<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-SG"
                       href="https://www.techradar.com/sg/feeds/tag/security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar SG in Security ]]></title>
                <link>https://www.techradar.com/sg/pro/security</link>
        <description><![CDATA[ All the latest security content from the TechRadar  SG team ]]></description>
                                    <lastBuildDate>Fri, 21 Aug 2026 03:00:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM</strong></li><li><strong>LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of an open-source security scanner</strong></li><li><strong>Some of the credentials still work, nearly five months after the original breach, indicating that there is still a persistent security risk until they are changed</strong></li></ul><p>Security firms CloudSEK and Hudson Rock have claimed more than 2,500 organizations have had credentials harvested in a supply-chain attack on LiteLLM.</p><p>LiteLLM, an open source gateway which translates API calls for over 100 large language models into a single OpenAI-compatible format, was not directly compromised in the attack, as hackers targeted a known vulnerability in Aqua Security's Trivy.</p><p>The list included many large and critical service providers, including but not limited to Cisco, Samsung, Salesforce, and Amazon Web Services, as well as Airbus U.S. Space & Defense, Thales Group, Deutsche Bahn, Munich Re, and the London Stock Exchange Group.</p><h2 id="an-attack-that-is-still-a-concern-nearly-five-months-later">An attack that is still a concern nearly five months later</h2><p>The original attack occurred on March 24 2026 and was spearheaded by a financially motivated hacking group called TeamPCP, which compromised Trivy, an open source security tool that scans for vulnerabilities.</p><p>The modified package, which was subsequently downloaded and 'invited' in by LiteLLM without checking its ID- an automated process that essentially allowed a poisoned version of the trusted tool in- gained server administrator privileges and then installed a stealer.</p><p>The stealer compromised credentials and secrets far more valuable than corporate data, including Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys.</p><p>These are arguably worse from a security standpoint than a singular breach because of both the scale of the attack and the fact that hackers now had a 'key' to many security doors rather than having to run exploits to get there.</p><p>The victim-scale research <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" target="_blank">done by CloudSEK</a> was further <a href="https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure" target="_blank">corroborated the following day by Hudson Rock,</a> and it painted a grim picture of what was still an outstanding issue nearly 5 months after the original attack.</p><p>The irony is that some of the credentials still work: Independent researcher Kevin Beaumont said <a href="https://cyberplace.social/@GossiTheDog/117084861164567831" target="_blank">some of the compromised keys were still valid</a> after he tested them, even as the impacted organization insisted it had 'rotated' those keys to new ones. </p><p>CloudSEK's figures indicate 2,500-plus companies and 434,000 CI/CD pipelines were compromised, while Hudson Rock has released a 153 GB archive of the exfiltrated material after examining a 195 TB file it had obtained. Both firms are running <a href="https://exposure.cloudsek.com/ai-supply-chain-incident" target="_blank">domain-lookup tools</a> so organizations can check their own exposure online.</p><p>Whether these revelations lead organizations to double-check their use of AI tools in multiple mission-critical instances that could compromise not only customer data but their own trade secrets down the line remains to be seen.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/massive-supply-chain-attack-sees-terabytes-of-data-belonging-to-some-of-the-worlds-biggest-and-most-sensitive-organizations-leaked-online</link>
                                                                            <description>
                            <![CDATA[ Hackers compromised a security tool, used it to steal the publishing keys of a popular AI tool, and released a poisoned version under that tool's real name in a far-reaching attack ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">P9jdiJp3QVmve9YwEXsdCb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 21 Aug 2026 03:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM</strong></li><li><strong>LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of an open-source security scanner</strong></li><li><strong>Some of the credentials still work, nearly five months after the original breach, indicating that there is still a persistent security risk until they are changed</strong></li></ul><p>Security firms CloudSEK and Hudson Rock have claimed more than 2,500 organizations have had credentials harvested in a supply-chain attack on LiteLLM.</p><p>LiteLLM, an open source gateway which translates API calls for over 100 large language models into a single OpenAI-compatible format, was not directly compromised in the attack, as hackers targeted a known vulnerability in Aqua Security's Trivy.</p><p>The list included many large and critical service providers, including but not limited to Cisco, Samsung, Salesforce, and Amazon Web Services, as well as Airbus U.S. Space & Defense, Thales Group, Deutsche Bahn, Munich Re, and the London Stock Exchange Group.</p><h2 id="an-attack-that-is-still-a-concern-nearly-five-months-later">An attack that is still a concern nearly five months later</h2><p>The original attack occurred on March 24 2026 and was spearheaded by a financially motivated hacking group called TeamPCP, which compromised Trivy, an open source security tool that scans for vulnerabilities.</p><p>The modified package, which was subsequently downloaded and 'invited' in by LiteLLM without checking its ID- an automated process that essentially allowed a poisoned version of the trusted tool in- gained server administrator privileges and then installed a stealer.</p><p>The stealer compromised credentials and secrets far more valuable than corporate data, including Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys.</p><p>These are arguably worse from a security standpoint than a singular breach because of both the scale of the attack and the fact that hackers now had a 'key' to many security doors rather than having to run exploits to get there.</p><p>The victim-scale research <a href="https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines" target="_blank">done by CloudSEK</a> was further <a href="https://www.hudsonrock.com/blog/largest-ai-supply-chain-breach-of-2026-litellm-hack-impacts-thousands-of-global-enterprises-claim-your-ethical-disclosure" target="_blank">corroborated the following day by Hudson Rock,</a> and it painted a grim picture of what was still an outstanding issue nearly 5 months after the original attack.</p><p>The irony is that some of the credentials still work: Independent researcher Kevin Beaumont said <a href="https://cyberplace.social/@GossiTheDog/117084861164567831" target="_blank">some of the compromised keys were still valid</a> after he tested them, even as the impacted organization insisted it had 'rotated' those keys to new ones. </p><p>CloudSEK's figures indicate 2,500-plus companies and 434,000 CI/CD pipelines were compromised, while Hudson Rock has released a 153 GB archive of the exfiltrated material after examining a 195 TB file it had obtained. Both firms are running <a href="https://exposure.cloudsek.com/ai-supply-chain-incident" target="_blank">domain-lookup tools</a> so organizations can check their own exposure online.</p><p>Whether these revelations lead organizations to double-check their use of AI tools in multiple mission-critical instances that could compromise not only customer data but their own trade secrets down the line remains to be seen.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ NASA's ground control software has a worrying security flaw which could let hackers contact spacecraft ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>NASA’s ground control software has a critical vulnerability that could allow third-party access to spacecraft</strong></li><li><strong>The flaw has been found in a browser-based variant of NASA’s AMMOS Instrument Toolkit</strong></li><li><strong>NASA has not publicly responded to the flaw’s disclosure</strong></li></ul><p>NASA’s open source ground control software has a critical vulnerability that could enable an unauthenticated attacker to gain access and take control of spacecraft. The AMMOS Instrument Toolkit’s browser-based interface is the source of the vulnerability, which has since been resolved.</p><p>The AIT-GUI (AMMOS Instrument Toolkit Graphical User Interface) tool up to version 2.5.1 has been identified as vulnerable, but the fault has been fixed in v2.5.2, according to researcher Yuval Elbar.</p><p>If the vulnerability had been found by a third party, it would have given access to issue commands to spacecraft, instruments, and execute server-side scripts. In addition, command sequences could potentially have been run by an attacker, leaving craft almost wholly beyond NASA’s control.</p><h2 id="weak-api">Weak API</h2><p>Elbar, who works with the Cycode Agentic Development Security Platform, <a href="https://cycode.com/blog/ait-gui-unauthenticated-command-execution/" target="_blank">disclosed</a> the vulnerability on August 18, 2026. The problem appears to start with AIT-GUI running as a web server with all network interfaces open, rather than the host’s setting. Incredibly, the API also has no authentication, or authorization protection. In addition, the CSRF (cross-site request forgery) protection on changing endpoints is also absent on affected versions of AIT-GUI.</p><p>Attackers can exploit basic access-control security failings in AIT-GUI, exposing the /cmd and /script/run and /seq prompts while also setting up filesystem paths. This enables files (potentially malware, or custom-built scripts) to be passed directly to NASA craft via a vulnerable AIT-GUI browser session, potentially escalating to full control.</p><p>To emphasize the scale of the weakness, Elbar introduced the disclosure with “A web GUI used to drive spacecraft and instrument commanding shipped a server that listens on every network interface, asks nobody for a password, and can be steered by any web page an operator happens to open.”</p><h2 id="external-access">External access</h2><p>As if this wasn’t concerning enough, the attacker doesn’t need to be on the same network. Direct access via an exposed port, or directing an operator to a web page hiding malicious code, or even simply a web page under live control by an attacker, can afford access to a third party.</p><p>Elbar adds “operational and ground-system software inherits the same web weaknesses as everything else, but with a far higher cost of failure. Auth, CSRF defense, and input confinement are not optional extras on a panel that commands hardware.”</p><p>Cycode advises administrators of AIT systems to upgrade AIT-GUI to v2.5.2 and run checks on the console port. They should also review command history.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/nasas-ground-control-software-has-a-worrying-security-flaw-which-could-let-hackers-contact-spacecraft</link>
                                                                            <description>
                            <![CDATA[ Security researchers uncover flaw in the open source software used by NASA ground control to communicate with instruments and spacecraft. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GavWpCWPsakeaQDwtaCU3D</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/S52AXmcF8SwjhEHAXXYc7k-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 20:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/S52AXmcF8SwjhEHAXXYc7k-1280-80.jpg">
                                                            <media:credit><![CDATA[ahundt / Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[NASA]]></media:description>                                                            <media:text><![CDATA[NASA]]></media:text>
                                <media:title type="plain"><![CDATA[NASA]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/S52AXmcF8SwjhEHAXXYc7k-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NASA’s ground control software has a critical vulnerability that could allow third-party access to spacecraft</strong></li><li><strong>The flaw has been found in a browser-based variant of NASA’s AMMOS Instrument Toolkit</strong></li><li><strong>NASA has not publicly responded to the flaw’s disclosure</strong></li></ul><p>NASA’s open source ground control software has a critical vulnerability that could enable an unauthenticated attacker to gain access and take control of spacecraft. The AMMOS Instrument Toolkit’s browser-based interface is the source of the vulnerability, which has since been resolved.</p><p>The AIT-GUI (AMMOS Instrument Toolkit Graphical User Interface) tool up to version 2.5.1 has been identified as vulnerable, but the fault has been fixed in v2.5.2, according to researcher Yuval Elbar.</p><p>If the vulnerability had been found by a third party, it would have given access to issue commands to spacecraft, instruments, and execute server-side scripts. In addition, command sequences could potentially have been run by an attacker, leaving craft almost wholly beyond NASA’s control.</p><h2 id="weak-api">Weak API</h2><p>Elbar, who works with the Cycode Agentic Development Security Platform, <a href="https://cycode.com/blog/ait-gui-unauthenticated-command-execution/" target="_blank">disclosed</a> the vulnerability on August 18, 2026. The problem appears to start with AIT-GUI running as a web server with all network interfaces open, rather than the host’s setting. Incredibly, the API also has no authentication, or authorization protection. In addition, the CSRF (cross-site request forgery) protection on changing endpoints is also absent on affected versions of AIT-GUI.</p><p>Attackers can exploit basic access-control security failings in AIT-GUI, exposing the /cmd and /script/run and /seq prompts while also setting up filesystem paths. This enables files (potentially malware, or custom-built scripts) to be passed directly to NASA craft via a vulnerable AIT-GUI browser session, potentially escalating to full control.</p><p>To emphasize the scale of the weakness, Elbar introduced the disclosure with “A web GUI used to drive spacecraft and instrument commanding shipped a server that listens on every network interface, asks nobody for a password, and can be steered by any web page an operator happens to open.”</p><h2 id="external-access">External access</h2><p>As if this wasn’t concerning enough, the attacker doesn’t need to be on the same network. Direct access via an exposed port, or directing an operator to a web page hiding malicious code, or even simply a web page under live control by an attacker, can afford access to a third party.</p><p>Elbar adds “operational and ground-system software inherits the same web weaknesses as everything else, but with a far higher cost of failure. Auth, CSRF defense, and input confinement are not optional extras on a panel that commands hardware.”</p><p>Cycode advises administrators of AIT systems to upgrade AIT-GUI to v2.5.2 and run checks on the console port. They should also review command history.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android users beware — if you own one of these budget smartphones, your device could be hacked with a simple video call ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Unisoc system-on-chip (SoC) devices – usually budget smartphones – are vulnerable to a video call-based exploit</strong></li><li><strong>Any smartphone can be used to place the call, with malicious code sent in call setup messages</strong></li><li><strong>Despite attempts, Unisoc did not respond to the disclosure</strong></li></ul><p>Security researchers have demonstrated a weakness in several Unisoc SoC-based devices that makes them vulnerable to an exploit sent during a video call. The exploit can deliver root access of the target device to the attacker, placing them in full control of the handset.</p><p>The vulnerability is in the firmware running on several Unisoc SoCs, each of which are used in budget smartphones, including models from Xiaomi, Motorola, and Realme.</p><p>A successful attack can be used to alter an Android device’s operating system, but the proof-of-concept was tested on a controlled network rather than a carrier network. Additionally, the devices involved were rooted. Consequently, the attack may not have real-world implications.</p><h2 id="which-phones-are-affected">Which phones are affected?</h2><p>While you may not know the name Unisoc, it is a big player in the chip business, sitting fourth behind MediaTek, Qualcomm, and Apple. Its chips appear in IoT and smart home devices, as well as mobile technology, typically for well-known companies including Samsung and Motorola.</p><p>The researcher who uncovered the vulnerability is known only by the alias 0x50594d. </p><p>They tested the exploit on three models:</p><p>    • Realme C33</p><p>    • Xiaomi Redmi A5 (with security patch level 2026-01-01)</p><p>    • Motorola E13 (running security patch level 2025-02-01)</p><p>In addition, the phones were installed with the July 2025 Android security update.</p><p>The advisory indicates that the flaw is in the modem firmware of four Unisoc SoCs. These are the T612, T616, T606, and T7250, which means any phone using those SoCs is potentially at risk. </p><p>However, it is important to note that the vulnerability was exploited in specific conditions.</p><h2 id="improper-isolation">Improper Isolation</h2><p>The phones used in testing the exploit were all rooted, a process that makes devices prone to malware. In the majority of cases, these phones would not normally be rooted. In addition, the exploit was tested across a closed VoLTE network, rather than across a carrier network. </p><p>Finally, as noted, the phones were running older security patches. So, the conditions for the exploit are very specific, but nevertheless concerning.</p><p>0x50594d’s research was published on the SSD Secure Disclosure website, which summarized it as an “exploitable Improper Isolation of Shared Resources on System-on-a-Chip. A critical vulnerability has been identified in the Unisoc modem firmware that allows arbitrary code execution with kernel privileges from the modem context.”</p><p>“An attacker who gains the ability to execute code on the modem can read from and write to the entire memory space by disabling protections on the first Memory Protection Unit (MPU) region (region ID 0).”</p><p>It is should be noted that Unisoc has so far failed to respond to the security disclosure.</p><p><em>Via </em><a href="https://cybernews.com/security/millions-android-phones-exposed-unisoc-modem-flaw/" target="_blank"><em>Cybernews</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-users-beware-if-you-own-one-of-these-budget-smartphones-your-device-could-be-hacked-with-a-simple-video-call</link>
                                                                            <description>
                            <![CDATA[ Security researchers uncover exploit on budget smartphones equipped with a Unisoc system-on-chip, initiated by starting a video call and able to grant root access to an attacker ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7dTizPTTN5jWTw9eeS9gxh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sMMYYw2WasgE4m4saLhZ9M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 18:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Realme Phones]]></category>
                                                    <category><![CDATA[Android]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Phones]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sMMYYw2WasgE4m4saLhZ9M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / fizkes]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A man looking frustrated at his mobile phone]]></media:description>                                                            <media:text><![CDATA[A man looking frustrated at his mobile phone]]></media:text>
                                <media:title type="plain"><![CDATA[A man looking frustrated at his mobile phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sMMYYw2WasgE4m4saLhZ9M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Unisoc system-on-chip (SoC) devices – usually budget smartphones – are vulnerable to a video call-based exploit</strong></li><li><strong>Any smartphone can be used to place the call, with malicious code sent in call setup messages</strong></li><li><strong>Despite attempts, Unisoc did not respond to the disclosure</strong></li></ul><p>Security researchers have demonstrated a weakness in several Unisoc SoC-based devices that makes them vulnerable to an exploit sent during a video call. The exploit can deliver root access of the target device to the attacker, placing them in full control of the handset.</p><p>The vulnerability is in the firmware running on several Unisoc SoCs, each of which are used in budget smartphones, including models from Xiaomi, Motorola, and Realme.</p><p>A successful attack can be used to alter an Android device’s operating system, but the proof-of-concept was tested on a controlled network rather than a carrier network. Additionally, the devices involved were rooted. Consequently, the attack may not have real-world implications.</p><h2 id="which-phones-are-affected">Which phones are affected?</h2><p>While you may not know the name Unisoc, it is a big player in the chip business, sitting fourth behind MediaTek, Qualcomm, and Apple. Its chips appear in IoT and smart home devices, as well as mobile technology, typically for well-known companies including Samsung and Motorola.</p><p>The researcher who uncovered the vulnerability is known only by the alias 0x50594d. </p><p>They tested the exploit on three models:</p><p>    • Realme C33</p><p>    • Xiaomi Redmi A5 (with security patch level 2026-01-01)</p><p>    • Motorola E13 (running security patch level 2025-02-01)</p><p>In addition, the phones were installed with the July 2025 Android security update.</p><p>The advisory indicates that the flaw is in the modem firmware of four Unisoc SoCs. These are the T612, T616, T606, and T7250, which means any phone using those SoCs is potentially at risk. </p><p>However, it is important to note that the vulnerability was exploited in specific conditions.</p><h2 id="improper-isolation">Improper Isolation</h2><p>The phones used in testing the exploit were all rooted, a process that makes devices prone to malware. In the majority of cases, these phones would not normally be rooted. In addition, the exploit was tested across a closed VoLTE network, rather than across a carrier network. </p><p>Finally, as noted, the phones were running older security patches. So, the conditions for the exploit are very specific, but nevertheless concerning.</p><p>0x50594d’s research was published on the SSD Secure Disclosure website, which summarized it as an “exploitable Improper Isolation of Shared Resources on System-on-a-Chip. A critical vulnerability has been identified in the Unisoc modem firmware that allows arbitrary code execution with kernel privileges from the modem context.”</p><p>“An attacker who gains the ability to execute code on the modem can read from and write to the entire memory space by disabling protections on the first Memory Protection Unit (MPU) region (region ID 0).”</p><p>It is should be noted that Unisoc has so far failed to respond to the security disclosure.</p><p><em>Via </em><a href="https://cybernews.com/security/millions-android-phones-exposed-unisoc-modem-flaw/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are using “evolved” capabilities in AI-generated malware to hit US critical infrastructure at an unprecedented scale —  “active threat” currently hitting energy, water and agricultural industries ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/hackers-are-using-evolved-capabilities-in-ai-generated-malware-to-hit-us-critical-infrastructure-at-an-unprecedented-scale-active-threat-currently-hitting-energy-water-and-agricultural-industries</link>
                                                                            <description>
                            <![CDATA[ The attackers are exploiting internet-facing Siemens S7 Series programmable logic controllers to scout for potential targets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QDfEDMhpgNJ3K4drrGKAGb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 17:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/supimol kumying]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:description>                                                            <media:text><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:text>
                                <media:title type="plain"><![CDATA[cyber, attack, hacked word on screen binary code display, hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kHR7hTFieuBmjcpgHnKHh4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Siemens S7 Series programmable logic controllers are being hit in a new critical infrastructure attack against energy, water and agriculture</strong></li><li><strong>Attackers are using AI-generated malware to chain exploitations, and hiding their malicious software as a monitoring tool</strong></li><li><strong>The identity of the attackers is not known</strong></li></ul><p>A joint warning issued by federal agencies has warned that US critical infrastructure is facing an “active threat” in the form of AI-generated malware specifically targeting programmable logic controllers (PLCs).</p><p>PLCs are widely used across the energy, water and agricultural industries to control pumps and monitor systems. The attacks have been labelled as an “evolution” in attacker capabilities, with the AI systems capable of chaining exploitations to gain control of PLCs.</p><p>The warning comes from the National Security Agency (NSA) and FBI, alongside other federal agencies who said in an <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a?utm_source=SiemensS7SeriesPLC&utm_medium=GovDelivery" target="_blank" rel="nofollow">advisory</a> that, “This is not a theoretical risk — it is an active threat.”</p><h2 id="siemens-s7-series-plcs-under-active-attack">Siemens S7 Series PLCs under active attack</h2><p>The advisory warns that Siemens S7 Series PLCs are the chosen target of this latest campaign with the attackers leveraging “AI-assisted development” in their penetration.</p><p>“Depending on the specific circumstances, exploitation of poorly protected PLCs could lead to disruption of critical industrial processes, safety incidents, downtime or equipment damage, compromise of sensitive data, compliance violations, and cascading impacts across interconnected systems,” the advisory warns.</p><p>The identity of the attackers has not been revealed, but critical infrastructure systems are a favorite target of state-sponsored groups looking to scout out potential targets to later cripple water treatment and disrupt energy supplies.</p><p>The hackers are locating vulnerable PLCs using internet scanning platforms and disguising the malware as monitoring tools in order to evade detection. To defend against this attack vector, the advisory said that PLCs should be isolated from the internet, with software updates performed as soon as they become available.</p><p>The advisory said that the attacks are “an evolution in threat actor capabilities,” with the AI generated scripts “dramatically reducing the technical expertise and time required to develop working exploitation scripts and malicious tools.”</p><h2 id="who-has-been-targeting-critical-infrastructure">Who has been targeting critical infrastructure?</h2><p>The US war with Iran has led to a significant increase in attacks against critical infrastructure.</p><p>In July 2026, an <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">attack against the operational technology of 30 Minnesota community water systems</a> showed indications of Iranian involvement. Shortly before the attack CISA updated an advisory warning that Rockwell Automation, Schneider Electric, and Siemens PLCs were under active attack.</p><p>April saw Rockwell Automation/Allen-Bradley-manufactured <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">PLCs were exploited in attacks against water and energy systems</a>, as well as to compromise Government Services and Facilities. </p><p><a href="https://www.techradar.com/pro/security/nsa-warns-that-cybercriminals-are-targeting-this-one-critical-component-that-the-energy-chemical-food-agriculture-and-transportation-sectors-rely-on-heres-what-we-know">Automatic Tank Gauge (ATG) systems have also been hit during attacks</a> targeting energy, chemical, food, agriculture, and transportation industries. These systems were also found to be largely internet-facing, and when compromised could allow attackers to turn off systems designed to monitor fuel levels, temperature and potential leaks.</p><p>Russia has also been involved in targeting critical infrastructure at a global scale. The <a href="https://www.techradar.com/pro/security/us-and-security-allies-warn-russian-attacks-on-critical-infrastructure-are-ramping-up-against-poorly-configured-and-vulnerable-networking-devices-worldwide">attacks hit broken and poorly configured networking devices</a> such as routers that had passed their End-of-Life (EoL) and were no longer receiving updates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers pose as ransomware recovery agents, but just go on to steal more from victims ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>GuidePoint observed “Ransom Busters” posing as recovery firms in ransomware incidents</strong></li><li><strong>Group claimed to hack RaaS panels, offering decryption keys for $20K–$60K</strong></li><li><strong>Researchers say it’s likely the same affiliates behind infections, not genuine rescuers</strong></li></ul><p>Ransomware operations have evolved again, and this time around the crooks are pretending to be the good guys.</p><p>Cybersecurity researchers GuidePoint Security were recently brought in to respond to multiple <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks against their clients. In some of those incidents, the victims were also contacted by a group calling themselves “Ransom Busters”, which offered to delete the stolen files from the attackers’ servers, while providing the victims with working decryption keys.</p><p>What made the offer suspicious was the fact that Ransom Busters reached out to the victims before the attackers had gone public. The crooks claimed to have hacked into the admin panels of multiple Ransomware-as-a-Service (RaaS) operations, including DragonForce, Settra, and Anubis, giving them not just insight into who was targeted, but also access to stolen data and the decryption keys.</p><h2 id="just-another-affiliate">Just another affiliate</h2><p>For their services, Ransom Busters ask between $20,000, and $60,000 - however, the researchers are saying this is all a ruse, and that Ransom Busters are, most likely, just affiliates of these ransomware services. Not only that, but they are also most likely the ones who infected these companies with ransomware in the first place.</p><p>They said that both the attackers and Ransom Busters are using the same software, same tactics, and same identifiers, leading to the conclusion that it’s the same group on both ends of the spectrum. </p><p>The good news is that no one seems to have paid Ransom Busters for their offer. The only thing GuidePoint observed was one victim paying the actual ransom demand, rather than the fake recovery firm. That firm, fortunately, did not have its name listed on the leak site, and its files remain secure for now.</p><p>Pretending to be a recovery firm is the next evolutionary step in the life of ransomware. </p><p>In its early days, ransomware was all about encrypting the computers and asking for payment in exchange for the decryption key. When companies responded by building out strong backups, the criminals moved to stealing files and threatening to release them to the public. Soon after, some added Distributed Denial of Service (DDoS) into the mix, blocking not just the back end but also the front-end, in an effort to force a payment.</p><p>Some criminals even called their victims on the phone for further intimidation.</p><p>These days, more and more groups are moving away from encryptors and focus solely on data theft, since it’s cheaper yet equally lucrative.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-pose-as-ransomware-recovery-agents-but-just-go-on-to-steal-more-from-victims</link>
                                                                            <description>
                            <![CDATA[ Ransom Busters are not an actual ransomware recovery firm - they're ransomware affiliates looking to steal your money, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3sbDoKf4V4v9EtMs8LXuvL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 15:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GuidePoint observed “Ransom Busters” posing as recovery firms in ransomware incidents</strong></li><li><strong>Group claimed to hack RaaS panels, offering decryption keys for $20K–$60K</strong></li><li><strong>Researchers say it’s likely the same affiliates behind infections, not genuine rescuers</strong></li></ul><p>Ransomware operations have evolved again, and this time around the crooks are pretending to be the good guys.</p><p>Cybersecurity researchers GuidePoint Security were recently brought in to respond to multiple <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks against their clients. In some of those incidents, the victims were also contacted by a group calling themselves “Ransom Busters”, which offered to delete the stolen files from the attackers’ servers, while providing the victims with working decryption keys.</p><p>What made the offer suspicious was the fact that Ransom Busters reached out to the victims before the attackers had gone public. The crooks claimed to have hacked into the admin panels of multiple Ransomware-as-a-Service (RaaS) operations, including DragonForce, Settra, and Anubis, giving them not just insight into who was targeted, but also access to stolen data and the decryption keys.</p><h2 id="just-another-affiliate">Just another affiliate</h2><p>For their services, Ransom Busters ask between $20,000, and $60,000 - however, the researchers are saying this is all a ruse, and that Ransom Busters are, most likely, just affiliates of these ransomware services. Not only that, but they are also most likely the ones who infected these companies with ransomware in the first place.</p><p>They said that both the attackers and Ransom Busters are using the same software, same tactics, and same identifiers, leading to the conclusion that it’s the same group on both ends of the spectrum. </p><p>The good news is that no one seems to have paid Ransom Busters for their offer. The only thing GuidePoint observed was one victim paying the actual ransom demand, rather than the fake recovery firm. That firm, fortunately, did not have its name listed on the leak site, and its files remain secure for now.</p><p>Pretending to be a recovery firm is the next evolutionary step in the life of ransomware. </p><p>In its early days, ransomware was all about encrypting the computers and asking for payment in exchange for the decryption key. When companies responded by building out strong backups, the criminals moved to stealing files and threatening to release them to the public. Soon after, some added Distributed Denial of Service (DDoS) into the mix, blocking not just the back end but also the front-end, in an effort to force a payment.</p><p>Some criminals even called their victims on the phone for further intimidation.</p><p>These days, more and more groups are moving away from encryptors and focus solely on data theft, since it’s cheaper yet equally lucrative.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ransom-busters-poses-as-recovery-firm/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Moving AI from pilot to production ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Most organizations don't need convincing that <a href="https://www.techradar.com/best/best-ai-tools">AI</a> has potential. What I'm seeing instead is businesses trying to work out how to turn that potential into something that delivers real value.</p><p>Across the organizations we're working with, the conversation has shifted. Business leaders are increasingly confident in AI's potential, but many are now focused on whether they're moving quickly enough to realize that value.</p><p>In my experience, the organizations making the fastest progress are those with clear use cases, the right foundations and the confidence to move successful pilots into production.</p><p>We're seeing this reflected in conversations with customers every day. </p><p>Organizations are moving beyond asking what AI could do and are now focused on how to scale it in a way that delivers measurable business impact. </p><p>The reality is that experimentation has shown what's possible.  The challenge now is deploying AI consistently, securely, intentionally and at scale across the organization.</p><h2 id="building-the-right-foundations">Building the right foundations</h2><p>The past two years have rightly been characterized by experimentation as organizations explored new use cases, tested emerging technologies and began to understand where AI can make the biggest difference.</p><p>Getting an initial AI use case into production is an important milestone. The harder task is repeating that success across multiple teams, business processes and environments while maintaining <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, governance and performance.</p><p><a href="https://www.techradar.com/best/best-infrastructure-management-service">Infrastructure</a> is fundamental to successful AI adoption, and while the models, training, GPUs and applications are all important, networking is the critical part of that foundation. Previously, many organizations defaulted to a cloud-first approach where almost every new workload was expected to live in the <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a>. Today, business leaders are becoming more intentional, carefully considering the purpose of each AI workload and where it resides.</p><p>For many organizations, modernizing existing infrastructure is a higher priority than replacing it. The focus is on ensuring current environments can support growing AI workloads while continuing to deliver the resilience, security and agility the business depends on.</p><p>Infrastructure alone, however, isn't enough. Organizations also need to be clear about the problems they're trying to solve.</p><p>I've found it's far more effective to begin with focused, modular, use case-driven deployments than with large-scale AI programs that attempt to transform the organization overnight. Whether its helping customer service teams resolve queries faster, improving fraud detection, supporting engineers with technical knowledge or helping <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> automate repetitive tasks, organizations build confidence much faster when people can see AI solving real operational problems.</p><p>When organizations can demonstrate tangible business benefits and measurable return on investment from one deployment, it becomes much easier to move successful pilots into production and expand AI into other parts of the business.</p><h2 id="building-trust-in-ai">Building trust in AI</h2><p>As organizations become more ambitious with AI, trust becomes every bit as important as capability.</p><p>Trust is the cornerstone of AI adoption. Without trust, adoption stalls because users and stakeholders are less likely to engage with new technologies, regardless of their potential benefits.</p><p>At the same time, AI workloads introduce a level of operational dynamism that many existing security approaches were not designed to manage. As organizations connect more data, deploy larger models and begin introducing autonomous agents into operational workflows, they need security capabilities that evolve alongside them.</p><p>Security, governance and transparency aren't obstacles to innovation. They're what enable organizations to deploy AI confidently and responsibly.</p><p>That means observability, security and governance need to be embedded into every layer of the AI environment, from infrastructure and networks through to <a href="https://www.techradar.com/best/best-mobile-app-development-software">applications</a>, models and autonomous agents. Organizations must manage AI agents and ensure they remain secure while operating within clearly defined business guardrails, in many cases applying the same principles of control, management and security as they have done to human workers for years.</p><p>The challenge is that organizations are no longer governing a single AI application. They're increasingly managing multiple models, tools and services across different environments. Creating governance that keeps pace with that complexity requires security to become part of day-to-day operations rather than an afterthought.</p><p>Ethical, transparent and responsible use of AI also builds the confidence employees, customers and stakeholders need before AI can be adopted at scale. Without robust security and governance, organizations are likely to remain cautious, limiting both adoption and the value AI can deliver.</p><h2 id="make-ai-personal">Make AI personal</h2><p>Organizations make much faster progress when people can see how AI helps them solve a real problem. In our experience, people are much more likely to use AI once they've seen it solve a problem they recognize. </p><p>That's why leaders have an important role to play. </p><p>When leaders share practical examples, demonstrate how AI helps them in their own roles and encourage experimentation, they create the confidence others need to do the same.</p><h2 id="the-uk-s-opportunity">The UK's opportunity</h2><p>The UK has a significant opportunity to become a global leader in enterprise AI adoption by helping organizations move beyond experimentation and deploy AI securely, responsibly and at scale.</p><p>In my experience, successful AI adoption starts with strong foundations - investing in infrastructure that can support AI workloads, becoming more intentional about where those workloads run, embedding security and governance into every layer of the AI environment, and focusing on practical use cases that demonstrate measurable business value before scaling further.</p><h2 id="going-forward">Going forward</h2><p>AI is increasingly becoming a business imperative. The opportunity now is to help more organizations deploy AI consistently, securely and at scale. </p><p>Those that take a deliberate, long-term approach to infrastructure, trust and adoption will be better placed to realize the full potential of AI across the business. </p><p>If we can help more organizations make that transition from pilot to production, the UK will be well placed to lead through successful AI adoption.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've listed the best cloud backup solutions</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/moving-ai-from-pilot-to-production</link>
                                                                            <description>
                            <![CDATA[ Why infrastructure, trust and leadership are key to scaling enterprise AI successfully. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CyhX9STk7oK9pskN4eT87J</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 14:22:25 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Rob Lay ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most organizations don't need convincing that <a href="https://www.techradar.com/best/best-ai-tools">AI</a> has potential. What I'm seeing instead is businesses trying to work out how to turn that potential into something that delivers real value.</p><p>Across the organizations we're working with, the conversation has shifted. Business leaders are increasingly confident in AI's potential, but many are now focused on whether they're moving quickly enough to realize that value.</p><p>In my experience, the organizations making the fastest progress are those with clear use cases, the right foundations and the confidence to move successful pilots into production.</p><p>We're seeing this reflected in conversations with customers every day. </p><p>Organizations are moving beyond asking what AI could do and are now focused on how to scale it in a way that delivers measurable business impact. </p><p>The reality is that experimentation has shown what's possible.  The challenge now is deploying AI consistently, securely, intentionally and at scale across the organization.</p><h2 id="building-the-right-foundations">Building the right foundations</h2><p>The past two years have rightly been characterized by experimentation as organizations explored new use cases, tested emerging technologies and began to understand where AI can make the biggest difference.</p><p>Getting an initial AI use case into production is an important milestone. The harder task is repeating that success across multiple teams, business processes and environments while maintaining <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, governance and performance.</p><p><a href="https://www.techradar.com/best/best-infrastructure-management-service">Infrastructure</a> is fundamental to successful AI adoption, and while the models, training, GPUs and applications are all important, networking is the critical part of that foundation. Previously, many organizations defaulted to a cloud-first approach where almost every new workload was expected to live in the <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a>. Today, business leaders are becoming more intentional, carefully considering the purpose of each AI workload and where it resides.</p><p>For many organizations, modernizing existing infrastructure is a higher priority than replacing it. The focus is on ensuring current environments can support growing AI workloads while continuing to deliver the resilience, security and agility the business depends on.</p><p>Infrastructure alone, however, isn't enough. Organizations also need to be clear about the problems they're trying to solve.</p><p>I've found it's far more effective to begin with focused, modular, use case-driven deployments than with large-scale AI programs that attempt to transform the organization overnight. Whether its helping customer service teams resolve queries faster, improving fraud detection, supporting engineers with technical knowledge or helping <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> automate repetitive tasks, organizations build confidence much faster when people can see AI solving real operational problems.</p><p>When organizations can demonstrate tangible business benefits and measurable return on investment from one deployment, it becomes much easier to move successful pilots into production and expand AI into other parts of the business.</p><h2 id="building-trust-in-ai">Building trust in AI</h2><p>As organizations become more ambitious with AI, trust becomes every bit as important as capability.</p><p>Trust is the cornerstone of AI adoption. Without trust, adoption stalls because users and stakeholders are less likely to engage with new technologies, regardless of their potential benefits.</p><p>At the same time, AI workloads introduce a level of operational dynamism that many existing security approaches were not designed to manage. As organizations connect more data, deploy larger models and begin introducing autonomous agents into operational workflows, they need security capabilities that evolve alongside them.</p><p>Security, governance and transparency aren't obstacles to innovation. They're what enable organizations to deploy AI confidently and responsibly.</p><p>That means observability, security and governance need to be embedded into every layer of the AI environment, from infrastructure and networks through to <a href="https://www.techradar.com/best/best-mobile-app-development-software">applications</a>, models and autonomous agents. Organizations must manage AI agents and ensure they remain secure while operating within clearly defined business guardrails, in many cases applying the same principles of control, management and security as they have done to human workers for years.</p><p>The challenge is that organizations are no longer governing a single AI application. They're increasingly managing multiple models, tools and services across different environments. Creating governance that keeps pace with that complexity requires security to become part of day-to-day operations rather than an afterthought.</p><p>Ethical, transparent and responsible use of AI also builds the confidence employees, customers and stakeholders need before AI can be adopted at scale. Without robust security and governance, organizations are likely to remain cautious, limiting both adoption and the value AI can deliver.</p><h2 id="make-ai-personal">Make AI personal</h2><p>Organizations make much faster progress when people can see how AI helps them solve a real problem. In our experience, people are much more likely to use AI once they've seen it solve a problem they recognize. </p><p>That's why leaders have an important role to play. </p><p>When leaders share practical examples, demonstrate how AI helps them in their own roles and encourage experimentation, they create the confidence others need to do the same.</p><h2 id="the-uk-s-opportunity">The UK's opportunity</h2><p>The UK has a significant opportunity to become a global leader in enterprise AI adoption by helping organizations move beyond experimentation and deploy AI securely, responsibly and at scale.</p><p>In my experience, successful AI adoption starts with strong foundations - investing in infrastructure that can support AI workloads, becoming more intentional about where those workloads run, embedding security and governance into every layer of the AI environment, and focusing on practical use cases that demonstrate measurable business value before scaling further.</p><h2 id="going-forward">Going forward</h2><p>AI is increasingly becoming a business imperative. The opportunity now is to help more organizations deploy AI consistently, securely and at scale. </p><p>Those that take a deliberate, long-term approach to infrastructure, trust and adoption will be better placed to realize the full potential of AI across the business. </p><p>If we can help more organizations make that transition from pilot to production, the UK will be well placed to lead through successful AI adoption.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've listed the best cloud backup solutions</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Healthtech firm CareCloud reveals March 2026 data breach impacted 3.7 million patients ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CareCloud confirmed March 16 2026 cyberattack exposed data of 3.7 million individuals</strong></li><li><strong>Attackers accessed one AWS environment, stealing personal records including names</strong></li><li><strong>Incident deemed non‑material but may incur remediation, legal, and reputational costs</strong></li></ul><p>The <a href="https://www.techradar.com/pro/security/healthcare-tech-firm-carecloud-admits-data-breach-says-hackers-accessed-patient-info-heres-what-we-know" target="_blank">March 2026 cyberattack on CareCloud</a> exposed sensitive data on 3.7 million people, the company has confirmed.</p><p>The American <a href="https://www.techradar.com/best/best-electronic-health-record-ehr-software" target="_blank">IT healthcare</a> company had told the US Securities and Exchange Commission (SEC) it experienced a “temporary network disruption” in its Health division which “partially impacted the functionality and data access to one of six electronic health record environments for approximately eight hours."</p><p>Initial investigation determined that the criminals accessed people’s personal records, but it was not said how many people were affected, what the nature of the files were, or if they were exfiltrated or just exposed.</p><h2 id="notifying-the-department-of-health">Notifying the Department of Health</h2><p>In late July 2026, the company started notifying its customers of the incident, saying the unidentified actors accessed one of CareCloud’s AWS environments and claimed to have stolen files found there. The company did not say which type of data was taken, other than people’s full names. </p><p>In a separate report with the US Department of Health and Human Services, the company confirmed the exact number of affected individuals as 3,756,469.</p><p>At press time, no hacking groups claimed responsibility for the attack, or shared details about the volume, nature, and type of data potentially stolen.</p><p>CareCloud is a publicly traded American healthcare technology firm providing <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud‑based software</a> and services to medical practices and health systems, including electronic health records (EHR), practice management, billing and revenue cycle solutions. It works with tens of thousands of healthcare providers across the United States in more than 70 specialties and across all 50 states, with over 40,000 providers on its platform.</p><p>In its initial report with the SEC, CareCloud said the incident did not have a material impact, but that it might incur expenses in remediation and response costs, legal, regulatory and notification-related matters, and could possibly affect patients, customers, counterparties, reputation and operations.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank"><em>BleepingComputer</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/healthtech-firm-carecloud-reveals-march-2026-data-breach-impacted-3-7-million-patients</link>
                                                                            <description>
                            <![CDATA[ Impacted CareCloud patients are being notified, but we don't know what information was taken. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YbMtuDcty3QHXHSSBtvpj7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 13:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg">
                                                            <media:credit><![CDATA[Rawpixel / Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[healthcare]]></media:description>                                                            <media:text><![CDATA[healthcare]]></media:text>
                                <media:title type="plain"><![CDATA[healthcare]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fLLbfyMxWuqokngy6WuMzH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CareCloud confirmed March 16 2026 cyberattack exposed data of 3.7 million individuals</strong></li><li><strong>Attackers accessed one AWS environment, stealing personal records including names</strong></li><li><strong>Incident deemed non‑material but may incur remediation, legal, and reputational costs</strong></li></ul><p>The <a href="https://www.techradar.com/pro/security/healthcare-tech-firm-carecloud-admits-data-breach-says-hackers-accessed-patient-info-heres-what-we-know" target="_blank">March 2026 cyberattack on CareCloud</a> exposed sensitive data on 3.7 million people, the company has confirmed.</p><p>The American <a href="https://www.techradar.com/best/best-electronic-health-record-ehr-software" target="_blank">IT healthcare</a> company had told the US Securities and Exchange Commission (SEC) it experienced a “temporary network disruption” in its Health division which “partially impacted the functionality and data access to one of six electronic health record environments for approximately eight hours."</p><p>Initial investigation determined that the criminals accessed people’s personal records, but it was not said how many people were affected, what the nature of the files were, or if they were exfiltrated or just exposed.</p><h2 id="notifying-the-department-of-health">Notifying the Department of Health</h2><p>In late July 2026, the company started notifying its customers of the incident, saying the unidentified actors accessed one of CareCloud’s AWS environments and claimed to have stolen files found there. The company did not say which type of data was taken, other than people’s full names. </p><p>In a separate report with the US Department of Health and Human Services, the company confirmed the exact number of affected individuals as 3,756,469.</p><p>At press time, no hacking groups claimed responsibility for the attack, or shared details about the volume, nature, and type of data potentially stolen.</p><p>CareCloud is a publicly traded American healthcare technology firm providing <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud‑based software</a> and services to medical practices and health systems, including electronic health records (EHR), practice management, billing and revenue cycle solutions. It works with tens of thousands of healthcare providers across the United States in more than 70 specialties and across all 50 states, with over 40,000 providers on its platform.</p><p>In its initial report with the SEC, CareCloud said the incident did not have a material impact, but that it might incur expenses in remediation and response costs, legal, regulatory and notification-related matters, and could possibly affect patients, customers, counterparties, reputation and operations.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breach-impacts-37-million-patients/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 9 million facial recognition images leaked in major breach at reverse image search and identity verification service ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researcher inds ClarityCheck’s exposed 450GB database with 9M+ user images</strong></li><li><strong>Leak included faces, profiles, and photos, risking identity theft and phishing abuse</strong></li><li><strong>Company secured access quickly; no evidence of dark web distribution or misuse so far</strong></li></ul><p>An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, phishing, and more, experts have warned.</p><p>Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, <a href="https://www.expressvpn.com/blog/clarity-check-data-exposed/" target="_blank">recently found</a> one totaling 450.2GB in size. </p><p>It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users. The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.</p><h2 id="what-happened">What happened?</h2><p>Further investigation showed the database belonging to a company called ClarityCheck. This is a US-registered firm describing itself as a “reverse phone, email, image, vehicle lookup”, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.</p><p>It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between. To do that, they will either steal other people’s photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence. </p><p>Being able to verify someone’s identity has become everyone’s essential due diligence, regardless of if it’s a personal or business matter.</p><h2 id="how-claritycheck-responded">How ClarityCheck responded</h2><p>As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings. The company responded quickly, barring further access, and thanking the researcher for his work.</p><p>“I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy,” the company’s representative told Fowler.</p><p>Unfortunately, without a deeper investigation on ClarityCheck’s end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before. However, so far there is no evidence of abuse, since a “ClarityCheck photo database” is currently not being distributed or sold anywhere on the dark web.</p><h2 id="exposing-people-to-hackers">Exposing people to hackers</h2><p>In a world where data theft and leaks are increasingly common, a cause that’s easiest to address, is also the one resulting in most exposures - <a href="https://www.techradar.com/pro/security/the-biggest-data-leaker-is-probably-not-who-you-think-it-is" target="_blank">misconfigured databases</a>. Nowadays, almost every business harvests and stores data about their employees, partners, and customers. Most of them store these files in cloud databases, for easier access and better integration with business intelligence software.</p><p>However, cloud service providers work on a so-called “shared responsibility model”, which means they are responsible for providing industry-standard security features. Users, on the other hand, are responsible for using those features and properly configuring their databases (namely, setting up a strong password or encrypting the content). Unfortunately, many organizations don’t seem to be aware of the shared responsibility model, firmly believing it’s the service provider’s task to keep the data safe. Others simply keep these archives accessible by mistake.</p><p>Criminals are aware of this, and are taking advantage of the situation to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases, and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.</p><p>Over the years, Fowler and other searchers have found dozens of enormous databases that have leaked sensitive data on hundreds of millions of people. </p><p>In 2026, researchers found that European cloud provider Nextcloud kept an <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach">unprotected database</a> on the public internet, containing 367,000 records (8GB) of sensitive employee and client data.</p><p>In 2025, IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, was <a href="https://www.techradar.com/pro/security/data-center-firm-leaks-massive-38gb-database-containing-thousands-of-personal-records-online">leaking</a> 38GB of sensitive personal records. The unencrypted and non-password-protected database held 10,820 in total.</p><p>In 2024, sports analytics technology company TrackMan <a href="https://www.techradar.com/pro/security/top-sports-tech-firm-leaked-data-and-even-professional-athletes-could-be-affected">exposed</a> sensitive customer data: 110TB and 31,602,260 records. The database had no password.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/over-9-million-facial-recognition-images-leaked-in-major-breach-at-reverse-image-search-and-identity-verification-service</link>
                                                                            <description>
                            <![CDATA[ ClarityCheck locks down huge database after being notified about the spill. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">62yugNeibkwi9EAvzkKbvV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:description>                                                            <media:text><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:text>
                                <media:title type="plain"><![CDATA[Back View of Young Black Man Walking and Looking at Big Digital Screens Glitching While Displaying Code Lines. Professional Hacker Breaking Through Cybersecurity Protection System, Changing Code]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BUi4eir3JnCCT2MRGt3weS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researcher inds ClarityCheck’s exposed 450GB database with 9M+ user images</strong></li><li><strong>Leak included faces, profiles, and photos, risking identity theft and phishing abuse</strong></li><li><strong>Company secured access quickly; no evidence of dark web distribution or misuse so far</strong></li></ul><p>An online reverse-lookup platform has inadvertently leaked millions of faces on the internet, putting people at risk of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a>, phishing, and more, experts have warned.</p><p>Jeremiah Fowler, a cybersecurity researcher known for hunting exposed databases, <a href="https://www.expressvpn.com/blog/clarity-check-data-exposed/" target="_blank">recently found</a> one totaling 450.2GB in size. </p><p>It contained exactly 9,042,977 image files - profile pictures, screenshots, and scans of physical photographs - all seemingly uploaded by the users. The images showed adults, teenagers, and even children, and were stored in folders labeled “faces” and “profiles”.</p><h2 id="what-happened">What happened?</h2><p>Further investigation showed the database belonging to a company called ClarityCheck. This is a US-registered firm describing itself as a “reverse phone, email, image, vehicle lookup”, allowing users to identify unknown callers, verify online contacts, check photos, and decode vehicles using publicly available data from “trusted sources”.</p><p>It is a legitimate business whose use case grows more important by the day - cybercriminals create fake internet personas every day, and use them in all sorts of schemes, from romance scams, to fake job offers, to anything in between. To do that, they will either steal other people’s photos, obtain (or buy) them on the dark web, or generate them using artificial intelligence. </p><p>Being able to verify someone’s identity has become everyone’s essential due diligence, regardless of if it’s a personal or business matter.</p><h2 id="how-claritycheck-responded">How ClarityCheck responded</h2><p>As soon as Fowler confirmed who owned the database, he reached out to ClarityCheck and responsibly disclosed his findings. The company responded quickly, barring further access, and thanking the researcher for his work.</p><p>“I completely understand your concerns regarding the exposure of sensitive images and the associated privacy risks. We greatly appreciate ethical researchers like you who bring these matters to our attention so we can act swiftly to protect our users' data and privacy,” the company’s representative told Fowler.</p><p>Unfortunately, without a deeper investigation on ClarityCheck’s end, there is no way of confirming exactly how long the database remained open, or if anyone accessed it before. However, so far there is no evidence of abuse, since a “ClarityCheck photo database” is currently not being distributed or sold anywhere on the dark web.</p><h2 id="exposing-people-to-hackers">Exposing people to hackers</h2><p>In a world where data theft and leaks are increasingly common, a cause that’s easiest to address, is also the one resulting in most exposures - <a href="https://www.techradar.com/pro/security/the-biggest-data-leaker-is-probably-not-who-you-think-it-is" target="_blank">misconfigured databases</a>. Nowadays, almost every business harvests and stores data about their employees, partners, and customers. Most of them store these files in cloud databases, for easier access and better integration with business intelligence software.</p><p>However, cloud service providers work on a so-called “shared responsibility model”, which means they are responsible for providing industry-standard security features. Users, on the other hand, are responsible for using those features and properly configuring their databases (namely, setting up a strong password or encrypting the content). Unfortunately, many organizations don’t seem to be aware of the shared responsibility model, firmly believing it’s the service provider’s task to keep the data safe. Others simply keep these archives accessible by mistake.</p><p>Criminals are aware of this, and are taking advantage of the situation to steal valuable information. By using widely available tools like Shodan, Censys, or FOFA, they can scour the web for unencrypted, non-password protected databases, and exfiltrate data to be used in phishing, business email compromise, and other forms of cyberattacks.</p><p>Over the years, Fowler and other searchers have found dozens of enormous databases that have leaked sensitive data on hundreds of millions of people. </p><p>In 2026, researchers found that European cloud provider Nextcloud kept an <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach">unprotected database</a> on the public internet, containing 367,000 records (8GB) of sensitive employee and client data.</p><p>In 2025, IMDataCenter, a Florida-based data hygiene, enhancement, and append services provider, was <a href="https://www.techradar.com/pro/security/data-center-firm-leaks-massive-38gb-database-containing-thousands-of-personal-records-online">leaking</a> 38GB of sensitive personal records. The unencrypted and non-password-protected database held 10,820 in total.</p><p>In 2024, sports analytics technology company TrackMan <a href="https://www.techradar.com/pro/security/top-sports-tech-firm-leaked-data-and-even-professional-athletes-could-be-affected">exposed</a> sensitive customer data: 110TB and 31,602,260 records. The database had no password.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How AI is transforming the role of test engineers ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Software is being released at a pace traditional testing approaches struggle to match, while <a href="https://www.techradar.com/best/best-ai-tools">AI</a> is moving from assisting with test design to generating, adapting, and maintaining tests across the delivery pipeline. </p><p>The question facing software testers is no longer only how to scale testing, but how to guarantee the evidence automation produces. </p><p>Fundamentally, does AI scale quality, or simply magnify inconsistency?</p><p>In this environment, the test engineer’s role is becoming more strategic. Rather than focusing on individual test cases, test professionals are increasingly expected to orchestrate quality across AI-enabled systems. </p><p>This means applying domain expertise and judgement to connect AI-generated artefacts with requirements, identify hidden risks, and ensure meaningful coverage.</p><p>As AI takes on more generation and execution work, the value of the test engineer is shifting towards governance and evidence stewardship. Without human oversight, faster delivery can create a false sense of assurance.</p><h2 id="a-fine-balance-machine-logic-versus-human-control">A fine balance: machine logic versus human control</h2><p>AI-generated testing introduces new complexity for quality teams. Traditional <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> executed predefined instructions, but modern AI systems can interpret requirements, generate scenarios, and make decisions about coverage. This increases speed and scale but raises questions around validity, accountability, and confidence in outcomes. </p><p>The debate has moved beyond whether AI can generate tests to whether those tests are trustworthy, explainable, and aligned with the real-world risks they are intended to uncover. This is where standardization begins to provide a foundation. </p><p>Emerging standards and methodologies for testing machine-learning-based systems – including test methodology for ML‑based systems, recent guidelines on documenting AI‑enabled systems, and novel approaches to continuous auditing‑based conformity assessment -  are starting to define structured approaches for assessing robustness, bias, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, and other quality characteristics across the machine-learning lifecycle, giving teams a shared basis for judging whether AI‑generated tests are sound. </p><p>Human oversight remains the anchor of trust, ensuring automation elevates quality rather than simply increasing activity.</p><h2 id="the-era-of-the-quality-orchestrator">The era of the quality orchestrator</h2><p>The test engineer’s role is evolving into that of the quality orchestrator, a profile that combines technical depth with contextual awareness to ensure AI‑produced tests are not only efficient but trustworthy. </p><p>Rather than concentrating on individual test cases, the quality orchestrator validates AI outputs, identifies gaps automation overlooks, and applies human judgement where risk or ambiguity is high. They provide the governance layer AI cannot replicate, ensuring automation strengthens quality rather than simply increasing throughput.</p><p>AI systems can identify patterns, summarize logs, and propose test scenarios at a speed far beyond human capability. Yet testing involves more than processing information. Skilled testers challenge assumptions, explore unexpected behaviors, and assess risks that may not be obvious from requirements alone. </p><p>Understanding business context and determining whether a result is meaningful requires domain knowledge and judgement beyond pattern recognition.</p><h2 id="adding-value-where-ai-expectations-exceed-reality">Adding value: where AI expectations exceed reality</h2><p>AI-enabled testing delivers significant value where speed, scale, and pattern recognition matter most. It can extract requirements from standards, draft initial test cases, summarize logs, and accelerate repetitive activities that traditionally consume valuable testing time.</p><p>However, fully automated test generation remains aspirational. AI-generated tests depend heavily on high-quality requirements and <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>; ambiguity or missing context can create flawed assumptions and coverage gaps.</p><p>Consistent, structured documentation is therefore a prerequisite for dependable automation.  Recent guidelines on documenting AI-enabled systems provide a practical framework for traceability and transparency, including model cards, fact sheets, and other structured artefacts, all in the service of reliable automation and regulatory alignment, most notably the EU AI Act. </p><p>While AI can accelerate generation and execution, it cannot independently confirm that tests are correct, relevant, or aligned with intended risks.</p><p>Human oversight remains essential to ensure AI-generated outputs support genuine quality rather than superficial completeness.</p><h2 id="continuous-context-aware-ai-enabled-testing">Continuous, context-aware, AI-enabled testing</h2><p>The future of AI in testing points towards environments that are more continuous, context‑aware, and closely integrated with engineering and operations. Continuous conformance assessment is emerging as a logical extension of AI‑driven tooling, enabling systems to evaluate behavior in real time rather than at fixed milestones.  </p><p>Novel approaches to continuous auditing-based conformity assessment clearly reflect this shift, replacing standalone audits with the ongoing collection of evidence and automated checks throughout an AI system’s operational life. Shift‑right practices will become increasingly important as organizations analyze real‑world logs to understand software behavior under genuine usage conditions.</p><p>The industry is also exploring AI-driven detection of standards changes and affected requirements, though strong traceability remains essential before these capabilities can be relied upon at scale. As generative and agentic AI enter the delivery pipeline, the assessment challenge will only deepen, and with it the need for common quality criteria. </p><p>This is indicative of where the discussion is in 2026, with generative and agentic AI introducing new layers of complexity that make shared quality criteria even more essential.</p><h2 id="from-test-engineer-to-quality-orchestrator-redefining-the-future-of-software-testing">From test engineer to quality orchestrator: redefining the future of software testing</h2><p>As AI continues to redefine software testing, confidence in quality cannot be delegated to automation. The testers who succeed will combine technical expertise with judgement and governance, orchestrating human oversight and AI capability to deliver trustworthy outcomes. </p><p>The advantage will belong to organizations that invest in orchestration capability now, in their people as much as their tooling. </p><p>AI can guarantee the speed of a pipeline; only human judgement can guarantee that the evidence it produces is reviewable, defensible, and credible.</p><p><em></em><a href="https://www.techradar.com/best/best-small-business-software"><em>We've reviewed, rated, and ranked the best small business software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/how-ai-is-transforming-the-role-of-test-engineers</link>
