The Sovereign Australian Prime Alliance SAPA has welcomed Defence Industry Minister Pat Conroy’s vision to develop Australian-owned prime contractors capable of standing…
Global Security News
Why Most Organizations Can’t Say What’s Actually Exposed to the Internet
Ask most security teams for a complete, current list of everything their organization has facing the public internet, and there may be a pause before the answer.
Global Security News
Plain English Foundation’s new services help organisations use AI well
Services that help govern AI use, improve the quality of AI-generated content and build staff capability
Global Security News
CISA outlines improvement plan for CVE program
The Cybersecurity and Infrastructure Security Agency published a paper Wednesday that lays out its plan for improving the Common Vulnerabilities and Exposures (CVE) program, a contract for which nearly ended last year before a last-minute reprieve. The white paper outlines the components of a “Quality Era” for the program, widely used as the definitive clearinghouse…
Global Security News
Datadog Brings AI to Both Ends of the User Journey with Journey Monitoring and Bits Testing
The capabilities combine to give teams a complete and vital view of the user journey — from pre-release testing to production monitoring
Global Security News
Mark Zuckerberg Lays Out His Vision: Muse AI Agent Fused With Smartglasses
Meta’s CEO announces a new hand-held AI device and tech products he said take consumers closer to ‘personal superintelligence.’
Global Security News
Semperis Reimagines Active Directory Migration from the Ground Up
Migrator for Active Directory treats AD migration as a security event — not a data-copy operation — with staged validation, agent-based endpoint cutover, and real-time…
Global Security News
DXC Announces Winners of the DXC Invitational Across Australia and New Zealand
Insurtech competition showcases latest innovations from late-stage insurance startups and scaleups with market-ready solutions
Global Security News
Humanforce named a Major Contender in the Everest Group Workforce Management Products PEAK Matrix Assessment 2026 and the Everest Group Human Capital Management (HCM) Platforms Mid-market PEAK Matrix Assessment 2026
Humanforce, the workforce management and human capital management HCM platform built for frontline and flexible workforces, has been named a Major Contender in two 2026 Everest…
Global Security News
DroneShield Opens Adelaide R&D Hub to Accelerate Next-Generation of Australian Defence Technology
DroneShieldhttps://www.droneshield.com/, a global leader in counter-drone and electronic warfare EW solutions, is pleased to announce the official opening of its R&D Facility…
Global Security News
OpenAI’s new priorities for third-party assessments are a fine start, but they lack teeth
OpenAI published a detailed list of priorities and principles on Tuesday designed to govern its third-party model assessors, a list that industry observers agreed was a good one. But they also stressed that it lacked any enforceable controls to truly maintain safety. If the goal is to encourage enterprise CIOs to trust OpenAI more, it…
Global Security News
Avalara Ushers in New Era of Agentic Tax and Compliance with Avalara Aviator
Avalara’s new agent hub brings together specialised AI agents to execute complex tax and compliance workflows while keeping people in control of the decisions that matter
Global Security News
UiPath Test Cloud Accelerates Autonomous Testing at Enterprise Scale
New Test Cloud capabilities help teams expand coverage and reduce maintenance work so they can release software faster, while building toward UiPath’s dark testing factory vision
Global Security News
Solana Trading Bot in 2026: How to Buy, Copy Trade and Exit From One Chat
In this post, I will discuss the Solana Trading Bot in 2026 and show you how to buy, copy-trade, and exit from one chat. A Solana trading bot is a Telegram-based tool that lets a trader buy, copy trade and exit Solana tokens from inside a chat, without a separate exchange account. Banana Gun is…
Global Security News
Barracuda Launches Industry-First AI Security and Governance Solution to Accelerate Safe AI Adoption for Resource-Constrained Businesses and MSPs
New Research Reveals Nearly Half of Senior IT Leaders Say Their Teams Lack the Skills to Securely Govern AI Already in Use, Creating Growing Security and Compliance Risks
Global Security News
Maintenance Company in Dubai: What to Check Before You Sign
In this post, I will talk about maintenance company in Dubai and what to check before you sign. Most homeowners pick a maintenance company in Dubai the way they pick a taxi: whoever answers first gets the job. A fast reply says nothing about who shows up. European Technical, working across Dubai and Sharjah, fields…
Global Security News
Qualtrics Introduces Healthcare XM: Press Ganey Data, Analytics & Solutions on the XM Data & AI Platform
Built on the world’s largest human experiential dataset, the XM Data & AI Platform powers Healthcare XM. Healthcare XM advances Experience Management to simulate, predict, and…
Global Security News
Exabeam Accelerates Global Channel Momentum as Exabeam APEX Partner Program Drives Measurable Growth
Channel-driven H1 new-logo pipeline exceeds target by 138% as partner satisfaction, conversion rates, and expansion bookings climb worldwide
Global Security News
Nutanix Acquires Ryax Technologies to Help Customers Accelerate Agentic AI Initiatives
Ryax platform provides smart scheduling and performance optimisation, with planned integration into Nutanix Kubernetes Platform and Nutanix Enterprise AI
Global Security News
OpenAI Agent Hacked Australian Government Website
The attack appeared to be the first publicly disclosed incident of an AI agent gaining unauthorized access to government files.
