
Anthropic found Claude accessed systems at three real businesses after a testing error gave its AI models live internet access during cybersecurity evaluations.


Identity systems sit at the center of enterprise security, but they are also one of the first places attackers look when launching ransomware and other disruptive cyberattacks. In this eSecurityPlanet video podcast, Marty Momdjian, General Manager, Ready1 & Strategic Initiatives at Semperis, joins the conversation to discuss how attackers compromise Active Directory and Entra ID,…

Today, we’re releasing the HIPAA Security Rule on AWS: Technical Safeguards Implementation and Readiness Guidance. This helps covered entities and business associates configure, implement, and evidence compliance with the HIPAA Security Rule Technical Safeguard requirements (45 CFR §164.312) when building healthcare workloads on AWS. The HIPAA Security Rule’s Technical Safeguards (§164.312) define five standards and…

Hims & Hers patients may have shared more than symptoms and treatment concerns when they sought care online. The Federal Trade Commission (FTC) has filed a lawsuit against Hims & Hers, alleging that the company allowed advertisers to collect and share sensitive patient information while telling customers their health information would remain confidential. The complaint,…

A Chinese-speaking threat actor is suspected to be behind a fresh wave of cyber attacks targeting government organizations mainly located in Central Asia, including Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic, since January 2025. These targeted organizations operate across several sectors, such as healthcare, research, government offices,
Microsoft has quietly pushed out a new OneDrive Photos app to Windows 11 users. What’s it all about?
In the U.S., regulation can protect incumbents while discouraging entrepreneurs. China gives fast-moving startups room to grow before exerting state control.
What you’ll get back depends on how much you spent – but don’t expect much.

South Korea’s Personal Information Protection Commission (PIPC) has fined KT Corp. 53.9 billion won ($37.4 million) after finding that weak network access controls allowed hackers to expose the personal information of 16,647 mobile customers. The regulator said hackers accessed KT’s wireless network through an unauthorized femtocell, a small base station used to extend mobile coverage,…
OWASP NHI guidance highlights detection gaps as the biggest security challenge.

Brinks Home is investigating a cybersecurity incident that attackers claim began with a Microsoft Entra voice phishing campaign targeting employee identities. The company confirmed an attacker has threatened to publicly release information allegedly stolen from its systems. “The party responsible for this situation has threatened to release information it claims to have taken. We are…
Disclosure: This article was created in collaboration with Status Labs.

Apple’s outgoing CEO, Tim Cook, bade an emotional farewell to analysts and shareholders on Thursday as the company announced a record June quarter. His successor, John Ternus, takes over at the beginning of September with the company seemingly in solid shape. The results were impressive, though some worrying challenges were confirmed. Apple managed to set a new…
Worried about your personal AI chats being exposed? Here’s how to tighten your privacy across several of the major chatbots.
Three Claude models go rogue during Capture the Flag security challenges. Here’s the trail of damage each left behind.
Behind the rogue agent’s attack on Hugging Face was a particular sequence of human decisions. We all need to pay better attention – because threat actors are learning, too.

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
Walking around Dubai, it’s hard to believe a war is still going on in neighboring countries. No missiles have struck the city, and it was clear during a recent visit that local residents are keeping to their routines. The biggest public worry, as it has been in many parts of the world, is the extreme…

Fortnite scam pages like the ones below appear by the dozen every day, recycled endlessly under different names and designs. One version promises $50 from a fake superhero collaboration. Another claims it can calculate what your locker is worth. Both lead to the same destination: a fake Epic Games login page designed to steal your…

As newspapers move online, the buildings that once housed their printing presses need new occupants. The Minnesota Star Tribune has just sold its old printing plant on the edge of Minneapolis to the aptly named property developer Legacy Investing, which plans to create a new data center there. has found the ideal way to bring…

It’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices. The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to ban them in their entirety on the grounds that…

It’s a sign of the times: Security conference DefCon has added smart glasses to its list of banned audio- or video-recording devices. The organizers have said that, with no consistent way to understand whether smart glasses are recording or not, they have taken the step to ban them in their entirety on the grounds that…

Software supply chain attacks are evolving beyond compromised software packages into attacks targeting the people, identities, and workflows used to build and distribute software. Intel 471’s report, Poisoned Trust: How Supply Chain Attacks Weaponize Developer Ecosystems, found that threat actors are increasingly targeting developer accounts, CI/CD pipelines, repositories, IDEs, and publishing infrastructure. By compromising these…
We tested the best laptop cooling pads to keep your device running smooth with powerful cooling, RGB lights, high RPM and more.
ZDNET’s latest Data Byte highlights the Netgear Orbi 370’s performance in our lab testing. Here’s what the numbers say.