                                                                            <description>
                            <![CDATA[ From test engineer to quality orchestrator: human oversight in AI-enabled test automation ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nEzD2m9y3YkLUUMj3ue7qc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 10:53:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Marija Jankovic ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:description>                                                            <media:text><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:text>
                                <media:title type="plain"><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Software is being released at a pace traditional testing approaches struggle to match, while <a href="https://www.techradar.com/best/best-ai-tools">AI</a> is moving from assisting with test design to generating, adapting, and maintaining tests across the delivery pipeline. </p><p>The question facing software testers is no longer only how to scale testing, but how to guarantee the evidence automation produces. </p><p>Fundamentally, does AI scale quality, or simply magnify inconsistency?</p><p>In this environment, the test engineer’s role is becoming more strategic. Rather than focusing on individual test cases, test professionals are increasingly expected to orchestrate quality across AI-enabled systems. </p><p>This means applying domain expertise and judgement to connect AI-generated artefacts with requirements, identify hidden risks, and ensure meaningful coverage.</p><p>As AI takes on more generation and execution work, the value of the test engineer is shifting towards governance and evidence stewardship. Without human oversight, faster delivery can create a false sense of assurance.</p><h2 id="a-fine-balance-machine-logic-versus-human-control">A fine balance: machine logic versus human control</h2><p>AI-generated testing introduces new complexity for quality teams. Traditional <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> executed predefined instructions, but modern AI systems can interpret requirements, generate scenarios, and make decisions about coverage. This increases speed and scale but raises questions around validity, accountability, and confidence in outcomes. </p><p>The debate has moved beyond whether AI can generate tests to whether those tests are trustworthy, explainable, and aligned with the real-world risks they are intended to uncover. This is where standardization begins to provide a foundation. </p><p>Emerging standards and methodologies for testing machine-learning-based systems – including test methodology for ML‑based systems, recent guidelines on documenting AI‑enabled systems, and novel approaches to continuous auditing‑based conformity assessment -  are starting to define structured approaches for assessing robustness, bias, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, and other quality characteristics across the machine-learning lifecycle, giving teams a shared basis for judging whether AI‑generated tests are sound. </p><p>Human oversight remains the anchor of trust, ensuring automation elevates quality rather than simply increasing activity.</p><h2 id="the-era-of-the-quality-orchestrator">The era of the quality orchestrator</h2><p>The test engineer’s role is evolving into that of the quality orchestrator, a profile that combines technical depth with contextual awareness to ensure AI‑produced tests are not only efficient but trustworthy. </p><p>Rather than concentrating on individual test cases, the quality orchestrator validates AI outputs, identifies gaps automation overlooks, and applies human judgement where risk or ambiguity is high. They provide the governance layer AI cannot replicate, ensuring automation strengthens quality rather than simply increasing throughput.</p><p>AI systems can identify patterns, summarize logs, and propose test scenarios at a speed far beyond human capability. Yet testing involves more than processing information. Skilled testers challenge assumptions, explore unexpected behaviors, and assess risks that may not be obvious from requirements alone. </p><p>Understanding business context and determining whether a result is meaningful requires domain knowledge and judgement beyond pattern recognition.</p><h2 id="adding-value-where-ai-expectations-exceed-reality">Adding value: where AI expectations exceed reality</h2><p>AI-enabled testing delivers significant value where speed, scale, and pattern recognition matter most. It can extract requirements from standards, draft initial test cases, summarize logs, and accelerate repetitive activities that traditionally consume valuable testing time.</p><p>However, fully automated test generation remains aspirational. AI-generated tests depend heavily on high-quality requirements and <a href="https://www.techradar.com/pro/best-it-documentation-tool">documentation</a>; ambiguity or missing context can create flawed assumptions and coverage gaps.</p><p>Consistent, structured documentation is therefore a prerequisite for dependable automation.  Recent guidelines on documenting AI-enabled systems provide a practical framework for traceability and transparency, including model cards, fact sheets, and other structured artefacts, all in the service of reliable automation and regulatory alignment, most notably the EU AI Act. </p><p>While AI can accelerate generation and execution, it cannot independently confirm that tests are correct, relevant, or aligned with intended risks.</p><p>Human oversight remains essential to ensure AI-generated outputs support genuine quality rather than superficial completeness.</p><h2 id="continuous-context-aware-ai-enabled-testing">Continuous, context-aware, AI-enabled testing</h2><p>The future of AI in testing points towards environments that are more continuous, context‑aware, and closely integrated with engineering and operations. Continuous conformance assessment is emerging as a logical extension of AI‑driven tooling, enabling systems to evaluate behavior in real time rather than at fixed milestones.  </p><p>Novel approaches to continuous auditing-based conformity assessment clearly reflect this shift, replacing standalone audits with the ongoing collection of evidence and automated checks throughout an AI system’s operational life. Shift‑right practices will become increasingly important as organizations analyze real‑world logs to understand software behavior under genuine usage conditions.</p><p>The industry is also exploring AI-driven detection of standards changes and affected requirements, though strong traceability remains essential before these capabilities can be relied upon at scale. As generative and agentic AI enter the delivery pipeline, the assessment challenge will only deepen, and with it the need for common quality criteria. </p><p>This is indicative of where the discussion is in 2026, with generative and agentic AI introducing new layers of complexity that make shared quality criteria even more essential.</p><h2 id="from-test-engineer-to-quality-orchestrator-redefining-the-future-of-software-testing">From test engineer to quality orchestrator: redefining the future of software testing</h2><p>As AI continues to redefine software testing, confidence in quality cannot be delegated to automation. The testers who succeed will combine technical expertise with judgement and governance, orchestrating human oversight and AI capability to deliver trustworthy outcomes. </p><p>The advantage will belong to organizations that invest in orchestration capability now, in their people as much as their tooling. </p><p>AI can guarantee the speed of a pipeline; only human judgement can guarantee that the evidence it produces is reviewable, defensible, and credible.</p><p><em></em><a href="https://www.techradar.com/best/best-small-business-software"><em>We've reviewed, rated, and ranked the best small business software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Before approving the next AI budget, check the network ]]></title>
                                                                                                <dc:content><![CDATA[ <p><a href="https://www.techradar.com/best/best-ai-tools">AI</a> has rapidly moved from experimentation to a boardroom priority. But before approving the next AI budget, UK business leaders should ask a critical question: can their network support AI at scale once it moves beyond the pilot stage?</p><p>Recent UK research found that 55% of organizations will prioritize AI or ML investment over the next 12 months, while nearly one in six admit they are investing aggressively with little evaluation because they fear being left behind. </p><p>This pressure is understandable, but this is where the ROI debate becomes too narrow. </p><p>The value of AI will not always appear neatly soon after deployment. Some gains come through <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> and <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>, while others emerge through long-term capability building: greater agility, better resilience, faster decision-making and new ways of working.</p><p>The danger is boards fund AI as a transformation, then judge it like a short-term software project. In the UK, only 15% of organizations say their AI implementations have exceeded expectations, which should prompt a deeper discussion about the conditions AI needs to succeed.</p><h2 id="where-ai-performance-breaks-down">Where AI performance breaks down</h2><p>When AI underperforms, the instinct is often to look at the model, the data, or the team that built the use case. Those factors matter, but rarely explain the whole problem.</p><p>AI depends on the context it works in: the data, the network, the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> model, the governance and the skills around it. If those conditions are weak, even a promising use case can struggle to become durable and valuable in production.</p><p>A proof of concept can look convincing in a narrow environment, with clean data, controlled users and a clear route to value. The difficulty starts when the same project has to operate across offices, clouds, systems and data rules that were never designed around AI.</p><p>This is when connectivity becomes part of the ROI calculation. If data moves too slowly, workflows break between systems, response times vary by location, or teams cannot see where performance is degrading, the business starts paying for delays, rework and lost confidence.</p><p>Among UK businesses whose AI implementations have failed to meet expectations, 24% cite inadequate network or connectivity performance as a contributing factor. That figure matters because it shows how easily an ambitious AI project can become an expensive pilot when the foundations are not ready.</p><h2 id="the-network-has-moved-into-the-roi-calculation">The network has moved into the ROI calculation</h2><p>For years, networks were treated as background infrastructure. That was easier to justify when the workload was email, <a href="https://www.techradar.com/best/secure-file-transfer-solutions">file sharing</a> or standard SaaS access. It is much harder to defend when AI is embedded into live operations, customer workflows, fraud detection, forecasting or field service.</p><p>AI creates a different operating requirement. The business needs to move data securely, route workloads intelligently, maintain uptime and understand where cost is accumulating. Without that visibility, ROI becomes reactive, without resilience AI-enabled processes remain fragile – and without secure connectivity, new use cases create new points of exposure. This is why the infrastructure conversation has to take place much earlier in the AI lifecycle.</p><p>Looking ahead, 54% of UK organizations say they need more flexible and scalable networks to thrive in an AI-driven environment, while 57% say they need greater resilience and reliability to maximize uptime. </p><p>Those numbers should not be read as a technical wish list, they are signals that AI is forcing enterprises to rebuild the conditions around digital performance. If AI is expected to support decisions, customers and operations, the network underneath becomes part of the growth plan.</p><h2 id="four-questions-before-the-next-round-of-ai-funding">Four questions before the next round of AI funding</h2><p>Before signing off the next AI budget, boards should ask where the data will move, who can see it moving, whether the network can support AI beyond the pilot stage, and what happens when something fails.</p><p>Those questions force the board to look below the application layer and examine whether the organization has the conditions to scale what it is funding. They also give the CIO a way to connect ambition to operational reality underneath: infrastructure, skills, governance, security, data movement and cost discipline.</p><p>The hardest part of AI ROI is that some value will take time to mature. No board would judge the value of the internet by what it delivered in its first year, and AI should be approached with the same understanding. Short-term measurement matters, but it cannot become an excuse to underinvest in the capability building that makes long-term value possible.</p><p>The next wave of AI investment will not be won by enthusiasm alone. Before the next model is selected, the next platform is funded, or the next pilot is announced, UK boards should look again at the network underneath. </p><p>AI investment driven by fear of missing out will only carry enterprises so far. Durable value will come from building the right conditions around it from the start.</p><p><em></em><a href="https://www.techradar.com/best/best-network-monitoring-tools"><em>We've featured the best network monitoring tools</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/before-approving-the-next-ai-budget-check-the-network</link>
                                                                            <description>
                            <![CDATA[ UK boards must assess connectivity, resilience and visibility before scaling their AI investments. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AEVBGayALBvufUhuWfPquG</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gMavKmnr8ZGuzV56Abc7DM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 10:01:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jean-Philippe Avelange ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gMavKmnr8ZGuzV56Abc7DM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital representation of the globe with digital lines connecting parts of it, below binary figures]]></media:description>                                                            <media:text><![CDATA[A digital representation of the globe with digital lines connecting parts of it, below binary figures]]></media:text>
                                <media:title type="plain"><![CDATA[A digital representation of the globe with digital lines connecting parts of it, below binary figures]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gMavKmnr8ZGuzV56Abc7DM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.techradar.com/best/best-ai-tools">AI</a> has rapidly moved from experimentation to a boardroom priority. But before approving the next AI budget, UK business leaders should ask a critical question: can their network support AI at scale once it moves beyond the pilot stage?</p><p>Recent UK research found that 55% of organizations will prioritize AI or ML investment over the next 12 months, while nearly one in six admit they are investing aggressively with little evaluation because they fear being left behind. </p><p>This pressure is understandable, but this is where the ROI debate becomes too narrow. </p><p>The value of AI will not always appear neatly soon after deployment. Some gains come through <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> and <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a>, while others emerge through long-term capability building: greater agility, better resilience, faster decision-making and new ways of working.</p><p>The danger is boards fund AI as a transformation, then judge it like a short-term software project. In the UK, only 15% of organizations say their AI implementations have exceeded expectations, which should prompt a deeper discussion about the conditions AI needs to succeed.</p><h2 id="where-ai-performance-breaks-down">Where AI performance breaks down</h2><p>When AI underperforms, the instinct is often to look at the model, the data, or the team that built the use case. Those factors matter, but rarely explain the whole problem.</p><p>AI depends on the context it works in: the data, the network, the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> model, the governance and the skills around it. If those conditions are weak, even a promising use case can struggle to become durable and valuable in production.</p><p>A proof of concept can look convincing in a narrow environment, with clean data, controlled users and a clear route to value. The difficulty starts when the same project has to operate across offices, clouds, systems and data rules that were never designed around AI.</p><p>This is when connectivity becomes part of the ROI calculation. If data moves too slowly, workflows break between systems, response times vary by location, or teams cannot see where performance is degrading, the business starts paying for delays, rework and lost confidence.</p><p>Among UK businesses whose AI implementations have failed to meet expectations, 24% cite inadequate network or connectivity performance as a contributing factor. That figure matters because it shows how easily an ambitious AI project can become an expensive pilot when the foundations are not ready.</p><h2 id="the-network-has-moved-into-the-roi-calculation">The network has moved into the ROI calculation</h2><p>For years, networks were treated as background infrastructure. That was easier to justify when the workload was email, <a href="https://www.techradar.com/best/secure-file-transfer-solutions">file sharing</a> or standard SaaS access. It is much harder to defend when AI is embedded into live operations, customer workflows, fraud detection, forecasting or field service.</p><p>AI creates a different operating requirement. The business needs to move data securely, route workloads intelligently, maintain uptime and understand where cost is accumulating. Without that visibility, ROI becomes reactive, without resilience AI-enabled processes remain fragile – and without secure connectivity, new use cases create new points of exposure. This is why the infrastructure conversation has to take place much earlier in the AI lifecycle.</p><p>Looking ahead, 54% of UK organizations say they need more flexible and scalable networks to thrive in an AI-driven environment, while 57% say they need greater resilience and reliability to maximize uptime. </p><p>Those numbers should not be read as a technical wish list, they are signals that AI is forcing enterprises to rebuild the conditions around digital performance. If AI is expected to support decisions, customers and operations, the network underneath becomes part of the growth plan.</p><h2 id="four-questions-before-the-next-round-of-ai-funding">Four questions before the next round of AI funding</h2><p>Before signing off the next AI budget, boards should ask where the data will move, who can see it moving, whether the network can support AI beyond the pilot stage, and what happens when something fails.</p><p>Those questions force the board to look below the application layer and examine whether the organization has the conditions to scale what it is funding. They also give the CIO a way to connect ambition to operational reality underneath: infrastructure, skills, governance, security, data movement and cost discipline.</p><p>The hardest part of AI ROI is that some value will take time to mature. No board would judge the value of the internet by what it delivered in its first year, and AI should be approached with the same understanding. Short-term measurement matters, but it cannot become an excuse to underinvest in the capability building that makes long-term value possible.</p><p>The next wave of AI investment will not be won by enthusiasm alone. Before the next model is selected, the next platform is funded, or the next pilot is announced, UK boards should look again at the network underneath. </p><p>AI investment driven by fear of missing out will only carry enterprises so far. Durable value will come from building the right conditions around it from the start.</p><p><em></em><a href="https://www.techradar.com/best/best-network-monitoring-tools"><em>We've featured the best network monitoring tools</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI vendor dependency is becoming a resilience risk ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Now that <a href="https://www.techradar.com/best/best-ai-tools">AI</a> has quickly become embedded in global enterprise operations, it has the ability to impact everything from data analysis to decision-making and even security. </p><p>Most conversations, however, focus on AI capability, power, productivity, and accuracy, but leave out one major issue. </p><p>While everyone is focused on what happens as AI is implemented, very few are asking what happens when access to AI capability suddenly disappears.</p><p>A prominent example of this is the debate around Anthropic restoring access to its Fable and Mythos AI models, which primarily revolved around compliance timelines and export control mechanics. </p><p>Yet, few have questioned why so many organizations discovered that one external decision, out of their control, removed a business-critical capability seemingly overnight. In short, AI access disruptions are a symptom of a much larger operational resilience issue, and expose an overlooked governance gap around dependency. </p><p>As organizations integrate AI deeper into their business operations, they need to shift their focus from exploring whether AI is secure enough right now to start asking whether their organizations can even continue operating if or when those very AI services become unavailable.</p><h2 id="security-does-not-equal-resilience">Security does not equal resilience</h2><p>These little discussed topics bring up an important point that <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and resilience are not synonymous.</p><p>Security prevents and protects systems from compromise. This keeps attackers from gaining access, reduces the number of vulnerabilities, and defends against malicious entities - all crucial elements of security operations. Resilience is the ability to continue business operations when systems, services, or data become unavailable, regardless of the cause. </p><p>We tend to associate resilience with situations such as cyberattacks or <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> failures. AI has changed the threat landscape for organizations, how they work with AI, and protect themselves from it. Organizations must now increasingly plan for disrupted access to critical tools and functions caused by geopolitical decisions, regulations, or changes made by technology providers themselves.</p><p>A service doesn't have to be hacked to become unavailable. A policy decision on the other side of the world can have the exact same operational effect. We saw exactly that with Anthropic. </p><p>With this in mind, resilience has to be built into how the enterprise operates and include any new AI infrastructure, so business continuity is ensured even through policy interference.</p><h2 id="ai-creates-a-new-kind-of-vendor-dependency">AI Creates a New Kind of Vendor Dependency</h2><p>Where traditional software dependency usually involves a single or small amount of vendors, enterprise AI often depends on an interconnected ecosystem that organizations do not own or control. Every additional layer in the AI ecosystem represents a dependency, and therefore a potential point of failure.</p><p>This creates four risk factors that leadership needs to be mindful of: </p><p><strong>Data sovereignty</strong>: Enterprise data may be processed under legal jurisdictions the organization doesn't control, with limited visibility into who can access it or whether it feeds future model training</p><p><strong>Model sovereignty</strong>: Organizations often have little to no control over model availability, feature capabilities and changes, or access decisions, leaving them exposed if a provider suddenly decides to restrict access or withdraw capabilities.</p><p><strong>Infrastructure dependency</strong>: Much of today’s enterprise AI ecosystem relies on a small handful of <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a> operating under specific national jurisdictions.</p><p><strong>AI supply chain risks</strong>: An interconnected system of foundation models, cloud platforms, and software vendors means disruption at even one layer can quickly cascade across the wider technology stack.</p><p>These factors increasingly depend on geopolitics rather than technology.</p><h2 id="ai-governance-is-a-boardroom-issue">AI Governance is a Boardroom Issue</h2><p>The reality is that a vendor contract alone cannot guarantee uninterrupted access to the tools and platforms that an enterprise has invested in. But governance frameworks haven’t truly evolved to account for this issue. Only newly emerging frameworks like NIS2 and DORA recognize that resilience must go beyond fending off <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> threats. </p><p>Best practice for an organization as they approach vendor contracts and governance frameworks of their own is to understand where dependencies lie across suppliers and develop contingency plans that allow them to operate smoothly through eras of disruption. </p><p>Whether the dependency is within an AI platform, <a href="https://www.techradar.com/best/best-itsm-tools">ITSM</a> solution, a <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>, or another business critical technology, organizations should assess how they would continue operating if access changed overnight. AI should be subjected to the same scrutiny as any other critical third-party vendors.</p><h2 id="begin-resilience-frameworks-before-the-next-disruption">Begin Resilience Frameworks Before the Next Disruption</h2><p>On top of this, boards should be cautious about accepting AI capability claims at face value. Organizations should require evidence that vendor claims deliver measurable outcomes. </p><p>While AI can quickly identify an overwhelming amount of potential vulnerabilities, discovery alone does not improve resilience. Human expertise here remains essential to validate findings, prioritize fixes based on order of immediate business impact and ensure resources are focused where true risk exists. </p><p>The biggest lesson from recent AI disruption is how many organizations have underestimated their dependence on technologies they don’t have assured control over. And with renewed conversation from U.S. legislators around a potential AI “kill switch,” this has to be top of mind.</p><p>Business leaders must recognize that with all the opportunity AI unlocks, the risk of vendor dependency is close to follow. If I were head of technology at a major enterprise today, I would ensure teams across the entire technology and security departments understand where critical AI capabilities originate, the dependencies that exist across the supply chain, and how operations can remain resilient if access changed overnight.</p><p>Ultimately, the future of successful enterprise AI use will be determined by organizations baking governance and resilience strategies into business plans so that through commercial, political, and operational disruptions, business can continue as securely as usual.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>Our rankings of the best cloud backup platforms</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-vendor-dependency-is-becoming-a-resilience-risk</link>
                                                                            <description>
                            <![CDATA[ The future of successful enterprise AI use will be determined by organizations baking governance and resilience strategies into business plans. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">m33oYELjJq5NE3ax66ypod</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/F8GmZXNJTQZttVhvkvgpp9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 20 Aug 2026 06:29:49 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ben Lipczynski ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/F8GmZXNJTQZttVhvkvgpp9-1280-80.jpg">
                                                            <media:credit><![CDATA[Quardia via Shutterstock ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hacking red and blue digital binary code matrix 01 background.]]></media:description>                                                            <media:text><![CDATA[Hacking red and blue digital binary code matrix 01 background.]]></media:text>
                                <media:title type="plain"><![CDATA[Hacking red and blue digital binary code matrix 01 background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/F8GmZXNJTQZttVhvkvgpp9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Now that <a href="https://www.techradar.com/best/best-ai-tools">AI</a> has quickly become embedded in global enterprise operations, it has the ability to impact everything from data analysis to decision-making and even security. </p><p>Most conversations, however, focus on AI capability, power, productivity, and accuracy, but leave out one major issue. </p><p>While everyone is focused on what happens as AI is implemented, very few are asking what happens when access to AI capability suddenly disappears.</p><p>A prominent example of this is the debate around Anthropic restoring access to its Fable and Mythos AI models, which primarily revolved around compliance timelines and export control mechanics. </p><p>Yet, few have questioned why so many organizations discovered that one external decision, out of their control, removed a business-critical capability seemingly overnight. In short, AI access disruptions are a symptom of a much larger operational resilience issue, and expose an overlooked governance gap around dependency. </p><p>As organizations integrate AI deeper into their business operations, they need to shift their focus from exploring whether AI is secure enough right now to start asking whether their organizations can even continue operating if or when those very AI services become unavailable.</p><h2 id="security-does-not-equal-resilience">Security does not equal resilience</h2><p>These little discussed topics bring up an important point that <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and resilience are not synonymous.</p><p>Security prevents and protects systems from compromise. This keeps attackers from gaining access, reduces the number of vulnerabilities, and defends against malicious entities - all crucial elements of security operations. Resilience is the ability to continue business operations when systems, services, or data become unavailable, regardless of the cause. </p><p>We tend to associate resilience with situations such as cyberattacks or <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> failures. AI has changed the threat landscape for organizations, how they work with AI, and protect themselves from it. Organizations must now increasingly plan for disrupted access to critical tools and functions caused by geopolitical decisions, regulations, or changes made by technology providers themselves.</p><p>A service doesn't have to be hacked to become unavailable. A policy decision on the other side of the world can have the exact same operational effect. We saw exactly that with Anthropic. </p><p>With this in mind, resilience has to be built into how the enterprise operates and include any new AI infrastructure, so business continuity is ensured even through policy interference.</p><h2 id="ai-creates-a-new-kind-of-vendor-dependency">AI Creates a New Kind of Vendor Dependency</h2><p>Where traditional software dependency usually involves a single or small amount of vendors, enterprise AI often depends on an interconnected ecosystem that organizations do not own or control. Every additional layer in the AI ecosystem represents a dependency, and therefore a potential point of failure.</p><p>This creates four risk factors that leadership needs to be mindful of: </p><p><strong>Data sovereignty</strong>: Enterprise data may be processed under legal jurisdictions the organization doesn't control, with limited visibility into who can access it or whether it feeds future model training</p><p><strong>Model sovereignty</strong>: Organizations often have little to no control over model availability, feature capabilities and changes, or access decisions, leaving them exposed if a provider suddenly decides to restrict access or withdraw capabilities.</p><p><strong>Infrastructure dependency</strong>: Much of today’s enterprise AI ecosystem relies on a small handful of <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a> operating under specific national jurisdictions.</p><p><strong>AI supply chain risks</strong>: An interconnected system of foundation models, cloud platforms, and software vendors means disruption at even one layer can quickly cascade across the wider technology stack.</p><p>These factors increasingly depend on geopolitics rather than technology.</p><h2 id="ai-governance-is-a-boardroom-issue">AI Governance is a Boardroom Issue</h2><p>The reality is that a vendor contract alone cannot guarantee uninterrupted access to the tools and platforms that an enterprise has invested in. But governance frameworks haven’t truly evolved to account for this issue. Only newly emerging frameworks like NIS2 and DORA recognize that resilience must go beyond fending off <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> threats. </p><p>Best practice for an organization as they approach vendor contracts and governance frameworks of their own is to understand where dependencies lie across suppliers and develop contingency plans that allow them to operate smoothly through eras of disruption. </p><p>Whether the dependency is within an AI platform, <a href="https://www.techradar.com/best/best-itsm-tools">ITSM</a> solution, a <a href="https://www.techradar.com/best/the-best-crm-software">CRM</a>, or another business critical technology, organizations should assess how they would continue operating if access changed overnight. AI should be subjected to the same scrutiny as any other critical third-party vendors.</p><h2 id="begin-resilience-frameworks-before-the-next-disruption">Begin Resilience Frameworks Before the Next Disruption</h2><p>On top of this, boards should be cautious about accepting AI capability claims at face value. Organizations should require evidence that vendor claims deliver measurable outcomes. </p><p>While AI can quickly identify an overwhelming amount of potential vulnerabilities, discovery alone does not improve resilience. Human expertise here remains essential to validate findings, prioritize fixes based on order of immediate business impact and ensure resources are focused where true risk exists. </p><p>The biggest lesson from recent AI disruption is how many organizations have underestimated their dependence on technologies they don’t have assured control over. And with renewed conversation from U.S. legislators around a potential AI “kill switch,” this has to be top of mind.</p><p>Business leaders must recognize that with all the opportunity AI unlocks, the risk of vendor dependency is close to follow. If I were head of technology at a major enterprise today, I would ensure teams across the entire technology and security departments understand where critical AI capabilities originate, the dependencies that exist across the supply chain, and how operations can remain resilient if access changed overnight.</p><p>Ultimately, the future of successful enterprise AI use will be determined by organizations baking governance and resilience strategies into business plans so that through commercial, political, and operational disruptions, business can continue as securely as usual.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>Our rankings of the best cloud backup platforms</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Comcast is adding motion detection to millions of routers, and I’m worried it’s a privacy nightmare ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Worried about intruders sneaking around inside your house when you’re out of town? You could get one of the <a href="https://www.techradar.com/news/best-home-security-camera">best home security cameras</a>, but what if your existing router could do some of the heavy lifting? That’s what Comcast has just started offering its customers, but the move has been met with considerable controversy. </p><p>Dubbed <a href="https://www.xfinity.com/hub/smart-home/wifi-motion" target="_blank">WiFi Motion</a>, the new feature is coming to Comcast-owned Xfinity’s internet services. Once you opt in, WiFi Motion detects changes in the Wi-Fi signals emitted by the company’s routers and other <a href="https://www.techradar.com/news/smart-home-devices">smart home devices</a> to detect the presence of people in your home. While there’s no video surveillance involved, it can be used as a basic way to sense people who should not be inside your house. When that happens, you’ll receive a notification in the Xfinity app. </p><p>While Xfinity told <a href="https://www.theverge.com/news/981381/comcast-xfinity-shield-wifi-motion-sensing" target="_blank">The Verge</a> that WiFi Motion would provide “a basic level of security,” it’s caused a degree of consternation among the general public — and <a href="https://www.techradar.com/computing/wi-fi-broadband/these-wi-fi-routers-can-help-detect-motion-in-your-home-but-are-also-sparking-privacy-worries-heres-why">not for the first time</a>. On <a href="https://www.reddit.com/r/technology/comments/1vrut6c/comcast_is_turning_millions_of_its_routers_into/" target="_blank">Reddit</a>, for example, one user described it as “Flock for your bedroom,” likening the system to <a href="https://www.techradar.com/tech/have-you-been-flocked-this-free-website-reveals-when-your-license-plate-has-been-searched-for-on-the-cop-camera-database">Flock’s controversial numberplate-recognition cameras</a>. </p><p>Another worried that “A few years from now they’ll be hit with a few million-dollar fine or lawsuit while profiting hundreds of millions from selling the data.” In a world where user data forms a lucrative trade and <a href="https://www.techradar.com/pro/personal-information-removal-services-and-data-brokers-everything-you-need-to-know">data brokers</a> increasingly siphon off people’s private information, it’s unsurprising that users are apprehensive about where their presence data might end up. </p><p>“Conspiracy guys were saying for probably a decade that they could use Wi-Fi to fully map out the interior of your house and track you,” added another Redditor. “Crazy that it’s just out in the open now.”</p><h2 id="a-potential-privacy-nightmare">A potential privacy nightmare</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kMRE9gQuwqSGzSbRvtemnY" name="xFinity" alt="A pair of xFinity routers sitting in front of a window" src="https://cdn.mos.cms.futurecdn.net/kMRE9gQuwqSGzSbRvtemnY.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: xFinity)</span></figcaption></figure><p>The privacy concerns for technology like this are wide-ranging. While many people already have indoor security cameras that can see who is walking around inside their homes, these people have consciously bought these products and opted into the system. </p><p>When surveillance is added to a router, though, we’re talking about orders of magnitude more people being affected — potentially many millions, in this instance. Moreover, most of them will not have bought a router for its tracking abilities, yet will find themselves with a device that can do just that. That’s enough to make anyone feel uneasy. </p><p>Once a system like this is in place on millions of routers, it opens a massive door to potential misuse — users simply have to trust that Xfinity is using this data responsibly, with no way of knowing if that’s actually the case. Who can see the data? How long is it retained? Are there proper checks in place? We don’t know the answers to any of these questions. </p><p>It also paints a huge target on the data. Any time private data is collected en masse, hackers start snooping around. If someone was able to hack into your router and use its presence detection to determine that no one was home, it would be simple to then disable the system and pick the optimal time for a burglary. </p><p>Even discounting all of that, there’s another privacy issue: Comcast says that enabling the feature means it might share your Wi-Fi Motion data with third parties at its discretion. </p><p>As per an <a href="https://www.xfinity.com/support/articles/wifi-motion?pageid=7194ef805fa2d04b0f7e8c9521f97343" target="_blank">Xfinity support page</a>, “Comcast may disclose information generated by your WiFi Motion to third parties without further notice to you in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena.” </p><p>We also don’t know if firmware updates will respect a user’s decision not to opt in to Comcast’s router-based presence tracking. For now, the company says that the feature is opt-in, but can we guarantee that that will always be the case? And if a future software update opts people in automatically, can you trust Comcast to explicitly tell you when that happens? </p><p>While this new router feature might be well-intentioned, it raises all manner of security and privacy concerns. If you’re worried about the implications for you and your family, replace your Comcast router with one of our picks for the <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523">best router</a> money can buy. And if you need to, consider one of the <a href="https://www.techradar.com/news/best-home-security-camera">best home security cameras</a> if you still want to be alerted to unwanted intruders.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/computing/comcast-is-adding-motion-detection-to-millions-of-routers-and-im-worried-its-a-privacy-nightmare</link>
                                                                            <description>
                            <![CDATA[ Comcast’s Xfinity routers can sense people’s presence in your home, but many users are worried. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KwMcRKCn9jUtspJBjxFDm6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/DwoVjUeDrwQfw32dsruQ6E-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 20:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/DwoVjUeDrwQfw32dsruQ6E-1280-80.jpeg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Modem router on a table in a living room. A woman using a laptop while sitting on the sofa is in background. Selective focus.]]></media:description>                                                            <media:text><![CDATA[Modem router on a table in a living room. A woman using a laptop while sitting on the sofa is in background. Selective focus.]]></media:text>
                                <media:title type="plain"><![CDATA[Modem router on a table in a living room. A woman using a laptop while sitting on the sofa is in background. Selective focus.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/DwoVjUeDrwQfw32dsruQ6E-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Worried about intruders sneaking around inside your house when you’re out of town? You could get one of the <a href="https://www.techradar.com/news/best-home-security-camera">best home security cameras</a>, but what if your existing router could do some of the heavy lifting? That’s what Comcast has just started offering its customers, but the move has been met with considerable controversy. </p><p>Dubbed <a href="https://www.xfinity.com/hub/smart-home/wifi-motion" target="_blank">WiFi Motion</a>, the new feature is coming to Comcast-owned Xfinity’s internet services. Once you opt in, WiFi Motion detects changes in the Wi-Fi signals emitted by the company’s routers and other <a href="https://www.techradar.com/news/smart-home-devices">smart home devices</a> to detect the presence of people in your home. While there’s no video surveillance involved, it can be used as a basic way to sense people who should not be inside your house. When that happens, you’ll receive a notification in the Xfinity app. </p><p>While Xfinity told <a href="https://www.theverge.com/news/981381/comcast-xfinity-shield-wifi-motion-sensing" target="_blank">The Verge</a> that WiFi Motion would provide “a basic level of security,” it’s caused a degree of consternation among the general public — and <a href="https://www.techradar.com/computing/wi-fi-broadband/these-wi-fi-routers-can-help-detect-motion-in-your-home-but-are-also-sparking-privacy-worries-heres-why">not for the first time</a>. On <a href="https://www.reddit.com/r/technology/comments/1vrut6c/comcast_is_turning_millions_of_its_routers_into/" target="_blank">Reddit</a>, for example, one user described it as “Flock for your bedroom,” likening the system to <a href="https://www.techradar.com/tech/have-you-been-flocked-this-free-website-reveals-when-your-license-plate-has-been-searched-for-on-the-cop-camera-database">Flock’s controversial numberplate-recognition cameras</a>. </p><p>Another worried that “A few years from now they’ll be hit with a few million-dollar fine or lawsuit while profiting hundreds of millions from selling the data.” In a world where user data forms a lucrative trade and <a href="https://www.techradar.com/pro/personal-information-removal-services-and-data-brokers-everything-you-need-to-know">data brokers</a> increasingly siphon off people’s private information, it’s unsurprising that users are apprehensive about where their presence data might end up. </p><p>“Conspiracy guys were saying for probably a decade that they could use Wi-Fi to fully map out the interior of your house and track you,” added another Redditor. “Crazy that it’s just out in the open now.”</p><h2 id="a-potential-privacy-nightmare">A potential privacy nightmare</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1200px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="kMRE9gQuwqSGzSbRvtemnY" name="xFinity" alt="A pair of xFinity routers sitting in front of a window" src="https://cdn.mos.cms.futurecdn.net/kMRE9gQuwqSGzSbRvtemnY.jpg" mos="" align="middle" fullscreen="" width="1200" height="675" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: xFinity)</span></figcaption></figure><p>The privacy concerns for technology like this are wide-ranging. While many people already have indoor security cameras that can see who is walking around inside their homes, these people have consciously bought these products and opted into the system. </p><p>When surveillance is added to a router, though, we’re talking about orders of magnitude more people being affected — potentially many millions, in this instance. Moreover, most of them will not have bought a router for its tracking abilities, yet will find themselves with a device that can do just that. That’s enough to make anyone feel uneasy. </p><p>Once a system like this is in place on millions of routers, it opens a massive door to potential misuse — users simply have to trust that Xfinity is using this data responsibly, with no way of knowing if that’s actually the case. Who can see the data? How long is it retained? Are there proper checks in place? We don’t know the answers to any of these questions. </p><p>It also paints a huge target on the data. Any time private data is collected en masse, hackers start snooping around. If someone was able to hack into your router and use its presence detection to determine that no one was home, it would be simple to then disable the system and pick the optimal time for a burglary. </p><p>Even discounting all of that, there’s another privacy issue: Comcast says that enabling the feature means it might share your Wi-Fi Motion data with third parties at its discretion. </p><p>As per an <a href="https://www.xfinity.com/support/articles/wifi-motion?pageid=7194ef805fa2d04b0f7e8c9521f97343" target="_blank">Xfinity support page</a>, “Comcast may disclose information generated by your WiFi Motion to third parties without further notice to you in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena.” </p><p>We also don’t know if firmware updates will respect a user’s decision not to opt in to Comcast’s router-based presence tracking. For now, the company says that the feature is opt-in, but can we guarantee that that will always be the case? And if a future software update opts people in automatically, can you trust Comcast to explicitly tell you when that happens? </p><p>While this new router feature might be well-intentioned, it raises all manner of security and privacy concerns. If you’re worried about the implications for you and your family, replace your Comcast router with one of our picks for the <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523">best router</a> money can buy. And if you need to, consider one of the <a href="https://www.techradar.com/news/best-home-security-camera">best home security cameras</a> if you still want to be alerted to unwanted intruders.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts manage to hack Microsoft Copilot by continually asking it questions about itself ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive data</strong></li><li><strong>Exploit used malicious URLs and persistent memory poisoning to bypass guardrails</strong></li><li><strong>Microsoft patched CVE‑2026‑24301 server‑side; technique may affect other AI models</strong></li></ul><p>Microsoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and it worked. It was not a straightforward process, and the AI did not turn “evil”, but one might say it is gullible and somewhat naive.</p><p>Security firm Varonis has published a new report outlining its discovery of a vulnerability in Copilot they named <a href="https://www.varonis.com/blog/cosnitch" target="_blank">CoSnitch</a>. </p><p>The name is a major hint at what the vulnerability is - as CoSnitch is a chain of three vulnerabilities which Microsoft later labeled as CVE-2026-24301, giving it a severity score of 8.8/10 (high), and fixing it with a patch.</p><h2 id="you-can-t-trick-me-and-i-ll-tell-you-exactly-why">You can’t trick me, and I’ll tell you exactly why</h2><p>Cybercriminals have long been using AI as part of their arsenal, as it helps them draft convincing phishing emails, write malicious code, and identify high-value targets - and developers have responded by placing guardrails, which making AI outright refuse to do certain things. </p><p>In the report, Varonis said its researchers did not hunt for bugs in the code or try to reverse-engineer an existing exploit. They just talked to the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>, and with each subsequent question, learned more about its guardrails and how they work. They called the technique “meta-hacking”.</p><p>Whenever Copilot declined a request, it explained why, giving the researchers snippets of insight into how it operates. Or, as Varonis hinted, it “snitched” on itself. This, eventually, helped them map out its defenses and learn how to work around it:</p><p>“The resistance is part of the technique,” they explained. “Each “that won’t work because…” is an invitation to probe the “because.” You don’t exploit the model. You manipulate it into cooperating.”</p><p>After a long conversation with Copilot, the researchers were told, inadvertently, how to create a URL which would, as soon as it was clicked, kick off a chain reaction that resulted in sensitive data exfiltration.</p><h2 id="the-dangers-of-connecting-ai-to-apps">The dangers of connecting AI to apps</h2><p>So, Varonis learned that by creating a URL like this one - “https://copilot.microsoft.com/?q=&autorun=1*” - they could get Copilot to run any malicious prompt as soon as it was clicked. Threat actors could, for example, add this link in a phishing email and trick the victim into clicking on it, telling AI to send all sensitive data to the attackers’ infrastructure.</p><p>But that is only half of the challenge. In this setup, the researchers could only exfiltrate the data the victims shared with Copilot during their sessions together. </p><p>The risk escalates the moment the victim connects the AI to their apps - Gmail, Drive, Calendar, and others. As Varonis explained, the malicious prompt could tell Copilot to exfiltrate all email addresses found in Gmail, all passwords and other secrets found in the emails’ bodies, all information stored in the Drive folder, and all events logged in the Calendar.</p><p>The third part of the CoSnitch vulnerability chain is called “Persistent memory poisoning via web summarization”. As Varonis explained, attackers could craft a webpage which, when summarized by Copilot, injects attacker instructions into the victim's permanent memory store. </p><p>“The injection survives password changes, session revocation, and device re-enrollment, persisting forever,” they warned. This flaw is called “indirect prompt injection” and it is not exactly novel - it’s been observed before and stems from the fact that the AI cannot differentiate between instructions, and data to be analyzed.</p><p>Microsoft was notified about the existence of CoSnitch in December 2025, but only addressed it in mid-August 2026, the researchers said. Unfortunately, we don’t know how Microsoft sorted it - we can only speculate Copilot was instructed not to explain how its guardrails work. Given what CoSnitch is in the first place, perhaps it is for the best that Microsoft hid the solution. </p><p>Luckily enough, it doesn’t seem to have been exploited in the wild, since Varonis could not find any evidence of abuse. The fix was applied on the server side, meaning there is nothing for users to do at this point. </p><p>Since this is not a bug in the code, other AI models might be susceptible to the same techniques, the researchers warned. “The novel meta-hacking technique that uncovered CoSnitch — using the AI’s own reasoning to surface its hidden internals — applies to any agentic platform with a natural language interface,” they concluded, adding that they’ll be publishing more research soon.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/experts-manage-to-hack-microsoft-copilot-by-continually-asking-it-questions-about-itself</link>
                                                                            <description>
                            <![CDATA[ An AI isn't secure if it's gullible and can be tricked into compliance, experts find. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">osapivCe5RVsp5iw5HpeDY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 14:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Copilot keyboard button]]></media:description>                                                            <media:text><![CDATA[Copilot keyboard button]]></media:text>
                                <media:title type="plain"><![CDATA[Copilot keyboard button]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Varonis uncovers CoSnitch, a chain of flaws letting Copilot leak sensitive data</strong></li><li><strong>Exploit used malicious URLs and persistent memory poisoning to bypass guardrails</strong></li><li><strong>Microsoft patched CVE‑2026‑24301 server‑side; technique may affect other AI models</strong></li></ul><p>Microsoft’s Copilot AI just told a group of researchers how to abuse it for data exfiltration, and it worked. It was not a straightforward process, and the AI did not turn “evil”, but one might say it is gullible and somewhat naive.</p><p>Security firm Varonis has published a new report outlining its discovery of a vulnerability in Copilot they named <a href="https://www.varonis.com/blog/cosnitch" target="_blank">CoSnitch</a>. </p><p>The name is a major hint at what the vulnerability is - as CoSnitch is a chain of three vulnerabilities which Microsoft later labeled as CVE-2026-24301, giving it a severity score of 8.8/10 (high), and fixing it with a patch.</p><h2 id="you-can-t-trick-me-and-i-ll-tell-you-exactly-why">You can’t trick me, and I’ll tell you exactly why</h2><p>Cybercriminals have long been using AI as part of their arsenal, as it helps them draft convincing phishing emails, write malicious code, and identify high-value targets - and developers have responded by placing guardrails, which making AI outright refuse to do certain things. </p><p>In the report, Varonis said its researchers did not hunt for bugs in the code or try to reverse-engineer an existing exploit. They just talked to the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI</a>, and with each subsequent question, learned more about its guardrails and how they work. They called the technique “meta-hacking”.</p><p>Whenever Copilot declined a request, it explained why, giving the researchers snippets of insight into how it operates. Or, as Varonis hinted, it “snitched” on itself. This, eventually, helped them map out its defenses and learn how to work around it:</p><p>“The resistance is part of the technique,” they explained. “Each “that won’t work because…” is an invitation to probe the “because.” You don’t exploit the model. You manipulate it into cooperating.”</p><p>After a long conversation with Copilot, the researchers were told, inadvertently, how to create a URL which would, as soon as it was clicked, kick off a chain reaction that resulted in sensitive data exfiltration.</p><h2 id="the-dangers-of-connecting-ai-to-apps">The dangers of connecting AI to apps</h2><p>So, Varonis learned that by creating a URL like this one - “https://copilot.microsoft.com/?q=&autorun=1*” - they could get Copilot to run any malicious prompt as soon as it was clicked. Threat actors could, for example, add this link in a phishing email and trick the victim into clicking on it, telling AI to send all sensitive data to the attackers’ infrastructure.</p><p>But that is only half of the challenge. In this setup, the researchers could only exfiltrate the data the victims shared with Copilot during their sessions together. </p><p>The risk escalates the moment the victim connects the AI to their apps - Gmail, Drive, Calendar, and others. As Varonis explained, the malicious prompt could tell Copilot to exfiltrate all email addresses found in Gmail, all passwords and other secrets found in the emails’ bodies, all information stored in the Drive folder, and all events logged in the Calendar.</p><p>The third part of the CoSnitch vulnerability chain is called “Persistent memory poisoning via web summarization”. As Varonis explained, attackers could craft a webpage which, when summarized by Copilot, injects attacker instructions into the victim's permanent memory store. </p><p>“The injection survives password changes, session revocation, and device re-enrollment, persisting forever,” they warned. This flaw is called “indirect prompt injection” and it is not exactly novel - it’s been observed before and stems from the fact that the AI cannot differentiate between instructions, and data to be analyzed.</p><p>Microsoft was notified about the existence of CoSnitch in December 2025, but only addressed it in mid-August 2026, the researchers said. Unfortunately, we don’t know how Microsoft sorted it - we can only speculate Copilot was instructed not to explain how its guardrails work. Given what CoSnitch is in the first place, perhaps it is for the best that Microsoft hid the solution. </p><p>Luckily enough, it doesn’t seem to have been exploited in the wild, since Varonis could not find any evidence of abuse. The fix was applied on the server side, meaning there is nothing for users to do at this point. </p><p>Since this is not a bug in the code, other AI models might be susceptible to the same techniques, the researchers warned. “The novel meta-hacking technique that uncovered CoSnitch — using the AI’s own reasoning to surface its hidden internals — applies to any agentic platform with a natural language interface,” they concluded, adding that they’ll be publishing more research soon.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft smothers malware by tracking behavior instead of blocking domains ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Microsoft says blocking domains is ineffective against MacSync Stealer’s evolving infrastructure</strong></li><li><strong>Defender experts tracked over 30 domains by analyzing behavioral patterns instead</strong></li><li><strong>Mitigation focuses on spotting suspicious shell sessions, osascript activity, and /tmp/sync archives</strong></li></ul><p>Microsoft says it has found a way to stop the dangerous MacSync Stealer malware by monitoring certain behaviors, rather than keeping track of the domains used in the attacks. </p><p>MacSync Stealer is a piece of infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> built for the Apple ecosystem - it steals passwords, browser data, cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions, SSH/cloud credentials and other sensitive information.</p><p>It was being distributed via ClickFix scams. Victims would visit a malicious website which would tell them they had a problem (an outdated browser or a “protected” document that can only be viewed after “verifying” identities), and which would immediately offer a solution. That solution is to bring up the Terminal and paste a command which, in reality, deployed the malware. </p><p>Initially, defenders would keep their Mac fleets safe by blocking the domains used to host the infrastructure - the websites, the malware executables, and the exfiltrated data. But they soon realized that a new domain would pop up as soon as the old one was blocked, and the malware would continue its operations unabated.</p><h2 id="behavioral-analysis">Behavioral analysis</h2><p>Now, in a new <a href="https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/" target="_blank" rel="nofollow">report</a>, Microsoft said it successfully identified more than 30 domains by looking at behavioral patterns such as repeated execution, request characteristics, staging behavior, and upload methods.</p><p>“Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors across the activity. This behavior-led approach connected more than 30 domains and showed that the infrastructure supported more than C2 communication, extending into active collection, staging, and exfiltration,” Microsoft explained.</p><p>In other words, to defend against MacSync Stealer, don’t focus on blocking domains. Instead, pay attention to shell sessions spawning ‘curl’ with specific flag combinations, osascript quickly chaining into network activity, and archives appearing under /tmp/sync just before outbound PUT traffic begins.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsoft-smothers-malware-by-tracking-behavior-instead-of-blocking-domains</link>
                                                                            <description>
                            <![CDATA[ Blocking domains is a game of whack-a-mole in which attackers automate new moles popping up almost instantly. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">s7yaw5ga5C2LtpwcJawi2K</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg">
                                                            <media:credit><![CDATA[Elchinator from Pixabay ]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[malware]]></media:description>                                                            <media:text><![CDATA[malware]]></media:text>
