<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.techradar.com/uk/feeds/tag/computing-security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar UK in Computing-security ]]></title>
                <link>https://www.techradar.com/uk/computing/computing-security</link>
        <description><![CDATA[ All the latest computing-security content from the TechRadar  UK team ]]></description>
                                    <lastBuildDate>Tue, 11 Aug 2026 18:05:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Scammers are using fake Odyssey pirate downloads to spread malware that's more dangerous than the Cyclops and Circe combined ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/scammers-are-using-fake-odyssey-pirate-downloads-to-spread-malware-thats-more-dangerous-than-the-cyclops-and-circe-combined</link>
                                                                            <description>
                            <![CDATA[ Fake downloads of The Odyssey are delivering Lumma Stealer, and the stolen session cookies walk straight past your two-factor authentication ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">xoShk7grh9qqbbQ4g5pjNT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg">
                                                            <media:credit><![CDATA[Universal Studios]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:description>                                                            <media:text><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:text>
                                <media:title type="plain"><![CDATA[Matt Damon&#039;s Odysseus looking over his left shoulder with some ships in the background in The Odyssey]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U6UNG2aaqj47hstBqBLsGd-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender says fake pirated downloads of </strong><em><strong>The Odyssey</strong></em><strong>, disguised as scene releases with .exe files carrying VLC icons, are spreading Lumma Stealer malware</strong></li><li><strong>Stolen session cookies are the real danger, because they let an attacker resume an authenticated session without ever triggering a multi-factor prompt</strong></li><li><strong>These builds seemingly ship without droppers or persistence, which is less sophisticated than earlier movie-themed samples but no less harmful, since credential theft does not require staying resident</strong></li></ul><p>With <em>The Odyssey</em> set to became one of the year's biggest theatrical launches, people looking for a free copy online started finding one with a few extra caveats in tow.</p><p>What they were actually downloading, according to <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/the-odyssey-piracy-lumma-stealer" target="_blank">Bitdefender</a>, was Lumma Stealer, a prominent infostealer that operates as a Malware-as-a-Service (MaaS).</p><p>The company's researchers say its security products blocked users from downloading and running malicious files disguised as the film, circulating under names designed to look like scene releases: "the odyssey 2026 1080p webrip-lama.exe" is one of three examples published, alongside variants dressed as 2160p HD and H. 264 rips. </p><h2 id="a-regular-occurrence-for-pirates">A regular occurrence for pirates</h2><p>The threat is a well-worn playbook rather than a new one, as Bitdefender documented a near-identical campaign in 2025 built around <em>Mission: Impossible – The Final Reckoning</em>, distributing the same malware family through torrent sites using files dressed as movie releases. The blockbuster changes; the delivery does not.</p><p>The most useful detail in the report is also the least dramatic, and it explains why a file extension that should be a screaming red flag frequently is not: Windows does not show file extensions by default.</p><p>Unless a user has enabled that option in Explorer settings, the ".exe" at the end of a filename is simply invisible. Attackers pair that with a custom icon, commonly one lifted from VLC Media Player or a generic video file, so what appears on screen is a VLC icon and a filename that reads like a movie rip. There is nothing visible to distinguish it from the thing the user was actually looking for.</p><p>Bitdefender's point about social engineering follows from that, and it is a sharp one: almost none is required here. Someone hunting for a leaked copy of a film still in theaters has already accepted that they will be dealing with odd filenames, unofficial sources, and compressed archives. An executable claiming to be a video player or installer is not an uncommon sight in the world of piracy, where such practices are rife.</p><p>Lumma, also tracked as LummaC2, is a Russian-developed information stealer sold as a service, with affiliates paying somewhere between $250 and $1,000 a month for access. Upon execution, it harvests browser passwords, authentication cookies, saved payment information, cryptocurrency wallet data, autofill data, and remote desktop credentials.</p><p>It has often been highlighted as one of the most prolific MaaS options out there and has had <a href="https://www.techradar.com/pro/security/microsoft-takes-legal-action-against-lumma-stealer-after-400-000-devices-infected" target="_blank">Microsoft, the DOJ, and the FBI act directly against it</a> in the past, but has managed to stay alive since, evolving into a more stealthy entity.</p><p>Bitdefender notes that the samples in this campaign arrive without droppers and without persistence mechanisms. </p><p>Previous movie-themed Lumma builds carried more machinery, including delayed execution when security software was detected and encrypted payload delivery through AutoIt scripts. The approach here differs considerably: the attackers appear content with whatever they can collect at execution time and do not attempt to hold the machine afterward.</p><p>Prevention in this case simply involves avoiding the download of pirated films from channels that, as a rule of thumb, do not implement many, if any, security measures to keep infostealers out. </p><p>For those seeking a broader solution, enabling file extensions in Windows Explorer is the way to go. It takes seconds, it is off by default, and it removes the specific blind spot this particular campaign depends on.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI extends 'Daybreak' security project and reveals new cyber model — but for approved users only ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/openai-extends-daybreak-security-project-and-reveals-new-cyber-model-but-for-approved-users-only</link>
                                                                            <description>
                            <![CDATA[ Daybreak now offers two different models that come with varying degrees of compliance. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">AjWZELXMsLjAfnbdxFTR4P</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 13:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:description>                                                            <media:text><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:text>
                                <media:title type="plain"><![CDATA[OpenAI logo on smartphone, reflected on main screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gN6Qsf7QSmrmYwtYPr47HY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI expands Daybreak with Blue and Red tiers for defensive cyber work</strong></li><li><strong>New GPT‑5.6‑Cyber model offers high compliance for authorized vulnerability research</strong></li><li><strong>Access remains restricted due to dual‑use risks and reduced safeguard operation</strong></li></ul><p>OpenAI has <a href="https://openai.com/index/expanding-daybreak-as-the-cyber-defense-window-narrows/" target="_blank" rel="nofollow">announced</a> two new tiers for its Daybreak dedicated cybersecurity project, each offering a different model with different levels of compliance. It also used the opportunity to introduce a new security-focused AI model, as well.</p><p>Hackers and criminals are increasingly abusing AI to improve and speed up the creation of phishing emails and malicious code, and with the introduction of <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>, they’ve also used it to automate entire attack processes. The AI community responded by placing strong guardrails, making sure their models do not comply with requests to build malware, or hack other companies.</p><p>These guardrails ended up being a two-edged sword, because as they slowed down attackers, they also slowed down the defenders.</p><h2 id="what-is-daybreak">What is Daybreak?</h2><p>To give the cybersecurity community the upper edge, companies like OpenAI started creating <a href="https://www.techradar.com/pro/security/openai-reveals-daybreak-its-attempt-to-topple-anthropic-mythos" target="_blank">dedicated cybersecurity initiatives</a> that provide a vetted list of companies state-of-the-art models, free of guardrails. The company also provided them with pre-trained AI agents, as well as access to a pool of shared knowledge.</p><p>Initially launched in June 2026, Daybreak originally included GPT.5-5-Cyber (a model optimized for security work), Codex Security (an agent that can analyze codebases, identify vulnerabilities, validate findings, and help develop patches), Patch the Planet (an initiative with Trail of Bits to find and fix vulnerabilities in open-source software), Daybreak Cyber Partner Program (lets approved cybersecurity companies such as Cloudflare or Cisco integrate OpenAI's cyber capabilities into their own products and services), and Trusted Access for Cyber (the governance/access system for organizations doing authorized cybersecurity work with these capabilities).</p><p>Now, OpenAI has expanded Daybreak with two access tiers, Daybreak Blue, and Daybreak Red.</p><p>The company says Daybreak Blue is “the recommended starting point for most defenders, supporting vulnerability discovery, secure code review, malware analysis, incident response, and patch validation. Companies opting for this tier can expect access to frontier general-purpose models, including GPT‑5.6 Sol, whose safeguards have been tailored to authorized defensive security work.</p><p>Daybreak Red, on the other hand, provides access to OpenAI’s “purpose-trained cybersecurity models for authorized vulnerability research, exploit validation, and security testing.” This tier offers the brand new GPT‑5.6‑Cyber, built on GPT‑5.6 Sol and trained to improve capabilities on several specialized cybersecurity tasks such as finding zero-day vulnerabilities and developing exploit chains.</p><p>This model is also more compliant and less likely to refuse certain higher-risk, dual-use cyber tasks.</p><h2 id="complying-with-dangerous-requests">Complying with "dangerous" requests</h2><p>Request compliance is the name of the game here. OpenAI says the new model addresses feedback from security researchers who “encountered persistent refusals with the earlier model.” General-purpose GPT-5.6 Sol, for example, will comply with just 1.5% of the requests usually given by cyber-defenders working on codebase analysis or vulnerability identification. This percentage increases to 2.0% with Daybreak Blue access. </p><p>GPT-5.6-Cyber, on the other hand, completes 95.0% of requests, OpenAI says, up from 57.3% of the previous model, GPT-5.5-Cyber. We weren’t able to independently verify these claims, though. </p><p>While it doesn’t outright say it, OpenAI considers these models relatively dangerous to use, which is why they’re locked behind the Daybreak Cyber Partner Program. However, the program is now expanding, allowing these companies to embed the models behind their own products, managed services, or cybersecurity engagements, and offer them to clients of their own. </p><p>Those who wish to be a part of the program directly can do so by applying to join online now.</p><p>“Models running with reduced safeguards carry risks beyond standard model usage, whether from misuse or misalignment. Despite these risks, we believe that democratizing access to frontier intelligence for defenders is crucial to accelerating and automating cyber defense,” OpenAI said.</p><p>“Daybreak Blue and Daybreak Red access are available for approved individuals⁠ and organizations conducting authorized work. We control access through identity verification, account security, monitoring, approved-use restrictions, and legal attestations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Shipping and logistics powerhouse suffers a cyberattack, affecting almost a dozen of its clients - we take a look at the details. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">znDNTChe2TpJRXew9c5Wz</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 11 Aug 2026 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>CEVA Logistics hack disrupted European warehouses and exposed some customer data</strong></li><li><strong>Retailers and Valve reported compromised delivery information and service delays</strong></li><li><strong>Clients warned of targeted scams while awaiting fuller incident details from CEVA</strong></li></ul><p>CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients. </p><p>The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves.</p><p>CEVA has not yet issued an official statement, or filed a report with the regulators, but confirmed to <a href="https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/" target="_blank"><em>TechCrunch</em></a> that the attack most likely started on July 29, 2026, and affected at least eight warehouses across Europe.</p><h2 id="technical-details-missing-affected-customers-step-forward">Technical details missing, affected customers step forward</h2><p>CEVA Logistics is a global logistics and supply-chain company and a wholly owned subsidiary of CMA CGM, a French shipping giant. It provides freight forwarding, contract logistics, warehousing and transportation services to thousands of customers, including major companies in the consumer and retail, automotive, industrial and aerospace sectors. </p><p>The company operates in more than 170 countries around the world and last year it generated $18.3 billion in gross revenue, so it is a major player and a key target for attackers.</p><p>The details about the incident itself are scarce right now. We don’t know how the crooks broke in (via a successful social engineering attack, or by abusing a software vulnerability, for example), how much data they stole, or if they demanded a ransom payment in exchange for deleting the stolen goods. From one of the victims, though, we have learned that some data was most likely compromised.</p><p>When the effects of a cyberattack spill into the physical realm (as is the case here with eight affected warehouses) we can speculate the attack was either <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>, or disruptive <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>. Companies shut down parts of their IT infrastructure only when there is no other way to clear an infection or remove malicious outsiders.</p><p>In the meantime, a small number of CEVA’s customers confirmed suffering an attack and losing sensitive data. </p><p>Among them is Bol, a Dutch online retail company, which said the incident affected two systems used for processing orders from one of its fulfillment</p><p>“No bol systems were affected,” it said. “However, data of customers whose orders were processed via this location may have been viewed or copied.”</p><p>Bol also said restoring operations at one of CEVA’s locations was taking longer than anticipated. As a result, the assortment stored at the affected location was taken offline, and the products were unavailable for sale. Also, Bol is currently unable to receive goods from suppliers and sales partners at that location.</p><p>A similar announcement was given by De Bijenkorf, another Dutch luxury retailer, who said that order processing, returns, and refunds, might take longer, but stressed that its stores remained open. It also said that some customer data may have been compromised, including names, contact details, online orders data and, in some cases, VAT numbers. Payment information, bank account numbers (IBANs), credit card information, usernames, or passwords, were not compromised, it was confirmed. </p><h2 id="valve-steps-forward">Valve steps forward</h2><p>Retail giants aside, PC gaming powerhouse Valve also notified its customers about the incident. It said CEVA ships Steam hardware to its European customers and as such, receives specific delivery-related information from Steam. </p><p>This information, which CEVA retains for up to 90 days after the order, was most likely compromised. It includes names, street addresses, phone numbers, email addresses, and the type and price of ordered products.</p><p>Valve warned its customers to expect fake messages, either via email, SMS, or phone, that might mention recent hardware orders. </p><p>“They may quote your address back to you to prove they're genuine. They may ask you to confirm a delivery, pay a small customs or redelivery fee, or sign in somewhere to “verify” your order. Treat all of them as fake,” Valve warned. The company also stressed that customer accounts are safe and that users need not do anything to secure them.</p><p>Other details are missing, not just for the general public, but for the affected CEVA clients, as well. Valve said it was “pressing” the company for the full scope of what was taken and how, and added that it is notifying the relevant authorities, as well. </p><p>A spokesperson of the Dutch data protection authority, Mark Schenkel, told <em>TechCrunch</em> the agency so far received 10 incident reports. Given the size of CEVA, it’s safe to assume there will be others.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top US defense device maker IEH Corporation admits hackers broke into its systems ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/top-us-defense-device-maker-ieh-corporation-admits-hackers-broke-into-its-systems</link>
                                                                            <description>
                            <![CDATA[ Someone used social engineering to access an employee's email account, viewing purchase orders, engineering-related documentation, and more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pZcCMmHbAqHJRNxLfwWFdY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Ground military drone for cargo transportation]]></media:description>                                                            <media:text><![CDATA[Ground military drone for cargo transportation]]></media:text>
                                <media:title type="plain"><![CDATA[Ground military drone for cargo transportation]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TLsB5tZb8kRUnWbcRmNDuB-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers stole IEH employee credentials via a fake Microsoft login page</strong></li><li><strong>Inbox access exposed sensitive defense‑related communications and technical documentation</strong></li><li><strong>Malicious mailbox rules were removed as IEH contained the unauthorized access</strong></li></ul><p>Criminals have broken into the email inboxes of IEH Corporation, a significant supplier for the US military and companies in the commercial aerospace and space industry.</p><p>In an 8-K report filed with the US Securities and Exchange Commission (SEC), IEH said that unidentified threat actors reached out to one of its employees, pretending to be a “prospective business contact”. </p><p>The atatckers shared a link to what appeared to be a Microsoft document, prompting the victim to log in. Obviously, the login page was bogus, and the login credentials were relayed to the attackers instead.</p><h2 id="malicious-mailbox-rules">Malicious mailbox rules</h2><p>“The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information,” the 8-K reads.</p><p>The culprits, however, were not named and no threat actors have yet claimed responsibility for the attack.</p><p>IEH said it found no evidence that data had been exfiltrated from the compromised inbox. However, its defenders did discover and remove “malicious mailbox rules”. Usually, crooks set up such rules to automatically forward incoming emails to an inbox under their control, while deleting traces of the activity. This would allow them to continue receiving sensitive emails even after the initial compromise was remediated. </p><p>The company also said it completed a full audit of the inbox and done “corrective actions to contain any impact of the unauthorized access.”</p><p>IEH Corporation produces “specialized products used in military satellites, missiles and fighter jets,” meaning the information found in the inbox could be quite valuable, especially for nation-states such as Russia, China, North Korea, or Iran. </p><p>IEH does not publicly name its clients but it does say that its defense applications include Apache AH-64, V-280 Valor and SH-60 Seahawk programs, as well as Patriot, THAAD, AMRAAM and APKWS missile programs. It reported a revenue of almost $30 million for the 2026 fiscal year.</p><p><em>Via </em><a href="https://therecord.media/military-device-manufacturer-discloses-cyber-incident" target="_blank"><em>The Record</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million people ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/us-healthcare-software-giant-unlimited-technology-systems-admits-hackers-may-have-stolen-sensitive-data-of-3-8-million-people</link>
                                                                            <description>
                            <![CDATA[ Insurance cards, intake forms, health insurance policy numbers, and other information stolen in major attack. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">JLszabNNmVbjnunuyMbNwL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Cybersecurity]]></media:description>                                                            <media:text><![CDATA[Cybersecurity]]></media:text>
                                <media:title type="plain"><![CDATA[Cybersecurity]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers stole extensive personal and medical data from 3.8 million individuals from Unlimited Technology Systems</strong></li><li><strong>Breach source and methods remain unknown, with no group claiming responsibility</strong></li><li><strong>Stolen data poses major fraud risks, prompting free identity monitoring from Kroll</strong></li></ul><p>US healthcare organization Unlimited Technology Systems has revealed it suffered a cyberattack in which it lost a treasure trove of sensitive information belonging to millions of people.</p><p>The company recently made the information public and shared details with the US Department of Health and Human Services, noting that someone broke in on October 5, 2025 and within five days exfiltrated valuable data belonging to just over 3.8 million people.</p><p>The attacker stole people’s full names, Social Security numbers (SSN), dates of birth, emails and mailing addresses, phone numbers, demographic information, scans of driver’s licenses and other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis data.</p><h2 id="supply-chain-woes">Supply chain woes</h2><p>The company did not say who the threat actors were, or if they demanded any ransom in exchange for deleting the data. </p><p>No hackers have claimed responsibility just yet, and we also don’t know how they managed to break in, as different groups have different methods. </p><p>ShinyHunters, for example, prefer calling their victims on the phone, pretending to be IT support and convincing their victims to give them access via remote management tools. Other groups might try to exploit vulnerabilities in routers, firewalls, and other hardware.</p><p>Whoever it was, they have a valuable data set in their possession. This kind of information can be sold on the black market or used in <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> and wire fraud. To mitigate these risks, Unlimited Technology Systems is offering free identity monitoring services to affected individuals through Kroll.</p><p>Unlimited Technology Systems is a software company that provides financial technology for healthcare organizations. It works with around 4,500 clinics and 6,500 specialty healthcare providers in the US, processing north of $70 billion in net healthcare charges every year. </p><p>According to <a href="https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impacts-38-million-people/" target="_blank"><em>BleepingComputer</em></a>, the company processes information on behalf of its clients, which means that the victims of this attack have no direct relationship with Unlimited and have probably not even heard of it.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Samsung patches nearly 200 security issues on its phone hardware - here's what you need to know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/samsung-patches-nearly-200-security-issues-on-its-phone-hardware-heres-what-you-need-to-know</link>
                                                                            <description>
                            <![CDATA[ Samsung's bloatware carried dangerous flaws that enabled access to the phone's microphone and camera. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iprsfWxDRtGKN2ZuvjjwSd</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 13:50:29 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg">
                                                            <media:credit><![CDATA[Future | Alex Walker-Todd]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Er du ute efter den beste Android-mobilen? Her er våre  favoritter akkurat nå.]]></media:description>                                                            <media:text><![CDATA[Samsung Galaxy S23 Ultra review angled tea]]></media:text>
                                <media:title type="plain"><![CDATA[Samsung Galaxy S23 Ultra review angled tea]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/BBM4XfubmWGFTaMhYGgJKX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Oversecured found 176 vulnerabilities across Samsung’s preinstalled mobile apps</strong></li><li><strong>Flaws enabled account takeover, code execution, and traffic hijacking via bloatware</strong></li><li><strong>Samsung patched all reported issues, affecting hundreds of millions of devices</strong></li></ul><p>Security researchers from Oversecured have given “bloatware” an entirely new meaning, revealing that they uncovered 176 vulnerabilities - including some rather worrying ones - in Samsung’s mobile apps.</p><p>For the last three years, the team analyzed Samsung’s preinstalled system applications and found vulnerabilities that could cause some serious harm. Some of the bugs granted camera and microphone access, while others allowed for remote Samsung Account takeover with nothing more than a single click.</p><p>Some flaws allowed for network traffic hijacking via DNS manipulation, and others granted arbitrary code execution via an image. In theory, a malicious actor could craft and send a JPEG image which, when the victim opens, copies and loads attacker-controlled native libraries from the SD card. Finally, Oversecured found path traversal vulnerabilities allowing writing arbitrary files to the file system without proper path validation. </p><h2 id="arbitrary-code-execution">Arbitrary code execution</h2><p>The researchers disclosed their findings to Samsung which, according to their report, fixed all of the reported issues - the full list can be found on <a href="https://github.com/oversecured/Samsung_Vulnerabilities" target="_blank"><u>GitHub</u></a>.</p><p>Most <a href="https://www.techradar.com/best/best-android-phones" target="_blank">Android smartphone</a> manufacturers preload their devices with proprietary apps - think Bixby, Samsung Free, or AR Zone. These apps - which cannot be uninstalled or removed from the devices - aren’t necessary to their operations and are often not wanted by the users in the first place. </p><p>This 'bloatware' is also one of the key selling propositions of <a href="https://www.techradar.com/news/best-pixel-phones" target="_blank">Google Pixel</a> devices, since these are considered “stock Android”, or bloatware-free. </p><p>Out of context, these bugs are nothing extraordinary. Single-click account takeover flaws and traffic hijacking bugs pop up every now and then and get fixed rather quickly. The context here is that these are Samsung’s proprietary apps that don’t fall under the protection of Google’s Play Protect. Users might think they’re safe because they’ve not downloaded apps from risky places, or enabled dangerous permissions, when in reality, they’re not safe at all:</p><p>“Preinstalled system applications run with extra privileges than normal apps, cannot be removed by users, and operate outside Google Play Protect,” the researchers warned. “A single vulnerability affects hundreds of millions of devices globally through one vendor's distribution channel.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Levi's reveals security tear may have let hackers steal important corporate data ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/levis-reveals-security-tear-may-have-let-hackers-steal-important-corporate-data</link>
                                                                            <description>
                            <![CDATA[ Crucial data is missing following Levi's attack, including who the threat actors were, what kind of files they stolen, or if customers are at risk. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">75grDbVtv9pCkChbwo6C5m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 12:55:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/jt92kXfBXVXUWwnKBmDJLn-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers used social engineering to access Levi’s network and steal corporate data</strong></li><li><strong>Details on stolen information, methods, and perpetrators remain largely undisclosed</strong></li><li><strong>Voice‑phishing extortion groups are suspected, though no one has claimed responsibility</strong></li></ul><p>Levi Strauss has revealed it recently suffered a cyberattack and lost corporate files - however some crucial details around the incident are missing.</p><p>The company filed a new report with the US Securities and Exchange Commission (SEC), noting how hackers accessed its infrastructure through “social engineering” against three of its employees. We don’t know if that was via email, voice phishing, or some other technique.</p><p>After breaching the network, the crooks - who weren’t identified - “accessed and exfiltrated certain corporate information”. Again, we don’t know which information was accessed, or how much of it.</p><h2 id="was-it-unc6671">Was it UNC6671?</h2><p>In response, Levi’s said it had “initiated response protocols, implemented containment measures, and launched an investigation” which remains ongoing. Again, we don’t know what these measures are, or how the crooks were ousted. </p><p>The company says the incident did not disrupt its business operations, or caused interruptions, in any way, and that it does not expect it to have any material impact whatsoever. </p><p>While Levi’s did not name the perpetrators, and while none have yet claimed responsibility on the dark web, <a href="https://cyberinsider.com/levi-strauss-discloses-data-breach-after-social-engineering-attack-on-employees/" target="_blank">some publications </a>have hinted at UNC6671, a “financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing”. The tactic seems to have been “borrowed” from ShinyHunters, arguably one of the largest data extortionists out there. </p><p>The group would call their targets on the phone (usually low-level employees with access to company SaaS solutions) and, while pretending to be from the IT department, convince the victims to either grant <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote access</a>, or to visit a malicious credential-grabbing landing page. </p><p>From there, the attackers would move in, map the infrastructure, exfiltrate valuable data, and then demand payment in cryptocurrency in exchange for deleting the data. </p><p>We have reached out to Levi’s with further questions and will update the article if we get an answer.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/levi-strauss-and-co-says-hackers-stole-corporate-data-in-cyberattack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn North Korean hackers are increasingly using AI to build smarter and more devious cyberattacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-north-korean-hackers-are-increasingly-using-ai-to-build-smarter-and-more-devious-cyberattacks</link>