Global Security News
Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand’s national parks. What could possibly have gone wrong? Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping…
Global Security News
ICYMI: August 2026 @AWS Security
Read all about the latest AWS security features, compliance updates, and hands-on resources in our monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts August brought 20 AWS Security Blog posts organized across seven categories. Identity and access management led the month with five posts…
Global Security News
Placeholder domain used in dev docs now serves ClickFix attacks
The “third-party.com” domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. […]
Global Security News
Americans’ views on data centers have turned more negative
American attitudes toward data centers have turned noticeably more negative over the course of 2026, according to a new Pew Research Center survey. 54% of U.S. adults now say data centers are mostly bad for the environment, up from 39% in January. Half say they hurt home energy costs (up from 38%), and 49% say…
Global Security News
The Group Chat Where World Leaders Are Racing to Create AI Controls
An island meeting and texts between the leaders of Canada, France and Norway reveal an emerging alliance: “We’re in.”
Global Security News
New RemControl Android banking malware targets users in Europe and Canada
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. […]
Global Security News
EDR Evasion Stack Helps Process Injection Slip Past Defenses
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
Global Security News
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
Global Security News
Mamdani Targets ‘Greedy Algorithm’ of Corporations in a New Brand of Politics
Politicians on the left and right are watching how the New York mayor’s tactics play out in world’s center of capitalism.
Global Security News
F5 fixes actively exploited zero-day flaw in BIG-IP APM
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available. BIG-IP APM is a software component in F5’s BIG-IP hardware platform that…
Global Security News
U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93616 Check Point Multiple Products Path…
Global Security News
Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
HealthTech apps need secure architecture, encrypted data, strong access controls, continuous testing, and post-launch monitoring to protect patient information.
Global Security News
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. […]
Global Security News
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack
Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found. The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security…
Global Security News
How device code phishing gives scammers access to your account
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts. The message claims the code will let you open the document or join the meeting. In fact, it approves…
Global Security News
Hackers start exploiting critical WordPress flaw for code execution
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. […]
Global Security News
F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated…
Global Security News
Pentagon cyber chief: The demand far exceeds supply
The Pentagon’s top civilian cyber policy official said Tuesday her single priority is expanding the cyber options available to the president and the defense secretary, describing a gap between what commanders are asking for and what the force can deliver. “I’m focused on one single priority, and that is building a more robust set of…
Global Security News
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below – gocommunity-io/dockerd (222 downloads) kreuzwenker/
Global Security News
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
Global Security News
Ryuk ransomware operator sentenced to 2 years in prison
A 35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday. Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and…
Global Security News
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a…
Global Security News
DoorDash Spent $1.4 Million Trying to Stop Mamdani From Becoming Mayor. Now We Know Why.
Last year, well before DoorDash’s $131.5 million settlement with New York City for underpaying 264,000 delivery workers was announced Tuesday, the company spent around $1.4 million on the campaign to stop Zohran Mamdani, who oversaw the historic settlement, from becoming mayor. At the time, DoorDash’s campaign contributions in the run-up to the 2025 mayoral election…
Global Security News
Lenovo Expands Virtualization Portfolio for AI-Ready IT
Lenovo is expanding its virtualization portfolio with new infrastructure, deployment services, and validated solutions designed to give enterprises more flexibility as they modernize legacy environments and prepare for AI workloads. The additions include the ThinkAgile VX850 V4, expanded Infrastructure Deployment Services, and new Express Solutions spanning Microsoft, Red Hat, Nutanix, and SUSE technologies. For channel…
Global Security News
Fastly Launches AI Runtime Controls for Enterprise Agents
Fastly is expanding its edge platform with three AI-focused security and governance capabilities designed to give enterprises — and the MSPs and MSSPs supporting them — more control over how AI models, applications and autonomous agents interact with enterprise infrastructure. The new AI Runtime Control, AI Firewall and API Security capabilities are intended to apply…
Global Security News
Facing Congressional Scrutiny, Flock Details New Search Guardrails
The company says it cut its default data-retention period to seven days from 30, added standardized search categories and will require case numbers.
Global Security News
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. […]
Global Security News
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
Global Security News
Anthropic Leaders Back Startup Developing System to Detect Biological Threats
Pilgrim has raised $25 million and has developed a 50-pound device that detects biological threats.