                                <media:title type="plain"><![CDATA[malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/G8QNviZt3KrDbfWVANJrNM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft says blocking domains is ineffective against MacSync Stealer’s evolving infrastructure</strong></li><li><strong>Defender experts tracked over 30 domains by analyzing behavioral patterns instead</strong></li><li><strong>Mitigation focuses on spotting suspicious shell sessions, osascript activity, and /tmp/sync archives</strong></li></ul><p>Microsoft says it has found a way to stop the dangerous MacSync Stealer malware by monitoring certain behaviors, rather than keeping track of the domains used in the attacks. </p><p>MacSync Stealer is a piece of infostealer <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> built for the Apple ecosystem - it steals passwords, browser data, cookies, Keychain secrets, cryptocurrency wallets, Telegram sessions, SSH/cloud credentials and other sensitive information.</p><p>It was being distributed via ClickFix scams. Victims would visit a malicious website which would tell them they had a problem (an outdated browser or a “protected” document that can only be viewed after “verifying” identities), and which would immediately offer a solution. That solution is to bring up the Terminal and paste a command which, in reality, deployed the malware. </p><p>Initially, defenders would keep their Mac fleets safe by blocking the domains used to host the infrastructure - the websites, the malware executables, and the exfiltrated data. But they soon realized that a new domain would pop up as soon as the old one was blocked, and the malware would continue its operations unabated.</p><h2 id="behavioral-analysis">Behavioral analysis</h2><p>Now, in a new <a href="https://www.microsoft.com/en-us/security/blog/2026/08/18/hunting-macsync-stealer-infrastructure-through-behavioral-pivots/" target="_blank" rel="nofollow">report</a>, Microsoft said it successfully identified more than 30 domains by looking at behavioral patterns such as repeated execution, request characteristics, staging behavior, and upload methods.</p><p>“Microsoft Defender Experts expanded that view by correlating recurring endpoints and network behaviors across the activity. This behavior-led approach connected more than 30 domains and showed that the infrastructure supported more than C2 communication, extending into active collection, staging, and exfiltration,” Microsoft explained.</p><p>In other words, to defend against MacSync Stealer, don’t focus on blocking domains. Instead, pay attention to shell sessions spawning ‘curl’ with specific flag combinations, osascript quickly chaining into network activity, and archives appearing under /tmp/sync just before outbound PUT traffic begins.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bluesky reveals recent outage was caused by major DDoS attack ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Bluesky confirms 24‑hour outage was caused by a DDoS attack on August 17 2026</strong></li><li><strong>Researchers linked it to Iraq‑313 Team, using DiamWall‑based DDoS‑for‑hire infrastructure</strong></li><li><strong>Company upgraded defenses; no details yet on attackers, traffic origin, or user impact</strong></li></ul><p>The recent outage on Bluesky was the result of a Distributed Denial of Service (DDoS) attack, the company has confirmed.</p><p>Bluesky is a decentralized social media platform which is rather similar to X, since it allows users to post short messages and multimedia. Its key difference is the Authenticated Transfer Protocol (AT Protocol) upon which it was built, and which allows users and developers more control compared to other social networks. </p><p>On Sunday, August 16 2026, users started reporting problems accessing Bluesky. On Reddit, users from the US, UK, France, and other countries, said they were having issues loading the Bluesky website and app, or accessing their feeds. A day later, on August 17, Bluesky said it suffered a <a href="https://www.techradar.com/news/best-ddos-protection" target="_blank">DDoS attack</a> that lasted roughly 24 hours. </p><h2 id="iranians-claim-the-attack">Iranians claim the attack</h2><p>The company did not say who the attackers were, where the malicious traffic originated from, or if any specific DDoS infrastructure was used in the attack. It also did not say how many people were affected, but stressed that it upgraded its defenses and was continuing to monitor the situation. </p><p>At the same time, security researchers took to the IFIN public forum to discuss the attacks, saying they saw The Islamic Cyber Resistance in Iraq-313 Team, an Iran-backed threat actor, take responsibility for the attack, as well as for a similar DDoS strike on GitHub. It sounds plausible, since we’ve seen the 313 Team use DDoS to target similar services in the past, including <a href="https://www.techradar.com/pro/security/pro-iran-hackers-claim-recent-spotify-outage-was-revenge-for-us-action-in-their-country" target="_blank">Spotify</a> and <a href="https://www.techradar.com/pro/security/some-ubuntu-services-are-still-down-following-outages-after-ddos-attack" target="_blank">Ubuntu</a>.</p><p>Their initial research suggests the crooks used DDoS-for-hire infrastructure that relies on DiamWall which, in turn, seems to be using IP addresses supplied by a China-based reseller. This does not mean the attack traffic came from China, or that Chinese entities were involved in the attack. </p><p><em>Via </em><a href="https://techcrunch.com/2026/08/18/bluesky-says-its-recent-outage-was-caused-by-another-ddos-attack/" target="_blank"><em>TechCrunch</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/bluesky-reveals-recent-outage-was-caused-by-major-ddos-attack</link>
                                                                            <description>
                            <![CDATA[ Iranian state-backed threat actors claim responsibility, but Bluesky did not confirm it. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XWRWqy2sSk4nuEfa3exsC8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/n2uEkSyW5LSHxg5dkMHRjE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/n2uEkSyW5LSHxg5dkMHRjE-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Jaque Silva/NurPhoto via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Bluesky app logo appears on the screen of a smartphone lying on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[The Bluesky app logo appears on the screen of a smartphone lying on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[The Bluesky app logo appears on the screen of a smartphone lying on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/n2uEkSyW5LSHxg5dkMHRjE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bluesky confirms 24‑hour outage was caused by a DDoS attack on August 17 2026</strong></li><li><strong>Researchers linked it to Iraq‑313 Team, using DiamWall‑based DDoS‑for‑hire infrastructure</strong></li><li><strong>Company upgraded defenses; no details yet on attackers, traffic origin, or user impact</strong></li></ul><p>The recent outage on Bluesky was the result of a Distributed Denial of Service (DDoS) attack, the company has confirmed.</p><p>Bluesky is a decentralized social media platform which is rather similar to X, since it allows users to post short messages and multimedia. Its key difference is the Authenticated Transfer Protocol (AT Protocol) upon which it was built, and which allows users and developers more control compared to other social networks. </p><p>On Sunday, August 16 2026, users started reporting problems accessing Bluesky. On Reddit, users from the US, UK, France, and other countries, said they were having issues loading the Bluesky website and app, or accessing their feeds. A day later, on August 17, Bluesky said it suffered a <a href="https://www.techradar.com/news/best-ddos-protection" target="_blank">DDoS attack</a> that lasted roughly 24 hours. </p><h2 id="iranians-claim-the-attack">Iranians claim the attack</h2><p>The company did not say who the attackers were, where the malicious traffic originated from, or if any specific DDoS infrastructure was used in the attack. It also did not say how many people were affected, but stressed that it upgraded its defenses and was continuing to monitor the situation. </p><p>At the same time, security researchers took to the IFIN public forum to discuss the attacks, saying they saw The Islamic Cyber Resistance in Iraq-313 Team, an Iran-backed threat actor, take responsibility for the attack, as well as for a similar DDoS strike on GitHub. It sounds plausible, since we’ve seen the 313 Team use DDoS to target similar services in the past, including <a href="https://www.techradar.com/pro/security/pro-iran-hackers-claim-recent-spotify-outage-was-revenge-for-us-action-in-their-country" target="_blank">Spotify</a> and <a href="https://www.techradar.com/pro/security/some-ubuntu-services-are-still-down-following-outages-after-ddos-attack" target="_blank">Ubuntu</a>.</p><p>Their initial research suggests the crooks used DDoS-for-hire infrastructure that relies on DiamWall which, in turn, seems to be using IP addresses supplied by a China-based reseller. This does not mean the attack traffic came from China, or that Chinese entities were involved in the attack. </p><p><em>Via </em><a href="https://techcrunch.com/2026/08/18/bluesky-says-its-recent-outage-was-caused-by-another-ddos-attack/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI needs rules and rails: Why governance must move beyond policy ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Motorways don't stay safe simply because drivers follow the Highway Code. They rely on speed limits, lane markings, and crash barriers that keep traffic moving to help prevent mistakes from becoming serious accidents.</p><p>AI governance works the same way. Policies define the rules, but operational controls keep organizations on course when technology, users, and risks change. </p><p>As organizations accelerate AI adoption, many have focused on developing policies, governance frameworks, and acceptable use guidelines. Those are essential first steps. But policies alone can't prevent AI systems from accessing the wrong <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, interacting with the wrong applications, or creating unintended operational risks.</p><p>The EU AI Act has made AI governance a board-level issue, requiring organizations that use or develop AI to identify, manage, and document risks, particularly for high-risk systems.</p><p>This has introduced new expectations around oversight, documentation, data governance, and transparency. However, regulation alone won't solve the biggest practical challenge: AI adoption is moving faster than governance. </p><p>Employees are using public <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>, developers are relying on <a href="https://www.techradar.com/pro/best-vibe-coding-tools">coding</a> assistants, and business teams are deploying AI capabilities across existing platforms. In many cases, these technologies are introduced before <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, compliance, and risk teams fully understand what they can access, which systems they influence, or how they change the organization's overall risk profile.</p><p>That's the gap between regulatory ambition and operational reality. Organizations may have approved AI use cases and governance frameworks, but they're often governing only part of the AI already operating across the business.</p><p>Closing that gap starts with treating AI as an operational challenge rather than simply a compliance exercise. In practice, moving beyond policy means understanding how AI is used, applying controls according to business risk, and adapting governance as AI capabilities evolve. </p><h2 id="shadow-ai-is-changing-the-governance-challenge">Shadow AI is changing the governance challenge </h2><p>Traditional governance assumes organizations know what technologies are operating across the business. AI has changed that. Shadow AI is no longer limited to employees experimenting with public tools.</p><p>It also includes embedded AI capabilities introduced through routine software updates, AI-powered workflows created by business users, and autonomous agents operating across enterprise systems without ever being treated as formal AI projects. These capabilities are often adopted faster than governance processes can identify, assess, and manage them.</p><p>Today, AI isn't simply supporting <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> - it's acting on their behalf. AI agents can retrieve information, trigger workflows, interact with enterprise systems, and make operational decisions using permissions inherited from the people or systems they represent.</p><p>Because of this, the enterprise attack surface has fundamentally changed. Security teams are no longer protecting only people, devices, and applications - they're also securing autonomous systems capable of moving across environments, accessing sensitive information, interacting with critical workflows, and making decisions independently.</p><p>Every new AI agent represents another potential pathway for accidental misuse or malicious activity if it isn't governed appropriately. </p><h2 id="regulation-defines-the-rules-context-builds-the-rails">Regulation defines the rules. Context builds the rails. </h2><p>The EU AI Act places significant emphasis on accountability, oversight, and risk management throughout the AI lifecycle. But meeting those expectations requires far more than documentation.</p><p>Regulation defines the outcomes organizations must achieve; the challenge is translating those requirements into operational governance across environments where AI is constantly evolving.</p><p>That starts with understanding AI in context. Risk can't be assessed by looking at an AI system in isolation. An AI assistant summarizing internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a> may appear relatively low risk until it gains access to commercially sensitive information.</p><p>Likewise, an AI agent automating procurement may operate safely under normal circumstances, but its risk profile changes significantly if it can approve financial transactions, inherit privileged identities, or initiate actions across critical business systems.  </p><p>Risk is defined not only by the AI itself, but by the identities, applications, <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, data, and business processes it connects to. As it becomes more deeply embedded across these interconnected systems, AI governance increasingly overlaps with cybersecurity.</p><p>Every AI capability introduced into the enterprise can create new attack paths, expand access to sensitive information, and increase the number of non-human identities operating across the environment.</p><p>Recent incidents, such as PocketOS’s database being wiped by an AI coding agent in seconds, have shown how quickly AI risk can become operational risk when AI systems are granted more authority than intended.</p><p>Organizations should therefore govern AI identities and permissions with the same rigor as human users, regularly reviewing inherited access and removing unnecessary privileges before they create new attack paths.</p><p>Governance also needs to extend beyond individual AI systems. Organizations should understand how AI interacts with identities, enterprise assets, business processes, and critical data so they can prioritize controls where they'll have the greatest impact. </p><p>Bringing security, risk, compliance, and technology teams together around this shared understanding turns governance into an enabler of resilience rather than simply a compliance exercise.  </p><h2 id="building-the-rails">Building the rails </h2><p>As AI regulation continues to evolve, organizations will be expected to demonstrate that governance exists not only on paper, but in practice. Policies establish the rules, but operational governance builds the rails that keep AI operating safely as technologies evolve, permissions change, and new capabilities emerge.</p><p>Moving beyond policy means embedding governance into day-to-day operations. Organizations should continuously identify new AI capabilities, understand how they relate to enterprise assets, review the permissions they inherit, assess business impact, and prioritize the exposures that present the greatest risk.</p><p>This allows teams to apply controls where they'll have the greatest impact while supporting responsible AI adoption across the business. </p><p>Governance also needs to keep pace with change. As AI agents evolve and environments shift, organizations should be able to adjust permissions, restrict access, isolate affected agents, or prevent actions that exceed an AI system's intended role before they become wider operational issues.</p><p>The objective isn't to slow AI adoption, but to create the confidence to innovate securely as AI becomes part of everyday business.</p><h2 id="innovation-needs-both-rules-and-rails">Innovation needs both rules and rails </h2><p>AI will continue to transform how organizations operate, innovate, and compete.  But organizations that realize AI's full potential won't be those with the longest policy documents.</p><p>They'll be the ones that embed governance into everyday operations, govern AI identities and permissions with the same discipline as any other critical asset, and continuously adapt controls as technology evolves. </p><p>The EU AI Act has raised expectations around accountability, but organizations that move beyond policy and compliance will be best placed to unlock AI’s full potential.</p><p>In the age of autonomous AI, governance isn't just about setting the rules -  it's about creating the guardrails that let organizations innovate with confidence without compromising security, trust, or resilience.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-needs-rules-and-rails-why-governance-must-move-beyond-policy</link>
                                                                            <description>
                            <![CDATA[ Organizations need operational guardrails that keep AI aligned with business objectives as adoption accelerates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EhLxQ6jZ7ypUFMCqmymatk</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/4d3FzfBhbeGTkD9mnMpEdM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 10:10:10 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nadir Izrael ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/4d3FzfBhbeGTkD9mnMpEdM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A close up of a person&#039;s eyes and face. They are wearing glasses and in one eye there&#039;s. a reflection of a digital brain]]></media:description>                                                            <media:text><![CDATA[A close up of a person&#039;s eyes and face. They are wearing glasses and in one eye there&#039;s. a reflection of a digital brain]]></media:text>
                                <media:title type="plain"><![CDATA[A close up of a person&#039;s eyes and face. They are wearing glasses and in one eye there&#039;s. a reflection of a digital brain]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/4d3FzfBhbeGTkD9mnMpEdM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Motorways don't stay safe simply because drivers follow the Highway Code. They rely on speed limits, lane markings, and crash barriers that keep traffic moving to help prevent mistakes from becoming serious accidents.</p><p>AI governance works the same way. Policies define the rules, but operational controls keep organizations on course when technology, users, and risks change. </p><p>As organizations accelerate AI adoption, many have focused on developing policies, governance frameworks, and acceptable use guidelines. Those are essential first steps. But policies alone can't prevent AI systems from accessing the wrong <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, interacting with the wrong applications, or creating unintended operational risks.</p><p>The EU AI Act has made AI governance a board-level issue, requiring organizations that use or develop AI to identify, manage, and document risks, particularly for high-risk systems.</p><p>This has introduced new expectations around oversight, documentation, data governance, and transparency. However, regulation alone won't solve the biggest practical challenge: AI adoption is moving faster than governance. </p><p>Employees are using public <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>, developers are relying on <a href="https://www.techradar.com/pro/best-vibe-coding-tools">coding</a> assistants, and business teams are deploying AI capabilities across existing platforms. In many cases, these technologies are introduced before <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, compliance, and risk teams fully understand what they can access, which systems they influence, or how they change the organization's overall risk profile.</p><p>That's the gap between regulatory ambition and operational reality. Organizations may have approved AI use cases and governance frameworks, but they're often governing only part of the AI already operating across the business.</p><p>Closing that gap starts with treating AI as an operational challenge rather than simply a compliance exercise. In practice, moving beyond policy means understanding how AI is used, applying controls according to business risk, and adapting governance as AI capabilities evolve. </p><h2 id="shadow-ai-is-changing-the-governance-challenge">Shadow AI is changing the governance challenge </h2><p>Traditional governance assumes organizations know what technologies are operating across the business. AI has changed that. Shadow AI is no longer limited to employees experimenting with public tools.</p><p>It also includes embedded AI capabilities introduced through routine software updates, AI-powered workflows created by business users, and autonomous agents operating across enterprise systems without ever being treated as formal AI projects. These capabilities are often adopted faster than governance processes can identify, assess, and manage them.</p><p>Today, AI isn't simply supporting <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a> - it's acting on their behalf. AI agents can retrieve information, trigger workflows, interact with enterprise systems, and make operational decisions using permissions inherited from the people or systems they represent.</p><p>Because of this, the enterprise attack surface has fundamentally changed. Security teams are no longer protecting only people, devices, and applications - they're also securing autonomous systems capable of moving across environments, accessing sensitive information, interacting with critical workflows, and making decisions independently.</p><p>Every new AI agent represents another potential pathway for accidental misuse or malicious activity if it isn't governed appropriately. </p><h2 id="regulation-defines-the-rules-context-builds-the-rails">Regulation defines the rules. Context builds the rails. </h2><p>The EU AI Act places significant emphasis on accountability, oversight, and risk management throughout the AI lifecycle. But meeting those expectations requires far more than documentation.</p><p>Regulation defines the outcomes organizations must achieve; the challenge is translating those requirements into operational governance across environments where AI is constantly evolving.</p><p>That starts with understanding AI in context. Risk can't be assessed by looking at an AI system in isolation. An AI assistant summarizing internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a> may appear relatively low risk until it gains access to commercially sensitive information.</p><p>Likewise, an AI agent automating procurement may operate safely under normal circumstances, but its risk profile changes significantly if it can approve financial transactions, inherit privileged identities, or initiate actions across critical business systems.  </p><p>Risk is defined not only by the AI itself, but by the identities, applications, <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>, data, and business processes it connects to. As it becomes more deeply embedded across these interconnected systems, AI governance increasingly overlaps with cybersecurity.</p><p>Every AI capability introduced into the enterprise can create new attack paths, expand access to sensitive information, and increase the number of non-human identities operating across the environment.</p><p>Recent incidents, such as PocketOS’s database being wiped by an AI coding agent in seconds, have shown how quickly AI risk can become operational risk when AI systems are granted more authority than intended.</p><p>Organizations should therefore govern AI identities and permissions with the same rigor as human users, regularly reviewing inherited access and removing unnecessary privileges before they create new attack paths.</p><p>Governance also needs to extend beyond individual AI systems. Organizations should understand how AI interacts with identities, enterprise assets, business processes, and critical data so they can prioritize controls where they'll have the greatest impact. </p><p>Bringing security, risk, compliance, and technology teams together around this shared understanding turns governance into an enabler of resilience rather than simply a compliance exercise.  </p><h2 id="building-the-rails">Building the rails </h2><p>As AI regulation continues to evolve, organizations will be expected to demonstrate that governance exists not only on paper, but in practice. Policies establish the rules, but operational governance builds the rails that keep AI operating safely as technologies evolve, permissions change, and new capabilities emerge.</p><p>Moving beyond policy means embedding governance into day-to-day operations. Organizations should continuously identify new AI capabilities, understand how they relate to enterprise assets, review the permissions they inherit, assess business impact, and prioritize the exposures that present the greatest risk.</p><p>This allows teams to apply controls where they'll have the greatest impact while supporting responsible AI adoption across the business. </p><p>Governance also needs to keep pace with change. As AI agents evolve and environments shift, organizations should be able to adjust permissions, restrict access, isolate affected agents, or prevent actions that exceed an AI system's intended role before they become wider operational issues.</p><p>The objective isn't to slow AI adoption, but to create the confidence to innovate securely as AI becomes part of everyday business.</p><h2 id="innovation-needs-both-rules-and-rails">Innovation needs both rules and rails </h2><p>AI will continue to transform how organizations operate, innovate, and compete.  But organizations that realize AI's full potential won't be those with the longest policy documents.</p><p>They'll be the ones that embed governance into everyday operations, govern AI identities and permissions with the same discipline as any other critical asset, and continuously adapt controls as technology evolves. </p><p>The EU AI Act has raised expectations around accountability, but organizations that move beyond policy and compliance will be best placed to unlock AI’s full potential.</p><p>In the age of autonomous AI, governance isn't just about setting the rules -  it's about creating the guardrails that let organizations innovate with confidence without compromising security, trust, or resilience.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ SMEs aren’t too small to target for cybercriminals, they’re too exposed to ignore ]]></title>
                                                                                                <dc:content><![CDATA[ <p>When cybercriminals look at a small and medium-sized enterprise (<a href="https://www.techradar.com/best/accounting-software-small-business">SME</a>), they see a route into a larger organization or supply chain with a bigger payout.</p><p>SMEs operate with the same level of connectivity, supply chain reliance and regulatory responsibilities as larger organizations, but nowhere near the security budget or cyber staffing.</p><p>That imbalance, and connection to a larger environment, is what cybercriminals are exploiting. The Cyber Security Breaches Survey 2025/2026 found that 46% of small <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a> and 65% of medium businesses reported a cyber breach or attack over the past 12 months.</p><p>SMEs are now targeted based on how exposed they are and the bigger payout they can lead to.</p><h2 id="the-economic-risk-caused-by-the-sme-cyber-gap">The economic risk caused by the SME cyber gap</h2><p>SMEs account for 99% of the UK’s business population, employing three-fifths of the private sector workforce and generating half of the private sector’s turnover, according to the Federation of Small Businesses.</p><p>A fifth of those breached by a cyber incident reported revenue loss and reputational damage, while suffering from extended <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> disruption.</p><p>Temporary loss of access and interruption to online services can have a significant impact not only on the SME impacted but their wider supply chain. Especially in sectors such as banking, retail and public services, which hold vast amounts of customer data and process payments, the knock-on effect of a cyber incident within a connected SME can be huge. </p><p>One compromise from a supplier account can be the catalyst for a much larger breach, which in turn can have a wider economic impact, as we saw with JLR. Connected SMEs are valuable to the UK economy, but that also makes them a greater risk.</p><h2 id="attackers-have-industrialized-cyber-threats">Attackers have industrialized cyber threats</h2><p>Cybercriminals don’t have to spend lots of time building sophisticated attack campaigns anymore. Access to phishing kits, ransomware-as-a-service and AI-driven social engineering have made it easier to launch attacks at scale, without a high cost.  </p><p>It means that attackers can automate reconnaissance and personalize attacks at machine speed, only to encounter SMEs relying on a patchwork of tools such as firewalls and <a href="https://www.techradar.com/news/best-email-provider">email</a> filtering. Even if the tools are in place, visibility and understanding what to do when an alert comes in are vital.</p><p>Verizon’s 2025 DBIR SMB Snapshot found that credential abuse, vulnerability and phishing are among the leading initial access points for cybercriminals. </p><p>With the economics of cyber threats skewed towards attackers, they don’t have to beat every defense layer. They just need one unpatched system or usable identity to gain access, before moving through the supply chain to cause a much bigger compromise. </p><h2 id="phishing-is-more-than-a-badly-written-email">Phishing is more than a badly written email</h2><p>Phishing remains a primary tactic for cybercriminals, exploiting busy staff who may not have sufficient protection. It can be a founder checking emails off their phone, <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a> handling an invoice, a <a href="https://www.techradar.com/best/best-hr-software">HR</a> manager opening a CV, or a supplier message from a familiar-looking address.</p><p>These attacks have become more convincing with AI, due to language and sentence structure being more polished, and the content more accurately relating to the target’s role or current activity. That’s also taken further with voice and impact manipulation. </p><p>The Cyber Security Breaches Survey 2025/2026 found that UK businesses experienced approximately 5.13 million phishing cybercrimes in the past 12 months. Targeting an unsuspecting or unprotected person is often easier for a cybercriminal than hacking a firewall.</p><p>Even if a phishing attempt is unsuccessful, the scale of these threats can take away attention and resources from an SME, making them easier to target in future.</p><p>As a result, SMEs need to be prepared to recover when one of these attacks slips through. Prevention isn’t enough anymore. They need to be able to quickly identify if a credential was stolen, what was accessed and if the attacker has moved across the network, all of which is tricky with limited resources. </p><h2 id="moving-towards-autonomous-security">Moving towards autonomous security</h2><p>The current focus for SMEs bolstering their cyber defenses is what happens in the first minutes after a potential breach or software failure happens.</p><p>Existing <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> tools will likely flag an alert to a central dashboard, but with the volume of threats made possible by AI, that’ll only create a sea of noise for real attacks to hide in. What SMEs really need is an autonomous system that takes action on alerts, assessing the risk, restricting access, revoking credentials and flagging to human teams for oversight and auditability. </p><p>When a phishing attempt is detected, for example, when a suspicious link is clicked, an autonomous system should isolate the account, block the unusual activity and alert the security team with a recommendation within minutes.</p><p>Guided by a human-in-the-loop, good automation should be able to distinguish between low-risk alerts and serious threats, with the ability to advise, or even action, the next phase of containment. </p><h2 id="cyber-resilience-must-become-accessible">Cyber resilience must become accessible</h2><p>So much is said about ‘cyber resilience’ but SMEs, who make up the largest proportion of the business world in the UK, have limited time, limited budgets and limited cybersecurity expertise.</p><p>Since cybercriminals have automated and industrialized their threats, SMEs need access to autonomous defenses to match. They need simple deployment, greater visibility, clear recovery and automation that doesn’t overwhelm them.</p><p>SMEs have become a lucrative target and it’s important they get greater protection.</p><p><em></em><a href="https://www.techradar.com/best/best-malware-removal"><em>We've featured the best malware removal.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/smes-arent-too-small-to-target-for-cybercriminals-theyre-too-exposed-to-ignore</link>
                                                                            <description>
                            <![CDATA[ SMEs are an open door to big cyber breaches. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">9YdGuE5PxqsX5Y9ohyknSi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 19 Aug 2026 08:45:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Raj Maghani ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>When cybercriminals look at a small and medium-sized enterprise (<a href="https://www.techradar.com/best/accounting-software-small-business">SME</a>), they see a route into a larger organization or supply chain with a bigger payout.</p><p>SMEs operate with the same level of connectivity, supply chain reliance and regulatory responsibilities as larger organizations, but nowhere near the security budget or cyber staffing.</p><p>That imbalance, and connection to a larger environment, is what cybercriminals are exploiting. The Cyber Security Breaches Survey 2025/2026 found that 46% of small <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a> and 65% of medium businesses reported a cyber breach or attack over the past 12 months.</p><p>SMEs are now targeted based on how exposed they are and the bigger payout they can lead to.</p><h2 id="the-economic-risk-caused-by-the-sme-cyber-gap">The economic risk caused by the SME cyber gap</h2><p>SMEs account for 99% of the UK’s business population, employing three-fifths of the private sector workforce and generating half of the private sector’s turnover, according to the Federation of Small Businesses.</p><p>A fifth of those breached by a cyber incident reported revenue loss and reputational damage, while suffering from extended <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> disruption.</p><p>Temporary loss of access and interruption to online services can have a significant impact not only on the SME impacted but their wider supply chain. Especially in sectors such as banking, retail and public services, which hold vast amounts of customer data and process payments, the knock-on effect of a cyber incident within a connected SME can be huge. </p><p>One compromise from a supplier account can be the catalyst for a much larger breach, which in turn can have a wider economic impact, as we saw with JLR. Connected SMEs are valuable to the UK economy, but that also makes them a greater risk.</p><h2 id="attackers-have-industrialized-cyber-threats">Attackers have industrialized cyber threats</h2><p>Cybercriminals don’t have to spend lots of time building sophisticated attack campaigns anymore. Access to phishing kits, ransomware-as-a-service and AI-driven social engineering have made it easier to launch attacks at scale, without a high cost.  </p><p>It means that attackers can automate reconnaissance and personalize attacks at machine speed, only to encounter SMEs relying on a patchwork of tools such as firewalls and <a href="https://www.techradar.com/news/best-email-provider">email</a> filtering. Even if the tools are in place, visibility and understanding what to do when an alert comes in are vital.</p><p>Verizon’s 2025 DBIR SMB Snapshot found that credential abuse, vulnerability and phishing are among the leading initial access points for cybercriminals. </p><p>With the economics of cyber threats skewed towards attackers, they don’t have to beat every defense layer. They just need one unpatched system or usable identity to gain access, before moving through the supply chain to cause a much bigger compromise. </p><h2 id="phishing-is-more-than-a-badly-written-email">Phishing is more than a badly written email</h2><p>Phishing remains a primary tactic for cybercriminals, exploiting busy staff who may not have sufficient protection. It can be a founder checking emails off their phone, <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a> handling an invoice, a <a href="https://www.techradar.com/best/best-hr-software">HR</a> manager opening a CV, or a supplier message from a familiar-looking address.</p><p>These attacks have become more convincing with AI, due to language and sentence structure being more polished, and the content more accurately relating to the target’s role or current activity. That’s also taken further with voice and impact manipulation. </p><p>The Cyber Security Breaches Survey 2025/2026 found that UK businesses experienced approximately 5.13 million phishing cybercrimes in the past 12 months. Targeting an unsuspecting or unprotected person is often easier for a cybercriminal than hacking a firewall.</p><p>Even if a phishing attempt is unsuccessful, the scale of these threats can take away attention and resources from an SME, making them easier to target in future.</p><p>As a result, SMEs need to be prepared to recover when one of these attacks slips through. Prevention isn’t enough anymore. They need to be able to quickly identify if a credential was stolen, what was accessed and if the attacker has moved across the network, all of which is tricky with limited resources. </p><h2 id="moving-towards-autonomous-security">Moving towards autonomous security</h2><p>The current focus for SMEs bolstering their cyber defenses is what happens in the first minutes after a potential breach or software failure happens.</p><p>Existing <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> tools will likely flag an alert to a central dashboard, but with the volume of threats made possible by AI, that’ll only create a sea of noise for real attacks to hide in. What SMEs really need is an autonomous system that takes action on alerts, assessing the risk, restricting access, revoking credentials and flagging to human teams for oversight and auditability. </p><p>When a phishing attempt is detected, for example, when a suspicious link is clicked, an autonomous system should isolate the account, block the unusual activity and alert the security team with a recommendation within minutes.</p><p>Guided by a human-in-the-loop, good automation should be able to distinguish between low-risk alerts and serious threats, with the ability to advise, or even action, the next phase of containment. </p><h2 id="cyber-resilience-must-become-accessible">Cyber resilience must become accessible</h2><p>So much is said about ‘cyber resilience’ but SMEs, who make up the largest proportion of the business world in the UK, have limited time, limited budgets and limited cybersecurity expertise.</p><p>Since cybercriminals have automated and industrialized their threats, SMEs need access to autonomous defenses to match. They need simple deployment, greater visibility, clear recovery and automation that doesn’t overwhelm them.</p><p>SMEs have become a lucrative target and it’s important they get greater protection.</p><p><em></em><a href="https://www.techradar.com/best/best-malware-removal"><em>We've featured the best malware removal.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'The attacks we found only scratch the surface of what is possible': Experts say so-called 'Proactive SIM' cards can hijack smartphones, IoT devices and even EV chargers ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers find a standardized SIM command is exposed on nine of 26 tested devices and used it to achieve code execution on a commercial EV charger</strong></li><li><strong>The exposure is concentrated in machine-to-machine hardware rather than phones, affecting six of eight cellular modules but only three of 18 handsets, with no iPhone or Pixel among them</strong></li><li><strong>Every attack requires the attacker to already control the SIM, and while Qualcomm has produced a hardened configuration disabling the interface by default, no vendor had published a public advisory yet</strong></li></ul><p>A malicious SIM card can instruct the device it sits in to run commands of an attacker's choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the entire device over.</p><p>Researchers from the University of Birmingham and the German security firm Fuzzware demonstrated this against a commercial Autel EV charger, achieving code execution driven entirely SIM card-issued commands.</p><h2 id="one-malicious-sim-card-to-rule-them-all">One malicious SIM card to rule them all?</h2><p>The work focuses on a standardized feature called Proactive SIM, which as a feature, is not malicious; it's a standard in a cellular specification that lets a SIM push commands to a device rather than acting as a passive identifier for one's identity on a network.</p><p>The problem is one specific command in that set, RUN AT, which asks the modem to execute an AT command, the modem control language dating to the 1981 Hayes Smartmodem that every vendor has since extended with its own additions. </p><p>The support extender essentially gives a SIM module its own general-purpose console on devices that lack safeguards to prevent such an attack.</p><p>Tomasz Piotr Lisowski and Dr Marius Muench of Birmingham, working with Fuzzware's Kristian Covic, built a toolkit called CATana to find out what a hostile card could do with that console.</p><p>The team <a href="https://www.usenix.org/conference/woot26/presentation/lisowski" target="_blank">tested 26 devices</a>, 18 smartphones and eight cellular modules, and found the SIM AT interface exposed on nine of them. The exposure is overwhelmingly concentrated in machine-to-machine hardware: six of the eight modules accepted the command, compared with just three of the 18 phones: the Oppo Find X5, the Oppo Reno 14 F 5G, and the Asus Zenfone 9. This makes it not <a href="https://www.techradar.com/news/simjacker-attack-could-affect-a-billion-smartphones" target="_blank">exactly a Simjacker-esque exploit</a> but still one that needs to be taken seriously.</p><p>All nine devices that accepted the command run a Qualcomm chip or modem, but five others that do were not vulnerable to the attack. The researchers first shared the reports with Google, Oppo, Quectel, Semtech, and Qualcomm in March 2026, and with the GSMA in May.  Qualcomm has since built a hardened configuration that switches the interface off by default, which the researchers say will be the default on future devices.</p><p>The attack vector, however, is limited because, to leverage it, the attacker must already control the SIM itself. Knowing a victim's contact number is not enough; the attacker needs physical access to the SIM slot. The exploit is real and concerning, but it has limited utility compared to a remote one for smartphones.</p><p>The IoT side is more concerning, however: unattended equipment with an accessible SIM tray can now potentially be exploited, and physical swaps might be easier than with something more personal, like one's personal phone. The card essentially talks to the equivalent of a Linux computer, one that the paper calls a rich attack surface for hostile SIM cards.</p><p>For now, the irony is that while modern smartphones have largely retired the surface this attack vector exploits, the machine-to-machine world has not, and the equipment least likely to receive a firmware update is the equipment most exposed currently.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/the-attacks-we-found-only-scratch-the-surface-of-what-is-possible-experts-say-so-called-proactive-sim-cards-can-hijack-smartphones-iot-devices-and-even-ev-chargers</link>
                                                                            <description>
                            <![CDATA[ Standardized SIM command from the modem era lets a hostile card run code inside an EV charger ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FLAAth49s8BqNZgE7XcQbY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uLTVZ33PJNJAQnchjt5Ngn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 20:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uLTVZ33PJNJAQnchjt5Ngn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / 010110010101101]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[SIM card going into an iPhone]]></media:description>                                                            <media:text><![CDATA[SIM card going into an iPhone]]></media:text>
                                <media:title type="plain"><![CDATA[SIM card going into an iPhone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uLTVZ33PJNJAQnchjt5Ngn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers find a standardized SIM command is exposed on nine of 26 tested devices and used it to achieve code execution on a commercial EV charger</strong></li><li><strong>The exposure is concentrated in machine-to-machine hardware rather than phones, affecting six of eight cellular modules but only three of 18 handsets, with no iPhone or Pixel among them</strong></li><li><strong>Every attack requires the attacker to already control the SIM, and while Qualcomm has produced a hardened configuration disabling the interface by default, no vendor had published a public advisory yet</strong></li></ul><p>A malicious SIM card can instruct the device it sits in to run commands of an attacker's choosing, and on the cellular modules embedded in electric vehicle chargers, industrial routers, and car telematics units, essentially allowing it to take the entire device over.</p><p>Researchers from the University of Birmingham and the German security firm Fuzzware demonstrated this against a commercial Autel EV charger, achieving code execution driven entirely SIM card-issued commands.</p><h2 id="one-malicious-sim-card-to-rule-them-all">One malicious SIM card to rule them all?</h2><p>The work focuses on a standardized feature called Proactive SIM, which as a feature, is not malicious; it's a standard in a cellular specification that lets a SIM push commands to a device rather than acting as a passive identifier for one's identity on a network.</p><p>The problem is one specific command in that set, RUN AT, which asks the modem to execute an AT command, the modem control language dating to the 1981 Hayes Smartmodem that every vendor has since extended with its own additions. </p><p>The support extender essentially gives a SIM module its own general-purpose console on devices that lack safeguards to prevent such an attack.</p><p>Tomasz Piotr Lisowski and Dr Marius Muench of Birmingham, working with Fuzzware's Kristian Covic, built a toolkit called CATana to find out what a hostile card could do with that console.</p><p>The team <a href="https://www.usenix.org/conference/woot26/presentation/lisowski" target="_blank">tested 26 devices</a>, 18 smartphones and eight cellular modules, and found the SIM AT interface exposed on nine of them. The exposure is overwhelmingly concentrated in machine-to-machine hardware: six of the eight modules accepted the command, compared with just three of the 18 phones: the Oppo Find X5, the Oppo Reno 14 F 5G, and the Asus Zenfone 9. This makes it not <a href="https://www.techradar.com/news/simjacker-attack-could-affect-a-billion-smartphones" target="_blank">exactly a Simjacker-esque exploit</a> but still one that needs to be taken seriously.</p><p>All nine devices that accepted the command run a Qualcomm chip or modem, but five others that do were not vulnerable to the attack. The researchers first shared the reports with Google, Oppo, Quectel, Semtech, and Qualcomm in March 2026, and with the GSMA in May.  Qualcomm has since built a hardened configuration that switches the interface off by default, which the researchers say will be the default on future devices.</p><p>The attack vector, however, is limited because, to leverage it, the attacker must already control the SIM itself. Knowing a victim's contact number is not enough; the attacker needs physical access to the SIM slot. The exploit is real and concerning, but it has limited utility compared to a remote one for smartphones.</p><p>The IoT side is more concerning, however: unattended equipment with an accessible SIM tray can now potentially be exploited, and physical swaps might be easier than with something more personal, like one's personal phone. The card essentially talks to the equivalent of a Linux computer, one that the paper calls a rich attack surface for hostile SIM cards.</p><p>For now, the irony is that while modern smartphones have largely retired the surface this attack vector exploits, the machine-to-machine world has not, and the equipment least likely to receive a firmware update is the equipment most exposed currently.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This technology turns every router into a potential means for surveillance': Report claims Wi-Fi devices could 'quietly identify' people with nearly 100% accuracy ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Ordinary Wi-Fi networks can reportedly identify people without cameras or consent</strong></li><li><strong>KASTEL researchers achieved nearly 100% identification accuracy across 197 volunteers tested</strong></li><li><strong>Wi-Fi signals can reportedly reveal people from different viewing angles</strong></li></ul><p>A new study suggests that ordinary Wi-Fi networks could be repurposed to identify individuals without cameras, sensors, or their knowledge or consent.</p><p>Researchers from KASTEL, the Institute of Information Security and Dependability at KIT, tested the approach on 197 volunteers in controlled conditions.</p><p>Their system reportedly achieved nearly 100% identification accuracy regardless of a person's viewing angle or the way that person walked.</p><h2 id="a-method-that-needs-no-extra-hardware">A method that needs no extra hardware</h2><p>The technique relies on beamforming feedback information, a type of signal that connected devices routinely send back to a router.</p><p>This information is transmitted without any encryption, meaning anyone within range of the network could potentially intercept and read it.</p><p>By analyzing these radio signals over time, the system reportedly builds images of people from multiple viewpoints inside a space.</p><p>Earlier wireless sensing methods often required specialized equipment, such as LIDAR sensors or detailed measurements of channel state information from a network.</p><p>By contrast, the researchers say a standard, unmodified Wi-Fi device is entirely sufficient to carry out this new identification process.</p><p>"By observing the propagation of radio waves, we can create an image of the surroundings and of persons who are present," said Thorsten Strufe, a professor at KASTEL, KIT's Institute of Information Security and Dependability.</p><p>"This works similar to a normal camera, the difference being that in our case, radio waves instead of light waves are used for the recognition.</p><p>A user does not need to carry a phone, smartwatch, or other Wi-Fi-enabled device for the system to work.</p><p>Turning off one's own device would reportedly not prevent identification, since other active Wi-Fi devices nearby could still be used.</p><h2 id="privacy-concerns-extend-beyond-conventional-surveillance">Privacy concerns extend beyond conventional surveillance</h2><p>The researchers argue that widespread wireless networks could create privacy concerns because they operate throughout homes, offices, restaurants, cafés, and other public environments.</p><p>Felix Morsbach noted that intelligence agencies and cybercriminals already have simpler methods, including compromising CCTV systems and connected video doorbells.</p><p>“The omnipresent wireless networks might become a nearly comprehensive surveillance infrastructure with one concerning property: they are invisible and raise no suspicion,” Morsbach added.</p><p>Compared with existing surveillance options, such as CCTV footage or connected video doorbells, wireless signals leave no visible trace behind.</p><p>Professor Strufe cautioned that this same invisibility could make the technology particularly attractive within certain authoritarian political systems around the world.</p><p>"The technology is powerful, but at the same time entails risks to our fundamental rights, especially to privacy," said Strufe.</p><p>Ordinary <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523">routers</a> could potentially enable people to be recognized without their knowledge during routine movements, and this could be dangerous in the wrong hands.</p><p>Therefore, widespread deployment could make individual encounters difficult to distinguish from ordinary wireless activity.</p><p>The researchers argue that privacy safeguards should be incorporated into Wi-Fi technology before such capabilities become widely and easily exploited.</p><p>Specifically, they are calling for protections to be written into the forthcoming IEEE 802.11bf wireless standard currently under active development.</p><p>Via <a href="https://www.sciencedaily.com/releases/2026/08/260811052857.htm" target="_blank" rel="nofollow">ScienceDaily</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/this-technology-turns-every-router-into-a-potential-means-for-surveillance-report-claims-wi-fi-devices-could-quietly-identify-people-with-nearly-100-accuracy</link>
                                                                            <description>
                            <![CDATA[ Researchers say ordinary Wi-Fi networks identified 197 people with nearly 100% accuracy, raising concerns about invisible surveillance and privacy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kvHT4cF7FrtXwgMrPbL5bj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 19:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person plugging an Ethernet cable into a router]]></media:description>                                                            <media:text><![CDATA[A person plugging an Ethernet cable into a router]]></media:text>
                                <media:title type="plain"><![CDATA[A person plugging an Ethernet cable into a router]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kqDd8hw4VtrskmqGDY5fKa-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ordinary Wi-Fi networks can reportedly identify people without cameras or consent</strong></li><li><strong>KASTEL researchers achieved nearly 100% identification accuracy across 197 volunteers tested</strong></li><li><strong>Wi-Fi signals can reportedly reveal people from different viewing angles</strong></li></ul><p>A new study suggests that ordinary Wi-Fi networks could be repurposed to identify individuals without cameras, sensors, or their knowledge or consent.</p><p>Researchers from KASTEL, the Institute of Information Security and Dependability at KIT, tested the approach on 197 volunteers in controlled conditions.</p><p>Their system reportedly achieved nearly 100% identification accuracy regardless of a person's viewing angle or the way that person walked.</p><h2 id="a-method-that-needs-no-extra-hardware">A method that needs no extra hardware</h2><p>The technique relies on beamforming feedback information, a type of signal that connected devices routinely send back to a router.</p><p>This information is transmitted without any encryption, meaning anyone within range of the network could potentially intercept and read it.</p><p>By analyzing these radio signals over time, the system reportedly builds images of people from multiple viewpoints inside a space.</p><p>Earlier wireless sensing methods often required specialized equipment, such as LIDAR sensors or detailed measurements of channel state information from a network.</p><p>By contrast, the researchers say a standard, unmodified Wi-Fi device is entirely sufficient to carry out this new identification process.</p><p>"By observing the propagation of radio waves, we can create an image of the surroundings and of persons who are present," said Thorsten Strufe, a professor at KASTEL, KIT's Institute of Information Security and Dependability.</p><p>"This works similar to a normal camera, the difference being that in our case, radio waves instead of light waves are used for the recognition.</p><p>A user does not need to carry a phone, smartwatch, or other Wi-Fi-enabled device for the system to work.</p><p>Turning off one's own device would reportedly not prevent identification, since other active Wi-Fi devices nearby could still be used.</p><h2 id="privacy-concerns-extend-beyond-conventional-surveillance">Privacy concerns extend beyond conventional surveillance</h2><p>The researchers argue that widespread wireless networks could create privacy concerns because they operate throughout homes, offices, restaurants, cafés, and other public environments.</p><p>Felix Morsbach noted that intelligence agencies and cybercriminals already have simpler methods, including compromising CCTV systems and connected video doorbells.</p><p>“The omnipresent wireless networks might become a nearly comprehensive surveillance infrastructure with one concerning property: they are invisible and raise no suspicion,” Morsbach added.</p><p>Compared with existing surveillance options, such as CCTV footage or connected video doorbells, wireless signals leave no visible trace behind.</p><p>Professor Strufe cautioned that this same invisibility could make the technology particularly attractive within certain authoritarian political systems around the world.</p><p>"The technology is powerful, but at the same time entails risks to our fundamental rights, especially to privacy," said Strufe.</p><p>Ordinary <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523">routers</a> could potentially enable people to be recognized without their knowledge during routine movements, and this could be dangerous in the wrong hands.</p><p>Therefore, widespread deployment could make individual encounters difficult to distinguish from ordinary wireless activity.</p><p>The researchers argue that privacy safeguards should be incorporated into Wi-Fi technology before such capabilities become widely and easily exploited.</p><p>Specifically, they are calling for protections to be written into the forthcoming IEEE 802.11bf wireless standard currently under active development.</p><p>Via <a href="https://www.sciencedaily.com/releases/2026/08/260811052857.htm" target="_blank" rel="nofollow">ScienceDaily</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Geekom reveals multiple mini-PCs may be infected with malware hidden in a network driver — but it's now down to you to fix your PC ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Geekom has admitted a software driver contained malware</strong></li><li><strong>A LAN driver on a legacy page was hosting the Asruex backdoor</strong></li><li><strong>The malware can track keystrokes, steal passwords, and intercept data</strong></li></ul><p>Hardware maker Geekom has admitted that a network driver for multiple mini PC variants hosted Asruex backdoor malware, potentially putting users at risk</p><p>The LAN driver for Geekom’s range of A7, A8, AE7, AE8, AX7 Pro and AX8 Pro mini-PCs hosted the malicious package with administrator-level permissions that allowed it to monitor everything you type, steal data, and even swipe passwords from your machine. The malicious software also connects to a command and control (C2) network to send and receive information from hackers.</p><p>Geekom has issued an apology and removed the software package in question, but if you have a Geekom mini PC from the aforementioned range and have installed the LAN driver, I’d definitely recommend doing a full system virus scan, with a wipe and reset just to be sure.</p><h2 id="geekom-ships-malware-riddled-lan-driver">Geekom ships malware-riddled LAN driver</h2><p><a href="https://videocardz.com/newz/geekom-mini-pc-driver-archive-contains-file-flagged-as-malware" target="_blank"><em>Videocardz</em></a> first broke the story after investigating claims from a Reddit user who reported finding a malicious executable file contained within the LAN driver.</p><p><em>Videocardz</em> then independently investigated the claim using FileScan.IO, MetaDefender VirusTotal, and YARAify. Each antivirus engine detected the executable as malicious.</p><p>In Geekom’s statement about the malicious file, the company said that the driver was hosted on a “legacy page [that] had already been replaced and was no longer accessible through the normal Support navigation, although it remained indexed by search engines.”</p><p>So when users searched for the LAN driver using Google, the result that came up was the malicious file. I always recommend users install drivers and other software from the official distributor rather than using Google listings as hackers can use tactics such as SEO poisoning or promoted pages to offer dodgy software. But in this case the legacy page was official.</p><p>Geekom has <a href="https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs" target="_blank" rel="nofollow">confirmed</a> that none of its mini PC range were shipped with the malicious driver preinstalled, so if you haven’t directly downloaded the malicious software from the legacy page, you should be okay. But consider running a Windows Defender scan to be sure.</p><p>In order to guarantee that your mini PC is free of the malicious driver, perform a complete wipe and reset of Windows, and install a new Windows image direct from Microsoft’s official page. Going forward, only install software and drivers from the official support pages of the manufacturer.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/geekom-reveals-multiple-mini-pcs-may-be-infected-with-malware-hidden-in-a-network-driver-but-its-now-down-to-you-to-fix-your-pc</link>
                                                                            <description>
                            <![CDATA[ A malicious executable hidden within a LAN driver can track keystrokes, intercept data, and swipe passwords from Geekom mini-PCs. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AhLptuzu7RCo7xSnaxqfyg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg">
                                                            <media:credit><![CDATA[Alastair Jennings]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Geekom Mini PC A7]]></media:description>                                                            <media:text><![CDATA[Geekom Mini PC A7]]></media:text>
                                <media:title type="plain"><![CDATA[Geekom Mini PC A7]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/WJok7QZ99U3Sz57DMBX87f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Geekom has admitted a software driver contained malware</strong></li><li><strong>A LAN driver on a legacy page was hosting the Asruex backdoor</strong></li><li><strong>The malware can track keystrokes, steal passwords, and intercept data</strong></li></ul><p>Hardware maker Geekom has admitted that a network driver for multiple mini PC variants hosted Asruex backdoor malware, potentially putting users at risk</p><p>The LAN driver for Geekom’s range of A7, A8, AE7, AE8, AX7 Pro and AX8 Pro mini-PCs hosted the malicious package with administrator-level permissions that allowed it to monitor everything you type, steal data, and even swipe passwords from your machine. The malicious software also connects to a command and control (C2) network to send and receive information from hackers.</p><p>Geekom has issued an apology and removed the software package in question, but if you have a Geekom mini PC from the aforementioned range and have installed the LAN driver, I’d definitely recommend doing a full system virus scan, with a wipe and reset just to be sure.</p><h2 id="geekom-ships-malware-riddled-lan-driver">Geekom ships malware-riddled LAN driver</h2><p><a href="https://videocardz.com/newz/geekom-mini-pc-driver-archive-contains-file-flagged-as-malware" target="_blank"><em>Videocardz</em></a> first broke the story after investigating claims from a Reddit user who reported finding a malicious executable file contained within the LAN driver.</p><p><em>Videocardz</em> then independently investigated the claim using FileScan.IO, MetaDefender VirusTotal, and YARAify. Each antivirus engine detected the executable as malicious.</p><p>In Geekom’s statement about the malicious file, the company said that the driver was hosted on a “legacy page [that] had already been replaced and was no longer accessible through the normal Support navigation, although it remained indexed by search engines.”</p><p>So when users searched for the LAN driver using Google, the result that came up was the malicious file. I always recommend users install drivers and other software from the official distributor rather than using Google listings as hackers can use tactics such as SEO poisoning or promoted pages to offer dodgy software. But in this case the legacy page was official.</p><p>Geekom has <a href="https://videocardz.com/newz/geekom-apologizes-for-hosting-malware-in-driver-package-for-its-mini-pcs" target="_blank" rel="nofollow">confirmed</a> that none of its mini PC range were shipped with the malicious driver preinstalled, so if you haven’t directly downloaded the malicious software from the legacy page, you should be okay. But consider running a Windows Defender scan to be sure.</p><p>In order to guarantee that your mini PC is free of the malicious driver, perform a complete wipe and reset of Windows, and install a new Windows image direct from Microsoft’s official page. Going forward, only install software and drivers from the official support pages of the manufacturer.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Loan company breach sees nearly 750,000 users have financial info, SSNs leaked ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Heights Finance breach exposed sensitive customer data via a compromised third‑party cloud platform</strong></li><li><strong>Stolen records included contact details, financial info, and government identifiers</strong></li><li><strong>Over 700,000 Texans affected; company offers credit monitoring and identity protection</strong></li></ul><p>US loan company Heights Finance has revealed it suffered a cyberattack earlier in 2026 in which it lost sensitive data on hundreds of thousands of its customers.</p><p>The company published a data breach notification on its website, disclosing that on May 7 2026, it saw an “unauthorized actor” gaining access to a cloud-based platform, hosted by a third party, which the company uses to store certain customer data. </p><p>The breach was limited to that cloud platform only and did not affect its loan management system, or other systems and networks.</p><h2 id="at-least-700-000-victims">At least 700,000 victims</h2><p>As is standard practice in these incidents, Heights Finance notified the relevant authorities and brought in outside cybersecurity help.</p><p>The subsequent investigation determined that the attackers - which were not named - stole contact details (names, postal addresses, phone numbers, email addresses), financial information (account details, bank account information such as bank name, account number, routing number), government identifiers (Social Security numbers, tax IDs, driver’s license numbers), and other miscellaneous data.</p><p>“Your information may be involved if you received a loan through Heights, or if you inquired about or applied for a loan product (including through a third party),” the company said. “Your information may also be involved if you were a former borrower of Curo Management or any of its former or current related brands.”</p><p>The exact number of affected individuals is not known at this time. Heights Finance told regulators in Texas that the breach affected more than 730,000 of its residents, and added that it affected those living in Alabama, Tennessee, Georgia, Texas and South Carolina.</p><p>We don’t know which <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud-based platform</a> Heights Finance is using, and the threat actors are yet to claim responsibility for the attack. In the meantime, the company is offering affected customers credit monitoring and identity protection services through Epiq.</p><p><em>Via </em><a href="https://therecord.media/financial-info-leak-debt-consolidator" target="_blank"><em>The Record</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/loan-company-breach-sees-nearly-750-000-users-have-financial-info-ssns-leaked</link>
                                                                            <description>
