Microsoft has hailed its success in disrupting EvilTokens, an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscription platform combining account compromise, mailbox analysis, target selection, and fraud preparation. Its dashboard and chatbot centralized access to…
Global Security News
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. […]
Global Security News
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Global Security News
Check Point Fixes a New Actively Exploited Critical Security Flaw
Check Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The security firm bug is already being exploited. Attackers can abuse the flaw without logging in to…
Global Security News
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. […]
Global Security News
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday. The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said. The…
Global Security News
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server…
Global Security News
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. […]
Global Security News
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes…
Global Security News
K-Pop Is Betting on AI and Robots. Will Fans Buy It?
Watch how South Korea’s music industry is embracing robotics and artificial intelligence, even as fans and performers raise concerns.
Global Security News
Salesforce, Microsoft Signal New Enterprise AI Shift
Enterprise AI is moving beyond copilots and experimentation toward redesigning how work actually gets done. In this edition of Channel Insider’s Inside the Headlines, we break down two developments pointing toward that shift: Salesforce and Nvidia’s Koa reasoning model for Agentforce CRM workflows, and Microsoft’s Frontier Playbook for enterprise AI transformation. For channel partners, the…
Global Security News
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.”
Global Security News
Shai-Hulud Attack Nips Cyber-Firm CrowdSec’s GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack.
Global Security News
Reducing shadow IT visibility gaps with Wazuh
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. […]
Global Security News
SoftBank’s $11 Billion Bond Sale Raises the Stakes on OpenAI
Masayoshi Son wants more OpenAI, and SoftBank is turning to the junk-bond market to help finance it. SoftBank Group has launched a $10 billion dollar-denominated bond sale and a €1 billion (approximately $1.15 billion) euro-denominated offering, with proceeds set to help fund the Japanese conglomerate’s next $10 billion investment in OpenAI. The senior unsecured notes…
Global Security News
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
Global Security News
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.” The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud,…
Global Security News
RatHat Android Malware Uses AI to Target Banking Credentials in Real Time
RatHat Android malware uses generative AI to navigate infected devices, steal banking credentials, intercept OTP codes and reinstall itself after removal again.
Global Security News
Review: M5 Ultra Mac Studio: Pure, unadulterated power
I’m old enough to remember when Macs were friendly little machines. While a little underpowered and equipped with some platform-unique foibles, they were really good at some things, highly secure, and had the best user interface of any PC. That was then; this is now. And while the platform is still unique, still highly secure,…
Global Security News
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
Global Security News
Check Point warns of Management Server zero-day exploited in attacks
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. […]
Global Security News
Claude Opus 5.5 delivers Fable 5.1 performance – and costs 40% less
Anthropic’s newest Claude model aims to make frontier AI cheaper, faster, and safer, while giving subscribers more breathing room before those frustrating usage limits kick in.
Global Security News
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in
Global Security News
AI Leaders Are Standing On a Liability Landmine
Plus, Anthropic delays its IPO, and AI agents have trust issues.
Global Security News
MovieReaper Malware Uses The Odyssey Torrents to Infect Users Worldwide
MovieReaper malware spreads through compromised Odyssey torrents, infecting hundreds of victims while using Solana to locate command-and-control infrastructure.