Global Security News
UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
Global Security News
Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster
MSSP Tier 1 analysts can cut phishing triage time with interactive analysis, fresh threat intelligence, clearer evidence and complete Tier 2 handoffs worldwide.
Global Security News
CVE-2026-87902: Critical WordPress Core Flaw Enables Unauthenticated RCE Under Certain Conditions
WordPress has released an emergency security update addressing a critical vulnerability in its Core software that can allow an unauthenticated attacker to load arbitrary local PHP files and, under specific server and theme conditions, achieve remote code execution. Tracked as CVE-2026-87902, the vulnerability affects WordPress releases from version 4.7.0 through 7.1.1 and carries a CVSS…
Global Security News
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. Adobe Bridge is a creative asset manager that lets you preview, organize, edit, and publish multiple creative assets quickly and easily. Adobe Connect is a secure, highly customizable web conferencing and virtual training platform used for…
Global Security News
OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems
OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks. The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s…
Global Security News
CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Exploited for Remote Code Execution
F5 has disclosed a critical zero-day vulnerability affecting BIG-IP Access Policy Manager (APM) that is already being exploited in the wild. Tracked as CVE-2026-94127, the flaw can allow an unauthenticated remote attacker to execute arbitrary code on vulnerable BIG-IP systems by sending specially crafted traffic to an affected OAuth configuration. The vulnerability is a heap-based…
Global Security News
CVE-2026-93616: Check Point Management Server Zero-Day Exploited in Targeted Attacks
Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management infrastructure after confirming exploitation in targeted attacks. Tracked as CVE-2026-93616 and rated 9.8 on the CVSS scale, the flaw enables an unauthenticated attacker with network access to the vulnerable management service to upload and execute arbitrary scripts. The vulnerability…
Global Security News
GitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these applications use to authenticate themselves can remain valid for years unless manually revoked. If leaked, those keys can potentially give attackers administrative control over an organization’s…
Global Security News
From admin to architect: Jamf’s vision for the autonomous Apple enterprise
Now a private company, Jamf opened its big annual event for Apple enterprise management teams, JNUC, by taking big steps to exploit artificial intelligence in the management of Apple fleets. During her keynote speech at the Kansas City event, CEO Beth Tschida shared some of the details of the platform-scale overhaul the company has set…
Global Security News
How to fix your Windows File History if the September update broke it
A bug in the Windows Sept patch Tuesday update may stop File History from working. But a new optional update fixes it.
Global Security News
AI Has Cracked the Most Diabolical Problems in Math. Why Can’t It Solve Chess?
Chess engines can beat grandmasters—but they can’t agree on a single infallible strategy. And, instead of ruining the game, artificial intelligence is now uncovering new ways of playing.
Global Security News
Hundreds of Leaked GitHub App Keys Still Authenticate
GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access
Global Security News
Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and…
Global Security News
InfraTrust report warns network management systems under attack
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. […]
Global Security News
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker’s server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and…
Global Security News
Microsoft Disrupts AI-Powered EvilTokens Service Linked to 12,000 Hacked Inboxes
Microsoft disrupted EvilTokens after the AI-powered phishing service compromised 12,000 inboxes across 10,000 organisations and enabled complex financial fraud.
Global Security News
Cofense measures employee readiness against real-world phishing threats
Cofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting. The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving security teams evidence of program effectiveness rather than training completion. This measurement advances Secure Behavior Management (SBM), an…
Global Security News
How One Kubernetes YAML Can Hand Over a GCP Organization
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. […]
Global Security News
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Global Security News
80,000 relay servers help users in China slip past U.S. AI region bans
More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models, according to Team Cymru. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and illicit activity,” said Scott Fisher, Senior Principal Engineer at Team Cymru. Earlier this…
Global Security News
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead…
Global Security News
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below – @memtensor/memos-cloud-openclaw-plugin versions
Global Security News
Portnox detects and removes unauthorized AI applications from managed devices
Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability addresses shadow AI: generative AI applications that increasingly act as autonomous agents, reaching local files, remote resources, and enterprise data with…
Global Security News
Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure
Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk. Stolen credentials and other information exposed in data breaches can circulate across dark web marketplaces, forums and other sources. For…
Global Security News
Finnish AI Cloud Startup Verda Raises $189M, Tops $1B Valuation
Finnish AI infrastructure startup Verda has raised $189 million in an oversubscribed Series B round, pushing its valuation above $1 billion as it expands GPU capacity across Europe. Emergence Capital led the round, joined by Supermicro, MUFG Innovation Partners, Varma, Lifeline Ventures, 6 Degrees Capital, byFounders, Tesi, and several angel investors. The financing brings Verda’s…
Global Security News
Okta Expands AI Agent Security and Governance
Okta is expanding its identity security controls for AI agents, adding new capabilities for agent discovery, access governance, runtime enforcement, and rapid response as enterprises deploy more autonomous AI across their environments. The new capabilities build on Okta’s blueprint for the secure agentic enterprise, introduced in March 2026, and are designed to answer four increasingly…
Global Security News
DarkMe RAT trades zero-days for plain phishing emails
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on…
Global Security News
Barracuda brings AI security and governance within reach of smaller organizations
Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance. Barracuda AI Data Security represents a major milestone in Barracuda’s expanding AI Security…
Global Security News
Lookout targets smishing, voice cloning, and vishing with real-time mobile protection
Lookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice cloning, and other voice phishing (vishing) techniques. Frontier AI is transforming social engineering by enabling attackers to create highly…
Global Security News
Fake Claude Max giveaway tricks users into handing over their Google account credentials
A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto Networks’ Unit 42 reported a campaign that used draggable fake browser windows to target Microsoft 365 users. “Phishing…
Global Security News
Nearly 70% of workers use AI regularly now – but many get no time to upskill
ZDNET Exclusive: A new Workera report shows businesses and employees aren’t on the same page about AI upskilling. Here’s what organizations need to know.