                            <![CDATA[ Heights Finance said its cloud account was compromised, and information such as bank accounts and SSNs, stolen. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sVNrSWMVEPvYz8KDTwayqF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Heights Finance breach exposed sensitive customer data via a compromised third‑party cloud platform</strong></li><li><strong>Stolen records included contact details, financial info, and government identifiers</strong></li><li><strong>Over 700,000 Texans affected; company offers credit monitoring and identity protection</strong></li></ul><p>US loan company Heights Finance has revealed it suffered a cyberattack earlier in 2026 in which it lost sensitive data on hundreds of thousands of its customers.</p><p>The company published a data breach notification on its website, disclosing that on May 7 2026, it saw an “unauthorized actor” gaining access to a cloud-based platform, hosted by a third party, which the company uses to store certain customer data. </p><p>The breach was limited to that cloud platform only and did not affect its loan management system, or other systems and networks.</p><h2 id="at-least-700-000-victims">At least 700,000 victims</h2><p>As is standard practice in these incidents, Heights Finance notified the relevant authorities and brought in outside cybersecurity help.</p><p>The subsequent investigation determined that the attackers - which were not named - stole contact details (names, postal addresses, phone numbers, email addresses), financial information (account details, bank account information such as bank name, account number, routing number), government identifiers (Social Security numbers, tax IDs, driver’s license numbers), and other miscellaneous data.</p><p>“Your information may be involved if you received a loan through Heights, or if you inquired about or applied for a loan product (including through a third party),” the company said. “Your information may also be involved if you were a former borrower of Curo Management or any of its former or current related brands.”</p><p>The exact number of affected individuals is not known at this time. Heights Finance told regulators in Texas that the breach affected more than 730,000 of its residents, and added that it affected those living in Alabama, Tennessee, Georgia, Texas and South Carolina.</p><p>We don’t know which <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud-based platform</a> Heights Finance is using, and the threat actors are yet to claim responsibility for the attack. In the meantime, the company is offering affected customers credit monitoring and identity protection services through Epiq.</p><p><em>Via </em><a href="https://therecord.media/financial-info-leak-debt-consolidator" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Millions of stolen records allegedly dumped online by mystery "Hatman" hacker — McDonalds, Vodafone and more see Microsoft Azure records stolen ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Hacker “TheHatman” claims to have stolen millions of Azure/Entra employee records from major firms</strong></li><li><strong>Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud</strong></li><li><strong>Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic</strong></li></ul><p>A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.</p><p>A hacker going by the alias “TheHatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments. </p><p>TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations.</p><h2 id="what-was-stolen-and-from-whom">What was stolen and from whom?</h2><p>Among the victims and the number of records exposed, are:</p><p>McDonald’s Corporation: 1,700,000 records<br>TCS (Tata Consultancy Services): 800,000 records<br>Vodafone: 425,000 records<br>HCL Technologies: 250,000 records<br>InterContinental Hotels Group (IHG): 185,000 records<br>Kyndryl: 170,000 records<br>Gap Inc.: 80,000 records<br>Hexaware Technologies: 20,000 records<br>Wyndham Hotels: 9,000 records</p><p>They are now looking for a buyer: “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” TheHatman said in one of the posts.</p><p>In their writeup, security researchers from <a href="https://cybernews.com/security/mcdonalds-vodafone-azure-microdoft-credential-theft/" target="_blank"><em>Cybernews</em></a> said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.</p><p>They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records. </p><h2 id="what-are-the-risks">What are the risks?</h2><p>Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.</p><p>For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - it’s been documented time and time again. </p><h2 id="what-did-the-victims-say">What did the victims say?</h2><p>Most organizations are yet to give an official statement about these claims. Gap told <a href="https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/" target="_blank"><em>BleepingComputer</em></a> that it found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident. </p><p>“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” Gap told the publication.</p><p>Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident. </p><p>“The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” TCS said in the filing. “The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.”</p><p>TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years.” </p><p>Not everyone agrees with that assessment, though. Security researchers Hudson Rock believe the attackers stole login credentials with an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a>, rather than through password spraying. </p><p>“Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure,” the researchers said in their report. “If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.”</p><p>Hudson Rock also described the stolen data as “likely highly authentic”, hinting that just because it’s older, it doesn’t mean it’s not useful.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/millions-of-stolen-records-allegedly-dumped-online-by-mystery-hatman-hacker-mcdonalds-vodafone-and-more-see-microsoft-azure-records-stolen</link>
                                                                            <description>
                            <![CDATA[ Some affected companies argue the data is years old and claim no breach in their systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">g2uaoVUQzwLLWJpVyugm5B</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hacker “TheHatman” claims to have stolen millions of Azure/Entra employee records from major firms</strong></li><li><strong>Data includes names, emails, job titles, privileged accounts; risks include impersonation and fraud</strong></li><li><strong>Victims dispute scope, but researchers say infostealer‑based theft makes the leaks likely authentic</strong></li></ul><p>A cybercriminal is selling millions of user records on the dark web, which they claim to have stolen from large organizations such as McDonalds, Tata Consultancy Services, and Wyndham Hotels.</p><p>A hacker going by the alias “TheHatman” posted multiple threads on dark web forums, claiming to have stolen information from Azure and Entra environments. </p><p>TheHatman said they broke in using compromised login credentials, targeting almost a dozen organizations.</p><h2 id="what-was-stolen-and-from-whom">What was stolen and from whom?</h2><p>Among the victims and the number of records exposed, are:</p><p>McDonald’s Corporation: 1,700,000 records<br>TCS (Tata Consultancy Services): 800,000 records<br>Vodafone: 425,000 records<br>HCL Technologies: 250,000 records<br>InterContinental Hotels Group (IHG): 185,000 records<br>Kyndryl: 170,000 records<br>Gap Inc.: 80,000 records<br>Hexaware Technologies: 20,000 records<br>Wyndham Hotels: 9,000 records</p><p>They are now looking for a buyer: “I’m selling McDonald’s Corporation internal employee dump downloaded directly from Azure Tenant using compromised credentials,” TheHatman said in one of the posts.</p><p>In their writeup, security researchers from <a href="https://cybernews.com/security/mcdonalds-vodafone-azure-microdoft-credential-theft/" target="_blank"><em>Cybernews</em></a> said they analyzed one of the samples posted on the dark web and said the entries were “consistent with Azure directory exports”.</p><p>They contained employee names, emails, phone numbers, job titles, workplace addresses, IDs, the departments they work in, user group memberships, service accounts, and highly privileged account records. </p><h2 id="what-are-the-risks">What are the risks?</h2><p>Stealing information such as names, email addresses, and workplace details might not sound like a worrisome breach of privacy, but the implications are rather big. Cybercriminals can use it to impersonate a business partner or a major client, and try to trick their employees into installing <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or making a fraudulent wire transaction. That way, they can escalate what seems like a relatively benign breach, into a full-blown cyberattack with material and legal consequences.</p><p>For example, a criminal might discover a Vodafone employee that regularly handles payments to a particular supplier. They might impersonate that supplier’s finance director, engage in conversation and, while requesting a new payment, warn that the company changed their bank account. This is not a purely theoretical scenario - it’s been documented time and time again. </p><h2 id="what-did-the-victims-say">What did the victims say?</h2><p>Most organizations are yet to give an official statement about these claims. Gap told <a href="https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/" target="_blank"><em>BleepingComputer</em></a> that it found no evidence of the breach and suggested that the attackers merely repackaged data from an older incident. </p><p>“Our preliminary investigation indicates that the data in question is limited in scope, non-sensitive and dated back to several years ago. Notably, there is no evidence to suggest that our corporate systems have been compromised,” Gap told the publication.</p><p>Tata Consultancy Services notified the Indian National Stock Exchange about the breach last week, also suggesting that this was a resurfacing of an older incident. </p><p>“The Company has investigated the matter and has not found any credible evidence of a breach of TCS systems or customer environments,” TCS said in the filing. “The information referenced appears to be more than four years old and limited to basic employee information. There is no indication that customer data, customer systems, or TCS operational systems have been impacted.”</p><p>TCS said the attackers broke in using credential stuffing, something that could have only been done years ago: “The attacker claims to have used password spray and Multi-Factor Authentication (MFA) fatigue as the attack vector. The Company has had strong safeguards in place against such techniques for more than two years.” </p><p>Not everyone agrees with that assessment, though. Security researchers Hudson Rock believe the attackers stole login credentials with an <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">infostealer</a>, rather than through password spraying. </p><p>“Judging by the massive size of the organizations impacted, it appears highly likely that this campaign originates from targeted exploitation of Infostealer infections rather than a systemic zero-day vulnerability in Azure,” the researchers said in their report. “If this were a widespread vulnerability, we would likely see a much broader spectrum of organizations impacted, including smaller businesses, rather than just these massive Fortune 500-level enterprises.”</p><p>Hudson Rock also described the stolen data as “likely highly authentic”, hinting that just because it’s older, it doesn’t mean it’s not useful.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Pokémon Center data breach exposes customer info, cancels some orders ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Pokémon Center UK orders disrupted after CEVA Logistics cyberattack on July 30 2026</strong></li><li><strong>Customer names, addresses, emails, and order details likely exposed, but accounts and payments safe</strong></li><li><strong>Around a dozen organizations confirmed affected; no group has claimed responsibility yet</strong></li></ul><p>Customers who recently ordered their favorite Pikachu toy from Pokémon Center might have to do it all over again, since the company suffered a third-party cyberattack which disrupted its operations.</p><p>The official store for Pokémon merchandise in the UK has reached out to its customers via email to warn them about a recent cyberattack and its consequences. </p><p>According to<em> </em><a href="https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/" target="_blank"><em>BleepingComputer</em></a>, which has seen a copy of the email, the company told its customers they had to “cancel your recent order due to an unforeseen fulfilment issue”. </p><div class="product"><a data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="ceva-logistics">CEVA Logistics</h2><p>The company’s website is also showing a notification saying the company is “currently experiencing delays affecting some orders for our UK customers.” </p><p>“These orders may take longer than usual to process, dispatch, and deliver. We apologize for the inconvenience and appreciate your patience.”</p><p>The company said the attack struck its logistics provider, CEVA Logistics. </p><p>"CEVA Logistics, the vendor Pokémon Center utilizes to ship products from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026."</p><p>Last week, one of the biggest shipping and logistics companies in the world <a href="https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know" target="_blank">disclosed an incident</a> that forced it to shut down parts of its IT infrastructure and affected eight warehouses. At the time, a handful of its customers reported being affected by the breach, including Dutch retailers Bol and De Bijenkorf, and PC gaming powerhouse Valve. </p><p>Pokémon Center said the data most likely exposed in this incident includes people’s full names, mailing addresses, phone numbers, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, and details about what they previously ordered on the site. User accounts are apparently safe, and so are payment details. </p><p>So far, around a dozen organizations are confirmed as having been affected. No threat actors have claimed responsibility yet. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders</link>
                                                                            <description>
                            <![CDATA[ Another victim of the CEVA Logistics supply chain attack steps forward as orders get halted and postponed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gmsChWHs9LaKRXbkHCNR48</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:23:42 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:29:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg">
                                                            <media:credit><![CDATA[Pokemon Company]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Jiggly puff Angry]]></media:description>                                                            <media:text><![CDATA[Jiggly puff Angry]]></media:text>
                                <media:title type="plain"><![CDATA[Jiggly puff Angry]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uhBYCXndSH8w5FSohcafnX-1280-80.jpeg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Pokémon Center UK orders disrupted after CEVA Logistics cyberattack on July 30 2026</strong></li><li><strong>Customer names, addresses, emails, and order details likely exposed, but accounts and payments safe</strong></li><li><strong>Around a dozen organizations confirmed affected; no group has claimed responsibility yet</strong></li></ul><p>Customers who recently ordered their favorite Pikachu toy from Pokémon Center might have to do it all over again, since the company suffered a third-party cyberattack which disrupted its operations.</p><p>The official store for Pokémon merchandise in the UK has reached out to its customers via email to warn them about a recent cyberattack and its consequences. </p><p>According to<em> </em><a href="https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/" target="_blank"><em>BleepingComputer</em></a>, which has seen a copy of the email, the company told its customers they had to “cancel your recent order due to an unforeseen fulfilment issue”. </p><div class="product"><a data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6350dae-9b08-11f1-b70e-1d3b7178f10e" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="ceva-logistics">CEVA Logistics</h2><p>The company’s website is also showing a notification saying the company is “currently experiencing delays affecting some orders for our UK customers.” </p><p>“These orders may take longer than usual to process, dispatch, and deliver. We apologize for the inconvenience and appreciate your patience.”</p><p>The company said the attack struck its logistics provider, CEVA Logistics. </p><p>"CEVA Logistics, the vendor Pokémon Center utilizes to ship products from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026."</p><p>Last week, one of the biggest shipping and logistics companies in the world <a href="https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know" target="_blank">disclosed an incident</a> that forced it to shut down parts of its IT infrastructure and affected eight warehouses. At the time, a handful of its customers reported being affected by the breach, including Dutch retailers Bol and De Bijenkorf, and PC gaming powerhouse Valve. </p><p>Pokémon Center said the data most likely exposed in this incident includes people’s full names, mailing addresses, phone numbers, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, and details about what they previously ordered on the site. User accounts are apparently safe, and so are payment details. </p><p>So far, around a dozen organizations are confirmed as having been affected. No threat actors have claimed responsibility yet. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybersecurity needs a new KPI: it's time to measure our ability to adapt ]]></title>
                                                                                                <dc:content><![CDATA[ <p>For years, cybersecurity has become increasingly measurable. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> leaders can often tell you how long it takes to detect an intrusion, contain an attack and restore normal operation. Those figures have given boards a straightforward way to judge progress, offering reassurance that investment in security is delivering real improvements.</p><p>Metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) have earned their place at the table. They both provide a clear picture of how effectively security teams perform when something goes wrong and have helped drive better incident response across the industry. </p><p>The problem is not that these metrics are wrong. They were designed for a different era, when technology changed more slowly, attack methods evolved over longer timescales and AI wasn't yet part of the equation.</p><p>Today's businesses are introducing new technologies at an extraordinary pace. AI is becoming embedded across organizations, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments continue to expand and businesses are more interconnected than ever before. At the same time, attackers are constantly adapting their own techniques, taking advantage of new tactics and tools almost as quickly as they emerge.</p><p>CISO’s and boards need to dynamically review the changing threat landscape and risk posture and ask themselves whether the metrics relied on for years still tell us everything we need to know.</p><h2 id="mind-the-gap">Mind the gap</h2><p>Every business wants to detect attacks sooner, contain them faster and recover with minimal disruption. That’s why MTTD and MTTR  remain valuable operational measures. They tell us how effectively a security team performed once an incident was underway.</p><p>What they don't tell us is whether the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> is becoming better prepared for what comes next, more resilient, more agile in recovery. That matters because cyber risk continues to evolve long after an incident has been contained.</p><p>The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber breach or attack during the previous year.</p><p>This reinforces how security teams are operating in an environment where incidents are a regular reality, whether it's in their own environment, or that of one of their supply chain. Responding well is important, but resilience is shaped by everything that happens before incidents.</p><p>A business may recover quickly from an attack but still take months to review its security policies, reassess supplier risk or strengthen controls in response to what it has learned. By the time those changes are made, the threat landscape will have moved on.</p><p>Traditional metrics tell us how quickly a business responds to an incident. They don't tell us how quickly it learns from one, or how quickly it adapts. </p><h2 id="closing-the-gap">Closing the gap</h2><p>If we're going to close that gap of preparedness, our metrics need to evolve as well. Resilience is no longer defined solely by how well a business responds to isolated incidents, but by how quickly it keeps pace with continuous change.</p><p>I believe organizations should start thinking about another benchmark alongside the ones we already know: Mean Time to Adapt (MTTA).</p><p>MTTA considers how long it takes to recognize a meaningful change in the threat landscape and turn that knowledge into action.</p><p>Sometimes that action will be technical. It could mean updating the rules security tools used to detect emerging attack techniques. Or it might involve tightening access to critical systems after a serious vulnerability is discovered. It may also be a proactive lessons learned view of an attack on another organization or sector to understand how vulnerable the organization would be.</p><p>In other cases, the response will be organizational rather than technical. It may involve reviewing governance, changing how cyber risk is reported to the board or refreshing <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> awareness programs to reflect the latest tactics being used by attackers.  </p><p>Either way, resilience depends on both. The strongest security programs combine technical improvements with organizational change, ensuring businesses can recognize change and act on it quickly.</p><p>That’s why closing this gap is not only a technology challenge. It relies on decision-making, leadership and a willingness to keep questioning whether existing assumptions still hold true. <a href="https://www.techradar.com/best/best-small-business-website-builders">Businesses</a> that adapt well rarely assume their current security program is finished. They expect it to evolve because the environment around them is evolving too.</p><p>That thinking is increasingly reflected across the wider industry. For example, the National Cyber Security Centre's Cyber Assessment Framework places governance, risk management and continual improvement at the heart of cyber resilience. It recognizes that security is an ongoing organizational capability, not a one-time achievement. </p><h2 id="a-different-conversation-in-the-boardroom">A different conversation in the boardroom</h2><p>If preparedness and adaptation becomes a more meaningful measure of resilience, it will change the conversations taking place in the boardroom.</p><p>Most directors already receive regular updates covering incidents, phishing activity and response times. Those reports remain important, but they won’t always show how well the business is responding to change itself.</p><p>The discussion must now move beyond operational reporting and give greater prominence to MTTA. This would give boards a way to measure how quickly an organization responds to change, rather than simply how efficiently it handles incidents.</p><p>In practice, that means asking a different set of questions. How quickly does the business reassess risk when a significant new threat emerges? How long does it take for new intelligence to shape security policies? Have lessons from recent attacks fundamentally changed the way the organization operates, or have they simply been recorded and filed away?</p><p>By measuring adaptation, rather than response alone, organizations can answer these questions with greater confidence and build a broader picture of resilience.</p><p>And this isn't solely a question for security teams. It depends on leadership, governance and how prepared the wider business is to make decisions as risks continue to evolve.</p><h2 id="measuring-what-matters">Measuring what matters</h2><p>MTTD and MTTR will remain valuable measures of operational performance. But if organizations want to understand how resilient they really are, they also need to know how quickly they adapt.</p><p>MTTA fills that gap. It won't replace today's cyber metrics, but it will enhance them by measuring a capability that is becoming increasingly important as technology, AI and cyber threats continue to evolve.</p><p>It’s now MTTA time to shine.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/cybersecurity-needs-a-new-kpi-its-time-to-measure-our-ability-to-adapt</link>
                                                                            <description>
                            <![CDATA[ Cyber resilience depends on more than response times. It's time to measure adaptation too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pN5E9BZQwVuAYtmzZC5MrH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 10:00:07 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Cheryl Martin ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, cybersecurity has become increasingly measurable. <a href="https://www.techradar.com/news/best-internet-security-suites">Security</a> leaders can often tell you how long it takes to detect an intrusion, contain an attack and restore normal operation. Those figures have given boards a straightforward way to judge progress, offering reassurance that investment in security is delivering real improvements.</p><p>Metrics such as Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) have earned their place at the table. They both provide a clear picture of how effectively security teams perform when something goes wrong and have helped drive better incident response across the industry. </p><p>The problem is not that these metrics are wrong. They were designed for a different era, when technology changed more slowly, attack methods evolved over longer timescales and AI wasn't yet part of the equation.</p><p>Today's businesses are introducing new technologies at an extraordinary pace. AI is becoming embedded across organizations, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud</a> environments continue to expand and businesses are more interconnected than ever before. At the same time, attackers are constantly adapting their own techniques, taking advantage of new tactics and tools almost as quickly as they emerge.</p><p>CISO’s and boards need to dynamically review the changing threat landscape and risk posture and ask themselves whether the metrics relied on for years still tell us everything we need to know.</p><h2 id="mind-the-gap">Mind the gap</h2><p>Every business wants to detect attacks sooner, contain them faster and recover with minimal disruption. That’s why MTTD and MTTR  remain valuable operational measures. They tell us how effectively a security team performed once an incident was underway.</p><p>What they don't tell us is whether the <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> is becoming better prepared for what comes next, more resilient, more agile in recovery. That matters because cyber risk continues to evolve long after an incident has been contained.</p><p>The UK Government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses experienced a cyber breach or attack during the previous year.</p><p>This reinforces how security teams are operating in an environment where incidents are a regular reality, whether it's in their own environment, or that of one of their supply chain. Responding well is important, but resilience is shaped by everything that happens before incidents.</p><p>A business may recover quickly from an attack but still take months to review its security policies, reassess supplier risk or strengthen controls in response to what it has learned. By the time those changes are made, the threat landscape will have moved on.</p><p>Traditional metrics tell us how quickly a business responds to an incident. They don't tell us how quickly it learns from one, or how quickly it adapts. </p><h2 id="closing-the-gap">Closing the gap</h2><p>If we're going to close that gap of preparedness, our metrics need to evolve as well. Resilience is no longer defined solely by how well a business responds to isolated incidents, but by how quickly it keeps pace with continuous change.</p><p>I believe organizations should start thinking about another benchmark alongside the ones we already know: Mean Time to Adapt (MTTA).</p><p>MTTA considers how long it takes to recognize a meaningful change in the threat landscape and turn that knowledge into action.</p><p>Sometimes that action will be technical. It could mean updating the rules security tools used to detect emerging attack techniques. Or it might involve tightening access to critical systems after a serious vulnerability is discovered. It may also be a proactive lessons learned view of an attack on another organization or sector to understand how vulnerable the organization would be.</p><p>In other cases, the response will be organizational rather than technical. It may involve reviewing governance, changing how cyber risk is reported to the board or refreshing <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> awareness programs to reflect the latest tactics being used by attackers.  </p><p>Either way, resilience depends on both. The strongest security programs combine technical improvements with organizational change, ensuring businesses can recognize change and act on it quickly.</p><p>That’s why closing this gap is not only a technology challenge. It relies on decision-making, leadership and a willingness to keep questioning whether existing assumptions still hold true. <a href="https://www.techradar.com/best/best-small-business-website-builders">Businesses</a> that adapt well rarely assume their current security program is finished. They expect it to evolve because the environment around them is evolving too.</p><p>That thinking is increasingly reflected across the wider industry. For example, the National Cyber Security Centre's Cyber Assessment Framework places governance, risk management and continual improvement at the heart of cyber resilience. It recognizes that security is an ongoing organizational capability, not a one-time achievement. </p><h2 id="a-different-conversation-in-the-boardroom">A different conversation in the boardroom</h2><p>If preparedness and adaptation becomes a more meaningful measure of resilience, it will change the conversations taking place in the boardroom.</p><p>Most directors already receive regular updates covering incidents, phishing activity and response times. Those reports remain important, but they won’t always show how well the business is responding to change itself.</p><p>The discussion must now move beyond operational reporting and give greater prominence to MTTA. This would give boards a way to measure how quickly an organization responds to change, rather than simply how efficiently it handles incidents.</p><p>In practice, that means asking a different set of questions. How quickly does the business reassess risk when a significant new threat emerges? How long does it take for new intelligence to shape security policies? Have lessons from recent attacks fundamentally changed the way the organization operates, or have they simply been recorded and filed away?</p><p>By measuring adaptation, rather than response alone, organizations can answer these questions with greater confidence and build a broader picture of resilience.</p><p>And this isn't solely a question for security teams. It depends on leadership, governance and how prepared the wider business is to make decisions as risks continue to evolve.</p><h2 id="measuring-what-matters">Measuring what matters</h2><p>MTTD and MTTR will remain valuable measures of operational performance. But if organizations want to understand how resilient they really are, they also need to know how quickly they adapt.</p><p>MTTA fills that gap. It won't replace today's cyber metrics, but it will enhance them by measuring a capability that is becoming increasingly important as technology, AI and cyber threats continue to evolve.</p><p>It’s now MTTA time to shine.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ National infrastructure needs a new approach to cyber resilience ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The prospect of bringing more of Britain's critical national infrastructure into public ownership has prompted plenty of debate about investment, governance and accountability. </p><p>Far less attention has been paid to what it could mean for <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a>. </p><p>Regardless of where you stand politically, one thing is clear. Public ownership does not make cyber risk disappear. </p><p>If anything, it raises expectations that essential services will be more resilient, more coordinated and better prepared to withstand disruption.</p><p>That expectation reflects the reality of the threat landscape. Energy providers, water companies, transport operators and healthcare organizations all sit at the center of complex digital ecosystems. Their ability to deliver essential services depends on thousands of suppliers, technology vendors and third parties. </p><p>When one organization is compromised, the effects can spread well beyond its own network. Resilience therefore depends on far more than protecting individual organizations. It depends on understanding and managing the relationships between them.</p><p>If the government is serious about strengthening national infrastructure, cybersecurity must become part of that conversation from day one. That means moving beyond isolated <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs and towards a model where organizations share intelligence, understand common risks and coordinate their response before disruption spreads.</p><h2 id="critical-infrastructure-extends-beyond-organizational-boundaries">Critical infrastructure extends beyond organizational boundaries</h2><p>Some of the defining cyber attacks of recent years have demonstrated that attackers are rarely interested in a single target. They look for opportunities to compromise one organization in order to reach many others.</p><p>The SolarWinds attack remains one of the clearest examples. By compromising trusted software updates, attackers gained access to thousands of organizations around the world. More recently, the <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> attack on Synnovis disrupted pathology services across several NHS trusts, leading to cancelled operations, delayed appointments and widespread disruption to patient care. </p><p>Neither incident remained confined to the organization that was initially compromised. Both exposed the reality that critical infrastructure now depends on interconnected supply chains as much as physical assets.</p><p>That presents a challenge for every operator of critical national infrastructure. Security can no longer be viewed solely through the lens of protecting your own estate. Organizations also need visibility into the threats affecting suppliers, partners and the wider ecosystem. A vulnerability within a <a href="https://www.techradar.com/best/best-open-source-software">software</a> provider or outsourced service can quickly become a problem for every organization that depends on it.</p><p>This is where many existing security programs begin to show their limitations. Organizations have invested heavily in detection technologies, vulnerability management platforms and threat intelligence feeds. They are collecting more information than ever before. Yet many still struggle to translate that information into confident operational decisions.</p><h2 id="better-decisions-start-with-better-intelligence">Better decisions start with better intelligence</h2><p>The cybersecurity industry has spent years focusing on visibility. The assumption has been that if organizations can discover every vulnerability, identify every <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset</a> and collect every threat feed, they will naturally become more secure.</p><p>The evidence suggests otherwise.</p><p>Filigran's recent State of Threat Management report found that organizations consume an average of fourteen different threat intelligence feeds, yet fewer than half have fully operationalized that intelligence across their security programs. </p><p>At the same time, 84% of respondents said the attacks they experience exploit risks that were already known but had not been prioritized. Almost every organization surveyed also reported difficulty determining whether identified exposures were genuinely exploitable.</p><p>Those findings illustrate a wider industry problem. The challenge is no longer discovering risk. It is deciding which risks deserve immediate attention.</p><p>Security teams are surrounded by alerts, vulnerability reports and intelligence updates. Every tool claims to identify another critical issue demanding urgent action. Without context, everything starts to look important. Analysts spend valuable time investigating vulnerabilities that may never be exploited while genuinely dangerous attack paths remain hidden among the noise. </p><p>That has consequences beyond operational efficiency. Every hour spent investigating a low priority issue is an hour that cannot be spent reducing real business risk. Organizations are not simply overwhelmed by the volume of information. They are overwhelmed by the number of decisions they are expected to make every day.</p><h2 id="threat-intelligence-should-shape-decisions-long-before-an-incident">Threat intelligence should shape decisions long before an incident</h2><p>One reason this happens is that threat intelligence is still too often treated as a function of the Security Operations Centre. Intelligence is gathered, analyzed and used to help detect or investigate malicious activity once attackers have already reached the network.</p><p>Yet, threat intelligence has far greater value when it informs decisions much earlier in the security lifecycle.</p><p>Used effectively, it should help organizations understand which vulnerabilities are actively being targeted, which attack paths present the greatest business risk and which remediation activities will deliver the greatest reduction in exposure. Rather than treating every vulnerability as equally urgent, security teams can focus on the threats that genuinely matter to their environment.</p><p>This is also where Continuous Threat Exposure Management, or CTEM, has an important role to play. CTEM should not be viewed as another technology category or another security acronym. It provides a structured framework for connecting threat intelligence, exposure management, validation and remediation into a continuous process. Instead of relying on assumptions or theoretical risk scores, organizations can validate whether a vulnerability is genuinely exploitable before committing time and resources to fixing it.</p><p>Perhaps the biggest obstacle is not technical at all. Many organizations still operate with threat intelligence, vulnerability management, penetration testing and governance teams working independently, each with different priorities, processes and tooling. Breaking down those silos often delivers greater improvements than introducing another security platform.</p><h2 id="building-a-national-capability">Building a national capability</h2><p>If critical infrastructure is expected to become more resilient, collaboration has to become part of everyday operations rather than something that only happens during a major incident. That thinking is already beginning to take shape. </p><p>Earlier this month, the National Cyber Security Centre and GCHQ issued a call for industry, academia and critical infrastructure operators to help define Cyber Shield, a proposed national cyber defense capability designed to combine AI, shared intelligence and coordinated defense at national scale. </p><p>Significantly, the initiative recognizes that the government cannot build this capability alone. It will depend on close collaboration with the organizations responsible for protecting the UK's essential services. </p><p>Additionally, the Cyber Security and Resilience Bill provides an opportunity to strengthen that approach by encouraging greater consistency across essential sectors. Frameworks such as the National Cyber Security Centre's Cyber Assessment Framework already give organizations a common language for measuring resilience. </p><p>They become even more valuable when they encourage organizations to learn from one another instead of tackling similar challenges in isolation.</p><p>Open standards have an important role to play as well. The Dutch National Cyber Security Centre recently made STIX and TAXII 2.1 the mandatory standard for sharing cyber threat intelligence across government. </p><p>While technical on the surface, the decision reflects a broader principle. When organizations exchange intelligence using common standards, they remove friction from collaboration and can respond to threats more quickly.</p><p>Technology alone will not deliver that outcome. Artificial intelligence, automation and modern security platforms can help organizations process more information and reduce manual effort, but they still depend on good intelligence, sound governance and trusted relationships. </p><p>For the simple reason that fast decisions only become good decisions when they are supported by the right context.</p><h2 id="resilience-is-a-shared-responsibility">Resilience is a shared responsibility</h2><p>Whether more of Britain's critical national infrastructure ultimately moves into public ownership is only part of the story. Cyber attackers do not distinguish between public and private organizations. They target weak links, trusted suppliers and interconnected systems wherever they find them.</p><p>The organizations that will be best prepared for the years ahead will be those that treat resilience as a collective responsibility. They will operationalize threat intelligence before incidents occur, validate real-world risk rather than relying on assumptions, and collaborate across organizational boundaries as readily as attackers do.</p><p>Protecting critical infrastructure has never been solely about defending individual organizations. It is about strengthening the entire ecosystem that keeps essential services running. If the UK wants to build genuinely resilient national infrastructure, that is where the conversation needs to begin.</p><p><a href="https://www.techradar.com/best/best-patch-management-tools"><em>We've listed the best path management software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/national-infrastructure-needs-a-new-approach-to-cyber-resilience</link>
                                                                            <description>
                            <![CDATA[ Public ownership cannot stop cyber threats; Britain needs shared intelligence, prioritized risks and coordinated resilience. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xEJFbFMZL3oxC8gS262oBg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5RYCUPY3MrRkUECQECzDC-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 18 Aug 2026 08:56:06 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jake Taylor ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5RYCUPY3MrRkUECQECzDC-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trojan horse on top of blocks of hexadecimal programming codes. 3D illustration of the concept of online hacking, computer spyware, malware and ransomware.]]></media:description>                                                            <media:text><![CDATA[Trojan horse on top of blocks of hexadecimal programming codes. 3D illustration of the concept of online hacking, computer spyware, malware and ransomware.]]></media:text>
                                <media:title type="plain"><![CDATA[Trojan horse on top of blocks of hexadecimal programming codes. 3D illustration of the concept of online hacking, computer spyware, malware and ransomware.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5RYCUPY3MrRkUECQECzDC-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The prospect of bringing more of Britain's critical national infrastructure into public ownership has prompted plenty of debate about investment, governance and accountability. </p><p>Far less attention has been paid to what it could mean for <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a>. </p><p>Regardless of where you stand politically, one thing is clear. Public ownership does not make cyber risk disappear. </p><p>If anything, it raises expectations that essential services will be more resilient, more coordinated and better prepared to withstand disruption.</p><p>That expectation reflects the reality of the threat landscape. Energy providers, water companies, transport operators and healthcare organizations all sit at the center of complex digital ecosystems. Their ability to deliver essential services depends on thousands of suppliers, technology vendors and third parties. </p><p>When one organization is compromised, the effects can spread well beyond its own network. Resilience therefore depends on far more than protecting individual organizations. It depends on understanding and managing the relationships between them.</p><p>If the government is serious about strengthening national infrastructure, cybersecurity must become part of that conversation from day one. That means moving beyond isolated <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> programs and towards a model where organizations share intelligence, understand common risks and coordinate their response before disruption spreads.</p><h2 id="critical-infrastructure-extends-beyond-organizational-boundaries">Critical infrastructure extends beyond organizational boundaries</h2><p>Some of the defining cyber attacks of recent years have demonstrated that attackers are rarely interested in a single target. They look for opportunities to compromise one organization in order to reach many others.</p><p>The SolarWinds attack remains one of the clearest examples. By compromising trusted software updates, attackers gained access to thousands of organizations around the world. More recently, the <a href="https://www.techradar.com/best/best-ransomware-protection">ransomware</a> attack on Synnovis disrupted pathology services across several NHS trusts, leading to cancelled operations, delayed appointments and widespread disruption to patient care. </p><p>Neither incident remained confined to the organization that was initially compromised. Both exposed the reality that critical infrastructure now depends on interconnected supply chains as much as physical assets.</p><p>That presents a challenge for every operator of critical national infrastructure. Security can no longer be viewed solely through the lens of protecting your own estate. Organizations also need visibility into the threats affecting suppliers, partners and the wider ecosystem. A vulnerability within a <a href="https://www.techradar.com/best/best-open-source-software">software</a> provider or outsourced service can quickly become a problem for every organization that depends on it.</p><p>This is where many existing security programs begin to show their limitations. Organizations have invested heavily in detection technologies, vulnerability management platforms and threat intelligence feeds. They are collecting more information than ever before. Yet many still struggle to translate that information into confident operational decisions.</p><h2 id="better-decisions-start-with-better-intelligence">Better decisions start with better intelligence</h2><p>The cybersecurity industry has spent years focusing on visibility. The assumption has been that if organizations can discover every vulnerability, identify every <a href="https://www.techradar.com/best/best-software-asset-management-tools">asset</a> and collect every threat feed, they will naturally become more secure.</p><p>The evidence suggests otherwise.</p><p>Filigran's recent State of Threat Management report found that organizations consume an average of fourteen different threat intelligence feeds, yet fewer than half have fully operationalized that intelligence across their security programs. </p><p>At the same time, 84% of respondents said the attacks they experience exploit risks that were already known but had not been prioritized. Almost every organization surveyed also reported difficulty determining whether identified exposures were genuinely exploitable.</p><p>Those findings illustrate a wider industry problem. The challenge is no longer discovering risk. It is deciding which risks deserve immediate attention.</p><p>Security teams are surrounded by alerts, vulnerability reports and intelligence updates. Every tool claims to identify another critical issue demanding urgent action. Without context, everything starts to look important. Analysts spend valuable time investigating vulnerabilities that may never be exploited while genuinely dangerous attack paths remain hidden among the noise. </p><p>That has consequences beyond operational efficiency. Every hour spent investigating a low priority issue is an hour that cannot be spent reducing real business risk. Organizations are not simply overwhelmed by the volume of information. They are overwhelmed by the number of decisions they are expected to make every day.</p><h2 id="threat-intelligence-should-shape-decisions-long-before-an-incident">Threat intelligence should shape decisions long before an incident</h2><p>One reason this happens is that threat intelligence is still too often treated as a function of the Security Operations Centre. Intelligence is gathered, analyzed and used to help detect or investigate malicious activity once attackers have already reached the network.</p><p>Yet, threat intelligence has far greater value when it informs decisions much earlier in the security lifecycle.</p><p>Used effectively, it should help organizations understand which vulnerabilities are actively being targeted, which attack paths present the greatest business risk and which remediation activities will deliver the greatest reduction in exposure. Rather than treating every vulnerability as equally urgent, security teams can focus on the threats that genuinely matter to their environment.</p><p>This is also where Continuous Threat Exposure Management, or CTEM, has an important role to play. CTEM should not be viewed as another technology category or another security acronym. It provides a structured framework for connecting threat intelligence, exposure management, validation and remediation into a continuous process. Instead of relying on assumptions or theoretical risk scores, organizations can validate whether a vulnerability is genuinely exploitable before committing time and resources to fixing it.</p><p>Perhaps the biggest obstacle is not technical at all. Many organizations still operate with threat intelligence, vulnerability management, penetration testing and governance teams working independently, each with different priorities, processes and tooling. Breaking down those silos often delivers greater improvements than introducing another security platform.</p><h2 id="building-a-national-capability">Building a national capability</h2><p>If critical infrastructure is expected to become more resilient, collaboration has to become part of everyday operations rather than something that only happens during a major incident. That thinking is already beginning to take shape. </p><p>Earlier this month, the National Cyber Security Centre and GCHQ issued a call for industry, academia and critical infrastructure operators to help define Cyber Shield, a proposed national cyber defense capability designed to combine AI, shared intelligence and coordinated defense at national scale. </p><p>Significantly, the initiative recognizes that the government cannot build this capability alone. It will depend on close collaboration with the organizations responsible for protecting the UK's essential services. </p><p>Additionally, the Cyber Security and Resilience Bill provides an opportunity to strengthen that approach by encouraging greater consistency across essential sectors. Frameworks such as the National Cyber Security Centre's Cyber Assessment Framework already give organizations a common language for measuring resilience. </p><p>They become even more valuable when they encourage organizations to learn from one another instead of tackling similar challenges in isolation.</p><p>Open standards have an important role to play as well. The Dutch National Cyber Security Centre recently made STIX and TAXII 2.1 the mandatory standard for sharing cyber threat intelligence across government. </p><p>While technical on the surface, the decision reflects a broader principle. When organizations exchange intelligence using common standards, they remove friction from collaboration and can respond to threats more quickly.</p><p>Technology alone will not deliver that outcome. Artificial intelligence, automation and modern security platforms can help organizations process more information and reduce manual effort, but they still depend on good intelligence, sound governance and trusted relationships. </p><p>For the simple reason that fast decisions only become good decisions when they are supported by the right context.</p><h2 id="resilience-is-a-shared-responsibility">Resilience is a shared responsibility</h2><p>Whether more of Britain's critical national infrastructure ultimately moves into public ownership is only part of the story. Cyber attackers do not distinguish between public and private organizations. They target weak links, trusted suppliers and interconnected systems wherever they find them.</p><p>The organizations that will be best prepared for the years ahead will be those that treat resilience as a collective responsibility. They will operationalize threat intelligence before incidents occur, validate real-world risk rather than relying on assumptions, and collaborate across organizational boundaries as readily as attackers do.</p><p>Protecting critical infrastructure has never been solely about defending individual organizations. It is about strengthening the entire ecosystem that keeps essential services running. If the UK wants to build genuinely resilient national infrastructure, that is where the conversation needs to begin.</p><p><a href="https://www.techradar.com/best/best-patch-management-tools"><em>We've listed the best path management software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Russian websites could soon be easy pickings for hackers as security certificates expire — banks, emails, and government systems all potentially at risk ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Japanese certificate authority GlobalSign revoked TLS certificates for thousands of Russian domains in June 2026 as it implemented US and EU sanctions</strong></li><li><strong>As a result, seven major Russian banks now serve certificates from a state root that no mainstream browser trusts, forcing users to manually install them</strong></li><li><strong>Ukraine's Foreign Intelligence Service says the losses turn Russian banking, email, and internal systems into easier targets</strong></li></ul><p>Russian companies are finding themselves in an extremely tricky situation as US OFAC and EU sanctions now affect international security certificates issued by third-party providers.</p><p>A statement <a href="https://szru.gov.ua/news-media/news/rosiyany-spalyat-miliony-rubliv-shchob-vidkryty-sait-vlasnoi-podatkovoi" target="_blank">issued by Ukraine's Foreign Intelligence Service</a> on August 12 said the certificate withdrawals essentially left the country's internal systems, email, and banking exposed to attack because no internationally recognized certificates were issued for their domains.</p><p>It noted Russian state services, including the Federal Tax Service, increasingly fail to load in Chrome, Firefox, and Safari, and estimated that roughly 90% of the Russian market still depends on foreign-issued certificates, and that wide implementation of these sanctions could make it harder for users to access affected sites.</p><div class="product"><a data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="web-trust-certificates-sanctioned-away">Web trust certificates sanctioned away?</h2><p>The move began on June 13 2026 when Japanese certificate authority GlobalSign, which controls much of Russia's commercial foreign certificate market, force-revoked TLS certificates it had previously issued to Russian companies.</p><p>Its local arm said that it could not influence the parent company's decision, which came due to new CA/Browser Forum rules, starting May 4. The rules effectively made screening applicants against the US OFAC and BIS lists, and European sanctions lists, mandatory for certificate authorities rather than optional, essentially tying the certificate provider's hands.</p><p>The move was implemented in two waves; the first affected an estimated 15,000-20,000 domains, and the second affected a more specific 310 domains across 44 companies, including large domestic names such as Rosneft, Gazprombank, Alrosa, and Positive Technologies.</p><p>The Ukrainian side insists that Russian internal systems, messengers, email, and banking APIs have become "ideal targets for hacker attacks," and there is some truth to it, even if mitigation is already underway on the Russian end. It estimates that reconfiguring infrastructure could cost larger corporations as much as 10 to 50 million rubles and take up to six months, and it is an error-prone process.</p><p>The move saw Russian domain owners, including its banks and tax services, turn elsewhere, with some moving first to a Greek academic certificate authority, HARICA, before turning to China's TrustAsia, which currently provides its state entities with certificates.</p><p>A more complicated play from the Russian end is a homegrown alternative the government continues pushing: <a href="https://www.techradar.com/news/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions" target="_blank">state-issued trust root certificates</a> that users must install manually. While the Ministry of Digital Development describes manual installation of its root certificate as "safe" and as having no effect on device function, <a href="https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/" target="_blank">security researchers have previously warned in 2022</a> and <a href="https://riposte.levelflow.org/2026/06/state-ssl/" target="_blank">again in 2026</a> that a state-controlled root could be abused for "HTTPS traffic interception and man-in-the-middle attacks".</p><p>Moscow's other recommendation is that users switch to Yandex Browser, which ships with the domestic root built in. Ukraine's narrative dismisses that as an alternative prone to freezing and cache failures and offering no meaningful data protection, an assessment it attributes to "experts inside Russia."</p><p>Whatever the short-term outcomes result in here for .RU domains, a move like this could further disconnect Russia from the rest of the world, with Russian services working smoothly only for users running Russian software with a state root installed. </p><p>This might already be the trajectory for a Russia reeling from cyberattacks and sanctions, but one can assume the certificate revocations will only compress the timeline to that point, whether by design or an unintended consequence.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/russian-websites-could-soon-be-easy-pickings-for-hackers-as-security-certificates-expire-banks-emails-and-government-systems-all-potentially-at-risk</link>
                                                                            <description>
                            <![CDATA[ Russia's websites lost their trusted certificates, and the fix Moscow is offering asks users to install a state root that can vouch for any site on the internet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">VksYNmo8goBbFDPCH35DfJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 19:35:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:30:18 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Japanese certificate authority GlobalSign revoked TLS certificates for thousands of Russian domains in June 2026 as it implemented US and EU sanctions</strong></li><li><strong>As a result, seven major Russian banks now serve certificates from a state root that no mainstream browser trusts, forcing users to manually install them</strong></li><li><strong>Ukraine's Foreign Intelligence Service says the losses turn Russian banking, email, and internal systems into easier targets</strong></li></ul><p>Russian companies are finding themselves in an extremely tricky situation as US OFAC and EU sanctions now affect international security certificates issued by third-party providers.</p><p>A statement <a href="https://szru.gov.ua/news-media/news/rosiyany-spalyat-miliony-rubliv-shchob-vidkryty-sait-vlasnoi-podatkovoi" target="_blank">issued by Ukraine's Foreign Intelligence Service</a> on August 12 said the certificate withdrawals essentially left the country's internal systems, email, and banking exposed to attack because no internationally recognized certificates were issued for their domains.</p><p>It noted Russian state services, including the Federal Tax Service, increasingly fail to load in Chrome, Firefox, and Safari, and estimated that roughly 90% of the Russian market still depends on foreign-issued certificates, and that wide implementation of these sanctions could make it harder for users to access affected sites.</p><div class="product"><a data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="f4664762-9b08-11f1-a4e4-9bf54b7953c4" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="web-trust-certificates-sanctioned-away">Web trust certificates sanctioned away?</h2><p>The move began on June 13 2026 when Japanese certificate authority GlobalSign, which controls much of Russia's commercial foreign certificate market, force-revoked TLS certificates it had previously issued to Russian companies.</p><p>Its local arm said that it could not influence the parent company's decision, which came due to new CA/Browser Forum rules, starting May 4. The rules effectively made screening applicants against the US OFAC and BIS lists, and European sanctions lists, mandatory for certificate authorities rather than optional, essentially tying the certificate provider's hands.</p><p>The move was implemented in two waves; the first affected an estimated 15,000-20,000 domains, and the second affected a more specific 310 domains across 44 companies, including large domestic names such as Rosneft, Gazprombank, Alrosa, and Positive Technologies.</p><p>The Ukrainian side insists that Russian internal systems, messengers, email, and banking APIs have become "ideal targets for hacker attacks," and there is some truth to it, even if mitigation is already underway on the Russian end. It estimates that reconfiguring infrastructure could cost larger corporations as much as 10 to 50 million rubles and take up to six months, and it is an error-prone process.</p><p>The move saw Russian domain owners, including its banks and tax services, turn elsewhere, with some moving first to a Greek academic certificate authority, HARICA, before turning to China's TrustAsia, which currently provides its state entities with certificates.</p><p>A more complicated play from the Russian end is a homegrown alternative the government continues pushing: <a href="https://www.techradar.com/news/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions" target="_blank">state-issued trust root certificates</a> that users must install manually. While the Ministry of Digital Development describes manual installation of its root certificate as "safe" and as having no effect on device function, <a href="https://www.bleepingcomputer.com/news/security/russia-creates-its-own-tls-certificate-authority-to-bypass-sanctions/" target="_blank">security researchers have previously warned in 2022</a> and <a href="https://riposte.levelflow.org/2026/06/state-ssl/" target="_blank">again in 2026</a> that a state-controlled root could be abused for "HTTPS traffic interception and man-in-the-middle attacks".</p><p>Moscow's other recommendation is that users switch to Yandex Browser, which ships with the domestic root built in. Ukraine's narrative dismisses that as an alternative prone to freezing and cache failures and offering no meaningful data protection, an assessment it attributes to "experts inside Russia."</p><p>Whatever the short-term outcomes result in here for .RU domains, a move like this could further disconnect Russia from the rest of the world, with Russian services working smoothly only for users running Russian software with a state root installed. </p><p>This might already be the trajectory for a Russia reeling from cyberattacks and sanctions, but one can assume the certificate revocations will only compress the timeline to that point, whether by design or an unintended consequence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware gang crashes own attack — with no-one to blame but themselves ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Akira ransomware tried Safe Mode boot to disable defenses but broke its own encryptor</strong></li><li><strong>Defender later flagged and quarantined payload, leaving attackers with only stolen data</strong></li><li><strong>Huntress advises VPN brute‑force alerts, MFA, SIEM logging, and Safe Mode monitoring</strong></li></ul><p>A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive data, albeit limping.</p><p>Akira is a well-known <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group, considered one of the most active cybercriminal organizations on the internet. Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor.</p><p>With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information.</p><p>However, in a recent attack, they tried to first disable the device’s antivirus and endpoint detection and response (EDR) solutions. The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor. </p><div class="product"><a data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="the-good-and-the-bad-of-safe-mode-with-networking">The good and the bad of Safe Mode with Networking</h2><p>A new report published by security researchers <a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr" target="_blank">Huntress</a> said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking. This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents. At the same time, it grants internet access which, for Akira, is the perfect combination.</p><p>“This means Defender real-time protection was down too,” Akira explained. “For the entire Safe Mode window, the host had no working EDR, and AV was blinded. This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years. However, this is the first time we have seen Akira use it.”</p><p>What Akira didn’t bank on was Safe Mode with Networking also preventing its encryptor from running. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.”</p><p>The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it. </p><p>“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defense you can plan around,” Huntress warned, stressing that not every victim might get such a lucky break.</p><p>“Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akira's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”</p><h2 id="how-to-defend-against-akira-ransomware">How to defend against Akira ransomware</h2><p>To defend against Akira, Huntress recommends users set up alerts on bursts of failed VPN logins against multiple usernames from one source. It works well because Akira starts its breach with a brute-force attack against the VPN. It also says users should correlate those failures with a successful login from the same IP or ASN within a short window.</p><p>The second step is to turn on multi-factor authentication (<a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>) on every VPN account. Users should also disable or IP-allowlist the SSL VPN during active attacks and, if compromised, rotate all AD and VPN credentials. “Treat everything in that Get-ADUser dump as exposed,” the researchers warn.</p><p>EDR should be deployed to every host, as well as SIEM and ingest VPN + Windows Event Logs. “The first VPN logons were visible hours before any detonation—this time advantage is only possible if the logs are on SIEM.”</p><p>Finally, users can set up alerts on boot-configuration changes and Safe Mode boots, to catch Akira red handed. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/ransomware-gang-crashes-own-attack-with-no-one-to-blame-but-themselves</link>
                                                                            <description>
