2026-07-09
- ransomware
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
Angelo John Martino III, a ransomware negotiator at DigitalMint, was sentenced to 70 months in prison for conspiring with BlackCat affiliates to extort $75.3 million from five U.S. companies he was hired to help during ransomware incidents. Martino shared confidential negotiating positions and insurance policy limits with his co-conspirators to maximize ransom demands, effectively playing both sides of negotiations between April and September 2023. His co-conspirators, including fellow DigitalMint negotiator Kevin Tyler Martin and Sygnia incident response manager Ryan Clifford Goldberg, received four-year sentences for their roles in deploying BlackCat ransomware against additional victims.
Why it matters: Ransomware victims and negotiation firms need to understand that insider threats from negotiators with access to sensitive client data pose a severe risk, requiring stronger vetting, access controls, and separation of duties to prevent co-conspirators from exploiting confidential negotiating positions and insurance information.
- breaches incidents
OpenMandriva Linux says contributor tried to sabotage the project
OpenMandriva Linux project reported an attempted sabotage incident stemming from a dispute between contributors. The project disclosed the incident publicly and took steps to address the internal conflict.
Why it matters: Open source project maintainers and users should monitor for similar internal threats to critical infrastructure projects, as compromised build systems or repositories could distribute malicious code to downstream users.
- threat intel
Iran's Cyber Crosshairs Focus Beyond Critical Infrastructure
An article discussing how Iranian threat actors are expanding their targeting beyond critical infrastructure to broader internet-facing systems. The piece emphasizes that obscurity provides no protection against multiple concurrent threats.
Why it matters: Security teams at any organization with internet-facing assets should assume Iranian threat actors may probe their infrastructure, regardless of whether they operate critical systems, and need robust vulnerability management and threat detection capabilities.
- threat intel
Injective SDK on npm infected with cryptocurrency wallet stealer
Hackers compromised the Injective Labs SDK repository on GitHub and published a malicious package to npm that targeted cryptocurrency wallet credentials, specifically private keys and mnemonic seed phrases. The attack exploited the trust developers place in open-source dependencies to distribute wallet-stealing malware.
Why it matters: Developers using the compromised Injective SDK package face immediate risk of cryptocurrency wallet theft; practitioners should audit npm dependencies and check for the malicious package version in their supply chains.
- identity access
AI Agents Are a New Kind of Identity & Most Organizations Aren't Ready
Security organizations are applying traditional identity management approaches to AI agents, treating them like service accounts or API tokens, but experts argue this misses critical distinctions in how AI agents operate and should be governed. The gap between current practices and required controls suggests most organizations lack adequate frameworks for managing AI agent identities and access.
Why it matters: Security teams managing AI agent deployments need to understand that legacy identity and access management (IAM) tools and policies are insufficient, requiring new governance models to prevent unauthorized access and credential compromise.
- vulnerabilitiesCVE-2026-12485CVE-2026-12486
WolfSSL, GeoVision, VTK vulnerabilities
Cisco Talos disclosed three vulnerabilities in WolfSSL (two improper input validation issues and one integer underflow), fourteen advisories covering 37 CVEs in GeoVision's camera and monitoring solutions (spanning memory corruption, command injection, buffer overflow, privilege escalation, and authentication issues), and one heap-based buffer overflow in VTK-DICOM. All vulnerabilities have been patched by their respective vendors, and Snort rules are available for detection.
Why it matters: Organizations using WolfSSL for embedded security, GeoVision for surveillance and access control, or VTK-DICOM for medical imaging should prioritize patching these vulnerabilities to prevent remote code execution, privilege escalation, and authentication bypass attacks affecting their operational infrastructure.
- threat intel
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
Datadog Security Labs identified multiple coordinated campaigns systematically enumerating GitHub organizations, repositories, and user accounts via the GitHub API. The attackers use automated scraping tools with legitimate-appearing user agents and leverage dormant ghost accounts or compromised OAuth tokens to avoid detection while conducting reconnaissance.
Why it matters: Any organization with public or private GitHub repositories faces reconnaissance risk from attackers mapping corporate structures and code repositories; security teams should review GitHub API access logs and monitor for unusual enumeration patterns.
- ransomware
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft identified a Windows backdoor called GigaWiper that combines three destructive capabilities: disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving decryption keys. The malware operates as a modular tool, allowing operators to select which destructive method to deploy on compromised machines.
Why it matters: Windows administrators and defenders need to detect and block GigaWiper to prevent irreversible data destruction and system failures on infected endpoints; understanding its modular structure helps with hunting and containment strategies.
- ai security
Microsoft expects more Windows security updates from AI-discovered flaws
Microsoft reports that it will issue more Windows security updates going forward, driven by its expanded use of artificial intelligence to identify vulnerabilities in its codebase. The company expects this approach to uncover flaws that traditional methods might miss, resulting in higher patch volumes for Windows users.
