A one-page visual summary of the 16–31 August 2026 cyber attacks timeline: 110 incidents broken down by motivation, attack technique, initial access vector, targeted sector, and country — Cyber Crime and Malware led the period, with Information & Communication the hardest-hit sector.
Global Security News
16-31 August 2026 Cyber Attacks Timeline
The second half of August 2026 brought 110 confirmed cyber incidents, with Cyber Crime once again the dominant motivation at 78% of attacks. Malware remained the weapon of choice, exploitation of public-facing applications (T1190) continued to lead initial access, and Information & Communication emerged as the hardest-hit sector. This timeline breaks down the period by…
Global Security News
Facing Outraged Residents, Flock Got Help From Group That Uses AI to Rally Public Support
The debate over Flock cameras in Knoxville, Tennessee, had reached a fever pitch this July when a stay-at-home mom received a text message from a nonprofit group she had never heard of. The group, Neighbors for Strong Communities, asked Ashley Smith to speak out in support of Flock’s controversial license-plate readers. The nonprofit even offered…
Global Security News
Samsung Fans Are Thoroughly Unimpressed by Apple’s Foldable Phone
The Korean company and its devotees are mocking Apple for hyping a product they’ve had for years.
Global Security News
The Startup That Built OpenAI’s Biggest Data Center Is Now Making Tiny Ones
Crusoe raised $3.9 billion at a valuation of nearly $31 billion, as it bets on factory-built data centers.
Global Security News
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. […]
Global Security News
Spain reports first data breach involving autonomous AI agent
Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company’s network, found a way to alter personal records, and pulled invoice data. “Before drawing any conclusions, it should be noted that the available information comes from the…
Global Security News
NEXTDC, Vertiv and Partners win Innovation Award at inaugural Data Centres Australia Excellence Awards
Vertiv a global leader in critical digital infrastructure, and NEXTDC have won the Innovation Award at the inaugural Data Centres Australia Excellence Awards for the NEXTDC AI…
Global Security News
16 governance tools for securing your AI fleet
Every DevOps team member knows that dealing with an AI is like being a circus lion tamer. The boss and the audience are happy when the lions sit on the pedestal and roar on cue, but there’s always the danger that they’ll go rogue and bring the whole show to a quick and disastrous end.…
Global Security News
AI Agent Carries Out Multi-Stage Data Theft Attack
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach
Global Security News
Microsoft shares workaround for Windows domain login issues
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. […]
Global Security News
How MSSPs Can Prove Their Value When “Nothing Happened”
For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business disruption. But it can also create an awkward conversation with the client: What exactly did we pay for this month? The problem is not that the SOC did nothing. Quite the opposite. Analysts may have…
Global Security News
Fake AI trading agent steals crypto wallet passwords
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who download AI agents from…
Global Security News
Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution
Choosing an enterprise threat intelligence solution is about more than just data volume or integrations. The right provider should deliver relevant intelligence, fit existing workflows, and help security teams investigate threats faster. While SOCs may prioritize rapid investigation and enrichment at scale, MSSPs may focus more on multi-tenancy and customer separation. This enterprise threat intelligence…
Global Security News
Chosen Brick, Iran’s Surveillance Malware
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the…
Global Security News
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. […]
Global Security News
Are Australian organisations adopting AI faster than they are building workforce capability?
ConnectOS report reveals AI adoption is accelerating across Australian organisations, but workforce capability, governance and skills development risk falling behind.
