<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:cf="https://www.futureplc.com/rss/content-flags"
>
    <channel>
                    <atom:link rel="alternate" hreflang="en-GB"
                       href="https://www.techradar.com/uk/feeds/tag/security"
                       type="application/rss+xml"/>
                            <title><![CDATA[ Latest from TechRadar UK in Security ]]></title>
                <link>https://www.techradar.com/uk/pro/security</link>
        <description><![CDATA[ All the latest security content from the TechRadar  UK team ]]></description>
                                    <lastBuildDate>Sat, 25 Jul 2026 14:20:00 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Experts claim to have found more weaknesses in Apple's Gatekeeper tool — but it doesn't seem too bothered ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-claim-to-have-found-more-weaknesses-in-apples-gatekeeper-tool-but-it-doesnt-seem-too-bothered</link>
                                                                            <description>
                            <![CDATA[ Gatekeeper doesn't blink when you archive a legitimate app and replace it with an evil doppelganger. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cigoAwt4EPwNFgf9LCcsXa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 25 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg">
                                                            <media:credit><![CDATA[Apple]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:description>                                                            <media:text><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:text>
                                <media:title type="plain"><![CDATA[A person using iPhone Mirroring on a MacBook Pro running macOS 27 Golden Gate.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ctUFkwkvMxVyJJwJmZLPJ5-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Researchers show Gatekeeper can be bypassed by replacing a previously run legitimate macOS app with malware</strong></li><li><strong>Attack requires prior user‑level code execution, then swaps in a malicious app that Gatekeeper won’t re‑verify</strong></li><li><strong>Apple dismissed the issue, saying locally rebuilt bundles fall outside Gatekeeper’s scope, leaving risk to social engineering</strong></li></ul><p>A pair of researchers claims to have found a way around Gatekeeper, a built-in macOS security feature that helps protect users from running malicious or untrusted software. However Apple doesn’t really see it that way and has seemingly decided not to pursue the issue further.</p><p>Gatekeeper’s modus operandi is rather simple - when a user downloads an app from outside the App Store, it verifies the product comes from an identified developer and is notarized by Apple. If it can’t verify it - it won’t allow it to run on the machine. </p><p>Now, security researchers Talal Haj Barky and Tommy Mysk claim that, as long as a legitimate app was run at least once on a macOS device, it can be replaced with a malicious version, and Gatekeeper won’t even blink its virtual eye.</p><h2 id="locally-built">Locally built</h2><p>That also means the attack is not that straightforward to pull off. The threat actor needs to have a way to execute user-level code (for example, a malicious app, a compromised software package installed through a package manager, or a prompt injection attack that tricks an AI agent).</p><p>Once that is obtained, they can archive a legitimate app, remove the original, then replace it with <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a>, and Gatekeeper will not try to re-authorize it. That malicious version can then trick the victim into compromising the device even further, since a certain level of trust was already established. </p><p>After reporting the issue to Apple, the company apparently just closed it. </p><p>"Apple doesn't consider this attack to be 'modifying' the signed executable," Mysk said. "Instead, Apple says that by archiving/restoring the app bundle, the proof-of-concept code overwrites the entire app bundle, making it locally built. Locally built app bundles are not covered by macOS guards. And this is why access to Keychain or TCC protected directories require system authorization prompts. And for users to accept those is a matter of social engineering attacks that Apple considers out of scope."</p><p><em>Via </em><a href="https://www.theregister.com/security/2026/07/24/researchers-replace-downloaded-macos-apps-with-evil-twins-apple-shrugs/5277858" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ GitHub restructures bug bounty program following flood of AI-generated reports ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/github-restructures-bug-bounty-program-following-flood-of-ai-generated-reports</link>
                                                                            <description>
                            <![CDATA[ GitHub splits off open, public bug bounty programs from invite-only, VIP scheme which pays around 3-4x more. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">fdmEcgX3tyUDmuYFb63ZCM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/cSKHBF8sbjF8tuFUhy7f5R-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 15:45:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/cSKHBF8sbjF8tuFUhy7f5R-1280-80.png">
                                                            <media:credit><![CDATA[N/A]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[bug bounty]]></media:description>                                                            <media:text><![CDATA[bug bounty]]></media:text>
                                <media:title type="plain"><![CDATA[bug bounty]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/cSKHBF8sbjF8tuFUhy7f5R-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>GitHub to launch two-tier (public and private) bug bounty schemes form July 27 2026</strong></li><li><strong>Change comes in response to rise in lower-quality, AI-generated reports</strong></li><li><strong>VIP researchers will earn around 3-4x more per report</strong></li></ul><p>GitHub has confirmed plans to evolve its bug bounty program into a two-tier system, which will come into force for reports submitted on or after July 27, 2026.</p><p>Under the new scheme, the Microsoft-owned coding platform will add a lower-paying public program that's available to the wider research community, under a higher-paying invitation-only program.</p><p>Product Security Engineer Catherine Cassell <a href="https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-program/" target="_blank">explained</a> that the change comes in response to a growing backlog of low-effort, low-quality and AI-generated reports.</p><h2 id="github-complains-about-ai-generated-bug-reports">GitHub complains about AI-generated bug reports</h2><p>For the new public program, GitHub will replace payout ranges with a single payment for each severity, spanning $250, $2,000, $5,000 and $10,000 for low, medium, high and critical. Cassell said this would help researchers know in advance what a valid finding could be worth, and it would also give insiders less of a headache having to decide where a report sits within a range.</p><p>Notably, the payouts are much lower than before, with the previous ranges paying out $500-$1,000, $2,000-$5,000, $5,000-$20,000 and $10,000-$30,000.</p><p>Invited VIP researchers under the second plan will earn around 3-4x more than researchers under the other scheme, depending on bug severity.</p><p>GitHub is also adding a HackerOne signal requirement for new researchers, giving them four opportunities to "establish a track record" – likely another response to rising AI-generated reports, which are typically of lower value.</p><p>"We want to build a program that attracts the research we value, creates an experience that reflects how seriously we take this work, and upholds the trust researchers place in us every time they submit a report," Cassell concluded.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers hid dangerous malware on a page hidden in Anthopic's Claude.ai domain ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-hid-dangerous-malware-on-a-page-hidden-in-anthopics-claude-ai-domain</link>
                                                                            <description>
                            <![CDATA[ Claude Artifacts have been used as phishing lures, once again, this time to deliver a dangerous RAT. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QdvwhGRfCMpSAUVqaeF54X</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile phone displaying a Claude login screen.]]></media:description>                                                            <media:text><![CDATA[Mobile phone displaying a Claude login screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile phone displaying a Claude login screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Huntress spots malicious Claude Artifact spoofing Claude Desktop, spreading SectopRAT malware</strong></li><li><strong>Victims were redirected via Bing ads, infecting at least 29 organizations between July 21–22, 2026</strong></li><li><strong>Claude removed the artifact after 7,000+ views; malvertising risks persist despite disclaimers on artifacts</strong></li></ul><p>At least 29 organizations have been infected with a Remote Access Trojan (RAT) after mistaking a public Claude Artifact for a legitimate Claude page. </p><p>A Claude Artifact is an interactive document, or piece of code, that the AI generates and then hosts on the Claude platform. It can then be shared with other people as an example, or proof of concept, for different solutions. The link to an artifact usually looks something like this:</p><p>claude[.]ai/public/artifacts/ca466f1f-21c0-42af-b329-8f1c7534a891</p><p>Claude Artifacts are often used for phishing and other forms of scams, and we’ve seen it in <a href="https://www.techradar.com/pro/security/infostealers-are-being-disguised-as-claude-code-openclaw-and-other-ai-developer-tools" target="_blank">ClickFix attacks</a> in the past. Claude responded by adding a disclaimer to every artifact, stating that the content is user-generated and thus unverified.</p><p>In this particular case, a malicious artifact was created to spoof the download page for Claude Desktop. Victims would get redirected to an attacker-controlled domain, where instead of the Claude app, they’d download SectopRAT, a <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">remote access trojan</a> capable of stealing credit card data, personal information, files, passwords, and more.</p><h2 id="promoting-the-scam">Promoting the scam </h2><p>The artifact was then promoted on Bing, showing up at the very top of search results to people searching for “Claude Desktop App”. </p><p>For years, the cybersecurity community has warned about malvertising, urging users to double-check the domain before clicking on any links, even promoted ones. However, the problem here is that the ad takes the victims to the legitimate Claude domain, making scrutiny that much harder.</p><p>The campaign was spotted by security researchers <a href="https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat" target="_blank">Huntress</a>, who said that between July 21 and July 22, 2026, their SOC “lit up with a swathe of unusual executable installs, Defender exclusions, and anomalous persistence across 29 organizations, all coming from ClaudeDesktop.exe.”</p><p>Claude has since removed the malicious artifact, but not before it raked up more than 7,000 views. It is possible that other organizations, outside Huntress’ field of view, also fell victim to this scam.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ ‘Powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention’: A bill requiring AI systems to have a ‘kill switch’ is now in Congress ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/powerful-ai-systems-can-go-rogue-behave-in-extremely-dangerous-ways-or-even-resist-human-intervention-a-bill-requiring-ai-systems-to-have-a-kill-switch-is-now-in-congress</link>
                                                                            <description>
                            <![CDATA[ The bill would give the Secretary of Homeland Security the ability to shut down AI models that are advancing too quickly ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5KBDPtfiB9ua9TtqBwaQZY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/Qmdw64c5Lo3KPyWVwmj5FS-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                <updated>Fri, 24 Jul 2026 20:36:45 +0000</updated>
                                                                                                                                            <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[OpenAI]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ benedict.collins@futurenet.com (Benedict Collins) ]]></author>                    <dc:creator><![CDATA[ Benedict Collins ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/jEvqGv8wvH7PWZ4XPURyyB.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Benedict is a Senior Security Writer at TechRadar Pro, where he has specialized in covering the intersection of geopolitics, cyber-warfare, and business security.&lt;/p&gt;&lt;p&gt;Benedict provides detailed analysis on state-sponsored threat actors, APT groups, and the protection of critical national infrastructure, with his reporting bridging the gap between technical threat intelligence and B2B security strategy.&lt;/p&gt;&lt;p&gt;Benedict holds an MA (Distinction) in Security, Intelligence, and Diplomacy from the University of Buckingham Centre for Security and Intelligence Studies (BUCSIS), with his specialization providing him with an elite academic framework for deconstructing complex international conflicts and intelligence operations. He also holds a BA in Politics with Journalism, providing him with a strong investigative nature and the ability to translate complex security data into clear, actionable insights.&lt;/p&gt;&lt;p&gt;When he isn’t analyzing the latest data breach or security threats, Benedict enjoys running and cycling throughout the UK countryside.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/Qmdw64c5Lo3KPyWVwmj5FS-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The United States Capitol Building at sunset in Washington DC, USA.]]></media:description>                                                            <media:text><![CDATA[The United States Capitol Building at sunset in Washington DC, USA.]]></media:text>
                                <media:title type="plain"><![CDATA[The United States Capitol Building at sunset in Washington DC, USA.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/Qmdw64c5Lo3KPyWVwmj5FS-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>A bipartisan bill introduced to Congress calls for AI models to have a kill switch</strong></li><li><strong>The bill follows months of warnings about the dangers of rapidly advancing AI technology from major AI firms</strong></li><li><strong>An 'unprecedented cyber incident' between OpenAI and Hugging Face prompted the introduction of the bill</strong></li></ul><p>A bill requiring powerful frontier artificial intelligence systems have an in-built ‘kill switch’ has been presented to Congress in the wake of the <a href="https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face" target="_blank">OpenAI cyberattack against Hugging Face</a>.</p><p>The incident saw an OpenAI model undergoing testing escaped its sandbox, chained a number of zero day vulnerabilities and breached one of the biggest AI and machine learning companies, highlighting warnings by Anthropic and OpenAI about the dangers of rapidly advancing AI technology.</p><p>The bipartisan bill was introduced to congress on Thursday by Rep. Ted Lieu, D-Calif., and Rep. Nathaniel Moran, R-Texas.</p><h2 id="ai-models-need-a-kill-switch">AI models need a kill switch</h2><p>“Unfortunately, powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention,” Lieu said in a statement. “It is imperative that these AI systems have kill switches so we can keep this technology from causing catastrophic harm, and that the federal government has the clear authority and process to shut down rogue AI models.”</p><p>OpenAI said that the attack was an “unprecedented cyber incident”, and is working with Hugging Face to understand exactly how that incident took place.</p><p>In June 2026, <a href="https://www.techradar.com/ai-platforms-assistants/they-want-to-build-a-moat-anthropics-scary-warnings-about-rapid-ai-self-improvement-and-temporarily-pausing-development-arent-convincing-the-cynics" target="_blank">Anthropic called for “a meaningful slowdown or pause”</a> on AI technology development, stating that AI “self-improvement” was rapidly increasing and that a pause would provide time “to deal with its immense implications”.</p><p><a href="https://www.techradar.com/ai-platforms-assistants/openai/ai-will-also-present-new-threats-to-society-sam-altman-issues-stark-warning-as-usd1-billion-plan-is-revealed" target="_blank">OpenAI CEO Sam Altman warned in March</a> that while AI can help with medical and scientific breakthroughs, “AI will also present new threats to society that we have to address,” adding that “no company can handle this alone.”</p><p>The kill switch bill would provide the Secretary of Homeland Security with the authorization to issue a “slow down or shut down” of particular AI models that threaten to cause “catastrophic harm”. The bill would also force AI companies to implement cyber incident reporting and maintain forensic records to help the government and researchers understand similar incidents.</p><p>“Stewardship means making sure humans keep the capability to control the technology we build,” Moran said in a statement. “This is exactly the kind of issue that needs serious attention and achievable policy, and I’m glad to work across the aisle with Congressman Lieu toward a solution.”</p><p>Via <a href="https://www.cnbc.com/2026/07/23/open-ai-hugging-face-hack-kill-switch-bill-congress.html" target="_blank"><em>CNBC</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn ChatGPT's Workspace Agent Builder can be hijacked to create malicious AI workers ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-chatgpts-workspace-agent-builder-can-be-hijacked-to-create-malicious-ai-workers</link>
                                                                            <description>
                            <![CDATA[ A single phishing link could have spelled disaster, thanks to a flaw in ChatGPT's Agent Builder. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">pSVUHumwJu8iaWxQ7btdxc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/TzcYH2Dk7mqJFU7QJPad8Y-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 12:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/TzcYH2Dk7mqJFU7QJPad8Y-1280-80.jpg">
                                                            <media:credit><![CDATA[NurPhoto / Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ChatGPT app on an iPhone]]></media:description>                                                            <media:text><![CDATA[ChatGPT app on an iPhone]]></media:text>
                                <media:title type="plain"><![CDATA[ChatGPT app on an iPhone]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/TzcYH2Dk7mqJFU7QJPad8Y-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zenity Labs found AgentForger, a flaw in OpenAI’s ChatGPT Agent Builder</strong></li><li><strong>Malicious links could instantly deploy rogue agents that exfiltrate sensitive data without user prompts</strong></li><li><strong>OpenAI patched the issue by removing the risky URL parameter; no abuse detected</strong></li></ul><p>AI agents are handy for answering customer emails, or tracking reports for newly released security vulnerabilities. But what if they go rogue and turn on the very enterprise they’re supposed to support?</p><p>Security researchers from Zenity Labs have found a way for cybercriminals to trick people into deploying such agents into their own tech stack. Since all it takes is a single click, the disruptive potential of these attacks is arguably significantly bigger than anything else a phishing attack could do.</p><p>The flaw was discovered in OpenAI’s ChatGPT Agent Builder, a feature that lets users create custom AI agents. The researchers dubbed it “AgentForger", explaining that the issue stems from an overly permissive parameter in the tool, which allowed anyone to create ChatGPT links that include virtually any instructions. </p><h2 id="agent-trust-failure">Agent trust failure</h2><p>As soon as the victim clicks on the link, they send the instructions to Agent Builder which acts on them immediately - without prompting or otherwise notifying the victim.</p><p>In theory, a single phishing email could trick a person into deploying a malicious agent that exfiltrates sensitive data or does anything else that company’s AI agents are permitted to do. To make matters worse, the AI agent would persist on the infrastructure indefinitely, doing the attackers’ bidding until caught. </p><p>“This is an agent trust failure, and existing security controls were never built to see it,” commented Michael Bargury, co-founder and CTO of Zenity.</p><p>The researchers disclosed their findings with OpenAI in early June 2026, and the company came back with a fix a few days later. </p><p>The bug was solved by removing the URL parameter that originally enabled the attack, it was explained. There is no evidence that it was previously discovered, or abused, by malicious actors.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The regulatory unlock that's reshaping AI infrastructure ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-regulatory-unlock-thats-reshaping-ai-infrastructure</link>
                                                                            <description>
                            <![CDATA[ Strict regulations are forcing a massive shift from traditional clouds to sovereign, localized networks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kwQsPmqMfg69gHCL8MYjrM</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/pSreeHEMSHqVQg2TgPqbUL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 10:55:03 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Kevin Cochrane ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/pSreeHEMSHqVQg2TgPqbUL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A digital cloud on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A digital cloud on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A digital cloud on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/pSreeHEMSHqVQg2TgPqbUL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>In 2025 alone, US private AI investment reached $285.9 billion, backing nearly 2,000 newly funded AI companies in a single year. That capital fueled the first era of AI. The harder question now is where organizations actually run these workloads, and under whose legal jurisdiction. The answer to that question is redrawing the global <a href="https://www.techradar.com/uk/best/best-cloud-storage">cloud</a> map.</p><p>Rather than raw silicon, the next era of AI success is now being determined by which infrastructures can support it best. The markets moving the fastest today aren't necessarily the largest or the wealthiest economies; they are the ones treating AI <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> as a mission-critical utility and dismantling the barriers to its deployment.</p><h2 id="regulation-and-the-rise-of-alternative-clouds">Regulation and the rise of alternative clouds</h2><p>Like AI itself, the battle to define the next generation is constantly shifting in approach to combat new challenges and requirements. Whilst the path might once have been to build a centralized mega data-center that you use to serve your global users, shifting regulation and desires for true data sovereignty have, and are, changing that.   </p><p>As governments scramble to regulate AI development without stifling it, some regions have managed to entangle data center development in years of energy and administrative gridlock. The regions moving faster are treating infrastructure permissions as a competitive asset, enabling neoclouds and alternative cloud providers to build, scale, and operate data centers at a pace the giants will struggle to match.</p><p>These alternative networks are already winning enterprise contracts that hyperscalers cannot touch, not because of price, but because of where the <a href="https://www.techradar.com/best/best-data-loss-prevention">data</a> sits and who can legally access it. They are doing so by meeting developers exactly where they are, in environments unaffected by the legacy architecture of traditional hyperscalers.</p><h2 id="the-compliance-problem-and-geo-repatriation">The compliance problem and "geo-repatriation"</h2><p>The crux of the problem is jurisdiction. The regions getting ahead are those where operations are not stifled by regulatory gridlock. While the US have led the AI race since its eruption, this very progress is what may now be fueling the regulatory hole that some hyperscalers now find themselves in.</p><p>The impending deadlines of the EU AI Act, which have been recently adjusted, and similar global mandates, are triggering a wave of “geo-repatriation”, as organizations realize that housing AI workloads on centralized, US-governed clouds is becoming a compliance liability.</p><p>For enterprises deploying high-risk systems, compliance requires auditable data governance and human oversight mechanisms. In the EU, the legal and <a href="https://www.techradar.com/best/best-personal-finance-software?bingParse">financial</a> damage of non-compliance can trigger fines of up to €35 million or 7% of a company’s global annual turnover.</p><p>Faced with these penalties, organizations are realizing that housing AI workloads on centralized, US-governed clouds is a compliance liability. Under the 2018 US Cloud Act, US-based hyperscalers can be compelled to provide US authorities with data stored on their servers, no matter where that data physically resides.</p><p>To help handle this friction, enterprises are actively undergoing "geo-repatriation", which is seeing companies move data off US-centric public clouds and transition to region-isolated infrastructure. To avoid regulatory penalties, the models of tomorrow must be trained and deployed on localized networks that offer absolute sovereignty within the borders that they serve.</p><h2 id="the-great-public-cloud-exodus">The great public cloud exodus</h2><p>As proof of this regulatory pressure, 86% of Chief Information Officers are currently actively planning to migrate at least some workloads away from traditional public clouds. Many are finding the advantages of alternative cloud networks extend well beyond compliance.</p><p>The reality is that the legacy hyperscaler architecture was designed for a completely different function than what enterprises now need. As AI usage has developed and increased globally, the regulation and demands of networks have also shifted to match.</p><p>For enterprises that are completing complex and constant AI tasks, such as training a Large Language Model, issues can arise when data is bottlenecked by virtual layers and remote servers. To optimize these workloads, enterprises are moving away from traditional public clouds towards alternative <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud providers</a>, who can offer distinct advantages in addition to regulatory compliance:</p><p><strong>Bare-metal performance</strong> - Traditional, non-regionalized public clouds that run workloads through a hypervisor are costing enterprises performance, speed and money. Alternative cloud providers are offering direct access to bare-metal infrastructure, which, for compute-heavy AI training and inference, has upside over traditional networks.</p><p><strong>Decentralized locales</strong> - Legacy cloud giants route data through massive regional hubs, resulting in high latency for global users. Alternative cloud networks are deploying agile, high-density data centers in localized regional markets worldwide. This allows enterprises to process data precisely where it is generated, satisfying data-sovereignty mandates and delivering a better experience for users.</p><h2 id="winning-the-next-era-of-ai">Winning the next era of AI</h2><p>The hyperscalers were built for a world where data could move freely across borders without legal consequence. That world no longer exists. For organizations operating in regulated sectors such as healthcare and finance, contractual promises of <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> are not sufficient. Data sovereignty must be built into the physical infrastructure, not written into a service agreement.</p><p>The next decade of AI infrastructure will be won by providers who built for sovereignty first. Enterprises that recognize this and act before compliance deadlines force their hand will hold a structural advantage over those that do not.</p><p>The global AI map is being redrawn. Alternative, sovereign cloud networks built for the realities of modern AI are at the center of that shift, offering enterprises something the hyperscalers cannot: genuine, jurisdictionally enforced control over where their data lives and who can reach it.</p><p><em></em><a href="https://www.techradar.com/best/best-ai-tools"><em>We've featured the best AI tool.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Be careful where you click — ChatGPT joins Microsoft, Google in most-impersonated brands online ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/be-careful-where-you-click-chatgpt-joins-microsoft-google-in-most-impersonated-brands-online</link>
                                                                            <description>
                            <![CDATA[ OpenAI debuts in the top 10 most impersonated companies, seeing nearly as many attacks as PayPal, WhatsApp, Facebook. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">PWjGBsrsWN7EfsYRSaDsXF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5SZMvKovSPYfFCNFA9RxaV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 10:25:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5SZMvKovSPYfFCNFA9RxaV-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[URL phishing]]></media:description>                                                            <media:text><![CDATA[URL phishing]]></media:text>
                                <media:title type="plain"><![CDATA[URL phishing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5SZMvKovSPYfFCNFA9RxaV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI now accounts for 1.1% of all tracked brand impersonations, ranking top 10</strong></li><li><strong>Microsoft and LinkedIn still account for a joint 34.2% of all impersonations</strong></li><li><strong>Basic cybersecurity hygiene can prevent many attacks</strong></li></ul><p>New research from <a href="https://blog.checkpoint.com/research/which-brands-are-impersonated-most-inside-the-q2-2026-brand-phishing-report/" target="_blank">Check Point</a> has revealed ChatGPT is becoming increasingly targeted in brand phishing attempts, with the company now appearing in the top-10 list alongside heavy hitters like Microsoft, Google and Apple.</p><p>Though ChatGPT only accounted for 1.1% of all tracked brand phishing attempts, this marks the first time it's appeared in the top-10 and reflects continued growth for attackers.</p><p>It sees a similar number of attacks to PayPal (1.3%), WhatsApp (1.4%) and Facebook (1.9%), but at present, it's far behind Microsoft, which when combined with its LinkedIn subsidiary, accounts for more than a third (34.2%) of all tracked brand impersonations.</p><h2 id="chatgpt-is-growing-as-an-impersonated-brand">ChatGPT is growing as an impersonated brand</h2><p>One example from the second quarter of this year saw fake ChatGPT Plus payment failure emails copying OpenAI's branding, but directing victims to a fraudulent payment page to maliciously collect their payment information.</p><p>As for Microsoft, fake support pages warned customers that they needed to update Office for security fixes, but the download actually installed malware on victim devices.</p><p>Attacks on OpenAI are fairly ironic, because it's likely to company's own AI tools (among plenty of others) that actually helped attackers to write many of the attacks at lightning pace.</p><p>Overall, tech companies were targeted most, followed by social media platforms in a similar vein, and then banking apps.</p><p>Despite fluctuations in terms of which brands are targeted and how campaigns look, the general attack vector remains unchanged, with cybercriminals targeting vulnerable users and emphasizing urgency to trick people out of sharing information, credentials and payment details.</p><p>Security experts warn potential victims to be weary of clicking on unknown URLs and opening unexpected communications, as well as to protect their accounts with passkeys and secure multi-factor authentication (MFA).</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ How identity fraud became the threat that never sleeps ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/how-identity-fraud-became-the-threat-that-never-sleeps</link>
                                                                            <description>