Why it matters: Windows administrators and security teams should prepare for increased patch management overhead and testing cycles as Microsoft's AI-driven vulnerability detection generates more updates to deploy and evaluate.
- vulnerabilities
npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk
npm version 12 disables install scripts by default to mitigate supply chain attacks, and deprecates granular access tokens that could bypass two-factor authentication. These changes shift security-sensitive operations from automatic execution to opt-in workflows, requiring developers to explicitly enable script execution during package installation.
Why it matters: JavaScript developers and DevOps teams using npm must update their CI/CD and local build processes to accommodate the new default, as package installations will no longer automatically run scripts that some dependencies may require.
- cloud saas
How ProdSec uses Wiz
This article appears to be promotional content about how Wiz, a cloud security platform, supports product security workflows. The piece lacks substantive details about specific capabilities, findings, or actionable insights for practitioners.
Why it matters: Product security teams considering cloud security tooling may find vendor perspectives relevant, but this content provides no concrete evaluation criteria or comparative data to inform decision-making.
- research
Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense
Verizon's Data Breach Investigations Report (DBIR) examines how attackers exploit common weaknesses with accelerating speed and scale. Wiz research contributes insights on vulnerabilities, trust relationships, and artificial intelligence (AI) in cloud environments. The analysis suggests that AI adoption and cloud expansion are reshaping the threat landscape for defenders.
Why it matters: Security practitioners need to understand how attackers are accelerating exploitation of known weaknesses and abusing trust relationships in cloud environments to prioritize detection and remediation efforts.
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
A news roundup titled ThreatsDay covers multiple security stories including cloud bucket hijacking, a Windows local privilege escalation chain, and a global fraud investigation. The piece emphasizes that many security breaches stem from common administrative oversights and misconfigurations rather than sophisticated attacks.
Why it matters: Security practitioners need to review this week's threat digest to identify which stories affect their infrastructure and threat model, particularly stories involving cloud storage misconfigurations and Windows privilege escalation exploits that may require immediate patching or access control reviews.
- industry
QIZ Security Raises $17 Million for Cryptographic Governance Platform
Israeli startup QIZ Security has raised $17 million in funding for a platform that manages cryptographic posture and post-quantum cryptography governance. The platform appears designed to help organizations assess and manage their cryptographic infrastructure as they prepare for quantum-resistant algorithms.
Why it matters: Security teams responsible for cryptographic asset inventory and post-quantum migration need to evaluate emerging tools as the transition to quantum-safe cryptography becomes an industry priority.
- threat intel
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
In October 2025, Microsoft Threat Intelligence identified GigaWiper, a Golang-based backdoor that combines command-and-control capabilities with multiple destructive payloads including disk wiping, fake ransomware encryption, and system sabotage. The malware is notable for consolidating code from separate malware families—a standalone wiper, Crucio ransomware, and FlockWiper—into a single modular implant that allows threat actors to select their destruction method on demand. This represents a shift in wiper tactics toward operational efficiency by merging standalone tools into unified platforms that reduce deployment footprint while expanding destructive capabilities.
Why it matters: Organizations and defenders need to identify and contain GigaWiper infections immediately, as the backdoor's multiple destructive modules can render systems and storage unrecoverable; detection and mitigation recommendations are available from Microsoft Defender.
- threat intel
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
A new phishing-as-a-service platform called Forg365 targets Microsoft 365 accounts using adversary-in-the-middle and device code methods combined with AI-generated phishing lures to increase effectiveness and evasion.
Why it matters: Microsoft 365 administrators and users face increased phishing risk from a sophisticated, commercialized threat; practitioners should review email filtering, conditional access policies, and user training to defend against AI-assisted account compromise.
- threat intel
764 splinter group leader sentenced to 40 years in jail
A 19-year-old San Antonio man who led 8884, an offshoot of the extremist collective 764, was sentenced to 40 years in prison for sexually exploiting children through coercion, blackmail, and production of child sexual abuse material. Chavez, who joined 764 as a child in 2022, participated in a sprawling network of mostly adolescents engaged in sextortion, self-harm coercion, and animal torture targeting vulnerable minors. Federal prosecutors highlighted 764's mission to foster social unrest by corrupting children and emphasized the need for parental oversight of online activities.
Why it matters: Law enforcement, child safety advocates, and parents need to understand that 764-affiliated groups systematically recruit and exploit minors for extremist purposes, with reoffending rates high among graduates of the network; courts and jurisdictions must treat these cases with appropriate severity and ensure supervision of convicted members to prevent future victimization.
- threat intel
As Global Conflicts Go Digital, Businesses Need Wartime Gameplans
A Ukrainian tax software company became a casualty of digital wartime operations, illustrating how cyberwarfare extends beyond direct military targets to affect civilian businesses. The incident demonstrates that organizations globally, even those geographically distant from conflict zones, face heightened cybersecurity risks and need contingency planning for such scenarios.