Global Security News
Citing China, President Trump doubles down on hands-off approach to AI regulation
By Derek B. Johnson President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry veterans and spurred calls for more regulatory oversight. In a Truth Social post Monday, Trump dismissed worries from critics that…
Global Security News
Some cheap smart glasses are a security disaster
Apart from the privacy concerns around smart glasses, researchers have found that some cheap brands come with barely any security at all. ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested two inexpensive pairs, costing A$60 and A$110 (around US$42 and US$78), and found more than a dozen flaws across the smart…
Global Security News
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email inboxes across more than 10,000 organizations globally, the company said Tuesday. Acting on federal court order Sept. 15, Microsoft and partners seized 50 websites the phishing-as-a-service used…
Global Security News
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU). […]
Global Security News
Z.ai disables coding assistant feature after flaw exposed enterprise code upload risk
Chinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enterprises over how AI tools handle sensitive source code. The company apologised and said…
Global Security News
The Truth about GET and HTTP Standards, (Tue, Sep 22nd)
On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow “GET” requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do? I did a quick check of a couple of common web…
Global Security News
Aviatrix Launches Quantum Harvest and Decrypt Protection Solution
Aviatrix is launching Harvest and Decrypt Protection, a cloud security offering that combines post-quantum encryption with workload communication governance to help enterprises limit both future quantum decryption risk and the paths attackers can use to exfiltrate data today. The software applies both controls through a single policy and enforcement point across cloud environments. Aviatrix combines…
Global Security News
Secure Your Spot at the 2026 PCI SSC Community Meetings
Don’t miss out – the 2026 PCI SSC Europe Community Meeting is approaching, and the Asia-Pacific Community Meeting is right around the corner! Take advantage of unparalleled networking opportunities, agendas filled with must-know content to bring back to your organization, and insights into the latest developments in global payment security. You can find the agendas…
Global Security News
AMD Reaches $1 Trillion Market Cap as Stock Climbs More Than 180% in 2026
AMD has joined the $1 trillion club after one of the strongest stock rallies in the chip sector this year. Shares of Advanced Micro Devices climbed about 10% Monday to a record intraday high of $615.52, briefly pushing the company’s market capitalization above $1 trillion. The stock is now up more than 180% in 2026…
Global Security News
Chaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-Day
The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher…
Global Security News
Barracuda AI Data Security Targets MSP Governance Gap
Barracuda Networks is targeting a growing AI security and governance gap among smaller organizations with the launch of Barracuda AI Data Security, a new offering designed to give MSPs and resource-constrained IT teams centralized controls to protect and govern generative AI use. The launch comes as Barracuda research shows 44% of senior IT leaders at…
Global Security News
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets
Global Security News
Researchers uncover malware that uses AI to choose its next move
To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the malware, no running it. CAIRN explorer connects malware binaries by metadata…
Global Security News
Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page
Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future victim. According to Cloudscope researchers, the redirect ran for at least 78 minutes, from roughly 7:49pm CT…
Global Security News
Beware these fake websites selling subscriptions to AI assistants
Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes. The sites impersonate AI products with solid reputations, including GPT-6 Astra, DaVinci Resolve, PixAI and OpenCut, in addition to some that no longer exist (such as Omegle, a chat…
Global Security News
Beware these fake websites selling subscriptions to AI assistants
Websites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes. The sites impersonate AI products with solid reputations, including GPT-6 Astra, DaVinci Resolve, PixAI and OpenCut, in addition to some that no longer exist (such as Omegle, a chat…
Global Security News
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, 22nd September 2026, CyberNewswire
Global Security News
AI Incident Response Readiness Lags Behind AI Adoption, ISACA Finds
A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure
Global Security News
Webinar tomorrow: Inside real-world Google Workspace breaches
Tomorrow’s webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. […]
Global Security News
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. […]
Global Security News
Meta Shows AI Agents Aren’t Just For Businesses Anymore
Plus, OpenAI urges Washington to lead global AI-safety standards effort
Global Security News
AI Agents Are Rewriting the Rules of Lateral Movement
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote.…
Global Security News
Okta Blueprint Alliance Targets AI Agent Security
Okta has launched the Blueprint Alliance with AWS, CrowdStrike, Databricks, Docker, Lovable, Proofpoint, ServiceNow, Wiz, and Zscaler to develop a shared architecture for securing and governing AI agents across enterprise environments. The coalition, announced at Oktane in Las Vegas, is focused on making AI agents easier to identify, monitor, contain, and manage across increasingly complex…
Global Security News
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to…
Global Security News
EU Targets AI Data Center Power and Water Use With New Efficiency Labels
Europe’s AI infrastructure boom is about to come with a new metric: how efficiently data centers use power and water. The European Commission has proposed a common rating system requiring data centers with capacity above 500 kilowatts to report information about their energy and water efficiency. The EU-designed label would make facilities easier to compare…
Global Security News
The latest deepfake numbers give CISOs plenty to worry about
AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner. 36% reported the same for a video call. 79% of CISOs surveyed reported at least…
Global Security News
Ireland Fines Google €403 Million for Violating GDPR Location Rules
Google just got a reminder that location tracking requires more than buried privacy controls. Ireland’s Data Protection Commission slapped Google with a €403 million ($462 million) penalty on Monday, ruling that the search giant broke European Union privacy laws by misleading users and mishandling how it tracked their physical whereabouts. The decision marks the watchdog’s…
Global Security News
The next intellectual property thief may sound like your CEO
Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted. CSC surveyed 300 senior executives specializing in intellectual property law during the second quarter…
Global Security News
More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
Global Security News
Network Segmentation Failures Are Expanding the Corporate Attack Surface
Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks
Global Security News
DORA Year Two: Can Your SOC Actually See the Attack?