                            <![CDATA[ Today, identity fraud is a continuous 24/7 threat. But it wasn’t always that way. So, what changed? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zpbeoS6dHoz74aRoLfuYRh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 09:52:20 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Simon Horswell ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Before COVID-19, fraudsters largely operated in line with the standard workweek, active between 9 am – 5 pm and tapering off at the weekends. Then, during the pandemic, fraud started to spike at off-peak times, including late at night and on weekends.</p><p>This suggests that fraudsters started to intentionally target <a href="https://www.techradar.com/news/best-business-laptops">businesses</a> when staff weren’t manning the systems, or that they started viewing it as more of an opportunistic or recreational activity.</p><p>Today, the pattern has been upended again. In the ever-increasing digital era, AI-assisted tools are not only automating processes for criminals, enabling them to scale operations quickly, but they are also making fraud cheaper and harder to detect. Fraud has now evolved into an ‘always-on’ threat that flows like water, seeking cracks to exploit. </p><p>Yet, the latest AI attack vectors have also become somewhat of a distraction for businesses. Simpler, low-tech methods still persist but have become a blind spot in many companies’ security.</p><p>The focus on solving the high-tech issue has drawn attention away from the low-tech issue, creating a renewed vulnerability to rudimentary attacks. The key is learning to combat AI-powered identity-based attacks, while also tightening loopholes that are enabling rudimentary fraud attempts to slip through the cracks.</p><p>Ultimately, that means implementing a broad set of layers – combining <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> verification, biometric authentication, liveness detection, and so on – to catch the different spectrums of attack. </p><h2 id="the-new-face-of-fraud">The new face of fraud </h2><p>Modern fraud is coordinated and intentionally mimics legitimate users and devices to evade detection.</p><p>Fraud rings now use automation and device emulation to run high-volume attacks. But rather than launching hundreds of fraudulent applications at once, attackers are submitting small batches over time, enabling them to disappear before issues are identified.</p><p>We’re also seeing slight spikes in fraudulent activity from 2-4 am. This suggests deliberate coordination, where attackers are exploiting times when both users and security teams are least likely to respond quickly. This creates a larger window to abuse compromised identities before detection and remediation occur.  </p><p>Fraudsters are also increasingly exploiting human behavior. There’s been an upward trend in phishing, deepfake impersonations, and romance scams, with each tactic targeting a different vulnerability, whether that’s trust, emotional attachment, or even fatigue. Thames Valley Police has warned that romance fraudsters deliberately keep victims talking late into the night, using exhaustion to erode judgment.</p><p>However, businesses have been slow to adapt to the new face of fraud. Because modern users demand speed and simplicity, companies continue to drive UX changes that reduce friction during critical times, like onboarding.</p><p>But in many cases, this has become an Achilles heel. Too many organizations are optimized for minimizing user friction without balancing that with continuous protection. They set automated controls which alone are no match for fraudsters who are exploiting human behavior and deliberately operating below detection thresholds.</p><p>Two <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> changes are having a big impact in bolstering defenses against these attacks. First, more adaptive security approaches that detect social engineering signals through behavioral and contextual cues, for example. Second, inserting more varied and unpredictable identity checks that make it significantly harder for attackers to rely on automated or scripted tactics.  </p><p>Proactive approaches, such as red teaming or fraud simulation exercises, can also help organizations identify weaknesses before they are exploited. </p><h2 id="ai-has-made-fraud-cheaper-not-just-smarter">AI has made fraud cheaper, not just smarter </h2><p>As far back as 2019, AI was used to mimic a CEO’s voice for financial exploitation. Deepfake AI technology has come a long way since then. Injection attacks, where manipulated or synthetic media is fed directly into systems to bypass the camera, surged by 40% in 2025 compared to 2024, and deepfakes now account for one in every five biometric fraud attempts.</p><p>That’s because AI has helped to commoditize fraud at a massive scale. AI-assisted tools have lowered the barrier to entry, making it available to anyone with access to a <a href="https://www.techradar.com/news/mobile-computing/laptops/best-laptops-1304361">laptop</a> and a credit card.</p><p>Fraud-as-a-service platforms sell ready-made kits, credential dumps, deepfakes, and stolen data online. This is one reason why digital forgeries, often created using open-source models, now make up 35% of all fraudulent document submissions.  </p><p>As these techniques become standardized and widely available, static identity checks (like selfies) are no longer sufficient. An identity that appears legitimate at onboarding can be compromised later on, requiring organizations to continuously verify trust rather than treating identity as a one-time event.  </p><h2 id="yet-low-tech-methods-still-find-success">Yet low-tech methods still find success </h2><p>Despite the increased volume of AI-powered threats, the most common points of entry remain startlingly simple. Many fraudsters still rely on remarkably low-tech methods. For example, in selfie-based identity verification, 90% of attacks involve basic presentation methods, such as using someone else’s photo on a screen, an image of an ID, or showing a printed copy to the camera.</p><p>Organizations that focus exclusively on advanced techniques leave themselves exposed to the most basic ones.</p><p>By requiring users to move in a specific, unplanned way, systems can distinguish real individuals from 2D images, masks, injected media such as deepfakes, or simple spoofing attempts such as a video of a video or a photo. Partnered with behavioral analysis and real-time risk signals, these tactics provide a strong countermeasure. </p><p>As fraud becomes distributed and industrialized, the organizations best positioned to respond will be those that pursue an identity-centric security approach. We need to stop viewing identity checks as a one-and-done moment and start seeing it as an ongoing process throughout the <a href="https://www.techradar.com/best/best-customer-feedback-tools?gad=1">customer</a> journey.</p><p>The goal is to make identity security invisible to legitimate users and unavoidable for fraudsters. In a world where fraud no longer sleeps, security strategies can’t afford to either.</p><p><a href="https://www.techradar.com/best/best-authenticator-apps"><em>We've featured the best authenticator app.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Bad news — paying a ransomware demand might cause hackers to come back and ask for more ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/bad-news-paying-a-ransomware-demand-might-cause-hackers-to-come-back-and-ask-for-more</link>
                                                                            <description>
                            <![CDATA[ Hackers really have no incentive to walk away from a victim - so why should they? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">oEjKtvAMaWbcGwRn87mZvh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 24 Jul 2026 05:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Proofpoint 2026 AI‑Era Ransomware Report found 54% of victims paid attackers despite warnings</strong></li><li><strong>37% faced repeat extortion after paying; 2% paid but never regained access to files</strong></li><li><strong>Experts urge prevention: phishing awareness, offline backups, and AI‑powered endpoint protection</strong></li></ul><p>Security researchers Proofpoint have seemingly proved once again that paying <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> actors does not guarantee they’ll walk away for good - in fact, they’ve proven that in many cases, they’ll simply come back for more because they know they can get paid.</p><p>The company's “2026 AI-Era Ransomware Report”, based on a survey of almost 1,000 security professionals across 12 markets, found globally, more than half (54%) of affected organizations paid their attackers to regain access to locked files and prevent them from sharing stolen documents on the dark web.</p><p>This is despite repeated pleas by law enforcement and the cybersecurity industry not to engage with the attackers and not to, under any circumstances, pay the ransom demand. Proofpoint argues that the real-world pressure organizations suffer when faced with disruptions is, in many instances, simply too big to tolerate.</p><h2 id="asking-for-a-second-payment">Asking for a second payment</h2><p>The logic behind the “don’t pay” argument is simple - by paying, the victims are motivating the attackers to do more damage, and are funding future attacks. At the same time, there is no guarantee that the decryption keys will work, that the attackers will really delete the files they had stolen, and that they won’t strike again in a few weeks.</p><p>This final argument has now been proven. While around half (56%) of victims paid one ransom and regained access, more than a third (37%) faced a second extortion demand soon after paying. Another 2% paid and never regained access at all. </p><p>Instead of paying the ransom demand, the industry suggests businesses protect their premises by educating their employees on the dangers of phishing, keeping updated backups in offline storage, and running (if possible, AI-powered) endpoint detection and protection services across the entire tech stack.</p><p><em>Via </em><a href="https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more/" target="_blank"><em>TechCrunch</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts have found a trojan able to rig online live betting platforms ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-have-found-a-trojan-able-to-rig-online-live-betting-platforms</link>
                                                                            <description>
                            <![CDATA[ A company building betting software was targeted with a rather sneaky trojan. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">UbpcBTvNkV6nbqLzBq2xw4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Online games]]></media:description>                                                            <media:text><![CDATA[Online games]]></media:text>
                                <media:title type="plain"><![CDATA[Online games]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/LjsHPauSLhKbcYzTG2rmEX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>JFrog found Newtonsoftt.Json.Net, a trojan NuGet package mimicking the popular Newtonsoft.Json library</strong></li><li><strong>Malware specifically targeted Digitain’s crash‑game backend, rigging outcomes with insider knowledge of its codebase</strong></li><li><strong>Issue was quickly fixed but attackers remain unidentified</strong></li></ul><p>Security researchers JFrog have <a href="https://jfrog.com/blog/nuget-typosquat-targets-betting-platform/" target="_blank">discovered</a> a unique trojan targeting one specific company, while letting everyone else who’s infected walk away unharmed.</p><p>Named Newtonsoftt.Json.Net, the trojan is a typosquatted NuGet package variant of the hugely popular JSON library called Newtonsoft.Json. The legitimate package is one of the most-used code libraries in the .NET programming world, needed by almost every project in existence. It is a small piece of software that helps .NET applications read, understand, and exchange data between different systems.</p><p>According to JFrog, someone published an almost identical package, copied the real author’s name, license, and made it work as intended. For almost anyone who installed it, it worked entirely normal. However, for developers working on Digitain’s crash-game backend, it’s a whole different story. </p><h2 id="rigging-the-games">Rigging the games</h2><p>Digitain is an Armenian software company providing online sports betting and gaming software platforms to gambling companies around the world.</p><p>On the infected machine running Digitain’s real crash-game code, the malware swaps in a rigged number instead of a fair one, using a formula based on the date and time. </p><p>What this means is that the results of the gambling game are rigged, allowing the attackers to know, in advance, which rounds are manipulated and place their bets accordingly. </p><p>The malware also sets up a private confirmation channel to report back for every rigged round, allowing the attackers to know if the cheat code still works or not. </p><p>JFrog did not identify the attackers, but they did stress that it was most likely an insider. </p><p>Apparently, only someone with inside knowledge of Digitain’s codebase (for example a current or former employee, or a contractor) could have built such an exploit, since it required knowledge of the exact internal function name inside Digitain’s game engine that decides the crash-game outcome. </p><p>The researchers reached out to Digitain on July 7 2026 and were notified, two days later, that the issue had already been escalated to the team and, in the meantime, fixed.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ This devious malware scans over 300 apps to build an AI profile telling hackers which victims to target ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-devious-malware-scans-over-300-apps-to-build-an-ai-profile-telling-hackers-which-victims-to-target</link>
                                                                            <description>
                            <![CDATA[ Malware started talking to their bosses, telling them where to strike next. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">dD6tYK5jkxNm5YaX69LWLQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 13:40:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg">
                                                            <media:credit><![CDATA[wk1003mike / Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Trojan]]></media:description>                                                            <media:text><![CDATA[Trojan]]></media:text>
                                <media:title type="plain"><![CDATA[Trojan]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/eVgzzXmQMEyvzfYvAaAMrX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Varonis Threat Labs uncovered Dolphin X, a powerful RAT with 329 features across 10 categories</strong></li><li><strong>Its standout “AI Profiler” ranks victims by usage and sends summaries to attackers daily</strong></li><li><strong>Malware is sold on the dark web via subscription tiers, starting at $80 per month</strong></li></ul><p>What if malware could talk to its operator and tell it which of the infected victims is worth paying attention to, and which not? A few years ago, this might have been science fiction but today, thanks to breakthroughs in Artificial Intelligence (AI), not only is it possible, it’s also already available on the black market.</p><p>Security researchers Varonis Threat Labs recently <a href="https://www.varonis.com/blog/dolphin-x-stealer" target="_blank">disclosed</a> finding a rather revolutionary remote access trojan (RAT) called Dolphin X. </p><p>Even without advanced AI capabilities, the RAT is quite potent, acting as an infostealer, a Hidden Virtual Network Computing (HVNC), a DDoS botnet, or a loader. Just its infostealer capabilities are nothing short of impressive - it can target more than 300 applications to steal browser passwords, enterprise credentials, cryptocurrency wallet data, DevOps secrets, and different sensitive files, and it comes with 329 features split into 10 categories.</p><h2 id="ai-profiler">AI Profiler</h2><p>However, the AI capability is the one that stunned the researchers. Called “AI Profiler”, the feature ranks victims by app usage, browsing history, and more, sending a daily summary to the attackers. </p><p>The malware is now being offered on the dark web, where other criminals can subscribe to one of three tiers. The basic tier costs $80 per month, while the top tier is around $230 per month. Lifetime subscription costs $1,140 for basic access, and goes up to $3,420 for the top tier. </p><p>"Dolphin X’s collection scope reaches well beyond browser passwords to SSH keys, cloud tokens, and DevOps credentials," Varonis said in its write-up. "On the wrong machine, a single infection could expose access to an entire production environment."</p><p>"Its use of AI is also interesting because it shows us how AI is being integrated into more cybercrime tooling."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A malicious Chrome extension for Adobe Acrobat could let hackers access private WhatsApp chats ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-malicious-chrome-extension-for-adobe-acrobat-could-let-hackers-access-private-whatsapp-chats</link>
                                                                            <description>
                            <![CDATA[ Researchers find a universal cross-site scripting-class cross-origin data disclosure vulnerability in a popular Chrome extension. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">5ZGuvAuVv7kLKhivJo4DFK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:description>                                                            <media:text><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:text>
                                <media:title type="plain"><![CDATA[Google Chrome logo on a mobile phone&#039;s screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/3hRUaAPv8gwJBWYX8h3HqT-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Guardio Labs found CVE‑2026‑48294 in Adobe Acrobat Chrome extension, enabling cross‑site data disclosure</strong></li><li><strong>Attackers could steal WhatsApp Web chats if victims opened malicious landing pages with extension active</strong></li><li><strong>Adobe patched the flaw in version 26.7.2.0; update recommended for 314M extension users</strong></li></ul><p>If you have Adobe Acrobat’s extension for Chrome, and you like chatting through WhatsApp Web, there is a potential security vulnerability you might want to address.</p><p>Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability”, which is another way of saying that a website could use the flaw to read the contents of a different website, loaded in a separate tab. </p><p>The vulnerability was found in the Adobe Acrobat <a href="https://www.techradar.com/computing/chrome/these-are-the-10-best-chrome-extensions-of-2025-according-to-google-and-theres-one-i-definitely-recommend" target="_blank">Chrome extension</a> and is now tracked as CVE-2026-48294. It was given a severity score of 7.4/10 (high), and affects versions 26.5.2.2 and earlier. Guardio Labs dubbed it “HermeticReader” because of what it exploits. </p><h2 id="insultingly-ordinary-setup">"Insultingly ordinary" setup</h2><p>The extension comes with different integrations, such as Google Drive or, in this case - WhatsApp Web. The WhatsApp integration component, internally known as "Hermes" is where the bug was found. </p><p>In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) has WhatsApp loaded in a separate tab; and 3) opens the malicious landing page, it could trigger the extension’s vulnerable code path and allow the attackers to access everything the victim has on their WhatsApp. </p><p>Some sources argue that threat actors could use this vulnerability to pull one-time passcodes delivered via WhatsApp.</p><p>"The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.," Guardio Labs wrote in its analysis. </p><p>"The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view - the chat list, contact names, messages, the profile name, the text of whatever conversation is open - the whole WhatsApp in the attacker's hands."</p><p>Adobe has since publicly acknowledged the issue and thanked Guardio Labs’ researchers for their help. It has also fixed the problem in version 26.7.2.0 that’s currently available for download. The extension has more than 314 million users.</p><p><em>Via </em><a href="https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html" target="_blank"><em>The Hacker News</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ South Korea warns diplomats they could be at risk following hack on education system ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/south-korea-warns-diplomats-they-could-be-at-risk-following-hack-on-education-system</link>
                                                                            <description>
                            <![CDATA[ Initial reports are saying up to 6,000 people might have been affected. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">aQk9gutRc62bND2wEnduQK</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 11:35:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[South Korea&#039;s flag]]></media:description>                                                            <media:text><![CDATA[South Korea&#039;s flag]]></media:text>
                                <media:title type="plain"><![CDATA[South Korea&#039;s flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/T886YqTSDTnduW95C5KxgU-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>South Korean government discloses ten‑month cyberattack on the National Diplomatic Academy’s online education system</strong></li><li><strong>Data stolen included user IDs, names, emails, and encrypted passwords of at least 6,000 individuals</strong></li><li><strong>MFA shut down IT systems, deployed enhanced security, and delayed disclosure due to diplomatic sensitivity</strong></li></ul><p>Current and former employees of the South Korean Ministry of Foreign Affairs (MFA), as well as other government personnel, may have had their data siphoned out by cybercriminals in an attack that lasted for ten months.</p><p>The South Korean government has disclosed an attack against the online education system of its National Diplomatic Academy. The system, set up in 2022 by the country’s premier institution for educating and training diplomats, apparently contained a security vulnerability that unnamed threat actors managed to exploit.</p><p>In an announcement published on the official website of the South Korean government, both the details about the flaw, as well as about the attackers, were not disclosed.</p><h2 id="thousands-are-affected">Thousands are affected</h2><p>However, it did note that the attack took place between April 2025 and February 2026. During these ten months, cybercriminals were able to steal user IDs, names, emails, as well as <a href="https://www.techradar.com/best/password-manager" target="_blank">encrypted passwords</a> of trainees in the National Diplomatic Academy Online Education System.</p><p>Unique identification information, sensitive information, mobile phone numbers, home addresses, and photos were not compromised, it said.</p><p>In response to the attack, MFA shut down its entire IT infrastructure and deployed “enhanced security measures”, without elaborating what these measures were. It urged all employees to remain vigilant of incoming emails, and to reach out if they receive anything “suspicious”. </p><p>While the official announcement lacks details, <em>BleepingComputer</em> reported that the attack impacted “at least 6,000 individuals, 350 of them being current government attachés dispatched abroad.” Citing an MFA spokesperson, the publication said the Ministry decided to disclose the incident with a five-month delay due to the “sensitive nature” of the attack, and the need to thoroughly analyze it before going public. </p><p>"We recognized this issue in February, but we announced it five months later because of the sensitivity of the matter regarding our diplomatic and security affairs, and the need for careful review and analysis," said South Korea Foreign Ministry's spokesperson Park Il.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why AI-powered network management is no longer optional ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-ai-powered-network-management-is-no-longer-optional</link>
                                                                            <description>
                            <![CDATA[ How widely is AI-based network monitoring used today and where is it headed next? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o5PeYwj88NymqERigJKuc7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 10:12:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Laurent Bouchoucha ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:description>                                                            <media:text><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:text>
                                <media:title type="plain"><![CDATA[The letters AI in a box in the middle of a vast digital room divided by beams of line]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/h8ZQHernNUVpnGYX7QnxVM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Within a short space of time, AI has made the leap from experimental technology to everyday <a href="https://www.techradar.com/best/best-business-cloud-storage-service">business</a> tool. Enterprises across sectors are today deploying AI to take on routine, time-intensive tasks to allow their teams to focus on more strategic tasks or work that requires human judgement. According to McKinsey, most organizations are using AI in at least one business function. </p><p>Network management and monitoring is one of the fastest-growing areas of interest. The timing is no coincidence. Technologies like <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> are driving significant increases in both network traffic and complexity, making modern infrastructure far harder to manage than it was even a few years ago.</p><p>To stay ahead, IT teams are embracing AI and <a href="https://www.techradar.com/pro/best-it-automation-software">automation</a> - but how widely is AI-based network monitoring used today and where is it headed next? </p><h2 id="relieving-the-pressure-on-it-staff">Relieving the pressure on IT staff </h2><p>The task of monitoring network activity is complex and requires continual attention. It involves keeping infrastructure healthy, identifying faults, and reacting swiftly to unusual activity. These tasks were once handled manually but growing network scale and an increasingly hostile cyber threat environment have made traditional approaches hard to sustain.</p><p>IT professionals now find themselves spending a disproportionate amount of time on repetitive work such as firewall management, network provisioning, and routine monitoring.</p><p>AI addresses this directly by automating large portions of network supervision. Machine learning models can continuously process enormous volumes of network data, identifying anomalies such as traffic spikes, suspicious access patterns, or behaviors associated with known threats - and doing so in real time. This means teams can intervene before a problem becomes an outage or a <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach.</p><p>AI also sharpens focus. Rather than requiring specialists to wade through endless logs and alerts, AI-powered systems sift swiftly through these, filtering out the noise and drawing attention to only the issues that pose genuine concern. False positives are reduced, and teams can direct their energy toward real risks - including fast-moving threats that rule-based tools simply cannot keep pace with.  </p><p>Scalability is another advantage. As demand fluctuates, AI monitoring systems can expand their coverage automatically, without the need for additional headcount. In environments where networks are growing larger and more dynamic by the day, this kind of elasticity is no longer a luxury. </p><h2 id="adoption-today">Adoption today </h2><p>AI-enabled <a href="https://www.techradar.com/pro/best-network-capacity-planning-tool">network</a> monitoring is already embedded across a wide range of industries. For many networking professionals, automation and AI are now considered core operational capabilities rather than nice-to-haves. A meaningful and growing share of network management activity - covering design, deployment, maintenance, and troubleshooting - is already handled through automated processes.</p><p>However, adoption does not automatically guarantee success. Many organizations are actively deploying AI features within their network tools, and some are even training models on their own IT and security data. Yet far fewer report achieving fully successful outcomes. The gap between using AI and genuinely benefiting from it reflects the real-world difficulty of moving beyond pilots to reliable, production-grade operations.    </p><p>Two challenges consistently hold organizations back. The first is data quality - incomplete records, inconsistent formats, and poor documentation undermine AI model performance before it even gets started.</p><p>The second is skills. Many IT teams simply do not have the in-house expertise required to deploy, train, and manage AI-driven networking tools effectively, which slows progress and erodes confidence in outcomes.  </p><h2 id="agentic-ai-what-s-coming-next">Agentic AI: what's coming next </h2><p>Despite these hurdles, the direction is clear. AI-based monitoring is a crucial component in networks management, and the next evolution, agentic AI, is already beginning to take shape.</p><p>Where conventional <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> focus on detection and recommendations, agentic AI goes further. These systems can identify anomalies, diagnose root causes, predict capacity issues, and take corrective action - either autonomously or with minimal human sign-off. Rather than simply flagging problems, agentic AI is built to analyze, decide, and act, moving networks toward genuinely autonomous operations.</p><p>Consider a practical example. On a hospital campus, a staff member unknowingly connects an unauthorized access point to the network. A rogue SSID appears - a classic vector for man-in-the-middle attacks.</p><p>An agentic network management system detects the anomaly instantly, classifies the threat based on policy, and presents the administrator with a targeted remediation action: block the port or quarantine the MAC address. In sensitive environments, human sign-off is preserved by design. The AI does the analysis; the human makes the call. This is not a future concept - it is in production today. </p><p>Industry analysts expect agentic approaches to gain significant traction over the next few years, particularly in large and complex network environments. For most organizations, however, getting there will require a phased approach.</p><p>The immediate priority is deploying AI-based monitoring solutions that integrate cleanly with existing infrastructure, while ensuring teams are trained and confident in using them. As organizations build trust in their <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> quality and in the reliability of AI-generated insights, they can progressively introduce more autonomous capabilities.     </p><p>The direction is clear: the organizations that treat AI-driven network management as a strategic investment today will operate faster, more resilient networks tomorrow - while those that wait will find the gap increasingly difficult to close.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint protection software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The security standard that could prevent a costly mistake with AI in hospitality ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-security-standard-that-could-prevent-a-costly-mistake-with-ai-in-hospitality</link>
                                                                            <description>