Global Security News
KDDI, Exaforce Expand Agentic SOC Services in US, EMEA
KDDI America and KDDI Europe are adding Exaforce’s agentic SOC platform to their managed security portfolios, giving the cybersecurity vendor a new route to multinational enterprises across the US and EMEA. Under separate partnership agreements, the two KDDI subsidiaries will market and sell the Exaforce Agentic SOC Platform directly to enterprise customers while also incorporating…
Global Security News
Introducing the Agentic Skills Marketplace: Curated AI Capabilities for the Modern SOC
For years, SOC Prime has focused on one core problem: curating behavioral detection rules that cover both the threats that never go away and the new ones that emerge every day. As agentic AI changes how security teams work, we see the same opportunity opening up in a new area — and we’re expanding our…
Global Security News
Fake Claude Max giveaway hides a Google account phishing trap
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and…
Global Security News
Arista patches actively exploited VeloCloud Orchestrator zero-day
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. […]
Global Security News
Why AI is Leaving Many Employees More Overworked and Less Productive
Plus, Meta’s Muse app sparks fears of financial-sector disruption
Global Security News
The president has called for AI leadership. Here’s the mission.
America leads the world in artificial intelligence. As it should. But tech leaders keep warning, with alarming frequency, that we are at risk of losing control. President Donald Trump has called for an AI czar and an “AI Force.” The details remain unclear, but the announcement underscores something fundamental. A technology this consequential demands clear…
Global Security News
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other…
Global Security News
Exabeam APEX Partner Program Exceeds H1 Pipeline Target
Exabeam’s channel-driven new-logo pipeline exceeded its first-half 2026 global target by 138%, giving the cybersecurity vendor an early measure of momentum one year after launching its APEX Partner Program. The company also reported expansion bookings at 125% of plan as it continues to build around a channel-first growth strategy. The results come alongside year-over-year gains…
Global Security News
ShinyHunters claims FBI breach was revenge for “false” report
Extortion group ShinyHunters is not afraid to make enemies. Now it claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site, ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group. In a very long post on its leak site,…
Global Security News
Ransomware Attacks Reach Record High for 2026
A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC data
Global Security News
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security…
Global Security News
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a “major step up from Opus 5,” and “achieves the best scores of any model to date on our automated behavioral audit,…
Global Security News
Microsoft: September Windows updates break Always On VPN connections
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. […]
Global Security News
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel’s AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04…
Global Security News
EvilTokens made phishing-as-a-service look easy. Then it got taken down
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold…
Global Security News
ServiceNow vs. Salesforce for IT Partners: Key Differences
ServiceNow and Salesforce are moving deeper into each other’s territory as AI agents, automation, low-code development, and customer service reshape the enterprise software market. For IT partners, that growing overlap creates a more complicated opportunity. Choosing where to build expertise is no longer simply a question of IT workflows versus CRM; it increasingly depends on…
Global Security News
Black Hat Fireside Chat: As AI agents spread, the network shifts from traffic mover to policy enforcer
The network’s job has always been simple: watch the traffic. Authority stopped there. Related: AI agents have a Lord Of The Flies problem For decades, network traffic came from something physical: a server, a laptop, a badge reader, a printer, each with a fixed address. An AI agent isn’t physical, and it has no fixed…
Global Security News
Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strategies
According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In…
Global Security News
Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026,…
Global Security News
GPT-6 Sol and Luna arrive with 50% lower API prices
OpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop app. The models are not yet available in Chat. OpenAI API users can access them as…