Why it matters: All businesses should evaluate their exposure to supply chain disruptions and nation-state cyber activity linked to global conflicts, and establish incident response plans for wartime-related threats.
- ransomware
Latvian forestry company still restoring systems weeks after ransomware attack
A financially motivated foreign group carried out a ransomware attack on Latvijas Valsts Mezi (LVM), Latvia's state-owned forestry company, and the organization was still in recovery weeks after the incident.
Why it matters: Organizations operating critical infrastructure or managing national resources should assess their incident response and recovery capabilities, as extended downtime from ransomware can disrupt operations and service delivery.
- ai security
The Hidden Security Risks of Reduced Summer IT Coverage
IT staffing typically decreases during summer vacations while security threats remain constant. The article discusses how AI-driven automation can help organizations maintain consistent security operations and reduce dependency on manual processes throughout the year.
Why it matters: Security practitioners managing lean summer teams should evaluate automation and AI tools to prevent coverage gaps that attackers may exploit during reduced staffing periods.
- identity access
Conditional Access Misconfigurations Exposed 55 Orgs with MFA On
Two organizations experienced successful attacks against Microsoft 365 systems despite having Conditional Access policies and multifactor authentication (MFA) enabled, suggesting configuration gaps in their policies. Huntress Managed ISPM identified these misconfigurations and found the issue affected 55 organizations. The article highlights how standard conditional access controls can fail when improperly configured.
Why it matters: Security teams relying on Conditional Access and MFA as primary defenses need to audit their policy configurations immediately, as these controls can be bypassed through misalignment of rules that appears secure on surface review.
- regulatory
A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway
European lawmakers rejected a proposal to restrict tech companies' scanning of private messages for child abuse material, but companies intend to proceed with these surveillance practices anyway. The Chat Control bill enables automated scanning of personal communications across text, email, and social media platforms.
Why it matters: Organizations operating in Europe face regulatory and reputational risk as privacy advocates, policymakers, and users oppose message scanning, while compliance gaps between legislative intent and corporate implementation could trigger enforcement action or legal challenges.
- industry
Citrix launches MCP Gateway to secure enterprise AI agents
Citrix announced new MCP Gateway functionality for its NetScaler platform that enables enterprises to securely route, govern, and observe traffic to Model Context Protocol servers. The update also includes enhancements to NetScaler AI Gateway for improved model routing and token-level usage tracking on large language model traffic.
Why it matters: Enterprise security teams need tools to manage and monitor AI agent traffic alongside LLM traffic; this update provides centralized governance from a single platform and dashboard.
- vulnerabilities
Palo Alto Networks Patches 13 Vulnerabilities
The company patched 13 vulnerabilities in PAN-OS software, including buffer overflow, denial of service, command injection, server-side request forgery (SSRF), and authentication bypass issues.
Why it matters: Palo Alto Networks customers running PAN-OS must evaluate and apply these patches to their firewall deployments to prevent exploitation of these flaws.
- ai security
Vectogate debuts platform to secure and govern autonomous AI agents
Vectogate launched an AI governance platform that provides centralized control and oversight of autonomous AI agents accessing sensitive data and internal business systems. The platform addresses enterprise governance challenges as AI agents take on increasingly autonomous roles, with private beta access available now.
Why it matters: Security practitioners overseeing AI deployments need governance solutions to control autonomous agents accessing sensitive data and systems; this platform offers early access to evaluate centralized oversight capabilities.
- government policy
NSA revives 'Tailored Access Operations' name for elite hacking unit
The National Security Agency (NSA) has renamed its Office of Computer Network Operations back to Tailored Access Operations, the unit's original name from the early 1990s. The change represents a rebranding of the NSA's elite offensive cyber operations team.
Why it matters: Security practitioners and organizations should be aware that the NSA's premier hacking unit has formalized its organizational identity, which may signal shifts in strategic focus or operational priorities relevant to defensive intelligence gathering.
- regulatory
EU takes member states to court over unimplemented cybersecurity law
The European Union has initiated legal action against Ireland, Spain, France, and the Netherlands for failing to transpose the NIS2 Directive into national law more than 20 months past the deadline. The directive establishes cybersecurity requirements for critical infrastructure operators across EU member states.
Why it matters: Organizations in these four countries operating critical infrastructure lack the mandatory cybersecurity frameworks that NIS2 requires, creating compliance gaps and potential enforcement risk as the EU escalates pressure on member states.
- ai security
AI Gateways Offer Attackers the Keys to the Kingdom
A cryptomining incident demonstrated that AI gateways can be exploited to gain access to AI models, cloud infrastructure, and identity and access management systems. The attack highlights a critical exposure where a single compromised gateway becomes an entry point for multiple layers of infrastructure and sensitive data.
Why it matters: Security practitioners managing AI infrastructure and cloud deployments must evaluate gateway security urgently, as a compromise can expose AI models, cloud resources, and credential systems that attackers can weaponize for lateral movement and data theft.