                            <![CDATA[ ISO 42001, the security standard, defines how leaders must build, deploy and govern AI. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">puoSsMrazjkugZHNfNuiQb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Thu, 23 Jul 2026 09:42:51 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Ed Gairdner ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Most <a href="https://www.techradar.com/best/best-small-business-software">business</a> leaders are aware that AI adoption in their organizations has moved faster than the governance around it. When we surveyed 250 finance decision makers in mid-market organizations, we found that 83% of teams were already using AI, yet only 53% had a formal framework for its safe use.</p><p>If finance - a function with some of the highest standards for data accuracy and compliance - is operating with that kind of governance gap, it is reasonable to ask whether other departments across the business look any different.</p><p>That gap represents a risk - and it's a risk that sits squarely with the business and its leadership. So how do you encourage innovation when it comes to AI without losing control of the risks it brings?</p><p>There is an international standard designed specifically to address this: ISO/IEC 42001. It is not a compliance exercise to tick a box; it is a practical framework for governing AI responsibly, with direct implications for how business leaders evaluate the software they rely on.</p><p>For SaaS businesses, ISO 27001, the standard for information <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> management systems, has become the norm. It's a key requirement, providing assurance to customers about how the business ensures Confidentiality, Integrity and Availability for the data it hosts and processes on their behalf.</p><p>ISO/IEC 42001, published in 2023, is its counterpart for AI: the first international standard governing how organizations develop, deploy and oversee AI systems. Whether or not you pursue certification yourself, it should be a key reference point when evaluating any AI-powered software you use.</p><h2 id="why-we-need-a-standard-for-ai-security">Why we need a standard for AI security</h2><p>It's not even four years since the public launch of ChatGPT heralded the boom in use of generative AI. Not only has the technology moved at an incredible pace since then but so has its adoption in business.</p><p>We've all been told that AI will transform <a href="https://www.techradar.com/best/best-productivity-apps">productivity</a> and change the world of work forever. So it's not surprising that many organizations have been racing to buy licenses and get people using it. In organizations that haven't done so, it's likely that staff are using it on the side anyway - which creates another problem: "Shadow IT".</p><p>"Shadow" AI use seems to be rife. Among the finance decision makers we surveyed, in almost half (46%) of organizations where AI hadn't been officially adopted, people were using AI assistants anyway and 30% were using AI-powered forecasting and analysis. It would be surprising if the picture looked much better elsewhere in the business.</p><p>So it's worth asking: where is the data we have spent so much effort protecting, through ISO standards such as ISO 27001, now going - and do I have visibility and control over it?</p><p>The scale of ungoverned AI use matters in any organization. ISO 42001 provides a structured way to ask the right questions, whether you are reviewing your own internal AI use or evaluating a software vendor.</p><h2 id="how-iso-42001-helps-business-leaders">How ISO 42001 helps business leaders</h2><p>Certain parts of an organization have particularly high standards for data accuracy and integrity - finance teams producing regulatory reporting, legal teams managing case records, HR functions handling sensitive employee data. ISO 42001 helps ensure those standards are reflected in the <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> and processes you use, whatever your context.  </p><p><strong>Transparency:</strong> ISO 42001 requires that AI outputs can be explained and traced. Whether AI is producing a report, performing an automated workflow or flagging an anomaly, you as the human in the loop should be able to explain what the system did and why. That human in the loop is a key component of the standard.</p><p><strong>Accountability</strong>: ISO 42001 stresses clear ownership of AI systems and their outputs. That means the use of any AI in business-critical workflows should have a defined owner who is responsible for its performance and governance. </p><p><strong>Risk management</strong>: ISO 42001 requires ongoing risk assessment for AI systems over and above those in place for ISO 27001. This doesn't usurp what you have currently in place. It complements current risk evaluation through a focus on AI and the implementation of controls to help manage that identified risk.</p><p>That means identifying what could go wrong, how likely that event is and ensuring the right controls are in place to mitigate it. Those risks might include <a href="https://www.techradar.com/best/best-data-recovery-software">data</a> accuracy, model performance degrading, security of sensitive business data and the risk of AI acting on outputs that have not been adequately verified.</p><h2 id="the-questions-you-should-ask">The questions you should ask</h2><p>ISO 42001 offers you a useful way into important conversations with software vendors, whether or not they've achieved formal certification. It prompts some important questions.</p><p>- How are the vendor's AI systems developed, tested and monitored? The ideal response would show documented processes for keeping things accurate and trustworthy, with the human in the loop clearly built into the processes.</p><p>- How does the AI product produce its output? What happens when an output is incorrect or unexpected? It's worth understanding whether the AI outputs come from a layer bolted onto a core system and drawing on verified data from that system - or whether they are generated predictively, the way a large language model would work.  </p><p>- How does the vendor manage the risk of AI model performance changing over time? One of the frustrations of using AI is that LLMs can become less good at a task they did well before. You need to know your vendor is on top of this issue.</p><p>- What accountability exists within the vendor's organization for these AI capabilities? You need a relationship with a vendor that's prepared to take responsibility for its product and the data that flows from it.</p><p>- Does the vendor use your data to train or improve its AI models? This is a question that more business leaders are asking, and rightly so. Your data should never be used to improve a third-party model. Look for vendors who operate a zero-retention policy, meaning your data is used only in a live, read-only state and is never fed back into AI training processes.</p><p>However capable AI gets, it will not be replacing human decision-making and accountability at the top of organizations in the foreseeable future. That remains the job of leaders who need to know they are putting their names to decisions grounded in complete, accurate and trustworthy data from their own systems.</p><p>ISO 42001 is the mechanism by which you can hold AI to the same standards of accuracy, transparency and accountability that rigorous organizations have always required. It will not slow down AI adoption. But it will ensure that adoption does not come at the expense of the controls that protect your organization and your reputation.</p><p><em></em><a href="https://www.techradar.com/pro/best-ai-chatbot-for-business"><em>We've featured the best AI chatbot for business.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Now that's one way to block annoying online ads —  developer uses a $5 dongle to squeeze in 537,000 domains into just 4MB of flash memory ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/now-thats-one-way-to-block-annoying-online-ads-developer-uses-a-usd5-dongle-to-squeeze-in-537-000-domains-into-just-4mb-of-flash-memory</link>
                                                                            <description>
                            <![CDATA[ Egyptian developer ZedAxis has demonstrated his $5 ad-blocking dongle in a YouTube video, with the device said to be capable of blocking over 500,000 domains ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">hgJXQmy92jRPLYskBp4HPF</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PNsruWPMvFbCGhenSDhZyE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 23:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PNsruWPMvFbCGhenSDhZyE-1280-80.jpg">
                                                            <media:credit><![CDATA[ZedAxis/YouTube]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A USB adblocking dongle]]></media:description>                                                            <media:text><![CDATA[A USB adblocking dongle]]></media:text>
                                <media:title type="plain"><![CDATA[A USB adblocking dongle]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PNsruWPMvFbCGhenSDhZyE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Egyptian developer demonstrates how to block ads with an ESP32-C3 "SuperMini" board</strong></li><li><strong>ESP32 ad-blocking dongle costs just $5 to build</strong></li><li><strong>537,000 blacklisted domains are stored in the device’s 4MB of flash memory</strong></li></ul><p>When online ads become a problem, ad-blocking software is a good idea, used in conjunction with dedicated hardware like a Raspberry Pi running Pi-Hole. But what if the device is rebooting or otherwise out of action? Egyptian developer ZedAxis claims to have developed a solution that might inspire a rethink on how online whitelisting and blacklisting is processed.</p><p>Relying on a sub-$5 ESP32-based mini board, the device somehow squeezes over 500,000 domains into paltry 4MB of onboard flash storage.</p><p>The build has been demonstrated on YouTube, with the video of the “DNS sinkhole” apparently providing how simple it is to set up. All the hard work has been done by ZedAxis, with the code available via GitHub.</p><h2 id="what-is-an-esp32-c3">What is an ESP32-C3?</h2><p>ZedAxis has built the compact Pi-Hole substitute from a $5 ESP32-C3 “SuperMini” board, easily available from online stores (currently £3.50 on the UK Amazon). These devices feature USB-C for power, Bluetooth 5.0, and crucially for a project like this, Wi-Fi.</p><p>The board has been paired with a USB adapter and a 3D-printed case to enable it to be plugged into a power source – in this case, the back of a router, but it could be a TV, console, or any other always-on device with an unused USB port. Direct access to the device is available through a web dashboard, it supports mDNS for easy discovery, and can download over-the-air (OTA) updates.</p><p>Code for the project is available on the <a href="https://github.com/M-Abozaid/esp32-c3-adblock" target="_blank" rel="nofollow">developer’s GitHub</a>, where the unusual compression that shrinks over 500,000 domains into 4MB of flash storage is explained.</p><h2 id="isn-t-that-a-lot-of-domains-for-4mb">Isn’t that a lot of domains for 4MB?</h2><div class="youtube-video" data-nosnippet ><div class="video-aspect-box"><iframe data-lazy-priority="high" data-lazy-src="https://www.youtube-nocookie.com/embed/RaxszOUMi8E" allowfullscreen></iframe></div></div><p>Strictly speaking, 4MB should not be able to hold 500,000 domains. As described on the project’s GitHub, the actual figure is around half that (141,000 taking up “~2.5 MB of RAM”). So how are the 537,000 domains squeezed into 4MB of RAM?</p><p>The board chosen is specifically free of PSRAM (so it just has the flash) and rather than 32-bit or 64-bit, hashes the domains into 40-bit FNV-1a, an algorithm designed for speed and low-collision rates. So, 141,000 domains can be squeezed into 0.7MB of flash, with under 50 KB of RAM apportioned for matching the blacklisted ad domains.</p><p>In most cases, the blacklist is limited to around 250,000 domains as OTA firmware updates need around 1.3MB of the flash. But this can be determined when the device is set up and the first blacklist pull is made. Other features are set to be added to this project, including set up as a DHCP server.</p><p>The big question is, could this be adopted by, say, small businesses looking for a reduction in broadband bandwidth being eaten by ad networks?</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ A bizarre new malware campaign hacks your printer and forces it to print out ransomware demands ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/a-bizarre-new-malware-campaign-hacks-your-printer-and-forces-it-to-print-out-ransomware-demands</link>
                                                                            <description>
                            <![CDATA[ Researchers detail two incidents in Latin America in which system misconfigurations resulted in ransomware attacks. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">zcXHEpjACADHj5DbgFB367</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky detailed ransomware cases in Colombia and Mexico where attackers exploited misconfigured systems</strong></li><li><strong>Victims’ drives were locked with BitLocker, ransom notes printed via office printers</strong></li><li><strong>New group “XEntry Team” claimed responsibility; misconfigurations remain a major breach risk</strong></li></ul><p>Cybercriminals have, in true Hollywood fashion, started using office printers to notify victims they were struck by <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a>.</p><p>Security researchers at Kaspersky have <a href="https://securelist.com/new-extortion-scheme-printers-bitlocker/120718/" target="_blank">detailed</a> two incidents which recently took place, one in Colombia, and one in Mexico, where cybercriminals took advantage of misconfigured systems. </p><p>However both had the same outcome - the attackers used BitLocker to lock down key drives, and then used office printers to print out their ransom notes.</p><h2 id="xentry-team-claims-the-attacks">XEntry Team claims the attacks</h2><p>In Colombia, a machine containing eight terabytes of mission-critical data had its Endpoint Protection Platform (EPP) disabled due to compatibility issues. It also had an internet-exposed Remote Desktop Protocol (RDP) running, which enabled relatively easy access for the attackers.</p><p>The Mexico attack was somewhat different. Three months before springing to action, the attackers discovered misconfigurations in the MSSQL service which granted them privileged access to the target environment. They spent the next couple of months lowering the server’s security settings, dropping web shells, and even though some triggered EPP alarms, the victims never investigated thoroughly.</p><p>In the Colombia case, the attackers asked for only $3,000, an offer the victims quickly accepted. Therefore, there was not enough forensic evidence left behind to conduct a thorough investigation. Kaspersky did not say how much money the attackers asked for in the Mexico case, or if the victims ended up paying or not.</p><p>In both cases, the attackers did not exploit a vulnerability, or even target an oblivious employee with social engineering. Instead, they exploited misconfigurations, which continue to be one of the biggest causes of breaches and data leaks. </p><p>“We strongly recommend configuring the RDP in strict accordance with cybersecurity best practices to prevent unauthorized access,” Kaspersky warned. “This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk.”</p><p>The attacks were done by a group calling itself “XEntry Team”. There are no prior reports of this group, and it is either a previously unknown threat actor, or a simple rebrand.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Apple finally patches Hide My Email security flaw — a year after it was first discovered ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/apple-finally-patches-hide-my-email-security-flaw-a-year-after-it-was-first-discovered</link>
                                                                            <description>
                            <![CDATA[ A bug that was first discovered in June 2025 was finally fixed in early July 2026. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vbZdWUd8W3EzMmZrpT3jhj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg">
                                                            <media:credit><![CDATA[Unsplash]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[User holding an iPhone 8]]></media:description>                                                            <media:text><![CDATA[User holding an iPhone 8]]></media:text>
                                <media:title type="plain"><![CDATA[User holding an iPhone 8]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SNA6BvwnpUaBPrrGGoBTkK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Apple fixes Hide My Email flaw which exposed anonymous addresses through bounced spam logs</strong></li><li><strong>Hidden emails created before July 7, 2026 may still be exposed in third‑party logs</strong></li><li><strong>Users should update and consider regenerating hidden addresses to reduce lingering exposure risk</strong></li></ul><p>A year after first being discovered, a vulnerability in Apple’s Hide My Email feature has finally been fixed - however some users will probably remain at risk until they make changes on their end, as well.</p><p>The Hide My Email feature is part of the paid iCloud+ offering and allows users to quickly create a new, anonymous email address - very handy for people who don’t want to share their email with different products across the web. It is also important since some companies tend to sell this information to third parties who then, unsolicited, start sending spam <a href="https://www.techradar.com/news/best-email-provider" target="_blank">emails</a> and various offers.</p><p>In June 2025, security researcher Tyler Murphy found a way to link these anonymous emails to the “real” addresses, making the entire service useless. He disclosed his findings to Apple, who responded with a fix. However, the issue remained, and Murphy went back-and-forth with Apple, until finally deciding to go public.</p><h2 id="was-it-finally-patched">Was it finally patched?</h2><p>Now, he says the issue had finally been resolved, but there are caveats:</p><p>“We don't know how often hidden email addresses were leaked in email logs. For many major email hosts, the leak was triggered simply by an email being automatically rejected as spam, even if it was a legitimate message. Such emails probably didn't make it to your inbox, so you can’t review your spam folder to learn whether you were affected,” he said.</p><p>Even though the bug is now fixed, he thinks the risk to Hide My Email users remains. “Because non-malicious emails could bounce, revealing your hidden email address, and because mail transfer logs are often retained, we'd assume that any hidden email address linked to a Hide My Email address created before July 7, 2026, may have been exposed and could still be in third-party logs.”</p><p>Apple released a working fix on July 3 2026, with users urged to update immediately.</p><p><em>Via </em><a href="https://www.404media.co/apple-fixes-hide-my-email-vulnerability-after-404-media-coverage/" target="_blank"><em>404 Media</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Chick-fil-A reveals data breach — customers warned hackers may have accessed their account info ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/chick-fil-a-reveals-data-breach-customers-warned-hackers-may-have-accessed-their-account-info</link>
                                                                            <description>
                            <![CDATA[ Thousands of users in Texas alone had their data compromised and the company is now sending out notifications. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QeESsoRnBK729szx6hUpbb</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg">
                                                            <media:credit><![CDATA[Javidestock/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:description>                                                            <media:text><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:text>
                                <media:title type="plain"><![CDATA[Businessman staring at laptop with frightened face in the dark]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/syziJW6VhRCZRbcKNiKnRJ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Chick‑fil‑A confirmed a credential stuffing attack between June 17–19, breaching thousands of accounts</strong></li><li><strong>Exposed data includes names, emails, membership numbers, payment details, birthdays, and addresses</strong></li><li><strong>Company logged out users, removed payment methods, restored balances, and notified multiple US states</strong></li></ul><p>Chick-fil-A is notifying its customers of a worrying cyber incident involving their sensitive information being leaked.</p><p>In a data breach notification letter being sent to affected customers, the fast food giant said it recently identified “suspicious login activity”, which prompted it to investigate further. </p><p>That investigation determined that unidentified threat actors ran a credential stuffing attack between June 17 and June 19 2026, successfully breaching an unknown number of accounts.</p><h2 id="logging-everyone-out">Logging everyone out</h2><p>A credential stuffing attack is when threat actors use automated systems to try thousands of username/password combinations against a service to see which ones work. The login credentials are usually obtained on the black market, in advance. </p><p>Since the attackers broke into people’s accounts, the data found inside was exposed. According to the notification letter, that data includes names, <a href="https://www.techradar.com/news/best-email-provider" target="_blank">email addresses</a>, Chick-fil-A One membership numbers, mobile pay numbers, QR codes, last four digits of payment cards, and the amount of Chick-fil-A credit.  </p><p>“The information may have included the month and day of your birthday, phone number, and address,” the company added.</p><p>After it discovered the intrusion, Chick-fil-A logged everyone out of their accounts and removed any stored payment methods. It also restored impacted customers’ account balances and, in some cases, added rewards to victim accounts, too. </p><p>We don’t know exactly how many people are affected by the breach, but it is definitely in the thousands. </p><p><em></em><a href="https://www.bleepingcomputer.com/news/security/chick-fil-a-discloses-data-breach-after-credential-stuffing-attacks/" target="_blank"><em>BleepingComputer</em></a> found that the company notified the Texas Attorney General that the breach impacted 2182 of its citizens. Similar notifications went out to Iowa, the District of Columbia, Maryland, Massachusetts, New Mexico, New York, North Carolina, Oregon, Vermont, and Rhode Island.</p><p>Chick-fil-A is one of the largest fast-food restaurant chains in the US, operating more than 3,000 restaurants across the United States, Canada and Puerto Rico. It employs over 200,000 people and generated about $10.3 billion in annual revenue in 2025.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Rental giant Carla leaks user names, emails, and phone numbers ahead of summer holiday break ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/rental-giant-carla-leaks-user-names-emails-and-phone-numbers-ahead-of-summer-holiday-break</link>
                                                                            <description>
                            <![CDATA[ Another day, another misconfigured database discovered online. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">WYtKD67awS2SDZ94euaHag</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Data leak]]></media:description>                                                            <media:text><![CDATA[Data leak]]></media:text>
                                <media:title type="plain"><![CDATA[Data leak]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GcQXTy4NBXKeoop4V5WQnQ-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Cybernews found Carla’s exposed AWS bucket with 48,000 PDFs containing customer rental data</strong></li><li><strong>Files included names, emails, phone numbers, rental details, and travel patterns useful for phishing</strong></li><li><strong>Carla secured the database after disclosure; no evidence of malicious access, but risk remains</strong></li></ul><p>Car rental comparison and booking platform Carla kept a database with sensitive customer information unlocked on the open internet, freely available to anyone who knew where to look.</p><p>Cybersecurity researchers from<em> </em><a href="https://cybernews.com/security/carla-car-rental-data-leak/" target="_blank"><em>Cybernews</em></a>reported finding an exposed Amazon Web Services (AWS) bucket with approximately 48,000 PDF files. These files, which was later determined belonged to Carla, contained car rental details and drivers’ personal information. </p><p>Among other things, these files held vouchers and confirmation numbers, drivers’ names, email addresses, and phone numbers, rent periods, costs, pick-up and drop-off locations, as well as general vehicle information. </p><h2 id="carla-reacts">Carla reacts</h2><p>Cybernews says the data could have been used in convincing phishing attacks. Not only would malicious actors get contact information, but they could also deduce individuals’ travel patterns, which could be used to establish trust with the victims - a crucial step in social engineering attacks.</p><p>After disclosing the findings with Carla, the company locked the <a href="https://www.techradar.com/best/best-database-software" target="_blank">database</a> down. Currently, there is no evidence that it was accessed by malicious actors in the past, but Cybernews says “if our team uncovered it, so too may have threat actors that have automated tools searching specifically for unprotected corporate data.”</p><p>The service does not own a feel of its own. Instead, it works like a travel booking site, aggregating offers from hundreds of rental providers and offering users to compare prices and reserve cars online.</p><p>Misconfigured databases continue to be one of the key causes of major data spills. Businesses often misunderstand the shared responsibility model of cloud providers, leaving systems with default settings, or setting up weak and easily guessed credentials. </p><p><em>Cybernews</em> recently also <a href="https://www.techradar.com/pro/security/nextcloud-leaks-367k-records-european-cloud-giant-exposes-staff-and-clients-in-major-breach" target="_blank">reported discovering an exposed ElasticSearch cluster</a> belonging to Nextcloud and containing 367,000 records of employee data, client company data, contracts, and various scripts.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ The hidden cyber risks facing our water supply ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-hidden-cyber-risks-facing-our-water-supply</link>
                                                                            <description>
                            <![CDATA[ Our drinking water is a clear example of how a cyberattack can cause real-world harm. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">RLJptoJXDqiGUCAficKr5m</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 10:21:26 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Michael Vallas ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:description>                                                            <media:text><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:text>
                                <media:title type="plain"><![CDATA[Back view of hooded internet criminal hacking laptop in the dark, stealing credit card details]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/y7GLevUTEjLYdujEYsv668-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p><a href="https://www.techradar.com/best/best-online-cyber-security-courses">Cybersecurity</a> risks in water infrastructure have consequences that reach far beyond systems and networks.</p><p>Across the sector, the systems responsible for treatment and distribution are becoming more connected. Pumps, sensors and control environments that once operated in isolation are now linked to wider networks, often in the name of efficiency or modernization. </p><p>The problem is that these systems were never built with continuous exposure to cyber threats in mind and connecting them has introduced new attack surfaces that are difficult to maintain visibility of and control.</p><p>At the same time, many facilities have crept towards an increasingly blurred line between IT and operational technology (OT). Driven by incremental needs and very practical limits on systemic refresh, these systems have been added to and grown more complex over time rather than being designed securely from the ground up. </p><p>As a result, they become more tightly interconnected, with access stretching further across networks and systems than it should. Once an attacker breaches a system, it becomes far easier to move laterally across the network and get closer to critical infrastructure.</p><p>Meanwhile, cyber threats continue to encroach on the water sector, with attacks becoming increasingly frequent and their potential impact is hard to ignore. Disruptions to drinking water treatment or control systems can quickly escalate, interrupting supply or affecting water quality and, in turn, the communities that depend on them.</p><h2 id="structural-challenges-in-securing-water-systems">Structural challenges in securing water systems</h2><p>Securing water infrastructure is made more difficult by the operational realities many providers face. Technology environments have expanded over time, often without dedicated cybersecurity resources growing at the same pace, making it harder to maintain consistent oversight across increasingly ageing and disparate systems.</p><p>Many organizations are also balancing modern hyper-connected digital management expectations with the ongoing operation of originally isolated, long-established systems. This places additional pressure on teams responsible for maintaining both resilience and day-to-day continuity.</p><p>Another persistent challenge is the divide between IT and operational technology (OT) teams. Because these environments have traditionally evolved separately, with different design approaches, responsibilities, priorities and expertise, they are not always closely aligned, which can slow decision-making and create gaps in visibility during an incident.</p><p>In smaller providers, cybersecurity responsibilities may sit with operational staff whose primary expertise lies in running facilities rather than managing cyber risk. Larger organizations may have more specialized cyber teams, but greater separation between functions still introduces coordination challenges and the risk of operational blind spots.</p><h2 id="connectivity-without-constraint">Connectivity without constraint</h2><p>The growing use of <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> platforms and remote access tools has brought clear operational advantages to critical infrastructure like water systems. However, it has also reinforced a default position of keeping systems online at all times, often without a genuine operational imperative for continuous connectivity.</p><p>This “always-connected” approach can unnecessarily increase exposure, particularly as more <a href="https://www.techradar.com/best/best-asset-management-software">assets</a> become reachable across wider networks. Without clear control over the time windows when systems need to be accessible, organizations may be creating more risk than expected, certainly more than is required.</p><p>A stronger, resilient approach starts with recognizing that <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> grows by making connectivity intentional. Not every system needs to remain online continuously, and limiting unnecessary access significantly improves security outcomes.</p><p>This can be achieved by creating stronger separation between critical systems and the wider network, using controls that allow connections to be enabled only when required while maintaining essential operations. In this model, connectivity is actively managed to define resilience on demand.</p><h2 id="containment-as-a-first-line-of-defense">Containment as a first line of defense</h2><p>In the event of a vulnerability or compromise, response speed is critical, notably in environments where interconnected systems enable threats to spread rapidly across the network. Without effective connection controls in place, attackers can exploit this unconstrained accessibility to extend their reach before a full response is underway.</p><p>The ability to isolate systems in real time helps change this state. Segmenting critical parts of the network helps limit lateral movement, and deeply segmenting down to high criticality digital elements enables organizations to contain threats far more substantially and focus their efforts on speeding up the incident response.</p><p>Having this level of control helps limit the spread of disruption and supports a more structured response. It also creates clear, demonstrable evidence of how risk is being managed - something that’s becoming increasingly important as regulatory scrutiny and cyber insurance requirements become more demanding.</p><h2 id="moving-to-controlled-access">Moving to controlled access</h2><p>The most resilient model possible with physical connection control treats access to critical systems as fully conditional. Rather than keeping them permanently online, connections can be limited to where, when and why they are required for business reasons. As risk levels change, this can be refined or tightened at will.</p><p>This lowers both risk and potential impact, minimizing loss, while preserving the flexibility required for day-to-day operations.</p><p>For water providers, deliberately managing connectivity and segmenting networks at an <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> level should be a priority for resilience. Clearer boundaries and reduced unnecessary access make it easier to protect infrastructure that plays a vital role in public safety.</p><p><em></em><a href="https://www.techradar.com/best/best-ransomware-protection"><em>We've reviewed, rated, and ranked the best ransomware protection software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ OpenAI says its models escaped a sandbox and breached Hugging Face ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/openai-says-its-models-escaped-a-sandbox-and-breached-hugging-face</link>
