<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link href="https://www.techradar.com/feeds/tag/security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from TechRadar in Security ]]></title>
                <link>https://www.techradar.com/pro/security</link>
        <description><![CDATA[ All the latest security content from the TechRadar team ]]></description>
                                    <lastBuildDate>Thu, 23 Jul 2026 18:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Experts have found a trojan able to rig online live betting platforms ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-have-found-a-trojan-able-to-rig-online-live-betting-platforms</link>
                                                                            <description>
                            <![CDATA[ A company building betting software was targeted with a rather sneaky trojan. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UbpcBTvNkV6nbqLzBq2xw4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Online games]]></media:description>                                                            <media:text><![CDATA[Online games]]></media:text>
                                <media:title type="plain"><![CDATA[Online games]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>JFrog found Newtonsoftt.Json.Net, a trojan NuGet package mimicking the popular Newtonsoft.Json library</strong></li><li><strong>Malware specifically targeted Digitain’s crash‑game backend, rigging outcomes with insider knowledge of its codebase</strong></li><li><strong>Issue was quickly fixed but attackers remain unidentified</strong></li></ul><p>Security researchers JFrog have <a href="https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/" target="_blank">discovered</a> a unique trojan targeting one specific company, while letting everyone else who’s infected walk away unharmed.</p><p>Named Newtonsoftt.Json.Net, the trojan is a typosquatted NuGet package variant of the hugely popular JSON library called Newtonsoft.Json. The legitimate package is one of the most-used code libraries in the .NET programming world, needed by almost every project in existence. It is a small piece of software that helps .NET applications read, understand, and exchange data between different systems.</p><p>According to JFrog, someone published an almost identical package, copied the real author’s name, license, and made it work as intended. For almost anyone who installed it, it worked entirely normal. However, for developers working on Digitain’s crash-game backend, it’s a whole different story. </p><h2 id="rigging-the-games">Rigging the games</h2><p>Digitain is an Armenian software company providing online sports betting and gaming software platforms to gambling companies around the world.</p><p>On the infected machine running Digitain’s real crash-game code, the malware swaps in a rigged number instead of a fair one, using a formula based on the date and time. </p><p>What this means is that the results of the gambling game are rigged, allowing the attackers to know, in advance, which rounds are manipulated and place their bets accordingly. </p><p>The malware also sets up a private confirmation channel to report back for every rigged round, allowing the attackers to know if the cheat code still works or not. </p><p>JFrog did not identify the attackers, but they did stress that it was most likely an insider. </p><p>Apparently, only someone with inside knowledge of Digitain’s codebase (for example a current or former employee, or a contractor) could have built such an exploit, since it required knowledge of the exact internal function name inside Digitain’s game engine that decides the crash-game outcome. </p><p>The researchers reached out to Digitain on July 7 2026 and were notified, two days later, that the issue had already been escalated to the team and, in the meantime, fixed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Flock cameras spotted hiding inside speed signs from a growing backlash — as Wisconsin officials resort to covering ALPRs with trash bags after company refuses to take them down ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/computing/computing-security/flock-cameras-spotted-hiding-inside-speed-signs-from-a-growing-backlash-as-wisconsin-officials-resort-to-covering-alprs-with-trash-bags-after-company-refuses-to-take-them-down</link>
                                                                            <description>
                            <![CDATA[ Flock cameras are still getting heated backlash, and now these ALPR systems are being hidden inside speed signs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QpxvKQAmoP7dUuTtgDhdTm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o5qzeQtrqmk4vfz5tKpgi7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 15:46:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ rowan.davies@futurenet.com (Rowan Davies) ]]></author>                    <dc:creator><![CDATA[ Rowan Davies ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/q5Az6iW5pbAotRovdNvQAf.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rowan is an Editorial Associate and Apprentice Writer for TechRadar. A recent addition to the news team, he is involved in generating stories for topics that spread across TechRadar&#039;s categories. His interests in audio tech and knowledge in entertainment culture help bring the latest updates in tech news to our readers.&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;He has been writing for publications since he started his studies at age 18. Rowan graduated from Cardiff University in 2023 after attaining a Master&#039;s in Creative Writing, and earlier a Bachelor&#039;s in Media, Journalism, and Culture. He began his journey as a writer at Cardiff University&#039;s Quench Magazine contributing to film/ TV, music, and culture sections, later becoming Music Section Editor.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;br&gt;&lt;/p&gt;
&lt;p&gt;In his free time, Rowan is a freelance writer for Cardiff-based culture magazine Buzz where he reviews music, film, and conducts interviews with featured guests. When he is not writing, you can find him at any given music gig, or endlessly scrolling TikTok immersing in celebrity news and drama. &amp;nbsp;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o5qzeQtrqmk4vfz5tKpgi7-1280-80.jpg">
                                                            <media:credit><![CDATA[Flock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Flock license plate reader]]></media:description>                                                            <media:text><![CDATA[Flock license plate reader]]></media:text>
                                <media:title type="plain"><![CDATA[Flock license plate reader]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o5qzeQtrqmk4vfz5tKpgi7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The Flock backlash is growing, and city officials have started covering ALPR cameras with trash bags </strong></li><li><strong>Some cameras are even being smashed up </strong></li><li><strong>A handful of Flock cameras have been spotted inside speed signs out of sight from drivers</strong></li></ul><p>The recent backlash to security company Flock highlights severe privacy concerns with its Automated License Plate Recognition (ALPR) systems — and local authorities are taking matters into their own hands. </p><p>In an article by <a href="https://www.404media.co/flock-objects-to-our-removing-their-equipment-emails-reveal-why-a-town-put-bags-over-its-flock-cameras/" target="_blank">404media</a>, city officials of Verona, Wisconsin have been protesting Flock’s ubiquitous surveillance cameras by covering them with black bags. The move follows a council vote to remove three cameras from the area, which Flock refused to take down according to recently exchanged emails. </p><p>“We kind of looked at the contract, talked it over amongst staff, and the thing we felt most comfortable with was just covering them so they could stop spying on people … I’m 100% certain that they were still working," said Luke Diaz, Mayor of Verona. </p><p>But for some residents, covering Flock’s ALPR systems with trash bags simply isn’t enough to give them peace of mind — some are going the extra mile by smashing Flock’s surveillance cameras, according to <a href="https://www.reddit.com/r/technology/comments/1v3sccw/flock_cameras_keep_getting_smashed_so_now_theyre/" target="_blank">an article shared to Reddit</a>. </p><blockquote class="reddit-card"  ><a href="https://www.reddit.com/r/technology/comments/1v3h6zz/comment/oz38mmu">Comment</a> from <a href="https://www.reddit.com/r/technology">r/technology</a></blockquote><script async src="//embed.redditmedia.com/widgets/platform.js" charset="UTF-8"></script><p>Just yesterday (July 22), <a href="https://www.techradar.com/computing/computing-security/flock-is-pulling-its-plan-to-use-its-microphone-network-to-monitor-for-signs-of-human-distress-but-privacy-concerns-remain">Flock decided to abandon its plans to roll out its ‘human distress detection’ feature</a> beyond the trial period. This tool used Flock’s urban acoustic microphones to detect sounds such as human screaming, and would then alert local police allowing them to reach the incident quickly. </p><p>Though these detectors are still in place, they can no longer pick up on human activity, and instead listen out for sounds such as gun shots or vehicle crashes. For those who have actively campaigned against this, it’s a huge win, but the microphones that remain in place are still sparking widespread concern regarding civil privacy, even though <a href="https://www.flocksafety.com/blog/how-flocks-audio-detection-works" target="_blank">Flock says</a> these systems cannot understand or analyze speech. </p><h2 id="the-people-vs-flock">The People vs Flock </h2><p>Since Flock’s ALPR systems became a means of public surveillance, the tech firm has been met with waves of backlash to the extent where the American Civil Liberties Union (ACLU) has<a href="https://www.aclu.org/campaigns-initiatives/get-the-flock-out" target="_blank"> launched campaigns against these types of systems</a> — claiming Flock is “quietly trying to build a nationwide mass surveillance system”.  </p><p>Public concern has become so heated, some local authorities are pumping the breaks on introducing Flock cameras to certain areas. <a href="https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/lapd-hits-pause-on-flock-surveillance-cameras-due-to-serious-concerns-around-civil-liberties-and-privacy-as-the-backlash-continues-to-grow">The LAPD is one of the most recent police departments that has acted on this</a>, making the decision not to renew its contract with the tech company. </p><p>However, there are countless cities across the US that still have these systems in place and not only is the number increasing, the tech is getting smarter. ALPR systems don’t just capture your license plate, they are designed to identify your vehicle’s make and model, as well as its color and things such as bumps, scratches, and accessories like bumper stickers. </p><p>As a result of the rapidly advancing technology, <a href="https://www.techradar.com/vehicle-tech/hybrid-electric-vehicles/this-free-tool-is-helping-drivers-avoid-automatic-license-plate-readers-as-fears-grow-around-intrusive-new-devices-that-could-track-your-phone-airpod-and-smartwatch-data">drivers have been seeking ways to avoid areas where these systems are in place</a> — the website DeFlock allows you to plan routes that actively avoid Flock’s cameras. Naturally, some local authorities are camouflaging its Flock ALPR systems to prevent vandalism. </p><div class="see-more see-more--clipped"><blockquote class="twitter-tweet hawk-ignore" data-lang="en"><p lang="en" dir="ltr">They are hiding Flock cameras now, secret compartment found in speed radar box pic.twitter.com/4kkeRsKufi<a href="https://twitter.com/cantworkitout/status/2079969721458541042">July 22, 2026</a></p></blockquote><div class="see-more__filter"></div></div><p>In a video shared to X by @OrwellDay (see above), the user captured footage of what looks like a regular speed-display sign, but uncovered a hidden Flock camera placed around the back. “Someone did some custom metal fabricating,” they say. </p><p>Quite a sneaky tactic, right? It doesn’t end there, and according to the replies on Reddit, these systems aren’t just being concealed inside speed signs. <a href="https://www.reddit.com/r/technology/comments/1v3sccw/comment/oz5j82r/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button" target="_blank">One user claims </a>that ALPR systems are being hidden in fake cacti in some parts of Arizona, making it more difficult for tools like DeFlock to list the locations of cameras. </p><p>It's becoming increasingly difficult to avoid the watchful eye of Flock's ALPR cameras, but it seems that residents will stop at nothing to find ways to combat the rise of these counteractive measures. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-devious-malware-scans-over-300-apps-to-build-an-ai-profile-telling-hackers-which-victims-to-target</link>
                                                                            <description>
                            <![CDATA[ Malware started talking to their bosses, telling them where to strike next. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dD6tYK5jkxNm5YaX69LWLQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 13:40:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg">
                                                            <media:credit><![CDATA[wk1003mike / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trojan]]></media:description>                                                            <media:text><![CDATA[Trojan]]></media:text>
                                <media:title type="plain"><![CDATA[Trojan]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Varonis Threat Labs uncovered Dolphin X, a powerful RAT with 329 features across 10 categories</strong></li><li><strong>Its standout “AI Profiler” ranks victims by usage and sends summaries to attackers daily</strong></li><li><strong>Malware is sold on the dark web via subscription tiers, starting at $80 per month</strong></li></ul><p>What if malware could talk to its operator and tell it which of the infected victims is worth paying attention to, and which not? A few years ago, this might have been science fiction but today, thanks to breakthroughs in Artificial Intelligence (AI), not only is it possible, it’s also already available on the black market.</p><p>Security researchers Varonis Threat Labs recently <a href="https://www.varonis.com/blog/dolphin-x-stealer" target="_blank">disclosed</a> finding a rather revolutionary remote access trojan (RAT) called Dolphin X. </p><p>Even without advanced AI capabilities, the RAT is quite potent, acting as an infostealer, a Hidden Virtual Network Computing (HVNC), a DDoS botnet, or a loader. Just its infostealer capabilities are nothing short of impressive - it can target more than 300 applications to steal browser passwords, enterprise credentials, cryptocurrency wallet data, DevOps secrets, and different sensitive files, and it comes with 329 features split into 10 categories.</p><h2 id="ai-profiler">AI Profiler</h2><p>However, the AI capability is the one that stunned the researchers. Called “AI Profiler”, the feature ranks victims by app usage, browsing history, and more, sending a daily summary to the attackers. </p><p>The malware is now being offered on the dark web, where other criminals can subscribe to one of three tiers. The basic tier costs $80 per month, while the top tier is around $230 per month. Lifetime subscription costs $1,140 for basic access, and goes up to $3,420 for the top tier. </p><p>"Dolphin X’s collection scope reaches well beyond browser passwords to SSH keys, cloud tokens, and DevOps credentials," Varonis said in its write-up. "On the wrong machine, a single infection could expose access to an entire production environment."</p><p>"Its use of AI is also interesting because it shows us how AI is being integrated into more cybercrime tooling."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A malicious Chrome extension for Adobe Acrobat could let hackers access private WhatsApp chats ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-malicious-chrome-extension-for-adobe-acrobat-could-let-hackers-access-private-whatsapp-chats</link>
                                                                            <description>
                            <![CDATA[ Researchers find a universal cross-site scripting-class cross-origin data disclosure vulnerability in a popular Chrome extension. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5ZGuvAuVv7kLKhivJo4DFK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:description>                                                            <media:text><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Guardio Labs found CVE‑2026‑48294 in Adobe Acrobat Chrome extension, enabling cross‑site data disclosure</strong></li><li><strong>Attackers could steal WhatsApp Web chats if victims opened malicious landing pages with extension active</strong></li><li><strong>Adobe patched the flaw in version 26.7.2.0; update recommended for 314M extension users</strong></li></ul><p>If you have Adobe Acrobat’s extension for Chrome, and you like chatting through WhatsApp Web, there is a potential security vulnerability you might want to address.</p><p>Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability”, which is another way of saying that a website could use the flaw to read the contents of a different website, loaded in a separate tab. </p><p>The vulnerability was found in the Adobe Acrobat <a href="https://www.techradar.com/computing/chrome/these-are-the-10-best-chrome-extensions-of-2025-according-to-google-and-theres-one-i-definitely-recommend" target="_blank">Chrome extension</a> and is now tracked as CVE-2026-48294. It was given a severity score of 7.4/10 (high), and affects versions 26.5.2.2 and earlier. Guardio Labs dubbed it “HermeticReader” because of what it exploits. </p><h2 id="insultingly-ordinary-setup">"Insultingly ordinary" setup</h2><p>The extension comes with different integrations, such as Google Drive or, in this case - WhatsApp Web. The WhatsApp integration component, internally known as "Hermes" is where the bug was found. </p><p>In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) has WhatsApp loaded in a separate tab; and 3) opens the malicious landing page, it could trigger the extension’s vulnerable code path and allow the attackers to access everything the victim has on their WhatsApp. </p><p>Some sources argue that threat actors could use this vulnerability to pull one-time passcodes delivered via WhatsApp.</p><p>"The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.," Guardio Labs wrote in its analysis. </p><p>"The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view - the chat list, contact names, messages, the profile name, the text of whatever conversation is open - the whole WhatsApp in the attacker's hands."</p><p>Adobe has since publicly acknowledged the issue and thanked Guardio Labs’ researchers for their help. It has also fixed the problem in version 26.7.2.0 that’s currently available for download. The extension has more than 314 million users.</p><p><em>Via </em><a href="https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ South Korea warns diplomats they could be at risk following hack on education system ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/south-korea-warns-diplomats-they-could-be-at-risk-following-hack-on-education-system</link>
                                                                            <description>
                            <![CDATA[ Initial reports are saying up to 6,000 people might have been affected. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aQk9gutRc62bND2wEnduQK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[South Korea&#039;s flag]]></media:description>                                                            <media:text><![CDATA[South Korea&#039;s flag]]></media:text>
                                <media:title type="plain"><![CDATA[South Korea&#039;s flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>South Korean government discloses ten‑month cyberattack on the National Diplomatic Academy’s online education system</strong></li><li><strong>Data stolen included user IDs, names, emails, and encrypted passwords of at least 6,000 individuals</strong></li><li><strong>MFA shut down IT systems, deployed enhanced security, and delayed disclosure due to diplomatic sensitivity</strong></li></ul><p>Current and former employees of the South Korean Ministry of Foreign Affairs (MFA), as well as other government personnel, may have had their data siphoned out by cybercriminals in an attack that lasted for ten months.</p><p>The South Korean government has disclosed an attack against the online education system of its National Diplomatic Academy. The system, set up in 2022 by the country’s premier institution for educating and training diplomats, apparently contained a security vulnerability that unnamed threat actors managed to exploit.</p><p>In an announcement published on the official website of the South Korean government, both the details about the flaw, as well as about the attackers, were not disclosed.</p><h2 id="thousands-are-affected">Thousands are affected</h2><p>However, it did note that the attack took place between April 2025 and February 2026. During these ten months, cybercriminals were able to steal user IDs, names, emails, as well as <a href="https://www.techradar.com/best/password-manager" target="_blank">encrypted passwords</a> of trainees in the National Diplomatic Academy Online Education System.</p><p>Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not compromised, it said.</p><p>In response to the attack, MFA shut down its entire IT infrastructure and deployed “enhanced security measures”, without elaborating what these measures were. It urged all employees to remain vigilant of incoming emails, and to reach out if they receive anything “suspicious”. </p><p>While the official announcement lacks details, <em>BleepingComputer</em> reported that the attack impacted “at least 6,000 individuals, 350 of them being current government attachés dispatched abroad.” Citing an MFA spokesperson, the publication said the Ministry decided to disclose the incident with a five-month delay due to the “sensitive nature” of the attack, and the need to thoroughly analyze it before going public. </p><p>"We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis," said South Korea Foreign Ministry's spokesperson Park Il.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why AI-powered network management is no longer optional ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-ai-powered-network-management-is-no-longer-optional</link>
                                                                            <description>
                            <![CDATA[ How widely is AI-based network monitoring used today and where is it headed next? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o5PeYwj88NymqERigJKuc7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 10:12:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Laurent Bouchoucha ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:description>                                                            <media:text><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:text>
                                <media:title type="plain"><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Within a short space of time, AI has made the leap from experimental technology to everyday <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> tool. Enterprises across sectors are today deploying AI to take on routine, time-intensive tasks to allow their teams to focus on more strategic tasks or work that requires human judgement. According to McKinsey, most organizations are using AI in at least one business function. </p><p>Network management and monitoring is one of the fastest-growing areas of interest. The timing is no coincidence. Technologies like <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> are driving significant increases in both network traffic and complexity, making modern infrastructure far harder to manage than it was even a few years ago.</p><p>To stay ahead, IT teams are embracing AI and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> - but how widely is AI-based network monitoring used today and where is it headed next? </p><h2 id="relieving-the-pressure-on-it-staff">Relieving the pressure on IT staff </h2><p>The task of monitoring network activity is complex and requires continual attention. It involves keeping infrastructure healthy, identifying faults, and reacting swiftly to unusual activity. These tasks were once handled manually but growing network scale and an increasingly hostile cyber threat environment have made traditional approaches hard to sustain.</p><p>IT professionals now find themselves spending a disproportionate amount of time on repetitive work such as firewall management, network provisioning, and routine monitoring.</p><p>AI addresses this directly by automating large portions of network supervision. Machine learning models can continuously process enormous volumes of network data, identifying anomalies such as traffic spikes, suspicious access patterns, or behaviors associated with known threats - and doing so in real time. This means teams can intervene before a problem becomes an outage or a <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach.</p><p>AI also sharpens focus. Rather than requiring specialists to wade through endless logs and alerts, AI-powered systems sift swiftly through these, filtering out the noise and drawing attention to only the issues that pose genuine concern. False positives are reduced, and teams can direct their energy toward real risks - including fast-moving threats that rule-based tools simply cannot keep pace with.  </p><p>Scalability is another advantage. As demand fluctuates, AI monitoring systems can expand their coverage automatically, without the need for additional headcount. In environments where networks are growing larger and more dynamic by the day, this kind of elasticity is no longer a luxury. </p><h2 id="adoption-today">Adoption today </h2><p>AI-enabled <a href="https://www.techradar.com/pro/best-network-capacity-planning-tool">network</a> monitoring is already embedded across a wide range of industries. For many networking professionals, automation and AI are now considered core operational capabilities rather than nice-to-haves. A meaningful and growing share of network management activity - covering design, deployment, maintenance, and troubleshooting - is already handled through automated processes.</p><p>However, adoption does not automatically guarantee success. Many organizations are actively deploying AI features within their network tools, and some are even training models on their own IT and security data. Yet far fewer report achieving fully successful outcomes. The gap between using AI and genuinely benefiting from it reflects the real-world difficulty of moving beyond pilots to reliable, production-grade operations.    </p><p>Two challenges consistently hold organizations back. The first is data quality - incomplete records, inconsistent formats, and poor documentation undermine AI model performance before it even gets started.</p><p>The second is skills. Many IT teams simply do not have the in-house expertise required to deploy, train, and manage AI-driven networking tools effectively, which slows progress and erodes confidence in outcomes.  </p><h2 id="agentic-ai-what-s-coming-next">Agentic AI: what's coming next </h2><p>Despite these hurdles, the direction is clear. AI-based monitoring is a crucial component in networks management, and the next evolution, agentic AI, is already beginning to take shape.</p><p>Where conventional <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> focus on detection and recommendations, agentic AI goes further. These systems can identify anomalies, diagnose root causes, predict capacity issues, and take corrective action - either autonomously or with minimal human sign-off. Rather than simply flagging problems, agentic AI is built to analyze, decide, and act, moving networks toward genuinely autonomous operations.</p><p>Consider a practical example. On a hospital campus, a staff member unknowingly connects an unauthorized access point to the network. A rogue SSID appears - a classic vector for man-in-the-middle attacks.</p><p>An agentic network management system detects the anomaly instantly, classifies the threat based on policy, and presents the administrator with a targeted remediation action: block the port or quarantine the MAC address. In sensitive environments, human sign-off is preserved by design. The AI does the analysis; the human makes the call. This is not a future concept - it is in production today. </p><p>Industry analysts expect agentic approaches to gain significant traction over the next few years, particularly in large and complex network environments. For most organizations, however, getting there will require a phased approach.</p><p>The immediate priority is deploying AI-based monitoring solutions that integrate cleanly with existing infrastructure, while ensuring teams are trained and confident in using them. As organizations build trust in their <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> quality and in the reliability of AI-generated insights, they can progressively introduce more autonomous capabilities.     </p><p>The direction is clear: the organizations that treat AI-driven network management as a strategic investment today will operate faster, more resilient networks tomorrow - while those that wait will find the gap increasingly difficult to close.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The security standard that could prevent a costly mistake with AI in hospitality ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-security-standard-that-could-prevent-a-costly-mistake-with-ai-in-hospitality</link>
                                                                            <description>