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is
Global Security News
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it…
Global Security News
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been
Global Security News
New TASK#STOMP Windows Backdoor Enables Continuous Document Theft
TASK#STOMP Windows backdoor uses PowerShell, scheduled tasks and runtime C# compilation to steal business documents and maintain remote access.
Global Security News
CSuite Targets US and EU Organizations with Device-Code Phishing and Remote Access
ANY.RUN researchers investigated CSuite, a phishing and remote-access operation that combines credential theft, Microsoft 365 session hijacking, and the abuse of legitimate management tools. The campaign showed a strong US focus, with 60% of identified victim organizations based in the United States. By blending trusted business services with legitimate remote-access software, CSuite can give attackers…
Global Security News
Proofpoint Stops the Attacks Traditional Defenses Miss in the AI Era
Global Security News
Proofpoint Breaks Down the Divide Between Data Security and AI Security with the Industry’s First Unified Agentic System
Global Security News
Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
Mac security researcher Patrick Wardle says it’s trivial to turn Muse into “the ultimate backdoor.” Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting…
Global Security News
Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)
A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the US, Taiwan, South Korea, and a number of EU countries. CVE-2026-7273 exploitation is part of…
Global Security News
Somewhere in your traffic logs, a bot is doing more than looking
Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, and travel climbed to 30% in a single month. A GET request asks a website for a page.…
Global Security News
AI Drives Surge in Bot and API Threats
Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats
Global Security News
Public PoC Exposes Critical Veeam Agent Privilege Escalation
A Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, not tomorrow. On September 14, 2026, public technical details…
Global Security News
The Closed Quorum: Inside the first reported autonomous AI C2 implant
CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025. This malware is a useful reference example…
Global Security News
Introducing CAIRN: Frontier tracking for AI-integrated malware
A cairn is a marker left behind on a trail, a deliberately placed stack of stones that helps hikers find their way when the path is unclear. Attackers building AI-integrated malware unintentionally (and inevitably) leave behind markers of their own: prompt templates, provider endpoints, API keys, jailbreak terms, and other artifacts embedded throughout their tooling. …
Global Security News
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
A routine Terraform command is becoming an entry point for North Korean hackers targeting developers. TraderTraitor, a DPRK-linked threat actor, is using weaponized infrastructure projects disguised as job interview assignments, with malicious providers that can execute when a candidate runs terraform init. SentinelOne also found the group’s FLATROOF and ROOFDECK macOS backdoors on an Apple…
Global Security News
Another worry for water systems: infostealer exposure
Nearly two of every 10 U.S. water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday. The study from identity risk firm SpyCloud follows months of reports about a wave of cyberattacks hitting targets in the sector, which U.S. government officials suspect are tied to Iran.…
Global Security News
New Windows Defender zero-day blocks Microsoft antivirus updates
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. […]
Global Security News
Researchers used Claude to hack OpenAI
We’ve heard of OpenAI’s AI agents running amok and hacking other companies. Now, a cybersecurity company has turned the tables on the ChatGPT operator by using AI to help hack OpenAI itself. The hack, which also exposed a bug affecting dozens of other major online services, was conducted as security research. OpenAI paid the researchers…
Global Security News
Orkes Conductor RCE Draws Nearly 7,000 Exploit Attempts
A critical remote code execution flaw in Orkes Conductor is under active attack, with Fortinet blocking 6,696 exploitation attempts in seven days. CVE-2026-58138 affects Conductor versions 3.21.21 through 3.30.1 and carries a CVSS v3.1 score of 9.8. An unauthenticated attacker who can reach the workflow API can execute operating system commands without logging in. According…
Global Security News
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. “Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility,” Checkmarx said. “
Global Security News
CISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner Warns
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect
Global Security News
U.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a stack-based buffer overflow that could allow attackers…
Global Security News
The cyber AI parity window now has a deadline
In April, I wrote about what I called the Cyber AI Parity Window. This is the rare period in which defenders and adversaries gained access to the same transformative technology at roughly the same moment. For most of cybersecurity history, advanced offensive capability reached attackers years before defenders could respond with comparable technology. AI changed…
Global Security News
Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions
Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely related developer details. The network includes sites that…
Global Security News
CISA orders feds to patch Zyxel flaw exploited for data theft
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). […]
Global Security News
CISOs can no longer ignore the nation-state threat
Flare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and friction. The goal of CISOs has typically been to get adversaries out of networks as quickly as possible to contain liabilities, while government responders want to remain longer in compromised…
Global Security News
August 2026 Cyber Attacks Statistics Infographic
A one-page visual briefing on August 2026’s global cyber attack landscape: 218 confirmed incidents, a rising four-in-five share driven by profit-motivated crime, and a back-to-back spike that delivered 34 attacks in just two days.