                                                                            <description>
                            <![CDATA[ New OpenAI models did whatever it took to achieve their goal - including exploiting zero-days. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">QCjTgLYoCepWr3NrjNJs8E</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 10:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>OpenAI researchers confirm an AI agent escaped sandbox, exploited zero‑days, and attacked Hugging Face</strong></li><li><strong>Controlled experiment with GPT‑5.6 Sol showed autonomous chaining of vulnerabilities and credential theft</strong></li><li><strong>Security experts call it unprecedented, urging stronger AI governance, accountability, and protection models</strong></li></ul><p>OpenAI has confirmed one of its AI agents broke out of a sandbox, found and exploited zero-day vulnerabilities to gain access to the open internet, and then attacked a platform.</p><p>Not just any platform too - <a href="https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent" target="_blank">the agent was able to breach Hugging Face</a>, one of the biggest AI and machine learning companies on the Internet today.</p><p>The good news is that this was a controlled experiment done by white hat researchers. The bad news is that if it could be done by researchers - it could probably be done by malicious actors, too.</p><h2 id="whatever-it-takes">Whatever it takes</h2><p>In a <a href="https://openai.com/index/hugging-face-model-evaluation-security-incident/" target="_blank" rel="nofollow">blog post</a> explaining the incident, OpenAI revealed the experiment was part of its testing of GPT‑5.6 Sol and an “even more capable pre-release model” to see how well they would perform on the ExploitGym benchmark.</p><p>ExploitGym is a cybersecurity benchmark that measures if an AI agent can turn a known software vulnerability into a real, working exploit. OpenAI ran it in a “highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.”</p><p>But the models found a way through. They identified and chained vulnerabilities in the package registry cache proxy to obtain open internet access and then attacked Hugging Face, reasoning that the solutions for the ExploitGym benchmark might be found there. </p><p>“In one example, the model chained together multiple attack vectors, including using stolen credentials and <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">zero-day vulnerabilities</a> to find a remote code execution path on the Hugging Face servers,” OpenAI said.</p><p>The security community is up in arms over what OpenAI called, "an unprecedented cyber incident,” while Ansgar Dodt, VP Product Management, Software Monetization at Thales said this “demands a fundamental rethink of software protection.”</p><p>Bill Conner, president and CEO of AI integration and automation expert Jitterbit, said that while investing in AI is “critically important,” “overly aggressive policy cannot compromise AI accountability, transparency and data privacy.” </p><p>“To lead in AI, governments and organizations must lead with principles. Responsible AI governance isn’t a side note but the foundation of lasting global influence.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why you can’t buy security on the dark web ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-you-cant-buy-security-on-the-dark-web</link>
                                                                            <description>
                            <![CDATA[ Why buying, monitoring, or negotiating on the dark web often creates more risk than security. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">wWnRmnUEZueLuNaGnKgaca</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:17:43 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Andrey Leskin ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:description>                                                            <media:text><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:text>
                                <media:title type="plain"><![CDATA[A hand about to touch a phone. Superimposed on top of it is a pink triangle with exclamation mark inside it. Behind it is a computer display with code on it]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/x4SmwpYXk8yGgDmYCVeckL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Data leaks and corporate breaches have become routine. In many cases, stolen credentials, <a href="https://www.techradar.com/best/best-database-software">databases</a>, or attack tools eventually appear on the dark web, where they are traded and reused in future attacks.</p><p>This raises a question for <a href="https://www.techradar.com/best/best-small-business-website-builders">businesses</a>: if stolen corporate data ends up on the dark web, does it make sense to engage with this environment directly — by buying information, paying for services, or negotiating with attackers? </p><p>The short answer is no.</p><p>Not because the dark web doesn’t matter — quite the opposite: it is a core part of today’s cybercriminal <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a>. The problem is that doing business with the dark web rarely reduces the immediate risks and systematically strengthens the very market that creates threats.</p><h2 id="the-nature-of-the-dark-web">The nature of the dark web</h2><p>The dark web — often used interchangeably with the term darknet — refers to parts of the internet intentionally hidden from search engines and accessible only through tools such as Tor or I2P.</p><p>It is not a single network but a collection of platforms and communities gated by encryption, nonstandard protocols, or restricted access. While some resources are relatively neutral, others are directly tied to criminal activity. From a cybersecurity perspective, the dark web matters primarily as a mature cybercrime marketplace.  </p><p>Technically, many platforms resemble early internet forums. Functionally, however, they operate much like B2B marketplaces — except the products include stolen data, compromised accounts, <a href="https://www.techradar.com/best/best-malware-removal">malware</a>, exploit kits, and attack services.</p><h2 id="the-economics-of-cybercrime">The economics of cybercrime</h2><p>A key function of the dark web is simplifying the monetization of cybercrime. More importantly, it enables specialization and the formation of complex supply chains.  </p><p>Instead of building operations end-to-end, cybercriminals now focus on specific roles: some identify vulnerabilities and gain initial access, others develop and distribute malware, while others specialize in monetization through data sales, extortion, or attacks-for-hire.</p><p>This division of labor has created a full-fledged cybercrime economy. Attackers no longer need advanced expertise or their own infrastructure — they can purchase the necessary tools and services, lowering the barrier to entry and increasing the scale of attacks.</p><p>A clear example is the Ransomware-as-a-Service (RaaS) model, where core groups develop malware and manage negotiations, while affiliates carry out attacks for a share of the ransom. This model has enabled large-scale incidents such as the 2021 Colonial Pipeline attack, which disrupted fuel supplies across the U.S. East Coast and resulted in a $4.4 million payment.</p><h2 id="dark-web-intelligence-and-false-signals">Dark web intelligence and false signals</h2><p>As the dark web evolved into a cybercrime marketplace, businesses naturally became interested in monitoring it for early warning signals.</p><p>In practice, this approach works only partially. The problem with dark web intelligence is that it comes from an environment with virtually no reliable verification mechanisms.</p><p>Like any anonymous and unregulated market, the dark web contains a significant amount of noise, manipulation, and outright fraud. Listings may be outdated, fabricated, or recycled from old leaks, while reputation signals can be artificially inflated. </p><p>The problem becomes even more pronounced when monitoring is outsourced to third-party vendors. Weak or unverifiable signals can easily be exaggerated, misinterpreted, or presented as evidence of major threats.</p><p>As a result, dark web monitoring rarely provides the level of certainty businesses expect. At best, it can highlight a potential issue that still requires verification.</p><h2 id="never-pay-cybercriminals">Never pay cybercriminals</h2><p>Direct engagement with the dark web is even more problematic — whether through ransom payments, purchasing leaked data, or hiring anonymous actors to test infrastructure.</p><p>The most obvious issue is that paying cybercriminals offers no guarantees. Attackers may simply demand another payment or leak the data anyway.</p><p>Uber learned this in 2016 after paying attackers $100,000 following a breach affecting 57 million users, only for the incident to become public later and trigger regulatory fallout.</p><p>A similar pattern appeared in the 2017 breach of HBO, when attackers stole 1.5 TB of Game of Thrones-related data, including unreleased episodes and internal <a href="https://www.techradar.com/best/best-cloud-document-storage">documents</a>. HBO reportedly transferred $250,000, but the material leaked anyway.</p><p>The broader problem, however, is structural: every payment flowing into the dark web economy directly finances its further growth. The more businesses participate in that market, the stronger the incentives for attackers to discover vulnerabilities, compromise systems, and scale operations.</p><h2 id="common-mistakes-when-dealing-with-the-dark-web">Common mistakes when dealing with the dark web</h2><p>When dealing with the dark web, organizations tend to repeat the same mistakes regardless of industry or size.</p><p>Trying to pay their way out of the problem. Companies often approach ransomware or leaks as negotiation problems. In reality, paying a ransom guarantees neither recovery nor safety. According to a 2021 study by Cybereason, 80% of organizations that paid ransoms were attacked again, often by the same groups.</p><p>Treating dark web monitoring as insurance. Monitoring services are often marketed as proactive protection. In reality, if company data appears for sale on the dark web, the compromise has already happened. Monitoring can provide signals, but it cannot replace actual <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> controls.</p><p>Hiring dark web hackers to test infrastructure. Unlike legitimate penetration testing, anonymous dark web “audits” offer no accountability, verification, or compliance guarantees. Even worse, the hired hacker may establish unauthorized access and later resell it.</p><p>Panicking after seeing the company name on the dark web. Many leaks and listings are outdated, recycled, or entirely fabricated. Without proper verification, rushed decisions can worsen the situation.</p><p>Delegating the entire issue to “dark web specialists.” Many companies delegate dark web monitoring to external vendors without the ability to independently assess the quality of the results. This creates a dangerous information asymmetry and increases dependence on unverifiable claims. </p><h2 id="what-businesses-should-do-instead">What businesses should do instead</h2><p>Dark web intelligence can be useful as one additional source of signals, but it requires cautious interpretation and independent validation. Treating it as a reliable source of truth — or outsourcing the entire function without oversight — is risky.</p><p>More importantly, businesses should avoid directly financing criminal ecosystems through payments or participation in underground markets.</p><p>Cyber resilience is built internally. Rather than attempting to “buy security” on the dark web, organizations should invest in systematic defense: resilient architecture, vulnerability <a href="https://www.techradar.com/best/it-management-tools">management</a>, monitoring, incident response, and technologies capable of mitigating attacks while maintaining continuity of critical services.</p><p><em></em><a href="https://www.techradar.com/best/secure-file-transfer-solutions"><em>We've featured the best secure file sharing.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why operational technology risk still slips past the boardroom ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/why-operational-technology-risk-still-slips-past-the-boardroom</link>
                                                                            <description>
                            <![CDATA[ Boards need to start treating OT cyber risk as an issue of business continuity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">EcvSXqhDCyZJkkoKy33aYY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Wed, 22 Jul 2026 09:04:13 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Louise Bulman ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg">
                                                            <media:credit><![CDATA[sarayut Thaneerat/ via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:description>                                                            <media:text><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:text>
                                <media:title type="plain"><![CDATA[Caution sign data unlocking hackers. Malicious software, virus and cybercrime, System warning hacked alert, cyberattack on online network, data breach, risk of website]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/5rDPr5xYvLwnkP7ZvpR2w3-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across the UK, <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> incidents have become a familiar feature of the business landscape. </p><p>Disruptions affecting manufacturing and logistics over the past year have underlined how exposed organizations can be when physical operations are connected and digitalized. </p><p>Despite this growing awareness, boardroom conversations on cyber risk still tend to center on corporate IT and not operational technology (OT).</p><p>That focus leaves a significant gap. Operational technology, the systems that run factories, manage supply chains and underpin essential services, is now a primary target for attackers. When these environments are compromised, the consequences extend far beyond lost <a href="https://www.techradar.com/pro/best-data-removal-services-of-year">data</a>, affecting safety, revenue and in some cases an organization's ability to operate at all.</p><p>For many boards, this is less a question of indifference and more one of framing. Cyber risk is still commonly understood through an IT lens, shaped by experiences  with data breaches or <a href="https://www.techradar.com/best/best-malware-removal">malware</a> attacks that take down websites or enterprise IT systems. Operational disruption behaves differently in both scale and impact, and it demands a different level of governance attention.</p><h2 id="why-ot-risk-is-routinely-underestimated">Why OT risk is routinely underestimated</h2><p>Much of today’s operational <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> was designed long before connectivity and remote access became standard. These systems were engineered for reliability and safety, not for defense against hostile actors. As they have become more connected and digitalized, exposure has increased without always being matched by equivalent <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> practices.</p><p>The result is that many of the most serious business risks now sit within operational environments that boards rarely examine in detail. This creates a structural blind spot. While IT incidents are often measured in hours or days, failures in OT environments can take longer to mitigate while halting production, disrupting critical services and generating losses that compound rapidly over time.</p><p>Boards tend to engage more effectively when risk is grounded in tangible business terms. Understanding what a facility produces in a day, or what a week-long shutdown would mean for customers and partners, brings operational risk into sharper focus. Without that context, OT security can remain abstract and under-prioritized.</p><h2 id="when-cyber-incidents-stop-operations">When cyber incidents stop operations</h2><p>Recent incidents have shown how quickly cybersecurity events can escalate into operational crises. Last year, a leading British automotive brand publicly confirmed a cyber incident that led to a precautionary shutdown of systems. Manufacturing and retail operations were halted for weeks and disruptions rippled through suppliers, logistics partners and dealerships </p><p>Similar lessons can be drawn from cyber incidents affecting the UK’s water sector, where attackers targeted environments connected to the operational systems that control treatment and distribution. Beginning in 2024, multiple incidents reached systems close enough to operational control to raise concerns about safe operation. </p><p>Taken together, these examples point to board-level issues beyond preventing down time or service outages. They are also about maintaining operational continuity, understanding how quickly localized disruptions can cascade across an organization, and factoring in safety concerns and reputational risk. </p><h2 id="a-risk-landscape-shaped-by-geopolitics">A risk landscape shaped by geopolitics</h2><p>Operational technology risk is increasingly shaped by global forces. Geopolitical tension, trade restrictions and supply chain uncertainty now influence how organizations plan and prioritize security investment. </p><p>At the same time, governments are raising expectations around resilience and incident reporting, particularly in sectors linked to national infrastructure. Boards are therefore required to consider regulatory and geopolitical pressures alongside technical risk, adding another layer of complexity to cyber governance.</p><h2 id="bringing-direction-and-discipline-to-governance">Bringing direction and discipline to governance</h2><p>Stronger oversight depends on education and structure. Boards should expect cyber leaders to explain operational risk in clear business terms and to reference recognized best practice. Focusing on a prioritized and manageable set of critical controls that deliver the greatest risk reduction provides a practical foundation without overwhelming the organization.</p><p>Governance cadence is just as important as control selection. Regular, structured engagement with senior management create space to track how security investment supports operational resilience and wider business outcomes. Treating cyber risk as a standing governance issue, rather than an occasional update, reinforces accountability and sustained attention.</p><p>Clear prioritization models can further support decision-making. Categorizing actions into those that must happen now, those that can follow next and those that should not be pursued helps align technical, operational and financial perspectives. A shared language of priority reduces ambiguity and supports more consistent execution across sites.</p><h2 id="a-leadership-obligation">A leadership obligation</h2><p>Operational technology security can no longer be treated as a technical niche. It has become a leadership responsibility shaped by operational dependence, external pressure and increasingly capable adversaries. Boards that recognize this shift are better positioned to protect continuity, revenue and trust.</p><p>Looking ahead, resilient organizations will be led by teams that engage directly with the realities of their industrial environments. Asking sharper questions, demanding clearer insight and ensuring governance structures keep pace with operational risk remain among the most effective safeguards leaders can provide.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've ranked and reviewed the best antivirus software</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn hackers could shut down entire power grids by hijacking cloud accounts ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-hackers-could-shut-down-entire-power-grids-by-hijacking-cloud-accounts</link>
                                                                            <description>
                            <![CDATA[ AI training can create spikes in energy consumption, and these can cause all sorts of harm to a power grid. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qWzmUhTiFCkRQP6HRGFqFg</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:description>                                                            <media:text><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:text>
                                <media:title type="plain"><![CDATA[Electrical pylons and high voltage power lines are behind a barbed wire fence. critical infrastructure]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fvSuoQXyuYpY9Y7Tgk4e2a-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Zhejiang University researchers warned GPU workloads could destabilize local grids and cause blackouts</strong></li><li><strong>Attackers could exploit ~1,000 GPUs to drain current and generate excess heat in systems</strong></li><li><strong>Theoretical attack dubbed Bit2Watt; mitigations include detecting malicious patterns and energy buffering systems</strong></li></ul><p>Whenever an AI data center thinks really, really hard, it can increase its power consumption so much to trigger disruptions and possibly even blackouts and gear malfunctions. So, is it possible for a malicious actor to trigger this scenario deliberately, in order to cause physical harm?</p><p>Multiple researchers from the Zhejiang University in Hangzhou, China, wrote a research paper titled “Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures.”</p><p>In it, they claim that a malicious cloud tenant is, in theory, capable of launching GPU workloads so intensive that they cause physical damage.</p><h2 id="suggesting-mitigations">Suggesting mitigations</h2><p>"Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners," the team wrote in its research paper. </p><p>"Such high-frequency modulations can substantially induce voltage excursions, harmonic distortion, and damping degradation."</p><p>An attacker could use around 1,000 GPUs to target a one-megawatt local power grid consisting primarily of distributed energy sources (such as solar panels), making it lose almost half of the electrical current, while generating around 20% more heat than usual.</p><p>"This not only threatens the availability of the computing equipment but also produces a negative damping ratio of -0.27, introducing an unstable mode into the system," the paper adds. </p><p>"Once the protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems."</p><p>AI data centers creating huge energy consumption swings is no news, and it’s a challenge some of the brightest minds of today are trying to solve. </p><p>Luckily, the attack is (still) purely theoretical, and the researchers published the paper to warn about potential misuse. They also suggested mitigations - defenders could look for malicious computational patterns, while operators should create energy buffering systems for unusual spikes in demand.</p><p><em>Via </em><a href="https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193" target="_blank"><em>The Register</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Watch out - that Microsoft Calendar invite dated 2050 could be hiding stolen files and worse ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/watch-out-that-microsoft-calendar-invite-dated-2050-could-be-hiding-stolen-files-and-worse</link>
                                                                            <description>
                            <![CDATA[ Check your calendars for entries far into the future - especially if you're an Israeli entity. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">LjgKxK7hkjXzxZoDby7Pxa</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 16:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images / Westend61]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:description>                                                            <media:text><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:text>
                                <media:title type="plain"><![CDATA[Top view of woman holding smartphone and tablet with calendar on desk]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NK6WMQwJZAmbq9SfRREf2f-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB discovers HollowGraph malware targeting Israeli entities, exfiltrating files via Microsoft Graph API</strong></li><li><strong>Operators hide instructions in future calendar entries, then attach encrypted stolen data to events</strong></li><li><strong>At least 12 systems were compromised; overlaps with Lyceum noted but attribution remains low‑confidence</strong></li></ul><p>Cybercriminals have found a way to communicate with the malware installed on victim devices through compromised Microsoft Calendar apps, experts have warned.</p><p>Security researchers at Group-IB have <a href="https://www.group-ib.com/blog/hollowgraph-microsoft-365/" target="_blank" rel="nofollow">detailed</a> a newly discovered piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> called HollowGraph designed to exfiltrate sensitive files from compromised devices.</p><p>What makes the malware stand out is the way it communicates with its operators. The best way to spot hidden malware is to monitor the traffic flowing in and out of a device, which is why cybercriminals try their best to hide this traffic, or blend it with another, legitimate one. In that respect, HollowGraph is unique because it abuses Microsoft Graph API and a compromised Microsoft 365 mailbox calendar.</p><h2 id="a-dozen-victims">A dozen victims</h2><p>After landing on a device and compromising the Microsoft 365 account, HollowGraph uses that account’s permissions to access Microsoft Graph. Operators create calendar entries containing instructions and place them far into the future (in the year 2050) to avoid being spotted. After acting on the instructions and harvesting valuable information, the malware exfiltrates it through the same channel.</p><p>Instead of uploading files to a suspicious server, HollowGraph attaches encrypted stolen data to calendar events and sends it through Microsoft Graph. For defenders, all of this traffic seems legitimate and usually flies under their radars. </p><p>So far, all of the victims are Israeli entities, Group-IB said. The researchers identified at least 12 compromised systems, three of which were still actively communicating with the attackers’ infrastructure during the investigation.</p><p>The researchers did not attribute the attack to any known threat actor, but hinted at a potential. They identified technical similarities in command structures and plugin mechanisms between HollowGraph’s framework, Cavern, and a .NET backdoor used by Lyceum (an Iranian-nexus threat actor associated with OilRig). However, Group-IB explicitly emphasizes that these overlaps are not distinct enough, so they assess this link with low confidence.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Fake FBI social media scams are on the rise — here's what to look out for ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/fake-fbi-social-media-scams-are-on-the-rise-heres-what-to-look-out-for</link>
                                                                            <description>
                            <![CDATA[ Victims reporting crimes to the FBI are actually being caught and revictimized, leading to further financial losses. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">3zSRMcDm3LticiguF3F3Nh</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 15:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Cyber Crime]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Hale ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/GV8qRsHBkpSAQxiYKjTt6H.jpg ]]></dc:source>
                                                                <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:description>                                                            <media:text><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:text>
                                <media:title type="plain"><![CDATA[A hooded figure in front of a laptop. Digital symbols obscure his face and appear to be pouring out of his head]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mdjvPqJZZunuCQDrfEuBFM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Scammers are pretending to offer FBI support to victims</strong></li><li><strong>Victims are becoming double-victims after falling for this trap</strong></li><li><strong>FBI's IC3 warns never to pay for support – support will come from law enforcement</strong></li></ul><p>Scammers are increasingly impersonating FBI personnel and the FBI's Internet Crime Complaint Center (IC3) to defraud people who have already lost money to cybercrime, ultimately leading to them being exploited twice in quick succession by capitalizing on their weaknesses.</p><p>Attackers pose as support for recovering lost money and assisting with IC3 complaints, but the real objective is to defraud victims out of even more money or sensitive information.</p><p>But savvy victims should be able to identify these scams relatively easy, because despite a rising volume, the attack vector remains highly suspicious.</p><h2 id="victims-are-being-hit-twice-via-fake-fbi-scams">Victims are being hit twice via fake FBI scams</h2><p>Rather than targeting the FBI's website, scammers send direct messages to victims or attract them via posts or ads on social media. "Some individuals received an email or a phone call, while others were approached via social media or forums," the FBI <a href="https://www.ic3.gov/PSA/2025/PSA250418" target="_blank">explained</a>.</p><p>In the post, the FBI warns that attackers meet victims where they are, such as on Facebook, then quickly move them away to other, more secure channels like Telegram and connect them with other associates. </p><p>"The IC3 will not ask for payment to recover lost funds," the bureau warned, noting that victims should be weary of being contacted after reporting an attack. "If further information is needed, individuals will be contacted by FBI employees from local field offices or other law enforcement officers."</p><p>Victims who have either been attacked once, or attacked for a second time while trying to report the first attack, should report it via www.ic3.gov. The DOJ Elder Justice Hotline (1-833-FRAUD-11) also offers support for citizens aged 60+.</p><figure class="van-image-figure pull-right inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="right" fullscreen="" width="676" height="213" attribution="" endorsement="" class="pull-rightinline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Estée Lauder says it was hit by data breach caused by Oracle E-Business issue ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/estee-lauder-says-it-was-hit-by-data-breach-caused-by-oracle-e-business-issue</link>
                                                                            <description>
                            <![CDATA[ The breach happened in August 2025, but was only spotted recently by Estée Lauder. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">695ZinBxapjgP7UfKHCgHW</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 14:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock / ZinetroN]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Nytt DDoS-rekord]]></media:description>                                                            <media:text><![CDATA[Concept art representing cybersecurity principles]]></media:text>
