U.S. and allied officials said companies should start preparing now for a cyberattack that changes how they provide essential services.
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
Security researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human…
How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones
The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications.
Three AI security disclosures, fourteen days: what the warnings signs are telling us
This week, the UK’s AI Security Institute (AISI) published an incident report most organizations would have quietly buried. During a routine cyber…
Apple Challenges UK Demand For Access To Encrypted iCloud Data
Apple is challenging a UK order reportedly requiring access to encrypted iCloud data, reviving a wider dispute over privacy, security, and lawful access.
AI Deception Emerges in Cyber Tests as Agents Target Real People and Systems
AISI found AI agents taking unsanctioned online actions, including social engineering and code attacks, during controlled cyber tests. The UK’s AI…
Apple briefly removes Telegram from App Store over reported CSAM violation
Apple briefly removed Telegram from the App Store over reported CSAM, highlighting moderation failures and the distribution power held by app-store…
OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January…
Apple Seeks Injunction as OpenAI Blames Tech Giant for Security Lapses
Apple seeks an injunction against OpenAI as the companies clash over former employees, confidential hardware files, and internal security controls.
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a…
WhatsApp Users Say They’re Being Locked Out of Accounts by Mistake
Several WhatsApp users say they were wrongly suspended after automated moderation errors, raising concerns about appeals, access, and false positives.
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range…
OnePlus Nord 6 Gets Six Years of Security Updates, Four Android Upgrades
The OnePlus Nord 6 will receive six years of security updates but only four generations of Android upgrades. Here’s how that split could affect app…
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives…
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report.
Securing Branch Networks With Firewalls, VPNs, IDS/IPS, and Identity-Based Access
Branch networks no longer behave like quiet extensions of a single headquarters LAN. They terminate local user traffic, break out directly to the internet…
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
Homeland Security told immigrants that leaving the US would wipe out fines it claims they owe. Now it wants private investigators to find them in their…
Hackers Turned Microsoft Logins, Zoom Events, and Government Websites Into Attack Tools
Cybercriminals spent July 2026 proving that trusted business utilities including Microsoft authentication pages, Zoom event invitations, and official…
Don’t Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT,…
Google Blogger Locked Legitimate Websites After Mistaking Them for Malware
Thousands of Blogger website owners woke up this week to a jarring surprise: their perfectly legitimate blogs had been locked and slapped with a “Malware…
From 2 weeks to 2 minutes: Amazon Cognito launches Provisioned limits for self-service rate limit management
Imagine preparing for your biggest sales event of the year, and you want to ensure your customer identity management service can handle the elevated…
Poison Claude is Selling Cheap AI Tokens Built on Fake Accounts and Free Credits
A shadowy online service called Poison Claude is reselling access to Anthropic’s premium AI models at a significant discount. Researchers suggest that…
Prisma AIRS – Unified Data Protection for Claude
As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers…
IBM’s agentic AI platform is under active attack – patch now
A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA