
Job pressures have increased as companies run headlong into AI adoption, causing 26% of top security executives to consider leaving their position.


Christopher Nolan’s The Odyssey had barely reached theaters before scammers began targeting people searching for pirated copies, according to Malwarebytes. Within hours of the film’s release, researchers found two separate scams running on cloned piracy sites: fake browser warnings and Windows executables disguised as movie downloads. “Neither scam has anything to do with the movie…
Last week, Searchlight Cyber released details about a vulnerability they are calling “wp2shell”. The vulnerability was initially announced without a CVE number. But now has been assigned CVE-2026-63030. Many WordPress plugin vulnerabilities are never assigned CVE numbers. But wp2shell is different. It is a SQL injection vulnerability in WordPress Core, not a plugin, and can…

The head of a key federal government AI testing lab is leaving his post just months after taking over. A Department of Commerce spokesperson confirmed to CyberScoop that Chris Fall is stepping down as director of the Center for AI Standards and Innovation, and his position is being backfilled. “Following Chris’s departure, NIST Director Dr.…
Apricorn’s new 4TB Aegis Secure Key is the biggest-capacity hardware-encrypted flash drive on the market right now.

A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it…

Microsoft 365 calendars have become a hiding place for espionage malware, with commands and stolen files stashed inside appointments dated to the year 2050, researchers from Group-IB discovered. Targeted campaign tied to Iranian espionage activity The malware, which Group-IB calls HOLLOWGRAPH, is one component of a bigger toolkit the company links with high confidence to…
Most mainstream phones are durable enough for everyday use, but if you’re the adventure-seeking kind, check out our top rugged phones.
An agentic AI infiltrated the production infrastructure of an AI project. Then an AI detected it. Is this the future of cyberattacks, and how will they be defended against?
An agentic AI infiltrated the production infrastructure of an AI project. Then an AI detected it. Is this the future of cyberattacks, and how will they be defended against?

Amazon Web Services (AWS) successfully completed an onboarding audit with no findings for ISO 9001:2015, 27001:2022, 27017:2015, 27018:2019, 27701:2019, 20000-1:2018, and 22301:2019, and Cloud Security Alliance (CSA) STAR Cloud Controls Matrix (CCM) v4.0. EY Certify Point auditors conducted the audit and reissued the certificates on May 31, 2026. The objective of the audit was to…
Backup and disaster recovery may be a mature technology category, but much of the infrastructure protecting MSP customers was designed for a far different threat landscape. Michael Fass, co-founder and CEO of backup and disaster recovery provider Slide, argues that aging BCDR platforms can create security, recovery and operational risks for MSPs already contending with…
Soaring hard drive prices are making NAS boxes a niche product, but the Synology DS225+ still makes sense. Here’s why.

Hugging Face disclosed that attackers breached its production infrastructure using an autonomous AI agent attack. The attackers gained access to internal datasets and credentials by exploiting vulnerabilities in the company’s data-processing pipeline. While the investigation is ongoing, the company said it has found no evidence that public-facing models, datasets, or Spaces were modified, and its…

Christopher Nolan’s The Odyssey is one of the biggest movie releases of the year and scammers wasted no time taking advantage of it. Within hours of the film’s release, we found scams targeting people looking for pirated copies. Some used fake browser warnings on piracy sites, while others disguised malware as movie downloads. Some used…

Join us in Vancouver, BC, Canada, September 15-17 for the 2026 PCI SSC North America Community Meeting! The entire payment card industry is invited to come together as a community for important Council updates, insights on industry trends, strategies on best practices, engaging keynotes, and industry expert speakers.
Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys, with most jobs paying only a few cents at a…
Connecting certain LG monitors prompts Windows Update to install an LG app without consent, while the software runs at startup and displays McAfee trial adverts.
Scale Computing, an edge computing and network solutions provider, is expanding deployment options for its edge solutions to include support for AMD EPYC and AMD Ryzen AI processors. SC//HyperCore now supports AMD CPU infrastructure Scale Computing’s SC//HyperCore virtualization suite version 9.7 adds support for AMD CPU-based infrastructure, expanding support for customers and partners and providing…