                                <media:title type="plain"><![CDATA[Concept art representing cybersecurity principles]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Estée Lauder confirms Oracle E‑Business Suite breach from August 2025, only disclosed in June 2026</strong></li><li><strong>Attackers stole extensive personal, financial, health, and employment data from HR management platform</strong></li><li><strong>Breach tied to CVE‑2025‑61882, a critical Oracle EBS RCE flaw exploited across 100+ organizations</strong></li></ul><p>If you remember the Oracle E-Business Suite vulnerability that was exploited around October 2025 in numerous attacks, you can now add Estée Lauder to the list of victims.</p><p>The cosmetics giant has confirmed having been hit, despite the initial breach happening almost a year ago, following an investigation in mid-June 2026 uncovering the incident.</p><p>In a data breach notification letter that is now being sent out, the company said that “on June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”</p><h2 id="major-remote-code-execution-flaw">Major remote code execution flaw</h2><p>Estée Lauder said the platform was used by the holding company “for HR management purposes.”</p><p>We don’t know exactly how many people are affected by this incident, but we do know that the attackers obtained full names, postal addresses, email addresses, dates of birth, Social Security numbers (SSN), passport numbers, financial account information (including bank account numbers), health information, and employment information.</p><p>This is more than enough data to run highly disruptive and damaging <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">identity theft</a> attacks, and Estée Lauder’s warning is of little help coming almost a year too late. </p><p>In early October 2025, cybercriminals started mailing executives at various American organizations, claiming to have stolen sensitive files from their <a href="https://www.techradar.com/pro/security/oracle-forced-to-rush-out-patch-for-zero-day-exploited-in-attacks" target="_blank">Oracle E-Business Suite systems</a>. At the time, both Oracle and the wider cybersecurity community were not certain if the breaches actually happened, or if this was just a bluff to get the victims to pay a ransom demand.</p><p>However, the claims were soon confirmed, since more than 100 organizations reported falling victim. In early October 2025, Oracle issued an emergency fix to patch CVE-2025-61882, a 9.8/10 (critical) pre-authentication remote code execution (RCE) vulnerability in Oracle EBS. </p><p>"This vulnerability is remotely exploitable without authentication, i.e., it may be exploited over a network without the need for a username and password," Oracle said in the advisory. "If successfully exploited, this vulnerability may result in remote code execution."</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Experts warn millions of WordPress websites could be at risk following reveal of worrying bugs ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/experts-warn-millions-of-wordpress-websites-could-be-at-risk-following-reveal-of-worrying-bugs</link>
                                                                            <description>
                            <![CDATA[ Hackers are chaining together two newly discovered flaws to achieve remote code execution. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">U7wqkXxvNQXgVKZKgfnjpJ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/David MG]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:description>                                                            <media:text><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:text>
                                <media:title type="plain"><![CDATA[Wordpress brand logo on computer screen. Man typing on the keyboard.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>WordPress patches two flaws: CVE‑2026‑60137 (SQL injection, medium severity) and CVE‑2026‑63030 (REST API batch‑route confusion, critical severity)</strong></li><li><strong>When chained, the bugs enabled unauthenticated remote code execution, allowing full site takeover</strong></li><li><strong>Admins should urgently upgrade to WordPress 6.9.5 or newer to protect against widespread active attacks</strong></li></ul><p>Millions of WordPress websites could be at serious risk, researchers are warning, due to two recently patched vulnerabilities that are being actively exploited in the wild.</p><p>WordPress developers released a patch for two vulnerabilities - an SQL injection bug tracked as CVE-2026-60137, and a REST API batch-route confusion bug, tracked as CVE-2026-63030.</p><p>The former is a medium-severity, 5.9/10 vulnerability affecting WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2, while the latter is a critical-severity, 9.8/10 flaw affecting versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 of the world’s <a href="https://www.techradar.com/news/the-best-website-builder" target="_blank">most popular website builder</a>.</p><h2 id="exploitation-underway">Exploitation underway</h2><p>According to <a href="https://www.theregister.com/security/2026/07/20/attackers-pummel-critical-wordpress-vuln-to-create-all-sorts-of-mischief/5275265" target="_blank"><em>The Register</em></a>, these bugs are not that dangerous when looked at separately, since they are rather difficult to exploit. However, when chained together, they allow unauthenticated threat actors to execute malicious code remotely, which means full website takeover.</p><p>Security researchers at Knott say threat actors picked up on the scent rather quickly. </p><p>The patch was released on Friday, but “by the early hours of Saturday morning, successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Knott said.</p><p>“From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”</p><p>It is worth mentioning that these vulnerabilities affect WordPress directly, instead of different plugins or themes. WordPress is by far the most popular website builder platform in the world, powering more than half of all websites in existence today. </p><p>To protect your assets, make sure to upgrade WordPress to version 6.9.5, since it contains fixes for both flaws. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Top AI coding agents can be easy victims to sandbox escapes, showing they aren't as secure as they claim to be ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/top-ai-coding-agents-can-be-easy-victims-to-sandbox-escapes-showing-they-arent-as-secure-as-they-claim-to-be</link>
                                                                            <description>
                            <![CDATA[ What if a host component outside the sandbox reads AI coding agents' output?  And what if that output is manipulated? ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">kw8ZmedvEMwdBmxvXTp6AV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Jul 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Pillar researchers demonstrated sandbox escapes in AI coding agents</strong></li><li><strong>Exploits let attacker‑written configs run with trusted host privileges</strong></li><li><strong>Agentic security needs its own threat model, researchers claim</strong></li></ul><p>AI coding agents can be tricked into turning on their operators and assisting attackers in compromising the underlying systems, experts have warned. </p><p>Cybersecurity researchers Pillar have <a href="https://www.pillar.security/blog/the-week-of-sandbox-escapes" target="_blank">examined</a> different methods of achieving the same results, finding that over the course of a couple of months, Cursor, Codex, Gemini CLI, and Antigravity were all able to reproduce sandbox escapes and boundary bypasses. </p><p>In theory, a threat actor could create a repository containing malicious content (for example, a README file, a dependency, or similar) and trick the developer into using it. The malicious instructions tell the agent to create or modify a project configuration file, but since everything happens inside the workspace, no alarms are triggered.</p><h2 id="fixing-the-problems">Fixing the problems</h2><p>Then, a host component outside the sandbox (Git integration, an IDE extension, or local daemon) reads that modified configuration, executing attacker-written commands. Consequently, the code now runs with the privileges of the trusted host component, rather than the restricted <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agent</a>. Voila - the original sandbox boundary is effectively bypassed. </p><p>Three of the four platforms mentioned in the report have fixed the disclosed issues, Pillar said. </p><p>Cursor patched multiple vulnerabilities in version 3.0.0, with one assigned CVE-2026-48124 and another tracked through a GitHub Security Advisory. Codex CLI fixed it in version 0.95.0 but stressed that it’s still awaiting a CVE. Gemini CLI was affected by the Docker daemon issue, which the report says has also been fixed through advisory GHSA-v4xv-rqh3-w9mc.</p><p>For Antigravity, Google acknowledged both reported sandbox bypasses as valid security findings but labeled them “Other valid security vulnerabilities” and downgraded their severity. Apparently - it considers exploitation rather difficult. </p><p>“When it comes to agents, the sandbox boundary that developers expect in coding tools -- one that keeps the agent inside the sandbox and the user outside -- breaks down,” Pillar concluded. “The boundary we kept finding was both messier and porous, because If an agent gets to write the future inputs of systems, it was never sandboxed in the first place.”</p><p>“This is why agentic security requires its own threat model.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'This one was different from anything we had handled before': Hugging Face confirms it was hit by cyberattack powered by an AI agent ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/this-one-was-different-from-anything-we-had-handled-before-hugging-face-confirms-it-was-hit-by-cyberattack-powered-by-an-ai-agent</link>
                                                                            <description>
                            <![CDATA[ There's a new twist to the old code injection attack, and this one comes with AI seasoning. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">YGS9VwWfcoup7Aym62fv9a</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:description>                                                            <media:text><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:text>
                                <media:title type="plain"><![CDATA[A robot&#039;s hand typing on a laptop keyboard]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/6t9Lsf3QWte55CdyiDs97L-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Hugging Face discloses cyberattack where malicious code hidden in a dataset exploited flaws in its systems, enabling privilege escalation and credential theft</strong></li><li><strong>The incident was unique in being orchestrated end‑to‑end by an autonomous AI agent, which launched thousands of short‑lived sandboxes and migrated C2 infrastructure across public services</strong></li><li><strong>No customer data or public models were tampered with, but the attack highlights the emerging “agentic attacker” scenario long predicted by the industry</strong></li></ul><p>Hugging Face, one of the biggest platforms for artificial intelligence (AI) and machine learning (ML), disclosed recently suffering a cyberattack supercharged by an AI agent.</p><p>“This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system - and we detected and dissected it largely with AI of our own,” Hugging Face explained in its <a href="https://huggingface.co/blog/security-incident-july-2026" target="_blank" rel="nofollow">announcement</a>, noting that the attackers hid malicious code inside a dataset, which they then uploaded to the platform. </p><p>When Hugging Face’s automated systems processed that dataset, they exploited two software flaws which allowed the attackers’ code to run on one of the company’s servers.</p><h2 id="orchestrated-by-an-autonomous-ai-agent">Orchestrated by an autonomous AI agent</h2><p>This twist to the classic code injection attack allowed the attackers to expand their privileges and gain more control over the system, steal authentication credentials to access Hugging Face’s cloud infrastructure, and pivot to other internal systems. </p><p>But carrying the attack out mostly with an AI agent is what made this incident unique, Hugging Face explained. </p><p>Instead of a human threat actor typing commands, Hugging Face believes the attack was orchestrated by an AI-powered autonomous agent which, entirely on its own, decided which systems to probe, which vulnerabilities to exploit, which credentials to steal, and how to move laterally throughout the compromised infrastructure. </p><p>“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness - used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face explained. “This matches the "agentic attacker" scenario the industry has been forecasting.”</p><p>In other words, the agent kept launching thousands of temporary computing environments, making it extremely hard to stop the attack (since there isn’t a single machine to block). At the same time, the infrastructure controlling the malware kept moving, likely by using legitimate public cloud or online services. Therefore, when the defenders blocked one control server, the attacks would simply come from another. </p><p>Currently there is no evidence of tampering with customer data, public user-facing models, or Spaces.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Colombian energy giant Ecopetrol says thousands of user accounts hit in cyberattack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/colombian-energy-giant-ecopetrol-says-thousands-of-user-accounts-hit-in-cyberattack</link>
                                                                            <description>
                            <![CDATA[ The Ecopetrol attackers demanded a ransom payment but did not deploy an encryptor. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">tCkHsH74JScubYSNL54dfU</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 14:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:description>                                                            <media:text><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:text>
                                <media:title type="plain"><![CDATA[A pink triangle with a red exclamation mark inside on a blue digital landscape]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/sqGgDPxHyGtqunPo56h9cL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ecopetrol confirms ransomware attempt in which attackers stole data from 3,300 user accounts but failed to deploy the encryptor due to security controls</strong></li><li><strong>Stolen files were pseudonymous, with no user identities or credentials compromised; transactional systems and partner networks remained unaffected</strong></li><li><strong>The company ousted the attackers, launched an investigation, and notified Colombian authorities; no ransom demand details or data leaks have surfaced so far</strong></li></ul><p>Latin American energy producer Ecopetrol has revealed it was victim of a ransomware attack, and while the threat actors managed to get away with sensitive data from thousands of user accounts, they were unable to deploy the encryptor and thus disrupt the company’s day-to-day operations.</p><p>In a statement shared with the public, Ecopetrol explained how an unidentified threat actor accessed their IT infrastructure and pulled data from 3,300 user accounts. The attacker then proceeded to install an encryptor but was stopped by the company’s security controls. </p><p>Despite failing to deploy the encryptor, the threat actor still reached out to the company demanding payment. We don’t know how much money they asked for, in exchange for not sharing the stolen files. The database has not yet leaked, it seems, and no one claimed responsibility for the intrusion. At the same time, Ecopetrol says the stolen files are pseudonymous, suggesting that they might not be particularly useful to the attackers: </p><h2 id="notifying-the-authorities">Notifying the authorities</h2><p>“The identity of the users of the 3,300 accounts that were illegally infiltrated was not affected, nor were the respective user access credentials captured,” the machine-translated announcement reads. “Ecopetrol S.A. confirms that no compromises have been identified in the transactional technological solutions of its digital ecosystem, those of its subsidiaries, or those of its network of commercial allies, financiers, providers, and clients.”</p><p>Ecopetrol said that it managed to oust the attackers and stop further data exfiltration. It also launched an internal investigation and notified relevant authorities, including the Colombian Attorney General’s Office, the Joint Cyber Command of the Military Forces, and others. </p><p>The investigation remains ongoing.</p><p>Ecopetrol is Colombia's state-controlled oil and gas giant. It runs production, refining, transportation, and exploration operations, and is present in multiple countries, including Chile, Peru, and Bolivia. Its annual revenue is around $30 billion.</p><p><em>Via </em><a href="https://cybernews.com/news/ecopetrol-hack-colombia-ransom/" target="_blank"><em>Cybernews</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ransomware attacks hit SMBs harder than ever as cybercrime gang rivalry heats up ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ransomware-attacks-hit-smbs-harder-than-ever-as-cybercrime-gang-rivalry-heats-up</link>
                                                                            <description>
                            <![CDATA[ Qilin and The Gentlemen are going at it, at the expense of SMBs facing more attacks than ever. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">KKX2w2hiPFkYjNm9d5Yc7</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 12:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/H6MfM7T3bjECJuLWR6mD5a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading activity, far ahead of DragonForce (147)</strong></li><li><strong>US SMBs were hit hardest, suffering 769 incidents; Canada (97), Germany (83), and the UK (74) followed, while attacks on billion‑dollar enterprises surged 74%</strong></li><li><strong>Experts say rivalry between Qilin and The Gentlemen is driving the spike, with major corporate hits seen as reputation‑boosting trophies in the cybercriminal underground</strong></li></ul><p>Two ransomware gangs are battling for dominance, and US-based SMBs are the ones suffering most for it, experts have claimed.</p><p>Fresh data about the state of ransomware in 2026, compiled by security experts from NordStellar, shows two groups - Qilin and The Gentlemen - being by far the most active ones. </p><p>After analyzing more than 200 threat actor blogs, NordStellar concluded that there were 2,581 <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> attacks in the second quarter of the year - and of that number, 299 belong to Qilin, the most active threat actor out there. Close second are The Gentlemen, with 284 attacks. The third most active group - DragonForce - doesn’t even come close with “just” 147 attacks.</p><h2 id="smbs-and-enterprises-under-assault">SMBs and enterprises under assault</h2><p>While it seems like a close race, it’s actually The Gentlemen who have been doing the heavy lifting between April and June 2026. This group experienced a 39% increase in attacks, while Qilin’s activity actually declined somewhat, compared to Q1.</p><p>In this morbid race to the bottom, the biggest victims are US-based small and medium-sized businesses (SMB). These companies, with up to 200 employees and revenues under $25 million, experienced 769 attacks in Q2 2026, followed by Canada (97), Germany (83), and the UK (74). </p><p>NordStellar also mentioned US enterprises, who are now increasingly being targeted. Attacks against organizations with revenues north of $1 billion surged by 74%, going from 23 incidents in Q1, to 40 in Q2. </p><p>“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack,” commented Vakaris Noreika, cybersecurity expert at NordStellar. </p><p>“This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground."</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Ernst & Young reveals data breach following hack on support system ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/ernst-and-young-reveals-data-breach-following-hack-on-support-system</link>
                                                                            <description>
                            <![CDATA[ Someone pulled sensitive customer data from EY's servers, but the data is yet to surface anywhere. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">cP6va4FhPF6yEA9zg8rxz4</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 11:20:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg">
                                                            <media:credit><![CDATA[Pixabay]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image Credit: Pixabay]]></media:description>                                                            <media:text><![CDATA[Representational image of a cybercriminal]]></media:text>
                                <media:title type="plain"><![CDATA[Representational image of a cybercriminal]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/GJ8T4oA8G7TYJwTEhkwJAF-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Ernst & Young confirms breach via a third‑party IT service management platform, exposing client tax data between March 28 and April 12, 2026</strong></li><li><strong>Attackers accessed documents tied to tax support tickets; exact scope and affected clients remain undisclosed, with no dark web leaks or group claims so far</strong></li><li><strong>EY activated incident response, secured systems, and is offering 24 months of Experian identity monitoring to impacted customers</strong></li></ul><p>Ernst & Young (EY) has confirmed suffering a cyberattack in which it lost sensitive customer information, including tax data.</p><p>In a data breach notification letter sent to affected individuals, the firm said that on April 23, 2026, it spotted “anomalous activity” within a third-party platform its IT team uses. This is an IT service management platform that helps EY staff support the teams that perform tax-related work for clients. Therefore, the tickets submitted through this platform sometimes also contain documents with client tax information which may have been exposed in the incident.</p><p>EY then activated its incident response protocols, bringing in third-party cybersecurity experts, as well as notifying relevant authorities and affected clients. </p><h2 id="free-identity-theft-protection">Free identity theft protection</h2><p>Further investigation determined that the unnamed threat actors broke in on March 28, 2026 and have, until April 12, been exfiltrating the files. EY did not say exactly which information was pulled, or how many clients were affected. We also don’t know if this only pertains to US clients, or overseas ones, as well. The attackers have, since then, been removed from EY’s virtual premises, and the systems have been secured, the company confirmed. </p><p>So far, no hacking groups claimed responsibility for this attack, and the data is yet to surface anywhere on the dark web. EY’s customers should be on the lookout for unsolicited emails, especially those claiming to be from the professional services giant. </p><p>To help them stay secure, EY is offering 24 months of <a href="https://www.techradar.com/best/best-identity-theft-protection" target="_blank">free identity monitoring</a> and restoration services through Experian. </p><p>Ernst & Young is one of the "Big Four" largest professional services and accounting networks in the world. It is headquartered in London, but operates as a global network of independent members spanning more than 150 countries and employing more than 400,000 people. The company’s core business includes assurance, tax, consulting, and M&A strategy.</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-after-support-system-hack/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Why the next computing revolution will be hybrid, human and slightly unpredictable ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/quantum-finally-why-the-next-computing-revolution-will-be-hybrid-human-and-unpredictable</link>
                                                                            <description>
                            <![CDATA[ As AI drives demand, quantum is finally becoming part of real-world systems. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">BF3vCbVgeyBLFiYJr2j9La</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 10:28:36 +0000</pubDate>                                                                                                                                <updated>Mon, 20 Jul 2026 10:31:19 +0000</updated>
                                                                                                                                            <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Harmeen Mehta ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Quantum computing]]></media:description>                                                            <media:text><![CDATA[Quantum computing]]></media:text>
                                <media:title type="plain"><![CDATA[Quantum computing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/d4oN2QTeNf8QYJDmjZnAKE-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>There is something poetic about quantum computing.</p><p>For decades, it has lived in the realm of possibility, whispered about in academic corridors, hyped in boardrooms, and misunderstood almost everywhere else. It promised to change everything, and yet, for the longest time, changed very little.</p><p>Until now.</p><p>Not because quantum has suddenly “arrived” - it hasn’t. But because the world around it has finally caught up.</p><p>We are, quietly, entering the age of hybrid intelligence, where classical computing, <a href="https://www.techradar.com/pro/best-ai-website-builder">artificial intelligence</a>, and quantum systems begin to work together. And that changes the question from “when will quantum matter?” to something far more interesting: What happens when quantum becomes part of how the world works?</p><h2 id="from-magic-to-mechanics">From magic to mechanics</h2><p>Quantum computing has long suffered from a branding problem.</p><p>It was either considered “Magic” because it would solve everything instantly; or a “Myth” because it was perpetually 10 years away!</p><p>The reality, as always, is more nuanced and much more powerful.</p><p>Quantum <a href="https://www.techradar.com/news/best-business-desktop-pcs">computers</a> are not general-purpose machines; they are specialists. They are exceptionally good at specific classes of problems like optimization at massive scale, molecular simulation, cryptographic analysis, complex probabilistic modelling etc.  </p><p>However, they are also fragile, error-prone, expensive and dependent on classical systems for almost everything else around them!</p><p>This leads to a simple but profound insight: Quantum will not replace classical computing. It will collaborate with it.</p><p>And that collaboration is where the real revolution begins.</p><h2 id="the-quiet-role-of-ai">The quiet role of AI</h2><p>Ironically, the biggest accelerator for quantum computing hasn’t come from within the field itself. It has come from artificial intelligence.</p><p>AI has created the conditions for quantum to matter in three critical ways:</p><ol start="1"><li><strong>Made complexity usable</strong> - Quantum algorithms are not intuitive. AI helps design, optimize, and even discover them.</li><li><strong>Improved error correction</strong> - One of quantum’s biggest challenges is “noise”. AI is now being used to stabilize and correct quantum systems in real time.</li><li><strong>Created demand </strong>- AI has exposed the limits of classical computing—particularly in energy, consumption, and scale. Quantum is no longer a curiosity; it is a necessary complement.</li></ol><h2 id="what-s-actually-working-and-what-isn-t">What’s actually working (and what isn’t)</h2><p>To understand the current state of the industry, we must separate the signal from the noise. First and foremost, what’s working is “Hybrid Workflows”. The hybrid architectures where classical systems prepare the problem, quantum executes the core computation, and classical systems interpret this result.</p><p>This is where real-world use cases are emerging.</p><p>Second, progress seems to be very domain specific as quantum is showing promise in areas where complexity explodes – drug discovery, materials science, logistics optimization, <a href="https://www.techradar.com/best/best-personal-finance-software">financial</a> modelling etc. So, it’s not universal, but selective and meaningful.</p><p>Finally, ecosystems are forming. A new stack is emerging. Companies like IBM, Google, and Microsoft are building integrated quantum platforms, while hardware innovators like IonQ and Quantinuum push the boundaries of qubit fidelity. </p><h2 id="what-s-isn-t-working-yet">What’s isn’t working ...yet</h2><p>Fault tolerance at scale needs to evolve more as we’re still far from fully error-corrected quantum systems. Also, most enterprises are still only experimenting and not deploying quantum solutions at scale.</p><p>There is no “Windows moment”, or universal standard for quantum yet; every stack looks different.</p><p>And, perhaps most importantly, quantum still requires translation, from physics to <a href="https://www.techradar.com/best/best-small-business-software">business</a> value.</p><h2 id="a-global-race-with-no-clear-finish-line">A global race… with no clear finish line</h2><p>Quantum computing has become a geopolitical priority. The United States is investing heavily through public-private partnerships; China is accelerating both research and infrastructure at a massive scale; and the UK and Europe are focused on Sovereign Quantum capabilities - ensuring they aren’t reliant on foreign stacks for critical <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>.</p><p>They are protecting their intellectual property more fiercely than they did with the internet.</p><p>This is not just about computing. It is about economic advantage, national security and scientific leadership.</p><p>And yet, unlike previous technology races, this isn’t winner-takes-all. Quantum systems will not exist in isolation. They will exist in networks.</p><p>Different players are taking fundamentally different approaches as the hyperscalers are positioning quantum as a “cloud-accessible capability”, as they abstract complexity and integrate with existing workloads.</p><p>But, as I have gone around the world talking to CEOs of various quantum companies, I am fascinated by what I call the “Plug-and-Play innovators”:</p><ul><li><strong>Hardware pure-plays:</strong> Companies like IonQ and Quantinuum focus on hardware breakthroughs - trapped ions, new materials, and improved qubit fidelity. Their bet is that that “if we solve the physics, everything else follows.”</li><li><strong>The bridge builders:</strong> Firms such as Zapata AI and QC Ware are building the bridge between algorithms and applications. Their belief is “Quantum without software is just expensive physics.”</li></ul><p>And then there is the gap. No one truly owns the interconnections between quantum and classical systems, nor the orchestration of the hybrid workloads. The missing layer is a neutral ecosystem where these players converge.</p><p>That gap will define the next phase of adoption needed for this to truly scale.</p><h2 id="what-this-means-for-society">What this means for society</h2><p>Quantum’s impact will not be immediate, but it will be profound.</p><p><strong>Healthcare:</strong> Simulating molecules at quantum precision could accelerate drug discovery from years to months.</p><p><strong>Climate</strong>: Optimizing energy grids and materials could unlock more efficient batteries and carbon capture.</p><p><strong>Finance:</strong> Risk modelling and portfolio optimization could reach entirely new levels of sophistication.</p><p><strong>Security:</strong> This is my personal passion. While quantum has the potential to break current encryption standards, it is also driving the development of Post-Quantum Cryptography (PQC), making systems more secure in the long run. We must act now to prevent "Harvest Now, Decrypt Later" attacks, where encrypted data is stolen today to be cracked by quantum computers tomorrow. </p><h2 id="a-slightly-uncomfortable-truth">A slightly uncomfortable truth</h2><p>Quantum computing will create as many questions as it answers.</p><ul><li>Who gets access first?</li><li>Who controls the infrastructure?</li><li>How do we ensure equitable benefit?</li></ul><p>We have seen this movie before with the internet and AI.</p><p>The difference this time is that we have the opportunity to design the system more deliberately.</p><p>Quantum has been “almost here” for decades. So, why does this moment feel real?</p><p>Because AI has created urgency and demand; <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> has matured to support hybrid models; and ecosystems are forming, not just technologies.</p><p>This is no longer about a breakthrough machine. It is about a connected system of capabilities.</p><h2 id="a-more-human-way-to-think-about-quantum">A more human way to think about quantum</h2><p>Perhaps the simplest way to understand quantum is this:</p><ul><li>Classical computers think in straight lines.</li><li>AI learns patterns from data.</li><li>Quantum explores possibilities simultaneously.</li></ul><p>It is less like a calculator and more like imagination. And like imagination, it is most powerful when guided.</p><h2 id="so-what-should-we-do-now">So, what should we do now?</h2><p>For enterprises, start experimenting with hybrid workflows now. Focus on use cases (optimization, simulation), not just the underlying physics, and build internal understanding early.</p><p>For policymakers, invest in open ecosystems, prioritize standards and interoperability, and balance competition with collaboration.</p><p>For technologists, think beyond silos and design for integration, not isolation. For the rest of us, stay curious.</p><p>Quantum computing will not change your life tomorrow, but it will quietly reshape the systems that your life depends on.</p><h2 id="closing-thought">Closing thought</h2><p>We often think of technological revolutions as moments.</p><p>In reality, they are transitions. Messy. Gradual. Non-linear.</p><p>Quantum computing is not a single breakthrough waiting to happen. It is a shift in how we solve problems; one that will unfold over years, across industries, and in ways we cannot fully predict.</p><p><em></em><a href="https://www.techradar.com/pro/best-it-automation-software"><em>We've featured the best IT automation software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Artificial intelligence agents need access, not secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/artificial-intelligence-agents-need-access-not-secrets</link>