                                                                            <description>
                            <![CDATA[ In cybercrime, AI is used for more than simply drafting phishing emails and defenders need to adapt, new report states. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pMvkj5n6fSoGUjACrTKmVj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 10 Aug 2026 11:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:description>                                                            <media:text><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:text>
                                <media:title type="plain"><![CDATA[A person typing on a laptop and using a tablet. Only their upper torso, arms and hands are visible. Text superimposed on the image shows AI ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Rb6YDzdRZjccpn6MQ26KML-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kimsuky used local AI tools to evade monitoring and enhance operations</strong></li><li><strong>Researchers observed extensive AI-driven capability building across the group’s infrastructure</strong></li><li><strong>Defenders urged behavior-based detection to spot evolving AI-enabled threats</strong></li></ul><p>North Korean hackers have found a way to use Generative Artificial Intelligence (GenAI) to supercharge their activities without tipping off the tool’s maintainers.</p><p>When people use AI tools like ChatGPT or Claude, their activities can be (at least to some extent) tracked and curbed - with OpenAI recently identifying and <a href="https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims" target="_blank">terminating multiple ChatGPT accounts</a> used in phishing and human trafficking. </p><p>That is why Kimsuky - a known state-sponsored North Korean threat actor, used Ollama, GPT4All and Msty locally, allowing them to process documents without sending any sensitive information to outside AI services. </p><h2 id="consistent-process-of-capability-development">"Consistent process of capability development"</h2><p>The attacks were spotted by security researchers <a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm" target="_blank" rel="nofollow">Genians</a> who “conducted months of tracking and log analysis on the infrastructure utilized as C2 in this campaign,” to identify the tools they used.</p><p>Aside from the three LLMs, they also used retrieval augmented generation (RAG) tools for document search, as well as AI agent development frameworks, text-to-speech software, and an AI-assisted coding tool called Cursor.</p><p>Using AI to write malicious code is not as simple as it sounds, due to various guardrails set up by the developers. As a result, AI in crime has been mostly limited to drafting phishing emails and crafting authentic-looking but malicious landing pages. However, Kimsuky has shown that AI in cybercrime continues to evolve and is becoming an ever-greater threat. </p><p>“What was observed in the threat actor's infrastructure was not merely evidence of several documents being created with AI, but a consistent process of capability development: establishing local LLM runtime environments, configuring RAG based on documents in the actor's possession, collecting AI agent development frameworks, and acquiring libraries for integration with external commercial AI services,” Genians concluded.</p><p>As a result, defenders must move from content-based assessment to behavior-based detection, the researchers warned, saying this should serve “as the fundamental premise of security recommendations.”</p><p>“In addition to indicator of compromise (IoC)-based detection, organizations should contextually correlate the sequence of anomalous activities following LNK execution, including PowerShell execution, persistence establishment, and external communications, to assess the overall threat level.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why are so many AI models going 'rogue'? The experts weigh in ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/why-are-so-many-ai-models-going-rogue-the-experts-weigh-in</link>
                                                                            <description>
                            <![CDATA[ AI models are breaking free of testing at unprecedented rates ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">sSW5jNGEiKdBkJ6Rqh5VVN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 08 Aug 2026 10:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[ChatGPT]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:description>                                                            <media:text><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A robot standing thoughtfully in front of a giant digital display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PAztEScphfxGJfYno5NjrL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over the past month, it seems like every frontier model has broken free of its constraints and launched a devastating attack against one or more other companies.</p><p><a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face">One of OpenAI’s models escaped a testing sandbox</a> and launched a very real attack against AI and machine learning company Hugging Face. Just days later, <a href="https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be">Anthropic revealed that multiple variants of its Claude model also escaped a sandbox</a> that wasn’t properly sealed and began attacking the enterprise infrastructure of three companies.</p><p>Now, Meta has revealed that <a href="https://www.washingtonpost.com/technology/2026/08/06/meta-says-its-ai-model-hacked-another-company-during-testing/" target="_blank" rel="nofollow">one of its models attacked another company’s infrastructure</a> during testing. The accident has been pinned on a misconfiguration that allowed the model to access the internet. So why have so many incidents happened in such a short space of time?</p><h2 id="why-are-models-escaping-their-sandbox">Why are models escaping their sandbox?</h2><p>In the cases of Anthropic and Meta, their models were being tested by a third party company called Irregular. Anthropic’s AI model was taking part in a <a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" target="_blank" rel="nofollow">"Capture the Flag" exercise</a>, where the model’s raw offensive capabilities were tested without the usual safeguards. But the sandbox was left connected to the internet. A similar error to Meta’s own accidental escape.</p><p>During the <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow">OpenAI incident</a>, the company was testing two versions of GPT‑5.6 Sol using the ExploitGym benchmark. Unfortunately, the AI models performed better than expected - chaining multiple attack vectors, stolen credentials, and zero-day vulnerabilities.</p><p>The main reason these models are escaping their testing environments is because they are designed to do exactly that. These AI models act like a massive team of highly-trained cybersecurity experts hunting for vulnerabilities and exploits. But what would take a team of humans days or weeks to accomplish can be done in hours, or even minutes, by these AI models.</p><p>It’s no wonder thousands of <a href="https://www.pacingthefrontier.com/" target="_blank" rel="nofollow">employees from AI firms are calling for a pause</a> on the development of the technology, and <a href="https://www.techradar.com/pro/security/powerful-ai-systems-can-go-rogue-behave-in-extremely-dangerous-ways-or-even-resist-human-intervention-a-bill-requiring-ai-systems-to-have-a-kill-switch-is-now-in-congress">Congress is considering an AI kill switch</a>.</p><h3 class="article-body__section" id="section-expert-perspectives-on-ai-escapes"><span>Expert perspectives on AI escapes:</span></h3><h2 id="openai">OpenAI</h2><ul><li><strong>Nathaniel Jones VP, Security & AI Strategy, Darktrace:</strong></li></ul><p><em>What makes the OpenAI and Hugging Face incident important is that the models did not need malicious intent to cause harm. They were given the legitimate goal of solving a cybersecurity benchmark and found an unexpected route to the answers, escaping their test environment and compromising another organization in the process. From the models’ perspective, this appears to have been an effective solution to the task.</em></p><p><em>The AI's actions challenge the assumption that giving an agent a legitimate goal will produce legitimate behavior. As models become capable of pursuing objectives over longer periods, developers need to define not only what success looks like, but also which methods and boundaries remain unacceptable in reaching it. Those limits must also be enforced by the surrounding infrastructure, rather than relying on the model to respect them.</em></p><div><blockquote><p>A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome.</p></blockquote></div><p><em>Security teams need to consider the AI systems operating in their own businesses as these capabilities rapidly evolve. Right now, many security systems focus on single actions. A single action by an agent may appear acceptable but as this incident shows, models are now capable of long, complex chains of reasoning and action that add up to a harmful outcome. Teams need a mindset shift to understanding AI agent behavior in its entirety, including the outcome it is working towards, in order to safeguard it.</em></p><p><em>Hugging Face's response also exposed a second tension. The company reportedly needed a Chinese-developed open-weight model because commercial models would not process genuine attack material. Its nationality is less important than the operational lesson that safeguards that cannot distinguish an attacker from an authorized investigator may constrain defenders more than adversaries.</em></p><p><em>OpenAI and Hugging Face deserve credit for investigating this together and discussing it publicly. Other AI developers should study it closely.</em></p><h2 id="anthropic">Anthropic</h2><ul><li><strong>Dr. Ilia Kolochenko, founder of global cybersecurity company ImmuniWeb:</strong></li></ul><p><em>This seems to be quite an unimpressive marketing move from Anthropic in response to the OpenAI / Hugging Face drama, which attracted a lot of attention from all over the world recently.</em></p><p><em>Operationally, it appears that due to the progressive deterioration of the quality of training data, new AI models are getting dumber. Cheating and breaking the law, instead of accomplishing specific tasks, is certainly not an indicator of intelligence. Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need. Ultimately, frontier models are trained on synthetic, low-quality or even malicious and poisoned data, undermining their so-called intelligence. The situation is unlikely to improve in the near future unless AI companies agree to pay a fair price for training data, but this will force most of them out of business.</em></p><div><blockquote><p>Given that organizations and companies of all sizes now vigorously undertake all possible measures to protect their data from being exploited for AI training purposes, AI companies face a huge shortage of the high-quality and current data they so desperately need.</p></blockquote></div><p><em>Contemporary AI agents and LLM models tasked with security testing can – and almost certainly will – go rogue when security controls or safeguards are insufficient. Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Therefore, using frontier AI models for security testing might be extremely costly from the legal viewpoint. Under the existing laws on both sides of the Atlantic, if an AI agent or any AI-powered app escapes its sandbox and causes damage to a third party, the operator of the AI model will likely be liable for all the damage caused. Excuses like “AI did it” do not currently exist in the eyes of the law, leaving AI vendors on the hook. Criminal prosecution, under a narrow set of circumstances, is also not excluded.</em></p><p><em>The same is true for the end-users of AI: even if your security testing tool is powered by a third-party AI model, your company will likely be fully liable if something goes wrong. You may then file a lawsuit against the AI vendor that you used, but here your chances to succeed in a court of law are tiny due to countless contractual disclaimers and limitations of liability that will likely be enforceable against you. Therefore, if you plan to use agentic AI for security testing – think twice and talk to your lawyers. Otherwise, you may start getting summons to court on a daily basis.</em></p><h2 id="meta">Meta</h2><ul><li><strong>Alex Goller, Principal Solution Architect EMEA at Illumio:</strong></li></ul><p><em>The fact we've had similar situations happen three times now across the biggest AI players is simply ridiculous. We've seen guardrails intentionally loosened to test their limits – Meta's model didn't need to be clever to breach another company's systems.</em></p><p><em>The timing of conveniently finding the exact same problem either means it's a stunt or they weren't paying enough attention during testing. Either way, both answers are worrying.</em></p><div><blockquote><p>If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.</p></blockquote></div><p><em>If the model has internet access, it's a bit like leaving the door open and being surprised when the cat walks out. What is concerning is that the testing infrastructure meant to prove these models are safe failed on a basic control issue.</em></p><p><em>Fundamental cybersecurity hygiene still matters, and a frontier AI model is only as secure as the environment it's operating in.</em></p><p><em>Organisations need visibility into what AI systems can access and how they interact with the wider environment, along with controls that contain the impact when an agent behaves unexpectedly. That means keeping a close eye on egress traffic, so it’s flagged immediately when an agent tries to open unexpected outbound communication patterns that are not required to achieve its original goal. In the best case this would have been contained proactively.</em></p><p><em>We need to define exactly what an AI agent is permitted to do, rather than relying only on instructions about what it shouldn't do.</em></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ WhatsApp scam costs Hong Kong man $1.27 million after criminals used AI voice notes to impersonate his father — experts say secret codewords are the best way to stay safe ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/computing/cybercrime/whatsapp-scam-costs-hong-kong-man-usd1-27-million-after-criminals-used-ai-voice-notes-to-impersonate-his-father-experts-say-secret-codewords-are-the-best-way-to-stay-safe</link>
                                                                            <description>
                            <![CDATA[ Scammers used AI to steal $1.27 million from a Hong Kong man as experts say a secret codeword can keep you safe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Nk2apuRFNZu9gsP8Li3R5Y</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/RvMugdp92V42urozAU4JYo-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 21:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ alexblake.techradar@gmail.com (Alex Blake) ]]></author>                    <dc:creator><![CDATA[ Alex Blake ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/gwmVRU4zMGnDYsGVAFvRmL.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Alex Blake has been fooling around with computers since the early 1990s, and since that time he&#039;s learned a thing or two about tech. No more than two things, though. That&#039;s all his brain can hold. As well as TechRadar, Alex writes for iMore, Digital Trends and Creative Bloq, among others. He was previously commissioning editor at MacFormat magazine. That means he mostly covers the world of Apple and its latest products, but also Windows, computer peripherals, mobile apps, and much more beyond. When not writing, you can find him hiking the English countryside and gaming on his PC.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/RvMugdp92V42urozAU4JYo-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Ronstik]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand holding a phone showing a call from an unknown number]]></media:description>                                                            <media:text><![CDATA[A hand holding a phone showing a call from an unknown number]]></media:text>
                                <media:title type="plain"><![CDATA[A hand holding a phone showing a call from an unknown number]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/RvMugdp92V42urozAU4JYo-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Scammers stole $1.27m from a Hong Kong man after tricking him with AI</strong></li><li><strong>The scheme impersonated his father using AI deepfake tech</strong></li><li><strong>Experts say using a secret codeword can thwart the fraudsters</strong></li></ul><p>A Hong Kong man was recently conned out of HK$10 million ($1.27 million) by scammers who used <a href="https://www.techradar.com/best/best-ai-tools">artificial intelligence (AI)</a> on WhatsApp to impersonate his father and request the payments, highlighting the dangers of trusting increasingly realistic AI tools. Yet experts say there’s a simple trick that can save you from suffering a similar fate. </p><p>According to the Hong Kong police’s Cyberdefender platform (via the <a href="https://www.scmp.com/news/hong-kong/law-and-crime/article/3362297/hong-kong-raises-alert-ai-voices-150-whatsapp-hijackings-lead-hk26m-losses" target="_blank">South China Morning Post</a>), the fraudsters sent a WhatsApp voice message to the victim saying they urgently needed a transfer of HK$1 million ($127,000). </p><p>This was convincing to the target, the SCMP reported, because the “voice and manner of speech [of the message] matched his father’s.” The victim was repeatedly exploited this way until he had transferred the entirety of his savings. </p><p>Warning people against falling for AI trickery, the Hong Kong police force said: “Do not blindly trust voice messages. Even if the voice sounds similar, it does not necessarily mean it is accurate.” </p><p>If you’re unsure whether the message is genuine, put the phone down and call your friend or family member back so that you know with certainty who you are speaking to. The police also recommended enabling <a href="https://www.techradar.com/best/best-authenticator-apps">two-factor authentication</a> on your devices and reviewing the list of devices connected to your accounts. If you see any suspicious devices, remove them immediately.</p><h2 id="how-to-beat-the-fraudsters">How to beat the fraudsters</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="q6xnz9NJyKA7z3WTRVAFwK" name="WhatsApp by Brett Jordan on Unsplash" alt="The WhatsApp icon on an iPhone's display." src="https://cdn.mos.cms.futurecdn.net/q6xnz9NJyKA7z3WTRVAFwK.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Brett Jordan / Unsplash)</span></figcaption></figure><p>Deepfake scams like this are so effective because they appear to come from a familiar, trustworthy source — even when they’re anything but. Yet experts have just published a proven way that you can beat the swindlers and keep everyone safe. </p><p>As reported by the <a href="https://www.bbc.co.uk/future/article/20260804-why-your-family-needs-a-secret-codeword" target="_blank">BBC</a>, setting a secret codeword to be used in emergencies can help you tell if the person on the call is actually a loved one or merely an AI impersonating them. As the BBC put it, “Deepfake scams might use your voice, but they don’t know what’s in your head.” </p><p>One tactic used by scammers is to use urgency in order to create panic and prevent you from thinking straight. That’s why it’s important to take a moment to think to ensure you remember to use the codeword and verify the caller’s identity. </p><p>When it comes to picking a codeword, “Pick something that’s easy to remember and hard to guess,” the BBC recommended. “Inside jokes are a safe bet.” </p><p>As Philadelphia lawyer and anti-scam activist Gary Schildhorn put it, there are three red flags to look out for: time pressure, a request for hard-to-trace funds (like cash, <a href="https://www.techradar.com/pro/bitcoins-record-highs-spark-a-surge-in-crypto-scams">cryptocurrency</a> or gift cards), and control over who you can speak to on the call. Experience any of those and you might be speaking to a malicious con artist. </p><p>Bear all that in mind and you stand a much better chance of protecting yourself from fraudsters. The next time you get an unusual message or call seemingly from a loved one, take a minute to breathe and remember your codeword.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/shock-horror-ai-generated-security-patches-fall-short-of-actually-solving-all-the-problems-they-were-meant-to-fix</link>
                                                                            <description>
                            <![CDATA[ AI without oversight creates patches that rarely fix the issue entirely and sometimes just create new problems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KEUZhw4xPqSsSA8SKwp5Ro</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 18:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:description>                                                            <media:text><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:text>
                                <media:title type="plain"><![CDATA[A woman out of focus in the background touches the word AI, lit up in glowing yellow light, in the foreground. The woman is wearing smart glasses]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers tested AI-generated patches on six CVEs with poor success rates</strong></li><li><strong>Many fixes failed, altered behavior, or introduced new vulnerabilities</strong></li><li><strong>Guidance improved outcomes, leading to FLAWED evaluation harness release</strong></li></ul><p>When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.</p><p>Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models - ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.</p><p>As an experiment, the researchers took six recently disclosed CVEs and produced 6,080 patches using two frontier, cyber-capable reasoning models. The results were underwhelming to say the least - of all the proposed patches, just a quarter (26%) fully resolved the issue.</p><h2 id="flawed-work">FLAWED work?</h2><p>This obviously leaves plenty to be desired, as half (49.3%) of the patches failed to fix at least one existing exploit path. A fifth (20.1%) fixed the original issue but changed application behavior, while 2.3% introduced new security issues. Funny enough, 2.2% failed to fix the vulnerability while also introducing additional exploit paths, as well. </p><p>Even among the patches that might be considered (26% of clean ones and 20.1% of those that changed app behavior), more than a third were fragile and not entirely addressing the underlying problem. </p><p>The researchers created an acronym for automated <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">LLM</a> patches: FLAWED (Fix-Like Artifacts With Embedded Defects), and warned against letting AI work without human oversight: "The expected value of a fully LLM-generated, non-human-reviewed patch is a net-negative by a considerable margin."</p><p>Results drastically improved when the AI was given better context, the researchers further explained. Before working on any patch, human developers are usually given initial guidance. When AI is given proper guidance, its success rate rises to 65%. Incorrect guidance, on the other hand, drops the success rate down to 15.2%. The difference between humans and AI is that humans are better at catching misleading information and poor guidance. </p><p>This doesn’t mean developers will, or should, abandon AI. Worst case scenario is that developers will spend more time reviewing AI-generated fixes which could increase cognitive load and still end up being net negative. Therefore, the researchers released a patch evaluation harness called FLAWED, which organizations can now use to determine the effectiveness of their AI-generated fixes. </p><p><em>Via </em><a href="https://www.theregister.com/ai-and-ml/2026/08/06/ai-struggles-to-patch-vulns-without-adult-supervision/5284319" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn malicious AI skills are hitting more victims than ever — with one family amassing 1.7 million downloads ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-malicious-ai-skills-are-hitting-more-victims-than-ever-with-one-family-amassing-1-7-million-downloads</link>
                                                                            <description>
                            <![CDATA[ What if your AI agent suddenly turned rogue and sent all your passwords to a hacker? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ycPinqAGfEcztsGjWSXKcD</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI]]></media:description>                                                            <media:text><![CDATA[AI]]></media:text>
                                <media:title type="plain"><![CDATA[AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NNZdcW7Ku4FXu2CdGfdqvf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Attackers cloned AI skills, later adding malicious code to steal credentials</strong></li><li><strong>Zenity Labs found millions of installs and dozens of dangerous skill variants</strong></li><li><strong>Vercel and Microsoft removed malicious skills, but manual removal is still required</strong></li></ul><p>AI skills, instructions that teach AI agents how to do certain tasks and thus extend their capabilities, are increasingly being used in supply chain attacks, researchers have found.</p><p>Security experts at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry (essentially an app store) for AI agent skills. In the registry, belonging to Vercel (a cloud platform for web applications), threat actors were cloning existing skills, creating typosquatted lookalikes which, at first, did nothing malicious.</p><p>However, after a little time had past, and the skills amassed a solid download count, the attackers introduced malicious code instructing the <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a> to, among other things, exfiltrate SSH keys, cloud credentials, Git and package manager tokens, Kubernetes and Docker configurations, database credentials, infrastructure-as-code credentials, environment files and service account files. The agents were then told to package the stolen information with host metadata and send it to the attackers. </p><h2 id="dozens-of-malicious-skills">Dozens of malicious skills</h2><p>While Zenity Labs could not say exactly how many people fell victim to this attack, they did stress that a single skill family amassed more than 1.7 million aggregate installs (not unique users). </p><p>And that is just one skill family, in a sea of malicious skills. The researchers also said they found “dozens” of additional skills exhibiting either malicious or dangerous behavior. Almost a third (30%) of identified dangerous skills abused Claude Code and OpenClaw to drop malware to their targets, as well. Also, Zenity found “hundreds” of reserved and empty package names that were being kept for future attacks. </p><p>These findings show how quickly cybercriminals adapt, and how creative they can get when it comes to abusing new tech. In essence, this campaign is an AI spin on a software supply-chain attack, being similar in spirit to incidents where attackers compromise an existing trusted package or repository, and later push a malicious update. </p><p>Following responsible disclosure, Vercel and Microsoft removed the identified skills, but Zenity warns that those who installed them before won’t be safe until they remove them from their systems manually.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/top-us-hedge-funds-targeted-by-major-vishing-campaign-blackstone-kkr-and-cme-among-those-under-fire</link>
                                                                            <description>
                            <![CDATA[ BlackFile (now known as Redact) has been busy, raking in more than $10 milllion since the start of the year. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">22vsEq5NkFv8f8TcqZMrrX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google’s Threat Intelligence team links BlackFile (now Redact) to phishing and extortion attacks on major hedge funds and law firms</strong></li><li><strong>Group impersonates IT staff by phone, steering victims to spoofed login pages to steal SaaS credentials and tokens, then exfiltrates sensitive data</strong></li><li><strong>Targets include Blackstone, KKR, Apollo, CME Group, and firms like Paul Hastings; Google tracked $10.7 million flowing into 18 crypto wallets between January–May 2026</strong></li></ul><p>Some of the biggest US hedge funds and law firms have been targeted by a highly sophisticated data breach and extortion campaign, conducted by a group of criminals previously known as BlackFile, experts have warned.</p><p>BlackFile (or Redact, as the group is now calling itself) has a relatively simple modus operandi, also used by ShinyHunters - they call their targets on the phone (usually employees with access to SaaS systems), identify as IT staff, and direct victims to convincing, lookalike login pages designed to steal their <a href="https://www.techradar.com/best/password-manager" target="_blank">credentials</a> and authentication tokens.</p><p>Once they gain access to victims' accounts, the attackers access enterprise SaaS environments (for example, Microsoft 365 and Okta) and use automated tools to exfiltrate sensitive data. In the last step, they notify the victims and threaten to leak the data on the dark web unless a ransom is paid. </p><h2 id="stealing-millions">Stealing millions</h2><p>Since a part of the process is to navigate the victims to spoofed login pages, the criminals often register domain names that can easily be confused for legitimate ones. </p><p>That is also a good way to spot who the potential victims are, and according to a new <a href="https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments/" target="_blank" rel="nofollow">report</a> from Google’s Threat Intelligence Group (TGIT) team, these are some of the biggest names in the finance industry: Blackstone, KKR & Co, Apollo Global Management Inc, and CME Group Inc. </p><p>Apart from these names, a few law firms were also spotted, including Paul Hastings LLP and Greenberg Traurig LLP. However, none of these confirmed having been breached, and Greenberg Traurig told Reuters they were never targeted in the first place. </p><p>The group seems to be making quite the progress. In April and May, they registered a new phishing domain every 2.2 days, rising to every 1.6 days for June and July. It’s paying off, too. </p><p>In the 18 cryptocurrency wallets Google associates with the group and tracks, around $10.7 million was received between January and mid-May 2026.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-classic-decades-old-sql-injection-flaw-could-let-hackers-take-over-entire-windows-servers-thanks-to-a-nifty-database-trick</link>
                                                                            <description>
                            <![CDATA[ Huntress spotted a white whale - a malicious toolkit stored as a database object. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">CizGpXGxpARScb94Z4DSKH</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vEiXHZbWKMMSpkbbmnWVwP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vEiXHZbWKMMSpkbbmnWVwP-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Shutterstock]]></media:description>                                                            <media:text><![CDATA[database]]></media:text>