Global Security News
August 2026 Cyber Attacks Statistics
August 2026 statistics report breaks down 218 confirmed cyber incidents by motivation, attack vector, initial access technique, and target sector. Financially motivated Cyber Crime drove more than 4 in 5 attacks, Malware remained the weapon of choice, and Information & Communication infrastructure bore the brunt of targeting across 70 countries.
Global Security News
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. “SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,” Trellix researchers
Global Security News
Contagious Interview: 30,000 devices infected by a fake job interview
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…
Global Security News
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words…
Global Security News
A cheap fake base station can still track 5G subscribers
Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks. On the standalone-5G networks they tested, operators concealed the phone’s permanent identity correctly in every…
Global Security News
California joins US states clamping down on data center gold rush
The state of California has joined the growing number of governments and communities at all levels across the US taking proactive, even preemptive, measures to keep data center development under control. California Governor Gavin Newsom signed what he called the “most comprehensive data center laws in the nation” on Monday. While the seven bills don’t…
Global Security News
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed “Comment2Shell,” on September 17 in version 7.1.1 and told site owners to…
Global Security News
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating
Global Security News
Dragos Acquires NetRise and runZero to Expand its Industry Defining xOT Cybersecurity Platform
With the close of Accenture’s majority investment, Dragos extends to exposure management and software supply chain security, Robert M. Lee is named Chairman in addition to CEO
Global Security News
A10 Networks Launches A10 AI Gateway, an Intelligent Control Plane for Unified Management of All AI Operations
Centralises AI model visibility, cost management and governance to support secure AI adoption within customer environments
Global Security News
F5 positioned as Market Shaper in the Gartner Emerging Market Quadrant for AI Application Security
To us, the recognition underscores F5’s ability to secure AI across cloud, on-premises, and air-gapped environments at enterprise scale
Global Security News
Lenovo Modernises Virtualisation Infrastructure for an AI-Ready Future
New ThinkAgile Infrastructure, Expanded Lenovo Express Solutions and Deployment Services Give Customers Greater Choice, Resilience and Control.
Global Security News
Fastly Extends Real-Time Edge Control to AI
New capabilities govern AI requests, protect AI applications, and enforce agent access on Fastly’s unified platform
Global Security News
Australia leads APAC in AI ROI, despite widest confidence gap
Notion appoints Tom Karemacher as ANZ General Manager to close the AI confidence gap as 61% of decision makers express high confidence in their organisation’s AI capabilities,…
Global Security News
Sovereign Australian Prime Alliance welcomes Government ambition to build Australian sovereign defence primes
The Sovereign Australian Prime Alliance SAPA has welcomed Defence Industry Minister Pat Conroy’s vision to develop Australian-owned prime contractors capable of standing…
Global Security News
Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit
By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable for infringements — a detail that tends to concentrate executive attention. ENISA’s 2025 NIS Investments report found that 34%…
Global Security News
From Payment Plan to Ransomware – Inside a Global Group Attack
By: Iris Suaner, Cofense Phishing Defense Center Highly sophisticated ransomware now targets industries worldwide. Today’s ransomware allows threat actors to infiltrate networks, encrypt confidential data, and hold critical systems hostage until a cryptocurrency ransom is paid. Worse, threat actors often employ “double extortion” techniques by stealing sensitive company data and threatening to publish data publicly…
Global Security News
European AI spending is on track to reach nearly $470 billion by 2030
European organizations will spend nearly $470 billion on AI in 2030, IDC forecasts, with spending growing at a compound annual rate of 35% from 2025. At that rate, the market more than quadruples in five years. Generative AI will account for 55.4% of the total by 2030. agentic AI is the main driver. Companies are…