                            <![CDATA[ In a new attack, Akira disables EDR tools, but kills the encryptor, as well, as researchers still warn of a worrying practice. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S9XN4Dopx2hurqZaBZ8g2k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 16:15:00 +0000</pubDate>                                                                                                                                <updated>Tue, 18 Aug 2026 13:30:49 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Akira ransomware tried Safe Mode boot to disable defenses but broke its own encryptor</strong></li><li><strong>Defender later flagged and quarantined payload, leaving attackers with only stolen data</strong></li><li><strong>Huntress advises VPN brute‑force alerts, MFA, SIEM logging, and Safe Mode monitoring</strong></li></ul><p>A recent ransomware attack saw the operators Akira (figuratively) shoot themselves in the foot - and they still walked away with sensitive data, albeit limping.</p><p>Akira is a well-known <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> group, considered one of the most active cybercriminal organizations on the internet. Its modus operandi is simple in theory: they look for an exposed VPN instance (for example, one with a default or weak password), access the domain controller, enumerate Active Directory, steal sensitive data, and deploy an encryptor.</p><p>With the encryptor they leave a ransom note, instructing the victim to reach out and negotiate a payment in exchange for the decryption key and for deleting the stolen documents and information.</p><p>However, in a recent attack, they tried to first disable the device’s antivirus and endpoint detection and response (EDR) solutions. The process backfired, resulting in the security solutions successfully spotting and quarantining the encryptor. </p><div class="product"><a data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><strong><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">Threat Exposure Platform: at NordStellar</a></strong><br><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="0693e444-9b09-11f1-a97e-b36957f61fe6" data-action="Deal Block" data-label="Threat Exposure Platform" data-dimension48="Threat Exposure Platform" data-dimension25="">View Deal</a></p></div><h2 id="the-good-and-the-bad-of-safe-mode-with-networking">The good and the bad of Safe Mode with Networking</h2><p>A new report published by security researchers <a href="https://www.huntress.com/blog/akira-hits-safe-mode-ransomware-rebooting-around-edr" target="_blank">Huntress</a> said that after establishing persistence on a device, Akira rebooted it into Safe Mode with Networking. This Windows startup mode boots the OS with only the essential drivers and services, excluding important components such as antivirus programs or EDR agents. At the same time, it grants internet access which, for Akira, is the perfect combination.</p><p>“This means Defender real-time protection was down too,” Akira explained. “For the entire Safe Mode window, the host had no working EDR, and AV was blinded. This is MITRE ATT&CK T1688: Impair Defenses: Safe Mode Boot, a technique that ransomware families like Snatch and AvosLocker have used for years. However, this is the first time we have seen Akira use it.”</p><p>What Akira didn’t bank on was Safe Mode with Networking also preventing its encryptor from running. “Safe Mode boots with a stripped-down environment and constrained virtual memory, and the Akira process tree appears to have starved it, getting the "Out of Virtual Memory" pop-up and the cascade of PowerShell hard errors line up exactly with the moment the payload tried to kick things off.”</p><p>The operators had no other choice but to boot the device back up normally, at which point a scheduled Defender scan detected the encryptor, flagged it, and ultimately quarantined it. </p><p>“The takeaway is a little uncomfortable. While Safe Mode blinded our controls, it may also have prevented the encryption it was meant to enable. That's a lucky side effect of the attacker's own mistake in these circumstances, not a defense you can plan around,” Huntress warned, stressing that not every victim might get such a lucky break.</p><p>“Ultimately, this could be a case of winning the battle, but not the war. It's possible that a host with more physical memory or a larger page file might give akira.exe enough virtual memory to encrypt the endpoint in Safe Mode. Akira's developers or affiliates could retool the encryptor to reduce its memory demands or make its Safe Mode launch sequence more reliable, meaning that the same failure may not occur in a future intrusion.”</p><h2 id="how-to-defend-against-akira-ransomware">How to defend against Akira ransomware</h2><p>To defend against Akira, Huntress recommends users set up alerts on bursts of failed VPN logins against multiple usernames from one source. It works well because Akira starts its breach with a brute-force attack against the VPN. It also says users should correlate those failures with a successful login from the same IP or ASN within a short window.</p><p>The second step is to turn on multi-factor authentication (<a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>) on every VPN account. Users should also disable or IP-allowlist the SSL VPN during active attacks and, if compromised, rotate all AD and VPN credentials. “Treat everything in that Get-ADUser dump as exposed,” the researchers warn.</p><p>EDR should be deployed to every host, as well as SIEM and ingest VPN + Windows Event Logs. “The first VPN logons were visible hours before any detonation—this time advantage is only possible if the logs are on SIEM.”</p><p>Finally, users can set up alerts on boot-configuration changes and Safe Mode boots, to catch Akira red handed. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ MacOS users warned to beware screen-sharing bug which can turn Macs into cryptomining slaves ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure</strong></li><li><strong>Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig</strong></li><li><strong>Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately</strong></li></ul><p>Less than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.</p><p>Alfredo Pesoli, a security researcher from Bynario, discovered an authentication issue in macOS Screen Sharing and reported it to Apple. Screen Sharing is a built-in macOS tool that allows users to remotely connect, and use, another Mac device. It is similar to third-party tools such as AnyDesk or TeamViewer and comes in rather handy for IT teams accessing Macs stored in closets or used by remote and home-working employees.</p><p>The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials. It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.</p><h2 id="the-netherlands-issue-a-warning">The Netherlands issue a warning</h2><p>Soon after disclosure, Apple released an out-of-bound fix, signaling that this is, indeed, a dangerous vulnerability. “Apple does not ship an update out of band unless something is critical,” security researchers Calif said in their <a href="https://blog.calif.io/p/no-country-for-old-passwords" target="_blank" rel="nofollow">technical writeup</a>. The National Vulnerability Database (NVD) assigned it an identifier - CVE-2026-65400 - and gave it a severity rating of 9.6/10 (critical). </p><p>Approximately at the same time the patch was released, the flaw was also showcased at the 2026 Black Hat conference, with a video demonstration was made public a few days later.</p><p>Apple said it fixed it with improved state management, addressing the bug in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1.</p><p>Now, less than a week after the disclosure, researchers are saying the bug is being leveraged in actual cyberattacks, with Dutch security officials being first to react</p><p>“The NCSC has received a report showing that active abuse of this vulnerability has been observed on several systems on which port 5900 was accessible from the internet,” the Netherlands National Cyber Security Centrum (NCSC) said in a machine-translated report. “In all these cases, root access was gained on the affected system and a Monero crypto miner was placed.”</p><h2 id="why-monero">Why Monero?</h2><p>Monero is considered an “altcoin” - a cryptocurrency built as an alternative to Bitcoin. It is one of the oldest active altcoins out there, having been launched more than 12 years ago. Most cryptocurrencies rarely live through a single four-year bitcoin cycle but Monero, just like Ethereum, Litecoin, Solana, and a handful of others, endures.</p><p>It is similar to Bitcoin because it, too, can be “mined” (unlike Ethereum, for example). It differs on the privacy front. Unlike Bitcoin, whose transactions are recorded on a public ledger and can often be traced, Monero is designed to obscure the sender, recipient, and the amount of transactions. This privacy feature has, unfortunately, also attracted criminals.</p><p>Another key feature that made crooks choose Monero for their <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">cryptojackers</a> is the fact that the altcoin uses a proof-of-work (mining) algorithm optimized for general-purpose CPUs, making mining relatively profitable on ordinary servers, desktops, and cloud machines. </p><p>Although it was not specifically stated, it is safe to assume that in this incident, the attackers were deploying XMRig. It is, by far, the most popular cryptojacker and one that mines primarily Monero (its ticker is XMR).</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The best way to go about it is to install the patch Apple just released. This effectively plugs the hole and makes the device secure. Those who are unable to deploy the patch immediately should block Screen Sharing and enable it only when it is actually needed and used. To do that, users can go to System Settings > General > Sharing and toggle the Screen Sharing switch off. </p><p>Finally, it is worth mentioning that the NCSC stressed the crooks could only exploit the flaw when the target device’s port 5900 is exposed to the internet. Therefore, setting routers and firewalls to block the port can also work, although we’d only recommend it as a last resort. Installing the patch is still the best way to go. </p><p>Right now, no groups claimed responsibility for this attack, and there is no evidence it is being used for anything else. In theory, though, it can also be used for data exfiltration, malware deployment, and possibly even ransomware attacks. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/macos-users-warned-to-beware-screen-sharing-bug-which-can-turn-macs-into-cryptomining-slaves</link>
                                                                            <description>
                            <![CDATA[ Apple patched a critical-severity flaw in Screen Sharing which allowed crooks unabated access to vulnerable devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GNymd9yeKgRVNJ8phk4pgn</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Far Chinberdiev / Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple Mac Pro on a desk.]]></media:description>                                                            <media:text><![CDATA[The Apple Mac Pro on a desk.]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple Mac Pro on a desk.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5HfdStguEjjwWA3HyeKfCZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CVE‑2026‑65400 macOS Screen Sharing flaw exploited for cryptojacking within days of disclosure</strong></li><li><strong>Attackers gained root via exposed port 5900 and deployed Monero miners using XMRig</strong></li><li><strong>Apple patched in Sequoia 15.7.9, Sonoma 14.8.9, Tahoe 26.6.1; users urged to update immediately</strong></li></ul><p>Less than a week after being publicly disclosed, a macOS vulnerability plaguing Screen Sharing was observed as being used in cryptojacking attacks.</p><p>Alfredo Pesoli, a security researcher from Bynario, discovered an authentication issue in macOS Screen Sharing and reported it to Apple. Screen Sharing is a built-in macOS tool that allows users to remotely connect, and use, another Mac device. It is similar to third-party tools such as AnyDesk or TeamViewer and comes in rather handy for IT teams accessing Macs stored in closets or used by remote and home-working employees.</p><p>The bug allows a remote attacker to bypass authentication and gain access to a vulnerable Mac device without valid credentials. It apparently stems from a logic issue in the Screen Sharing server’s authentication process, affecting systems where the service is exposed to the internet.</p><h2 id="the-netherlands-issue-a-warning">The Netherlands issue a warning</h2><p>Soon after disclosure, Apple released an out-of-bound fix, signaling that this is, indeed, a dangerous vulnerability. “Apple does not ship an update out of band unless something is critical,” security researchers Calif said in their <a href="https://blog.calif.io/p/no-country-for-old-passwords" target="_blank" rel="nofollow">technical writeup</a>. The National Vulnerability Database (NVD) assigned it an identifier - CVE-2026-65400 - and gave it a severity rating of 9.6/10 (critical). </p><p>Approximately at the same time the patch was released, the flaw was also showcased at the 2026 Black Hat conference, with a video demonstration was made public a few days later.</p><p>Apple said it fixed it with improved state management, addressing the bug in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1.</p><p>Now, less than a week after the disclosure, researchers are saying the bug is being leveraged in actual cyberattacks, with Dutch security officials being first to react</p><p>“The NCSC has received a report showing that active abuse of this vulnerability has been observed on several systems on which port 5900 was accessible from the internet,” the Netherlands National Cyber Security Centrum (NCSC) said in a machine-translated report. “In all these cases, root access was gained on the affected system and a Monero crypto miner was placed.”</p><h2 id="why-monero">Why Monero?</h2><p>Monero is considered an “altcoin” - a cryptocurrency built as an alternative to Bitcoin. It is one of the oldest active altcoins out there, having been launched more than 12 years ago. Most cryptocurrencies rarely live through a single four-year bitcoin cycle but Monero, just like Ethereum, Litecoin, Solana, and a handful of others, endures.</p><p>It is similar to Bitcoin because it, too, can be “mined” (unlike Ethereum, for example). It differs on the privacy front. Unlike Bitcoin, whose transactions are recorded on a public ledger and can often be traced, Monero is designed to obscure the sender, recipient, and the amount of transactions. This privacy feature has, unfortunately, also attracted criminals.</p><p>Another key feature that made crooks choose Monero for their <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">cryptojackers</a> is the fact that the altcoin uses a proof-of-work (mining) algorithm optimized for general-purpose CPUs, making mining relatively profitable on ordinary servers, desktops, and cloud machines. </p><p>Although it was not specifically stated, it is safe to assume that in this incident, the attackers were deploying XMRig. It is, by far, the most popular cryptojacker and one that mines primarily Monero (its ticker is XMR).</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>The best way to go about it is to install the patch Apple just released. This effectively plugs the hole and makes the device secure. Those who are unable to deploy the patch immediately should block Screen Sharing and enable it only when it is actually needed and used. To do that, users can go to System Settings > General > Sharing and toggle the Screen Sharing switch off. </p><p>Finally, it is worth mentioning that the NCSC stressed the crooks could only exploit the flaw when the target device’s port 5900 is exposed to the internet. Therefore, setting routers and firewalls to block the port can also work, although we’d only recommend it as a last resort. Installing the patch is still the best way to go. </p><p>Right now, no groups claimed responsibility for this attack, and there is no evidence it is being used for anything else. In theory, though, it can also be used for data exfiltration, malware deployment, and possibly even ransomware attacks. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The internet is becoming more stressful and unlikeable — with AI slop and data leaks to blame ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>An Incogni survey has found people are becoming more frustrated with the internet</strong></li><li><strong>Users cite AI slop and data leaks as the main reasons for stress and anxiety when using the internet</strong></li><li><strong>Many users want to spend less time online, and are deleting social media profiles and messaging</strong></li></ul><p>For years, personal data collection for advertising, tracking, and service improvement was thought to be the fair price to pay to access the world wide web. But now, many people believe that using the internet will lead to their data being leaked or exposed.</p><p>A new <a href="https://blog.incogni.com/attitudes-toward-internet-stressed-exposed/" target="_blank" rel="nofollow">Incogni survey</a> found more than half of internet users believe their personal data will inevitably be exposed, with 63% stating that this fear causes anxiety when using the internet.</p><p>But beyond this, internet users now fear they can no longer tell what is real content uploaded by a human and what is AI generated, not only eroding trust in the internet, but also making people not want to use the internet at all. Almost half of internet users are less sure of what is real on the internet.</p><h2 id="inevitable-data-exposure">Inevitable data exposure</h2><p>You’ve likely been prompted thousands of times to accept or reject cookies, or review a privacy policy before using a website. Every cookie you accept will collect data on your browsing habits and behavior on sites in order to display personalized adverts that you are more likely to click. Cookies also help keep you logged in and store your information on websites.</p><p>While this helps make many websites across the web free to use for those accessing them, sometimes your data is sold to advertisers or third-parties where it is stored insecurely, and <a href="https://www.techradar.com/pro/security/stolen-session-cookies-render-mfa-irrelevant-how-usd900-per-month-turnkey-malware-is-putting-enterprise-grade-account-hijacking-in-the-hands-of-rookie-hackers" target="_blank">can be stolen or leaked</a>.</p><p>Among the 1,000 internet users surveyed, the fear of data exposure was strongest among the Millennials and Gen X generations. 56% of Gen X and 55% of Millennials believed that their data would at some point be breached or exposed, showing just how normal data breaches and exposure have become online.</p><p>Just 11% of those surveyed believed there was little likelihood of their data being breached.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="BdfP8Jxppb8qhTMGtD7v9j" name="more_than_50_of_respondents_believe_that_their_data_is_bound_to_be_breached" alt="A graph showing internet user opinions on how likely their data is to be leaked online." src="https://cdn.mos.cms.futurecdn.net/BdfP8Jxppb8qhTMGtD7v9j.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><h2 id="ai-is-making-the-internet-less-real">AI is making the internet less real</h2><p>AI content creation has exploded in recent years. Social media sites are full of AI ‘creators’ whose pages either share AI generated content or scrape the internet for content that users are likely to interact with, and share it through their own pages. These profiles require little human input, but can share content at an industrial scale and reap huge rewards from advertisers.</p><p>If you’ve been on Instagram lately, you may have seen videos from AI creators all sharing the same captions. “Tonight, V stepped into the crowd..” or “Japan is transforming footsteps into electricity.” These captions use keywords to abuse Instagram’s algorithm on popular topics to drive engagement, regardless of whether the content actually has anything to do with the caption.</p><p>But they’re also making it harder to know what is real on the internet.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:86.23%;"><img id="Scf358baJc5KPcBAWuaJP3" name="majority_of_respondents_highlight_negative_aspects_of_ai_proliferation" alt="A graph showing the opinions of internet users on AI generated content" src="https://cdn.mos.cms.futurecdn.net/Scf358baJc5KPcBAWuaJP3.jpg" mos="" align="middle" fullscreen="" width="1024" height="883" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>48% of those surveyed said that they are less sure of what’s real, with 40% also stating that the lack of accountability for deepfake creators was a bother. </p><p>Additionally, 27% said that AI generated content made them want to spend less time online, with 16% also saying that navigating an internet full of low quality AI content made them feel more tired or fatigued. Just 8% of respondents said that AI generated content improved their online experience.</p><p>There are some positive attitudes to AI content online. 12% said that AI-generated content made information more accessible, with slightly less (11%) saying that they were excited about the creative possibilities AI offers.</p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-eEqjge"></div>                            </div>                            <script src="https://kwizly.com/embed/eEqjge.js" async></script><h2 id="time-to-go-offline">Time to go offline?</h2><p>Attitudes to how long people spend online are also changing. Over half (51%) of Gen Z internet users believe they spend too much time on consuming content on the internet, with 43% of Millennials and 42% of Gen X respondents having a likeminded view.</p><p>Whether it’s responding to emails, navigating networking platforms, finding new furniture, or looking for where to go to eat - the internet is now a life requirement for most people. And every time you access another website in work or your personal life, there is more data that could be leaked.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:50.10%;"><img id="bKNqbbh5Xk5WGih8KJEY58" name="almost_half_of_respondents_believe_they_spend_too_much_time_online" alt="A graph showing opinions on whether internet users spend too much time online" src="https://cdn.mos.cms.futurecdn.net/bKNqbbh5Xk5WGih8KJEY58.jpg" mos="" align="middle" fullscreen="" width="1024" height="513" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>The ultimate effect of this is that people are being driven away from using the internet. 58% of respondents said that they had deleted a social media account or messaging app because of stress, anxiety, or privacy concerns. </p><p>“It seems that the costs of engaging with these platforms are starting to outweigh any perceived or actual benefits,” the Incogni survey said.</p><h2 id="or-time-to-pay-for-privacy">Or time to pay for privacy?</h2><p>Incogni also asked if users would be willing to pay for an internet where tracking and algorithms did not exist. 30% of respondents said they would, but this largely relied on income. Those with a higher income were more likely to pay for this ‘private’ internet, while those with a lower income were less likely.</p><p>For many internet users, privacy shouldn’t be a luxury, but a guarantee. There is a level of trust involved when sharing personal data with advertisers, and the expectation is that the data won’t be leaked or stolen. Unfortunately, the opinions show that this is far from what's expected.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="GzytHWP7DeEspVa7QgtqPD" name="fewer_than_30_of_respondents_would_pay_for_an_internet_with_no_tracking_or_algorithmic_feeds" alt="A graph showing if internet users would pay for an internet without tracking or algorithmic feeds" src="https://cdn.mos.cms.futurecdn.net/GzytHWP7DeEspVa7QgtqPD.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/the-internet-is-becoming-more-stressful-and-unlikeable-with-ai-slop-and-data-leaks-to-blame</link>
                                                                            <description>
                            <![CDATA[ AI content and data leaks are driving people away from the internet, with some people willing to pay for an internet without algorithms or data harvesting. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5VpX2PdN4zGpVbwe7CEvnX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 13:08:34 +0000</pubDate>                                                                                                                                <updated>Mon, 17 Aug 2026 13:08:39 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Browsers]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images/Tatiana Maksimova]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:description>                                                            <media:text><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:text>
                                <media:title type="plain"><![CDATA[Female hands typing on a laptop in neon light. A lock as a symbol of cybersecurity on a foreground.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HU8VZ2jkrVAHBpb3Aqqg8j-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>An Incogni survey has found people are becoming more frustrated with the internet</strong></li><li><strong>Users cite AI slop and data leaks as the main reasons for stress and anxiety when using the internet</strong></li><li><strong>Many users want to spend less time online, and are deleting social media profiles and messaging</strong></li></ul><p>For years, personal data collection for advertising, tracking, and service improvement was thought to be the fair price to pay to access the world wide web. But now, many people believe that using the internet will lead to their data being leaked or exposed.</p><p>A new <a href="https://blog.incogni.com/attitudes-toward-internet-stressed-exposed/" target="_blank" rel="nofollow">Incogni survey</a> found more than half of internet users believe their personal data will inevitably be exposed, with 63% stating that this fear causes anxiety when using the internet.</p><p>But beyond this, internet users now fear they can no longer tell what is real content uploaded by a human and what is AI generated, not only eroding trust in the internet, but also making people not want to use the internet at all. Almost half of internet users are less sure of what is real on the internet.</p><h2 id="inevitable-data-exposure">Inevitable data exposure</h2><p>You’ve likely been prompted thousands of times to accept or reject cookies, or review a privacy policy before using a website. Every cookie you accept will collect data on your browsing habits and behavior on sites in order to display personalized adverts that you are more likely to click. Cookies also help keep you logged in and store your information on websites.</p><p>While this helps make many websites across the web free to use for those accessing them, sometimes your data is sold to advertisers or third-parties where it is stored insecurely, and <a href="https://www.techradar.com/pro/security/stolen-session-cookies-render-mfa-irrelevant-how-usd900-per-month-turnkey-malware-is-putting-enterprise-grade-account-hijacking-in-the-hands-of-rookie-hackers" target="_blank">can be stolen or leaked</a>.</p><p>Among the 1,000 internet users surveyed, the fear of data exposure was strongest among the Millennials and Gen X generations. 56% of Gen X and 55% of Millennials believed that their data would at some point be breached or exposed, showing just how normal data breaches and exposure have become online.</p><p>Just 11% of those surveyed believed there was little likelihood of their data being breached.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="BdfP8Jxppb8qhTMGtD7v9j" name="more_than_50_of_respondents_believe_that_their_data_is_bound_to_be_breached" alt="A graph showing internet user opinions on how likely their data is to be leaked online." src="https://cdn.mos.cms.futurecdn.net/BdfP8Jxppb8qhTMGtD7v9j.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><h2 id="ai-is-making-the-internet-less-real">AI is making the internet less real</h2><p>AI content creation has exploded in recent years. Social media sites are full of AI ‘creators’ whose pages either share AI generated content or scrape the internet for content that users are likely to interact with, and share it through their own pages. These profiles require little human input, but can share content at an industrial scale and reap huge rewards from advertisers.</p><p>If you’ve been on Instagram lately, you may have seen videos from AI creators all sharing the same captions. “Tonight, V stepped into the crowd..” or “Japan is transforming footsteps into electricity.” These captions use keywords to abuse Instagram’s algorithm on popular topics to drive engagement, regardless of whether the content actually has anything to do with the caption.</p><p>But they’re also making it harder to know what is real on the internet.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:86.23%;"><img id="Scf358baJc5KPcBAWuaJP3" name="majority_of_respondents_highlight_negative_aspects_of_ai_proliferation" alt="A graph showing the opinions of internet users on AI generated content" src="https://cdn.mos.cms.futurecdn.net/Scf358baJc5KPcBAWuaJP3.jpg" mos="" align="middle" fullscreen="" width="1024" height="883" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>48% of those surveyed said that they are less sure of what’s real, with 40% also stating that the lack of accountability for deepfake creators was a bother. </p><p>Additionally, 27% said that AI generated content made them want to spend less time online, with 16% also saying that navigating an internet full of low quality AI content made them feel more tired or fatigued. Just 8% of respondents said that AI generated content improved their online experience.</p><p>There are some positive attitudes to AI content online. 12% said that AI-generated content made information more accessible, with slightly less (11%) saying that they were excited about the creative possibilities AI offers.</p><div style="min-height: 250px;">                                <div class="kwizly-quiz kwizly-eEqjge"></div>                            </div>                            <script src="https://kwizly.com/embed/eEqjge.js" async></script><h2 id="time-to-go-offline">Time to go offline?</h2><p>Attitudes to how long people spend online are also changing. Over half (51%) of Gen Z internet users believe they spend too much time on consuming content on the internet, with 43% of Millennials and 42% of Gen X respondents having a likeminded view.</p><p>Whether it’s responding to emails, navigating networking platforms, finding new furniture, or looking for where to go to eat - the internet is now a life requirement for most people. And every time you access another website in work or your personal life, there is more data that could be leaked.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:50.10%;"><img id="bKNqbbh5Xk5WGih8KJEY58" name="almost_half_of_respondents_believe_they_spend_too_much_time_online" alt="A graph showing opinions on whether internet users spend too much time online" src="https://cdn.mos.cms.futurecdn.net/bKNqbbh5Xk5WGih8KJEY58.jpg" mos="" align="middle" fullscreen="" width="1024" height="513" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure><p>The ultimate effect of this is that people are being driven away from using the internet. 58% of respondents said that they had deleted a social media account or messaging app because of stress, anxiety, or privacy concerns. </p><p>“It seems that the costs of engaging with these platforms are starting to outweigh any perceived or actual benefits,” the Incogni survey said.</p><h2 id="or-time-to-pay-for-privacy">Or time to pay for privacy?</h2><p>Incogni also asked if users would be willing to pay for an internet where tracking and algorithms did not exist. 30% of respondents said they would, but this largely relied on income. Those with a higher income were more likely to pay for this ‘private’ internet, while those with a lower income were less likely.</p><p>For many internet users, privacy shouldn’t be a luxury, but a guarantee. There is a level of trust involved when sharing personal data with advertisers, and the expectation is that the data won’t be leaked or stolen. Unfortunately, the opinions show that this is far from what's expected.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1024px;"><p class="vanilla-image-block" style="padding-top:60.35%;"><img id="GzytHWP7DeEspVa7QgtqPD" name="fewer_than_30_of_respondents_would_pay_for_an_internet_with_no_tracking_or_algorithmic_feeds" alt="A graph showing if internet users would pay for an internet without tracking or algorithmic feeds" src="https://cdn.mos.cms.futurecdn.net/GzytHWP7DeEspVa7QgtqPD.jpg" mos="" align="middle" fullscreen="" width="1024" height="618" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Incogni)</span></figcaption></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Tokenmaxxing: Why AI consumption needs control ]]></title>
                                                                                                <dc:content><![CDATA[ <p>AI spend made headlines again recently with the Claude Fable 5 model from Anthropic. Before <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> concerns led to the model being suspended, there were also cost concerns. Anthropic says Fable costs $10 or approximately €9 per million input tokens and $50 per million output tokens. This is double the price of the company’s previously most expensive model, Claude Opus 4.8.</p><p>Posts soon began to pop up on LinkedIn, showing just how quickly teams were going through their tokens and, as a result, their budget. There are some caveats here. Namely, that Fable 5 is an advanced model and, for most <a href="https://www.techradar.com/best/best-small-business-phone-systems">businesses</a>, won’t need to run non-stop or be used for every task.</p><p>But therein lies a key issue: AI use is accelerating and models are evolving. But the level of control and visibility businesses have over how much is being spent, by who and for what is lagging behind.</p><h2 id="how-ai-consumption-became-a-finance-problem">How AI consumption became a finance problem </h2><p>There is a massive shift within the UK software market toward AI and specifically Anthropic’s ecosystem. Proprietary data from Pleo looking at the top tech merchants based on number of spending customers, shows that Anthropic (Claude) surged from 12th place in Q4 2025 to 7th in Q1 2026. Meanwhile, the average spend per customer increased +43.0% in this time.</p><p>This rapid climb signals that Anthropic has reached enterprise maturity in the UK market with businesses moving beyond the experimentation phase. But while this reflects growing confidence in AI adoption, it also presents some financial challenges.</p><p>On the whole, AI has redefined how the workplace runs, but it is not a free trial. The cost of tokens has gone up, and new models that can achieve what was seemingly unthinkable a few years ago come with a price tag to match. The new challenge for business leaders is to leverage these technologies but also limit rampant spending.  </p><p>This is why many organizations are turning to their <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a> teams. Finance has the visibility to dig into the details and map AI use across the organization, whether it quietly shows up as a subscription renewal or a new budget request. But more than that, they can be instrumental in ensuring teams embrace open conversations, not just OpenAI. </p><h2 id="ai-activity-does-not-translate-to-ai-value">AI activity does not translate to AI value</h2><p>Just about every organization will have developed transformational ways of using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. But, whether they know it or not, there will be wasteful ones too.</p><p>When it comes to inefficient use, some of the major culprits include asking AI agents open-ended questions, model mismatch where tokens are burned unnecessarily; and duplicate tools, resulting from shadow AI and overlapping subscriptions. These prevent businesses from seeing the full picture; one that is, in all probability, very expensive. </p><p>User literacy can improve this. But for finance teams they must start with the grey area of AI consumption. Two teams might show as active AI users, but one that’s using an LLM to produce more content faster is doing something fundamentally different to one that’s using it for peripheral <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> tasks. In fact, only 29% of European SMEs using Gen AI are doing so in core business activities.</p><p>To improve the control they have over AI, organizations must start by elevating their visibility from who is using AI, to who is using it to become smarter, faster and more productive.  </p><h2 id="how-to-regain-control-over-ai-use">How to regain control over AI use</h2><p>A complete view of AI spend is essential, regardless of whether costs are rising.   </p><p>Breaking spend down by department, team and budget helps identify both disproportionate usage and areas where adoption may be lagging. These should be combined with performance metrics such as the time-to-first-draft on marketing content; code review cycle times in engineering; support ticket resolution time in customer support; and so on.</p><p>This combination of spend and performance can reveal whether AI investment is translating into measurable productivity gains and not just higher <a href="https://www.techradar.com/best/best-small-business-software">software</a> costs.</p><p>Visibility should also extend to model-level usage. As mentioned before, the cost difference between frontier reasoning models and lighter alternatives can be tenfold. Monitoring model and vendor usage alongside token consumption helps organizations route routine tasks to lower-cost options, maximize ROI and reduce unnecessary spend. </p><p>Finance teams should therefore expand reporting and budgeting frameworks to include AI-specific metrics. A key question at month-end is whether AI-enabled teams are increasing output and capacity without increasing headcount. This provides a clear headline for AI's impact, can justify investment and distinguish between high-value and low-value AI usage. </p><p>Ultimately, effective control over AI is not about costs alone. It is about understanding where AI is creating value and ensuring investment is aligned with <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> outcomes.</p><h2 id="ai-control-is-at-your-fingertips">AI control is at your fingertips</h2><p>The good news is that none of these metrics require a sophisticated AI analytics stack. Finance teams should already have the tools for real-time visibility into what’s being spent and where. All that’s needed now is to fold AI into the mix and collaborate with other departments to measure and improve its ROI.</p><p>The outcome is that organizations control AI use through oversight, without restricting spend, adoption or innovation through lengthy procurement processes. Spend policies, category controls and clear approval thresholds control what is spent, and everything is measured.</p><p>But crucially, teams don’t slow down as a result. The only difference is that AI is optimized for impact.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/tokenmaxxing-why-ai-consumption-needs-control</link>
                                                                            <description>
                            <![CDATA[ Finance teams aren't trying to stop AI investment – they want to maximise its impact ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hcyzexFFxWpsNFQSDUDure</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 09:47:05 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Marija Nakevska ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:description>                                                            <media:text><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:text>
                                <media:title type="plain"><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>AI spend made headlines again recently with the Claude Fable 5 model from Anthropic. Before <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> concerns led to the model being suspended, there were also cost concerns. Anthropic says Fable costs $10 or approximately €9 per million input tokens and $50 per million output tokens. This is double the price of the company’s previously most expensive model, Claude Opus 4.8.</p><p>Posts soon began to pop up on LinkedIn, showing just how quickly teams were going through their tokens and, as a result, their budget. There are some caveats here. Namely, that Fable 5 is an advanced model and, for most <a href="https://www.techradar.com/best/best-small-business-phone-systems">businesses</a>, won’t need to run non-stop or be used for every task.</p><p>But therein lies a key issue: AI use is accelerating and models are evolving. But the level of control and visibility businesses have over how much is being spent, by who and for what is lagging behind.</p><h2 id="how-ai-consumption-became-a-finance-problem">How AI consumption became a finance problem </h2><p>There is a massive shift within the UK software market toward AI and specifically Anthropic’s ecosystem. Proprietary data from Pleo looking at the top tech merchants based on number of spending customers, shows that Anthropic (Claude) surged from 12th place in Q4 2025 to 7th in Q1 2026. Meanwhile, the average spend per customer increased +43.0% in this time.</p><p>This rapid climb signals that Anthropic has reached enterprise maturity in the UK market with businesses moving beyond the experimentation phase. But while this reflects growing confidence in AI adoption, it also presents some financial challenges.</p><p>On the whole, AI has redefined how the workplace runs, but it is not a free trial. The cost of tokens has gone up, and new models that can achieve what was seemingly unthinkable a few years ago come with a price tag to match. The new challenge for business leaders is to leverage these technologies but also limit rampant spending.  </p><p>This is why many organizations are turning to their <a href="https://www.techradar.com/best/best-personal-finance-software">finance</a> teams. Finance has the visibility to dig into the details and map AI use across the organization, whether it quietly shows up as a subscription renewal or a new budget request. But more than that, they can be instrumental in ensuring teams embrace open conversations, not just OpenAI. </p><h2 id="ai-activity-does-not-translate-to-ai-value">AI activity does not translate to AI value</h2><p>Just about every organization will have developed transformational ways of using <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. But, whether they know it or not, there will be wasteful ones too.</p><p>When it comes to inefficient use, some of the major culprits include asking AI agents open-ended questions, model mismatch where tokens are burned unnecessarily; and duplicate tools, resulting from shadow AI and overlapping subscriptions. These prevent businesses from seeing the full picture; one that is, in all probability, very expensive. </p><p>User literacy can improve this. But for finance teams they must start with the grey area of AI consumption. Two teams might show as active AI users, but one that’s using an LLM to produce more content faster is doing something fundamentally different to one that’s using it for peripheral <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> tasks. In fact, only 29% of European SMEs using Gen AI are doing so in core business activities.</p><p>To improve the control they have over AI, organizations must start by elevating their visibility from who is using AI, to who is using it to become smarter, faster and more productive.  </p><h2 id="how-to-regain-control-over-ai-use">How to regain control over AI use</h2><p>A complete view of AI spend is essential, regardless of whether costs are rising.   </p><p>Breaking spend down by department, team and budget helps identify both disproportionate usage and areas where adoption may be lagging. These should be combined with performance metrics such as the time-to-first-draft on marketing content; code review cycle times in engineering; support ticket resolution time in customer support; and so on.</p><p>This combination of spend and performance can reveal whether AI investment is translating into measurable productivity gains and not just higher <a href="https://www.techradar.com/best/best-small-business-software">software</a> costs.</p><p>Visibility should also extend to model-level usage. As mentioned before, the cost difference between frontier reasoning models and lighter alternatives can be tenfold. Monitoring model and vendor usage alongside token consumption helps organizations route routine tasks to lower-cost options, maximize ROI and reduce unnecessary spend. </p><p>Finance teams should therefore expand reporting and budgeting frameworks to include AI-specific metrics. A key question at month-end is whether AI-enabled teams are increasing output and capacity without increasing headcount. This provides a clear headline for AI's impact, can justify investment and distinguish between high-value and low-value AI usage. </p><p>Ultimately, effective control over AI is not about costs alone. It is about understanding where AI is creating value and ensuring investment is aligned with <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> outcomes.</p><h2 id="ai-control-is-at-your-fingertips">AI control is at your fingertips</h2><p>The good news is that none of these metrics require a sophisticated AI analytics stack. Finance teams should already have the tools for real-time visibility into what’s being spent and where. All that’s needed now is to fold AI into the mix and collaborate with other departments to measure and improve its ROI.</p><p>The outcome is that organizations control AI use through oversight, without restricting spend, adoption or innovation through lengthy procurement processes. Spend policies, category controls and clear approval thresholds control what is spent, and everything is measured.</p><p>But crucially, teams don’t slow down as a result. The only difference is that AI is optimized for impact.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Securing adoption in the era of shadow AI ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Artificial intelligence (AI) is rapidly becoming embedded in the modern workplace, with employees are increasingly turning to <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to work more efficiently and boost productivity. </p><p>This growing demand for faster, more effective ways of working is driving the rise of shadow AI - the use of AI tools outside approved organizational controls and governance frameworks – which results in organizations quickly losing visibility into data usage and potential risks.</p><p>The scale of this challenge is significant. While 90% of executives are confident in their organizations' visibility into AI tools, just 52% of employees admit to using AI tools without approval, often through personal accounts. </p><p>As a result, organizations are left grappling with a widening gap between AI adoption and AI governance.</p><h2 id="the-next-frontier-of-ai-risk">The next frontier of AI risk</h2><p>When AI is used without formal oversight, it can bypass governance controls, increasing the risk of errors, regulatory breaches and sensitive data leakages. Organizations are most exposed when AI is already influencing business-critical activities, from customer service and operational decision-making to software development and content creation.  </p><p>The challenge will intensify as businesses move beyond <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a>, which generate information, to large action models and agentic systems that can take action. These systems can diagnose issues, recommend actions and execute workflows with minimum human input, increasing both the speed and scale at which mistakes occur. </p><p>A shadow agent operating outside approved governance frameworks could trigger harmful actions before organizations have the visibility and governance capabilities needed to intervene.</p><p>There is also a longer-term risk that future AI systems will be trained on synthetic or lower-quality data, weakening performance and decision-making over time. Transparency and traceability will be critical to maintaining accountability, protecting ethical standards and preserving the effectiveness of AI systems as adoption continues to accelerate.</p><h2 id="ai-governance-as-an-enabler">AI governance as an enabler</h2><p>What works is AI governance that enables innovation while putting clear guardrails in place that are integrated, transparent, auditable, and aligned with existing risk and compliance frameworks. If AI is to be used safely, firms must be able to successfully identify exactly what went wrong and why when issues arise.  </p><p>In practice, mature governance starts with an approved AI tool stack that provides safe and trusted options for common use cases. This should be supported by risk-based policies that make clear the <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> being handled, what can and cannot be shared, which tools are permitted, and where human approval is required. </p><p>Low-risk tasks such as drafting or summarizing content should not be governed in the same way as high-risk uses involving customer data, regulated information or business-critical decisions.</p><p>Training is equally important. The challenge, beyond only enforcing controls, involves helping employees understand why those controls exist and how to use AI responsibly. As agents increasingly diagnose issues, recommend actions, and execute workflows with minimum input, human oversight and approval processes must scale alongside them. </p><p>Interoperability will be critical to making this workable at scale, allowing organizations to operate across jurisdictions and multiple AI models without repeatedly rebuilding governance processes and systems from scratch.</p><h2 id="making-responsible-adoption-the-easy-choice">Making responsible adoption the easy choice </h2><p>For <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and compliance leaders, the goal should be to make responsible AI adoption the path of least resistance. Employees turn to shadow AI when approved tools are unavailable, difficult to access or fail to meet their needs. Companies that focus solely on restricting usage risk driving activity further underground and losing out on the efficiency and innovation gains that AI can deliver. </p><p>Organizations that successfully balance AI <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and control over their systems recognize that shadow AI use is often a symptom of unmet demand. Employees typically turn to unauthorized tools because they are easier to access, faster to use or better suited to the task at hand. Rather than focusing on restrictions alone, leaders should understand where AI is already being used across the business and ensure approved alternatives are available for the most common use cases. </p><p>With three-quarters of office professionals saying they would be likely to look for a new job that offered better AI skills development, firms that combine governance with opportunities to build AI skills are likely to see stronger adoption of approved tools and, as a result, less reliance on shadow AI. </p><p>Building an AI-enabled culture means giving employees the tools, knowledge and confidence to innovate within clear boundaries. By doing so, shadow AI can be reduced while the speed and agility that workers increasingly expect is maintained. </p><h2 id="the-organizations-best-positioned-to-succeed">The organizations best positioned to succeed</h2><p>The businesses that strike the right balance for AI success will be those that view governance as a foundation for AI adoption and not a barrier to it. By making the secure, approved path the easiest path, shadow AI risk is reduced without sacrificing productivity. </p><p>Embedding strong governance, supported by trusted and well-managed data foundations, avoids costly mistakes and allows AI to be deployed and scaled with greater safety and confidence.</p><p><em></em><a href="https://www.techradar.com/best/best-small-business-software"><em>We've reviewed, rated, and ranked the best small business software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/securing-adoption-in-the-era-of-shadow-ai</link>
                                                                            <description>
                            <![CDATA[ How organizations can reduce shadow AI risks while enabling secure, responsible AI adoption at scale. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWQQNLn4PNm6qBbTdrgQiB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 17 Aug 2026 07:43:57 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Martin Tombs ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:description>                                                            <media:text><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:text>
                                <media:title type="plain"><![CDATA[Hands typing on a tablet with AI superimposed in text in front]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qP76MS2BAb7kSuWrvJXXYL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Artificial intelligence (AI) is rapidly becoming embedded in the modern workplace, with employees are increasingly turning to <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to work more efficiently and boost productivity. </p><p>This growing demand for faster, more effective ways of working is driving the rise of shadow AI - the use of AI tools outside approved organizational controls and governance frameworks – which results in organizations quickly losing visibility into data usage and potential risks.</p><p>The scale of this challenge is significant. While 90% of executives are confident in their organizations' visibility into AI tools, just 52% of employees admit to using AI tools without approval, often through personal accounts. </p><p>As a result, organizations are left grappling with a widening gap between AI adoption and AI governance.</p><h2 id="the-next-frontier-of-ai-risk">The next frontier of AI risk</h2><p>When AI is used without formal oversight, it can bypass governance controls, increasing the risk of errors, regulatory breaches and sensitive data leakages. Organizations are most exposed when AI is already influencing business-critical activities, from customer service and operational decision-making to software development and content creation.  </p><p>The challenge will intensify as businesses move beyond <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">large language models</a>, which generate information, to large action models and agentic systems that can take action. These systems can diagnose issues, recommend actions and execute workflows with minimum human input, increasing both the speed and scale at which mistakes occur. </p><p>A shadow agent operating outside approved governance frameworks could trigger harmful actions before organizations have the visibility and governance capabilities needed to intervene.</p><p>There is also a longer-term risk that future AI systems will be trained on synthetic or lower-quality data, weakening performance and decision-making over time. Transparency and traceability will be critical to maintaining accountability, protecting ethical standards and preserving the effectiveness of AI systems as adoption continues to accelerate.</p><h2 id="ai-governance-as-an-enabler">AI governance as an enabler</h2><p>What works is AI governance that enables innovation while putting clear guardrails in place that are integrated, transparent, auditable, and aligned with existing risk and compliance frameworks. If AI is to be used safely, firms must be able to successfully identify exactly what went wrong and why when issues arise.  </p><p>In practice, mature governance starts with an approved AI tool stack that provides safe and trusted options for common use cases. This should be supported by risk-based policies that make clear the <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> being handled, what can and cannot be shared, which tools are permitted, and where human approval is required. </p><p>Low-risk tasks such as drafting or summarizing content should not be governed in the same way as high-risk uses involving customer data, regulated information or business-critical decisions.</p><p>Training is equally important. The challenge, beyond only enforcing controls, involves helping employees understand why those controls exist and how to use AI responsibly. As agents increasingly diagnose issues, recommend actions, and execute workflows with minimum input, human oversight and approval processes must scale alongside them. </p><p>Interoperability will be critical to making this workable at scale, allowing organizations to operate across jurisdictions and multiple AI models without repeatedly rebuilding governance processes and systems from scratch.</p><h2 id="making-responsible-adoption-the-easy-choice">Making responsible adoption the easy choice </h2><p>For <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> and compliance leaders, the goal should be to make responsible AI adoption the path of least resistance. Employees turn to shadow AI when approved tools are unavailable, difficult to access or fail to meet their needs. Companies that focus solely on restricting usage risk driving activity further underground and losing out on the efficiency and innovation gains that AI can deliver. </p><p>Organizations that successfully balance AI <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and control over their systems recognize that shadow AI use is often a symptom of unmet demand. Employees typically turn to unauthorized tools because they are easier to access, faster to use or better suited to the task at hand. Rather than focusing on restrictions alone, leaders should understand where AI is already being used across the business and ensure approved alternatives are available for the most common use cases. </p><p>With three-quarters of office professionals saying they would be likely to look for a new job that offered better AI skills development, firms that combine governance with opportunities to build AI skills are likely to see stronger adoption of approved tools and, as a result, less reliance on shadow AI. </p><p>Building an AI-enabled culture means giving employees the tools, knowledge and confidence to innovate within clear boundaries. By doing so, shadow AI can be reduced while the speed and agility that workers increasingly expect is maintained. </p><h2 id="the-organizations-best-positioned-to-succeed">The organizations best positioned to succeed</h2><p>The businesses that strike the right balance for AI success will be those that view governance as a foundation for AI adoption and not a barrier to it. By making the secure, approved path the easiest path, shadow AI risk is reduced without sacrificing productivity. </p><p>Embedding strong governance, supported by trusted and well-managed data foundations, avoids costly mistakes and allows AI to be deployed and scaled with greater safety and confidence.</p><p><em></em><a href="https://www.techradar.com/best/best-small-business-software"><em>We've reviewed, rated, and ranked the best small business software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is the new Water Cyber Shield Act too little, too late, and can a cyber group do it better? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/is-the-new-water-cyber-shield-act-too-little-too-late-and-can-a-cyber-group-do-it-better-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ Numerous recent attacks are prompting Congress to do something ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tjiX2NnAd6dGXFsmpcTECc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 16 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:description>                                                            <media:text><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:text>
                                <media:title type="plain"><![CDATA[Aerial view of water treatment factory at city wastewater cleaning facility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZtdYh6C8PhDP5njg8EtK6M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Two US senators have proposed a new <a href="https://www.schiff.senate.gov/wp-content/uploads/2026/08/Summary_Water-Cyber-Shield-Act.pdf" target="_blank" rel="nofollow">Water Cyber Shield Act</a> to provide the EPA with additional funding and tools to conduct cybersecurity assessments on critical water infrastructure.</p><p>The act would provide $300 million annually to allow for upgrades to water utility infrastructure. Numerous coordinated attacks have been launched against US water infrastructure in recent years across 12 states, with <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">30 Minnesota utilities hit by Iran earlier this month</a>.</p><p>But a separate Water Watch Center group has been set up to monitor 91% of the roughly 50,000 community water systems nationwide following a two-year pilot. The group, set up by DEF CON Franklin and the National Rural Water Association, will offer managed detection and response services provided by five cybersecurity firms.</p><h2 id="why-are-water-utilities-being-attacked">Why are water utilities being attacked?</h2><p>The FBI, CISA, NSA, and many more <a href="https://www.techradar.com/pro/security/us-agencies-warn-iranian-hackers-are-targeting-american-critical-infrastructure-causing-disruptive-effects-within-the-united-states">agencies have issued warnings</a> about the increased threat to water utilities from Iran. </p><p>Water utilities are considered a low risk, high reward attack for state-sponsored hackers looking to cause as much damage as possible as many of the water control systems rely on  internet connected operational technology (OT) devices and logic controllers.</p><p>These devices are widely deployed across water infrastructure to control water treatment and are connected to computers at monitoring stations. Theoretically if a hacker gained control of these systems, they could turn off the treatment of water or open sewage gates to contaminate water supplies.</p><p>Many water treatment systems are designed to last decades, with these OT devices and logic controllers expected to last as long as possible. But as new tech and hardware is developed, these devices stop receiving software updates that can put them at a greater risk of being attacked.</p><p>For many in the cybersecurity industry though, the Water Cyber Shield Act is too little, too late.</p><h3 class="article-body__section" id="section-expert-perspectives-on-hardening-water-utilities"><span>Expert perspectives on hardening water utilities</span></h3><h2 id="will-the-water-cyber-shield-act-be-passed">Will the Water Cyber Shield Act be passed?</h2><p><strong>Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs: </strong></p><p><em>While it's always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it's likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found </em><a href="https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys" target="_blank" rel="nofollow"><em>here</em></a><em>)</em></p><div><blockquote><p>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</p></blockquote></div><p><em>I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past.  If we look at just the 118</em><sup><em>th</em></sup><em> and 119</em><sup><em>th</em></sup><em> Congress, we have had 9 bills introduced, as far as I'm aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still "pending' but considering no movement has occurred on them, they will likely reach the same fate.</em></p><p><em>Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn't be dependent on the goodwill of private citizens to protect public infrastructure.</em></p><p><em>Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn't the first time we have had this situation happen before.  So, my fingers are crossed, but I'm not holding my breath.</em></p><h2 id="too-little-too-late">Too little, too late?</h2><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong> </p><p><em>I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade.</em></p><div><blockquote><p>This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</p></blockquote></div><p><em>Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.</em></p><p><em>My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised.</em></p><p><em>It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.</em></p><h2 id="is-300-million-even-enough">Is $300 million even enough?</h2><p><strong>Damon Small, Board of Directors, Xcape, Inc.:</strong> </p><p><em>The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector's systemic fragility.</em></p><div><blockquote><p>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</p></blockquote></div><p><em>Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.</em></p><p><em>The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments.</em></p><p><em>Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.</em></p><p><em>Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why was there an 'evil’ Delta airlines Wi-Fi network? The experts weigh in ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/why-was-there-an-evil-delta-airlines-wi-fi-network-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ A passenger set up an evil Wi-Fi network on a post-DEF CON Delta flight - we find out what the experts think. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ZAjHb9bTEpdhjJqTyEPWfb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 15 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Servers &amp; Network Devices]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Computing Components]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/KZMrozx7RQQq5F2nbhK2iZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As many attendees of this year’s DEF CON hacker conference departed Las Vegas recently, many unsuspecting passengers on Delta Flight 591 attempted to access an onboard Wi-Fi network.</p><p>What they didn’t know was that ‘Delta WiFi Fast’ was actually a fake network, allegedly set up by a fellow passenger intended to mimic the actual onboard Wi-Fi network and scam other users.</p><p>The unknown passenger was able to disable the legitimate Wi-Fi networks for 30 minutes while they launched the attack, and in doing so, may have violated United States federal law.</p><h2 id="how-did-the-attack-take-place">How did the attack take place?</h2><p>According to Aircraft Communications Addressing and Reporting System (ACARS) messages, the situation was first brought to light by the crew of the flight, who shared the following message:</p><p>“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX”</p><p>Another message <a href="https://app.airframes.io/messages/7299585926" target="_blank" rel="nofollow">read</a>:</p><p>“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFRENCE IN LAS THE WERE ABLE TO JAM OUR WIFI AND BRODCAST THERE SIGNIAL”</p><p>The actual details of what happened on the flight outside of these messages isn’t clear, but according to Monika Hathaway, head of press for DEF CON, similar attacks happened in Las Vegas: “Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations.”</p><p>Delta airlines confirmed that no aircraft operating systems were affected and flight safety was never in question.</p><p>Wi-Fi deauthorization attacks can be launched with cheap, widely available ‘deauth boards’ which are small, battery powered devices that send deauthentication frames to devices within their range. On board a plane, these could easily reach most devices.</p><p>Once the legitimate Wi-Fi has been jammed and the other users booted from the network, the attacker can then set up an ‘evil twin’ network that users will attempt to connect to, which can be used to snoop on their internet traffic, steal credentials, and perform other malicious activities.</p><h3 class="article-body__section" id="section-expert-perspectives-on-the-delta-wi-fi-attack"><span>Expert perspectives on the Delta Wi-Fi attack</span></h3><h2 id="evil-twin-attacks-and-the-risks-of-connecting">‘Evil twin’ attacks and the risks of connecting</h2><p><strong>Aras Nazarovas, Senior Information Security Researcher at Cybernews:</strong></p><p><em>An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victim devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case here.</em></p><p><em>Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.</em></p><p><em>The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data like name, email, address, etc. Or, the hacker may even go further and provide fake login pages for banks, social media, and try to extract login details from the victims.</em></p><div><blockquote><p>Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.</p></blockquote></div><p><em>Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers. </em></p><p><em>If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received.</em></p><p><em>However, if a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine.</em></p><h2 id="who-would-launch-the-attack">Who would launch the attack?</h2><p><strong>Seemant Sehgal, Founder & CEO, BreachLock:</strong></p><p><em>Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.</em></p><div><blockquote><p>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</p></blockquote></div><p><em>Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved.</em></p><p><em>The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.</em></p><p><strong>Denis Calderone, CTO, Suzu Labs:</strong></p><p><em>Hackers will hack. I go to DEF CON most years, and it's pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn't have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that's taking the expected hijinks way too far.</em></p><div><blockquote><p>These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</p></blockquote></div><p><em>The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth.</em></p><p><em>But there's a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.</em></p><p><em>For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same.</em></p><p><em>Beyond that, if a WiFi network on a plane doesn't match what the crew announced or what's printed on the seat card, don't connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that's not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you're being asked for something that doesn't make sense for the context, you're probably not on the real network.</em></p><h2 id="reputational-harm-for-the-cybersecurity-industry">Reputational harm for the cybersecurity industry</h2><p><strong>Jacob Warner, Director of IT, Xcape, Inc.:</strong></p><p><em>While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks.</em></p><p><em>Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet.</em></p><div><blockquote><p>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</p></blockquote></div><p><em>Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.</em></p><p><em>This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.</em></p><p><em>Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.</em></p><p><strong>John Strand, Owner, Black Hills Information Security, Inc.:</strong></p><p><em>This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.</em></p><div><blockquote><p>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated.</p></blockquote></div><p><em>There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.</em></p><p><em>I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This one just needs a script': Researchers find ultimate Windows kill switch which can disable antivirus with almost no user interaction ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Researchers uncovered “Download more RAM” flaw in consumer DDR4/DDR5 memory</strong></li><li><strong>Attack bypassed Windows VBS and HVCI, disabling antivirus and protections</strong></li><li><strong>Microsoft patched CVE‑2026‑23670; tools now help enable memory write protection</strong></li></ul><p>Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. </p><p>All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side.</p><p>Luckily, the vulnerability was discovered by white hat hackers, reported to Microsoft and remedied before falling into the wrong hands.</p><h2 id="download-more-ram">Download more RAM</h2><p>During the 2026 USENIX Security Symposium, security researchers from the University of Birmingham and Durham University presented a discovery they called “Download more RAM”. </p><p>According to the researchers, some consumer memory chips (DDR4 and <a href="https://www.techradar.com/computing/best-ddr5-ram" target="_blank">DDR5</a> DIMM) allowed software to alter the configuration reports it sends to the motherboard. In practice, it means that a threat actor could instruct the RAM chip to tell the computer it was bigger than it actually was, making the device “think” it has twice as much RAM memory as it actually has.</p><p>The researchers then established that this phantom extra memory can serve as an alias for real memory locations, granting them the ability to both read, and modify, memory allocations that should be under the processor’s, and Windows’ protection.</p><p>This window let them work around both Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). </p><p>VBS, first introduced with Windows 10, is a security feature that uses hardware virtualization to isolate critical security functions from the OS, while HVCI uses virtualization to make sure only trusted and verified code can run in the Windows kernel.</p><p>The researchers also used the flaw to disable both antivirus and endpoint detection and response (EDR) software, re-introduce older, vulnerable drivers, compromise corporate systems under lockdown, and bypass kernel-level game anti-cheat protections. </p><p>The worst part is that this entire process can be chained together into a one-click script. In theory, if a victim is served this script as a file and they run it, they would trigger a chain of events that includes creating memory aliases, rebooting the computer, and disabling security protections. </p><p>"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees,” said Professor Tom Chothia, from the University of Birmingham. “Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."</p><h2 id="who-is-vulnerable-and-how-to-stay-safe">Who is vulnerable and how to stay safe</h2><p>The attack surface is rather large, as well. The researchers analyzed the market and found three major manufacturers (Corsair, G.Skill, and ADATA) shipping at least one consumer memory product line in which the configuration chip was left entirely unprotected. Together, these vendors make up more than half (55%) of the high-performance consumer memory market and more than 70% of the gaming market (this doesn’t mean that 55% of the high-performance market is vulnerable - many devices are running other modules, too).</p><p>Modules from Crucial, Kingston and HyperX, and some G.Skill lines, were found to use partial write protection, but still enough to keep the device secure. </p><p>Before publishing their work, the researchers disclosed their findings to Microsoft, who quickly addressed it. The bug is now tracked as CVE-2026-23670, and is described on the National Vulnerability Database (NVD) as an “untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave” which “allows an authorized attacker to bypass a security feature locally.”</p><p>The bug was given a severity score of 5.7/10 (medium), and was fixed as part of the April 2026 Patch Tuesday cumulative update. Therefore, systems with Secure Boot running should be protected against this vulnerability. </p><p>Corsair added a feature to its iCue tools that lets users retroactively enable write protection on their memory modules. There is also a free tool called HWinfo with the same functionality, the researchers said, stressing that it mitigates the issue on non-Corsair models. Also, some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.</p><p>“The ‘Download More RAM’ attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk,” said Dr Marius Muench, from the University of Birmingham.  </p><p>“Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to." </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-one-just-needs-a-script-researchers-find-ultimate-windows-kill-switch-which-can-disable-antivirus-with-almost-no-user-interaction</link>