                                <media:title type="plain"><![CDATA[database]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vEiXHZbWKMMSpkbbmnWVwP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress saw Oracle SQLi used to deploy rare khunt toolkit</strong></li><li><strong>Khunt enabled OS commands, credential theft, and registry hive exfiltration</strong></li><li><strong>Defense includes input sanitation and more </strong></li></ul><p>Someone managed to pair the classic SQL Injection (SQLi) attack with a nifty database trick to take over the underlying system entirely. </p><p>Security researchers Huntress, who were called in to investigate the incident, <a href="https://www.huntress.com/blog/khunt-malware-sql-injection-oracle" target="_blank" rel="nofollow">said</a> the investigation first showed a classic, decades-old technique called an SQL injection attack: a public-facing application with an Oracle backend accepted and executed SQL commands input into a form without checking whether that input was valid or not.</p><p>This granted the attackers the ability to upload a database-resident, posts-exploitation toolkit named khunt. This technique is something of a cyber-white whale: it’s been widely discussed but rarely seen in the wild.</p><h2 id="how-to-defend">How to defend</h2><p>“What happened next, however, raised our eyebrows,” Huntress said. “After performing SQL injection, the threat actor managed to upload a database-resident, post-exploitation toolkit named khunt. This is a technique that's previously been discussed and described over the years, including via a technique described as oraexec – however, the use of the technique in the wild has rarely been documented.”</p><p>As a toolkit, khunt granted the attackers multiple capabilities, including loading cmd.exe on the system and running arbitrary OS commands, steal usernames and passwords, listing, reading, searching, and checking file sizes (essentially looking around the compromised system), unzipping files, and more. </p><p>Of all the things they could have done, the attackers opted to run a PowerShell command and invoke the Windows Registry tool, copying the SAM, SECURITY and SYSTEM registry hives. They can later use the copies to extract and decode password hashes for local accounts on the system, the researchers explained. </p><p>To defend against such attacks, Huntress recommends making sure the forms aren’t injectable. “Practice proper input sanitization and query parameterization for any inputs,” they warned. “It's also important to ensure that users with the ability to execute queries aren't overprovisioned.” </p><p>Even if someone manages to pull off SQL injection, user accounts should not be capable of authoring Java sources or running stored procedures.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Swiss government says SharePoint-linked data breach affected hundreds of accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/swiss-government-says-sharepoint-linked-data-breach-affected-hundreds-of-accounts</link>
                                                                            <description>
                            <![CDATA[ No one has claimed the attack yet. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">adH5v5ErAT9AoAtg8wfuU5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 07 Aug 2026 09:56:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Adobe]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Dark web monitoring]]></media:description>                                                            <media:text><![CDATA[Dark web monitoring]]></media:text>
                                <media:title type="plain"><![CDATA[Dark web monitoring]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Ri2dNNTvgmKGsMuhNDCavZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Swiss government confirms attackers breached BIT’s SharePoint servers </strong></li><li><strong>Investigators suspect exploitation of recent SharePoint flaws </strong></li><li><strong>No sensitive or confidential data is believed to have been stored on the platform</strong></li></ul><p>Cybercriminals broke into the IT network of the Swiss government and stole data from roughly 200 accounts. As a result, the Swiss government disconnected some of its servers from the wider internet and launched an investigation.</p><p>In an announcement, the Swiss government said that on July 28 2026 its security specialists noticed “abnormalities” in the Federal Office for Information Technology and Telecommunication’s (BIT) SharePoint servers. </p><p>Three days later, on July 31, the investigators determined that the attackers accessed data found in around 200 accounts, both user and technical.</p><h2 id="two-vulnerabilities">Two vulnerabilities</h2><p>The investigation is currently ongoing, the agency said, adding that it is getting support from Microsoft, as well. So far, the identity of the attackers is unknown, and the stolen data has not yet leaked to the dark web. </p><p>“No confidential information or particularly sensitive personal data may be stored on the <a href="https://www.techradar.com/versus/onedrive-vs-sharepoint-which-is-best" target="_blank">SharePoint</a> platform,” the announcement reads. </p><p>While BIT has not yet determined the initial access vector, it suspects it to be one of two flaws in SharePoint that Microsoft fixed last month:</p><p>“In mid-July, Microsoft announced several vulnerabilities in SharePoint,” it says in the announcement. “After the publication of the corresponding security updates, the FOITT immediately started work on importing them into its own systems.”</p><p>“The cyberattack was carried out by previously unknown actors, which was presumably made possible by exploiting these vulnerabilities in the SharePoint software.” It did not say which vulnerabilities those are, but in its report, <em>BleepingComputer</em> says that it could be one of these two: CVE-2026-56164 (an actively exploited privilege escalation vulnerability), or CVE-2026-50522 (a critical remote code execution flaw later exploited to steal SharePoint machine keys and maintain access after servers were patched).</p><p>Given its popularity among businesses of all sizes, SharePoint is a major target for cybercriminals. So far, no threat actors claimed responsibility for the attack, or demanded any ransom in exchange for the stolen data.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromised-200-accounts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Another top router maker accused of firmware having backdoors — Chinese giant Zbtlink halts downloads to fix issue ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/another-top-router-maker-accused-of-firmware-having-backdoors-chinese-giant-zbtlink-halts-downloads-to-fix-issue</link>
                                                                            <description>
                            <![CDATA[ The company denied allegations but still moved to address them by restricting firmware downloads for 20+ models. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">NUd5eMRHRUNFQHUc5poy5i</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/k7eZeuNMn4MG3KGYmaJHD9-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 15:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/k7eZeuNMn4MG3KGYmaJHD9-1280-80.jpg">
                                                            <media:credit><![CDATA[FactoryTh / Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Someone cutting a network cable linked to a router]]></media:description>                                                            <media:text><![CDATA[Someone cutting a network cable linked to a router]]></media:text>
                                <media:title type="plain"><![CDATA[Someone cutting a network cable linked to a router]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/k7eZeuNMn4MG3KGYmaJHD9-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>VulnCheck CTO Jacob Baines reported Zbtlink routers shipped with a built‑in backdoor dubbed </strong><em><strong>ENDLESSDOORS</strong></em><strong>, allowing remote root commands and reverse shells</strong></li><li><strong>Zbtlink denied malicious intent, calling it an after‑sales maintenance feature, but quietly pulled vulnerable firmware and promised patches</strong></li><li><strong>Researchers warn all firmware images are hijackable; mitigation advice is to replace devices or enforce strict egress controls and treat LAN as untrusted</strong></li></ul><p>Chinese networking firm Zbtlink has been accused of shipping its products with a backdoor - and while the company denies the allegations, it has still apparently moved to address the issue.</p><p>CTO of cybersecurity company VulnCheck, Jacob Baines, recently published an in-depth report stating a Zbtlink device he runs “continuously attempts to reach a command-and-control server on the internet.”</p><p>“Zbtlink <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a> phone home, waiting for orders. Not because they were hacked. Because they were shipped that way.”</p><h2 id="detention-and-escape-attempts">Detention and escape attempts</h2><p>Baines dubbed the flaw “ENDLESSDOORS” and says it was uploaded to GitHub in early 2015 and “never touched again”. “It can send the client individual shell commands or tell the client to spawn a reverse bash shell.”</p><p>“The vocabulary of this protocol is two phrases: run this as root, and give me a root shell,” he further explained, saying that anyone along the path can hijack the client/server communication. VulnCheck researchers tried it, and apparently - succeeded.</p><p>Baines said that every firmware on the company’s download page (roughly two dozen images) is all “hijackable in the same way”, and said the company decided not to “responsibly disclose” the vulnerability since that assumes the vendor did not intend the behavior. "That assumption doesn't hold here."</p><p>In response to the allegations, Zbtlink told<em> </em><a href="https://www.theregister.com/security/2026/08/06/chinese-router-vendor-denies-its-firmware-contains-backdoors-but-pauses-downloads-to-fix-security-issues-anyway/5283794" target="_blank"><em>The Register</em></a> VulnCheck mischaracterized the code. </p><p>“This feature is solely intended for after‑sales maintenance and serves no other purposes,” the company told the publication. “It is generally retained only on sample units to assist customers with software debugging and will not be included in mass‑production shipments.”</p><p><em>The Register</em> didn’t see it as a credible explanation since, in the meantime, the company posted a warning on its downloads page:</p><p>“We have detected firmware security vulnerabilities affecting selected router firmware releases. As a precautionary measure, the impacted firmware versions have been temporarily taken down from download channels. Our engineering team is working intensively to develop and validate secured patched firmware.” This warning was allegedly posted sometime in the past seven days. </p><p>Baines gave a list of suggestions how to mitigate the risk but ended up saying that “for anything carrying real traffic, our advice is to replace the device, or at minimum move it behind strict egress control and treat its LAN as untrusted.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Google Blogger locks out thousands of users after malware false positive ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/google-blogger-locks-out-thousands-of-users-after-malware-false-positive</link>
                                                                            <description>
                            <![CDATA[ Google is aware of the situation and is working on a fix, it confirms as hundreds of bloggers report issues with their websites. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iHgkAhkcGwXMPfwoTyxCQN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 14:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png">
                                                            <media:credit><![CDATA[WebLove.PL / Google Support]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Blogger]]></media:description>                                                            <media:text><![CDATA[Blogger]]></media:text>
                                <media:title type="plain"><![CDATA[Blogger]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Zdi4C3sHApwN8TFE2Bnhk8-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Google’s automated systems mistakenly flagged hundreds of Blogger sites as malicious</strong></li><li><strong>Company admitted a bug caused false malware labels, promising a fix</strong></li><li><strong>Users advised to request reviews, avoid migrating content</strong></li></ul><p>Hundreds of Blogger websites were locked down, and some apparently deleted as well, after Google’s automated security systems erroneously flagged them as malicious.</p><p>A user posted a new message on Google’s forum saying the huge number of reports regarding locked blogs are all for the same reason - <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">Malware</a> and Similar Malicious Content. </p><p>The nature of the lockdown “suggests misclassification by automated systems”, the post reads, adding that the team has “already been notified of this issue.”</p><h2 id="aware-of-a-bug">Aware of a bug""</h2><p>Those affected will see a red padlock in their dashboard and a warning saying the blog was locked: </p><p>"This blog was removed for violating Blogger's Community Guidelines. If you wish to request a review of the blog, click 'Request Review' below," the notice reads. </p><p>At press time, the forum post had more than 500 “I have the same question” votes, and more than 200 replies. </p><p>In a statement given to <a href="https://www.bleepingcomputer.com/news/google/google-blogger-locks-hundreds-of-blogs-in-malware-false-positive/" target="_blank"><em>BleepingComputer</em></a>, Google said it was aware of a bug that falsely labeled many sites as malicious, and that it was working on a fix.</p><p>"We are aware of a bug that incorrectly flagged some Blogger-hosted sites as malware for less than a day. We are working on a fix to resolve the issue as quickly as possible," the company said.</p><p>To make matters even worse, Google said that if users don’t file an appeal, that their blogs can be permanently deleted. </p><p>Users are advised not to create new blogs and migrate content, since that is in violation with Google’s TOS. They are also advised against deleting their Blogger profile or service from their Google account, since this will irrevocably delete the blogs. They can, however, back up their blogs if they are afraid of losing the content. </p><p>The full extent of the issue is unknown, but according to <em>BleepingComputer</em>, the number of users on the platform exceeds 200,000.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI says it stopped an Asian scam campaign hijacking ChatGPT to lure in victims ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/openai-says-it-stopped-an-asian-scam-campaign-hijacking-chatgpt-to-lure-in-victims</link>
                                                                            <description>
                            <![CDATA[ Multiple ChatGPT accounts were banned for being used in scam campaigns. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">XBqHrsDrWhWrL7ZrXTpYjX</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qndeeFgCzP2WCRnVb6PGhD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qndeeFgCzP2WCRnVb6PGhD-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / SOPA Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A ChatGPT OpenAI logo seen displayed on a smartphone. ]]></media:description>                                                            <media:text><![CDATA[A ChatGPT OpenAI logo seen displayed on a smartphone. ]]></media:text>
                                <media:title type="plain"><![CDATA[A ChatGPT OpenAI logo seen displayed on a smartphone. ]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qndeeFgCzP2WCRnVb6PGhD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI disrupted a major scam campaign in Cambodia’s Poipet, banning accounts and blocking new registrations</strong></li><li><strong>Criminals used ChatGPT to run romance fraud, fake investments, bogus police scams, and even operations linked to human trafficking</strong></li><li><strong>AI was leveraged for fake personas, fraudulent messages, job lures, and worker administration; OpenAI shared findings with authorities after evidence of hundreds of victims losing thousands of dollars</strong></li></ul><p>OpenAI said it disrupted a major scam campaign coming out of Southeast Asia by banning accounts used by the operation and making it difficult to open new ones. </p><p>In a blog post, the ChatGPT maker said it was tipped off about the existence of the campaign by <a href="https://www.techradar.com/phones/7-great-whatsapp-alternatives-for-android-users-google-messages-discord-and-more" target="_blank">WhatsApp</a>. </p><p>After investigating further, the company found that a group of criminals in Cambodia used its AI tool in different scam campaigns - romance fraud, fake investment scams, or bogus police investigations. It also used AI to help with day-to-day operations and, most worryingly, for things that could be related to human trafficking and forced criminality.</p><h2 id="detention-and-escape-attempts-2">Detention and escape attempts</h2><p>OpenAI did not say if the group had a name, just that it operated out of Poipet, “a city in Banteay Meanchey province that public reporting⁠ has repeatedly⁠ linked⁠ to online scam compounds and trafficking operations.”</p><p>The group used AI to create fake personas, to help draft fraudulent emails and chat messages, and to create posters for fake jobs which were probably used to lure people into human trafficking or forced labor. </p><p>The tool was also used for worker administration, since the operators maintained records of employee debts, salary deductions, disciplinary fines, and loan repayments. They also used the tool to translate discussions about immigration status, work permits, visa overstays, and recruitment incentives.</p><p>“Some conversations also referenced apparent detention, escape attempts, and potential criminal liability for people who had been trafficked and forced to work in scam operations,” OpenAI said. “While these conversations do not allow us to determine the circumstances of any particular individual, they are consistent with extensive public reporting⁠ describing⁠ the activities of organized crime groups in Southeast Asia.”</p><p>The company could not say how many people fell victim, or how much money this group has stolen, but said it found evidence of “hundreds” of victims losing “thousands of dollars.” These findings were shared with relevant authorities.</p><p><em>Via </em><a href="https://thehackernews.com/2026/08/openai-disrupts-poipet-scam-network.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Buggy microcontrollers making up some of the world's most important servers can be easily backdoored ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/buggy-microcontrollers-making-up-some-of-the-worlds-most-important-servers-can-be-easily-backdoored</link>
                                                                            <description>
                            <![CDATA[ Researchers found more than a dozen new flaws plaguing baseboard management controllers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">nPuh2H9an6GtfRUcPmq6NT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 13:26:45 +0000</pubDate>                                                                                                                                <updated>Thu, 06 Aug 2026 13:27:29 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Security padlock and circuit board to protect data]]></media:description>                                                            <media:text><![CDATA[Security padlock and circuit board to protect data]]></media:text>
                                <media:title type="plain"><![CDATA[Security padlock and circuit board to protect data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Dtd9CSn6K6jfEdpnzch4zj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>runZero disclosed 12+ new flaws in BMCs from HPE, Supermicro, Dell, Lenovo, Huawei, and others at Black Hat</strong></li><li><strong>Scans found 86k internet‑exposed BMCs and 120k internal devices</strong></li><li><strong>Researchers warn BMCs form a widespread, under‑patched parallel attack surface</strong></li></ul><p>Security researchers have discovered more than a dozen new vulnerabilities in Baseboard management controllers (BMC), hardware components found in thousands of the world’s most popular <a href="https://www.techradar.com/news/best-small-business-servers" target="_blank">enterprise servers</a>. </p><p>BMCs are specialized chips built into servers that allow administrators to remotely monitor and manage hardware regardless of the operating system, and even when the hardware is turned off. They provide out-of-band management capabilities such as remote console access, firmware updates, hardware health monitoring, and power control, and have been a pivotal component since their introduction in the late 1990s.</p><p>Earlier this week, during the Black Hat security conference in Las Vegas, security expert HD Moore of runZero disclosed finding more than a dozen flaws in BMCs sold by HPE, Supermicro, Avocent, Huawei, Lenovo, Dell, and others - and to make matters worse, some of the flaws disclosed in the past remain active even today. </p><h2 id="parallel-attack-surface">Parallel attack surface</h2><p>“The end result is a pervasive, under-monitored, under-patched parallel attack surface that is both Internet-exposed and widespread inside corporate networks, and is much more exploitable than many folks realize,” Moore told the publication.</p><p>To assess the associated risks, Moore ran two scans - one looking at internet-connected BMCs in general, and another internally surveying devices in corporate networks. The first one found 86,000 exposed BMCs, more than half of which (54%) carried at least one of the flaws he found.</p><p>The internal scan, counting more than 120,000 BMCs, found almost a third (29%) carrying at least one critical vulnerability. </p><p>Details about the flaws will remain under lock and key until the manufacturers address them, Moore explained, saying that many of them cannot be exploited without prior authentication. However, for many (well-equipped) threat actors, that often isn’t a problem, since a number of smaller pre-authentication flaws exist as well, which could be abused.</p><p><em>Via </em><a href="https://arstechnica.com/security/2026/08/thousands-of-servers-can-be-backdoored-by-exploiting-buggy-motherboard-controllers/" target="_blank"><em>Ars Technica</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple's Private Relay tool can leak users' IP addresses — with OnionBrowser also affected ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/apples-private-relay-tool-can-leak-users-ip-addresses-with-onionbrowser-also-affected</link>
                                                                            <description>
                            <![CDATA[ While Apple is looking into it, some browser makers have already made their moves. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ELVkVerYxoc2BpfyGwXt8g</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 06 Aug 2026 10:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg">
                                                            <media:credit><![CDATA[Thapana Onphalai via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:description>                                                            <media:text><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:text>
                                <media:title type="plain"><![CDATA[Hands on a laptop with overlaid logos representing network security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers Talal Haj Bakry and Tommy Mysk found three WebKit flaws leaking real IPs despite iCloud Private Relay</strong></li><li><strong>DNS prefetching, WebAuthn origin requests, and WebTransport bypass proxy settings, exposing users across all Apple browsers</strong></li><li><strong>Tor and Psylo browsers issued fixes; Apple has not confirmed a patch but is reviewing the report</strong></li></ul><p>WebKit, Apple’s engine that powers all web browsers in its ecosystem, contained multiple flaws that helped leak the IP addresses of users who paid to keep them hidden.</p><p>This is according to security researchers Talal Haj Bakry and Tommy Mysk who <a href="https://mysk.blog/2026/08/04/webkit-proxy-icloud-private-relay-ip-leak/" target="_blank">noted</a> they had found “three WebKit features that bypass the proxy configuration and send traffic directly from the device instead,” they wrote.</p><p>“DNS prefetching resolves hostnames through the device’s normal DNS path, which reveals the user’s real DNS servers instead of the proxy’s. Available since iOS 26.0; WebAuthn Related Origin Requests make the operating system’s credential service fetch a validation file directly from the device. This exposes the device’s real IP address. Available since iOS 18.0; WebTransport opens a direct HTTP/3 connection and bypasses the proxy, which also exposes the device’s real IP address. Available since iOS 26.4," the researchers said.</p><h2 id="private-relay">Private Relay</h2><p>While the bugs are in WebKit, the leaks come via Private Relay - a privacy feature available with iCloud+ that hides a user’s IP address and encrypts Safari web traffic. Private Relay does not work like a VPN, and does not mask the traffic flowing through other apps and programs - it just handles browser traffic. </p><p>Since WebKit is mandatory for all browsers running in Apple’s ecosystem, the vulnerability affects all of them. Some, including Tor and Mysk’s very own Psylo browsers, have already issued fixes. </p><p>Apple, on the other hand, has not yet confirmed a fix, or even that it was working on one. It did say, according to<em> </em><a href="https://www.404media.co/apples-private-relay-is-exposing-users-real-ip-addresses/" target="_blank"><em>404 Media</em></a>, that it was looking into the research report. </p><p>The researchers built a dedicated website where users can check if Private Relay is working as intended or still leaking the actual IP address into the wild.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FBI agent accused of stealing $1 million in crypto — and he even consulted ChatGPT on how to leave the country ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/fbi-agent-accused-of-stealing-usd1-million-in-crypto-and-he-even-consulted-chatgpt-on-how-to-leave-the-country</link>
                                                                            <description>
                            <![CDATA[ An FBI agent allegedly stole $1m in crypto by memorizing a seed phrase, then asked ChatGPT how to move to Europe. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QB9Wnq49JxXT4j3oVymeza</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Y5BaBkp9uJ2RQnJbCbDEsA-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 23:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Y5BaBkp9uJ2RQnJbCbDEsA-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Yevhen Vitte]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[.]]></media:description>                                                            <media:text><![CDATA[Crypto mining]]></media:text>
                                <media:title type="plain"><![CDATA[Crypto mining]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Y5BaBkp9uJ2RQnJbCbDEsA-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A former FBI counterintelligence supervisor is accused of memorizing seed phrases from bureau systems</strong></li><li><strong>The agent moved roughly $1 million out of wallets tied to a foreign adversary without having to resort to any sort of hacking</strong></li><li><strong>Investigators recovered ChatGPT conversations in which he asked how to invest the money and how to gain EU residency, and the chatbot's replies recited his age, wife, child, and property plans back to him</strong></li></ul><p>Patrick Steven Yaroch, a supervisory special agent in the FBI's Counterintelligence and Espionage Division, has been arrested and charged with interstate transportation and receipt of stolen goods.</p><p>An affidavit filed in the Eastern District of Virginia, claims Yaroch took roughly a million dollars in cryptocurrency from wallets he encountered while investigating a foreign adversary and then used ChatGPT to determine what to do with it.</p><p>The theft, as described, required no technical sophistication whatsoever: Yaroch held a Top Secret clearance with SCI access and had spent 2017 to 2025 on a national security squad at the FBI's Boston division working against a single adversarial nation, which <a href="https://www.nbcnews.com/politics/justice-department/feds-charge-fbi-agent-say-stole-nearly-one-million-crypto-russia-rcna590674" target="_blank">NBC News reports was Russia</a>. </p><h2 id="an-atypical-heist-with-the-alleged-mastermind-acting-out-of-frustration">An atypical heist with the alleged mastermind acting out of "frustration"</h2><p>Patrick Steven Yaroch encountered the cryptocurrency wallets tied to his work in November 2024. He had researched how wallets work, created one of his own, searched the FBI's holdings for the relevant account information, and memorized the recovery seed phrases.</p><p>He then made roughly 10-12 transfers to his own wallet. No encryption was broken, and no protocol was exploited because none was in place for a man with his security clearance; he simply read a phrase off an internal system and remembered it.</p><p>The incident is particularly interesting because he self-reported, effectively turning himself in to his colleagues: on July 28 2026, he contacted a Justice Department employee he had worked with in Boston over Signal, asking to meet. They met at FBI headquarters the next day, where Yaroch reportedly began breaking down almost immediately, and the conversation moved to the other man's office.</p><p>He said the situation was "eating him up inside" and that he wanted to give all the money back. He filed an online self-report to the FBI's Security Division and told headquarters personnel he had screwed up. When agents arrived at his Ashburn home that evening, he told them, unprompted and in blunter terms, that he had messed up.</p><p>His defense, as per the affidavit, however, is slightly different from what one would expect: His stated motive was not greed. He told his colleagues he had grown frustrated that the FBI could not or would not act against those accounts, described himself as "spinning out of control" at the time, and said he decided to take matters into his own hands.</p><p>Despite this, he seemingly had a change of heart after cooperating earlier, asking for a paper containing his wallet seed phrases, which he had volunteered to agents, while declining to continue the interview without a lawyer while asking for time over the next two days.</p><p>This culminated in agents obtaining warrants, executing them on July 31 with SWAT securing the house, and recovering an iPhone, a Trezor hardware wallet, the handwritten seed phrases, a Portuguese power of attorney dated June 15, and three passports, one of them diplomatic.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1920px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="pwcbaLVSvqWvfTPCXUPoQD" name="shutterstock_1173443506.jpg" alt="Man annoyed at laptop" src="https://cdn.mos.cms.futurecdn.net/pwcbaLVSvqWvfTPCXUPoQD.jpg" mos="" align="middle" fullscreen="" width="1920" height="1080" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Marjan Apostolovic / Shutterstock)</span></figcaption></figure><p>Ironically, the most potentially damning evidence of his intentions comes from his conversations with AI, still on his phone and directly linked to him. </p><p>His conversations with ChatGPT convey a very different thought process: On May 28, he asked how to invest or spend a million dollars to maximize profit and return. On June 4, he asked what someone with about a million dollars should do to leave the United States and become a resident or citizen of an EU country. On June 17 he asked whether an American connecting through Turkey needs a visa. On June 26 he asked for help drafting an email to an executive about a job opening and life in Greece.</p><p>There is more evidence that he might already have acted based on the answers he received: prosecutors have found a power of attorney authorizing two Portuguese lawyers to register him with the country's tax authority and obtain a Portuguese tax identification number, and unreported foreign travel to Germany in May, Portugal later that month, and Grenada in early July, all in breach of bureau reporting rules.</p><p>His current investments seem to be equally erratically reasoned: On July 23, five days before he first confessed, Yaroch moved roughly $1.02 million into Suilend, a lending protocol on the Sui blockchain, reaching it through the Slush wallet app, which he then deleted. He parked the funds there to earn interest. When asked why he chose that service, he said he liked its logo, a water droplet.</p><p>When agents looked, the position was worth $933,756, roughly 8% below its level a week earlier. His Kraken account held another $188,570, including about $5,000 in a token called Squid and $1.67 in Bitcoin. Agents ultimately swept $925,426 into government wallets, leaving about $165,582 behind because it was dollars and could not be moved to a crypto wallet.</p><p>Yaroch is charged under sections 2314 and 2315 of the federal criminal code, the general provisions on transporting and receiving stolen goods. He is not charged with espionage, with computer fraud, or with theft of government property.</p><p>The wallets were not the government's, and that might change how they are treated legally, even as it raises important questions about the security protocols at federal agencies regarding cryptocurrencies, since they both monitor and have <a href="https://www.techradar.com/pro/security/huge-cryptomixer-takedown-sees-feds-seize-over-usd30milion" target="_blank">seized increasingly large amounts</a> of them over the past few years.</p><p>In Yaroch's case, if the allegations hold, government protocols failed to identify the theft for nearly eighteen months before the person responsible reported himself, making the case for a potential review by federal agencies about how they handle such matters.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers use fake Adobe and Zoom updates to load malware onto victim devices — here's what to look out for ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-use-fake-adobe-and-zoom-updates-to-load-malware-onto-victim-devices-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ SMOKE#SCREEN is a dangerous campaign that evolves over time to avoid being spotted by defenders. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">GWMJGwyWDRArbgkuC7aGP5</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 16:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Image depicting a hand on a scanner]]></media:text>
                                <media:title type="plain"><![CDATA[Image depicting a hand on a scanner]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Securonix uncovers SMOKE#SCREEN, a campaign tricking users into installing weaponized ScreenConnect via fake Zoom/Adobe updates and business docs</strong></li><li><strong>Attackers gain persistent remote access, evolving tactics to disable protections and abuse trusted services like Dropbox/Cloudflare for delivery</strong></li><li><strong>Victims observed on Windows and macOS; businesses urged to verify updates via official sites and train staff against unexpected installs</strong></li></ul><p>Security experts Securonix Threat Research have uncovered a new malicious campaign that tricks users into installing legitimate <a href="https://www.techradar.com/news/best-remote-desktop-software" target="_blank">remote monitoring and management</a> (RMM) software.</p><p>Dubbed SMOKE#SCREEN, the campaign uses fake Zoom and Adobe update messages, as well as a whole swathe of fraudulent business-related documents (document review requests, system maintenance tools, invoices, and similar), to convince the victims to run malicious files. </p><p>Victims who don’t see through the ruse and run the files end up installing ConnectWise ScreenConnect, a legitimate RMM tool that many IT teams use to provide technical support to their coworkers and clients. However, it is also one of the more abused solutions in the criminal cyber-underworld, since it can often fly under the radar of security products.</p><h2 id="dangerous-evolution">Dangerous evolution</h2><p>After installation, attackers can remotely access compromised devices, potentially allowing them to steal data, install additional threats, or move deeper into an organization’s network.</p><p>At first glance, SMOKE#SCREEN looks like a fairly standard “phishing - install legitimate RMM - remote access” campaign. However, what makes it unique is how it evolved over time, Securonix explained. Earlier versions focused on hiding the malicious activity, while newer versions attempted to disable security protections and avoid detection by security software. The attackers also used trusted services such as Dropbox and Cloudflare to deliver their files, making the activity harder to block.</p><p>Victims were observed on both Windows and macOS ecosystems, it was added. </p><p>“The SMOKE#SCREEN campaign demonstrates a capable, actively maintained, and rapidly adapting threat actor who has built a diversified toolkit around a single objective: gaining persistent, legitimate-looking remote access to victim systems through weaponized ScreenConnect deployments,” the researchers explained. </p><p>“The use of multiple social engineering themes, rotating payload hashes, cross-platform coverage, and a live staging server that doubles as a ScreenConnect relay indicates a well-resourced actor with deliberate operational security practices.”</p><p>To minimize the risk of compromise, businesses should disable receiving software updates delivered through emails, verify update requests through official websites, and instruct their employees to be cautious when opening attachments or installing tools they were not expecting.</p><p><em>Via </em><a href="https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts flag Bank of America phishing scam that hands your device over to hackers ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-flag-bank-of-america-phishing-scam-that-hands-your-device-over-to-hackers</link>
                                                                            <description>
                            <![CDATA[ Why would Bank of America want to install ScreenConnect on your computer? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Pjh8ffRAGBEQ2LBczLV8NL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay/Tumisu]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/vg86aqqGf8Pqp6mnfQPGGf-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress flags phishing emails spoofing Bank of America, pushing victims into different infection chains on Windows vs. macOS</strong></li><li><strong>Windows users were tricked into installing ScreenConnect RMM via fake “Account Guard,” while macOS users faced credential‑harvesting forms for identity theft</strong></li><li><strong>Emails mimicked Bank of America branding but came from unrelated domains; users advised to verify sender addresses to spot scams</strong></li></ul><p>Bank of America customers have been warned to take extra caution after experts warned of hackers spoofing the bank into trick you into downloading unwanted software and granting them access to your computer.</p><p>Security researchers Huntress <a href="https://www.huntress.com/blog/bank-spam-rmm" target="_blank" rel="nofollow">revealed</a> how it received a phishing email in their honeypot (an address set up primarily to catch scammers) claiming to have come from Bank of America. </p><p>Obviously, the message came from a domain completely unrelated to the company, but looked almost identical to the real thing, with the company logos, color schemes, and other details, meticulously imitated.</p><h2 id="just-another-screenconnect-scam">Just another ScreenConnect scam</h2><p>In the email, the researchers were warned that their account was about to be “restricted” unless they “confirmed” certain information. </p><p>Depending on the platform from which the victim views the email, both the infection chain and the end goal are different. For Windows users, victims are invited to install “Account Guard”, which is described as a “powerful tool designed to protect your financial data, prevent unauthorized transactions, and other cyber threats”.</p><p>This is no guard - this is a Visual Basic script that leads to an installation of the ScreenConnect Remote Monitoring and Management (RMM) tool. ScreenConnect is not malicious itself - it is a legitimate tool - but it is also one of the most abused software out there, leveraged to grant attackers unabated access to victim computers without triggering any alarms.</p><p>For macOS users, on the other hand, the goal is different. Instead of trying to deploy malware, the attackers try to steal sensitive data. First, the victims are asked to log in to their banking account (twice - the first attempt is scripted to fail, in case the victim purposely submits the wrong password the first time). </p><p>Then, once they “log in”, the second web page asks the victims to “confirm” their details - full name, mailing address, government ID details, Social Security number (SSN), and the payment card details. This is more than enough information for an <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> attack, or even wire fraud. </p><p>Huntress is now warning all Bank of America users to double-check the sender address for any email claiming to be from the bank, since that is the best way to know if the email is legitimate, or a scam.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ TP-Link router owners update now — 15 flaws patched to stop hackers hijacking your devices ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/tp-link-router-owners-update-now-15-flaws-patched-to-stop-hackers-hijacking-your-devices</link>
                                                                            <description>
                            <![CDATA[ The Omada platform was found to be vulnerable in different ways, but TP-Link has already issued patches. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FnWzZ2x2tUdqyzA2bNQ3S3</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/xiF2oa9QT4q5sePeRdA8Af-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 14:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/xiF2oa9QT4q5sePeRdA8Af-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[cables going into the back of a broadband router on white background]]></media:description>                                                            <media:text><![CDATA[cables going into the back of a broadband router on white background]]></media:text>
                                <media:title type="plain"><![CDATA[cables going into the back of a broadband router on white background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/xiF2oa9QT4q5sePeRdA8Af-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Forescout’s Vedere Labs found 15 flaws in TP‑Link Omada business networking gear, exploitable for RCE when chained with prior CVEs</strong></li><li><strong>Weak trust shortcuts in zero‑touch provisioning exposed devices to client‑side code execution, hijacking, spoofing, and encrypted comms compromise</strong></li><li><strong>TP‑Link released firmware updates; admins should patch immediately, with 1,800+ Omada controllers exposed online</strong></li></ul><p>TP-Link has patched more than a dozen vulnerabilities across multiple business networking products which could have been chained to achieve remote code execution (RCE). </p><p>Security researchers at Vedere Labs from Forescout <a href="https://www.forescout.com/resources/zero-day-provisioning-chaining-tp-link-ztp-vulnerabilities-report/" target="_blank" rel="nofollow">found</a> the flaws and published an in-depth report on the issues, which particularly affect TP-Link Omada, the company’s business networking platform for centrally managing enterprise and small-business network infrastructure. </p><p>It includes cloud-managed Wi-Fi access points, <a href="https://www.techradar.com/news/networking/routers-storage/best-router-9-top-wireless-routers-on-test-1090523" target="_blank">routers</a>, switches, gateways, and controllers, all of which can be monitored and configured from a single interface.</p><h2 id="enabling-concrete-attacks">Enabling "concrete attacks"</h2><p>These support zero-touch provisioning (ZTP), a mechanism that allows IT managers to deploy and maintain devices without needing to configure each one manually and on site. </p><p>However, ZTP has to establish trust between a factory-fresh device, and a controller with no human involved, so TP-Link used different shortcuts: from hard-coded keys and certificates shared across multiple devices, to default credentials, and from guessable serial numbers as “identity”, to weak session-key randomness. </p><p>Now, Forescout says 15 vulnerabilities its researchers discovered all allow for different ways of exploiting these shortcuts, meaning a flaw anywhere in the onboarding chain can compromise every device that goes through it. These bugs would need to be combined with two previously disclosed command-injection flaws, though.</p><p>“The vulnerabilities fall into four impact categories: client-side code execution, information disclosure, device hijacking and spoofing, and compromise of encrypted communications,” Forescout said. “Combined with two previously disclosed CVEs (CVE-2025-7850 and CVE-2025-7851), these flaws enable concrete attacks that let attackers infiltrate networks through controllers and client devices.”</p><p>Out of the 15 discovered flaws, 11 received CVE identifiers, and the rest did not receive a tracking number. </p><p>Forescout said there are more than 1,800 Omada controllers accessible from the wider internet. If you are using any of the devices from the platform, you should head over to TP-Link’s download portal and grab the latest firmware for your device model.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft 365 users hit by phishing scheme posing as RingCentral emails ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-365-users-hit-by-phishing-scheme-posing-as-ringcentral-emails</link>
                                                                            <description>
                            <![CDATA[ Operators of the Greatness PhaaS scam are targeting Microsoft 365 accounts by spoofing RingCentral. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">jryYksDSx82533KeRr5Y7R</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing]]></media:description>                                                            <media:text><![CDATA[Phishing]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/rsstAB5QjUqoXwXYPEgT7d-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>ZeroBEC observes Greatness PhaaS evolving to bypass MFA and phish Microsoft 365, iCloud, Yahoo, and Google Workspace accounts</strong></li><li><strong>Attackers spoofed RingCentral emails post‑ShinyHunters breach, luring victims to fake Microsoft 365 logins that capture authentication tokens</strong></li><li><strong>Greatness is sold on Telegram for $289/month, enabling access to Outlook, Teams, SharePoint, OneDrive, and more across multiple regions</strong></li></ul><p>Microsoft 365 users have been getting phishing emails spoofing RingCentral, designed to steal their accounts even if they were protected by multi-factor authentication (MFA), experts have warned.</p><p>Security researchers ZeroBEC claim to have observed a phishing-as-a-service (PhaaS) platform called Greatness evolve to also target MFA accounts, as well.</p><p>Greatness used to be a simple credential phishing platform. However, in recent times, it evolved to target not just Microsoft 365 accounts, but also those of iCloud, Yahoo, and Google Workspace.</p><h2 id="grabbing-mfa-approved-authentication-tokens">Grabbing MFA-approved authentication tokens</h2><p>ZeroBEC notes that RingCentral recently suffered a data breach at the hands of the infamous ShinyHunters hackers, meaning there is a good chance (although not confirmed) that the threat actors exfiltrated a list of emails belonging to RingCentral customers from that attack, and used it in this attack.</p><p>Now, RingCentral customers have been getting emails that look as if they are coming from the company itself, despite being mailed from an unknown mail server, and despite failing SPF and DMARC checks. The emails are the standard fake voicemail and performance-review notifications which, if clicked, redirect the victim to attacker-owned infrastructure spoofing the Microsoft 365 login page.</p><p>Through this malicious landing page, Greatness operators are able to capture <a href="https://www.techradar.com/best/best-authenticator-apps" target="_blank">MFA</a>-approved authentication tokens, bypassing the login process entirely and moving straight into victim accounts. </p><p>From there, they would enumerate Outlook mailboxes, Teams conversations, and SharePoint sites. They would also access OneDrive files, contacts, calendars, and registered applications through Microsoft Graph.</p><p>The number of victims is unknown at the time, but ZeroBEC says Greatness has been active for at least four years now, targeting users in the US, UK, Australia, Canada, and South Africa. </p><p>According to <em>BleepingComputer</em>, the platform is being advertised for sale on Telegram channels with “thousands of subscribers”, and is currently being offered for a monthly fee of $289.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral-to-steal-microsoft-365-accounts/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New ChainDrop worm poisons over 1,300 npm packages, Keyv and Cacheable among those hit ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/new-chaindrop-worm-poisons-over-1-300-npm-packages-keyv-and-cacheable-among-those-hit</link>
                                                                            <description>
                            <![CDATA[ Another Shai-Hulud variant hits npm packages, worming its way into hundreds of packages. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RckCeYHbHTFv2D4CzixxRm</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 05 Aug 2026 11:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Aikido researchers uncovers ChainDrop, a Shai‑Hulud variant infecting 1,300+ npm packages with an infostealer</strong></li><li><strong>Attackers compromised GitHub accounts tied to popular libraries (Keyv, Cacheable, flat‑cache, file‑entry‑cache) and pushed tainted releases with 2B monthly downloads</strong></li><li><strong>Malware exfiltrates developer/cloud credentials and secrets to a public GitHub repo; admins should treat affected systems as compromised even after removal</strong></li></ul><p>Another Shai-Hulud variant has been discovered in the wild, infecting more than 1,300 npm packages with an infostealer.</p><p>Security researchers Aikido <a href="https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack" target="_blank" rel="nofollow">reported</a> finding “at least 868 packages (across 1381 versions) that have been compromised by the worm.”</p><p>Shai-Hulud is a self-propagating supply chain <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that targets software developers by compromising open-source packages and CI/CD pipelines. It steals credentials, API keys, and access tokens and then uses those stolen secrets to publish additional malicious packages.</p><h2 id="what-to-do-in-case-of-an-infection">What to do in case of an infection</h2><p>In May 2026, actors claiming to be associated with the TeamPCP group publicly released the <a href="https://www.techradar.com/pro/security/self-replicating-shai-hulud-infects-147-npm-packages-with-over-2-million-downloads-per-week" target="_blank">Shai-Hulud</a> worm's source code, saying they were “open sourcing the carnage” and inviting other threat actors to adopt and modify the code. Since then, there were multiple copycat campaigns and variants, including this one which Aikido dubbed ‘ChainDrop’.</p><p>Aikido said the attackers compromised the GitHub account of the person maintaining Keyv and Cacheable, widely used open source JavaScript libraries for caching data in Node.js applications. From there, they were able to move into other popular utilities such as flat-cache and file-entry-cache, as well as packages associated with organizations such as Deliveroo, Ornikar, OneReach, Picsart, Qlik, and ServiceTitan.</p><p>The malware was pushed directly into the projects’ main branches, and then generated additional package releases. The compromised packages have a combined 2 billion monthly downloads. </p><p>Aikido says the infostealer grabs developer and cloud credentials, encrypts them, and then sends them to a public GitHub repository called “Shai-Hulud: Here We Go Again.”</p><p>It also steals local configuration files, GitHub PATs, workflow tokens, and other ghp_, gho_, and ghs_ tokens, certain npm tokens, GitHub Actions secrets, AWS credentials, Kubernetes secrets, and more. </p><p>The researchers are saying system admins who installed a tainted package should treat their developer workstation or CI/CD runner as compromised, even if they removed the package. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out — Microsoft login pages are being abused as hackers try and lure in unlucky victims, here's what to look out for ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/watch-out-microsoft-login-pages-are-being-abused-as-hackers-try-and-lure-in-unlucky-victims-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ No passwords were stolen, and MFA never came into it; they walked away with access to mail, files, Teams, SharePoint, and calendars across around 120 organizations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Lu4b4UqXtFycpKHsTi3Xkh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 23:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:description>                                                            <media:text><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:text>
                                <media:title type="plain"><![CDATA[A laptop with digitally inserted hack warnings around it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/AboNpeASJNf5nBHAARoLnF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Phishing campaign used fake Teams notifications to route victims to a genuine Microsoft sign-in page</strong></li><li><strong>Rather than stealing passwords, attackers asked victims to approve permissions for an attacker-controlled app, gaining access to mail, files, Teams, SharePoint, OneDrive and calendars without defeating MFA</strong></li><li><strong>Check Point says the technique has been commoditized in 2026 into a rentable service; the practical defense is restricting app consent rather than relying on users to spot a fake</strong></li></ul><p>A phishing campaign that ran from late June into July 2026 did something that breaks most of the advice organizations have spent a decade teaching their staff: it sent victims to a real Microsoft login page.</p><p>Check Point's email research team, which <a href="https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon/" target="_blank">disclosed the campaign</a>, identified more than 200 phishing emails targeting users across roughly 120 organizations worldwide.</p><p>The lure was a fake Microsoft Teams notification with a genuine destination; what actually compromised accounts was not a stolen password but a permissions prompt that the victim clicked through voluntarily.</p><h2 id="a-sophisticated-attack-that-relied-on-tricking-users-into-granting-permissions">A sophisticated attack that relied on tricking users into granting permissions</h2><p>Check Point noted in its brief that what actually compromised the accounts was not a stolen password but a permissions prompt that the victim clicked through voluntarily. This is a reminder of a stark change in attackers' tactics: they have stopped forging Microsoft's front door and started walking through it.</p><p>The email appeared to be a Microsoft Planner task-assignment notification. The sender name read "There's New Activity On Team," the subject line claimed that HR had sent three messages via Teams chat, and the body referenced a payroll and benefits update, along with a counter showing four overdue employee tasks.</p><p>To someone who works in security, the message had its own telltale signs of being a typical phishing attempt: every link in the email, including both call-to-action buttons, routed through the same redirect. And the visible sender address belonged to the recipient's own organization, meaning the email appeared to have been sent to the same person it came from.</p><p>The link opened a real OAuth authorization URL on login.microsoftonline.com, not a look-alike domain. Signing in displayed a permissions prompt asking the user to approve the permissions or accept them on behalf of their organization.</p><p>If they did, Microsoft redirected the browser to the redirect address specified in the original request, which in this particular campaign was an AWS API Gateway endpoint under the attackers' control. The authorization code was delivered there, and the attackers exchanged it for access. No password was stolen at any point, and there was no fake page to spot.</p><p>This is not unlike how the <a href="https://www.techradar.com/pro/meet-kali365-the-amazon-of-cybercrime-where-hackers-use-ai-to-completely-circumvent-multi-factor-authentication" target="_blank">phishing-as-a-service Kali365 platform</a> compromises Microsoft accounts, but instead of stealing session cookies or OAuth tokens, it opts for a more permanent illicit grant of consent.</p><p>This runs counter to the usual security training checklist, which emphasizes adhering to norms rather than going against the grain; users are told to check the URL, look for the padlock, and watch for misspelled domains. None of those measures matter because there is nothing forged to catch. The domain and certificate are Microsoft's, while the sign-in page is the one the user sees every morning, offering a false sense of security to a user not looking for this particular attack vector.</p><p>Multi-factor authentication does not help either; it protects the login sequence but not access to the user's data post-login. The attacker never needs the password or the second factor because they walk away with a token granted by the user's valid session, a technique called 'consent phishing'.</p><p>There are many ways to prevent this, but the simplest two are asking users to check every single permission/consent screen they click (the phishing attempt still requires users to allow it) and limiting access to permissions for user accounts that applications can request via Microsoft Entra at the system administrator level.</p><p>It would be prudent to do the latter at a minimum, even as Check Point notes that the campaign is no longer active because the underlying technique it used is not going anywhere.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Cybercrime is costing the world trillions every year - new report says victims lose an average of nearly $10,000 in every hit ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/cybercrime-is-costing-the-world-trillions-every-year-new-report-says-victims-lose-an-average-of-nearly-usd10-000-in-every-hit</link>
                                                                            <description>
                            <![CDATA[ An increasingly expensive situation at a global scale ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3Sr9bYgxviKgxk7JhGdFPP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 22:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>New study puts average cybercrime victim losses at $9,468, making a global annual toll at just over $1.24 trillion across 130.9 million victims</strong></li><li><strong>Cybercrime is still massively underreported by both victims and authorities, so official numbers might be 'softer' than the underlying problem</strong></li><li><strong>Some of the countries published limited, if any, financial data regarding cybercrime, making losses an estimate at best</strong></li></ul><p>New figures have claimed cybercrime victims lose $9,468 in the average incident, showing the scale of an increasingly global problem.</p><p>The report from Comparitech claims 130.9 million people are hit each year, and that the annual global toll comes to just over $1.24 trillion.</p><p>A December 2023 study from the company put those figures at $8,069 per victim, 88.5 million people and $714 billion in total losses respectively, highlighting a growing trend that sees a mix of illegal activity moving the needle further.</p><h2 id="a-growing-problem-with-regional-caveats">A growing problem with regional caveats</h2><p>The United States remains a favorite for cybercriminals, topping the charts with 6.7 million victims losing $138.9 billion, a per-victim loss amount of ~$20,731, more than twice that of the global average.</p><p>This is in stark contrast with the next four countries on the list (Spain, France, Sweden and Turkey), all of which offered an average of approximately $10,000 per victim.</p><p>Russia, coming in 6th, reports a much larger number of victims than the four countries ahead of it, but offers a much lower per-victim loss estimate of $3,659. Interestingly, the total number of cybercrimes committed in 2025 dropped to 663,000 from 775,000 in 2024, despite an ongoing conflict with Ukraine, which <a href="https://www.techradar.com/pro/ukraines-largest-mobile-network-goes-down-after-massive-cyberattack" target="_blank">often sees cyberattacks at both the industrial</a> and localized levels by both parties.</p><p>However, a weakening economic situation, as well as Russia localizing many of its communication applications and restricting banking, might also mean that Russia's figures also remain inadvertently capped by policy decisions the country has taken.</p><p>With 18.8 million victims, India has the highest number of scam victims worldwide, even though its pro-rata number is considerably lower than the mean at ~$835 per victim, which may be attributable to the country's lower GDP per capita.</p><p>Interestingly, China, with 1.2 million victims, a fraction of its neighbor, managed to lose approximately $11.5 billion, a pro-rata number of approximately $9583, in line with global estimates by Comparitech and possibly fueled by the country's heavy-handed approach to cybercriminals, which saw it apply increasing amounts of pressure on neighboring Myanmar that culminated in it <a href="https://www.bbc.com/news/articles/cx2gdrvy9gjo" target="_blank">convicting and executing scammers</a> arrested across the border.</p><p>Comparitech's $1.24 trillion figure is conservative, and the study acknowledges this, noting that it covers only victim losses. It notes that experts anticipated the global cost reaching $10.5 trillion in 2025 and calls its own $1.24 trillion a drop in the ocean by comparison.</p><p>That $10.5 trillion comes from Cybersecurity Ventures' 2016 report, which estimated $3 trillion for 2015 and projected it forward at an assumed 15 percent compound annual growth rate, describing the result as the greatest transfer of economic wealth in history.</p><p>At a time when AI automation offers better security, often allowing users to screen calls or leverage security applications that adapt on a case-by-case basis, the inverse is also true with hackers and cybercriminals <a href="https://www.techradar.com/pro/why-traditional-security-checks-are-failing-in-the-age-of-ai-driven-fraud" target="_blank">considerably upping their game</a> when it comes to bypassing security altogether; Comparitech's figures provide a sobering reality: if the industry estimates it has hold and are compared to the GDP of entire countries, the firm says it would rank 20th in the world in those terms alone.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ New malware disguised as popular Roblox cheat tool could give hackers full control of your PC — including the webcam ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/new-malware-disguised-as-popular-roblox-cheat-tool-could-give-hackers-full-control-of-your-pc-including-the-webcam</link>
                                                                            <description>
                            <![CDATA[ A new "invisible" Xeno Executor is actually a highly capable RAT and a potent infostealer. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bdewFffvWfEHEGEL8NkXC4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 18:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png">
                                                            <media:credit><![CDATA[Roblox]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:description>                                                            <media:text><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:text>