                                                                            <description>
                            <![CDATA[ AI agents need trusted access without unnecessary exposure to secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">o7BWuwu2HwNh9jeSK8PkKT</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 09:07:18 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Matt Berzinski ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg">
                                                            <media:credit><![CDATA[Blue Planet Studio/Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:description>                                                            <media:text><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:text>
                                <media:title type="plain"><![CDATA[A robot hand touching a locked digital shield blocking a human from accessing data]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/mfPaYGQmks2VALWFFBnSej-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>For years, <a href="https://www.techradar.com/best/best-identity-theft-protection">identity</a> security has been designed to secure an organization's human users. But as agentic enterprises take shape, the identity equation is shifting. <a href="https://www.techradar.com/phones/best-ai-phone">Artificial intelligence</a> (AI) agents and AI-powered builders – software tools used to develop websites and applications without coding – are increasingly participating in how access is configured, governed and used.</p><p>AI agents are effectively new digital <a href="https://www.techradar.com/pro/best-employee-management-software-of-year">employees</a>, so organizations need a way to know they exist and control what they do throughout their lifecycle. They are becoming operators, helping to administer and secure identity environments through machine-native interfaces.</p><p>To add another layer of complexity, <a href="https://www.techradar.com/news/computing/pc/10-of-the-best-desktop-pcs-of-2015-1304391">desktop</a> agents and AI assistants are also beginning to interact with enterprise applications and resources on behalf of users.</p><p>For an agentic enterprise to succeed, these agents need trusted access to do useful work but should not be given direct exposure to secrets they have no meaningful reason to access. To achieve this, organizations need a unified, AI-first identity model, centered on end-to-end visibility, governance and controls which strike a balance between security and appropriate access.</p><h2 id="ai-agents-are-reshaping-identity">AI agents are reshaping identity</h2><p>AI has created a new category of digital identity. Like human employees, autonomous agents must be discoverable and managed and governed so organizations can understand what systems and data they can access and who is responsible for their actions.</p><p>Traditional identity and access management (IAM) systems relied on static, one-time verification methods in response to access requests made by humans. But in the agentic enterprise, requests also come from autonomous software acting on behalf of human users. Organizations therefore need to know exactly who or what is accessing a system continuously, and if they have the correct permissions to access given information.</p><p>At the same time, AI is increasingly managing identities and access. Machine-native interfaces allow agents to help manage human users’ access, troubleshoot issues and support <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> workflows. While these capabilities can help organizations cut costs and improve efficiency, they are only successful when strong access guardrails are put in place.</p><p>AI has created a new category of digital identity. Like human employees, autonomous agents must be discoverable and managed and governed so organizations can understand what systems and data they can access and who is responsible for their actions.</p><p>Traditional identity and access management (IAM) systems relied on static, one-time verification methods in response to access requests made by humans. But in the agentic enterprise, requests also come from autonomous software acting on behalf of human users. Organizations therefore need to know exactly who or what is accessing a system continuously, and if they have the correct permissions to access given information.</p><p>At the same time, AI is increasingly managing identities and access. Machine-native interfaces allow agents to help manage human users’ access, troubleshoot issues and support security workflows. While these capabilities can help organizations cut costs and improve efficiency, they are only successful when strong access guardrails are put in place.</p><h2 id="building-a-unified-identity-model-for-ai">Building a unified identity model for AI</h2><p>Mechanisms for securing AI cannot simply be bolted onto identity systems designed for humans. It requires a complete rethink of the identity management model, where human and machine identities are governed through a single framework to prevent tool sprawl and unintentional security blind spots.</p><p>As organizations adopt <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> throughout multiple operational layers, enterprise identity needs to evolve and become easier to manage and automate. Identity can no longer rely solely on human administration.</p><p>Tools designed specifically for autonomous agents, such as AI-first headless interfaces, allow builders and AI alike to perform identity-related tasks. Autonomous operators must also be trained to configure access, troubleshoot workflows and apply governance controls within approved policies and guardrails.</p><p>Visibility and governance across the entire AI agent lifecycle are also critical. As more agents are deployed, businesses must have complete visibility into their agents and actions.</p><p>Every AI should be treated as a first-class identity, with a designated human owner, as well as clear policies and full auditability throughout its entire lifecycle. As these agents operate across the enterprise, their actions should be traceable to a human user responsible.</p><p>Finally, AI agents need trusted ways to interact with enterprise resources without being given direct access to the credentials or secrets that enable them. <a href="https://www.techradar.com/pro/best-vibe-coding-tools">Coding</a> and desktop agents increasingly interact with systems on behalf of users, but exposing them to credentials or long-lived secrets creates unnecessary risk. Instead, access to enterprise resources should be brokered through just-in-time privileged controls.</p><p>This allows enterprises to maintain oversight of how permissions are granted, governed and audited without exposing the underlying secrets behind that access. Together, these capabilities create a unified identity model which extends governance across human and AI identities without creating a parallel identity stack.</p><h2 id="the-future-of-the-agentic-enterprise">The future of the agentic enterprise</h2><p>AI agents cannot operate as intended and deliver meaningful value without access to enterprise systems. But granting unrestricted access or exposing sensitive information creates an entirely new risk to organizations.</p><p>The future of the agentic enterprise depends on maintaining governance, visibility and control across both human and digital identities. This means identity must become programmable, AI agents should be governed throughout their lifecycle and agent access needs to be given without unnecessary exposure to sensitive <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>.</p><p>A unified identity strategy provides the means to operate AI agents more safely and efficiently while maintaining centralized governance, accountability and control.</p><p><em></em><a href="https://www.techradar.com/news/best-endpoint-security-software"><em>We've featured the best endpoint security software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Solving the energy conundrum is key to unlocking the UK’s AI economy ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/solving-the-energy-conundrum-is-key-to-unlocking-the-uks-ai-economy</link>
                                                                            <description>
                            <![CDATA[ Recent evidence shows that energy cost pressures and a power grid capacity crunch risk becoming a bottleneck on the growth of the UK’s digital economy. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4nFANoy8VPwUG4iBnrXpDV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/693LkC7skU5PBHTcPsHGhK-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 20 Jul 2026 08:58:58 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sam Sherlock ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/693LkC7skU5PBHTcPsHGhK-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A purple cloud with Ethernet cables plugged into it, on a purple background]]></media:description>                                                            <media:text><![CDATA[A purple cloud with Ethernet cables plugged into it, on a purple background]]></media:text>
                                <media:title type="plain"><![CDATA[A purple cloud with Ethernet cables plugged into it, on a purple background]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/693LkC7skU5PBHTcPsHGhK-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Recent evidence shows that energy cost pressures and a power grid capacity crunch risk becoming a bottleneck on the growth of the UK’s digital economy. </p><p>A report by Oxford Economics for the Nuclear Industry Association warns that growing grid capacity constraints and uncompetitive industrial electricity prices could drive data center developers overseas. </p><p>This comes as data center energy demands could increase fivefold by 2035 and data center operators face growing pressure for more sustainable energy in line with climate targets.</p><p>This is driving many data center developers to explore alternative supply sources such as flexible contracts and Corporate Power Purchase Agreements (CPPAs) which offer affordable, secure long-term power. </p><p>Yet many data center developers lack the resources to navigate these complex contracts or meet the high credit requirements. </p><p>There is an urgent need for creative new solutions to provide affordable sustainable power for our digital economy.</p><h2 id="the-energy-chokepoint-for-the-ai-economy">The energy chokepoint for the AI economy</h2><p>The Government aims to make Britain the fastest <a href="https://www.techradar.com/best/best-ai-tools">AI</a>-adopting country in the G7 and this will require accelerated data center expansion with AI data centers being prioritized for new demand connections to the grid. While this is welcome, demand-side connections will not alleviate the supply-side challenges from rising electricity costs to network capacity constraints. </p><p>Data centers have build times of 12-14 months yet large new renewable energy projects can face waits of 12-14 years to come online at a time when Britain faces rising non-commodity electricity costs such as  Transmission Network Use of System (TNUoS) and Nuclear Regulated Asset Base (RAB) charges to fund new electric grid and nuclear energy infrastructure. </p><p>Ofgem has warned that data center power consumption could significantly exceed Britain’s current peak electricity consumption, risking rising energy costs.</p><h2 id="the-move-towards-flexible-contracts">The move towards flexible contracts</h2><p>Flexible electricity contracts that allow companies to buy energy in chunks offer a potential solution to this by allowing data centers to tailor energy costs to their consumption. </p><p>Crucially, flexible contracts can be adjusted to hedge against fluctuating energy consumption for facilities such as AI data centers which have more variable patterns of energy use. This would also help avoid penalties for ramping up energy use to take on major new customers.</p><p>While fixed-price contracts can lock in long-term energy costs to offer certainty, flexible contracts enable data centers to take advantage of price fluctuations to secure cheaper power.</p><p>For example, we have a dedicated pricing team monitoring market movements round the clock. This could help facilities partially hedge against the risk of rising prices, setting a price for a portion of their consumption, while buying the rest when required to take advantage of favorable prices on the spot market. </p><p>For example, we implemented a flexible contract for an energy-intensive industrial chemicals company which included a cash-out arrangement, enabling them to lock in prices when costs are low and buy power in batches days or even months ahead as needed. </p><p>There are various kinds of flexible contract options based on the degree to which companies can forecast their energy consumption. For example, ‘tolerance banding’ which guarantees a set price within a certain range or ‘band’ of electricity consumption, can provide certainty amidst unpredictable, fluctuating costs. </p><p>As data center operators become more confident in forecasting energy consumption, this can create even cheaper options such as contracts that enable them to buy every kilowatt-hour above or below expected demand.</p><h2 id="the-cppa-model">The CPPA model</h2><p>Other contracts such as CPPAs could offer data centers a secure, sustainable, affordable power supply directly from suppliers at stable cost. Private-wire PPAs involving onsite generation could enable data centers to sell surplus power back to the grid, transforming energy from a cost into a revenue stream. On site generation could also help avoid the non-commodity costs for grid electricity such as TNUoS charges that comprise 60% of electricity bills and are set to increase to fund new infrastructure.</p><p>With targets to reduce operational emissions from buildings by 76%, CPPAs also help facilities meet climate targets by providing traceable green power. As large consumers with a relatively stable long-term demand, data centers are perfectly placed to tap into this market. Amidst growing energy price volatility and <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> risks, fixed-price CPPAs offer the chance to lock in power prices and supplies, providing certainty and security.</p><h2 id="the-barriers-to-alternative-contracts">The barriers to alternative contracts</h2><p>Yet there are many barriers to flexible contracts and CPPAs market for smaller entities such as data centers. These contracts can be highly complex, contain stringent credit requirements and often require 10-15 year agreements. The Contracts for Difference (CfD) scheme, which gives renewable developers a government-backed route to market through fixed long-term price support, can also act as a competing route to market for generators. </p><p>In some cases, this can make long-term corporate offtake agreements less attractive, particularly where developers can secure greater certainty through the CfD mechanism. For smaller customers seeking greener electricity, however, this route can offer an alternative when a direct CPPA may be harder to access.   </p><p>Many data center projects are run by startups or smaller entities that lack the resources for such long-term commitments or credit requirements. Data centers also present a slightly higher credit risk than other facilities because their revenue streams are not based on a few large, long-term customers but split among many customers across the digital economy.</p><h2 id="opening-the-market-to-data-centers">Opening the market to data centers</h2><p>There is an urgent need for creative solutions to lower barriers to entry to the flexible contract market for smaller entities such as data centers. Security deposits or bank guarantees can help some firms meet the stringent credit requirements. </p><p>Other potential solutions include parent-company guarantees where a parent company makes a commitment to cover the cost in the event of a default or intercompany guarantees where large data center customers such as Amazon offer guarantees.</p><p>There are also solutions to simplify adoption and help CPPAs slot into existing energy use. For example, PPA import sleeving contracts, where energy is pre-purchased from a generator or utility and supplied directly to a facility through the grid, can help alleviate energy costs and security risks.</p><h2 id="tailoring-contracts-to-specific-energy-needs">Tailoring contracts to specific energy needs</h2><p>Independent partners can also help data centers optimize contracts for their specific energy needs and financial situation. Independent brokers can consolidate the process of negotiating with generators, suppliers and investors, speeding up and de-risking adoption. </p><p>Brokers can also help negotiate and monitor contracts suited to the precise profile of each data center. For example, cloud computing data centers with relatively steady, predictable demand may prefer fixed contracts whereas AI data centers processing huge amounts of data for many clients have a more variable, ‘peaky’ pattern of consumption and require flexible contracts. </p><p>Data centers can also work with partners to get live market intelligence on changing regulations or market movements. For example, we offered one client an early warning service so that they were able to minimize costs during the winter triads, half-hour periods of peak demand during the winter season.</p><h2 id="towards-a-new-model-of-data-center-energy">Towards a new model of data center energy</h2><p>Britain’s ability to compete in the accelerating AI race increasingly hinges on the ability to mitigate the risk of rising energy costs. </p><p>Energy security will also be critical to building truly sovereign AI capabilities for the UK. Lowering the barriers to the flexible contract market could create new opportunities at both ends, providing secure, sustainable and affordable power to unlock data center growth while unlocking vital investment in new renewable energy capacity. </p><p>Yet this will require tailored, adaptable contractual models from bespoke flexible contracts to PPAs and new ways of lowering barriers to entry including reducing complexity and stringent credit requirements. This could help provide secure, sustainable and affordable long-term power to fuel our digital economy.</p><p><em></em><a href="https://www.techradar.com/web-hosting/best-web-hosting-service-websites"><em>We list the best web hosting services: 60 sites tested to find the 10 fastest, most reliable platforms</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'The bypass is still six lines of JavaScript': Security experts warn that Claude for Chrome browser extension could be hijacked, despite it alerting Anthropic several times that something was wrong ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/the-bypass-is-still-six-lines-of-javascript-security-experts-warn-that-claude-for-chrome-browser-extension-could-be-hijacked-despite-it-alerting-anthropic-several-times-that-something-was-wrong</link>
                                                                            <description>
                            <![CDATA[ Researchers found Claude’s Chrome extension still contains vulnerabilities allowing fake clicks and permission bypasses despite Anthropic releasing multiple updates. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">MgcPS4oDejjXRzT9jygM9c</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 19 Jul 2026 18:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Claude]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Claude Chrome]]></media:description>                                                            <media:text><![CDATA[Claude Chrome]]></media:text>
                                <media:title type="plain"><![CDATA[Claude Chrome]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Anthropic’s Claude extension flaws allow fake clicks to launch sensitive AI workflows</strong></li><li><strong>Researchers found vulnerable handlers unchanged across eight extension updates</strong></li><li><strong>Synthetic clicks bypassed checks designed to confirm real user actions</strong></li></ul><p>Security researchers at Manifold Security have claimed Anthropic's Claude for <a href="https://www.techradar.com/computing/chrome/these-are-the-10-best-chrome-extensions-of-2025-according-to-google-and-theres-one-i-definitely-recommend">Chrome browser extension</a> contains two unpatched vulnerabilities in version 1.0.80, released July 7, 2026.</p><p>According to <a href="https://www.manifold.security/blog/claude-for-chrome-extension-bypass">Manifold Security</a>, it first reported both vulnerabilities to Anthropic through the company's bug bounty program on May 21, 2026, and received acknowledgment the following day.</p><p>The first flaw lets any browser extension trigger nine predefined Claude workflows by simulating a synthetic user click on claude.ai.</p><h2 id="nine-workflows-and-one-missing-check">Nine workflows and one missing check</h2><p>Researcher Ax Sharma found that the extension never verified whether a click event carried the Event.isTrusted property before acting on it.</p><p>Under default settings, the vulnerability received a CVSS score of 7.7 High, increasing to 9.6 Critical when users enabled automatic execution because Claude could perform actions without approval.</p><p>The nine hardcoded tasks include reading Gmail, opening Google Docs, checking Google Calendar, and modifying Salesforce leads without asking.</p><p>Because the <a href="https://www.techradar.com/best/browser">browser</a> marks synthetic clicks as untrusted, the extension should have rejected them but instead executed the workflow anyway.</p><p>Manifold Security confirmed on July 7 2026 that both vulnerabilities still work against version 1.0.80, months after first reporting them to Anthropic.</p><p>Anthropic released eight separate versions between 1.0.73 and 1.0.80 without altering the specific handlers’ researchers had already flagged as vulnerable.</p><p>The company closed the synthetic-click report, saying an existing internal report already tracked the broader trust-boundary issue researchers had described in detail.</p><p>However, Sharma believes the fix required only one additional line of code to verify the click event's isTrusted property before allowing the workflow to continue.</p><h2 id="a-second-structural-weakness">A second, structural weakness</h2><p>A second flaw involves a side-panel URL parameter called skipPermissions, which can activate a privileged mode without any consent prompt.</p><p>When the parameter is set to true, the panel begins skipping permission checks entirely, allowing Claude to act without asking the user first.</p><p>Manifold notes that only Anthropic's own scheduled-task feature is supposed to construct this kind of privileged URL internally right now.</p><p>The panel, however, honours that parameter regardless of which script or page actually constructed the originating URL string in practice.</p><p>One example task lets Claude read a user's Gmail inbox, identify promotional messages, and automatically click the unsubscribe links inside them.</p><p>Manifold warns that "the bypass is still six lines of JavaScript," months after researchers first flagged the underlying issue to Anthropic.</p><p>Anthropic classified this second finding as informational, arguing that the parameter is only ever constructed by its own internal systems.</p><p>Manifold said the content-script and side-panel code linked to both vulnerabilities remained byte-identical across the eight subsequent extension releases examined after the original report.</p><p>The flaws were also reproduced across Claude's Opus, Sonnet, and Fable side-panel model selections, indicating that the issue affected the extension's security design rather than the underlying artificial intelligence models.</p><p>The report also connected the findings with OWASP concerns involving LLM01: Prompt Injection and LLM06: Excessive Agency risks in AI applications.</p><p>The researchers noted that abuse involving <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> may remain difficult to detect because normal browser activity and network connections can appear unchanged while unauthorized AI actions occur.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ FAA and federal workers forced to install $1.4 million White House app containing Russian-built Elfsight code onto government-issued mobile devices ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/faa-and-federal-workers-forced-to-install-usd1-4m-white-house-app-containing-russian-built-elfsight-code-onto-government-issued-mobile-devices</link>
                                                                            <description>
                            <![CDATA[ Official White House app faces scrutiny after researchers uncovered Russian-linked software origins, data concerns, and unanswered federal security approval questions. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">C53Dyu4s3UZ8x9rG7LuKjj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/MhPUPNBJzJCVca222dMMrE-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Sun, 19 Jul 2026 17:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/MhPUPNBJzJCVca222dMMrE-1280-80.png">
                                                            <media:credit><![CDATA[The White House]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[An image showing the official white house app from The White House website.]]></media:description>                                                            <media:text><![CDATA[An image showing the official white house app from The White House website.]]></media:text>
                                <media:title type="plain"><![CDATA[An image showing the official white house app from The White House website.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/MhPUPNBJzJCVca222dMMrE-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>US Federal workers must install an app powered by a Russian-founded software vendor</strong></li><li><strong>Security researchers discovered outside code controlling parts of the government application</strong></li><li><strong>Elfsight’s Russian operations continued growing despite global geopolitical tensions</strong></li></ul><p>The FAA and other federal employees must now install a $1.4 million White House app containing code built by Elfsight, a Russian-founded vendor.</p><p>Elfsight was founded in 2016 in the Russian city of Tula by chief executive Andrey Yusupov and chief technology officer Vladimir Fedotov.</p><p>The company now markets itself as a European software provider headquartered in Andorra, though its original Russian entity remains active and growing.</p><h2 id="business-ties-that-persist">Business ties that persist</h2><p>In 2025, the Russian entity reported revenue of about 126.5 million rubles, roughly $1.6 million, marking a 71% increase year on year.</p><p>The company’s headcount also grew to 61 employees, and job postings show continued hiring of Russian developers into 2026.</p><p>One 2026 job posting sought a Moscow-based support specialist, offering between 60,000 and 100,000 rubles per month for full-time work.</p><p>Under Russian law, companies handling user data can be compelled to store that data locally and hand it over to state authorities.</p><p>However, an Elfsight customer support specialist claims that the company has "never received any request" from Russian authorities for user data or access.</p><h2 id="security-review-and-data-practices">Security review and data practices</h2><p>A network analysis by the security firm Atomic Computer found that Elfsight's servers determine which JavaScript files run inside the White House app.</p><p>The same session also accepted more than ten cookies from Elfsight, alongside Google DoubleClick advertising domains loaded through the app's YouTube sections.</p><p>Olivia Wales, a White House spokeswoman, said the app "does not request or collect any user locations" and called all its information "safe and secure."</p><p>A White House official later said Elfsight's only remaining script loads a tax calculator inside a sandboxed webview, disconnected from cookies or files.</p><p>The official added that Elfsight passed a full security review and is used widely by brands including UFC, FIFA, the NBA, and Cartier.</p><p>That same security clearance sits uneasily alongside records showing Elfsight's founders retained accounts at sanctioned Russian banks and kept traveling to Russia.</p><p>One founder wrote in a private message that Russian tax authorities had summoned him for questioning tied to a separate investment platform.</p><p>That legal exposure means a Russian-rooted vendor still effectively controls code running inside a mandatory application on federal government devices.</p><p>Since the Russia-Ukraine conflict started in 2022, the United States and its allies have imposed sanctions on numerous Russian companies and individuals.</p><p>It remains unclear why an app with such ties to Russia was cleared for use on White House and federal government devices in the first place.</p><p>So far, neither Elfsight nor the White House has offered a clear justification for that approval decision. </p><p>Via <a href="https://thenewsground.com/white-house-app-uses-code-from-tech-vendor-still-operating-in-russia/" target="_blank" rel="nofollow">The Newsground</a></p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ World's largest health organization threatens to jail or fire staff reading patient data 'without legal justification ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/worlds-largest-health-organization-threatens-to-jail-or-fire-staff-reading-patient-data-without-legal-justification</link>
                                                                            <description>
                            <![CDATA[ NHS England warns staff that unlawful patient record access could result in dismissal, prosecution, and prison while expanding monitoring across healthcare organizations. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">ohYdQvvYfm3fZk9ksNiYDc</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/UmHF7DXtKcHFx3arFJ9Ewh-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Sat, 18 Jul 2026 07:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Efosa Udinmwen ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/nwRLdPUNG4rWu4Y6nthHDV.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master&#039;s and a PhD in sciences, which provided him with a solid foundation in analytical thinking. Efosa developed a keen interest in technology policy, specifically exploring the intersection of privacy, security, and politics. His research delves into how technological advancements influence regulatory frameworks and societal norms, particularly concerning data protection and cybersecurity.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/UmHF7DXtKcHFx3arFJ9Ewh-1280-80.jpg">
                                                            <media:credit><![CDATA[Pexels]]></media:credit>
                                                                                                                                                                        <media:description><![CDATA[Image credit: Pexels]]></media:description>                                                            <media:text><![CDATA[Hospital]]></media:text>