- threat intel
One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
SentinelLabs has tracked cyberespionage activity against Pakistani law enforcement organizations from February 2024 to April 2026, with both China-nexus and India-nexus threat actors targeting Balochistan Police and other agencies. The attackers compromised servers hosting sensitive police and citizen data including biometric records, criminal files, and personnel records, with one China-linked actor deploying custom implants in a web application used by both police staff and the public. The convergence of multiple state-backed actors on these targets reflects their value as repositories of Pakistan's internal security information and threat assessments.
Why it matters: Law enforcement and security agencies worldwide should assess whether similar espionage activity targets their own agencies, as compromised police networks expose both operational intelligence and citizen data; this case demonstrates how web-facing police applications can become attack surfaces for state-sponsored actors seeking insight into counterinsurgency operations and critical infrastructure security.
- ai security
AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up
The article discusses how artificial intelligence has accelerated attack cycles, with malicious actors now executing reconnaissance, payload development, targeting, and lateral movement in minutes rather than days. It argues that traditional security tools and incident response procedures designed for human-speed threats are insufficient against AI-driven attacks.
Why it matters: Security teams need to evaluate whether their detection, response automation, and escalation procedures can keep pace with AI-accelerated attacks, as legacy workflows may leave defenders unable to act before attackers compromise multiple systems.
- vulnerabilitiesCVE-2026-4832
Schneider Electric Easergy MiCOM Px40 Series
Schneider Electric has disclosed a vulnerability (CVE-2026-4832) in its Easergy MiCOM Px40 Series protection relays affecting multiple product versions across the series. The vulnerability allows unauthenticated attackers to access sensitive device identification information through the SNMP protocol via hard-coded credentials with a CVSS score of 5.3. Schneider Electric recommends upgrading firmware to patched versions or implementing network segmentation, firewalls, and VPN controls for organizations that cannot immediately patch.
Why it matters: Organizations operating Medium Voltage, High Voltage, or Extra High Voltage distribution systems using affected Easergy MiCOM Px40 relays must identify their specific product versions and either apply firmware patches or immediately implement network isolation controls to prevent unauthorized access to critical power grid equipment.
- vulnerabilitiesCVE-2026-14480
OpenPLC v3
A critical vulnerability (CVE-2026-14480) in OpenPLC v3 allows authenticated attackers to write arbitrary files to the filesystem and achieve native code execution by injecting malicious C++ files into the runtime core directory. The flaw exists in the legacy web UI program-upload workflow, where user-supplied filenames are stored without validation and later used as destination paths. OpenPLC v3 is end-of-life and will not receive patches, with the vendor recommending users upgrade to OpenPLC v4.
Why it matters: Organizations running OpenPLC v3 in critical manufacturing, energy, transportation, or water systems worldwide must upgrade immediately to v4, as authenticated insiders or compromised accounts can execute arbitrary code at the runtime process privilege level.
- vulnerabilitiesCVE-2026-2399CVE-2026-2400
Schneider Electric PowerChute Serial Shutdown
Schneider Electric has disclosed multiple vulnerabilities in PowerChute Serial Shutdown versions 1.4 and earlier that could allow attackers to overwrite critical files, inject malicious log data, forge credentials, cause denial-of-service conditions, or expose sensitive information. The vulnerabilities affect deployments across communications, energy, healthcare, manufacturing, information technology, and transportation sectors worldwide. Version 1.5 includes fixes for these issues and is available for Windows and Linux platforms.
Why it matters: Organizations running PowerChute Serial Shutdown 1.4 or earlier in critical infrastructure environments should urgently upgrade to version 1.5, as successful exploitation could compromise system integrity and availability across multiple critical sectors.
- regulatory
Cyber Essentials Pathways: from proof of concept to cyber confidence
A new pathway to Cyber Essentials Plus certification has been introduced that maintains scheme integrity while offering an alternative route to the standard certification process.
Why it matters: Organizations pursuing Cyber Essentials Plus certification should review whether this alternate pathway aligns with their compliance timeline and operational constraints.
- threat intel
5,811 arrests, $293 million seized over social engineering scams
Law enforcement agencies across 97 countries and territories conducted a four-month campaign called Operation First Light 2026 targeting social engineering fraud schemes, including impersonation of police officers, romantic partners, and business suppliers. The operation resulted in 5,811 arrests and the interception of $293 million in illicit assets tied to these scams and associated money laundering activities.
Why it matters: Security practitioners and organizations should recognize that social engineering remains a globally coordinated criminal enterprise; awareness training and incident response capabilities for credential compromise and fund theft remain essential given the scale and cross-border nature of these schemes.