                                                                            <description>
                            <![CDATA[ Microsoft fixed it as part of the April Patch Tuesday cumulative update, but there are other fixes and mitigations available, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">D5GiErt8bYeqUgE82r6EtQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu.]]></media:description>                                                            <media:text><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:text>
                                <media:title type="plain"><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers uncovered “Download more RAM” flaw in consumer DDR4/DDR5 memory</strong></li><li><strong>Attack bypassed Windows VBS and HVCI, disabling antivirus and protections</strong></li><li><strong>Microsoft patched CVE‑2026‑23670; tools now help enable memory write protection</strong></li></ul><p>Microsoft has recently fixed a vulnerability that allowed threat actors to bypass advanced security measures, disable antivirus software, and expose the target device to full system takeover. </p><p>All of this, it seems, could have been possible with a very simple script, and a single click from the victim’s side.</p><p>Luckily, the vulnerability was discovered by white hat hackers, reported to Microsoft and remedied before falling into the wrong hands.</p><h2 id="download-more-ram">Download more RAM</h2><p>During the 2026 USENIX Security Symposium, security researchers from the University of Birmingham and Durham University presented a discovery they called “Download more RAM”. </p><p>According to the researchers, some consumer memory chips (DDR4 and <a href="https://www.techradar.com/computing/best-ddr5-ram" target="_blank">DDR5</a> DIMM) allowed software to alter the configuration reports it sends to the motherboard. In practice, it means that a threat actor could instruct the RAM chip to tell the computer it was bigger than it actually was, making the device “think” it has twice as much RAM memory as it actually has.</p><p>The researchers then established that this phantom extra memory can serve as an alias for real memory locations, granting them the ability to both read, and modify, memory allocations that should be under the processor’s, and Windows’ protection.</p><p>This window let them work around both Virtualization-based Security (VBS) and Hypervisor-Enforced Code Integrity (HVCI). </p><p>VBS, first introduced with Windows 10, is a security feature that uses hardware virtualization to isolate critical security functions from the OS, while HVCI uses virtualization to make sure only trusted and verified code can run in the Windows kernel.</p><p>The researchers also used the flaw to disable both antivirus and endpoint detection and response (EDR) software, re-introduce older, vulnerable drivers, compromise corporate systems under lockdown, and bypass kernel-level game anti-cheat protections. </p><p>The worst part is that this entire process can be chained together into a one-click script. In theory, if a victim is served this script as a file and they run it, they would trigger a chain of events that includes creating memory aliases, rebooting the computer, and disabling security protections. </p><p>"Our work exploits the fact that all processes share the same memory to bypass Windows' strongest security guarantees,” said Professor Tom Chothia, from the University of Birmingham. “Previous attacks of this kind needed a screwdriver and physical access to the machine. This one just needs a script. That changes who can carry it out and how far it can spread."</p><h2 id="who-is-vulnerable-and-how-to-stay-safe">Who is vulnerable and how to stay safe</h2><p>The attack surface is rather large, as well. The researchers analyzed the market and found three major manufacturers (Corsair, G.Skill, and ADATA) shipping at least one consumer memory product line in which the configuration chip was left entirely unprotected. Together, these vendors make up more than half (55%) of the high-performance consumer memory market and more than 70% of the gaming market (this doesn’t mean that 55% of the high-performance market is vulnerable - many devices are running other modules, too).</p><p>Modules from Crucial, Kingston and HyperX, and some G.Skill lines, were found to use partial write protection, but still enough to keep the device secure. </p><p>Before publishing their work, the researchers disclosed their findings to Microsoft, who quickly addressed it. The bug is now tracked as CVE-2026-23670, and is described on the National Vulnerability Database (NVD) as an “untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave” which “allows an authorized attacker to bypass a security feature locally.”</p><p>The bug was given a severity score of 5.7/10 (medium), and was fixed as part of the April 2026 Patch Tuesday cumulative update. Therefore, systems with Secure Boot running should be protected against this vulnerability. </p><p>Corsair added a feature to its iCue tools that lets users retroactively enable write protection on their memory modules. There is also a free tool called HWinfo with the same functionality, the researchers said, stressing that it mitigates the issue on non-Corsair models. Also, some motherboards offer a BIOS setting to block writes to memory configuration chips, which users can enable as an interim measure.</p><p>“The ‘Download More RAM’ attack demonstrates once more the importance of understanding systems, especially in terms of security guarantees. If a lower layer can become compromised, it puts the full system at risk,” said Dr Marius Muench, from the University of Birmingham.  </p><p>“Windows makes a strong promise: that even an attacker with administrator rights can't touch the secure kernel. We found that promise rests on the assumption that your memory is telling the truth about itself - on a lot of the memory people actually buy, it doesn't have to." </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Scammers hijack real Shopify notifications to swindle victims — here's how to stay safe ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Huntress uncovers Shopify refund scam using fake orders and app notifications</strong></li><li><strong>Attackers embed contact details in shipping addresses to trick victims into paying</strong></li><li><strong>Users advised to ignore suspicious info, verify refunds, and report fake stores</strong></li></ul><p>Hackers are targeting businesses and individuals running Shopify stores with a highly sophisticated fake refund scam, experts have warned.</p><p>Security researchers at Huntress <a href="https://www.huntress.com/blog/shopify-fake-refund-scam" target="_blank">outlined</a> how the fake refund scam works: first, a victim gets a notification that they received a refund. It could be for a returned iPhone, or a canceled service or order. The “refund” can be anywhere from a few hundred, to a few thousand dollars. Soon after, the scammers call (or mail) the victim, say they work at the company that gave the erroneous refund, and convince the victim to return the funds.</p><p>If the victim complies, they are actually sending their own money to the victims, since the “refund” part never happened.</p><h2 id="abusing-shopify-s-infrastructure">Abusing Shopify's infrastructure</h2><p>There are a couple of ways to pull this attack off: sometimes the scammers really make the initial transaction, but are able to cancel it and return the funds; in other scenarios, they create spoofed pages showing the transactions, tricking those slightly more gullible. </p><p>In most cases, fake refund scams can be spotted relatively easily, which is why they are not that popular nowadays. However, this new campaign comes with a sinister twist that will make even hardened veterans wince.</p><p>Huntress’ report notes the attackers start by creating a Shopify store of their own (or use a compromised one). The one the researchers observed was called “My Store” and was later deleted before it could be further scrutinized. Then, the attackers make a fake order themselves, setting their targets as the recipients using their phone numbers, or email addresses.</p><p>This type of information isn’t that difficult to come by these days. There are hundreds of email and phone number databases leaked on the dark web, which can be picked up for free (or for a handful of dollars). When they submit the purchase order, a notification appears in the victim’s Shop apps. </p><p>Yes, that’s right. In the Shopify app itself. Coming through Shopify infrastructure. As such, it can easily be confused for an authentic notification. It is even worse for users that enabled push notifications on their mobile phones, since they’ll see a notification with the Shopify logo, next to all the other notifications on their phone. </p><p>But the attackers still need to pull off the hardest part - getting the victim to “return” the money. In this case, instead of calling or messaging them, they leave their contact information in the shipping address, hoping victims would panic and reach out themselves.</p><p>In one shared example, the shipping address was listed as: Owen Nolan “2856 If You Didnt Place This Order Call Us at 1_888_690_3420-”, Albany NY United States 1_888_690_3420.”</p><p>For those treading carefully through the internet’s wastelands, the message included in the shipping address is an immediate red flag. Grammar mistakes, all letters capitalized, and a phone number completely out of place should be quite an obvious sign of an attempted fraud. However, since these kinds of scams bet on people being fast, reckless, overworked, and afraid, it might just work.</p><p>Huntress did not say if the scam made any meaningful impact among the Shopify’s community, or if it targeted a specific subgroup of users. </p><h2 id="defending-against-fake-refund-scams">Defending against fake refund scams</h2><p>To protect against such attacks, the researchers advise users never interact with phone numbers, email addresses, or links contained in an order that aren’t recognizable. They also advise users concerned about the security of their SHop account or personal data to contact support, and stress users should check their bank accounts to confirm whether they were actually changed. If they weren’t, they can report the order as “Not my order” in the shop app. </p><p>Finally, when purchasing from a store on Shop in general, users should check the store and its product reviews to learn about other customers’ experiences. If users are concerned that a product or store could be fake, it can easily be reported. Many of the shops in this scam were brand-new, with some using a "coming soon" description, as well. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/scammers-hijack-real-shopify-notifications-to-swindle-victims-heres-how-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Would you recognize a fake notification if it came directly from Shopify? Some scammers are betting you wouldn't. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">u7cEBFyhxgwb3nwswX5ieS</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 15:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[use Shopify to build your online busness]]></media:description>                                                            <media:text><![CDATA[use Shopify to build your online busness]]></media:text>
                                <media:title type="plain"><![CDATA[use Shopify to build your online busness]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sTv9eAmsTTbHV59N8KXUZk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress uncovers Shopify refund scam using fake orders and app notifications</strong></li><li><strong>Attackers embed contact details in shipping addresses to trick victims into paying</strong></li><li><strong>Users advised to ignore suspicious info, verify refunds, and report fake stores</strong></li></ul><p>Hackers are targeting businesses and individuals running Shopify stores with a highly sophisticated fake refund scam, experts have warned.</p><p>Security researchers at Huntress <a href="https://www.huntress.com/blog/shopify-fake-refund-scam" target="_blank">outlined</a> how the fake refund scam works: first, a victim gets a notification that they received a refund. It could be for a returned iPhone, or a canceled service or order. The “refund” can be anywhere from a few hundred, to a few thousand dollars. Soon after, the scammers call (or mail) the victim, say they work at the company that gave the erroneous refund, and convince the victim to return the funds.</p><p>If the victim complies, they are actually sending their own money to the victims, since the “refund” part never happened.</p><h2 id="abusing-shopify-s-infrastructure">Abusing Shopify's infrastructure</h2><p>There are a couple of ways to pull this attack off: sometimes the scammers really make the initial transaction, but are able to cancel it and return the funds; in other scenarios, they create spoofed pages showing the transactions, tricking those slightly more gullible. </p><p>In most cases, fake refund scams can be spotted relatively easily, which is why they are not that popular nowadays. However, this new campaign comes with a sinister twist that will make even hardened veterans wince.</p><p>Huntress’ report notes the attackers start by creating a Shopify store of their own (or use a compromised one). The one the researchers observed was called “My Store” and was later deleted before it could be further scrutinized. Then, the attackers make a fake order themselves, setting their targets as the recipients using their phone numbers, or email addresses.</p><p>This type of information isn’t that difficult to come by these days. There are hundreds of email and phone number databases leaked on the dark web, which can be picked up for free (or for a handful of dollars). When they submit the purchase order, a notification appears in the victim’s Shop apps. </p><p>Yes, that’s right. In the Shopify app itself. Coming through Shopify infrastructure. As such, it can easily be confused for an authentic notification. It is even worse for users that enabled push notifications on their mobile phones, since they’ll see a notification with the Shopify logo, next to all the other notifications on their phone. </p><p>But the attackers still need to pull off the hardest part - getting the victim to “return” the money. In this case, instead of calling or messaging them, they leave their contact information in the shipping address, hoping victims would panic and reach out themselves.</p><p>In one shared example, the shipping address was listed as: Owen Nolan “2856 If You Didnt Place This Order Call Us at 1_888_690_3420-”, Albany NY United States 1_888_690_3420.”</p><p>For those treading carefully through the internet’s wastelands, the message included in the shipping address is an immediate red flag. Grammar mistakes, all letters capitalized, and a phone number completely out of place should be quite an obvious sign of an attempted fraud. However, since these kinds of scams bet on people being fast, reckless, overworked, and afraid, it might just work.</p><p>Huntress did not say if the scam made any meaningful impact among the Shopify’s community, or if it targeted a specific subgroup of users. </p><h2 id="defending-against-fake-refund-scams">Defending against fake refund scams</h2><p>To protect against such attacks, the researchers advise users never interact with phone numbers, email addresses, or links contained in an order that aren’t recognizable. They also advise users concerned about the security of their SHop account or personal data to contact support, and stress users should check their bank accounts to confirm whether they were actually changed. If they weren’t, they can report the order as “Not my order” in the shop app. </p><p>Finally, when purchasing from a store on Shop in general, users should check the store and its product reviews to learn about other customers’ experiences. If users are concerned that a product or store could be fake, it can easily be reported. Many of the shops in this scam were brand-new, with some using a "coming soon" description, as well. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI is making cyber threats faster, but trust will define which businesses survive ]]></title>
                                                                                                <dc:content><![CDATA[ <p>A small business owner receives a call from a customer. </p><p>An email that appeared to come from the business led the customer to a fraudulent <a href="https://www.techradar.com/news/the-best-website-builder">website</a>, and their personal information may have been compromised. </p><p>What makes situations like this so damaging is that the owner never knew the risk existed. </p><p>The domain used in the attack had been registered for a campaign years earlier and left quietly active, sitting outside anyone's management, until someone else found a use for it.</p><p>Situations like this rarely begin with a major <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach. More often they start with something small: a forgotten domain, an outdated email configuration, or a digital asset nobody realized was still active. </p><p>AI makes finding those unnoticed weaknesses all too easy for attackers. According to KnowBe4's 2025 Phishing Threat Trends Report, 82.6% of phishing emails now show some use of AI, a 53.5% increase year-over-year. Attackers are adopting the same <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> businesses use to improve efficiency, and the speed advantage has shifted. The good news is that businesses can use the same advances in AI to identify many of these risks before attackers do.</p><p>But the speed of detection is only part of the challenge. The harder problem is visibility. You can't secure what you don't know you own.</p><p>More and more, small businesses manage <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a>, websites, email systems, social channels, and third-party tools, and as those layers expand, the gaps between ownership and oversight become easier to miss. </p><p>Forgotten domains are a common example. Domains created for promotions, campaigns, or discontinued services often stay active long after their purpose disappears. Left unmanaged, they become blind spots that attackers exploit through phishing, impersonation, and brand abuse, and they can quietly erode credibility well before any breach, since a domain that no longer resolves correctly signals neglect to customers and machines alike.</p><p>Simply put, many business owners no longer have a complete view of the digital assets they own or the vulnerabilities that come with them.</p><h2 id="security-needs-to-be-embedded-not-bolted-on">Security needs to be embedded, not bolted on</h2><p>Small business owners are focused on serving customers, growing revenue, and running their businesses. They are not thinking about <a href="https://www.techradar.com/news/best-dns-server">DNS</a> records, certificate renewals, or dormant subdomains during their day. Nor should they have to.</p><p>But many do not have the option. According to VikingCloud's 2026 research, 84% of SMB owners manage cybersecurity themselves, often without dedicated training or expertise. </p><p>The most effective security strategies are built into the infrastructure which businesses depend on every day, rather than added after problems arise. There are three layers where this matters most: the domain, which serves as a business' identity online; the website, where customers form opinions about credibility and trustworthiness; and <a href="https://www.techradar.com/news/best-email-provider">email</a>, which remains one of the most important channels for customer communication and one of the most common targets for impersonation and fraud.</p><p>Embedding security into the solutions businesses already use helps them maintain visibility and confidence without constant manual oversight of all of those moving parts.</p><h2 id="trust-is-now-measured-by-both-people-and-machines">Trust is now measured by both people and machines</h2><p>Today’s <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> conversation always comes back to trust. That’s what SMBs want to win by securing their online business. It is the engine of their success.</p><p>We know that trust is one of the most important competitive advantages a business can have: according to McKinsey reporting on digital trust, 40% of consumers have completely pulled their business from a company after discovering the organization was reckless with customer data, and 10% of consumers will cut ties with a brand immediately upon learning of a data breach, regardless of whether their own personal information was actually compromised or stolen.</p><p>For years, trust online was primarily a human judgment. Customers visited a website, received an email, or interacted with a brand, and decided whether it appeared credible. Today they still make those decisions, but they are no longer the only ones making them.</p><p>Search engines, AI assistants, and automated systems increasingly evaluate trust signals on behalf of users. Roughly two-thirds of Google searches now end without a click, according to Similarweb clickstream data analyzed by SparkToro. Trust is no longer just a customer's perception; it is becoming part of how businesses get discovered.</p><p>Credibility is no longer determined solely by what customers see. Domain resolution, certificate validity, email authentication records, and the consistency of businesses’ online presence all feed into the assessments that influence search rankings, AI-generated recommendations, and discovery across the platforms customers use every day. A business that doesn’t deliver on these fronts may be overlooked long before a customer ever decides whether to trust it.</p><h2 id="trust-and-security-are-now-competitive-infrastructure">Trust and security are now competitive infrastructure</h2><p>For decades, businesses viewed security as a defensive function, meant to reduce risk and respond to threats. That perspective is changing.</p><p>Trust and security now influence customer acquisition, retention, reputation, and long-term growth. In the <a href="https://www.techradar.com/best/best-ai-tools">AI</a> era, trust is no longer just a security outcome. It is a business strategy. As AI accelerates both innovation and risk, customers have become more selective about who they engage with and where they share their information. Credibility is difficult to earn and almost impossible to buy back once lost.</p><p>At Network Solutions, we have spent decades helping businesses establish and protect their digital identities. One lesson remains consistent: investing in trust early creates advantages competitors struggle to replicate.</p><p>Businesses that stand out in the years ahead won't simply adopt more AI. They'll build trust into every layer of their digital presence. The business owner who took that call from a customer deserved a better security infrastructure, not a better incident response after the fact.</p><p>Technology will continue to evolve, and so will the threats. Trust will only become more valuable. The businesses that thrive won't simply adopt more AI; they'll build stronger foundations for trust. That's where our industry needs to go next.</p><p><em></em><a href="https://www.techradar.com/news/the-best-free-website-builder"><em>We've listed the best free website builders</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-is-making-cyber-threats-faster-but-trust-will-define-which-businesses-survive</link>
                                                                            <description>
                            <![CDATA[ AI exposes forgotten digital risks, but trust determines who earns customers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rjWsC9qPQ3tDUr7vdY2jQE</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 13:04:56 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sachin Puri ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone malware]]></media:description>                                                            <media:text><![CDATA[Phone malware]]></media:text>
                                <media:title type="plain"><![CDATA[Phone malware]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/YQaVTQE6JAfu6bvPgwmd5U-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>A small business owner receives a call from a customer. </p><p>An email that appeared to come from the business led the customer to a fraudulent <a href="https://www.techradar.com/news/the-best-website-builder">website</a>, and their personal information may have been compromised. </p><p>What makes situations like this so damaging is that the owner never knew the risk existed. </p><p>The domain used in the attack had been registered for a campaign years earlier and left quietly active, sitting outside anyone's management, until someone else found a use for it.</p><p>Situations like this rarely begin with a major <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach. More often they start with something small: a forgotten domain, an outdated email configuration, or a digital asset nobody realized was still active. </p><p>AI makes finding those unnoticed weaknesses all too easy for attackers. According to KnowBe4's 2025 Phishing Threat Trends Report, 82.6% of phishing emails now show some use of AI, a 53.5% increase year-over-year. Attackers are adopting the same <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> businesses use to improve efficiency, and the speed advantage has shifted. The good news is that businesses can use the same advances in AI to identify many of these risks before attackers do.</p><p>But the speed of detection is only part of the challenge. The harder problem is visibility. You can't secure what you don't know you own.</p><p>More and more, small businesses manage <a href="https://www.techradar.com/news/best-domain-registrars">domain names</a>, websites, email systems, social channels, and third-party tools, and as those layers expand, the gaps between ownership and oversight become easier to miss. </p><p>Forgotten domains are a common example. Domains created for promotions, campaigns, or discontinued services often stay active long after their purpose disappears. Left unmanaged, they become blind spots that attackers exploit through phishing, impersonation, and brand abuse, and they can quietly erode credibility well before any breach, since a domain that no longer resolves correctly signals neglect to customers and machines alike.</p><p>Simply put, many business owners no longer have a complete view of the digital assets they own or the vulnerabilities that come with them.</p><h2 id="security-needs-to-be-embedded-not-bolted-on">Security needs to be embedded, not bolted on</h2><p>Small business owners are focused on serving customers, growing revenue, and running their businesses. They are not thinking about <a href="https://www.techradar.com/news/best-dns-server">DNS</a> records, certificate renewals, or dormant subdomains during their day. Nor should they have to.</p><p>But many do not have the option. According to VikingCloud's 2026 research, 84% of SMB owners manage cybersecurity themselves, often without dedicated training or expertise. </p><p>The most effective security strategies are built into the infrastructure which businesses depend on every day, rather than added after problems arise. There are three layers where this matters most: the domain, which serves as a business' identity online; the website, where customers form opinions about credibility and trustworthiness; and <a href="https://www.techradar.com/news/best-email-provider">email</a>, which remains one of the most important channels for customer communication and one of the most common targets for impersonation and fraud.</p><p>Embedding security into the solutions businesses already use helps them maintain visibility and confidence without constant manual oversight of all of those moving parts.</p><h2 id="trust-is-now-measured-by-both-people-and-machines">Trust is now measured by both people and machines</h2><p>Today’s <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> conversation always comes back to trust. That’s what SMBs want to win by securing their online business. It is the engine of their success.</p><p>We know that trust is one of the most important competitive advantages a business can have: according to McKinsey reporting on digital trust, 40% of consumers have completely pulled their business from a company after discovering the organization was reckless with customer data, and 10% of consumers will cut ties with a brand immediately upon learning of a data breach, regardless of whether their own personal information was actually compromised or stolen.</p><p>For years, trust online was primarily a human judgment. Customers visited a website, received an email, or interacted with a brand, and decided whether it appeared credible. Today they still make those decisions, but they are no longer the only ones making them.</p><p>Search engines, AI assistants, and automated systems increasingly evaluate trust signals on behalf of users. Roughly two-thirds of Google searches now end without a click, according to Similarweb clickstream data analyzed by SparkToro. Trust is no longer just a customer's perception; it is becoming part of how businesses get discovered.</p><p>Credibility is no longer determined solely by what customers see. Domain resolution, certificate validity, email authentication records, and the consistency of businesses’ online presence all feed into the assessments that influence search rankings, AI-generated recommendations, and discovery across the platforms customers use every day. A business that doesn’t deliver on these fronts may be overlooked long before a customer ever decides whether to trust it.</p><h2 id="trust-and-security-are-now-competitive-infrastructure">Trust and security are now competitive infrastructure</h2><p>For decades, businesses viewed security as a defensive function, meant to reduce risk and respond to threats. That perspective is changing.</p><p>Trust and security now influence customer acquisition, retention, reputation, and long-term growth. In the <a href="https://www.techradar.com/best/best-ai-tools">AI</a> era, trust is no longer just a security outcome. It is a business strategy. As AI accelerates both innovation and risk, customers have become more selective about who they engage with and where they share their information. Credibility is difficult to earn and almost impossible to buy back once lost.</p><p>At Network Solutions, we have spent decades helping businesses establish and protect their digital identities. One lesson remains consistent: investing in trust early creates advantages competitors struggle to replicate.</p><p>Businesses that stand out in the years ahead won't simply adopt more AI. They'll build trust into every layer of their digital presence. The business owner who took that call from a customer deserved a better security infrastructure, not a better incident response after the fact.</p><p>Technology will continue to evolve, and so will the threats. Trust will only become more valuable. The businesses that thrive won't simply adopt more AI; they'll build stronger foundations for trust. That's where our industry needs to go next.</p><p><em></em><a href="https://www.techradar.com/news/the-best-free-website-builder"><em>We've listed the best free website builders</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ AI agents are inside the enterprise – are your security foundations ready for them? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The recent release of Anthropic Mythos is a wake-up call for the tech industry – and the fact that Anthropic themselves chose not to release it publicly speaks volumes about the level of risk we have now reached. AI agents have evolved from <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbots</a> with upgraded capabilities to effective employees with <a href="https://www.techradar.com/best/best-database-software">database</a> access, API keys, and system privileges.</p><p>However, the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> protecting them is built on the same strategy that failed to stop ChatGPT jailbreaks in 2023. And this time, there’s no human to review an agent’s output, just an autonomous agent carrying out commands in a silo.</p><p>AI agents are reshaping enterprise systems and the way work gets done. Securing them requires an equally fundamental shift in thinking. Ultimately, now that agents act independently, resilience must be rooted in foundational controls, including hardware-level and lower-stack security, to be ready when the higher-level safeguards fail.</p><h2 id="how-ai-agents-expand-the-attack-surface">How AI agents expand the attack surface</h2><p>Before agentic AI, the biggest AI risks were bad recommendations, inappropriate responses, and conversational data exposure. Human oversight acted as a safeguard for every action, and AI systems operated without direct access to sensitive information. The primary concern was reputational damage rather than risks to underlying <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>.</p><p>When Anthropic released the Model Context Protocol (MCP) in November 2024, it established a standardized framework that allows AI agents to connect to databases, file systems, and enterprise tools. But within eight months, a critical vulnerability emerged (CVE-2025-49596, CVSS9.4), triggering emergency security responses across the industry.</p><p>The risk came from four factors working together. Autonomy means agents can decide and act without human review. Privileged access gives them credentials, tokens and file system permissions. Machine-speed execution leaves little time for human intervention. And cross-system reach means one compromised agent can move across connected environments.</p><p>Together, these factors expanded the attack surface far beyond what traditional security controls – even AI-enabled ones – were built to manage.</p><h2 id="why-software-only-defences-keep-falling-short">Why software-only defences keep falling short</h2><p>The industry is moving quickly to secure AI agents, but the response largely mirrors a familiar approach: adding more layers of <a href="https://www.techradar.com/best/best-small-business-software">software</a>. Most companies are focusing on two main layers: input guardrails – implementing more software tools designed to stop malicious instructions from ever reaching AI agents, and permissions and monitoring – limiting what compromised agents can access.</p><p>It’s the same strategy the industry had relied on for decades: deploy quickly, remain agile, and address vulnerabilities as they emerge. Both methods operate inside the software trust boundary.</p><p>But history shows this approach often ends the same way: with the need for hardware-layer protections. In the 1990s and 2000s, network security responded to software exploits by deploying additional software layers. Breaches persisted until organizations eventually adopted hardware-enforced network segmentation.</p><p>The same pattern played out with endpoint security in the 2000s and 2010s. As malware evolved to bypass detection, the response was behavioral analysis, sandboxing, and endpoint detection and response. Yet more software. Breaches continued until TPM (Trust Platform Module) chips and hardware-enforced secure boot became widely adopted. <a href="https://www.techradar.com/uk/best/best-cloud-storage">Cloud</a> security, in the 2010s and 2020s, followed a similar path.</p><p>A common lesson runs through each of these domains: when the software trust boundary is compromised, the hardware layer – where data actually lives – must be secured too.</p><h2 id="the-case-for-hardware-level-security">The case for hardware-level security</h2><p>This time, we cannot afford to learn slowly. Agents are already being connected to the systems that <a href="https://www.techradar.com/news/best-business-laptops">business</a> rely on for their daily operations. Incidents like the MCP critical vulnerability and recent reports of a data leak caused by a Meta AI agent show how quickly the risks can become real.</p><p>Guardrails, permissions, and monitoring are necessary, but they are insufficient, and they represent the security layers that history shows will eventually be bypassed. Effective defense requires a third layer – one that exists beyond the software trust boundary and provides oversight at the hardware level, where sensitive data is ultimately stored and processed.</p><p>Hardware Root of Trust serves as the final security barrier, helping contain breaches before they escalate into a full system compromise. As the number of companies using AI agents continues to grow, security needs to move deeper than the application layer.</p><p>The industry has already learned that software alone cannot secure complex systems – it should not wait for a major compromise to learn the same lesson again.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/ai-agents-are-inside-the-enterprise-are-your-security-foundations-ready-for-them</link>
                                                                            <description>
                            <![CDATA[ How AI agents are exposing the need for hardware-level security foundations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cv4mtV4XvRUK6YcpZ6GRQL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 10:30:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Camellia Chan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The recent release of Anthropic Mythos is a wake-up call for the tech industry – and the fact that Anthropic themselves chose not to release it publicly speaks volumes about the level of risk we have now reached. AI agents have evolved from <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbots</a> with upgraded capabilities to effective employees with <a href="https://www.techradar.com/best/best-database-software">database</a> access, API keys, and system privileges.</p><p>However, the <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> protecting them is built on the same strategy that failed to stop ChatGPT jailbreaks in 2023. And this time, there’s no human to review an agent’s output, just an autonomous agent carrying out commands in a silo.</p><p>AI agents are reshaping enterprise systems and the way work gets done. Securing them requires an equally fundamental shift in thinking. Ultimately, now that agents act independently, resilience must be rooted in foundational controls, including hardware-level and lower-stack security, to be ready when the higher-level safeguards fail.</p><h2 id="how-ai-agents-expand-the-attack-surface">How AI agents expand the attack surface</h2><p>Before agentic AI, the biggest AI risks were bad recommendations, inappropriate responses, and conversational data exposure. Human oversight acted as a safeguard for every action, and AI systems operated without direct access to sensitive information. The primary concern was reputational damage rather than risks to underlying <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>.</p><p>When Anthropic released the Model Context Protocol (MCP) in November 2024, it established a standardized framework that allows AI agents to connect to databases, file systems, and enterprise tools. But within eight months, a critical vulnerability emerged (CVE-2025-49596, CVSS9.4), triggering emergency security responses across the industry.</p><p>The risk came from four factors working together. Autonomy means agents can decide and act without human review. Privileged access gives them credentials, tokens and file system permissions. Machine-speed execution leaves little time for human intervention. And cross-system reach means one compromised agent can move across connected environments.</p><p>Together, these factors expanded the attack surface far beyond what traditional security controls – even AI-enabled ones – were built to manage.</p><h2 id="why-software-only-defences-keep-falling-short">Why software-only defences keep falling short</h2><p>The industry is moving quickly to secure AI agents, but the response largely mirrors a familiar approach: adding more layers of <a href="https://www.techradar.com/best/best-small-business-software">software</a>. Most companies are focusing on two main layers: input guardrails – implementing more software tools designed to stop malicious instructions from ever reaching AI agents, and permissions and monitoring – limiting what compromised agents can access.</p><p>It’s the same strategy the industry had relied on for decades: deploy quickly, remain agile, and address vulnerabilities as they emerge. Both methods operate inside the software trust boundary.</p><p>But history shows this approach often ends the same way: with the need for hardware-layer protections. In the 1990s and 2000s, network security responded to software exploits by deploying additional software layers. Breaches persisted until organizations eventually adopted hardware-enforced network segmentation.</p><p>The same pattern played out with endpoint security in the 2000s and 2010s. As malware evolved to bypass detection, the response was behavioral analysis, sandboxing, and endpoint detection and response. Yet more software. Breaches continued until TPM (Trust Platform Module) chips and hardware-enforced secure boot became widely adopted. <a href="https://www.techradar.com/uk/best/best-cloud-storage">Cloud</a> security, in the 2010s and 2020s, followed a similar path.</p><p>A common lesson runs through each of these domains: when the software trust boundary is compromised, the hardware layer – where data actually lives – must be secured too.</p><h2 id="the-case-for-hardware-level-security">The case for hardware-level security</h2><p>This time, we cannot afford to learn slowly. Agents are already being connected to the systems that <a href="https://www.techradar.com/news/best-business-laptops">business</a> rely on for their daily operations. Incidents like the MCP critical vulnerability and recent reports of a data leak caused by a Meta AI agent show how quickly the risks can become real.</p><p>Guardrails, permissions, and monitoring are necessary, but they are insufficient, and they represent the security layers that history shows will eventually be bypassed. Effective defense requires a third layer – one that exists beyond the software trust boundary and provides oversight at the hardware level, where sensitive data is ultimately stored and processed.</p><p>Hardware Root of Trust serves as the final security barrier, helping contain breaches before they escalate into a full system compromise. As the number of companies using AI agents continues to grow, security needs to move deeper than the application layer.</p><p>The industry has already learned that software alone cannot secure complex systems – it should not wait for a major compromise to learn the same lesson again.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Beware the token trap: Why saving on inference might put your ADLC at risk ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Agentic AI’s prolific use of tokens can create sizeable, unexpected costs for organizations. But saving on token costs without factoring in risk can be a fatal step.  </p><p>As upfront prices for flagship <a href="https://www.techradar.com/phones/best-ai-phone">artificial intelligence</a> models continue to shrink, organizations have begun to wise up to the hidden costs they encounter with agentic AI models.</p><p>Specifically, the costs of tokens, which may look tiny when viewed as individual charges, can add up exponentially as AI agents become more active, leaving organizations with hefty AI expenditures they may not have anticipated.  </p><p>This is putting CISOs in something of a bind. If they seek to save money on inference costs, primarily driven by token generation incurred by agentic AI, they may increase their security risk and accumulate hidden technical debt that puts their Agentic Development Lifecycle (ADLC) in jeopardy. It’s a problem that many CISOs may not have factored into their security budgets, but it cannot be left unaddressed.</p><p>The effectiveness of automated security processes is being impeded by fragmented pricing across the AI landscape, whether we’re talking about hyper-optimized nano models (essentially lightweight, yet powerful models built for a specific use, like Google’s Nano Banana 2 image generator) or premium reasoning engines, like Salesforce Atlas or OpenAI o3. </p><p>Organizations do have to keep a close eye on token costs to prevent them from spiraling, but CISOs also need to examine how agentic AI is affecting their <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><h2 id="the-hidden-costs-of-ai-agents">The hidden costs of AI agents</h2><p>Erratic pricing has been a trademark of generative AI pretty much from the beginning.  </p><p>About two years after OpenAI released ChatGPT, the Chinese company DeepSeek shook up the AI market with the release of a powerful, open-weighted large language model whose training parameters were publicly available, allowing users to customize the model and build on the cheap compared with other generative AI models. </p><p>ChatGPT-maker OpenAI and other AI companies started doing the same, and suddenly, the costs of using GenAI systems dropped off a cliff. In fact, prices fell faster for GenAI than for any other technology in history.</p><p>The emergence of agentic AI has introduced some stealth costs into the equation, however. The costs of agentic software range from free for <a href="https://www.techradar.com/best/the-best-open-source-crm-of-year">open-source</a> models to enterprise agents, with prices that vary from one-time fees (roughly $15,000 for basic models to more than $1 million for global enterprise models) to monthly subscriptions (which can range from a few thousand to $13,000 or more).</p><p>But those costs are fixed. Inference costs are another story: they scale with usage and can amount to 90% of AI lifecycle costs. </p><p>Tokens come into play when an AI agent requests processing from GenAI models, which charge agents for processing information. At a glance, the costs may appear inconsequential. Input tokens generally range from 15 cents to $5 per million requests. Output tokens, which require slightly more processing, cost from about 60 cents to $25 per million.</p><p>They may start small, but can add up in no time, thanks to AI agents that work very quickly, autonomously, and unpredictably. They are designed to interact with systems and other agents throughout the enterprise. A single action might generate scores of LLM calls. Token use, which has grown exponentially with the use of AI agents, has already increased IT budgets by about 20% according to recent estimates.</p><p>The accelerating cost of agentic AI is prompting CISOs to look for ways to save money where they can, and one way is to identify <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLMs</a> that charge the least per token. But what they may not be considering are the risk factors associated with those LLMs. If CISOs concern themselves only with the costs, they may open themselves up to security risks.</p><p>But better security doesn’t necessarily have to cost more. Depending on what they’re using agentic AI for, they may find they don’t always have to trade security for lower token costs. </p><h2 id="getting-costs-and-risks-under-control">Getting costs (and risks) under control</h2><p>There are a few things organizations can do to help stop token costs from getting out of hand, including:</p><p>Match Agents and LLMs to the Job at Hand. Commodity AI systems can cost little or nothing, but they lack the deep reasoning for complex security synthesis. But not every application or function within the organization requires a reasoning engine. You can set up agents to work with low-cost LLMs on low-risk projects, while preserving higher-cost LLMs for critical tasks. It’s also worth being aware of which agents are likely to request more LLM calls.</p><p>Factor Risk Scores in Choosing Agents and LLMs. The security implications of using AI can’t be ignored. When developing a budget plan, include risk factors.</p><p>Monitor Workflows. Keeping a close watch on workflows can help you track costs and performance, allowing you to better understand which tools work best in which situations.</p><p>Lean on Human Oversight. Despite agentic AI’s autonomy, in fact, because of agentic AI’s autonomy, forgetting about the importance of the human element is risky business. Teams need thorough upskilling in secure development, with clearly defined ownership roles. And they must be given prominent oversight roles throughout the ADLC.</p><p>Agentic AI is fast becoming integral to enterprise operations, and organizations must control its associated costs. But a race to the bottom on token pricing creates hidden technical debt. Instead, CISOs need to weigh security performance when choosing <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> as part of establishing an up-to-date security maturity model and an AI governance policy that emphasizes performance, costs, and risk <a href="https://www.techradar.com/best/it-management-tools">management</a>.</p><p>Only that approach allows agentic AI to be deployed without either breaking the budget or putting your entire organization at risk.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/beware-the-token-trap-why-saving-on-inference-might-put-your-adlc-at-risk</link>
                                                                            <description>
                            <![CDATA[ Saving on token costs without factoring in risk can be a fatal step. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">yV7Rm3gzNFF6xcfugivXJ4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 14 Aug 2026 09:57:27 +0000</pubDate>                                                                                                                                <updated>Fri, 14 Aug 2026 09:57:55 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Pieter Danhieux ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Agentic AI’s prolific use of tokens can create sizeable, unexpected costs for organizations. But saving on token costs without factoring in risk can be a fatal step.  </p><p>As upfront prices for flagship <a href="https://www.techradar.com/phones/best-ai-phone">artificial intelligence</a> models continue to shrink, organizations have begun to wise up to the hidden costs they encounter with agentic AI models.</p><p>Specifically, the costs of tokens, which may look tiny when viewed as individual charges, can add up exponentially as AI agents become more active, leaving organizations with hefty AI expenditures they may not have anticipated.  </p><p>This is putting CISOs in something of a bind. If they seek to save money on inference costs, primarily driven by token generation incurred by agentic AI, they may increase their security risk and accumulate hidden technical debt that puts their Agentic Development Lifecycle (ADLC) in jeopardy. It’s a problem that many CISOs may not have factored into their security budgets, but it cannot be left unaddressed.</p><p>The effectiveness of automated security processes is being impeded by fragmented pricing across the AI landscape, whether we’re talking about hyper-optimized nano models (essentially lightweight, yet powerful models built for a specific use, like Google’s Nano Banana 2 image generator) or premium reasoning engines, like Salesforce Atlas or OpenAI o3. </p><p>Organizations do have to keep a close eye on token costs to prevent them from spiraling, but CISOs also need to examine how agentic AI is affecting their <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><h2 id="the-hidden-costs-of-ai-agents">The hidden costs of AI agents</h2><p>Erratic pricing has been a trademark of generative AI pretty much from the beginning.  </p><p>About two years after OpenAI released ChatGPT, the Chinese company DeepSeek shook up the AI market with the release of a powerful, open-weighted large language model whose training parameters were publicly available, allowing users to customize the model and build on the cheap compared with other generative AI models. </p><p>ChatGPT-maker OpenAI and other AI companies started doing the same, and suddenly, the costs of using GenAI systems dropped off a cliff. In fact, prices fell faster for GenAI than for any other technology in history.</p><p>The emergence of agentic AI has introduced some stealth costs into the equation, however. The costs of agentic software range from free for <a href="https://www.techradar.com/best/the-best-open-source-crm-of-year">open-source</a> models to enterprise agents, with prices that vary from one-time fees (roughly $15,000 for basic models to more than $1 million for global enterprise models) to monthly subscriptions (which can range from a few thousand to $13,000 or more).</p><p>But those costs are fixed. Inference costs are another story: they scale with usage and can amount to 90% of AI lifecycle costs. </p><p>Tokens come into play when an AI agent requests processing from GenAI models, which charge agents for processing information. At a glance, the costs may appear inconsequential. Input tokens generally range from 15 cents to $5 per million requests. Output tokens, which require slightly more processing, cost from about 60 cents to $25 per million.</p><p>They may start small, but can add up in no time, thanks to AI agents that work very quickly, autonomously, and unpredictably. They are designed to interact with systems and other agents throughout the enterprise. A single action might generate scores of LLM calls. Token use, which has grown exponentially with the use of AI agents, has already increased IT budgets by about 20% according to recent estimates.</p><p>The accelerating cost of agentic AI is prompting CISOs to look for ways to save money where they can, and one way is to identify <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLMs</a> that charge the least per token. But what they may not be considering are the risk factors associated with those LLMs. If CISOs concern themselves only with the costs, they may open themselves up to security risks.</p><p>But better security doesn’t necessarily have to cost more. Depending on what they’re using agentic AI for, they may find they don’t always have to trade security for lower token costs. </p><h2 id="getting-costs-and-risks-under-control">Getting costs (and risks) under control</h2><p>There are a few things organizations can do to help stop token costs from getting out of hand, including:</p><p>Match Agents and LLMs to the Job at Hand. Commodity AI systems can cost little or nothing, but they lack the deep reasoning for complex security synthesis. But not every application or function within the organization requires a reasoning engine. You can set up agents to work with low-cost LLMs on low-risk projects, while preserving higher-cost LLMs for critical tasks. It’s also worth being aware of which agents are likely to request more LLM calls.</p><p>Factor Risk Scores in Choosing Agents and LLMs. The security implications of using AI can’t be ignored. When developing a budget plan, include risk factors.</p><p>Monitor Workflows. Keeping a close watch on workflows can help you track costs and performance, allowing you to better understand which tools work best in which situations.</p><p>Lean on Human Oversight. Despite agentic AI’s autonomy, in fact, because of agentic AI’s autonomy, forgetting about the importance of the human element is risky business. Teams need thorough upskilling in secure development, with clearly defined ownership roles. And they must be given prominent oversight roles throughout the ADLC.</p><p>Agentic AI is fast becoming integral to enterprise operations, and organizations must control its associated costs. But a race to the bottom on token pricing creates hidden technical debt. Instead, CISOs need to weigh security performance when choosing <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> as part of establishing an up-to-date security maturity model and an AI governance policy that emphasizes performance, costs, and risk <a href="https://www.techradar.com/best/it-management-tools">management</a>.</p><p>Only that approach allows agentic AI to be deployed without either breaking the budget or putting your entire organization at risk.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-website-builder"><em>We've featured the best AI website builder.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World-first autonomous ‘end-to-end’ AI attack against Taiwan tied to Chinese hackers — and the scariest part is that it was fully open source ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/world-first-autonomous-end-to-end-ai-attack-against-taiwan-tied-to-chinese-hackers-and-the-scariest-part-is-that-it-was-fully-open-source</link>
                                                                            <description>
                            <![CDATA[ China implicated in Taiwan attack through written documentation recovered from the attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HxPDT8x5CyBeVeFNd79h3E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:description>                                                            <media:text><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:text>
                                <media:title type="plain"><![CDATA[A Chinese military facility with multiple computers visible on a desk, with a large Chinese flag in the background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UQyjwYkZut5eDweL2vKmvb-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>China launched a fully autonomous vulnerability hunting attack against Taiwan</strong></li><li><strong>The attack leveraged eight open-source AI models to hunt for new attack vectors</strong></li><li><strong>The attack hit Taiwan government accounts, personnel records, the nuclear safety agency, and more</strong></li></ul><p>A first-of-its-kind cyberattack using autonomous AI has been spotted attacking Taiwan, and it compromised 85 government accounts and stole over 2,500 personnel records before moving on to hit the country’s nuclear safety agency and at least seven energy companies.</p><p>The attack used eight open-source AI models to build a hacking program that was able to independently conduct reconnaissance and intrusion, and was able to chain vulnerabilities and change tactics whenever it was blocked.</p><p>The intrusion took place over the course of four days, and was first exposed by <a href="https://www.ft.com/content/7d2ab3e0-9085-48f6-b38a-d90260d58795?syn-25a6b1a6=1" target="_blank" rel="nofollow"><em>The Financial Times</em></a> on August 12, 2026. The FT article covered research performed by Dream, an Israeli AI and cyberdefense company that first identified the breach.</p><h2 id="autonomous-ai-attack">Autonomous AI attack</h2><p>The attack was first uncovered during routine monitoring of cyber criminal activity. Dream found a 160MB online archive of 1,395 files. Further examination of the files revealed that the attack relied on Hermes and OpenClaw - two open-source AI agents.</p><p>As is typical of attacks relying on AI models, the hackers had framed the context of the intrusion as a routine cyber readiness test in order to bypass the built-in guardrails of the AI models.</p><p>The attack used multiple agents to hunt for new vulnerabilities and access points across the internet, providing the tool with multiple attack paths to take if one failed to gain entry.</p><p>AI agents have been quickly integrated into the attacks of cybercriminal organizations and state-sponsored threat actors alike, enhancing their abilities to launch highly complex attacks at scale. “This must be the basic assumption of every government around the globe,” said Amir Becker, Dream's chief strategy officer.</p><p>Dream did not tie the attack to any specific cybercriminal group, nor did it confirm the target of the attack, but said it had alerted a government in the “Asia-Pacific.” Documentation within the recovered archive contained Simplified Chinese, which is the official written language used in mainland China. </p><p>The archive also contained data collected from the targets, which was written in Traditional Chinese. This form of written Chinese is widely used in Taiwan, Hong Kong, and Macau.</p><p>Taiwan's Ministry of Digital Affairs has refused to comment on the breach, and the Chinese authorities have not responded to requests for comment.</p><p>China has long considered Taiwan to be a part of mainland China. Taiwan declared its independence following the end of the Chinese Civil War in 1949. A report from Taiwan’s National Security Bureau earlier this year revealed that the country was subject to <a href="https://www.techradar.com/pro/security/taiwanese-infrastructure-suffered-over-2-5-million-chinese-cyberattacks-per-day-in-2025-report-reveals">2.5 million Chinese cyberattacks per day in 2025</a>.</p><h2 id="expert-perspective-on-autonomous-ai-attack">Expert perspective on autonomous AI attack</h2><p><strong>Collin Hogue-Spears, senior director of solution management at Black Duck:</strong></p><p><em>The agents ran the intrusion end to end and invented nothing new to run it with. Familiar identity and API failures opened every confirmed path into Taiwan's systems. Dream Research Labs documented up to eight subagents working concurrently across twelve waves, ranking attack paths, redirecting when a technique failed, and researching alternatives online before trying again.</em></p><p><em>What they found was exposed development endpoints, an API accepting authentication tokens with the signature check disabled, unauthenticated data APIs, and passwords built from employee ID numbers.</em></p><p><em>The framework also ran its own AI static analysis hunting unknown flaws, but Dream says it worked against two public single sign-on SDK sample projects, and none of those findings produced a confirmed exploit on the live systems. No zero-day appears anywhere in the report, but a nuclear safety regulator does.</em></p><p><em>In conventional web and identity logs, this reads as a security scan. The distinguishing signal is the sequence across systems, not any single request. The tell is not the request. It is what the same account does next, somewhere else.</em></p><p><em>Conventional scanners have tested thousands of endpoints at machine speed for twenty years, so raw coverage is not the change here. What Dream Research Labs describes is chaining: password spraying, then fresh SSO sessions, then access to routes an account had never touched, then the same suspected weakness retested until it held, then one identity surfacing across several connected applications.</em></p><div><blockquote><p>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities.</p></blockquote></div><p><em>Simplified Chinese in the operator's notes is one signal. Traditional Chinese in the stolen files is just Taiwan. Dream rested its China assessment on a code-switching observation, and only half of it points at the attacker. Per Chinese-language coverage of the report, Simplified characters appeared in the operators' internal communications and Traditional characters appeared in the exfiltrated data. The first describes the operator's working language. The second describes the victim, because that is what Taiwanese government files look like [Traditional Characters].</em></p><p><em>The evidence therefore supports a Chinese Mainland-language operator against a Taiwanese target, with a target profile consistent with mainland collection priorities. It does not name a group or establish state direction. The report also publishes no indicators, no hashes, and no victim confirmation; it does not identify the model, and its executive summary claims installed backdoors while its own attack chain says authentication blocked the web shell.</em></p><p><em>Security leaders must reject unsigned authentication tokens and prohibit the alg:none setting outright, and separately require reauthentication or multi-factor at any single sign-on boundary into a sensitive system. Dream describes two independent identity failures in Taiwan, and closing one leaves the other open. Provider guardrails cannot compensate for a password-only SSO bridge.</em></p><p><em>They must also monitor route diversity per source, per session, per account, and per device rather than by request rate alone, because a distributed set of agents spreads requests across addresses and sessions that no single volume threshold catches. If your detection assumes one attacker at one address working one path at a time, you have modeled the wrong shape.</em></p><p><em>Your thresholds were built for one attacker on one path. This was eight, in parallel. And they must ask two questions of any AI attack disclosure before acting on it: which model ran the operation, and what can we hunt on tomorrow morning?"</em></p><p>Via <a href="https://united24media.com/world/researchers-say-china-likely-linked-to-unprecedented-autonomous-ai-attack-on-taiwan-21623" target="_blank" rel="nofollow"><em>United24</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft's nemesis returns: Nightmare Eclipse is back with a new zero day which could be bad news for Windows users ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑day</strong></li><li><strong>Flaw bypasses a recent patch and works on fully updated Windows 11 systems</strong></li><li><strong>Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched</strong></li></ul><p>Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.</p><p>The newest flaw is called ShieldBreak, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches. </p><p>“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate,” Nightmare Eclipse <a href="https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main/ShieldBreak.cpp" target="_blank" rel="nofollow">said</a> on their GitHub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”</p><h2 id="a-bypass-for-the-rogueplanet-fix">A bypass for the RoguePlanet fix</h2><p>The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called RoguePlanet.</p><p>“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” the GitHub read entry.</p><p>Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">vulnerability</a> disclosure”. </p><p>In response to an enquiry by <a href="https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889" target="_blank"><em>The Register</em></a>, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."</p><p>"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."</p><h2 id="a-hacker-on-a-mission">A hacker on a mission</h2><p>Together with ShieldBreak, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated BlueHammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed BlueHammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure. </p><p>Just before publishing the work, they <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" target="_blank" rel="nofollow">said</a> “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”</p><p>At first, Microsoft took a tough stance, calling the public release “<a href="https://therecord.media/microsoft-says-it-will-not-pursue-security-researchers-disclosure" target="_blank">never justifiable</a>” and even warning that it might pursue legal cases against people who put customers at risk.</p><p>The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”</p><p>In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released RedSun and UnDefend (both targeting Defender), YellowKey (a BitLocker bypass), GreenPlasma (a CTFMON-based privilege-escalation flaw), MiniPlasma (a regression of a vulnerability Microsoft had originally fixed in 2020), RoguePlanet (another Defender privilege-escalation bug), GreatXML (a BitLocker/Windows Recovery Environment bypass), LegacyHive (a Windows User Profile Service privilege-escalation flaw), and now ShieldBreak. </p><p>BlueHammer was fixed in April, RedSun and UnDefend in May, and YellowKey, GreenPlasma, and MiniPlasma, in June. RoguePlanet was patched in July, while LegacyHive, GreatXML, and ShieldBreak, remain unpatched. </p><p>It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For GreenPlasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components. </p><p>ShieldBreak, however, seems to be more dangerous in that respect. Speaking to <em>The Register</em>, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication. </p><p>He also said that while ShieldBreak was described as a bypass for the RoguePlanet fix, the two flaws actually operated quite differently. </p><p>“RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”</p><p>No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/microsofts-nemesis-returns-nightmare-eclipse-is-back-with-a-new-zero-day-which-could-be-bad-news-for-windows-users</link>