                            <![CDATA[ ISO 42001, the security standard, defines how leaders must build, deploy and govern AI. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">puoSsMrazjkugZHNfNuiQb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 09:42:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ed Gairdner ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most <a href="https://www.techradar.com/best/best-small-business-software">business</a> leaders are aware that AI adoption in their organizations has moved faster than the governance around it. When we surveyed 250 finance decision makers in mid-market organizations, we found that 83% of teams were already using AI, yet only 53% had a formal framework for its safe use.</p><p>If finance - a function with some of the highest standards for data accuracy and compliance - is operating with that kind of governance gap, it is reasonable to ask whether other departments across the business look any different.</p><p>That gap represents a risk - and it's a risk that sits squarely with the business and its leadership. So how do you encourage innovation when it comes to AI without losing control of the risks it brings?</p><p>There is an international standard designed specifically to address this: ISO/IEC 42001. It is not a compliance exercise to tick a box; it is a practical framework for governing AI responsibly, with direct implications for how business leaders evaluate the software they rely on.</p><p>For SaaS businesses, ISO 27001, the standard for information <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> management systems, has become the norm. It's a key requirement, providing assurance to customers about how the business ensures Confidentiality, Integrity and Availability for the data it hosts and processes on their behalf.</p><p>ISO/IEC 42001, published in 2023, is its counterpart for AI: the first international standard governing how organizations develop, deploy and oversee AI systems. Whether or not you pursue certification yourself, it should be a key reference point when evaluating any AI-powered software you use.</p><h2 id="why-we-need-a-standard-for-ai-security">Why we need a standard for AI security</h2><p>It's not even four years since the public launch of ChatGPT heralded the boom in use of generative AI. Not only has the technology moved at an incredible pace since then but so has its adoption in business.</p><p>We've all been told that AI will transform <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and change the world of work forever. So it's not surprising that many organizations have been racing to buy licenses and get people using it. In organizations that haven't done so, it's likely that staff are using it on the side anyway - which creates another problem: "Shadow IT".</p><p>"Shadow" AI use seems to be rife. Among the finance decision makers we surveyed, in almost half (46%) of organizations where AI hadn't been officially adopted, people were using AI assistants anyway and 30% were using AI-powered forecasting and analysis. It would be surprising if the picture looked much better elsewhere in the business.</p><p>So it's worth asking: where is the data we have spent so much effort protecting, through ISO standards such as ISO 27001, now going - and do I have visibility and control over it?</p><p>The scale of ungoverned AI use matters in any organization. ISO 42001 provides a structured way to ask the right questions, whether you are reviewing your own internal AI use or evaluating a software vendor.</p><h2 id="how-iso-42001-helps-business-leaders">How ISO 42001 helps business leaders</h2><p>Certain parts of an organization have particularly high standards for data accuracy and integrity - finance teams producing regulatory reporting, legal teams managing case records, HR functions handling sensitive employee data. ISO 42001 helps ensure those standards are reflected in the <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> and processes you use, whatever your context.  </p><p><strong>Transparency:</strong> ISO 42001 requires that AI outputs can be explained and traced. Whether AI is producing a report, performing an automated workflow or flagging an anomaly, you as the human in the loop should be able to explain what the system did and why. That human in the loop is a key component of the standard.</p><p><strong>Accountability</strong>: ISO 42001 stresses clear ownership of AI systems and their outputs. That means the use of any AI in business-critical workflows should have a defined owner who is responsible for its performance and governance. </p><p><strong>Risk management</strong>: ISO 42001 requires ongoing risk assessment for AI systems over and above those in place for ISO 27001. This doesn't usurp what you have currently in place. It complements current risk evaluation through a focus on AI and the implementation of controls to help manage that identified risk.</p><p>That means identifying what could go wrong, how likely that event is and ensuring the right controls are in place to mitigate it. Those risks might include <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> accuracy, model performance degrading, security of sensitive business data and the risk of AI acting on outputs that have not been adequately verified.</p><h2 id="the-questions-you-should-ask">The questions you should ask</h2><p>ISO 42001 offers you a useful way into important conversations with software vendors, whether or not they've achieved formal certification. It prompts some important questions.</p><p>- How are the vendor's AI systems developed, tested and monitored? The ideal response would show documented processes for keeping things accurate and trustworthy, with the human in the loop clearly built into the processes.</p><p>- How does the AI product produce its output? What happens when an output is incorrect or unexpected? It's worth understanding whether the AI outputs come from a layer bolted onto a core system and drawing on verified data from that system - or whether they are generated predictively, the way a large language model would work.  </p><p>- How does the vendor manage the risk of AI model performance changing over time? One of the frustrations of using AI is that LLMs can become less good at a task they did well before. You need to know your vendor is on top of this issue.</p><p>- What accountability exists within the vendor's organization for these AI capabilities? You need a relationship with a vendor that's prepared to take responsibility for its product and the data that flows from it.</p><p>- Does the vendor use your data to train or improve its AI models? This is a question that more business leaders are asking, and rightly so. Your data should never be used to improve a third-party model. Look for vendors who operate a zero-retention policy, meaning your data is used only in a live, read-only state and is never fed back into AI training processes.</p><p>However capable AI gets, it will not be replacing human decision-making and accountability at the top of organizations in the foreseeable future. That remains the job of leaders who need to know they are putting their names to decisions grounded in complete, accurate and trustworthy data from their own systems.</p><p>ISO 42001 is the mechanism by which you can hold AI to the same standards of accuracy, transparency and accountability that rigorous organizations have always required. It will not slow down AI adoption. But it will ensure that adoption does not come at the expense of the controls that protect your organization and your reputation.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Now that's one way to block annoying online ads —  developer uses a $5 dongle to squeeze in 537,000 domains into just 4MB of flash memory ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/now-thats-one-way-to-block-annoying-online-ads-developer-uses-a-usd5-dongle-to-squeeze-in-537-000-domains-into-just-4mb-of-flash-memory</link>
                                                                            <description>
                            <![CDATA[ Egyptian developer ZedAxis has demonstrated his $5 ad-blocking dongle in a YouTube video, with the device said to be capable of blocking over 500,000 domains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hgJXQmy92jRPLYskBp4HPF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PNsruWPMvFbCGhenSDhZyE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 23:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PNsruWPMvFbCGhenSDhZyE-1280-80.jpg">
                                                            <media:credit><![CDATA[ZedAxis/YouTube]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A USB adblocking dongle]]></media:description>                                                            <media:text><![CDATA[A USB adblocking dongle]]></media:text>
                                <media:title type="plain"><![CDATA[A USB adblocking dongle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PNsruWPMvFbCGhenSDhZyE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Egyptian developer demonstrates how to block ads with an ESP32-C3 "SuperMini" board</strong></li><li><strong>ESP32 ad-blocking dongle costs just $5 to build</strong></li><li><strong>537,000 blacklisted domains are stored in the device’s 4MB of flash memory</strong></li></ul><p>When online ads become a problem, ad-blocking software is a good idea, used in conjunction with dedicated hardware like a Raspberry Pi running Pi-Hole. But what if the device is rebooting or otherwise out of action? Egyptian developer ZedAxis claims to have developed a solution that might inspire a rethink on how online whitelisting and blacklisting is processed.</p><p>Relying on a sub-$5 ESP32-based mini board, the device somehow squeezes over 500,000 domains into paltry 4MB of onboard flash storage.</p><p>The build has been demonstrated on YouTube, with the video of the “DNS sinkhole” apparently providing how simple it is to set up. All the hard work has been done by ZedAxis, with the code available via GitHub.</p><h2 id="what-is-an-esp32-c3">What is an ESP32-C3?</h2><p>ZedAxis has built the compact Pi-Hole substitute from a $5 ESP32-C3 “SuperMini” board, easily available from online stores (currently £3.50 on the UK Amazon). These devices feature USB-C for power, Bluetooth 5.0, and crucially for a project like this, Wi-Fi.</p><p>The board has been paired with a USB adapter and a 3D-printed case to enable it to be plugged into a power source – in this case, the back of a router, but it could be a TV, console, or any other always-on device with an unused USB port. Direct access to the device is available through a web dashboard, it supports mDNS for easy discovery, and can download over-the-air (OTA) updates.</p><p>Code for the project is available on the <a href="https://github.com/M-Abozaid/esp32-c3-adblock" target="_blank" rel="nofollow">developer’s GitHub</a>, where the unusual compression that shrinks over 500,000 domains into 4MB of flash storage is explained.</p><h2 id="isn-t-that-a-lot-of-domains-for-4mb">Isn’t that a lot of domains for 4MB?</h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/RaxszOUMi8E" allowfullscreen></iframe></div></div><p>Strictly speaking, 4MB should not be able to hold 500,000 domains. As described on the project’s GitHub, the actual figure is around half that (141,000 taking up “~2.5 MB of RAM”). So how are the 537,000 domains squeezed into 4MB of RAM?</p><p>The board chosen is specifically free of PSRAM (so it just has the flash) and rather than 32-bit or 64-bit, hashes the domains into 40-bit FNV-1a, an algorithm designed for speed and low-collision rates. So, 141,000 domains can be squeezed into 0.7MB of flash, with under 50 KB of RAM apportioned for matching the blacklisted ad domains.</p><p>In most cases, the blacklist is limited to around 250,000 domains as OTA firmware updates need around 1.3MB of the flash. But this can be determined when the device is set up and the first blacklist pull is made. Other features are set to be added to this project, including set up as a DHCP server.</p><p>The big question is, could this be adopted by, say, small businesses looking for a reduction in broadband bandwidth being eaten by ad networks?</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-bizarre-new-malware-campaign-hacks-your-printer-and-forces-it-to-print-out-ransomware-demands</link>
                                                                            <description>
                            <![CDATA[ Researchers detail two incidents in Latin America in which system misconfigurations resulted in ransomware attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zcXHEpjACADHj5DbgFB367</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky detailed ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems</strong></li><li><strong>Victims’ drives were locked with BitLocker, ransom notes printed via office printers</strong></li><li><strong>New group “XEntry Team” claimed responsibility; misconfigurations remain a major breach risk</strong></li></ul><p>Cybercriminals have, in true Hollywood fashion, started using office printers to notify victims they were struck by <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>.</p><p>Security researchers at Kaspersky have <a href="https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/" target="_blank">detailed</a> two incidents which recently took place, one in Colombia, and one in Mexico, where cybercriminals took advantage of misconfigured systems. </p><p>However both had the same outcome - the attackers used BitLocker to lock down key drives, and then used office printers to print out their ransom notes.</p><h2 id="xentry-team-claims-the-attacks">XEntry Team claims the attacks</h2><p>In Colombia, a machine containing eight terabytes of mission-critical data had its Endpoint Protection Platform (EPP) disabled due to compatibility issues. It also had an internet-exposed Remote Desktop Protocol (RDP) running, which enabled relatively easy access for the attackers.</p><p>The Mexico attack was somewhat different. Three months before springing to action, the attackers discovered misconfigurations in the MSSQL service which granted them privileged access to the target environment. They spent the next couple of months lowering the server’s security settings, dropping web shells, and even though some triggered EPP alarms, the victims never investigated thoroughly.</p><p>In the Colombia case, the attackers asked for only $3,000, an offer the victims quickly accepted. Therefore, there was not enough forensic evidence left behind to conduct a thorough investigation. Kaspersky did not say how much money the attackers asked for in the Mexico case, or if the victims ended up paying or not.</p><p>In both cases, the attackers did not exploit a vulnerability, or even target an oblivious employee with social engineering. Instead, they exploited misconfigurations, which continue to be one of the biggest causes of breaches and data leaks. </p><p>“We strongly recommend configuring the RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk.”</p><p>The attacks were done by a group calling itself “XEntry Team”. There are no prior reports of this group, and it is either a previously unknown threat actor, or a simple rebrand.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple finally patches Hide My Email security flaw — a year after it was first discovered ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/apple-finally-patches-hide-my-email-security-flaw-a-year-after-it-was-first-discovered</link>
                                                                            <description>
                            <![CDATA[ A bug that was first discovered in June 2025 was finally fixed in early July 2026. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vbZdWUd8W3EzMmZrpT3jhj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[User holding an iPhone 8]]></media:description>                                                            <media:text><![CDATA[User holding an iPhone 8]]></media:text>
                                <media:title type="plain"><![CDATA[User holding an iPhone 8]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple fixes Hide My Email flaw which exposed anonymous addresses through bounced spam logs</strong></li><li><strong>Hidden emails created before July 7, 2026 may still be exposed in third‑party logs</strong></li><li><strong>Users should update and consider regenerating hidden addresses to reduce lingering exposure risk</strong></li></ul><p>A year after first being discovered, a vulnerability in Apple’s Hide My Email feature has finally been fixed - however some users will probably remain at risk until they make changes on their end, as well.</p><p>The Hide My Email feature is part of the paid iCloud+ offering and allows users to quickly create a new, anonymous email address - very handy for people who don’t want to share their email with different products across the web. It is also important since some companies tend to sell this information to third parties who then, unsolicited, start sending spam <a href="https://www.techradar.com/news/best-email-provider" target="_blank">emails</a> and various offers.</p><p>In June 2025, security researcher Tyler Murphy found a way to link these anonymous emails to the “real” addresses, making the entire service useless. He disclosed his findings to Apple, who responded with a fix. However, the issue remained, and Murphy went back-and-forth with Apple, until finally deciding to go public.</p><h2 id="was-it-finally-patched">Was it finally patched?</h2><p>Now, he says the issue had finally been resolved, but there are caveats:</p><p>“We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” he said.</p><p>Even though the bug is now fixed, he thinks the risk to Hide My Email users remains. “Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”</p><p>Apple released a working fix on July 3 2026, with users urged to update immediately.</p><p><em>Via </em><a href="https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/" target="_blank"><em>404 Media</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chick-fil-A reveals data breach — customers warned hackers may have accessed their account info ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/chick-fil-a-reveals-data-breach-customers-warned-hackers-may-have-accessed-their-account-info</link>
                                                                            <description>
                            <![CDATA[ Thousands of users in Texas alone had their data compromised and the company is now sending out notifications. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QeESsoRnBK729szx6hUpbb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Javidestock/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:description>                                                            <media:text><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:text>
                                <media:title type="plain"><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Chick‑fil‑A confirmed a credential stuffing attack between June 17–19, breaching thousands of accounts</strong></li><li><strong>Exposed data includes names, emails, membership numbers, payment details, birthdays, and addresses</strong></li><li><strong>Company logged out users, removed payment methods, restored balances, and notified multiple US states</strong></li></ul><p>Chick-fil-A is notifying its customers of a worrying cyber incident involving their sensitive information being leaked.</p><p>In a data breach notification letter being sent to affected customers, the fast food giant said it recently identified “suspicious login activity”, which prompted it to investigate further. </p><p>That investigation determined that unidentified threat actors ran a credential stuffing attack between June 17 and June 19 2026, successfully breaching an unknown number of accounts.</p><h2 id="logging-everyone-out">Logging everyone out</h2><p>A credential stuffing attack is when threat actors use automated systems to try thousands of username/password combinations against a service to see which ones work. The login credentials are usually obtained on the black market, in advance. </p><p>Since the attackers broke into people’s accounts, the data found inside was exposed. According to the notification letter, that data includes names, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, last four digits of payment cards, and the amount of Chick-fil-A credit.  </p><p>“The information may have included the month and day of your birthday, phone number, and address,” the company added.</p><p>After it discovered the intrusion, Chick-fil-A logged everyone out of their accounts and removed any stored payment methods. It also restored impacted customers’ account balances and, in some cases, added rewards to victim accounts, too. </p><p>We don’t know exactly how many people are affected by the breach, but it is definitely in the thousands. </p><p><em></em><a href="https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/" target="_blank"><em>BleepingComputer</em></a> found that the company notified the Texas Attorney General that the breach impacted 2182 of its citizens. Similar notifications went out to Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.</p><p>Chick-fil-A is one of the largest fast-food restaurant chains in the US, operating more than 3,000 restaurants across the United States, Canada and Puerto Rico. It employs over 200,000 people and generated about $10.3 billion in annual revenue in 2025.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/rental-giant-carla-leaks-user-names-emails-and-phone-numbers-ahead-of-summer-holiday-break</link>
                                                                            <description>
                            <![CDATA[ Another day, another misconfigured database discovered online. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WYtKD67awS2SDZ94euaHag</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data leak]]></media:description>                                                            <media:text><![CDATA[Data leak]]></media:text>
                                <media:title type="plain"><![CDATA[Data leak]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cybernews found Carla’s exposed AWS bucket with 48,000 PDFs containing customer rental data</strong></li><li><strong>Files included names, emails, phone numbers, rental details, and travel patterns useful for phishing</strong></li><li><strong>Carla secured the database after disclosure; no evidence of malicious access, but risk remains</strong></li></ul><p>Car rental comparison and booking platform Carla kept a database with sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.</p><p>Cybersecurity researchers from<em> </em><a href="https://cybernews.com/security/carla-car-rental-data-leak/" target="_blank"><em>Cybernews</em></a>reported finding an exposed Amazon Web Services (AWS) bucket with approximately 48,000 PDF files. These files, which was later determined belonged to Carla, contained car rental details and drivers’ personal information. </p><p>Among other things, these files held vouchers and confirmation numbers, drivers’ names, email addresses, and phone numbers, rent periods, costs, pick-up and drop-off locations, as well as general vehicle information. </p><h2 id="carla-reacts">Carla reacts</h2><p>Cybernews says the data could have been used in convincing phishing attacks. Not only would malicious actors get contact information, but they could also deduce individuals’ travel patterns, which could be used to establish trust with the victims - a crucial step in social engineering attacks.</p><p>After disclosing the findings with Carla, the company locked the <a href="https://www.techradar.com/best/best-database-software" target="_blank">database</a> down. Currently, there is no evidence that it was accessed by malicious actors in the past, but Cybernews says “if our team uncovered it, so too may have threat actors that have automated tools searching specifically for unprotected corporate data.”</p><p>The service does not own a feel of its own. Instead, it works like a travel booking site, aggregating offers from hundreds of rental providers and offering users to compare prices and reserve cars online.</p><p>Misconfigured databases continue to be one of the key causes of major data spills. Businesses often misunderstand the shared responsibility model of cloud providers, leaving systems with default settings, or setting up weak and easily guessed credentials. </p><p><em>Cybernews</em> recently also <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach" target="_blank">reported discovering an exposed ElasticSearch cluster</a> belonging to Nextcloud and containing 367,000 records of employee data, client company data, contracts, and various scripts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The hidden cyber risks facing our water supply ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-hidden-cyber-risks-facing-our-water-supply</link>
                                                                            <description>
                            <![CDATA[ Our drinking water is a clear example of how a cyberattack can cause real-world harm. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RLJptoJXDqiGUCAficKr5m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 10:21:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Vallas ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.techradar.com/best/best-online-cyber-security-courses">Cybersecurity</a> risks in water infrastructure have consequences that reach far beyond systems and networks.</p><p>Across the sector, the systems responsible for treatment and distribution are becoming more connected. Pumps, sensors and control environments that once operated in isolation are now linked to wider networks, often in the name of efficiency or modernization. </p><p>The problem is that these systems were never built with continuous exposure to cyber threats in mind and connecting them has introduced new attack surfaces that are difficult to maintain visibility of and control.</p><p>At the same time, many facilities have crept towards an increasingly blurred line between IT and operational technology (OT). Driven by incremental needs and very practical limits on systemic refresh, these systems have been added to and grown more complex over time rather than being designed securely from the ground up. </p><p>As a result, they become more tightly interconnected, with access stretching further across networks and systems than it should. Once an attacker breaches a system, it becomes far easier to move laterally across the network and get closer to critical infrastructure.</p><p>Meanwhile, cyber threats continue to encroach on the water sector, with attacks becoming increasingly frequent and their potential impact is hard to ignore. Disruptions to drinking water treatment or control systems can quickly escalate, interrupting supply or affecting water quality and, in turn, the communities that depend on them.</p><h2 id="structural-challenges-in-securing-water-systems">Structural challenges in securing water systems</h2><p>Securing water infrastructure is made more difficult by the operational realities many providers face. Technology environments have expanded over time, often without dedicated cybersecurity resources growing at the same pace, making it harder to maintain consistent oversight across increasingly ageing and disparate systems.</p><p>Many organizations are also balancing modern hyper-connected digital management expectations with the ongoing operation of originally isolated, long-established systems. This places additional pressure on teams responsible for maintaining both resilience and day-to-day continuity.</p><p>Another persistent challenge is the divide between IT and operational technology (OT) teams. Because these environments have traditionally evolved separately, with different design approaches, responsibilities, priorities and expertise, they are not always closely aligned, which can slow decision-making and create gaps in visibility during an incident.</p><p>In smaller providers, cybersecurity responsibilities may sit with operational staff whose primary expertise lies in running facilities rather than managing cyber risk. Larger organizations may have more specialized cyber teams, but greater separation between functions still introduces coordination challenges and the risk of operational blind spots.</p><h2 id="connectivity-without-constraint">Connectivity without constraint</h2><p>The growing use of <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> platforms and remote access tools has brought clear operational advantages to critical infrastructure like water systems. However, it has also reinforced a default position of keeping systems online at all times, often without a genuine operational imperative for continuous connectivity.</p><p>This “always-connected” approach can unnecessarily increase exposure, particularly as more <a href="https://www.techradar.com/best/best-asset-management-software">assets</a> become reachable across wider networks. Without clear control over the time windows when systems need to be accessible, organizations may be creating more risk than expected, certainly more than is required.</p><p>A stronger, resilient approach starts with recognizing that <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> grows by making connectivity intentional. Not every system needs to remain online continuously, and limiting unnecessary access significantly improves security outcomes.</p><p>This can be achieved by creating stronger separation between critical systems and the wider network, using controls that allow connections to be enabled only when required while maintaining essential operations. In this model, connectivity is actively managed to define resilience on demand.</p><h2 id="containment-as-a-first-line-of-defense">Containment as a first line of defense</h2><p>In the event of a vulnerability or compromise, response speed is critical, notably in environments where interconnected systems enable threats to spread rapidly across the network. Without effective connection controls in place, attackers can exploit this unconstrained accessibility to extend their reach before a full response is underway.</p><p>The ability to isolate systems in real time helps change this state. Segmenting critical parts of the network helps limit lateral movement, and deeply segmenting down to high criticality digital elements enables organizations to contain threats far more substantially and focus their efforts on speeding up the incident response.</p><p>Having this level of control helps limit the spread of disruption and supports a more structured response. It also creates clear, demonstrable evidence of how risk is being managed - something that’s becoming increasingly important as regulatory scrutiny and cyber insurance requirements become more demanding.</p><h2 id="moving-to-controlled-access">Moving to controlled access</h2><p>The most resilient model possible with physical connection control treats access to critical systems as fully conditional. Rather than keeping them permanently online, connections can be limited to where, when and why they are required for business reasons. As risk levels change, this can be refined or tightened at will.</p><p>This lowers both risk and potential impact, minimizing loss, while preserving the flexibility required for day-to-day operations.</p><p>For water providers, deliberately managing connectivity and segmenting networks at an <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> level should be a priority for resilience. Clearer boundaries and reduced unnecessary access make it easier to protect infrastructure that plays a vital role in public safety.</p><p><em></em><a href="https://www.techradar.com/best/best-ransomware-protection"><em>We've reviewed, rated, and ranked the best ransomware protection software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI says its models escaped a sandbox and breached Hugging Face ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face</link>