Global Security News
The Blueprint for Operational Resilience: Navigating the Post-CPS 230 Reality
In this post, I will give you the blueprint for operational resilience by navigating the Post-CPS 230 reality. Data-breach notifications in Australia hit an all-time high in 2025, with a significant majority stemming from malicious attacks. In parallel, the Australian Prudential Regulation Authority’s (APRA) CPS 230 Operational Risk Management standard officially took effect in July…
Global Security News
Riverbed NPM 360 uses AI to predict and prevent network disruptions
Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict emerging issues and increasingly prevent disruptions before they impact users. The new Riverbed Network 360 offerings natively integrate the powerful agentic AI capabilities of Riverbed IQ and…
Global Security News
Tuskira Vector brings autonomous red teaming to attack surface validation
Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization’s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization’s deployed compensating controls, the internal risks already reported by its security tools, and the architecture of its application and infrastructure…
Global Security News
The AI security question leaders should be asking instead
In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter for AI agents. It also looks at how…
Global Security News
A flat cybersecurity budget doesn’t have to mean weaker coverage
Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. Her advice is to stop trimming every line by the same percentage. Instead, sort each security expense…
Global Security News
AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions
New AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a “project” where AWS and coding agents set up permissions automatically. Paid projects get a monthly spend limit, starting at $20, and a project that reaches its limit is halted instead…
Global Security News
GNOME 51 adds passkey logins, offline maps and drawn PDF signatures
GNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coruña. The release adds offline maps and live transit information to Maps, new login options at the login screen, hand-drawn signatures in the Papers document viewer, and smoother animations when the system is under load. Fedora 45…
Global Security News
AI is adding to the review load on open-source projects, many of them thinly funded
AI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery’s Technology Policy Council, among them Simson Garfinkel and Josiah Dykstra. The tools write code and find security flaws quickly. The maintainers who decide what enters a project’s official release still have…
Global Security News
Atturra Delivers Next-Generation Network Incident Management System for Powerlink Queensland
Powerlink and Atturra named as finalists in the 2026 SAP Best Tech Awards for Best Tech SAP Industry Disruptor
Global Security News
Riverbed Brings Powerful Agentic AI and 360-Degree Visibility to Network Operations
New Network 360 Offerings Combine Deep Network Evidence, AI and Extended Network Visibility, Helping NetOps Teams Eliminate Disruption
Global Security News
Hitachi Vantara Commits to Net-Zero Greenhouse Gas Emissions by FY2040, With SBTi-Validated Targets
SBTi independently validates near- and long-term science-based targets Near-term targets align with a pathway to limit warming to 1.5 degrees Celsius Commitment builds on…
Global Security News
Splunk declares transformational shift as AI agents reshape enterprise IT
Splunk has made a number of announcements this week that has been described by executives as transformational rather than incremental.
Global Security News
Horizon3 Announces Integration with CrowdStrike Falcon Next-Gen SIEM
Horizon3 today announced a new integration that enables validated Horizon3 NodeZero platform findings to flow into CrowdStrike Falcon Next-Gen SIEM
Global Security News
Smart Communications Posts Record Growth as Businesses Prioritise Modern Customer Engagement
Record bookings growth, strong customer retention, industry recognition, and strategic leadership appointments underscore growing demand across regulated industriesGU2
Global Security News
The world must establish red lines for autonomous AI weapons
AI is transforming warfare and international conflict. Autonomous weapon systems pose a genuine threat to civilians. The war in Ukraine has become a proving ground for weapons that can navigate, identify targets, resist electronic countermeasures, and pursue and engage targets autonomously without the need for human control. That evolution should concern technology professionals, regulators, policymakers,…
Global Security News
Nozomi Networks Introduces Nozomi Compass to Modernise the Everyday Work of OT Asset and Service Management
Pairs the industry’s deepest first-party OT asset data to guide OT-safe change and remediation workflows Delivers continuous compliance evidence, safer change governance, and…
Global Security News
HubSpot and OpenAI deepen partnership to bring AI transformation to every SMB
HubSpot, the agentic customer platform for scaling businesses, today announced the launch of the first CRM integration with ChatGPT Ads for customers to build, manage and…
Global Security News
ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Global Security News
HubSpot unveils its most foundational product update, helping organisations put AI context to work for better growth outcomes
New data finds that when AI is fueled by high quality context, businesses using HubSpot can create 3.6x more qualified leads and win 3.2x more deals.