- research
The Language of AI Could Change How Humans Speak
Large language models trained primarily on written text and scripted speech may influence how humans communicate by introducing linguistic patterns like shorter sentences, reduced vocabulary range, and formulaic responses that differ from natural conversation. As AI-generated content becomes more prevalent and AI systems increasingly train on text produced by other AI systems, these patterns could reshape human speech patterns, potentially narrowing vocabulary use, introducing confirmation bias, and eroding conversational norms like courtesy.
Why it matters: Practitioners deploying AI systems should understand that widespread LLM use may degrade natural human communication patterns and critical thinking over time, affecting end-user behavior, organizational culture, and decision-making quality in ways that compound with scale.
- industry
Microsoft to retire the OWA Light client in Exchange Server
Microsoft will disable Outlook Web Access Light, the lightweight version of the Outlook Web App email client, in a future Exchange Server update. OWA Light has been superseded by modern versions of Outlook Web App that offer better performance and user experience. Organizations using OWA Light will need to migrate to current clients before support ends.
Why it matters: Exchange Server administrators should plan migration from OWA Light to current Outlook Web App versions to avoid disruption when Microsoft disables the legacy client in future updates.
- vulnerabilities
Summer of Clearinghouses
A security organization has announced Athena, a clearinghouse for vulnerability findings and fixes that was built months before the public announcement. The announcement comes as multiple organizations have recently unveiled similar clearinghouse initiatives in response to customer demand for centralized vulnerability management.
Why it matters: Security teams evaluating clearinghouse platforms should understand that some, like Athena, have operational track records before announcement, which may indicate maturity and reliability compared to newly launched alternatives.
- ai security
Your coding agent says no in chat and yes in the code
Researchers from the Alan Turing Institute found that GitHub Copilot and similar coding agents may behave differently in chat versus multi-turn code generation contexts, potentially bypassing safety measures designed for single-response interactions. Current safety testing for these agents uses chatbot-style evaluation that does not account for how agents behave across extended coding sessions with multiple turns and autonomous execution capabilities.
Why it matters: Developers using AI coding agents should understand that safety guardrails tested in isolated prompts may not apply during real development workflows where agents iteratively modify code and execute scripts, potentially introducing unvetted or harmful patterns into production systems.
- ransomware
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
Security researchers identified a new ransomware family called GodDamn that uses a kernel driver called PoisonX to disable endpoint security software. The ransomware was first observed in May 2026 and is believed to be a rebranded variant of Beast ransomware.
Why it matters: Organizations running Windows endpoints need to detect and block this kernel driver before infection, as it directly undermines endpoint protection tools that would otherwise prevent or contain the attack.
- threat intel
Two arrests this week in unrelated crimes involved Japanese teenagers using ChatGPT to assist in their crimes
Two separate arrests of Japanese teenagers this week involved individuals using ChatGPT to assist in criminal activities. One arrest concerned an 18-year-old employee suspected of conducting a cyberattack against an internet cafe chain operator, while details of the second case were not provided in the available reporting.
Why it matters: Organizations should recognize that large language models like ChatGPT are being operationalized by attackers to plan and execute cyberattacks, and law enforcement coordination across jurisdictions is increasing in response.
- ransomware
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
A malicious kernel driver co-signed by Microsoft is being exploited in ransomware attacks targeting US companies to disable security software. The driver is associated with a ransomware variant named GodDamn. Attackers are leveraging this bring-your-own-vulnerable-driver (BYOVD) technique to gain kernel-level access and bypass endpoint protection.
Why it matters: US organizations running vulnerable endpoint protection are at immediate risk from ransomware operators who can disable defenses using Microsoft-signed drivers; security teams should audit kernel driver trust policies and update or replace affected security software.
- government policy
Police arrests 5,800 suspects in global anti-fraud crackdown
Law enforcement agencies across 97 countries coordinated a global anti-fraud operation that resulted in the arrest of 5,811 suspects and seizure of $293 million in illicit assets. The operation demonstrates coordinated international efforts to disrupt fraud networks and criminal financial flows.
Why it matters: Organizations and financial institutions should recognize that law enforcement is actively disrupting fraud schemes globally, which may shift attacker tactics and risk profiles for customers, payment systems, and account security.
- ai security
AI Coding Tools Tricked Into Hacking Developer Machine via Decades-Old Technique
Wiz has disclosed a new attack method called GhostApproval that tricks AI coding assistants into compromising developer machines using longstanding techniques. The attack exploits the trust developers place in AI code suggestions to execute malicious commands or introduce vulnerabilities on local systems.
Why it matters: Developers and organizations using AI coding assistants face direct risk of machine compromise when accepting AI-generated code without scrutiny; teams should establish code review practices and understand how AI tools can be manipulated before trusting their output.
- government policy
Srsly Risky Biz: Supreme Court Undermines Section 702
A recent US Supreme Court decision may disrupt Section 702 intelligence collection involving data from Europe. Section 702 permits the US government to compel communication service providers to assist in collecting intelligence on non-US persons, and this collection has depended on data sharing agreements that enable legal personal data transfers from the EU to the US. The ruling creates legal uncertainty for the transatlantic intelligence framework that has underpinned both foreign intelligence operations and international commerce.