                                                                            <description>
                            <![CDATA[ This is the tenth zero-day the disgruntled researcher disclosed, and yet another released soon after a Patch Tuesday. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y9Ed8CXdbTCPjPE5PcQuC6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 16:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Är du ute efter bästa VPN för Windows 10 och Windwos 11? Här är våra favoriter just nu.]]></media:description>                                                            <media:text><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:text>
                                <media:title type="plain"><![CDATA[Fingertip pressing keyboard key with Windows logo on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/iGi8rqmXBTK3ZPbi4ExzfW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Nightmare Eclipse discloses ShieldBreak, a new Windows privilege‑escalation zero‑day</strong></li><li><strong>Flaw bypasses a recent patch and works on fully updated Windows 11 systems</strong></li><li><strong>Researcher’s ongoing exploit spree leaves multiple Windows vulnerabilities still unpatched</strong></li></ul><p>Nightmare Eclipse has struck again! The notorious zero-day researcher with a Microsoft grudge disclosed its latest vulnerability, and just as in previous instances, they picked their timing and released their research hours after Microsoft published its August Patch Tuesday cumulative update in order to maximize the hurt.</p><p>The newest flaw is called ShieldBreak, and is described as a local escalation of privilege vulnerability that allows threat actors to gain SYSTEM-level privileges on vulnerable systems. Speaking of vulnerable systems, the list is rather long because it includes all versions of Windows 11, including those with the latest security patches. </p><p>“The PoC was tested in the latest version of windows 11 25h2 (+Canary channel) and windows server 2025, the PoC also have a 100% success rate,” Nightmare Eclipse <a href="https://git.projectnightcrawler.dev/NightmareEclipse/ShieldBreak/src/branch/main/ShieldBreak.cpp" target="_blank" rel="nofollow">said</a> on their GitHub account. “Please note that Windows 10 (and respective server editions) are not currently supported, they are however vulnerable to ShieldBreak as well.”</p><h2 id="a-bypass-for-the-rogueplanet-fix">A bypass for the RoguePlanet fix</h2><p>The mysterious attacker also said that the bug was actually a bypass for the patch Microsoft issued to fix their earlier work, called RoguePlanet.</p><p>“Microsoft has failed to properly patch the RoguePlanet vulnerability CVE-2026-50656, this PoC demonstrates a full patch bypass,” the GitHub read entry.</p><p>Microsoft, on the other hand, responded in pure enterprise fashion, sharing a boilerplate statement that it was “investigating” and that it “supports coordinated <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">vulnerability</a> disclosure”. </p><p>In response to an enquiry by <a href="https://www.theregister.com/cyber-crime/2026/08/12/microsoft-vendetta-hacker-has-a-new-zero-day-that-gives-system-privileges-on-fully-patched-windows/5286889" target="_blank"><em>The Register</em></a>, a company spokesperson said Microsoft "is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims."</p><p>"Microsoft is committed to investigating security issues and updating impacted products to protect customers as soon as possible,” the statement reads. “Importantly, we support coordinated vulnerability disclosure, an industry standard that protects customers and supports the research community by ensuring their findings are thoroughly investigated and addressed before being made public."</p><h2 id="a-hacker-on-a-mission">A hacker on a mission</h2><p>Together with ShieldBreak, the number of disclosed Windows vulnerabilities and exploits now counts 10. Nightmare Eclipse’s campaign began in April 2026, when they demonstrated BlueHammer, a Windows Defender local privilege-escalation flaw that gives low-privileged users SYSTEM-level access. The researcher claimed BlueHammer, now tracked as CVE-2026-33825, was previously reported to Microsoft, but the company allegedly mishandled the disclosure. </p><p>Just before publishing the work, they <a href="https://arstechnica.com/security/2026/06/locked-in-heated-rivalry-with-researcher-microsoft-fixes-0-day-they-disclosed/" target="_blank" rel="nofollow">said</a> “someone violated our agreement and left me homeless with nothing. They knew this will happen and they still stabbed me in the back anyways, this is their decision not mine.”</p><p>At first, Microsoft took a tough stance, calling the public release “<a href="https://therecord.media/microsoft-says-it-will-not-pursue-security-researchers-disclosure" target="_blank">never justifiable</a>” and even warning that it might pursue legal cases against people who put customers at risk.</p><p>The community interpreted this statement as a threat of legal action against Nightmare Eclipse, which triggered a backlash. Microsoft later backed away, saying “to be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”</p><p>In the meantime, Nightmare Eclipse (also known as Chaotic Eclipse) went on a full-blown rampage. They released RedSun and UnDefend (both targeting Defender), YellowKey (a BitLocker bypass), GreenPlasma (a CTFMON-based privilege-escalation flaw), MiniPlasma (a regression of a vulnerability Microsoft had originally fixed in 2020), RoguePlanet (another Defender privilege-escalation bug), GreatXML (a BitLocker/Windows Recovery Environment bypass), LegacyHive (a Windows User Profile Service privilege-escalation flaw), and now ShieldBreak. </p><p>BlueHammer was fixed in April, RedSun and UnDefend in May, and YellowKey, GreenPlasma, and MiniPlasma, in June. RoguePlanet was patched in July, while LegacyHive, GreatXML, and ShieldBreak, remain unpatched. </p><p>It is also worth mentioning that not all of Nightmare Eclipse’s releases were equally complete or reproducible by third parties. For GreenPlasma, independent researchers said it contained the vulnerability but turning it into a reliable working exploit required significant additional technical work. Some of the early Defender exploits were also apparently difficult to reproduce, mostly because they relied on delicate race conditions and very specific sequences of Windows components. </p><p>ShieldBreak, however, seems to be more dangerous in that respect. Speaking to <em>The Register</em>, security researcher Kevin Beaumont confirmed it as working: “I've tried it, it works on latest Windows 11,” he told the publication. </p><p>He also said that while ShieldBreak was described as a bypass for the RoguePlanet fix, the two flaws actually operated quite differently. </p><p>“RoguePlanet was a filesystem race condition vuln that uses virtual disks and NT native file manipulation to trick quarantine process into overwriting system files,” Beaumont explained. “ShieldBreak user-mode callback hook to change file contents during a Defender cloud-hydration scan via cfapi (Cloud Filter API).”</p><p>No one knows how much ammunition Nightmare Eclipse still has, but we will certainly be paying attention to them in the hours after next month’s Patch Tuesday, as well. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Android users targeted by new WindRelay malware which can clone contactless cards in just 13 minutes ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/android-users-targeted-by-new-windrelay-malware-which-can-clone-contactless-cards-in-just-13-minutes</link>
                                                                            <description>
                            <![CDATA[ Crooks are calling victims on the phone and installing POS malware on their smartphones. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">shwHxntyNEjscciJEjL9Li</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg">
                                                            <media:credit><![CDATA[Rapeepong Puttakumwong via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Person pays using POS hardware card reader]]></media:description>                                                            <media:text><![CDATA[Person pays using POS hardware card reader]]></media:text>
                                <media:title type="plain"><![CDATA[Person pays using POS hardware card reader]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5kMrDAjQJGcdHytVASFjn5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WindRelay campaign used vishing plus custom malware to turn phones into POS skimmers</strong></li><li><strong>Victims installed personalized RATs and NFC malware, enabling real‑time card theft</strong></li><li><strong>Attacks were highly targeted across Eastern Europe, with only a few individuals hit</strong></li></ul><p>Hackers are turning people’s smartphones into malicious <a href="https://www.techradar.com/news/the-best-pos-system" target="_blank">Point of Sale</a> (POS) devices and stealing their money directly from their payment cards, experts have warned. </p><p>Security researchers Group-IB spotted multiple such attacks across Eastern Europe, and named the campaign <a href="https://www.group-ib.com/blog/windrelay-nfc-spynote-rat-combo-fraud/" target="_blank">WindRelay</a>, after the custom-built malware used during the attacks.</p><p>The report notes this is a highly sophisticated, custom-tailored attack designed specifically for the victim. It starts with some form of reconnaissance, in which the attackers learn their victim’s identity, phone number, and likely other details. Although the researchers don’t discuss it, it is quite possible that the attackers obtained (or purchased) the data from unrelated data breaches and leaks.</p><h2 id="vishing-and-malware">Vishing and malware</h2><p>After learning a little bit about their target, the attackers get to work. They first prepare a remote access trojan (RAT) named SpyNote. They personalize the label with the victim’s own name (instead of it being a generic or impersonated brand), to build trust with their victim:</p><p>“Such tactics are more effective at weakening a victim’s natural defenses and suspicions,” the researchers noted in the report. “It removes the one cue people are trained to check before installing something unfamiliar — a strange or generic app name — right at the moment they’re most likely to hesitate.”</p><p>Then, they call the victim on the phone and introduce themselves as employees of their target’s bank. They claim the victim has a problem with their bank card, and instruct them to deploy SpyNote through the device’s package installer (the standard way to sideload apps outside an official app store).</p><p>SpyNote is a classic RAT that the attackers then use to deploy stage-two malware themselves. In this next step, they personally (as opposed to having the victim do it) install WindRelay, custom near-field communication (NFC) malware designed to capture contactless payment card data in real-time, when a card is tapped against the phone. </p><p>In other words, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> turns the smartphone into a POS, and when a victim taps their card against it, the information is relayed to an attacker’s terminal. </p><h2 id="vishing-malware">Vishing + malware</h2><p>Vishing + malware combo is nothing new. We’ve seen it deployed numerous times before, and ShinyHunters are probably the shiniest example of the practice (pun definitely intended). Over the last couple of years, ShinyHunters have been calling their victims on the phone, impersonating the IT department, and getting their victims to log in via fake login portals which relay the credentials to the attackers.</p><p>They then use the credentials to access their victims’ SaaS products, exfiltrate as much sensitive data as possible, and then demand ransom in exchange for deleting the stolen files.</p><p>This new campaign, however, is a testament to the technique’s evolution. While ShinyHunters’ operatives only stay on the phone call until the victim logs in, these crooks remain on the line for as long as it takes. Group-IB says the average call lasts around 13 minutes, and by that moment, the victim will have installed both SpyNote and WindRelay, and has tapped their bank card against the phone, making unwanted payments.</p><p>In at least one case, the attackers successfully applied for a loan at the victim’s bank, stealing not only the money they had on their account, but also money they would have earned in the future.</p><p>The identity of the attackers is unknown at the time. We also don’t know exactly how many victims there were, but given the highly personalized nature of the attack, it’s safe to assume that there were only a handful.</p><p>Group-IB says it observed attacks in Czechia, Slovakia, and Slovenia, suggesting a threat actor focused primarily on Eastern European victims. The researchers also said they identified 23 samples uploaded to VirusTotal between November 2025 and July 2026, meaning the campaign was active for approximately seven months, targeting 23 individuals. </p><p>“The samples mimic various institutions from the targeted countries and contain text in the language of each targeted country,” the researchers said. “Some samples contain personalized UI elements and labels, such as the name of the victim, similar to the personalized RAT. This suggests the threat actor behind these campaigns most likely has the capability to dynamically build malicious applications tailored to individual victims.”</p><p>Group-IB says users should treat personalized app labels as a red flag and should apply extra friction to loan applications. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bad news: your AI application isn't that special ]]></title>
                                                                                                <dc:content><![CDATA[ <p>There are more than 70,000 <a href="https://www.techradar.com/best/best-ai-tools">AI</a> companies operating today. </p><p>Most of them will not exist in five years. </p><p>Before you can see why — or figure out whether yours is one of them — you need a distinction the market keeps blurring.</p><p>Strip away the pitch decks and there are really only two types of AI system being built today.</p><p>The first is AI infrastructure: the orchestration and governance technology that makes AI usable at scale. In plain terms, this is the plumbing — agent frameworks, model routing, evaluation and monitoring tools, guardrails, and the controls that let a large organization use AI safely. </p><p>It sits between the foundation models and the end user, and it is where an enormous amount of venture money is going right now.</p><p>The second is the surface application: the tool an actual person uses to do actual work. The underwriting assistant, the contract reviewer, the sales copilot. The thing with a login screen and a job to do.</p><p>What I see in the market is a blending of the two. Some firms are selling <a href="https://www.techradar.com/best/best-architecture-software">architecture</a>. </p><p>Some are selling tools. Many are trying to sell both, on the theory that owning the whole stack is the safest position. </p><p>And while this market is filled with tremendous exuberance with seemingly everyone starting an AI company, I am very skeptical that many of these firms will ever see profitability as history offers a strong counter. </p><p>We've run this experiment twice.</p><h2 id="the-past-and-the-future">The past and the future</h2><p>The dot-com era ran the first version of this experiment, and its final tally is worth stating plainly. Researchers estimate that roughly 50,000 <a href="https://www.techradar.com/best/the-best-crm-for-startups">startups</a> were founded in the United States between 1998 and 2002 to commercialize the internet. </p><p>Of those, something like 8,000 attracted venture funding. About 1,700 internet-related companies made it to an IPO across the whole era — 585 in 1999 and 2000 alone — and at the peak, only about 14 percent of the tech companies going public were profitable. </p><p>By late 2002, most internet stocks had lost more than three-quarters of their value and roughly 1.7 trillion dollars had been wiped out. And the number of enduring, large-scale winners from that entire cohort — Amazon, eBay, Priceline, Expedia — you can count on two hands. Run the funnel: 50,000 founded, 8,000 funded, 1,700 public, fewer than ten giants. </p><p>A real gold rush works the same way: a few strike it rich, some make a living, and most go home with less than they brought. This is important to remember for everything that follows.</p><p>If that funnel looks like a quirk of one bubble, it is not — it is how markets distribute winnings everywhere. Hendrik Bessembinder at Arizona State studied every U.S. stock since 1926, more than 25,000 companies, and found that the best-performing 4 percent account for all of the net wealth the stock market has ever created; the other 96 percent, taken together, did no better than Treasury bills. </p><p>Just 90 companies — a third of one percent — produced more than half of it, and the majority of stocks lost money outright over their lifetimes. The market wins; almost no individual company does. Keep that in mind every time someone tells you AI will create trillions in value. It will. That says nothing about whether any particular company captures a dime of it.</p><h2 id="the-example-of-cloud">The example of cloud</h2><p><a href="https://www.techradar.com/best/best-cloud-computing-services">Cloud computing</a> is the sharper rerun. In the early days there were hundreds of cloud providers and a thriving ecosystem of middleware companies selling the connective tissue — provisioning tools, management layers, monitoring platforms. </p><p>Today three companies control roughly two-thirds of the cloud market, and their share grows every year. </p><p>And here is the part that matters for AI: the middleware layer did not consolidate alongside the platforms. It was absorbed by them. The hyperscalers built the management consoles, the <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, the orchestration, and shipped it as a feature. The companies whose entire business was cloud plumbing were acquired cheap or squeezed out.</p><p>Meanwhile, the application layer on top of that consolidated <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> exploded. Thousands of SaaS companies built durable, profitable businesses without owning a single server. The bottom of the stack ended up in a few hands. The top produced thousands of winners.</p><h2 id="it-has-already-happened-once-inside-this-stack">It has already happened once inside this stack</h2><p>If cloud feels like ancient history, look at the data layer — the foundation every AI system sits on. That consolidation already occurred, and it finished recently. The "modern data stack" boom of the last decade funded hundreds of startups selling pipelines, catalogs, transformation tools, and warehouses. </p><p>Today the independent tier has settled to exactly two companies at scale: Snowflake and Databricks, each running at roughly five billion dollars in annual revenue, with the hyperscalers’ native offerings holding most of the rest of the market. Nearly everyone else was acquired, absorbed as a platform feature, or left scraping for the remainder.</p><p>And notice the shape it settled into. The top five data platforms — Snowflake, BigQuery, Redshift, Databricks, and Microsoft’s offering — hold roughly two-thirds of the market. That is almost exactly where cloud landed: three players, about two-thirds of the market, a long tail fighting over the rest. </p><p>Two different layers, a decade apart, ending in the same proportions. That is not a coincidence. It is what happens when competing takes huge capital and the platforms can build whatever sits next to them. Expect the AI orchestration layer to end up the same way.</p><p>The consolidation was driven as much by the buyer as by the vendors. Large enterprises learned that scattered data is expensive data: every additional platform meant another copy of the truth, another integration, another <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> review, another contract. </p><p>So CTOs stopped buying data tools one team at a time and started making strategic platform decisions — pick one or two providers, consolidate the estate onto them, and hold that line. A single source of truth became an explicit architectural goal at most large companies, and once thousands of enterprises were making that same decision, the market had no room left for a long tail of vendors.</p><p>Look at what it took for Snowflake and Databricks to survive that consolidation: enormous capital, the fact that customers’ data lives on their platforms and is costly to move, and deep ties into how their customers work every day. You can survive as an independent alongside the hyperscalers — but only by becoming one of the few names a CTO puts on the strategic list, and almost nobody makes that list.</p><h2 id="the-same-consolidation-is-coming-for-ai">The same consolidation is coming for AI</h2><p>Apply that pattern to the two types of AI company and the forecast writes itself.</p><p>The infrastructure layer — orchestration and governance — will consolidate down to a few. Not because the current tools are bad, but because this layer sits directly in the expansion path of the biggest players in technology. The model providers and hyperscalers have every incentive to build orchestration, evaluation, and governance into their platforms, and they are already doing it. Every capability that today justifies a standalone infrastructure startup is a roadmap item at a company with a hundred times the resources and a direct line to the same customers.</p><p>If you are building an architecture-only solution, this is the uncomfortable implication: you are likely to be taken out by one of the big players. Maybe you get acquired, if you are early and lucky. More often, the platform simply builds what you sell and includes it for free. Either way, orchestration and governance alone is not a <a href="https://www.techradar.com/best/best-business-plan-software">business</a> you can hold. The only real question is how long you have.</p><p>Which leaves the application layer as the open field. And this is the counterintuitive part: infrastructure consolidation is good news for application builders. When orchestration and governance become cheap, standardized, and built into the platforms, the cost of building a serious AI application collapses — just as commodity cloud ignited the SaaS boom. We are already seeing a massive increase in the number of AI applications getting built, and most will likely not survive.</p><h2 id="better-software-worse-odds">Better software, worse odds</h2><p>Part of what makes this cycle different is how little it costs to enter. Building serious software used to take millions in capital and a room full of engineers — a filter that limited how many companies could even try. Today a handful of people with AI tools can ship in weeks what took a funded startup a year. </p><p>So new ventures are multiplying, not because there are more good ideas, but because the cost of trying has collapsed. The scale tells the story: more than 70,000 AI companies operate globally today, roughly 18,000 to 30,000 of them in the United States alone. </p><p>The comparison to the dot-com era’s 50,000 is not perfectly apples to apples — that was a five-year founding total for one country, this is a snapshot of companies operating worldwide right now — but the order of magnitude is the same, this wave is global, and the count is still climbing.</p><p>Here is the twist that makes the coming shakeout more brutal, not less: the <a href="https://www.techradar.com/best/best-small-business-software">software</a> being built is genuinely good. This is not the dot-com era, where half-finished products hid behind splashy <a href="https://www.techradar.com/best/best-content-marketing-tools">marketing</a>. The tools are now so powerful that quality is the baseline — which means quality has stopped differentiating anything. When every product is polished, capable, and shipped fast, none of that separates you from the next founder who did the same thing last month. </p><p>And that is precisely why so few founders see the danger. Every one of them genuinely believes they are building something singular — and by their own measure, they are right. They compare their product to what came before: the clunky incumbent, the manual process, the way the work used to get done. Against that <a href="https://www.techradar.com/best/best-benchmarks-software">benchmark</a> it looks revolutionary. </p><p>What they never compare it to is the tens of thousands of other teams looking at the same models and the same problems, building virtually the same thing at the same time. Measured against the past, every AI product is remarkable. Measured against the field, almost none are. More entrants than either previous cycle, all building excellent software, almost none of it distinguishable. </p><p>That is the setup for the largest culling yet, and it will run almost entirely on the moats, because there is nothing else left to separate the winners from the losers.</p><h2 id="the-delusion-of-special">The delusion of special</h2><p>I see this up close. I have this conversation with application founders every week, and it always goes the same way. They believe the quality of what they built is their moat: the product works, customers love it, nothing else on the market feels as good. </p><p>All of that can be true, and none of it protects them. Quality can be copied. The same tools that let them build an excellent product in months let a competitor build one in weeks. A few founders have built something that truly stands alone, but I just can’t see many finding a way to real profitability.  </p><p>There will be some winners, but I think they will need to rest on three key differentiators:</p><p><strong>1. Data</strong>. Not data you scraped or licensed — proprietary data your business generates by operating: claims histories, transaction flows, patient outcomes. If your system gets smarter from data competitors cannot obtain at any price, you compound. If you are building on the same public internet as everyone else, you do not.</p><p><strong>2. Distribution</strong>. If you already own the customer relationship — an installed base, a trusted brand, an embedded sales channel — you can put an AI product in front of buyers faster and cheaper than any startup. This is why incumbents are more dangerous in this cycle than the last one. The startup has to build the product and buy the audience. The incumbent only has to build the product.</p><p><strong>3. Integration into workflows</strong>. The one people underestimate. Companies that wire themselves into how work actually gets done — the approvals, the systems of record, the daily habits of thousands of employees — become painful to remove even when a rival ships something better. Switching costs are not glamorous, but they have protected enterprise software for thirty years, and they will protect AI applications too.</p><p>Have one of these and you can build a durable business on commodity infrastructure. Have two and you can build a great one. Have none and you are likely running out of time.</p><h2 id="your-toughest-competitor-is-your-customer">Your toughest competitor is your customer</h2><p>And here is what makes the application layer even harder than the dot-com or SaaS eras: surface applications are not just competing with other vendors. They are competing with the companies they are trying to sell to. The same commodity infrastructure that makes it easy for a startup to spin up an AI application makes it just as easy for the buyer to build one internally. </p><p>Every enterprise pitch now runs into a question that barely existed in the SaaS era: why would we buy this when a small internal team could build it in a quarter?</p><p>And here is the uncomfortable part. The three advantages that decide the application winners — distribution, proprietary data, embedded workflows — are precisely what the buyer already has. The enterprise owns its data. It is its own distribution. It controls its own workflows. The customer starts the build-versus-buy conversation holding every moat you are trying to claim. </p><p>A surface application does not just need to be better than its competitors. It needs to be so much better than what the customer could build themselves that buying beats owning — and that bar rises every time the underlying infrastructure gets easier to use.</p><h2 id="know-which-company-you-are">Know which company you are</h2><p>I am not going to pretend to know which specific firms win. But the structure of the outcome is already visible, because we have now watched it three times — dot-com, cloud, and the data layer: infrastructure consolidates to a few, applications proliferate, and the survivors are the ones holding data, distribution, or workflow integration that cannot be copied.</p><p>So the first question is not "is my product good?" It is "which of the two companies am I?" If you are infrastructure, your realistic endgame is being bought or being bypassed — plan accordingly. If you are an application, the model is not your moat and the product probably is not either.</p><p>So what is?</p><h2 id="the-good-news-and-who-gets-it">The good news, and who gets it</h2><p>One clarification before closing, because everything above can read as pessimism about AI itself. It is the opposite. The technology will create enormous value, and the markets built on it will grow. The open question is who keeps that value, and a century of evidence gives a consistent answer: mostly the consumers of a technology, not its producers. </p><p>William Nordhaus at Yale measured this across decades of American innovation and found that producers capture only about 2 percent of the total value their innovations create — the rest flows to the people and businesses that use them. Railroads transformed the economy and ruined most of their investors. Airlines moved the world and destroyed capital for a hundred years. The internet made a handful of platforms rich — and made every company that deployed it more productive. </p><p>This cycle is already tracing the same shape: the infrastructure layer consolidates, prices its scarcity, and books historic profits, while the application layer competes and hands its margin to the buyer.</p><p>That is the real ending of this story. The coming massacre of AI companies and the coming growth of the AI economy are the same event, seen from opposite sides of the table. If you sell AI, the funnel is your problem and the moats are your only defense. </p><p>If you buy AI, the competition among 70,000 firms is working precisely in your favor: every improvement, every price cut, every copied feature moves value from their side of the table to yours. The bad news in this article is only bad depending on which chair you sit in.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We've reviewed, rated, and ranked the best business cloud storage</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/bad-news-your-ai-application-isnt-that-special</link>
                                                                            <description>
                            <![CDATA[ The AI massacre is coming, and knowing which side of the stack you're on will decide whether you survive it. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eHLUZAbXTkXznrbUAxNgqW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 14:40:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Jeff McMillan ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There are more than 70,000 <a href="https://www.techradar.com/best/best-ai-tools">AI</a> companies operating today. </p><p>Most of them will not exist in five years. </p><p>Before you can see why — or figure out whether yours is one of them — you need a distinction the market keeps blurring.</p><p>Strip away the pitch decks and there are really only two types of AI system being built today.</p><p>The first is AI infrastructure: the orchestration and governance technology that makes AI usable at scale. In plain terms, this is the plumbing — agent frameworks, model routing, evaluation and monitoring tools, guardrails, and the controls that let a large organization use AI safely. </p><p>It sits between the foundation models and the end user, and it is where an enormous amount of venture money is going right now.</p><p>The second is the surface application: the tool an actual person uses to do actual work. The underwriting assistant, the contract reviewer, the sales copilot. The thing with a login screen and a job to do.</p><p>What I see in the market is a blending of the two. Some firms are selling <a href="https://www.techradar.com/best/best-architecture-software">architecture</a>. </p><p>Some are selling tools. Many are trying to sell both, on the theory that owning the whole stack is the safest position. </p><p>And while this market is filled with tremendous exuberance with seemingly everyone starting an AI company, I am very skeptical that many of these firms will ever see profitability as history offers a strong counter. </p><p>We've run this experiment twice.</p><h2 id="the-past-and-the-future">The past and the future</h2><p>The dot-com era ran the first version of this experiment, and its final tally is worth stating plainly. Researchers estimate that roughly 50,000 <a href="https://www.techradar.com/best/the-best-crm-for-startups">startups</a> were founded in the United States between 1998 and 2002 to commercialize the internet. </p><p>Of those, something like 8,000 attracted venture funding. About 1,700 internet-related companies made it to an IPO across the whole era — 585 in 1999 and 2000 alone — and at the peak, only about 14 percent of the tech companies going public were profitable. </p><p>By late 2002, most internet stocks had lost more than three-quarters of their value and roughly 1.7 trillion dollars had been wiped out. And the number of enduring, large-scale winners from that entire cohort — Amazon, eBay, Priceline, Expedia — you can count on two hands. Run the funnel: 50,000 founded, 8,000 funded, 1,700 public, fewer than ten giants. </p><p>A real gold rush works the same way: a few strike it rich, some make a living, and most go home with less than they brought. This is important to remember for everything that follows.</p><p>If that funnel looks like a quirk of one bubble, it is not — it is how markets distribute winnings everywhere. Hendrik Bessembinder at Arizona State studied every U.S. stock since 1926, more than 25,000 companies, and found that the best-performing 4 percent account for all of the net wealth the stock market has ever created; the other 96 percent, taken together, did no better than Treasury bills. </p><p>Just 90 companies — a third of one percent — produced more than half of it, and the majority of stocks lost money outright over their lifetimes. The market wins; almost no individual company does. Keep that in mind every time someone tells you AI will create trillions in value. It will. That says nothing about whether any particular company captures a dime of it.</p><h2 id="the-example-of-cloud">The example of cloud</h2><p><a href="https://www.techradar.com/best/best-cloud-computing-services">Cloud computing</a> is the sharper rerun. In the early days there were hundreds of cloud providers and a thriving ecosystem of middleware companies selling the connective tissue — provisioning tools, management layers, monitoring platforms. </p><p>Today three companies control roughly two-thirds of the cloud market, and their share grows every year. </p><p>And here is the part that matters for AI: the middleware layer did not consolidate alongside the platforms. It was absorbed by them. The hyperscalers built the management consoles, the <a href="https://www.techradar.com/best/best-network-monitoring-tools">monitoring</a>, the orchestration, and shipped it as a feature. The companies whose entire business was cloud plumbing were acquired cheap or squeezed out.</p><p>Meanwhile, the application layer on top of that consolidated <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> exploded. Thousands of SaaS companies built durable, profitable businesses without owning a single server. The bottom of the stack ended up in a few hands. The top produced thousands of winners.</p><h2 id="it-has-already-happened-once-inside-this-stack">It has already happened once inside this stack</h2><p>If cloud feels like ancient history, look at the data layer — the foundation every AI system sits on. That consolidation already occurred, and it finished recently. The "modern data stack" boom of the last decade funded hundreds of startups selling pipelines, catalogs, transformation tools, and warehouses. </p><p>Today the independent tier has settled to exactly two companies at scale: Snowflake and Databricks, each running at roughly five billion dollars in annual revenue, with the hyperscalers’ native offerings holding most of the rest of the market. Nearly everyone else was acquired, absorbed as a platform feature, or left scraping for the remainder.</p><p>And notice the shape it settled into. The top five data platforms — Snowflake, BigQuery, Redshift, Databricks, and Microsoft’s offering — hold roughly two-thirds of the market. That is almost exactly where cloud landed: three players, about two-thirds of the market, a long tail fighting over the rest. </p><p>Two different layers, a decade apart, ending in the same proportions. That is not a coincidence. It is what happens when competing takes huge capital and the platforms can build whatever sits next to them. Expect the AI orchestration layer to end up the same way.</p><p>The consolidation was driven as much by the buyer as by the vendors. Large enterprises learned that scattered data is expensive data: every additional platform meant another copy of the truth, another integration, another <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> review, another contract. </p><p>So CTOs stopped buying data tools one team at a time and started making strategic platform decisions — pick one or two providers, consolidate the estate onto them, and hold that line. A single source of truth became an explicit architectural goal at most large companies, and once thousands of enterprises were making that same decision, the market had no room left for a long tail of vendors.</p><p>Look at what it took for Snowflake and Databricks to survive that consolidation: enormous capital, the fact that customers’ data lives on their platforms and is costly to move, and deep ties into how their customers work every day. You can survive as an independent alongside the hyperscalers — but only by becoming one of the few names a CTO puts on the strategic list, and almost nobody makes that list.</p><h2 id="the-same-consolidation-is-coming-for-ai">The same consolidation is coming for AI</h2><p>Apply that pattern to the two types of AI company and the forecast writes itself.</p><p>The infrastructure layer — orchestration and governance — will consolidate down to a few. Not because the current tools are bad, but because this layer sits directly in the expansion path of the biggest players in technology. The model providers and hyperscalers have every incentive to build orchestration, evaluation, and governance into their platforms, and they are already doing it. Every capability that today justifies a standalone infrastructure startup is a roadmap item at a company with a hundred times the resources and a direct line to the same customers.</p><p>If you are building an architecture-only solution, this is the uncomfortable implication: you are likely to be taken out by one of the big players. Maybe you get acquired, if you are early and lucky. More often, the platform simply builds what you sell and includes it for free. Either way, orchestration and governance alone is not a <a href="https://www.techradar.com/best/best-business-plan-software">business</a> you can hold. The only real question is how long you have.</p><p>Which leaves the application layer as the open field. And this is the counterintuitive part: infrastructure consolidation is good news for application builders. When orchestration and governance become cheap, standardized, and built into the platforms, the cost of building a serious AI application collapses — just as commodity cloud ignited the SaaS boom. We are already seeing a massive increase in the number of AI applications getting built, and most will likely not survive.</p><h2 id="better-software-worse-odds">Better software, worse odds</h2><p>Part of what makes this cycle different is how little it costs to enter. Building serious software used to take millions in capital and a room full of engineers — a filter that limited how many companies could even try. Today a handful of people with AI tools can ship in weeks what took a funded startup a year. </p><p>So new ventures are multiplying, not because there are more good ideas, but because the cost of trying has collapsed. The scale tells the story: more than 70,000 AI companies operate globally today, roughly 18,000 to 30,000 of them in the United States alone. </p><p>The comparison to the dot-com era’s 50,000 is not perfectly apples to apples — that was a five-year founding total for one country, this is a snapshot of companies operating worldwide right now — but the order of magnitude is the same, this wave is global, and the count is still climbing.</p><p>Here is the twist that makes the coming shakeout more brutal, not less: the <a href="https://www.techradar.com/best/best-small-business-software">software</a> being built is genuinely good. This is not the dot-com era, where half-finished products hid behind splashy <a href="https://www.techradar.com/best/best-content-marketing-tools">marketing</a>. The tools are now so powerful that quality is the baseline — which means quality has stopped differentiating anything. When every product is polished, capable, and shipped fast, none of that separates you from the next founder who did the same thing last month. </p><p>And that is precisely why so few founders see the danger. Every one of them genuinely believes they are building something singular — and by their own measure, they are right. They compare their product to what came before: the clunky incumbent, the manual process, the way the work used to get done. Against that <a href="https://www.techradar.com/best/best-benchmarks-software">benchmark</a> it looks revolutionary. </p><p>What they never compare it to is the tens of thousands of other teams looking at the same models and the same problems, building virtually the same thing at the same time. Measured against the past, every AI product is remarkable. Measured against the field, almost none are. More entrants than either previous cycle, all building excellent software, almost none of it distinguishable. </p><p>That is the setup for the largest culling yet, and it will run almost entirely on the moats, because there is nothing else left to separate the winners from the losers.</p><h2 id="the-delusion-of-special">The delusion of special</h2><p>I see this up close. I have this conversation with application founders every week, and it always goes the same way. They believe the quality of what they built is their moat: the product works, customers love it, nothing else on the market feels as good. </p><p>All of that can be true, and none of it protects them. Quality can be copied. The same tools that let them build an excellent product in months let a competitor build one in weeks. A few founders have built something that truly stands alone, but I just can’t see many finding a way to real profitability.  </p><p>There will be some winners, but I think they will need to rest on three key differentiators:</p><p><strong>1. Data</strong>. Not data you scraped or licensed — proprietary data your business generates by operating: claims histories, transaction flows, patient outcomes. If your system gets smarter from data competitors cannot obtain at any price, you compound. If you are building on the same public internet as everyone else, you do not.</p><p><strong>2. Distribution</strong>. If you already own the customer relationship — an installed base, a trusted brand, an embedded sales channel — you can put an AI product in front of buyers faster and cheaper than any startup. This is why incumbents are more dangerous in this cycle than the last one. The startup has to build the product and buy the audience. The incumbent only has to build the product.</p><p><strong>3. Integration into workflows</strong>. The one people underestimate. Companies that wire themselves into how work actually gets done — the approvals, the systems of record, the daily habits of thousands of employees — become painful to remove even when a rival ships something better. Switching costs are not glamorous, but they have protected enterprise software for thirty years, and they will protect AI applications too.</p><p>Have one of these and you can build a durable business on commodity infrastructure. Have two and you can build a great one. Have none and you are likely running out of time.</p><h2 id="your-toughest-competitor-is-your-customer">Your toughest competitor is your customer</h2><p>And here is what makes the application layer even harder than the dot-com or SaaS eras: surface applications are not just competing with other vendors. They are competing with the companies they are trying to sell to. The same commodity infrastructure that makes it easy for a startup to spin up an AI application makes it just as easy for the buyer to build one internally. </p><p>Every enterprise pitch now runs into a question that barely existed in the SaaS era: why would we buy this when a small internal team could build it in a quarter?</p><p>And here is the uncomfortable part. The three advantages that decide the application winners — distribution, proprietary data, embedded workflows — are precisely what the buyer already has. The enterprise owns its data. It is its own distribution. It controls its own workflows. The customer starts the build-versus-buy conversation holding every moat you are trying to claim. </p><p>A surface application does not just need to be better than its competitors. It needs to be so much better than what the customer could build themselves that buying beats owning — and that bar rises every time the underlying infrastructure gets easier to use.</p><h2 id="know-which-company-you-are">Know which company you are</h2><p>I am not going to pretend to know which specific firms win. But the structure of the outcome is already visible, because we have now watched it three times — dot-com, cloud, and the data layer: infrastructure consolidates to a few, applications proliferate, and the survivors are the ones holding data, distribution, or workflow integration that cannot be copied.</p><p>So the first question is not "is my product good?" It is "which of the two companies am I?" If you are infrastructure, your realistic endgame is being bought or being bypassed — plan accordingly. If you are an application, the model is not your moat and the product probably is not either.</p><p>So what is?</p><h2 id="the-good-news-and-who-gets-it">The good news, and who gets it</h2><p>One clarification before closing, because everything above can read as pessimism about AI itself. It is the opposite. The technology will create enormous value, and the markets built on it will grow. The open question is who keeps that value, and a century of evidence gives a consistent answer: mostly the consumers of a technology, not its producers. </p><p>William Nordhaus at Yale measured this across decades of American innovation and found that producers capture only about 2 percent of the total value their innovations create — the rest flows to the people and businesses that use them. Railroads transformed the economy and ruined most of their investors. Airlines moved the world and destroyed capital for a hundred years. The internet made a handful of platforms rich — and made every company that deployed it more productive. </p><p>This cycle is already tracing the same shape: the infrastructure layer consolidates, prices its scarcity, and books historic profits, while the application layer competes and hands its margin to the buyer.</p><p>That is the real ending of this story. The coming massacre of AI companies and the coming growth of the AI economy are the same event, seen from opposite sides of the table. If you sell AI, the funnel is your problem and the moats are your only defense. </p><p>If you buy AI, the competition among 70,000 firms is working precisely in your favor: every improvement, every price cut, every copied feature moves value from their side of the table to yours. The bad news in this article is only bad depending on which chair you sit in.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We've reviewed, rated, and ranked the best business cloud storage</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Trump signs memo calling for cyber privateers to conduct cyberattacks abroad against criminal groups targeting Americans — but they have to escrow $1 million to join ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/trump-signs-memo-calling-for-cyber-privateers-to-conduct-cyberattacks-abroad-against-criminal-groups-targeting-americans-but-they-have-to-escrow-usd1-million-to-join</link>
                                                                            <description>
                            <![CDATA[ Private companies will be legally allowed to conduct cyberattacks against foreign groups on behalf of the US government. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">utyNFb8pS4FFJvAbLae83g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 12:05:00 +0000</pubDate>                                                                                                                                <updated>Thu, 13 Aug 2026 12:52:56 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:description>                                                            <media:text><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:text>
                                <media:title type="plain"><![CDATA[An image of a digitized skull and crossbones symbolizing hacking and cyberattacks overlayed on a background of digital glitches and noise.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/zTH6vPrB4yxX7dzdy29Xga-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US government to allow private firms to conduct legal cyberattacks on foreign organizations targeting Americans</strong></li><li><strong>Firms will be allowed to disrupt and destroy physical and virtual information systems and networks</strong></li><li><strong>US victims of cyber scams and fraud lose around $20,000</strong></li></ul><p>President Trump has signed a <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/" target="_blank" rel="nofollow">memo</a> which allows private US firms to partner with the US government in operations designed to surveille and disrupt Transnational Criminal Organizations (TCOs).</p><p>According to the memo, the partnership “will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” essentially turning private companies into privateers with the ability to launch cyber attacks against foreign entities.</p><p>The memo marks a significant shift in how the US tackles foreign cybercrime. “American businesses’ innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace,” the memo states. But what does this actually mean in practice?</p><h2 id="us-to-leverage-private-sector-for-cyber-defense">US to leverage private sector for cyber defense</h2><p>The US is the most targeted country in the world for cyber attacks and cybercrime, with <a href="https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit">6.7 million victims losing $138.9 billion in the last year</a>, placing the average loss per-victim at around $20,731.</p><p>The program will effectively create a global cyber surveillance network that acts as an early warning system against attacks targeting critical national infrastructure, such as the recent <a href="https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers">Iranian attacks targeting over 30 US water systems</a>. Private companies that “discover an imminent cyber-attack against United States critical infrastructure” will be required to notify the National Coordination Center (NCC).</p><p>The US government isn’t just looking to work alongside the big tech companies. Big companies will be part of the picture to “provide critical capacity,” but smaller companies will also have the opportunity to become involved with the program as they are “more agile,” and “may be better suited for specialized or discrete tasks.”</p><p>When a threat is detected, private companies will put together a “cyber operations package” to be reviewed and approved by the Program Executive Directors. These packages will likely include plans for surveillance and offensive cyber operations.</p><p>Private companies looking to become part of the program will be vetted according to government guidelines, and will have to operate within a set of operating procedures under the oversight of the federal government. “No operation may be approved unless it complies with these operating procedures,” the memo says.</p><p>There is however a caveat that those involved within the program must “maintain a bond or escrow in an amount not less than $1 million,” which would be forfeit should a private company “enter non‑compliance with its contractual agreement.”</p><p>The memo also sets our parameters to prevent private companies from accidentally or intentionally targeting US citizens, or US information systems at home and abroad, with the company required to “cease such operation, conduct minimization procedures, and immediately notify the NCC,” in the event that a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation”.</p><p>Additionally, “any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government”.</p><p>The memo is the latest step in the Trump administration’s efforts to allow private companies to legally launch cyberattacks on behalf of the US government. “The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States,” the memo states.</p><p>The program will also put together a report on its progress every year, as well as reviewing the performance of each private company within the program within the same time frame.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why employees, not threat actors, are 2026’s biggest risk ]]></title>
                                                                                                <dc:content><![CDATA[ <p>With all the buzz around nation-state threats, it’s easy for organizations to focus on threats outside the business – and forget about risks that can spiral outwards from within.</p><p>Whilst GenAI tools have introduced undeniable efficiencies for <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, these platforms have also introduced a new class of risk: two in three UK organizations admit they can’t track whether employees are sharing data via approved tools.</p><p>Most of the time, employees aren’t sharing sensitive data because they have malicious intentions. They are uploading sensitive information – like contracts, client proposals or supplier agreements to models like ChatGPT and Claude to save time on routine tasks.</p><p>Almost all (93%) of CEOs across the globe have adopted generative AI to some extent in the past 12 months (PwC). What’s concerning is that much of this activity is happening without any oversight, in the <a href="https://www.techradar.com/best/browser">browser</a> – meaning organizations are failing to track the flow of company information, including when and where it’s uploaded.   </p><p>This is spiraling into serious risk for businesses.</p><p>First, because employees may inadvertently share credentials or other access details with public LLMs, which could result in unauthorized access if the model is compromised.</p><p>Second, uploading personal <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> to LLMs can trigger compliance breaches with laws like GDPR and the Data Use and Access Act – resulting in costly fines as well as reputational damage.</p><p>To take control of this issue, leaders will need to implement tools and technologies that provide visibility and control over usage at both the browser and the application levels. </p><h2 id="the-incentive-problem">The incentive problem</h2><p>Employees don’t need more mandatory cybersecurity training – the problem is incentive. Many company-owned gated LLMs are still in the pilot stage, falling short of the speed and precision offered by public alternatives.</p><p>While the majority of employees understand the risks, 35% of UK <a href="https://www.techradar.com/best/best-small-business-software">businesses</a> admit data sharing through external tools takes place – indicating many would rather ‘throw caution to the wind’ than waste valuable time using slower tools.</p><p>But the risks of this behavior – particularly in highly regulated sectors like financial services, could mean unsanctioned LLMs become 'hidden icebergs’ in an organization. Concealed, but capable of causing catastrophic damage upon impact – like inadvertently exposing customer transaction histories or credit scores. </p><p>Part of curbing Shadow AI use in the enterprise therefore starts with designing approved AI tools that integrate easily with existing platforms (for example, Microsoft 365 and Google Workspace). These tools should be continuously improved based on user feedback, ideally avoiding excessive restrictions that make the tool frustrating to use.</p><p>But the fact is, nearly two-thirds of organizations are currently stuck in the pilot stage when it comes to their AI initiatives and haven’t started to scale across the enterprise (McKinsey). So, what can organizations do today to gain control of the Shadow AI problem?</p><h2 id="the-solution-tools-to-bring-unsanctioned-ai-usage-under-control">The solution – tools to bring unsanctioned AI usage under control </h2><p>You can’t control what you can’t see, which is why organizations need a real-time view of who, or what, is accessing what data, from which devices, and where it’s being shared.</p><p>Next-gen identity <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> platforms can help organizations to gain an immediate understanding of how employees interact with consumer AI tools like ChatGPT, Claude, and Gemini, tracking interaction frequency and monitoring document uploads.</p><p>Once high-risk behavior is identified, organizations can then automate corrective actions, redirect users to secure AI alternatives, or prompt users to justify their business use case before proceeding. </p><p>Visibility will become even more important with the emergence of ‘nested’ agents. In this scenario, employees might believe they’re only interacting with a single AI agent, but that <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbot</a> may delegate tasks to multiple underlying agents. The organization has no visibility into how many downstream agents or services its information is being shared with. </p><p>An identity security tool makes these identities ‘discoverable’ via a real-time ‘agent ledger’. This ledger acts as a complete, unchangeable trace of all agent activities and interactions. It also applies controls to each agent in the database.</p><p>Only the absolute minimum privilege required for a task is granted, at the exact moment it is needed, and for the shortest possible duration. In this way, agent permissions don’t automatically ‘cascade’. If an agent wants to connect with another agent, it must be verified by the system first.  </p><h2 id="closing-the-visibility-gap">Closing the visibility gap</h2><p>Shadow AI is more than a tooling problem: it’s an identity problem. Organizations can close the ‘visibility gap’ by using tools that track interaction frequency, block sensitive document uploads, and prompt employees as well as AI agents to justify their business case before they use unsanctioned tools.</p><p>Once organizations know which tools are being used, what data they're accessing, and where that information goes, they can apply effective guardrails to secure behaviors – both human and non-human. A simple inventory of AI agents is not enough; now, organizations need to move beyond flat inventories and develop an understanding of the context and relationships that surround every agent.</p><p>In essence, identity security platforms become adaptive – moving from static to dynamic, real-time approaches to access. This is helping organizations to operationalize zero trust by ensuring that no identity, human or non-human, is trusted by default. </p><p>In the era of AI agents, securing <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> has become a prerequisite for innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-employees-not-threat-actors-are-2026s-biggest-risk</link>
                                                                            <description>
                            <![CDATA[ Shadow AI is exposing businesses to hidden employee-led risks, demanding stronger identity security and visibility. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7wTNzGYJUFR6wQCijY6k9G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 09:48:16 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Bradford ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>With all the buzz around nation-state threats, it’s easy for organizations to focus on threats outside the business – and forget about risks that can spiral outwards from within.</p><p>Whilst GenAI tools have introduced undeniable efficiencies for <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, these platforms have also introduced a new class of risk: two in three UK organizations admit they can’t track whether employees are sharing data via approved tools.</p><p>Most of the time, employees aren’t sharing sensitive data because they have malicious intentions. They are uploading sensitive information – like contracts, client proposals or supplier agreements to models like ChatGPT and Claude to save time on routine tasks.</p><p>Almost all (93%) of CEOs across the globe have adopted generative AI to some extent in the past 12 months (PwC). What’s concerning is that much of this activity is happening without any oversight, in the <a href="https://www.techradar.com/best/browser">browser</a> – meaning organizations are failing to track the flow of company information, including when and where it’s uploaded.   </p><p>This is spiraling into serious risk for businesses.</p><p>First, because employees may inadvertently share credentials or other access details with public LLMs, which could result in unauthorized access if the model is compromised.</p><p>Second, uploading personal <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> to LLMs can trigger compliance breaches with laws like GDPR and the Data Use and Access Act – resulting in costly fines as well as reputational damage.</p><p>To take control of this issue, leaders will need to implement tools and technologies that provide visibility and control over usage at both the browser and the application levels. </p><h2 id="the-incentive-problem">The incentive problem</h2><p>Employees don’t need more mandatory cybersecurity training – the problem is incentive. Many company-owned gated LLMs are still in the pilot stage, falling short of the speed and precision offered by public alternatives.</p><p>While the majority of employees understand the risks, 35% of UK <a href="https://www.techradar.com/best/best-small-business-software">businesses</a> admit data sharing through external tools takes place – indicating many would rather ‘throw caution to the wind’ than waste valuable time using slower tools.</p><p>But the risks of this behavior – particularly in highly regulated sectors like financial services, could mean unsanctioned LLMs become 'hidden icebergs’ in an organization. Concealed, but capable of causing catastrophic damage upon impact – like inadvertently exposing customer transaction histories or credit scores. </p><p>Part of curbing Shadow AI use in the enterprise therefore starts with designing approved AI tools that integrate easily with existing platforms (for example, Microsoft 365 and Google Workspace). These tools should be continuously improved based on user feedback, ideally avoiding excessive restrictions that make the tool frustrating to use.</p><p>But the fact is, nearly two-thirds of organizations are currently stuck in the pilot stage when it comes to their AI initiatives and haven’t started to scale across the enterprise (McKinsey). So, what can organizations do today to gain control of the Shadow AI problem?</p><h2 id="the-solution-tools-to-bring-unsanctioned-ai-usage-under-control">The solution – tools to bring unsanctioned AI usage under control </h2><p>You can’t control what you can’t see, which is why organizations need a real-time view of who, or what, is accessing what data, from which devices, and where it’s being shared.</p><p>Next-gen identity <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> platforms can help organizations to gain an immediate understanding of how employees interact with consumer AI tools like ChatGPT, Claude, and Gemini, tracking interaction frequency and monitoring document uploads.</p><p>Once high-risk behavior is identified, organizations can then automate corrective actions, redirect users to secure AI alternatives, or prompt users to justify their business use case before proceeding. </p><p>Visibility will become even more important with the emergence of ‘nested’ agents. In this scenario, employees might believe they’re only interacting with a single AI agent, but that <a href="https://www.techradar.com/pro/best-ai-chatbot-for-business">chatbot</a> may delegate tasks to multiple underlying agents. The organization has no visibility into how many downstream agents or services its information is being shared with. </p><p>An identity security tool makes these identities ‘discoverable’ via a real-time ‘agent ledger’. This ledger acts as a complete, unchangeable trace of all agent activities and interactions. It also applies controls to each agent in the database.</p><p>Only the absolute minimum privilege required for a task is granted, at the exact moment it is needed, and for the shortest possible duration. In this way, agent permissions don’t automatically ‘cascade’. If an agent wants to connect with another agent, it must be verified by the system first.  </p><h2 id="closing-the-visibility-gap">Closing the visibility gap</h2><p>Shadow AI is more than a tooling problem: it’s an identity problem. Organizations can close the ‘visibility gap’ by using tools that track interaction frequency, block sensitive document uploads, and prompt employees as well as AI agents to justify their business case before they use unsanctioned tools.</p><p>Once organizations know which tools are being used, what data they're accessing, and where that information goes, they can apply effective guardrails to secure behaviors – both human and non-human. A simple inventory of AI agents is not enough; now, organizations need to move beyond flat inventories and develop an understanding of the context and relationships that surround every agent.</p><p>In essence, identity security platforms become adaptive – moving from static to dynamic, real-time approaches to access. This is helping organizations to operationalize zero trust by ensuring that no identity, human or non-human, is trusted by default. </p><p>In the era of AI agents, securing <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> has become a prerequisite for innovation.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Data sovereignty is more than a pin on a map ]]></title>
