
People are leaning on AI for a task more dreaded than homework: navigating social situations with their fellow humans.

ESAFENET’s CDG showed up in our data before. The company focused on secure document management and data leakage prevention solutions. The “CDG” stands for “Content Data Guard”, and the product appears to be mostly targeting the Chinese market [1]. Sadly, like so many security products, it suffers from basic security vulnerabilities like SQL Injection, XSS,…

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware Chaos ransomware’s msaRAT: Living…

Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel…

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems Australian energy provider Origin Energy…
The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it’s multi-faceted. You’ve got them leading with “don’t worry, your credit card is fine”, the hacker leading with “they didn’t respond when I tried to report it”, and now news that the two parties have…
In Part 3 of this exploration of AI ethics, we bring this topic closer to home: How can we use the power of AI to strengthen human trust and character?
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors.…
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. […]

US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not just looking around. They’re changing things. The updated advisory from CISA, the FBI, NSA, and the Department of Energy…

A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on July 23, 2026, said it has operated since late 2024 and impersonated TradingView, Solana, and…
Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves…
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. […]

Learn why cyber security matters in the field of education in this post. Cyber security refers to the practice of defending computers, servers, mobile devices, electronic systems, networks, and data from digital attacks, damage, or unauthorized access. Today, cyber security has become a critical concern for various industries. In the field of education, where technology’s…

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracked as CVE-2026-16723, the vulnerability carries an Alibaba-assigned CVSS score of 9.0. The confirmed chain…

Cryptocurrency may be highly volatile, but it’s currently a trendy investment opportunity. Many of the most widely used digital currencies, including Bitcoin and Ethereum, are experiencing similar cycles of low value followed by rapid appreciation. Many seasoned investors have been betting on cryptocurrency for years, but how can someone new to the industry participate? Here…

Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server. An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The chain needs no administrator rights, continuous integration (CI) runner access, victim interaction

The U.S. Justice Department is prosecuting an American man for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, a case believed to be the first of its kind in the United States where federal prosecutors have charged someone for the alleged destruction of data using a “duress” password,…
Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.
Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency about a pending cyber incident notification regulation had a few consistent messages: We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when…
As organizations rapidly adopt artificial intelligence (AI), security teams are racing to understand how frontier AI models could reshape enterprise cyber risk. Rather than relying on theoretical scenarios, Zscaler spent 90 days using frontier AI models from Anthropic and OpenAI to assess dozens of real enterprise environments from an adversarial perspective. The results suggest that…

EU fined Google €890M under the DMA for favoring its own services and restricting Play Store competition, with AI search features also under scrutiny. The European Commission hit Google with two fines totalling €890 million on Thursday for violating the Digital Markets Act, one for giving its own services preferential placement in Google Search and…

When an administrator introduces a rule change in AWS Network Firewall and network connectivity is disrupted, pinpointing the cause requires inspecting multiple points in the traffic path. The firewall gives you stateless and stateful rule engines, domain rules, and routing to the firewall endpoint inside your Amazon Virtual Private Cloud (Amazon VPC). A network drop…

Botnets powered by residential proxy networks are proliferating, enabling cybercriminals of all types to evade detection by blending in with seemingly legitimate traffic, Lumen Technology’s Black Lotus Labs said in a report Friday. The global scale of botnets observed by Lumen is currently approaching 60 million victim IP addresses, Chris Formosa, senior lead information security…
The hacking of Hugging Face by a rogue OpenAI agent is significant, but unsurprising — and preventing the next AI model escape will be difficult, at best.
Samsung just launched its latest lineup of phones, and Amazon has free gift card offers on every single one.

The White House is monitoring developments after OpenAI revealed earlier this week that one of the company’s AI systems went beyond its intended parameters during a security test and managed to hack into the infrastructure of the AI platform Hugging Face. According to Reuters, presidential technology advisor Michael Kratsios has been briefed on the incident.…
In this post, I will discuss luxury ORM Los Angeles and show you a realistic timeline for suppressing negative search results. In the high-stakes world of high-end commerce, your brand’s digital footprint is your most valuable asset. One disparaging article or a series of coordinated negative reviews can do more damage to your bottom line…
Dependency mapping focuses on what breaks, not what exists
SSO failure modes create cascading authentication outages across connected services
Recovery is only as fast as your understanding of what depends on what.
A recent uptick in lag and disconnects led me to reevaluate my home office setup. Here’s how I validated my solution.

Microsoft, along with more than two dozen tech companies, are pressing policymakers to support open-source AI systems and code across society, arguing that it will be a safer approach than attempting to restrict access or relying on a handful of closed, proprietary models. The open letter, posted Friday, draws parallels to the software industry of…

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware. “BlueNoroff has operationalised trust abuse by combining compromised industry contacts, social engineering, wallet

Cybersecurity vendor Coro has appointed three executives to lead EMEA sales, product strategy, and research and development as the company pursues international and channel growth. New executives take charge of EMEA, product, and R&D Among the hires are: Ingo Schaefer as Vice President of Sales, EMEA Dor Avrahami as Vice President of Product Itzik Schacher…

Resin art has become a popular corner of TikTok, with some videos attracting millions of views. But not every glossy, colorful post is what it claims to be. Scammers are using the look of handmade resin art to trick buyers, collectors, and even fellow artists into sending money for work that either doesn’t exist or…

Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway. Victims are asked to log in with their email address and password to claim free Call of Duty Points (CP), the game’s premium currency. They’re then redirected to a second page asking for their…

During an internal OpenAI security evaluation, a chain of AI models escaped its sandbox, reached the internet, and then accessed Hugging Face infrastructure to complete the test objective. OpenAI is a leading artificial intelligence (AI) research and deployment company. Its best-known product is undoubtedly ChatGPT. Hugging Face is a website where developers and researchers share…
As detailed in The Register, security researchers uncovered a vulnerability in Apple’s macOS Gatekeeper security feature that could allow malicious actors to replace legitimate applications with harmful versions.
In a battle of the top Android watches, one does it a little better.

Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine. They codenamed the flaw Certighost. Because Domain Controller accounts carry directory replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync.

Slopsquatting, phantom squatting, and HalluSquatting all exploit the same late-binding attack pattern, where AI coding agents trust hallucinated package, repo, or domain names. ActiveState explains how pre-fetch verification and governed dependency management can help stop these attacks before malicious code enters the pipeline. […]
Dell’s 14S pairs a sleek design with excellent battery life, making it one of the best midrange PC I’ve tested in 2026.

Google has started rolling out a new way to recover access to your account if you’ve lost your phone or forgotten your password: a “selfie video” verification option. After recording a short video of your face during setup, you can later submit another video during account recovery to prove you are who you claim to…
AM/FM, NOAA weather band, solar and hand-crank charging, and a power bank – this tech is what actually works when the grid doesn’t.

Meta has introduced Facebook Verified, a free badge meant to show that a person behind a profile has completed identity verification through a selfie check. (Source: Meta) The company says the goal is to give users a signal that they are dealing with a person, not a bot or an AI-generated account, when browsing Marketplace…