                                                                            <description>
                            <![CDATA[ New OpenAI models did whatever it took to achieve their goal - including exploiting zero-days. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QCjTgLYoCepWr3NrjNJs8E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 10:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI researchers confirm an AI agent escaped sandbox, exploited zero‑days, and attacked Hugging Face</strong></li><li><strong>Controlled experiment with GPT‑5.6 Sol showed autonomous chaining of vulnerabilities and credential theft</strong></li><li><strong>Security experts call it unprecedented, urging stronger AI governance, accountability, and protection models</strong></li></ul><p>OpenAI has confirmed one of its AI agents broke out of a sandbox, found and exploited zero-day vulnerabilities to gain access to the open internet, and then attacked a platform.</p><p>Not just any platform too - <a href="https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent" target="_blank">the agent was able to breach Hugging Face</a>, one of the biggest AI and machine learning companies on the Internet today.</p><p>The good news is that this was a controlled experiment done by white hat researchers. The bad news is that if it could be done by researchers - it could probably be done by malicious actors, too.</p><h2 id="whatever-it-takes">Whatever it takes</h2><p>In a <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow">blog post</a> explaining the incident, OpenAI revealed the experiment was part of its testing of GPT‑5.6 Sol and an “even more capable pre-release model” to see how well they would perform on the ExploitGym benchmark.</p><p>ExploitGym is a cybersecurity benchmark that measures if an AI agent can turn a known software vulnerability into a real, working exploit. OpenAI ran it in a “highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.”</p><p>But the models found a way through. They identified and chained vulnerabilities in the package registry cache proxy to obtain open internet access and then attacked Hugging Face, reasoning that the solutions for the ExploitGym benchmark might be found there. </p><p>“In one example, the model chained together multiple attack vectors, including using stolen credentials and <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerabilities</a> to find a remote code execution path on the Hugging Face servers,” OpenAI said.</p><p>The security community is up in arms over what OpenAI called, "an unprecedented cyber incident,” while Ansgar Dodt, VP Product Management, Software Monetization at Thales said this “demands a fundamental rethink of software protection.”</p><p>Bill Conner, president and CEO of AI integration and automation expert Jitterbit, said that while investing in AI is “critically important,” “overly aggressive policy cannot compromise AI accountability, transparency and data privacy.” </p><p>“To lead in AI, governments and organizations must lead with principles. Responsible AI governance isn’t a side note but the foundation of lasting global influence.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why you can’t buy security on the dark web ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-you-cant-buy-security-on-the-dark-web</link>
                                                                            <description>
                            <![CDATA[ Why buying, monitoring, or negotiating on the dark web often creates more risk than security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWnRmnUEZueLuNaGnKgaca</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:17:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrey Leskin ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data leaks and corporate breaches have become routine. In many cases, stolen credentials, <a href="https://www.techradar.com/best/best-database-software">databases</a>, or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.</p><p>This raises a question for <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a>: if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers? </p><p>The short answer is no.</p><p>Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.</p><h2 id="the-nature-of-the-dark-web">The nature of the dark web</h2><p>The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.</p><p>It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.  </p><p>Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, exploit kits, and attack services.</p><h2 id="the-economics-of-cybercrime">The economics of cybercrime</h2><p>A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.  </p><p>Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.</p><p>This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.</p><p>A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.</p><h2 id="dark-web-intelligence-and-false-signals">Dark web intelligence and false signals</h2><p>As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.</p><p>In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.</p><p>Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated. </p><p>The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.</p><p>As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.</p><h2 id="never-pay-cybercriminals">Never pay cybercriminals</h2><p>Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.</p><p>The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.</p><p>Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.</p><p>A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>. HBO reportedly transferred $250,000, but the material leaked anyway.</p><p>The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.</p><h2 id="common-mistakes-when-dealing-with-the-dark-web">Common mistakes when dealing with the dark web</h2><p>When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.</p><p>Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.</p><p>Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls.</p><p>Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.</p><p>Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.</p><p>Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims. </p><h2 id="what-businesses-should-do-instead">What businesses should do instead</h2><p>Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.</p><p>More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.</p><p>Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability <a href="https://www.techradar.com/best/it-management-tools">management</a>, monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why operational technology risk still slips past the boardroom ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-operational-technology-risk-still-slips-past-the-boardroom</link>
                                                                            <description>
                            <![CDATA[ Boards need to start treating OT cyber risk as an issue of business continuity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EcvSXqhDCyZJkkoKy33aYY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:04:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Louise Bulman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across the UK, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> incidents have become a familiar feature of the business landscape. </p><p>Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. </p><p>Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).</p><p>That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, affecting safety, revenue and in some cases an organization's ability to operate at all.</p><p>For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences  with data breaches or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.</p><h2 id="why-ot-risk-is-routinely-underestimated">Why OT risk is routinely underestimated</h2><p>Much of today’s operational <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> practices.</p><p>The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.</p><p>Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.</p><h2 id="when-cyber-incidents-stop-operations">When cyber incidents stop operations</h2><p>Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships </p><p>Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. </p><p>Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk. </p><h2 id="a-risk-landscape-shaped-by-geopolitics">A risk landscape shaped by geopolitics</h2><p>Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment. </p><p>At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.</p><h2 id="bringing-direction-and-discipline-to-governance">Bringing direction and discipline to governance</h2><p>Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.</p><p>Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.</p><p>Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.</p><h2 id="a-leadership-obligation">A leadership obligation</h2><p>Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.</p><p>Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn hackers could shut down entire power grids by hijacking cloud accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-hackers-could-shut-down-entire-power-grids-by-hijacking-cloud-accounts</link>
                                                                            <description>
                            <![CDATA[ AI training can create spikes in energy consumption, and these can cause all sorts of harm to a power grid. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qWzmUhTiFCkRQP6HRGFqFg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:description>                                                            <media:text><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:text>
                                <media:title type="plain"><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zhejiang University researchers warned GPU workloads could destabilize local grids and cause blackouts</strong></li><li><strong>Attackers could exploit ~1,000 GPUs to drain current and generate excess heat in systems</strong></li><li><strong>Theoretical attack dubbed Bit2Watt; mitigations include detecting malicious patterns and energy buffering systems</strong></li></ul><p>Whenever an AI data center thinks really, really hard, it can increase its power consumption so much to trigger disruptions and possibly even blackouts and gear malfunctions. So, is it possible for a malicious actor to trigger this scenario deliberately, in order to cause physical harm?</p><p>Multiple researchers from the Zhejiang University in Hangzhou, China, wrote a research paper titled “Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures.”</p><p>In it, they claim that a malicious cloud tenant is, in theory, capable of launching GPU workloads so intensive that they cause physical damage.</p><h2 id="suggesting-mitigations">Suggesting mitigations</h2><p>"Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners," the team wrote in its research paper. </p><p>"Such high-frequency modulations can substantially induce voltage excursions, harmonic distortion, and damping degradation."</p><p>An attacker could use around 1,000 GPUs to target a one-megawatt local power grid consisting primarily of distributed energy sources (such as solar panels), making it lose almost half of the electrical current, while generating around 20% more heat than usual.</p><p>"This not only threatens the availability of the computing equipment but also produces a negative damping ratio of -0.27, introducing an unstable mode into the system," the paper adds. </p><p>"Once the protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems."</p><p>AI data centers creating huge energy consumption swings is no news, and it’s a challenge some of the brightest minds of today are trying to solve. </p><p>Luckily, the attack is (still) purely theoretical, and the researchers published the paper to warn about potential misuse. They also suggested mitigations - defenders could look for malicious computational patterns, while operators should create energy buffering systems for unusual spikes in demand.</p><p><em>Via </em><a href="https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse</link>
                                                                            <description>
                            <![CDATA[ Check your calendars for entries far into the future - especially if you're an Israeli entity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LjgKxK7hkjXzxZoDby7Pxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Westend61]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:description>                                                            <media:text><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:text>
                                <media:title type="plain"><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake FBI social media scams are on the rise — here's what to look out for ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/fake-fbi-social-media-scams-are-on-the-rise-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Victims reporting crimes to the FBI are actually being caught and revictimized, leading to further financial losses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3zSRMcDm3LticiguF3F3Nh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Scammers are pretending to offer FBI support to victims</strong></li><li><strong>Victims are becoming double-victims after falling for this trap</strong></li><li><strong>FBI's IC3 warns never to pay for support – support will come from law enforcement</strong></li></ul><p>Scammers are increasingly impersonating FBI personnel and the FBI's Internet Crime Complaint Center (IC3) to defraud people who have already lost money to cybercrime, ultimately leading to them being exploited twice in quick succession by capitalizing on their weaknesses.</p><p>Attackers pose as support for recovering lost money and assisting with IC3 complaints, but the real objective is to defraud victims out of even more money or sensitive information.</p><p>But savvy victims should be able to identify these scams relatively easy, because despite a rising volume, the attack vector remains highly suspicious.</p><h2 id="victims-are-being-hit-twice-via-fake-fbi-scams">Victims are being hit twice via fake FBI scams</h2><p>Rather than targeting the FBI's website, scammers send direct messages to victims or attract them via posts or ads on social media. "Some individuals received an email or a phone call, while others were approached via social media or forums," the FBI <a href="https://www.ic3.gov/PSA/2025/PSA250418" target="_blank">explained</a>.</p><p>In the post, the FBI warns that attackers meet victims where they are, such as on Facebook, then quickly move them away to other, more secure channels like Telegram and connect them with other associates. </p><p>"The IC3 will not ask for payment to recover lost funds," the bureau warned, noting that victims should be weary of being contacted after reporting an attack. "If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers."</p><p>Victims who have either been attacked once, or attacked for a second time while trying to report the first attack, should report it via www.ic3.gov. The DOJ Elder Justice Hotline (1-833-FRAUD-11) also offers support for citizens aged 60+.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Estée Lauder says it was hit by data breach caused by Oracle E-Business issue ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/estee-lauder-says-it-was-hit-by-data-breach-caused-by-oracle-e-business-issue</link>
                                                                            <description>
                            <![CDATA[ The breach happened in August 2025, but was only spotted recently by Estée Lauder. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">695ZinBxapjgP7UfKHCgHW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Estée Lauder confirms Oracle E‑Business Suite breach from August 2025, only disclosed in June 2026</strong></li><li><strong>Attackers stole extensive personal, financial, health, and employment data from HR management platform</strong></li><li><strong>Breach tied to CVE‑2025‑61882, a critical Oracle EBS RCE flaw exploited across 100+ organizations</strong></li></ul><p>If you remember the Oracle E-Business Suite vulnerability that was exploited around October 2025 in numerous attacks, you can now add Estée Lauder to the list of victims.</p><p>The cosmetics giant has confirmed having been hit, despite the initial breach happening almost a year ago, following an investigation in mid-June 2026 uncovering the incident.</p><p>In a data breach notification letter that is now being sent out, the company said that “on June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”</p><h2 id="major-remote-code-execution-flaw">Major remote code execution flaw</h2><p>Estée Lauder said the platform was used by the holding company “for HR management purposes.”</p><p>We don’t know exactly how many people are affected by this incident, but we do know that the attackers obtained full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSN), passport numbers, financial account information (including bank account numbers), health information, and employment information.</p><p>This is more than enough data to run highly disruptive and damaging <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> attacks, and Estée Lauder’s warning is of little help coming almost a year too late. </p><p>In early October 2025, cybercriminals started mailing executives at various American organizations, claiming to have stolen sensitive files from their <a href="https://www.techradar.com/pro/security/oracle-forced-to-rush-out-patch-for-zero-day-exploited-in-attacks" target="_blank">Oracle E-Business Suite systems</a>. At the time, both Oracle and the wider cybersecurity community were not certain if the breaches actually happened, or if this was just a bluff to get the victims to pay a ransom demand.</p><p>However, the claims were soon confirmed, since more than 100 organizations reported falling victim. In early October 2025, Oracle issued an emergency fix to patch CVE-2025-61882, a 9.8/10 (critical) pre-authentication remote code execution (RCE) vulnerability in Oracle EBS. </p><p>"This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password," Oracle said in the advisory. "If successfully exploited, this vulnerability may result in remote code execution."</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-millions-of-wordpress-websites-could-be-at-risk-following-reveal-of-worrying-bugs</link>
                                                                            <description>
                            <![CDATA[ Hackers are chaining together two newly discovered flaws to achieve remote code execution. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U7wqkXxvNQXgVKZKgfnjpJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)</strong></li><li><strong>When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover</strong></li><li><strong>Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks</strong></li></ul><p>Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.</p><p>WordPress developers released a patch for two vulnerabilities - an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.</p><p>The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the world’s <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">most popular website builder</a>.</p><h2 id="exploitation-underway">Exploitation underway</h2><p>According to <a href="https://www.theregister.com/security/2026/07/20/attackers-pummel-critical-wordpress-vuln-to-create-all-sorts-of-mischief/5275265" target="_blank"><em>The Register</em></a>, these bugs are not that dangerous when looked at separately, since they are rather difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, which means full website takeover.</p><p>Security researchers at Knott say threat actors picked up on the scent rather quickly. </p><p>The patch was released on Friday, but “by the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Knott said.</p><p>“From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”</p><p>It is worth mentioning that these vulnerabilities affect WordPress directly, instead of different plugins or themes. WordPress is by far the most popular website builder platform in the world, powering more than half of all websites in existence today. </p><p>To protect your assets, make sure to upgrade WordPress to version 6.9.5, since it contains fixes for both flaws. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top AI coding agents can be easy victims to sandbox escapes, showing they aren't as secure as they claim to be ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/top-ai-coding-agents-can-be-easy-victims-to-sandbox-escapes-showing-they-arent-as-secure-as-they-claim-to-be</link>
                                                                            <description>
                            <![CDATA[ What if a host component outside the sandbox reads AI coding agents' output?  And what if that output is manipulated? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kw8ZmedvEMwdBmxvXTp6AV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Pillar researchers demonstrated sandbox escapes in AI coding agents</strong></li><li><strong>Exploits let attacker‑written configs run with trusted host privileges</strong></li><li><strong>Agentic security needs its own threat model, researchers claim</strong></li></ul><p>AI coding agents can be tricked into turning on their operators and assisting attackers in compromising the underlying systems, experts have warned. </p><p>Cybersecurity researchers Pillar have <a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes" target="_blank">examined</a> different methods of achieving the same results, finding that over the course of a couple of months, Cursor, Codex, Gemini CLI, and Antigravity were all able to reproduce sandbox escapes and boundary bypasses. </p><p>In theory, a threat actor could create a repository containing malicious content (for example, a README file, a dependency, or similar) and trick the developer into using it. The malicious instructions tell the agent to create or modify a project configuration file, but since everything happens inside the workspace, no alarms are triggered.</p><h2 id="fixing-the-problems">Fixing the problems</h2><p>Then, a host component outside the sandbox (Git integration, an IDE extension, or local daemon) reads that modified configuration, executing attacker-written commands. Consequently, the code now runs with the privileges of the trusted host component, rather than the restricted <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a>. Voila - the original sandbox boundary is effectively bypassed. </p><p>Three of the four platforms mentioned in the report have fixed the disclosed issues, Pillar said. </p><p>Cursor patched multiple vulnerabilities in version 3.0.0, with one assigned CVE-2026-48124 and another tracked through a GitHub Security Advisory. Codex CLI fixed it in version 0.95.0 but stressed that it’s still awaiting a CVE. Gemini CLI was affected by the Docker daemon issue, which the report says has also been fixed through advisory GHSA-v4xv-rqh3-w9mc.</p><p>For Antigravity, Google acknowledged both reported sandbox bypasses as valid security findings but labeled them “Other valid security vulnerabilities” and downgraded their severity. Apparently - it considers exploitation rather difficult. </p><p>“When it comes to agents, the sandbox boundary that developers expect in coding tools -- one that keeps the agent inside the sandbox and the user outside -- breaks down,” Pillar concluded. “The boundary we kept finding was both messier and porous, because If an agent gets to write the future inputs of systems, it was never sandboxed in the first place.”</p><p>“This is why agentic security requires its own threat model.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This one was different from anything we had handled before': Hugging Face confirms it was hit by cyberattack powered by an AI agent ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent</link>
                                                                            <description>
                            <![CDATA[ There's a new twist to the old code injection attack, and this one comes with AI seasoning. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YGS9VwWfcoup7Aym62fv9a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hugging Face discloses cyberattack where malicious code hidden in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft</strong></li><li><strong>The incident was unique in being orchestrated end‑to‑end by an autonomous AI agent, which launched thousands of short‑lived sandboxes and migrated C2 infrastructure across public services</strong></li><li><strong>No customer data or public models were tampered with, but the attack highlights the emerging “agentic attacker” scenario long predicted by the industry</strong></li></ul><p>Hugging Face, one of the biggest platforms for artificial intelligence (AI) and machine learning (ML), disclosed recently suffering a cyberattack supercharged by an AI agent.</p><p>“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own,” Hugging Face explained in its <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="nofollow">announcement</a>, noting that the attackers hid malicious code inside a dataset, which they then uploaded to the platform. </p><p>When Hugging Face’s automated systems processed that dataset, they exploited two software flaws which allowed the attackers’ code to run on one of the company’s servers.</p><h2 id="orchestrated-by-an-autonomous-ai-agent">Orchestrated by an autonomous AI agent</h2><p>This twist to the classic code injection attack allowed the attackers to expand their privileges and gain more control over the system, steal authentication credentials to access Hugging Face’s cloud infrastructure, and pivot to other internal systems. </p><p>But carrying the attack out mostly with an AI agent is what made this incident unique, Hugging Face explained. </p><p>Instead of a human threat actor typing commands, Hugging Face believes the attack was orchestrated by an AI-powered autonomous agent which, entirely on its own, decided which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally throughout the compromised infrastructure. </p><p>“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face explained. “This matches the "agentic attacker" scenario the industry has been forecasting.”</p><p>In other words, the agent kept launching thousands of temporary computing environments, making it extremely hard to stop the attack (since there isn’t a single machine to block). At the same time, the infrastructure controlling the malware kept moving, likely by using legitimate public cloud or online services. Therefore, when the defenders blocked one control server, the attacks would simply come from another. </p><p>Currently there is no evidence of tampering with customer data, public user-facing models, or Spaces.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Colombian energy giant Ecopetrol says thousands of user accounts hit in cyberattack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/colombian-energy-giant-ecopetrol-says-thousands-of-user-accounts-hit-in-cyberattack</link>
                                                                            <description>