                                                                                                <dc:content><![CDATA[ <p>As governments and organizations rethink their reliance on foreign-owned <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a>, data sovereignty has become a boardroom priority. </p><p>However, the conversation has become overly focused on where data is stored, overlooking the legal, operational and resilience factors that determine whether organizations are truly in control.</p><p>Whether through misunderstanding or a deliberate attempt to mislead, the term data sovereignty is often misused.</p><p>Data residency and data sovereignty are being conflated, despite being very different. Data residency is about the physical location of data, while data sovereignty is much broader and also includes legal jurisdiction, operational control, resilience, governance and the ability to manage risk.</p><p>Concerns about dependence on foreign-owned digital infrastructure have brought added urgency to issues of digital independence and control over critical technology.</p><p>In response, various vendors - particularly the big US-based hyperscalers - are now repositioning themselves with “sovereign” alternatives based primarily on where they store customer data. </p><p>While this might address some of their customers’ needs, reducing sovereignty to a question of geography creates a misleadingly simple narrative: if an organization moves data to the “right” country, it will somehow become compliant. In reality, the core issue is not just where data should be hosted, but understanding who may seek access to it and who ultimately controls the infrastructure supporting it. </p><p>This misunderstanding is giving rise to what could be described as “data sovereignty washing”, with simplified claims that don't reflect legal or operational reality. </p><h2 id="data-sans-frontieres">Data sans frontières</h2><p>Governments the world over have well-established legal mechanisms for requesting information held in other jurisdictions. While data residency influences which laws apply and how requests are handled, it does not provide immunity from lawful access or eliminate international cooperation. </p><p>An example is the US CLOUD Act. Under certain conditions, it enables US authorities to request data from US service providers even when it is stored outside the United States. So, even if a UK or European-owned organization hosts data with a US-owned provider in a UK or European data center, it may still be reachable under US legal process. Being physically ‘local’ doesn’t change that. </p><p>The US is far from unique in this regard. Many other countries have legislation in place allowing authorities to access data for law enforcement or national security purposes, often supported by cross-border agreements and established legal processes. </p><p>The risk is that enterprises treat location as a complete sovereignty strategy, rather than one element of it. Threat actors care about the value of the data, not geography. As a result, organizations can spend significant time and money <a href="https://www.techradar.com/best/best-data-migration-tools">migrating data</a> to new locations while leaving their biggest <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> risks fundamentally unchanged. </p><p>A more useful starting point is to ask what risks the organization is actually trying to reduce. That shifts the focus and any subsequent changes in approach away from maps, and towards threat modelling, which provides the right context for meaningful conversations about sovereignty.</p><h2 id="start-with-the-threat-model">Start with the threat model</h2><p>Different organizations have fundamentally different threat models. A local retailer, a multinational bank, a defense contractor and a government department are unlikely to share the same priorities, even if they all process sensitive information. </p><p>For some organizations, regulatory compliance or data residency requirements may be the primary concern. For others, resilience against cyberattack, protection of intellectual property, or reducing dependence on a particular technology provider may be far more important. It’s generally a matter of sector-specific and business priorities. </p><p>So, rather than simply asking where data is stored, leaders should consider who ultimately controls the infrastructure, how dependent they are on individual <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a>, what happens if services become unavailable, and whether they retain sufficient visibility and control over critical systems. If any of this raises operational or regulatory concerns, it may be sensible to adjust strategy.</p><h2 id="the-resilience-paradox">The resilience paradox</h2><p>An unintended consequence of pursuing absolute data localization is that it can reduce resilience. Organizations often improve availability and <a href="https://www.techradar.com/best/best-data-recovery-service">data recovery</a> by maintaining geographically separate copies of critical data. Restricting everything to a single jurisdiction can reduce those options. </p><p>Decisions about sovereignty should therefore factor in availability, confidentiality, and integrity – all of which are important. The most effective approaches recognize that resilience sometimes requires carefully managed distribution rather than rigid localization. </p><p>Consider this scenario: an organization has ensured all their <a href="https://www.techradar.com/news/best-email-provider">email</a> is stored within a single jurisdiction to meet sovereignty objectives. Months later, their provider has a major outage in that one region, and they lose access to their email for days. Even worse, a serious data loss event affects their <a href="https://www.techradar.com/best/best-backup-software">backups</a>, which are also stored in the same region. If they had optimized for resilience instead, their data would have been safe and available throughout. </p><p>Even though the organization successfully addressed one aspect of sovereignty, they weakened another by reducing their ability to recover critical business information. That's ultimately the difference between treating sovereignty as a marketing claim and treating it as a genuine risk management exercise.</p><p><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/data-sovereignty-is-more-than-a-pin-on-a-map</link>
                                                                            <description>
                            <![CDATA[ Storing data locally won't guarantee sovereignty without governance, resilience and operational control. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">a3JZoFhZVMmYES4ZxKQdSY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/EXMLBYo5k7EwcuyYg9vmmM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 09:00:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Bron Gondwana ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/EXMLBYo5k7EwcuyYg9vmmM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A long corridor with a sleek black floor, glowing green lights in the ceiling and rows of LEDS on either wall]]></media:description>                                                            <media:text><![CDATA[A long corridor with a sleek black floor, glowing green lights in the ceiling and rows of LEDS on either wall]]></media:text>
                                <media:title type="plain"><![CDATA[A long corridor with a sleek black floor, glowing green lights in the ceiling and rows of LEDS on either wall]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/EXMLBYo5k7EwcuyYg9vmmM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>As governments and organizations rethink their reliance on foreign-owned <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a>, data sovereignty has become a boardroom priority. </p><p>However, the conversation has become overly focused on where data is stored, overlooking the legal, operational and resilience factors that determine whether organizations are truly in control.</p><p>Whether through misunderstanding or a deliberate attempt to mislead, the term data sovereignty is often misused.</p><p>Data residency and data sovereignty are being conflated, despite being very different. Data residency is about the physical location of data, while data sovereignty is much broader and also includes legal jurisdiction, operational control, resilience, governance and the ability to manage risk.</p><p>Concerns about dependence on foreign-owned digital infrastructure have brought added urgency to issues of digital independence and control over critical technology.</p><p>In response, various vendors - particularly the big US-based hyperscalers - are now repositioning themselves with “sovereign” alternatives based primarily on where they store customer data. </p><p>While this might address some of their customers’ needs, reducing sovereignty to a question of geography creates a misleadingly simple narrative: if an organization moves data to the “right” country, it will somehow become compliant. In reality, the core issue is not just where data should be hosted, but understanding who may seek access to it and who ultimately controls the infrastructure supporting it. </p><p>This misunderstanding is giving rise to what could be described as “data sovereignty washing”, with simplified claims that don't reflect legal or operational reality. </p><h2 id="data-sans-frontieres">Data sans frontières</h2><p>Governments the world over have well-established legal mechanisms for requesting information held in other jurisdictions. While data residency influences which laws apply and how requests are handled, it does not provide immunity from lawful access or eliminate international cooperation. </p><p>An example is the US CLOUD Act. Under certain conditions, it enables US authorities to request data from US service providers even when it is stored outside the United States. So, even if a UK or European-owned organization hosts data with a US-owned provider in a UK or European data center, it may still be reachable under US legal process. Being physically ‘local’ doesn’t change that. </p><p>The US is far from unique in this regard. Many other countries have legislation in place allowing authorities to access data for law enforcement or national security purposes, often supported by cross-border agreements and established legal processes. </p><p>The risk is that enterprises treat location as a complete sovereignty strategy, rather than one element of it. Threat actors care about the value of the data, not geography. As a result, organizations can spend significant time and money <a href="https://www.techradar.com/best/best-data-migration-tools">migrating data</a> to new locations while leaving their biggest <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> risks fundamentally unchanged. </p><p>A more useful starting point is to ask what risks the organization is actually trying to reduce. That shifts the focus and any subsequent changes in approach away from maps, and towards threat modelling, which provides the right context for meaningful conversations about sovereignty.</p><h2 id="start-with-the-threat-model">Start with the threat model</h2><p>Different organizations have fundamentally different threat models. A local retailer, a multinational bank, a defense contractor and a government department are unlikely to share the same priorities, even if they all process sensitive information. </p><p>For some organizations, regulatory compliance or data residency requirements may be the primary concern. For others, resilience against cyberattack, protection of intellectual property, or reducing dependence on a particular technology provider may be far more important. It’s generally a matter of sector-specific and business priorities. </p><p>So, rather than simply asking where data is stored, leaders should consider who ultimately controls the infrastructure, how dependent they are on individual <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a>, what happens if services become unavailable, and whether they retain sufficient visibility and control over critical systems. If any of this raises operational or regulatory concerns, it may be sensible to adjust strategy.</p><h2 id="the-resilience-paradox">The resilience paradox</h2><p>An unintended consequence of pursuing absolute data localization is that it can reduce resilience. Organizations often improve availability and <a href="https://www.techradar.com/best/best-data-recovery-service">data recovery</a> by maintaining geographically separate copies of critical data. Restricting everything to a single jurisdiction can reduce those options. </p><p>Decisions about sovereignty should therefore factor in availability, confidentiality, and integrity – all of which are important. The most effective approaches recognize that resilience sometimes requires carefully managed distribution rather than rigid localization. </p><p>Consider this scenario: an organization has ensured all their <a href="https://www.techradar.com/news/best-email-provider">email</a> is stored within a single jurisdiction to meet sovereignty objectives. Months later, their provider has a major outage in that one region, and they lose access to their email for days. Even worse, a serious data loss event affects their <a href="https://www.techradar.com/best/best-backup-software">backups</a>, which are also stored in the same region. If they had optimized for resilience instead, their data would have been safe and available throughout. </p><p>Even though the organization successfully addressed one aspect of sovereignty, they weakened another by reducing their ability to recover critical business information. That's ultimately the difference between treating sovereignty as a marketing claim and treating it as a genuine risk management exercise.</p><p><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ What is Tokenmaxxing, and why should businesses care about it? ]]></title>
                                                                                                <dc:content><![CDATA[ <p>The past two years have seen unprecedented adoption of generative AI. This was driven largely by <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> platforms such as Claude, which reported 28 million paying US customers in March.</p><p>In the corporate world and startups, this has put the pressure on companies to invest in AI, to keep up with the latest models and bolster <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and efficiency. But now that the world has adopted AI, a stark readiness gap is emerging as governance and AI skills lag behind. AI fluency is now a baseline expectation for employees as leaders feel the pressure to prove the returns on their hefty investments.  </p><p>Tokenmaxxing is the latest AI trend to come under fire as businesses want employees to use more AI in their work. In essence, this means boosting AI input to maximize AI output. On the surface, it sounds efficient and harmless. But underneath, it poses major security risks. </p><h2 id="tokenmaxxing-explained">Tokenmaxxing explained</h2><p>So what actually is tokenmaxxing?</p><p>A ‘token’ is a unit of data processed by an AI model. For example, a word or character inputted into an LLM search. So ‘tokenmaxxing’ quite simply means over-engineering generative AI prompts to get the most out of one search input. This can be anything from overly detailed prompts, to overloading an LLM chat with information, to asking an AI model for step-by-step breakdowns, as opposed to short summaries.</p><p>The trend is driven by businesses as leaders face pressure to prove the ROI of AI. It became a tongue-in-cheek benchmark of AI performance. Some companies, such as Meta, even gamified tokenmaxxing, measuring and ranking AI usage and citing the highest scorers ‘Token Legends’.</p><p>Their assumption is that AI usage means being AI-forward. But instead, companies need to consider the value they get from <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. They also need to keep security at the center of the conversation.</p><h2 id="the-hidden-costs-of-tokenmaxxing">The hidden costs of tokenmaxxing</h2><p>Although it might look like harmless corporate showboating, this trend poses a wide range of security risks given that LLM vendors are 52% more likely to be designated as “high risk” than traditional SaaS. This is due to access to sensitive data, IP, and internal workflows, so it’s imperative that <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> have oversight of how employees use these resources.</p><p>Rapid adoption of AI has led to an experimentation mindset. This is a positive shift from an innovation standpoint, but from a compliance perspective, a ‘trial and error’ approach is more error than trial.</p><p>The legacy tech systems most major enterprises are still reliant on are controlled by procurement and security teams and were not designed for the agility of AI technology. Meaning both innovation and compliance are lagging behind. It’s the latter that’s causing major concerns in the <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> world.  </p><p>When employees face mounting pressure to get the job done, they won’t wait for security teams to approve new tools, which results in shadow AI. This is where unmanaged, unapproved AI tools operate inside company environments without oversight.</p><p>Industry data shows that 70% of 16k cybersecurity customers currently have some form of shadow AI lurking within their organization, largely due to AI tools introduced through improper procurement channels that now have access to company data without oversight or guardrails.</p><p>There’s also been a 36% increase in shadow IT year-on-year, with organizations discovering, on average, around 140 Shadow IT tools accessing their environment within 90 days of connecting to the platform.</p><p>The bottom line is that AI adoption is drastically outpacing governance, and employees are prioritizing speed over control.</p><h2 id="how-businesses-can-defend-against-shadow-ai">How businesses can defend against Shadow AI</h2><p>The core issue isn’t tokenmaxxing itself; it’s businesses' inability to keep up with <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> demand for speedy access to the latest AI tools. This ultimately results in friction between the desire to safely onboard new tools and the ongoing pressure to use AI.</p><p>When security teams intervene and revoke access to unmanaged tools, employees just reinstall them. Industry data finds that within a 30-day period, the average enterprise sees employees reinstall revoked tools 100+ times. Within one year, it happens 1,000 times.</p><p>To bolster defenses, organizations must design their procurement systems to match the speed of AI innovation, so they can keep up with the rate of AI usage, as demonstrated by so-called ‘token legends’.</p><h2 id="three-actions-businesses-can-take-now">Three actions businesses can take now</h2><p>The more generative AI gets adopted in the corporate world, the more employees will face pressure to adopt and prove its ROI. Tokenmaxxing is just one hype within this wider picture. Businesses need to act fast to stop the gap between experimentation and control widening.</p><p>Three things leaders and compliance teams can kickstart today to bolster defenses against shadow AI are:</p><ul><li>Shrinking vendor review timelines so they match the speed of AI adoption</li><li>Set up continuous monitoring systems to detect threats caused by tokenmaxxing before they jeopardize safety</li><li>Implement employee training and policies for AI usage to ensure employees don’t expose sensitive data or IP</li></ul><p>The new mandate is matching speed with governance, and it’s up to <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams to lead the charge.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/what-is-tokenmaxxing-and-why-should-businesses-care-about-it</link>
                                                                            <description>
                            <![CDATA[ Tokenmaxxing highlights how businesses’ race to maximize AI productivity is exposing governance and security risks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">7XwpBRLwgXdzyzYFZ2ewYA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 13 Aug 2026 08:59:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Iccha Sethi ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A line of robots typing at computers]]></media:description>                                                            <media:text><![CDATA[A line of robots typing at computers]]></media:text>
                                <media:title type="plain"><![CDATA[A line of robots typing at computers]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9WT9t3hZhDVD84bF8rSypL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The past two years have seen unprecedented adoption of generative AI. This was driven largely by <a href="https://www.techradar.com/computing/artificial-intelligence/best-llms">LLM</a> platforms such as Claude, which reported 28 million paying US customers in March.</p><p>In the corporate world and startups, this has put the pressure on companies to invest in AI, to keep up with the latest models and bolster <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and efficiency. But now that the world has adopted AI, a stark readiness gap is emerging as governance and AI skills lag behind. AI fluency is now a baseline expectation for employees as leaders feel the pressure to prove the returns on their hefty investments.  </p><p>Tokenmaxxing is the latest AI trend to come under fire as businesses want employees to use more AI in their work. In essence, this means boosting AI input to maximize AI output. On the surface, it sounds efficient and harmless. But underneath, it poses major security risks. </p><h2 id="tokenmaxxing-explained">Tokenmaxxing explained</h2><p>So what actually is tokenmaxxing?</p><p>A ‘token’ is a unit of data processed by an AI model. For example, a word or character inputted into an LLM search. So ‘tokenmaxxing’ quite simply means over-engineering generative AI prompts to get the most out of one search input. This can be anything from overly detailed prompts, to overloading an LLM chat with information, to asking an AI model for step-by-step breakdowns, as opposed to short summaries.</p><p>The trend is driven by businesses as leaders face pressure to prove the ROI of AI. It became a tongue-in-cheek benchmark of AI performance. Some companies, such as Meta, even gamified tokenmaxxing, measuring and ranking AI usage and citing the highest scorers ‘Token Legends’.</p><p>Their assumption is that AI usage means being AI-forward. But instead, companies need to consider the value they get from <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a>. They also need to keep security at the center of the conversation.</p><h2 id="the-hidden-costs-of-tokenmaxxing">The hidden costs of tokenmaxxing</h2><p>Although it might look like harmless corporate showboating, this trend poses a wide range of security risks given that LLM vendors are 52% more likely to be designated as “high risk” than traditional SaaS. This is due to access to sensitive data, IP, and internal workflows, so it’s imperative that <a href="https://www.techradar.com/best/best-business-cloud-storage-service">businesses</a> have oversight of how employees use these resources.</p><p>Rapid adoption of AI has led to an experimentation mindset. This is a positive shift from an innovation standpoint, but from a compliance perspective, a ‘trial and error’ approach is more error than trial.</p><p>The legacy tech systems most major enterprises are still reliant on are controlled by procurement and security teams and were not designed for the agility of AI technology. Meaning both innovation and compliance are lagging behind. It’s the latter that’s causing major concerns in the <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> world.  </p><p>When employees face mounting pressure to get the job done, they won’t wait for security teams to approve new tools, which results in shadow AI. This is where unmanaged, unapproved AI tools operate inside company environments without oversight.</p><p>Industry data shows that 70% of 16k cybersecurity customers currently have some form of shadow AI lurking within their organization, largely due to AI tools introduced through improper procurement channels that now have access to company data without oversight or guardrails.</p><p>There’s also been a 36% increase in shadow IT year-on-year, with organizations discovering, on average, around 140 Shadow IT tools accessing their environment within 90 days of connecting to the platform.</p><p>The bottom line is that AI adoption is drastically outpacing governance, and employees are prioritizing speed over control.</p><h2 id="how-businesses-can-defend-against-shadow-ai">How businesses can defend against Shadow AI</h2><p>The core issue isn’t tokenmaxxing itself; it’s businesses' inability to keep up with <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employee</a> demand for speedy access to the latest AI tools. This ultimately results in friction between the desire to safely onboard new tools and the ongoing pressure to use AI.</p><p>When security teams intervene and revoke access to unmanaged tools, employees just reinstall them. Industry data finds that within a 30-day period, the average enterprise sees employees reinstall revoked tools 100+ times. Within one year, it happens 1,000 times.</p><p>To bolster defenses, organizations must design their procurement systems to match the speed of AI innovation, so they can keep up with the rate of AI usage, as demonstrated by so-called ‘token legends’.</p><h2 id="three-actions-businesses-can-take-now">Three actions businesses can take now</h2><p>The more generative AI gets adopted in the corporate world, the more employees will face pressure to adopt and prove its ROI. Tokenmaxxing is just one hype within this wider picture. Businesses need to act fast to stop the gap between experimentation and control widening.</p><p>Three things leaders and compliance teams can kickstart today to bolster defenses against shadow AI are:</p><ul><li>Shrinking vendor review timelines so they match the speed of AI adoption</li><li>Set up continuous monitoring systems to detect threats caused by tokenmaxxing before they jeopardize safety</li><li>Implement employee training and policies for AI usage to ensure employees don’t expose sensitive data or IP</li></ul><p>The new mandate is matching speed with governance, and it’s up to <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> teams to lead the charge.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This North Korean recruitment scam was so convincing it even fooled Google ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Lazarus expanded Dream Job with a zero‑day, new backdoor, and advanced relays</strong></li><li><strong>Fake job lures, trojanized PDFs, and spoofed sites enabled high‑level compromises</strong></li><li><strong>Targets included defense and aerospace firms, prompting stronger phishing awareness</strong></li></ul><p>Security experts from <a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank">Check Point Research</a> say they have uncovered a new wave of "Operation Dream Job" attacks, leveraging a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen webshell/relay.</p><p>Lazarus Group is a hacking collective on the payroll of the North Korean government. It is a state-sponsored threat actor known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country’s weapons program and the wider state apparatus.</p><p>It is also known for running Operation Dream Job - a hacking campaign that’s been going on for years, and that lures victims with highly lucrative but bogus job opportunities.</p><h2 id="what-is-operation-dream-job">What is Operation Dream Job?</h2><p>The scam works like this: the attackers come up with a fake company, often in the software development, defense, aerospace, or military industries. </p><p>They create the fake company’s website, LinkedIn account, as well as fake people supposedly employed there. Then, they reach out to their targets, offering great working conditions, amazing salaries, and an opportunity to work on exciting projects.</p><p>Victims that take the bait are then led through a series of “interviews” and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code, as part of a “training exercise” or “skill evaluation”. At this moment, the victims get compromised, while the attackers gain access to their actual employers’ infrastructure.</p><p>From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen <a href="https://www.techradar.com/pro/security/fbi-says-north-korean-lazarus-hackers-were-behind-usd1-5-billion-bybit-crypto-hack" target="_blank">more than a billion dollars</a> in cryptocurrency from one of its victims.</p><h2 id="ante-up">Ante up</h2><p>Perhaps the biggest finding is that Lazarus even managed to fool Google - fake Lockheed Martin and Enveil job postings all made it through filters, while spoofed, malicious websites were showing at the top of search results.</p><p>Then, there is the new Windows vulnerability the group has been exploiting. A zero-day, now tracked as CVE-2026-68820, is described as a “use-after-free bug in Windows Ancillary Function Driver for WinSock”, allowing authorized attackers to elevate privileges locally.</p><p>This bug was found in a core Windows networking component and allows an attacker who already deployed a piece of malware on the machine to escalate privileges to the highest level. Microsoft patched it on August 11 2026. </p><p>Lazarus used this bug to deploy a previously undocumented backdoor called Troy. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> comes with 17 commands, including file upload and download, interactive shell access, in-memory DLL injection, and process termination.</p><p>The group was also using compromised Roundcube webmail and CMS servers as C2 relays, instead of simply running their own infrastructure, and they were deploying a new PHP webshell called RelayShell. This one doesn’t behave like a conventional backdoor, since it passes commands and responses between victims and operators through text files. </p><p>In one of the observed infection chains, Check Point also found the crooks using SecurityPDF, a trojanized <a href="https://www.techradar.com/best/best-pdf-readers-for-windows" target="_blank">PDF viewer</a> which they were hosting on websites impersonating a legitimate business called Enveil. The drake viewer scans PDF files for a particular hidden marker and, if it finds it, decrypts it and loads Troy directly into memory. </p><p>Lazarus usually targets cryptocurrency and software developers. This time around, however, it set its sights on defense organizations, aerospace companies, as well as those working in aviation. Most of the victims are located in Europe and India, with confirmed activity in France, Germany, Brazil and India.</p><p>Check Point also said that not all victims were also targets - some of the organizations compromised in the attacks were later used as infrastructure. In at least one case, Lazarus compromised a Western European organization and used it to send spear-phishing messages to additional victims, effectively exploiting that organization’s reputation and trusted communications. </p><p>Since these attacks primarily start with a social engineering element, the best course of action is to educate employees on the dangers of phishing and the fact that, if someone is reaching out with a job offer too good to be true - it most likely is.</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/this-north-korean-recruitment-scam-was-so-convincing-it-even-fooled-google</link>
                                                                            <description>
                            <![CDATA[ Fake sites were popping up at the top of search engine results pages and used to convince victims to download a trojanized PDF viewer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BcxcZYRcAHfQvhcvJWD8HM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[North Korean flag with a hooded hacker]]></media:description>                                                            <media:text><![CDATA[North Korean flag with a hooded hacker]]></media:text>
                                <media:title type="plain"><![CDATA[North Korean flag with a hooded hacker]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kDLU9By5uaPPbwrbfEaZFJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Lazarus expanded Dream Job with a zero‑day, new backdoor, and advanced relays</strong></li><li><strong>Fake job lures, trojanized PDFs, and spoofed sites enabled high‑level compromises</strong></li><li><strong>Targets included defense and aerospace firms, prompting stronger phishing awareness</strong></li></ul><p>Security experts from <a href="https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/" target="_blank">Check Point Research</a> say they have uncovered a new wave of "Operation Dream Job" attacks, leveraging a previously undocumented backdoor, a brand new Windows zero-day vulnerability, and a never-before-seen webshell/relay.</p><p>Lazarus Group is a hacking collective on the payroll of the North Korean government. It is a state-sponsored threat actor known for targeting cryptocurrency developers and other professionals in the Web3 industry, stealing their tokens and using the money to fund the country’s weapons program and the wider state apparatus.</p><p>It is also known for running Operation Dream Job - a hacking campaign that’s been going on for years, and that lures victims with highly lucrative but bogus job opportunities.</p><h2 id="what-is-operation-dream-job">What is Operation Dream Job?</h2><p>The scam works like this: the attackers come up with a fake company, often in the software development, defense, aerospace, or military industries. </p><p>They create the fake company’s website, LinkedIn account, as well as fake people supposedly employed there. Then, they reach out to their targets, offering great working conditions, amazing salaries, and an opportunity to work on exciting projects.</p><p>Victims that take the bait are then led through a series of “interviews” and somewhere along the line, they are either given weaponized PDF files or asked to download and run executables and other code, as part of a “training exercise” or “skill evaluation”. At this moment, the victims get compromised, while the attackers gain access to their actual employers’ infrastructure.</p><p>From there, the ending can be relatively different. Lazarus has, on at least one occasion, stolen <a href="https://www.techradar.com/pro/security/fbi-says-north-korean-lazarus-hackers-were-behind-usd1-5-billion-bybit-crypto-hack" target="_blank">more than a billion dollars</a> in cryptocurrency from one of its victims.</p><h2 id="ante-up">Ante up</h2><p>Perhaps the biggest finding is that Lazarus even managed to fool Google - fake Lockheed Martin and Enveil job postings all made it through filters, while spoofed, malicious websites were showing at the top of search results.</p><p>Then, there is the new Windows vulnerability the group has been exploiting. A zero-day, now tracked as CVE-2026-68820, is described as a “use-after-free bug in Windows Ancillary Function Driver for WinSock”, allowing authorized attackers to elevate privileges locally.</p><p>This bug was found in a core Windows networking component and allows an attacker who already deployed a piece of malware on the machine to escalate privileges to the highest level. Microsoft patched it on August 11 2026. </p><p>Lazarus used this bug to deploy a previously undocumented backdoor called Troy. This <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> comes with 17 commands, including file upload and download, interactive shell access, in-memory DLL injection, and process termination.</p><p>The group was also using compromised Roundcube webmail and CMS servers as C2 relays, instead of simply running their own infrastructure, and they were deploying a new PHP webshell called RelayShell. This one doesn’t behave like a conventional backdoor, since it passes commands and responses between victims and operators through text files. </p><p>In one of the observed infection chains, Check Point also found the crooks using SecurityPDF, a trojanized <a href="https://www.techradar.com/best/best-pdf-readers-for-windows" target="_blank">PDF viewer</a> which they were hosting on websites impersonating a legitimate business called Enveil. The drake viewer scans PDF files for a particular hidden marker and, if it finds it, decrypts it and loads Troy directly into memory. </p><p>Lazarus usually targets cryptocurrency and software developers. This time around, however, it set its sights on defense organizations, aerospace companies, as well as those working in aviation. Most of the victims are located in Europe and India, with confirmed activity in France, Germany, Brazil and India.</p><p>Check Point also said that not all victims were also targets - some of the organizations compromised in the attacks were later used as infrastructure. In at least one case, Lazarus compromised a Western European organization and used it to send spear-phishing messages to additional victims, effectively exploiting that organization’s reputation and trusted communications. </p><p>Since these attacks primarily start with a social engineering element, the best course of action is to educate employees on the dangers of phishing and the fact that, if someone is reaching out with a job offer too good to be true - it most likely is.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘TikTok may be used on government devices’: Trump administration removes TikTok ban on government phones, so employees are now free to doomscroll once again ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>The Trump administration has lifted the TikTok ban for federal devices</strong></li><li><strong>The app was banned from being installed by government employees in 2022</strong></li><li><strong>TikTok in America is now majority owned by a US company, with ByteDance still holding around a 20% share</strong></li></ul><p>The Trump administration has lifted a ban on government employees having TikTok on their mobile devices.</p><p>The law was introduced in 2022 when TikTok was deemed to be a national security threat because of potential ties between TikTok’s parent company ByteDance, and the Chinese government.</p><p>A memo released by the Office of Management and Budget (OMB) states, “TikTok may be used on government devices.”</p><h2 id="government-to-go-back-to-doomscrolling">Government to go back to doomscrolling</h2><p>The details as to why the government banned the app in the first place have not been fully disclosed. Discussions within the senate centered around data collection and Chinese government influence over the app’s algorithm.</p><p><a href="https://www.techradar.com/computing/cyber-security/tiktok-to-be-saved-in-the-us-as-trump-confirms-a-deal-with-china-ahead-of-upcoming-ban">TikTok briefly went offline in the US in 2025</a> as the Trump administration forced ByteDance to sell the app to American owners or have the app be permanently blacklisted in the US.</p><p>The two settled on having an American version of the app for American audiences controlled by TikTok USDS Joint Venture.</p><p>The Department of Transportation, Treasury Department, and Health and Human Services have all since created official accounts on the app and have begun posting. The White House also has an official account which mainly posts hype edits of the President.</p><p>Via <a href="https://www.engadget.com/2235010/government-workers-can-officially-waste-time-scrolling-tiktok-again/" target="_blank"><em>Engadget</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/tiktok-may-be-used-on-government-devices-trump-administration-removes-tiktok-ban-on-government-phones-so-employees-are-now-free-to-doomscroll-once-again</link>
                                                                            <description>
                            <![CDATA[ The US government has lifted the ban on TikTok being installed on government devices. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nk7HzCowcX9FXAeH86JDcF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Caa2mzJkJUGpLHopsEdCMZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Tiktok]]></category>
                                                    <category><![CDATA[Social Media]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Internet]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Caa2mzJkJUGpLHopsEdCMZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Photo by Jaap Arriens/NurPhoto via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The TikTok logo is seen on a mobile device, with a picture of US President Trump in the background]]></media:description>                                                            <media:text><![CDATA[The TikTok logo is seen on a mobile device, with a picture of US President Trump in the background]]></media:text>
                                <media:title type="plain"><![CDATA[The TikTok logo is seen on a mobile device, with a picture of US President Trump in the background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Caa2mzJkJUGpLHopsEdCMZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>The Trump administration has lifted the TikTok ban for federal devices</strong></li><li><strong>The app was banned from being installed by government employees in 2022</strong></li><li><strong>TikTok in America is now majority owned by a US company, with ByteDance still holding around a 20% share</strong></li></ul><p>The Trump administration has lifted a ban on government employees having TikTok on their mobile devices.</p><p>The law was introduced in 2022 when TikTok was deemed to be a national security threat because of potential ties between TikTok’s parent company ByteDance, and the Chinese government.</p><p>A memo released by the Office of Management and Budget (OMB) states, “TikTok may be used on government devices.”</p><h2 id="government-to-go-back-to-doomscrolling">Government to go back to doomscrolling</h2><p>The details as to why the government banned the app in the first place have not been fully disclosed. Discussions within the senate centered around data collection and Chinese government influence over the app’s algorithm.</p><p><a href="https://www.techradar.com/computing/cyber-security/tiktok-to-be-saved-in-the-us-as-trump-confirms-a-deal-with-china-ahead-of-upcoming-ban">TikTok briefly went offline in the US in 2025</a> as the Trump administration forced ByteDance to sell the app to American owners or have the app be permanently blacklisted in the US.</p><p>The two settled on having an American version of the app for American audiences controlled by TikTok USDS Joint Venture.</p><p>The Department of Transportation, Treasury Department, and Health and Human Services have all since created official accounts on the app and have begun posting. The White House also has an official account which mainly posts hype edits of the President.</p><p>Via <a href="https://www.engadget.com/2235010/government-workers-can-officially-waste-time-scrolling-tiktok-again/" target="_blank"><em>Engadget</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why organizations are falling into an AI Security Illusion ]]></title>
                                                                                                <dc:content><![CDATA[ <p>Many organizations believe they are successfully leveraging <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to strengthen their security posture. </p><p>Investment is rising, AI is being embedded across multiple workloads and workflows, and governance frameworks continue to expand, giving the impression on the surface that progress is being made. </p><p>But beneath this AI adoption lies an unseen problem: a growing gap between what organizations believe about their infrastructure security, and what they can actually evidence. </p><h2 id="confidence-is-rising-but-so-are-breaches">Confidence is rising, but so are breaches</h2><p>According to a global 2026 Hybrid Cloud Security Survey, which gathered the views of more than 1,000 Security and IT leaders, 93 percent have invested in new security technologies, yet despite this, breach rates have hit their highest point. Sixty-five per cent of organizations experienced a data breach in the past 12 months, an 18 percent rise year on year, and a near 40 percent rise over three years. </p><p>These worrying statistics are starting to ring alarm bells, highlighting that within organizations we are starting to see an ‘illusion of security’ creeping in. Organizations are investing heavily in <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> tools,  yet still seem to lack clear visibility into the outcomes of their investments. In other words,  leaving security to be measured by what has been implemented, rather than what can actually be verified.</p><p>A perfect storm of conditions has brought us to this point: AI adoption has scaled faster than governance and security teams can keep pace with, and hybrid <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> has added another dimension of complexity that few organizations have fully reckoned with.</p><p>AI is now embedded across enterprise environments, accelerating not just how organizations operate, but how risk moves through them. As adoption has outpaced oversight, the consequences are starting to surface, with nearly half of organizations surveyed reporting a rise in AI-related insider threats, including data leaks, and unsanctioned use (shadow AI). Perhaps surprisingly confidence hasn't reduced. Many organizations continue to classify their AI security posture as "defined" or "integrated," despite evidence portraying a radically different story.</p><p>That confidence often rests on assumptions, and the scale of the disconnect is striking; AI is now involved in 83 percent of security incidents, spanning external attacks, internal exposures, and direct targeting of AI systems. As threats move faster across increasingly fragmented and distributed environments, assumptions about what’s secure quickly fall apart and without clear visibility into how data moves and systems behave, organizations cannot reliably manage risk.</p><h2 id="the-warning-signs">The warning signs</h2><p>No single indicator reveals a false sense of AI security, but several recurring patterns make it obvious.</p><p>The first is investment without impact. Many organizations are expanding their security stacks, yet detection and response times are still moving in the wrong direction. More than 40 percent report that it now takes longer to detect and investigate breaches than it did previously, and that's not a coincidence. </p><p>When signals are spread across systems that don't connect, teams spend longer piecing together what happened rather than acting on it. Adding tools without improving visibility doesn't create more clarity. It creates more data, and more data without context is just more noise to wade through not to mention more false positives and perhaps even worse more false negatives.  </p><p>The second is an inability to trace incidents back to their source. More than one in four organizations cannot determine the root cause of a breach, which means incidents are being closed out without fully understanding how they happened. The consequences are predictable: nearly one-third of organizations report multiple incidents within the same year. Without traceability, there is no learning, and without learning, the same gaps simply get exploited again.</p><p>The third is the visibility gap opening in AI-driven environments. With nearly three-quarters of organizations reporting limited visibility into AI-driven data flows, which span APIs, models, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, and distributed infrastructure that is dynamic by design and doesn't map cleanly onto traditional monitoring approaches. Security teams can often see that something happened, but simply can’t get to the how or the why. That gap between knowing an incident occurred and understanding it, is exactly where the illusion lives.</p><h2 id="moving-from-illusion-to-evidence">Moving from illusion to evidence</h2><p>In response to growing complexity, organizations are collecting more telemetry than ever; metrics, events, logs and traces (MELT data), but more data does not necessarily equate to better understanding. These signals each offer only a partial view: one measures performance, another records activity, other flags issues after the fact. </p><p>None of them, on their own, are able to explain how systems behave as a whole. What’s missing is the connective tissue, the context that shows how these signals relate, how one event triggers another, and how issues propagate across the environment. Without that, organizations aren’t gaining insight; they’re just accumulating noise.</p><p>Shattering the AI ‘security illusion’ requires a shift from reactive security to proactive monitoring and real-time observation of how systems behave. Security leaders agree, with more than 90 percent of organizations reporting that complete visibility across data in motion is critical to their successful security outcomes. </p><p>This is where network-derived telemetry becomes essential. Unlike logs, which show what systems say they’re doing, network telemetry proves what is happening: how data moves, how systems interact, and how threats develop. It's the shift from assumption to evidence and then proof, and it's the only foundation solid enough to build real security on. The network is the source of truth for today’s security teams.</p><h2 id="ai-security-must-be-measured-not-assumed">AI security must be measured, not assumed</h2><p>AI is reshaping the threat landscape, enabling faster, more adaptive attacks while increasing the complexity of enterprise environments. But defenders are not without their own advantages. </p><p>The same technologies fueling attacks are already supporting security teams, automating detection, accelerating response, and investment in these capabilities continues to grow.</p><p>But let there be no mistake: investment is not proof. Security must be measured by the ability to observe, understand, and validate what is actually happening across the environment. </p><p>In the age of AI, the real risk is not organizations underinvesting in security, but the belief that they are secure without the evidence to prove it.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/why-organizations-are-falling-into-an-ai-security-illusion</link>
                                                                            <description>
                            <![CDATA[ If AI strengthens security, why do organizations continue to suffer breaches? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ztCCsPmiPEsGZaQpY9QqRF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 14:39:44 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Danielle Kinsella ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Many organizations believe they are successfully leveraging <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> to strengthen their security posture. </p><p>Investment is rising, AI is being embedded across multiple workloads and workflows, and governance frameworks continue to expand, giving the impression on the surface that progress is being made. </p><p>But beneath this AI adoption lies an unseen problem: a growing gap between what organizations believe about their infrastructure security, and what they can actually evidence. </p><h2 id="confidence-is-rising-but-so-are-breaches">Confidence is rising, but so are breaches</h2><p>According to a global 2026 Hybrid Cloud Security Survey, which gathered the views of more than 1,000 Security and IT leaders, 93 percent have invested in new security technologies, yet despite this, breach rates have hit their highest point. Sixty-five per cent of organizations experienced a data breach in the past 12 months, an 18 percent rise year on year, and a near 40 percent rise over three years. </p><p>These worrying statistics are starting to ring alarm bells, highlighting that within organizations we are starting to see an ‘illusion of security’ creeping in. Organizations are investing heavily in <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> tools,  yet still seem to lack clear visibility into the outcomes of their investments. In other words,  leaving security to be measured by what has been implemented, rather than what can actually be verified.</p><p>A perfect storm of conditions has brought us to this point: AI adoption has scaled faster than governance and security teams can keep pace with, and hybrid <a href="https://www.techradar.com/best/best-cloud-storage">cloud</a> has added another dimension of complexity that few organizations have fully reckoned with.</p><p>AI is now embedded across enterprise environments, accelerating not just how organizations operate, but how risk moves through them. As adoption has outpaced oversight, the consequences are starting to surface, with nearly half of organizations surveyed reporting a rise in AI-related insider threats, including data leaks, and unsanctioned use (shadow AI). Perhaps surprisingly confidence hasn't reduced. Many organizations continue to classify their AI security posture as "defined" or "integrated," despite evidence portraying a radically different story.</p><p>That confidence often rests on assumptions, and the scale of the disconnect is striking; AI is now involved in 83 percent of security incidents, spanning external attacks, internal exposures, and direct targeting of AI systems. As threats move faster across increasingly fragmented and distributed environments, assumptions about what’s secure quickly fall apart and without clear visibility into how data moves and systems behave, organizations cannot reliably manage risk.</p><h2 id="the-warning-signs">The warning signs</h2><p>No single indicator reveals a false sense of AI security, but several recurring patterns make it obvious.</p><p>The first is investment without impact. Many organizations are expanding their security stacks, yet detection and response times are still moving in the wrong direction. More than 40 percent report that it now takes longer to detect and investigate breaches than it did previously, and that's not a coincidence. </p><p>When signals are spread across systems that don't connect, teams spend longer piecing together what happened rather than acting on it. Adding tools without improving visibility doesn't create more clarity. It creates more data, and more data without context is just more noise to wade through not to mention more false positives and perhaps even worse more false negatives.  </p><p>The second is an inability to trace incidents back to their source. More than one in four organizations cannot determine the root cause of a breach, which means incidents are being closed out without fully understanding how they happened. The consequences are predictable: nearly one-third of organizations report multiple incidents within the same year. Without traceability, there is no learning, and without learning, the same gaps simply get exploited again.</p><p>The third is the visibility gap opening in AI-driven environments. With nearly three-quarters of organizations reporting limited visibility into AI-driven data flows, which span APIs, models, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud services</a>, and distributed infrastructure that is dynamic by design and doesn't map cleanly onto traditional monitoring approaches. Security teams can often see that something happened, but simply can’t get to the how or the why. That gap between knowing an incident occurred and understanding it, is exactly where the illusion lives.</p><h2 id="moving-from-illusion-to-evidence">Moving from illusion to evidence</h2><p>In response to growing complexity, organizations are collecting more telemetry than ever; metrics, events, logs and traces (MELT data), but more data does not necessarily equate to better understanding. These signals each offer only a partial view: one measures performance, another records activity, other flags issues after the fact. </p><p>None of them, on their own, are able to explain how systems behave as a whole. What’s missing is the connective tissue, the context that shows how these signals relate, how one event triggers another, and how issues propagate across the environment. Without that, organizations aren’t gaining insight; they’re just accumulating noise.</p><p>Shattering the AI ‘security illusion’ requires a shift from reactive security to proactive monitoring and real-time observation of how systems behave. Security leaders agree, with more than 90 percent of organizations reporting that complete visibility across data in motion is critical to their successful security outcomes. </p><p>This is where network-derived telemetry becomes essential. Unlike logs, which show what systems say they’re doing, network telemetry proves what is happening: how data moves, how systems interact, and how threats develop. It's the shift from assumption to evidence and then proof, and it's the only foundation solid enough to build real security on. The network is the source of truth for today’s security teams.</p><h2 id="ai-security-must-be-measured-not-assumed">AI security must be measured, not assumed</h2><p>AI is reshaping the threat landscape, enabling faster, more adaptive attacks while increasing the complexity of enterprise environments. But defenders are not without their own advantages. </p><p>The same technologies fueling attacks are already supporting security teams, automating detection, accelerating response, and investment in these capabilities continues to grow.</p><p>But let there be no mistake: investment is not proof. Security must be measured by the ability to observe, understand, and validate what is actually happening across the environment. </p><p>In the age of AI, the real risk is not organizations underinvesting in security, but the belief that they are secure without the evidence to prove it.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-backup"><em>We've reviewed, rated, and ranked the best cloud backup</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google says Chrome blocked seven billion malicious Android notifications every day in its bid to cut down on scams ]]></title>
                                                                                                <dc:content><![CDATA[ <ul><li><strong>Google cut seven billion daily Android Chrome notifications using layered defenses</strong></li><li><strong>Chrome now limits abusive sites, revokes permissions, and blocks high‑volume spam</strong></li><li><strong>Android improvements simplify managing alerts and reduce scam and malware exposure</strong></li></ul><p>Google says it has cut the number of notifications Chrome users get on their Android devices by seven billion a day. </p><p>In a new <a href="https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/" target="_blank" rel="nofollow">report</a>, the company outlined how it has built a multi-layered defense system to shield its users from unwanted notifications, protecting them from spam and malware, and helping their devices’ battery last longer. </p><p>Most importantly, Google says the achievement significantly improved the overall user experience on Android. </p><h2 id="notification-bombardment">Notification bombardment</h2><p>For the longest time, individual websites were allowed to send push notifications directly to their users’ phones, even when they were not actively browsing them. </p><p>When a user visits a certain website, they get prompted to “show notifications”, and if they tap “allow”, the website starts sending the alerts. Sometimes, users do it without fully realizing what they’re agreeing to.</p><p>Once granted, the notifications (sent through Chrome) get shown next to other alerts (such as the ones coming from WhatsApp, Gmail, or other apps). </p><p>Unlike other notifications - which usually alert users to unread messages, calendar events, or similar - these mostly promote new content, deals, or other updates. They can also alert users of breaking news, which is arguably the most useful type among the ones mentioned here. </p><p>Legitimate websites use the feature responsibly and generally don’t flood their users with unwanted pings. However, some sites abuse the privilege, bombarding users with unwanted advertising, misleading alerts, clickbait articles, and other formats, just to get them to open the page (where they’re often served ads). More worryingly, malicious or compromised websites can use notifications to push scam messages, fake virus warnings, phishing links or other potentially dangerous content. </p><p>Because these alerts are served through Chrome and resemble ordinary system notifications, users may not immediately realize the risk. </p><p>But because they are served through Chrome, Google can do something about it, and the company has now “pulled back the curtain” on the toolkit that made these improvements possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:800px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M8dLsateSbGVwYwoPrRba3" name="mobile security.jpg" alt="Mobile Security" src="https://cdn.mos.cms.futurecdn.net/M8dLsateSbGVwYwoPrRba3.jpg" mos="" align="middle" fullscreen="" width="800" height="450" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock.com)</span></figcaption></figure><h2 id="swiss-cheese">Swiss cheese</h2><p>Described as a “swiss cheese” model, Google says it created overlapping protections that cover the entire notification lifecycle. Chrome now automatically revokes notification permissions for sites users haven’t engaged with in a little while. </p><p>So, if a site keeps flooding the visitor with notifications that they’re not responding to, Chrome will eventually shut them off. Same goes for sites that have “repeatedly received suspicious notification warnings”. Google did not say how many is considered “repeatedly” and in what timeframe.</p><p>The second layer is analyzing signals such as service worker activity. By looking for coordinated behaviors, Google claims it can now pinpoint networks that serve malicious content, and block them. </p><p>On the Firebase Cloud Messaging (FCM) server side, the company introduced message rate limits that disallow high-volume notification abuse. Google now evaluates sites based on factors such as message volume relative to time spent on site, the frequency of permission prompts, and general engagement levels.</p><p>In other words, if a user spends 10 minutes on a website but then receives 50 notifications, it will raise quite a few red flags. Same goes for users that don’t really interact with the website a lot. “Disruptive domains” are now limited to 1,000 messages per minute and will receive HTTP 429 responses if they exceed this threshold, Google explained.</p><p>Finally, the company updated how notifications are handled on Android phones. Users can update their preferences directly from the notification bar, simplifying the process for users who can’t be bothered to dig deep into system settings. </p><p>“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Google said. </p><p>“Beyond security enhancements, this strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable.”</p> ]]></dc:content>
                                                                                                                                            <link>https://www.techradar.com/pro/security/google-says-chrome-blocked-seven-billion-malicious-android-notifications-every-day-in-its-bid-to-cut-down-on-scams</link>
                                                                            <description>
                            <![CDATA[ A "Swiss cheese" approach to defense seems to be working, as the number of unwanted notifications dwindles. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">DYTMghKLR3LUcJNVnvbzV4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 12 Aug 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Annoyed man with phone]]></media:description>                                                            <media:text><![CDATA[Annoyed man with phone]]></media:text>
                                <media:title type="plain"><![CDATA[Annoyed man with phone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/o9BDDKXmm9T4Lqtm38fsmV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google cut seven billion daily Android Chrome notifications using layered defenses</strong></li><li><strong>Chrome now limits abusive sites, revokes permissions, and blocks high‑volume spam</strong></li><li><strong>Android improvements simplify managing alerts and reduce scam and malware exposure</strong></li></ul><p>Google says it has cut the number of notifications Chrome users get on their Android devices by seven billion a day. </p><p>In a new <a href="https://blog.google/security/the-multi-layered-defenses-that-harden-chrome-against-abusive-notifications/" target="_blank" rel="nofollow">report</a>, the company outlined how it has built a multi-layered defense system to shield its users from unwanted notifications, protecting them from spam and malware, and helping their devices’ battery last longer. </p><p>Most importantly, Google says the achievement significantly improved the overall user experience on Android. </p><h2 id="notification-bombardment">Notification bombardment</h2><p>For the longest time, individual websites were allowed to send push notifications directly to their users’ phones, even when they were not actively browsing them. </p><p>When a user visits a certain website, they get prompted to “show notifications”, and if they tap “allow”, the website starts sending the alerts. Sometimes, users do it without fully realizing what they’re agreeing to.</p><p>Once granted, the notifications (sent through Chrome) get shown next to other alerts (such as the ones coming from WhatsApp, Gmail, or other apps). </p><p>Unlike other notifications - which usually alert users to unread messages, calendar events, or similar - these mostly promote new content, deals, or other updates. They can also alert users of breaking news, which is arguably the most useful type among the ones mentioned here. </p><p>Legitimate websites use the feature responsibly and generally don’t flood their users with unwanted pings. However, some sites abuse the privilege, bombarding users with unwanted advertising, misleading alerts, clickbait articles, and other formats, just to get them to open the page (where they’re often served ads). More worryingly, malicious or compromised websites can use notifications to push scam messages, fake virus warnings, phishing links or other potentially dangerous content. </p><p>Because these alerts are served through Chrome and resemble ordinary system notifications, users may not immediately realize the risk. </p><p>But because they are served through Chrome, Google can do something about it, and the company has now “pulled back the curtain” on the toolkit that made these improvements possible.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:800px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="M8dLsateSbGVwYwoPrRba3" name="mobile security.jpg" alt="Mobile Security" src="https://cdn.mos.cms.futurecdn.net/M8dLsateSbGVwYwoPrRba3.jpg" mos="" align="middle" fullscreen="" width="800" height="450" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock.com)</span></figcaption></figure><h2 id="swiss-cheese">Swiss cheese</h2><p>Described as a “swiss cheese” model, Google says it created overlapping protections that cover the entire notification lifecycle. Chrome now automatically revokes notification permissions for sites users haven’t engaged with in a little while. </p><p>So, if a site keeps flooding the visitor with notifications that they’re not responding to, Chrome will eventually shut them off. Same goes for sites that have “repeatedly received suspicious notification warnings”. Google did not say how many is considered “repeatedly” and in what timeframe.</p><p>The second layer is analyzing signals such as service worker activity. By looking for coordinated behaviors, Google claims it can now pinpoint networks that serve malicious content, and block them. </p><p>On the Firebase Cloud Messaging (FCM) server side, the company introduced message rate limits that disallow high-volume notification abuse. Google now evaluates sites based on factors such as message volume relative to time spent on site, the frequency of permission prompts, and general engagement levels.</p><p>In other words, if a user spends 10 minutes on a website but then receives 50 notifications, it will raise quite a few red flags. Same goes for users that don’t really interact with the website a lot. “Disruptive domains” are now limited to 1,000 messages per minute and will receive HTTP 429 responses if they exceed this threshold, Google explained.</p><p>Finally, the company updated how notifications are handled on Android phones. Users can update their preferences directly from the notification bar, simplifying the process for users who can’t be bothered to dig deep into system settings. </p><p>“These integrated efforts effectively shield users from sophisticated scams that leverage notifications to distribute malware, harvest personal information, or solicit fraudulent payments,” Google said. </p><p>“Beyond security enhancements, this strategy has substantially decreased unnecessary background activity, reduced user device battery consumption, and transformed the notification lifecycle so users receive only the content they find truly valuable.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>