As AI becomes embedded in customer experiences, internal workflows, and throughout the supply chain, security leaders are being asked to do more than manage risk. They are being asked to help the business make more informed decisions and move faster. At the same time, AI has evolved faster than the programs built to govern it.…
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050. Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic,…
Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on…
Abbott Laboratories, one of the world’s largest healthcare and medical device companies, is investigating two apparently unrelated cyber incidents after confirming unauthorized access to internal systems. While Abbott says there has been no impact on manufacturing, laboratory operations, or patient care, cybercriminal groups ShinyHunters and ShadowByt3$ claim the breaches were far more extensive. Those claims…
Mitel’s new global channel leader says hybrid communications, AI, and stronger partner alignment represent the company’s biggest opportunities for growth as organizations continue modernizing their collaboration environments. Ben Macdonald, who joined Mitel in June as Vice President of Global Channel Go-to-Market, told Channel Insider he plans to focus on simplifying the partner experience while using…
Organizations running WordPress should prioritize installing the latest WordPress security update after public proof-of-concept (PoC) exploits were released for WordPress vulnerabilities that can be chained to achieve remote code execution (RCE). “This is going to hurt. WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers,…
DNS is a critical component for PC networking, searching, and security. If you want to learn how to set it up on Ubuntu-based distros from the command line, here’s how.

2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional…
JadePuffer follow-up campaign deployed ENCFORGE locker built to destroy AI model artifacts
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for assessing AI SOC solutions, including how to validate accuracy, operating models, long-term reliability, and production readiness. […]
SEO is not dead. Here’s how to get cited more often and boost search visibility in AI tools today.
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating. Key takeaways: Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve…
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already…
Any hopes the U.S. held for building an impregnable lead in the technology were dashed by the progress seen at a convention in Shanghai.

Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine. The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and…
Looking ahead just a short time, Apple could hold a powerful position in AI where it most makes sense: deployment. Not only will the company offer up its own AI models for the kind of tasks millions use ChatGPT to do today, but it will provide more sophisticated on-device agentic models to help users get…

Italy’s data protection authority, the Garante per la Protezione dei Dati Personali, fined WINDTRE €1.7 million over “serious data security shortcomings” that let hackers breach its systems twice and exfiltrate personal data belonging to more than 365,000 customers. The regulator opened its investigation after WINDTRE, one of Italy’s major telecom operators, reported two separate data…

Radware, a provider of AI and application security and delivery solutions for multi-cloud environments, has announced a new cloud-augmented protection architecture for DefensePro X, which protects against distributed denial-of-service attacks (DDoS). The new architecture will extend the platform with AI-powered cloud algorithms while keeping traffic inspection and mitigation on-premises. For channel partners, including Radware’s MSSP…

A vulnerability chain has been discovered in WordPress Core that could allow for remote code execution. WordPress is an open-source content management system (CMS) used to design, build, and publish personal and commercial websites. Successful exploitation of vulnerability chain could allow for remote code execution in the context of the affected service account. Depending on…
Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration. Adam Kues of Searchlight Cyber first…
Most tech professionals wouldn’t recommend their own role to someone entering the industry today.

For the latest discoveries in cyber research for the week of 20th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Ernst & Young, a global accounting and professional services company, has disclosed a data breach involving a compromised third-party IT support platform. The exposed support tickets may have contained client documents, tax information,…

At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands’ civilian and…
The $230 Codex Micro sold out before I could buy one, so I turned my Stream Deck+ into a surprisingly capable alternative.
Enterprises are handing AI agents real access to customer records, financial systems, internal documents, and the tools that…

Microsoft has issued a warning about a recent surge in ACR Stealer activity that uses ClickFix-style social engineering to steal credentials, browser data, and sensitive business documents. In a new report, Microsoft researchers detailed two separate campaigns observed between late April and mid-June 2026 that use different execution techniques for the same theft. The campaign…

The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain…

Malware designers have evolved beyond their initial simplicity, becoming more devious in their abilities to access your personal data. Gone are the days of attempting to hack into corporate systems; they are finding it a lot more lucrative to go after private individuals. This malware is of particular interest to those in South Africa as…

Major AI labs are unleashing forward-deployed engineers (FDEs) to try and grab enterprise customers. Large consultancies are dishing out tokens and assembling armies of consultants — both human and agent — to do the same. But smaller firms are in the mix now, as well. AI is helping 28Stone Consulting, a New York-based, 230-person technology…