                            <![CDATA[ The Ecopetrol attackers demanded a ransom payment but did not deploy an encryptor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tCkHsH74JScubYSNL54dfU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ecopetrol confirms ransomware attempt in which attackers stole data from 3,300 user accounts but failed to deploy the encryptor due to security controls</strong></li><li><strong>Stolen files were pseudonymous, with no user identities or credentials compromised; transactional systems and partner networks remained unaffected</strong></li><li><strong>The company ousted the attackers, launched an investigation, and notified Colombian authorities; no ransom demand details or data leaks have surfaced so far</strong></li></ul><p>Latin American energy producer Ecopetrol has revealed it was victim of a ransomware attack, and while the threat actors managed to get away with sensitive data from thousands of user accounts, they were unable to deploy the encryptor and thus disrupt the company’s day-to-day operations.</p><p>In a statement shared with the public, Ecopetrol explained how an unidentified threat actor accessed their IT infrastructure and pulled data from 3,300 user accounts. The attacker then proceeded to install an encryptor but was stopped by the company’s security controls. </p><p>Despite failing to deploy the encryptor, the threat actor still reached out to the company demanding payment. We don’t know how much money they asked for, in exchange for not sharing the stolen files. The database has not yet leaked, it seems, and no one claimed responsibility for the intrusion. At the same time, Ecopetrol says the stolen files are pseudonymous, suggesting that they might not be particularly useful to the attackers: </p><h2 id="notifying-the-authorities">Notifying the authorities</h2><p>“The identity of the users of the 3,300 accounts that were illegally infiltrated was not affected, nor were the respective user access credentials captured,” the machine-translated announcement reads. “Ecopetrol S.A. confirms that no compromises have been identified in the transactional technological solutions of its digital ecosystem, those of its subsidiaries, or those of its network of commercial allies, financiers, providers, and clients.”</p><p>Ecopetrol said that it managed to oust the attackers and stop further data exfiltration. It also launched an internal investigation and notified relevant authorities, including the Colombian Attorney General’s Office, the Joint Cyber Command of the Military Forces, and others. </p><p>The investigation remains ongoing.</p><p>Ecopetrol is Colombia's state-controlled oil and gas giant. It runs production, refining, transportation, and exploration operations, and is present in multiple countries, including Chile, Peru, and Bolivia. Its annual revenue is around $30 billion.</p><p><em>Via </em><a href="https://cybernews.com/news/ecopetrol-hack-colombia-ransom/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ransomware-attacks-hit-smbs-harder-than-ever-as-cybercrime-gang-rivalry-heats-up</link>
                                                                            <description>
                            <![CDATA[ Qilin and The Gentlemen are going at it, at the expense of SMBs facing more attacks than ever. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KKX2w2hiPFkYjNm9d5Yc7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading activity, far ahead of DragonForce (147)</strong></li><li><strong>US SMBs were hit hardest, suffering 769 incidents; Canada (97), Germany (83), and the UK (74) followed, while attacks on billion‑dollar enterprises surged 74%</strong></li><li><strong>Experts say rivalry between Qilin and The Gentlemen is driving the spike, with major corporate hits seen as reputation‑boosting trophies in the cybercriminal underground</strong></li></ul><p>Two ransomware gangs are battling for dominance, and US-based SMBs are the ones suffering most for it, experts have claimed.</p><p>Fresh data about the state of ransomware in 2026, compiled by security experts from NordStellar, shows two groups - Qilin and The Gentlemen - being by far the most active ones. </p><p>After analyzing more than 200 threat actor blogs, NordStellar concluded that there were 2,581 <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks in the second quarter of the year - and of that number, 299 belong to Qilin, the most active threat actor out there. Close second are The Gentlemen, with 284 attacks. The third most active group - DragonForce - doesn’t even come close with “just” 147 attacks.</p><h2 id="smbs-and-enterprises-under-assault">SMBs and enterprises under assault</h2><p>While it seems like a close race, it’s actually The Gentlemen who have been doing the heavy lifting between April and June 2026. This group experienced a 39% increase in attacks, while Qilin’s activity actually declined somewhat, compared to Q1.</p><p>In this morbid race to the bottom, the biggest victims are US-based small and medium-sized businesses (SMB). These companies, with up to 200 employees and revenues under $25 million, experienced 769 attacks in Q2 2026, followed by Canada (97), Germany (83), and the UK (74). </p><p>NordStellar also mentioned US enterprises, who are now increasingly being targeted. Attacks against organizations with revenues north of $1 billion surged by 74%, going from 23 incidents in Q1, to 40 in Q2. </p><p>“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack,” commented Vakaris Noreika, cybersecurity expert at NordStellar. </p><p>“This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ernst & Young reveals data breach following hack on support system ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ernst-and-young-reveals-data-breach-following-hack-on-support-system</link>
                                                                            <description>
                            <![CDATA[ Someone pulled sensitive customer data from EY's servers, but the data is yet to surface anywhere. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cP6va4FhPF6yEA9zg8rxz4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ernst & Young confirms breach via a third‑party IT service management platform, exposing client tax data between March 28 and April 12, 2026</strong></li><li><strong>Attackers accessed documents tied to tax support tickets; exact scope and affected clients remain undisclosed, with no dark web leaks or group claims so far</strong></li><li><strong>EY activated incident response, secured systems, and is offering 24 months of Experian identity monitoring to impacted customers</strong></li></ul><p>Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data.</p><p>In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform that helps EY staff support the teams that perform tax-related work for clients. Therefore, the tickets submitted through this platform sometimes also contain documents with client tax information which may have been exposed in the incident.</p><p>EY then activated its incident response protocols, bringing in third-party cybersecurity experts, as well as notifying relevant authorities and affected clients. </p><h2 id="free-identity-theft-protection">Free identity theft protection</h2><p>Further investigation determined that the unnamed threat actors broke in on March 28, 2026 and have, until April 12, been exfiltrating the files. EY did not say exactly which information was pulled, or how many clients were affected. We also don’t know if this only pertains to US clients, or overseas ones, as well. The attackers have, since then, been removed from EY’s virtual premises, and the systems have been secured, the company confirmed. </p><p>So far, no hacking groups claimed responsibility for this attack, and the data is yet to surface anywhere on the dark web. EY’s customers should be on the lookout for unsolicited emails, especially those claiming to be from the professional services giant. </p><p>To help them stay secure, EY is offering 24 months of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">free identity monitoring</a> and restoration services through Experian. </p><p>Ernst & Young is one of the "Big Four" largest professional services and accounting networks in the world. It is headquartered in London, but operates as a global network of independent members spanning more than 150 countries and employing more than 400,000 people. The company’s core business includes assurance, tax, consulting, and M&A strategy.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the next computing revolution will be hybrid, human and slightly unpredictable ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/quantum-finally-why-the-next-computing-revolution-will-be-hybrid-human-and-unpredictable</link>
                                                                            <description>
                            <![CDATA[ As AI drives demand, quantum is finally becoming part of real-world systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BF3vCbVgeyBLFiYJr2j9La</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 10:28:36 +0000</pubDate>                                                                                                                                <updated>Mon, 20 Jul 2026 10:31:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Harmeen Mehta ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing]]></media:description>                                                            <media:text><![CDATA[Quantum computing]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There is something poetic about quantum computing.</p><p>For decades, it has lived in the realm of possibility, whispered about in academic corridors, hyped in boardrooms, and misunderstood almost everywhere else. It promised to change everything, and yet, for the longest time, changed very little.</p><p>Until now.</p><p>Not because quantum has suddenly “arrived” - it hasn’t. But because the world around it has finally caught up.</p><p>We are, quietly, entering the age of hybrid intelligence, where classical computing, <a href="https://www.techradar.com/pro/best-ai-website-builder">artificial intelligence</a>, and quantum systems begin to work together. And that changes the question from “when will quantum matter?” to something far more interesting: What happens when quantum becomes part of how the world works?</p><h2 id="from-magic-to-mechanics">From magic to mechanics</h2><p>Quantum computing has long suffered from a branding problem.</p><p>It was either considered “Magic” because it would solve everything instantly; or a “Myth” because it was perpetually 10 years away!</p><p>The reality, as always, is more nuanced and much more powerful.</p><p>Quantum <a href="https://www.techradar.com/news/best-business-desktop-pcs">computers</a> are not general-purpose machines; they are specialists. They are exceptionally good at specific classes of problems like optimization at massive scale, molecular simulation, cryptographic analysis, complex probabilistic modelling etc.  </p><p>However, they are also fragile, error-prone, expensive and dependent on classical systems for almost everything else around them!</p><p>This leads to a simple but profound insight: Quantum will not replace classical computing. It will collaborate with it.</p><p>And that collaboration is where the real revolution begins.</p><h2 id="the-quiet-role-of-ai">The quiet role of AI</h2><p>Ironically, the biggest accelerator for quantum computing hasn’t come from within the field itself. It has come from artificial intelligence.</p><p>AI has created the conditions for quantum to matter in three critical ways:</p><ol start="1"><li><strong>Made complexity usable</strong> - Quantum algorithms are not intuitive. AI helps design, optimize, and even discover them.</li><li><strong>Improved error correction</strong> - One of quantum’s biggest challenges is “noise”. AI is now being used to stabilize and correct quantum systems in real time.</li><li><strong>Created demand </strong>- AI has exposed the limits of classical computing—particularly in energy, consumption, and scale. Quantum is no longer a curiosity; it is a necessary complement.</li></ol><h2 id="what-s-actually-working-and-what-isn-t">What’s actually working (and what isn’t)</h2><p>To understand the current state of the industry, we must separate the signal from the noise. First and foremost, what’s working is “Hybrid Workflows”. The hybrid architectures where classical systems prepare the problem, quantum executes the core computation, and classical systems interpret this result.</p><p>This is where real-world use cases are emerging.</p><p>Second, progress seems to be very domain specific as quantum is showing promise in areas where complexity explodes – drug discovery, materials science, logistics optimization, <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> modelling etc. So, it’s not universal, but selective and meaningful.</p><p>Finally, ecosystems are forming. A new stack is emerging. Companies like IBM, Google, and Microsoft are building integrated quantum platforms, while hardware innovators like IonQ and Quantinuum push the boundaries of qubit fidelity. </p><h2 id="what-s-isn-t-working-yet">What’s isn’t working ...yet</h2><p>Fault tolerance at scale needs to evolve more as we’re still far from fully error-corrected quantum systems. Also, most enterprises are still only experimenting and not deploying quantum solutions at scale.</p><p>There is no “Windows moment”, or universal standard for quantum yet; every stack looks different.</p><p>And, perhaps most importantly, quantum still requires translation, from physics to <a href="https://www.techradar.com/best/best-small-business-software">business</a> value.</p><h2 id="a-global-race-with-no-clear-finish-line">A global race… with no clear finish line</h2><p>Quantum computing has become a geopolitical priority. The United States is investing heavily through public-private partnerships; China is accelerating both research and infrastructure at a massive scale; and the UK and Europe are focused on Sovereign Quantum capabilities - ensuring they aren’t reliant on foreign stacks for critical <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><p>They are protecting their intellectual property more fiercely than they did with the internet.</p><p>This is not just about computing. It is about economic advantage, national security and scientific leadership.</p><p>And yet, unlike previous technology races, this isn’t winner-takes-all. Quantum systems will not exist in isolation. They will exist in networks.</p><p>Different players are taking fundamentally different approaches as the hyperscalers are positioning quantum as a “cloud-accessible capability”, as they abstract complexity and integrate with existing workloads.</p><p>But, as I have gone around the world talking to CEOs of various quantum companies, I am fascinated by what I call the “Plug-and-Play innovators”:</p><ul><li><strong>Hardware pure-plays:</strong> Companies like IonQ and Quantinuum focus on hardware breakthroughs - trapped ions, new materials, and improved qubit fidelity. Their bet is that that “if we solve the physics, everything else follows.”</li><li><strong>The bridge builders:</strong> Firms such as Zapata AI and QC Ware are building the bridge between algorithms and applications. Their belief is “Quantum without software is just expensive physics.”</li></ul><p>And then there is the gap. No one truly owns the interconnections between quantum and classical systems, nor the orchestration of the hybrid workloads. The missing layer is a neutral ecosystem where these players converge.</p><p>That gap will define the next phase of adoption needed for this to truly scale.</p><h2 id="what-this-means-for-society">What this means for society</h2><p>Quantum’s impact will not be immediate, but it will be profound.</p><p><strong>Healthcare:</strong> Simulating molecules at quantum precision could accelerate drug discovery from years to months.</p><p><strong>Climate</strong>: Optimizing energy grids and materials could unlock more efficient batteries and carbon capture.</p><p><strong>Finance:</strong> Risk modelling and portfolio optimization could reach entirely new levels of sophistication.</p><p><strong>Security:</strong> This is my personal passion. While quantum has the potential to break current encryption standards, it is also driving the development of Post-Quantum Cryptography (PQC), making systems more secure in the long run. We must act now to prevent "Harvest Now, Decrypt Later" attacks, where encrypted data is stolen today to be cracked by quantum computers tomorrow. </p><h2 id="a-slightly-uncomfortable-truth">A slightly uncomfortable truth</h2><p>Quantum computing will create as many questions as it answers.</p><ul><li>Who gets access first?</li><li>Who controls the infrastructure?</li><li>How do we ensure equitable benefit?</li></ul><p>We have seen this movie before with the internet and AI.</p><p>The difference this time is that we have the opportunity to design the system more deliberately.</p><p>Quantum has been “almost here” for decades. So, why does this moment feel real?</p><p>Because AI has created urgency and demand; <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> has matured to support hybrid models; and ecosystems are forming, not just technologies.</p><p>This is no longer about a breakthrough machine. It is about a connected system of capabilities.</p><h2 id="a-more-human-way-to-think-about-quantum">A more human way to think about quantum</h2><p>Perhaps the simplest way to understand quantum is this:</p><ul><li>Classical computers think in straight lines.</li><li>AI learns patterns from data.</li><li>Quantum explores possibilities simultaneously.</li></ul><p>It is less like a calculator and more like imagination. And like imagination, it is most powerful when guided.</p><h2 id="so-what-should-we-do-now">So, what should we do now?</h2><p>For enterprises, start experimenting with hybrid workflows now. Focus on use cases (optimization, simulation), not just the underlying physics, and build internal understanding early.</p><p>For policymakers, invest in open ecosystems, prioritize standards and interoperability, and balance competition with collaboration.</p><p>For technologists, think beyond silos and design for integration, not isolation. For the rest of us, stay curious.</p><p>Quantum computing will not change your life tomorrow, but it will quietly reshape the systems that your life depends on.</p><h2 id="closing-thought">Closing thought</h2><p>We often think of technological revolutions as moments.</p><p>In reality, they are transitions. Messy. Gradual. Non-linear.</p><p>Quantum computing is not a single breakthrough waiting to happen. It is a shift in how we solve problems; one that will unfold over years, across industries, and in ways we cannot fully predict.</p><p><em></em><a href="https://www.techradar.com/pro/best-it-automation-software"><em>We've featured the best IT automation software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Artificial intelligence agents need access, not secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/artificial-intelligence-agents-need-access-not-secrets</link>
                                                                            <description>
                            <![CDATA[ AI agents need trusted access without unnecessary exposure to secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o7BWuwu2HwNh9jeSK8PkKT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 09:07:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Matt Berzinski ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> security has been designed to secure an organization's human users. But as agentic enterprises take shape, the identity equation is shifting. <a href="https://www.techradar.com/phones/best-ai-phone">Artificial intelligence</a> (AI) agents and AI-powered builders – software tools used to develop websites and applications without coding – are increasingly participating in how access is configured, governed and used.</p><p>AI agents are effectively new digital <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, so organizations need a way to know they exist and control what they do throughout their lifecycle. They are becoming operators, helping to administer and secure identity environments through machine-native interfaces.</p><p>To add another layer of complexity, <a href="https://www.techradar.com/news/computing/pc/10-of-the-best-desktop-pcs-of-2015-1304391">desktop</a> agents and AI assistants are also beginning to interact with enterprise applications and resources on behalf of users.</p><p>For an agentic enterprise to succeed, these agents need trusted access to do useful work but should not be given direct exposure to secrets they have no meaningful reason to access. To achieve this, organizations need a unified, AI-first identity model, centered on end-to-end visibility, governance and controls which strike a balance between security and appropriate access.</p><h2 id="ai-agents-are-reshaping-identity">AI agents are reshaping identity</h2><p>AI has created a new category of digital identity. Like human employees, autonomous agents must be discoverable and managed and governed so organizations can understand what systems and data they can access and who is responsible for their actions.</p><p>Traditional identity and access management (IAM) systems relied on static, one-time verification methods in response to access requests made by humans. But in the agentic enterprise, requests also come from autonomous software acting on behalf of human users. Organizations therefore need to know exactly who or what is accessing a system continuously, and if they have the correct permissions to access given information.</p><p>At the same time, AI is increasingly managing identities and access. Machine-native interfaces allow agents to help manage human users’ access, troubleshoot issues and support <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> workflows. While these capabilities can help organizations cut costs and improve efficiency, they are only successful when strong access guardrails are put in place.</p><p>AI has created a new category of digital identity. Like human employees, autonomous agents must be discoverable and managed and governed so organizations can understand what systems and data they can access and who is responsible for their actions.</p><p>Traditional identity and access management (IAM) systems relied on static, one-time verification methods in response to access requests made by humans. But in the agentic enterprise, requests also come from autonomous software acting on behalf of human users. Organizations therefore need to know exactly who or what is accessing a system continuously, and if they have the correct permissions to access given information.</p><p>At the same time, AI is increasingly managing identities and access. Machine-native interfaces allow agents to help manage human users’ access, troubleshoot issues and support security workflows. While these capabilities can help organizations cut costs and improve efficiency, they are only successful when strong access guardrails are put in place.</p><h2 id="building-a-unified-identity-model-for-ai">Building a unified identity model for AI</h2><p>Mechanisms for securing AI cannot simply be bolted onto identity systems designed for humans. It requires a complete rethink of the identity management model, where human and machine identities are governed through a single framework to prevent tool sprawl and unintentional security blind spots.</p><p>As organizations adopt <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> throughout multiple operational layers, enterprise identity needs to evolve and become easier to manage and automate. Identity can no longer rely solely on human administration.</p><p>Tools designed specifically for autonomous agents, such as AI-first headless interfaces, allow builders and AI alike to perform identity-related tasks. Autonomous operators must also be trained to configure access, troubleshoot workflows and apply governance controls within approved policies and guardrails.</p><p>Visibility and governance across the entire AI agent lifecycle are also critical. As more agents are deployed, businesses must have complete visibility into their agents and actions.</p><p>Every AI should be treated as a first-class identity, with a designated human owner, as well as clear policies and full auditability throughout its entire lifecycle. As these agents operate across the enterprise, their actions should be traceable to a human user responsible.</p><p>Finally, AI agents need trusted ways to interact with enterprise resources without being given direct access to the credentials or secrets that enable them. <a href="https://www.techradar.com/pro/best-vibe-coding-tools">Coding</a> and desktop agents increasingly interact with systems on behalf of users, but exposing them to credentials or long-lived secrets creates unnecessary risk. Instead, access to enterprise resources should be brokered through just-in-time privileged controls.</p><p>This allows enterprises to maintain oversight of how permissions are granted, governed and audited without exposing the underlying secrets behind that access. Together, these capabilities create a unified identity model which extends governance across human and AI identities without creating a parallel identity stack.</p><h2 id="the-future-of-the-agentic-enterprise">The future of the agentic enterprise</h2><p>AI agents cannot operate as intended and deliver meaningful value without access to enterprise systems. But granting unrestricted access or exposing sensitive information creates an entirely new risk to organizations.</p><p>The future of the agentic enterprise depends on maintaining governance, visibility and control across both human and digital identities. This means identity must become programmable, AI agents should be governed throughout their lifecycle and agent access needs to be given without unnecessary exposure to sensitive <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>.</p><p>A unified identity strategy provides the means to operate AI agents more safely and efficiently while maintaining centralized governance, accountability and control.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint security software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Solving the energy conundrum is key to unlocking the UK’s AI economy ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/solving-the-energy-conundrum-is-key-to-unlocking-the-uks-ai-economy</link>
                                                                            <description>
                            <![CDATA[ Recent evidence shows that energy cost pressures and a power grid capacity crunch risk becoming a bottleneck on the growth of the UK’s digital economy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4nFANoy8VPwUG4iBnrXpDV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/693LkC7skU5PBHTcPsHGhK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 08:58:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sam Sherlock ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/693LkC7skU5PBHTcPsHGhK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A purple cloud with Ethernet cables plugged into it, on a purple background]]></media:description>                                                            <media:text><![CDATA[A purple cloud with Ethernet cables plugged into it, on a purple background]]></media:text>