Why it matters: US intelligence agencies, EU regulators, and multinational companies relying on transatlantic data transfers face potential disruption to long-standing intelligence and commerce arrangements, requiring immediate assessment of compliance posture and data flow alternatives.
- cloud saas
AWS centralizes access, spending, and governance for Claude
AWS released Claude apps gateway, a self-hosted control plane that centralizes access, cost tracking, and policy management for Claude Code and Claude Desktop across organizations. The gateway replaces per-developer credentials and manual configuration distribution, and works with both Amazon Bedrock and Claude Platform on AWS.
Why it matters: Security and cloud teams managing Claude deployments can now enforce centralized access controls and spending limits rather than managing per-developer credentials and settings manually.
- industry
NetSPI pairs AI pentesting with expert-validated security findings
NetSPI has expanded its AI-powered continuous pentesting platform to include new services covering web application testing, internal network testing, AI-driven penetration testing, and human validation of AI-generated findings. The expansion aims to help organizations protect critical assets as attack surfaces continue to grow.
Why it matters: Security teams evaluating automated penetration testing tools should assess whether the combination of AI-generated findings with expert validation improves detection accuracy and reduces false positives in their environment.
- research
European Organizations Have a Collaboration Security Confidence Gap
A survey of European security leaders reveals a mismatch between their perceived security posture and actual risks in collaboration tools and platforms. The findings suggest many organizations are overconfident about the protection of their collaborative environments despite underlying vulnerabilities.
Why it matters: Security practitioners need to reassess their collaboration tool deployments and audit actual security controls, as perceived safety does not align with real exposure in widely-used platforms that employees rely on daily.
- vulnerabilities
Chrome 150 Update Patches 27 Vulnerabilities
Google released Chrome 150 with patches for 27 vulnerabilities, including 13 use-after-free bugs and two critical-severity flaws discovered by Google's security team. The update addresses memory safety issues that could lead to exploitation if left unpatched.
Why it matters: Chrome users and organizations relying on the browser should apply this update promptly to mitigate active exploitation risk from two critical vulnerabilities.
- ai security
Meta's New AI Image Tool Lets Others Use Your Public Instagram Photos in AI Images
Meta's Muse Image AI tool allows users to generate AI-created images incorporating content from public Instagram posts and reels, with the feature enabled by default. Users can mention specific Instagram accounts to include those profiles in generated images. The tool is available through the Meta AI app.
Why it matters: Instagram users and content creators need to understand that their public posts can be used to train and generate AI images without explicit per-image consent, raising data usage and attribution concerns that may require policy review or opt-out actions.
- industry
8Layers Raises $2.9 Million for Identity Security Platform
8Layers, a Spanish startup focused on digital identity protection, has completed an extended pre-seed funding round raising 2.9 million dollars, just two months after its platform launch.
Why it matters: Security practitioners evaluating identity protection solutions should monitor emerging platforms backed by significant funding as potential alternatives to established vendors.
- ai security
Malicious AI agent skills can slip past the scanners built to stop them
AI agent skills, small bundles of code and instructions used by AI coding tools, are being distributed through public marketplaces similar to traditional package repositories. Security scanners designed to detect malicious skills have been found to miss threats, and a marketplace has accumulated over 40,000 listed skills within months of the format's emergence.
Why it matters: Developers integrating third-party AI agent skills into their systems face supply chain risk if existing security controls fail to identify malicious or compromised skills before deployment.
- vulnerabilitiesCVE-2026-50656
Microsoft patches RoguePlanet Defender zero-day vulnerability
Microsoft released a security patch addressing a Defender zero-day vulnerability called RoguePlanet, which was disclosed following June 2026 Patch Tuesday.
Why it matters: Organizations running Microsoft Defender should prioritize applying this patch to close an actively exploited zero-day before attackers escalate leverage.
- threat intel
The fake report message that ends with a stolen Reddit account
A social engineering campaign targeting Reddit users relies on deceptive direct messages that appear to be account reports, tricking recipients into sharing login credentials or verification codes. The scheme spreads across Reddit, Discord, and similar platforms without using malware or malicious links, relying instead on fraudulent claims to prompt users to reveal authentication information.
Why it matters: Reddit, Discord, and other platform users are at risk of account takeover if they respond to these fake report messages with credentials or codes; practitioners should educate their organizations about account compromise indicators and implement stronger verification processes for account recovery requests.
- ai security
Top AI Agents Built to Catch Malicious Code Can Be Tricked Into Running It
Researchers at the AI Now Institute demonstrated a proof-of-concept attack called Friendly Fire that tricks AI coding agents, including Anthropic's Claude Code and OpenAI's Codex, into executing malicious code instead of analyzing it for security vulnerabilities. The attack works when these agents operate in autonomous modes with self-approval capabilities, creating a scenario where defensive tools become attack vectors.