Global Security News
Cloudflare Helps End the Search-or-AI-Training Tradeoff
New controls and recommended settings go live today, allowing publishers and businesses to independently control how their content is used across search, AI training, and AI…
Global Security News
Merlin Entertainments Elevates the Guest Experience Across Its Global Attractions with NiCE Cxone
Across LEGOLAND Resorts, Madame Tussauds, and more, NiCE’s CX AI platform is making every stage of the guest visit, from ticketing to reservations, feel effortless
Global Security News
UTS partners with Nexon Asia Pacific on $20 million-plus network modernisation
The University of Technology Sydney UTS has partnered with Nexon Asia Pacific Nexon on a $20 million-plus refresh of the network and Wi-Fi across every UTS campus. The…
Global Security News
Nutanix Recognised Across Three 2026 Gartner Magic Quadrant Reports
Nutanix has been recognised across three 2026 Gartner® Magic Quadrant™ reports: Distributed Hybrid Infrastructure, Server Virtualisation and Container Management.
Global Security News
Splunk expands AI security workforce to enable autonomous defence at machine speed
To combat the growing threat of AI-led attacks Splunk is expanding its Agentic SOC Workforce to enable organisations to defend autonomously, block attacks at the source and…
Global Security News
Salesforce’s massive outage exposes the hidden risks of cloud dependencies
While its flagship Dreamforce event was in full swing on Wednesday, Salesforce was triaging a roughly seven and a half hour-long service outage that disrupted user access and caused “severe delays” and intermittent errors. Some customers were also unable to submit new support cases. The service outage hit at 3:50 a.m. EDT, impacting “multiple instances…
Global Security News
SUSE Brings Real-Time Enterprise Linux to LF Energy SEAPATH to Advance Virtualised Digital Substations
In collaboration with Savoir-faire Linux, SUSE becomes the first enterprise Linux vendor to deliver validated, real-time operating system support for the open source SEAPATH…
Global Security News
The Anonymous Math Geek Who Quit Anthropic—and Became the Face of AI Safety
Long-simmering worries about the technology’s potential dangers have exploded into the global consciousness since Jacob Coxon’s dire warning.
Global Security News
Exabeam Research: Security Leaders Identify AI Agent Access as a Top Insider Risk Priority
Nearly half rank AI agents operating with excessive‚ compromised‚ or unintended access as the greatest threat to their organisations, while behavioural context and…
Global Security News
ExpressVPN Launches Fortify VPN Router With GL.iNet For High-Performance Home Protection
Fortify evolves ExpressVPN’s router offering onto GL.iNet’s higher-performance Flint 2 platform, with 12 months of ExpressVPN’s Advanced plan included for new and returning users.
Global Security News
Rubrik Adds New MCP Support to Expand Access to Agentic Cyber Resilience
Powered by Claude, Rubrik AI Now Used by One Third of Global Customers
Global Security News
Citadel Edge backing sovereign AI for growth
Todd Trevillion is accustomed to changing tack. He is quite an accomplished sailor for one. And back in 2020 he had not been at the Citadel Group long when the ASX-listed…
Global Security News
Expanded NVIDIA partnership enables Splunk to bring agentic AI to sensitive machine data
Splunk Enterprise customers will be able to run accelerated, agentic AI directly on sensitive machine data in their own environments rather than being constrained by the need…
Global Security News
Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called “Claude Money” that will allow you to connect your bank accounts directly to Claude and “understand your money.” […]
Global Security News
DigiCert research finds certificate failures are a six-figure infrastructure risk
Nearly one in ten Australian organisations reported that their most significant certificate incident cost more than $250,000.
Global Security News
Inside the White House Tussle to Sway Trump on AI
Senior administration officials have gathered almost daily in recent months to plot potential guardrails.