Managed detection and response services give organizations access to 24/7 threat monitoring, investigation, and incident response without requiring them to build a complete security operations center. They combine security technology, automation, and human expertise to help organizations identify and contain threats more efficiently. We evaluated five leading MDR providers for 2026 based on threat coverage,…

Bitsight says some cheap Android TV boxes have shipped with apps that rewrite their hardware identity to mimic Samsung, Huawei, Xiaomi, or Vivo phones, then click ads on websites run by the same operators. Researchers named the operation Fuyao and attributed it to Zhejiang Fengwo IoT Technology Co., Ltd., a mainland China company founded in…

Organizations are rapidly embedding artificial intelligence (AI) into enterprise resource planning (ERP) systems, but many cybersecurity leaders remain unconvinced that their organizations are prepared to secure these environments. According to the 2026 Onapsis State of AI, Security, and ERP report, AI adoption is accelerating across SAP, Oracle, and Salesforce environments even as concerns about security,…

This week’s cybersecurity landscape was defined by attacks against critical infrastructure, actively exploited enterprise flaws, rapidly expanding AI exposure, and major compromises involving healthcare, energy, financial, and retail data. At the same time, AI agents demonstrated how quickly vulnerabilities can be discovered and weaponized, reinforcing the need for faster patching, stronger identity controls, continuous asset…

Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET’s new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix attacks, record quishing activity, and ransomware tools designed to disable security software. […]

Google is creating a new naming scheme for the bad actors behind cybersecurity threats, hoping that it will help to standardize the way that attacks are reported. Spoiler: It won’t. Security researchers use these naming schemes so that they can attribute attacks without necessarily knowing exactly who is behind them. Google had naming schemes in…

Google says AI found and helped fix 1,072 Chrome security bugs in two releases, dramatically accelerating vulnerability detection and patching Google’s Chrome Security team published a detailed account of how AI models have transformed their vulnerability management pipeline, and the headline figure is difficult to dismiss: in the last two Chrome releases alone, the team…

Broadcom has addresses five vulnerabilities in its VMware product range, three of which have been accorded a “critical” rating. The affected products are: VMware ESX, VMware vCenter, VMware Workstation, VMware Fusion, VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure CVE-206-59309 affects the VMware Directory Service. According to Broadcom,…
Cybercrime has become a commercialized ecosystem where criminals can buy or rent nearly every capability needed to launch sophisticated attacks. These services provide anonymity, plausible deniability, and access to short-lived infrastructure that is difficult to detect, attribute, and disrupt, enabling low-skilled actors to operate at scale, according to the Infoblox 2026 Threat Landscape Report. “Cybercrime…

Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers and Microsoft’s own. Google subsidiary Wiz found a flaw in the database’s Gremlin API, usually used for storing and managing property graph data. If bad…

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out…
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29…

A security investigation into inexpensive Android TV boxes led researchers to an ad fraud operation that had remained unnoticed for several years. Fuyao apps ecosystem (Source: Bitsight) According to Bitsight, the operation, named Fuyao, uses preinstalled Android apps, device identity spoofing, AI-generated websites, and residential proxy services to generate advertising revenue without device owners’ knowledge.…

An academic study has disclosed a “widespread class” of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user’s network session. The findings have been released by a group of researchers from Singapore’s Nanyang Technological…
According to the newly-published study, phishing and social engineering are becoming more expensive to recover from, trickier to detect, and increasingly augmented by artificial intelligence. Read more in my article on the Fortra blog.

Device code phishing – the abuse of the OAuth 2.0 device authorization grant to steal access tokens – has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide…

Palo Alto Networks’ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

Researchers have described a campaign that delivers a remote access Trojan (RAT) called AtlasRAT through a fake Flash Player installer. People still go looking for “Flash player” because a surprising amount of content and software was built around Flash and never properly migrated. Users often just want a quick way to get those old sites,…

JetBrains is warning of a critical security vulnerability in its TeamCity DevOps platform that could allow unauthenticated attackers to execute arbitrary operating system commands on vulnerable servers. “If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary commands,“ the company said in…
If you want to get started with trading, then using either a mobile or desktop device is a great idea.
Organizations no longer need to choose between strong endpoint security and a productive workforce.

We almost never get both sides of an intrusion. This time we did. Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased…

Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI’s July 21 announcement that some of its models had escaped an isolated testing environment by exploiting a previously unknown vulnerability and reached the systems of Hugging Face, the open-source machine…
The Smartwings window shades are convenient and fully customizable, making them a good option for non-standard windows.
U.S. policy has long favored lower taxes on profits and investment. That might need rethinking.
I was asked for help with a problem similar to the following. Here is a ZIP file, analyzed with zipdump.py: The filename you see, is in Simplified Chinese: zipdump.py relies on the zipfile or pyzipper Python modules to parse the given ZIP file, and have the metadata (filenames and comments) decoded correctly. If this ZIP…

Less than two weeks after OpenAI disclosed that an experimental AI model breached Hugging Face during a cybersecurity evaluation, Anthropic has revealed that its own review uncovered three incidents in which Claude models gained unauthorized access to the production infrastructure of three organizations during similar testing. Anthropic said it launched the review after OpenAI disclosed…

Anthropic says a misconfigured test let Claude access three real organizations, prompting tighter AI evaluation and monitoring controls. Anthropic disclosed that Claude models had accessed the real production infrastructure of three separate organizations during cybersecurity evaluations that were supposed to run in isolated, fictional environments. The company found the incidents after reviewing 141,006 evaluation runs…
Annual upgrades matter less these days, and better software support lets you hold onto your phone for longer.