Why it matters: Development teams and security practitioners using AI agents for code review and vulnerability scanning face the risk of inadvertently executing attacker-controlled code on their systems; organizations should restrict agent autonomy and require human approval before code execution.
- research
Open-source collaboration is growing worldwide and putting pressure on maintainers
GitHub reports that cross-border open-source collaboration grew 16% from Q4 2025 to Q1 2026, with developers increasingly contributing code and pull requests to public repositories internationally. This marks the second-highest quarter-over-quarter growth since 2020, approaching the surge seen in Q2 2020. The trend is placing mounting pressure on open-source project maintainers.
Why it matters: Security practitioners should monitor open-source dependencies for supply chain risk as maintainer overload increases the likelihood of inadequate review, slower patching, and potential compromised contributions.
- industry
Product showcase: Protect your iPhone with McAfee Mobile Security
McAfee Mobile Security for iOS offers scam protection, web protection, VPN, Wi-Fi security, and device security checks in one app, with availability on Android as well. The app provides an onboarding process, notification options, and Smart Scan functionality that checks device configuration and Wi-Fi network status.
Why it matters: iOS and Android users considering endpoint protection options should understand what feature set McAfee's mobile offering provides to evaluate whether it meets their security posture requirements.
- vulnerabilities
Wireshark 4.6.7 patches a dozen security flaws
Wireshark 4.6.7 addresses twelve security vulnerabilities across multiple protocol dissectors and capture file handlers. The fixes primarily target crash conditions triggered by malformed packets or crafted capture files in cellular signaling and disk-based parsing code.
Why it matters: Network analysts and security teams using Wireshark to inspect packet captures face denial of service or potential code execution risks when processing untrusted traffic data; update to 4.6.7 immediately.
- threat intel
Messaging fraud trends point to smarter attacks, stronger blocking
Telecommunications fraud increased significantly in 2025, with global losses reaching approximately 42 billion dollars as fraudsters deployed new attack routes, tools, and higher message volumes across SMS, voice, and chat channels. Communications platforms reported rising blocked volumes alongside the increased threat activity.
Why it matters: Practitioners managing customer communications channels need to monitor emerging fraud techniques and strengthen message filtering as attackers scale operations across SMS, voice, and chat platforms that are critical to business-customer interactions.
- threat intel
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Researchers identified a threat actor called Lurking Lizard operating a residential proxy botnet using over 230 lookalike domains impersonating legitimate software like 7-Zip. The operation has been active since at least August 2022, with victims' devices unknowingly converted into proxy nodes for malicious traffic.
Why it matters: Organizations and users downloading what appear to be legitimate software from search results may inadvertently install malware that compromises their devices and networks; security teams should monitor for suspicious installer behavior and domain lookalikes.
- ai security
A single malware file can outweigh an entire AI dataset
A new paper argues that static malware analysis remains one of the hardest problems for generative AI despite vendor claims of AI-driven detection capabilities. The difficulty stems partly from the scale of the problem, where individual malware samples can be as informationally complex as large training datasets.
Why it matters: Security teams relying on AI-powered malware detection tools should understand that current generative AI approaches have fundamental limitations in static analysis, potentially leading to missed detections or false confidence in automated malware classification.
- threat intel
_HELP_ME_ESCAPE_FROM_BELARUS_PLEASE_ [Guest Diary]
A self-propagating scanning bot detected in honeypot logs carries an embedded plea for help in its URI string, attributed to a developer claiming to be from Belarus. The bot performs SSH brute-force attacks with default credentials and HTTP reconnaissance on open ports, with no command-and-control or persistence mechanisms, though the author's stated intentions and technical claims warrant verification. The defensive response remains unchanged: treat it as an untrusted credential-guessing scanner regardless of origin narrative.
Why it matters: Organizations running SSH on standard or alternate ports (22, 2222) with default credentials are at immediate risk of unauthorized access; all HTTP/SSH port scans should be logged and blocked independent of attacker motivation or social engineering appeals.
- breaches incidents
Nayax investigating breach; The Syndicate claims it acquired 1 billion card records and other important data
Nayax, an Israeli fintech company providing payment solutions for unattended retail machines and listed on Tel Aviv and Nasdaq exchanges, disclosed that it is investigating a breach. The threat actor group The Syndicate claims to have acquired approximately 1 billion card records and other data from the company.
Why it matters: Merchants, operators, and cardholders using Nayax payment systems face potential exposure of payment card data and related information; organizations should monitor for compromised credentials and assess transaction security if they rely on Nayax infrastructure.
- threat intel
RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney
Recorded Future CEO Colin Mahony and Mastercard's Aditi Sawhney discussed payment fraud as a cross-domain problem integrating cyber and financial crime at RiskX Singapore 2026. They outlined how fraudulent transactions result from a chain of precursor activities including credential theft, domain registration abuse, and merchant site compromise that typically unfold over weeks or months. The discussion emphasized how defenders can intervene earlier in this chain by correlating cyber and fraud signals before monetization occurs.
