News Feed
Aggregated from vendor blogs, The Register, NCSC UK, IT Pro, and more.
Expanded multistage chain of thought monitoring makes frontier model work more expensive
Gaps in expiry checks could let dead plastic make purchases again
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing…
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
Partners need to be able to confidently answer key client questions relating to supply chain security going forward...
New dynamic model routing capabilities aim to help customers box clever when it comes to their AI model choice
Learn about the AI accelerator chips known as AWS Trainium and understand how, where, and why they are used within AI infrastructure...
<p>Apple has addressed close to 20 vulnerabilities in the open source <a href="https://webkit.org/" target="_blank" rel="noopener">WebKit</a> browser engine that underpins its Safari browser, which are present in its desktop and notebook, and mobile operating systems.</p> <…
Phishing, malvertising attacks could target devs to gain access to private corporate networks
Patch batch spans current kit, older iGadgets, Macs, and Vision Pro
Security controls can block a familiar attack method while missing quieter ways to achieve the same objective. Picus Security's Blue Report 2026 shows how prevention rates can vary dramatically by technique and why behavioral testing is needed to uncover those gaps. [...]
AI developers are struggling to find enough data to train their models, sparking a bidding war for failed Spirit Airlines deidentified data
How to social engineer an AI's reasoning engine
Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]
TheHatman claims the data has been stolen from the victims' Azure and Entra tenants using compromised credentials
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. [...]
The program includes new and upgraded substations, new cables, and reinforcement of existing overhead lines
An eight-hour GitHub outage saw an error rate of 50% for repo downloads and major disruption to Actions, APIs, and Copilot
Microsoft says some users are experiencing issues searching in Microsoft 365 apps, including Outlook on the web, Outlook desktop, SharePoint Online, and OneDrive. [...]
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week. [...]
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials. [...]
Data sovereignty has become a key channel priority
Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detecti…
<p>A series of prominent organisations including UK fossil fuel giant Shell, Dutch consumer and health tech multinational Philips, and the US’ General Electric (GE) are probing security breaches after being “named and shamed” by the <a href="https://www.computerweekly.com/news/366642957/ICO…
McDonald's, Vodafone, TCS, Kyndryl, and others named as researchers point to compromised credentials
With more patches per month than at a pirate convention, the bug must be an endangered species. Well, about that
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
On this week's episode of The Reg's Kettle podcast, we revisit 'hacker summer camp,' where the hottest topic was ... sigh... agentic AI
<p>Earlier this year Grok was asked to produce millions of sexualised images of women and children. Jess Asato, Labour MP for Lowestoft spoke out, after she became a victim of this form of online abuse. “As a member of Parliament who deals a lot with violence against women and girls, I spoke o…
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality…
<p>Quintas Energy, which provides independent asset management services to the renewable energy sector, is deploying Box to establish a <a href="https://www.computerweekly.com/news/366639242/RWS-Global-deploys-Boxs-AI-tools-to-streamline-contract-workflow">secure, intelligent content lay…
<div class="imagecaption alignLeft"> <img src="https://cdn.ttgtmedia.com/rms/computerweekly/CW-60-anniversary-logo-white-400px.jpg" alt="Computer Weekly 60th anniversary logo" width="226" height="117"> </div> <p><i>On 22 September 2026, Computer Weekly turns 60. To mark…
Hidden API Estate And AI-speed Recon Are Reshaping Modern Application Risk Key Takeaways Unknown APIs create unattributed exposure, and such exposure rarely gets tested. Attackers build their own inventory through live reconnaissance; they do not wait for your spreadsheet. API discovery must pull fr…
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
The incident involving OpenAI models shows that autonomous hacks make human oversight more important, not less
Key Takeaways Cloud environments change continuously, while security still relies on periodic scans, leaving gaps where risks go undetected. That gap becomes exposure. Qualys Real-Time CSPM monitors cloud changes as they happen, while still supporting periodic scans for environments that require the…
Unit 42 is putting the latest frontier cyber models to work across customer environments to find, validate and help remediate the attack paths that matter most. In May, we introduced Frontier AI … The post Putting OpenAI Cyber Models to Work for Defenders appeared first on Palo Alto Networks B…
AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong
<p>When Labour MP Jess Asato first saw the fake images of herself circulating online, the experience was both unsettling and violating. The hyper-realistic deepfakes, created without her consent using xAI's Grok platform, looked unmistakably like her – a digital theft of her identity. Now, she…
The August 2026 Microsoft Patch Tuesday release delivers security fixes for vulnerabilities affecting a wide range of Microsoft products and services. As attackers continue to exploit unpatched vulnerabilities, timely patching remains critical for reducing exposure and strengthen…
42Critical355Important1Moderate0LowMicrosoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as…
<p>An average of £3,000 was lost by people as a result of financial investment fraud via social media platforms, according to a TSB survey. The warning comes as more people use unregulated advice via tech platforms and artificial intelligence (AI).</p> <p>The findings also revealed…
As organizations race to deploy agentic AI, legacy network security solutions are ill-equipped to keep up, forcing productivity tradeoffs while exposing coverage gaps. At the same time, Frontier AI is proving capable … The post Palo Alto Networks Recognized as the Only Vendor to be Named a 4X …
Key Takeaways Human-speed compliance is dead. Attackers utilizing modern, autonomous AI tools can chain enterprise misconfigurations and weaponize vulnerabilities in under 25 minutes, rendering manual, periodic audit cycles completely obsolete. The “Configuration Gap” is your biggest bli…
AI tutors can offer useful support, but their quality and safeguards vary widely. Here’s what parents should check before handing one to a child.
Palo Alto Networks works closely with OpenAI across our product platform and Unit 42, leveraging advanced frontier model capabilities. Furthermore, we are a partner in the OpenAI Daybreak Cyber Partner Program, working … The post Strengthening Security of AI Coding: Prisma AIRS API Integration…
Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event.Key takeawaysBuilding defensive cybersecurity tooli…
<p>As frontier artificial intelligence (AI) models become capable of reasoning across increasingly complex environments, the gap between <a href="https://www.computerweekly.com/opinion/Stop-debating-frontier-AI-start-defending-against-it">discovering a vulnerability and exploiting</a&…
The enterprise workforce now operates almost entirely within the web browser. In fact, employees do roughly 85% of their daily work inside it, turning the browser into the sole operating system of … The post Bridging the Gap: An Unprecedented Approach to Browser and Endpoint Security appeared …
We spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger.Key takeawaysFrontier AI dramatically scales security testing. In one month, Tenable…
As AI adoption shifts from experimental tools to the business core, enterprises are deploying AI agents and assistants across every department. Developers are accelerating software delivery with Claude Code and business functions … The post Prisma AIRS - Unified Data Protection for Claude appe…