Global Security News
In Search of the Best iPhone Data Recovery Tool
We live our lives through our phones, keeping everything from grocery lists to photos of our kids locked inside it. However, a glitch with a third party app, a bad software update or an accidental tap can wipe away years of memories in less than a second. When that happens, the standard backup options from…
Global Security News
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Researchers wanted to test if LG’s smart TVs come with any security risks – but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can’t be legally bound to a contract you…
Global Security News
Salesforce Debuts Koa, a CRM Reasoning Model Built on Nvidia’s Nemotron
Yesterday, Salesforce and Nvidia announced Koa, Salesforce’s first CRM reasoning model for Agentforce. Built on Nvidia’s post-training Nemotron 3 Super, Koa is designed to handle multistep CRM tasks such as updating sales opportunities, routing support cases, and scheduling follow-ups. Salesforce built the model using a proprietary synthetic dataset based on nearly three decades of CRM…
Global Security News
OpenAI Shares More Safety Incidents and Adopts New Rules for Reporting Them
The company said it hopes to inspire competitors to greater transparency as public fears about AI dangers mount.
Global Security News
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
Global Security News
Architecting a secure landing zone in the AWS European Sovereign Cloud
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and…
Global Security News
Salesforce Global Outage Hits Customers on Second Day of Dreamforce
Salesforce’s biggest annual conference was in full swing when customers around the world began struggling to access parts of its cloud platform. The Sept. 16 outage, which struck on the second day of Dreamforce 2026, affected Salesforce instances across multiple regions. Customers experienced severe delays, intermittent errors, and service outages as engineers investigated issues with…
Global Security News
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. […]
Global Security News
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. […]
Global Security News
CISA promotes a fresh way to deter cyberattackers: Lie to them
For the first time, the Cybersecurity and Infrastructure Security Agency is advising critical infrastructure owners and operators on how to set up phony systems, accounts and data to deceive would-be hackers into being distracted and discovered. The Wednesday guidance, “Using Cyber Decoys to Strengthen Detection and Response,” arose from internal discussions with CISA’s threat hunters…
Global Security News
BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control…
Global Security News
Samsung Backs Dutch AI Chipmaker Euclyd in $231M Series A Round
Nvidia’s AI chip empire has another challenger. Dutch startup Euclyd has raised more than €200 million ($231 million) in Series A funding to develop AI chips designed specifically for inference, the stage where trained models process requests and generate responses. Samsung co-led the round with Somerset Capital Partners, EQT’s Scaleup Europe Fund and Innovation Industries.…
Global Security News
What MSP Growth Looks Like After 130 Customers
Managing more than 130 customers and thousands of endpoints created a new problem for Aligned Technology Partners: the work required to run the MSP was consuming resources it needed to keep growing. For President Brian Davis, reaching that scale has meant relying more heavily on partners such as Sherweb to handle some of the complexity…
Global Security News
LinkedIn fights for the right to tell customers when the feds want their data
Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is…
Global Security News
LinkedIn fights for the right to tell customers when the feds want their data
Microsoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US government, which sometimes come with secrecy orders that prevent LinkedIn from alerting customers whose information is…
Global Security News
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. […]
Global Security News
Scans Targeting Hospitality Applications, (Wed, Sep 16th)
Earlier today, I noted an odd request showing up in our “First Seen” report: GET /PIAF-HMS/ HTTP/1.1 Host: [redacted] User-Agent: Farez-Sorter/1.0 Accept-Encoding: gzip This request is linked to a rather old application, a “PBX in a Flash Hospitality Management System” [1]. The last update, the addition of a license file, happened 10 years ago, and I would…
Global Security News
Data Broker Radaris Loses Domains in Privacy Fight
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal…
Global Security News
Fighting Your Dragons Through Tough Tech Times
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
Global Security News
I recommend you don’t run these appliances on your power station – even if you can
Using a power station for backup is ideal, but not with these appliances.