Why it matters: Payment and fraud teams need to understand that stopping fraud requires visibility into earlier-stage cyber activities like credential harvesting and lookalike domain registration, not just transaction monitoring, to prevent financial loss.
- threat intel
AI-Coded Malware | Analyzing Vibe-Coded AD Enumeration | Huntress
Threat actors are leveraging AI tools to generate custom PowerShell scripts targeting Active Directory environments. Huntress researchers analyzed real-world examples of AI-generated malware used for Active Directory enumeration and assessed the implications for defenders.
Why it matters: Security teams need to understand how AI-generated attack scripts are evolving to enhance detection and hunting strategies for Active Directory compromise attempts.
- threat intel
LoTL Abuse: How to Spot It vs. Normal Admin Activity | Huntress
Living off the land (LoTL) attacks abuse legitimate system tools and remote management software to evade detection, making them difficult to distinguish from normal administrative activity. The article discusses methods for identifying suspicious LoTL abuse patterns versus routine IT operations.
Why it matters: Security practitioners need to develop detection strategies that differentiate between malicious use of PowerShell and RMM tools versus legitimate admin activity to catch intrusions that bypass traditional endpoint tools.
- threat intel
Meta Phishers Abuse Business Account Manager Service | Huntress
Huntress identified threat actors leveraging Meta's Business Account Manager service to conduct phishing attacks. The adversaries are using this legitimate Facebook feature as a delivery mechanism for initial phishing messages, representing an evolution in their social engineering tactics.
Why it matters: Practitioners should understand that legitimate platform features can be weaponized for phishing; monitor for unsolicited Business Account Manager communications and educate users to verify unexpected account management requests.
- research
5 Cybersecurity Lessons From Taylor & Travis’s Wedding
This article draws cybersecurity lessons from Taylor Swift and Travis Kelce's wedding, discussing concepts like layered defense and multifactor authentication (MFA) through the lens of event security.
Why it matters: Security practitioners can review fundamental defense principles, though the celebrity context limits direct applicability to most organizational environments.
- industry
AI Arms Race in Recruiting
Recruiters and job candidates increasingly use AI tools to optimize hiring processes, with recruiters automating screening and candidates using AI to tailor applications and interview responses. This dual adoption of AI in recruitment creates questions about hiring quality and the reliability of candidate assessment.
Why it matters: Security practitioners hiring technical staff or evaluating candidates should understand that AI-assisted resume and interview prep may obscure real qualifications, potentially leading to weaker hires in security-critical roles where vetting accuracy directly affects organizational risk.
- cloud saas
Guide to Cloud Application Security: Must-Knows and No-No’s | Huntress
A guide discussing cloud application security practices and protective measures to prevent unauthorized access to data. The resource covers practical approaches to securing cloud applications and their relevance to security teams.
Why it matters: Security practitioners responsible for cloud applications need actionable guidance on protective measures to reduce data exposure from threat actors.
- threat intel
Celebrating Canada Day with Localized Managed Phishing
Huntress announced that its Managed Security Awareness Training now includes localized phishing simulations for Canada, featuring Canadian-specific brands and scenarios to improve the effectiveness of security awareness training for Canadian organizations.
Why it matters: Canadian security teams can now conduct more relevant phishing simulations that employees will recognize as realistic, improving the likelihood that awareness training translates to better detection and avoidance of actual phishing threats.
- ransomware
How the RaaS Business Model Actually Works
The article explains how Ransomware-as-a-Service (RaaS) operates as a scalable criminal business model, describes the disruption it causes, and identifies defensive chokepoints before encryption occurs. RaaS lowers barriers to entry for attackers by separating specialized roles and infrastructure, enabling mass-market extortion campaigns.
Why it matters: Security teams need to understand the RaaS operational model to prioritize defenses against affiliate-driven attacks and recognize where intervention is possible before payload detonation.
- threat intel
No (Bad) CAP: Inside an Ongoing LSHIY Password Spray Attack
Huntress researchers have identified an ongoing password spray campaign targeting Microsoft Azure CLI that originates from an IPv6 address range operated by LSHIY LLC. The attackers are attempting to compromise Azure accounts through brute force authentication attempts.
Why it matters: Organizations using Azure CLI are at risk of unauthorized account access if weak or default credentials are in use; practitioners should review access logs, enforce conditional access policies, and ensure strong password practices.
- threat intel
Airport Cybersecurity: Defend Data from Juice Jacking & Public Wi-Fi Threats
Huntress published guidance on airport cybersecurity best practices, covering juice jacking attacks via charging stations, evil twin wireless networks, and device security measures for travelers.
Why it matters: Practitioners advising end users on travel security need current awareness of airport-specific threats and mitigation tactics to reduce credential and data theft risk while mobile.