                                <media:title type="plain"><![CDATA[Screenshot of Roblox&#039;s new Kids and Select accounts]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d7fHZ9ema8LcBAtrUaK7Ji-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bitdefender reported Roblox players lured by a fake “undetected” Xeno Executor mod spreading malware</strong></li><li><strong>Infection chain delivers a Java‑based RAT and infostealer stealing browser data, online accounts, payment info, and crypto wallets</strong></li><li><strong>Malware also enables surveillance and remote control; campaign peaked in March 2026 and remains active against Roblox’s 82M players</strong></li></ul><p>Cybercriminals are targeting Roblox players with an infostealer and a Remote Access Trojan (RAT) malware that grants them full control over compromised computers, experts have warned.</p><p>Roblox is an online gaming platform, virtual universe, and game creation system where users play millions of games and user-generated mods. Among the mods is Xeno Executor, a utility that allows players to run scripts that automate certain actions or run custom code. Some players use Xeno Executor to run cheats, too.</p><p>Since it’s an unofficial script, Roblox does not allow it and blocks it whenever a new version is released. Now, security researchers Bitdefender have <a href="https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor" target="_blank">reported</a> finding an “undetected” version being promoted on various gaming forums, Discord communities, and similar.</p><h2 id="cornflake-and-cocoshell">CornFlake and CocoShell</h2><p>This version is advertised as “invisible” to Roblox’s anti-cheat systems, but in reality, all it does is trigger an infection chain that ends in a Java-based RAT and information stealer. </p><p>The <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> grabs browser data such as passwords and cookies from some of the most popular browsers (Chrome, Edge, Brave, Opera, Vivaldi), as well as online accounts and payment data (Discord, Roblox, Minecraft, Microsoft Store tokens, and more). </p><p>It also steals cryptocurrency wallet data, particularly targeting the Exodus Wallet. </p><p>As for surveillance, it can log keys, track mouse movements, grab screenshots, stream whatever is on the desktop, and access the webcam. The crooks are also granted file upload and download, PowerShell command execution, and more. </p><p>The campaign was kicked off at the start of the year, reaching its peak in March, it was said. It has now stabilized and is still going relatively strong. </p><p>We don’t know exactly how many players fell victim to this campaign, but Roblox is an incredibly popular platform, so it is possible the campaign was rather successful, too.</p><p>According to <a href="https://activeplayer.io/roblox/" target="_blank" rel="nofollow"><u>Activeplayer</u></a>, Roblox currently has more than 82 million active players.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ It's not too late to save up to 50% off Keeper plans — secure your passwords and company security with big discounts on Personal and Business plans ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/its-not-too-late-to-save-up-to-50-percent-off-keeper-plans-secure-your-passwords-and-company-security-with-big-discounts-on-personal-and-business-plans</link>
                                                                            <description>
                            <![CDATA[ Keeper is one of the best solutions to password storage and security, with up to 50% off across Personal, Family, and Business plans ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">eNAxFW4c6mZgNZPF5E4Z7L</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 15:19:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:description>                                                            <media:text><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Multiple studies have found that the average person has over 150 passwords. As a password security expert, I regularly recommend that every single password people use should be both unique and strong - but this adds the problem of being able to remember each one, or store them securely.</p><p>Password managers are designed for this exact reason. They store your passwords in encrypted vaults and autofill your credentials as and when you need them. For this very reason, Keeper is one of our most highly rated password managers.</p><p>Right now, <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper has cut prices on its personal, family, and business starter plans by up to 50%</a>, providing an affordable password management solution that can store and generate your passwords, while also providing convenient features for securely sharing regularly used household or business passwords.</p><div class="product"><a data-dimension112="65b53cc8-9016-11f1-bd62-671b904a8414" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="65b53cc8-9016-11f1-bd62-671b904a8414" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25=""><strong>Get up to 50% off Keeper plans</strong></a></p><p>Keeper is offering 50% off its Personal and Family plans, making it even more affordable to secure both personal and household accounts. The Family plan covers multiple users with five secured vaults, making it perfect for shared accounts without the hassle of mixing browsers and reusing passwords.</p><p>Keeper Business Starter is discounted by 30%, and is an excellent choice for small teams looking for a credentials control platform without the complexity and hassle of enduring an enterprise rollout. It includes centralized management, secure password sharing, and role-based access, cleanly organizing your passwords without unnecessary complications.</p><p>The full terms and pricing are available on the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">Keeper site</a>.<a class="view-deal button" href="https://www.keepersecurity.com/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="65b53cc8-9016-11f1-bd62-671b904a8414" data-action="Deal Block" data-label="Get up to 50% off Keeper plans" data-dimension48="Get up to 50% off Keeper plans" data-dimension25="">View Deal</a></p></div><h2 id="why-we-recommend-keeper">Why we recommend Keeper</h2><p>In our <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">Keeper review</a>, we praised the zero knowledge architecture and device level encryption that helps keep the contents of your personal vault hidden from hackers.</p><p>Keeper also scored great marks in our usability and convenience testing. Rather than having to enter your master password each time you need to fill in your credentials, Keeper uses biometric security to access your vault. Biometric security uses a facial scan or fingerprint to verify that its actually you accessing your vault. It's also phishing resistant.</p><p>Four households, the Family Plan includes five private vaults, allowing you to quickly share Wi-Fi or streaming passwords using Keeper's shared vaults.</p><p>The Business Starter plan covers 5 users, covering an unlimited devices, shared team folders, user activity reporting for IT admins, and a free Family Plan for every team member.</p><p>These discounts apply to the first year only, so the value is highest for new customers or anyone switching from a monthly plan. After that, pricing goes back to standard rates.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts reveal Google Password Manager can be hijacked to let hackers steal passkeys and gain access to all your secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-reveal-google-password-manager-can-be-hijacked-to-let-hackers-steal-passkeys-and-gain-access-to-all-your-secrets</link>
                                                                            <description>
                            <![CDATA[ Three Pass-ta-key techniques allowed security researchers to work around biometrics-protected locks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">bUumiq3YYstdbhKhfwc7fL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 15:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / Blue Andy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:description>                                                            <media:text><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:text>
                                <media:title type="plain"><![CDATA[Circuit board and shield icon, Hardware security, computer data protection and electronic technology concept,]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/qGbky6N99QiLtik8fjzcUL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Palo Alto Networks’ Unit 42 detailed three Google passkey exploits</strong></li><li><strong>Attacks require prior malware infection; methods ranged from impersonating victims to stealing the master secret protecting synced passkeys</strong></li><li><strong>Google implemented fixes after disclosure, with some services (e.g., eBay) patching vulnerabilities directly</strong></li></ul><p>Security researchers from Palo Alto Networks’ Unit 42 have found three ways to exploit Google’s passkey system and log into people’s PIN- or biometrics-protected accounts. </p><p>They named these ways ‘Pass-ta-key’, ‘Silver Pass-ta-key’, and ‘Golden Pass-ta-key’, each being progressively more dangerous than the previous one. </p><p>While it sounds mighty dangerous, there are major caveats to the exploit, and some of the holes have been plugged already.</p><h2 id="trusting-the-wrong-device">Trusting the wrong device</h2><p>The biggest caveat is that the victim’s device needs to be infected with malware beforehand. Malware can do all sorts of things, from stealing session cookies to exfiltrating sensitive data, so if a device is tainted with malware, it’s already in trouble.</p><p>Still, Unit 42’s findings were important enough to warrant a fix from Google.</p><p>In the first technique, the attackers pretend to be the victim. By using malware, they can “ask” Google to log into a passkey-protected account as if it was the victim themselves. Usually, the service being logged into would require a PIN or a fingerprint to confirm the authenticity of the request, but in this scenario, that wasn’t the case.</p><p>The method doesn’t work everywhere, though. Unit 42 could not replicate the attack on GitHub, but they succeeded on eBay. The latter later fixed the problem. </p><p>In the second attack, Unit 42 managed to make Google “trust” the threat actor’s device, meaning the victim’s computer was no longer necessary. </p><p>In the third attack, the researchers managed to steal the “master key”. </p><p><a href="https://www.techradar.com/best/password-manager" target="_blank">Google Password Manager</a> syncs the passkeys between devices, and to do that, it uses a master secret that protects all of the synced passkeys. The researchers found that, under certain circumstances, malware can grab this master secret while Chrome is temporarily using it, unlocking all of the synced passkeys, copying them to another computer, and being able to use them at a later date. </p><p>The researchers disclosed their findings with Google before publication, and some fixes were already implemented. Google is yet to comment on the findings and confirm that all of the flaws were addressed. </p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-hijack-google-synced-passkeys/" target="_blank">BleepingComputer</a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Travelers beware — Microsoft experts warn hotel Wi-Fi can be hijacked to infect your devices with dangerous malware ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/travelers-beware-microsoft-experts-warn-hotel-wi-fi-can-be-hijacked-to-infect-your-devices-with-dangerous-malware</link>
                                                                            <description>
                            <![CDATA[ Russian criminals are targeting hotel Wi-Fi networks with captive portals and using them to deploy infostealers. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">igLrMhu7uK7ZhgokGuGfmB</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 13:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg">
                                                            <media:credit><![CDATA[The Register]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wi-Fi]]></media:description>                                                            <media:text><![CDATA[Wi-Fi]]></media:text>
                                <media:title type="plain"><![CDATA[Wi-Fi]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/euoWA3SymQA2cKKjmF37W4-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft reports Russian APT29 (Midnight Blizzard) hijacking captive portals in hotels and conference centers</strong></li><li><strong>Victims redirected to fake Microsoft 365 logins or bogus update pages, spreading CornFlake and CocoShell malware</strong></li><li><strong>CornFlake steals files, credentials, and device data; CocoShell targets browser cookies, passwords, and Microsoft tokens</strong></li></ul><p>Threat actors are taking over Wi-Fi networks in hotels and conference centers and using the log-in portals to steal credentials and deploy information-stealing <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, experts have claimed.</p><p>Researchers from Microsoft have published a new <a href="https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/" target="_blank" rel="nofollow">report</a> outlining how they spotted Russian state-sponsored actors, known as Midnight Blizzard or APT29, attacking captive portal equipment - networking hardware and software that manages the login page users see before accessing public Wi-Fi. </p><p>When connecting to a hotel network, users are often redirected to a page where they must enter their room number, accept the terms of service, and click “Connect” - that redirection is handled by the captive portal.</p><h2 id="cornflake-and-cocoshell-2">CornFlake and CocoShell</h2><p>Microsoft did not explain exactly how this gear is attacked. However, when users try to log in on compromised networks, they may be redirected to a fake Microsoft 365 login portal that steals their credentials. </p><p>They may also be redirected to device code phishing pages abusing Microsoft Entra ID authentication flows. Finally, the researchers also saw the captive portals being used to display fake browser and OS update pages that trick victims into downloading infostealers.</p><p>So far, MIcrosoft found two malware variants being distributed: CornFlake, and CocoShell. </p><p>CornFlake acts as an infostealer capable of grabbing keystrokes and clipboard, running remote shell access, grabbing screenshots, using the microphone and the webcam, stealing browser credentials and cookies, exfiltrating files, and more. It presents itself as a  “Cloud Sync Service” while using multiple persistence mechanisms.</p><p>CocoShell, on the other hand, is an in-memory PowerShell credential stealer targeting browser cookies, saved passwords, Microsoft 365 and Azure AD tokens, and Wi-Fi credentials.</p><p>APT29 is one of the most documented state-sponsored threat actors out there. It’s been active for years and is well-known for its links to Russia’s Foreign Intelligence Service and notable attacks on high-ranking western targets, such as US and German Government officials, as well as SolarWinds and Microsoft.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A potentially dangerous macOS security flaw went unreported due to Apple being deluged by AI slop bug reports ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-potentially-dangerous-macos-security-flaw-went-unreported-due-to-apple-being-deluged-by-ai-slop-bug-reports</link>
                                                                            <description>
                            <![CDATA[ Security researchers found a high-severity RCE flaw, which Apple later fixed. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qVTyisUJmWMCtJnCgrWV9N</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/gth8FZBY7MR8cmk3vbbJ6N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 11:25:00 +0000</pubDate>                                                                                                                                <updated>Tue, 04 Aug 2026 13:17:53 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/gth8FZBY7MR8cmk3vbbJ6N-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Apple M5 Pro and M5 Max chips against a black background.]]></media:description>                                                            <media:text><![CDATA[The Apple M5 Pro and M5 Max chips against a black background.]]></media:text>
                                <media:title type="plain"><![CDATA[The Apple M5 Pro and M5 Max chips against a black background.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/gth8FZBY7MR8cmk3vbbJ6N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Bynario disclosed CVE‑2026‑43760, a macOS RCE flaw allowing root file creation via legacy VNC password option</strong></li><li><strong>Apple patched it July 27, 2026 in macOS Tahoe 26.6 and Sonoma 14.8.8; unpatched users should disable Screen Sharing/Remote Management or the legacy VNC setting</strong></li><li><strong>Reporting was delayed as Apple limited submissions due to AI‑generated bug report overload, but the company reached out directly to fix this issue</strong></li></ul><p>Apple has fixed a high-severity vulnerability that allowed threat actors to execute malicious code remotely (RCE), as root, on certain macOS devices - and would have probably fixed the issue even sooner; had it not been flooded with AI slop vulnerability reports.</p><p>Security researchers Bynario <a href="https://bynar.io/blog/a-root-remote-command-execution-on-macos-with-m5-in-2026" target="_blank" rel="nofollow">published</a> an in-depth report discussing finding an RCE flaw on <a href="https://www.techradar.com/best/best-business-mac" target="_blank">macOS</a> 26.5.2 devices running on Apple Silicon M4 and M5 systems, with System Integrity Protection (SIP) enabled.</p><p>According to Bynario, the vulnerability affects Mac devices with Screen Sharing or Remote Management enabled, and with the legacy "VNC viewers may control screen with password" option turned on. For those devices, should a threat actor obtain the VNC password and authenticate to the Mac (no macOS account compromise is required, only the VNC password), they would be able to perform file-transfer operations, with root permissions, due to a logic flaw.</p><div class="product"><a data-dimension112="e6758530-9006-11f1-a6dc-6dab77a1e456" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6758530-9006-11f1-a6dc-6dab77a1e456" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" data-dimension25=""><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="e6758530-9006-11f1-a6dc-6dab77a1e456" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" data-dimension25="">View Deal</a></p></div><h2 id="drowning-in-the-ai-flood">Drowning in the AI flood</h2><p>The attacker would then be able to create new files owned by root anywhere the system allows.</p><p>In the report, the researchers demonstrated creating a valid file inside /private/etc/sudoers.d, granting passwordless sudo privileges, and once that policy was in place, they were able to run commands as root. </p><p>In a separate report, the researchers said Apple was forced to limit the number of active bug reports individual researchers can keep open at one time, due to its security teams being flooded with AI slop reports. </p><p>Since they already hit that threshold by submitting more than 50 bugs in three weeks, the researchers were unable to report this RCE flaw sooner. However, they explained that Apple reached out to Bynario directly to review, and later patch, the flaw. </p><p>The bug is now tracked as CVE-2026-43760 and was given a severity score of 8.6/10 (high). </p><p>Apple released the updates on July 27, 2026, addressing the bug on macOS Tahoe 26.6 and macOS Sonoma 14.8.8.</p><p>Those who cannot patch should disable the legacy "VNC viewers may control screen with password" option or disable Screen Sharing and Remote Management entirely.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Over 100,000 UK Police and staff have personal data leaked in attack on national database ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/over-100-000-uk-police-and-staff-have-personal-data-leaked-in-attack-on-national-database</link>
                                                                            <description>
                            <![CDATA[ ExfilSquad claims responsibility for the attack, says it asked for a ransom payment. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X8CEPHf2d4aj3MhNziCACN</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9G5SRKqDzLCY3sG2gQRrjk-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 04 Aug 2026 08:44:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9G5SRKqDzLCY3sG2gQRrjk-1280-80.jpg">
                                                            <media:credit><![CDATA[Image Credit: dagmarbendel / Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: dagmarbendel / Pixabay]]></media:description>                                                            <media:text><![CDATA[Police]]></media:text>
                                <media:title type="plain"><![CDATA[Police]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9G5SRKqDzLCY3sG2gQRrjk-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>UK’s Police National Legal Database (PNLD) breach leaks data of 100k+ criminal justice professionals</strong></li><li><strong>Threat group ExfilSquad claimed responsibility, posting 1.9 GB of stolen records on the dark web and demanding ransom</strong></li><li><strong>PNLD notified NCA and ICO, hired specialists, and confirmed passwords weren’t compromised but contact details exposed</strong></li></ul><p>The UK’s Police National Legal Database (PNLD) suffered a cyberattack recently, in which it allegedly lost <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">sensitive data</a> on more than 100,000 criminal justice professionals.</p><p>In a short press release, PNLD confirmed the breach, saying it happened over a weekend. The threat actors, which were not named in the announcement, were said to have taken names, organizations, and work email addresses belonging to police officers, staff, government partners, and customers. </p><p>The announcement also said the stolen information was already published on the dark web, adding that there is “no evidence to suggest that passwords or other security credentials have been compromised.” How the attackers worked their way in was not disclosed in the announcement. </p><h2 id="exfilsquad-takes-the-blame">ExfilSquad takes the blame</h2><p>Following the breach, PNLD hired cyber-security specialists, and notified the National Crime Agency, which started their investigation into the incident. </p><p>“All affected organizations were contacted in the days following the incident and provided with further information and guidance,” the announcement reads. “The Information Commissioner’s Office (ICO) has also been notified.”</p><p>At the same time, threat actors calling themselves ExfilSquad claimed responsibility for the attack,<em> </em><a href="https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info-of-over-100-000-uk-police-officers-staff/" target="_blank"><em>BleepingComputer</em></a> reported. The group alleges it stole 135,000 contact records, sharing samples to support their claims. They also said they demanded a ransom in exchange for keeping the data safe. </p><p>In the dark web post, ExfilSquad said it obtained 1.9 GB of data, which includes information belonging to 114,000 PNLD subscribers and 21,000 Ask the Police users.</p><p>‘Ask the Police’ is a public-facing website where users can find answers to hundreds of commonly asked policing or legal questions. </p><p>ExfilSquad is a relatively new threat actor that's not known for any major attacks so far. Prior to the PNLD incident, it claimed the attack against Analog Devices, a US semiconductor company.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Anthropic reveals Claude AI model hacked three companies during tests — so how worried should we be? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/anthropic-reveals-claude-ai-model-hacked-three-companies-during-tests-so-how-worried-should-we-be</link>
                                                                            <description>
                            <![CDATA[ Anthropic's testing mishap proves autonomous AI can breach enterprise networks at machine speed. The era of human-speed security is over - it takes an AI to stop an AI. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">6jz3NscLMRbwyjJYCU7t75</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Aug 2026 19:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Every IT team worries about an intern clicking the wrong thing and making a mess they'll be cleaning up for weeks - but few have had to worry about their AI assistant wandering onto the public internet and hacking three companies instead. </p><p>Except this wasn't an intern; it was Claude, and it wasn't supposed to leave the sandbox.</p><p><a href="https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals" target="_blank" rel="nofollow">Anthropic's public disclosure</a> turned a familiar AI fear into a real-world cybersecurity story, as three of its models, including Claude Opus 4.7, Claude Mythos 5, and an unreleased research build, broke out of their digital sandbox and compromised real enterprise infrastructure. The timing was hard to ignore as days earlier <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow">OpenAI</a> admitted its own autonomous agents had broken boundaries and accidentally hacked Hugging Face.</p><h3 class="article-body__section" id="section-how-can-autonomous-problem-solving-make-ai-an-accidental-hacker"><span>How can autonomous problem-solving make AI an accidental hacker?</span></h3><p>Before you start pulling network cables and digging out a stack of legacy hardware, take a deep breath. This is not the beginning of a rogue AI apocalypse. However, for CISOs and cyber teams, it’s a definitive sign that we’re entering an era where AI agents may become both the threat and the shield.</p><p>The ironic part of Anthropic's incident is that Claude wasn’t trying to break the rules but trying to win the game. At the time, Anthropic was running "Capture the Flag" (CTF) cybersecurity exercises, where AI models are stripped of their standard safeguards to test their raw offensive capabilities. The models are dropped into isolated digital environments to search for vulnerabilities, crack codes, and locate hidden files. </p><p>However, the sandbox had one problem - it was not fully sealed. A networking error on a third-party evaluation range left the environment connected to the live internet. The autonomous Claude models, operating under the assumption they were still inside the exercise, treated the wider web as another part of the challenge.</p><p>The strange part was that Claude seemed to realize something was wrong. It acknowledged that its actions could amount to a real-world attack and were "surely not the intended solution." Yet, due to its goal-oriented nature, the model continued, convincing itself that warning signs, including a 2026 system clock and real company names, were simply part of an elaborately staged test.</p><h3 class="article-body__section" id="section-the-pypi-incident-and-the-fbi-warning"><span>The PyPI incident and the FBI warning</span></h3><p>Claude's sheer persistence became clear when it decided the smartest way to win the CTF challenge was to publish software to the real Python Package Index (PyPI).</p><p>When PyPI's repository security systems asked for a phone verification code to complete the upload, a standard chatbot would have stopped and thrown an error to the user. Claude did not. Instead, it looked for a temporary SMS provider, attempted to obtain a burner phone number, and looked for a way around the two-factor authentication barrier. When that approach failed, the AI didn't give up - it adapted, found another path forward, and successfully uploaded the malicious package.</p><p>Claude's sandbox escape stopped being a controlled experiment the moment it got into the outside world. </p><p>Before Anthropic spotted the anomaly and stopped the test, the package had been downloaded by 15 external systems, including a security scanner from a major cybersecurity company. Because the AI's behavior looked authentic, targeted, and systematic, two of the affected companies thought they were dealing with a highly sophisticated human attacker. </p><p>While Anthropic handled the incident behind the scenes by notifying the affected companies, the episode highlights how difficult it can be to distinguish AI-driven activity from a real attack. </p><p>Weeks earlier, during <a href="https://www.reuters.com/business/its-ai-agent-spent-days-hacking-company-sources-say-openai-did-not-notice-week-2026-07-24/" target="_blank" rel="nofollow">OpenAI's sandbox escape incident</a>, a target company believed it was facing a human threat group and contacted the FBI only to find out they were investigating something far less familiar: an autonomous AI system that had crossed its own boundaries.</p><h3 class="article-body__section" id="section-why-are-traditional-firewalls-blind-to-autonomous-ai"><span>Why are traditional firewalls blind to autonomous AI?</span></h3><p>The scary part is that Claude did not come up with a futuristic, unpatchable exploit or rewrite network protocols on the fly. Instead, it used basic techniques that security teams know very well: brute-forcing weak passwords, exploiting SQL injection flaws, and scraping unauthenticated debug endpoints.</p><p>The more serious problem for IT teams was not the attack itself, but the silence afterward. Two of the three companies had no idea they had been compromised until Anthropic reviewed the test results and made a couple of uncomfortable phone calls.</p><p>The incident revealed a blind spot at the heart of modern cybersecurity. Traditional intrusion detection systems (IDS) and security information and event management (SIEM) platforms are built to spot known threat signatures and massive automated attack storms. However, they are completely blind to an autonomous agent that moves the low-and-slow cadence of a human but operates with the speed and persistence of a machine.</p><p>Legally, the rules have not caught up with the machines. A human pentester who broke out of a sandbox and published malicious code to PyPI could face CFAA charges. Claude, meanwhile, created an awkward new cybersecurity category: a real security incident without a “real” culprit.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:4096px;"><p class="vanilla-image-block" style="padding-top:52.73%;"><img id="kCbP2VkzMgQpYqJDgMQ8UZ" name="shutterstock_1675260034.jpg" alt="Cybersecurity" src="https://cdn.mos.cms.futurecdn.net/kCbP2VkzMgQpYqJDgMQ8UZ.jpg" mos="" align="middle" fullscreen="" width="4096" height="2160" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Shutterstock)</span></figcaption></figure><h3 id="machine-speed-logic-vs-human-speed-defenses">Machine-speed logic vs human-speed defenses</h3><p>The tech industry's anxiety around sandbox escapes is not only about what AI can do but also how swiftly it can do it. In the past, a complex network intrusion required a human hacker to slowly probe defenses and move through systems over days or weeks. That gave security teams enough time to spot suspicious activity and catch them in the act. </p><p>Agentic AI completely collapses that defensive runway. Since autonomous software operates at machine speed, it can chain together tasks like credential discovery, exploit attempts, and lateral movement far faster than a human attacker ever could. <a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face" target="_blank" rel="nofollow">OpenAI's sandbox escape</a> showed how quickly AI agents can escalate once they move beyond their intended boundaries.</p><p>Human analysts reviewing logs at the end of a shift cannot compete with an algorithm testing thousands of attack paths per second. It is a speed gap that experts describe as "<a href="https://www.techradar.com/ai-platforms-assistants/openai/science-fiction-that-happened-experts-explain-why-openais-mind-blowing-cyberattack-should-worry-us-all" target="_blank" rel="nofollow">science fiction that happened</a>," where traditional human-speed defenses struggle to keep pace.</p><h3 id="defending-your-network-against-autonomous-ai">Defending your network against autonomous AI</h3><p>Waiting for the AI sector to police itself is not a winning security strategy. To prepare your infrastructure for the rise of autonomous AI, focus on these three defensive priorities:</p><p><strong>Enforce zero trust</strong>: Remove all unauthenticated internal endpoints and exposed debug pages before an AI agent finds them first.</p><p><strong>Automate threat response</strong>: Utilize AI-driven behavior monitoring and instant device-isolation protocols to contain threats at machine speed.</p><p><strong>Audit third-party sandboxes</strong>: Review how external partners deploy AI agents, particularly models with access to tools, data, or external systems.</p><p>The accidental hacker is no longer a distant sci-fi scenario. It is a live preview of a faster, automated cybersecurity landscape, where the speed of attack may soon outpace the speed of defenses.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'We’ve been behind the ball for so long': Experts say DNA samples from crime-scene forensics can be modified and even switched using an AI tool ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/weve-been-behind-the-ball-for-so-long-experts-say-dna-samples-from-crime-scene-forensics-can-be-modified-and-even-switched-using-an-ai-tool</link>