                                <media:title type="plain"><![CDATA[A purple cloud with Ethernet cables plugged into it, on a purple background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/693LkC7skU5PBHTcPsHGhK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Recent evidence shows that energy cost pressures and a power grid capacity crunch risk becoming a bottleneck on the growth of the UK’s digital economy. </p><p>A report by Oxford Economics for the Nuclear Industry Association warns that growing grid capacity constraints and uncompetitive industrial electricity prices could drive data center developers overseas. </p><p>This comes as data center energy demands could increase fivefold by 2035 and data center operators face growing pressure for more sustainable energy in line with climate targets.</p><p>This is driving many data center developers to explore alternative supply sources such as flexible contracts and Corporate Power Purchase Agreements (CPPAs) which offer affordable, secure long-term power. </p><p>Yet many data center developers lack the resources to navigate these complex contracts or meet the high credit requirements. </p><p>There is an urgent need for creative new solutions to provide affordable sustainable power for our digital economy.</p><h2 id="the-energy-chokepoint-for-the-ai-economy">The energy chokepoint for the AI economy</h2><p>The Government aims to make Britain the fastest <a href="https://www.techradar.com/best/best-ai-tools">AI</a>-adopting country in the G7 and this will require accelerated data center expansion with AI data centers being prioritized for new demand connections to the grid. While this is welcome, demand-side connections will not alleviate the supply-side challenges from rising electricity costs to network capacity constraints. </p><p>Data centers have build times of 12-14 months yet large new renewable energy projects can face waits of 12-14 years to come online at a time when Britain faces rising non-commodity electricity costs such as  Transmission Network Use of System (TNUoS) and Nuclear Regulated Asset Base (RAB) charges to fund new electric grid and nuclear energy infrastructure. </p><p>Ofgem has warned that data center power consumption could significantly exceed Britain’s current peak electricity consumption, risking rising energy costs.</p><h2 id="the-move-towards-flexible-contracts">The move towards flexible contracts</h2><p>Flexible electricity contracts that allow companies to buy energy in chunks offer a potential solution to this by allowing data centers to tailor energy costs to their consumption. </p><p>Crucially, flexible contracts can be adjusted to hedge against fluctuating energy consumption for facilities such as AI data centers which have more variable patterns of energy use. This would also help avoid penalties for ramping up energy use to take on major new customers.</p><p>While fixed-price contracts can lock in long-term energy costs to offer certainty, flexible contracts enable data centers to take advantage of price fluctuations to secure cheaper power.</p><p>For example, we have a dedicated pricing team monitoring market movements round the clock. This could help facilities partially hedge against the risk of rising prices, setting a price for a portion of their consumption, while buying the rest when required to take advantage of favorable prices on the spot market. </p><p>For example, we implemented a flexible contract for an energy-intensive industrial chemicals company which included a cash-out arrangement, enabling them to lock in prices when costs are low and buy power in batches days or even months ahead as needed. </p><p>There are various kinds of flexible contract options based on the degree to which companies can forecast their energy consumption. For example, ‘tolerance banding’ which guarantees a set price within a certain range or ‘band’ of electricity consumption, can provide certainty amidst unpredictable, fluctuating costs. </p><p>As data center operators become more confident in forecasting energy consumption, this can create even cheaper options such as contracts that enable them to buy every kilowatt-hour above or below expected demand.</p><h2 id="the-cppa-model">The CPPA model</h2><p>Other contracts such as CPPAs could offer data centers a secure, sustainable, affordable power supply directly from suppliers at stable cost. Private-wire PPAs involving onsite generation could enable data centers to sell surplus power back to the grid, transforming energy from a cost into a revenue stream. On site generation could also help avoid the non-commodity costs for grid electricity such as TNUoS charges that comprise 60% of electricity bills and are set to increase to fund new infrastructure.</p><p>With targets to reduce operational emissions from buildings by 76%, CPPAs also help facilities meet climate targets by providing traceable green power. As large consumers with a relatively stable long-term demand, data centers are perfectly placed to tap into this market. Amidst growing energy price volatility and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> risks, fixed-price CPPAs offer the chance to lock in power prices and supplies, providing certainty and security.</p><h2 id="the-barriers-to-alternative-contracts">The barriers to alternative contracts</h2><p>Yet there are many barriers to flexible contracts and CPPAs market for smaller entities such as data centers. These contracts can be highly complex, contain stringent credit requirements and often require 10-15 year agreements. The Contracts for Difference (CfD) scheme, which gives renewable developers a government-backed route to market through fixed long-term price support, can also act as a competing route to market for generators. </p><p>In some cases, this can make long-term corporate offtake agreements less attractive, particularly where developers can secure greater certainty through the CfD mechanism. For smaller customers seeking greener electricity, however, this route can offer an alternative when a direct CPPA may be harder to access.   </p><p>Many data center projects are run by startups or smaller entities that lack the resources for such long-term commitments or credit requirements. Data centers also present a slightly higher credit risk than other facilities because their revenue streams are not based on a few large, long-term customers but split among many customers across the digital economy.</p><h2 id="opening-the-market-to-data-centers">Opening the market to data centers</h2><p>There is an urgent need for creative solutions to lower barriers to entry to the flexible contract market for smaller entities such as data centers. Security deposits or bank guarantees can help some firms meet the stringent credit requirements. </p><p>Other potential solutions include parent-company guarantees where a parent company makes a commitment to cover the cost in the event of a default or intercompany guarantees where large data center customers such as Amazon offer guarantees.</p><p>There are also solutions to simplify adoption and help CPPAs slot into existing energy use. For example, PPA import sleeving contracts, where energy is pre-purchased from a generator or utility and supplied directly to a facility through the grid, can help alleviate energy costs and security risks.</p><h2 id="tailoring-contracts-to-specific-energy-needs">Tailoring contracts to specific energy needs</h2><p>Independent partners can also help data centers optimize contracts for their specific energy needs and financial situation. Independent brokers can consolidate the process of negotiating with generators, suppliers and investors, speeding up and de-risking adoption. </p><p>Brokers can also help negotiate and monitor contracts suited to the precise profile of each data center. For example, cloud computing data centers with relatively steady, predictable demand may prefer fixed contracts whereas AI data centers processing huge amounts of data for many clients have a more variable, ‘peaky’ pattern of consumption and require flexible contracts. </p><p>Data centers can also work with partners to get live market intelligence on changing regulations or market movements. For example, we offered one client an early warning service so that they were able to minimize costs during the winter triads, half-hour periods of peak demand during the winter season.</p><h2 id="towards-a-new-model-of-data-center-energy">Towards a new model of data center energy</h2><p>Britain’s ability to compete in the accelerating AI race increasingly hinges on the ability to mitigate the risk of rising energy costs. </p><p>Energy security will also be critical to building truly sovereign AI capabilities for the UK. Lowering the barriers to the flexible contract market could create new opportunities at both ends, providing secure, sustainable and affordable power to unlock data center growth while unlocking vital investment in new renewable energy capacity. </p><p>Yet this will require tailored, adaptable contractual models from bespoke flexible contracts to PPAs and new ways of lowering barriers to entry including reducing complexity and stringent credit requirements. This could help provide secure, sustainable and affordable long-term power to fuel our digital economy.</p><p><em></em><a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites"><em>We list the best web hosting services: 60 sites tested to find the 10 fastest, most reliable platforms</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'The bypass is still six lines of JavaScript': Security experts warn that Claude for Chrome browser extension could be hijacked, despite it alerting Anthropic several times that something was wrong ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-bypass-is-still-six-lines-of-javascript-security-experts-warn-that-claude-for-chrome-browser-extension-could-be-hijacked-despite-it-alerting-anthropic-several-times-that-something-was-wrong</link>
                                                                            <description>
                            <![CDATA[ Researchers found Claude’s Chrome extension still contains vulnerabilities allowing fake clicks and permission bypasses despite Anthropic releasing multiple updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MgcPS4oDejjXRzT9jygM9c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 19 Jul 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Claude Chrome]]></media:description>                                                            <media:text><![CDATA[Claude Chrome]]></media:text>
                                <media:title type="plain"><![CDATA[Claude Chrome]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Anthropic’s Claude extension flaws allow fake clicks to launch sensitive AI workflows</strong></li><li><strong>Researchers found vulnerable handlers unchanged across eight extension updates</strong></li><li><strong>Synthetic clicks bypassed checks designed to confirm real user actions</strong></li></ul><p>Security researchers at Manifold Security have claimed Anthropic's Claude for <a href="https://www.techradar.com/computing/chrome/these-are-the-10-best-chrome-extensions-of-2025-according-to-google-and-theres-one-i-definitely-recommend">Chrome browser extension</a> contains two unpatched vulnerabilities in version 1.0.80, released July 7, 2026.</p><p>According to <a href="https://www.manifold.security/blog/claude-for-chrome-extension-bypass">Manifold Security</a>, it first reported both vulnerabilities to Anthropic through the company's bug bounty program on May 21, 2026, and received acknowledgment the following day.</p><p>The first flaw lets any browser extension trigger nine predefined Claude workflows by simulating a synthetic user click on claude.ai.</p><h2 id="nine-workflows-and-one-missing-check">Nine workflows and one missing check</h2><p>Researcher Ax Sharma found that the extension never verified whether a click event carried the Event.isTrusted property before acting on it.</p><p>Under default settings, the vulnerability received a CVSS score of 7.7 High, increasing to 9.6 Critical when users enabled automatic execution because Claude could perform actions without approval.</p><p>The nine hardcoded tasks include reading Gmail, opening Google Docs, checking Google Calendar, and modifying Salesforce leads without asking.</p><p>Because the <a href="https://www.techradar.com/best/browser">browser</a> marks synthetic clicks as untrusted, the extension should have rejected them but instead executed the workflow anyway.</p><p>Manifold Security confirmed on July 7 2026 that both vulnerabilities still work against version 1.0.80, months after first reporting them to Anthropic.</p><p>Anthropic released eight separate versions between 1.0.73 and 1.0.80 without altering the specific handlers’ researchers had already flagged as vulnerable.</p><p>The company closed the synthetic-click report, saying an existing internal report already tracked the broader trust-boundary issue researchers had described in detail.</p><p>However, Sharma believes the fix required only one additional line of code to verify the click event's isTrusted property before allowing the workflow to continue.</p><h2 id="a-second-structural-weakness">A second, structural weakness</h2><p>A second flaw involves a side-panel URL parameter called skipPermissions, which can activate a privileged mode without any consent prompt.</p><p>When the parameter is set to true, the panel begins skipping permission checks entirely, allowing Claude to act without asking the user first.</p><p>Manifold notes that only Anthropic's own scheduled-task feature is supposed to construct this kind of privileged URL internally right now.</p><p>The panel, however, honours that parameter regardless of which script or page actually constructed the originating URL string in practice.</p><p>One example task lets Claude read a user's Gmail inbox, identify promotional messages, and automatically click the unsubscribe links inside them.</p><p>Manifold warns that "the bypass is still six lines of JavaScript," months after researchers first flagged the underlying issue to Anthropic.</p><p>Anthropic classified this second finding as informational, arguing that the parameter is only ever constructed by its own internal systems.</p><p>Manifold said the content-script and side-panel code linked to both vulnerabilities remained byte-identical across the eight subsequent extension releases examined after the original report.</p><p>The flaws were also reproduced across Claude's Opus, Sonnet, and Fable side-panel model selections, indicating that the issue affected the extension's security design rather than the underlying artificial intelligence models.</p><p>The report also connected the findings with OWASP concerns involving LLM01: Prompt Injection and LLM06: Excessive Agency risks in AI applications.</p><p>The researchers noted that abuse involving <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> may remain difficult to detect because normal browser activity and network connections can appear unchanged while unauthorized AI actions occur.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FAA and federal workers forced to install $1.4 million White House app containing Russian-built Elfsight code onto government-issued mobile devices ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/faa-and-federal-workers-forced-to-install-usd1-4m-white-house-app-containing-russian-built-elfsight-code-onto-government-issued-mobile-devices</link>
                                                                            <description>
                            <![CDATA[ Official White House app faces scrutiny after researchers uncovered Russian-linked software origins, data concerns, and unanswered federal security approval questions. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C53Dyu4s3UZ8x9rG7LuKjj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MhPUPNBJzJCVca222dMMrE-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 19 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/MhPUPNBJzJCVca222dMMrE-1280-80.png">
                                                            <media:credit><![CDATA[The White House]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image showing the official white house app from The White House website.]]></media:description>                                                            <media:text><![CDATA[An image showing the official white house app from The White House website.]]></media:text>
                                <media:title type="plain"><![CDATA[An image showing the official white house app from The White House website.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MhPUPNBJzJCVca222dMMrE-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US Federal workers must install an app powered by a Russian-founded software vendor</strong></li><li><strong>Security researchers discovered outside code controlling parts of the government application</strong></li><li><strong>Elfsight’s Russian operations continued growing despite global geopolitical tensions</strong></li></ul><p>The FAA and other federal employees must now install a $1.4 million White House app containing code built by Elfsight, a Russian-founded vendor.</p><p>Elfsight was founded in 2016 in the Russian city of Tula by chief executive Andrey Yusupov and chief technology officer Vladimir Fedotov.</p><p>The company now markets itself as a European software provider headquartered in Andorra, though its original Russian entity remains active and growing.</p><h2 id="business-ties-that-persist">Business ties that persist</h2><p>In 2025, the Russian entity reported revenue of about 126.5 million rubles, roughly $1.6 million, marking a 71% increase year on year.</p><p>The company’s headcount also grew to 61 employees, and job postings show continued hiring of Russian developers into 2026.</p><p>One 2026 job posting sought a Moscow-based support specialist, offering between 60,000 and 100,000 rubles per month for full-time work.</p><p>Under Russian law, companies handling user data can be compelled to store that data locally and hand it over to state authorities.</p><p>However, an Elfsight customer support specialist claims that the company has "never received any request" from Russian authorities for user data or access.</p><h2 id="security-review-and-data-practices">Security review and data practices</h2><p>A network analysis by the security firm Atomic Computer found that Elfsight's servers determine which JavaScript files run inside the White House app.</p><p>The same session also accepted more than ten cookies from Elfsight, alongside Google DoubleClick advertising domains loaded through the app's YouTube sections.</p><p>Olivia Wales, a White House spokeswoman, said the app "does not request or collect any user locations" and called all its information "safe and secure."</p><p>A White House official later said Elfsight's only remaining script loads a tax calculator inside a sandboxed webview, disconnected from cookies or files.</p><p>The official added that Elfsight passed a full security review and is used widely by brands including UFC, FIFA, the NBA, and Cartier.</p><p>That same security clearance sits uneasily alongside records showing Elfsight's founders retained accounts at sanctioned Russian banks and kept traveling to Russia.</p><p>One founder wrote in a private message that Russian tax authorities had summoned him for questioning tied to a separate investment platform.</p><p>That legal exposure means a Russian-rooted vendor still effectively controls code running inside a mandatory application on federal government devices.</p><p>Since the Russia-Ukraine conflict started in 2022, the United States and its allies have imposed sanctions on numerous Russian companies and individuals.</p><p>It remains unclear why an app with such ties to Russia was cleared for use on White House and federal government devices in the first place.</p><p>So far, neither Elfsight nor the White House has offered a clear justification for that approval decision. </p><p>Via <a href="https://thenewsground.com/white-house-app-uses-code-from-tech-vendor-still-operating-in-russia/" target="_blank" rel="nofollow">The Newsground</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World's largest health organization threatens to jail or fire staff reading patient data 'without legal justification ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/worlds-largest-health-organization-threatens-to-jail-or-fire-staff-reading-patient-data-without-legal-justification</link>
                                                                            <description>
                            <![CDATA[ NHS England warns staff that unlawful patient record access could result in dismissal, prosecution, and prison while expanding monitoring across healthcare organizations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ohYdQvvYfm3fZk9ksNiYDc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UmHF7DXtKcHFx3arFJ9Ewh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 18 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UmHF7DXtKcHFx3arFJ9Ewh-1280-80.jpg">
                                                            <media:credit><![CDATA[Pexels]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pexels]]></media:description>                                                            <media:text><![CDATA[Hospital]]></media:text>
                                <media:title type="plain"><![CDATA[Hospital]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UmHF7DXtKcHFx3arFJ9Ewh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NHS warns curiosity over patient records could end healthcare careers permanently</strong></li><li><strong>Jail time now joins dismissal for unlawful access to confidential medical records</strong></li><li><strong>High-profile crime victims' records triggered tougher NHS privacy enforcement nationwide</strong></li></ul><p>NHS England has launched <a href="https://www.england.nhs.uk/2026/07/snooping-staff-face-sack-prison-inappropriate-access-patient-data/" target="_blank">a nationwide campaign</a> warning staff that accessing patient records without proper legal justification could end their careers.</p><p>The initiative includes screensavers and posters across NHS organisations reminding workers not to let curiosity override professional and legal boundaries.</p><p>Staff who breach these confidentiality rules risk disciplinary action, dismissal, regulatory referral, or even imprisonment under existing data protection legislation.</p><h2 id="a-response-to-recent-high-profile-breaches">A response to recent high-profile breaches</h2><p>The campaign follows several recent dismissals linked to staff who unlawfully viewed records connected to victims of high-profile crimes nationwide.</p><p>NHS England specifically cited unlawful access incidents involving the 2023 Nottingham attacks and the 2024 Southport knife attack, both of which drew significant national attention.</p><p>“Patients must be able to trust that their personal information is kept confidential by the NHS – any instance of staff looking at records without a valid reason is wholly unacceptable, a disgraceful breach of patients’ trust and against the law,” said Sir Jim Mackey, NHS Chief Executive.</p><p>He added that most staff manage patient information appropriately, although a limited group has seriously damaged that confidence through inappropriate access.</p><p>New guidance has now been issued outlining different categories of unlawful access, alongside advice on monitoring and conducting regular audits.</p><p>Some newer electronic patient record systems can reportedly flag suspicious activity in real time, helping organisations identify unauthorised access quickly.</p><p>Breaches can be reported to both the Information Commissioner's Office (ICO) and police, who may pursue criminal prosecution under the Data Protection Act 2018.</p><h2 id="legal-consequences-and-independent-findings">Legal consequences and independent findings</h2><p>The ICO reiterated the expectations of patients and staff, as well as the consequences of this illegal action.</p><p>“When people seek medical care, they share some of their most sensitive personal information in the trust that it will be kept safe,” said Paul Arnold, Chief Executive of the ICO.</p><p>“Unauthorised access to those records is not just a breach of data protection law — it is a betrayal of that trust, with real and lasting consequences for patients and their families…Staff who breach that trust face serious consequences: loss of employment, removal of professional accreditation and criminal prosecution.”</p><p>The temptation to access patient records unlawfully often increases when cases attract widespread public attention.</p><p>"When a local incident becomes national news – a serious crime, a public tragedy, a story that captures widespread attention – there is an increased risk that healthcare staff could be tempted to look at records they have no reason to view," Arnold added.</p><p>“Anyone considering accessing records for personal reasons or out of curiosity should be in no doubt they could be putting their career at risk, and may face disciplinary action, dismissal, referral to the regulator or even time in prison,” said Sir Jim Mackey.</p><p>Findings show that 18 staff members at York and Scarborough Teaching Hospitals wrongfully accessed patient records since 2021.</p><p>Eight of those 18 cases were subsequently referred onward to the ICO for further formal investigation.</p><p>Another investigation began after up to 40 staff members reportedly accessed the medical records of a three-year-old boy injured in a crocodile enclosure incident near Huntingdon.</p><p>Cambridge University Hospitals said restrictions had already been placed on the child's records and confirmed any staff lacking legitimate clinical or operational reasons would face disciplinary action, including dismissal.</p><p>Offences under the Data Protection Act 2018 and Computer Misuse Act 1990 can carry fines and prison sentences for those convicted.</p><p>The scale of these repeated incidents suggests that existing safeguards have not consistently deterred staff from unlawfully viewing sensitive records.</p><p>“Having the ability to view a record is not the same as having a legitimate need to do so. Every member of staff has a personal responsibility to respect that boundary…” Arnold added.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'You're giving ballistic ⁠missiles to individuals with Mythos': JPMorgan CEO Jamie Dimon says Anthropic's AI model poses some serious risks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/youre-giving-ballistic-missiles-to-individuals-with-mythos-jpmorgan-ceo-jamie-dimon-says-anthropics-ai-model-poses-some-serious-risks</link>
                                                                            <description>
                            <![CDATA[ Restricting Mythos to vetted organizations and keeping it out of the hands of the public seems to be the safest option for Anthropic, with JPMorgan CEO describing its risks as a “real issue.” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A8CaD6HFsE4EaCwPFME4in</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:description>                                                            <media:text><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:text>
                                <media:title type="plain"><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>JPMorgan CEO Jamie Dimon warns controls may be needed for Claude Mythos</strong></li><li><strong>The AI model from Anthropic is highly advanced, and has been proven to detect zero-day vulnerabilities and even develop working exploits</strong></li><li><strong>The US government has previously instructed Anthropic to block access to foreign nationals, citing security concerns</strong></li></ul><p>Artificial intelligence is becoming increasingly powerful, a fact highlighted with the US government’s recent instruction to <a href="https://www.techradar.com/ai-platforms-assistants/claude/we-dont-know-if-the-models-are-conscious-anthropics-ceo-isnt-sure-if-claude-ai-is-conscious-but-hed-probably-quite-like-it-if-you-upgraded-to-claude-max-just-to-find-out">limit access to Anthropic’s Claude Mythos model</a>.</p><p>Now, the CEO of JPMorgan has described the risks the technology poses as a “real issue,” and likened wide access to the AI as “giving ballistic ⁠missiles to individuals.”</p><p>Speaking at the Pennsylvania Defense ​and Innovation Summit, JPMorgan’s Jamie Dimon underscored the risks posed by the AI, which has already been shown to both identify and exploit cybersecurity challenges.</p><h2 id="mythos-isn-t-skynet">Mythos isn’t Skynet  </h2><p>Currently, Claude Mythos is limited to a small selection of organizations, companies, and federal and military departments. Public access to the AI has been blocked, and worldwide access has been blocked due to the potential security issues of this powerful AI.</p><p>Claude Mythos is not the type of threat that can become self-aware and take over military appliances like the fictional Skynet of the <em>Terminator </em>movie series. However, it does have the capacity to cause immense damage in the wrong hands.</p><p>The AI is capable of detecting cybersecurity vulnerabilities and reporting on them; it is also able to generate automatic exploits. So, for white hat cybersecurity analysts, it is a powerful defensive tool, but in the wrong hands, it is a destructive power. In addition, its automated capabilities make it easy for black hats to scale their cybercrime operation and make ransomware, phishing, and other data-based scams more profitable.</p><p>It isn’t just cybersecurity where Anthropic’s Claude Mythos AI has demonstrated such incredible capacities. Scientific research, specifically biology, can be targeted by attackers using AI to turn complex concepts into terms, potentially to misuse the information. </p><p>There is also the challenge of a strategic imbalance between single nations or bodies having exclusive access to the technology.</p><h2 id="will-the-public-ever-access-anthropic-s-claude-mythos">Will the public ever access Anthropic’s Claude Mythos?</h2><p>Given the security considerations, it seems unlikely that Claude Mythos will be publicy available anytime soon. However, Anthropic has already stated that it intends Mythos-level features and capabilities to become more widely available.</p><p>For this to happen, however, it needs to develop and apply various safeguards.</p><p>The most likely scenario is that public access to Mythos is eventually unblocked, with restrictions to specific features that relate to cybersecurity and biological/medical tasks and research.</p><p><a href="https://www.anthropic.com/glasswing">Project Glasswing</a> is already in operation with a handful of key partners (including Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, and others), and will probably be expanded until the safeguards are demonstrated to be fit for purpose, and public use.</p><p>Via <a href="https://www.reuters.com/business/finance/jpmorgan-ceo-dimon-says-anthropics-mythos-ai-risks-are-real-issue-2026-07-16/" target="_blank"><em>Reuters</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers breached DHS after alarms were twice ruled 'false positives' ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-breached-dhs-after-alarms-were-twice-ruled-false-positives</link>
                                                                            <description>
                            <![CDATA[ DHS analysts twice ruled intrusion alerts on its HSIN network "false positives", allowing hackers to have weeks of unintended access on the platform. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S7qHKNnZwz8rdwVVzTB3Ub</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/choBmEDFXmpj5ZcXHq5F5M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 19:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/choBmEDFXmpj5ZcXHq5F5M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Department of Homeland Security logo on a flag]]></media:description>                                                            <media:text><![CDATA[Department of Homeland Security logo on a flag]]></media:text>