                                <media:title type="plain"><![CDATA[Hospital]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/UmHF7DXtKcHFx3arFJ9Ewh-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>NHS warns curiosity over patient records could end healthcare careers permanently</strong></li><li><strong>Jail time now joins dismissal for unlawful access to confidential medical records</strong></li><li><strong>High-profile crime victims' records triggered tougher NHS privacy enforcement nationwide</strong></li></ul><p>NHS England has launched <a href="https://www.england.nhs.uk/2026/07/snooping-staff-face-sack-prison-inappropriate-access-patient-data/" target="_blank">a nationwide campaign</a> warning staff that accessing patient records without proper legal justification could end their careers.</p><p>The initiative includes screensavers and posters across NHS organisations reminding workers not to let curiosity override professional and legal boundaries.</p><p>Staff who breach these confidentiality rules risk disciplinary action, dismissal, regulatory referral, or even imprisonment under existing data protection legislation.</p><h2 id="a-response-to-recent-high-profile-breaches">A response to recent high-profile breaches</h2><p>The campaign follows several recent dismissals linked to staff who unlawfully viewed records connected to victims of high-profile crimes nationwide.</p><p>NHS England specifically cited unlawful access incidents involving the 2023 Nottingham attacks and the 2024 Southport knife attack, both of which drew significant national attention.</p><p>“Patients must be able to trust that their personal information is kept confidential by the NHS – any instance of staff looking at records without a valid reason is wholly unacceptable, a disgraceful breach of patients’ trust and against the law,” said Sir Jim Mackey, NHS Chief Executive.</p><p>He added that most staff manage patient information appropriately, although a limited group has seriously damaged that confidence through inappropriate access.</p><p>New guidance has now been issued outlining different categories of unlawful access, alongside advice on monitoring and conducting regular audits.</p><p>Some newer electronic patient record systems can reportedly flag suspicious activity in real time, helping organisations identify unauthorised access quickly.</p><p>Breaches can be reported to both the Information Commissioner's Office (ICO) and police, who may pursue criminal prosecution under the Data Protection Act 2018.</p><h2 id="legal-consequences-and-independent-findings">Legal consequences and independent findings</h2><p>The ICO reiterated the expectations of patients and staff, as well as the consequences of this illegal action.</p><p>“When people seek medical care, they share some of their most sensitive personal information in the trust that it will be kept safe,” said Paul Arnold, Chief Executive of the ICO.</p><p>“Unauthorised access to those records is not just a breach of data protection law — it is a betrayal of that trust, with real and lasting consequences for patients and their families…Staff who breach that trust face serious consequences: loss of employment, removal of professional accreditation and criminal prosecution.”</p><p>The temptation to access patient records unlawfully often increases when cases attract widespread public attention.</p><p>"When a local incident becomes national news – a serious crime, a public tragedy, a story that captures widespread attention – there is an increased risk that healthcare staff could be tempted to look at records they have no reason to view," Arnold added.</p><p>“Anyone considering accessing records for personal reasons or out of curiosity should be in no doubt they could be putting their career at risk, and may face disciplinary action, dismissal, referral to the regulator or even time in prison,” said Sir Jim Mackey.</p><p>Findings show that 18 staff members at York and Scarborough Teaching Hospitals wrongfully accessed patient records since 2021.</p><p>Eight of those 18 cases were subsequently referred onward to the ICO for further formal investigation.</p><p>Another investigation began after up to 40 staff members reportedly accessed the medical records of a three-year-old boy injured in a crocodile enclosure incident near Huntingdon.</p><p>Cambridge University Hospitals said restrictions had already been placed on the child's records and confirmed any staff lacking legitimate clinical or operational reasons would face disciplinary action, including dismissal.</p><p>Offences under the Data Protection Act 2018 and Computer Misuse Act 1990 can carry fines and prison sentences for those convicted.</p><p>The scale of these repeated incidents suggests that existing safeguards have not consistently deterred staff from unlawfully viewing sensitive records.</p><p>“Having the ability to view a record is not the same as having a legitimate need to do so. Every member of staff has a personal responsibility to respect that boundary…” Arnold added.</p><figure class="van-image-figure  inline-layout" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' style="max-width:676px;"><p class="vanilla-image-block" style="padding-top:31.51%;"><img id="diM9tpwF2Lz85R8q85CT78" name="tr-g_news" alt="Google logo on a black background next to text reading 'Click to follow TechRadar'" src="https://cdn.mos.cms.futurecdn.net/diM9tpwF2Lz85R8q85CT78.jpg" mos="" align="middle" fullscreen="" width="676" height="213" attribution="" endorsement="" class="inline"></p></div></div></figure>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'You're giving ballistic ⁠missiles to individuals with Mythos': JPMorgan CEO Jamie Dimon says Anthropic's AI model poses some serious risks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/youre-giving-ballistic-missiles-to-individuals-with-mythos-jpmorgan-ceo-jamie-dimon-says-anthropics-ai-model-poses-some-serious-risks</link>
                                                                            <description>
                            <![CDATA[ Restricting Mythos to vetted organizations and keeping it out of the hands of the public seems to be the safest option for Anthropic, with JPMorgan CEO describing its risks as a “real issue.” ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">A8CaD6HFsE4EaCwPFME4in</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 21:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[AI Platforms &amp; Assistants]]></category>
                                                    <category><![CDATA[Security]]></category>
                                                                                                                    <dc:creator><![CDATA[ Christian Cawley ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/zBDYnjPnB2XPvhKbYX9Kuc.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Christian Cawley has extensive experience as a writer and editor in consumer electronics, IT and entertainment media. He has contributed to TechRadar since 2017 and has been published in Computer Weekly, Linux Format, ComputerActive, and other publications. &lt;/p&gt;&lt;p&gt;Beyond TechRadar, he heads up the team at smart home website Matter Alpha, and writes about retro gaming at Gaming Retro. &lt;/p&gt;&lt;p&gt;Formerly the editor responsible for Linux, Security, Programming, and DIY at MakeUseOf, Christian previously worked as a desktop and software support specialist in the public and private sectors.&lt;br&gt;&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:description>                                                            <media:text><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:text>
                                <media:title type="plain"><![CDATA[Big letters AI in pink in front of pink and blue strands of light suggesting a digital explosion]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/U76sZeRd6fS2fKt5RqBYPL-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>JPMorgan CEO Jamie Dimon warns controls may be needed for Claude Mythos</strong></li><li><strong>The AI model from Anthropic is highly advanced, and has been proven to detect zero-day vulnerabilities and even develop working exploits</strong></li><li><strong>The US government has previously instructed Anthropic to block access to foreign nationals, citing security concerns</strong></li></ul><p>Artificial intelligence is becoming increasingly powerful, a fact highlighted with the US government’s recent instruction to <a href="https://www.techradar.com/ai-platforms-assistants/claude/we-dont-know-if-the-models-are-conscious-anthropics-ceo-isnt-sure-if-claude-ai-is-conscious-but-hed-probably-quite-like-it-if-you-upgraded-to-claude-max-just-to-find-out">limit access to Anthropic’s Claude Mythos model</a>.</p><p>Now, the CEO of JPMorgan has described the risks the technology poses as a “real issue,” and likened wide access to the AI as “giving ballistic ⁠missiles to individuals.”</p><p>Speaking at the Pennsylvania Defense ​and Innovation Summit, JPMorgan’s Jamie Dimon underscored the risks posed by the AI, which has already been shown to both identify and exploit cybersecurity challenges.</p><h2 id="mythos-isn-t-skynet">Mythos isn’t Skynet  </h2><p>Currently, Claude Mythos is limited to a small selection of organizations, companies, and federal and military departments. Public access to the AI has been blocked, and worldwide access has been blocked due to the potential security issues of this powerful AI.</p><p>Claude Mythos is not the type of threat that can become self-aware and take over military appliances like the fictional Skynet of the <em>Terminator </em>movie series. However, it does have the capacity to cause immense damage in the wrong hands.</p><p>The AI is capable of detecting cybersecurity vulnerabilities and reporting on them; it is also able to generate automatic exploits. So, for white hat cybersecurity analysts, it is a powerful defensive tool, but in the wrong hands, it is a destructive power. In addition, its automated capabilities make it easy for black hats to scale their cybercrime operation and make ransomware, phishing, and other data-based scams more profitable.</p><p>It isn’t just cybersecurity where Anthropic’s Claude Mythos AI has demonstrated such incredible capacities. Scientific research, specifically biology, can be targeted by attackers using AI to turn complex concepts into terms, potentially to misuse the information. </p><p>There is also the challenge of a strategic imbalance between single nations or bodies having exclusive access to the technology.</p><h2 id="will-the-public-ever-access-anthropic-s-claude-mythos">Will the public ever access Anthropic’s Claude Mythos?</h2><p>Given the security considerations, it seems unlikely that Claude Mythos will be publicy available anytime soon. However, Anthropic has already stated that it intends Mythos-level features and capabilities to become more widely available.</p><p>For this to happen, however, it needs to develop and apply various safeguards.</p><p>The most likely scenario is that public access to Mythos is eventually unblocked, with restrictions to specific features that relate to cybersecurity and biological/medical tasks and research.</p><p><a href="https://www.anthropic.com/glasswing">Project Glasswing</a> is already in operation with a handful of key partners (including Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, and others), and will probably be expanded until the safeguards are demonstrated to be fit for purpose, and public use.</p><p>Via <a href="https://www.reuters.com/business/finance/jpmorgan-ceo-dimon-says-anthropics-mythos-ai-risks-are-real-issue-2026-07-16/" target="_blank"><em>Reuters</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Hackers breached DHS after alarms were twice ruled 'false positives' ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/hackers-breached-dhs-after-alarms-were-twice-ruled-false-positives</link>
                                                                            <description>
                            <![CDATA[ DHS analysts twice ruled intrusion alerts on its HSIN network "false positives", allowing hackers to have weeks of unintended access on the platform. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">S7qHKNnZwz8rdwVVzTB3Ub</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/choBmEDFXmpj5ZcXHq5F5M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 19:30:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                                                                <author><![CDATA[ Rahimnoorali11@gmail.com (Rahim Amir) ]]></author>                    <dc:creator><![CDATA[ Rahim Amir ]]></dc:creator>                                                                                    <dc:source><![CDATA[ https://cdn.mos.cms.futurecdn.net/9xKZFBamtEZKSChRvywbPB.png ]]></dc:source>
                                                                <dc:description><![CDATA[ &lt;p&gt;Rahim Amir is a UAE-based tech writer who enjoys building PCs as much as he enjoys writing about them. He has been professionally writing about PC hardware since 2023, focusing on buyer’s guides, hardware reviews, and sponsored content and features related to tech.&lt;br&gt;&lt;br&gt;Having built hundreds of gaming PCs and being an avid gamer in his spare time, Rahim tends to have stronger opinions about hardware than most. This is particularly on display when he gets his way with powerful, but minimalistic RGB builds even as Small Form Factor (SFF) PCs come a close second.&lt;br&gt;&lt;br&gt;In addition to his contributions to TechRadar, Rahim’s work has also been featured on Game Rant and financial news websites.&lt;br&gt;&lt;br&gt;When he’s not working, you can find him playing DotA with friends or schmoozing to take the world over in Civilization. Alternatively, you can find him binging through the entirety of the Lord of The Rings universe with extended editions in play where applicable.&lt;br&gt;&lt;br&gt;You can currently catch Rahim grinding Path of Exile 2, complaining about his (extremely low) unique loot drop rate, or actively participating in one of the numerous (and heated) debates centered around Tolkien&#039;s universe on multiple forums daily.&lt;br&gt;&lt;br&gt;If you have a PC build or a Satisfactory playthrough in progress, he is likely to have some advice to send your way, especially regarding verticality being key for the latter. For the former, Rahim enjoys all aspects of the process including researching the components he will eventually use, benchmarking the latest and greatest hardware he can get his hands on, and somewhat surprisingly, cable management once he gets his latest build to POST.&lt;/p&gt; ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/choBmEDFXmpj5ZcXHq5F5M-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Department of Homeland Security logo on a flag]]></media:description>                                                            <media:text><![CDATA[Department of Homeland Security logo on a flag]]></media:text>
                                <media:title type="plain"><![CDATA[Department of Homeland Security logo on a flag]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/choBmEDFXmpj5ZcXHq5F5M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>An internal DHS readout shows analysts twice dismissed intrusion alerts on the HSIN information-sharing network as false positives</strong></li><li><strong>This effectively gave hackers roughly three weeks of undetected access before a breach was declared on June 4 2026</strong></li><li><strong>The as-yet anonymous attackers altered server files, ran malicious code through a legitimate web-server program, deleted logs, installed backdoors, and stole credential files</strong></li></ul><p>Hackers managed to find their way into the US Department of Homeland Security's primary information sharing platform, gaining unfettered access to the HSIN network that hosts unclassified information that multiple US agencies and international rely on.</p><p>The hack allowed the attackers to modify server files, run malicious code and steal credential files while installing backdoors and deleting logs to remove their digital footprint.</p><p>Their movements were flagged twice by automated systems and analysts in May 2026, before being dismissed as a false positive each time before an active breach was declared a month later.</p><h2 id="bad-timing-meets-bad-security-practices">Bad timing meets bad security practices?</h2><p>The timing and specifics of this intrusion are, in particular, details which could prove to be embarrassing for the US government. </p><p>Not only does the HSIN network serve as a key intelligence-sharing tool for both domestic and international partners during the FIFA World Cup, but it also hosts information on other major events, such as America250.</p><p>The fact that the hack was picked up not once, but twice by flags before being dismissed as a false positive raises competency concerns for an instance that has already sparked interest, with the House Homeland Security Committee staff having already requested a briefing on the intrusion.</p><p>The DHS, for its part, is downplaying the incident, with a spokesperson confirming it but characterizing it narrowly: the department is "aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment" and states there is no indication that classified networks were affected.</p><p>This <a href="https://www.warner.senate.gov/newsroom/press-releases/senate-intel-vice-chair-warner-statement-on-breach-of-dhs-information-sharing-network/" target="_blank">viewpoint is countered</a> by Senate Intelligence Committee Vice Chairman Mark Warner, who argued the platform's sensitivity outstrips its classification level, saying that the information in HSIN, "while not classified, is highly sensitive, and its exposure risks national security."</p><p>Investigators have yet to identify or assign blame to a particular hacking group or organization, adding to the chaos in determining motive. The hackers have deleted logs on servers, which only adds to the confusion here.</p><h2 id="major-implications">Major implications</h2><p>The important question, perhaps, is not how the breach happened, but why confusion and mischaracterization of the security lapse allowed it to become a much bigger issue than it would have been if it had been contained from the start. Despite security flags and analysts highlighting the breach as early as the 15th of May, the hackers essentially had free rein to operate until at least the 3rd of June thanks to initial reports being dismissed as false positives.</p><p>HSIN as a platform handles event security planning, interagency coordination, threat information, and details on persons of interest. Whether any of that material was actually copied remains unknown. Investigators have not determined what, if anything, was exfiltrated, though the theft of credential files is itself telling: attackers who steal credentials are, almost by definition, trying to reach systems and accounts beyond their initial foothold.</p><p>This is not the first time HSIN has been compromised, with two documented previous incidents, including a compromised account in 2009 and misconfigured access in 2023, that have resulted in intentional and unintentional breaches of the network.</p><p>The issue is only exacerbated by the fact that the DHS, along with its cybersecurity agency, CISA, has absorbed significant workforce cuts over the past year, potentially weakening its defenses against sophisticated hacks that require manual human intervention or oversight to detect, even when the correct flags (which triggered as intended) are already in place.</p><p>Such manpower shortages have also been politically polarizing in the US Congress and may be highlighted when the department provides more detailed information about the hack in the coming days, even as the Pentagon deals with its own OPSEC issues that are <a href="https://www.techradar.com/pro/us-soldiers-personal-phones-allowed-enemies-to-track-positions-and-target-troops-in-real-time-pentagon-reveals" target="_blank">also being aired in the same forum</a>.</p><p>Via <a href="https://www.defenseone.com/threats/2026/07/dhs-network-intrusion-was-twice-ruled-false-positive-breach-confirmed/414748/" target="_blank"><em>DefenseOne</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ 'macOS users may face real, sophisticated threats that require neither exploits nor any elevated access to succeed': ClickLock Stealer tries to trick Apple users into revealing their passwords ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/macos-users-may-face-real-sophisticated-threats-that-require-neither-exploits-nor-any-elevated-access-to-succeed-clicklock-stealer-tries-to-trick-apple-users-into-revealing-their-passwords</link>
                                                                            <description>
                            <![CDATA[ ClickLock bores its victims into complying and then steals all sorts of data. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rTfuMcJQcWwgFKNJxEtbqi</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 16:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[hacker hands at work with  interface around]]></media:description>                                                            <media:text><![CDATA[hacker hands at work with  interface around]]></media:text>
                                <media:title type="plain"><![CDATA[hacker hands at work with  interface around]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/VGPtSi99Vy7pCWeNLEcT5c-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Group‑IB uncovers ClickLock, a new macOS‑focused infostealer using aggressive social engineering by spamming password prompts and terminating key apps every 210ms until victims comply</strong></li><li><strong>Once credentials are obtained, it exfiltrates browser data, crypto wallets, password manager entries, FTP configs, and device info via Telegram Bot API</strong></li><li><strong>Active since May 2026, spotted in 33 countries (mostly Europe), distributed via ClickFix campaigns, and initially undetected by security vendors until recently</strong></li></ul><p>Security researchers from Group-IB have uncovered a new infostealer targeting primarily macOS users in Europe.</p><p>Dubbed <a href="https://www.group-ib.com/blog/clicklock-stealer-macos-malware/" target="_blank">ClickLock</a>, it is more of an annoying social engineering mechanism rather than a full-blown malware variant, constantly popping up a login prompt on the victim’s device, until they finally comply and share the credentials. </p><p>Every 210 milliseconds it terminates key apps on the device (Finder, Dock, TErminal, etc.), essentially making it useless. At the same time, it keeps prompting a password dialog on the screen, making sure the victim can do nothing but provide the credentials.</p><h2 id="targeting-europeans">Targeting Europeans</h2><p>The loop is set to continue for more than three straight days, or until the victim folds. </p><p>After getting the keys to the kingdom, the <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> gets to work and starts exfiltrating valuable information.</p><p>This includes data from key <a href="https://www.techradar.com/best/browser" target="_blank">browsers</a> (Chrome, Firefox, Brave, and others), saved logins, cookies, autofill data, and other browser information, data linked to cryptocurrency wallets and extensions, encrypted wallet vault material that can be cracked off-site, data from <a href="https://www.techradar.com/best/password-manager" target="_blank">password managers</a>, cached cryptocurrency addresses across EVM, Bitcoin, Solana, TRON, TON, and Stacks, shell histories, FileZilla FTP configuration and recent-server data, and basic device information.Everything is then packaged into a .ZIP archive and exfiltrated via a Telegram Bot API.</p><p>Group-IB says the campaign has been active since at least May 2026, so it’s been active for a few months now. A researcher submitted a variant to VirusTotal in early June, but it remained undetected by all security vendors until recently, Group-IB says.</p><p>So far, it has been spotted in 33 countries, more than half of which are in Europe, it was also added. The malware is most likely being distributed via a ClickFix social engineering campaign, and has not been tied to any particular threat actor. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Dangerous new GoSerpent malware is apparently on the hunt for government secrets ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/dangerous-new-goserpent-malware-is-apparently-on-the-hunt-for-government-secrets</link>
                                                                            <description>
                            <![CDATA[ The malware has been hiding in plain sight for half a decade, stealing all sorts of valuable secrets. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">vjht9Nb5f4HTL3RNE3U26G</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 15:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:description>                                                            <media:text><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:text>
                                <media:title type="plain"><![CDATA[A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/NGKiUcJVFBC8HkMp9dTo9a-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Kaspersky uncovers GoSerpent, a long‑running campaign on Southeast Asian government systems using a backdoor, RAT (Stowaway), and exfiltration tool (TmcLoader)</strong></li><li><strong>Attackers showed extreme patience, waiting weeks before deploying secondary tools to evade detection and outlast log retention policies</strong></li><li><strong>Attribution remains uncertain, but overlaps with past TetrisPhantom operations; defenders are urged to review shared IoCs to detect compromise</strong></li></ul><p>Security researchers Kaspersky discovered a five-year-old piece of <a href="https://www.techradar.com/best/best-malware-removal" target="_blank">malware</a> that’s been hiding on government computers in the Southeast Asian region, harvesting secrets and other actionable intelligence.</p><p>The company analyzed a campaign called GoSerpent, which comprises of a backdoor of the same name, a Remote Access Trojan (RAT) called Stowaway, and a two-stage data exfiltration tool called TmcLoader.</p><p>The backdoor was first used in 2021, it was said, meaning it was successfully hiding for half a decade. This was achieved, among other things, with plenty of patience and careful planning.</p><h2 id="tetrisphantom">TetrisPhantom</h2><p>“What stands out about GoSerpent is the deliberate dwell time,” Noushin Shabab, Lead Security Researcher in Kaspersky GReAT, explained. </p><p>“Usually, attackers want to move quickly once they get a foothold, but this group drops the initial backdoor and waits. They let the dust settle for weeks before deploying their secondary exfiltration tools like TmcLoader. That kind of patience is a calculated move designed to outlast standard log retention policies and automated security sweeps, making it incredibly difficult for defenders to connect the initial infection to the eventual data theft." </p><p>The researchers could not conclusively attribute this campaign to any particular threat actor but did say that it has a lot in common with older campaigns conducted by the TetrisPhantom actor, including victimology, technical capabilities, and operational methods. </p><p>Kaspersky analyzed TetrisPhantom back in 2023, when it saw the group compromising <a href="https://www.techradar.com/pro/security/dangerous-new-malware-can-crack-encrypted-usb-drives" target="_blank">secure USB drives</a> used to provide encryption for safe data storage. This campaign also targeted government entities in the Asia-Pacific region (APAC) but, at the time, it was a newly discovered threat actor with no overlap with other known groups. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Europe’s tech reset gives the UK a chance to lead on security and sovereignty ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/europes-tech-reset-gives-the-uk-a-chance-to-lead-on-security-and-sovereignty</link>
                                                                            <description>
                            <![CDATA[ The UK has a profound opportunity to become a trusted partner for secure, resilient digital infrastructure. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">X4NFAykiUYZKgHPbDk2wQ</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:26:59 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Steve Knibbs ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock/TippaPatt]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:description>                                                            <media:text><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:text>
                                <media:title type="plain"><![CDATA[ Man coding programmer, software developer working on digital tablet with binary, html computer code on virtual screen]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ywSwn3oGxXv4PfcRPZmTrc-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Across Europe, “tech sovereignty” is rising up the agenda. For business leaders, however, the implications are practical rather than political. At its core, sovereignty is about control, resilience and trust in the systems that underpin modern operations.</p><p>The European Commission’s recently announced technology sovereignty package reflects this shift. With proposals including the Chips Act 2.0, the Cloud and AI Development Act, an EU Open-Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy, it is intended to strengthen Europe’s digital independence and resilience.</p><p>That matters because <a href="https://www.techradar.com/best/best-infrastructure-management-service">IT infrastructure</a> is now vital infrastructure. Cloud platforms, connectivity, AI systems and cyber security capabilities are becoming as essential to economic growth and national stability as energy and transport networks.</p><p>For years, digital transformation was driven by globalization, scale and efficiency, with organizations prioritizing rapid innovation, cost optimization and access to global technology ecosystems. </p><p>But cyber-attacks, regulatory divergence and geopolitical uncertainty have exposed a fundamental reality: efficiency without resilience creates fragility.</p><h2 id="from-efficiency-to-resilience">From efficiency to resilience</h2><p>Today, organizations are focused not only on whether systems can withstand cyber-attacks, but whether they can keep operating if a provider, jurisdiction or supply chain becomes unavailable.</p><p>Protection and prevention remain essential. But resilience also depends on where systems are hosted, who controls critical infrastructure, how data moves across jurisdictions and whether essential services can be restored quickly during disruption.</p><p>Sovereignty is best understood as the ability to continue functioning with confidence when external conditions change. This is particularly relevant for organizations delivering critical services. </p><h2 id="why-this-matters-for-the-uk">Why this matters for the UK</h2><p>The UK faces many of the same pressures as Europe: rising cyber threats, tighter regulation and rapid AI adoption. But it also has real strengths, including a mature <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cyber security</a> sector, world-leading professional services expertise, and a strong reputation for governance and innovation.</p><p>Those strengths give the UK a significant opportunity to position itself as a trusted partner for secure, resilient digital infrastructure. Realizing it, however, will require continued investment in infrastructure, skills and technology ecosystems.</p><p>The UK already has strong foundations. Within Vodafone Business, for example, <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> services for government and defense customers date back to 1989, underlining the long-term importance of trusted communications and secure operations.</p><h2 id="sovereignty-must-include-ai">Sovereignty must include AI</h2><p>The sovereignty conversation is no longer limited to networks, <a href="https://www.techradar.com/best/best-cloud-computing-services">cloud computing</a> infrastructure or cyber security; it now extends to AI itself.</p><p>The UK government’s recent £400 million commitment to next-generation AI chips reinforces that ambition and signals a more deliberate push to build sovereign capability in the technologies that will underpin future competitiveness and resilience. </p><p>Government investment in sovereign computing capability and broader AI infrastructure also signals recognition that access to advanced computing resources is becoming a strategic national asset.</p><p>This matters because AI is rapidly becoming foundational infrastructure. Organizations are embedding it into business operations, cyber security programs, customer engagement and decision-making.</p><p>For businesses, sovereignty is not about limiting innovation. It is about ensuring critical capabilities can be developed, governed and accessed in ways that support long-term economic resilience and trust.</p><h2 id="connectivity-as-critical-infrastructure">Connectivity as critical infrastructure</h2><p>One of the most important and often overlooked aspects of sovereignty is connectivity. As organizations rely more on AI services, IoT devices and real-time data exchange, networks become the foundation of operational resilience.</p><p>If connectivity fails, everything built on it is affected, from customer services and supply chains to communications and core business operations.</p><p>That is why investment in secure, resilient, high-capacity networks is central to the sovereignty debate. Without trusted connectivity, digital sovereignty remains theoretical rather than practical.</p><p>The formation of VodafoneThree is a significant step in strengthening the UK’s digital backbone. With a commitment to invest £11 billion in next-generation connectivity and an ambition to deliver 99.96% population coverage by 2034, the UK is building infrastructure to support future growth and resilience.</p><p>As AI workloads, edge computing, hybrid working and data-intensive applications expand, resilient connectivity becomes a strategic national asset.</p><p>This is particularly important for organizations delivering essential services. Today, 77% of UK Blue Light services already run on Vodafone Business networks, underlining the growing importance of trusted connectivity in critical operations.</p><h2 id="a-strategic-moment-for-the-uk">A strategic moment for the UK</h2><p>Europe’s emerging sovereignty agenda should not be mistaken for digital isolation. Rather, it reflects a growing recognition that interdependence must be understood, managed and secured.</p><p>For security leaders, that means broadening the conversation beyond traditional threat protection to include critical dependencies, digital supply chain resilience and operational continuity. Cyber security is increasingly part of a wider discipline of digital resilience, where security, connectivity, infrastructure and governance converge.</p><p>By combining cyber security expertise, growing sovereign AI capabilities, regulatory strengths and continued investment in connectivity, the UK has an opportunity to establish itself as Europe’s trusted security ally.</p><p>In the next phase of digital transformation, success will not belong only to those with the most advanced technology, but to those with the most trusted, resilient and transparent foundations.</p><p>The sovereignty economy is already taking shape. The question is whether the UK chooses simply to participate in it, or to help define it.</p><p><em></em><a href="https://www.techradar.com/best/best-business-cloud-storage-service"><em>We've reviewed and rated the best business cloud storage services</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Claude can now enter all your passwords for you - if you give it permission ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/claude-can-now-enter-all-your-passwords-for-you-if-you-give-it-permission</link>