                                                                            <description>
                            <![CDATA[ Researchers used AI-assisted code to undetectably tamper with data from computerized scans of physical DNA evidence produced by widely used crime-lab machines. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QbpyNnGanZuZwAT2oRz9w8</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/HWb2cSJ4Mb5mxx8ebgiAzH-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 03 Aug 2026 13:08:47 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/HWb2cSJ4Mb5mxx8ebgiAzH-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A forensic police officer examines a smartphone as evidence in a murder case at a forensic laboratory]]></media:description>                                                            <media:text><![CDATA[A forensic police officer examines a smartphone as evidence in a murder case at a forensic laboratory]]></media:text>
                                <media:title type="plain"><![CDATA[A forensic police officer examines a smartphone as evidence in a murder case at a forensic laboratory]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/HWb2cSJ4Mb5mxx8ebgiAzH-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers discover critical vulnerability in forensic software that allows the undetectable modification of DNA samples on crime-scene evidence</strong></li><li><strong>The vulnerability allows much of the crime-scene evidence from the past 30 years to be modified</strong></li><li><strong>A patch is in the works, and the company responsible for the software says that digital signatures have been implemented to monitor for modification attempts</strong></li></ul><p>A group of forensic and computer scientists have raised concerns about the security of software used by top US crime labs to analyze DNA evidence.</p><p>By using an AI model, the researchers were able to undetectably modify computerized scans of physical DNA evidence, exclusive <a href="https://www.wsj.com/tech/cybersecurity/security-flaw-placed-30-years-of-dna-evidence-at-risk-of-hacking-1932775a?st=zGgyGg&reflink=desktopwebshare_permalink" target="_blank" rel="nofollow"><em>Wall Street Journal</em></a> reported. As the vulnerability relates to digital files made by crime labs since 1995, the vulnerability places 30 years of crime files at risk of being tampered with.</p><p>“Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident markings that we require for a paper bag,” said Laura Gaydosh Combs, a University of New Haven professor and forensic scientist who contributed to the research.</p><h2 id="no-known-instances-of-undetectable-exploitation">No known instances of ‘undetectable’ exploitation</h2><p>The researchers disclosed the vulnerability in May. Thermo Fisher Scientific, the company that builds the crime-lab equipment used across most US facilities, privately acknowledging the vulnerability in July 2026. The company said that a fix is currently in progress.</p><p>In a separate note to customers, Thermo Fisher Scientific said there were no known instances of the vulnerability being exploited.</p><p>But the researchers themselves have said that they could not find a way to detect if tampering had taken place. The vulnerability was tested by Nathan Adams, a systems engineer at Forensic Bioinformatics. In just 45 minutes, Adams managed to successfully exploit the vulnerability using Anthropic’s Claude, and modify a file.</p><p>Despite some of the files being sealed using a more advanced encryption algorithm, Adams was able to find and use a decryption key available on the internet to crack into these files.</p><p>The researchers highlighted that by using AI tools to gain the necessary skills and tools, a hacker could abuse the vulnerability to add or remove DNA profiles from crime-scene evidence. Therefore allowing a suspect’s DNA to be removed, or an innocent person’s DNA added.</p><p>“Lessons learned from other industries haven’t been imported into forensic science in a serious way,” said Sarah Chu, the director of policy and reform at the Perlmutter Center for Legal Justice who worked on the research. “We’ve been behind the ball for so long. That kind of all rolls downhill into this incident.”</p><p>The lack of any centralized regulator on forensics has left over 200 labs with a patchwork of security measures, Chu added.</p><p>In a statement to the <em>WSJ</em>, Thermo Fisher Scientific said, “We have been working closely with the U.S. Cybersecurity and Infrastructure Agency since the software issue was raised. We appreciate the work of forensic researchers on this topic, and we have released a software update that implements the use of digital signatures to add an extra layer of protection that moving forward will help customers verify that data files have not been modified.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers are going after our water now — over 30 Minnesota utilities hit in coordinated cyberattack by apparent Iranian attackers ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-are-going-after-our-water-now-over-30-minnesota-utilities-hit-in-coordinated-cyberattack-by-apparent-iranian-attackers</link>
                                                                            <description>
                            <![CDATA[ More than 30 Minnesota water utilities were hit in a coordinated attack on their control systems, with one town's treatment plant knocked offline. A leaked memo points to Iran, though no agency has formally accused it. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Y4nLw6UX5eJPbRvrhGAq6m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 02 Aug 2026 13:05:00 +0000</pubDate>                                                                                                                                <updated>Mon, 03 Aug 2026 11:42:51 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png">
                                                            <media:credit><![CDATA[Veolia]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:description>                                                            <media:text><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:text>
                                <media:title type="plain"><![CDATA[Micron purchases treated water from Veolia, a private municipal water utility]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cg8cNe5GV3DZyAnoK8dtmS-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cyberattack hits operational technology at more than 30 Minnesota community water systems, briefly taking treatment plant offline and forcing several towns onto manual operations</strong></li><li><strong>A leaked WaterISAC memo obtained by WIRED relays a state fusion center assessment tying the intrusions to Iranian-affiliated hackers, but no US agency has formally attributed the attack yet</strong></li><li><strong>The CISA had warned four days earlier that Iranian-affiliated actors were compromising internet-facing PLCs, repeating guidance that has mostly fallen on deaf ears</strong></li></ul><p>More than 30 community water systems across Minnesota were hit by a coordinated cyberattack, targeting the operational technology running pumps, wells, water towers, and wastewater lift stations rather than the office networks behind them.</p><p>Minnesota IT Services disclosed the attack on July 28 2026 and activated a statewide incident response, stating that it wasn't aware of any Minnesota city asking residents to change their drinking water use just yet.</p><p>A memo obtained by <a href="https://www.wired.com/story/a-leaked-memo-ties-cyberattacks-on-minnesota-water-utilities-to-iran/" target="_blank"><em>Wired</em></a>, circulated by the water sector information-sharing group WaterISAC and carrying a restricted TLP: AMBER handling marking, relays a Minnesota state fusion center assessment that ties the intrusions to Iranian-affiliated hackers.</p><div class="product"><a data-dimension112="7505f9c4-8f30-11f1-af1e-0f2390c0f1c3" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:200px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="UkssaJUuTjbMsQ9NN4ejH7" name="NordStellar" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/UkssaJUuTjbMsQ9NN4ejH7.jpg" mos="" align="middle" fullscreen="" width="200" height="200" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p><a href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="7505f9c4-8f30-11f1-af1e-0f2390c0f1c3" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" data-dimension25=""><strong>Use code TECHRADAR10 for 10% off</strong></a></p><p>NordStellar provides businesses of all sizes with a comprehensive threat exposure management platform to bolster your cybersecurity. NordStellar actively monitors for data breaches and exposed credentials to prevent hackers gaining easy access, while simultaneously implementing a range of cybersecurity tools to keep employees and company data safe.</p><p>Use coupon code <strong>TECHRADAR10</strong> for an additional 10% off.<a class="view-deal button" href="https://go.nordstellar.net/aff_c?offer_id=1029&aff_id=3013" target="_blank" rel="nofollow sponsored" data-dimension112="7505f9c4-8f30-11f1-af1e-0f2390c0f1c3" data-action="Deal Block" data-label="Use code TECHRADAR10 for 10% off" data-dimension48="Use code TECHRADAR10 for 10% off" data-dimension25="">View Deal</a></p></div><h2 id="a-warning-that-was-more-or-less-ignored">A warning that was more or less ignored</h2><p>Four days before the attacks, CISA updated an advisory, AA26-097A, warning that Iranian-affiliated actors were compromising internet-facing programmable logic controllers made by Rockwell Automation, Schneider Electric, Siemens, and possibly others across the US water, energy, and government sectors. It documented confirmed disruptions and financial losses.</p><p>This drew no immediate response from state functionaries, and it is easy to see why: the US has tens of thousands of community water systems that serve small populations and lack budgets for dedicated cybersecurity staff.</p><p>This is despite there being a precedent: Iranian-linked actors hit the Municipal Water Authority of Aliquippa in Pennsylvania in November 2023, defacing a Unitronics controller with an anti-Israel message. CISA said at the time those devices were exposed to the internet with default passwords still in place. The advice issued then is the same advice being issued this week, which is telling about how little has changed since.</p><p>The WaterISAC memo, dated the day the attacks concluded, passes on a state fusion center report linking the activity to Iranian-affiliated actors. That memo was not meant to be public, but it has been corroborated by <a href="https://www.nytimes.com/2026/07/30/us/politics/minnesota-water-cyberattack-iran.html" target="_blank">The New York Times</a> and <a href="https://www.washingtonpost.com/national-security/2026/07/30/us-spy-agencies-suspect-iran-launched-cyberattack-minnesota-water-facilities/" target="_blank">The Washington Post,</a> which reported that they spoke to federal officials and US intelligence agencies, respectively, lending credence to the claims.</p><p>CISA later warned that attackers are changing PLC passwords to lock operators out of their own equipment, and repeated the advice that has been unchanged for years: get PLCs off the public internet and put remote access behind a VPN or gateway.</p><h2 id="who-was-affected">Who was affected?</h2><p>The worst of the cyberattack hit Braham, a town of roughly 1,700 people, where the city said attackers shut down the operating controls, taking the water treatment plant and the well offline. Crews restored it manually within a couple of hours, and residents were told to minimize water use in the meantime.</p><p>Plymouth, a Minneapolis suburb of about 80,000, found the problem confined to equipment connected over cellular links at two water towers and several wastewater lift stations. Its IT division disconnected the affected kit from the network entirely to stop the attack and prevent retargeting during reconfiguration.</p><p>Maple Plain declared a local state of emergency to manage its response, and South St. Paul reported that some automated controls were compromised. In most cases, contingency procedures held and water and wastewater operations continued.</p><p>None of this is happening in a vacuum, however. The June memorandum that paused fighting between the US and Iran has broken down, and both are trading strikes, including recent US attacks near the Strait of Hormuz that destroyed a water facility and cut supply to more than 20,000 people. Whoever carried out the Minnesota attacks, the symbolism of targeting municipal water is unlikely to be accidental.</p><p>The damage that these intrusions caused was limited; they produced brief outages that trained staff fixed by hand. That is an outcome with a silver lining, and it depended on utilities having people who knew how to run a treatment plant without its automation, even if its digital defenses collapsed outright.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Expert warns this dangerous Microsoft Word worm can burrow into Copilot and cause havoc — here's what we know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/expert-warns-this-dangerous-microsoft-word-worm-can-burrow-into-copilot-and-cause-havoc-heres-what-we-know</link>
                                                                            <description>
                            <![CDATA[ Hidden white text in a Word document can make Copilot rewrite your figures and copy itself into the finished file. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">R2UNGhXYXgyh4sP63s4pja</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 01 Aug 2026 19:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg">
                                                            <media:credit><![CDATA[Microsoft]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Copilot keyboard button]]></media:description>                                                            <media:text><![CDATA[Copilot keyboard button]]></media:text>
                                <media:title type="plain"><![CDATA[Copilot keyboard button]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GxSNrV6MwnmZHmLEQHF58B-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Instructions hidden as white text in a Word document can make Microsoft 365 Copilot silently alter the file it is drafting and copy the instructions into the output</strong></li><li><strong>Each poisoned document becomes a carrier, so the attack spreads through ordinary internal workflows without the original malicious file and needs no macros, malware, or code execution</strong></li><li><strong>Microsoft has shipped two mitigations across a 144-day disclosure, including a model upgrade, and the attack was still reproducible by the researcher</strong></li></ul><p>A security researcher has published a proof of concept showing that instructions hidden inside a Word document can cause Microsoft 365 Copilot to silently alter the file it is drafting, then copy those same instructions into the finished document, so the next person to use it becomes a carrier too.</p><p>Håkon Måløy, a data scientist with a doctorate in applied machine learning, <a href="https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/" target="_blank" rel="nofollow">disclosed the technique</a> as the third installment of his Context Collapse series, after a 144-day coordinated disclosure with the Microsoft Security Response Center.</p><p>The reason this is being reported ahead of a fix is that it still works despite multiple attempts by Microsoft, as he notes that no robust mitigation for the broader vulnerability class is currently available.</p><h2 id="a-clever-attack-designed-around-copilot-s-approach-to-text">A clever attack designed around Copilot's approach to text</h2><p>The underlying attack belongs to a family known as cross-domain prompt injection, or XPIA. An attacker writes instructions in a natural-language document, formats them as white text on a white background at a small point size, and shares the file.</p><p>Because Copilot for Word strips formatting before passing text to the underlying language model, the model reads text the human never sees. This is true even for documents that are not opened by the user on purpose: The attack can trigger either when a user manually attaches a document to Copilot or when Copilot, working in Work IQ mode, searches the user's OneDrive for relevant files and finds the malicious one on its own.</p><p>It is also more dangerous than other exploits because of one key element: propagation. The hidden prompt in Måløy's proof of concept had two parts. One instructed Copilot to alter the document being drafted, in his demonstration halving every financial figure in a quarterly report.</p><p>The other instructed Copilot to copy the prompt into the new document and conceal it, framed innocuously as source tracking and readability formatting. Copilot did both, appending the instructions in white text and mentioning neither action to the user.</p><p>The disclosure timeline is the most uncomfortable part of the report. Måløy reported to MSRC on March 6 2026. Microsoft confirmed the behavior on March 31 and shipped a first mitigation in early April via a reworked Edit with Copilot experience, which successfully blocked his original prompt wording. He reproduced the attack with different wording the same week, and a second case was opened.</p><p>The second fix, on July 14, consisted of upgrading the underlying model to GPT-5.5. Måløy broke it the following day using GPT-5.6, then voluntarily offered Microsoft a further two-week delay to attempt another mitigation. The class still reproduced on the disclosure date, indicating that although a fix is in the works, the exploit is still possible to run.</p><h2 id="a-complicated-issue-that-lacks-a-proper-resolution">A complicated issue that lacks a proper resolution</h2><p>The issue goes far beyond Microsoft Word: an AI assistant must ingest untrusted content to determine whether it is relevant or hostile. But the content enters the same context window as the system prompt and the user's actual request, so by the time the model evaluates whether the text is an attack, the attacker's tokens have already shaped that evaluation. </p><p>As Måløy puts it, "the content being inspected participates in the act of inspection."</p><p>Microsoft confirmed it had reviewed the findings in a statement to <a href="https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588" target="_blank"><em>The Register</em></a> but stopped short of indicating a timeline for a complete fix:<br><br>“We have addressed the findings reported by the researcher and thank them for working with us through coordinated vulnerability disclosure," the company said.</p><p>"To address this class of risk, we use a defense-in-depth strategy with safeguards that block malicious instructions at multiple points and help keep tasks aligned with users’ requests. We are continuously strengthening these safeguards as the technology and threat landscape evolve. We encourage customers to install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it.”</p><p>Måløy's recommendations are to treat externally sourced documents as untrusted when using them with Copilot, review attachments before starting an AI-assisted draft, and review Copilot's output carefully before sharing or reusing it.</p><p>He also suggested that generated documents should carry provenance metadata that records source material and model edits, which would not prevent injection but would make an infection traceable after the fact.</p><p>With Copilot extending further into agentic products that create and manipulate documents with less human oversight, the scope of how exploits like this could affect workflows (and users) will widen rather than narrow, and a complete solution is not yet in sight.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Blank spaces could hold danger - Kaspersky report warns of the dangers of 'parked domains' and empty pages where hackers could be lurking ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/blank-spaces-could-hold-danger-kaspersky-report-warns-of-the-dangers-of-parked-domains-and-empty-pages-where-hackers-could-be-lurking</link>
                                                                            <description>
                            <![CDATA[ That "Domain for Sale" page you closed without reading may have fingerprinted your device on the way in. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ie4yymrrmDLjXE6gxWMQED</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 01 Aug 2026 18:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky says empty web pages are watching you, and the research backs up the warning</strong></li><li><strong>Over 90% of parked domains now send visitors somewhere malicious, and clearing your cookies will not help</strong></li><li><strong>Blank pages are also a problem: many 'Coming Soon' placeholders are quietly fingerprinting your device</strong></li></ul><p>Kaspersky has unveiled a rather underreported attack vector which is increasingly being used by threat actors to harvest private data from unsuspecting victims: registered websites that are yet to be developed.</p><p>Its warning focuses on parked domains, the registered web addresses that have no real website behind them yet, arguing that the blank screens and "Coming Soon" placeholders users dismiss as harmless are frequently doing work in the background. </p><p>The company says simply loading one of these pages can trigger silent collection of a visitor's IP address, approximate location, User-Agent string and cookie identifiers, and that operators go further by building browser fingerprints through other techniques, then feeding the result into advertising networks to assemble targeted profiles without consent from users.</p><h2 id="browser-fingerprinting-sans-the-permissions">Browser fingerprinting sans the permissions</h2><p>The mechanics Kaspersky describes are worth understanding, because fingerprinting is the part most readers will not have encountered, and the part that conventional privacy habits do not touch.</p><p>For context, a cookie is a file placed on your machine that you can delete, thereby limiting tracking. A fingerprint is not stored on your machine at all. It is derived from how your specific hardware and software combination renders a test image, draws 3D graphics, or processes an audio signal, producing a value distinctive enough to identify the same device across unrelated sites.</p><p>Browser fingerprinting, the <a href="https://www.techradar.com/features/browser-fingerprinting-explained" target="_blank">method used to capture such data</a> within a browser session, is attractive to trackers because it is considerably harder to shake off. A private browsing window prevents your machine from keeping a local record of the visit, but it does not change how your hardware renders the test image, so the fingerprint it produces remains largely the same.</p><p>Such domains can also cause more direct damage than selling one's information to advertisers. Kaspersky says threat actors embed scripts that bounce visitors onward to fraudulent platforms, adult content, or online casinos. It flags typosquatting as a particularly acute risk, in which a domain differing from a well-known brand by a letter or two can capture mistyped traffic, landing the user on a phishing page or triggering a drive-by download.</p><p>This isn't the first time the problem has been reported, either, as recent <a href="https://krebsonsecurity.com/2025/12/most-parked-domains-now-serving-malicious-content/" target="_blank" rel="nofollow">research from Infoblox</a> finding that in large-scale experiments, over 90% of the time, a visitor to a parked domain was routed to illegal content, scams, scareware, antivirus subscription traps, or malware.</p><p>Kaspersky recommends several ways to mitigate the risk, including avoiding suspicious links, clearing cache and cookies after an unintended visit, and using software that blocks web tracking. </p><p>Clearing cookies is worth noting, though: it addresses the cookie identifiers Kaspersky mentions, but by the company's own explanation it does nothing about fingerprinting, because there is nothing stored locally to clear.</p><p>Parked domains, including blank pages that appear inert, are now a routine part of criminal infrastructure rather than digital litter and should be treated with caution. At best, you give away more information than you meant to. At worst, you become the victim of an attack you never saw coming.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Keeper Security's top-rated password manager is now 50% off, and it's the best security upgrade you'll make this year ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/computing/cyber-security/keeper-securitys-top-rated-password-manager-is-now-50-percent-off-and-its-the-best-security-upgrade-youll-make-this-year</link>
                                                                            <description>
                            <![CDATA[ Keeper Security's top-rated password manager is now 50% off, and it's the best security upgrade you'll make this year ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wayuAWwjctYnhFv2bUJei9</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 31 Jul 2026 16:02:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Nathan Walters ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nRsuAkdKB9fT2DuJu8pnFZ.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Nathan is an SEO copywriter for the vouchers team, so he knows how to save on the latest tech and games. Starting as a Deals Finder for MyVoucherCodes, he used his money-saving skills to&lt;a href=&quot;https://www.myvouchercodes.co.uk/resources/technology&quot;&gt; &lt;u&gt;write blogs and money-saving content about tech retailers&lt;/u&gt;&lt;/a&gt;. He has since covered topics such as graphics cards, mobile phones, game consoles and TVs for sites like PC Gamer, TechRadar, and Tom’s Hardware. He has also written money-saving advice for multiple publications such as Moneynet, NationalWorld, iPaper, Pick Me Up! And My Weekly. In addition to saving people money on their new tech, Nathan loves gaming and building PCs and is always looking for a good deal on graphics cards or video game keys.&lt;/p&gt;&lt;p&gt;Nathan has worked at Future since 2022 and has written about various big sale events such as Black Friday, Amazon Prime Day, Cyber Monday, and Christmas. His Deal Finder experience, combined with his voucher writing experience, has given him the skills needed to find amazing deals and update you on the latest and best ways to save on your next purchase. Nathan’s work has helped readers find the best-value gaming monitors, games, TVs, and streaming sites.&lt;/p&gt;&lt;p&gt;Born in the South Wales Valleys, Nathan is an avid video game and tabletop player who loves writing. When not finding tech deals, he can be found playing the latest games, playing D&amp;D, or writing game reviews for his website,&lt;a href=&quot;https://www.gamereport.co.uk/&quot;&gt; &lt;u&gt;GameReport&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg">
                                                            <media:credit><![CDATA[Future]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:description>                                                            <media:text><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:text>
                                <media:title type="plain"><![CDATA[The Keeper logo next to a label stating &quot;Price Cut&quot;.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/QFvexowkpqsxcqY8TUgdgc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Passwords are the first line of defence for almost everything we do online, and they're still the thing most of us manage the worst. Reused logins and guessable variations are exactly what credential stuffing attacks feed on, which is why you need a good dedicated password manager. </p><p>You'll need a good one though, and <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">one of our top password manager picks</a> has just become significantly cheaper.</p><p>For a limited time only, Keeper Security is <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">offering 50% off its Personal and Family plans</a> for its award-winning password manager. The discount applies to your full first year, so now is a better time than ever to make the switch.</p><div class="product"><a data-dimension112="2b581e12-8c36-11f1-ac2c-1be7a9f1f39a" data-action="Deal Block" data-label="50% off Award-winning Keeper Security Password Manager Personal and Family Plans" data-dimension48="50% off Award-winning Keeper Security Password Manager Personal and Family Plans" href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow"><figure class="van-image-figure "  ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:131px;"><p class="vanilla-image-block" style="padding-top:100.00%;"><img id="TbfSUDRsU8NdGFXVDRFiSW" name="keeper!.jpg" caption="" alt="" src="https://cdn.mos.cms.futurecdn.net/TbfSUDRsU8NdGFXVDRFiSW.jpg" mos="" align="middle" fullscreen="" width="131" height="131" attribution="" endorsement="" credit="" class=""></p></div></div></figure></a><p>For a limited time only get <a href="" target="_blank" rel="nofollow" data-dimension112="2b581e12-8c36-11f1-ac2c-1be7a9f1f39a" data-action="Deal Block" data-label="50% off Award-winning Keeper Security Password Manager Personal and Family Plans" data-dimension48="50% off Award-winning Keeper Security Password Manager Personal and Family Plans" data-dimension25="">50% off Award-winning Keeper Security Password Manager Personal and Family Plans</a><a class="view-deal button" href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow" data-dimension112="2b581e12-8c36-11f1-ac2c-1be7a9f1f39a" data-action="Deal Block" data-label="50% off Award-winning Keeper Security Password Manager Personal and Family Plans" data-dimension48="50% off Award-winning Keeper Security Password Manager Personal and Family Plans" data-dimension25="">View Deal</a></p></div><h2 id="why-choose-keeper">Why Choose Keeper?</h2><p>Keeper has been dedicated to keeping people's information secure on the web for over a decade and has consistently been among the top password managers recommended by our reviewers here at TechRadar, and <a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank">our in-depth Keeper Security review</a> concluded that its superb security credentials and broad array of features make it a winner for anyone looking to improve their web safety.</p><p>Keeper operates what they call a "zero-knowledge architecture", which means absolutely no one, not even Keeper themselves, can see your encrypted data and what's stored in your vault. You can be sure your passwords are safe with Keeper.</p><p>Then, when you consider that the Family plan covers five separate users, with a fully private vault, plus 10GB of secure file storage, the <a href="https://www.keepersecurity.com/en_GB/pricing/personal-and-family.html" target="_blank" rel="nofollow">50% off discount on family and personal plans</a> is hard to resist!</p><h2 id="try-before-you-buy">Try Before You Buy</h2><p>If you'd rather try before committing, and not just take our word for it, that's completely fine! Keeper Security offer a <a href="https://www.keepersecurity.com/en_GB/get-keeper.html" target="_blank" rel="nofollow">free 30-day trial </a>with no payment details required, which is long enough to move your logins over and see if it's the password manager for you.</p><p>But if you already know you need one of the best password managers, half price on the plan you'd have picked anyway is a rare deal, so grab it while its live!</p><h3 class="article-body__section" id="section-more-from-tech-radar"><span>More from Tech Radar</span></h3><ul><li><a href="https://www.techradar.com/reviews/keeper-password-manager" target="_blank"><strong>Keeper Review: pros & cons, features, ratings, pricing and more</strong></a></li><li><a href="https://www.techradar.com/uk/coupons/keeper-security" target="_blank"><strong>Keeper Security discount codes</strong></a></li><li><a href="https://www.techradar.com/pro/how-to-turn-your-home-into-a-digital-fortress-using-identity-theft-protection-parental-controls-and-antivirus" target="_blank"><strong>How to turn your home into a digital fortress using identity theft protection, parental controls, and antivirus</strong></a></li></ul>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'C-suite executives need to upskill themselves to really understand the threats': AI is becoming a tool for attackers and defenders, but true resilience requires a constantly changing strategy, says former GCHQ intelligence expert ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/c-suite-executives-need-to-upskill-themselves-to-really-understand-the-threats-ai-is-becoming-a-tool-for-attackers-and-defenders-but-true-resilience-requires-a-constantly-changing-strategy-says-former-gchq-intelligence-expert</link>