                                <media:title type="plain"><![CDATA[Department of Homeland Security logo on a flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/choBmEDFXmpj5ZcXHq5F5M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>An internal DHS readout shows analysts twice dismissed intrusion alerts on the HSIN information-sharing network as false positives</strong></li><li><strong>This effectively gave hackers roughly three weeks of undetected access before a breach was declared on June 4 2026</strong></li><li><strong>The as-yet anonymous attackers altered server files, ran malicious code through a legitimate web-server program, deleted logs, installed backdoors, and stole credential files</strong></li></ul><p>Hackers managed to find their way into the US Department of Homeland Security's primary information sharing platform, gaining unfettered access to the HSIN network that hosts unclassified information that multiple US agencies and international rely on.</p><p>The hack allowed the attackers to modify server files, run malicious code and steal credential files while installing backdoors and deleting logs to remove their digital footprint.</p><p>Their movements were flagged twice by automated systems and analysts in May 2026, before being dismissed as a false positive each time before an active breach was declared a month later.</p><h2 id="bad-timing-meets-bad-security-practices">Bad timing meets bad security practices?</h2><p>The timing and specifics of this intrusion are, in particular, details which could prove to be embarrassing for the US government. </p><p>Not only does the HSIN network serve as a key intelligence-sharing tool for both domestic and international partners during the FIFA World Cup, but it also hosts information on other major events, such as America250.</p><p>The fact that the hack was picked up not once, but twice by flags before being dismissed as a false positive raises competency concerns for an instance that has already sparked interest, with the House Homeland Security Committee staff having already requested a briefing on the intrusion.</p><p>The DHS, for its part, is downplaying the incident, with a spokesperson confirming it but characterizing it narrowly: the department is "aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment" and states there is no indication that classified networks were affected.</p><p>This <a href="https://www.warner.senate.gov/newsroom/press-releases/senate-intel-vice-chair-warner-statement-on-breach-of-dhs-information-sharing-network/" target="_blank">viewpoint is countered</a> by Senate Intelligence Committee Vice Chairman Mark Warner, who argued the platform's sensitivity outstrips its classification level, saying that the information in HSIN, "while not classified, is highly sensitive, and its exposure risks national security."</p><p>Investigators have yet to identify or assign blame to a particular hacking group or organization, adding to the chaos in determining motive. The hackers have deleted logs on servers, which only adds to the confusion here.</p><h2 id="major-implications">Major implications</h2><p>The important question, perhaps, is not how the breach happened, but why confusion and mischaracterization of the security lapse allowed it to become a much bigger issue than it would have been if it had been contained from the start. Despite security flags and analysts highlighting the breach as early as the 15th of May, the hackers essentially had free rein to operate until at least the 3rd of June thanks to initial reports being dismissed as false positives.</p><p>HSIN as a platform handles event security planning, interagency coordination, threat information, and details on persons of interest. Whether any of that material was actually copied remains unknown. Investigators have not determined what, if anything, was exfiltrated, though the theft of credential files is itself telling: attackers who steal credentials are, almost by definition, trying to reach systems and accounts beyond their initial foothold.</p><p>This is not the first time HSIN has been compromised, with two documented previous incidents, including a compromised account in 2009 and misconfigured access in 2023, that have resulted in intentional and unintentional breaches of the network.</p><p>The issue is only exacerbated by the fact that the DHS, along with its cybersecurity agency, CISA, has absorbed significant workforce cuts over the past year, potentially weakening its defenses against sophisticated hacks that require manual human intervention or oversight to detect, even when the correct flags (which triggered as intended) are already in place.</p><p>Such manpower shortages have also been politically polarizing in the US Congress and may be highlighted when the department provides more detailed information about the hack in the coming days, even as the Pentagon deals with its own OPSEC issues that are <a href="https://www.techradar.com/pro/us-soldiers-personal-phones-allowed-enemies-to-track-positions-and-target-troops-in-real-time-pentagon-reveals" target="_blank">also being aired in the same forum</a>.</p><p>Via <a href="https://www.defenseone.com/threats/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414748/" target="_blank"><em>DefenseOne</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to trick Apple users into revealing their passwords ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated-threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clicklock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords</link>
                                                                            <description>
                            <![CDATA[ ClickLock bores its victims into complying and then steals all sorts of data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rTfuMcJQcWwgFKNJxEtbqi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new GoSerpent malware is apparently on the hunt for government secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/dangerous-new-goserpent-malware-is-apparently-on-the-hunt-for-government-secrets</link>
                                                                            <description>
                            <![CDATA[ The malware has been hiding in plain sight for half a decade, stealing all sorts of valuable secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vjht9Nb5f4HTL3RNE3U26G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:description>                                                            <media:text><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky uncovers GoSerpent, a long‑running campaign on Southeast Asian government systems using a backdoor, RAT (Stowaway), and exfiltration tool (TmcLoader)</strong></li><li><strong>Attackers showed extreme patience, waiting weeks before deploying secondary tools to evade detection and outlast log retention policies</strong></li><li><strong>Attribution remains uncertain, but overlaps with past TetrisPhantom operations; defenders are urged to review shared IoCs to detect compromise</strong></li></ul><p>Security researchers Kaspersky discovered a five-year-old piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that’s been hiding on government computers in the Southeast Asian region, harvesting secrets and other actionable intelligence.</p><p>The company analyzed a campaign called GoSerpent, which comprises of a backdoor of the same name, a Remote Access Trojan (RAT) called Stowaway, and a two-stage data exfiltration tool called TmcLoader.</p><p>The backdoor was first used in 2021, it was said, meaning it was successfully hiding for half a decade. This was achieved, among other things, with plenty of patience and careful planning.</p><h2 id="tetrisphantom">TetrisPhantom</h2><p>“What stands out about GoSerpent is the deliberate dwell time,” Noushin Shabab, Lead Security Researcher in Kaspersky GReAT, explained. </p><p>“Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft." </p><p>The researchers could not conclusively attribute this campaign to any particular threat actor but did say that it has a lot in common with older campaigns conducted by the TetrisPhantom actor, including victimology, technical capabilities, and operational methods. </p><p>Kaspersky analyzed TetrisPhantom back in 2023, when it saw the group compromising <a href="https://www.techradar.com/pro/security/dangerous-new-malware-can-crack-encrypted-usb-drives" target="_blank">secure USB drives</a> used to provide encryption for safe data storage. This campaign also targeted government entities in the Asia-Pacific region (APAC) but, at the time, it was a newly discovered threat actor with no overlap with other known groups. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europe’s tech reset gives the UK a chance to lead on security and sovereignty ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/europes-tech-reset-gives-the-uk-a-chance-to-lead-on-security-and-sovereignty</link>
                                                                            <description>
                            <![CDATA[ The UK has a profound opportunity to become a trusted partner for secure, resilient digital infrastructure. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X4NFAykiUYZKgHPbDk2wQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:26:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Knibbs ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/TippaPatt]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:description>                                                            <media:text><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:text>
                                <media:title type="plain"><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across Europe, “tech sovereignty” is rising up the agenda. For business leaders, however, the implications are practical rather than political. At its core, sovereignty is about control, resilience and trust in the systems that underpin modern operations.</p><p>The European Commission’s recently announced technology sovereignty package reflects this shift. With proposals including the Chips Act 2.0, the Cloud and AI Development Act, an EU Open-Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy, it is intended to strengthen Europe’s digital independence and resilience.</p><p>That matters because <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> is now vital infrastructure. Cloud platforms, connectivity, AI systems and cyber security capabilities are becoming as essential to economic growth and national stability as energy and transport networks.</p><p>For years, digital transformation was driven by globalization, scale and efficiency, with organizations prioritizing rapid innovation, cost optimization and access to global technology ecosystems. </p><p>But cyber-attacks, regulatory divergence and geopolitical uncertainty have exposed a fundamental reality: efficiency without resilience creates fragility.</p><h2 id="from-efficiency-to-resilience">From efficiency to resilience</h2><p>Today, organizations are focused not only on whether systems can withstand cyber-attacks, but whether they can keep operating if a provider, jurisdiction or supply chain becomes unavailable.</p><p>Protection and prevention remain essential. But resilience also depends on where systems are hosted, who controls critical infrastructure, how data moves across jurisdictions and whether essential services can be restored quickly during disruption.</p><p>Sovereignty is best understood as the ability to continue functioning with confidence when external conditions change. This is particularly relevant for organizations delivering critical services. </p><h2 id="why-this-matters-for-the-uk">Why this matters for the UK</h2><p>The UK faces many of the same pressures as Europe: rising cyber threats, tighter regulation and rapid AI adoption. But it also has real strengths, including a mature <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cyber security</a> sector, world-leading professional services expertise, and a strong reputation for governance and innovation.</p><p>Those strengths give the UK a significant opportunity to position itself as a trusted partner for secure, resilient digital infrastructure. Realizing it, however, will require continued investment in infrastructure, skills and technology ecosystems.</p><p>The UK already has strong foundations. Within Vodafone Business, for example, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> services for government and defense customers date back to 1989, underlining the long-term importance of trusted communications and secure operations.</p><h2 id="sovereignty-must-include-ai">Sovereignty must include AI</h2><p>The sovereignty conversation is no longer limited to networks, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> infrastructure or cyber security; it now extends to AI itself.</p><p>The UK government’s recent £400 million commitment to next-generation AI chips reinforces that ambition and signals a more deliberate push to build sovereign capability in the technologies that will underpin future competitiveness and resilience. </p><p>Government investment in sovereign computing capability and broader AI infrastructure also signals recognition that access to advanced computing resources is becoming a strategic national asset.</p><p>This matters because AI is rapidly becoming foundational infrastructure. Organizations are embedding it into business operations, cyber security programs, customer engagement and decision-making.</p><p>For businesses, sovereignty is not about limiting innovation. It is about ensuring critical capabilities can be developed, governed and accessed in ways that support long-term economic resilience and trust.</p><h2 id="connectivity-as-critical-infrastructure">Connectivity as critical infrastructure</h2><p>One of the most important and often overlooked aspects of sovereignty is connectivity. As organizations rely more on AI services, IoT devices and real-time data exchange, networks become the foundation of operational resilience.</p><p>If connectivity fails, everything built on it is affected, from customer services and supply chains to communications and core business operations.</p><p>That is why investment in secure, resilient, high-capacity networks is central to the sovereignty debate. Without trusted connectivity, digital sovereignty remains theoretical rather than practical.</p><p>The formation of VodafoneThree is a significant step in strengthening the UK’s digital backbone. With a commitment to invest £11 billion in next-generation connectivity and an ambition to deliver 99.96% population coverage by 2034, the UK is building infrastructure to support future growth and resilience.</p><p>As AI workloads, edge computing, hybrid working and data-intensive applications expand, resilient connectivity becomes a strategic national asset.</p><p>This is particularly important for organizations delivering essential services. Today, 77% of UK Blue Light services already run on Vodafone Business networks, underlining the growing importance of trusted connectivity in critical operations.</p><h2 id="a-strategic-moment-for-the-uk">A strategic moment for the UK</h2><p>Europe’s emerging sovereignty agenda should not be mistaken for digital isolation. Rather, it reflects a growing recognition that interdependence must be understood, managed and secured.</p><p>For security leaders, that means broadening the conversation beyond traditional threat protection to include critical dependencies, digital supply chain resilience and operational continuity. Cyber security is increasingly part of a wider discipline of digital resilience, where security, connectivity, infrastructure and governance converge.</p><p>By combining cyber security expertise, growing sovereign AI capabilities, regulatory strengths and continued investment in connectivity, the UK has an opportunity to establish itself as Europe’s trusted security ally.</p><p>In the next phase of digital transformation, success will not belong only to those with the most advanced technology, but to those with the most trusted, resilient and transparent foundations.</p><p>The sovereignty economy is already taking shape. The question is whether the UK chooses simply to participate in it, or to help define it.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We've reviewed and rated the best business cloud storage services</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Claude can now enter all your passwords for you - if you give it permission ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/claude-can-now-enter-all-your-passwords-for-you-if-you-give-it-permission</link>
                                                                            <description>
                            <![CDATA[ 1Password partnership will mean Claude will never see the secrets or load them into its own memory. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gESvv4V9PcQSPAyMJnfqm6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile phone displaying a Claude login screen.]]></media:description>                                                            <media:text><![CDATA[Mobile phone displaying a Claude login screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile phone displaying a Claude login screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>1Password unveils Claude partnership, letting Anthropic’s AI authenticate on users’ behalf via zero‑exposure architecture</strong></li><li><strong>Users approve each login with biometrics</strong></li><li><strong>New Agentic Mode in the browser extension locks down the interface when AI agents take over</strong></li></ul><p>Top <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a> company 1Password has launched a new tool that allows artificial intelligence assistant Claude to authenticate on behalf of their user, and thus complete assignments that were previously impossible without major security tradeoffs.</p><p><a href="https://1password.com/blog/1password-for-claude" target="_blank" rel="nofollow">1Password for Claude</a> is built on “zero-exposure architecture” - so in practice, it means Claude can essentially ask 1Password to complete the sign-in process, but it will never see the credentials, and they will never be loaded into its memory. </p><p>In turn, 1Password will notify the user, and will request biometric approval before proceeding. Once granted, it will autofill the credentials and check to see if they were exposed on the page or not. If submission fails, it will clear the filled values and report back. </p><h2 id="agentic-mode">Agentic Mode</h2><p>"We need a new security model that is purpose-built for agents, not just humans,” said Nancy Wang, CTO of 1Password. “The answer isn't handing agents your secrets. It is to let a user give an agent permission to use a credential without letting the agent see it. Claude knows it used your login; it does not need the password or one-time code in its context. That distinction is where trust in agents starts and the foundation we're building with Anthropic."</p><p>To further strengthen its security posture, 1Password also announced Agentic Mode, a new feature in the browser extension that gives users visibility and control over browser-based <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>. When a compatible AI agent takes over, the 1Password extension automatically locks down and hides the interface. The agent can only use the logins and OTPs explicitly approved for the current task. </p><p>Even if the integration is not set up, and even if 1Password is not required for the current agentic task, Agentic Mode works, the company stressed. Other agents, besides Claude, are supported, as well. </p><p>Currently a major debate is ongoing, about how much permissions AI agents should receive, and under what rules. We’ve already seen horror stories of AI agents deleting people’s entire email inboxes, or otherwise ruining days of hard work. Whether or not this picks up or most people remain skeptical about giving AI access to certain services, remains to be seen. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is sovereignty threatening your resilience? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/is-sovereignty-threatening-your-resilience</link>
                                                                            <description>
                            <![CDATA[ Sovereignty has entered a hype-cycle, and organizations risk missing the bigger operational picture. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rMdcuBG65eFf5gJc3ZQddV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/p2uWFBGHtrHTjrYSDny87M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 13:55:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Matt Johnson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/p2uWFBGHtrHTjrYSDny87M-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A data center with racks of servers and lots of lights glowing]]></media:description>                                                            <media:text><![CDATA[A data center with racks of servers and lots of lights glowing]]></media:text>
                                <media:title type="plain"><![CDATA[A data center with racks of servers and lots of lights glowing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/p2uWFBGHtrHTjrYSDny87M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The question of where <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> lives has become considerably more fraught over the past few years. </p><p>A mix of regulatory scrutiny, geopolitical tensions across the Atlantic, and the related unease about the concentration of infrastructure power among the hyperscalers have all combined to push data sovereignty up the executive agenda. </p><p>The result? A strategic posture that’s increasingly shaped by political anxiety rather than operational logic. </p><p>And while both need to be considered by the boardroom, leaning too much on the former leads to very different decisions.</p><p>To be clear, there’s no debate that compliance with data residency requirements remains a genuine obligation for organizations in regulated industries, and nobody is suggesting otherwise. </p><p>The concern is with what comes next: many organizations are at the "we must manage our data carefully" stage, and are considering a leap to "we should consider exiting hyperscaler <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> entirely." While the logic could be understandable, the reality is that full disengagement is neither effective nor necessary for the bulk of organizations. </p><p>The hyperscalers earned their position because they offered capabilities that were genuinely difficult to replicate at scale, and the organizations that depend on them most deeply are not in a position to unwind that dependency in any near-term timeframe. A multi-year transformation program with substantial execution risk is rarely the right answer to a political concern that may itself shift within that same period.</p><h2 id="conflating-data-residency-and-operational-resilience">Conflating data residency and operational resilience</h2><p>The focus on sovereignty has meant that ideas about data residency, infrastructure control, and operational resilience are being treated as interchangeable concepts. While connected, these are distinct ideas with distinct impacts on a business’s ability to function effectively and comply with regulation. </p><p>Let’s consider the incidents that really bring organizations down, and what makes <a href="https://www.techradar.com/best/best-data-recovery-software">data recovery</a> harder than it needs to be. It’s system failures, slow incident response, and exploited security vulnerabilities that take customer-facing services offline, erode trust and incur regulatory fines. A platform that fails during peak demand causes the same commercial and reputational damage regardless of where its data is stored. </p><p>Similarly, a <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach does not become more or less severe based on whether it occurred on domestic or international infrastructure. The metrics that determine whether an organization functions under pressure are uptime, security posture and the quality of incident response capability. Sovereignty is one input to that picture, not the frame through which the whole picture should be viewed.</p><p>Simply put, an organization is not resilient simply because its data sits in the right jurisdiction. Resilience is an architectural and operational property that has to be built deliberately.</p><h2 id="where-real-control-lives">Where real control lives</h2><p>If sovereignty decisions are best understood as one component of broader operational resilience, then the more productive question is where in the stack is control most effectively exercised. The answer, particularly as <a href="https://www.techradar.com/best/best-ai-tools">AI</a> applications proliferate, is primarily at the data layer.</p><p>The <a href="https://www.techradar.com/best/best-database-software">database</a> has moved beyond its traditional role as a storage mechanism. In modern architectures, it is often the most reliable point of deterministic control in the entire stack: the place where governance is enforced in practice rather than documented in policy. </p><p>Data location, <a href="https://www.techradar.com/best/best-encryption-software">encryption</a>, access controls, cross-region movement – all of these are data infrastructure questions at heart. Getting them right is what makes meaningful sovereignty achievable, not as a political statement, but as an operational capability.</p><p>So in turn, when an organization has genuine control over governance at the data layer, suddenly the choice between a hyperscaler and a fully domestic alternative becomes less relevant. The question shifts from which provider to use to whether the infrastructure is flexible enough to enforce the appropriate rules for each workload. That reframing tends to produce considerably better outcomes.</p><p>In practice, this means building in tiers: cloud-native performance where the business requires speed, scalability and flexibility, on-premise or segmented deployments for regulated workloads, and the architectural flexibility to move between configurations as circumstances change. After all, regulations will continue to evolve. </p><p>The geopolitical environment that is currently driving sovereignty conversations will look different in three years. That means infrastructure decisions made under today's conditions need to remain workable under tomorrow's.</p><h2 id="building-for-change-not-for-certainty">Building for change, not for certainty</h2><p>The practical implication for technology leaders is straightforward: meet your regulatory obligations, exercise genuine control at the data layer, and build the architectural flexibility to adjust as requirements shift. </p><p>But after that, it’s important to give equal attention and consideration to the failure modes that are statistically far more likely to cause very tangible and costly problems: outages at peak load, delayed incident responses and vulnerabilities that could be exploited. </p><p>At the end of the day, those are far likelier to be discussed in post-mortems – not sovereignty. And while sovereignty deserves its place in the technology strategy conversation, it should sit within a resilience framework, not above it.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-databases"><em>We've featured the best cloud databases</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Coca-Cola shuts down Fairlife dairy production lines following ransomware attack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/coca-cola-shuts-down-fairlife-dairy-production-lines-following-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ Coca-Cola confirms ransomware attack on Fairlife in an 8-K form filed with the SEC. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">98MXZYAA7TvT8EPNELLnKY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png">
                                                            <media:credit><![CDATA[Coca-Cola]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:description>                                                            <media:text><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:text>
                                <media:title type="plain"><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Coca‑Cola confirmed a ransomware attack on its dairy subsidiary Fairlife, forcing suspension of US production operations while Canada sites remain unaffected</strong></li><li><strong>Incident response protocols were activated, with third‑party experts and authorities engaged; product quality and safety were not impacted</strong></li><li><strong>Analysts warn the financial impact could be significant given Fairlife’s importance, with losses compounding the longer production remains offline</strong></li></ul><p>Coca Cola was forced to shut down parts of its operations to tackle an ongoing ransomware infection.</p><p>In an 8-K form recently filed with the US Securities and Exchange Commission (SEC), the company said the attackers struck Fairlife, its dairy company.</p><p>“On July 16, 2026, The Coca-Cola Company announced that fairlife, a dairy company owned by the company, identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> event,” the filing reads.</p><h2 id="compounding-impact">Compounding impact</h2><p>Coca Cola then explained that it kicked off its incident response and business continuity protocols, bringing in third-party cybersecurity experts to help investigate the attack and assess the damages. It also notified relevant authorities.</p><p>However, the production in the US has been affected, since parts of the operation had to be suspended: “Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are not currently impacted,” Coca Cola explained.</p><p>It said it was now working to bring the systems back up, and that it has “not yet determined whether the incident is reasonably likely to materially affect the company.”</p><p>In a statement shared with TechRadar Pro, Cybersecurity Researcher and Advanced Services Lead at Arcova, Joseph Perry, stressed that the material impact is likely to be great. How great - depends on how fast Coca Cola moves. </p><p>“Fairlife is not a minor business buried inside Coca-Cola’s portfolio. Coca-Cola generated nearly $48 billion in net revenue last year and made a $6.1 billion contingent payment tied to its acquisition of fairlife, which provides important context for the value of the operation now sitting idle,” Perry explains. </p><p>“With production suspended across fairlife’s US facilities, every hour can compound the financial impact through lost output, delayed shipments, recovery costs, inventory exposure and potential disruption for retailers. Coca-Cola has not yet quantified the loss, but the longer production remains offline, the more quickly a cyber incident becomes a material business event.”</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Teenage TfL hackers sentenced to years in prison following Scattered Spider attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/teenage-tfl-hackers-sentenced-to-years-in-prison-following-scattered-spider-attacks</link>
                                                                            <description>