We have detected several campaigns using fake downloads of games, mods, cracks, and software to spread RenPy Loader. Once installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild and the EtherHiding technique before ultimately delivering Amatera Stealer. Amatera is an infostealer—a type of malware designed to steal sensitive information from an infected…

7-Zip fixed a vulnerability that could let attackers run code by tricking users into opening malicious XZ-compressed archive files. 7-Zip released version 26.02 to address a remote code execution vulnerability in its handling of XZ-compressed data. The flaw, discovered by researcher Landon Peng, can be triggered through a specially crafted archive. If a user opens…

Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said that earlier that week, it identified unauthorized access to some…
F5 fixes critical nginx flaw CVE-2026-42533 that can crash servers and, in some cases, allow remote code execution through crafted HTTP requests. F5 released patches for a critical nginx vulnerability, tracked as CVE-2026-42533 (CVSS score of 9.2), that can allow an unauthenticated attacker to trigger a heap buffer overflow using specially crafted HTTP requests. “heap…

While they’re not as common as reviews for cafes and dry cleaners, reviews have poured into Google Maps by the thousands for the growing network of jails operated by U.S. Immigration and Customs Enforcement. The reviews have come from internet users sharing their often harrowing experiences in the detention facilities. Google then purges these reviews…

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow…

A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other…

Windows 11 now runs on 78.8% of Windows devices after Microsoft ended support for Windows 10 on 14 October 2025, according to Lansweeper. Windows 10 still accounts for 16.9% of devices and no longer receives security updates, leaving newly discovered vulnerabilities unpatched. “There’s a temporary bridge that we need to consider when looking at these…

A new Westcon-Comstor survey found that 87% of channel partners are changing how they plan, procure, and deliver IT infrastructure projects as hardware price volatility and supply constraints continue to disrupt customer deployments. The findings suggest partners are increasingly turning to capacity planning, accelerated purchasing, and vendor changes to keep projects on schedule despite ongoing…
Hugging Face says an autonomous AI agent breached part of its production infrastructure and accessed internal data and service credentials. Hugging Face is one of the world’s leading open-source AI companies. It provides a platform where developers and organizations can build, share, and deploy machine learning and generative AI models. Hugging Face disclosed that an…

Unknown hackers exploited two SonicWall SMA 1000 zero-days to gain root access on VPN appliances before patches became available. Volexity published its findings after conducting an incident response investigation involving a compromised organization whose SonicWall SMA 1000 series VPN appliances were hit with zero-day exploits starting June 22, 2026. The threat actor, which Volexity tracks…

Last week on Malwarebytes Labs: Shark vacuum flaw exposes cameras, home maps and Wi-Fi passwords How to use GitHub safely The backlash against Flock cameras is spreading Security updates available for Adobe, Chrome, Firefox, VMWare, and Zoom Samsung backs down on threat to delete health data Claude for Chrome flaw could let rogue extensions access…

Security operations centers (SOCs) have spent years struggling under the weight of growing alert volumes, expanding attack surfaces, and chronic staffing shortages. Now artificial intelligence is adding a new complication: not just more information, but more machine-generated information that must itself be evaluated. “There is an asymmetry here because you now have to parse through…
1. What is Claude Mythos? Claude Mythos is an advanced AI model developed by Anthropic and is optimized for cybersecurity and healthcare applications. Mythos 5 was originally released in April to a small group of vetted technology partners ahead of a planned wider rollout. Anthropic established Project Glasswing, a consortium that gives limited, controlled access…

Out-of-band vulnerabilities surface when an application quietly reaches out to an external system during an attack, and capturing that traffic calls for infrastructure that many researchers assemble on their own. A new open-source project from Microsoft supplies that infrastructure in a package meant to run inside a private environment. Dusseldorf is an out-of-band application security…

In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk, reset a privileged cloud account,…

In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. “We identified unauthorized access to a limited set of internal datasets…

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below – git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) – Published on July 18, 2026 Dendreo (versions 1.1.3, 1.1.4)…

Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poisoned example teaches a…
ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting started The onboarding process begins with a request for notification permissions, followed…

Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves. Open source AI in 2026, in four numbers. (Source: Mozilla) “Without investment…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
The Pentagon is using a surging budget to avoid choosing between defense-tech startups and old-school contractors.