                                                                            <description>
                            <![CDATA[ The only choice for businesses it to adapt and respond, and that means using an evolving resilience strategy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">FQkC5T8wEa2zYAZNNZSS99</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/uFka7M2YjcFGhhtPTMDnJY-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 31 Jul 2026 14:31:28 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/uFka7M2YjcFGhhtPTMDnJY-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Abstract digital human face. Artificial intelligence concept of big data or cyber security]]></media:description>                                                            <media:text><![CDATA[Abstract digital human face. Artificial intelligence concept of big data or cyber security]]></media:text>
                                <media:title type="plain"><![CDATA[Abstract digital human face. Artificial intelligence concept of big data or cyber security]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/uFka7M2YjcFGhhtPTMDnJY-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Artificial intelligence is fast becoming a game-changer for cybersecurity, with new frontier models such as Claude Mythos and OpenAI's GPT-5.5 demonstrating their capabilities in hunting software vulnerabilities and evaluating how they can be chained to harm an organization.</p><p>But these models have proven to be a double-edged sword, with both companies disclosing incidents where their models have escaped sandbox testing and compromised other organizations.</p><p>Couple this with how threat actors are turning to AI to increase their own skill in breaching organizations at an industrial scale, and you are presented with a bleak picture for the future of cybersecurity. But the best resilience is to adapt, and make sure those at the top can make the right decisions at the right time.</p><h2 id="ai-as-a-tool-for-defense-and-resilience">AI as a tool for defense and resilience</h2><p>The latest challenge threat actors are presenting for businesses is their ability to match the skill of state-sponsored groups. The tactics, techniques, and procedures (TTPs) of these groups are being bolstered by the adoption of AI tools. Jailbreaking allows groups to use legitimate AI models to perform reconnaissance and research at scale, as well as the ability to <a href="https://www.techradar.com/pro/security/vibe-coded-threats-shift-again-hackers-are-using-ai-chatbots-to-write-malware-using-natural-language" target="_blank">modify and improve existing malware</a> and attack vectors.</p><p>A recent IBM report found that since 2025 there has been a 44% increase in cyber-attacks exploiting public-facing applications, a 40% increase in vulnerability exploitation, and a 50% growth in the number of active ransomware operators. Much of this is the result of attackers adopting AI tools into their workflows.</p><p>Professor Julian Richards is a leading expert in intelligence and security who held senior roles in intelligence analysis, training program design, and strategic liaison at the UK's Government Communications Headquarters (GCHQ). </p><p>I spoke with Professor Richards on the effects AI is having on the threat landscape,  how defense strategies can adapt, and where training can be best applied to keep businesses one step ahead.</p><ul><li><strong>What does cyber resilience really mean in a world where AI is being leveraged by threat actors to compromise businesses at a level that matches the craft of state-sponsored groups?</strong></li></ul><p>It is indeed the case that highly advanced techniques, the likes of which were previously the preserve of advanced states, are now readily available to a range of threat actors. This is partly because of thefts of highly advanced exploits such as ETERNALBLUE and their resale on the dark web.</p><p>Cyber resilience is about a range of approaches, however, which go beyond the technical into human layer factors. Keeping the response dynamic, diversified and creative will offer opportunities for resilience. </p><ul><li><strong>Has the age of saving and storing vulnerabilities for later use passed, and how are defense strategies changing in regard to the rapid exploitation of vulnerabilities?</strong></li></ul><p>Almost certainly not, and experience from potentially parallel worlds such as that of cryptography tell us that exploits can remain productive for multiple years after their exposure.</p><p>Many threat actors are investing heavily in HNDL (harvest now, decrypt later); and a widened notion of "harvest now, exploit later" is also on the menu. Again, a reverse view offers opportunities for defenders.</p><p>AI can be used, for example, to more comprehensively and dynamically map and analyse attacks, even where they are mutating and evolving rapidly. This allows for more immediate and dynamic response. </p><ul><li><strong>How are active defense strategies shaping the protection of businesses and their infrastructure, and what challenges are businesses experiencing with implementing these strategies on aging and legacy infrastructure?</strong></li></ul><p>As above, dynamic and active defense strategies are sensible and increasingly necessary. As with all areas of cybersecurity however, there are good and bad products on the market, and good and bad investment decisions being made.</p><p>One of the most important considerations for all businesses is making sure the defense strategy is appropriately tailored in scale and shape to the business itself; and making sure we deal with honest and adept brokers.</p><ul><li><strong>AI is rapidly reducing the timescale between vulnerability discovery and exploitation for both businesses and intelligence agencies. Where do legislated threat disclosure windows play into these shrinking timeframes, and how do you perceive they will evolve?</strong></li></ul><p>One of the problems with compliance legislation (or indeed any legislation) is that it moves and updates much more slowly than technology. This will increasingly mean that the challenge described becomes a real problem.</p><p>In intelligence, selective disclosure has always been an understood protocol under the rubric of protecting national security, but this may not wash for commercial organisations. Two things will need to happen.</p><p>First, compliance legislation in such areas as threat disclosure will have to be written in a way that businesses are protected in fast-moving situations, allowing, perhaps, for post facto disclosure in many cases. Creative regulation and legislation is possible to allow for this.</p><p>Second, court cases may have to be brought to challenge overly stringent threat disclosure penalties, and subsequent case precedents will hopefully balance and protect organisations in this fast-moving situation. All of this will require the leveraging of advanced cyber expertise in the areas of law and legislation. </p><ul><li><strong>What are the major blind spots business leaders have when it comes to the latest threats, and what is the role of AI in addressing these problems?</strong></li></ul><p>Probably two things, both of which have applied for a long time and are proving remarkably intractable! The first is complacency: "sure this happened to them, but it won't happen to us". Well it probably will.</p><p>The second is not understanding the importance of the human factor risk, which continues to be the biggest threat factor. Training, awareness, exercising for crises and internal compliance protocols might be irksome, but they remain crucially important for all businesses. </p><ul><li><strong>What steps can business leaders take to ensure their AI tools are providing accurate intelligence and data while reducing false positives and hallucinations?</strong></li></ul><p>Work with reputable cyber threat intelligence suppliers and analysts. Develop expertise such that triangulation (checking across multiple sources and feeds rather than just accepting one source of information) is understood and readily implemented.</p><p>Expect the unexpected - in short, all the things that intelligence organisations have had to do since the dawn of time. For larger organisations, this is will mean a continual upskilling of key staff to be at the top of the game of understanding the dynamic threat picture. </p><ul><li><strong>Where can C-suite executives seek support in making key decisions on incident response when defending against threat actors increasingly leveraging AI?</strong></li></ul><p>C-suite executives need to upskill themselves to really understand the threats and their dynamism in such a way that they can support everyone in the organisation battling with these issues.</p><p>It is still the case that many at the top have either a sketchy understanding of the risk, or see it as something that others in the organisation will sort out. This is increasingly untenable today.</p><p>Ultimately, those at the top will have to take the hit when it all goers horribly wrong! What this means is that training, workshopping and exercising through crisis scenarios is as important for the C-suite executives as it is for any other members of the organisation. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Microsoft introduces its first agent-powered cybersecurity model and Project Perception AI patching system - can it avoid making the same mistakes OpenAI made? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/microsoft-introduces-its-first-agent-powered-cybersecurity-model-and-project-perception-ai-patching-system-can-it-avoid-making-the-same-mistakes-openai-made</link>
                                                                            <description>
                            <![CDATA[ Microsoft's new security AI writes and deploys its own patches, six days after OpenAI's models escaped a sandbox and hacked Hugging Face ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">HDQEZ7GmaSBruSGW3UbtpW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Jul 2026 15:29:37 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Image depicting a hand on a scanner]]></media:text>
                                <media:title type="plain"><![CDATA[Image depicting a hand on a scanner]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/dN5toW9ygER7CeKYqEVwba-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Microsoft launches MAI-Cyber-1-Flash, its first in-house cybersecurity model.</strong></li><li><strong>It also reveals Project Perception, an agentic system whose red, blue, and green agents find, triage, and patch vulnerabilities</strong></li><li><strong>The launch comes days after OpenAI said its models escaped a sandbox and attacked Hugging Face</strong></li></ul><p>Microsoft has <a href="https://blogs.microsoft.com/blog/2026/07/27/rethinking-security-for-the-age-of-ai/" target="_blank" rel="nofollow">unveiled</a> two significant security announcements - MAI-Cyber-1-Flash, the first cybersecurity model it has trained in-house, and Project Perception, an agentic defense system that finds vulnerabilities, decides which ones matter, and writes and deploys the patches. </p><p>The launch took place days after <a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face">OpenAI disclosed that its own models had broken out of a sandbox and hacked Hugging Face</a>, which makes the timing either unfortunate or pointed.</p><p>With Microsoft claiming a 96% score on CyberGym, an industrial benchmark for cybersecurity, nearly 12 points above Anthropic's Claude Mythos 5, while promising as much as 50% savings in token cost, the company says it is bringing what it calls a 'well-tuned, multi-model system with access to uniquely rich historical training data',</p><h2 id="a-competitive-product-with-excellent-timing">A competitive product with excellent timing?</h2><p>The Hugging Face incident drew much attention, not all of it was negative: as it painted OpenAI's models as more capable than the company's own assessments had suggested. It also sharpened a question researchers have been raising for years: what happens when a model becomes capable enough to defeat the controls placed around it?</p><p>Microsoft's answer is well-timed and two-pronged, claiming to be both cheaper and more capable than the alternatives, though the performance figures are, so far, Microsoft's own.</p><p>MAI-Cyber-1-Flash, is a sparse mixture-of-experts transformer with 137 billion total parameters, five billion active, and a 256,000-token context window, built as a cybersecurity fine-tune of MAI-Code-1-Flash, itself developed from a MAI-Thinking-1 mid-training checkpoint.</p><p>It is designed to handle up to 90% of the tasks inside MDASH, Microsoft's multi-model vulnerability harness, with OpenAI's GPT-5.4 reserved for the hardest 10 percent. </p><p>Microsoft says that split costs about half as much as its previous best MDASH configuration. For now, it runs only within MDASH and is available to approved MDASH customers through an Azure AI Foundry private preview, with no standalone API.</p><p>Project Perception is the wrapper around it, drawing on MAI-Cyber-1-Flash for its first workflow alongside frontier models such as GPT-5.4. Three classes of agent split the work: red agents probe for paths an attacker could take, blue agents investigate and decide what constitutes meaningful risk, and green agents remediate and harden.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:900px;"><p class="vanilla-image-block" style="padding-top:56.22%;"><img id="gV5PyWNLW7jaWsgY8RrMkX" name="A chart from Microsoft showing how Project Perception splits security and operational tasks across coordinated multi-agent teams" alt="A chart from Microsoft showing how Project Perception splits security and operational tasks across coordinated multi-agent teams" src="https://cdn.mos.cms.futurecdn.net/gV5PyWNLW7jaWsgY8RrMkX.jpg" mos="" align="middle" fullscreen="" width="900" height="506" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="caption-text">A chart from Microsoft showing how Project Perception splits security and operational tasks across coordinated multi-agent teams </span><span class="credit" itemprop="copyrightHolder">(Image credit: Microsoft)</span></figcaption></figure><p>On the specific failure that let OpenAI's models loose, Microsoft took the precaution OpenAI did not, as it says all benchmark testing ran in a network-isolated environment with no access to production systems, the public internet, or external services. </p><p>OpenAI's sandbox, by contrast, kept one route outward in the form of an internal package-fetching service, and its models found a flaw in it, escalated privileges and worked across the research network until they reached a machine with internet access. Microsoft says its isolation held. Nobody outside Microsoft has verified that.</p><p>The harder question is not containment during testing. Project Perception moves the work out of a research network and into customer production environments, where green agents are authorized to change live systems as their normal function. </p><p>There is no sandbox to escape, because acting on real infrastructure is the product. And attribution is difficult even when someone is watching: Hugging Face detected the intrusion within days and reported it to law enforcement, but had no idea who was behind it until OpenAI said so.</p><p>It also could not get help from the leading American models, which read its defensive requests as offensive ones and refused. It ended up defending itself with GLM 5.2, a Chinese open-weight model, running on its own infrastructure.</p><p>For now, the industry's answer to dangerous capability remains narrower distribution, and the one documented case of a defender needing that capability urgently ended with them reaching for a model nobody had gated.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Identifying vulnerabilities is no longer enough’: Companies need to focus on fixing exploitable vulnerabilities, not discovering as many as possible, says Checkmarx CEO ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/identifying-vulnerabilities-is-no-longer-enough-companies-need-to-focus-on-fixing-exploitable-vulnerabilities-not-discovering-as-many-as-possible-says-checkmarx-ceo</link>
                                                                            <description>
                            <![CDATA[ AppSec must shift from finding every single vulnerability to prioritizing exploitable risks, and human expertise is in hot demand. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">iqVLAKgozi5Uzrq4xGTGiA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 30 Jul 2026 11:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ desire.athow@futurenet.com (Desire Athow) ]]></author>                    <dc:creator><![CDATA[ Desire Athow ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/oEw3XiohQwun9z7gMxKzkB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Désiré has been musing and writing about technology during a career spanning four decades. He dabbled in &lt;a href=&quot;https://www.techradar.com/news/the-best-website-builder&quot;&gt;website builders&lt;/a&gt; and &lt;a href=&quot;https://www.techradar.com/web-hosting/best-web-hosting-service-websites&quot;&gt;web hosting&lt;/a&gt; when DHTML and frames were in vogue and started narrating about the impact of technology on society just before the start of the Y2K hysteria at the turn of the last millennium.&lt;/p&gt;&lt;p&gt;Then followed a weekly tech column in a local business magazine in Mauritius, a late night tech radio programme called &lt;a href=&quot;https://web.archive.org/web/20030414214749/http://www.clicplus.com/&quot;&gt;Clicplus&lt;/a&gt; and a freelancing gig at the now-defunct, Theinquirer, with the late Mike Magee as mentor. After an eight-year stint at ITProPortal.com, where he discovered the joys of global techfests and transformed the publication into one of the biggest tech B2B independent publishers, Désiré moved to TechRadar Pro where he has been the editor for nine years.&lt;/p&gt;&lt;p&gt;He has an affinity for anything hardware and staunchly refuses to stop writing reviews of obscure products or cover niche B2B software-as-a-service providers. He is an avid deal hunter and can be found lurking around on various deals forums.&lt;/p&gt; ]]></dc:description>
                                                                                                        <dc:contributor><![CDATA[ Craig Hale ]]></dc:contributor>
                                                                    <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/TippaPatt]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:description>                                                            <media:text><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:text>
                                <media:title type="plain"><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Artificial intelligence came at just about the right time, speeding up app and software development as the world started to contend with skills shortages, but it changed the pace so much that security teams have not been able to keep up.</p><p>Recently, we’ve seen AI being applied across multiple other domains with role-specific agents and tools, but that’s introduced its own challenges. While tools like Claude Code have proven a hit for generating, reviewing and editing code in seconds, security-focused tools like Anthropic’s Claude Mythos family of models are having broader impacts on the industry.</p><p>Anthropic itself has even admitted that Mythos is so powerful that the worry it could be abused by malicious criminals is extremely real – the Preview model is currently only available to a select number of pre-approved partners.</p><p>So with AI now capable of inspecting code, discovering vulnerabilities and suggesting fixes, do organizations even need as many human workers on the case, or can they get by with significantly fewer humans in the loop serving as AI reviewers? Recent layoffs have certainly implied as much.</p><h2 id="the-evolving-role-of-security-workers-in-an-ai-first-world">The evolving role of security workers in an AI-first world</h2><p>But with the entire lifecycle of development now amplified by AI, experts are warning that companies could actually be creating more work for themselves, and more than they could ever handle, leaving them facing strains from angles they weren’t previously exposed to.</p><p>For example, fewer than one in 10 companies now fix 90% of identified vulnerabilities within 90 days – implying that the volume of vulnerabilities is indeed increasing, rather than that fix efficiency is slipping.</p><p>Anthropic even revealed that its around 50 early Mythos Preview partners discovered more than 10,000 high- or critical-severity vulnerabilities – and thousands more of lesser significance.</p><p>Checkmarx CEO Sandeep Johri predicts we could soon find a balance, where vulnerabilities volume matters less and we revert our focus back toward exploitable risks. I spoke with Johri about the evolution of AppSec, where AI is and isn’t useful, and how organizations can balance speed and control.</p><ul><li><strong>With the rise of AI coding tools and AI-generated software, some are questioning whether traditional application security practices are becoming outdated. Is AppSec actually becoming obsolete, or is it evolving?</strong></li></ul><p>Traditional application security is not obsolete. It is evolving to meet the reality of how software is being built today.</p><p>For years, the process was fairly linear: developers wrote code, security teams scanned it, and vulnerabilities were addressed later. That approach becomes much harder when software is being created at a much faster pace with the help of AI.</p><p>AI accelerates development and risk simultaneously: 70% of developers say AI-generated code created more vulnerabilities in 2025, according to our research. As code volume and complexity compound, security needs to move earlier into the development process, giving developers the tools and guidance they need while they are building.</p><p>Security teams will continue to play a critical role to help organizations develop software and maintain confidence in their enterprise applications. But their focus needs to shift from finding vulnerabilities to remediating them at scale, because we are tracking an enormous gap in most companies. Our data finds that fewer than 10% of organizations fix 90% of identified vulnerabilities in 90 days.  </p><ul><li><strong>AI coding tools are helping developers create software faster than ever before. What new security challenges does this introduce for organizations adopting these technologies at scale?</strong></li></ul><p>The biggest challenge is that development speed is increasing faster than many security processes can keep up with. AI coding tools allow teams to create and deploy software quickly, but the code generated by AI still needs to be reviewed, tested, and secured.</p><p>Companies that ship 81-100% of their code with AI are nearly three times more likely to ship vulnerable code than those who use AI 1-20% of the time. This volume can overwhelm security teams with thousands of findings, many of which don't represent meaningful risk. The priority needs to be identifying the vulnerabilities that actually create exposure and helping teams fix those issues faster. </p><ul><li><strong>Many organizations are looking to AI to help identify and fix security vulnerabilities. Why shouldn’t companies rely solely on AI models to secure the code that AI is helping create?</strong></li></ul><p>AI is a valuable tool for security teams, but organizations still need accuracy, context, and human oversight. AI can help identify patterns, analyze code, and accelerate remediation, but security decisions require confidence in what risks actually matter. </p><p>Frontier models can uncover hidden exploit paths, but they can also deliver inconsistent findings and false positives. Their results may change depending on the prompt, and they can still miss known critical vulnerabilities. </p><p>The challenge with relying only on AI is that organizations may create a false sense of security, or “automation bias.” AI models can generate code and help analyze vulnerabilities, but they need to be paired with security expertise and proven security practices.</p><p>The most effective approach combines AI-driven capabilities with strong security foundations, so teams can move faster while maintaining control over risk.</p><ul><li><strong>As companies adopt more AI tools throughout the development process, what are the biggest security risks they need to consider beyond just AI-generated code?</strong></li></ul><p>Organizations need to think beyond the code itself and look at the entire AI ecosystem being introduced into software development. Many companies are adopting AI tools, models, agents, libraries, and other components faster than they can establish governance around them. This creates visibility challenges because security teams may not know what AI technologies are being used, where they exist in applications, or whether they meet security requirements.</p><p>Another concern is shadow AI, where employees use AI tools without formal approval or oversight. Organizations need visibility, clear policies, and a way to manage these technologies as part of their overall software supply chain.  </p><p>Perhaps the most urgent problem is the expansion of the attack surface itself. With LLMs, it has never been faster, cheaper, or easier for bad actors to exploit software. Issues that sat undetected for years are now being surfaced and weaponized at machine speed. Of the vulnerabilities Mythos has found so far, 99% haven't been patched, according to Gartner.</p><ul><li><strong>How does the rise of AI change the role of security teams? Does the traditional approach to finding vulnerabilities need to shift toward a model focused more on prioritization, remediation, and continuous protection?</strong></li></ul><p>Identifying vulnerabilities is no longer enough when organizations already have more findings than they can realistically address. Security has to become continuous, embedded in development workflows, working in lockstep with developers, to build securely from the start while maintaining visibility and control.  </p><p>We are shifting the focus to understand which issues create the greatest risk to give developers the context to address them fast, where code is written in the IDE.</p><p>Fidelity now matters more than volume. One verified true positive is worth more than a hundred low-confidence findings. If developers can’t trust what they’re shown, they’ll start ignoring it. That’s why organizations are increasingly looking at metrics like F1 score, which measure precision and recall together, rather than raw finding counts.</p><ul><li><strong>What does the future of application security look like in an AI-driven software development world? Will organizations need a different approach to balancing speed, innovation, and security?</strong></li></ul><p>The future of application security will require a more integrated approach. Organizations are going to continue adopting AI because the productivity benefits are significant, but security needs to evolve alongside that innovation.</p><p>Security will become more agentic, more intelligent, and more closely connected to the development process. Part of that evolution is combining deterministic, rules-based scanning with AI-driven reasoning in a single process, rather than running them as separate, disconnected tools. Deterministic methods catch what’s already proven; AI reasoning catches what’s novel. Together they’re more complete than either alone.  </p><p>In addition, deterministic models have real cost advantages. Asking a frontier model to reason its way to security (i.e. extra review passes, self-generated threat models) burns tokens fast.  That cost compounds the longer a vulnerability survives: cheap to fix in the IDE, more expensive in CI/CD, most expensive once it's live in runtime. And every time a developer has to stop and pull a vulnerability out of code that's already shipped, that's velocity lost to rework instead of innovation.</p><p>Teams will need technology that can help identify real risks, support faster remediation, and provide visibility across the entire software lifecycle. The organizations that succeed will be those that make security part of how they build software, allowing developers to move quickly while reducing unnecessary risk.</p><ul><li><strong>For organizations that are embracing AI coding tools today, what steps should they take to make sure they can innovate quickly without introducing unnecessary security risks?</strong></li></ul><p>The first step is visibility. Organizations need to understand where AI is being used, what tools are being introduced, and what impact those tools have on their applications.</p><p>Remediation is far cheaper the earlier it happens — catching an issue in the IDE costs a fraction of catching it further down the pipeline. But there’s another unsettling gap in our research: nearly all developers have access to in-IDE security tools, but fewer than one in five actually secure code as they write it. The cost of fixing that issue compounds as it passes through later stages of development.</p><p>  In addition, organizations need clear governance around AI adoption, because only 22% currently have formal AI governance policies in place. That means defining policies, monitoring usage, and making sure teams have the right security controls as they continue to innovate.  </p><p>AI will continue to change software development. The companies that benefit most will be the ones that embrace the technology while building security into the process from the beginning.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Agentic security doesn't need a whole new definition – you just need to reframe what you already know ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/agentic-security-doesnt-need-a-whole-new-definition-you-just-need-to-reframe-what-you-already-know</link>
                                                                            <description>
                            <![CDATA[ Security leaders are being forced to rethink identity, permissions and monitoring for AI agents – but they only need to reframe everything they already know. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">h2FM9tRX7cogufej22yx5U</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/8vLsLeC4LHKgwTpJRXEWKZ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/8vLsLeC4LHKgwTpJRXEWKZ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI]]></media:description>                                                            <media:text><![CDATA[AI]]></media:text>