                            <![CDATA[ Two young men pleaded guilty to hacking into Transport for London in 2024 and were given long prison sentences. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SLBSG4pbDpZE9xtCXUuJpP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Two UK men sentenced to 5 years and 6 months for the 2024 cyberattack on Transport for London, linked to the Scattered Spider group</strong></li><li><strong>Police seized devices showing evidence of the TfL breach; Flowers was also mid‑attack on US healthcare firms SSM Health and Sutter Health at the time of arrest</strong></li><li><strong>TfL reported $39M in damages; the NCA says the sentencing effectively dismantled Scattered Spider, with Microsoft confirming the arrests degraded the group’s operations</strong></li></ul><p>Two young men, one aged 20 and the other 18, have been sentenced to five years and six months in prison for their involvement in the <a href="https://www.techradar.com/pro/security/tfl-admits-2024-cyberattack-may-have-affected-over-10-million-people-personal-customer-info-stolen-heres-what-we-know-so-far">cyberattack on Transport for London (TfL)</a> in 2024.</p><p>Thalha Jubair, from East London, and Owen Flowers, from Walsall, West Midlands were arrested in 2025 under the suspicion that they were the leading members of <a href="https://www.techradar.com/pro/security/fbi-cisa-warn-of-more-scattered-spider-attacks-to-come">Scattered Spider</a> - an infamous hacking collective known for breaching dozens of companies. Initial reports from different cybersecurity organizations claimed the group consisted mostly of teenagers whose native language was English. </p><p>During the arrest, the police seized different types of electronic equipment from the suspects, including laptops, PCs, smartphones, hard drives, removable storage, and more. On one of the computers, law enforcement found screenshots and videos showing the intrusion into TfL’s systems.</p><h2 id="millions-in-damages">Millions in damages</h2><p>To make matters even worse, Flowers was in the middle of breaking into US healthcare companies SSM Health Care Corporation and Sutter Health when he was arrested: According to the National Crime Agency (NCA), these two were already “infiltrated and damaged”.</p><p>The attack on TfL was one of the more disruptive incidents that year, and one which caused a lot of financial damage, too. According to a report TfL shared with the City of London Police (CoLP), it suffered around $39 million in loss and recovery costs.</p><p>Both Jubair and Flowers initially pleaded not guilty and changed their pleas to guilty on the day they were due to stand trial, it was said. Now, they are both sentenced to more than five years in jail. The NCA says these arrests and sentencing effectively dismantled the notorious hacking collective.</p><p>“Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity,” the NCA said in its <a href="https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case" target="_blank" rel="nofollow">report</a>. </p><p>“Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group's ability to continue conducting cybercriminal operations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Human-led, AI-assisted testing: Why AI won’t replace penetration testers...yet. ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/human-led-ai-assisted-testing-why-ai-wont-replace-penetration-testers-yet</link>
                                                                            <description>
                            <![CDATA[ Why human expertise remains essential in AI-powered testing. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">skJxAJL5jBKg7eJH8sZoHV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 11:00:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Shaun Peapell ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over the last year, one topic has dominated conversations across the <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> industry:<a href="https://www.techradar.com/best/best-ai-tools"> artificial intelligence</a>.</p><p>Every week seems to bring another announcement, another capability, or another prediction about how AI will transform security. In offensive security, the discussion has become particularly intense. We are seeing AI-assisted vulnerability discovery, AI-generated attack simulations, AI-powered analysis tools, and increasingly bold claims about autonomous security testing. </p><p>The question I am asked most often is surprisingly simple:</p><p>“Will AI replace penetration testers?”</p><p>My answer is equally simple:  No.</p><p>What AI will do is change how penetration testers work.</p><p>And in many ways, it will make experienced penetration testers even more valuable.</p><h2 id="ai-is-already-changing-security-testing">AI is already changing security testing:</h2><p>Let’s start with the obvious.</p><p>AI is genuinely impressive.</p><p>Modern AI models can process vast amounts of information, identify patterns, summarize findings, correlate data sources, and surface potential issues far faster than any individual analyst could achieve manually.</p><p>Within offensive <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, AI is already helping teams:</p><ul><li>Identify vulnerabilities more quickly</li><li>Analyze large datasets</li><li>Correlate findings across environments</li><li>Surface potential attack paths</li><li>Generate documentation and reporting</li><li>Reduce repetitive manual tasks</li></ul><p>These are meaningful improvements.</p><p>Many of the activities that traditionally consumed valuable consultant time can now be accelerated significantly.</p><p>As a result, organizations are gaining greater visibility into their environments than ever before.</p><p>But visibility alone has never been the ultimate goal.</p><h2 id="finding-vulnerabilities-has-never-been-the-hard-part">Finding vulnerabilities has never been the hard part:</h2><p>One of the biggest misconceptions in cybersecurity is that finding vulnerabilities is the primary challenge.</p><p>It isn’t.</p><p>Understanding risk is.</p><p>Most organizations already have access to large amounts of security <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>. They run vulnerability scanners. They receive penetration testing reports. They consume threat intelligence. They deploy attack surface management tools. They monitor logs and alerts.</p><p>The problem is rarely a complete lack of information. The problem is understanding what matters.</p><ul><li>Which vulnerabilities are genuinely exploitable?</li><li>Which attack paths represent realistic threats?</li><li>Which issues require immediate remediation?</li><li>Which findings can safely wait?</li></ul><p>These questions are considerably harder to answer than simply identifying a vulnerability. And they are questions that require context.</p><h2 id="context-is-where-human-expertise-matters">Context is where human expertise matters</h2><p>A vulnerability rarely exists in isolation.</p><p>The real-world risk associated with any finding depends on a range of factors, including asset criticality, business impact, compensating controls, user privileges, environmental configuration, attacker motivation, and the relationships between multiple weaknesses.</p><p>This is where experienced penetration testers provide value that AI alone cannot replicate.</p><p>When performing an assessment, we are not simply identifying vulnerabilities. We are thinking like attackers.</p><p>We are asking questions such as:</p><ul><li>How would I gain initial access?</li><li>What would I target next?</li><li>How could I chain these weaknesses together?</li><li>What data could be accessed?</li><li>How difficult would exploitation actually be?</li><li>What is the likely business impact?</li></ul><p>These decisions are rarely straightforward. They require judgement, creativity, and experience.</p><p>Two organizations may have the same vulnerability present within their environments, yet the associated risk could be dramatically different depending on the surrounding context.</p><p>Understanding that difference is where human expertise becomes critical.</p><h2 id="the-future-isn-t-autonomous-testing">The future isn’t autonomous testing:</h2><p>There is currently a great deal of excitement around autonomous security testing. The idea is appealing. Feed an environment into an AI model and receive a complete understanding of risk in return. </p><p>The reality is significantly more complex.</p><p>Attackers do not operate according to predefined workflows.</p><ul><li>They adapt.</li><li>They improvise.</li><li>They exploit unexpected opportunities.</li><li>They combine seemingly insignificant weaknesses into meaningful attack chains.</li></ul><p>Successful offensive security assessments require the same flexibility.</p><p>While AI can assist with analysis and discovery, security testing remains fundamentally an exercise in understanding human behavior, <a href="https://www.techradar.com/best/best-business-plan-software">business</a> context, and attacker decision-making. These are areas where human expertise continues to outperform automation.</p><p>For the foreseeable future, I believe the most effective approach will be human-led, AI-assisted testing. Not human versus AI. Human plus AI.</p><h2 id="ai-should-make-penetration-testers-better">AI should make penetration testers better:</h2><p>The conversation should not be about replacing penetration testers. It should be about enabling them. When repetitive activities are automated, consultants can spend more time focusing on the areas where they create the greatest value.</p><p>Instead of manually processing information, they can spend more time:</p><ul><li>Investigating attack paths</li><li>Validating exploitability</li><li>Understanding business impact</li><li>Identifying complex attack chains</li><li>Advising clients on remediation priorities</li><li>Delivering meaningful security outcomes</li></ul><p>In many respects, AI allows skilled security professionals to operate at a higher level. It augments expertise rather than replacing it. The result is not fewer penetration testers.</p><p>It is more effective penetration testers.</p><h2 id="the-real-challenge-is-prioritization">The real challenge is prioritization:</h2><p>As AI continues to improve vulnerability discovery and analysis, organizations will inevitably uncover more security findings.</p><p>That sounds positive, but it introduces a new challenge. More findings do not automatically reduce risk. In fact, without effective prioritization, they can create additional noise.</p><p>The organizations that succeed over the next decade will not necessarily be the ones finding the most vulnerabilities. They will be the ones that can most effectively distinguish genuine risk from background noise, understand how attackers are likely to exploit weaknesses in practice, and make informed decisions about where to focus finite resources.</p><p>As AI continues to improve vulnerability discovery and analysis, security teams will inevitably gain access to more data, more findings, and greater visibility than ever before. While that represents a significant advancement for the industry, visibility alone does not reduce risk. The real value lies in understanding what matters, what is exploitable, and what action should be taken next.</p><p>That is why I believe the future of security testing is not autonomous. It is human-led and AI-assisted. <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> will continue to accelerate analysis, improve visibility, and help uncover opportunities that may previously have been missed. However, understanding business context, assessing real-world risk, and making sound security decisions will remain fundamentally human responsibilities.</p><p>The cybersecurity industry has spent years trying to solve the visibility problem. AI is helping us make enormous progress. The next challenge is prioritization, and that is where experienced security professionals will continue to play their most important role.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Windows 10 still powers one in six PCs around today — and that could be a major security issue very soon ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/windows-10-still-powers-one-in-six-pcs-around-today-and-that-could-be-a-major-security-issue-very-soon</link>
                                                                            <description>
                            <![CDATA[ The average Windows 10 device has around 3x as many active CVEs as a Windows 11 device, and migration is slowing down. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eF6pAVMWyFJMSwjFqv3K5h</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 10:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock - Wachiwit]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Windows 10 Logo on Laptop]]></media:description>                                                            <media:text><![CDATA[Windows 10 Logo on Laptop]]></media:text>
                                <media:title type="plain"><![CDATA[Windows 10 Logo on Laptop]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/yBsirNxrnuBxshrCgrFwsQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Migration is slowing down as the more difficult cases remain on the legacy OS</strong></li><li><strong>Windows 10 devices are said to have 3x as many active CVEs</strong></li><li><strong>Technical limitations and physical upgrades aren't a major issue</strong></li></ul><p>According to new <a href="https://www.lansweeper.com/blog/insights/windows-10-holdouts-carry-three-times-the-risk-of-windows-11/" target="_blank">Lansweeper</a> data, as many as 16.9% of Windows client devices, which equates roughly to a total of one in six overall, still runs Windows 10.</p><p>While Windows 11 now accounts for 78.8% of installs and Windows 10's market share has fallen from about 50% in mid-2025, Lansweeper warns the migration is starting to slow down, implying the remaining Windows 10 market share could show no signs of going anywhere.</p><p>And that's a worrying state of affairs, because the average Windows 10 device has around 3x as many active CVEs (1,903) as a Windows 11 devices (652).</p><h2 id="windows-10-market-share-could-be-a-security-nightmare">Windows 10 market share could be a security nightmare</h2><p>Additionally, around two-thirds of the active CVEs on Windows 10 are rated high or critical, and the rate of vulnerabilities known to be exploitable is around 1.7x higher than on Windows 11.</p><p>The report notes that <a href="https://www.techradar.com/computing/windows/windows-10s-final-patch-fixes-a-bewildering-number-of-security-flaws-and-shows-why-you-need-extended-updates">Microsoft's Extended Security Updates (ESU) program</a> buys some breathing room, protecting consumers until October 2027 and paying commercial customers until October 2028.</p><p>Healthcare and pharmaceuticals (23%), consumer and retails (23%) and manufacturing (18%) are among the industries most likely to still be running Windows 10, with SMBs (21.4%) more likely to be running the outgoing OS compared with enterprises (16.6%).</p><p>Lansweeper also revealed that technical limitations aren't necessarily to blame, with only 2.8% of the Windows 10 devices it analyzed failing Windows 11's hardware requirements.</p><p>More broadly, the report warns that nearly one-fifth (18.7%) of the entire Windows landscape it monitors runs end-of-life operating systems like Windows 7, Windows 8.1 and Windows XP.</p><p>The report concludes that, while many users have now upgraded to the latest OS, the remaining estate is smaller but disproportionately more difficult, expensive or risky to update. But with ESU programs soon running to an end, deeper considerations into leaving Windows 10 should be made.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A unified front against fraud: Securing the UK's payments future ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/a-unified-front-against-fraud-securing-the-uks-payments-future</link>
                                                                            <description>
                            <![CDATA[ As sophisticated scams escalate, can a unified front finally secure the UK’s payments? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sNMzuwf5FhhwcyiHd3GYvf</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mSXzX87uURsnFxxnUSDpiK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 10:16:04 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Justin Jacobs ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mSXzX87uURsnFxxnUSDpiK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A credit card held above a phone]]></media:description>                                                            <media:text><![CDATA[A credit card held above a phone]]></media:text>
                                <media:title type="plain"><![CDATA[A credit card held above a phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mSXzX87uURsnFxxnUSDpiK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The UK's payment landscape is undergoing a rapid transformation. While regulatory initiatives, such as the mandatory authorized push payment (APP) reimbursement scheme, provide safeguards, sophisticated cyber-attacks and elaborate scams relentlessly evolve.</p><p>To reduce fraud, strong data-sharing frameworks and collaboration across the <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> services industry are essential. Collaboration between big tech, telecoms, banks and the public sector can help combat fraud through a joined-up approach to data-sharing aimed at driving out scammers and identifying potentially fraudulent transactions.   </p><h2 id="current-landscape">Current landscape</h2><p>The scale of UK fraud is stark, with losses reaching £1.28 billion in 2025, a 4% increase year-on-year. Fraud is now operating on an industrial scale, with criminals using increasingly advanced tools and techniques to target victims. Fraud increasingly funds serious and organized crime in the UK and globally, reinforcing its status as a national <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> threat.</p><p>Authorized Push Payment (APP) fraud is a growing area of concern – this type of fraud continues to rise, with 248,070 cases recorded in 2025 (up 7%), showing that fraudsters are consistently adapting, pivoting to exploit new vulnerabilities, even as defenses strengthen. New scams have focused on investment, purchase-related, advance fee, invoice, and mandate scams as well as romance and impersonation scams. </p><p>Total losses from APP fraud rose sharply to £576.4 million (up 19%). This reflects a clear shift in criminal behavior, from exploiting systems to manipulating people through increasingly sophisticated social engineering.</p><p>Purchase scams made up 71% of all APP cases, demonstrating the scale and diversity of modern fraud tactics. This impact extends beyond financial loss, affecting individual livelihoods, disrupting businesses, and undermining national economic confidence.      </p><p>Crucially, most APP fraud now originates outside the banking system. 66% of cases begin online (accounting for 32% of losses) and 17% via telecommunications networks, highlighting the growing role of digital platforms and telecoms in enabling fraud. Criminals are no longer primarily hacking systems; they are manipulating people, using sophisticated social engineering to bypass even the strongest technical controls. </p><h2 id="key-considerations-for-the-payments-industry">Key considerations for the payments industry  </h2><p>Tackling these challenges requires a multi-faceted approach, combining robust technology, seamless collaboration to enable effective and compliant <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>-sharing, effective regulation, and public awareness. Key considerations are:</p><h2 id="what-does-government-strategy-mean-in-practice">What does government strategy mean in practice? </h2><p>Initiatives, such as the Government Fraud Strategy, provide an important framework for government, law enforcement, and the private sector. <a href="https://www.techradar.com/best/best-infrastructure-management-service">Infrastructure</a> and data-sharing initiatives need to be effective, compliant, and aligned with national priorities to disrupt and prevent fraud. This ensures the fight against fraud remains a national priority that continuously adapts.  </p><p>New data-sharing initiatives with Faster Payment System participants can play a key role here. Pay.UK’s work with participants on Enhanced Data Exchange (EDEx) will facilitate secure, timely data-sharing to empower financial institutions to detect and prevent fraudulent payments before they happen.</p><p>While still in development, its principles will complement the FCA’s APP fraud guidance and the Home Office’s Data Strategy ambitions: to enable secure, proportionate information exchange that helps prevent fraud before funds leave the system.   </p><h2 id="how-can-the-industry-continue-to-build-cross-sector-collaboration">How can the industry continue to build cross-sector collaboration? </h2><p>Cross-sector intelligence sharing and advanced data analytics are increasingly vital. Real-time, secure data exchange illuminates patterns, identifies emerging threats, and enables proactive intervention before attacks occur. When combined with strong governance and clear accountability, this kind of collaboration shifts fraud defense from isolated warning signs to a coordinated, system‑wide response.</p><p>Confirmation of Payee significantly reduces misdirected <a href="https://www.techradar.com/news/best-mobile-payment-app">payments</a> and various APP fraud types such as impersonation and invoice scams. It's a vital, preventative layer of security before funds are transferred. It has implications beyond its intended purpose and has strongly influenced the development of Verification of Payee in Europe.   </p><p>There is a growing call for greater enforceable responsibilities for technology platforms and telecommunications providers, not only to prevent fraud at source, but also to contribute financially and operationally to combating it. </p><h2 id="how-can-the-industry-empower-and-educate-end-users">How can the industry empower and educate end users? </h2><p>Beyond technology and industry collaboration, fraud prevention has a vital human dimension. Educating and empowering end users remain central – recognizing the warning signs of a scam is still one of the strongest protections available. But education alone is not enough. Consumers also need better information at the moment a decision is made.</p><p>It’s encouraging to see that, as a payments community, we are already building richer data-sharing across the ecosystem to provide clearer, more relevant context when prompting customers to pause before making a payment. Banks are moving beyond generic warnings, providing genuinely useful guidance and strengthening the point of payment as a powerful, collective line of defense.</p><p>The APP reimbursement scheme is a significant consumer protection funded by UK banks. Data from the PSR shows that £215 million was reimbursed to victims of APP fraud in 2025 alone. Across the first 15 months of the scheme (October 2024 to December 2025), 89% of the money lost to APP scams has been successfully claimed back from a payment firm and returned to victims.</p><p>While not a direct comparison, this is a significant uptick from the 65% reimbursement rate reported by UK Finance for personal accounts in 2024. Providing a safety net of up to £85,000 for victims, this scheme offers a clear recovery mechanism and brings more consistency for <a href="https://www.techradar.com/best/the-best-customer-database-software-of-year">customers</a> than the previous voluntary Contingent Reimbursement Model (CRM) Code. </p><p>Further, the scheme continues to evolve in line with the shifting payment landscape. The PSR has appointed Frontier Economics to carry out an independent evaluation and review of the APP fraud policies, the results of which are due to be published in the second half of 2026.</p><p>These findings, which look at the current effectiveness of the policies, fraud performance reporting and the reimbursement requirement, will influence the future of APP fraud prevention strategies and regulatory requirements, ensuring the creation of safe and trusted payment infrastructure</p><p>The battle against payment fraud is ongoing, demanding constant vigilance and strategic adaptation. While the digital age has transformed how we transact, it has also presented fraudsters with new avenues for exploitation. Yet, as outlined, it is a battle we are actively and collectively winning.</p><p>By embracing a multi-faceted approach, combining robust technological defenses, seamless industry collaboration, effective regulatory frameworks, and comprehensive public awareness, we are building a formidable shield against these threats.</p><p><em></em><a href="https://www.techradar.com/best/best-billing-and-invoicing-software"><em>We've featured the best billing and invoicing software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft nemesis returns with another zero-day PoC — but is 'LegacyHive' as nasty as expected? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-nemesis-returns-with-another-zero-day-poc-but-is-legacyhive-as-nasty-as-expected</link>
                                                                            <description>
                            <![CDATA[ Chaotic Eclipse is back with a new Windows 11 zero-day called LegacyHive. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">437WE24R6f5RrojuCvuFfS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/Ham patipak]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:description>                                                            <media:text><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:text>
                                <media:title type="plain"><![CDATA[A laptop with the Windows 11 desktop on screen, glowing, while on a work desk ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HCMx4u3U8KVpNCqssJps2J-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher “Chaotic Eclipse” releases new Windows 11 zero‑day dubbed </strong><em><strong>LegacyHive</strong></em><strong>, a local privilege escalation bug targeting user registry hives</strong></li><li><strong>Exploit could let attackers elevate low‑privileged accounts, but requires prior device access; no CVE or full PoC was published</strong></li><li><strong>Experts caution that skilled actors could weaponize it quickly, urging intelligence teams to prepare mitigations despite lower perceived impact than earlier releases</strong></li></ul><p>Chaotic Eclipse, the infamous security researcher with a Microsoft grudge, did as they previously promised and released yet another zero-day vulnerability for fully patched Windows 11 devices. </p><p>However, other researchers don’t see it as dangerous as some of their previous releases.</p><p>Chaotic Eclipse disclosed a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day</a> called LegacyHive, which is a local privilege escalation (LPE) bug targeting Windows’ user hives.</p><h2 id="escalating-privileges">Escalating privileges</h2><p>A few months ago, a hacker/researcher with the alias Chaotic Eclipse started publishing functioning exploits for fully patched Windows 11 systems, all with PoCs, claiming that Microsoft acted against them in ill faith and argued that the company does not treat researchers with the respect they deserve.</p><p>They released a total of <a href="https://www.techradar.com/pro/security/the-exact-same-issue-that-was-reported-to-microsoft-by-google-project-zero-is-actually-still-present-unpatched-chaotic-eclipse-strikes-again-with-another-worrying-windows-security-flaw" target="_blank">seven exploits</a>, some more damning than others, and promised to release a “bone-shattering” one on July 14 2026. In the meantime, Microsoft first criticized the researcher for not “responsibly” disclosing the flaws, and at one point even threatening possible legal action. However, it did not sue the researcher and later backed away from the threat entirely, partly as a result of strong public backlash.</p><p>In Windows, user hives are registry files that store configuration settings specific to an individual user account. These include desktop preferences, user-specific application settings, network drive mappings, user-specific security and privacy settings, and more. </p><p>With LegacyHive, threat actors could, in theory, gain privileged read-write access targeting other users’ hives. Or, in other words, they could turn low-privileged accounts into high-privileged ones. However, they would first need to have any access to the device, which is one of the reasons why some security researchers don’t see it as disastrous as Chaotic Eclipse’s previous work.</p><p>What also makes LegacyHive different from some other releases is that this one was not released with a CVE identifier or a fully functioning Proof of Concept (PoC). </p><p>Still, security experts are urging intelligence teams to work fast, because skilled threat actors can fill the gaps with relative ease, and turn LegacyHive into a potent weapon.</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/15/microsofts-serial-tormentor-drops-legacyhive-0-day/5271723" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet</link>
                                                                            <description>
                            <![CDATA[ The hacker told the AI he was an authorized pentester - and the AI believed him. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2aLD452X3VLZeF4n8MnsB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:description>                                                            <media:text><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:text>
