plans to dump waste heat from a new data center in Wrocław into the municipal district heating network. Citylink is designing the data center…
Global Security News
Samsung Galaxy Z Fold 8 review: The compact foldable I’ve wanted all along
With its unique size, the Galaxy Z Fold 8 is a refreshing take on foldable phones, and I’m all for it.
Global Security News
I read Microsoft’s Windows 11 ‘quality’ progress report – and the subtext says it all
Microsoft’s latest progress report details much-needed Windows 11 improvements in reliability, performance, stability, and usability. But here’s what else I see.
Global Security News
Moonshot’s Kimi AI model has also escaped from a test environment

Yet another AI model has escaped from a cybersecurity test lab: This time, it’s the Chinese company Moonshot’s Kimi K3 model on the run. Frontier Security spotted that Kimi K3 had found a loophole in the UK AI Safety Institute’s test environment for AI models performing cybersecurity tasks. The news follows similar exploits by models…
Global Security News
Hugging Face Breach: OpenAI Agent Abused Exposed Credentials Across Four Services
An autonomous AI agent powered by a combination of OpenAI models escaped an isolated cyber-capability evaluation environment, reached the public internet, and conducted a multi-stage intrusion into Hugging Face’s systems. The models included GPT-5.6 Sol and a more capable internal research prototype operating with reduced cyber refusals and without the production safeguards normally used to…
Global Security News
Airtable joins Evernote, Brightcove, WeTransfer and AOL in Bending Spoons portfolio

Bending Spoons has snapped up Airtable to add to its portfolio of software companies, alongside AOL, Evernote, WeTransfer, Brightcove and Vimeo Airtable made its name as a builder of low/no code database services, aimed particularly at non-technical staff, but is now one of many vendors facing financial difficulties in the face of the SaaS/AIpocalypse. The…
Global Security News
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports

The U.S. Coast Guard said it is monitoring the aftermath of a cyberattack that disrupted gate operations at all three of North Carolina’s port facilities this week, though it offered few details as the investigation into the breach continues. A Coast Guard spokesperson told CyberScoop that the branch’s IT unit was coordinating with partner agencies…
Global Security News
I compared Google’s pricier Pixel 11 series to Samsung’s Galaxy lineup – here’s the better value now
The Pixel 11 may cost more, but Google’s software advantage may make it worth it for you.
Global Security News
AI Agents, Supply Chain Attacks, and Critical Flaws Define the Week in August 2026

This week’s cybersecurity landscape was shaped by rapidly expanding AI risks, attacks on trusted developer workflows, actively exploited enterprise software, and costly data breaches. Research into rogue agents, prompt injection, passkeys, and offensive AI showed why governance must keep pace with deployment, while incidents involving npm, hotel networks, remote monitoring tools, and sensitive public-sector data…
Global Security News
Real emails, hijacked payments: Two H1 2026 attack chains
Gen’s H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. […]
Global Security News
Wispr moves beyond AI dictation with note-taking assistant

Wispr, the startup behind dictation tool Wispr Flow, has created an AI note-taking assistant that records meetings and generates conversation summaries for users. The Wispr Flow Notetaker tool “captures your meetings so you can stop splitting your attention between listening and writing things down,” said Sahaj Garja, Wispr CTO and co-founder. Notetaker starts recording with…
Global Security News
North Carolina Ports confirms cyberattack disrupting operations
Global Security News
Snowflake attacker pleads guilty to hack of 165 companies’ data

A Canadian hacker has admitted being part of a group responsible for several major cyberattacks. Connor Riley Moucka pleaded guilty to being part of a coterie of hackers that hit 165 organizations, resulting in the theft of customer records and the extortion of millions of dollars. Industry sources have identified Moucka as one of the…
Global Security News
Apple rushes out emergency fix for screen sharing flaw on Macs – update ASAP
The updates were unexpected. Apple must have considered this flaw serious enough to warrant an immediate fix.
Global Security News
Netrio CEO: How AI Will Reshape MSP Services and Value
What will the MSP of the future look like as AI takes over more routine IT work? In this episode of Channel Insider: Partner POV, Netrio CEO Mark Clayman joins Victoria Durgin to discuss how artificial intelligence is changing managed services, customer expectations, IT service delivery, and the skills MSPs will need to compete. Clayman…
Global Security News
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP
WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerability requires no attacker privileges. According to pwn.ai,
Global Security News
I’m a diehard OnePlus user: Here’s my plan now that the company is leaving North America
OnePlus has officially ended business across North America and Europe. I explain what happens next and the best alternatives to consider.
Global Security News
DeepMind founder ascends to singular AI role at Google

Demis Hassabis, the driving force behind Google DeepMind, is ascending to the role of chief scientist at Alphabet, Google’s parent company, replacing Jeff Dean who is leaving to work at a start-up. The role will enable Hassabis to “put his full attention on actively shaping the future of AGI,” or artificial general intelligence, Alphabet CEO…
Global Security News
200 accounts compromised in Swiss government’s Microsoft SharePoint breach

Hackers exploited vulnerabilities in Microsoft SharePoint servers belonging to Switzerland’s Federal Office of Information Technology, Systems and Telecommunication (BIT), compromising the login credentials of around 200 accounts. On July 28, BIT’s security specialists noticed unusual activity on the SharePoint servers. Once the intrusion was confirmed, BIT blocked internet access to the platform and closed the…
Global Security News
What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
Global Security News
How I survive summer without AC: My top hot weather coping tips, tricks, and gadgets
No AC? Me neither. Here’s how to keep yourself and your home cool during a heatwave.
Global Security News
Wi-Fi 7 adoption in the US quadrupled in a year – is it time to upgrade?
Wi‑Fi 7 is rapidly moving out of the lab and into American living rooms, with data from Ookla showing US usage is growing fast.
Global Security News
Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026
Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. Key takeaways Building defensive cybersecurity tooling no longer requires a developer. Agentic tooling drove…
Global Security News
Growing Up The Hard Way
Global Security News
Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to…
Global Security News
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it.…
Global Security News
The Morning Risk Report: Prosecutors Probed Whistleblower Claims That JPMorgan Mishandled Fraud Cases
Plus: Explosive drone at German airport marks new threat for Europe, and Meta AI hacks add to concerns over rogue bots.
Global Security News
Healthcare and Victim Support Charities Affected by Beacon Cyber Incident
Global Security News
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active “widespread email-driven phishing campaign” that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. “The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,
Global Security News
Researchers Discover Hidden Backdoor in 20 Router Models Allowing Remote Root Access

A hidden backdoor in 20 router models lets remote servers execute commands as root, putting affected devices at risk of takeover. Jacob Baines had a router on his desk that kept trying to call home, and it wasn’t supposed to. VulnCheck researchers found a backdoor baked into Zbtlink routers, and it’s not the kind of…
Global Security News
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where scanning






























