The new Apple Watch includes several “intelligent” listening features that have privacy and security baked in. But the protections can’t change the facts…
Category: EN
Part 2: Securing and Scaling Goose-to-Java Agent Traffic With agentgateway
In Part 1 of this series, we built a Quarkus-based MCP tool server and connected it to the Goose AI agent over Streamable HTTP. The tools worked, the demo…
OpenSSL 4.1 Alpha Release Announcement
The OpenSSL Project is pleased to announce that OpenSSL 4.1 Alpha1 pre-release is available, which adds significant new functionality to the OpenSSL…
OpenAI’s rebel agent swarm died young, but its chilling logs live on
‘The Collective’ learned to communicate, organize, cheat, and apparently sacrifice its own
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges
Europol and European Labour Authority strengthen cooperation against labour exploitation
The Working Arrangement formalises cooperation that has already demonstrated its value through joint involvement in EMPACT activities. It provides a…
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA,…
August 2026 Cyber Threat Landscape: GenAI Data Exposure Emerges as a New Enterprise Risk as Attacks, Phishing, and Ransomware Accelerate
Key takeaways GenAI usage continued to grow, with the average user generating 106 prompts in August, up from 95 in July and around 78 in June, while…
Nvidia To Buy Hugging Face For $12.9bn
Leading AI chipmaker to purchase major AI developer platform as Hugging Face chief speaks of ‘turning point’ for open-source AI
Pipelines on Fire: Why Your CI/CD Tools Are the New Cyber Battlefield
Fifteen years in, and the conversation I have most often with security leads still starts the same way: how’s your perimeter, how’s your endpoint…
Passkey-themed social engineering leads to identity and cloud compromise
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA…
Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware
Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an…
Scans for Proxmox Servers, (Wed, Sep 9th)
About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The…
WRAITH – Browser Hooking and Blind XSS Page Mirroring
WRAITH combines BeEF-style browser hooks with blind-XSS capture and a credentialed Page Mirror. Tested locally, with its limits examined.
Nscale In $3.5bn Compute Deal For Figure Humanoid Robots
Data centre provider Nscale to supply at least $3.5bn of compute to Figure AI, becomes shareholder in humanoid robot maker
MikroTik routers hijacked, Russian data center threats, UK cybercrime losses surge
MikroTik routers hijacked through internet-exposed SSH Russian data centers face new security requirements UK account-hack losses surge thanks to new…
Serial Microsoft 0-day hunter drops yet another Defender exploit
A bypass of a bypass of a bypass
HelmGuard Raises $7.3 Million for Agentic GRC and Security
The company will increase its US market presence and will expand its engineering and go-to-market teams.
A week in security (August 31 – September 6)
Last week on Malwarebytes Labs: Stay safe!
CVE-2026-75650 Adobe Commerce Zero-Day: Patch Isn’t Enough
Adobe patched the actively exploited CVE-2026-75650 Magento zero-day, but compromised stores still need malware hunting and broad credential rotation.
