It has been reported that OpenAI is developing the first consumer hardware product, an AI speaker with no screen to turn ChatGPT into a constantly available household companion. Through the use of advanced artificial intelligence capabilities, the device is…
Tag: EN
How Pro-Iran Hacktivist Networks Mobilize During Kinetic Conflict
The current conflict between the United States and Iran has become a case study in how asymmetric warfare and coalition building are reshaping the cyber and geopolitical dimensions of modern conflict. Following the United States and Israel’s joint military strikes…
US Indicts Three Russian Nationals Over Bulletproof Hosting Network Linked to Global Cybercrime
The EU sanctioned nine Russian citizens and four entities for engaging in cyber-espionage campaigns and attacks against the EU, member states, Ukraine, and other countries. The sanctions were imposed by the Council of the European Union and coordinated with…
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 107
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter UAC-0145 Primary Compromise Vectors as of July 2026 SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor …
Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials
Hackers compromised hotel Wi-Fi gateways to redirect users to fake Microsoft 365 login pages and steal credentials. ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft…
Security Affairs newsletter Round 587 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press. Iran-Linked…
Top 10 Best Active Directory Management Tools 2026
Managing Active Directory with native tools alone can become time-consuming as an organization grows. Routine tasks such as provisioning users, resetting passwords, managing group memberships, auditing permissions, and maintaining compliance can place a heavy burden on IT teams. Manual processes…
Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more than one AI platform at the same time. Developers pull up coding…
PentesterFlow – AI Tool for Penetration Testers and Bug Hunters to Automate Workflows
PentesterFlow is a new open-source, human-in-the-loop agentic AI command-line tool built specifically for penetration testers and bug bounty hunters, designed to automate recon-to-reporting workflows without sacrificing analyst oversight. Most agentic AI security tools suffer from hallucinated findings, weak context retention,…
Beyond the blind spots: Defeating frontier AI model threats in your application development process
Looking back a few months ago, it's wild to think about how much things have changed in the world of cybersecurity. Not long ago, running a few outdated application runtimes, pushing Common Vulnerabilities and Exposures (CVE) patches to "next month's…
Ghost Font Exposes a Blind Spot in AI Vision by Hiding Text in Motion-Based Optical Illusions
Artificial intelligence has made significant progress in reading documents, recognizing handwritten text and interpreting low-quality images. However, a new experimental typography project called Ghost Font is revealing an unexpected limitation in how many AI vision systems process visual information.Created by…
Google Fixes Dialogflow CX Flaw That Could Have Exposed AI Chatbot Conversations
Google has patched a security vulnerability in its Dialogflow CX platform that could have allowed attackers to steal sensitive conversations from AI-powered chatbots and deploy phishing attacks by abusing a permissions loophole.The flaw, dubbed "Rogue Agent" by researchers at…
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL. Confiant, which detailed the campaign on…
Iran-Linked Actors Breach Are Targeting US Water and Energy Control Systems
US agencies warn Iran-linked actors are targeting internet-exposed water and energy control systems, risking disruption. Federal agencies updated their cybersecurity advisory this week: Iran-linked actors are inside American water and energy control systems, and they’re not just looking around. They’re…
The hacker who humiliated spyware makers and was never caught
An awe-inspiring hacktivist who hacked two controversial government spyware makers may be the most prolific hacker to have never gotten caught. What do we know about Phineas Fisher? This article has been indexed from Security News | TechCrunch Read the…
GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations
A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services.…
Russian Cyber Spies Exploited Critical Zimbra Flaw to Access Emails and 2FA Codes
Cyber espionage groups backed by the Russian government exploited a previously unknown vulnerability in the Zimbra Collaboration Suite (ZCS) in order to steal emails, browser credentials, and two-factor authentication (2FA) recovery codes from government and commercial organizations throughout the…
10 Best ZTNA Solutions (Zero Trust Network Access) In 2026
Zero Trust Network Access (ZTNA) anchors 2026 cybersecurity amid remote, cloud, and hybrid booms. ZTNA solutions aren’t hype—they’re vital for data locks, compliance wins, and borderless teams. “Never trust, always verify”: ZTNA okays only vetted users/devices, location-blind. Shrink attack planes,…
Researcher Claims Working Jailbreak on Top AI Models Including GPT-5.6, Claude Opus 5, and Fable
A well-known AI red teamer claims to have developed a universal jailbreak that works against leading large language models, including heavily guarded flagships such as GPT-5.6 Sol, Claude Opus 5, and Fable. In a public post on X, Pliny the…
Australian energy provider Origin Energy disclosed a data breach impacting customer data
Origin Energy confirmed a data breach after a hacker claimed to have stolen data from 2 million customers and threatened to leak it. Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records…