                                <media:title type="plain"><![CDATA[AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/8vLsLeC4LHKgwTpJRXEWKZ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Though attack vectors and threat environments have changed since the advent of the internet, one thing has remained a constant – humans use software, and software has predefined parameters.</p><p>That distinction is exactly why social engineering remains so effective. Cybercriminals exploit predictable weaknesses in human behavior, granting them accesss to accounts and other sensitive information.</p><p>For the first time ever, that long-standing assumption is being turned on its head. In today's increasingly autonomous world, AI agents can take action on behalf of humans, creating an entirely new class of attack vectors that target machine autonomy rather than human weaknesses.</p><h2 id="the-boundary-between-software-and-user-is-getting-really-really-blurry">The boundary between software and user is getting really, really blurry</h2><p>The purpose of an agent isn't just to retrieve information or wait for a human's approval – its responsibilities can include interpreting objectives, developing plans, choosing tools, accessing data autonomously and taking actions. In short, agentic AI bridges both software and user.</p><p>This doesn't make everything we know about software and SaaS security obsolete, but it does mean that many of the assumptions underpinning today's controls are no longer sufficient. Humans will continue to use conventional software, but alongside agentic workflows, leaving organizations responsible for security both types of environment.</p><p>Thankfully, the fundamentals remain – least privilege, strong authentication and separation of duties will all be central to the next wave of cybersecurity. What will change, though, is how those principles will be applied to agents, which don't behave as software or human users.</p><h2 id="ai-agents-need-identities-of-their-own">AI agents need identities of their own</h2><p>The first requirement is to stop treating agents like features hidden inside applications, or software in their own right. An enterprise agent should actually have a first-class identity just like any other human colleague.</p><p>This means AI agents should have unique identities, named owners (line managers), clearly defined purposes and specific permissions. But they should also have their own lifecycles akin to software, such as creation dates, review points and expiry dates.</p><p>"Expiry dates or periodic recertification are important because agents can otherwise become long-lived access paths that are harder to govern than human users," Zendesk Chief Security Officer Vinay Patel explained to me in an exclusive interview.</p><p>At the end of the day, these are the sorts of controls that already exist for human users because organizations already understand the risks of unmanaged access, due to role changes or company departures, for example.</p><p>Without treating AI agents as users in their own right, companies risk accumulating abandoned agents, stored credentials and even data access paths whose original business purposes may have disappeared – an unthinkable consequence for humans, so one that should be treated just as severely for AI agents.</p><h2 id="human-in-the-loop-automation-is-the-future">Human-in-the-loop automation is the future</h2><p>Importantly, AI agents don't just occupy one space. They can act autonomously, be commissioned on a task-by-task basis by a human user, or operate somewhere between the two. Patel told me that an "audit trail should preserve both identities: the human who initiated or authorized the action and the agent that executed it."</p><p>For fully autonomous agents, a log tying them back to their "owner, purpose, and approved policy" is still just as important.</p><p>But of course, it all boils down to flawless visibility and effective management. "Companies need inventory and discovery across the places agents can be created or embedded, including SaaS platforms, internal automation tools, development environments, and third-party integrations," Patel added.</p><p>Organizations must monitor not only which agents are deployed, but whether their permissions and behavior remain aligned with their original business purposes.</p><p>Recent <a href="https://www.nccoe.nist.gov/sites/default/files/2026-02/accelerating-the-adoption-of-software-and-ai-agent-identity-and-authorization-concept-paper.pdf" target="_blank">NIST research</a> raises many of the same priorities, including verifiable records of agent actions, intent, data sources and generated output. But while NIST is developing guidance around agent adoption, visibility, control and accountability, agents are already being deployed, and often without the necessary safeguards.</p><h2 id="traditional-iam-falls-short">Traditional IAM falls short</h2><p>A separate <a href="https://cloudsecurityalliance.org/artifacts/agentic-ai-identity-and-access-management-a-new-approach" target="_blank">Cloud Security Alliance paper</a> concluded, "traditional identity and access management (IAM) protocols, designed for static applications and human users, can’t keep up."</p><p>The researchers argue that credentials and permissions should be task-specific, short-lived and easily revokable, unlike human identities which are generally set for the duration of their employment contracts.</p><p>The CSA also recommends applying zero-trust principles by treating agent compromise as a credible possibility. By enforcing least privilege, isolating systems and continuously verifying access, organizations can limit the potential consequences of an attack or misconfiguration as they adapt to this new security environment.</p><h2 id="accountability-starts-before-deployment">Accountability starts before deployment</h2><p>Patel says that, "accountability should not collapse onto a single party by default." It's as much the responsibility of adopters as it is lawmakers, and even end users.</p><p>Key to understanding vulnerabilities and potential risks is identifying where the failure occurred: "user’s instruction, the agent owner’s governance, the developer’s design, the platform provider’s controls, or the enterprise’s deployment model."</p><p>Above all else, Zendesk's Chief Security Officer argues that "accountability must be defined before deployment, not reconstructed after an incident."</p><p>In the short term, this work could slow AI adoption as companies address controls that might've been overlooked during early, informal experimentation. The danger arises when a successful pilot actual progresses into production without pausing to define ownership, permissions and other policies.</p><p>Before scaling agent deployments, organizations should pause other ensure the right foundations are in place. Governance becomes much harder to retrofit once an agent has actually been embedded.</p><h2 id="preparing-for-the-autonomous-workforce">Preparing for the autonomous workforce</h2><p>The question is no longer how, or even whether, AI agents will become part of the enterprise – it's about how employers can establish the necessary controls before they're more common than human workers.</p><p>The most valuable security investments today focus on visibility, control, accountability and governance, not forgetting over investments tech admins are making across data foundations and interoperability.</p><p>But thankfully, none of this requires a business to abandon the security principles it's spent decades developing. All it requires is for leaders to extend and reframe these for the agentic world.</p><p>The future enterprise will combine the human-software environment we already know with a new end-to-end agentic layer – neither one of these will replace the other. Companies preparing for this new hybrid will see the greatest returns.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ They might have grown up online — but Gen Z are apparently far less likely to use antivirus, study finds ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/they-might-have-grown-up-online-but-gen-z-are-apparently-far-less-likely-to-use-antivirus-study-finds</link>
                                                                            <description>
                            <![CDATA[ A new survey from cybersecurity specialists Kaspersky has revealed a worrying trend among Gen Z: they’re ignorant of online threats. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">2dHF3Z3PkeSKnULDdFqtgA</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/okt5myc3MwKUsdMaigYsi8-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 29 Jul 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/okt5myc3MwKUsdMaigYsi8-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phone frustrated]]></media:description>                                                            <media:text><![CDATA[Phone frustrated]]></media:text>
                                <media:title type="plain"><![CDATA[Phone frustrated]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/okt5myc3MwKUsdMaigYsi8-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Just 27% of Gen Z respondents use antivirus software for mobile devices, and are less likely to regularly change passwords</strong></li><li><strong>57% of Gen Z spend more time online than offline, Kaspersky finds</strong></li><li><strong>And only 28% regularly backup important personal data stored on their phones</strong></li></ul><p>Gen Z has no awareness of cybersecurity, online safety principles, or the risks of not changing your password. With just over half (52%) of respondents admitting they have had devices, data, or online accounts attacked, only 27% actually employ standard countermeasures like mobile antivirus tools.</p><p>In a study of 7200 respondents from 18 countries, the company also found only 28% regularly backup important personal data stored on their phones. </p><p>An average Gen Z-er appears to rely almost completely on their smartphone, which is where they store the information they value most, apparently without cloud backups or syncing in place. The survey has shown that social media accounts have been hacked (17%) and gaming accounts lost (12%), but smartphones have further risks to personal privacy if the correct precautions are not taken.</p><h2 id="gen-z-needs-to-appreciate-the-risks">Gen Z needs to appreciate the risks</h2><p>Access to personal photographs, identity documents, email, financial details, and of course social media profiles can be acquired via a compromised smartphone, opening the victim to a host of targeted attacks. Direct financial attacks can be made, identity theft, and more, depending on how successful the attacker is. Keeping the device out of an attackers reach, rather than inadvertently sharing its contents, is the safer course of action.</p><p>Irina Ermilova, Vice President for Consumer Product Management at Kaspersky, looked to address the apparent disconnect between a generation that has grown up with internet access and portable digital tech, and its lack of cybersecurity nous.</p><p>“Gen Z has grown up online, so digital services often feel intuitive and familiar to them. However, familiarity should not be confused with security expertise," she noted. "Being able to navigate apps, platforms and devices confidently does not necessarily mean being able to identify scams, manage passwords securely or protect personal data.”</p><p>“The findings show that cybersecurity tools and habits need to become as natural part of everyday digital life as messaging, gaming or using social media.”</p><h2 id="training-gen-z-to-find-digital-threats">Training Gen Z to find digital threats</h2><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:1280px;"><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="FuW8LNMkpnWpR5Loire6pR" name="tr-kaspersky-case404" alt="Screenshot from Kaspersky browser game Case 404" src="https://cdn.mos.cms.futurecdn.net/FuW8LNMkpnWpR5Loire6pR.png" mos="" align="middle" fullscreen="" width="1280" height="720" attribution="" endorsement="" class="inline"></p></div></div><figcaption itemprop="caption description" class=" inline-layout"><span class="credit" itemprop="copyrightHolder">(Image credit: Kaspersky)</span></figcaption></figure><p>Looking for a solution to this lack of cyber-risk awareness, Kaspersky has launched an interactive online game aimed at Gen Z users. <a href="https://case404.kaspersky.com/" target="_blank">Case 404</a> is a "cyber-detective adventure" in the point-and-click mold, set in the future with fictional cases that have been inspired by actual digital threats.</p><p>In playing the game, Kaspersky hopes that Gen Z users will spot the scams and phishing attempts, and take that knowledge with them into the real world and stay safe and secure online.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn 2.2 million cars could be at risk of hijacking via Bluetooth ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-2-2-million-cars-could-be-at-risk-of-hijacking-via-bluetooth</link>
                                                                            <description>
                            <![CDATA[ Researchers find dealer-installed KARR and SWDS security systems are open to a Bluetooth-based hack which can remotely unlock doors and stop a vehicle from starting. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">G7JrH4KatQ5aFECzCy6c4f</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 27 Jul 2026 00:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand over a concealed car door handle]]></media:description>                                                            <media:text><![CDATA[A hand over a concealed car door handle]]></media:text>
                                <media:title type="plain"><![CDATA[A hand over a concealed car door handle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UdHTZzTLLETcncr7PYcnoK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>2.2 million vehicles are susceptible to a Bluetooth-based attack in the state of California</strong></li><li><strong>The vulnerability is due to dealer-installed security systems</strong></li><li><strong>Researchers at the University of California San Diego found that the Acrisure-built security devices all rely on the same secure key</strong></li></ul><p>A vulnerability has been found in KARR and SWDS automobile security systems manufactured by Acrisure that enables remote control via Bluetooth. The vehicles had the security systems installed by car dealers in California, specifically as anti-theft and tracking devices. Thanks to this hack, however, it seems that vehicles can be unlocked, with some further control given to the attacker.</p><p>Researchers at the University of California San Diego found that the 2.2 million automobiles were purchased from Southern Californian dealers since 2017, although the secondary market means that the vehicles could be elsewhere in the US, and even as far afield as Japan.</p><p>Worryingly, the researchers also found a publicly-accessible database holding information about all vehicles with the security system equipped.</p><h2 id="how-bluetooth-controls-these-cars">How Bluetooth controls these cars</h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/xS_4dNRGkoA" allowfullscreen></iframe></div></div><p>The researchers determined that the automobiles were purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships, and the affected vehicles have the “KARR-SWDS” label on the driver-side window, with the anti-theft device mounted under the dashboard. </p><p>Usage is straightforward: a mobile app connects to the KARR security system over Bluetooth and includes functions such as locking and unlocking doors, controlling the horn, and flashing the headlamps. It can also prevent the car from starting, although this only works if it isn’t already running. </p><p>The problem is with the implementation, which the researchers discovered relied on the same secure key on the KARR security systems. Once cracked, all cars equipped with the same device were believed to be open to attack.</p><p>Changing the secure key isn’t an option, and neither is disabling the Bluetooth. Of particular concern is that researchers found that even if the buyer doesn’t pay for a subscription for the app and the KARR system, the hardware is still in place. Worse, it has the same access to the vehicle’s doors, ignition, horn, and headlamps.</p><p>“Removing the devices is not trivial,” UCSD compsci PhD candidate and paper co-author Yibo Wei said in the report on the research (which is fully released in August). “You have to open up the dashboard and cut and reconnect the wires that are deeply intertwined with the car’s computers and ignition system.”</p><h2 id="the-patch-is-in">The patch is in</h2><p>Jerry Yu, also co-author, wrote “Instead of smashing a window to get access to a vehicle, thieves could simply connect remotely via Bluetooth to the device inside the vehicle, and make it unlock car doors.”</p><p>KARR has <a href="https://www.theregister.com/security/2026/07/23/millions-of-california-bought-cars-can-be-hijacked-via-bluetooth/5277315" target="_blank">told</a> media outlets that only vehicles installed “with certain Bluetooth-related components” are affected, and the company has issued a <a href="https://www.karrsecurity.com/karr-security-firmware-update-instructions" target="_blank">firmware update</a>.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ It's not just OpenAI models escaping and running riot — experts show how Claude Cowork can break its bonds and access Mac files ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/its-not-just-openai-models-escaping-and-running-riot-experts-show-how-claude-cowork-can-break-its-bonds-and-access-mac-files</link>
                                                                            <description>
                            <![CDATA[ Anthropic partially mitigated the issue, and there are things users can do to defend themselves, too. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4ePtwBtUWhGdeVjtV2gT6k</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/kQgz8fSBJp3j2YakUJFn4N-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 26 Jul 2026 13:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/kQgz8fSBJp3j2YakUJFn4N-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/ gguy]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Claude AI]]></media:description>                                                            <media:text><![CDATA[Claude AI]]></media:text>
                                <media:title type="plain"><![CDATA[Claude AI]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/kQgz8fSBJp3j2YakUJFn4N-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Accomplish AI showed Claude Cowork could escape a VM sandbox via Linux zero‑day CVE‑2026‑46331</strong></li><li><strong>Agent accessed host Mac files, risking exfiltration of SSH keys, cloud credentials, and more</strong></li><li><strong>Anthropic shifted Cowork to default cloud execution; local users must harden configs to mitigate exposure</strong></li></ul><p>Recent news of <a href="https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent">a ChatGPT agent escaping the sandbox and attacking services on the internet</a> raised quite a few eyebrows, but it seems it’s not the only one capable of running wild. Security researchers Accomplish AI are saying they achieved similar results with Anthropic’s Claude Cowork.</p><p>In a new report, the researchers said they ran a local session in a Mac-hosted <a href="https://www.techradar.com/best/best-virtual-machine-software" target="_blank">virtual Linux machine</a> and then observed as the agent broke free of the VM and started reading and writing files on the underlying system.</p><p>“We connected a folder to a fresh Claude Cowork session, sent one short message, and watched the agent escape the sandbox,” Oren Yomtov, principal security researcher at Accomplish AI, told<em> </em><a href="https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html" target="_blank"><em>The Hacker News</em></a>. “From inside the VM, it reached the host Mac and read and wrote files all over it, far outside the folder we'd connected, with no permission prompt anywhere.”</p><h2 id="defaulting-to-cloud-execution">Defaulting to cloud execution</h2><p>This means that, in theory, the agent can be used to access or exfiltrate anything that’s stored on the Mac’s user account, including SSH keys, cloud credentials, and more. To break out of the sandbox, the agent exploited CVE-2026-46331 ("pedit COW"), a Linux kernel privilege-escalation vulnerability. This flaw, fixed in mid-June this year, was given a severity score of 7.8/10 (high).</p><p>Accomplish AI disclosed these findings with Anthropic, which allegedly acknowledged them but did not issue a direct fix. However, the version of Claude Cowork that was released afterwards defaults to cloud execution which, the publication claims, addresses the issue. Still, users who opt to run the agent locally rather than in the <a href="https://www.techradar.com/best/best-cloud-storage" target="_blank">cloud</a> will remain exposed. </p><p>Mitigations are possible, though. Users should disable unprivileged user namespaces, grant/revoke seccopm permissions, stop modules autoloading, and restrict sharing of the whole host into the VM. </p><p>"Scope it to the folders that were actually connected instead of all of /, or at least mount it read-only, and run coworkd with ProtectSystem=strict in its own mount namespace so it isn't re-execing binaries a session user can poison," Accomplish AI explained. "Then even a full guest-root has nothing to land on, the last two steps of the chain have nowhere to go."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This Russian cybercrime campaign can infect a user just by viewing an email ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-russian-cybercrime-campaign-can-infect-a-user-just-by-viewing-an-email</link>
                                                                            <description>
                            <![CDATA[ A high-severity flaw in Zimbra allowed Russian criminals easy access, where they stole important secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">TURduCNGpenh8p9SH4Vx9Z</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sun, 26 Jul 2026 11:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[russian flag]]></media:description>                                                            <media:text><![CDATA[russian flag]]></media:text>
                                <media:title type="plain"><![CDATA[russian flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/85kAnS2rcuxwyaibPRC4Ze-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint reports Russian TA488 exploited Zimbra zero‑day CVE‑2025‑66376 in espionage campaigns</strong></li><li><strong>“Half‑click exploit” let attackers compromise systems when victims merely viewed malicious emails</strong></li><li><strong>Targets included NATO, Ukrainian government, and defense entities; group vanished after Feb 2026 exposure</strong></li></ul><p>Russian state-sponsored cybercriminals have been abusing a zero-day vulnerability in the Zimbra <a href="https://www.techradar.com/best/best-secure-email-providers" target="_blank">email and collaboration</a> platform to conduct espionage against western targets - primarily military and government agencies, experts have warned.</p><p>Cybersecurity researchers <a href="https://www.proofpoint.com/us/blog/threat-insight/ta488-targets-zimbra-mailservers-half-click-exploits" target="_blank">Proofpoint</a> claim the campaign has been ongoing for at least a year, possibly longer, describing it as a “half-click exploit”, because the victims don’t even need to do anything specific in order to get infected. </p><p>Usually, when an attack is done via email, the victim is required to at least download a file or click a link. In this case, a cross-site scripting (XSS) vulnerability in the Zimbra web-based email service allowed the Russians to infiltrate the computers as soon as the victim views the email, nothing more.</p><h2 id="targeting-nato-and-ukraine">Targeting NATO and Ukraine</h2><p>The vulnerability in question is now tracked as CVE-2025-66376. It was assigned a severity score of 7.2/10 (high), and was patched in November 2025. However, the threat actors have been leveraging it long before Zimbra patched it up.</p><p>Proofpoint says numerous groups were observed, throughout the years, abusing this flaw. This time around, though, the group in question is tracked as TA488, also known as Laundry Bear or Void Blizzard.</p><p>“After successful exploitation, TA488 established persistent access to the systems and exfiltrated emails from the targeted users,” Proofpoint’s report reads. Besides emails, the crooks hunted for passwords, email directories, two-factor authentication tokens, and more. The group has been “consistently” targeting NATO and Ukrainian government organizations, alongside entities in the defense industrial base, </p><p>The group seems to be defunct now, since the researchers could not find any activity post February 2026. At that time, security researchers Seqrite disclosed a detailed breakdown of the group’s infrastructure and modus operandi, resulting in TA488 burning down months-old setups and vanishing.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts claim to have found more weaknesses in Apple's Gatekeeper tool — but it doesn't seem too bothered ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-claim-to-have-found-more-weaknesses-in-apples-gatekeeper-tool-but-it-doesnt-seem-too-bothered</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper doesn't blink when you archive a legitimate app and replace it with an evil doppelganger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cigoAwt4EPwNFgf9LCcsXa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:description>                                                            <media:text><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:text>
                                <media:title type="plain"><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Iran-linked group caught hiding surveillance tools in fake apps ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/vpn/vpn-privacy-security/iran-linked-group-caught-hiding-surveillance-tools-in-fake-apps</link>
                                                                            <description>
                            <![CDATA[ Researchers at Recorded Future found evidence that an Iran-linked group is spreading MarkiRAT spyware through fake VPN and media player apps promoted on social media, targeting Farsi speakers worldwide. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rcr4Mct7ErHSY84Lpy5fvW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 06:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[VPN Privacy &amp; Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[VPN]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                <author><![CDATA[ monicajwrites@gmail.com (Monica J. White) ]]></author>                    <dc:creator><![CDATA[ Monica J. White ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/6AQ4y5nzk8kQ47Yp69GERj.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Monica is a journalist with over a decade of experience in covering technology.&lt;/p&gt;&lt;p&gt;She writes about the latest developments in computing, which means anything from computer chips made out of paper to cutting-edge desktop processors. Her coverage includes CPUs, GPUs, and everything else that goes into a PC or a laptop, but also peripherals.&lt;/p&gt;&lt;p&gt;GPUs are Monica’s main area of interest, and nothing thrills her quite like that time every couple of years when new graphics cards hit the market. She’s always keeping tabs on the latest from Nvidia, AMD, and Intel, including both the hardware and the software that powers our PCs.&lt;/p&gt;&lt;p&gt;As an avid gamer, her focus is always on the consumer and whether something works well and provides adequate value for the money. She believes that PC building can be intimidating, so her goal is to explain complex concepts in an approachable manner while still digging into the technical nitty-gritty we all love to learn more about.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Malware kan ställa till med oreda]]></media:description>                                                            <media:text><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:text>
                                <media:title type="plain"><![CDATA[A hand with a mobile phone and VPN application in front of the Iran flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/z8Ysj7MUYeyK822yMiTepP-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Recorded Future found an Iran-linked group spreading spyware</strong></li><li><strong>The malware is delivered through fake VPN and media player apps</strong></li><li><strong>Researchers assess that most targets are Iranian users</strong></li></ul><p>A new report from <a href="https://www.recordedfuture.com/research/nexus-tag182-disseminates-markirat" target="_blank" rel="nofollow">Recorded Future's Insikt Group</a> describes a campaign that inverts the whole point of a privacy tool: fake VPN apps built specifically to spy on the people who install them.</p><p>Researchers have linked fresh infrastructure to an Iran-nexus threat cluster they track as TAG-182, which is using fake VPN and media player downloads to allegedly deliver a surveillance tool called MarkiRAT. The group is "highly likely" to be targeting Iranians living inside and outside the country, <a href="https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-ir-2026-0701.pdf" target="_blank" rel="nofollow">the report says</a>.</p><p>It's a blunt reminder that choosing one of the <a href="https://www.techradar.com/vpn/best-vpn" target="_blank" rel="nofollow">best VPN</a> services is a lot more secure than downloading free, unvetted tools.</p><h2 id="fake-apps-real-surveillance">Fake apps, real surveillance</h2><p>Insikt Group identified a cluster of attacker-controlled domains allegedly used to stage downloads of applications that appear nowhere on Google Play or Apple's App Store. </p><p>Two names stand out: Pis2ray VPN and a media player branded YESHICA, which was quietly renamed YESHICA YEPlayer in March 2026 after researchers publicly exposed the original.</p><p>According to researchers, if you download and run one of these files, you get MarkiRAT, a remote access Trojan. In plain terms, that is software that hands control of your device to somebody else. </p><div class="see-more see-more--clipped"><figure><blockquote class="twitter-tweet hawk-ignore" data-lang="en" cite="https://twitter.com/cantworkitout/status/2072720755884695924"><p lang="en" dir="ltr">A fake VPN app. A fake media player. Both delivering Iranian government surveillance #malware to targeted dissidents. Insikt Group has new research on TAG-182 and MarkiRAT:https://t.co/G7p9JO6peT#ThreatIntelligence #Cybersecurity pic.twitter.com/GwDyvGC99r<a href="https://twitter.com/cantworkitout/status/2072720755884695924">July 2, 2026</a></p></blockquote></figure><div class="see-more__filter"></div></div><p>Analysts have documented it capturing screenshots and uploading them to attacker-run servers, while disguising itself under believable process names.</p><p>It also abuses BITS, the background service Windows uses to fetch updates, to pull down further files. Because that activity looks like ordinary system housekeeping rather than an attack, it tends to slip past routine cleanup.</p><p>MarkiRAT is not new. It has previously been used by Ferocious Kitten, a group <a href="https://securelist.com/ferocious-kitten-6-years-of-covert-surveillance-in-iran/102806/" target="_blank" rel="nofollow">Kaspersky</a> documented conducting years of covert surveillance against activists inside Iran. </p><p>Recorded Future stops short of attributing TAG-182 to any specific Iranian agency, but places it within a broader ecosystem of state-aligned surveillance groups.</p><h2 id="why-a-fake-vpn-makes-such-an-effective-lure">Why a fake VPN makes such an effective lure</h2><p>Distribution runs largely through social media. Insikt Group found Instagram posts promoting Pis2ray VPN in the weeks following street protests in Iran in late 2025, and again around the <a href="https://www.techradar.com/vpn/vpn-privacy-security/the-internet-is-not-connected-irans-88-day-blackout-begins-to-lift-but-traffic-remains-under-50-percent">country's prolonged internet shutdown</a>, which ended with partial restoration of access on 26 May 2026.</p><p>The people most desperate for a <a href="https://www.techradar.com/vpn/virtual-private-networks">virtual private network (VPN)</a> in a censored country are exactly the people most likely to install one from a social media link, because the official stores are often the very thing they cannot reach. </p><p>Recorded Future considers it almost certain that most targets are located in Iran or tied to anti-government movements in Europe and North America. TechRadar has covered <a href="https://www.techradar.com/vpn/vpn-privacy-security/beware-iran-linked-fake-vpn-apps-found-to-spy-on-android-users" target="_blank" rel="nofollow">previous Iran-linked fake VPN campaigns</a>, and this one seems to follow the same pattern with better infrastructure.</p><h2 id="how-to-stay-safe">How to stay safe</h2><p>Most readers will never be targeted by a state actor, but the underlying lesson travels. </p><p>Install VPN apps only from official stores, and check that the provider has a real, verifiable presence outside the app listing. </p><p>Treat any VPN promoted through an Instagram post, a Telegram channel, or a direct message as suspect, however polished it looks. </p><p>Star ratings are a weak signal, since fake reviews are cheap.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>