Two major conferences loom large on the US cybersecurity events calendar: The RSA Conference and Black Hat. RSA was launched in 1991 by then CEO Jim Bidzos of RSA Data Security, the encryption company founded by Ron Rivest, Adi Shamir, and Leonard Adleman. Originally, the conference had a cryptography focus, but that all changed in…

Traefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform and security teams a container whose entire executable content is a single memory-safe binary, with validated cryptography built inside it and every advanced capability, from API gateway to AI and MCP gateway…

Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure. Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built…

AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across fragmented security technologies, disconnected workflows, and manual processes. Security teams have invested heavily in tools that identify…

Resecurity has announced the availability of native integration with IBM QRadar SIEM, a widely used Security Information and Event Management (SIEM) platform used by the leading Fortune 100 corporations worldwide. The plugin is available for activation via IBM Application Exchange. The integration leverages open standards STIX and TAXII (including version 2.1) to ingest, normalize, and…

SilverFox targeted a Japanese manufacturer with new DLL sideloading techniques, kernel drivers, and resilient ValleyRAT persistence mechanisms. Cato CTRL documented a new SilverFox campaign targeting a Japanese industrial manufacturer. The attack chain adds two previously undocumented DLL-sideloading hosts, two kernel drivers not previously associated with SilverFox, and a dual-layer recovery architecture that keeps ValleyRAT running…
MELBOURNE, Fla., July 30, 2026, CyberNewswire – The growing number of high-profile AI security incidents making headlines around the world are not simply cybersecurity failures. They are architectural failures, according to OpenMatter Network Co-Founder and CEO Renee Davis. “Recent incidents involving increasingly autonomous AI systems – including OpenAI’s widely reported cyber evaluation that resulted in…

Anthropic on Thursday became the latest artificial intelligence (AI) company to reveal that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, had breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the…

In this interview with Help Net Security, Eliran Almong, CEO of Cyviation, explains why airline cyber losses happen on the ground while the aircraft stays unmonitored. He walks through GNSS jamming that leaves no trace in a SIEM, and a PX4 Autopilot flaw his team disclosed where drone command channels accept unsigned messages. He argues…

In 2024, sysadmins expected AI to automate patch management optimization, vulnerability prioritization, infrastructure monitoring, and incident response within two years. Action1’s 2026 Survey Report: AI Impact on Sysadmins found that those expectations proved overly optimistic. The largest shortfalls appeared in high-impact operational and security functions, where AI needs to understand business context, system dependencies, risk,…

Founders pitching a cybersecurity seed round this summer are joining a line that keeps getting longer. Product Hunt launches hit their highest level since late 2023 last quarter, and the Census Bureau’s count of high-propensity business applications kept climbing. Seed deal volume in cyber ticked down. Those figures come from the Q2 2026 Insights report…
Here’s a look at the most interesting products from the past week, featuring releases from BlackCloak, Contrast Security, Dropzone AI, PortSwigger, Realm Security, Reco, Root Evidence, and ZeroFox. BlackCloak extends deepfake protection to the executive’s trusted circle Deepfakes have made one of our oldest assumptions unreliable: that you can trust a familiar face or voice.…
For years, Australians have purchased rooftop solar largely on faith. They’ve compared quotes, read reviews, spoken with installers and weighed up payback periods, often making…
All of the major AI providers want you to use, and ideally stay within, their super apps, and now Microsoft is looking to capture that attention, too. During an earnings call this week, CEO Satya Nadella confirmed that the tech giant is building a Copilot ‘super app’ that will be rolled out this quarter. The…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
New integration helps deliver centralised policy enforcement across AI applications to drive faster enterprise AI deployments

A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy, now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material…

A prominent Norwegian AI researcher on Tuesday posted details about an AI worm that is wreaking havoc in various Microsoft applications, including Word and Copilot. The report from noted Norwegian AI researcher Håkon Måløy, now confirmed by Microsoft, said that an attacker can conceal instructions in a document that is later used as source material…

Anthropic said a review of its cybersecurity testing found three cases in which its models broke out of sealed test environments and reached the live computer systems of outside organizations, according to a company blog post published Thursday. The company said it began the review after OpenAI disclosed earlier this month that some of its…