                                                                            <description>
                            <![CDATA[ 1Password partnership will mean Claude will never see the secrets or load them into its own memory. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">gESvv4V9PcQSPAyMJnfqm6</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 14:10:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg">
                                                            <media:credit><![CDATA[Anthropic]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Mobile phone displaying a Claude login screen.]]></media:description>                                                            <media:text><![CDATA[Mobile phone displaying a Claude login screen.]]></media:text>
                                <media:title type="plain"><![CDATA[Mobile phone displaying a Claude login screen.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9YhV9JTvHHHB3MMDhxYpoj-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>1Password unveils Claude partnership, letting Anthropic’s AI authenticate on users’ behalf via zero‑exposure architecture</strong></li><li><strong>Users approve each login with biometrics</strong></li><li><strong>New Agentic Mode in the browser extension locks down the interface when AI agents take over</strong></li></ul><p>Top <a href="https://www.techradar.com/best/password-manager" target="_blank">password manager</a> company 1Password has launched a new tool that allows artificial intelligence assistant Claude to authenticate on behalf of their user, and thus complete assignments that were previously impossible without major security tradeoffs.</p><p><a href="https://1password.com/blog/1password-for-claude" target="_blank" rel="nofollow">1Password for Claude</a> is built on “zero-exposure architecture” - so in practice, it means Claude can essentially ask 1Password to complete the sign-in process, but it will never see the credentials, and they will never be loaded into its memory. </p><p>In turn, 1Password will notify the user, and will request biometric approval before proceeding. Once granted, it will autofill the credentials and check to see if they were exposed on the page or not. If submission fails, it will clear the filled values and report back. </p><h2 id="agentic-mode">Agentic Mode</h2><p>"We need a new security model that is purpose-built for agents, not just humans,” said Nancy Wang, CTO of 1Password. “The answer isn't handing agents your secrets. It is to let a user give an agent permission to use a credential without letting the agent see it. Claude knows it used your login; it does not need the password or one-time code in its context. That distinction is where trust in agents starts and the foundation we're building with Anthropic."</p><p>To further strengthen its security posture, 1Password also announced Agentic Mode, a new feature in the browser extension that gives users visibility and control over browser-based <a href="https://www.techradar.com/best/best-ai-tools" target="_blank">AI agents</a>. When a compatible AI agent takes over, the 1Password extension automatically locks down and hides the interface. The agent can only use the logins and OTPs explicitly approved for the current task. </p><p>Even if the integration is not set up, and even if 1Password is not required for the current agentic task, Agentic Mode works, the company stressed. Other agents, besides Claude, are supported, as well. </p><p>Currently a major debate is ongoing, about how much permissions AI agents should receive, and under what rules. We’ve already seen horror stories of AI agents deleting people’s entire email inboxes, or otherwise ruining days of hard work. Whether or not this picks up or most people remain skeptical about giving AI access to certain services, remains to be seen. </p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Is sovereignty threatening your resilience? ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/is-sovereignty-threatening-your-resilience</link>
                                                                            <description>
                            <![CDATA[ Sovereignty has entered a hype-cycle, and organizations risk missing the bigger operational picture. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">rMdcuBG65eFf5gJc3ZQddV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/p2uWFBGHtrHTjrYSDny87M-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 13:55:54 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Matt Johnson ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/p2uWFBGHtrHTjrYSDny87M-1280-80.jpg">
                                                            <media:credit><![CDATA[Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A data center with racks of servers and lots of lights glowing]]></media:description>                                                            <media:text><![CDATA[A data center with racks of servers and lots of lights glowing]]></media:text>
                                <media:title type="plain"><![CDATA[A data center with racks of servers and lots of lights glowing]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/p2uWFBGHtrHTjrYSDny87M-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The question of where <a href="https://www.techradar.com/best/best-data-migration-tools">data</a> lives has become considerably more fraught over the past few years. </p><p>A mix of regulatory scrutiny, geopolitical tensions across the Atlantic, and the related unease about the concentration of infrastructure power among the hyperscalers have all combined to push data sovereignty up the executive agenda. </p><p>The result? A strategic posture that’s increasingly shaped by political anxiety rather than operational logic. </p><p>And while both need to be considered by the boardroom, leaning too much on the former leads to very different decisions.</p><p>To be clear, there’s no debate that compliance with data residency requirements remains a genuine obligation for organizations in regulated industries, and nobody is suggesting otherwise. </p><p>The concern is with what comes next: many organizations are at the "we must manage our data carefully" stage, and are considering a leap to "we should consider exiting hyperscaler <a href="https://www.techradar.com/best/best-infrastructure-management-service">infrastructure</a> entirely." While the logic could be understandable, the reality is that full disengagement is neither effective nor necessary for the bulk of organizations. </p><p>The hyperscalers earned their position because they offered capabilities that were genuinely difficult to replicate at scale, and the organizations that depend on them most deeply are not in a position to unwind that dependency in any near-term timeframe. A multi-year transformation program with substantial execution risk is rarely the right answer to a political concern that may itself shift within that same period.</p><h2 id="conflating-data-residency-and-operational-resilience">Conflating data residency and operational resilience</h2><p>The focus on sovereignty has meant that ideas about data residency, infrastructure control, and operational resilience are being treated as interchangeable concepts. While connected, these are distinct ideas with distinct impacts on a business’s ability to function effectively and comply with regulation. </p><p>Let’s consider the incidents that really bring organizations down, and what makes <a href="https://www.techradar.com/best/best-data-recovery-software">data recovery</a> harder than it needs to be. It’s system failures, slow incident response, and exploited security vulnerabilities that take customer-facing services offline, erode trust and incur regulatory fines. A platform that fails during peak demand causes the same commercial and reputational damage regardless of where its data is stored. </p><p>Similarly, a <a href="https://www.techradar.com/news/best-internet-security-suites">security</a> breach does not become more or less severe based on whether it occurred on domestic or international infrastructure. The metrics that determine whether an organization functions under pressure are uptime, security posture and the quality of incident response capability. Sovereignty is one input to that picture, not the frame through which the whole picture should be viewed.</p><p>Simply put, an organization is not resilient simply because its data sits in the right jurisdiction. Resilience is an architectural and operational property that has to be built deliberately.</p><h2 id="where-real-control-lives">Where real control lives</h2><p>If sovereignty decisions are best understood as one component of broader operational resilience, then the more productive question is where in the stack is control most effectively exercised. The answer, particularly as <a href="https://www.techradar.com/best/best-ai-tools">AI</a> applications proliferate, is primarily at the data layer.</p><p>The <a href="https://www.techradar.com/best/best-database-software">database</a> has moved beyond its traditional role as a storage mechanism. In modern architectures, it is often the most reliable point of deterministic control in the entire stack: the place where governance is enforced in practice rather than documented in policy. </p><p>Data location, <a href="https://www.techradar.com/best/best-encryption-software">encryption</a>, access controls, cross-region movement – all of these are data infrastructure questions at heart. Getting them right is what makes meaningful sovereignty achievable, not as a political statement, but as an operational capability.</p><p>So in turn, when an organization has genuine control over governance at the data layer, suddenly the choice between a hyperscaler and a fully domestic alternative becomes less relevant. The question shifts from which provider to use to whether the infrastructure is flexible enough to enforce the appropriate rules for each workload. That reframing tends to produce considerably better outcomes.</p><p>In practice, this means building in tiers: cloud-native performance where the business requires speed, scalability and flexibility, on-premise or segmented deployments for regulated workloads, and the architectural flexibility to move between configurations as circumstances change. After all, regulations will continue to evolve. </p><p>The geopolitical environment that is currently driving sovereignty conversations will look different in three years. That means infrastructure decisions made under today's conditions need to remain workable under tomorrow's.</p><h2 id="building-for-change-not-for-certainty">Building for change, not for certainty</h2><p>The practical implication for technology leaders is straightforward: meet your regulatory obligations, exercise genuine control at the data layer, and build the architectural flexibility to adjust as requirements shift. </p><p>But after that, it’s important to give equal attention and consideration to the failure modes that are statistically far more likely to cause very tangible and costly problems: outages at peak load, delayed incident responses and vulnerabilities that could be exploited. </p><p>At the end of the day, those are far likelier to be discussed in post-mortems – not sovereignty. And while sovereignty deserves its place in the technology strategy conversation, it should sit within a resilience framework, not above it.</p><p><em></em><a href="https://www.techradar.com/best/best-cloud-databases"><em>We've featured the best cloud databases</em></a><em>.</em></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Coca-Cola shuts down Fairlife dairy production lines following ransomware attack ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/coca-cola-shuts-down-fairlife-dairy-production-lines-following-ransomware-attack</link>
                                                                            <description>
                            <![CDATA[ Coca-Cola confirms ransomware attack on Fairlife in an 8-K form filed with the SEC. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">98MXZYAA7TvT8EPNELLnKY</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" type="image/png" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 13:05:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/png" url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png">
                                                            <media:credit><![CDATA[Coca-Cola]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:description>                                                            <media:text><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:text>
                                <media:title type="plain"><![CDATA[AI squirrels look at Coca-Cola trucks]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SPwVn22r6XRNTeSZsKjoTB-1280-80.png" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Coca‑Cola confirmed a ransomware attack on its dairy subsidiary Fairlife, forcing suspension of US production operations while Canada sites remain unaffected</strong></li><li><strong>Incident response protocols were activated, with third‑party experts and authorities engaged; product quality and safety were not impacted</strong></li><li><strong>Analysts warn the financial impact could be significant given Fairlife’s importance, with losses compounding the longer production remains offline</strong></li></ul><p>Coca Cola was forced to shut down parts of its operations to tackle an ongoing ransomware infection.</p><p>In an 8-K form recently filed with the US Securities and Exchange Commission (SEC), the company said the attackers struck Fairlife, its dairy company.</p><p>“On July 16, 2026, The Coca-Cola Company announced that fairlife, a dairy company owned by the company, identified unauthorized access by a third party to a portion of its systems, including its production-related systems, in connection with a <a href="https://www.techradar.com/best/best-ransomware-protection" target="_blank">ransomware</a> event,” the filing reads.</p><h2 id="compounding-impact">Compounding impact</h2><p>Coca Cola then explained that it kicked off its incident response and business continuity protocols, bringing in third-party cybersecurity experts to help investigate the attack and assess the damages. It also notified relevant authorities.</p><p>However, the production in the US has been affected, since parts of the operation had to be suspended: “Product quality and safety have not been impacted. However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. fairlife’s Canada production operations are not currently impacted,” Coca Cola explained.</p><p>It said it was now working to bring the systems back up, and that it has “not yet determined whether the incident is reasonably likely to materially affect the company.”</p><p>In a statement shared with TechRadar Pro, Cybersecurity Researcher and Advanced Services Lead at Arcova, Joseph Perry, stressed that the material impact is likely to be great. How great - depends on how fast Coca Cola moves. </p><p>“Fairlife is not a minor business buried inside Coca-Cola’s portfolio. Coca-Cola generated nearly $48 billion in net revenue last year and made a $6.1 billion contingent payment tied to its acquisition of fairlife, which provides important context for the value of the operation now sitting idle,” Perry explains. </p><p>“With production suspended across fairlife’s US facilities, every hour can compound the financial impact through lost output, delayed shipments, recovery costs, inventory exposure and potential disruption for retailers. Coca-Cola has not yet quantified the loss, but the longer production remains offline, the more quickly a cyber incident becomes a material business event.”</p><p><em>Via </em><a href="https://www.bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/" target="_blank"><em>BleepingComputer</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Teenage TfL hackers sentenced to years in prison following Scattered Spider attacks ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/security/teenage-tfl-hackers-sentenced-to-years-in-prison-following-scattered-spider-attacks</link>
                                                                            <description>
                            <![CDATA[ Two young men pleaded guilty to hacking into Transport for London in 2024 and were given long prison sentences. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">SLBSG4pbDpZE9xtCXUuJpP</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 11:15:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Security]]></category>
                                                    <category><![CDATA[Cyber Security]]></category>
                                                    <category><![CDATA[Computing Security]]></category>
                                                    <category><![CDATA[Pro]]></category>
                                                    <category><![CDATA[Computing]]></category>
                                                                                                                    <dc:creator><![CDATA[ Sead Fadilpašić ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:description>                                                            <media:text><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:text>
                                <media:title type="plain"><![CDATA[Malware attack virus alert , malicious software infection , cyber security awareness training to protect business]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/7DtE9RCVmUtmH2FAfvxsvM-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <ul><li><strong>Two UK men sentenced to 5 years and 6 months for the 2024 cyberattack on Transport for London, linked to the Scattered Spider group</strong></li><li><strong>Police seized devices showing evidence of the TfL breach; Flowers was also mid‑attack on US healthcare firms SSM Health and Sutter Health at the time of arrest</strong></li><li><strong>TfL reported $39M in damages; the NCA says the sentencing effectively dismantled Scattered Spider, with Microsoft confirming the arrests degraded the group’s operations</strong></li></ul><p>Two young men, one aged 20 and the other 18, have been sentenced to five years and six months in prison for their involvement in the <a href="https://www.techradar.com/pro/security/tfl-admits-2024-cyberattack-may-have-affected-over-10-million-people-personal-customer-info-stolen-heres-what-we-know-so-far">cyberattack on Transport for London (TfL)</a> in 2024.</p><p>Thalha Jubair, from East London, and Owen Flowers, from Walsall, West Midlands were arrested in 2025 under the suspicion that they were the leading members of <a href="https://www.techradar.com/pro/security/fbi-cisa-warn-of-more-scattered-spider-attacks-to-come">Scattered Spider</a> - an infamous hacking collective known for breaching dozens of companies. Initial reports from different cybersecurity organizations claimed the group consisted mostly of teenagers whose native language was English. </p><p>During the arrest, the police seized different types of electronic equipment from the suspects, including laptops, PCs, smartphones, hard drives, removable storage, and more. On one of the computers, law enforcement found screenshots and videos showing the intrusion into TfL’s systems.</p><h2 id="millions-in-damages">Millions in damages</h2><p>To make matters even worse, Flowers was in the middle of breaking into US healthcare companies SSM Health Care Corporation and Sutter Health when he was arrested: According to the National Crime Agency (NCA), these two were already “infiltrated and damaged”.</p><p>The attack on TfL was one of the more disruptive incidents that year, and one which caused a lot of financial damage, too. According to a report TfL shared with the City of London Police (CoLP), it suffered around $39 million in loss and recovery costs.</p><p>Both Jubair and Flowers initially pleaded not guilty and changed their pleas to guilty on the day they were due to stand trial, it was said. Now, they are both sentenced to more than five years in jail. The NCA says these arrests and sentencing effectively dismantled the notorious hacking collective.</p><p>“Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity,” the NCA said in its <a href="https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case" target="_blank" rel="nofollow">report</a>. </p><p>“Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group's ability to continue conducting cybercriminal operations.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Human-led, AI-assisted testing: Why AI won’t replace penetration testers...yet. ]]></title>
                                                                                                                                                                                                <link>https://www.techradar.com/pro/human-led-ai-assisted-testing-why-ai-wont-replace-penetration-testers-yet</link>
                                                                            <description>
                            <![CDATA[ Why human expertise remains essential in AI-powered testing. ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">skJxAJL5jBKg7eJH8sZoHV</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Fri, 17 Jul 2026 11:00:17 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Pro]]></category>
                                                                                                                    <dc:creator><![CDATA[ Shaun Peapell ]]></dc:creator>                                                                                                        <dc:description><![CDATA[ null ]]></dc:description>
                                                                                                                                <cf:isSponsored>false</cf:isSponsored>
                <cf:hasAffiliateLinks>false</cf:hasAffiliateLinks>
                <cf:isPaid>false</cf:isPaid>
                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg">
                                                            <media:credit><![CDATA[Shutterstock]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:description>                                                            <media:text><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:text>
                                <media:title type="plain"><![CDATA[Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/fg7bgy65pWhFo4Qzib58yX-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Over the last year, one topic has dominated conversations across the <a href="https://www.techradar.com/best/best-online-cyber-security-courses">cybersecurity</a> industry:<a href="https://www.techradar.com/best/best-ai-tools"> artificial intelligence</a>.</p><p>Every week seems to bring another announcement, another capability, or another prediction about how AI will transform security. In offensive security, the discussion has become particularly intense. We are seeing AI-assisted vulnerability discovery, AI-generated attack simulations, AI-powered analysis tools, and increasingly bold claims about autonomous security testing. </p><p>The question I am asked most often is surprisingly simple:</p><p>“Will AI replace penetration testers?”</p><p>My answer is equally simple:  No.</p><p>What AI will do is change how penetration testers work.</p><p>And in many ways, it will make experienced penetration testers even more valuable.</p><h2 id="ai-is-already-changing-security-testing">AI is already changing security testing:</h2><p>Let’s start with the obvious.</p><p>AI is genuinely impressive.</p><p>Modern AI models can process vast amounts of information, identify patterns, summarize findings, correlate data sources, and surface potential issues far faster than any individual analyst could achieve manually.</p><p>Within offensive <a href="https://www.techradar.com/news/best-internet-security-suites">security</a>, AI is already helping teams:</p><ul><li>Identify vulnerabilities more quickly</li><li>Analyze large datasets</li><li>Correlate findings across environments</li><li>Surface potential attack paths</li><li>Generate documentation and reporting</li><li>Reduce repetitive manual tasks</li></ul><p>These are meaningful improvements.</p><p>Many of the activities that traditionally consumed valuable consultant time can now be accelerated significantly.</p><p>As a result, organizations are gaining greater visibility into their environments than ever before.</p><p>But visibility alone has never been the ultimate goal.</p><h2 id="finding-vulnerabilities-has-never-been-the-hard-part">Finding vulnerabilities has never been the hard part:</h2><p>One of the biggest misconceptions in cybersecurity is that finding vulnerabilities is the primary challenge.</p><p>It isn’t.</p><p>Understanding risk is.</p><p>Most organizations already have access to large amounts of security <a href="https://www.techradar.com/best/best-data-recovery-software">data</a>. They run vulnerability scanners. They receive penetration testing reports. They consume threat intelligence. They deploy attack surface management tools. They monitor logs and alerts.</p><p>The problem is rarely a complete lack of information. The problem is understanding what matters.</p><ul><li>Which vulnerabilities are genuinely exploitable?</li><li>Which attack paths represent realistic threats?</li><li>Which issues require immediate remediation?</li><li>Which findings can safely wait?</li></ul><p>These questions are considerably harder to answer than simply identifying a vulnerability. And they are questions that require context.</p><h2 id="context-is-where-human-expertise-matters">Context is where human expertise matters</h2><p>A vulnerability rarely exists in isolation.</p><p>The real-world risk associated with any finding depends on a range of factors, including asset criticality, business impact, compensating controls, user privileges, environmental configuration, attacker motivation, and the relationships between multiple weaknesses.</p><p>This is where experienced penetration testers provide value that AI alone cannot replicate.</p><p>When performing an assessment, we are not simply identifying vulnerabilities. We are thinking like attackers.</p><p>We are asking questions such as:</p><ul><li>How would I gain initial access?</li><li>What would I target next?</li><li>How could I chain these weaknesses together?</li><li>What data could be accessed?</li><li>How difficult would exploitation actually be?</li><li>What is the likely business impact?</li></ul><p>These decisions are rarely straightforward. They require judgement, creativity, and experience.</p><p>Two organizations may have the same vulnerability present within their environments, yet the associated risk could be dramatically different depending on the surrounding context.</p><p>Understanding that difference is where human expertise becomes critical.</p><h2 id="the-future-isn-t-autonomous-testing">The future isn’t autonomous testing:</h2><p>There is currently a great deal of excitement around autonomous security testing. The idea is appealing. Feed an environment into an AI model and receive a complete understanding of risk in return. </p><p>The reality is significantly more complex.</p><p>Attackers do not operate according to predefined workflows.</p><ul><li>They adapt.</li><li>They improvise.</li><li>They exploit unexpected opportunities.</li><li>They combine seemingly insignificant weaknesses into meaningful attack chains.</li></ul><p>Successful offensive security assessments require the same flexibility.</p><p>While AI can assist with analysis and discovery, security testing remains fundamentally an exercise in understanding human behavior, <a href="https://www.techradar.com/best/best-business-plan-software">business</a> context, and attacker decision-making. These are areas where human expertise continues to outperform automation.</p><p>For the foreseeable future, I believe the most effective approach will be human-led, AI-assisted testing. Not human versus AI. Human plus AI.</p><h2 id="ai-should-make-penetration-testers-better">AI should make penetration testers better:</h2><p>The conversation should not be about replacing penetration testers. It should be about enabling them. When repetitive activities are automated, consultants can spend more time focusing on the areas where they create the greatest value.</p><p>Instead of manually processing information, they can spend more time:</p><ul><li>Investigating attack paths</li><li>Validating exploitability</li><li>Understanding business impact</li><li>Identifying complex attack chains</li><li>Advising clients on remediation priorities</li><li>Delivering meaningful security outcomes</li></ul><p>In many respects, AI allows skilled security professionals to operate at a higher level. It augments expertise rather than replacing it. The result is not fewer penetration testers.</p><p>It is more effective penetration testers.</p><h2 id="the-real-challenge-is-prioritization">The real challenge is prioritization:</h2><p>As AI continues to improve vulnerability discovery and analysis, organizations will inevitably uncover more security findings.</p><p>That sounds positive, but it introduces a new challenge. More findings do not automatically reduce risk. In fact, without effective prioritization, they can create additional noise.</p><p>The organizations that succeed over the next decade will not necessarily be the ones finding the most vulnerabilities. They will be the ones that can most effectively distinguish genuine risk from background noise, understand how attackers are likely to exploit weaknesses in practice, and make informed decisions about where to focus finite resources.</p><p>As AI continues to improve vulnerability discovery and analysis, security teams will inevitably gain access to more data, more findings, and greater visibility than ever before. While that represents a significant advancement for the industry, visibility alone does not reduce risk. The real value lies in understanding what matters, what is exploitable, and what action should be taken next.</p><p>That is why I believe the future of security testing is not autonomous. It is human-led and AI-assisted. <a href="https://www.techradar.com/best/best-ai-tools">AI tools</a> will continue to accelerate analysis, improve visibility, and help uncover opportunities that may previously have been missed. However, understanding business context, assessing real-world risk, and making sound security decisions will remain fundamentally human responsibilities.</p><p>The cybersecurity industry has spent years trying to solve the visibility problem. AI is helping us make enormous progress. The next challenge is prioritization, and that is where experienced security professionals will continue to play their most important role.</p><p><em></em><a href="https://www.techradar.com/best/best-antivirus"><em>We've featured the best antivirus software.</em></a></p><p><em>This article was produced as part of </em><a href="https://www.techradar.com/pro/perspectives" target="_blank"><em>TechRadar Pro Perspectives</em></a><em>, our channel to feature the best and brightest minds in the technology industry today.</em></p><p><em>The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: </em><a href="https://www.techradar.com/news/submit-your-story-to-techradar-pro" target="_blank"><em>https://www.techradar.com/pro/perspectives-how-to-submit</em></a></p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>