                                <media:title type="plain"><![CDATA[A human shakes a robot&#039;s hand in front of blue concentric circles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PRCsQfoXPXi2t4jsGwWr6L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Russian hacker “bandcampro” used Google’s Gemini CLI to control an eight‑device botnet at a dental clinic</strong></li><li><strong>The attacker tricked the AI by posing as a pen tester, directing it to migrate C2 infrastructure, troubleshoot connectivity, and prepare payload bundles</strong></li><li><strong>The AI assisted with daily operations like password guessing and WordPress access, highlighting risks of misuse when threat actors co‑opt AI tools</strong></li></ul><p>A Russian hacker and his AI companion were able to successfully control a miniature, eight-system botnet, with the hacker giving instructions in conversational language, and the AI doing his bidding, experts have found.</p><p>Analyzing 200 session logs obtained from the Russian-speaking threat actor known as “bandcampro”, cybersecurity researchers Trend Micro saw the hacker use Google’s Gemini CLI, an open source AI command-line tool that lets developers interact with Google's <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">Gemini AI</a> models directly from a terminal. </p><p>Scouring through a month’s worth of session logs (between April 21 and May 19 2026), the researchers discovered that the attacker tricked the AI by telling it they were an “authorized pen tester”. While the AI mostly complied with their nefarious overlord, they refused the orders on at least one occasion.</p><h2 id="gone-in-six-minutes">Gone in six minutes</h2><p>Trend Micro found the hacker controlled eight devices belonging to a dental clinic and sought to access their access their OpenDental database.</p><p>Using the AI, bandcampro did a number of things, starting with migrating the botnet to a new C2 infrastructure. He gave the AI a skill file with the full architecture description, standard operating procedures, infection one-liner, persistence commands, and troubleshooting steps.</p><p>He then told it to “study the C2 migration”, which had the AI process the guide and prepare all the code and necessary steps. It took the tool around six minutes to get the job done. </p><p>"The AI read the migration guide, then prepared a migration bundle, a small archive of server code, payloads, and the skill file. It then unpacked the bundle, launched the C&C server on a VPS, and brought up the Cloudflare tunnel," Trend Micro says.</p><p>Bandcampro then used the AI to troubleshoot connectivity issues, as well as for various daily operations, such as guessing passwords, generating plausible variants of existing passwords for WordPress portals, and more.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Thousands of US military beneficiaries have data breached following TRICARE cyberattack — DoD Benefits Numbers and some Social Security numbers leaked ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/thousands-of-us-military-beneficiaries-have-data-breached-following-tricare-cyberattack-dod-benefits-numbers-and-some-social-security-numbers-leaked</link>
                                                                            <description>
                            <![CDATA[ TriWest suffers an attack and loses TRICARE data on some 12,000 people. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sKjC3VLGBvQgwi3mgFXgtj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:description>                                                            <media:text><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:text>
                                <media:title type="plain"><![CDATA[An office worker in front of a computer holding his hand in one hand and looking unhappy]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/nKQTr6znQKVirervbiEDkL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>TriWest Healthcare confirmed an April 16 breach in which an attacker accessed and downloaded sensitive data tied to 12,000 TRICARE beneficiaries</strong></li><li><strong>Stolen information includes names, DoD Benefits numbers, ZIP codes, authorization request types, and in some cases SSNs, addresses, and dates of birth</strong></li><li><strong>TriWest says it acted immediately to contain the intrusion and notify affected individuals; no group has claimed responsibility and stolen data has not surfaced online</strong></li></ul><p>US healthcare services company TriWest Healthcare networks recently suffered a cyberattack in which it lost sensitive customer data belonging to thousands of its clients’ users.</p><p>TriWest is a private company that manages government healthcare programs, primarily on behalf of the US Department of Defense (DoD) and the Department of Veterans Affairs (VA). One of its clients is TRICARE, a DoD healthcare program for active-duty service members, National Guard and Reserve members, military retirees, and their families. </p><p>According to Cybernews, TriWest recently started notifying TRICARE customers that an “unauthorized person” accessed its network on April 16 and “downloaded some TriWest information.” Citing data provided to the California State Attorney General’s Office, the publication says 12,000 TRICARE beneficiaries were recently notified of the breach.</p><h2 id="sounding-the-alarm">Sounding the alarm</h2><p>In a statement shared with <a href="https://www.moaa.org/content/publications-and-media/news-articles/2026-news-articles/benefits/nearly-12,000-tricare-beneficiaries-warned-of-data-breach/" target="_blank"><u>Military Times</u></a>, TriWest explained what it did the moment it spotted the intrusion: “With regard to timing, as soon as the incident was discovered, TriWest took immediate action to prevent any further unauthorized activity and worked diligently with the government to notify affected individuals, consistent with applicable law and notification timelines,” TriWest officials said.</p><p>The details about the incident, the nature of the attack, or the identity of the attackers, were not disclosed. We do know that the miscreants walked away with people’s names, DoD Benefits numbers, ZIP codes, types of authorization requests and, in some cases, Social Security numbers (SSN), postal addresses, and dates of birth.</p><p>At press time, the TriWest website, as well as the company’s newsroom, were offline. It is unclear if there is any connection to the data breach. So far, no threat actors claimed responsibility for the attack, and the data is yet to surface on the dark web.</p><p>In the meantime, TRICARE beneficiaries are warned to be wary of incoming emails, especially those claiming to come from the program or the company.</p><p><em>Via </em><a href="https://cybernews.com/news/tricare-west-health-data-breach-military-beneficiaries/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cloud sprawl taught organizations a lesson. AI is testing whether they learned it ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/cloud-sprawl-taught-organizations-a-lesson-ai-is-testing-whether-they-learned-it</link>
                                                                            <description>
                            <![CDATA[ Businesses are layering AI complexity onto already sprawling cloud environments. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cQMkEG6QJ6TVbWxGYdoLPV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y9gz3ntBvZYTntd8XpFxfL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 14:52:12 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Tim Chase ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y9gz3ntBvZYTntd8XpFxfL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A blue digital cloud containing lots of symbols on a dark blue background]]></media:description>                                                            <media:text><![CDATA[A blue digital cloud containing lots of symbols on a dark blue background]]></media:text>
                                <media:title type="plain"><![CDATA[A blue digital cloud containing lots of symbols on a dark blue background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y9gz3ntBvZYTntd8XpFxfL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many organizations are still trying to get to grips with <a href="https://www.techradar.com/uk/best/best-cloud-storage">cloud</a> sprawl. Years of cloud adoption have delivered undeniable benefits, giving businesses greater agility, scalability and access to innovation.</p><p>But they have also created a significant management challenge. As environments have expanded across multiple cloud providers, accounts and services, maintaining visibility has become increasingly difficult.</p><p><a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> and IT teams have spent years trying to establish consistent visibility across increasingly complex cloud environments, identifying what assets exist, where they are located, who is responsible for them and whether they are adequately secured. For many organizations, those questions still remain difficult to answer.</p><p>Now, as enterprises accelerate their adoption of AI, a new layer of complexity is being added on top of existing cloud environments. AI models, agents, APIs, vector <a href="https://www.techradar.com/best/best-database-software">databases</a> and automated workflows are appearing across organizations at remarkable speed, creating a fresh challenge that many security leaders are only beginning to confront.</p><p>In many respects, AI sprawl is becoming the new cloud sprawl.</p><h2 id="the-pace-of-ai-adoption-is-creating-a-visibility-problem">The pace of AI adoption is creating a visibility problem</h2><p>While previous technology shifts unfolded over years, AI capabilities are evolving in months. New models, tools and services are constantly emerging, while software providers are rapidly embedding AI functionality into existing products. This pace of change presents a unique challenge for governance.</p><p>Traditionally, organizations have introduced new technologies through relatively structured processes involving the usual things like procurement, security reviews and compliance assessments. AI adoption often looks very different.</p><p>Teams can experiment with models in development environments, departments can adopt AI powered applications independently, and new capabilities can appear within existing software platforms almost overnight.</p><p>As a result, many organizations lack a complete inventory of where AI is being used across their <a href="https://www.techradar.com/best/best-phone-service-for-business">business</a>.</p><p>This is both a security concern and visibility problem for effective governance and compliance. If organizations cannot identify where AI is running, they will struggle to understand what data it can access, what decisions it is influencing and what risks it may introduce.</p><h2 id="ai-is-adding-another-layer-to-cloud-complexity">AI is adding another layer to cloud complexity</h2><p>As organizations embraced multi cloud strategies, adopted SaaS applications and empowered development teams to move faster, cloud estates became increasingly distributed. Security teams found themselves managing thousands of assets spread across multiple environments.</p><p>AI is now introducing another set of services and technologies that need to be inventoried, understood and secured. A modern AI deployment rarely consists of a single model operating in isolation. Instead, organizations are building interconnected ecosystems involving cloud <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, data pipelines, APIs, machine learning platforms, third-party services and increasingly autonomous agents.</p><p>Each additional connection creates another dependency to monitor and another potential point of failure. The challenge is not necessarily that AI introduces entirely new security risks. In many cases, it amplifies existing visibility and governance issues that organizations were already struggling to address.</p><p>Many security leaders are still working to achieve comprehensive visibility across their cloud environments. Adding AI systems into the mix means managing another layer of complexity without an established playbook for doing so effectively. That lack of maturity is one of the defining characteristics of AI governance today.</p><h2 id="why-ai-agents-are-changing-the-conversation">Why AI agents are changing the conversation</h2><p>Unlike traditional software applications, AI agents are increasingly capable of taking actions on behalf of users. They can retrieve information, access systems, trigger workflows and interact with other applications with varying degrees of autonomy.  </p><p>Historically, security strategies have focused primarily on managing human access to systems and data. Concepts such as identity governance, multi factor authentication and zero trust were designed around human users. But AI is beginning to change those assumptions.</p><p>Organizations are creating growing numbers of non human identities, each requiring the right permissions and access rights. These systems may interact with sensitive information, business applications and critical infrastructure in ways that are difficult to monitor using traditional approaches.</p><p>As AI adoption accelerates, <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> is likely to become one of the most important control points for managing risk. The principle of least privilege remains just as relevant as it has always been, but organizations must now apply it to both human and machine actors.</p><p>That requires a much clearer understanding of how AI systems operate, what resources they can access and how those permissions are governed over time.</p><h2 id="securing-ai-at-the-speed-of-ai">Securing AI at the speed of AI</h2><p>AI capabilities are evolving at extraordinary speed, while security and governance processes are often constrained by regulatory requirements, internal approvals and operational realities.</p><p>Attackers do not face the same constraints. They can experiment, adapt and exploit emerging opportunities far more quickly than most organizations can implement new controls. This creates an ongoing race between innovation and governance.</p><p>The objective should not be to slow AI adoption. Few organizations can afford to ignore the opportunities AI presents, whether through <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> gains, operational efficiencies or competitive advantage. Instead, the focus should be on ensuring that governance evolves alongside adoption.</p><p>This means recognizing that AI security is both about protecting models and understanding how AI interacts with cloud environments, business processes, identities and data. Organizations need to tackle this by establishing visibility early rather than attempting to retrofit governance once complexity has already taken hold.</p><h2 id="applying-the-lessons-learned-from-cloud">Applying the lessons learned from cloud</h2><p>The good news is that organizations do not need to start from scratch. The cloud era provided valuable lessons about the relationship between innovation, visibility and governance. Many of those lessons are directly applicable to AI.</p><p>Organizations must begin by understanding their AI footprint. This way they can identify where AI is being used, what systems it connects to and what data it can access. They can establish clear ownership, extend existing risk management frameworks and ensure that AI deployments are subject to the same level of scrutiny as other critical technologies.</p><p>Most importantly, they can recognize that visibility is not a one off exercise. As AI capabilities continue to evolve, maintaining an accurate understanding of the environment will become an ongoing requirement.</p><p>Cloud sprawl demonstrated how quickly complexity can accumulate when technology adoption outpaces governance. AI presents a similar challenge, but at an even greater pace.</p><p>As AI becomes increasingly embedded across the enterprise, that lesson may prove more important than ever.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Zoom patches critical security flaw which could have let hackers hijack accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/zoom-patches-critical-security-flaw-which-could-have-let-hackers-hijack-accounts</link>
                                                                            <description>
                            <![CDATA[ Zoom finds improper input validation bug, but fortunately sees no evidence of abuse. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">StnEZtLDbRcvUu2DBR5ea3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png">
                                                            <media:credit><![CDATA[LinkedIn]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Zoom Verified on LinkedIn Example]]></media:description>                                                            <media:text><![CDATA[Zoom Verified on LinkedIn Example]]></media:text>
                                <media:title type="plain"><![CDATA[Zoom Verified on LinkedIn Example]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/oQs6iUSDCYDEV6yP7Pj9Gh-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zoom patches critical improper input validation flaw in multiple Windows clients and SDKs that allowed remote account takeover</strong></li><li><strong>Additional high‑severity bugs fixed include CVE‑2026‑53410 (TOCTOU race condition), CVE‑2026‑53409 (privilege management flaw), and CVE‑2026‑53411 (input validation issue)</strong></li><li><strong>All vulnerabilities were found internally, with no evidence of exploitation; users are urged to update Zoom Workplace and related products to the latest versions</strong></li></ul><p>Zoom has patched a critical-level vulnerability in multiple products that allowed threat actors to take over people’s accounts remotely.</p><p>In a security advisory, Zoom said it fixed an Improper Input Validation bug plaguing Zoom Desktop Client for Windows (before version 7.0.0), Zoom VDI Client for Windows (before versions 7.0.10, 6.6.15, and 6.5.18), and Zoom Meeting SDK for Windows (before version 7.0.0). It did not go into more details on how the flaw works.</p><p>The bug is now tracked as CVE-2026-53412, and was given a severity score of 9.8/10 (critical). To fix it, users are advised to update their software to the newest version.</p><h2 id="more-vulnerabilities">More vulnerabilities</h2><p>While certainly the most dangerous one, this is not the only bug Zoom recently addressed. The company also fixed a handful of less severe vulnerabilities, including a time-of-check to time-of-use (TOCTOU) race condition bug affecting Zoom Workplace for Windows before 7.0.5, Zoom Workplace VDI Client and VDI Plugin before 6.5.17/6.6.14, Zoom Rooms for Windows before 7.0.5, and Remote Control for Zoom Contact Center before 7.0.0. This bug is tracked as CVE-2026-53410 and was given a “high” severity score of 7/10. </p><p>Other notable mentions include CVE-2026-53409 (a high-severity improper privilege management flaw in Zoom Rooms for Windows before version 7.1.0), and </p><p>CVE-2026-53411 (a high-severity improper input validation flaw affecting the Zoom Workplace VDI Plugin for Windows before version 6.6.14).</p><p>Zoom found all of these vulnerabilities in-house and says there is no evidence that any of these were abused in real-life attacks in the past. </p><p>Zoom Workplace (the company’s <a href="https://www.techradar.com/best/best-online-collaboration-tools" target="_blank">all-in-one collaboration platform</a>) offers video meetings, team chat, phone, email, calendar, scheduling, whiteboards, and other productivity tools. It is an evolution of the original Zoom Meetings app which now competes with platforms such as Microsoft 365 and Google Workspace.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/zoom-warns-of-critical-account-takeover-vulnerability/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shadow AI often emerges when workplace technology fails employees ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/shadow-ai-often-emerges-when-workplace-technology-fails-employees</link>
                                                                            <description>
                            <![CDATA[ Employees use shadow AI for a reason. Organizations should pay attention.. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TqfCarsuiyYYbAibjBkCvZ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SjSwAU6f7Pkb5hStzepX5L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 16 Jul 2026 11:04:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Patricia Leppert ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SjSwAU6f7Pkb5hStzepX5L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands typing on a keyboard, with digital text and symbols superimposed on top showing a conversation with a chatbot]]></media:description>                                                            <media:text><![CDATA[Hands typing on a keyboard, with digital text and symbols superimposed on top showing a conversation with a chatbot]]></media:text>
                                <media:title type="plain"><![CDATA[Hands typing on a keyboard, with digital text and symbols superimposed on top showing a conversation with a chatbot]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SjSwAU6f7Pkb5hStzepX5L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Shadow AI is a security issue. When employees use unsanctioned <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> without formal oversight, sensitive information can end up in platforms the business has not approved, monitored or secured. </p><p>The risks around data protection, compliance and governance are real, and organizations are right to take them seriously.</p><p>But if we view shadow AI only through a security lens, we risk treating the symptom rather than the cause.</p><p>Most employees are not deliberately trying to bypass policies or create risk. </p><p>In most cases, they are trying to solve a problem quickly and move their work forward. When approved tools are slow, difficult to access, limited in functionality or unclear to use, people naturally look for alternatives that help them get the job done.</p><p>That means shadow AI is not just a <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> challenge. It is also a signal that workplace technology is failing to meet employee needs.</p><p>For organizations, the lesson is clear: reducing shadow AI requires more than stronger controls. It requires providing employees with secure, accessible tools that are capable of supporting the way work actually happens.</p><h2 id="when-approved-tools-are-not-enough">When approved tools are not enough</h2><p>Many organizations still frame unsanctioned AI use as a failure of <a href="https://www.techradar.com/pro/best-employee-experience-tools">employee</a> behavior. From that perspective, the answer seems simple: issue stricter policies, block more tools and remind people of the risks.</p><p>This may reduce some exposure in the short term, but it rarely solves the underlying problem. Employees turn to AI tools because they offer speed, convenience and support with tasks that official systems may not handle well.</p><p>The challenge is not only that employees are using the wrong tools. It is that the approved route may not feel practical enough to use.</p><p>That distinction matters. If the official process is too slow, people may bypass it. If the guidance is too vague, teams may make their own decisions. If approved tools do not meet real business needs, unofficial ones will fill the gap.</p><p>Shadow AI is therefore not just  a sign of poor compliance, but can also be a signal of underlying friction. </p><h2 id="digital-friction-creates-hidden-risk">Digital friction creates hidden risk</h2><p>Digital friction refers to the everyday technology barriers that make it harder for employees to do their jobs efficiently. It might be a login process that takes too long, a blocked platform that prevents a simple task, an approval workflow that slows a project or a sanctioned tool that lacks the functionality employees need.</p><p>Individually, these problems may seem minor. Together, they shape how employees behave.</p><p>When workplace technology makes work harder, employees become more likely to find their own solutions. Research has found that 80% of employees lose time to dysfunctional IT, costing them an average of 1.3 workdays per month. Almost half also say it has delayed critical operations or projects.</p><p>The risk is not only lost <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>. Digital friction can also weaken trust in approved systems, pushing work into less visible environments where security teams have less oversight.</p><p>This is why blocking tools without addressing employee needs can backfire. It may push behavior further out of sight rather than bringing it under control.</p><h2 id="security-cannot-succeed-if-it-competes-with-productivity">Security cannot succeed if it competes with productivity</h2><p>For years, security has often been seen by employees as something that interrupts work. </p><p><a href="https://www.techradar.com/best/password-generator">Password</a> resets, access requests, approval chains and tool restrictions all exist for valid reasons, but they can still feel like barriers when they are poorly designed.</p><p>The same is true for AI governance. A policy that simply says which tools cannot be used is unlikely to be enough. Employees need practical guidance on what they can use, what information can be entered and where to go when they are unsure.</p><p>The secure route has to be clear enough to follow and useful enough to choose.</p><p>This does not mean weakening security. It means designing security around how work actually happens. The strongest controls are often the ones that employees can follow without feeling they are being forced to choose between protection and productivity.</p><p>Authentication is a useful example. Passwords have long been a source of frustration for employees and a known weakness for organizations. Approaches such as zero trust and biometric authentication can strengthen protection while improving the user experience. </p><p>The principle is simple: good security should reduce risk without adding unnecessary friction.</p><h2 id="ai-governance-needs-an-owner">AI governance needs an owner</h2><p>One reason shadow AI can grow quickly is that responsibility is often unclear.</p><p>AI tools can enter an organisation through different teams for different reasons. A small experiment in one department can become part of a core workflow before anyone has assessed the risk, agreed ownership or defined the rules.</p><p>As adoption grows, that governance gap becomes harder to ignore. This is especially true when employees are already questioning whether official routes can keep pace. Research has found that 62% of employees lack confidence that their IT teams are providing the latest AI and digital tools, while 57% do not trust their IT team to resolve issues quickly or effectively and 47% fear their IT team will not adequately protect personal or work-related data.</p><p>Security teams have an important role to play, but they cannot solve this alone. AI governance needs input from IT, legal, compliance, HR and leaders across the whole organisation. It must become a core part of the organization's operating model rather than a standalone policy.</p><p>That means establishing clear ownership for how AI is introduced, used and governed across the organization. It also means recognizing that governance is not only about stopping unsafe behavior. It is about enabling safe behaviorat scale.</p><p>Human oversight remains essential. AI can process information quickly, but it does not understand every business context, regulatory requirement or reputational consequence. People still need to challenge outputs and take responsibility for decisions that carry real-world impact.</p><h2 id="employees-need-guidance-they-can-actually-use">Employees need guidance they can actually use</h2><p>AI policies often fail because they are too abstract. Employees may be told to avoid sharing sensitive data and use approved tools, but that doesn't always help in the moment.</p><p>A team under pressure needs practical answers. Can this document be uploaded? Can this customer query be summarized? Can this dataset be analyzed? Which tool is approved for this task? Who should be asked if the answer is unclear?</p><p>Guidance needs to be specific, accessible and easy to apply during the working day. If employees have to search through long policy documents or wait days for an answer, they may default to the fastest available option.</p><p>This is where trust becomes critical. Employees are more likely to follow security guidance when they believe approved systems will help them do their jobs effectively. If they see official processes as slow, restrictive or disconnected from reality, they are more likely to look elsewhere.</p><p>Trust also depends on transparency. People need to understand why certain tools are restricted, how data is protected and what the approved route is designed to achieve. A policy that simply says “do not use this tool” does not build confidence. It creates a rule. Rules matter, but they work best when employees understand the reason behind them.</p><h2 id="security-by-design-must-apply-to-the-workplace">Security-by-design must apply to the workplace</h2><p>Security-by-design is often discussed in relation to products and software development, but the same principle should apply to the digital workplace.</p><p>Too often, security is bolted on after a tool or process has already been adopted. By that point, controls can feel like an extra layer rather than a natural part of the workflow. Bringing security into the conversation earlier helps organizations identify risk before behaviors become embedded.</p><p>For AI, this means involving security, <a href="https://www.techradar.com/best/it-management-tools">IT</a> and governance teams before tools are rolled out widely. It also means listening to employees about what they need from those tools.</p><p>If approved AI systems are too limited, employees will work around them. If the access process is too slow, adoption will fragment. If guidance is unclear, teams will interpret the rules differently.</p><p>Understanding those pressures is central to reducing risk.</p><h2 id="the-easiest-path-should-be-the-secure-one">The easiest path should be the secure one</h2><p>Shadow AI shows that workplace systems are struggling to keep pace with how work is changing. When employees turn to unsanctioned tools, it often points to a gap between what people need to do their jobs and what approved systems allow them to do.</p><p>The organizations that respond well will not be those that only add stricter controls. They will be those that make secure behavior easier to adopt than unsafe workarounds.</p><p>That requires clear ownership, practical tools, accessible guidance and security processes designed around real workflows.</p><p>In the age of AI, reducing risk means giving employees secure routes that are practical enough to use. When the approved path is also the easiest path, businesses can protect data without slowing people down.</p><p><em></em><a href="https://www.techradar.com/best/password-manager"><em>We've reviewed and ranked the best password managers</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>