Global Security News
Spain’s data agency gets first report of AI-powered data breach
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). […]
Global Security News
Spain reports first alleged AI-powered data theft attack
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). […]
Global Security News
BragJack Attack Can Turn a Browser’s Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
Global Security News
Goodbye, Claude Cowork: Anthropic merges its two Claudes into one
From Claude to Cowork and back again – plus, Anthropic’s all-new Claude Docs.
Global Security News
How September’s Pixel Drop changes the way you call and message important contacts
The update lets you contact VIPs with a tap and adds scam protection.
Global Security News
Big Tech’s AI safety rift signals disruption and disparity for enterprises
A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems. The latest flashpoint came after Meta CEO Mark Zuckerberg called for neutral evaluators to independently test AI models, pushing back on…
Global Security News
Big Tech’s AI safety rift signals disruption and disparity for enterprises
A growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems. The latest flashpoint came after Meta CEO Mark Zuckerberg called for neutral evaluators to independently test AI models, pushing back on…
Global Security News
Forget the AI Apocalypse—the Real Threats Are Already Here
Airplanes, elevators and restaurants all have regulations to ensure their safe operation. Many experts argue for similar conventional measures for AI.
Global Security News
AWS bets that AI agents need an inbox, not another chat window
AWS is betting that AI agents need a different interface as they move beyond answering prompts and start working autonomously in the background. The company has open-sourced Pizza Bot, a self-hosted application that gives users an inbox for managing work delegated to AI agents, with separate threads for ongoing tasks and a queue for work…
Global Security News
What CEOs Really Think About the AI Apocalypse Threat
At a private gathering in Washington this week, dozens of business leaders cited the AI safety threats as real, urging President Trump to work with China’s Xi Jinping.
Global Security News
Oracle’s September patches put Fusion Middleware back in the hot seat
Oracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suite vulnerabilities and 78 Fusion Middleware vulnerabilities can be remotely exploited without authentication. Other…
Global Security News
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
Global Security News
HYPR Finds Security Gaps as Hiring Fraud Rises
HYPR research found that hiring fraud is nearly universal among the HR leaders it surveyed, with 98% reporting encounters with candidate fraud even as 96% said they believed their organizations would catch it. The bigger security concern is how those fraudulent hires are being found: 68% are ultimately uncovered through human observation and intuition after…
Global Security News
AI agent authorization risks remain a gap in new NIST-CISA token security guidance
AI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike. “Protecting Tokens and Assertions from Forgery, Theft, and Misuse,” a new report from the National Institute of…
Global Security News
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques…
Global Security News
Apple just gave every iPhone photo a digital alibi
The fight against AI slop is real, even in photography, which is why Apple introduced its Reference Image tech alongside its new iPhones. This shifts image verification to the moment of capture, creating a privacy-preserving digital negative that could help newsrooms, businesses, and individuals prove that images are real. Apple’s Security Research team just shared a white…
Global Security News
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
Global Security News
The 24 New Rules for Making Work Better
Plus, the Big Law talent wars and spending habits of Silicon Valley’s newly minted AI millionaires.
Global Security News
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint statement from the agencies Wednesday. The “joint offshore security boardings” of the two commercial ships in the Gulf of Mexico on Aug. 21 and Aug. 24 “were designed…
Global Security News
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product’s built-in AI with a single click. On…
Global Security News
Treasury’s Scott Bessent says no liability exemptions for AI labs
The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop.
Global Security News
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]
Global Security News
CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
Global Security News
Google Patches Pixel Modem Zero-Day Exploited in Targeted Attacks
Google has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a high-severity flaw, tracked as CVE-2026-58704 (CVSS score of 8.0), in the cellular modem that has…
Global Security News
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
Global Security News
66% of financial services IT leaders keep finding AI they never approved: Jay Tuseth on sovereignty debt and who ends up paying it down
Two thirds of financial services IT leaders have walked into AI tools and agents their own staff spun up without asking, and 86% say that creates business risk. Nutanix APJ…
Global Security News
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can’t Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the…
Global Security News
Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure. Revolut has confirmed that its systems were not breached. Instead,…
